From f5b22e51fc3ab033640f4000261c38366af20a9a Mon Sep 17 00:00:00 2001 From: "joost.de.cupere@xenit.eu" Date: Thu, 14 Jul 2022 10:49:19 +0200 Subject: [PATCH] Enable the option to self manage secrets --- README.md | 48 ++++++++++++++++++ alfresco-0.1.0.tgz | Bin 11641 -> 11709 bytes index.yaml | 6 +-- xenit-alfresco/templates/acs/acs-secret.yaml | 4 +- .../templates/active-mq/mq-secret.yaml | 4 +- xenit-alfresco/templates/db-secret.yaml | 4 +- .../templates/docker-registry-secrets.yaml | 4 +- xenit-alfresco/values.yaml | 9 ++++ 8 files changed, 72 insertions(+), 7 deletions(-) diff --git a/README.md b/README.md index f01d49e..3b72139 100644 --- a/README.md +++ b/README.md @@ -123,6 +123,54 @@ For more information take a look at * Description: A field to tell the helm chart what cni provider your cluster is using. By default we assume cilium. If this is not the case you will need to add a network policy to allow the following * Alfresco to access heartbeat +#### `general.secrets.acs.selfManaged` + +* Required: false +* Default: false +* Description: Whether or not you want to provide secrets for the helm chart yourself. This is useful when working on a prod environment and you want a secure secret solution (for example Bitnami' Sealed secrets) +* Please note that when you enable this you are yourself responsible to provide a secret acs-secret in the namespace that you will install this chart in. +* Secret data expected: +``` + GLOBAL_objectstorage.store.myS3ContentStore.value.accessKey + GLOBAL_objectstorage.store.myS3ContentStore.value.secretKey +``` + +#### `general.secrets.mq.selfManaged` + +* Required: false +* Default: false +* Description: Whether or not you want to provide secrets for the helm chart yourself. This is useful when working on a prod environment and you want a secure secret solution (for example Bitnami' Sealed secrets) +* Please note that when you enable this you are yourself responsible to provide a secret mq-secret in the namespace that you will install this chart in. +* Secret data expected: +``` + ACTIVEMQ_ADMIN_LOGIN + ACTIVEMQ_ADMIN_PASSWORD + GLOBAL_messaging.broker.username + GLOBAL_messaging.broker.password +``` + +#### `general.secrets.db.selfManaged` + +* Required: false +* Default: false +* Description: Whether or not you want to provide secrets for the helm chart yourself. This is useful when working on a prod environment and you want a secure secret solution (for example Bitnami' Sealed secrets) +* Please note that when you enable this you are yourself responsible to provide a secret db-secret in the namespace that you will install this chart in. +* Secret data expected: +``` + DB_USERNAME + DB_PASSWORD + POSTGRES_USER + POSTGRES_PASSWORD +``` + +#### `general.secrets.imageCredentials.selfManaged` + +* Required: false +* Default: false +* Description: Whether or not you want to provide secrets for the helm chart yourself. This is useful when working on a prod environment and you want a secure secret solution (for example Bitnami' Sealed secrets) +* Please note that when you enable this you are yourself responsible to provide a secret privatecred alfrescocred in the namespace that you will install this chart in. +* Secret data expected: Both secrets should be dockerconfigjson secrets + ### Ingress #### `ingress.host` diff --git a/alfresco-0.1.0.tgz b/alfresco-0.1.0.tgz index a9770f919f0e1ab70f59c1bd124b030757b4e48f..8f25ae26056291ed7367d4cd17fb3dc480a53368 100644 GIT binary patch delta 11405 zcmZ9S^;eZoyte7??(XiER_R8hC8Zk)fd`};2~oNm>5fe|(y4%Sce7zX$M5^D^UL`Q zX02H>^SS1_???g0eKadwngn(eC2cp-%4J}J1GZ1iaaNKZ$ufMod z^D&`NWc~D3ORIJ<2JG6)Dk?OFt?p_nDn@~YO}86VXQ`}&1lGdK%NyJZ5uJrm+Tc|& zmgIVRytP&qxxH|sm-)R@??%3r4&U3wAxA|VscJD43(|B?N@8Q7cvv9npGE%>lH>VN!rZ^J1fKuYb2PTAJ)()8XscU!1Z9i-z%Ys6 zfXw%JwmWvl!^)TXR_Ym{&te4Wl6_TdK376Shn5`6R8cMF;uA_jw{LPFUQ}Grjq!$T zbCplYVz3Xq`rb{R9tM0s@K^l9& zm?!Q>EZQyFC)Y`o(1S$jkcVEOzfJ-)*!}oamwO+V11?6q!!EK3nzSE$q`%Gl(D0VW zj~MkP=fSUEcF9HISs68FeJWM>l1M&JhIt+x!W{Z84W04_Z=nyxJAWhZ z&u=L);e@EX}yme>6=^8(oWkn1BS$Zk+BZ8E4)Md?b)r2_n1eX$pwgT zi;>>Jk0Qhq7B*sST|hbKz65s9m91Coc788-v;N2>hmWoRME|c5$zenC&jNl zX;B(UiEu`V*5B2I80lUGe$)Dz!&)z=@hae~%6FOcXGWkT^(tKVHzfLF9)oVOrU^{j)_9D&29^VmfY#^3oqlekXB6zCb25xKQCE}LR4cz94}jDfs=GtB z24Y0b3Q_IkTjHQ!5)6f7+&{1t4V~hqlCIV+j+dhF{XtpE53Xpp%R9X$@J4-mAZ_TC)dA!V4ypI&Tbsp5)uCny+1Tha=W6>Jh97RoEp7UV7CF}% zrx6Dl3=*PkLqh^-%@|5n^)kC*kZ#MHQziWc@Fi0{6+5JKWIh)HaK|VaB>gzW|ibop_0&b*1dG z3bd#yrA~X5C4%O_LY#qbCu5$3Tli%h^?2w(njx_%JbB^_WAdyQ22Q5Zvd>ZK7`w+J zU0l24KH2XZ5UIa%)&1m6FBuMQ_db*QP9`qmb-+rUx$c$ZmJI(IoOZ5MnFHa5y*gvz z$VytF<+xI&(P>%NAVAPgvg$9`u}z)#_Zg5PXPE+rw=Y{I!4~bUeb8>~$KDW>hzoBN zxkoZ+m>0hNI9bk%Pz0J&EJQ_=wOl92qWT_Mym%1=1m@w zrYcwSvN{dR5McjaMy1^4OZs(rsAg zph9|xOT9jfYahh?DGa5{(e6W;?lNX%f8rwg&Q`T0V+-0ue*XDq0t7ZWxs}r}*I3pF z{KA9>eyMTN=Gc3Zk%8c$ErPok;!>ZiEx54jvH7Nv{Psgxs)h66nt|tiG_oay;lvYG z9FVGhfAo+FXthJ9LQ6-|LLy1Jb^NK;ibVMly$;pfqB=FoXS?)zr-uGkLF%W-w?Qe- zW_J0jA(!{?&!}9RDjV;KZq{pf@VfevWFzk^wTjPBI*YP#bWZ4+^^~mANouGOnLV@F+dM4Q zbL}>L#Tsi}wiMR9R|fJ=8y&XtJ{b$Szi)H2MUJnw7+i{t-OOSTApB8f zPjuJ2qRE)YLD&i-!B^0AH|6I0qnU47FUeP#-N{3Jm*1mx6${Q#TPd0}hhth5Jd~O( zgh|m8ju7R0Vc#_EegWr{P&oGJlR@+!o7owK~YL*nt)sGa}N0<34W;SPsqOv^k z;v|1cDpMxE7~mWa9v2Najz>NC4&+;7Ga*2uo5Y*E<}@Y>HUm4NUVph+Lsd`|O7QnR z$^wR;yIxBL9RI^V0Z)QZ$u|Th0qYGeETixGI6kM;W#v4{o7e3e0Ig-~kQX0cDQ(@m zjp)@wV3kd}LoBMKW;b9Gn!d|76jJ@UZP(|_^^Dwh!