Skip to content

docs(pro): document how to get and enable the FIPS images - #16080

Merged
devGregA merged 1 commit into
DefectDojo:bugfixfrom
devGregA:docs/fips-image-access
Sep 24, 2026
Merged

devGregA merged 1 commit into
DefectDojo:bugfixfrom
devGregA:docs/fips-image-access

Conversation

@devGregA

Copy link
Copy Markdown
Contributor

Description

The FIPS 140-3 page told readers to email for access to the FIPS images, and its Docker Compose steps referenced a DD_IMAGE_TAG variable and an x-psirt-vars block that the deployment files do not have. This replaces both with how the images are actually obtained and enabled.

fips_mode.md

  • New "Getting the FIPS images" section: every image with a FIPS variant is published as <version>-fips next to its standard image, from 3.3.200. The registry credentials in the license pull them, with nothing to request. It lists the six image references, and notes that the images are linux/amd64 only and signed with SBOM attestations.
  • Coverage table: removes the PSIRT advisory engine row (the sidecar no longer ships) and adds the OSCAL validator, which the Helm chart already refuses to render alongside fips.enabled.
  • Kubernetes tab: states the 3.3.200 minimum.
  • Compose tab, rewritten: from 3.3.300 a single DD_FIPS_MODE variable, set with dojo-compose-cli environment add, selects the -fips images and turns on enforcement, and it persists across upgrades. There is a short note on how to do it by hand on 3.3.200, and why those edits don't survive an upgrade.

fips_on_ecs_fargate.md

  • Says where the two images come from, and how to copy them into ECR.
  • Drops psirt from the DD_FIPS_MODE list and removes the PSIRT_ENABLED variable, which the nginx entrypoint no longer reads.

Translations (de, es, fr, it, ja, pt-br, zh-hans): the same corrections, applied to their existing structure. The new section uses an explicit {#getting-the-fips-images} heading ID, so the anchor resolves in every language.

The Compose instructions depend on the deployment-file change shipping in 3.3.300, so this should merge once that release is out.

Test results

Built the site locally with the production config (hugo --minify --gc --config config/production/hugo.toml): clean build. Confirmed in the rendered HTML that #getting-the-fips-images and #guard-rails exist on every language's page, that #coverage, #deployment-notes and #enabling-fips-mode exist on the English page, and that the ECS page's #authenticate-to-the-registry target exists on the Kubernetes upgrade page. No page still mentions the old contact address.

🤖 Generated with Claude Code

The FIPS page told readers to email for access, and its Docker Compose
steps used a DD_IMAGE_TAG variable and an x-psirt-vars block that the
deployment files do not have.

- New "Getting the FIPS images" section: <version>-fips tags from 3.3.200,
  pulled with the license's registry credentials, linux/amd64 only, signed.
- Compose tab rewritten around DD_FIPS_MODE (3.3.300+), set with
  dojo-compose-cli so it survives upgrades, with a note for 3.3.200.
- Coverage: drop the PSIRT advisory engine, add the OSCAL validator.
- ECS page: where the images come from and how to copy them into ECR;
  drop the removed PSIRT sidecar references.
- Translations: the same corrections, with explicit heading IDs so the
  new anchor and #guard-rails resolve in every language.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@devGregA
devGregA requested a review from Maffooch as a code owner September 24, 2026 16:51
@devGregA devGregA added this to the 3.3.300 milestone Sep 24, 2026
@devGregA devGregA added the docs label Sep 24, 2026
@devGregA
devGregA added this pull request to the merge queue Sep 24, 2026
Merged via the queue into DefectDojo:bugfix with commit 41e0c26 Sep 24, 2026
30 checks passed
@devGregA
devGregA deleted the docs/fips-image-access branch September 24, 2026 17:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants