Draft: Enable USE_GO_FIPS_MODULE by default

What does this MR do?

Flip the two-way-door FIPS toggle to on by default: USE_GO_FIPS_MODULE: "true" and FIPS_BUILDER_IMAGE_SUFFIX: "" in gitlab-ci-config/variables.yml (with the check-packages.yml local fallback kept in sync). FIPS package builds now default to upstream Go's native FIPS 140-3 module (GOFIPS140, CMVP certificate 5247) on the base builder images, instead of the golang-fips fork on the _fips images. Comments and doc/development/ci-variables.md are updated to describe the new defaults and the revert pair. lib/gitlab/build/check.rb gets a comment-only update — the code path and its specs are unchanged, and the CI variable remains the single control point.

To revert: set USE_GO_FIPS_MODULE: "false" and FIPS_BUILDER_IMAGE_SUFFIX: "_fips".

🛑 Hold merge — two gates

  1. !9771 (closed) must merge first, so all seven Go components export GOFIPS140 (it blocks #10002 (closed) via #10090 (closed)).
  2. Gitaly's first fips-capable release is 19.4 — v19.3.1 still pins labkit v1.64.1. Release packages must pin a fips-capable gitaly before this default applies to them.

Evidence (empirical, 2026-09-09/10)

Related to #10002 (closed)

Merge request reports

Loading
Loading