INFO: Log in to your Red Hat account... INFO: Configure AWS Credentials... WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. INFO: Logged in as 'rhtap-shared' on 'https://api.openshift.com' INFO: Create ROSA with HCP cluster... WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. INFO: Creating cluster 'kx-adfe0dabc1' INFO: To view a list of clusters and their status, run 'rosa list clusters' INFO: Cluster 'kx-adfe0dabc1' has been created. INFO: Once the cluster is installed you will need to add an Identity Provider before you can login into the cluster. See 'rosa create idp --help' for more information. Name: kx-adfe0dabc1 Domain Prefix: kx-adfe0dabc1 Display Name: kx-adfe0dabc1 ID: 2mdivqrmr5tbkud9vmbsjj59ri2q14fv External ID: 966fc8af-df31-41a8-b79c-86fc8a489d77 Control Plane: ROSA Service Hosted OpenShift Version: 4.18.9 Channel Group: stable DNS: Not ready AWS Account: 381492310364 AWS Billing Account: 381492310364 API URL: Console URL: Region: us-east-1 Availability: - Control Plane: MultiAZ - Data Plane: MultiAZ Nodes: - Compute (desired): 3 - Compute (current): 0 Network: - Type: OVNKubernetes - Service CIDR: 172.30.0.0/16 - Machine CIDR: 10.0.0.0/16 - Pod CIDR: 10.128.0.0/14 - Host Prefix: /23 - Subnets: subnet-0208a6297964e4fe1, subnet-0c161c939f7025e15, subnet-023e5c7b3016ed194, subnet-02dbd8abbf884d77f, subnet-0360c2d20442c5ba5, subnet-0aad9c992e402a91a EC2 Metadata Http Tokens: optional Role (STS) ARN: arn:aws:iam::381492310364:role/rhads-hcp-HCP-ROSA-Installer-Role Support Role ARN: arn:aws:iam::381492310364:role/rhads-hcp-HCP-ROSA-Support-Role Instance IAM Roles: - Worker: arn:aws:iam::381492310364:role/rhads-hcp-HCP-ROSA-Worker-Role Operator IAM Roles: - arn:aws:iam::381492310364:role/rhads-hcp-openshift-cluster-csi-drivers-ebs-cloud-credentials - arn:aws:iam::381492310364:role/rhads-hcp-openshift-cloud-network-config-controller-cloud-creden - arn:aws:iam::381492310364:role/rhads-hcp-openshift-image-registry-installer-cloud-credentials - arn:aws:iam::381492310364:role/rhads-hcp-openshift-ingress-operator-cloud-credentials - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-kms-provider - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-kube-controller-manager - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-capa-controller-manager - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-control-plane-operator Managed Policies: Yes State: waiting (Waiting for user action) Private: No Delete Protection: Disabled Created: Nov 7 2025 05:04:46 UTC [DEPRECATED] User Workload Monitoring: Enabled Details Page: https://console.redhat.com/openshift/details/s/358VrmfhKOAjjeTKoDtMhqPnCds OIDC Endpoint URL: https://oidc.op1.openshiftapps.com/2jtsga3i2etnl697l7bk5i1kmbm4a95j (Managed) Etcd Encryption: Disabled Audit Log Forwarding: Disabled External Authentication: Disabled Zero Egress: Disabled INFO: Preparing to create operator roles. INFO: Operator Roles already exists INFO: Preparing to create OIDC Provider. INFO: OIDC provider already exists INFO: To determine when your cluster is Ready, run 'rosa describe cluster -c kx-adfe0dabc1'. INFO: To watch your cluster installation logs, run 'rosa logs install -c kx-adfe0dabc1 --watch'. INFO: Track the progress of the cluster creation... WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. W: Region flag will be removed from this command in future versions INFO: Cluster 'kx-adfe0dabc1' is in waiting state waiting for installation to begin. Logs will show up within 5 minutes 0001-01-01 00:00:00 +0000 UTC hostedclusters kx-adfe0dabc1 Version 2025-11-07 05:09:06 +0000 UTC hostedclusters kx-adfe0dabc1 ValidAWSIdentityProvider StatusUnknown 2025-11-07 05:09:07 +0000 UTC certificates cluster-api-cert Issuing certificate as Secret does not exist 2025-11-07 05:09:07 +0000 UTC certificates cluster-api-cert Issuing certificate as Secret does not exist 2025-11-07 05:09:10 +0000 UTC hostedclusters kx-adfe0dabc1 The hosted control plane is not found 2025-11-07 05:09:10 +0000 UTC hostedclusters kx-adfe0dabc1 Condition not found in the CVO. 2025-11-07 05:09:10 +0000 UTC hostedclusters kx-adfe0dabc1 ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-11-07 05:09:10 +0000 UTC hostedclusters kx-adfe0dabc1 The hosted control plane is not found 2025-11-07 05:09:10 +0000 UTC hostedclusters kx-adfe0dabc1 The hosted control plane is not found 2025-11-07 05:09:10 +0000 UTC hostedclusters kx-adfe0dabc1 Condition not found in the CVO. 2025-11-07 05:09:10 +0000 UTC hostedclusters kx-adfe0dabc1 Condition not found in the CVO. 2025-11-07 05:09:10 +0000 UTC hostedclusters kx-adfe0dabc1 Condition not found in the CVO. 2025-11-07 05:09:10 +0000 UTC hostedclusters kx-adfe0dabc1 Condition not found in the CVO. 2025-11-07 05:09:10 +0000 UTC hostedclusters kx-adfe0dabc1 The hosted control plane is not found 2025-11-07 05:09:10 +0000 UTC hostedclusters kx-adfe0dabc1 Ignition server deployment not found 2025-11-07 05:09:10 +0000 UTC hostedclusters kx-adfe0dabc1 NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-11-07 05:09:10 +0000 UTC hostedclusters kx-adfe0dabc1 HostedCluster is supported by operator configuration 2025-11-07 05:09:10 +0000 UTC hostedclusters kx-adfe0dabc1 Release image is valid 2025-11-07 05:09:10 +0000 UTC hostedclusters kx-adfe0dabc1 The hosted control plane is not found 2025-11-07 05:09:10 +0000 UTC hostedclusters kx-adfe0dabc1 Reconciliation active on resource 2025-11-07 05:09:10 +0000 UTC hostedclusters kx-adfe0dabc1 The hosted control plane is not found 2025-11-07 05:09:10 +0000 UTC hostedclusters kx-adfe0dabc1 The hosted control plane is not found 2025-11-07 05:09:11 +0000 UTC hostedclusters kx-adfe0dabc1 configuration is invalid: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-11-07 05:09:11 +0000 UTC hostedclusters kx-adfe0dabc1 ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 0001-01-01 00:00:00 +0000 UTC hostedclusters kx-adfe0dabc1 Version 2025-11-07 05:09:06 +0000 UTC hostedclusters kx-adfe0dabc1 ValidAWSIdentityProvider StatusUnknown 2025-11-07 05:09:10 +0000 UTC hostedclusters kx-adfe0dabc1 Release image is valid 2025-11-07 05:09:10 +0000 UTC hostedclusters kx-adfe0dabc1 Condition not found in the HCP 2025-11-07 05:09:10 +0000 UTC hostedclusters kx-adfe0dabc1 Reconciliation active on resource 2025-11-07 05:09:10 +0000 UTC hostedclusters kx-adfe0dabc1 Ignition server deployment not found 2025-11-07 05:09:10 +0000 UTC hostedclusters kx-adfe0dabc1 HostedCluster is supported by operator configuration 2025-11-07 05:09:10 +0000 UTC hostedclusters kx-adfe0dabc1 router load balancer is not provisioned; 4s since creation.; router load balancer is not provisioned; 4s since creation. 2025-11-07 05:09:10 +0000 UTC hostedclusters kx-adfe0dabc1 Condition not found in the CVO. 2025-11-07 05:09:10 +0000 UTC hostedclusters kx-adfe0dabc1 Condition not found in the CVO. 2025-11-07 05:09:10 +0000 UTC hostedclusters kx-adfe0dabc1 Condition not found in the CVO. 2025-11-07 05:09:10 +0000 UTC hostedclusters kx-adfe0dabc1 Condition not found in the CVO. 2025-11-07 05:09:10 +0000 UTC hostedclusters kx-adfe0dabc1 Condition not found in the CVO. 2025-11-07 05:09:11 +0000 UTC hostedclusters kx-adfe0dabc1 HostedCluster is at expected version 2025-11-07 05:10:33 +0000 UTC certificates cluster-api-cert Certificate is up to date and has not expired 2025-11-07 05:10:37 +0000 UTC hostedclusters kx-adfe0dabc1 Configuration passes validation 2025-11-07 05:10:38 +0000 UTC hostedclusters kx-adfe0dabc1 Required platform credentials are found 2025-11-07 05:10:40 +0000 UTC hostedclusters kx-adfe0dabc1 Configuration passes validation 2025-11-07 05:10:40 +0000 UTC hostedclusters kx-adfe0dabc1 AWS KMS is not configured 2025-11-07 05:10:40 +0000 UTC hostedclusters kx-adfe0dabc1 router load balancer is not provisioned; 4s since creation.; router load balancer is not provisioned; 4s since creation. 2025-11-07 05:10:40 +0000 UTC hostedclusters kx-adfe0dabc1 EtcdAvailable StatefulSetNotFound 2025-11-07 05:10:40 +0000 UTC hostedclusters kx-adfe0dabc1 Kube APIServer deployment not found 2025-11-07 05:10:40 +0000 UTC hostedclusters kx-adfe0dabc1 lookup api.kx-adfe0dabc1.9dn5.p3.openshiftapps.com on 172.30.0.10:53: no such host 2025-11-07 05:10:41 +0000 UTC hostedclusters kx-adfe0dabc1 [capi-provider deployment has 1 unavailable replicas, cluster-api deployment has 1 unavailable replicas] 2025-11-07 05:10:44 +0000 UTC hostedclusters kx-adfe0dabc1 OIDC configuration is valid 2025-11-07 05:10:44 +0000 UTC hostedclusters kx-adfe0dabc1 Reconciliation completed successfully 2025-11-07 05:11:04 +0000 UTC hostedclusters kx-adfe0dabc1 All is well 2025-11-07 05:11:05 +0000 UTC hostedclusters kx-adfe0dabc1 All is well 2025-11-07 05:11:09 +0000 UTC hostedclusters kx-adfe0dabc1 WebIdentityErr 2025-11-07 05:11:24 +0000 UTC hostedclusters kx-adfe0dabc1 EtcdAvailable QuorumAvailable 2025-11-07 05:12:33 +0000 UTC hostedclusters kx-adfe0dabc1 Kube APIServer deployment is available 2025-11-07 05:13:04 +0000 UTC hostedclusters kx-adfe0dabc1 Ignition server deployment is available 2025-11-07 05:13:09 +0000 UTC hostedclusters kx-adfe0dabc1 Payload loaded version="4.18.9" image="quay.io/openshift-release-dev/ocp-release@sha256:dafd6d1fe6008bf1a3e5baea3420aa0344412bf3167e1e92bec5c92098dc6464" architecture="Multi" 2025-11-07 05:13:09 +0000 UTC hostedclusters kx-adfe0dabc1 ClusterVersionAvailable FromClusterVersion 2025-11-07 05:13:09 +0000 UTC hostedclusters kx-adfe0dabc1 Unable to apply 4.18.9: some cluster operators are not available 2025-11-07 05:13:09 +0000 UTC hostedclusters kx-adfe0dabc1 Condition not found in the CVO. 2025-11-07 05:13:10 +0000 UTC hostedclusters kx-adfe0dabc1 All is well 2025-11-07 05:13:27 +0000 UTC hostedclusters kx-adfe0dabc1 The hosted control plane is available INFO: Cluster 'kx-adfe0dabc1' is now ready INFO: ROSA with HCP cluster is ready, create a cluster admin account for accessing the cluster WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. INFO: Storing login command... INFO: Check if it's able to login to OCP cluster... Retried 1 times... Retried 2 times... INFO: Check if apiserver is ready... Waiting for cluster operators to be accessible for 2m... NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.18.9 True False False 4m37s dns 4.18.9 False False True 4m37s DNS "default" is unavailable. image-registry False True True 4m26s Available: The deployment does not have available replicas... ingress False True True 4m18s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.18.9 True False False 4m31s kube-controller-manager 4.18.9 True False False 4m31s kube-scheduler 4.18.9 True False False 4m31s kube-storage-version-migrator monitoring network 4.18.9 True True False 4m9s DaemonSet "/openshift-network-operator/iptables-alerter" is waiting for other operators to become ready... node-tuning False True False 4m16s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.18.9 True False False 4m31s openshift-controller-manager 4.18.9 True False False 4m31s openshift-samples operator-lifecycle-manager 4.18.9 True False False 4m33s operator-lifecycle-manager-catalog 4.18.9 True False False 4m30s operator-lifecycle-manager-packageserver 4.18.9 True False False 4m30s service-ca storage 4.18.9 False False False 4m30s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service cluster operators to be accessible finished! [INFO] Cluster operators are accessible. Waiting for cluster to be reported as healthy for 60m... Unable to connect to the server: dial tcp: lookup api.kx-adfe0dabc1.9dn5.p3.openshiftapps.com on 172.30.0.10:53: no such host Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.18.9 True False False 5m38s dns 4.18.9 False False True 5m38s DNS "default" is unavailable. image-registry False True True 5m27s Available: The deployment does not have available replicas... ingress False True True 5m19s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.18.9 True False False 5m32s kube-controller-manager 4.18.9 True False False 5m32s kube-scheduler 4.18.9 True False False 5m32s kube-storage-version-migrator monitoring network 4.18.9 True True False 5m10s DaemonSet "/openshift-network-operator/iptables-alerter" is waiting for other operators to become ready... node-tuning False True False 5m17s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.18.9 True False False 5m32s openshift-controller-manager 4.18.9 True False False 5m32s openshift-samples operator-lifecycle-manager 4.18.9 True False False 5m34s operator-lifecycle-manager-catalog 4.18.9 True False False 5m31s operator-lifecycle-manager-packageserver 4.18.9 True False False 5m31s service-ca storage 4.18.9 False False False 5m31s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.18.9 True False False 6m38s dns 4.18.9 False True True 6m38s DNS "default" is unavailable. image-registry False True True 6m27s Available: The deployment does not have available replicas... ingress False True True 6m19s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.18.9 True False False 6m32s kube-controller-manager 4.18.9 True False False 6m32s kube-scheduler 4.18.9 True False False 6m32s kube-storage-version-migrator monitoring network 4.18.9 True True False 6m10s DaemonSet "/openshift-multus/multus" is not available (awaiting 1 nodes)... node-tuning False True False 6m17s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.18.9 True False False 6m32s openshift-controller-manager 4.18.9 True False False 6m32s openshift-samples operator-lifecycle-manager 4.18.9 True False False 6m34s operator-lifecycle-manager-catalog 4.18.9 True False False 6m31s operator-lifecycle-manager-packageserver 4.18.9 True False False 6m31s service-ca storage 4.18.9 False True False 6m31s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.18.9 True False False 7m38s dns 4.18.9 False True True 7m38s DNS "default" is unavailable. image-registry False True True 7m27s Available: The deployment does not have available replicas... ingress False True True 7m19s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.18.9 True False False 7m32s kube-controller-manager 4.18.9 True False False 7m32s kube-scheduler 4.18.9 True False False 7m32s kube-storage-version-migrator monitoring network 4.18.9 True True False 7m10s DaemonSet "/openshift-multus/multus-additional-cni-plugins" is not available (awaiting 2 nodes)... node-tuning 4.18.9 True True False 2s Waiting for 2/3 Profiles to be applied openshift-apiserver 4.18.9 True False False 7m32s openshift-controller-manager 4.18.9 True False False 7m32s openshift-samples operator-lifecycle-manager 4.18.9 True False False 7m34s operator-lifecycle-manager-catalog 4.18.9 True False False 7m31s operator-lifecycle-manager-packageserver 4.18.9 True False False 7m31s service-ca storage 4.18.9 True True False 42s AWSEBSCSIDriverOperatorCRProgressing: AWSEBSDriverNodeServiceControllerProgressing: Waiting for DaemonSet to deploy node pods Waiting for cluster to be reported as healthy... Trying again in 60s Unable to connect to the server: dial tcp: lookup api.kx-adfe0dabc1.9dn5.p3.openshiftapps.com on 172.30.0.10:53: no such host Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.18.9 Unknown False False 22s csi-snapshot-controller 4.18.9 True False False 9m39s dns 4.18.9 True True True 5s DNS default is degraded image-registry 4.18.9 True False False 3s ingress 4.18.9 True True True 2s The "default" ingress controller reports Degraded=True: DegradedConditions: One or more other status conditions indicate a degraded state: CanaryChecksSucceeding=Unknown (CanaryRouteNotAdmitted: Canary route is not admitted by the default ingress controller) insights 4.18.9 True False False 63s kube-apiserver 4.18.9 True False False 9m33s kube-controller-manager 4.18.9 True False False 9m33s kube-scheduler 4.18.9 True False False 9m33s kube-storage-version-migrator 4.18.9 True False False 59s monitoring Unknown True Unknown 48s Rolling out the stack. network 4.18.9 True True False 9m11s DaemonSet "/openshift-multus/network-metrics-daemon" is not available (awaiting 2 nodes) node-tuning 4.18.9 True False False 2m3s openshift-apiserver 4.18.9 True False False 9m33s openshift-controller-manager 4.18.9 True False False 9m33s openshift-samples False False False 5s SampleUpsertsPending operator-lifecycle-manager 4.18.9 True False False 9m35s operator-lifecycle-manager-catalog 4.18.9 True False False 9m32s operator-lifecycle-manager-packageserver 4.18.9 True False False 9m32s service-ca 4.18.9 True False False 59s storage 4.18.9 True False False 2m43s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.18.9 True False False 56s csi-snapshot-controller 4.18.9 True False False 10m dns 4.18.9 True False False 65s image-registry 4.18.9 True False False 63s ingress 4.18.9 True False False 62s insights 4.18.9 True False False 2m3s kube-apiserver 4.18.9 True False False 10m kube-controller-manager 4.18.9 True False False 10m kube-scheduler 4.18.9 True False False 10m kube-storage-version-migrator 4.18.9 True False False 119s monitoring Unknown True Unknown 108s Rolling out the stack. network 4.18.9 True True False 10m DaemonSet "/openshift-multus/network-metrics-daemon" is not available (awaiting 1 nodes) node-tuning 4.18.9 True False False 3m3s openshift-apiserver 4.18.9 True False False 10m openshift-controller-manager 4.18.9 True False False 10m openshift-samples 4.18.9 True False False 54s operator-lifecycle-manager 4.18.9 True False False 10m operator-lifecycle-manager-catalog 4.18.9 True False False 10m operator-lifecycle-manager-packageserver 4.18.9 True False False 10m service-ca 4.18.9 True False False 119s storage 4.18.9 True False False 3m43s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.18.9 True False False 116s csi-snapshot-controller 4.18.9 True False False 11m dns 4.18.9 True False False 2m5s image-registry 4.18.9 True False False 2m3s ingress 4.18.9 True False False 2m2s insights 4.18.9 True False False 3m3s kube-apiserver 4.18.9 True False False 11m kube-controller-manager 4.18.9 True False False 11m kube-scheduler 4.18.9 True False False 11m kube-storage-version-migrator 4.18.9 True False False 2m59s monitoring Unknown True Unknown 2m48s Rolling out the stack. network 4.18.9 True False False 11m node-tuning 4.18.9 True False False 4m3s openshift-apiserver 4.18.9 True False False 11m openshift-controller-manager 4.18.9 True False False 11m openshift-samples 4.18.9 True False False 114s operator-lifecycle-manager 4.18.9 True False False 11m operator-lifecycle-manager-catalog 4.18.9 True False False 11m operator-lifecycle-manager-packageserver 4.18.9 True False False 11m service-ca 4.18.9 True False False 2m59s storage 4.18.9 True False False 4m43s Waiting for cluster to be reported as healthy... Trying again in 60s healthy cluster to be reported as healthy finished!