# rego

Published articles for rego.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Policy as Code in 2026: OPA, Kyverno, Cedar and What's Next

DevFeed: [Policy as Code in 2026: OPA, Kyverno, Cedar and What's Next](<https://devfeed.tech/articles/policy-as-code-in-2026-opa-kyverno-cedar-and-what-s-next-26775.md>)

Original publisher: [Read original article](<https://www.harness.io/blog/policy-as-code-in-2026-opa-kyverno-cedar-and-what-s-next>)

Author: Abhijit Pujare Eric Minick

Published: 2026-09-11T00:00:00Z

Content type: article

Language: en

Sources: [Harness Blog](<https://devfeed.tech/sources/harness-blog.md>)

Topics: [policy-as-code](<https://devfeed.tech/topics/policy-as-code.md>), [Open Policy Agent](<https://devfeed.tech/topics/open-policy-agent.md>), [rego](<https://devfeed.tech/topics/rego.md>), [Kyverno](<https://devfeed.tech/topics/kyverno.md>), [Software Engineering](<https://devfeed.tech/topics/software-engineering.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [JSON](<https://devfeed.tech/topics/json.md>), [YAML](<https://devfeed.tech/topics/yaml.md>), [AI Agent](<https://devfeed.tech/topics/ai-agent.md>)

Tags: [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [json](<https://devfeed.tech/tags/json.md>), [kyverno](<https://devfeed.tech/tags/kyverno.md>), [opa](<https://devfeed.tech/tags/opa.md>), [open-policy-agent](<https://devfeed.tech/tags/open-policy-agent.md>), [policies](<https://devfeed.tech/tags/policies.md>), [policy-as-code](<https://devfeed.tech/tags/policy-as-code.md>), [rego](<https://devfeed.tech/tags/rego.md>), [security](<https://devfeed.tech/tags/security.md>), [software-engineering](<https://devfeed.tech/tags/software-engineering.md>), [yaml](<https://devfeed.tech/tags/yaml.md>)

### AI overview

This article surveys the 2026 Policy as Code ecosystem, comparing general-purpose Open Policy Agent and Rego with specialized approaches such as Kyverno, Cedar, and agent-oriented governance. It discusses the shift toward automated, machine-readable governance, the separation of policy from business logic, and the challenges of authoring and maintaining Rego as schemas evolve.

### Source excerpt

| Blog

## Accelerate teams with platform engineering and policy-as-code

DevFeed: [Accelerate teams with platform engineering and policy-as-code](<https://devfeed.tech/articles/accelerate-teams-with-platform-engineering-and-policy-as-code-12124.md>)

Original publisher: [Read original article](<https://platformengineering.org/blog/accelerate-teams-with-platform-engineering-and-policy-as-code>)

Author: Rafael Ferreira

Published: 2026-07-23T05:40:01Z

Content type: article

Language: en

Sources: [Platform Engineering Blog](<https://devfeed.tech/sources/platform-engineering-blog.md>)

Topics: [Platform Engineering](<https://devfeed.tech/topics/platform-engineering.md>), [DevOps](<https://devfeed.tech/topics/devops.md>), [Security](<https://devfeed.tech/topics/security.md>), [Code](<https://devfeed.tech/topics/code.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [opa](<https://devfeed.tech/topics/opa.md>), [JSON](<https://devfeed.tech/topics/json.md>), [rego](<https://devfeed.tech/topics/rego.md>), [YAML](<https://devfeed.tech/topics/yaml.md>), [Git](<https://devfeed.tech/topics/git.md>)

Tags: [best-practices](<https://devfeed.tech/tags/best-practices.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [git](<https://devfeed.tech/tags/git.md>), [json](<https://devfeed.tech/tags/json.md>), [kyverno](<https://devfeed.tech/tags/kyverno.md>), [platform](<https://devfeed.tech/tags/platform.md>), [platform-engineering](<https://devfeed.tech/tags/platform-engineering.md>), [policy](<https://devfeed.tech/tags/policy.md>), [rego](<https://devfeed.tech/tags/rego.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This article explains how platform engineering uses internal platforms, golden paths, automation, and self-service to reduce developer cognitive load while improving security, compliance, cost control, and delivery speed. It also presents Policy-as-Code as a way to encode rules in versioned, testable definitions and validate them continuously before deployment, with tools such as OPA and Kyverno providing immediate feedback and audit trails.

