Open Policy Agent (OPA) is a free, open-source policy engine that separates policy decisions from the software that enforces them. It evaluates policies against structured input and can return structured output, with stated use cases including microservices, Kubernetes, CI/CD pipelines, and API gateways. Policies use Rego, a declarative language for expressing rules over complex hierarchical data. Applications can request evaluation through a REST API, Go API, WebAssembly, or custom evaluators using OPA's intermediate representation. OPA bundles distribute policies and data to instances, while discovery bundles distribute flexible configuration. Management interfaces support policy distribution, health and status checks, and decision logs. Listed integrations include Kubernetes, Terraform, Envoy, and code editors; the documentation recommends OPA Gatekeeper for Kubernetes admission control. Installation guidance covers macOS, Linux/Unix, Windows, and Docker. OPA's security guidance says authentication and authorization are off by default and recommends configuring TLS, authentication, and authorization when securing the API. OPA is a graduated Cloud Native Computing Foundation project and provides a Slack community for users and maintainers.
Who it is for
OPA suits developers and platform teams that need policy decisions separated from enforcement across services, Kubernetes, CI/CD, or API gateways. It may fit teams comfortable working with Rego and configuring the API security controls they need.
What is good
- Free and open source under Apache License 2.0.
- Evaluates policies over structured input and returns structured output.
- Supports REST, Go, WebAssembly, and custom evaluators.
- Management interfaces include health checks and decision logs.
- Installation options include macOS, Linux/Unix, Windows, and Docker.
What to know first
- API authentication and authorization are off by default.
- Kubernetes admission control documentation recommends OPA Gatekeeper.
- Commercial support listings are not vetted endorsements.
Verdict
OPA provides a flexible policy engine with multiple evaluation interfaces and integrations for software infrastructure. Teams securing its API need to configure authentication, authorization, and TLS rather than assume those protections are enabled by default.
Open Policy Agent plans and pricing
All plansCompared on infrastructure policy as code tools
- Policy language
- Rego
- IaC formats
- Terraform plan JSON, JSON, YAML
- Policy testing
- Yes
- Admission control
- Yes
- Runtime enforcement
- Yes
- CI/CD integration
- Yes
- Policy reporting
- Yes


