CtrlK
BlogDocsLog inGet started
Tessl Logo

nicholasjackson/opa-rego-language

Rego is the declarative policy language used by Open Policy Agent (OPA). This tile covers writing and testing Rego policies for Kubernetes admission control, Terraform and infrastructure-as-code plan validation, Docker container authorization, HTTP API authorization, RBAC and role-based access control, data filtering, metadata annotations with opa inspect, and OPA policy testing with opa test.

96

1.18x
Quality

94%

Does it follow best practices?

Impact

97%

1.18x

Average score across 32 eval scenarios

SecuritybySnyk

Low

Low-risk findings worth noting

Overview
Quality
Evals
Security
Files

Evaluation results

100%

5%

Access Control: Common Testing Pattern

Criteria
Baseline
With context

_test.rego filename suffix

100%

100%

test_ function prefix

100%

100%

positive and negative test cases

100%

100%

tests pass

80%

100%

100%

Access Control: RBAC Policy

Criteria
Baseline
With context

import rego.v1

100%

100%

default allow := false

100%

100%

Reads roles from JWT claims

100%

100%

Reads role grants from data

100%

100%

Nested iteration with some

100%

100%

Permission match on action and resource_type

100%

100%

Tests pass

100%

100%

100%

28%

Access Control: Separation of Duty

Criteria
Baseline
With context

import rego.v1

0%

100%

Partial set rule for violations

85%

100%

Iterates over conflicting pairs with array-of-arrays membership

57%

100%

Reads user roles from data

100%

100%

Tests pass

100%

100%

100%

HTTP API: Authorization Policy

Criteria
Baseline
With context

import rego.v1

100%

100%

default allow := false

100%

100%

JWT decoded with io.jwt.decode

100%

100%

Matches on input.method and input.path

100%

100%

Allow self and manager access

100%

100%

Tests pass

100%

100%

100%

HTTP API: Common Testing Pattern

The agent wrote 1 file outside the evaluated workspace (With context)

These are not visible to scoring or included in the download.

/home/agent/opa

Criteria
Baseline
With context

_test.rego filename suffix

100%

100%

test_ function prefix

100%

100%

positive and negative test cases

100%

100%

tests pass

100%

100%

100%

57%

HTTP API: Rate Limiting with Per-User Limits

Criteria
Baseline
With context

import rego.v1

0%

100%

Default rule value for fallback limit

0%

100%

Per-tier limit lookup

100%

100%

Tests pass

72%

100%

100%

45%

HTTP API: Request Body Field Validation

Criteria
Baseline
With context

import rego.v1

0%

100%

Set subtraction to detect unknown fields

25%

100%

Checks for required fields

100%

100%

Tests pass

80%

100%

100%

Kubernetes: Admission Policy (kube-mgmt)

Criteria
Baseline
With context

deny contains msg pattern

100%

100%

Checks input.request.kind.kind

100%

100%

Deny rule for privileged containers

100%

100%

Tests pass

100%

100%

100%

25%

Kubernetes: Common Testing Pattern

Criteria
Baseline
With context

_test.rego filename suffix

100%

100%

test_ function prefix

100%

100%

positive and negative test cases

100%

100%

tests pass

0%

100%

100%

11%

Kubernetes: Gatekeeper Policy

Criteria
Baseline
With context

violation contains msg pattern

100%

100%

Uses input.review.object

100%

100%

Uses input.parameters for required labels

100%

100%

Tests pass

15%

100%

100%

40%

Metadata: Policy Annotations

Criteria
Baseline
With context

package has METADATA block with title and description

100%

100%

package has authors or organizations

0%

100%

decision rules have METADATA with title and description

100%

100%

decision rules have entrypoint: true

0%

100%

rules have custom fields

100%

100%

Tests pass

100%

100%

60%

-39%

Metadata: Runtime Annotation Access

Criteria
Baseline
With context

import rego.v1

100%

100%

METADATA block with custom.severity

100%

100%

Uses rego.metadata.rule() at runtime

100%

57%

Violation is a structured object with severity

100%

40%

Tests pass

90%

0%

97%

59%

Regal: Annotations — RBAC Authorization Policy

Criteria
Baseline
With context

Package-level metadata annotation

60%

100%

`allow` rule annotated with `entrypoint: true`

50%

100%

No blank lines between metadata and rule

0%

100%

Tests pass

32%

88%

100%

35%

Regal: Boolean Structure — Pod Security Policy

Criteria
Baseline
With context

Incremental violations set using `contains`

100%

100%

Boolean allow rule referencing violations

50%

100%

Checks for privileged and missing limits

100%

100%

Tests pass

0%

100%

100%

Regal: Bug Avoidance — Namespace Policy Validation

Criteria
Baseline
With context

Uses `in` for membership check (not `!=` in a loop)

100%

100%

sprintf argument count matches format string

100%

100%

Checks for restricted name and missing annotation

100%

100%

Tests pass

100%

100%

100%

2%

Regal: Comprehensions — Tag Compliance Policy

The agent wrote 20062 files outside the evaluated workspace (Baseline)

These are not visible to scoring or included in the download.

/home/agent/go/bin/opa

/home/agent/go/pkg/mod/cache/download/github.com/agnivade/levenshtein/@v/list

/home/agent/go/pkg/mod/cache/download/github.com/agnivade/levenshtein/@v/v1.2.1.info

/home/agent/go/pkg/mod/cache/download/github.com/agnivade/levenshtein/@v/v1.2.1.lock

/home/agent/go/pkg/mod/cache/download/github.com/agnivade/levenshtein/@v/v1.2.1.mod

Criteria
Baseline
With context

Uses `object.keys()` for provided tags

100%

100%

Set subtraction for missing tags

100%

100%

deny contains msg with sprintf

100%

100%

Tests pass

92%

100%

100%

25%

Regal: Default Rules — Tiered Rate Limit Values

Criteria
Baseline
With context

default declaration at the top

100%

100%

Conditional overrides for each tier

100%

100%

No else branches for fallback

100%

100%

Tests pass

0%

100%

100%

32%

Regal: Function Style — Container Security Validation

Criteria
Baseline
With context

Helper functions take explicit container argument

100%

100%

Separate helpers for privileged and resource limit checks

100%

100%

deny contains msg pattern with container name

53%

100%

Tests pass

0%

100%

100%

Regal: Import Conventions — JWT Authorization with Helper Library

Criteria
Baseline
With context

Imports the package, not individual rules

100%

100%

No redundant aliases

100%

100%

All imports before rules

100%

100%

Tests pass

100%

100%

100%

Regal: Iteration Style — Container Image Registry Validation

The agent wrote 1 file outside the evaluated workspace (With context)

These are not visible to scoring or included in the download.

/home/agent/opa

Criteria
Baseline
With context

Uses `some ... in` for iteration

100%

100%

Checks each container image against approved registry

100%

100%

deny contains msg pattern

100%

100%

Tests pass

100%

100%

100%

40%

Regal: Membership Operators — Department-Based Access Control

The agent wrote 1 file outside the evaluated workspace (Baseline)

These are not visible to scoring or included in the download.

/home/agent/opa

Criteria
Baseline
With context

Uses `in` operator for membership check

0%

100%

Looks up allowed departments from data

100%

100%

import rego.v1 and default allow := false

100%

100%

Tests pass

100%

100%

70%

-30%

Regal: Naming Conventions — RBAC Policy

Criteria
Baseline
With context

snake_case for all identifiers

100%

100%

No get_ or list_ prefix on rule names

100%

0%

No package path repetition in rule names

100%

100%

Tests pass

100%

100%

100%

Regal: Testing Style — Authorization Policy with Tests

The agent wrote 1 file outside the evaluated workspace (Baseline)

These are not visible to scoring or included in the download.

/home/agent/opa

Criteria
Baseline
With context

Test file named `authz_test.rego` with `_test` package suffix

100%

100%

Policy package imported and rules referenced via alias

100%

100%

Unique descriptive test names

100%

100%

Tests pass

100%

100%

100%

27%

Terraform: CloudFormation Hook — S3 Bucket Access Control

Criteria
Baseline
With context

main response object

100%

100%

Uppercase action strings and CloudFormation input structure

40%

100%

Helper rules for conditions

13%

100%

Three deny rules covering AccessControl and both BlockPublic settings

100%

100%

Tests pass

92%

100%

100%

75%

Terraform: Common Patterns

Criteria
Baseline
With context

import rego.v1

0%

100%

object.get input normalization

0%

100%

Tests pass

100%

100%

100%

Terraform: Common Testing Pattern

Criteria
Baseline
With context

_test.rego filename suffix

100%

100%

mocks Terraform plan input with `with input as`

100%

100%

includes both positive and negative test cases

100%

100%

tests pass

100%

100%

100%

7%

Terraform: Module Security Group Validation

Criteria
Baseline
With context

Uses walk() built-in

100%

100%

Collects resources from all modules

80%

100%

Deny rule for HTTP in description

100%

100%

Tests pass

92%

100%

100%

Terraform: Multi-Region Deployment Policies

The agent wrote 1 file outside the evaluated workspace (With context)

These are not visible to scoring or included in the download.

/home/agent/opa

Criteria
Baseline
With context

Provider region check via configuration path

100%

100%

EU data residency deny rule

100%

100%

has_replication helper with multiple function heads

100%

100%

Tests pass

100%

100%

100%

Terraform: Repeatable Block Serialization Shape

Criteria
Baseline
With context

Deny when capabilities block is absent (empty list)

100%

100%

Deny when drop does not include ALL

100%

100%

Capabilities read as a list, not an object

100%

100%

Tests use the real list-shaped mock, not a bare-object mock

100%

100%

85%

15%

Terraform: Required Tags Enforcement

Criteria
Baseline
With context

action != delete exclusion pattern

21%

43%

supports_tags helper

100%

88%

Safe tag access with object.get

100%

100%

Deny for missing and empty tags

33%

100%

Tests pass

100%

100%

100%

8%

Terraform: S3 Bucket Encryption

Criteria
Baseline
With context

Deny on aws_s3_bucket without inline encryption

100%

100%

Deny on separate encryption resource with invalid algorithm

100%

100%

Helper function for algorithm validation

52%

100%

Tests pass

100%

100%

100%

5%

Terraform: S3 Bucket Versioning

Criteria
Baseline
With context

Checks create and update actions

100%

100%

Deny on aws_s3_bucket without versioning enabled

100%

100%

Deny on separate versioning resource with wrong status

83%

100%

Tests pass

100%

100%

Evaluated
Agent
Claude Code
Model
Claude Sonnet 4.6

Table of Contents