Wener Notes

rego

约 2 分钟阅读
text
# rule-name IS value IF body
# 多个表达式为 AND
v if { a:=1; a == 1; 2 == 2 }
# if 可以省略
v { "hello" == "world" }
  • 类型
    • Scalar
    • String
    • Object
    • Set
    • Composite
  • Comprehension
    • Array [ <term> | <body> ]
    • Object { <key>: <term> | <body> }
    • Set { <term> | <body> }
  • future keyword
    • if, in, every, contains
    • contains 和 if 是可选的
    • import future.keywords.if
  • Complete Definition
    • 值不可变
  • implicit
    • data, input
  • unification operator =
    • assignment + comparison
    • := + ==

METADATA

  • YAML
    • title
    • description
    • related_resources
    • authors
    • organizations
    • schemas
    • custom
    • scope - package, rule, document, subpackages
    • entrypoint
      • --prune-unused
text
# METADATA
# title: My rule
# description: A rule that determines if x is allowed.
# authors:
# - John Doe <[email protected]>
# entrypoint: true
text

# METADATA
# schemas:
#   - input: schema.input
#   - data.acl: schema["acl-schema"]
allow {
    access := data.acl["alice"]
    access[_] == input.operation
}

# METADATA
# schemas:
#   - input.x: {type: number}
allow {
    input.x == 42
}

通过 Metadata 定义返回结果

text
# METADATA
# title: Example
# description: Example package with documentation
package example

import future.keywords.contains
import future.keywords.if

# METADATA
# title: Deny non admin users
# description: Only admin users are allowed to access these resources
# related_resources:
# - https://docs.example.com/policy/rule/E123
# custom:
#   code: 401
#   error_id: E123
deny contains {
	"code": metadata.custom.code,
	"message": sprintf("Unauthorized due to policy rule (%s, %s)", [
		metadata.custom.error_id,
		concat(",", [ref | ref := metadata.related_resources[_].ref]),
	]),
} if {
	input.admin == false

	metadata := rego.metadata.rule()
}

with

text
ok:= false
h := r  if {
	ok;
	r := {"OK":1, "X":input.X}
}

h := r  if {
	not ok;
	r := {"OK":0, "X":input.X}
}

h2 := r if {
	r:= h with input as {"X":2}
}

External Data

Integration

常用结构

text
# 多个规则
deny[message] if {
  condition
  message := "Why";
}

# 最终
allowed if {
  true
}

FAQ

single-value rule data.example.headers conflicts with

text
headers := {
    "X-OK": "OK",
}

headers["X-OK"] = 1

单个值

text
headers := {
    "X-OK": "X"
} if {}
else = {
    "X-OK": 1
}

关联信息

反向链接、本文链接的其他页面和外部资料。

References

GitHub8 条
Wikipedia1 条
其他外链5 条
最近更新commit b4d3722Edit

On this page