Skip to main content

Overview

Formal policies can call 189 standard OPA built-in functions (reference for each function’s signature). Formal blocks every function that reaches the network or that only makes sense outside a proxy. Formal adds no custom built-ins. The same list applies everywhere a policy runs: in the Control Plane when you save it, on Connectors, and on the Formal Endpoint.

Blocked Functions

These standard OPA functions are not available: Instead of calling http.send, load external data with a Policy Data Loader and read it from data. To run your own code during evaluation, use Hooks.

What Happens if You Call One

The Control Plane compiles every policy before it saves it. A call to a blocked function fails that check, and the policy is not saved:

Allowed Functions

Operators (17)

assign (:=), eq (=), equal (==), neq (!=), lt (<), lte (<=), gt (>), gte (>=), plus (+), minus (-), mul (*), div (/), rem (%), and (&), or (|), and the in membership operator (internal.member_2, internal.member_3)

Numbers (8)

abs, ceil, floor, round, numbers.range, numbers.range_step, format_int, to_number

Aggregates (8)

count, sum, product, max, min, sort, all, any

Arrays (3)

array.concat, array.reverse, array.slice

Sets (3)

intersection, union, set_diff

Objects (10)

object.filter, object.get, object.keys, object.remove, object.subset, object.union, object.union_n, json.filter, json.remove, json.patch

Strings (23)

concat, contains, endswith, indexof, indexof_n, lower, replace, split, sprintf, startswith, strings.any_prefix_match, strings.any_suffix_match, strings.count, strings.replace_n, strings.reverse, substring, trim, trim_left, trim_prefix, trim_right, trim_space, trim_suffix, upper

Regular Expressions and Globs (11)

re_match, regex.find_all_string_submatch_n, regex.find_n, regex.globs_match, regex.is_valid, regex.match, regex.replace, regex.split, regex.template_match, glob.match, glob.quote_meta

Bits (6)

bits.and, bits.lsh, bits.negate, bits.or, bits.rsh, bits.xor

Types and Casts (14)

is_array, is_boolean, is_null, is_number, is_object, is_set, is_string, type_name, cast_array, cast_boolean, cast_null, cast_object, cast_set, cast_string

Encoding (21)

base64.decode, base64.encode, base64.is_valid, base64url.decode, base64url.encode, base64url.encode_no_pad, hex.decode, hex.encode, json.is_valid, json.marshal, json.marshal_with_options, json.unmarshal, json.match_schema, json.verify_schema, urlquery.decode, urlquery.decode_object, urlquery.encode, urlquery.encode_object, yaml.is_valid, yaml.marshal, yaml.unmarshal

Tokens (16)

io.jwt.decode, io.jwt.decode_verify, io.jwt.encode_sign, io.jwt.encode_sign_raw, io.jwt.verify_es256, io.jwt.verify_es384, io.jwt.verify_es512, io.jwt.verify_hs256, io.jwt.verify_hs384, io.jwt.verify_hs512, io.jwt.verify_ps256, io.jwt.verify_ps384, io.jwt.verify_ps512, io.jwt.verify_rs256, io.jwt.verify_rs384, io.jwt.verify_rs512

Time (10)

time.add_date, time.clock, time.date, time.diff, time.format, time.now_ns, time.parse_duration_ns, time.parse_ns, time.parse_rfc3339_ns, time.weekday

Cryptography (15)

crypto.hmac.equal, crypto.hmac.md5, crypto.hmac.sha1, crypto.hmac.sha256, crypto.hmac.sha512, crypto.md5, crypto.sha1, crypto.sha256, crypto.parse_private_keys, crypto.x509.parse_and_verify_certificates, crypto.x509.parse_and_verify_certificates_with_options, crypto.x509.parse_certificate_request, crypto.x509.parse_certificates, crypto.x509.parse_keypair, crypto.x509.parse_rsa_private_key

Networks (7)

net.cidr_contains, net.cidr_contains_matches, net.cidr_expand, net.cidr_intersects, net.cidr_is_valid, net.cidr_merge, net.cidr_overlap

Graphs and GraphQL (9)

graph.reachable, graph.reachable_paths, walk, graphql.is_valid, graphql.parse, graphql.parse_and_verify, graphql.parse_query, graphql.parse_schema, graphql.schema_is_valid

Other (8)

uuid.parse, uuid.rfc4122, semver.compare, semver.is_valid, units.parse, units.parse_bytes, rand.intn, opa.runtime

Read Deployment Settings with opa.runtime

opa.runtime() returns an object with a single env key. It holds only the environment variables whose names start with FORMAL_POLICY_ENV_, read from the Connector or Endpoint that evaluates the policy. Other variables, such as credentials, are never exposed. Set a variable on the Connector:
Read it in a policy:
If the variable isn’t set, region is undefined and the rule doesn’t match.

Next Steps

Evaluation

Inputs available at each policy stage

Operations

Validate, test, and troubleshoot policies