Skip to content

Adapt FIPS refinements from release-3.21 to release-3.13 for OCP 4.12 re-release #76

Description

@baijum

Context

Jira: HELM-832

We need to do a final re-release of Helm 3.13 for OCP Tools 4.12 to address outstanding CVEs. The release-3.13 branch already has the initial FIPS enablement commit (e3cc3f0 — TAGS=no_openssl + GODEBUG=fips140=auto env var on build-cross), but it is missing the two follow-up refinements that landed on release-3.21.

Changes needed on release-3.13

1. Move fips140=auto from Makefile env var to go.mod godebug directive

Add to go.mod:

godebug fips140=auto

This embeds the FIPS auto-mode directive into the binary itself (not just at build time), matching the approach in commit d9ead43 on release-3.21.

Remove the now-redundant GODEBUG=fips140=auto env var from the build-cross target in Makefile.

2. Add GOFIPS140=certified to Makefile build targets

Add the GOFIPS140 variable and prepend it to build commands, matching commit 1cc9984 on release-3.21:

GOFIPS140 ?= certified

Prepend GOFIPS140=$(GOFIPS140) to both build and build-cross targets so the certified FIPS 140 crypto module is selected at build time.

3. (Optional) Replace gox with individual go build in build-cross

release-3.13 still uses gox for cross-compilation while release-3.21 switched to individual go build commands per architecture. Consider adapting this as well for consistency, though not strictly required for FIPS compliance.

4. Update Go dependencies for CVE fixes

Update go.mod dependencies cited in the CVEs with fixed versions, retaining the current go directive version and Kubernetes API version.

Reference commits on release-3.21

  • 9f8ec87 — Initial FIPS enablement (already adapted in e3cc3f0 on release-3.13)
  • d9ead43 — Move fips140=auto to go.mod godebug directive
  • 1cc9984 — Add GOFIPS140=certified to Makefile

Acceptance criteria

  • go.mod contains godebug fips140=auto
  • Makefile no longer sets GODEBUG=fips140=auto as env var
  • Makefile uses GOFIPS140=certified on build targets
  • Go dependencies updated for CVE fixes
  • Scratch build passes check-patch
  • helm version output is valid SemVer

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions