EL 9 to EL 10 Upgrade
Upgrading from EL 9 (AlmaLinux 9, Rocky Linux 9, CentOS Stream 9) to EL 10 is a major version upgrade. This guide covers the complete upgrade process using Leapp and ELevate, along with important considerations.
Before You Upgrade: Key Changes in EL 10
Section titled “Before You Upgrade: Key Changes in EL 10”Understand the key changes in EL 10 before proceeding:
| Change | EL 9 | EL 10 |
|---|---|---|
| Package manager | DNF 4 | DNF 4.20 (still DNF 4, command-compatible) |
| Default Python | 3.9 | 3.12 |
| Rootless container network | slirp4netns | pasta |
| NetworkManager config format | keyfile (ifcfg deprecated) | keyfile only (ifcfg removed) |
| Default crypto policy | DEFAULT (SHA-1 allowed) | DEFAULT (SHA-1 disabled) |
| Podman version | 4.x | 5.x |
Upgrade Paths
Section titled “Upgrade Paths”| Source | Target | Tool |
|---|---|---|
| AlmaLinux 9 | AlmaLinux 10 | ELevate (includes Leapp) |
| Rocky Linux 9 | Rocky Linux 10 | ELevate (includes Leapp) |
| CentOS Stream 9 | CentOS Stream 10 | ELevate (leapp-data-centos) |
Prerequisites
Section titled “Prerequisites”- System updated to the latest minor version of EL 9
- At least 5 GB free disk space on
/and/varpartitions - Complete system backup (snapshot or backup files)
- Physical or remote console access (multiple reboots occur during upgrade)
- Verify compatibility of critical applications with EL 10
- CPU must support x86_64-v2 microarchitecture (EL 10 minimum requirement — older CPUs will be blocked by Leapp)
Preparation
Section titled “Preparation”Update to the Latest Minor Version
Section titled “Update to the Latest Minor Version”sudo dnf update -ysudo rebootVerify Current System Version
Section titled “Verify Current System Version”cat /etc/redhat-releaseuname -rCreate a Full Backup
Section titled “Create a Full Backup”# Back up /etc directorysudo tar czf /root/etc-backup-$(date +%Y%m%d).tar.gz /etc/
# List installed packages (for comparison after upgrade)rpm -qa --qf '%{NAME}\n' | sort > /root/packages-before-upgrade.txtMigrate ifcfg Network Config (Important)
Section titled “Migrate ifcfg Network Config (Important)”EL 10 completely removes ifcfg format support. Migrate to keyfile before upgrading:
sudo nmcli connection migratels /etc/NetworkManager/system-connections/Check Crypto Policy
Section titled “Check Crypto Policy”Identify any services relying on SHA-1 (old SSH keys, self-signed certificates):
update-crypto-policies --show
# Check SSH host key typesls -la /etc/ssh/ssh_host_*_keyUpgrade with ELevate (AlmaLinux / Rocky Linux)
Section titled “Upgrade with ELevate (AlmaLinux / Rocky Linux)”Install ELevate
Section titled “Install ELevate”sudo dnf install -y http://repo.almalinux.org/elevate/elevate-release-latest-el9.noarch.rpmInstall Leapp Data Package
Section titled “Install Leapp Data Package”Choose the data package matching your target distribution:
sudo dnf install -y leapp-upgrade leapp-data-almalinuxsudo dnf install -y leapp-upgrade leapp-data-rockyRun Pre-upgrade Check
Section titled “Run Pre-upgrade Check”sudo leapp preupgradeThe pre-check generates a report listing all inhibitors and warnings. All inhibitors must be resolved before proceeding.
View the report:
sudo cat /var/log/leapp/leapp-report.txtResolve Common Inhibitors
Section titled “Resolve Common Inhibitors”SHA-1 related warnings:
# Temporarily allow SHA-1 to complete the upgrade (restore afterward)sudo update-crypto-policies --set DEFAULT:SHA1Kernel module blockers:
Some legacy kernel modules are not available in EL 10:
sudo leapp answer --section remove_pam_pkcs11_module_check.confirm=TrueExecute the Upgrade
Section titled “Execute the Upgrade”After resolving all inhibitors:
sudo leapp upgradesudo rebootThe upgrade takes approximately 20-40 minutes. The system automatically reboots into the upgrade environment, then reboots again into EL 10.
Post-Upgrade Checks
Section titled “Post-Upgrade Checks”Confirm Upgrade Success
Section titled “Confirm Upgrade Success”cat /etc/redhat-releaseuname -rClean Up Old Packages
Section titled “Clean Up Old Packages”sudo dnf remove $(rpm -qa | grep -i 'el9\|leapp') --skip-broken -ysudo dnf autoremove -ysudo dnf distro-sync -yCheck Network
Section titled “Check Network”nmcli connection showip addrping -c 3 8.8.8.8Restore Crypto Policy
Section titled “Restore Crypto Policy”If you temporarily modified the crypto policy before the upgrade:
sudo update-crypto-policies --set DEFAULT# Regenerate SSH host keys if neededsudo ssh-keygen -AVerify the DNF Version and Metadata Behavior
Section titled “Verify the DNF Version and Metadata Behavior”EL 10 still uses DNF 4 (4.20); confirm the version after upgrading:
dnf --version# Should show 4.20.xEL 10 no longer downloads filelists metadata by default. If a query that depends on file paths fails, add:
sudo dnf --setopt=optional_metadata_types=filelists repoquery -l <package>Check Critical Services
Section titled “Check Critical Services”sudo systemctl --failedsudo journalctl -p err -bCommon Post-Upgrade Issues
Section titled “Common Post-Upgrade Issues”dnf module Commands Are Deprecated
Section titled “dnf module Commands Are Deprecated”EL 10 no longer distributes AppStream modular content. The dnf module command still exists, but prints a deprecation warning and has no module streams available.
Migration path: The EL 9 pattern of dnf module enable php:8.1 is replaced on EL 10 by installing versioned packages directly:
# On EL 10, install a specific PHP version directlysudo dnf install php8.2# Or use upstream repositories like Remi for more version optionsAny automation scripts relying on dnf module must be updated before the upgrade.
Rootless Container Network Issues (Podman)
Section titled “Rootless Container Network Issues (Podman)”Podman 5 defaults to the pasta network backend. If you encounter issues:
# Install slirp4netns as a fallbacksudo dnf install slirp4netnsOld SSH Keys Rejected
Section titled “Old SSH Keys Rejected”After SHA-1 is disabled, old RSA keys may fail:
Rollback Plan
Section titled “Rollback Plan”An in-place major upgrade has no official “undo” command. Once ELevate has replaced the system packages, the only reliable way back is restoring a complete pre-upgrade backup. That’s exactly why the pre-upgrade backup/snapshot is not optional.
Choose a rollback method based on deployment type:
| Environment | Pre-upgrade preparation | Rollback method |
|---|---|---|
| Cloud instance (ECS/CVM, etc.) | Take a full machine image/snapshot before upgrading | Roll back from the snapshot or rebuild the instance in the console |
| VM (KVM/VMware) | Clone the disk while powered off, or take a VM snapshot | Restore the disk/snapshot |
| Bare metal (LVM root) | lvcreate -s root-volume snapshot + separate backup of /boot, /etc | Restore from snapshot and backup (below) |
| Bare metal (no snapshots) | Full file-level or block-level backup (see Backup) | Reinstall EL 9, then restore the backup |
# Assuming the root volume is /dev/vg0/root, reserve 10G for the snapshotsudo lvcreate -s -L 10G -n root-pre-el10 /dev/vg0/root
# Also back up /boot and key config separately (the snapshot doesn't cover them)sudo tar czf /backup/boot-pre-el10.tar.gz /bootsudo tar czf /backup/etc-pre-el10.tar.gz /etc# 1) Restore /boot first — the snapshot excludes /boot, so you must restore the# EL 9 kernel and boot entries BEFORE rebooting; otherwise the merged EL 9 root# is paired with the EL 10 kernel, causing boot failure or mismatched modulessudo tar xzf /backup/boot-pre-el10.tar.gz -C /
# 2) Merge the root snapshot back into the original volume (takes effect on next activation/reboot)sudo lvconvert --merge /dev/vg0/root-pre-el10
# 3) Reboot for the merge to take effectsudo rebootIf the upgrade fails but the system still boots, don’t rush to roll back — most issues are leftover third-party repos or a few services not yet adapted; work through Common Post-Upgrade Issues above first. Only perform a full rollback when the system won’t boot or core services can’t be recovered.
Further Reading
Section titled “Further Reading”- EL 8 to EL 9 Upgrade — Previous major version upgrade guide
- DNF Basics — DNF 4.20 and modularity deprecation notes
- NetworkManager — ifcfg migration
- ELevate Official Documentation — AlmaLinux ELevate project