Skip to content

Post-Migration Checklist

After completing the migration from CentOS to AlmaLinux or Rocky Linux, follow this checklist item by item to verify that the system is functioning correctly.

Tip: Bookmark this page and go through each item after migration. Mark each check as complete in your own documentation as you go.

First, confirm that the system has successfully switched to the target distribution.

Check os-release
$ cat /etc/os-release

Confirm that the NAME and ID fields show the correct distribution name (AlmaLinux or Rocky Linux).

Check redhat-release
$ cat /etc/redhat-release
Confirm the distribution identifier package
$ rpm -qa | grep -E '(almalinux|rocky)-release'
Confirm no leftover CentOS identifier packages
$ rpm -qa | grep centos-release

If CentOS packages still remain:

Clean up leftover CentOS packages
$ sudo dnf remove centos-release centos-logos centos-indexhtml 2>/dev/null
$ sudo dnf distro-sync -y
Check the currently running kernel
$ uname -r
View all installed kernels
$ rpm -qa kernel-core | sort
Confirm the GRUB default kernel
$ sudo grubby --default-kernel

Ensure the running kernel is from the target distribution. If you are still using an old kernel:

Install the latest kernel and set it as default
$ sudo dnf install -y kernel
$ sudo grubby --set-default /boot/vmlinuz-$(rpm -q kernel-core --qf '%{VERSION}-%{RELEASE}.%{ARCH}\n' | sort -V | tail -1)
List all failed services
$ systemctl list-units --type=service --state=failed

If any services have failed, investigate each one:

View details of a failed service
$ systemctl status <service-name>
$ journalctl -u <service-name> -n 50 --no-pager
Compare with the pre-migration service list
$ systemctl list-units --type=service --state=running > ~/services-after-migration.txt
$ diff ~/services-before-migration.txt ~/services-after-migration.txt
Check SSH service
$ systemctl is-active sshd
Check cron scheduler
$ systemctl is-active crond
Check system logging service
$ systemctl is-active rsyslog
Check firewall service
$ systemctl is-active firewalld
List all enabled repositories
$ dnf repolist --enabled

Confirm that the repositories point to the correct distribution. There should be no leftover CentOS repositories.

Check for leftover CentOS repository files
$ ls /etc/yum.repos.d/ | grep -i centos
Test repository availability
$ sudo dnf check-update
Confirm EPEL repository is working (if needed)
$ dnf repolist | grep epel

If EPEL is missing but needed:

Install EPEL
$ sudo dnf install -y epel-release
Check Nginx status (if applicable)
$ systemctl is-active nginx && curl -s -o /dev/null -w "%{http_code}" http://localhost/
Check Apache/httpd status (if applicable)
$ systemctl is-active httpd && curl -s -o /dev/null -w "%{http_code}" http://localhost/
Check MySQL/MariaDB (if applicable)
$ systemctl is-active mariadb || systemctl is-active mysqld
$ mysqladmin ping 2>/dev/null && echo "Database connection OK"
Check PostgreSQL (if applicable)
$ systemctl is-active postgresql
$ sudo -u postgres psql -c "SELECT version();" 2>/dev/null
Check PHP version (if applicable)
$ php -v 2>/dev/null
Check Python version
$ python3 --version
Check Java version (if applicable)
$ java -version 2>/dev/null

For custom-built applications, perform the following checks:

Check if the application port is listening
$ sudo ss -tlnp | grep <application-port>
Test the application HTTP endpoint (if applicable)
$ curl -s http://localhost:<port>/health
Check the current SELinux mode
$ getenforce

Under normal circumstances, this should return Enforcing. If it returns Disabled or Permissive, confirm whether this is the expected configuration.

View the SELinux configuration file
$ cat /etc/selinux/config
Check for SELinux denial records
$ sudo ausearch -m avc -ts recent 2>/dev/null | head -30

After migration, some files may have incorrect SELinux labels:

Relabel the filesystem (if SELinux issues exist)
$ sudo fixfiles -F onboot

This will relabel the entire filesystem on the next reboot. If you prefer not to reboot:

Relabel immediately (may take a long time)
$ sudo restorecon -Rv /etc /var /home
Check firewall status
$ sudo firewall-cmd --state
List all allowed services and ports
$ sudo firewall-cmd --list-all
Confirm critical ports are allowed
$ sudo firewall-cmd --query-port=22/tcp # SSH
$ sudo firewall-cmd --query-port=80/tcp # HTTP
$ sudo firewall-cmd --query-port=443/tcp # HTTPS

Compare with the pre-migration firewall configuration:

List all zone configurations
$ sudo firewall-cmd --list-all-zones | grep -A 10 "active"
Check network interface status
$ ip addr show
Check the default route
$ ip route show default
Check DNS configuration
$ cat /etc/resolv.conf
Test DNS resolution
$ dig +short google.com
Test internet connectivity
$ ping -c 3 8.8.8.8
Check NetworkManager connections
$ nmcli connection show
Confirm the hostname is correct
$ hostnamectl
Check root's crontab
$ sudo crontab -l
Check system-level cron jobs
$ ls -la /etc/cron.d/
$ ls -la /etc/cron.daily/
$ ls -la /etc/cron.weekly/
Check systemd timers
$ systemctl list-timers --all

Confirm that the backup system is still working properly after migration.

Check if backup tools are available
$ which rsync && rsync --version | head -1
If using LVM snapshots, confirm snapshot status
$ sudo lvs

Important: After the migration is verified to be successful, it is recommended to immediately create a new full backup as a new baseline.

Create a post-migration package list snapshot
$ rpm -qa --queryformat '%{NAME}-%{VERSION}-%{RELEASE}.%{ARCH}\n' | sort > ~/packages-after-migration-verified.txt

Confirm that the system can receive updates normally:

Check for available updates
$ sudo dnf check-update
Install all available updates
$ sudo dnf update -y
If the kernel was updated, reboot the system
$ sudo needs-restarting -r && echo "No reboot needed" || echo "Reboot required to apply kernel updates"

The following script performs most checks at once and outputs a report:

Run post-migration quick check
$ echo "===== System Version ====="
$ cat /etc/redhat-release
$ echo ""
$ echo "===== Kernel Version ====="
$ uname -r
$ echo ""
$ echo "===== SELinux Status ====="
$ getenforce
$ echo ""
$ echo "===== Failed Services ====="
$ systemctl list-units --type=service --state=failed --no-legend
$ echo ""
$ echo "===== Enabled Repositories ====="
$ dnf repolist --enabled 2>/dev/null
$ echo ""
$ echo "===== Firewall Status ====="
$ sudo firewall-cmd --state 2>/dev/null
$ echo ""
$ echo "===== Disk Usage ====="
$ df -h / /boot /var 2>/dev/null
$ echo ""
$ echo "===== Network Connectivity ====="
$ ping -c 1 -W 3 8.8.8.8 >/dev/null 2>&1 && echo "Internet reachable" || echo "Internet unreachable"
$ dig +short google.com >/dev/null 2>&1 && echo "DNS OK" || echo "DNS issue"
$ echo ""
$ echo "===== Leftover CentOS Packages ====="
$ rpm -qa | grep -i centos || echo "None found"