Masquerade uses OVN-K over eno2/br-ex — no bridge setup required
Test cases(24 of 50)
Complete prerequisites first ([PRE-01](PRE-01) → [PRE-08](PRE-08) minimum) before running these tests. Go to prerequisites
NOT POSSIBLE on SNO — live migration requires ≥2 nodes. Documented as an expected failure.
Test on local storage
Optimal for single-NIC — OVN-K over eno2/br-ex, no bridge setup required
✗ NOT TESTABLE ON HETZNER -- TOS violation! OVN-K localnet works technically (verified 30.06.2026: ping successful), but any VM MAC that reaches eno2/the physical switch via this interface is detected and reported by Hetzner as an unauthorised MAC (server suspension threatened). Only the registered server MAC is permitted.
✗ NOT TESTABLE — SR-IOV requires a dedicated second NIC (Intel X710, Mellanox ConnectX). The sole NIC eno2 is consumed by OVN-K and cannot be used for SR-IOV VFs.
Variant A uses pure software bridges br-net1/2/3 (port: []) — no VM MAC leaves eno2/the physical switch, no TOS risk. Variant B (on-premises, trunk port) is relevant only with your own switch.
purely internal software bridges br-net1/br-net2 (port: []) — no VM MAC leaves the node
VM with three interfaces: masquerade (management/SSH), br-net1 (application data), br-net2 (storage replication). Separation of traffic types as in production environments — on this Hetzner SNO via pure software bridges (Variant A), not real VLANs.
Confirm these before running steps:
1Re-verify prerequisites: NNCP and NetworkAttachmentDefinitions (NADs) must exist
oc get nncpoc get network-attachment-definition -n vmtest2Verify SSH key secret — without it login is not possible, as the Fedora containerDisk image has no console password by default
oc get secret vm-ssh-key -n vmtest4Wait for VM start until Phase Running is reached
oc get vmi multi-nic-vm -n vmtest -w5Brief wait for key propagation — cloud-init must boot and set the SELinux boolean before qemu-guest-agent accepts the SSH key
6Log in via SSH
virtctl ssh fedora@vm/multi-nic-vm -n vmtest -i ~/.ssh/ocp-vm-key7List all three interfaces and verify initial state
ip addr (while in SSH session)8Assign static IPs on enp2s0 and enp3s0 (these networks have no DHCP server)
sudo ip addr add 192.168.10.50/24 dev enp2s0sudo ip addr add 192.168.20.50/24 dev enp3s0sudo ip link set enp2s0 upsudo ip link set enp3s0 up9Verify configuration — all three interfaces must now show an IP
ip addr11Optional, for deeper proof at packet level: tcpdump on the node — RHCOS has NO tcpdump in the host image (deliberately minimal), toolbox container is required
NODE=$(oc get node -o name)oc debug $NODEchroot /hosttoolboxtcpdump -i br-net1 -c 5 -n12Finally, confirm SSH access again via the management path (enp1s0/masquerade)
virtctl ssh fedora@vm/multi-nic-vm -n vmtest -i ~/.ssh/ocp-vm-key13Clean up (optional, if created only for testing)
oc delete vm multi-nic-vm -n vmtestUserDefinedNetwork with Layer2 topology is a pure overlay (encapsulated Geneve tunnel within OVN-K) — explicitly NOT localnet, so no VM MAC leaves the node.
⚠️ DEDICATED NAMESPACE REQUIRED: see NOTE below.
2 Pools: internal-pool binds to br-net1 — external-pool binds to eno2, requires a 2nd public IP
external-pool uses a provider-registered additional IP (e.g. Hetzner Additional IP); MetalLB speaker announces with the node's own MAC.
⚠️ SHARED RESOURCE: external-pool currently has only ONE IP — Clean up after this test (delete vm-ssh-lb) before starting TC-HCP-002
⚠️ NOT usable by default on the current SNO cluster: there is no customer-controlled router in the path for peering. Left for documentation purposes and future tests.
L2Advertisement explicitly binds to br-net1/br-net2 — ARP announcements stay node-internal.
Single-NIC OK — HyperShift pods use the OVN-K pod network.
⚠️ Check Pod/Node Capacity before starting TC-HCP-002 — see steps below.
⚠️ SNO EXAMPLE INSTALLATION: --control-plane-availability-policy SingleReplica is mandatory on a single-node cluster.
⚠️ Be sure enough compute resources are available on the SNO node before starting this test.
Import over OVN-K — bandwidth is shared with OCP traffic on eno2/br-ex in this cluster