NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #286 by repository stars
Last release today
09 Oct 2026
Ships on a steady schedule
a new release about every 8 days
Nearly every release is documented
notes for 59 of the last 60 stable releases
85 versions withdrawn
withdrawn after publishing
10 years old
4354 releases · first in 2016
Nothing published for this version
In this release we reached a milestone for Wasm: any Rego policy can be compiled to Wasm now! In the next few weeks we will focus on expanding on the
In this release we reached a milestone for Wasm: any Rego policy can be compiled to Wasm now! In the next few weeks we will focus on expanding on the set of built-ins supported out-of-the-box and inside the NodeJS SDK.
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
This release includes many small improvements and bug fixes.
This release includes many small improvements and bug fixes.
This release includes a few new built-in functions for string manipulation:
trim_left, trim_right, trim_prefix, and trim_suffix (thanks @hasit)regex.find_all_string_submatch_n and strings.replace_n (thanks @kenfdev)/ separators for keyresource configuration optiontopdown: Fix namespacing to use caller bindings
Fix a number of links in the OPA documentation.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Update the --plugin-dir flag as deprecated
This release includes a large number of improvements to the docs as
well as performance optimizations that improve several end-to-end
benchmarks by ~25%. Also, the opa eval and other sub-commands now
accept a -b or --bundle flag that tell OPA to treat file paths as
bundles (either .tar.gz or directories). This improves behaviour in
large or mixed workspaces.
This release includes a few improvements to built-in functions:
A new function for converting SI strings (e.g., "10MB") to numbers:
units.num_bytes(x)
(#1561). This
is useful in the context of Kubernetes if you need to deal with
resource limits and requests.
The io.jwt.verify_* functions have been extended to support JWKs.
This release also improves support for providing custom built-in functions to OPA. See the extensions documentation on openpolicyagent.org.
Fix panic in OPA HTTP server with /health?bundle=true when using bundles loaded from CLI (#1703).
/health?bundle=true when
using bundles loaded from CLI (#1703).Fix panic in OPA HTTP server caused by concurrent map writes
Fix bundle plugin to report error in case bundle manifest roots overlap
This release updates OPA to use the latest stable Golang release (1.12.8) that includes important fixes in the net/http package. See this golang-nuts
This release updates OPA to use the latest stable Golang release (1.12.8) that includes important fixes in the net/http package. See this golang-nuts group message for details.
Nothing published for this version
Nothing published for this version
The diagnostics feature deprecated in v0.10.1 has been removed.
This release adds support for downloading multiple bundles to OPA
using the new bundles key in the configuration. APIs that include
bundle information have been updated to support multiple bundles:
These changes are backwards compatible. If you are using the
existing bundle key in the configuration, you will not see any
changes in the APIs listed above.
We recommend that you switch to the new bundles key and update
consumers of the above APIs to support multiple bundles.
For more information on bundles see the this page in the OPA documentation.
This release adds support for emitting decision logs to stdout. This is useful for shipping decision logs directly to existing logging backends.
You can enable console decision logging on the command line:
opa run --server --set decision_logs.console=true
Console decision logging can be enabled alongside normal and custom decision logging.
openpolicyagent/opa:edge Docker images are available now. The
edge tag refers to the tip of master.rego.Rego#PrepareForEVal now times partial evaluation properly.Fix performance impact of bundle activation on policy queries
Fix deadlock caused by log masking decision evaluation
POST / endpointNothing published for this version
Nothing published for this version
This release includes two new features and an important bug fix.
This release includes two new features and an important bug fix.
This release includes an important feature for protecting sensitive
information in decision logs: masking. With the new decision log
masking feature you can configure OPA to remove sensitive information
from the input and result fields of decision log events. See the
Decision Log documentation for details.
This release adds support for signing bundle download requests using an AWS signing scheme. This feature allows you to configure OPA to download bundles directly from S3. See the Configuration documentation for details.
This release includes a few small but backward incompatible changes:
This release includes a few small but backward incompatible changes:
The compiler will reject functions that redeclare arguments. A search of public .rego files on GitHub only returned one result which was contained in the OPA documentation. For example:
f(x) {
x := 1 # bad: redeclaration of 'x'
x == 1 # ok
}
Errors returned by built-in calls are no longer coded as
eval_internal_error. Instead they are returned as
eval_builtin_error. This change is made so callers can
differentiate between actual internal errors and built-in errors
that are result of bad inputs from the policy.
