mirror of
https://github.com/microsoft/regorus.git
synced 2026-08-05 02:16:11 +00:00
Regorus now defaults to rego v1. `import rego.v1` is no longer needed. Additionally, `future` keywords are automatically imported. See https://www.openpolicyagent.org/docs/latest/v0-upgrade/#changes-to-rego-in-opa-v10 to understand the differences between rego v1 and v0. BREAKING CHANGE: v0 style policies will error out by default. To enable v0 behavior, call engine.set_rego_v0(true) before loading policies. Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>
26 lines
1.4 KiB
Rego
26 lines
1.4 KiB
Rego
package example
|
|
|
|
default allow := false # unless otherwise defined, allow is false
|
|
|
|
allow := true if { # allow is true if...
|
|
count(violation) == 0 # there are zero violations.
|
|
}
|
|
|
|
violation[server.id] if { # a server is in the violation set if...
|
|
some server
|
|
public_server[server] # it exists in the 'public_server' set and...
|
|
server.protocols[_] == "http" # it contains the insecure "http" protocol.
|
|
}
|
|
|
|
violation[server.id] if { # a server is in the violation set if...
|
|
server := input.servers[_] # it exists in the input.servers collection and...
|
|
server.protocols[_] == "telnet" # it contains the "telnet" protocol.
|
|
}
|
|
|
|
public_server[server]if { # a server exists in the public_server set if...
|
|
some i, j
|
|
server := input.servers[_] # it exists in the input.servers collection and...
|
|
server.ports[_] == input.ports[i].id # it references a port in the input.ports collection and...
|
|
input.ports[i].network == input.networks[j].id # the port references a network in the input.networks collection and...
|
|
input.networks[j].public # the network is public.
|
|
} |