INFO: Log in to your Red Hat account... INFO: Configure AWS Credentials... WARN: The current version (1.2.59) is not up to date with latest rosa cli released version (1.2.62). WARN: It is recommended that you update to the latest version. INFO: Logged in as 'rhtap-shared' on 'https://api.openshift.com' INFO: Create ROSA with HCP cluster... WARN: The current version (1.2.59) is not up to date with latest rosa cli released version (1.2.62). WARN: It is recommended that you update to the latest version. INFO: Creating cluster 'kx-0301960e0d' INFO: To view a list of clusters and their status, run 'rosa list clusters' INFO: Cluster 'kx-0301960e0d' has been created. INFO: Once the cluster is installed you will need to add an Identity Provider before you can login into the cluster. See 'rosa create idp --help' for more information. Name: kx-0301960e0d Domain Prefix: kx-0301960e0d Display Name: kx-0301960e0d ID: 2q6fh5uksgf8ho8c7sqttage51n1jsro External ID: 3af8733c-8cb1-42bd-8926-b1abd7b86fec Control Plane: ROSA Service Hosted OpenShift Version: 4.20.21 Channel Group: stable DNS: Not ready AWS Account: 381492310364 AWS Billing Account: 381492310364 API URL: Console URL: Region: us-east-1 Availability: - Control Plane: MultiAZ - Data Plane: MultiAZ Nodes: - Compute (desired): 3 - Compute (current): 0 Network: - Type: OVNKubernetes - Service CIDR: 172.30.0.0/16 - Machine CIDR: 10.0.0.0/16 - Pod CIDR: 10.128.0.0/14 - Host Prefix: /23 - Subnets: subnet-0208a6297964e4fe1, subnet-0c161c939f7025e15, subnet-023e5c7b3016ed194, subnet-02dbd8abbf884d77f, subnet-0360c2d20442c5ba5, subnet-0aad9c992e402a91a EC2 Metadata Http Tokens: optional Role (STS) ARN: arn:aws:iam::381492310364:role/rhads-hcp-HCP-ROSA-Installer-Role Support Role ARN: arn:aws:iam::381492310364:role/rhads-hcp-HCP-ROSA-Support-Role Instance IAM Roles: - Worker: arn:aws:iam::381492310364:role/rhads-hcp-HCP-ROSA-Worker-Role Operator IAM Roles: - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-control-plane-operator - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-kms-provider - arn:aws:iam::381492310364:role/rhads-hcp-openshift-image-registry-installer-cloud-credentials - arn:aws:iam::381492310364:role/rhads-hcp-openshift-ingress-operator-cloud-credentials - arn:aws:iam::381492310364:role/rhads-hcp-openshift-cluster-csi-drivers-ebs-cloud-credentials - arn:aws:iam::381492310364:role/rhads-hcp-openshift-cloud-network-config-controller-cloud-creden - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-kube-controller-manager - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-capa-controller-manager Managed Policies: Yes State: waiting (Waiting for user action) Private: No Delete Protection: Disabled Created: May 9 2026 14:37:14 UTC Details Page: https://console.redhat.com/openshift/details/s/3DUX4wqGllqYV3jELaoV0OJFYt8 OIDC Endpoint URL: https://oidc.op1.openshiftapps.com/2jtsga3i2etnl697l7bk5i1kmbm4a95j (Managed) Etcd Encryption: Disabled Audit Log Forwarding: Disabled External Authentication: Disabled INFO: Preparing to create operator roles. INFO: Operator Roles already exists INFO: Preparing to create OIDC Provider. INFO: OIDC provider already exists INFO: To determine when your cluster is Ready, run 'rosa describe cluster -c kx-0301960e0d'. INFO: To watch your cluster installation logs, run 'rosa logs install -c kx-0301960e0d --watch'. INFO: Track the progress of the cluster creation... WARN: The current version (1.2.59) is not up to date with latest rosa cli released version (1.2.62). WARN: It is recommended that you update to the latest version. W: Region flag will be removed from this command in future versions INFO: Cluster 'kx-0301960e0d' is in waiting state waiting for installation to begin. Logs will show up within 5 minutes 0001-01-01 00:00:00 +0000 UTC hostedclusters kx-0301960e0d Version 2026-05-09 14:40:38 +0000 UTC hostedclusters kx-0301960e0d ValidAWSIdentityProvider StatusUnknown 2026-05-09 14:40:39 +0000 UTC certificates cluster-api-cert Issuing certificate as Secret does not exist 2026-05-09 14:40:39 +0000 UTC certificates cluster-api-cert Issuing certificate as Secret does not exist 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d The hosted control plane is not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Condition not found in the CVO. 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d The hosted control plane is not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d The hosted control plane is not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Condition not found in the CVO. 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Condition not found in the CVO. 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Condition not found in the CVO. 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Condition not found in the CVO. 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d The hosted control plane is not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Ignition server deployment not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d HostedCluster is supported by operator configuration 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Release image is valid 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d The hosted control plane is not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Reconciliation active on resource 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d configuration is invalid: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d The hosted control plane is not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d The hosted control plane is not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d The hosted control plane is not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d The hosted control plane is not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Condition not found in the CVO. 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Condition not found in the CVO. 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Condition not found in the CVO. 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Condition not found in the CVO. 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d The hosted control plane is not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Ignition server deployment not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d HostedCluster is supported by operator configuration 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Release image is valid 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d The hosted control plane is not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Reconciliation active on resource 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d configuration is invalid: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d The hosted control plane is not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d The hosted control plane is not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d The hosted control plane is not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d The hosted control plane is not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Condition not found in the CVO. 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Condition not found in the CVO. 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Condition not found in the CVO. 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Condition not found in the CVO. 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d The hosted control plane is not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Ignition server deployment not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d HostedCluster is supported by operator configuration 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Release image is valid 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d The hosted control plane is not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Reconciliation active on resource 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d configuration is invalid: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d The hosted control plane is not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d The hosted control plane is not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d The hosted control plane is not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d The hosted control plane is not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Condition not found in the CVO. 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Condition not found in the CVO. 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Condition not found in the CVO. 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Condition not found in the CVO. 