pub struct OpaPlugin {
host: String,
policy: String,
ssl_verify: bool,
timeout: Duration,
with_consumer: bool,
send_headers_upstream: Vec<String>,
client: Arc<OutboundClient>,
}Expand description
Sends an OPA input document to an external policy server and routes on the
returned decision: allow: true continues (success port), otherwise
rejects (error port).
Fields§
§host: StringOPA base URL (e.g. http://opa:8181).
policy: StringDecision path appended as /v1/data/<policy>.
ssl_verify: boolTLS certificate verification for https callouts.
timeout: DurationWhole-call callout deadline.
with_consumer: boolInclude the matched consumer object in the input document.
send_headers_upstream: Vec<String>OPA-response header names copied onto the request forwarded upstream on allow (lowercased). Empty means none are copied.
client: Arc<OutboundClient>Shared pooled HTTP client (from PluginResources).
Implementations§
Source§impl OpaPlugin
impl OpaPlugin
Sourcepub fn from_config(
config: &HashMap<String, Value>,
resources: &Arc<PluginResources>,
) -> Result<Self, String>
pub fn from_config( config: &HashMap<String, Value>, resources: &Arc<PluginResources>, ) -> Result<Self, String>
Builds the plugin from node config.
Accepted keys:
host(string, required): OPA base URL. Missing → config error.policy(string, required): decision path appended as/v1/data/<policy>. Missing → config error.ssl_verify(bool, defaulttrue): verify TLS certificates forhttpscallouts.timeout(integer ms, default3000): whole-call callout deadline.with_consumer(bool, defaultfalse): include aconsumerobject (built fromcontext.message’sconsumer.*keys) in the input document.with_route/with_service(bool, defaultfalse): accepted for APISIX compatibility but no-ops — featherbit has no route/service objects.send_headers_upstream(array of strings, optional): OPA-response header names copied onto the request forwarded upstream on allow. A configured name absent from the OPA response removes any client-supplied value.
type: opa
config:
host: http://opa:8181
policy: example/allow
with_consumer: true
send_headers_upstream: [x-user-id]
ssl_verify: true
timeout: 3000Sourcefn build_opa_input(&self, ctx: &Context, now_unix: u64) -> Value
fn build_opa_input(&self, ctx: &Context, now_unix: u64) -> Value
Builds the OPA input document from the context, mirroring
opa/helper.lua’s build_opa_input as closely as featherbit’s
Context allows. now_unix is injected so the (otherwise
wall-clock) var.timestamp is testable.
Sourcefn apply_allow(&self, ctx: &mut Context, decision: &OpaDecision)
fn apply_allow(&self, ctx: &mut Context, decision: &OpaDecision)
On an allow decision, copies the configured send_headers_upstream
from the OPA response onto the request forwarded upstream. A configured
header absent from the OPA response removes any client-supplied value.
Sourcefn build_deny(
&self,
ctx: Context,
decision: &OpaDecision,
) -> PluginExecutionError
fn build_deny( &self, ctx: Context, decision: &OpaDecision, ) -> PluginExecutionError
Builds the OPA_DENIED rejection from a deny decision, honoring
OPA-supplied status (default 403), headers, and reason (as the body).
Sourcefn build_error(
&self,
ctx: Context,
status: u16,
message: String,
) -> PluginExecutionError
fn build_error( &self, ctx: Context, status: u16, message: String, ) -> PluginExecutionError
Builds the OPA_ERROR rejection used when the callout fails or the
response cannot be interpreted as a decision.
Trait Implementations§
Source§impl Plugin for OpaPlugin
impl Plugin for OpaPlugin
Source§fn plugin_type(&self) -> &str
fn plugin_type(&self) -> &str
Source§fn execute<'life0, 'life1, 'async_trait>(
&'life0 self,
ctx: Context,
_named_inputs: &'life1 HashMap<String, Value>,
) -> Pin<Box<dyn Future<Output = Result<PluginOutput, PluginExecutionError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
fn execute<'life0, 'life1, 'async_trait>(
&'life0 self,
ctx: Context,
_named_inputs: &'life1 HashMap<String, Value>,
) -> Pin<Box<dyn Future<Output = Result<PluginOutput, PluginExecutionError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
Auto Trait Implementations§
impl Freeze for OpaPlugin
impl !RefUnwindSafe for OpaPlugin
impl Send for OpaPlugin
impl Sync for OpaPlugin
impl Unpin for OpaPlugin
impl UnsafeUnpin for OpaPlugin
impl !UnwindSafe for OpaPlugin
Blanket Implementations§
§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
§impl<T> Instrument for T
impl<T> Instrument for T
§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more