Overview
Formal policies can call 189 standard OPA built-in functions (reference for each function’s signature). Formal blocks every function that reaches the network or that only makes sense outside a proxy. Formal adds no custom built-ins. The same list applies everywhere a policy runs: in the Control Plane when you save it, on Connectors, and on the Formal Endpoint.Blocked Functions
These standard OPA functions are not available:
Instead of calling
http.send, load external data with a Policy Data Loader and read it from data. To run your own code during evaluation, use Hooks.
What Happens if You Call One
The Control Plane compiles every policy before it saves it. A call to a blocked function fails that check, and the policy is not saved:Allowed Functions
Operators (17)
assign (:=), eq (=), equal (==), neq (!=), lt (<), lte (<=), gt (>), gte (>=), plus (+), minus (-), mul (*), div (/), rem (%), and (&), or (|), and the in membership operator (internal.member_2, internal.member_3)
Numbers (8)
abs, ceil, floor, round, numbers.range, numbers.range_step, format_int, to_number
Aggregates (8)
count, sum, product, max, min, sort, all, any
Arrays (3)
array.concat, array.reverse, array.slice
Sets (3)
intersection, union, set_diff
Objects (10)
object.filter, object.get, object.keys, object.remove, object.subset, object.union, object.union_n, json.filter, json.remove, json.patch
Strings (23)
concat, contains, endswith, indexof, indexof_n, lower, replace, split, sprintf, startswith, strings.any_prefix_match, strings.any_suffix_match, strings.count, strings.replace_n, strings.reverse, substring, trim, trim_left, trim_prefix, trim_right, trim_space, trim_suffix, upper
Regular Expressions and Globs (11)
re_match, regex.find_all_string_submatch_n, regex.find_n, regex.globs_match, regex.is_valid, regex.match, regex.replace, regex.split, regex.template_match, glob.match, glob.quote_meta
Bits (6)
bits.and, bits.lsh, bits.negate, bits.or, bits.rsh, bits.xor
Types and Casts (14)
is_array, is_boolean, is_null, is_number, is_object, is_set, is_string, type_name, cast_array, cast_boolean, cast_null, cast_object, cast_set, cast_string
Encoding (21)
base64.decode, base64.encode, base64.is_valid, base64url.decode, base64url.encode, base64url.encode_no_pad, hex.decode, hex.encode, json.is_valid, json.marshal, json.marshal_with_options, json.unmarshal, json.match_schema, json.verify_schema, urlquery.decode, urlquery.decode_object, urlquery.encode, urlquery.encode_object, yaml.is_valid, yaml.marshal, yaml.unmarshal
Tokens (16)
io.jwt.decode, io.jwt.decode_verify, io.jwt.encode_sign, io.jwt.encode_sign_raw, io.jwt.verify_es256, io.jwt.verify_es384, io.jwt.verify_es512, io.jwt.verify_hs256, io.jwt.verify_hs384, io.jwt.verify_hs512, io.jwt.verify_ps256, io.jwt.verify_ps384, io.jwt.verify_ps512, io.jwt.verify_rs256, io.jwt.verify_rs384, io.jwt.verify_rs512
Time (10)
time.add_date, time.clock, time.date, time.diff, time.format, time.now_ns, time.parse_duration_ns, time.parse_ns, time.parse_rfc3339_ns, time.weekday
Cryptography (15)
crypto.hmac.equal, crypto.hmac.md5, crypto.hmac.sha1, crypto.hmac.sha256, crypto.hmac.sha512, crypto.md5, crypto.sha1, crypto.sha256, crypto.parse_private_keys, crypto.x509.parse_and_verify_certificates, crypto.x509.parse_and_verify_certificates_with_options, crypto.x509.parse_certificate_request, crypto.x509.parse_certificates, crypto.x509.parse_keypair, crypto.x509.parse_rsa_private_key
Networks (7)
net.cidr_contains, net.cidr_contains_matches, net.cidr_expand, net.cidr_intersects, net.cidr_is_valid, net.cidr_merge, net.cidr_overlap
Graphs and GraphQL (9)
graph.reachable, graph.reachable_paths, walk, graphql.is_valid, graphql.parse, graphql.parse_and_verify, graphql.parse_query, graphql.parse_schema, graphql.schema_is_valid
Other (8)
uuid.parse, uuid.rfc4122, semver.compare, semver.is_valid, units.parse, units.parse_bytes, rand.intn, opa.runtime
Read Deployment Settings with opa.runtime
opa.runtime() returns an object with a single env key. It holds only the environment variables whose names start with FORMAL_POLICY_ENV_, read from the Connector or Endpoint that evaluates the policy. Other variables, such as credentials, are never exposed.
Set a variable on the Connector:
region is undefined and the rule doesn’t match.
Next Steps
Evaluation
Inputs available at each policy stage
Operations
Validate, test, and troubleshoot policies