{"id":93949,"date":"2020-04-20T13:40:28","date_gmt":"2020-04-20T05:40:28","guid":{"rendered":"http:\/\/4563.org\/?p=93949"},"modified":"2020-04-20T13:40:28","modified_gmt":"2020-04-20T05:40:28","slug":"opa-%e8%bf%9b%e9%98%b6-%e5%88%86%e5%b8%83%e5%bc%8f%e5%88%a9%e5%99%a8-bundle","status":"publish","type":"post","link":"http:\/\/4563.org\/?p=93949","title":{"rendered":"OPA \u8fdb\u9636-\u5206\u5e03\u5f0f\u5229\u5668 Bundle"},"content":{"rendered":"<div>\n<div>\n<div>\n<h1>                  OPA \u8fdb\u9636-\u5206\u5e03\u5f0f\u5229\u5668 Bundle               <\/h1>\n<p> <\/p>\n<div>\n<div> <span>\u8cc7\u6df1\u5927\u4f6c : newmiao <\/span>  <span><i><\/i> 20<\/span> <\/div>\n<div> <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div isfirst=\"1\"> <\/p>\n<p><code>Bundle<\/code>\u662f<code>OPA<\/code>\u7ba1\u7406<code>policy<\/code>\u548c<code>data<\/code>\u7684\u4e00\u79cd\u65b9\u5f0f\u3002<\/p>\n<p><code>OPA<\/code>\u5b9e\u73b0\u7684\u8f7b\u91cf\u7ea7\u7b56\u7565\u5f15\u64ce\uff0c\u4e00\u5f00\u59cb\u5c31\u662f\u4e3a\u4e86\u4e91\u539f\u751f\u73af\u5883\u7684<code>service<\/code>\u63d0\u4f9b\u89e3\u8026\u7684\u7b56\u7565\u670d\u52a1\uff0c\u5206\u5e03\u5f0f\u662f\u5fc5\u7136\u8981\u8003\u8651\u7684\u95ee\u9898\u3002<\/p>\n<p>\u5728<code>Bundle api<\/code>\u7684\u8bbe\u8ba1\u4e2d\uff0c\u5176\u5b9e\u5c31\u5168\u9762\u8003\u8651\u5e76\u4f53\u73b0\u4e86\u5728\u5206\u5e03\u5f0f\u5e94\u7528\u4e2d\u5982\u4f55\u66f4\u597d\u7684\u89e3\u8026\u7b56\u7565\u5f15\u64ce\u7684\u7ba1\u7406\u3002<\/p>\n<p>\u6bd4\u5982\uff1a<\/p>\n<ul>\n<li>\u5982\u4f55\u505a\u96c6\u4e2d\u914d\u7f6e\u7ba1\u7406<\/li>\n<li>\u5982\u4f55\u52a8\u6001\u66f4\u65b0\u7b56\u7565<\/li>\n<li>\u5982\u4f55\u76d1\u63a7\u7b56\u7565\u5f15\u64ce\u8282\u70b9\u7684\u72b6\u6001\u4ee5\u53ca\u51b3\u7b56\u65e5\u5fd7\u6536\u96c6<\/li>\n<\/ul>\n<p>\u6709\u4e86\u8fd9\u4e9b\u529f\u80fd\uff0c\u518d\u52a0\u4e0a\u5176\u9ad8\u6548\u7684\u7b56\u7565\u63cf\u8ff0\u8bed\u8a00<code>Rego<\/code>\uff0c<code>OPA<\/code>\u624d\u771f\u6b63\u79f0\u5f97\u4e0a\u662f<strong>\u4e91\u539f\u751f\u65f6\u4ee3\u7684\u901a\u7528\u7b56\u7565\u5f15\u64ce<\/strong>\u3002<\/p>\n<p>\u672c\u6587\u5c06\u5e26\u5927\u5bb6\u7b80\u5355\u68b3\u7406\u4e00\u904d<code>Bundle<\/code>\u7684\u7ec4\u7ec7\u65b9\u5f0f\u3001\u7ba1\u7406 api \u3001\u53ca\u76d1\u63a7\u65b9\u5f0f\u3002<\/p>\n<p>\u8003\u8651\u5230\u4e00\u6b21\u6027\u8fc7\u5b8c\u4e0d\u6613\u6d88\u5316\uff0c\u6587\u672b\u4f1a\u63d0\u4f9b\u4e00\u4e2a\u76f4\u63a5\u53ef\u5b9e\u64cd\u7684<code>docker-compose<\/code>\u7248\u672c\u7684<code>demo<\/code>\uff0c\u5c06\u5168\u9762\u8986\u76d6\u672c\u6587\u7ec6\u8282<\/p>\n<p>\u5efa\u8bae\u5927\u5bb6\u770b\u5b8c\u672c\u6587\uff0c\u672c\u673a\u8fd0\u884c\u53bb\u4f53\u9a8c\u4e00\u4e0b\uff0c\u4f1a\u6709\u66f4\u76f4\u89c2\u7684\u7406\u89e3\u3002<\/p>\n<p><strong>\u6587\u7ae0\u76ee\u5f55<\/strong><\/p>\n<ul>\n<li>Bundle \u6587\u4ef6\u7ec4\u7ec7\u65b9\u5f0f<\/li>\n<li>opa server api<\/li>\n<li>Bundle \u7ba1\u7406 api<\/li>\n<li>Bundle \u96c6\u6210\u65b9\u5f0f\n<ul>\n<li>opa server \u65b9\u5f0f<\/li>\n<li>go lib \u65b9\u5f0f<\/li>\n<\/ul>\n<\/li>\n<li>Bundle \u7684\u76d1\u63a7<\/li>\n<li>Bundle in action<\/li>\n<\/ul>\n<h2>Bundle \u6587\u4ef6\u7ec4\u7ec7\u65b9\u5f0f<\/h2>\n<p>\u4e0b\u9762\u6211\u4eec\u5148\u6765\u770b\u4e0b<code>Bundle<\/code>\u7684\u6587\u4ef6\u7ec4\u7ec7\u65b9\u5f0f<\/p>\n<p>\u5728<code>Bundle<\/code>\u4e0b\u7684<code>data<\/code>,\u53ea\u80fd\u88ab\u8bc6\u522b<code>data.json<\/code>\u548c<code>data.yaml<\/code>\u7684\u6587\u4ef6, \u800c\u5176\u4e0a\u8fb9\u7684\u76ee\u5f55\u4f1a\u4f5c\u4e3a\u5176\u6570\u636e\u524d\u7f00<\/p>\n<p>\u5982\u4e0b\u8fb9<code>roles\/data.json<\/code> (<code>bundle\/example<\/code>\u4f5c\u4e3a\u4e00\u4e2a<code>bundle<\/code>)\uff0c\u4f1a\u5c06<code>data.json<\/code>\u7684\u6570\u636e\u6302\u5728<code>data.roles<\/code>\u8282\u70b9\u4e0b<\/p>\n<pre><code>cd bundle\/example tree -a . \u251c\u2500\u2500 .manifest \u251c\u2500\u2500 bindings \u2502   \u2514\u2500\u2500 data.json \u251c\u2500\u2500 main.rego \u251c\u2500\u2500 rbac.rego \u2514\u2500\u2500 roles     \u2514\u2500\u2500 data.json <\/code><\/pre>\n<p>\u5176\u4e2d<code>.manifest<\/code>\u6587\u4ef6\u662f<code>Bundle<\/code>\u7684\u4e00\u4e2a\u53ef\u9009\u7684\u5143\u6570\u636e\uff08<code>metadata<\/code>\uff09\u914d\u7f6e\u6587\u4ef6<\/p>\n<pre><code>cat .manifest {   \"revision\" : \"9f160bcd446bf50b1b17b570c322198a68d8e106\",   \"roots\": [\"roles\", \"bindings\",\"rbac\",\"system\"] } <\/code><\/pre>\n<p>\u5b83\u7684\u4f5c\u7528\u662f\u58f0\u660e<code>Bundle<\/code>\u7684\u7248\u672c<code>revision<\/code>\u53ca\u5176\u4e0b\u7684\u8def\u5f84\u524d\u7f00\uff08<code>roots: path prefix<\/code>\uff09<\/p>\n<p><code>roots<\/code>\u4e0d\u4ec5\u89c4\u5b9a\u4e86<code>Bundle<\/code>\u5e94\u8be5\u6709\u7684\u8def\u5f84\u524d\u7f00\uff1b\u5728\u7528<code>Bundle api<\/code>\uff08\u540e\u8fb9\u4f1a\u63d0\u5230\uff09\u66f4\u65b0\u6587\u4ef6\u65f6\uff0c\u4e5f\u4f1a\u6309\u5176\u89c4\u5b9a\u7684\u8def\u5f84\u524d\u7f00\u6765\u66f4\u65b0\u6587\u4ef6<\/p>\n<p>\u7136\u540e<code>bundle<\/code>\u4e5f\u652f\u6301<code>tarball<\/code>\u683c\u5f0f\u52a0\u8f7d\u5230<code>server<\/code><\/p>\n<p>\u4f8b\u5982<code>opa run -b<\/code>\u7684\u65b9\u5f0f\u6307\u5b9a<code>Bundle<\/code><\/p>\n<pre><code>cd bundle\/example tar -czf bundle.tar.gz . opa run -b bundle.tar.gz <\/code><\/pre>\n<blockquote>\n<p>Tips: \u5173\u4e8e\u5982\u4f55\u5728\u4ea4\u4e92\u5f0f\u547d\u4ee4\u884c\u91cc\u4f20\u9012<code>input<\/code>\u3002 \u4e4b\u524d\u975e bundle \u4f7f\u7528 <code>opa run quick-start repl.input:quick-start\/input.json<\/code> \u5230 bundle \u683c\u5f0f\u65f6\uff0c\u5c31\u9700\u8981\u6784\u5efa <strong><code>repl\/input\/data.json<\/code><\/strong> \u6587\u4ef6\u683c\u5f0f\u4f5c\u4e3a\u8f93\u5165<\/p>\n<\/blockquote>\n<p>\u5177\u4f53\u53ef\u4ee5\u7528\u65f6\u53c2\u8003\u6587\u6863bundle-file-format<\/p>\n<h2>opa server api<\/h2>\n<p>\u5728\u4e86\u89e3<code>Bundle<\/code>\u652f\u6301\u7684\u7ba1\u7406 api \u524d\uff0c\u6211\u4eec\u5148\u770b\u4e0bopa server api<\/p>\n<p>\u4e3b\u8981 api \u5982\u4e0b\uff1a<\/p>\n<p>| type | \u7528\u9014 | | &#8212;- | &#8212;- | | Data api| \u67e5\u8be2\u6587\u6863\uff08\u80fd\u88ab\u8f93\u51fa\u7684\u89c4\u5219\u3001\u865a\u62df\u6587\u6863\u7b49\uff09| | Policy api| \u67e5\u8be2\u7b56\u7565| | Query api| \u6267\u884c\u547d\u4ee4| | Compile api| \u6267\u884c\u90e8\u5206\u67e5\u8be2\u8ba1\u7b97\uff08<code>partial evaluate query<\/code>\uff09| | Health api| \u5065\u5eb7\u68c0\u67e5| | Metric api| \u6307\u6807\u7edf\u8ba1\uff08<code>prometheus<\/code>\u683c\u5f0f)|<\/p>\n<p>\u4e0b\u9762\u6211\u4eec\u4ee5\u6587\u6863\u67e5\u8be2\uff08<code>Data<\/code>\uff09 api \u4e3a\u4f8b\u5c1d\u8bd5\u4e0b\uff1a<\/p>\n<p>\u6211\u4eec\u5148\u7528\u4e4b\u524d<code>quick-start<\/code>\u7684\u4ee3\u7801\u8d77\u4e00\u4e2a<code>opa sever<\/code><\/p>\n<pre><code>opa run --server quick-start <\/code><\/pre>\n<p>(\u6ce8\u610f\uff1a<code>opa server api<\/code>\u7684\u8def\u5f84\u524d\u7f00\u4e3a<code>\/v1\/<\/code>, \u5bf9\u5e94\u7684\uff0c\u67e5\u8be2 api \u8def\u5f84\u524d\u7f00\u4e3a<code>\/v1\/data\/<\/code>,)<\/p>\n<pre><code># \u6784\u9020 input \u8f93\u51fa\u8bf7\u6c42 cat &lt;&lt;EOF &gt; v1-data-input.json {     \"input\": $(cat quick-start\/input.json) } EOF # \u67e5\u8be2 example_rbac curl -s  http:\/\/0.0.0.0:8181\/v1\/data\/example_rbac?pretty=true -d @v1-data-input.json  {   \"result\": {     \"allow\": true,     \"role_has_permission\": [       \"widget-reader\"     ],     \"user_has_role\": [       \"widget-reader\"     ]   } } <\/code><\/pre>\n<blockquote>\n<p>Tips\uff1a\u4e0d\u6307\u5b9a\u8def\u5f84\u65f6\uff0c\u9ed8\u8ba4\u8def\u5f84\u4e3a<code>data.system.main<\/code>\uff0c\u8fd9\u65f6\u8f93\u5165\u4e0d\u9700\u8981\u5305\u88f9\u5728<code>input<\/code> key \u5185\u3002 \u4e5f\u53ef\u4ee5\u4f7f\u7528<code>--set<\/code> \u548c <code>--set-file<\/code> \u53ef\u4ee5\u8986\u76d6\u914d\u7f6e\u6587\u4ef6\u4e2d\u7684\u914d\u7f6e <code>opa run --server --set=default_decision=example_rbac\/allow\/ quick-start<\/code> <code>curl -s http:\/\/0.0.0.0:8181\/ -d @quick-start\/input.json<\/code><\/p>\n<\/blockquote>\n<p>\u800c\u4e14 Data \u67e5\u8be2\u4e5f\u652f\u6301\u7ec4\u5408\u53c2\u6570\u5982<code>explain<\/code>,<code>metrics<\/code>,<code>provenance<\/code>\u7b49\uff0c\u8be6\u7ec6\u67e5\u770b\u6587\u6863\uff0c\u8fd9\u91cc\u5c31\u4e0d\u5c55\u5f00\u4e86\u3002<\/p>\n<h2>Bundle \u7ba1\u7406 api<\/h2>\n<p><code>Bundle<\/code>\u4e3a\u4e86\u5728\u5206\u5e03\u5f0f\u7cfb\u7edf\u4e2d\u66f4\u597d\u7684\u5c55\u73b0 OPA \u7684\u5a01\u529b\uff0c\u63d0\u4f9b\u4e86\u56db\u79cd Api\uff1a<\/p>\n<ul>\n<li>Bundles \u7528\u4e8e\u7b56\u7565\u5206\u53d1\uff0c\u53ef\u4ee5\u5b9a\u65f6\u8f6e\u8bad\u66f4\u65b0<code>Bundle<\/code>\u5305<\/li>\n<li>Decision Logs \u5b9a\u671f\u4e0a\u4f20\u65e5\u5fd7\u5305\uff0c\u652f\u6301\u6309\u5927\u5c0f\u5206\u7247\uff0c\u5f00\u542f\u540e\u4f1a\u6709\u65e5\u5fd7 id\uff0c\u51b3\u7b56\u65e5\u5fd7\u53ef\u8ffd\u6eaf<\/li>\n<li>Status \u5b9a\u671f\u4e0a\u4f20\u670d\u52a1\u72b6\u6001\uff0c\u5305\u542b<code>metrics<\/code>\u7b49\u4fe1\u606f<\/li>\n<li>Discovery \u670d\u52a1\u53d1\u73b0\uff0c\u53ef\u4ee5\u7528\u4e8e\u96c6\u4e2d\u7ba1\u7406<code>OPA<\/code>\u7684<code>Bundle<\/code>\u914d\u7f6e\uff0c\u5404\u4e2a\u8282\u70b9\u4e0b\u8f7d\u5b9a\u671f\u540c\u6b65\u914d\u7f6e\u540e\uff0c\u6309\u914d\u7f6e\u53bb\u66f4\u65b0<code>Bundle<\/code><\/li>\n<\/ul>\n<p>\u5982\u4e0b\u56fe\uff1a<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/4563.org\/wp-content\/uploads\/2020\/05\/20200519_5ec460b21e7fe.png\" alt=\"OPA \u8fdb\u9636-\u5206\u5e03\u5f0f\u5229\u5668 Bundle\" \/><\/p>\n<p>\u8fd9\u91cc\u4e3e\u4e2a\u5e26\u6ce8\u91ca<code>Bundle<\/code>\u7684\u56db\u79cd\u63a5\u53e3\u914d\u7f6e\u4f8b\u5b50<\/p>\n<p>\uff08\u5148\u626b\u4e00\u904d\u7559\u4e2a\u5370\u8c61\uff0c\u5177\u4f53\u4f7f\u7528\u65f6\u67e5\u770b\u6587\u6863\uff0c\u540e\u8fb9\u4f1a\u63d0\u4f9b\u53ef\u5b9e\u64cd\u7684\u4ee3\u7801\uff09<\/p>\n<pre><code># opa\/config-bundle.yaml services:   # \u5b9a\u4e49\u670d\u52a1\uff0c\u652f\u6301\u591a\u4e2a   - name: example_bundle     url: http:\/\/demo-server:8888\/  labels:   app: myapp  bundles:   # \u5b9a\u4e49 bundle, \u652f\u6301\u591a\u4e2a   authz:     # bundle \u6240\u5904\u7684\u670d\u52a1     service: example_bundle     # \u8fd9\u91cc\u6307\u4ece resource \u5904\u66f4\u65b0 bundle \u6587\u4ef6\u5305\uff0c\u5373\uff1a     # http:\/\/demo-server:8888\/bundle\/rbac.tar.gz     resource: bundle\/rbac.tar.gz     polling:       # 300~600s \u95f4\u66f4\u65b0\u4e00\u6b21       min_delay_seconds: 300       max_delay_seconds: 600  decision_logs:   service: example_bundle   # partition_name \u4e3a\u533a\u5206\u4e0a\u4f20\u5730\u5740,\u4f1a\u8ddf\u5230 \/logs \u540e, \u5373\uff1a   # http:\/\/demo-server:8888\/logs\/bundle   # \u6ce8\u610f\u4e0a\u4f20\u7684\u662f gzip \u65e5\u5fd7\u6587\u4ef6   partition_name: bundle   reporting:     min_delay_seconds: 30     max_delay_seconds: 60  status:   service: example_bundle   # \u5373 http:\/\/demo-server:8888\/status\/bundle   partition_name: bundle  # \u9ed8\u8ba4\u67e5\u8be2\u8def\u5f84 default_decision: rbac\/allow <\/code><\/pre>\n<h2>Bundle \u96c6\u6210\u65b9\u5f0f<\/h2>\n<p>\u8fd9\u91cc\u6211\u4eec\u7b80\u5355\u8fc7\u4e0b\u96c6\u6210\u65b9\u5f0f<\/p>\n<h3>opa server \u65b9\u5f0f<\/h3>\n<p>\u8fd0\u884c\u65b9\u5f0f\u5f88\u7b80\u5355\u5982\u4e0b\uff1a<\/p>\n<pre><code>opa run -s -a 0.0.0.0:8181 -c opa\/config-bundle.yaml <\/code><\/pre>\n<p>\u8fd0\u884c\u540e\uff0copa server \u4f1a\u6839\u636e\u914d\u7f6e\u81ea\u52a8\u62c9\u53d6<code>Bundle<\/code>\u5305\uff1a<code>rbac.tar.gz<\/code><\/p>\n<p>\u4e0b\u8f7d\u6210\u529f\u540e\u542f\u52a8\u7b56\u7565\u670d\u52a1\u3002\u540c\u65f6\u5b9a\u671f\u4e0a\u4f20\u51b3\u7b56\u65e5\u5fd7\u548c\u72b6\u6001\u7ed9\u670d\u52a1\u7aef\uff08\u5373\uff1a<code>demo-server:8888<\/code>\uff09<\/p>\n<h3>go lib \u65b9\u5f0f<\/h3>\n<p>\u4f7f\u7528 lib <code>github.com\/open-policy-agent\/opa\/rego<\/code>\u96c6\u6210<\/p>\n<p>\u5173\u952e\u4ee3\u7801\u4e3e\u4f8b\u5982\u4e0b\uff1a<\/p>\n<pre><code>\/\/ \u6784\u5efa\u67e5\u8be2\uff0cPrepareForEval \u53ef\u91cd\u7528 var err error query, err := rego.New(     rego.LoadBundle(\".\/rbac.tar.gz\"),     rego.Query(\"x = data.rbac.allow\"), ).PrepareForEval(context.Background())  \/\/ \u6267\u884c\u67e5\u8be2 results, err := query.Eval(context.Background(), rego.EvalInput(input)) if err != nil {     fmt.Fatalln(\"Opa eval error:\", err)     return } else if len(results) == 0 {     fmt.Fatalln(\"Opa eval error: no result\")     return }  fmt.Println(\"Opa result:\", results[0].Expressions[0].Value) <\/code><\/pre>\n<p>\u5177\u4f53\u7ec4\u7ec7\u65b9\u5f0f\u5b98\u65b9\u63a8\u8350\u7684\u6709\u4e0b\u8fb9<strong>\u96c6\u4e2d\u5f0f<\/strong>\u548c<strong>\u5206\u5e03\u5f0f<\/strong>\u8fd9\u4e24\u79cd\uff1a<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/4563.org\/wp-content\/uploads\/2020\/05\/20200519_5ec460b6cc7ac.png\" alt=\"OPA \u8fdb\u9636-\u5206\u5e03\u5f0f\u5229\u5668 Bundle\" \/><\/p>\n<p><img decoding=\"async\" src=\"http:\/\/4563.org\/wp-content\/uploads\/2020\/05\/20200519_5ec460bc9594a.png\" alt=\"OPA \u8fdb\u9636-\u5206\u5e03\u5f0f\u5229\u5668 Bundle\" \/><\/p>\n<p>\u63a8\u8350\u611f\u5174\u8da3\u7684\u540c\u5b66\u518d\u53bb\u770b\u4e0b\u5b98\u65b9 go \u96c6\u6210\u7684 demo: example-api-authz-go<\/p>\n<h2>Bundle \u7684\u76d1\u63a7<\/h2>\n<p>opa server \u652f\u6301<code>metrics<\/code>, \u800c\u4e14\u662f<code>prometheus<\/code>\u683c\u5f0f\u7684<\/p>\n<p>\u6240\u4ee5\u914d\u5408<code>prometheus<\/code>\u53ef\u4ee5\u76f4\u63a5\u8fdb\u884c\u5bf9\u5176\u6570\u636e\u6307\u6807\u7684\u76d1\u63a7\uff0c\u5982\u4e0b\u56fe\uff1a<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/4563.org\/wp-content\/uploads\/2020\/05\/20200519_5ec460c20afe4.png\" alt=\"OPA \u8fdb\u9636-\u5206\u5e03\u5f0f\u5229\u5668 Bundle\" \/><\/p>\n<p>\u518d\u914d\u5408<code>grafana<\/code>\u7684<code>dashbord<\/code>\u53ef\u4ee5\u66f4\u597d\u7684\u5c55\u793a<code>metrics<\/code>\u6570\u636e\uff0c\u5982\u4e0b\u56fe\uff1a<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/4563.org\/wp-content\/uploads\/2020\/05\/20200519_5ec460c72b908.png\" alt=\"OPA \u8fdb\u9636-\u5206\u5e03\u5f0f\u5229\u5668 Bundle\" \/><\/p>\n<h2>Bundle in action<\/h2>\n<p>\u4e0a\u8fb9\u8bf4\u8fd9\u4e48\u591a\uff0c\u4e0d\u5b9e\u9645\u8bd5\u4e00\u4e0b\u600e\u4e48\u77e5\u9053<code>Bundle<\/code>\u7a76\u7adf\u5982\u4f55\u5462\uff1f<\/p>\n<p>\u8fd9\u91cc\u63d0\u4f9b\u4e00\u4e2a<code>docker-compose<\/code>\u7248\u7684 demo \u7ed9\u5927\u5bb6\u53bb\u672c\u5730\u9a8c\u8bc1\u5c1d\u8bd5<\/p>\n<p>\u91cc\u8fb9\u63d0\u4f9b\u4e86\u4e09\u79cd<code>Bundle<\/code>\u7248\u672c\uff1a<\/p>\n<ul>\n<li>opa-bundle<\/li>\n<li>opa-discovery<\/li>\n<li>demo-sever (go lib \u96c6\u6210)<\/li>\n<\/ul>\n<p>\u4e5f\u63d0\u4f9b\u4e86\u4e24\u79cd\u7248\u672c\u7684<code>monitor<\/code><\/p>\n<ul>\n<li>slim version<\/li>\n<li>advance version<\/li>\n<\/ul>\n<p>\u4ee3\u7801\u89c1\uff1aNewbMiao\/opa-koans\/bundle<\/p>\n<p>\u91cc\u8fb9\u6709\u8be6\u7ec6\u7684\u64cd\u4f5c\u6587\u6863\uff0c\u6709\u95ee\u9898\u53ef\u4ee5\u5728 Repo \u91cc\u63d0 issue<\/p>\n<p>\u8fd9\u4e2a Repo \u5305\u542b\u4e86\u8fd9\u4e00\u7cfb\u5217\u7684<code>OPA<\/code>\u6559\u7a0b\uff0c\u6b22\u8fce\u611f\u5174\u8da3\u7684\u540c\u5b66 <strong><code>star<\/code><\/strong> \u5173\u6ce8\uff01<\/p>\n<p>\u540c\u65f6\u6211\u5728\u77e5\u4e4e\u4e5f\u5efa\u4e86\u4e00\u4e2aOPA \u6280\u672f\u5708\uff0c\u4e5f\u6b22\u8fce\u5927\u5bb6\u53c2\u4e0e\u8ba8\u8bba\u3002<\/p>\n<p>\u597d\u4e86\uff0c\u5230\u6b64\uff0c<code>OPA<\/code>\u7684\u57fa\u672c\u6559\u7a0b\u5c31\u7ed3\u675f\u4e86\u3002\u540e\u8fb9\u518d\u62bd\u7a7a\u7ed3\u5408\u5b98\u65b9\u7684\u4f8b\u5b50\u5199\u4e9b\u5b9e\u6218\u6559\u7a0b\u5427\u3002<\/p>\n<p>\u6700\u540e\u9644\u4e0a\u4e00\u4e2a Repo \u4e2d\u9a8c\u8bc1 Bundle \u7684\u8fc7\u7a0b\uff0c\u5927\u5bb6\u4e5f\u53ef\u4ee5\u4ece\u8fd9\u91cc\u5f00\u59cb\u5c1d\u8bd5\u54e6<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/4563.org\/wp-content\/uploads\/2020\/05\/20200519_5ec460cdae492.gif\" alt=\"OPA \u8fdb\u9636-\u5206\u5e03\u5f0f\u5229\u5668 Bundle\" \/><\/p>\n<p>\u6587\u7ae0\u9996\u53d1\u516c\u4f17\u53f7\uff1anewbmiao<\/p>\n<p>\u63a8\u8350\u9605\u8bfb\uff1aOPA \u7cfb\u5217<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/4563.org\/wp-content\/uploads\/2020\/05\/20200519_5ec460d38793e.png\" alt=\"OPA \u8fdb\u9636-\u5206\u5e03\u5f0f\u5229\u5668 Bundle\" \/><\/p>\n<\/p><\/div>\n<div> <b>\u5927\u4f6c\u6709\u8a71\u8aaa<\/b> (<span>2<\/span>)        <\/div>\n<div> <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<ul>\n<li data-pid=\"1179776\" data-uid=\"2\">\n<div>\n<div>\n<div> <span>\u8cc7\u6df1\u5927\u4f6c : guonaihong <\/span>  <\/div>\n<div> <i title=\"\u5f15\u7528\"><\/i>  <span>          <\/span> <\/div>\n<\/p><\/div>\n<div>                                                             Bundle \u662f k8s \u751f\u6001\u91cc\u7684\uff1f                                                            <\/div>\n<\/p><\/div>\n<\/li>\n<li data-pid=\"1179777\" data-uid=\"2\">\n<div>\n<div>\n<div> <span>\u4e3b<\/span> <span>\u8cc7\u6df1\u5927\u4f6c : newmiao <\/span>  <\/div>\n<div> <i title=\"\u5f15\u7528\"><\/i>  <span>          <\/span> <\/div>\n<\/p><\/div>\n<div>                                                             @guonaihong \u8fdb\u5165\u4e86 CNCF \u5b75\u5316\u9879\u76ee\uff0c\u662f CNCF \u751f\u6001\u4e0b\uff0c\u53ef\u4ee5\u770b\u770b\u8fd9\u4e2a\u58f0\u660e\uff1a https:\/\/www.cncf.io\/blog\/2019\/04\/02\/toc-votes-to-move-opa-into-cncf-incubator\/                                                            <\/div>\n<\/p><\/div>\n<\/li>\n<li>\n","protected":false},"excerpt":{"rendered":"<p>OPA \u8fdb\u9636-\u5206\u5e03\u5f0f\u5229\u5668 Bund&hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[],"tags":[],"_links":{"self":[{"href":"http:\/\/4563.org\/index.php?rest_route=\/wp\/v2\/posts\/93949"}],"collection":[{"href":"http:\/\/4563.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/4563.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/4563.org\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/4563.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=93949"}],"version-history":[{"count":0,"href":"http:\/\/4563.org\/index.php?rest_route=\/wp\/v2\/posts\/93949\/revisions"}],"wp:attachment":[{"href":"http:\/\/4563.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=93949"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/4563.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=93949"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/4563.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=93949"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}