INFO: Log in to your Red Hat account... INFO: Configure AWS Credentials... WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. INFO: Logged in as 'rhtap-shared' on 'https://api.openshift.com' INFO: Create ROSA with HCP cluster... WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. INFO: Creating cluster 'kx-4cdce9d4e9' INFO: To view a list of clusters and their status, run 'rosa list clusters' INFO: Cluster 'kx-4cdce9d4e9' has been created. INFO: Once the cluster is installed you will need to add an Identity Provider before you can login into the cluster. See 'rosa create idp --help' for more information. Name: kx-4cdce9d4e9 Domain Prefix: kx-4cdce9d4e9 Display Name: kx-4cdce9d4e9 ID: 2mem6djr0lcnt13t441bgbh06f5sjfsd External ID: 5454262a-e423-491b-904a-07f1de27ed01 Control Plane: ROSA Service Hosted OpenShift Version: 4.17.42 Channel Group: stable DNS: Not ready AWS Account: 381492310364 AWS Billing Account: 381492310364 API URL: Console URL: Region: us-east-1 Availability: - Control Plane: MultiAZ - Data Plane: MultiAZ Nodes: - Compute (desired): 3 - Compute (current): 0 Network: - Type: OVNKubernetes - Service CIDR: 172.30.0.0/16 - Machine CIDR: 10.0.0.0/16 - Pod CIDR: 10.128.0.0/14 - Host Prefix: /23 - Subnets: subnet-0208a6297964e4fe1, subnet-0c161c939f7025e15, subnet-023e5c7b3016ed194, subnet-02dbd8abbf884d77f, subnet-0360c2d20442c5ba5, subnet-0aad9c992e402a91a EC2 Metadata Http Tokens: optional Role (STS) ARN: arn:aws:iam::381492310364:role/rhads-hcp-HCP-ROSA-Installer-Role Support Role ARN: arn:aws:iam::381492310364:role/rhads-hcp-HCP-ROSA-Support-Role Instance IAM Roles: - Worker: arn:aws:iam::381492310364:role/rhads-hcp-HCP-ROSA-Worker-Role Operator IAM Roles: - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-capa-controller-manager - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-control-plane-operator - arn:aws:iam::381492310364:role/rhads-hcp-openshift-image-registry-installer-cloud-credentials - arn:aws:iam::381492310364:role/rhads-hcp-openshift-ingress-operator-cloud-credentials - arn:aws:iam::381492310364:role/rhads-hcp-openshift-cluster-csi-drivers-ebs-cloud-credentials - arn:aws:iam::381492310364:role/rhads-hcp-openshift-cloud-network-config-controller-cloud-creden - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-kms-provider - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-kube-controller-manager Managed Policies: Yes State: waiting (Waiting for user action) Private: No Delete Protection: Disabled Created: Nov 8 2025 21:08:09 UTC [DEPRECATED] User Workload Monitoring: Enabled Details Page: https://console.redhat.com/openshift/details/s/35DE9MnrBnDhUyp63z0cHjkUIhF OIDC Endpoint URL: https://oidc.op1.openshiftapps.com/2jtsga3i2etnl697l7bk5i1kmbm4a95j (Managed) Etcd Encryption: Disabled Audit Log Forwarding: Disabled External Authentication: Disabled Zero Egress: Disabled INFO: Preparing to create operator roles. INFO: Operator Roles already exists INFO: Preparing to create OIDC Provider. INFO: OIDC provider already exists INFO: To determine when your cluster is Ready, run 'rosa describe cluster -c kx-4cdce9d4e9'. INFO: To watch your cluster installation logs, run 'rosa logs install -c kx-4cdce9d4e9 --watch'. INFO: Track the progress of the cluster creation... WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. W: Region flag will be removed from this command in future versions INFO: Cluster 'kx-4cdce9d4e9' is in waiting state waiting for installation to begin. Logs will show up within 5 minutes 0001-01-01 00:00:00 +0000 UTC hostedclusters kx-4cdce9d4e9 Version 2025-11-08 21:11:29 +0000 UTC hostedclusters kx-4cdce9d4e9 ValidAWSIdentityProvider StatusUnknown 2025-11-08 21:11:30 +0000 UTC hostedclusters kx-4cdce9d4e9 The hosted control plane is not found 2025-11-08 21:11:30 +0000 UTC hostedclusters