From 7c34fc71bf6d6ad1cb5fbf93ddcfa3bfa705e208 Mon Sep 17 00:00:00 2001 From: bhearn7 Date: Mon, 7 Jun 2021 15:25:51 -0400 Subject: [PATCH 1/8] update redis dep --- chart/Chart.lock | 6 +- chart/Chart.yaml | 2 +- chart/charts/postgresql-1.0.1.tgz | Bin 8687 -> 8687 bytes chart/charts/redis-12.8.3-bb.0.tgz | Bin 54151 -> 0 bytes chart/charts/redis-14.1.0-bb.0.tgz | Bin 0 -> 82358 bytes chart/deps/redis/Chart.lock | 6 +- chart/deps/redis/Chart.yaml | 4 +- chart/deps/redis/Kptfile | 4 +- chart/deps/redis/README.md | 782 ++++--- chart/deps/redis/charts/common-1.4.1.tgz | Bin 12484 -> 0 bytes chart/deps/redis/charts/common-1.5.2.tgz | Bin 0 -> 12953 bytes chart/deps/redis/ci/extra-flags-values.yaml | 5 +- chart/deps/redis/ci/sentinel-values.yaml | 6 + chart/deps/redis/ci/standalone-values.yaml | 1 + chart/deps/redis/templates/NOTES.txt | 136 +- chart/deps/redis/templates/_helpers.tpl | 402 ++-- .../redis/templates/configmap-scripts.yaml | 430 ---- chart/deps/redis/templates/configmap.yaml | 72 +- chart/deps/redis/templates/extra-list.yaml | 4 + chart/deps/redis/templates/headless-svc.yaml | 28 +- .../redis/templates/health-configmap.yaml | 44 +- chart/deps/redis/templates/master/psp.yaml | 45 + .../deps/redis/templates/master/service.yaml | 46 + .../redis/templates/master/statefulset.yaml | 402 ++++ .../redis/templates/metrics-prometheus.yaml | 39 - .../redis/templates/metrics-sentinel-svc.yaml | 38 + chart/deps/redis/templates/metrics-svc.yaml | 42 +- chart/deps/redis/templates/networkpolicy.yaml | 53 +- chart/deps/redis/templates/pdb.yaml | 27 +- .../deps/redis/templates/prometheusrule.yaml | 26 +- chart/deps/redis/templates/psp.yaml | 43 - .../templates/redis-master-statefulset.yaml | 382 ---- .../redis/templates/redis-master-svc.yaml | 43 - .../templates/redis-node-statefulset.yaml | 507 ----- chart/deps/redis/templates/redis-role.yaml | 22 - .../redis/templates/redis-rolebinding.yaml | 19 - .../redis/templates/redis-serviceaccount.yaml | 15 - .../templates/redis-slave-statefulset.yaml | 386 ---- .../deps/redis/templates/redis-slave-svc.yaml | 43 - .../templates/redis-with-sentinel-svc.yaml | 43 - .../redis/templates/replicas/service.yaml | 46 + .../redis/templates/replicas/statefulset.yaml | 405 ++++ chart/deps/redis/templates/role.yaml | 27 + chart/deps/redis/templates/rolebinding.yaml | 21 + .../redis/templates/scripts-configmap.yaml | 450 ++++ chart/deps/redis/templates/secret.yaml | 16 +- .../redis/templates/sentinel/service.yaml | 54 + .../redis/templates/sentinel/statefulset.yaml | 580 ++++++ .../deps/redis/templates/serviceaccount.yaml | 20 + .../deps/redis/templates/servicemonitor.yaml | 85 + chart/deps/redis/values.schema.json | 64 +- chart/deps/redis/values.yaml | 1845 ++++++++++------- 52 files changed, 4245 insertions(+), 3521 deletions(-) delete mode 100644 chart/charts/redis-12.8.3-bb.0.tgz create mode 100644 chart/charts/redis-14.1.0-bb.0.tgz delete mode 100644 chart/deps/redis/charts/common-1.4.1.tgz create mode 100644 chart/deps/redis/charts/common-1.5.2.tgz create mode 100644 chart/deps/redis/ci/sentinel-values.yaml create mode 100644 chart/deps/redis/ci/standalone-values.yaml delete mode 100644 chart/deps/redis/templates/configmap-scripts.yaml create mode 100644 chart/deps/redis/templates/extra-list.yaml create mode 100644 chart/deps/redis/templates/master/psp.yaml create mode 100644 chart/deps/redis/templates/master/service.yaml create mode 100644 chart/deps/redis/templates/master/statefulset.yaml delete mode 100644 chart/deps/redis/templates/metrics-prometheus.yaml create mode 100644 chart/deps/redis/templates/metrics-sentinel-svc.yaml delete mode 100644 chart/deps/redis/templates/psp.yaml delete mode 100644 chart/deps/redis/templates/redis-master-statefulset.yaml delete mode 100644 chart/deps/redis/templates/redis-master-svc.yaml delete mode 100644 chart/deps/redis/templates/redis-node-statefulset.yaml delete mode 100644 chart/deps/redis/templates/redis-role.yaml delete mode 100644 chart/deps/redis/templates/redis-rolebinding.yaml delete mode 100644 chart/deps/redis/templates/redis-serviceaccount.yaml delete mode 100644 chart/deps/redis/templates/redis-slave-statefulset.yaml delete mode 100644 chart/deps/redis/templates/redis-slave-svc.yaml delete mode 100644 chart/deps/redis/templates/redis-with-sentinel-svc.yaml create mode 100644 chart/deps/redis/templates/replicas/service.yaml create mode 100644 chart/deps/redis/templates/replicas/statefulset.yaml create mode 100644 chart/deps/redis/templates/role.yaml create mode 100644 chart/deps/redis/templates/rolebinding.yaml create mode 100644 chart/deps/redis/templates/scripts-configmap.yaml create mode 100644 chart/deps/redis/templates/sentinel/service.yaml create mode 100644 chart/deps/redis/templates/sentinel/statefulset.yaml create mode 100644 chart/deps/redis/templates/serviceaccount.yaml create mode 100644 chart/deps/redis/templates/servicemonitor.yaml diff --git a/chart/Chart.lock b/chart/Chart.lock index f6be325..5d3641e 100644 --- a/chart/Chart.lock +++ b/chart/Chart.lock @@ -7,9 +7,9 @@ dependencies: version: 1.0.1 - name: redis repository: file://./deps/redis - version: 12.8.3-bb.0 + version: 14.1.0-bb.0 - name: bb-test-lib repository: oci://registry.dso.mil/platform-one/big-bang/pipeline-templates/pipeline-templates version: 0.4.0 -digest: sha256:cdf6e2694ba10c26845caffc96343262185f697595fdcb658c1c6e9796ddb029 -generated: "2021-05-11T11:23:19.071211-04:00" +digest: sha256:0c10340f474ea0d7c14a56d06f6fae7be320def84f8a0664843498d193cd5af3 +generated: "2021-06-07T15:24:16.279073-04:00" diff --git a/chart/Chart.yaml b/chart/Chart.yaml index 6d4387d..9c01ced 100644 --- a/chart/Chart.yaml +++ b/chart/Chart.yaml @@ -33,7 +33,7 @@ dependencies: condition: anchore-feeds-db.enabled,anchoreEnterpriseGlobal.enabled alias: anchore-feeds-db - name: redis - version: "12.8.3-bb.0" + version: "14.1.0-bb.0" repository: "file://./deps/redis" condition: anchore-ui-redis.enabled,anchoreEnterpriseGlobal.enabled alias: anchore-ui-redis diff --git a/chart/charts/postgresql-1.0.1.tgz b/chart/charts/postgresql-1.0.1.tgz index 1877132187aa7f054422eca0a279d6ed9bde09bc..64b3ecbc3ec014c2e8d5db4061058d4276ed1180 100644 GIT binary patch delta 8617 zcmV;aAy(e+L+?Y7O$id)Nwqioo}0LlRy2QSn177>FBgc3V1<(So5y_ygTdf%e_#DO z7!2zF4i29^`DVC3IC!@IY&hJ1`psbYbbs*d8yGw?9<5K#1!CU}KD(`Y=l(?=l#yRB z+>0;|8OeltcQXAu4u#KfjN}UxLxcpHB90+JDVpO1rviWY ziVK{;&dKSkAKsnq!W9tIdF7I8nMNfr~7 zhB)vRG{GZS2$AtozkhXg6_m3!plsgvNGOq8QzF3;L4A_U`)EpY(a#v>ypLm?El?_g zES-Cocy&ct#7CYFWo_q&=NFyze2{Vu_>0jnk%u*~c z?}u`&@%Ca74KFeCV=`rkt@=gtOFJ;bU=R$w#~FWT{V!3RWBvy)fc5KtI6QndtgrvW z{ll;8|4TeuTgChZlAt;E)c?y_Ju+;-+uDM&42NX40;G$M^Ee*Un1n0&ar=KLzCtU$ z4P>T2pQAYt4%;yjn2YT_z%j?bu>e6~`_1e<6=Q}uPQ|vY&+tqy;ZfgNDFLB!LGXUg zG4tm+iEv**=l!jWVL!{`n51)Gzw@@XysbKNqYCcD$1@xv zk3~5!UO93N5G-k& zCm0f%rvgaI1x69j8Q^qD7)=%1Um`}(G{#=ev910iiSY<#DCStT@-u(OaQumILDD&B zI=SFN*?;+ordS~*Aj!Fa1zJj~SmgZ7Vt0vGU`9n&6AKIx=7ix0Y#DD0uxU|KegxaP z80V_L zAx&pwo-^zxc`Qg4W4~yJ_x18BUc8sPvO?}8vqDPFl)M5Ym6LytrV%#-8$pV({6#@v zmJrp4IYS|y<#D{a6WRrPxT5SbrYPe5jOzdOw=7gbQ=iTxH!xhv`S4n{H^z+6=uBfb zf~SMZq+)q0NP}Nx&nx@x3hoh-rvoK(YQ$u$&9^enGh?UaLatO|3w(Dn-{7mn$2F-#-b4htGpS zFz7$oha@^sJs3;Diwngc1@9ci@ybZx zk;PYH_lsuRQoMc{Ba-Mkr}$$|BtLVo4(cdN?mL4B&q#`+J&A{A#Zzp?Cn{T>;u&Sw zZW31{j%9zbDb3SJLMr&L!eL}EFUYUx+C=(HP=@AMBF=deA+A5GuWHG|f4Q&zQq(XK zN6+uIRqFNj;A%m_1w@2P3UG*4DN0BP8KX-gMQ*umT4;G{Fn}Gs*{G?zE62q&l;&}~ z2Pthd22xf4V)_EI{2qi0N_n|;DQIQOm<0ek^Xz|#oC-(3p6wM!B%rB<^ZKvHd-5av z2~IMco(U9Q?y8T9_%0eFNd^x9g(2qr9gXk^PBDspWkleUG?W9+$v^N2p1&sY?|eE& zVljeV$rJo&DnTewK!5Bn5$nff+ILP9a!~u(T>hiR+nLsU1lPBomtet2$Scc53km>6 z2)%z|G{-!}aRK=Pf66EmnAt+-Xg-4FAlMHM?JGz016Ry+)}d-u{`{C@F3c~01SgcO zM)2g|@EtMl!Ym)ba4<;JZ_TYpiUCCtG22U+b3qd@9kS)RHup81+LA!ixu4=I-$3)1 z1o_DDS${@itl^tR-<3p^FF`WRs1Qr+OMrimIhGykogKeDet8a25FsItuW)n*^4~pp zd31IRzy5UmUV;dbKrx*M3&aa>7a1c<65~1EDXQrvn_Cv$pgk-}!y|a9#l3$wV-G+sh!Gs@KYb$k!zU$P#&5=a1Rs9ajPIS@ zeI(y~Pa{00OddjFyL}bgoM|Y~t=OW9E2ZYg$n#PxqyT3RjS9rEVoc^(A~)n2ymyP0 z3?;A(x5mpfobv?+QzM}fj+GdZW$`M2Ul%yFTZgK$2Q-aWQa0sUb0!Blq>O*zP-tjj zOyoWpqbZK{ZmZ5mrUQn#E0I>oxJhU5%y&3%T>}xn&h>2`&>- zeoJwv_&3ZLm2%1obmujgojS5|&I%*qDl~QrBB3~@SI1^ljmROVq8uCDFFi>Gjj-RC7EYNWL|l*M$VbPIAas38ix^6gPgq{wJgf2EHX1sJuc7|vo8 zV&H-yf#<6Sp7G>?hS69ZK}($aTP4_{1v_p=bTINlo9;v{+YFVtAa2Z$~jIkBOypkyIKa{PYdL`x&*#2$))7@ z7eT+F&y*xnYVzA#@0`LM3r$j`o+y-_EKfDIFn&EgIy?LITtv-28XQZn2f zS*62owyy&saKb+feh;`nBIf~$A|^K~_0Igb-QKlrk55kPZS!ULhcU$M>wsrC4CIEX zFtP_riISzF;_MYt7AM}j(Q^3YSujx6f47(J`jCHnbrY7_#^sCvtyVbxgu`6mb}p+# zPe$$c^4w>%WLjATTxB2p8D&?9MR&vZTiau}Gr>pq8yaWreku8{RsO$N;5fsK2O@h6 zSCD@V^8eGplc#n0|Jk#rU*-QV@myc`zk?-7MoI-G#Zt+4UL=w%;R27~yZ-I1Crf$9 zpE9MASzs;q8}*}dWePk~&Nl{{mX++61=NBFw8NoV$HfMW5?m-ZZa}a+4dL*q`jaGQ z`D{i$LC-IN$>rkf9l!sbSDNxo8_I|aA9H^clNrGgpe$3!2i~t(Ls#X6Y(sX0!xV=o z=NLFmF#NSp1el`^!EwX^F|5_6@;qVo;+^SAk;5E|lzT&l!`(ohNDTkdKnm`!D5u{M zQCQ7#dG=C9U5UKGb{%!gUC9!~IUw1O1yOC8&H{I$y4=X@k8f2EMlbF@unwLDF*JXa zDt9k%t-QTAf*B*Jm_hG9xc?tgaI8Sn?cQgqb^WcU;3*b4)8`kIWsGKws3}(XSt{+8 z5j3^gcf;bT%A^IH%5Za>EHQgYlT6Od-d|n}gMELn2mdt;p810w1TRsBl&>YhJdo4c zKnY$GVG)z?dd4r4ro6u#PO(74p67qcF142a-@O|!{UPZ*xO}b@Y)jijCsED1b{34} zM8+XfE*7Ltm-vRF)KS|&g-&o zYjM`)-aE^^Sav%k4dXoO6j^uIXiZ%F{@Gj7*XIj9t@58XX(T9n9B1H7{{Mf^_V;V@ z-{I4*`rj|})cpT1Ng9oe>G&PWJbQ+cM?dZDez&u+2gZu0&x|O`x@%Tyf#!$Zr47?A ziW|{t)Ht`<0t?KDP^NXa#F;*R$wIb&HOa|%3Ir8D3k_7ivK|_0k!XbJ-%t{7fN%pJ zb1Dpa71de|fx_WUe|5a!My`J%x-8ZOdENN8uK&`S^(YKrga7~j!Qr#|`agKO|8@O; ziN{_4cK%gFxufwLQ-B9QA+A(5QZ($r?JbzUOXb$>Ei?s4cP?rMQ(9#IEjWzqzfuL; zHQQ>!*5F(>InUuKa04Wba4KNm71(ZXJ$cL=HQTVZXAQQnMBfc2fc1ZcFn&Bpgp0Qh zz3)fyjYKTbQ(gngPv;bCBb*0C8`i0)oHFu>D|p=(vkka4=vs9$DB)}#xaSQb1L(oi z5NiD2I(;}zST_)_x!Dw@tId^=okkl?xeh30p^95dOOusa4{6r*?kUQ+zAr6}x^*7X zX62edS*m(_0D8^_Td#l7yKC>(IruyMU4IY2LFA4A8+etsmh4RP@5^fSW4v-*;%G}} zNt6~BTvrF)t5z(FRfQKb-PJ7uUuSZh)ug5{KH7_(Hzc&D`E@*Kny2xn%;>1h~$&7gK+9p&SDGTE^?U7a!I( ziPL3CAUmkzle6>Jr^ja(Kc5|+I`vgIM)xt*wu}it;a3^is~m)D7Ym}*UJHz3u`u3e zK@+{#e*|8Q&cFI$eG_X8$aew%=KY)VS3g`FoxVQ1Z#(4`sesy$y)P%js*S=#e z)~@8O?VEKEaP1NC98wn(`_HTVj!kDcy8oe3AEi^Rs*1Jy& z3H5ES__|h_kdLxJH@SjyOTEOq*cryIx3zw(v*=i^W0!yM_){seSTM?PTz%;SU({Yy z_?~CYl`31uCnvrc)a0VZn~h$`29noFzrSgx(%z^$#XwY{Tx+P1JNT(@#9%0<<= zXjhb|_OpMuYSmHAe0M9|pT}D+S6(D)VBN2Y9g@5!X}l^f29|BtIL}?gp8}D&znJQ4 zO&w@xA?RL+bZGF5V^)cVMZ&$X1?}>!g<<8~QP;O~G=GQ~T!FD(9Bvi%q>ylNcJlM- z%VXu6(%h~~#y{%!@8zfWe+ze`k=z;n59e`0Bm95DT$Jn@_ce;sD(>Ug7svlIJ~=%< zKD{{ppY!AQuP*-k=i}4AU5t;;f9jGuT6C}L=48iiSReVuR`~t!`LhRiu$^I)tylX{ z;niyv;(eB4=jOc-B72QRbqmRKdu{mWYgqL!-J8~9!C%9#E%`h7c7q;zJQ}B8hjZ6i zSMz^fbY)T%ca`;3Wpl0BnN0G3yJnZ98@ht`bblIB5*2LR>OR~LMg1iy|UxYMt@+$Kd%=f1jrSGCs)N<_*7$%76p z-8ASv#kdscDz&NqEgSi|ZT!m&d%KRr>1==F`=)Nz)#!(sPz7o?0?qClgY#Bmo%%9R8}m44IITWy#kV|z%1^CZcp>Fim>cguizK#@{WJ^ zWl9`pj!MsO(m+2gl(0jF0l0<=ZUii+=nnp<9JDu8*|k0@&DddH^$^}tqzn5hNg2zAZd0j*BL`t!d93)lW=CmAjJm}AFX zxWaDgVRN<5Ze8Otf(kpUSGs}e;XY2ox+|~4Vp>36U#ob(M{%}5lZ_P@e?M#9{~bO( z_{#sk#M8mr73=%A;O%#@88-y@Qil)_+Sh7?iteFWK&ujZ-w&TZ>$SvGMKx~f1xMqE;s7yLMhcuuTWNjpaI`~R`D|)NYEcj!4kIM)nCO*rK zvTHR8+ZY?WyM z)2s;mh*UsqoC0Fuf(RUnT-VmHFk&f=fCxaq1*7R47|wDNLw!b>TrWglX7PAsGMP*fUwGfb0>_C;Re|CdxRC7DA&o3((r5@q zqg?6LJ@0%$Y@CNFf2D#8hB8UMRzh#i0krFe#H6VNREDU~fa>8ZcWo>uC}XF6_zA~J z*{;z>?LvmaOEkBsoS3G>m|=!L=7bZ0x##(AP>f-)|DXDH%nw)~I2ykx!eDtmjDK+h znFG%=wM7^=@jQ(%i&qjSlFk_7g5`Q(cTUoH1y>84T2BjEe@G77t|74+1lt>RH(v$2 zvZGT*0VqP!Rw8grl9g{>Oh%n!tb+nUS+;A`&sCHp9TQEDPbD;$iJa(=&5nqngjM)e zBFP3SX7Go~yWe-VD!+GuYXgpo=xb71l$jya0x?k?iwqhOL^;z$SKZW&dEQ^(yYJ3P z_T6_QcuP$Fe+1KSZl=yekw-SAr~1z+=^BaLe(Fa!#wL=KOLk`>H%GwKDT_Dh%y2@N zn1dZ|m%22`Xo^$80dY=4qT)W5!HLzx&|?*=3eNlpDxtHHUBqsbEHwulf)^tqUpv${ z;c?s;ZAHssfe9b|HeKz_utg z5ivDd5`Ar;XBC^8Z(DWV=!{@`S8=j|%}9)EIly3vn52ygVE^!0T)&Ft(ncL`bnK+7 zQmpJAs>d6t^1{}{p^ZxNb!3x#Z3Ot)v$%2%e|1uYZF5hwXX5%Ju&EjeCKcFiIo{;J z9jR!`#Z-DkY^qm1tJs{H%vt6d=(yaWI{iD28D#U{3Kzw0fC?Mf z>CB9^y9QH@P1Bq|v9MM4HkH~*P%CTe^HC=@g5?ie;4Rp=z5|mR7|X*#r1HtxPwj35 ze-+w%)<|_&WG8S_q@N0viI&b_io#2U(l0MNXrr*%$+?nCvjwvDU<0F6Bkpd*rZk#Q zijgwuwGdY+o75qRvNC;B9h*vCr+ZPUiA|{hov3}PCBs)QtoRLe+_e^hn` zn+!)yTtlR_0Acd{HF>moqwi%EYw9eYf9lxEQuH*30E3jECV?gr6>KWGwLWj8iu)s4 z7z1?)MY%-ZjY2mt*>J=7KK!QYt0Gs`=VraT$D&u*6iy~>ymE%!=^c# z9c()0a1)!yn#Gk{L5ANPb!Elt0{HoIantBBDQRPzk>89}RCAs93Oe;CH!%6|`)BP_ zt}(2B);xbX)(KVa3J@j-`%fRHe-x-=nmC z9vC*^^!eC00jMT*Y|e{sccah^eE9t{u~`=rYGNAs{5;s3*PE98)`a0GnDSejt4@`+ zAtxYGAtYSdOb!R1cV<`{&tuYxjVV)5$HC^{p~$pjQx6I(KRf34Vb4Al)xo<1@*&7o>y(=k+!K$}Xu!K!YnEoowTYE#R) z3h=YJUu)#b$(^uqOxKTvjg5-bx-+CJP~SW9EUst{S2T|!h{+``(k{}pOq?3s8O0lI zB~&TMTq9tDG7HX4SjKG{bIFK5SQ-@u{5v=T1n?te+KYmuGs+T^e`Qr0su`YXGlsJE zKLoxx+e9=}`fY0^w#oc43KwNR9oK@1@5>|pC0@NylH7;A;?LhFfQ-6aqBe1j?GxP} z{0SvljQ8$glmE>F&~3VAo)^i=&pBp$b!*EDt&g@!=)JndK~^k`3o1|9I;+1PZ)=m* z%2^J`HTo)pl0-UEfA;TO*`Sm$x=@5qsyIyo=M)vMfCvY2fm;dEzM2G{cVx8xWQpU| z9w7MJ(Yv?WV57VNxEeoVjNaPtT&~q}-WsogOlxE#xLR17k7MrFnO`0{aQ@61zE>#e z^r&&%68=VWg;&mT#ckq)1LpS~=ZE$d8JGGfJ!rM{a97V8f4v~Mpv+Lu8Dynb(|$yb z=Ku$!t!JB6YF0sK913(Kn!va`D7OKn*wd~(Zj<4+@bcNw+BHvv)lyBb5nA*P|@ zc4Ab7gcoTu^$L$xDN0CazZc#;B%KHF#yC8*YV7$!vD%ahIj^*XQ8i=7o=tbL#zqi$ zCIz2LSFLe!e@X*RdEpr*`8y_Jftj7gfZD9DRAtv}ShV(l%DPuXep6F9&mtu7L?`N* z+w>hs*&~e^wph|v3lc6Q{m49}O!w3_ElG?_z8{@yNX{DFnJHeNC80S3td^=~0L5Wg z?i(3SBkNP78Hb$aTcyRVbpW{M4FfQFRN97V!)JYce{&dE=c{tux>vkn%3WjmV*JZX zolUKcv6=~HmN>6y&Jpl#6}w}WcHS~d)t-Zvltj*lZ4L_(MK}cuPqIdp5s{<m>t-7*>nwyvv4F$LK?^Vv!P^>TJo|?EooLSS175!NJ3)7 z0CB_JdC16Ai%3e0F?$S*>lgT;<|Nm`)yuBCe}7J6I_)P&qSLQPI(^fYTiSQH>ne$N z4RoMbV#V{KXs1UQavj7jgL8&GcJHLj7tx?Z4MJ>8=I&RRYp-w0JG6>x%nB& zXdHM|UTdYq8ZG^n#4ertDZa8{lKdq>zK-uh<|@3=uEItMo)H#^#KvK^8XCkqr^XS~ zf2O*!8gf~?+&T9=%Pu}3C^JJr7Uy#{?nnTUoz_kkRZl;!s-Ke#v+Q!qUMLX1+C#a7mF_L@JSi7BZi&lb zZ~%Xj{~Ycq_L1bu&5~148N+B=(>G2Ff2EeE63b~`_zI^hD6>_TX0rhF)~NW9+FYujYt}V2P6Wo2PvSgTdfnZ%_R@ z7!2zF4h~*C`(}40i}SGY>qhLKvTe<1Wq}bkeG-ipfr*%xj<=zSj7F1CRt2S z8sfm4(*zG;E=0zM{r>g!bx_XQfU;TNBcViYMTrDQ1ocTW>!S(HML%Ph^FEGoHbikLaaboWM)Ln^GOiWq<@u9FiWw( zydTQ7#@mZUG`zyhkI94~w(J+pFYLhV27_SNdz$fg*8c**gZlW-|NZXSQd*J#N% zflT%13p4}5VKYVobFsMtIOZ5Q79c2WzL~zKV#F}Vso0eD8J_ATJnTCwB_LET2;R>* zX8tTE5$-GKyuXn#>}Po#lXT|mcizT^w^2uKSi!ycc#cDc1+O&C+uIIl8sbc-KLjEv zX1qXxYq$jt5+SZZ`!w~DpV5D)hL&l02+5M+8R3F0ukcb~`HEpAFrbpH%6`i)$9RhJ zSd;_fl_U2v$81CCA%LYzyMrwQ~Xm8`w-5f%gif(4E9 z1VcjeQ~*i2z$gMb1)MGjqp4#13&aST#MsL@w$*l4!%eyVUJpA~tKb(Xut_8J;tSQ_<%F2@>{EmiZb?Fc(Se zboq^Xd&FjZSd1r10mTBdRFaX0a~$O{W~SRcE-1U|1@~EJ0`V)}M^QpjBKzrwajyCs z(sW8@Im3RE$AV-r_KS9SUoWrX#e2CcE96cyE2QL1$tyroIq83B8gVnQ5u_N)Ulasp z2~mBRF%;ry9>>djp4@Oe(;zIEUIZ+T~`i)|GiZOb{n-C8@0GxkHMi>ocqu2vrSc`^cM*`ST z8=-yeXX-utgyRHIno^;sD@|ea%c}rhp%f+v!h$Ons8UC0P$ARW&yy~EPH<@r^3;%=R3s_3218Jy#DLSj{FFJ zg3}DA=K_US+v=ktzKh0ClEDK&VTd_@Mt24duXd@((NZJD-e@ zm=B>>@&rGcNDxXC&>#B?#QHIr^qtd$9Mpa`lmDpkcBVBS!p)uMC0H;L^2&12f&zdM zLa%=r%`s1LTtL3WpEAk>X134;nhjww2=;;l`^pjhz!fu{b*NgEKR@P}3-b#g!3kx{ zAw1hZct^~;Fw2LqI~XMDx8_zP#ekxSnC&IZxu6M{4%u>DoBN7RZAhT$%un&PZ=m@L zf_!B7tUo0&*6>ZE?@A)dmmryDREQ<^CBT2j9LtXN&QIQ+yt;rWh>(!SS2#Kc`R@+A zIyygrUw=AzFF}MzpqS2rIpPJl%Z!l)iSZ0?71eiO^VRA5_b0C|Hn-uTR@p)2QckL} z+BTfLJwJf~oV-7l7|5^i^&B(BDiqdommn!@Z3>)Z@_;ee+=1f9uKa&t ziMzSobLf!N=_Mauk)ZlcJ~>yju=n=phm*Ix#^;J=q^DLmo$7UL@b1-`k^Q`!ECuG> zjlDkl`Sr=V#?B?dYK=*PDA+wM)>@gVnDoVTSNlOs5>h+9EMg`(TF(z{?ksI<9-n+$0 zh7wqYTjOOK&cz&qsgckK$4ZRIvUnN5uXCK*twUAW0h-23DVuVwIg^7NQpSI9C^WP% zCUT#Q(FDhOw^ipO(*eWWl}M{(TqaN;zc-y7L;$RvlS6XN3`Q6&l+Gkx(4d>k~7oM&yuFQI3u7m!718##oE) zTnmmg0>n9)sT1cz&+ckHC}@9u4Md9LzMKO64f%hLV;l;~o)WG+nF{WsH1eI!_!BIU zKgCGo412QVxoKPNjZR55-_dj`k7G-{ac;or0y9RUQecS50;h7&{{#%9h^W6aMkkni z`X4!=Z7IDrB}9VaV;rO95Do_Fr4;IEE{bEwzIr=FB+ePWm@~}hG>(6UaG;jDX{im~ zek-`=>TOm%>g-E;AC=;P8fh&KWieeU-GZD9YKQ`_e0x+ADKZ+>U+LpT0Y)tENpl89Ycuq2Zop0|_W%)0^Ej4Odl10g zU2t;)!5NM*;y92}6wl=9yt@ndA`A?$K%L_~@8-q_GKJt5ZLEK&D)!*+&U-VJNSFGL8AkAJ-7uajUMcQ??*VK5&kpaa89??*x@vieUqIt0)=FB zs*i;n%kuhM3u%(b9bhXjj>q7C2iz*- z)%3c#`9o;=o(epKbCQO*b`Bui3jPi8UD5uYys$!f&nnW?92b=pBj$v=lDcJ+_g-WX zks^A$)N6l-=7LLkQm(AOzT_nf2LLlMjg^H%&mN%4F>nu9W|~Oe^wa72MU5{h8Sb8} z(&0CoHvthi;U5OS2V5YL^8iH=lN*(KXMWsmZrip;r)TxH`6B$o7~G;@ z*@LA-$x=~q_6jMB6Yu?Kx%=!zFi_Tix0mkvkb8f16PDV><%|HWRyg^D!(8BYE~`XO zM(y|V+-J08T3H37)8otcNAFH*L{{_ue&ZWM4`tb57qv@D?=W5eunr6E?t1loshB4T z7D#PU63|`G%nXaG?1Mk0>>9D?e)xWCdkps``0!yvR8UeZm3-$gkz@(ycnIJ1@9sQV$~*a# zDV59|Yq{U3AC)Up;F)s1G0?QEWWOw+7DS*O4%Ip?Hei(CLb-7Zg5_xl2hY`?BstHg zQ}PLVehEx27hmuA{qMZelyBNlMqK!qqnLk83620|nL_?HG!aDPQP{f>yj zYL?5hmon-~v|C2d z)Mno`i>E4+7H}%V&2h58>=jKiIX8QMIou8Q{J{?V*KY8_AM_x2g)*dkEeYmr+H73_6R6L%KtzimHm3l(DTKYP%->^*{2y~ZhKWv9$}UG{Ay z&br)tXSo;4Zi}R0oJXA^>-Gw*iHqMqdrSKIe8Hzx{?jIn1Z7X-47|?&|HXgaUQPZx zc>Y!Y`(>V*|Nj+9qoFY!zeAa4&rtH{r@h_pcQ*FGSn>3k5oK9-%}OoM{II*UVcJD; zBU%j`=Qdklju{ckwCSjC|q>UJu1=4Q>s(R-Ft=IO_-QWrN57dhj%a z8vnOWA5Ih24a941Hbv=bb0uV_(MD6Q14>z_;+E3VWTn<)nsvQn-AEzP=sB?0`f z@^ka%MnQ#J;3>Mop|&I*%GbJ?ySvRAE)^oTOn{mI*V*=bf-ZlRLqK24czyTc!^$Rc zx+n=`2X%CMe)0P3u;~!QxvBH3SAMkJ9zqvU6;qvJ0_4z~FDX&niZ0Ys!(Zx{{_Bvntj=5O7 zlDD#N)+yog$2Wg(Pg*dL^RmTtr7};A56jv%>fnE5G;!BF7|qyU@$w8$t6$a$jIORM zs7_+}T;b)gd84q}jp}kMdvScJoRpiW!;Ll)NM!Bb`jUh(TW2(SGlDy4XzHzZpB578 z+g|Z?r8FTQWr1#T1?QG}iFdIxj9hPP{a9zwkzB_v;qiZ`Qe?4Ul;ODg(g!}Ty{Pa# z`9gwnIf(D8t6ASR2<-Znwr!1u*;t$dw|sTv>mI2qfK-cC!8AQ$R{*LPt_q*ViS}QK z&IQt+Md%XBDoSUa@=yaz)-DiLuKhHZR`Ic1Te}0dw!YT(j^=6G!m4oH%C#sLRp+8z zQKH(<;;MgDM>X@^t@LmnZ@FA~k*I-nzb1A_@}8#gvbY#nwq4^q_Yr>zL}vbcqOUb| zprM7J2O-j-!849oB^nk9_reym%eNMWm2-z(-!9PXF=B89#%gi6RoIh4!sYqt&u6br zly6FNyDl03u-|`>pWgp1+>M5EXZSyy#|e$_p}Bu3*){Gf6sJ|(N3SnW{%3T0c5!lc zdGbFOC-09h|NG~Yv%g)AjxK)ck~>;-udC){$8K03`NmfG{qD;bkM3YQ!zf#?_MyV7 zS1iPbEXB^vdoD!w8jI={lIix^@X^<>>R-Ayt*3&&f?r$mck=B9J@j}qPQMQ4uCuP@ zz36|+q$=(z>#NGI| zdC!@?WPF~X`aW8axnwM3CWxsj_zhIa5yf1%K z;y86wdVZ4z`e~trWttDTH#3BuzB$vv?``)pMiVUNIOo7ahBCae_v#$*zmai2(bLNR zvqkunVIbG>|AYO8|Nrh+|Bo;8v>XQ74nLJ!a-HXxZRJ0zw~A5Q8Of`;oBcaDf7Cn! zWS!m|$4S8F{aXC5UZ?5Ep?EcvSc`w!%Powmo(j#wbXVau-X?AYDbp#x>!@3ntZKE^ z#9}gGtGe}}!Z?)9p+UJ;VnhFu&<)j^J;3$+Mj=z zUv?}1H}OlKY7bb){|AG5{O|o2FAl!)|1a^h2zAZd0j*BL`t!d93)lW=rx`8!m}AFX zxWaDgVRN<5Ze8OtgbF*WSGtAC!5&V-x+|~4Vp>4n+^BfJM{zbslZ_P@f4^wn|J{B5 z{44+e5>E$fSFG>fg16ttX50|qOC3T$XkV)lD!PYi0j)~teZTwiMXybk*87X=a@vRi zQ79+wgKwLaGpm|41!6NSMm6hOMP<_AIivx#AZsHT)WKKkThUvEX2BoZdt62sG4WZp zlwGS)*v8n{-Y(2yMLfqge+=zMsNayO`v{xzPS{CZ#f?MRa+qqXcW)Q_hpdv7)BZv0 z-{JpfCr8KcPJ$$QY96zi|37+)fD1ZFEWuqZhqrq@1_e{rBwK%pQD3=v-7 zm}W)bN2CH`;}j4J=S1L8C@%GQhXMgs*@pwEzeC~YZav2h+If0PO?7|JC1S_!>A2hg?~5|gG9P#K~^1FDCw+_tftpp2dN;U^p? zWxGZjwG9~xuh7h6mDGd@7;2Oyop|Y<5HpC9J}) z5=k~tF@rx;-u=F{QTe?MTpMsyL|>EAqRb4T7Kn-JSY*(MAj+90y6UEG%=7*N-+gyM zvhThd!dqhUejh90X}RdD7>_rfWT`pe5WE->`P!kr z36JB(Xe(M4b4*w$6$C1sj28D*?jz``{pW z_Ha}x*p&XGV;A-t9gQ-NV=#F})&PXD&gC_hLb20P!eOkld5ujrud$n7Vcf*V_`r$nD6zO&J+QhcogtqN-5zXomCeCE8VEB##B6pBC_0o$U~ zM8wo+N%Xabo>gpWzHQZcqcei(UB$@;HYG8x7*}Ao<#>|= zcch{%7gOm8v8i75tYUL!GH01*uqxX+f-^NL9MK<&qtlu2$nx?fwy4e`VNe5VI&U=k;*4$Kef9N ze^hAmStHe9ksZTrk$x&vCR#d$2@0ovhbD>U$z)6Jt5HZ(L(dGxMjnrpKe_NHi zXEll9#I~r;}7!Ax;yU%DJk6&Dw+2ZObv~ao99x zvx7~?9ByLsRI|8pE6DJhqpqxYT>w8{E^ZoK#wBfxGxD2}ifXPCUqPq-K}|!1siLItDNpC`P+1$S;rzsxPu8i$-HU3>R@1-v~SfE532xvHZNY`NiVm} zW14OXwXg}p)%&(DLse!XegZ$%i6f+@eXx$0DD z8*&076+*(L&G=yOd1r=|@jS+@*qAZ}bsTK=AB#*oHuaz&;}&d884yL}kdih}f=zoM z4?Azps;LCKhU&>^(-jb8f82^q$57qE`1uoK(;TWMHXTFt1hlEd8?5TK+L9)gr#7{$ zs{lWn`?W@{9N!BY$8`Nv*x0B@tvf@y1ogcm&*GBia82_#f|y+4BJCng%fzYCy-~c? zRzj76%rycgD6`<)gk{{OF_(<^gQZbnz`uthKmb2droAXgI;AWze_2+wp_<{THe)Dj z|6|~rvrR-prQfzzVw=n#qi|mK({U{r`@THlU*YAUlH@+@6o39c24vLb61A~wY#;0X z;7=&YV!ZPJoBVGcfNs+@^Bg8iKj)b3)U7RtS|4qd&^vXDgREE>7gV0IRaSpJ-qt3q zm9rd>YxGqHC5d#Tf9&76vOy_hbfE|zS8*B#&M7Kh0uc`60=E*ReKig|@5pHX$pXjA z9YFB6qjzt$!A5xla5a9!7`?UOxm>H|yft0}nbycga6Pv+AIIFUGrv4`;QXmId@oVb z=~3gjCH#%%3a^~wird5o2h8tV&JXP^GAi{^deCa?;l7?Xe|kZ1L7AbRGssG>ru~Q< z&jAidThG?3)U1NeI27neG=Xt>P;LWCv8P>!>dM!4$Dc;>?lNkLZvvw9w>5@@Lrg=* z?Zl`E2`|!S>J=U>QfAg^eKa zObR}gu3F>df0PEC^1?Gr@^?(c95XwO0kv6QsmiX|uxRZ7m36O){HCUIo<&IDu};)8 zv*|mKvPT*-Y_X)T=Omm<`jJ^mneM4=T9O!V3qo@SSS?k}0E)w~ z+&40uM%JfDGY&b;H%g0J>i}@i+YP|vQE3~dHJ|nMf6d*%I$xFJ*1h5tQ|=ne!_hCV zbT+j%#%d;*S>n8+IY+>|RqT#g+Ih<;ReKIvP!c&GHaW~m6yX#sJjohWMnsYd%%)hm zN-1_dCd%YH4ggG!S;R2p*^Eg+aHf}$UaJbg1W)DeY?IWC2fC$ zSo(k;R%q!rBzEb{Pw}-4ljJW5@^yS4GE?D=wiPx?@QkoPBsLDS)zBc`1vQSK ze>T;X)sV~D<<7a|S$6ROL75o}vN)fqaYq7(?6h{WsCxQ&RsEb~m}Qq+_CkU974NH@ z&vNZC-%Q1Rgu@sy>>C7(U1~$GV1G$-e}ZQu-QMve>D2=6&>qSqtaNXI=SjK9aZ6n6 z2K(?Q`Om?QVjoGa+$=c-l`)K_HGSixe^6?9DzTjAg~vEuLYb|yG@AvWw?@T>)aHWa z!63vgX2=q5Q$A z_BQ>kH~g*VbmzC;-CfV~ewAFdN`fM#u3%_7C1H^y&&j^`cS*(~Pr0GHnx7fNW1-x> zH9k9S16NVB9%>z~WQ>M{o=WA5bli|4p|2#H-T$MiGPatex18sJ_5|03Y$qbZvluN) v7DscD<;pii?s3WkV4BBvM-9GS)%^N=eZD?V`TYL?00960j4tXP0GDc zVQyr3R8em|NM&qo0PMYed)u~>IJ$r9Q_RxY6T55b#c`5WyE(hA?Y6#696z?({`NLq z7a}1E#}vU5pdFpW_aog8aX;C8@J52KqGZ`gTJb!mu}EMr00x7Z!C)rFK4HDXDT;Y_ zj%LBXJiycM_xmsQ_vOF+e!uwdV81{3m%)C2|HbpY{`2S0{-rBgAkAMdW83GeW~5-0XEw6s133 zbo<@GUdP7~4t*SY1hZksg%Hi~5Ij1Y(Xay$d- z*3*A?063aRWL(hi+!WT0X?oCo-+kZlG4o;)arx?PghOC7i9Ngv$iG3MhkdxlbN2=X z2?oY#jJt5cfiR$Bjzfs?7{@X8fm1*X5cr5AU_4Gdp2Qd!j&E=bjD#K*kQjI<1doOs zkx-N);e_qN6tO90yATk@*)A~58KBSyMq`eB`McYhQZXuK049V_labwVJtjRKW89k| z#&Mi}lB={sJkd=9!5%xrL>oQEk$25h=^mL))L*WA?e6XM-|s!!??&OIbB*V>H1_3e zDcG*)o*bu+D@Q@j{R|P=RUFHrc!o$YH2udh`)>=04(N&hR!?MB9{Vxz{@ce)fSaM1 zldwCE(+ar{9raFOrDjvM-7s*5N_^^F^nQ2H@yP@;J_I&Jd(U4CzaEV6 zzSqYizmL8ieDi#7fA867Z-4K_*ZAwb7vH?xdo~z-?e$-N^UVO`7yZ%Rv(Y!t`{VJz zANBjs&|YVPLmVTH{UJDe{k?(P-*fl&FZ(Zs&-aJ>{ciu8Z=OH@`sLn>|J(Viuk3b@ zTK|&qvxgD@o7ex#!HfQWas5AkKG>}P$9T5jTQd0;g_BNaN*Pzne?%rD6i&K6zUdIg z2^G>94$&wO3vY}9h9z(CiImd-w!lxY5Tf`L3+538_&wosKru~1ANZ6oAvKK2B#EW4 zxhqRb2yjDUo}fSqTg1acI`avWjlpORJ|3ea;If?(4gdif;eZX{!=3zT%d_U)1aW+e z<_cASh{k*fgXjDE&ouIvhi3x45PPyB_%wXVVTx`rh(UoVMm~;(WJlpEfnSXONJxx* zSzi><_&%T`6u^;`S%A#Y1Ve;kG{YRnOq4haFk*NY zLdr4lDdK7zZ%GgUy}@xzd@P5tSa}yn=mm*S!U@>?eK(y0CGjRq)t@L-l=Qc?1&2u- zw#E9PXoj;<4<=12TZ71ToykWpHhAnV}?Wiw9wOG zuXmk{a2#TerAY5nkM$CUV|S7eANOPfthW`#*o~4PAmPMS?@U*s6xAUp%v2k1r4osP zU=GZ5E(8?EXbyB-BFC;C2lWeP3F9!rFhgM?VR$hXQVNhzt}ww?S%f^?t(d!tE^)-J zSub6!ZbW@I)w+7352{;kaXIu%KeuF0t;Mrdy?g|@Ur0SxjD93kFxi2W!6@}Y5)a+bxEZN%~u_U(SpKmp&VWBYrb8$loj(MGjbr>WBjT~1sbMH9Vfak9k&bL7zq*hWxo9iLV9QN5 zvsl+)pn0vvBjvX?$JI~>)$cQ2TMbeP0E@Wo%KSEMXL-h}ducP@J=e!0fSGIygGM&c>bLByTqdnm(HZ2AMsp$*J6?4Iv1D=F-QFn zOCcnJZ68jtcYR4_m?nG(&pQBrBs5NDg4+T3^fo*ga~!`RK|mPxXy~&c>r`0h)sb3b#`nf)`*E3RWLdA2T>P z(>v`i;-gTy1j`1(6>F8HGY%EV8nAtSd~tj!gz6nJSttn9gb9cWnq{WqDk&wS;C>pA&$CA?njnln{3GK$q+BrF5vT=;OsbF{k@sMu!WSl8d@^e~A4!N5WKAi#a0dX}qNtD9SyUlLC2?ayyNJyY9wki%MM`EK7JRSx#jOE-IOnsU=-T-8i(%c?Bj z?3gZ^I%nebFt4%doibglMM{&55XXf2g_m3{$iiEecphf#avEbcrGc*&rdq~HjIH<2 zrP87M@SvCtR=~_l7^kz>xq(x9yZUmT$6S4q;!cS;Vyun}q;`&(K7$F!jPN3DEZn#} zI*Ss?xAhT(6g$!;Qi<9$Wqt$9@Jz}Zd(U6IA?aH$N`^4#_h+@(UufwtifM#nPBN86 z%Z)>`IW^Vh^9bjJhk1mDMovCCQxl{sompI5NlQLq>ZRfAiU+;tI2OE*$7nnz9z=4l zhHc5_nbopj#IGsxzeRzNTjQPO_ERJY$3>CkFoF@dTAJ^v9oxkk6*r*BcSpJzDPKrD z!imeL*!2Q}L++}%a!F*5hyih_I%DJxJw%G`=%qCx4~61w!lW_D0F{Dcad2`p!YK%?KvEP9gZY}r$H2~$ zh&@nMCc=UhF|e>dIUAP604+>NnL18Fp;rs4pqXHkEmARAO6e=AQc;YL-(&A^Cb*~L zm}ZP@%c+aae5ehA`Ery`aeP%S{as9F!}JxvnBc%a$7B1QetU-abeR2V1|x?Z{Q6tRmJr^c zNDX0bFmx{pl@H%o)s^(zx~?j&>Ze?QU?pGvn9`(S7f%@+(HSBk2>HBg*&o#FA?Tmo zfO;tCbTq|ku45b1L?gFTEQS{loZ97pO=%MNVzp__B}KhpTGk>l23>JReH=(SilSiN z)v~wJ?PQf*xdb7iLTVRdq$K4y#vWJD6fac^#FF`RM?mpxLzRLj**Y|nE)iI$0SX!o zH4;MT*tLpE$O2fzbEf!lOlOiqDQ2#qY!^`lA2UuuC5j6qcDk7%3Dqr&y&Whda}956|AQl^)n}lUus2IXw+h43!v0-K{r(jLaGKtbY5G!gcc@e z6)8Z3r7DIG2{U?F*}|uhk_;y0w7GpqFjl>XAcc^c*}U_TU^4{Gx|3@xHjRlFxw@9C zYYo9+=)a?w{sViwE6eHXGpEyuN64!k=JRh44l_xx?H~&&oCcW`cb*6xms4F# z`X!C2AV|e*L}6|2(87?}%|*r3THpeT$oDZ#BFlmRt`u`ZrgsDVHYdFr$rM~kuGmXr z!sk-7BiO2RgX2-LLZZ*!a!>^aEEb%2xSNDgOm0YkC;Gfhb-=LLj0Hs07wlT%A=p00 z@42#ks(1QTm1TF#vRt?KN z6q$4Pj=equP*gKo^}HTGu#zHB+p&%dd;J)(SCnyj5p!Iqht zEe3tpo1z$bvV0ItQJBndOg!zO2PDt0EIbU;Dh+7s12sh?QteRQg0AU@OG9@|V#eJ# zk^PU-&O7E$#|#^OPne`OrUaI4G6`vnnUE202u)ZzJUgAOw6qpiHk`&~TQd-VS_lnG}J3}FwVBdfj zz7F@o*$jkTQeacs~flw6E>Urh)kSzO)-oS*;qECyIbf=b6 zwqB*dF{E5<_u}=TDwU0l1b3Q~79`b5F9pp-)Hdefn5!L3ZYuUqL%aswVfIZ@nN~7H zmGAV=>cT(bd9lKecwSNGps9_+gK`b=#`H%l&Z8fc+XI7b5(15VHJbWxM|>V3p$~f` zn&Ma)2Em`6$vPQ$J+nmu&-;IL6ayRudb`SQ zoKq1`DaY_TeviH11#66AzX(*YgTK*h@(~Fa^%cjnKwB$OKcv<_q-Zj=^eLuoc zKBQS^c_(@rxZujKPVXMYEXZ0+kZiKvhDs=R{x^SA2cp) z%WJ6+g@6KSxZoI=H^qJu;CL5schUuiaT;GcOSu#we?~$f@Wh#EJ=G9qNx(@IU^i`v zS^h-n%Tu+7S<(laq8R%S#Z(%DGSdhNg=j~8iKCFFY}*rTYuC;leYBXWA8LV#9fO2m z7JUYGSNq3g)~K_SqgR7sBgz;dHice<5{5IVh{?0A6k$Ot>LW&xv^M>d&PGJSWxEor z#RzvTv&Lu+NS{=J*frHrq-aFS3jqx$LPVG%IS}$&{?x2%kE8VOlmbUS zuG8Kk3FvjBhEQ>EgD}UO`0pF@V0B->HtQweU zql&V&Kys}VX(Q8jQahrPt`;e<&Lc`f?pWVPNK5|ux9i!z)Vz2BQ5JHu$`mJj=lt#? zj(>mWz(<(GID)r7I;;5v)QAPA)W^VZfIUuQ#YZ>|us$a8w7qXZVuG|Q%4!I-DkvqnSC$UAgqRNFvV+bD{QL3A79L3($8G?gm z{)>G_`dHW_Ri$khot64Mc?OBbV?mbl9tt^e%`bz6`Q0>IE4e@v>b7x!h&DbBU#yQq zxN&1x-HkyFq5bwklFvB`C(@+g4EkO9zuwo5IYHO5sbwkEhk0cyt2Avct#4(fUsu^r zErl>|?X41H^wDL6^oel61UsWiCtK%xIkEK@&a@eqB zq&z94l}wMhP>ZBdy*xSkQWTh5Q6&SneTz!!c<`V0tG`=yw1(xlPE|F>+0{!%kdZu$vS~nC!6ZMaShTUpfr0Ok=WYye~Nr*&EP_Vp3HX*2i6mPPUSTL zU5ds)!y_DEj;*_(-G$ayo^Toy6v&tuT&z2L%k7O2Bc7XnVwm@~649dAUCnETGuyiL zZdk=>tC+C_h%a+*HWA4pv&_lQgo z*JndRvln%ZEQ~;Cj7V;N>G@ShZ;dflW_sxxmL6_NvlJ#$$u~|?K;vDZsHZ!@uG+#$ zIK?p$!WdVWVzr)Qye0(Nf*8 zyi~M{R?M^WA={?*g`CfB&g9iZuIETTYfJ5LxwGx6ljGORoD|>h81=&V6s~9xv;501 zq8KAz2n0eNBq3jeu`-hqBdY%6avITqPUbF??YUmoo^|r)!VJB?xW>22xGy9eQ}IVU zAEvh`0i2~ zhjxShXM3JlgPMN5IZ@o4D1L?~ib{w%$LT$!NA(D*#%9@*&2^mwelZS8RqBKfnNOJ< zH)Z(jtnP!BL9Q}zHQBZ{XDgetmCf18=4@qiI`Y>#9od{|JkI_7vzX2>pW=kU@p~D6 zEruSv!8|6Ox?`jMtP0aw6Jf3@rssmFo+w1YoD)w+=6A71MQK53GK4|*MOSG#mGLQ+ z_VHJXf>w@IDY4SC2WAu>A?}ZoFEfGP65u3Brsi8IS`-niy+v~nXP0Qen_}U=ZU z8z{vrFEW=bP-F~qnmmn-Y+G@~)}t||te3Up(nx3=ax2vm+8Y&Axge`%fuM7t5G|YG z7($GFefK=f%t%>~W=(Tr6a*vWU8lh;GUj1~oFoh|W9C}EhPkCqW^Pa*l(lrd+E=@B**l31| zWY*ba#XEP9;qYTJ!tf}Fn1#Y}qNb7C(g@*c%^?VW;bt#7nKmQ$dbPc=G{%ZNNs%j^ zr9lYAg0f`tx_jpJi=a0O=*V>MhP#}^Rvv6N!p&Sq~LUQQ!mitU5cfCQ^7+4Zxbxv!JyHs!&6Z}P9k=Nn&b5WwZ zMiI$HdjS_vfW`JJyKzKsLyJW5`zY3#ldh8JgNF3V`S2kN+wJ7TY&+0}yE|8l!Ok7L zdIfz82Kge&SVfF_ync9u2vHp7w4?XnCl6xgK`>WBMW478% zdsmG!o_OFE2 zaK$M{!Ag_=>+{)fJMecX&-s9Tc5^;OVjGkFmKpgTcCPK#s-{~d1=JdJfEb78Fe72Y zjX~K8c2%#jwLdl}xGffa5zXH7m-H|EiKW*3*Evr#6YvHz4k(SOW+G{yob4J2(l~ZY z7={3&8w{fWh1Z&hs+`*v_{3?i+LMrQD`%peI7fU|=EO4`&xo-GA5Kv?QDMgDZHVL4 zg;s}6(kCGD_(L9_O4D!}kV{8H6U~=_SA_>!F_nS|h{dKj2r^@qGw3@TTUOhM{&}ks zEEi;Yu=jOkkZHwh@`P6oBA0p>4wW1_rMICWHF?lArh$)RB_M@Hj;)Lk*GzIZH^RBw8#vY#lxcGpzg zE9#5oIFpBD3B&QTTZm3l8CT;)9#~K9v7{4R;7iqTi&IjRB~YOhiF=-LL!gSX$+R<{nsw@@S$UYCZ!+?8zus8`aRZmt~0;K+m# zI{MZ=PT!Ty*oXQkh%xf#hVzQ~V`77GRG`NT6{}LL*EHs%cyD}$BOH%uJToyZl?E-Q zNuGiGf_?rd7@8ICa$6Zafe9U#%#^l?ZYc5L7R8|`Bjf2QkSAsXC~Xa?N3pb#RPPRL z_6B=r_>1S@YRK*)HuN7T;}>&g=UIG+9b#(>&a$Pg<3$(a47PVJRsyDUDo#U->UT11 zW3j1*AjW01+J@LwR(I)84?baWA_)pci9f-uVy4#lN@u{B>CRF5>RSoEa`ntecwqEE z<2*e>?|%xB{q|Gl|IFooW!@CeQ1>5qo~cBj5%p>->oRPpyJT1@e*0-wIKtP7&jeS;BajZKN~#ax(Y$0gdmkY#9W?FH)nD&&1ECf1s&TMpE)u(To8^eC!=8j3PjKv1V|k(7gjJHP zc3rHP{U!>?QGv0xm?5`H-F1q8<>^C>%u?i$MqAW5z}UUW#FCKf2D^Ys9-A{u!nVS@ z$4d=<4RTOV$FPW&o7#ganzjd`RJfX~+q(=qIe>QsI%4FX#leRLj@d8?nKP^axzu>X zIP@hYIxHZ5VQnci<@+~848fr8D|+up>9*$kPazSD+WDT8;nyrdSg;JiUW)q6+M1cF zRSCJ32^CXfd5kvAOvTcGx|xv~MYJbS>Rr)H7)2k|^`c?{uES>uPNp`4Wf+-a(@XNP zRd(qb{(Sf7%#r1Kyy1---e`Y+Xx=EPZ^Ihfpt4@pSTY5-VUwRiu9t@usr8dJiuU^E zS;6EllSJ_};D#~rM_J!Z5_EY2pbycs=bALV>4e1EU^pfr3hc~c&LV+YAE>t&;i~N= zBZKsx^Y@`bp(v~*!57HpBw>$RY9*Mm}(6z=MKEg z-uO`4S;P3f)y{4vnvlVI(N2~QWxk$@Lx8;NbYk@WR&H^*U1lxvuR^IMXK%y9I^zF# zpVU73XMdFa*LVuC-s#)RJ&lg!QEV-ILG$Lap3OG z)D9_6E82P4WC>9Kg+6TCrE)1$%^~v+Y*&BJCI8$JU_0)5pAP(TaDIAn`n_^Q`Zhhh z6a(f|492VcScneV#$0t??#N3bQ*@&?!5L*-#;pkEdLQ-W{Mb3&lv9^+mI~(b5T7Po zg(}Nu~v#!GYyNb*=yKpNnUD9w8%z-7731&LYm%xwR60TC*IH?nw1KJDF zF~QrME*!8lP5`;VyRxz;g9k8bL$SvpcmL>y_+mT}+@OH?+35fcEsKBVTGd_uGz)^o zp>Jrn{HGylF`q!!E~$P~XghVMPjp&MbrPA{O;RTkNerMuok<}u zKd$Qg!_K;y->*|cMZWde( z>JW#DuCvrbNp&7v3jbg<6l&iq=R?;=9H~K1GvD4h@KI*Me6bI%>tm1lcqiBAOKQ@t zr?;o_qKuq~K^M-G5KtjWbSi!bau6Gbyv(LN$cH61%>!ohUjQ(J6DQ%yqf#IUoh9FO zV=UunzIu9!Z*cq+To;EorTNMK23L8KRkb5On1MHG|G;&D1sF#_LLF67^y`pDb2XMS zXRMWKHOtTME5b2D;6?35peJU#$7xS>v@3wO9+qK`&mz0#Ixx7#^VJZzmiOsbZ~yRM zmEP-Ga`1oBvQEa8%)D|6h;yAavU0*?R7lt5d=4&YPnhon3`;(((Uvl8s$SzNX;iMO z?mV=)bEMGG(%d_XBLK9U2GqIa6Pj1EW8~Hc=zFhH58xyOts`! z)?8`Ezt@FB&G<7REMxD7uTRPxyh6~<#;8fwHg_atxIlNhc+$a*T1(%}bB>@e!|D9y z>*aSRL1+OJj9zeR!=Y^B0-evW~It{iLHVk6n<^!*FVsmDisX$X&&HA}SMS z^QpQa*+R*(cc6}mIjO=5<+KM?Ih$IyM!^t@icm_F>PHjKh_9{O+UzBStAy7GXKYwD zd1ofhM(g+8T~1p&eS36#b#hiv(`0=7mO@Zo10x*I*suNHx{M>9urBibSm?*{o&Is> z?37SAdwYIaKw_2VS%kf=fGXQF88hyjG_+>xm8DS3Ey^c)u*B~3B*nV8`G3BPFeA$x z-QOGprUR*i$!CMW!?0o^%v=DA}wH&Xynoy z!qc4L;Kpl75Vwn`_-SqlTpXYOd~#T^3R<_>LSAvR0v|pIkvEpts<%n#jC{BW;rU(n;4k=xM|A%;bvhyJH&PqS$XY z!|cZEwdEXj2EbvRVeoI|nH=oBl-Xzog?Y@?`@&|gS`rAoAo0@ym5~Q^_|;1^VQOIY zW|uE258n{Ssu#N8r#`~oJok8t{vTIU97H%~T^A*qY()FCg+WDQ0!3HcbDe`D^y3Fc>aLjC3}3cW zyXCWS^D&)rQ>L~+E1ED0p!o4bB0qf9p6o0<({WHxaw1BGYwqpR2o?z{2TirR%tEO9 zTT$OR=1HuMLs1mPG>VC&u80__6-tEG_|?_@ikU4~1k%d6Ic9ivgX2Rwiv%q?e}6UT z?z{b6_|HN2rP~)P2SsQ^0>TMqT|vegO80xhi)%;@5;*uh$D#D%?%fPVn4>|{pr(kD zaMHd0THf%#88i>sqG6IjmE<6mA{0~%R4L*?*ML|wRD=Ch$4Jdu^SET=c)!uGiDu>T zXh}Tx9g%hv(@0@$Mo9UW7xSE`(EK$lQXiM39LvNIIn|uYa4A`?Yrfj$P3V=n8s>Xe zhoeckpm_NaIK5Dp)Lpab|A2!T>~#kN;|!*Jbh5lcLJUAU7L&XOe}iI~`Ok!*RayJe zY%st)8sXi}DB+-iep+H-Xi;AH7 zs0P!7cQHjx@r>Q~{*4VK$8V}#oLo6^uGM@>#LbQ5iE1%ao7C+V?gf4IMU)=TG_9ue zG^*`_%2!xwWtFNfTw;Y9o3*xCYoF6v%N7=F8$+_WUnIZPDoDCi>s6O4zto~D)?B#e z@)b5qZnNY*_a#@j&Z_RGy7u+e=EYc!`q*|^*3?{Tf!4!VxK!(^ZWirk(S9C_RwlsI z*&1-H?4-43FCMT%Y}*af8|ltr=94R7DC-)_O33)!m#;4bftq`?xkDq-{CB42$F%P~ z8u2vojk4*Bl43;a45m%}yT!Ai5Oz}BCt0x7;lduAintsvDeOKn6iow2k6AE?5obvEjJv95|XYVn@bu)JM3C$-L~cj}-??5lZN3fIwpIIV!xj@kE^YkJT} z)#^@1EfLsPJ}QOa%pre{;T7(B7W!KK+5)u1z*W_%9K-xQoF(j+)(sn7xo$wp!1XomZ9I$kyeL29 zEA7~#N@K}#0D zpOl#G8}|32W(nwl=(&NGt$`FJi|>XV&0#0FO?5*?PrMlWm-9%nGd_>-+c9))(TI!z z|6vt#W+?hqMdJHS=3yO6r$U*XN!Br$uRnZ{4yIjjlt7Vzv@QhLrMq^K>c9_rYoc-C zG|h_pUt^H0Dq(Zos_%7nl4$vvsH|A-eWAa381)@m9#&n~mxt7HkQPEMF}uw?|M}F{Ke4OkrKF$2{VNAtV7^qj%A{|ZOi$&WW>$;RA&g> z-R-2oTtX@}bi`#eMV18+im^v$GaUMAk5l<*)IHGR&?2$l`zrl4;P8gTRBpuG&cBmz zOw%kLKJ{2vkDSgpYhpN9(C$F4yu~0^##k14N{-msK(g+FKHNL z4BPk*>6_S4Z6{Z+s6W^xRocsU&O65`wPg!!?ch|XRgJwdB-E%>StFz=#0qj;55IBD z762-b-)f`SJeJFj=xV*U$GCRfo7Bz~$A4WT|M--vUjFEpx zL&jr7Le6qWZ8^{;PH6VhDWfL}{)3VboOhvP6?Lr$nrT^68PX|z7yf+k`lsUy`1#=V z$}F>ohoa+7|NeYvu#5|2qDELt>tw zz=U+U*EX<#|L^r*?iKj|%a{F4{^v(|9)bVMtF)T^|E$PL^S8QPV8i`CHTQ4ky${Ox z*UI)aW7ZtKC}N~+x8mU3YEu@=97H~R0O-O;_#>elSM;2Fk!nun2{c???k4T_57Sgk z6OK)ND-Yc;)d1`*s%D$2jzX5!5q+y9`N}X`_9@$^=3JX+9Zzxp_h>jKlNpL!m5+|C zK?7{w|M#E2Eam@tvDyD0>9M!(8?#FvN+NiJqKXZ=MR;IEIBhoZ91|^U=52QF_B-|z z$AqH^Zro{gAf)O&Tn$5oyi^QNUh=WXMI@KedCg) zGt_MzveVI@$QXY872JP<^JII1Wjb4=_D$!>561^bua7S-u5_qO2R_0i#t}IG`{aXw zdFQ~61Hb+DAHb(LwDz-G6o(Z6vI9MB^^>QECuiz15MeTH0vOm9yjUG;4)m)rG1!M= zTGh@JF__Ka-+lbG%|P2%%v<*Lei36Wjvl=sT_k<1Xq#S=KT2V^~s?;4Y+#q_UQPPPWj$h zne^NnL47$=2B%Df3$Rd9kwRlkI=00(p9M|@J~~uZ*>0SK2ka+?V|l8!y||c=boq{o zN-G;l7>>n&X9|EfrMDrt=Q_cf?dw%K2b1>#%cfy_G{a&b)2r`JULO~S$6T?wLdpAA zzk7(olMfZu?tZTt&MX&(4JJ31MP%L_TwETXuZmMu?P}BtB^P4oJgKG-2VT80IUvil zUB??i53aZ*|vIgF40T6y0Ez$5b90 zVE+qXC>CXHn95^};yM{iVM}e`CS^5g%TTacwaDX%OaLvH@2*yfVmd;jU=A~kLZ%mx z5bDK}lF3;F(aS}zNFI<}9W=x+$J}a7tSNaJM)D4m!;1#KEXz0vf-bxbJ**m@N{=LF zxQJe)a<$2X4?OX%CCm`t;20RjW@VOo*o9w212h78BS$D5K|pT{pgEPQp%B^RmjYuE zO-cSBxdQgHoEZ2$;YHmrFXuH2JJRk@7IoSPI%(B~z&jRl9~Nc0goE?%FJ5gst~`Ep z!0GE07UKQC%MUzY=A*ru#ddR7Sy(K5cT5B$cdB_uWwmQOud0%t)FKsu3hB6o@^W_cDBw-7{7fl{GX)zB&^QB2hhD|beHF>N8e$I#X&fmw6fN6o1W zpHtAuOfsizgIofRtuhrRWhp3zBULXCWp%*sd5pdb&?M(mQn(XZQ&J-%?`>v=;`;Sr zO-Qx3bBvGQWAAY0TgWt&`3RvoUtFdclgm}tkqKK%?PP@nfr_5~`rp54fuKl{5`vO* zlz&Q1l@u{$V$KpYK9rfcU_ov!ETc}Dc2n6#(9ada+%hr)1k^(TxG`Mg`77tihr#f_ zz6_sPFCns*M2kzpBk6%&DcKQ|H5LiOb7yYQ*= z92M z96LMf!rRbsyHhzOY&`f8;kpj~)^qN+1&0AfVY;ParXmeW<3tjxTdHQ>WU^OPoyPJP zkPx11!@c?eAHhqwU@`-6eRv8_;Ugp=`2%+T1ALm>NhGo|50u7925rb8ID{wSA7`QQ zGqpoESV7lksFS0$iiI_uK@VGg6T<+izsw|~h zt}~d?kZ>BeP_R>uVo{k>d}(b5P9+KbkyX}t=1^`SX~UC2UGDb6rdwmfuT#Ib1l7_T3=A{;;Rz%T;o6{#x&R%7TyU}+AxNfD^D{aDHjKTxBd%EKkNKV>36xF3B5cu2Q zzzxB9a&op3;iW$pQ{Ks0BiptuG}=0o;$bZ%g=(HwQ)Me(u0ju5a748(7lGUcTye^~ z*kzzbAZY75P%SAe<3vy?LoDSG(8}i^*G!f3!TQ|_a!t1PFUbF_;)x4RP^*erhp07; zm5(=-+digvnKUYrP0Ol;U5Grv_7lNY~LS-ql5S(lwR6{$^#Zn>} zBN9-tTg>MAZn|bsE85xDJwgi+&Gfvy!;kXbG1vAhHzN2PubEW@rmeYW2A|RCJlylX z)q~u&YK_;%=lF~DIsS6Ji7T*wc<$nZh0G5+1jG3`O4NK)2!)L z6l!#qt#4<6vuvr%MLDC%I+xh~i4c?V!)(W=}0DYrWW0+sY@t*ONcmDMayJ{i%)rwwB1> z>RAx~_1TLT#rUt!_Xc~L_-~K#tUvzSpEK^8wk1loIE0UGF&j|2ZZdxXA;7yViK2jD zA5?)P))73@aQ~(H-Qt;9jtN-Wq(nnB<&(IjA+AmdTY$TE^I6b^611kCRAb^3CZxhc z#YGuZ=Oe8xtL9SBifb6L&iVKjH0GEUJ7~6t1tTqs zEgI+|tR==-Rc$rQwMADM<+>B)yqayF>*i*{>G4^lw!{$$edu@P|Ktm)zcpCm)eIGU zrWSj1wDf4{cOT&bU7bf$vzJ!B<37C&T{Px6c4s6A2-EKTZ3d!LKma=su-@39icOl6 z57+qHuGE%+a;bq7TM-&d5a7UN^UzzdKL*By1kpgRix;p#Ytb4mLtM0sA0+N_QT{Wu z>I#xvlL)vd|I4%I#r!YNU+it-|31o7DgV`n=WoyKJ})t_QNn8_Cz^=zd>-K;94Zcd za@GOx%-=&eRepM{cDpDU1%ypcDL==^pC9;sj2Xjh2s}=3F{r#ul4)YWtGVD_r-J_n zeCn>%4A9K~2YdZz{bKz0{r!#p|0vG`#D7;L^m+0B^_c-85>Bp!sz*Z1*p&=HqYee# z(y3s*_4zvzq|GjOnAYYft>j^wRXKcpB2N}xmHeIb5U_}b48MA^ZFsg8yIls);K=~q z>Gzpym3af;PE|;rDPLV*f@FahnV?&gFX7+FGB~~%#JYa_hhuF-!RjUFK zl_e}OOv zs9@mg0-@mS409kM%&$=RzXga3f^YyUs=Co?*7U^4&`mplmh>dD|g(ic|A3|tYA!aNVD zBFxjWR}ufs#NOJ4le1lk+b%rmn;xoG3!N;SiWKBr+aG=XEUUpqYY7LfWf)ii(wg{K z#a;e)6^pU#uhO3H{bg9$CzN$J#J(Z+FND}XnY>$V3AsX{U$K1DE!iud#IKwu+dhe< z52Ev=Z|=Yg*jJ1rp0HQySl4-yRqE9kT^vEBA3x@5Kl!hP)l>W$>dVePu|8BQ#1Glu zlIp!wcgxIdsos8SyX5A1oTq62pJ5&okGWAyXP8fMvW5h(i}Js}eD<=K|9vp%Z|wh% z@mQBu((5Ri2F#AUQ~si(w!Tr$G+DtyK6veHL&8bdqcNte>(N=Sc+9M!tmtc4bR?_B zFwEzTFPuy)RX49^FL%a~+v`8`18>N=bU(Sq^IcF;>tXn6(U_U@Tgx9?K!CeD*`9`z z8=K1f?Kt!!NECUpzgTy{y|!u~F_yDU!inWV zm%bV*C?+z9M`tq{c6k)sn1lS#$FT$3;1iF7qw@+Z(Wc|6t7Q&6*|FS=Ufiow>h*cK zYo!kl)4_84OLa5vV=zP9o4&S|Wa~xQVzEhB-Roq8;}CPqx`g&TI*VwCLp}sYchIpJ z%0(GH$yJOKNS!m`a(4sj_Ww1ye=Xeq_nwvfzxH1~-|YX7@zktzOLV<+bYxH1H5xmU zq+{F8#I|isY}?kv={OVH)=X^M=EU~I{pI(*_m8{Q{cf*k_3EmwQ|mO&sr_K@!Zqyp zsXg2+L=GGLc#&SC^+JZVp^=knyP9(J5ID=AtzJaBo3<%VP6aZu z?vE9J5O-aOTOldaE;69u;~a0;LOGj zw?@)2anG4Yf1W2%bJVWPs$TLakv4m_l`!-B*@{Uso<A%y;u_YwpFUXIAc9VsQPA7RXH48X2uI0y zO=3}qj6spCVInZ=8GZ8HE?8Fm;=kk=xhXb3{R*gY$e;YHj;0J39>oC_e$c8y@`8&8 zt@OvE>O-CcT>d|y@bVzht1S}>I${3V0vTU-TT^zQKV^fUg*XmHh|b&^BQ(%X;7hd? z$ot9eFX)zL=BLZ-eBp_PUtZ#98%bj3rE&1}h|afBAAcbPIHtq5IsJcf|2}9&Z>KEi zs_J`x92w}d=#T!3T2)X6p5i_ws)&W5x6HNLOS4ed49S~hiiiJ=U7zzaxuk^%6P$~N zSmort>P1JKs@qG1Xz(liI+HbCa!`fk-U}#(47787?Kll0KBSFF#pcCnX(jPum5hd8 z%zT?jm8Aly^NnJ^H@b%oF*Hwk2hXt-Gu|;!aZ&W5`%Us=l&`9=NYa&!W%x6D<(x$s z8H#zmQW?MV!=tRKJz|BUXOHjK&I%*6F8CFHRn@mnOwPVNX_ThiCN~WrN!^O(0S*mw za|q0t$rcoZe6dXrdcFvpJSFdZ03%LIf|-kJHvYOmjD-`_|H)d)cqlsGytdGoi?0gHBhZIj=!-`vDP2k%sT&wfdh zDNW%=bm81TQ0Gec1&HrINZ^?!f*6bmzgS_ppQle-Gl#TSptIWa>Fy!!eXndNr298G z=&3hQ0B9{H1hiuiSl83@6;J#-_a+o)ydg+MPw?&fpa%=(LN*>m6P{n_vkZ>c-z7WQK^&Rk__MJ|9PNwjHs6kI|7&VUMZ+G*AKyM-*8*HssurBT*3OUz47tPr$kc?Qe=A1BABCl zH;wAW*xdQ0q`h-D4|9d*;I~6cK(&W4UHjm&4i6mx`o>Kquh*2kZT;`r9NF04lbyhS zD6XV=i7dX?K0_fIG8gW-1Dkaz2#jFdowS_Q7P=CCJVJuL{w`il-gi$AXHy$Re?w+6 zHmwj$tPb7O&CYf8=i~d-;tZH>6geC;#u`!x%or%BuoBcnt8hYVh=MCydnVd)Go@NS z$aC}lI=|S4Qq|CExh&H`3*0zjsY|sA z$uDTFNu^o?sULA-7&98^Y?r#`+=X~6BOc(fm8^XKm8ZmLt~s~EKtf_ys=?H*JMyus zzNIZ>MEq^S_7Uz0*qXuH`1d}_YDTG_jkXu+4SAu>be~4%>ISqF|c&1_byPU>Aiequ1s`DZl0lK&B&Nq`< zFSKQ>PGr{d3uV+G|M!iUzs-wRs#r=21zusfIOWvw)Sde zcnntT2k`QF_(eJU?&>Jv->BE6i3*;-qLISj|GGV`!z?ue@S6Y8Ny}AgE=_PC6KCkv zwMD;>(bueq(w}SBLj&XJTMupMf;vGibYS`;K6F9v{8;KdVTUG@*Db}ko?b2^{62VK8 znBHO1Nk>`gCc47e>7)iF!PWl(D+Fd_j%-7(&CujZZ^Gi2V{ zzcH*Py9_Ah1!M5QFngFBC1x8koF~UJydwX$Le<`2Va9O8{{4~Z#gt&UgnJC7Z^f{Wa9{y%<4En9kr-#4pJPqDRba3HW?2zD zES4mvOf;{a9vXKf=9;JMfEuGOR2zmEYGn#Sp?kcRd1p)G+X=+?r@r&#P^$0i5Y&f& zv9;rcR%^avU5!;d56-lM)X8dCDXHTnHEI=;0R!eKp6~kAeb{}(puDEv$LS--;~q4~ zwJ2sq)sEMs^0gW@gw?C6$==QE3y-2(kTHrAaI%Jr4)(b)e>J^*BO1LYq9I^ohPznc>`!hNZ5MK%z|Wm16o?E~q}Q|5KXNP0iEbubrPP}4b31i7)^hamp-Q}xPh zSdsc_O-WJ$E;k%kECTei*6iA*WFt0ylP+J@BQ}G4Pd}?{J`uOzvi?+@0(UEG>2%D( zG}tN`v@85IZv}}HQ~*v+*|No%I)?WL>rPlowgaQ16>q_80j!o2$|1n0q28rAkvjGK zkRW7V!$mPy4E2?s{q-hF{BwY@2-dg*xM)vQsSC4<=SqIK0IPuBRE$;yf(CaE(MossBg(GB+woG## zhxRk?EZ+M|)>E0f2e&E-rqkC&-rs9)Z(D_JmsP6OT}KKEO-hPx*%BYpHX-r6x;m>F zrF+y2kh-At0}IT%l9ns&k6X;v$Q+IEA3LC7*|etncxLlrJ?vag*XqroL~rlz9-*Bu zIf>vV@;4QoX@rtcRc-6HF!6O;)a2s1t_1>B1aLL5P0n~Era!eij1aVh&#iUpO0(<) zvh*ZQTWM%Pi07!W5QKE+GmBQHK+KY%NO}HLi~%! z(u>B00F%)cJj2%6^G2bq;-5OWz?M#)(olxI@ec8D=ziH-OYCd+rgoObr?{=OjXY%A zM2`!m7IL}Kk?SHH>`Qan%H@@ko0fuBFGXcC1o1>2cd9ax zxN-bgSzS+3qvcvOar{tO*TWqzb!o9omZv2#hPmK4{)xA-N`w_^Qj+0yLTKqOk7UYSB2bS4BoNpN`f|4)OK7?i zK}35MESOm6p)IM1EBFrzz}-A0eum65NVm}RsAo+*?qI345bBFLn_MN}S5we8c9!=lsolnN??fPdKk;KZZy((zj;x9RM^>(cJ z1_Axid%JXWb(}MRY1zKragFQXzWKftys8#~!8nuHcQHH!_~|_p9K3fW!W*zfL+pZ=?Wy)97nr$8Stb2{Y!4g;fiA+kU?KuB3KryAprjJDd2e2EoblJ`J6*C^^Ye%oG0Bj&zm_(fk6QR?= z^!eQLcw6&ziBa%%>nr1Yq3Nn1{@7(SQfdE-RMLdLGMF2y1jC}o*cDK=YFszhU|jA^ z+5=C|gR@%wh1D7mE()TH)99uWr_=Hx-OPmOi2#du47$SZQSPhxW|&dumG>N;T2mcN zzxmzAn7rQiKHNQmu{!KIst{{CkAoeS*UxEN+3K^&=-WS}p;a)OnnWCALI()e0NP-j zjZ^WZIh=9#o@SQVR1(mj3XUsH-C3)~MFOoUhn_oJQplI$0)?TwD~ZW=T>wc^yw!cd zD0ZOPtrnl?v%dWW_E#E^x@@FQ$kf#L+mQLU&-oUN7Ovi7yf^l=X95HitE8Eh`~21y zzXU;ga{q5Fm^F{3WA0gJYMZ)i7kVmhvdi+nMS($*O%_Dyl6(=gFTKlCXBJnM2HgU6Q`nuq_rjA$8;U#E8&mjxt-2EEKb1a092xbG5&FWM| zINueE@Z4R3Ygmeg;@X@{nW}s3yXSp$cnPFj~OLDDwa_wOsMX5r2nvhm|TBGnwxP`4uAM@nOJe{dr^2t(0V@U~W ztL}8#VK`o=bmhwp+?t-|JIZ{1SY`=O2raY1axvge?H>UJdzgpcR zSDp3zyEYvdEZd5>?B6`UC!*JW5RvpubbaqsS6)oI{n${JGS5wi{$+r5(jMcZmw0Jj z=k1SGUD1MTNaxzUsJcmYJ@IAfY5&ZB9fEpK1u_}x;&26tD43=B1g@FW&=16TuzXl2 zU2D!X_-vqM3SFq!63>}|;NtPd23?aV*M(5n3g?}eLD3JS$SO6+~X5k)b zve7P}6tcs|M;$Ya3e-hCY7ExUZXdx!mvj0ubZZ#*1UoX0pzCz`V(8hQkL4HTymaxTNHZoEl6>HEL8*Ex>(!e4D&zY{MfyDU%i=xgD{}x)T&_oE z*av-l)r-I68C*C%gNpbQMnOFqP%UdPSG*?v)(J!dbwBfmnfKK2k^^OPT6{k^&H?M- z^&WFip~FdYLiN-sqS!9D9c~zVRLU*45nKfSlpfXZ0|nlsr#}6E2SLC0fbP5#LH~tI zd-lE}fGM?5YZKiL)HD`g?C-^xmX48TpJn^Em@73drX4i2hA)j0_Ky-{hIr5JQ?Dqq zQ?CGFjyllC=Y+}UOjkglW4+GTB+YOXjaw-M>g$(8Oo%BwMlZ>(5ej%T_^VXNi)YsP zlOZp6cfySPa$6K3>;EtFSru1iyc16CgvR>zKt-5B$)KPTJ7aQY%#ke{G6h#~=DHN@ z@jWB$kDaQT{g*Kr?Jxt14B|CEpgmJ(5@rnY2#EA^I|aJFs&dMYN=q5hv_$4k!vnm0 zRfz9xgBuI6fE(AXE4J-R2+vzT(zm>}8U@|OEhEE}opiSj&ejjk=4Yt1Rt)LlPmb{g z-IA+p|JR%$sA#XM`O-CUPr3ls{xrvPbS*~Ib9DatJfWHz-%HwTW%D#rGb^EIHK-jK zE1GmgYr6cq$Fd%y?kq@mh}j`FDQ0ZYp6&`+l$x=R41yXX2q%;jDV%)=|x=MRi>A%RicHHmu}^-5B@eGe!7W`WRtW z;4l+mujM-k>@2ry1ie-pc48vO91@?uX@m=Yn%aYguMeT4cU7%9F@J)23#T5^PX|>? zGlyhx^(l1FjEH-97 zs0qB{=&Ab>{x9UB-Dn;0;5!kF_$5#Km4QlU{%7ED&@`pOF`7Yd=2xkldSrwaGOrMZTx#dB1Brs%labdrl242 zx0VTnu~B`)VMh1ELTIR(VA#coiMFrNll!PdBE;st^@TH`hYMaJjGo z1Utd<2CElxP`8so8YiCZMS;TtFNXIfyr)s1jJyk~3-ch!QFQ#-45$qE?z6^?@_P-> zuv$Jt_ZNmUzekW;>#ijRdL|1u53faz1I9w2QG#dt;7EDd_|OBfVPSFgGAIEJdn+)X z6RYOyPG?~Jfnw0Pc>wZB8A&UsCEtF$Rk*eY3bBfg6)%Y@5-m<*lc$ctNnp)1hslTE zBSZyhG$wszclv*_h|VYz3*lb`eh_>KBX{@B7z8wd9_3IHM&7=ZZ$DRz7fo$TgyQkb3ZEZc=!rNNd0K zgA)j^hY%v_M@qbr({Hx*TYMD~66E%A-OPDGnV0gjg4`W z#}M@y@Ny*NyKl&iF)?`YCK!8kQ`7#qcKWW%^tsWhUE-2BElzt;@oiBA0<#?h-7O+Vn^{@P*Vq=8CUN4h^*$^0V7sBSZ+$q8WH0JHGt9=uXv z-r!{43C<^mK|3INUr5$m)ZqqkW=X-^f@i!F?Kt92NphIFwjBYuW7Ooal<&K01f~Fp zXx2e(GUg7=a_~ag{(6q-!XehUrJ!9PI)-q{AewmwIHpNb?`Bzs46zO1b)FnwnHv^s z4mg*gAk$2rLXG#Ge}Hrc8gD{)8C(Uh3U{v;J3z*pGrjz!cJ`T2bgy{)ZznKaiy$vZ z8I?i_=HM-#8NBR5=T2jJsjh=4=a+APDcyf^A7D*wRUAJ?w+^;5KBD2w@NTpWVbMl84`eJr-NM`oJ|Hp&U#Dmy_V)KZFmLY=fbs; zA_yfrEE(r}D?KyHpLW;|mTv$87sFOxtOeX7wQRT$C`IzQPJ#r-Kz_cNeWym9b)k&ovPxEkk&}Y0UYQ&_VgGQ zok>hH7NAN)pwMDR#j%Vtjz_?mq`Bc)HiyGZBWd7y?7lxL&P^*Ke{)2d*3^L6u+~zy z*Zd)nFwmok_EAFBw$nOhR|vlXH0DB}=2KRiQx?YrQ+SaOc46j=Y3S4$f*Yw`a3m4znnavmpK zwv)@GG?;fgPfhPTz)O--d}r5di1mHwC;RDiuD zH<`0rV8;m0e0bAbSCN?az^y*&FM1c)SK_;3~tC)@v z6Ehcc50G+fW2%WTnn@Y98-Wsp9I^4HxT)KN?_bt~$6`#SHL;W}@hT$a8eq1+38DH;bcABm%7-U2 zVs$C!ev^nhVG-URe{0uJ0Y2UIA_Ea&7e?kZo8w=fLl(U6^0kdr2vKuU4=;6ROMuHP zgG$GDvQ>8-I4U>z`{XpDbJ~JDO_~P>k4b&#@~n+?;IBK2s7T=n;(BHiM4+S~ReKv% zs^0_iQHhx$+jhihu@0}f3Z7SfS{sLh>%f9aSXipHtx5t91=HH*^r{(Fo(o%&IJp9Z z$B-YJ;xkgY39g%-A7@zDA$KQ)5{z3v!`pXn&SLZuH)nfVs$wSgdaz~i&Us;hv2qk@ z>UIPGQE=aNG*vLg*l!u-0|jZZ1{fMJfc?B01O$1uvw9B)#dcmZ>Q|2<ZIPCC=Fx1|y$9+Zny$82!8HfZD1O-c0O|eyW>vZYRu&_ zdv@mN3bSql0~~J}g2m$BK`K>FzzDgqWhQ65(E(vE6pzq9?mTjlNmUdDKkIV>_K}4} zYPCIu)fF^`3@T>{ylJ_EXNR?{P`^9ooVI2xX_C%GTi`|OfDe2|mZ@P(rB+9GN0HQh z5%`vKkx#|NlHNQqruWR_He}l0 z7u$L9rfI-bTzXF}7!S7-Hm|CyH8mfJUos*<6KV<({6>gDR{AMR>9p^y+U~}Re&j-g z?!Ezze&92{TdbV(AmJ`Cm||Ig@{MEmv_|e4|1N`4dbFx1F8p~*{Z~f{u^c=Ct=5F0 ztBS1v*Fl~n)YOl}s`10jG!9^WQYS-k29M&ZwXy00yplIO+m$^;Z|0IDZdGZba}qgM{IjM;ra-bU2r_vEGG>BC}}USCv{E? z`HqhkJVTH`MKS&3zX*Zv(Npjc~jRF9ZZi>3Z zhQoFE*U|qf$uR91s@ZVEW+tup4nT49xB=s(PNMSi&a~U`Lt0pJA8Sr24HTw`3)dF= zFI5%)i_fhrWvnTNsqgF29jxBXGU2);S}lMm4=+yn^HOa8yD=m+>Y(DIU)Ht+9-xX$ zl958U!p(71CaNKY?dKUpiqCg*E8db< zLx<%Ckfs>b@qktC*KjB+Eo$WW3(h*MnLzsf;rZG(Av9`mSW_eEaIdbxPggZ&3ys%R zBOP0Qz0fcV;cW|2JvvYQ`jj9s#cxHFNi{-xNqn-v{D^Oh){JK- zVL3WrNiT2);0S}Qu{gJod$;t`WE`0rM(Y@WEH7ksVUu4_7KjE66=Wf3%br$<9i-TI z;zw#lqAGPIjM%~^4I&p2oj*}r-1WCNk-cV)bL$NrN#?%(rhm?#tVWaABdG#~wYnfF zf%HLy0LSr8xtfn;saVM{|NJIyvqz6*Wba8)Qj0?~TV*DZ}# zIRkXhoT!=?J6YD?!-^{Tu362mfOc5Yy`ds0%{P2g!4Cf+af!_xz{uj$+H9Gmh{?Ew z4**8JS#<||s5v=p>?q9StwpmT&QcA&IvSl-p=`qMdfJ*-q85)ps#G46lA2v$QSjoV z4Iv^WC+KUr^#w4lbV*bJQP)oVSXmrKB{0@vm z6au|M5=3ZW&F<3|6ttSJT*V?#_W)k!V}%;h+AYKQ-jnaSBwi{&bSsH^@s}L_B*jki zMGyzP>J!zSwr$~DBzj*@I_fUI3)(w==hSYy^2mPe7npfJ%Io8FoLlRUgdtd{Eg(96 zE-)&5?8~aPA9}PKwdWGqSoct zYfkOHCIu1wLR34`Z{$clZo(EI4Qj&U$)J6xsod`qItR@-Zk4|!6(o&_C`AgFgfM{1 zt!k{lgE_&bd_XYjLF~CDW_IgT#JP|`MEa>gW~wQ1`S9M@TV6%=u`BLfNRfwNC~Aa; z@HY#-OguzDS)JxUl#et}O?jug@OIj$(Oo+7aLiX%ShQrDCZr(Xa>Ivn$=(&@O_GGf zKiWO>4sVMl;45q5S> z!s~^9t^@jlH}0Yo*rFi;&pd^QM$Tdeb0}a@3?PU561!(RJhZZyfV#A@QYKRrCDle^ zaVSyC36Ung8}@e6fwF||PmdqIQh2pEkP)VpR%f2f%<>R{2h4w!OW3{#Nb&i8p&9^y zU9PMQXjI~FXGF@3C>edkvxTzk!Ab$)f|hI<=jBrKeadC zE}yo+=cU)EDmLe8c@Nts(N3Xqt)>r?acy9VWr_$viVban__@3C5$vrK4G-BD#n}4_ z!OC0p%;Y^)K!^BQtcrThMk}`FS57)7*EotP$M6wDibj1g1bdV-{qFIJeyz@wNs`2- zj!KIrSIjQclwtG>9WZGziDEV0&(lsbPG!E^v6~ixIAo)UCRV^WMt0~U>~A?PfUFqV z6Kf5zboc<=7>LqPCBrhCYd2vFfB!k`%jMaM_B#>7nGbjaN&0J84f^45dmQy!Rh3fO zUcLv@q4;B!f4oDgfpkUZ+rUH~bAaEc|3Bcakdi_71rz2H{c9Al=sKrM>o3JwlOuT< z{C*M>Cey`Z?aPqf?qO01)hBTYgCgZyl zc2kFxSfeTkqDb3`{buZ>y>9|iPHa9eW#~c_p%svZfr?`@6qmDRN@volgR8=VTOuJl zKC%iOG_!_+F-hm>kS-A8An8TP97;y2hTs>sw-^=e3cKh+;*kGPe|w4(r2=$v{1ZCuU6e@*u7o zDaiOC@Ue*#q8yY=)jlv#8|dy|qbk+CX6=Bt+|#0>BLE{cA53v{wo;KleZlLqfrVHA7g?Qt&9E?=77SFIK4=m! zC!CXqm4L6`48AB}_VuoOo3QkQ5DE^wOp!n75KIkZdilR&( zvGnz{3pPn3X*jrhPP&c9W``WRzT?sq~J%thqK&v2#vM7up}vQ(WjEM0Ln)H5I7G?@=E!{DQ`LSsSLF z^CBIen6ESmQM6QBR4=ce&koHG` zYU(qAK4Y!7i+4S(qB`ju8S@7+4}A!juQNi`wzuLd^4Er6VkRO6uTQ|$lKa%uID?NJ zG&QVNZe~Q%1{P+2U+D`r>JMaGk2k4vvwUs1sBrJo4Kb7SmovxF8;Z`-`?UCBj|m^? z19zPp9dtm)ilsyOVV!891Z5w-iwYA|DSx_L`j}!KauG$kSYas(&N5`vcyKCMkjFmj zBgsHBDsGAmm7@vP5BX4MSufGXUTPgT+}raL;OGW)*GxORoVO>V@nHl(&4RobLttd3Hs$Gb=tGiCZ>EVMAQ<*k2818KkFTcZforG(4-Bz`4bU|OcJ|}jI-u? z+zqn%6Pbxjk?g;*PX4=&zMd6}C%!qL(|VQ*e|-T1`nvFBSQMIwZaU)BS4^|!e1KIO z2hEzV-AT4ye@MtUs8994046r8mv5TZq2)Q7gO@~1er0Lc>b*=mn`{8Jk1Uq@HM{k2 zPIT-E{~PCFN^gjpfxkX}PSP+rbvDtQN=~8a+Em%bC%d%?-?low)sUH`@p4rTJ1|`b z+~|$6e>wStzK¬QOqqFm;V?%gkCz_w%eivT*P499h?HNnQ9lVu=j?;%c*+^RYrD zGcz@MgQ33jSEat_luRqtjuM^_Dt$W>i+JMJu8&J+v< zU^k@a-Ez=SWtK1{Ggw2tu*KqAU5M`7UmiG4PAdo{ckZxuF%8$Z3M+?EKLI? zYNpAQE2?Tg)9A56_DJnNs!{l2)Nbeecvs)fh3su07l5Nsd}X5g_hvlovoKgyGl{a> z0`iA<>>=+d`311I>%uX#0L8b75O(;e`hla%> z-3yPEoVt1|VVxsZQ$fE>$AwEg<%2>Cor9Z4CMguZ5Q{eZtC?%RMOXzTT!Z^joOqN5 zk>5IGACpoV?D^E0!%*2~ZzVpR8$(u9VIzys7|6MdrYz{^K^R7g%bGMhdfeos*!u!W z(o0Ub)0!K)-1_HI1HjBM)1L3MRWY+xs)Icav`Y5co0x1@ju6ipM7(Tdy1-*@m88~` z?wrkVFJN%Ecvw?cQ~RGc){%R^FIDsRihEOX|OTGiqeiaZ8=OTW$!(Tmspf3||VH zIJ+6etoG*g3(uT!k~DDhI&n1wS3$Vyt#@dMPV`LvaY2sydSSaiPQP{WiM6)8)gWu- z%~RV6kJQm6;Q&vKWk5u~L)fuT?EnctWKNiQx>`jT(x+^GpXlb(glF85(SI4&Zs}T> z+eT~HMpRMys3kz-dK6{Yl5D}F18OT5_TjnmPcvAjj$EWK8vh%7^S2{8@bmWdU@2xvQHGELE6u8Yn192YGU9Ls z88C3I9GD3+XKxu#sdq!sKr+XB z{)F6+`OB}3c4e$-MSnbEru3E&i(kCcnCC?ZkY>etpZxt`y%_r!uWhPp zE2P)Sr%P{(wLh365$kaB10xgyU$$VcbH&P}I8Bc&ID0V%o~g@@VmeD;3&mRRZ$Jb(C@huqrR(=#UtZ9mw zU-K*k?FX>As87Mu`#?eu-hn+Q@uB8>%myLyrncmIpi1AUBcZ4h3!&i?60{z=162=6 zaei##hX?OR#Ntss0Wbr-V>^>r?k3L>2wWN0 z0FvNc>&XGdKb1F>78&hRppDO<&|YMB7zc-&&O!NPV)p4tX=)C9@9lv7#e10Ou$N5fvmxW4+7rMWrW zs^Bf2oN#yTe}vx8H$PB?{J2R#W8X7kBjT8_-nY;8|M{OMK-zsvwLa*lm}F`~gJef- zoLFFxF-kb_xP@b*%dC5Qz9G zsC8)Mfs-%dk>OS|_ANwn~4NF!?qjOWMtls8izIo57UzUb;O!rL;@H+Ki$XA0;sRrOlII+${*)eKJz@ zllABWo7Nb_cE9w6p)=n$(Q89cCK(f&E)`x{lJ5+#UKr45Z;?#ZQ^6%L{do5HLnAj~Ts`$B<9dYzC*C#FVb&q9X5 z$v{nsB~l&+&n)uH^VZ=a7ru9hk%h=$#6l)Wma20r^C{)hBt#t0A(E%fs-VJD6w6xT*s(7v@b_BRLe(%n*@xe6dCT*(x8811u zVRB34;5c)6yu{MmJP0XY*9ewKm%nZ1pj>&zxZ*tEqShLi#2_0w`>79$MlC=1z-uB{ zfbKnrDP+ncn0H5$YL-NKfEjlZMp@g>i@%0i)I4Udun0*|age>rsaqSKXqnls-1n_T zL|8;SQ9_g)g3e2BJ9LPtUV(1hhzm{(f=PIB@Za(ZM+eOyo9qF6Cv9s2x?pm)Drt&f zy;FpbwWJtWw3!T4wUQQ`STz!bzzT5Tb5mK+X{~}y`V&GB^Mn!fFt@V9gh1pp-UsR8 znSa<|9epPZX=*CGe)0k2-}`uf=-kt?&ajgL zJ&kuYOUz%$S<)4@ISCZ0zK^`iYjB!P$mAXTZz<>m17}C%CjzN6R&=0r6O=%c*^E5S ztDb)Nu!sZ(n&2e$->}e8)aS`~J?6OvfH=a#MIn_nf;_Sd1jemC5v;o*8CPzZA-pIR zZVZxFLH{|`Wb-9gc{YjqM#7T*!|>^+FjfFf_})**5P36}-o9E|eNt+YwD z#1OJC!1jHKFD`rQG+Vse4$Yd5Mo-RI>rOqX=DU{}Zdyeeu7lU&uUZ3CU7>} zo@Y`x+-|6C#z-nFG(XMk6iA~baXpN356j_siW^yG5xkVQP#+Q=W6a{{g}{Gzg$v&Q z?m{9NB3vs_W!+8YiF>1^T&Iq4u^5rV`I-+6Qe2HeEU97pk%@CSuHK|1r5RLdin8!D zkx7C9`&6*843uoH_o%Tm;Q4oJJ7IsTwt@ebx7ds!|cI zTJ+L~1ErHL(!Ro6aolI?{u2UeG;9RGg-&pzGQX|O8){BRE8npr#`V11)hVU**zJal z3z4#WF<|6_a-J+A){(mRq%hbkhQwyNYGryvJM5C~k`PVrjEvY``3|8}(s$ukO9!QZ z!(ltkf4UHb51HeRao?DD*%5%e1Ps&5qD7WJykpyQe4xCS?K6C~g+qyiQeDRbn>aN; z{Kk%6W?s4l&i7r~U%Ugt%Lp-Jz4#mIkw+Uyl1lQa$)lNY;9*a$eaC*+yN$ES<<9K1 zfeZDb+v-XQY6@=uZ2D&p`V(k$OY_QdCe0-vq@Wa*KC8W>1hAF$)&Szc;}Cy_W7koX zl{W(n0I_$@+w=z%#}?Bzu_nCHx|p)vif?&Ezyu$!hDX1v;5(exlZr3J0Ydt*Z9goc zKL>VpMwHNS4?sqSEKBPb13?BkFzRE=q$~dn+g@{PR2YzCh?TR558uI1d@YJvwQ`)9 z-h3xnORIHJ5||l1Fz&IYD%@)gFL7+tl9IqBPIvBD8nq5WHsS~&srp5R4Q=3kz&U8e z8k1PbFt=j<58(UZ?sbWiW`{dJQmwX&+XF@_OyG&)69)ESn8+Z($z^^%9gZ8X4;2I0 zsbO6!udS9o3~TlgecJBnH?QJ+sy#Q{K^CPq%h|ZlRxQJLo&psc6Xl2{kuio%M98u9 zIr%%ninBJ+Y=Za6HZ#`)xN6TNCvE16$Nt%P;x_3P*RgOHrc*Z?iB6u3$&j$VwZ$`P ze+1?R6nCKzMi(6L?7KoeaQ-+I_ z2%wSL$7mpLuQ`g15u|c(4nB~nS7s}%a!?QsGC0YcEH@M45VI3P;QJZ)y^jphxm$Oh zE!OGmezfrdbisjt$sa&c{cB3~FQcgMV-R_dE`NU(#S(Wx+6&Hw513>s-b!kQTR|Ah z|MBvEy^oxRPy#tjGKjDTZ$vF)1ct0bhDE4`G6c0)j^tGbX1Yd^()T<2w z$Ify84*;t`RKIjOeV3f({9^f|&hf&Zv5!YCIaAgz1MXJ#v8u&IO&0oncK*vLIEvR< z&i3}m_td+TBIOCg72|u*m+ROu3YEmN7)}XdmX=_76iInG<)GD3BocFB$)1&W z+rVCr=91-a#0gSdlN11zvf+rpmz}S2Ek&n){Iz@J9=ZL&(??%_`yJdJpnv#7N%?=^ zO{rzb&YPbqZ3Mky^1b1ftLvFC#7B*Dem0AZI6t#eYRVlpxc_he^o;*W^= zhvSjLrtFcodMn;>y)9@40z->tr>gs)%siF{fx5h)e@KLe>!4cP&*G3%@bW_FDthgZ3y@qeo1WQQODzNxo-BEHQ`VkcgDWU|)`W z;_-N1K&p61xC+8l;PJ5<-Ds{zI+Y|YMxCjTJF3Z^@|rM9>sTi($s*!7D#092o+Vl2 z#N6*)^@$S@$4R6Nou+e%%rW9nY?C-O>&iEcR=3fKd2vpkCMN1 z%I-qllm?-iPT{>Xu6x__*;Oyf!mwNT?f2rRU9b*|zN_^I>h0dXAIp=Xu-=@hRWbE{aW zIFJxF7mxM5I#}{t;Fm?Jgr+-7gjbTmZV1la9(m1DDOllF!fmM3qY?g~-C*mr?1y@e zo%d9?0QwSU6Id5bNg%1|j77>#&5{TTV*{JGuDL1v6Q++AQ!>+?Bj3UAetmhh~K&c`G?@hvH#W`{MNOW^IP}R zr*5b7s}zEZAW(2s=166BRibj9uvBR&Af2Cf0qAJg3XAcrqMx$C7FtR{EDq^BSMKpF zjkC0au7cDKvRBCKs>zqILaqMw#Vfn)DXan&aG>`w@I~dMHDBa`$VC<3OwZ@sFLa)A zEE)>*LghCMB7DdEe5{h&3RqaJoradi2=z?o9UUsmti~RiHnvgvAFZSUvlk0}+qxoH zs)$u#adnD}I!K}d0|pxqJwyB3B5bVB)!bC?nvlIqcqRqyDd%wJIzI%FU-4Wcbi}ii zOeLSiiO*<=7%8~{9ubx#JP{;eAz)_8iE_vK|Nfu{H#6|$%dpN3Taa;m2_yVUk z#QRWtwAsxaN%b8Vz(F6p15_LQ98VGoia>BwP?GXnC7-6;m{I@5liU&OM7==0g7&&n z63jlhDP8s5WA_npz9U!1QiMAoLF6mDi{?WiOEsZUCx|>gi)jkZzoUfFOXV>s`;!uh z{BuU5jD}F~fJfT<=^ZEizU*IlmnikTGCUrt>DwWR+KTE(`EN+Bsf2h69(v4I#~u&7 zoCnDafZ$|O5-02`;F&PXMh6`g9H@su-MSj9tWt8xj|@Gc6)UbaJ$OR3JRvt0HpVB{ zJbI9#$5STcG?gy>nxfzMC1bJjAfzd+kuEEG03$?FBcy`;LbCPRbIx-4v%r0X;6{H6 zz!OD#hnAffkI?WicRp^amg1o+Q63FYuzeR5%$A276P4&wG@QZ)`nL5HDGgFGP}-GD zFNgBbf_f5#R@)8T=-$An0nselPd68)JqZI4rhit_kmV>@%y(c#i9T_U-2Tu)pVC^# zjHYs~B@FF2CoQ1{!6w2&YU+sP)vvmcW6tW_!^j zeMlm%P9!>xfePNwvE>`N$Zu+~rQ`;nFs9)8ozjT`x3R*Y!zL(juF3GK?|yJUXm3gb zCn3qj+%f}rVTM#h8Fk=#0;A6Z@Q1^5lnJJYuTRBv#A)KMWZfy)<^Z#UQE!saF^%XS zxlvAOy382vzXXpC+{hEC*@B6gXM;;+^X}< z`x;L=K-Lg>n#nDsnmQ{^sM(RycDwT#l!k*dCwRfN3B(edBO}+q2}p_vf`YtPm0ohh zKe*&X*aZlKD|TqBF0FH^8490A49@4<++lm5)w+~;q1C*3C6ZL{k8SQqxrrtGU(8FD ze=edAkLtIF`GU=7JWG1%m2_@r%iK%hYmQ)|DPjKRS#C$m$ z7Z`KNrV!GoV=kzUmuj5<@%qKDvg_}3&mD(Y#uu_LH^p*$KO{aUG{w7zUq>Vf#O1+2 z1u`iS)p6o1nXqB*)1I&yzsfH_tb&&(6ljG_hzFPi>dy>Sc;)?9vGmGBEztl@xk58k zt^$}UkStD}{NwG5moH8(UVK*pwfUu_q}T8}FYybxpB#F=N>VOCqHxL5KWa|}sdi^pg=pmqXg6XkGL0pCtW53u5aoePlq5eRo=z(~r8uxgDw!q=gI0d4 zAHV#WH3_kB78T>8!B@@YTA_VjF?eAPKF8qwX>+&oR$kyuYbj0Ghd2zpAPwi*3|uZ% zXzO9rHTM*+xi$w?u}YW0rc?K4Pi(pZj%)tc=L-nzKk8f2D;?bV_1DKwT?mx~X?+}gke6fYrb-~D zb}ZzOeMngZCtIzpKLn;uo|}=mVtmPP6hUZCSMg?WL5WAha1J3vE6wqnqel?iD|Ztl zO0^leQWd9Q*_hrby6tKMq$x=wlvg6M8MqD=;C*JDE44rqgWeQhVj+S`qin=J%jR6N zAlYgwSK<$G9FGc*`V1p~Epeh?{8GMIkx!T(q)n4TZfjo>9W8uIz7PrYfwj#wGmJqY zW?d%LsbKexlg?xIOv=&3iJv`q|FO$swB5-=*F7ZNSX(UR?({T*^sF<6JKg>C`-4>` zpcl36DQNYxQPJiqxMQR)@83k^HNRp|5wid2kQ^T!A047H`Rdpxe`fyg`J#yA%hYbwNf4gK9e?<5>YJsJ7C2 zwjlC&67xhmP~?HkN+Sjr1sY*+sgH=t#HCaHqU)I965uPf0urQxg=3Pi2~CU#tOnVO zH!s~z=i$R&A#_4b95}yR17~=J0ucW9hY#gN+rUHyq8O0F$S`+X7?7*}knC&bNaYRy z{u&w`!}1#$@?D*&dYN1T`^S_QFN|Rq;F560F48+ zCI+cy-M3$cgB=-!1=u#jq zG#cg7Eagc+L(xl^;NcYmQ`|B9_mLBGkvjQA6pLZ?*JdR(pN~R5>ERa)^}S#KygGJL zuKxL`S8qYniFt4{jNzbYaHnLF@GO?Z4LwDzj6T}5RJ11~JOmxolt#W4uLs>gQXYE6 z13x$ZDcvv_1%oh1=PHO@rMSGjSbE^888L9KuUWMX8eL1g*x;lqbQ?4RV(Y^O#8 ziEnfHuoC@YD34Z?sDrJ=2Ag38!>Obv9!+d{*3V4B7Re8av>d2V!#|k`c-&_$fqL?# zv#_!?px2Onr4UJFX#zl!lebM_?M=PIRa{8-ZGPET9~n0l9T1U_!;^Ppmu zu=(R)7AIPvtW2F$sZc?`B1J$zLzQgjkX$pxMc5iwwKaK|xYmNcll;Jp(Mahjt{DMo z8R77}u<;fXuJt`tU5TQA%HN|*Iz>q_V}i?aHq;NWzdX;tyy(0t#jnsUiJ)jd4MTn{ z@I)_(n=fR6!C>uXGs!vk1=-hT%No_uL9X6QYm!u;t-h(ay~*GaLX3`tiO%$4V?tvz z{eGnUX7r0{{(^(ULTop7H3t9aV!*j_dn5IZAn!GUD6lsD@B4eoSrE|4k%ZM4gb&=# z-~N&h=ECuUp4wc;BBWJiIgUPJKA`x^5Xs?&mMWnz)?VAIVbsFkkSe%<>?tovIukA z`2xLCMN!#VEXy85wjb(W^>lpsk2(LK$;C+4ZPS2d=l@avaq0X&dGz?n{rTU;gI5~( zWExez4jpxz8T~MWl(x#}S27)!Y%ZKI$vVX5RIrV40s@6&2QJE6>bvU3bWdZ}c+C0F zvl|+wW?OV%@%ex9=%`=5|G(}(dU}8Uck%4)k$;AKL__i%QY9)OF_*F-Dj8Hbhf-3h zgf`dM3iHN?mdl>cVix%<@&YL(6jSf$TqzTr3g8`N5LL{-$(XCZXqfB(-@Mhu3n1sH zd~=@H73%Emb+DHK1QHfn49IM*|NWZISpJ381GbY?EdTf?HpgF0E0OYqPS|Nkg^=A| zSbuknWBbQX7z3=-nIJapzk79{mZp8R_x4D_#sjiSZcDk)K&K8!%mPhy1$e6~Bn&Ek zPYY(1(g}W0n3JWjDAz48Wt#jz>=~6Mre=j)txUw|BcVQ(oTvkeIT)xz}VXFChi1I(ZQ0HRw>^{_yY2dK(zAC(bY*Exyys%Igsfh&>dJ^d?WSV=|sv_V6-dx(XWjm+^-}m-}#T zf~m`)L2k`%HpW+(lk3FX&z)y_awWJpCr*MZnle+CtEX4HN8(kEkwp6oH1C6RL6Qcr z4nuP=f@YkBAtXaHjy3y0nzU-l_7H?cAIPJz2mgGdx*C)QlYK592>a2mi+$;gu3FdG zF#&wl_?JBLZa^NPxlm}=aHG4mHi&1yS^v&7~<4fJen)(5zR3j^%i9-J(NCC0?P4c%kMe zmBSQ>Yjw26&KiF5f<7HtViX=jCk9Oy?ZUQ;kB19ux=%8^=2=3_T!EI)wb0@g$oK$Z>}d zpI=8O$-4gMgxy)b0q#XR!Ffb``no}>dzCX0vJ zDu9AO znE2UqEnY+SrzYDH=0nE3Z6Xiwvv7Zs+gyP>vbK!C`uP zR%3W`pqHrIfZKXW&7f`)gUxoid&Fi?Qsj>A`em^cx_(__U-~=kjQ7MxISc0XJR^_xkK8rITY^s(MT+3z%!))rI z^xuS_5^6w>pFDjPn73Y>4M_j!Xx2FU3&k{H+SoJzeAWrFHQ`>=FrCM^jq)D@%`cvv z*DpEszo(((+mJhat-ll2j6~~8$K#R5;#Bft z$X_~nf(QMsw?~K$GY(QBHRL6-ZFV*}{YxZa7 zN|q^94zjcUBceSJ>t zGwkl&lo8c##(fro2Syx+bC-Zui(&)eKB`R`;qfG4o|2xcc_ZNV(}_!TdQ)8lI7w}8 zTaXac&q1Vg9XwK#kn=sXK82oTXK|{tJK&WFjwR8YAPK@=_RCWxJ`-sWAyXnJap30C zGT8WEsN4qyNS#17u*z`dloP@w|A*u@CE%2kI!_AeMf}ol0MC7$+c%#~ZHflOzov`~ zpxjc3eu81w3()4G@L@CF;GYGiSl{QPa<{?vCPaR5tHoD*1Y0%kS3V#%o7AQPmKPEb67);#nv ztf;$NtCkVq;OmaDMtLm*aClBc>LghtFFXCiKm*F;O;PFK_k&5q6DD%MF5Tpyvqy@B z6QC2bj7v6Ge(VWLlYki)vmCrQ2I>!sUFlwaVspI6vHGe|$^)tr-rGS?Ryi_qrHj0m z>pd8%lBb!)JRz`om4bL=Kc6f{Z69<>Hd%QM(=-aTtParkU41@cI__{7KhG=dY2)eI3oBr zBmJY}$Fotl=&2yD8>RD@&8U;d6-vg?RBp0&U0AthnwP8*VFjP8o63>9X+0%54TmDVKlRX^f2E#jhkI$gX=z>O!AQK7u?S zJshG3`a{3K(8k<9DG6N-v;GUIFys|y;5Qoe$BMHkAXkNZX26_ecq5}TCa`DSjE|yUM6^d#<0R>bA%}O~R7hgz5H8qDe&KVAP zQw#3?5&l>M@V$C{>w?Z6)pw@HsKcy10=XN^q^;T#N@&b;C_8zIfUfoXh$<#U{q1=6 zUwQRA&_d`_23t;k>kfUIvf*!CaziEwi^-dxy6dT+8_4%-?n@~R19*jsKMhUzpwfq^ z#6~mYmeKkGDsW&u>;`Cz#JP3KFGym!1E~xZvNaegzm22jH539wFA#2#YN24@w^j~@w`tL=%wW`Lw)NG-? zJ^nIO>e0Q{e0{Asg3x|@0i4%ci0vDY_g&1I=^pjI>Hgj+7<}!ZEz}n_R6kjnEv%{5 zVw}eseWcATuC${uRa)ngkPJ!SnNMg61?$FHsA8tE#EXvWHX6vHH;O`R+4+D#;uL#K zk&R3Z`(gqmNbaRnvu4~NB0jsabs5?z15Or?7&-q1m2ir$G>%QKVl_tRFq3XKM>Zdl zK&ExYXp}=H(H@xDbe(Qpvu;<{PgSClFx7MHvN=|NS)^t` z_N^G31E>*;Lq%B_Lf+2ua3E5Xz^q7;$n=nSQ_hVZTgU8}(OKdWvOkHB36IFhuNQI^ zH1cU80iXBu&!1i#%Ad)9BX43BU8K~zJSZ9U3U04m2loPPEwAK#H|S_pue_&!O@frY zi9EzsDU1)uH~$O_^{VWexvljlt!N2Os_rc9Sr;%Nvx;#;y?gN?P8epTvaYC~A!~z_ ztZB+7^Fvd95clXU2Nxst6;B9{o@26>JepF8TZ?2A6ML>xyf~`5Jly>wDgw_jKM9uh z_8^;t6nO2VFv_Jv{fXOvX(uk!{0GGun@yleishrT;(Axv0!hLpX%#)sR2|P(1hbCy zINFww*t0RS7&P$*l2wDmyg@oQ$HCCb@(ZrGVMk_ z1?py0gB?Zt5|$@Xvm(~16l}2^pti6PobcTu*7*AW~sdHR;Cpz}C_?5Jvf8b$5@B>QrR?qt8}**Dy8p`d)u`ufO{Y^>;{! z-?H4bY8!Tv`cYQZ4{l4J_7^hSR4;L#R81bgeyL2wu9MUxW z#O8;y`5P&r{KP=owVLF^S75P(<*`{D#65F9Bs7GV&{*C?@&t5iK0tA!`)&WYkNkI$ zjp|rswjno10J&Wsm|_<-p0plM7#F>K9EZnP!8z9yzT%NQW3?H0NIBj&4=V`9kbX~j zZ|_+}NXZO)G}o!@EF4kq(gb4UghOA0SrjrM@)`-MB`C43XehaNbKTfJ$=6ewJ`hGo zobyci%ac={us0Xvy+x&T>3{kE1T*1?+H9Pf+Ni9`X~LMU6{dfxf$3fv`iZ`a3j=FW z0r6#M2pn8r>6+EZn+%{nt&_jdN(EFUuGM5?ND4~|kkVzsuuhVKhWf~4Zl*qsL0vtQ0EY@N z@^I(Z-79)2rHMq>%aSnJbOlttS-k=U_YK&Z$hiM ztcp<~f?cr$RG&}|*7}W>sk~{D&1O`xDwc$%a%hl`ABmjvS2&bw-hcYkC7(V)oP41# zp9wDsfHhgCKd6IccUc7TE6|br7)+-2pa|>l3iD8)N2SUilF0rsnx{;xw-XOZ|LCaL ze{aEXGx}kJ(TW{^N4_nLT*ZP~G+2NK&4{oGCImuOR$^tdVhMm8B$ ze}{AufBie~!IJSa8M<&zZWDg}#O5!q0?&$0vk%Jf-1U zoB#gF?Dqrm9jWelUwn3ZKBe*+gLM9F7tb=eusELi#IXTYG4|NY(uz#VFSc4Ahl}?NslZe6O7abk%ef(2E?o6w*P>?MoE=Ng{<6 z>${KQD-n`$4ra*0Vr`3Snnd!OgAVq0rcY4iY#E0GFypt+z*s(9_R*?6SofI%2~xx# zxkxYOBHw~rJ7VWxfrThJm9V1VF;Y2fi&U=|uh^47(vf#6h7odj#^s?FBvGhNt7Wc% zyUs&<|J==^@;{?GM-nU^_3~<6+Zkg?{`daTlPBf;??+FM?(;wI;wcF&9!=Q zPAFPZPSXEPdv150A~ zAJ$BCt{I&hw1a=CAOa1x|GRkh_DG2m?(LB?ptq*<>u63+&w8iNNy@p($q*;pV?r?Dc9hlN z7tB6{oj?Yl^qyXP{!iWc*H@P4{h_?P118)wUY8myIsZ?-KI#|G|M5}((f#?~$@B4J z?;*JgW&`kv8V4bR^4Bv77H`T1p45eoi=0DGpAevmD18WdX&LF>+di~-9^D=Z_f&_QaDEHi~ zaWm^^J-b6L*?d4gekATCo0CtUI=K#Bn|~!kZN0{24y-qX$W7kBWy! zp;^RJvX6Pr@?{^CKP7PzMCq7xX&jd#GEAcZ`Mc=au&WGbQCrLPra(;OAy<>vE=2BY z;~sZI{>*sF@=j77^N>&GKS>%?oY#~K$)2+niTn0YwLt2(hpIV!UjY2u65tZ~?`i+|s4V|IetfV0-^sIv{FhD{Nog`+sa;h-7t?Awdj(9A9b=z%~)gbSxuxWzLu2^!)XE99}>Heed_8&V(-Rh0n zi~{a~=@4#3(#@06_pbUQmePK=2-VW}G>+w$-K_!2ihODbDZ9lkL8X>{7eG>#A6f!P zf878ajrQuZ1wUCmn6FxVqVMFpLD>3%zukD?JiUv1`3TzQIEz!j`k~o zuAyans9|{xxiSep@Q(xs4aK~XK#)i7qyKO_C*+z!4GRd4Z20<`qEki?rBFPc`6P?d zAT%F5av!-zSe&WI^~i1%gmmP+@_7*8wwPyR>VEw6sY{4)L~%RHDMU^SD$$y;A;v3V z6ZQd$5ZMJXq|`ZXo&)*xiHw*>Gr_RuAexw*PnQh6SoF6+ME>!}eI(B*#2E%s`t3q2 z;#i8+5+Y-sMSd4U1l-QUhwoG|kQu*XK4x%$cqp3EkWU^6G7F+$mPK{D@$g|w_5%yL z3Tv(fT(%(7{kVVi{>b_E_k)M;|F2KKKm7FRt1j6ufQQ_Wl&f;cN^v3k0rXjfZFeot z+&`;5OXPpR;7x45e_Jm9A0Ho=?7#i5A07Aa<^Nqg?c{&BLf%aio=v7m)l?dqc#=?G z(g+L@LzSm4lO&XhjHFYVqK~;Gjw6QOxt-3>0(|E|1AIlpzz2Tdg&g4Mhzy=pbY%HQ zLK)axIdI5a=+fv8;kTbaWf;?R>ZaV)vpPEJk}g(LGXHoDVPf5Jz(OCIsG3nnN8SAT zuFSB1TQlshFvGr?VPz`n@Zu&h)4iz9#9o%stJdsD6$A%G3xMP|-fF)gQ$h^Fo&;*+ z%cBuTSKW7XWhmb@2@mtHRrwl`7uL#>2r{Pz;H`wH7o_BxM-NhxP7{8uFJL*Ynk8{` zow&ky=M(~ywX(eN#$5)|TvuBLm5|8tFCIi-)u=+j)@Ig{W>5o^8&rb;y}2{|`g|-RRD7 zOl8U_3|(Eo4P*_xU48cbv)Z%d{#R+lZukCw(myKS|Hn@r-QWMacviUoEx{X;N@G+R zQI^5V^`meH{?{e@1aBMo^DXCT*Qo6D{g+M|eoeZlz1LSt6E!Z5VD4!hOa|H32G59V z#&q>h_QyH^ul95OW8NU8lhRl6jU_JGddqr4hO$jy4|+!0v|C-mvxXLpRtM|f!MN0! ztx*`0?%zf4?_vN}=E7%XxWKZTbraB&?q)&5Hd-BpT+bm&l0bMRF>A({KPXu(79gD! zJXk_K!`?JvU;nWAx8s8xH;b00Hi%l7mBlJp?98Sn-_(H)=+B zrebl6Z{1pSD*n|e46X9_I@L+VJDNx^Ci}Llh1Jag>_-_agVIb31H&k~%C7CDSManb zYsdfMY|FCyUs+Q&VgQ!j|6f<+|Hn_izQ6x>@vLJ1|EH>mPDa$bl!y-*qfxpK1QaBt zX)p>Is(fh}+71FI=Vw~8DQwZdO2QS+sZorasuFxCNm%`={!+i4^CZoGQ-77^({oE2 zwfZ!Is0+7?ls;)>7lp>^461LtH59DSt$Sxt>JoSbmE!k#LZWOoV#$Hd<)L$4k+ak! z`b`rWi4bD$A)~)a>`Uf!7OH$?s&+PtyHr=x=82qU5T$IwDx&Ul2{>EMeK%$1XRY8i zd2>{{w17v=0&rz>3}0j!U3L3z~91nJ^db}M6OzrNZD6g*k1&Vndy=n1fJ zabMMot;(vMqcI9HRccd`Jlv95dN+?50VS10Qe~20ev8wt%@^mY7tGqU6c4M-EbQ5@ zvEO~Ovi+`Nz=Mnli!F5soWFpfWXb)noM3NN{_pqu#})bi@ss=ee;3aR^1pSLo8;q& zAC0F}p^yF?Pej$<+0eN1u>_}PH&5c$nX+)^iYX%Of+q00YEvCgr#(YjXnRK2e?OxU zoiN`S&5JE`xvW|;i9X}I|s1dpW3m#g$k5Vi{};{^^^7cU4e* zh6L^YS?O6q{}DqrBmYa~zoW;G%k;nBzt{inJIw-vO=Fyj zD>SqPYNEAi^2;|@EJ*^NksFdGS>%zYkKmud>>?YFgAb(ZRGBNBkNmy@)$`XE z@>`IEW9A*WowKpF24W}1fy;t@kPEl~cW}{?lUK7{4D&pJYmFNImLyj^*MWh^Z8hU2b+Y@fNPa{t`Iv*i94DqZ9)>VNxn z{$G!uJiWjFck!%n{~Pr$B84L13sgHAd60%HEv{CmUMT;jI#XNm8`4$uSCTa(UtQ9j z&CNd-DR@g=Ipjs*MbG#i=>)2-RgVp;7Fa4^G!&_%s8*URG6}9&q}hs0=;A}%+Gk8t0M*Kd*j`*YBr%T^tRE8p24ix~$P|kzUa^FRWta+iXW21ox2?}E;%MdO zuP6%3oJmn@ZJ3lA02R7^R=&Fxmr!lDBDd%$cl$El=Zpy$Oe>n_T*-;;Bb!apb9U?5 zgeuR}_^Cb790Gdz_1tfn?p(5YE3yL-;~P*Nj5xn!;K$ItCoQ`nEthOw?-Kgjk~!r^ znqolHNtIpQlC$J$ZIa*dF4c}9ZB zXCD@|`pQhY*+*jOanoHaKW)Z|mnS4)X%et22E{&uvB}G>GE28QmAT6-YE>=sZo%Q% zLHb%cg`}%IR{dX!IUveD)cqR2>f`PK>4q$tq|+|xAHg1SxrbOKx(oQKhAI4ep#fPP z{tCttr+~5#a3>$+Mf0wwEJ3eY1LHtIeNIeq-*^^EJ=Yut%wT2%ia6j?{SWNyyJBx; zvZOtCqlvDiRUu1Ie0U()F!5(-Al!AyuTtKR1MiZIgG8ix$qVHapv!e(XE;^d6XK8{ zN-cUR=ZwFol};3H`Xr%|&u0d3*bQzcame?ahm1zWu6|WX(o;^T?-Mbfjd*BEQ!VM* zphF#_Q`!&Ie*kF)|7k%3KhI)}%#GHCh-{?vXUlxliPPFiz4@paV(^tgxxq8i?P`MY zm7Y)Ob-w&^b{_MC{#19YcFy{~e?(lh)8=D^qvxv8Pe_)_v?EJ{P`DG8{>0`#Bzz_@ z+0H&Ey2LG^yLD)D7OiPmXtQu&_(Bf-lf_g3X{uer!qFAUklba+`DGT9?v*50nm74s zLCzkvx2CgTZ2GfrD!fG0FD}$q&ePfz_y5`Qk1Ncc9JL;XwF5MKYq`wckkQk}Eb{D} zL?5mE8I~uchK*w2RM8FFi6KYgXEx?GIT3!Pb4s0CN1_~~Q@_jl%2K;x!gBz8T|JGi zHKQ8DupL3mQ-Q#VwW5rwt8%J)^Gi*L3WomFPsHMewiRmBJeS%tgfp$G#np*4m4hTZE!yy> z_~kOL^v+nqEwc!Ewa%_Cr~3f%&+A#H|Hs1ox9b1h??0{B|L^txJ9<`+|FUCrE)YEk z)NHJ!stSKR`9U6uV-~sf)kex$ z|4C=zL4E7bD130q`9}rV?fQQ{J}RI8{@48{_xXQz@~m+FG43abFc(|EBT$}C7*y6q zF;D6An<)U|lTtNKSgOwbVqse+y-{zWjiX<-qzerLTe*D_ZS$|6GmQ6+zlg4Wp@~k* zjb+UVmPyABK7D%j)&6BRVqO{oaI`wWF&Wxh=Ve!+T1tW@4k!N-Jd(umS@$DoYF+sS z##?>*^r=g3$cPH|^f7T9pLyJ82Q>$m5DAnXo_9W^@@$XG+1ZT`~n^)e5S8V+`*+gx6qVf45s+kN++w*ajsF4 zt5Jp>YX{wKZhcoLP#IymR%5t^(l?`j$sfKdDgVu9YB$YD6|23~k5f%s)Q!=NIbl}; zyGF;1C=C*26y;;`;P2vr(jk%{BD($nn&KPN8s&+gGDe<}eQjyUCsV`_>xXB$S)HoP zC`+&8{^iy2#o$AiFo9wuiKzpv)Qg>y}xAh zei0ABX1^*X7RD?4e5mEi@$=sjcEu9Gev&T-&xra{eO1IV`_u9!uV+GZYt2Fj1&f}A z4kd>Xx4}@?q+M5sj(i^c=lyfH&l3LsnkG>YO*Rt&mg;|xD*E52_w^rl^Q^%C|BARk z=!j>jO8A-ZFqHpK>0}YxZ_r46|Bg-;r2l%$dAf+s*Y;-XOljnkeWRJ^YNx|4u@ZV6 zsMJB_>|Hl#q5UCX64!W3C=+~3Cug_lpb3oqat0z87nU^x3 z>`Rv1N*wm-(?GtF-+cOXa7Yxh5lI#wQ>Ub8N|AC$QP@US<3~YM~3!+ zHM2H~58{EKZnEa<02vBjT6J@Q`D$aE9ua6zcrqVwku#M+-h0*-jnP@5C$}vlW`Uyo1|3Mkjy%mOjE5(<4Gx?XCduc zdJ;^%)MjdQ2UKC{vj0Z~L@#Us>K1aq6xYX-rv0xJF5 zXMg(aMJ(C#@+qs^&f+iad@EPr|7SD_s6Sd=6|{u^|N2SU|L?f}^?m)<-8}2?|F0w> zJpX>{+`mS!&xZHc3vJ~5A^L4Iu3wLFJ3N04NLS+cb$itv&C==GOn<4bdX}Fi-ZV%V z)Ou?(A?x#UPgy!`79C3cNJ=alG>8pvIZqozhs64+TNt&bA4#9Jn}O9wrd}^?zg&D- z-2N?#!@vU+X7G@O}c?5p{{1rp}1 zZUIbnb6O0s|0;rfn+tAhviuhB`Zn`kLzvgy*7UcIAm6f^EsODb5i9Kbnj(BtFB=N* zy4%lOe7DKzDrc;~v)!Wbev8Mgu!K#{nSCRza7z$tdopukzGPAV;`S)KH`se+!< zl#ZwGVa8D^@=SFB%k3@cKnFnysQrv1hSFOkG{? zh1v&ugwIkTrs&vz0fiVgu+PvYqndt}tKoEMZ)?e=x!k@su5?{}R@ykh(iY0Noa!u7 z!>KP@AU%HX2$nh~SLhaXZ)zg!ud5!oIJo zb!+HlQ>~lo_A}SIwbsovG03;6o7t)m)3}0V>KW@et)ZT|RaNLBdE+mlG+VTUO^Dy^ zt3vNu+431aE9n1XF49TD#Gm1cD!?WBzy6c2pO)i4o;<$K|Fe^49sS=qBErT0e7SY~ zpM_(ejS4WIQ?m*%|7J5Spf%R*XaVa1ypkf&>SDt%keZ%qHGxLBHQ(E^@bX?I=b+z; zTtl~H49jU^fsUzuv|2YR_YR$>>Ot46MyP(?EJD{H|CWMGspQAMr5kUJ#VaUs_$6Mv zA!%yuSJpTddLpJk37n;^RQ4TPu~FRhJJWA1zam%Dcr5SFy2%hwjWsP+K+y6a%k3id zBA?Dtv|rv+YcBQrs)OQk7Knw7W31Zomepd`5?92S^^{`^I@(Y_W^dMCLq%5M`BvP5 z2EOqY^)%b%|68xCeWfy_|voKU_VU3-FfMXDqI;jK!p_b&aZDMvbUlxrORS zyah^PGpp;7k|MkN7sle+^=yy2*??Y=(v^E%($$vfojqE-KFO;UUjM@A(zvE2DARxv zap{=b_^{}^&r%`1g8mmiT_+LTlK9^z$B!SC{XZW+y3hZ!lc%$e0{E@Og#CA~w(tLm zIQH47eqlPzT3`5iGlegXa67u*3NTkv^J41_HN3@67AtofT|En(T(Y@vWB9hoLsNcU z@7@RrP)h@L%UZH(XFm(JLVsEQb@vW5zFBdyoA|X=7T>IFGfR}~u&1EdgrbJWa*itP z)dGJm`^#okXz@%o4!p7xmp%GlNzVy0C%2~QT1X|f=E9X0|WNAx!cyx zJ+^S-?RR%Qg;aeX8%k>m=AWY)3hyRN9j}EmTzzXugO)~JaknUUZH@P6zMz}88Qa)< z_W24)U+}Yn{AXWeD@lRN^1nWPbX4~LdHVRtz5KU}XC3iR$wTrRkn~2ZD(oQ(4c`Ny zJ>}8(=m_e{mRUSg?g3tPn}j`M>sBn0b9AIwwpQf~ah-R~R3qC%-?XXseYt$nJA!*fG?iCz%%|8x9#CqHpbA$~B1S=itiNm&v}QK8!<`&LkEH|K*7bVe@g zP1P8BRWXCw)#~JNP*+*ulL<>tvm{|rYHYdPN-<0t`G#^7>Zw&mTB$6a)xJE9Tzf{| z<&u+!pCD=vev5vKw6ogZ#cxrU?6<5V=pHoq0TqQo>>i4GRmhqt&_R8lJa8Pz7X4lP zT|E0rey*s1oCS@1_wT|+jePg5cN%~dNPHfl3U&OyJ7wW4m_$5bTNz^s|9|x4xa9xe ze{%fv-u|m#Ulm64MOZk8Lj~^f3pZ}da zd*pkp3#CuP%V3m9uH{ssM5l8?-v7wLS@HGn`vEBt*6zBpl)NciF@*|Ky_Cm+Cwd`% z`iDZQJ^9T6s6r+avE@{`co^JDuThC^_qn z&tew&Eb;=TxOaKC4pe_|&tI`b1Uwp$Blm;*K|5urVq61L5=#wY7sXQlmV?2FBPyny zuZWyJF$2#@7E3C_p0By3?hF(qy!&KUeUNSV=0x~vz#(cxJG1x^1$vm z3qy33gSw8o)ohNe5$XQO!jO|+c@p|voW$N9Ig3(L2&~fqB8`klobao_XM#`-bFJKy z>xx+-$n`Yvro^L>WPv~v41Vxe|37F~UyZ*U=ysWiBr8B3d=vRk^Dbp~rJZ4Z^AA|PoE8E3~0H%dT2{fqTyuDQI zO)U(cVHdw6Gi0Z;9Mc?C1`F?CrKKEJIDqne@jv~-_vZ69lKYokBb%` zmLm|xvMlA5yFPAIy8B!;S+ju?*d^m7{pKA%FUg)oDE=Xr6_R6E@bMVQXxEsxkoMu} zc+3Si+`{?E0%f&0FHl$npn~}M1TRqMij$WJTR)%R<;Tk1ws$6~+H8Iy`IN4IHvPV@ z*FGhmVCW^DHJHkTEHKk@Y=-a&+(o^>zm3YX9VAnxiVh_9i~EM8l7&af5>6^v1VE1LXJPm%z#2$$Ijf{VVH$Ya z4WeO}Pp*T+p=1dscLxax({om_5ihqCrzJw%NV>LvR>|RJQM;`O?fR@5ASQGk;W)GF zyI1AI?o>V9?Yd}~vP*ol279Xm9y%?Vm)x$5At!~8o6An4{()=SdC+JMGRq;^&?z$r zS3qA2Wvdml*7O)IK*_2~$x3nB#cf(GXw__2ithlWHq79-E;V+++!o6C{kwyb3rdFQ zB65-9YoHA8?}o@-p;RN5FM+rNly9CreGUq>tW}P?0J{^Exhhrxxiyr}-@Ld1B6sFX zzkgv3rWn)!r3RyFv{GxqC5x48tIJkyPqWj%?F&j;=wB)&)lN(Nov-fudUm$fw(E5V zJ#*(OW?#?U02&Jd5}##tHBqd4Z$jbrg)P4ix)4u2TseUkGQU9Oco5#;glnVb;G;rcu^H-x2{bH!?HmS&*Z+2M(9W=%Yd>uL zkTYlGtd)p8DWv-okG(x>^mJ(q!R1Sl-$ zyS-PdSfrDar{`ylE!IeaMs>+^46!0o_L}d`CB=k{nCf{6w!M4^qZL>w^rc;dG(2C} z?sG0)#^uqdl#`>AEQ8Ev=+>TVIP~_vfK)<6R98A z2+RA_G54qqV#=2^PwNbd!tJ3%>vrTqhX&wYSUs!tR=yvK&Kw{~;x+wxF~6ne z{0cSZj?em~>z1nVE7YtzJ~89Fn5nK%H=1}+tbKshdfEgHyp$ul!s1-Waq4-&woB^U zdQ2%Jz1h6^7`tXT!FqO08}baXcWgwq_7}9239I$#T;_d3`G{(f1Q}&)YqHo zVhDQvK)m?5dma^#9L65>mcKjc9YC){F)`B~4343vjgn&0CZF5&-w)II+%oYYxc3ji zy-UujYx{KOqi)^)ifqDiS8*RvR1Z6QmZ4^ywWjfsqLrEe;egtJKKFhG8_~D=aO!J% zf*v+fu?g<)Nc!_A-TfV8e;%#3zvJ(Qb1Q47X=8n>)r)4-V8vd}dHd@x5BpKuYxZ-9 zo8DEfIMu%Fx-Zy*+mq?_1shp0PnxQ1if4!dmE%YINjI4=l(S$LM#hD1G~R0 zbdld(jnJfXG-)KDr?M^!a3HwU+%U{x<6w*x{$8UnwZ+o~rw67ej32G``2Vox~4Z z#{pFu#$0I=O~FD;@tMr$S`~h(Qu(&tHzdQEO!5+h6lrK3Ph;7@zQFmQJ2^6|S542a zT0gfbUOPuX!545&{srsy`+jzg4cqHld&B2*kN*Wd@xrnp^D>V8*&>(tE}5=lmu*!8 zAQQLAI39X!cIdNct&iVi26lb>GXXi%wC^@=!zvD=sB9MnF=>y=rt&JN%}AAI@YXsr zKgSgWetFmrS+z9J1K2>nZaVvL75ze!>uW&3nE~Z>3j;l6)_`?E9duC^#do^txGJn$$MNQ5UAE3VoM|g{Yl<5UTiNkR z>ADdhw|z#w(gI|S4k!zKRSYYK;24o!Eo9&MoCs=IlH zJJT<^ooO#5T&7=i+sNl7VN^KyUZ}W%ehc+BoAZI)=ts5g{;BKgzux`$&m;T)?dZ5n zKUX60^ODZh9=k``+k$>M)0&Awu?`J)rQh?=%br%yW%@O6er6graNHLiH|alrljJS+ zpS#2K-xN;%^DdR3zjyjGD?tav{VG9n>)$gaxR`AA>9_FTZ{=cdbV|2y0B;wB6LIyG z$4aJTS#mLX$0pVS@W=u-lC|-fxV{A#Hlann2}&LA9;BM|`|!5HoU;-*VNmB&oG~4R zL))&}jA!Merk*4KW?tbF+aVW|1fXci^(2H^h2~L3BNtrDHIy=E28#p$KeAa>;u9$7 zt&GbgiITTB4E3gINsQcv|HeK0B<~|J;o@VG7&h6|t?S3IN!-mK8$8YiX@MioL^?Q5 z)#KA7sp_&kmnF|P!b-><&w;t_&zl#Unwzva`rv7K#pe0}@No-=#n}U@&uAVTy6Tx4 z4K+U-zmn!$p+;dIICy*jQVS4Mip>)MZqSv$S`TTc;8e~*2cU)P1mw5{-;a|eNr9s} z!s^IXAYHSjjKY{$iOJKN`h=i?LKQ7oh2?2I!a;t~RM<;irOpVkUC* zosIBG(r>sgW~_dvEI^kn`WDUC5V;Q#l_5rW(g!zn50OvK??ZIN*b0!ZJG&82p;)VH z577Z-79+vpF-f#L<$hi=tv9jYcT=fdQLh$213$~Mo?$pH2kPk%&c=bodTH+v;$dD< zJ%e7)Cy5taTR1fobBoa2RUpt@+V!ggaWCy93CnZT`bSydCUBopOPI-`z4PQ+xH|*A zK~}t1+~8{>fad?&IM`eMFWg~-e|*Q2q+({eso!&7Np92Up!;+<5e?h$Y&VFgWm_s=v0;{RrMD1!6hg`3$@RTcPQX@$q}m_3xDE&hzdNs4i)>e~qXD%KF|d7r#(1=iLb>+u zao(WP;*ut80jupw_1X_~ICapJLZ^8zQ}!@Zp% zVpX;MtB!=PEB1ShO`(*Q8h`u|9l?A1{u7KI{~bl%6j%TA&!jWyqAJ@NXIbV;*`c_6 z(%hdKiq4!ref#$P>o+fw)|R{sXN6Ca*u-?Gq)QCO-Cx$AD-P6biVf+$m{D^CXL+T$4V*#Q8(Xy^YEe`VQxx#In;%vkOf__9GjenmKz|I@SB#x zg7W=Vp%_h zL}ee#Ct;8sXU9qM;kAHQ@)BnwR4_O_gp=cw<3peOe-g?b!WGj%4vF=N#$0ec#iC6a zn{YF&M^wVfGP18U*4KuaTBmZHnklBfg5bd+m?_sVW4}oi*B7AcBv9LFdvm7QtjecM zOi;TbQLb8-{k^S)4oTILJGK7bI0URvjb>754LM;%$py7F!`{cfKp%YC|v zTOdU_Kgi(2|DwY6rSU>ZJj(*C;(k&t7U_U|;G7A|Qw7WGCw|fHh{nAN76flz>Y;mv4Z^4*0IiOfGi4a=vh|ydM!_N%udZ z3Y%>yHmQ7YV_8kv2o29kpvc^v%9)&?Kuh^6Ht+1NhJtNT@i)t2&n=@CsGRb1l?mFC z1SBN9VI#*}XMWqkThXDyz(QLW;}u2KQ!0XEgiy=Q%grJ6=b|^o0|R5bd@(Txu62!i z`yrjZ?xo1{sm@U_#br}A$PvnihsJLg615#ZELcGrnV4HTwqUfgaLJKfS&OIUWX6K6 z*TLOIhSw(w$EdDc zVQyr3R8em|NM&qo0PMYcTiiIZFus5DDRes74a_g@Zpdx7&t}hIfSK@2Lihohea|y9 zFA=u7TL-u0wPZ*y;k&<&Znh-Lm%c!f8T{-{Xj`f(Nu^SiR8`7Qgy~>!3NzN9!&&^N zJ9vh};qc}2=i=YtaOnQK{d_q5)AsY>i&xKIZErt+_NU?Y&a>h0PhfZ##JEpR8O;7P zTp5?!xNqcvNkSN8m?U(x0YC^DnviTh0{f7`3rNuhO!3bsqnIQkaJ91m)3o^cvcJ>c z*@#ezk_aUsMs&0hfCSFa2!v!dBgqB;8A=JoOaPrSmeSE+5ORK_{R_+zIK%yr%m(W3 z4FDLN2wDQ5-US7$D~)-(|Ed3JBSJLHaLUB1_bEyMC3zO2rvOG*FbPovF3~)=f^m)j zWh6s=aL53rfQ%VRK!(OB%TNRu0gwU+BFG@1EXzZdX9!S~U7-w6oP>x&q9B9`2uZ>q zPIx(-Oz2ZEg>;JOQxIdy=uicfbU*X?|fgT=mI-We5#s zkTR4NpTs2Hz#(s@hG6y`q#Vb9G8kS`S$cqH6ZuylUI#ln!%sWUp7+yavT=##*CdO? zXi3-sZ=UFJ5gR}a{P$`g%kn77aQNR5q8!`| zW(+6&aaL5YK5WQ$k}5fx0(V2lX)cLKc!{z=H;C654P+nmF&S)>%=5gz-5&-Q7yaSJ zm!5xL`Z48yOv1~%z|kWAhtHn9aOMBbtLG2$|302|3vWY0zu;>Fo*>FbfKK7gi-+sCCYWUop|1Vy=c$ok9@jL?GFyZPLO5jDzC*Byw6bac7VWFr2@CZaX;#w4&A}&1A7=6NQ4q!&|Bm!)T zDOVfDc#>yA*?cNW3JBl|XDo-Y(6(@hxOx_0Dv*JTIf&30<}nj^Dl`BP!wVGC5xBV( zKTUmBznegYuHjsg3P4ISHUir(o-oP=>6;ba0#;r_H30IBch zRMwwJQl#$p=n>e1&#`BKLIeypa-H!tcG@Kz8jMa9P@>a zGTv1`lQ^HDO}bSDCAH5KQpy!>4eW%!-8_4@1&S}5dQd6&2y-?q>U`u-HzYXDO^@vU z9)a0h|9u2!d``F>qFFP|@D*ezD7vx=OuRCiKPu+Ao=lGlnn!XVshl-nPv{IL8ynqm znO`7fHiGw>eSgX?P?jKus8$_Hv5%x>d+OZyqvO1jbeiH`KJtxOXZdu zm(q|FimhXV4;Y-#fzc)bq+iGw2f9yc=^9$E_SDgzDzzA#REqO=n|L zu+ef&|FzwZDCy5|?3g1sBgq9!E}dNx0P07Z_l_)Jjd{mCg-0|`Q?aEJ@LmpJ5(OEe zDQCbdq>7GljDi>^my!~>ouzlm1nScig?Ky%uoTpCDCFmTsqTom@MJf>hI9G^;IT2< zn1UxUWQejSPXUT40u(V({BV3k*l~s^O4t*pp`*dzvY5$zOa>7N=^&>l3nn>^&_E!d zgGXtG0zQ~HnFR8kZb`{CBOoc0INpmLI3a|oZk$?N`4o58qrU0~#YnT9GH`*w3?{jN z5oU;6cmO9t00?25!VvX6L+5D{gY=RP3S}oqNfZ=YRs-G!*{r}_4+j!H>I<#y(Ib%B zYv`j#Vi_&h+n>-}epU;w=%i}3+Qs*go)N}eP*B7hQ)BeVIVr|%z1qZiq&1A$F=WjMef!yQ`v{n<4BpBn2vLMTaKEkyzHT=3WxPGRzdOd`N zA_pyE^>`LG0LyYz1;!^VPEgze4Uh!rqFg`_4PL*jgI~a_YMxc813?Cph|IwDFbJnG zgCSq@VVq83lFv|vL$&qI#Zp2T7e9rF(7GY$^*nv{iCdG&M9vOyre-%65-rOc(VTbS1z&wxhS3#@z&Il_w`nH*iVTn^F`}Ae8<#`4(cQH)dFan6 z(gl9NF{0od$rEOFE4PZq;uB6NLonh4lT%JNAD-ljFS#>r@m#?Sb4Jy4xUjY45`yaz zr%G1sS>nZ=yv0sEBPkBG2rm^@tM&+d4uo)3GiLYw54C_&ZK{Rn5lp#B9FQcQ2fVEt z0LWMT4VcTt4(!YQ2XM0gJuqrN6=;kX0LB@D(Ol1OzC=-Yg*f+{imx0c*?<{LYdK$* zcn4F-{Bx3LAj~NvGe^vG3$&aX35gJu8nT0FRJVA@6Q=sbV?!3O`AEL&+m-ej2vb-j zebv>wX2ca!S!le3sBI!{dBP;3;1{8D{HCl6SAOVH+{jSlOA-%>1vs(Ua-lc07>eiC z##Dy*!jen?g5gvM&IF)Y%H~Qu`t%jI#T12khS~g)1kBeYG7h8`g~LG8T&M+hgSBP< z!`lz1Z}z`8f9<|~>mNE%v$Vn0?pk@Mr~3(P<`j+d7+iA!E2V&9MX42TmE$BT2$Rf% z5@r+Hgin0$jEtAA!<1&|;1de>W)TIuQG}&dY7KmrCtMXH8UI0tF>th;f3zSQPZl5m)yt;cC@00KFiX!A~A*&~IKf;i+eb0vW+veh>`=Y~5r4^*N%5BVsa3Zfc#1MiA`SLf{8|Mb!!ty3 zrU9PGpQ}I|LmcNBI-6#QPDvbrALI+biZ@F@rFj@4N=vAx@Kp>;k|u zY9sJMe6spnzqC6}zjetRfo<{L?G#zQ(&mD#y&P(PU5rH?$cyo)UAY7JRxVu_Vh285 z7-mOKT^MdhUiH8gJEi8^yW-aEb#SXx^xj%>b5AONwlEdPpyfFkH}$nTNs^-F9&qaL zss{6kJs%WmXO=92+Xh%7uS~NHNe?%1o{XqED~<6CGk3*n-M-~UN-j1SmDk+B&tmFp zUt$rKXz@~^7Hq{^=rb49dfg1XXpaOhexS%e)D?r^vOf}+lm_EEKqQxef9HLYreKBhlrBu~L9VqVBks{I92ox-ZBK&=x`s-hU1 zZFg)+mGx^LpaSB;!({5lT?VTbQJi zm5F(ZMs`ujGUl7QrCV&`aQ2HKrGjy4%H$g@JG}3$8Jnia!H|t6))s#M;d<5-H!4 z17VO$zqwVXR?!%)8eL&@Jy0!?#45jzfkZYiR)Dvr+n$fuI`@|QA=q#uG^uudW_;3Y z3Nv(^5v~y*>7#3K%HIMAC{89Z0;&97o^68*#I6xagwGBcD?dstm;v_KXp73f+Lexz z7AT5>f}&FV`5IJuV0y=HJm!|gT(}}Iu0;W;UV&7+>w`me?uEzTquwc2Wj?A?F5ihV z88dm7JcU{GaltWHlAMn=y29c}WB@6}lSK3hw|WPUaKe`e{#(-{JUw8-aPh`u39GGj zGDPqW!@iC&;r{-5r_$&V;8dy;P!b{FG*5NGUC_?|TOpFabSTtonmvTof^wl3jc}+J zYuoxp(OEJDi*=*$63r!nLIUdp>KSC=v=ezI@=G*d2)AsIiC(=~h5~TV7YAzMZ`D=$ zCjbFJJ1Btv-mbpdF`J0hlE0g=~x^-j=(-SBJ5O|YlZ$&L0Q8JF&?9E9>(YmA(vgYs5a@AIPc6E znQ=SE_KUbcW0DEu2ac8fm$7me#Ku-flQ=w+@dec9XDJWYVoaHEB`J@cuT-7dR-`1_ zERWSqJdFpbvW##YT81E1u~XlAXp_}zrv#2rD9);*$V9E)n+mlGRch)Lv+>>ebX?;~tK*YORKP&Tzu0)h?xlSOyS?-5dBOXd@EZ2wGJLP> z6{p|$*F`&RSwX^al|~7z_~P1>mOc^9<4`{gZKF^+wLGEICr`nXAmsl=;go>h6vZ(C z*CdOh-jm;SXFDVoU4Cr%iy0nP3-0e1US}*&bGtN5O9VB#t5KrjxN1;WdlaZ#aw;)T zU@wMvMokr~x&_!sO$ymmoDzsXID5&~6>7+gPk9sp$h_oP=LLp_^r7NU6yfn0iO@DD zD!?M2lQ9B=2r}4CJk2kTHT^Wdh;Sx!jk&hqRa3aWD|{`NXaG(?gsx0y8;e{;LA_pX zk!!}VRmW0&2B8SjQ_v2_AVOoDpy;U;7$!H&{%*edhfzoE1NMTRuUfD76kJbnIMohq z6h!j`&Tt6Qj9g)gNrID!0WVJ!6=2gidfVcwt3s9Jar_h{q=HT?P0E;f3c@KNf*s5g zyaK7%=Poxwl-e*?-BUxkGMmd%w0IcsZE}dLT6u&_v!J^dseeN@wm-x&{l(iE-r%Rgx%=D zrB@2MTx*@bv<5{zwdYvA6~4bCFq;Q3O|2fXt%f##z|y1Z_~$*v>pIXy z$F~##FG^FqAbAqmLO{hC(*`+i30f(EO>#yxN6$Lg+F6i9EP?n^!|>{B-5H01%F2@g zW8Y#=9=jYKH-i=)X!Qh>%-WSmO~{Z~p%M*>E@<2G4e0y?pf#vyqzkmO(+E#MxPVmT~($tVH-ZU8#!$Cd=!v zzm8p?j@5+R;uA;*@07=Dg3$wwCgAE`Z~w46KftNY(w>GD z4AtBzq2{{!j!;h$6BljRE;>}BEqq6DSOO(D6^?@)N?dp**7S^vN7RGAc8iHYbv+Z8OVSEi)PdtpLNi7jE zK3dik64OqMFDS;4?F&Z5`0@R*;$n2~EgKl)n-h(o*A*M%hrU8^j33}i(J_9ID~HGU z!T!$UV@eHi*#Maita?{5GBxm536iM+xmuJ=4bauYWNHBa?&D;N#p(V7Wo*=6AX287 zZ}%80Q}Wqz!7`@(>I;{t!e1g@rVhzN#7s>|&uIB3vsL?&YVnoeK0|;6|Y8q(l98*(AV0%za z1NH@@YFcQx)36#BcU@eKtpR-D$eLP-`|+v$u{O4*e(+Wet}!8Zh^|?!UssH;(X@68 zu(=Z!SUSX}&^#88u`wI+5M|>(aA*m$Q3dZO&c-^4TyLO_$qHRVZ9L?xKh~zYd9hHm zO))!G2)FU|&F?zkMt9nZ5jWm`dx*JdjJY|!=a`#9NmwH2#y(zLQ`n73Zkz&tfi@4HE}I1EqsVf5#Ix!p2!dHS_S@@%xjr-J`RSaeJ?hyy4uXqNb#0x6S*4DI^%V?38DnC9ZPe zOQl|YL6kKo$_T&(m13Kt*yeF>Quf}OSk#rb59(W5t7F)FZDyc5Qr(~F?c>_3G#w)B z8}#a+c&^v1z$xz8Y=C56x#@uDboXWhaPKvo4i57^&K6MBt2uqJ^c|fIz?!e?)LSq5 z%1-mrPQ?S5sQ2Y{oqmRpT6J+lW)PtZ43l7c7-Tzzr%c0znWDftugqLf{5D>iSt|C% zo|lPG<6GhaP1!TcT%oyu0ABJE&5Ajgx|dP6UZrVuovvyq9=?k+i#pcjnO-)Ra`zN5 zy(Ck0Gq`5%q5!u|%^R9rNdL-7me0zG_Wz6D8jSop0{ZG#U5a55G^v$4uGIL!N8~!$ z9W#`@!*PtM!A6lG(Q%_LBL><4rW zKfEwTFtLIh_O0Lsu^%W3ajMBZG;H}hx=UHk;pihpgd{Q?P#2N-Gir#_IC}QHrAB3@M(jb`wImw zklsTqaLM+o2Lqov{n``^Y>xASfs~%{t_D)>{LUjOi~d_Sl+rhAnqjXima+!?3c-{$ z5Lb$(tbw_5IAsmo-+4S`(dy*`D!VZ3T}4#ZAy_4(vJU2IF_m>tR}ZSJgZ#UXsw|hP z`wy#haDRcg%3|8xV_c=dYRd&ynj3k(z)BB-B_b>9uv9lz)i$Xu%%jjFrB{ky-QEVaEumN0k2;ix1c#SH*E_)jk0cOo;9M= z$NyY7N0`<*F?0u0%rhI3L+)4V1W}x_iO$eJ%=4(mUTE`?sIcPi)JLMyF+L}WN@pzS zBvC<9>m^aa^mThlG&ZcpO`@fV4{j0_H;GCwFY71ac70briGqMTbCgJ=1YSA`=zBIr znd!03zaB}B2THhEO4G)wb4dLua|mK2oCr45OC@rwKD0i$8y!OU@ph20rdknQSPo4G z@Lm)!j>+|bmfHIydBSvFa3IB}iUZ^$5t1Z9=7G{brzp{fodVNSK$3VajviMN50gp8TeTZSN*TrKO_r-9jvTi&oNlCq3CM_9 z@dcKocFc%)%bQ&(7M&VSv_|xa4C1n!X|1oaL`GsX;(!x|v>(X=un#`*g_;T};zu9? zS2-5nX8=fwGAR6a4-3K6SH;RQjvU^ym{iRhR_6({%wkcm*GD*bAOu0blk zK6=D)>wSxrmq4lQi-^)E03t#G@vKPO~=f3hylRi2aiF1C@0nkG>osv9`j5{!j z{TcC7uZ4U;`F?k=(#nnO0)|fhpbHq*(;%RfTYVkTSKv!|p>|~@Of5l*#0sU%5Z?@G z0aGlpak&yhr?ddT*;lkDwGpRyg|Z8`#6%OIU+~qp*sc_$@M$HSPlWQb8-^kvs?xdC z`tF{Wo8OuS-NDk@<&_oMLB;2h*t<9VF5zqhI(lB!mf-2PTpBoy1h>AW#Cr zwD69I)aklZFlIB72&A+>&f{1VW@whiI%(7fQ1OpWN)m_e#p8DDMimN;qt08(78gqU zm}a@yRs-MX(F9dTwxdm-<%wy1nS0IAg%l3ag(D84i*@osb^37xGo0*RK^zMO`yEa| zQuyu&C03k^2oE^QRO})w%FB&Z-n}}DiAHLIbzO4=TKMThQUZDhKY0-=hoL;_gwujK z;$w66_Ov<`S)l=ylQ-fDj>rMxgf&+j#o9+n(pPTWf0YTNK^px9&p~2}!70*=V zKtq%z!@`vYpdwVJ+;YZe#I!sXHj@ywt0Zs!r-YP^Oc5ov*q6Yr7v&(x2hD;&YBO zl3c*#vKVcczx!BnJ3C%6LSJe9UoCS18F5xRs@J44}fmUR7t^%D< z-I1$+hl+djv(a6)teZ`>=UTuo;bc>TV+kJ{hpJAwSqto6E;p+|ubGea7YXRMh9s?b zM|_7Qt#V~7bUBWJh8Yw&6#1O!c?!tA(ca&-ceZ=A^JDP~NmU2d_+V53FL)=Z1Kn}K zsFLl?<-nWV0=Vq}zk=y^dVuftOYPBmr9-~5qjk?!+zm~uIb3gP$6Clb1bP zcYD6|Y~6D#e^8ngN`m>lc}kj{IP+zV=YoRLiUySoVcL?ev85}mD2(cb&1&7Qs(szq z3+<8M^)`1Wz)iv7O?G$(;B_W>9sG{Ac?ZnR!Q_qhdPnFD@#W1ne8Gc;9bX?c-X(6_ zw%iNb{Z)V43?bj%*-_scBe0jZ=~uDp@58RQEqlLh-)i0KLPl45BC=~mT1RWUV5M5K z+cLbXrgt~v+f+_01AGw^{L2~Pja|Kp?|xUqd^rMI-T4I9d-4W#~Q8cx9H!3IJ9(%uH@wX0?*N_CIzq(;eHnzUax4+)NG=!zk z$n1pGu{Rr%xt0a|~a=i2dr!Slf{8V9GWavo&4sHE25x!peT*UL)5a(`)D+mqw`a>;Ugb!qs%o zCgcP&ZX9x}FeDiwbWqx`f%YRbJeL-#H@Jw&#Xu%s8SIl#D3t2jj}-T3(Ib>ZDZ!;1 zjcTW&w`D6)l`7PxJ>}wJeJxh5O}ZtzS!{#iWTK(zncX0*04`pLRKJI$$_YVnnGjbg+W?2ng|U1!Jxi6-tenUF&)Z z*%RI}dArP<K+xQoYJ5>T>vGu-Al%99Nc1goe`2_;^LWrKgbjwz5%(TnqHv9;1p&FDg zHcC}W99c-qM>+zfX)LZZqQdl|IxbZ+xYqz$)4a_jHBy>uL_fng7cP59xEDtNQUFb_ zyrKijY0+(lYlatkZSey#l^E5c zuHa?0lROre7+fHI5x}x*?IWojXp#jqTm}kln9_n{t>Y-Wl)FYkt%TUcz=^h=*Su0T z6IZUDXXgGJz=<)%97^^57p0GCcj@Aw@4#f*ZnkT7V3rQ(Ew^=JRTA%w{j{Prh39&q z%fc9OOHyc%`!bbap|YV*X*QDHH|KeJqbAtv-px%RnnBO&P~8K4aC;jlvU|7S^=mLR zL61o`0y{JFRb0I}fUkE~C=(Z@p)4!drJ}()mGapPX7iC5v?h|79mAHc%|+w`ksf+?gx^#S00aMy!x;`5EaAVQx*#gH=a0?crd zGgLUIN~Nv{7_ywe4-;(WaCE}6pU6xt$0(a&8D03qxya1ii{)C*RBjn@V#sx(5};2q zlBYUkpuBlY-{d5(aS{rkN?NIQ@W)hySEcXg)*HmMtx zrrA#KmCtUJhSLvHr*xY?u$q4Sv)k5>mBxPT;vRoGMRB~iN4)wspuD=rA->vX=e*v7 z-|rP)52-ky_rvnK#@9h(aN-5CuvdH?0^{J_ho{apz6qQ@Qm%#9#Xr717rQmoqLesC z?`;p28{dNm{5mq0KYAo3XhF^sdY|sVRYqIvEYX%>ok4d#GxWe;!VTE&;jhhwzH9e& zJVD1UJGJ<=s{~admvjk9-pVI-`uH4%>MC*2gE=F;r|#k70UhGUdV)fhnO3d>qg@{b)%3j|2Xm z6IB=~W_?S9d`YcHwQX&xPzB!o=|6v3;Su{a18F<=X*fkQ*#BQjl2u^3&u};#zI^^% z{5u>DoqxB7+s|M9Y5V!`#jEG9wzr=@`_pjy`EdLBpTKaPMASVwWib2GaAjO>$4>5$LI@#aSRw>_D=~K>qot_mmfB^Az#2GHgt~OEa#?FpOw#1a1V6_FxuH zF+(BCGgQ1a>Qk2CWFqRz_n5`vgSx!VtX>r2%2Q7|a~AK6{WM;ES88)Q85Q_Q8B8J= zlLUPPBm*DS6*s*6N4av{K2;>=Z0aM`XsS)>ZkaWMD{)pTk7lAhJtp2OUCVlDP;x;? zj9>}74!%w12Z}%nDZM6HWM=x{R2CI(%ep;XxQ+~G?0n-_fapZ3Glr(uNpXGA_Am&i zFoU7EZYfTuFv({q!y%C52qzht{KrN*#ZiP3r!4^V1c&t0n)KBEmO{Y_f+YreP>dqC z8}47X7Ar|NhlQA_xF58*3R0@!%Q2F1r+3{bI+WPd9GCUQS~at&>o%-4#DRKF2W{Nm zgwJk)vUbdls1$biu3AN(PFJpV--{uh(VhkH)?p%w|Lt}@XqiSegHWJ7}4+&-*$B(!Qzh?e{mN^K_d8pimjFIupN?^@Q z_gCATRlL2>q?N*M!8z;ckfI}c<#N@tB(jo6=CY_;(JBlSeS2ILuagE?=KWo8X(_ML zvwNauU0JhGa&SJ#qz9Pfy(z5OPP*?0XtD|A%pDMN)gciv3w$K!z_R6cqBNT)%vj;~7oL8aOGK_Z-u$?g%SqJV)bT{;$ zc1CoZKU<}C(Up$VC?kMnFubhwek?F9CQ;X-V@Zek^6tzA&U-< z-k%+u_Sq-4MjXxie>*!bU%ja8|Lr_`*#Ena=ezH~af~44t0+hz6Zbz{PjM_SxfWq5 z08?;*xR8oa8k0GSz<1wmY~0)g0FTQ=uKl0oF0wS#?D*NAacu!-6`b&4$@B$SBgqwA9d`SiiW4NHN&lz_wz$3R)2py=kf^}# zlNrPbCrw`@E3c+0Tq5Yk#t-Vt;5x$$8K0hlG0rF}uB55C8&G0;s$4>_=>UzB_P(=j z#=E^WGR0Hgagl6+=tOuyu25fc0E#JU8M@lhpdE%I&2YlTp!a7QDDm=VDmwYkvVQL+m$`F7}xBnbjr#NrRL$=?v@UM`~2LS>9OG(15o7cUYegqkmcTNVHz}p`9EWE{E zJ_kV%p^!w#9(LX?bww3lpG5QQHCGJFb|0MN34q48ltkq^$=M{QNQSP;3>C6tbo;YB z>DF-B0CiJW5M)SP6Z`tf5xPRz6VNzHAP7)$RT%{PHwPgb4+7}}<5etWPgdI{8kT+ z25gp^U)O=<63y$8T*^FDOXJwvt!st)VzVy*-~&aDpwYv{2!M=1sd{-k8ht_`2m;3D zAiy^7{kkDUQBWx9Z3=q55?@i$gFr^QED$avsgf!q_|@nF0J`;X5O7H_-PqXagFQ9l z%LTuj*L!adM~iEEWnVQZdpewsw*~~$&XOJkX%{81ML0mqXNAARX4j~z%T61`Am2<6cr5XCFH9R7M}(mfIK@fmTplU2bO@N0OIGELs>`iq zIwOH}Ft@Z(sfsy9r$=GsnlIOK)eVI?qc~C2bQ*0>9KGK^I6pjg42gt9h<04{Z5shIG^4)^f9q2QSx);fiZX84iFfM9 zZEveW!twi)Glz&}(9;x!VzCzZ^d0fHJ-xX{JM)kv(VF&;RcGI2vCS-7UtTM3_dr1A_)a#$}LeMD!l5fPU zAAu*9b$b&2`k49d z^xdjpD3{f~U?4fPy<0u0Y>q8k)KSCz_PN>EM(-vG^+59;2*xD4hFR2YwCPni=se;b zI)BtSeZ(H>U62{d%}GzkTsF zvgX*~o9AxN3fUwpS6&~N=YZD17_|@A0_)}PWWfE#yk*$y-j@cjxbxwJh-8#!a6+Xl z@Rby<1CSxvBBR`6?Q?ppkFG|q#a-$k&?U;_CH~C;Y@aH2c@J#LUeJJh z9s+wRqel-s-YSR3K_wE5(SDvzG8mzv7pa4%q)1ZT1Dk@^np(D1rC<&IU#|b(`4q(| z%4naZ@fyI3r^Wwo`0QE5|L@iC!T;}Go|~J&ci;-oM#AxajAJA`)MmU}!YLYo?*>xn z4!+wsK`hS_ov$=SI{HSQ5sTZ*MQJ`UWVTx8usBdoea@tj*$8wYHATd)6G9AwNaE>D zVsZiF^0oZE1sqAyOmlH=(oVd66V}SDu)(d|oRWU9snvAtSuVb9)wRpIn|tMESL}Zb_TGOhizY^ z$^nN0n9lH`lGOlVLNrQ3Bh!s;*WkO2Hz=Ngo&NSVpm{2GK?F)jDV`)VlrTWX()%?> zGA#ZIW>}mGsodZICjf#7kH;wEBl*{>XAdIn?OmNuW*o`R>-oYVE1R&wx1Sn1>v9Q=KPzd?E82)=M zbN9<62|DRk0*Hu~Df`MWHspwSd}QT^N=NdN?z@qwD~;|B)qy%eeH>;eI^!nf=(V`P z>HSz~z(%6FzOq$IIOy+FAk|=C$&N~ zjh=^b{)3Ej-O>Y7zW8KV1Qn+EXOwZ2Vry3UEXYi8{p!-=_%sxid*(I+MYAiE?U7ju zGX#47c)i_!9t@v?zi;; zgRAWe#Nc+%W@x8;d8b+b@~pCi}l+hsCx@!CRvV9~+ zt+`*yeq60LOr}}7KRPncsy)(;V;VWEOAn=x72dC6XOi2%p01GU8;j{4%2gZGqAatKPgblHT5Snzth(4?RFf{-7Z7Ax4S}9_jd2JrTcGW*c)wa>;4;&yq{W= z*Q7R@$^r$w)_iNDx)Y@OX{kcybwW>_5nl&3!Z4J{CkZz->bGk|>0Mb^?#O!@YZvRw ze4?h3uXAj63QO_>6^(F(mjk}1{^)fA(nX?KIq1}{8B81ZxQbG>{iTl<_6m4`VKS9R zWIeFS(zv0Tv3u_Hi3ujKGwF32h3;}c%Y`ltjoy*jCXB1z^aW6LJtjUE&9eGTZ1y*F zfze_?N;}~{BBo}&I*pL$F11tLJdW}VrsuGzGSSWX+*H20Dr-Ji%aB!C&et#LcaU+T z09~O-y0w~7SsgmZI&f<|ZnN9n@Xb92TcA6ARlPlH$FD7*>==P*s&ZZbRDr8N{Y{&( z)mDmKY0Kp9#*!7&)`P-2i`=qgg||q(Xvts_?Z)X89_2HzJ#6ncus22FC8vu`QHEqz zZ+XTn(|oHOLvjNW)QO48(RAI>p-$!A&x+FS(Z@11oek?{K-gRR{*{}|QXC@yH)p^MV~Vl?=~Af0s1t}5RCRn zLRkiJ!l)&lRswA$?5l;UQ#F(?d(}qsg8xf!0(!qDJ)>w~L_8E_b!AYACIC)D; zDKig{MDzvt$7{gJm8myy5`h`X5WvZpWHYI}LDuO`_-m3~#so%mkP`WyfGLs!Ni|oe zG)aTiMpmTaSJ$f-$vCVqkZyx(PYZWk6I2soVkF1hYA9w$q8OuS785;xn0T5XZ&F54 zU-pLX3g}S4X_c8yOniNvQimeu@1e~g5Z{buRvqryjr#w%t(av@r^n*LXq_PJR>SQkOSczm<|)f8%qk+z=iCWBXnf7aRB@QTwxvOPoX_@T26b zjTvGvf((u}fI1tIhK=I84fD3;S_j=mWQxTrZr@vKj$@)mw? z1@XnGQN^Y2o^e2U$Me5V{$JsY(!W{u-l^bUtJqh9SxIzP#VEwC$7#jDDTk;HsdgxQ%(RLwHwj|nR3@V0qb-kS-; zbX@t;lI!7F$K$U5#evvbEI;|Qtp6{bKYQ-1|1Wm7AJ+eSd6bxTx3DXxnCJ@BNsSJ z<14+NEN(Xen`U%f&kxXu>H=GJ)YL7j64Gwdg1Qb;O$06U8q{i5C|wLj;Bz3_^ay;Q zC<|zwrZGklkZ5ezg;D)j>{%`j>l+dq?qVau8+DLGfQ-GZ*#PPSHM=7soOxDj<35?b zaP%oK*xjbCWNYs>1ND0Q%?o(Zj`I^6Vam;nJ(YtB*oV2Mb8ut%On4s^8A_E4F6i~@ zDDjP`ucHNL%X6cqA=PE-#+1hJ3I%1N;yI$;u~u+847N$tdPmz2dBx$@Ks%3jONF%z zxVN{f^4Fikvv^zKi{60EQc1`KP9iWAas0y#t;~C~-xRT6$A$RL5wL|p8?on{|&cay7B)no;@Ev z*nju&R99EQ0sHbO|Mqr6-h0wz4%<`M&Q|fqn^@n-Su*Zn-+9i95)8GAoRGt0wP&hLFIN1vy#d5T7$NWiuMbOPza;}JL_3F>MhrTImS z>GX)O69l9Au1+*r+!|_imB@xLvV!ATmvw;rQd$=3k@3}zF= zjs+~TC6s|* zeNofSN-ip;y47cIPi0zZ1ENTsYW`MfQ9X_rMufW9$1ZDm2!T19?um4()FcMzG_5u8 zeb9kQ;aXosr7Eq^q&{qFwZ(T_U6CIvBp zk-mwJ%VLTczzLY48Oi2LO@wY%8lNkrt?@8Rnr6xA!O_{_(ZSndx||<Ey%F z;lBR%9|N3z<~2X-LW&?f2Ac(n*V|jg2LKL_Uq9adPf&av{-^q+dq>C0ZyL1NAmm*f z+y7a-FiMu-TtJd?8&VlITpXNTCgeIPb|=~oApcC||9Vfs;qg;J+f(p(s9PwpI*q)w zdBRaS^+rrrS@drA^z7iIT_ic>9LeN^(oH})HPNegIMjhqaA4XJt zLGAN_nID+>D`Dm@ril7C70zK2d8P*qGn}&X2xpw9BbLR_(|C)mpuvuc5wZ>|^7D-vqtO_EwDDg_>IxRtvTEOK)&KJdKaL z|1Sr5kkT~S| z$u4~&-@;^qsE&&azziq8kVu1V_avQt1>97jX7JN8m8XQV!{fb@ZvH}D7jC~iKHM)~ zq`K)*`Ht%w?~{0bLWoEYOy`uLnfYC&qTSC(YG%FC{t~-y-||wte?Cx@t)b@%hjh0K z3M3tRuqzOX-r^+xWRWdM-c9D5YT>giZmEE=7y$aMwNR#!FUIRhsE=Qt=r=NBW${zw zNZiL+@uG+=VLuC4dojebCtX}FYu5j@c zB{#vZei3g>o}eP%zm3J-xE;jtSThqRET9tj+T8$ojUk0T@GC}|)wFjlqkO$nbY@)_ zty@VdNyQc0HY&Dl+qP}nwr$(CZQItn^Zk3D+jBSCyjmBlt+AdldhfH@cl!XHy(Yt` z>m#pwXSp@1w5-qpx3M&on?8}4j(cL)HBz7~hGp+jxwJ9&)FE!j4!^zmd^{bM2p6Y9 z%%;mCe?#R12ZH-QGd*ISv!WPFPqgP-b34Dad^M_tzFUXA)dysb4#bu%P&F=C$@Khn zSJr*{>zD17H=de@4pPd!4fQxilUIpN6K&X%O?tXYm6HL{^fh-OccmE42xijOVN)yU zkE9h>KcIV2p#<=6be1)STwMT5x8WP`dDL(v{@rr5C-6Pv;U?Z?SI60(A%!A9tP)A; zOUL-&ka4Np;Nn^yo=NbmYwO7cHp0@>VM+?blw5t3+?sM^zHY_4RPNcBEz91clw1OD zc$#Pwn-?}ebLArCUaZieRJoj7%yxk?c!6F}I&DS|a86K*A>hS#7qL5&W_q8nfJ^47Eh?i#eUJK{9D>Sr_J zms}e3dYb0YN&H9AQ9`1gNpJW}in@!SXlK7{Ifo&P9Sp`~ZI=5PKwqOj_1#KQ z6BDZ)h}Nx$WR&{mE&Ndy>)g&!RUp^xf(NNdgK!o=xU6ayW4pN;Gv8YSbzP?x(f_Ix z)8WIPOXARO^5;OvAe1mS(*%haTI@+Ms%Q#yAf*srq_4znux%zH%MHI2zy$O*eYM?4y8++QtW@g{fCxskf>L898Z+b{W}U-yfsKA zSg-i^^cBcEe0jVJHHuECFRLj2tVR!DDc&#K=PDYcmS7 zGu=|yM;66WwDDG~|MCsef!&4*SUV*IgSMSD zt$}2+ImaXkEaE-O#oRvYX;M0ssNFhdpfz}EODbiAJ1_dAsxE*+&_qKf?{IvG!f5;@ z#6+ay26pBJt{ZS$paeW>0h;7FhLAeNC!=Ww?%v-v(*|h5{c(Qpr(hCuqf{R9L3=q#fq8Zx?x6z4F5w|4gf3cj5bdYx3NTZTi0-^+) zcOT7D7%q-?!OY7s{6z^oVl}^@8^T$&1Cn+9Zc3>cEm)OC#1KceJBn-UahvjC6^-0H zbgsH8qRsbUuamyTqS}_AozD6mo01U8QzDAU9|NkeYsV!90xAo~Y!-kPz$za)?u$2V z&Iz%J-7@2#4s}c_37D(&X`zQd$buihpjL$U%MP7&*Ny*e{8i`~qRJ83_44mT(jEd%`c+HQu-eODkm!yv_yg8$+ znX=7rf%7nRx)?oQ0YT)dYj@ceKN>&!0h;>PT-6@GV9q#5M!XPLa>k*>1lk-eHlj$k z;z>M{UT>8n%Twi<RFCIf?qg}-?^1kCjxZc&T6?Fck$i*9w~D*}lr74Qjml1h+z zyJ6={DcI4ak^~T2?1wR+Hz&zba~wbCag}s=QWUD$!Ro4nalfWwHK8CGb|*1~nv7D4 z3mVbz$ZQXh`$B1u+GnRszN|a$vO3$6SJ zynv_Db{$=1ZpNNdc{SvU0_pQ%C@25d@cdu&E()`jbQwkc1IGBXp+O+DlFSmAzuI(A zcUon`oMeY@(L!SLsx4{Gj*+)8*w0%y-zODSo(htQS3GLU>1piM8UUIE4nfF^+A{z$-p=nm9hnRn z4wt;GuGE10c)&h%Ir+NZ`ua+jLrDC|w%LW(-`_|JUGNYf18Hd~2x`_dC##kkJ(l;n z^@-le$;8eag)ypw@)5yYd3s%LgWI`V9U?Js5kp94UO-*TsG!NnZRdDtxyrhFcCupI zD3Euv8XoB?eT^V{+{sm5<6}}7d0^$wb6Bi}&7py5-b$(%_ByxomlZ5Bc8{z_FIIf* zh|<>JK2fpuD}QlYVl1bWzd7n`q?EqGhmfY*pu{RS&(Qb{Ic+vdfr>l!)yNg2lkC%o zU3h`*0RAdZsPk8Q1s4a3zn(WXxu_itQE6Chv$E80&RmzOJh_0mOVbJC9d-40WM(}y zDPrv!uSv*n2@Q>0a0g-cr6-2W_>14aNp}gOd1HOB!hC#w=kTTe`zx3W?v96cOm2c5mVQb#36g4l{GT%3H&`vh}A5Ix8igI8-eGQy=+29zzx} zwaI4C+sh;D3PX4+Ua9$~ANo-(3mH=SZXGq&JMq<=AS_8qcSKq^WvAKJ=EoT1W*Y(|B#}pb4ZlCu_zCqZnV|*Rf`# z?uH9OPgi2KPO>8ZCEpjtM14zVcx5NEvD;>M!fw32usC#VFp!BTrsW30QZ9v)Dujul z?(wHc!6&*`swvqk_K749 zTqaj?RaI`iaa#uXGE2I;SCK`w9FD0We&MHSSWEi=MwIMHZFn$q3VyPctl`KW$`e4O0B_l63c)kvyTUE#2ar z!cVFbqF}koBi{9(&Cutpa;*p;9!coieC^bPzn?|BF>kV1bl4NtTiz7!0b_`9`{6CV z+Cde@zbwZ9UzbA?EP$5^6AoIOd%)I+gMyT=!WiHxJGqLB&$Z7Ia-b!>ZN_ROSmfR( zi0yOI0NW+>hQP}e73<y9ISX1@3*vi}R{_x#)q|qSU9D7`!|J_8>WFeHkQf%lYw`Go=bPkseihg3{>?6T zv4aXpR5f{M7%11tAzYPA1m0nf#0alu# z^5KdhY(!{St;#h6E-_1C8B@bA2YYSe&i$f&95nBbE>@Xg?#tw2Rc2-C;pw9mMCJJ| zA<6-9dnxs&8@+mXG-};kkvZO~C{WFq%gU5hOK_$E!jgO=)&~X@sWO{0gVSv$T5j_B2Arq!D{$iuy)6ZKWlj5~5!1Y~0sCc;|SyXVhAw)oN>_3QVdYkxbUV{r5F8 zll_DFe$?1ScxQ|NDX-`*P#m5>drzmBj_(Qw2=-Z#FN@h<>dSzWne4VZTv{Dy+^9?X~N`kuiPIN&S}-Lm?8c~IHl5McTKczbRD|N041 z<5&Sq5lNa)htLI~vL>$pGCY;|Z)xJrcevt7FR!P4 z5ARpwfEM>J#GH^M;Uo10QTOgKBB*2tM`y_=@B|Qxk~eNJm?TQv8*s{0(3c9NnTv`@ zlat^o9uCcGaBDeZ5O1rNIMap9f5gR zM)X;KmQ_L? z2?EX|6cgZEaj2<^{*%|Gia|xTV?;h%a$)yb?DISioE+2_nciB-u^njvE_1aQw-bz$ zl9R@BL?t?Lsj9_Fl{%Z|!p`Dk8&ULy#@);ZN9O3$o~rBrURKybJXVXJf&-sDkDg}J zYevlpRLlN!=#4%l2R~L@(^I~fX*K+l{GCK!_&C}Q-gQ4#p`Zk$_!-s#3xpM8=fAe8 z%CVU7L?;c@L%5>4wg)92-Zpe%KJ-IkTiC`%2^es0lE1TP^AwXy=d+plH@_5Wz>CL zVW@LhSxPTB`snCFq*)mwf^8e^Dk4E2tMuxIIdBURrwp*|=@TV$h-I z?5>11KsA__$bdq!Eg~wBMudGO-ADsF_-VZ@X5>?R&zpx_Bm3RZ3RnU)+2#0#TApkh z0?eaQSWKZWy5|~Ut}(0`tE|SfwDR`!RSnT7SoWxF?-mHELhfl43h;ayNWP*6w9DrF zQA&oAGK@EB{;Kqd)2}b9HMul-`?xwceq7&r0(L*(c+`n6H!vH18#^G2L%RQr*b00K zk-}z$xXYlP8*XAa*;u_jT3bAvU%yX3w?4koEeOq^Yh*zZT{=okz)4Sj#*5iZvfIRp z%3x^VKa+n9_nXF>oy#AM`G2xCQFW)=P8s9Bq*Gl5>rS8FhnJtH106RP)iqVZq8cT$ z)P!{(&sQHl*|?n?+#fl^6XsT6qM~q*$HnjFT7wz^3uzTnE-&xl&Ruu&-EJ*={PWra zP0!C>1YNKPjxMjC{D&_dOST38?~kd6@ZE-oI{^{?+Mz7RDElG4-)cbqhp zM#qf8EF0_NL_4)5ib4vCIXiHABfPaQ+h<`d_f5w-R|DKs77mw@&S}bIuHBpCVbg@~ zt*7nj%UUr;u3+>`IhstwiQg4PrhuupyX&#*j)fqI4IjcdYSy0hqSJM?RzIwmeTsw{ zA{8DEmcIeWgqEGR929j^9!5O2qCV-|HSK*cTgy&>p5?M z#t%+|Ziw3OTm)T-`w#bUgo zRRWdi;id6{-8D<;ve&N51**JuRMu7BT*mgCJwb5nl5#N&o;}ljF&I&Bef%-Vw_wzC zRfVJ@hlF>0P1T|awE?>h+V+~wcVJX|_4_v58ixCAhxBgK;pG+K{e5QGQGFiP;u*I> zzwDv$+%S5}QQX@E)-S6Vn^EguO&+y(z3GzXW1yUh_Dh~7<|Y%?IJIr%5!dJ2B^}Gp z?!g96jvM&9 z{DDra_6i}60zU))e*~$Dtn{q5+5I0uno*VK6flE+6^jPcL!hx4p-YqKHuz1e<4oTh zrg-O)f&70Q>GbdapCc_dTtvAtV4qBi!1hU|O1j0olg9o%jXaJ-9+I;lCEM^#1#fvl z%Xc8JV`H8opSEihCe1y_H~yx#xL2ss*A&Mz2X1)AUZlzJm9V>j>VhtpA9 z(dwV^N~~@-7eU!CxBnkq9@GpvZj>^+>7rPfnqJ)@q!(Fs$27pVmJxRi&)ygwy69#@ ze^HL0hx7i2mme&e_=XC22(uI#iW_|Xe`ILl;!ZVScB@0dzKlvaEpY17?se);zA1vS(*z!AWOVAQ23 zUEx3l3STZjav>HhI#VH^>agWk_w%8TH9BvU+8+3L*w9?iu{I)DY$f;D&RyZqHcQjr zImr*wtuLbkqtaEj{i>vnD=1Y@=(`K7bRU@*7}DJ_ycTjp4?WqhwtrFG;!tD2 zUcu81_hGEY->b=1-INE-tq@IitKVCq0lp<7j@!;aa9P(AG}@y~)Jg?)2)88jUlZO< zskZ#kn7A_1A4Ws1sVsg<={*lNInmqmcFi1V`PSJb>K`+-GUwg+%9+vWwqFLI{)iMd z0nW5DUsZq|iE4LQknd3QUtw|f>WdSPe?)`F))Eb0cYqClBxsE>KS|2L>#cMtv!DAu za%3)Wz`9!8g$#JszQ#6V>6T$VBTMs1fN#aRiapb00Bv(lkNfpD;OTttyXM2KQ^o1( z>>+B|@gpK9olErAM&4h7q*d*+IdtD}qK%ASKNh?NB1|?%T4Y?{V$LU#TWeov2X`0c z0E*uUvg)0IKCKb8-Jd?%u;!6zJ+Ri{5kf(DrXVo8AkgSxirQA;vS<33)$7aEL7WV6 z>>qGvlbomG9xec^Ya|14(6xnMJKlf$fCaqc!v;=TW<~~1+M9cmk}YASAqpL#|D|4{ba; zlJ7CHTSuCfR?`#STfKcS)f2FNfGN|pv8`MKxt`KJ8PZ37f_Kjc|H>?Wx8!k&yMf~h z^LVQ~l!$;)qS<<22;5rw*GTAmKbw#M5YRG-TgNU-f3Au7Br!l|6;{y1+h|~Cg!iNI zH&4-z3&J$6tucJxtren(?RF77G6%9Z5pjv?=M#+MB}RsIZ63+l z>E-R|?$z7g9NdkL4fnR^f8oQ>0`TlTwRM2enhX$gVB3 z0DLg?ki#!@6+ASZet~!*GDCN!nbrBxG zzH}M+(2{x#^sxz&g?MqO?Jt43GYQarw&Ni^q|3_?-TUppyO18ZKRK^)r<#owXc35Eh21Cav0ewf zh=mf}lS?WT)+R4#OfEp^`_^-IBGDl_1~Kr$&pWJd%yYkzitx+R385p9NMj{ffO8V| zb4%eTg<|&&&Ow|J7(#}>qfk6TG?a&xk5okT7irm1o-3m&Rg`W*dJo{$YzaBP9F8ok zWOU)}4lILo>Dg4c0svufRK@QFY;SMlP8ZaZM}l<2o_wcoLQyU2#OWXA$PA+~P|F1y zR;43Fzf*9?^cKrZj>Df+m|0Q{n^&vax2q>?%t0cH`6$BQ*7Z&}x|nR)Qie13G_Gq= zhO_9+tDjc;_T!5^mCh5V;E6|DRp=jDb-Sv%nUV0MQnD4W@68fjlMI|FGGQs3EuFB6 zHh1Z`7}=UUvncZl(e?P5!TwqQ7%=*_@6?9UsprbFRD_ znYExjGSeV#KwnJ{toPT`iVn=EbyyGdPe}{2W~2=vPL;Xr&wao&>CbbSYD|&E`1LLP9if_d~6BCSqa~7rJx}Qe`5PYF48g zvT|ya)6E3e5bxvY7w)C#=^eU$ns3IOHN^Lw}Ao51Qczl0Li=fwlbKy@QB@n(l3 zSg_Jo;~YF@md$&+FIcoGTmkA{Tqdjz)d$cxcT{w|lJu865(^Ihz%f0j-c!csALgJN zdmyMan>MY{$F|{$9gd)0h&z0aIsqag}G2I)bzZWt$K>gtP}Q8&4{%Me!8| z)V~p~HQ?Uq4xd~9g6i$>f7c227`xm)J~@D5S@HUQcmQV>+e{O^kt{?ek#9Jk9?jVj ze=mxww91gU8C}jIewvPV4@g#&FFqx{QuIH{qjlTlRnj$!4~V$>6gbg0OCea^LBt__ zPy`X=x(QewF)|BFZAa>WY*#d?PQmYijViJuUr(s{XgZ-9@MEvgvQ95u zq`D;QJXVR6R2$VVr$gU$6y)!;`DKozdc-Ne*{F+iMrU91!gE}_`fz=Qs#D=pUFbXO z*|rQh;kHOpQBEfwXx{fN4Lfdu&Q#uk)l79G|U;yZBaQ&8L?^ zTTYV?k{`ychexf^O8jmoCTX{7lQ67)M+kVae+h$JE-1qlVw0&47Z4(EsgHLMBm_iE z(iuggZMf8pLa%ME5PX=R-%&9UtoSrj=~hfOcBFUZ9^h;J!ycy6!+{c+VvR`3 z;pBit;{*TVc5{PlOx2uQRr%eYE--*Vs5*yYzRpALdAX|eaKi|@^1M7*`%Ww5IiX?W z>%&QmL|P@(9qQ3LMdJ#5pGx2!hcI$nDPj31TFB*}=!V?bD`NbGQ_d?tQKW1Fp?a8n zG5MZ&c|gcN6#wZF3eQWHbB|PE^CDUf%;%4zkUrw9YU(O2RhGm~K?aIvGBwT@0lZV5 zLC48y22d6J1l^2BiBf8sZ%WMvbmUT}`6O9Vv0C3Ux|q~8h5fe#2oMmp!7l3#GEE#s zg^o#E=Q!KY_-sgh^I`!LI#;V|;jEFp<{KfZy5{ww)^V*>9?wm#Qyj++TT0KYC(!EF zQ}de^;uZB{W{o|BiQcq3Ppt=ehQyDnjFg$2U86)b3xo&XI2ps?QW5qq#kVWl%+GvtZ1f8)ZAlvDGF=D{hAegh1adv_2V)d<&^^Ns7*{9WJ6QnBg zX_(O9G!VtoUNI`+Mb_Jv1+wN`k^!RT_0qbx;dfXTgTF2Gols5hWw1@}M_};D{k~BM zn62>?4H901qxhNZD@u4w5isT6&fN3hmwFd38pXNGVIoR#OvGdb_bRML1Y3=Il1b6+ zZHzQz?;12GTGEON{9#^6$IIp)yQ{_u?F7^quT%X1e+p%~ zvUOx*jbT`yDo4lh)0qgpp8rhw94DRyeb&gHn|C1dCLaO39TR5&@4I_*b6Vdk8?Q;W zvFP<(7t4Tt7F;j*I`FJI(bjl$z#C{2}D)VJ=!(JgM*b;sNU4b|1tg+X@)7wv{9xR%;?- zKgk!Us%$IdP&#WWW(oa2@9)GGvK}Qq*YQQ~j~7sK!FRI3{d8h|hhglC8BGb?*(%HEQ@AO14uNh97O>B;Y?t})2(jv~(B>ZJg=@;u=k z$Wb=(jL>MT=+Cey31TX!7`7zK44asb$6DXg2#9(|6lLr-dg_K zByKy9WZHT%5(F{g&NK!TYl;!3YbHg&!a@)3X8oE}?rd3vmEIOP!^YsLA!qf-P zrpFjndyu>Pkbda95@p{ne3LyA;>?Hw1&c=x7QY&rK&k&cOfubScKb}%#9?s&v(eW_ z-m3XW@4$ni+kbE}bC#Gz%;!t8cy3XpZ(^c3deB?q&(`3A!+Z>F&a#R-oAXi6XH!_!VUZwnoNNVVTgP~3jvRSWg8hM&3tjrR2D^nx)Fj`K53441@wh^EuNMEoG z0T&cmhC4n9O@MQIw$BL|b3RtUa*Jq4pG(ae@|=uC$tVOpCL#CG5?@MjTtv&hi*ys~ z-M^fQchltdF5bJxEMh+V`D|(95}SK8=fOum>R)24rMm_G0w}t(4P;DuS@x)WDu-1e zZ#xlw)VKa&y1;owWY&%Zc_utbA=nt~-hgF42``IkF_k^MfJISGs-b_SxPvK$p*uF! z`fr++Pfhxd)+p&i3XOG-Ws$0D5-uY7#KJ*bOwem!4`U|9}5G-ZZcV+UboU6_oZ zj^JizG4~u+^tVtxlOm?Ra(23l9Q1#+At(75`%-kdX2VpPXk$mXtdWt{nCs+lz>^-2 z^jGXB&FKzFYa_eBTXEKyD%wv3Dls^Dl`#G3{M}nWMuB&yPSFL9*{8Z~b5x9s!~UI5 zE_>w9VF&u9~nMQzG!wyS(b9z@9@E>`i0A)K@xcTZDb zzx3zZu_^Mn%LwzZV?pc>tuZ~~zn}RE`y|Vl3tOId?4V^5&4ZLZSA9$wHuX>rLK%7- z4dI{k5Vk!8T=M`s+WUbsaFBWM(%g0AhNJDnGGR+tbHib6s2djIp?dh_5-mUdI_YAdQbx$qt zTKg=k3qy!MDDZB(j|b|l^TU+D4nqNk)7p1LmF*?}%9}Qa`R6nLQJ4gPnYYbv!&92K zQ@`mVV$1!gE^XP>qNXS$xnWP_#41A61IAPy4HrwBzN;a*4fR#j!ARxgrxK4i&kexj-^Y5iwBqs-X6jYn5q%_yEy7R!G@GZ|}Z;tjc6}Zvm|hiYLe%$9eB&rL7odZ49FO=8S7lu8V+Sxw} zn%t|cLnoQFmI%x=cKpTa%`2(biMIN2G?>I`u3SHq#Y{#s7$i`FU*j+1QCc(TB#k)$ z{!|IlplL=IP7TXrSXyOF3f~QAci#o*OUsMlEG=*WWkya@E^12oN3Na~#Z~3+MiNO+ zLm7sk8Y)KAwN5G~P6aA%NyX`RD~;Ys%WmpUslvv!_2P1rFpdt-wdwqp6}+lw&KoEU zP$q;5Yvv-l)CYXrSH5pb8t@dp=A)cDh1hxesZo#F$X?YIFO{d(AYCRxF_>pul<%Jm zkJ+#XEqmk1W}FI_+ne#S8!O3%+4dU!%aRaE2bL$2R%5BMOFPWcOUzRcN?G6FoGO^< z2+4wzWfnl`PsRl2e&`Wk3128ON4(Cj13^B?Eu6POGDjdheE84;?<2 zA63Lx;($#h|3X@<2Xgp`$Ki^Ogn7h%P3P*|N{0c3n2?W0o3-Ow+GEHNTb&6Cz<5H@ z(`yXnXcI>lCFxCI@IF>PfnMc$K5COISQYOhrsyc`CW5ap;ck`46t1%$uB4M zC8bBdp@;+|WWSv!xQ_|i<|e~P{e!A7w3hzSn*L@0klV!Zq?(%b(5EBSjP^+N(fm8o zyH1YP#w2>-?1U7(eaoJdT;Ci%rr|Hu0Nio$-x~Un-W8><28d8M)w0l~y*~>Hg0i*a zW7jyW`kLPG#AeM5#4@ez`6R7~N|fZrFew=YHlqr2_0T#hJ(~J0Bzs31bf*c9 zoC~k2ua;buDp3fXpWC3q=4;Yzm4zPFvYN_I4ajYp%7w$I70ADgEk-U8#%7EzLlo*Y zKuiM4=R7^No#%x99YAs1&m6`$gneiw(2 z=j2IHuf!rg1m2-;2;|pRU+9XP%q?|d6Khw;1#!*T)odeLt6lP;%fE~zU>AqrSK@ar z+Sl6aZY6#UC?_oC)zyyL=i8^dCQ^S|u4~zvmc!NOtxx>Sg{vM)Gt|1so@+jRrP5UL zfxN1yvW?Hr&$!t-)5Balcm5+x^G=C8++wKwPFz)q3 z!Tn8*?+jE@_R3%;fO1#UgV}No>IXTK$w^Y#Gyt)`U4;jt%z{+*h2F46uT?_Mk|3td zlIQy8S)Q)C6}m6MOsl&|!i>yM&^sKCo``2yB+*|#H9`8u0&y-;+`jHs$>wklkJX}V zH_r94kRG=DCQ|E0ggW!-%IjUxAFiZfWFRKNqlJ^v_T~AWHqA0wtaI{I%QZUTv4e1m zOcEk|91JFiZ|o!Und(;PRjGrXm9GDI6bavA!>~us+3D&gO@y*X)Gg}KmRJ0hK+>TEj}m3~%LPH!$GTi`^*#2j{9mDa zA{eL{g~XTPL%K}?RaAp2@scA1IeC*}TuNSf1;r^;>y2^*UZ6jC4Szsp^q(n=rh*cw zhKVI0v%E+H8n#e!(o{V-KsH^R$#CFd-QK4~5Ig{vc&!N2Dw^!jN=KQ_?n#`)Xn;w) zR!3;q{_mO5c{B*cJkrN>Z4+JGGvh8HMj`Ir4)NfU-$_e{dQ8rjN+sY=kpNjT?3(Zs zpy&zk0f&on4#4GRZ?6EjV)g*D94kl93AK*K_kX`%7(IQZEEl(3#Ygsh)kRP%U#j^j zl~Qc=bjBYjANP0zeIlskc^6|sK_zX~Xte<(dJZT~0huA)hj&%8fRV3)5Vv<9M^{@B zfX#u*etm6abCz(N3Wg9xIlvtHe!$FS(qPyR>+xPCr5iv@89HdHH1XO zHlsyG5|>IxGee;Mg^Mca=i-B>(5Pwc@>BC*NU?V*BzY137yy{|h&bgqMd>>=NPE!B zBLCEvXT^8aF3|zgDp=H;OwCgWWX0%r4kMfJ&~j07)RAteog|^NA5dd-a=+K+@7!?j zw& z5A0qXd`bal)2ehYCHOIGFp+hF0EgS!oD~2T_vOwRz~-n$V7fGs3Kldj6Av=CqL=Ir zWCpH;DE~l$-6(%!9Ut|d&fhq}zsQ1vk)S|nV4i`6BXA`jf^&RlI`p@-cG(NF7FV&c zQhWU*9deT--y+9x7CO_TJ(o^nKmP=Oarh-b5yDg@fq4wKlwa1~LL9~nme=t~c_&6Y z5*+s5>P($Vx-a{D;6IgJ9%EX;0Zeel3)$~6Zwi`0U5y3s*g7QeX|F(tRUcY**iF|i zB9HY>J(MSM7vF%zb^IIC%Ll>O1(O+}3e2HT8%rt;tsR5Lke#2}N6BimP<-~h70+@o7Guy>=)Sb|09evJry+Dr0-9LCc z)aSCusEd;a48@EdkLx#DM-H?of|S8Iy<{aogtIFHaQoTg<^6fN^l-h|5l3%61Na%I z6!?FY08aO|zI-Tqu(#+)^^dpXhT$QOX6z_EX)$k@Ngz z^G9Le8Kj39!qDXqP$R-_2j~^NAQ_7D?7|gy$k!}#CQDQ4>tuj+MC)XJ2LSF>8Ds$T z_eYt+z`Lo`1SsI17`J7o&FV9r^suEoCUw&E_degabeISYWwb;fw@6E=3$O9F5Y@PD zVj}*XiP|r$nz5@n(}j5U!}`Y|fy0r5(7qvMN9uoDrH!oqphWzDuWs(C1o;Bp>ia8xbOXdX8Le~01OU!)VDK5i>6bta3 zM9o4IQi~s}&I|UBlMz67phc(rt3kcXlIOy(uL+4h&>Sbus5mR>#U>$4gLDkQj)|dF zi~Q{q<4Ohj%1;fumv{a|N_neZI6d0yVTeTp2_Z@liFo~it41dSuF`N7zLw3#Z740k zZe-W8#E=nD0oux;Z+^lA2R%@sL3MQ{&*L|C2_((ROG(swZ3l~(uiJM(8H$TxDwM(s z#a7@Sxi~CALZpAl6hjLiyuy>&{r!&(ri30*AD1(d!yW9y5P^s)5hv0E<$*2XUou%B zQM`z`t7=RMPgd8|G+uZcxFb-kMM&l(tID5U0^MZbq6go;anr=@(8meo3tCRTaNnxKF6^`Q@~k4GoQtE&X798&AW8v#@Jw~jL3$4c<4Ts2@&(KKG%ouqaKGRX zS^phJLEaiwSa1nn)|K-#ugzHDiWc}*Y#4c*%k((n7}wqsC_xVTf;t4|j;e?>b_Q=z zl1PgDnrpEBQ`h1;6?g@v3J5r0@2ijnzKW+Z%UqJ4`CzbqCGQ;d9CnNEWoy;b(xp;fwl{^64?yI(TG0$D4h8Jg8UOBKgm4_QYWiH*j@(A zdPkiuC4_kgq@6*z1vb|zeD{+4*32kItFs`RQI4h>=sqRT=XFdIKb%%_WSI6b7%zqQ z9Agw28PVjH{f0k1MQl^DhM@at18LJto7joEbVPeLcs^&UV6%G*tb06W&tn^0h{E5J zY7Xg#PIrsR#H(ewA-GV$d9y!l5fmoS&LR-4RUN3!;$8c$mZ0DXZG(45%Xp@gppWo_ z&$c+RkgmUtQCr!&NNAACe91WUu}BZ8Lh{Vq%Snb&KnCN{SW%oJ=8nX6VMENCx=CMdbYADaK0xm0QR7R)F4Ul; zoI`3U%*hTlykWn}VMHe@vPXbP;=J1`t~Sqxf>x~NXCf%E8`ygE{ZqA^SC+`GK=b%- z>tu@bSmZr>w;*%<0#HUFizlK|Uf_1uZm6pAduot@m9Q>Mpb15nmKgzF1iIFK3z}m0 zqEj91IcDHpaP-PR1uZ+kDY&%3e*&^E|LJ1VV`xGF-{r$T>z#rR=--%#{na&1LPK$H z`8wC7t^MnVRVWymN;AK`17Igg+je>#7UK;Dt7f?jh8oZ2F}>B~0g^{OSV-+O1d>|PM&O}n`WwGZU7VPvTw)Vi?VM14smtvK zde6B=oA#<5%zb5~m%k>e9U(~KiDyEPA?9{&XH_-4fB*COBR0|H<`uNm;J6)v5v!ow zqq8X6ZYVF^LD@dS?G^~4qEvrf36(~DJ6+&S5vIG_3CB6l{I-F z6jyf3V{0}rbw^%+iu2>V(dIHxrFHN`*ct0Sm5_`|E;-Z47ylIB$_Z#9^MIh{Yy1GO z(Ln0T(}1CCxt<-GSc$;N$0uF9^jI}d4rzQe@T-F9Qvy3W)nh8S;H%tA?Z%C(<>5l@ z0?+B7NKEiGof&Mx{95S>Q9l-`Qv+L8=kYz2v44=gYQ3r4GdC5sFll)OCP~O;kX~-C zp?iLIz(6(*NQBgMn@V2~>j3Z4_^0SlLJ%X_L_4!_%BAUros@+4n}XVerj;|J$`#5> z#PC5HExITZu}69z{L2On8!WK*6z8N1IhbMSwjU7OTI_8qw9{(2W3^Gq#-&Bzkl4H` zY=kh;#9Ju}RbqQa(~BwDL7-8L1WA-3dOdAGP{^{G$QHJzf~ux*?QCfv`R3F_k__md3>Q-RK6@p$^YX!TM?`^98d=R0 z&OBkSdE-F#e=(SOYisxzkc?7g*D#;ug9Msa*2YZ}qZE=4g~lFF&3iO8J@G~RVPNwQ zLHxIfi#4J0bTB5_C3x*Hbf>FP1l<-uTEin9ln{hUm3e14 z)i0p4Rza6N5lMgG9HBupnEshr|97%U1MLtyyi=1 zJEJEhI3EW*8SSKiGBKXet)Puju>r$96A#L@2b^CN@CkmTrqs)&pr% zCUygV?#oi{95pd%25tP(W)>~eoS5ny+Xm7kb1Y+e5lDE?JO|vZ!C4Pvb!ivZGV@$# z1t2^4kU|1DjBigm&=0+M^{-v2gn*} zF^N1X*}06VWYa}gE}}AGUI0c&D%m6n1d~MQ#t>+<4ulBgTMm9&KLbF+oG!@cu*(4z zqGB~mfW%W>XuKwfMQcZPC1+g7W3 z27&R5cWy?%L>S6Wt7rnxujFK+M4JUz{LAz~pU4^aAP7Z$Mk4sGOHLs!*CYNU)f?+? zhQt>HJ}Me``9z{=cSch~Wc|T`?UsHmpc=?f`kkAC^pkm33ZxQ2vk(?(agu`uYo)8e;2*j$hk{e=0AaT0G3Lx?Aw&7f2BC-9|^1U%uP z;${4>R1*6{&fzQKd{znTdZ5;?WZ+NOcrgyxkDOmtUW>~Gu3fPQW}HOwx#Bysw)PR5 z@R(s-qUQ8s>53TjK)N+Os&Vp7ghsGn0aXnA$wHe%0$)JPoMR``Wt6HX7IAMkZ*6Q~ zYw#9XYFQvvqb)+X zoS!UKI4O~FjI)+gL7`d~jrQ(>*FJ%2Cly@h66HXygkQBT2y(cn1w*96@V*hl8fMHR zRF(qXOyTm040|4xw1S^3RthXxNd=@xMmEWVVQe+L>LLe6r?sJ6!cV$D7Gf|=55>LH z-x4UdQMX3Te)V#9Mg5f=KUoA4zXjjeEx@=;TFljADaXl@mGu9yxkWJpeC=+s!_Lnl!k;DrzOG|a4aY@DYk+*osYgt^ z4M1HT$a63yy`|w4@5jbK8XMGFK-O{Q8px{KhBUl!DyPvH$U3>3#dAM|(SC^On4Oil z4tye~p=47SSxOTm?X)CQ)s&#yfxUw;$iA7D^%EH$9pr$_`+Vy#53x0`@7r+u-rVo| zHXOezJ-0MNzNh}BRv-z!8`8t+^`Pn?zR|E62 z`L3@9=4bO>Uk%L9=D%L$;+nF>Tk>Gv@Tf02>0gKs`?5{{LcG{l1oLzGv9E}mpUabd z#nt>=zU<3Z^9%82uhQmZ!Tjw0?90I1sz(y?-*^*!T zl3QpUzjhbIZF#m=xMLTDj1@iGOE!0-HC?ir>-e@e193I)_9d&iE${XWuCB0(4w!Y4 z<*NSe7Mv}6xK}v1r#ht7Jlu09d}}`L6`mCa%vF8dvzxm;FZX2{xlO&?H$}=6%q8S~ zBR}^oLAeaf+xK)YpIC*fyStiO@O8J!=Pf(CXEuFH-tL>gTH)?)y4Si51aNSA=QsptC^!K~Z#E&0B? z(5?mSlGR+-`(3xcY4`Vx!R40x-`yq8J4!b(U)`n$d{IIHh?n8!P5HprEnVptwVQr3 zUhpfz*nr>MiXVJVqrHYF{4#aIjd{YarlzTIg)akh%f9d{!MTjz{4%`Zm&xg0h(G*N z$@0tah_7;qFI~;g=M%pQLHdkd@k<5Z6P86HD zov+|%v>ePjg0!mRd0{oT|p7-?R&QLj`CPA9PcmaeF@KpC|Wt`f5dI^v{!q+E7a(&zrN)KMhvD~cuUIKlyp`C>k0*Ln!#II6Q>ehr#{YV@HVKN z(+u8h&C;}-Mj5=BLOZL#+o%LjGk70$54zuFs`Pw|t}G?+W-9iq0&k;QKF#1QE%#Fc zuPyzvGQ7)*0yTrTv~ExZyqOw8C7rERRA@zbo6!dhmO3vrN~N8>GGSn{x=h)o@Xi+q zOF_=c!29=v$H}~w{DKpL#)5x?&u;|Y!z$l`47?t{4v#02#jpGz@I}sx*mP!G_pq$A zWMk=+m9}L{h%bohZ#{S)9UL4SEX9Wj^#gvzVhvI09JBC7ES_-16)Av0R)!cS-On1Z zYIytKHi35>FdF7u$cvpl%Q%=qzzsB1K%=(s^lVf5@URg+D84NSSa7}w$5q;6H>@oU zW^+o?s@uU9rS*{+RGkvZNg}XhY{;%n^d=e%sJkac-@^)cg<{Lcr_bsY-I|`^$LZ-i zeTM8jROB}HjDlJ-cozCi;_-^&TqV3;M8sR;`|S$}eQONwjmE%PR9X6K4Da>= zjyA$$b-(3wW##a0EAnW=Q&+UyG=ldFDxJ{?-Y=+%Mk9E?pn@8W;QfMXYczuQ3o5fw z0q@r0l{O;~jp@S|61dbDAHI+Xrgh={a!PVEgZIm+&e06sFQ-sP1-xHKlvB}QPz z4|i$|?^ffUTwBCyaZhW&yPW{2H9>BU4{OHml)$w~>`vqRZJi*VX0Wal#8ZsnsepG~ z?@CdCc_a7A#`tiXZk9FTXJdKu*8MGu$fP!=F}$m~yx8Hk>+(|ccv%8(Q{R`2%S%=< zwIRF};(P_X=0TYnq88rfI*}#tHq$@kop#i{;rV%ovMQ&Yt^FG7`-<=u3-#yW-OiG3 z25(buqr!RHj<-?K*=Py8P2G+P@NUQLXyx^7>VH&#cRT(^8^K%Wh_nRWbsdpbzAv`t zkyMybLwK9<4>#_b6e4L^5|>%@Omg5w7o|6H#$s}|mLJk~Jdjc+qZNFLw&P8d_JaEt zGI`D8OC*ccPC{1G1*xdj-1&sOcH26_OwGKFF|1^48U+0MxhA?dY)w4s#y;a-W_XO% z%{!*AI(}|!C!>ZQACsyVEI#KTCio1j?a(__@MIekG2=<#xw+YM^LFt(9?^06a7)L2 z`}Fw4Ia&3?R*nr=v&2%XH9t6@!Lp{oy6M<1uIYQ`csy1zRpknlulaeV@$#AH&UbF? zup*@fYGgv4tx+AS+_>nNu*BUl4HzmLd(&`{97M&jGkETe8lc+t*4)K4HTK*OkFTg7 zsLP_#3jE3sNoYMq;7$h>Bh)((QpcQ8(~s6{sI_2MKDy~RirRE+`tj$G){g#(yrLgV z$JQPyNmxIunYU&-VQd+QChoQN4!wAJZmHPHzucOuv1uY_CvYj&Xl~wSZcm{#N;Ad2 zjj3$R47z7bjXh?u^e50oRXS8SV`1iy*|ezW;iz{2^(v@eR%_(;UAE@x{R=-}Rfikt zTG|Pj=#N)g@bdjuWB*kkCJl0={?c=jV1QNcVi_M;h#(TT<#8~OHEOve6LtjW3OVf>tt z1nD=ch7@d97}$6S#EUs@OrsD3XL-&gjV0u_!RYcR=5uuuC4#Vz3Na8%)W0)P33|9D zLsa_SWp=<$ph?Vu(|Zcia|7?K1s~K;pe_iZ*#vGV8o_Mruyz9VQ3<6JsGQ1XfeMPt z=pG()58U{K{-Z1(SDZk7m_q3Ua$w&=yuz{xRL3nep1{opFqBUK5bc7-Qzn1pqAolD zd2n(~A%T&x57CfNonz0xa_P>D3%LgO@QDlqKBmE}2AC`vRTBSk19w&I9h0unc$&;v zF^P;haQo=b{E^P1fDKliK$Qxxd;(2O%kBgUHfBryZ`{Vb;shL9v(tOl=-dqWZ5f@* zC(y)s!s)%C7e#SqO@JrspimQUioyh%xK*q6UZAq*O|Z#SU>A0P-g{odSAsHT9{(P39L$mR*Ju0S0=W$-DSe@ z$};ih0r}e%j#rk6H;>TYu5er#q3;OCbrWbFvcG&PYYE376F=_uGa~W9chxfS<}v)+ z6^>Vyi8l}G->z`H1{rm|CYQ*T%S1{$sr6;c^~vbQZp+(|EmsyPx8ujWJ=t<)k@AKe z^H-M3)<>Zm^VDB$4(m@~ZCB#$N;YcaAbz>_WPK+HgK8~9-vU;W8CF1X)0g_NCnu+WRRzj8r>b=4|n z0y7@+xKdqhe8m>T`7X`lXlJs)G&ViNX%tu4EJ_m|yFOonc|`C!BBj6dd@<%%EM^`V zEgbT+hI-w$eVYW;$>YrgG#RDl7RWXyZ#Agv6VsJlusZz7UG9Y^bX?xgaxDH#A|L0TT|#gI|X%?oFZgq;~&2d#7tO;4L9J8Cspiz!ti! zCP@`wH`7o*Mdd3wpRr)u*-b3`m?YEc-m{3Dt1I107B? z?5XD+(Wtx95tR=?kB4Tr-K6|>gY#QluS7oC^|j0#5n+9Cu8 zqluh#BPzr-kG&^&#?7Db86g?Z7S(yHr52Ko_!YAUN+{A`ZK!_|N%Z~2t3UPB|G{Lz zVq&{h6UdGeS|d{0^jW)S@5CPJC`St{@(puUD;cv6c0_!+uV6Dt)U#6? zC4L|~en_Y{_d_3w@B3G3Id~w5KS@JvyRFu78vGC}_6a3_IezsL;s;T-7dCJhsxD$# zWvdIbiX5XdjbeV~d(0!(GauMDKrn;GFqPGDvNO>GcNcUXlwsZXorL z0LHA1q5AKgE`Hs0{@81^c6M^9*41ijK=6UbB=rM<>a6!~InL?bIXTU68o%z&q>RL% z*Yo&TbTy>v&g!K;9K9L8?nvHCLXX8l($MR~*kMQY(Q&@qYqd@RuZ4_xI1Lsq8)MSw z=a?O}@oFEu1cR7ac;&|&iV1hg#SDxmB8izG3!b>BNj%Q*1Zm9HIq3W`WK{D}nfeFjhJ0v}iAgq)*&%^{$*hH0n03>+rzDSfz^6XL zbFo97;aMB#LM)xPx++Ag^^4-B%BTV2&XC6AnJ?K`CNX=WOE5rb1R(5yKAQB=vR%*> zB+ez3ig{Bq?=BC61tcuhFCn84#d`UBaKcNwvXv~H&bpdE&~J>*B4*S}Yp7Wa6|fZ- z*W6g-(-!E->kV41PTAPDehoAmkTdS<;Qh4ceZ`r^dhqMmmyGbpRzNpo7>k`SuY8=h zxoUO!k<6UTSg@2(zuXy02~~PIyRFt~NXAr?T)p7qn2MP?kFv0M*VLCJ38f#n4NUQv zn2Cs9hs+~%s?NK<2!BdOO6ZqNfZ9UQOcs+@G^A4&cQp#0D|$);9 z;+g;^eGL&B>aO|j42dx#8>yHSv-S#zF3BK7T=!3cLH7Y9vwaYE_GYVuQ&BN zIFdtCLJwOW+NQ{;+kz$)>)C3((3!#WeeN4pAD9ApqPT44ksqYbAs#{#CKi7L7EJu=UjO z*+HZk^HA`BwLq?S$t*re1Uu7XzVHJkoL44)59$e@WC85J8XNj8vOVW=h2TTLIk>CA z3Za14-mo~8i#3x~PGh6G}Jf8m<{GX|0np4NLMZ z4bWjiAIHj!N^Z+8dCiR+EV^#rHm}d1G<{HYLpK>xw(X^p`KY?Rlh9~TmAoj|y5$Hr zgI4Q>9}Br}PN=gM_Jm~;N~umo_8?p)BL+HP>_Ru6vXI68IMcc#1JTj%I~_&b0PCN0 zd+Muh#O7s>)k@?ZQ}wM?l!g0NOHqb|S!f+RdeT+?N4 zvbMGHJluuD_g(+6zvnP3<}@1TYwMb+35xN7h1*J@jXAyg_C|6fV0`!&Uc!W$q8MTv z`=fN6_ZmB0uPf~%naSdxPHyT;CHX6nKb@!h&r!ffJ-p_69v_367y9VwvD~jamsUdR zF6O~rmz+-QS}Ac&^1`%vBJ;QOeqP!-K08%}@8iO{P)a}W|A7?I;fTz3sB0cL4>F@y zDcx2?FH5dn;)onSv;w7sxq^-MM72g_vcgObhq_kx=W(QnS3WIEw32=}@$qgg;^WE7 zQ!)wY6qTK7@b^k)D&0CB_*X1GICzBGnh&Ov9nDj90zYIO=xr~fqZzbX1`_6j+QrPa z2z6In`VpMwD;DGF_IapRO|8?V9|4^1YfxZ=O4i(tDWTE2T+l+6rlTnBz7ez-$rXS|05~jhO>5<8(-Gm(|>iw`X8SD%%(m&`~8zLso4E;VMcB3^-l9~H3V%$SYFtkrtDFg((} z!xqo6t_daY&r%x`)=xnaHt6-7+rsByu;?X%#hq#5d#sn*raIa-)!QRlk{R|qDyibJ zb3y|p%`Z@4FZL~E^d<37 zYH$rSTKs!%GL5FaVyDn&tJUus-+FLN&3)85tbL7r9CgX5Hc{E-Ze+v)qpH>pN9hh) z=?c1ka`x`z!|UT$&&#Y_J3Hhl9bYOc0@gqwdCYL)_#8xCt+*qUjPPT1SP;RCRErtZ zLD?T#Q34AVs-D?LHcq6*e?2Y3EUR~<<4c^H5(KsS;ef!Gt*=wXMXP`KxO>n&==KMX zjvjyaJzOE6k@%oR{||U!8dvra-(k={6p6-p zP@@7!qJUFmS%wCnp<#&dkSPuWQ>SOHdm&jQKqLjpsR)f=R(u^g=Fwr+(o2Rkidg9J zFj&CA!;la6i9gW>cynyk{D>oNo)WY>sxByZ*J8aIpz#kq0Q(2u(M|0jy@KRGh+z6Lzd zWc%#h3AtvmJt+G`NFJ$;Q}{LJ(ISIb(U5S&2eU>VQAa{C@krgNqIMCgQa#*OLjkpy zgPmW?Ic;$gl1>K%Z7O;EBu>Ik#J%2CpLBfE>BLH$mU5vGI^rJbbZj-kC-+*v!KK=! zk^c^Duk8V8U-jGj`25ljJ@w>_d*;!cNvZ&E56EvV<9E|mceeTvz{8Q+@b-7zOx-xy zCaEs6Js|JX7y2czRO(GD@8r{#)DJW`ndhBJ+0&lKu6kh-1ntbbU$dXK!A7g5VD5^! zANn2}<+`*poiFSJ@}IcX(28@zRa7s}sGO;;dh<}0L7rJuSo6#`zyI1w|Cu&#E22qb ziT;zS{cFWSIs<3`%htU(WNvOz**%`wSo`T%y?X6-*ik)pEE?O}Avdp9Zic_Ne!oXL z9oV5Kh5cz|uO54|IH)*KD{LP%!kV1AB3md$o#Iq#FX4G56_=uCe5F|2 z(F@n}*f^ju>u3Nv2=We=VC*b-(iyR-AMWiF?dDclUq@Y&AgJqW!2$NF-+f5_RsHV~ zatL4!01XJ3V0f6D&uEb;r=*p~&sex{A}-Uk0bQa*je#R(uyDd-NTy+T-~$bU4`|uc z$YZ-2v;dzC_UVq@=uYEc)mGxqh)LSbE^>DHp8WRLwyp*9*Y-gDAvm(|e{B!`+IFV% z*Y@wfw_B}WlvJEu0==%u6eI$ClNJ(o#Eqh|idpj+JvD z0`sf0)6mkIsGcxey$Q{>279QiY@-!IMr#E|F&224!~{%gl9icUnP#JGB~haRgAHuD z75Cfh+BlzU*mUoXkqQsn8Tal9LMIbH^yR`BP0=?~@z~%_XZUEax|$Rox{2$(_2)nT zxoe&~rm9`g5Bi};<|sl;!2gbigpPP3b1+!7b9&xLMn_yr_QpIMvq-`}Qq^>i3gJ(I z9fJ~Vy&W@JhlXBsaJ6Xr~IVL|D->ikU#`X*v>WU=%`{{`T=NcL*e{ z=tyH`?Nn?*w)VZbUKIycpe<$2zCIIs#$Pp6<_Rrn!Ujg%JJvu! zZaF#JPhW)6FTCV2zE|_fy>!ezsN=bac`^!^m~pPquhq(;MV!Hlnd0&}@fZz|65?D4 zi(?*RCJKo{o_5ImfBxtHO`r`K7et}bd$=NGc3c9=pc=PUq_=_bX?2@-6wlFt0Xn`A z2@`ubx1XbFOg)&@F`3i9@mL=u<4maq<6ZDRyy|xkyGNw+J-IsU9&``(h#z{|s%J!- z7*tO*Z294s&m$_q|9ccO3Veg^Pf5CvDS?Iw4G6^|a$0qC!Abvt>K}M1#eUKtV?;)e zDMi^lwUeGNl%z>xyb&h!ii69Jk_&mr1jptk(V&FgaUD%?SP5h6>5qAik4#DCR^6UItGBh3@mgjMF8sMfMvoRo{yH**mFt-WpD;)!YBJ!GR9(6#5 zj+-8Oj=8>M8kW35`2MgC27O|4L6o|8^|C6?G96AkAsHLW{fzg4TFR=i3wfgM4*_|) zN_1z}ZZ|sbioR5|u(|Jgcatj``=BP?HyLHcelBuF>=P!(UBqVUdCXHop(BZA4D>4+ zX_7HXwMp+?l7TxB8-~L1WoE&=D`xtdQ6GO8F(E%hu{v>MCVJSSw`02K;DbE{iz|&7 z!JS-FQ2`Q?LgP$<2j_jvs5fUJl{~Jy4b-rr=X|W_(+Lj+`+LH|G58BSrQ^$M8hhX% z1%$;9;O<3F`DsF98cN1IxF!;yY`|d-k(vxsSq9aCMjx!N#u5V;EE(Q>bAK8ewGu1@ zaEQQNL@~Sac_LD0mcJN->!Eug1LnZ>178uy2@cPHpUFFBdz&hINZ1B zEHGw9H_%tBzBE&=#I-D^kyyxbpwJTD1NS`|F7gZqH1wr9Ffg{ln-LW{o`w>kh(CC1 zCu+BuggZfji-K65+uJ7*B4NxXsC9l{vK)`Phbgvl$sEcY)9Wsh!9=iFT?#Ce7;pk% zCive+-NW9&LFeuBm(P#SpTB-{@%((x*{8$qk=-Y=+MuuSLkUqwOr+7?$cPU22_^3X ze-zVrfy-ENU1$}*{`7-p*LT!6duko2x=LB-v2eWTl2>YhG9r&=h=K7^n+%>RazVyM zyqxeP^lE%LnhOf%62U(^8f4^m_qyavpO87dWJDyfHuqYu7!x~{B9@(*&lESPxIAr& z16_N#FxN|FGvLs?e-o0|{E9)L%l^?mIXpN#*hdck>d<;8s%sRmN#UQ8Kg5iArOTie zT(5z;rDY;IeA1CK)`?>NH#U}g`z741LU1IOA_=4+BidQRv!?>$jhM}b=lHUsgOX9w zC}uv6czOfc__7J35<=L3g;B>0r+S2^lWWIKV_3FC3BJ-ZAifkVn2?xFX>9#t%#uBS z^RnA&-M{~fo8SmoBa7x~yjNxs{`>p))kS+|D4l++J*a(=_1#qrwY6jn$W?zxc8y^h zWS9jRaXG_AhcLY(v-VC$YG*A*@m!yW#Xh0w5h&31x{9xJk3-psG$&D^0F8V-sSc=b z_N>f5sS#39c(8B{QT3zvfQ#(jqDCmfbnS-r-iLVtTX-LBqE=>t3X{wuG>B$&#B97` zNGO@{Iaea8+K6k4+D>D-H^GVNG77chiUIUJ8BaG`$0PXd`5ebf(c5wJ7QRGC`%TVmp-_-F(P2WSLwYYP1n!7Sh<~hKEggXK-wE zT6>%cHN2r8=5Ww(p*A@MBb|j-_heAtof@LB0$bFumZ4Z5{VjchoJ)@!Lxbs6dz|PYv z?t3XOr2}MA*=t`r_3F$&7>usHJ5b!7`d3W#8uMgoTXs-@Ms$3sM&Ogm zJ{?~4F>cbSQ)SqnM=`%*#%%#66k-n2u@<`#4JXtOl9=t2Ypn>$c!JnKSQAhNjf7ej zD#@JDP|JqbjLi9!S%+ttjdvmmg|;baJBK2>bTUy~h^Bzr_>(7{Y21}o3K-XOGmaph zkNu_Lh>NUK3m7Q6WgNRUT)>H55@DAK&d0#6Y7NF2_XOG1Oq%g&1l5c-7VbghVP(KD zYD!8v21|gAgbl!hSFMQ&x^^+4GVX3S)J8P(pcv-3x1W)uv8xIAO=W}AwAPc9Yv=lcLeO8C#St2}z^TPD%-9xesu;F@zL&4Q){#I#F?G7}N>`^aW2< zzs`5yu`OdB0PhIK+>AaX>qqZoU|=>(+upSpAO;)gxlv+hKSld2XuER}Ci`T@ufYo& zz4F|YIM&4&VmBbml*#9k>cM~s0)^qv+SAKP#E~szMWWc}n3C#Y_n_M!I_Q&|tDy)v z3~hDDFFGJyol3OB3cJxG=886k7q!D@$H3SV1sLK=wiiS1_DRUKX$W%> zpzxYv%eQKh-N2RhcW&p0Ww! zAo1M9-(YkHHSj%1v7jXb!L(`5qhdDVG%lC;D;Weg1PL(PAN8g&ozReeNMnz*C$Al& z`!~VEJvAYt3L%0aQoPUc2nfXLtjmriWXRYad{jJb|D(gv=(Ifrjv;duj%lK{kQy^# zH3Rmlm}$UcXf9S~PH^HzbAvkA2sqdF-Us(5C0pqGbHqP(Nr@fZam{wlrO{(~JY+f; z-zEeaIEmu}r+M{E6sg{wxIP~`G9FbVI{yoz4-d^ zJ-0f^fOOL;?Guj^s(m>4bx2}gT<#5YW;N}8*Xcw_JY~Z)XHv}OhVN9XihdNS zlB*FmAs&F{N}Hhe3;PeaWkVPh8f4_?)KpPe$t>vPPg=qIePOBXn_LirS-%R^mQDD< zK!L-I(`1T7(ou44K9kO^@X^AYPtEcU@T%tKG0qdS{NN(jAnJeJ`0 z(@bb>2l*6C0Uci|B(dQ>OlnS;st3VpQ z{x|R}6q+Rf%(045gk2HJb3V6u-at`p1U)LqH46faYBxqIDCvb6T!0P42hc7fAw$x4 zg+yoY!7gMGLnca*A5d}Tc}lV8j3i3U^EhbXUHSO=&m15`Efj?qD~qp&%XQKWj^voj;E+! zCaKrcoL$u=K@?(@9crK-fH(oFnJ)QRu)=8IjfXAlBej`~f=be=5lrX_Oa>>xLK!b0 z(j9&Jbk7hv{UV@K^te?5A4%)X=xB0F2+dkSS`3YpC;E0D8d(4;c||ePY7WIB#xY%h z7E8vU{xmT2iMA+*Q}u6{lhsIi#;wMs-44eTQ8^pJh#4^x!#p*vJt$$FafMMQHH0HK z)Na#o_aY65*tjb|S;OP*-0@3p;jx2kIVOdr@D-mhbXjZ~MWT1rA2CS}hh1_iQw6La zQtyhzl7%u@v_Orw5B$8bn2KbCtdw+34HN1IU2@JCsW*N0v>N{L@Ms0#m2X&B$Ico?^ zjubhB-2{nJZ$|1WjvzSkGZ&g}ca4u$H_*=JLMLB9HUsCOlg+y7IXyv}54VCzb`e3_ z#I4xpIN#)=V_daWSK$xobjDPSsmGpxnD2-anZO<$f*yK=dA_Uy3c0Oa@X*r2x8e(t zK<_!*TmoSP3NcrKTL1;S?{wrMVo#JDO*+w&d+&d1^9bXT)S+wdlXhgHvDEJL41)BW zGlo0e{{7c`s{mjowQUg8;(m4WKXhXm`#nv}I*x^BTVos?92`7)@BsdQaBz_S|3UxZ z!B_nU2M-@Vc--$lIQr_K|KQ=n2VaqcZ2?gCON6BHR|gx9m7m-nf`3H^+6Yp%B1}r=O zM~8>G^Z)SZ!K1tLe;Yr%${}LRvg9VyO{X)bALne&?3^q678k|KZU=KY#x}?msxVJO8)w z+u0#M1bjpT^2~J&Pqm|vL`nPSh9#MpN@V`D@xEhvb6s}#bE!g2IKmV`0lb4s6WSXg zjbohF0z1GbZ%q|3s7;}soTa6kT01)}>}3EMPckhAWWF%}eof~r{le)1+bJ5Be*6<# z;9J{DNFLLvk^qHJ-JUytw`|z$Z@*)%BJE$9)~wIC=&Mg+HW`prY9OeI`Xv(MB)3DP&=)?yI$GI&VVfRX>Q-IfQ*4TSk?&}_;;jvZFd_nG^Z`r+l!UAC} z757djuem%!2itqOSuafthLs_DJ5kI!QG#_#@R^xbS_*AI+@Wx!H)%#tTN%UAYvmEM zt5-wU7&AITjNuFxHtAD7aY46aH!HJ0*pmx^&sJO8Q!~NIb)wk6qEbo7h;%(O+Z__E za*SF~q#)M5#E^Lq=3!|L#`jN>Ab?mLt03P6(q!yFg`lK8bu@P1pQhs3AUBxmbNN8n zk9nN!%T)d_&X+BlWTY6K4_XY!3o;-_822lTi-&dIaPwV35+TQ1$vUc}9%5;xK3iIY zhMwwM=U?JsI)tg4AZOr5Q}nJe?y1-SH2L9}37gEiY*vu%3zJV)dGzowI}FAdl%Qii zv6X4jBBbDVR7JedVkB9RBd*2K>dC8RkTjju$ZctD6}7FQw;g9b4M^|W#Mh3qIu+Kl ztfRzBY4O&n@iytPonQ@3UY9DbPnU0=GTV6g_;bb+ zIUo;Pg#10>aWWr}!xkYPzYdQllEtt5An*km{RiZc&X78xexS&&ZQuVEUnp)b2v~5w z2*+YT`sxvnF9pcr38SVJ~M(fbbn%#!(ts5OfxOg#bg;Ab z_8?KrN2QCsGH$2O%}^aXOb3VQ?Kq9$$)1^_X#?&jIVFR>Nh~%$V*y>98#H~0l)`mb zF%KnTZ0@Pfd2}(0nV9jwL(C<{x88aF5EygUG3KTq>#qSBCRKQuSvV!dm^W{;kmD=h z1PaJuN{5^F< zm@5b7m_9V{oMF98uvI(00%`s>p|e%{go@rSoQ;pOu2#1JvPmpIEYDB8LysJbR zEurA!fsNP*_?QN*Vve!QAjW^6=5q?B)nSm!F|;>J&ak_S86&#goO>()$NMM>7F`1I z9hwb<`=~Uf-I&KQ8*AygnAHw$Ka*C`RAWF%2OQ-cZd;H5l+S*sbsap^Kqz?koll`> zOu%Du&*7B_5hLM(APK@=cJrVTj|u6A$do7`_PVLG3_(ZFb!N8AN*zO1m%?!Qgm|J$ z{)^%^)xv3K6CP)hA9}fWu%5f76iEt9X#zRKzp8w3pxn}kevIK0HE465`LG&q@XriW za*<2Mk?RT-j9tqgK_D;FnS4 zdfB8;Gxw*t8%YPSMEfg(?Z#(LqbnAV@(mKfioGhrlmBo!X5A!A3qRnk2NNLge+9~x z9=(Wr#AKQx+Htb1070I0nh2Ob-0+IoiIebH{47{(pQx(=3pr$hXG^Of*z>wWeh$$$ zUb=C&x>g-#X^5He_$-z{(28$+{GGZ9JN1+Y|LxAyf_Bx z53^mFUVdT=yvSc6J=Dqrs_S#P&Wxpr&04uCb(X56RWUH$4>qq*UY+cwz+&{pUMpvj zRo76e#F#^IS+Ar>h1z8-2;u4kMK%tls5?~BFq`O zhb(QEt6pQ(4OokYw0m(9cEzl{vckhD1i87oBOT1)$TJfHkCGJ^0os%=z|Kz2m0$;M zw04O%!4)J+4p>LZpzVGcvnc3{==d_=(~j`}!ASq$@WFi4&iW~+>qhH5=5yLf{eu-_ zXe-XTyDprV(dsE1#ZXCeHDhyq5p`2Q&dn5v&`axMD~UH?k_C&5pFX7Bg!F85JcF|x zYL_k~zh$zT}opg;673@s$3%?e!=Q2&8c80w01 z;wBjp;~Ddk00J$#(=KTX$>YoRO2)vFRPd>?ZJq?uj{?@QBMHY6Xdk{t26_ecqF($v z<>Eh=axsqrI)5uJE1&?{YKVz(gg*lRQZo$kOpF6G@! z;v}~u-K1Fpa_c}%CGTkU1M>&qp6{9Ncp^Z|81D=#FcmDuimMr*AxxTfgv!n9P z%ot^uwL>5V%L46`!qY-yTIZ#chWfOf_amyA6#aK+?EaM&?glM{Ic2cr=BM_0D(DLG{hE79N<&9{p%dZ-tdMmb0+i?0Eu--Tv?O0V@L+oM?e?s; zM50yKnNVlMB<<+T5-HlMCg&QA0r{<6Qka6qV+dWKbMMiEHmLO7l}dS~BG=5lUM4Ah zFO#+2KwPtSq#dJBP+1MAcBy>HvU zwlW4^H*z2Kg%!mbS7r-Kic4DOu}TkVdy8xBXhgNvIVU7Tp(^GPDj_HIBnfm9N32L` z5=~kSWY!x+Bev>%Kp+6p9aAJD3}NQ+A{z(|LHb%XYsd9N;;}1NmtmYT;AHWTk+XNG zgwuSbb!_TtR%3JqkhI$=vU!lqMV8gh)DD@%cw`oo4z33$FsbBE?xXLWHrg=J?zGFA zwcGppkZDm#*kYenTla3E3>-_A&pNV!kOGtR9Z z+r;eH(OKLjWOo`J5+0J{U(WZ_l=Vi7ta|$4r|0|XHThTaCSu{aq~puIoKY|1_S){? zUZAbzmAdZ+Eu-pH_w+BZFWH-LjM%D#@d5ev2j5b!!miod+I-T8mLO1NXKBZ|fC-rw zj2rsd^N&%?FuL5iqJD;4OG>h)l1&%;wpu#w(OV8KM*1rr6COUppvyF%UW;3GGKx)x zX+kwSkOK?#xIM^{-LbC(lf50t0i^_9H@H)~bm%{E8!%baxrTp`h1hNajV0V0`g1$q zRklEpa79{0PpA9>anJ#%w-cFhj4dH{p|Ma5s`vxNszHJ+UoPx%u(UG&!uVcib$#ck z)lWH$ogJMn-c-hi>&+LCF)Q>aP&ca@Y-!pTvosk(uD*q?UT!RGgvXF6#h&;EUDX zRe+`+-|6q}^mkvN{tgN8Tb8<3ZNpAdKFX^4!ENc&{y=7%;wA2p)Pe@31J?kKACz{sSb8cY%J*0{!p|yvi4Mxq0uGog8cD-0L7>T9F?vo;-jhdH@tn zkK@#NjErY&eA&5V3rN%O6I<-h7jKk=@)HAT*J+XtUs#JJERW0LAnw`op;kkTV;ZTO zNS%Oo$pMJOj~N%ebes;46axyRR$tw( zc&N@;Y5pCOkM~W(3j7IFB+%a5JL#JNnPZRkI#rzoBRamcffy;_FxOxb226-F*Qss^ zN~|jyDDK@}H?B|e^^D4U!U~BCo|tmDCp>0v&dGa+N}cMA-s=A`X2KEcmOU(4(;XRj zvAK&g0~=8R@nxGsmOSh9Qy6|qMvUAFAm)?^9Nb*#hSf-$42Yr)% zWjRL7@PjSO*rJZv7lf&QQIinX25sy^3EWJsnaS_=UPL}p%yjpO`cD8>fPo9tir^|^F z*bnCbNI|#0&J(TjcAhBoy<#z_K3N=V#uVStJe9XilKGq}R>hIfbPf&j+iyg{{51~M zwaV z52J--V!fTXPx=Q3+5USq!_Dc(4Mxj${5|Y9R)PJEU{=BJLeMfsP-#3%@i~cZl*f*x=^@aKu*#+68t)3v2`NQ5nEb82iiH% z)q@_xhA-;CMm2n~^J1>dwIyv6eJ5rt2vR}2-9Km-Bx_9Zb0antbZGqUG_M7nRK&W%mw^6ax*_KszutA@~SF_7`a3 zCC^MC)U&6qs(c@Y$&}>`Vn)4%!CtkqLLJgJM!BA2psqS>CuZN&bK@*vsvqirUgXG? zkPd2YPodyX3Mrge-(3`6iBOEQKSvf8i|t<1I8@*4wXnZabAk$I%Q_r@8NYc3#{A)O zk5=iyy2}(ukRtxbg*;z~bPI0mh@F827NX>I!itQ?Na3*6sa`Q&v8NWvMBeEbM#$kA z<%ginIR_L(#} zRhd!yb5H2*x6&^?|6orJc*wR+0hXQrgQNWUe|Y%tuKvTV{AfI$`I3!g60-qGk>Kte z|Ht^@`S<73o^j;^)k?>fOb7d?|(Ua{lkB1{kQ74 z|EJR*pS}I+tN-tR{nc0hpa15+`u~6R)mNSW>wo{hzxwL`_rJ>Lf0px)N|68Ro1+u_ z*Efd;GcM#eN6)@FJfu<7^?W*w>0ER}Ccim6{O0fgWNV*!_|4(L;X&u%L8pIo(Lea+ z==j06-y9tu9d;ib9{xLiPp2%@9X{+Hd~93J=@*bm2( z`Ln*im`wW*Ic29a{`doSqC{c*=1d8&eeC4nyV>i}cjEfl*+Kto{^&Y>Hv9Ou`4x>L zZ~Dv88E3P96aSd~W%|p5AN>Dv_V3>uKKi(lUSo47pn|8~Ns zmw)*Oz4*7o>%aW@o5L4Rr}4uV-#z%pNgTg^doq6h?(k^z^p`jP_VD9Re}DG;Jp6yz zch9J%y0vXIDpgQKdPg9jfIvbE#Y9R%2k8Nk76`rfW>k<)K%_}A(xfN|qSAW_ML?Q> zh*YIl>5yx)Ib)phjq{#!#+x7fSo2?}GMl0D_fuynGGZ;AjtBv;)e=&`we_NZSsr9`6AQ*u}XzCexY3j=W!3dP2sw5DsY~XDN1S5=< z?xDTibaXs{U<4X1p(dr`uH%4Kg9Q6}+nIRU=qfq6gY*K7jRNl>13^ZbZYsg%ws2`b zUjqaP+B-otM3*R=!-B_*U;8*@Ijm0lksuTH9&egnj$@P%>wSJfZPn-^_8SOBxDg1E)Y%6 zAb%-U!yswfAURE+AY~0L16M~G9ce8U7aJKHl%%8=!qiyZ-#AzY<#SI{$sowj8SEu2w79%v8*1S|W1J=|^0os8VgWD)Lmo(^VOo|0fQFMlapQ+sdyU>jds zq=B7}hr7ADcaW?-%K4tVhm@n6GYaV!Def$n%PU3=&PU{PlLy`P_oq)L#Km#uxUtDd18$V<=MPs`6s-SID% zHd75U@k0mu_-m^LddjM}L-f!{Jzu+f-XLiY2vQCyVXW;JbWcj#MGFxmi#GIAlK`Uw z?-{Fs{DEMEo20TX5R8B*0VP#{V8lP8@=u78hX2YtlJJ=|B~t)^7oef4WE7aaF&%O* zb^lw}4qmm>Nr6p(yCM{>9M#coH)2y{BU7cLV%-Ul>YyEZPexBqKN<1=qT9%jqRa(FMX1w*jp&4g&h^PEkpDW8 zmQ?~E_?((ZBrZ=>@_+l}7MFJWe%tgk*W<^JJp%&N`qFL>eR8|+yFNirBoZZFXtPRK z1G*A8qL!B(JG#1TPY*V_ySwi?IhE`cY07sH)vupQ3Sy}#Pk*LcC8eZ9ut}nMZ{DQJ zk@tI2U$4;C)+XWjg*T%g{W(X0#pUbURxFo7(z9oe^VJgPM@tO5`}$ODY;K4$(>%%& zZ)`A_4M?#rro|Tfgy%wXbaME$k3LVe^mDLlz^UXtJvAuLH4=5MGw@HCva=?85R0) zIC=8(=Wm)6$MenCUBsZ3K3*qey#^?O}e4tIe6!gS3rPFLqns+eArPiL_VUIDsJzK5R(L`^gVNw&4M z&91CaS53x$_#n0NoN7JMt`b&y1+U8W)~t%6F?hc%KM@*RQv+G?$rhH8VZIY`(1A+4 z6M1wLxZ-1R{S<{sp5QrsLxYVm7qx6)ExTXcHBpIrmYFFWhAmc!x_Sc)zD~M0T&Ptz z=taH0#eA?7O8R?v2oZGNCZ29B{0Q0V{NOa=xxZ?>;^X_XH&rBXlLsu&eyMB|5BvK)3DRU(cAQ*+blLVR>JL@6d45t9|)v>!l`17 z@xv3>6A5Enr>7!VY5+cwM{VmzBRxHRD@?lVrKYClHEwQfOUvCN3|*~$MROzy^9hBy zf+xCr9fLrqF508xW1E?#u;HScZd*SZmq$w&(1R~;hs7F9;KC}JBW*ATtwf7J?QD6! z%S}y9p^^zXx6R&@J$(4^Xrp?jKyOI;V2O48o%;k1RpX5jlM}Q>p@u3^YKx1D>Ns0< zd?F8Ch3-zoN0)I;T%OkYVC96>#sm&k>x>bT75t2r{EV*JV-vIaoB@iCjZKECm`>n+ zS2Q=lJo?|1Q+?a$*s) zc$Afu)fcwLb~-|NfF}ynDq|wK8OX`Ww+|1~q2Z+~!-X`lv9Se%o|g}bVC#tjY_%|z z#27>Zd#m$DO`OtLN@{AZ#&f}82MGD;2+x69a{PCk4PJHaYuOH-2cwQtlJ4&Be_CB# zy~lR7leia0cqWj4;Lr^Mc`vGS%6Y4v(3Zl3gXP=W+6o3esSb)Tq&X^K?FlimGocJL zEMh6p@Kx*9C*&E>u(~}q|4!m)D^Wdp=tOcfW1=xc_GEueD2!sPU2;${e5>hH_k_0I z8nbGH5$I7Tu%We)WhNh-$6`Go2HIw3Y~MaO@rOnBPv9~qcr?J8m`9JhIx;{gi_Jl0 z+1Rl+rl_-{oneQG2to;Io&0;0tajRV4i5QR>0-kUNmoL{!cqyXD(iY->xlv-->rZu z@iC7tQO@^?H>W_uU6YcNpS*g-yCTURK`2QiJQGMgeN%9jF;VTo(}m>{38R>7?GtZ~ zzeIUe9j7n8J_woM(J-iNUQOX)5PVLpp`kJCki;b*D9ER%XmJuBY=h|{?KGBPT(p;Q z^VTh;-@p0`2YD5ohYP5CdwUB8iy00a6iF)?oykezW&nXe8B$Kkdu(=U3;0C*>e!pY ze>btQu~FC4ONWN9-;|bSqNk@Hb{M5TmE=B9OEy~F((T2@3=bPfxqQ_=q4j>$mB6vk zmB2CVFd9o>V>#v55Z*Iou*Y{)&peECz=fHRY@lH$v!`3l>Ck+W^}!m_esY^LZz>4> z8pw&8ta8x8?Ns}(Ph8L$A?_B9q^73M9WUXc5)c;X&n5(KhoBU}H`c>g56IW;?*R%c{(Yb$Ygcek{e*eBk6cSI^M zC`kH<9OOBBms8%i+p=i2tNcN|?|B!PO%)yxHw6aAL>u zz%2L2)5RVHPsQ~(f8-MrD_`A8z+w?jPPZOqSq<;)?ml_#6!^PeR^P%RbP9%h@q&8x z7mxMA!a_LnZFB3%_x3ej3ly4KT07rd-p#?zkLf}~Lz6Nyg?CTy@lamnY%$ck0}Mly zP4JvP?;uX#e%w?L9oJR6OxpZli)sGXG1(YhCDojaEGjeIyyRD zy?O;WCv0JIo!DhOevp#;(a{kpY>dyvbVe$i$Am2!0`-pq7Pq(*{AqI(0@6rFmPpXB z#jNXjq;N5Cb8~kO4yHpFJlww5&|3*s9R| zr6-4*lU0;ZDDmAjrtc zb8Bi?p-|}2{b(*wWCTXy4Ren)3tq?#I@f4k9~ZYtVG-(AXApCBOG~ zneHSgcNk1ZOB*rf+_|?hLeIoR&cnmQso+mrq=zdH2EFJlBz%66l9(MDtvn(nYWAK?4a@mB zJ)Ond$L9jT>ftf4&TlO;Ha51DXBYL+ywZ70_~__pw(Tj+&D*y-mxuD{85tvzldu1@ z)D}LIRr!~&pf>)|-{80QwUlM#qsutS&qN>8F#O zH~slv{Yzh8Uo#Zv7sklKvM^kzRbgHRc;qr(ZcM-&A0I;kHaSI^``pg8e^%=mpPw2X z?K-&mZ+v^&^IS*^r!R64z;OD!mFRAZImunm$dL8;;kNYyxDa@{QN6QSzokhsaj+oe zxi3~aDO?O82kS~RO<{$Dyp+q+^|A*WQ$nO@#CcW1k_(hE()#||7R?X2bh2bpq2Zjf zFGDt!;P9t=Y#(hgU7bYr9Df!#UWYKeQh=d_>DqssX7y*q!;%32KMg>yTGa!JJal8BbH$LIS ziXHy;1OTs;6yw_XJCX(OjT;yK%E>gRl2=JNdHtRIPkaZFa7xd{c8gR$iuLn7w`Y}B zBv+pj*eFRk`M@-17j+R}88}DoI`v8Cg!X;wul_8M@AAFB)gilRkk{Ff*U|B@22M$4 zduOM$=ebbfpyRcJA}DF5&3DN+y2t?W9I{uvyu5}T?p=CoQF~oqU;ppr&`}%ksHmvu z{Z@pZF>@Tb+qVzTpzUH4xL{H}HNZr&GlU#&!b#!FW<;k4BS;-=&4`CZKB$20SHP0( z3W&7Qf&f2^daMX|o=(ITvuceI=y4>lxoZRNB9R#eu;w33g|A-=6Yh+Cw85O{q0Dy;w$KtPFnm8qCh|e!tdEaH;ut=3k7{L}J&{Irc^VbI4eJ-eT&%{J9jKbK^ zz~ITR{wyur9OJqkhO{Lc%7OSNY zu*oT<)4snpUa03Kd{9J3a%k_TL|T|2fE4qVmX_*TTF;@Kz{1zB^B&au4?9HLVBV9m z{-Q9Uwj-l>w8}xx^+$u*32l0Ec6PjFW3UD;mu7wNcw*-E`rxre2`rtR0U%-1Mn+7z zBg7`{%qXb$QZy{GyaKjlgTZtXv+-jmKDD3=fSsM4!0lGbXE`~y!(wl6-3eyg`1Y~A z&Tp+iZwPp>gj|2;zdl%L@e!8J$pG*?SU2-s877ZozMTy1yvHnNL50C!vK0b!PZ%Gd zFxXb&Y9v7}Qsi*yJu1(@*HVSBx;e3JZOSV?zCaj^$MCgwE8%b^(Y`ND1BX&y-`bqOEmStwqc8z@ zkbazfUs`V1=>hAVV5zIziZ{cs#XOiZdU|?#$MJHmG;u4jFszm}rn&;Qgu+x;G&kcx z`jkAFGtkSxd1~LSA6z1)1fsnDKV!otE8ww;&B$jD}Ugm9|L%1`z*#9~MonnW_l z@v3+1?Cf}jg)h5(`_S6`jQ?47wrdT`*8~pP3a14TZ?KPVoLK zqpJwNeg6}$q9W&mdVlzM`2&#Cus|sBcnN|bHtab`_xAO*M_%EO@S0au-0kLH9?GZW z%u+;Sm-iuVWwzk{zapHM8Su(8hzBiSXl_eYoI7y5YkLB`N zy)!vEsjjQrl`ZFU?fP{Rn*HE5#mtY0Z;53RNlH!qIU3SkIl-f0iz$yowYBPILmn?K z+Nr9k@k1c2ISK)hSy>#~f($2zTZ!G>>Yp>EY2KKWwS6tS?{&0oV~0lb2?N@cOiu%T z1X1qn>`c`92)%#*-gBYr%8Fj9Z#3yh9JDzZF5eUpY43ib@<(Yfyo8Uqm?`Z-p)>O3t(oMCVK;dtEV+X?+5*b;*=juG&XjSx ztTXcEgOg#okGJrjhsi?(eapR5O&@yZJeT~-x)qd*8Z$kH5qIeR%gh`i==;`baTaw)h4?cqL zC|>_2nea{|ySB6A-_MehpIBiCVh|U@$m4m`;wF^lAtFytF5Z^YSkC^z;~8y<8j0rz9Z&@us7T7~*l!UXXNM z;0~XR+qVc)%OLXU`T(`@@(1+n?6EpoG8#C<{-5*C*W_flvezSov+hp1QM2?igjC21 z3Ir_b{dG>>Qq%_T3x9oQl{h0Gd-DDCzHM2q%Md;5p&YYpe0l_S*-in&AD?J-IsXpS?^C2j5&A zhw{jo#Vtj{us8l7A}pS`i6u;P;Z>!nsi~Jois*g>E?lvn(OwjV!{He+ZtNE?U3!+0 zaWf2iqk@FH4)DZPEP=p;CwsJjPs|V4`Vk!+J&VgU(E|d3RCIJ|*4D2^nxnqooUm%I zgiTd8N1`y*HD?(aAQZ*f*;$3h40OdXNE0=?2!p}S4yHVYieP|C%W!DEm7PTb&T3K1SJW`;@ElES#RJfw0$`@kAAfG4`!U>y?0CO)}1?C zmX?+`#l_R1aI(|qemBDRPn{8#w^fcG;@$qm`%?BD5v6lY+{+~_z@r0F2Bt~zM z3sXsqdGh4q(dnrcPHBt;!r^fE-_+4uylOro!TO_l;ovLh-rn9X1sV)1lG#rPD|Dy) z8i>uo3RIro+Sj9nL|DP#EB3`-zuKmz?w`;`*ZmuSI)@2jeY3bj~PB)ch^nwolvvp4>gadxykzO?f* z-AWUuB%`jOp>*$F(jMEDHsUCW`SlWv4IXN*PgT>Q@Yqyn`1kJI^+}vVeh{g)of;C1!qmx)_7_6O=lJY9(_pf1x zBra*EVKRGr`@bunnu#$P8LZlwQW__;@AG#S@TmROvHvissE{ZqD$>F!`KM%N#zsd| ztw^p$5ZFk^CcGaYWRF*Ma=Mi%?IIXPA$ND7E5VBd8YP`OiSZ=<%yjZ5<~?eD%A>in zY7i%|J4RDv0Ed$cYG*vk&d#2))HZp;Fw>^UauOo zoo#vCJuuLf2ao%b2dBw~VJufi+$vCbY_8AJz@Jz6SFT=3c#mppZ&&G&-L_~5q$gqZ zhK7bxlf#r-hW9KjA5O)s?5&JILXRW>v#VooNbJ+r*4A_5oAlAqk@ZYdScQ4n(RefQ zDT(?C>1IEA?F0!q5dEVcoS!YhD&3}Jdi1K5#2(a<>FMeHn*dJF%6c+d#=LYsQA)J*BeC;Mx2OG{C^ySr1w zx=Gir`OY|xkpI#I!0ZwZ6ZzT+61?sMZngNsV0`w{c)?P z*G>@Mbfrv%fYz^uft+MY8+CX6+KUk&%)5ziXp_Yuwz}48{K2j z1%P&U6ao-lUX^=nx~;^$D8e%V{zHdl&;>wYVWFpwPy16EmI6I5r=@|M@YhZ? z4+(X9w{$y+dyoHo9{z%x!;=A0($m}f`e>Y-oQ8{P3PwkbKDdnQp3s8U^_c$voI+SS zD?@7V!Fo)8maGayXIwB?Ht&fS`6p3-0}rKt3X& zZL#Nh;oujhgC)iFt#=c+-!tai`YyH(dg zO7vM8(7@%ntPg@Ftfnhq zc+a0i3x92+SS&U&F_G?IeUd*ccDU*I7l-fimkYmt^*{eRGUa3dJbEsqm*+9lM0Mp# z=SP?Efrp>@Q!C8NhK1zda5%ZiTjb+Mj{u6ti_g{7 z)svt-z{mm!y_;-kc4rmXlYe{|LUKco4erQ;c;|w!pF-Cu(7dWRScBK z%gfsyP}m{`okGB-s)-4+`}dj~gp%Z|fAo;}nE(EsG@}ISzxwMaVMncrkq^&cb?}nc zUFb0^0001Jz;#v2m93xrclS;I|K<1Z{r~?v`~Ls=`@iV_2g^!J|NH;{$w*57Pyhe_ z6TkoL|G!`i004IW^#6w(2-pGuWJ3Sj`~N{eNhL`sprjHQEG8!d`oGctZzz4+^`1?z zh9LrNZzU(^tuGbm^xxS3FKc4{zxw~(Z37IX16>1yk-i`ozW{F|SBZQ29;W62e)`_V z%BE&+_CPQK?P`Dkf|ZSQ5x!msRUK_ZX#@2DLoKv+paW7%-&@BY>;txuHS^Mu3Q|$h zvp4W@(Unls@dtttcG^HNLi?VEgrS8|2o5MZxs z?5m|AY2d75f-q4wcQG@Q0C|9cZhrc%&cXMbfMCQuSvj3R zKUZldwIKf>y#QI17DycoaTFz@-;)< z(>Jk^HT2Qbb@4FM)V0&q&=2&n3knMM3y=V-+p4R$Dr@luR#&>C89AX_;nEh8C6 zFBv4#Fv3?4f-v=Tb+I!92k97+mZ9Q*&o0>8L{iJd?Vhe4(gz4u_A;|m zbFuR`(R79c=(yQ92g}&&BE2LvA^x&{_J&Hq(lTy_`t|`z+DN3Dc>vPI4KAZBsq5$E zBO$Bj=V)f{rRk{dtK;Bipr($p^>X)faganKj8#;CU}YD$kF=wnx1_$4G6LmhuP=%A zQ*(2$Q}s~Ol!BvFWp$N|WVF44{H0~x4MAvcl&q7kG+53_M^;}}6{0DLRtJKW1A@Jz zNh>!dIsX57Z+`CRz{`K_&37>}+GnTOF1tH_%T!Q)zVP$2Bo#|7)AZ+&ljbkXi>N)P(fX+0`tA6$P@;<8TaM~RQaUY2=Po_#B6#q4);9UQ zE&AXyX6w$NN7*s2gyi6C1D&{JJGVx%z;*|Np5l(cl*UDRdO2*Nrm6scnlSydcx0)n zD%iHevQM5oA(6dwj5&XT^MASQq0%4j(Ko zF4joVIdN#Ea(%tnV|kXD8OvfBc!6+w zsD^`vU1MgB933?p8dCp>EVZld&yq!b&Hy=1*GVg@s60zfeo|U0JXE>vy}xSgI$g(f z?YTkZt(@sIlE=6@XgMnRVV1VPjN+Kf2XgML*NTA!mAbA;5;3;Z+ zV%V21uC_FgL(j#P5FbxF)1y-!%?bBC8kwpb z2D`@In8NY;DI%ujvxVuF%Ju#m6`{x8Ltg4O$kI`5Z*OqqRjyc5%OLniJ^5NqdwU>y z@MXfQSG=y1@8Q0j22^Rn7XX)OXh3$|*HjUR-FHc@Muvvr(a}_76nT>SMb7CWEz zzN#vBWaXZfmAL$6IX11aD;fRhz>tvqw{Nw58LR#0+Q0?0AE*n%!M*G75@V ztdcAh71dpP`@&_`MFCOc1edW=CQ;_NWmeztx;pv5pr9D6l5U&9Sj9k&!om^`!^{=# zo>x#nHeKh(z!jeTsIXL@K}fe_X8{k#zk)r>$w}DW_8bDKqeYFc1n-ZTR{E|O41tQt z(?rdl$oc$=#wvkrOPoJ9g`G--9(fLdx+xN&CpVi;Rz-$D>Vl%iS1OUB%cCU>xD10A zb#?MbCnvF3C9qA2b9c%u!=vh7!XFXzxzN!k1Cc~ z7XfLd6s)uq1qB79(@M;ESWr15(9}-=H@E-(!Rf>W!!nNHIsWbUjbV`u4p7bJRG<5^YaVb?GefyU)z8>`nbD`_4f7sj4rw9^XqeKGEhqu&#O>j zWbFFwgVRK{2X2`a(_;r#N){lappXeke7)6t&YdivR5UXAAU+?F&^DB>_A|DWHRN#f zCqt5Or-5-LC3hfTChRb0nH5t~Vg%Gswz0|GUl1`ZcQq+xjw6qWiTV02Aug_}2{%F{ zoaTJQ4BIz0GBuS|z>ILPzb-0Lc{iT_px&R9*4WwE@7=#2mu?wMeSSQMc{RTF z?Afy$i>KCc?NM|Kb5T71+-S&VEhQWd&qJL7pZ7%UEZ`SDj$8iG#w{?CZ7nT#T_-A9 z%}cF9cgO`a+UDA$o~5TpJtUmijJ(!4`k8LUt8x7*C*;wSCl~kD#_34;)5hio1s!+% z(NQ3Y=r^Ae#050kuv`jBsj1|RmWe>EG~_$2WP!K$tFN+%TQZ(;9lHqWX5ZcV(Fp(R zCB9XOx>_0-HM%iX-EJ*0yF8S?eR!xA7ItTMcb62}=Y%cHSA#oYCsJTZ$qN9}cb1)t zJ=Hbg>6d5)%`bS?ws(N@K~%$z!lz_@=5o)I2>UO5eQ69bemNr-NBfzPAtD zYCPOtNQ9Yd?HA!5wjJ#(lrh(^JCP+1bdnG*sKT5m_qyI?dr6cD%^oQet9koNLwm5LxRD1iUIPrjpOO zYFcj5+8R!oMfgVC?Gq;*)agcbbWDuXfeYdBB}%~A$>k^fYS>qwK7E=TzjHJjUgNux zydP7Voz3}dh9YZw60>hxQi^nSeJgBPTFTx+j9cFZ)|M*bucwGb?$quk3?2~ z|G>!J`!^iTx>xAp&R#Tz9L^sv;aL9R@9;Qg>5xxZ9~Kg1f3)29XaverOg=6wwWYku z*-~NCu8QXsVg=h#4Udfc!yDJXeRQe$nRcHvLMqbi931}`5#!@)JIT};j*O3|)y|aC z@TGmvpk@5?>szz%m60M+9s;u`sH>}A`zt@mRZY@*cz6tf)DbUVzU;^Tg0Hq2j6JHT zkZ_%@Bc)X(Z*TC7Cj2L|l-+ar%MDdHJO---&X97tj^&i&lc$h-R9H%{cW0jwO4u_T z0(Dyp)wj(s>mX*N8-79xCb5Uho~=mx{OKDdeIHOK*TcAa!kRMy~Mn z3jYoBj;=0JX16YJj!#Ua!^xSjRZY@bSy}y61`^}~w|VK@-+~hrcd4#&$qUF+^h6Yv zDk-u?1#iECd}}utE8gDrH0FYha@pJ2ZA+K1cNmOSxKG!aC8p{1djI;&wzoW_;!Ep& zF|D*KC@3hmyj<6pwoXY$=gPNFZX)s&a@1PJ3&J8I^sKBm13eS!x zT%~Y!ahY3LiJ@T;i^k4>9mr9j)JXQ+_$EE1-yMT2b&LwZ?RS zK;Ybf!j`I%(&OcunJGA2V)=u5+mY8gdHG3kl}6JOlT{A%*RDOX?@Nop=H1dt7lT_{ z^A6-F2+3cjZZQCMbapDe8((O7d?_!#_*=Tw!x-*6!PY~0@Vxw_yQ0Py|8y0%M_y4u zB3VmIOI7juslC0Lth5x0#G?g>&#(AphybfrYUX5}pU9IZPqydd#OHT^_T??yG!F`r zL-%JsookQc2Lk^AkETZzwi?2xJes+x(EZAA_|s)btbvJ1jj3u>TLd);G`!ZsVZVR37^+kUk{~S|?Ce@@Zm#24DN|QGTlnq!pNbE9 z%3@v9WE@^!yTD z^QwV?fxNuDfZW{N=(xD>9y?_(ugcjiDknCr)Cf}X+F8I?It+3P0D*HcLN6ahMNyhp zyI;{r{!-`X5*QrZ*4Nh;9K85UEi>%%$Vk=Xct~KN^Xh{uDN%T45}qQ(Xp zrj|kEISK)v(h94qW%Kg$v%>lpd!Em2Y`78Ft*opXh$m}Lt}{sE4S;ih6@{qBmndzw zXIn`JE}-!wJ)H#+&+0Yuo0bR4$<583BtXs0&0TX&JoTChJG3F3?2GB@jdE(GM#z!q zMSlKJsj-N5mdq71Gqak|WAL{RPT^n6?&o{VG+}~?&F6$I(t{fs8txezKmGh!TRTUd zDOuo#pdbYv%jGk4`^E{AR;tBn_5GE|D;$|&O~u7j)jxtoeB~d+i4EfMl$g`08PCJM#QUEMgEj~aL^*E1XrGcxEE0yIUHB#)epnXEd0x9nj; zmI~Cz$Hz0f73O({03B>gl11IWYf@fe7YG$`yXF2)KsHTSPIcwJla^Nqu(rae2hAKu zzBc~OblT*b!FS6ZdQoHNN{;H`62qcW|37!w(WMC!Zk2fy-tOE;HIFUSludp1>~Tg0 zYxSh&{n#lH0#ll>8Npvfhm^53hTOkfGF-n-if`+Z>(vI7_GomQqm*|D5Flz?-B~s& zSJQZ1YpmZ>#P5pxyUn=5Rf^0{!>60|iT6tY-z}$Uw2a#y)~BM;=veIH*P6yU%Cu4n zFA-y?`@3(Q24m5$%Z!o*+zW-wUniBCMPAe{JHStdrc~P0>ZsefX4mZe5KKY`1`kNFISs_kfmZRWhtuj2dn0y z#zONZnwsq!W5>u+u!8?Ova0OS{ad%_t4)_|N_rQ&%2GH0CDhfXL6t^aEoCVmBBtIb zB1`=pPkIK*Qa;2^y&)h=Z|_Z&rNBCSxI9BXa%t_0dx`+-uv0F5H994k{b)M}2h@1^ z19f%vmb2sEB(nRAU#-nrf>%P~+MSRC)pW53Uz)-~0z*O;HtV+{qoOF?>o;V4SBA++ zqt@2Ev=o;RSk9P?4Azd$&KoywT&VZoP}bGG>g?hIpE2UgngsJyPy2HyDk^#&P6xD4 zO>t~YRWF5pzx%xKgm5^+4+N6?EDgXtJtczoSIIp*JR+i^PjU_OgeZ@Xk0E}mjG9_n`uh48swQb?Pjbrg@-7w@7Lu;-{{H>!`SWm+F$hFY!z}t} z$gyL2D4(90Ia0>$Tg%`e9jYt7^?R+)v*hF_Po7+CouSXO@`7e-F%)LzE-;q?fUmxhBy}S$X4r?8n1;fC5A!~5fOjz zrmikl>vvMfLTF8zu-3=QN_xTPJtrgw*#zM)zl2URsSetv!xU(Q@C_np|{;+wvk-`PY=%Ne<%7$5!K5h)yqven$* zsGjL6tNsx?S>>>>I`$@S;bw2Di0SsQmUu3Shc$)PE<*$WOACp&+@KNZ&i^Wg(3RHz zhZy30VL+|#mOV5g)!D}8MkFoUlkRTy>LU>vxv|kvUOv8yN=iy%n1ma(6ie+7^OjW9 zO9pZjScpWTx}ILZ%D!`dYdGc58&mPmIGB|$V>11c3U}VG_QJy8)zMo=$H%u;mF#aL zD{aZo2!x%5L|80V`RZ&aBW8DiZV}%C32dYno^33iw}XQvgv@yAyB*9WB-s- z(tf^Iw*&%#%U{c~mRa2se&5>3M5-@}PEJlz(b2JRwcqxFrs$O) zClwl5h3y-QKBya=lUNMZN)v6(mh(}?dx~V!?I)q2oMK~Prw2Ai+jCc+@{R}Z4XN#n znOenQ=a?Zps|(Aa5F-+k&yn|=zqBQ6XlhFN2X#v&{?66K4n(OG%G>uc63c2e%dDEY z4U2S{xKu_UJgYyuLnj`Tl9Q8DQBhT_X=<>Yot*^&=!E7%i*b#=Z30TL{}5gJm-v6G zYiX%?dR8p6W_BFkgM}=$mmBEl>8bhpe&{zv^#1OLsoFNL1XqMK;zf_oy(j2!k($iU1S65Z>U&scc4kqMzWYV2OLlx1V zGi>x^42nw(i);xe`*|qGi%TjYt~qpBTGEP&oRgE22X_2V|4Wd`Y&rhIeSfL_wLw`~ z89YnIZM`3H`PbasV-i{c872JAeemgXlultC=KP`J!2}9x$57hPkWEQJyrdF!wR7AG zb6Y;L)C>BdFYUOZ#E3=AqPX`kW3adPiRC+wy2>vrzF(U+ZVL-5A8t-h6L|;zOP;wW zJrLzT3FeVWUH#xRQsFTJReN8XJ?V+b5m{3(t_-1h8f=cc&0nxCJvC5GUqo*W^B3%wo`6vXHL zy8S8-G(L*wA<~!Dcp=ncY4f*@VaX4l!8R4M^yb#P06ymv>e$*KZ%FXF`8p@s;QL(=Gasf8BWSfQvh19Td+l zeVLq`9QnzW?b}C}sNYM2adox+3SRSM!H1iFyqlCh5xhj;#(4?@PdHC7s%z314 zQ57*IN6trZb!{zc+DR7&C9ML`GWNz46trvCfyd{UmR=5SsX&Sb&c_IC&qeX% z6&F(_3(T!gRskNJoCKdO@SNZKd0Jyt=SvNRLi13?>`URlFH9gym6VjQi`Vn&>e$o8 ztv(U!8yYxEN=lLhs7p#p`ZuLuggu6?L>`Yul*S*$1u%|_$dL8m7JE=G}YC$W~)iMTG=Xl$nu{@ov$`+}ZK(;_~vyN!PAt{A!*% z^YHW;T{SO5KTguxYg$pIKp-$lfLg@l?Oh$6E1%JlO~exy_2h`K(*x=H5$zXXa*w8C zK~ZKJZy%qsrArS9WAJ2w^_ga#mVMl+e9qOWPi~h0oC^N5$pSZEFsq4;k1Ra@_4KN9 z!1nPH?tIfUN!sP>tIEou;G&YZZ#!DUDYF_)wtl8tMG9y@g7gp=p^b6D}e^4LkvotWbgu@`*+%|X~KJfFC zCcVortK8DkQsxH-Pia`JWwPx1)|^8QH#>h1!o>gh2Jz_qv=h`-cnluLZ1bZb2y4gx zG>h`)*f5k`ow9{noxZ zy1FuQsfB<5jqU~ovB#6Td9 z^Wt?E2oQqdl9&K@CNaq!0sCTOUV#K+Nbc@eukPyCJa%VS>#+TYG}~Q|ufFfAufFfA zufF=p+g^0_FFb$tX_sC6K;_YMe|_qGi}(M|C;sV?FMjiu%dbL{&w2Bk-UOyz_o86W zAKiQZW54$iwTOK4vzHehdgPJE{@XKObK7!QbIVgMy6AOxU;Cj4-to&%AAa$RZ^w68 z6ZhTR`s;~{Tfg%4J7;fx$}^sUzSzF<_7`3Kj+=(Axb>D>?;N?~!f*awZO=EhAK!B3 z>%aY;W9>hB_7DH(t>0I{94!|T`_<3=pS#r|A7xIKJ~fJy>#kz?>@cffBgBI9}C`l?1GQqd+*Jk zd*1th>2JK(-E+@94?oL)?f357bL)LK|LI*fe&;JQ$6s*Amwt8nyPp}lj6M7&^JC#V z3(vdZlmF?}AAZ3<%uYY}_6uKm)ibty@=yQt&9~k5weLLirtdkzPxBuGxrp6;?1Epv z_Cx;g$jF=d8d$sUj+r;UV0z!Z!QvekKJ*s4$0;7)@}2K~ckgxA{i^r2D{g)NZ~ykp zmp|Cpe=i93y!Fa&@zwWI>Ac~q?~OnB)-Qkk>o-IT?C9|=@4fr(|NNf!Y_m^&81VJm z^x-`GggY)o!To%Zf9<2+{@wR}@sTs$ftm5~@xS`O;>pjK9==fN0CyjI=aZjz*;8K9 z`bO};Ltp&%?T23UE-@ET6FQ1$H%0E3yu6XRR#~yy*1DEbw-9i!Qj}f>(UdyZzwre(t&**ZtS0zxK7Sy=>`QcRW1&;FkMtrXRj>zPclB4l z`qf|m(xa!p^6?Aa_NsgCKlj)}Z+rOjzxl+Aiq~wNDtz{q@4fKCmw)etzjf?_uRQqK z+n%+{d)6mE`N_HC#~=FcqbL6`>GpZ>r|!7$N3Va^h48Ki9In+C3ZHz#=*MpP^S6yY z>Cf+c!b1-|^!A;L7rpMni*J4FTc7^<)1Ue2%Puay=dF)DK}cR z7uddi`@VZ${?7->C1oTm4EnzR){P zii?+T;;YuJt)q9{b=O~iu<_h?ANjRg&wl%(&-}?JJoy(LXX_Wf@P&O>4E@|!&)xEy z56pk`^Z)p@d!Kso#c!;=tNnzJee7f0j@Uap`}+%@_=(?o_q)IPsn!6tb6alv z>`g!Yq>I4h04?7p{2cx5(yQ_WcJ@a4MvgLy2fqgT_KJ(Gj zdrlpE+Fd`qcK`nUW49l=l{N-QnKYhA%)m2x`ojCEjcf8{{TfX$h!mCc4c->px@(WLY<}-(O z?|$a(x8MFR58ig<_gde)=8qryKkw}BG5Y*HmtB0{U7wx*=FG*{h#-_WR$M znVG;lgLv12FaEcS?|=4( z|Lp%g^1es5bPk$S`M>3LjuqT!V1HEHb2z{Y0J`M=E{&z)|8|b;8sCinTaPDkX;}p_ zR1=q<9Pq0I%9~J|1QlT5o{)icQ=m0ofI$%cS+aN9z`T7DJAlcCd$LcPXe*l*PA2Z;fz{72EYf!ljTt<;s zwF`CJK$+KZ_HbRP1f<|rINZ7k^-;9p;3Z#PjP2nXrs3^84M-O4z^@e+QF{p!hfWoW zYFLFLs3R{xq)-fRr7ILcwdu=y?}~b)g$8u>{XTJ zU#iRSR-0mXM5r=TqoYepOSU=Kg1lhOlhiA;;xswW)2X(A>6CrX?5 zKdj3$Gz1coaA*h|5b~Cw(@mEkhfCVo1EaJ10K?dmcf1D#R}iI$+68rM@CnW|S{fAv zLv6~7jsIlLf4yYU(d%JVUQ>;z&4QImgD&%b=kDbFPvc{y$<6y8*5x^Sc62*vxs546 z5fk@Bat&a*!O>Ewqbaa`ba}Z@;Kd5_h&721AfUL)fR7zCBiW-3qU+2-;p|!9`W3I~ zAYe(3vJE!k)u_!|u)wh6Rv54rQQHF6;f^1%^GBGGOhUnYZ}A*H|MXpt!tT z5a66WTU58cck6*y2?(kpLXfksNnF2nv{FY-({ugWftruQ*Za?)N>gaB1ptabRzkkM zcou*LWR?2_)9sPO_~AdHInoFuxkHnLNS{q2gi_?nGDi1H?E!+6P%dl!#=sN7ar`ubpvC# z^;xQ9PXkz~47oeFh02&A-PWl-_5UvRUj+uR?0T!S0K3?KyGr9@N&9bda?}66F3$?= zKUPP8K~h5u91O(*P_E+KxfbIjE>6_`K_v6tDzHyT*JI7YW$48wNAjcDhFP#fsiIL# z%tzyIy~NnFCY%SO+O}>*caYn%IVn{ygXy6s)s#~Q1_8kVaUtWs^~R0ZfRP(04dgSs zH&PiDqNZX*qo~nBWEM99ND#1ITCz)%#W5?rg66Y;JrXu3RzYB)GYt8{HXCh~%80>| z6~}6#JPZO}(i#||D1!`Dn;u2IV#=(so~TkoKOabP{Ter+dqj{for4_B_NrKiPeu!2 zsUC{xHTe86Y<9;lUUkPlVoR7Tx_-@GyiBNPJ@GuOTmOaaj9LH0ZXtA7zUL(sx0P|UV<_x!}S@#PP2j> z(Da$>g#{+;3407IxvZYhdU!JmLp#7y-L2Gh%mW3`2heeZbqGCRon2nG00;w7?1Bmk z;b6Jc>>E-50YNo%=4x)E1J|bvK?mR}H+=ajk_Q7=UIt}UflZ2J%dTG&T*Sw{h-4It zF6;W>r4#l9pQlZaaR>kemg_S_s@#m`7^&i>?^pm4f{9(&zWo>mWdsOn;1+VgQXNVD ztw07nT-!!L!}Z-p)6b&D_U%2YAI%`Zgi!<57%v-`vCa;+t{p4B__~qp*S>1`y6wx$ zTP-jgLk~Cy7(U7f$AofJ@OA|IbmF%2ZO?2z{XJdmf5E}4+56qn-Tt2_O(yn#OS>n= zH}n6k%hQ|vFP4yFb%L9T+Zbjl|d6{2cm&E_3@$QDh8zC!Wspl}fekkxI5 zZ4K4fm<23~Dg?3c$6?q&7O<)=@*Gh`7A=mAS<&*Hg0Qq!5SIFYuoOa=0!2+;NhB0D zPt%Z?!wUVV85BvQU?lGG=laIHjvLY)f&daIH(!e&*&8SVwagTOu4#iq8~|K3N^=#! z^=p(XC1Ne*`pgc#u(={yNwS{Hz!LViF~I5sFX;uC_p6`;MKBxwiu#*_1o=!C%2yn_ zp)~T%CQ(H>v)q7PU+iL}v0!?hq3>kWPr2?7(Bl%0nEz?3fKlOeY8qIl{JEK@+M(*M1bp8F=16O7<%*)m;x2L%OK)iZXNs zL%bwWNo_^NilrIy9H>Iq8|;3>=Ci&}7yZv|z}l)}|F(43|0XAQ?oR4|9@|_$WnV#vIPy1 z-pWr8VLGQq?yi&Z+pQ)VGd)UGU|m8-FQHQ+svuS@i5D^KeBYF4NjKA>VlQ4j#a#Pv zWf2i@Krlo&=A%Lz1|n(!3_B3Omi)h?lt4(u94#S=^$ zD#p2dTiTKTZG0r+>i8aIFDxE|%1|?MKj?X8fY{93 z0ll+DP1kRFjZ!?PdI_ZoMWp3ckn)78uj()LZ4MI_eN%rW{gZQsH_~V`bVS->bp^Nz zpbyX)mx={emDFQ5Yx91>+M@@2W&`nxix@DB3GkbZG9n|qNxs0VYBo5)z>@2Epo{<` z(5HOTIe=l{xK(lbh=De2c)&qi3UeqzcPCW-P=E;s)Abpup_Hq0A4i<&=R8(N;b*YWb^d-mQcne=bAXgBK}o# zypFtvP3w|jJ5&+hRh@KyVuQ)AD7k8$gvl=7fIh4tr&w;sYaCTNL8k1JXN34_-lPa% zUxi-VG(Z)bs^drIaU!wpM_ZM6iEg-!okvmYCr zFw*oZVAq8B={Alwt5x?5u!?DoNdh@b5I1FH(l7xghgnBdLMp>p%k2nsxrTKcfLc(} zn;ykWs1+ZG{H+a@Y#FhpFn>3MB%x(PjT!76}3AO>p}P9oX5 zD9?Bw9C8|lw^H0drd2LbB(!h}xZ>-%4ObbVtnN}UtWdS@@KIh?Si%9SjM#+(RUHc= z8wmq=4cxntfh+JXLUcLs3fj&%=LO@8V;lw1A46VA9t24h=n3zpg1*&PJAys)s{v<- z4%te4=?r0wz3m&oBp1e7ll}I?Y?~n*KYmY_^^P66R{oUt zFR7Wtz1E?Ul7XOD)6>bdTWJaDdVOk(MRnXN$@h_BB6dDnxbL0v(<#O z&Xil!1T?~c9)7m=o0L0?sNIv;5g9^OA$4Sikwqlpn5<3FvOc0^5w)|A1ROSOPF_e$ z3{kcF1Q*l{xs*3BH7#?z#U^gXyoqP=NzI&ijd)l?x<%gO)i4Njpr8?X!C{#OuJ52T zooa0jfzA(}=sMkW6WwQ9c!&cNKoBD?Y9Y>B;+%p<5Omt0BJ5MAr&$>tnUG#pV|zDt z;H4<#Yho4xOPyG7PQ-KmB+t;4GS1bETO+{okY8hU3zWtL4Kb&o*rfrM;8)d6?03fv zWHtFy91Dsumfa>Pxh*{34VLPNAQ|zcaqLn+8RqQXX)YvM&X^1`gQbZmP!wlsUMd^g z6K^dkmUN`Qjw{O$OFICvYg1eeqo=(P!=!hIXw(x^4svB06Gs>67fUPJU7FIkurz#zkVmT>0n#}d6T|?|3 zYF|!pgLAT(b(C7bPO!T%X(JUauUk>4W5=Qd@A{yjR0z?OIfjnCE0MvqOAq74W&o@f z7gt(0+1epTo1$&lm|G3oGgm6Ph^Q~N0~s{Zna1fq-Mw&1+2g%t<1n*>oU%s9{5eqG zHHrL+nS<`Ekw3|ZXHEoZA|IAL)qo(<=WX>T8fx!++ z<|oL1l#y^O!yaBj1PpVzKH~*-2udR(^3TJ~1|n_+lt#dCGYHb9&Z!fd*T)j|nY=B^ z(~9e+Bwt4Kp3w3XCZZCt zDM#zgYSlxTlP^0-T58}NQHPt26nGt)%nlohDW`$SvU#EM;&7^1&>;v2YPq;cja6LD zNUfm?b(;2~pURTmw9@mY5)N2J(4#G`*W$F9KxAV*-TeOy6IerQ8vk7??MlagZ~Fh& z=js3ar+G%{sALZ?>p_}%-bnLLg%^kp8HLC5D=6C+XB6o5FleHy$kb6E1dPJzV>E8Z zK4zTUOnP(Fp`cVXGYfOP$LY?MI=V=O1Wnh{F{|jba0ADRj3nGjdSx}s$e`y_)+x(8 zXJxMT-Res9A{(;Y(QJzNjrVks|IyK|RjdGANvE9l1&tnsloAQ4>p1$P2?;t_} zR8B#0?k5a$(M)4^(6KWP3WE4a!HlIqItzL|P@3){A;DAr`&Q(*h$J5iJpIKyRGO7N z+N?6H>To;jm9XKBWY^w6=L);bf9U{Q+xXAPvE=+O?Jn({*qs0C@$@nOI}{C>L@%E=IZCh~D$hhFSD? z4Da__Cm_++FrYI5CJdZC8#S=JJiT>zu~|kH<_Y9zcR(?`k)!8(IMgXDWkG`?1~*Xb zbKy8`ofV#1o0pJ>sFs(PEpQH$Aw|0;L9ytd3U<&)h6819)AbyH{1#|IA_Fz$CNq?g zpk3*gz=b59CP<@Q47Y>2QzX%p;iME_L?A@qxxyns`45p9j%&SY*hUTE!kdK@U7o5c zJb|eb^2t8Tr6RYr=umuKiD4j}i8dI?JJcTe6?0q3*_~z40$e4yp_fca!LF3+xRnuZ zn99HUnpvraBaadvjoR2TC}>;J?z@_SY7@pXDvM=^9Vy?yKWt4n|HER6nqg0=U3;UQ zVmi&47057Vf?6(Gl7SgMbBWp%#Z|EF61q+K5P|Checz1SiqB1h79|2~A}|ex^-fC! zOq@fE57W9@ma8mumbN(kqTM)IMYISy_)X=$ti~Z9LDtSJz(kc)-byir#HPOoeC!uh z>0Veaf7>pxd%uXmXX`ud8rQ%#>7EKa) zWm|}L=C;sCY)8*vheW`LowHGw=UrEm4r~nlbMraBPZ#}v2@>D+YpXK>y83^|QvTmv z6Px#cuglYi{(n;P0)S=QWGdk^!Ja2F!@^o8wLfGdRsI;Pbx8j=k1^{c=QCR~eWuWN zz;Ni9uyoL&1&oA#BPyp*GJD@SxkG!o>pQ?Il2fOgOShh*bvV9r*OVpG4V|2sKYZZu z6;oh78a;3jLluS`Fw9kQBXQvJ@)Uo=%PcRC>;OvH@Wb4DKbrRa9@a-_@J4Mw?k@r$GN)`;? z#pdGi@8sz$|BWz{(d#RaQs_Gb_PZE#^Z)GLxijJa9iJH6%>TMBPapDMMd%B(j{eGuOtr(n)Tk$YXa>@#E+!nUHrOZay(u}~+%>XSWY%WBx_{VhAJF!u`E z3@&UmJ>~|f>o9b?8Ig--C}85aRk!QfXPReR&xNE7s!d<2Ny=p{t}<|Ib*6o3m?RGL zbd+6PXF_;CcD^(^4^p8k*fGzU9f4?Gu$qX#joOq`CwYWMyR#F42A!JhxuHQ3Ud`NS zDE-l13$JXV_f8DmP7hQteSrBC(F5y%`nvCHYVod5uSk0Lg>zHVYXu=x z1yoM84L|$LL3E*ca+YP0GybKw*vdZi{{|#3bjtm^g1YGcyLTqz|HezZH}C&mpJyfd z|J9rk_U#?G_OBUi!|48cpt+jAIQ_OdtzY-CHadR>O8e6Ib$!(wY_j@_mHtFq*(yII zmAcE2xa+eQfQ;hFmYS@dZ#pE};gXnF$T1t{F=jcY12H~Xv0gLU;qqCB85nIe)$6YH zyPGea>(8UWb1Q;H@`jTxk#6<;m_$h;P^T%ly!$aIp+lw>lspXU^nvUq<;J zm@ulf258EHsWZlYTnzbM7Px`g@&jD!dx3ie#=LGeqrH_F@;x>)U^8A1q7S;S(1g!x zWt9fJZgzv4@1{8IXO6{mwly@~*KoSUhOnA>X0Ay6Ost%G19r^t`P&C&BQ5%IN!1Aa zE)+GTWERED_Z$3(Yd`)U?AP$%{XeC#iPZjYY4_&&&-Hm$Hxq{ND?avjY>JP*f6mKiX71Y^*6K^8Nfz#EUlo(XLJ87f2 zg7!fM%aA7PJL>g%xsr||9owIFBFS%ETbgOI`u>PljCMl4$ZsLFUuDxV#P35=m33h3Xn~&Td%sr;Jj`^vnmh7VC(_zm3RYGvyX4Dn;JwP zbYH30EvJ>$dfimB8{F&Gvu`F(L0(JW%s`Ep+!1th&luBb1@4(Ob%l1aHy$TWvra=; zjqqE0SLpe6wrs$s5C30)DXS4gPkVj30K54AN;`M&N}m7NIk}ntXI-9^`2Xf4BOHDC zp@IAV3?ADsF2D$;d>3F;W_4abqp!8`0%jw)FGrx!#43-0WVDp&2@H+fu)JvtcW;$z z4*D&PJak?9FoGsJ_?WVL%M7Ek&tvdZHtO=-2d1XPQDAKYi8_yLBRMx#rr$fL;yNfyEv;^lLO^8$Rd9A% z)Y8n>q{!AOOk?SG7E!y1t3~~-)54W|D~?DSq%QW+&^jWai|Z?>^%|9s(z&Zf=Mls; z{Ddx^lQcE6l+lmDo|03<6*ygMsq8zZVAo+LZSv_HMZ-y&8n9&ht489(>0lP-_R(*{19poUL+q1dR^}Y*(9kOVVu$*@16?Imd#O${0`DnpG)X($8h> z)GCzS;~Gd3Q(0Y^D2c1Pk7F**9M9mSn~CT?C0(-BE=>(s-kH4xD;Ig0#_QvlU2@0N zg=KPBB1lYglOH;j+mH_FKK#F;=t>g7bvggLYkYDd8UH!CdH#2Op2A8T!1J6FhL2r6 z`1nuBV;jcxE5OP3`ijr1bNI?0*2dSHLS}DXSy`<&hiqh*#cs(umP~@0@4{wW|0HcNoVXw@F%By$pkt(Kt#k!+I&)~+ahT_A zU)4R7$?L1LL($SpCS);&(R?3jI6e-)?pkSnai^UT@0Q@G4k3DG$$am2T+HTn+;?1_ z+56+)b=}PoC533G^*CGb_ve1fZex|UnQU}JI-TUICKJVLQ%sJ&XG{y9j9MJm(8?N^ zrjft2=aX61F=^Hr^|N(US&Xju6!;eKix#(0jZrFfHZ7#(oCL#4F93U{L1}WNXG&zM z7OUX@%=XOl3q}Dg)Zy{p`mq1aRj)5EK)3wAyC%kx@n5?pcW>JN>+!6_{8#ocFC#4dGD;i!Qh68U#jKyj zesye2+$)^a2gB<=#49V$*bieJl>Ss48&f)TPH&~b_Erje>qQ^TQv>CNCz-g(8bbQ= zlLQ$+U}yq*l-XX6V|8_*4Z~VZ5m5Uz)s*WS>Wkfm4KJ4GEVA};94e8{k?T;&?$@}u zd$jiiYwG@|ZvD$*YHSJ^2Qrx5MSfUB4@!Tuj>)@X?9e?Hv!?pJ%Rj}#c1Y-4qeg!rWqka;M$iM-|B3rs5 zi%8a1yYp9VGU8cFa(a(T?%M32ryw3&^q!w5fTF$ zkX7ogU)uo)@*s0tYT1n5L*FS30Uy<55cRP1Tc}`F@WK%r9Pzz2z`m%-K>`6Hz;k_M z7wmmUuRqEcxxx^b6%CxLDY3vqn(Z{_4UII01=^n-m<_x1Sd5fZ!WYg%xbqL2y)- zBlw1b-J%ujpwY*X%OY$3&+nhvclCa|;S8vc&hvlg_{3!L{^!Zb@y+|+*5w%jd*!`g zdNv$#%Y=z(-4p9_k7@!3`<;kLX1LG@uV_h}ea~-WWM!9SDhk?ZIXl!62Yf zYm4fQActfb2L&E(H@I@hl~vii_!C!w;LKUszUzaE*Q5*)YRhFxe3fXZLkh~A#~7mA z#t=I>0dL}34JL<%_=q72=AujW=9@lq8z>H9K(J%Gcyt5|?>#s-KVpM@0!qOD3hzX3 zGTaab&9OsAK?M=!R^19@i0+b5b6U<kX`8fynp9$n`iwFFm$+}l4oGW&Ix_uv1wR44YU_s4z7-Guyv4d=it84+B1M;F~ z00Dmi_$P(awlsg;ENqvK^69YGie^{uPu4u_KGjw`h5CK6Ixq=cF>q{i`L34oh4@ev-ML(3kZ=)i$Y8zUJS;<`)0euB{E|k%#Xh*8YLIO${1Ox}f6<*x1 zRAN=N`=xjvP*MgNsy01};$Zd)rCERNpmcq47$%O$B*i;Gsq6QL$bO+DWmrjp*awvJ zduL_=K@>Mh1@!}LUr<(vlLchYP|nWpTLB{b=1b+j;0luos)mxvs03H~s)fcXbgNc0 zZzt@DO9us|5cK;A!K5z{zvj|?P*305T5qlPvCgdd5;Lf0Z2&bV0up>?H-j314vK=q z<$ej5%?B7*ay<_qpEgAZd}f4y&21rHItrJNcq5w>W{tGEY;d3o7NQ**$>Ixo*^@gT zuIi1|30?xw2LeE08Hx9l+i7ANN{9gz#)chfRLKsKd+hpyvBMs|Dvf}+0;Xo;fd;H~ zSGd;8dRg()ZH}y$(X-;mr|Vb2SiEXZ%I=?@s21mk1?}C z1x<&CusV``0ZX55-MX*?P=vs>2XwXThKEEMf-xHj<3A}QO_7ew1{nhgnw}?P!|6ii z0QTX^A|jFp!91$Dl#w=2Vf}|;15q&Spn#wXWXPG~3lxZVL6GktG8c6OT%R%oosq=Q z!^x66`qGa4Z{s5oZsJ)Q7P1DOf@AfL|#>5S$pEtWH9X6`_! zoQAwl5ox&n)d(*;&H|JyKRucYCY4h4H9xZ#gHab35 zdhzJk?$Od^qcCubMr~Sj{bH$D+BIqj$F|Slnb3V$K~ztvL$Hjz^;~q5h z;BY5qdYC>1T>!`m*`w-g_NcDJCags7ie+vG+eH-UM7LE5!Z_t5={iwvRdS&l?c^p6 z|92q*j%yqonZ6O>6rQZ$tMh_hU3iHjEkuaxpoOl~i|+{W^0Nd<`Jg>Z{9_xOZbFaa z+u^pg03&Tg_tu#JTXCc;D+U#K&B({q6U}m&MXmjvr}-*Z&d1@3+2_+)bggn}d>pQ< zeLg1R%OJA&qz+f&D)fbk^@Q4UK5^7(ga-N|2aMd> zUdTXS7!ivJAczqcwUCIDa;pG(1VN__Dq>}DY*YV>1yL7O0;V{IfTbb?oD=a4I*nxA zcgae>8@EP)J})C0gEz%{aTcbfy;l@P3(8X#5;hjzXQm+!g`lwXBsLDSvs6> z7^j@YeS)HNA?C!@hX=VfjanjnD~y=dsMY9`^=;4|1Fol0#%-%?p=lJzaBj^-U#}Y;GRo#SxCA#H3uLyoLFsiHSc4mo z>a~HDER!c$;Dy;_d86XQ=7x)UwEfdAH$C=yR;jp$_Z3AQU9`?i5 zkmUx}w8?uJCrsoDzqjdn4nTg(CD?DsgCoQhk!wO(mzz^ist^6>av{rRoi*!c!A}n( zaaM)TqdDUGOt|KW3^$}<@SxUDI@PP=zUixQxoQtdQ0F8pdMm;I90uA4M#47za_C58{wZ%?L9JsxG0-7y^e_ z1gt`J_{>p5#YB}=wxLj*g-Y%LANxgJ+8jn&!Cpk|Qhabitq5Wy`Tm70`spJ1Nio0y28dc)AfR=~6<8VNB5sZo!7t$f@_y(yn5+^Dy`gGD zKHcb-NG(9s&W1Q1VzN_StdpRSzB@0T*mUJ&O>1Wg&SEs{I^_Rah~|zurBA~NB;9Ai zRw^SI#mM0i?l_mJjbjS1uQCg?aZ@6oNfA&`D62_tYDqM$kv!@`zpTru7W$^2ab4L! zNSLOdasAHuC83c?dtIp5g?@Fw5M?)5;w3ZxYJ4uLTm_DjE6-O7L@XqtW@oadQ_Asp*P$8PJNx>|LW>z};T_eBKN zUb2>ppt^|tJTHP0iuGLtg;{?R65sV}-EI0F?Dtif*jqQ6y`->W6YP1e zUpoeCTmw+Z0;mpA>_j--G%<6b_+v8;Ans{8%i5!qV+0G)x2z(Z5O5w&a= z7YfE{_AXt`hb09gNAb{R%j(qos9$saGlc?!wQkMIb{MRg&6MoYF1u88P}zlku{2gB zyCw>Spy_#Y*mEmgVHL=(wgHsQ&xIAkw6wxGx^2c=f^E7DxYY;_jJI^f{J^9{VF<{fD~MDYgCSt- zJw`K2Yj;lN+$%?f zbYd-q={h>Gvt}Jh^r09zBwmMrf!G8BhJe6;0D4I5S{U7iJR6TLir7{p`sgxBGbf%7 zO42cA=3pCb)%qf8Uk!u6^@Z4owWZ#N=~QH!N()#-ZMij;6|2fWx_%xI5`MXn(-GM+ zvq=c*5HNuq0wB~Xc_Ezz{~&6IsN}d51LlA=xuiO&&X_z(7n8EaYctGSCvuNCz?8b;XlPq@D^!R&atTdhgW3^whayQn zs&FOV7mLO0Y%mHdD^CRjR2;Zmp?#@@VA{Lg{%u1Vxq z!uwU1mkY5$JAoIC*tTtz^bh&1sqm&@ot|fI=IGIrN9OkxA|HxZ`_rtT?GDei`- z#=mqxml?qsrftlN9?ZQaWvj~LXg-Um-Lc0-BTrg3IW zHV3L)B2_V|@RbwOaPL6f;w;X^a+xL0zak_>8T1fgG)6X+n@R{{ZfPURK%=d4u!_W$ z2~tg4){X==r!7nH{I*2V9y4PmJJ_nH`t`htM7GTQjGu*Y-k~!ACJY$OOm7`tY?e`l zd7`q;pete-XaFlHJPZ+W11Mr}1I0cEZ`wL*bD3uwe7J0J0S77CH3^DE2UW0xMhaPo zD6I$)B@+>)!62fv28bwSBSNPYJFbs(s~|rNO7@sNRw!J1#0Q6Q3pL7!fYQVcFg`Xu zwnJq}7}p6R!4jlE7$n?Ss=B^Q>&S`DlGR*RZNI;wUX6MA`l$hwMUO z`}UI}mQDe_ga`tz%I$_!KISA6UbcOEp-=>KI>uSOrV<@G51JgWIE)lmPZq$i5+DK% z6`md) zQl*OmxT50nF3|7}kHwiu2DJy$7S@{gc7a&2_HP%tNTZ~6n5d{nFQ~&ZVs1rDD537w zaRb+ok2vL*U_0h^)v4`_GeSZv&UoCZfG}DfM+Vixi*I3i2UwahPC9 z5=uE>%-Rk{ly|QMmY$8!Z*w|EU__&krzYcb%^aGXGaPK%3GO&D)Otct6%j3_uEo`= zD;$ubn1d@#ZsiE7b)Gw|@#|X?*EignB=P7___Nrgs91p%(GfLE)F;0tiKoZFFlbG1 zW;sq#wdn!R^%tq+1>H06F_u4*H5n!@^ynx-6niaH yGKz~M$g%_~@-c}1immY?!|Lb6<0&EU=Ck>1KAX=vJ^w!d0RR7x0A2n7*aiSA(gEB6 literal 0 HcmV?d00001 diff --git a/chart/deps/redis/Chart.lock b/chart/deps/redis/Chart.lock index 20b9cde..3b577ef 100644 --- a/chart/deps/redis/Chart.lock +++ b/chart/deps/redis/Chart.lock @@ -1,6 +1,6 @@ dependencies: - name: common repository: https://charts.bitnami.com/bitnami - version: 1.4.1 -digest: sha256:81be4c0ebd0a81952423b24268e82697231b8c07991ee60b23b950ff1db003a2 -generated: "2021-02-24T06:54:40.099558726Z" + version: 1.5.2 +digest: sha256:7b5a8ece9b57d70ef47eb7ed27e6f66b059fb0fc1f2ca59a15bb495e32366690 +generated: "2021-06-07T12:05:28.337668-06:00" diff --git a/chart/deps/redis/Chart.yaml b/chart/deps/redis/Chart.yaml index f85fabd..b963b25 100644 --- a/chart/deps/redis/Chart.yaml +++ b/chart/deps/redis/Chart.yaml @@ -1,7 +1,7 @@ annotations: category: Database apiVersion: v2 -appVersion: 6.0.12 +appVersion: 6.2.2 dependencies: - name: common repository: https://charts.bitnami.com/bitnami @@ -25,4 +25,4 @@ name: redis sources: - https://github.com/bitnami/bitnami-docker-redis - http://redis.io/ -version: 12.8.3-bb.0 +version: 14.1.0-bb.0 diff --git a/chart/deps/redis/Kptfile b/chart/deps/redis/Kptfile index b06bf30..229270c 100644 --- a/chart/deps/redis/Kptfile +++ b/chart/deps/redis/Kptfile @@ -5,7 +5,7 @@ metadata: upstream: type: git git: - commit: ba3a0e31485ed629e379487ceff44ff4863e28ef + commit: 7197041c0f82be53dfb9986565627b053988317c repo: https://repo1.dso.mil/platform-one/big-bang/apps/sandbox/redis directory: /chart - ref: main + ref: upgrade-redis diff --git a/chart/deps/redis/README.md b/chart/deps/redis/README.md index f0601e4..10646e2 100644 --- a/chart/deps/redis/README.md +++ b/chart/deps/redis/README.md @@ -59,255 +59,374 @@ The command removes all the Kubernetes components associated with the chart and ## Parameters -The following table lists the configurable parameters of the RedisTM chart and their default values. - -| Parameter | Description | Default | -|:------------------------------------------------------|:----------------------------------------------------------------------------------------------------------------------------------------------------|:--------------------------------------------------------| -| `global.imageRegistry` | Global Docker image registry | `nil` | -| `global.imagePullSecrets` | Global Docker registry secret names as an array | `[]` (does not add image pull secrets to deployed pods) | -| `global.storageClass` | Global storage class for dynamic provisioning | `nil` | -| `global.redis.password` | RedisTM password (overrides `password`) | `nil` | -| `image.registry` | RedisTM Image registry | `docker.io` | -| `image.repository` | RedisTM Image name | `bitnami/redis` | -| `image.tag` | RedisTM Image tag | `{TAG_NAME}` | -| `image.pullPolicy` | Image pull policy | `IfNotPresent` | -| `image.pullSecrets` | Specify docker-registry secret names as an array | `nil` | -| `nameOverride` | String to partially override redis.fullname template with a string (will prepend the release name) | `nil` | -| `fullnameOverride` | String to fully override redis.fullname template with a string | `nil` | -| `cluster.enabled` | Use master-slave topology | `true` | -| `cluster.slaveCount` | Number of slaves | `2` | -| `existingSecret` | Name of existing secret object (for password authentication) | `nil` | -| `existingSecretPasswordKey` | Name of key containing password to be retrieved from the existing secret | `nil` | -| `usePassword` | Use password | `true` | -| `usePasswordFile` | Mount passwords as files instead of environment variables | `false` | -| `password` | RedisTM password (ignored if existingSecret set) | Randomly generated | -| `configmap` | Additional common RedisTM node configuration (this value is evaluated as a template) | See values.yaml | -| `clusterDomain` | Kubernetes DNS Domain name to use | `cluster.local` | -| `networkPolicy.enabled` | Enable NetworkPolicy | `false` | -| `networkPolicy.allowExternal` | Don't require client label for connections | `true` | -| `networkPolicy.ingressNSMatchLabels` | Allow connections from other namespaces | `{}` | -| `networkPolicy.ingressNSPodMatchLabels` | For other namespaces match by pod labels and namespace labels | `{}` | -| `securityContext.*` | Other pod security context to be included as-is in the pod spec | `{}` | -| `securityContext.enabled` | Enable security context (both redis master and slave pods) | `true` | -| `securityContext.fsGroup` | Group ID for the container (both redis master and slave pods) | `1001` | -| `containerSecurityContext.*` | Other container security context to be included as-is in the container spec | `{}` | -| `containerSecurityContext.enabled` | Enable security context (both redis master and slave containers) | `true` | -| `containerSecurityContext.runAsUser` | User ID for the container (both redis master and slave containers) | `1001` | -| `serviceAccount.create` | Specifies whether a ServiceAccount should be created | `false` | -| `serviceAccount.name` | The name of the ServiceAccount to create | Generated using the fullname template | -| `serviceAccount.annotations` | Specifies annotations to add to ServiceAccount. | `nil` | -| `rbac.create` | Specifies whether RBAC resources should be created | `false` | -| `rbac.role.rules` | Rules to create | `[]` | -| `metrics.enabled` | Start a side-car prometheus exporter | `false` | -| `metrics.image.registry` | RedisTM exporter image registry | `docker.io` | -| `metrics.image.repository` | RedisTM exporter image name | `bitnami/redis-exporter` | -| `metrics.image.tag` | RedisTM exporter image tag | `{TAG_NAME}` | -| `metrics.image.pullPolicy` | Image pull policy | `IfNotPresent` | -| `metrics.image.pullSecrets` | Specify docker-registry secret names as an array | `nil` | -| `metrics.extraArgs` | Extra arguments for the binary; possible values [here](https://github.com/oliver006/redis_exporter#flags) | {} | -| `metrics.podLabels` | Additional labels for Metrics exporter pod | {} | -| `metrics.podAnnotations` | Additional annotations for Metrics exporter pod | {} | -| `metrics.resources` | Exporter resource requests/limit | Memory: `256Mi`, CPU: `100m` | -| `metrics.serviceMonitor.enabled` | if `true`, creates a Prometheus Operator ServiceMonitor (also requires `metrics.enabled` to be `true`) | `false` | -| `metrics.serviceMonitor.namespace` | Optional namespace which Prometheus is running in | `nil` | -| `metrics.serviceMonitor.interval` | How frequently to scrape metrics (use by default, falling back to Prometheus' default) | `nil` | -| `metrics.serviceMonitor.selector` | Default to kube-prometheus install (CoreOS recommended), but should be set according to Prometheus install | `{ prometheus: kube-prometheus }` | -| `metrics.serviceMonitor.relabelings` | ServiceMonitor relabelings. Value is evaluated as a template | `[]` | -| `metrics.serviceMonitor.metricRelabelings` | ServiceMonitor metricRelabelings. Value is evaluated as a template | `[]` | -| `metrics.service.type` | Kubernetes Service type (redis metrics) | `ClusterIP` | -| `metrics.service.externalTrafficPolicy` | External traffic policy (when service type is LoadBalancer) | `Cluster` | -| `metrics.service.annotations` | Annotations for the services to monitor (redis master and redis slave service) | {} | -| `metrics.service.labels` | Additional labels for the metrics service | {} | -| `metrics.service.loadBalancerIP` | loadBalancerIP if redis metrics service type is `LoadBalancer` | `nil` | -| `metrics.priorityClassName` | Metrics exporter pod priorityClassName | `nil` | -| `metrics.prometheusRule.enabled` | Set this to true to create prometheusRules for Prometheus operator | `false` | -| `metrics.prometheusRule.additionalLabels` | Additional labels that can be used so prometheusRules will be discovered by Prometheus | `{}` | -| `metrics.prometheusRule.namespace` | namespace where prometheusRules resource should be created | Same namespace as redis | -| `metrics.prometheusRule.rules` | [rules](https://prometheus.io/docs/prometheus/latest/configuration/alerting_rules/) to be created, check values for an example. | `[]` | -| `persistence.existingClaim` | Provide an existing PersistentVolumeClaim | `nil` | -| `master.persistence.enabled` | Use a PVC to persist data (master node) | `true` | -| `master.hostAliases` | Add deployment host aliases | `[]` | -| `master.persistence.path` | Path to mount the volume at, to use other images | `/data` | -| `master.persistence.subPath` | Subdirectory of the volume to mount at | `""` | -| `master.persistence.storageClass` | Storage class of backing PVC | `generic` | -| `master.persistence.accessModes` | Persistent Volume Access Modes | `[ReadWriteOnce]` | -| `master.persistence.size` | Size of data volume | `8Gi` | -| `master.persistence.matchLabels` | matchLabels persistent volume selector | `{}` | -| `master.persistence.matchExpressions` | matchExpressions persistent volume selector | `{}` | -| `master.persistence.volumes` | Additional volumes without creating PVC | `{}` | -| `master.statefulset.labels` | Additional labels for redis master StatefulSet | `{}` | -| `master.statefulset.annotations` | Additional annotations for redis master StatefulSet | `{}` | -| `master.statefulset.updateStrategy` | Update strategy for StatefulSet | onDelete | -| `master.statefulset.rollingUpdatePartition` | Partition update strategy | `nil` | -| `master.statefulset.volumeClaimTemplates.labels` | Additional labels for redis master StatefulSet volumeClaimTemplates | `{}` | -| `master.statefulset.volumeClaimTemplates.annotations` | Additional annotations for redis master StatefulSet volumeClaimTemplates | `{}` | -| `master.podLabels` | Additional labels for RedisTM master pod | {} | -| `master.podAnnotations` | Additional annotations for RedisTM master pod | {} | -| `master.extraEnvVars` | Additional Environment Variables passed to the pod of the master's stateful set set | `[]` | -| `master.extraEnvVarCMs` | Additional Environment Variables ConfigMappassed to the pod of the master's stateful set set | `[]` | -| `master.extraEnvVarsSecret` | Additional Environment Variables Secret passed to the master's stateful set | `[]` | -| `podDisruptionBudget.enabled` | Pod Disruption Budget toggle | `false` | -| `podDisruptionBudget.minAvailable` | Minimum available pods | `1` | -| `podDisruptionBudget.maxUnavailable` | Maximum unavailable | `nil` | -| `redisPort` | RedisTM port (in both master and slaves) | `6379` | -| `tls.enabled` | Enable TLS support for replication traffic | `false` | -| `tls.authClients` | Require clients to authenticate or not | `true` | -| `tls.certificatesSecret` | Name of the secret that contains the certificates | `nil` | -| `tls.certFilename` | Certificate filename | `nil` | -| `tls.certKeyFilename` | Certificate key filename | `nil` | -| `tls.certCAFilename` | CA Certificate filename | `nil` | -| `tls.dhParamsFilename` | DH params (in order to support DH based ciphers) | `nil` | -| `master.command` | RedisTM master entrypoint string. The command `redis-server` is executed if this is not provided. Note this is prepended with `exec` | `/run.sh` | -| `master.preExecCmds` | Text to inset into the startup script immediately prior to `master.command`. Use this if you need to run other ad-hoc commands as part of startup | `nil` | -| `master.configmap` | Additional RedisTM configuration for the master nodes (this value is evaluated as a template) | `nil` | -| `master.disableCommands` | Array of RedisTM commands to disable (master) | `["FLUSHDB", "FLUSHALL"]` | -| `master.extraFlags` | RedisTM master additional command line flags | [] | -| `master.nodeSelector` | RedisTM master Node labels for pod assignment | {"beta.kubernetes.io/arch": "amd64"} | -| `master.tolerations` | Toleration labels for RedisTM master pod assignment | [] | -| `master.affinity` | Affinity settings for RedisTM master pod assignment | {} | -| `master.schedulerName` | Name of an alternate scheduler | `nil` | -| `master.service.type` | Kubernetes Service type (redis master) | `ClusterIP` | -| `master.service.externalTrafficPolicy` | External traffic policy (when service type is LoadBalancer) | `Cluster` | -| `master.service.port` | Kubernetes Service port (redis master) | `6379` | -| `master.service.nodePort` | Kubernetes Service nodePort (redis master) | `nil` | -| `master.service.annotations` | annotations for redis master service | {} | -| `master.service.labels` | Additional labels for redis master service | {} | -| `master.service.loadBalancerIP` | loadBalancerIP if redis master service type is `LoadBalancer` | `nil` | -| `master.service.loadBalancerSourceRanges` | loadBalancerSourceRanges if redis master service type is `LoadBalancer` | `nil` | -| `master.resources` | RedisTM master CPU/Memory resource requests/limits | Memory: `256Mi`, CPU: `100m` | -| `master.livenessProbe.enabled` | Turn on and off liveness probe (redis master pod) | `true` | -| `master.livenessProbe.initialDelaySeconds` | Delay before liveness probe is initiated (redis master pod) | `5` | -| `master.livenessProbe.periodSeconds` | How often to perform the probe (redis master pod) | `5` | -| `master.livenessProbe.timeoutSeconds` | When the probe times out (redis master pod) | `5` | -| `master.livenessProbe.successThreshold` | Minimum consecutive successes for the probe to be considered successful after having failed (redis master pod) | `1` | -| `master.livenessProbe.failureThreshold` | Minimum consecutive failures for the probe to be considered failed after having succeeded. | `5` | -| `master.readinessProbe.enabled` | Turn on and off readiness probe (redis master pod) | `true` | -| `master.readinessProbe.initialDelaySeconds` | Delay before readiness probe is initiated (redis master pod) | `5` | -| `master.readinessProbe.periodSeconds` | How often to perform the probe (redis master pod) | `5` | -| `master.readinessProbe.timeoutSeconds` | When the probe times out (redis master pod) | `1` | -| `master.readinessProbe.successThreshold` | Minimum consecutive successes for the probe to be considered successful after having failed (redis master pod) | `1` | -| `master.readinessProbe.failureThreshold` | Minimum consecutive failures for the probe to be considered failed after having succeeded. | `5` | -| `master.shareProcessNamespace` | RedisTM Master pod `shareProcessNamespace` option. Enables /pause reap zombie PIDs. | `false` | -| `master.priorityClassName` | RedisTM Master pod priorityClassName | `nil` | -| `volumePermissions.enabled` | Enable init container that changes volume permissions in the registry (for cases where the default k8s `runAsUser` and `fsUser` values do not work) | `false` | -| `volumePermissions.image.registry` | Init container volume-permissions image registry | `docker.io` | -| `volumePermissions.image.repository` | Init container volume-permissions image name | `bitnami/bitnami-shell` | -| `volumePermissions.image.tag` | Init container volume-permissions image tag | `"10"` | -| `volumePermissions.image.pullPolicy` | Init container volume-permissions image pull policy | `Always` | -| `volumePermissions.resources ` | Init container volume-permissions CPU/Memory resource requests/limits | {} | -| `volumePermissions.securityContext.*` | Security context of the init container | `{}` | -| `volumePermissions.securityContext.runAsUser` | UserID for the init container (when facing issues in OpenShift or uid unknown, try value "auto") | 0 | -| `slave.hostAliases` | Add deployment host aliases | `[]` | -| `slave.service.type` | Kubernetes Service type (redis slave) | `ClusterIP` | -| `slave.service.externalTrafficPolicy` | External traffic policy (when service type is LoadBalancer) | `Cluster` | -| `slave.service.nodePort` | Kubernetes Service nodePort (redis slave) | `nil` | -| `slave.service.annotations` | annotations for redis slave service | {} | -| `slave.service.labels` | Additional labels for redis slave service | {} | -| `slave.service.port` | Kubernetes Service port (redis slave) | `6379` | -| `slave.service.loadBalancerIP` | LoadBalancerIP if RedisTM slave service type is `LoadBalancer` | `nil` | -| `slave.service.loadBalancerSourceRanges` | loadBalancerSourceRanges if RedisTM slave service type is `LoadBalancer` | `nil` | -| `slave.command` | RedisTM slave entrypoint string. The command `redis-server` is executed if this is not provided. Note this is prepended with `exec` | `/run.sh` | -| `slave.preExecCmds` | Text to inset into the startup script immediately prior to `slave.command`. Use this if you need to run other ad-hoc commands as part of startup | `nil` | -| `slave.configmap` | Additional RedisTM configuration for the slave nodes (this value is evaluated as a template) | `nil` | -| `slave.disableCommands` | Array of RedisTM commands to disable (slave) | `[FLUSHDB, FLUSHALL]` | -| `slave.extraFlags` | RedisTM slave additional command line flags | `[]` | -| `slave.livenessProbe.enabled` | Turn on and off liveness probe (redis slave pod) | `true` | -| `slave.livenessProbe.initialDelaySeconds` | Delay before liveness probe is initiated (redis slave pod) | `5` | -| `slave.livenessProbe.periodSeconds` | How often to perform the probe (redis slave pod) | `5` | -| `slave.livenessProbe.timeoutSeconds` | When the probe times out (redis slave pod) | `5` | -| `slave.livenessProbe.successThreshold` | Minimum consecutive successes for the probe to be considered successful after having failed (redis slave pod) | `1` | -| `slave.livenessProbe.failureThreshold` | Minimum consecutive failures for the probe to be considered failed after having succeeded. | `5` | -| `slave.readinessProbe.enabled` | Turn on and off slave.readiness probe (redis slave pod) | `true` | -| `slave.readinessProbe.initialDelaySeconds` | Delay before slave.readiness probe is initiated (redis slave pod) | `5` | -| `slave.readinessProbe.periodSeconds` | How often to perform the probe (redis slave pod) | `5` | -| `slave.readinessProbe.timeoutSeconds` | When the probe times out (redis slave pod) | `1` | -| `slave.readinessProbe.successThreshold` | Minimum consecutive successes for the probe to be considered successful after having failed (redis slave pod) | `1` | -| `slave.readinessProbe.failureThreshold` | Minimum consecutive failures for the probe to be considered failed after having succeeded. (redis slave pod) | `5` | -| `slave.shareProcessNamespace` | RedisTM slave pod `shareProcessNamespace` option. Enables /pause reap zombie PIDs. | `false` | -| `slave.persistence.enabled` | Use a PVC to persist data (slave node) | `true` | -| `slave.persistence.path` | Path to mount the volume at, to use other images | `/data` | -| `slave.persistence.subPath` | Subdirectory of the volume to mount at | `""` | -| `slave.persistence.storageClass` | Storage class of backing PVC | `generic` | -| `slave.persistence.accessModes` | Persistent Volume Access Modes | `[ReadWriteOnce]` | -| `slave.persistence.size` | Size of data volume | `8Gi` | -| `slave.persistence.matchLabels` | matchLabels persistent volume selector | `{}` | -| `slave.persistence.matchExpressions` | matchExpressions persistent volume selector | `{}` | -| `slave.statefulset.labels` | Additional labels for redis slave StatefulSet | `{}` | -| `slave.statefulset.annotations` | Additional annotations for redis slave StatefulSet | `{}` | -| `slave.statefulset.updateStrategy` | Update strategy for StatefulSet | onDelete | -| `slave.statefulset.rollingUpdatePartition` | Partition update strategy | `nil` | -| `slave.statefulset.volumeClaimTemplates.labels` | Additional labels for redis slave StatefulSet volumeClaimTemplates | `{}` | -| `slave.statefulset.volumeClaimTemplates.annotations` | Additional annotations for redis slave StatefulSet volumeClaimTemplates | `{}` | -| `slave.extraEnvVars` | Additional Environment Variables passed to the pod of the slave's stateful set set | `[]` | -| `slave.extraEnvVarCMs` | Additional Environment Variables ConfigMappassed to the pod of the slave's stateful set set | `[]` | -| `masslaveter.extraEnvVarsSecret` | Additional Environment Variables Secret passed to the slave's stateful set | `[]` | -| `slave.podLabels` | Additional labels for RedisTM slave pod | `master.podLabels` | -| `slave.podAnnotations` | Additional annotations for RedisTM slave pod | `master.podAnnotations` | -| `slave.schedulerName` | Name of an alternate scheduler | `nil` | -| `slave.resources` | RedisTM slave CPU/Memory resource requests/limits | `{}` | -| `slave.affinity` | Enable node/pod affinity for slaves | {} | -| `slave.tolerations` | Toleration labels for RedisTM slave pod assignment | [] | -| `slave.spreadConstraints` | [Topology Spread Constraints](https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/) for RedisTM slave pod | {} | -| `slave.priorityClassName` | RedisTM Slave pod priorityClassName | `nil` | -| `sentinel.enabled` | Enable sentinel containers | `false` | -| `sentinel.usePassword` | Use password for sentinel containers | `true` | -| `sentinel.masterSet` | Name of the sentinel master set | `mymaster` | -| `sentinel.initialCheckTimeout` | Timeout for querying the redis sentinel service for the active sentinel list | `5` | -| `sentinel.quorum` | Quorum for electing a new master | `2` | -| `sentinel.downAfterMilliseconds` | Timeout for detecting a RedisTM node is down | `60000` | -| `sentinel.failoverTimeout` | Timeout for performing a election failover | `18000` | -| `sentinel.parallelSyncs` | Number of parallel syncs in the cluster | `1` | -| `sentinel.port` | RedisTM Sentinel port | `26379` | -| `sentinel.cleanDelaySeconds` | Delay seconds before issuing the the cleaning in the next node | `5` | -| `sentinel.configmap` | Additional RedisTM configuration for the sentinel nodes (this value is evaluated as a template) | `nil` | -| `sentinel.staticID` | Enable static IDs for sentinel replicas (If disabled IDs will be randomly generated on startup) | `false` | -| `sentinel.service.type` | Kubernetes Service type (redis sentinel) | `ClusterIP` | -| `sentinel.service.externalTrafficPolicy` | External traffic policy (when service type is LoadBalancer) | `Cluster` | -| `sentinel.service.nodePort` | Kubernetes Service nodePort (redis sentinel) | `nil` | -| `sentinel.service.annotations` | annotations for redis sentinel service | {} | -| `sentinel.service.labels` | Additional labels for redis sentinel service | {} | -| `sentinel.service.redisPort` | Kubernetes Service port for RedisTM read only operations | `6379` | -| `sentinel.service.sentinelPort` | Kubernetes Service port for RedisTM sentinel | `26379` | -| `sentinel.service.redisNodePort` | Kubernetes Service node port for RedisTM read only operations | `` | -| `sentinel.service.sentinelNodePort` | Kubernetes Service node port for RedisTM sentinel | `` | -| `sentinel.service.loadBalancerIP` | LoadBalancerIP if RedisTM sentinel service type is `LoadBalancer` | `nil` | -| `sentinel.livenessProbe.enabled` | Turn on and off liveness probe (redis sentinel pod) | `true` | -| `sentinel.livenessProbe.initialDelaySeconds` | Delay before liveness probe is initiated (redis sentinel pod) | `5` | -| `sentinel.livenessProbe.periodSeconds` | How often to perform the probe (redis sentinel container) | `5` | -| `sentinel.livenessProbe.timeoutSeconds` | When the probe times out (redis sentinel container) | `5` | -| `sentinel.livenessProbe.successThreshold` | Minimum consecutive successes for the probe to be considered successful after having failed (redis sentinel container) | `1` | -| `sentinel.livenessProbe.failureThreshold` | Minimum consecutive failures for the probe to be considered failed after having succeeded. | `5` | -| `sentinel.readinessProbe.enabled` | Turn on and off sentinel.readiness probe (redis sentinel pod) | `true` | -| `sentinel.readinessProbe.initialDelaySeconds` | Delay before sentinel.readiness probe is initiated (redis sentinel pod) | `5` | -| `sentinel.readinessProbe.periodSeconds` | How often to perform the probe (redis sentinel pod) | `5` | -| `sentinel.readinessProbe.timeoutSeconds` | When the probe times out (redis sentinel container) | `1` | -| `sentinel.readinessProbe.successThreshold` | Minimum consecutive successes for the probe to be considered successful after having failed (redis sentinel container) | `1` | -| `sentinel.readinessProbe.failureThreshold` | Minimum consecutive failures for the probe to be considered failed after having succeeded. (redis sentinel container) | `5` | -| `sentinel.resources` | RedisTM sentinel CPU/Memory resource requests/limits | `{}` | -| `sentinel.image.registry` | RedisTM Sentinel Image registry | `docker.io` | -| `sentinel.image.repository` | RedisTM Sentinel Image name | `bitnami/redis-sentinel` | -| `sentinel.image.tag` | RedisTM Sentinel Image tag | `{TAG_NAME}` | -| `sentinel.image.pullPolicy` | Image pull policy | `IfNotPresent` | -| `sentinel.image.pullSecrets` | Specify docker-registry secret names as an array | `nil` | -| `sentinel.extraEnvVars` | Additional Environment Variables passed to the pod of the sentinel node stateful set set | `[]` | -| `sentinel.extraEnvVarCMs` | Additional Environment Variables ConfigMappassed to the pod of the sentinel node stateful set set | `[]` | -| `sentinel.extraEnvVarsSecret` | Additional Environment Variables Secret passed to the sentinel node statefulset | `[]` | -| `sentinel.preExecCmds` | Text to inset into the startup script immediately prior to `sentinel.command`. Use this if you need to run other ad-hoc commands as part of startup | `nil` | -| `sysctlImage.enabled` | Enable an init container to modify Kernel settings | `false` | -| `sysctlImage.command` | sysctlImage command to execute | [] | -| `sysctlImage.registry` | sysctlImage Init container registry | `docker.io` | -| `sysctlImage.repository` | sysctlImage Init container name | `bitnami/bitnami-shell` | -| `sysctlImage.tag` | sysctlImage Init container tag | `"10"` | -| `sysctlImage.pullPolicy` | sysctlImage Init container pull policy | `Always` | -| `sysctlImage.mountHostSys` | Mount the host `/sys` folder to `/host-sys` | `false` | -| `sysctlImage.resources` | sysctlImage Init container CPU/Memory resource requests/limits | {} | -| `podSecurityPolicy.create` | Specifies whether a PodSecurityPolicy should be created | `false` | +### Global parameters + +| Name | Description | Value | +| ------------------------- | ----------------------------------------------------- | ----- | +| `global.imageRegistry` | Global Docker image registry | `nil` | +| `global.imagePullSecrets` | Global Docker registry secret names as an array | `[]` | +| `global.storageClass` | Global StorageClass for Persistent Volume(s) | `nil` | +| `global.redis.password` | Global Redis(TM) password (overrides `auth.password`) | `nil` | + + +### Common parameters + +| Name | Description | Value | +| ------------------- | -------------------------------------------------- | --------------- | +| `kubeVersion` | Override Kubernetes version | `nil` | +| `nameOverride` | String to partially override common.names.fullname | `nil` | +| `fullnameOverride` | String to fully override common.names.fullname | `nil` | +| `commonLabels` | Labels to add to all deployed objects | `{}` | +| `commonAnnotations` | Annotations to add to all deployed objects | `{}` | +| `clusterDomain` | Kubernetes cluster domain name | `cluster.local` | +| `extraDeploy` | Array of extra objects to deploy with the release | `[]` | + + +### Redis(TM) Image parameters + +| Name | Description | Value | +| ------------------- | ---------------------------------------------------- | --------------------- | +| `image.registry` | Redis(TM) image registry | `docker.io` | +| `image.repository` | Redis(TM) image repository | `bitnami/redis` | +| `image.tag` | Redis(TM) image tag (immutable tags are recommended) | `6.2.1-debian-10-r36` | +| `image.pullPolicy` | Redis(TM) image pull policy | `IfNotPresent` | +| `image.pullSecrets` | Redis(TM) image pull secrets | `[]` | +| `image.debug` | Enable image debug mode | `false` | + + +### Redis(TM) common configuration parameters + +| Name | Description | Value | +| -------------------------------- | ------------------------------------------------------------------------------------ | ------------- | +| `architecture` | Redis(TM) architecture. Allowed values: `standalone` or `replication` | `replication` | +| `auth.enabled` | Enable password authentication | `true` | +| `auth.sentinel` | Enable password authentication on sentinels too | `true` | +| `auth.password` | Redis(TM) password | `""` | +| `auth.existingSecret` | The name of an existing secret with Redis(TM) credentials | `nil` | +| `auth.existingSecretPasswordKey` | Password key to be retrieved from existing secret | `nil` | +| `auth.usePasswordFiles` | Mount credentials as files instead of using an environment variable | `false` | +| `existingConfigmap` | The name of an existing ConfigMap with your custom configuration for Redis(TM) nodes | `nil` | + + +### Redis(TM) master configuration parameters + +| Name | Description | Value | +| ------------------------------------------- | ------------------------------------------------------------------------------------------------ | --------------- | +| `master.configuration` | Configuration for Redis(TM) master nodes | `nil` | +| `master.disableCommands` | Array with Redis(TM) commands to disable on master nodes | `[]` | +| `master.command` | Override default container command (useful when using custom images) | `[]` | +| `master.args` | Override default container args (useful when using custom images) | `[]` | +| `master.preExecCmds` | Additional commands to run prior to starting Redis(TM) master | `[]` | +| `master.extraFlags` | Array with additional command line flags for Redis(TM) master | `[]` | +| `master.extraEnvVars` | Array with extra environment variables to add to Redis(TM) master nodes | `[]` | +| `master.extraEnvVarsCM` | Name of existing ConfigMap containing extra env vars for Redis(TM) master nodes | `nil` | +| `master.extraEnvVarsSecret` | Name of existing Secret containing extra env vars for Redis(TM) master nodes | `nil` | +| `master.containerPort` | Container port to open on Redis(TM) master nodes | `6379` | +| `master.livenessProbe.enabled` | Enable livenessProbe on Redis(TM) master nodes | `true` | +| `master.livenessProbe.initialDelaySeconds` | Initial delay seconds for livenessProbe | `5` | +| `master.livenessProbe.periodSeconds` | Period seconds for livenessProbe | `5` | +| `master.livenessProbe.timeoutSeconds` | Timeout seconds for livenessProbe | `5` | +| `master.livenessProbe.failureThreshold` | Failure threshold for livenessProbe | `5` | +| `master.livenessProbe.successThreshold` | Success threshold for livenessProbe | `1` | +| `master.readinessProbe.enabled` | Enable readinessProbe on Redis(TM) master nodes | `true` | +| `master.readinessProbe.initialDelaySeconds` | Initial delay seconds for readinessProbe | `5` | +| `master.readinessProbe.periodSeconds` | Period seconds for readinessProbe | `5` | +| `master.readinessProbe.timeoutSeconds` | Timeout seconds for readinessProbe | `1` | +| `master.readinessProbe.failureThreshold` | Failure threshold for readinessProbe | `5` | +| `master.readinessProbe.successThreshold` | Success threshold for readinessProbe | `1` | +| `master.customLivenessProbe` | Custom livenessProbe that overrides the default one | `{}` | +| `master.customReadinessProbe` | Custom readinessProbe that overrides the default one | `{}` | +| `master.resources.limits` | The resources limits for the Redis(TM) master containers | `{}` | +| `master.resources.requests` | The requested resources for the Redis(TM) master containers | `{}` | +| `master.podSecurityContext.enabled` | Enabled Redis(TM) master pods' Security Context | `true` | +| `master.podSecurityContext.fsGroup` | Set Redis(TM) master pod's Security Context fsGroup | `1001` | +| `master.containerSecurityContext.enabled` | Enabled Redis(TM) master containers' Security Context | `true` | +| `master.containerSecurityContext.runAsUser` | Set Redis(TM) master containers' Security Context runAsUser | `1001` | +| `master.schedulerName` | Alternate scheduler for Redis(TM) master pods | `nil` | +| `master.updateStrategy.type` | Redis(TM) master statefulset strategy type | `RollingUpdate` | +| `master.priorityClassName` | Redis(TM) master pods' priorityClassName | `""` | +| `master.hostAliases` | Redis(TM) master pods host aliases | `[]` | +| `master.podLabels` | Extra labels for Redis(TM) master pods | `{}` | +| `master.podAnnotations` | Annotations for Redis(TM) master pods | `{}` | +| `master.shareProcessNamespace` | Share a single process namespace between all of the containers in Redis(TM) master pods | `false` | +| `master.podAffinityPreset` | Pod affinity preset. Ignored if `master.affinity` is set. Allowed values: `soft` or `hard` | `""` | +| `master.podAntiAffinityPreset` | Pod anti-affinity preset. Ignored if `master.affinity` is set. Allowed values: `soft` or `hard` | `soft` | +| `master.nodeAffinityPreset.type` | Node affinity preset type. Ignored if `master.affinity` is set. Allowed values: `soft` or `hard` | `""` | +| `master.nodeAffinityPreset.key` | Node label key to match. Ignored if `master.affinity` is set | `""` | +| `master.nodeAffinityPreset.values` | Node label values to match. Ignored if `master.affinity` is set | `[]` | +| `master.affinity` | Affinity for Redis(TM) master pods assignment | `{}` | +| `master.nodeSelector` | Node labels for Redis(TM) master pods assignment | `{}` | +| `master.tolerations` | Tolerations for Redis(TM) master pods assignment | `[]` | +| `master.spreadConstraints` | Spread Constraints for Redis(TM) master pod assignment | `{}` | +| `master.lifecycleHooks` | for the Redis(TM) master container(s) to automate configuration before or after startup | `{}` | +| `master.extraVolumes` | Optionally specify extra list of additional volumes for the Redis(TM) master pod(s) | `[]` | +| `master.extraVolumeMounts` | Optionally specify extra list of additional volumeMounts for the Redis(TM) master container(s) | `[]` | +| `master.sidecars` | Add additional sidecar containers to the Redis(TM) master pod(s) | `{}` | +| `master.initContainers` | Add additional init containers to the Redis(TM) master pod(s) | `{}` | +| `master.persistence.enabled` | Enable persistence on Redis(TM) master nodes using Persistent Volume Claims | `true` | +| `master.persistence.path` | The path the volume will be mounted at on Redis(TM) master containers | `/data` | +| `master.persistence.subPath` | The subdirectory of the volume to mount on Redis(TM) master containers | `""` | +| `master.persistence.storageClass` | Persistent Volume storage class | `nil` | +| `master.persistence.accessModes` | Persistent Volume access modes | `[]` | +| `master.persistence.size` | Persistent Volume size | `8Gi` | +| `master.persistence.annotations` | Additional custom annotations for the PVC | `{}` | +| `master.persistence.selector` | Additional labels to match for the PVC | `{}` | +| `master.persistence.existingClaim` | Use a existing PVC which must be created manually before bound | `nil` | +| `master.service.type` | Redis(TM) master service type | `ClusterIP` | +| `master.service.port` | Redis(TM) master service port | `6379` | +| `master.service.nodePort` | Node port for Redis(TM) master | `nil` | +| `master.service.externalTrafficPolicy` | Redis(TM) master service external traffic policy | `Cluster` | +| `master.service.clusterIP` | Redis(TM) master service Cluster IP | `nil` | +| `master.service.loadBalancerIP` | Redis(TM) master service Load Balancer IP | `nil` | +| `master.service.loadBalancerSourceRanges` | Redis(TM) master service Load Balancer sources | `[]` | +| `master.service.annotations` | Additional custom annotations for Redis(TM) master service | `{}` | +| `master.terminationGracePeriodSeconds` | Integer setting the termination grace period for the redis-master pods | `30` | + + +### Redis(TM) replicas configuration parameters + +| Name | Description | Value | +| -------------------------------------------- | ------------------------------------------------------------------------------------------------- | --------------- | +| `replica.replicaCount` | Number of Redis(TM) replicas to deploy | `3` | +| `replica.configuration` | Configuration for Redis(TM) replicas nodes | `nil` | +| `replica.disableCommands` | Array with Redis(TM) commands to disable on replicas nodes | `[]` | +| `replica.command` | Override default container command (useful when using custom images) | `[]` | +| `replica.args` | Override default container args (useful when using custom images) | `[]` | +| `replica.preExecCmds` | Additional commands to run prior to starting Redis(TM) replicas | `[]` | +| `replica.extraFlags` | Array with additional command line flags for Redis(TM) replicas | `[]` | +| `replica.extraEnvVars` | Array with extra environment variables to add to Redis(TM) replicas nodes | `[]` | +| `replica.extraEnvVarsCM` | Name of existing ConfigMap containing extra env vars for Redis(TM) replicas nodes | `nil` | +| `replica.extraEnvVarsSecret` | Name of existing Secret containing extra env vars for Redis(TM) replicas nodes | `nil` | +| `replica.containerPort` | Container port to open on Redis(TM) replicas nodes | `6379` | +| `replica.livenessProbe.enabled` | Enable livenessProbe on Redis(TM) replicas nodes | `true` | +| `replica.livenessProbe.initialDelaySeconds` | Initial delay seconds for livenessProbe | `5` | +| `replica.livenessProbe.periodSeconds` | Period seconds for livenessProbe | `5` | +| `replica.livenessProbe.timeoutSeconds` | Timeout seconds for livenessProbe | `5` | +| `replica.livenessProbe.failureThreshold` | Failure threshold for livenessProbe | `5` | +| `replica.livenessProbe.successThreshold` | Success threshold for livenessProbe | `1` | +| `replica.readinessProbe.enabled` | Enable readinessProbe on Redis(TM) replicas nodes | `true` | +| `replica.readinessProbe.initialDelaySeconds` | Initial delay seconds for readinessProbe | `5` | +| `replica.readinessProbe.periodSeconds` | Period seconds for readinessProbe | `5` | +| `replica.readinessProbe.timeoutSeconds` | Timeout seconds for readinessProbe | `1` | +| `replica.readinessProbe.failureThreshold` | Failure threshold for readinessProbe | `5` | +| `replica.readinessProbe.successThreshold` | Success threshold for readinessProbe | `1` | +| `replica.customLivenessProbe` | Custom livenessProbe that overrides the default one | `{}` | +| `replica.customReadinessProbe` | Custom readinessProbe that overrides the default one | `{}` | +| `replica.resources.limits` | The resources limits for the Redis(TM) replicas containers | `{}` | +| `replica.resources.requests` | The requested resources for the Redis(TM) replicas containers | `{}` | +| `replica.podSecurityContext.enabled` | Enabled Redis(TM) replicas pods' Security Context | `true` | +| `replica.podSecurityContext.fsGroup` | Set Redis(TM) replicas pod's Security Context fsGroup | `1001` | +| `replica.containerSecurityContext.enabled` | Enabled Redis(TM) replicas containers' Security Context | `true` | +| `replica.containerSecurityContext.runAsUser` | Set Redis(TM) replicas containers' Security Context runAsUser | `1001` | +| `replica.schedulerName` | Alternate scheduler for Redis(TM) replicas pods | `nil` | +| `replica.updateStrategy.type` | Redis(TM) replicas statefulset strategy type | `RollingUpdate` | +| `replica.priorityClassName` | Redis(TM) replicas pods' priorityClassName | `""` | +| `replica.hostAliases` | Redis(TM) replicas pods host aliases | `[]` | +| `replica.podLabels` | Extra labels for Redis(TM) replicas pods | `{}` | +| `replica.podAnnotations` | Annotations for Redis(TM) replicas pods | `{}` | +| `replica.shareProcessNamespace` | Share a single process namespace between all of the containers in Redis(TM) replicas pods | `false` | +| `replica.podAffinityPreset` | Pod affinity preset. Ignored if `replica.affinity` is set. Allowed values: `soft` or `hard` | `""` | +| `replica.podAntiAffinityPreset` | Pod anti-affinity preset. Ignored if `replica.affinity` is set. Allowed values: `soft` or `hard` | `soft` | +| `replica.nodeAffinityPreset.type` | Node affinity preset type. Ignored if `replica.affinity` is set. Allowed values: `soft` or `hard` | `""` | +| `replica.nodeAffinityPreset.key` | Node label key to match. Ignored if `replica.affinity` is set | `""` | +| `replica.nodeAffinityPreset.values` | Node label values to match. Ignored if `replica.affinity` is set | `[]` | +| `replica.affinity` | Affinity for Redis(TM) replicas pods assignment | `{}` | +| `replica.nodeSelector` | Node labels for Redis(TM) replicas pods assignment | `{}` | +| `replica.tolerations` | Tolerations for Redis(TM) replicas pods assignment | `[]` | +| `replica.spreadConstraints` | Spread Constraints for Redis(TM) replicas pod assignment | `{}` | +| `replica.lifecycleHooks` | for the Redis(TM) replica container(s) to automate configuration before or after startup | `{}` | +| `replica.extraVolumes` | Optionally specify extra list of additional volumes for the Redis(TM) replicas pod(s) | `[]` | +| `replica.extraVolumeMounts` | Optionally specify extra list of additional volumeMounts for the Redis(TM) replicas container(s) | `[]` | +| `replica.sidecars` | Add additional sidecar containers to the Redis(TM) replicas pod(s) | `{}` | +| `replica.initContainers` | Add additional init containers to the Redis(TM) replicas pod(s) | `{}` | +| `replica.persistence.enabled` | Enable persistence on Redis(TM) replicas nodes using Persistent Volume Claims | `true` | +| `replica.persistence.path` | The path the volume will be mounted at on Redis(TM) replicas containers | `/data` | +| `replica.persistence.subPath` | The subdirectory of the volume to mount on Redis(TM) replicas containers | `""` | +| `replica.persistence.storageClass` | Persistent Volume storage class | `nil` | +| `replica.persistence.accessModes` | Persistent Volume access modes | `[]` | +| `replica.persistence.size` | Persistent Volume size | `8Gi` | +| `replica.persistence.annotations` | Additional custom annotations for the PVC | `{}` | +| `replica.persistence.selector` | Additional labels to match for the PVC | `{}` | +| `replica.service.type` | Redis(TM) replicas service type | `ClusterIP` | +| `replica.service.port` | Redis(TM) replicas service port | `6379` | +| `replica.service.nodePort` | Node port for Redis(TM) replicas | `nil` | +| `replica.service.externalTrafficPolicy` | Redis(TM) replicas service external traffic policy | `Cluster` | +| `replica.service.clusterIP` | Redis(TM) replicas service Cluster IP | `nil` | +| `replica.service.loadBalancerIP` | Redis(TM) replicas service Load Balancer IP | `nil` | +| `replica.service.loadBalancerSourceRanges` | Redis(TM) replicas service Load Balancer sources | `[]` | +| `replica.service.annotations` | Additional custom annotations for Redis(TM) replicas service | `{}` | +| `replica.terminationGracePeriodSeconds` | Integer setting the termination grace period for the redis-replicas pods | `30` | + + +### Redis(TM) Sentinel configuration parameters + +| Name | Description | Value | +| --------------------------------------------- | ------------------------------------------------------------------------------------------------ | ------------------------ | +| `sentinel.enabled` | Use Redis(TM) Sentinel on Redis(TM) pods. | `false` | +| `sentinel.image.registry` | Redis(TM) Sentinel image registry | `docker.io` | +| `sentinel.image.repository` | Redis(TM) Sentinel image repository | `bitnami/redis-sentinel` | +| `sentinel.image.tag` | Redis(TM) Sentinel image tag (immutable tags are recommended) | `6.0.9-debian-10-r38` | +| `sentinel.image.pullPolicy` | Redis(TM) Sentinel image pull policy | `IfNotPresent` | +| `sentinel.image.pullSecrets` | Redis(TM) Sentinel image pull secrets | `[]` | +| `sentinel.image.debug` | Enable image debug mode | `false` | +| `sentinel.masterSet` | Master set name | `mymaster` | +| `sentinel.quorum` | Sentinel Quorum | `2` | +| `sentinel.downAfterMilliseconds` | Timeout for detecting a Redis(TM) node is down | `60000` | +| `sentinel.failoverTimeout` | Timeout for performing a election failover | `18000` | +| `sentinel.cleanDelaySeconds` | Delay seconds when cleaning nodes IPs | `5` | +| `sentinel.parallelSyncs` | Number of replicas that can be reconfigured in parallel to use the new master after a failover | `1` | +| `sentinel.staticID` | Enable static Sentinel IDs for each replica | `false` | +| `sentinel.configuration` | Configuration for Redis(TM) Sentinel nodes | `nil` | +| `sentinel.command` | Override default container command (useful when using custom images) | `[]` | +| `sentinel.args` | Override default container args (useful when using custom images) | `[]` | +| `sentinel.preExecCmds` | Additional commands to run prior to starting Redis(TM) Sentinel | `[]` | +| `sentinel.containerPort` | Container port to open on Redis(TM) Sentinel nodes | `26379` | +| `sentinel.livenessProbe.enabled` | Enable livenessProbe on Redis(TM) Sentinel nodes | `true` | +| `sentinel.livenessProbe.initialDelaySeconds` | Initial delay seconds for livenessProbe | `5` | +| `sentinel.livenessProbe.periodSeconds` | Period seconds for livenessProbe | `5` | +| `sentinel.livenessProbe.timeoutSeconds` | Timeout seconds for livenessProbe | `5` | +| `sentinel.livenessProbe.failureThreshold` | Failure threshold for livenessProbe | `5` | +| `sentinel.livenessProbe.successThreshold` | Success threshold for livenessProbe | `1` | +| `sentinel.readinessProbe.enabled` | Enable readinessProbe on Redis(TM) Sentinel nodes | `true` | +| `sentinel.readinessProbe.initialDelaySeconds` | Initial delay seconds for readinessProbe | `5` | +| `sentinel.readinessProbe.periodSeconds` | Period seconds for readinessProbe | `5` | +| `sentinel.readinessProbe.timeoutSeconds` | Timeout seconds for readinessProbe | `1` | +| `sentinel.readinessProbe.failureThreshold` | Failure threshold for readinessProbe | `5` | +| `sentinel.readinessProbe.successThreshold` | Success threshold for readinessProbe | `1` | +| `sentinel.customLivenessProbe` | Custom livenessProbe that overrides the default one | `{}` | +| `sentinel.customReadinessProbe` | Custom readinessProbe that overrides the default one | `{}` | +| `sentinel.resources.limits` | The resources limits for the Redis(TM) Sentinel containers | `{}` | +| `sentinel.resources.requests` | The requested resources for the Redis(TM) Sentinel containers | `{}` | +| `sentinel.containerSecurityContext.enabled` | Enabled Redis(TM) Sentinel containers' Security Context | `true` | +| `sentinel.containerSecurityContext.runAsUser` | Set Redis(TM) Sentinel containers' Security Context runAsUser | `1001` | +| `sentinel.lifecycleHooks` | for the Redis(TM) sentinel container(s) to automate configuration before or after startup | `{}` | +| `sentinel.extraVolumes` | Optionally specify extra list of additional volumes for the Redis(TM) Sentinel | `[]` | +| `sentinel.extraVolumeMounts` | Optionally specify extra list of additional volumeMounts for the Redis(TM) Sentinel container(s) | `[]` | +| `sentinel.service.type` | Redis(TM) Sentinel service type | `ClusterIP` | +| `sentinel.service.port` | Redis(TM) service port for Redis(TM) | `6379` | +| `sentinel.service.sentinelPort` | Redis(TM) service port for Sentinel | `26379` | +| `sentinel.service.nodePorts.redis` | Node port for Redis(TM) | `nil` | +| `sentinel.service.nodePorts.sentinel` | Node port for Sentinel | `nil` | +| `sentinel.service.externalTrafficPolicy` | Redis(TM) Sentinel service external traffic policy | `Cluster` | +| `sentinel.service.clusterIP` | Redis(TM) Sentinel service Cluster IP | `nil` | +| `sentinel.service.loadBalancerIP` | Redis(TM) Sentinel service Load Balancer IP | `nil` | +| `sentinel.service.loadBalancerSourceRanges` | Redis(TM) Sentinel service Load Balancer sources | `[]` | +| `sentinel.service.annotations` | Additional custom annotations for Redis(TM) Sentinel service | `{}` | +| `sentinel.terminationGracePeriodSeconds` | Integer setting the termination grace period for the redis-node pods | `30` | + + +### Other Parameters + +| Name | Description | Value | +| --------------------------------------- | ------------------------------------------------------------------- | ------- | +| `networkPolicy.enabled` | Enable creation of NetworkPolicy resources | `false` | +| `networkPolicy.allowExternal` | Don't require client label for connections | `true` | +| `networkPolicy.extraIngress` | Add extra ingress rules to the NetworkPolicy | `[]` | +| `networkPolicy.extraEgress` | Add extra ingress rules to the NetworkPolicy | `[]` | +| `networkPolicy.ingressNSMatchLabels` | Labels to match to allow traffic from other namespaces | `{}` | +| `networkPolicy.ingressNSPodMatchLabels` | Pod labels to match to allow traffic from other namespaces | `{}` | +| `podSecurityPolicy.create` | Specifies whether a PodSecurityPolicy should be created | `false` | +| `rbac.create` | Specifies whether RBAC resources should be created | `false` | +| `rbac.rules` | Custom RBAC rules to set | `[]` | +| `serviceAccount.create` | Specifies whether a ServiceAccount should be created | `true` | +| `serviceAccount.name` | The name of the ServiceAccount to use. | `""` | +| `serviceAccount.annotations` | Additional custom annotations for the ServiceAccount | `{}` | +| `pdb.create` | Specifies whether a ServiceAccount should be created | `false` | +| `pdb.minAvailable` | Min number of pods that must still be available after the eviction | `1` | +| `pdb.maxUnavailable` | Max number of pods that can be unavailable after the eviction | `nil` | +| `tls.enabled` | Enable TLS traffic | `false` | +| `tls.authClients` | Require clients to authenticate | `true` | +| `tls.certificatesSecret` | Then name of the existing secret that contains the TLS certificates | `nil` | +| `tls.certFilename` | Certificate filename | `nil` | +| `tls.certKeyFilename` | Certificate Key filename | `nil` | +| `tls.certCAFilename` | CA Certificate filename | `nil` | +| `tls.dhParamsFilename` | File containing DH params (in order to support DH based ciphers) | `nil` | + + +### Metrics Parameters + +| Name | Description | Value | +| ----------------------------------------------------- | ------------------------------------------------------------------------------------------------ | --------------------------------- | +| `metrics.enabled` | Start a sidecar prometheus exporter to expose Redis(TM) metrics | `false` | +| `metrics.image.registry` | Redis(TM) Exporter image registry | `docker.io` | +| `metrics.image.repository` | Redis(TM) Exporter image repository | `bitnami/redis-exporter` | +| `metrics.image.tag` | Redis(TM) Redis(TM) Exporter image tag (immutable tags are recommended) | `1.20.0-debian-10-r16` | +| `metrics.image.pullPolicy` | Redis(TM) Exporter image pull policy | `IfNotPresent` | +| `metrics.image.pullSecrets` | Redis(TM) Exporter image pull secrets | `[]` | +| `metrics.redisTargetHost` | A way to specify an alternative Redis(TM) hostname | `localhost` | +| `metrics.extraArgs` | Extra arguments for Redis(TM) exporter, for example: | `{}` | +| `metrics.containerSecurityContext.enabled` | Enabled Redis(TM) exporter containers' Security Context | `true` | +| `metrics.containerSecurityContext.runAsUser` | Set Redis(TM) exporter containers' Security Context runAsUser | `1001` | +| `metrics.resources.limits` | The resources limits for the Redis(TM) exporter container | `{}` | +| `metrics.resources.requests` | The requested resources for the Redis(TM) exporter container | `{}` | +| `metrics.podLabels` | Extra labels for Redis(TM) exporter pods | `{}` | +| `metrics.podAnnotations` | Annotations for Redis(TM) exporter pods | `{}` | +| `metrics.service.type` | Redis(TM) exporter service type | `ClusterIP` | +| `metrics.service.port` | Redis(TM) exporter service port | `9121` | +| `metrics.service.externalTrafficPolicy` | Redis(TM) exporter service external traffic policy | `Cluster` | +| `metrics.service.loadBalancerIP` | Redis(TM) exporter service Load Balancer IP | `""` | +| `metrics.service.loadBalancerSourceRanges` | Redis(TM) exporter service Load Balancer sources | `[]` | +| `metrics.service.annotations` | Additional custom annotations for Redis(TM) exporter service | `{}` | +| `metrics.sentinel.enabled` | Start a sidecar prometheus exporter to expose Redis(TM) Sentinel metrics | `false` | +| `metrics.sentinel.image.registry` | Redis(TM) Sentinel Exporter image registry | `docker.io` | +| `metrics.sentinel.image.repository` | Redis(TM) Sentinel Exporter image repository | `bitnami/redis-sentinel-exporter` | +| `metrics.sentinel.image.tag` | Redis(TM) Redis(TM) Sentinel Exporter image tag (immutable tags are recommended) | `1.7.1-debian-10-r109` | +| `metrics.sentinel.image.pullPolicy` | Redis(TM) Sentinel Exporter image pull policy | `IfNotPresent` | +| `metrics.sentinel.image.pullSecrets` | Redis(TM) Sentinel Exporter image pull secrets | `[]` | +| `metrics.sentinel.extraArgs` | Extra arguments for Redis(TM) Sentinel exporter, for example: | `{}` | +| `metrics.sentinel.containerSecurityContext.enabled` | Enabled Redis(TM) Sentinel exporter containers' Security Context | `true` | +| `metrics.sentinel.containerSecurityContext.runAsUser` | Set Redis(TM) Sentinel exporter containers' Security Context runAsUser | `1001` | +| `metrics.sentinel.resources.limits` | The resources limits for the Redis(TM) Sentinel exporter container | `{}` | +| `metrics.sentinel.resources.requests` | The requested resources for the Redis(TM) Sentinel exporter container | `{}` | +| `metrics.sentinel.service.type` | Redis(TM) Sentinel exporter service type | `ClusterIP` | +| `metrics.sentinel.service.port` | Redis(TM) Sentinel exporter service port | `9355` | +| `metrics.sentinel.service.externalTrafficPolicy` | Redis(TM) Sentinel exporter service external traffic policy | `Cluster` | +| `metrics.sentinel.service.loadBalancerIP` | Redis(TM) Sentinel exporter service Load Balancer IP | `""` | +| `metrics.sentinel.service.loadBalancerSourceRanges` | Redis(TM) Sentinel exporter service Load Balancer sources | `[]` | +| `metrics.sentinel.service.annotations` | Additional custom annotations for Redis(TM) Sentinel exporter service | `{}` | +| `metrics.serviceMonitor.enabled` | Create ServiceMonitor resource(s) for scraping metrics using PrometheusOperator | `false` | +| `metrics.serviceMonitor.namespace` | The namespace in which the ServiceMonitor will be created | `nil` | +| `metrics.serviceMonitor.interval` | The interval at which metrics should be scraped | `30s` | +| `metrics.serviceMonitor.scrapeTimeout` | The timeout after which the scrape is ended | `nil` | +| `metrics.serviceMonitor.relabellings` | Metrics relabellings to add to the scrape endpoint | `[]` | +| `metrics.serviceMonitor.honorLabels` | Specify honorLabels parameter to add the scrape endpoint | `false` | +| `metrics.serviceMonitor.additionalLabels` | Additional labels that can be used so ServiceMonitor resource(s) can be discovered by Prometheus | `{}` | +| `metrics.prometheusRule.enabled` | Create a custom prometheusRule Resource for scraping metrics using PrometheusOperator | `false` | +| `metrics.prometheusRule.namespace` | The namespace in which the prometheusRule will be created | `nil` | +| `metrics.prometheusRule.additionalLabels` | Additional labels for the prometheusRule | `{}` | +| `metrics.prometheusRule.rules` | Custom Prometheus rules | `[]` | + + +### Init Container Parameters + +| Name | Description | Value | +| ------------------------------------------------------ | ----------------------------------------------------------------------------------------------- | ----------------------- | +| `volumePermissions.enabled` | Enable init container that changes the owner/group of the PV mount point to `runAsUser:fsGroup` | `false` | +| `volumePermissions.image.registry` | Bitnami Shell image registry | `docker.io` | +| `volumePermissions.image.repository` | Bitnami Shell image repository | `bitnami/bitnami-shell` | +| `volumePermissions.image.tag` | Bitnami Shell image tag (immutable tags are recommended) | `10` | +| `volumePermissions.image.pullPolicy` | Bitnami Shell image pull policy | `Always` | +| `volumePermissions.image.pullSecrets` | Bitnami Shell image pull secrets | `[]` | +| `volumePermissions.resources.limits` | The resources limits for the init container | `{}` | +| `volumePermissions.resources.requests` | The requested resources for the init container | `{}` | +| `volumePermissions.containerSecurityContext.runAsUser` | Set init container's Security Context runAsUser | `0` | +| `sysctl.enabled` | Enable init container to modify Kernel settings | `false` | +| `sysctl.image.registry` | Bitnami Shell image registry | `docker.io` | +| `sysctl.image.repository` | Bitnami Shell image repository | `bitnami/bitnami-shell` | +| `sysctl.image.tag` | Bitnami Shell image tag (immutable tags are recommended) | `10` | +| `sysctl.image.pullPolicy` | Bitnami Shell image pull policy | `Always` | +| `sysctl.image.pullSecrets` | Bitnami Shell image pull secrets | `[]` | +| `sysctl.command` | Override default init-sysctl container command (useful when using custom images) | `[]` | +| `sysctl.mountHostSys` | Mount the host `/sys` folder to `/host-sys` | `false` | +| `sysctl.resources.limits` | The resources limits for the init container | `{}` | +| `sysctl.resources.requests` | The requested resources for the init container | `{}` | + Specify each parameter using the `--set key=value[,key=value]` argument to `helm install`. For example, ```bash $ helm install my-release \ - --set password=secretpassword \ + --set auth.password=secretpassword \ bitnami/redis ``` @@ -323,8 +442,6 @@ $ helm install my-release -f values.yaml bitnami/redis > **Tip**: You can use the default [values.yaml](values.yaml) -> **Note for minikube users**: Current versions of minikube (v0.24.1 at the time of writing) provision `hostPath` persistent volumes that are only writable by root. Using chart defaults cause pod failure for the RedisTM pod as it attempts to write to the `/bitnami` directory. Consider installing RedisTM with `--set persistence.enabled=false`. See minikube issue [1990](https://github.com/kubernetes/minikube/issues/1990) for more information. - ## Configuration and installation details ### [Rolling VS Immutable tags](https://docs.bitnami.com/containers/how-to/understand-rolling-tags-containers/) @@ -339,31 +456,39 @@ To modify the RedisTM version used in this chart you can specify a [v ### Cluster topologies -#### Default: Master-Slave +#### Default: Master-Replicas + +When installing the chart with `architecture=replication`, it will deploy a RedisTM master StatefulSet (only one master node allowed) and a RedisTM replicas StatefulSet. The replicas will be read-replicas of the master. Two services will be exposed: + +- RedisTM Master service: Points to the master, where read-write operations can be performed +- RedisTM Replicas service: Points to the replicas, where only read operations are allowed. -When installing the chart with `cluster.enabled=true`, it will deploy a RedisTM master StatefulSet (only one master node allowed) and a RedisTM slave StatefulSet. The slaves will be read-replicas of the master. Two services will be exposed: +In case the master crashes, the replicas will wait until the master node is respawned again by the Kubernetes Controller Manager. - - RedisTM Master service: Points to the master, where read-write operations can be performed - - RedisTM Slave service: Points to the slaves, where only read operations are allowed. +#### Standalone -In case the master crashes, the slaves will wait until the master node is respawned again by the Kubernetes Controller Manager. +When installing the chart with `architecture=standalone`, it will deploy a standalone RedisTM StatefulSet (only one node allowed) and a RedisTM replicas StatefulSet. A single service will be exposed: -#### Master-Slave with Sentinel +- RedisTM Master service: Points to the master, where read-write operations can be performed -When installing the chart with `cluster.enabled=true` and `sentinel.enabled=true`, it will deploy a RedisTM master StatefulSet (only one master allowed) and a RedisTM slave StatefulSet. In this case, the pods will contain an extra container with RedisTM Sentinel. This container will form a cluster of RedisTM Sentinel nodes, which will promote a new master in case the actual one fails. In addition to this, only one service is exposed: +#### Master-Replicas with Sentinel - - RedisTM service: Exposes port 6379 for RedisTM read-only operations and port 26379 for accessing RedisTM Sentinel. +When installing the chart with `architecture=replication` and `sentinel.enabled=true`, it will deploy a RedisTM master StatefulSet (only one master allowed) and a RedisTM replicas StatefulSet. In this case, the pods will contain an extra container with RedisTM Sentinel. This container will form a cluster of RedisTM Sentinel nodes, which will promote a new master in case the actual one fails. In addition to this, only one service is exposed: -For read-only operations, access the service using port 6379. For write operations, it's necessary to access the RedisTM Sentinel cluster and query the current master using the command below (using redis-cli or similar: +- RedisTM service: Exposes port 6379 for RedisTM read-only operations and port 26379 for accessing RedisTM Sentinel. + +For read-only operations, access the service using port 6379. For write operations, it's necessary to access the RedisTM Sentinel cluster and query the current master using the command below (using redis-cli or similar): ``` -SENTINEL get-master-addr-by-name +SENTINEL get-master-addr-by-name ``` + This command will return the address of the current master, which can be accessed from inside the cluster. In case the current master crashes, the Sentinel containers will elect a new master node. ### Using password file + To use a password file for RedisTM you need to create a secret containing the password. > *NOTE*: It is important that the file with the password must be called `redis-password` @@ -371,9 +496,9 @@ To use a password file for RedisTM you need to create a secret contai And then deploy the Helm Chart using the secret name as parameter: ```console -usePassword=true -usePasswordFile=true -existingSecret=redis-password-file +auth.enabled=true +auth.usePasswordFiles=true +auth.existingSecret=redis-password-file sentinels.enabled=true metrics.enabled=true ``` @@ -390,7 +515,7 @@ TLS support can be enabled in the chart by specifying the `tls.` parameters whil For example: -First, create the secret with the cetificates files: +First, create the secret with the certificates files: ```console kubectl create secret generic certificates-tls-secret --from-file=./cert.pem --from-file=./cert.key --from-file=./ca.pem @@ -422,8 +547,7 @@ tls-ca-cert-file ### Host Kernel Settings -RedisTM may require some changes in the kernel of the host machine to work as expected, in particular increasing the `somaxconn` value and disabling transparent huge pages. -To do so, you can set up a privileged initContainer with the `sysctlImage` config values, for example: +RedisTM may require some changes in the kernel of the host machine to work as expected, in particular increasing the `somaxconn` value and disabling transparent huge pages. To do so, you can set up a privileged initContainer with the `sysctlImage` config values, for example: ``` sysctlImage: @@ -459,7 +583,7 @@ By default, the chart mounts a [Persistent Volume](http://kubernetes.io/docs/use 3. Install the chart ```bash -$ helm install my-release --set persistence.existingClaim=PVC_NAME bitnami/redis +$ helm install my-release --set master.persistence.existingClaim=PVC_NAME bitnami/redis ``` ## Backup and restore @@ -486,9 +610,7 @@ $ kubectl cp my-redis-master-0:/data/dump.rdb dump.rdb -c redis ### Restore -To restore in a new cluster, you will need to change a parameter in the redis.conf file and then upload the `dump.rdb` to the volume. - -Follow the following steps: +To restore in a new cluster, you will need to change a parameter in the redis.conf file and then upload the `dump.rdb` to the volume. Follow the following steps: - First you will need to set in the `values.yaml` the parameter `appendonly` to `no`, if it is already `no` you can skip this step. @@ -505,7 +627,7 @@ configmap: |- For example, : ```bash -helm install new-redis -f values.yaml . --set cluster.enabled=true --set cluster.slaveCount=3 +helm install new-redis -f values.yaml . --set architecture=replication --set replica.replicaCount=3 ``` - Now that the PVC were created, stop it and copy the `dump.rdp` on the persisted data by using a helping pod. @@ -551,23 +673,18 @@ $ kubectl delete pod volpod - Start again the cluster: ``` -helm install new-redis -f values.yaml . --set cluster.enabled=true --set cluster.slaveCount=3 +helm install new-redis -f values.yaml . --set architecture=replication --set replica.replicaCount=3 ``` ## NetworkPolicy -To enable network policy for RedisTM, install -[a networking plugin that implements the Kubernetes NetworkPolicy spec](https://kubernetes.io/docs/tasks/administer-cluster/declare-network-policy#before-you-begin), -and set `networkPolicy.enabled` to `true`. +To enable network policy for RedisTM, install [a networking plugin that implements the Kubernetes NetworkPolicy spec](https://kubernetes.io/docs/tasks/administer-cluster/declare-network-policy#before-you-begin), and set `networkPolicy.enabled` to `true`. -For Kubernetes v1.5 & v1.6, you must also turn on NetworkPolicy by setting -the DefaultDeny namespace annotation. Note: this will enforce policy for _all_ pods in the namespace: +For Kubernetes v1.5 & v1.6, you must also turn on NetworkPolicy by setting the DefaultDeny namespace annotation. Note: this will enforce policy for _all_ pods in the namespace: kubectl annotate namespace default "net.beta.kubernetes.io/network-policy={\"ingress\":{\"isolation\":\"DefaultDeny\"}}" -With NetworkPolicy enabled, only pods with the generated client label will be -able to connect to RedisTM. This label will be displayed in the output -after a successful install. +With NetworkPolicy enabled, only pods with the generated client label will be able to connect to RedisTM. This label will be displayed in the output after a successful install. With `networkPolicy.ingressNSMatchLabels` pods from other namespaces can connect to redis. Set `networkPolicy.ingressNSPodMatchLabels` to match pod labels in matched namespace. For example, for a namespace labeled `redis=external` and pods in that namespace labeled `redis-client=true` the fields should be set: @@ -580,15 +697,89 @@ networkPolicy: redis-client: true ``` +### Setting Pod's affinity + +This chart allows you to set your custom affinity using the `XXX.affinity` parameter(s). Find more infomation about Pod's affinity in the [kubernetes documentation](https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity). + +As an alternative, you can use of the preset configurations for pod affinity, pod anti-affinity, and node affinity available at the [bitnami/common](https://github.com/bitnami/charts/tree/master/bitnami/common#affinities) chart. To do so, set the `XXX.podAffinityPreset`, `XXX.podAntiAffinityPreset`, or `XXX.nodeAffinityPreset` parameters. + ## Troubleshooting Find more information about how to deal with common errors related to Bitnami’s Helm charts in [this troubleshooting guide](https://docs.bitnami.com/general/how-to/troubleshoot-helm-chart-issues). -## Upgrading an existing Release to a new major version +## Upgrading A major chart version change (like v1.2.3 -> v2.0.0) indicates that there is an incompatible breaking change needing manual actions. +### To 14.0.0 + +- Several parameters were renamed or disappeared in favor of new ones on this major version: + - The term *slave* has been replaced by the term *replica*. Therefore, parameters prefixed with `slave` are now prefixed with `replicas`. + - Credentials parameter are reorganized under the `auth` parameter. + - `cluster.enabled` parameter is deprecated in favor of `architecture` parameter that accepts two values: `standalone` and `replication`. + - `securityContext.*` is deprecated in favor of `XXX.podSecurityContext` and `XXX.containerSecurityContext`. + - `sentinel.metrics.*` parameters are deprecated in favor of `metrics.sentinel.*` ones. +- New parameters to add custom command, environment variables, sidecars, init containers, etc. were added. +- Chart labels were adapted to follow the [Helm charts standard labels](https://helm.sh/docs/chart_best_practices/labels/#standard-labels). +- values.yaml metadata was adapted to follow the format supported by [readmenator](https://github.com/bitnami-labs/readmenator). + +Consequences: + +Backwards compatibility is not guaranteed. To upgrade to `14.0.0`, install a new release of the RedisTM chart, and migrate the data from your previous release. You have 2 alternatives to do so: + +- Create a backup of the database, and restore it on the new release as explained in the [Backup and restore](#backup-and-restore) section. +- Reuse the PVC used to hold the master data on your previous release. To do so, use the `master.persistence.existingClaim` parameter. The following example assumes that the release name is `redis`: + +```bash +$ helm install redis bitnami/redis --set auth.password=[PASSWORD] --set master.persistence.existingClaim=[EXISTING_PVC] +``` + +| Note: you need to substitute the placeholder _[EXISTING_PVC]_ with the name of the PVC used on your previous release, and _[PASSWORD]_ with the password used in your previous release. + +### To 13.0.0 + +This major version updates the RedisTM docker image version used from `6.0` to `6.2`, the new stable version. There are no major changes in the chart and there shouldn't be any breaking changes in it as `6.2` is basically a stricter superset of `6.0`. For more information, please refer to [RedisTM 6.2 release notes](https://raw.githubusercontent.com/redis/redis/6.2/00-RELEASENOTES). + +### To 12.3.0 + +This version also introduces `bitnami/common`, a [library chart](https://helm.sh/docs/topics/library_charts/#helm) as a dependency. More documentation about this new utility could be found [here](https://github.com/bitnami/charts/tree/master/bitnami/common#bitnami-common-library-chart). Please, make sure that you have updated the chart dependencies before executing any upgrade. + +### To 12.0.0 + +[On November 13, 2020, Helm v2 support was formally finished](https://github.com/helm/charts#status-of-the-project), this major version is the result of the required changes applied to the Helm Chart to be able to incorporate the different features added in Helm v3 and to be consistent with the Helm project itself regarding the Helm v2 EOL. + +**What changes were introduced in this major version?** + +- Previous versions of this Helm Chart use `apiVersion: v1` (installable by both Helm 2 and 3), this Helm Chart was updated to `apiVersion: v2` (installable by Helm 3 only). [Here](https://helm.sh/docs/topics/charts/#the-apiversion-field) you can find more information about the `apiVersion` field. +- The different fields present in the *Chart.yaml* file has been ordered alphabetically in a homogeneous way for all the Bitnami Helm Charts + +**Considerations when upgrading to this version** + +- If you want to upgrade to this version from a previous one installed with Helm v3, you shouldn't face any issues +- If you want to upgrade to this version using Helm v2, this scenario is not supported as this version doesn't support Helm v2 anymore +- If you installed the previous version with Helm v2 and wants to upgrade to this version with Helm v3, please refer to the [official Helm documentation](https://helm.sh/docs/topics/v2_v3_migration/#migration-use-cases) about migrating from Helm v2 to v3 + +**Useful links** + +- https://docs.bitnami.com/tutorials/resolve-helm2-helm3-post-migration-issues/ +- https://helm.sh/docs/topics/v2_v3_migration/ +- https://helm.sh/blog/migrate-from-helm-v2-to-helm-v3/ + +### To 11.0.0 + +When deployed with sentinel enabled, only a group of nodes is deployed and the master/slave role is handled in the group. To avoid breaking the compatibility, the settings for this nodes are given through the `slave.xxxx` parameters in `values.yaml` + +### To 9.0.0 + +The metrics exporter has been changed from a separate deployment to a sidecar container, due to the latest changes in the RedisTM exporter code. Check the [official page](https://github.com/oliver006/redis_exporter/) for more information. The metrics container image was changed from oliver006/redis_exporter to bitnami/redis-exporter (Bitnami's maintained package of oliver006/redis_exporter). + +### To 7.0.0 + +In order to improve the performance in case of slave failure, we added persistence to the read-only slaves. That means that we moved from Deployment to StatefulSets. This should not affect upgrades from previous versions of the chart, as the deployments did not contain any persistence at all. + +This version also allows enabling RedisTM Sentinel containers inside of the RedisTM Pods (feature disabled by default). In case the master crashes, a new RedisTM node will be elected as master. In order to query the current master (no redis master service is exposed), you need to query first the Sentinel cluster. Find more information [in this section](#master-slave-with-sentinel). + ### To 11.0.0 When using sentinel, a new statefulset called `-node` was introduced. This will break upgrading from a previous version where the statefulsets are called master and slave. Hence the PVC will not match the new naming and won't be reused. If you want to keep your data, you will need to perform a backup and then a restore the data in this new version. @@ -670,40 +861,3 @@ And edit the RedisTM slave (and metrics if enabled) deployment: kubectl patch deployments my-release-redis-slave --type=json -p='[{"op": "remove", "path": "/spec/selector/matchLabels/chart"}]' kubectl patch deployments my-release-redis-metrics --type=json -p='[{"op": "remove", "path": "/spec/selector/matchLabels/chart"}]' ``` - -## Upgrading - -### To 12.0.0 - -[On November 13, 2020, Helm v2 support was formally finished](https://github.com/helm/charts#status-of-the-project), this major version is the result of the required changes applied to the Helm Chart to be able to incorporate the different features added in Helm v3 and to be consistent with the Helm project itself regarding the Helm v2 EOL. - -**What changes were introduced in this major version?** - -- Previous versions of this Helm Chart use `apiVersion: v1` (installable by both Helm 2 and 3), this Helm Chart was updated to `apiVersion: v2` (installable by Helm 3 only). [Here](https://helm.sh/docs/topics/charts/#the-apiversion-field) you can find more information about the `apiVersion` field. -- The different fields present in the *Chart.yaml* file has been ordered alphabetically in a homogeneous way for all the Bitnami Helm Charts - -**Considerations when upgrading to this version** - -- If you want to upgrade to this version from a previous one installed with Helm v3, you shouldn't face any issues -- If you want to upgrade to this version using Helm v2, this scenario is not supported as this version doesn't support Helm v2 anymore -- If you installed the previous version with Helm v2 and wants to upgrade to this version with Helm v3, please refer to the [official Helm documentation](https://helm.sh/docs/topics/v2_v3_migration/#migration-use-cases) about migrating from Helm v2 to v3 - -**Useful links** - -- https://docs.bitnami.com/tutorials/resolve-helm2-helm3-post-migration-issues/ -- https://helm.sh/docs/topics/v2_v3_migration/ -- https://helm.sh/blog/migrate-from-helm-v2-to-helm-v3/ - -### To 11.0.0 - -When deployed with sentinel enabled, only a group of nodes is deployed and the master/slave role is handled in the group. To avoid breaking the compatibility, the settings for this nodes are given through the `slave.xxxx` parameters in `values.yaml` - -### To 9.0.0 - -The metrics exporter has been changed from a separate deployment to a sidecar container, due to the latest changes in the RedisTM exporter code. Check the [official page](https://github.com/oliver006/redis_exporter/) for more information. The metrics container image was changed from oliver006/redis_exporter to bitnami/redis-exporter (Bitnami's maintained package of oliver006/redis_exporter). - -### To 7.0.0 - -In order to improve the performance in case of slave failure, we added persistence to the read-only slaves. That means that we moved from Deployment to StatefulSets. This should not affect upgrades from previous versions of the chart, as the deployments did not contain any persistence at all. - -This version also allows enabling RedisTM Sentinel containers inside of the RedisTM Pods (feature disabled by default). In case the master crashes, a new RedisTM node will be elected as master. In order to query the current master (no redis master service is exposed), you need to query first the Sentinel cluster. Find more information [in this section](#master-slave-with-sentinel). diff --git a/chart/deps/redis/charts/common-1.4.1.tgz b/chart/deps/redis/charts/common-1.4.1.tgz deleted file mode 100644 index 110cf10636c084a920c9cbd8c77c9a3bb0368cad..0000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 12484 zcmV;#Fgwp5iwG0|00000|0w_~VMtOiV@ORlOnEsqVl!4SWK%V1T2nbTPgYhoO;>Dc zVQyr3R8em|NM&qo0PMZ{d)qjYDB3^suc%9>Z|qD&OLiW!-pSrgoXm{B?oNE|bn>0; z?$d@yNJ5(e*Z?R;llc7Y=fjHxUwYWGtDOAdgs282T{r-l7vxl5CFtT;xXg%13021j)dfSEOU+nl#vgZ3&Q9D%=QA5WyPO^ z=t(pP5-eg)GO1s^gdfR}BR+?J;&cj{yI{mPj5*6QLdRhE4pKHIF$}T1z?j02NQ$Ne zVpU#50l@nS5#~=I0w|M^;4EcxG)yrJ=Rl;u=_m>&Y>E$HB4s8Hc6Y}_PV!+Cv+1q{ zxobe~N{;dF6bXrW`AMS^kXT{vK-iBOM#3&=%1|P9Q#NM8ed|pTKaVmx4$krXg7HKg z1U=iapa&D2W|#*(ka(J`q?&W`am;?Y6 zsgAy~mCawaNx^a+V+~~~A#9n0-QA0ei^%V6AmaGWSPdw8^a_!=Z*sQ^S1 z$T*9!5LiS3{)DDkia#h0a;`Sb20n33rL2rOYlQmoeh7gI%+c!Ce$(eCAC5U66o36?phfIzU3 z1j-Wp((uY05^R`;Q3yVN214UBPcVdry&{jNR5cMP2qA1IB$g1K<9P_--`~9pAv6n7 z2-_(U62ez6PeS$Ye}y|c(7U`0G&-L@_e_gRTToRpjz^etoV?CCq2tqdf|EQYbbK_X zta$zA6OMDOy#@e1FqJTkvHDv*QzYZbn@<_XLO6BVJUuwa^8@(&8KQGMhs(?23joV7 zN0M=+Pp(R%Do`!G7tmgdyo@D|{=4com1O<# z$XHU7e=(b8jAAN_u~6n8{v<53xq3Tiwx9d_UgP(l-h@StCvJeJKUldz4anVfsw z-l-Rbj1wwH5TY!L&hsJW6iX~3!gh;F2k^ZJecCme^Q5gY$VG-?ToEQ}l3V1X6P#is zaP-!dgfH-C&Ll2@NS3jbjpsio8C1ny>^z| z97F!qXONY-@%p@2g6GDY&UXOoK<{?;x**W^J|mNG?>c?scQXZbXUX_3`Pu8H{^;r*Pq-6WGNY_zwb*c%FJlB&-kuMiGF##G@c>^L~KidCG z6ug8BGzZBbp5XYrqx1zbAsK{9&XPRF3FK6gv?#D2?MHpMAaYXEdK4H-p~rABA@RgT zJP1G(P?BhC5v34*zPtpL(Gn~N11RMU1kwhsQKNK(}luUElHX4r}t*CzFS;n{&9{d> z#gPVC_zv~AAGFIbLvj*H7CEf?{SZQdV~%C<<1L!v5W*3`X`-u`qP>1UESK*FhJ%~J zaIgl3g95__Dt0EDLBa)i(Zs~>R^eA|8IdLlcB(r7O5ZqfaYL>_$Phk9V3pZbcMPV$7LifeYJH`3B@dbFhcdNMw1G@CmPYDrGCSeeXRJ zrUx$|{FNTRJU#vR?&S3;yg4~}cX9x8mYeyQaW*3fRxdcjIoDJu=dU-(vDR3)Y5M!Z zcW&CWTN#z6n;rN9BSg}h^=IEd>pji&pG?tsbFp9Ft+4(-9n}5*Po6z}dcXeP#C^q(h;$*^$Qx%E#@uqh3p@!q>7rAr!DTPW6P zj>kkuK38j|l7LasX5>Ekg)=6IWF5ub$FhP%<60^8#xs|Ezh(PIhTWSm5FAEsYq!~j z7acV^cOAUnWK;v@dlW_xelK>v7YBNmxl*i77v1e{--L$bz$~b^idV-n*J~D^V-81} zA&NeqYHbMgF7^VZ%knfeMMaJE3iYOw`v#A@zwPamyjk68T7^+7Sb3^~_g=A2Q^G94eM5V_JoZerB{ixsC&o1akZso{kIz^n^ORmuK&*)@!$RDgZuUWHlB6% z|Nnt0=15`~qWD}fKBh_}YwMl}h}kqlk_=O9T)rqx{Q!ZN$4AbyDSXqvDZ(uS+ExlX zRbW0NF}9Yl{c8WR-;NoV13CD9l}C?O|YCp-HI3W85%xUn|1-cJBKLEY%>^89}Nzl~=N``=s3g+w$#JTbA=qH~s7UUJ3F zjA+I?7c#CsEpLKQ}_m8*VabbI+JqG*hh-f&*6 zacXsfRxxQ}#?@+`3k;0f(7Q-vIF5u3NB6_awcA(B;%bRyw5`OaUzfb=lIji$wEJhR zrz!spQ*2QDFSY;rPoC7}|I@*}|Mym&HRS)BPnnWXO5LN@K+-`hI(1N|nDS*zuMrBZ z>uPD@ylJZByBX%3BpAMc0m#CXHY*`2Fg3@$)_P!TkwIk-YGeo`s$61PE4B=lw2!9W+-YHZNZj`6#9RAEv zN=5`HfU-$j(> zthR(R9PdQI(a7xv8X!dgmq&Y28n~M7Iz&q$Z?RoWb5*d)I9@2Q`&jTwJrKB2U?sZy zy8HubcLY}ER}asE90p2t=`3)qyj>f?Iu}-;nReG38HbFop|f8;`1=W#*&9bILJ;`0l{lhOfCQX=P( z#^5i6j@b1Q<88VAo0c_I8w27;ag~%bd8Bmz8BOPES-ik7K{M5j8RjUh(^RN6%Ri%b z)Bfx#k2Y5RhNG~qnN+>jg_6=jpbF?0^|jk-3C((IYKuJ^ZeQp7QZdmRrVYEtx^ zsjsFuoTGL%p{X-<7WEM=Dd4)_uKm{K&N-g1BzE+P@oPvObK?9Q>o|t+UbNhfXgSC8 z_K?uGp3SKWIfp_8ZcZ|f+>E=KzpKV1DFXOGgnsSViImFsNO;(zf zWyq}Ys(RbIm4N4-k*~E`2%(KwO+Hj}K-6QX2Q6{cd*Kd*DW+pN31QIJW60DP>J1$T zHNVet4Dzv&-a*?}qY$Q>OSb7XN8XqV%O#GP^6b>W!sOnlXVM5Gp-+sc<%5Y){9QHxuB9CTv;|&VVt)2|aklSc(y?g8DeYa)P<) zBT5nw^XZTo|NIJ|3wCHzbZX;a{2y90>-cGbNK)o7Hp-3jg@}A;{b$Q!)Skb3u2 zD}=#=g5?fgKo~lK@xb9zdtG+Fo}H)o;EFoHcI3SBgFZxdq>I9qM~`i#AB}Q`7Aw)HH_a<$rqIET^>nv^#pPoGEeTbdv`Qa`xDE8|WzO zh0K0|;j<^0#(qws&tCovFA~zx#wu`_qG5^?KZv1Z;uk*Wb_EeWa5<%py(v*Yqtiah zZppHvQXJ3G}dp@&fmWB7rfbyW1hi7TBlYWAwv9Ged2=urd0{|w=aS{{Vt@N`w+rH-ey zJWGkPL}ki}Nj@5-xOMWiC&_7aToLMRK5d}40AzcFQAIh;e3tDB71xK8^n#8c<9J3` zF1%IT&Pb=BYIRzyqMw?Q%e2z3rV?&gMR2|C-PYoCe}MdMJuUu!$v7J0+l&7m44&2Z z|L^_(xAm-l{>wk3b82`64pSsrkK;IIidBK~Bu<98AVOjq<91)1S76n{V6~=7Q^$VL zIBKVl2Ry2LY&p4A_vYC1HjQe2R?cdRFBVr?=pxk;v{}oAx8gsw8@N(rr{-32E303| z1U>&6{u=tnko?ttSzV)Ev}4xUn|l#|_nxNwmsx5picPHmOXPq5S-*b&*V8Ba_xFF@ z%CnaIrwQf)kaY^`b3a9xi{qeZfsS3W7T2)K1wp@VUkZ$~pssOutpd#^Y7)HRzn_(k zi&FB*EOlQBJG~=&s9$B<)=_rW|3cGrr@i(aIzHH(|HkKai}9aN`i=Sj(lR+0EW4&t8t8_o%f54ZI|@MzSVVl?&XSdp`&3h zw-0xF{_QyH_TIBMboK#pmzEoU${3gM`Ev>2^76%l?elzyW0`8=ICns=$k4uWUUqv_ z%UaOTWAKMyR0+oy;b-lsjZ_J9-sW0v5Z76;0!oTLe0I)fSF zCQ#FCG9wcSx^(<%v@nC`24p(#7283}N2CVIb5iOrIuIgDiS|ec^+RU{Qd+O=wpT;D z@D7o{e{WRPp1{Tt_IewYG&)_-%2VrICAPsh6C>E^I=f!_6+5AH?9R$^0UmKSbxWoh z!KEX&a4VzOFg1UzHM1IkOOKN3josMsMlcG?-FG_!?Iuj)u$|2r|7p_{HtE_OA&eZsoyK$z9h6oG%re7N2+v}a4N!gAf)cD3F6b37kZ`B3lKugi&*_UbVow)?96@*Br9%mw~Iy*zjU_D@@? z%4L4h`XFCz3o&Zl7TT%o=y~i=3mAzyHtM>(>vqz?-OxYppRfBg_5TaRDWT&HngC1v zzx{^)ckllG$J=?<(EmRg#sD;AxwHvCIZIRZzeM9jYJb5~w)}fEUXcFlgfY2D&bLDI zeWr*euw8g2LKk!xf|t;1$EFUdXYcxAc4+@jXaZr6|N3k4mj_?O1noV2b`YAZLLXnA zyghpRj{`UkpZKaZXiNh{057Zk~=JImqF<51TDiz=fJV* zCZ>rwg@tB}Bu#4DywjOZey#IkVmc$7Q4=<;gENcR%!I|Fa>;jjz4-2gUGyZ|&9!ew zBAWDUD?Qap&np>tzKi?CJoI&sykvi!D<^upk@9Dk|`7Xx>VIOxYTQWcahd{Fvhr`Lq(4b3Bhsr5Yp` z$>+!Tl~z$1zg%mxnrl$2722IpkNMZxr(Azc@}KHKfJQ)_sC%W>2}W%6rZW<;g*U@x zh?Nem=C}5+!p62#{)%BfM4tjk&_ zvnJz-biOpkYX^E3%C4m|p|~%#TN-@@sjw97isvjUQS>j^t3}|JFwNAdAE9yX>{_6~ zB9JQs+SI_?nOk;cy|H(~t9{T{9}EX)g;DT*fZZeFI<|oJ6=$LnZXFTUZLaL=(%qe2 zG2^`!&3#Gl6of(*u<6(C{Ot2Pv1H8av#f16t6x@&tz4}CPZ1|58D7&Bv_$`Z{EZ`afMT^l!}^S6+6EsfvRx8P7N zCs$VbYp~i?e#GMmkyzjLwhBUC@j9ejPP$Ep8XP5wRfP_-;e;{SVLEW{Q&?%W1&)%> zF3iA#k=xfx>n}H77S}()SxREfB3<2SmS{r#Iwnzl5IW7GO2KZ^$g)6Bjo^l@qY4Jq z-e@F!KDf%6!v;UKSxD8mH$P8)1&5tx{PL!aP)F$|kvD3F*2Ag&?wkD3zHkXWRu2~t zp<~W;b6-pO6_~KBbpvE-!)Y&&r=&US;w`wdRFN*As(&-@i>or%>^Z^MomHGkI_ z*;0%CCP%eIf60jYQnGEt{P%bKi0cyn52Ist!~UN^f4{l^yMKTF^LCyq`F|8wyneNP zva@*?kY%{L;{q!C+U*50NMF+rR5o-&uAnAq*K-Bg`WtZtRbh3wf)+b)svtTXI7{70 zwN7=rlkS=;=rxjPh(x`9Vqf2uE9n%w*#4#y$$VQ1>18e_Z%SVA;1qn(;egVw-*mIt zI<6ESizR02`hG9teehejlMXQ}$NmR6#7qT$4qd0!0?u+boV(iF>v9d3oA<`mma9AE zjT2a|;EXG!&N4TgEx7{IoANz@Wv|E;x4TV)&IBGA3V9w|8pzP zRs4U)hAU40{~tH*|MM8`&bRIp22 z+oHU03onPNGza%qlpeYzZFoTw3w%uNt+j?xMPD&^s-1M*ZiHs>ZWFqN`8RaPq=`kf zca}unNUgi;YE=tiVRS@h>(Q+v4t(fV+6YA)bg@aI_8P#LR9 zTiYr%OVUo(ZmdG>E#816@s-u9iIS?i`weq(YkxK;-F!l?De3A^mw?)^yz^Vjt}gOg zjn{9OT{`=;gk?HdBCAbvpC1;LyOR#-#r|K86LS4Ta7)hrKHYn=UyuLnKe^BUb1P49 z6$kK%VvFtfKW#q#(=gnfas6s^y1l;o^Yt9QriGjF^)`sPmYdhqzNUw_3S_Z!w=>kU z0^}UeMU?5XT@jk9czbxGPJmi#FsysYn!tV*cnx@YSvvd*9^br*>~-SW8lCTUwiR7e z{qRw+YC_e+;{`|6#%e)4mtV5m6oei%Y#O1gCE%`Y$=5S-4u7y%!V=Ji_ zcGt#qkM0G!dzeiff6VT#k@VmAS#1CLYuDASz-9SgpY8YS@jrV{p5NPlxA9!X{Im9u zDx)pEA#NIbMupbpwV*v@bky(bdu8h?UUA)neie2Zd&OS2Rf&52zEzPsS{rP(wL#I^ zDk@%=W@j$EXr)bC7n+w})P?~vPwu;3wp+RHC-y=U$=sr(v8H1SicoK{isopVR`Ohx zXTv%S>T-qYG^pF#^)7DST|L2;z5i!f`=*%fn?)u;616wcy)C|i9$&6@=B|*aaF0}s zq;>CdZ}4zb40QJu^rqVjE>T~s=@eY%E*n}n+n4vLvoB#iMcL9RS-D`!SB$)$_mk#! zCrwT3Y(THwd|njQ7a(~3^E`>FhnZGJN8R_BFP%Gem(EqM=qYDh*AYM6M$xf@7a%dG z%2WtL*!B*!hNT|7<1%u2ZXB<$FYvU<)W7n;_b4<07!ZitzvJ zMDUKLb6`~0R474)Ii!T*D2QI4{(h!&68I7eO>8a##Or&<~>Fzxb~H z*S(mGchx`cPcfsrC7>aS&+|;%J|cJ&iHj_F6b;dN@F!034)8r=FSUmrq4xT-)=l|L3 z@88e=TY0wNmAMzn&4wSzkSnd_P%UIZ@DhIcCr+o;*S~GMo2AsU5s8VuVQN>hjKpF$ zHAR2dOQG1^Qe}3uD|F0Ro+*)HxDHY_CNT`LyueD}SVT;{Cc&d$!1 zW*sCr!!*G(CfI84YHdBR@bo%A!(0$X51=1?iaxoZ40{>ZL2)IPZN$G6%l=l4=@y4b zOo9iX(1)VoIpmqrQ;Sj>FO-oFuHD%nI43kY0A<0G@lPlVrdT4SJu8$A!Yw9~z8*Ll zoxR{W50x_aW1=5~i9S1+dDa(N33p*b63Np(q9c3 zCP=_g@tDLy*%;bypD7T(I5ZVDoMMRu9G91>o#a%KDXyZJah61c?e4(#s~?U}b|QGK zu>|#3aVK^z*;E@e?|(dn7;{NRBt{a8$BOUA`X)W9kIgIARDY`e&RNa@WknQ`od?Gp zYhQvO5{n?{`RER!!QNkjp6Ty?G>H19in4LBqKD!L3?r7N?800hH%!fau0m_GjuX%f zkyL-PhM%3umPK^@L(DR)4a0>q$Tkvu;B9us?@cg2XQmZ&gFjWM=9Q@}C zyv8EtL|cil^794We9Fvidq*_OkFLu!MA^Z_b#+CVDa*q6`g5 zy5e+d48)aY*XmE(JX}82t~-U+ecBrE2Rim>94Yy3m-4e}SM9hfxhN4=BHok1R_lOm zvr5J(QIgS}Ng<=+vQrN}5TQK}0?VC9aY%G#7Bg^HKzCwUu8L8qdYsj;L|MjJ#)Q4l$`7Fw_F-Hk5 zgM-a}iIUAn5-v!Z0;VF@A<(T6-eWSu)Hn(+uzq7eYO}^zT@f6O;H=!CF)V)OmOZoc zL2PSs!r28N3K~Ie8R_>z*=c$j8jJyHV{g-_jfb%R9w&^9ydH zhtQpFd~o&{1jg{ok*oIG_LeTg8IwCjw4abX*XgJtXz4(fr>P0?6lbj+c+KK-%nc91 z2_6$6`5bIi=vy?!qSk?eQ{G^{o9_X@?vcC1>G`*wBJ>d(&fM&%$}O zq1p1ytYPI-VScM64^e!Msdg^>!-g*aa-46u3~V95RB^uXy{d(UnR)W^_^8muikToV zpOF~5SP{m;;@vURF(E_5Lpy^NlwVwH3C=jSsa+_OB(AypjENT!wmVGOcz3Tq__y8u z^WDK;cTq-qUTx7Mv^VGtp6zE0NZ2k_T^Cq1Zr2io)sZtpw`k<9B^Q>Bo!OI6 z|DKh|sRdRMlX?L?Mc8;QFr2w%M3s0q!<>@@pDi7|>IR4^f5@?s56+RIKF;CK9Holh zi83WM8cmyVwZ=5smLpAB-Ki|iOP9_{W7f$mcBNlD&9Av~euFFKn$Kd9|n7LScvfg5K;TQttv8K=-rY$Z}p^N~I>5>DsEPv11tn)jPZ z{ol5?96({uQMTydo8Z0%`OfkD4C>^wk#y&HzIvrp}HUCi0s-P zgw1z*;SPi;reiq?VbF(ANY3cEJbbR?zip=SyJX_WVCp{xQ&$_SrtHh9jk-1d6;_1h zwsD^xQE^uBS-PBcN}I+r9j#OZ2s_d`@|pS(EG1w2=G3?JxOG@Ej>dR%Thd==(cRoe z_SaeUHn;s0xiCrt_dKBlS*BQUfBvCk9jZ}B?SvG#P zlk~#wZ0OSvK09@V_UI9ESA|vcI9`2No7$Phvscc#1<8%h%DH0?rHf($8TXmCm4?^^ z?J0b;JB~=ZaV&sQdysz4azlVzV0VeXwVK?fmLby($)hFX*LFA0+1lgh-OjX;A#9GH zciYI<9YQa0@U4vElJTqM+bs46)*C;a>+WwN&;H~6Pk-B0|6gw$o8xCvB!1nYGr7lZ zaqg`!elZdP(S)PQ7_K{hhYreyBxrN|3Ov8^7#4Wk);KO(|LjeY*IfV19j5;;$K!v$ z$wkoKJN=axL4(EZE`r*u|A;sxbiCZAU%`IAmWjR8C|$t-yj~EF$JG~>DiLRCO6d4K z8Y>OJ5)06f<@0Q0m$GL8`&l7Mx}{CMX4>DJbFzo+9CeLn~0_iDz!3 zrVauCInVHc0!ZjM07%N=I&h&@uDF-c$OP9C0V#`-#7O{vKcQ)s;sZ!@t%$H7@D6V; zY3igXsTsKp|Mel;L*Bb|Oz5W|kZ8ONtbrrZ*atI+2G62FFTq2CXm8N(@n`!%kmYH5 z%u*6B#Z?n~GzVnB9~TvioSWJ?`tW6Xf#%{NkWq<;qS-^8tWiFEY_ewxEOqgt(OV{u zITo18hXx-TfK(!cI7jmUfJkgoU@gYfWpGO8ARN-v00A~C(YNhHL6G2K?ooAUGLSYX zU{H1^ZM0OAJbq{nbHax511!pGn@^H%3G2t#{F zJRw5iDIl3Eg2pBTfgnuDuL{OtFAM?{$5@D;Sb~?K`%;&LDND*bPdf3gG<1Sd@{tpX z-{}DmCMF+xll5{v(veSevaoqp)4a*i;W5_ z`@TpLVqn_E{v6NE4p>`As`^N17ZL`4vtP52*d|{`f$A3c$Zi1?%A+de(zXA9=LIPh zEp>+#V!4u3AML3rowW}Hrh@2%NqR17Mbb}uL1?i*_80`4VvuBtg#vJasGgK#Ra-Iz zotv%Tj0r*XfycRNR%;3qOt`31Ly2rRx?4~t0=Bf$?|Z#odyW%Jm8&N>0UPdZ79x~o zt5-Ec_%1_#=D0|dQjW&w&)yci)$hN+@Yxeg<085G@$! zg)N?Y*$-E3(Ct}TFS%}2(J$EYQ)6nf)@D?7@-LfBQ1RQ^3HJ8g`!}bN{AA=*%&1@~ zzD^S2e*bpU5cdaHNJPA1CgP=+OHGU0zrnvLG@Pd3<;oDglQCe)a@#K0%SU^9dm+yEg4?Syd2vVL|4m2E5^ zgF)1f`a$r^I|^^v3{Quc!(jh0?DhBhkL}t2J(uj{OMNeMVc8j{%>~Jnh+sTpMSOpmxM_ru%(()UBqpho>FU1Gr!*8bE3E>oqe6F!!1;O~x%? zG@b86@XJ3j$BR?rxs-T{1yDw8r%Wu;j<$hgL={gZFlCxbrR8gUKZ?3%eu@nf^cD2r zXGI006WP37XAPWY`%wk05&Cm?%a-nGZq!(`?pE=$mkZpB zk-%cd&Jz2Hj?Lh?K1c?$eZ?$43p~nGNC`a`h8JARs>MoHNSRB<2};E-$AYCZ+*8Qy z>3{co856QsB4WmQ*Mql8Pg;uWlg6e5?x{ZL_Ik6uo@Dmt{pO{NDfo O0RR6Us#Y@qLID6$ubF88 diff --git a/chart/deps/redis/charts/common-1.5.2.tgz b/chart/deps/redis/charts/common-1.5.2.tgz new file mode 100644 index 0000000000000000000000000000000000000000..585f9b72ca009909d94e198722f546ebccc6ad7f GIT binary patch literal 12953 zcmV;KGG@&miwG0|00000|0w_~VMtOiV@ORlOnEsqVl!4SWK%V1T2nbTPgYhoO;>Dc zVQyr3R8em|NM&qo0PMYMd)qjYC_JC_E9#}wZ|qD&OLi`^-pQU#Cz+W%-JSS2>GZSP z-KPzaB?)bcU<05WP2%(0&x0EY-gL2L$JsGIBr*vU3WY+Us!%9IY&K)*{);K$GF*^Z z@~7=TgTY|%%bga|gnH)G%Upo+gaMVn1OMCfv9FjPSECODDZET%0o= zi=$rOcC6QjDJB{6ULPdRvV=(N^RuQ{=ij&InD8AY$(2e|nho z08*kl`mL>O{<2L9mh%WTl$C_AWsdgu&(F_8zq38L$nXdfGk(2!b(Fs}yWTxpeyseT zlO#uRO$)#Z`9ByQKCa9Er-y?(`F|77&JNV%;LZ-b*3y>aA35b1D>?h(_5O>OAQ?*p zkTiyjvj~Mi5%%ySnPmxnP#olBQC~}$J85zIA3Oiu8YT9BBjYhmsiY`EnQcWHteF3g zpB@Zr^Z)VV#|L-w|0bSKpY|WXoX(CwpoB3^P_6&ZW{ND)6p!G+{>4SFr;7DXQ06=Z z0)mYtq%6kghF2C4qhT7BLhsWjplOukF+yP2EA)6uRTH6t5WsFsBMHG7E&>St_V#T6 zfmw(G*iERA5PbXmBvAkUcd)ky{fmp9M(5L~zG-n~3#v-Sag3Z}{4(b>oxF>t80QI1 zC$A?dD_+0)h*7S!*B(G0OeIVsRDY{yMr1U7^)cfpgj1Kz(}y!$9Kokg5T4-zE-s2M z04zgJB;!h<_FkKA9(iv7RIfNmCkUbWT!p0CQBA;S_#t9uMOk?-@9O+~#k6_qy zANtLKoDv>)4dhzmr~q8=IGPqz6}KL(Ka2{(J4`T=jK4=dvjp#dO=G!a^sX>)#h9tt z9zbAb%e9Q489dV`ItKg$Le;2i)An3{T~BI+9zaY4R-qbx*#xSoQGsgdy@d8!1ZFID z^xs#%Q%N@;kBr4Nc^I)-#!^gWF&4@k#E&w7du!9)1M9kSuK)~3&s0^CClZ1H!t%rA z1!hSLHPzg7NXQ5iHwVi(q9@?@>YF&yB;T!5NLLi0S5V`r>97Z%A*E@o5FQSylgF}I z$|UUKERzeb+k5q*ka3#IF$5&b!n1sYJVl8jq-?*abOhgsz^7fKIZx^u16^b!!irE) zliea8o?wDRVED$BY)S#iGM2E(;yWdas(4MAQ0h8vDCD=tsuhvHJytE{{3fir`I^vg zXUXj`patW=)d-QGgw&5%{=)Q0+h z)BcM{Mn*K*q6N6Z{(CY!7}V^)Cxge2?(DytcrIc8$ti*)e1a0bE5rg=M{(y|tFV<4 zCwBj!l=*ZF;RoY~oFr^SlFH<$fAnGa1(%fSd&Ts8^!|2BO!&gb^SiQk=%Ba;IwAX$ z(zddl7S>Wt)##8c<1FKpNcG!o+~^G$vwbqdREFyfl~u0H z{yFSDhjX$3$sn3ybk%Ji-|ARMMm#~+l94m1@KNepbP3}3a1 zbm0IO7cjzzj%@e6G00IF`CGxQ{qZLKQEKlPA zkaNbv-h&748H^A(&e$AdIG>{7--t+(u*rP^Gn&#_p0A92KM(r<_Uqn*pa0LruMaLR?gg-0ArE{8$=*q>C}ABH3XW!;RM^6u*-r4^*@vLY6>m}s)>#z0Pq1O-wH#}S%xVXyb2AQLtSE_-*0FItDd}3uGVK>%7 z)o_BL23hzD^|$Y|i!dW{8cG&AtOkPs0)Y`nS^RiIW*9&)rkKRKiYeM341#j`ZeTdP zE)0hoU^px=Y@lLivKb^Sz>6j(ezyugYRiZ;Nw8P-_$z(m#KjG{1|cJyn9bKd)LVl- z*kz^-kaL&^E66BP#bGHDib}g3B zhZn`Kvb|%%F_o@Rx8k^pq@{1RPAZ|8<#$F?y^GPLg70}IY1~r3;kthoYM&XRnF5G91p#8%M$Th8SaInZ>>_{?x;L{im08|kp! z7>F!_aAOvUN{H|OlBr}u1|%?QS9%Oo$nj=>z_|) zg8gD#YCcje&LJ>Dp^Ny_pz)X$)r|Fz46Rt-*4T% zk!AO$3kyD9BAVbeU|cR)GuO6 z8ZA5nl4WY#DsRJ9My&qTt2AvoRjFpbWH*Ee9mB34l;eTf)8kPm%TW!}O2fL9zCD|z z<2q}2RM6NS|D!S@iBv+zTG~n-c1!sZCU4A)t+RT~C|tqbE%>Zva{JX8c1k9@-<5%O zCAxzP?2xvW+rk8C>=wu@v91Br@v2iGfY7I(3o+ZfEz|7AyK{>s>z7v7w*Iu}|8@g? zdj`M?{r^CHtDXND4({T=Zsge{{_F4BZy^yzBsx_yi9kN55n4~E{c8WR-;NoVS<$oCXTwZPkIA-tAwPLl*i z2$GXjs2Lc8WDwJ_K7Ax%L1qcWsHCvMqHuQ->kkFS6`C}aIKhUi^Q9u3@8^6!#p1Ku z;B<4pP$yX0?Eq~IPGJ{$8}LWZR_u_sMFN$v)Sm6aIPBsd72s_#BYVwK-2on^0dM5Z zGT^g9`CScU<+~o)x*cS{9Tf-kTL1!N3YKpOs;Tx`KwyS4Xtd$txLXmZL^4`ZIe;{k zRcL$Vw{gOVeDbLN-8H9Kwb|fj#bPZh<#Ma;*u*VJuG9bv<+pOj>+HOmz$6q!M^=QO;j7cJJc~FNT&X?L#Z?6CLoWsre z|AxciLEZoNnSPWBQGwFuJamCeG`oO1_;V=QKw6 z43g(*1Wyk2Pda;-kH_>Q1pTJQWRQHpQJFF(Wtc`&;p`$Ri7;WTqeY3jS;JO!z%D4w zO^^OJBB*x6{C0-OXW*D6Bti)O96<0}aQRM=f^g$JNfz)&P7*q%7z4>N-Py4B6B_8c zyi{!{%taC2D%cEtt6Y;vYvBTv;+xPJwMM9%QUSY`R4?DWQ)RU!oME&V_Fj)&EQkS8 z1n_#ar=@|b>8?X`74jC_Ua21hX%twC?!JP4FSR>@YxApzXF(1F zrMh$$xK`e7j9{G$E6_~4n=sp52*N^|X+O~^WEdzm-ze=nb@fAQYTNFQ+Ie2TJ`tYjqV!wzz zeVdsRC&ovrurX^O`YvD>MWEk%ITK+*=a@RRA{WSQ3WZ|j^A4k^B5p-tDTeSoN!YnC z2P&nl#Ef^)#m4Ubo(pN6#|82Cbd?c_&dv#sO9wnns9b~^gFn-B%&wLgb;tGJw5+Mx z7!W^-x1^-WBdGh&(qy5Q#dCxynX7Khk&~oOQ=!%@|BUi=`?IS&+F1D;-oLtLQuSIF zN=gfXDxja$*KVsNH0y1sE%xnkt2*D8iizGyZFrtb&!wrK`f7^9Ic!%GnmSWwQ6JHg z0Hm54&B!;fKdV=fG zEVxtwIC^Gsyj3P{%e<*(@oCJQYK>}GLldHE@duJ+E>O^myimA21DeM8aapZ<1=8KY z6Dy~i1F?Fx6^A$&2ab|coTK6`eNG|aNa6)V+CGifnw8~|3FB4uws$KBUiwD9)@C6D z_QXQ`p_=ojeuie)a<1ke*n=R!bRwq#3x~Ezp4DJ;yck~Q`zzK|d4xifV zvitRHY{dsx)B(05=anB0AhaW06t+BiY%6_d#ByDB7?ZeX6t;kT?Wy085ozhJ_m<>nvtwHT zqvHaezfze+#C{25B8ivIv^xIJRu^t4d#crT8n!mjQPvBY{|uuik1&n=9CV+&{7GIs zb1g^{Q!+|0_9GKYCVu8~ZdY{SJ(ol9*qajdGn(zA?3OG$D#h_kO}@aP5qKE2FoqxL zT1Q16w7S$O(`K*w&9V8=azxP_{cK0X(}uQn)U+Fy);VM_@Yuo1{Mzuplf3B5Zo*F+&y#FQV7Rwu{(O_qkkbf;d$5~lS+mq|DQQDAvT@`SGA5YAd z!1E;eo=R;82fzIClSd5*{xg8jYIzWn!{c>9F5|t?@rulfBVC&>-PmeAYm33CQ-ap^9>v`7GNNDz6Wx>II!Z#&J$rF1%IT&Pb=BYIRzyqo10RtF+QD zrV?&hMR2|C-_+uCmq6rpJuUu!$vBzd&BcEYhff;u-*^818+tZB|LLDmdS`eAUL-`c zo;PyL6sZE`A*14WeuVA5IIqCEhe2yim8OpUpmEer9}jp~`Pg!Dv+m8Yhk_c_{4C7X z7N0GzwA4kaC1|sji&@1#v>UimWUuB{ax1G}#soe868sYQ=dAqIepOwgUbJJ@*_%5N zfBT-M{4Y;)ZEFQsA^!(Y2KDp*j~_j{yZ`Y1pv*s>HDXTiD$N}Em8BzVJrKQA2@rR0-Y;=cHYO53tW`&D*r9c5?z7nvn{?X_>w zxx(iBH$JZ$jQ@NzXw3gdkDolgoBucQY%u@LVIG>AT%44p+Ic=vR<^TwtxvyO0vP79 zuEq&UJMWhp+b-#ueXHyA-ODxQLPx{>GPfIdd;aY>>-OHWSLyr%;qDp+{FpH=;nSxQ zz{SP0d%I`(2qT$j;y8CezqpZO?Rz-vDJ*M2L!ZI#f~870J_|l+Pi?45m_t+-7Z(A1 zh7l3?eE>z;q6C!cCy2*<>ar5_IMG)o5V`&ke|I(J!`xR*y&x zl;@<>UvwZumQd}H5bB4{45zeS+ikCgcHzAs0{_;isy%^?6Y}*o{H3B3T6rkGtHdrC zXJQC@U5DCBzhWnpj@?;VF2G~XW^TzeBe-(pmTqMf8>Z&3jb>H@aOqJ}y|EiR-Ux<4 zx%+NspxuNCyvlk_l5a=9s}J{T&i|sA9nGSp#;&~wr{7F-7Gx%jnd6+|xe3fjCFOQg zl#Sv3H{!naAp%Xo-8W;l;ycrzm5BgzglDkpc3MhgsvP2dc;>3LxylM>>0FIpxf^Gy zXo#@HZ))~s9Sv0v+ID7vaa+=QEA#$t+wq0%a{tOqxDj(`S`%O8q z(q290!**Y_Uw-2_M=tO?_44Q$*gtKlDwp|1>w|o`EyS>OTWGJcqvx?hEnp<<*r@CB zuG>imw?qHDd%o<`)c?;3PiZ>Yq6x6l|2t^-e-9qt-T!?f&j$McPlhpoj94yh!e`Es zL}!L2lVxgu!Be*Udoo#){_lh_xlGQtLi2s5B#mLW@Js|Q=r8~;q2Hd(DOAti_u1^w z{*9(F1bzO?FY%x6eHK%4@c7A5VA2i!^!((_>o%9V#oj}(%0^n`zBLIw%tm&y0FJ7gn8xN57MU{|H>qv!9mw?M2RZ{SrgO?!YQm;< zaAtP~T1y+`!X=^2wQom~H16A0`l^+_SF-2%F76hO{~=F9{(F%n`@cm*2$IH}Txl^_ z<^Os5_;F4CKYcp9%l~>K&j#|}M(7~Ca9jbrp6cBkB2|L5k>Y=y7^afn3V>bCA(!~6 z2(ofPyj5Fay}*oWbh#~Of-%a@x)h5XZA6BPfi18u93P@@u{G_w=&!cO)UXIlEn9Mj zW{4>3GOoxP!b@ZC9hv@iu952!*Rwurq3KH>+Dmmzb2zk^&mhapib1i zQkw)LHhR+;iP*xM!79W`2Uqi3dst!T6}By0ILi}Bv&MB84sJ{2q8|!aJ8re=y7uS! zN19N=7ckCKqb6CGwZ6)LPNvfN(ipED=vgYeR?dXte(Y{(^aZ5CO0+AUv#>T7}#<{a=fdq!S?}nkBIBo653as ziAuP2L|C`Evad>acY4K)_eM1LCB0J+3RS@7RJ--F&+o*FF|W_Ew&ARPSueJ7x&A*R zoRWBSMOV-Y{r~CXM*QE?!@K*xZ|1p-{{MsGikIJRUHf<3c58Hh*U?VRU!Q)vn%3{y zxE`Iqg`^v4{I0$QM{+s6w9;RL)vodr9!;r4eb?tY2zkZpka9WgHXUkklq6OaI?RR> z#$<=-z`ajFrPUTVNM?JeTtSD6V+t;K#!MI=6>(&9~s$Mq>_Lh6y*7nVGDahC9o7t)n)7gVn z?ip`7UBW$ct*+2z_QqG@G+Wk%s|dgAcZGgwXUi>omizxQCgg;p_#?TB3vh-1Z}|A> zldAvkU@&}qm;dKRp3C_Ejty75``_Ph-T&t?+^ul|mN<300LwC0^8$KpU5^*AoxmG8 z0zD8{JO zbK`RQeT)%}u}Cd#Z;(Q;*+4Cx%NDgJv*iLqm%_A?Zs!aaeKzj9Z_5_0&RcPG(ja@W zkHa?B30-Jvv36@zO-gsJ8q0f7)$nV&ct_II)>2+O9(x*2(O2NCtYx$B_>PV0sDCm4 z*6Jm4Gmpn=c-~582-SI~#Rd#oZ)EkpNW01Baun^>$JE26-Cwm=?amUju(OR#0dLtY z=5=vHj=7w3Yzd$%`p5ji`Z`=>4V`bpA?VN>uhCDlUHyOU9$ky{D2x7BY-+ETAX*=8 zPR%8J3;rC-8Y*KoX=_`hX34aZwHvEYdyCf~NqlAXa-yWF?taBw+}fY*NjIO+8%nx5 z)D@t%Ebsi*vdfFSR^#<6W|z)BtzelBmdI+;+~p5gQ!!s*D&Tt{ZOqZCooA+yIt5)>7RT7yR{3_ zYW)b>0y_3q)@oM3KU%xy9EV-r_AA{(S--xzJru1O#u-!LyCydxRpDSMZ0~dMgJ83u4$|JRh@QT zyjzWw1+V$_UYA>v6l_-^~5g4&#cpnE`q$ola&| zGl}AzDQ0@VHl?*s#x9Q6Xk~3p)97B>yNB7-@yBdA>0eASIxDaE)b!T)Yl!!Sqo^=C zn-kJzPQtF$3*bMV!SK=E+9T1bT3mtuTjBZV7rX*as8^S$-3|1rJ+s~g9r~4Oz~=nF zeW175Nd6!EEVuvth3@iRfK~Z_pBxVA@m~i|hIjV=O+1$| z|E)c&%4kb}giT}LDDS$wp7k$SIvx!4y~1^Uu(<9+zY4mH{UX-E>QDW_!0ON)tqr%^ z+OTMC9euD%4Kx>?w9=-n3(d<|^XwDvk2Dy7cR=}>8J*SolTfBgh&_Wq|;?VDn@Zx)%DNYdU!cUZ(4N`JYInY&`b z!aY{8rZ&CHzrn*{G0>exlf4~l$tC*B6|jQK++|ZsXZz|tb@nBwr>I*wB`X(<`Kq$_ z^KR1I?4+sLAr0uYo9~OF`T`8Ef1W2<^)S=s$+-I-`;~L2?zFt@6;0)g>pJ3T^ljHM z&q);ozT+tjO3P@^Wn}Z-G&jTNjcsuMwn8->>{3=KGC}zw=N!}0s~9vcLnUckNRG;V zdX1Jgx)#x^Uq_=faNvDuOGl=NVeO+|(qB>+toV)iC2cW-I<9jJ_d4Rhs_p>;USI0g z5NpK+EhLWNe!s8OB4vv`yQhj8!KrK5djB=X9N{VMBIwKPlVQ&ZC zPpJTrXBp#CfS6*E=#Utg5gAQsI(Y~j6C&x{E}P|hlE%FqNO59iPe)v7EicqU*6TfopZ|f$tor)bU3asXS~fy4)i;doOP0|{ z>?fw^Z+a;d`#Y-4o_3B;ILk97QViEY!X`9=5z2E^0>>g^>V>`D&JMi){@-7o^m?bK zr%JQ##h76lV;WJk+Phj?k1RaB&Rak05e&kQ;YSygV=rSnDy~Gcjrf>E8ChGk;R61JErg$VF(DDgD)u zVM+vy6pu+1%Er(;Ihg|SvqMv1!&8(f;JCb0?<7wponaNljI%hTY<~}Szy0p`WG{r5 z8cR@r6?dZNlFhV1^ZxsH5FwXzOd}#uJXCx?(KjikI&FetP4%bh?}FtVNLECV*?Dlx zQTq}El_+|>zK`xO93K3+*Ejt=42R*sR8clADtai6Kp3+mVdv)hz)@oE^EKNijuXh7 z&_sW;hM%3umPK^@OT;qNhG9&{W7JB!z^KG@2cD0|G^LU%JU=U>)GAJ6Oceo;ga3Sn zmnb4mwUr2KKcC^%$IRTe_&UvUxw=B{bAS1>>if2;eeQjRQ#<2HL8&lhF@}PToc7C!PkF#`!=v{mhzhAZ=at8>fiqk_D*3LCR4)W3MT5s zO=FU=*pj3{lZ?d^7Wt z%_%)?!`Y=qDko6H?f~Bj!86h{tl8;E#Kyd>s zPriNr0yqkm^9VOVb|Wk!9=9R6HkL0=US5Kb8}p_0UnqsiN7Z2|OjH6jzG|(pYTasH z&fCNA@Xy=AQVaT5oHM?Wh`)B}zO83tZEZcM8>}s@)qwpN{8v|0CHOA@+;q@3!%N-iS;-_xeGdmyD zwkD^XodZchBd9GS{az?LO;1CEF%WHRgr!DRZ=k-%?ml=s?8U3$9#j=DI~!lm$Yiy` zbyL>MrJq%E(etzw${kprO%W%fzUJ?H(B+qp^vJhH2kmX5YV#CF0YX@Gk z=nT2xK{&w)6_PK&hV{Q8GZe5JW5zKe65}JaKtZ($j%keixNHb$DkPG4uh#WqvUK)- z_^|ui!Cpz5YLkV*8zJlMqJhTPh;9v_jvUyx7{aRPby` ze0(*Fdihi)g*6*SBs#-Xdt3f)<2iu1xnQ{rY$3o@%?0C(Rx2$tGw1p7>q0p#cwZo& z(+FMg3}Zp@?wIKynGxZE6=@2}&#pBmTokyJNgCDspT_15Dcc_mGdiHF*kgci>@m!jbGu)y5Zw9z6m0$ zPU>PMu1{+lakhMH+zQ-Ci`k-M)=%x)iLFHHyL_w<_5`y<@zd8twJGwdQvcW89S2a@ zRFW-5$u_vJLB2CwoI;&^Hni{z7wflrCGr)C^|adaC26#*haUM#2aMU;K5Zdi5fRHc zaFm?l9Ce%&9Ro=?l6V1;UK!%h*Z(R()P0+PsY)RTY=l7kp}Ilmi0s-P2F-T|!5#z& zrV}|0U^sw4NY2tpnTvf z{I@wxV!(7xIZJ2e;0UKWa!o7iW^;-d^qB|wZR3zIxCMa&w|H&8>1X3$xvk3D zOFmz^{af_-f@Q@~R6iJMjl1|lm=jl1!Tl> zX^$q`5+KP$3;7~S_jL29-QLa)yvs16Bmt@^D55FOi16aW6{zwEIJZ$#M?CmZfg{Pp2Qv(ZPr_k8#t|iHe>mv#Cx^XWmM6(EOK7wbS555k z0*C>BTvRO5(rV}E{pZO!S%~{U$0Z($X7_dIue|@zB$yQ_b@A8ZH%uOL6qw5U1|J)M zR3bz;CyO2cm1uH;EyvWQv`Q8r9MY))0&HBO??SJ4%WL^6QOaSj7vm`R$UQRIdmE%N zeQ{@!w7AmJEum+qz9{a-kCGFh>6r1EiQF{#6@))XCalP!M#$X4$y~lE9*__QQ>Esd}oATi8T!uao z6dij#VYa_tBt(c+y!rPj6DIvxiJ*iJEXil+_R&E@dI+z_j`xCo@DTiF-ssE^L12&5 z$5bdh1;h(Q(8%O!5R@swR>3&v2fZGNA{62W7UL>(pX-t^V{v&qP$%A%hE9;gKXEGY ztsVeD|GBcUcl4jQK?{HRJMHx{BB!h19^0IIqjDhQ3Zx=k$1-+ytYZd!r!pLdt~=ln zwnl&*&=k-}@913%ui1iUtIC7>}+A7pW)&Ml4Ug2Vxt1f zzAw_L7?@TIIKze68f%MHRUc{Eg@nQ1Y~(B@w#jT#pt=J-vO55UR;dcPEcoByq9CQB zrS7moELW21Cwsn3=Qjj_sh~Qwl%9)P!}Jq`(6rb%dkBKf5G0+UPyo(Jswd?{)s{>_ z=Vp&MV?t1UG<0E_)hfgkDHnBWh_D>pol=tTTUzP&{eHha8;qsONJU|IaXb@(9zYxL@_+qF3p3oF!$C!!Wc-|1g~&6*mpL z^gPGU-@W_k?a9ktsbtRGCgM@g*F6m>_1zHT>X#+t@*_Blw2fWSgPqr;+_QNc{pSo9 zOItki@vOS6X6f^< zh(?r=1i2KIVY9iZv@lkdHVO%|h0VdL6Ia%T>RAvxtWon>5NMviUn{z1X3Tm6_uN$f zO@XLo%k0kh*(>H9e#{t`;DLE|Z}%)8VI&h>*=5kxu?!+35f+CbN^XEYgWm;96?)Ht zPoa`|p~r_8ff8^;;FCwt@5dOi825T@gcx3m5JR63!|f1acnyRYwiCjo75mX0>9#?B z42Iz#9Q1lWzfIu{o8xSR9EOJv;b3qucxbaE9JmCLa83khgG3oiW13Pi#kf36HlcEw zk94vx#mF`%+m4V#=AzHWeL2Ox&9%7q5ag5!n33NZ_cJk=t3ib7wpC{eFIF@q=>&yI zr)Bb*sqbahFgxS4xgePm5sYW72>dToT#b>)oGVaqY|>wut{xhFN<&ez(kj3@T%>5q z_5i39n2eQ)MR;trjDlpZ-hLnUdJi7_q+{tU;^)W_sLkz$HXn1H2>$1cX% zz7~cYE)SaNuRe@aRZmV~*9s6#hS35>OioRu1KqttM|%&D8d;MFPj|lx^PmaSsGfhMe8`yc3B zq-D}N#%*78SRvOKs<+$x|%$LNRKL++LQWb2yaA z8}uZh1sfUWdTrefR*QDI7;0rr@Rt{Eug@qLMsQjG?7VrX;hC_`^uC0#5?>@;02Lxf zv3`?AU$?W!@~Mb0C7iM%!IBv$>wxiV#|(vP-U%!>8%erQ<5;3m_QIT+tj;yRYi7wPf#W=Zgr;Z0@PcbuwOGlYDRapK{h3@ulk_d>(3ARlG&e!UsFQfyXWq?d+weadj4Mk P00960<_VnJ089Y@bqU3V literal 0 HcmV?d00001 diff --git a/chart/deps/redis/ci/extra-flags-values.yaml b/chart/deps/redis/ci/extra-flags-values.yaml index 71132f7..8c1dcef 100644 --- a/chart/deps/redis/ci/extra-flags-values.yaml +++ b/chart/deps/redis/ci/extra-flags-values.yaml @@ -3,9 +3,10 @@ master: - --maxmemory-policy allkeys-lru persistence: enabled: false -slave: +replica: extraFlags: - --maxmemory-policy allkeys-lru persistence: enabled: false -usePassword: false +auth: + enabled: false diff --git a/chart/deps/redis/ci/sentinel-values.yaml b/chart/deps/redis/ci/sentinel-values.yaml new file mode 100644 index 0000000..48dfa1d --- /dev/null +++ b/chart/deps/redis/ci/sentinel-values.yaml @@ -0,0 +1,6 @@ +sentinel: + enabled: true +metrics: + enabled: true + sentinel: + enabled: true diff --git a/chart/deps/redis/ci/standalone-values.yaml b/chart/deps/redis/ci/standalone-values.yaml new file mode 100644 index 0000000..dfef688 --- /dev/null +++ b/chart/deps/redis/ci/standalone-values.yaml @@ -0,0 +1 @@ +architecture: standalone diff --git a/chart/deps/redis/templates/NOTES.txt b/chart/deps/redis/templates/NOTES.txt index 5c27951..07905a6 100644 --- a/chart/deps/redis/templates/NOTES.txt +++ b/chart/deps/redis/templates/NOTES.txt @@ -1,18 +1,18 @@ ** Please be patient while the chart is being deployed ** {{- if contains .Values.master.service.type "LoadBalancer" }} -{{- if not .Values.usePassword }} +{{- if not .Values.auth.enabled }} {{ if and (not .Values.networkPolicy.enabled) (.Values.networkPolicy.allowExternal) }} ------------------------------------------------------------------------------- WARNING - By specifying "master.service.type=LoadBalancer" and "usePassword=false" you have + By specifying "master.service.type=LoadBalancer" and "auth.enabled=false" you have most likely exposed the Redis(TM) service externally without any authentication mechanism. For security reasons, we strongly suggest that you switch to "ClusterIP" or - "NodePort". As alternative, you can also switch to "usePassword=true" + "NodePort". As alternative, you can also switch to "auth.enabled=true" providing a valid password on "password" parameter. ------------------------------------------------------------------------------- @@ -20,117 +20,137 @@ {{- end }} {{- end }} -{{- if and .Values.sentinel.enabled (not .Values.cluster.enabled)}} - -------------------------------------------------------------------------------- - WARNING - - Using redis sentinel without a cluster is not supported. A single pod with - standalone redis has been deployed. - - To deploy redis sentinel, please use the values "cluster.enabled=true" and - "sentinel.enabled=true". - -------------------------------------------------------------------------------- -{{- end }} - -{{- if .Values.cluster.enabled }} +{{- if eq .Values.architecture "replication" }} {{- if .Values.sentinel.enabled }} -Redis(TM) can be accessed via port {{ .Values.sentinel.service.redisPort }} on the following DNS name from within your cluster: -{{ template "redis.fullname" . }}.{{ .Release.Namespace }}.svc.{{ .Values.clusterDomain }} for read only operations +Redis(TM) can be accessed via port {{ .Values.sentinel.service.port }} on the following DNS name from within your cluster: + + {{ template "common.names.fullname" . }}.{{ .Release.Namespace }}.svc.{{ .Values.clusterDomain }} for read only operations For read/write operations, first access the Redis(TM) Sentinel cluster, which is available in port {{ .Values.sentinel.service.sentinelPort }} using the same domain name above. {{- else }} -Redis(TM) can be accessed via port {{ .Values.redisPort }} on the following DNS names from within your cluster: -{{ template "redis.fullname" . }}-master.{{ .Release.Namespace }}.svc.{{ .Values.clusterDomain }} for read/write operations -{{ template "redis.fullname" . }}-slave.{{ .Release.Namespace }}.svc.{{ .Values.clusterDomain }} for read-only operations -{{- end }} +Redis(TM) can be accessed on the following DNS names from within your cluster: + + {{ printf "%s-master.%s.svc.%s" (include "common.names.fullname" .) .Release.Namespace .Values.clusterDomain }} for read/write operations (port {{ .Values.master.service.port }}) + {{ printf "%s-replicas.%s.svc.%s" (include "common.names.fullname" .) .Release.Namespace .Values.clusterDomain }} for read-only operations (port {{ .Values.replica.service.port }}) +{{- end }} {{- else }} -Redis(TM) can be accessed via port {{ .Values.redisPort }} on the following DNS name from within your cluster: -{{ template "redis.fullname" . }}-master.{{ .Release.Namespace }}.svc.{{ .Values.clusterDomain }} +Redis(TM) can be accessed via port {{ .Values.master.service.port }} on the following DNS name from within your cluster: + + {{ template "common.names.fullname" . }}-master.{{ .Release.Namespace }}.svc.{{ .Values.clusterDomain }} {{- end }} -{{ if .Values.usePassword }} +{{ if .Values.auth.enabled }} + To get your password run: export REDIS_PASSWORD=$(kubectl get secret --namespace {{ .Release.Namespace }} {{ template "redis.secretName" . }} -o jsonpath="{.data.redis-password}" | base64 --decode) + {{- end }} To connect to your Redis(TM) server: 1. Run a Redis(TM) pod that you can use as a client: + kubectl run --namespace {{ .Release.Namespace }} redis-client --restart='Never' {{ if .Values.auth.enabled }} --env REDIS_PASSWORD=$REDIS_PASSWORD {{ end }} --image {{ template "redis.image" . }} --command -- sleep infinity + {{- if .Values.tls.enabled }} - kubectl run --namespace {{ .Release.Namespace }} {{ template "redis.fullname" . }}-client --restart='Never' --env REDIS_PASSWORD=$REDIS_PASSWORD --image {{ template "redis.image" . }} --command -- sleep infinity Copy your TLS certificates to the pod: - kubectl cp --namespace {{ .Release.Namespace }} /path/to/client.cert {{ template "redis.fullname" . }}-client:/tmp/client.cert - kubectl cp --namespace {{ .Release.Namespace }} /path/to/client.key {{ template "redis.fullname" . }}-client:/tmp/client.key - kubectl cp --namespace {{ .Release.Namespace }} /path/to/CA.cert {{ template "redis.fullname" . }}-client:/tmp/CA.cert + kubectl cp --namespace {{ .Release.Namespace }} /path/to/client.cert redis-client:/tmp/client.cert + kubectl cp --namespace {{ .Release.Namespace }} /path/to/client.key redis-client:/tmp/client.key + kubectl cp --namespace {{ .Release.Namespace }} /path/to/CA.cert redis-client:/tmp/CA.cert + +{{- end }} Use the following command to attach to the pod: - kubectl exec --tty -i {{ template "redis.fullname" . }}-client \ - {{- if and (.Values.networkPolicy.enabled) (not .Values.networkPolicy.allowExternal) }}--labels="{{ template "redis.fullname" . }}-client=true" \{{- end }} + kubectl exec --tty -i redis-client \ + {{- if and (.Values.networkPolicy.enabled) (not .Values.networkPolicy.allowExternal) }}--labels="{{ template "common.names.fullname" . }}-client=true" \{{- end }} --namespace {{ .Release.Namespace }} -- bash -{{- else }} - kubectl run --namespace {{ .Release.Namespace }} {{ template "redis.fullname" . }}-client --rm --tty -i --restart='Never' \ - {{ if .Values.usePassword }} --env REDIS_PASSWORD=$REDIS_PASSWORD \{{ end }} - {{- if and (.Values.networkPolicy.enabled) (not .Values.networkPolicy.allowExternal) }}--labels="{{ template "redis.fullname" . }}-client=true" \{{- end }} - --image {{ template "redis.image" . }} -- bash -{{- end }} 2. Connect using the Redis(TM) CLI: -{{- if .Values.cluster.enabled }} +{{- if eq .Values.architecture "replication" }} {{- if .Values.sentinel.enabled }} - redis-cli -h {{ template "redis.fullname" . }} -p {{ .Values.sentinel.service.redisPort }}{{ if .Values.usePassword }} -a $REDIS_PASSWORD{{ end }}{{ if .Values.tls.enabled }} --tls --cert /tmp/client.cert --key /tmp/client.key --cacert /tmp/CA.cert{{ end }} # Read only operations - redis-cli -h {{ template "redis.fullname" . }} -p {{ .Values.sentinel.service.sentinelPort }}{{ if .Values.usePassword }} -a $REDIS_PASSWORD{{ end }}{{ if .Values.tls.enabled }} --tls --cert /tmp/client.cert --key /tmp/client.key --cacert /tmp/CA.cert{{ end }} # Sentinel access + redis-cli -h {{ template "common.names.fullname" . }} -p {{ .Values.sentinel.service.port }}{{ if .Values.auth.enabled }} -a $REDIS_PASSWORD{{ end }}{{ if .Values.tls.enabled }} --tls --cert /tmp/client.cert --key /tmp/client.key --cacert /tmp/CA.cert{{ end }} # Read only operations + redis-cli -h {{ template "common.names.fullname" . }} -p {{ .Values.sentinel.service.sentinelPort }}{{ if .Values.auth.enabled }} -a $REDIS_PASSWORD{{ end }}{{ if .Values.tls.enabled }} --tls --cert /tmp/client.cert --key /tmp/client.key --cacert /tmp/CA.cert{{ end }} # Sentinel access {{- else }} - redis-cli -h {{ template "redis.fullname" . }}-master{{ if .Values.usePassword }} -a $REDIS_PASSWORD{{ end }}{{ if .Values.tls.enabled }} --tls --cert /tmp/client.cert --key /tmp/client.key --cacert /tmp/CA.cert{{ end }} - redis-cli -h {{ template "redis.fullname" . }}-slave{{ if .Values.usePassword }} -a $REDIS_PASSWORD{{ end }}{{ if .Values.tls.enabled }} --tls --cert /tmp/client.cert --key /tmp/client.key --cacert /tmp/CA.cert{{ end }} + redis-cli -h {{ printf "%s-master" (include "common.names.fullname" .) }}{{ if .Values.auth.enabled }} -a $REDIS_PASSWORD{{ end }}{{ if .Values.tls.enabled }} --tls --cert /tmp/client.cert --key /tmp/client.key --cacert /tmp/CA.cert{{ end }} + redis-cli -h {{ printf "%s-replicas" (include "common.names.fullname" .) }}{{ if .Values.auth.enabled }} -a $REDIS_PASSWORD{{ end }}{{ if .Values.tls.enabled }} --tls --cert /tmp/client.cert --key /tmp/client.key --cacert /tmp/CA.cert{{ end }} {{- end }} {{- else }} - redis-cli -h {{ template "redis.fullname" . }}-master{{ if .Values.usePassword }} -a $REDIS_PASSWORD{{ end }}{{ if .Values.tls.enabled }} --tls --cert /tmp/client.cert --key /tmp/client.key --cacert /tmp/CA.cert{{ end }} + redis-cli -h {{ template "common.names.fullname" . }}-master{{ if .Values.auth.enabled }} -a $REDIS_PASSWORD{{ end }}{{ if .Values.tls.enabled }} --tls --cert /tmp/client.cert --key /tmp/client.key --cacert /tmp/CA.cert{{ end }} {{- end }} -{{ if and (.Values.networkPolicy.enabled) (not .Values.networkPolicy.allowExternal) }} -Note: Since NetworkPolicy is enabled, only pods with label -{{ template "redis.fullname" . }}-client=true" -will be able to connect to redis. -{{- else -}} +{{- if and (.Values.networkPolicy.enabled) (not .Values.networkPolicy.allowExternal) }} + +Note: Since NetworkPolicy is enabled, only pods with label {{ template "common.names.fullname" . }}-client=true" will be able to connect to redis. + +{{- else }} To connect to your database from outside the cluster execute the following commands: +{{- if and (eq .Values.architecture "replication") .Values.sentinel.enabled }} +{{- if contains "NodePort" .Values.sentinel.service.type }} + + export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") + export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ template "common.names.fullname" . }}) + redis-cli -h $NODE_IP -p $NODE_PORT {{- if .Values.auth.enabled }} -a $REDIS_PASSWORD{{ end }}{{ if .Values.tls.enabled }} --tls --cert /tmp/client.cert --key /tmp/client.key --cacert /tmp/CA.cert{{ end }} + +{{- else if contains "LoadBalancer" .Values.sentinel.service.type }} + + NOTE: It may take a few minutes for the LoadBalancer IP to be available. + Watch the status with: 'kubectl get svc --namespace {{ .Release.Namespace }} -w {{ template "common.names.fullname" . }}' + + export SERVICE_IP=$(kubectl get svc --namespace {{ .Release.Namespace }} {{ template "common.names.fullname" . }} --template "{{"{{ range (index .status.loadBalancer.ingress 0) }}{{.}}{{ end }}"}}") + redis-cli -h $SERVICE_IP -p {{ .Values.sentinel.service.port }} {{- if .Values.auth.enabled }} -a $REDIS_PASSWORD{{ end }}{{ if .Values.tls.enabled }} --tls --cert /tmp/client.cert --key /tmp/client.key --cacert /tmp/CA.cert{{ end }} + +{{- else if contains "ClusterIP" .Values.sentinel.service.type }} + + kubectl port-forward --namespace {{ .Release.Namespace }} svc/{{ template "common.names.fullname" . }} {{ .Values.sentinel.service.port }}:{{ .Values.sentinel.service.port }} & + redis-cli -h 127.0.0.1 -p {{ .Values.sentinel.service.port }} {{- if .Values.auth.enabled }} -a $REDIS_PASSWORD{{ end }}{{ if .Values.tls.enabled }} --tls --cert /tmp/client.cert --key /tmp/client.key --cacert /tmp/CA.cert{{ end }} + +{{- end }} +{{- else }} {{- if contains "NodePort" .Values.master.service.type }} export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") - export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ template "redis.fullname" . }}-master) - redis-cli -h $NODE_IP -p $NODE_PORT {{- if .Values.usePassword }} -a $REDIS_PASSWORD{{ end }}{{ if .Values.tls.enabled }} --tls --cert /tmp/client.cert --key /tmp/client.key --cacert /tmp/CA.cert{{ end }} + export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ printf "%s-master" (include "common.names.fullname" .) }}) + redis-cli -h $NODE_IP -p $NODE_PORT {{- if .Values.auth.enabled }} -a $REDIS_PASSWORD{{ end }}{{ if .Values.tls.enabled }} --tls --cert /tmp/client.cert --key /tmp/client.key --cacert /tmp/CA.cert{{ end }} {{- else if contains "LoadBalancer" .Values.master.service.type }} NOTE: It may take a few minutes for the LoadBalancer IP to be available. - Watch the status with: 'kubectl get svc --namespace {{ .Release.Namespace }} -w {{ template "redis.fullname" . }}' + Watch the status with: 'kubectl get svc --namespace {{ .Release.Namespace }} -w {{ template "common.names.fullname" . }}' - export SERVICE_IP=$(kubectl get svc --namespace {{ .Release.Namespace }} {{ template "redis.fullname" . }} --template "{{"{{ range (index .status.loadBalancer.ingress 0) }}{{.}}{{ end }}"}}") - redis-cli -h $SERVICE_IP -p {{ .Values.master.service.port }} {{- if .Values.usePassword }} -a $REDIS_PASSWORD{{ end }}{{ if .Values.tls.enabled }} --tls --cert /tmp/client.cert --key /tmp/client.key --cacert /tmp/CA.cert{{ end }} + export SERVICE_IP=$(kubectl get svc --namespace {{ .Release.Namespace }} {{ printf "%s-master" (include "common.names.fullname" .) }} --template "{{"{{ range (index .status.loadBalancer.ingress 0) }}{{.