INFO: Log in to your Red Hat account... INFO: Configure AWS Credentials... WARN: The current version (1.2.59) is not up to date with latest rosa cli released version (1.2.62). WARN: It is recommended that you update to the latest version. INFO: Logged in as 'rhtap-shared' on 'https://api.openshift.com' INFO: Create ROSA with HCP cluster... WARN: The current version (1.2.59) is not up to date with latest rosa cli released version (1.2.62). WARN: It is recommended that you update to the latest version. INFO: Creating cluster 'kx-3e0031faf4' INFO: To view a list of clusters and their status, run 'rosa list clusters' INFO: Cluster 'kx-3e0031faf4' has been created. INFO: Once the cluster is installed you will need to add an Identity Provider before you can login into the cluster. See 'rosa create idp --help' for more information. Name: kx-3e0031faf4 Domain Prefix: kx-3e0031faf4 Display Name: kx-3e0031faf4 ID: 2q8btjnpc38stnn9s3vkf9fec7sthl4r External ID: ae3a6c40-c16e-475d-93f2-5fd7e1f18f46 Control Plane: ROSA Service Hosted OpenShift Version: 4.21.9 Channel Group: stable DNS: Not ready AWS Account: 381492310364 AWS Billing Account: 381492310364 API URL: Console URL: Region: us-east-1 Availability: - Control Plane: MultiAZ - Data Plane: MultiAZ Nodes: - Compute (desired): 3 - Compute (current): 0 Network: - Type: OVNKubernetes - Service CIDR: 172.30.0.0/16 - Machine CIDR: 10.0.0.0/16 - Pod CIDR: 10.128.0.0/14 - Host Prefix: /23 - Subnets: subnet-0208a6297964e4fe1, subnet-0c161c939f7025e15, subnet-023e5c7b3016ed194, subnet-02dbd8abbf884d77f, subnet-0360c2d20442c5ba5, subnet-0aad9c992e402a91a EC2 Metadata Http Tokens: optional Role (STS) ARN: arn:aws:iam::381492310364:role/rhads-hcp-HCP-ROSA-Installer-Role Support Role ARN: arn:aws:iam::381492310364:role/rhads-hcp-HCP-ROSA-Support-Role Instance IAM Roles: - Worker: arn:aws:iam::381492310364:role/rhads-hcp-HCP-ROSA-Worker-Role Operator IAM Roles: - arn:aws:iam::381492310364:role/rhads-hcp-openshift-cluster-csi-drivers-ebs-cloud-credentials - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-kube-controller-manager - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-capa-controller-manager - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-control-plane-operator - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-kms-provider - arn:aws:iam::381492310364:role/rhads-hcp-openshift-cloud-network-config-controller-cloud-creden - arn:aws:iam::381492310364:role/rhads-hcp-openshift-image-registry-installer-cloud-credentials - arn:aws:iam::381492310364:role/rhads-hcp-openshift-ingress-operator-cloud-credentials Managed Policies: Yes State: waiting (Waiting for user action) Private: No Delete Protection: Disabled Created: May 12 2026 11:19:45 UTC Details Page: https://console.redhat.com/openshift/details/s/3DccQuPp4yjikOcHiD9JbNLNWwq OIDC Endpoint URL: https://oidc.op1.openshiftapps.com/2jtsga3i2etnl697l7bk5i1kmbm4a95j (Managed) Etcd Encryption: Disabled Audit Log Forwarding: Disabled External Authentication: Disabled INFO: Preparing to create operator roles. INFO: Operator Roles already exists INFO: Preparing to create OIDC Provider. INFO: OIDC provider already exists INFO: To determine when your cluster is Ready, run 'rosa describe cluster -c kx-3e0031faf4'. INFO: To watch your cluster installation logs, run 'rosa logs install -c kx-3e0031faf4 --watch'. INFO: Track the progress of the cluster creation... WARN: The current version (1.2.59) is not up to date with latest rosa cli released version (1.2.62). WARN: It is recommended that you update to the latest version. W: Region flag will be removed from this command in future versions INFO: Cluster 'kx-3e0031faf4' is in waiting state waiting for installation to begin. Logs will show up within 5 minutes 0001-01-01 00:00:00 +0000 UTC hostedclusters kx-3e0031faf4 Version 2026-05-12 11:22:57 +0000 UTC certificates cluster-api-cert Issuing certificate as Secret does not exist 2026-05-12 11:22:58 +0000 UTC certificates cluster-api-cert Issuing certificate as Secret does not exist 2026-05-12 11:22:58 +0000 UTC hostedclusters kx-3e0031faf4 ValidAWSIdentityProvider StatusUnknown 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 Condition not found in the CVO. 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 Condition not found in the CVO. 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 The hosted control plane is not found 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 The hosted control plane is not found 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 The hosted control plane is not found 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 The hosted control plane is not found 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 The hosted control plane is not found 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 Condition not found in the CVO. 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 The hosted control plane is not found 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 The hosted control plane is not found 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 Condition not found in the CVO. 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 Condition not found in the CVO. 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 Ignition server deployment not found 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 HostedCluster is supported by operator configuration 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 Release image is valid 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 Reconciliation active on resource 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 configuration is invalid: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 Reconciliation active on resource 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 configuration is invalid: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 Reconciliation active on resource 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 configuration is invalid: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 Reconciliation active on resource 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 configuration is invalid: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 Reconciliation active on resource 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 configuration is invalid: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 Reconciliation active on resource 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 configuration is invalid: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 0001-01-01 00:00:00 +0000 UTC hostedclusters kx-3e0031faf4 Version 2026-05-12 11:22:58 +0000 UTC hostedclusters kx-3e0031faf4 ValidAWSIdentityProvider StatusUnknown 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 Release image is valid 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 Condition not found in the CVO. 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 Reconciliation active on resource 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 Ignition server deployment not found 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 Condition not found in the CVO. 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 router load balancer is not provisioned; 8s since creation.; router load balancer is not provisioned; 8s since creation. 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 HostedCluster is supported by operator configuration 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 Condition not found in the HCP 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 Condition not found in the CVO. 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 Condition not found in the CVO. 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 HostedCluster is at expected version 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 Condition not found in the CVO. 2026-05-12 11:24:29 +0000 UTC certificates cluster-api-cert Certificate is up to date and has not expired 2026-05-12 11:24:33 +0000 UTC hostedclusters kx-3e0031faf4 Required platform credentials are found 2026-05-12 11:24:33 +0000 UTC hostedclusters kx-3e0031faf4 Configuration passes validation 2026-05-12 11:24:35 +0000 UTC hostedclusters kx-3e0031faf4 EtcdAvailable StatefulSetNotFound 2026-05-12 11:24:35 +0000 UTC hostedclusters kx-3e0031faf4 OIDC configuration is valid 2026-05-12 11:24:35 +0000 UTC hostedclusters kx-3e0031faf4 lookup api.kx-3e0031faf4.km4c.p3.openshiftapps.com on 172.30.0.10:53: no such host 2026-05-12 11:24:35 +0000 UTC hostedclusters kx-3e0031faf4 Configuration passes validation 2026-05-12 11:24:35 +0000 UTC hostedclusters kx-3e0031faf4 AWS KMS is not configured 2026-05-12 11:24:35 +0000 UTC hostedclusters kx-3e0031faf4 Kube APIServer deployment not found 2026-05-12 11:24:35 +0000 UTC hostedclusters kx-3e0031faf4 router load balancer is not provisioned; 8s since creation.; router load balancer is not provisioned; 8s since creation. 