Refactor GOFIPS140 export to one central control for all Go builds

Problem

The FIPS toggle exports GOFIPS140 in each Go software definition. After !9771 (closed), seven recipes each contain the same line:

env['GOFIPS140'] = Build::Check.go_fips_module_version if Build::Check.use_go_fips_module?

Each new Go component must add this line. If an author does not add the line, the build makes a non-FIPS binary and gives no warning. The 2026-09-09 toggle run (https://gitlab.com/gitlab-org/omnibus-gitlab/-/jobs/16399836115) showed this gap for registry, gitlab-kas, and gitlab-elasticsearch-indexer.

Goal

Make the FIPS module the default for all Go builds when the toggle is on. Require a manual, explicit step to build a Go component without the FIPS module.

Tasks

  • Export GOFIPS140 one time, at a central point, when Build::Check.use_go_fips_module? is true. Candidate: the build entry point. Recipe env merges over inherited ENV. Verify with one canary run that the process environment survives to the software shellouts.
  • Add an explicit bypass. A recipe must set an explicit marker to opt out of the FIPS module. Document the bypass and its review expectations.
  • Remove the per-recipe GOFIPS140 lines.
  • Re-run the golang-fips-native-toggle-test harness. Confirm GOFIPS140="v1.0.0" in all seven Go component builds, and confirm the bypass works in a canary recipe.

References