---
tags:
- security
- l1
- flashcard-deck
- open-policy-agent
---
<!-- wiki:breadcrumb:start -->
[Portal](../../../../library/portal/index.md) | **Level:** [L1: Foundations](../../../../library/portal/levels.md) | **Topics:** [Open Policy Agent](../../../../library/portal/topics.md) | **Domain:** Security
<!-- wiki:breadcrumb:end -->

id	category	difficulty	tags	question	answer	source_path
open-policy-agent/c5cb552ac16c	open-policy-agent	easy	opa, rego, fundamentals	What is Open Policy Agent (OPA)?	OPA is a general-purpose, open-source policy engine that decouples policy from application code. Applications query OPA over HTTP, passing structured JSON input; OPA evaluates the query against loaded Rego policies and returns a decision.\n\nRemember: OPA = general-purpose policy engine. Decouples policy from code.\n\nFun fact: CNCF graduated. Uses Rego ("ray-go") language.	training/library/topics/open-policy-agent/primer.md
open-policy-agent/ecdfed21a173	open-policy-agent	easy	opa, rego, fundamentals	What language is used to write OPA policies?	Rego — a declarative query language purpose-built for policy. Rego is not imperative; you define what is true and OPA derives all consequences. Policy rules are evaluated simultaneously, not sequentially.\n\nRemember: OPA = general-purpose policy engine. Decouples policy from code.\n\nFun fact: CNCF graduated. Uses Rego ("ray-go") language.	training/library/topics/open-policy-agent/primer.md
open-policy-agent/1b0145f43811	open-policy-agent	easy	opa, rego, fundamentals	What are the two JSON documents available inside a Rego policy at evaluation time?	`input` — the structured query document sent by the calling application; `data` — background data loaded into OPA (allow-lists, user directories, configuration). Policy rules can reference both.\n\nRemember: Rego = declarative policy language. Rules return true/false or sets/objects.\n\nExample: `deny[msg] { input.kind=="Pod"; not input.spec.securityContext.runAsNonRoot; msg:="No root" }`	training/library/topics/open-policy-agent/primer.md
open-policy-agent/5ff0176277db	open-policy-agent	easy	opa, deployment	What are the three deployment patterns for OPA?	Sidecar (runs alongside each service in the same pod — low latency, localhost calls), centralized service (shared OPA cluster — easier to manage, network hop required), and library/embedded (OPA SDK or WASM compiled in-process — no network dependency).\n\nRemember: OPA = general-purpose policy engine. Decouples policy from code.\n\nFun fact: CNCF graduated. Uses Rego ("ray-go") language.	training/library/topics/open-policy-agent/primer.md
open-policy-agent/17d24b2d3be2	open-policy-agent	easy	opa, rego, rules	In Rego, what happens when multiple rule bodies share the same rule name (e.g., multiple `allow` blocks)?	They are implicitly OR'd — if any single rule body evaluates to true, the overall rule is true. All conditions inside a single body are AND'd.\n\nRemember: Rego = declarative policy language. Rules return true/false or sets/objects.\n\nExample: `deny[msg] { input.kind=="Pod"; not input.spec.securityContext.runAsNonRoot; msg:="No root" }`	training/library/topics/open-policy-agent/primer.md
open-policy-agent/f514f46c047e	open-policy-agent	easy	opa, testing	What naming convention does OPA use to identify test rules?	Test rules must have names starting with `test_`. OPA's built-in test runner (`opa test`) discovers and runs all rules matching this prefix, reporting pass/fail per rule.\n\nRemember: OPA = general-purpose policy engine. Decouples policy from code.\n\nFun fact: CNCF graduated. Uses Rego ("ray-go") language.	training/library/topics/open-policy-agent/primer.md
open-policy-agent/9f3180e3d4b6	open-policy-agent	easy	opa, cli	What command runs all OPA unit tests in a directory?	`opa test ./policies/` — runs all test rules (prefixed `test_`) found recursively. Add `-v` for verbose output showing individual test names and results.\n\nRemember: OPA = general-purpose policy engine. Decouples policy from code.\n\nFun fact: CNCF graduated. Uses Rego ("ray-go") language.	training/library/topics/open-policy-agent/street_ops.md
open-policy-agent/21d5fa081da4	open-policy-agent	easy	opa, gatekeeper, kubernetes	What are the two Kubernetes CRD types introduced by OPA Gatekeeper?	`ConstraintTemplate` — defines a new constraint kind and embeds the Rego logic; `Constraint` — an instance of a ConstraintTemplate that specifies parameters and the scope of resources to apply it to.\n\nRemember: OPA = general-purpose policy engine. Decouples policy from code.\n\nFun fact: CNCF graduated. Uses Rego ("ray-go") language.	training/library/topics/open-policy-agent/primer.md
open-policy-agent/894343756e9b	open-policy-agent	easy	opa, conftest	What is Conftest and what is it used for?	Conftest is a CLI tool that wraps OPA for testing configuration files (Kubernetes manifests, Terraform plans, Dockerfiles, HCL). Write Rego policies in a `policy/` directory and run `conftest test <file>` to validate configs in CI without an OPA server.\n\nRemember: Conftest = OPA/Rego for config files. Dockerfile, K8s YAML, Terraform. CI checks.	training/library/topics/open-policy-agent/primer.md
open-policy-agent/95870394f7e7	open-policy-agent	medium	opa, rego, rules	What is a partial rule in Rego, and how does it differ from a complete rule?	A partial rule builds a set or object by accumulating elements from all matching rule bodies (e.g., `violations[msg] { ... }`). A complete rule assigns exactly one value — only one body can be true. Mixing them up causes OPA to raise a conflict error.\n\nRemember: Rego = declarative policy language. Rules return true/false or sets/objects.\n\nExample: `deny[msg] { input.kind=="Pod"; not input.spec.securityContext.runAsNonRoot; msg:="No root" }`	training/library/topics/open-policy-agent/primer.md
open-policy-agent/f3f87d0f154a	open-policy-agent	medium	opa, rego, negation	What does `not` mean in Rego, and what is this pattern called?	`not expr` is negation-as-failure: the condition is considered false if `expr` cannot be proven true given the current data. It does not mean logical NOT in the classical sense — it means "OPA could not derive a proof for this."\n\nRemember: Rego = declarative policy language. Rules return true/false or sets/objects.\n\nExample: `deny[msg] { input.kind=="Pod"; not input.spec.securityContext.runAsNonRoot; msg:="No root" }`	training/library/topics/open-policy-agent/primer.md
open-policy-agent/ab5f8c002887	open-policy-agent	medium	opa, gatekeeper, audit	What is Gatekeeper audit mode and how do you check violations?	Audit mode continuously evaluates existing cluster resources against active constraints (not just new admissions). Violations are recorded in `.status.violations` on the Constraint object. Check with: `kubectl get constraint <name> -o json | jq '.status.violations'`\n\nRemember: Gatekeeper = OPA for K8s. ConstraintTemplates(logic) + Constraints(where).\n\nExample: Template=policy, Constraint=application. "Namespace X must have label Y."	training/library/topics/open-policy-agent/street_ops.md
open-policy-agent/8ba3d029f04b	open-policy-agent	medium	opa, bundles	What is an OPA bundle?	A tarball containing Rego policy files and JSON data files, served from a bundle server (S3, GCS, nginx, OCI registry). OPA polls the bundle server and hot-reloads policy without restarting. The bundle manifest pins a revision string for staleness detection.\n\nRemember: OPA = general-purpose policy engine. Decouples policy from code.\n\nFun fact: CNCF graduated. Uses Rego ("ray-go") language.	training/library/topics/open-policy-agent/primer.md
open-policy-agent/ec2545bf45ac	open-policy-agent	medium	opa, bundles, operations	How can you verify that a running OPA instance has loaded the latest bundle?	Use the health endpoint: `curl http://localhost:8181/health?bundles=true` — returns 200 only if bundles loaded successfully. Also check: `curl http://localhost:8181/v1/data/system/bundle | jq '.result.manifest.revision'` to see the loaded revision string.\n\nRemember: Bundles = policy packages via HTTP. OPA pulls periodically. "GitOps for policies."	training/library/topics/open-policy-agent/street_ops.md
open-policy-agent/bae19d6e9ca7	open-policy-agent	medium	opa, cli, evaluation	What is the `opa eval` command and give an example of evaluating a policy against inline input?	`opa eval` evaluates a Rego query against loaded policy and data. Example: `opa eval --data ./policies/ --input '{"user":{"role":"admin"}}' 'data.authz.allow'` — loads policies from the directory, provides JSON input inline, and returns the query result.\n\nRemember: OPA = general-purpose policy engine. Decouples policy from code.\n\nFun fact: CNCF graduated. Uses Rego ("ray-go") language.	training/library/topics/open-policy-agent/street_ops.md
open-policy-agent/bfb77ab54f95	open-policy-agent	medium	opa, gatekeeper, kubernetes	What does `enforcementAction: dryrun` do in a Gatekeeper Constraint?	It puts the constraint in audit-only mode — violations are recorded in `.status.violations` but no admission requests are blocked. This is the safe migration path: deploy as dryrun, monitor violations, remediate, then switch to `enforcementAction: deny`.\n\nRemember: Gatekeeper = OPA for K8s. ConstraintTemplates(logic) + Constraints(where).\n\nExample: Template=policy, Constraint=application. "Namespace X must have label Y."	training/library/topics/open-policy-agent/street_ops.md
open-policy-agent/f1d04b827eb8	open-policy-agent	medium	opa, cli, validation	What does `opa check --strict` do?	Performs syntax checking and type checking of Rego files. `--strict` enables additional checks: catches unresolved references, unused imports, and deprecated built-in usage. Run in CI before merging policy changes.\n\nRemember: OPA = general-purpose policy engine. Decouples policy from code.\n\nFun fact: CNCF graduated. Uses Rego ("ray-go") language.	training/library/topics/open-policy-agent/street_ops.md
open-policy-agent/b9a620370c3a	open-policy-agent	medium	opa, decision-logs	What fields should OPA decision logs contain at minimum?	At minimum: `input` (the query document), `result` (the policy decision), `query` (what was evaluated), and `timestamp`. Decision logs are the audit trail for policy decisions — ship them to a SIEM or object storage from day one.\n\nRemember: OPA = general-purpose policy engine. Decouples policy from code.\n\nFun fact: CNCF graduated. Uses Rego ("ray-go") language.	training/library/topics/open-policy-agent/primer.md
open-policy-agent/da62f116eb43	open-policy-agent	medium	opa, gatekeeper, troubleshooting	How do you check if a ConstraintTemplate has a Rego error after deploying it to Gatekeeper?	`kubectl get constrainttemplate <name> -o jsonpath='{.status.byPod[*].errors}'` — a non-empty result means the template failed to compile. Gatekeeper may pass all requests evaluated by a broken template, creating a silent security gap.\n\nRemember: Rego = declarative policy language. Rules return true/false or sets/objects.\n\nExample: `deny[msg] { input.kind=="Pod"; not input.spec.securityContext.runAsNonRoot; msg:="No root" }`	training/library/topics/open-policy-agent/street_ops.md
open-policy-agent/3eb94046c844	open-policy-agent	medium	opa, rego, data-model	What is the difference between `input` and `data` in OPA?	`input` is the per-request document sent by the calling application — it changes with every query. `data` is background state loaded into OPA ahead of time (user lists, config, allow-lists) — it persists across queries and is updated via bundles or the Data API.\n\nRemember: OPA = general-purpose policy engine. Decouples policy from code.\n\nFun fact: CNCF graduated. Uses Rego ("ray-go") language.	training/library/topics/open-policy-agent/primer.md
open-policy-agent/a0d4cc156ee4	open-policy-agent	medium	opa, rego, comprehensions	Write a Rego comprehension that builds the set of all container image names from a pod spec.	`images := {img \| img := input.pod.spec.containers[_].image}` — the `[_]` iterates over all elements of the containers array; the set comprehension collects each unique image value.\n\nRemember: Rego = declarative policy language. Rules return true/false or sets/objects.\n\nExample: `deny[msg] { input.kind=="Pod"; not input.spec.securityContext.runAsNonRoot; msg:="No root" }`	training/library/topics/open-policy-agent/primer.md
open-policy-agent/f766467dbc4f	open-policy-agent	medium	opa, gatekeeper, kubernetes	Why should you always exclude `kube-system` from Gatekeeper Constraints?	If a constraint applies to `kube-system`, it can block re-scheduling of critical cluster components (kube-dns, metrics-server) if those pods don't satisfy the constraint. This can break cluster DNS and monitoring. Use `excludedNamespaces: ["kube-system", "gatekeeper-system"]` in every Constraint.\n\nRemember: Gatekeeper = OPA for K8s. ConstraintTemplates(logic) + Constraints(where).\n\nExample: Template=policy, Constraint=application. "Namespace X must have label Y."	training/library/topics/open-policy-agent/footguns.md
open-policy-agent/f9d17c3a5509	open-policy-agent	medium	opa, security, defaults	Why is `default allow = true` considered a security anti-pattern in OPA?	It creates an allowlist-by-exception model: everything is permitted unless explicitly denied. Missing a deny rule opens an unintended access path. Best practice is `default allow = false` (deny by default) and enumerate conditions under which allow is true — a missed case blocks rather than exposes.\n\nRemember: deny[msg] collects violations. Empty deny = allowed. Any message = denied.	training/library/topics/open-policy-agent/footguns.md
open-policy-agent/0a9a7e021ce5	open-policy-agent	medium	opa, wasm, deployment	What is the purpose of `opa build -t wasm`?	It compiles a Rego policy to a WebAssembly (WASM) module. The WASM module can be embedded in any environment with a WASM runtime (browsers, Cloudflare Workers, Go/Rust apps) and evaluates policy in-process with no network dependency, enabling edge policy enforcement with sub-millisecond latency.\n\nRemember: OPA = general-purpose policy engine. Decouples policy from code.\n\nFun fact: CNCF graduated. Uses Rego ("ray-go") language.	training/library/topics/open-policy-agent/trivia.md