kx-4cdce9d4e9 Condition not found in the CVO. 2025-11-08 21:11:30 +0000 UTC hostedclusters kx-4cdce9d4e9 The hosted control plane is not found 2025-11-08 21:11:30 +0000 UTC hostedclusters kx-4cdce9d4e9 The hosted control plane is not found 2025-11-08 21:11:30 +0000 UTC hostedclusters kx-4cdce9d4e9 ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-11-08 21:11:30 +0000 UTC hostedclusters kx-4cdce9d4e9 The hosted control plane is not found 2025-11-08 21:11:30 +0000 UTC hostedclusters kx-4cdce9d4e9 The hosted control plane is not found 2025-11-08 21:11:30 +0000 UTC hostedclusters kx-4cdce9d4e9 Condition not found in the CVO. 2025-11-08 21:11:30 +0000 UTC hostedclusters kx-4cdce9d4e9 Condition not found in the CVO. 2025-11-08 21:11:30 +0000 UTC hostedclusters kx-4cdce9d4e9 Ignition server deployment not found 2025-11-08 21:11:30 +0000 UTC hostedclusters kx-4cdce9d4e9 The hosted control plane is not found 2025-11-08 21:11:30 +0000 UTC hostedclusters kx-4cdce9d4e9 Condition not found in the CVO. 2025-11-08 21:11:30 +0000 UTC hostedclusters kx-4cdce9d4e9 Condition not found in the CVO. 2025-11-08 21:11:30 +0000 UTC hostedclusters kx-4cdce9d4e9 NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-11-08 21:11:30 +0000 UTC hostedclusters kx-4cdce9d4e9 HostedCluster is supported by operator configuration 2025-11-08 21:11:30 +0000 UTC hostedclusters kx-4cdce9d4e9 Release image is valid 2025-11-08 21:11:30 +0000 UTC hostedclusters kx-4cdce9d4e9 The hosted control plane is not found 2025-11-08 21:11:30 +0000 UTC hostedclusters kx-4cdce9d4e9 Reconciliation active on resource 2025-11-08 21:11:30 +0000 UTC certificates cluster-api-cert Issuing certificate as Secret does not exist 2025-11-08 21:11:30 +0000 UTC certificates cluster-api-cert Issuing certificate as Secret does not exist 2025-11-08 21:11:31 +0000 UTC hostedclusters kx-4cdce9d4e9 ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-11-08 21:11:31 +0000 UTC hostedclusters kx-4cdce9d4e9 configuration is invalid: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-11-08 21:11:31 +0000 UTC hostedclusters kx-4cdce9d4e9 HostedCluster is at expected version 2025-11-08 21:12:58 +0000 UTC certificates cluster-api-cert Certificate is up to date and has not expired 2025-11-08 21:12:59 +0000 UTC hostedclusters kx-4cdce9d4e9 Configuration passes validation 2025-11-08 21:13:01 +0000 UTC hostedclusters kx-4cdce9d4e9 Required platform credentials are found 2025-11-08 21:13:05 +0000 UTC hostedclusters kx-4cdce9d4e9 OIDC configuration is valid 2025-11-08 21:13:05 +0000 UTC hostedclusters kx-4cdce9d4e9 Reconciliation completed successfully 2025-11-08 21:13:07 +0000 UTC hostedclusters kx-4cdce9d4e9 AWS KMS is not configured 2025-11-08 21:13:07 +0000 UTC hostedclusters kx-4cdce9d4e9 capi-provider deployment has 1 unavailable replicas 2025-11-08 21:13:07 +0000 UTC hostedclusters kx-4cdce9d4e9 lookup api.kx-4cdce9d4e9.jf0s.p3.openshiftapps.com on 172.30.0.10:53: no such host 2025-11-08 21:13:07 +0000 UTC hostedclusters kx-4cdce9d4e9 Configuration passes validation 2025-11-08 21:13:07 +0000 UTC hostedclusters kx-4cdce9d4e9 Waiting for etcd to reach quorum 2025-11-08 21:13:07 +0000 UTC hostedclusters kx-4cdce9d4e9 Kube APIServer deployment not found 2025-11-08 21:13:30 +0000 UTC hostedclusters kx-4cdce9d4e9 All is well 2025-11-08 21:13:31 +0000 UTC hostedclusters kx-4cdce9d4e9 All is well 2025-11-08 21:13:37 +0000 UTC hostedclusters kx-4cdce9d4e9 WebIdentityErr 2025-11-08 21:14:03 +0000 UTC hostedclusters kx-4cdce9d4e9 EtcdAvailable QuorumAvailable 2025-11-08 21:14:27 +0000 UTC hostedclusters kx-4cdce9d4e9 Kube APIServer deployment is available 2025-11-08 21:14:53 +0000 UTC hostedclusters kx-4cdce9d4e9 Ignition server deployment is available 2025-11-08 21:15:07 +0000 UTC hostedclusters kx-4cdce9d4e9 All is well 2025-11-08 21:15:11 +0000 UTC hostedclusters kx-4cdce9d4e9 All is well 2025-11-08 21:15:20 +0000 UTC hostedclusters kx-4cdce9d4e9 Unable to apply 4.17.42: some cluster operators are not available 2025-11-08 21:15:20 +0000 UTC hostedclusters kx-4cdce9d4e9 Condition not found in the CVO. 2025-11-08 21:15:20 +0000 UTC hostedclusters kx-4cdce9d4e9 Payload loaded version="4.17.42" image="quay.io/openshift-release-dev/ocp-release@sha256:9b7b9909a1f064d5238f35f6e5fc9ac275a0d463a74e8c545544755d953a46d9" architecture="Multi" 2025-11-08 21:15:20 +0000 UTC hostedclusters kx-4cdce9d4e9 ClusterVersionAvailable FromClusterVersion 2025-11-08 21:15:56 +0000 UTC hostedclusters kx-4cdce9d4e9 Cluster operators console, dns, image-registry, ingress, insights, kube-storage-version-migrator, monitoring, node-tuning, openshift-samples, service-ca, storage are not available 2025-11-08 21:16:02 +0000 UTC hostedclusters kx-4cdce9d4e9 The hosted control plane is available INFO: Cluster 'kx-4cdce9d4e9' is now ready INFO: ROSA with HCP cluster is ready, create a cluster admin account for accessing the cluster WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. INFO: Storing login command... INFO: Check if it's able to login to OCP cluster... Retried 1 times... Retried 2 times... Retried 3 times... Retried 4 times... INFO: Check if apiserver is ready... Waiting for cluster operators to be accessible for 2m... NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.17.42 True False False 6m51s dns 4.17.42 False False True 6m51s DNS "default" is unavailable. image-registry False True True 6m2s Available: The deployment does not have available replicas... ingress False True True 6m28s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.17.42 True False False 6m44s kube-controller-manager 4.17.42 True False False 6m44s kube-scheduler 4.17.42 True False False 6m44s kube-storage-version-migrator monitoring network 4.17.42 True True False 6m22s DaemonSet "/openshift-network-operator/iptables-alerter" is waiting for other operators to become ready... node-tuning False True False 6m55s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.17.42 True False False 6m44s openshift-controller-manager 4.17.42 True False False 6m44s openshift-samples operator-lifecycle-manager 4.17.42 True False False 6m47s operator-lifecycle-manager-catalog 4.17.42 True False False 6m44s operator-lifecycle-manager-packageserver 4.17.42 True False False 6m43s service-ca storage 4.17.42 False False False 6m43s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service cluster operators to be accessible finished! [INFO] Cluster operators are accessible. Waiting for cluster to be reported as healthy for 60m... NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.17.42 True False False 6m51s dns 4.17.42 False False True 6m51s DNS "default" is unavailable. image-registry False True True 6m2s Available: The deployment does not have available replicas... ingress False True True 6m28s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.17.42 True False False 6m44s kube-controller-manager 4.17.42 True False False 6m44s kube-scheduler 4.17.42 True False False 6m44s kube-storage-version-migrator monitoring network 4.17.42 True True False 6m22s DaemonSet "/openshift-network-operator/iptables-alerter" is waiting for other operators to become ready... node-tuning False True False 6m55s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.17.42 True False False 6m44s openshift-controller-manager 4.17.42 True False False 6m44s openshift-samples operator-lifecycle-manager 4.17.42 True False False 6m47s operator-lifecycle-manager-catalog 4.17.42 True False False 6m44s operator-lifecycle-manager-packageserver 4.17.42 True False False 6m43s service-ca storage 4.17.42 False False False 6m43s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.17.42 