INFO: Log in to your Red Hat account... INFO: Configure AWS Credentials... WARN: The current version (1.2.59) is not up to date with latest rosa cli released version (1.2.61). WARN: It is recommended that you update to the latest version. INFO: Logged in as 'rhtap-shared' on 'https://api.openshift.com' INFO: Create ROSA with HCP cluster... WARN: The current version (1.2.59) is not up to date with latest rosa cli released version (1.2.61). WARN: It is recommended that you update to the latest version. INFO: Creating cluster 'kx-1239a6226d' INFO: To view a list of clusters and their status, run 'rosa list clusters' INFO: Cluster 'kx-1239a6226d' has been created. INFO: Once the cluster is installed you will need to add an Identity Provider before you can login into the cluster. See 'rosa create idp --help' for more information. Name: kx-1239a6226d Domain Prefix: kx-1239a6226d Display Name: kx-1239a6226d ID: 2peb3vkdph24mruvov1fesssleh67mln External ID: b3830da1-75d1-4741-86b9-992b525c6ab7 Control Plane: ROSA Service Hosted OpenShift Version: 4.21.7 Channel Group: stable DNS: Not ready AWS Account: 381492310364 AWS Billing Account: 381492310364 API URL: Console URL: Region: us-east-1 Availability: - Control Plane: MultiAZ - Data Plane: MultiAZ Nodes: - Compute (desired): 3 - Compute (current): 0 Network: - Type: OVNKubernetes - Service CIDR: 172.30.0.0/16 - Machine CIDR: 10.0.0.0/16 - Pod CIDR: 10.128.0.0/14 - Host Prefix: /23 - Subnets: subnet-0208a6297964e4fe1, subnet-0c161c939f7025e15, subnet-023e5c7b3016ed194, subnet-02dbd8abbf884d77f, subnet-0360c2d20442c5ba5, subnet-0aad9c992e402a91a EC2 Metadata Http Tokens: optional Role (STS) ARN: arn:aws:iam::381492310364:role/rhads-hcp-HCP-ROSA-Installer-Role Support Role ARN: arn:aws:iam::381492310364:role/rhads-hcp-HCP-ROSA-Support-Role Instance IAM Roles: - Worker: arn:aws:iam::381492310364:role/rhads-hcp-HCP-ROSA-Worker-Role Operator IAM Roles: - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-control-plane-operator - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-kms-provider - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-kube-controller-manager - arn:aws:iam::381492310364:role/rhads-hcp-kube-system-capa-controller-manager - arn:aws:iam::381492310364:role/rhads-hcp-openshift-image-registry-installer-cloud-credentials - arn:aws:iam::381492310364:role/rhads-hcp-openshift-ingress-operator-cloud-credentials - arn:aws:iam::381492310364:role/rhads-hcp-openshift-cluster-csi-drivers-ebs-cloud-credentials - arn:aws:iam::381492310364:role/rhads-hcp-openshift-cloud-network-config-controller-cloud-creden Managed Policies: Yes State: waiting (Waiting for user action) Private: No Delete Protection: Disabled Created: Apr 2 2026 23:47:12 UTC Details Page: https://console.redhat.com/openshift/details/s/3Bp6OaUGosrL2ljcQM16GKd9Mey OIDC Endpoint URL: https://oidc.op1.openshiftapps.com/2jtsga3i2etnl697l7bk5i1kmbm4a95j (Managed) Etcd Encryption: Disabled Audit Log Forwarding: Disabled External Authentication: Disabled INFO: Preparing to create operator roles. INFO: Operator Roles already exists INFO: Preparing to create OIDC Provider. INFO: OIDC provider already exists INFO: To determine when your cluster is Ready, run 'rosa describe cluster -c kx-1239a6226d'. INFO: To watch your cluster installation logs, run 'rosa logs install -c kx-1239a6226d --watch'. INFO: Track the progress of the cluster creation... WARN: The current version (1.2.59) is not up to date with latest rosa cli released version (1.2.61). WARN: It is recommended that you update to the latest version. W: Region flag will be removed from this command in future versions INFO: Cluster 'kx-1239a6226d' is in waiting state waiting for installation to begin. Logs will show up within 5 minutes 0001-01-01 00:00:00 +0000 UTC hostedclusters kx-1239a6226d Version 2026-04-02 23:51:32 +0000 UTC certificates cluster-api-cert Issuing certificate as Secret does not exist 2026-04-02 23:51:32 +0000 UTC certificates cluster-api-cert Issuing certificate as Secret does not exist 2026-04-02 23:51:32 +0000 UTC hostedclusters kx-1239a6226d ValidAWSIdentityProvider StatusUnknown 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Condition not found in the CVO. 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Condition not found in the CVO. 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d The hosted control plane is not found 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d The hosted control plane is not found 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d The hosted control plane is not found 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d The hosted control plane is not found 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d The hosted control plane is not found 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Condition not found in the CVO. 