Policy & Governance
Open Policy Agent (OPA)
An open-source policy engine that evaluates structured input against declarative policies written in Rego.
Problem it solves
Why it exists.
It separates policy decisions from application and platform code so rules can be reviewed and reused consistently.
Optimized for
Where it shines.
Authorization, infrastructure guardrails, Kubernetes admission, and compliance checks across systems.
Use with care
Where not to use it.
Do not centralize policies without clear ownership, testing, versioning, and an operational fallback.
Components
What it is made of.
- OPA engine
- Rego
- Policy bundles
- Decision logs
- Integrations
Process
How it works.
- A system sends structured input
- OPA evaluates the relevant Rego policy
- A decision is returned
- The caller allows, denies, or audits the action