Skip to content

Fix OPA configuration handling - #274

Closed
omer9564 wants to merge 2 commits into
mainfrom
per-12470-pdp-config-issue-with-disabled-decision-logs
Closed

omer9564 wants to merge 2 commits into
mainfrom
per-12470-pdp-config-issue-with-disabled-decision-logs

Conversation

@omer9564

Copy link
Copy Markdown
Contributor

No description provided.

@omer9564
omer9564 requested a review from danyi1212 June 19, 2025 08:24
@omer9564
omer9564 force-pushed the per-12470-pdp-config-issue-with-disabled-decision-logs branch from 3593f89 to 5c34c63 Compare June 24, 2025 10:42
@zeevmoney

Copy link
Copy Markdown
Member

Thanks @omer9564. This was a real bug and it's still on main: with decision logs disabled, the OPA config file is never written, so PDP_OPA_PLUGINS (including permit_graph) never load.

The fix is now in #388, built on your change, with you credited as co-author. One adjustment: the services.permit_io credentials are what OPA uses to upload decision logs, so they follow OPA_DECISION_LOG_ENABLED rather than OPA_BEARER_TOKEN_REQUIRED. It also adds tests that render the config for every combination of decision logs, plugins and bearer settings.

Closing this in favour of #388.

@zeevmoney zeevmoney closed this Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants