🗂️ Navigation

Open Policy Agent

Policy-based control for cloud native environments.

Visit Website →

Overview

Open Policy Agent (OPA) is an open-source, general-purpose policy engine that enables unified, context-aware policy enforcement across the entire stack. While not strictly an IaC scanner, OPA is a foundational technology used by many IaC compliance tools to create and enforce custom policies.

✨ Key Features

  • General-purpose policy engine
  • Declarative policy language (Rego)
  • Can be used to enforce policies on any JSON/YAML data
  • Integrates with a wide range of tools and services
  • Decouples policy from application logic
  • Open-source and CNCF graduated project

🎯 Key Differentiators

  • General-purpose and flexible
  • Declarative policy language
  • Wide adoption and strong community

Unique Value: Provides a unified way to enforce policies across the entire cloud-native stack.

🎯 Use Cases (4)

Enforcing custom policies on IaC Kubernetes admission control API authorization Data filtering

✅ Best For

  • Writing custom policies for Terraform using Rego
  • Enforcing organizational policies on Kubernetes deployments

💡 Check With Vendor

Verify these considerations match your specific requirements:

  • Out-of-the-box IaC scanning (requires policy authoring)
  • Vulnerability scanning

💻 Platforms

CLI Go library Sidecar proxy

✅ Offline Mode Available

🔌 Integrations

Kubernetes Terraform Envoy Kafka and many more

💰 Pricing

Contact for pricing
Free Tier Available

Free tier: Full open-source version is free.

Visit Open Policy Agent Website →