-
Notifications
You must be signed in to change notification settings - Fork 26
Add extensible source providers #429
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
ashutosh-narkar
merged 1 commit into
open-policy-agent:main
from
ashutosh-narkar:ext-source-provider
Sep 30, 2026
Merged
Changes from all commits
Commits
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,41 @@ | ||
| # A providers entry, handled by the E2E test source provider (see | ||
| # provider_test.go): its data goes under its path, its Rego keeps its | ||
| # package, and its metadata is available to the revision template. | ||
| exec opactl-with-providers build --config config.d/bundle.yml --data-dir tmp --non-interactive | ||
| ! stderr . | ||
| ! stdout . | ||
|
|
||
| exec tar tf bundles/app/bundle.tar.gz | ||
| cmp stdout exp/tarball | ||
|
|
||
| exec tar xf bundles/app/bundle.tar.gz | ||
| exec jq -e '.revision == "v1" and (.roots | sort) == ["authz", "users"]' .manifest | ||
| exec jq -e '. == {"users": {"alice": ["admin"]}}' data.json | ||
|
|
||
| -- config.d/bundle.yml -- | ||
| bundles: | ||
| app: | ||
| object_storage: | ||
| filesystem: | ||
| path: bundles/app/bundle.tar.gz | ||
| revision: input.sources.app.providers.users.version | ||
| requirements: | ||
| - source: app | ||
| sources: | ||
| app: | ||
| providers: | ||
| - name: users | ||
| type: e2e.files | ||
| path: users | ||
| files: | ||
| data.json: '{"alice": ["admin"]}' | ||
| authz.rego: | | ||
| package authz | ||
| import rego.v1 | ||
| allow if input.user in data.users.alice | ||
| metadata: | ||
| version: v1 | ||
| -- exp/tarball -- | ||
| /data.json | ||
| /app/users/authz.rego | ||
| /.manifest |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,33 @@ | ||
| # A providers entry contributing manifest metadata, a root it has no files | ||
| # for, and its Rego version (the policy uses v1 syntax without importing | ||
| # rego.v1). | ||
| exec opactl-with-providers build --config config.d/bundle.yml --data-dir tmp --non-interactive | ||
| ! stderr . | ||
| ! stdout . | ||
|
|
||
| exec tar xf bundles/app/bundle.tar.gz | ||
| exec jq -e '.rego_version == 1 and .metadata == {"example": {"version": "v1"}} and (.roots | sort) == ["authz", "lazy/remote"]' .manifest | ||
|
|
||
| -- config.d/bundle.yml -- | ||
| bundles: | ||
| app: | ||
| object_storage: | ||
| filesystem: | ||
| path: bundles/app/bundle.tar.gz | ||
| requirements: | ||
| - source: app | ||
| sources: | ||
| app: | ||
| providers: | ||
| - name: users | ||
| type: e2e.files | ||
| files: | ||
| authz.rego: | | ||
| package authz | ||
| allow if input.user == "alice" | ||
| contribution: | ||
| metadata: | ||
| example: | ||
| version: v1 | ||
| roots: [lazy/remote] | ||
| rego_version: 1 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,45 @@ | ||
| # Changing an entry's path leaves nothing from the old path in the bundle: | ||
| # the entry's directory is emptied before every sync. Both builds share the | ||
| # same data directory. | ||
| exec opactl-with-providers build --config config.d/old.yml --data-dir tmp --non-interactive | ||
| exec tar xf bundles/app/bundle.tar.gz | ||
| exec jq -e '. == {"old": {"v": 1}}' data.json | ||
|
|
||
| exec opactl-with-providers build --config config.d/new.yml --data-dir tmp --non-interactive | ||
| ! stderr . | ||
| ! stdout . | ||
| exec tar xf bundles/app/bundle.tar.gz | ||
| exec jq -e '. == {"new": {"v": 2}}' data.json | ||
|
|
||
| -- config.d/old.yml -- | ||
| bundles: | ||
| app: | ||
| object_storage: | ||
| filesystem: | ||
| path: bundles/app/bundle.tar.gz | ||
| requirements: | ||
| - source: app | ||
| sources: | ||
| app: | ||
| providers: | ||
| - name: users | ||
| type: e2e.files | ||
| path: old | ||
| files: | ||
| data.json: '{"v": 1}' | ||
| -- config.d/new.yml -- | ||
| bundles: | ||
| app: | ||
| object_storage: | ||
| filesystem: | ||
| path: bundles/app/bundle.tar.gz | ||
| requirements: | ||
| - source: app | ||
| sources: | ||
| app: | ||
| providers: | ||
| - name: users | ||
| type: e2e.files | ||
| path: new | ||
| files: | ||
| data.json: '{"v": 2}' |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,20 @@ | ||
| # opactl registers no custom source types, so any providers entry is | ||
| # rejected when the configuration is loaded. | ||
| ! exec $OPACTL build --config config.d/bundle.yml --data-dir tmp --non-interactive | ||
| stderr '^invalid configuration: source "app": provider "users": unknown type "example.custom-source"' | ||
| ! stdout . | ||
|
|
||
| -- config.d/bundle.yml -- | ||
| bundles: | ||
| hello-world: | ||
| object_storage: | ||
| filesystem: | ||
| path: bundles/hello-world/bundle.tar.gz | ||
| requirements: | ||
| - source: app | ||
| sources: | ||
| app: | ||
| providers: | ||
| - name: users | ||
| type: example.custom-source | ||
| param1: value | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,46 @@ | ||
| # A git repository and a providers entry in the same source. | ||
| cd repo | ||
| env HOME=. | ||
| exec git init . | ||
| exec git branch -m main | ||
| exec git config --global user.name "botbotbot" | ||
| exec git config --global user.email "bot@bot.bot" | ||
| exec git add . | ||
| exec git commit -m initial-commit | ||
| cd .. | ||
|
|
||
| exec opactl-with-providers build --config config.d/bundle.yml --data-dir tmp --non-interactive | ||
| ! stderr . | ||
| ! stdout . | ||
|
|
||
| exec tar xf bundles/app/bundle.tar.gz | ||
| exec jq -e '.revision == "git-v1" and (.roots | sort) == ["rules", "users"]' .manifest | ||
| exec jq -e '. == {"users": {"alice": ["admin"]}}' data.json | ||
| exists app/policy.rego | ||
|
|
||
| -- repo/policy.rego -- | ||
| package rules | ||
| import rego.v1 | ||
| allow if input.user in data.users.alice | ||
| -- config.d/bundle.yml -- | ||
| bundles: | ||
| app: | ||
| object_storage: | ||
| filesystem: | ||
| path: bundles/app/bundle.tar.gz | ||
| revision: $"git-{input.sources.app.providers.users.version}" | ||
| requirements: | ||
| - source: app | ||
| sources: | ||
| app: | ||
| git: | ||
| repo: ./repo/ | ||
| reference: refs/heads/main | ||
| providers: | ||
| - name: users | ||
| type: e2e.files | ||
| path: users | ||
| files: | ||
| data.json: '{"alice": ["admin"]}' | ||
| metadata: | ||
| version: v1 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Would it be possible to have a provider registered for E2E test purposes? So we could have a positive tests here, too.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Added tests.