Build FIPS images with upstream Go

Build the FIPS images with the standard Go compiler

The FIPS builder images build a Go compiler from the golang-fips source code. This merge request removes that step.

Why

GitLab moves its Go components to the FIPS 140-3 module in the standard Go release, and the golang-fips project stops at the end of the life of Go 1.26.

We cannot keep the two methods together. The golang-fips compiler accepts the GOFIPS140 setting and builds the program without an error message. The program then contains the GOFIPS140 module and the OpenSSL connection, but a program cannot use the two together. Such a program stops with an error on a host in FIPS mode. This is the host where you install a FIPS package.

The change

The merge request deletes docker/snippets/go_fips and the line GOLANG_FIPS_TAG in docker/VERSIONS. It adds no lines.

This is sufficient. If docker/scripts/snippets.rb does not find a file with the name go_fips, the script uses the file go. Thus the FIPS images install the same standard Go release as the other images.

The FIPS images continue to exist, because they keep the curl_<platform>_fips snippets. These snippets install the development packages that the FIPS builds need to connect to the curl library of the operating system.

Check

./docker/scripts/generate-dockerfile docker/Dockerfile_almalinux_9.erb
./docker/scripts/generate-dockerfile docker/Dockerfile_almalinux_9.erb --fips
diff -u docker/Dockerfile_almalinux_9 docker/Dockerfile_almalinux_9_fips

On almalinux_8, almalinux_9, amazonlinux_2023, ubuntu_22.04, ubuntu_24.04 and ubuntu_26.04, only the curl packages are different. On amazonlinux_2, the openssl11 package and the Node flag --openssl-is-fips are also different. These two items come from other snippets and are not related to this merge request.

A text search for the name golang-fips gives no result.

Merge request reports

Loading
Loading