INFO: Log in to your Red Hat account... INFO: Configure AWS Credentials... WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. INFO: Logged in as 'konflux-ci-418295695583' on 'https://api.openshift.com' INFO: Create ROSA with HCP cluster... WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. INFO: Creating cluster 'kx-1d256ecf0d' INFO: To view a list of clusters and their status, run 'rosa list clusters' INFO: Cluster 'kx-1d256ecf0d' has been created. INFO: Once the cluster is installed you will need to add an Identity Provider before you can login into the cluster. See 'rosa create idp --help' for more information. Name: kx-1d256ecf0d Domain Prefix: kx-1d256ecf0d Display Name: kx-1d256ecf0d ID: 2lv382d3v3crja5qk1le5bjb21dbbioc External ID: f7f7d351-7c04-40aa-b97a-d2adc448afd6 Control Plane: ROSA Service Hosted OpenShift Version: 4.17.41 Channel Group: stable DNS: Not ready AWS Account: 418295695583 AWS Billing Account: 418295695583 API URL: Console URL: Region: us-east-1 Availability: - Control Plane: MultiAZ - Data Plane: MultiAZ Nodes: - Compute (desired): 3 - Compute (current): 0 Network: - Type: OVNKubernetes - Service CIDR: 172.30.0.0/16 - Machine CIDR: 10.0.0.0/16 - Pod CIDR: 10.128.0.0/14 - Host Prefix: /23 - Subnets: subnet-001fc23497e4a3aeb, subnet-00ffba09365a434bc, subnet-074cbf0329958194a, subnet-0689cd077699b690a, subnet-0f9f09e46f74cde64, subnet-033f48892ddbaa09d EC2 Metadata Http Tokens: optional Role (STS) ARN: arn:aws:iam::418295695583:role/ManagedOpenShift-HCP-ROSA-Installer-Role Support Role ARN: arn:aws:iam::418295695583:role/ManagedOpenShift-HCP-ROSA-Support-Role Instance IAM Roles: - Worker: arn:aws:iam::418295695583:role/ManagedOpenShift-HCP-ROSA-Worker-Role Operator IAM Roles: - arn:aws:iam::418295695583:role/rosa-hcp-openshift-cloud-network-config-controller-cloud-credent - arn:aws:iam::418295695583:role/rosa-hcp-kube-system-kms-provider - arn:aws:iam::418295695583:role/rosa-hcp-kube-system-kube-controller-manager - arn:aws:iam::418295695583:role/rosa-hcp-kube-system-capa-controller-manager - arn:aws:iam::418295695583:role/rosa-hcp-kube-system-control-plane-operator - arn:aws:iam::418295695583:role/rosa-hcp-openshift-image-registry-installer-cloud-credentials - arn:aws:iam::418295695583:role/rosa-hcp-openshift-ingress-operator-cloud-credentials - arn:aws:iam::418295695583:role/rosa-hcp-openshift-cluster-csi-drivers-ebs-cloud-credentials Managed Policies: Yes State: waiting (Waiting for user action) Private: No Delete Protection: Disabled Created: Oct 16 2025 05:26:36 UTC [DEPRECATED] User Workload Monitoring: Enabled Details Page: https://console.redhat.com/openshift/details/s/348Po1NmUaAzdoxJEVQy0x4Ty82 OIDC Endpoint URL: https://oidc.op1.openshiftapps.com/2du11g36ejmoo4624pofphlrgf4r9tf3 (Managed) Etcd Encryption: Disabled Audit Log Forwarding: Disabled External Authentication: Disabled Zero Egress: Disabled INFO: Preparing to create operator roles. INFO: Operator Roles already exists INFO: Preparing to create OIDC Provider. INFO: OIDC provider already exists INFO: To determine when your cluster is Ready, run 'rosa describe cluster -c kx-1d256ecf0d'. INFO: To watch your cluster installation logs, run 'rosa logs install -c kx-1d256ecf0d --watch'. INFO: Track the progress of the cluster creation... WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. W: Region flag will be removed from this command in future versions INFO: Cluster 'kx-1d256ecf0d' is in waiting state waiting for installation to begin. Logs will show up within 5 minutes 0001-01-01 00:00:00 +0000 UTC hostedclusters kx-1d256ecf0d Version 2025-10-16 05:30:30 +0000 UTC hostedclusters kx-1d256ecf0d ValidAWSIdentityProvider StatusUnknown 2025-10-16 05:30:31 +0000 UTC certificates cluster-api-cert Issuing certificate as Secret does not exist 2025-10-16 05:30:31 +0000 UTC certificates cluster-api-cert Issuing certificate as Secret does not exist 2025-10-16 05:30:35 +0000 UTC hostedclusters kx-1d256ecf0d The hosted control plane is not found 2025-10-16 05:30:35 +0000 UTC hostedclusters kx-1d256ecf0d Condition not found in the CVO. 2025-10-16 05:30:35 +0000 UTC hostedclusters kx-1d256ecf0d ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-10-16 05:30:35 +0000 UTC hostedclusters kx-1d256ecf0d The hosted control plane is not found 2025-10-16 05:30:35 +0000 UTC hostedclusters kx-1d256ecf0d The hosted control plane is not found 2025-10-16 05:30:35 +0000 UTC hostedclusters kx-1d256ecf0d Condition not found in the CVO. 2025-10-16 05:30:35 +0000 UTC hostedclusters kx-1d256ecf0d Condition not found in the CVO. 2025-10-16 05:30:35 +0000 UTC hostedclusters kx-1d256ecf0d Condition not found in the CVO. 2025-10-16 05:30:35 +0000 UTC hostedclusters kx-1d256ecf0d Condition not found in the CVO. 2025-10-16 05:30:35 +0000 UTC hostedclusters kx-1d256ecf0d The hosted control plane is not found 2025-10-16 05:30:35 +0000 UTC hostedclusters kx-1d256ecf0d Ignition server deployment not found 2025-10-16 05:30:35 +0000 UTC hostedclusters kx-1d256ecf0d NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-10-16 05:30:35 +0000 UTC hostedclusters kx-1d256ecf0d HostedCluster is supported by operator configuration 2025-10-16 05:30:35 +0000 UTC hostedclusters kx-1d256ecf0d Release image is valid 2025-10-16 05:30:35 +0000 UTC hostedclusters kx-1d256ecf0d The hosted control plane is not found 2025-10-16 05:30:35 +0000 UTC hostedclusters kx-1d256ecf0d Reconciliation active on resource 2025-10-16 05:30:35 +0000 UTC hostedclusters kx-1d256ecf0d The hosted control plane is not found 2025-10-16 05:30:35 +0000 UTC hostedclusters kx-1d256ecf0d The hosted control plane is not found 2025-10-16 05:30:36 +0000 UTC hostedclusters kx-1d256ecf0d configuration is invalid: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-10-16 05:30:36 +0000 UTC hostedclusters kx-1d256ecf0d ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-10-16 05:32:04 +0000 UTC certificates cluster-api-cert Certificate is up to date and has not expired 2025-10-16 05:32:24 +0000 UTC hostedclusters kx-1d256ecf0d Configuration passes validation 2025-10-16 05:32:27 +0000 UTC hostedclusters kx-1d256ecf0d Required platform credentials are found 2025-10-16 05:32:30 +0000 UTC hostedclusters kx-1d256ecf0d OIDC configuration is valid 2025-10-16 05:32:30 +0000 UTC hostedclusters kx-1d256ecf0d Reconciliation completed successfully 2025-10-16 05:32:36 +0000 UTC hostedclusters kx-1d256ecf0d AWS KMS is not configured 2025-10-16 05:32:36 +0000 UTC hostedclusters kx-1d256ecf0d capi-provider deployment has 2 unavailable replicas 2025-10-16 05:32:36 +0000 UTC hostedclusters kx-1d256ecf0d lookup api.kx-1d256ecf0d.m40g.p3.openshiftapps.com on 172.30.0.10:53: no such host 2025-10-16 05:32:36 +0000 UTC hostedclusters kx-1d256ecf0d Configuration passes validation 2025-10-16 05:32:36 +0000 UTC hostedclusters kx-1d256ecf0d Waiting for etcd to reach quorum 2025-10-16 05:32:36 +0000 UTC hostedclusters kx-1d256ecf0d Kube APIServer deployment not found 2025-10-16 05:32:58 +0000 UTC hostedclusters kx-1d256ecf0d All is well 2025-10-16 05:32:59 +0000 UTC hostedclusters kx-1d256ecf0d All is well 2025-10-16 05:33:05 +0000 UTC hostedclusters kx-1d256ecf0d WebIdentityErr 2025-10-16 05:33:25 +0000 UTC hostedclusters kx-1d256ecf0d EtcdAvailable QuorumAvailable 2025-10-16 05:43:22 +0000 UTC hostedclusters kx-1d256ecf0d Kube APIServer deployment is available 2025-10-16 05:43:36 +0000 UTC hostedclusters kx-1d256ecf0d All is well 2025-10-16 05:45:27 +0000 UTC hostedclusters kx-1d256ecf0d All is well 2025-10-16 05:45:32 +0000 UTC hostedclusters kx-1d256ecf0d The hosted control plane is available INFO: Cluster 'kx-1d256ecf0d' is now ready INFO: ROSA with HCP cluster is ready, create a cluster admin account for accessing the cluster WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. INFO: Storing login command... INFO: Check if it's able to login to OCP cluster... Retried 1 times... INFO: Check if apiserver is ready... Waiting for cluster operators to be accessible for 2m... NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.17.41 True False False 2m10s dns 4.17.41 False False True 2m9s DNS "default" is unavailable. image-registry False True True 118s Available: The deployment does not have available replicas... ingress False True True 113s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.17.41 True False False 2m2s kube-controller-manager 4.17.41 True False False 2m2s kube-scheduler 4.17.41 True False False 2m2s kube-storage-version-migrator monitoring network 4.17.41 True True False 99s DaemonSet "/openshift-network-operator/iptables-alerter" is waiting for other operators to become ready... node-tuning False True False 2m DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.17.41 True False False 2m2s openshift-controller-manager 4.17.41 True False False 2m2s openshift-samples operator-lifecycle-manager 4.17.41 True False False 2m4s operator-lifecycle-manager-catalog 4.17.41 True False False 115s operator-lifecycle-manager-packageserver 4.17.41 True False False 2m2s service-ca storage 4.17.41 False False False 2m2s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service cluster operators to be accessible finished! [INFO] Cluster operators are accessible. Waiting for cluster to be reported as healthy for 60m... NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.17.41 True False False 2m10s dns 4.17.41 False False True 2m9s DNS "default" is unavailable. image-registry False True True 118s Available: The deployment does not have available replicas... ingress False True True 113s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.17.41 True False False 2m2s kube-controller-manager 4.17.41 True False False 2m2s kube-scheduler 4.17.41 True False False 2m2s kube-storage-version-migrator monitoring network 4.17.41 True True False 99s DaemonSet "/openshift-network-operator/iptables-alerter" is waiting for other operators to become ready... node-tuning False True False 2m DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.17.41 True False False 2m2s openshift-controller-manager 4.17.41 True False False 2m2s openshift-samples operator-lifecycle-manager 4.17.41 True False False 2m4s operator-lifecycle-manager-catalog 4.17.41 True False False 115s operator-lifecycle-manager-packageserver 4.17.41 True False False 2m2s service-ca storage 4.17.41 False False False 2m2s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.17.41 True False False 3m11s dns 4.17.41 False False True 3m10s DNS "default" is unavailable. image-registry False True True 2m59s Available: The deployment does not have available replicas... ingress False True True 2m54s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.17.41 True False False 3m3s kube-controller-manager 4.17.41 True False False 3m3s kube-scheduler 4.17.41 True False False 3m3s kube-storage-version-migrator monitoring network 4.17.41 True True False 2m40s DaemonSet "/openshift-network-operator/iptables-alerter" is waiting for other operators to become ready... node-tuning False True False 3m1s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.17.41 True False False 3m3s openshift-controller-manager 4.17.41 True False False 3m3s openshift-samples operator-lifecycle-manager 4.17.41 True False False 3m5s operator-lifecycle-manager-catalog 4.17.41 True False False 2m56s operator-lifecycle-manager-packageserver 4.17.41 True False False 3m3s service-ca storage 4.17.41 False False False 3m3s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.17.41 True False False 4m11s dns 4.17.41 False False True 4m10s DNS "default" is unavailable. image-registry False True True 3m59s Available: The deployment does not have available replicas... ingress False True True 3m54s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.17.41 True False False 4m3s kube-controller-manager 4.17.41 True False False 4m3s kube-scheduler 4.17.41 True False False 4m3s kube-storage-version-migrator monitoring network 4.17.41 True True False 3m40s DaemonSet "/openshift-network-operator/iptables-alerter" is waiting for other operators to become ready... node-tuning False True False 4m1s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.17.41 True False False 4m3s openshift-controller-manager 4.17.41 True False False 4m3s openshift-samples operator-lifecycle-manager 4.17.41 True False False 4m5s operator-lifecycle-manager-catalog 4.17.41 True False False 3m56s operator-lifecycle-manager-packageserver 4.17.41 True False False 4m3s service-ca storage 4.17.41 False False False 4m3s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.17.41 True False False 5m11s dns 4.17.41 False False True 5m10s DNS "default" is unavailable. image-registry False True True 4m59s Available: The deployment does not have available replicas... ingress False True True 4m54s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.17.41 True False False 5m3s kube-controller-manager 4.17.41 True False False 5m3s kube-scheduler 4.17.41 True False False 5m3s kube-storage-version-migrator monitoring network 4.17.41 True True False 4m40s DaemonSet "/openshift-multus/network-metrics-daemon" is waiting for other operators to become ready... node-tuning 4.17.41 True True False 13s Waiting for 1/2 Profiles to be applied openshift-apiserver 4.17.41 True False False 5m3s openshift-controller-manager 4.17.41 True False False 5m3s openshift-samples operator-lifecycle-manager 4.17.41 True False False 5m5s operator-lifecycle-manager-catalog 4.17.41 True False False 4m56s operator-lifecycle-manager-packageserver 4.17.41 True False False 5m3s service-ca storage 4.17.41 True True False 32s AWSEBSCSIDriverOperatorCRProgressing: AWSEBSDriverNodeServiceControllerProgressing: Waiting for DaemonSet to deploy node pods Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.17.41 Unknown False False 16s csi-snapshot-controller 4.17.41 True False False 6m11s dns 4.17.41 True True False 19s DNS "default" reports Progressing=True: "Have 1 available DNS pods, want 2.\nHave 2 available node-resolver pods, want 3." image-registry True True False 16s Progressing: The deployment has not completed... ingress False True True 5m54s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights 4.17.41 True False False 57s kube-apiserver 4.17.41 True False False 6m3s kube-controller-manager 4.17.41 True False False 6m3s kube-scheduler 4.17.41 True False False 6m3s kube-storage-version-migrator 4.17.41 True False False 54s monitoring Unknown True Unknown 28s Rolling out the stack. network 4.17.41 True True False 5m40s DaemonSet "/openshift-multus/multus" is not available (awaiting 1 nodes)... node-tuning 4.17.41 True True False 24s Waiting for 1/3 Profiles to be applied openshift-apiserver 4.17.41 True False False 6m3s openshift-controller-manager 4.17.41 True False False 6m3s openshift-samples 4.17.41 True False False 12s operator-lifecycle-manager 4.17.41 True False False 6m5s operator-lifecycle-manager-catalog 4.17.41 True False False 5m56s operator-lifecycle-manager-packageserver 4.17.41 True False False 6m3s service-ca 4.17.41 True False False 53s storage 4.17.41 True True False 92s AWSEBSCSIDriverOperatorCRProgressing: AWSEBSDriverNodeServiceControllerProgressing: Waiting for DaemonSet to deploy node pods Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.17.41 True False False 43s csi-snapshot-controller 4.17.41 True False False 7m11s dns 4.17.41 True False False 79s image-registry 4.17.41 True False False 76s ingress 4.17.41 True False False 57s insights 4.17.41 True False False 117s kube-apiserver 4.17.41 True False False 7m3s kube-controller-manager 4.17.41 True False False 7m3s kube-scheduler 4.17.41 True False False 7m3s kube-storage-version-migrator 4.17.41 True False False 114s monitoring Unknown True Unknown 88s Rolling out the stack. network 4.17.41 True False False 6m40s node-tuning 4.17.41 True False False 84s openshift-apiserver 4.17.41 True False False 7m3s openshift-controller-manager 4.17.41 True False False 7m3s openshift-samples 4.17.41 True False False 72s operator-lifecycle-manager 4.17.41 True False False 7m5s operator-lifecycle-manager-catalog 4.17.41 True False False 6m56s operator-lifecycle-manager-packageserver 4.17.41 True False False 7m3s service-ca 4.17.41 True False False 113s storage 4.17.41 True False False 2m32s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.17.41 True False False 104s csi-snapshot-controller 4.17.41 True False False 8m12s dns 4.17.41 True False False 2m20s image-registry 4.17.41 True False False 2m17s ingress 4.17.41 True False False 118s insights 4.17.41 True False False 2m58s kube-apiserver 4.17.41 True False False 8m4s kube-controller-manager 4.17.41 True False False 8m4s kube-scheduler 4.17.41 True False False 8m4s kube-storage-version-migrator 4.17.41 True False False 2m55s monitoring Unknown True Unknown 2m29s Rolling out the stack. network 4.17.41 True False False 7m41s node-tuning 4.17.41 True False False 2m25s openshift-apiserver 4.17.41 True False False 8m4s openshift-controller-manager 4.17.41 True False False 8m4s openshift-samples 4.17.41 True False False 2m13s operator-lifecycle-manager 4.17.41 True False False 8m6s operator-lifecycle-manager-catalog 4.17.41 True False False 7m57s operator-lifecycle-manager-packageserver 4.17.41 True False False 8m4s service-ca 4.17.41 True False False 2m54s storage 4.17.41 True False False 3m33s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.17.41 True False False 2m44s csi-snapshot-controller 4.17.41 True False False 9m12s dns 4.17.41 True False False 3m20s image-registry 4.17.41 True False False 3m17s ingress 4.17.41 True False False 2m58s insights 4.17.41 True False False 3m58s kube-apiserver 4.17.41 True False False 9m4s kube-controller-manager 4.17.41 True False False 9m4s kube-scheduler 4.17.41 True False False 9m4s kube-storage-version-migrator 4.17.41 True False False 3m55s monitoring Unknown True Unknown 3m29s Rolling out the stack. network 4.17.41 True False False 8m41s node-tuning 4.17.41 True False False 3m25s openshift-apiserver 4.17.41 True False False 9m4s openshift-controller-manager 4.17.41 True False False 9m4s openshift-samples 4.17.41 True False False 3m13s operator-lifecycle-manager 4.17.41 True False False 9m6s operator-lifecycle-manager-catalog 4.17.41 True False False 8m57s operator-lifecycle-manager-packageserver 4.17.41 True False False 9m4s service-ca 4.17.41 True False False 3m54s storage 4.17.41 True False False 4m33s Waiting for cluster to be reported as healthy... Trying again in 60s healthy cluster to be reported as healthy finished!