Skip to content

update Kernels page for UEK standardization - #39

Merged
dougburks merged 2 commits into
3/devfrom
docs/uek-kernel-standardization
Sep 4, 2026
Merged

dougburks merged 2 commits into
3/devfrom
docs/uek-kernel-standardization

Conversation

@TOoSmOotH

@TOoSmOotH TOoSmOotH commented Sep 4, 2026 •

Copy link
Copy Markdown
Contributor

Follow-up to securityonion#16188, which standardized on the Oracle UEK kernel and made removal of the stock EL9 (RHCK) kernel automatic.

The Kernels page still described the old state: the ISO ships both kernels, and you may opt to remove RHCK yourself with dnf remove. That is no longer how it happens.

Rewritten around the current behavior, leading with the fact that none of this needs admin action:

  • The move to UEK8 and the removal of the stock EL9 kernel are automatic. Nodes pick up UEK8 through their normal OS updates, and the highstate removes RHCK on the first pass after the node reboots onto it.
  • Why the removal is deferred until after the reboot (dnf refuses to erase the running kernel, and the node proves it boots on UEK8 before its fallback is deleted).
  • A note that UEK7 kernel-uek 5.x packages are left to age out on their own.
  • A Doing It Manually section for when a node did not get there on its own: so-kernel-upgrade to install UEK8 and set the boot default (with the caveat that the manager has to have the kernel repo synced), and so-kernel-upgrade --cleanup to remove RHCK without waiting for the next highstate.

The old "fewer reboot prompts / less /boot usage" pitch is dropped — it was framing for a manual step that no longer exists.

Not included: release-notes.md has no 3.3.0 section yet, and the page's nav placement under Tricks and Tips is unchanged.

securityonion#16188 standardized on the Oracle UEK kernel and made
removal of the stock EL9 (RHCK) kernel automatic, so the page's manual
"dnf remove" recipe is no longer the way this happens.

Rewrites the page around the current behavior: so-kernel-upgrade to move
a node still on RHCK or UEK7 onto UEK8, why the RHCK removal is deferred
until after the reboot (dnf protects the running kernel), that the
highstate performs it, and so-kernel-upgrade --cleanup to trigger it by
hand. Notes that UEK7 5.x packages are left to age out on their own.
The page opened with the benefits of dropping the stock EL9 kernel, which
read as a pitch for doing something the admin no longer has to do. Says
up front that the move to UEK8 and the RHCK removal are automatic and
need no action, and moves so-kernel-upgrade into a "Doing It Manually"
section for the case where a node did not get there on its own.
@dougburks
dougburks merged commit 2f05da3 into 3/dev Sep 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants