runtime

package
v0.33.22 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 28, 2026 License: Apache-2.0 Imports: 40 Imported by: 0

Documentation

Index

Constants

View Source
const DefaultRegoVersion = RegoV1

Variables

This section is empty.

Functions

This section is empty.

Types

type Bundle

type Bundle struct {
	ID   string
	Name string
	Path string
}

type BundleState

type BundleState struct {
	ID             string
	Revision       string
	LastDownload   time.Time
	LastActivation time.Time
	Errors         []error
}

type CompileResult

type CompileResult struct {
	Result      *any
	Metrics     map[string]any
	Explanation types.TraceV1
}

CompileResult contains the results of a Compile execution.

type Config

type Config struct {
	LocalBundles                  LocalBundlesConfig `json:"local_bundles"`
	InstanceID                    string             `json:"instance_id"`
	PluginsErrorLimit             int                `json:"plugins_error_limit"`
	GracefulShutdownPeriodSeconds int                `json:"graceful_shutdown_period_seconds"`
	MaxPluginWaitTimeSeconds      int                `json:"max_plugin_wait_time_seconds"`
	Flags                         Flags              `json:"flags"`
	Config                        OPAConfig          `json:"config"`
}

type Flags

type Flags struct {
	EnableStatusPlugin bool `json:"enable_status_plugin"`
}

type LocalBundlesConfig

type LocalBundlesConfig struct {
	Watch              bool                       `json:"watch"`
	LocalPolicyImage   string                     `json:"local_policy_image"`
	FileStoreRoot      string                     `json:"file_store_root"`
	Paths              []string                   `json:"paths"`
	Ignore             []string                   `json:"ignore"`
	SkipVerification   bool                       `json:"skip_verification"`
	VerificationConfig *bundle.VerificationConfig `json:"verification_config"`
}

type Module

type Module struct {
	ID      string
	Name    string
	Content string
	Rules   []string
}

type OPAConfig

type OPAConfig struct {
	Services                     map[string]any          `json:"services,omitempty"`
	Labels                       map[string]string       `json:"labels,omitempty"`
	Discovery                    *discovery.Config       `json:"discovery,omitempty"`
	Bundles                      map[string]*bp.Source   `json:"bundles,omitempty"`
	DecisionLogs                 *logs.Config            `json:"decision_logs,omitempty"`
	Status                       *status.Config          `json:"status,omitempty"`
	Plugins                      map[string]any          `json:"plugins,omitempty"`
	Keys                         map[string]*keys.Config `json:"keys,omitempty"`
	DefaultDecision              *string                 `json:"default_decision,omitempty"`
	DefaultAuthorizationDecision *string                 `json:"default_authorization_decision,omitempty"`
	Caching                      *cache.Config           `json:"caching,omitempty"`
	PersistenceDirectory         *string                 `json:"persistence_directory,omitempty"`
}

func (*OPAConfig) DiscoveryCopy

func (c *OPAConfig) DiscoveryCopy() *discovery.Config

func (*OPAConfig) ServicesCopy

func (c *OPAConfig) ServicesCopy() map[string]any

type Option

type Option func(*Runtime)

func WithBuiltin1

func WithBuiltin1(decl *rego.Function, impl rego.Builtin1) Option

func WithBuiltin2

func WithBuiltin2(decl *rego.Function, impl rego.Builtin2) Option

func WithBuiltin3

func WithBuiltin3(decl *rego.Function, impl rego.Builtin3) Option

func WithBuiltin4

func WithBuiltin4(decl *rego.Function, impl rego.Builtin4) Option

func WithBuiltinDyn

func WithBuiltinDyn(decl *rego.Function, impl rego.BuiltinDyn) Option

func WithImport

func WithImport(imp string) Option

func WithImports

func WithImports(imp []string) Option

func WithPlugin

func WithPlugin(name string, factory plugins.Factory) Option

func WithRegoVersion

func WithRegoVersion(v ast.RegoVersion) Option

func WithStorage

func WithStorage(storageInterface storage.Store) Option

type PathFilterFn

type PathFilterFn func(packageName string) bool

type Policy

type Policy struct {
	PackageName string
	Location    string
}

func (Policy) Name

func (p Policy) Name() string

type PolicyItem

type PolicyItem struct {
	Name string
	ID   string
}

type RegoVersion

type RegoVersion int
const (
	RegoUndefined RegoVersion = iota
	// RegoV0 is the default, original Rego syntax.
	RegoV0
	// RegoV0CompatV1 requires modules to comply with both the RegoV0 and RegoV1 syntax (as when 'rego.v1' is imported in a module).
	// Shortly, RegoV1 compatibility is required, but 'rego.v1' or 'future.keywords' must also be imported.
	RegoV0CompatV1
	// RegoV1 is the Rego syntax enforced by OPA 1.0; e.g.:
	// future.keywords part of default keyword set, and don't require imports;
	// 'if' and 'contains' required in rule heads;
	// (some) strict checks on by default.
	RegoV1
)

func RegoVersionFromString

func RegoVersionFromString(v string) RegoVersion

func (RegoVersion) String

func (v RegoVersion) String() string

func (RegoVersion) ToAstRegoVersion

func (v RegoVersion) ToAstRegoVersion() ast.RegoVersion

type Result

type Result struct {
	Result      rego.ResultSet
	Metrics     map[string]any
	Explanation types.TraceV1
	DecisionID  string
}

Result contains the results of a Query execution.

type Runtime

type Runtime struct {
	Logger          *zerolog.Logger
	Config          *Config
	InterQueryCache cache.InterQueryCache
	// contains filtered or unexported fields
}

func New

func New(ctx context.Context, cfg *Config, opts ...Option) (*Runtime, error)

func (*Runtime) CheckPluginsStatus

func (r *Runtime) CheckPluginsStatus() error

CheckPluginsStatus, check all plugins if status is NOT plugins.StateOK.

func (*Runtime) Compile

func (r *Runtime) Compile(
	ctx context.Context,
	qStr string,
	input map[string]any,
	unknowns []string,
	disableInlining []string,
	pretty, includeMetrics, includeInstrumentation bool,
	explain types.ExplainModeV1,
) (*CompileResult, error)

func (*Runtime) GetBundleByID

func (r *Runtime) GetBundleByID(ctx context.Context, id string) (*Bundle, error)

func (*Runtime) GetBundles

func (r *Runtime) GetBundles(ctx context.Context) ([]*PolicyItem, error)

func (*Runtime) GetModule

func (r *Runtime) GetModule(ctx context.Context, id string) (*Module, error)

func (*Runtime) GetPluginsManager

func (r *Runtime) GetPluginsManager() *plugins.Manager

func (*Runtime) GetPolicies

func (r *Runtime) GetPolicies(ctx context.Context, id string) ([]*PolicyItem, error)

func (*Runtime) GetPolicy

func (r *Runtime) GetPolicy(ctx context.Context, id string) (*types.PolicyV1, error)

func (*Runtime) GetPolicyList

func (r *Runtime) GetPolicyList(ctx context.Context, id string, fn PathFilterFn) ([]Policy, error)

GetPolicyList returns the list of policies loaded by the runtime for a given bundle, identified with the policy id.

func (*Runtime) GetPolicyRoot

func (r *Runtime) GetPolicyRoot(ctx context.Context) (string, error)

GetPolicyRoot returns the package root name from the policy list (not from the .manifest file). If no policies exist, it will return an empty string as the policy root.

func (*Runtime) GetPolicyRootForPath

func (r *Runtime) GetPolicyRootForPath(ctx context.Context, path string) (string, error)

GetPolicyRootForPath returns the package root name from the policy list (not from the .manifest file) based on the given path.

func (*Runtime) ListPolicies

func (r *Runtime) ListPolicies(ctx context.Context) ([]types.PolicyV1, error)

func (*Runtime) Query

func (r *Runtime) Query(
	ctx context.Context,
	qStr string,
	input map[string]any,
	pretty, includeMetrics, includeInstrumentation bool,
	explain types.ExplainModeV1,
) (*Result, error)

Query executes a REGO query against the Aserto OPA Runtime explain can be "notes", "full" or "off".

func (*Runtime) Start

func (r *Runtime) Start(ctx context.Context) error

func (*Runtime) Stop

func (r *Runtime) Stop(ctx context.Context)

func (*Runtime) ValidateQuery

func (r *Runtime) ValidateQuery(query string) (ast.Body, error)

func (*Runtime) ValidateRule

func (r *Runtime) ValidateRule(rule string) (bool, error)

type State

type State struct {
	Ready   bool
	Errors  []error
	Bundles []BundleState
}

Directories

Path Synopsis

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL