OPA includes a policy-testing framework and the opa test command. Use it for unit tests that prove allowed behavior, denied behavior, boundary cases, missing inputs, malformed data, role combinations, and exceptions. A policy test suite is most valuable when it protects the cases an author is likely to break during a seemingly unrelated rule change.
package authz
test_admin_dev_allowed if {
allow with input as {
"user": {"role": "admin"},
"resource": {"environment": "dev"}
}
}
test_admin_prod_denied if {
not allow with input as {
"user": {"role": "admin"},
"resource": {"environment": "production"}
}
}
Test undefined and missing data
One of the most dangerous policy bugs is disagreement about missing information. Does an absent attribute deny, fall back to a default, or cause an integration error? Write tests for missing identity attributes, unknown resource metadata, incomplete network context, and stale external data.
Test enforcement integration
Unit-tested Rego is not enough. Run integration tests that prove the surrounding application translates the decision correctly. Include OPA unavailable, bundle unavailable, invalid response, timeout, and stale-policy scenarios so the actual fail-open/fail-closed behavior is known before an outage.
Regression-test exceptions
Emergency exceptions tend to outlive their incident. Give exception rules an owner, reason, expiry condition, and tests that make the exceptional path visible. A later cleanup should fail a test if it accidentally broadens the exception rather than removing it.