INFO: Log in to your Red Hat account... INFO: Configure AWS Credentials... WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. INFO: Logged in as 'konflux-ci-418295695583' on 'https://api.openshift.com' INFO: Create ROSA with HCP cluster... WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. INFO: Creating cluster 'kx-09cb51a54f' INFO: To view a list of clusters and their status, run 'rosa list clusters' INFO: Cluster 'kx-09cb51a54f' has been created. INFO: Once the cluster is installed you will need to add an Identity Provider before you can login into the cluster. See 'rosa create idp --help' for more information. Name: kx-09cb51a54f Domain Prefix: kx-09cb51a54f Display Name: kx-09cb51a54f ID: 2m3733132vnhrh9rdbdpinit96eo1o27 External ID: d9768e21-4494-44fc-9beb-c2ed9393723a Control Plane: ROSA Service Hosted OpenShift Version: 4.17.41 Channel Group: stable DNS: Not ready AWS Account: 418295695583 AWS Billing Account: 418295695583 API URL: Console URL: Region: us-east-1 Availability: - Control Plane: MultiAZ - Data Plane: MultiAZ Nodes: - Compute (desired): 3 - Compute (current): 0 Network: - Type: OVNKubernetes - Service CIDR: 172.30.0.0/16 - Machine CIDR: 10.0.0.0/16 - Pod CIDR: 10.128.0.0/14 - Host Prefix: /23 - Subnets: subnet-001fc23497e4a3aeb, subnet-00ffba09365a434bc, subnet-074cbf0329958194a, subnet-0689cd077699b690a, subnet-0f9f09e46f74cde64, subnet-033f48892ddbaa09d EC2 Metadata Http Tokens: optional Role (STS) ARN: arn:aws:iam::418295695583:role/ManagedOpenShift-HCP-ROSA-Installer-Role Support Role ARN: arn:aws:iam::418295695583:role/ManagedOpenShift-HCP-ROSA-Support-Role Instance IAM Roles: - Worker: arn:aws:iam::418295695583:role/ManagedOpenShift-HCP-ROSA-Worker-Role Operator IAM Roles: - arn:aws:iam::418295695583:role/rosa-hcp-kube-system-capa-controller-manager - arn:aws:iam::418295695583:role/rosa-hcp-kube-system-control-plane-operator - arn:aws:iam::418295695583:role/rosa-hcp-kube-system-kms-provider - arn:aws:iam::418295695583:role/rosa-hcp-openshift-ingress-operator-cloud-credentials - arn:aws:iam::418295695583:role/rosa-hcp-openshift-cluster-csi-drivers-ebs-cloud-credentials - arn:aws:iam::418295695583:role/rosa-hcp-openshift-cloud-network-config-controller-cloud-credent - arn:aws:iam::418295695583:role/rosa-hcp-openshift-image-registry-installer-cloud-credentials - arn:aws:iam::418295695583:role/rosa-hcp-kube-system-kube-controller-manager Managed Policies: Yes State: waiting (Waiting for user action) Private: No Delete Protection: Disabled Created: Oct 22 2025 11:27:12 UTC [DEPRECATED] User Workload Monitoring: Enabled Details Page: https://console.redhat.com/openshift/details/s/34Q4OvSu5HzU6Ag2HVlk2O0huCR OIDC Endpoint URL: https://oidc.op1.openshiftapps.com/2du11g36ejmoo4624pofphlrgf4r9tf3 (Managed) Etcd Encryption: Disabled Audit Log Forwarding: Disabled External Authentication: Disabled Zero Egress: Disabled INFO: Preparing to create operator roles. INFO: Operator Roles already exists INFO: Preparing to create OIDC Provider. INFO: OIDC provider already exists INFO: To determine when your cluster is Ready, run 'rosa describe cluster -c kx-09cb51a54f'. INFO: To watch your cluster installation logs, run 'rosa logs install -c kx-09cb51a54f --watch'. INFO: Track the progress of the cluster creation... WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. W: Region flag will be removed from this command in future versions INFO: Cluster 'kx-09cb51a54f' is in waiting state waiting for installation to begin. Logs will show up within 5 minutes 0001-01-01 00:00:00 +0000 UTC hostedclusters kx-09cb51a54f Version 2025-10-22 11:30:58 +0000 UTC hostedclusters kx-09cb51a54f ValidAWSIdentityProvider StatusUnknown 2025-10-22 11:30:59 +0000 UTC certificates cluster-api-cert Issuing certificate as Secret does not exist 2025-10-22 11:30:59 +0000 UTC certificates cluster-api-cert Issuing certificate as Secret does not exist 2025-10-22 11:31:03 +0000 UTC hostedclusters kx-09cb51a54f The hosted control plane is not found 2025-10-22 11:31:03 +0000 UTC hostedclusters kx-09cb51a54f Condition not found in the CVO. 2025-10-22 11:31:03 +0000 UTC hostedclusters kx-09cb51a54f ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-10-22 11:31:03 +0000 UTC hostedclusters kx-09cb51a54f The hosted control plane is not found 2025-10-22 11:31:03 +0000 UTC hostedclusters kx-09cb51a54f The hosted control plane is not found 2025-10-22 11:31:03 +0000 UTC hostedclusters kx-09cb51a54f Condition not found in the CVO. 2025-10-22 11:31:03 +0000 UTC hostedclusters kx-09cb51a54f Condition not found in the CVO. 2025-10-22 11:31:03 +0000 UTC hostedclusters kx-09cb51a54f Condition not found in the CVO. 2025-10-22 11:31:03 +0000 UTC hostedclusters kx-09cb51a54f Condition not found in the CVO. 2025-10-22 11:31:03 +0000 UTC hostedclusters kx-09cb51a54f The hosted control plane is not found 2025-10-22 11:31:03 +0000 UTC hostedclusters kx-09cb51a54f Ignition server deployment not found 2025-10-22 11:31:03 +0000 UTC hostedclusters kx-09cb51a54f NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-10-22 11:31:03 +0000 UTC hostedclusters kx-09cb51a54f HostedCluster is supported by operator configuration 2025-10-22 11:31:03 +0000 UTC hostedclusters kx-09cb51a54f Release image is valid 2025-10-22 11:31:03 +0000 UTC hostedclusters kx-09cb51a54f The hosted control plane is not found 2025-10-22 11:31:03 +0000 UTC hostedclusters kx-09cb51a54f Reconciliation active on resource 2025-10-22 11:31:03 +0000 UTC hostedclusters kx-09cb51a54f The hosted control plane is not found 2025-10-22 11:31:03 +0000 UTC hostedclusters kx-09cb51a54f The hosted control plane is not found 2025-10-22 11:31:04 +0000 UTC hostedclusters kx-09cb51a54f configuration is invalid: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-10-22 11:31:04 +0000 UTC hostedclusters kx-09cb51a54f ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 0001-01-01 00:00:00 +0000 UTC hostedclusters kx-09cb51a54f Version 2025-10-22 11:31:03 +0000 UTC hostedclusters kx-09cb51a54f Release image is valid 2025-10-22 11:31:03 +0000 UTC hostedclusters kx-09cb51a54f Waiting for hosted control plane kubeconfig to be created 2025-10-22 11:31:03 +0000 UTC hostedclusters kx-09cb51a54f Reconciliation active on resource 2025-10-22 11:31:03 +0000 UTC hostedclusters kx-09cb51a54f HostedCluster is supported by operator configuration 2025-10-22 11:31:03 +0000 UTC hostedclusters kx-09cb51a54f Ignition server deployment not found 2025-10-22 11:31:03 +0000 UTC hostedclusters kx-09cb51a54f Condition not found in the CVO. 2025-10-22 11:31:03 +0000 UTC hostedclusters kx-09cb51a54f Condition not found in the CVO. 2025-10-22 11:31:03 +0000 UTC hostedclusters kx-09cb51a54f Condition not found in the CVO. 2025-10-22 11:31:03 +0000 UTC hostedclusters kx-09cb51a54f Condition not found in the CVO. 2025-10-22 11:31:03 +0000 UTC hostedclusters kx-09cb51a54f Condition not found in the CVO. 2025-10-22 11:31:04 +0000 UTC hostedclusters kx-09cb51a54f HostedCluster is at expected version 2025-10-22 11:32:26 +0000 UTC certificates cluster-api-cert Certificate is up to date and has not expired 2025-10-22 11:32:32 +0000 UTC hostedclusters kx-09cb51a54f Configuration passes validation 2025-10-22 11:32:33 +0000 UTC hostedclusters kx-09cb51a54f Required platform credentials are found 2025-10-22 11:32:36 +0000 UTC hostedclusters kx-09cb51a54f AWS KMS is not configured 2025-10-22 11:32:36 +0000 UTC hostedclusters kx-09cb51a54f capi-provider deployment has 2 unavailable replicas 2025-10-22 11:32:36 +0000 UTC hostedclusters kx-09cb51a54f lookup api.kx-09cb51a54f.we0x.p3.openshiftapps.com on 172.30.0.10:53: no such host 2025-10-22 11:32:36 +0000 UTC hostedclusters kx-09cb51a54f Configuration passes validation 2025-10-22 11:32:36 +0000 UTC hostedclusters kx-09cb51a54f Kube APIServer deployment not found 2025-10-22 11:32:38 +0000 UTC hostedclusters kx-09cb51a54f OIDC configuration is valid 2025-10-22 11:32:38 +0000 UTC hostedclusters kx-09cb51a54f Reconciliation completed successfully 2025-10-22 11:32:46 +0000 UTC hostedclusters kx-09cb51a54f All is well 2025-10-22 11:33:00 +0000 UTC hostedclusters kx-09cb51a54f All is well 2025-10-22 11:33:05 +0000 UTC hostedclusters kx-09cb51a54f WebIdentityErr 2025-10-22 11:33:17 +0000 UTC hostedclusters kx-09cb51a54f EtcdAvailable QuorumAvailable 2025-10-22 11:33:52 +0000 UTC hostedclusters kx-09cb51a54f Kube APIServer deployment is available 2025-10-22 11:34:05 +0000 UTC hostedclusters kx-09cb51a54f All is well 2025-10-22 11:34:11 +0000 UTC hostedclusters kx-09cb51a54f Ignition server deployment is available 2025-10-22 11:34:13 +0000 UTC hostedclusters kx-09cb51a54f All is well 2025-10-22 11:34:35 +0000 UTC hostedclusters kx-09cb51a54f Payload loaded version="4.17.41" image="quay.io/openshift-release-dev/ocp-release@sha256:57f09f90de7ab876109581cef6b2cf9da8ff62818bd9fb1503c0cc26d5a5d80a" architecture="Multi" 2025-10-22 11:34:35 +0000 UTC hostedclusters kx-09cb51a54f ClusterVersionAvailable FromClusterVersion 2025-10-22 11:34:35 +0000 UTC hostedclusters kx-09cb51a54f Unable to apply 4.17.41: some cluster operators are not available 2025-10-22 11:34:35 +0000 UTC hostedclusters kx-09cb51a54f Condition not found in the CVO. 2025-10-22 11:35:06 +0000 UTC hostedclusters kx-09cb51a54f Cluster operators console, dns, image-registry, ingress, insights, kube-storage-version-migrator, monitoring, node-tuning, openshift-samples, service-ca, storage are not available 2025-10-22 11:35:16 +0000 UTC hostedclusters kx-09cb51a54f The hosted control plane is available INFO: Cluster 'kx-09cb51a54f' is now ready INFO: ROSA with HCP cluster is ready, create a cluster admin account for accessing the cluster WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. INFO: Storing login command... INFO: Check if it's able to login to OCP cluster... Retried 1 times... INFO: Check if apiserver is ready... Waiting for cluster operators to be accessible for 2m... NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.17.41 True False False 3m56s dns 4.17.41 False False True 4m2s DNS "default" is unavailable. image-registry False True True 3m55s Available: The deployment does not have available replicas... ingress False True True 3m54s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.17.41 True False False 4m3s kube-controller-manager 4.17.41 True False False 4m3s kube-scheduler 4.17.41 True False False 4m3s kube-storage-version-migrator monitoring network 4.17.41 True True False 3m48s DaemonSet "/openshift-multus/network-metrics-daemon" is waiting for other operators to become ready... node-tuning False True False 3m36s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.17.41 True False False 4m3s openshift-controller-manager 4.17.41 True False False 4m3s openshift-samples operator-lifecycle-manager 4.17.41 True False False 4m1s operator-lifecycle-manager-catalog 4.17.41 True False False 4m2s operator-lifecycle-manager-packageserver 4.17.41 True False False 4m2s service-ca storage 4.17.41 False False False 4m2s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service cluster operators to be accessible finished! [INFO] Cluster operators are accessible. Waiting for cluster to be reported as healthy for 60m... NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.17.41 True False False 3m57s dns 4.17.41 False False True 4m3s DNS "default" is unavailable. image-registry False True True 3m56s Available: The deployment does not have available replicas... ingress False True True 3m55s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.17.41 True False False 4m4s kube-controller-manager 4.17.41 True False False 4m4s kube-scheduler 4.17.41 True False False 4m4s kube-storage-version-migrator monitoring network 4.17.41 True True False 3m49s DaemonSet "/openshift-multus/network-metrics-daemon" is waiting for other operators to become ready... node-tuning False True False 3m37s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.17.41 True False False 4m4s openshift-controller-manager 4.17.41 True False False 4m4s openshift-samples operator-lifecycle-manager 4.17.41 True False False 4m2s operator-lifecycle-manager-catalog 4.17.41 True False False 4m3s operator-lifecycle-manager-packageserver 4.17.41 True False False 4m3s service-ca storage 4.17.41 False False False 4m3s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.17.41 True False False 4m57s dns 4.17.41 False True True 5m3s DNS "default" is unavailable. image-registry False True True 4m56s Available: The deployment does not have available replicas... ingress False True True 4m55s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.17.41 True False False 5m4s kube-controller-manager 4.17.41 True False False 5m4s kube-scheduler 4.17.41 True False False 5m4s kube-storage-version-migrator monitoring network 4.17.41 True True False 4m49s DaemonSet "/openshift-network-operator/iptables-alerter" is waiting for other operators to become ready... node-tuning False True False 4m37s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.17.41 True False False 5m4s openshift-controller-manager 4.17.41 True False False 5m4s openshift-samples operator-lifecycle-manager 4.17.41 True False False 5m2s operator-lifecycle-manager-catalog 4.17.41 True False False 5m3s operator-lifecycle-manager-packageserver 4.17.41 True False False 5m3s service-ca storage 4.17.41 False True False 5m3s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.17.41 True False False 5m57s dns 4.17.41 False False True 6m3s DNS "default" is unavailable. image-registry False True True 5m56s Available: The deployment does not have available replicas... ingress False True True 5m55s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights 4.17.41 True False False 21s kube-apiserver 4.17.41 True False False 6m4s kube-controller-manager 4.17.41 True False False 6m4s kube-scheduler 4.17.41 True False False 6m4s kube-storage-version-migrator 4.17.41 True False False 17s monitoring network 4.17.41 True True False 5m49s DaemonSet "/openshift-multus/network-metrics-daemon" is waiting for other operators to become ready... node-tuning 4.17.41 True True False 18s Waiting for 1/2 Profiles to be applied openshift-apiserver 4.17.41 True False False 6m4s openshift-controller-manager 4.17.41 True False False 6m4s openshift-samples operator-lifecycle-manager 4.17.41 True False False 6m2s operator-lifecycle-manager-catalog 4.17.41 True False False 6m3s operator-lifecycle-manager-packageserver 4.17.41 True False False 6m3s service-ca 4.17.41 True False False 19s storage 4.17.41 True True False 46s AWSEBSCSIDriverOperatorCRProgressing: AWSEBSDriverNodeServiceControllerProgressing: Waiting for DaemonSet to deploy node pods Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.17.41 True False False 21s csi-snapshot-controller 4.17.41 True False False 6m57s dns 4.17.41 True False False 42s image-registry 4.17.41 True False False 35s ingress 4.17.41 True True True 24s The "default" ingress controller reports Degraded=True: DegradedConditions: One or more other status conditions indicate a degraded state: CanaryChecksSucceeding=Unknown (CanaryRouteNotAdmitted: Canary route is not admitted by the default ingress controller) insights 4.17.41 True False False 81s kube-apiserver 4.17.41 True False False 7m4s kube-controller-manager 4.17.41 True False False 7m4s kube-scheduler 4.17.41 True False False 7m4s kube-storage-version-migrator 4.17.41 True False False 77s monitoring Unknown True Unknown 53s Rolling out the stack. network 4.17.41 True False False 6m49s node-tuning 4.17.41 True False False 49s openshift-apiserver 4.17.41 True False False 7m4s openshift-controller-manager 4.17.41 True False