[ 
https://issues.apache.org/jira/browse/CAMEL-24830?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Claus Ibsen reassigned CAMEL-24830:
-----------------------------------

    Assignee: Andrea Cosentino

> camel-opa - OpaSecurityPolicy should support the in-process WASM evaluation 
> mode
> --------------------------------------------------------------------------------
>
>                 Key: CAMEL-24830
>                 URL: https://issues.apache.org/jira/browse/CAMEL-24830
>             Project: Camel
>          Issue Type: Improvement
>            Reporter: Claus Ibsen
>            Assignee: Andrea Cosentino
>            Priority: Major
>
> h2. Problem
> {{OpaSecurityPolicy}} (an {{AuthorizationPolicy}}) is the idiomatic way to 
> guard a route segment: {{.policy(opaPolicy)}} and a deny throws 
> {{CamelAuthorizationException}}. But it only has the server constructor, 
> {{OpaSecurityPolicy(String serverUrl, String policyPath)}}, so it can only 
> use the REST evaluator. The producer supports 
> {{evaluationMode=wasm&policyBundle=...}} for in-process evaluation, and that 
> is the mode we recommend for hot paths such as AI tool calls (see the blog 
> post "Authorizing what an AI agent may do in Apache Camel"), which today has 
> to fall back to {{interceptFrom}} + {{opa:}} producer + {{choice/stop}} 
> because the policy cannot do it.
> h2. Proposal
> * Add a WASM mode to {{OpaSecurityPolicy}}, e.g. a constructor/setters for 
> {{policyBundle}} (and {{evaluationMode}}), reusing 
> {{OpaWasmEvaluator}}/{{OpaWasmPolicyPool}} from the producer.
> * The decision contract ({{CamelOpaDecisionAllow}}, {{CamelOpaDecision}} 
> headers, {{CamelAuthorizationException}} on deny) must be identical across 
> modes.
> * No health check registered in WASM mode, consistent with CAMEL-24743.
> * Document it in {{opa-component.adoc}} under "As a security policy", and 
> update the {{ai-tools-spiffe-opa}} example in camel-examples to use 
> {{.policy(...)}} once available.
> Related: CAMEL-24743.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to