Skip to content

EL 8 to EL 9 Upgrade

Upgrading from EL 8 (CentOS 8, AlmaLinux 8, Rocky Linux 8) to EL 9 is a major version upgrade. This guide covers the full process using the Leapp and ELevate tools.

SourceTargetTool
CentOS 8 / CentOS Stream 8AlmaLinux 9 / Rocky Linux 9ELevate
AlmaLinux 8AlmaLinux 9Leapp / ELevate
Rocky Linux 8Rocky Linux 9Leapp / ELevate
  • System is updated to the latest EL 8 minor release
  • At least 2 GB of free disk space (on /var)
  • A reliable full system backup
  • Physical or remote console access (not just SSH)
Ensure EL 8 is fully updated
dnf update -y
reboot
Confirm current system version
cat /etc/redhat-release
uname -r
Back up critical data and configurations
# Back up /etc
tar czf /root/etc-backup-$(date +%Y%m%d).tar.gz /etc/
# Save the list of installed packages
rpm -qa --qf '%{NAME}\n' | sort > /root/installed-packages-el8.txt
# Save partition table
fdisk -l > /root/partition-table.txt
# Back up boot configuration
cp -a /boot/grub2/ /root/grub2-backup/
Install the ELevate repository
dnf install -y http://repo.almalinux.org/elevate/elevate-release-latest-el8.noarch.rpm

Install the data package corresponding to your target system:

For upgrading to AlmaLinux 9
dnf install -y leapp-upgrade leapp-data-almalinux
For upgrading to Rocky Linux 9
dnf install -y leapp-upgrade leapp-data-rocky
For upgrading to CentOS Stream 9
dnf install -y leapp-upgrade leapp-data-centos
Run the pre-upgrade assessment
leapp preupgrade

This generates a detailed report listing all issues that must be addressed.

View the pre-upgrade report
cat /var/log/leapp/leapp-report.txt
Remove incompatible repositories
# Disable incompatible third-party repos
dnf config-manager --disable <repo-name>
Confirm PAM module compatibility
leapp answer --section authselect_check.confirm=True
Manually specify GRUB device
echo 'GRUB_DEVICE=/dev/sda' >> /etc/default/leapp
Remove third-party kernel modules
rmmod <module-name>
# Also remove the corresponding config from /etc/modules-load.d/
List packages from non-official repos
dnf list installed | grep -v '@baseos' | grep -v '@appstream'
Configure Leapp to handle custom packages
# Add packages to remove during upgrade
echo "custom-package-name" >> /etc/leapp/transaction/to_remove
# Add packages to keep during upgrade
echo "package-to-keep" >> /etc/leapp/transaction/to_keep
Execute the in-place upgrade
leapp upgrade

The upgrade process takes considerable time. Be patient.

Reboot to complete the upgrade
reboot
Confirm the system is now EL 9
cat /etc/redhat-release
uname -r
rpm -q kernel-core
Check for failed services
systemctl --failed
Check network configuration
ip addr show
nmcli connection show
ping -c 3 8.8.8.8
Check repository configuration
dnf repolist
dnf check-update
Clean up Leapp upgrade data
# Remove upgrade-related packages
dnf remove -y leapp-upgrade leapp-data-* elevate-release
# Remove old EL 8 kernels
dnf remove -y $(rpm -qa | grep el8 | grep kernel)
# Remove Leapp leftover data
rm -rf /var/log/leapp /root/tmp_leapp_py3
Rebuild the RPM database
rpm --rebuilddb
Relabel SELinux contexts
fixfiles -B onboot
reboot

EL 9 defaults to the NetworkManager key-file format instead of the legacy ifcfg format.

Migrate network configuration to the new format
nmcli connection migrate

EL 9 disables some legacy cryptographic algorithms by default.

Check the SSH crypto policy
update-crypto-policies --show

If temporary compatibility with older clients is needed:

Temporarily lower the crypto policy (not recommended long-term)
update-crypto-policies --set DEFAULT:SHA1

EL 9 ships Python 3.9 by default. Python 2 is no longer available.

Check the Python version
python3 --version
alternatives --list | grep python
Check and reset the PHP module stream
dnf module list php
dnf module reset php
dnf module enable php:8.1
Verify shared library dependencies are satisfied
for bin in /usr/local/bin/*; do
ldd "$bin" 2>&1 | grep "not found" && echo " --> $bin"
done
Verify custom service files
systemd-analyze verify /etc/systemd/system/*.service 2>&1 | grep -v "^$"

Compare Pre- and Post-Upgrade Package Lists

Section titled “Compare Pre- and Post-Upgrade Package Lists”
Compare package changes
rpm -qa --qf '%{NAME}\n' | sort > /root/installed-packages-el9.txt
diff /root/installed-packages-el8.txt /root/installed-packages-el9.txt

If the upgrade process is interrupted or fails:

Review upgrade logs
cat /var/log/leapp/leapp-upgrade.log
journalctl -b -p err

If you created an LVM snapshot or VM snapshot beforehand, restoring it is the most reliable rollback method.

Restore from LVM snapshot (if applicable)
lvconvert --merge /dev/vg0/pre-upgrade-snap
reboot