opa-demo 如何在开放式策略代理中使用基于角色的访问控制(RBAC)。 请参阅。 创建RBAC策略 package rbac.authz # user-role assignments user_roles := { " design_group_kpi_editor " : [ " kpi_editor_design " , " viewer_limit_ds " ], " system_group_kpi_editor " : [ " kpi_editor_system " , " viewer_limit_ds " ], " manufacture_group_kpi_editor " : [ " kpi_editor_manufacture " , " viewer " ], " project_leader " : [ " viewer_limit_ds