What signals and metrics do you track to operate Open Policy Agent (OPA) well?
Quick Answer
For Open Policy Agent (OPA), watch policy evaluation latency at admission, count of denied vs audited violations, and policy unit-test coverage. Trend them over time; a single scan is a snapshot, the trend tells you if you are getting more secure or just accumulating debt.
Detailed Answer
Operating a scanner is not "turn it on" — it needs the same observability as any production system. For Open Policy Agent (OPA), the signals that matter are policy evaluation latency at admission, count of denied vs audited violations, and policy unit-test coverage.
Trend them. Rising Critical counts on a stable codebase usually means a base image or dependency has aged, not that developers got careless. A rising false-positive rate is an early warning that the gate is about to lose the team's trust. Scan duration matters because a slow gate is a gate people route around.
Feed these into a dashboard alongside remediation SLAs so security posture is visible to the people who own it, not buried in a tool nobody logs into.
Code Example
# Signals to track for Open Policy Agent (OPA) # policy evaluation latency at admission, count of denied vs audited violations, and policy unit-test coverage # rule: trend over time, don't react to a single scan # rule: watch false-positive rate as closely as finding count
Interview Tip
Name false-positive rate as a leading indicator — it shows you understand adoption, not just scanning.