{"id":14384143,"url":"https://github.com/loft-sh/jspolicy","last_synced_at":"2025-05-14T16:03:22.537Z","repository":{"id":38842753,"uuid":"363779064","full_name":"loft-sh/jspolicy","owner":"loft-sh","description":"jsPolicy - Easier \u0026 Faster Kubernetes Policies using JavaScript or TypeScript","archived":false,"fork":false,"pushed_at":"2025-02-14T00:17:46.000Z","size":157649,"stargazers_count":387,"open_issues_count":19,"forks_count":39,"subscribers_count":7,"default_branch":"main","last_synced_at":"2025-04-12T22:17:10.270Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"https://www.jspolicy.com","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/loft-sh.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2021-05-03T00:24:46.000Z","updated_at":"2025-04-05T10:40:42.000Z","dependencies_parsed_at":"2025-03-08T11:49:05.144Z","dependency_job_id":null,"html_url":"https://github.com/loft-sh/jspolicy","commit_stats":null,"previous_names":[],"tags_count":18,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/loft-sh%2Fjspolicy","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/loft-sh%2Fjspolicy/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/loft-sh%2Fjspolicy/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/loft-sh%2Fjspolicy/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/loft-sh","download_url":"https://codeload.github.com/loft-sh/jspolicy/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":248637786,"owners_count":21137538,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-28T18:01:09.755Z","updated_at":"2025-04-12T22:17:45.165Z","avatar_url":"https://github.com/loft-sh.png","language":"Go","funding_links":[],"categories":["Go","Configuration Management"],"sub_categories":[],"readme":"\u003cbr\u003e\n\u003ca href=\"https://www.jspolicy.com\"\u003e\u003cimg src=\"docs/static/media/jspolicy-logo-dark.svg\"\u003e\u003c/a\u003e\n\n### **[Website](https://www.jspolicy.com)** • **[Getting Started Guide](https://www.jspolicy.com/docs/getting-started/installation)** • **[Documentation](https://www.jspolicy.com/docs/why-jspolicy)** • **[Blog](https://loft.sh/blog)** • **[Twitter](https://twitter.com/loft_sh)** • **[Slack](https://slack.loft.sh/)**\n\n![Latest Release](https://img.shields.io/github/v/release/loft-sh/jspolicy?style=for-the-badge\u0026label=Latest%20Release\u0026color=%23007ec6)\n![License: Apache-2.0](https://img.shields.io/github/license/loft-sh/jspolicy?style=for-the-badge\u0026color=%23007ec6)\n\n\n### jsPolicy - Easier \u0026 Faster Kubernetes Policies using JavaScript or TypeScript\n- **Lightning Fast \u0026 Secure Policy Execution** - jsPolicy runs policies with Google's super fast V8 JavaScript engine in a pool of pre-heated sandbox environments. Most policies do not even take a single millisecond to execute\n- **Great Language For Policies** - JavaScript is made for handling and manipulating JSON objects (short for: JavaScript Object Notation!) and Kubernetes uses JSON by converting your YAML to JSON during every API request\n- **3 Policy Types** for anything you need:\n  - **Validating Policies** - Request validation that is as easy as calling `allow()`, `deny(\"This is not allowed\")`, or `warn(\"We'll let this one slip, but upgrade to the new ingress controller\")`\n  - **Mutating Policies** - Simple mutations of the kubectl request payload via `mutate(modifiedObj)`\n  - **Controller Policies** - Run custom JavaScript controllers that react to any changes to the objects in your cluster (controller policies are reactive, so they are not webhooks and part of a Kubernetes API server request but instead react to `Events` in your cluster after they have happened). With controller policies you can write resource sync mechanisms, enforce objects in namespaces, garbage collectors or fully functional CRD controllers\n- **Simple yet Powerful** - Create a functional webhook with a single line of JavaScript or write your own fully blown custom StatefulSet controller in TypeScript with jsPolicy. There are no limits and the possibilities are endless\n- **Easy Cluster Access** - Control cluster state with built-in functions such as `get(\"Pod\", \"v1\", \"my-namespace/my-pod\")`, `list(\"Namespace\", \"v1\")`, `create(limitRange)`, `update(mySecret)` or `remove(configMap)`\n- **Focus on Policy Logic** - Jump right in and only focus on writing your own policy logic or simply reuse existing policies. Let jsPolicy do the rest and don't worry about high-availability, performance tuning, auditing, certificate management, webhook registration, prometheus metrics, shared resource caches, controller boilerplate, dynamic policy management etc. anymore\n- **Turing Complete Policy Language** - Use `loops`, `Promises`, `generator` functions, `?` operators, TypeScript Type-Safe practices, hot reloaders, linting, test frameworks and all other modern JS language features and development best practices for writing clean and easy to maintain policy code\n- **Huge Ecosystem of Libraries** - Use any CommonJS JavaScript or TypeScript library from npmjs or from your private registry\n- **Easy Policy Sharing \u0026 Reuse** - Share entire policies or reusable functions via npmjs or via your private registry\n- **Efficient Policy Development** - Use any of the dev tools available in JavaScript or TypeScript for a highly efficient workflow\n\n\nLearn more on [www.jspolicy.com](https://www.jspolicy.com).\n\n\n[![Join us on Slack!](docs/static/media/slack.svg)](https://slack.loft.sh/)\n\n\u003cbr\u003e\n\n## Architecture \n[![jsPolicy Architecture](docs/static/media/diagrams/jspolicy-architecture.svg)](https://www.jspolicy.com)\n\n![jsPolicy Compatibility](docs/static/media/cluster-compatibility.png)\n\n\nLearn more in the [documentation](https://www.jspolicy.com/docs/why-jspolicy).\n\n\u003cbr\u003e\n\n\u003cp align=\"center\"\u003e\n⭐️ \u003cstrong\u003eDo you like jsPolicy? Support the project with a star\u003c/strong\u003e ⭐️\n\u003c/p\u003e\n\n\u003cbr\u003e\n\n## Quick Start\nTo learn more about jspolicy, [**open the full getting started guide**](https://www.jspolicy.com/docs/getting-started/installation).\n\n### 1. Install jsPolicy\nInstall jsPolicy to your Kubernetes cluster via Helm v3:\n```bash\nhelm install jspolicy jspolicy -n jspolicy --create-namespace --repo https://charts.loft.sh\n```\n\n\n### 2. Create a Policy\nCreate the file `policy.yaml`:\n```bash\n# policy.yaml\napiVersion: policy.jspolicy.com/v1beta1\nkind: JsPolicy\nmetadata:\n  name: \"deny-default-namespace.company.tld\"\nspec:\n  operations: [\"CREATE\"]\n  resources: [\"*\"]\n  scope: Namespaced\n  javascript: |\n    if (request.namespace === \"default\") {\n      deny(\"Creation of resources within the default namespace is not allowed!\");\n    }\n```\n\n### 3. Apply The Policy\nApply the policy in your cluster:\n```bash\nkubectl apply -f policy.yaml\n```\n\n\n### 4. See Policy In Action\n```bash\nkubectl create deployment nginx-deployment -n default --image=nginx\n```\n\n## Contributing\n\nThank you for your interest in contributing! Please refer to\n[CONTRIBUTING.md](https://github.com/loft-sh/jspolicy/blob/main/CONTRIBUTING.md) for guidance.\n\n\u003cbr\u003e\n\n---\n\nThis project is open-source and licensed under Apache 2.0, so you can use it in any private or commercial projects.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Floft-sh%2Fjspolicy","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Floft-sh%2Fjspolicy","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Floft-sh%2Fjspolicy/lists"}