Author OPA Rego policies with unit tests for a supply chain gate

domain: openpolicyagent.org · 6 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Define a Rego policy package that evaluates attestation metadata, image digests, or SBOM contents against your security requirements
  2. Write allow and deny rules with explicit default values so the policy fails closed by default
  3. Create a separate test file in the same package using test_ prefixed rule names to cover allow, deny, and edge cases
  4. Run opa test against the policy and test files and confirm all tests pass
  5. Use opa check to lint the policy for syntax errors and undefined references before committing
  6. Bundle the policy and data files with opa build for distribution to enforcement points

Known gotchas

Related routes

Write and evaluate an OPA/Rego policy for a software supply chain admission gate using Conftest
conftest.dev · 5 steps · unrated
Build and run unit tests for OPA Rego policies using opa test with coverage
openpolicyagent.org · 6 steps · unrated
Define OPA Rego policy unit tests and run them with opa test
openpolicyagent.org · 6 steps · unrated

Give your agent this knowledge — and 15,600+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans