# Open Policy Agent

Open Policy Agent is a general-purpose policy engine that unifies policy enforcement across applications, proxies, Kubernetes, CI/CD pipelines, and API gateways.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## How to attach an owner to every cloud resource you find

DevFeed: [How to attach an owner to every cloud resource you find](<https://devfeed.tech/articles/how-to-attach-an-owner-to-every-cloud-resource-you-find-26946.md>)

Original publisher: [Read original article](<https://thenewstack.io/attach-owner-cloud-resources/>)

Author: Zeen Rachidi

Published: 2026-09-15T14:00:00Z

Content type: tutorial

Language: en

Sources: [The New Stack](<https://devfeed.tech/sources/the-new-stack.md>)

Topics: [Cloud](<https://devfeed.tech/topics/cloud.md>), [Provisioning](<https://devfeed.tech/topics/provisioning.md>), [Open Policy Agent](<https://devfeed.tech/topics/open-policy-agent.md>), [audit trail](<https://devfeed.tech/topics/audit-trail.md>)

Tags: [audit-trail](<https://devfeed.tech/tags/audit-trail.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-services](<https://devfeed.tech/tags/cloud-services.md>), [devops](<https://devfeed.tech/tags/devops.md>), [env-zero](<https://devfeed.tech/tags/env-zero.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [logs](<https://devfeed.tech/tags/logs.md>), [open-policy-agent](<https://devfeed.tech/tags/open-policy-agent.md>), [platform-engineering](<https://devfeed.tech/tags/platform-engineering.md>), [policy](<https://devfeed.tech/tags/policy.md>), [post-contributed](<https://devfeed.tech/tags/post-contributed.md>), [provisioning](<https://devfeed.tech/tags/provisioning.md>), [sponsor-env-zero](<https://devfeed.tech/tags/sponsor-env-zero.md>), [sponsored-post-contributed](<https://devfeed.tech/tags/sponsored-post-contributed.md>)

### AI overview

This tutorial explains how to identify cloud resources without assigned owners and prevent new ownerless resources. It presents continuously synced inventory queries, Open Policy Agent policies requiring owner tags, and logs or audit trails for resource governance.

### Source excerpt

The engineer who knew why that cloud instance existed has left the company. The instance is still running, the bill The post How to attach an owner to every cloud resource you find appeared first on The New Stack.

## Policy as Code in 2026: OPA, Kyverno, Cedar and What's Next

DevFeed: [Policy as Code in 2026: OPA, Kyverno, Cedar and What's Next](<https://devfeed.tech/articles/policy-as-code-in-2026-opa-kyverno-cedar-and-what-s-next-26775.md>)

Original publisher: [Read original article](<https://www.harness.io/blog/policy-as-code-in-2026-opa-kyverno-cedar-and-what-s-next>)

Author: Abhijit Pujare Eric Minick

Published: 2026-09-11T00:00:00Z

Content type: article

Language: en

Sources: [Harness Blog](<https://devfeed.tech/sources/harness-blog.md>)

Topics: [policy-as-code](<https://devfeed.tech/topics/policy-as-code.md>), [Open Policy Agent](<https://devfeed.tech/topics/open-policy-agent.md>), [rego](<https://devfeed.tech/topics/rego.md>), [Kyverno](<https://devfeed.tech/topics/kyverno.md>), [Software Engineering](<https://devfeed.tech/topics/software-engineering.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [JSON](<https://devfeed.tech/topics/json.md>), [YAML](<https://devfeed.tech/topics/yaml.md>), [AI Agent](<https://devfeed.tech/topics/ai-agent.md>)

