INFO: Log in to your Red Hat account... INFO: Configure AWS Credentials... WARN: The current version (1.2.59) is not up to date with latest rosa cli released version (1.2.61). WARN: It is recommended that you update to the latest version. INFO: Logged in as 'rhtap-shared' on 'https://api.openshift.com' INFO: Create ROSA with HCP cluster... WARN: The current version (1.2.59) is not up to date with latest rosa cli released version (1.2.61). WARN: It is recommended that you update to the latest version. INFO: Creating cluster 'kx-47752a56d3' INFO: To view a list of clusters and their status, run 'rosa list clusters' INFO: Cluster 'kx-47752a56d3' has been created. INFO: Once the cluster is installed you will need to add an Identity Provider before you can login into the cluster. See 'rosa create idp --help' for more information. Name: kx-47752a56d3 Domain Prefix: kx-47752a56d3 Display Name: kx-47752a56d3 ID: 2pq5o43ker7poaqvfdtonf56alq3os43 External ID: 0eeaa5b7-5e0e-4a8d-94dd-dc80f087d89b Control Plane: ROSA Service Hosted OpenShift Version: 4.19.9 Channel Group: stable DNS: Not ready AWS Account: 381492310364 AWS Billing Account: 381492310364 API URL: Console URL: Region: us-east-1 Availability: - Control Plane: MultiAZ - Data Plane: MultiAZ Nodes: - Compute (desired): 3 - Compute (current): 0 Network: - Type: OVNKubernetes - Service CIDR: 172.30.0.0/16 - Machine CIDR: 10.0.0.0/16 - Pod CIDR: 10.128.0.0/14 - Host Prefix: /23 - Subnets: subnet-0208a6297964e4fe1, subnet-0c161c939f7025e15, subnet-023e5c7b3016ed194, subnet-02dbd8abbf884d77f, subnet-0360c2d20442c5ba5, subnet-0aad9c992e402a91a EC2 Metadata Http Tokens: optional Role (STS) ARN: arn:aws:iam::381492310364:role/rhads-hcp-HCP-ROSA-Installer-Role Support Role ARN: arn:aws:iam::381492310364:role/rhads-hcp-HCP-ROSA-Support-Role Instance IAM Roles: - Worker: arn:aws:iam::381492310364:role/rhads-hcp-HCP-ROSA-Worker-Role Operator IAM Roles: - arn:aws:iam::381492310364:role/rhads-hcp-openshift-cloud-network-config-controller-cloud-creden - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-kube-controller-manager - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-capa-controller-manager - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-control-plane-operator - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-kms-provider - arn:aws:iam::381492310364:role/rhads-hcp-openshift-image-registry-installer-cloud-credentials - arn:aws:iam::381492310364:role/rhads-hcp-openshift-ingress-operator-cloud-credentials - arn:aws:iam::381492310364:role/rhads-hcp-openshift-cluster-csi-drivers-ebs-cloud-credentials Managed Policies: Yes State: waiting (Waiting for user action) Private: No Delete Protection: Disabled Created: Apr 20 2026 22:34:59 UTC Details Page: https://console.redhat.com/openshift/details/s/3CdnppllnMJor0QB0HjsrzHEKTA OIDC Endpoint URL: https://oidc.op1.openshiftapps.com/2jtsga3i2etnl697l7bk5i1kmbm4a95j (Managed) Etcd Encryption: Disabled Audit Log Forwarding: Disabled External Authentication: Disabled INFO: Preparing to create operator roles. INFO: Operator Roles already exists INFO: Preparing to create OIDC Provider. INFO: OIDC provider already exists INFO: To determine when your cluster is Ready, run 'rosa describe cluster -c kx-47752a56d3'. INFO: To watch your cluster installation logs, run 'rosa logs install -c kx-47752a56d3 --watch'. INFO: Track the progress of the cluster creation... WARN: The current version (1.2.59) is not up to date with latest rosa cli released version (1.2.61). WARN: It is recommended that you update to the latest version. W: Region flag will be removed from this command in future versions INFO: Cluster 