# CentOS Stream 9

Final CloudStack KVM template rebuilt from the official CentOS Stream 9
GenericCloud image `20260810.0` and validated on 11 August 2026.

## Artifact

- File: `centos-stream-9.qcow2`
- Format: standalone sparse QCOW2, uncompressed, with no backing file
- Architecture: x86_64
- Boot mode: legacy BIOS
- Virtual disk: 30 GiB (32212254720 bytes)
- Stored file: 1.00 GiB (1070399488 bytes)
- Fixed swap file: 1 GiB (1073737728 bytes)
- SHA-256: `8d3bae0b185d3fe33a8cc06f9010aa554e1ae6b85df07a0224f8a5cd10aabb4a`
- Mirror URL: https://cloud-mirrors.noc.sh/centos-stream-9/centos-stream-9.qcow2
- Final CloudStack template UUID: `aa2462c7-eb1b-4f77-842d-f16f03d674f8`
- Retained private rebuild-source UUID: `4158ab90-8bd6-4c09-9325-54dd7fdd717a`
- Source image SHA-256: `bdecef3804f21c6aee4805f982e6a527bce91d4636bc4c11df37908bf770e7b7`
- Source state: Ready / Download Complete

## Guest contents

- Minimal VPS guest: 374 RPM packages
- Kernel: `5.14.0-734.el9.x86_64`
- cloud-init: `24.4-8.el9.1`
- QEMU Guest Agent: `10.1.0-23.el9`
- NetworkManager, OpenSSH, DNF, XFS, SELinux, chrony, rsyslog, polkit,
  policycoreutils, GRUB, dracut, and the active kernel modules retained
- Cockpit, NFS/RPC, quota, SSSD, GSS proxy, geolocation, and physical
  microcode payloads removed without automatic dependency removal
- The official image already omits kernel headers, kernel development files,
  `linux-firmware`, and `kernel-modules-extra`
- CentOS Stream BaseOS, AppStream, and Extras repositories enabled

## CloudStack registration

Register the template privately with these settings:

- Hypervisor: KVM
- Format: QCOW2
- OS type: CentOS Stream 9
- HVM: Yes
- Password enabled: Yes
- SSH key enabled: Yes
- Public: No
- Featured: No
- Extractable: No
- Architecture: x86_64
- Template details: `guest.cpu.mode=host-model`

The EL9 x86-64-v2 baseline is not satisfied by CloudStack's default `qemu64`
CPU model. Do not remove the `guest.cpu.mode=host-model` template detail.

Root password and key delivery require both effective OpenSSH settings:

```text
PasswordAuthentication yes
PermitRootLogin yes
```

The settings are stored in
`/etc/ssh/sshd_config.d/00-cloudstack-password.conf` so they take precedence
over the official image's `50-cloud-init.conf` defaults.

Do not copy transient CloudStack runtime details such as
`Message.ReservedCapacityFreed.Flag`.

## Verification

Run before registration:

```bash
sha256sum centos-stream-9.qcow2
qemu-img check centos-stream-9.qcow2
qemu-img info centos-stream-9.qcow2
```

Expected SHA-256:

```text
8d3bae0b185d3fe33a8cc06f9010aa554e1ae6b85df07a0224f8a5cd10aabb4a  centos-stream-9.qcow2
```

Fresh Base, Pro, and Ultra deployments passed boot, networking, automatic root
disk expansion, 1 GiB swap, CloudStack password delivery, SSH key delivery,
cloud-init completion, SELinux Enforcing, zero failed systemd units, host-model
CPU, and QEMU Guest Agent checks. Base passed key and password access before and
after a CloudStack reboot. Pro and Ultra passed password-only access with no
residual authorized keys. A final password-only Base smoke test was repeated
from the canonical URL and final template UUID.
