INFO: Log in to your Red Hat account... INFO: Configure AWS Credentials... WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. INFO: Logged in as 'rhtap-shared' on 'https://api.openshift.com' INFO: Create ROSA with HCP cluster... WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. INFO: Creating cluster 'kx-9051e5f132' INFO: To view a list of clusters and their status, run 'rosa list clusters' INFO: Cluster 'kx-9051e5f132' has been created. INFO: Once the cluster is installed you will need to add an Identity Provider before you can login into the cluster. See 'rosa create idp --help' for more information. Name: kx-9051e5f132 Domain Prefix: kx-9051e5f132 Display Name: kx-9051e5f132 ID: 2mcqc3d435k1vhce4m63p2bdr0j8sf5v External ID: ceca4f13-613d-4e24-abb1-8cbe94c84188 Control Plane: ROSA Service Hosted OpenShift Version: 4.17.42 Channel Group: stable DNS: Not ready AWS Account: 381492310364 AWS Billing Account: 381492310364 API URL: Console URL: Region: us-east-1 Availability: - Control Plane: MultiAZ - Data Plane: MultiAZ Nodes: - Compute (desired): 3 - Compute (current): 0 Network: - Type: OVNKubernetes - Service CIDR: 172.30.0.0/16 - Machine CIDR: 10.0.0.0/16 - Pod CIDR: 10.128.0.0/14 - Host Prefix: /23 - Subnets: subnet-0208a6297964e4fe1, subnet-0c161c939f7025e15, subnet-023e5c7b3016ed194, subnet-02dbd8abbf884d77f, subnet-0360c2d20442c5ba5, subnet-0aad9c992e402a91a EC2 Metadata Http Tokens: optional Role (STS) ARN: arn:aws:iam::381492310364:role/rhads-hcp-HCP-ROSA-Installer-Role Support Role ARN: arn:aws:iam::381492310364:role/rhads-hcp-HCP-ROSA-Support-Role Instance IAM Roles: - Worker: arn:aws:iam::381492310364:role/rhads-hcp-HCP-ROSA-Worker-Role Operator IAM Roles: - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-capa-controller-manager - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-control-plane-operator - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-kms-provider - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-kube-controller-manager - arn:aws:iam::381492310364:role/rhads-hcp-openshift-image-registry-installer-cloud-credentials - arn:aws:iam::381492310364:role/rhads-hcp-openshift-ingress-operator-cloud-credentials - arn:aws:iam::381492310364:role/rhads-hcp-openshift-cluster-csi-drivers-ebs-cloud-credentials - arn:aws:iam::381492310364:role/rhads-hcp-openshift-cloud-network-config-controller-cloud-creden Managed Policies: Yes State: waiting (Waiting for user action) Private: No Delete Protection: Disabled Created: Nov 6 2025 01:04:16 UTC [DEPRECATED] User Workload Monitoring: Enabled Details Page: https://console.redhat.com/openshift/details/s/355DUmTYwQwOm4MLKGbwy4YFaCT OIDC Endpoint URL: https://oidc.op1.openshiftapps.com/2jtsga3i2etnl697l7bk5i1kmbm4a95j (Managed) Etcd Encryption: Disabled Audit Log Forwarding: Disabled External Authentication: Disabled Zero Egress: Disabled INFO: Preparing to create operator roles. INFO: Operator Roles already exists INFO: Preparing to create OIDC Provider. INFO: OIDC provider already exists INFO: To determine when your cluster is Ready, run 'rosa describe cluster -c kx-9051e5f132'. INFO: To watch your cluster installation logs, run 'rosa logs install -c kx-9051e5f132 --watch'. INFO: Track the progress of the cluster creation... WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. W: Region flag will be removed from this command in future versions INFO: Cluster 'kx-9051e5f132' is in waiting state waiting for installation to begin. Logs will show up within 5 minutes 0001-01-01 00:00:00 +0000 UTC hostedclusters kx-9051e5f132 Version 2025-11-06 01:08:17 +0000 UTC hostedclusters kx-9051e5f132 ValidAWSIdentityProvider StatusUnknown 2025-11-06 01:08:18 +0000 UTC certificates cluster-api-cert Issuing certificate as Secret does not exist 2025-11-06 01:08:18 +0000 UTC certificates cluster-api-cert Issuing certificate as Secret does not exist 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 The hosted control plane is not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Condition not found in the CVO. 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 The hosted control plane is not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 The hosted control plane is not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Condition not found in the CVO. 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Condition not found in the CVO. 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Condition not found in the CVO. 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Condition not found in the CVO. 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 The hosted control plane is not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Ignition server deployment not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 HostedCluster is supported by operator configuration 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Release image is valid 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 The hosted control plane is not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Reconciliation active on resource 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 configuration is invalid: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 The hosted control plane is not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 The hosted control plane is not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 The hosted control plane is not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 The hosted control plane is not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Condition not found in the CVO. 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Condition not found in the CVO. 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Condition not found in the CVO. 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Condition not found in the CVO. 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 The hosted control plane is not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Ignition server deployment not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 HostedCluster is supported by operator configuration 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Release image is valid 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 The hosted control plane is not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Reconciliation active on resource 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 configuration is invalid: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 The hosted control plane is not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 The hosted control plane is not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 The hosted control plane is not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 The hosted control plane is not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Condition not found in the CVO. 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Condition not found in the CVO. 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Condition not found in the CVO. 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Condition not found in the CVO. 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 The hosted control plane is not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Ignition server deployment not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 HostedCluster is supported by operator configuration 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Release image is valid 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 The hosted control plane is not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Reconciliation active on resource 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 configuration is invalid: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 The hosted control plane is not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 The hosted control plane is not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 The hosted control plane is not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 The hosted control plane is not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Condition not found in the CVO. 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Condition not found in the CVO. 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Condition not found in the CVO. 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Condition not found in the CVO. 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 The hosted control plane is not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Ignition server deployment not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 HostedCluster is supported by operator configuration 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Release image is valid 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 The hosted control plane is not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Reconciliation active on resource 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 configuration is invalid: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 The hosted control plane is not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 The hosted control plane is not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 The hosted control plane is not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 The hosted control plane is not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Condition not found in the CVO. 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Condition not found in the CVO. 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Condition not found in the CVO. 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Condition not found in the CVO. 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 The hosted control plane is not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Ignition server deployment not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 HostedCluster is supported by operator configuration 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Release image is valid 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 The hosted control plane is not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Reconciliation active on resource 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 configuration is invalid: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 The hosted control plane is not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 The hosted control plane is not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 0001-01-01 00:00:00 +0000 UTC hostedclusters kx-9051e5f132 Version 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Release image is valid 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Waiting for hosted control plane kubeconfig to be created 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 HostedCluster is at expected version 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 HostedCluster is supported by operator configuration 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Ignition server deployment not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Condition not found in the CVO. 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Reconciliation active on resource 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Condition not found in the CVO. 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Condition not found in the CVO. 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Condition not found in the CVO. 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Condition not found in the CVO. 2025-11-06 01:09:43 +0000 UTC certificates cluster-api-cert Certificate is up to date and has not expired 2025-11-06 01:09:44 +0000 UTC hostedclusters kx-9051e5f132 Configuration passes validation 2025-11-06 01:09:45 +0000 UTC hostedclusters kx-9051e5f132 Required platform credentials are found 2025-11-06 01:09:47 +0000 UTC hostedclusters kx-9051e5f132 OIDC configuration is valid 2025-11-06 01:09:47 +0000 UTC hostedclusters kx-9051e5f132 Reconciliation completed successfully 2025-11-06 01:09:51 +0000 UTC hostedclusters kx-9051e5f132 AWS KMS is not configured 2025-11-06 01:09:51 +0000 UTC hostedclusters kx-9051e5f132 capi-provider deployment has 1 unavailable replicas 2025-11-06 01:09:51 +0000 UTC hostedclusters kx-9051e5f132 lookup api.kx-9051e5f132.fz6c.p3.openshiftapps.com on 172.30.0.10:53: no such host 2025-11-06 01:09:51 +0000 UTC hostedclusters kx-9051e5f132 Configuration passes validation 2025-11-06 01:09:51 +0000 UTC hostedclusters kx-9051e5f132 Waiting for etcd to reach quorum 2025-11-06 01:09:51 +0000 UTC hostedclusters kx-9051e5f132 Kube APIServer deployment not found 2025-11-06 01:10:14 +0000 UTC hostedclusters kx-9051e5f132 All is well 2025-11-06 01:10:14 +0000 UTC hostedclusters kx-9051e5f132 All is well 2025-11-06 01:10:20 +0000 UTC hostedclusters kx-9051e5f132 WebIdentityErr 0001-01-01 00:00:00 +0000 UTC hostedclusters kx-9051e5f132 Version 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Release image is valid 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Get "https://a9162bcff594d41239dda7b41efa6651-fc9742acf351ff2a.elb.us-east-1.amazonaws.com:443/healthz": dial tcp: lookup a9162bcff594d41239dda7b41efa6651-fc9742acf351ff2a.elb.us-east-1.amazonaws.com on 172.30.0.10:53: no such host 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 HostedCluster is at expected version 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 HostedCluster is supported by operator configuration 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Ignition server deployment not found 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Condition not found in the CVO. 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Reconciliation active on resource 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Condition not found in the CVO. 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Condition not found in the CVO. 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Condition not found in the CVO. 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Condition not found in the CVO. 2025-11-06 01:09:43 +0000 UTC certificates cluster-api-cert Certificate is up to date and has not expired 2025-11-06 01:09:44 +0000 UTC hostedclusters kx-9051e5f132 Configuration passes validation 2025-11-06 01:09:45 +0000 UTC hostedclusters kx-9051e5f132 Required platform credentials are found 2025-11-06 01:09:47 +0000 UTC hostedclusters kx-9051e5f132 OIDC configuration is valid 2025-11-06 01:09:47 +0000 UTC hostedclusters kx-9051e5f132 Reconciliation completed successfully 2025-11-06 01:09:51 +0000 UTC hostedclusters kx-9051e5f132 AWS KMS is not configured 2025-11-06 01:09:51 +0000 UTC hostedclusters kx-9051e5f132 [aws-cloud-controller-manager deployment