This commit fixes an issue when upgrading codebases to OPA v1.7.0.
In PR #7797, we introduced the ability to provide "branding"
information in OPA commands and help messages, which would
allow easier customized OPA distributions in the future.
However, this changeset removed the public symbol `cmd.RootCommand`,
and required refactoring to use `cmd.Command`, which breaks automated
upgrades, such as those done by Dependabot.
This PR adds back the missing symbol, with the original/default "OPA"
branding provided. This should allow existing codebases to upgrade
without requiring any code changes.
Signed-off-by: Philip Conrad <philip@chariot-chaser.net>
This change allows users that build their own executable or "spin" of
OPA to give it a name, and have it reference itself properly in help
texts.
It's a vanity thing, but I think some people would appreciate it, hat
tip to the international association of pedants.
Signed-off-by: Stephan Renatus <stephan@styra.com>
Co-authored-by: kevinstyra <83973046+kevinstyra@users.noreply.github.com>
All published OPA images now run with a non-root uid/gid.
The uid:gid is set to 1000:1000 for all images. As a result
there is no longer a need for the --rootless image variant
hence it will not be published as part of future releases.
This change is in line with container security best practices.
OPA can still be run with root privileges by explicitly setting the user,
either with the --user argument for docker run, or by specifying
the securityContext in the Kubernetes Pod specification.
Fixes: #4295
Signed-off-by: Ashutosh Narkar <anarkar4387@gmail.com>
I have added a system for showing fatal and non-fatal deprecation warnings. It's configurable by command and environment.
If we merge this PR, running a rootless image with any OPA command other than `opa run` will result in a fatal error and exit code 1.
It's possible for users to continue to use the image by unsetting: OPA_DOCKER_IMAGE_TAG=rootless.
`opa run` will show the message, but it's not fatal for this command. This is intended to avoid production disruption.
Signed-off-by: Charlie Egan <charlie@styra.com>
With the site refresh, we have begun referring to services being policy
enabled instead of applications. These changes just update a few spots that
were not touched in the refresh.
- Updated source code layout to use standard Go project structure.
- Makefile for build and test execution.
- Glide for dependency management.
- Integrated spf13/cobra for command line entry point.
- Added docs on release and development process.