Tags: [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [json](<https://devfeed.tech/tags/json.md>), [kyverno](<https://devfeed.tech/tags/kyverno.md>), [opa](<https://devfeed.tech/tags/opa.md>), [open-policy-agent](<https://devfeed.tech/tags/open-policy-agent.md>), [policies](<https://devfeed.tech/tags/policies.md>), [policy-as-code](<https://devfeed.tech/tags/policy-as-code.md>), [rego](<https://devfeed.tech/tags/rego.md>), [security](<https://devfeed.tech/tags/security.md>), [software-engineering](<https://devfeed.tech/tags/software-engineering.md>), [yaml](<https://devfeed.tech/tags/yaml.md>)

### AI overview

This article surveys the 2026 Policy as Code ecosystem, comparing general-purpose Open Policy Agent and Rego with specialized approaches such as Kyverno, Cedar, and agent-oriented governance. It discusses the shift toward automated, machine-readable governance, the separation of policy from business logic, and the challenges of authoring and maintaining Rego as schemas evolve.

### Source excerpt

| Blog

## Optimizing OPA performance: From arrays to objects

DevFeed: [Optimizing OPA performance: From arrays to objects](<https://devfeed.tech/articles/optimizing-opa-performance-from-arrays-to-objects-22577.md>)

Original publisher: [Read original article](<https://medium.com/capital-one-tech/optimizing-opa-performance-from-arrays-to-objects-a3c966acdaa5?source=rss----3db3a67cb648---4>)

Author: Capital One Tech

Published: 2026-07-07T14:25:30Z

Content type: tutorial

Language: en

Sources: [Capital One Tech](<https://devfeed.tech/sources/capital-one-tech.md>)

Topics: [opa](<https://devfeed.tech/topics/opa.md>), [Open Policy Agent](<https://devfeed.tech/topics/open-policy-agent.md>), [rego](<https://devfeed.tech/topics/rego.md>), [Data structures](<https://devfeed.tech/topics/data-structures.md>), [Optimization](<https://devfeed.tech/topics/optimization.md>), [Algorithms, Complexity](<https://devfeed.tech/topics/algorithms-complexity.md>)

Tags: [algorithms](<https://devfeed.tech/tags/algorithms.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [data-structures](<https://devfeed.tech/tags/data-structures.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [opa](<https://devfeed.tech/tags/opa.md>), [open-policy-agent](<https://devfeed.tech/tags/open-policy-agent.md>), [optimization](<https://devfeed.tech/tags/optimization.md>), [performance-tuning](<https://devfeed.tech/tags/performance-tuning.md>), [rego](<https://devfeed.tech/tags/rego.md>), [software-development](<https://devfeed.tech/tags/software-development.md>), [software-engineering](<https://devfeed.tech/tags/software-engineering.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>)

### AI overview

This article explains how to improve Open Policy Agent performance by choosing appropriate data structures for Rego policies. It focuses on replacing nested arrays with keyed objects to avoid inefficient array traversal when evaluating large datasets.

### Source excerpt

Achieve 99% faster Rego policy execution through optimization. Note: This post focuses on one aspect of performance tuning Rego policies and datasets evaluated by OPA-arrays vs. objects. The Rego Style Guide and Regal Rego linter are very helpful resources for learning Rego best practices and avoiding code smells in Rego policies. There is also the OPA performance tuning documentation. In 2018, I started using open policy agent (OPA) as a solution for controlling and preventing unwanted behaviors in our Kubernetes Clusters. OPA, along with Kubernetes Dynamic Admission Control, provided a means to build preventive controls. Since then, I have worked with several PaC solutions. I have always stayed close to the OPA tool set because of how well it supports multiple use cases. OPA is domain agnostic and can be used with virtually any use case, as long as you supply the correct data and policies. To that end, OPA use cases have expanded throughout several technical disciplines, such as cloud-native computing and software supply chain management. OPA performance engineering OPA enables us to unify PaC solutions across multiple use cases and systems, using the same languages and tools. However, there is always room for improvement and performance engineering policies and the execution thereof. In addition, optimizing data that policies evaluate and mutate should be part of our focus when we deliver OPA-based solutions. Recently I was asked to help with OPA performance issues. I made several recommendations, but I overlooked one simple and glaring issue: the poor performing policy was processing a large data set using nested-arrays, instead of the best practice of using keyed-objects. Later, something was bothering me about my interaction and I realized that while I gave decent architectural level advice, I completely missed the best engineering advice. Rego policies and data should be optimized just like other algorithms and relative data, and part of that optimization is

