Repository navigation
feat(evaluate): let evaluate policy take --policy more than once - #1247
Conversation
A policy kept at a repository's root sent its .git objects and CI config, which the evaluator never loads and which run into the bundle's file cap. Refs kosli-dev/server#6971 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
A policy and a shared library such as ergo can now be sent in one command without copying them into one directory. Every --policy joins one bundle, each keyed relative to its own root, as opa eval -d does, so a data file keeps its path under data. Two files the evaluator loads under one name are refused, naming both; for any other file the first --policy wins and the copy left behind is named on stderr. Refs kosli-dev/server#6971, kosli-dev/server#7196 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…or loads The help now names the files the evaluator reads (modules other than tests, and the data filenames), where a data file lands under data, that every other file travels unread, and how two --policy roots resolve a name they share. Refs kosli-dev/server#6971, kosli-dev/server#7196 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
allow is always evaluated and must be defined, and every rule the policy package annotates as an entrypoint is evaluated and printed by name. The help now says so, with how the policy package is found among libraries and which annotations are refused. Refs kosli-dev/server#6971 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Claude finished @pbeckham's task in 1m 1s —— View job Review of commits since last pass (
|
…other A root given twice, however spelled, clashed with itself, and a root inside another sent each of its files under two names, which the evaluator reads as two modules declaring the same rules. Pins evaluatorLoads with a table test, since it copies the evaluator's loader, and corrects the policyBundleKey comment that still said every entry is parsed as a module. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
On issue 1 of the review summary: the |
kosli evaluate policynow takes--policymore than once, so a policy and a shared Rego library can be sent in one command from wherever each is kept. The help now says what a bundle carries, which of its files the evaluator loads, and which rules it evaluates and prints.Why
A policy written against a shared library had to be copied into one directory with that library before it could be evaluated, and the copy drifts from the library's own repository. Authors also had no way to learn from the CLI which of their files decide the verdict: that a README travels but is not read, that
data.yamllands underdata, or thatallowmust be defined while everyentrypoint: truerule is returned beside it.What changed
--policyjoins one bundle, and each file is keyed relative to its own root, asopa eval -d one -d tworeads them. Modules import each other by package, so their location does not matter, and a data file keeps thedatapath its own root gives it.README.md, the first--policywins and the copy left behind is named on stderr..gitand hit the 100-file cap.evaluate trail --server-sidestill takes one--policy; its behaviour is unchanged apart from the dot-directory rule.Verification
New tests in
evaluatePolicy_test.gopin down a policy plus a library file travelling as one evaluation, per-root keys including a nesteddata.yaml, refusal of a loaded clash for.rego,data.yaml,data.jsonand*.ergo.yml, first-wins with a stderr notice forREADME.mdand*_test.rego, the caps counted across roots, dot-directories left out, and both help paragraphs. The existing bundle and cap tests still pass unchanged apart from the fixture README's wording.main.ymlruns the full integration suite on push, which covers theevaluate trailandtrailssuites that share the bundle code.🤖 Generated with Claude Code