INFO: Log in to your Red Hat account... INFO: Configure AWS Credentials... WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. INFO: Logged in as 'rhtap-shared' on 'https://api.openshift.com' INFO: Create ROSA with HCP cluster... WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. INFO: Creating cluster 'kx-ebfcf9789a' INFO: To view a list of clusters and their status, run 'rosa list clusters' INFO: Cluster 'kx-ebfcf9789a' has been created. INFO: Once the cluster is installed you will need to add an Identity Provider before you can login into the cluster. See 'rosa create idp --help' for more information. Name: kx-ebfcf9789a Domain Prefix: kx-ebfcf9789a Display Name: kx-ebfcf9789a ID: 2m8j4ihgtbgonah05g5ogclf0bmvap5m External ID: 2975e65d-7f5f-4e71-99cf-954d80d45dbe Control Plane: ROSA Service Hosted OpenShift Version: 4.17.42 Channel Group: stable DNS: Not ready AWS Account: 381492310364 AWS Billing Account: 381492310364 API URL: Console URL: Region: us-east-1 Availability: - Control Plane: MultiAZ - Data Plane: MultiAZ Nodes: - Compute (desired): 3 - Compute (current): 0 Network: - Type: OVNKubernetes - Service CIDR: 172.30.0.0/16 - Machine CIDR: 10.0.0.0/16 - Pod CIDR: 10.128.0.0/14 - Host Prefix: /23 - Subnets: subnet-0208a6297964e4fe1, subnet-0c161c939f7025e15, subnet-023e5c7b3016ed194, subnet-02dbd8abbf884d77f, subnet-0360c2d20442c5ba5, subnet-0aad9c992e402a91a EC2 Metadata Http Tokens: optional Role (STS) ARN: arn:aws:iam::381492310364:role/rhads-hcp-HCP-ROSA-Installer-Role Support Role ARN: arn:aws:iam::381492310364:role/rhads-hcp-HCP-ROSA-Support-Role Instance IAM Roles: - Worker: arn:aws:iam::381492310364:role/rhads-hcp-HCP-ROSA-Worker-Role Operator IAM Roles: - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-kube-controller-manager - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-capa-controller-manager - arn:aws:iam::381492310364:role/rhads-hcp-openshift-ingress-operator-cloud-credentials - arn:aws:iam::381492310364:role/rhads-hcp-openshift-cluster-csi-drivers-ebs-cloud-credentials - arn:aws:iam::381492310364:role/rhads-hcp-openshift-cloud-network-config-controller-cloud-creden - arn:aws:iam::381492310364:role/rhads-hcp-openshift-image-registry-installer-cloud-credentials - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-control-plane-operator - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-kms-provider Managed Policies: Yes State: waiting (Waiting for user action) Private: No Delete Protection: Disabled Created: Oct 30 2025 15:12:22 UTC [DEPRECATED] User Workload Monitoring: Enabled Details Page: https://console.redhat.com/openshift/details/s/34n6lspu41hB6KM35CvIR1a6H7Y OIDC Endpoint URL: https://oidc.op1.openshiftapps.com/2jtsga3i2etnl697l7bk5i1kmbm4a95j (Managed) Etcd Encryption: Disabled Audit Log Forwarding: Disabled External Authentication: Disabled Zero Egress: Disabled INFO: Preparing to create operator roles. INFO: Operator Roles already exists INFO: Preparing to create OIDC Provider. INFO: OIDC provider already exists INFO: To determine when your cluster is Ready, run 'rosa describe cluster -c kx-ebfcf9789a'. INFO: To watch your cluster installation logs, run 'rosa logs install -c kx-ebfcf9789a --watch'. INFO: Track the progress of the cluster creation... WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. W: Region flag will be removed from this command in future versions INFO: Cluster 'kx-ebfcf9789a' is in waiting state waiting for installation to begin. Logs will show up within 5 minutes 0001-01-01 00:00:00 +0000 UTC hostedclusters kx-ebfcf9789a Version 2025-10-30 15:16:16 +0000 UTC hostedclusters kx-ebfcf9789a ValidAWSIdentityProvider StatusUnknown 2025-10-30 15:16:17 +0000 UTC certificates cluster-api-cert Issuing certificate as Secret does not exist 2025-10-30 15:16:17 +0000 UTC certificates cluster-api-cert Issuing certificate as Secret does not exist 2025-10-30 15:16:19 +0000 UTC hostedclusters kx-ebfcf9789a The hosted control plane is not found 2025-10-30 15:16:19 +0000 UTC hostedclusters kx-ebfcf9789a Condition not found in the CVO. 2025-10-30 15:16:19 +0000 UTC hostedclusters kx-ebfcf9789a ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-10-30 15:16:19 +0000 UTC hostedclusters kx-ebfcf9789a The hosted control plane is not found 2025-10-30 15:16:19 +0000 UTC hostedclusters kx-ebfcf9789a The hosted control plane is not found 2025-10-30 15:16:19 +0000 UTC hostedclusters kx-ebfcf9789a Condition not found in the CVO. 2025-10-30 15:16:19 +0000 UTC hostedclusters kx-ebfcf9789a Condition not found in the CVO. 2025-10-30 15:16:19 +0000 UTC hostedclusters kx-ebfcf9789a Condition not found in the CVO. 2025-10-30 15:16:19 +0000 UTC hostedclusters kx-ebfcf9789a Condition not found in the CVO. 2025-10-30 15:16:19 +0000 UTC hostedclusters kx-ebfcf9789a The hosted control plane is not found 2025-10-30 15:16:19 +0000 UTC hostedclusters kx-ebfcf9789a Ignition server deployment not found 2025-10-30 15:16:19 +0000 UTC hostedclusters kx-ebfcf9789a NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-10-30 15:16:19 +0000 UTC hostedclusters kx-ebfcf9789a HostedCluster is supported by operator configuration 2025-10-30 15:16:19 +0000 UTC hostedclusters kx-ebfcf9789a Release image is valid 2025-10-30 15:16:19 +0000 UTC hostedclusters kx-ebfcf9789a The hosted control plane is not found 2025-10-30 15:16:19 +0000 UTC hostedclusters kx-ebfcf9789a Reconciliation active on resource 2025-10-30 15:16:19 +0000 UTC hostedclusters kx-ebfcf9789a The hosted control plane is not found 2025-10-30 15:16:19 +0000 UTC hostedclusters kx-ebfcf9789a The hosted control plane is not found 2025-10-30 15:16:21 +0000 UTC hostedclusters kx-ebfcf9789a configuration is invalid: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-10-30 15:16:21 +0000 UTC hostedclusters kx-ebfcf9789a ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-10-30 15:17:50 +0000 UTC certificates cluster-api-cert Certificate is up to date and has not expired 2025-10-30 15:18:01 +0000 UTC hostedclusters kx-ebfcf9789a Configuration passes validation 2025-10-30 15:18:03 +0000 UTC hostedclusters kx-ebfcf9789a Required platform credentials are found 2025-10-30 15:18:09 +0000 UTC hostedclusters kx-ebfcf9789a OIDC configuration is valid 2025-10-30 15:18:09 +0000 UTC hostedclusters kx-ebfcf9789a Reconciliation completed successfully 2025-10-30 15:18:10 +0000 UTC hostedclusters kx-ebfcf9789a AWS KMS is not configured 2025-10-30 15:18:10 +0000 UTC hostedclusters kx-ebfcf9789a [capi-provider deployment has 2 unavailable replicas, kube-apiserver deployment has 2 unavailable replicas] 2025-10-30 15:18:10 +0000 UTC hostedclusters kx-ebfcf9789a lookup api.kx-ebfcf9789a.w9uf.p3.openshiftapps.com on 172.30.0.10:53: no such host 2025-10-30 15:18:10 +0000 UTC hostedclusters kx-ebfcf9789a Configuration passes validation 2025-10-30 15:18:10 +0000 UTC hostedclusters kx-ebfcf9789a Waiting for Kube APIServer deployment to become available 2025-10-30 15:18:33 +0000 UTC hostedclusters kx-ebfcf9789a All is well 2025-10-30 15:18:34 +0000 UTC hostedclusters kx-ebfcf9789a All is well 2025-10-30 15:18:38 +0000 UTC hostedclusters kx-ebfcf9789a WebIdentityErr 2025-10-30 15:18:54 +0000 UTC hostedclusters kx-ebfcf9789a EtcdAvailable QuorumAvailable 2025-10-30 15:19:24 +0000 UTC hostedclusters kx-ebfcf9789a Kube APIServer deployment is available 2025-10-30 15:19:51 +0000 UTC hostedclusters kx-ebfcf9789a Ignition server deployment is available 2025-10-30 15:20:09 +0000 UTC hostedclusters kx-ebfcf9789a Condition not found in the CVO. 2025-10-30 15:20:09 +0000 UTC hostedclusters kx-ebfcf9789a Unable to apply 4.17.42: some cluster operators are not available 2025-10-30 15:20:09 +0000 UTC hostedclusters kx-ebfcf9789a All is well 2025-10-30 15:20:09 +0000 UTC hostedclusters kx-ebfcf9789a Payload loaded version="4.17.42" image="quay.io/openshift-release-dev/ocp-release@sha256:9b7b9909a1f064d5238f35f6e5fc9ac275a0d463a74e8c545544755d953a46d9" architecture="Multi" 2025-10-30 15:20:09 +0000 UTC hostedclusters kx-ebfcf9789a ClusterVersionAvailable FromClusterVersion 2025-10-30 15:20:46 +0000 UTC hostedclusters kx-ebfcf9789a Cluster operators console, dns, image-registry, ingress, insights, kube-storage-version-migrator, monitoring, node-tuning, openshift-samples, service-ca, storage are not available 2025-10-30 15:20:54 +0000 UTC hostedclusters kx-ebfcf9789a The hosted control plane is available INFO: Cluster 'kx-ebfcf9789a' is now ready INFO: ROSA with HCP cluster is ready, create a cluster admin account for accessing the cluster WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. INFO: Storing login command... INFO: Check if it's able to login to OCP cluster... Retried 1 times... INFO: Check if apiserver is ready... Waiting for cluster operators to be accessible for 2m... NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.17.42 True False False 3m30s dns 4.17.42 False False True 3m33s DNS "default" is unavailable. image-registry False True True 3m19s Available: The deployment does not have available replicas... ingress False True True 3m18s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.17.42 True False False 3m24s kube-controller-manager 4.17.42 True False False 3m24s kube-scheduler 4.17.42 True False False 3m24s kube-storage-version-migrator monitoring network 4.17.42 True True False 3m8s DaemonSet "/openshift-multus/network-metrics-daemon" is waiting for other operators to become ready... node-tuning False True False 2m53s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.17.42 True False False 3m24s openshift-controller-manager 4.17.42 True False False 3m24s openshift-samples operator-lifecycle-manager 4.17.42 True False False 3m27s operator-lifecycle-manager-catalog 4.17.42 True False False 3m15s operator-lifecycle-manager-packageserver 4.17.42 True False False 3m24s service-ca storage 4.17.42 False False False 3m24s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service cluster operators to be accessible finished! [INFO] Cluster operators are accessible. Waiting for cluster to be reported as healthy for 60m... NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.17.42 True False False 3m31s dns 4.17.42 False False True 3m34s DNS "default" is unavailable. image-registry False True True 3m20s Available: The deployment does not have available replicas... ingress False True True 3m19s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.17.42 True False False 3m25s kube-controller-manager 4.17.42 True False False 3m25s kube-scheduler 4.17.42 True False False 3m25s kube-storage-version-migrator monitoring network 4.17.42 True True False 3m9s DaemonSet "/openshift-multus/network-metrics-daemon" is waiting for other operators to become ready... node-tuning False True False 2m54s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.17.42 True False False 3m25s openshift-controller-manager 4.17.42 True False False 3m25s openshift-samples operator-lifecycle-manager 4.17.42 True False False 3m28s operator-lifecycle-manager-catalog 4.17.42 True False False 3m16s operator-lifecycle-manager-packageserver 4.17.42 True False False 3m25s service-ca storage 4.17.42 False False False 3m25s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.17.42 True False False 4m31s dns 4.17.42 False False True 4m34s DNS "default" is unavailable. image-registry False True True 4m20s Available: The deployment does not have available replicas... ingress False True True 4m19s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.17.42 True False False 4m25s kube-controller-manager 4.17.42 True False False 4m25s kube-scheduler 4.17.42 True False False 4m25s kube-storage-version-migrator monitoring network 4.17.42 True True False 4m9s DaemonSet "/openshift-multus/network-metrics-daemon" is waiting for other operators to become ready... node-tuning False True False 3m54s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.17.42 True False False 4m25s openshift-controller-manager 4.17.42 True False False 4m25s openshift-samples operator-lifecycle-manager 4.17.42 True False False 4m28s operator-lifecycle-manager-catalog 4.17.42 True False False 4m16s operator-lifecycle-manager-packageserver 4.17.42 True False False 4m25s service-ca storage 4.17.42 False False False 4m25s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.17.42 True False False 5m31s dns 4.17.42 False False True 5m34s DNS "default" is unavailable. image-registry False True True 5m20s Available: The deployment does not have available replicas... ingress False True True 5m19s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.17.42 True False False 5m25s kube-controller-manager 4.17.42 True False False 5m25s kube-scheduler 4.17.42 True False False 5m25s kube-storage-version-migrator monitoring network 4.17.42 True True False 5m9s DaemonSet "/openshift-multus/network-metrics-daemon" is waiting for other operators to become ready... node-tuning False True False 4m54s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.17.42 True False False 5m25s openshift-controller-manager 4.17.42 True False False 5m25s openshift-samples operator-lifecycle-manager 4.17.42 True False False 5m28s operator-lifecycle-manager-catalog 4.17.42 True False False 5m16s operator-lifecycle-manager-packageserver 4.17.42 True False False 5m25s service-ca storage 4.17.42 False False False 5m25s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.17.42 True False False 6m32s dns 4.17.42 False False True 6m35s DNS "default" is unavailable. image-registry False True True 6m21s Available: The deployment does not have available replicas... ingress False True True 6m20s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.17.42 True False False 6m26s kube-controller-manager 4.17.42 True False False 6m26s kube-scheduler 4.17.42 True False False 6m26s kube-storage-version-migrator monitoring network 4.17.42 True True False 6m10s DaemonSet "/openshift-multus/multus-additional-cni-plugins" is not available (awaiting 2 nodes)... node-tuning 4.17.42 True True False 24s Waiting for 2/3 Profiles to be applied openshift-apiserver 4.17.42 True False False 6m26s openshift-controller-manager 4.17.42 True False False 6m26s openshift-samples operator-lifecycle-manager 4.17.42 True False False 6m29s operator-lifecycle-manager-catalog 4.17.42 True False False 6m17s operator-lifecycle-manager-packageserver 4.17.42 True False False 6m26s service-ca storage 4.17.42 True False False 19s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.17.42 True True False 10s SyncLoopRefreshProgressing: working toward version 4.17.42, 1 replicas available csi-snapshot-controller 4.17.42 True False False 7m32s dns 4.17.42 True True False 9s DNS "default" reports Progressing=True: "Have 2 available DNS pods, want 3." image-registry 4.17.42 True False False 8s ingress False True True 7m20s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights 4.17.42 True False False 53s kube-apiserver 4.17.42 True False False 7m26s kube-controller-manager 4.17.42 True False False 7m26s kube-scheduler 4.17.42 True False False 7m26s kube-storage-version-migrator 4.17.42 True False False 30s monitoring Unknown True Unknown 23s Rolling out the stack. network 4.17.42 True True False 7m10s DaemonSet "/openshift-multus/network-metrics-daemon" is not available (awaiting 1 nodes) node-tuning 4.17.42 True False False 84s openshift-apiserver 4.17.42 True False False 7m26s openshift-controller-manager 4.17.42 True False False 7m26s openshift-samples operator-lifecycle-manager 4.17.42 True False False 7m29s operator-lifecycle-manager-catalog 4.17.42 True False False 7m17s operator-lifecycle-manager-packageserver 4.17.42 True False False 7m26s service-ca 4.17.42 True False False 51s storage 4.17.42 True False False 79s Waiting for cluster to be reported as healthy... Trying again in 60s Unable to connect to the server: dial tcp: lookup api.kx-ebfcf9789a.w9uf.p3.openshiftapps.com on 172.30.0.10:53: no such host Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.17.42 True False False 2m10s csi-snapshot-controller 4.17.42 True False False 9m32s dns 4.17.42 True False False 2m9s image-registry 4.17.42 True False False 2m8s ingress 4.17.42 True False False 115s insights 4.17.42 True False False 2m53s kube-apiserver 4.17.42 True False False 9m26s kube-controller-manager 4.17.42 True False False 9m26s kube-scheduler 4.17.42 True False False 9m26s kube-storage-version-migrator 4.17.42 True False False 2m30s monitoring Unknown True Unknown 2m23s Rolling out the stack. network 4.17.42 True False False 9m10s node-tuning 4.17.42 True False False 3m24s openshift-apiserver 4.17.42 True False False 9m26s openshift-controller-manager 4.17.42 True False False 9m26s openshift-samples 4.17.42 True False False 107s operator-lifecycle-manager 4.17.42 True False False 9m29s operator-lifecycle-manager-catalog 4.17.42 True False False 9m17s operator-lifecycle-manager-packageserver 4.17.42 True False False 9m26s service-ca 4.17.42 True False False 2m51s storage 4.17.42 True False False 3m19s Waiting for cluster to be reported as healthy... Trying again in 60s healthy cluster to be reported as healthy finished!