The ast.QueryCompiler#WithInput function and
ast.QueryContext#Input field have been removed because they were
unused and had no affect.
The ast.Compiler and ast.QueryCompiler functions to register
extra changes now require a stage and metric name.
This release includes a few notable features and improvements:
The some keyword allows you to declare local variables to avoid
namespacing issues. See the Some
Keyword
section in the documentation for more detail.
The opa test, eval, REPL, and HTTP API have been extended with a
new explanation mode for filtering tracing notes. This makes it
easier to see the output of trace(msg) calls from your policy.
The WebAssembly (Wasm) compiler has been extended to include support for compiling rules into Wasm. Previously the compiler relied on partial evaluation to inline all rules. In some cases this is not possible due to limitations on Rego queries. In coming releases, the Wasm support will be extended to cover the entire language.
The rego package has been extended to support prepared
queries. Prepared queries cache the parsed and compiled query ASTs
for re-use across multiple Eval calls. For small policies the
speedup can be significant. See the GoDoc for details.
input document over HTTP (#1293)json logs the default and add json-prettyNothing published for this version
Add net.cidr_contains and net.cidr_intersects built-ins (#1289). This change deprecates the old net.cidr_overlap built-in function. The latter will be…
This release publishes the Hugo-based documentation to GitHub Pages :tada:
array.slice built-in function (#1243)net.cidr_contains and net.cidr_intersects built-ins
(#1289). This
change deprecates the old net.cidr_overlap built-in function. The
latter will be supported for backwards compatibility but new
policies should refer to net.cidr_contains.This release includes a small but backwards incompatible change to the http.send built-in. Previously, http.send would _always_ decode responses as JS…
This release migrates the OPA documentation over to Hugo (from GitBook). Going forward the OPA documentation will be generated using Hugo and hosted on Netlify (instead of GitHub Pages). The Hugo/Netlify stack brings us inline with the goal for other CNCF projects and provides nice features like "preview before merge".
This release includes a small but backwards incompatible change to the
http.send built-in. Previously, http.send would always decode
responses as JSON even if the Content-Type was unset or explicitly not
JSON. If you were previously relying on HTTP responses that did not
set the Content-Type correctly, you will need to update your policy to
pass "force_json_decode": true as in the http.send parameters.
These release contians a small but backwards incompatible change to the custom decision logger API. Custom decision loggers can now return an error wh…
This release includes a small but backwards incompatible change to the Decision Log event format. Instead of including the OPA version as a top-level…
This release adds support for scoping bundles to specific roots
under data. This allows bundles to be used in conjunction with
sidecars like kube-mgmt that load local data and policy into
OPA. See the Bundles
page for more details.
This release includes a small but backwards incompatible change to the Decision Log event format. Instead of including the OPA version as a top-level field, the OPA version is included in the labels. The OPA version field was only added in v0.10.3 so this should not impact many consumers.
Nothing published for this version
This release includes a backwards incompatible change to the plugin interface. Specifically, when plugins are registered, callers must provide a facto…
This release includes support for authentication via client certificates (thanks @srenatus!) For improvements to authentication see #1163.
This release includes a backwards incompatible change to the plugin interface. Specifically, when plugins are registered, callers must provide a factory that can validate configuration before instantiating the plugin. This allows OPA to ensure that all configuration is valid before activating changes. Since plugins were undocumented prior to this release, this change should be low impact. For details on plugin development see the new Plugins page on the website.
This release includes a backwards incompatible change to the HTTP decision logger event type. Specifically, "null" inputs are now handled correctly and decision logs for ad-hoc queries now populate the "query" field in the event instead of the "path" field. If you are using consuming decision log events in Go, please switch to the decision logger framework documented here: https://github.com/open-policy-agent/opa/blob/master/docs/book/plugins.md.
opa test (#961)Mark diagnostics feature as deprecated
Add glob built-ins for easier path matching (thanks @aeneasr)
glob built-ins for easier path matching (thanks @aeneasr)Deprecating --insecure-addr flag (thanks @repenno)
Wasm compiler. This release adds initial/experimental support for
compiling Rego policies into Wasm executables. Wasm executables can be loaded
and executed in compatible Wasm runtimes like V8 (nodejs). You can try this
out by running opa build.
Data mocking. This release adds support for replacing/mocking the data
document using the with keyword. In the past, with only supported the
input document. This made it tricky to test context-dependent policies. With
the new with keyword support, it's easier to write tests against contextual
policies.
Negation Optimization. This release includes an optimization in partial
evaluation for dealing with negated statements (not keyword). In the past,
OPA would generate a support rule for negated statements. This is harder for
clients to consume and not readily optimized. The optimization computes the
necessary cross-product of the negated query and inlines it into the caller.
This leads to simpler partial evaluation results that are readily optimized,
translated into other query languages (e.g., SQL and Elasticsearch),
or compiled into Wasm.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Add option to enable http redirects
net.cidr_overlap built-in function (thanks @aeneasr)regex.template_match built-in function (thanks @aeneasr)Nothing published for this version
Nothing published for this version
Add io.jwt.verify_es256 and io.jwt.verify_ps256 built-in functions (@optnfast)
This release adds two major features to OPA itself.
This release adds two major features to OPA itself.
Query Profiler: the opa eval subcommand now supports a --profiler option
to help policy authors understand the performance profile of their policies.
Give it a shot and let us know if you find it helpful or if you find cases
that could be improved!
Compile API: OPA now exposes Partial Evaluation with first-class interfaces. In prior releases, Partial Evaluation was only used for optimizations purposes. As of v0.9, callers can use Partial Evaluation via HTTP or Golang to obtain conditional decisions that can be evaluated on the client-side.
Here is a short list of notable miscellaneous improvements.
...along with 30+ other fixes and improvements.
Fix virtual document cache invalidation
Handle escaped paths in data writes
Add eval subcommand to run queries from the command line (deprecates opa run --eval)
This release includes a few major features that improve OPA's management capabilities.
Bundles: OPA can be configured to download bundles of policy and data from remote HTTP servers. This allows administrators to configure OPA to pull down all of the policy and data required at the enforcement point. When OPA boots it will download the bundle and active it. OPA will periodically check in with the server to download new revisions of the bundle.
Status: OPA can be configured to report its status to remote HTTP servers. The status includes a description of the active bundle. This allows administrators to monitor the status of OPA in a central place.
Decision Logs: OPA can be configured to report decision logs to remote HTTP servers. This allows administrators to audit and debug decisions in a central place.
The command line file loading convention has been changed slightly. If you were
previously loading files with opa run * you should use opa run . now. OPA
will not namespace data under top-level directory names anymore. The problem
with the old approach was that data layout was dependent on the root directory
name. For example opa run /some/path1 and opa run /some/path2 would yield
different results even if both paths contained identical data.
Thanks to @jyoverna for adding a trace built-in function that allows policy
authors to include notes in the trace. For example, authors can now embed
trace calls in their policies. When OPA encounters a trace call it will
include a "note" in the trace. Callers can filter the trace results to show only
notes. This helps diagnose incorrect decisions in large policies. For example:
package example
allow {
input.method = allows_methods[_]
trace(sprintf("input method is %v", [input.method]))
}
allowed_methods = ["GET", "HEAD"]
As well as many other smaller improvements, refactoring, and fixes.
Use rego.ParsedInput to provide input from form
Nested expressions: now you can write expressions like (temp_f - 32)*5/9!
Nested expressions: now you can write expressions like (temp_f - 32)*5/9!
Assignment/comparison operators: now you can write x := <expression> to
declare local variables and x == y when you strictly want to compare two
values (and not bind any variables like with =).
Prometheus support: now you can hook up Prometheus to OPA and collect performance metrics on the different APIs. (thanks @rlguarino)
This release adds and improves a bunch of new built-in functions. See the Language Reference for details.
This release adds initial support for partial evaluation. Partial evaluation allows callers to mark certain inputs as unknown and then evaluate querie
This release adds initial support for partial evaluation. Partial evaluation allows callers to mark certain inputs as unknown and then evaluate queries to produce new queries which can be evaluated once inputs become known.
Improve InterfaceToValue to handle other Go types
Fix eval of objects/sets containing vars
Refactor topdown evaluation/unification
Fix index usage for virtual docs
Fix unsafe var errors on functions (#471, #467)
Substitute comprehension terms requring eval
Your coding agent can read these notes before it upgrades. Set up the MCP server →