Previously the test runner would set fail to the value generated by the
test rule or false on undefined. The intent was to communicate the value
generated by the rule. In practice users are not writing tests that
generate values other than true so this is essentially unnecessary.
Fixes#954
Signed-off-by: Torin Sandall <torinsandall@gmail.com>
The docker authorization tutorial was using an old version of the
plugin. The latest version of the plugin implements the new Docker
plugin model and has different installation steps. These changes should
fix the parse errors that users were seeing when running through the
tutorial.
Signed-off-by: Torin Sandall <torinsandall@gmail.com>
With these changes, the identity will be undefined if a token is not
specified. This is less surprising than the empty string that would be
set prior to these changes.
Fixes#901
Signed-off-by: Torin Sandall <torinsandall@gmail.com>
The rule 'r' was being defined incrementally when that was not intended.
Rename to 's' to avoid this.
Signed-off-by: Torin Sandall <torinsandall@gmail.com>
The output from running the interactive
interpretter with v0.9.1 does not match
a few of the examples list in the
How Do I Write Policies section.
This updates the examples to match
the examples observed from running
the v0.9.1 cli.
Signed-off-by: Travis Tripp <os.travis.tripp@gmail.com>
By default kube-mgmt will try to load policies out of configmaps in the opa namespace OR configmaps in other namespaces labelled openpolicyagent.org/policy=rego.
Signed-off-by: Nikhil Bhatia nbhatia@microsoft.com
In de828cd we added any and all built-in functions. This broke the
example policy in the terraform tutorial that was expecting "all" to be
a variable. We fix this by replacing the unification expressions ("=")
with assignments (":=").
Fixes#888
Signed-off-by: Torin Sandall <torinsandall@gmail.com>
Previously the example policy at the end of the tutorial would allow
operations if the Authz-User was contained in the input headers but not
in the user mapping. This change makes sure that the user is defined in
the mapping.
Also, update the example to use := and == instead of = (which is
functionaly the same but better practice because they avoid capturing
globals.)
Fixes#880
Signed-off-by: Torin Sandall <torinsandall@gmail.com>
Previously the configuration reference for bundles, status updates,
decision logs, etc. was split across multiples. These changes refactor
the docs so that the configuration reference is in one place.
Also, fix a few issues in the gitbook SUMMARY.md file that made the TOC
not work properly.
Fixes#871
Signed-off-by: Torin Sandall <torinsandall@gmail.com>
The signing key used in the new test(corresponding to certPemEs256) is:
-----BEGIN PRIVATE KEY-----
MIGHAgEAMBMGByqGSM49AgEGCCqGSM49AwEHBG0wawIBAQQgtT+DJZkjOAhEaLnU
dc0BOvwnmFxFGyYz0PRkdOV/r82hRANCAATPwn3WCEXLmjp/bFniDwuwsfu7bASl
Pae2PyWhqGeWwe23Xlyx+tSqxlkXYe4pZ23BkAAscpGjyn5gXHExyDlK
-----END PRIVATE KEY-----
Signed-off-by: Richard Kettlewell <Richard.Kettlewell@thalesesecurity.com>
The behavior is the same as the rs256 version, except that it uses
RSA-PSS for verification.
The signing key used in the new tests (corresponding to certPemPs) is:
-----BEGIN RSA PRIVATE KEY-----
MIIEowIBAAKCAQEAuJApsyzFv+Y85M5JjezHvMDw/spgVCI7BqpYhnzK3xXw1dnk
z1bWXGA9yF6AeADlE+1yc1ozrAURTnFSihIgj414i3MC2/0FkNcdAbnX7d9q9/jd
CkHda4HER0zzXCaHlgnzoAz6edUU800+h0LleLnfgg4UST+0DFTCIGpfTbs7OPSy
2WgT1vP6xbB45CUOJA7o0q6XE+hdhWWN0plrDiYD+0Y1SpOQYXmHhSmr+WVeKeoh
5/0zeEVab6TQYec/16ByEyepaZB0g6WyGkFE6aG1NrpvDd24s/h7BAJg/S2mtu1l
KWEqYjOgwzEl5XQQyXbpnq1USb12ArX16rZdewIDAQABAoIBAEw7F04vVvpdIZer
8MuTGijHVIMYmdMGVHT7VRcvYifkixX5Kr3M8zsycTJafhuS2wtxDs3AWwlZCn3o
5puqwxIn77tBZNPyXSMnBo8Y8KwKlMcZXksHS2pFLgn5KadNLsF1GNBpq+c4cK/R
ntsFcXx84Wl5YT2j9z0EoS38YaLb1tnzKn4nAmr/0+hfpcI7X1Uij5HvewhhDQlI
JtBO/a/mmS9v3wd2zu2LZkZpRIGM1PHnnRYOJa4wZ/XGZAEnlKrraVOAbb+wfYYq
HPkrMY+yd2bcDpnP7ea4MjScJVEer5tX6VE3EoE/Y0LcxgZ3vfOXbPAIIAiFddBb
Zu2JB/kCgYEAwTVm5/d3eeQxyu7JgNnCb1O16uGbHxl+7cM/2oEiMYtIBM1oOz6o
gxmBXcwtn/v3xr7JtnYv6D4UW4tLKWv7g5H4DrrF8k8EJYj3KU+iUnIjugqFRNFl
5hunBiaW5lR27mNOIk24xkJYbCGF32dftKopKvtZKCpWTF32v43u0bUCgYEA9It5
ZfrAR09o1caLl1JfgOocQBwdpSDzGkyIyxSBd4rw5rGgN1E7e4zQxmTsPpQvFVrC
nNpIu7Mv+3nnowyyrl/kQCLw1JS+ZuGRC44aGlInhX4Ev6dNY/A0PlrUdyhGIiAV
lbZdKSyKH4x+aTLUc+xVrKLr6hESCy7qjXIpsG8CgYA+G3d/+7nJUgR7knTt2ZI6
DTO+VFV0EtMNhSUijT47pOU6vfjSiprKwcknKLpF4k5M8gmPgMB3rHUI1GcN4qtQ
KP0PZxS4hpPzqOqiufmY/R3k8PrUG2fhJ2RygrchRWeRzBRSzJ8oBC2+XKxXGzjV
r5laOr/3PFzPYaku/GYXvQKBgC/4jD/tCHr0oOQOpqNwjTuEsTYCTe5uoEGwccUk
qKECqG8YuQ0g6kI6RVolwhIkj3fo7fRG/a2UYP071KyveP2r4eKS+Bs7cn5MEV/q
6EPxib8uEVBnSU8pd5Yjyzn0tI1NLe7Ib038Zrv5m3KXfgWffs72xsCLyLZY5boJ
gxQRAoGBALElFEMT/3lIvlVyWyVsEMs0t15DH6WciJEDt1jcgOkgd6EDyNUaSeYY
ebc1unFA+wy3GfeF0jQt4vJ50xfIwpDUdClIsFwQMO2BmSI74MdsdsqnXRJDEm99
XGCADKfGvBKXKseZNDZopF1a95YEGeEFt6f/bh9ZSs4UaCwzYrxp
-----END RSA PRIVATE KEY-----
Signed-off-by: Richard Kettlewell <Richard.Kettlewell@thalesesecurity.com>
Previously OPA would only load JSON/YAML/Rego files off the command
line. With these changes, OPA will load .tar.gz files and interpret them
as bundles. This is useful if you want to test your bundles locally with
OPA without running OPA as a server, configuring it to pull down the
bundle, etc.
Also, update docs to mention that data files MUST be named data.json.
Fixes#870Fixes#873
Signed-off-by: Torin Sandall <torinsandall@gmail.com>
and to_array functions require no justification.
For the others: I realized this would be useful to have when I was
doing http calls that returned a types.A and thus when I parsed my code
on occasion it only threw type errors at runtime when I attempted to use
the result in another builtin. It would be great to have some way to
throw these type errors at compile time as well if the
user likes, hence these functions.
Changed names to cast_, added test, added copyright banner, added docs.
Signed-off-by: Varun Mathur <varun.mathur@live.com>
Signed-off-by: Varun Mathur <vmathur@cloudsimple.com>
Signed-off-by: Varun Mathur <varun.mathur@live.com>
These changes update the subcommands to support a file/directory name
filter. This allows users to exclude certain files from being loaded.
With these changes users can excldue private directories created by
Kubernetes for volume-mounted ConfigMaps.
As part of this change, update the Kubernetes deployment documentation
to use the new --ignore flag, run OPA as a Deployment instead of as a
ReplicationController, and generally improve the example.
Fixes#782
Signed-off-by: Torin Sandall <torinsandall@gmail.com>
This change removes the default decision log buffer limit to avoid
unintentionally dropping decision logs. If users are concerned about
memory usage they can set the limit, but by default they will not be
surprised by log discards.
Signed-off-by: Torin Sandall <torinsandall@gmail.com>