}}{{ end }}"}}") + redis-cli -h $SERVICE_IP -p {{ .Values.master.service.port }} {{- if .Values.auth.enabled }} -a $REDIS_PASSWORD{{ end }}{{ if .Values.tls.enabled }} --tls --cert /tmp/client.cert --key /tmp/client.key --cacert /tmp/CA.cert{{ end }} {{- else if contains "ClusterIP" .Values.master.service.type }} - kubectl port-forward --namespace {{ .Release.Namespace }} svc/{{ template "redis.fullname" . }}-master {{ .Values.redisPort }}:{{ .Values.redisPort }} & - redis-cli -h 127.0.0.1 -p {{ .Values.redisPort }} {{- if .Values.usePassword }} -a $REDIS_PASSWORD{{ end }}{{ if .Values.tls.enabled }} --tls --cert /tmp/client.cert --key /tmp/client.key --cacert /tmp/CA.cert{{ end }} + kubectl port-forward --namespace {{ .Release.Namespace }} svc/{{ printf "%s-master" (include "common.names.fullname" .) }} {{ .Values.master.service.port }}:{{ .Values.master.service.port }} & + redis-cli -h 127.0.0.1 -p {{ .Values.master.service.port }} {{- if .Values.auth.enabled }} -a $REDIS_PASSWORD{{ end }}{{ if .Values.tls.enabled }} --tls --cert /tmp/client.cert --key /tmp/client.key --cacert /tmp/CA.cert{{ end }} {{- end }} {{- end }} -{{ include "redis.checkRollingTags" . }} +{{- end }} +{{- include "redis.checkRollingTags" . }} {{- include "redis.validateValues" . }} +{{- $requiredPassword := list -}} +{{- $secretName := include "redis.secretName" . -}} +{{- $secretPasswordKey := include "redis.secretPasswordKey" . -}} +{{- if and .Values.auth.enabled (not .Values.auth.existingSecret) -}} + {{- $requiredRedisPassword := dict "valueKey" "auth.password" "secret" $secretName "field" $secretPasswordKey -}} + {{- $requiredPassword = append $requiredPassword $requiredRedisPassword -}} +{{- end -}} +{{- $requiredRedisPasswordErrors := include "common.validations.values.multiple.empty" (dict "required" $requiredPassword "context" $) -}} +{{- include "common.errors.upgrade.passwords.empty" (dict "validationErrors" (list $requiredRedisPasswordErrors) "context" $) -}} diff --git a/chart/deps/redis/templates/_helpers.tpl b/chart/deps/redis/templates/_helpers.tpl index 65735a7..cf6866d 100644 --- a/chart/deps/redis/templates/_helpers.tpl +++ b/chart/deps/redis/templates/_helpers.tpl @@ -1,158 +1,129 @@ {{/* vim: set filetype=mustache: */}} + {{/* -Expand the name of the chart. +Return the proper Redis image name */}} -{{- define "redis.name" -}} -{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" -}} +{{- define "redis.image" -}} +{{ include "common.images.image" (dict "imageRoot" .Values.image "global" .Values.global) }} {{- end -}} {{/* -Expand the chart plus release name (used by the chart label) +Return the proper Redis Sentinel image name */}} -{{- define "redis.chart" -}} -{{- printf "%s-%s" .Chart.Name .Chart.Version -}} +{{- define "redis.sentinel.image" -}} +{{ include "common.images.image" (dict "imageRoot" .Values.sentinel.image "global" .Values.global) }} {{- end -}} {{/* -Create a default fully qualified app name. -We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). -If release name contains chart name it will be used as a full name. +Return the proper image name (for the metrics image) */}} -{{- define "redis.fullname" -}} -{{- if .Values.fullnameOverride -}} -{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" -}} -{{- else -}} -{{- $name := default .Chart.Name .Values.nameOverride -}} -{{- if contains $name .Release.Name -}} -{{- .Release.Name | trunc 63 | trimSuffix "-" -}} -{{- else -}} -{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" -}} -{{- end -}} -{{- end -}} +{{- define "redis.metrics.image" -}} +{{ include "common.images.image" (dict "imageRoot" .Values.metrics.image "global" .Values.global) }} {{- end -}} {{/* -Return the appropriate apiVersion for networkpolicy. +Return the proper image name (for the metrics image) */}} -{{- define "networkPolicy.apiVersion" -}} -{{- if semverCompare ">=1.4-0, <1.7-0" .Capabilities.KubeVersion.GitVersion -}} -{{- print "extensions/v1beta1" -}} -{{- else -}} -{{- print "networking.k8s.io/v1" -}} -{{- end -}} +{{- define "redis.metrics.sentinel.image" -}} +{{ include "common.images.image" (dict "imageRoot" .Values.metrics.sentinel.image "global" .Values.global) }} {{- end -}} {{/* -Return the appropriate apiGroup for PodSecurityPolicy. +Return the proper image name (for the init container volume-permissions image) */}} -{{- define "podSecurityPolicy.apiGroup" -}} -{{- if semverCompare ">=1.14-0" .Capabilities.KubeVersion.GitVersion -}} -{{- print "policy" -}} -{{- else -}} -{{- print "extensions" -}} -{{- end -}} +{{- define "redis.volumePermissions.image" -}} +{{ include "common.images.image" (dict "imageRoot" .Values.volumePermissions.image "global" .Values.global) }} {{- end -}} {{/* -Return the appropriate apiVersion for PodSecurityPolicy. +Return sysctl image */}} -{{- define "podSecurityPolicy.apiVersion" -}} -{{- if semverCompare ">=1.14-0" .Capabilities.KubeVersion.GitVersion -}} -{{- print "policy/v1beta1" -}} -{{- else -}} -{{- print "extensions/v1beta1" -}} -{{- end -}} +{{- define "redis.sysctl.image" -}} +{{ include "common.images.image" (dict "imageRoot" .Values.sysctl.image "global" .Values.global) }} {{- end -}} {{/* -Return the proper Redis(TM) image name +Return the proper Docker Image Registry Secret Names */}} -{{- define "redis.image" -}} -{{- $registryName := .Values.image.registry -}} -{{- $repositoryName := .Values.image.repository -}} -{{- $tag := .Values.image.tag | toString -}} +{{- define "redis.imagePullSecrets" -}} {{/* Helm 2.11 supports the assignment of a value to a variable defined in a different scope, -but Helm 2.9 and 2.10 doesn't support it, so we need to implement this if-else logic. -Also, we can't use a single if because lazy evaluation is not an option +but Helm 2.9 and 2.10 does not support it, so we need to implement this if-else logic. +Also, we can not use a single if because lazy evaluation is not an option */}} {{- if .Values.global }} - {{- if .Values.global.imageRegistry }} - {{- printf "%s/%s:%s" .Values.global.imageRegistry $repositoryName $tag -}} - {{- else -}} - {{- printf "%s/%s:%s" $registryName $repositoryName $tag -}} - {{- end -}} -{{- else -}} - {{- printf "%s/%s:%s" $registryName $repositoryName $tag -}} +{{- if .Values.global.imagePullSecrets }} +imagePullSecrets: +{{- range .Values.global.imagePullSecrets }} + {{- $credType := typeOf . -}} + {{ if eq $credType "map[string]interface {}" }} + - name: {{ get . "name" }} + {{ else }} + - name: {{ . }} + {{ end }} +{{- end }} +{{- else if or .Values.image.pullSecrets .Values.metrics.image.pullSecrets .Values.sysctlImage.pullSecrets .Values.volumePermissions.image.pullSecrets }} +imagePullSecrets: +{{- range .Values.image.pullSecrets }} + - name: {{ . }} +{{- end }} +{{- range .Values.metrics.image.pullSecrets }} + - name: {{ . }} +{{- end }} +{{- range .Values.sysctlImage.pullSecrets }} + - name: {{ . }} +{{- end }} +{{- range .Values.volumePermissions.image.pullSecrets }} + - name: {{ . }} +{{- end }} +{{- end -}} +{{- else if or .Values.image.pullSecrets .Values.metrics.image.pullSecrets .Values.sysctlImage.pullSecrets .Values.volumePermissions.image.pullSecrets }} +imagePullSecrets: +{{- range .Values.image.pullSecrets }} + - name: {{ . }} +{{- end }} +{{- range .Values.metrics.image.pullSecrets }} + - name: {{ . }} +{{- end }} +{{- range .Values.sysctlImage.pullSecrets }} + - name: {{ . }} +{{- end }} +{{- range .Values.volumePermissions.image.pullSecrets }} + - name: {{ . }} +{{- end }} {{- end -}} {{- end -}} {{/* -Return the proper Redis(TM) Sentinel image name -*/}} -{{- define "sentinel.image" -}} -{{- $registryName := .Values.sentinel.image.registry -}} -{{- $repositoryName := .Values.sentinel.image.repository -}} -{{- $tag := .Values.sentinel.image.tag | toString -}} -{{/* -Helm 2.11 supports the assignment of a value to a variable defined in a different scope, -but Helm 2.9 and 2.10 doesn't support it, so we need to implement this if-else logic. -Also, we can't use a single if because lazy evaluation is not an option +Return the appropriate apiVersion for networkpolicy. */}} -{{- if .Values.global }} - {{- if .Values.global.imageRegistry }} - {{- printf "%s/%s:%s" .Values.global.imageRegistry $repositoryName $tag -}} - {{- else -}} - {{- printf "%s/%s:%s" $registryName $repositoryName $tag -}} - {{- end -}} +{{- define "networkPolicy.apiVersion" -}} +{{- if semverCompare ">=1.4-0, <1.7-0" .Capabilities.KubeVersion.GitVersion -}} +{{- print "extensions/v1beta1" -}} {{- else -}} - {{- printf "%s/%s:%s" $registryName $repositoryName $tag -}} +{{- print "networking.k8s.io/v1" -}} {{- end -}} {{- end -}} {{/* -Return the proper image name (for the metrics image) -*/}} -{{- define "redis.metrics.image" -}} -{{- $registryName := .Values.metrics.image.registry -}} -{{- $repositoryName := .Values.metrics.image.repository -}} -{{- $tag := .Values.metrics.image.tag | toString -}} -{{/* -Helm 2.11 supports the assignment of a value to a variable defined in a different scope, -but Helm 2.9 and 2.10 doesn't support it, so we need to implement this if-else logic. -Also, we can't use a single if because lazy evaluation is not an option +Return the appropriate apiGroup for PodSecurityPolicy. */}} -{{- if .Values.global }} - {{- if .Values.global.imageRegistry }} - {{- printf "%s/%s:%s" .Values.global.imageRegistry $repositoryName $tag -}} - {{- else -}} - {{- printf "%s/%s:%s" $registryName $repositoryName $tag -}} - {{- end -}} +{{- define "podSecurityPolicy.apiGroup" -}} +{{- if semverCompare ">=1.14-0" .Capabilities.KubeVersion.GitVersion -}} +{{- print "policy" -}} {{- else -}} - {{- printf "%s/%s:%s" $registryName $repositoryName $tag -}} +{{- print "extensions" -}} {{- end -}} {{- end -}} {{/* -Return the proper image name (for the init container volume-permissions image) -*/}} -{{- define "redis.volumePermissions.image" -}} -{{- $registryName := .Values.volumePermissions.image.registry -}} -{{- $repositoryName := .Values.volumePermissions.image.repository -}} -{{- $tag := .Values.volumePermissions.image.tag | toString -}} -{{/* -Helm 2.11 supports the assignment of a value to a variable defined in a different scope, -but Helm 2.9 and 2.10 doesn't support it, so we need to implement this if-else logic. -Also, we can't use a single if because lazy evaluation is not an option +Return the appropriate apiVersion for PodSecurityPolicy. */}} -{{- if .Values.global }} - {{- if .Values.global.imageRegistry }} - {{- printf "%s/%s:%s" .Values.global.imageRegistry $repositoryName $tag -}} - {{- else -}} - {{- printf "%s/%s:%s" $registryName $repositoryName $tag -}} - {{- end -}} +{{- define "podSecurityPolicy.apiVersion" -}} +{{- if semverCompare ">=1.14-0" .Capabilities.KubeVersion.GitVersion -}} +{{- print "policy/v1beta1" -}} {{- else -}} - {{- printf "%s/%s:%s" $registryName $repositoryName $tag -}} +{{- print "extensions/v1beta1" -}} {{- end -}} {{- end -}} @@ -191,202 +162,72 @@ Create the name of the service account to use */}} {{- define "redis.serviceAccountName" -}} {{- if .Values.serviceAccount.create -}} - {{ default (include "redis.fullname" .) .Values.serviceAccount.name }} + {{ default (include "common.names.fullname" .) .Values.serviceAccount.name }} {{- else -}} {{ default "default" .Values.serviceAccount.name }} {{- end -}} {{- end -}} {{/* -Get the password secret. +Return the configuration configmap name */}} -{{- define "redis.secretName" -}} -{{- if .Values.existingSecret -}} -{{- printf "%s" .Values.existingSecret -}} +{{- define "redis.configmapName" -}} +{{- if .Values.existingConfigmap -}} + {{- printf "%s" (tpl .Values.existingConfigmap $) -}} {{- else -}} -{{- printf "%s" (include "redis.fullname" .) -}} + {{- printf "%s-configuration" (include "common.names.fullname" .) -}} {{- end -}} {{- end -}} {{/* -Get the password key to be retrieved from Redis(TM) secret. +Return true if a configmap object should be created */}} -{{- define "redis.secretPasswordKey" -}} -{{- if and .Values.existingSecret .Values.existingSecretPasswordKey -}} -{{- printf "%s" .Values.existingSecretPasswordKey -}} -{{- else -}} -{{- printf "redis-password" -}} +{{- define "redis.createConfigmap" -}} +{{- if empty .Values.existingConfigmap }} + {{- true -}} {{- end -}} {{- end -}} {{/* -Return Redis(TM) password +Get the password secret. */}} -{{- define "redis.password" -}} -{{- if not (empty .Values.global.redis.password) }} - {{- .Values.global.redis.password -}} -{{- else if not (empty .Values.password) -}} - {{- .Values.password -}} +{{- define "redis.secretName" -}} +{{- if .Values.auth.existingSecret -}} +{{- printf "%s" .Values.auth.existingSecret -}} {{- else -}} - {{- randAlphaNum 10 -}} +{{- printf "%s" (include "common.names.fullname" .) -}} {{- end -}} {{- end -}} {{/* -Return sysctl image -*/}} -{{- define "redis.sysctl.image" -}} -{{- $registryName := default "docker.io" .Values.sysctlImage.registry -}} -{{- $repositoryName := .Values.sysctlImage.repository -}} -{{- $tag := default "buster" .Values.sysctlImage.tag | toString -}} -{{/* -Helm 2.11 supports the assignment of a value to a variable defined in a different scope, -but Helm 2.9 and 2.10 doesn't support it, so we need to implement this if-else logic. -Also, we can't use a single if because lazy evaluation is not an option +Get the password key to be retrieved from Redis(TM) secret. */}} -{{- if .Values.global }} - {{- if .Values.global.imageRegistry }} - {{- printf "%s/%s:%s" .Values.global.imageRegistry $repositoryName $tag -}} - {{- else -}} - {{- printf "%s/%s:%s" $registryName $repositoryName $tag -}} - {{- end -}} +{{- define "redis.secretPasswordKey" -}} +{{- if and .Values.auth.existingSecret .Values.auth.existingSecretPasswordKey -}} +{{- printf "%s" .Values.auth.existingSecretPasswordKey -}} {{- else -}} - {{- printf "%s/%s:%s" $registryName $repositoryName $tag -}} +{{- printf "redis-password" -}} {{- end -}} {{- end -}} {{/* -Return the proper Docker Image Registry Secret Names -*/}} -{{- define "redis.imagePullSecrets" -}} -{{/* -Helm 2.11 supports the assignment of a value to a variable defined in a different scope, -but Helm 2.9 and 2.10 does not support it, so we need to implement this if-else logic. -Also, we can not use a single if because lazy evaluation is not an option +Return Redis(TM) password */}} -{{- if .Values.global }} -{{- if .Values.global.imagePullSecrets }} -imagePullSecrets: -{{- range .Values.global.imagePullSecrets }} - {{- $credType := typeOf . -}} - {{ if eq $credType "map[string]interface {}" }} - - name: {{ get . "name" }} - {{ else }} - - name: {{ . }} - {{ end }} -{{- end }} -{{- else if or .Values.image.pullSecrets .Values.metrics.image.pullSecrets .Values.sysctlImage.pullSecrets .Values.volumePermissions.image.pullSecrets }} -imagePullSecrets: -{{- range .Values.image.pullSecrets }} - - name: {{ . }} -{{- end }} -{{- range .Values.metrics.image.pullSecrets }} - - name: {{ . }} -{{- end }} -{{- range .Values.sysctlImage.pullSecrets }} - - name: {{ . }} -{{- end }} -{{- range .Values.volumePermissions.image.pullSecrets }} - - name: {{ . }} -{{- end }} -{{- end -}} -{{- else if or .Values.image.pullSecrets .Values.metrics.image.pullSecrets .Values.sysctlImage.pullSecrets .Values.volumePermissions.image.pullSecrets }} -imagePullSecrets: -{{- range .Values.image.pullSecrets }} - - name: {{ . }} -{{- end }} -{{- range .Values.metrics.image.pullSecrets }} - - name: {{ . }} -{{- end }} -{{- range .Values.sysctlImage.pullSecrets }} - - name: {{ . }} -{{- end }} -{{- range .Values.volumePermissions.image.pullSecrets }} - - name: {{ . }} -{{- end }} +{{- define "redis.password" -}} +{{- if not (empty .Values.global.redis.password) }} + {{- .Values.global.redis.password -}} +{{- else if not (empty .Values.auth.password) -}} + {{- .Values.auth.password -}} +{{- else -}} + {{- randAlphaNum 10 -}} {{- end -}} {{- end -}} {{/* Check if there are rolling tags in the images */}} {{- define "redis.checkRollingTags" -}} -{{- if and (contains "bitnami/" .Values.image.repository) (not (.Values.image.tag | toString | regexFind "-r\\d+$|sha256:")) }} -WARNING: Rolling tag detected ({{ .Values.image.repository }}:{{ .Values.image.tag }}), please note that it is strongly recommended to avoid using rolling tags in a production environment. -+info https://docs.bitnami.com/containers/how-to/understand-rolling-tags-containers/ -{{- end }} -{{- if and (contains "bitnami/" .Values.sentinel.image.repository) (not (.Values.sentinel.image.tag | toString | regexFind "-r\\d+$|sha256:")) }} -WARNING: Rolling tag detected ({{ .Values.sentinel.image.repository }}:{{ .Values.sentinel.image.tag }}), please note that it is strongly recommended to avoid using rolling tags in a production environment. -+info https://docs.bitnami.com/containers/how-to/understand-rolling-tags-containers/ -{{- end }} -{{- end -}} - -{{/* -Return the proper Storage Class for master -*/}} -{{- define "redis.master.storageClass" -}} -{{/* -Helm 2.11 supports the assignment of a value to a variable defined in a different scope, -but Helm 2.9 and 2.10 does not support it, so we need to implement this if-else logic. -*/}} -{{- if .Values.global -}} - {{- if .Values.global.storageClass -}} - {{- if (eq "-" .Values.global.storageClass) -}} - {{- printf "storageClassName: \"\"" -}} - {{- else }} - {{- printf "storageClassName: %s" .Values.global.storageClass -}} - {{- end -}} - {{- else -}} - {{- if .Values.master.persistence.storageClass -}} - {{- if (eq "-" .Values.master.persistence.storageClass) -}} - {{- printf "storageClassName: \"\"" -}} - {{- else }} - {{- printf "storageClassName: %s" .Values.master.persistence.storageClass -}} - {{- end -}} - {{- end -}} - {{- end -}} -{{- else -}} - {{- if .Values.master.persistence.storageClass -}} - {{- if (eq "-" .Values.master.persistence.storageClass) -}} - {{- printf "storageClassName: \"\"" -}} - {{- else }} - {{- printf "storageClassName: %s" .Values.master.persistence.storageClass -}} - {{- end -}} - {{- end -}} -{{- end -}} -{{- end -}} - -{{/* -Return the proper Storage Class for slave -*/}} -{{- define "redis.slave.storageClass" -}} -{{/* -Helm 2.11 supports the assignment of a value to a variable defined in a different scope, -but Helm 2.9 and 2.10 does not support it, so we need to implement this if-else logic. -*/}} -{{- if .Values.global -}} - {{- if .Values.global.storageClass -}} - {{- if (eq "-" .Values.global.storageClass) -}} - {{- printf "storageClassName: \"\"" -}} - {{- else }} - {{- printf "storageClassName: %s" .Values.global.storageClass -}} - {{- end -}} - {{- else -}} - {{- if .Values.slave.persistence.storageClass -}} - {{- if (eq "-" .Values.slave.persistence.storageClass) -}} - {{- printf "storageClassName: \"\"" -}} - {{- else }} - {{- printf "storageClassName: %s" .Values.slave.persistence.storageClass -}} - {{- end -}} - {{- end -}} - {{- end -}} -{{- else -}} - {{- if .Values.slave.persistence.storageClass -}} - {{- if (eq "-" .Values.slave.persistence.storageClass) -}} - {{- printf "storageClassName: \"\"" -}} - {{- else }} - {{- printf "storageClassName: %s" .Values.slave.persistence.storageClass -}} - {{- end -}} - {{- end -}} -{{- end -}} +{{- include "common.warnings.rollingTag" .Values.image }} +{{- include "common.warnings.rollingTag" .Values.sentinel.image }} +{{- include "common.warnings.rollingTag" .Values.metrics.image }} {{- end -}} {{/* @@ -395,6 +236,7 @@ Compile all warnings into a single message, and call fail. {{- define "redis.validateValues" -}} {{- $messages := list -}} {{- $messages := append $messages (include "redis.validateValues.spreadConstraints" .) -}} +{{- $messages := append $messages (include "redis.validateValues.architecture" .) -}} {{- $messages := without $messages "" -}} {{- $message := join "\n" $messages -}} @@ -405,22 +247,24 @@ Compile all warnings into a single message, and call fail. {{/* Validate values of Redis(TM) - spreadConstrainsts K8s version */}} {{- define "redis.validateValues.spreadConstraints" -}} -{{- if and (semverCompare "<1.16-0" .Capabilities.KubeVersion.GitVersion) .Values.slave.spreadConstraints -}} +{{- if and (semverCompare "<1.16-0" .Capabilities.KubeVersion.GitVersion) .Values.replica.spreadConstraints -}} redis: spreadConstraints Pod Topology Spread Constraints are only available on K8s >= 1.16 Find more information at https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/ {{- end -}} {{- end -}} -{{/* -Renders a value that contains template. -Usage: -{{ include "redis.tplValue" (dict "value" .Values.path.to.the.Value "context" $) }} -*/}} -{{- define "redis.tplValue" -}} - {{- if typeIs "string" .value }} - {{- tpl .value .context }} - {{- else }} - {{- tpl (.value | toYaml) .context }} - {{- end }} +{{/* Validate values of Redis(TM) - must provide a valid architecture */}} +{{- define "redis.validateValues.architecture" -}} +{{- if and (ne .Values.architecture "standalone") (ne .Values.architecture "replication") -}} +redis: architecture + Invalid architecture selected. Valid values are "standalone" and + "replication". Please set a valid architecture (--set architecture="xxxx") +{{- end -}} +{{- if and .Values.sentinel.enabled (not (eq .Values.architecture "replication")) }} +redis: architecture + Using redis sentinel on standalone mode is not supported. + To deploy redis sentinel, please select the "replication" mode + (--set "architecture=replication,sentinel.enabled=true") +{{- end -}} {{- end -}} diff --git a/chart/deps/redis/templates/configmap-scripts.yaml b/chart/deps/redis/templates/configmap-scripts.yaml deleted file mode 100644 index 6d74027..0000000 --- a/chart/deps/redis/templates/configmap-scripts.yaml +++ /dev/null @@ -1,430 +0,0 @@ -apiVersion: v1 -kind: ConfigMap -metadata: - name: {{ template "redis.fullname" . }}-scripts - namespace: {{ .Release.Namespace | quote }} - labels: - app: {{ template "redis.name" . }} - chart: {{ template "redis.chart" . }} - heritage: {{ .Release.Service }} - release: {{ .Release.Name }} -data: -{{- if and .Values.cluster.enabled .Values.sentinel.enabled }} - start-node.sh: | - #!/bin/bash - - . /opt/bitnami/scripts/libos.sh - . /opt/bitnami/scripts/liblog.sh - . /opt/bitnami/scripts/libvalidations.sh - - not_exists_dns_entry() { - myip=$(hostname -i) - - if [[ -z "$(getent ahosts "$HEADLESS_SERVICE" | grep "^${myip}" )" ]]; then - warn "$HEADLESS_SERVICE does not contain the IP of this pod: ${myip}" - return 1 - fi - info "$HEADLESS_SERVICE has my IP: ${myip}" - return 0 - } - - HEADLESS_SERVICE="{{ template "redis.fullname" . }}-headless.{{ .Release.Namespace }}.svc.{{ .Values.clusterDomain }}" - REDIS_SERVICE="{{ template "redis.fullname" . }}.{{ .Release.Namespace }}.svc.{{ .Values.clusterDomain }}" - - # Waits for DNS to add this ip to the service DNS entry - retry_while not_exists_dns_entry - - export REDIS_REPLICATION_MODE="slave" - if [[ -z "$(getent ahosts "$HEADLESS_SERVICE" | grep -v "^$(hostname -i) ")" ]]; then - export REDIS_REPLICATION_MODE="master" - fi - - {{- if and .Values.securityContext.runAsUser (eq (.Values.securityContext.runAsUser | int) 0) }} - useradd redis - chown -R redis {{ .Values.slave.persistence.path }} - {{- end }} - - if [[ -n $REDIS_PASSWORD_FILE ]]; then - password_aux=`cat ${REDIS_PASSWORD_FILE}` - export REDIS_PASSWORD=$password_aux - fi - - if [[ -n $REDIS_MASTER_PASSWORD_FILE ]]; then - password_aux=`cat ${REDIS_MASTER_PASSWORD_FILE}` - export REDIS_MASTER_PASSWORD=$password_aux - fi - - if [[ "$REDIS_REPLICATION_MODE" == "master" ]]; then - echo "I am master" - if [[ ! -f /opt/bitnami/redis/etc/master.conf ]];then - cp /opt/bitnami/redis/mounted-etc/master.conf /opt/bitnami/redis/etc/master.conf - fi - else - if [[ ! -f /opt/bitnami/redis/etc/replica.conf ]];then - cp /opt/bitnami/redis/mounted-etc/replica.conf /opt/bitnami/redis/etc/replica.conf - fi - - if is_boolean_yes "$REDIS_TLS_ENABLED"; then - sentinel_info_command="redis-cli {{- if .Values.usePassword }} -a $REDIS_PASSWORD {{- end }} -h $REDIS_SERVICE -p {{ .Values.sentinel.port }} --tls --cert ${REDIS_TLS_CERT_FILE} --key ${REDIS_TLS_KEY_FILE} --cacert ${REDIS_TLS_CA_FILE} sentinel get-master-addr-by-name {{ .Values.sentinel.masterSet }}" - else - sentinel_info_command="redis-cli {{- if .Values.usePassword }} -a $REDIS_PASSWORD {{- end }} -h $REDIS_SERVICE -p {{ .Values.sentinel.port }} sentinel get-master-addr-by-name {{ .Values.sentinel.masterSet }}" - fi - REDIS_SENTINEL_INFO=($($sentinel_info_command)) - REDIS_MASTER_HOST=${REDIS_SENTINEL_INFO[0]} - REDIS_MASTER_PORT_NUMBER=${REDIS_SENTINEL_INFO[1]} - - - # Immediately attempt to connect to the reported master. If it doesn't exist the connection attempt will either hang - # or fail with "port unreachable" and give no data. The liveness check will then timeout waiting for the redis - # container to be ready and restart the it. By then the new master will likely have been elected - if is_boolean_yes "$REDIS_TLS_ENABLED"; then - sentinel_info_command="redis-cli {{- if .Values.usePassword }} -a $REDIS_PASSWORD {{- end }} -h $REDIS_MASTER_HOST -p {{ .Values.sentinel.port }} --tls --cert ${REDIS_TLS_CERT_FILE} --key ${REDIS_TLS_KEY_FILE} --cacert ${REDIS_TLS_CA_FILE} sentinel get-master-addr-by-name {{ .Values.sentinel.masterSet }}" - else - sentinel_info_command="redis-cli {{- if .Values.usePassword }} -a $REDIS_PASSWORD {{- end }} -h $REDIS_MASTER_HOST -p {{ .Values.sentinel.port }} sentinel get-master-addr-by-name {{ .Values.sentinel.masterSet }}" - fi - - if [[ ! ($($sentinel_info_command)) ]]; then - # master doesn't actually exist, this probably means the remaining pods haven't elected a new one yet - # and are reporting the old one still. Once this happens the container will get stuck and never see the new - # master. We stop here to allow the container to not pass the liveness check and be restarted. - exit 1 - fi - fi - - if [[ ! -f /opt/bitnami/redis/etc/redis.conf ]];then - cp /opt/bitnami/redis/mounted-etc/redis.conf /opt/bitnami/redis/etc/redis.conf - fi - {{- if .Values.tls.enabled }} - ARGS=("--port" "0") - ARGS+=("--tls-port" "${REDIS_TLS_PORT}") - ARGS+=("--tls-cert-file" "${REDIS_TLS_CERT_FILE}") - ARGS+=("--tls-key-file" "${REDIS_TLS_KEY_FILE}") - ARGS+=("--tls-ca-cert-file" "${REDIS_TLS_CA_FILE}") - ARGS+=("--tls-auth-clients" "${REDIS_TLS_AUTH_CLIENTS}") - ARGS+=("--tls-replication" "yes") - {{- if .Values.tls.dhParamsFilename }} - ARGS+=("--tls-dh-params-file" "${REDIS_TLS_DH_PARAMS_FILE}") - {{- end }} - {{- else }} - ARGS=("--port" "${REDIS_PORT}") - {{- end }} - - if [[ "$REDIS_REPLICATION_MODE" == "slave" ]]; then - ARGS+=("--slaveof" "${REDIS_MASTER_HOST}" "${REDIS_MASTER_PORT_NUMBER}") - fi - - {{- if .Values.usePassword }} - ARGS+=("--requirepass" "${REDIS_PASSWORD}") - ARGS+=("--masterauth" "${REDIS_MASTER_PASSWORD}") - {{- else }} - ARGS+=("--protected-mode" "no") - {{- end }} - - if [[ "$REDIS_REPLICATION_MODE" == "master" ]]; then - ARGS+=("--include" "/opt/bitnami/redis/etc/master.conf") - else - ARGS+=("--include" "/opt/bitnami/redis/etc/replica.conf") - fi - - ARGS+=("--include" "/opt/bitnami/redis/etc/redis.conf") - {{- if .Values.slave.extraFlags }} - {{- range .Values.slave.extraFlags }} - ARGS+=({{ . | quote }}) - {{- end }} - {{- end }} - - {{- if .Values.slave.preExecCmds }} - {{ .Values.slave.preExecCmds | nindent 4}} - {{- end }} - - {{- if .Values.slave.command }} - exec {{ .Values.slave.command }} "${ARGS[@]}" - {{- else }} - exec redis-server "${ARGS[@]}" - {{- end }} - - start-sentinel.sh: | - #!/bin/bash - - . /opt/bitnami/scripts/libos.sh - . /opt/bitnami/scripts/libvalidations.sh - . /opt/bitnami/scripts/libfile.sh - - sentinel_conf_set() { - local -r key="${1:?missing key}" - local value="${2:-}" - - # Sanitize inputs - value="${value//\\/\\\\}" - value="${value//&/\\&}" - value="${value//\?/\\?}" - [[ "$value" = "" ]] && value="\"$value\"" - - replace_in_file "/opt/bitnami/redis-sentinel/etc/sentinel.conf" "^#*\s*${key} .*" "${key} ${value}" false - } - sentinel_conf_add() { - echo $'\n'"$@" >> "/opt/bitnami/redis-sentinel/etc/sentinel.conf" - } - host_id() { - echo "$1" | openssl sha1 | awk '{print $2}' - } - not_exists_dns_entry() { - myip=$(hostname -i) - - if [[ -z "$(getent ahosts "$HEADLESS_SERVICE" | grep "^${myip}" )" ]]; then - warn "$HEADLESS_SERVICE does not contain the IP of this pod: ${myip}" - return 1 - fi - info "$HEADLESS_SERVICE has my IP: ${myip}" - return 0 - } - - HEADLESS_SERVICE="{{ template "redis.fullname" . }}-headless.{{ .Release.Namespace }}.svc.{{ .Values.clusterDomain }}" - REDIS_SERVICE="{{ template "redis.fullname" . }}.{{ .Release.Namespace }}.svc.{{ .Values.clusterDomain }}" - - if [[ -n $REDIS_PASSWORD_FILE ]]; then - password_aux=`cat ${REDIS_PASSWORD_FILE}` - export REDIS_PASSWORD=$password_aux - fi - - if [[ ! -f /opt/bitnami/redis-sentinel/etc/sentinel.conf ]]; then - cp /opt/bitnami/redis-sentinel/mounted-etc/sentinel.conf /opt/bitnami/redis-sentinel/etc/sentinel.conf - {{- if .Values.usePassword }} - printf "\nsentinel auth-pass %s %s" "{{ .Values.sentinel.masterSet }}" "$REDIS_PASSWORD" >> /opt/bitnami/redis-sentinel/etc/sentinel.conf - {{- if .Values.sentinel.usePassword }} - printf "\nrequirepass %s" "$REDIS_PASSWORD" >> /opt/bitnami/redis-sentinel/etc/sentinel.conf - {{- end }} - {{- end }} - {{- if .Values.sentinel.staticID }} - printf "\nsentinel myid %s" "$(host_id "$HOSTNAME")" >> /opt/bitnami/redis-sentinel/etc/sentinel.conf - {{- end }} - fi - - export REDIS_REPLICATION_MODE="slave" - - # Waits for DNS to add this ip to the service DNS entry - retry_while not_exists_dns_entry - - if [[ -z "$(getent ahosts "$HEADLESS_SERVICE" | grep -v "^$(hostname -i)")" ]]; then - export REDIS_REPLICATION_MODE="master" - fi - - # Clean sentineles from the current sentinel nodes - for node in $( getent ahosts "$HEADLESS_SERVICE" | grep -v "^$(hostname -i)" | cut -f 1 -d ' ' | uniq ); do - info "Cleaning sentinels in sentinel node: $node" - if is_boolean_yes "$REDIS_SENTINEL_TLS_ENABLED"; then - redis-cli {{- if .Values.usePassword }} -a $REDIS_PASSWORD {{- end }} -h $node -p {{ .Values.sentinel.port }} --tls --cert ${REDIS_SENTINEL_TLS_CERT_FILE} --key ${REDIS_SENTINEL_TLS_KEY_FILE} --cacert ${REDIS_SENTINEL_TLS_CA_FILE} sentinel reset "*" - else - redis-cli {{- if .Values.usePassword }} -a $REDIS_PASSWORD {{- end }} -h $node -p {{ .Values.sentinel.port }} sentinel reset "*" - fi - sleep {{ .Values.sentinel.cleanDelaySeconds }} - done - info "Sentinels clean up done" - - if [[ "$REDIS_REPLICATION_MODE" == "master" ]]; then - REDIS_MASTER_HOST="$(hostname -i)" - REDIS_MASTER_PORT_NUMBER="{{ .Values.redisPort }}" - else - if is_boolean_yes "$REDIS_SENTINEL_TLS_ENABLED"; then - sentinel_info_command="redis-cli {{- if .Values.usePassword }} -a $REDIS_PASSWORD {{- end }} -h $REDIS_SERVICE -p {{ .Values.sentinel.port }} --tls --cert ${REDIS_SENTINEL_TLS_CERT_FILE} --key ${REDIS_SENTINEL_TLS_KEY_FILE} --cacert ${REDIS_SENTINEL_TLS_CA_FILE} sentinel get-master-addr-by-name {{ .Values.sentinel.masterSet }}" - else - sentinel_info_command="redis-cli {{- if .Values.usePassword }} -a $REDIS_PASSWORD {{- end }} -h $REDIS_SERVICE -p {{ .Values.sentinel.port }} sentinel get-master-addr-by-name {{ .Values.sentinel.masterSet }}" - fi - REDIS_SENTINEL_INFO=($($sentinel_info_command)) - REDIS_MASTER_HOST=${REDIS_SENTINEL_INFO[0]} - REDIS_MASTER_PORT_NUMBER=${REDIS_SENTINEL_INFO[1]} - - # Immediately attempt to connect to the reported master. If it doesn't exist the connection attempt will either hang - # or fail with "port unreachable" and give no data. The liveness check will then timeout waiting for the sentinel - # container to be ready and restart the it. By then the new master will likely have been elected - if is_boolean_yes "$REDIS_SENTINEL_TLS_ENABLED"; then - sentinel_info_command="redis-cli {{- if .Values.usePassword }} -a $REDIS_PASSWORD {{- end }} -h $REDIS_MASTER_HOST -p {{ .Values.sentinel.port }} --tls --cert ${REDIS_SENTINEL_TLS_CERT_FILE} --key ${REDIS_SENTINEL_TLS_KEY_FILE} --cacert ${REDIS_SENTINEL_TLS_CA_FILE} sentinel get-master-addr-by-name {{ .Values.sentinel.masterSet }}" - else - sentinel_info_command="redis-cli {{- if .Values.usePassword }} -a $REDIS_PASSWORD {{- end }} -h $REDIS_MASTER_HOST -p {{ .Values.sentinel.port }} sentinel get-master-addr-by-name {{ .Values.sentinel.masterSet }}" - fi - - if [[ ! ($($sentinel_info_command)) ]]; then - # master doesn't actually exist, this probably means the remaining pods haven't elected a new one yet - # and are reporting the old one still. Once this happens the container will get stuck and never see the new - # master. We stop here to allow the container to not pass the liveness check and be restarted. - exit 1 - fi - fi - sentinel_conf_set "sentinel monitor" "{{ .Values.sentinel.masterSet }} "$REDIS_MASTER_HOST" "$REDIS_MASTER_PORT_NUMBER" {{ .Values.sentinel.quorum }}" - - add_replica() { - if [[ "$1" != "$REDIS_MASTER_HOST" ]]; then - sentinel_conf_add "sentinel known-replica {{ .Values.sentinel.masterSet }} $1 {{ .Values.redisPort }}" - fi - } - - {{- if .Values.sentinel.staticID }} - # remove generated known sentinels and replicas - tmp="$(sed -e '/^sentinel known-/d' -e '/^$/d' /opt/bitnami/redis-sentinel/etc/sentinel.conf)" - echo "$tmp" > /opt/bitnami/redis-sentinel/etc/sentinel.conf - - for node in $(seq 0 {{ .Values.cluster.slaveCount }}); do - NAME="{{ template "redis.fullname" . }}-node-$node" - IP="$(getent hosts "$NAME.$HEADLESS_SERVICE" | awk ' {print $1 }')" - if [[ "$NAME" != "$HOSTNAME" && -n "$IP" ]]; then - sentinel_conf_add "sentinel known-sentinel {{ .Values.sentinel.masterSet }} $IP {{ .Values.sentinel.port }} $(host_id "$NAME")" - add_replica "$IP" - fi - done - add_replica "$(hostname -i)" - {{- end }} - - {{- if .Values.tls.enabled }} - ARGS=("--port" "0") - ARGS+=("--tls-port" "${REDIS_SENTINEL_TLS_PORT_NUMBER}") - ARGS+=("--tls-cert-file" "${REDIS_SENTINEL_TLS_CERT_FILE}") - ARGS+=("--tls-key-file" "${REDIS_SENTINEL_TLS_KEY_FILE}") - ARGS+=("--tls-ca-cert-file" "${REDIS_SENTINEL_TLS_CA_FILE}") - ARGS+=("--tls-replication" "yes") - ARGS+=("--tls-auth-clients" "${REDIS_SENTINEL_TLS_AUTH_CLIENTS}") - {{- if .Values.tls.dhParamsFilename }} - ARGS+=("--tls-dh-params-file" "${REDIS_SENTINEL_TLS_DH_PARAMS_FILE}") - {{- end }} - {{- end }} - {{- if .Values.sentinel.preExecCmds }} - {{ .Values.sentinel.preExecCmds | nindent 4 }} - {{- end }} - exec redis-server /opt/bitnami/redis-sentinel/etc/sentinel.conf --sentinel {{- if .Values.tls.enabled }} "${ARGS[@]}" {{- end }} - prestop-sentinel.sh: | - #!/bin/bash - - . /opt/bitnami/scripts/libvalidations.sh - - REDIS_SERVICE="{{ include "redis.fullname" . }}.{{ .Release.Namespace }}.svc.{{ .Values.clusterDomain }}" - - if [[ -n "$REDIS_PASSWORD_FILE" ]]; then - password_aux=$(cat "$REDIS_PASSWORD_FILE") - export REDIS_PASSWORD="$password_aux" - fi - - if is_boolean_yes "$REDIS_SENTINEL_TLS_ENABLED"; then - sentinel_info_command="redis-cli {{- if .Values.usePassword }} -a ${REDIS_PASSWORD} {{- end }} -h ${REDIS_SERVICE} -p {{ .Values.sentinel.port }} --tls --cert ${REDIS_SENTINEL_TLS_CERT_FILE} --key ${REDIS_SENTINEL_TLS_KEY_FILE} --cacert ${REDIS_SENTINEL_TLS_CA_FILE} sentinel get-master-addr-by-name {{ .Values.sentinel.masterSet }}" - else - sentinel_info_command="redis-cli {{- if .Values.usePassword }} -a ${REDIS_PASSWORD} {{- end }} -h ${REDIS_SERVICE} -p {{ .Values.sentinel.port }} sentinel get-master-addr-by-name {{ .Values.sentinel.masterSet }}" - fi - REDIS_SENTINEL_INFO=($($sentinel_info_command)) - REDIS_MASTER_HOST="${REDIS_SENTINEL_INFO[0]}" - - if [[ "$REDIS_MASTER_HOST" == "$(hostname -i)" ]]; then - if is_boolean_yes "$REDIS_SENTINEL_TLS_ENABLED"; then - redis-cli {{- if .Values.usePassword }} -a "$REDIS_PASSWORD" {{- end }} -h "$REDIS_SERVICE" -p {{ .Values.sentinel.port }} --tls --cert "$REDIS_SENTINEL_TLS_CERT_FILE" --key "$REDIS_SENTINEL_TLS_KEY_FILE" --cacert "$REDIS_SENTINEL_TLS_CA_FILE" sentinel failover mymaster - else - redis-cli {{- if .Values.usePassword }} -a "$REDIS_PASSWORD" {{- end }} -h "$REDIS_SERVICE" -p {{ .Values.sentinel.port }} sentinel failover mymaster - fi - fi -{{- else }} - start-master.sh: | - #!/bin/bash - {{- if and .Values.securityContext.runAsUser (eq (.Values.securityContext.runAsUser | int) 0) }} - useradd redis - chown -R redis {{ .Values.master.persistence.path }} - {{- end }} - if [[ -n $REDIS_PASSWORD_FILE ]]; then - password_aux=`cat ${REDIS_PASSWORD_FILE}` - export REDIS_PASSWORD=$password_aux - fi - if [[ ! -f /opt/bitnami/redis/etc/master.conf ]];then - cp /opt/bitnami/redis/mounted-etc/master.conf /opt/bitnami/redis/etc/master.conf - fi - if [[ ! -f /opt/bitnami/redis/etc/redis.conf ]];then - cp /opt/bitnami/redis/mounted-etc/redis.conf /opt/bitnami/redis/etc/redis.conf - fi - {{- if .Values.tls.enabled }} - ARGS=("--port" "0") - ARGS+=("--tls-port" "${REDIS_TLS_PORT}") - ARGS+=("--tls-cert-file" "${REDIS_TLS_CERT_FILE}") - ARGS+=("--tls-key-file" "${REDIS_TLS_KEY_FILE}") - ARGS+=("--tls-ca-cert-file" "${REDIS_TLS_CA_FILE}") - ARGS+=("--tls-auth-clients" "${REDIS_TLS_AUTH_CLIENTS}") - {{- if .Values.tls.dhParamsFilename }} - ARGS+=("--tls-dh-params-file" "${REDIS_TLS_DH_PARAMS_FILE}") - {{- end }} - {{- else }} - ARGS=("--port" "${REDIS_PORT}") - {{- end }} - {{- if .Values.usePassword }} - ARGS+=("--requirepass" "${REDIS_PASSWORD}") - ARGS+=("--masterauth" "${REDIS_PASSWORD}") - {{- else }} - ARGS+=("--protected-mode" "no") - {{- end }} - ARGS+=("--include" "/opt/bitnami/redis/etc/redis.conf") - ARGS+=("--include" "/opt/bitnami/redis/etc/master.conf") - {{- if .Values.master.extraFlags }} - {{- range .Values.master.extraFlags }} - ARGS+=({{ . | quote }}) - {{- end }} - {{- end }} - {{- if .Values.master.preExecCmds }} - {{ .Values.master.preExecCmds | nindent 4}} - {{- end }} - {{- if .Values.master.command }} - exec {{ .Values.master.command }} "${ARGS[@]}" - {{- else }} - exec redis-server "${ARGS[@]}" - {{- end }} - {{- if .Values.cluster.enabled }} - start-slave.sh: | - #!/bin/bash - {{- if and .Values.securityContext.runAsUser (eq (.Values.securityContext.runAsUser | int) 0) }} - useradd redis - chown -R redis {{ .Values.slave.persistence.path }} - {{- end }} - if [[ -n $REDIS_PASSWORD_FILE ]]; then - password_aux=`cat ${REDIS_PASSWORD_FILE}` - export REDIS_PASSWORD=$password_aux - fi - if [[ -n $REDIS_MASTER_PASSWORD_FILE ]]; then - password_aux=`cat ${REDIS_MASTER_PASSWORD_FILE}` - export REDIS_MASTER_PASSWORD=$password_aux - fi - if [[ ! -f /opt/bitnami/redis/etc/replica.conf ]];then - cp /opt/bitnami/redis/mounted-etc/replica.conf /opt/bitnami/redis/etc/replica.conf - fi - if [[ ! -f /opt/bitnami/redis/etc/redis.conf ]];then - cp /opt/bitnami/redis/mounted-etc/redis.conf /opt/bitnami/redis/etc/redis.conf - fi - {{- if .Values.tls.enabled }} - ARGS=("--port" "0") - ARGS+=("--tls-port" "${REDIS_TLS_PORT}") - ARGS+=("--tls-cert-file" "${REDIS_TLS_CERT_FILE}") - ARGS+=("--tls-key-file" "${REDIS_TLS_KEY_FILE}") - ARGS+=("--tls-ca-cert-file" "${REDIS_TLS_CA_FILE}") - ARGS+=("--tls-auth-clients" "${REDIS_TLS_AUTH_CLIENTS}") - ARGS+=("--tls-replication" "yes") - {{- if .Values.tls.dhParamsFilename }} - ARGS+=("--tls-dh-params-file" "${REDIS_TLS_DH_PARAMS_FILE}") - {{- end }} - {{- else }} - ARGS=("--port" "${REDIS_PORT}") - {{- end }} - ARGS+=("--slaveof" "${REDIS_MASTER_HOST}" "${REDIS_MASTER_PORT_NUMBER}") - {{- if .Values.usePassword }} - ARGS+=("--requirepass" "${REDIS_PASSWORD}") - ARGS+=("--masterauth" "${REDIS_MASTER_PASSWORD}") - {{- else }} - ARGS+=("--protected-mode" "no") - {{- end }} - ARGS+=("--include" "/opt/bitnami/redis/etc/redis.conf") - ARGS+=("--include" "/opt/bitnami/redis/etc/replica.conf") - {{- if .Values.slave.extraFlags }} - {{- range .Values.slave.extraFlags }} - ARGS+=({{ . | quote }}) - {{- end }} - {{- end }} - {{- if .Values.slave.preExecCmds }} - {{ .Values.slave.preExecCmds | nindent 4}} - {{- end }} - {{- if .Values.slave.command }} - exec {{ .Values.slave.command }} "${ARGS[@]}" - {{- else }} - exec redis-server "${ARGS[@]}" - {{- end }} - {{- end }} - -{{- end -}} diff --git a/chart/deps/redis/templates/configmap.yaml b/chart/deps/redis/templates/configmap.yaml index 77bdc81..220c11f 100644 --- a/chart/deps/redis/templates/configmap.yaml +++ b/chart/deps/redis/templates/configmap.yaml @@ -1,53 +1,61 @@ +{{- if (include "redis.createConfigmap" .) }} apiVersion: v1 kind: ConfigMap metadata: - name: {{ template "redis.fullname" . }} + name: {{ printf "%s-configuration" (include "common.names.fullname" .) }} namespace: {{ .Release.Namespace | quote }} - labels: - app: {{ template "redis.name" . }} - chart: {{ template "redis.chart" . }} - heritage: {{ .Release.Service }} - release: {{ .Release.Name }} + labels: {{- include "common.labels.standard" . | nindent 4 }} + {{- if .Values.commonLabels }} + {{- include "common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }} + {{- end }} + {{- if .Values.commonAnnotations }} + annotations: {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }} + {{- end }} data: redis.conf: |- -{{- if .Values.configmap }} - # User-supplied configuration: -{{- tpl .Values.configmap . | nindent 4 }} -{{- end }} + # User-supplied common configuration: + {{- if .Values.commonConfiguration }} + {{- include "common.tplvalues.render" ( dict "value" .Values.commonConfiguration "context" $ ) | nindent 4 }} + {{- end }} + # End of common configuration master.conf: |- dir {{ .Values.master.persistence.path }} -{{- if .Values.master.configmap }} # User-supplied master configuration: -{{- tpl .Values.master.configmap . | nindent 4 }} -{{- end }} -{{- if .Values.master.disableCommands }} -{{- range .Values.master.disableCommands }} + {{- if .Values.master.configuration }} + {{- include "common.tplvalues.render" ( dict "value" .Values.master.configuration "context" $ ) | nindent 4 }} + {{- end }} + {{- if .Values.master.disableCommands }} + {{- range .Values.master.disableCommands }} rename-command {{ . }} "" -{{- end }} -{{- end }} + {{- end }} + {{- end }} + # End of master configuration replica.conf: |- - dir {{ .Values.slave.persistence.path }} + dir {{ .Values.replica.persistence.path }} slave-read-only yes -{{- if .Values.slave.configmap }} - # User-supplied slave configuration: -{{- tpl .Values.slave.configmap . | nindent 4 }} -{{- end }} -{{- if .Values.slave.disableCommands }} -{{- range .Values.slave.disableCommands }} + # User-supplied replica configuration: + {{- if .Values.replica.configuration }} + {{- include "common.tplvalues.render" ( dict "value" .Values.replica.configuration "context" $ ) | nindent 4 }} + {{- end }} + {{- if .Values.replica.disableCommands }} + {{- range .Values.replica.disableCommands }} rename-command {{ . }} "" -{{- end }} -{{- end }} -{{- if .Values.sentinel.enabled }} + {{- end }} + {{- end }} + # End of replica configuration + {{- if .Values.sentinel.enabled }} sentinel.conf: |- dir "/tmp" bind 0.0.0.0 - port {{ .Values.sentinel.port }} - sentinel monitor {{ .Values.sentinel.masterSet }} {{ template "redis.fullname" . }}-node-0.{{ template "redis.fullname" . }}-headless.{{ .Release.Namespace }}.svc.