Migrate Rego to v1 syntax
rego_migrate_v1Migrate Rego v0 policies to Rego v1: rename reserved rules, replace removed built-ins, format syntax with opa fmt, validate with opa check, and compare rule/value equivalence against test inputs.
Instructions
Migrate Rego v0 source to Rego v1. First renames what v1 reserves (a rule called contains, every, if or in, and every reference to it in the module) and replaces built-ins v1 removed: re_match and net.cidr_overlap by their v1 names, and all, any, set_diff and the cast_* family by a helper function appended to the module that returns exactly what the built-in did, so behaviour does not change. re_match and net.cidr_overlap get such a helper too where the rename would change behaviour: the module mocks one spelling with with while calling both, or binds regex or net itself. Then opa fmt --rego-v1 converts the syntax (if, contains, import rego.v1) and opa check validates the result. rewrites lists each change by line and notes says why; a renamed rule must also be renamed in any other module that uses it. Pass inputs to evaluate the original as v0 and the result as v1 against each and compare every rule of the package, and queries to compare expressions too, such as calls to its functions; equivalence reports any difference. Evaluating runs the policy, http.send included. Returns the migrated source even when check finds remaining errors. A source that parses only as Rego v1 is returned unchanged; one that parses as both, such as v1 that imports rego.v1, is reformatted like any other. If the source parses as neither, returns INVALID_REGO with opa's own message.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| inputs | No | Up to 20 input documents to check the migration against. The original is evaluated as Rego v0 and the migrated policy as Rego v1 against each one, every rule of the package that is not a function is compared by value and by type, and `equivalence` reports any that differ. | |
| source | Yes | Rego v0 source to migrate to Rego v1 syntax. Rules named with a word v1 reserves are renamed and built-ins v1 removed are replaced before `opa fmt --rego-v1` converts the syntax; any remaining issues are returned in `errors` so you can resolve them manually. | |
| queries | No | Up to 10 Rego expressions to compare on each of `inputs` as well. A function has no value without arguments, so this is how functions are compared: `data.lib.names.label_ok(input.name, input.label)`. An expression that names a rule this tool renames, as `data.<package>.<rule>`, reaches it under its new name on the migrated side. |