|uGM=n9=)UqBrO$F}ZIx+ST! zqP`+&?12@0#s$A3@g}c0kv2C7F1M@U2XF}Y+v^(u?^Ugv7s|YTcR2(AseVq82OP4aliS;$TobFdCiVG`;&j4hz zIgjRT`~s$ys6p_cx83h=aQDo#;JYI$_1>-|%iV&8Nal z%5$yZ!Ji8jIcA$qRfd$-ghZ(kzi_W2y)osZg|B-BoeXh1bk7j&r+FJTEmnxU>`#@} z)`{{1ljC;+)$QB_QCF(_+oT4y{a(O)a5(wTOYUzIA89zEL4a11b@T=F_5E`SI;Yy6 z%4}%|bLV6=1cRRk`(?{?HJ4=+CqJ8%;{72>@Cv0uk3oGj&2ij%vrhDewmjjSPTi4F zaXL`Gs{ZeGMmU)lm>y>wr`eP_GM!vMVr`Iy5sC%d*KP}xVQM)S80@aEW(Ck<9smiI zWgzm%YdIS^ z7yrnhOx6z`Dz){EtWQY;uD#aZ65F~XE6e3fO)nZ2i%xgLQkMq`GJS+-V9Jnig)%O zaswf%CbXrl7VmQd%^53r7s?j$q-*Xe_yY|mGtdsV2Y3<=2(6xc_p~oNsgQ5b#r7lC zcTqROt1E}rM?=*y`qk@2eDP&Jp($zLMR8#Ps>76hAZ3r_4QJmIGd#PyHZ3-X1%x* zx8@pE>O{aaz1i%aS-H`KKaMVn7Dgwl3bPeh$^_5-NT1D4G^@S{-LP^#yk+6ajDvj* z9gnUa#Q;a&dbK>zl9y4ieTy+xiJT}(enw&zgag=kk(3CKcFw5~4R`sFl&(6MB8K=6 z?bmsB^$$=F#a~1MQjWMqtUF}QZ8HQi*c^C$Gzok%1RTYz#ADb^tqdLI7FY373M-;n zpY!G|iFSgbiw86CFOGZ^<&4fH6_MRw`h}0&KA0SXW}*8*fewXb z6z%M)M7`(K`zV%cAoh^SdG0azOl`l(4N!$K=K5h6Ixb$HaQCz~NY(vm3aYE?)j|g0 zV-LwBPz>-ML(FKNCqC4`aZQIH(yk;~Vl1aLB%brS$e6&cU|(uNglOapJeA51|6G1R z&OYMW#x8KI4PK8pKbkjrk0+JkHF;$6h~x7YgWGSwBuQu(>h?Xo;HxZE^_Wv!41jpE zqdPLsR!7(6hI2e&KIqnA@`Rc1fIyPR>Nw3g=Ea`OkLjkp9VgZ@0k6bP%>4(0Ed2`; z4O)d~tEhG&8t?tUu7UJ}(;Hm;Wz+`L9_DLrZ-HF!^y*2i&w^g%^g3|bo4hK>o^5fy#Gyff#V+utFQm0b{($cVAL)1$8e}OG&I`SaIWaJhc zA9S8Y!sE%#R)a(DnHtCF`C4g>oRsiUGXidX>3E*>2Lt=}gIxwae_K2B^w^h7#Q(lP z-a$c=Yqi_$EqTxvdjPS9XI~Uzk~>9?@p?_P^a}T5B}{E$`iYsH+in|)NLI6qlx=<1 zYs`VF@<)D)Dnqj1pP~rvc%|^6YW5RHkHXBF26LX(xs}|P)bdi&8M_d{%DkB>%Wjl( zmXEbG>9&X4DJB{7z2o-pM#`1>>|N3v7Mc5h?JTy#nI*`-gagDYj~oAagWIlHD#_j= zh#n>;ml){iaP?C2kLXU;L5E_d8vv#Ta(_QqD}--Y)X?n>VSnh;-z-ged^}wko$UDD zsvPg0Pv~1b=lwyw(|;-#Px^_1jI0|Q#e6AB3-`CH`A43PO`1c%t47Hy zaWBVDFv3wH>@A-auOz7CcvZk`UYHtQQ!>=5z~=~{R2}74`|(E{zK6JXet8~+{GEYd zM2@`Qj{7)Kzj0qlT2-#TB~xm?#Tn%khtDYbd=pM6K#sU7L~oTpA~|S8YLcrsR@6U^ zK|4F{hoecb#Ia&`Rbb*-aZYk=gpl}zUuzRAijQlol-)j4HyBJAoyL7BZS2K?99lsQFLN+8ea20F;uygXtDCvAod0 zl-=lo&JS%xGWe zu}X@LH0B(I|7DUZiWx<%M1L)_!}$%MjRP1*{G`|AVM?4b$n08W>6;~g4J^*xiJ@Fk zY4LVEu`~%p7eF?QN$^YQyI6B`HxqUP8GCtyUs@Tb zyI_W|TkJk79#e%Z31b`lsz?geFsTaJLaY+Eg8d_vy4Rhbkh}3vFO9CMi9P~hnlfoN z@wIX`>q?u8RGvtAv26-sTT-{pOT-YRUx1@s8(vDU^UwsxeDxnSGQn$6eJC4Wft&Zq8hn)o2_#XxgoTKLhx_3qZZOXd+okv})@A_pJR zfm?(&mY~pP7o#my+;C@0>YM=4XSL2QbpLqPPa*gMaKYy|rol^Y@b43=TV%~wI03?)v z`{*|C*woUF$0h|9UxBy_XD^ALVn#qihXjvdi0t4Efd&BoQ$4Fb`Kj7JvODm@JT67EXsgsKTKq_}nE$kZ~eq)w>}MrtRj>mb62JRPKE;}oZ> zy=&ZpL3+E%N)I1Php#~+6v`}c8{O!*{L?Dscqo zwd&0{!<)VjFBsP*AL(nG`$hA--e1LtxkT}&tnV+L!1Yi>(vLU!ZS;UjZ#vm#Q6C!O zArZ2ze`U%5g*CNkvU5ShkkE{UEtcvX4`-Wq4NPSmSsaAGPPiyz{`ZEAu7il#oMr!&BEsS=YP0m$1q4RAxnkN**PwO3LW zB%q(mY2zn5rI4)~^D%R(=xIV|kNo*uyCb?3G-Tfb57|b+xzWZ3utmq?%%({frWjjV z&Lk7(*KY0Y;n1IyVmmj7Y&HmGVAtL8tqH^2}5D zYAe3V%ZyZcSEAg64E-vl#rM@|Qq3T%heZTQP3DoZ;cT_hWPe|K%~yZs22;Y7cL6a5 zqcvOSkv0MqzGdf0ip&n{PV1=!Eh~T?pjI@&1_bDv!ajX&D*es5zZ=!RaTxMa5@C`Q z!}R0IW|;mwHI~WyCn3Ae_dq7~T8EXltwj^6VgxmH#tHa-uD5eB);*34DN#<#-YJnv z7T%BYISXlBGs&JX*R4aDcNn+8_Rb^VFLinYR;T*kgPp0g=-UpS%F^=KW}~cdR(D4H zK>piW!oYO&R~#hhU`LP!EEWHQ=A%sG4AUW4qoH5D4T_A#&VZ^n`b}tB-(LNN z0;b%`6Km#%pGEZIad(-c{<3oWU75dUmR$LQaVoQ21V)OSoXDJ}hCL^i1o#MQIXnv4 zU=!G=FMoU(m{`#ibR*(&yhG`~eT=*Y{^0~S@R5V3ynfhx4oQ!uub~zxZ3oPDl6!rZ z>jfL$)H>Y)jM#-AAQ|Lrzg(sUDVX9K8nxLv)Tw_bDUn7;D^*$|$IP`(lQCfxwX3r= zxL20YFii;@sVm&oWhSUK)k!w?G>ZLmp)G#SM- zs`P#ZRgfleOIH8qPhM9ZOgk#?NROgzY8q`Fh*+d*P*KA*Oy~I&>gqG(1NV zShzh81&{26PIdsw;*94S+b48flc~X@{1NB$j)&vVC#93))22Izy zvcN1}F;JKQQKt;dEI9*pt0loEouhT|S`RGm{5om>f=q2zJZ##uvAg|~Ip!aqg;T1- z=@)^NG>+xZxG4$$CNl3^Fp;Y>^J!x${b`3hFDJsQ19@@>zh=_y$3Dj!bEnZ{&}mXA z6~5}g^x3EC9|hQDKf9LhFlYaCg+-HSS}oGD1kVoTVr3@ER7q0M8me`auvcuXJ+F=4 zu0UhWiTYRZFcdKU?ciW0nq{-u7^2zIcin4K=Nu+91w?r+zgrDEGjshD!mypJtF$GeFteIpE_2z9lQ=74cChsk1`x5 zNMEVNS1@_tP_dWH0^W05L|lvW)wqVo8i`tmDTMth&+&IDz!s!xmIIJcMv7+yLy(S^ z-=nHVL=s|4eR>qQ2;!s71D6;@*!8%qQyA!&$UpIMk3lQ!4JY858!WU%R*gQrX3xu> zjFC(+rxOO6yyTY!17Ec=1cHtm7t+Jwl0d)?qmjG-B8b%GSjG$PDc2>oH=Kq5tPx!8 z%R3?vFRbq_Jh%s5d03ZXIinlQyh?sVBFYag^CZr}i1eSgmv3_w15A#E;E>6L;S3Ao zn~*TkM38v;Bj5Iu3pMw64cJM#ztOe3XJTaEk_Flt$45>N74|=W=1X?n2;#3a@6M6? zx&}UcM`_7Ye|moPa5U8&S^O6!N>RK4%qDa|%{g}~FJMp#f2ooSdtli1mH+cg;wCrF z#Cm<@B559+Fs$Pth2$mGQYn9xPhb7no9G3@AS`mFdoH_}xN?x!%0qo2jZ4YE-}L2a z0iYddag~d5dEVnllC7vGcM=t$IJwBa&+BeO2oa|D);K|K`iviN zsLUUjtGYm1i4IXoh>Kx$Qd}X>$K}SF^}OI5XVPOLrd6WY#w)eHugNVO7~2G(K_7qZ z7e|52=YU3pDQx(iO5wBXM*4ODFSL96@uP>z=q5;P4fLOgNS%ge3%`bTeiP0eAcdg*Vt+PnM9cWZTTzgrz;S zG-xqy(K(Iqe)QYGCUW+hEm_P5;CnlW+myd}`VR)u2|@O%v9&E(D*#vVg=briu&D9e zT!{JAO)e^Zv8#Wl)R&lkUzD&levdXJbzm5O;x!a-VsRKkBs~FF4}7!yLHj>l;EIZ} zzp5*Bf8wbl9hO+vCkjl|1b6S{b09lFqOGg5{l`=fcnIYRcyq>W)27wh(rZl5pdcDm zZ<1Aa{#93B3kaLd)E+C zvs`3vJ}>-nzVSS?x`{fBe{z9)+>kP$nV$YBn>B`%EHL7GukSd`K(w&tf>qvsiK(r@ zr2@{nPQSWAOhkZ(|21sxaTv0mlNA^MxI;Iu((g$RpMaSQ!rPRh_tN#tbWy}>Hk(@W zioe)Bs94-bWfp*j;NliX6@|vm!Mx=p%Q-qO0aV?nG|8$C$CQZUhf|dnrF$m30=;BV zxS^M11dP5nHi0EJ+NXn%G@Z9Fg9(I8vEWykc3Ku?yP@(8lnXJ~X^;-CM111*b!I&w ze(J$dz%o3@u_$iR>7{yMppJpU`^&r7RZ)VDjPDs+Wbf!>gxwca-ZZFe8-~m6Ml_Ki zHJ9}0#k(T+{BM;6p0K4f&Bcfk%XN_~S-Ae2U{X}V%`XHEr(}VVlwmM8cPWT4x`D|~G1D1Ix_I-Z7TF~zBx42MJ1CwB$da^|>Ugmn*3>cXD z@Wbi*^-n%AZnKaK5k*Q0Z#Obb?b&o&zjpin{S#tYnaF$(-p%W zYsV93&(r;FuzeyxM(}=f(nFm&(RHk#g1K&{KJ6R1A$M$I!f8R9#q4axtleQ1THhb% zGCns6K?HvAeKM`WD-Cak!~&k^cA+dI3N2HbQ!i_8!y-;*XPi&Jf)#R&wLB&7=T+_@ z8IL^}F90yV15NC|ESvi`lRwRYyCv``Ras;AkY}$C>%ldu_i4!3EcbxWtE(rHqJ{+8B!TuBVP@82Ez@}8foOp?-opBm#b)MZlk ze9~)zMZ%C!oJc~?V$-d}<_D8uOVXCI%zTDlu@B0hS9DL3Y?Gs))3#g4b8f<$=x0rU z(Ocr=1X7*)bOjkQ&Knin^yEh-jUAgs*&54pfUr`q+IF9|l2w{+P^)V==Nq<>6(0@l zRqz=L%caZyjId~DnSV2}Q14e`-S90NYn<$7ENWM%cn8TXv>K?t_8^(SagoNQDZVq>c zpLrNRTHU@=(&G(9hZZk$b@@t6Do)P+d6D@oo;UI@4R9ERLj3EFE3@Z-M&ZwUS{dzso2 zz^GAbRioN74PN`T2Z1ich6C~4R*m_10BfoS?(s@ec0o|i*mLn1_ULzxj;8r_klFgz z6&(8wIIXh}ZWfJ$3o0uR@a>+w{TRIBP|A$Lrd;b|%@VEc-w}Rb#)&VAVdopW~JvbV)* z3Y+P=VVlv>8J-B`7;V=Gk3UsYu4Kj$i)3MmtfLR$R}nqQ#|;(xaZn-1&A%Imj-9_P z6jceoN`i+@!2ca^3$MJ{6iOHs5aj3^Qk3M-hg}4BKnM*fs&gE`FQQszk&@dQpY|`hvY<5pmkW+VWEW{dsQu`1*IseR`1k z##LsZ&yTLnx@YA~cUKvaZ4W=hKHjA`yw7~(>4<*}l1>+N{d3&CYRXbVYARbyBD?z$AMf%(jX`Ohopu*_2LEz-rYQAj20OPuiED&)g zqv>%^&UtZ%QvLI*P**RGKQn)has6Z#*U2sd_ggfJ1b9{ET&CkS@bBgtOC69^PL!|G zE6PuYk=a*M*#B_u+vQfc$GQ~n+!50v`?4rzo@FhWt%d4_oRqL6m&B>c#du)15rrAQ zQ&0S&2kjCkvIZ>MNr5jX>vty_NpjP#dqFg0Bmeik&V}s+=wYIH6_>@905JN4u51>`*?Z_QZd(M~(0fa2BHa^hj&; z&rtqng{TqO5CUMm+Y}NX>iDaR5C6a$h)N&(B(VXJs4~HsP0Da9t#KW2h6>{d|5`q7 z$o~qYFUTM44(9`cPs+Fhma>acdqaHG?%~ba$bL@nx}npkx1)f^O$a>Hj+jaP8U9Ls zr8Xaa;OODtrZzmDX1x`M!D)PTW<(8;$PO)z9^DM__&5s>M&fQ=$QnM&Nc{!Fau^{*(vlu z8$59_NeegfV}*kQ!A$>wKDc#w Gxc>p3YU_Xi delta 11295 zcmXY%rKLeinjr*9>F$#59AM@-zUQ2O z;ND;M@7`-&Yjv8!Op@$?g(Nf$Y45=46(}5n5*WgKPogkl{Pz1;HVQsIzB_)%RhVmy znKG`VsQD4M{x{E&C%I__eSI%++6F*hUjtEzA6+E%ZhO;HkkU!+=ANKJSn{<2h%__6 zmz;)I(DsPwb<~v-9>AdBGr_h`6mdf7OF_H;nHW+2BD;{5i-8X?+j(<)fYuTI9Ua%L zI)v1_Ck7fAQnLI&V;0s=d@s>Ri2l*pwL@{Id+wzuYLBc$zSifv((TN_iB2j^f(zQb z9A;=G(Ipt}>Po*DgEY7YXz0%}gNc&K6Bhu^F8KO#bWdh4)d8-ShEN z5}v0+zJsi4zDtW1{)q&)g)44t(YNS4*K>r~AoB{x+QLjJR{eE*h!wXduMA1MmVo

IirTM(-0+<@Y>qjwc9=}p;_WNXq!f>T6<=O!G3NVO0vob0Gm=(MnC1z+&(g{g zdZAZ!@qaukh-1w&bI;RViG+#j=gfU0&BalbwlDVCA6RpOiC;-Wh&*<;6p%iaFn!$a z&1u3JqRJU@Phf;-7w0%k%;f!@=)O%E4H4FX)dKjQgcecj(FlinK3rvGDk=rCUl1x} z9hm&SnqK^*AZC$c_%j+>u1T80Hkin9FzaVm_cWqF0~h$3+cjIFR_`ja*>JEW{P&NB z0)B(2pdeUFPLpI-uzHQXOQFf}v@F}XYUvT>KAvm@#dQ5{<0~4Xz|s5xBVQ$4F3QFV zbzotz>hUBx{hPsR{ywtFT|-Qv2B`~MQTDsOQEjX#W%0Jr0|&RC;RYFev!Z@w;fSAb7( z6H8aOk!Gm&-ge+Sf9850DrOrRA-2n*O1Tv?^7qSSY|GH9+j5_=7ORRR3xX%4zk1CX zZSA)2Nr)kBSQsG`iEwm=Cni2m;@5{-R!AGM*FmB|-j>#+8?nFIGDDLS`(IG)pbCqS z1(q(WrFxwN5eRp_S7v*l`f|j%as(XS>UyYOYS@;_T_qZL1xyZKd-!&@{GEwZdlx_+ zzOfZYTR75;bN0NTT&^eCHWXVws7Auyl~msFTU`WWhU^HR7xs{}$O8C)@zZd>206hh z6aiFeG({lX#3vgy!Ffd(a&8Z4Jp-~QUg-8)%r+94UT?J>kA$wf)KC|oUgar&l<;deJVb_~XIt@dLc{ z>S(mhOk>v&d}tz=cv02!6M*!SKLw}5+Eb6NmVGj=AXtOat1SZ&1BaI879)oN>=CiG zzTrnBIU~~}ReS@2HYk@9_!k{d?k7clJ1*lrSVzkInizajlPro)Bhe#yny**3`rRh- z5d+^_D0I6p!G@1^Mz@sC#_0M|x@O7xM z{Ni)p*q6WMNUa~Mebz=5k3J84m+nYL*3jM-#VFDXG>s;reV=$4fYqkV5wO$vtTM8J z<$%3`n{6dq$3d8anFqmeqj)HUhw`foj!GE|@XFcabX6V7i8k{RjM=YJK?x zNYc{!?193nz|#|*hL|p|UtSnGV=I#H@3VUrX&-9-Pp&8q3@ufa(g`>r-|CM97VRN_ z?XhIe{`|sO?dVnOL9C-<-xHiGOf5t+rN?MieSM?LicXx)R8D@zNc2eQL%t;~=SfMQ z``p-6Bw8UK3ojORHM>OD1}+o9bDN}-^&l60cOjQ;3B=G8$edA8anEoZNA_(h9ie$# z7}O=_p#7bgxO;_#oR*(|?A_bkPu%xOTj`17+b+&>e*li{TWOmQSONX<(-N8=kb3>> zOzfO>X%;6E4)3-N-y%Mu#aE7OE8P<30QienJD&K|9caQ4YAEa&ID-!goM;(VHarDK zJ%&b{EWp<4{edLRNg4h;u`}I8gu%~-tqKW&`o+D(O�+%#b|OqBTi6=l1QJ z5(~nP;vgoSWBQ-^DK|E7qz#&>;84LibR_&M)aUrB_*B3dcT$b(^T+-QLB?Z zdIDQtd@cF!$d9pKf8qA=gstGmhQ3s5&L}_oMnT7w^vY=8_T^)p+h7+Fu`HYC#@o&% z0;zUjA=YaGQ!!t?GpbT=osvqwfZPqU6sF<#_5I10IFqr=Fs8LpQyB9r`z~?|yB`WW zw|*b})0e$Hs@{7ocTpxPl`K6(6CH;cehB@$oR{8x`9#$*TxQLPqkZ|{^)^o3pBV{O zF0`r}7FXPbOMhj>8A?tw*7yO%_i0oQTjTW#K$7zGQGq1Lh?H>jfi*vu|DLnpGgr;x zR^+m)lz;TlPS|ahVyS=NyDx@W63qBN7Z_ z2fuaE)SxkrF&6A_Bd=3V>bkP}^l3nwKFzy5TP{T~!Sq=RTSXpY$>LAj_-nwxFgQTUY|E5k$y~J*`hdzAOuP;loi0(uq7dv{K@+Kv)l`Ame+^ zdmQ<#@OV3NVk}kOYG)XutC6Wy_5*6`o3(i9! z8`p;k3vr4?Pm8f(?4k)zE%7%`SC-@4TNOAMVVtsaICpBrp?p8Qd?(sy8N$IF>p&<8 z40xx4nE$NQr}7(gNsCVaSi^59+ixD>q8}gAlY>eFgZn%<<@Z9qXGvf`kuEIvjKszd z&o?!TDX#ec$ut}u;KSFvBO@`cm9g%OTaeIdBu{VEgb8>!rAlv zkqB$(BG_UIYiXQZrI!LRt~8t;SG`)*cjv9Fz~_~GH~qr(448BRl8N1`+sAnNezFfH z1Fl4;DFw@gJKuPPG}xkjWBB=BMeVJ6q|^!UB!5qlkrddriMMzG6_}xfSya*eI%`tC zks^83-Q^|q;}oKT@}>;@T6`@<+%y6%s}6m(I$`r_v15Ab)1TH0f%=>fJc^2S`hf>e z+m>!xJUqd{;K&K^`;MG$T*|@%w81cHV|4tQ3dQt_I=t5?oYI=l0E2>q0zO<`?g~YEr|kCUB7OP?{?)L zr@W5jZ~FzSrn+Ar1?RN9)?DxX@%pGsQO~kMyHX~|;!Fs5`%s@PL^$<3#+-VRZQ%L> zt$fQ*411s0{SRK}2tgN)sbNBADrOEzRF197Ib+E2^Q2t*=f)Ju@~X0RyUYbFZ-u@u z=|P5aY%rG+2P0YN)pwtJ9(9$0L)X6SZcoq1X`7x2$MO0WY1q`g5F<=MdefI>v;Faf z_)B-bWL!28puuy&*;w^9R-F0eB@ z(L3GO09X^l@^1+N)#IaiQ9XRts_Ric^SPkeB<>-r-uxOUFXj?bko++dwr6SyCgIli z?kH(;`V_)dJDV3vygc9twNSqb?c>#wj%3bzb3fWbhc8|B&-&tE}|Q-R+enfrY%;rqFnOjL0trG+~N9s zXAWAYw@-Pwizf=w&Wft4q4^rg^q(f1D(Ih4We}s)S=(w?SBZYwG$&h#liDCp+qwd8 zW%3nn!Mbd5P^;AZNr|)M3tWn)MZg3Qh)x*r_Rx)e$F@Hb&c(9ymalgT+zi+|s%Oan zA+ac&8{np%e(EiF(b51m>sY8iWq6IRGUs6TVC@Vwh-sW^k!WT&F5j!35nAWXn~T#s zN&dc4D`f6_@{4H>68+Vnt4)MgCsj%?grH-+bEdz6a4I|iC!#O}Xj|dE2Y?3Hx{NQ$ zn^lOVTb}*oM`lJk%ODM5G91FDry2i@i`-E=U(Um?pyTdr$}L;s5cS2q^&ckK_|N6+ z?ai+gh}Q(*w5@*?K0ovbz8blK zYM?Hg(!ZUVQLInn{le5IK=0j3c5fG}h&W9Aakuc*SNNhZ{Uyv@p+nm_nHmaM9$vI zz7QIS)Z9qdoDapjJbVSn-tRkES=|d$1e)8(zH){JeHB|MS^w<2T1h{6zB8ZW(<}nE zi06eC{d?j}%kGT(`$G+-p%JO(B70w7_?