Draft: Enable USE_GO_FIPS_MODULE by default
What does this MR do?
Flip the two-way-door FIPS toggle to on by default: USE_GO_FIPS_MODULE: "true" and FIPS_BUILDER_IMAGE_SUFFIX: "" in gitlab-ci-config/variables.yml (with the check-packages.yml local fallback kept in sync). FIPS package builds now default to upstream Go's native FIPS 140-3 module (GOFIPS140, CMVP certificate 5247) on the base builder images, instead of the golang-fips fork on the _fips images. Comments and doc/development/ci-variables.md are updated to describe the new defaults and the revert pair. lib/gitlab/build/check.rb gets a comment-only update — the code path and its specs are unchanged, and the CI variable remains the single control point.
To revert: set USE_GO_FIPS_MODULE: "false" and FIPS_BUILDER_IMAGE_SUFFIX: "_fips".
🛑 Hold merge — two gates
- !9771 (closed) must merge first, so all seven Go components export
GOFIPS140(it blocks #10002 (closed) via #10090 (closed)). - Gitaly's first fips-capable release is 19.4 — v19.3.1 still pins labkit v1.64.1. Release packages must pin a fips-capable gitaly before this default applies to them.
Evidence (empirical, 2026-09-09/10)
- Toggle harness PASS on master heads: #10002 (comment 3810976584) (FIPS job succeeded;
GOFIPS140="v1.0.0"in all four wired components; package assembled). - Toggle harness PASS on !9771 (closed)'s branch: FIPS job https://gitlab.com/gitlab-org/omnibus-gitlab/-/jobs/16422094037 —
GOFIPS140="v1.0.0"in all seven Go components. - Full-OS package build green with the toggle off (legacy path unchanged): https://gitlab.com/gitlab-org/omnibus-gitlab/-/pipelines/2837192726.
Related to #10002 (closed)