Conversation
This change is cosmetic. It refactors out reboot method and some definitions out of specific modules and places them into the common util library for re-use by other modules. Unit tests have been adjusted accordingly. Signed-off-by: Ani Sinha <anisinha@redhat.com>
ani-sinha
force-pushed
the
fips-enablement
branch
from
September 30, 2026 11:24
0aca91e to
7488640
Compare
…s support A new configuration module is introduced for Fedora/RHEL on x86 that adds support for enabling fips mode for cloud deployments. The config option looks like the following: rhel: fips_mode: true The "fips_mode" is a boolean value that can be used to turn on fips mode for the cloud VM. For RHEL/Fedora, teh utility "/usr/libexec/fips-setup-helper" is used to set up the crypto policies to enable fips mode. Additionally, one must also enable "fips=1" kernel command line option in order to harden the kernel for fips mode. Most RHEL/Fedora images boot through grub and therefore new kernel command line can be added through grub. Exception is RHEL CVM images that uses direct kernel UKI boot and does not have grub installed. This patch does not handle enabling fips mode for CVM images for now. Necessary schema definitions and unit tests have been added to exercize various aspects of the cc_rhel module implementation and validate the schema definition. Documentation for the new module has also been added. Signed-off-by: Ani Sinha <anisinha@redhat.com>
ani-sinha
force-pushed
the
fips-enablement
branch
from
September 30, 2026 11:30
7488640 to
373aafa
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Proposed Commit Message
A new configuration module is introduced for Fedora/RHEL that adds
support for enabling fips mode for cloud deployments. The config option
looks like the following:
The "fips_mode" is a boolean value that can be used to turn on fips
mode for the cloud VM.
For RHEL/Fedora, teh utility "/usr/libexec/fips-setup-helper" is used
to set up the crypto policies to enable fips mode. Additionally, one
must also enable "fips=1" kernel command line option in order to harden
the kernel for fips mode.
Most RHEL/Fedora images boot through grub and therefore new kernel
command line can be added through grub. Exception is RHEL CVM images
that uses direct kernel UKI boot and does not have grub installed. This
patch does not handle enabling fips mode for CVM images for now.
Necessary schema definitions and unit tests have been added to exercize
various aspects of the cc_rhel module implementation and validate the
schema definition. Documentation for the new module has also been
added.
Signed-off-by: Ani Sinha anisinha@redhat.com
Test Steps
Unit tests added with the commit.
Functional tests on a KVM VM with NOCLOUD data source for UEFI and non-UEFI boots.Additional tests on Azure and AWS will be conducted by Khushi (@khuspate), our other team member.
Merge type