Show HN: Open Policy Registry: a Docker-inspired workflow for OPA policies
openpolicyregistry.io
openpolicyregistry.io
We created the policy CLI [2] to replicate the docker workflow for OPA policies, and the open policy registry [3] as a place where the OPA community can store and share policy images.
[1] https://www.openpolicyagent.org
There is currently a lot of special casing required, as the OCI spec laying out the Registry API and interactions are not very rich. This limits usability and performance.
But we certainly are going to add support for ohters, ghcr.io, acr etc.
Step two is to make OPA natively understand and support OCI images.
Next step would be special image types, and multi layering. For example I would love it if we have separate layers for rego, wasm, and data.json, as the data often needs to eleve independent of the rego and wasm code.