# AlmaLinux 9

Validated CloudStack KVM VPS template rebuilt and promoted on 2026-08-11.

## Artifact

- File: `almalinux-9.qcow2`
- Format: standalone sparse uncompressed QCOW2
- Architecture: x86_64
- Virtual disk: 30 GiB (32212254720 bytes)
- Physical file: 1.01 GiB (1089732608 bytes)
- Compressed clusters: 0
- Backing file: none
- SHA-256: `8a9bca656b1e8158dfc37884b34038c87e6f610c950b02c8d74583e83c0db220`
- Mirror URL: https://cloud-mirrors.noc.sh/almalinux-9/almalinux-9.qcow2
- CloudStack template UUID: `0858433d-450c-481a-b91c-73dd21187b74`
- Source state: Ready / Download Complete

## Guest baseline

- Release: AlmaLinux 9.8
- Kernel: `5.14.0-687.36.1.el9_8.x86_64`
- Packages: 380
- Swap: fixed 1 GiB `/swap.img`
- Root filesystem: XFS with automatic first-boot growth
- Cloud-init: `24.4-8.el9_8.1.alma.1`, DataSourceCloudStack
- QEMU Guest Agent: enabled
- SELinux: enforcing
- Boot: legacy BIOS and UEFI guest packages retained

The minimal-VPS transaction used `dnf remove --noautoremove`. It removed only
two superseded kernels, CPU microcode for physical hardware, the NFS client,
and SSSD client components. GRUB BIOS/EFI, shim, dracut, current kernel and
modules, VirtIO, NetworkManager, OpenSSH, cloud-init, QEMU Guest Agent, DNF,
XFS, SELinux, chrony, rsyslog, fwupd, kexec-tools, and tuned remain installed.

## CloudStack registration

Register the template privately with these settings:

- Hypervisor: KVM
- Format: QCOW2
- OS type: AlmaLinux 9
- HVM: Yes
- Password enabled: Yes
- SSH key enabled: Yes
- Public: No
- Featured: No
- Extractable: No
- Template details: `guest.cpu.mode=host-model`

Run `cleanupdetails=true` separately before setting `guest.cpu.mode` so no
transient builder details remain.

## Verification

Run before registration:

```bash
sha256sum almalinux-9.qcow2
qemu-img check almalinux-9.qcow2
qemu-img info almalinux-9.qcow2
```

Expected SHA-256:

```text
8a9bca656b1e8158dfc37884b34038c87e6f610c950b02c8d74583e83c0db220  almalinux-9.qcow2
```

Acceptance passed with the Base, Pro, and Ultra offerings. Tests covered
CloudStack password and SSH-key injection, password/key access after reboot,
password-only deployments with no residual authorized key, hostname and
network assignment, 30/50/80 GiB disk growth, 1 GiB swap, cloud-init with no
errors or recoverable warnings, QEMU Guest Agent `guest-ping`, SELinux
enforcing, one current kernel, enabled repositories, and zero failed systemd
units. A final password-only Base smoke test passed after importing the
canonical mirror URL.

## Lifecycle note

Validated final CloudStack template. Rebuild and repeat the complete acceptance
suite after material kernel, cloud-init, CloudStack, or hypervisor changes.
