Skip to content

EL 9 to EL 10 Upgrade

Upgrading from EL 9 (AlmaLinux 9, Rocky Linux 9, CentOS Stream 9) to EL 10 is a major version upgrade. This guide covers the complete upgrade process using Leapp and ELevate, along with important considerations.

Understand the key changes in EL 10 before proceeding:

ChangeEL 9EL 10
Package managerDNF 4DNF 4.20 (still DNF 4, command-compatible)
Default Python3.93.12
Rootless container networkslirp4netnspasta
NetworkManager config formatkeyfile (ifcfg deprecated)keyfile only (ifcfg removed)
Default crypto policyDEFAULT (SHA-1 allowed)DEFAULT (SHA-1 disabled)
Podman version4.x5.x
SourceTargetTool
AlmaLinux 9AlmaLinux 10ELevate (includes Leapp)
Rocky Linux 9Rocky Linux 10ELevate (includes Leapp)
CentOS Stream 9CentOS Stream 10ELevate (leapp-data-centos)
  • System updated to the latest minor version of EL 9
  • At least 5 GB free disk space on / and /var partitions
  • Complete system backup (snapshot or backup files)
  • Physical or remote console access (multiple reboots occur during upgrade)
  • Verify compatibility of critical applications with EL 10
  • CPU must support x86_64-v2 microarchitecture (EL 10 minimum requirement — older CPUs will be blocked by Leapp)
Ensure EL 9 is fully up to date
sudo dnf update -y
sudo reboot
Confirm current system version
cat /etc/redhat-release
uname -r
Back up critical data and configuration
# Back up /etc directory
sudo tar czf /root/etc-backup-$(date +%Y%m%d).tar.gz /etc/
# List installed packages (for comparison after upgrade)
rpm -qa --qf '%{NAME}\n' | sort > /root/packages-before-upgrade.txt

EL 10 completely removes ifcfg format support. Migrate to keyfile before upgrading:

Migrate ifcfg profiles to keyfile format
sudo nmcli connection migrate
ls /etc/NetworkManager/system-connections/

Identify any services relying on SHA-1 (old SSH keys, self-signed certificates):

Check current crypto policy
update-crypto-policies --show
# Check SSH host key types
ls -la /etc/ssh/ssh_host_*_key

Upgrade with ELevate (AlmaLinux / Rocky Linux)

Section titled “Upgrade with ELevate (AlmaLinux / Rocky Linux)”
Install ELevate repository (AlmaLinux example)
sudo dnf install -y http://repo.almalinux.org/elevate/elevate-release-latest-el9.noarch.rpm

Choose the data package matching your target distribution:

AlmaLinux 9 → AlmaLinux 10
sudo dnf install -y leapp-upgrade leapp-data-almalinux
Rocky Linux 9 → Rocky Linux 10
sudo dnf install -y leapp-upgrade leapp-data-rocky
Run upgrade pre-check
sudo leapp preupgrade

The pre-check generates a report listing all inhibitors and warnings. All inhibitors must be resolved before proceeding.

View the report:

View detailed pre-check report
sudo cat /var/log/leapp/leapp-report.txt

SHA-1 related warnings:

Terminal window
# Temporarily allow SHA-1 to complete the upgrade (restore afterward)
sudo update-crypto-policies --set DEFAULT:SHA1

Kernel module blockers:

Some legacy kernel modules are not available in EL 10:

Terminal window
sudo leapp answer --section remove_pam_pkcs11_module_check.confirm=True

After resolving all inhibitors:

Start the upgrade (system will reboot multiple times)
sudo leapp upgrade
sudo reboot

The upgrade takes approximately 20-40 minutes. The system automatically reboots into the upgrade environment, then reboots again into EL 10.

