You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

OPA/Rego Azure诊断设置策略编译WASM报错求助

关于Azure资源诊断设置合规性Rego策略编译WASM的问题

Rego策略

package azure_resources_diagnostic_settings
default compliant = false
# logs
# description: Checks whether if logs configuration matches against the provided configuration. If no log configuration is provided, then the resource is considered compliant by default.
# parameters:
#   - Diagnostic Setting Logs to be evaluated.
#   - Configuration against which it must be compared.
# output:
#   true:
#     - No Logs configuration is provided.
#     - Diagnostic Setting Logs configuration matches with the one on the provided configuration.
#   false: At least one log setting doesn't matches when comparing it against the provided configuration.
logs(logsSettings, configuration) = true
{
  object.get(configuration, "logs", null) == null
}
else = true
{
  enabled = [temp | temp := logsSettings[_]; temp.enabled == true]
  object.get(configuration, "logs", null) != null
  object.get(configuration.logs, "categoryGroups", null) != null
  count([temp | temp := enabled[_]; lower(temp.categoryGroup) == lower(configuration.logs.categoryGroups[_])]) == count(configuration.logs.categoryGroups)
}
else = true
{
  enabled = [temp | temp := logsSettings[_]; temp.enabled == true]
  object.get(configuration, "logs", null) != null
  object.get(configuration.logs, "categories", null) != null
  count([temp | temp := enabled[_]; lower(temp.category) == lower(configuration.logs.categories[_])]) == count(configuration.logs.categories)
}
# evaluate
# description: Checks whether the diagnostic setting configuration of the specified Azure Resource matches against the provided configuration.
# parameters:
#   - Diagnostic Setting to be evaluated.
#   - Configuration against which it must be compared.
# output:
#   true: Diagnostic Setting configuration matches with the one on the provided configuration.
#   false: At least one setting doesn't matches when comparing it against the provided configuration.
evaluate(diagnosticSetting, configuration) = true
{
  object.get(diagnosticSetting.properties, configuration.destinationDetails, null) != null
  count([temp | temp := logs(diagnosticSetting.properties.logs, configuration)]) != 0
}
# main
# description: Checks whether the diagnostic settings configuration of the specified Azure Resource matches against the provided configuration. If the resource is not included in the provided parameters, it is considered compliant by default.
# input: Azure Microsoft Resource basic information along with its diagnostic settings.
# reference: Azure Monitor Diagnostic Settings (https://docs.microsoft.com/en-us/rest/api/monitor/diagnostic-settings/list)
# output:
#   true:
#     - The resource is not included in the provided parameters.
#     - The resource diagnostic settings configuration matches with the provided criteria.
#   false:
#     - There are no diagnostic settings configured.
#     . None of the configured diagnostic settings matches against the provided criteria.
compliant = true
{
  count([temp | temp := data.resources[_]; lower(temp.type) == lower(input.resource.type)]) == 0
}
else = true
{
  configuration = [temp | temp := data.resources[_]; lower(temp.type) == lower(input.resource.type)][0]
  diagnosticSettings = [temp | temp := input.resource.children[_];lower(temp.resourceType) == "microsoft.insights/diagnosticsettings"][0].contents
  count([temp | temp :=  evaluate(diagnosticSettings[_], configuration)]) != 0
}

构建命令

./opa.exe build .\policy.rego --v0-compatible --target wasm --output .\output.tar.gz --entrypoint azure_resources_diagnostic_settings --debug

错误信息

error: 1 error occurred: .\policy.rego:1: rego_type_error: undefined ref:  data.azure_resources_diagnostic_settings.evaluate  
          data.azure_resources_diagnostic_settings.evaluate  
          ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^  
          have: (any, any) => boolean

已尝试操作

  • 将count([temp | temp := evaluate(diagnosticSettings[_], configuration)]) != 0替换为count([temp | temp := diagnosticSettings[_]; evaluate(temp, configuration)]) != 0,错误依旧
  • 定位到evaluate函数中的count([temp | temp := logs(diagnosticSetting.properties.logs, configuration)]) != 0可能是问题点,但未找到解决方案

疑问

  1. 为何该策略在Rego Playground中无此错误?
  2. 如何成功将该策略编译为WASM?

问题解答

1. 为何Rego Playground无此错误?

