Sign inSign up

rootioinc/node

By rootioinc

•Updated 3 months ago

Node.js 24 with wolfSSL FIPS 140-3 (Cert #4718) on Debian Trixie

Image
0

2.5K

rootioinc/node repository overview

⁠rootioinc/node:24.16-trixie-slim-fips

Node.js 24 on Debian Trixie with FIPS 140-3 validated cryptography — provided by wolfSSL (CMVP Certificate #4718) through the OpenSSL 3.5.6 provider interface (wolfProvider).

Node.js24.16.0 (latest 24 LTS minor, from NodeSource)
OpenSSL3.5.6
FIPS modulewolfSSL FIPS 140-3, Certificate #4718 (via wolfProvider)
Base imagerootioinc/debian:trixie-slim-fips
Architecturelinux/amd64

⁠What this image is

A thin Node.js layer on top of the Root.io FIPS base image. The base provides the validated crypto stack (wolfSSL + wolfProvider as the exclusive OpenSSL provider); this image adds Node.js and routes its crypto through that FIPS boundary. FIPS is active out of the box — no flags required.

⁠Quick start

docker pull rootioinc/node:24.16-trixie-slim-fips

# Run your app
docker run --rm -v "$PWD:/app" -w /app rootioinc/node:24.16-trixie-slim-fips node server.js

# Confirm FIPS is active
docker run --rm rootioinc/node:24.16-trixie-slim-fips \
  node -e "console.log('FIPS:', require('crypto').getFips())"   # -> FIPS: 1

⁠FIPS behaviour

  • crypto.getFips() returns 1.
  • Crypto routes through wolfProvider (wolfSSL FIPS, Cert #4718); the OpenSSL default provider is not loaded.
  • MD5 is blocked (ERR_OSSL_EVP_UNSUPPORTED); non-FIPS algorithms are rejected.
  • ~30 FIPS-approved cipher suites; TLS 1.2 / 1.3 supported.
  • OPENSSL_CONF=/etc/fips/openssl.cnf is set by the base and must not be overridden.

⁠Runtime notes

  • Runs as non-root user appuser (uid 1001); working dir /app.
  • The entrypoint runs a FIPS power-on self-test (fips-startup-check) and a Node FIPS init check at startup. Set FIPS_CHECK=false to skip them (development only).

⁠Tags

  • 24.16-trixie-slim-fips — Node.js 24.16 on Debian Trixie, FIPS 140-3.

⁠Architecture / multi-arch

Currently published for linux/amd64. The build is architecture-agnostic (Node is installed from NodeSource's per-arch apt repo), but an arm64 image requires an arm64 build of the rootioinc/debian:trixie-slim-fips base (with arm64 wolfSSL FIPS coverage) to be published first.


Vendor: root.io Inc. — built on rootioinc/debian:trixie-slim-fips.

Tag summary

Content type

Image

Digest

sha256:72cf3907d…

Size

134.2 MB

Last updated

3 months ago

docker pull rootioinc/node:24.16-trixie-slim-fips