EL 8 to EL 9 Upgrade
Upgrading from EL 8 (CentOS 8, AlmaLinux 8, Rocky Linux 8) to EL 9 is a major version upgrade. This guide covers the full process using the Leapp and ELevate tools.
Overview
Section titled “Overview”Upgrade Paths
Section titled “Upgrade Paths”| Source | Target | Tool |
|---|---|---|
| CentOS 8 / CentOS Stream 8 | AlmaLinux 9 / Rocky Linux 9 | ELevate |
| AlmaLinux 8 | AlmaLinux 9 | Leapp / ELevate |
| Rocky Linux 8 | Rocky Linux 9 | Leapp / ELevate |
Prerequisites
Section titled “Prerequisites”- System is updated to the latest EL 8 minor release
- At least 2 GB of free disk space (on
/var) - A reliable full system backup
- Physical or remote console access (not just SSH)
Preparation
Section titled “Preparation”Update the Current System
Section titled “Update the Current System”dnf update -yrebootVerify the Current System Version
Section titled “Verify the Current System Version”cat /etc/redhat-releaseuname -rCreate a Full Backup
Section titled “Create a Full Backup”# Back up /etctar czf /root/etc-backup-$(date +%Y%m%d).tar.gz /etc/
# Save the list of installed packagesrpm -qa --qf '%{NAME}\n' | sort > /root/installed-packages-el8.txt
# Save partition tablefdisk -l > /root/partition-table.txt
# Back up boot configurationcp -a /boot/grub2/ /root/grub2-backup/Installing the ELevate Tools
Section titled “Installing the ELevate Tools”Install the elevate-release Package
Section titled “Install the elevate-release Package”dnf install -y http://repo.almalinux.org/elevate/elevate-release-latest-el8.noarch.rpmInstall Leapp and Upgrade Data
Section titled “Install Leapp and Upgrade Data”Install the data package corresponding to your target system:
dnf install -y leapp-upgrade leapp-data-almalinuxdnf install -y leapp-upgrade leapp-data-rockydnf install -y leapp-upgrade leapp-data-centosPre-Upgrade Assessment
Section titled “Pre-Upgrade Assessment”Run the Pre-Upgrade Check
Section titled “Run the Pre-Upgrade Check”leapp preupgradeThis generates a detailed report listing all issues that must be addressed.
Review the Pre-Upgrade Report
Section titled “Review the Pre-Upgrade Report”cat /var/log/leapp/leapp-report.txtCommon Blocking Issues and Solutions
Section titled “Common Blocking Issues and Solutions”Issue: Deprecated Repositories Detected
Section titled “Issue: Deprecated Repositories Detected”# Disable incompatible third-party reposdnf config-manager --disable <repo-name>Issue: PAM Configuration Incompatible
Section titled “Issue: PAM Configuration Incompatible”leapp answer --section authselect_check.confirm=TrueIssue: GRUB Device Detection Failure
Section titled “Issue: GRUB Device Detection Failure”echo 'GRUB_DEVICE=/dev/sda' >> /etc/default/leappIssue: Custom Kernel Modules Detected
Section titled “Issue: Custom Kernel Modules Detected”rmmod <module-name># Also remove the corresponding config from /etc/modules-load.d/Handling Third-Party Packages
Section titled “Handling Third-Party Packages”dnf list installed | grep -v '@baseos' | grep -v '@appstream'# Add packages to remove during upgradeecho "custom-package-name" >> /etc/leapp/transaction/to_remove
# Add packages to keep during upgradeecho "package-to-keep" >> /etc/leapp/transaction/to_keepPerforming the Upgrade
Section titled “Performing the Upgrade”Start the Upgrade Process
Section titled “Start the Upgrade Process”leapp upgradeThe upgrade process takes considerable time. Be patient.
Reboot into the Upgrade Environment
Section titled “Reboot into the Upgrade Environment”rebootPost-Upgrade Checks
Section titled “Post-Upgrade Checks”Verify the System Version
Section titled “Verify the System Version”cat /etc/redhat-releaseuname -rrpm -q kernel-coreCheck System Service Status
Section titled “Check System Service Status”systemctl --failedVerify Network Connectivity
Section titled “Verify Network Connectivity”ip addr shownmcli connection showping -c 3 8.8.8.8Verify Repository Configuration
Section titled “Verify Repository Configuration”dnf repolistdnf check-updateClean Up Upgrade Artifacts
Section titled “Clean Up Upgrade Artifacts”# Remove upgrade-related packagesdnf remove -y leapp-upgrade leapp-data-* elevate-release
# Remove old EL 8 kernelsdnf remove -y $(rpm -qa | grep el8 | grep kernel)
# Remove Leapp leftover datarm -rf /var/log/leapp /root/tmp_leapp_py3Rebuild the RPM Database
Section titled “Rebuild the RPM Database”rpm --rebuilddbReset SELinux Labels
Section titled “Reset SELinux Labels”fixfiles -B onbootrebootKnown Issues
Section titled “Known Issues”Network Configuration Changes
Section titled “Network Configuration Changes”EL 9 defaults to the NetworkManager key-file format instead of the legacy ifcfg format.
nmcli connection migrateSSH Configuration Changes
Section titled “SSH Configuration Changes”EL 9 disables some legacy cryptographic algorithms by default.
update-crypto-policies --showIf temporary compatibility with older clients is needed:
update-crypto-policies --set DEFAULT:SHA1Python Version Changes
Section titled “Python Version Changes”EL 9 ships Python 3.9 by default. Python 2 is no longer available.
python3 --versionalternatives --list | grep pythonPHP Module Stream Changes
Section titled “PHP Module Stream Changes”dnf module list phpdnf module reset phpdnf module enable php:8.1Application Compatibility Checks
Section titled “Application Compatibility Checks”Check Dynamic Library Dependencies
Section titled “Check Dynamic Library Dependencies”for bin in /usr/local/bin/*; do ldd "$bin" 2>&1 | grep "not found" && echo " --> $bin"doneValidate systemd Service Files
Section titled “Validate systemd Service Files”systemd-analyze verify /etc/systemd/system/*.service 2>&1 | grep -v "^$"Compare Pre- and Post-Upgrade Package Lists
Section titled “Compare Pre- and Post-Upgrade Package Lists”rpm -qa --qf '%{NAME}\n' | sort > /root/installed-packages-el9.txtdiff /root/installed-packages-el8.txt /root/installed-packages-el9.txtHandling Upgrade Failures
Section titled “Handling Upgrade Failures”If the upgrade process is interrupted or fails:
Check Upgrade Logs
Section titled “Check Upgrade Logs”cat /var/log/leapp/leapp-upgrade.logjournalctl -b -p errRestore from Snapshot
Section titled “Restore from Snapshot”If you created an LVM snapshot or VM snapshot beforehand, restoring it is the most reliable rollback method.
lvconvert --merge /dev/vg0/pre-upgrade-snapreboot