Refactor GOFIPS140 export to one central control for all Go builds
Problem
The FIPS toggle exports GOFIPS140 in each Go software definition. After !9771 (closed), seven recipes each contain the same line:
env['GOFIPS140'] = Build::Check.go_fips_module_version if Build::Check.use_go_fips_module?Each new Go component must add this line. If an author does not add the line, the build makes a non-FIPS binary and gives no warning. The 2026-09-09 toggle run (https://gitlab.com/gitlab-org/omnibus-gitlab/-/jobs/16399836115) showed this gap for registry, gitlab-kas, and gitlab-elasticsearch-indexer.
Goal
Make the FIPS module the default for all Go builds when the toggle is on. Require a manual, explicit step to build a Go component without the FIPS module.
Tasks
- Export
GOFIPS140one time, at a central point, whenBuild::Check.use_go_fips_module?is true. Candidate: the build entry point. Recipeenvmerges over inheritedENV. Verify with one canary run that the process environment survives to the software shellouts. - Add an explicit bypass. A recipe must set an explicit marker to opt out of the FIPS module. Document the bypass and its review expectations.
- Remove the per-recipe
GOFIPS140lines. - Re-run the
golang-fips-native-toggle-testharness. ConfirmGOFIPS140="v1.0.0"in all seven Go component builds, and confirm the bypass works in a canary recipe.
References
- Scope discussion: #10002 (closed) ("Other Go binaries")
- Interim per-recipe implementation: !9771 (closed) (closes #10090 (closed))
- Empirical evidence: https://gitlab.com/gitlab-org/omnibus-gitlab/-/jobs/16399836115