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d The hosted control plane is not found 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d The hosted control plane is not found 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Condition not found in the CVO. 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Condition not found in the CVO. 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Ignition server deployment not found 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d HostedCluster is supported by operator configuration 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Release image is valid 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Reconciliation active on resource 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d configuration is invalid: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Reconciliation active on resource 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d configuration is invalid: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Reconciliation active on resource 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d configuration is invalid: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Reconciliation active on resource 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d configuration is invalid: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Reconciliation active on resource 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d configuration is invalid: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Reconciliation active on resource 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d configuration is invalid: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d ValidConfiguration condition is false: NamedCertificates get secret: Invalid value: "cluster-api-cert": Secret "cluster-api-cert" not found 0001-01-01 00:00:00 +0000 UTC hostedclusters kx-1239a6226d Version 2026-04-02 23:51:32 +0000 UTC hostedclusters kx-1239a6226d ValidAWSIdentityProvider StatusUnknown 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Condition not found in the CVO. 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Condition not found in the HCP 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Reconciliation active on resource 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Ignition server deployment not found 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d router load balancer is not provisioned; 2s since creation.; private-router load balancer is not provisioned; 2s since creation.; router load balancer is not provisioned; 2s since creation. 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Release image is valid 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Condition not found in the CVO. 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d HostedCluster is at expected version 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Condition not found in the CVO. 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Condition not found in the CVO. 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d HostedCluster is supported by operator configuration 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Condition not found in the CVO. 2026-04-02 23:53:01 +0000 UTC certificates cluster-api-cert Certificate is up to date and has not expired 2026-04-02 23:53:07 +0000 UTC hostedclusters kx-1239a6226d Required platform credentials are found 2026-04-02 23:53:07 +0000 UTC hostedclusters kx-1239a6226d Configuration passes validation 2026-04-02 23:53:09 +0000 UTC hostedclusters kx-1239a6226d OIDC configuration is valid 2026-04-02 23:53:09 +0000 UTC hostedclusters kx-1239a6226d Reconciliation completed successfully 2026-04-02 23:53:10 +0000 UTC hostedclusters kx-1239a6226d lookup api.kx-1239a6226d.ba86.p3.openshiftapps.com on 172.30.0.10:53: no such host 2026-04-02 23:53:10 +0000 UTC hostedclusters kx-1239a6226d Configuration passes validation 2026-04-02 23:53:10 +0000 UTC hostedclusters kx-1239a6226d EtcdAvailable StatefulSetNotFound 2026-04-02 23:53:10 +0000 UTC hostedclusters kx-1239a6226d AWS KMS is not configured 2026-04-02 23:53:10 +0000 UTC hostedclusters kx-1239a6226d Kube APIServer deployment not found 2026-04-02 23:53:10 +0000 UTC hostedclusters kx-1239a6226d router load balancer is not provisioned; 2s since creation.; private-router load balancer is not provisioned; 2s since creation.; router load balancer is not provisioned; 2s since creation. 2026-04-02 23:53:10 +0000 UTC hostedclusters kx-1239a6226d capi-provider deployment has 1 unavailable replicas 2026-04-02 23:53:17 +0000 UTC hostedclusters kx-1239a6226d All is well 2026-04-02 23:54:23 +0000 UTC hostedclusters kx-1239a6226d All is well 2026-04-02 23:54:50 +0000 UTC hostedclusters kx-1239a6226d EtcdAvailable QuorumAvailable 2026-04-02 23:55:04 +0000 UTC hostedclusters kx-1239a6226d lookup api.kx-1239a6226d.ba86.p3.openshiftapps.com on 172.30.0.10:53: no such host 0001-01-01 00:00:00 +0000 UTC hostedclusters kx-1239a6226d Version 2026-04-02 23:51:32 +0000 UTC hostedclusters kx-1239a6226d Cannot validate AWS identity provider while KubeAPIServer is not available 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Condition not found in the CVO. 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d HostedCluster is supported by operator configuration 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Reconciliation active on resource 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Ignition server deployment not found 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Waiting for hosted control plane kubeconfig to be created 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Release image is valid 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Condition not found in the CVO. 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d HostedCluster is at expected version 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Condition not found in the CVO. 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Condition not found in the CVO. 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Condition not found in the CVO. 2026-04-02 23:53:01 +0000 UTC certificates cluster-api-cert Certificate is up to date and has not expired 2026-04-02 23:53:07 +0000 UTC hostedclusters kx-1239a6226d Configuration passes validation 2026-04-02 23:53:07 +0000 UTC hostedclusters kx-1239a6226d Required platform credentials are found 2026-04-02 23:53:09 +0000 UTC hostedclusters kx-1239a6226d OIDC configuration is valid 2026-04-02 23:53:09 +0000 UTC hostedclusters kx-1239a6226d Reconciliation completed successfully 2026-04-02 23:53:10 +0000 UTC hostedclusters kx-1239a6226d Configuration passes validation 2026-04-02 23:53:10 +0000 UTC hostedclusters kx-1239a6226d AWS KMS is not configured 2026-04-02 23:53:10 +0000 UTC hostedclusters kx-1239a6226d Kube APIServer deployment not found 2026-04-02 23:53:10 +0000 UTC hostedclusters kx-1239a6226d capi-provider deployment has 1 unavailable replicas 2026-04-02 23:53:17 +0000 UTC hostedclusters kx-1239a6226d All is well 2026-04-02 23:54:23 +0000 UTC hostedclusters kx-1239a6226d All is well 2026-04-02 23:54:50 +0000 UTC hostedclusters kx-1239a6226d EtcdAvailable QuorumAvailable 2026-04-02 23:55:16 +0000 UTC hostedclusters kx-1239a6226d lookup api.kx-1239a6226d.ba86.p3.openshiftapps.com on 172.30.0.10:53: no such host 0001-01-01 00:00:00 +0000 UTC hostedclusters kx-1239a6226d Version 2026-04-02 23:51:32 +0000 UTC hostedclusters kx-1239a6226d Cannot validate AWS identity provider while KubeAPIServer is not available 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Condition not found in the CVO. 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d HostedCluster is supported by operator configuration 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Reconciliation active on resource 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Ignition server deployment not found 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Waiting for Kube APIServer deployment to become available 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Release image is valid 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Condition not found in the CVO. 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d HostedCluster is at expected version 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Condition not found in the CVO. 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Condition not found in the CVO. 