Opa – An open-source, general-purpose policy engine
github.com
github.com
I'm really curious to hear if it was in any way informed or inspired by other logic programming systems, and/or what some of the more challenging aspects were of implementing a predicate logic system like this in Golang.
I don't think that Golang introduces any unique challenges for implementing a logic system, just the usual suspects like garbage collection, lack of generics, etc.
Hope this helps.
Also, are there any theoretical limits to how much data could be loaded in to OPA?
1. You can include JSON data as input when you execute a policy query. In your example, you could include the management hierarchy or a user in a JWT that's provided as input to the policy query.
2. You can load JSON data into OPA out-of-band. OPA will cache this data in-memory and you can refer to it in your policies. There are two ways to do this. (a) use OPA's REST API to push data into the engine (e.g., PUT /v1/data/management/hierarchy <JSON body>) or (b) use OPA's Bundle feature to pull down bundles of policy and data from a remote endpoint.
3. If providing the data as input or out-of-band will not work, we have an experimental HTTP built-in function that you can call inside your policies to query the external data source on-the-fly when the policy is evaluated. This feature is still experimental but over time we intend to improve support for it (e.g., currently you can't mock out these built-in calls, but it's on the ROADMAP.)
Regarding limits, OPA keeps policies and data in-memory, so you're limited by RAM on a single host.
To someone who doesn't already know what a "policy engine" is, that intro is completely meaningless. Might want to at least move a tiny blurb from the later doc to that opening paragraph.
Technically asking a question about the authors is a project question, so I'm not sure why I got downvoted :/.
XACML as a specification covers multiple things (e.g., access control language, overall architecture, etc.) If you wanted to map OPA to a component in XACML, it's closest to the PDP.
That being said, OPA gives you a more expressive language to author policy. Also, OPA is intended to be used as building block in other systems. OPA exposes APIs to offload policy decisions from services and manage the policies and data that are evaluated. One of the non-goals of OPA is management-plane concerns around policy storage, policy administration, etc.
does it enable HATEOAS?
tks
1. what movies are available to my region 2. is this profile allowed to watch a certain movie? 3. can i view my account settings?
may be a good fit, but just wanted to be sure. another area may be in gaming, where new functions such as: 1. am i allowed to access this weapon 2. am i allowed to be on this terrain map 3. who my team members are
may pop up.
I have some application use cases that are very similar along these lines, so I'd like to know more about this before going in deeper to evaluate OPA.
that being said, all looks positive and i thank you for the good work you have done, specially open sourcing it to make it available.
s/u/oo/g