OPA & Gatekeeper
OPA runs as a library, a sidecar or a shared server fed by bundles, while Gatekeeper wraps Rego in ConstraintTemplates with audit and mutation. Interviewers probe topology and decision logs.
on this pageshowhide
explore
- Running the Engine11 questions
- Library, Sidecar or Server4 questions
- Asking for a Decision3 questions
- Authorizing Live Requests4 questions
- Feeding the Engine11 questions
- Bundles and Revisions4 questions
- Loading Context Data4 questions
- The Decision Log Plugin3 questions
- Rules as Cluster Objects23 questions
- Templates and Parameters4 questions
- Audit Over Live Objects3 questions
- Replicated Object Cache4 questions
- Assign and ModifySet4 questions
- Writing a Violation Rule4 questions
- Testing a Constraint Offline4 questions
questions
page 2 of 2Your Gatekeeper Constraint is blocking system-namespace workloads — how do you scope or exempt it?
basics
~20 sNarrow the Constraint's match block: list kinds, restrict namespaces or add excludedNamespaces, or select by label. For system namespaces that must never be evaluated at all, exempt them engine-wide in Gatekeeper's Config rather than per rule.
An OPA sidecar in 3,000 pods versus one shared decision service — what do you size before choosing?
basics
~20 sMemory multiplied by replica count, and policy-fetch fan-out. Each sidecar holds its own copy of the policy and any base data, and polls for updates independently, so 3,000 replicas mean 3,000 copies and 3,000 pollers.
In an OPA ext_authz policy, how do you allow writes to /admin only from one mTLS identity?
basics
~10 sWrite a positive allow over an explicit default deny: match the first parsed_path segment, check the method is a write, and compare input.attributes.source.principal, the peer identity the proxy authenticated, against the one permitted value.
Two OPA bundles declare overlapping roots in their manifests — what happens?
basics
~20 sOPA requires bundle roots to be disjoint. It refuses to activate a bundle whose roots overlap another configured bundle's, records the error and keeps serving what it had, so the new rules silently never take effect.
In Gatekeeper, what changes when the audit controller runs with audit-from-cache enabled?
basics
~10 sGatekeeper's audit normally reads each constrained kind from the API server every cycle. With --audit-from-cache it evaluates Gatekeeper's replicated object cache instead: far cheaper, but unreplicated kinds are invisible and silently report zero violations.
gator test in your rule repo's CI exits 0 on a manifest you know violates the constraint — why?
basics
~20 sUsual causes: the constraint is set to dryrun or warn, so violations print without failing the exit code; the rule files were never in the input set; the match block selects nothing; or the CI step discards the status.
How does the location path in a Gatekeeper Assign select a field inside a Pod?
basics
~20 sThe location is a dotted path from the object's root, with list entries picked by a key filter such as spec.containers[name:*]. Missing intermediate fields are created on the way; a glob only matches list entries that already exist.
Your OPA decision logs are rate-limited and an auditor wants proof one request was evaluated last Tuesday — what can you show?
basics
~20 sA rate-limited or sampled OPA decision log is telemetry, not a ledger. You can show the entries that survived, but rate-limited, dropped and buffer-lost decisions leave no trace at all, so a missing entry proves nothing about whether the policy ran.
Your OPA sidecars hold a 400 MB data document and keep OOMing. What do you do?
basics
~20 sEvery OPA instance holds the whole data document in memory, so the cost is paid per replica and per sidecar. Shrink it: ship only the fields rules read, scope bundle roots per consumer, and key the document by the lookup value.
How do you share Rego helpers across Gatekeeper ConstraintTemplates?
basics
~20 sThrough the ConstraintTemplate's libs field: each helper is Rego source shipped inside the same object, under the lib package namespace and imported as data.lib.<name>. A template is self-contained, so every one carries its own copy.
In a Gatekeeper ConstraintTemplate, what belongs in the rule body versus in its parameters?
basics
~20 sPut the invariant in the template body and the values that vary between teams in parameters, declared with types in the openAPIV3Schema. Fork into a second template only when the logic differs, not when a number does.
When should you call OPA's /v1/compile instead of /v1/data?
basics
~20 sWhen you cannot supply every fact at query time. /v1/data needs a complete input and answers with a value; /v1/compile takes a query plus the references you name as unknown and answers with the conditions that are still left to check.
Centralizing OPA as one shared decision service — what leaves each caller that never left before?
basics
~20 sEvery query's input document. A rule can only judge facts it is given, so the input carries account, tenant and requester identifiers, and centralizing sends all of it across a boundary on every call and usually into a decision-log store.
An OPA ext_authz result returns allowed true plus a resolved-subject header. What must hold for the upstream to trust it?
basics
~10 sThe proxy must be the only way in, and the caller must not be able to set that header themselves. Any route around the gate hands the upstream a subject nobody authenticated.
showing 31–45 of 45