Conftest verify
conftest_verifyVerify conftest policies by running their test_* rules to ensure correctness. Returns per-file pass/fail results or NO_TESTS_FOUND.
Instructions
Run the test_* rules inside *_test.rego files within a conftest policy directory, verifying that the policies themselves are correct. Equivalent to opa test but using conftest's policy-loading machinery. Returns per-file pass/fail results, and NO_TESTS_FOUND when the directory holds no test rules. Requires conftest on PATH or CONFTEST_BINARY set; returns CONFTEST_NOT_FOUND otherwise.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| data | No | Paths to data directories. Each must be inside an allowed root (OPA_MCP_ALLOWED_PATHS). | |
| policy | No | Path to the directory containing both the Rego policies and the `*_test.rego` test files. Must be inside an allowed root (OPA_MCP_ALLOWED_PATHS). Omit to use conftest's default `./policy` directory. | |
| namespace | No | Namespace to verify. Omit to verify all namespaces. | |
| v0Compatible | No | Read the policies as Rego v0 (`--rego-version v0`), the syntax before OPA 1.0: rules without `if`, `deny[msg] { ... }`. conftest reads v1 by default and refuses such a policy. |