OPA & Rego
A standalone path through Open Policy Agent, the general-purpose policy engine, and its language Rego. Beginner covers the decoupled-policy model, installing OPA, Rego basics (rules, queries), and testing policies. Intermediate builds real guardrails: deny/allow patterns, data and inputs, Conftest for config/IaC, and policy testing/coverage. Advanced goes deep: OPA Gatekeeper for Kubernetes admission, the decision API and bundles, performance and safety, and secure policy delivery. Real Rego and CLI output throughout; each level ends with a self-test feeding a rotating final exam.
01
OPA fundamentals
4 lessons02
Rego patterns, data & Conftest
4 lessons03
Gatekeeper, bundles & delivery
4 lessons01Gatekeeper: Kubernetes admissionConstraints and templates in-cluster.14 min02The decision API & bundlesOPA as a service; distributing policy.12 min03Performance, safety & the landscapeFast, safe Rego; Sentinel & Kyverno.12 min04Delivering policy securelyVersion, test, and enforce guardrails.12 min
Progress is saved in this browser only — no account required.
Final exam
Test yourself on everything
14 questions drawn from all 3 sections — every answer explained as you pick.