Developers / Benchmark
Policy-engine latency, with the method that produced it.
Policy evaluation in the sidecar deployment model is CPU-bound: the decision never leaves the host. What this page measures is the policy engine itself, in process. End-to-end sidecar percentiles are a separate measurement and are still outstanding; the title says which of the two you are reading, because a latency figure without its method is not evidence.
SCOPE
What this figure is, and is not.
Stated first, deliberately, because the same number is misleading one topology over.
It is
Policy evaluation latency measured in the sidecar deployment model, where the engine runs alongside the agent on the same host and the decision path involves no network round-trip.
It is not
- A service-level guarantee. It is a measurement under stated conditions, not a commitment.
- A figure that transfers to other seams. A gateway adapter, a transparent MCP proxy or an HTTP forward-auth hop each add their own cost, on their own path.
- A comparison against other products. Nothing here is measured against another vendor, so nothing here claims to beat one.
RESULTS · POLICY EVALUATION
The decision itself costs about 0.13 of a microsecond.
This is the first figure published on this page, and it is deliberately the narrower of the two this page owes you: the cost of evaluating a policy, measured in process. The conditions are in the second table, beside the number rather than after it, because a latency figure whose conditions arrive afterwards is a marketing claim wearing a lab coat. The end-to-end sidecar percentiles from the load harness are still outstanding, and the distinction matters enough to keep them apart.
A microsecond is a thousand nanoseconds. A typical evaluation is roughly an eight-thousandth of a millisecond, and a large rule set is still under two microseconds. The useful statement is not that this is fast — it is that the decision is cheap enough that anything you can measure in a deployment is the hop around it, not the decision. That is why this page will not print one number and call it latency.
internal/policy: a small allow-list for the simple cases, a rule set with an argument condition for the rule cases, and a deliberately large rule set for the last row. Engine embedded, not a remote OPA.go test -bench -benchtime=3s -count=3 against internal/policy. Three runs per case; the spread between them is the range printed above.What is still owed. Two things, and this page will not pretend either is done. A run on the production instance type rather than a laptop — the number above is honest about its hardware but it is not the hardware you would deploy onto. And p50, p95, p99 and max from the load harness, covering the sidecar path end to end rather than the evaluation alone. Those are the figures an SRE will ask for, and they are not these.
WHAT WAS WITHDRAWN