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d The hosted control plane is not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Ignition server deployment not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d HostedCluster is supported by operator configuration 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Release image is valid 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d The hosted control plane is not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Reconciliation active on resource 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d configuration is invalid: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d The hosted control plane is not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d The hosted control plane is not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d The hosted control plane is not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d The hosted control plane is not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Condition not found in the CVO. 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Condition not found in the CVO. 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Condition not found in the CVO. 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Condition not found in the CVO. 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d The hosted control plane is not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Ignition server deployment not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d HostedCluster is supported by operator configuration 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Release image is valid 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d The hosted control plane is not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Reconciliation active on resource 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d configuration is invalid: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d The hosted control plane is not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d The hosted control plane is not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 0001-01-01 00:00:00 +0000 UTC hostedclusters kx-0301960e0d Version 2026-05-09 14:40:38 +0000 UTC hostedclusters kx-0301960e0d ValidAWSIdentityProvider StatusUnknown 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Release image is valid 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Condition not found in the HCP 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d HostedCluster is at expected version 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Reconciliation active on resource 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Ignition server deployment not found 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d HostedCluster is supported by operator configuration 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Condition not found in the CVO. 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Condition not found in the CVO. 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Condition not found in the CVO. 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Condition not found in the CVO. 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d router load balancer is not provisioned; 7s since creation.; router load balancer is not provisioned; 7s since creation. 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Condition not found in the CVO. 2026-05-09 14:42:05 +0000 UTC certificates cluster-api-cert Certificate is up to date and has not expired 2026-05-09 14:42:10 +0000 UTC hostedclusters kx-0301960e0d Configuration passes validation 2026-05-09 14:42:10 +0000 UTC hostedclusters kx-0301960e0d Required platform credentials are found 2026-05-09 14:42:12 +0000 UTC hostedclusters kx-0301960e0d OIDC configuration is valid 2026-05-09 14:42:12 +0000 UTC hostedclusters kx-0301960e0d Reconciliation completed successfully 2026-05-09 14:42:17 +0000 UTC hostedclusters kx-0301960e0d router load balancer is not provisioned; 7s since creation.; router load balancer is not provisioned; 7s since creation. 2026-05-09 14:42:17 +0000 UTC hostedclusters kx-0301960e0d lookup api.kx-0301960e0d.e436.p3.openshiftapps.com on 172.30.0.10:53: no such host 2026-05-09 14:42:17 +0000 UTC hostedclusters kx-0301960e0d Configuration passes validation 2026-05-09 14:42:17 +0000 UTC hostedclusters kx-0301960e0d capi-provider deployment has 1 unavailable replicas 2026-05-09 14:42:17 +0000 UTC hostedclusters kx-0301960e0d AWS KMS is not configured 2026-05-09 14:42:17 +0000 UTC hostedclusters kx-0301960e0d EtcdAvailable StatefulSetNotFound 2026-05-09 14:42:17 +0000 UTC hostedclusters kx-0301960e0d Kube APIServer deployment not found 2026-05-09 14:42:17 +0000 UTC hostedclusters kx-0301960e0d Configuration passes validation 2026-05-09 14:42:17 +0000 UTC hostedclusters kx-0301960e0d lookup api.kx-0301960e0d.e436.p3.openshiftapps.com on 172.30.0.10:53: no such host 2026-05-09 14:42:46 +0000 UTC hostedclusters kx-0301960e0d WebIdentityErr 2026-05-09 14:43:32 +0000 UTC hostedclusters kx-0301960e0d All is well 2026-05-09 14:43:32 +0000 UTC hostedclusters kx-0301960e0d All is well 2026-05-09 14:43:32 +0000 UTC hostedclusters kx-0301960e0d All is well 2026-05-09 14:43:32 +0000 UTC hostedclusters kx-0301960e0d All is well 2026-05-09 14:44:01 +0000 UTC hostedclusters kx-0301960e0d EtcdAvailable QuorumAvailable 2026-05-09 14:44:33 +0000 UTC hostedclusters kx-0301960e0d Kube APIServer deployment is available 2026-05-09 14:44:45 +0000 UTC hostedclusters kx-0301960e0d Ignition server deployment is available 2026-05-09 14:44:46 +0000 UTC hostedclusters kx-0301960e0d All is well 2026-05-09 14:44:52 +0000 UTC hostedclusters kx-0301960e0d lookup api.kx-0301960e0d.e436.p3.openshiftapps.com on 172.30.0.10:53: no such host 2026-05-09 14:44:54 +0000 UTC hostedclusters kx-0301960e0d All is well 2026-05-09 14:45:16 +0000 UTC hostedclusters kx-0301960e0d lookup api.kx-0301960e0d.e436.p3.openshiftapps.com on 172.30.0.10:53: no such host 0001-01-01 00:00:00 +0000 UTC hostedclusters kx-0301960e0d Version 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d HostedCluster is at expected version 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Reconciliation active on resource 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Waiting for components to be available: ingress-operator, cluster-network-operator 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Release image is valid 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d HostedCluster is supported by operator configuration 2026-05-09 14:42:05 +0000 UTC certificates cluster-api-cert Certificate is up to date and has not expired 2026-05-09 14:42:10 +0000 UTC hostedclusters kx-0301960e0d Configuration passes validation 2026-05-09 14:42:10 +0000 UTC hostedclusters kx-0301960e0d Required platform credentials are found 2026-05-09 14:42:12 +0000 UTC hostedclusters kx-0301960e0d Reconciliation completed successfully 2026-05-09 14:42:12 +0000 UTC hostedclusters kx-0301960e0d OIDC configuration is valid 2026-05-09 14:42:17 +0000 UTC hostedclusters kx-0301960e0d Configuration passes validation 2026-05-09 14:42:17 +0000 UTC hostedclusters kx-0301960e0d AWS KMS is not configured 2026-05-09 14:42:17 +0000 UTC hostedclusters kx-0301960e0d router deployment has 1 unavailable replicas 2026-05-09 14:43:32 +0000 UTC hostedclusters kx-0301960e0d All is well 2026-05-09 14:43:32 +0000 UTC hostedclusters kx-0301960e0d All is well 2026-05-09 14:44:01 +0000 UTC hostedclusters kx-0301960e0d EtcdAvailable QuorumAvailable 2026-05-09 14:44:33 +0000 UTC hostedclusters kx-0301960e0d Kube APIServer deployment is available 2026-05-09 14:44:45 +0000 UTC hostedclusters kx-0301960e0d Ignition server deployment is available 2026-05-09 14:44:46 +0000 UTC hostedclusters kx-0301960e0d All is well 2026-05-09 14:44:54 +0000 UTC hostedclusters kx-0301960e0d All is well 2026-05-09 14:45:31 +0000 UTC hostedclusters kx-0301960e0d ClusterVersionAvailable FromClusterVersion 2026-05-09 14:45:31 +0000 UTC hostedclusters kx-0301960e0d An update is already in progress and the details are in the Progressing condition 2026-05-09 14:45:31 +0000 UTC hostedclusters kx-0301960e0d Unable to apply 4.20.21: an unknown error has occurred: MultipleErrors 2026-05-09 14:45:31 +0000 UTC hostedclusters kx-0301960e0d Payload loaded version="4.20.21" image="quay.io/openshift-release-dev/ocp-release@sha256:bd5aae6fd48ac8ca03a31e028dfb0dafd75a4b6f34cd84c6f4df5d961244f42e" architecture="Multi" 2026-05-09 14:45:49 +0000 UTC hostedclusters kx-0301960e0d lookup api.kx-0301960e0d.e436.p3.openshiftapps.com on 172.30.0.10:53: no such host 2026-05-09 14:45:56 +0000 UTC hostedclusters kx-0301960e0d Multiple errors are preventing progress: * Cluster operators console, csi-snapshot-controller, dns, image-registry, ingress, insights, kube-storage-version-migrator, monitoring, network, node-tuning, openshift-samples, service-ca, storage are not available * Could not update imagestream "openshift/driver-toolkit" (474 of 673): resource may have been deleted * Could not update operatorgroup "openshift-monitoring/openshift-cluster-monitoring" (614 of 673): resource may have been deleted * Could not update role "openshift-authentication/prometheus-k8s" (601 of 673): resource may have been deleted * Could not update role "openshift-console-operator/prometheus-k8s" (632 of 673): resource may have been deleted * Could not update role "openshift-console/prometheus-k8s" (636 of 673): resource may have been deleted * Could not update role "openshift-ingress-operator/prometheus-k8s" (643 of 673): resource may