INFO: Log in to your Red Hat account... INFO: Configure AWS Credentials... WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. INFO: Logged in as 'konflux-ci-418295695583' on 'https://api.openshift.com' INFO: Create ROSA with HCP cluster... WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. INFO: Creating cluster 'kx-92792514a0' INFO: To view a list of clusters and their status, run 'rosa list clusters' INFO: Cluster 'kx-92792514a0' has been created. INFO: Once the cluster is installed you will need to add an Identity Provider before you can login into the cluster. See 'rosa create idp --help' for more information. Name: kx-92792514a0 Domain Prefix: kx-92792514a0 Display Name: kx-92792514a0 ID: 2m4co2vebrtmijvpf6g8qq5ju9tititu External ID: b79812fb-9506-445f-8ca3-72f5c076c0d7 Control Plane: ROSA Service Hosted OpenShift Version: 4.17.41 Channel Group: stable DNS: Not ready AWS Account: 418295695583 AWS Billing Account: 418295695583 API URL: Console URL: Region: us-east-1 Availability: - Control Plane: MultiAZ - Data Plane: MultiAZ Nodes: - Compute (desired): 3 - Compute (current): 0 Network: - Type: OVNKubernetes - Service CIDR: 172.30.0.0/16 - Machine CIDR: 10.0.0.0/16 - Pod CIDR: 10.128.0.0/14 - Host Prefix: /23 - Subnets: subnet-001fc23497e4a3aeb, subnet-00ffba09365a434bc, subnet-074cbf0329958194a, subnet-0689cd077699b690a, subnet-0f9f09e46f74cde64, subnet-033f48892ddbaa09d EC2 Metadata Http Tokens: optional Role (STS) ARN: arn:aws:iam::418295695583:role/ManagedOpenShift-HCP-ROSA-Installer-Role Support Role ARN: arn:aws:iam::418295695583:role/ManagedOpenShift-HCP-ROSA-Support-Role Instance IAM Roles: - Worker: arn:aws:iam::418295695583:role/ManagedOpenShift-HCP-ROSA-Worker-Role Operator IAM Roles: - arn:aws:iam::418295695583:role/rosa-hcp-openshift-cluster-csi-drivers-ebs-cloud-credentials - arn:aws:iam::418295695583:role/rosa-hcp-openshift-cloud-network-config-controller-cloud-credent - arn:aws:iam::418295695583:role/rosa-hcp-kube-system-kube-controller-manager - arn:aws:iam::418295695583:role/rosa-hcp-kube-system-capa-controller-manager - arn:aws:iam::418295695583:role/rosa-hcp-kube-system-control-plane-operator - arn:aws:iam::418295695583:role/rosa-hcp-kube-system-kms-provider - arn:aws:iam::418295695583:role/rosa-hcp-openshift-image-registry-installer-cloud-credentials - arn:aws:iam::418295695583:role/rosa-hcp-openshift-ingress-operator-cloud-credentials Managed Policies: Yes State: waiting (Waiting for user action) Private: No Delete Protection: Disabled Created: Oct 24 2025 06:17:51 UTC [DEPRECATED] User Workload Monitoring: Enabled Details Page: https://console.redhat.com/openshift/details/s/34V71iXOwChlMkYFACQWNVUx0Jv OIDC Endpoint URL: https://oidc.op1.openshiftapps.com/2du11g36ejmoo4624pofphlrgf4r9tf3 (Managed) Etcd Encryption: Disabled Audit Log Forwarding: Disabled External Authentication: Disabled Zero Egress: Disabled INFO: Preparing to create operator roles. INFO: Operator Roles already exists INFO: Preparing to create OIDC Provider. INFO: OIDC provider already exists INFO: To determine when your cluster is Ready, run 'rosa describe cluster -c kx-92792514a0'. INFO: To watch your cluster installation logs, run 'rosa logs install -c kx-92792514a0 --watch'. INFO: Track the progress of the cluster creation... WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. W: Region flag will be removed from this command in future versions INFO: Cluster 'kx-92792514a0' is in waiting state waiting for installation to begin. Logs will show up within 5 minutes 0001-01-01 00:00:00 +0000 UTC hostedclusters kx-92792514a0 Version 2025-10-24 06:22:51 +0000 UTC hostedclusters kx-92792514a0 ValidAWSIdentityProvider StatusUnknown 2025-10-24 06:22:52 +0000 UTC certificates cluster-api-cert Issuing certificate as Secret does not exist 2025-10-24 06:22:52 +0000 UTC certificates cluster-api-cert Issuing certificate as Secret does not exist 2025-10-24 06:22:55 +0000 UTC hostedclusters kx-92792514a0 The hosted control plane is not found 2025-10-24 06:22:55 +0000 UTC hostedclusters kx-92792514a0 Condition not found in the CVO. 2025-10-24 06:22:55 +0000 UTC hostedclusters kx-92792514a0 ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-10-24 06:22:55 +0000 UTC hostedclusters kx-92792514a0 The hosted control plane is not found 2025-10-24 06:22:55 +0000 UTC hostedclusters kx-92792514a0 The hosted control plane is not found 2025-10-24 06:22:55 +0000 UTC hostedclusters kx-92792514a0 Condition not found in the CVO. 2025-10-24 06:22:55 +0000 UTC hostedclusters kx-92792514a0 Condition not found in the CVO. 2025-10-24 06:22:55 +0000 UTC hostedclusters kx-92792514a0 Condition not found in the CVO. 2025-10-24 06:22:55 +0000 UTC hostedclusters kx-92792514a0 Condition not found in the CVO. 2025-10-24 06:22:55 +0000 UTC hostedclusters kx-92792514a0 The hosted control plane is not found 2025-10-24 06:22:55 +0000 UTC hostedclusters kx-92792514a0 Ignition server deployment not found 2025-10-24 06:22:55 +0000 UTC hostedclusters kx-92792514a0 NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-10-24 06:22:55 +0000 UTC hostedclusters kx-92792514a0 HostedCluster is supported by operator configuration 2025-10-24 06:22:55 +0000 UTC hostedclusters kx-92792514a0 Release image is valid 2025-10-24 06:22:55 +0000 UTC hostedclusters kx-92792514a0 The hosted control plane is not found 2025-10-24 06:22:55 +0000 UTC hostedclusters kx-92792514a0 Reconciliation active on resource 2025-10-24 06:22:55 +0000 UTC hostedclusters kx-92792514a0 ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-10-24 06:22:55 +0000 UTC hostedclusters kx-92792514a0 The hosted control plane is not found 2025-10-24 06:22:55 +0000 UTC hostedclusters kx-92792514a0 The hosted control plane is not found 2025-10-24 06:22:56 +0000 UTC hostedclusters kx-92792514a0 configuration is invalid: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-10-24 06:24:21 +0000 UTC certificates cluster-api-cert Certificate is up to date and has not expired 2025-10-24 06:24:22 +0000 UTC hostedclusters kx-92792514a0 Configuration passes validation 2025-10-24 06:24:33 +0000 UTC hostedclusters kx-92792514a0 Required platform credentials are found 2025-10-24 06:24:36 +0000 UTC hostedclusters kx-92792514a0 AWS KMS is not configured 2025-10-24 06:24:36 +0000 UTC hostedclusters kx-92792514a0 lookup api.kx-92792514a0.qj22.p3.openshiftapps.com on 172.30.0.10:53: no such host 2025-10-24 06:24:36 +0000 UTC hostedclusters kx-92792514a0 Configuration passes validation 2025-10-24 06:24:36 +0000 UTC hostedclusters kx-92792514a0 Waiting for etcd to reach quorum 2025-10-24 06:24:36 +0000 UTC hostedclusters kx-92792514a0 Kube APIServer deployment not found 2025-10-24 06:24:38 +0000 UTC hostedclusters kx-92792514a0 capi-provider deployment has 2 unavailable replicas 2025-10-24 06:24:39 +0000 UTC hostedclusters kx-92792514a0 OIDC configuration is valid 2025-10-24 06:24:39 +0000 UTC hostedclusters kx-92792514a0 Reconciliation completed successfully 2025-10-24 06:24:59 +0000 UTC hostedclusters kx-92792514a0 All is well 2025-10-24 06:25:00 +0000 UTC hostedclusters kx-92792514a0 All is well 2025-10-24 06:25:05 +0000 UTC hostedclusters kx-92792514a0 WebIdentityErr 0001-01-01 00:00:00 +0000 UTC hostedclusters kx-92792514a0 Version 2025-10-24 06:22:55 +0000 UTC hostedclusters kx-92792514a0 Release image is valid 2025-10-24 06:22:55 +0000 UTC hostedclusters kx-92792514a0 Reconciliation active on resource 2025-10-24 06:22:55 +0000 UTC hostedclusters kx-92792514a0 HostedCluster is at expected version 2025-10-24 06:22:55 +0000 UTC hostedclusters kx-92792514a0 Condition not found in the CVO. 2025-10-24 06:22:55 +0000 UTC hostedclusters kx-92792514a0 Get "https://a94e024b218574de698a3ab4de4bc0e9-bb34bb5a7cc7d696.elb.us-east-1.amazonaws.com:443/healthz": dial tcp: lookup a94e024b218574de698a3ab4de4bc0e9-bb34bb5a7cc7d696.elb.us-east-1.amazonaws.com on 172.30.0.10:53: no such host 2025-10-24 06:22:55 +0000 UTC hostedclusters kx-92792514a0 Condition not found in the CVO. 2025-10-24 06:22:55 +0000 UTC hostedclusters kx-92792514a0 Condition not found in the CVO. 2025-10-24 06:22:55 +0000 UTC hostedclusters kx-92792514a0 Condition not found in the CVO. 2025-10-24 06:22:55 +0000 UTC hostedclusters kx-92792514a0 Condition not found in the CVO. 2025-10-24 06:22:55 +0000 UTC hostedclusters kx-92792514a0 HostedCluster is supported by operator configuration 2025-10-24 06:24:21 +0000 UTC certificates cluster-api-cert Certificate is up to date and has not expired 2025-10-24 06:24:22 +0000 UTC hostedclusters kx-92792514a0 Configuration passes validation 2025-10-24 06:24:33 +0000 UTC hostedclusters kx-92792514a0 Required platform credentials are found 2025-10-24 06:24:36 +0000 UTC hostedclusters kx-92792514a0 AWS KMS is not configured 2025-10-24 06:24:36 +0000 UTC hostedclusters kx-92792514a0 lookup api.kx-92792514a0.qj22.p3.openshiftapps.com on 172.30.0.10:53: no such host 2025-10-24 06:24:36 +0000 UTC hostedclusters kx-92792514a0 Configuration passes validation 2025-10-24 06:24:38 +0000 UTC hostedclusters kx-92792514a0 [catalog-operator deployment has 1 unavailable replicas, certified-operators-catalog deployment has 2 unavailable replicas, cloud-credential-operator deployment has 1 unavailable replicas, cluster-network-operator deployment has 1 unavailable replicas, cluster-storage-operator deployment has 1 unavailable replicas, community-operators-catalog deployment has 2 unavailable replicas, csi-snapshot-controller-operator deployment has 1 unavailable replicas, dns-operator deployment has 1 unavailable replicas, hosted-cluster-config-operator deployment has 1 unavailable replicas, ingress-operator deployment has 1 unavailable replicas, olm-operator deployment has 1 unavailable replicas, packageserver deployment has 3 unavailable replicas, redhat-marketplace-catalog deployment has 2 unavailable replicas, redhat-operators-catalog deployment has 2 unavailable replicas, router deployment has 2 unavailable replicas] 2025-10-24 06:24:39 +0000 UTC hostedclusters kx-92792514a0 OIDC configuration is valid 2025-10-24 06:24:39 +0000 UTC hostedclusters kx-92792514a0 Reconciliation completed successfully 2025-10-24 06:24:59 +0000 UTC hostedclusters kx-92792514a0 All is well 2025-10-24 06:25:00 +0000 UTC hostedclusters kx-92792514a0 All is well 2025-10-24 06:25:27 +0000 UTC hostedclusters kx-92792514a0 EtcdAvailable QuorumAvailable 2025-10-24 06:25:52 +0000 UTC hostedclusters kx-92792514a0 Kube APIServer deployment is available 2025-10-24 06:26:06 +0000 UTC hostedclusters kx-92792514a0 All is well 2025-10-24 06:26:11 +0000 UTC hostedclusters kx-92792514a0 All is well 2025-10-24 06:26:16 +0000 UTC hostedclusters kx-92792514a0 Ignition server deployment is available 2025-10-24 06:26:21 +0000 UTC hostedclusters kx-92792514a0 Payload loaded version="4.17.41" image="quay.io/openshift-release-dev/ocp-release@sha256:57f09f90de7ab876109581cef6b2cf9da8ff62818bd9fb1503c0cc26d5a5d80a" architecture="Multi" 2025-10-24 06:26:21 +0000 UTC hostedclusters kx-92792514a0 Condition not found in the CVO. 2025-10-24 06:26:21 +0000 UTC hostedclusters kx-92792514a0 ClusterVersionAvailable FromClusterVersion 2025-10-24 06:26:21 +0000 UTC hostedclusters kx-92792514a0 Unable to apply 4.17.41: some cluster operators are not available 2025-10-24 06:26:58 +0000 UTC hostedclusters kx-92792514a0 Cluster operators console, dns, image-registry, ingress, insights, kube-storage-version-migrator, monitoring, node-tuning, openshift-samples, service-ca, storage are not available 2025-10-24 06:27:14 +0000 UTC hostedclusters kx-92792514a0 The hosted cluster is not degraded INFO: Cluster 'kx-92792514a0' is now ready INFO: ROSA with HCP cluster is ready, create a cluster admin account for accessing the cluster WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. INFO: Storing login command... INFO: Check if it's able to login to OCP cluster... Retried 1 times... INFO: Check if apiserver is ready... Waiting for cluster operators to be accessible for 2m... NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.17.41 True False False 4m9s dns 4.17.41 False False True 4m11s DNS "default" is unavailable. image-registry False True True 3m57s Available: The deployment does not have available replicas... ingress False True True 3m56s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.17.41 True False False 4m2s kube-controller-manager 4.17.41 True False False 4m2s kube-scheduler 4.17.41 True False False 4m1s kube-storage-version-migrator monitoring network 4.17.41 True True False 3m49s DaemonSet "/openshift-network-operator/iptables-alerter" is waiting for other operators to become ready... node-tuning False True False 3m33s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.17.41 True False False 4m2s openshift-controller-manager 4.17.41 True False False 4m2s openshift-samples operator-lifecycle-manager 4.17.41 True False False 4m4s operator-lifecycle-manager-catalog 4.17.41 True False False 3m54s operator-lifecycle-manager-packageserver 4.17.41 True False False 4m1s service-ca storage 4.17.41 False False False 4m1s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service cluster operators to be accessible finished! [INFO] Cluster operators are accessible. Waiting for cluster to be reported as healthy for 60m... NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.17.41 True False False 4m10s dns 4.17.41 False False True 4m12s DNS "default" is unavailable. image-registry False True True 3m58s Available: The deployment does not have available replicas... ingress False True True 3m57s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.17.41 True False False 4m3s kube-controller-manager 4.17.41 True False False 4m3s kube-scheduler 4.17.41 True False False 4m2s kube-storage-version-migrator monitoring network 4.17.41 True True False 3m50s DaemonSet "/openshift-network-operator/iptables-alerter" is waiting for other operators to become ready... node-tuning False True False 3m34s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.17.41 True False False 4m3s openshift-controller-manager 4.17.41 True False False 4m3s openshift-samples operator-lifecycle-manager 4.17.41 True False False 4m5s operator-lifecycle-manager-catalog 4.17.41 True False False 3m55s operator-lifecycle-manager-packageserver 4.17.41 True False False 4m2s service-ca storage 4.17.41 False False False 4m2s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.17.41 True False False 5m10s dns 4.17.41 False True True 5m12s DNS "default" is unavailable. image-registry False True True 4m58s Available: The deployment does not have available replicas... ingress False True True 4m57s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.17.41 True False False 5m3s kube-controller-manager 4.17.41 True False False 5m3s kube-scheduler 4.17.41 True False False 5m2s kube-storage-version-migrator monitoring network 4.17.41 True True False 4m50s DaemonSet "/openshift-multus/multus-additional-cni-plugins" is not available (awaiting 1 nodes)... node-tuning False True False 4m34s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.17.41 True False False 5m3s openshift-controller-manager 4.17.41 True False False 5m3s openshift-samples operator-lifecycle-manager 4.17.41 True False False 5m5s