'kx-47752a56d3' is in waiting state waiting for installation to begin. Logs will show up within 5 minutes 0001-01-01 00:00:00 +0000 UTC hostedclusters kx-47752a56d3 Version 2026-04-20 22:40:10 +0000 UTC hostedclusters kx-47752a56d3 ValidAWSIdentityProvider StatusUnknown 2026-04-20 22:40:10 +0000 UTC certificates cluster-api-cert Issuing certificate as Secret does not exist 2026-04-20 22:40:10 +0000 UTC certificates cluster-api-cert Issuing certificate as Secret does not exist 2026-04-20 22:40:11 +0000 UTC hostedclusters kx-47752a56d3 The hosted control plane is not found 2026-04-20 22:40:11 +0000 UTC hostedclusters kx-47752a56d3 Condition not found in the CVO. 2026-04-20 22:40:11 +0000 UTC hostedclusters kx-47752a56d3 ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-04-20 22:40:11 +0000 UTC hostedclusters kx-47752a56d3 The hosted control plane is not found 2026-04-20 22:40:11 +0000 UTC hostedclusters kx-47752a56d3 The hosted control plane is not found 2026-04-20 22:40:11 +0000 UTC hostedclusters kx-47752a56d3 Condition not found in the CVO. 2026-04-20 22:40:11 +0000 UTC hostedclusters kx-47752a56d3 Condition not found in the CVO. 2026-04-20 22:40:11 +0000 UTC hostedclusters kx-47752a56d3 Condition not found in the CVO. 2026-04-20 22:40:11 +0000 UTC hostedclusters kx-47752a56d3 Condition not found in the CVO. 2026-04-20 22:40:11 +0000 UTC hostedclusters kx-47752a56d3 The hosted control plane is not found 2026-04-20 22:40:11 +0000 UTC hostedclusters kx-47752a56d3 Ignition server deployment not found 2026-04-20 22:40:11 +0000 UTC hostedclusters kx-47752a56d3 NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-04-20 22:40:11 +0000 UTC hostedclusters kx-47752a56d3 HostedCluster is supported by operator configuration 2026-04-20 22:40:11 +0000 UTC hostedclusters kx-47752a56d3 Release image is valid 2026-04-20 22:40:11 +0000 UTC hostedclusters kx-47752a56d3 The hosted control plane is not found 2026-04-20 22:40:11 +0000 UTC hostedclusters kx-47752a56d3 Reconciliation active on resource 2026-04-20 22:40:11 +0000 UTC hostedclusters kx-47752a56d3 The hosted control plane is not found 2026-04-20 22:40:11 +0000 UTC hostedclusters kx-47752a56d3 The hosted control plane is not found 2026-04-20 22:40:12 +0000 UTC hostedclusters kx-47752a56d3 configuration is invalid: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-04-20 22:40:12 +0000 UTC hostedclusters kx-47752a56d3 ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-04-20 22:41:40 +0000 UTC certificates cluster-api-cert Certificate is up to date and has not expired 2026-04-20 22:41:42 +0000 UTC hostedclusters kx-47752a56d3 Required platform credentials are found 2026-04-20 22:41:42 +0000 UTC hostedclusters kx-47752a56d3 Configuration passes validation 2026-04-20 22:41:44 +0000 UTC hostedclusters kx-47752a56d3 OIDC configuration is valid 2026-04-20 22:41:44 +0000 UTC hostedclusters kx-47752a56d3 Reconciliation completed successfully 2026-04-20 22:41:45 +0000 UTC hostedclusters kx-47752a56d3 Configuration passes validation 2026-04-20 22:41:45 +0000 UTC hostedclusters kx-47752a56d3 [capi-provider deployment has 1 unavailable replicas, control-plane-pki-operator deployment has 1 unavailable replicas] 2026-04-20 22:41:45 +0000 UTC hostedclusters kx-47752a56d3 AWS KMS is not configured 2026-04-20 22:41:45 +0000 UTC hostedclusters kx-47752a56d3 Waiting for etcd to reach quorum 2026-04-20 22:41:45 +0000 UTC hostedclusters kx-47752a56d3 Kube APIServer deployment not found 2026-04-20 22:41:45 +0000 UTC hostedclusters kx-47752a56d3 lookup api.kx-47752a56d3.gg5u.p3.openshiftapps.com on 172.30.0.10:53: no such host 2026-04-20 22:42:06 +0000 UTC hostedclusters kx-47752a56d3 All is well 2026-04-20 22:42:06 +0000 UTC hostedclusters kx-47752a56d3 All is well 2026-04-20 22:42:06 +0000 UTC hostedclusters kx-47752a56d3 All is well 2026-04-20 22:42:14 +0000 UTC hostedclusters kx-47752a56d3 WebIdentityErr 2026-04-20 22:42:26 +0000 UTC hostedclusters kx-47752a56d3 EtcdAvailable QuorumAvailable 2026-04-20 22:43:05 +0000 UTC hostedclusters kx-47752a56d3 Kube APIServer deployment is available 2026-04-20 22:43:18 +0000 UTC hostedclusters kx-47752a56d3 [catalog-operator deployment has 1 unavailable replicas, certified-operators-catalog deployment has 2 unavailable replicas, cloud-credential-operator deployment has 1 unavailable replicas, cluster-image-registry-operator deployment has 1 unavailable replicas, cluster-network-operator deployment has 1 unavailable replicas, cluster-node-tuning-operator deployment has 1 unavailable replicas, cluster-storage-operator deployment has 1 unavailable replicas, cluster-version-operator deployment has 1 unavailable replicas, community-operators-catalog deployment has 2 unavailable replicas, csi-snapshot-controller-operator deployment has 1 unavailable replicas, dns-operator deployment has 1 unavailable replicas, hosted-cluster-config-operator deployment has 1 unavailable replicas, ingress-operator deployment has 1 unavailable replicas, machine-approver deployment has 1 unavailable replicas, olm-operator deployment has 1 unavailable replicas, packageserver deployment has 3 unavailable replicas, redhat-marketplace-catalog deployment has 2 unavailable replicas, redhat-operators-catalog deployment has 2 unavailable replicas, router deployment has 2 unavailable replicas] 2026-04-20 22:43:24 +0000 UTC hostedclusters kx-47752a56d3 Ignition server deployment is available 2026-04-20 22:43:44 +0000 UTC hostedclusters kx-47752a56d3 Working towards 4.19.9: 282 of 629 done (44% complete) 2026-04-20 22:43:44 +0000 UTC hostedclusters kx-47752a56d3 ClusterVersionSucceeding FromClusterVersion 2026-04-20 22:43:44 +0000 UTC hostedclusters kx-47752a56d3 ClusterVersionAvailable FromClusterVersion 2026-04-20 22:43:44 +0000 UTC hostedclusters kx-47752a56d3 Payload loaded version="4.19.9" image="quay.io/openshift-release-dev/ocp-release@sha256:fda39a9c5701bf35da74263177d8976d4bd9205e69b9a9d5834389f71005d51a" architecture="Multi" 2026-04-20 22:43:50 +0000 UTC hostedclusters kx-47752a56d3 An update is already in progress and the details are in the Progressing condition 2026-04-20 22:44:14 +0000 UTC hostedclusters kx-47752a56d3 Multiple errors are preventing progress: * Cluster operators console, dns, image-registry, ingress, insights, kube-storage-version-migrator, monitoring, network, node-tuning, openshift-samples, service-ca are not available * Could not update imagestream "openshift/driver-toolkit" (447 of 629): resource may have been deleted * Could not update operatorgroup "openshift-monitoring/openshift-cluster-monitoring" (570 of 629): resource may have been deleted * Could not update role "openshift-authentication/prometheus-k8s" (557 of 629): resource may have been deleted * Could not update role "openshift-console-operator/prometheus-k8s" (587 of 629): resource may have been deleted * Could not update role "openshift-console/prometheus-k8s" (591 of 629): resource may have been deleted * Could not update role "openshift-ingress-operator/prometheus-k8s" (598 of 629): resource may have been deleted * Could not update role "openshift-kube-apiserver-operator/prometheus-k8s" (602 of 629): resource may have been deleted 2026-04-20 22:44:14 +0000 UTC hostedclusters kx-47752a56d3 All is well 2026-04-20 22:44:23 +0000 UTC hostedclusters kx-47752a56d3 All is well 2026-04-20 22:44:26 +0000 UTC hostedclusters kx-47752a56d3 Cluster operators console, dns, image-registry, ingress, insights, kube-storage-version-migrator, monitoring, node-tuning, openshift-samples, service-ca, storage are not available 2026-04-20 22:44:34 +0000 UTC hostedclusters kx-47752a56d3 The hosted cluster is not degraded 2026-04-20 22:45:16 +0000 UTC hostedclusters kx-47752a56d3 The hosted control plane is available INFO: Cluster 'kx-47752a56d3' is now ready INFO: ROSA with HCP cluster is ready, create a cluster admin account for accessing the cluster WARN: The current version (1.2.59) is not up to date with latest rosa cli released version (1.2.61). WARN: It is recommended that you update to the latest version. INFO: Storing login command... INFO: Check if it's able to login to OCP cluster... Retried 1 times... Retried 2 times... Retried 3 times... Retried 4 times... Retried 5 times... Retried 6 times... Retried 7 times... Retried 8 times... Retried 9 times... Retried 10 times... ERROR: Failed to login the cluster. INFO: Print debug info...... WARN: The current version (1.2.59) is not up to date with latest rosa cli released version (1.2.61). WARN: It is recommended that you update to the latest version. W: Region flag will be removed from this command in future versions Name: kx-47752a56d3 Domain Prefix: kx-47752a56d3 Display Name: kx-47752a56d3 ID: 2pq5o43ker7poaqvfdtonf56alq3os43 External ID: 0eeaa5b7-5e0e-4a8d-94dd-dc80f087d89b Control Plane: ROSA Service Hosted OpenShift Version: 4.19.9 Channel Group: stable DNS: kx-47752a56d3.gg5u.p3.openshiftapps.com AWS Account: 381492310364 AWS Billing Account: 381492310364 API URL: https://api.kx-47752a56d3.gg5u.p3.openshiftapps.com:443 Console URL: https://console-openshift-console.apps.rosa.kx-47752a56d3.gg5u.p3.openshiftapps.com Region: us-east-1 Availability: - Control Plane: MultiAZ - Data Plane: MultiAZ Nodes: - Compute (desired): 3 - Compute (current): 1 Network: - Type: OVNKubernetes - Service CIDR: 172.30.0.0/16 - Machine CIDR: 10.0.0.0/16 - Pod CIDR: 10.128.0.0/14 - Host Prefix: /23 - Subnets: subnet-0208a6297964e4fe1, subnet-0c161c939f7025e15, subnet-023e5c7b3016ed194, subnet-02dbd8abbf884d77f, subnet-0360c2d20442c5ba5, subnet-0aad9c992e402a91a EC2 Metadata Http Tokens: optional Role (STS) ARN: arn:aws:iam::381492310364:role/rhads-hcp-HCP-ROSA-Installer-Role Support Role ARN: arn:aws:iam::381492310364:role/rhads-hcp-HCP-ROSA-Support-Role Instance IAM Roles: - Worker: arn:aws:iam::381492310364:role/rhads-hcp-HCP-ROSA-Worker-Role Operator IAM Roles: - arn:aws:iam::381492310364:role/rhads-hcp-openshift-cloud-network-config-controller-cloud-creden - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-kube-controller-manager - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-capa-controller-manager - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-control-plane-operator - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-kms-provider - arn:aws:iam::381492310364:role/rhads-hcp-openshift-image-registry-installer-cloud-credentials - arn:aws:iam::381492310364:role/rhads-hcp-openshift-ingress-operator-cloud-credentials - arn:aws:iam::381492310364:role/rhads-hcp-openshift-cluster-csi-drivers-ebs-cloud-credentials Managed Policies: Yes State: ready Private: No Delete Protection: Disabled Created: Apr 20 2026 22:34:59 UTC Details Page: https://console.redhat.com/openshift/details/s/3CdnppllnMJor0QB0HjsrzHEKTA OIDC Endpoint URL: https://oidc.op1.openshiftapps.com/2jtsga3i2etnl697l7bk5i1kmbm4a95j (Managed) Etcd Encryption: Disabled Audit Log Forwarding: Disabled External Authentication: Disabled