2026-05-12 11:24:35 +0000 UTC hostedclusters kx-3e0031faf4 Reconciliation completed successfully 2026-05-12 11:24:35 +0000 UTC hostedclusters kx-3e0031faf4 capi-provider deployment has 1 unavailable replicas 0001-01-01 00:00:00 +0000 UTC hostedclusters kx-3e0031faf4 Version 2026-05-12 11:22:58 +0000 UTC hostedclusters kx-3e0031faf4 Cannot validate AWS identity provider while KubeAPIServer is not available 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 Condition not found in the CVO. 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 HostedCluster is supported by operator configuration 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 Reconciliation active on resource 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 Ignition server deployment not found 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 Waiting for Kube APIServer deployment to become available 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 Release image is valid 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 Condition not found in the CVO. 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 HostedCluster is at expected version 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 Condition not found in the CVO. 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 Condition not found in the CVO. 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 Condition not found in the CVO. 2026-05-12 11:24:29 +0000 UTC certificates cluster-api-cert Certificate is up to date and has not expired 2026-05-12 11:24:33 +0000 UTC hostedclusters kx-3e0031faf4 Configuration passes validation 2026-05-12 11:24:33 +0000 UTC hostedclusters kx-3e0031faf4 Required platform credentials are found 2026-05-12 11:24:35 +0000 UTC hostedclusters kx-3e0031faf4 OIDC configuration is valid 2026-05-12 11:24:35 +0000 UTC hostedclusters kx-3e0031faf4 lookup api.kx-3e0031faf4.km4c.p3.openshiftapps.com on 172.30.0.10:53: no such host 2026-05-12 11:24:35 +0000 UTC hostedclusters kx-3e0031faf4 Configuration passes validation 2026-05-12 11:24:35 +0000 UTC hostedclusters kx-3e0031faf4 AWS KMS is not configured 2026-05-12 11:24:35 +0000 UTC hostedclusters kx-3e0031faf4 Waiting for Kube APIServer deployment to become available 2026-05-12 11:24:35 +0000 UTC hostedclusters kx-3e0031faf4 Reconciliation completed successfully 2026-05-12 11:24:35 +0000 UTC hostedclusters kx-3e0031faf4 [capi-provider deployment has 2 unavailable replicas, kube-apiserver deployment has 2 unavailable replicas] 2026-05-12 11:25:38 +0000 UTC hostedclusters kx-3e0031faf4 All is well 2026-05-12 11:25:38 +0000 UTC hostedclusters kx-3e0031faf4 All is well 2026-05-12 11:26:04 +0000 UTC hostedclusters kx-3e0031faf4 EtcdAvailable QuorumAvailable 2026-05-12 11:26:30 +0000 UTC hostedclusters kx-3e0031faf4 Kube APIServer deployment is available 2026-05-12 11:26:37 +0000 UTC hostedclusters kx-3e0031faf4 Ignition server deployment is available 2026-05-12 11:27:00 +0000 UTC hostedclusters kx-3e0031faf4 lookup api.kx-3e0031faf4.km4c.p3.openshiftapps.com on 172.30.0.10:53: no such host 2026-05-12 11:27:13 +0000 UTC hostedclusters kx-3e0031faf4 Payload loaded version="4.21.9" image="quay.io/openshift-release-dev/ocp-release@sha256:874cb62361d692ccf74dfd3ed5a76832dbde51815e96f6b0f32fab137e59b36a" architecture="Multi" 2026-05-12 11:27:13 +0000 UTC hostedclusters kx-3e0031faf4 ClusterVersionAvailable FromClusterVersion 2026-05-12 11:27:13 +0000 UTC hostedclusters kx-3e0031faf4 Working towards 4.21.9: 460 of 683 done (67% complete) 2026-05-12 11:27:13 +0000 UTC hostedclusters kx-3e0031faf4 An update is already in progress and the details are in the Progressing condition 2026-05-12 11:27:13 +0000 UTC hostedclusters kx-3e0031faf4 ClusterVersionSucceeding FromClusterVersion 0001-01-01 00:00:00 +0000 UTC hostedclusters kx-3e0031faf4 Version 2026-05-12 11:22:58 +0000 UTC hostedclusters kx-3e0031faf4 Cannot validate AWS identity provider while KubeAPIServer is not available 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 Reconciliation active on resource 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 Waiting for components to be available: cloud-credential-operator, cluster-network-operator, olm-operator, ingress-operator, catalog-operator 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 HostedCluster is at expected version 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 Release image is valid 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 HostedCluster is supported by operator configuration 2026-05-12 11:24:29 +0000 UTC certificates cluster-api-cert Certificate is up to date and has not expired 2026-05-12 11:24:33 +0000 UTC hostedclusters kx-3e0031faf4 Configuration passes validation 2026-05-12 11:24:33 +0000 UTC hostedclusters kx-3e0031faf4 Required platform credentials are found 2026-05-12 11:24:35 +0000 UTC hostedclusters kx-3e0031faf4 AWS KMS is not configured 2026-05-12 11:24:35 +0000 UTC hostedclusters kx-3e0031faf4 Reconciliation completed successfully 2026-05-12 11:24:35 +0000 UTC hostedclusters kx-3e0031faf4 Configuration passes validation 2026-05-12 11:24:35 +0000 UTC hostedclusters kx-3e0031faf4 OIDC configuration is valid 2026-05-12 11:24:35 +0000 UTC hostedclusters kx-3e0031faf4 router deployment has 1 unavailable replicas 2026-05-12 11:25:38 +0000 UTC hostedclusters kx-3e0031faf4 All is well 2026-05-12 11:25:38 +0000 UTC hostedclusters kx-3e0031faf4 All is well 2026-05-12 11:26:04 +0000 UTC hostedclusters kx-3e0031faf4 EtcdAvailable QuorumAvailable 2026-05-12 11:26:30 +0000 UTC hostedclusters kx-3e0031faf4 Kube APIServer deployment is available 2026-05-12 11:26:37 +0000 UTC hostedclusters kx-3e0031faf4 Ignition server deployment is available 2026-05-12 11:27:00 +0000 UTC hostedclusters kx-3e0031faf4 lookup api.kx-3e0031faf4.km4c.p3.openshiftapps.com on 172.30.0.10:53: no such host 2026-05-12 11:27:13 +0000 UTC hostedclusters kx-3e0031faf4 Payload loaded version="4.21.9" image="quay.io/openshift-release-dev/ocp-release@sha256:874cb62361d692ccf74dfd3ed5a76832dbde51815e96f6b0f32fab137e59b36a" architecture="Multi" 2026-05-12 11:27:13 +0000 UTC hostedclusters kx-3e0031faf4 ClusterVersionAvailable FromClusterVersion 2026-05-12 11:27:13 +0000 UTC hostedclusters kx-3e0031faf4 Unable to apply 4.21.9: an unknown error has occurred: MultipleErrors 2026-05-12 11:27:13 +0000 UTC hostedclusters kx-3e0031faf4 An update is already in progress and the details are in the Progressing condition 2026-05-12 11:27:33 +0000 UTC hostedclusters kx-3e0031faf4 Multiple errors are preventing progress: * Cluster operators console, dns, ingress, insights, kube-storage-version-migrator, monitoring, network, node-tuning, openshift-samples, service-ca, storage are not available * Could not update imagestream "openshift/driver-toolkit" (484 of 683): resource may have been deleted * Could not update operatorgroup "openshift-monitoring/openshift-cluster-monitoring" (623 of 683): resource may have been deleted * Could not update role "openshift-authentication/prometheus-k8s" (609 of 683): resource may have been deleted * Could not update role "openshift-console-operator/prometheus-k8s" (641 of 683): resource may have been deleted * Could not update role "openshift-console/prometheus-k8s" (645 of 683): resource may have been deleted * Could not update role "openshift-ingress-operator/prometheus-k8s" (652 of 683): resource may have been deleted * Could not update role "openshift-kube-apiserver-operator/prometheus-k8s" (656 of 683): resource may have been deleted 0001-01-01 00:00:00 +0000 UTC hostedclusters kx-3e0031faf4 Version 2026-05-12 11:22:58 +0000 UTC hostedclusters kx-3e0031faf4 Cannot validate AWS identity provider while KubeAPIServer is not available 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 Reconciliation active on resource 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 HostedCluster is at expected version 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 HostedCluster is supported by operator configuration 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 Release image is valid 2026-05-12 11:24:29 +0000 UTC certificates cluster-api-cert Certificate is up to date and has not expired 2026-05-12 11:24:33 +0000 UTC hostedclusters kx-3e0031faf4 Configuration passes validation 2026-05-12 11:24:33 +0000 UTC hostedclusters kx-3e0031faf4 Required platform credentials are found 2026-05-12 11:24:35 +0000 UTC hostedclusters kx-3e0031faf4 Configuration passes validation 2026-05-12 11:24:35 +0000 UTC hostedclusters kx-3e0031faf4 AWS KMS is not configured 2026-05-12 11:24:35 +0000 UTC hostedclusters kx-3e0031faf4 ignition-server-proxy deployment has 2 unavailable replicas 2026-05-12 11:24:35 +0000 UTC hostedclusters kx-3e0031faf4 Reconciliation completed successfully 2026-05-12 11:24:35 +0000 UTC hostedclusters kx-3e0031faf4 OIDC configuration is valid 2026-05-12 11:25:38 +0000 UTC hostedclusters kx-3e0031faf4 All is well 2026-05-12 11:25:38 +0000 UTC hostedclusters kx-3e0031faf4 All is well 2026-05-12 11:26:04 +0000 UTC hostedclusters kx-3e0031faf4 EtcdAvailable QuorumAvailable 2026-05-12 11:26:30 +0000 UTC hostedclusters kx-3e0031faf4 Kube APIServer deployment is available 2026-05-12 11:26:37 +0000 UTC hostedclusters kx-3e0031faf4 Ignition server deployment is available 2026-05-12 11:27:13 +0000 UTC hostedclusters kx-3e0031faf4 Payload loaded version="4.21.9" image="quay.io/openshift-release-dev/ocp-release@sha256:874cb62361d692ccf74dfd3ed5a76832dbde51815e96f6b0f32fab137e59b36a" architecture="Multi" 2026-05-12 11:27:13 +0000 UTC hostedclusters kx-3e0031faf4 ClusterVersionAvailable FromClusterVersion 2026-05-12 11:27:13 +0000 UTC hostedclusters kx-3e0031faf4 Unable to apply 4.21.9: some cluster operators are not available 2026-05-12 11:27:13 +0000 UTC hostedclusters kx-3e0031faf4 An update is already in progress and the details are in the Progressing condition 2026-05-12 11:27:33 +0000 UTC hostedclusters kx-3e0031faf4 Cluster operators console, dns, image-registry, ingress, insights, kube-storage-version-migrator, monitoring, node-tuning, openshift-samples, service-ca, storage are not available 2026-05-12 11:27:40 +0000 UTC hostedclusters kx-3e0031faf4 The hosted control plane is available 0001-01-01 00:00:00 +0000 UTC hostedclusters kx-3e0031faf4 Version 2026-05-12 11:22:58 +0000 UTC hostedclusters kx-3e0031faf4 Cannot validate AWS identity provider while KubeAPIServer is not available 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 Reconciliation active on resource 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 HostedCluster is at expected version 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 HostedCluster is supported by operator configuration 2026-05-12 11:23:00 +0000 UTC hostedclusters kx-3e0031faf4 Release image is valid 2026-05-12 11:24:29 +0000 UTC certificates cluster-api-cert Certificate is up to date and has not expired 2026-05-12 11:24:33 +0000 UTC hostedclusters kx-3e0031faf4 Configuration passes validation 2026-05-12 11:24:33 +0000 UTC hostedclusters kx-3e0031faf4 Required platform credentials are found 2026-05-12 11:24:35 +0000 UTC hostedclusters kx-3e0031faf4 Configuration passes validation 2026-05-12 11:24:35 +0000 UTC hostedclusters kx-3e0031faf4 AWS KMS is not configured 2026-05-12 11:24:35 +0000 UTC hostedclusters kx-3e0031faf4 ignition-server-proxy deployment has 1 unavailable replicas 2026-05-12 11:24:35 +0000 UTC hostedclusters kx-3e0031faf4 Reconciliation completed successfully 2026-05-12 11:24:35 +0000 UTC hostedclusters kx-3e0031faf4 OIDC configuration is valid 2026-05-12 11:25:38 +0000 UTC hostedclusters kx-3e0031faf4 All is well 2026-05-12 11:25:38 +0000 UTC hostedclusters kx-3e0031faf4 All is well 2026-05-12 11:26:04 +0000 UTC hostedclusters kx-3e0031faf4 EtcdAvailable QuorumAvailable 2026-05-12 11:26:30 +0000 UTC hostedclusters kx-3e0031faf4 Kube APIServer deployment is available 2026-05-12 11:26:37 +0000 UTC hostedclusters kx-3e0031faf4 Ignition server deployment is available 2026-05-12 11:27:13 +0000 UTC hostedclusters kx-3e0031faf4 Payload loaded version="4.21.9" image="quay.io/openshift-release-dev/ocp-release@sha256:874cb62361d692ccf74dfd3ed5a76832dbde51815e96f6b0f32fab137e59b36a" architecture="Multi" 2026-05-12 11:27:13 +0000 UTC hostedclusters kx-3e0031faf4 ClusterVersionAvailable FromClusterVersion 2026-05-12 11:27:13 +0000 UTC hostedclusters kx-3e0031faf4 Unable to apply 4.21.9: some cluster operators are not available 2026-05-12 11:27:13 +0000 UTC hostedclusters kx-3e0031faf4 An update is already in progress and the details are in the Progressing condition 2026-05-12 11:27:33 +0000 UTC hostedclusters kx-3e0031faf4 Cluster operators console, dns, image-registry, ingress, insights, kube-storage-version-migrator, monitoring, node-tuning, openshift-samples, service-ca, storage are not available 2026-05-12 11:28:12 +0000 UTC hostedclusters kx-3e0031faf4 The hosted control plane is available INFO: Cluster 'kx-3e0031faf4' is now ready INFO: ROSA with HCP cluster is ready, create a cluster admin account for accessing the cluster WARN: The current version (1.2.59) is not up to date with latest rosa cli released version (1.2.62). WARN: It is recommended that you update to the latest version. INFO: Storing login command... INFO: Check if it's able to login to OCP cluster... Retried 1 times... INFO: Check if apiserver is ready... Waiting for cluster operators to be accessible for 2m... NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.21.9 True False False 3m37s dns 4.21.9 False False True 3m36s DNS "default" is unavailable. image-registry False True True 3m20s Available: The deployment does not have available replicas... ingress False True True 3m20s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.21.9 True False False 3m26s kube-controller-manager 4.21.9 True False False 3m26s kube-scheduler 4.21.9 True False False 3m26s kube-storage-version-migrator monitoring network 4.21.9 True True False 3m10s Deployment "/openshift-network-console/networking-console-plugin" is not available (awaiting 2 nodes) node-tuning False True False 2m57s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.21.9 True False False 3m26s openshift-controller-manager 4.21.9 True False False 3m26s openshift-samples operator-lifecycle-manager 4.21.9 True False False 3m25s operator-lifecycle-manager-catalog 4.21.9 True False False 3m19s operator-lifecycle-manager-packageserver 4.21.9 True False False 3m25s service-ca storage 4.21.9 False True False 3m25s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service cluster operators to be accessible finished! [INFO] Cluster operators are accessible. Waiting for cluster to be reported as healthy for 60m... NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.21.9 True False False 3m37s dns 4.21.9 False False True 3m36s DNS "default" is unavailable. image-registry False True True 3m20s Available: The deployment does not have available replicas... ingress False True True 3m20s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.21.9 True False False 3m26s kube-controller-manager 4.21.9 True False False 3m26s kube-scheduler 4.21.9 True False False 3m26s kube-storage-version-migrator monitoring network 4.21.9 True True False 3m10s Deployment "/openshift-network-console/networking-console-plugin" is not available (awaiting 2 nodes) node-tuning False True False 2m57s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.21.9 True False False 3m26s openshift-controller-manager 4.21.9 True False False 3m26s openshift-samples operator-lifecycle-manager 4.21.9 True False False 3m25s operator-lifecycle-manager-catalog 4.21.9 True False False 3m19s operator-lifecycle-manager-packageserver 4.21.9 True False False 3m25s service-ca storage 4.21.9 False True False 3m25s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.21.9 True False False 4m38s dns 4.21.9 False False True 4m37s DNS "default" is unavailable. image-registry False True True 4m21s Available: The deployment does not have available replicas... ingress False True True 4m21s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.21.9 True False False 4m27s kube-controller-manager 4.21.9 True False False 4m27s kube-scheduler 4.21.9 True False False 4m27s kube-storage-version-migrator monitoring network 4.21.9 True True False 4m11s Deployment "/openshift-network-console/networking-console-plugin" is not available (awaiting 2 nodes) node-tuning False True False 3m58s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.21.9 True False False 4m27s openshift-controller-manager 4.21.9 True False False 4m27s openshift-samples operator-lifecycle-manager 4.21.9 True False False 4m26s operator-lifecycle-manager-catalog 4.21.9 True False False 4m20s operator-lifecycle-manager-packageserver 4.21.9 True False False 4m26s service-ca storage 4.21.9 False True False 4m26s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.21.9 True False False 5m38s dns 4.21.9 False False True 5m37s DNS "default" is unavailable. image-registry False True True 5m21s Available: The deployment does not have available replicas... ingress False True True 5m21s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.21.9 True False False 5m27s kube-controller-manager 4.21.9 True False False 5m27s kube-scheduler 4.21.9 True False False 5m27s kube-storage-version-migrator monitoring network 4.21.9 True True False 5m11s Deployment "/openshift-network-console/networking-console-plugin" is not available (awaiting 2 nodes) node-tuning False True False 4m58s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.21.9 True False False 5m27s openshift-controller-manager 4.21.9 True False False 5m27s openshift-samples operator-lifecycle-manager 4.21.9 True False False 5m26s operator-lifecycle-manager-catalog 4.21.9 True False False 5m20s operator-lifecycle-manager-packageserver 4.21.9 True False False 5m26s service-ca storage 4.21.9 False True False 5m26s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.21.9 True False False 6m38s dns 4.21.9 False False True 6m37s DNS "default" is unavailable. image-registry False True True 6m21s Available: The deployment does not have available replicas... ingress False True True 6m21s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.21.9 True False False 6m27s kube-controller-manager 4.21.9 True False False 6m27s kube-scheduler 4.21.9 True False False 6m27s kube-storage-version-migrator monitoring network 4.21.9 True True False 6m11s Deployment "/openshift-network-console/networking-console-plugin" is not available (awaiting 2 nodes) node-tuning False True False 5m58s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.21.9 True False False 6m27s openshift-controller-manager 4.21.9 True False False 6m27s openshift-samples operator-lifecycle-manager 4.21.9 True False False 6m26s operator-lifecycle-manager-catalog 4.21.9 True False False 6m20s operator-lifecycle-manager-packageserver 4.21.9 True False False 6m26s service-ca storage 4.21.9 False True False 6m26s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.21.9 True False False 7m38s dns 4.21.9 False False True 7m37s DNS "default" is unavailable. image-registry False True True 7m21s Available: The deployment does not have available replicas... ingress False True True 7m21s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.21.9 True False False 7m27s kube-controller-manager 4.21.9 True False False 7m27s kube-scheduler 4.21.9 True False False 7m27s kube-storage-version-migrator monitoring network 4.21.9 True True False 7m11s DaemonSet "/openshift-network-operator/iptables-alerter" is not available (awaiting 1 nodes)... node-tuning 4.21.9 True True False 1s Waiting for 3/3 Profiles to be applied openshift-apiserver 4.21.9 True False False 7m27s openshift-controller-manager 4.21.9 True False False 7m27s openshift-samples operator-lifecycle-manager 4.21.9 True False False 7m26s operator-lifecycle-manager-catalog 4.21.9 True False False 7m20s operator-lifecycle-manager-packageserver 4.21.9 True False False 7m26s service-ca storage 4.21.9 True True False 7s VolumeDataSourceValidatorDeploymentControllerProgressing: Waiting for Deployment to deploy pods Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.21.9 True False False 8m39s dns 4.21.9 False True True 8m38s DNS "default" is unavailable. image-registry False True True 8m22s Available: The deployment does not have available replicas... ingress False True True 8m22s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.21.9 True False False 8m28s kube-controller-manager 4.21.9 True False False 8m28s kube-scheduler 4.21.9 True False False 8m28s kube-storage-version-migrator monitoring network 4.21.9 True True False 8m12s DaemonSet "/openshift-multus/network-metrics-daemon" is not available (awaiting 3 nodes)... node-tuning 4.21.9 True False False 62s openshift-apiserver 4.21.9 True False False 8m28s openshift-controller-manager 4.21.9 True False False 8m28s openshift-samples operator-lifecycle-manager 4.21.9 True False False 8m27s operator-lifecycle-manager-catalog 4.21.9 True False False 8m21s operator-lifecycle-manager-packageserver 4.21.9 True False False 8m27s service-ca storage 4.21.9 True True False 68s VolumeDataSourceValidatorDeploymentControllerProgressing: Waiting for Deployment to deploy pods Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.21.9 True False False 9m39s dns 4.21.9 False True True 9m38s DNS "default" is unavailable. image-registry False True True 9m22s Available: The deployment does not have available replicas... ingress False True True 9m22s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights 4.21.9 True False False 24s kube-apiserver 4.21.9 True False False 9m28s kube-controller-manager 4.21.9 True False False 9m28s kube-scheduler 4.21.9 True False False 9m28s kube-storage-version-migrator 4.21.9 True False False 21s monitoring network 4.21.9 True True False 9m12s DaemonSet "/openshift-multus/network-metrics-daemon" is not available (awaiting 3 nodes)... node-tuning 4.21.9 True False False 2m2s openshift-apiserver 4.21.9 True False False 9m28s openshift-controller-manager 4.21.9 True False False 9m28s openshift-samples operator-lifecycle-manager 4.21.9 True False False 9m27s operator-lifecycle-manager-catalog 4.21.9 True False False 9m21s operator-lifecycle-manager-packageserver 4.21.9 True False False 9m27s service-ca 4.21.9 True False False 21s storage 4.21.9 True False False 2m8s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.21.9 True False False 13s csi-snapshot-controller 4.21.9 True False False 10m dns 4.21.9 True True False 16s DNS "default" reports Progressing=True: "Have 2 available DNS pods, want 3." image-registry 4.21.9 True False False 20s ingress 4.21.9 True False True 25s The "default" ingress controller reports Degraded=True: DegradedConditions: One or more other status conditions indicate a degraded state: CanaryChecksSucceeding=Unknown (CanaryRouteNotAdmitted: Canary route is not admitted by the default ingress controller). insights 4.21.9 True False False 84s kube-apiserver 4.21.9 True False False 10m kube-controller-manager 4.21.9 True False False 10m kube-scheduler 4.21.9 True False False 10m kube-storage-version-migrator 4.21.9 True False False 81s monitoring Unknown True Unknown 54s Rolling out the stack. network 4.21.9 True True False 10m DaemonSet "/openshift-multus/network-metrics-daemon" is not available (awaiting 1 nodes) node-tuning 4.21.9 True False False 3m2s openshift-apiserver 4.21.9 True False False 10m openshift-controller-manager 4.21.9 True False False 10m openshift-samples False False False 6s SampleUpsertsPending operator-lifecycle-manager 4.21.9 True False False 10m operator-lifecycle-manager-catalog 4.21.9 True False False 10m operator-lifecycle-manager-packageserver 4.21.9 True False False 10m service-ca 4.21.9 True False False 81s storage 4.21.9 True False False 3m8s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.21.9 True False False 73s csi-snapshot-controller 4.21.9 True False False 11m dns 4.21.9 True False False 76s image-registry 4.21.9 True False False 80s ingress 4.21.9 True False False 85s insights 4.21.9 True False False 2m24s kube-apiserver 4.21.9 True False False 11m kube-controller-manager 4.21.9 True False False 11m kube-scheduler 4.21.9 True False False 11m kube-storage-version-migrator 4.21.9 True False False 2m21s monitoring 4.21.9 True False False 28s network 4.21.9 True False False 11m node-tuning 4.21.9 True False False 4m2s openshift-apiserver 4.21.9 True False False 11m openshift-controller-manager 4.21.9 True False False 11m openshift-samples 4.21.9 True False False 57s operator-lifecycle-manager 4.21.9 True False False 11m operator-lifecycle-manager-catalog 4.21.9 True False False 11m operator-lifecycle-manager-packageserver 4.21.9 True False False 11m service-ca 4.21.9 True False False 2m21s storage 4.21.9 True False False 4m8s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.21.9 True False False 2m14s csi-snapshot-controller 4.21.9 True False False 12m dns 4.21.9 True False False 2m17s image-registry 4.21.9 True False False 2m21s ingress 4.21.9 True False False 2m26s insights 4.21.9 True False False 3m25s kube-apiserver 4.21.9 True False False 12m kube-controller-manager 4.21.9 True False False 12m kube-scheduler 4.21.9 True False False 12m kube-storage-version-migrator 4.21.9 True False False 3m22s monitoring 4.21.9 True False False 89s network 4.21.9 True False False 12m node-tuning 4.21.9 True False False 5m3s openshift-apiserver 4.21.9 True False False 12m openshift-controller-manager 4.21.9 True False False 12m openshift-samples 4.21.9 True False False 118s operator-lifecycle-manager 4.21.9 True False False 12m operator-lifecycle-manager-catalog 4.21.9 True False False 12m operator-lifecycle-manager-packageserver 4.21.9 True False False 12m service-ca 4.21.9 True False False 3m22s storage 4.21.9 True False False 5m9s Waiting for cluster to be reported as healthy... Trying again in 60s healthy cluster to be reported as healthy finished!