World Congress 2023 • Sep 27, 2023

OPA for the cloud natives

Philipp Krenn

Are your security checks tightly coupled to your code? Open Policy Agent decouples them. Discover how shifting left with policy-as-code automates your cloud-native governance.

Pause
Mute Enter Fullscreen
#1 about 3 min

Decoupling security checks from deployment pipelines

How separating security policies from application code enables continuous auditing and compliance.

#2 about 3 min

Classifying security incidents and proactive prevention

Why catching policy violations in continuous integration is preferable to relying on tribal knowledge or vendor fixes.

#3 about 3 min

Core concepts and architecture of Open Policy Agent

How OPA evaluates queries against policies and data to return decisions across different APIs.

#4 about 4 min

Writing basic access and resource policies in Rego

Examples of using Rego to enforce user access limits, management hierarchies, and container registry origins.

#5 about 2 min

Enforcing policy validations in continuous integration pipelines

How companies use OPA to validate Terraform plans against policies before allowing pull request merges.

#6 about 4 min

Testing and debugging rules in the OPA playground

A live demonstration of evaluating both simple and complex Kubernetes label policies within the interactive Rego environment.

#7 about 1 min

Deployment models for co-locating OPA instances

Best practices for embedding OPA as a Go library or running it as a co-located daemon set to minimize latency.

#8 about 4 min

Validating data queries and infrastructure security configurations

How OPA can enforce rules on Elasticsearch queries and validate Kubernetes environments against CIS benchmarks.

#9 about 4 min

Optimizing performance and overcoming Open Policy Agent barriers

Insights into profiling Rego queries to enhance speed alongside the challenges of adopting the complex language ecosystem.

#10 about 3 min

Audience questions on data formats and deployment environments

Responses regarding Rego's support for JSON and YAML alongside non-Kubernetes OPA deployments and API integrations.

Matching moments

7:07 min

Implementing programmatic policy checks with Open Policy Agent

Madhu Akula · LIVE

2:41 min

Usability and syntax challenges with rego and opa

Chris Nesbitt-Smith · LIVE

1:54 min

Expanding Open Policy Agent across diverse ecosystems

Anderson Dadario +1 · LIVE

2:03 min

Uploading and evaluating Open Policy Agent rules dynamically

Anderson Dadario +1 · LIVE

1:43 min

Defining and evaluating access policies using Rego

Anderson Dadario +1 · LIVE

2:44 min

Replacing verbose XACML with Open Policy Agent

Anderson Dadario +1 · LIVE

Upcoming sessions on this topic

Open session

World Congress 2026 North America

September 25, 2026 · 11:40–12:10

Stage 6

Codifying Trade-offs: Security, Cost, and Compliance as Agent Guardrails

Suzanne Daniels

Chief Developer Advisor at Microsoft

Suzanne Daniels
Open session

World Congress 2026 North America

September 25, 2026 · 12:20–12:50

Stage 4

Give the Agent a Budget, Not a Token

Sachin Malhotra

MTS @Anthropic

Sachin Malhotra
Open session

World Congress 2026 North America

September 23, 2026 · 15:45–17:45

Stage 8

Docker's Agentic Platform: Sandboxes, MCP, and the Infrastructure of Autonomous Development

Oleg Šelajev

AI and Developer Relations at Docker

Oleg Šelajev
Open session

World Congress 2026 North America

September 24, 2026 · 11:40–12:10

Stage 2

The Private AI Platform: Why Agentic Apps Need a Private Application Platform

Oren Penso

Global field CTO, Tanzu division, Broadcom

Oren Penso
Open session

World Congress 2026 North America

September 25, 2026 · 15:45–15:55

Outdoor Stage

Closing the Visibility Gap: Lessons from Safety Critical Agentic Systems

Vivek Pandit

Frontier AI Lead at Turing

Vivek Pandit
Open session

World Congress 2026 North America

September 25, 2026 · 15:30–16:00

Mainstage

One Boundary for the Agentic Era

Mark Lechner

Chief Information Security Officer of Docker

Mark Lechner