INFO: Log in to your Red Hat account... INFO: Configure AWS Credentials... WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. INFO: Logged in as 'konflux-ci-418295695583' on 'https://api.openshift.com' INFO: Create ROSA with HCP cluster... WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. INFO: Creating cluster 'kx-b2a4a8a201' INFO: To view a list of clusters and their status, run 'rosa list clusters' INFO: Cluster 'kx-b2a4a8a201' has been created. INFO: Once the cluster is installed you will need to add an Identity Provider before you can login into the cluster. See 'rosa create idp --help' for more information. Name: kx-b2a4a8a201 Domain Prefix: kx-b2a4a8a201 Display Name: kx-b2a4a8a201 ID: 2mctqcriao5hfcvh5m291mfo3h4ardul External ID: 3150cda1-a69c-4f0a-8c97-2cc2f389d54f Control Plane: ROSA Service Hosted OpenShift Version: 4.17.42 Channel Group: stable DNS: Not ready AWS Account: 418295695583 AWS Billing Account: 418295695583 API URL: Console URL: Region: us-east-1 Availability: - Control Plane: MultiAZ - Data Plane: MultiAZ Nodes: - Compute (desired): 3 - Compute (current): 0 Network: - Type: OVNKubernetes - Service CIDR: 172.30.0.0/16 - Machine CIDR: 10.0.0.0/16 - Pod CIDR: 10.128.0.0/14 - Host Prefix: /23 - Subnets: subnet-001fc23497e4a3aeb, subnet-00ffba09365a434bc, subnet-074cbf0329958194a, subnet-0689cd077699b690a, subnet-0f9f09e46f74cde64, subnet-033f48892ddbaa09d EC2 Metadata Http Tokens: optional Role (STS) ARN: arn:aws:iam::418295695583:role/ManagedOpenShift-HCP-ROSA-Installer-Role Support Role ARN: arn:aws:iam::418295695583:role/ManagedOpenShift-HCP-ROSA-Support-Role Instance IAM Roles: - Worker: arn:aws:iam::418295695583:role/ManagedOpenShift-HCP-ROSA-Worker-Role Operator IAM Roles: - arn:aws:iam::418295695583:role/rosa-hcp-kube-system-kube-controller-manager - arn:aws:iam::418295695583:role/rosa-hcp-kube-system-capa-controller-manager - arn:aws:iam::418295695583:role/rosa-hcp-kube-system-control-plane-operator - arn:aws:iam::418295695583:role/rosa-hcp-kube-system-kms-provider - arn:aws:iam::418295695583:role/rosa-hcp-openshift-cluster-csi-drivers-ebs-cloud-credentials - arn:aws:iam::418295695583:role/rosa-hcp-openshift-cloud-network-config-controller-cloud-credent - arn:aws:iam::418295695583:role/rosa-hcp-openshift-image-registry-installer-cloud-credentials - arn:aws:iam::418295695583:role/rosa-hcp-openshift-ingress-operator-cloud-credentials Managed Policies: Yes State: waiting (Waiting for user action) Private: No Delete Protection: Disabled Created: Nov 6 2025 04:59:35 UTC [DEPRECATED] User Workload Monitoring: Enabled Details Page: https://console.redhat.com/openshift/details/s/355g6rhnyVyzYd0c2BLPPQgKHsD OIDC Endpoint URL: https://oidc.op1.openshiftapps.com/2du11g36ejmoo4624pofphlrgf4r9tf3 (Managed) Etcd Encryption: Disabled Audit Log Forwarding: Disabled External Authentication: Disabled Zero Egress: Disabled INFO: Preparing to create operator roles. INFO: Operator Roles already exists INFO: Preparing to create OIDC Provider. INFO: OIDC provider already exists INFO: To determine when your cluster is Ready, run 'rosa describe cluster -c kx-b2a4a8a201'. INFO: To watch your cluster installation logs, run 'rosa logs install -c kx-b2a4a8a201 --watch'. INFO: Track the progress of the cluster creation... WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. W: Region flag will be removed from this command in future versions INFO: Cluster 'kx-b2a4a8a201' is in waiting state waiting for installation to begin. Logs will show up within 5 minutes 0001-01-01 00:00:00 +0000 UTC hostedclusters kx-b2a4a8a201 Version 2025-11-06 05:04:18 +0000 UTC hostedclusters kx-b2a4a8a201 ValidAWSIdentityProvider StatusUnknown 2025-11-06 05:04:19 +0000 UTC certificates cluster-api-cert Issuing certificate as Secret does not exist 2025-11-06 05:04:19 +0000 UTC certificates cluster-api-cert Issuing certificate as Secret does not