home.social

#rego — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #rego, aggregated by home.social.

fetched live
  1. The book we wrote on Rego is unexpectedly chonky when you get the real physical thing!

    #Rego #OpenPolicyAgent #OPA

  2. The book we wrote on Rego is unexpectedly chonky when you get the real physical thing!

    #Rego #OpenPolicyAgent #OPA

  3. The book we wrote on Rego is unexpectedly chonky when you get the real physical thing!

    #Rego #OpenPolicyAgent #OPA

  4. The book we wrote on Rego is unexpectedly chonky when you get the real physical thing!

    #Rego #OpenPolicyAgent #OPA

  5. The book we wrote on Rego is unexpectedly chonky when you get the real physical thing!

    #Rego #OpenPolicyAgent #OPA

  6. Regal v0.42.0 is out! This release Brings some nice new features for editing and debugging your Rego:

    • Initial support for go to reference and renaming for symbols (function arguments and some bindings).
    • A mid-debugging 'Evaluate' feature. Use this to inspect variables and expressions in stack frames, with watch expression support in VS Code
    • A new future.keywords completion provider for import statements

    Check out the full release notes for video demos of each feature. Happy debugging!

    github.com/open-policy-agent/r

    #OPA #Regal #PolicyAsCode #Rego

  7. Regal v0.42.0 is out! This release Brings some nice new features for editing and debugging your Rego:

    • Initial support for go to reference and renaming for symbols (function arguments and some bindings).
    • A mid-debugging 'Evaluate' feature. Use this to inspect variables and expressions in stack frames, with watch expression support in VS Code
    • A new future.keywords completion provider for import statements

    Check out the full release notes for video demos of each feature. Happy debugging!

    github.com/open-policy-agent/r

    #OPA #Regal #PolicyAsCode #Rego

  8. Regal v0.42.0 is out! This release Brings some nice new features for editing and debugging your Rego:

    • Initial support for go to reference and renaming for symbols (function arguments and some bindings).
    • A mid-debugging 'Evaluate' feature. Use this to inspect variables and expressions in stack frames, with watch expression support in VS Code
    • A new future.keywords completion provider for import statements

    Check out the full release notes for video demos of each feature. Happy debugging!

    github.com/open-policy-agent/r

    #OPA #Regal #PolicyAsCode #Rego

  9. Regal v0.42.0 is out! This release Brings some nice new features for editing and debugging your Rego:

    • Initial support for go to reference and renaming for symbols (function arguments and some bindings).
    • A mid-debugging 'Evaluate' feature. Use this to inspect variables and expressions in stack frames, with watch expression support in VS Code
    • A new future.keywords completion provider for import statements

    Check out the full release notes for video demos of each feature. Happy debugging!

    github.com/open-policy-agent/r

    #OPA #Regal #PolicyAsCode #Rego

  10. Regal v0.42.0 is out! This release Brings some nice new features for editing and debugging your Rego:

    • Initial support for go to reference and renaming for symbols (function arguments and some bindings).
    • A mid-debugging 'Evaluate' feature. Use this to inspect variables and expressions in stack frames, with watch expression support in VS Code
    • A new future.keywords completion provider for import statements

    Check out the full release notes for video demos of each feature. Happy debugging!

    github.com/open-policy-agent/r

    #OPA #Regal #PolicyAsCode #Rego

  11. Prolog nezmizel. Jeho hlavní myšlenku dnes potkáváme v nástrojích, které se Prologu na první pohled nepodobají: v CodeQL pro analýzu kódu, v Rego pro policy-as-code, v Z3 pro práci s omezeními a v Leanu pro formální důkazy. Každý řeší jiný problém, ale všechny připomínají totéž: někdy je lepší popsat vztahy, pravidla, omezení nebo tvrzení než vrstvit další if.

    https://zdrojak.cz/clanky/prolog-nezmizel-jen-dnes-zije-v-jinych-nastrojich/
  12. Prolog nezmizel. Jeho hlavní myšlenku dnes potkáváme v nástrojích, které se Prologu na první pohled nepodobají: v CodeQL pro analýzu kódu, v Rego pro policy-as-code, v Z3 pro práci s omezeními a v Leanu pro formální důkazy. Každý řeší jiný problém, ale všechny připomínají totéž: někdy je lepší popsat vztahy, pravidla, omezení nebo tvrzení než vrstvit další if.

    https://zdrojak.cz/clanky/prolog-nezmizel-jen-dnes-zije-v-jinych-nastrojich/
  13. anthropic allows openclaw cli usage again but there are no performance metrics in the announcement. evaluating cel expressions server-side with no local test harness is a bad abstraction. you don't find out your policy is wrong until staging fails. #k8s #rego

    docs.openclaw.ai/providers/ant

  14. docs.docker.com/build/policies - #Docker build policies written in #Rego validate #container build conditions and fail if not met. Just put a Dockerfile.rego next to the Dockerfile (or {filename}.rego to match Dockerfile location) and it'll pick it up. No build flags necessary.

  15. docs.docker.com/build/policies - #Docker build policies written in #Rego validate #container build conditions and fail if not met. Just put a Dockerfile.rego next to the Dockerfile (or {filename}.rego to match Dockerfile location) and it'll pick it up. No build flags necessary.

  16. docs.docker.com/build/policies - build policies written in validate build conditions and fail if not met. Just put a Dockerfile.rego next to the Dockerfile (or {filename}.rego to match Dockerfile location) and it'll pick it up. No build flags necessary.

  17. docs.docker.com/build/policies - #Docker build policies written in #Rego validate #container build conditions and fail if not met. Just put a Dockerfile.rego next to the Dockerfile (or {filename}.rego to match Dockerfile location) and it'll pick it up. No build flags necessary.

  18. docs.docker.com/build/policies - #Docker build policies written in #Rego validate #container build conditions and fail if not met. Just put a Dockerfile.rego next to the Dockerfile (or {filename}.rego to match Dockerfile location) and it'll pick it up. No build flags necessary.

  19. Found while moving! Styra used to make a unique t-shirt for every #Kubecon back in the days. This was the first one made in the pandemic. Rudolph should have worn a mask though!

    #OPA #Rego

  20. Found while moving! Styra used to make a unique t-shirt for every #Kubecon back in the days. This was the first one made in the pandemic. Rudolph should have worn a mask though!

    #OPA #Rego

  21. Found while moving! Styra used to make a unique t-shirt for every #Kubecon back in the days. This was the first one made in the pandemic. Rudolph should have worn a mask though!

    #OPA #Rego

  22. Found while moving! Styra used to make a unique t-shirt for every #Kubecon back in the days. This was the first one made in the pandemic. Rudolph should have worn a mask though!

    #OPA #Rego

  23. Found while moving! Styra used to make a unique t-shirt for every #Kubecon back in the days. This was the first one made in the pandemic. Rudolph should have worn a mask though!

    #OPA #Rego

  24. I love spacelift.io for a number of reasons, namely it saves you from running #Terraform or #OpenTofu in whatever "CI" tool your company uses this week (been there, hated it) and doesn't cost an arm, leg and kidney that Terraform Cloud charge you (loved TFC until that switcharoo).

    Anyway, I've been wrapping up a thing I've been working on. Many SaaS tools allow you to send #webhooks, but rarely give you control over if, where and what is sent. Now #Spacelift let you control all of this using a Policy based on #OpenPolicyAgent.

    SL provide an event, you develop your policy in the #Rego language, not only can you use that policy to decide: Is this an event I want to send a webhook for? But more than that, you can use the policy language to craft the exact payload. Since you may not get a choice of what that looks like on the other end.

    Docs: docs.spacelift.io/concepts/pol

    Now that's just for notifications etc. You can control almost anything within the tool: Logins, Plans, Triggers, Pushes and more.

    #DevOps #SRE

  25. I love spacelift.io for a number of reasons, namely it saves you from running #Terraform or #OpenTofu in whatever "CI" tool your company uses this week (been there, hated it) and doesn't cost an arm, leg and kidney that Terraform Cloud charge you (loved TFC until that switcharoo).

    Anyway, I've been wrapping up a thing I've been working on. Many SaaS tools allow you to send #webhooks, but rarely give you control over if, where and what is sent. Now #Spacelift let you control all of this using a Policy based on #OpenPolicyAgent.

    SL provide an event, you develop your policy in the #Rego language, not only can you use that policy to decide: Is this an event I want to send a webhook for? But more than that, you can use the policy language to craft the exact payload. Since you may not get a choice of what that looks like on the other end.

    Docs: docs.spacelift.io/concepts/pol

    Now that's just for notifications etc. You can control almost anything within the tool: Logins, Plans, Triggers, Pushes and more.

    #DevOps #SRE

  26. I love spacelift.io for a number of reasons, namely it saves you from running or in whatever "CI" tool your company uses this week (been there, hated it) and doesn't cost an arm, leg and kidney that Terraform Cloud charge you (loved TFC until that switcharoo).

    Anyway, I've been wrapping up a thing I've been working on. Many SaaS tools allow you to send , but rarely give you control over if, where and what is sent. Now let you control all of this using a Policy based on .

    SL provide an event, you develop your policy in the language, not only can you use that policy to decide: Is this an event I want to send a webhook for? But more than that, you can use the policy language to craft the exact payload. Since you may not get a choice of what that looks like on the other end.

    Docs: docs.spacelift.io/concepts/pol

    Now that's just for notifications etc. You can control almost anything within the tool: Logins, Plans, Triggers, Pushes and more.

  27. I love spacelift.io for a number of reasons, namely it saves you from running #Terraform or #OpenTofu in whatever "CI" tool your company uses this week (been there, hated it) and doesn't cost an arm, leg and kidney that Terraform Cloud charge you (loved TFC until that switcharoo).

    Anyway, I've been wrapping up a thing I've been working on. Many SaaS tools allow you to send #webhooks, but rarely give you control over if, where and what is sent. Now #Spacelift let you control all of this using a Policy based on #OpenPolicyAgent.

    SL provide an event, you develop your policy in the #Rego language, not only can you use that policy to decide: Is this an event I want to send a webhook for? But more than that, you can use the policy language to craft the exact payload. Since you may not get a choice of what that looks like on the other end.

    Docs: docs.spacelift.io/concepts/pol

    Now that's just for notifications etc. You can control almost anything within the tool: Logins, Plans, Triggers, Pushes and more.

    #DevOps #SRE

  28. I love spacelift.io for a number of reasons, namely it saves you from running #Terraform or #OpenTofu in whatever "CI" tool your company uses this week (been there, hated it) and doesn't cost an arm, leg and kidney that Terraform Cloud charge you (loved TFC until that switcharoo).

    Anyway, I've been wrapping up a thing I've been working on. Many SaaS tools allow you to send #webhooks, but rarely give you control over if, where and what is sent. Now #Spacelift let you control all of this using a Policy based on #OpenPolicyAgent.

    SL provide an event, you develop your policy in the #Rego language, not only can you use that policy to decide: Is this an event I want to send a webhook for? But more than that, you can use the policy language to craft the exact payload. Since you may not get a choice of what that looks like on the other end.

    Docs: docs.spacelift.io/concepts/pol

    Now that's just for notifications etc. You can control almost anything within the tool: Logins, Plans, Triggers, Pushes and more.

    #DevOps #SRE

  29. Using or trialling OPA? We want to hear from you in our 2025 Community Survey.

    surveymonkey.com/r/SCBSDZN

    Whether you're new to OPA or have been on the Rego train for years, hearing about how you use OPA projects will help us share OPA for the months and years to come.

    We're going to be at KubeCon tomorrow in the project pavilion. Come and say hi!

    #Rego #OPA #OpenPolicyAgent #KubeCon #CloudNativeCon

  30. Using or trialling OPA? We want to hear from you in our 2025 Community Survey.

    surveymonkey.com/r/SCBSDZN

    Whether you're new to OPA or have been on the Rego train for years, hearing about how you use OPA projects will help us share OPA for the months and years to come.

    We're going to be at KubeCon tomorrow in the project pavilion. Come and say hi!

    #Rego #OPA #OpenPolicyAgent #KubeCon #CloudNativeCon

  31. Using or trialling OPA? We want to hear from you in our 2025 Community Survey.

    surveymonkey.com/r/SCBSDZN

    Whether you're new to OPA or have been on the Rego train for years, hearing about how you use OPA projects will help us share OPA for the months and years to come.

    We're going to be at KubeCon tomorrow in the project pavilion. Come and say hi!

    #Rego #OPA #OpenPolicyAgent #KubeCon #CloudNativeCon

  32. Политики над конфигами (OPA/Rego) в GitOps-пайплайне

    Привет, Хабр! Представим, что вы отвечаете за десятки конфигурационных файлов Kubernetes (или Terraform, Ansible, не суть важно) в репозитории, и каждый pull request может потенциально привести к тому, что в кластер уйдёт что-то не то. Наш любимый коллега случайно поставил контейнер с privileged -правами, другой задеплоил образ из публичного репозитория Docker Hub, а третий вовсе забыл про лимиты памяти и CPU. Без автоматического контроля такие промахи легко попадут в продакшн. Ошибки в настройках сегодня одна из главных причин инцидентов безопасности в облачных средах. Как же нам держать всё под контролем? Внедрить политики как код: формализованные правила, проверяемые автоматически на каждом шаге. В этой статье я расскажу, как применять Open Policy Agent и язык Rego, чтобы навести порядок в GitOps-пайплайне и не допускать лишнего в конфигурациях. Читать про внедрение политик в GitOps

    habr.com/ru/companies/otus/art

    #gitops #Open_Policy_Agent #Rego #Policy_as_Code #политики_как_код

  33. Политики над конфигами (OPA/Rego) в GitOps-пайплайне

    Привет, Хабр! Представим, что вы отвечаете за десятки конфигурационных файлов Kubernetes (или Terraform, Ansible, не суть важно) в репозитории, и каждый pull request может потенциально привести к тому, что в кластер уйдёт что-то не то. Наш любимый коллега случайно поставил контейнер с privileged -правами, другой задеплоил образ из публичного репозитория Docker Hub, а третий вовсе забыл про лимиты памяти и CPU. Без автоматического контроля такие промахи легко попадут в продакшн. Ошибки в настройках сегодня одна из главных причин инцидентов безопасности в облачных средах. Как же нам держать всё под контролем? Внедрить политики как код: формализованные правила, проверяемые автоматически на каждом шаге. В этой статье я расскажу, как применять Open Policy Agent и язык Rego, чтобы навести порядок в GitOps-пайплайне и не допускать лишнего в конфигурациях. Читать про внедрение политик в GitOps

    habr.com/ru/companies/otus/art

    #gitops #Open_Policy_Agent #Rego #Policy_as_Code #политики_как_код

  34. Политики над конфигами (OPA/Rego) в GitOps-пайплайне

    Привет, Хабр! Представим, что вы отвечаете за десятки конфигурационных файлов Kubernetes (или Terraform, Ansible, не суть важно) в репозитории, и каждый pull request может потенциально привести к тому, что в кластер уйдёт что-то не то. Наш любимый коллега случайно поставил контейнер с privileged -правами, другой задеплоил образ из публичного репозитория Docker Hub, а третий вовсе забыл про лимиты памяти и CPU. Без автоматического контроля такие промахи легко попадут в продакшн. Ошибки в настройках сегодня одна из главных причин инцидентов безопасности в облачных средах. Как же нам держать всё под контролем? Внедрить политики как код: формализованные правила, проверяемые автоматически на каждом шаге. В этой статье я расскажу, как применять Open Policy Agent и язык Rego, чтобы навести порядок в GitOps-пайплайне и не допускать лишнего в конфигурациях. Читать про внедрение политик в GitOps

    habr.com/ru/companies/otus/art

    #gitops #Open_Policy_Agent #Rego #Policy_as_Code #политики_как_код

  35. Took a walk with Harry today, and we spotted a car evidently owned by a person of culture.

    #rego

  36. Took a walk with Harry today, and we spotted a car evidently owned by a person of culture.

    #rego

  37. Took a walk with Harry today, and we spotted a car evidently owned by a person of culture.

    #rego

  38. Took a walk with Harry today, and we spotted a car evidently owned by a person of culture.

    #rego

  39. Took a walk with Harry today, and we spotted a car evidently owned by a person of culture.

    #rego

  40. On my way to present on #OPA and #Rego for the #CloudNative #Mauritius community. Sadly not in person ☀️ but virtually from cloudy Stockholm. Still, looking forward to getting to do some live coding!