Skip to content

CentOS 7 EOL and Migration Paths

CentOS 7 reached end of life on June 30, 2024, and RHEL 7’s official Extended Lifecycle Support (ELS) ended on June 30, 2026. If your servers still run CentOS 7, the question is no longer “should I migrate” but “which migration path costs the least.” This article compares four paths and walks through the most common one step by step.

DateEvent
2024-06-30CentOS 7 end of life; official mirrors emptied
2026-06-30RHEL 7 official ELS (Extended Lifecycle Support) ends
NowNo security patches from CentOS/RHEL at all; installing new software is a struggle

Real risks of running CentOS 7 today:

  • No official patches for newly disclosed vulnerabilities — internet-exposed services (SSH, web, databases) carry the highest risk
  • Old packages remain installable from vault.centos.org but will never be updated
  • Vendors keep dropping EL 7 support (PHP, Python, and OpenSSL toolchains are stuck on old versions)
PathCostBenefitFits
1. ELevate in-place upgrade to EL 8/9Medium (downtime window + testing)Keeps data and configuration; moves into a supported releaseMost legacy servers
2. Fresh install and redeployHigh (migrate apps and data)Cleanest, no legacy baggageSystems that are containerized or configuration-as-code
3. Commercial ELS (TuxCare, etc.)Ongoing paymentNo system changes; EL 7 patches keep arrivingCannot migrate soon but must stay compliant
4. IsolationLowRisk contained at the network layerTransition systems about to be retired

Path 1 Walkthrough: ELevate to AlmaLinux 8/9

Section titled “Path 1 Walkthrough: ELevate to AlmaLinux 8/9”

The ELevate project (maintained by AlmaLinux) is built on leapp and supports CentOS 7 to AlmaLinux 8, Rocky 8, Oracle Linux 8, and more. CentOS 7 to EL 8 is the most mature upgrade chain.

  • Back up all data; snapshot the VM
  • Confirm free disk space is at least 50% of used space
  • Remove third-party repositories (or confirm they have EL 8 versions)
  • Confirm critical applications support EL 8 (especially kernel modules and self-compiled software)
  • Reserve a 1-2 hour downtime window
Install the ELevate repository and leapp tools
$ sudo yum install -y http://repo.almalinux.org/elevate/elevate-release-latest-el7.noarch.rpm
$ sudo yum install -y leapp-upgrade leapp-data-almalinux
Pre-upgrade check: fix every inhibitor before proceeding
$ sudo leapp preupgrade

The pre-check lists inhibitors and suggestions. Common fixes:

Handle common inhibitors (follow your actual report output)
# Remove unsupported kernel modules (ploop, etc.)
$ sudo modprobe -r ploop
# Allow SSH root login (leapp requires it)
$ sudo sh -c "echo 'PermitRootLogin yes' >> /etc/ssh/sshd_config"
# Answer the question file, then re-run the pre-check
$ sudo leapp answer --section remove_pam_kde_plasma_dependencies.confirm=True
$ sudo leapp preupgrade
Once the report is clean, run the upgrade and reboot
$ sudo leapp upgrade
$ sudo reboot

The system enters the upgrade process on reboot. Verify afterwards:

Verify the upgrade
$ cat /etc/redhat-release
$ rpm -qa | grep el7 | wc -l # should be 0 or close to 0

Going Further to EL 9 or Switching Distributions

Section titled “Going Further to EL 9 or Switching Distributions”

Path 2: When a Fresh Install Is the Better Move

Section titled “Path 2: When a Fresh Install Is the Better Move”

A reinstall is often faster and safer than an in-place upgrade when any of these hold:

  • The system was configured once at provisioning and untouched since, with documentation available
  • Applications are containerized, or rebuildable with Ansible or similar tools
  • The host carries lots of self-compiled software or third-party repositories of unknown origin

For fresh installs go straight to EL 9 or EL 10 (AlmaLinux or Rocky). See the installation guide for details.

Yes — it holds the final snapshot from June 2024. Fine as a temporary package source, but it receives no security updates and is not suitable for the long run.

No. The supported chain crosses one major version at a time: CentOS 7 to EL 8, then EL 8 to EL 9. There is no supported two-hop path.

TuxCare (CloudLinux) and CIQ, among others, offer extended kernel and userspace patches for EL 7 — a good bridge for compliance-bound systems. Before signing, confirm what is covered (kernel, glibc, OpenSSL) and until when.