World Congress 2023 Sep 27, 2023

OPA for the cloud natives

Philipp Krenn

Are your security checks tightly coupled to your code? Open Policy Agent decouples them. Discover how shifting left with policy-as-code automates your cloud-native governance.

Pause
Mute Enter Fullscreen
#1 about 3 min

Decoupling security checks from deployment pipelines

How separating security policies from application code enables continuous auditing and compliance.

#2 about 3 min

Classifying security incidents and proactive prevention

Why catching policy violations in continuous integration is preferable to relying on tribal knowledge or vendor fixes.

#3 about 3 min

Core concepts and architecture of Open Policy Agent

How OPA evaluates queries against policies and data to return decisions across different APIs.

#4 about 4 min

Writing basic access and resource policies in Rego

Examples of using Rego to enforce user access limits, management hierarchies, and container registry origins.

#5 about 2 min

Enforcing policy validations in continuous integration pipelines

How companies use OPA to validate Terraform plans against policies before allowing pull request merges.

#6 about 4 min

Testing and debugging rules in the OPA playground

A live demonstration of evaluating both simple and complex Kubernetes label policies within the interactive Rego environment.

#7 about 1 min

Deployment models for co-locating OPA instances

Best practices for embedding OPA as a Go library or running it as a co-located daemon set to minimize latency.

#8 about 4 min

Validating data queries and infrastructure security configurations

How OPA can enforce rules on Elasticsearch queries and validate Kubernetes environments against CIS benchmarks.

#9 about 4 min

Optimizing performance and overcoming Open Policy Agent barriers

Insights into profiling Rego queries to enhance speed alongside the challenges of adopting the complex language ecosystem.

#10 about 3 min

Audience questions on data formats and deployment environments

Responses regarding Rego's support for JSON and YAML alongside non-Kubernetes OPA deployments and API integrations.

Matching moments

7:07 min

Implementing programmatic policy checks with Open Policy Agent

Madhu Akula · LIVE

2:41 min

Usability and syntax challenges with rego and opa

Chris Nesbitt-Smith · LIVE

1:54 min

Expanding Open Policy Agent across diverse ecosystems

Anderson Dadario +1 · LIVE

2:03 min

Uploading and evaluating Open Policy Agent rules dynamically

Anderson Dadario +1 · LIVE

1:43 min

Defining and evaluating access policies using Rego

Anderson Dadario +1 · LIVE

2:44 min

Replacing verbose XACML with Open Policy Agent

Anderson Dadario +1 · LIVE

Upcoming sessions on this topic

Open session

World Congress 2026 North America

September 25, 2026 · 12:20–12:50

Stage 4

Give the Agent a Budget, Not a Token

Sachin Malhotra

MTS @Anthropic

Sachin Malhotra
Open session

World Congress 2026 North America

September 23, 2026 · 15:45–17:45

Stage 8

Docker's Agentic Platform: Sandboxes, MCP, and the Infrastructure of Autonomous Development

Oleg Šelajev

AI and Developer relations at Docker

Oleg Šelajev
Open session

World Congress 2026 North America

September 25, 2026 · 15:45–15:55

Outdoor Stage

Closing the Visibility Gap: Lessons from Safety Critical Agentic Systems

Vivek Pandit

Frontier AI Lead at Turing

Vivek Pandit
Open session

World Congress 2026 North America

September 25, 2026 · 15:30–16:00

Mainstage

One Boundary for the Agentic Era

Mark Lechner

Chief Information Security Officer, Dokcer

Mark Lechner
Open session

World Congress 2026 North America

September 24, 2026 · 14:25–14:35

Outdoor Stage

SecurePrompt: Building a Pre-Flight Security Layer for Agentic AI

Ravi Sastry Kadali

AI/ML Engineer at General Motors

Ravi Sastry Kadali
Open session

World Congress 2026 North America

September 24, 2026 · 13:30–14:00

Stage 6

AI vs. AI: Defending the open source supply chain with agentic workflows

Manfred Moser

Senior Principal DevRel Engineer at Chainguard

Manfred Moser