[media-types] Re: [EXTERNAL] Re: Re: [IANA #1448 906] application/vnd.rego registration request
Amaury Chamayou <[email protected]> Wed, 15 Apr 2026 06:48:46 +0000
| Newsgroups | gmane.ietf.types |
|---|---|
| Message-ID | <VI0PR83MB059142E53068123FFB2195AAF9222@VI0PR83MB0591.EURPRD83.prod.outlook.com> |
Hi Darrel, Have you asked the Linux Foundation? Can we proceed with the registration in the vendor tree at least for the time being? Thank you, Amaury ________________________________ From: Amaury Chamayou <[email protected]> Sent: 08 April 2026 18:44 To: Alexey Melnikov <[email protected]>; Darrel Miller <[email protected]> Cc: [email protected] <[email protected]>; [email protected] <[email protected]> Subject: [media-types] Re: [EXTERNAL] Re: Re: [IANA #1448906] application/vnd.rego registration request I don't believe the media type is in widespread use, I am asking for it to be registered because I would like to start using it. I have reached out to Anders Eknert beforehand, who confirmed that there was no existing dedicated media type, and has reviewed the contents of the application form before I submitted it. I have found only two mentions of application/vnd.rego so far: https://oneuptime.com/blog/post/2026-03-18-add-artifact-podman-artifact-store/view https://hackmd.io/@oidf-wg-authzen/rJe_FxjLyl Just to make sure: would the registration of application/vnd.rego prevent in any way prevent the potential, eventual registration of application/rego by the LF later on? Thank you, Amaury ________________________________ From: Alexey Melnikov <[email protected]> Sent: 08 April 2026 15:40 To: Darrel Miller <[email protected]>; Amaury Chamayou <[email protected]> Cc: [email protected] <[email protected]>; [email protected] <[email protected]> Subject: [EXTERNAL] Re: [media-types] Re: [IANA #1448906] application/vnd.rego registration request On 08/04/2026 13:08, Darrel Miller wrote: As rego is a product of the Open Policy Agent project (https://www.cncf.io/projects/open-policy-agent-opa/) which is a Linux Foundation effort, would this not be more appropriate in the standards subtree considering LF is a SDO registered with IESG? Sure, we can ask. I think it would depend on whether or not the media type is already in use. Darrel ________________________________ From: Alexey Melnikov <[email protected]><mailto:[email protected]> Sent: Wednesday, April 08, 2026 05:45 To: [email protected]<mailto:[email protected]> <[email protected]><mailto:[email protected]> Cc: [email protected]<mailto:[email protected]> <[email protected]><mailto:[email protected]> Subject: [media-types] Re: [IANA #1448906] application/vnd.rego registration request Hi Amanda, One small comment below, otherwise good to register. On 31/03/2026 19:47, Amanda Baber via RT wrote: > Hi Alexey, > > Would you be able to review this new request by April 14th? > > thanks, > Amanda > > ===== > > Name: Amaury Chamayou > > Email: [email protected]<mailto:[email protected]> > > Media type name: application > > Media subtype name: vnd.rego > > Required parameters: N/A > > Optional parameters: N/A > > Encoding considerations: 8bit If lines longer than 1000 octets are allowed, this should be changed to "binary". > Security considerations: Rego Policies are intended to be parsed, validated, and evaluated by the recipient; however, they may be rejected for the following reasons: > > a) The sender is not trusted > b) The policy is too long > c) The policy is not syntactically or semantically valid > d) The policy refers to unsupported features by the host > > A Rego parser, checker, and runtime must be integrated into the host for a policy to be able to be evaluated against inputs. The language itself is not Turing complete, but integrators must take steps to ensure policy evaluation does not exceed acceptable compute and memory constraints. > > Since the text can contains free-form string literals, it is possible the policy contains sensitive information. > > Policies should be sent over TLS, or a similar encrypted and integrity-protected channel to the host, to avoid possible tampering during transit, and unauthorized disclosure of information to third parties. > Within a local filesystem or access-controlled server, policies may be stored in plain text. > > Interoperability considerations: The contents of this file are expected to be UTF-8 encoded. > > Published specification: https://www.openpolicyagent.org/docs/policy-language > > Applications which use this media: Rego is used to enforce policies in microservices, Kubernetes, CI/CD pipelines, API gateways, Transparency Services etc. > > Fragment identifier considerations: N/A > > Restrictions on usage: No restrictions > > Provisional registration? (standards tree only): No > > Additional information: > > 1. Deprecated alias names for this type: N/A > 2. Magic number(s): N/A > 3. File extension(s): .rego > 4. Macintosh file type code: N/A > 5. Object Identifiers: N/A > > General Comments: > > Person to contact for further information: > > 1. Name: Anders Eknert > 2. Email: [email protected]<mailto:[email protected]> > > Intended usage: COMMON > > Author/Change controller: Open Policy Agent > (https://github.com/open-policy-agent/opa/blob/main/GOVERNANCE.md, https://github.com/open-policy-agent/opa/blob/main/MAINTAINERS.md) Best Regards, Alexey _______________________________________________ media-types mailing list -- [email protected]<mailto:[email protected]> To unsubscribe send an email to [email protected]<mailto:[email protected]> _______________________________________________ media-types mailing list -- [email protected]<mailto:[email protected]> To unsubscribe send an email to [email protected]<mailto:[email protected]> _______________________________________________ media-types mailing list -- [email protected] To unsubscribe send an email to [email protected]