opal
Policy and data administration, distribution, and real-time updates on top of Policy Agents (OPA, Cedar, ...)
File Explorer
Download Latest Version (.zip)- bug_report.md
- documentation_template.md
- feature_request.md
- docs-build.yml
- on_release.yml
- pre-commit.yml
- tests.yml
- pull_request_template.md
- Dockerfile
- seed_gitea.py
- conftest.py
- docker-compose.yml
- helpers.py
- invariants.py
- pytest.ini
- README.md
- test_boot.py
- test_boot_states.py
- test_leak.py
- test_remote_transitions.py
- test_resilience.py
- test_transitions.py
- data.json
- policy.cedar
- rbac.rego
- README.md
- utils.rego
- docker-compose-app-tests.yml
- README.md
- run.sh
- bundle.tar.gz
- bundle.tar.gz.bak
- data.json
- nginx.conf
- authz.rego
- nginx.conf
- squid.conf
- docker-compose-api-policy-source-example.yml
- docker-compose-example-alpine.yml
- docker-compose-example-cedar.yml
- docker-compose-example-eopa.yml
- docker-compose-example.yml
- docker-compose-git-webhook.yml
- docker-compose-scopes-example.yml
- docker-compose-single-topic-multi-tenant.yml
- docker-compose-with-callbacks.yml
- docker-compose-with-kafka-example.yml
- docker-compose-with-oauth-initial.yml
- docker-compose-with-proxy-example.yml
- docker-compose-with-rate-limiting.yml
- docker-compose-with-security.yml
- docker-compose-with-statistics.yml
- Dockerfile
- run-example-with-scopes.sh
- run-example-with-security.sh
- run-example-with-single-topic-multi-tenant.sh
- opal-client.mdx
- opal-server.mdx
- overview.mdx
- postgres-database.mdx
- overview.mdx
- publishing-data-update.mdx
- run-server-and-client.mdx
- send-queries-to-opa.mdx
- updating-the-policy.mdx
- opal-client-setup.mdx
- opal-server-setup.mdx
- overview.mdx
- running-in-prod.mdx
- secure-mode-setup.mdx
- data-topics.mdx
- get-client-image.mdx
- lets-run-the-client.mdx
- obtain-jwt-token.mdx
- opa-runner-parameters.mdx
- server-uri.mdx
- standalone-opa-uri.mdx
- broadcast-interface.mdx
- data-sources.mdx
- get-server-image.mdx
- policy-repo-location.mdx
- policy-repo-syncing.mdx
- putting-all-together.mdx
- security-parameters.mdx
- download-docker-images.mdx
- overview.mdx
- run-docker-containers.mdx
- troubleshooting.mdx
- configuration.mdx
- intro.mdx
- tldr.mdx
- deploy.mdx
- features.mdx
- introduction.mdx
- troubleshooting.mdx
- _security.mdx
- architecture.mdx
- design.mdx
- modules.mdx
- scopes.md
- _configure_backbone_pubsub.mdx
- cedar.mdx
- configure_external_data_sources.mdx
- healthcheck_policy_and_update_callbacks.mdx
- helm-chart-for-kubernetes.mdx
- install_as_python_packages.mdx
- monitoring_opal.mdx
- opa-version-migration.mdx
- opal_server_connectivity.mdx
- run_opal_with_kafka.mdx
- run_opal_with_pulsar.mdx
- setup_opal_behind_proxy.mdx
- single-topic-multi-tenant.mdx
- track_a_git_repo.mdx
- track_an_api_bundle_server.mdx
- trigger_data_updates.mdx
- use_self_signed_certificates.mdx
- write_your_own_fetch_provider.mdx
- FAQ.mdx
- fetch-providers.mdx
- release-updates.mdx
- welcome.mdx
- custom.scss
- prism-theme.js
- FAQ-1.png
- favicon.ico
- opal.png
- opal_plus.png
- .nojekyll
- .gitignore
- .nvmrc
- babel.config.js
- docusaurus.config.js
- package.json
- pnpm-lock.yaml
- pnpm-workspace.yaml
- sidebars.js
- __init__.py
- api.py
- register.py
- reporter.py
- __init__.py
- api.py
- __init__.py
- api.py
- fetcher.py
- rpc.py
- updater.py
- example-transaction.json
- opal.rego
- __init__.py
- logger.py
- options.py
- runner.py
- __init__.py
- api.py
- fetcher.py
- options.py
- topics.py
- updater.py
- __init__.py
- api.py
- base_policy_store_client.py
- cedar_client.py
- liveness_probe.py
- mock_policy_store_client.py
- opa_client.py
- policy_store_client_factory.py
- schemas.py
- __init__.py
- callbacks_reporter_test.py
- cedar_client_liveness_test.py
- data_updater_test.py
- engine_runner_test.py
- opa_client_liveness_test.py
- opa_client_test.py
- server_to_client_intergation_test.py
- __init__.py
- cli.py
- client.py
- config.py
- limiter.py
- logger.py
- main.py
- utils.py
- requires.txt
- setup.py
- __init__.py
- jwt_signer_test.py
- __init__.py
- authz.py
- casting.py
- deps.py
- signer.py
- types.py
- verifier.py
- __init__.py
- commands.py
- docs.py
- typer_app.py
- __init__.py
- cli.py
- confi.py
- README.md
- types.py
- invalid-package.rego
- jwt.rego
- no-package.rego
- play.rego
- rbac.rego
- parsing_test.py
- paths_test.py
- __init__.py
- parsing.py
- paths.py
- py.typed
- __init__.py
- base_fetching_engine.py
- core_callbacks.py
- fetch_worker.py
- fetching_engine.py
- __init__.py
- fastapi_rpc_fetch_provider.py
- http_fetch_provider.py
- __init__.py
- failure_handler_test.py
- http_fetch_test.py
- rpc_fetch_test.py
- __init__.py
- events.py
- fetch_provider.py
- fetcher_register.py
- logger.py
- branch_tracker_test.py
- bundle_maker_test.py
- commit_viewer_test.py
- conftest.py
- diff_viewer_test.py
- repo_cloner_test.py
- repo_watcher_test.py
- __init__.py
- branch_tracker.py
- bundle_maker.py
- bundle_utils.py
- commit_viewer.py
- diff_viewer.py
- env.py
- exceptions.py
- repo_cloner.py
- tar_file_to_local_git_extractor.py
- __init__.py
- decorators.py
- filter.py
- formatter.py
- intercept.py
- redaction.py
- scrubbing.py
- thirdparty.py
- __init__.py
- apm.py
- metrics.py
- __init__.py
- data.py
- policy.py
- policy_source.py
- scopes.py
- security.py
- store.py
- webhook.py
- __init__.py
- sslcontext.py
- tarsafe.py
- __init__.py
- api_policy_source.py
- base_policy_source.py
- git_policy_source.py
- __init__.py
- expiring_redis_lock.py
- hierarchical_lock.py
- named_lock.py
- __init__.py
- hierarchical_lock_test.py
- path_utils_test.py
- redaction_test.py
- test_config.py
- test_utils.py
- url_utils_test.py
- __init__.py
- listener.py
- publisher.py
- utils.py
- __init__.py
- async_utils.py
- config.py
- corn_utils.py
- emport.py
- http_utils.py
- logger.py
- middleware.py
- paths.py
- urls.py
- utils.py
- requires.txt
- setup.py
- test_data_update_publisher.py
- __init__.py
- api.py
- data_update_publisher.py
- __init__.py
- api.py
- __init__.py
- callbacks.py
- factory.py
- task.py
- __init__.py
- api.py
- deps.py
- listener.py
- __init__.py
- __init__.py
- api.py
- loader.py
- purge.py
- scope_repository.py
- service.py
- task.py
- __init__.py
- api.py
- jwks.py
- broadcaster_consistency_integration_test.py
- broadcaster_reconnect_integration_test.py
- config_docs_drift_test.py
- debug_stats_endpoint_test.py
- debug_stats_test.py
- delete_scope_cache_purge_test.py
- delete_scope_route_test.py
- fetch_timeout_test.py
- forget_repo_test.py
- git_executor_test.py
- healthcheck_db_kill_test.py
- healthcheck_endpoint_test.py
- invalid_repo_recovery_test.py
- liveness_probe_test.py
- metrics_emission_test.py
- policy_repo_webhook_test.py
- preload_reset_test.py
- purge_channel_test.py
- reconnecting_broadcaster_test.py
- repoint_purge_test.py
- safe_connection_manager_test.py
- scope_policy_clone_wait_test.py
- scope_policy_fallback_test.py
- scopes_task_wiring_test.py
- source_backoff_test.py
- sync_scopes_perpass_test.py
- test_git_fetcher_repos_last_fetched.py
- webhook_task_cleanup_test.py
- __init__.py
- cli.py
- config.py
- debug_stats.py
- git_fetcher.py
- loadlimiting.py
- main.py
- publisher.py
- pubsub.py
- pubsub_resilience.py
- redis_utils.py
- server.py
- statistics.py
- requires.txt
- setup.py
- __packaging__.py
- requires.txt
- gunicorn_conf.py
- start.sh
- wait-for.sh
- .dockerignore
- .editorconfig
- .gitignore
- .gitmodules
- .isort.cfg
- .pre-commit-config.yaml
- cedar-agent
- CODE_OF_CONDUCT.md
- CONTRIBUTING.md
- LICENSE
- Makefile
- MANIFEST.in
- netlify.toml
- pytest.ini
- README.md
- requirements.txt
- semver2pypi.py
# Installation Guide
1. Get the code
git clone https://github.com/permitio/opal
Downloads the entire project code from GitHub to your computer.
cd opal
Moves into the project folder you just downloaded.
2. Docker
Easy RecommendedPrerequisites
- Git Needed to download the project code from GitHub.
- Docker Desktop Needed to build and run containers. Install it and keep it running in the background.
curl -L https://raw.githubusercontent.com/permitio/opal/master/docker/docker-compose-example.yml \
Runs the command against the services defined in the compose file.
> docker-compose.yml && docker compose up
Builds and starts all defined containers (server, database, etc.) at once, in the background.
<img src="https://img.shields.io/docker/pulls/permitio/opal-client?label=Docker%20pulls" alt="Docker pulls">
Type this command into your terminal and run it.
Run docker compose ps to check the containers are Up. If the README mentions a port, open http://localhost:PORT in your browser.
Pulled directly from this repo's README.
3. Python
EasyPrerequisites
pip install -r requirements.txt
Installs the Python libraries listed in requirements.txt (or similar).
python <μ€νν νμΌλͺ
>.py # READMEμμ μ νν μ€ν νμΌλͺ
μ νμΈνμΈμ
Runs the Python script (or module).
If it runs without errors and prints output in the terminal, it worked.
4. Make
MediumPrerequisites
- Git Needed to download the project code from GitHub.
- Make Usually pre-installed on Linux/macOS. On Windows, install separately (e.g. via MSYS2 or WSL).
make
Compiles the code based on the generated build configuration to produce an executable.
If it finishes without errors, it worked. Try running the generated executable directly.
// repository documentation
Was this content helpful?
(0 ratings)
