How a Missing Kernel Flag Broke FIPS-Certified Containers in Managed Kubernetes
Ubuntu, Monday, September 28th, 2026
Ubuntu Pro FIPS containers failed on mainline kernels in EKS and Fargate; Canonical patched it without recertification.
A customer migrating to FedRAMP found Ubuntu Pro 22.04 FIPS container images silently failing on mainline Linux kernels used by managed Kubernetes services such as AWS EKS and Fargate.
The root cause was a hard dependency in libgcrypt20-fips on GRND_RESEED_ONLY, an Ubuntu-specific kernel flag that does not exist in mainline kernels.
Canonical explains the failure and how it shipped a patch that preserved FIPS compliance without triggering months of recertification.