← DevOps tools
Policy & Governance

Open Policy Agent (OPA)

An open-source policy engine that evaluates structured input against declarative policies written in Rego.

Why it exists.

It separates policy decisions from application and platform code so rules can be reviewed and reused consistently.

Where it shines.

Authorization, infrastructure guardrails, Kubernetes admission, and compliance checks across systems.

Where not to use it.

Do not centralize policies without clear ownership, testing, versioning, and an operational fallback.

What it is made of.

  • OPA engine
  • Rego
  • Policy bundles
  • Decision logs
  • Integrations

How it works.

  1. A system sends structured input
  2. OPA evaluates the relevant Rego policy
  3. A decision is returned
  4. The caller allows, denies, or audits the action
Questions and answers.Open the interview practice set for Open Policy Agent (OPA).
Search