### Source excerpt

Move from DevOps to platform engineering. Learn golden paths, platform thinking, and why demand is rising for skilled platform engineers

## Automated DevOps Compliance with Harness Rego Policy Packs

DevFeed: [Automated DevOps Compliance with Harness Rego Policy Packs](<https://devfeed.tech/articles/automated-devops-compliance-with-harness-rego-policy-packs-13381.md>)

Original publisher: [Read original article](<https://www.harness.io/blog/compliance-without-complexity-introducing-harness-rego-policy-packs>)

Author: Abhijit Pujare Vishal Vishwaroop

Published: 2026-07-14T00:00:00Z

Content type: release

Language: en

Sources: [Harness Blog](<https://devfeed.tech/sources/harness-blog.md>)

Topics: [DevOps](<https://devfeed.tech/topics/devops.md>), [rego](<https://devfeed.tech/topics/rego.md>), [sdlc](<https://devfeed.tech/topics/sdlc.md>), [opa](<https://devfeed.tech/topics/opa.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [audit](<https://devfeed.tech/tags/audit.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [devops](<https://devfeed.tech/tags/devops.md>), [governance](<https://devfeed.tech/tags/governance.md>), [opa](<https://devfeed.tech/tags/opa.md>), [policy](<https://devfeed.tech/tags/policy.md>), [policy-as-code](<https://devfeed.tech/tags/policy-as-code.md>), [rego](<https://devfeed.tech/tags/rego.md>), [sdlc](<https://devfeed.tech/tags/sdlc.md>)

### AI overview

Harness announces Policy Packs, a curated library of pre-written Rego policies that helps teams align software delivery lifecycles with compliance frameworks. The packs provide out-of-the-box governance controls covering frameworks including SOC 2, NIST, PCI DSS, HIPAA, and HITRUST.

### Source excerpt

Shift governance left with out-of-the-box Policy-as-Code. Simplify compliance and achieve continuous audit readiness across your entire SDLC. | Blog

## Optimizing OPA performance: From arrays to objects

DevFeed: [Optimizing OPA performance: From arrays to objects](<https://devfeed.tech/articles/optimizing-opa-performance-from-arrays-to-objects-22577.md>)

Original publisher: [Read original article](<https://medium.com/capital-one-tech/optimizing-opa-performance-from-arrays-to-objects-a3c966acdaa5?source=rss----3db3a67cb648---4>)

Author: Capital One Tech

Published: 2026-07-07T14:25:30Z

Content type: tutorial

Language: en

Sources: [Capital One Tech](<https://devfeed.tech/sources/capital-one-tech.md>)

Topics: [opa](<https://devfeed.tech/topics/opa.md>), [Open Policy Agent](<https://devfeed.tech/topics/open-policy-agent.md>), [rego](<https://devfeed.tech/topics/rego.md>), [Data structures](<https://devfeed.tech/topics/data-structures.md>), [Optimization](<https://devfeed.tech/topics/optimization.md>), [Algorithms, Complexity](<https://devfeed.tech/topics/algorithms-complexity.md>)

Tags: [algorithms](<https://devfeed.tech/tags/algorithms.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [data-structures](<https://devfeed.tech/tags/data-structures.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [opa](<https://devfeed.tech/tags/opa.md>), [open-policy-agent](<https://devfeed.tech/tags/open-policy-agent.md>), [optimization](<https://devfeed.tech/tags/optimization.md>), [performance-tuning](<https://devfeed.tech/tags/performance-tuning.md>), [rego](<https://devfeed.tech/tags/rego.md>), [software-development](<https://devfeed.tech/tags/software-development.md>), [software-engineering](<https://devfeed.tech/tags/software-engineering.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>)

### AI overview

This article explains how to improve Open Policy Agent performance by choosing appropriate data structures for Rego policies. It focuses on replacing nested arrays with keyed objects to avoid inefficient array traversal when evaluating large datasets.

