skip to content

OPA & Gatekeeper

OPA runs as a library, a sidecar or a shared server fed by bundles, while Gatekeeper wraps Rego in ConstraintTemplates with audit and mutation. Interviewers probe topology and decision logs.

on this pageshow

explore

questions

page 2 of 2

Your Gatekeeper Constraint is blocking system-namespace workloads — how do you scope or exempt it?

level: seniorimportance: should knowfreq 54%

basics

~20 s

Narrow the Constraint's match block: list kinds, restrict namespaces or add excludedNamespaces, or select by label. For system namespaces that must never be evaluated at all, exempt them engine-wide in Gatekeeper's Config rather than per rule.

open as a page

An OPA sidecar in 3,000 pods versus one shared decision service — what do you size before choosing?

level: seniorimportance: should knowfreq 46%

basics

~20 s

Memory multiplied by replica count, and policy-fetch fan-out. Each sidecar holds its own copy of the policy and any base data, and polls for updates independently, so 3,000 replicas mean 3,000 copies and 3,000 pollers.

open as a page

In an OPA ext_authz policy, how do you allow writes to /admin only from one mTLS identity?

level: seniorimportance: should knowfreq 48%

basics

~10 s

Write a positive allow over an explicit default deny: match the first parsed_path segment, check the method is a write, and compare input.attributes.source.principal, the peer identity the proxy authenticated, against the one permitted value.

open as a page

Two OPA bundles declare overlapping roots in their manifests — what happens?

level: middleimportance: nice to knowfreq 30%

basics

~20 s

OPA requires bundle roots to be disjoint. It refuses to activate a bundle whose roots overlap another configured bundle's, records the error and keeps serving what it had, so the new rules silently never take effect.

open as a page

In Gatekeeper, what changes when the audit controller runs with audit-from-cache enabled?

level: middleimportance: nice to knowfreq 34%

basics

~10 s

Gatekeeper's audit normally reads each constrained kind from the API server every cycle. With --audit-from-cache it evaluates Gatekeeper's replicated object cache instead: far cheaper, but unreplicated kinds are invisible and silently report zero violations.

open as a page

gator test in your rule repo's CI exits 0 on a manifest you know violates the constraint — why?

level: middleimportance: nice to knowfreq 30%

basics

~20 s

Usual causes: the constraint is set to dryrun or warn, so violations print without failing the exit code; the rule files were never in the input set; the match block selects nothing; or the CI step discards the status.

open as a page

How does the location path in a Gatekeeper Assign select a field inside a Pod?

level: middleimportance: nice to knowfreq 34%

basics

~20 s

The location is a dotted path from the object's root, with list entries picked by a key filter such as spec.containers[name:*]. Missing intermediate fields are created on the way; a glob only matches list entries that already exist.

open as a page

Your OPA decision logs are rate-limited and an auditor wants proof one request was evaluated last Tuesday — what can you show?

level: seniorimportance: nice to knowfreq 34%

basics

~20 s

A rate-limited or sampled OPA decision log is telemetry, not a ledger. You can show the entries that survived, but rate-limited, dropped and buffer-lost decisions leave no trace at all, so a missing entry proves nothing about whether the policy ran.

open as a page

Your OPA sidecars hold a 400 MB data document and keep OOMing. What do you do?

level: seniorimportance: nice to knowfreq 30%

basics

~20 s

Every OPA instance holds the whole data document in memory, so the cost is paid per replica and per sidecar. Shrink it: ship only the fields rules read, scope bundle roots per consumer, and key the document by the lookup value.

open as a page

How do you share Rego helpers across Gatekeeper ConstraintTemplates?

level: seniorimportance: nice to knowfreq 27%

basics

~20 s

Through the ConstraintTemplate's libs field: each helper is Rego source shipped inside the same object, under the lib package namespace and imported as data.lib.<name>. A template is self-contained, so every one carries its own copy.

open as a page

In Gatekeeper, what does an external data Provider add to a rule, and what does a slow one do to admission?

level: seniorimportance: nice to knowfreq 28%

basics

~20 s

A Provider registers an HTTPS service Gatekeeper may call during evaluation, letting a rule resolve a fact no cluster object holds — an image tag to its digest. The call runs inside the admission request, so provider latency becomes request latency.

open as a page

In a Gatekeeper ConstraintTemplate, what belongs in the rule body versus in its parameters?

level: seniorimportance: nice to knowfreq 40%

basics

~20 s

Put the invariant in the template body and the values that vary between teams in parameters, declared with types in the openAPIV3Schema. Fork into a second template only when the logic differs, not when a number does.

open as a page

When should you call OPA's /v1/compile instead of /v1/data?

level: seniorimportance: nice to knowfreq 27%

basics

~20 s

When you cannot supply every fact at query time. /v1/data needs a complete input and answers with a value; /v1/compile takes a query plus the references you name as unknown and answers with the conditions that are still left to check.

open as a page

Centralizing OPA as one shared decision service — what leaves each caller that never left before?

level: seniorimportance: nice to knowfreq 33%

basics

~20 s

Every query's input document. A rule can only judge facts it is given, so the input carries account, tenant and requester identifiers, and centralizing sends all of it across a boundary on every call and usually into a decision-log store.

open as a page

An OPA ext_authz result returns allowed true plus a resolved-subject header. What must hold for the upstream to trust it?

level: seniorimportance: nice to knowfreq 38%

basics

~10 s

The proxy must be the only way in, and the caller must not be able to set that header themselves. Any route around the gate hands the upstream a subject nobody authenticated.

open as a page

showing 31–45 of 45