Adopt Go native FIPS 140-3 module (GOFIPS140) in omnibus-gitlab
Summary
Adopt Go's native FIPS 140-3 cryptographic module (GOFIPS140) for the Go
components built by omnibus-gitlab, replacing the golang-fips fork
(GOEXPERIMENT=boringcrypto). This is the omnibus-gitlab portion of
&22761 (closed).
The legacy golang-fips toolchain sunsets at Go 1.26 EOL (~February 2027), so
this is both a compliance and a maintenance necessity. The native module holds
full CMVP validation (module v1.0.0).
Scope (omnibus-gitlab)
omnibus-gitlab does not build the Go toolchain itself — the FIPS builder images
(*_fips, from gitlab-omnibus-builder) ship it. omnibus consumes it, gates
FIPS on USE_SYSTEM_SSL=true, passes FIPS_MODE=1 to each component Makefile,
and sets GOEXPERIMENT=boringcrypto directly for gitlab-pages. The work here
is to add a reversible switch to the native GOFIPS140 activation.
Work
- Add a two-way-door gate (
USE_GO_FIPS_MODULE, default off) inBuild::Check, plus a pinnedGO_FIPS_MODULE_VERSION. (!9595 (merged)) - Export
GOFIPS140per Go component (gitlab-pages,gitlab-shell,gitaly,workhorse) when native mode is on, else keep boringcrypto. (!9595 (merged)) - CI toggle:
USE_GO_FIPS_MODULE+FIPS_BUILDER_IMAGE_SUFFIXso FIPS build and verify jobs can run on the base (upstream Go) images. (!9595 (merged)) - Specs and docs. (!9595 (merged))
Dependencies (must land before the native path is usable remaining gate: release pins)
-
Upstream component MRs honoring
GOFIPS140(per &22761 (closed)); the critical blocker is labkit splitting itscrypto/boringdependency behind build tags. Done 2026-08: labkit released the build-tag split in v1.64.9 (2026-08-03), and all component bumps merged by 2026-08-20. The remaining gate is release pins, not code: - gitlab-shell: cleared. v14.57.0 (2026-08-28) is the first fips-capable tag; v14.57.3 (2026-09-04) carries labkit v1.64.11 + labkit/v2 v2.35.0 (includes the fips/sshalgo port from gitlab-shell!1524 (merged)). Any 19.4 package pinning v14.57.x is fips-capable. - gitaly: still open. Latest tag v19.3.1 (2026-08-25) carries labkit v1.64.1; the labkit bump (v1.64.11 via gitaly!9076 (merged)) is master-only, so the first fips-capable release is 19.4. -
A FIPS build image (or the base image) providing upstream Go for FIPS jobs — omnibus already supports this via
FIPS_BUILDER_IMAGE_SUFFIX="". -
Empirical re-verification: re-run the
golang-fips-native-toggle-testharness (USE_GO_FIPS_MODULE=true+FIPS_BUILDER_IMAGE_SUFFIX="") on current master heads. The 2026-07-15 run failed only on the since-fixed labkit blocker; a clean run is the proof point before any default-flip decision. PASS 2026-09-09 — all four Go components built withGOFIPS140="v1.0.0"and the package job succeeded; evidence in #10002 (comment 3810976584). -
Parallel effort (not an omnibus blocker): CNG toolchain migration — gitlab-org/build/CNG!3010 (merged) (
FIPS pipeline green, in reviewmerged 2026-09-04 — CNG production FIPS images now build on Go's native FIPS 140-3 module).
Other Go binaries (scope decision needed)
omnibus also builds registry, gitlab-kas, and gitlab-elasticsearch-indexer, whose recipes export no GOFIPS140. On _fips builder images these inherited OpenSSL crypto from the fork toolchain implicitly; with USE_GO_FIPS_MODULE=true on base images they build with standard (non-FIPS) Go crypto, unmarked. Either:
- Extend the
env['GOFIPS140'] = Build::Check.go_fips_module_version if Build::Check.use_go_fips_module?export toregistry.rb,gitlab-kas.rb, andgitlab-elasticsearch-indexer.rb, or - Declare these binaries out of FIPS scope in this issue explicitly.
Acceptance criteria
- With the toggle off, FIPS builds are byte-for-byte behaviourally unchanged
(legacy
golang-fips). - With
USE_GO_FIPS_MODULE="true"andFIPS_BUILDER_IMAGE_SUFFIX="", FIPS packages build on upstream Go andgo version -m <binary>reportsGOFIPS140=v1.0.0-...with nogoboringcryptosymbols. - Rollback is a variable flip; no code revert required.
See the attached work plan for full design detail, the cross-repo coordination notes, and verification steps.
Related to &22761 (closed) Mirrors gitlab-org/build/CNG!3010 (merged) Implemented by !9595 (merged)