INFO: Log in to your Red Hat account... INFO: Configure AWS Credentials... WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. INFO: Logged in as 'rhtap-shared' on 'https://api.openshift.com' INFO: Create ROSA with HCP cluster... WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. INFO: Creating cluster 'kx-eceddecb18' INFO: To view a list of clusters and their status, run 'rosa list clusters' INFO: Cluster 'kx-eceddecb18' has been created. INFO: Once the cluster is installed you will need to add an Identity Provider before you can login into the cluster. See 'rosa create idp --help' for more information. Name: kx-eceddecb18 Domain Prefix: kx-eceddecb18 Display Name: kx-eceddecb18 ID: 2m2i5k9plitr0q5n19l250ji00djc2lc External ID: 331a057b-e9c5-4a83-8a93-8c935e080801 Control Plane: ROSA Service Hosted OpenShift Version: 4.19.9 Channel Group: stable DNS: Not ready AWS Account: 381492310364 AWS Billing Account: 381492310364 API URL: Console URL: Region: us-east-1 Availability: - Control Plane: MultiAZ - Data Plane: MultiAZ Nodes: - Compute (desired): 3 - Compute (current): 0 Network: - Type: OVNKubernetes - Service CIDR: 172.30.0.0/16 - Machine CIDR: 10.0.0.0/16 - Pod CIDR: 10.128.0.0/14 - Host Prefix: /23 - Subnets: subnet-0208a6297964e4fe1, subnet-0c161c939f7025e15, subnet-023e5c7b3016ed194, subnet-02dbd8abbf884d77f, subnet-0360c2d20442c5ba5, subnet-0aad9c992e402a91a EC2 Metadata Http Tokens: optional Role (STS) ARN: arn:aws:iam::381492310364:role/rhads-hcp-HCP-ROSA-Installer-Role Support Role ARN: arn:aws:iam::381492310364:role/rhads-hcp-HCP-ROSA-Support-Role Instance IAM Roles: - Worker: arn:aws:iam::381492310364:role/rhads-hcp-HCP-ROSA-Worker-Role Operator IAM Roles: - arn:aws:iam::381492310364:role/rhads-hcp-openshift-cloud-network-config-controller-cloud-creden - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-kube-controller-manager - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-capa-controller-manager - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-control-plane-operator - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-kms-provider - arn:aws:iam::381492310364:role/rhads-hcp-openshift-image-registry-installer-cloud-credentials - arn:aws:iam::381492310364:role/rhads-hcp-openshift-ingress-operator-cloud-credentials - arn:aws:iam::381492310364:role/rhads-hcp-openshift-cluster-csi-drivers-ebs-cloud-credentials Managed Policies: Yes State: waiting (Waiting for user action) Private: No Delete Protection: Disabled Created: Oct 21 2025 11:39:01 UTC [DEPRECATED] User Workload Monitoring: Enabled Details Page: https://console.redhat.com/openshift/details/s/34NGiM953hm301n24TeyszdAjNC OIDC Endpoint URL: https://oidc.op1.openshiftapps.com/2jtsga3i2etnl697l7bk5i1kmbm4a95j (Managed) Etcd Encryption: Disabled Audit Log Forwarding: Disabled External Authentication: Disabled Zero Egress: Disabled INFO: Preparing to create operator roles. INFO: Operator Roles already exists INFO: Preparing to create OIDC Provider. INFO: OIDC provider already exists INFO: To determine when your cluster is Ready, run 'rosa describe cluster -c kx-eceddecb18'. INFO: To watch your cluster installation logs, run 'rosa logs install -c kx-eceddecb18 --watch'. INFO: Track the progress of the cluster creation... WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. W: Region flag will be removed from this command in future versions INFO: Cluster 'kx-eceddecb18' is in waiting state waiting for installation to begin. Logs will show up within 5 minutes 0001-01-01 00:00:00 +0000 UTC hostedclusters kx-eceddecb18 Version 2025-10-21 11:44:23 +0000 UTC hostedclusters kx-eceddecb18 ValidAWSIdentityProvider StatusUnknown 2025-10-21 11:44:25 +0000 UTC certificates cluster-api-cert Issuing certificate as Secret does not exist 2025-10-21 11:44:25 +0000 UTC certificates cluster-api-cert Issuing certificate as Secret does not exist 2025-10-21 11:44:27 +0000 UTC hostedclusters kx-eceddecb18 The hosted control plane is not found 2025-10-21 11:44:27 +0000 UTC hostedclusters kx-eceddecb18 Condition not found in the CVO. 2025-10-21 11:44:27 +0000 UTC hostedclusters kx-eceddecb18 ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-10-21 11:44:27 +0000 UTC hostedclusters kx-eceddecb18 The hosted control plane is not found 2025-10-21 11:44:27 +0000 UTC hostedclusters kx-eceddecb18 The hosted control plane is not found 2025-10-21 11:44:27 +0000 UTC hostedclusters kx-eceddecb18 Condition not found in the CVO. 2025-10-21 11:44:27 +0000 UTC hostedclusters kx-eceddecb18 Condition not found in the CVO. 2025-10-21 11:44:27 +0000 UTC hostedclusters kx-eceddecb18 Condition not found in the CVO. 2025-10-21 11:44:27 +0000 UTC hostedclusters kx-eceddecb18 Condition not found in the CVO. 2025-10-21 11:44:27 +0000 UTC hostedclusters kx-eceddecb18 The hosted control plane is not found 2025-10-21 11:44:27 +0000 UTC hostedclusters kx-eceddecb18 Ignition server deployment not found 2025-10-21 11:44:27 +0000 UTC hostedclusters kx-eceddecb18 NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-10-21 11:44:27 +0000 UTC hostedclusters kx-eceddecb18 HostedCluster is supported by operator configuration 2025-10-21 11:44:27 +0000 UTC hostedclusters kx-eceddecb18 Release image is valid 2025-10-21 11:44:27 +0000 UTC hostedclusters kx-eceddecb18 The hosted control plane is not found 2025-10-21 11:44:27 +0000 UTC hostedclusters kx-eceddecb18 Reconciliation active on resource 2025-10-21 11:44:27 +0000 UTC hostedclusters kx-eceddecb18 The hosted control plane is not found 2025-10-21 11:44:27 +0000 UTC hostedclusters kx-eceddecb18 The hosted control plane is not found 2025-10-21 11:44:28 +0000 UTC hostedclusters kx-eceddecb18 configuration is invalid: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-10-21 11:44:28 +0000 UTC hostedclusters kx-eceddecb18 ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 0001-01-01 00:00:00 +0000 UTC hostedclusters kx-eceddecb18 Version 2025-10-21 11:44:23 +0000 UTC hostedclusters kx-eceddecb18 ValidAWSIdentityProvider StatusUnknown 2025-10-21 11:44:27 +0000 UTC hostedclusters kx-eceddecb18 Release image is valid 2025-10-21 11:44:27 +0000 UTC hostedclusters kx-eceddecb18 Condition not found in the HCP 2025-10-21 11:44:27 +0000 UTC hostedclusters kx-eceddecb18 Reconciliation active on resource 2025-10-21 11:44:27 +0000 UTC hostedclusters kx-eceddecb18 Ignition server deployment not found 2025-10-21 11:44:27 +0000 UTC hostedclusters kx-eceddecb18 HostedCluster is supported by operator configuration 2025-10-21 11:44:27 +0000 UTC hostedclusters kx-eceddecb18 router load balancer is not provisioned; 4s since creation.; private-router load balancer is not provisioned; 4s since creation.; router load balancer is not provisioned; 4s since creation. 2025-10-21 11:44:27 +0000 UTC hostedclusters kx-eceddecb18 Condition not found in the CVO. 2025-10-21 11:44:27 +0000 UTC hostedclusters kx-eceddecb18 Condition not found in the CVO. 2025-10-21 11:44:27 +0000 UTC hostedclusters kx-eceddecb18 Condition not found in the CVO. 2025-10-21 11:44:27 +0000 UTC hostedclusters kx-eceddecb18 Condition not found in the CVO. 2025-10-21 11:44:27 +0000 UTC hostedclusters kx-eceddecb18 Condition not found in the CVO. 2025-10-21 11:44:28 +0000 UTC hostedclusters kx-eceddecb18 HostedCluster is at expected version 2025-10-21 11:45:53 +0000 UTC certificates cluster-api-cert Certificate is up to date and has not expired 2025-10-21 11:45:56 +0000 UTC hostedclusters kx-eceddecb18 Configuration passes validation 2025-10-21 11:45:58 +0000 UTC hostedclusters kx-eceddecb18 Required platform credentials are found 2025-10-21 11:46:02 +0000 UTC hostedclusters kx-eceddecb18 OIDC configuration is valid 2025-10-21 11:46:03 +0000 UTC hostedclusters kx-eceddecb18 Reconciliation completed successfully 2025-10-21 11:46:06 +0000 UTC hostedclusters kx-eceddecb18 Configuration passes validation 2025-10-21 11:46:06 +0000 UTC hostedclusters kx-eceddecb18 router load balancer is not provisioned; 4s since creation.; private-router load balancer is not provisioned; 4s since creation.; router load balancer is not provisioned; 4s since creation. 2025-10-21 11:46:06 +0000 UTC hostedclusters kx-eceddecb18 AWS KMS is not configured 2025-10-21 11:46:06 +0000 UTC hostedclusters kx-eceddecb18 Kube APIServer deployment not found 2025-10-21 11:46:06 +0000 UTC hostedclusters kx-eceddecb18 EtcdAvailable StatefulSetNotFound 2025-10-21 11:46:06 +0000 UTC hostedclusters kx-eceddecb18 capi-provider deployment has 2 unavailable replicas 2025-10-21 11:46:06 +0000 UTC hostedclusters kx-eceddecb18 lookup api.kx-eceddecb18.smht.p3.openshiftapps.com on 172.30.0.10:53: no such host 2025-10-21 11:46:06 +0000 UTC hostedclusters kx-eceddecb18 Configuration passes validation 2025-10-21 11:46:06 +0000 UTC hostedclusters kx-eceddecb18 Waiting for Kube APIServer deployment to become available 2025-10-21 11:46:15 +0000 UTC hostedclusters kx-eceddecb18 All is well 2025-10-21 11:46:29 +0000 UTC hostedclusters kx-eceddecb18 All is well 2025-10-21 11:46:35 +0000 UTC hostedclusters kx-eceddecb18 WebIdentityErr 2025-10-21 11:47:02 +0000 UTC hostedclusters kx-eceddecb18 EtcdAvailable QuorumAvailable 2025-10-21 11:47:45 +0000 UTC hostedclusters kx-eceddecb18 Kube APIServer deployment is available 2025-10-21 11:48:05 +0000 UTC hostedclusters kx-eceddecb18 All is well 2025-10-21 11:48:07 +0000 UTC hostedclusters kx-eceddecb18 All is well 2025-10-21 11:48:10 +0000 UTC hostedclusters kx-eceddecb18 Ignition server deployment is available 2025-10-21 11:48:34 +0000 UTC hostedclusters kx-eceddecb18 Unable to apply 4.19.9: some cluster operators are not available 2025-10-21 11:48:34 +0000 UTC hostedclusters kx-eceddecb18 Payload loaded version="4.19.9" image="quay.io/openshift-release-dev/ocp-release@sha256:fda39a9c5701bf35da74263177d8976d4bd9205e69b9a9d5834389f71005d51a" architecture="Multi" 2025-10-21 11:48:34 +0000 UTC hostedclusters kx-eceddecb18 ClusterVersionAvailable FromClusterVersion 2025-10-21 11:48:40 +0000 UTC hostedclusters kx-eceddecb18 An update is already in progress and the details are in the Progressing condition 2025-10-21 11:48:55 +0000 UTC hostedclusters kx-eceddecb18 The hosted control plane is available INFO: Cluster 'kx-eceddecb18' is now ready INFO: ROSA with HCP cluster is ready, create a cluster admin account for accessing the cluster WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. INFO: Storing login command... INFO: Check if it's able to login to OCP cluster... Retried 1 times... Retried 2 times... Retried 3 times... INFO: Check if apiserver is ready... Waiting for cluster operators to be accessible for 2m... NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.19.9 True False False 5m27s dns 4.19.9 False False True 5m29s DNS "default" is unavailable. image-registry False True True 5m12s Available: The deployment does not have available replicas... ingress False True True 5m9s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.19.9 True False False 5m18s kube-controller-manager 4.19.9 True False False 5m18s kube-scheduler 4.19.9 True False False 5m18s kube-storage-version-migrator monitoring network 4.19.9 True True False 4m58s DaemonSet "/openshift-multus/network-metrics-daemon" is