|_Qxnt8z8koKo#gzo6PF@HyfNV=GSD^dkL_u62?lcK9JfDLTCgp0vic z4ij|~brNfsZplXj76W~Md9^M@4jfC3gb#66bGSyca;8^rai{Bow|&uJsX$K=K#HGS zH$XX_X$L(scrNN9nyxdlg7we$M*YFahjU54Abe=BUIE%o= zlN_#bX5fqMQ)0sS#7X-(KH=eOSTKEYm&hArFmc8f0WAUkfjNVb{8M2p!3 zu5sl%$zf-m(ObGay?KQ6+#>EVVNBIe4@J@i7Ev}~mXVz$`o|^o2DkaL%k7gSU8Ecv zpg3H`{?@*)+tK+6|nMjL7b1!)_z@ri&yb>%g`@ z(6YT{W3~}Ie$D)P!7}sVsUc&|RiQch;pm9Zt$8V^##to4sfLx=ITc09c?;qV|ZZ$*m*rub$e7T+& zNrxtN11D(r2P4q~*w(>3&pXgym|!Db1?WYE%ko(K=yiQ6bhgUzmwL7q)V7_bg-2*_ zI;dTMsa7p^wy{4!RrMACEjPKcPt>wkzfV*OHX4?$+M$+(%1~X;rHM07Z0ZOM%he5h z$Sa}iPLHFTAbOZqSXkSdC0cds3Pzvo`q&$ck?6E9+f@*udkDdP#_I{;>TppKnRCbb zfmelBu*T*_@h)M=SMte9j94#aCrF1_D zp3o#X7r3YIR2X?5&BQ5yk6h$4#lZ4{gqbJtuQDbCvg+2`tsjdV;FO}V7Ko5(G(oHO z(?8Wz*O($OW*S1I9k9mzu}dMJ1tvei-frOZ%Jw2*Kj179!&YtBZz%WyT>MWP)xA#FJ%gK z?c5~voirk$@J9Y%8&Y~z<&f6<3t`M5FcF0_Z zVf;J6HfO(zPs1~lvM;4`MAh#0^;x|b<153my=n?r_K=AXgVU!q(kb+`x`n{ZQ>j4 z@ip?!7bF!%!+jp`275^jlPTwmhUlP$T!y4M_`fcqFfMdM2~K;Yh4pBN>wKf*RqLr* zaI^_J1asSdf_XU|Z1LYi3r3+GBo`oaI(P>73Lad8)oJ9Z;Jl4%>=B#pO{>lq%xlRR zu@c{(F!hRn?|kDMK;n{yBz#f zG+lXWUH=M99D%EheM2)SaHy#z>(T@YykX+Zv4D7Cz2&c|cO(TaMwqw#fG78>Az*f> zNM@{2k|q1pnDrYqqBd=trIzFz^p(tFy#p^kkc0E8<-OpnPS-u;w2RsALeW6HHm=y? zs~&ee8f?h4r78 zAw_&XhJ<7EbqcFd(=n5o&R-VlnE3_n-=8{~9~>3vpn< zu?oH5=e!{)JG2FD1c3|l5XeX4^R%w$$M*nQ>96IOc2$re57%P`g0+<_F|BY;rvSOx z`!^P0&w}St*uY5r`t+A&69@s#2jE@bAH=k#${_e|xLE|X9KH5jL{JpLbS_*F zRjH@m-i_BR4-l2g$^+If=gYTJUIaV|X-Mxf97nR0F@tV)I4|nK;wvfqCP#8`TD80f zoE??^;Jr-ll*IdIO0nQr*vnat(VUr;u{xHNU2|L3CW$xcP`F@ppgKEBp6k8Qr`T)} zYxYk#g#iGU`WeT;LUG{O;v@q@2K;{Nc5+l+}0sxEfIqh~DUQZi&Z~m|d z4qZz^ux1XQj$-`3Bu9P0X@@m_$NwgRtzhE&zf?id8rYbkXu))L<+`6VO;(8rJoc(! z<5slT!r<5;{}IotNKjSY%1Rx}ca%~3iklqV~?77l$uiu9%` zPiHmk-phF(1w_t$u79RhEktChp<+9Yk;7j$$3Mq>*{vG=g!_|9?4Z(}ZtvBB1P2yv z?EkYO7LCfNyAwv%!-qfN42*4Vuspjxu-aKh;orWp!w?z5v_7yrQx4Nr@M={0pntkb zh`rpsD(UD|S4`X&2E@pjiX;0bKxQ;$i>6!v!0&uBufbeR32@wCIIa#nx4L#=lQRP$j~U)+?q>@}=_HI~lYa|9_uds#3w?59#we3UB!1RC11p(ariT9UUm=*~ z*flY2%WeN*pOWFy22-`g@40PaMk%6CcRv+U>1cU*)f>YGQmqI2Y^cfqaCj5lQQs?2 z_?02`e<>-wJa(7GB^#vW@~r;?Ul6gijKL}(P6cS$02e2kWP+B@*376=+%AmcZntGY zxjdqv5D}_Q8JP3^6inSdefsww1c2kZ@X|{~;nEv&Pv3M}pV{Dy#P%=j{D|M*m*1h3 zF~Zl+jnpo{vh9EOcw`c^nO@a|pY5py-QvC(muou-v%mZ_Z{IT76+208TE8P@Du8E) z#3^nD(m0hrNtv*L%N%|xrAIkHVgGdIO*B@1;{{va-)(|_{9cJ{y2df~&_@LD@d&y_ zY?1f#ibV7#p$NFkuWF$2neyx+*E)@IOnUqL%r!%}v7<^efLc?x>)NSdbT5$YQ>*F7 z(HgWi@KXorsDV|;Rh~%8<(!ntiOGPJVkFA4<)ORI^2 zpkpi)ObUde9oE$0f59bSqw+nzwA+A((B^~lMRDwU>d4Niw)D)DKY3pcKUO#zk0SkS zvep(}GVxa6$gduYHBBv`7XpO5WETX2UbQd=fllk^uYX5M0D(J97P9=PAX=wW84vhZ zr7p1zK7$Hs;u?F_4Y>q6LU>orXeS)yD7QXHrb5*$k}lcfmG50=h}V!HvbO_u+fp(2 zEpv`Y*u3wN>IWbnvB;h~KQoIWNQ@GACy8tuH|f0<|9#?AMN#KhDB$6kk-R(|{par1 zig~>Y9#&!5b(=qU3IwW$oBm-9LeK`@IIQ>SxPy>{sWU0Z)c+Jb>_rFI6-ArK5xBHo zXPih2fHuBys141>6*uVY(g`3pqF6zyghHoGSY4kOpizMKl5Sf6Jo5~29C&{*l4+*v z#ey@HZea)wz5y^VPE4N{LZGeK%t;kh^4iqxA-w@uc$c@4uRooj^eX6*fU+;O7Dj4{ zREEB!I2H;%7O7`ntjdH1hg5r7D$i?KUi9v{^K;0Tx$=1VELQSDS-u-&^2_;nqE2p9 za$|Ypo*w z`iYr3wNIeqPKfnsXV^(Xb^zOX-+ujZ!l4wMfMwr9snM>RV^Vv5{cHR)j+%W@IqvB! zN%OYS(E_n9V)EKH+^)ca5uPNv$A+h8mvv@s`^aqqNQUx!&vdSp3Mm%yMlogPKJE|U z(fbV?2BHG*({isY!={y8aHNyrZWZ6J!D&Ya(5<96(VGY!C}mX}#_4_kC*TcTwX~In z@>k*jnG*{%OMe~p^*x=N{`bALDNIFMSP<=>^0RU{;n&np!}1Za#apNGO_jwTKxGhv996?7ThcZF zfjpdhTZXu}@zhd~<<<3Fc+!-}D+^kge(Pgo>*jbfZkg%z4`?4J5p+2**%#gDk5FN8 zTDCK=&-xDGz{zs(5^f6#cD6*d?mlRmHWGD@uj~s3k9MYqPIhO<0x=L;>kgX&9&Rs2 zB6~aW*02dF+ho#qx8j2mb1T9gAoGB_A!1gDMF`8Yldu!My{Od;{WD(6qxt$9+o7m9 zL*jyYy|^LU6>Ocmc05e{Ums(HcO?H=-Dn*)zW0IYmj>Z`XBpXR2`v&HvnR?n+yT>D zdd(`o3R+a5+3!n&?Xh$o=U=Ea+jInXQm1q7^8QF6Zf=O@9+=R zq&p4N{DAe~8=6L%>Lt`(cmV|_brBpl0wxQeUj73~hl60Ou@y1qkIonj(kPSH?1Jsu z)eCQ6?IV{I+66~0vI@l0+CVOs!G5#i@WSZax`_rgXQ4LRyQZ=rrn<_Qa*of|q=iPr z4%N1Tm4e^&DfC>8oMfz=u+?Yp4Up8YkzAAq)8oi_KLnT@46d}C+n>nR5B&AOAeu~G zGu|N2#0|#_itBsniszMDlOUvy`Ry_S@1KyY7_$6S7eyPozPe)84~WSL7b=U4=a);3 z6@;F!WFfnx;66rhU)IDU&We7G+xF%9MD{pdV3Qa>cY8O}W6dS6Vp(|UIUV(ws>aFy zG?qW^SlQ|-kcExa)9O+Okm{06no&%f1-^{)%7O*kpZ4YKW~|%6qILO=^@gWC+FL{&vs9FS?x8%bf;o|wqiB<0ew*ad!Qf%N zvZ3k{^>Hq8^r`8aj}mt?s&~+AST{Bt0A_X`6Z`7s4nPx*!!O=F z%pF0z_^0HKgoxM55G=ty2sOlz0^?}~E2&*ku0c(NngJKD=Nr&iC zDmMVMRig68(W}>?3L+Qec9F%EZDRDqdpAwF??~LlhTxy4+t4?goyn=_z~`HDZ{;hf zq+p#nNhqSvk-d`UDP)F6Y~+7j^shKi9qf3Tu3{nJb+mu z2Fr7y=1u~qC)txhN1#}9_77rNwVVfZ>OjwyBtDJfXfe|JBK+JCL;vyBq$uB&%kO?8 zm&en09`A9+hWpv|MT89_7b~#Z&^&~2r-cfH-`0E?3t-7u8n7iuWt z;pWgZBBh8~l16xv@UWe@Offn9DOGaXB>i@oa^=vnYqukQv+V? zZ~HbgGASS{cX$d>+9~`X?b-2Zuj35WCV|dn0*XkhHC1l}z_7LF#o^#&xrx zdaVqUx^~T9mL8!IqsFxKkqA1I!zU?fFBsH>qx}vXG-KBg3mNp~_h*-UCIa3(^x;x3 zJ_E)v!r5hm2f{WM!@H!QpnI?cw6){)-BAsPmwotg&gpRiRiyI4f0;d}G_V0p6{hFp z_uW8aLUq~b5q)7tg$>PpOa6_1C6`!PfAA~$ppSWW8u)KK`XwN#G5{tDx-1QW2CAkA zy36osgm_5tuN^X4dW9c{Eg^&Z#bL2dkCjBL>dJ{cGwgO8e2_=907&B#{hEOTV z!z$+-Em1`rQpS*3~|`c5Z|y9&2faGY8g zfYf4SNKw>Nz6 zXAU_dTX_`Mky`Cty8Pbc2*DJmEygz>U$L77?;hmV5}HIX0_R~T#O0%LQ;iVMBHiN$ z$0gk+6qZ|NnA+^j?RFT+$q>nD`o~7C*%pOn9goM@M3iH!$?v9nO@=-jdi3q(F~uDJ zvYA3NId1gLFZ$C(^s~VZ_~=^^ zAVKP#l*Y*^P@Q&r3|>Uma~?t8k(8(51*fFreRH#0uUvYu1K8nd;H)k#L~7h={{mAT zdl9t>QSURrg7iz&mMMs_(;!~S^6eo-8|-?-aW5#>y+&HpHodP|RwD?*JIg#p?eH*bk+s|)l4NYd0FRnb zxLvNWta5~Ik}fqzy5)uS@CniyU?;gsVhAM7Iy-Afp!nBt7LTFLP><;S5U>yPgKs_; zB2QuijL4hwLA?bx9WXDg2+%@sR_{ALbYo{FQPVydGbDb#8