Adopt Go native FIPS 140-3 module (GOFIPS140) in omnibus-gitlab

Summary

Adopt Go's native FIPS 140-3 cryptographic module (GOFIPS140) for the Go components built by omnibus-gitlab, replacing the golang-fips fork (GOEXPERIMENT=boringcrypto). This is the omnibus-gitlab portion of &22761 (closed).

The legacy golang-fips toolchain sunsets at Go 1.26 EOL (~February 2027), so this is both a compliance and a maintenance necessity. The native module holds full CMVP validation (module v1.0.0).

Scope (omnibus-gitlab)

omnibus-gitlab does not build the Go toolchain itself — the FIPS builder images (*_fips, from gitlab-omnibus-builder) ship it. omnibus consumes it, gates FIPS on USE_SYSTEM_SSL=true, passes FIPS_MODE=1 to each component Makefile, and sets GOEXPERIMENT=boringcrypto directly for gitlab-pages. The work here is to add a reversible switch to the native GOFIPS140 activation.

Work

  • Add a two-way-door gate (USE_GO_FIPS_MODULE, default off) in Build::Check, plus a pinned GO_FIPS_MODULE_VERSION. (!9595 (merged))
  • Export GOFIPS140 per Go component (gitlab-pages, gitlab-shell, gitaly, workhorse) when native mode is on, else keep boringcrypto. (!9595 (merged))
  • CI toggle: USE_GO_FIPS_MODULE + FIPS_BUILDER_IMAGE_SUFFIX so FIPS build and verify jobs can run on the base (upstream Go) images. (!9595 (merged))
  • Specs and docs. (!9595 (merged))

Dependencies (must land before the native path is usable remaining gate: release pins)

  • Upstream component MRs honoring GOFIPS140 (per &22761 (closed)); the critical blocker is labkit splitting its crypto/boring dependency behind build tags. Done 2026-08: labkit released the build-tag split in v1.64.9 (2026-08-03), and all component bumps merged by 2026-08-20. The remaining gate is release pins, not code: - gitlab-shell: cleared. v14.57.0 (2026-08-28) is the first fips-capable tag; v14.57.3 (2026-09-04) carries labkit v1.64.11 + labkit/v2 v2.35.0 (includes the fips/sshalgo port from gitlab-shell!1524 (merged)). Any 19.4 package pinning v14.57.x is fips-capable. - gitaly: still open. Latest tag v19.3.1 (2026-08-25) carries labkit v1.64.1; the labkit bump (v1.64.11 via gitaly!9076 (merged)) is master-only, so the first fips-capable release is 19.4.

  • A FIPS build image (or the base image) providing upstream Go for FIPS jobs — omnibus already supports this via FIPS_BUILDER_IMAGE_SUFFIX="".

  • Empirical re-verification: re-run the golang-fips-native-toggle-test harness (USE_GO_FIPS_MODULE=true + FIPS_BUILDER_IMAGE_SUFFIX="") on current master heads. The 2026-07-15 run failed only on the since-fixed labkit blocker; a clean run is the proof point before any default-flip decision. PASS 2026-09-09 — all four Go components built with GOFIPS140="v1.0.0" and the package job succeeded; evidence in #10002 (comment 3810976584).

  • Parallel effort (not an omnibus blocker): CNG toolchain migration — gitlab-org/build/CNG!3010 (merged) (FIPS pipeline green, in review merged 2026-09-04 — CNG production FIPS images now build on Go's native FIPS 140-3 module).

Other Go binaries (scope decision needed)

omnibus also builds registry, gitlab-kas, and gitlab-elasticsearch-indexer, whose recipes export no GOFIPS140. On _fips builder images these inherited OpenSSL crypto from the fork toolchain implicitly; with USE_GO_FIPS_MODULE=true on base images they build with standard (non-FIPS) Go crypto, unmarked. Either:

  • Extend the env['GOFIPS140'] = Build::Check.go_fips_module_version if Build::Check.use_go_fips_module? export to registry.rb, gitlab-kas.rb, and gitlab-elasticsearch-indexer.rb, or
  • Declare these binaries out of FIPS scope in this issue explicitly.

Acceptance criteria

  • With the toggle off, FIPS builds are byte-for-byte behaviourally unchanged (legacy golang-fips).
  • With USE_GO_FIPS_MODULE="true" and FIPS_BUILDER_IMAGE_SUFFIX="", FIPS packages build on upstream Go and go version -m <binary> reports GOFIPS140=v1.0.0-... with no goboringcrypto symbols.
  • Rollback is a variable flip; no code revert required.

See the attached work plan for full design detail, the cross-repo coordination notes, and verification steps.

Related to &22761 (closed) Mirrors gitlab-org/build/CNG!3010 (merged) Implemented by !9595 (merged)

Edited by Jason Plum