## Secure DevSecOps: Evaluating OPA Policies Local to Your Data

DevFeed: [Secure DevSecOps: Evaluating OPA Policies Local to Your Data](<https://devfeed.tech/articles/secure-devsecops-evaluating-opa-policies-local-to-your-data-13366.md>)

Original publisher: [Read original article](<https://www.harness.io/blog/announcing-opa-policy-evaluation-on-your-own-infrastructure>)

Author: Abhijit Pujare Rishabh Gupta

Published: 2026-06-09T00:00:00Z

Content type: release

Language: en

Sources: [Harness Blog](<https://devfeed.tech/sources/harness-blog.md>)

Topics: [Open Policy Agent](<https://devfeed.tech/topics/open-policy-agent.md>), [DevSecOps](<https://devfeed.tech/topics/devsecops.md>), [Security](<https://devfeed.tech/topics/security.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>)

Tags: [devsecops](<https://devfeed.tech/tags/devsecops.md>), [firewalls](<https://devfeed.tech/tags/firewalls.md>), [harness](<https://devfeed.tech/tags/harness.md>), [open-policy-agent](<https://devfeed.tech/tags/open-policy-agent.md>), [security](<https://devfeed.tech/tags/security.md>), [shift-left](<https://devfeed.tech/tags/shift-left.md>)

### AI overview

Harness announces local evaluation of Open Policy Agent policies on Kubernetes infrastructure. The capability is intended to let policies access internal systems and keep API tokens, certificates, and passwords within corporate security and data-residency boundaries.

### Source excerpt

Harness solves the firewall dilemma for OPA. Shift-left governance-as-code while keeping API tokens and internal systems secure within your local perimeter. | Blog

## Security Benchmarking Authorization Policy Engines: Rego, Cedar, OpenFGA & Teleport ACD

DevFeed: [Security Benchmarking Authorization Policy Engines: Rego, Cedar, OpenFGA & Teleport ACD](<https://devfeed.tech/articles/security-benchmarking-authorization-policy-engines-rego-cedar-openfga-teleport-acd-29590.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/benchmarking-policy-languages/>)

Author: info@goteleport.com (Mohamed Ouad, Doyensec)

Published: 2025-06-04T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [benchmarking](<https://devfeed.tech/topics/benchmarking.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Security](<https://devfeed.tech/topics/security.md>), [rego](<https://devfeed.tech/topics/rego.md>), [Open Policy Agent](<https://devfeed.tech/topics/open-policy-agent.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [authorization](<https://devfeed.tech/tags/authorization.md>), [benchmarking](<https://devfeed.tech/tags/benchmarking.md>), [opa](<https://devfeed.tech/tags/opa.md>), [open-policy-agent](<https://devfeed.tech/tags/open-policy-agent.md>), [performance](<https://devfeed.tech/tags/performance.md>), [rego](<https://devfeed.tech/tags/rego.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article introduces the Security Policy Evaluation Framework (SPEF), an automated testing and benchmarking system for evaluating authorization policy engines. It describes how SPEF assesses robustness, correctness, and performance across Rego, Cedar, OpenFGA, and Teleport ACD.

### Source excerpt

Explore how the Security Policy Evaluation Framework (SPEF) benchmarks Rego, Cedar, OpenFGA, and Teleport ACD for vulnerabilities, correctness, and performance.

## Kube-Policies: Guardrails for Apps Running in Kubernetes

DevFeed: [Kube-Policies: Guardrails for Apps Running in Kubernetes](<https://devfeed.tech/articles/kube-policies-guardrails-for-apps-running-in-kubernetes-15739.md>)

Original publisher: [Read original article](<https://developer.squareup.com/blog/kube-policies-guardrails-for-apps-running-in-kubernetes>)

Author: Hardik Darji

Published: 2025-01-28T08:00:00Z

Content type: article

Language: en

Sources: [Square Corner Blog RSS Feed](<https://devfeed.tech/sources/square-corner-blog-rss-feed.md>)

Topics: [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [cloud security](<https://devfeed.tech/topics/cloud-security.md>), [Open Policy Agent](<https://devfeed.tech/topics/open-policy-agent.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [SIEM, Security, Observability](<https://devfeed.tech/topics/siem-security-observability.md>)

Tags: [admission-controller](<https://devfeed.tech/tags/admission-controller.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [observability](<https://devfeed.tech/tags/observability.md>), [open-policy-agent](<https://devfeed.tech/tags/open-policy-agent.md>), [security](<https://devfeed.tech/tags/security.md>), [security-policies](<https://devfeed.tech/tags/security-policies.md>), [testing](<https://devfeed.tech/tags/testing.md>)

### AI overview

This article introduces Square's design considerations for security guardrails in Kubernetes environments. It explains why default Kubernetes configurations can leave applications vulnerable and describes requirements for an abstraction layer built on Open Policy Agent, including policy dry-runs, minimal user disruption, testing, exception management, extensibility, and observability.

### Source excerpt

Design considerations for highly sensitive environments.

## Ep. 8: Enhancing Go Application Security with JWT and OPA

DevFeed: [Ep. 8: Enhancing Go Application Security with JWT and OPA](<https://devfeed.tech/articles/ep-8-enhancing-go-application-security-with-jwt-and-opa-22249.md>)

Original publisher: [Read original article](<https://www.ardanlabs.com/blog/2024/07/enhancing-go-application-security-with-jwt-and-opa-ep-8.html>)

Published: 2024-07-02T00:00:00Z

Content type: tutorial

Language: en

Sources: [William Kennedy](<https://devfeed.tech/sources/william-kennedy.md>)

Topics: [Go Language](<https://devfeed.tech/topics/go-language.md>), [Security](<https://devfeed.tech/topics/security.md>), [JSON Web Tokens](<https://devfeed.tech/topics/jwt.md>), [Open Policy Agent](<https://devfeed.tech/topics/open-policy-agent.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>)

Tags: [access-control-policies-go](<https://devfeed.tech/tags/access-control-policies-go.md>), [advanced-go-security-tools](<https://devfeed.tech/tags/advanced-go-security-tools.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [authentication-vs-authorization](<https://devfeed.tech/tags/authentication-vs-authorization.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [comprehensive-security-framework-go](<https://devfeed.tech/tags/comprehensive-security-framework-go.md>), [dynamic-authorization-rules](<https://devfeed.tech/tags/dynamic-authorization-rules.md>), [embedding-opa-scripts-go](<https://devfeed.tech/tags/embedding-opa-scripts-go.md>), [external-service-opa](<https://devfeed.tech/tags/external-service-opa.md>), [flexible-authorization-go](<https://devfeed.tech/tags/flexible-authorization-go.md>), [go](<https://devfeed.tech/tags/go.md>), [go-application-security](<https://devfeed.tech/tags/go-application-security.md>), [go-application-security-guide](<https://devfeed.tech/tags/go-application-security-guide.md>), [go-authentication](<https://devfeed.tech/tags/go-authentication.md>), [go-authorization](<https://devfeed.tech/tags/go-authorization.md>), [go-developer-security](<https://devfeed.tech/tags/go-developer-security.md>), [go-security-best-practices](<https://devfeed.tech/tags/go-security-best-practices.md>), [go-security-frameworks](<https://devfeed.tech/tags/go-security-frameworks.md>), [go-token-expiration-management](<https://devfeed.tech/tags/go-token-expiration-management.md>), [implementing-jwt-go](<https://devfeed.tech/tags/implementing-jwt-go.md>), [jwt](<https://devfeed.tech/tags/jwt.md>), [jwt-private-key-signing](<https://devfeed.tech/tags/jwt-private-key-signing.md>), [jwt-token-generation](<https://devfeed.tech/tags/jwt-token-generation.md>), [jwt-validation-go](<https://devfeed.tech/tags/jwt-validation-go.md>), [opa](<https://devfeed.tech/tags/opa.md>), [opa-go-tutorial](<https://devfeed.tech/tags/opa-go-tutorial.md>), [open-policy-agent-go](<https://devfeed.tech/tags/open-policy-agent-go.md>), [public-key-verification-jwt-go](<https://devfeed.tech/tags/public-key-verification-jwt-go.md>), [reliable-authentication-go](<https://devfeed.tech/tags/reliable-authentication-go.md>), [robust-go-authentication](<https://devfeed.tech/tags/robust-go-authentication.md>), [scalable-security-go](<https://devfeed.tech/tags/scalable-security-go.md>), [secure-go-applications](<https://devfeed.tech/tags/secure-go-applications.md>), [secure-token-management](<https://devfeed.tech/tags/secure-token-management.md>), [security](<https://devfeed.tech/tags/security.md>), [updating-access-control-policies-go](<https://devfeed.tech/tags/updating-access-control-policies-go.md>), [verifying-user-identity-go](<https://devfeed.tech/tags/verifying-user-identity-go.md>)

### AI overview

This episode explains authentication and authorization for Go applications, including JWT generation, signing, validation, and expiration management. It also introduces Open Policy Agent for managing dynamic authorization rules separately from application code.

### Source excerpt

Introduction: In this segment, Bill delves into the fundamental aspects of authentication and authorization, equipping Go developers with essential knowledge and advanced tools to enhance the security of their applications. Through practical examples and detailed explanations, he unpacks the intricacies of these concepts, demonstrating their crucial role in protecting and managing access to your software systems. Learn the distinct roles of verifying user identity and determining access levels. Discover how to use JWTs for secure token generation, validation, and expiration management.

## Automatic source locations with Rego

DevFeed: [Automatic source locations with Rego](<https://devfeed.tech/articles/automatic-source-locations-with-rego-7835.md>)

Original publisher: [Read original article](<https://snyk.io/blog/automatic-source-locations-rego/>)

Author: Jasper Van der Jeugt

Published: 2024-02-12T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [opa](<https://devfeed.tech/topics/opa.md>), [snyk-iac](<https://devfeed.tech/topics/snyk-iac.md>), [Infrastructure as code](<https://devfeed.tech/topics/infrastructure-as-code.md>), [Open Policy Agent](<https://devfeed.tech/topics/open-policy-agent.md>), [AWS CloudFormation](<https://devfeed.tech/topics/aws-cloudformation.md>), [Terraform](<https://devfeed.tech/topics/terraform.md>)

Tags: [blog](<https://devfeed.tech/tags/blog.md>), [blog-post](<https://devfeed.tech/tags/blog-post.md>), [cloud-security](<https://devfeed.tech/tags/cloud-security.md>), [cloudformation](<https://devfeed.tech/tags/cloudformation.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [iac](<https://devfeed.tech/tags/iac.md>), [opa](<https://devfeed.tech/tags/opa.md>), [rego](<https://devfeed.tech/tags/rego.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-iac](<https://devfeed.tech/tags/snyk-iac.md>), [technical](<https://devfeed.tech/tags/technical.md>)

### AI overview

This technical Snyk article explains automatic source code locations for Rego policy violations in Snyk IaC. The feature reports accurate file, line, and column information, including for custom rules. A simplified proof of concept uses CloudFormation YAML, Rego policies, and YAML tree traversal to infer attribute paths and retrieve source locations.

### Source excerpt

We recently released a series of improvements to Snyk IaC, and in this blog post, we're taking a technical dive into a particularly interesting feature -- automatic source code locations for rule violations.

## Open Policy Agent for Trino arrived

DevFeed: [Open Policy Agent for Trino arrived](<https://devfeed.tech/articles/open-policy-agent-for-trino-arrived-8748.md>)

Original publisher: [Read original article](<https://trino.io/blog/2024/02/06/opa-arrived.html>)

Author: Manfred Moser

Published: 2024-02-06T00:00:00Z

Content type: article

Language: en

Sources: [Trino Blog](<https://devfeed.tech/sources/trino-blog.md>)

Topics: [Open Policy Agent](<https://devfeed.tech/topics/open-policy-agent.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Pull Request](<https://devfeed.tech/topics/pull-request.md>), [Code review](<https://devfeed.tech/topics/code-review.md>), [migration](<https://devfeed.tech/topics/migration.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [migration](<https://devfeed.tech/tags/migration.md>), [opa](<https://devfeed.tech/tags/opa.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [policy](<https://devfeed.tech/tags/policy.md>), [pull-request](<https://devfeed.tech/tags/pull-request.md>), [review](<https://devfeed.tech/tags/review.md>)

### AI overview

Trino 438 introduces an access control integration with Open Policy Agent (OPA). The article recounts the collaboration that brought the integration to Trino, its presentation at Trino Summit 2023, migration from Apache Ranger, and demonstrations of OPA across data platforms.

### Source excerpt

Trino now ships with an access control integration using the popular and widely used Open Policy Agent (OPA) from the Cloud Native Computing Foundation. The release of Trino 438 marks an important milestone of the effort towards this integration.

## Rego 103: Types of values and rules

DevFeed: [Rego 103: Types of values and rules](<https://devfeed.tech/articles/rego-103-types-of-values-and-rules-8061.md>)

Original publisher: [Read original article](<https://snyk.io/blog/rego-103-values-and-rules/>)

Author: Jasper Van der Jeugt; Becki Lee

Published: 2023-11-16T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [rego](<https://devfeed.tech/topics/rego.md>), [opa](<https://devfeed.tech/topics/opa.md>), [Open Policy Agent](<https://devfeed.tech/topics/open-policy-agent.md>), [Infrastructure as code](<https://devfeed.tech/topics/infrastructure-as-code.md>), [Programming](<https://devfeed.tech/topics/programming.md>)

Tags: [beginner](<https://devfeed.tech/tags/beginner.md>), [blog](<https://devfeed.tech/tags/blog.md>), [blog-post](<https://devfeed.tech/tags/blog-post.md>), [cloud-security](<https://devfeed.tech/tags/cloud-security.md>), [code](<https://devfeed.tech/tags/code.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [enablement](<https://devfeed.tech/tags/enablement.md>), [iac-security](<https://devfeed.tech/tags/iac-security.md>), [infrastructure-as-code](<https://devfeed.tech/tags/infrastructure-as-code.md>), [learn](<https://devfeed.tech/tags/learn.md>), [opa](<https://devfeed.tech/tags/opa.md>), [policy](<https://devfeed.tech/tags/policy.md>), [programming](<https://devfeed.tech/tags/programming.md>), [rego](<https://devfeed.tech/tags/rego.md>), [snyk-cloud](<https://devfeed.tech/tags/snyk-cloud.md>), [snyk-iac](<https://devfeed.tech/tags/snyk-iac.md>), [types](<https://devfeed.tech/tags/types.md>)

### AI overview

This beginner-focused article is the third part of a Rego introduction series. It explains scalar and composite value types, including strings, numbers, booleans, null, arrays, objects, and sets, and introduces set rules, object rules, functions, and iteration for writing policies evaluated by OPA.

### Source excerpt

Learn about the different types of Values and Rules you can use to build policies in OPA & Rego.

## Rego 101: Introduction to Rego

DevFeed: [Rego 101: Introduction to Rego](<https://devfeed.tech/articles/rego-101-introduction-to-rego-7987.md>)

Original publisher: [Read original article](<https://snyk.io/blog/introduction-to-rego/>)

Author: Becki Lee

Published: 2023-11-02T05:00:00Z

Content type: tutorial

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [rego](<https://devfeed.tech/topics/rego.md>), [opa](<https://devfeed.tech/topics/opa.md>), [Open Policy Agent](<https://devfeed.tech/topics/open-policy-agent.md>), [Infrastructure as code](<https://devfeed.tech/topics/infrastructure-as-code.md>), [Security](<https://devfeed.tech/topics/security.md>), [Programming](<https://devfeed.tech/topics/programming.md>)

Tags: [blog](<https://devfeed.tech/tags/blog.md>), [blog-post](<https://devfeed.tech/tags/blog-post.md>), [cloud-security](<https://devfeed.tech/tags/cloud-security.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [enablement](<https://devfeed.tech/tags/enablement.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [iac-security](<https://devfeed.tech/tags/iac-security.md>), [infrastructure-as-code](<https://devfeed.tech/tags/infrastructure-as-code.md>), [infrastructure-as-code-iac](<https://devfeed.tech/tags/infrastructure-as-code-iac.md>), [learn](<https://devfeed.tech/tags/learn.md>), [opa](<https://devfeed.tech/tags/opa.md>), [policy](<https://devfeed.tech/tags/policy.md>), [rego](<https://devfeed.tech/tags/rego.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-cloud](<https://devfeed.tech/tags/snyk-cloud.md>), [snyk-iac](<https://devfeed.tech/tags/snyk-iac.md>), [tutorial](<https://devfeed.tech/tags/tutorial.md>)

### AI overview

A beginner-focused introduction to Rego, the declarative policy language used with Open Policy Agent (OPA). It explains policy as code, how OPA evaluates Rego policies, and how these policies can be applied to cloud and infrastructure-as-code resources.

### Source excerpt

Learn how to write your first policy as code rules in Rego. This Rego tutorial for beginners covers the basics of Rego syntax and using OPA.

## Enforcing Policies with Gatekeeper in Kubernetes

DevFeed: [Enforcing Policies with Gatekeeper in Kubernetes](<https://devfeed.tech/articles/enforcing-policies-with-gatekeeper-in-kubernetes-17693.md>)

Original publisher: [Read original article](<https://blog.container-solutions.com/enforcing-policies-with-gatekeeper-in-kubernetes>)

Author: Cameron Wood, Elieser Pereira, Rodrigo Martinez

Published: 2022-06-30T13:34:38Z

Content type: tutorial

Language: en

Sources: [Blog - Container Solutions](<https://devfeed.tech/sources/blog-container-solutions.md>)

Topics: [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Policy Agent](<https://devfeed.tech/topics/open-policy-agent.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>)

Tags: [best-practices](<https://devfeed.tech/tags/best-practices.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [open-policy-agent](<https://devfeed.tech/tags/open-policy-agent.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [policy](<https://devfeed.tech/tags/policy.md>), [security](<https://devfeed.tech/tags/security.md>), [security-policies](<https://devfeed.tech/tags/security-policies.md>), [wtf-is-cloud-native](<https://devfeed.tech/tags/wtf-is-cloud-native.md>)

### AI overview

This tutorial explains how Gatekeeper works with Kubernetes RBAC to enforce authorization rules and pod security policies. It presents Gatekeeper, based on Open Policy Agent, as a way to add deny rules, protect namespaces, and replace deprecated Pod Security Policies.

### Source excerpt

When managing Kubernetes clusters, cluster administrators need to ensure the overall stability of the system. To accomplish this it is necessary to avoid disruptions to the control plane, and also avoid any risks of users being able to escalate their privileges thus causing further problems. With this in mind, protecting the kube-system namespace and enforcing pod security policies to run payloads with just the necessary access is a must.