open-policy-agent/75cde5ad4adf	open-policy-agent	hard	opa, rego, performance	You have a policy that iterates over a list of 10,000 approved users for every admission request. OPA latency is climbing. What is the fix?	Replace list iteration with set membership lookup. Instead of `data.users[i].name == input.user` (O(n) scan), key the data object by the lookup field: `data.users[input.user].active == true` (O(1) hash lookup). Profile the policy with `opa bench` before deploying.\n\nRemember: OPA = general-purpose policy engine. Decouples policy from code.\n\nFun fact: CNCF graduated. Uses Rego ("ray-go") language.	training/library/topics/open-policy-agent/footguns.md
open-policy-agent/4d8e03a4b1ec	open-policy-agent	hard	opa, gatekeeper, failurepolicy	What is the risk of `failurePolicy: Fail` on the Gatekeeper webhook, and how do you mitigate it?	If Gatekeeper becomes unreachable (pod crash, network issue), all admission requests matching the webhook scope are rejected — the cluster becomes unmanageable. Mitigate: run multiple Gatekeeper replicas with a PodDisruptionBudget, exclude critical namespaces with `namespaceSelector`, and consider `failurePolicy: Ignore` for non-security-critical clusters with compensating audit monitoring.\n\nRemember: Gatekeeper = OPA for K8s. ConstraintTemplates(logic) + Constraints(where).\n\nExample: Template=policy, Constraint=application. "Namespace X must have label Y."	training/library/topics/open-policy-agent/footguns.md
open-policy-agent/49d310b15eb3	open-policy-agent	hard	opa, bundles, monitoring	What Prometheus metric should you alert on to detect OPA bundle staleness, and what liveness probe detects bundle failure?	Alert on `opa_bundle_last_success_time_seconds` — fire when the time since last successful bundle download exceeds your acceptable policy lag. For liveness, use `GET /health?bundles=true` — this endpoint returns 500 if the bundle has not loaded successfully, triggering pod restart.\n\nRemember: OPA = general-purpose policy engine. Decouples policy from code.\n\nFun fact: CNCF graduated. Uses Rego ("ray-go") language.	training/library/topics/open-policy-agent/footguns.md
open-policy-agent/4243a397f6ce	open-policy-agent	hard	opa, spiffe, integration	How does OPA integrate with SPIFFE/SPIRE for workload identity-based authorization?	SPIRE issues SVIDs (SPIFFE Verifiable Identity Documents — X.509 certs or JWTs) to workloads. OPA policies can consume the SPIFFE ID from the mTLS certificate or JWT presented by a calling service, using it as `input.principal`. This enables cryptographically-attested workload identity in OPA policy without relying on IP or service account names.\n\nRemember: OPA = one language (Rego), many enforcement points (K8s, API, CI).\n\nExample: Enforce: no root containers, required labels, approved registries.	training/library/topics/open-policy-agent/primer.md
open-policy-agent/bc10de26cab6	open-policy-agent	hard	opa, rego, unification	Explain Rego unification and how it differs from assignment in imperative languages.	In Rego, `x := 1` succeeds only if `x` is unbound or already equals 1 — it is unification (pattern matching), not assignment. If `x` is already bound to a different value, the expression fails (the rule body containing it is false). This means variable values cannot be mutated mid-rule; a variable has at most one value within a rule body.\n\nRemember: Rego = declarative policy language. Rules return true/false or sets/objects.\n\nExample: `deny[msg] { input.kind=="Pod"; not input.spec.securityContext.runAsNonRoot; msg:="No root" }`	training/library/topics/open-policy-agent/primer.md
open-policy-agent/c5cb552ac17d	open-policy-agent	hard	opa, gatekeeper, constrainttemplate	What happens to admission requests when a Gatekeeper ConstraintTemplate has a Rego compile error, and how do you detect this in CI?	Gatekeeper marks the template as errored and may pass all requests that would have been evaluated by the broken template — a silent enforcement gap. Detect in CI using `gator test -f ./constraints/` (runs ConstraintTemplate tests locally) and check `.status.byPod[*].errors` after every deploy. Never deploy ConstraintTemplates without running `gator test` in the pipeline.\n\nRemember: Rego = declarative policy language. Rules return true/false or sets/objects.\n\nExample: `deny[msg] { input.kind=="Pod"; not input.spec.securityContext.runAsNonRoot; msg:="No root" }`	training/library/topics/open-policy-agent/footguns.md

<!-- wiki:related:start -->
---

## Wiki Navigation

### Related Content

- [Open Policy Agent](../../../../library/topics/open-policy-agent/index.md) (Topic Pack, L2) — Open Policy Agent

<!-- wiki:related:end -->
