Skip to content

feat(cc_rhel): introduce a new config module for RHEL/Fedora with fips support - #7119

Open
ani-sinha wants to merge 2 commits into
canonical:mainfrom
ani-sinha:fips-enablement
Open

ani-sinha wants to merge 2 commits into
canonical:mainfrom
ani-sinha:fips-enablement

Conversation

@ani-sinha

@ani-sinha ani-sinha commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Proposed Commit Message

A new configuration module is introduced for Fedora/RHEL that adds
support for enabling fips mode for cloud deployments. The config option
looks like the following:

rhel:
  fips_mode: true

The "fips_mode" is a boolean value that can be used to turn on fips
mode for the cloud VM.

For RHEL/Fedora, teh utility "/usr/libexec/fips-setup-helper" is used
to set up the crypto policies to enable fips mode. Additionally, one
must also enable "fips=1" kernel command line option in order to harden
the kernel for fips mode.

Most RHEL/Fedora images boot through grub and therefore new kernel
command line can be added through grub. Exception is RHEL CVM images
that uses direct kernel UKI boot and does not have grub installed. This
patch does not handle enabling fips mode for CVM images for now.

Necessary schema definitions and unit tests have been added to exercize
various aspects of the cc_rhel module implementation and validate the
schema definition. Documentation for the new module has also been
added.

Signed-off-by: Ani Sinha anisinha@redhat.com

Test Steps

Unit tests added with the commit.
Functional tests on a KVM VM with NOCLOUD data source for UEFI and non-UEFI boots.Additional tests on Azure and AWS will be conducted by Khushi (@khuspate), our other team member.

Merge type

  • [] Squash merge using "Proposed Commit Message"
  • [ x] Rebase and merge unique commits. Requires commit messages per-commit each referencing the pull request number (#<PR_NUM>)

This change is cosmetic. It refactors out reboot method and some definitions
out of specific modules and places them into the common util library for
re-use by other modules. Unit tests have been adjusted accordingly.

Signed-off-by: Ani Sinha <anisinha@redhat.com>
@github-actions github-actions Bot added the documentation This Pull Request changes documentation label Sep 30, 2026
…s support

A new configuration module is introduced for Fedora/RHEL on x86 that adds
support for enabling fips mode for cloud deployments. The config option
looks like the following:

rhel:
  fips_mode: true

The "fips_mode" is a boolean value that can be used to turn on fips
mode for the cloud VM.

For RHEL/Fedora, teh utility "/usr/libexec/fips-setup-helper" is used
to set up the crypto policies to enable fips mode. Additionally, one
must also enable "fips=1" kernel command line option in order to harden
the kernel for fips mode.

Most RHEL/Fedora images boot through grub and therefore new kernel
command line can be added through grub. Exception is RHEL CVM images
that uses direct kernel UKI boot and does not have grub installed. This
patch does not handle enabling fips mode for CVM images for now.

Necessary schema definitions and unit tests have been added to exercize
various aspects of the cc_rhel module implementation and validate the
schema definition. Documentation for the new module has also been
added.

Signed-off-by: Ani Sinha <anisinha@redhat.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation This Pull Request changes documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant