View a selection of projects and talks about integrating OPA with
Kubernetes.
View Kubernetes Admission Control Details![Integration Logo](/img/logos/integrations/styra-das.png)
Styra Declarative Authorization Service
Policy as Code Control Plane by Styra
Styra DAS has native support for mutating and validating Kubernetes
at admission time via a prebuilt ‘system-type’, this is
documented here.
View Details![Integration Logo](/img/logos/opa-no-text-color.png)
Fairwinds Insights Configuration Validation Software
Implements auditing and admission checking of Kubernetes resources
using Rego policy using
Polaris.
View Details![Integration Logo](/img/logos/opa-no-text-color.png)
OPA Gatekeeper
Rego Policy Controller for Kubernetes
OPA Gatekeeper integrates with
Kubernetes Admission
and also uses Custom Resources and the Kubernetes API server to
store policy state.
View OPA Gatekeeper Details![Integration Logo](/img/logos/integrations/kubernetes-authorization.png)
Kubernetes Authorization
View
an example project
showing how it’s possible to integrate OPA with Kubernetes User Authorization.
View Kubernetes Authorization Details![Integration Logo](/img/logos/integrations/spacelift.png)
Spacelift
Spacelift supports Rego as a language to describe policies for various
resource types, including Kubernetes. View the
policy documentation for
more information.
View Spacelift Details![Integration Logo](/img/logos/integrations/clair-datasource.png)
Kubernetes Admission Control using Vulnerability Scanning
This example project in
OPA contrib
uses OPA to enforce admission policy in Kubernetes.
View Details![Integration Logo](/img/logos/integrations/google-kubernetes-engine.png)
GKE Policy Automation
The GKE Policy Automation project provides a set of policies for
validating Kubernetes clusters running on GKE. Review the
policy library here
View GKE Policy Automation Details![Integration Logo](/img/logos/integrations/kubeshield.png)
KubeShield
Secure Kubernetes using eBPF & Open Policy Agent
KubeShield implements runtime policy for containers in a Kubernetes
cluster using eBPF. Follow the
tutorial here
to get up and running.
View KubeShield DetailsImplements the CIS benchmark using Rego for Kubernetes workloads.
View ccbr DetailsIntegrations are ordered by the amount of linked content.