INFO: Log in to your Red Hat account... INFO: Configure AWS Credentials... WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. INFO: Logged in as 'konflux-ci-418295695583' on 'https://api.openshift.com' INFO: Create ROSA with HCP cluster... WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. INFO: Creating cluster 'kx-83e942e860' INFO: To view a list of clusters and their status, run 'rosa list clusters' INFO: Cluster 'kx-83e942e860' has been created. INFO: Once the cluster is installed you will need to add an Identity Provider before you can login into the cluster. See 'rosa create idp --help' for more information. Name: kx-83e942e860 Domain Prefix: kx-83e942e860 Display Name: kx-83e942e860 ID: 2m8gpi9linr8durogl3k4kblelnoj9cp External ID: 15ca86c3-390f-4ef2-8ea6-8dd313fd075e Control Plane: ROSA Service Hosted OpenShift Version: 4.17.42 Channel Group: stable DNS: Not ready AWS Account: 418295695583 AWS Billing Account: 418295695583 API URL: Console URL: Region: us-east-1 Availability: - Control Plane: MultiAZ - Data Plane: MultiAZ Nodes: - Compute (desired): 3 - Compute (current): 0 Network: - Type: OVNKubernetes - Service CIDR: 172.30.0.0/16 - Machine CIDR: 10.0.0.0/16 - Pod CIDR: 10.128.0.0/14 - Host Prefix: /23 - Subnets: subnet-001fc23497e4a3aeb, subnet-00ffba09365a434bc, subnet-074cbf0329958194a, subnet-0689cd077699b690a, subnet-0f9f09e46f74cde64, subnet-033f48892ddbaa09d EC2 Metadata Http Tokens: optional Role (STS) ARN: arn:aws:iam::418295695583:role/ManagedOpenShift-HCP-ROSA-Installer-Role Support Role ARN: arn:aws:iam::418295695583:role/ManagedOpenShift-HCP-ROSA-Support-Role Instance IAM Roles: - Worker: arn:aws:iam::418295695583:role/ManagedOpenShift-HCP-ROSA-Worker-Role Operator IAM Roles: - arn:aws:iam::418295695583:role/rosa-hcp-kube-system-control-plane-operator - arn:aws:iam::418295695583:role/rosa-hcp-kube-system-kms-provider - arn:aws:iam::418295695583:role/rosa-hcp-openshift-image-registry-installer-cloud-credentials - arn:aws:iam::418295695583:role/rosa-hcp-openshift-ingress-operator-cloud-credentials - arn:aws:iam::418295695583:role/rosa-hcp-openshift-cluster-csi-drivers-ebs-cloud-credentials - arn:aws:iam::418295695583:role/rosa-hcp-openshift-cloud-network-config-controller-cloud-credent - arn:aws:iam::418295695583:role/rosa-hcp-kube-system-kube-controller-manager - arn:aws:iam::418295695583:role/rosa-hcp-kube-system-capa-controller-manager Managed Policies: Yes State: waiting (Waiting for user action) Private: No Delete Protection: Disabled Created: Oct 30 2025 12:32:12 UTC [DEPRECATED] User Workload Monitoring: Enabled Details Page: https://console.redhat.com/openshift/details/s/34mnI9i4pg0cum9Z5uEecJ37wFs OIDC Endpoint URL: https://oidc.op1.openshiftapps.com/2du11g36ejmoo4624pofphlrgf4r9tf3 (Managed) Etcd Encryption: Disabled Audit Log Forwarding: Disabled External Authentication: Disabled Zero Egress: Disabled INFO: Preparing to create operator roles. INFO: Operator Roles already exists INFO: Preparing to create OIDC Provider. INFO: OIDC provider already exists INFO: To determine when your cluster is Ready, run 'rosa describe cluster -c kx-83e942e860'. INFO: To watch your cluster installation logs, run 'rosa logs install -c kx-83e942e860 --watch'. INFO: Track the progress of the cluster creation... WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. W: Region flag will be removed from this command in future versions INFO: Cluster 'kx-83e942e860' is in waiting state waiting for installation to begin. Logs will show up within 5 minutes 0001-01-01 00:00:00 +0000 UTC hostedclusters kx-83e942e860 Version 2025-10-30 12:36:52 +0000 UTC hostedclusters kx-83e942e860 ValidAWSIdentityProvider StatusUnknown 2025-10-30 12:36:53 +0000 UTC certificates cluster-api-cert Issuing certificate as Secret does not exist 2025-10-30 12:36:53 +0000 UTC certificates cluster-api-cert Issuing certificate as Secret does not exist 2025-10-30 12:36:54 +0000 UTC hostedclusters kx-83e942e860 The hosted control plane is not found 2025-10-30 12:36:54 +0000 UTC hostedclusters kx-83e942e860 Condition not found in the CVO. 2025-10-30 12:36:54 +0000 UTC hostedclusters kx-83e942e860 ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-10-30 12:36:54 +0000 UTC hostedclusters kx-83e942e860 The hosted control plane is not found 2025-10-30 12:36:54 +0000 UTC hostedclusters kx-83e942e860 The hosted control plane is not found 2025-10-30 12:36:54 +0000 UTC hostedclusters kx-83e942e860 Condition not found in the CVO. 2025-10-30 12:36:54 +0000 UTC hostedclusters kx-83e942e860 Condition not found in the CVO. 2025-10-30 12:36:54 +0000 UTC hostedclusters kx-83e942e860 Condition not found in the CVO. 2025-10-30 12:36:54 +0000 UTC hostedclusters kx-83e942e860 Condition not found in the CVO. 2025-10-30 12:36:54 +0000 UTC hostedclusters kx-83e942e860 The hosted control plane is not found 2025-10-30 12:36:54 +0000 UTC hostedclusters kx-83e942e860 Ignition server deployment not found 2025-10-30 12:36:54 +0000 UTC hostedclusters kx-83e942e860 NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-10-30 12:36:54 +0000 UTC hostedclusters kx-83e942e860 HostedCluster is supported by operator configuration 2025-10-30 12:36:54 +0000 UTC hostedclusters kx-83e942e860 Release image is valid 2025-10-30 12:36:54 +0000 UTC hostedclusters kx-83e942e860 The hosted control plane is not found 2025-10-30 12:36:54 +0000 UTC hostedclusters kx-83e942e860 Reconciliation active on resource 2025-10-30 12:36:54 +0000 UTC hostedclusters kx-83e942e860 The hosted control plane is not found 2025-10-30 12:36:54 +0000 UTC hostedclusters kx-83e942e860 The hosted control plane is not found 2025-10-30 12:36:55 +0000 UTC hostedclusters kx-83e942e860 configuration is invalid: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-10-30 12:36:55 +0000 UTC hostedclusters kx-83e942e860 ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-10-30 12:46:15 +0000 UTC certificates cluster-api-cert Certificate is up to date and has not expired 2025-10-30 12:46:24 +0000 UTC hostedclusters kx-83e942e860 Configuration passes validation 2025-10-30 12:46:28 +0000 UTC hostedclusters kx-83e942e860 Required platform credentials are found 2025-10-30 12:46:31 +0000 UTC hostedclusters kx-83e942e860 Configuration passes validation 2025-10-30 12:46:31 +0000 UTC hostedclusters kx-83e942e860 AWS KMS is not configured 2025-10-30 12:46:31 +0000 UTC hostedclusters kx-83e942e860 EtcdAvailable StatefulSetNotFound 2025-10-30 12:46:31 +0000 UTC hostedclusters kx-83e942e860 Kube APIServer deployment not found 2025-10-30 12:46:31 +0000 UTC hostedclusters kx-83e942e860 capi-provider deployment has 2 unavailable replicas 2025-10-30 12:46:31 +0000 UTC hostedclusters kx-83e942e860 lookup api.kx-83e942e860.8wft.p3.openshiftapps.com on 172.30.0.10:53: no such host 2025-10-30 12:46:37 +0000 UTC hostedclusters kx-83e942e860 OIDC configuration is valid 2025-10-30 12:46:37 +0000 UTC hostedclusters kx-83e942e860 Reconciliation completed successfully 2025-10-30 12:46:40 +0000 UTC hostedclusters kx-83e942e860 All is well 2025-10-30 12:46:54 +0000 UTC hostedclusters kx-83e942e860 All is well 2025-10-30 12:47:00 +0000 UTC hostedclusters kx-83e942e860 WebIdentityErr 2025-10-30 12:47:12 +0000 UTC hostedclusters kx-83e942e860 EtcdAvailable QuorumAvailable 2025-10-30 12:47:43 +0000 UTC hostedclusters kx-83e942e860 Kube APIServer deployment is available 2025-10-30 12:48:00 +0000 UTC hostedclusters kx-83e942e860 All is well 2025-10-30 12:48:07 +0000 UTC hostedclusters kx-83e942e860 Ignition server deployment is available 2025-10-30 12:48:07 +0000 UTC hostedclusters kx-83e942e860 All is well 2025-10-30 12:48:17 +0000 UTC hostedclusters kx-83e942e860 ClusterVersionSucceeding FromClusterVersion 2025-10-30 12:48:17 +0000 UTC hostedclusters kx-83e942e860 Condition not found in the CVO. 2025-10-30 12:48:17 +0000 UTC hostedclusters kx-83e942e860 Payload loaded version="4.17.42" image="quay.io/openshift-release-dev/ocp-release@sha256:9b7b9909a1f064d5238f35f6e5fc9ac275a0d463a74e8c545544755d953a46d9" architecture="Multi" 2025-10-30 12:48:17 +0000 UTC hostedclusters kx-83e942e860 ClusterVersionAvailable FromClusterVersion 2025-10-30 12:48:17 +0000 UTC hostedclusters kx-83e942e860 Working towards 4.17.42: 25 of 621 done (4% complete) 0001-01-01 00:00:00 +0000 UTC hostedclusters kx-83e942e860 Version 2025-10-30 12:36:54 +0000 UTC hostedclusters kx-83e942e860 Reconciliation active on resource 2025-10-30 12:36:54 +0000 UTC hostedclusters kx-83e942e860 Get "https://aa9eea698c03746efa50fa1bbb3f05e2-278263c97c29d129.elb.us-east-1.amazonaws.com:443/healthz": dial tcp: lookup aa9eea698c03746efa50fa1bbb3f05e2-278263c97c29d129.elb.us-east-1.amazonaws.com on 172.30.0.10:53: no such host 2025-10-30 12:36:54 +0000 UTC hostedclusters kx-83e942e860 Release image is valid 2025-10-30 12:36:54 +0000 UTC hostedclusters kx-83e942e860 HostedCluster is supported by operator configuration 2025-10-30 12:36:55 +0000 UTC hostedclusters kx-83e942e860 HostedCluster is at expected version 2025-10-30 12:46:15 +0000 UTC certificates cluster-api-cert Certificate is up to date and has not expired 2025-10-30 12:46:24 +0000 UTC hostedclusters kx-83e942e860 Configuration passes validation 2025-10-30 12:46:28 +0000 UTC hostedclusters kx-83e942e860 Required platform credentials are found 2025-10-30 12:46:31 +0000 UTC hostedclusters kx-83e942e860 Configuration passes validation 2025-10-30 12:46:31 +0000 UTC hostedclusters kx-83e942e860 router deployment has 1 unavailable replicas 2025-10-30 12:46:31 +0000 UTC hostedclusters kx-83e942e860 AWS KMS is not configured 2025-10-30 12:46:31 +0000 UTC hostedclusters kx-83e942e860 lookup api.kx-83e942e860.8wft.p3.openshiftapps.com on 172.30.0.10:53: no such host 2025-10-30 12:46:37 +0000 UTC hostedclusters kx-83e942e860 OIDC configuration is valid 2025-10-30 12:46:37 +0000 UTC hostedclusters kx-83e942e860 Reconciliation completed successfully 2025-10-30 12:46:40 +0000 UTC hostedclusters kx-83e942e860 All is well 2025-10-30 12:46:54 +0000 UTC hostedclusters kx-83e942e860 All is well 2025-10-30 12:47:12 +0000 UTC hostedclusters kx-83e942e860 EtcdAvailable QuorumAvailable 2025-10-30 12:47:43 +0000 UTC hostedclusters kx-83e942e860 Kube APIServer deployment is available 2025-10-30 12:48:00 +0000 UTC hostedclusters kx-83e942e860 All is well 2025-10-30 12:48:07 +0000 UTC hostedclusters kx-83e942e860 Ignition server deployment is available 2025-10-30 12:48:07 +0000 UTC hostedclusters kx-83e942e860 All is well 2025-10-30 12:48:17 +0000 UTC hostedclusters kx-83e942e860 Condition not found in the CVO. 2025-10-30 12:48:17 +0000 UTC hostedclusters kx-83e942e860 Payload loaded version="4.17.42" image="quay.io/openshift-release-dev/ocp-release@sha256:9b7b9909a1f064d5238f35f6e5fc9ac275a0d463a74e8c545544755d953a46d9" architecture="Multi" 2025-10-30 12:48:17 +0000 UTC hostedclusters kx-83e942e860 ClusterVersionAvailable FromClusterVersion 2025-10-30 12:48:17 +0000 UTC hostedclusters kx-83e942e860 Unable to apply 4.17.42: some cluster operators are not available 2025-10-30 12:48:55 +0000 UTC hostedclusters kx-83e942e860 Cluster operators console, dns, image-registry, ingress, insights, kube-storage-version-migrator, monitoring, node-tuning, openshift-samples, service-ca, storage are not available 2025-10-30 12:49:27 +0000 UTC hostedclusters kx-83e942e860 The hosted cluster is not degraded 2025-10-30 12:49:29 +0000 UTC hostedclusters kx-83e942e860 The hosted control plane is available INFO: Cluster 'kx-83e942e860' is now ready INFO: ROSA with HCP cluster is ready, create a cluster admin account for accessing the cluster WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. INFO: Storing login command... INFO: Check if it's able to login to OCP cluster... Retried 1 times... Retried 2 times... Retried 3 times... Retried 4 times... Retried 5 times... Retried 6 times... Retried 7 times... Retried 8 times... Retried 9 times... Retried 10 times... ERROR: Failed to login the cluster. INFO: Print debug info...... WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. W: Region flag will be removed from this command in future versions Name: kx-83e942e860 Domain Prefix: kx-83e942e860 Display Name: kx-83e942e860 ID: 2m8gpi9linr8durogl3k4kblelnoj9cp External ID: 15ca86c3-390f-4ef2-8ea6-8dd313fd075e Control Plane: ROSA Service Hosted OpenShift Version: 4.17.42 Channel Group: stable DNS: kx-83e942e860.8wft.p3.openshiftapps.com AWS Account: 418295695583 AWS Billing Account: 418295695583 API URL: https://api.kx-83e942e860.8wft.p3.openshiftapps.com:443 Console URL: https://console-openshift-console.apps.rosa.kx-83e942e860.8wft.p3.openshiftapps.com Region: us-east-1 Availability: - Control Plane: MultiAZ - Data Plane: MultiAZ Nodes: - Compute (desired): 3 - Compute (current): 3 Network: - Type: OVNKubernetes - Service CIDR: 172.30.0.0/16 - Machine CIDR: 10.0.0.0/16 - Pod CIDR: 10.128.0.0/14 - Host Prefix: /23 - Subnets: subnet-001fc23497e4a3aeb, subnet-00ffba09365a434bc, subnet-074cbf0329958194a, subnet-0689cd077699b690a, subnet-0f9f09e46f74cde64, subnet-033f48892ddbaa09d EC2 Metadata Http Tokens: optional Role (STS) ARN: arn:aws:iam::418295695583:role/ManagedOpenShift-HCP-ROSA-Installer-Role Support Role ARN: arn:aws:iam::418295695583:role/ManagedOpenShift-HCP-ROSA-Support-Role Instance IAM Roles: - Worker: arn:aws:iam::418295695583:role/ManagedOpenShift-HCP-ROSA-Worker-Role Operator IAM Roles: - arn:aws:iam::418295695583:role/rosa-hcp-kube-system-control-plane-operator - arn:aws:iam::418295695583:role/rosa-hcp-kube-system-kms-provider - arn:aws:iam::418295695583:role/rosa-hcp-openshift-image-registry-installer-cloud-credentials - arn:aws:iam::418295695583:role/rosa-hcp-openshift-ingress-operator-cloud-credentials - arn:aws:iam::418295695583:role/rosa-hcp-openshift-cluster-csi-drivers-ebs-cloud-credentials - arn:aws:iam::418295695583:role/rosa-hcp-openshift-cloud-network-config-controller-cloud-credent - arn:aws:iam::418295695583:role/rosa-hcp-kube-system-kube-controller-manager - arn:aws:iam::418295695583:role/rosa-hcp-kube-system-capa-controller-manager Managed Policies: Yes State: ready Private: No Delete Protection: Disabled Created: Oct 30 2025 12:32:12 UTC [DEPRECATED] User Workload Monitoring: Enabled Details Page: https://console.redhat.com/openshift/details/s/34mnI9i4pg0cum9Z5uEecJ37wFs OIDC Endpoint URL: https://oidc.op1.openshiftapps.com/2du11g36ejmoo4624pofphlrgf4r9tf3 (Managed) Etcd Encryption: Disabled Audit Log Forwarding: Disabled External Authentication: Disabled Zero Egress: Disabled