Batch-evaluate OPA policy against input files
opa_execEvaluate a policy decision against multiple input files independently and return per-file results, with optional fail gates for CI policy checks.
Instructions
Evaluate a policy decision against one or more input files using opa exec --format=json. Unlike rego_eval (single input), opa exec processes every file independently and returns a per-file result -- ideal for CI pipelines that check many config files against a policy in one call. Supply bundle for a bundle, or dataPaths for plain .rego, JSON and YAML files and directories, which are loaded as opa eval --data loads them; the two are mutually exclusive. Each file that fails evaluation appears in results with an error field rather than a result field. Set one of fail/failDefined/failNonEmpty to turn the call into a CI gate: the result then reports failed: true (instead of erroring) when the gate condition is met.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| fail | No | CI gate: report `failed: true` when any decision is undefined or errors. Mutually exclusive with `failDefined` and `failNonEmpty`. | |
| bundle | No | Path to an OPA bundle directory or `.tar.gz` archive to load as the policy source. Mutually exclusive with `dataPaths`. | |
| timeout | No | Per-exec evaluation timeout as a Go duration, e.g. `"30s"` or `"5m"`. Still bounded by the server subprocess timeout (OPA_MCP_TIMEOUT_MS). | |
| decision | Yes | The policy entrypoint to evaluate for each input, e.g. `"authz/allow"`. `opa exec` names a decision by slash-separated path with no `data.` prefix; the Rego reference forms (`data.authz.allow`, `authz.allow`) are accepted here and converted, because passing one straight through leaves every file undefined. | |
| dataPaths | No | Policy and data files or directories, loaded the way `opa eval --data` loads them: a `.rego` file as a module, a JSON or YAML file merged into the data root, a directory recursively, so every JSON and YAML file in it is data and must parse. One difference: a bundle archive (`.tar.gz`) inside a directory is not loaded, and `warnings` names it. A bundle given here directly (an archive, or a directory holding a `.manifest`) is loaded as a bundle; bundles and plain paths cannot be mixed. To load a directory as a bundle, reading only its `.rego` files and those named data.json, data.yaml or data.yml, pass it as `bundle`. Mutually exclusive with `bundle`. | |
| inputPaths | Yes | One or more JSON/YAML input file paths, or a directory containing input files. OPA evaluates each file independently. Every path must be inside an allowed root. | |
| failDefined | No | CI gate: report `failed: true` when any decision is defined or errors. Use when a defined result means a violation. Mutually exclusive with `fail` and `failNonEmpty`. | |
| failNonEmpty | No | CI gate: report `failed: true` when any decision result is non-empty or errors. Mutually exclusive with `fail` and `failDefined`. | |
| v0Compatible | No | Read the policy as Rego v0 (`--v0-compatible`), the syntax OPA used before 1.0: rules without `if`, partial sets as `deny[msg] { ... }`. Needed for a policy that has not been migrated, which OPA 1.x otherwise refuses to load. Where the tool also takes a query, the query is read as v0 too, with the future keywords imported so `in`, `every` and `some x in` still work in it. | |
| v1Compatible | No | Opt in to OPA v1.0-compatible behaviors (`--v1-compatible`). |