3 OPA in Mercari ● Preparing guardrails for Istio at scale ● Enhance Kubernetes Security with Gatekeeper ● Open Policy AgentとSpinnakerで実現するマイクロサービ スの安全な継続的デリバリー ● Introduce Conftest
7 OPA for cloud resources ● Domain agnostic and general purpose policy engine ● terraform plan and configuration can be converted to JSON ● Conftest supports JSON and HCL/HCL2
12 Takeaways ● OPA & Conftest support not only Kubernetes but also a cloud resource (Terraform) use case ● OPA & Conftest covers fine-grained use cases that existing tools don’t support