Add two-way-door toggle for native Go FIPS (GOFIPS140)

What does this MR do?

Introduces a two-way-door toggle to build the Go-based components against upstream Go's native FIPS 140-3 module (GOFIPS140) instead of the golang-fips fork (GOEXPERIMENT=boringcrypto), mirroring the CNG migration in gitlab-org/build/CNG!3010 (merged).

The new behavior is gated behind USE_GO_FIPS_MODULE and defaults to off, so the existing golang-fips build path is unchanged. Enabling it is fully reversible — no code revert required.

Build gate (lib/gitlab/build/check.rb)

  • Adds GO_FIPS_MODULE_VERSION (default v1.0.0, the CMVP-certified module, see gitlab-org#22761 (closed)), plus go_fips_module_version and use_go_fips_module? (true only when use_system_ssl? and USE_GO_FIPS_MODULE=true).
  • boringcrypto_supported? is retained as the legacy fallback.

Go components

  • gitlab-pages, gitlab-shell, gitaly, and workhorse (via gitlab-rails) export GOFIPS140 when native mode is on, otherwise keep setting GOEXPERIMENT=boringcrypto. FIPS_MODE=1 is unchanged. GOFIPS140 and boringcrypto are never set together (cmd/go rejects the combination).

CI toggle

  • gitlab-ci-config/variables.yml adds USE_GO_FIPS_MODULE (default false) and FIPS_BUILDER_IMAGE_SUFFIX (default _fips).
  • FIPS build and verify jobs interpolate ${FIPS_BUILDER_IMAGE_SUFFIX} into their image names. Setting the suffix to "" routes FIPS jobs to the base builder images, which already ship a GOFIPS140-capable upstream Go (GO_VERSION 1.26.4), so no new gitlab-omnibus-builder image variant is needed.

Enabling native FIPS (in a pipeline): set USE_GO_FIPS_MODULE="true" and FIPS_BUILDER_IMAGE_SUFFIX="". If only the build toggle is set, the build fails loudly (cmd/go rejects GOFIPS140 on a golang-fips toolchain) rather than producing a mis-built package.

Docs and specs are included: doc/development/ci-variables.md documents the new variables, and spec/lib/gitlab/build/check_spec.rb covers the gate.

Related to #10002 (closed)

Mirrors gitlab-org/build/CNG!3010 (merged)

Test plan

Warning

This MR only adds the gated plumbing. The native GOFIPS140 path cannot be used until the related upstream project MRs are all in place — the component Makefiles (gitaly, gitlab-pages, gitlab-shell, workhorse) must honor GOFIPS140 and stop forcing GOEXPERIMENT=boringcrypto, and the CNG side (gitlab-org/build/CNG!3010 (merged)) must land. This work is tracked in gitlab-org#22761 (closed). Until then, only the default (legacy golang-fips) path is exercisable.

1. Default path unchanged (this MR, now)

  • Run the standard Trigger:package:fips job with no new variables set.
  • Expect: FIPS jobs pull *_fips images, components build with GOEXPERIMENT=boringcrypto, and rpm-verify-fips stays green — confirming no regression.

2. Native path (once upstream MRs are in place)

  • Run a pipeline with USE_GO_FIPS_MODULE="true" and FIPS_BUILDER_IMAGE_SUFFIX="".
  • Expect: FIPS build/verify jobs run on the base (upstream Go) builder images; no job sets GOEXPERIMENT=boringcrypto.
  • On the resulting binaries, go version -m <binary> reports build GOFIPS140=v1.0.0-..., and no goboringcrypto symbols are present.
  • FIPS verification (rpm-verify-fips / functionality checks) stays green.

3. Mismatch is a loud failure (safety check)

  • Run with USE_GO_FIPS_MODULE="true" but leave FIPS_BUILDER_IMAGE_SUFFIX="_fips".
  • Expect: the build fails visibly because cmd/go rejects GOFIPS140 on a golang-fips toolchain — never a silently mis-built package.

Checklist

See Definition of done.

For anything in this list which will not be completed, please provide a reason in the MR discussion.

Required

  • MR title and description are up to date, accurate, and descriptive.
  • MR targeting the appropriate branch.
  • Latest Merge Result pipeline is green.
  • When ready for review, MR is labeled workflowready for review per the Distribution MR workflow.
  • The UBT version and corresponding checksum hash have been updated and referenced in the merge request if applicable.
    • UBT EE pipeline (Trigger:ee-package-ubt) is green

For GitLab team members

If you don't have access to this, the reviewer should trigger these jobs for you during the review process.

  • The manual Trigger:ee-package jobs have a green pipeline running against latest commit.
  • If config/software or config/patches directories are changed, make sure the build-package-on-all-os job within the Trigger:ee-package downstream pipeline succeeded.
  • Since this changes SSL/FIPS-related build behavior, the Trigger:package:fips manual job within the Trigger:ee-package downstream pipeline must succeed (default-off path — confirms no regression).
  • CI configuration is changed, so the branch is pushed to dev.gitlab.org to confirm regular branch builds aren't broken.

Expected (please provide an explanation if not completing)

  • Test plan indicating conditions for success has been posted — see Test plan above; test 1 (default path) applies now, tests 2–3 gate on the upstream work in gitlab-org#22761 (closed).
  • Documentation created/updated.
  • Tests added.
  • Integration tests added to GitLab QA — n/a, gated build-time change.
  • Equivalent MR/issue for the GitLab Chart opened — the CNG side is gitlab-org/build/CNG!3010 (merged).
Edited by Jason Plum

Merge request reports

Loading
Loading