exist 2025-11-06 05:04:20 +0000 UTC hostedclusters kx-b2a4a8a201 The hosted control plane is not found 2025-11-06 05:04:20 +0000 UTC hostedclusters kx-b2a4a8a201 Condition not found in the CVO. 2025-11-06 05:04:20 +0000 UTC hostedclusters kx-b2a4a8a201 ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-11-06 05:04:20 +0000 UTC hostedclusters kx-b2a4a8a201 The hosted control plane is not found 2025-11-06 05:04:20 +0000 UTC hostedclusters kx-b2a4a8a201 The hosted control plane is not found 2025-11-06 05:04:20 +0000 UTC hostedclusters kx-b2a4a8a201 Condition not found in the CVO. 2025-11-06 05:04:20 +0000 UTC hostedclusters kx-b2a4a8a201 Condition not found in the CVO. 2025-11-06 05:04:20 +0000 UTC hostedclusters kx-b2a4a8a201 Condition not found in the CVO. 2025-11-06 05:04:20 +0000 UTC hostedclusters kx-b2a4a8a201 Condition not found in the CVO. 2025-11-06 05:04:20 +0000 UTC hostedclusters kx-b2a4a8a201 The hosted control plane is not found 2025-11-06 05:04:20 +0000 UTC hostedclusters kx-b2a4a8a201 Ignition server deployment not found 2025-11-06 05:04:20 +0000 UTC hostedclusters kx-b2a4a8a201 NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-11-06 05:04:20 +0000 UTC hostedclusters kx-b2a4a8a201 HostedCluster is supported by operator configuration 2025-11-06 05:04:20 +0000 UTC hostedclusters kx-b2a4a8a201 Release image is valid 2025-11-06 05:04:20 +0000 UTC hostedclusters kx-b2a4a8a201 The hosted control plane is not found 2025-11-06 05:04:20 +0000 UTC hostedclusters kx-b2a4a8a201 Reconciliation active on resource 2025-11-06 05:04:20 +0000 UTC hostedclusters kx-b2a4a8a201 The hosted control plane is not found 2025-11-06 05:04:20 +0000 UTC hostedclusters kx-b2a4a8a201 The hosted control plane is not found 2025-11-06 05:04:21 +0000 UTC hostedclusters kx-b2a4a8a201 configuration is invalid: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-11-06 05:04:21 +0000 UTC hostedclusters kx-b2a4a8a201 ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 0001-01-01 00:00:00 +0000 UTC hostedclusters kx-b2a4a8a201 Version 2025-11-06 05:04:20 +0000 UTC hostedclusters kx-b2a4a8a201 Release image is valid 2025-11-06 05:04:20 +0000 UTC hostedclusters kx-b2a4a8a201 Waiting for Kube APIServer deployment to become available 2025-11-06 05:04:20 +0000 UTC hostedclusters kx-b2a4a8a201 Reconciliation active on resource 2025-11-06 05:04:20 +0000 UTC hostedclusters kx-b2a4a8a201 HostedCluster is supported by operator configuration 2025-11-06 05:04:20 +0000 UTC hostedclusters kx-b2a4a8a201 Ignition server deployment not found 2025-11-06 05:04:20 +0000 UTC hostedclusters kx-b2a4a8a201 Condition not found in the CVO. 2025-11-06 05:04:20 +0000 UTC hostedclusters kx-b2a4a8a201 Condition not found in the CVO. 2025-11-06 05:04:20 +0000 UTC hostedclusters kx-b2a4a8a201 Condition not found in the CVO. 2025-11-06 05:04:20 +0000 UTC hostedclusters kx-b2a4a8a201 Condition not found in the CVO. 2025-11-06 05:04:20 +0000 UTC hostedclusters kx-b2a4a8a201 Condition not found in the CVO. 2025-11-06 05:04:21 +0000 UTC hostedclusters kx-b2a4a8a201 HostedCluster is at expected version 2025-11-06 05:05:48 +0000 UTC certificates cluster-api-cert Certificate is up to date and has not expired 2025-11-06 05:05:49 +0000 UTC hostedclusters kx-b2a4a8a201 Configuration passes validation 2025-11-06 05:05:51 +0000 UTC hostedclusters kx-b2a4a8a201 Required platform credentials are found 2025-11-06 05:05:54 +0000 UTC hostedclusters kx-b2a4a8a201 AWS KMS is not configured 2025-11-06 05:05:54 +0000 UTC hostedclusters kx-b2a4a8a201 [capi-provider deployment has 1 unavailable replicas, kube-apiserver deployment has 2 unavailable replicas] 2025-11-06 05:05:54 +0000 UTC hostedclusters kx-b2a4a8a201 lookup api.kx-b2a4a8a201.4we6.p3.openshiftapps.com on 172.30.0.10:53: no such host 2025-11-06 05:05:54 +0000 UTC hostedclusters kx-b2a4a8a201 Configuration passes validation 2025-11-06 05:05:54 +0000 