Add two-way-door toggle for native Go FIPS (GOFIPS140)
What does this MR do?
Introduces a two-way-door toggle to build the Go-based components against
upstream Go's native FIPS 140-3 module (GOFIPS140) instead of the
golang-fips fork (GOEXPERIMENT=boringcrypto), mirroring the CNG migration in
gitlab-org/build/CNG!3010 (merged).
The new behavior is gated behind USE_GO_FIPS_MODULE and defaults to off, so
the existing golang-fips build path is unchanged. Enabling it is fully
reversible — no code revert required.
Build gate (lib/gitlab/build/check.rb)
- Adds
GO_FIPS_MODULE_VERSION(defaultv1.0.0, the CMVP-certified module, see gitlab-org#22761 (closed)), plusgo_fips_module_versionanduse_go_fips_module?(true only whenuse_system_ssl?andUSE_GO_FIPS_MODULE=true). boringcrypto_supported?is retained as the legacy fallback.
Go components
gitlab-pages,gitlab-shell,gitaly, andworkhorse(viagitlab-rails) exportGOFIPS140when native mode is on, otherwise keep settingGOEXPERIMENT=boringcrypto.FIPS_MODE=1is unchanged.GOFIPS140andboringcryptoare never set together (cmd/gorejects the combination).
CI toggle
gitlab-ci-config/variables.ymladdsUSE_GO_FIPS_MODULE(defaultfalse) andFIPS_BUILDER_IMAGE_SUFFIX(default_fips).- FIPS build and verify jobs interpolate
${FIPS_BUILDER_IMAGE_SUFFIX}into their image names. Setting the suffix to""routes FIPS jobs to the base builder images, which already ship a GOFIPS140-capable upstream Go (GO_VERSION 1.26.4), so no newgitlab-omnibus-builderimage variant is needed.
Enabling native FIPS (in a pipeline): set USE_GO_FIPS_MODULE="true" and
FIPS_BUILDER_IMAGE_SUFFIX="". If only the build toggle is set, the build fails
loudly (cmd/go rejects GOFIPS140 on a golang-fips toolchain) rather than
producing a mis-built package.
Docs and specs are included: doc/development/ci-variables.md documents the new
variables, and spec/lib/gitlab/build/check_spec.rb covers the gate.
Related issues
Related to #10002 (closed)
Mirrors gitlab-org/build/CNG!3010 (merged)
Test plan
Warning
This MR only adds the gated plumbing. The native GOFIPS140 path cannot be
used until the related upstream project MRs are all in place — the component
Makefiles (gitaly, gitlab-pages, gitlab-shell, workhorse) must honor
GOFIPS140 and stop forcing GOEXPERIMENT=boringcrypto, and the CNG side
(gitlab-org/build/CNG!3010 (merged)) must land. This
work is tracked in gitlab-org#22761 (closed).
Until then, only the default (legacy golang-fips) path is exercisable.
1. Default path unchanged (this MR, now)
- Run the standard
Trigger:package:fipsjob with no new variables set. - Expect: FIPS jobs pull
*_fipsimages, components build withGOEXPERIMENT=boringcrypto, andrpm-verify-fipsstays green — confirming no regression.
2. Native path (once upstream MRs are in place)
- Run a pipeline with
USE_GO_FIPS_MODULE="true"andFIPS_BUILDER_IMAGE_SUFFIX="". - Expect: FIPS build/verify jobs run on the base (upstream Go) builder images; no
job sets
GOEXPERIMENT=boringcrypto. - On the resulting binaries,
go version -m <binary>reportsbuild GOFIPS140=v1.0.0-..., and nogoboringcryptosymbols are present. - FIPS verification (
rpm-verify-fips/ functionality checks) stays green.
3. Mismatch is a loud failure (safety check)
- Run with
USE_GO_FIPS_MODULE="true"but leaveFIPS_BUILDER_IMAGE_SUFFIX="_fips". - Expect: the build fails visibly because
cmd/gorejectsGOFIPS140on agolang-fipstoolchain — never a silently mis-built package.
Checklist
See Definition of done.
For anything in this list which will not be completed, please provide a reason in the MR discussion.
Required
- MR title and description are up to date, accurate, and descriptive.
- MR targeting the appropriate branch.
- Latest Merge Result pipeline is green.
- When ready for review, MR is labeled workflowready for review per the Distribution MR workflow.
- The UBT version and corresponding checksum hash have been updated and referenced in the merge request if applicable.
- UBT EE pipeline (
Trigger:ee-package-ubt) is green
- UBT EE pipeline (
For GitLab team members
If you don't have access to this, the reviewer should trigger these jobs for you during the review process.
- The manual
Trigger:ee-packagejobs have a green pipeline running against latest commit. - If
config/softwareorconfig/patchesdirectories are changed, make sure thebuild-package-on-all-osjob within theTrigger:ee-packagedownstream pipeline succeeded. - Since this changes SSL/FIPS-related build behavior, the
Trigger:package:fipsmanual job within theTrigger:ee-packagedownstream pipeline must succeed (default-off path — confirms no regression). - CI configuration is changed, so the branch is pushed to
dev.gitlab.orgto confirm regular branch builds aren't broken.
Expected (please provide an explanation if not completing)
- Test plan indicating conditions for success has been posted — see Test plan above; test 1 (default path) applies now, tests 2–3 gate on the upstream work in gitlab-org#22761 (closed).
- Documentation created/updated.
- Tests added.
- Integration tests added to GitLab QA — n/a, gated build-time change.
- Equivalent MR/issue for the GitLab Chart opened — the CNG side is gitlab-org/build/CNG!3010 (merged).