has 1 unavailable replicas, capi-provider deployment has 2 unavailable replicas, catalog-operator deployment has 1 unavailable replicas, certified-operators-catalog deployment has 1 unavailable replicas, cloud-credential-operator deployment has 1 unavailable replicas, cluster-image-registry-operator deployment has 1 unavailable replicas, cluster-network-operator deployment has 1 unavailable replicas, cluster-node-tuning-operator deployment has 1 unavailable replicas, cluster-storage-operator deployment has 1 unavailable replicas, cluster-version-operator deployment has 1 unavailable replicas, community-operators-catalog deployment has 1 unavailable replicas, csi-snapshot-controller-operator deployment has 1 unavailable replicas, dns-operator deployment has 1 unavailable replicas, hosted-cluster-config-operator deployment has 1 unavailable replicas, ingress-operator deployment has 1 unavailable replicas, oauth-openshift deployment has 2 unavailable replicas, olm-operator deployment has 1 unavailable replicas, openshift-oauth-apiserver deployment has 2 unavailable replicas, packageserver deployment has 3 unavailable replicas, redhat-marketplace-catalog deployment has 1 unavailable replicas, redhat-operators-catalog deployment has 1 unavailable replicas, router deployment has 2 unavailable replicas] 2025-11-06 01:09:51 +0000 UTC hostedclusters kx-9051e5f132 lookup api.kx-9051e5f132.fz6c.p3.openshiftapps.com on 172.30.0.10:53: no such host 2025-11-06 01:09:51 +0000 UTC hostedclusters kx-9051e5f132 Configuration passes validation 2025-11-06 01:10:14 +0000 UTC hostedclusters kx-9051e5f132 All is well 2025-11-06 01:10:14 +0000 UTC hostedclusters kx-9051e5f132 All is well 2025-11-06 01:10:43 +0000 UTC hostedclusters kx-9051e5f132 EtcdAvailable QuorumAvailable 2025-11-06 01:11:07 +0000 UTC hostedclusters kx-9051e5f132 Kube APIServer deployment is available 2025-11-06 01:11:21 +0000 UTC hostedclusters kx-9051e5f132 All is well 2025-11-06 01:11:28 +0000 UTC hostedclusters kx-9051e5f132 All is well 2025-11-06 01:11:31 +0000 UTC hostedclusters kx-9051e5f132 Ignition server deployment is available 2025-11-06 01:11:55 +0000 UTC hostedclusters kx-9051e5f132 ClusterVersionAvailable FromClusterVersion 2025-11-06 01:11:55 +0000 UTC hostedclusters kx-9051e5f132 ClusterVersionSucceeding FromClusterVersion 2025-11-06 01:11:55 +0000 UTC hostedclusters kx-9051e5f132 Condition not found in the CVO. 2025-11-06 01:11:55 +0000 UTC hostedclusters kx-9051e5f132 Working towards 4.17.42: 524 of 621 done (84% complete) 2025-11-06 01:11:55 +0000 UTC hostedclusters kx-9051e5f132 Payload loaded version="4.17.42" image="quay.io/openshift-release-dev/ocp-release@sha256:9b7b9909a1f064d5238f35f6e5fc9ac275a0d463a74e8c545544755d953a46d9" architecture="Multi" 2025-11-06 01:12:31 +0000 UTC hostedclusters kx-9051e5f132 Multiple errors are preventing progress: * Cluster operators console, dns, ingress, insights, kube-storage-version-migrator, monitoring, network, node-tuning, openshift-samples, service-ca are not available * Could not update imagestream "openshift/driver-toolkit" (438 of 621): resource may have been deleted * Could not update operatorgroup "openshift-monitoring/openshift-cluster-monitoring" (550 of 621): resource may have been deleted * Could not update role "openshift-authentication/prometheus-k8s" (537 of 621): resource may have been deleted * Could not update role "openshift-console-operator/prometheus-k8s" (579 of 621): resource may have been deleted * Could not update role "openshift-console/prometheus-k8s" (583 of 621): resource may have been deleted * Could not update role "openshift-ingress-operator/prometheus-k8s" (590 of 621): resource may have been deleted * Could not update role "openshift-kube-apiserver-operator/prometheus-k8s" (594 of 621): resource may have been deleted 0001-01-01 00:00:00 +0000 UTC hostedclusters kx-9051e5f132 Version 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 HostedCluster is at expected version 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Reconciliation active on resource 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 Release image is valid 2025-11-06 01:08:20 +0000 UTC hostedclusters kx-9051e5f132 HostedCluster is supported by operator configuration 2025-11-06 01:09:43 +0000 UTC certificates cluster-api-cert Certificate is up to date and has not expired 2025-11-06 01:09:44 +0000 UTC hostedclusters kx-9051e5f132 Configuration passes validation 2025-11-06 01:09:45 +0000 UTC hostedclusters kx-9051e5f132 Required platform credentials are found 2025-11-06 01:09:47 +0000 UTC hostedclusters kx-9051e5f132 Reconciliation completed successfully 2025-11-06 01:09:47 +0000 UTC hostedclusters kx-9051e5f132 OIDC configuration is valid 2025-11-06 01:09:51 +0000 UTC hostedclusters kx-9051e5f132 Configuration passes validation 2025-11-06 01:09:51 +0000 UTC hostedclusters kx-9051e5f132 AWS KMS is not configured 2025-11-06 01:10:14 +0000 UTC hostedclusters kx-9051e5f132 All is well 2025-11-06 01:10:14 +0000 UTC hostedclusters kx-9051e5f132 All is well 2025-11-06 01:10:43 +0000 UTC hostedclusters kx-9051e5f132 EtcdAvailable QuorumAvailable 2025-11-06 01:11:07 +0000 UTC hostedclusters kx-9051e5f132 Kube APIServer deployment is available 2025-11-06 01:11:21 +0000 UTC hostedclusters kx-9051e5f132 All is well 2025-11-06 01:11:28 +0000 UTC hostedclusters kx-9051e5f132 All is well 2025-11-06 01:11:31 +0000 UTC hostedclusters kx-9051e5f132 Ignition server deployment is available 2025-11-06 01:11:55 +0000 UTC hostedclusters kx-9051e5f132 Unable to apply 4.17.42: some cluster operators are not available 2025-11-06 01:11:55 +0000 UTC hostedclusters kx-9051e5f132 Condition not found in the CVO. 2025-11-06 01:11:55 +0000 UTC hostedclusters kx-9051e5f132 Payload loaded version="4.17.42" image="quay.io/openshift-release-dev/ocp-release@sha256:9b7b9909a1f064d5238f35f6e5fc9ac275a0d463a74e8c545544755d953a46d9" architecture="Multi" 2025-11-06 01:11:55 +0000 UTC hostedclusters kx-9051e5f132 ClusterVersionAvailable FromClusterVersion 2025-11-06 01:12:31 +0000 UTC hostedclusters kx-9051e5f132 Cluster operators console, dns, image-registry, ingress, insights, kube-storage-version-migrator, monitoring, node-tuning, openshift-samples, service-ca, storage are not available 2025-11-06 01:12:42 +0000 UTC hostedclusters kx-9051e5f132 The hosted cluster is not degraded 2025-11-06 01:12:47 +0000 UTC hostedclusters kx-9051e5f132 The hosted control plane is available INFO: Cluster 'kx-9051e5f132' is now ready INFO: ROSA with HCP cluster is ready, create a cluster admin account for accessing the cluster WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. INFO: Storing login command... INFO: Check if it's able to login to OCP cluster... Retried 1 times... INFO: Check if apiserver is ready... Waiting for cluster operators to be accessible for 2m... NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.17.42 True False False 4m9s dns 4.17.42 False False True 4m10s DNS "default" is unavailable. image-registry False True True 3m58s Available: The deployment does not have available replicas... ingress False True True 3m52s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.17.42 True False False 4m2s kube-controller-manager 4.17.42 True False False 4m2s kube-scheduler 4.17.42 True False False 4m2s kube-storage-version-migrator monitoring network 4.17.42 True True False 3m45s DaemonSet "/openshift-multus/network-metrics-daemon" is waiting for other operators to become ready... node-tuning False True False 4m13s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.17.42 True False False 4m2s openshift-controller-manager 4.17.42 True False False 4m2s openshift-samples operator-lifecycle-manager 4.17.42 True False False 4m3s operator-lifecycle-manager-catalog 4.17.42 True False False 3m49s operator-lifecycle-manager-packageserver 4.17.42 True False False 4m2s service-ca storage 4.17.42 False False False 4m2s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service cluster operators to be accessible finished! [INFO] Cluster operators are accessible. Waiting for cluster to be reported as healthy for 60m... NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.17.42 True False False 4m9s dns 4.17.42 False False True 4m10s DNS "default" is unavailable. image-registry False True True 3m58s Available: The deployment does not have available replicas... ingress False True True 3m52s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.17.42 True False False 4m2s kube-controller-manager 4.17.42 True False False 4m2s kube-scheduler 4.17.42 True False False 4m2s kube-storage-version-migrator monitoring network 4.17.42 True True False 3m45s DaemonSet "/openshift-multus/network-metrics-daemon" is waiting for other operators to become ready... node-tuning False True False 4m13s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.17.42 True False False 4m2s openshift-controller-manager 4.17.42 True False False 4m2s openshift-samples operator-lifecycle-manager 4.17.42 True False False 4m3s operator-lifecycle-manager-catalog 4.17.42 True False False 3m49s operator-lifecycle-manager-packageserver 4.17.42 True False False 4m2s service-ca storage 4.17.42 False False False 4m2s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.17.42 True False False 5m9s dns 4.17.42 False False True 5m10s DNS "default" is unavailable. image-registry False True True 4m58s Available: The deployment does not have available replicas... ingress False True True 4m52s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.17.42 True False False 5m2s kube-controller-manager 4.17.42 True False False 5m2s kube-scheduler 4.17.42 True False False 5m2s kube-storage-version-migrator monitoring network 4.17.42 True True False 4m45s DaemonSet "/openshift-multus/network-metrics-daemon" is waiting for other operators to become ready... node-tuning False True False 5m13s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.17.42 True False False 5m2s openshift-controller-manager 4.17.42 True False False 5m2s openshift-samples operator-lifecycle-manager 4.17.42 True False False 5m3s operator-lifecycle-manager-catalog 4.17.42 True False False 4m49s operator-lifecycle-manager-packageserver 4.17.42 True False False 5m2s service-ca storage 4.17.42 False False False 5m2s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.17.42 True False False 6m9s dns 4.17.42 False False True 6m10s DNS "default" is unavailable. image-registry False True True 5m58s Available: The deployment does not have available replicas... ingress False True True 5m52s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.17.42 True False False 6m2s kube-controller-manager 4.17.42 True False False 6m2s kube-scheduler 4.17.42 True False False 6m2s kube-storage-version-migrator monitoring network 4.17.42 True True False 5m45s DaemonSet "/openshift-multus/network-metrics-daemon" is waiting for other operators to become ready... node-tuning False True False 6m13s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.17.42 True False False 6m2s openshift-controller-manager 4.17.42 True False False 6m2s openshift-samples operator-lifecycle-manager 4.17.42 True False False 6m3s operator-lifecycle-manager-catalog 4.17.42 True False False 5m49s operator-lifecycle-manager-packageserver 4.17.42 True False False 6m2s service-ca storage 4.17.42 False False False 6m2s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.17.42 True False False 7m10s dns 4.17.42 False False True 7m11s DNS "default" is unavailable. image-registry False True True 6m59s Available: The deployment does not have available replicas... ingress False True True 6m53s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.17.42 True False False 7m3s kube-controller-manager 4.17.42 True False False 7m3s kube-scheduler 4.17.42 True False False 7m3s kube-storage-version-migrator monitoring network 4.17.42 True True False 6m46s DaemonSet "/openshift-multus/network-metrics-daemon" is waiting for other operators to become ready... node-tuning False True False 7m14s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.17.42 True False False 7m3s openshift-controller-manager 4.17.42 True False False 7m3s openshift-samples operator-lifecycle-manager 4.17.42 True False False 7m4s operator-lifecycle-manager-catalog 4.17.42 True False False 6m50s operator-lifecycle-manager-packageserver 4.17.42 True False False 7m3s service-ca storage 4.17.42 False False False 7m3s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.17.42 True False False 8m10s dns 4.17.42 False True True 8m11s DNS "default" is unavailable. image-registry False True True 7m59s Available: The deployment does not have available replicas... ingress False True True 7m53s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.17.42 True False False 8m3s kube-controller-manager 4.17.42 True False False 8m3s kube-scheduler 4.17.42 True False False 8m3s kube-storage-version-migrator monitoring network 4.17.42 True True False 7m46s DaemonSet "/openshift-ovn-kubernetes/ovnkube-node" is not available (awaiting 3 nodes)... node-tuning 4.17.42 True True False 16s Waiting for 3/3 Profiles to be applied openshift-apiserver 4.17.42 True False False 8m3s openshift-controller-manager 4.17.42 True False False 8m3s openshift-samples operator-lifecycle-manager 4.17.42 True False False 8m4s operator-lifecycle-manager-catalog 4.17.42 True False False 7m50s operator-lifecycle-manager-packageserver 4.17.42 True False False 8m3s service-ca storage 4.17.42 True True False 12s AWSEBSCSIDriverOperatorCRProgressing: AWSEBSDriverNodeServiceControllerProgressing: Waiting for DaemonSet to deploy node pods Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.17.42 True False False 9m10s dns 4.17.42 False True True 9m11s DNS "default" is unavailable. image-registry False True True 8m59s Available: The deployment does not have available replicas... ingress False True True 8m53s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.17.42 True False False 9m3s kube-controller-manager 4.17.42 True False False 9m3s kube-scheduler 4.17.42 True False False 9m3s kube-storage-version-migrator monitoring network 4.17.42 True True False 8m46s DaemonSet "/openshift-multus/network-metrics-daemon" is waiting for other operators to become ready... node-tuning 4.17.42 True False False 76s openshift-apiserver 4.17.42 True False False 9m3s openshift-controller-manager 4.17.42 True False False 9m3s openshift-samples operator-lifecycle-manager 4.17.42 True False False 9m4s operator-lifecycle-manager-catalog 4.17.42 True False False 8m50s operator-lifecycle-manager-packageserver 4.17.42 True False False 9m3s service-ca storage 4.17.42 True False False 72s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.17.42 Unknown False False 