INFO: Log in to your Red Hat account... INFO: Configure AWS Credentials... WARN: The current version (1.2.59) is not up to date with latest rosa cli released version (1.2.60). WARN: It is recommended that you update to the latest version. INFO: Logged in as 'konflux-ci-418295695583' on 'https://api.openshift.com' INFO: Create ROSA with HCP cluster... WARN: The current version (1.2.59) is not up to date with latest rosa cli released version (1.2.60). WARN: It is recommended that you update to the latest version. INFO: Creating cluster 'kx-9b3410734d' INFO: To view a list of clusters and their status, run 'rosa list clusters' INFO: Cluster 'kx-9b3410734d' has been created. INFO: Once the cluster is installed you will need to add an Identity Provider before you can login into the cluster. See 'rosa create idp --help' for more information. Name: kx-9b3410734d Domain Prefix: kx-9b3410734d Display Name: kx-9b3410734d ID: 2o0m2n1d1an1nibku3ss6s5erb0f5vb5 External ID: f74f81bc-a136-47a8-95cc-bfdd35cad863 Control Plane: ROSA Service Hosted OpenShift Version: 4.17.46 Channel Group: stable DNS: Not ready AWS Account: 418295695583 AWS Billing Account: 418295695583 API URL: Console URL: Region: us-east-1 Availability: - Control Plane: MultiAZ - Data Plane: MultiAZ Nodes: - Compute (desired): 3 - Compute (current): 0 Network: - Type: OVNKubernetes - Service CIDR: 172.30.0.0/16 - Machine CIDR: 10.0.0.0/16 - Pod CIDR: 10.128.0.0/14 - Host Prefix: /23 - Subnets: subnet-001fc23497e4a3aeb, subnet-00ffba09365a434bc, subnet-074cbf0329958194a, subnet-0689cd077699b690a, subnet-0f9f09e46f74cde64, subnet-033f48892ddbaa09d EC2 Metadata Http Tokens: optional Role (STS) ARN: arn:aws:iam::418295695583:role/ManagedOpenShift-HCP-ROSA-Installer-Role Support Role ARN: arn:aws:iam::418295695583:role/ManagedOpenShift-HCP-ROSA-Support-Role Instance IAM Roles: - Worker: arn:aws:iam::418295695583:role/ManagedOpenShift-HCP-ROSA-Worker-Role Operator IAM Roles: - arn:aws:iam::418295695583:role/rosa-hcp-openshift-cluster-csi-drivers-ebs-cloud-credentials - arn:aws:iam::418295695583:role/rosa-hcp-openshift-cloud-network-config-controller-cloud-credent - arn:aws:iam::418295695583:role/rosa-hcp-openshift-image-registry-installer-cloud-credentials - arn:aws:iam::418295695583:role/rosa-hcp-openshift-ingress-operator-cloud-credentials - arn:aws:iam::418295695583:role/rosa-hcp-kube-system-control-plane-operator - arn:aws:iam::418295695583:role/rosa-hcp-kube-system-kms-provider - arn:aws:iam::418295695583:role/rosa-hcp-kube-system-kube-controller-manager - arn:aws:iam::418295695583:role/rosa-hcp-kube-system-capa-controller-manager Managed Policies: Yes State: waiting (Waiting for user action) Private: No Delete Protection: Disabled Created: Jan 23 2026 17:26:55 UTC Details Page: https://console.redhat.com/openshift/details/s/38fSd3FSKGYpxIZU91wHcnxUai6 OIDC Endpoint URL: https://oidc.op1.openshiftapps.com/2du11g36ejmoo4624pofphlrgf4r9tf3 (Managed) Etcd Encryption: Disabled Audit Log Forwarding: Disabled External Authentication: Disabled INFO: Preparing to create operator roles. INFO: Operator Roles already exists INFO: Preparing to create OIDC Provider. INFO: OIDC provider already exists INFO: To determine when your cluster is Ready, run 'rosa describe cluster -c kx-9b3410734d'. INFO: To watch your cluster installation logs, run 'rosa logs install -c kx-9b3410734d --watch'. INFO: Track the progress of the cluster creation... WARN: The current version (1.2.59) is not up to date with latest rosa cli released version (1.2.60). WARN: It is recommended that you update to the latest version. W: Region flag will be removed from this command in future versions INFO: Cluster 'kx-9b3410734d' is in waiting state waiting for installation to begin. Logs will show up within 5 minutes 0001-01-01 00:00:00 +0000 UTC hostedclusters kx-9b3410734d Version 2026-01-23 17:31:11 +0000 UTC hostedclusters kx-9b3410734d ValidAWSIdentityProvider StatusUnknown 2026-01-23 17:31:12 +0000 UTC hostedclusters kx-9b3410734d The hosted control plane is not found 2026-01-23 17:31:12 +0000 UTC hostedclusters kx-9b3410734d Condition not found in the CVO. 2026-01-23 17:31:12 +0000 UTC hostedclusters kx-9b3410734d The hosted control plane is not found 2026-01-23 17:31:12 +0000 UTC hostedclusters kx-9b3410734d The hosted control plane is not found 2026-01-23 17:31:12 +0000 UTC hostedclusters kx-9b3410734d ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-01-23 17:31:12 +0000 UTC hostedclusters kx-9b3410734d The hosted control plane is not found 2026-01-23 17:31:12 +0000 UTC hostedclusters kx-9b3410734d The hosted control plane is not found 2026-01-23 17:31:12 +0000 UTC hostedclusters kx-9b3410734d Condition not found in the CVO. 2026-01-23 17:31:12 +0000 UTC hostedclusters kx-9b3410734d Condition not found in the CVO. 2026-01-23 17:31:12 +0000 UTC hostedclusters kx-9b3410734d Ignition server deployment not found 2026-01-23 17:31:12 +0000 UTC hostedclusters kx-9b3410734d The hosted control plane is not found 2026-01-23 17:31:12 +0000 UTC hostedclusters kx-9b3410734d Condition not found in the CVO. 2026-01-23 17:31:12 +0000 UTC hostedclusters kx-9b3410734d Condition not found in the CVO. 2026-01-23 17:31:12 +0000 UTC hostedclusters kx-9b3410734d NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-01-23 17:31:12 +0000 UTC hostedclusters kx-9b3410734d HostedCluster is supported by operator configuration 2026-01-23 17:31:12 +0000 UTC hostedclusters kx-9b3410734d Release image is valid 2026-01-23 17:31:12 +0000 UTC hostedclusters kx-9b3410734d The hosted control plane is not found 2026-01-23 17:31:12 +0000 UTC hostedclusters kx-9b3410734d Reconciliation active on resource 2026-01-23 17:31:12 +0000 UTC hostedclusters kx-9b3410734d configuration is invalid: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-01-23 17:31:12 +0000 UTC hostedclusters kx-9b3410734d ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-01-23 17:31:12 +0000 UTC certificates cluster-api-cert Issuing certificate as Secret does not exist 2026-01-23 17:31:12 +0000 UTC certificates cluster-api-cert Issuing certificate as Secret does not exist 2026-01-23 17:31:12 +0000 UTC certificates cluster-api-cert Issuing certificate as Secret does not exist 2026-01-23 17:31:12 +0000 UTC certificates cluster-api-cert Issuing certificate as Secret does not exist 2026-01-23 17:31:12 +0000 UTC certificates cluster-api-cert Issuing certificate as Secret does not exist 0001-01-01 00:00:00 +0000 UTC hostedclusters kx-9b3410734d Version 2026-01-23 17:31:11 +0000 UTC hostedclusters kx-9b3410734d ValidAWSIdentityProvider StatusUnknown 2026-01-23 17:31:12 +0000 UTC hostedclusters kx-9b3410734d Release image is valid 2026-01-23 17:31:12 +0000 UTC hostedclusters kx-9b3410734d Condition not found in the HCP 2026-01-23 17:31:12 +0000 UTC hostedclusters kx-9b3410734d HostedCluster is at expected version 2026-01-23 17:31:12 +0000 UTC hostedclusters kx-9b3410734d Reconciliation active on resource 2026-01-23 17:31:12 +0000 UTC hostedclusters kx-9b3410734d Ignition server deployment not found 2026-01-23 17:31:12 +0000 UTC hostedclusters kx-9b3410734d HostedCluster is supported by operator configuration 2026-01-23 17:31:12 +0000 UTC hostedclusters kx-9b3410734d Condition not found in the CVO. 2026-01-23 17:31:12 +0000 UTC hostedclusters kx-9b3410734d Condition not found in the CVO. 2026-01-23 17:31:12 +0000 UTC hostedclusters kx-9b3410734d Condition not found in the CVO. 2026-01-23 17:31:12 +0000 UTC hostedclusters kx-9b3410734d Condition not found in the CVO. 2026-01-23 17:31:12 +0000 UTC hostedclusters kx-9b3410734d router load balancer is not provisioned; 9s since creation.; private-router load balancer is not provisioned; 10s since creation.; router load balancer is not provisioned; 9s since creation. 2026-01-23 17:31:12 +0000 UTC hostedclusters kx-9b3410734d Condition not found in the CVO. 2026-01-23 17:32:42 +0000 UTC certificates cluster-api-cert Certificate is up to date and has not expired 2026-01-23 17:32:44 +0000 UTC hostedclusters kx-9b3410734d Configuration passes validation 2026-01-23 17:32:44 +0000 UTC hostedclusters kx-9b3410734d Required platform credentials are found 2026-01-23 17:32:47 +0000 UTC hostedclusters kx-9b3410734d router load balancer is not provisioned; 9s since creation.; private-router load balancer is not provisioned; 10s since creation.; router load balancer is not provisioned; 9s since creation. 2026-01-23 17:32:47 +0000 UTC hostedclusters kx-9b3410734d lookup api.kx-9b3410734d.fnn9.p3.openshiftapps.com on 172.30.0.10:53: no such host 2026-01-23 17:32:47 +0000 UTC hostedclusters kx-9b3410734d Configuration passes validation 2026-01-23 17:32:47 +0000 UTC hostedclusters kx-9b3410734d capi-provider deployment has 1 unavailable replicas 2026-01-23 17:32:47 +0000 UTC hostedclusters kx-9b3410734d AWS KMS is not configured 2026-01-23 17:32:47 +0000 UTC hostedclusters kx-9b3410734d EtcdAvailable StatefulSetNotFound 2026-01-23 17:32:47 +0000 UTC hostedclusters kx-9b3410734d Kube APIServer deployment not found 2026-01-23 17:32:48 +0000 UTC hostedclusters kx-9b3410734d OIDC configuration is valid 2026-01-23 17:32:48 +0000 UTC hostedclusters kx-9b3410734d Reconciliation completed successfully 2026-01-23 17:33:16 +0000 UTC hostedclusters kx-9b3410734d WebIdentityErr 2026-01-23 17:33:25 +0000 UTC hostedclusters kx-9b3410734d All is well 2026-01-23 17:33:40 +0000 UTC hostedclusters kx-9b3410734d All is well 2026-01-23 17:34:00 +0000 UTC hostedclusters kx-9b3410734d EtcdAvailable QuorumAvailable 2026-01-23 17:34:29 +0000 UTC hostedclusters kx-9b3410734d Kube APIServer deployment is available 2026-01-23 17:34:46 +0000 UTC hostedclusters kx-9b3410734d All is well 2026-01-23 17:34:56 +0000 UTC hostedclusters kx-9b3410734d All is well 2026-01-23 17:35:07 +0000 UTC hostedclusters kx-9b3410734d Condition not found in the CVO. 2026-01-23 17:35:07 +0000 UTC hostedclusters kx-9b3410734d Payload loaded version="4.17.46" image="quay.io/openshift-release-dev/ocp-release@sha256:3a6c78bb8f3098e7a6f08eacd30af9ab2ca8a4d2a739c614ad942a2c40b88dd8" architecture="Multi" 2026-01-23 17:35:07 +0000 UTC hostedclusters kx-9b3410734d ClusterVersionAvailable FromClusterVersion 2026-01-23 17:35:07 +0000 UTC hostedclusters kx-9b3410734d Unable to apply 4.17.46: an unknown error has occurred: MultipleErrors 2026-01-23 17:35:28 +0000 UTC hostedclusters kx-9b3410734d The hosted control plane is available INFO: Cluster 'kx-9b3410734d' is now ready INFO: ROSA with HCP cluster is ready, create a cluster admin account for accessing the cluster WARN: The current version (1.2.59) is not up to date with latest rosa cli released version (1.2.60). WARN: It is recommended that you update to the latest version. INFO: Storing login command... INFO: Check if it's able to login to OCP cluster... Retried 1 times... INFO: Check if apiserver is ready... Waiting for cluster operators to be accessible for 2m... NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.17.46 True False False 3m39s dns 4.17.46 False False True 3m41s DNS "default" is unavailable. image-registry False True True 3m26s Available: The deployment does not have available replicas... ingress False True True 3m25s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.17.46 True False False 3m31s kube-controller-manager 4.17.46 True False False 3m31s kube-scheduler 4.17.46 True False False 3m31s kube-storage-version-migrator monitoring network 4.17.46 True True False 3m19s DaemonSet "/openshift-multus/network-metrics-daemon" is waiting for other operators to become ready... node-tuning False True False 3m11s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.17.46 True False False 3m31s openshift-controller-manager 4.17.46 True False False 3m31s openshift-samples operator-lifecycle-manager 4.17.46 True False False 3m32s operator-lifecycle-manager-catalog 4.17.46 True False False 3m31s operator-lifecycle-manager-packageserver 4.17.46 True False False 3m31s service-ca storage 4.17.46 False False False 3m30s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service cluster operators to be accessible finished! [INFO] Cluster operators are accessible. Waiting for cluster to be reported as healthy for 60m... NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.17.46 True False False 3m40s dns 4.17.46 False False True 3m42s DNS "default" is unavailable. image-registry False True True 3m27s Available: The deployment does not have available replicas... ingress False True True 3m26s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.17.46 True False False 3m32s kube-controller-manager 4.17.46 True False False 3m32s kube-scheduler 4.17.46 True False False 3m32s kube-storage-version-migrator monitoring network 4.17.46 True True False 3m20s DaemonSet "/openshift-multus/network-metrics-daemon" is waiting for other operators to become ready... node-tuning False True False 3m12s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.17.46 True False False 3m32s openshift-controller-manager 4.17.46 True False False 3m32s openshift-samples operator-lifecycle-manager 4.17.46 True False False 3m33s operator-lifecycle-manager-catalog 4.17.46 True False False 3m32s operator-lifecycle-manager-packageserver 4.17.46 True False False 3m32s service-ca storage 4.17.46 False False False 3m31s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.17.46 True False False 4m40s dns 4.17.46 False False True 4m42s DNS "default" is unavailable. image-registry False True True 4m27s Available: The deployment does not have available replicas... ingress False True True 4m26s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.17.46 True False False 4m32s kube-controller-manager 4.17.46 True False False 4m32s kube-scheduler 4.17.46 True False False 4m32s kube-storage-version-migrator monitoring network 4.17.46 True True False 4m20s DaemonSet "/openshift-multus/network-metrics-daemon" is waiting for other operators to become ready... node-tuning False True False 4m12s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.17.46 True False False 4m32s openshift-controller-manager 4.17.46 True False False 4m32s openshift-samples operator-lifecycle-manager 4.17.46 True False False 4m33s operator-lifecycle-manager-catalog 4.17.46 True False False 4m32s operator-lifecycle-manager-packageserver 4.17.46 True False False 4m32s service-ca storage 4.17.46 False False False 4m31s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.17.46 True False False 5m40s dns 4.17.46 False False True 5m42s DNS "default" is unavailable. image-registry False True True 5m27s Available: The deployment does not have available replicas... ingress False True True 5m26s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights 4.17.46 True False False 8s kube-apiserver 4.17.46 True False False 5m32s kube-controller-manager 4.17.46 True False False 5m32s kube-scheduler 4.17.46 True False False 5m32s kube-storage-version-migrator 4.17.46 True False False 4s monitoring network 4.17.46 True True False 5m20s DaemonSet "/openshift-multus/network-metrics-daemon" is waiting for other operators to become ready... node-tuning 4.17.46 True False False 38s openshift-apiserver 4.17.46 True False False 5m32s openshift-controller-manager 4.17.46 True False False 5m32s openshift-samples operator-lifecycle-manager 4.17.46 True False False 5m33s operator-lifecycle-manager-catalog 4.17.46 True False False 5m32s operator-lifecycle-manager-packageserver 4.17.46 True False False 5m32s service-ca 4.17.46 True False False 5s storage 4.17.46 True False False 28s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.17.46 True False False 28s csi-snapshot-controller 4.17.46 True False False 6m40s dns 4.17.46 True False False 22s image-registry True True False 16s Progressing: The deployment has not completed... ingress 4.17.46 True False True 11s The "default" ingress controller reports Degraded=True: DegradedConditions: One or more other status conditions indicate a degraded state: CanaryChecksSucceeding=Unknown (CanaryRouteNotAdmitted: Canary route is not admitted by the default ingress controller) insights 4.17.46 True False False 68s kube-apiserver 4.17.46 True False False 6m32s kube-controller-manager 4.17.46 True False False 6m32s kube-scheduler 4.17.46 True False False 6m32s kube-storage-version-migrator 4.17.46 True False False 64s monitoring Unknown True Unknown 41s Rolling out the stack. network 4.17.46 True False False 6m20s node-tuning 4.17.46 True False False 41s openshift-apiserver 4.17.46 True False False 6m32s openshift-controller-manager 4.17.46 True False False 6m32s openshift-samples 4.17.46 True False False 9s operator-lifecycle-manager 4.17.46 True False False 6m33s operator-lifecycle-manager-catalog 4.17.46 True False False 6m32s operator-lifecycle-manager-packageserver 4.17.46 True False False 6m32s service-ca 4.17.46 True False False 65s storage 4.17.46 True False False 88s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.17.46 True False False 89s csi-snapshot-controller 4.17.46 True False False 7m41s dns 4.17.46 True False False 83s image-registry 4.17.46 True False False 77s ingress 4.17.46 True False False 72s insights 4.17.46 True False False 2m9s kube-apiserver 4.17.46 True False False 7m33s kube-controller-manager 4.17.46 True False False 7m33s kube-scheduler 4.17.46 True False False 7m33s kube-storage-version-migrator 4.17.46 True False False 2m5s monitoring Unknown True Unknown 102s Rolling out the stack. network 4.17.46 True False False 7m21s node-tuning 4.17.46 True False False 102s openshift-apiserver 4.17.46 True False False 7m33s openshift-controller-manager 4.17.46 True False False 7m33s openshift-samples 4.17.46 True False False 70s operator-lifecycle-manager 4.17.46 True False False 7m34s operator-lifecycle-manager-catalog 4.17.46 True False False 7m33s operator-lifecycle-manager-packageserver 4.17.46 True False False 7m33s service-ca 4.17.46 True False False 2m6s storage 4.17.46 True False False 2m29s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.17.46 True False False 2m29s csi-snapshot-controller 4.17.46 True False False 8m41s dns 4.17.46 True False False 2m23s image-registry 4.17.46 True False False 2m17s ingress 4.17.46 True False False 2m12s insights 4.17.46 True False False 3m9s kube-apiserver 4.17.46 True False False 8m33s kube-controller-manager 4.17.46 True False False 8m33s kube-scheduler 4.17.46 True False False 8m33s kube-storage-version-migrator 4.17.46 True False False 3m5s monitoring 4.17.46 True False False 40s network 4.17.46 True False False 8m21s node-tuning 4.17.46 True False False 2m42s openshift-apiserver 4.17.46 True False False 8m33s openshift-controller-manager 4.17.46 True False False 8m33s openshift-samples 4.17.46 True False False 2m10s operator-lifecycle-manager 4.17.46 True False False 8m34s operator-lifecycle-manager-catalog 4.17.46 True False False 8m33s operator-lifecycle-manager-packageserver 4.17.46 True False False 8m33s service-ca 4.17.46 True False False 3m6s storage 4.17.46 True False False 3m29s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.17.46 True False False 3m29s csi-snapshot-controller 4.17.46 True False False 9m41s dns 4.17.46 True False False 3m23s image-registry 4.17.46 True False False 3m17s ingress 4.17.46 True False False 3m12s insights 4.17.46 True False False 4m9s kube-apiserver 4.17.46 True False False 9m33s kube-controller-manager 4.17.46 True False False 9m33s kube-scheduler 4.17.46 True False False 9m33s kube-storage-version-migrator 4.17.46 True False False 4m5s monitoring 4.17.46 True False False 100s network 4.17.46 True False False 9m21s node-tuning 4.17.46 True False False 3m42s openshift-apiserver 4.17.46 True False False 9m33s openshift-controller-manager 4.17.46 True False False 9m33s openshift-samples 4.17.46 True False False 3m10s operator-lifecycle-manager 4.17.46 True False False 9m34s operator-lifecycle-manager-catalog 4.17.46 True False False 9m33s operator-lifecycle-manager-packageserver 4.17.46 True False False 9m33s service-ca 4.17.46 True False False 4m6s storage 4.17.46 True False False 4m29s Waiting for cluster to be reported as healthy... Trying again in 60s healthy cluster to be reported as healthy finished!