waiting for other operators to become ready... node-tuning False True False 5m22s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.19.9 True False False 5m18s openshift-controller-manager 4.19.9 True False False 5m18s openshift-samples operator-lifecycle-manager 4.19.9 True False False 5m22s operator-lifecycle-manager-catalog 4.19.9 True False False 5m6s operator-lifecycle-manager-packageserver 4.19.9 True False False 5m18s service-ca storage 4.19.9 False False False 5m18s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service cluster operators to be accessible finished! [INFO] Cluster operators are accessible. Waiting for cluster to be reported as healthy for 60m... NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.19.9 True False False 5m27s dns 4.19.9 False False True 5m29s DNS "default" is unavailable. image-registry False True True 5m12s Available: The deployment does not have available replicas... ingress False True True 5m9s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.19.9 True False False 5m18s kube-controller-manager 4.19.9 True False False 5m18s kube-scheduler 4.19.9 True False False 5m18s kube-storage-version-migrator monitoring network 4.19.9 True True False 4m58s DaemonSet "/openshift-multus/network-metrics-daemon" is waiting for other operators to become ready... node-tuning False True False 5m22s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.19.9 True False False 5m18s openshift-controller-manager 4.19.9 True False False 5m18s openshift-samples operator-lifecycle-manager 4.19.9 True False False 5m22s operator-lifecycle-manager-catalog 4.19.9 True False False 5m6s operator-lifecycle-manager-packageserver 4.19.9 True False False 5m18s service-ca storage 4.19.9 False False False 5m18s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.19.9 True False False 6m27s dns 4.19.9 False False True 6m29s DNS "default" is unavailable. image-registry False True True 6m12s Available: The deployment does not have available replicas... ingress False True True 6m9s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.19.9 True False False 6m18s kube-controller-manager 4.19.9 True False False 6m18s kube-scheduler 4.19.9 True False False 6m18s kube-storage-version-migrator monitoring network 4.19.9 True True False 5m58s DaemonSet "/openshift-multus/multus-additional-cni-plugins" is not available (awaiting 1 nodes)... node-tuning 4.19.9 True True False 8s Waiting for 1/1 Profiles to be applied openshift-apiserver 4.19.9 True False False 6m18s openshift-controller-manager 4.19.9 True False False 6m18s openshift-samples operator-lifecycle-manager 4.19.9 True False False 6m22s operator-lifecycle-manager-catalog 4.19.9 True False False 6m6s operator-lifecycle-manager-packageserver 4.19.9 True False False 6m18s service-ca storage 4.19.9 True False False 4s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.19.9 True False False 7m27s dns 4.19.9 False True True 7m29s DNS "default" is unavailable. image-registry False True True 7m12s Available: The deployment does not have available replicas... ingress False True True 7m9s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.19.9 True False False 7m18s kube-controller-manager 4.19.9 True False False 7m18s kube-scheduler 4.19.9 True False False 7m18s kube-storage-version-migrator monitoring network 4.19.9 True True False 6m58s DaemonSet "/openshift-multus/network-metrics-daemon" is waiting for other operators to become ready... node-tuning 4.19.9 True False False 47s openshift-apiserver 4.19.9 True False False 7m18s openshift-controller-manager 4.19.9 True False False 7m18s openshift-samples operator-lifecycle-manager 4.19.9 True False False 7m22s operator-lifecycle-manager-catalog 4.19.9 True False False 7m6s operator-lifecycle-manager-packageserver 4.19.9 True False False 7m18s service-ca storage 4.19.9 True False False 64s Waiting for cluster to be reported as healthy... Trying again in 60s Unable to connect to the server: dial tcp: lookup api.kx-eceddecb18.smht.p3.openshiftapps.com on 172.30.0.10:53: no such host Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.19.9 True False False 3s csi-snapshot-controller 4.19.9 True False False 9m28s dns 4.19.9 True True True 26s DNS default is degraded image-registry True True False 28s Progressing: The deployment has not completed... ingress 4.19.9 True False False 10s insights 4.19.9 True False False 71s kube-apiserver 4.19.9 True False False 9m19s kube-controller-manager 4.19.9 True False False 9m19s kube-scheduler 4.19.9 True False False 9m19s kube-storage-version-migrator 4.19.9 True False False 69s monitoring Unknown True Unknown 56s Rolling out the stack. network 4.19.9 True True False 8m59s DaemonSet "/openshift-multus/network-metrics-daemon" is not available (awaiting 1 nodes) node-tuning 4.19.9 True False False 2m48s openshift-apiserver 4.19.9 True False False 9m19s openshift-controller-manager 4.19.9 True False False 9m19s openshift-samples 4.19.9 True False False 4s operator-lifecycle-manager 4.19.9 True False False 9m23s operator-lifecycle-manager-catalog 4.19.9 True False False 9m7s operator-lifecycle-manager-packageserver 4.19.9 True False False 9m19s service-ca 4.19.9 True False False 69s storage 4.19.9 True False False 3m5s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.19.9 True False False 63s csi-snapshot-controller 4.19.9 True False False 10m dns 4.19.9 True False False 86s image-registry 4.19.9 True False False 88s ingress 4.19.9 True False False 70s insights 4.19.9 True False False 2m11s kube-apiserver 4.19.9 True False False 10m kube-controller-manager 4.19.9 True False False 10m kube-scheduler 4.19.9 True False False 10m kube-storage-version-migrator 4.19.9 True False False 2m9s monitoring Unknown True Unknown 116s Rolling out the stack. network 4.19.9 True False False 9m59s node-tuning 4.19.9 True False False 3m48s openshift-apiserver 4.19.9 True False False 10m openshift-controller-manager 4.19.9 True False False 10m openshift-samples 4.19.9 True False False 64s operator-lifecycle-manager 4.19.9 True False False 10m operator-lifecycle-manager-catalog 4.19.9 True False False 10m operator-lifecycle-manager-packageserver 4.19.9 True False False 10m service-ca 4.19.9 True False False 2m9s storage 4.19.9 True False False 4m5s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.19.9 True False False 2m3s csi-snapshot-controller 4.19.9 True False False 11m dns 4.19.9 True False False 2m26s image-registry 4.19.9 True False False 2m28s ingress 4.19.9 True False False 2m10s insights 4.19.9 True False False 3m11s kube-apiserver 4.19.9 True False False 11m kube-controller-manager 4.19.9 True False False 11m kube-scheduler 4.19.9 True False False 11m kube-storage-version-migrator 4.19.9 True False False 3m9s monitoring Unknown True Unknown 2m56s Rolling out the stack. network 4.19.9 True False False 10m node-tuning 4.19.9 True False False 4m48s openshift-apiserver 4.19.9 True False False 11m openshift-controller-manager 4.19.9 True False False 11m openshift-samples 4.19.9 True False False 2m4s operator-lifecycle-manager 4.19.9 True False False 11m operator-lifecycle-manager-catalog 4.19.9 True False False 11m operator-lifecycle-manager-packageserver 4.19.9 True False False 11m service-ca 4.19.9 True False False 3m9s storage 4.19.9 True False False 5m5s Waiting for cluster to be reported as healthy... Trying again in 60s healthy cluster to be reported as healthy finished!