11s csi-snapshot-controller 4.17.42 True False False 10m dns 4.17.42 False True True 10m DNS "default" is unavailable. image-registry False True True 9m59s Available: The deployment does not have available replicas... ingress False True True 9m53s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights 4.17.42 True False False 31s kube-apiserver 4.17.42 True False False 10m kube-controller-manager 4.17.42 True False False 10m kube-scheduler 4.17.42 True False False 10m kube-storage-version-migrator 4.17.42 True False False 28s monitoring Unknown True Unknown 1s Rolling out the stack. network 4.17.42 True True False 9m46s DaemonSet "/openshift-multus/network-metrics-daemon" is not available (awaiting 2 nodes) node-tuning 4.17.42 True False False 2m16s openshift-apiserver 4.17.42 True False False 10m openshift-controller-manager 4.17.42 True False False 10m openshift-samples operator-lifecycle-manager 4.17.42 True False False 10m operator-lifecycle-manager-catalog 4.17.42 True False False 9m50s operator-lifecycle-manager-packageserver 4.17.42 True False False 10m service-ca 4.17.42 True False False 28s storage 4.17.42 True False False 2m12s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.17.42 True False False 22s csi-snapshot-controller 4.17.42 True False False 11m dns 4.17.42 True True False 19s DNS "default" reports Progressing=True: "Have 2 available DNS pods, want 3." image-registry 4.17.42 True False False 14s ingress 4.17.42 True False True 33s The "default" ingress controller reports Degraded=True: DegradedConditions: One or more other status conditions indicate a degraded state: CanaryChecksSucceeding=Unknown (CanaryRouteNotAdmitted: Canary route is not admitted by the default ingress controller) insights 4.17.42 True False False 92s kube-apiserver 4.17.42 True False False 11m kube-controller-manager 4.17.42 True False False 11m kube-scheduler 4.17.42 True False False 11m kube-storage-version-migrator 4.17.42 True False False 89s monitoring Unknown True Unknown 62s Rolling out the stack. network 4.17.42 True True False 10m DaemonSet "/openshift-multus/network-metrics-daemon" is not available (awaiting 2 nodes) node-tuning 4.17.42 True False False 3m17s openshift-apiserver 4.17.42 True False False 11m openshift-controller-manager 4.17.42 True False False 11m openshift-samples 4.17.42 True False False 6s operator-lifecycle-manager 4.17.42 True False False 11m operator-lifecycle-manager-catalog 4.17.42 True False False 10m operator-lifecycle-manager-packageserver 4.17.42 True False False 11m service-ca 4.17.42 True False False 89s storage 4.17.42 True False False 3m13s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.17.42 True True False 82s SyncLoopRefreshProgressing: working toward version 4.17.42, 1 replicas available csi-snapshot-controller 4.17.42 True False False 12m dns 4.17.42 True False False 79s image-registry 4.17.42 True False False 34s ingress 4.17.42 True False False 93s insights 4.17.42 True False False 2m32s kube-apiserver 4.17.42 True False False 12m kube-controller-manager 4.17.42 True False False 12m kube-scheduler 4.17.42 True False False 12m kube-storage-version-migrator 4.17.42 True False False 2m29s monitoring Unknown True Unknown 2m2s Rolling out the stack. network 4.17.42 True False False 11m node-tuning 4.17.42 True False False 4m17s openshift-apiserver 4.17.42 True False False 12m openshift-controller-manager 4.17.42 True False False 12m openshift-samples 4.17.42 True False False 66s operator-lifecycle-manager 4.17.42 True False False 12m operator-lifecycle-manager-catalog 4.17.42 True False False 11m operator-lifecycle-manager-packageserver 4.17.42 True False False 12m service-ca 4.17.42 True False False 2m29s storage 4.17.42 True False False 4m13s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.17.42 True False False 2m22s csi-snapshot-controller 4.17.42 True False False 13m dns 4.17.42 True False False 2m19s image-registry 4.17.42 True False False 94s ingress 4.17.42 True False False 2m33s insights 4.17.42 True False False 3m32s kube-apiserver 4.17.42 True False False 13m kube-controller-manager 4.17.42 True False False 13m kube-scheduler 4.17.42 True False False 13m kube-storage-version-migrator 4.17.42 True False False 3m29s monitoring 4.17.42 True False False 57s network 4.17.42 True False False 12m node-tuning 4.17.42 True False False 5m17s openshift-apiserver 4.17.42 True False False 13m openshift-controller-manager 4.17.42 True False False 13m openshift-samples 4.17.42 True False False 2m6s operator-lifecycle-manager 4.17.42 True False False 13m operator-lifecycle-manager-catalog 4.17.42 True False False 12m operator-lifecycle-manager-packageserver 4.17.42 True False False 13m service-ca 4.17.42 True False False 3m29s storage 4.17.42 True False False 5m13s Waiting for cluster to be reported as healthy... Trying again in 60s healthy cluster to be reported as healthy finished!