False 7m4s openshift-samples 4.17.41 True False False 38s operator-lifecycle-manager 4.17.41 True False False 7m2s operator-lifecycle-manager-catalog 4.17.41 True False False 7m3s operator-lifecycle-manager-packageserver 4.17.41 True False False 7m3s service-ca 4.17.41 True False False 79s storage 4.17.41 True False False 106s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.17.41 True False False 81s csi-snapshot-controller 4.17.41 True False False 7m57s dns 4.17.41 True False False 102s image-registry 4.17.41 True False False 95s ingress 4.17.41 True False True 84s The "default" ingress controller reports Degraded=True: DegradedConditions: One or more other status conditions indicate a degraded state: CanaryChecksSucceeding=Unknown (CanaryRouteNotAdmitted: Canary route is not admitted by the default ingress controller) insights 4.17.41 True False False 2m21s kube-apiserver 4.17.41 True False False 8m4s kube-controller-manager 4.17.41 True False False 8m4s kube-scheduler 4.17.41 True False False 8m4s kube-storage-version-migrator 4.17.41 True False False 2m17s monitoring Unknown True Unknown 113s Rolling out the stack. network 4.17.41 True False False 7m49s node-tuning 4.17.41 True False False 109s openshift-apiserver 4.17.41 True False False 8m4s openshift-controller-manager 4.17.41 True False False 8m4s openshift-samples 4.17.41 True False False 98s operator-lifecycle-manager 4.17.41 True False False 8m2s operator-lifecycle-manager-catalog 4.17.41 True False False 8m3s operator-lifecycle-manager-packageserver 4.17.41 True False False 8m3s service-ca 4.17.41 True False False 2m19s storage 4.17.41 True False False 2m46s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.17.41 True False False 2m22s csi-snapshot-controller 4.17.41 True False False 8m58s dns 4.17.41 True False False 2m43s image-registry 4.17.41 True False False 2m36s ingress 4.17.41 True False False 2m25s insights 4.17.41 True False False 3m22s kube-apiserver 4.17.41 True False False 9m5s kube-controller-manager 4.17.41 True False False 9m5s kube-scheduler 4.17.41 True False False 9m5s kube-storage-version-migrator 4.17.41 True False False 3m18s monitoring Unknown True Unknown 2m54s Rolling out the stack. network 4.17.41 True False False 8m50s node-tuning 4.17.41 True False False 2m50s openshift-apiserver 4.17.41 True False False 9m5s openshift-controller-manager 4.17.41 True False False 9m5s openshift-samples 4.17.41 True False False 2m39s operator-lifecycle-manager 4.17.41 True False False 9m3s operator-lifecycle-manager-catalog 4.17.41 True False False 9m4s operator-lifecycle-manager-packageserver 4.17.41 True False False 9m4s service-ca 4.17.41 True False False 3m20s storage 4.17.41 True False False 3m47s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.17.41 True False False 3m22s csi-snapshot-controller 4.17.41 True False False 9m58s dns 4.17.41 True False False 3m43s image-registry 4.17.41 True False False 3m36s ingress 4.17.41 True False False 3m25s insights 4.17.41 True False False 4m22s kube-apiserver 4.17.41 True False False 10m kube-controller-manager 4.17.41 True False False 10m kube-scheduler 4.17.41 True False False 10m kube-storage-version-migrator 4.17.41 True False False 4m18s monitoring Unknown True Unknown 3m54s Rolling out the stack. network 4.17.41 True False False 9m50s node-tuning 4.17.41 True False False 3m50s openshift-apiserver 4.17.41 True False False 10m openshift-controller-manager 4.17.41 True False False 10m openshift-samples 4.17.41 True False False 3m39s operator-lifecycle-manager 4.17.41 True False False 10m operator-lifecycle-manager-catalog 4.17.41 True False False 10m operator-lifecycle-manager-packageserver 4.17.41 True False False 10m service-ca 4.17.41 True False False 4m20s storage 4.17.41 True False False 4m47s Waiting for cluster to be reported as healthy... Trying again in 60s healthy cluster to be reported as healthy finished!