INFO: Log in to your Red Hat account... INFO: Configure AWS Credentials... WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. INFO: Logged in as 'rhtap-shared' on 'https://api.openshift.com' INFO: Create ROSA with HCP cluster... WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. INFO: Creating cluster 'kx-c80b1c5347' INFO: To view a list of clusters and their status, run 'rosa list clusters' INFO: Cluster 'kx-c80b1c5347' has been created. INFO: Once the cluster is installed you will need to add an Identity Provider before you can login into the cluster. See 'rosa create idp --help' for more information. Name: kx-c80b1c5347 Domain Prefix: kx-c80b1c5347 Display Name: kx-c80b1c5347 ID: 2mdhv9gv6t5n0ors46b8mliquiq7qb2c External ID: 847ce4c4-b75e-458c-b95c-e500bd94f475 Control Plane: ROSA Service Hosted OpenShift Version: 4.19.9 Channel Group: stable DNS: Not ready AWS Account: 381492310364 AWS Billing Account: 381492310364 API URL: Console URL: Region: us-east-1 Availability: - Control Plane: MultiAZ - Data Plane: MultiAZ Nodes: - Compute (desired): 3 - Compute (current): 0 Network: - Type: OVNKubernetes - Service CIDR: 172.30.0.0/16 - Machine CIDR: 10.0.0.0/16 - Pod CIDR: 10.128.0.0/14 - Host Prefix: /23 - Subnets: subnet-0208a6297964e4fe1, subnet-0c161c939f7025e15, subnet-023e5c7b3016ed194, subnet-02dbd8abbf884d77f, subnet-0360c2d20442c5ba5, subnet-0aad9c992e402a91a EC2 Metadata Http Tokens: optional Role (STS) ARN: arn:aws:iam::381492310364:role/rhads-hcp-HCP-ROSA-Installer-Role Support Role ARN: arn:aws:iam::381492310364:role/rhads-hcp-HCP-ROSA-Support-Role Instance IAM Roles: - Worker: arn:aws:iam::381492310364:role/rhads-hcp-HCP-ROSA-Worker-Role Operator IAM Roles: - arn:aws:iam::381492310364:role/rhads-hcp-openshift-ingress-operator-cloud-credentials - arn:aws:iam::381492310364:role/rhads-hcp-openshift-cluster-csi-drivers-ebs-cloud-credentials - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-kube-controller-manager - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-capa-controller-manager - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-control-plane-operator - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-kms-provider - arn:aws:iam::381492310364:role/rhads-hcp-openshift-cloud-network-config-controller-cloud-creden - arn:aws:iam::381492310364:role/rhads-hcp-openshift-image-registry-installer-cloud-credentials Managed Policies: Yes State: waiting (Waiting for user action) Private: No Delete Protection: Disabled Created: Nov 7 2025 03:55:21 UTC [DEPRECATED] User Workload Monitoring: Enabled Details Page: https://console.redhat.com/openshift/details/s/358NQN2gVeqibnn1umk02QT0tWd OIDC Endpoint URL: https://oidc.op1.openshiftapps.com/2jtsga3i2etnl697l7bk5i1kmbm4a95j (Managed) Etcd Encryption: Disabled Audit Log Forwarding: Disabled External Authentication: Disabled Zero Egress: Disabled INFO: Preparing to create operator roles. INFO: Operator Roles already exists INFO: Preparing to create OIDC Provider. INFO: OIDC provider already exists INFO: To determine when your cluster is Ready, run 'rosa describe cluster -c kx-c80b1c5347'. INFO: To watch your cluster installation logs, run 'rosa logs install -c kx-c80b1c5347 --watch'. INFO: Track the progress of the cluster creation... WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. W: Region flag will be removed from this command in future versions INFO: Cluster 'kx-c80b1c5347' is in waiting state waiting for installation to begin. Logs will show up within 5 minutes 0001-01-01 00:00:00 +0000 UTC hostedclusters kx-c80b1c5347 Version 2025-11-07 03:59:56 +0000 UTC hostedclusters kx-c80b1c5347 ValidAWSIdentityProvider StatusUnknown 2025-11-07 03:59:57 +0000 UTC certificates cluster-api-cert Issuing certificate as Secret does not exist 2025-11-07 03:59:57 +0000 UTC certificates cluster-api-cert Issuing certificate as Secret does not exist 2025-11-07 03:59:59 +0000 UTC hostedclusters kx-c80b1c5347 The hosted control plane is not found 2025-11-07 03:59:59 +0000 UTC hostedclusters kx-c80b1c5347 Condition not found in the CVO. 2025-11-07 03:59:59 +0000 UTC hostedclusters kx-c80b1c5347 ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-11-07 03:59:59 +0000 UTC hostedclusters kx-c80b1c5347 The hosted control plane is not found 2025-11-07 03:59:59 +0000 UTC hostedclusters kx-c80b1c5347 The hosted control plane is not found 2025-11-07 03:59:59 +0000 UTC hostedclusters kx-c80b1c5347 Condition not found in the CVO. 2025-11-07 03:59:59 +0000 UTC hostedclusters kx-c80b1c5347 Condition not found in the CVO. 2025-11-07 03:59:59 +0000 UTC hostedclusters kx-c80b1c5347 Condition not found in the CVO. 2025-11-07 03:59:59 +0000 UTC hostedclusters kx-c80b1c5347 Condition not found in the CVO. 2025-11-07 03:59:59 +0000 UTC hostedclusters kx-c80b1c5347 The hosted control plane is not found 2025-11-07 03:59:59 +0000 UTC hostedclusters kx-c80b1c5347 Ignition server deployment not found 2025-11-07 03:59:59 +0000 UTC hostedclusters kx-c80b1c5347 NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-11-07 03:59:59 +0000 UTC hostedclusters kx-c80b1c5347 HostedCluster is supported by operator configuration 2025-11-07 03:59:59 +0000 UTC hostedclusters kx-c80b1c5347 Release image is valid 2025-11-07 03:59:59 +0000 UTC hostedclusters kx-c80b1c5347 The hosted control plane is not found 2025-11-07 03:59:59 +0000 UTC hostedclusters kx-c80b1c5347 Reconciliation active on resource 2025-11-07 03:59:59 +0000 UTC hostedclusters kx-c80b1c5347 ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2025-11-07 03:59:59 +0000 UTC hostedclusters kx-c80b1c5347 The hosted control plane is not found 2025-11-07 03:59:59 +0000 UTC hostedclusters kx-c80b1c5347 The hosted control plane is not found 2025-11-07 04:00:00 +0000 UTC hostedclusters kx-c80b1c5347 configuration is invalid: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 0001-01-01 00:00:00 +0000 UTC hostedclusters kx-c80b1c5347 Version 2025-11-07 03:59:59 +0000 UTC hostedclusters kx-c80b1c5347 Release image is valid 2025-11-07 03:59:59 +0000 UTC hostedclusters kx-c80b1c5347 Waiting for hosted control plane kubeconfig to be created 2025-11-07 03:59:59 +0000 UTC hostedclusters kx-c80b1c5347 Reconciliation active on resource 2025-11-07 03:59:59 +0000 UTC hostedclusters kx-c80b1c5347 HostedCluster is at expected version 2025-11-07 03:59:59 +0000 UTC hostedclusters kx-c80b1c5347 Ignition server deployment not found 2025-11-07 03:59:59 +0000 UTC hostedclusters kx-c80b1c5347 HostedCluster is supported by operator configuration 2025-11-07 03:59:59 +0000 UTC hostedclusters kx-c80b1c5347 Condition not found in the CVO. 2025-11-07 03:59:59 +0000 UTC hostedclusters kx-c80b1c5347 Condition not found in the CVO. 2025-11-07 03:59:59 +0000 UTC hostedclusters kx-c80b1c5347 Condition not found in the CVO. 2025-11-07 03:59:59 +0000 UTC hostedclusters kx-c80b1c5347 Condition not found in the CVO. 2025-11-07 03:59:59 +0000 UTC hostedclusters kx-c80b1c5347 Condition not found in the CVO. 2025-11-07 04:01:27 +0000 UTC certificates cluster-api-cert Certificate is up to date and has not expired 2025-11-07 04:01:29 +0000 UTC hostedclusters kx-c80b1c5347 Configuration passes validation 2025-11-07 04:01:30 +0000 UTC hostedclusters kx-c80b1c5347 Required platform credentials are found 2025-11-07 04:01:33 +0000 UTC hostedclusters kx-c80b1c5347 AWS KMS is not configured 2025-11-07 04:01:33 +0000 UTC hostedclusters kx-c80b1c5347 capi-provider deployment has 1 unavailable replicas 2025-11-07 04:01:33 +0000 UTC hostedclusters kx-c80b1c5347 lookup api.kx-c80b1c5347.wtpc.p3.openshiftapps.com on 172.30.0.10:53: no such host 2025-11-07 04:01:33 +0000 UTC hostedclusters kx-c80b1c5347 Configuration passes validation 2025-11-07 04:01:33 +0000 UTC hostedclusters kx-c80b1c5347 Waiting for etcd to reach quorum 2025-11-07 04:01:33 +0000 UTC hostedclusters kx-c80b1c5347 Kube APIServer deployment not found 2025-11-07 04:01:36 +0000 UTC hostedclusters kx-c80b1c5347 OIDC configuration is valid 2025-11-07 04:01:36 +0000 UTC hostedclusters kx-c80b1c5347 Reconciliation completed successfully 2025-11-07 04:01:54 +0000 UTC hostedclusters kx-c80b1c5347 All is well 2025-11-07 04:01:54 +0000 UTC hostedclusters kx-c80b1c5347 All is well 2025-11-07 04:02:02 +0000 UTC hostedclusters kx-c80b1c5347 WebIdentityErr 2025-11-07 04:02:12 +0000 UTC hostedclusters kx-c80b1c5347 EtcdAvailable QuorumAvailable 2025-11-07 04:03:18 +0000 UTC hostedclusters kx-c80b1c5347 Kube APIServer deployment is available 2025-11-07 04:03:32 +0000 UTC hostedclusters kx-c80b1c5347 All is well 2025-11-07 04:03:37 +0000 UTC hostedclusters kx-c80b1c5347 Ignition server deployment is available 2025-11-07 04:03:50 +0000 UTC hostedclusters kx-c80b1c5347 All is well 2025-11-07 04:03:53 +0000 UTC hostedclusters kx-c80b1c5347 ClusterVersionSucceeding FromClusterVersion 2025-11-07 04:03:53 +0000 UTC hostedclusters kx-c80b1c5347 Payload loaded version="4.19.9" image="quay.io/openshift-release-dev/ocp-release@sha256:fda39a9c5701bf35da74263177d8976d4bd9205e69b9a9d5834389f71005d51a" architecture="Multi" 2025-11-07 04:03:53 +0000 UTC hostedclusters kx-c80b1c5347 ClusterVersionAvailable FromClusterVersion 2025-11-07 04:03:53 +0000 UTC hostedclusters kx-c80b1c5347 Working towards 4.19.9: 534 of 629 done (84% complete) 2025-11-07 04:03:59 +0000 UTC hostedclusters kx-c80b1c5347 An update is already in progress and the details are in the Progressing condition 2025-11-07 04:04:22 +0000 UTC hostedclusters kx-c80b1c5347 Cluster operators console, dns, image-registry, ingress, insights, kube-storage-version-migrator, monitoring, node-tuning, openshift-samples, service-ca, storage are not available 2025-11-07 04:04:37 +0000 UTC hostedclusters kx-c80b1c5347 The hosted control plane is available INFO: Cluster 'kx-c80b1c5347' is now ready INFO: ROSA with HCP cluster is ready, create a cluster admin account for accessing the cluster WARN: The current version (1.2.56) is not up to date with latest rosa cli released version (1.2.57). WARN: It is recommended that you update to the latest version. INFO: Storing login command... INFO: Check if it's able to login to OCP cluster... Retried 1 times... INFO: Check if apiserver is ready... Waiting for cluster operators to be accessible for 2m... Unable to connect to the server: dial tcp: lookup api.kx-c80b1c5347.wtpc.p3.openshiftapps.com on 172.30.0.10:53: no such host Waiting for cluster operators to be accessible... Trying again in 10s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.19.9 True False False 3m59s dns 4.19.9 False False True 3m56s DNS "default" is unavailable. image-registry False True True 3m41s Available: The deployment does not have available replicas... ingress False True True 3m39s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.19.9 True False False 3m46s kube-controller-manager 4.19.9 True False False 3m46s kube-scheduler 4.19.9 True False False 3m46s kube-storage-version-migrator monitoring network 4.19.9 True True False 3m31s Deployment "/openshift-network-console/networking-console-plugin" is not available (awaiting 2 nodes) node-tuning False True False 3m47s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.19.9 True False False 3m46s openshift-controller-manager 4.19.9 True False False 3m46s openshift-samples operator-lifecycle-manager 4.19.9 True False False 3m47s operator-lifecycle-manager-catalog 4.19.9 True False False 3m38s operator-lifecycle-manager-packageserver 4.19.9 True False False 3m46s service-ca storage 4.19.9 False False False 3m45s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service cluster operators to be accessible finished! [INFO] Cluster operators are accessible. Waiting for cluster to be reported as healthy for 60m... Unable to connect to the server: dial tcp: lookup api.kx-c80b1c5347.wtpc.p3.openshiftapps.com on 172.30.0.10:53: no such host Waiting for cluster to be reported as healthy... Trying again in 60s Unable to connect to the server: dial tcp: lookup api.kx-c80b1c5347.wtpc.p3.openshiftapps.com