Confirm system version
cat /etc/redhat-release
uname -r
Remove upgrade leftovers
sudo dnf remove $(rpm -qa | grep -i 'el9\|leapp') --skip-broken -y
sudo dnf autoremove -y
sudo dnf distro-sync -y
Verify network is working
nmcli connection show
ip addr
ping -c 3 8.8.8.8

If you temporarily modified the crypto policy before the upgrade:

Restore default crypto policy
sudo update-crypto-policies --set DEFAULT
# Regenerate SSH host keys if needed
sudo ssh-keygen -A

Verify the DNF Version and Metadata Behavior

Section titled “Verify the DNF Version and Metadata Behavior”

EL 10 still uses DNF 4 (4.20); confirm the version after upgrading:

Confirm DNF version
dnf --version
# Should show 4.20.x

EL 10 no longer downloads filelists metadata by default. If a query that depends on file paths fails, add:

Load filelists metadata temporarily
sudo dnf --setopt=optional_metadata_types=filelists repoquery -l <package>
Check for failed services
sudo systemctl --failed
sudo journalctl -p err -b

EL 10 no longer distributes AppStream modular content. The dnf module command still exists, but prints a deprecation warning and has no module streams available.

Migration path: The EL 9 pattern of dnf module enable php:8.1 is replaced on EL 10 by installing versioned packages directly:

Terminal window
# On EL 10, install a specific PHP version directly
sudo dnf install php8.2
# Or use upstream repositories like Remi for more version options

Any automation scripts relying on dnf module must be updated before the upgrade.

Rootless Container Network Issues (Podman)

Section titled “Rootless Container Network Issues (Podman)”

Podman 5 defaults to the pasta network backend. If you encounter issues:

Terminal window
# Install slirp4netns as a fallback
sudo dnf install slirp4netns

After SHA-1 is disabled, old RSA keys may fail:

Generate a new Ed25519 key (recommended)
ssh-keygen -t ed25519 -C "[email protected]"

An in-place major upgrade has no official “undo” command. Once ELevate has replaced the system packages, the only reliable way back is restoring a complete pre-upgrade backup. That’s exactly why the pre-upgrade backup/snapshot is not optional.

Choose a rollback method based on deployment type:

EnvironmentPre-upgrade preparationRollback method
Cloud instance (ECS/CVM, etc.)Take a full machine image/snapshot before upgradingRoll back from the snapshot or rebuild the instance in the console
VM (KVM/VMware)Clone the disk while powered off, or take a VM snapshotRestore the disk/snapshot
Bare metal (LVM root)lvcreate -s root-volume snapshot + separate backup of /boot, /etcRestore from snapshot and backup (below)
Bare metal (no snapshots)Full file-level or block-level backup (see Backup)Reinstall EL 9, then restore the backup
Bare metal: create an LVM root snapshot before upgrading
# Assuming the root volume is /dev/vg0/root, reserve 10G for the snapshot
sudo lvcreate -s -L 10G -n root-pre-el10 /dev/vg0/root
# Also back up /boot and key config separately (the snapshot doesn't cover them)
sudo tar czf /backup/boot-pre-el10.tar.gz /boot
sudo tar czf /backup/etc-pre-el10.tar.gz /etc
Rollback: merge-restore from the LVM snapshot
# 1) Restore /boot first — the snapshot excludes /boot, so you must restore the
# EL 9 kernel and boot entries BEFORE rebooting; otherwise the merged EL 9 root
# is paired with the EL 10 kernel, causing boot failure or mismatched modules
sudo tar xzf /backup/boot-pre-el10.tar.gz -C /
# 2) Merge the root snapshot back into the original volume (takes effect on next activation/reboot)
sudo lvconvert --merge /dev/vg0/root-pre-el10
# 3) Reboot for the merge to take effect
sudo reboot

If the upgrade fails but the system still boots, don’t rush to roll back — most issues are leftover third-party repos or a few services not yet adapted; work through Common Post-Upgrade Issues above first. Only perform a full rollback when the system won’t boot or core services can’t be recovered.