OPA/Rego Azure诊断设置策略编译WASM报错求助
关于Azure资源诊断设置合规性Rego策略编译WASM的问题
Rego策略
package azure_resources_diagnostic_settings default compliant = false # logs # description: Checks whether if logs configuration matches against the provided configuration. If no log configuration is provided, then the resource is considered compliant by default. # parameters: # - Diagnostic Setting Logs to be evaluated. # - Configuration against which it must be compared. # output: # true: # - No Logs configuration is provided. # - Diagnostic Setting Logs configuration matches with the one on the provided configuration. # false: At least one log setting doesn't matches when comparing it against the provided configuration. logs(logsSettings, configuration) = true { object.get(configuration, "logs", null) == null } else = true { enabled = [temp | temp := logsSettings[_]; temp.enabled == true] object.get(configuration, "logs", null) != null object.get(configuration.logs, "categoryGroups", null) != null count([temp | temp := enabled[_]; lower(temp.categoryGroup) == lower(configuration.logs.categoryGroups[_])]) == count(configuration.logs.categoryGroups) } else = true { enabled = [temp | temp := logsSettings[_]; temp.enabled == true] object.get(configuration, "logs", null) != null object.get(configuration.logs, "categories", null) != null count([temp | temp := enabled[_]; lower(temp.category) == lower(configuration.logs.categories[_])]) == count(configuration.logs.categories) } # evaluate # description: Checks whether the diagnostic setting configuration of the specified Azure Resource matches against the provided configuration. # parameters: # - Diagnostic Setting to be evaluated. # - Configuration against which it must be compared. # output: # true: Diagnostic Setting configuration matches with the one on the provided configuration. # false: At least one setting doesn't matches when comparing it against the provided configuration. evaluate(diagnosticSetting, configuration) = true { object.get(diagnosticSetting.properties, configuration.destinationDetails, null) != null count([temp | temp := logs(diagnosticSetting.properties.logs, configuration)]) != 0 } # main # description: Checks whether the diagnostic settings configuration of the specified Azure Resource matches against the provided configuration. If the resource is not included in the provided parameters, it is considered compliant by default. # input: Azure Microsoft Resource basic information along with its diagnostic settings. # reference: Azure Monitor Diagnostic Settings (https://docs.microsoft.com/en-us/rest/api/monitor/diagnostic-settings/list) # output: # true: # - The resource is not included in the provided parameters. # - The resource diagnostic settings configuration matches with the provided criteria. # false: # - There are no diagnostic settings configured. # . None of the configured diagnostic settings matches against the provided criteria. compliant = true { count([temp | temp := data.resources[_]; lower(temp.type) == lower(input.resource.type)]) == 0 } else = true { configuration = [temp | temp := data.resources[_]; lower(temp.type) == lower(input.resource.type)][0] diagnosticSettings = [temp | temp := input.resource.children[_];lower(temp.resourceType) == "microsoft.insights/diagnosticsettings"][0].contents count([temp | temp := evaluate(diagnosticSettings[_], configuration)]) != 0 }
构建命令
./opa.exe build .\policy.rego --v0-compatible --target wasm --output .\output.tar.gz --entrypoint azure_resources_diagnostic_settings --debug
错误信息
error: 1 error occurred: .\policy.rego:1: rego_type_error: undefined ref: data.azure_resources_diagnostic_settings.evaluate data.azure_resources_diagnostic_settings.evaluate ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ have: (any, any) => boolean
已尝试操作
- 将
count([temp | temp := evaluate(diagnosticSettings[_], configuration)]) != 0替换为count([temp | temp := diagnosticSettings[_]; evaluate(temp, configuration)]) != 0,错误依旧 - 定位到
evaluate函数中的count([temp | temp := logs(diagnosticSetting.properties.logs, configuration)]) != 0可能是问题点,但未找到解决方案
疑问
- 为何该策略在Rego Playground中无此错误?
- 如何成功将该策略编译为WASM?
问题解答
1. 为何Rego Playground无此错误?
Rego Playground默认使用较新的OPA版本,运行时的引用解析和类型检查逻辑更宽松,能自动识别同包内的函数引用。而WASM编译启用--v0-compatible模式时,会强制使用旧版本的严格解析规则,错误地将同包函数调用解析为data命名空间下的引用,从而抛出未定义引用的错误。
2. 如何成功编译为WASM?
可通过调整策略逻辑并优化编译参数解决:
步骤1:修复函数调用逻辑
集合推导中直接调用函数生成元素的写法在v0兼容模式下易触发解析错误,需改为条件判断形式:
- 修改
evaluate函数:将count([temp | temp := logs(diagnosticSetting.properties.logs, configuration)]) != 0替换为logs(diagnosticSetting.properties.logs, configuration) - 修改
compliant规则:将count([temp | temp := evaluate(diagnosticSettings[_], configuration)]) != 0替换为some ds in diagnosticSettings; evaluate(ds, configuration)
步骤2:调整后的完整Rego策略
package azure_resources_diagnostic_settings default compliant = false # logs # description: Checks whether if logs configuration matches against the provided configuration. If no log configuration is provided, then the resource is considered compliant by default. # parameters: # - Diagnostic Setting Logs to be evaluated. # - Configuration against which it must be compared. # output: # true: # - No Logs configuration is provided. # - Diagnostic Setting Logs configuration matches with the one on the provided configuration. # false: At least one log setting doesn't matches when comparing it against the provided configuration. logs(logsSettings, configuration) = true { object.get(configuration, "logs", null) == null } else = true { enabled = [temp | temp := logsSettings[_]; temp.enabled == true] object.get(configuration, "logs", null) != null object.get(configuration.logs, "categoryGroups", null) != null count([temp | temp := enabled[_]; lower(temp.categoryGroup) == lower(configuration.logs.categoryGroups[_])]) == count(configuration.logs.categoryGroups) } else = true { enabled = [temp | temp := logsSettings[_]; temp.enabled == true] object.get(configuration, "logs", null) != null object.get(configuration.logs, "categories", null) != null count([temp | temp := enabled[_]; lower(temp.category) == lower(configuration.logs.categories[_])]) == count(configuration.logs.categories) } # evaluate # description: Checks whether the diagnostic setting configuration of the specified Azure Resource matches against the provided configuration. # parameters: # - Diagnostic Setting to be evaluated. # - Configuration against which it must be compared. # output: # true: Diagnostic Setting configuration matches with the one on the provided configuration. # false: At least one setting doesn't matches when comparing it against the provided configuration. evaluate(diagnosticSetting, configuration) = true { object.get(diagnosticSetting.properties, configuration.destinationDetails, null) != null logs(diagnosticSetting.properties.logs, configuration) } # main # description: Checks whether the diagnostic settings configuration of the specified Azure Resource matches against the provided configuration. If the resource is not included in the provided parameters, it is considered compliant by default. # input: Azure Microsoft Resource basic information along with its diagnostic settings. # reference: Azure Monitor Diagnostic Settings # output: # true: # - The resource is not included in the provided parameters. # - The resource diagnostic settings configuration matches with the provided criteria. # false: # - There are no diagnostic settings configured. # . None of the configured diagnostic settings matches against the provided criteria. compliant = true { count([temp | temp := data.resources[_]; lower(temp.type) == lower(input.resource.type)]) == 0 } else = true { configuration = [temp | temp := data.resources[_]; lower(temp.type) == lower(input.resource.type)][0] diagnosticSettings = [temp | temp := input.resource.children[_];lower(temp.resourceType) == "microsoft.insights/diagnosticsettings"][0].contents some ds in diagnosticSettings evaluate(ds, configuration) }
步骤3:重新执行构建命令
如果不需要兼容旧版OPA,可移除--v0-compatible参数(该参数是触发解析错误的核心原因之一):
./opa.exe build .\policy.rego --target wasm --output .\output.tar.gz --entrypoint azure_resources_diagnostic_settings --debug
若必须保持v0兼容,使用调整后的策略代码重新编译即可。
内容的提问来源于stack exchange,提问作者delucaezequiel
相关产品推荐
相关产品推荐

