docs(pro): document how to get and enable the FIPS images - #16080
Merged
Merged
Conversation
The FIPS page told readers to email for access, and its Docker Compose steps used a DD_IMAGE_TAG variable and an x-psirt-vars block that the deployment files do not have. - New "Getting the FIPS images" section: <version>-fips tags from 3.3.200, pulled with the license's registry credentials, linux/amd64 only, signed. - Compose tab rewritten around DD_FIPS_MODE (3.3.300+), set with dojo-compose-cli so it survives upgrades, with a note for 3.3.200. - Coverage: drop the PSIRT advisory engine, add the OSCAL validator. - ECS page: where the images come from and how to copy them into ECR; drop the removed PSIRT sidecar references. - Translations: the same corrections, with explicit heading IDs so the new anchor and #guard-rails resolve in every language. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
blakeaowens
approved these changes
Sep 24, 2026
Maffooch
approved these changes
Sep 24, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
The FIPS 140-3 page told readers to email for access to the FIPS images, and its Docker Compose steps referenced a
DD_IMAGE_TAGvariable and anx-psirt-varsblock that the deployment files do not have. This replaces both with how the images are actually obtained and enabled.fips_mode.md<version>-fipsnext to its standard image, from 3.3.200. The registry credentials in the license pull them, with nothing to request. It lists the six image references, and notes that the images are linux/amd64 only and signed with SBOM attestations.fips.enabled.DD_FIPS_MODEvariable, set withdojo-compose-cli environment add, selects the-fipsimages and turns on enforcement, and it persists across upgrades. There is a short note on how to do it by hand on 3.3.200, and why those edits don't survive an upgrade.fips_on_ecs_fargate.mdpsirtfrom theDD_FIPS_MODElist and removes thePSIRT_ENABLEDvariable, which the nginx entrypoint no longer reads.Translations (de, es, fr, it, ja, pt-br, zh-hans): the same corrections, applied to their existing structure. The new section uses an explicit
{#getting-the-fips-images}heading ID, so the anchor resolves in every language.The Compose instructions depend on the deployment-file change shipping in 3.3.300, so this should merge once that release is out.
Test results
Built the site locally with the production config (
hugo --minify --gc --config config/production/hugo.toml): clean build. Confirmed in the rendered HTML that#getting-the-fips-imagesand#guard-railsexist on every language's page, that#coverage,#deployment-notesand#enabling-fips-modeexist on the English page, and that the ECS page's#authenticate-to-the-registrytarget exists on the Kubernetes upgrade page. No page still mentions the old contact address.🤖 Generated with Claude Code