Evaluate Rego query
rego_evalEvaluate Rego queries against policies and input documents. Supports batch inputs and v0-compatible policies for pre-1.0 Rego syntax.
Instructions
Evaluate a Rego query against a policy and an input document using opa eval. Returns the standard {result: [...]} shape. The bread-and-butter authoring tool. The policy is optional, so a query alone tries out a built-in or an expression. Pass inputs to evaluate one query against many input documents in one call, and v0Compatible for a policy still written in pre-1.0 Rego.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| input | No | Inline input document. | |
| paths | No | Policy / data file or directory paths. Each must be inside an allowed root. | |
| query | Yes | Rego query to evaluate, e.g. "data.example.allow". | |
| inputs | No | Several input documents to evaluate the same query against, up to 50, in place of `input`/`inputPath`. The result is `batch`: one entry per input, in order, each holding that input's `result` (empty when the query was undefined for it) or an `error`. An input that fails at runtime does not stop the others. A policy that does not compile fails the call, and after an input times out the inputs not yet started come back as `NOT_EVALUATED`. | |
| source | No | Inline Rego policy source. Optional: without `source` or `paths` the query runs on its own, which is enough to try a built-in or an expression. | |
| partial | No | Run partial evaluation rather than full evaluation. | |
| unknowns | No | Refs to treat as unknown during partial evaluation. | |
| inputPath | No | Path to a JSON input file. Mutually exclusive with `input`. | |
| v0Compatible | No | Read the policy as Rego v0 (`--v0-compatible`), the syntax OPA used before 1.0: rules without `if`, partial sets as `deny[msg] { ... }`. Needed for a policy that has not been migrated, which OPA 1.x otherwise refuses to load. Where the tool also takes a query, the query is read as v0 too, with the future keywords imported so `in`, `every` and `some x in` still work in it. | |
| strictBuiltinErrors | No | Treat builtin errors as fatal instead of returning undefined. |