KOP OPA GateKeeper - Installation Profiles - Rafay Product Documentation

Installation Profiles

Installation Profiles allows the users to pass the installation parameters for OPA Gatekeeper. The Installation Profiles page shows custom and default profiles. A default installation profile is provided that can be leveraged out of box. In cases where installation profiles need to be customized, a custom installation profile can be created.


Create a Custom Installation Profile

Perform the below steps to create a custom installation profile:

Excluded Namespaces and Process
Users are allowed to exclude the namespace(s) and process associated with the selected namespace from evaluation

Sync Objects
Sync Objects allows to sync data into OPA. Kubernetes data can be replicated into OPA via the sync config resource.

Installation Parameters

Note: This requires replication of Kubernetes resources into OPA before they can be evaluated against the enforced policies

New versions of the profile can be created by clicking New Version and going through the same workflow as above. Parameters for the installation profile can be viewed by clicking the info button under Configuration next to Spec.


Using a Custom Installation Profile

Custom Installation Profiles can be selected as part of enabling OPA Gatekeeper when creating or updating a blueprint.


OPA Version Upgrade/Downgrade

As mentioned in the error message, uninstall OPA (remove OPA config from Blueprint), delete CRDs using Kubectl manually and again update the blueprint with OPA v3.7.1. This will successfully downgrade the OPA version

The list of CRDs to be deleted are given below: