Skip to content

[feature]: fluentd — add FIPS-compliant variant (debian-13) #604

Description

@romanisb

Target Image(s)

dhi.io/fluentd (currently: 1.19.x, debian-13)

Problem Statement

Fluentd is widely deployed as the log collector in regulated environments where FIPS 140-2 / 140-3 validated cryptography is a hard requirement. The current dhi.io/fluentd image uses standard OpenSSL 3.x (libssl3) but does not activate the OpenSSL FIPS provider, so it cannot be used in environments that mandate FIPS-only cryptography.

Affected use cases include:

  • TLS connections to log destinations (Elasticsearch, S3, Kafka, Splunk HEC) over HTTPS/TLS
  • TLS client authentication in fluent-plugin-secure-forward / in_forward with TLS
  • Any crypto performed by Ruby's openssl gem at runtime (digest, cipher, HMAC)

Fluentd is a Ruby application and delegates all cryptographic operations to the system openssl gem, which in turn links against the system libssl. OpenSSL 3.x ships a FIPS provider (openssl-provider-fips) that can be activated via configuration with no recompilation of Ruby or Fluentd gems required.

Proposed Solution

Add a FIPS variant for the dhi.io/fluentd debian-13 runtime and dev images, producing tags such as:

  • 1-debian13-fips, 1.19-debian13-fips, 1.19.3-debian13-fips
  • 1-debian13-fips-dev, 1.19-debian13-fips-dev

The implementation would follow the existing DHI FIPS pattern for OpenSSL-backed images:

  • Include the openssl-provider-fips package
  • Configure OpenSSL to load the FIPS provider and set default_properties = fips=yes
  • Set OPENSSL_CONF and OPENSSL_MODULES environment variables accordingly
  • Add a smoke-test that verifies FIPS mode is active at image build time (e.g. ruby -e "require 'openssl'; raise unless OpenSSL.fips_mode")

Additional Context

Benefits

  • Enables Fluentd to be deployed in FedRAMP-moderate/high and DoD IL4/IL5 environments that enforce FIPS-only cryptography
  • Consistent with the DHI approach of providing compliance-ready variants alongside standard runtime/dev images
  • No change to the non-FIPS image or its behavior, purely additive

Pre-submission Checklist

  • I have searched existing issues to ensure this feature hasn't been requested before
  • This feature request is related to Docker Hardened Images
  • I have provided sufficient detail about the proposed feature

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions