FIPS Support for Self-Hosted Spacelift Server Images
Build two images when releasing new versions of Spacelift, with the new one having FIPS enabled and tagged with -FIPS or something similar.
The FIPS image should also include a log message that verifies it’s enable on-boot. This eliminates the need for the user to enable exec mode to confirm it for auditors.
Ideally, all install methods including CloudFormation, would include an option to enable FIPS. This would automatically select the FIPS image.
- Problem
Log in to comment and vote
Comments1
Black Breeze
Feb 18
Thanks for raising this Chad! I’m routing this to the team that directly owns self-hosting for further discovery and scoping. cc @Krzysztof Niepokojczycki