From 4310da805f7f4b9ec9daf691c60cf8489d92a5a5 Mon Sep 17 00:00:00 2001 From: "Joshua M. Boniface" Date: Wed, 29 Dec 2021 22:31:01 -0500 Subject: [PATCH] Initial commit of PVC Bootstrap system Adds the PVC Bootstrap system, which allows the automated deployment of one or more PVC clusters. --- .gitignore | 3 + README.md | 67 ++ bootstrap-daemon/clusters.yaml.sample | 7 + bootstrap-daemon/pvcbootstrapd-worker.service | 16 + bootstrap-daemon/pvcbootstrapd-worker.sh | 40 + bootstrap-daemon/pvcbootstrapd.py | 24 + bootstrap-daemon/pvcbootstrapd.service | 16 + bootstrap-daemon/pvcbootstrapd.yaml.sample | 91 ++ bootstrap-daemon/pvcbootstrapd.yaml.template | 33 + bootstrap-daemon/pvcbootstrapd/Daemon.py | 242 ++++++ bootstrap-daemon/pvcbootstrapd/__init__.py | 0 .../pvcbootstrapd/dnsmasq-lease.py | 122 +++ bootstrap-daemon/pvcbootstrapd/flaskapi.py | 235 ++++++ .../pvcbootstrapd/lib/__init__.py | 0 bootstrap-daemon/pvcbootstrapd/lib/ansible.py | 63 ++ .../pvcbootstrapd/lib/dataclasses.py | 49 ++ bootstrap-daemon/pvcbootstrapd/lib/db.py | 219 +++++ bootstrap-daemon/pvcbootstrapd/lib/dnsmasq.py | 108 +++ bootstrap-daemon/pvcbootstrapd/lib/git.py | 166 ++++ bootstrap-daemon/pvcbootstrapd/lib/hooks.py | 267 ++++++ bootstrap-daemon/pvcbootstrapd/lib/host.py | 71 ++ .../pvcbootstrapd/lib/installer.py | 79 ++ bootstrap-daemon/pvcbootstrapd/lib/lib.py | 148 ++++ bootstrap-daemon/pvcbootstrapd/lib/redfish.py | 785 ++++++++++++++++++ bootstrap-daemon/pvcbootstrapd/lib/tftp.py | 45 + bootstrap-daemon/requirements.txt | 9 + docs/images/pvcbootstrapd-net.png | Bin 0 -> 35211 bytes docs/images/pvcbootstrapd-phy.png | Bin 0 -> 60710 bytes docs/swagger.html | 13 + docs/swagger.json | 191 +++++ gen-api-doc | 24 + install-pvcbootstrapd.sh | 211 +++++ 32 files changed, 3344 insertions(+) create mode 100644 .gitignore create mode 100644 README.md create mode 100644 bootstrap-daemon/clusters.yaml.sample create mode 100644 bootstrap-daemon/pvcbootstrapd-worker.service create mode 100755 bootstrap-daemon/pvcbootstrapd-worker.sh create mode 100755 bootstrap-daemon/pvcbootstrapd.py create mode 100644 bootstrap-daemon/pvcbootstrapd.service create mode 100644 bootstrap-daemon/pvcbootstrapd.yaml.sample create mode 100644 bootstrap-daemon/pvcbootstrapd.yaml.template create mode 100755 bootstrap-daemon/pvcbootstrapd/Daemon.py create mode 100644 bootstrap-daemon/pvcbootstrapd/__init__.py create mode 100755 bootstrap-daemon/pvcbootstrapd/dnsmasq-lease.py create mode 100755 bootstrap-daemon/pvcbootstrapd/flaskapi.py create mode 100644 bootstrap-daemon/pvcbootstrapd/lib/__init__.py create mode 100755 bootstrap-daemon/pvcbootstrapd/lib/ansible.py create mode 100755 bootstrap-daemon/pvcbootstrapd/lib/dataclasses.py create mode 100755 bootstrap-daemon/pvcbootstrapd/lib/db.py create mode 100755 bootstrap-daemon/pvcbootstrapd/lib/dnsmasq.py create mode 100755 bootstrap-daemon/pvcbootstrapd/lib/git.py create mode 100755 bootstrap-daemon/pvcbootstrapd/lib/hooks.py create mode 100755 bootstrap-daemon/pvcbootstrapd/lib/host.py create mode 100755 bootstrap-daemon/pvcbootstrapd/lib/installer.py create mode 100755 bootstrap-daemon/pvcbootstrapd/lib/lib.py create mode 100755 bootstrap-daemon/pvcbootstrapd/lib/redfish.py create mode 100755 bootstrap-daemon/pvcbootstrapd/lib/tftp.py create mode 100644 bootstrap-daemon/requirements.txt create mode 100644 docs/images/pvcbootstrapd-net.png create mode 100644 docs/images/pvcbootstrapd-phy.png create mode 100644 docs/swagger.html create mode 100644 docs/swagger.json create mode 100755 gen-api-doc create mode 100755 install-pvcbootstrapd.sh diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..9c923c3 --- /dev/null +++ b/.gitignore @@ -0,0 +1,3 @@ +*.pyc +*.tmp +*.swp diff --git a/README.md b/README.md new file mode 100644 index 0000000..b7fcb5f --- /dev/null +++ b/README.md @@ -0,0 +1,67 @@ +# PVC Bootstrap System + +The PVC bootstrap system provides a convenient way to deploy PVC clusters. Rather than manual node installation, this system provides a fully-automated deployment from node powering to cluster readiness, based on pre-configured values. It is useful if an administrator will deploy several PVC clusters or for repeated re-deployment for testing purposes. + +## Setup + +Setting up the PVC bootstrap system is fairly complicated and is mostly manual. This is due both to some requirements that cannot be satisfied by Debian packaging, and also to provide maximum flexibility to the administrator. However, some helper scripts are provided to automate some aspects, and the entire setup process is documented here. + +### Preparing to use the PVC Bootstrap system + +1. Prepare a Git repository to store cluster configurations. This can be done automatically with the `create-local-repo.sh` script in the [PVC Ansible](https://github.com/parallelvirtualcluster/pvc-ansible) repository. + +2. Create `group_vars` for each cluster you plan to bootstrap. Additionally, ensure you configure the `bootstrap.yml` file for each cluster with the relevant details of the hardware you will be using. This step can be repeated for each cluster in the future as new clusters are required, and the system will automatically pull changes to the local PVC repository once configured. + +### Preparing a PVC Bootstrap host + +1. The recommended OS for a PVC Bootstrap host is Debian GNU/Linux or a similar derivative. In terms of hardware, a small single-board computer like a Raspberry Pi or small desktop will work, as the host does not require significant CPU, memory, or disk resources. + +2. Install the required dependencies for the following steps: python3, python3-pip, and Ansible. + +3. Set up the network as detailed in the "Networking for Bootstrap" section. + +4. Create a working directory for `pvcbootstrapd`, usually `/srv/tftp` or something similar. + +5. Clone this repository under the working directory. + +6. Run the `./install-pvcbootstrapd.sh` script from the root of the repository to install the required systemd units and template configuration files. It will prompt for several configuration parameters. + +### Running the PVC Bootstrap daemon + +1. Edit the `/etc/pvc/pvcbootstrapd.yaml` configuration file to suit your needs. + +2. Start the `pvcbootstrapd.service` and `pvcbootstrapd-worker.service` units. + +3. Observe the logs for each service. + +### Networking for Bootstrap + +When using the pvcbootstrapd system, a dedicated network is required to provide bootstrap DHCP and TFTP to the cluster. This network can either have a dedicated, upstream router that does not provide DHCP, or the network can be routed with network address translation (NAT) through the bootstrap host. + +In bootstrap mode (as opposed to manual install mode), new nodes are configured with their interfaces as follows: + + * BMC: bootstrap + * Interface 1 (first among all LOM ports): bootstrap + * Interface 2+ (all other ports): LACP (802.3ad) bond0 + +The Bootstrap interfaces do DHCP from the bootstrap host, and are thus responsible for autoconfiguration. The remaining interfaces, in an LACP bond, are used to underlay the various standard PVC networks. + +Care must therefore be taken to ensure that the BMC and *first* lan-on-motherboard interface are connected as vLAN access ports in the bootstrap network, and that the remaining ports have some connectivity along the various configured PVC networks, before proceeding. + +Consider the following diagram for reference: + +![Per-Node Physical Connections](/docs/images/pvcbootstrapd-phy.png) + +![Overall Network Topology](/docs/images/pvcbootstrapd-net.png) + +### Deploying a Cluster + +1. Ensure the cluster configuration is committed to the repository, including the BMC MAC addresses, default IPMI credentials, and all other cluster configurations. + +2. Connect the network ports as outlined above. + +3. Connect power to the servers, but do not power on. + +4. Wait for the cluster bootstrapping to complete. + +5. Power off the servers and put them into production. diff --git a/bootstrap-daemon/clusters.yaml.sample b/bootstrap-daemon/clusters.yaml.sample new file mode 100644 index 0000000..73fd85a --- /dev/null +++ b/bootstrap-daemon/clusters.yaml.sample @@ -0,0 +1,7 @@ +--- +# clusters.yml +# This file defines a list of Clusters that pvcbootstrapd should be aware of. + +clusters: + - cluster1 + - cluster2 diff --git a/bootstrap-daemon/pvcbootstrapd-worker.service b/bootstrap-daemon/pvcbootstrapd-worker.service new file mode 100644 index 0000000..fde632b --- /dev/null +++ b/bootstrap-daemon/pvcbootstrapd-worker.service @@ -0,0 +1,16 @@ +# Parallel Virtual Cluster Provisioner API provisioner worker unit file + +[Unit] +Description = Parallel Virtual Cluster Bootstrap API worker +After = network-online.target + +[Service] +Type = simple +WorkingDirectory = /usr/share/pvc +Environment = PYTHONUNBUFFERED=true +Environment = PVC_CONFIG_FILE=/etc/pvc/pvcbootstrapd.yaml +ExecStart = /usr/share/pvc/pvcbootstrapd-worker.sh +Restart = on-failure + +[Install] +WantedBy = multi-user.target diff --git a/bootstrap-daemon/pvcbootstrapd-worker.sh b/bootstrap-daemon/pvcbootstrapd-worker.sh new file mode 100755 index 0000000..3063f81 --- /dev/null +++ b/bootstrap-daemon/pvcbootstrapd-worker.sh @@ -0,0 +1,40 @@ +#!/usr/bin/env bash + +# pvcbootstrapd-worker.py - API Celery worker daemon startup stub +# Part of the Parallel Virtual Cluster (PVC) system +# +# Copyright (C) 2018-2021 Joshua M. Boniface +# +# This program is free software: you can redistribute it and/or modify +# it under the terms of the GNU General Public License as published by +# the Free Software Foundation, version 3. +# +# This program is distributed in the hope that it will be useful, +# but WITHOUT ANY WARRANTY; without even the implied warranty of +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +# GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public License +# along with this program. If not, see . +# +############################################################################### + +CELERY_BIN="$( which celery )" + +# This absolute hackery is needed because Celery got the bright idea to change how their +# app arguments work in a non-backwards-compatible way with Celery 5. +case "$( cat /etc/debian_version )" in + 10.*) + CELERY_ARGS="worker --app pvcbootstrapd.flaskapi.celery --concurrency 99 --pool gevent --loglevel DEBUG" + ;; + 11.*) + CELERY_ARGS="--app pvcbootstrapd.flaskapi.celery worker --concurrency 99 --pool gevent --loglevel DEBUG" + ;; + *) + echo "Invalid Debian version found!" + exit 1 + ;; +esac + +${CELERY_BIN} ${CELERY_ARGS} +exit $? diff --git a/bootstrap-daemon/pvcbootstrapd.py b/bootstrap-daemon/pvcbootstrapd.py new file mode 100755 index 0000000..5d12e8f --- /dev/null +++ b/bootstrap-daemon/pvcbootstrapd.py @@ -0,0 +1,24 @@ +#!/usr/bin/env python3 + +# pvcbootstrapd.py - Bootstrap API daemon startup stub +# Part of the Parallel Virtual Cluster (PVC) system +# +# Copyright (C) 2018-2021 Joshua M. Boniface +# +# This program is free software: you can redistribute it and/or modify +# it under the terms of the GNU General Public License as published by +# the Free Software Foundation, version 3. +# +# This program is distributed in the hope that it will be useful, +# but WITHOUT ANY WARRANTY; without even the implied warranty of +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +# GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public License +# along with this program. If not, see . +# +############################################################################### + +import pvcbootstrapd.Daemon # noqa: F401 + +pvcbootstrapd.Daemon.entrypoint() diff --git a/bootstrap-daemon/pvcbootstrapd.service b/bootstrap-daemon/pvcbootstrapd.service new file mode 100644 index 0000000..1fe3616 --- /dev/null +++ b/bootstrap-daemon/pvcbootstrapd.service @@ -0,0 +1,16 @@ +# Parallel Virtual Cluster Bootstrap API daemon unit file + +[Unit] +Description = Parallel Virtual Cluster Bootstrap API daemon +After = network-online.target + +[Service] +Type = simple +WorkingDirectory = /usr/share/pvc +Environment = PYTHONUNBUFFERED=true +Environment = PVC_CONFIG_FILE=/etc/pvc/pvcbootstrapd.yaml +ExecStart = /usr/share/pvc/pvcbootstrapd.py +Restart = on-failure + +[Install] +WantedBy = multi-user.target diff --git a/bootstrap-daemon/pvcbootstrapd.yaml.sample b/bootstrap-daemon/pvcbootstrapd.yaml.sample new file mode 100644 index 0000000..f890c6b --- /dev/null +++ b/bootstrap-daemon/pvcbootstrapd.yaml.sample @@ -0,0 +1,91 @@ +--- +pvc: + # Enable debug mode + debug: true + + # Deploy username + deploy_username: deploy + + # Database (SQLite) configuration + database: + # Path to the database file + path: /srv/tftp/pvcbootstrapd.sql + + # Flask API configuration + api: + # Listen address + address: 10.199.199.254 + + # Listen port + port: 9999 + + # Redis Celery queue configuration + queue: + # Connect address + address: 127.0.0.1 + + # Connect port + port: 6379 + + # Redis path (almost always 0) + path: "/0" + + # DNSMasq DHCP configuration + dhcp: + # Listen address + address: 10.199.199.254 + + # Default gateway address + gateway: 10.199.199.1 + + # Local domain + domain: pvcbootstrap.local + + # DHCP lease range start + lease_start: 10.199.199.10 + + # DHCP lease range end + lease_end: 10.199.199.99 + + # DHCP lease time + lease_time: 1h + + # DNSMasq TFTP configuration + tftp: + # Root TFTP path (contents of the "buildpxe.sh" output directory; generally read-only) + root_path: "/srv/tftp/pvc-installer" + + # Per-host TFTP path (almost always "/host" under "root_path"; must be writable) + host_path: "/srv/tftp/pvc-installer/host" + + # PVC Ansible repository configuration + # Note: If "path" does not exist, "remote" will be cloned to it via Git using SSH private key "keyfile". + # Note: The VCS will be refreshed regularly via the API in response to webhooks. + ansible: + # Path to the VCS repository + path: "/var/home/joshua/pvc" + + # Clusters configuration file + clusters_file: "clusters.yml" + + # Path to the deploy key (if applicable) used to clone and pull the repository + keyfile: "/var/home/joshua/id_ed25519.joshua.key" + + # Git remote URI for the repository + remote: "ssh://git@git.bonifacelabs.ca:2222/bonifacelabs/pvc.git" + + # Git branch to use + branch: "master" + + # Filenames of the various group_vars components of a cluster + # Generally with pvc-ansible this will contain 2 files: "base.yml", and "pvc.yml"; refer to the + # pvc-ansible documentation and examples for details on these files. + # The third file, "bootstrap.yml", is used by pvcbootstrapd to map BMC MAC addresses to hosts and + # to simplify hardware detection. It must be present or the cluster will not be bootstrapped. + # Adjust these entries to match the actual filenames of your clusters; the pvc-ansible defaults + # are provided here. All clusters using this pvcbootstrapd instance must share identical filenames + # here. + cspec_files: + base: "base.yml" + pvc: "pvc.yml" + bootstrap: "bootstrap.yml" diff --git a/bootstrap-daemon/pvcbootstrapd.yaml.template b/bootstrap-daemon/pvcbootstrapd.yaml.template new file mode 100644 index 0000000..7a165f8 --- /dev/null +++ b/bootstrap-daemon/pvcbootstrapd.yaml.template @@ -0,0 +1,33 @@ +--- +pvc: + debug: true + deploy_username: DEPLOY_USERNAME + database: + path: ROOT_DIRECTORY/pvcbootstrapd.sql + api: + address: BOOTSTRAP_ADDRESS + port: 9999 + queue: + address: 127.0.0.1 + port: 6379 + path: "/0" + dhcp: + address: BOOTSTRAP_ADDRESS + gateway: BOOTSTRAP_ADDRESS + domain: pvcbootstrap.local + lease_start: BOOTSTRAP_DHCPSTART + lease_end: BOOTSTRAP_DHCPEND + lease_time: 1h + tftp: + root_path: "ROOT_DIRECTORY/tftp" + host_path: "ROOT_DIRECTORY/tftp/host" + ansible: + path: "ROOT_DIRECTORY/repo" + clusters_path: "clusters.yml" + keyfile: "ROOT_DIRECTORY/id_ed25519" + remote: "GIT_REMOTE" + branch: "GIT_BRANCH" + cspec_files: + base: "base.yml" + pvc: "pvc.yml" + bootstrap: "bootstrap.yml" diff --git a/bootstrap-daemon/pvcbootstrapd/Daemon.py b/bootstrap-daemon/pvcbootstrapd/Daemon.py new file mode 100755 index 0000000..431f4f8 --- /dev/null +++ b/bootstrap-daemon/pvcbootstrapd/Daemon.py @@ -0,0 +1,242 @@ +#!/usr/bin/env python3 + +# Daemon.py - PVC HTTP API daemon +# Part of the Parallel Virtual Cluster (PVC) system +# +# Copyright (C) 2018-2021 Joshua M. Boniface +# +# This program is free software: you can redistribute it and/or modify +# it under the terms of the GNU General Public License as published by +# the Free Software Foundation, version 3. +# +# This program is distributed in the hope that it will be useful, +# but WITHOUT ANY WARRANTY; without even the implied warranty of +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +# GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public License +# along with this program. If not, see . +# +############################################################################### + +import os +import yaml +import signal + +import pvcbootstrapd.lib.dnsmasq as dnsmasqd +import pvcbootstrapd.lib.lib as lib +import pvcbootstrapd.lib.db as db +import pvcbootstrapd.lib.git as git +import pvcbootstrapd.lib.tftp as tftp +import pvcbootstrapd.lib.ansible as ansible + +from distutils.util import strtobool as dustrtobool + +# Daemon version +version = "0.1" + +# API version +API_VERSION = 1.0 + + +########################################################## +# Exceptions +########################################################## + + +class MalformedConfigurationError(Exception): + """ + An exception when parsing the PVC daemon configuration file + """ + + def __init__(self, error=None): + self.msg = f"ERROR: Configuration file is malformed: {error}" + + def __str__(self): + return str(self.msg) + + +########################################################## +# Helper Functions +########################################################## + + +def strtobool(stringv): + if stringv is None: + return False + if isinstance(stringv, bool): + return bool(stringv) + try: + return bool(dustrtobool(stringv)) + except Exception: + return False + + +########################################################## +# Configuration Parsing +########################################################## + +def get_config_path(): + try: + return os.environ["PVCD_CONFIG_FILE"] + except KeyError: + print('ERROR: The "PVCD_CONFIG_FILE" environment variable must be set.') + os._exit(1) + + +def read_config(): + pvcbootstrapd_config_file = get_config_path() + + print(f"Loading configuration from file '{pvcbootstrapd_config_file}'") + + # Load the YAML config file + with open(pvcbootstrapd_config_file, "r") as cfgfile: + try: + o_config = yaml.load(cfgfile, Loader=yaml.SafeLoader) + except Exception as e: + print(f"ERROR: Failed to parse configuration file: {e}") + os._exit(1) + + # Create the configuration dictionary + config = dict() + + # Get the base configuration + try: + o_base = o_config["pvc"] + except KeyError as k: + raise MalformedConfigurationError(f"Missing top-level category {k}") + + for key in ['debug', 'deploy_username']: + try: + config[key] = o_base[key] + except KeyError as k: + raise MalformedConfigurationError(f"Missing first-level key {k}") + + # Get the first-level categories + try: + o_database = o_base["database"] + o_api = o_base["api"] + o_queue = o_base["queue"] + o_dhcp = o_base["dhcp"] + o_tftp = o_base["tftp"] + o_ansible = o_base["ansible"] + except KeyError as k: + raise MalformedConfigurationError(f"Missing first-level category {k}") + + # Get the Datbase configuration + for key in ['path']: + try: + config[f"database_{key}"] = o_database[key] + except Exception: + raise MalformedConfigurationError(f"Missing second-level key '{key}' under 'database'") + + # Get the API configuration + for key in ['address', 'port']: + try: + config[f"api_{key}"] = o_api[key] + except Exception: + raise MalformedConfigurationError(f"Missing second-level key '{key}' under 'api'") + + # Get the queue configuration + for key in ['address', 'port', 'path']: + try: + config[f"queue_{key}"] = o_queue[key] + except Exception: + raise MalformedConfigurationError(f"Missing second-level key '{key}' under 'queue'") + + # Get the DHCP configuration + for key in ['address', 'gateway', 'domain', 'lease_start', 'lease_end', 'lease_time']: + try: + config[f"dhcp_{key}"] = o_dhcp[key] + except Exception: + raise MalformedConfigurationError(f"Missing second-level key '{key}' under 'dhcp'") + + # Get the TFTP configuration + for key in ['root_path', 'host_path']: + try: + config[f"tftp_{key}"] = o_tftp[key] + except Exception: + raise MalformedConfigurationError(f"Missing second-level key '{key}' under 'tftp'") + + # Get the Ansible configuration + for key in ['path', 'clusters_file', 'keyfile', 'remote', 'branch']: + try: + config[f"ansible_{key}"] = o_ansible[key] + except Exception: + raise MalformedConfigurationError(f"Missing second-level key '{key}' under 'ansible'") + + # Get the second-level categories under Ansible + try: + o_ansible_cspec_files = o_ansible['cspec_files'] + except KeyError as k: + raise MalformedConfigurationError(f"Missing second-level category {k} under 'ansible'") + + # Get the Ansible CSpec Files configuration + for key in ['base', 'pvc', 'bootstrap']: + try: + config[f"ansible_cspec_files_{key}"] = o_ansible_cspec_files[key] + except Exception: + raise MalformedConfigurationError(f"Missing third-level key '{key}' under 'ansible/cspec_files'") + + return config + + +config = read_config() + + +########################################################## +# Entrypoint +########################################################## + + +def entrypoint(): + import pvcbootstrapd.flaskapi as pvcbootstrapd # noqa: E402 + + # Print our startup messages + print("") + print("|----------------------------------------------------------|") + print("| |") + print("| ███████████ ▜█▙ ▟█▛ █████ █ █ █ |") + print("| ██ ▜█▙ ▟█▛ ██ |") + print("| ███████████ ▜█▙ ▟█▛ ██ |") + print("| ██ ▜█▙▟█▛ ███████████ |") + print("| |") + print("|----------------------------------------------------------|") + print("| Parallel Virtual Cluster Bootstrap API daemon v{0: <9} |".format(version)) + print("| Debug: {0: <49} |".format(str(config["debug"]))) + print("| API version: v{0: <42} |".format(API_VERSION)) + print( + "| Listen: {0: <48} |".format( + "{}:{}".format(config["api_address"], config["api_port"]) + ) + ) + print("|----------------------------------------------------------|") + print("") + + # Initialize the database + db.init_database(config) + + # Initialize the Ansible repository + git.init_repository(config) + + # Initialize the tftp root + tftp.init_tftp(config) + + # Start DNSMasq + dnsmasq = dnsmasqd.DNSMasq(config) + dnsmasq.start() + + def cleanup(retcode): + dnsmasq.stop() + exit(retcode) + + def term(signum="", frame=""): + print("Received TERM, exiting.") + cleanup(0) + + signal.signal(signal.SIGTERM, term) + signal.signal(signal.SIGINT, term) + signal.signal(signal.SIGQUIT, term) + + # Start Flask + pvcbootstrapd.app.run(config['api_address'], config['api_port'], use_reloader=False, threaded=False, processes=4) diff --git a/bootstrap-daemon/pvcbootstrapd/__init__.py b/bootstrap-daemon/pvcbootstrapd/__init__.py new file mode 100644 index 0000000..e69de29 diff --git a/bootstrap-daemon/pvcbootstrapd/dnsmasq-lease.py b/bootstrap-daemon/pvcbootstrapd/dnsmasq-lease.py new file mode 100755 index 0000000..e7bbe73 --- /dev/null +++ b/bootstrap-daemon/pvcbootstrapd/dnsmasq-lease.py @@ -0,0 +1,122 @@ +#!/usr/bin/env python3 + +# dnsmasq-lease.py - DNSMasq lease interface for pvcnodedprov +# Part of the Parallel Virtual Cluster (PVC) system +# +# Copyright (C) 2018-2021 Joshua M. Boniface +# +# This program is free software: you can redistribute it and/or modify +# it under the terms of the GNU General Public License as published by +# the Free Software Foundation, version 3. +# +# This program is distributed in the hope that it will be useful, +# but WITHOUT ANY WARRANTY; without even the implied warranty of +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +# GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public License +# along with this program. If not, see . +# +############################################################################### + +from os import environ +from sys import argv +from requests import post +from json import dumps + +# Request log +# dnsmasq-dhcp[877466]: 2067194916 available DHCP range: 10.199.199.10 -- 10.199.199.19 +# dnsmasq-dhcp[877466]: 2067194916 DHCPDISCOVER(ens8) 52:54:00:34:36:40 +# dnsmasq-dhcp[877466]: 2067194916 tags: ens8 +# dnsmasq-dhcp[877466]: 2067194916 DHCPOFFER(ens8) 10.199.199.14 52:54:00:34:36:40 +# dnsmasq-dhcp[877466]: 2067194916 requested options: 1:netmask, 28:broadcast, 2:time-offset, 3:router, +# dnsmasq-dhcp[877466]: 2067194916 requested options: 15:domain-name, 6:dns-server, 12:hostname +# dnsmasq-dhcp[877466]: 2067194916 next server: 10.199.199.1 +# dnsmasq-dhcp[877466]: 2067194916 sent size: 1 option: 53 message-type 2 +# dnsmasq-dhcp[877466]: 2067194916 sent size: 4 option: 54 server-identifier 10.199.199.1 +# dnsmasq-dhcp[877466]: 2067194916 sent size: 4 option: 51 lease-time 1h +# dnsmasq-dhcp[877466]: 2067194916 sent size: 4 option: 58 T1 30m +# dnsmasq-dhcp[877466]: 2067194916 sent size: 4 option: 59 T2 52m30s +# dnsmasq-dhcp[877466]: 2067194916 sent size: 4 option: 1 netmask 255.255.255.0 +# dnsmasq-dhcp[877466]: 2067194916 sent size: 4 option: 28 broadcast 10.199.199.255 +# dnsmasq-dhcp[877466]: 2067194916 sent size: 4 option: 3 router 10.199.199.1 +# dnsmasq-dhcp[877466]: 2067194916 sent size: 4 option: 6 dns-server 10.199.199.1 +# dnsmasq-dhcp[877466]: 2067194916 sent size: 8 option: 15 domain-name test.com +# dnsmasq-dhcp[877466]: 2067194916 available DHCP range: 10.199.199.10 -- 10.199.199.19 +# dnsmasq-dhcp[877466]: 2067194916 DHCPREQUEST(ens8) 10.199.199.14 52:54:00:34:36:40 +# dnsmasq-dhcp[877466]: 2067194916 tags: ens8 +# dnsmasq-dhcp[877466]: 2067194916 DHCPACK(ens8) 10.199.199.14 52:54:00:34:36:40 +# dnsmasq-dhcp[877466]: 2067194916 requested options: 1:netmask, 28:broadcast, 2:time-offset, 3:router, +# dnsmasq-dhcp[877466]: 2067194916 requested options: 15:domain-name, 6:dns-server, 12:hostname +# dnsmasq-dhcp[877466]: 2067194916 next server: 10.199.199.1 +# dnsmasq-dhcp[877466]: 2067194916 sent size: 1 option: 53 message-type 5 +# dnsmasq-dhcp[877466]: 2067194916 sent size: 4 option: 54 server-identifier 10.199.199.1 +# dnsmasq-dhcp[877466]: 2067194916 sent size: 4 option: 51 lease-time 1h +# dnsmasq-dhcp[877466]: 2067194916 sent size: 4 option: 58 T1 30m +# dnsmasq-dhcp[877466]: 2067194916 sent size: 4 option: 59 T2 52m30s +# dnsmasq-dhcp[877466]: 2067194916 sent size: 4 option: 1 netmask 255.255.255.0 +# dnsmasq-dhcp[877466]: 2067194916 sent size: 4 option: 28 broadcast 10.199.199.255 +# dnsmasq-dhcp[877466]: 2067194916 sent size: 4 option: 3 router 10.199.199.1 +# dnsmasq-dhcp[877466]: 2067194916 sent size: 4 option: 6 dns-server 10.199.199.1 +# dnsmasq-dhcp[877466]: 2067194916 sent size: 8 option: 15 domain-name test.com +# dnsmasq-script[877466]: ['/var/home/joshua/dnsmasq-lease.py', 'add', '52:54:00:34:36:40', '10.199.199.14'] +# dnsmasq-script[877466]: environ({'DNSMASQ_INTERFACE': 'ens8', 'DNSMASQ_LEASE_EXPIRES': '1638422308', 'DNSMASQ_REQUESTED_OPTIONS': '1,28,2,3,15,6,12', 'DNSMASQ_TAGS': 'ens8', 'DNSMASQ_TIME_REMAINING': '3600', 'DNSMASQ_LOG_DHCP': '1', 'LC_CTYPE': 'C.UTF-8'}) + +# Renew log +# dnsmasq-dhcp[877466]: 1471211555 available DHCP range: 10.199.199.10 -- 10.199.199.19 +# dnsmasq-dhcp[877466]: 1471211555 DHCPREQUEST(ens8) 10.199.199.14 52:54:00:34:36:40 +# dnsmasq-dhcp[877466]: 1471211555 tags: ens8 +# dnsmasq-dhcp[877466]: 1471211555 DHCPACK(ens8) 10.199.199.14 52:54:00:34:36:40 +# dnsmasq-dhcp[877466]: 1471211555 requested options: 1:netmask, 28:broadcast, 2:time-offset, 3:router, +# dnsmasq-dhcp[877466]: 1471211555 requested options: 15:domain-name, 6:dns-server, 12:hostname +# dnsmasq-dhcp[877466]: 1471211555 next server: 10.199.199.1 +# dnsmasq-dhcp[877466]: 1471211555 sent size: 1 option: 53 message-type 5 +# dnsmasq-dhcp[877466]: 1471211555 sent size: 4 option: 54 server-identifier 10.199.199.1 +# dnsmasq-dhcp[877466]: 1471211555 sent size: 4 option: 51 lease-time 1h +# dnsmasq-dhcp[877466]: 1471211555 sent size: 4 option: 58 T1 30m +# dnsmasq-dhcp[877466]: 1471211555 sent size: 4 option: 59 T2 52m30s +# dnsmasq-dhcp[877466]: 1471211555 sent size: 4 option: 1 netmask 255.255.255.0 +# dnsmasq-dhcp[877466]: 1471211555 sent size: 4 option: 28 broadcast 10.199.199.255 +# dnsmasq-dhcp[877466]: 1471211555 sent size: 4 option: 3 router 10.199.199.1 +# dnsmasq-dhcp[877466]: 1471211555 sent size: 4 option: 6 dns-server 10.199.199.1 +# dnsmasq-dhcp[877466]: 1471211555 sent size: 8 option: 15 domain-name test.com +# dnsmasq-script[877466]: ['/var/home/joshua/dnsmasq-lease.py', 'old', '52:54:00:34:36:40', '10.199.199.14'] +# dnsmasq-script[877466]: environ({'DNSMASQ_INTERFACE': 'ens8', 'DNSMASQ_LEASE_EXPIRES': '1638422371', 'DNSMASQ_REQUESTED_OPTIONS': '1,28,2,3,15,6,12', 'DNSMASQ_TAGS': 'ens8', 'DNSMASQ_TIME_REMAINING': '3600', 'DNSMASQ_LOG_DHCP': '1', 'LC_CTYPE': 'C.UTF-8'}) + +action = argv[1] + +api_uri = environ.get('API_URI', 'http://127.0.0.1:9999/checkin/dnsmasq') +api_headers = { + 'ContentType': 'application/json' +} + +print(environ) + +if action in ['add']: + macaddr = argv[2] + ipaddr = argv[3] + api_data = dumps({ + 'action': action, + 'macaddr': macaddr, + 'ipaddr': ipaddr, + 'hostname': environ.get('DNSMASQ_SUPPLIED_HOSTNAME'), + 'client_id': environ.get('DNSMASQ_CLIENT_ID'), + 'expiry': environ.get('DNSMASQ_LEASE_EXPIRES'), + 'vendor_class': environ.get('DNSMASQ_VENDOR_CLASS'), + 'user_class': environ.get('DNSMASQ_USER_CLASS0') + }) + post(api_uri, headers=api_headers, data=api_data, verify=False) + +elif action in ['tftp']: + size = argv[2] + destaddr = argv[3] + filepath = argv[4] + api_data = dumps({ + 'action': action, + 'size': size, + 'destaddr': destaddr, + 'filepath': filepath + }) + post(api_uri, headers=api_headers, data=api_data, verify=False) + +exit(0) diff --git a/bootstrap-daemon/pvcbootstrapd/flaskapi.py b/bootstrap-daemon/pvcbootstrapd/flaskapi.py new file mode 100755 index 0000000..2bdea5a --- /dev/null +++ b/bootstrap-daemon/pvcbootstrapd/flaskapi.py @@ -0,0 +1,235 @@ +#!/usr/bin/env python3 + +# pvcbootstrapd.py - PVC Cluster Auto-bootstrap +# Part of the Parallel Virtual Cluster (PVC) system +# +# Copyright (C) 2018-2021 Joshua M. Boniface +# +# This program is free software: you can redistribute it and/or modify +# it under the terms of the GNU General Public License as published by +# the Free Software Foundation, version 3. +# +# This program is distributed in the hope that it will be useful, +# but WITHOUT ANY WARRANTY; without even the implied warranty of +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +# GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public License +# along with this program. If not, see . +# +############################################################################### + +import flask +import json + +from pvcbootstrapd.Daemon import config, API_VERSION + +import pvcbootstrapd.lib.dnsmasq as dnsmasq +import pvcbootstrapd.lib.lib as lib +import pvcbootstrapd.lib.db as db +import pvcbootstrapd.lib.git as git +import pvcbootstrapd.lib.ansible as ansible + +from time import sleep +from threading import Thread, Event +from dataclasses import dataclass +from flask_restful import Resource, Api, abort +from celery import Celery +from celery.utils.log import get_task_logger + + +logger = get_task_logger(__name__) + + +# Create Flask app and set config values +app = flask.Flask(__name__) +blueprint = flask.Blueprint('api', __name__, url_prefix='') +api = Api(blueprint) +app.register_blueprint(blueprint) + +app.config["CELERY_BROKER_URL"] = f"redis://{config['queue_address']}:{config['queue_port']}{config['queue_path']}" + +celery = Celery(app.name, broker=app.config["CELERY_BROKER_URL"]) +celery.conf.update(app.config) + + +# +# Celery functions +# +@celery.task(bind=True) +def dnsmasq_checkin(self, data): + lib.dnsmasq_checkin(config, data) + + +@celery.task(bind=True) +def host_checkin(self, data): + lib.host_checkin(config, data) + + +# +# API routes +# +class API_Root(Resource): + def get(self): + """ + Return basic details of the API + --- + tags: + - root + responses: + 200: + description: OK + schema: + type: object + id: Message + properties: + message: + type: string + description: A text message describing the result + example: "The foo was successfully maxed" + """ + return { "message": "pvcbootstrapd API" }, 200 +api.add_resource(API_Root, '/') + + +class API_Checkin(Resource): + def get(self): + """ + Return checkin details of the API + --- + tags: + - checkin + responses: + 200: + description: OK + schema: + type: object + id: Message + """ + return { "message": "pvcbootstrapd API Checkin interface" }, 200 +api.add_resource(API_Checkin, '/checkin') + + +class API_Checkin_DNSMasq(Resource): + def post(self): + """ + Register a checkin from the DNSMasq subsystem + --- + tags: + - checkin + consumes: + - application/json + parameters: + - in: body + name: dnsmasq_checkin_event + description: An event checkin from an external bootstrap tool component. + schema: + type: object + required: + - action + properties: + action: + type: string + description: The action of the event. + example: "add" + macaddr: + type: string + description: (add, old) The MAC address from a DHCP request. + example: "ff:ff:ff:ab:cd:ef" + ipaddr: + type: string + description: (add, old) The IP address from a DHCP request. + example: "10.199.199.10" + hostname: + type: string + description: (add, old) The client hostname from a DHCP request. + example: "pvc-installer-live" + client_id: + type: string + description: (add, old) The client ID from a DHCP request. + example: "01:ff:ff:ff:ab:cd:ef" + vendor_class: + type: string + description: (add, old) The DHCP vendor-class option from a DHCP request. + example: "CPQRIB3 (HP Proliant DL360 G6 iLO)" + user_class: + type: string + description: (add, old) The DHCP user-class option from a DHCP request. + example: None + responses: + 200: + description: OK + schema: + type: object + id: Message + """ + try: + data = json.loads(flask.request.data) + except Exception as e: + logger.warn(e) + data = { 'action': None } + logger.info(f"Handling DNSMasq checkin for: {data}") + + task = dnsmasq_checkin.delay(data) + return { "message": "received checkin from DNSMasq" }, 200 +api.add_resource(API_Checkin_DNSMasq, '/checkin/dnsmasq') + + +class API_Checkin_Host(Resource): + def post(self): + """ + Register a checkin from the Host subsystem + --- + tags: + - checkin + consumes: + - application/json + parameters: + - in: body + name: host_checkin_event + description: An event checkin from an external bootstrap tool component. + schema: + type: object + required: + - action + properties: + action: + type: string + description: The action of the event. + example: "begin" + hostname: + type: string + description: The system hostname. + example: "hv1.mydomain.tld" + host_macaddr: + type: string + description: The MAC address of the system provisioning interface. + example: "ff:ff:ff:ab:cd:ef" + host_ipaddr: + type: string + description: The IP address of the system provisioning interface. + example: "10.199.199.11" + bmc_macaddr: + type: string + description: The MAC address of the system BMC interface. + example: "ff:ff:ff:01:23:45" + bmc_ipaddr: + type: string + description: The IP addres of the system BMC interface. + example: "10.199.199.10" + responses: + 200: + description: OK + schema: + type: object + id: Message + """ + try: + data = json.loads(flask.request.data) + except Exception as e: + data = { 'action': None } + logger.info(f"Handling Host checkin for: {data}") + + task = host_checkin.delay(data) + return { "message": "received checkin from Host" }, 200 +api.add_resource(API_Checkin_Host, '/checkin/host') diff --git a/bootstrap-daemon/pvcbootstrapd/lib/__init__.py b/bootstrap-daemon/pvcbootstrapd/lib/__init__.py new file mode 100644 index 0000000..e69de29 diff --git a/bootstrap-daemon/pvcbootstrapd/lib/ansible.py b/bootstrap-daemon/pvcbootstrapd/lib/ansible.py new file mode 100755 index 0000000..a63c98c --- /dev/null +++ b/bootstrap-daemon/pvcbootstrapd/lib/ansible.py @@ -0,0 +1,63 @@ +#!/usr/bin/env python3 + +# ansible.py - PVC Cluster Auto-bootstrap Ansible libraries +# Part of the Parallel Virtual Cluster (PVC) system +# +# Copyright (C) 2018-2021 Joshua M. Boniface +# +# This program is free software: you can redistribute it and/or modify +# it under the terms of the GNU General Public License as published by +# the Free Software Foundation, version 3. +# +# This program is distributed in the hope that it will be useful, +# but WITHOUT ANY WARRANTY; without even the implied warranty of +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +# GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public License +# along with this program. If not, see . +# +############################################################################### + +import pvcbootstrapd.lib.git as git + +import ansible_runner +import tempfile +import yaml + +from time import sleep +from celery.utils.log import get_task_logger + + +logger = get_task_logger(__name__) + + +def run_bootstrap(config, cspec, cluster, nodes): + """ + Run an Ansible bootstrap against a cluster + """ + logger.debug(nodes) + + # Construct our temporary INI inventory string + logger.info(f"Constructing virtual Ansible inventory") + base_yaml = git.load_base_yaml(config, cluster.name) + local_domain = base_yaml.get('local_domain') + inventory = [f"""[{cluster.name}]"""] + for node in nodes: + inventory.append(f"""{node.name}.{local_domain} ansible_host={node.host_ipaddr}""") + inventory = '\n'.join(inventory) + logger.debug(inventory) + + # Waiting 30 seconds to ensure everything is booted an stabilized + logger.info("Waiting 30s before starting Ansible bootstrap.") + sleep(30) + + # Run the Ansible playbooks + with tempfile.TemporaryDirectory(prefix="pvc-ansible-bootstrap_") as pdir: + r = ansible_runner.run(private_data_dir=f"{pdir}", inventory=inventory, limit=f"{cluster.name}", playbook=f"{config['ansible_path']}/pvc.yml", extravars={"bootstrap": "yes"}) + logger.info("Final status:") + logger.info("{}: {}".format(r.status, r.rc)) + logger.info(r.stats) + if r.rc == 0: + git.commit_repository() + git.push_repository() diff --git a/bootstrap-daemon/pvcbootstrapd/lib/dataclasses.py b/bootstrap-daemon/pvcbootstrapd/lib/dataclasses.py new file mode 100755 index 0000000..612f9c5 --- /dev/null +++ b/bootstrap-daemon/pvcbootstrapd/lib/dataclasses.py @@ -0,0 +1,49 @@ +#!/usr/bin/env python3 + +# dataclasses.py - PVC Cluster Auto-bootstrap dataclasses +# Part of the Parallel Virtual Cluster (PVC) system +# +# Copyright (C) 2018-2021 Joshua M. Boniface +# +# This program is free software: you can redistribute it and/or modify +# it under the terms of the GNU General Public License as published by +# the Free Software Foundation, version 3. +# +# This program is distributed in the hope that it will be useful, +# but WITHOUT ANY WARRANTY; without even the implied warranty of +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +# GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public License +# along with this program. If not, see . +# +############################################################################### + +from dataclasses import dataclass + + +@dataclass +class Cluster: + """ + An instance of a Cluster + """ + id: int + name: str + state: str + + +@dataclass +class Node: + """ + An instance of a Node + """ + id: int + cluster: str + state: str + name: str + nid: int + bmc_macaddr: str + bmc_iapddr: str + host_macaddr: str + host_ipaddr: str + diff --git a/bootstrap-daemon/pvcbootstrapd/lib/db.py b/bootstrap-daemon/pvcbootstrapd/lib/db.py new file mode 100755 index 0000000..89821c7 --- /dev/null +++ b/bootstrap-daemon/pvcbootstrapd/lib/db.py @@ -0,0 +1,219 @@ +#!/usr/bin/env python3 + +# db.py - PVC Cluster Auto-bootstrap database libraries +# Part of the Parallel Virtual Cluster (PVC) system +# +# Copyright (C) 2018-2021 Joshua M. Boniface +# +# This program is free software: you can redistribute it and/or modify +# it under the terms of the GNU General Public License as published by +# the Free Software Foundation, version 3. +# +# This program is distributed in the hope that it will be useful, +# but WITHOUT ANY WARRANTY; without even the implied warranty of +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +# GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public License +# along with this program. If not, see . +# +############################################################################### + +import os +import sqlite3 +import contextlib +import json + +from time import sleep +from pvcbootstrapd.lib.dataclasses import Cluster, Node + + +# +# Database functions +# +@contextlib.contextmanager +def dbconn(db_path): + conn = sqlite3.connect(db_path) + conn.execute("PRAGMA foreign_keys = 1") + cur = conn.cursor() + yield cur + conn.commit() + conn.close() + + +def init_database(config): + db_path = config["database_path"] + if not os.path.isfile(db_path): + # Initializing the database + with dbconn(db_path) as cur: + # Table listing all clusters + cur.execute( + """CREATE TABLE clusters + (id INTEGER PRIMARY KEY AUTOINCREMENT, + name TEXT UNIQUE NOT NULL, + state TEXT NOT NULL)""" + ) + # Table listing all nodes + # FK: cluster -> clusters.id + cur.execute( + """CREATE TABLE nodes + (id INTEGER PRIMARY KEY AUTOINCREMENT, + cluster INTEGER NOT NULL, + state TEXT NOT NULL, + name TEXT UNIQUE NOT NULL, + nodeid INTEGER NOT NULL, + bmc_macaddr TEXT NOT NULL, + bmc_ipaddr TEXT NOT NULL, + host_macaddr TEXT NOT NULL, + host_ipaddr TEXT NOT NULL, + CONSTRAINT cluster_col FOREIGN KEY (cluster) REFERENCES clusters(id) ON DELETE CASCADE )""" + ) + + +# +# Cluster functions +# +def get_cluster(config, cid=None, name=None): + if cid is None and name is None: + return None + elif cid is not None: + findfield = 'id' + datafield = cid + elif name is not None: + findfield = 'name' + datafield = name + + with dbconn(config["database_path"]) as cur: + cur.execute( + f"""SELECT * FROM clusters WHERE {findfield} = ?""", + (datafield,) + ) + rows = cur.fetchall() + + if len(rows) > 0: + row = rows[0] + else: + return None + + return Cluster(row[0], row[1], row[2]) + + +def add_cluster(config, name, state): + with dbconn(config["database_path"]) as cur: + cur.execute( + """INSERT INTO clusters + (name, state) + VALUES + (?, ?)""", + (name, state) + ) + + return get_cluster(config, name=name) + + +def update_cluster_state(config, name, state): + with dbconn(config["database_path"]) as cur: + cur.execute( + """UPDATE clusters + SET state = ? + WHERE name = ?""", + (state, name) + ) + + return get_cluster(config, name=name) + + +# +# Node functions +# +def get_node(config, cluster_name, nid=None, name=None, bmc_macaddr=None): + cluster = get_cluster(config, name=cluster_name) + + if nid is None and name is None and bmc_macaddr is None: + return None + elif nid is not None: + findfield = 'id' + datafield = nid + elif bmc_macaddr is not None: + findfield = 'bmc_macaddr' + datafield = bmc_macaddr + elif name is not None: + findfield = 'name' + datafield = name + + with dbconn(config["database_path"]) as cur: + cur.execute( + f"""SELECT * FROM nodes WHERE {findfield} = ? AND cluster = ?""", + (datafield, cluster.id) + ) + rows = cur.fetchall() + + + if len(rows) > 0: + row = rows[0] + else: + return None + + return Node(row[0], cluster.name, row[2], row[3], row[4], row[5], row[6], row[7], row[8]) + + +def get_nodes_in_cluster(config, cluster_name): + cluster = get_cluster(config, name=cluster_name) + + with dbconn(config["database_path"]) as cur: + cur.execute( + """SELECT * FROM nodes WHERE cluster = ?""", + (cluster.id, ) + ) + rows = cur.fetchall() + + node_list = list() + for row in rows: + node_list.append( + Node(row[0], cluster.name, row[2], row[3], row[4], row[5], row[6], row[7], row[8]) + ) + + return node_list + + +def add_node(config, cluster_name, state, name, nodeid, bmc_macaddr, bmc_ipaddr, host_macaddr, host_ipaddr): + cluster = get_cluster(config, name=cluster_name) + + with dbconn(config["database_path"]) as cur: + cur.execute( + """INSERT INTO nodes + (cluster, state, name, nodeid, bmc_macaddr, bmc_ipaddr, host_macaddr, host_ipaddr) + VALUES + (?, ?, ?, ?, ?, ?, ?, ?)""", + (cluster.id, state, name, nodeid, bmc_macaddr, bmc_ipaddr, host_macaddr, host_ipaddr) + ) + + return get_node(config, cluster_name, name=name) + + +def update_node_state(config, cluster_name, name, state): + cluster = get_cluster(config, name=cluster_name) + + with dbconn(config["database_path"]) as cur: + cur.execute( + """UPDATE nodes + SET state = ? + WHERE name = ? AND cluster = ?""", + (state, name, cluster.id) + ) + + return get_node(config, cluster_name, name=name) + + +def update_node_addresses(config, cluster_name, name, bmc_macaddr, bmc_ipaddr, host_macaddr, host_ipaddr): + cluster = get_cluster(config, name=cluster_name) + + with dbconn(config["database_path"]) as cur: + cur.execute( + """UPDATE nodes + SET bmc_macaddr = ?, bmc_ipaddr = ?, host_macaddr = ?, host_ipaddr = ? + WHERE name = ? AND cluster = ?""", + (bmc_macaddr, bmc_ipaddr, host_macaddr, host_ipaddr, name, cluster.id) + ) + + return get_node(config, cluster_name, name=name) diff --git a/bootstrap-daemon/pvcbootstrapd/lib/dnsmasq.py b/bootstrap-daemon/pvcbootstrapd/lib/dnsmasq.py new file mode 100755 index 0000000..2766477 --- /dev/null +++ b/bootstrap-daemon/pvcbootstrapd/lib/dnsmasq.py @@ -0,0 +1,108 @@ +#!