Skip to main content

opa-golib-python-bindings

Python bindings for the OPA Rego engine, embedding github.com/open-policy-agent/opa/v1/rego via a Go c-shared library and a stdlib-only ctypes wrapper.

Build

Requires Go >= 1.26 and Python >= 3.14.

make build   # builds src/opa_bindings/libopabridge.so
make test    # builds + runs pytest

Usage

from opa_bindings import OpaEngine

users = {"alice": {"role": "admin"}}

with OpaEngine() as engine:
    engine.add_policy("authz.rego", """
package authz

allow if lookup_user(input.user).role == "admin"
""")
    engine.add_data({"admin": ["alice"]}, path="roles")   # deep-merged; conflicts raise
    engine.register_function("lookup_user", lambda name: users.get(name))

    engine.eval_document("authz.allow", {"user": "alice"})  # -> True
    engine.eval_query("x = data.roles.admin[_]")            # -> [{"x": "alice"}]

Notes:

  • add_data deep-merges objects; identical values coexist, conflicting values raise OpaError(code="merge_conflict") naming the conflicting path.
  • register_function infers arity from the callable's signature. A *args function is variadic and is called from Rego with a single array argument: many(["a", "b"]) (OPA does not support variadic builtins with return values).
  • Builtin arguments and return values are JSON-compatible objects. A callback exception becomes an evaluation error; returning is fine.
  • An undefined document raises OpaUndefinedError.
  • Pass coverage=True to eval_document / eval_query to capture a coverage report (OPA's cover tracer) in engine.last_coverage: per-file covered / not_covered line ranges plus line counts and a coverage percentage over all added policies. Evaluating without coverage=True resets it to None.
  • Pass trace=True to capture the full evaluation trace in engine.last_trace: a list of event dicts (op, location, node, locals, ...) in evaluation order. locals holds the plugged variable bindings live at each step, so the value a statement produced is visible (e.g. {"x": 6} after x := input.n * 2); a false condition appears as a Fail event at its location. An undefined document still carries its trace — the main way to see which condition failed. Note that node shows the compiler-rewritten expression (temporaries like __local0__), a statement may appear multiple times (Redo on backtracking), and tracing slows evaluation, so keep it opt-in per call. Coverage only records which statements were evaluated; traces are how to see their results.
  • Rego print(...) output is captured per evaluation: set engine.print_handler to a callable(message, location) to receive it (default: written to stderr); engine.last_prints holds the (message, location) pairs of the last eval.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

opa_golib_python_bindings-0.2.0.tar.gz (20.9 kB view details)

Uploaded Source

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

opa_golib_python_bindings-0.2.0-py3-none-manylinux_2_34_x86_64.whl (14.7 MB view details)

Uploaded Python 3manylinux: glibc 2.34+ x86-64

opa_golib_python_bindings-0.2.0-py3-none-manylinux_2_34_aarch64.whl (13.4 MB view details)

Uploaded Python 3manylinux: glibc 2.34+ ARM64

opa_golib_python_bindings-0.2.0-py3-none-macosx_11_0_x86_64.whl (8.3 MB view details)

Uploaded Python 3macOS 11.0+ x86-64

opa_golib_python_bindings-0.2.0-py3-none-macosx_11_0_arm64.whl (7.6 MB view details)

Uploaded Python 3macOS 11.0+ ARM64

File details

Details for the file opa_golib_python_bindings-0.2.0.tar.gz.

File metadata

File hashes

Hashes for opa_golib_python_bindings-0.2.0.tar.gz
Algorithm Hash digest
SHA256 db3a9dda91363e7b6d5835bbbf5d0df3fb439fa7289b99c25c383e2cc8947237
MD5 09312e8da1eb3f005eacd39ebecec9e9
BLAKE2b-256 a7a40140a9e263cd9b7c985d99aad21c1473502696eafa7bdb132bd8e37d7489

See more details on using hashes here.

Provenance

The following attestation bundles were made for opa_golib_python_bindings-0.2.0.tar.gz:

Publisher: publish.yml on phi1010/opa-golib-python-bindings

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file opa_golib_python_bindings-0.2.0-py3-none-manylinux_2_34_x86_64.whl.

File metadata

File hashes

Hashes for opa_golib_python_bindings-0.2.0-py3-none-manylinux_2_34_x86_64.whl
Algorithm Hash digest
SHA256 f54150295927509cac7bf5fd19de1d1c4ac8f80028fd144f6b37da9018442164
MD5 7dcdafa1467f9ea0f9a5065c1ffbc857
BLAKE2b-256 11a3ad471bb6bfa07ffae35eee13b9d06ba55913c8387d6a1c42d60dd088dade

See more details on using hashes here.

Provenance

The following attestation bundles were made for opa_golib_python_bindings-0.2.0-py3-none-manylinux_2_34_x86_64.whl:

Publisher: publish.yml on phi1010/opa-golib-python-bindings

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file opa_golib_python_bindings-0.2.0-py3-none-manylinux_2_34_aarch64.whl.

File metadata

File hashes

Hashes for opa_golib_python_bindings-0.2.0-py3-none-manylinux_2_34_aarch64.whl
Algorithm Hash digest
SHA256 11237543ba9ae78c75e4aad8beffb2f9ffba24365dd50052ea9c548dc9af69e6
MD5 d959c09f58d90387572be8b82f7b8f34
BLAKE2b-256 56b60936e7182115b26686fd62d9e9057a71af328979c05598c2223270bad9c4

See more details on using hashes here.

Provenance

The following attestation bundles were made for opa_golib_python_bindings-0.2.0-py3-none-manylinux_2_34_aarch64.whl:

Publisher: publish.yml on phi1010/opa-golib-python-bindings

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file opa_golib_python_bindings-0.2.0-py3-none-macosx_11_0_x86_64.whl.

File metadata

File hashes

Hashes for opa_golib_python_bindings-0.2.0-py3-none-macosx_11_0_x86_64.whl
Algorithm Hash digest
SHA256 2289a271e8db5d76d691c7c7dffa6a90e1ecb85a7d12be54017db425f4c79e21
MD5 e0ef5ecbedf7177d5815aaeb51e1636c
BLAKE2b-256 f2329ee393b04f350e517fdead0fa02361a1e438ae6e5a7433fe31b2fa2c9526

See more details on using hashes here.

Provenance

The following attestation bundles were made for opa_golib_python_bindings-0.2.0-py3-none-macosx_11_0_x86_64.whl:

Publisher: publish.yml on phi1010/opa-golib-python-bindings

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file opa_golib_python_bindings-0.2.0-py3-none-macosx_11_0_arm64.whl.

File metadata

File hashes

Hashes for opa_golib_python_bindings-0.2.0-py3-none-macosx_11_0_arm64.whl
Algorithm Hash digest
SHA256 e6b3a9d4288bb501a8aed49a48a5c3475176804e70a7193dbd0c05b93e5acb5d
MD5 11a894ef41b8ca93c1a3c75b95b7a1c4
BLAKE2b-256 65a811d7f599464ad4829721dc772ef5c83d0c1204745ebe71c2170983a00ed4

See more details on using hashes here.

Provenance

The following attestation bundles were made for opa_golib_python_bindings-0.2.0-py3-none-macosx_11_0_arm64.whl:

Publisher: publish.yml on phi1010/opa-golib-python-bindings

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.3.0

5 files

This release

0.2.0 This release

5 files

0.1.2

5 files

0.1.0

5 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page