UTC hostedclusters kx-b2a4a8a201 Waiting for Kube APIServer deployment to become available 2025-11-06 05:05:56 +0000 UTC hostedclusters kx-b2a4a8a201 OIDC configuration is valid 2025-11-06 05:05:56 +0000 UTC hostedclusters kx-b2a4a8a201 Reconciliation completed successfully 2025-11-06 05:06:16 +0000 UTC hostedclusters kx-b2a4a8a201 All is well 2025-11-06 05:06:17 +0000 UTC hostedclusters kx-b2a4a8a201 All is well 2025-11-06 05:06:23 +0000 UTC hostedclusters kx-b2a4a8a201 WebIdentityErr 2025-11-06 05:06:35 +0000 UTC hostedclusters kx-b2a4a8a201 EtcdAvailable QuorumAvailable 2025-11-06 05:07:00 +0000 UTC hostedclusters kx-b2a4a8a201 Kube APIServer deployment is available 2025-11-06 05:07:23 +0000 UTC hostedclusters kx-b2a4a8a201 Ignition server deployment is available 2025-11-06 05:07:30 +0000 UTC hostedclusters kx-b2a4a8a201 ClusterVersionSucceeding FromClusterVersion 2025-11-06 05:07:30 +0000 UTC hostedclusters kx-b2a4a8a201 Condition not found in the CVO. 2025-11-06 05:07:30 +0000 UTC hostedclusters kx-b2a4a8a201 Payload loaded version="4.17.42" image="quay.io/openshift-release-dev/ocp-release@sha256:9b7b9909a1f064d5238f35f6e5fc9ac275a0d463a74e8c545544755d953a46d9" architecture="Multi" 2025-11-06 05:07:30 +0000 UTC hostedclusters kx-b2a4a8a201 ClusterVersionAvailable FromClusterVersion 2025-11-06 05:07:30 +0000 UTC hostedclusters kx-b2a4a8a201 Working towards 4.17.42: 370 of 621 done (59% complete) 2025-11-06 05:07:53 +0000 UTC hostedclusters kx-b2a4a8a201 All is well 2025-11-06 05:08:08 +0000 UTC hostedclusters kx-b2a4a8a201 Cluster operators console, dns, image-registry, ingress, insights, kube-storage-version-migrator, monitoring, node-tuning, openshift-samples, service-ca, storage are not available 2025-11-06 05:08:14 +0000 UTC hostedclusters kx-b2a4a8a201 lookup api.kx-b2a4a8a201.4we6.p3.openshiftapps.com on 172.30.0.10:53: no such host 2025-11-06 05:08:29 +0000 UTC hostedclusters kx-b2a4a8a201 All is well 2025-11-06 05:08:39 +0000 UTC hostedclusters kx-b2a4a8a201 The hosted cluster is not degraded 2025-11-06 05:08:58 +0000 UTC hostedclusters kx-b2a4a8a201 The hosted control plane is available INFO: Cluster 'kx-b2a4a8a201' is now ready INFO: ROSA with HCP cluster is ready, create a cluster admin account for accessing the cluster WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. INFO: Storing login command... INFO: Check if it's able to login to OCP cluster... Retried 1 times... Retried 2 times... INFO: Check if apiserver is ready... Waiting for cluster operators to be accessible for 2m... NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.17.42 True False False 5m24s dns 4.17.42 False False True 5m25s DNS "default" is unavailable. image-registry False True True 4m25s Available: The deployment does not have available replicas... ingress False True True 5m10s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.17.42 True False False 5m14s kube-controller-manager 4.17.42 True False False 5m14s kube-scheduler 4.17.42 True False False 5m14s kube-storage-version-migrator monitoring network 4.17.42 True True False 5m1s DaemonSet "/openshift-network-operator/iptables-alerter" is waiting for other operators to become ready... node-tuning False True False 4m43s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.17.42 True False False 5m14s openshift-controller-manager 4.17.42 True False False 5m14s openshift-samples operator-lifecycle-manager 4.17.42 True False False 5m17s operator-lifecycle-manager-catalog 4.17.42 True False False 5m18s operator-lifecycle-manager-packageserver 4.17.42 True False False 5m14s service-ca storage 4.17.42 False False False 5m14s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service cluster operators to be accessible finished! [INFO] Cluster operators are accessible. Waiting for cluster to be reported as healthy for 60m... Unable to connect to the server: dial tcp: lookup api.kx-b2a4a8a201.4we6.p3.openshiftapps.com on 172.30.0.10:53: no such host Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.17.42 True False False 6m25s dns 4.17.42 False True True 6m26s DNS "default" is unavailable. image-registry False True True 5m26s Available: The deployment does not have available replicas... ingress False True True 6m11s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.17.42 True False False 6m15s kube-controller-manager 4.17.42 True False False 6m15s kube-scheduler 4.17.42 True False False 6m15s kube-storage-version-migrator monitoring network 4.17.42 True True False 6m2s DaemonSet "/openshift-network-operator/iptables-alerter" is waiting for other operators to become ready... node-tuning False True False 5m44s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.17.42 True False False 6m15s openshift-controller-manager 4.17.42 True False False 6m15s openshift-samples operator-lifecycle-manager 4.17.42 True False False 6m18s operator-lifecycle-manager-catalog 4.17.42 True False False 6m19s operator-lifecycle-manager-packageserver 4.17.42 True False False 6m15s service-ca storage 4.17.42 False True False 6m15s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.17.42 Unknown False False 13s csi-snapshot-controller 4.17.42 True False False 7m25s dns 4.17.42 True False False 7s image-registry True True False 3s Progressing: The deployment has not completed... ingress False True True 7m11s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights 4.17.42 True False False 43s kube-apiserver 4.17.42 True False False 7m15s kube-controller-manager 4.17.42 True False False 7m15s kube-scheduler 4.17.42 True False False 7m15s kube-storage-version-migrator 4.17.42 True False False 16s monitoring Unknown True Unknown 14s Rolling out the stack. network 4.17.42 True False False 7m2s node-tuning 4.17.42 True False False 60s openshift-apiserver 4.17.42 True False False 7m15s openshift-controller-manager 4.17.42 True False False 7m15s openshift-samples False False False 7s SampleUpsertsPending operator-lifecycle-manager 4.17.42 True False False 7m18s operator-lifecycle-manager-catalog 4.17.42 True False False 7m19s operator-lifecycle-manager-packageserver 4.17.42 True False False 7m15s service-ca 4.17.42 True False False 41s storage 4.17.42 True False False 57s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.17.42 True False False 47s csi-snapshot-controller 4.17.42 True False False 8m25s dns 4.17.42 True False False 67s image-registry 4.17.42 True True False 63s Progressing: The deployment has not completed... ingress 4.17.42 True False False 43s insights 4.17.42 True False False 103s kube-apiserver 4.17.42 True False False 8m15s kube-controller-manager 4.17.42 True False False 8m15s kube-scheduler 4.17.42 True False False 8m15s kube-storage-version-migrator 4.17.42 True False False 76s monitoring Unknown True Unknown 74s Rolling out the stack. network 4.17.42 True False False 8m2s node-tuning 4.17.42 True False False 2m openshift-apiserver 4.17.42 True False False 8m15s openshift-controller-manager 4.17.42 True False False 8m15s openshift-samples 4.17.42 True False False 58s operator-lifecycle-manager 4.17.42 True False False 8m18s operator-lifecycle-manager-catalog 4.17.42 True False False 8m19s operator-lifecycle-manager-packageserver 4.17.42 True False False 8m15s service-ca 4.17.42 True False False 101s storage 4.17.42 True False False 117s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.17.42 True False False 107s csi-snapshot-controller 4.17.42 True False False 9m25s dns 4.17.42 True False False 2m7s image-registry 4.17.42 True False False 2m3s ingress 4.17.42 True False False 103s insights 4.17.42 True False False 2m43s kube-apiserver 4.17.42 True False False 9m15s kube-controller-manager 4.17.42 True False False 9m15s kube-scheduler 4.17.42 True False False 9m15s kube-storage-version-migrator 4.17.42 True False False 2m16s monitoring Unknown True Unknown 2m14s Rolling out the stack. network 4.17.42 True False False 9m2s node-tuning 4.17.42 True False False 3m openshift-apiserver 4.17.42 True False False 9m15s openshift-controller-manager 4.17.42 True False False 9m15s openshift-samples 4.17.42 True False False 118s operator-lifecycle-manager 4.17.42 True False False 9m18s operator-lifecycle-manager-catalog 4.17.42 True False False 9m19s operator-lifecycle-manager-packageserver 4.17.42 True False False 9m15s service-ca 4.17.42 True False False 2m41s storage 4.17.42 True False False 2m57s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.17.42 True True False 2m48s SyncLoopRefreshProgressing: working toward version 4.17.42, 1 replicas available csi-snapshot-controller 4.17.42 True False False 10m dns 4.17.42 True False False 3m8s image-registry 4.17.42 True False False 3m4s ingress 4.17.42 True False False 2m44s insights 4.17.42 True False False 3m44s kube-apiserver 4.17.42 True False False 10m kube-controller-manager 4.17.42 True False False 10m kube-scheduler 4.17.42 True False False 10m kube-storage-version-migrator 4.17.42 True False False 3m17s monitoring 4.17.42 True False False 19s network 4.17.42 True False False 10m node-tuning 4.17.42 True False False 4m1s openshift-apiserver 4.17.42 True False False 10m openshift-controller-manager 4.17.42 True False False 10m openshift-samples 4.17.42 True False False 2m59s operator-lifecycle-manager 4.17.42 True False False 10m operator-lifecycle-manager-catalog 4.17.42 True False False 10m operator-lifecycle-manager-packageserver 4.17.42 True False False 10m service-ca 4.17.42 True False False 3m42s storage 4.17.42 True False False 3m58s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.17.42 True False False 3m48s csi-snapshot-controller 4.17.42 True False False 11m dns 4.17.42 True False False 4m8s image-registry 4.17.42 True False False 4m4s ingress 4.17.42 True False False 3m44s insights 4.17.42 True False False 4m44s kube-apiserver 4.17.42 True False False 11m kube-controller-manager 4.17.42 True False False 11m kube-scheduler 4.17.42 True False False 11m kube-storage-version-migrator 4.17.42 True False False 4m17s monitoring 4.17.42 True False False 79s network 4.17.42 True False False 11m node-tuning 4.17.42 True False False 5m1s openshift-apiserver 4.17.42 True False False 11m openshift-controller-manager 4.17.42 True False False 11m openshift-samples 4.17.42 True False False 3m59s operator-lifecycle-manager 4.17.42 True False False 11m operator-lifecycle-manager-catalog 4.17.42 True False False 11m operator-lifecycle-manager-packageserver 4.17.42 True False False 11m service-ca 4.17.42 True False False 4m42s storage 4.17.42 True False False 4m58s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.17.42 True False False 4m48s csi-snapshot-controller 4.17.42 True False False 12m dns 4.17.42 True False False 5m8s image-registry 4.17.42 True False False 5m4s ingress 4.17.42 True False False 4m44s insights 4.17.42 True False False 5m44s kube-apiserver 4.17.42 True False False 12m kube-controller-manager 4.17.42 True False False 12m kube-scheduler 4.17.42 True False False 12m kube-storage-version-migrator 4.17.42 True False False 5m17s monitoring 4.17.42 True False False 2m19s network 4.17.42 True False False 12m node-tuning 4.17.42 True False False 6m1s openshift-apiserver 4.17.42 True False False 12m openshift-controller-manager 4.17.42 True False False 12m openshift-samples 4.17.42 True False False 4m59s operator-lifecycle-manager 4.17.42 True False False 12m operator-lifecycle-manager-catalog 4.17.42 True False False 12m operator-lifecycle-manager-packageserver 4.17.42 True False False 12m service-ca 4.17.42 True False False 5m42s storage 4.17.42 True False False 5m58s Waiting for cluster to be reported as healthy... Trying again in 60s healthy cluster to be reported as healthy finished!