The Open Policy Agent (OPA) is a powerful open-source tool that enables developers to define and enforce policies for access and permissions across various applications. It supports multiple integrations and can be deployed in diverse environments.
Use this profile to understand the building block briefly, place it in the model, and open related building blocks.
Usable application software: supports people in a task.
Concrete cog in the system that works inside larger relationships.
Open Policy Agent is a general-purpose policy engine that evaluates structured input against declarative rules. Applications use it to move authorization, compliance, or configuration decisions out of their own program code.
Tim Hinrichs, Torin Sandall, and Teemu Koponen created OPA around Styra to express and evaluate policy consistently across heterogeneous cloud systems. The project joined the CNCF in 2018 and graduated in 2021.
Imagine OPA as an independent decision service beside an application. The application sends a concrete situation as structured input: who wants to perform which action on what resource? OPA combines that input with Rego policies and available data, then returns a decision. The application remains responsible for enforcement.
The calling component describes the decision context, commonly as JSON data.
The declarative language expresses rules for deriving results from input and data.
OPA computes an outcome such as allow, deny, or a structured configuration.
The integrating application interprets the result and applies it at its control point.
OPA helps when many services need consistent, testable rules across APIs, Kubernetes, or CI/CD. Distribution, freshness, and explainability of policies and data remain key operational concerns. OPA decides; each integration must enforce the outcome securely.
Where this building block is located in the topic model.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.