### Source excerpt

Achieve 99% faster Rego policy execution through optimization. Note: This post focuses on one aspect of performance tuning Rego policies and datasets evaluated by OPA-arrays vs. objects. The Rego Style Guide and Regal Rego linter are very helpful resources for learning Rego best practices and avoiding code smells in Rego policies. There is also the OPA performance tuning documentation. In 2018, I started using open policy agent (OPA) as a solution for controlling and preventing unwanted behaviors in our Kubernetes Clusters. OPA, along with Kubernetes Dynamic Admission Control, provided a means to build preventive controls. Since then, I have worked with several PaC solutions. I have always stayed close to the OPA tool set because of how well it supports multiple use cases. OPA is domain agnostic and can be used with virtually any use case, as long as you supply the correct data and policies. To that end, OPA use cases have expanded throughout several technical disciplines, such as cloud-native computing and software supply chain management. OPA performance engineering OPA enables us to unify PaC solutions across multiple use cases and systems, using the same languages and tools. However, there is always room for improvement and performance engineering policies and the execution thereof. In addition, optimizing data that policies evaluate and mutate should be part of our focus when we deliver OPA-based solutions. Recently I was asked to help with OPA performance issues. I made several recommendations, but I overlooked one simple and glaring issue: the poor performing policy was processing a large data set using nested-arrays, instead of the best practice of using keyed-objects. Later, something was bothering me about my interaction and I realized that while I gave decent architectural level advice, I completely missed the best engineering advice. Rego policies and data should be optimized just like other algorithms and relative data, and part of that optimization is

## Security Benchmarking Authorization Policy Engines: Rego, Cedar, OpenFGA & Teleport ACD

DevFeed: [Security Benchmarking Authorization Policy Engines: Rego, Cedar, OpenFGA & Teleport ACD](<https://devfeed.tech/articles/security-benchmarking-authorization-policy-engines-rego-cedar-openfga-teleport-acd-29590.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/benchmarking-policy-languages/>)

Author: info@goteleport.com (Mohamed Ouad, Doyensec)

Published: 2025-06-04T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [benchmarking](<https://devfeed.tech/topics/benchmarking.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Security](<https://devfeed.tech/topics/security.md>), [rego](<https://devfeed.tech/topics/rego.md>), [Open Policy Agent](<https://devfeed.tech/topics/open-policy-agent.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [authorization](<https://devfeed.tech/tags/authorization.md>), [benchmarking](<https://devfeed.tech/tags/benchmarking.md>), [opa](<https://devfeed.tech/tags/opa.md>), [open-policy-agent](<https://devfeed.tech/tags/open-policy-agent.md>), [performance](<https://devfeed.tech/tags/performance.md>), [rego](<https://devfeed.tech/tags/rego.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article introduces the Security Policy Evaluation Framework (SPEF), an automated testing and benchmarking system for evaluating authorization policy engines. It describes how SPEF assesses robustness, correctness, and performance across Rego, Cedar, OpenFGA, and Teleport ACD.

### Source excerpt

Explore how the Security Policy Evaluation Framework (SPEF) benchmarks Rego, Cedar, OpenFGA, and Teleport ACD for vulnerabilities, correctness, and performance.

## Ep. 9: Go Package Design: Authorization and API Structures

DevFeed: [Ep. 9: Go Package Design: Authorization and API Structures](<https://devfeed.tech/articles/ep-9-go-package-design-authorization-and-api-structures-22251.md>)

Original publisher: [Read original article](<https://www.ardanlabs.com/blog/2024/07/go-package-design-authorization-and-api-structures-ep-9.html>)

Published: 2024-07-17T00:00:00Z

Content type: tutorial

Language: en

Sources: [William Kennedy](<https://devfeed.tech/sources/william-kennedy.md>)

Topics: [Go Language](<https://devfeed.tech/topics/go-language.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [rego](<https://devfeed.tech/topics/rego.md>), [Software Engineering](<https://devfeed.tech/topics/software-engineering.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [api-structures-in-go](<https://devfeed.tech/tags/api-structures-in-go.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [clean-code-go](<https://devfeed.tech/tags/clean-code-go.md>), [context-in-go-middleware](<https://devfeed.tech/tags/context-in-go-middleware.md>), [efficient-go-code](<https://devfeed.tech/tags/efficient-go-code.md>), [error-handling-patterns-go](<https://devfeed.tech/tags/error-handling-patterns-go.md>), [exported-and-unexported-apis-go](<https://devfeed.tech/tags/exported-and-unexported-apis-go.md>), [go](<https://devfeed.tech/tags/go.md>), [go-api-best-practices](<https://devfeed.tech/tags/go-api-best-practices.md>), [go-api-readability](<https://devfeed.tech/tags/go-api-readability.md>), [go-authorization](<https://devfeed.tech/tags/go-authorization.md>), [go-authorization-logic](<https://devfeed.tech/tags/go-authorization-logic.md>), [go-development-practices](<https://devfeed.tech/tags/go-development-practices.md>), [go-error-management](<https://devfeed.tech/tags/go-error-management.md>), [go-middleware-handlers](<https://devfeed.tech/tags/go-middleware-handlers.md>), [go-package-design](<https://devfeed.tech/tags/go-package-design.md>), [go-package-organization](<https://devfeed.tech/tags/go-package-organization.md>), [go-package-tutorials](<https://devfeed.tech/tags/go-package-tutorials.md>), [go-software-architecture](<https://devfeed.tech/tags/go-software-architecture.md>), [go-software-tips](<https://devfeed.tech/tags/go-software-tips.md>), [intuitive-go-codebase](<https://devfeed.tech/tags/intuitive-go-codebase.md>), [maintainable-go-code](<https://devfeed.tech/tags/maintainable-go-code.md>), [rego](<https://devfeed.tech/tags/rego.md>), [rego-scripts-for-go](<https://devfeed.tech/tags/rego-scripts-for-go.md>), [role-based-authorization-in-go](<https://devfeed.tech/tags/role-based-authorization-in-go.md>), [scalable-go-software-design](<https://devfeed.tech/tags/scalable-go-software-design.md>), [secure-access-control-go](<https://devfeed.tech/tags/secure-access-control-go.md>), [software-design](<https://devfeed.tech/tags/software-design.md>), [user-claims-context-go](<https://devfeed.tech/tags/user-claims-context-go.md>)

### AI overview

This episode explains how to design Go packages that support role-based authorization with Rego, clearly separate exported and unexported APIs, manage errors consistently, and pass information through context between middleware and handlers.

### Source excerpt

Introduction: Welcome to Episode 9 of our Ultimate Software Design series! In this episode, Bill delves into the intricacies of implementing robust authorization and API structure within Go packages, offering invaluable insights for developers aiming to build scalable and maintainable software systems. Implement role-based authorization logic for secure and precise access control using Rego scripts. Learn best practices for structuring exported and unexported APIs to maintain a clean, intuitive, and maintainable codebase.

## Automatic source locations with Rego

DevFeed: [Automatic source locations with Rego](<https://devfeed.tech/articles/automatic-source-locations-with-rego-7835.md>)

Original publisher: [Read original article](<https://snyk.io/blog/automatic-source-locations-rego/>)

Author: Jasper Van der Jeugt

Published: 2024-02-12T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [opa](<https://devfeed.tech/topics/opa.md>), [snyk-iac](<https://devfeed.tech/topics/snyk-iac.md>), [Infrastructure as code](<https://devfeed.tech/topics/infrastructure-as-code.md>), [Open Policy Agent](<https://devfeed.tech/topics/open-policy-agent.md>), [AWS CloudFormation](<https://devfeed.tech/topics/aws-cloudformation.md>), [Terraform](<https://devfeed.tech/topics/terraform.md>)

Tags: [blog](<https://devfeed.tech/tags/blog.md>), [blog-post](<https://devfeed.tech/tags/blog-post.md>), [cloud-security](<https://devfeed.tech/tags/cloud-security.md>), [cloudformation](<https://devfeed.tech/tags/cloudformation.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [iac](<https://devfeed.tech/tags/iac.md>), [opa](<https://devfeed.tech/tags/opa.md>), [rego](<https://devfeed.tech/tags/rego.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-iac](<https://devfeed.tech/tags/snyk-iac.md>), [technical](<https://devfeed.tech/tags/technical.md>)

### AI overview

This technical Snyk article explains automatic source code locations for Rego policy violations in Snyk IaC. The feature reports accurate file, line, and column information, including for custom rules. A simplified proof of concept uses CloudFormation YAML, Rego policies, and YAML tree traversal to infer attribute paths and retrieve source locations.

### Source excerpt

We recently released a series of improvements to Snyk IaC, and in this blog post, we're taking a technical dive into a particularly interesting feature -- automatic source code locations for rule violations.

## Rego 103: Types of values and rules

DevFeed: [Rego 103: Types of values and rules](<https://devfeed.tech/articles/rego-103-types-of-values-and-rules-8061.md>)

Original publisher: [Read original article](<https://snyk.io/blog/rego-103-values-and-rules/>)

Author: Jasper Van der Jeugt; Becki Lee

Published: 2023-11-16T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [rego](<https://devfeed.tech/topics/rego.md>), [opa](<https://devfeed.tech/topics/opa.md>), [Open Policy Agent](<https://devfeed.tech/topics/open-policy-agent.md>), [Infrastructure as code](<https://devfeed.tech/topics/infrastructure-as-code.md>), [Programming](<https://devfeed.tech/topics/programming.md>)

Tags: [beginner](<https://devfeed.tech/tags/beginner.md>), [blog](<https://devfeed.tech/tags/blog.md>), [blog-post](<https://devfeed.tech/tags/blog-post.md>), [cloud-security](<https://devfeed.tech/tags/cloud-security.md>), [code](<https://devfeed.tech/tags/code.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [enablement](<https://devfeed.tech/tags/enablement.md>), [iac-security](<https://devfeed.tech/tags/iac-security.md>), [infrastructure-as-code](<https://devfeed.tech/tags/infrastructure-as-code.md>), [learn](<https://devfeed.tech/tags/learn.md>), [opa](<https://devfeed.tech/tags/opa.md>), [policy](<https://devfeed.tech/tags/policy.md>), [programming](<https://devfeed.tech/tags/programming.md>), [rego](<https://devfeed.tech/tags/rego.md>), [snyk-cloud](<https://devfeed.tech/tags/snyk-cloud.md>), [snyk-iac](<https://devfeed.tech/tags/snyk-iac.md>), [types](<https://devfeed.tech/tags/types.md>)

### AI overview

This beginner-focused article is the third part of a Rego introduction series. It explains scalar and composite value types, including strings, numbers, booleans, null, arrays, objects, and sets, and introduces set rules, object rules, functions, and iteration for writing policies evaluated by OPA.

### Source excerpt

Learn about the different types of Values and Rules you can use to build policies in OPA & Rego.

## Rego 102: Combining queries with AND/OR and custom messages

DevFeed: [Rego 102: Combining queries with AND/OR and custom messages](<https://devfeed.tech/articles/rego-102-combining-queries-with-and-or-and-custom-messages-8062.md>)

Original publisher: [Read original article](<https://snyk.io/blog/rego-for-beginners-part-2/>)

Author: Jasper Van der Jeugt; Becki Lee

Published: 2023-11-09T06:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [rego](<https://devfeed.tech/topics/rego.md>), [opa](<https://devfeed.tech/topics/opa.md>), [Programming](<https://devfeed.tech/topics/programming.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Infrastructure as code](<https://devfeed.tech/topics/infrastructure-as-code.md>), [JSON](<https://devfeed.tech/topics/json.md>), [YAML](<https://devfeed.tech/topics/yaml.md>)

Tags: [beginner](<https://devfeed.tech/tags/beginner.md>), [blog](<https://devfeed.tech/tags/blog.md>), [blog-post](<https://devfeed.tech/tags/blog-post.md>), [cloud-security](<https://devfeed.tech/tags/cloud-security.md>), [code](<https://devfeed.tech/tags/code.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [enablement](<https://devfeed.tech/tags/enablement.md>), [guide](<https://devfeed.tech/tags/guide.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [iac-security](<https://devfeed.tech/tags/iac-security.md>), [opa](<https://devfeed.tech/tags/opa.md>), [policy](<https://devfeed.tech/tags/policy.md>), [programming](<https://devfeed.tech/tags/programming.md>), [rego](<https://devfeed.tech/tags/rego.md>), [snyk-cloud](<https://devfeed.tech/tags/snyk-cloud.md>), [snyk-iac](<https://devfeed.tech/tags/snyk-iac.md>)

### AI overview

A beginner-focused guide to intermediate Rego syntax, explaining how to combine queries with AND and OR and introduce custom messages. It describes how OPA evaluates Rego policies against JSON or YAML input documents.

### Source excerpt

Learn how to use AND and OR rules and custom messages using OPA and Rego in the second part of our beginner's guide to Rego.

## Rego 101: Introduction to Rego

DevFeed: [Rego 101: Introduction to Rego](<https://devfeed.tech/articles/rego-101-introduction-to-rego-7987.md>)

Original publisher: [Read original article](<https://snyk.io/blog/introduction-to-rego/>)

Author: Becki Lee

Published: 2023-11-02T05:00:00Z

Content type: tutorial

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [rego](<https://devfeed.tech/topics/rego.md>), [opa](<https://devfeed.tech/topics/opa.md>), [Open Policy Agent](<https://devfeed.tech/topics/open-policy-agent.md>), [Infrastructure as code](<https://devfeed.tech/topics/infrastructure-as-code.md>), [Security](<https://devfeed.tech/topics/security.md>), [Programming](<https://devfeed.tech/topics/programming.md>)

Tags: [blog](<https://devfeed.tech/tags/blog.md>), [blog-post](<https://devfeed.tech/tags/blog-post.md>), [cloud-security](<https://devfeed.tech/tags/cloud-security.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [enablement](<https://devfeed.tech/tags/enablement.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [iac-security](<https://devfeed.tech/tags/iac-security.md>), [infrastructure-as-code](<https://devfeed.tech/tags/infrastructure-as-code.md>), [infrastructure-as-code-iac](<https://devfeed.tech/tags/infrastructure-as-code-iac.md>), [learn](<https://devfeed.tech/tags/learn.md>), [opa](<https://devfeed.tech/tags/opa.md>), [policy](<https://devfeed.tech/tags/policy.md>), [rego](<https://devfeed.tech/tags/rego.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-cloud](<https://devfeed.tech/tags/snyk-cloud.md>), [snyk-iac](<https://devfeed.tech/tags/snyk-iac.md>), [tutorial](<https://devfeed.tech/tags/tutorial.md>)

### AI overview

A beginner-focused introduction to Rego, the declarative policy language used with Open Policy Agent (OPA). It explains policy as code, how OPA evaluates Rego policies, and how these policies can be applied to cloud and infrastructure-as-code resources.

### Source excerpt

Learn how to write your first policy as code rules in Rego. This Rego tutorial for beginners covers the basics of Rego syntax and using OPA.

## Conquering your Build Horizon

DevFeed: [Conquering your Build Horizon](<https://devfeed.tech/articles/conquering-your-build-horizon-13012.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/conquering-your-build-horizon>)

Published: 2023-10-10T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Automation](<https://devfeed.tech/topics/automation.md>), [rego](<https://devfeed.tech/topics/rego.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [GitHub Copilot](<https://devfeed.tech/topics/github-copilot.md>)

Tags: [architecture](<https://devfeed.tech/tags/architecture.md>), [automation](<https://devfeed.tech/tags/automation.md>), [base-images](<https://devfeed.tech/tags/base-images.md>), [build-horizon](<https://devfeed.tech/tags/build-horizon.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [config](<https://devfeed.tech/tags/config.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [defense-in-depth](<https://devfeed.tech/tags/defense-in-depth.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [github-action](<https://devfeed.tech/tags/github-action.md>), [rego](<https://devfeed.tech/tags/rego.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

The article presents Build Horizon, a policy that limits how long build artifacts such as binaries and container images may remain in production before being rebuilt. It explains how freshness controls, dependency automation, and policy checks can reduce risks from outdated software and long-lived builds.

### Source excerpt

"Build Horizon" is a practice that imposes a maximum age on build artifacts. Learn more about how it works and see an example in action!

## Chainguard open sources new policy catalog for Sigstore policy-controller

DevFeed: [Chainguard open sources new policy catalog for Sigstore policy-controller](<https://devfeed.tech/articles/chainguard-open-sources-new-policy-catalog-for-sigstore-policy-controller-12974.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-open-sources-new-policy-catalog-for-sigstore-policy-controller>)

Published: 2023-04-18T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [sigstore policy controller](<https://devfeed.tech/topics/sigstore-policy-controller.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [rego](<https://devfeed.tech/topics/rego.md>), [YAML](<https://devfeed.tech/topics/yaml.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kubernetes-security](<https://devfeed.tech/tags/kubernetes-security.md>), [rego](<https://devfeed.tech/tags/rego.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [sigstore-policy-controller](<https://devfeed.tech/tags/sigstore-policy-controller.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [trust](<https://devfeed.tech/tags/trust.md>), [verification](<https://devfeed.tech/tags/verification.md>), [yaml](<https://devfeed.tech/tags/yaml.md>)

### AI overview

Chainguard open sources a policy catalog for Sigstore policy-controller. The catalog provides policies that organizations and open source projects can adopt incrementally to improve software supply-chain security, with community contributions supported.

### Source excerpt

To help unlock benefits of the Sigstore policy-controller, Chainguard open sources a policy catalog that can be adopted to improve your supply chain security.