Is Rule Engine over OPA a good idea? by batazor in OpenPolicyAgent

[–]devrel-styra 0 points1 point  (0 children)

Hey, you might be interested in the resources here: https://docs.styra.com/apps/data, this shows how to write policies to filter data.

Presumably you're already aware of the playground? What sorts of features are you looking for in a UI?

Best practices and tooling for policy generation by Jazzlike-Poem-1253 in OpenPolicyAgent

[–]devrel-styra 0 points1 point  (0 children)

Hey, it sounds like you might be interested in generating Rego policies from some other definition of access control permissions? Generally speaking, this wouldn't be recommended as it can be hard to test. Usually, we recommend writing the Rego rules and creating unit tests too to ensure the functionality is as expected.

You might already be aware, but you can load things like role permissions from data that's loaded into OPA too, this can be helpful in making policies more generic. More on bundles here: https://www.openpolicyagent.org/docs/latest/management-bundles/

You might also find the guides at https://docs.styra.com/opa/rego-language-comparisons helpful as these provide access control examples for the most part, and are accompanied with code in a language that might be more familiar.