From 669e48a6681b7e9d688310b86a4077ab2ae2b1e3 Mon Sep 17 00:00:00 2001 From: Mike Reeves Date: Fri, 4 Sep 2026 14:16:11 -0400 Subject: [PATCH 1/2] update Kernels page for UEK standardization securityonion#16188 standardized on the Oracle UEK kernel and made removal of the stock EL9 (RHCK) kernel automatic, so the page's manual "dnf remove" recipe is no longer the way this happens. Rewrites the page around the current behavior: so-kernel-upgrade to move a node still on RHCK or UEK7 onto UEK8, why the RHCK removal is deferred until after the reboot (dnf protects the running kernel), that the highstate performs it, and so-kernel-upgrade --cleanup to trigger it by hand. Notes that UEK7 5.x packages are left to age out on their own. --- docs/kernels.md | 39 ++++++++++++++++++++++++++++++++++++--- 1 file changed, 36 insertions(+), 3 deletions(-) diff --git a/docs/kernels.md b/docs/kernels.md index 35dda19c..9f76a85a 100644 --- a/docs/kernels.md +++ b/docs/kernels.md @@ -1,8 +1,41 @@ # Kernels -The Security Onion ISO image contains the standard RedHat kernel and the Oracle UEK kernel. It should default to the newer Oracle UEK kernel series. If you don't need the older RedHat kernel series, you may opt to remove it: +Security Onion standardizes on the Oracle Unbreakable Enterprise Kernel (UEK). Nodes run the UEK8 (6.x) kernel series, and the standard EL9 RedHat compatible kernel (RHCK, 5.14) is removed automatically once a node is actually running UEK8. + +This has a number of benefits. First, you will see fewer reboot prompts. Additionally, this will reduce your disk usage in the `/boot` partition. + +## Upgrading to UEK8 + +If a node is still running the standard EL9 kernel or the older UEK7 (5.x) kernel, you can move it to UEK8 by running the following command on that node: ``` -sudo dnf remove kernel kernel-core kernel-modules kernel-modules-core kernel-tools kernel-tools-libs +sudo so-kernel-upgrade +``` + +This installs the UEK8 kernel and makes it the boot default. It does not reboot the node, so you can schedule the reboot yourself. The new kernel does not take effect until you reboot. + +!!! NOTE + + The manager mirrors the UEK8 packages and serves them to the rest of the grid. If the manager has not synced them yet, `so-kernel-upgrade` on the manager will sync them for you; on any other node it will tell you to sync the manager first. + +## Removal of the EL9 Kernel + +Once a node reboots and comes up on UEK8, the next highstate removes the standard EL9 kernel packages: + ``` -This can be beneficial in a number of ways. First, you will see fewer reboot prompts. Additionally, this will reduce your disk usage in the /boot partition. +kernel kernel-core kernel-modules kernel-modules-core kernel-tools kernel-tools-libs +``` + +The removal is deliberately deferred until after the reboot. `dnf` refuses to erase the running kernel, and waiting also means the node has proven it boots on UEK8 before its fallback is deleted. Fresh installs reboot at the end of setup and are cleaned up on the first highstate after that; existing nodes are cleaned up whenever you reboot them. + +If you would rather not wait for the next highstate, you can run the cleanup directly: + +``` +sudo so-kernel-upgrade --cleanup +``` + +This does nothing unless the node is already running UEK8. + +!!! NOTE + + Older UEK7 `kernel-uek` 5.x packages are not removed by this cleanup. They age out on their own as newer kernels are installed. From f7cf5031f9edf675609a4b4d88bda6756fedda22 Mon Sep 17 00:00:00 2001 From: Mike Reeves Date: Fri, 4 Sep 2026 14:24:27 -0400 Subject: [PATCH 2/2] lead with the automatic behavior on the Kernels page The page opened with the benefits of dropping the stock EL9 kernel, which read as a pitch for doing something the admin no longer has to do. Says up front that the move to UEK8 and the RHCK removal are automatic and need no action, and moves so-kernel-upgrade into a "Doing It Manually" section for the case where a node did not get there on its own. --- docs/kernels.md | 32 +++++++++++++++----------------- 1 file changed, 15 insertions(+), 17 deletions(-) diff --git a/docs/kernels.md b/docs/kernels.md index 9f76a85a..b2b80d7d 100644 --- a/docs/kernels.md +++ b/docs/kernels.md @@ -1,41 +1,39 @@ # Kernels -Security Onion standardizes on the Oracle Unbreakable Enterprise Kernel (UEK). Nodes run the UEK8 (6.x) kernel series, and the standard EL9 RedHat compatible kernel (RHCK, 5.14) is removed automatically once a node is actually running UEK8. +Security Onion standardizes on the Oracle Unbreakable Enterprise Kernel (UEK). Nodes run the UEK8 (6.x) kernel series, and the standard EL9 RedHat compatible kernel (RHCK, 5.14) is removed once a node is actually running UEK8. -This has a number of benefits. First, you will see fewer reboot prompts. Additionally, this will reduce your disk usage in the `/boot` partition. +This is all automatic and you should not need to do anything. Nodes pick up the UEK8 kernel as part of their normal OS updates, and the stock EL9 kernel is removed for you on the next highstate after the node reboots onto UEK8. -## Upgrading to UEK8 +The removal is deliberately deferred until after the reboot. `dnf` refuses to erase the running kernel, and waiting also means the node has proven it boots on UEK8 before its fallback is deleted. Fresh installs reboot at the end of setup and are cleaned up on the first highstate after that; existing nodes are cleaned up whenever you reboot them. -If a node is still running the standard EL9 kernel or the older UEK7 (5.x) kernel, you can move it to UEK8 by running the following command on that node: +These are the packages removed: ``` -sudo so-kernel-upgrade +kernel kernel-core kernel-modules kernel-modules-core kernel-tools kernel-tools-libs ``` -This installs the UEK8 kernel and makes it the boot default. It does not reboot the node, so you can schedule the reboot yourself. The new kernel does not take effect until you reboot. - !!! NOTE - The manager mirrors the UEK8 packages and serves them to the rest of the grid. If the manager has not synced them yet, `so-kernel-upgrade` on the manager will sync them for you; on any other node it will tell you to sync the manager first. + Older UEK7 `kernel-uek` 5.x packages are not removed. They age out on their own as newer kernels are installed. -## Removal of the EL9 Kernel +## Doing It Manually -Once a node reboots and comes up on UEK8, the next highstate removes the standard EL9 kernel packages: +If a node did not end up on UEK8 on its own, you can run the following command on that node: ``` -kernel kernel-core kernel-modules kernel-modules-core kernel-tools kernel-tools-libs +sudo so-kernel-upgrade ``` -The removal is deliberately deferred until after the reboot. `dnf` refuses to erase the running kernel, and waiting also means the node has proven it boots on UEK8 before its fallback is deleted. Fresh installs reboot at the end of setup and are cleaned up on the first highstate after that; existing nodes are cleaned up whenever you reboot them. +This installs the UEK8 kernel and makes it the boot default. It does not reboot the node, so you can schedule the reboot yourself. The new kernel does not take effect until you reboot. + +!!! NOTE + + The manager mirrors the UEK8 packages and serves them to the rest of the grid. If the manager has not synced them yet, `so-kernel-upgrade` on the manager will sync them for you; on any other node it will tell you to sync the manager first. -If you would rather not wait for the next highstate, you can run the cleanup directly: +Similarly, if the stock EL9 kernel is still installed on a node that is already running UEK8, you can run the cleanup directly instead of waiting for the next highstate: ``` sudo so-kernel-upgrade --cleanup ``` This does nothing unless the node is already running UEK8. - -!!! NOTE - - Older UEK7 `kernel-uek` 5.x packages are not removed by this cleanup. They age out on their own as newer kernels are installed.