> Markdown version of [/videos/35-decoupled-authorization-using-policy-as-code?t=793](https://www.wearedevelopers.com/videos/35-decoupled-authorization-using-policy-as-code?t=793). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Decoupled Authorization using Policy as Code Still hardcoding authorization logic into your software? Discover how Open Policy Agent decouples access control, letting you update permissions dynamically without ever recompiling your apps. - **Speakers:** Anderson Dadario, Denys Vitali - **Event:** WeAreDevelopers LIVE - **Published:** October 12, 2020 - **Duration:** 32:16 - **URL:** https://www.wearedevelopers.com/videos/35-decoupled-authorization-using-policy-as-code ## Summary Traditional application development often hardcodes authorization logic directly into software, leading to tight coupling, poor auditability, and the operational friction of recompiling applications whenever access rules change. While authentication is highly standardized with protocols like SAML or OIDC, authorization remains fragmented. Adopting "policy as code" solves this vulnerability by decoupling business logic from access control, moving permission evaluations into a centralized, version-controlled, and testable environment. Open Policy Agent (OPA) serves as a modern, cloud-native policy engine that evaluates authorization requests against policies written in Rego, a high-level declarative language. By replacing verbose legacy standards like XACML, OPA establishes a lightweight Policy Decision Point (PDP) that can be deployed as a container sidecar, executed via CLI, or embedded directly within application code, such as a Go library. The target applications act as a Policy Enforcement Point (PEP), querying the OPA engine with standard JSON inputs and receiving structured allow/deny decisions. Decoupling authorization empowers platform and engineering teams to update access rules dynamically without restarting the underlying software. From securing a simple API using middleware to restricting Kubernetes ingress workflows and verifying trusted image sources, OPA standardizes security visibility across disparate architectures. Crucially, organizations gain strict governance over who can deploy authorization rules, shifting access control from hidden bespoke code snippets into an auditable, company-wide security standard. **Keywords:** policy as code, decoupled authorization, open policy agent, rego declarative language, access control centralization, policy decision point, policy enforcement point, XACML alternatives, API middleware integration, dynamic policy reloading, kubernetes admission control, security auditing visibility, application logic decoupling, RBAC authorization, container security standards ## Chapters 1. **Evaluating common authentication and custom authorization challenges** (01:52) — While standardized authentication methods exist, custom authorization integrations often lack unified tooling and create isolated administrative silos. 1. **Embedding authorization logic inside application source code** (02:43) — Checking user roles directly within application files tightly couples core business logic to restrictive security rules. 1. **Decoupling business logic with policy as code** (04:44) — Centralizing authorization decisions allows developers to version, test, and seamlessly share governance rules across multiple distinct applications. 1. **Understanding XACML components for access control evaluation** (06:16) — Policy enforcement and decision points coordinate closely to read data sources and accurately evaluate resource access requests. 1. **Replacing verbose XACML with Open Policy Agent** (08:46) — Open Policy Agent provides a streamlined administrative alternative to complex XML-based policies using the declarative language Rego. 1. **Implementing Open Policy Agent in application architectures** (11:31) — Client applications easily interact with Open Policy Agent via REST APIs to quickly invoke decoupled external authorization decisions. 1. **Defining and evaluating access policies using Rego** (13:13) — Writing structured policy files validates complex user roles against requested runtime operations to trigger appropriate systemic violations. 1. **Testing and querying Rego policies via HTTP** (14:57) — Executing local unit tests validates operational logic before safely passing active sample inputs to the policy server. 1. **Integrating OPA middleware in Golang web applications** (17:41) — Custom server middleware cleverly intercepts incoming HTTP requests to decode authentication details and seamlessly query external authorization rules. 1. **Structuring hierarchical employee access rules in Rego** (20:18) — Defining highly specific pattern matching constraints limits system data access strictly to users or their managing network supervisors. 1. **Uploading and evaluating Open Policy Agent rules dynamically** (22:39) — Submitting raw Rego files directly via HTTP permits the immediate application of new access policies against active workflows. 1. **Enforcing business requirement changes without application restarts** (24:42) — Modifying and rapidly reloading targeted policy variables instantly updates infrastructure access logic without recompiling rigid underlying source code. 1. **Iterating on logic using the web-based Rego playground** (27:19) — The online sandbox environment offers a rapid workspace to iteratively tweak and test authorization constraints without heavy local installations. 1. **Expanding Open Policy Agent across diverse ecosystems** (29:09) — Purpose-built plugin adaptations for Kubernetes, Kafka, and Linux module integration intelligently extend policy enforcement far beyond traditional web endpoints. 1. **Centralizing authorization oversight and system security traceability** (31:04) — Standardizing access controls creates strict programmatic auditing pipelines and ultimately limits production policy modifications exclusively to authorized developers. ## Related Moments - [Implementing programmatic policy checks with Open Policy Agent](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) (from "A practical guide to writing secure Dockerfiles") - [Core concepts and architecture of Open Policy Agent](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) (from "OPA for the cloud natives") - [Optimizing performance and overcoming Open Policy Agent barriers](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) (from "OPA for the cloud natives") - [Usability and syntax challenges with rego and opa](https://www.wearedevelopers.com/videos/532-policy-as-versioned-code-you-re-doing-it-wrong) (from "Policy as [versioned] code - you're doing it wrong") - [Writing basic access and resource policies in Rego](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) (from "OPA for the cloud natives") - [Testing and debugging rules in the OPA playground](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) (from "OPA for the cloud natives") ## Related Articles - [What is Agentic Programming and Why Should Developers Care?](https://www.wearedevelopers.com/magazine/625-what-is-agentic-programming-and-why-should-developers-care) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [A 5-Step Open-Source Setup for Agentic Engineering](https://www.wearedevelopers.com/magazine/738-a-5-step-open-source-setup-for-agentic-engineering) - [MLOps And AI Driven Development](https://www.wearedevelopers.com/magazine/82-mlops-and-ai-driven-development) ## Related Jobs - [Principal Software Engineer, Identity](https://www.wearedevelopers.com/jobs/ext/1469181-principal-software-engineer-identity) at **GitHub** - [Principal Product Manager, Agent Platform](https://www.wearedevelopers.com/jobs/ext/277541-principal-product-manager-agent-platform) at **GitHub** - [Senior Backend Developer — AI: MCP & Agent Engine](https://www.wearedevelopers.com/jobs/48297-senior-backend-developer-ai-mcp-agent-engine) at **basebox GmbH** - [Staff Developer Advocate, GitHub Security Lab](https://www.wearedevelopers.com/jobs/ext/1921051-staff-developer-advocate-github-security-lab) at **GitHub** - [Senior Software Engineer, Client Apps Platform](https://www.wearedevelopers.com/jobs/ext/1773893-senior-software-engineer-client-apps-platform) at **GitHub** - [Senior AI Agent Software Engineer (Go, Python) (m/f/x)](https://www.wearedevelopers.com/jobs/48277-senior-ai-agent-software-engineer-go-python-m-f-x) at **Dynatrace**