Files
releases/v1/topdown/evaluated.go
T
Stephan Renatus cb54e9c14f runtime: rule labels metadata processing follow-ups (#8613)
 We now parse rego metadata annotations by default.

Rule annotations now support a `labels` field. During policy eval,
labels from all successfully evaluated rules are collected and included
in each decision log entry as a top-level `rule_labels` array. Each
element preserves the label map from one evaluated rule. Exact
duplicates are omitted.

```rego
# METADATA
# labels:
#   severity: low
#   team: platform
allow if input.role == "admin"
```

The resulting decision log entry will contain:

```json
{"rule_labels": [{"severity": "low", "team": "platform"}]}
```

---------

Signed-off-by: Stephan Renatus <stephan.renatus@gmail.com>
2026-05-08 15:00:26 +00:00

40 lines
958 B
Go

// Copyright 2026 The OPA Authors. All rights reserved.
// Use of this source code is governed by an Apache2
// license that can be found in the LICENSE file.
package topdown
import (
"encoding/json"
"github.com/open-policy-agent/opa/v1/ast"
)
// EvaluatedRuleTracker records labels from annotations during evaluation.
// Labels from all successfully evaluated rules are aggregated. Exact
// duplicates (same key-value pairs) are suppressed.
type EvaluatedRuleTracker struct {
Labels []map[string]any
seen map[string]struct{}
}
func (t *EvaluatedRuleTracker) Record(rule *ast.Rule) {
if t == nil || len(rule.Annotations) == 0 {
return
}
for _, a := range rule.Annotations {
if len(a.Labels) > 0 {
b, _ := json.Marshal(a.Labels)
key := string(b)
if t.seen == nil {
t.seen = make(map[string]struct{})
}
if _, dup := t.seen[key]; !dup {
t.seen[key] = struct{}{}
t.Labels = append(t.Labels, a.Labels)
}
}
}
}