{"id":13644221,"url":"https://github.com/weaveworks/policy-agent","last_synced_at":"2025-04-09T06:12:14.118Z","repository":{"id":170941263,"uuid":"447531673","full_name":"weaveworks/policy-agent","owner":"weaveworks","description":"Weaveworks Policy Agent","archived":false,"fork":false,"pushed_at":"2025-03-27T10:39:46.000Z","size":2661,"stargazers_count":32,"open_issues_count":13,"forks_count":14,"subscribers_count":8,"default_branch":"dev","last_synced_at":"2025-03-27T11:36:39.228Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mpl-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/weaveworks.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2022-01-13T09:04:18.000Z","updated_at":"2024-09-04T18:12:34.000Z","dependencies_parsed_at":"2023-07-19T07:15:19.760Z","dependency_job_id":"46abf919-a64b-4bee-bb42-56494f66e955","html_url":"https://github.com/weaveworks/policy-agent","commit_stats":null,"previous_names":["weaveworks/policy-agent","weaveworks/magalix-policy-agent"],"tags_count":25,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/weaveworks%2Fpolicy-agent","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/weaveworks%2Fpolicy-agent/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/weaveworks%2Fpolicy-agent/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/weaveworks%2Fpolicy-agent/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/weaveworks","download_url":"https://codeload.github.com/weaveworks/policy-agent/tar.gz/refs/heads/dev","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":247987285,"owners_count":21028895,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-02T01:01:59.300Z","updated_at":"2025-04-09T06:12:14.101Z","avatar_url":"https://github.com/weaveworks.png","language":"Go","funding_links":[],"categories":["others","Go"],"sub_categories":[],"readme":"[![codecov](https://codecov.io/gh/weaveworks/policy-agent/branch/dev/graph/badge.svg?token=5HALYBWEIQ)](https://codecov.io/gh/weaveworks/policy-agent) ![build](https://github.com/weaveworks/policy-agent/actions/workflows/build.yml/badge.svg?branch=dev) [![Contributors](https://img.shields.io/github/contributors/weaveworks/policy-agent)](https://github.com/weaveworks/policy-agent/graphs/contributors)\n[![Release](https://img.shields.io/github/v/release/weaveworks/policy-agent?include_prereleases)](https://github.com/weaveworks/policy-agent/releases/latest)\n\n# Weave Policy Agent\n\nWeave Policy Agent is a policy-as-code engine built on Open Policy Agent (OPA) that ensures security, compliance, and best practices for Kubernetes applications. Designed for GitOps workflows, especially Flux, it enables fine-grained policies for Flux applications and tenants, ensuring isolation and compliance across Kubernetes deployments.\n\n## Features\n\n#### Prevent violating K8s resources via admission controller\nWeave Policy Agent uses the Kubernetes admission controller to monitor any Kubernetes Resource changes and prevent the ones violating the policies from getting deployed.\n\n#### Prevent violating terraform plans via `tf-controller`\nIf you are using flux's terraform controller ([tf-controller](https://github.com/weaveworks/tf-controller)) to apply and sync your terraform plans, you can use Weave Policy Agent to prevent violating plans from being applied to your cluster.\n\n#### Audit runtime compliance\nThe agent scans Kubernetes resources on the cluster and reports runtime violations at a configurable frequency.\n\n#### Advanced features for flux\nWhile the agent works natively with Kubernetes resources, Weave Policy Agent has specific features allowing fine-grained policy configurations to flux applications and tenants, as well as alerting integration with flux's `notification-controller`\n\n#### Observability via WeaveGitOps UI\nPolicies and violations can be displayed on WeaveGitOps Dashboards allowing better observability of the cluster's compliance.\n\n#### Example Policies\nExample policies that target K8s and Flux best practices are available [here](policies). Users can as well write their policies in Rego using the agent policy CRD.\n\n## Getting started\n\nTo get started, check out this [guide](docs/getting-started.md) on how to install the policy agent to your Kubernetes cluster and explore violations.\n\n## Documentation\n\nPolicy agent guides for running the agent in Weave GitOps Enterprise, and leveraging all its capabilities, are available at [docs.gitops.weave.works](https://docs.gitops.weave.works/docs/policy/intro/).\n\nRefer to this [doc](docs/README.md) for documentation on the high-level architecture and the different components that make up the agent.\n\n## Contribution\n\nNeed help or want to contribute? Please see the links below.\n\u003c!-- - Need help?\n    - Talk to us in\n      the [#weave-policy-agent channel](@todo add channel url)\n      on Weaveworks Community Slack. [Invite yourself if you haven't joined yet.](https://slack.weave.works/) --\u003e\n- Have feature proposals or want to contribute?\n    - Please create a [Github issue](https://github.com/weaveworks/weave-policy-agent/issues).\n    - Learn more about contributing [here](./CONTRIBUTING.md).\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fweaveworks%2Fpolicy-agent","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fweaveworks%2Fpolicy-agent","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fweaveworks%2Fpolicy-agent/lists"}