/usr/bin/env python3 + +# dnsmasq.py - PVC Cluster Auto-bootstrap DNSMasq instance +# Part of the Parallel Virtual Cluster (PVC) system +# +# Copyright (C) 2018-2021 Joshua M. Boniface +# +# This program is free software: you can redistribute it and/or modify +# it under the terms of the GNU General Public License as published by +# the Free Software Foundation, version 3. +# +# This program is distributed in the hope that it will be useful, +# but WITHOUT ANY WARRANTY; without even the implied warranty of +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +# GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public License +# along with this program. If not, see . +# +############################################################################### + +import os +import flask +import click +import requests +import subprocess +import signal +import json +import pvcbootstrapd.lib.lib as lib +from time import sleep +from threading import Thread, Event +from dataclasses import dataclass +from flask_restful import Resource, Api, abort +from celery import Celery + + +class DNSMasq: + """ + Implementes a daemonized instance of DNSMasq for providing DHCP and TFTP services + + The DNSMasq instance listens on the configured 'dhcp_address', and instead of a "real" + leases database forwards requests to the 'dnsmasq-lease.py' script. This script will + then hit the pvcbootstrapd '/checkin' API endpoint to perform actions. + + TFTP is provided to automate the bootstrap of a node, providing the pvc-installer + over TFTP as well as a seed configuration which is created by the API. + """ + def __init__(self, config): + self.environment = { + "API_URI": f"http://{config['api_address']}:{config['api_port']}/checkin/dnsmasq" + } + self.dnsmasq_cmd = [ + "/usr/sbin/dnsmasq", + "--bogus-priv", + "--no-hosts", + "--dhcp-authoritative", + "--filterwin2k", + "--expand-hosts", + "--domain-needed", + f"--domain={config['dhcp_domain']}", + f"--local=/{config['dhcp_domain']}/", + "--log-facility=-", + "--log-dhcp", + "--keep-in-foreground", + f"--dhcp-script={os.getcwd()}/pvcbootstrapd/dnsmasq-lease.py", + "--bind-interfaces", + f"--listen-address={config['dhcp_address']}", + f"--dhcp-option=3,{config['dhcp_gateway']}", + f"--dhcp-range={config['dhcp_lease_start']},{config['dhcp_lease_end']},{config['dhcp_lease_time']}", + "--enable-tftp", + f"--tftp-root={config['tftp_root_path']}/", + # This block of dhcp-match, tag-if, and dhcp-boot statements sets the following TFTP setup: + # If the machine sends client-arch 0, and is not tagged iPXE, load undionly.kpxe (chainload) + # If the machine sends client-arch 7 or 9, and is not tagged iPXE, load ipxe.efi (chainload) + # If the machine sends the iPXE option, load boot.ipxe (iPXE boot configuration) + "--dhcp-match=set:o_bios,option:client-arch,0", + "--dhcp-match=set:o_uefi,option:client-arch,7", + "--dhcp-match=set:o_uefi,option:client-arch,9", + "--dhcp-match=set:ipxe,175", + "--tag-if=set:bios,tag:!ipxe,tag:o_bios", + "--tag-if=set:uefi,tag:!ipxe,tag:o_uefi", + f"--dhcp-boot=tag:bios,undionly.kpxe", + f"--dhcp-boot=tag:uefi,ipxe.efi", + f"--dhcp-boot=tag:ipxe,boot.ipxe", + ] + if config["debug"]: + self.dnsmasq_cmd.append( + "--leasefile-ro" + ) + + print(self.dnsmasq_cmd) + self.stdout = subprocess.PIPE + + def execute(self): + self.proc = subprocess.Popen( + self.dnsmasq_cmd, + env=self.environment, + ) + + def start(self): + self.thread = Thread(target=self.execute, args=()) + self.thread.start() + + def stop(self): + self.proc.send_signal(signal.SIGTERM) + + def reload(self): + self.proc.send_signal(signal.SIGHUP) diff --git a/bootstrap-daemon/pvcbootstrapd/lib/git.py b/bootstrap-daemon/pvcbootstrapd/lib/git.py new file mode 100755 index 0000000..e1d57b1 --- /dev/null +++ b/bootstrap-daemon/pvcbootstrapd/lib/git.py @@ -0,0 +1,166 @@ +#!/usr/bin/env python3 + +# git.py - PVC Cluster Auto-bootstrap Git repository libraries +# Part of the Parallel Virtual Cluster (PVC) system +# +# Copyright (C) 2018-2021 Joshua M. Boniface +# +# This program is free software: you can redistribute it and/or modify +# it under the terms of the GNU General Public License as published by +# the Free Software Foundation, version 3. +# +# This program is distributed in the hope that it will be useful, +# but WITHOUT ANY WARRANTY; without even the implied warranty of +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +# GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public License +# along with this program. If not, see . +# +############################################################################### + +import os.path +import git +import yaml + +from celery.utils.log import get_task_logger + + +logger = get_task_logger(__name__) + + +def init_repository(config): + """ + Clone the Ansible git repository + """ + if not os.path.exists(config['ansible_path']): + logger.info(f"Cloning configuration repository {config['ansible_remote']} branch {config['ansible_branch']} to {config['ansible_path']}") + git_ssh_cmd = f"ssh -i {config['ansible_keyfile']}" + with git.Git().custom_environment(GIT_SSH_COMMAND=git_ssh_cmd): + git.Repo.clone_from(config['ansible_remote'], config['ansible_path'], branch=config['ansible_branch']) + g = git.cmd.Git(f"{config['ansible_path']}") + else: + g = git.cmd.Git(f"{config['ansible_path']}") + g.checkout(config['ansible_branch']) + + for submodule in g.submodules: + submodule.update(init=True) + + +def pull_repository(config): + """ + Pull (with rebase) the Ansible git repository + """ + logger.info(f"Updating local configuration repository {config['ansible_path']}") + try: + git_ssh_cmd = f"ssh -i {config['ansible_keyfile']}" + with git.Git().custom_environment(GIT_SSH_COMMAND=git_ssh_cmd): + g = git.cmd.Git(f"{config['ansible_path']}") + g.pull(rebase=True) + except Exception as e: + logger.warn(e) + + +def commit_repository(config): + """ + Commit uncommitted changes to the Ansible git repository + """ + logger.info(f"Committing changes to local configuration repository {config['ansible_path']}") + + try: + g = git.cmd.Git(f"{config['ansible_path']}") + g.add('--all') + g.commit( + '-m', + 'Automated commit from PVC Bootstrap Ansible subsystem', + author="PVC Bootstrap " + ) + except Exception as e: + logger.warn(e) + + +def push_repository(config): + """ + Push changes to the default remote + """ + logger.info(f"Pushing changes from local configuration repository {config['ansible_path']}") + + try: + g = git.cmd.Git(f"{config['ansible_path']}") + origin = g.remote(name='origin') + origin.push() + except Exception as e: + logger.warn(e) + + +def load_cspec_yaml(config): + """ + Load the bootstrap group_vars for all known clusters + """ + # Pull down the repository + pull_repository(config) + + # Load our clusters file and read the clusters from it + clusters_file = f"{config['ansible_path']}/{config['ansible_clusters_file']}" + logger.info(f"Loading cluster configuration from file '{clusters_file}'") + with open(clusters_file, 'r') as clustersfh: + clusters = yaml.load(clustersfh, Loader=yaml.SafeLoader).get('clusters', list()) + + # Define a base cpec + cspec = { + 'bootstrap': dict(), + 'hooks': dict(), + } + + # Read each cluster's cspec and update the base cspec + logger.info(f"Loading per-cluster specifications...") + for cluster in clusters: + cspec_file = f"{config['ansible_path']}/group_vars/{cluster}/{config['ansible_cspec_files_bootstrap']}" + if os.path.exists(cspec_file): + with open(cspec_file, 'r') as cpsecfh: + try: + cspec_yaml = yaml.load(cpsecfh, Loader=yaml.SafeLoader) + except Exception as e: + logger.warn(f"Failed to load {config['ansible_cspec_files_bootstrap']} for cluster {cluster}: {e}") + continue + + # Convert the MAC address keys to lowercase + # DNSMasq operates with lowercase keys, but often these are written with uppercase. + # Convert them to lowercase to prevent discrepancies later on. + cspec_yaml['bootstrap'] = {k.lower(): v for k, v in cspec_yaml['bootstrap'].items()} + + # Load in the base YAML for the cluster + base_yaml = load_base_yaml(config, cluster) + + # Set per-node values from elsewhere + for node in cspec_yaml['bootstrap']: + # Set the cluster value automatically + cspec_yaml['bootstrap'][node]['node']['cluster'] = cluster + + # Set the domain value automatically via base config + cspec_yaml['bootstrap'][node]['node']['domain'] = base_yaml['local_domain'] + + # Set the node FQDN value automatically + cspec_yaml['bootstrap'][node]['node']['fqdn'] = f"{cspec_yaml['bootstrap'][node]['node']['hostname']}.{cspec_yaml['bootstrap'][node]['node']['domain']}" + + # Append bootstrap entries to the main dictionary + cspec['bootstrap'] = {**cspec['bootstrap'], **cspec_yaml['bootstrap']} + + # Append hooks to the main dictionary (per-cluster) + if cspec_yaml.get('hooks'): + cspec['hooks'][cluster] = cspec_yaml['hooks'] + + logger.info(f"Finished loading per-cluster specifications") + logger.debug(f"cspec = {cspec}") + return cspec + + +def load_base_yaml(config, cluster): + """ + Load the base.yml group_vars for a cluster + """ + base_file = f"{config['ansible_path']}/group_vars/{cluster}/base.yml" + with open(base_file, 'r') as varsfile: + base_yaml = yaml.load(varsfile, Loader=yaml.SafeLoader) + + return base_yaml diff --git a/bootstrap-daemon/pvcbootstrapd/lib/hooks.py b/bootstrap-daemon/pvcbootstrapd/lib/hooks.py new file mode 100755 index 0000000..53a9cb1 --- /dev/null +++ b/bootstrap-daemon/pvcbootstrapd/lib/hooks.py @@ -0,0 +1,267 @@ +#!/usr/bin/env python3 + +# hooks.py - PVC Cluster Auto-bootstrap Hook libraries +# Part of the Parallel Virtual Cluster (PVC) system +# +# Copyright (C) 2018-2021 Joshua M. Boniface +# +# This program is free software: you can redistribute it and/or modify +# it under the terms of the GNU General Public License as published by +# the Free Software Foundation, version 3. +# +# This program is distributed in the hope that it will be useful, +# but WITHOUT ANY WARRANTY; without even the implied warranty of +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +# GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public License +# along with this program. If not, see . +# +############################################################################### + +import pvcbootstrapd.lib.git as git +import pvcbootstrapd.lib.db as db + +import ansible_runner +import tempfile +import yaml +import paramiko +import contextlib + +from re import match +from time import sleep +from celery.utils.log import get_task_logger + + +logger = get_task_logger(__name__) + + +@contextlib.contextmanager +def run_paramiko(node_address, username): + ssh_client = paramiko.SSHClient() + ssh_client.set_missing_host_key_policy(paramiko.AutoAddPolicy()) + ssh_client.connect(hostname=node_address, username=username) + yield ssh_client + ssh_client.close() + + +def run_hook_osddb(config, target, args): + """ + Add an OSD DB defined by args['disk'] + """ + for node in targets: + node_name = node.name + node_address = node.host_ipaddr + + device = args['disk'] + + logger.info(f"Creating OSD DB on node {node_name} device {device}") + + # Using a direct command on the target here is somewhat messy, but avoids many + # complexities of determining a valid API listen address, etc. + pvc_cmd_string = f"pvc storage osd create-db-vg --yes {node_name} {device}" + + with run_paramiko(node_address, config['deploy_username']) as c: + stdin, stdout, stderr = c.exec_command(pvc_cmd_string) + logger.debug(stdout.readlines()) + logger.debug(stderr.readlines()) + + +def run_hook_osd(config, targets, args): + """ + Add an OSD defined by args['disk'] with weight args['weight'] + """ + for node in targets: + node_name = node.name + node_address = node.host_ipaddr + + device = args['disk'] + weight = args.get('weight', 1) + ext_db_flag = args.get('ext_db', False) + ext_db_ratio = args.get('ext_db_ratio', 0.05) + + logger.info(f"Creating OSD on node {node_name} device {device} weight {weight}") + + # Using a direct command on the target here is somewhat messy, but avoids many + # complexities of determining a valid API listen address, etc. + pvc_cmd_string = f"pvc storage osd add --yes {node_name} {device} --weight {weight}" + if ext_db_flag: + pvc_cmd_string = f"{pvc_cmd_string} --ext-db --ext-db-ratio {ext_db_ratio}" + + with run_paramiko(node_address, config['deploy_username']) as c: + stdin, stdout, stderr = c.exec_command(pvc_cmd_string) + logger.debug(stdout.readlines()) + logger.debug(stderr.readlines()) + + +def run_hook_pool(config, targets, args): + """ + Add an pool defined by args['name'] on device tier args['tier'] + """ + for node in targets: + node_name = node.name + node_address = node.host_ipaddr + + name = args['name'] + pgs = args.get('pgs', '64') + tier = args.get('tier', 'default') # Does nothing yet + + logger.info(f"Creating storage pool on node {node_name} name {name} pgs {pgs} tier {tier}") + + # Using a direct command on the target here is somewhat messy, but avoids many + # complexities of determining a valid API listen address, etc. + pvc_cmd_string = f"pvc storage pool add {name} {pgs}" + + with run_paramiko(node_address, config['deploy_username']) as c: + stdin, stdout, stderr = c.exec_command(pvc_cmd_string) + logger.debug(stdout.readlines()) + logger.debug(stderr.readlines()) + + # This only runs once on whatever the first node is + break + + +def run_hook_network(config, targets, args): + """ + Add an network defined by args (many) + """ + for node in targets: + node_name = node.name + node_address = node.host_ipaddr + + vni = args['vni'] + description = args['description'] + nettype = args['type'] + mtu = args.get('mtu', None) + + pvc_cmd_string = f"pvc network add {vni} --description {description} --type {nettype}" + + if mtu is not None and mtu not in ['auto', 'default']: + pvc_cmd_string = f"{pvc_cmd_string} --mtu {mtu}" + + if nettype == 'managed': + domain = args['domain'] + pvc_cmd_string = f"{pvc_cmd_string} --domain {domain}" + + dns_servers = args.get('dns_servers', []) + for dns_server in dns_servers: + pvc_cmd_string = f"{pvc_cmd_string} --dns-server {dns_server}" + + is_ip4 = args['ip4'] + if is_ip4: + ip4_network = args['ip4_network'] + pvc_cmd_string = f"{pvc_cmd_string} --ipnet {ip4_network}" + + ip4_gateway = args['ip4_gateway'] + pvc_cmd_string = f"{pvc_cmd_string} --gateway {ip4_gateway}" + + ip4_dhcp = args['ip4_dhcp'] + if ip4_dhcp: + pvc_cmd_string = f"{pvc_cmd_string} --dhcp" + ip4_dhcp_start = args['ip4_dhcp_start'] + ip4_dhcp_end = args['ip4_dhcp_end'] + pvc_cmd_string = f"{pvc_cmd_string} --dhcp-start {ip4_dhcp_start} --dhcp-end {ip4_dhcp_end}" + else: + pvc_cmd_string = f"{pvc_cmd_string} --no-dhcp" + + is_ip6 = args['ip6'] + if is_ip6: + ip6_network = args['ip6_network'] + pvc_cmd_string = f"{pvc_cmd_string} --ipnet6 {ip6_network}" + + ip6_gateway = args['ip6_gateway'] + pvc_cmd_string = f"{pvc_cmd_string} --gateway6 {ip6_gateway}" + + logger.info(f"Creating network on node {node_name} VNI {vni} type {nettype}") + + with run_paramiko(node_address, config['deploy_username']) as c: + stdin, stdout, stderr = c.exec_command(pvc_cmd_string) + logger.debug(stdout.readlines()) + logger.debug(stderr.readlines()) + + # This only runs once on whatever the first node is + break + + +def run_hook_script(config, targets, args): + for node in targets: + node_name = node.name + node_address = node.host_ipaddr + + script = args.get('script', None) + source = args.get('source', None) + path = args.get('path', None) + + logger.info(f"Running script on node {node_name}") + + with run_paramiko(node_address, config['deploy_username']) as c: + if script is not None: + remote_path = '/tmp/pvcbootstrapd.hook' + with tempfile.NamedTemporaryFile(mode='w') as tf: + tf.write(script) + tf.seek(0) + + # Send the file to the remote system + tc = c.open_sftp() + tc.put(tf.name, remote_path) + tc.chmod(remote_path, 0o755) + tc.close() + elif source == 'local': + if not match(r'^/', path): + path = config['ansible_path'] + '/' + path + + remote_path = '/tmp/pvcbootstrapd.hook' + if path is None: + continue + + tc = c.open_sftp() + tc.put(path, remote_path) + tc.chmod(remote_path, 0o755) + tc.close() + elif source == 'remote': + remote_path = path + + stdin, stdout, stderr = c.exec_command(remote_path) + logger.debug(stdout.readlines()) + logger.debug(stderr.readlines()) + + +hook_functions = { + 'osddb': run_hook_osddb, + 'osd': run_hook_osd, + 'pool': run_hook_pool, + 'network': run_hook_network, + 'script': run_hook_script +} + + +def run_hooks(config, cspec, cluster, nodes): + """ + Run an Ansible bootstrap against a cluster + """ + logger.debug(nodes) + + cluster_hooks = cspec['hooks'][cluster.name] + + logger.debug(cspec) + + cluster_nodes = db.get_nodes_in_cluster(config, cluster.name) + + for hook in cluster_hooks: + hook_target = hook['target'] + hook_name = hook['name'] + logger.info(f"Running hook on {hook_target}: {hook_name}") + + if 'all' in hook_target: + target_nodes = cluster_nodes + else: + target_nodes = [node for node in cluster_nodes if node.name in hook_target] + + hook_type = hook['type'] + hook_args = hook['args'] + + # Run the hook function + hook_functions[hook_type](config, target_nodes, hook_args) + + # Wait 5s between hooks + sleep(5) diff --git a/bootstrap-daemon/pvcbootstrapd/lib/host.py b/bootstrap-daemon/pvcbootstrapd/lib/host.py new file mode 100755 index 0000000..d0f6cdc --- /dev/null +++ b/bootstrap-daemon/pvcbootstrapd/lib/host.py @@ -0,0 +1,71 @@ +#!/usr/bin/env python3 + +# host.py - PVC Cluster Auto-bootstrap host libraries +# Part of the Parallel Virtual Cluster (PVC) system +# +# Copyright (C) 2018-2021 Joshua M. Boniface +# +# This program is free software: you can redistribute it and/or modify +# it under the terms of the GNU General Public License as published by +# the Free Software Foundation, version 3. +# +# This program is distributed in the hope that it will be useful, +# but WITHOUT ANY WARRANTY; without even the implied warranty of +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +# GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public License +# along with this program. If not, see . +# +############################################################################### + +from celery.utils.log import get_task_logger + +import pvcbootstrapd.lib.db as db + + +logger = get_task_logger(__name__) + + +def installer_init(config, cspec, data): + bmc_macaddr = data['bmc_macaddr'] + bmc_ipaddr = data['bmc_ipaddr'] + host_macaddr = data['host_macaddr'] + host_ipaddr = data['host_ipaddr'] + cspec_cluster = cspec['bootstrap'][bmc_macaddr]['node']['cluster'] + cspec_hostname = cspec['bootstrap'][bmc_macaddr]['node']['hostname'] + cspec_nid = int(''.join(filter(str.isdigit, cspec_hostname))) + + cluster = db.get_cluster(config, name=cspec_cluster) + if cluster is None: + cluster = db.add_cluster(config, cspec_cluster, "provisioning") + logger.debug(cluster) + + node = db.get_node(config, cspec_cluster, name=cspec_hostname) + if node is None: + node = db.add_node(config, cspec_cluster, "installing", cspec_hostname, cspec_nid, bmc_macaddr, bmc_ipaddr, host_macaddr, host_ipaddr) + else: + node = db.update_node_addresses(config, cspec_cluster, cspec_hostname, bmc_macaddr, bmc_ipaddr, host_macaddr, host_ipaddr) + logger.debug(node) + + +def installer_complete(config, cspec, data): + bmc_macaddr = data['bmc_macaddr'] + cspec_hostname = cspec['bootstrap'][bmc_macaddr]['node']['hostname'] + cspec_cluster = cspec['bootstrap'][bmc_macaddr]['node']['cluster'] + + node = db.update_node_state(config, cspec_cluster, cspec_hostname, "installed") + logger.debug(node) + + +def set_boot_state(config, cspec, data, state): + bmc_macaddr = data['bmc_macaddr'] + bmc_ipaddr = data['bmc_ipaddr'] + host_macaddr = data['host_macaddr'] + host_ipaddr = data['host_ipaddr'] + cspec_cluster = cspec['bootstrap'][bmc_macaddr]['node']['cluster'] + cspec_hostname = cspec['bootstrap'][bmc_macaddr]['node']['hostname'] + + node = db.update_node_addresses(config, cspec_cluster, cspec_hostname, bmc_macaddr, bmc_ipaddr, host_macaddr, host_ipaddr) + node = db.update_node_state(config, cspec_cluster, cspec_hostname, state) + logger.debug(node) diff --git a/bootstrap-daemon/pvcbootstrapd/lib/installer.py b/bootstrap-daemon/pvcbootstrapd/lib/installer.py new file mode 100755 index 0000000..290232e --- /dev/null +++ b/bootstrap-daemon/pvcbootstrapd/lib/installer.py @@ -0,0 +1,79 @@ +#!/usr/bin/env python3 + +# lib.py - PVC Cluster Auto-bootstrap libraries +# Part of the Parallel Virtual Cluster (PVC) system +# +# Copyright (C) 2018-2021 Joshua M. Boniface +# +# This program is free software: you can redistribute it and/or modify +# it under the terms of the GNU General Public License as published by +# the Free Software Foundation, version 3. +# +# This program is distributed in the hope that it will be useful, +# but WITHOUT ANY WARRANTY; without even the implied warranty of +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +# GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public License +# along with this program. If not, see . +# +############################################################################### + +from jinja2 import Template + + +# +# Worker Functions - PXE/Installer Per-host Templates +# +def add_pxe(config, cspec_node, host_macaddr): + # Generate a per-client iPXE configuration for this host + destination_filename = f"{config['tftp_host_path']}/mac-{host_macaddr.replace(':', '')}.ipxe" + template_filename = f"{config['tftp_root_path']}/host-ipxe.j2" + + with open(template_filename, 'r') as tfh: + template = Template(tfh.read()) + + imgargs_host_list = cspec_node.get('config', {}).get('kernel_options') + if imgargs_host_list is not None: + imgargs_host = ' '.join(imgargs_host_list) + else: + imgargs_host = None + + rendered = template.render( + imgargs_host=imgargs_host + ) + + with open(destination_filename, 'w') as dfh: + dfh.write(rendered) + dfh.write('\n') + + +def add_preseed(config, cspec_node, host_macaddr, system_drive_target): + # Generate a per-client Installer configuration for this host + destination_filename = f"{config['tftp_host_path']}/mac-{host_macaddr.replace(':', '')}.preseed" + template_filename = f"{config['tftp_root_path']}/host-preseed.j2" + + with open(template_filename, 'r') as tfh: + template = Template(tfh.read()) + + add_packages_list = cspec_node.get('config', {}).get('packages') + if add_packages_list is not None: + add_packages = ','.join(add_packages_list) + else: + add_packages = None + + # We use the dhcp_address here to allow the listen_address to be 0.0.0.0 + rendered = template.render( + debrelease=cspec_node.get('config', {}).get('release'), + debmirror=cspec_node.get('config', {}).get('mirror'), + addpkglist=add_packages, + filesystem=cspec_node.get('config', {}).get('filesystem'), + skip_blockcheck=False, + fqdn=cspec_node['node']['fqdn'], + target_disk=system_drive_target, + pvcbootstrapd_checkin_uri=f"http://{config['dhcp_address']}:{config['api_port']}/checkin/host" + ) + + with open(destination_filename, 'w') as dfh: + dfh.write(rendered) + dfh.write('\n') diff --git a/bootstrap-daemon/pvcbootstrapd/lib/lib.py b/bootstrap-daemon/pvcbootstrapd/lib/lib.py new file mode 100755 index 0000000..06d1233 --- /dev/null +++ b/bootstrap-daemon/pvcbootstrapd/lib/lib.py @@ -0,0 +1,148 @@ +#!/usr/bin/env python3 + +# lib.py - PVC Cluster Auto-bootstrap libraries +# Part of the Parallel Virtual Cluster (PVC) system +# +# Copyright (C) 2018-2021 Joshua M. Boniface +# +# This program is free software: you can redistribute it and/or modify +# it under the terms of the GNU General Public License as published by +# the Free Software Foundation, version 3. +# +# This program is distributed in the hope that it will be useful, +# but WITHOUT ANY WARRANTY; without even the implied warranty of +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +# GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public License +# along with this program. If not, see . +# +############################################################################### + +import pvcbootstrapd.lib.db as db +import pvcbootstrapd.lib.git as git +import pvcbootstrapd.lib.redfish as redfish +import pvcbootstrapd.lib.host as host +import pvcbootstrapd.lib.ansible as ansible +import pvcbootstrapd.lib.hooks as hooks + +from pvcbootstrapd.lib.dataclasses import Cluster, Node + +from time import sleep +from threading import Thread, Event +from celery import Celery +from celery.utils.log import get_task_logger +from jinja2 import Template + + +logger = get_task_logger(__name__) + + +# +# Worker Functions - Checkins (Celery root tasks) +# +def dnsmasq_checkin(config, data): + """ + Handle checkins from DNSMasq + """ + logger.debug(f"data = {data}") + + # This is an add event; what we do depends on some stuff + if data['action'] in ['add']: + logger.info(f"Receiving 'add' checkin from DNSMasq for MAC address '{data['macaddr']}'") + cspec = git.load_cspec_yaml(config) + is_in_bootstrap_map = True if data['macaddr'] in cspec['bootstrap'] else False + if is_in_bootstrap_map: + if cspec['bootstrap'][data['macaddr']]['bmc'].get('redfish', None) is not None: + if cspec['bootstrap'][data['macaddr']]['bmc']['redfish']: + is_redfish = True + else: + is_redfish = False + else: + is_redfish = redfish.check_redfish(config, data) + + logger.info(f"Is device '{data['macaddr']}' Redfish capable? {is_redfish}") + if is_redfish: + redfish.redfish_init(config, cspec, data) + else: + logger.warn(f"Device '{data['macaddr']}' not in bootstrap map; ignoring.") + + return + + # This is a tftp event; a node installer has booted + if data['action'] in ['tftp']: + logger.info(f"Receiving 'tftp' checkin from DNSMasq for IP address '{data['destaddr']}'") + return + +def host_checkin(config, data): + """ + Handle checkins from the PVC node + """ + logger.info(f"Registering checkin for host {data['hostname']}") + logger.debug(f"data = {data}") + cspec = git.load_cspec_yaml(config) + bmc_macaddr = data['bmc_macaddr'] + cspec_cluster = cspec['bootstrap'][bmc_macaddr]['node']['cluster'] + + if data['action'] in ['install-start']: + # Node install has started + logger.info(f"Registering install start for host {data['hostname']}") + host.installer_init(config, cspec, data) + + elif data['action'] in ['install-complete']: + # Node install has finished + logger.info(f"Registering install complete for host {data['hostname']}") + host.installer_complete(config, cspec, data) + + elif data['action'] in ['system-boot_initial']: + # Node has booted for the first time and can begin Ansible runs once all nodes up + logger.info(f"Registering first boot for host {data['hostname']}") + target_state = "booted-initial" + + host.set_boot_state(config, cspec, data, target_state) + sleep(1) + + all_nodes = db.get_nodes_in_cluster(config, cspec_cluster) + ready_nodes = [node for node in all_nodes if node.state == target_state] + + # Continue once all nodes are in the booted-initial state + logger.info(f"Ready: {len(ready_nodes)} All: {len(all_nodes)}") + if len(ready_nodes) >= len(all_nodes): + cluster = db.update_cluster_state(config, cspec_cluster, "ansible-running") + + ansible.run_bootstrap(config, cspec, cluster, ready_nodes) + + elif data['action'] in ['system-boot_configured']: + # Node has been booted after Ansible run and can begin hook runs + logger.info(f"Registering post-Ansible boot for host {data['hostname']}") + target_state = "booted-configured" + + host.set_boot_state(config, cspec, data, target_state) + sleep(1) + + all_nodes = db.get_nodes_in_cluster(config, cspec_cluster) + ready_nodes = [node for node in all_nodes if node.state == target_state] + + # Continue once all nodes are in the booted-configured state + logger.info(f"Ready: {len(ready_nodes)} All: {len(all_nodes)}") + if len(ready_nodes) >= len(all_nodes): + cluster = db.update_cluster_state(config, cspec_cluster, "hooks-running") + + hooks.run_hooks(config, cspec, cluster, ready_nodes) + + elif data['action'] in ['system-boot_completed']: + # Node has been fully configured and can be shut down for the final time + logger.info(f"Registering post-hooks boot for host {data['hostname']}") + target_state = "booted-completed" + + host.set_boot_state(config, cspec, data, target_state) + sleep(1) + + all_nodes = db.get_nodes_in_cluster(config, cspec_cluster) + ready_nodes = [node for node in all_nodes if node.state == target_state] + + logger.info(f"Ready: {len(ready_nodes)} All: {len(all_nodes)}") + if len(ready_nodes) >= len(all_nodes): + cluster = db.update_cluster_state(config, cspec_cluster, "completed") + + # Hosts will now power down ready for real activation in production diff --git a/bootstrap-daemon/pvcbootstrapd/lib/redfish.py b/bootstrap-daemon/pvcbootstrapd/lib/redfish.py new file mode 100755 index 0000000..d1079ee --- /dev/null +++ b/bootstrap-daemon/pvcbootstrapd/lib/redfish.py @@ -0,0 +1,785 @@ +#!/usr/bin/env python3 + +# redfish.py - PVC Cluster Auto-bootstrap Redfish libraries +# Part of the Parallel Virtual Cluster (PVC) system +# +# Copyright (C) 2018-2021 Joshua M. Boniface +# +# This program is free software: you can redistribute it and/or modify +# it under the terms of the GNU General Public License as published by +# the Free Software Foundation, version 3. +# +# This program is distributed in the hope that it will be useful, +# but WITHOUT ANY WARRANTY; without even the implied warranty of +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +# GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public License +# along with this program. If not, see . +# +############################################################################### + +# Refs: +# https://downloads.dell.com/manuals/all-products/esuprt_software/esuprt_it_ops_datcentr_mgmt/dell-management-solution-resources_white-papers11_en-us.pdf +# https://downloads.dell.com/solutions/dell-management-solution-resources/RESTfulSerConfig-using-iDRAC-REST%20API%28DTC%20copy%29.pdf + +import requests +import urllib3 +import json +import re +import math +from sys import stderr, argv +from time import sleep +from celery.utils.log import get_task_logger + +import pvcbootstrapd.lib.installer as installer +import pvcbootstrapd.lib.db as db + + +logger = get_task_logger(__name__) + + +# +# Helper Classes +# +class AuthenticationException(Exception): + def __init__(self, error=None, response=None): + if error is not None: + self.short_message = error + else: + self.short_message = "Generic authentication failure" + + if response is not None: + response.status_code = response.status_code + + rinfo = response.json()['error']['@Message.ExtendedInfo'][0] + if rinfo.get('Message') is not None: + self.full_message = rinfo['Message'] + self.res_message = rinfo['Resolution'] + self.severity = rinfo['Severity'] + self.message_id = rinfo['MessageId'] + else: + self.full_message = '' + self.res_message = '' + self.severity = 'Fatal' + self.message_id = rinfo['MessageId'] + else: + response.status_code = None + + def __str__(self): + if response.status_code is not None: + message = f"{self.short_message}: {self.full_message} {self.res_message} (HTTP Code: {response.status_code}, Severity: {self.severity}, ID: {self.message_id})" + else: + message = f"{self.short_message}" + return str(message) + + +class RedfishSession: + def __init__(self, host, username, password): + # Disable urllib3 warnings + urllib3.disable_warnings(urllib3.exceptions.InsecureRequestWarning) + + # Perform login + login_payload = { "UserName": username, "Password": password } + login_uri = f"{host}/redfish/v1/Sessions" + login_headers = {'content-type': 'application/json'} + + self.host = None + login_response = None + + tries = 1 + max_tries = 25 + while tries < max_tries: + logger.info(f"Trying to log in to Redfish ({tries}/{max_tries - 1})...") + try: + login_response = requests.post( + login_uri, + data=json.dumps(login_payload), + headers=login_headers, + verify=False, + timeout=5 + ) + break + except Exception as e: + sleep(2) + tries += 1 + + if login_response is None: + logger.error("Failed to log in to Redfish") + return + + if login_response.status_code not in [200, 201]: + raise AuthenticationException( + f"Login failed", + response=login_response + ) + logger.info(f"Logged in to Redfish at {host} successfully") + + self.host = host + self.token = login_response.headers.get('X-Auth-Token') + self.headers = { 'content-type': 'application/json', 'x-auth-token': self.token } + + logout_uri = login_response.headers.get('Location') + if re.match(r"^/", logout_uri): + self.logout_uri = f"{host}{logout_uri}" + else: + self.logout_uri = logout_uri + + def __del__(self): + if self.host is None: + return + + logout_headers = { "Content-Type": "application/json", "X-Auth-Token": self.token } + + logout_response = requests.delete( + self.logout_uri, + headers=logout_headers, + verify=False, + timeout=15 + ) + + if logout_response.status_code not in [200, 201]: + raise AuthenticationException( + f"Logout failed", + response=logout_response + ) + logger.info(f"Logged out of Redfish at {host} successfully") + + def get(self, uri): + url = f"{self.host}{uri}" + + response = requests.get(url, headers=self.headers, verify=False) + + if response.status_code in [200, 201]: + return response.json() + else: + rinfo = response.json()['error']['@Message.ExtendedInfo'][0] + if rinfo.get('Message') is not None: + message = f"{rinfo['Message']} {rinfo['Resolution']}" + severity = rinfo['Severity'] + message_id = rinfo['MessageId'] + else: + message = rinfo + severity = 'Error' + message_id = 'N/A' + logger.warn(f"! Error: GET request to {url} failed") + logger.warn(f"! HTTP Code: {response.status_code} Severity: {severity} ID: {message_id}") + logger.warn(f"! Details: {message}") + return None + + def delete(self, uri): + url = f"{self.host}{uri}" + + response = requests.delete(url, headers=self.headers, verify=False) + + if response.status_code in [200, 201]: + return response.json() + else: + rinfo = response.json()['error']['@Message.ExtendedInfo'][0] + if rinfo.get('Message') is not None: + message = f"{rinfo['Message']} {rinfo['Resolution']}" + severity = rinfo['Severity'] + message_id = rinfo['MessageId'] + else: + message = rinfo + severity = 'Error' + message_id = 'N/A' + + logger.warn(f"! Error: DELETE request to {url} failed") + logger.warn(f"! HTTP Code: {response.status_code} Severity: {severity} ID: {message_id}") + logger.warn(f"! Details: {message}") + return None + + def post(self, uri, data): + url = f"{self.host}{uri}" + payload = json.dumps(data) + + response = requests.post(url, data=payload, headers=self.headers, verify=False) + + if response.status_code in [200, 201]: + return response.json() + else: + rinfo = response.json()['error']['@Message.ExtendedInfo'][0] + if rinfo.get('Message') is not None: + message = f"{rinfo['Message']} {rinfo['Resolution']}" + severity = rinfo['Severity'] + message_id = rinfo['MessageId'] + else: + message = rinfo + severity = 'Error' + message_id = 'N/A' + + logger.warn(f"! Error: POST request to {url} failed") + logger.warn(f"! HTTP Code: {response.status_code} Severity: {severity} ID: {message_id}") + logger.warn(f"! Details: {message}") + return None + + def put(self, uri, data): + url = f"{self.host}{uri}" + payload = json.dumps(data) + + response = requests.put(url, data=payload, headers=self.headers, verify=False) + + if response.status_code in [200, 201]: + return response.json() + else: + rinfo = response.json()['error']['@Message.ExtendedInfo'][0] + if rinfo.get('Message') is not None: + message = f"{rinfo['Message']} {rinfo['Resolution']}" + severity = rinfo['Severity'] + message_id = rinfo['MessageId'] + else: + message = rinfo + severity = 'Error' + message_id = 'N/A' + + logger.warn(f"! Error: PUT request to {url} failed") + logger.warn(f"! HTTP Code: {response.status_code} Severity: {severity} ID: {message_id}") + logger.warn(f"! Details: {message}") + return None + + def patch(self, uri, data): + url = f"{self.host}{uri}" + payload = json.dumps(data) + + response = requests.patch(url, data=payload, headers=self.headers, verify=False) + + if response.status_code in [200, 201]: + return response.json() + else: + rinfo = response.json()['error']['@Message.ExtendedInfo'][0] + if rinfo.get('Message') is not None: + message = f"{rinfo['Message']} {rinfo['Resolution']}" + severity = rinfo['Severity'] + message_id = rinfo['MessageId'] + else: + message = rinfo + severity = 'Error' + message_id = 'N/A' + + logger.warn(f"! Error: PATCH request to {url} failed") + logger.warn(f"! HTTP Code: {response.status_code} Severity: {severity} ID: {message_id}") + logger.warn(f"! Details: {message}") + return None + + +# +# Helper functions +# +def format_bytes_tohuman(databytes): + """ + Format a string of bytes into a human-readable value (using base-1000) + """ + # Matrix of human-to-byte values + byte_unit_matrix = { + "B": 1, + "KB": 1000, + "MB": 1000 * 1000, + "GB": 1000 * 1000 * 1000, + "TB": 1000 * 1000 * 1000 * 1000, + "PB": 1000 * 1000 * 1000 * 1000 * 1000, + "EB": 1000 * 1000 * 1000 * 1000 * 1000 * 1000, + } + + datahuman = "" + for unit in sorted(byte_unit_matrix, key=byte_unit_matrix.get, reverse=True): + if unit in ['TB', 'PB', 'EB']: + # Handle the situation where we might want to round to integer values + # for some entries (2TB) but not others (e.g. 1.92TB). We round if the + # result is within +/- 2% of the integer value, otherwise we use two + # decimal places. + new_bytes = databytes / byte_unit_matrix[unit] + new_bytes_plustwopct = new_bytes * 1.02 + new_bytes_minustwopct = new_bytes * 0.98 + cieled_bytes = int(math.ceil(databytes / byte_unit_matrix[unit])) + rounded_bytes = round(databytes / byte_unit_matrix[unit], 2) + if cieled_bytes > new_bytes_minustwopct and cieled_bytes < new_bytes_plustwopct: + new_bytes = cieled_bytes + else: + new_bytes = rounded_bytes + + # Round up if 5 or more digits + if new_bytes > 999: + # We can jump down another level + continue + else: + # We're at the end, display with this size + datahuman = "{}{}".format(new_bytes, unit) + + return datahuman + + +def get_system_drive_target(session, cspec_node, storage_root): + """ + Determine the system drive target for the installer + """ + # Handle an invalid >2 number of system disks, use only first 2 + if len(cspec_node['config']['system_disks']) > 2: + cspec_drives = cspec_node['config']['system_disks'][0:2] + else: + cspec_drives = cspec_node['config']['system_disks'] + + # If we have no storage root, we just return the first entry from + # the cpsec_drives as-is and hope the administrator has the right + # format here. + if storage_root is None: + return cspec_drives[0] + # We proceed with Redfish configuration to determine the disks + else: + storage_detail = session.get(storage_root) + + # Grab a full list of drives + drive_list = list() + for storage_member in storage_detail['Members']: + storage_member_root = storage_member['@odata.id'] + storage_member_detail = session.get(storage_member_root) + for drive in storage_member_detail['Drives']: + drive_root = drive['@odata.id'] + drive_detail = session.get(drive_root) + drive_list.append(drive_detail) + + system_drives = list() + + # Iterate through each drive and include those that match + for cspec_drive in cspec_drives: + if re.match(r"^\/dev", cspec_drive) or re.match(r"^detect:", cspect_drive): + # We only match the first drive that has these conditions for use in the preseed config + logger.info("Found a drive with a 'detect:' string or Linux '/dev' path, using it for bootstrap.") + return cspec_drive + + # Match any chassis-ID spec drives + for drive in drive_list: + # Like "Disk.Bay.2:Enclosure.Internal.0-1:RAID.Integrated.1-1" + drive_name = drive['Id'].split(':')[0] + # Craft up the cspec version of this + cspec_drive_name = f"Drive.Bay.{cspec_drive}" + if drive_name == cspec_drive_name: + system_drives.append(drive) + + # We found a single drive, so determine its actual detect string + if len(system_drives) == 1: + logger.info("Found a single drive matching the requested chassis ID, using it as the system disk.") + + # Get the model's first word + drive_model = system_drives[0].get('Model', 'INVALID').split()[0] + # Get and convert the size in bytes value to human + drive_size_bytes = system_drives[0].get('CapacityBytes', 0) + drive_size_human = format_bytes_tohuman(drive_size_bytes) + # Get the drive ID out of all the valid entries + # How this works is that, for each non-array disk, we must find what position our exact disk is + # So for example, say we want disk 3 out of 4, and all 4 are the same size and model and not in + # another (RAID) volume. This will give us an index of 2. Then in the installer this will match + # the 3rd list entry from "lsscsi". This is probably an unneccessary hack, since people will + # probably just give the first disk if they want one, or 2 disks if they want a RAID-1, but this + # is here just in case + idx = 0 + for drive in drive_list: + list_drive_model = drive.get('Model', 'INVALID').split()[0] + list_drive_size_bytes = drive.get('CapacityBytes', 0) + list_drive_in_array = False if drive.get('Links', {}).get('Volumes', [''])[0].get('@odata.id').split('/')[-1] == drive.get('Id') else True + if drive_model == list_drive_model and drive_size_bytes == list_drive_size_bytes and not list_drive_in_array: + index = idx + idx += 1 + drive_id = index + + # Create the target string + system_drive_target = f"detect:{drive_model}:{drive_size_human}:{drive_id}" + + # We found two drives, so create a RAID-1 array then determine the volume's detect string + elif len(system_drives) == 2: + logger.info("Found two drives matching the requested chassis IDs, creating a RAID-1 and using it as the system disk.") + + drive_one = system_drives[0] + drive_one_id = drive_one.get('Id', 'INVALID') + drive_one_path = drive_one.get('@odata.id', 'INVALID') + drive_one_controller = drive_one_id.split(':')[-1] + drive_two = system_drives[1] + drive_two_id = drive_two.get('Id', 'INVALID') + drive_two_path = drive_two.get('@odata.id', 'INVALID') + drive_two_controller = drive_two_id.split(':')[-1] + + # Determine that the drives are on the same controller + if drive_one_controller != drive_two_controller: + logger.error("Two drives are not on the same controller; this should not happen") + return None + + # Get the controller details + controller_root = f"{storage_root}/{drive_one_controller}" + controller_detail = session.get(controller_root) + + # Get the name of the controller (for crafting the detect string) + controller_name = controller_detail.get('Name', 'INVALID').split()[0] + + # Get the volume root for the controller + controller_volume_root = controller_detail.get('Volumes', {}).get('@odata.id') + + # Get the pre-creation list of volumes on the controller + controller_volumes_pre = [volume['@odata.id'] for volume in session.get(controller_volume_root).get('Members', [])] + + # Create the RAID-1 volume + payload = { + "VolumeType": "Mirrored", + "Drives": [ + { + "@odata.id": drive_one_path + }, + { + "@odata.id": drive_two_path + } + ] + } + session.post(controller_volume_root, payload) + + # Wait for the volume to be created + new_volume_list = [] + while len(new_volume_list) < 1: + sleep(5) + controller_volumes_post = [volume['@odata.id'] for volume in session.get(controller_volume_root).get('Members', [])] + new_volume_list = list(set(controller_volumes_post).difference(controller_volumes_pre)) + new_volume_root = new_volume_list[0] + + # Get the IDX of the volume out of any others + volume_id = 0 + for idx, volume in enumerate(controller_volumes_post): + if volume == new_volume_root: + volume_id = idx + break + + # Get and convert the size in bytes value to human + volume_detail = session.get(new_volume_root) + volume_size_bytes = volume_detail.get('CapacityBytes', 0) + volume_size_human = format_bytes_tohuman(volume_size_bytes) + + # Create the target string + system_drive_target = f"detect:{controller_name}:{volume_size_human}:{volume_id}" + + # We found too few or too many drives, error + else: + system_drive_target = None + + return system_drive_target + +# +# Redfish Task functions +# +def set_indicator_state(session, system_root, redfish_vendor, state): + """ + Set the system indicator LED to the desired state (on/off) + """ + state_values_write = { + 'Dell': { + 'on': 'Blinking', + 'off': 'Off', + }, + 'default': { + 'on': 'Lit', + 'off': 'Off', + }, + } + + state_values_read = { + 'default': { + 'on': 'Lit', + 'off': 'Off', + }, + } + + try: + # Allow vendor-specific overrides + if redfish_vendor not in state_values_write: + redfish_vendor = "default" + # Allow nice names ("on"/"off") + if state in state_values_write[redfish_vendor]: + state = state_values_write[redfish_vendor][state] + + # Get current state + system_detail = session.get(system_root) + current_state = system_detail['IndicatorLED'] + except KeyError: + return False + + try: + state_read = state + # Allow vendor-specific overrides + if redfish_vendor not in state_values_read: + redfish_vendor = "default" + # Allow nice names ("on"/"off") + if state_read in state_values_read[redfish_vendor]: + state_read = state_values_read[redfish_vendor][state] + + if state_read == current_state: + return False + except KeyError: + return False + + session.patch( + system_root, + { "IndicatorLED": state } + ) + + return True + + +def set_power_state(session, system_root, redfish_vendor, state): + """ + Set the system power state to the desired state + """ + state_values = { + 'default': { + 'on': 'On', + 'off': 'ForceOff', + }, + } + + try: + # Allow vendor-specific overrides + if redfish_vendor not in state_values: + redfish_vendor = "default" + # Allow nice names ("on"/"off") + if state in state_values[redfish_vendor]: + state = state_values[redfish_vendor][state] + + # Get current state, target URI, and allowable values + system_detail = session.get(system_root) + current_state = system_detail['PowerState'] + power_root = system_detail['Actions']['#ComputerSystem.Reset']['target'] + power_choices = system_detail['Actions']['#ComputerSystem.Reset']['ResetType@Redfish.AllowableValues'] + except KeyError: + return False + + # Remap some namings so we can check the current state against the target state + if state in ['ForceOff']: + target_state = 'Off' + else: + target_state = state + + if target_state == current_state: + return False + + if state not in power_choices: + return False + + session.post( + power_root, + { "ResetType": state } + ) + + return True + + +def set_boot_override(session, system_root, redfish_vendor, target): + """ + Set the system boot override to the desired target + """ + try: + system_detail = session.get(system_root) + boot_targets = system_detail['Boot']['BootSourceOverrideSupported'] + except KeyError: + return False + + if target not in boot_targets: + return False + + session.patch( + system_root, + { "Boot": { "BootSourceOverrideTarget": target } } + ) + + return True + + +def check_redfish(config, data): + """ + Validate that a BMC is Redfish-capable + """ + headers = { "Content-Type": "application/json" } + logger.info("Checking for Redfish response...") + count = 0 + while True: + try: + count += 1 + if count > 30: + retcode = 500 + logger.warn("Aborted after 300s; device too slow or not booting.") + break + resp = requests.get(f"https://{data['ipaddr']}/redfish/v1", headers=headers, verify=False, timeout=10) + retcode = resp.retcode + break + except Exception: + logger.info(f"Attempt {count}...") + continue + + if retcode == 200: + return True + else: + return False + + +# +# Entry function +# +def redfish_init(config, cspec, data): + """ + Initialize a new node with Redfish + """ + bmc_ipaddr = data['ipaddr'] + bmc_macaddr = data['macaddr'] + bmc_host = f"https://{bmc_ipaddr}" + + cspec_node = cspec['bootstrap'][bmc_macaddr] + logger.debug(f"cspec_node = {cspec_node}") + + bmc_username = cspec_node['bmc']['username'] + bmc_password = cspec_node['bmc']['password'] + + host_macaddr = '' + host_ipaddr = '' + + cspec_cluster = cspec_node['node']['cluster'] + cspec_hostname = cspec_node['node']['hostname'] + cspec_nid = int(''.join(filter(str.isdigit, cspec_hostname))) + + cluster = db.get_cluster(config, name=cspec_cluster) + if cluster is None: + cluster = db.add_cluster(config, cspec_cluster, "provisioning") + logger.debug(cluster) + + node = db.get_node(config, cspec_cluster, name=cspec_hostname) + if node is None: + node = db.add_node(config, cspec_cluster, "characterizing", cspec_hostname, cspec_nid, bmc_macaddr, bmc_ipaddr, host_macaddr, host_ipaddr) + else: + node = db.update_node_addresses(config, cspec_cluster, cspec_hostname, bmc_macaddr, bmc_ipaddr, host_macaddr, host_ipaddr) + logger.debug(node) + + # Create the session and log in + session = RedfishSession(bmc_host, bmc_username, bmc_password) + if session.host is None: + logger.info("Aborting Redfish configuration; reboot BMC to try again.") + del session + return + + logger.info("Characterizing node...") + # Get Refish bases + redfish_base_root = '/redfish/v1' + redfish_base_detail = session.get(redfish_base_root) + + redfish_vendor = list(redfish_base_detail['Oem'].keys())[0] + redfish_name = redfish_base_detail['Name'] + redfish_version = redfish_base_detail['RedfishVersion'] + + systems_base_root = redfish_base_detail['Systems']['@odata.id'].rstrip('/') + systems_base_detail = session.get(systems_base_root) + + system_root = systems_base_detail['Members'][0]['@odata.id'].rstrip('/') + + # Force off the system and turn on the indicator + set_power_state(session, system_root, redfish_vendor, 'off') + set_indicator_state(session, system_root, redfish_vendor, 'on') + + # Get the system details + system_detail = session.get(system_root) + + system_sku = system_detail['SKU'].strip() + system_serial = system_detail['SerialNumber'].strip() + system_power_state = system_detail['PowerState'].strip() + system_indicator_state = system_detail['IndicatorLED'].strip() + system_health_state = system_detail['Status']['Health'].strip() + + # Walk down the EthernetInterfaces construct to get the bootstrap interface MAC address + try: + ethernet_root = system_detail['EthernetInterfaces']['@odata.id'].rstrip('/') + ethernet_detail = session.get(ethernet_root) + first_interface_root = ethernet_detail['Members'][0]['@odata.id'].rstrip('/') + first_interface_detail = session.get(first_interface_root) + # Something went wrong, so fall back + except KeyError: + first_interface_detail = dict() + + # Try to get the MAC address directly from the interface detail (Redfish standard) + if first_interface_detail.get('MACAddress') is not None: + bootstrap_mac_address = first_interface_detail['MACAddress'].strip().lower() + # Try to get the MAC address from the HostCorrelation->HostMACAddress (HP DL360x G8) + elif len(system_detail.get('HostCorrelation', {}).get('HostMACAddress', [])) > 0: + bootstrap_mac_address = system_detail['HostCorrelation']['HostMACAddress'][0].strip().lower() + # We can't find it, so use a dummy value + else: + logger.error("Could not find a valid MAC address for the bootstrap interface.") + return + + # Display the system details + logger.info("Found details from node characterization:") + logger.info(f"> System Manufacturer: {redfish_vendor}") + logger.info(f"> System Redfish Version: {redfish_version}") + logger.info(f"> System Redfish Name: {redfish_name}") + logger.info(f"> System SKU: {system_sku}") + logger.info(f"> System Serial: {system_serial}") + logger.info(f"> Power State: {system_power_state}") + logger.info(f"> Indicator LED: {system_indicator_state}") + logger.info(f"> Health State: {system_health_state}") + logger.info(f"> Bootstrap NIC MAC: {bootstrap_mac_address}") + + # Update node host MAC address + host_macaddr = bootstrap_mac_address + node = db.update_node_addresses(config, cspec_cluster, cspec_hostname, bmc_macaddr, bmc_ipaddr, host_macaddr, host_ipaddr) + logger.debug(node) + + logger.info("Determining system disk...") + storage_root = system_detail.get('Storage', {}).get('@odata.id') + system_drive_target = get_system_drive_target(session, cspec_node, storage_root) + if system_drive_target is None: + logger.error("No valid drives found; configure a single system drive as a 'detect:' string or Linux '/dev' path instead and try again.") + return + logger.info(f"Found system disk {system_drive_target}") + + # Create our preseed configuration + logger.info("Creating node boot configurations...") + installer.add_pxe(config, cspec_node, host_macaddr) + installer.add_preseed(config, cspec_node, host_macaddr, system_drive_target) + + # Adjust any BIOS settings + logger.info("Adjusting BIOS settings...") + bios_root = system_detail.get('Bios', {}).get('@odata.id') + if bios_root is not None: + bios_detail = session.get(bios_root) + bios_attributes = list(bios_detail['Attributes'].keys()) + for setting, value in cspec_node['bmc'].get('bios_settings', {}).items(): + if setting not in bios_attributes: + continue + + payload = { "Attributes": { setting: value } } + session.patch(f"{bios_root}/Settings", payload) + + # Set boot override to Pxe for the installer boot + logger.info("Setting temporary PXE boot...") + set_boot_override(session, system_root, redfish_vendor, 'Pxe') + + # Turn on the system + logger.info("Powering on node...") + set_power_state(session, system_root, redfish_vendor, 'on') + + node = db.update_node_state(config, cspec_cluster, cspec_hostname, 'pxe-booting') + + logger.info("Waiting for completion of node and cluster installation...") + # Wait for the system to install and be configured + while node.state != "booted-completed": + sleep(60) + # Keep the Redfish session alive + session.get(redfish_base_root) + # Refresh our node state + node = db.get_node(config, cspec_cluster, name=cspec_hostname) + + # Graceful shutdown of the machine + set_power_state(session, system_root, redfish_vendor, 'GracefulShutdown') + system_power_state = "On" + while system_power_state != "Off": + sleep(5) + # Refresh our power state from the system details + system_detail = session.get(system_root) + system_power_state = system_detail['PowerState'].strip() + + # Turn off the indicator to indicate bootstrap has completed + set_indicator_state(session, system_root, redfish_vendor, 'off') + + # We must delete the session + del session + return diff --git a/bootstrap-daemon/pvcbootstrapd/lib/tftp.py b/bootstrap-daemon/pvcbootstrapd/lib/tftp.py new file mode 100755 index 0000000..18cbb63 --- /dev/null +++ b/bootstrap-daemon/pvcbootstrapd/lib/tftp.py @@ -0,0 +1,45 @@ +#!/usr/bin/env python3 + +# tftp.py - PVC Cluster Auto-bootstrap TFTP preparation libraries +# Part of the Parallel Virtual Cluster (PVC) system +# +# Copyright (C) 2018-2021 Joshua M. Boniface +# +# This program is free software: you can redistribute it and/or modify +# it under the terms of the GNU General Public License as published by +# the Free Software Foundation, version 3. +# +# This program is distributed in the hope that it will be useful, +# but WITHOUT ANY WARRANTY; without even the implied warranty of +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +# GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public License +# along with this program. If not, see . +# +############################################################################### + +import os.path +import git +import yaml + +from celery.utils.log import get_task_logger + + +logger = get_task_logger(__name__) + + +def build_tftp_repository(config): + # Generate an installer config + os.system(f"{config['root_path']}/repo/pvc-installer/buildpxe.sh -o {config['tftp_root_path']} -u {config['deploy_user']}") + + +def init_tftp(config): + """ + Prepare a TFTP root + """ + if not os.patch.exists(config['tftp_root_path']): + os.makedirs(config['tftp_root_path']) + os.makedirs(config['tftp_host_path']) + + build_tftp_repository(config) diff --git a/bootstrap-daemon/requirements.txt b/bootstrap-daemon/requirements.txt new file mode 100644 index 0000000..5344efc --- /dev/null +++ b/bootstrap-daemon/requirements.txt @@ -0,0 +1,9 @@ +ansible +ansible_runner +pyyaml +gitpython +requests +flask +flask_restful +click +sqlite3 diff --git a/docs/images/pvcbootstrapd-net.png b/docs/images/pvcbootstrapd-net.png new file mode 100644 index 0000000000000000000000000000000000000000..ff2c2f5494e00cf3a49ec225abcd06ed533ab4f1 GIT binary patch literal 35211 zcmd?Rc|4Wv_dgnuDVa*XA+B(rTwQK31-a zh*C+$NaD9{J)h_E{ho9FIRBi#&hzr*cH8%Tt!rKDTGv|d^Q|M5Ls$zNC_p zL6Em+Bq=lmF5!M~sF%Nwzqi-l-zh07p$?*y4k~F{qckOz^-vn{kE*hQqN1|n-_Lva zdWZb;B2@)Nc!7*P3MHwGhAR{QkSH>ICu^v=sj0}qm0nm_khh&T(bzvyQVFZ7tgfJ} zhCE`7w>CAARKmb@kbj^ze8YKr28JS!c#%9}6#PTs<0usc6$NFuh4CYW2E&K28tMv) z3Mxt(iV7$d6#U}9Gr^)z3Lquiv-0rqAo>4~(U3`cM|$}FouIv%KgvEv-!DWBV_|2f zh(;UftN)!?v^OcjAGETqqyLPJJRC_0^Zt9+%RAcN69iF`R5k$Jdii_!l01UpBmV!W zFD6D=!&Ad9JldZ^iF7cv3RO||`}_6~517IBt1Uo-2SIw|CF-`3L{BwSC9H)CDkM12 zN6{BcHnoQv-V`MpC5>PkbsuZ>ATvBVGQ={7U|?%VA}XU$o)i^-2ZEo5rM+1w3YHOT zs3)m}4)C>Biw*Ho^ut(LnBd`tCj7>R;D-xQ3^w#M3~(^CCI48?m8{;AzO#=;M{54ILa7KE8mX=tOgCp81 zA~=|6Vi^==5o?DvRQfArBM1?WN{$X*1d2sOw7-fK#ow50s27d(3b0WL zqd1yc`rA5~*@uTkI)+*W;`J?6;U#*S{zQzo7slQUXO6Zan>jivD_T1S`>2G3Tf_!a zG!1N&jKWo57@|=W*4{SA5ND=n8)QidF~Mtu;mB6ls7Nqjv@O=tl&E53?yYYC3J0Vc>0t*Yj4979l#HIF8caX1saYD9F5w~Z+g z6RwU6cht~}3JXGehZ0CcbqwAhDn!*1hC=&BML8O%5Ufp237+~`mB{LMx=%6Tr zP%_2BmttWY91yG)t8W$@YTy+dxjj z8iq2!P$Iylu=cUGHcEOL0XRI?SBan&8SH~6I+~a$>Y*K#D0cS#=IVriXd7!sUy#88 zMTte(MJlTJ!fQx4T#&Caieinz2H6Jat3`NtT989EP-?L#6O5XtCDAU{+SVxA)=)`3 z97FMR@U{)G577+5hg(PZ1*wE;=xNvm*hib$1ezJEMiHWd48SK?M)>Pnk|RCrDX|ze zJ$pS;5Y|yK45TCn2B?_Bpt1g*W<(ADNIeq=4Wh4^pS~VR-BHh!0Kak|M_QUVpu_cS zElsS{?P6^8B8ibiv@J%_8x?F~8EI`|7aJC7)WlFQ;g)*())po) z-ablRzF54yEx{LSLG<>E#+#Bof}>20{0WFfgXbgr_>fR~it4sX-r+I+YW@};-qyzU z$^;Lbe=x~VB{bTKY)$m{vW8Cwm>4M<#5$5A(WZK^(&zw>Xp$pJ!3_M9>Loyz3s7AI`kF+(?^FovLeJFm>By+u3WmEN- zC|h+~WCZIVoSv~p09+|ss$f)O&Fmb_NfFAS7M6a>A;uK-a1!3oGFm^JM2-z`FtvGabe_GPY)9dFH4O; zMYI~YWF-Sn4Lwcs5DR@z4+{&s0NW@{b4@i9dwq*&Kcb>tfQLE-Lm>x|6+;vw;CR9M znh;H`!7pIFEVo^=p?S28eWbC64N=21$j-x9)iO9T*w)<3NZmv+%Eup(#vW$kL2y)# zM(iD~l|0FCVq(KJlsw^3LbkOUR>MQl!jNdJVjpc_7K+#k%FA3WARyM97^SHi;H4QB z5`tD&iSY&t!>UG^gldLZM`KkT0uB8fJkWT>Aa5HzRn;IvRYeUCM?B~RUWkfD zjA{%flwwZ`#u~&#co97uV#CoYmL`5^RTHcU#>2}-)ymN!2yJF-1G-SMj5ScSCEEF$ zL@d{VvnIRFo@Ht_ef7Kd1Ap123t8TMR8ecv6^V#6e8GTru@VcfQo8j;2?^OH zc`>VMlQKzOK71NltSn;d>FW1{xgX7EBc5um&c;6xYX3%w?S6agd*ji-v++ldeUG`m zj|={jHj&V!g)a`tu#Y|28Lqke#c4Q2XgKTDl6W{ye#}j29&WxJY4(2_2FAC4szRXDA`e??VPM#iM$^zqASZr!_5Ydi_q-n zI7e;0eAB^(QzU7I>l_t#pVgigd8A$pM%m|d!dnbRl!t52^5T8S6q4#0Ee0NR^%fc? z(&0r^XsL_O$P0eRBVjD?F(=2a! z9>HsY{LkMmm>@qemVuOBUfM~Bl+JpIgt<%~A4wRd7M(~4DJpi?g!}joM>?5lj*#4M z!*zq#o5l{vT3w`;mhu=D9VntIxH$G?^Gnk+@5Ph+ZR=bQo?zKu?A${7^?2uS#gSuo z+UC1h4BO3!(ie8yT(!=pXW{O%GC#5}!S9mUSqbwB?PMJ;W8wJae3ii0kLDY)`BaU5 z&W*|m$IT~AP?Ry8j71=zHBq|)5pVN{=gNeN zspl`RSm9iceOEo1oxM`t`{eB5mD1GVU+_B#hXyah_B)^T@sv~C2ba%#erS(hA5Yqw zMa5V*_&!yTHm}&-Dlo=-F2u7pr-sUJR8)2X1B2~3Qeljk)DuZv+1#-AQdE-j@#%r0 z=k4*wG{eRdi+$!sT9n*7cC(y}rL|TwLfC9?TQPEZ>d!5Z@HH*e^{Qc8TeKAA0}b`=-#6!IDFRb@w-~ zR{d7?d9?QQvUasVug?J0FmwMQg?q6p>$y~6ZL-C?+x}IHXBAwuc$Iy!sB(5@xYzp+ zxyl=4?#)l8XE6fhSKC~(U4)m)?o{lO*~k$*9H|ojwBpEd&3j8v4ljOh`oJuN4tQNF z8#5A)Yok_eu<2~no0O}W3dJuEF*Y4NgrgOsl74Pmvj~kFVl{L7nQAt=POvOao;vhZ z29>&A;&wcrQ_`sK^>ru7gv|}5@JanLZAwGX+Xe%l$ERzQ{=BktGd!*0Uu{{1J<#(Y zoz1QVOWuVY5FKZKdo+H%uO;GhwfA80>E5e0*Oqx;0UZa64_@2aoW1pQKsaIJJYj1z z=7V8-+^_23_jmYQmo|U@VCmA?wMXDG8!NkW)@;=XX#Va=p=tr|U-J*xrjrPXk>9+q_H~Qp)7rpEs?Guqt{n| z)N$s1wA__&Mp5ag-!qZ7ZIoNDA9A%PC!}Y1P6^GH;zjsC14HMY1QzUI%1c~f;!&6$ zR1++oE@yMP|7lmz{K+@kgsPy5a}i5;O4@E->sZky9$weme)*eB94^ga=jC1QS}&zm zUo<=GxVf=pUKE_+*Az0kd~2VaEgn`SO8<@10O}npO?rpU+IR|S@LqeXF}K5x>41JNu|i*?WL0tA%F0@({0uZODIJ>mV+8IQr#~?+-dzVYQ&r zadXCHbDclcRX-}`i(*&4e!*+djYODc{k*^O+DR+(M?ML!j&0_kP5Gufj|#}uQuTYL z`+?S-Zd6!WfaQ3FqF^o+?D_-YvW4hDel8~cQ?PR#rzkFnpQ%>^r&Id9&{}r2n=0N$ z$H_93>TG^i%jV~g4|NH#1h7o+)w$8d#lb_ypynFT@;V3hG{?`RyxpO)>1&us4&vhP zANP%Og^omeX`ZLrU9&aC*yXYF?Q}RXBQE-gUQ}L&znZ&htTf|GivqU!$miIBF9)YH zitewD9g8B$V%JbZOZhmVq5QZX{g>IjQ$JXPoUQ};!Z0NztHuDEUtpk-*225zfACEA zcH1YM5&2lI7F_V<#ihU@i{q&~U0O&69|spcC7z_aU;wV+;9{EsQ{E0H`*N7)qn}K6 z14l{@ft!hI?%(*e;xW74N! zSC@d!t#LQ*;RdeR)!jhnrsglGkC8DLPj;@H(m;GOZUCj#?$ytEguCi9&vl%0Q_Ny9 z$-IJ{*d2zM2ajAg-F-QsD{_7LOL?^bn~;n!+U`#9`-^PiPqmk_dTK*Qnk_%btbI&n z;7h%6ZjX>G?kz4yK(~^>6DkWuE)HyYoRm3eC76meDbng?(gnP3@;^+01Z{Fb4lp<#=vYUFmjJuOPRrnUh zYK)4WKNV?sdSvyCO7J`DE#Zkn86UAcOxQaduC!MSW}BO+_kYi|Y8maJJe1L-<2ipY z&*>>%S<2zl<8nJ`_sMk)X_RcQFOOhvwOQ(zNEZEh8TMG}0=Rd+isWWW8>;V&=B=KN z6q)G4u^R2 zpCazf)b~~IhU98iwWek0i^cTuyKHTe7{QR}&P&+UxxV7?!OP_=xW?1#%)*+LzX@_|C1E&GezQ(}e*G!d+hmzXF^y%ep zyOX55^wf1lN1=e87xsJpK|Dny>%010jdB2VvNS`*Wi^}P>riX<_D z*f@5zLk7q?slojwOV68^ku{Ts>jeIWU2rYoz6&JgwJww1ep(cs9!8#~;hcw^`Q*6X zb`&T9N47|iYbG*UkUoSnRXs#Y2yJG~;d)EWixrth$8K6GN%^vp`S#OrBez-B+Z06zUqC0uU?_wgaqNaO`)?_=Rzfe1LB4o|zJ zAW!2vAb8aLO^-aRp9j7oxt=16j8@M9lgQ>fWdKoOy$)Red7r1cJq=|D_a2`c&_=?& z4mNnYbrzV_lUY)_-GBh?9;ziweTMkV4bF>;QwJ?6r=?)%T@8s_fNjn*;ZLd2nLP*db+%#I;?Hpf;l~vy>t-KxC z_aatYEt`_R2tkqElZqp9>{oxZ|27jD#^;^pKInM)<&XDG=7ftTSGMNN2aedJsqB}t zHBoSDpDpal=2xF8b_!uCv#2NJFeG0vI5p5lS(1>F!oIr`Ea!IoSItOxuV69*yZ8%; zBc~gOT??P;Y;9Z&Ds=3%7)V<`qY;i4O4tbJRS!8c0>d9SXZ!gktXhCjdgNHNCS}p< z*(+VAds~~o)nDyoOWNf8`o-mQcg}UIOF4H;gMxxArcqUo=i`muY|Y2NZ;x*^DN~ZX zOrk%=UZZVK(9S^&X9PKACVnco+`Y|=hahfwfMvhJ-mC-1|Evtt;0AX-r{{5Y*;KMr0sm@PA%?l37&0A?n*}2x;psZ+uL; z2y3Qkx55N8GQ+i6D6mgZ2=)-P&|r9FGH^1-N>=&l-j^&IP=P*2icCUoqHYJmnVAsTaub7dDbcP zo+Ou)iA9dgH|feaF;GI$|A_MkR%=RJIkojClGwcs{^WDs;T6&imw&e}Doy`mCj-+T z&UmI!muELZ+ZNK4)*(`hd;Q98t2OdV!PH=hxnkz=)zKLK=u79Q{AmTe`N;mSVuTP< z=TVuY&Xe+wGWe4=pDNZ_B@$8+PNa9;a2C;Bju-kT;|&6CqK(cMh9m|Oocx?r+1(O(m#tEc|nZA zsed4*I8ak4ZC(ti#Fe~QEOJuT4nJJrskslk!De1$AulME@eke!k?e5=dtd z&rlU2uwU32?sPZuihx!m{-N+nH|9}C(#{nRnySGG3GI1ZTUgI)!(B3m$K-X-9hs2Z ztQLr;=ghj3$~bwRk&W{N^SGB`WFM zetCNfi1WqB=epikoZ5frYYKC*AA}U7ECpn)P&JJ% zHm8@LHEXu`keln~=I>C!Be*UM<3P4L?PYPS4{9JQ-|yu@(}&|PhTg&kA3UQO5vi|r zCUq!gKFLJve3t)aZxMYQ*uZ>|17ykEXUw6py)z&0t&UxrpwHuQ z<2rK0=I1`EJwvs&*H7p0h|@#*ml3?V@oU8%&$XFDB1UpFq=xaN%B~rKTg!(t)>0TB zSEEbF0c8mj9-mf?isa{HDXTzvrsb@y&J1Brye^@JzPoLRdxL7(N18h_#4dL9_y(CW zd$ZS?fLdq%$(W?8v0H+zR+0CavIl3SxHc`Cgl|{48)VlE`wiRrg zdUu0f$}Ya2$wwy-PRkq`(Pt$JllGq5ImP+76zm2dj)9gqImMPX3@5GC5M{4ngNo;f5l`rS?g`8wDmqP!WRX^*6x;~!d?f%19N@+e+Ski{>KL_GcSAz!)+ zt4RATAI#ach2))W*i*@PeZh5KPegobuWrSLp=RpK4~?Svfv;rh$TZ@n=N;U8!7bk=Ea_^NK1 zss+SflGhT$Jd@=H($yIKtm-D95`=%DiFi16}z}p(V!o9y;+yJS`8WFaR4+nF{$9 zcBDSFNO-w_SU0O#T4m>OO2_0u#x5MY58ZhN<*bU2k9Vw#>hl=mh%dDul{t>0;X1=* zOioG86T>SA@ja805q>8enxmMU6DS(ZzoO5`{7G6Qi}8En$;Y70yB`nJ@b)t5bUDwb z(S>Tv^9s$(NAL80AmRClZGM@}Eow!3M6!0LP@3pwg{BD2{SiHZj{HRtkp*@nU=9;S zkXJrI5{pM-kSGOI<&;Y~B`Cz!GY_9>=#-B~4aEZQr~CBu=>Whate z8g#OO&dB}>UDYBZP4c4&51I*;u?e{u@r>|Z%pSVE!F%@P1!Ud+n8X;BJWfgs`V#=*qPA15AjVNYm@rtvTQN`ixpD@u>YmdLcyfnmdT4)vn0<{I9du`1nrDnCp+ zPDCecwYEK(fl-@XR5D0eJIOB2S`_*1eiO$+C^Y7eBhUGnTfE+zt?HkVX3}`p>J-ul$~@u z;?Fy?)^QDSV}WI!D#8;w9{`rb8+4R&ci$1u8C8xEt=_#MU?QuYEVi_rxO@h8e7Mdu z*h;*c+p~J_;13VYP7BUz0T1S(5qc%+Vyy5fo~SH~-ug@UiIHx$InOn#- z|9_UG7A=Hf9|h#>#FDDzh|_!si-e_y|Sp^wx%23R`=|JTTntH=K<-1fx<6Ue=$ zca2XYDfoZC2v3gwE86yjr4(2TY3Kane?>;_%lZocD;jceo zgXDk#$;%+*!zw^&Ww_3*WU9Z=7_j&$BypO3d&{^&n^J9Y9$f%61gim$bQ9U>Xg|r~ z{Qv4GNO!zEv^^ivwElOEf!<4>9+LnC#3#|xOW56TF3^ndF)UZR&aBzJ@#FqhvCifi zCP!FD0TSz50vchubCAkW<~tdtC(?zBnfD#Q=ZhHxSp<4!;$_v-#3QytzP}o@<7_5P zXJ!fOxI%g<2AM%23}+0`L=6BU2PV!}L;l9py$MNGv1;IJ{8j5KD)#}?HiXn$#^LRp zy-~~e)AD!e+oy}2E;#LQJ^RlLHY+;-80Zrlpu=YIh(ht9rZ(Xla` zAN}R^Z2A{~`O}cik$x?DC%qRD*i|*xG#c&njKUKyQZwRrVb9ZC!rc5WpB2RZI;6lN z^FuGg3$Esg$4MYHr9+98ate;O@pof>+$c2e%@LGi3|^GLuR;arid^UHNQ;%oqWu^8 z#j}7~WLx3rI%M#NC--AI#3Qt95#`>0l!{^DG%OoX|?_&x&qb8q5QR7tbBcfF(VxM zC($~o1R*VDyGlLTn5d;&+dJN!7u-{yDm}JX^p^dxHUK*ETf;bSq^73>%3uVAjOiie+b~GC9_e>Z08_lo*`n=VmTw%S?N^pGII)hJo2!(q?^Nhu-}KlF5Qfo}QjjHU(k^ znSDoAN5nNFKD``rt*uXtZkzE>l5*{?I?65vIwa}sq`GSi~s5vxov*Cw67 z?PJ6i0Asf6l1P;#ko@$ts&PfaCdH+!8VSb6OnNwYP{dUC(PaS3QqRaDr8)pobvDvrdwxR&@IprOe2HtU?5rehN^8Th+<>vR7Oy8~9L8e5UC$G-7{GKr zOp*Q9E!!eIfDvY--W~bJH;I-{$QmHFb8;rKY<&CJ zpr)_+n`ZkoNZbdoFjpvjEhDY0fX?wY?Tz^dwth->MIHd9YEh!0x~Df>P7qQ#AcX(- z0IFw(U}>wk!$$`yz0@*g-}O;>{UXt8z3vl_|d~0zx@=NknsTyq=6YV}sqWJVI z%ikjek#%*H`OW4Z2!@pa>XlO|yf$cY%g5Az=)wu@Kg%!l!p~6|PMl=0{P%dO1(<#F z!|OGutExJCe|vr1HsHW;u{Ypli(s++^&StBiJ$>yF18E*9)0#;LK~l6cVKlWi&I07 z10Q9H_V%D5CJu^C_jV_Ix$XbLYvt=J!>>{rbzu`-1#)&bB+iCDEUYhk)+?M)Th2^h z2c{Y$Xd|jy2DL{3Hu?)rQSZ-B&L%ep zr6!H*2%PHdG%7m4B!nhZRtg!>uyO#b++;9CC&duRDl!W^Isa8_Ca5*xanin{z;C!Accb)da{eMD z>oBVAA&#LG^zCUX4_Wlk@gdc?+#h?UR#2NEkU(&(A~1$pDo( zNw@Ym1fTu#>RL${GQr%nkYiXxS~``;+6g8*A>D{xO1 zGsbA)(py=3S+~~c>jNsBuZ`0+Fc}e3edkG=fJDyRD5;n_IGy(f4vqmR)!z{Iq%Q>3 z7($hJ`A22^&$686k9;KxF3&k4Qk&gZpMw_}e09yvWXqv@gEI`sD-wogKId%ZsRy&CI8M)y@Y z`viWaKOlfnPZsY-7L@;Ui87sp_DmJ*0LO=%{4fdXwUE)fq}ewpR>LG}onxbsP~5y; znMU}9slT`l{?|p*axW<1#vTWBC-UWp^3A>BpCH26_wpFj>G{$~fXufX|8v)Me*$_S zTnO!vhtLnIR`MtkCI=pNTT?r;Qp0$|x>7ozOv3$AQf6AuV^Z(GVX_<~W?OZt>`i~3 zVb~D=Y#J)ooh-gg=OM}{xKM3&R?A<8S%M#`)eDlw#WTII$*3SQ5)Vw~rUO7ixAhb1 z0Gqf0(TO}Cq$cy_b8}iu^3><2m2T0qZ$v?bbv<>S^n7x7&8|>5c=mTbFseUE5R#V_ zx$;m8X4+I8x@&D z6%coQ%Vp(a%Inwyw--9cnrD?|T_R)IwH$)51is-_?&RS#n6bSaM^kQP*{xRCx zG$51uW;T_E$(e0Jvbj=ETXX`c7#mmZX4KK6Ks0tZdkI_0BxOhJ7GPt`py`z`&XV{T zhgY`^=G7+G@7WP+thv}dpakW%SBm>gxF2E-$s!%ha`v(F;9cxQaiz>%PW4^Jx4Y~V z=aZE#n4O2sC3BlBk2p1F^Km4SDx$4`d6Buv22A~F^`2!1vzU>}$la0suJ3K3W{Ar= ztr~byN21vS(+6y+tAmjqUQGPH)c&qX#)?tqgl)2`wku-;ZqN(tqVpurhZe*Pb`P*Y3u#Ey#rm< zuv`2}QKI>6&bdPJVEXU!a!#){;0PU<8oSThsRYYwoY^Z2=j~xyrVKOJytGjLd!=3lC{*feNP@C8@9Kz8*zLFbkWB>Y>0wyL;n!@+(4eS;i9~pWQS;A*s{+ zl|UW2x5`isCw0MOxDk}ubH;sWONVk@#@W-J-#ZrL5>FpK`KFPT3$^edU9!C=SGexH zoc($Fn^Sq;p``rv&JdIhM(0G9^P;+`o|Dp>!iR@FR0JvR)Ki4HPp-Xpe*-+jb|chX zh`H-~{VngaT2adfg`{dP!A5P~O)GFh6V=@0v8YunDG&A0xeDG#m>p8h;y<+@D@~(5 zG%9mvXSmP8c%(bg6qs1F+_?lHb`G|ANbh|U!Vc4P2ehw$y|%bA?Dp-sGmziXb8=Q^ z-&zSfF03y?mhw7^d=t$Q-SFU|5Tkcz<^d?BE>0P`Q0NX|vzrs?x<3!SqpuUt&y3`LR$`$YL;(B&-lJV1Bk(}6}3kJ!}(N9lL zpLE&D##E{z%+JpsVkv*@DEg%00(am|&$m6@kmof#_IsRcIdJ{0g8V)tP;AbIwYbgQ zJB3NTHGW-CpX0E5T6w)C$ETONUH7=8?tOk#W+i>C_u)fBI2o6dcCgXft8wq#!}x7x zxUNztJxr(Djg41HU%K~!>H(Xp)u@HiIxfE}4kn4cPDW>PJ2`h}i3po?<2K2R{ijv0 zao-FazTvn>8?S%B~#Kxx#Vva|CfxW8Jk>9WTStCOPUgke3+5?O98z0 z^QJg&HX7wD`$rX4-=Oz%|2(*-Hz=T%E&vL2ajVCqnK^+-m=m;ZZy)Ev&v zoPLC@zE$GWU7oUf`9Q!mBE9$;PSX84u_5k}n+6Qm8N6on&s1k|z0#Wxr0GV0X(yKR zONHkluFK1C_Ss4Dny&F<;vDPOuMV`FsF7whwa^D<7pic%uLZF&-`~}QucWgHxBEA= z=R0pq)9)eQN{s!O)NOZxin|~w5XoxPlEPPLvz@~7gLhyEX}eSrYlKU~IM7Ih-PjVM z8A_uQSD`D&j{Nk9wc-F zZ?K}x6xpPo5pHQP7<1gPzlk19dUcJxEBRz~Y1qj>q9RlF(_aB&xa;hp!a0zBL>|a@ z=CZliof_XyQ%RQ^Wxj1!e|`dfW!^T5uzD+xulu)MK0P$>CY?qpyVURgRa_&tQcCT%TNy{piH1H&eZ3wU`s|5JAT zzN~Ye-q-vjvtD{m35yyqap4B4UL8=or%*F;k+qkIU~-8Mwv!wSdDRT^cbpKV`*v~f zjh>9RJjYn-h64CiUIN_wd~7-P5aa3Fs~e56$H$2OIlN zhCMIO7NBTzYXq#S@uE{vcK^9!K1xCnj%GJs+> zPLbDhA9vQvI=A~31fkuELLY(PbLQSZG#+Nyu$xXEz#Qf?&Jj#~Z1(0J=VJEBGmM&g zBPv~1^%C-&QX#}p21Ye0$^~bhUp)b`_U{GGt3nO^^*(3CciHS*sU0GFgchbWNmGm< z4%(|;;v+&?4XnT{hYNOJ@iZs~YLD^H*|$-Vdi%ZAPRVxXr{CAHS0H6uQ( zJ(JrwD+bQBKkD+)yLx7B`lh?5M z3wdZI85ToAQ?UC5!JYd7mG-TbpdGk06z%Oy{->hd+Nlxm*EZaCm4uVs(%W|mEpi=ij8lb$! zMe(wyyJ%jikg|)lK*@Vx=1C1gY**1SqS!Z&#wgW{#0Nj&+uld}K#Q2bBFK!45cu-i zFW^$8MJwg*Io;77|Jw^{^Gd<*R3N}_jr{i76gDWw%U}P=bO3Uo{V(Kz2|WP_3?496 zZ>W+kz6-4DXF1fy9xJ7w1N29JB(wjLrVk8yDni5u%&17V_^=7|1{jfHzS9tKvYzCw z(Ux%5F8voj-_Fmgo4SCwBo%sZr8q?4CCtzN*}0@CU|Y@X7Ol##5k4GUn+5E#iuj*z z&pmDYnB>$H@``$ef^2>?S< zP=(Hi!2GMyDSLxzAS5(UmV9LG>)qGr8{GGh!)Qt%Wio`|cWAzVxn}2>!gLRQ6y66onv|G$9Qg36rL@zf6yn4>z zS&d}&fFfAGR`%+14?2J0%zI#?sO|---hsQx*>9mbujY|HZ7v&QpVFX(7`?j{ltI3! z2u!|E4}K>BWR_xh-0_mT2XzWoq{z2|f<0h;8A;|z#8wfFhdktaFT+ZKrtfquOtjbssPE6)C=ve9nUMBbAF77p2Jb|N&r=Uqi#o7w z?*vWQ*DHKs%QHiKpB7+SBdqP~b{!%{DsgLJyh>gfCTBEIlTmQ84e4r6CD4gXujT%y z3UtAA$KVT;!>Nw_ZgHaD-!~1Pl@o0O#N?JO%^&J6)CwTsujcu?`#lYc@X|(<>XYv` zV#CA3(_Wu@&=Y+u3Kf4nTDs|vbz^QlUq-`Jitm^|cGk{86YoWQa3WvTnI`;`y%I+P zF?bmm#_9Q0luJZ|vY0UnPAz0aW;>v*=e({jo6AjcwPU)yTCjL?SN~k5Z^e2g^{I;= zqrbVP=tb-iZ64Pce9Pw~IzmXtPNwP+CozZB`PM?-c-ajCih)xxH*sQBYbkT!469V) z=s{c-&-ug7?Q4^#_$~=P(Hg^YvkmGJuSW%~zW_WXJ}l!WMyO__kK4ypluPlWkE!g| zRzAsy()VZRH{C5^d{$fs%e4#IWppM|?mh8iQ)0@;QkdL(2Z5lbdvtTnQ`WY&G{n~W zl9}LWoOA)xw`+$0i2wAcOdLtnRs5gptD84KodGz&&W?MOLtax!MlFJ4oDj3czKHN> zeBAuBmA%UIY8J;=z)=BsHLix^m2ib1DeKnW)^mmaEd1@6ZLJ&{1B#$dgcIHc za8PI&$FU!2HPpiw%irG;^BJj?okm`LQ2rMBdylx?*;dctulAH>=8aH|EA+J6bh^skdo2V;`HF8Lm0S}y#;E)j{Q{GLWB%j zAdcHp6jFOS`56_+>*g_HjaC<^@2@lp*xUZqpk~cTk~)iR{~fwV%}?KR?_#O&qOG7D z&0BOL5_daAiuThhP3Rl7Fj^)U{8wVq@EE~9oCTgZ8rm7qfR};*wtRQ#+robbd2)<}$v!=ica`$( zWsc;@y>M(+EZB$H2>ea>QBoT^uuJOcKZC3_;-+{F*NOKQDlE; zHF_F~A$(fd=WRKGpu$@hVWzUvH}2KcPjbT(@ngxayz)&T-&5yRye0kbAZJ#&IqUb( zD9+n|6R2f_+tsR&Gg$V>#ph`Q3z+Z>8?k!hW`%o`Q8b- zT1-dQ@3yFb-U5BVcC`uB6v5&DuA0j+V~>Xi@yJK$ul0+SK^Z7S$=%2N-$68g9Q^;p zG`=vpTmru=h7wCIHemj=b;NrqCaAtry3MuzGkt{1)btfAbg{;VrIr}iv1!A#9~DnI z2LXv``?jz9SGeo6(EFBT(IZLQM!~;mLzI$mXQYAtm<b}^-XWy5BrrSG5Xmd4RGcVDSZo|NiuSjPpT$-lpOsCPZv)nW`d%*Du z%Aq&`77lSYW81w2&}sl}H6cyho|K(XrbO(G=Dw8nKgTZ-M&k}-=az=xl>`H5Z~Wkh zK*$2XW`O2TiWg-mfCFkU$d(kJH~1*|x6HpA3Uvqp{uV7DRbYT2Cql&r{}w&iq1J<7 zeYFQ+vmjzP#o0LEkr#^4Ae{rz4834`h!{D)9dDtxBWE()?^VC~`v87>pwZQPzS-L$ z@*Id49jaHnr2`j;fT6pQ2XtwpA(U!zI(4&+=I>+|6WzFk{tDoZg14PgWjw`o^sjKB zvJB0?n7Mv2*la@^rI8Ux`-lu2YZn$c|GqK}w8NiSSmpq@IVo5ZsN9WJ57}LDg9MND)iP0F&`8P zWce$`2)COJH}H*+GCIiv|1Jxe} z@kX8Urnitj5fJbR|IWYK83mcXzb49uB6JzVzQ%`B8U6}jp9OCtvUW|TLMsg7jnlV| z5cm9Di+ss(s{uA4ZJ8GrO$(t`G6>ni6g0HuAKX{Rt&+5xR|z3yR0CoE`DIISBqVQlaet!MZp^xdqVmi3hgE8RL#ms=t9uigf%n zM1CP4g^=5TC1Z00{FfY0*u`zXOlT}7!}l*uN54Y1jamr}7Zrd5qT zm89A2KGpH|mTwI}oDDHQT#>p9LguX9n2lBXYfRsoN~X7~)vKHtC5s@qA=2myZ2q~L ziM-P=ReLDbOFMc2NuX#C~vtxG}gZud(`s$DGIHh_`R zADsVCXfgznN?|3tQIV3Q4snX4IpZL-)rwKxUUoaRZ4kIWfqk_9SSwxxtFJh$-2H;w z?84aH-F+_UJHZ(5 zn`N(z`%TVw_cf@b-%TDDR1pXA;L9Yr_jwYV#6|5aP0N9sZF7(pM&f3mbV0(+gtft9;JjxNdcZ$VJym?4PY{yQy;ixsr(fXU41nj%0kHyNlpG)K36S{4U1=e^D}<{0 zKqAe~5th!x(^dnliGI`a$S7g!(lEUW`z`38w-E)*F-~JN>oeH(n=>8ITZUx9SqIr} z2?BwH_V)Uh?TN)xVPfXBTkfNi0DmGS&<9_9K>PTPPju{E1?r)$oed{V45i&!WIr?p zmH@iuhV-FS536*R{nPm`KeX{b{&WCuw9AjIN0;rok`ZS&5$Ot6KjOC4Y1RpeNFi+0 z)E5uQ(0iM>lX3pIyNUQ+!oU#apDunADiNUnDQMT?YP+yvwzaX8yUB9`>JAf}%ki6# zvt@3bd*=*xKt&En`2IlzI{fG0oK?Sg*0g95Xe;0DHpxAoSgB_wgdB7Xr;vK9%`S^-EV$VM`eSDZ_iR`{cSN z*55VZPt>0niK#zh$9^!mUPIEH?GB?WR+l8e&Xv6S*sr*>-qBupX@ykTWeL?8H|jKj zc;WJdh2lZ8f$#~I03WQJ0stTAY3Hx8h}?(2fABT74Isv1=o9lhs!<0Bh~sNW$4=dk zt%^fx`(WmS(71mis%tI=+fFl%Z(*!))+Z9H-<_fN_yCn+L=A7;#C>#WbD+mk{o+Yb z1DKiN@1Ni4PYoh&w`AaLQ)uO*Gn!UgKrO%e`T}%;+!c&~l)nbZZHoxF;Sw_{2^@+d zq^asE^f5QEa)bgErh=jKC=~l20m(+1FMj2fU4fJ-pFg0%Y2~`d5srbq;CRdDiWe@I zz(A#e4p`;N)$1NS`r?wgG3>o*XvR74f-$g#yl~-m;IP@#bU)APxY;*19oe)skS3{O zc?U71iAXY$U2G9b+h0<4eI2hGL(;`!8a7_2pcer|6$m@fQ|p%We#DUWut`LJ7*c+g ztJt-5)%N-U(DSon61$8P&!K=(fzbKJm!R%3)1lvGflg)h=`S#7-&_y;<5+n(#!Ncj zW5?%Qoy})&UIFXJP%CoAefDum3p8g*oYXz{TdzPVYQpfM@h>1F)MxM4*N@7Is$nlx0RlqJFuUQtY91fl=3!e>2%Zndz{Rd4B(=Zj;D%_ zlC8e*Ms{@UM$;~&?OpYV8@ph@B5Qp)uhy~gz$WwB!OJ$+iZj)#1tyZ$zIWXF31(Fc zp}`>1py#~%`S{}lP_NgGWTLw(tlt#*v*qp=LQeA+ZOWnyM^=IRGJmU%-pk%BUU7gD zUkuFxzsj$)4|dQ;+_NJ*`3xbScpm?hs7*hakT6|j7a7T??kh1;%TbX$&$ZFIs@Z(> zD27*?kP|U4zC*T`?Li9L(aYkCYkGK@>3{n4zeTZgE`7aL_jTvaYT=24GAvzDBGc_( zvm+G$PitQSP4(KgkG7D?HWg*qX4|aD%qH^~Wym~+lFT8MVJjiyCS@v988W2En1oDa ztW-#98_JQX3@QKnanAYP@4WA~*7slk^vUw;YNI=HiCgB)IZHQkRvUm554@xtgF$To+zbQLs=fI3oi z)y0*A?+2*vUJv|41s=BhCmNw|1mlJgV23-&%vVAbB%6oO<1+LHI)_|-OjT(az;bc2P$Hn6ijuiR7f8) zf~4)b8Aat!4-0dWTVCwXZ?#&-&6OKv4o~cbPH-s&8O8#CAg=FInxJ+)&q@sb zc`n zRUC8f3AmO#DihwX(|vumH^+86*40&gz~|Oc^N?Sam=Dz{u08E&;yQ=-O>BP>Qoyll zMO<`}V4VMi8c6F3Y!l%mK11qNgHfBCkP4RRK{;pGkRd@%avmk}w8ZeWVf0Nj#N-9H z98-#f)MI=Pqme|(vEl&qhPrM)etI-r+B$*pbla5+70r>x5!qyIP~yIC3bk-}8l&jk zzgWV;9G4_T=?SRTE$;Gb<_=Pm*J-XmCt|i+Y|WRjo6o}fsccgr2g6>YTQUQBh8dr) zaUUf1-!9K+nXMSN!tY#nsov9=(!PVti2ze{@S~I1$$~H*>Ce&*N<&}R01Cn%Qwx1UnN!tkDDn*aDF9F8AF99SEOZh z!!Lf93(Kex9Us}ESPrEN+gjR(Cyt0+Wsj!t^x`lrfG zvGn@(aO!bo=ax1;a#CPfNp$Uf`8TOjxishGt3>wwXM`~It`2H@C~``-&isoJN_du4 z?m%+&>w7Litra?p{yq!)n0tDhBL%0%f(tegcg;Q~L@oGC9Wa!F@z3A)BZ7b}Z&uub zrkGZoTx!N~qT6}&z48oj{l9Sah1Gqp@MOV4_X>6x- z3jag)Aud4nIMMj7ZA!%|`E!EOeA36CCKDE+Q`x*O;zq&K(nbL%PyZaP-ed2vJ-U2Lp% z+FST#M%Zd<0g?o{>?>VIbBvJl~pDbIJn~3Li+Na+@UQ== z_d-X6T3va)*f6uttE?nB3<8{%adR@(4MAt^%6s1EDjZQcJydjE{}Rwr1MKYPPQ(f{ z`WSgx5si{wm)o5&q>sKyzny^ZM+rE*c~}&rf{&52L`F~zkZ)`*h@JZm#pTcYZ=pGK zq6iqSAYcgi!&5i``)7PfLWHLgX-9=btnKrd%@#F)?w~5U5K{ojAqgd z)V$sPeJXd)#2u}?4AgPfAP2Kcu!r}6HxU1Qo7&fVq$)kJ-SGlVmCuBZ$hI11Tj*_P zlNXawE?h!VTk7Ns-5P@ga??hy?0All3D?tH-N$mDniE`-q1-IWtZ};UH~NYD!kl!I zB_h$OJpp>(-WtRPij3eGUA`Sqj zD(##RQ;9ny7ZMlWy!<%xM&v-~CV}vys(KnyS*AU4(nW70`=U{`(p%xIKw=Q3P~3hF?Hep7pA?fhtURnMVu3$yNL>p=%E zcvqUeJR+0cVD6VsIyl6Xp6nN&G|_RL@$}_lAU_X64|Pn2ijMCUt;th`#|lShRQN=4 zp18bNAeuFM4hh;#@4L+V1hD=#2M|c#x+SFH!KAOyYKvPQ&*X9XH43S%0W>nH$<19SZIwM;_|{I?HJo?K}Nwr>iRqqJ}@hJWWVuy)9t^r%BH-kt9m znTbWDEm5+eDs5YP*JJNAOzPA{0b&8}p$~L)fC|5h^ZO4uvxJ|DJC9X<**9*sQ=ha% zAZq*^byyQRa=P`s=k9Q)7Wz1;2_8@I%2H&Lb?MlhtrqJ z=o!9JZX~I=)F3wACF2_kWC&5%b-6_Phvuoi({8iE3kF7Wh7}oEH#cqdxXlrX#UTlDGd;jd5 zpA6h9{Q-%TuMgeop%K5bSgJc6UweU2G^cdPpm4vj1K^seUdc?Y7E@=f05U)4a!-2a71K4EHMs)=$!&s&k0=AQ?TeO0gscMD7rP>n4`I100^9R z9m~NyQsz)KXuN^Cmbk0OnzxAKoU&AC^QB**W3!=9>B0Iwu!kY~HlH#z&%NL9`Hm3J zdKe$nR(eBNjq3v~gij^@6N7w9hO!7%rkM_Nt-nqeOEKI(=h`dhv*KO{G zfmWb?kS4t@8ta_1_cgu`swAXn^PB1|K2`y(M4)yJZ$01SF6(V21yI4<Uq-2V3}8E6I1AAuGrbbs${*;hGhWz$>{5UbjVt$=v!H2A*ri~G)cZmXtE3p{t> zsED|enZh=9QV%Q#j?kB?H`H2RdON&Mz-aKa{8SfyxXEqskI@5|Wk%tr?QdG8hKnba zm;mDbMsuehbU;UYu53@Dj{!D-Osr&Gl(8ZVzM50r zw`YYf{*`5AxorB-Gwn0FR)Otrrqt#4(S3Dtxq8aW7)CpwTUUSdKwQJm8(Z2#|BN>@=^`WKGcMLTI zrsibj%QJu}&mBLVE+b6Eme!rERO>xAQS@-~=H1Cso3j$|hBc5={xwyukZL^!G@!Z6 z_u=wZ6H?C&BrhSJ5X6Q;C?w<}GQo>*xWwE*;39-dvkH5aUmPHQ9`lb;`}ezpl#nCn z*t0Vlg6@nh`?>&zAOYD_q12i3^ill&y|`Z)%til>?;F-8|lGK9gXZRpznqO*pT#aMZj>B{Z#lht2i%I5Hp~s`MY<4pakT zAGrlZx)AJa%k0M!IC*$JAyq`S@{U5}B?z7H&!rX3gJY_HX3bFL?B2=%&y(josti10 z!A+f?cT>@xe45B%zq(K4L??UNt_S-#AWx)uYaVRHhKWq`>s%kHatUM-(tdH#XhjT? zkOG4n#(OyxS=5S$90pGHX52|tXN;P^NpV11Hdq9(J4&dScM{r6&V$6!7K$G-eCk6^ ztr!4M#Jv9g*N-DS=#& z2%}&gBo0zf63}cu5UU-YTp9$5cJ}9MuPl)z2qL(co)-k9`V91+4i4=VA%~v?(f~r- zUXt7&$VDLOAj|}rbdJ)B$BYLj{$IbGHg09+lR+3f@6( ztm*)+Uc1?(2$mL4Gn0*zu=FMoU%J_6F%*6acthGiRvsq(0)4`?J^ z@O}WeXbNmLU+N!NUD=gltX}J#snN#sF{T2ntn!f12z4~N8U0Lv!v>tWUmc2fT{jtn zjBOqW@?#|^#~E4$*1oOF>D3AKKy};+en)xv`v4?N1yLiLzwDH=Jf&emYxhoMEhu|w z>`3v@{$mhfMi(Rx9NuK0{7qYZ96AcY+nBAx0-j7){d$!8xG?ga-1ZxxC zRPKE_ujoc{)_LcPl2_gx?@oQ0;BHMqEj#al^4Z7E?HwIoG<#u^DV2Mpo*H2RQ>kE8 zVc+BmOaEzZ8{ZZ(e>46lk8V)+N%4`E=T&U83lE=RfTR~g$VV+L=EocA+;w~5&@2{`Lj4*~mTwheu z$W^;M-Xvw^&*X!poHLkcijo%!Jn-Q$$?wz6L(h>Q{y0e8sYCvj#Q$wY{PfFq^Rsl- zG(B;yZgkxxKhbN;dMi(OEE!&LfbQ*{38_cH0fTAwgbe~d?pZC&2(%Whi# z*~v-@|7TA$q{X;(2YgiYPs=~s@gZwXe>bj^2(EBBzMf3WI11EaRi+w?zwu{p7)SZf zE^n=dnk)NX7sRmuIpLVcqLs~dzx(WfDW`QO;PievCRc03OUd3;Ih-n`CyIFic1xk6 z-u3uk4Bexew_r{EMVN3TGx2tpn%pT=}JxYT2?~WHJ0td7n9jPdRZrjMAY2j_ELH_V}+mN^5q1Fu*wp%NauDnc5 z)QHMks2@q^Z%A++J-K^^mgKhscZmMX_HW#O#g}b!3j&NTr~^JPe0;Y1q_6kk>Qnql z!j!}Zzz(&kIrrgZSFY0!c)tvakoxc2-}v>{w3lM0|2LhkPO&l|0s+auA~C?*)7izv zyc4Y7zK!ZXI0f%RNmm9QKOmB6A6W`7U{Zrly&xgSTV;Dyd=D)=Y(NZ*19_ncsJH`8 zQ6sPKh}*O{q5yO|BHfs8rWk{fYCw?kP~P?|jter#VZ3KlFFiFT^G44Mr#OOZ z6gFzb?L+p!z!)@F?u6ErK2+l;8hOa5O{csulV7i}?Pv|m*BcNpztq7Nidt+9wTuu( zD#1K!bw?b_&{8|tJ~m&oYB`41xd8c2jbvgiZNy`F_BZ!aK3vNI%&@S-V->{C0jnlq zs!+2b!6`Ju^&YtO6tRAV^a-s4IsQlzVnvdF1JITNoX9rIONijyBl+ZB%V7lZ!8#me z`~7djpKU|J7H%Sn?E%@-plm)`0H%l{WN3z^0+jUCI~?{|rp-zh{;-+;JBLp7vZXCS zYmPSE=4b{zq>$mV@X*&i_v_b5bKH!J-k!Ysz9hU9*T83^os4c!ITus)L37v92?i)2T?Ndu9pG!w(JwDX`K#48dS{(H-^Ls{2%j1{P_!!;a~^ zR56>UbH54P$H86Q)ezAPQD<>VZ@UIe?bkQ_=mYof6S#)b6jb1QUj}oCOyoQT z!%>+3LB1SPFyN@`-<0u8nHz7i0hK7DBsu9jWEq}@3NODGK%dJV5534Ob}Sh687CyE*`))B}2XxIuBk0qR=dVlV*wf@IXFJ3?2(nhZUKL zvZW+TA9%NaY@qLI?!l~XdV|*ykY@S~-ie(`-x~QqB-@A&qt5+wxGe>IQnm!atr#^O z^*5kf_ZgbVX158Hv+o|2LS8jovuWkSG} zd~*+Wx(Djv7`M|M6{z8STqX8xZ{jxhloV@(Arbp?zdrJNA7)I{=3E`6o1~qZ>2%dFo3Qg zmHs*qYRE_o0{nV?z)Q_rs=_A0B#|HCmDi&dzF8UjE=)Z21G%1lUG&B=DYHu;)5cpr zye9^Nt2YIgk)tSNh)eDJ9jxvNis_rt!aU&@FpWXKTp~2+m$K=IM4|FLQB+`d6h47 zkg-<7$LkoRQFjCVJQ5^yrHf}8f}?;=4KOjvo}V45R7Vaub)ZrH{(@E;(X{R{I0yRx z?w$?ge{Ix5Pg;Un0NKULe1ibn4K4)54Cf4g2x4b0IevSmRlWj-B~?>tyvPtafuwV9 zJ(#@#8xxo6J0?OGG`f<8BO})vh@JY#ka76E!V*;06nh9ZR% z0o1c;P&eI^pN3vM`0th;luZ*h)u{0vE8)=u(Flt&zj_(C0!u>wE(ysgri_6wW4?HW zbhO_gbXEWf407V+IFSF(j~(BL{rp4`qg+*$f~6(Ludv@89D)-U{;~N%^u-l$ey9%RlV~(q1}T%4Kt7}gc-=}PKzMeLHm7G)`Dz^ z(J=uUB9aU>kd)U+pVip*C91-r#Bfw&Y@kky?r-ETyX~5(KUjCNYi2wH%Z5pzK*5~} zX5L=4ktE0!6mpuTztP&MD{nz9@kufRLM`Xmm18b@3E+;rQq9Px-3hVmGt4^D$cR;T z+gCj{z2}{wAgKACE7h7n*OYXzkKf+qOxq}O1NYwT`>$|tJq-j>;&BlEQN$NJnFnTw z_^TwBLBUp>RBSAxg#&;%GLHaIAAE9oEA#Z*3I{c$yfMbE@axxAaX!r@fmi5_1MUel zBK&RfN4uqWjhC2@=khH8~TuSA^3Y^irB>t;j`l* zz`K9%6CHYW(YMmHs@Nj_!V2?elBD9xd5z!RAn}Fe0iQqA7`DzwHU9z&2k)8y+E~o6 zmg+}jQm?Ek6VQIR*s&vj8n`d}%W57tKBa=J<$4y-F{n8|;$!fa!F=MxVD5!^g*~27 z0q1w*yF3t1S8rPf>4I$Wk=`Q*&{mRXDyU?iYUcgi!sRA2kZA9cmPMUa(PKfrAkeCR z5PRtIR}vJ2)|MMBB^=mRR9`ESV-!^Vr{WRiMl^`r&8m0vP~q<_2qpn;`-%#f7lg>z zMYzrE%qnmtsjIe<&KP2}boBu(3(z~dc>(sFz(0J&oB)Mb(8iROI9}gCJRPeZlzYKa z*t)rJt*a1Ln{g<0@TuYLioGfP2p$p-!9DHHJGc3n(1uy)EMS^Q^fBvNRA%zwf-NB4 z^Z38MIGzj{#D8u8>&g-TN(3Of)#tm!wQ@T>KO!!wO~u0uNT91LEU$kCcvZ+PkwZL_ z)D_4rJA6Lt{xebe&)a~=md&-d{lCgKA(A9ue9+&ne{E&VAnJp2dd2FHN%PSPxEji{QfTxv4QXZ2}D#Z992Erp0X1<`vBBEC|#(OqQz`5{;xP;+G(&v zGAp$ZPh0sb-mdtUxg`Yl@%%=o5Df@Gyv2?UzMcL8oW+N%1_$`JYsb#=)@Q9aEZQhk zp&NNq!N16RUzF*&%O6DnQ@sJStFDire+QzddfF~0aa#YIsux3#Jzqwr_$;HHC*!=E zJJ}F_-r~Z8BfJ`TcRBcTy0&Y&f8%|UQ~!^6ADC+WosfzTvx&vJ&|yT$Ny{j?;x~@J z_4C%u$&wRzDA}?>A}4&w?5>&*B4u>lj!|DVqzDvqwTQ=fK}zFocoY(kziJxqI~|Uu z90oWRypD1(l&%4Or{33`m5ryygY5p$nb%?wj{%3YMkmSu+W6!e*xdXo0Jj;%F6Pn- z;KN#4l-m~P&!Z82y-m^M{5vz6I0fa>;Y#7XLbuggyHaU(J1mNwr%l%G>;l)~i~8#z zNky(EhrC9lJVz?;3?Aj!fJOuoFe(l(_uwEowO^Wg@ztlkjEimrNY|qoKLCJ#mRx5Q z6MhCl`Pr5{dFb$SJDC{P>2#}ON(%`k7q62(Eh9=a5GMoNSliNp4QU67;pp05t69-= zSP70)F+Ak{axQG5jEBxD14sf9(Q)3zd8XasuQFoatqE#!XsL{aacH-uOG&{j1=Fr@B`*F=YQ;h_5}9aBJj# zDzKEm&l2s?%#|w3TB8QMjkkcNpnOUBeIz{7J};JiUC9_IhXZ*}fk_(YNi_>NIRPh6 zHNsJb^pC!uIwp)KOgX?=%7+H7uk`Nbqj**1;nfL4V&038<57d#pwUDWzp;@x{4ChM z{8uTw?=0KC9$(B}4tX3LLj&<4~ie4AEoFyY10V;mo>= z7k}HCO8uI+h6s-b0k0dvb~bvKeq19T!=q^Z-CB`aVpzO~8IQ)R*hpSnx(v>d1ry7N z^~@ufZ;%a}kK7i&AUSqH>HMnPHPdfn*(%fLj~w25sRGNJ4(zj#kWg2m&cKO4YQUs; z&+&u{*9z^knq;6Vgq~JLhA>Eg1)pS{7W*BeWWRAE+~OoU5{X12>0Y|j3{>5YCsMX6 z9H#TUhV>7kDDp-V`v2g;wfPkKbMY>MY{e!hwAUbE?y^=(cr%d#jJwUY=6RxG+Nw z`*|y43RCZpa4ClEKgCf*Y+(tcWwYP}cw&E^cAh`~e)u#Uu3LrMc}pQic-5hIk?qgF zjh)3{$;n*mb0B2URFI^`;3z23FC=SIm~weCKC{=Mit*FYwEgo>vEkuv@b}ZHG5)7b zC`|1yTv_@12ZUg_{j(ab2t06qgsR`x1R9iwxDJi^lb#*CO zSz?Qei%bU(ikh05E<~V_n*go*jmb%8ys&UmRu+ezzJ5wsnHWRxsYLo1zYES00uqdW z&I2447cn?!76Nwlz}u8KboqA}F*tk_{7RDbCy?u!TQ>_Hk5As*3)V~dgzIM{;?9g*FdTDwpEGz5JWH~yI zZT5Le{p5>`9>=92;$9cdd)cKB*8lvLuy$bMHI(+k^%tmga7zohAiCKbM zw#57dFN}d<^>VKZtMh5Omw&&d4L*Ru9jk>YF~6Ym&tbQtQjcANU7;&KQB?#Ty8+eG z0aMh;M~r=iJyNo=<^j%c(iV_}W}l?Jm*zU4ky<_XJ#W$Pp~6kSz#ZkB8_LQIcQSAxZM;mbd8{An1R}SFEx(X^0LE|ryb}Nv zim|h^Ym?60g7Xu`Juu4udF2=uQ+p@I!-f%rN=yKgw@>KME>B8MxR4rf*PVx2-p5=6tMWbQC`;! zs)*Zk@hkB8W@D;%t%kHOIh5&^cBqCF_jd=*DZjrBI+iBg}-Q zj)Uir`Gll_!@#%iN-qSsK`G&uXZz&mr$n`QU58rlY=k;O=)s`^0AAZc0w?Mfsxr)H{vN$EBmMt8nBP4DB*SO8UDYodBaxw7+zIE3nzqx zc^}upQO<-FXGTiRI<2QIEPYIlOh3Fle0Ni+Gdn8N9$*(G&*Sp ze-i}`Zx9E@ciJ2K3r6U`9nV)KY5R|bw$iAul@t_cj)VF{bYmI#RmgP0kd^a(YyP9z z?+e1#uFO6M7$@}{DW62WD7dL1UbIMC-WIKX;2?@0nq*;5NeWCKqJio9kyTYi77{iW%h6K z6kV2waW;hLAqGAH>41x6s#WgX&E~i<4))221qWczWS(4r`F>b8QT3I0rrc}7iEa0s zmRaeDW~3-CD(sqCMC`7UDX&dd+FpFQ6}trY>j7Y)5CnUtUNsc0q(O8wfV7SA?7+Z4 zLJT80Atth(FcjVaZpkRDLBQ_;|6v~Yms!$yK}ZuH_)i`8IS?VrOf|Lk(aJ z_mIBz1>0%b@bHP$qK5#u-ku{n|D=WR zca1LZACvPN6D@)C^-F0Henw48OY2nOqx!6+_udUJViw_XxNc+fT+v1o+hz$GfgP(@oEfz*DF_!ir z?QIZT%T7zGLnp0Qm12zV_8)+B$!r0HzS;v4B4MbhcX!)M)S&%6JL5mYv{qethP%6a zrcqY?Y5QzpOX+)_d%*y^o+WXYYT#s~)btZT1UjFc zS6hiv$f$#+^Luqdt6~Vknjz6zznykryl}TueWEtLS7bEjiIPRS1BZ%=)MrFW$}24_ zFKSsH|McmTkz0bnd)N()#uq`TWA|M;Z*)xVwxH>6K&La6{eMO2XYTT3CD-pl&ZZe8 zRwMO+^z`&olO>A{(>WJPoWqI>MW%oTBo6i{vfO9Bz=z~e3hLdA)rhl&Y~{T3RpIkj z`I@XWaV)SmtV&T+SzyuXiMNdPlMMzV_EUl8%cN3f@-0fg5jp;;pOAL4R1k z1u}rlxp59tuDs4S{N1u?y3{r4kA}1SezhO9?1STmM6A!c0rptr7dv&el<;PSVa$K(o{J^z<|@F^I7(c#lO21RYz5_HZ<0<}5<^>tL5;CQKyxRh8Pw!6C{}%lcg&DZd zTjW*=CrczSv)tC&T%0X+6C_+DmjUiIo z;*UM>P2>mTv|!iSN4?{?vO&1sNc9~!NC#sSzKHX1g&!vk#Qgz3uF;|W*+_sN)0?)@ z&^|sIzSzQPH)~uOGek3$>0onrUHIJimZz zvdDb>EC=XO3R&8T4sVz)SYOmC4e%Hm;(kQTu~?rOEQ}Ka17RRCeWuP@qlkzRggsgF zp}&(%PTG=G>y+t7s8ksk+;b++K?YE{>#X>-8#y@=U0q!XdA5muZX()ff6B|w#V}cp*<#l~$h+>|ypL28}B`hTx z+Snf4F?w|ESY%GDr>%Wu4zd#K?Kr;#PVC(=jC`)(DtzPQqp)>9JzZTX-iyE%gPPf+ z`Hl6I^{Q>O8f0DfY^aPssgGIjS1{2b=@^$)$`IhgQKL)G18ojX5Ca^eNb%Nqgd+ z?QL}msyqCSf**J8;TWESF%dQD1&9K&3+yVmP1FKoRj$SVkimDzuVmA5m+ZdepS zpc~z1Q;ocQ#?A;S$hCZE663~rH-{&4Pqia^sp+hnzL9+U`B6F&WiQeNY0+F1n7gkPpBC@AQJtiui3S-+#hr?Cst5uZQ1dcJ#D?0V|d zMniM@u6> z0S8BB>U(*WbxGbm5a;j#v-yLb^8SNE(Cqvda&g_kmZ3N|W+`d1&>y|90x$lH=yXL eEjQl^wcVhYg literal 0 HcmV?d00001 diff --git a/docs/images/pvcbootstrapd-phy.png b/docs/images/pvcbootstrapd-phy.png new file mode 100644 index 0000000000000000000000000000000000000000..374730e7e1a6a14f4c957bca342e9f95fbc48923 GIT binary patch literal 60710 zcmeFZc{r4B|2JMzQOQzNRF*7dXUrhVGG;7e?1Ql+GiET0Va6Cswo;Lll3iMbP)%y0 zY?Y;j78PTOl2l}gBH5nvqVD^1e?Ir~&vX2~$MHLUzo+9!nz`n>&hve~*Vp^?o+Jl5 zOOZ9wYnClrCSq-6;k0bo3f{71%X5WRfmg=d*5Q{eTZ;-sxrfrj$$>P|G9?&t={F@^ z?EnTVR0(FGq^pafk%*y8MiBTFyiRBM1(E|veoOD^YU}D~=;&(b8oKBhD8bC&y5NT% zLQ`AM&|~R(Uw=~2?;F82wZRQ`y6fmD!OX#Lwt+$HaPV)q0m28Nw+sAc7930?xseE% zz)&S!G#sX{2}3|1!C1LqZIyJ9;CEUel?48=BoV0$=p%kiUyf!V16;17r>Un211}*1 zm<&3&2yLLRsjaD}YoM*Eqo)Jj`1elGIy#!L#pO8rl6{$he|Z|TNm8h<|I!A@juc&8 zDw1trhhZX!+H6z+8n?8uFcOm$2&A$oqd(7vJ{%emOj>%?j}#V21PcK|K>^wN1^W6k zed*wmz~ABv)Aev>MN+7d)+A&YL*GKjALYDs_aI-egT-4r010Y<)k8PYaSbI94HsS~@!Yoi&n1wGE z96g#2ewf=Zv3hBzvld-&Q}G5iDI zOiO1AnvIPs+m&X<39}))6U~Bg{*ew={^72ONHUA1L!ISha3<4c&U^KE09j333 z@wF#%2odlg6c#)+&_xHYXXD`DViss_i)4k6;UtC=(##cM?`%j2f=M5(6(q7 zdu9a65`01jsFk^&AHoW6YwqiS(+Onjktwb$ctilkGSDM}Lq^keBb+S#ZLDbqHf97T z5*?{Wr(0SE1&|$4`Z%V3kR6+@kA_E}SO_vFGQiy0)xidf$5Qnu1P2FrM4$r(W8-U$ zCF)SDNE~fE%GtpTg)(5$Ifm45yd%en?Q7r|tfS-L?@ls9=)hdeF=&b&1&i{= z(+#x_pa!GO&@`gHevliDKp-%6nH)0B#@UxZC9-k$L1p$1s{+A-Y0oy|QW$Q}*^yf(qcLf^?nFP!0mw+jnp zIxubRiMkwcg`O`B{A9sG{S7e=x*lc(rX!1KfCXz{;^+tqwj0Br8tM-&A!#$=kpw3{ z16R1aqpJ(r)=tO48C=PL`&)*>{2UzE9Dg=DjK>#+48_PPx7wzv9;T}qGL+XY(GhN*=PRvMq zwsr`HO3-Inzz8ra6v5ffI#N5_4aTxJ_eZ$7+xWRUq5a%(7=ITFUmS|NJAgp)MG-J8eQjIkP!gTtt3z?)u$ke(mPj%c zh0|uzEOoS<5h$#kOPDnp8)ATD+Uwe~>1;;zc29m;A+5}+D=Hbq|L^~RX#MI^l z(=cxS0c5=pl7|P{(Js)=1;w)BFbHP$5iox@0?`BIguw*|h8j5G!$aW~9EOV%i-BiE zx&o(x)}ye=IJTR6kVlAqs9yx!)|nIG$bu};+|b@e2W=364`I{8*%&6B9<1X)w80U> z%~3FPgfA=7nd87g(Co=U&MZ9M+}bLDW3}b zIhn&m+1Lc?BCTNXAamgD&He0f4pzE$;W%Bl@L)ePb`Z{rWE1RYV-^?@=tTDo*0nW5 zx&<)E5!T?g90yAl(chdzCL8FH*w8{;h)!rW!phIa3Wen8nCVfmI;c>*0g`U*!U{ED zx&|SA9e`5dJ@oXnso@+N(IcD!gS?=dJ%br;8%|>eqHz=w(bg)Ifj30xBP{XedKiRT zu$3J;m>j_|h$IHt(1P6=Oh=3r&X4V27s-hTHSqVRA}ygUyE+hQh8&CmmK_NT!CITq ztlaT-#BjQwU7%HjnRbYuA4S*Q!qFx&)F!|X1`Ed8nTH^l=K8MIB!V`MPH_w*!HHH@ zFatLVGX%|~qXP`Wh=z8MWG!JF16G8-xd+7(PsdZ~!4}%#C>=tig>N_x2@7`!3#AwY zkja+5PJuA9U_T}a?%|??wm_r9ZE$9We&kT1n+}>C$}|Kv$)E=5P;pdOKe9f@&PJCU z=3(iJHh0z`Ik3b1YzR18TNKvW*NLfPf`l%L&FU@2$-!cI9#-c3*8syY7v6B z4kEK6p}>g75;%q)FdKa$!QKz;7v`alA)-Mjg!XIi4DLXMK4?Q3c090bA;+8<*{AO?o`BMdCf z3|xY>BLgBSNNuu{nOlIFtp&osFx1@4F(^0?3qumMEn&zAZ8#i-Ah4Z~7+3IdLpKsK z#3K-6Z|3G}V`;;oV^MgLo29dhi>*J?o)F2fKw@k>EM3D494-6;^z6dfL9{Rmhv`qZ z4x~8*+SnjKzGd#laH3+tFKB(=ND{*VyrS)HX3z8uH=tV>ShMlLAjE(+)JJ2j~TcqTIBxXtE9yOE!o!#MxRIf)AUK zK=x+t=0?Z+`vv%hBcRiU4uj%qr5)^R6N=Gi*-+j6ku(n3-yxhsFb@c$QNjCmhOlr$ zJ8-cd_=_;Kb8>bJ3PAfI13f|*;dCrM97w{!63(JnN5Dz`{wP*3A(Ba=B3vDVLtr*2 zdxAeA1dYUyIQj^DpaIs-nPq@?_0Z#lP{NR|daSS@ggeI77MKfxV_*T2TMLlFK~MXg z#Vw|E;QzlfW*BPUOe1C4GPz~e7G^Ht`@WuCT_M>py|7w)r<{-t_rhjwLx3J1BbbuI zR}15=C7_6AJLII)#nuWPbG$)pDAI8)4fuNOZTdqu;>5%R%uR)a7XM?KE*{|e zaU7<$x8;PMo?c=X8Ns}2_500#U+J)1V2n4=k~=}lIdJ1(#^ovNoNeMbj5$%H8?IVu`ID{1=l(K zAIpjVE+)p6wh=mJ2BG6nN|F?Qs9E*(6Mk$Eg01Vff>y>`B{l-EhQ;!_(lP`|!Sd z2WziHO^rylIn0+o)x6hSHPsU}aChjM+Bv-8e`*kPbV}gV$fmS*FBTR5W&P13#76G<)q-ipb6 z|L~~i_^(!sR`!k)1`l|nU(26AOW;2{Yt%kFJMsLA_q{O5DSO$!3)`U$KmYxe zJ-N6bL-*AcEKIHRhB=Wg8}swR^hd4Oz{i7!ME3?f+dZT{@!_ONXYbsP>#?^ZERS#Y zy<(e9*cUYnFMk`>m0fbZrt|cByR*AHn0C9rD89OiQ-jg?+N}F4H)Z7p-F+ znxUbAzx)-WSy|7!fXzju(6bCeE`I5{bA9^rrIWTpZDlgC3j?`~&d9J1(k2Y;xzVVx z=hX2nFmZmDRn~Q{IOaBZIphicY zam3BrH6!KE_g-?&Psx9Fzhg50llY29_k;y?8ytd9ReU({YMqq8-%T<>L5`5SoZE0Q zNpk#|(Wu_S>?f0!PU>~KwXERAl21SYUkdlTxsAZ&Q1|Qbtimuhpcy67hj89hUrSUq*$v@7F z?&gfpgh}pwGnU&U>SrhK)ZWGipN;vL?)KHYn^8O0CgC6v9VeHzNp0lP$-R`v-_bJk z*PjKpO-4N@tc}WWk^)bo+gtUR{Z<(Fx%xD#Clz|gc-llYo+-bqnQRX6^$+?CYkGG3=@DjztB%*pMlQl9Ep z_dSSQ6Vcdez3j@+_1c~RwW;;PQ@yc_(HR0f-;i}hsoi4lk+{3sVyhHbSvUW3Pfuvh%& zuc7Nlr5^Q$pE|fn$>!C^OrId)MK8`>1HmL6SED#ea2*Z~ZsevM z%pZTfV=?ak*f}*={x1nQ>=2s$Vjp|+n}Lw=H1MOj!0YHw9^WiCJ9YD^CUu2(Pw+#L zHUcIX(|1s;s+`(>4e>%rs`rXIuYSG!D&gnq5<;Pk$G0FfpPVonsSr9X=KJI_Eno9{ z>z&>h>bYR!@kcvaBrxi}Nh8ryZ~f(N?1`GZ#h#c68}7_5f42MSs@Dl(CNp2l2Y!Ay zdFPwu`rV)9sKWWWq+{wlxI*n9I&v|sx}t(rwf;+Pw?*N`{`&$ldK0(X_my8x-L!qt zllPy-Nat(Sqq5I=-woy7SC6P(PFUOVQF7J3GjgfQuKUIjD4Ksu4hg~EzhcH?g_cQo z%*=2G-+cdEQoCxncc00^wEa$rDpfN%hkcjiZhThGr4b%~ou3(H00(A>xhv00?ZLU? z8&<76Z2Bt5Y6L_EbwciiyyB~b#T?Faoi$GF@V_!bd542_y$kc48Dlxcv;-6zgt+o4 zeADqQM99%oC6&I}`Yz1RX>bpl_9+~Ava66^Yo;0zad9j6E%T{H%h!(bVSPr;^p$9N zfzw~?Z+!y3lc%^_{X!hFsInHb8~DGLt0mVcJ}q^_TgIz8$hjT&s%H~i(r)N|V9tFh zJa>#wK?uc5EM}1KU4QZ54pxGZQzLY_JML6#lZDyxj<7Deh^w;z+_!q0eo)?=%=7iz zgX@-O@JDVuTt85^LR9bQwy>c6yPSJXVfoz@~DE+4&e>T?&HGu6TAq;4STXI zmZ>bnMlEa2C!R38qT?fWBQ?OQh^tKGD%EYwaL?bLz=xv2q;TWoG?lKfagLVwfnz+? za2I)$Ysxi+Mcu@0)RNTrccvRZD7Wloy~vh}9XCl&(S)_{Kdc}0=Da19-P)jHcPsYc znn;j5coOdQ#?0WSi1WFjoq>h;zGEd?oIvXe80Yf~c?7p059DFFP!Q}n`$MA5bx>yS zfr@G$quBWa6CjMf={dV+u;`NQouIeUNg8cEBX93{_F;_nBo70};or%lt0mLf7B&S^ zTNiWqgUL5?wEnd~U{R?r3iBhcz7*+rxQx@keNSW-o!8O$eelgwG5D5?!r1`TuFv=s zJyQ8;`vg#N&vwG29n()M6)d^@))TDfd)hNlE`CpxUTnN9rBAr1H1So8ogX<^JdmQ_ zqa8I;S$O}KG05Yn+#iV=j%VCF0+oh>ux~TH!?LS$lUKS)bw!?u{871U>5P$oJ!1pG zil{aC{+dz~-wS(y*ju0gD?GsG5?geisuO=r4pW6SE~n0v9o-&T#QvdVuwmqBs{M0% zhtEDQH^0#?$4lsrdpz0b@28@hGTz}1trEG}Mj9-LnKy~Q1XNFy_4EBvPl2cQC;3iN zoP;kbHbxoVLVK2%+!#{@)!NvCI8=YUIq;W??YCiUlwK61`Pv)O{}$v@O$V-kKBWFX z_Mtasb%k;+g#ziSOGgM#HZ3Q&G(R}J7B+kia=TXq3ZE=V@%(0?^K!QWUOrHFzj1!E zi0f~|meUuy5u3l&d7CtIh0yT^WS^QcforwLT%Z97(dbt!R-uTpqtqw`p8J0)|;QClGE z-ptE`I#C8|o{m}agoA6AyB)LkjxT+-SXfZRmb=Xyg*G8#r^5cdsMFAWtUH6Ee~UUu zJoq+P{xSaD^aF1+mxNGhQI}3QjnRI+b16|uJRVmvhlDEKo2jaomY)AwRN&giv|ncK zdzLn)3~damX*=^A2Y-iCMRVvrMK6E3FRd?c$2-abbf9d_S<3Ij?-vDY79Jho1-w*< zjqAURI*xI+{+W*Z%G5ngIU-i%E$B5YtH2|**Iv<2?Uc0sVf%ZpTcFR?(~^`jv}a4h z20O|Nx9IvM0;fk;y+&!hY)$_B;=(|ZN`6tr@tv}fYdkj+)MlkD^;BaV8_grYiSERl z|GJzcHB?cn1a9Ais&`Fu`+aLroOcBfH3^=ct5>{4dsl+11Au53Wm!hP@;g$-H;4rn zWIZCts2_LKIPpMhON_@FaHZ9WKfDGy8~yGlyL>k^b_PruKciYT5Gj#rTTEjEn@vko##;Y5!3A9rkgW&1`r zKF8ws9X-=F*qoJs6iz7K4^l3R=F{S^_nGTz{mRikYnRI}`+ZuTEvA2R;beKB7~c{* z_Rf5D{^2;?m#pO!HBv}yI)P)1p5^oeN;Y0OJ+{_TWlaoD)&eIdIJoSOc5SoOVmmI0 zt`E{KaFYb#4Sk5pi?e5qICirqhMTitYFCX$EN6!A_;hgO5BnHgbsS4JQhoxIu&(cq zw!>xrgi7@zahQh7sAMUUuvfJR{`I%S9Q&VdWCRAUi#=Mu+-)coQtB|LYdOCyQ(LIQ z#nytRb|g*e_$$vF+^vMPR6gag58-Nb~?J!i8 zAp|8b`JP&Y-91@Vd!dcXm%B}1fzj}UCXn={%q{-7_@Ae1j9lwC9F8e6mUj>o^lH(E zOh=(v^!9H->Z0ok2nt~Bxx9*d|KC`ob!Yt~w`n`9i&0x$`6)lD8PxC{iT$94ph39K z&xo=6t8+p6)|JP4W;i)o?*AOIV)c4GfYw}}2HA8ArKF7f>&KA49VnL?&;)?G41nxZ zU;k}r8ve%q_-UwQy9TfZfSKgJMr#a)TeNH{^nKI#yf@?iq1CxM#Kx@WCJV-P8=el7 ztW8#KIl6boNuv=1)*GB#Hb8otrmG%T{eIwzJCweuH*P-J zpx%4}fl55Q0@$i0*y{Y!Rx=fNCz3Q)XcOv%Si`s5rR^e&*n@udky-#qbU9>aA%5hB zF)cvwwR^0^qTEyCGoOT8Bsq5N$dA~ zcYv`5Y{k0_4qd7;mpdxtLfm$&6)W!9RG-l@F>-H|S0DBYs}F~u!V1$lU=jl_EoD=5 zkKmq{&y3v5g=#7Y0pboya8p)h>H_aCC&)YuIoOMOUf)ETac9&HUo>M_JG3mb)(*I zi;E$6ip=f~`x=npP7v-=>=dp1c>Y|}ldWQxPhE}2NDn)0F+VRQzUXeZNqE|^?}ZIh zfGaR8e~FfX^ZJ2%fZyq6CL4k}Q6zT;cna!B)r8&56i9&iUI6Waz|*ku2DlKRc_4Xc z<8qyz@DC!d3hiZOx&`j!Z-J5BGmExyx?g650IZX*BAf%Kk}n|$I?BgBfP2$V>>k`X z0g9mWY%E<3OHA>v@OP7KEe+5HMn2hqR*$q9(@KC;H?=IsUEj|5e;aIyYT4Yn|1R0M@-plIY0XqgS?Z$q!s}BIF`s=6N8M@b^38Ce*(no>Gc* zj8r8IrSj*88L{Ou{ju{C=U%wJQ)WL_%5*dTu;n zI|0B^JR$ks_z{_)fQ2LX)~h_BHCDKNt1wRbBpmK6dO8WmDZAZv^QE+Pg(u|q$lVno zyzO>b))nT@&zba|_A%j#%xqU!`|U@~!uzALUtg_ukNwcolA=)YWXDqG`vwJV5Wy|e zbm};>9Xg(;SKdq)qbmCS)nA|Pv|Nn+Y%5yCqq!{N3GNi-p+wvBxvAdXyC$a+d5NfW zh8!=Iu>FKe#DYk1z0*)SW|_)pZHWDVjF4KA<>z~$UkDnd?hN_bg2(o>hc&h1Pt;oC zS8oqku|J|1;O_(AR-3qGb3ZV9K*Df-)l#;gsp+ujy`(pGDBn}`8l>01@yT2YTF;FRMgtI^g~tds>p+(eT^80odWh=p)XOBG3v{AO?EL%Wa|5> zCZ3ff@|o8&87kNuza*6(5(dYNkYWK|`JzT&wOI|4ZtfB-+dRF_2Ci`J1#6N*#qH`Y zd3-bqruoV}_~S9J1SPAbEK2u(Q{I|4>ZA&YTd0pf`Q9EyS^RC(SBLS-GI{4Rlh{wtN-v&H){t8>mF!u-6@(!m(Y z@law8f3ms3wST18S>EzD8G`gQVfq4MsTE|}xRl9)4xbdqZ9Ff`#3f&Br+~nzThNu50aRQ$0WHuRfhBm$lV1ny2`b4>GB)UhQf2djpTG z+d}AlUKU1aE6t8(TJ4e*GObW7Og@R~WO^v(;a68p-73*22>jqRJULK&;7?-Cy8pM8 z0&#}LB=R#3TW!fPJ#Upz@@Ta->H)rPXl_fzxB>lAogk{lg# zF_Atdb~%OhHC}UU^&hbmp7>{S|8-W3tFiW!ZX&-iBmS0fCUi_RdG(3-rHAoc|B~g8 z$hPF_uf9k|)$Ov8dG*x_nLkRAvOcA8GueOR1?T)=LB+xjv1lFBR?gwU zA1;6bbx-2nlV1IyziTaxiN94lT>=}rd>FUyR(^P9q(6w(P=QxG0=DSoqjd!#2vf5S+Yn7seEx^?@CM5wY%(^oVX4*an7!jqiG zeZOrYN}=*^Mblba+N&^<`U8ukR`h#`l?7kN1B?%Hl_@?sz>kdIOiLYXQ}j}8YA+xN za9ei&`0`4{HT@myLyCUmFXfcxk8L81?$#nTyDhg5`sD3ZyAHD8`$84nCL1LUy;ND- zB=HII;qMYKH5vF6fVg0iHge0hMguVBqlVq&$JfQqA`2I274K3UPx}tc_KEmLE?wFPPutXBxq3zVb9nSFL5c`erK|Hm z?$YU{tKc*(?exzD7A(RNaWxRsB-Qnu1pUy_a7ltL*Zj-n;z090Se;zIs_%S3mHBxd z1RXsh064UzMP0o3fJkv8vc9dr;uzocM2%X*<#8#M8K-*NpGrtm2y>82rvK7~eq>2q zwSX?q{LAHuWuW4?43-`8!fBtpLl=Yz_;J%4cmw2&M39L- zIW2k@gptUfzYaiy)CNTK7U+lVTHHnGa?HOk_o;W4>N04(bST~+08~~*bO=zo$$vud zWWg{Nsy@i8-^94=U8g{Y?b4{Tn5x!gQ=jdiJ$A+Z+}=~3#-N1@i<$lTXqvj`(pbq4 zao2?eQ)9sw3sRb1n@2AtRHA4@as0gi|0DxQTwBAFcgz0$Eo%F-uOQ%&K_r5jGe>HH z4o?n%v_+d{JAZ4klbU;Cn^BJcx#+g}$jPrAZxK%JcA9m9W-WToUK=`?RV{OytXwVK&+ z3=5=AS)k*S4d@7JB#U`Bug(NDpyYKCAcH4=|NN3XKRX?kB5f2_ijVwK;M`zD_j01= zt$8XbaMM6pW<3CkOrinkZps8IHh14IW@bl!UMUOQ}5B1u-e|q9;3&&woju zN%on20AyuE2AS=xSkWE4kf)ot*qUX2j^^-04P7^l%3mObXaTq$nX~{lUP>i+V)H;+ z8x(c^2LRB!9wOG)y8AraGu7?V;8c&m8Bp(PiH$MO^ zLKkp5Qj~a^`yz{{-yITdo_KD;$nc4YNPYsUf*=5Y!5)%Va?b)HM7&(=_m`Ge*h6h8 zkE%h6Gyvih*P`y+&P@W{pq&d51v+-;g8K0|E@8<=oM#_VNZ^jzR70 z_|pMU8t8e_xQ8Vl*3N#^8URHo9AFpDR|&faxvF_^@2o`p&G(WqkH=oMgMh4P30M&z zy&Fk48orfQ`R?G_=4^V$d$Hf(%21N`>lC71qBdoNzGtgM*YXvsvOs&N z@vge1^_i$|4V!YI&M7$VhgI{xhR7hrT6de@sNqwOc(SwNxw8l%_pq1z#1A`Kd0j`E z!!^sVpq3i|ybn8E0E*^(xcti64LTS^6@+a5@&HI;Kj^%*33K0uG;PCn@#q@9XJP&) zaB_^QZ|E7LlYDamR6XoF@C`N5&3c{Hc5g*4{fDq8u ziaG0h?GYrn6x}r=697t3IP@k%O}uMiTR2X}UorGis{BB4ctkV8DZLyq97Qr{Na6xLG}F);pAOJ9)PccS!M8~}oHCils^cBUXY zA9)1tAq-V215Bjll;U%rk^fSdFRnyy-7^?2jqmDw&4RXI!Yz|}Ml)488+v+r?4f82 z)Me_t6_|Fn3Sfup16!na5;AB3hkbNszuyMY;4x@#lpzV2OsJo@JM{DZ#Q9^%H~h1= z=mn&Tj9Y}Z>i2{{?1`92)JVwO+33D+x(x$#_*x|ZlSIVr=0G_xJqJ-fgnxk6Vj$oU zr#D-Y<_shr01X_TC@##W0RI#;`bJ`1skC)HPr9g$oDJ~hM%+)O zhxU-SO$FVluHA|}<1#?paLX#WcK6AuXa&_`OIj~z*ez0ou=;Obi{1VX0dR`ED%9;^ zURP(F)`8@elYl+I6+gwjn-}~*7%Sm9U-8D(v*Wxm(BN4@JtAmYf%kY*oVraBD3mh1 zlK7f7v{#MOU{N=ztB(3()VUUKEF9~3loxGY_rao$xcuj$i6@|fVKph zuZK`xr>2c!KLiZ}^D7tPeq?|}Rx91D5P6no_^OoKD7~r#^WxHEfs|*Bio_rU@eHkx zY(m)mS;?b={42ZMs$L$bTfUk<^VwwXds_5DcHxb&{Z_C7Y(=Z)_0EY*_y-_be8OvB zM|UT0sJEO!Xa@4Iq>pQt19$O3{y*J?SXV#6sZ^p>*{NYLdfubto6z>OTf%OgA3xfk zR;8W_E?##ha@GcDW6|2bY9jz_y^b+m4}u`H%HmHD^1kR(dKcAvIwcdJ|L34ED`&Xa z+Lb-uZ@U6dQ^~2mP3c#|RZno+a1izXt>pjrw!qT=e<*}|5`+wt=sosO zMuqgR4Ae1a(K(w-4E%Qt8`S0w>lVAb$@0ZI9=jAISCp>1Ninvd!Nkg6s9Mk#mF|N? zmwIHT)O5+m8j{ZXt4QF*|HVv5d1)hFym>z<6$kV*H$E$ge^;;)J$Q{Y?)EggMEskx zKGe-xzSx`HSijQ;m1q@cJboBd4o|vwr@`xS^|5sc^w;sPP)}wFaYUUir&v zA)eD-v3KX?hi*MS5lwKL?tA!w7@O9=A{bv0?0Z^4YPxOZvtoG7v6TfWEXmxf7q{(j zSX|72JI$pUcyB{<5N+$~+g3*8PG7&b4kYU*-cISvKHY8o___4Av0q+~z96-1;iA=J zA%0@>6?pxLrWV(fJd?8HflrFp<{bsK>(5Pak?qF(JkXk+V3&)erPWH} z8L3DYaDZlqR=tt29b}k^6)hf(T4H!{HpmeC7TLaZb)APEYb#T7ZnOcU9EF)~1zSOA zDCTNf)+1!{a2SNpYu&~3-?8l~3Y@>fA~Qt>V@FzqgN>leW!|A^<@fQo{SKLGq}6(i zcp_Rac!1Lf$O8oYbNgMSy4-_zmG1xtT)uqY|H+M)^=l<>EX-f5ft0WzNpxv8I*{f1 z!y+(w9Ma_ji@HO!=Bo3!@0`e%KuqKnRf%+jK}klZ*?EbB*{h~mIL7etyhsI*nTjtG z15%U>Ualf6wIa4AK`6nGu)NP>}o-n zSTIW4`;Dj3j>3Fs&4Np7eq8)t*IXxgKlJ}D_2^X_U`jN$X=JAUDl+@9sS^-q zn!@JcDA0X3*p(?Zwj}P7Q=33tD&&{6h*_vdBvS$Em9p}>ZXtA#Hl`W7&`SzAEcfo% z{<~N2grV*BfPN8x;s6dL&qHmlSMTC4oM%HdxZ|BF`p-f|!J8KQ)3%Aia=-FbnCV)3 zjh|Kh90NsO`eOUlL0ACdHvtUbSEt@$0eE2i_G4Ui`u@v|#Rk|exfkk(b(xM9Euo5= z0y6aa-X4tc@XAve=G<0il!#&2@=RZtqrK z$M6%?7qJa z&-rAe;2B=R50&&@v@8T)ftPJoc8mg=)QhH~O&&Z1OvSuT3HqFcPd)G0yQ`mH11rOd zJYlX(;%6YOVmArwU9uL+*ixrnZVR~j@fdZSD&D1fu;ijMpmHPNJD*A_5~oV6Z_RdG!+nRB3cL}LX?@$= z=AxA=&6g}O{s1hEdt;e z=l~4VLy`bOf!n%HQiCwGZNK`fk)K0l>vIMBC+7 zVp-G{056!VqL{`1_8#XiI65ziuX1tG4;2WWs9;|s^1+UK zOA`11rzq$rd zrDK+Z&PjERr5C}o;Y!ixB!%26QV1N*#q9|AYPMRlpOmcuzX1rbms2{ zsshBj@B=n^VhWipm0+3`q%pw&rt*fNzVo|fa3lBScwtOQ1**^%ZA0ExoI=lrGRLD z&LUxIr|ROm4gcrX?NN{Tw4(n?gaR)p*sZJs>?wE8z||#RH3eCU|7@B3<4xqrmlxO3cWT4FB>ZIL_|cGwbwzJyB_4aVyl4$06>xP z7BaOv$m=J-I``8KEPu-t$rMzP@)Y;PVj)$ky9my}Mj^ozN)~p+T~-I~?KPw@hPU|7 zvUD!_g82)?+k2clWzeh(_T=_G&42?#&A^khQ696eo$a%sp%2iw-ox7BO-NE|F2$EO zgSnz@9#ds^dMN9S$LieaU7-2eax3uFx@f@0_AX^S)LodWU4Tao-_D%w>YXQpy0^07 zrpRXPx>C^H9ssRN>w>+KP#$#`tnNy3p-l;-LDbOwZ#2N7F9K=jIum99ae*#u26~}L_2MKnQSM1!60l>r72g6YZJBTOusK0*;XbLS5 z&whLOyXCJ++_W%?{>@pw%J%uRRqM9~Kn#OLjtU^nKhFzowH^RyAHqK`FUjaShz7$pxd0iRhe!ODF=1`UHUupT z4;Tp|8IJRFbEC0${AO!rMqm(2cZ*3(l~PK-C-boqHd#ue8Q$(iyc;%r*DCggU2ph@ z6!N`c9t<#oat#4vqs3^niYQkNm@M2%&=ID~DBI-)Xx{y-FtZ?k+07^V_OK{BW`6q9 zDkq>Q3|3!~N>1#;OfMOH9tMzQUW*C2c{4O@gz4$J6-d0H${FeIfFMHh;Ok=Y&$0Ko z{4mvhK(-Y?hK(rO=^-cr-rX9;hG4w~kUM)WBP7GW0hsH~wVTjjlhP3}%SXLHu5DH{ z=uw^mtF!L`nv=#BXdN29Zwbj7&48023-f&-IPuhHzV)=lBYDA-=RTc_t%(40KP?;V zjeW)O)Uw;nK!yZ};Ps$8bPo{PkpScxt}5~(H}x8Tr^#TPZ~x+ zR)Ap+pnk0|^aj%)WyvtX?AmjHYLX(DG1)rr112^G0Db0Gn|I<*z;mH*kN)oHDdop! z_0|Byk$w)q=zEekB#lpx0@T`bHW&*{E3~YZJ+ObWCyD_hJ=s_WWf=WXC7CCZn3HA? z6o0}{lLB#8vzHYA={C>qQ`YW~e7n%pPg*hG)>2RP`|sjzgBYfOim&0@@Ziaur`5hf zyR*$;B8gabJ$0Yemv*06I^Y}m=SNTCF*Nz~Sw(Mf{*w%Mru?ZhxX9i&_B8o!`@Peb z=O+8p>=8qy+KsN-9=IWq6$A3#<*Q2R^2_66jTnt0!GDmro$|fZjz}!w&$^ zmuuFiI*#<2t8$CBGat#POhp&h+0y{Y%X|neGTlF-^%0u6;AvFYOc-?^18h60cjA}T zQ-PJq>$01aa(NRifcL@x6r$R!(b|Qc<6x3UB7B73m%nbi;KyIkG@kd>-pC=1GKs%w zTOQO!o7g1=6s|}M=-yBwpTKRvbwrIHk#p*{Zz$sc=}8Hja6fL>ianIIs(>lg^>DpW z^QtQksxwVpQt^XFy*})N=KbEB_O4yoX-}&xPgatYII%LSAl>yQm~|8Xus5YZlKCsQ zceZg=LZ7FVW^ahrmeY{{PxrW){8Wd-tlmo~Yb?kvYIQ$Si8mXStd~$cb>60FdlYTGM_Q?HcOf(^@pVt{ z`GmunH4@&DfOLm-&0YjK*CyaXxM_6G zr8L-m#kA%A3&7kKz~s+CL(o}2*M1R|JemuqHts0wg~n`QpPrqanLY_fOe@>XQ*>r$ zuj>r3h|T`>-s2w@>#e!rHzn<yg}^?6n{tWNbM2#-7<9Dzf5yj zba_D=mojewE}_(l6)}R zXPrsK#l9Gu%btl;_k%wrUaa2ad~q4e+nAZp8=e0k9pw4YXe?gX=w(;Q#&6Zo1;+Q!xPNGJvsu~PYpeS4i7}&=F(m#>k$H) zPe2k7C-!LLatzJ;+%Hlm5$D=2r1v4Q_8=(XmIwT@00F|oOzsSyIVGlWOi9v7c#9WE zD?Twm-)n-1ZOe*!F8|NFHI zbE8U?mew!iug}dYo_CB}do__>W_9#CLAx;>L<9kfpQ0d@i4? zLp5f>c1e|}wmFs-3x0TCyeS5X9*8>oGNt?|`K%Yvg!sAh@((lx^YyXq?nIH9upvMg z4tog#vXS;s&C{Ky;C)x2{GtlVo~OjG-iQW?$-U|oH~WsMbq2&KUX+s97=QG!o4fBy zh>gV8p4u1r>q}wT>2c5!%K>9sQJELdYsD0DfP?li~%{W6175i7AU-{osvSI#qdX2WajmGIK5umFVv*P&+ zXr#!sDgW6%Vc{u>DKm)3Dbw)tVzTB<#w(`5{g@W}{Pu4u<;}W_<94HcBVa(XO|nNe#jsReARweYi*cwGAA-Nke0g##=I6w@1==~2@u86ZPx;djhpqQBHb?bkQ(s%eP}!Z%NnOiC zMQm)JVy*GF&D0gDGTJ|*W{wkR>^y?DG@MO}7|(%r|WE z;h$e4m>j1#!||md{K~m zwr@DDBRck#0w3EA5;z%y;3KK0z|frjOpkg(ZXqk&lV^Eyd$&f=)>@`b$es=zMu;gW&VgQ|*|oQs3G%M?Wx6ZY7k16ebtMmEM}nq4p0idbRhC zZFF)*C+xf_WhtBNv@dXbm9&9i6et-~r@Lc59OO4{n>uE+Y25cr$S(b(4?Fu;zQx>Y ziBPkzM=*Arc8an|8pdc<``JIMfYpCdQ8^{pAa`0`C0DTbonO+1CNSmQxi{EOTeSPy z><9^P57JQqr2 zZm(xCh2=lxg3RY_4YnP8$$*Tl--86a-|ee>Zf>vcYD+?WjiVaE65 z(eR~4JX{zmL(S7>gI&XGL4ow`2PCT|jI=;5a1;b+&b`UcFNr;%*WbPUV1mLmmn{N- z-m4GZkd1m-3YfJ8Z$JSQy#OA%=h^0o{UoJTu@DnL-}H>Z`No{4eKlbEuVYWzTnylU zW^BEo66snB81fmn`K>Vr>Av!)P49xUH{L4zbtuwtlcJ2h&WPFup|4P!RO4Ar#y4dPQ6-6= zP^HsUf39j8EoU^&)IYaEd0yU9EVlnWM2)^b3{7x+>^9Ln^IWF2=l+u-$4g(Mo}1NY zMDAQMmwyv{PY1o}U=0lYdHnOt0iPkz+D2P$COkF2fALxL&IjWsWlefKFyaTKRwyqw zgYgrE=+B7*vmzXl6jN%Ivc;MHJN%o0++FXl9hnjC&k%lm<)KMu+{!pCGYyN-p1}&JT|eOi<^VDWyY4V%z>NI)Yj2ZFls<%8 zndN~IXc!d`1|~qzhCSH~>)8y`2s}IS={cirVi0_D2hV19?ES;x?T_bAVswv90QCz< zLTx1^kDr{`8Gl>uajKdX=0*Oons-Wx8WyW`&F&RtMsG4t!02hVZrxp8cxi{J^uzBf zz3iZG{t&$lfbMBwmE=Pg)d8b%_anFrT^LL|Vx_pJ70*ZZkmA8!h?eqEDBJ8x-PX0bBbA#iA04eZ@^Xc` zp+Q{HsZHjqzI<|sKeyj<+h)btjCQ$bI#?U;a@T~QMehfPBb6V-3HC98vUdkX^t<;D znb~Py{0SDJwJ&L_*O>mi$zAoS_tg(i0BQ^W(D_#X+$SkU2FR*YJNiYKC)sBwSBrbD zU-Kg3l=pG#t$x9E=Dh|lO!Hs7+~S;Fa5dB?N)hHc*#wPFReV((2*)SgwVekf|Is;E`9_ujE7wN;g> zST$=!j9S%JWA9Ze_NwvTp67l3YWw+6l3e$7o!4<5$M=M>i6YPI4E^%&=S!IW0SZJ2 zAmdKk%L70WB7N8CB=cigA3|QptnLC=l9v)HG`6C{QDdB{pXF6TH%7Ma0=MIT7rR1TX`vNxaJPl5*VRPeG#)KZAI(Gc!oEtowA!SqgO|X zkkMfT++E=jT~Cy_6t>9cq1PZhlN3y8s$Gd@Y-tgf!VZFICe~WnlKr{4275Nw8i`jb zcV>Ve(Dy761xt&Ga5sayfsKp<9Zul%gNWk4Ey^n36ZjQn;w>9yO;V*vdCWT#!@NSc zbwVt+1|^)&Y=gEkJ1YN=?IseXy`ag=65jbgMPmklsI*ZrMW8q8~N*+`X$SunQ$ z=G?-q{PL-J9zj95r!o3{UvG3ZUPi*>^dYnhPexpZfhbbeTlLFw43o$twNlmoqLv*^ zvGCQAfjI|@Xa_Ama{}9Cv&$=M_aM0o3q)waOz)xS|^VgUsJVmnlB)4kAt1AK8xM5)<(Iy? z<=C~Ry{EJNju}RNdkuz(=}*Xo+4ilzF6g7h?osDcbKRF=*;7EC6VLxzen`!`UBJOP zV4jtRoy;)pA|slgT}eUQF3{eynNZBr-Sdy6Vd9T}SR#ciA)NQG`p#X+)AnB(>W%Hu z#^|_%2p|%*MB9Yd#;XW=@EXF2DOo$hg5iLmym{Y2BSZRw=km@9k5LqBZ0eW8S62#P$!^9u}#om)G(CL=U}4R$IEYbd7I~G zHtN{y&H0i2S^4t4wtE^!PM;$&$~92y7SoK_<~rxnhNb!-;OMfzV~xg4=7?R#dG6Qr zBlyvoZP%9!m(;9*ey%E3-+utdwvn9uw>H&z2A#SIZ_)cK8X~`bPf&T# zJ@4pYen!3{VC@HNB9T<~b++$NE6?6e_;^-oR%$@femwC`o+SMa?)ML?U~f!dBot~cNV_3tFi{@XIqk2Bb;mDZyZMKM8vz~a!Kkj zE3mQLWs7kJhr!ZRbzQ(|+3-=o{S}q+fpdgkWt1NC-mFK!);u!W(Zlmy{D`An{bjr` zshIB@^O{^fbF-(75p%YsU`zd>y1EsM@PAB+LZ;%{JH;xIHTjPikn8G*p&I~@iN>FSa#Cnk%qQ6MmnwIbQ@w4TjFYC`&f|3Xr98s`_P~AMtA( zSVpS`0uuh{9a>1~8pzE+O8TTuv6U0JfuNrcS zbD9pF$F1)zR09%t(G0=HkPAu`gjMNIxvataQ`}weInr8$T zJ#>tn;H2*N$0TgE^~;1ysbYWa)Mn+RY^~WvlLR#xsV|941I8=bXvg_hDe}1MASjwn zlAOQBa)QoCr=af@aszZ-HCoY$0BQ-SY58XVVsN zw))FqmUx*QC!VonO2RD0vtntU&=SJJ#O#^gjL%l*Ka85s2*;pXHV4eorVo0Eta)G=C=k=X_)IpmcPJMB=ITxVHs}&_qh`7xH3=E$& z2%t5)Wq$h?WnNm_f@`Uf_b6C0U((>Va{S(C`Dn%tGWpo@fU}vAAoXw&NeG)8lMRn@ zB$`j`Wr=xmRxB@PZK8zzWRJ&c+Zq)`T^yP5r%qnTkCtHmS2)Hi;<1SmH7h|2)sbWp zCgv$_M;nO+^&118JwjgCRUnUkhO z&YT3e2X49p?UvgWwJW73F4{n17w1F$Pg*>`3_Fd@HcIPzMl{5mbIzIrOE^{OOSwin z#t**$J)O3GnXRLO8!DsAu%dN!q2;}8sJp0(Y zSLfmUV5^qmEY^dww?F2M=NBRw`#2XX`<-9p;*|gUq!Ht^XnM(r;WO|z(08d(v zbmn3F-EW@~AXyAV;UaE1(d%P$96f)pNJkv!DOw6eMQ0?4#pYev5GT}y&=a~gJpn|@8Rc&3S)if$C0v;o4!%)u ze5x9{YHjAifhWqO>oPsp+4o;+K!e`g4^CN%9_zSEExzN)O4oY0K|!09t)_Y>&@;9q zWjwo2azD!F^UsfTKPkVmdywoEag{DD-^2ra?tdTRFXR4bVM18Vc(3H9kbr*ry;+d& zU@Aum)s|Cf-2aOa`Ki9Y8I+I~=k_zNG)RZ)!|Pye3-^1AY|{XmVL5~6vB1b`<9giR zyHGW@mc}kCu9%?Vh`Nx4pwdBfxs~jc;EegP;;NUPj)C~R^aEQPH0Kg_uiE|n&0<088 z^L~x}Cmgkv5EHM(sn3+LCvqQHT$WZtaXD%_0ZY!XT$m$j>z@ODiK1;_-0x);ph5$?bI~2nDk+ z$b1B(HtxRmNu_=UApdpx8`U%=nE=%Q>u7@zAJ#zWx>3=V`+%05D}`@uVYc|HFgUz& z!H+r;|0&S!!FGHa3JzV65DvzdZ(TF_OmI2@G~E?tfP360UDtyt_l1eCt10rkmd)xx zXT}yN2&tT7@s#m>RI{-jP`PFvPV`L>e|P%EZJ@QD$9e3w^5m!23OKPc1k}4>0JaP* z*4wz}KIR?#k-8N7J2rBk%vI}t0sB4VCuhcZbvQ{_F9|;Zh20VoZWZPCjifXppOTkV zoqxU4aKUi(hQ(BlAbu3>j$CIE*0=HZjSuR$h;vH)lGl=hw#-!!v3lE5HsCN*(6~>| zMDKeI;^-^=_N8N5-InQwy(V*r$w}R{LebpSMf8NaI6OL>SJy8wUAwAa%i{|oz9*h? z>LpBl5@_qf7o#0Gz`6Jl0}%#Y)8;Rj{w{^k`0ifW4N^V-+C6+%m)Iy6jxu;1D%$l%Y1meL zBIv}ulNf)WzN1kbUT1%;-(XIbhq`(f;_aRus>fXTtOQ4E!YOXgR*9c8*Jme#l!Agu!V5$%6}+?BIlLl3mDUqLaq&YpSKJjT|SMzZ&9*`X3Z z^_c8Ff~4BJou`tKPhAq#1`RMZm*L2k?M$*Xd5*R(Hh%KI;-| z`SbiDNxw@8iHLsI`FE{MJe3v1o+0*3QtrA=1Up_6bDx@%S}YtmsVpHpqBHyv!}d7a zc9Tm}_*;5E?^OD9C2b~}`x9UaD?wd={K{D%r25uefnn|r{<|__uL)(;F3OP&ce0nz zd72B&f_t=37rdEqnbM%c<&qr*^icRLG43IV!{|TuB(N00GGGdLWo1$oOVSg$BvlmWwq9?UG3SF;g7isRN}W+yeb=8%{n zeu-5B0LP-QDfR#+?OV;yY5RvGi@O;?2cZEC-9mE?f+|DZ|}CJ?f8;TX@CeWgP~bfKHC zQ=?&V7zzH10Udf0yRstS!@fl8P${`E(ezkqZ_7u`3Z_cP{lb$0@i?h9$|-7g%MBGs zxukPj!wm~igzG14L}83Hzq~cV5o+jdc~Wta-^@J9dhEZr2y!*jGK58u%S-ht^9AP; zt$eZ3jNEvF!3@X>ika_bdk?`5|tiQT401d0e9@6Ld9`fhhb z_(Xr3!PPPQ6lt4o&Tt;Q_%#?1^d;*tnw@3+B?PPC9Y~Li?t;aVD1@xardWi6&`0y% za(pEeQ$#gaBf?XV4bgZFR&LN!^@DEG$TP2t!q&cxk+(|*d>$ionKUq4tcYJ`wAAo* zF5mh&T?5~R;Ao$Ms`&DnqV8eWDie383oHE@T7WU55t~exg%N4`X}kz@YCcIPc>m8a zK#kX`;lf#BQ>^82{tbJu|MJg*lgmEe2EHp{6obqL2lv!>K+%n{fFqBK8PwV^4(xU{ zJ=O|Ix>!spzMr*+-6d-|9ygP#K(-D@a7W%1Na?0TN~dDkJCk@H5D}4`zPP=Nrx?I~ zmxFe0@tD&o9%=>h{os7LRk#)oweMDbsQq)OB!nO7^hsGnn}PQQFEJ0W*^iHv^p)g$ z65gAPrReS4Gk%7_8Yk&TR*e04rXW|wmW1y$Xs77-HYAg?StYkFCqO;n-;f`h^2<(C zhw^7fiW02ELoR^0LN}&c|9@V9m*XPsyY{mwP4h*)$Boic=6!!Wz)B&ihKh;>*zeotCSQT1z46LunWG}}pmOVBsG=)Wb3xKX3bb}(bpGWq$a_$u zUiSvT88gXF<2#DtO1!GNqFA;QUs)pxlVh~&2J6-Y+(e1tOF<-wsJ~G2_yesvkZ?Gg zg8iduzHco8e(^N?Gb^n+=e!i8l`&VrZ=|pqMC3 z!*KO9=_R2WTL$ti({-{b& zqO!bY*sh8@`XpTETg-|Z1zbp|8BiPRWlK=fHvky6K9&vO@mX{E(V`%XTfaZsAmiLL zfo!~QBWNn3K>Xo?4*yY4`;XrDLpnlCatZhLu9MgyG#e0-X^pXtixD)sAhNrp*i$y@ zH*vgllo}+H?iM{15CxYgiZFiS`*e6dHNK6(ED}T1B=2g^)O1^Mkv_+iD9Q7yO~%y3 z{u|3IfMA1B}T5WQty%ME@VU8Z6&)W~;#X-~u1kaZ%czlk&|P zJr#}b5LJK=@y+3#57KFS5m2S)l|3{m0I$jZ$5k-1hEf$kb1`3?AdEOxycr7_4Z-nL z)l%hEAGaOBU>Ob2Dc9ZJ*J~49nV3r-fjHqyeAciK`<5 zdv_n*8S)F~#JrJ{mDrKh}t(&RdZ;=CkM7 z{=>MS?2sEH_kv4CZ%5YP@HIvhY|f)k8-?Z>0f3{oqDu=|{k89kAE zu!m=nzapRT*9h{F7ueew+1cYul@qvfZUoPnG2&P~0&DU-ERV?05UMaIU}tE-c(KtF zHUTU(0sMHiI=R1*AP0U&1oG6Qexr-CXKlGW>B)VF9*=PCIDGA@FasCFT&Y=Lamnig z+;H%=E-ut|p?k-SJ0M>Bf?BZ&p*KID>B8Bc6+p`{oQ_~CeacqsGWVQ3bZ$vaHH}z{ zAmcGeq8qQ5fb`oVd4&|3b)w|L>hei@+;U=~`Aee#*Qds=t9 zJi4{4zXi$$lxMKKFXj%Oky=Cc3&o8bi+nsI^bjw7?lgYtSQEfj^Yz*t4bg~g1#S$~ z33?4NQQWZmaVM2UAuna1H77}mt`WB)q_KPzXJHt_t22kI%AH2Rt*@b&YmqgIGtmul zSLUMy(zsaQkJyVijp!x{QmGvf6VHy2h-yt5v*X2VveS^asJe?&u;VA7E0N!p+E;>` z&od=VE3QA#qxAU-^>eqMy5RWy8ZA4($^arjy z0uo12*I%Vp6j2dswxKlCrFic)NIu>gLV)K>C3*SvUQp?g*P> zCn zs^cq(v!6b-l6FyI!Vl)g!FS_M^)<_pkPCl)u;eHv^m)@*S#GYc;#TM<9~>+PIc0seqTVslY^}}*_Iq{Wb*&QEp*{l`;ToNB47_1F zur>^A2l1hR%NE;|D2zd zS#5L_VPHONu}ukTIv!=rHL@*dn->eYp?bh$K{TyGWMs7^e~&blchJJnDhhBhwS52@ zDVtTmke2z68ps*1^ZuTe#a?_W1uTVoh{X8xqJpS6IvpRH>5^%b8Mq-@ZzG6; zq=x`}kJzsc?RV%w55B>YmYfb~X5l}v+rLk}hay>fzLFN+d}y0{dfeU^AwA@MLiXcq zn97p&&9V9v=dlht_g{WZ_?B8DuGtvynC$Re;{5{ygpzlx+lOK*tlja7acbb#gcSN> zKclEDzdDVoD>)Rg6K?m`{CBftbUaGR+CM{j5V_=$MIq;us_snau5GmKt+YP)@b7a2 zjaYk|h(YnftxvmoBe-kqK!>l6=_l)6hL>_;Pq-Y(cID!(l1jk+K)C?fe@qe^{YeMd z%3b*iw@7)hv+pd>rX;$TraPeqHeyOi@i_6cbc>&;{`jNK376U$CXtgx=H=* z$W`6|eJUspmHPW7VP;rge1vR_4co>k2U=arr2B&Wg7g9_^Uu1vKvqh=Lb$-%0d+nV(~G7O*?>dvB(jk)je#sWa(U_$_dW=`+QClfdUbQd@&ZYTjlh2qUR zCEm4R9SDu-hB_v zuK+Qoh=JA>oCiQG^xw;o#J~gMe^|u{zpAuWm0O;PTuhIgW$>QF!hj9-Q73=I9_|I_ z{Yxs6b}Y7Oy20A-tlcmGnr8k)XYTL7EIuVes2+|-_oHYU`wmVI7WD%TTL^C>AQHAC zv%>&J2!GDk9O~J+f3kKWaR09|8%l8PodpJh zM*N{b^J2qY?{JcXYPKUOY9@^YAhFjry+nRGPJ!$#nBVuT+T@LISMyU)et|?C*3eF= z?qM^|nE(z*zhDHdI-DKJM{8vO^^_s<6|tgit^QL1w8PB40z1&0`@zEG5vesMICSq* z+TARaP=flyy$fY4&+Ws#AQf9VPEo^dgx4A~}1jQvhU?GDFz|C-c~ zV{rcedw_zCpP{dO&wl`?vMXcl;M^>lyg>d*5^fi1LgGZ3Rw@VJFfe-Pde>pxxnnc! zq#hxL@TzsGIh75|fVk84EMOn*DyXG&{isYei}I+(0a8{k?;vVbE8 zG)PgfT~@?xNRra!gR|m@y?;3iGDkwq3OK1u%!~d#Wggz#%Y{jT($-M$6MM)~X;Kc6 zibfR zu2QQk0AQhVGw?Y-PyF)IJ4tyNxO5n$u}~&{{EQRcvgcz`66o+t?);sJ9-+yfZr+eh&ZhyN_$R0A`;8t!IDxd0|>x>)MOLQo7Xz_eprxYWJtmuNsC z$n`>oSH9{8$JF#^p0TSTFVmwEInsW0;0RdF3|y*Z+8Y~U0&Y3`)n!)+3I|8j(fzs+ zv#e7jdw=}bX_TWn)Ni=$1q}Y3(|n)ttL^hH(wpR+qxbwQ`1ofk6W19{tAp9-+DYsZ z|3YA+(VwFkeJ=CRpWS?mG3(2$;-;{!tIUmluV_L<`&;#eCb@Dtw2v?A_x7=>BZS# zaht$jhq=z29g_|~wb^xfV&407BIkPCG%XZ3Qk#0dzmOll?AP%;NPN;<-C;EkO^KoZ zJM-t_%D`m3c?Okj_@`x4VoQ1!VB)cj3Im1`r36AnLOVQ3bOf#oK_v>{ zzltnNiwLb9%_C1Tov?dFSOvWS_NJ<7|mAX1+-j7o>5ui zm3t<~`?GRqrI;~btx!kV4!1t9?P0-IR>=6`3$<+~dm-a6lsB`& zLC+87#z;^l0n_rl^j;6ue{_lV7;OBc7J+e`^x6JZJPm`;VuyEs@qWf=9BOFij;AT} z-dKo)V5M_a*SZF=#?3H(*LPTqJ=&W(r~zF7i7#LJ`0_uUSPl8}cef(tU4Q4s@$l<< z9~fNdQRqjOB?(G&E9zbLGrcJ=1m?A*i&XZ3B>lX4lbl#wg}r*)?cf-d;Cp>Zk@Rsw z4k;_>9=x+{*|qL~adtJJaT@2w{V3}z6<)t;@#IN~a;H^S@W0c_vA5DY6M!$-{uMCg z#!|4`-vfZbQ7ZIif&qG z#eZ#;7wbwrD_eiMiq?E;%<(n*j%yRJ&0Q_y`C@O|yzo`iC~VeTyAF0Ff6LTo=S0(p zIGwPzri1d}W2+-n0DRx>qL{3Qtj(XHn4J7jq4;99V{#SJc;0Y|SYEEn2d3_?kx)hz z3I$Q6%fHKsWU<>Jc9+(D?j(1C$L}#Aw=-&0I`*>Z$SC8 z*tb?F&M5(NI+}w9$Y7@eFa%9>dj2`|7u<0?Z9;8)-aK%2>l$)(Cp~B!_M}A|{}r1iTM0y=LHQ1L%-kR0 zgvpc+qjQz|)(`frN42vs5-uHs*|Zb zeS*r4CRtV$>owj!1L06Td1N4+_X6QrQzaB~6$+t?qlX6IMHa8j#D04b?4dj(%GV6Pj5^XARZ~O)!J^abTn(wHuAe@$p&j$kX{M8Z!blLlk;10XOL(M&7N0 zZ2|wd#Z??~hce}pO#)~HA9DZ@LBC2dMcgMDhG)s*!81*+zqObJjW~EkFF-SS}41p@-K37@`uEUaOQ7I_2>#Z@HL^=#=NERWevygTXwn3`D>dtDn%IsR7)w;U9DHVr`pzl@OG;%cDm+vuNf*Fpi z+bbOog zxpL|iMeu4SDuy)i7z|AM;fOGq z&T-mVE+ZSz-ZmUu#TlV`ZMT-!+$V@IKzEB$h7>S3Q+64*lKl807j-ZFF-4cI+`W^S zQDog=*&yUd4jyzhP7o0MI2yyDr}r|BL!?~jLC1QWvMp5<0kQ>=TVVcEHvT+x_Z?}$ ze-38@zpcis^7G!m57a67W?7nhZ(dC&lO*ktuAiDVJ1zC0aoV>>0X}N}8J2_G0=hXe zI;}kG>9s%H-sf#RJh}~%nGN+Vko11OVRb6!tXO0)IkGTrJ?^d;`1i!pRdL+Gtu{`O zO0ZPQk?TTHl(smJ93TBCg@e60FE4MM+A>5(D(V9RO@=Y_DCzN$W)f`zm#R7^wQ{RO z8Z}20gX4Wh%S>(9)UWaQm==y^bvxNV4hJj!no4`x_oEgVAMKQHSi7Pj1$TKtwTq4k zb^E-eTHQ4EzgLCyaghW5*-b*Dd6+}vC*ua34P*;dq&Xj4J?8X&^pmKsC^z>7 z!lHpHt523aKdfH<+`w%mm=RlfG($Oj>-l0r<3A=N?*gI- zQg!}#YVQR>bk4?~4{QsHQ;`OM7TXf@FP_1Rf}aA9g1XB=F}EocPiG{Uxeg#vv2fPQ zjJG#@YpebEM;$B37B0roYziIw{9pA{9nkqbHZU+4ZwE5$u7_@sv@X^6@d#Y2Fabbe zOzDoPWB&?7?6Is0euz&?i`5pXwOB7L_|R^N+HQ-yy(_Dh=C~;n34gCr@gc>(M70DO z(vsDGkNbLfUAKWby8jHUw1^nnU)5sKpL@TQsea44Rj+E^4r@OYOzX+RNU#<-2I&Pc z1sNB{VpY8eic*r80$Y{!p}L6Boz_1=TKfjihIF}^WWQ5(4N!9A*Vc z`+fDlXTbuwS9-KZ1&<%@F+3*|n|_>ukq{Y9Vt1_#p*Zl?fE$6?2pZ;)I1bq5fYko(EgTl%GhyFdO)88m4!7c z?Ap|S11uX9BoBHXg!K>cM`a7B29aNBMM#){(m@}|kUrAbW%=`uBg8vAPNw#*m)WLI z*_%gv@GilYH{^Rs74?^%TJU9lus^UE7X2zm{Qta6?vz9}&EWXnG`E*gG8{AsM{FrniO!8RdN}}y`;mKTmE)_DilfERd}c8iRqG)kqx+9^ z2&UCJ-1UqlXGy}JuYgHjpLlc7Xa1#@ZiFRCPg_sn|Jb7BBzdDitTyOfRpyIMU&6@~ z0Li222MRZBY5gx+it0JEWsTGx^6kM=?Ik?k^Z0CAIk?pvh&lPf-tr*(5hmqkASt8A z=*W^D^8*=Fc20p@cPzQwpnYVt4m{qZjVVKZqz08Ot!}Fa4byy`9!mU-zdqGhqc#q+ zf>Z2TfSV-mo$kN+GP&{Ty6qUZ87j+*uRv({T#%zV2nd61$h97SdqBTH4~z5m2?a7_ zNwyh2X5Iya5`38iZvlR6emdCcjdhu-BXC|Ib*6ltZOk1;_k9c|A_^DdZ5}IbFt0PS zu$bw-<14JrbIdAF9mzQ=%PaW^Vn=g+!8fn=F5hUe4w^>NEJ_6_zD^vEVRM2xvn8jSnVl{D zSYb<#!=n%KlZfYHuo|WEMP&<>3ocU5E{!erv1x^D3V?$Q%#Nbnl_W|eVI?a}DdXX{ zwqvA%%~rkugo5D)FYnP*b1COWXCyzxH+hu*Fq_hg?7V(1GA?Uh=vl+u8xvGm3JN(om(z#WB2$fLevyl6XpjI}jy;Wy_ zFt5y(=2@ph4e^`Jamz(PUvJXdC4Hsma#B{~@GJq14W1-C(at>S@+ZnD+!&L?NfmX^ zC?jwNL?RK_!4^k*I@%|L_cGeg-Y?z@k;i_iVnUJaezPzqJx#k1Fh_Y^f0Ly%N*YC` z_saY4he}lT7Ae~+9$HcA4DtxFcxO&-4%#3EF>A1|uM)3?`WnUN@3{{{nM{Yn#KfBg zaRM~ylP`w7#bUs(L$LQA@i6{ga$E|dLH2Bgi>{A$FsQHdy?dTavM$sSHa2jrEOg!} zd7!CTy$cR7W3<$c<_+MEz}MMacT7S&yCH8rR(UGxr^IH51dgc;o1xmuHKtU%g#%w?8G;OI;6Een@Zu*>hV}v6C7j~@COl5;p6j$N6H9j*p^oIml!Io{Fw#DwhG>hH$?%A*pwg0oe-Aq zI&`atIop4md+kHHXjKpzm=5n7x9>IOT7RiUE9*EoQb1LMC z4)#;a4$64bEm9QCJrK=Rd)`-6LH1UTV(+{+6SY!imV+sk+(-F_Sy6EzU$L(1n+nM8 zXHBq^NT9>IY|?-P$x)`R(G{(rnU{6SV1e^9nf2dWw0MsZqb$g#l~|TK>&>x69&JtU zTAuD4?-0=gQXP0(z`)#zfkxrQUbf5^;NhhX+^5|r)OjWN7=G>6qITd9Ptb5gUD{s; z7Ib`2kBak(4!9ejN_Ek<^xrQ}at0*1Ejl|{98|DmyVP+g!={WU0IZ2sz1&ec&x-W! zIZW6hjbB~5VG^GTTJ0Ous%QC-3jl{!^ zHr22%lkbhSRu|DoJ+Wt+nJWEw%HC)st~s#M_3v3SO)NvYD-l15CZI*PEdgQc_`AVN zr5+<7c)k3GFDY3EJPU)P0osH3V@Fe;EFS?(i1ro0q1jIz#x0xtxSLfR6361;`I7Q@ zcRGVJ@M`AD-->Bk0B?Bf@@~$2#2_Nx)`d#}F@3>B<~}@r#olu70J%rJI_m5P43^z2 z52y}xRdSpl;gHSnvQc>SkBk}b#&1A@@g23Lf#Kny^mE#*rqY_*edn^Iyrv#?iFoK! z-`%51=9>V>4m=J<<5c#)Z``}fA$)48?a7kY@pezQQO@Y&8wcWhlrsQ3{o8rBitVT- zjHrHSJTCpfz5ZQhAy|XU6&LB#q&ah`Z3eW&DX5;mHa0>-4qa-s#Q&|&+wl`9`TBHK zv#Y^}tPK-1I0MHw-pDr8PJICPygBh6UdhA+h*d?Lr+=J@g|gOHmbP;@zk1;JO#Q3w zl9CRG zM@K9qBqYT4_Vyv7{QMW&6D4Ykcj&6hLSV>xBy@Z1pK=SM`yh>FM6%<qj z9RptD;@YF8ACKet!!2M{$6svB==832;6n(SC@@u^z`&=pt@}*y?5_49yGwae`ZZJ&B@WOUOw`%Z~a@2SwKfgA(A{& zu2#*2fHoYgT&ydPis^3g0VOC`fI$q%6Hhe6{?P`t@iz&gJf@uEY$Kn!Ya3{$Q#V^od0IC!#IuG^KLs$kY=*lDeh>+gOPz32zM16Dq(ep-B!h<#=3*#k4iHozr$!k$; zpbgWK_H=Xwt{sm76a3tN?Lan0g>eT9*DDB!x_#$?j^2<*6h6Xp6_c0z-EtOnZYa82mUn z(!i#`c_`&{3P`vY4c*O!aExI14PclAfq99t8~0CbF|FQ}%eEP~tMKPzmV{<;1e*}= z2m(fNvs^D$q0KEX0@_tgm_##}39a6oj5ePJr#-9iT=VC7kPmZv>-n(S2kyAmP1;#E zKzOMdlJc<~=!%iqhgr)8BrF~f<1KeY$^<$A(?Y-b!2+MxdCM|dj+OXK2|C^jW@ma3 zRxY^*=>HcC5o@}kBZ7mp19+3N_YtjxJ?b_~EqAg&E}ujy&_&BaigW$0isEqFX$2pPeJeOlXnqJOpoVs~{|)q*7u`1)R3e0CmvIQ<=%al?@BSpQAt z@KDlsZ5zmk!%~ET08|n=3vi~6w$NS-zE@TM-sy8AX+UCCWBFyQrBG1;YCna>_>V)Y zq%ts*l!u7^N^zM9s`kN1!g|ZdN5_5gDx41AyphBTIdYHRGZ}A_ARikT$edb+>-~UE z0>M6U{Y+a{I~z*TX9B7wL!p$-N#8%-xQR{PIy8sw@@2BqM{r_oAD`M!~(ild4~ z-FdBstjP7aPp-ACXpr9vbaTB8b>~ANs=Mv(pmxx%N{^+HqZniY0rsPHP6*h(-M&9T zB1Jq>Yadf-(kxs8mQn;;Z%x`?pi4z|0@!BX8ep3HK4AuOpVndOQdk8t5vR z%PhHd+*|JQUdMM5Z@Rfbh^j5S-3ZIhRV+9{t~^VbBpkXRZKr<3k=A@5_#*#>a_iw@K`zKKt35dkfh&ya)O^S3Eq=K{m-YWu1r$Q65IX6)R z>`J9Xt17p9_gAgI2DMWCKfc~Ooa#UPACHt%8RrmXbL_qM=Gc;%6^VmHR%LHxXA>Do zB%4#n%ASc9*&{+3MI-Wd6>*{)Ychxzs*K^$CaX;?+(W3femBi9t zd62z+C;IBDR_rZDSi60;mj)b@HTu&h z`U_KQ7mjRECm-lDx*qrcoR@)#MO}XsyGgmJslvsFCtl)*SXI%QVjjy)7TTnL)lPUV z4Ula~Q;2_7J^GWAx8`5PZy!&cn~||=ekG1f#CuD6PvyMlIGYJqEuqsrRXO*jSZ*>0 zy(K^De5f@;H%9H0OO)q(<>C6e@aV?+q{r%V{fVkgLv9W7`U4cT%aq$^Xk|8A19tfy zj;G#YU(-nL7#(Ll$CZMU>OG@clv3-Mi+{V%L_|(+dHs$*e>3s3EbTd1w}x2QR>4&w#bB9?j2 z;QyqYA~)j?{OAwrZ==}*BHJMqa} zuOErySg1nz_XMpdit?ZCzgQRuNxsAR0XOS8d2_Cw?C}Ui&avgdewZ~&N}~0Slq2JG z7236*wS!2URW-Eb$1^6F<|v%Niq1H}cy0CQwZ)qwI$?a4KY62*5E{kWuFiVW`||Si z%o)sZcjjK&7CP&R>UQH}O}oU$;?@4wF13oUoS{dbh->ro2G)_+!2iP?Z5rpB3hd4De$;c$$hgD2U@xoYpDQ)jv{ zeb>7iyE~j5xO2@>EZz59`^i*qddl&(_F#P6om{H-Z}$_?(TaJe%iN}{1cqR0gEpeWlC`XU7O#y18fT)6xt z^z^-6&Ro~^iP6UzH0o@#Rp5;W;;0!#^ip`!zD|JfRwY}r&Xr64HjZv=>SL}QXqizcEVs2^UsdUT#cn|Lun`?8(g^g2PtvP*8-`+a^m~}qgKW!9OjSh(s z>^^%00N^=o`VsqJ&fDni1cl@auD7}T(DJvHpm?zg>R^t8625=sl)H5Ezg+8-p2 z--huQ)!qip2Y0y}#j15ViTXsGrg3z8dy|s0zRD@{SRdo5#%kAnMZ8|_0u7M{>raRm z1+S43vDK$z7d^l5d@)t$;HmB&SX#lC@O_N_lz^@a?~G_}26 z)S1o)xoBB!(Uqs_H#}G0=3Svn%64?z5OFT0WRM!_=P~wiyCw5sUQ3qmqVd6>K!VJQGspSyZU@#**{d>zHBX?#v4Ii!Xkkr(+FBCK^l}u)58(t)lckTULrOlv;S$ zi&Xpo`zOo|oe4t7X4-B8A*#%NT*dv#tjAFnO>mQ$y$$Gi=#*l3M!4BmV~69N8*y@w9%UpDhKTF)QhuAIc_>bWbi8zhcOdD6b^LGE*Y~YI9mE2fC$E_hs zZAHh9A@K-`WM#1ok}FxEE!0Ca%lve=BlK4voH)yo;;*ut+o*j%3NSAJ_QP-{R{po* zSi6KpQ9O^42uIr{GM-SMfM3 z1;kvyqh%o~M%xXBvRPNG-T#@A*E`_+lwG%~l6=Ce(DEcIoWoj|PGmfbT#Fv7%au)V z(`D{>lWnI`boKgKHm6IX29n)GvaGB};jh#SlFu<2ZC-jtE<5!0DbL1|(%QJiZL;gE z@x%X2G%tOVz87!o{m2xHRW&I>Njj1G;6&~jCd;G;UM0%; zpKBeoA`4Uw6kr4r=dyrY7^_$)D&*B0#1(dtoM2rT)BG9MeyW4Q_pkA5a#>DvXVCrJ z!gCSQ$pVDP^rz~RJimNrlh?pIOUzRH0DVCh9UDfGZ686wRa-Y4dfZl+Ac#+kBYvU( zP*g-3^*oI7YgY?5TKh%rBnQD%CM!pnjdGN@B7P;0+gh(6c1Y-U-u88ELb)-1ng2&c z-IlG0!2$l4u=u!26r&qT0?nu*>=cQ6@%pjsIm@rU=-^)=#6~0|&v#T-((jsxs%DFh zEHKwdODBB^E+TZB@rvabKB1nyOlTgm;jDk{ee&g8GLj%@mzt0w*+Pc8N^Iq&*jrye zJvWzUpWpOL@l=m%M@?K2+ck4Z=0;txR1|9qzkz=`z^ryp!NrtSN4);j*5SR$%Ct56d#^w*uhR6)W6_;{?UdD3?N~3IPLNwV zN4HiyyWEFAHkR4?Znuv+l_~7XHJdG=Kyf-Cpd222dVD_n{)$X1L4Ird>l=Q>*?h%7gB_}|$p`R{Avsr}!5D(9!u(Es zvI?sX&MFqgtt5RRWf4%EN19q%(g0snnq0k_Yiwmj&&0rBZNV-oMbK2c>h_Xdx6tk- z*4WsJuSbK^*wBJQ>(@4?wDcTn6R*w|6%Er}R{4@Y(F6h^@BaP!Z9lbee_q(&LcaK1 zMz>gw)b5gSwQ9nu1p%2jHb3SSdjRv)Om}y8Km4{BYg2V1Z?-nJuOP*1T}o8BzH%v~ zPpIJi`}d@YjIzeJn#;S#8q#zE%}LG^X|$VzU)ZG~OjggJ+q31=aUWzISlwY5*0Vllr^@JQ?>-C?xHVH|RvtXlbT@t-W-kO& z94=pNP>~R$V61t&9}2TBDX?*vSTf1?`41%^a^PGkU5S=i=M!`-6D`u)c!Y<~I+8+b-cYtM8?@ z7!%vXu6!$ozm06X5Zchb{3A9UU7+b_sHWCgtf8Ut_mQ+mKB7X|18*4@Q z@qW-?CR}b_Eo9Yn$K`kL0|t}tpFGk>i$=5S)+AlIA6)*s?W*%C9o`%?F{Q zhfhz*g3tAHMJnwrd7V5brXrU$gH)@Afw{htZmHF~RVNKe++xD??5#@-m<9$1sZjGU zt?_|4hx)*#kWG{6l}am4AQ6e7ghHiVzI1NJ0V=gnWR?O)i}eUri6KOeG6N&->!Gcq zLkFeKw@rxF=UWgszDh6c&d9fTI3?qK`}SApUP%2sYayVge4t`aWnAR-X81$PtqVG? z-N)u`eHF$1Z1O~R?BZ1B(K1ov1S1n&-M9pLN!`w#O(EMB3m6}B(qS5!`ZD2}`eV6| zU3@dfPrEyPPlM1$1yjRX(0!#uy@oAW0Nc>h+dCTq^W7Mkq}{JZDg_^qOkHfj3QtTw zTyEp~(ekSvC;R2=D=C}e>%V+1w;t~ZHUxYnnvDH#-$PkNEOEU??m?3-B?B-%fqTKt z_gdhFr2pYY1E-RbEewj}15V1|4jiRgA@iL7Z6!{?ab{5Yx%)mtjnx*nc}IqE5!%xI z{9r)rE+7<3x_8lo7fh;-Ix8M7z166u&B#0-dd1LCL=U$dy`6Q}4Nl$sZ4&)v`PV=z zevb@4cs}ztbf~r&2Jxk~0Fb27({s}|Sczem=)VJMirDNtY)4r8TZ-t#4w#U7?_DewJIgO15M+f@I=Ab!_6PYUE7bFu%F{vPGogRiuC)nR)TnH@OL~5? z{%_Bop9LpW9`R^)k&=X~r@MRl0FXJRCXfkD`qg(*eV6XksZ(OX2Ro5~#tXiA`}VJp zwDg`A#-H1?uYA!Mpin;c0-uJ#cT9m#dp0wdmzP7TeLm~8-<1Auh0-ID6=L>LpTD=d zx@rk0SkC=@p++Cv)j9X=Q*{b3+C^!*{UqfQvyA8b-t_czG;V35fI0ara?fT}R5q%l z4exx6PMZm~z|C$iEWUL8&p&k{Aj4$kwaeYZFk4=n?w|ia(ANI!dJF%QJF~P~WWtj%qU`hqC zM*=!HDjdfZ93wX379VvA7Q>59d5ZPM;V9z!i7*q~*g)LUo^t52Lv3B41}g_fWPKA_ zJ2o$h*q!*1C#B39Hq#1aZSTRs!HBn;PI3M2byq$Hj(7aE;*98Up6pc zZUFE|Zeyxp&-?Ra9ybbFS~Yr;Sg!G4M`+HUpXSFl=1-dsOK#wbDq~*KretEh?eX}f zSa>s|($Z3`o1d%lu0e{?`SRtg3wurM$&F0e(d)pHlxK%c#n%1C~w|=$>4!e zXCQcrxZuK%y9)mV80~lNnnv@@TMXsz^=Xh=5 z=&twjTwKpIqbZmO2fsIRrePhdO7eUjac~%#G5)E)yLM&bmDke>+g7-wb(W>br$H@dhxotS!H0vG z^*;LBDJ8W64}JZiDbUP`g-Tas67!RpE2QBt3FPW#%P)f_yN!(!tanII&`~>-bTVPp z4o{QQr+;ejn47G$Ho3*fSo!j$>6NOhyg;$AUH;M&A0Gn1>q`iKzD`U`RR3*M-#MPY z7^_=~GCf07*K8K?HdMNFW|w8`fCE`4MP!}w4I;1O`uci$ZUyX)nx~PHT||>@M^z>u zfkXnM>~=rQDKdSOl7dNrU(?{hlRFmYJ0c1A0V)`EY)&Cy(}0fT zr@n~)4;O&s?74GaL3e@QA29X3ife7JeOz3=xgE#!AK1}F4wj-IZ308PkauIC-UC8?R3j6bblBNpEv|bP_8Xd%tiO~_5G{yT#lrY+HWi zh!F`N;(H8Il5yZHwad&%i&1{3z(v@Giwel=U{d6;otwRq8XT6mn=#rEF`fyOYmJ2( z9AHBC3H!fR8suP7Ocxao)16gz*st6S?ixVcySF^$|iS{3YMXyTi`NbWZlf;s~2 zthdaf_V*@j4ofvTjY){3Ao~ha^*AJ5RH>s)p~ZSf#7NwhVSM|vu<#Kr4b5n5TwH2V zQBlj%(o$!7diodmO@KOW2(2YVuFru@xccgqOmx>mjQ{GBXtD^`Lri&CoQfoxHU3>& z=)cEf)z|*r*3lV|#1hKsXTDV~#J10^yMv)P12?d*bcTH7%#)`=EO5Q#)WKu6Bk5rt zC2N@Ys3q=$gM)*-hL+Z2TSG&`a)`f3kqP^so?T+lg0#d0f^+7%S6&V-u*@7B$yuY% z;G7Jj5||YaJ|k6$l*f-lYhx;m?wu!+Mlm}0!W$U~3kaAtmw(j2JST=lDL?UOwh(oX z6|STKzkrBdq z%J$tc&w+{-k6TjI(8m0s4sV;7v26|L0bzP|*iwu}!6PIB;0g<9#-fSgVvrMY2FQ?% zwNS)8c!1<%udYG-EC%B8*W_-zE8wzex)ZxoL)oeiiJ$^*9wd?kTVPuKQ*hJ$)33iS z+zPO~!8Sj<$^5xk@50~XsLZOn5>m+NAx|&B@(>f@RFo@-NaijlZSrExH8nJBykO+e zCX=W=t}-DZf&T8=*zU*0UC}s|KiHojF~;)kb2Up&*)B~=Qs;%(8ivNnnHrNuig6)$ z=(>0=Qwojte@HH=ynGz+B?c_9by{lbcSNA92MEz_rfskD>lcN8?#jl6#kNBy7bO{; z7{{}sq9uLIzGli97cdG@F9Ys+c0_ zKT+meVWzySEWc||$<#$6ljhsbQnF*naqv;KgGi!H7&LZbW2WscWSb`5M1sgk^i9&Z zupel{<~4b@I%kdcM8s-6y~4-+k!E0EAgQ>dqz^2fte~P|tGDmkC=#w;Ac1Wtg6$0i zc86AMKekQ5l;sOQ30d=0twUdy7PCKYqpI3)EQBWfCK#E9M<>2-#Hl2+6?9AWpLfFS zrE^_+)RL8&>fH&Z<>v2iUA$D2$dMmL3D|-}Yw<(dM`nhGo-KJ_O(&+Yc9S#ICHmQ^ zg+Auaaag-hlA7j+SG{$vT)+MV?rymrrzuIjW(3Abs!D#@*tOud z05U1Ae<7xjR#>=49ibPHfnY{>m~ot%pC3|GQ&UqPbDo!@UJH)hhFK9YAMsaMQFG@Q zESecP;mnHH&@?oXdvLyzazw7H1^tYvOyvUvK%DsR!LB@V?vz=vBRq2Tn(Z~slnOsp zrvGd$j&4p`nepXf4VBkt17q(^Ld`Z989aF|pTg1_q3pt^NP(P-w97K;G&aDmh~U?MqW2 znzT51Yx22ZeOr^Mnnt@g$<5KSyQ@IYQN-b2IQy=eg@7rpV(A#u;w3&-gCE%3y#Txa#`qa_ff8HYvC9ZGT*q-#HJCBp+M+nU|O?Oa)}z+HBiGTESerE2dBdolJ1g50-Jj zFHVIU>(jPY)lB8akr{^olMuh^JrrV424`BLfv^8Bd<{F{vj^f8t6nR4zPFno) zC>kX2EZiI)9~T4-IG1>XJUJkZ)2JiZ;R6*wJZAyv^1-A$4*Dyw@$Uz$t2|7}LDfdSe7 z``eMQcjL)65dbqGArOaIMY&N1KR+KAHiGd35jLqr2>PO9$bRm3?GRPLGnfBT!=S|B za71Ny-hFjF8r*x}^Prtk7>kD6VL#qL(+`t1$*3wkf&NAd6%Q3qu8xU3IB!r7nYFRRqpQhez35JSVjsQa)(Xv$G&d_8~S0m*uR4r zYmZh=XcojA3snb$DCP&yM{1C2D0^3WtCG)qv>D9Y?$3|SG~sst9XE+l0XDXUHxTeY zLXO){8e&dPPAVE2vu~Sw8&ljaE-q2xt7Qw_OiDrHuX-6SXwqjs?g>A4K zMja$$zdmxU60K?m`KhnFpRY;B2s*z8(T^YAfbZ!U8KpqVx8u<*B`a%rbF6|l`BNx} zhxPsduHVViWXUkg+Zt@l`hx|AV7q^CUtP)R1IUd=v+9ryUMF>tx(pC#dExiHdFz&jW zqX^-=+f%GHgNPz&!gPxVIy;&iN6XB3LezT9*JxgA!X2r`9REAci>=(xF}bX0#vJrh zwd;!1jdvw zKTS})R(CUF>jyw-?^tIMsiz}Qa!Vf?(vOXgr#@(%k2tpk_C;b{U=d-ly>GB2KM4X~ z@2jsVH*VBVU7h^>=a1h%US8beA|GiSO?j6w$yI=v$CN(WcOqy`*U|p32~M*d7>e{r z`Q|5{NYgJ03%Nm%&Jyf8h!=l=7$SWt8Izo;f$Z1wkqTd8KsWcFcy0w`e)LNOz2&&3QoUVRaI33f9#eino)yu8YOx6acTxL1^l{+ znrLu%`B%MqXb_eRyNFho0p?w#pFOEZ>+Y3(&~jD`;24QKPbJVTrJm3B_xI3NYTiuEb(jbYLv#Oqe)VS$WGjlg$Mim; zXYyelF4$DZPm;$YdNVhrMv0SD#u&LmW@??m1V7)OBAJ>H~;`-ZFh{ zw}y!9n%1K|e-&*hth0w!Thyu{QnZntLY9Q3YRP)MG1~{QnZMRh??r@Q>wv)^C{psY&nVs2>mQ z7nr*b4DCpsX2M2(f?2iKgRn`PJUYk?A!8ZSl=Fq?%@#ziAHoEW%h{EWcZh3y-pd^S zQBEXu`*(PCoQXIxqD?rd$&nxP7c{@z)0uLzubSu|%qxjc4US9<-FvJ~^|`{*A^pvJ zpj$b}h=8{gKW+{A8^FFc7$7=Wz?M_Nz%H-CmEkQ1{gX24BT9!As`uDlr%$Gciip>L z-KDJU5mnggrhed@^UoHTcMJN2(l}n~Y|^*mS3nSGHx>X;_0NqNdLEKA87U3^ zo`Ozni6DD>8E`GG8iQb24`vOOhKR z3t+LA2&1@gW77&{05nG_cEA2$F{^5qt?~r8b$_AgmN3sbM}(5*>{q4&uD-5_~eW81qs|p6R55#P-TNTm8 z=YdB5CT85^ShGIt@d!vEd*+W%q-knqY|9VExZrgySM-+8m&Ddx!5uW_8{;39+oYsC z_#l4T!KuQ%!vz=>XL<*Utbcuf+E=jsCb4_!9|Df=`s) zez>Wdl2`5UFJgN7Dto*Rujm_@8{_i7FWS+aCi&<#?(8=DsnjHCf^H&vTrIh@6V@QR zXY2up1hdvm|Cp}mrtOTYyq~Pr`BuOKN_s{{>Q^!o1b@#>&nG!w{|pkgP6B44XJorG zhlE`{_H#I~Xgk*zlRgo-lYB{#*$+BA^M&jWDR&*ZcxeO3ls^GtD`oEV3xQu%+$R1+ zR&eL=s>-n4cC%MIP3;`DO@M7e0>ODOWq|ghw517uZ86ya0KvVzToR1pn?3KvV{iHY zZDy~RNhLAi8SV0y_#DAoTRF?fC}P*{5r0A0>0vg1+2^#`4F|}}N1!!_CUtF5>%Q|| zK9#kPHn7t(z0oQX<$5X)>KZBnL1QoUM2@fqbh1>35eO`)JR?R*AOG47T&- zReUBE72+>6N8%>pLqBEEH4NPbCoGzMZn001#TI{wTKULb6x5&0rg4!0i8p6kr`eYASJfU@j7aJ&4J8QTvZ$OG*>d@$#IhmMt?h`@aeK2i z$5h+n-|d2@rY4}*H_uEoWL}9*|MFKPtGue|=4WsLN5wH$=cD_+v6scF0Ke1eSxL#Y z?P2*J2w;|3<-P~Pyu#T=ZqG+I9|aT0BJ1i&u(ExbXK9Fo(I22!dQ_5xqc+Fs?pfz~ zfzCze8{8Uv9{pDSprts9GFC!gzjUsK#848lrv@~UAi5rGF zmM@$}DJf#jbRiWH0ozc1TNM%?=mYVk=o!7Dhjb5#lp=@>f==-XAnKOQe9#H+`&hzngG{` z^-6wR70M3-XTX-^BdHCPTf1A{188D0=f9Gt*(6`Mhq+?E7OdaZ($|@ll@(D~SeT=M zx6N|ERCGzNyF=hSC2ZUB>IndMW={v1G?9#)-Eqy3CVU&=0FeA*7Zcl#g_>SD;2jKe zphq)vsEoSv3>zg(Tv3}Z<7K}L{b;{{?lS&iS9u{`^Jn7p%VzNIIx-rd4bLNimp`YwYVY$7vc%9nYUX$G`}# z#d@fn)B`{<8>|+y*Xy2xDAOb`-3N>~ft_CFaV9(cjZL3Te6*cUn}qKNJgH-1;(V@U z;*I%=&J=d7v-0#GD@GRPkQgIm<-5L`QuliPfRWPJFEZKQFF+#q_3te-y9945nppA^ zgsUo)ouZv?nQ4WIi-YKVl{!)^z6C*ye)34!Y|bp*36f(%GX%lYN|3FloxJ5c5gZJ! z*t;bGa-FSSjC6f>W`LYvdp~;dCV4$g2=!Y2KG)qV z@oD&w{Ea+LMH^yXDVfo616;2hV`4l&K!jkxVgSDLIHa5lrbyG6&%YqClad1IEo$(U<{D*bz_QeHoqeYrM`T}qPP$gp$=A+#c9Cy`Xf?goTvoWGhblx3mr+Hj4(}?+4^`~m znLo(;Ub%?%TdndsqFkBqrjY)3IqcnqZXX~PY0g6csPxlse7;-ME&n@;$*S)|6_d&4 zkIFKFpS5#U&B|3=sv-C$MEugMqOGK}+j? z(G?ym>C6Q;%VG8+Ve^sj=c&B;FpWo4M%|6AA5U$dw2x<})_*}Y1qs9Zm;-e?wog!z zNY8~nLd~c>kSfdkFKwkuNL~h^fqqaccp$K)#S)CiN46bp>#>)|C&+YDa~ntu-&%S^ zC+?&TGb6|vW#TaT;LpB5AD3pMkK!;KB}Z}^s}q;@k85y0h!zN(1H?0zHkh6 z{(eY>ZuNIGPD0#%9Dj$M+quhlLrwGI)Zl@(8~I28Wmy|Q(tqgiy;y+0_phc`8SP+Z+RaR1U^9EK&}ChYJMsQ{pz zk;+M6#WmE_yz@J~k{Q|dg6Y1#)m?n$pjUnu-~b})vd*O+rAPK~w7g$+XE_6`K+mx_~w&SyVfTvd5FaL2V=i5OUP(E^P9!^5^d0GlshQ%(Nb){!c+ z&-*r?yS|vm6}DVv8CxM<`!zV^X9p?ZnS!TvdT7Cc_QQ;b2b^>x%Kut0$xoY>vYqoq zLnxkfy-u#ZTThwH9^nZ^d8vq7$ zsCS%16cHFEc^?Usgx@dHZDs#${L|Ffd9KBt<>tdP23$Ag1e*RC2jU>Z+*IXe&T{`)T{EhcoEW0p@<3`FU&UY&HFQMEW3QazzI_}>~ zJ@ah(-O#ub9)FR7m}4xRS5eXCnSQoC9;0u6&Z~#+NiLl;CRJbR6zL+w7?Opnc<+Jq zWVR=&F_xe2QxDc1O$*dP*z4|I_0nzPL-M5@UkoB(lf4VNf`mY^@Y1id8#aNz*oi}G zn@K*ha&Hdaf(Z#SztP6@OQ+;jpQV>k@F}4t^E^AxgmyTA5{FHBa65(lh0Uflp~V2P ztZ|O~4thgAwHiT*Ds>;!h3?D`E^ZGS&y(b6uzN;VM&2>6`wR8))3rU%-X}+T-|TPT z?#^`MmZDbEryYOUNOJCyeSC0~M5@g*3@a=31I6IY#+Ag5|Jk_q{DAMJy?Y>V;&4ld zBr~DT%sD8&X2nkRDXz)o<1@{$2siPyw71*Nd?#7=NCIbqLv!04mo3ilBnSWQnWY@< z_}F5O5WqeuohJ%JkcRw#t!Jh)xFT0IHMOKKU%n*9#>N%{;LX1Y`sdToGqc_ISunxM zpUxV^f^mxxEN%{3eXIF9f=9YLQ~#vnoAj?uuERN6s!En!@$3uJtS_M-K_%@>LD41x z@<=5WRzvGMiwXUM+Yu)2`&QiA-oDU_ z{GJbdJyd-{P5ac`1_I{Kr`~71{p9T-s$c~f=nKCRF)7Y1|424OPXOUhT2!>w8Hy53 z4eLVqbJ(tJBJ)bJ>|d(h2>)XSLmtLxRfXHyy6xlh|GjzooW6 z#~WQ>@{C*v?Hf~{F}@v09GuYOhWBmzcO1AV$8TW9M7rmXJvV}#y2&I=WYEuvo8min zFfV^EH`$KxZS^9t-tUY8zBy|8IdsGm^i|(E7Ehni{-&o|uQPmZ-Spikqs!34JZA>z zy*&C_%}gE!gYmMydi83bwR4Nx;XxC&$46q?as&_@_6ieDJLD-KWJ6Vf6(R^~~qxU=kh{ zBtd)vD5udJMaL+u9Ln$QCIL^>ya+@3676$%q@P`%vLIF!iQmg6D{Zu;DLfN??~WCN zrMAy;Prcz4w@hprOdld0tFeFhT)@j6e}hfZNrWu*6R2 z+y0A9PeLMsd29Mhy6SxE8XC7}XRBEj+8+zd_1Yej@ZpZnu9fV2^UH#i%<|N^@?lg3 z)$=9!_Q`8^w8O$(OO3JbRJigq!!jPA&*V299=~F+7C~F%&70RMCrbZ9$c;ev!FLw) zbgE$LARPkpmpoumem!euZu9kx^F)&e|3VRtTq`M6uJA`tf}-qZwB)69&P9=wfo>vJ zb)wRumy}urxo+AMjgRkM#eMW*+)fbeaqI&w;wt^b=vtKa#R5eKYeygj;^9E#}+k7d+onIu78OZ}gL;L}%R= z96nb(_!VP~lAyq-Vq%)5=Gc%_fVK@Rlfb<@HY+R5TCO9rs_o7`7sNW1PQV~4wICFe zrKOlxGEIaz{t#tqlo_{yHPP5T^)+j~Sw(6W3QVHwEDX~alE~cTEhdQ@$y@rfq5L{u zET`3rNmbRxR@GW2SmS0A&O{lF>5paFr23yOLKj+O7~=`WXtjtG8p%u>mFWQs?89GG z{b)a5nd{;c&ndHO>&6wZ`GA z-QDEG=flJ4n|bPpSD5QWhi~{L6x(C8Zv+$Cpuew{hiwXKl({WWIGfNhMyU;#P!e5r^u~y z?l#VFGUybaGNVOz4@$%c-pl+;98s&9KX619bMANVGs9%fJ1!-flBtcBv~-RUuZLHv z%sGTr&qb7xm_$^TV4*5o2W3?4u{r3QQ>o4P$3>=CA?6 zuHg3N;swz!1^Aa_VK~4r!thUJL6h%#G2q(M0H}uQ|2Z)uEW0oH6^u=V66laYyQ33=t*+kbqA+w#(5o($VdIfMVE2!I2h1?Y~D$yuON1vD9JaNTmke2P=yJt!hHT?6PVG{|xDqibsv?3mOC2_0d&p2 zU~}hvJ7iGBr=I-bBOsrHf$nda#dkn;){5_+=JR>dV1@|?Sm_@gk0%4DTjRtoutl{2 z*=9>&!DJFi-U5%HAd|K==0skJAFAjws4;ec_zIK_QT&B zfh$n*sm|#mc{poorP1z+3Icv_u50sM$ngbR5PA$VF+0L)Yt9s~{9t+=X<+z?P(1y< z+h{QbAxn+T1LA4h!I1a}8M9K5A6lof5P3Ig43CfyZFHCF!=sY%oM6{$p$OM%_$)jr zf*JymfdYA#=zKC>6BCm*YXV+p4T4G1luvwRuu*;t;b4atr$LF*9J4<>73>k|!Z)`XmJ5EF>DZ@ykzzH~ja+K$Z4%s1IK9)Ps>jXk$D-e4eW`OEO@_!#k zd_+O~HUzKg8cV?*dzF8g;*nAl2KY25;4$tpL#Tn=?!R|;9^QkxxpK8_>%ku&2%rAH z9|8ZjdGLG6qxw@qWkbr}z|jA>*QnEQVopb9n)Z4kb7RnN!vHy~&K7mhTtQkYVv4R9 z0T-@)3iS!#vD=`Ir>L=H{r~$A_zcevF!|)}Av7>OLSMBne~FNd1W5#%Z}-M%r!*Xl zhD>8cT&7=nHC)bDumpw-l?E#?Hk%oq#eKd`iZEm%^&DF-%Pib8M=0z89ncqvG{McP z%>%5JL3HwT&|?^nKZ6Lr&t}^zE5CqP*}JlXBSd{_$@kQTS*4z1r1=Bx-c9F;6ONn5=mq zG?40lnVp>cv!BNNs@D`O37Q38_`g2o6oO6Ph6cjU>tju?$Ikf$e9!>?5K<#Qs?Qd8 z?)CR>wMBYSpWFu%@$N%OBG(E4@9v*o<6`wDI{CN?$nzk7A~J>4y=C8gg9N3UEwn;|RcrGGn@M!55)yYPJF&!$pTE!8(r6aop%l{JWUI(5T9t zG&VM_SJ+=lwMuV;Q2xh=KdWwsC*u~LM$PCEp8?cn#6Pf(;M|D zd00ETd7elf7@MCHt&FnI6YZf^`(*u`wJt<=Z4CfsX%D4Yrk1CM0|=*5jpTTLBy}(^_zj z1#&2bops>jz>B)dXFOMl z3)4a{1r(R{HHnP`@!^XtFr_T2KGXO#7FwSi;&{3ChoBn?qDVhz@k zPgith17Nb=<~Bh%fZUmgT8#zS-%)kDh0gnq0LR=iFfbUtgUL2*o!xO~K|Y}GgzH{h zm@>TY8fE$}9T0TkxUB^y{N2CT2W;;Ugmh%~3#4R!uiW0XgqH!;@{pq~t?MsR0f}E( zSz4MFz_OUV&}*GhhMm}@96o@ZSVMl4E1G{PhRS;L%5YxJ6==W;i&6MeH(bXa$_7;is4L^h>BNBN+h+I~7@=l} zJ*Nr(ICY*V2YKz~vt@;TGt|`7E98taA^}j3AZKUaeLlta<#_`yv68wSBx_-QuoMu81$awn4KamPkdB6%~?XsR)iCl5G;GWxSK(yalX&Pnv~4NW-ff2M%9g6d1J zmWGC6MrLNFC{!1$E?o6g<#Zp_Lrk1G!Xti#G$mvMtEe&qE`2BTA+f!b58hSS_*{)F z1ON1a2ts(J6}HV)hTHlV2#Q^L)y5Eq@lO6f`nunM7TPX~&)4cRpskI}PJAZXQ z@4ukN?^Jk_(!uj};G`Yxw(ia93Bpu6Hf80|dKhk)LR_t&B45h@%@!rV4x%sh`Rrb1 z#shl?2kDjN<<~-3kNEz*5Lzvk3o^(-rU(r7&SIN)^92T$6!b2c zZn$T?J;~(mhkQxP&KwWm@mF!UZe>91{g=&|rUz}j)c`I^*WI8H0J^!DD)19s(SM~IG+=q34}|ElUZut`Y=Qv=!&Jw3*z zrW`=lN`3f{8^Gd>++0Rz#ZB#srhIe!_wW}KY`vDi3Mc|1)|Pn$d^ID0`YsI(4_DDp zQ@;?#V(nc+LXMp<`v$l_hy0j7K(_8rAk(7X>gQOR0xyJwhcTlH8+9@BIEHZ|_>PEE(NJo%&dtvDe^pcSQv;<1MBZ*-r<4H8tf0(h zE%;UVt02PAmA4_EB)x7e^Y5bTZ6 zro14$c)?KTHn9!#ms`aEHEqEXB-yj4L)@bWjfg<3)F^!V^dFZCK)JQHqT=EvVCUEo zEg6E>Vy`-bw7UTKQCDw(piQBnwF!EWk~Eg6G5dtv1*P|}?(wgoW)wK8PpYYWU`mO$ zXmHPigi>B!TG}@u=BO{ydItiYWYnMTO?P16^aGXG%&~b2Fvxf)`armyEY2R2U+E(q zlU@w*Ec9zoO+mi~OLPh=_7islZAuyy6_pjtQee3TF1s4qhl-y+=V5~bB>)Ethl4JQ zL9DK>E+g27`@sH}rHGCse3^rBnhml2KA3$~+-usD$9%F;D<3|79J$uuZj%;+%InSO z7OD{X2erJV&U3;;!hC#9s<`F*qw{xbo**3~hVSuN3F=@Sc&wsJQR8GpjwDhh+A%Te z4{9P?{c$7_Z=w`n=F%U12<=HLEouuxfJ_{tQquL4ix@hGGl45!^&HN)J;rkV?dv*W zjdmwEN_E+4oo0++*vkBw8n9?T#J|{*@~Q5kv!tvPBsGdWr08yu|a4uj#z zPKI#kd(+X>>>Y;L#LImZ6%~3K_Z9A9d6c5tHi5hH1Z$ z@Ifjh5sV4HmWByQCmDRs^=CiPESs^=EP5L@fI-;m<#QJ}Q0hUihE5mmxe&o`Cg%un_ z8XVrlE9{q;)N>L^=Q!Zz2`E6e*YLJ8Qf>M^eh(P@HjGR&r=e873qjZTtlZ?l5BVvM z&cf^nfjnjM*b)GtnqfT`EiUCVz5vF1+F!|ntN9J&OY?wFkX>PBw=OB8(n((^7MEF) z-#&%m{7M?j$oe9vVw8YE3=kmO3@w5gzn!I(RT`6JzBtAiL@Y`Iv``O}MQ|Ugq1+Gt ziJCFaSa2EfkuNU;+jhWrO4gkGV=ol1t!hYO+$dKXsfP}7{OcgSQ^Gusy4E2{VlYJN zOHE9y6|Z;7Tt@n!4V9JQ3ZbJlxkc-lFUT-RLnaR$_7ZXJ%`jbK%)pg(W&9v6RrcuRsP8beQAD>e#Vain^8; z)YI?{ghF7Llzk8**yqbzX$}Y>kYb(*Tk~pbYXwzRRj2+9{$n>m3~*sLEjRqFO~T_k zwn^&v=_zm&j1KVkcgbJaV0MK+@WY*R*lSQw#^b$kps=l^82SPB9D)H1*TS76Cc>vrii|O#uSEqk5oS?mM-x9{O-4~UufwsK3@GxH6Fo+ zAs8wD?KCK2OMy|eNz&gEhR`qjOyFW%vCh(K!Ug2En)Yy6`R?xSVFHlKnIPKJ!9$<8 z8fbpXedmD$@b6$ynw14=;(x7LwJNLQ-aYmA!p_x)>!zKZ-7jGG8=|uw4@2xGUIQb` z34}8HVMHD?Tf2sD->TEoj$Dre2#8JbsJ}sSBl)vrUS3{AZgB7ruQeOx4rJ@l2H-?E zJ5rVps=Dld?I0vH`E5>HcvS}XxuFSsoFZWpm0UVyRqu(=U_#wmugGtRM551k3J&NI zxNtuxLNmpDZAfrPA$^c(i6Eb&^)^eX*%AW^`>LLV(i=CaF$64R7zt;S5A7Utjr?n|@MA{{5Q&WhacE9Hj z4#%L+gVG+vv`8fv9dH)>vT}X{wdNK?NHq#6#Cs+0xw*M@?d^7O54;+?mRb8sJq`sy z2Qa(Ips|Qw0Di&?p-A+EKp-qDfq$SnD3sQ#v7pF;4hJ6H4v(ll>5lDyfeph4hi{3D zqOxEF0ab26MW_tU;<^Zti1n9ynykS*a&Ghi@yuu7ebEixGH$OLe?LVShQj9&*oSyr zOURvtF5hh^jy73wrIt&;%AZ?M4iip-n+{1|~lC-`LGec}v5;Nom50Mw9hraB|f6djx0+YHt#Mx$e6RqbtUbm)(X>i{~N zmqFo=u)R5+o;sXhAVKZ#az_{uz`M8uSRxLr1>$*7Ya78Y4I_+-f{y${#3r04tdA~$ zC`7P}N%r&hhQM1d&nXiv#lo2YZUp6zMAy)af~RpkcdGMwQh0JBf zU@#iNVg`|8@WB0|N7~=j)m4J<%xS+)L)1S4g;G?);FS$K)hhM3ua%*t`Oh~OIW3s+ zo(!}Q|j;EB~9hk)snk=>GdIkhgA-|zydG*K9QmK_|@0!O**$1%hSDQ zTR$qEFI|the!704#AfWQq@fs>aFd#3fFN37{iYd%$YX1rUaQW&xCdpA7kfBN(ky}am`&B;Y4B2Rkz z_}Cd2+7fYgYjl&-(;We$)xFOQv#_vGCDY&V1%j3UYRN~x&AcnD->Qz8`JD5*+~*J) zOUiEDjkez)2n+gluG36lFJDd5L1E$xGzzCS?uho@Yo$fz_?R)eTRsS+mY6Im)U4hc z)_0ZXc!L)PCg->{_0d~Pd3ekYJZ5tD<&#cNgX3+Dof-l!a^E=Ks|ld?ze&9~nsm~f zv(re#Hg2Cu+FBafb|OVlUQuyeY!kUlEJ#dzX2J2F%TP;$H)Vxf?u5+-44yeMfmYugjz1RpNn=`yZxK@ig}KVkZsP}WbH5`^ zH!yefGB|M@ftgnEtPx*8={M`AjH(#{B}ZQ`PiBU4?oiGaOC?|T2KRauAGR$?Hh(FX z*i6GgXrNoPX05x{AHTgt@L*^gWuxk_{K#E6l*SP}Y@&^}y^8Z)YXH9#vgKb-l{A#` zljqXv{Tj$w{{1w<%x-&#qPmj*_ZIT%V+-c4pfbCXf35&)5wSgw=*&ou|1SFH@;T2j z(Xpb-RR;gJa(1>R$~Z{-yl%nYo2~5OTc%MMm-sLM8c6?KW)EpvGklx=W@&kRpawiR LY;Ts#B|P^JGqL6& literal 0 HcmV?d00001 diff --git a/docs/swagger.html b/docs/swagger.html new file mode 100644 index 0000000..a724f5b --- /dev/null +++ b/docs/swagger.html @@ -0,0 +1,13 @@ + + + + PVC Bootstrap API Documentation + + + + + + + + + diff --git a/docs/swagger.json b/docs/swagger.json new file mode 100644 index 0000000..0f57543 --- /dev/null +++ b/docs/swagger.json @@ -0,0 +1,191 @@ +{ + "definitions": { + "Message": { + "properties": { + "message": { + "description": "A text message describing the result", + "example": "The foo was successfully maxed", + "type": "string" + } + }, + "type": "object" + } + }, + "host": "localhost:9999", + "info": { + "title": "PVC Bootstrap API", + "version": "1.0" + }, + "paths": { + "/": { + "get": { + "description": "", + "responses": { + "200": { + "description": "OK", + "schema": { + "$ref": "#/definitions/Message" + } + } + }, + "summary": "Return basic details of the API", + "tags": [ + "root" + ] + } + }, + "/checkin": { + "get": { + "description": "", + "responses": { + "200": { + "description": "OK", + "schema": { + "$ref": "#/definitions/Message" + } + } + }, + "summary": "Return checkin details of the API", + "tags": [ + "checkin" + ] + } + }, + "/checkin/dnsmasq": { + "post": { + "consumes": [ + "application/json" + ], + "description": "", + "parameters": [ + { + "description": "An event checkin from an external bootstrap tool component.", + "in": "body", + "name": "dnsmasq_checkin_event", + "schema": { + "properties": { + "action": { + "description": "The action of the event.", + "example": "add", + "type": "string" + }, + "client_id": { + "description": "(add, old) The client ID from a DHCP request.", + "example": "01:ff:ff:ff:ab:cd:ef", + "type": "string" + }, + "hostname": { + "description": "(add, old) The client hostname from a DHCP request.", + "example": "pvc-installer-live", + "type": "string" + }, + "ipaddr": { + "description": "(add, old) The IP address from a DHCP request.", + "example": "10.199.199.10", + "type": "string" + }, + "macaddr": { + "description": "(add, old) The MAC address from a DHCP request.", + "example": "ff:ff:ff:ab:cd:ef", + "type": "string" + }, + "user_class": { + "description": "(add, old) The DHCP user-class option from a DHCP request.", + "example": "None", + "type": "string" + }, + "vendor_class": { + "description": "(add, old) The DHCP vendor-class option from a DHCP request.", + "example": "CPQRIB3 (HP Proliant DL360 G6 iLO)", + "type": "string" + } + }, + "required": [ + "action" + ], + "type": "object" + } + } + ], + "responses": { + "200": { + "description": "OK", + "schema": { + "$ref": "#/definitions/Message" + } + } + }, + "summary": "Register a checkin from the DNSMasq subsystem", + "tags": [ + "checkin" + ] + } + }, + "/checkin/host": { + "post": { + "consumes": [ + "application/json" + ], + "description": "", + "parameters": [ + { + "description": "An event checkin from an external bootstrap tool component.", + "in": "body", + "name": "host_checkin_event", + "schema": { + "properties": { + "action": { + "description": "The action of the event.", + "example": "begin", + "type": "string" + }, + "bmc_ipaddr": { + "description": "The IP addres of the system BMC interface.", + "example": "10.199.199.10", + "type": "string" + }, + "bmc_macaddr": { + "description": "The MAC address of the system BMC interface.", + "example": "ff:ff:ff:01:23:45", + "type": "string" + }, + "host_ipaddr": { + "description": "The IP address of the system provisioning interface.", + "example": "10.199.199.11", + "type": "string" + }, + "host_macaddr": { + "description": "The MAC address of the system provisioning interface.", + "example": "ff:ff:ff:ab:cd:ef", + "type": "string" + }, + "hostname": { + "description": "The system hostname.", + "example": "hv1.mydomain.tld", + "type": "string" + } + }, + "required": [ + "action" + ], + "type": "object" + } + } + ], + "responses": { + "200": { + "description": "OK", + "schema": { + "$ref": "#/definitions/Message" + } + } + }, + "summary": "Register a checkin from the Host subsystem", + "tags": [ + "checkin" + ] + } + } + }, + "swagger": "2.0" +} \ No newline at end of file diff --git a/gen-api-doc b/gen-api-doc new file mode 100755 index 0000000..b44b6fb --- /dev/null +++ b/gen-api-doc @@ -0,0 +1,24 @@ +#!/usr/bin/env python3 + +# gen-doc.py - Generate a Swagger JSON document for the API +# Part of the Parallel Virtual Cluster (PVC) system + +from flask_swagger import swagger +import os +import sys +import json + +os.environ['PVCD_CONFIG_FILE'] = "./bootstrap-daemon/pvcbootstrapd.yaml.sample" + +sys.path.append('bootstrap-daemon') + +import pvcbootstrapd.flaskapi as pvcbootstrapd + +swagger_file = "docs/swagger.json" +swagger_data = swagger(pvcbootstrapd.app) +swagger_data['info']['version'] = "1.0" +swagger_data['info']['title'] = "PVC Bootstrap API" +swagger_data['host'] = "localhost:9999" + +with open(swagger_file, 'w') as fd: + fd.write(json.dumps(swagger_data, sort_keys=True, indent=4)) diff --git a/install-pvcbootstrapd.sh b/install-pvcbootstrapd.sh new file mode 100755 index 0000000..cdb83db --- /dev/null +++ b/install-pvcbootstrapd.sh @@ -0,0 +1,211 @@ +#!/usr/bin/env bash + +# PVC Bootstrap system installer + +echo "Welcome to the PVC bootstrap installer. This will guide you through the setup process." +echo +echo "Please enter the bootstrap root directory; all components will be installed here:" +echo -n "[/srv/pvc] > " +read root_directory +if [[ -z ${root_directory} ]]; then + root_directory="/srv/pvc" +fi +echo + +echo "Please enter the IP network for the Bootstrap network (should be a /24):" +echo -n "[10.255.255.0/24] > " +read bootstrap_network +if [[ -z ${bootstrap_network} ]]; then + bootstrap_network="10.255.255.0/24" +fi +echo + +echo "Will the bootstrap interface be a vLAN? Note: It should not be configured yet if so!" +echo -n "[y/N] > " +read is_bootstrap_interface_vlan +case ${is_bootstrap_interface_vlan} in + y|Y|yes|Yes|YES) is_bootstrap_interface_vlan="yes" ;; + *) is_bootstrap_interface_vlan="no" ;; +esac +echo + +all_interfaces=( $( + ip address | grep '^[0-9]' | grep 'bond\|eno\|enp\|ens\|wlp' | awk '{ print $2 }' | tr -d ':' +) ) +if [[ "${is_bootstrap_interface_vlan}" == "yes" ]]; then +echo "Please enter the underlying device for the Bootstrap network vLAN:" +else +echo "Please enter the Bootstrap network interface:" +fi +echo "Available interfaces: ${all_interfaces[@]}" +bootstrap_interface="" +while true; do + echo -n "> " + read bootstrap_interface + if [[ -n ${bootstrap_interface} && "${all_interfaces[@]}" =~ "${bootstrap_interface}" ]]; then + break + fi +done +echo + +if [[ "${is_bootstrap_interface_vlan}" == "yes" ]]; then +echo "Please enter the Bootstrap network vLAN ID:" +echo -n "> " +read bootstrap_vlan +echo +fi + +echo "Please enter the Git remote (SSH-only) for your local PVC repository:" +while [[ -z ${git_remote} ]]; do +echo -n "> " +read git_remote +done +echo + +echo "Please enter the branch to use from the local PVC repository:" +echo -n "[master] > " +read git_branch +if [[ -z ${git_branch} ]]; then + git_branch="master" +fi +echo + +echo "Please enter a username for Ansible management of the cluster:" +echo -m "[deploy] >" +read deploy_username +if [[ -z ${deploy_username} ]]; then + deploy_username="deploy" +fi +echo + +echo "Proceeding with setup!" +echo + +echo "Installing dependencies..." +apt-get update +apt-get install --yes vlan iptables redis python3 python3-pip python3-virtualenv virtualenv + +echo "Creating root directory..." +sudo mkdir -p ${root_directory} +sudo chown $USER ${root_directory} + +echo "Creating virtualenv..." +virtualenv --python python3 ${root_directory}/venv + +echo "Installing pvcbootstrapd..." +cp -a bootstrap-daemon ${root_directory}/pvcbootstrapd + +echo "Determining IP addresses..." +bootstrap_address="$( awk -F'.' '{ print $1"."$2"."$3".1" }' <<<"${bootstrap_network}" )" +bootstrap_dhcpstart="$( awk -F'.' '{ print $1"."$2"."$3".100" }' <<<"${bootstrap_network}" )" +bootstrap_dhcpend="$( awk -F'.' '{ print $1"."$2"."$3".199" }' <<<"${bootstrap_network}" )" + +echo "Creating configuration..." +cp ${root_directory}/pvcbootstrapd/pvcbootstrapd.yaml.template ${root_directory}/pvcbootstrapd/pvcbootstrapd.yaml +sed -i "s/DEPLOY_USERNAME/${deploy_username}/" ${root_directory}/pvcbootstrapd/pvcbootstrapd.yaml +sed -i "s/ROOT_DIRECTORY/${root_directory}/" ${root_directory}/pvcbootstrapd/pvcbootstrapd.yaml +sed -i "s/BOOTSTRAP_ADDRESS/${bootstrap_address}/" ${root_directory}/pvcbootstrapd/pvcbootstrapd.yaml +sed -i "s/BOOTSTRAP_DHCPSTART/${bootstrap_dhcpstart}/" ${root_directory}/pvcbootstrapd/pvcbootstrapd.yaml +sed -i "s/BOOTSTRAP_DHCPEND/${bootstrap_dhcpend}/" ${root_directory}/pvcbootstrapd/pvcbootstrapd.yaml +sed -i "s/GIT_REMOTE/${git_remote}/" ${root_directory}/pvcbootstrapd/pvcbootstrapd.yaml +sed -i "s/GIT_BRANCH/${git_branch}/" ${root_directory}/pvcbootstrapd/pvcbootstrapd.yaml + +echo "Creating network configuration for interface ${bootstrap_interface} (is vLAN? ${is_bootstrap_interface_vlan})..." +if [[ "${is_bootstrap_interface_vlan}" == "yes" ]]; then +cat < /proc/sys/net/ipv4/ip_forward + post-up iptables -A FORWARD -i $IFACE -j ACCEPT + post-up iptables -A FORWARD -o $IFACE -m state --state ESTABLISHED,RELATED -j ACCEPT + post-up iptables -t nat -A POSTROUTING -i $IFACE -j MASQUERADE +EOF +else +cat < /proc/sys/net/ipv4/ip_forward + post-up iptables -A FORWARD -i $IFACE -j ACCEPT + post-up iptables -A FORWARD -o $IFACE -m state --state ESTABLISHED,RELATED -j ACCEPT + post-up iptables -t nat -A POSTROUTING -i $IFACE -j MASQUERADE +EOF +fi + +echo "Installing service units..." +cat < " +read edit_flag +case ${edit_flag} in + y|Y|yes|Yes|YES) + vim ${root_directory}/pvcbootstrapd/pvcbootstrapd.yaml + ;; + *) + true + ;; +esac +echo + +echo "Restart system to activate?" +echo -n "[Y/n] > " +read reboot_flag +case ${reboot_flag} in + n/N/no/No/NO) + exit 0 + ;; + *) + true + sudo reboot + ;; +esac