operator-lifecycle-manager-catalog 4.17.41 True False False 4m55s operator-lifecycle-manager-packageserver 4.17.41 True False False 5m2s service-ca storage 4.17.41 False True False 5m2s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.17.41 Unknown False False 10s csi-snapshot-controller 4.17.41 True False False 6m10s dns 4.17.41 False True True 6m12s DNS "default" is unavailable. image-registry False True True 5m58s Available: The deployment does not have available replicas... ingress False True True 5m57s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights 4.17.41 True False False 29s kube-apiserver 4.17.41 True False False 6m3s kube-controller-manager 4.17.41 True False False 6m3s kube-scheduler 4.17.41 True False False 6m2s kube-storage-version-migrator 4.17.41 True False False 25s monitoring network 4.17.41 True True False 5m50s DaemonSet "/openshift-multus/network-metrics-daemon" is waiting for other operators to become ready... node-tuning 4.17.41 True False False 47s openshift-apiserver 4.17.41 True False False 6m3s openshift-controller-manager 4.17.41 True False False 6m3s openshift-samples operator-lifecycle-manager 4.17.41 True False False 6m5s operator-lifecycle-manager-catalog 4.17.41 True False False 5m55s operator-lifecycle-manager-packageserver 4.17.41 True False False 6m2s service-ca 4.17.41 True False False 26s storage 4.17.41 True False False 44s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.17.41 True False False 48s csi-snapshot-controller 4.17.41 True False False 7m10s dns 4.17.41 True False False 54s image-registry 4.17.41 True True False 44s Progressing: The deployment has not completed... ingress 4.17.41 True False False 32s insights 4.17.41 True False False 89s kube-apiserver 4.17.41 True False False 7m3s kube-controller-manager 4.17.41 True False False 7m3s kube-scheduler 4.17.41 True False False 7m2s kube-storage-version-migrator 4.17.41 True False False 85s monitoring Unknown True Unknown 60s Rolling out the stack. network 4.17.41 True True False 6m50s DaemonSet "/openshift-multus/multus-additional-cni-plugins" is not available (awaiting 1 nodes)... node-tuning 4.17.41 True True False 26s Waiting for 1/3 Profiles to be applied openshift-apiserver 4.17.41 True False False 7m3s openshift-controller-manager 4.17.41 True False False 7m3s openshift-samples 4.17.41 True False False 44s operator-lifecycle-manager 4.17.41 True False False 7m5s operator-lifecycle-manager-catalog 4.17.41 True False False 6m55s operator-lifecycle-manager-packageserver 4.17.41 True False False 7m2s service-ca 4.17.41 True False False 86s storage 4.17.41 True False False 104s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.17.41 True False False 109s csi-snapshot-controller 4.17.41 True False False 8m11s dns 4.17.41 True False False 115s image-registry 4.17.41 True False False 105s ingress 4.17.41 True False False 93s insights 4.17.41 True False False 2m30s kube-apiserver 4.17.41 True False False 8m4s kube-controller-manager 4.17.41 True False False 8m4s kube-scheduler 4.17.41 True False False 8m3s kube-storage-version-migrator 4.17.41 True False False 2m26s monitoring Unknown True Unknown 2m1s Rolling out the stack. network 4.17.41 True False False 7m51s node-tuning 4.17.41 True False False 87s openshift-apiserver 4.17.41 True False False 8m4s openshift-controller-manager 4.17.41 True False False 8m4s openshift-samples 4.17.41 True False False 105s operator-lifecycle-manager 4.17.41 True False False 8m6s operator-lifecycle-manager-catalog 4.17.41 True False False 7m56s operator-lifecycle-manager-packageserver 4.17.41 True False False 8m3s service-ca 4.17.41 True False False 2m27s storage 4.17.41 True False False 2m45s Waiting for cluster to be reported as healthy... Trying again in 60s healthy cluster to be reported as healthy finished!