True False False 7m51s dns 4.17.42 False False True 7m51s DNS "default" is unavailable. image-registry False True True 7m2s Available: The deployment does not have available replicas... ingress False True True 7m28s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.17.42 True False False 7m44s kube-controller-manager 4.17.42 True False False 7m44s kube-scheduler 4.17.42 True False False 7m44s kube-storage-version-migrator monitoring network 4.17.42 True True False 7m22s DaemonSet "/openshift-multus/multus-additional-cni-plugins" is not available (awaiting 3 nodes)... node-tuning 4.17.42 True True False 1s Waiting for 3/3 Profiles to be applied openshift-apiserver 4.17.42 True False False 7m44s openshift-controller-manager 4.17.42 True False False 7m44s openshift-samples operator-lifecycle-manager 4.17.42 True False False 7m47s operator-lifecycle-manager-catalog 4.17.42 True False False 7m44s operator-lifecycle-manager-packageserver 4.17.42 True False False 7m43s service-ca storage 4.17.42 False True False 7m43s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.17.42 True False False 8m52s dns 4.17.42 False True True 8m52s DNS "default" is unavailable. image-registry False True True 8m3s Available: The deployment does not have available replicas... ingress False True True 8m29s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.17.42 True False False 8m45s kube-controller-manager 4.17.42 True False False 8m45s kube-scheduler 4.17.42 True False False 8m45s kube-storage-version-migrator monitoring network 4.17.42 True True False 8m23s DaemonSet "/openshift-multus/network-metrics-daemon" is waiting for other operators to become ready... node-tuning 4.17.42 True False False 62s openshift-apiserver 4.17.42 True False False 8m45s openshift-controller-manager 4.17.42 True False False 8m45s openshift-samples operator-lifecycle-manager 4.17.42 True False False 8m48s operator-lifecycle-manager-catalog 4.17.42 True False False 8m45s operator-lifecycle-manager-packageserver 4.17.42 True False False 8m44s service-ca storage 4.17.42 True False False 58s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.17.42 Unknown False False 19s csi-snapshot-controller 4.17.42 True False False 9m52s dns 4.17.42 False True True 9m52s DNS "default" is unavailable. image-registry False True True 9m3s Available: The deployment does not have available replicas... ingress False True True 9m29s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights 4.17.42 True False False 37s kube-apiserver 4.17.42 True False False 9m45s kube-controller-manager 4.17.42 True False False 9m45s kube-scheduler 4.17.42 True False False 9m45s kube-storage-version-migrator 4.17.42 True False False 33s monitoring Unknown True Unknown 22s Rolling out the stack. network 4.17.42 True False False 9m23s node-tuning 4.17.42 True False False 2m2s openshift-apiserver 4.17.42 True False False 9m45s openshift-controller-manager 4.17.42 True False False 9m45s openshift-samples operator-lifecycle-manager 4.17.42 True False False 9m48s operator-lifecycle-manager-catalog 4.17.42 True False False 9m45s operator-lifecycle-manager-packageserver 4.17.42 True False False 9m44s service-ca 4.17.42 True False False 35s storage 4.17.42 True False False 118s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.17.42 True False False 10s csi-snapshot-controller 4.17.42 True False False 10m dns 4.17.42 True False False 17s image-registry 4.17.42 False True False 5s Available: The deployment does not have available replicas... ingress 4.17.42 True False False 38s insights 4.17.42 True False False 97s kube-apiserver 4.17.42 True False False 10m kube-controller-manager 4.17.42 True False False 10m kube-scheduler 4.17.42 True False False 10m kube-storage-version-migrator 4.17.42 True False False 93s monitoring Unknown True Unknown 82s Rolling out the stack. network 4.17.42 True False False 10m node-tuning 4.17.42 True False False 3m2s openshift-apiserver 4.17.42 True False False 10m openshift-controller-manager 4.17.42 True False False 10m openshift-samples 4.17.42 True False False 10s operator-lifecycle-manager 4.17.42 True False False 10m operator-lifecycle-manager-catalog 4.17.42 True False False 10m operator-lifecycle-manager-packageserver 4.17.42 True False False 10m service-ca 4.17.42 True False False 95s storage 4.17.42 True False False 2m58s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.17.42 True False False 70s csi-snapshot-controller 4.17.42 True False False 11m dns 4.17.42 True False False 77s image-registry 4.17.42 True False False 45s ingress 4.17.42 True False False 98s insights 4.17.42 True False False 2m37s kube-apiserver 4.17.42 True False False 11m kube-controller-manager 4.17.42 True False False 11m kube-scheduler 4.17.42 True False False 11m kube-storage-version-migrator 4.17.42 True False False 2m33s monitoring Unknown True Unknown 2m22s Rolling out the stack. network 4.17.42 True False False 11m node-tuning 4.17.42 True False False 4m2s openshift-apiserver 4.17.42 True False False 11m openshift-controller-manager 4.17.42 True False False 11m openshift-samples 4.17.42 True False False 70s operator-lifecycle-manager 4.17.42 True False False 11m operator-lifecycle-manager-catalog 4.17.42 True False False 11m operator-lifecycle-manager-packageserver 4.17.42 True False False 11m service-ca 4.17.42 True False False 2m35s storage 4.17.42 True False False 3m58s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.17.42 True False False 2m11s csi-snapshot-controller 4.17.42 True False False 12m dns 4.17.42 True False False 2m18s image-registry 4.17.42 True False False 106s ingress 4.17.42 True False False 2m39s insights 4.17.42 True False False 3m38s kube-apiserver 4.17.42 True False False 12m kube-controller-manager 4.17.42 True False False 12m kube-scheduler 4.17.42 True False False 12m kube-storage-version-migrator 4.17.42 True False False 3m34s monitoring Unknown True Unknown 3m23s Rolling out the stack. network 4.17.42 True False False 12m node-tuning 4.17.42 True False False 5m3s openshift-apiserver 4.17.42 True False False 12m openshift-controller-manager 4.17.42 True False False 12m openshift-samples 4.17.42 True False False 2m11s operator-lifecycle-manager 4.17.42 True False False 12m operator-lifecycle-manager-catalog 4.17.42 True False False 12m operator-lifecycle-manager-packageserver 4.17.42 True False False 12m service-ca 4.17.42 True False False 3m36s storage 4.17.42 True False False 4m59s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.17.42 True False False 3m11s csi-snapshot-controller 4.17.42 True False False 13m dns 4.17.42 True False False 3m18s image-registry 4.17.42 True False False 2m46s ingress 4.17.42 True False False 3m39s insights 4.17.42 True False False 4m38s kube-apiserver 4.17.42 True False False 13m kube-controller-manager 4.17.42 True False False 13m kube-scheduler 4.17.42 True False False 13m kube-storage-version-migrator 4.17.42 True False False 4m34s monitoring 4.17.42 True False False 10s network 4.17.42 True False False 13m node-tuning 4.17.42 True False False 6m3s openshift-apiserver 4.17.42 True False False 13m openshift-controller-manager 4.17.42 True False False 13m openshift-samples 4.17.42 True False False 3m11s operator-lifecycle-manager 4.17.42 True False False 13m operator-lifecycle-manager-catalog 4.17.42 True False False 13m operator-lifecycle-manager-packageserver 4.17.42 True False False 13m service-ca 4.17.42 True False False 4m36s storage 4.17.42 True False False 5m59s Waiting for cluster to be reported as healthy... Trying again in 60s healthy cluster to be reported as healthy finished!