Skip to main content
Version: Next 🚧

FIPS

This example shows how to build a Kairos image with FIPS support.

Use the --fips flag in both kairos-init stages. Fedora 41 is the base Kairos builds with FIPS in CI:

FROM fedora:41

ARG VERSION=v1.0.0

RUN --mount=type=bind,from=quay.io/kairos/kairos-init:v0.17.3,src=/kairos-init,dst=/kairos-init \
/kairos-init -l debug -s install --version "${VERSION}" --fips && \
/kairos-init -l debug -s init --version "${VERSION}" --fips

Build the image:

docker build -t my-kairos-fips:v1.0.0 .

The image does not turn FIPS on in the kernel by itself. Add fips=1 to the kernel command line at install time:

#cloud-config
install:
grub_options:
extra_cmdline: "fips=1"

After install, cat /proc/sys/crypto/fips_enabled returns 1.

Ubuntu​

kairos-init --fips refuses Ubuntu, because the FIPS packages need an Ubuntu Pro subscription. Build from one of the Ubuntu FIPS examples instead. They attach Pro during the build and install linux-image-fips:

For full flag reference, see Kairos Factory.