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Condition not found in the CVO. 2026-04-02 23:53:01 +0000 UTC certificates cluster-api-cert Certificate is up to date and has not expired 2026-04-02 23:53:07 +0000 UTC hostedclusters kx-1239a6226d Configuration passes validation 2026-04-02 23:53:07 +0000 UTC hostedclusters kx-1239a6226d Required platform credentials are found 2026-04-02 23:53:09 +0000 UTC hostedclusters kx-1239a6226d OIDC configuration is valid 2026-04-02 23:53:09 +0000 UTC hostedclusters kx-1239a6226d Reconciliation completed successfully 2026-04-02 23:53:10 +0000 UTC hostedclusters kx-1239a6226d Configuration passes validation 2026-04-02 23:53:10 +0000 UTC hostedclusters kx-1239a6226d AWS KMS is not configured 2026-04-02 23:53:10 +0000 UTC hostedclusters kx-1239a6226d Waiting for Kube APIServer deployment to become available 2026-04-02 23:53:10 +0000 UTC hostedclusters kx-1239a6226d [capi-provider deployment has 2 unavailable replicas, kube-apiserver deployment has 2 unavailable replicas] 2026-04-02 23:53:17 +0000 UTC hostedclusters kx-1239a6226d All is well 2026-04-02 23:54:23 +0000 UTC hostedclusters kx-1239a6226d All is well 2026-04-02 23:54:50 +0000 UTC hostedclusters kx-1239a6226d EtcdAvailable QuorumAvailable 2026-04-02 23:55:39 +0000 UTC hostedclusters kx-1239a6226d lookup api.kx-1239a6226d.ba86.p3.openshiftapps.com on 172.30.0.10:53: no such host 2026-04-02 23:56:04 +0000 UTC hostedclusters kx-1239a6226d Kube APIServer deployment is available 2026-04-02 23:56:07 +0000 UTC hostedclusters kx-1239a6226d Ignition server deployment is available 2026-04-02 23:56:53 +0000 UTC hostedclusters kx-1239a6226d lookup api.kx-1239a6226d.ba86.p3.openshiftapps.com on 172.30.0.10:53: no such host 0001-01-01 00:00:00 +0000 UTC hostedclusters kx-1239a6226d Version 2026-04-02 23:51:32 +0000 UTC hostedclusters kx-1239a6226d Cannot validate AWS identity provider while KubeAPIServer is not available 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d HostedCluster is supported by operator configuration 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Waiting for components to be available: hosted-cluster-config-operator, community-operators-catalog 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d HostedCluster is at expected version 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Release image is valid 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Reconciliation active on resource 2026-04-02 23:53:01 +0000 UTC certificates cluster-api-cert Certificate is up to date and has not expired 2026-04-02 23:53:07 +0000 UTC hostedclusters kx-1239a6226d Configuration passes validation 2026-04-02 23:53:07 +0000 UTC hostedclusters kx-1239a6226d Required platform credentials are found 2026-04-02 23:53:09 +0000 UTC hostedclusters kx-1239a6226d OIDC configuration is valid 2026-04-02 23:53:09 +0000 UTC hostedclusters kx-1239a6226d Reconciliation completed successfully 2026-04-02 23:53:10 +0000 UTC hostedclusters kx-1239a6226d AWS KMS is not configured 2026-04-02 23:53:10 +0000 UTC hostedclusters kx-1239a6226d Configuration passes validation 2026-04-02 23:53:10 +0000 UTC hostedclusters kx-1239a6226d [ignition-server-proxy deployment has 2 unavailable replicas, router deployment has 1 unavailable replicas] 2026-04-02 23:53:17 +0000 UTC hostedclusters kx-1239a6226d All is well 2026-04-02 23:54:23 +0000 UTC hostedclusters kx-1239a6226d All is well 2026-04-02 23:54:50 +0000 UTC hostedclusters kx-1239a6226d EtcdAvailable QuorumAvailable 2026-04-02 23:56:04 +0000 UTC hostedclusters kx-1239a6226d Kube APIServer deployment is available 2026-04-02 23:56:07 +0000 UTC hostedclusters kx-1239a6226d Ignition server deployment is available 2026-04-02 23:56:53 +0000 UTC hostedclusters kx-1239a6226d Payload loaded version="4.21.7" image="quay.io/openshift-release-dev/ocp-release@sha256:c781dbeb8ddfbc3c5715f4dd6e10578b4dab144aa8a4b3e5072f55c26f9a029c" architecture="Multi" 2026-04-02 23:56:53 +0000 UTC hostedclusters kx-1239a6226d ClusterVersionAvailable FromClusterVersion 2026-04-02 23:56:53 +0000 UTC hostedclusters kx-1239a6226d Working towards 4.21.7: 566 of 683 done (82% complete) 2026-04-02 23:56:53 +0000 UTC hostedclusters kx-1239a6226d An update is already in progress and the details are in the Progressing condition 2026-04-02 23:56:53 +0000 UTC hostedclusters kx-1239a6226d ClusterVersionSucceeding FromClusterVersion 2026-04-02 23:57:00 +0000 UTC hostedclusters kx-1239a6226d lookup api.kx-1239a6226d.ba86.p3.openshiftapps.com on 172.30.0.10:53: no such host 0001-01-01 00:00:00 +0000 UTC hostedclusters kx-1239a6226d Version 2026-04-02 23:51:32 +0000 UTC hostedclusters kx-1239a6226d Cannot validate AWS identity provider while KubeAPIServer is not available 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Reconciliation active on resource 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d HostedCluster is at expected version 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d HostedCluster is supported by operator configuration 2026-04-02 23:51:34 +0000 UTC hostedclusters kx-1239a6226d Release image is valid 2026-04-02 23:53:01 +0000 UTC certificates cluster-api-cert Certificate is up to date and has not expired 2026-04-02 23:53:07 +0000 UTC hostedclusters kx-1239a6226d Configuration passes validation 2026-04-02 23:53:07 +0000 UTC hostedclusters kx-1239a6226d Required platform credentials are found 2026-04-02 23:53:09 +0000 UTC hostedclusters kx-1239a6226d Reconciliation completed successfully 2026-04-02 23:53:09 +0000 UTC hostedclusters kx-1239a6226d OIDC configuration is valid 2026-04-02 23:53:10 +0000 UTC hostedclusters kx-1239a6226d Configuration passes validation 2026-04-02 23:53:10 +0000 UTC hostedclusters kx-1239a6226d AWS KMS is not configured 2026-04-02 23:53:10 +0000 UTC hostedclusters kx-1239a6226d ignition-server-proxy deployment has 1 unavailable replicas 2026-04-02 23:53:17 +0000 UTC hostedclusters kx-1239a6226d All is well 2026-04-02 23:54:23 +0000 UTC hostedclusters kx-1239a6226d All is well 2026-04-02 23:54:50 +0000 UTC hostedclusters kx-1239a6226d EtcdAvailable QuorumAvailable 2026-04-02 23:56:04 +0000 UTC hostedclusters kx-1239a6226d Kube APIServer deployment is available 2026-04-02 23:56:07 +0000 UTC hostedclusters kx-1239a6226d Ignition server deployment is available 2026-04-02 23:56:53 +0000 UTC hostedclusters kx-1239a6226d Payload loaded version="4.21.7" image="quay.io/openshift-release-dev/ocp-release@sha256:c781dbeb8ddfbc3c5715f4dd6e10578b4dab144aa8a4b3e5072f55c26f9a029c" architecture="Multi" 2026-04-02 23:56:53 +0000 UTC hostedclusters kx-1239a6226d ClusterVersionAvailable FromClusterVersion 2026-04-02 23:56:53 +0000 UTC hostedclusters kx-1239a6226d Unable to apply 4.21.7: some cluster operators are not available 2026-04-02 23:56:53 +0000 UTC hostedclusters kx-1239a6226d An update is already in progress and the details are in the Progressing condition 2026-04-02 23:57:16 +0000 UTC hostedclusters kx-1239a6226d Cluster operators console, dns, image-registry, ingress, insights, kube-storage-version-migrator, monitoring, node-tuning, openshift-samples, service-ca, storage are not available 2026-04-02 23:57:16 +0000 UTC hostedclusters kx-1239a6226d The hosted control plane is available INFO: Cluster 'kx-1239a6226d' is now ready INFO: ROSA with HCP cluster is ready, create a cluster admin account for accessing the cluster WARN: The current version (1.2.59) is not up to date with latest rosa cli released version (1.2.61). WARN: It is recommended that you update to the latest version. INFO: Storing login command... INFO: Check if it's able to login to OCP cluster... Retried 1 times... INFO: Check if apiserver is ready... Waiting for cluster operators to be accessible for 2m... NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.21.7 True False False 2m20s dns 4.21.7 False False True 2m21s DNS "default" is unavailable. image-registry False True True 2m3s Available: The deployment does not have available replicas... ingress False True True 2m2s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.21.7 True False False 2m8s kube-controller-manager 4.21.7 True False False 2m8s kube-scheduler 4.21.7 True False False 2m8s kube-storage-version-migrator monitoring network 4.21.7 True True False 113s DaemonSet "/openshift-network-operator/iptables-alerter" is waiting for other operators to become ready... node-tuning False True False 2m3s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.21.7 True False False 2m8s openshift-controller-manager 4.21.7 True False False 2m8s openshift-samples operator-lifecycle-manager 4.21.7 True False False 2m11s operator-lifecycle-manager-catalog 4.21.7 True False False 2m1s operator-lifecycle-manager-packageserver 4.21.7 True False False 2m8s service-ca storage 4.21.7 False True False 2m8s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service cluster operators to be accessible finished! [INFO] Cluster operators are accessible. Waiting for cluster to be reported as healthy for 60m... NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.21.7 True False False 2m20s dns 4.21.7 False False True 2m21s DNS "default" is unavailable. image-registry False True True 2m3s Available: The deployment does not have available replicas... ingress False True True 2m2s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.21.7 True False False 2m8s kube-controller-manager 4.21.7 True False False 2m8s kube-scheduler 4.21.7 True False False 2m8s kube-storage-version-migrator monitoring network 4.21.7 True True False 113s DaemonSet "/openshift-network-operator/iptables-alerter" is waiting for other operators to become ready... node-tuning False True False 2m3s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.21.7 True False False 2m8s openshift-controller-manager 4.21.7 True False False 2m8s openshift-samples operator-lifecycle-manager 4.21.7 True False False 2m11s operator-lifecycle-manager-catalog 4.21.7 True False False 2m1s operator-lifecycle-manager-packageserver 4.21.7 True False False 2m8s service-ca storage 4.21.7 False True False 2m8s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.21.7 True False False 3m21s dns 4.21.7 False False True 3m22s DNS "default" is unavailable. image-registry False True True 3m4s Available: The deployment does not have available replicas... ingress False True True 3m3s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.21.7 True False False 3m9s kube-controller-manager 4.21.7 True False False 3m9s kube-scheduler 4.21.7 True False False 3m9s kube-storage-version-migrator monitoring network 4.21.7 True True False 2m54s DaemonSet "/openshift-network-operator/iptables-alerter" is waiting for other operators to become ready... node-tuning False True False 3m4s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.21.7 True False False 3m9s openshift-controller-manager 4.21.7 True False False 3m9s openshift-samples operator-lifecycle-manager 4.21.7 True False False 3m12s operator-lifecycle-manager-catalog 4.21.7 True False False 3m2s operator-lifecycle-manager-packageserver 4.21.7 True False False 3m9s service-ca storage 4.21.7 False True False 3m9s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.21.7 True False False 4m21s dns 4.21.7 False False True 4m22s DNS "default" is unavailable. image-registry False True True 4m4s Available: The deployment does not have available replicas... ingress False True True 4m3s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.21.7 True False False 4m9s kube-controller-manager 4.21.7 True False False 4m9s kube-scheduler 4.21.7 True False False 4m9s kube-storage-version-migrator monitoring network 4.21.7 True True False 3m54s DaemonSet "/openshift-network-operator/iptables-alerter" is waiting for other operators to become ready... node-tuning False True False 4m4s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.21.7 True False False 4m9s openshift-controller-manager 4.21.7 True False False 4m9s openshift-samples operator-lifecycle-manager 4.21.7 True False False 4m12s operator-lifecycle-manager-catalog 4.21.7 True False False 4m2s operator-lifecycle-manager-packageserver 4.21.7 True False False 4m9s service-ca storage 4.21.7 False True False 4m9s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.21.7 True False False 5m21s dns 4.21.7 False False True 5m22s DNS "default" is unavailable. image-registry False True True 5m4s Available: The deployment does not have available replicas... ingress False True True 5m3s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.21.7 True False False 5m9s kube-controller-manager 4.21.7 True False False 5m9s kube-scheduler 4.21.7 True False False 5m9s kube-storage-version-migrator monitoring network 4.21.7 True True False 4m54s DaemonSet "/openshift-network-operator/iptables-alerter" is waiting for other operators to become ready... node-tuning False True False 5m4s DaemonSet "tuned" has no available Pod(s) openshift-apiserver 4.21.7 True False False 5m9s openshift-controller-manager 4.21.7 True False False 5m9s openshift-samples operator-lifecycle-manager 4.21.7 True False False 5m12s operator-lifecycle-manager-catalog 4.21.7 True False False 5m2s operator-lifecycle-manager-packageserver 4.21.7 True False False 5m9s service-ca storage 4.21.7 False True False 5m9s AWSEBSCSIDriverOperatorCRAvailable: AWSEBSDriverNodeServiceControllerAvailable: Waiting for the DaemonSet to deploy the CSI Node Service Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.21.7 True False False 6m22s dns 4.21.7 False False True 6m23s DNS "default" is unavailable. image-registry False True True 6m5s Available: The deployment does not have available replicas... ingress False True True 6m4s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.21.7 True False False 6m10s kube-controller-manager 4.21.7 True False False 6m10s kube-scheduler 4.21.7 True False False 6m10s kube-storage-version-migrator monitoring network 4.21.7 True True False 5m55s DaemonSet "/openshift-multus/network-metrics-daemon" is waiting for other operators to become ready... node-tuning 4.21.7 True True False 14s Waiting for 3/3 Profiles to be applied openshift-apiserver 4.21.7 True False False 6m10s openshift-controller-manager 4.21.7 True False False 6m10s openshift-samples operator-lifecycle-manager 4.21.7 True False False 6m13s operator-lifecycle-manager-catalog 4.21.7 True False False 6m3s operator-lifecycle-manager-packageserver 4.21.7 True False False 6m10s service-ca storage 4.21.7 True True False 12s VolumeDataSourceValidatorDeploymentControllerProgressing: Waiting for Deployment to deploy pods Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.21.7 True False False 7m22s dns 4.21.7 False True True 7m23s DNS "default" is unavailable. image-registry False True True 7m5s Available: The deployment does not have available replicas... ingress False True True 7m4s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.21.7 True False False 7m10s kube-controller-manager 4.21.7 True False False 7m10s kube-scheduler 4.21.7 True False False 7m10s kube-storage-version-migrator monitoring network 4.21.7 True True False 6m55s DaemonSet "/openshift-multus/network-metrics-daemon" is waiting for other operators to become ready... node-tuning 4.21.7 True False False 74s openshift-apiserver 4.21.7 True False False 7m10s openshift-controller-manager 4.21.7 True False False 7m10s openshift-samples operator-lifecycle-manager 4.21.7 True False False 7m13s operator-lifecycle-manager-catalog 4.21.7 True False False 7m3s operator-lifecycle-manager-packageserver 4.21.7 True False False 7m10s service-ca storage 4.21.7 True True False 72s VolumeDataSourceValidatorDeploymentControllerProgressing: Waiting for Deployment to deploy pods Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.21.7 True False False 8m22s dns 4.21.7 False True True 8m23s DNS "default" is unavailable. image-registry False True True 8m5s Available: The deployment does not have available replicas... ingress False True True 8m4s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights kube-apiserver 4.21.7 True False False 8m10s kube-controller-manager 4.21.7 True False False 8m10s kube-scheduler 4.21.7 True False False 8m10s kube-storage-version-migrator monitoring network 4.21.7 True True False 7m55s DaemonSet "/openshift-multus/network-metrics-daemon" is waiting for other operators to become ready... node-tuning 4.21.7 True False False 2m14s openshift-apiserver 4.21.7 True False False 8m10s openshift-controller-manager 4.21.7 True False False 8m10s openshift-samples operator-lifecycle-manager 4.21.7 True False False 8m13s operator-lifecycle-manager-catalog 4.21.7 True False False 8m3s operator-lifecycle-manager-packageserver 4.21.7 True False False 8m10s service-ca storage 4.21.7 True True False 2m12s VolumeDataSourceValidatorDeploymentControllerProgressing: Waiting for Deployment to deploy pods Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console csi-snapshot-controller 4.21.7 True False False 9m22s dns 4.21.7 False True True 9m23s DNS "default" is unavailable. image-registry False True True 9m5s Available: The deployment does not have available replicas... ingress False True True 9m4s The "default" ingress controller reports Available=False: IngressControllerUnavailable: One or more status conditions indicate unavailable: DeploymentAvailable=False (DeploymentUnavailable: The deployment has Available status condition set to False (reason: MinimumReplicasUnavailable) with message: Deployment does not have minimum availability.) insights 4.21.7 True False False 46s kube-apiserver 4.21.7 True False False 9m10s kube-controller-manager 4.21.7 True False False 9m10s kube-scheduler 4.21.7 True False False 9m10s kube-storage-version-migrator 4.21.7 True False False 43s monitoring Unknown True Unknown 15s Rolling out the stack. network 4.21.7 True True False 8m55s DaemonSet "/openshift-multus/network-metrics-daemon" is waiting for other operators to become ready node-tuning 4.21.7 True False False 3m14s openshift-apiserver 4.21.7 True False False 9m10s openshift-controller-manager 4.21.7 True False False 9m10s openshift-samples operator-lifecycle-manager 4.21.7 True False False 9m13s operator-lifecycle-manager-catalog 4.21.7 True False False 9m3s operator-lifecycle-manager-packageserver 4.21.7 True False False 9m10s service-ca 4.21.7 True False False 42s storage 4.21.7 True False False 3m12s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.21.7 False True False 45s DeploymentAvailable: 0 replicas available for console deployment csi-snapshot-controller 4.21.7 True False False 10m dns 4.21.7 False True True 10m DNS "default" is unavailable. image-registry False True True 10m Available: The deployment does not have available replicas... ingress 4.21.7 True False True 47s The "default" ingress controller reports Degraded=True: DegradedConditions: One or more other status conditions indicate a degraded state: CanaryChecksSucceeding=Unknown (CanaryRouteNotAdmitted: Canary route is not admitted by the default ingress controller). insights 4.21.7 True False False 107s kube-apiserver 4.21.7 True False False 10m kube-controller-manager 4.21.7 True False False 10m kube-scheduler 4.21.7 True False False 10m kube-storage-version-migrator 4.21.7 True False False 104s monitoring Unknown True Unknown 76s Rolling out the stack. network 4.21.7 True False False 9m56s node-tuning 4.21.7 True False False 4m15s openshift-apiserver 4.21.7 True False False 10m openshift-controller-manager 4.21.7 True False False 10m openshift-samples operator-lifecycle-manager 4.21.7 True False False 10m operator-lifecycle-manager-catalog 4.21.7 True False False 10m operator-lifecycle-manager-packageserver 4.21.7 True False False 10m service-ca 4.21.7 True False False 103s storage 4.21.7 True False False 4m13s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.21.7 True False False 25s csi-snapshot-controller 4.21.7 True False False 11m dns 4.21.7 True False False 30s image-registry 4.21.7 False True False 14s Available: The deployment does not have available replicas... ingress 4.21.7 True False True 107s The "default" ingress controller reports Degraded=True: DegradedConditions: One or more other status conditions indicate a degraded state: CanaryChecksSucceeding=Unknown (CanaryRouteNotAdmitted: Canary route is not admitted by the default ingress controller). insights 4.21.7 True False False 2m47s kube-apiserver 4.21.7 True False False 11m kube-controller-manager 4.21.7 True False False 11m kube-scheduler 4.21.7 True False False 11m kube-storage-version-migrator 4.21.7 True False False 2m44s monitoring 4.21.7 True False False 52s network 4.21.7 True False False 10m node-tuning 4.21.7 True False False 5m15s openshift-apiserver 4.21.7 True False False 11m openshift-controller-manager 4.21.7 True False False 11m openshift-samples 4.21.7 True False False 20s operator-lifecycle-manager 4.21.7 True False False 11m operator-lifecycle-manager-catalog 4.21.7 True False False 11m operator-lifecycle-manager-packageserver 4.21.7 True False False 11m service-ca 4.21.7 True False False 2m43s storage 4.21.7 True False False 5m13s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.21.7 True False False 85s csi-snapshot-controller 4.21.7 True False False 12m dns 4.21.7 True False False 90s image-registry 4.21.7 True False False 54s ingress 4.21.7 True False False 2m47s insights 4.21.7 True False False 3m47s kube-apiserver 4.21.7 True False False 12m kube-controller-manager 4.21.7 True False False 12m kube-scheduler 4.21.7 True False False 12m kube-storage-version-migrator 4.21.7 True False False 3m44s monitoring 4.21.7 True False False 112s network 4.21.7 True False False 11m node-tuning 4.21.7 True False False 6m15s openshift-apiserver 4.21.7 True False False 12m openshift-controller-manager 4.21.7 True False False 12m openshift-samples 4.21.7 True False False 80s operator-lifecycle-manager 4.21.7 True False False 12m operator-lifecycle-manager-catalog 4.21.7 True False False 12m operator-lifecycle-manager-packageserver 4.21.7 True False False 12m service-ca 4.21.7 True False False 3m43s storage 4.21.7 True False False 6m13s Waiting for cluster to be reported as healthy... Trying again in 60s NAME VERSION AVAILABLE PROGRESSING DEGRADED SINCE MESSAGE console 4.21.7 True False False 2m26s csi-snapshot-controller 4.21.7 True False False 13m dns 4.21.7 True False False 2m31s image-registry 4.21.7 True False False 115s ingress 4.21.7 True False False 3m48s insights 4.21.7 True False False 4m48s kube-apiserver 4.21.7 True False False 13m kube-controller-manager 4.21.7 True False False 13m kube-scheduler 4.21.7 True False False 13m kube-storage-version-migrator 4.21.7 True False False 4m45s monitoring 4.21.7 True False False 2m53s network 4.21.7 True False False 12m node-tuning 4.21.7 True False False 7m16s openshift-apiserver 4.21.7 True False False 13m openshift-controller-manager 4.21.7 True False False 13m openshift-samples 4.21.7 True False False 2m21s operator-lifecycle-manager 4.21.7 True False False 13m operator-lifecycle-manager-catalog 4.21.7 True False False 13m operator-lifecycle-manager-packageserver 4.21.7 True False False 13m service-ca 4.21.7 True False False 4m44s storage 4.21.7 True False False 7m14s Waiting for cluster to be reported as healthy... Trying again in 60s healthy cluster to be reported as healthy finished!