Rego Playground默认使用较新的OPA版本,运行时的引用解析和类型检查逻辑更宽松,能自动识别同包内的函数引用。而WASM编译启用--v0-compatible模式时,会强制使用旧版本的严格解析规则,错误地将同包函数调用解析为data命名空间下的引用,从而抛出未定义引用的错误。

2. 如何成功编译为WASM?

可通过调整策略逻辑并优化编译参数解决:

步骤1:修复函数调用逻辑

集合推导中直接调用函数生成元素的写法在v0兼容模式下易触发解析错误,需改为条件判断形式:

  • 修改evaluate函数:将count([temp | temp := logs(diagnosticSetting.properties.logs, configuration)]) != 0替换为logs(diagnosticSetting.properties.logs, configuration)
  • 修改compliant规则:将count([temp | temp := evaluate(diagnosticSettings[_], configuration)]) != 0替换为some ds in diagnosticSettings; evaluate(ds, configuration)
步骤2:调整后的完整Rego策略
package azure_resources_diagnostic_settings
default compliant = false

# logs
# description: Checks whether if logs configuration matches against the provided configuration. If no log configuration is provided, then the resource is considered compliant by default.
# parameters:
#   - Diagnostic Setting Logs to be evaluated.
#   - Configuration against which it must be compared.
# output:
#   true:
#     - No Logs configuration is provided.
#     - Diagnostic Setting Logs configuration matches with the one on the provided configuration.
#   false: At least one log setting doesn't matches when comparing it against the provided configuration.
logs(logsSettings, configuration) = true
{
  object.get(configuration, "logs", null) == null
}
else = true
{
  enabled = [temp | temp := logsSettings[_]; temp.enabled == true]
  object.get(configuration, "logs", null) != null
  object.get(configuration.logs, "categoryGroups", null) != null
  count([temp | temp := enabled[_]; lower(temp.categoryGroup) == lower(configuration.logs.categoryGroups[_])]) == count(configuration.logs.categoryGroups)
}
else = true
{
  enabled = [temp | temp := logsSettings[_]; temp.enabled == true]
  object.get(configuration, "logs", null) != null
  object.get(configuration.logs, "categories", null) != null
  count([temp | temp := enabled[_]; lower(temp.category) == lower(configuration.logs.categories[_])]) == count(configuration.logs.categories)
}

# evaluate
# description: Checks whether the diagnostic setting configuration of the specified Azure Resource matches against the provided configuration.
# parameters:
#   - Diagnostic Setting to be evaluated.
#   - Configuration against which it must be compared.
# output:
#   true: Diagnostic Setting configuration matches with the one on the provided configuration.
#   false: At least one setting doesn't matches when comparing it against the provided configuration.
evaluate(diagnosticSetting, configuration) = true
{
  object.get(diagnosticSetting.properties, configuration.destinationDetails, null) != null
  logs(diagnosticSetting.properties.logs, configuration)
}

# main
# description: Checks whether the diagnostic settings configuration of the specified Azure Resource matches against the provided configuration. If the resource is not included in the provided parameters, it is considered compliant by default.
# input: Azure Microsoft Resource basic information along with its diagnostic settings.
# reference: Azure Monitor Diagnostic Settings
# output:
#   true:
#     - The resource is not included in the provided parameters.
#     - The resource diagnostic settings configuration matches with the provided criteria.
#   false:
#     - There are no diagnostic settings configured.
#     . None of the configured diagnostic settings matches against the provided criteria.
compliant = true
{
  count([temp | temp := data.resources[_]; lower(temp.type) == lower(input.resource.type)]) == 0
}
else = true
{
  configuration = [temp | temp := data.resources[_]; lower(temp.type) == lower(input.resource.type)][0]
  diagnosticSettings = [temp | temp := input.resource.children[_];lower(temp.resourceType) == "microsoft.insights/diagnosticsettings"][0].contents
  some ds in diagnosticSettings
  evaluate(ds, configuration)
}
步骤3:重新执行构建命令

如果不需要兼容旧版OPA,可移除--v0-compatible参数(该参数是触发解析错误的核心原因之一):

./opa.exe build .\policy.rego --target wasm --output .\output.tar.gz --entrypoint azure_resources_diagnostic_settings --debug

若必须保持v0兼容,使用调整后的策略代码重新编译即可。

内容的提问来源于stack exchange,提问作者delucaezequiel

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.12 09:14:53