have been deleted * Could not update role "openshift-kube-apiserver-operator/prometheus-k8s" (647 of 673): resource may have been deleted 0001-01-01 00:00:00 +0000 UTC hostedclusters kx-0301960e0d Version 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d HostedCluster is at expected version 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Reconciliation active on resource 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d Release image is valid 2026-05-09 14:40:40 +0000 UTC hostedclusters kx-0301960e0d HostedCluster is supported by operator configuration 2026-05-09 14:42:05 +0000 UTC certificates cluster-api-cert Certificate is up to date and has not expired 2026-05-09 14:42:10 +0000 UTC hostedclusters kx-0301960e0d Configuration passes validation 2026-05-09 14:42:10 +0000 UTC hostedclusters kx-0301960e0d Required platform credentials are found 2026-05-09 14:42:12 +0000 UTC hostedclusters kx-0301960e0d Reconciliation completed successfully 2026-05-09 14:42:12 +0000 UTC hostedclusters kx-0301960e0d OIDC configuration is valid 2026-05-09 14:42:17 +0000 UTC hostedclusters kx-0301960e0d Configuration passes validation 2026-05-09 14:42:17 +0000 UTC hostedclusters kx-0301960e0d AWS KMS is not configured 2026-05-09 14:42:17 +0000 UTC hostedclusters kx-0301960e0d ignition-server-proxy deployment has 1 unavailable replicas 2026-05-09 14:43:32 +0000 UTC hostedclusters kx-0301960e0d All is well 2026-05-09 14:43:32 +0000 UTC hostedclusters kx-0301960e0d All is well 2026-05-09 14:44:01 +0000 UTC hostedclusters kx-0301960e0d EtcdAvailable QuorumAvailable 2026-05-09 14:44:33 +0000 UTC hostedclusters kx-0301960e0d Kube APIServer deployment is available 2026-05-09 14:44:45 +0000 UTC hostedclusters kx-0301960e0d Ignition server deployment is available 2026-05-09 14:44:46 +0000 UTC hostedclusters kx-0301960e0d All is well 2026-05-09 14:44:54 +0000 UTC hostedclusters kx-0301960e0d All is well 2026-05-09 14:45:31 +0000 UTC hostedclusters kx-0301960e0d Unable to apply 4.20.21: some cluster operators are not available 2026-05-09 14:45:31 +0000 UTC hostedclusters kx-0301960e0d An update is already in progress and the details are in the Progressing condition 2026-05-09 14:45:31 +0000 UTC hostedclusters kx-0301960e0d Payload loaded version="4.20.21" image="quay.io/openshift-release-dev/ocp-release@sha256:bd5aae6fd48ac8ca03a31e028dfb0dafd75a4b6f34cd84c6f4df5d961244f42e" architecture="Multi" 2026-05-09 14:45:31 +0000 UTC hostedclusters kx-0301960e0d ClusterVersionAvailable FromClusterVersion 2026-05-09 14:45:56 +0000 UTC hostedclusters kx-0301960e0d Cluster operators console, dns, image-registry, ingress, insights, kube-storage-version-migrator, monitoring, node-tuning, openshift-samples, service-ca, storage are not available 2026-05-09 14:46:05 +0000 UTC hostedclusters kx-0301960e0d The hosted control plane is available INFO: Cluster 'kx-0301960e0d' is now ready INFO: ROSA with HCP cluster is ready, create a cluster admin account for accessing the cluster WARN: The current version (1.2.59) is not up to date with latest rosa cli released version (1.2.62). WARN: It is recommended that you update to the latest version. INFO: Storing login command... INFO: Check if it's able to login to OCP cluster... Retried 1 times... INFO: Check if apiserver is ready... Waiting for cluster operators to be accessible for 2m... NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.20.21 True False False 2m43s dns 4.20.21 False False True 2m47s DNS "default" is unavailable. image-registry False True True 111s Available: The deployment does not have available replicas... ingress False True True 2m22s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.20.21 True False False 2m46s kube-controller-manager 4.20.21 True False False 2m46s kube-scheduler 4.20.21 True False False 2m46s kube-storage-version-migrator monitoring network 4.20.21 True True False 2m17s DaemonSet "/openshift-network-operator/iptables-alerter" is waiting for other operators to become ready... node-tuning False True False 2m32s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.20.21 True False False 2m46s openshift-controller-manager 4.20.21 True False False 2m46s openshift-samples operator-lifecycle-manager 4.20.21 True False False 2m46s operator-lifecycle-manager-catalog 4.20.21 True False False 2m47s operator-lifecycle-manager-packageserver 4.20.21 True False False 2m46s service-ca storage 4.20.21 False True False 2m43s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service cluster operators to be accessible finished! [INFO] Cluster operators are accessible. Waiting for cluster to be reported as healthy for 60m... NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.20.21 True False False 2m43s dns 4.20.21 False False True 2m47s DNS "default" is unavailable. image-registry False True True 111s Available: The deployment does not have available replicas... ingress False True True 2m22s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.20.21 True False False 2m46s kube-controller-manager 4.20.21 True False False 2m46s kube-scheduler 4.20.21 True False False 2m46s kube-storage-version-migrator monitoring network 4.20.21 True True False 2m17s DaemonSet "/openshift-network-operator/iptables-alerter" is waiting for other operators to become ready... node-tuning False True False 2m32s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.20.21 True False False 2m46s openshift-controller-manager 4.20.21 True False False 2m46s openshift-samples operator-lifecycle-manager 4.20.21 True False False 2m46s operator-lifecycle-manager-catalog 4.20.21 True False False 2m47s operator-lifecycle-manager-packageserver 4.20.21 True False False 2m46s service-ca storage 4.20.21 False True False 2m43s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.20.21 True False False 3m44s dns 4.20.21 False False True 3m48s DNS "default" is unavailable. image-registry False True True 2m52s Available: The deployment does not have available replicas... ingress False True True 3m23s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.20.21 True False False 3m47s kube-controller-manager 4.20.21 True False False 3m47s kube-scheduler 4.20.21 True False False 3m47s kube-storage-version-migrator monitoring network 4.20.21 True True False 3m18s DaemonSet "/openshift-network-operator/iptables-alerter" is waiting for other operators to become ready... node-tuning False True False 3m33s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.20.21 True False False 3m47s openshift-controller-manager 4.20.21 True False False 3m47s openshift-samples operator-lifecycle-manager 4.20.21 True False False 3m47s operator-lifecycle-manager-catalog 4.20.21 True False False 3m48s operator-lifecycle-manager-packageserver 4.20.21 True False False 3m47s service-ca storage 4.20.21 False True False 3m44s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.20.21 True False False 4m44s dns 4.20.21 False False True 4m48s DNS "default" is unavailable. image-registry False True True 3m52s Available: The deployment does not have available replicas... ingress False True True 4m23s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.20.21 True False False 4m47s kube-controller-manager 4.20.21 True False False 4m47s kube-scheduler 4.20.21 True False False 4m47s kube-storage-version-migrator monitoring network 4.20.21 True True False 4m18s DaemonSet "/openshift-network-operator/iptables-alerter" is waiting for other operators to become ready... node-tuning False True False 4m33s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.20.21 True False False 4m47s openshift-controller-manager 4.20.21 True False False 4m47s openshift-samples operator-lifecycle-manager 4.20.21 True False False 4m47s operator-lifecycle-manager-catalog 4.20.21 True False False 4m48s operator-lifecycle-manager-packageserver 4.20.21 True False False 4m47s service-ca storage 4.20.21 False True False 4m44s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.20.21 True False False 5m44s dns 4.20.21 False False True 5m48s DNS "default" is unavailable. image-registry False True True 4m52s Available: The deployment does not have available replicas... ingress False True True 5m23s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.20.21 True False False 5m47s kube-controller-manager 4.20.21 True False False 5m47s kube-scheduler 4.20.21 True False False 5m47s kube-storage-version-migrator monitoring network 4.20.21 True True False 5m18s DaemonSet "/openshift-network-operator/iptables-alerter" is waiting for other operators to become ready... node-tuning False True False 5m33s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.20.21 True False False 5m47s openshift-controller-manager 4.20.21 True False False 5m47s openshift-samples operator-lifecycle-manager 4.20.21 True False False 5m47s operator-lifecycle-manager-catalog 4.20.21 True False False 5m48s operator-lifecycle-manager-packageserver 4.20.21 True False False 5m47s service-ca storage 4.20.21 False True False 5m44s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.20.21 True False False 6m44s dns 4.20.21 False False True 6m48s DNS "default" is unavailable. image-registry False