Skip to content

feat: enforce OPA runtime parity - #4

Merged
marcialwushu merged 1 commit into
mainfrom
feat/opa-runtime-parity
Oct 4, 2026
Merged

marcialwushu merged 1 commit into
mainfrom
feat/opa-runtime-parity

Conversation

@marcialwushu

Copy link
Copy Markdown
Member

Summary

  • validate the exact decision input contract before OPA evaluation and emit input/output contracts in Rego
  • distinguish UNIQUE, gap, overlap, invalid input, and invalid output results
  • add conformance --parity coverage for missing/extra keys, wrong types, values outside the domain, gaps, overlaps, and invalid outputs
  • evaluate cases in one asynchronous OPA invocation per decision, with timeout and runtime version reporting
  • generate committed policies and Rego tests from the YAML source, and verify generated artifacts in CI
  • use collision-resistant package names, explicit wildcard rules, generated server cases, and a dynamic server port
  • pin OPA 1.4.2 in GitHub Actions and Azure Pipelines

Validation

  • npm run check
  • npm test — 64 tests passed
  • npm run opa:check
  • npm run opa:test — 2 tests passed
  • npm run opa:server:test — 4 generated cases passed
  • OPA parity: example 11/11, numeric 4/4, quoted string 1/1
  • intent validation/tests
  • workflow YAML parsing
  • npm pack --dry-run

@marcialwushu
marcialwushu merged commit 8c02d9d into main Oct 4, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant