Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 5 additions & 12 deletions Dockerfile.collector
Original file line number Diff line number Diff line change
Expand Up @@ -30,33 +30,25 @@ COPY --from=bpf-generator /opt/app-root/src/.obi-src /opt/app-root/src/redhat-op
COPY redhat-opentelemetry-collector/LICENSE /licenses/
WORKDIR /opt/app-root/src/redhat-opentelemetry-collector

RUN CGO_ENABLED=1 GOEXPERIMENT=strictfipsruntime go build -C ./_build -mod=mod -tags strictfipsruntime -o opentelemetry-collector -trimpath -ldflags "-w"
RUN CGO_ENABLED=0 GOFIPS140=certified go build -C ./_build -mod=mod -tags no_openssl -o opentelemetry-collector -trimpath -ldflags "-w"

@andreasgerstmayr andreasgerstmayr Aug 19, 2026 •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Using CGO_ENABLED=0 avoids using glibc, and iirc there might be subtle and exotic differences around DNS, IPv6 and /etc/hosts. Not sure if it's an issue in practice though (not a blocker from my side)


COPY fips_check.sh .
RUN ./fips_check.sh
COPY fips_check_collector.sh .
RUN ./fips_check_collector.sh

FROM registry.redhat.io/ubi9/ubi-micro:latest@sha256:7e7f79ab747bf2b452e3043dd89f388e92be4c7fdcc8b815b58adf6c99c39c95 AS target-base

FROM registry.redhat.io/ubi9/ubi:latest@sha256:5426a8f45e80a07168a30ea24d84f266094b3756624a5508cc53927e6ee39e09 as install-additional-packages
COPY --from=target-base / /mnt/rootfs
RUN rpm --root /mnt/rootfs --import /etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release
# Install the systemd package which provides journalctl required by journald receiver and add user to systemd-journal group.
RUN dnf install --installroot /mnt/rootfs --releasever 9 --setopt install_weak_deps=false --setopt reposdir=/etc/yum.repos.d --nodocs -y openssl systemd && \
RUN dnf install --installroot /mnt/rootfs --releasever 9 --setopt install_weak_deps=false --setopt reposdir=/etc/yum.repos.d --nodocs -y systemd && \
dnf clean all && \
rm -rf /var/cache/yum
RUN rm -rf /mnt/rootfs/var/cache/*

# Enable post-quantum cryptography (ML-KEM) via DEFAULT:PQ crypto policy (OCPSTRAT-3113)
# Install crypto-policies-scripts on builder (not target) to avoid Python in final image
FROM registry.redhat.io/ubi9/ubi:latest@sha256:5426a8f45e80a07168a30ea24d84f266094b3756624a5508cc53927e6ee39e09 as crypto-policies
RUN dnf install --nodocs -y crypto-policies-scripts && \
update-crypto-policies --set DEFAULT:PQ && \
dnf clean all

FROM scratch
WORKDIR /
COPY --from=install-additional-packages /mnt/rootfs/ /
COPY --from=crypto-policies /etc/crypto-policies/ /etc/crypto-policies/

ARG VERSION=0.158.0-1

Expand All @@ -65,6 +57,7 @@ COPY opentelemetry-operator/LICENSE /licenses/.
COPY --from=builder /opt/app-root/src/redhat-opentelemetry-collector/_build/opentelemetry-collector /usr/bin/opentelemetry-collector
COPY redhat-opentelemetry-collector/configs/otelcol.yaml /etc/otelcol/config.yaml

ENV GODEBUG=fips140=auto
ARG USER_UID=1001
RUN useradd -u ${USER_UID} otelcol && usermod -a -G systemd-journal otelcol
USER ${USER_UID}
Expand Down
21 changes: 3 additions & 18 deletions Dockerfile.operator
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@ RUN exportOrFail() { echo $1; if [[ $1 == *= ]]; then echo "Error: empty variabl
exportOrFail AUTO_INSTRUMENTATION_GO_VERSION=`grep -v '\#' versions.txt | grep autoinstrumentation-go | awk -F= '{print $2}'` && \
exportOrFail AUTO_INSTRUMENTATION_APACHE_HTTPD_VERSION=`grep -v '\#' versions.txt | grep autoinstrumentation-apache-httpd | awk -F= '{print $2}'` && \
exportOrFail AUTO_INSTRUMENTATION_NGINX_VERSION=`grep -v '\#' versions.txt | grep autoinstrumentation-nginx | awk -F= '{print $2}'` && \
CGO_ENABLED=1 GOEXPERIMENT=strictfipsruntime go build -mod=mod -tags strictfipsruntime -o ./opentelemetry-operator -trimpath -ldflags "-s -w \
CGO_ENABLED=0 GOFIPS140=certified go build -mod=mod -tags no_openssl -o ./opentelemetry-operator -trimpath -ldflags "-s -w \
-X ${VERSION_PKG}.version=${OPERATOR_VERSION} \
-X ${VERSION_PKG}.buildDate=${BUILD_DATE} \
-X ${VERSION_PKG}.otelCol=${OTELCOL_VERSION} \
Expand All @@ -43,32 +43,17 @@ RUN exportOrFail() { echo $1; if [[ $1 == *= ]]; then echo "Error: empty variabl

FROM registry.redhat.io/ubi9/ubi-micro:latest@sha256:7e7f79ab747bf2b452e3043dd89f388e92be4c7fdcc8b815b58adf6c99c39c95 AS target-base

FROM registry.redhat.io/ubi9/ubi:latest@sha256:5426a8f45e80a07168a30ea24d84f266094b3756624a5508cc53927e6ee39e09 as install-additional-packages
COPY --from=target-base / /mnt/rootfs
RUN rpm --root /mnt/rootfs --import /etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release
RUN dnf install --installroot /mnt/rootfs --releasever 9 --setopt install_weak_deps=false --setopt reposdir=/etc/yum.repos.d --nodocs -y openssl && \
dnf clean all && \
rm -rf /var/cache/yum
RUN rm -rf /mnt/rootfs/var/cache/*

# Enable post-quantum cryptography (ML-KEM) via DEFAULT:PQ crypto policy (OCPSTRAT-3113)
# Install crypto-policies-scripts on builder (not target) to avoid Python in final image
FROM registry.redhat.io/ubi9/ubi:latest@sha256:5426a8f45e80a07168a30ea24d84f266094b3756624a5508cc53927e6ee39e09 as crypto-policies
RUN dnf install --nodocs -y crypto-policies-scripts && \
update-crypto-policies --set DEFAULT:PQ && \
dnf clean all

FROM scratch
WORKDIR /
COPY --from=install-additional-packages /mnt/rootfs/ /
COPY --from=crypto-policies /etc/crypto-policies/ /etc/crypto-policies/
COPY --from=target-base / /

ARG VERSION=0.158.0-1

RUN mkdir /licenses
COPY opentelemetry-operator/LICENSE /licenses/.
COPY --from=builder /opt/app-root/src/opentelemetry-operator/opentelemetry-operator /usr/bin/opentelemetry-operator

ENV GODEBUG=fips140=auto
ARG USER_UID=1001
USER ${USER_UID}
ENTRYPOINT ["/usr/bin/opentelemetry-operator"]
Expand Down
21 changes: 3 additions & 18 deletions Dockerfile.targetallocator
Original file line number Diff line number Diff line change
Expand Up @@ -13,36 +13,21 @@ COPY opentelemetry-operator opentelemetry-operator
COPY opentelemetry-operator/LICENSE /licenses/
WORKDIR /opt/app-root/src/opentelemetry-operator

RUN CGO_ENABLED=1 GOEXPERIMENT=strictfipsruntime go build -C ./cmd/otel-allocator -mod=mod -tags strictfipsruntime -o ./opentelemetry-target-allocator -trimpath -ldflags "-s -w"
RUN CGO_ENABLED=0 GOFIPS140=certified go build -C ./cmd/otel-allocator -mod=mod -tags no_openssl -o ./opentelemetry-target-allocator -trimpath -ldflags "-s -w"

FROM registry.redhat.io/ubi9/ubi-micro:latest@sha256:7e7f79ab747bf2b452e3043dd89f388e92be4c7fdcc8b815b58adf6c99c39c95 AS target-base

FROM registry.redhat.io/ubi9/ubi:latest@sha256:5426a8f45e80a07168a30ea24d84f266094b3756624a5508cc53927e6ee39e09 as install-additional-packages
COPY --from=target-base / /mnt/rootfs
RUN rpm --root /mnt/rootfs --import /etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release
RUN dnf install --installroot /mnt/rootfs --releasever 9 --setopt install_weak_deps=false --setopt reposdir=/etc/yum.repos.d --nodocs -y openssl && \
dnf clean all && \
rm -rf /var/cache/yum
RUN rm -rf /mnt/rootfs/var/cache/*

# Enable post-quantum cryptography (ML-KEM) via DEFAULT:PQ crypto policy (OCPSTRAT-3113)
# Install crypto-policies-scripts on builder (not target) to avoid Python in final image
FROM registry.redhat.io/ubi9/ubi:latest@sha256:5426a8f45e80a07168a30ea24d84f266094b3756624a5508cc53927e6ee39e09 as crypto-policies
RUN dnf install --nodocs -y crypto-policies-scripts && \
update-crypto-policies --set DEFAULT:PQ && \
dnf clean all

FROM scratch
WORKDIR /
COPY --from=install-additional-packages /mnt/rootfs/ /
COPY --from=crypto-policies /etc/crypto-policies/ /etc/crypto-policies/
COPY --from=target-base / /

ARG VERSION=0.158.0-1

RUN mkdir /licenses
COPY opentelemetry-operator/LICENSE /licenses/.
COPY --from=builder /opt/app-root/src/opentelemetry-operator/cmd/otel-allocator/opentelemetry-target-allocator /usr/bin/opentelemetry-target-allocator

ENV GODEBUG=fips140=auto
ARG USER_UID=1001
USER ${USER_UID}
ENTRYPOINT ["/usr/bin/opentelemetry-target-allocator"]
Expand Down
5 changes: 4 additions & 1 deletion fips_check.sh → fips_check_collector.sh
Original file line number Diff line number Diff line change
Expand Up @@ -22,4 +22,7 @@ pattern="encryptKey"
if [[ $(go tool objdump -s "$pattern" _build/opentelemetry-collector) ]]; then
echo "found $pattern"
exit 1
fi
fi

# Verify the FIPS 140 module version embedded in the binary
go version -m _build/opentelemetry-collector | grep "GOFIPS140=v1.0.0"
3 changes: 1 addition & 2 deletions rpms.in.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -8,11 +8,10 @@ contentOrigin:
- ubi9.repo
packages:
- golang
- openssl
- systemd
- crypto-policies-scripts
- clang
- llvm
- make
arches:
- x86_64
- aarch64
Expand Down
Loading