True True 5m52s Available: The deployment does not have available replicas... ingress False True True 6m23s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.20.21 True False False 6m47s kube-controller-manager 4.20.21 True False False 6m47s kube-scheduler 4.20.21 True False False 6m47s kube-storage-version-migrator monitoring network 4.20.21 True True False 6m18s DaemonSet "/openshift-network-operator/iptables-alerter" is waiting for other operators to become ready... node-tuning False True False 6m33s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.20.21 True False False 6m47s openshift-controller-manager 4.20.21 True False False 6m47s openshift-samples operator-lifecycle-manager 4.20.21 True False False 6m47s operator-lifecycle-manager-catalog 4.20.21 True False False 6m48s operator-lifecycle-manager-packageserver 4.20.21 True False False 6m47s service-ca storage 4.20.21 False True False 6m44s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.20.21 True False False 7m45s dns 4.20.21 False True True 7m49s DNS "default" is unavailable. image-registry False True True 6m53s Available: The deployment does not have available replicas... ingress False True True 7m24s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.20.21 True False False 7m48s kube-controller-manager 4.20.21 True False False 7m48s kube-scheduler 4.20.21 True False False 7m48s kube-storage-version-migrator monitoring network 4.20.21 True True False 7m19s DaemonSet "/openshift-network-operator/iptables-alerter" is not available (awaiting 2 nodes)... node-tuning 4.20.21 True True False 3s Waiting for 3/3 Profiles to be applied openshift-apiserver 4.20.21 True False False 7m48s openshift-controller-manager 4.20.21 True False False 7m48s openshift-samples operator-lifecycle-manager 4.20.21 True False False 7m48s operator-lifecycle-manager-catalog 4.20.21 True False False 7m49s operator-lifecycle-manager-packageserver 4.20.21 True False False 7m48s service-ca storage 4.20.21 True True False 1s AWSEBSCSIDriverOperatorCRProgressing: AWSEBSDriverNodeServiceControllerProgressing: Waiting for DaemonSet to deploy node pods... Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.20.21 True False False 8m45s dns 4.20.21 False True True 8m49s DNS "default" is unavailable. image-registry False True True 7m53s Available: The deployment does not have available replicas... ingress False True True 8m24s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights 4.20.21 True False False 7s kube-apiserver 4.20.21 True False False 8m48s kube-controller-manager 4.20.21 True False False 8m48s kube-scheduler 4.20.21 True False False 8m48s kube-storage-version-migrator 4.20.21 True False False 6s monitoring network 4.20.21 True True False 8m19s DaemonSet "/openshift-multus/network-metrics-daemon" is waiting for other operators to become ready... node-tuning 4.20.21 True False False 63s openshift-apiserver 4.20.21 True False False 8m48s openshift-controller-manager 4.20.21 True False False 8m48s openshift-samples operator-lifecycle-manager 4.20.21 True False False 8m48s operator-lifecycle-manager-catalog 4.20.21 True False False 8m49s operator-lifecycle-manager-packageserver 4.20.21 True False False 8m48s service-ca 4.20.21 True False False 6s storage 4.20.21 True False False 61s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.20.21 False True False 2s DeploymentAvailable: 0 replicas available for console deployment csi-snapshot-controller 4.20.21 True False False 9m46s dns 4.20.21 True False False 26s image-registry 4.20.21 True True False 32s Progressing: The deployment has not completed... ingress 4.20.21 True False True 10s The "default" ingress controller reports Degraded=True: DegradedConditions: One or more other status conditions indicate a degraded state: CanaryChecksSucceeding=Unknown (CanaryRouteNotAdmitted: Canary route is not admitted by the default ingress controller). insights 4.20.21 True False False 68s kube-apiserver 4.20.21 True False False 9m49s kube-controller-manager 4.20.21 True False False 9m49s kube-scheduler 4.20.21 True False False 9m49s kube-storage-version-migrator 4.20.21 True False False 67s monitoring Unknown True Unknown 40s Rolling out the stack. network 4.20.21 True True False 9m20s DaemonSet "/openshift-multus/network-metrics-daemon" is not available (awaiting 1 nodes) node-tuning 4.20.21 True False False 2m4s openshift-apiserver 4.20.21 True False False 9m49s openshift-controller-manager 4.20.21 True False False 9m49s openshift-samples 4.20.21 True False False 4s operator-lifecycle-manager 4.20.21 True False False 9m49s operator-lifecycle-manager-catalog 4.20.21 True False False 9m50s operator-lifecycle-manager-packageserver 4.20.21 True False False 9m49s service-ca 4.20.21 True False False 67s storage 4.20.21 True False False 2m2s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.20.21 True True False 56s SyncLoopRefreshProgressing: working toward version 4.20.21, 1 replicas available csi-snapshot-controller 4.20.21 True False False 10m dns 4.20.21 True False False 86s image-registry 4.20.21 True False False 92s ingress 4.20.21 True False False 70s insights 4.20.21 True False False 2m8s kube-apiserver 4.20.21 True False False 10m kube-controller-manager 4.20.21 True False False 10m kube-scheduler 4.20.21 True False False 10m kube-storage-version-migrator 4.20.21 True False False 2m7s monitoring 4.20.21 True False False 13s network 4.20.21 True False False 10m node-tuning 4.20.21 True False False 3m4s openshift-apiserver 4.20.21 True False False 10m openshift-controller-manager 4.20.21 True False False 10m openshift-samples 4.20.21 True False False 64s operator-lifecycle-manager 4.20.21 True False False 10m operator-lifecycle-manager-catalog 4.20.21 True False False 10m operator-lifecycle-manager-packageserver 4.20.21 True False False 10m service-ca 4.20.21 True False False 2m7s storage 4.20.21 True False False 3m2s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.20.21 True False False 117s csi-snapshot-controller 4.20.21 True False False 11m dns 4.20.21 True False False 2m27s image-registry 4.20.21 True False False 2m33s ingress 4.20.21 True False False 2m11s insights 4.20.21 True False False 3m9s kube-apiserver 4.20.21 True False False 11m kube-controller-manager 4.20.21 True False False 11m kube-scheduler 4.20.21 True False False 11m kube-storage-version-migrator 4.20.21 True False False 3m8s monitoring 4.20.21 True False False 74s network 4.20.21 True False False 11m node-tuning 4.20.21 True False False 4m5s openshift-apiserver 4.20.21 True False False 11m openshift-controller-manager 4.20.21 True False False 11m openshift-samples 4.20.21 True False False 2m5s operator-lifecycle-manager 4.20.21 True False False 11m operator-lifecycle-manager-catalog 4.20.21 True False False 11m operator-lifecycle-manager-packageserver 4.20.21 True False False 11m service-ca 4.20.21 True False False 3m8s storage 4.20.21 True False False 4m3s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.20.21 True False False 2m57s csi-snapshot-controller 4.20.21 True False False 12m dns 4.20.21 True False False 3m27s image-registry 4.20.21 True False False 3m33s ingress 4.20.21 True False False 3m11s insights 4.20.21 True False False 4m9s kube-apiserver 4.20.21 True False False 12m kube-controller-manager 4.20.21 True False False 12m kube-scheduler 4.20.21 True False False 12m kube-storage-version-migrator 4.20.21 True False False 4m8s monitoring 4.20.21 True False False 2m14s network 4.20.21 True False False 12m node-tuning 4.20.21 True False False 5m5s openshift-apiserver 4.20.21 True False False 12m openshift-controller-manager 4.20.21 True False False 12m openshift-samples 4.20.21 True False False 3m5s operator-lifecycle-manager 4.20.21 True False False 12m operator-lifecycle-manager-catalog 4.20.21 True False False 12m operator-lifecycle-manager-packageserver 4.20.21 True False False 12m service-ca 4.20.21 True False False 4m8s storage 4.20.21 True False False 5m3s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.20.21 True False False 3m57s csi-snapshot-controller 4.20.21 True False False 13m dns 4.20.21 True False False 4m27s image-registry 4.20.21 True False False 4m33s ingress 4.20.21 True False False 4m11s insights 4.20.21 True False False 5m9s kube-apiserver 4.20.21 True False False 13m kube-controller-manager 4.20.21 True False False 13m kube-scheduler 4.20.21 True False False 13m kube-storage-version-migrator 4.20.21 True False False 5m8s monitoring 4.20.21 True False False 3m14s network 4.20.21 True False False 13m node-tuning 4.20.21 True False False 6m5s openshift-apiserver 4.20.21 True False False 13m openshift-controller-manager 4.20.21 True False False 13m openshift-samples 4.20.21 True False False 4m5s operator-lifecycle-manager 4.20.21 True False False 13m operator-lifecycle-manager-catalog 4.20.21 True False False 13m operator-lifecycle-manager-packageserver 4.20.21 True False False 13m service-ca 4.20.21 True False False 5m8s storage 4.20.21 True False False 6m3s Waiting for cluster to be reported as healthy... Trying again in 60s healthy cluster to be reported as healthy finished!