on 172.30.0.10:53: no such host Waiting for cluster to be reported as healthy... Trying again in 60s Unable to connect to the server: dial tcp: lookup api.kx-c80b1c5347.wtpc.p3.openshiftapps.com on 172.30.0.10:53: no such host Waiting for cluster to be reported as healthy... Trying again in 60s Unable to connect to the server: dial tcp: lookup api.kx-c80b1c5347.wtpc.p3.openshiftapps.com on 172.30.0.10:53: no such host Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.19.9 True False False 8m dns 4.19.9 False True True 7m57s DNS "default" is unavailable. image-registry False True True 7m42s Available: The deployment does not have available replicas... ingress False True True 7m40s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.19.9 True False False 7m47s kube-controller-manager 4.19.9 True False False 7m47s kube-scheduler 4.19.9 True False False 7m47s kube-storage-version-migrator monitoring network 4.19.9 True True False 7m32s DaemonSet "/openshift-multus/network-metrics-daemon" is not available (awaiting 1 nodes)... node-tuning 4.19.9 True False False 73s openshift-apiserver 4.19.9 True False False 7m47s openshift-controller-manager 4.19.9 True False False 7m47s openshift-samples operator-lifecycle-manager 4.19.9 True False False 7m48s operator-lifecycle-manager-catalog 4.19.9 True False False 7m39s operator-lifecycle-manager-packageserver 4.19.9 True False False 7m47s service-ca storage 4.19.9 True False False 59s Waiting for cluster to be reported as healthy... Trying again in 60s Unable to connect to the server: dial tcp: lookup api.kx-c80b1c5347.wtpc.p3.openshiftapps.com on 172.30.0.10:53: no such host Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.19.9 True True False 20s SyncLoopRefreshProgressing: working toward version 4.19.9, 1 replicas available csi-snapshot-controller 4.19.9 True False False 10m dns 4.19.9 True False False 15s image-registry False True True 9m42s Available: The deployment does not have available replicas... ingress 4.19.9 True True True 49s The "default" ingress controller reports Degraded=True: DegradedConditions: One or more other status conditions indicate a degraded state: CanaryChecksSucceeding=Unknown (CanaryRouteNotAdmitted: Canary route is not admitted by the default ingress controller). insights 4.19.9 True False False 108s kube-apiserver 4.19.9 True False False 9m47s kube-controller-manager 4.19.9 True False False 9m47s kube-scheduler 4.19.9 True False False 9m47s kube-storage-version-migrator 4.19.9 True False False 104s monitoring Unknown True Unknown 76s Rolling out the stack. network 4.19.9 True True False 9m32s DaemonSet "/openshift-ovn-kubernetes/ovnkube-node" is not available (awaiting 1 nodes)... node-tuning 4.19.9 True True False 38s Waiting for 1/2 Profiles to be applied openshift-apiserver 4.19.9 True False False 9m47s openshift-controller-manager 4.19.9 True False False 9m47s openshift-samples 4.19.9 True False False 3s operator-lifecycle-manager 4.19.9 True False False 9m48s operator-lifecycle-manager-catalog 4.19.9 True False False 9m39s operator-lifecycle-manager-packageserver 4.19.9 True False False 9m47s service-ca 4.19.9 True False False 106s storage 4.19.9 True False False 2m59s Waiting for cluster to be reported as healthy... Trying again in 60s Unable to connect to the server: dial tcp: lookup api.kx-c80b1c5347.wtpc.p3.openshiftapps.com on 172.30.0.10:53: no such host Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.19.9 True True False 2m21s SyncLoopRefreshProgressing: working toward version 4.19.9, 1 replicas available csi-snapshot-controller 4.19.9 True False False 12m dns 4.19.9 True False False 2m16s image-registry 4.19.9 True False False 113s ingress 4.19.9 True False False 2m50s insights 4.19.9 True False False 3m49s kube-apiserver 4.19.9 True False False 11m kube-controller-manager 4.19.9 True False False 11m kube-scheduler 4.19.9 True False False 11m kube-storage-version-migrator 4.19.9 True False False 3m45s monitoring Unknown True Unknown 3m17s Rolling out the stack. network 4.19.9 True False False 11m node-tuning 4.19.9 True False False 2m39s openshift-apiserver 4.19.9 True False False 11m openshift-controller-manager 4.19.9 True False False 11m openshift-samples 4.19.9 True False False 2m4s operator-lifecycle-manager 4.19.9 True False False 11m operator-lifecycle-manager-catalog 4.19.9 True False False 11m operator-lifecycle-manager-packageserver 4.19.9 True False False 11m service-ca 4.19.9 True False False 3m47s storage 4.19.9 True False False 5m Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.19.9 True True False 3m21s SyncLoopRefreshProgressing: working toward version 4.19.9, 1 replicas available csi-snapshot-controller 4.19.9 True False False 13m dns 4.19.9 True False False 3m16s image-registry 4.19.9 True False False 2m53s ingress 4.19.9 True False False 3m50s insights 4.19.9 True False False 4m49s kube-apiserver 4.19.9 True False False 12m kube-controller-manager 4.19.9 True False False 12m kube-scheduler 4.19.9 True False False 12m kube-storage-version-migrator 4.19.9 True False False 4m45s monitoring 4.19.9 True False False 57s network 4.19.9 True False False 12m node-tuning 4.19.9 True False False 3m39s openshift-apiserver 4.19.9 True False False 12m openshift-controller-manager 4.19.9 True False False 12m openshift-samples 4.19.9 True False False 3m4s operator-lifecycle-manager 4.19.9 True False False 12m operator-lifecycle-manager-catalog 4.19.9 True False False 12m operator-lifecycle-manager-packageserver 4.19.9 True False False 12m service-ca 4.19.9 True False False 4m47s storage 4.19.9 True False False 6m Waiting for cluster to be reported as healthy... Trying again in 60s Unable to connect to the server: dial tcp: lookup api.kx-c80b1c5347.wtpc.p3.openshiftapps.com on 172.30.0.10:53: no such host Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.19.9 True False False 5m22s csi-snapshot-controller 4.19.9 True False False 15m dns 4.19.9 True False False 5m17s image-registry 4.19.9 True False False 4m54s ingress 4.19.9 True False False 5m51s insights 4.19.9 True False False 6m50s kube-apiserver 4.19.9 True False False 14m kube-controller-manager 4.19.9 True False False 14m kube-scheduler 4.19.9 True False False 14m kube-storage-version-migrator 4.19.9 True False False 6m46s monitoring 4.19.9 True False False 2m58s network 4.19.9 True False False 14m node-tuning 4.19.9 True False False 5m40s openshift-apiserver 4.19.9 True False False 14m openshift-controller-manager 4.19.9 True False False 14m openshift-samples 4.19.9 True False False 5m5s operator-lifecycle-manager 4.19.9 True False False 14m operator-lifecycle-manager-catalog 4.19.9 True False False 14m operator-lifecycle-manager-packageserver 4.19.9 True False False 14m service-ca 4.19.9 True False False 6m48s storage 4.19.9 True False False 8m1s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.19.9 True False False 6m22s csi-snapshot-controller 4.19.9 True False False 16m dns 4.19.9 True False False 6m17s image-registry 4.19.9 True False False 5m54s ingress 4.19.9 True False False 6m51s insights 4.19.9 True False False 7m50s kube-apiserver 4.19.9 True False False 15m kube-controller-manager 4.19.9 True False False 15m kube-scheduler 4.19.9 True False False 15m kube-storage-version-migrator 4.19.9 True False False 7m46s monitoring 4.19.9 True False False 3m58s network 4.19.9 True False False 15m node-tuning 4.19.9 True False False 6m40s openshift-apiserver 4.19.9 True False False 15m openshift-controller-manager 4.19.9 True False False 15m openshift-samples 4.19.9 True False False 6m5s operator-lifecycle-manager 4.19.9 True False False 15m operator-lifecycle-manager-catalog 4.19.9 True False False 15m operator-lifecycle-manager-packageserver 4.19.9 True False False 15m service-ca 4.19.9 True False False 7m48s storage 4.19.9 True False False 9m1s Waiting for cluster to be reported as healthy... Trying again in 60s healthy cluster to be reported as healthy finished!