OPA

Sysdig Secure leverages OPA to strengthen cloud and Kubernetes security with out-of-the-box policies as code.

Sysdig Secure Extends OPA

Sysdig Secure leverages OPA to enforce consistent policies across multiple infrastructure-as-code (IaC) sources (Terraform, Helm, Kustomize) and Kubernetes clusters, using a policy-as-code approach.

WHAT IS OPA?

OPA is an open-source policy engine that unifies policy enforcement for cloud-native environments. Sysdig Secure uses OPA to manage compliance and governance with policy as code.

Cloud Native Runtime Security
falco.org
About
cncf graduated
Created 2016.05.17
140m downloads
releases
0.40.0
Latest
kubernetes
security
containers
cncf
cloud-native
ebpf
hacktoberfest
falco
cloud-native
110+
Monthly Active
Contributors

Features

Apply Policy as Code
Leverage OPA and apply policy-as-code controls across your Kubernetes workloads.
Shift Security Further Left
Scan IaC source files before deployment to prevent runtime security issues
Enforce Compliance and Governance
Automate compliance and governance across the application life cycle by applying out-of-the-box policies.
Infrastructure-as-Code (IaC) Security

Manage risk when configuring cloud infrastructures and shift security further left with IaC security scanning.

LEARN MORE
Risk-Based Prioritization

Fix issues faster with risk-based prioritization, identifying production instances affected by IaC security issues and sorted by severity. Prioritize IaC fixes based on application context.

LEARN MORE
Detailed Risk Posture

Continuously validate risk posture and governance across all of your workloads and multicloud environments by applying out-of-the-box policies.

LEARN MORE
Out-of-the-Box Policies

Scan incoming pull requests for security violations based on pre-defined out-of-the-box policies. Get a comprehensive list of violations, their severity, and the failed resources per file.

LEARN MORE

Managed Service

A fully-managed Prometheus service with enterprise features for open source Prometheus monitoring, such as automatic service detection and assisted integration deployment.

Read more
Managed Service

Dashboards and Querying

Use a simple form-based approach to query your Prometheus time series, or use the powerful Prometheus Query Language (PromQL) to build dashboards and alerts.

Read more
Dashboards and Querying

Prometheus Alerting

Set alerts for Prometheus monitoring metrics and get automated notifications of application issues across your entire environment. Import your recording rules for faster configuration.

Read more
Prometheus Alerting

Configuration and Storage

A radically simplified Prometheus monitoring tool. Our agent can scrape metrics for you and our back end provides long-term time series retention with a unified view across your whole environment.

Read more
Configuration and Storage

Like what you see?