{{ .Values.clusterDomain }} {{ .Values.redisPort }} {{ .Values.sentinel.quorum }} + port {{ .Values.sentinel.containerPort }} + sentinel monitor {{ .Values.sentinel.masterSet }} {{ template "common.names.fullname" . }}-node-0.{{ template "common.names.fullname" . }}-headless.{{ .Release.Namespace }}.svc.{{ .Values.clusterDomain }} {{ .Values.sentinel.service.port }} {{ .Values.sentinel.quorum }} sentinel down-after-milliseconds {{ .Values.sentinel.masterSet }} {{ .Values.sentinel.downAfterMilliseconds }} sentinel failover-timeout {{ .Values.sentinel.masterSet }} {{ .Values.sentinel.failoverTimeout }} sentinel parallel-syncs {{ .Values.sentinel.masterSet }} {{ .Values.sentinel.parallelSyncs }} -{{- if .Values.sentinel.configmap }} # User-supplied sentinel configuration: -{{- tpl .Values.sentinel.configmap . | nindent 4 }} -{{- end }} + {{- if .Values.sentinel.configuration }} + {{- include "common.tplvalues.render" ( dict "value" .Values.sentinel.configuration "context" $ ) | nindent 4 }} + {{- end }} + # End of sentinel configuration + {{- end }} {{- end }} diff --git a/chart/deps/redis/templates/extra-list.yaml b/chart/deps/redis/templates/extra-list.yaml new file mode 100644 index 0000000..9ac65f9 --- /dev/null +++ b/chart/deps/redis/templates/extra-list.yaml @@ -0,0 +1,4 @@ +{{- range .Values.extraDeploy }} +--- +{{ include "common.tplvalues.render" (dict "value" . "context" $) }} +{{- end }} diff --git a/chart/deps/redis/templates/headless-svc.yaml b/chart/deps/redis/templates/headless-svc.yaml index d758c0d..f579c22 100644 --- a/chart/deps/redis/templates/headless-svc.yaml +++ b/chart/deps/redis/templates/headless-svc.yaml @@ -1,13 +1,15 @@ apiVersion: v1 kind: Service metadata: - name: {{ template "redis.fullname" . }}-headless + name: {{ printf "%s-headless" (include "common.names.fullname" .) }} namespace: {{ .Release.Namespace | quote }} - labels: - app: {{ template "redis.name" . }} - chart: {{ template "redis.chart" . }} - release: {{ .Release.Name }} - heritage: {{ .Release.Service }} + labels: {{- include "common.labels.standard" . | nindent 4 }} + {{- if .Values.commonLabels }} + {{- include "common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }} + {{- end }} + {{- if .Values.commonAnnotations }} + annotations: {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }} + {{- end }} spec: type: ClusterIP clusterIP: None @@ -16,13 +18,11 @@ spec: {{- end }} ports: - name: tcp-redis - port: {{ .Values.redisPort }} + port: {{ if .Values.sentinel.enabled }}{{ .Values.sentinel.service.port }}{{ else }}{{ .Values.master.service.port }}{{ end }} targetPort: redis - {{- if .Values.sentinel.enabled }} + {{- if .Values.sentinel.enabled }} - name: tcp-sentinel - port: {{ .Values.sentinel.port }} - targetPort: redis-sentinel - {{- end }} - selector: - app: {{ template "redis.name" . }} - release: {{ .Release.Name }} + port: {{ .Values.sentinel.service.sentinelPort }} + targetPort: sentinel + {{- end }} + selector: {{- include "common.labels.matchLabels" . | nindent 4 }} diff --git a/chart/deps/redis/templates/health-configmap.yaml b/chart/deps/redis/templates/health-configmap.yaml index 1bb8e74..c284ca4 100644 --- a/chart/deps/redis/templates/health-configmap.yaml +++ b/chart/deps/redis/templates/health-configmap.yaml @@ -1,20 +1,20 @@ apiVersion: v1 kind: ConfigMap metadata: - name: {{ template "redis.fullname" . }}-health + name: {{ printf "%s-health" (include "common.names.fullname" .) }} namespace: {{ .Release.Namespace | quote }} - labels: - app: {{ template "redis.name" . }} - chart: {{ template "redis.chart" . }} - heritage: {{ .Release.Service }} - release: {{ .Release.Name }} + labels: {{- include "common.labels.standard" . | nindent 4 }} + {{- if .Values.commonLabels }} + {{- include "common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }} + {{- end }} + {{- if .Values.commonAnnotations }} + annotations: {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }} + {{- end }} data: ping_readiness_local.sh: |- #!/bin/bash -{{- if .Values.usePasswordFile }} - password_aux=`cat ${REDIS_PASSWORD_FILE}` - export REDIS_PASSWORD=$password_aux -{{- end }} + + [[ -f $REDIS_PASSWORD_FILE ]] && export REDIS_PASSWORD="$(< "${REDIS_PASSWORD_FILE}")" export REDISCLI_AUTH="$REDIS_PASSWORD" response=$( timeout -s 3 $1 \ @@ -39,10 +39,8 @@ data: fi ping_liveness_local.sh: |- #!/bin/bash -{{- if .Values.usePasswordFile }} - password_aux=`cat ${REDIS_PASSWORD_FILE}` - export REDIS_PASSWORD=$password_aux -{{- end }} + + [[ -f $REDIS_PASSWORD_FILE ]] && export REDIS_PASSWORD="$(< "${REDIS_PASSWORD_FILE}")" export REDISCLI_AUTH="$REDIS_PASSWORD" response=$( timeout -s 3 $1 \ @@ -68,10 +66,8 @@ data: {{- if .Values.sentinel.enabled }} ping_sentinel.sh: |- #!/bin/bash -{{- if .Values.usePasswordFile }} - password_aux=`cat ${REDIS_PASSWORD_FILE}` - export REDIS_PASSWORD=$password_aux -{{- end }} + + [[ -f $REDIS_PASSWORD_FILE ]] && export REDIS_PASSWORD="$(< "${REDIS_PASSWORD_FILE}")" export REDISCLI_AUTH="$REDIS_PASSWORD" response=$( timeout -s 3 $1 \ @@ -112,10 +108,8 @@ data: {{- end }} ping_readiness_master.sh: |- #!/bin/bash -{{- if .Values.usePasswordFile }} - password_aux=`cat ${REDIS_MASTER_PASSWORD_FILE}` - export REDIS_MASTER_PASSWORD=$password_aux -{{- end }} + + [[ -f $REDIS_MASTER_PASSWORD_FILE ]] && export REDIS_MASTER_PASSWORD="$(< "${REDIS_MASTER_PASSWORD_FILE}")" export REDISCLI_AUTH="$REDIS_MASTER_PASSWORD" response=$( timeout -s 3 $1 \ @@ -138,10 +132,8 @@ data: fi ping_liveness_master.sh: |- #!/bin/bash -{{- if .Values.usePasswordFile }} - password_aux=`cat ${REDIS_MASTER_PASSWORD_FILE}` - export REDIS_MASTER_PASSWORD=$password_aux -{{- end }} + + [[ -f $REDIS_MASTER_PASSWORD_FILE ]] && export REDIS_MASTER_PASSWORD="$(< "${REDIS_MASTER_PASSWORD_FILE}")" export REDISCLI_AUTH="$REDIS_MASTER_PASSWORD" response=$( timeout -s 3 $1 \ diff --git a/chart/deps/redis/templates/master/psp.yaml b/chart/deps/redis/templates/master/psp.yaml new file mode 100644 index 0000000..161ee09 --- /dev/null +++ b/chart/deps/redis/templates/master/psp.yaml @@ -0,0 +1,45 @@ +{{- if .Values.podSecurityPolicy.create }} +apiVersion: {{ template "podSecurityPolicy.apiVersion" . }} +kind: PodSecurityPolicy +metadata: + name: {{ printf "%s-master" (include "common.names.fullname" .) }} + namespace: {{ .Release.Namespace | quote }} + labels: {{- include "common.labels.standard" . | nindent 4 }} + {{- if .Values.commonLabels }} + {{- include "common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }} + {{- end }} + {{- if .Values.commonAnnotations }} + annotations: {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }} + {{- end }} +spec: + allowPrivilegeEscalation: false + fsGroup: + rule: 'MustRunAs' + ranges: + - min: {{ .Values.master.podSecurityContext.fsGroup }} + max: {{ .Values.master.podSecurityContext.fsGroup }} + hostIPC: false + hostNetwork: false + hostPID: false + privileged: false + readOnlyRootFilesystem: false + requiredDropCapabilities: + - ALL + runAsUser: + rule: 'MustRunAs' + ranges: + - min: {{ .Values.master.containerSecurityContext.runAsUser }} + max: {{ .Values.master.containerSecurityContext.runAsUser }} + seLinux: + rule: 'RunAsAny' + supplementalGroups: + rule: 'MustRunAs' + ranges: + - min: {{ .Values.master.containerSecurityContext.runAsUser }} + max: {{ .Values.master.containerSecurityContext.runAsUser }} + volumes: + - 'configMap' + - 'secret' + - 'emptyDir' + - 'persistentVolumeClaim' +{{- end }} diff --git a/chart/deps/redis/templates/master/service.yaml b/chart/deps/redis/templates/master/service.yaml new file mode 100644 index 0000000..c253d1d --- /dev/null +++ b/chart/deps/redis/templates/master/service.yaml @@ -0,0 +1,46 @@ +{{- if not .Values.sentinel.enabled }} +apiVersion: v1 +kind: Service +metadata: + name: {{ printf "%s-master" (include "common.names.fullname" .) }} + namespace: {{ .Release.Namespace | quote }} + labels: {{- include "common.labels.standard" . | nindent 4 }} + app.kubernetes.io/component: master + {{- if .Values.commonLabels }} + {{- include "common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }} + {{- end }} + {{- if or .Values.master.service.annotations .Values.commonAnnotations }} + annotations: + {{- if .Values.master.service.annotations }} + {{- include "common.tplvalues.render" ( dict "value" .Values.master.service.annotations "context" $ ) | nindent 4 }} + {{- end }} + {{- if .Values.commonAnnotations }} + {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }} + {{- end }} + {{- end }} +spec: + type: {{ .Values.master.service.type }} + {{ if eq .Values.master.service.type "LoadBalancer" }} + externalTrafficPolicy: {{ .Values.master.service.externalTrafficPolicy }} + {{- end }} + {{- if and (eq .Values.master.service.type "LoadBalancer") .Values.master.service.loadBalancerIP }} + loadBalancerIP: {{ .Values.master.service.loadBalancerIP }} + {{- end }} + {{- if and (eq .Values.master.service.type "LoadBalancer") .Values.master.service.loadBalancerSourceRanges }} + loadBalancerSourceRanges: {{- toYaml .Values.master.service.loadBalancerSourceRanges | nindent 4 }} + {{- end }} + {{- if and (eq .Values.master.service.type "ClusterIP") .Values.master.service.clusterIP }} + clusterIP: {{ .Values.master.service.clusterIP }} + {{- end }} + ports: + - name: tcp-redis + port: {{ .Values.master.service.port }} + targetPort: redis + {{- if and (or (eq .Values.master.service.type "NodePort") (eq .Values.master.service.type "LoadBalancer")) .Values.master.service.nodePort }} + nodePort: {{ .Values.master.service.nodePort }} + {{- else if eq .Values.master.service.type "ClusterIP" }} + nodePort: null + {{- end }} + selector: {{- include "common.labels.matchLabels" . | nindent 4 }} + app.kubernetes.io/component: master +{{- end }} diff --git a/chart/deps/redis/templates/master/statefulset.yaml b/chart/deps/redis/templates/master/statefulset.yaml new file mode 100644 index 0000000..8ea35bd --- /dev/null +++ b/chart/deps/redis/templates/master/statefulset.yaml @@ -0,0 +1,402 @@ +{{- if or (not (eq .Values.architecture "replication")) (not .Values.sentinel.enabled) }} +apiVersion: {{ include "common.capabilities.statefulset.apiVersion" . }} +kind: StatefulSet +metadata: + name: {{ printf "%s-master" (include "common.names.fullname" .) }} + namespace: {{ .Release.Namespace | quote }} + labels: {{- include "common.labels.standard" . | nindent 4 }} + app.kubernetes.io/component: master + {{- if .Values.commonLabels }} + {{- include "common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }} + {{- end }} + {{- if .Values.commonAnnotations }} + annotations: {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }} + {{- end }} +spec: + selector: + matchLabels: {{- include "common.labels.matchLabels" . | nindent 6 }} + app.kubernetes.io/component: master + serviceName: {{ printf "%s-headless" (include "common.names.fullname" .) }} + {{- if .Values.master.updateStrategy }} + updateStrategy: {{- toYaml .Values.master.updateStrategy | nindent 4 }} + {{- end }} + template: + metadata: + labels: {{- include "common.labels.standard" . | nindent 8 }} + app.kubernetes.io/component: master + {{- if .Values.master.podLabels }} + {{- include "common.tplvalues.render" ( dict "value" .Values.master.podLabels "context" $ ) | nindent 8 }} + {{- end }} + {{- if and .Values.metrics.enabled .Values.metrics.podLabels }} + {{- include "common.tplvalues.render" ( dict "value" .Values.metrics.podLabels "context" $ ) | nindent 8 }} + {{- end }} + annotations: + {{- if (include "redis.createConfigmap" .) }} + checksum/configmap: {{ include (print $.Template.BasePath "/configmap.yaml") . | sha256sum }} + {{- end }} + checksum/health: {{ include (print $.Template.BasePath "/health-configmap.yaml") . | sha256sum }} + checksum/scripts: {{ include (print $.Template.BasePath "/scripts-configmap.yaml") . | sha256sum }} + checksum/secret: {{ include (print $.Template.BasePath "/secret.yaml") . | sha256sum }} + {{- if .Values.master.podAnnotations }} + {{- include "common.tplvalues.render" ( dict "value" .Values.master.podAnnotations "context" $ ) | nindent 8 }} + {{- end }} + {{- if and .Values.metrics.enabled .Values.metrics.podAnnotations }} + {{- include "common.tplvalues.render" ( dict "value" .Values.metrics.podAnnotations "context" $ ) | nindent 8 }} + {{- end }} + spec: + {{- include "redis.imagePullSecrets" . | nindent 6 }} + {{- if .Values.master.hostAliases }} + hostAliases: {{- include "common.tplvalues.render" (dict "value" .Values.master.hostAliases "context" $) | nindent 8 }} + {{- end }} + {{- if .Values.master.podSecurityContext.enabled }} + securityContext: {{- omit .Values.master.podSecurityContext "enabled" | toYaml | nindent 8 }} + {{- end }} + serviceAccountName: {{ template "redis.serviceAccountName" . }} + {{- if .Values.master.priorityClassName }} + priorityClassName: {{ .Values.master.priorityClassName | quote }} + {{- end }} + {{- if .Values.master.affinity }} + affinity: {{- include "common.tplvalues.render" (dict "value" .Values.master.affinity "context" $) | nindent 8 }} + {{- else }} + affinity: + podAffinity: {{- include "common.affinities.pods" (dict "type" .Values.master.podAffinityPreset "component" "master" "context" $) | nindent 10 }} + podAntiAffinity: {{- include "common.affinities.pods" (dict "type" .Values.master.podAntiAffinityPreset "component" "master" "context" $) | nindent 10 }} + nodeAffinity: {{- include "common.affinities.nodes" (dict "type" .Values.master.nodeAffinityPreset.type "key" .Values.master.nodeAffinityPreset.key "values" .Values.master.nodeAffinityPreset.values) | nindent 10 }} + {{- end }} + {{- if .Values.master.nodeSelector }} + nodeSelector: {{- include "common.tplvalues.render" (dict "value" .Values.master.nodeSelector "context" $) | nindent 8 }} + {{- end }} + {{- if .Values.master.tolerations }} + tolerations: {{- include "common.tplvalues.render" (dict "value" .Values.master.tolerations "context" $) | nindent 8 }} + {{- end }} + {{- if .Values.master.spreadConstraints }} + topologySpreadConstraints: {{- include "common.tplvalues.render" (dict "value" .Values.master.spreadConstraints "context" $) | nindent 8 }} + {{- end }} + {{- if .Values.master.shareProcessNamespace }} + shareProcessNamespace: {{ .Values.master.shareProcessNamespace }} + {{- end }} + {{- if .Values.master.schedulerName }} + schedulerName: {{ .Values.master.schedulerName | quote }} + {{- end }} + terminationGracePeriodSeconds: {{ .Values.master.terminationGracePeriodSeconds }} + containers: + - name: redis + image: {{ template "redis.image" . }} + imagePullPolicy: {{ .Values.image.pullPolicy | quote }} + {{- if .Values.master.lifecycleHooks }} + lifecycle: {{- include "common.tplvalues.render" (dict "value" .Values.master.lifecycleHooks "context" $) | nindent 12 }} + {{- end }} + {{- if .Values.master.containerSecurityContext.enabled }} + securityContext: {{- omit .Values.master.containerSecurityContext "enabled" | toYaml | nindent 12 }} + {{- end }} + {{- if .Values.master.command }} + command: {{- include "common.tplvalues.render" (dict "value" .Values.master.command "context" $) | nindent 12 }} + {{- else }} + command: + - /bin/bash + {{- end }} + {{- if .Values.master.args }} + args: {{- include "common.tplvalues.render" (dict "value" .Values.master.args "context" $) | nindent 12 }} + {{- else }} + args: + - -c + - /opt/bitnami/scripts/start-scripts/start-master.sh + {{- end }} + env: + - name: BITNAMI_DEBUG + value: {{ ternary "true" "false" .Values.image.debug | quote }} + - name: REDIS_REPLICATION_MODE + value: master + - name: ALLOW_EMPTY_PASSWORD + value: {{ ternary "no" "yes" .Values.auth.enabled | quote }} + {{- if .Values.auth.enabled }} + {{- if .Values.auth.usePasswordFiles }} + - name: REDIS_PASSWORD_FILE + value: "/opt/bitnami/redis/secrets/redis-password" + {{- else }} + - name: REDIS_PASSWORD + valueFrom: + secretKeyRef: + name: {{ template "redis.secretName" . }} + key: {{ template "redis.secretPasswordKey" . }} + {{- end }} + {{- end }} + - name: REDIS_TLS_ENABLED + value: {{ ternary "yes" "no" .Values.tls.enabled | quote }} + {{- if .Values.tls.enabled }} + - name: REDIS_TLS_PORT + value: {{ .Values.master.containerPort | quote }} + - name: REDIS_TLS_AUTH_CLIENTS + value: {{ ternary "yes" "no" .Values.tls.authClients | quote }} + - name: REDIS_TLS_CERT_FILE + value: {{ template "redis.tlsCert" . }} + - name: REDIS_TLS_KEY_FILE + value: {{ template "redis.tlsCertKey" . }} + - name: REDIS_TLS_CA_FILE + value: {{ template "redis.tlsCACert" . }} + {{- if .Values.tls.dhParamsFilename }} + - name: REDIS_TLS_DH_PARAMS_FILE + value: {{ template "redis.tlsDHParams" . }} + {{- end }} + {{- else }} + - name: REDIS_PORT + value: {{ .Values.master.containerPort | quote }} + {{- end }} + {{- if .Values.master.extraEnvVars }} + {{- include "common.tplvalues.render" (dict "value" .Values.master.extraEnvVars "context" $) | nindent 12 }} + {{- end }} + {{- if or .Values.master.extraEnvVarsCM .Values.master.extraEnvVarsSecret }} + envFrom: + {{- if .Values.master.extraEnvVarsCM }} + - configMapRef: + name: {{ .Values.master.extraEnvVarsCM }} + {{- end }} + {{- if .Values.master.extraEnvVarsSecret }} + - secretRef: + name: {{ .Values.master.extraEnvVarsSecret }} + {{- end }} + {{- end }} + ports: + - name: redis + containerPort: {{ .Values.master.containerPort }} + {{- if .Values.master.livenessProbe.enabled }} + livenessProbe: + initialDelaySeconds: {{ .Values.master.livenessProbe.initialDelaySeconds }} + periodSeconds: {{ .Values.master.livenessProbe.periodSeconds }} + # One second longer than command timeout should prevent generation of zombie processes. + timeoutSeconds: {{ add1 .Values.master.livenessProbe.timeoutSeconds }} + successThreshold: {{ .Values.master.livenessProbe.successThreshold }} + failureThreshold: {{ .Values.master.livenessProbe.failureThreshold }} + exec: + command: + - sh + - -c + - /health/ping_liveness_local.sh {{ .Values.master.livenessProbe.timeoutSeconds }} + {{- else if .Values.master.customLivenessProbe }} + livenessProbe: {{- toYaml .Values.master.customLivenessProbe | nindent 12 }} + {{- end }} + {{- if .Values.master.readinessProbe.enabled}} + readinessProbe: + initialDelaySeconds: {{ .Values.master.readinessProbe.initialDelaySeconds }} + periodSeconds: {{ .Values.master.readinessProbe.periodSeconds }} + timeoutSeconds: {{ add1 .Values.master.readinessProbe.timeoutSeconds }} + successThreshold: {{ .Values.master.readinessProbe.successThreshold }} + failureThreshold: {{ .Values.master.readinessProbe.failureThreshold }} + exec: + command: + - sh + - -c + - /health/ping_readiness_local.sh {{ .Values.master.readinessProbe.timeoutSeconds }} + {{- else if .Values.master.customReadinessProbe }} + readinessProbe: {{- toYaml .Values.master.customReadinessProbe | nindent 12 }} + {{- end }} + {{- if .Values.master.resources }} + resources: {{- toYaml .Values.master.resources | nindent 12 }} + {{- end }} + volumeMounts: + - name: start-scripts + mountPath: /opt/bitnami/scripts/start-scripts + - name: health + mountPath: /health + {{- if .Values.auth.usePasswordFiles }} + - name: redis-password + mountPath: /opt/bitnami/redis/secrets/ + {{- end }} + - name: redis-data + mountPath: {{ .Values.master.persistence.path }} + subPath: {{ .Values.master.persistence.subPath }} + - name: config + mountPath: /opt/bitnami/redis/mounted-etc + - name: redis-tmp-conf + mountPath: /opt/bitnami/redis/etc/ + - name: tmp + mountPath: /tmp + {{- if .Values.tls.enabled }} + - name: redis-certificates + mountPath: /opt/bitnami/redis/certs + readOnly: true + {{- end }} + {{- if .Values.master.extraVolumeMounts }} + {{- include "common.tplvalues.render" ( dict "value" .Values.master.extraVolumeMounts "context" $ ) | nindent 12 }} + {{- end }} + {{- if .Values.metrics.enabled }} + - name: metrics + image: {{ include "redis.metrics.image" . }} + imagePullPolicy: {{ .Values.metrics.image.pullPolicy | quote }} + {{- if .Values.metrics.containerSecurityContext.enabled }} + securityContext: {{- omit .Values.metrics.containerSecurityContext "enabled" | toYaml | nindent 12 }} + {{- end }} + command: + - /bin/bash + - -c + - | + if [[ -f '/secrets/redis-password' ]]; then + export REDIS_PASSWORD=$(cat /secrets/redis-password) + fi + redis_exporter{{- range $key, $value := .Values.metrics.extraArgs }} --{{ $key }}={{ $value }}{{- end }} + env: + - name: REDIS_ALIAS + value: {{ template "common.names.fullname" . }} + {{- if .Values.auth.enabled }} + - name: REDIS_USER + value: default + {{- if (not .Values.auth.usePasswordFiles) }} + - name: REDIS_PASSWORD + valueFrom: + secretKeyRef: + name: {{ template "redis.secretName" . }} + key: {{ template "redis.secretPasswordKey" . }} + {{- end }} + {{- end }} + {{- if .Values.tls.enabled }} + - name: REDIS_ADDR + value: rediss://{{ .Values.metrics.redisTargetHost }}:{{ .Values.master.containerPort }} + {{- if .Values.tls.authClients }} + - name: REDIS_EXPORTER_TLS_CLIENT_KEY_FILE + value: {{ template "redis.tlsCertKey" . }} + - name: REDIS_EXPORTER_TLS_CLIENT_CERT_FILE + value: {{ template "redis.tlsCert" . }} + {{- end }} + - name: REDIS_EXPORTER_TLS_CA_CERT_FILE + value: {{ template "redis.tlsCACert" . }} + {{- end }} + ports: + - name: metrics + containerPort: 9121 + {{- if .Values.metrics.resources }} + resources: {{- toYaml .Values.metrics.resources | nindent 12 }} + {{- end }} + volumeMounts: + {{- if .Values.auth.usePasswordFiles }} + - name: redis-password + mountPath: /secrets/ + {{- end }} + {{- if .Values.tls.enabled }} + - name: redis-certificates + mountPath: /opt/bitnami/redis/certs + readOnly: true + {{- end }} + {{- end }} + {{- if .Values.master.sidecars }} + {{- include "common.tplvalues.render" (dict "value" .Values.master.sidecars "context" $) | nindent 8 }} + {{- end }} + {{- $needsVolumePermissions := and .Values.volumePermissions.enabled .Values.master.persistence.enabled .Values.master.podSecurityContext.enabled .Values.master.containerSecurityContext.enabled }} + {{- if or .Values.master.initContainers $needsVolumePermissions .Values.sysctl.enabled }} + initContainers: + {{- if .Values.master.initContainers }} + {{- include "common.tplvalues.render" (dict "value" .Values.master.initContainers "context" $) | nindent 8 }} + {{- end }} + {{- if $needsVolumePermissions }} + - name: volume-permissions + image: {{ include "redis.volumePermissions.image" . }} + imagePullPolicy: {{ .Values.volumePermissions.image.pullPolicy | quote }} + command: + - /bin/bash + - -ec + - | + {{- if eq ( toString ( .Values.volumePermissions.containerSecurityContext.runAsUser )) "auto" }} + chown -R `id -u`:`id -G | cut -d " " -f2` {{ .Values.master.persistence.path }} + {{- else }} + chown -R {{ .Values.master.containerSecurityContext.runAsUser }}:{{ .Values.master.podSecurityContext.fsGroup }} {{ .Values.master.persistence.path }} + {{- end }} + {{- if eq ( toString ( .Values.volumePermissions.containerSecurityContext.runAsUser )) "auto" }} + securityContext: {{- omit .Values.volumePermissions.containerSecurityContext "runAsUser" | toYaml | nindent 12 }} + {{- else }} + securityContext: {{- .Values.volumePermissions.containerSecurityContext | toYaml | nindent 12 }} + {{- end }} + {{- if .Values.volumePermissions.resources }} + resources: {{- toYaml .Values.volumePermissions.resources | nindent 12 }} + {{- end }} + volumeMounts: + - name: redis-data + mountPath: {{ .Values.master.persistence.path }} + subPath: {{ .Values.master.persistence.subPath }} + {{- end }} + {{- if .Values.sysctl.enabled }} + - name: init-sysctl + image: {{ include "redis.sysctl.image" . }} + imagePullPolicy: {{ default "" .Values.sysctl.image.pullPolicy | quote }} + securityContext: + privileged: true + runAsUser: 0 + {{- if .Values.sysctl.command }} + command: {{- include "common.tplvalues.render" (dict "value" .Values.sysctl.command "context" $) | nindent 12 }} + {{- end }} + {{- if .Values.sysctl.resources }} + resources: {{- toYaml .Values.sysctl.resources | nindent 12 }} + {{- end }} + {{- if .Values.sysctl.mountHostSys }} + volumeMounts: + - name: host-sys + mountPath: /host-sys + {{- end }} + {{- end }} + {{- end }} + volumes: + - name: start-scripts + configMap: + name: {{ printf "%s-scripts" (include "common.names.fullname" .) }} + defaultMode: 0755 + - name: health + configMap: + name: {{ printf "%s-health" (include "common.names.fullname" .) }} + defaultMode: 0755 + {{- if .Values.auth.usePasswordFiles }} + - name: redis-password + secret: + secretName: {{ template "redis.secretName" . }} + items: + - key: {{ template "redis.secretPasswordKey" . }} + path: redis-password + {{- end }} + - name: config + configMap: + name: {{ include "redis.configmapName" . }} + {{- if .Values.sysctl.mountHostSys }} + - name: host-sys + hostPath: + path: /sys + {{- end }} + - name: redis-tmp-conf + emptyDir: {} + - name: tmp + emptyDir: {} + {{- if .Values.tls.enabled }} + - name: redis-certificates + secret: + secretName: {{ required "A secret containing the certificates for the TLS traffic is required when TLS in enabled" .Values.tls.certificatesSecret }} + defaultMode: 256 + {{- end }} + {{- if .Values.master.extraVolumes }} + {{- include "common.tplvalues.render" ( dict "value" .Values.master.extraVolumes "context" $ ) | nindent 8 }} + {{- end }} + {{- if not .Values.master.persistence.enabled }} + - name: redis-data + emptyDir: {} + {{- else if .Values.master.persistence.existingClaim }} + - name: redis-data + persistentVolumeClaim: + claimName: {{ printf "%s" (tpl .Values.master.persistence.existingClaim .) }} + {{- else }} + volumeClaimTemplates: + - metadata: + name: redis-data + labels: {{- include "common.labels.matchLabels" . | nindent 10 }} + app.kubernetes.io/component: master + {{- if .Values.master.persistence.annotations }} + annotations: {{- toYaml .Values.master.persistence.annotations | nindent 10 }} + {{- end }} + spec: + accessModes: + {{- range .Values.master.persistence.accessModes }} + - {{ . | quote }} + {{- end }} + resources: + requests: + storage: {{ .Values.master.persistence.size | quote }} + {{- if .Values.master.persistence.selector }} + selector: {{- include "common.tplvalues.render" (dict "value" .Values.master.persistence.selector "context" $) | nindent 10 }} + {{- end }} + {{- include "common.storage.class" (dict "persistence" .Values.master.persistence "global" .Values.global) | nindent 8 }} + {{- end }} +{{- end }} diff --git a/chart/deps/redis/templates/metrics-prometheus.yaml b/chart/deps/redis/templates/metrics-prometheus.yaml deleted file mode 100644 index ed53dc6..0000000 --- a/chart/deps/redis/templates/metrics-prometheus.yaml +++ /dev/null @@ -1,39 +0,0 @@ -{{- if and (.Values.metrics.enabled) (.Values.metrics.serviceMonitor.enabled) }} -apiVersion: monitoring.coreos.com/v1 -kind: ServiceMonitor -metadata: - name: {{ template "redis.fullname" . }} - {{- if .Values.metrics.serviceMonitor.namespace }} - namespace: {{ .Values.metrics.serviceMonitor.namespace }} - {{- else }} - namespace: {{ .Release.Namespace | quote }} - {{- end }} - labels: - app: {{ template "redis.name" . }} - chart: {{ template "redis.chart" . }} - release: {{ .Release.Name }} - heritage: {{ .Release.Service }} - {{- range $key, $value := .Values.metrics.serviceMonitor.selector }} - {{ $key }}: {{ $value | quote }} - {{- end }} -spec: - endpoints: - - port: metrics - {{- if .Values.metrics.serviceMonitor.interval }} - interval: {{ .Values.metrics.serviceMonitor.interval }} - {{- end }} - {{- if .Values.metrics.serviceMonitor.relabelings }} - relabelings: {{- include "common.tplvalues.render" ( dict "value" .Values.metrics.serviceMonitor.relabelings "context" $) | nindent 6 }} - {{- end }} - {{- if .Values.metrics.serviceMonitor.metricRelabelings }} - metricRelabelings: {{- include "common.tplvalues.render" ( dict "value" .Values.metrics.serviceMonitor.metricRelabelings "context" $) | nindent 6 }} - {{- end }} - selector: - matchLabels: - app: {{ template "redis.name" . }} - release: {{ .Release.Name }} - app.kubernetes.io/component: "metrics" - namespaceSelector: - matchNames: - - {{ .Release.Namespace }} -{{- end -}} diff --git a/chart/deps/redis/templates/metrics-sentinel-svc.yaml b/chart/deps/redis/templates/metrics-sentinel-svc.yaml new file mode 100644 index 0000000..cea413c --- /dev/null +++ b/chart/deps/redis/templates/metrics-sentinel-svc.yaml @@ -0,0 +1,38 @@ +{{- if and .Values.sentinel.enabled .Values.metrics.sentinel.enabled }} +apiVersion: v1 +kind: Service +metadata: + name: {{ printf "%s-sentinel-metrics" (include "common.names.fullname" .) }} + namespace: {{ .Release.Namespace | quote }} + labels: {{- include "common.labels.standard" . | nindent 4 }} + app.kubernetes.io/component: sentinel-metrics + {{- if .Values.commonLabels }} + {{- include "common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }} + {{- end }} + {{- if or .Values.metrics.sentinel.service.annotations .Values.commonAnnotations }} + annotations: + {{- if .Values.metrics.sentinel.service.annotations }} + {{- include "common.tplvalues.render" ( dict "value" .Values.metrics.sentinel.service.annotations "context" $ ) | nindent 4 }} + {{- end }} + {{- if .Values.commonAnnotations }} + {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }} + {{- end }} + {{- end }} +spec: + type: {{ .Values.metrics.sentinel.service.type }} + {{- if eq .Values.metrics.sentinel.service.type "LoadBalancer" }} + externalTrafficPolicy: {{ .Values.metrics.sentinel.service.externalTrafficPolicy }} + {{- end }} + {{- if and (eq .Values.metrics.sentinel.service.type "LoadBalancer") .Values.metrics.sentinel.service.loadBalancerIP }} + loadBalancerIP: {{ .Values.metrics.sentinel.service.loadBalancerIP }} + {{- end }} + {{- if and (eq .Values.metrics.sentinel.service.type "LoadBalancer") .Values.metrics.sentinel.service.loadBalancerSourceRanges }} + loadBalancerSourceRanges: {{- toYaml .Values.metrics.sentinel.service.loadBalancerSourceRanges | nindent 4 }} + {{- end }} + ports: + - name: tcp-metrics + port: {{ .Values.metrics.sentinel.service.port }} + protocol: TCP + targetPort: sentinelmetrics + selector: {{- include "common.labels.matchLabels" . | nindent 4 }} +{{- end }} diff --git a/chart/deps/redis/templates/metrics-svc.yaml b/chart/deps/redis/templates/metrics-svc.yaml index 767a464..7b88b2f 100644 --- a/chart/deps/redis/templates/metrics-svc.yaml +++ b/chart/deps/redis/templates/metrics-svc.yaml @@ -2,33 +2,37 @@ apiVersion: v1 kind: Service metadata: - name: {{ template "redis.fullname" . }}-metrics + name: {{ printf "%s-metrics" (include "common.names.fullname" .) }} namespace: {{ .Release.Namespace | quote }} - labels: - app: {{ template "redis.name" . }} - chart: {{ template "redis.chart" . }} - release: {{ .Release.Name }} - heritage: {{ .Release.Service }} - app.kubernetes.io/component: "metrics" - {{- if .Values.metrics.service.labels -}} - {{- toYaml .Values.metrics.service.labels | nindent 4 }} - {{- end -}} - {{- if .Values.metrics.service.annotations }} - annotations: {{- toYaml .Values.metrics.service.annotations | nindent 4 }} + labels: {{- include "common.labels.standard" . | nindent 4 }} + app.kubernetes.io/component: metrics + {{- if .Values.commonLabels }} + {{- include "common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }} + {{- end }} + {{- if or .Values.metrics.service.annotations .Values.commonAnnotations }} + annotations: + {{- if .Values.metrics.service.annotations }} + {{- include "common.tplvalues.render" ( dict "value" .Values.metrics.service.annotations "context" $ ) | nindent 4 }} + {{- end }} + {{- if .Values.commonAnnotations }} + {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }} + {{- end }} {{- end }} spec: type: {{ .Values.metrics.service.type }} - {{ if eq .Values.metrics.service.type "LoadBalancer" }} + {{- if eq .Values.metrics.service.type "LoadBalancer" }} externalTrafficPolicy: {{ .Values.metrics.service.externalTrafficPolicy }} {{- end }} - {{ if and (eq .Values.metrics.service.type "LoadBalancer") .Values.metrics.service.loadBalancerIP }} + {{- if and (eq .Values.metrics.service.type "LoadBalancer") .Values.metrics.service.loadBalancerIP }} loadBalancerIP: {{ .Values.metrics.service.loadBalancerIP }} {{- end }} + {{- if and (eq .Values.metrics.service.type "LoadBalancer") .Values.metrics.service.loadBalancerSourceRanges }} + loadBalancerSourceRanges: {{- toYaml .Values.metrics.service.loadBalancerSourceRanges | nindent 4 }} + {{- end }} ports: - - name: metrics - port: 9121 + - name: tcp-metrics + port: {{ .Values.metrics.service.port }} + protocol: TCP targetPort: metrics - selector: - app: {{ template "redis.name" . }} - release: {{ .Release.Name }} + selector: {{- include "common.labels.matchLabels" . | nindent 4 }} {{- end }} diff --git a/chart/deps/redis/templates/networkpolicy.yaml b/chart/deps/redis/templates/networkpolicy.yaml index 0249bc0..ec48bc2 100644 --- a/chart/deps/redis/templates/networkpolicy.yaml +++ b/chart/deps/redis/templates/networkpolicy.yaml @@ -2,55 +2,56 @@ kind: NetworkPolicy apiVersion: {{ template "networkPolicy.apiVersion" . }} metadata: - name: {{ template "redis.fullname" . }} + name: {{ template "common.names.fullname" . }} namespace: {{ .Release.Namespace | quote }} - labels: - app: {{ template "redis.name" . }} - chart: {{ template "redis.chart" . }} - release: {{ .Release.Name }} - heritage: {{ .Release.Service }} + labels: {{- include "common.labels.standard" . | nindent 4 }} + {{- if .Values.commonLabels }} + {{- include "common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }} + {{- end }} + {{- if .Values.commonAnnotations }} + annotations: {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }} + {{- end }} spec: podSelector: - matchLabels: - app: {{ template "redis.name" . }} - release: {{ .Release.Name }} - {{- if .Values.cluster.enabled }} + matchLabels: {{- include "common.labels.matchLabels" . | nindent 6 }} policyTypes: - Ingress + {{- if or (eq .Values.architecture "replication") .Values.networkPolicy.extraEgress }} - Egress egress: + {{- if eq .Values.architecture "replication" }} # Allow dns resolution - ports: - port: 53 protocol: UDP # Allow outbound connections to other cluster pods - ports: - - port: {{ .Values.redisPort }} + - port: {{ .Values.master.containerPort }} {{- if .Values.sentinel.enabled }} - - port: {{ .Values.sentinel.port }} + - port: {{ .Values.sentinel.containerPort }} {{- end }} to: - podSelector: - matchLabels: - app: {{ template "redis.name" . }} - release: {{ .Release.Name }} + matchLabels: {{- include "common.labels.matchLabels" . | nindent 14 }} + {{- end }} + {{- if .Values.networkPolicy.extraEgress }} + {{- include "common.tplvalues.render" ( dict "value" .Values.networkPolicy.extraEgress "context" $ ) | nindent 4 }} + {{- end }} {{- end }} ingress: # Allow inbound connections - ports: - - port: {{ .Values.redisPort }} + - port: {{ .Values.master.containerPort }} {{- if .Values.sentinel.enabled }} - - port: {{ .Values.sentinel.port }} + - port: {{ .Values.sentinel.containerPort }} {{- end }} {{- if not .Values.networkPolicy.allowExternal }} from: - podSelector: matchLabels: - {{ template "redis.fullname" . }}-client: "true" + {{ template "common.names.fullname" . }}-client: "true" - podSelector: - matchLabels: - app: {{ template "redis.name" . }} - release: {{ .Release.Name }} + matchLabels: {{- include "common.labels.matchLabels" . | nindent 14 }} {{- if .Values.networkPolicy.ingressNSMatchLabels }} - namespaceSelector: matchLabels: @@ -65,10 +66,18 @@ spec: {{- end }} {{- end }} {{- end }} - {{- end }} + {{- end }} {{- if .Values.metrics.enabled }} # Allow prometheus scrapes for metrics - ports: - port: 9121 {{- end }} + {{- if .Values.metrics.sentinel.enabled }} + # Allow prometheus scrapes for sentinel metrics + - ports: + - port: 9355 + {{- end }} + {{- if .Values.networkPolicy.extraIngress }} + {{- include "common.tplvalues.render" ( dict "value" .Values.networkPolicy.extraIngress "context" $ ) | nindent 4 }} + {{- end }} {{- end }} diff --git a/chart/deps/redis/templates/pdb.yaml b/chart/deps/redis/templates/pdb.yaml index b9dc54b..d8a3150 100644 --- a/chart/deps/redis/templates/pdb.yaml +++ b/chart/deps/redis/templates/pdb.yaml @@ -1,22 +1,23 @@ -{{- if .Values.podDisruptionBudget.enabled }} +{{- if .Values.pdb.create }} apiVersion: policy/v1beta1 kind: PodDisruptionBudget metadata: - name: {{ template "redis.fullname" . }} + name: {{ template "common.names.fullname" . }} namespace: {{ .Release.Namespace | quote }} - labels: - app: {{ template "redis.name" . }} - chart: {{ template "redis.chart" . }} + labels: {{- include "common.labels.standard" . | nindent 4 }} + {{- if .Values.commonLabels }} + {{- include "common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }} + {{- end }} + {{- if .Values.commonAnnotations }} + annotations: {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }} + {{- end }} spec: - {{- if .Values.podDisruptionBudget.minAvailable }} - minAvailable: {{ .Values.podDisruptionBudget.minAvailable }} + {{- if .Values.pdb.minAvailable }} + minAvailable: {{ .Values.pdb.minAvailable }} {{- end }} - {{- if .Values.podDisruptionBudget.maxUnavailable }} - maxUnavailable: {{ .Values.podDisruptionBudget.maxUnavailable }} + {{- if .Values.pdb.maxUnavailable }} + maxUnavailable: {{ .Values.pdb.maxUnavailable }} {{- end }} selector: - matchLabels: - app: {{ template "redis.name" . }} - chart: {{ template "redis.chart" . }} - release: {{ .Release.Name }} + matchLabels: {{- include "common.labels.matchLabels" . | nindent 6 }} {{- end }} diff --git a/chart/deps/redis/templates/prometheusrule.yaml b/chart/deps/redis/templates/prometheusrule.yaml index 48ae017..cd8bc68 100644 --- a/chart/deps/redis/templates/prometheusrule.yaml +++ b/chart/deps/redis/templates/prometheusrule.yaml @@ -2,24 +2,26 @@ apiVersion: monitoring.coreos.com/v1 kind: PrometheusRule metadata: - name: {{ template "redis.fullname" . }} + name: {{ template "common.names.fullname" . }} {{- if .Values.metrics.prometheusRule.namespace }} namespace: {{ .Values.metrics.prometheusRule.namespace }} {{- else }} namespace: {{ .Release.Namespace | quote }} {{- end }} - labels: - app: {{ template "redis.name" . }} - chart: {{ template "redis.chart" . }} - release: {{ .Release.Name | quote }} - heritage: {{ .Release.Service | quote }} -{{- with .Values.metrics.prometheusRule.additionalLabels }} -{{- toYaml . | nindent 4 }} -{{- end }} + labels: {{- include "common.labels.standard" . | nindent 4 }} + {{- if .Values.metrics.prometheusRule.additionalLabels }} + {{- include "common.tplvalues.render" (dict "value" .Values.metrics.prometheusRule.additionalLabels "context" $) | nindent 4 }} + {{- end }} + {{- if .Values.commonLabels }} + {{- include "common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }} + {{- end }} + {{- if .Values.commonAnnotations }} + annotations: {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }} + {{- end }} spec: -{{- with .Values.metrics.prometheusRule.rules }} + {{- with .Values.metrics.prometheusRule.rules }} groups: - - name: {{ template "redis.name" $ }} + - name: {{ template "common.names.name" $ }} rules: {{- tpl (toYaml .) $ | nindent 8 }} -{{- end }} + {{- end }} {{- end }} diff --git a/chart/deps/redis/templates/psp.yaml b/chart/deps/redis/templates/psp.yaml deleted file mode 100644 index eca04c1..0000000 --- a/chart/deps/redis/templates/psp.yaml +++ /dev/null @@ -1,43 +0,0 @@ -{{- if .Values.podSecurityPolicy.create }} -apiVersion: {{ template "podSecurityPolicy.apiVersion" . }} -kind: PodSecurityPolicy -metadata: - name: {{ template "redis.fullname" . }} - namespace: {{ .Release.Namespace | quote }} - labels: - app: {{ template "redis.name" . }} - chart: {{ template "redis.chart" . }} - heritage: {{ .Release.Service }} - release: {{ .Release.Name }} -spec: - allowPrivilegeEscalation: false - fsGroup: - rule: 'MustRunAs' - ranges: - - min: {{ .Values.securityContext.fsGroup }} - max: {{ .Values.securityContext.fsGroup }} - hostIPC: false - hostNetwork: false - hostPID: false - privileged: false - readOnlyRootFilesystem: false - requiredDropCapabilities: - - ALL - runAsUser: - rule: 'MustRunAs' - ranges: - - min: {{ .Values.containerSecurityContext.runAsUser }} - max: {{ .Values.containerSecurityContext.runAsUser }} - seLinux: - rule: 'RunAsAny' - supplementalGroups: - rule: 'MustRunAs' - ranges: - - min: {{ .Values.containerSecurityContext.runAsUser }} - max: {{ .Values.containerSecurityContext.runAsUser }} - volumes: - - 'configMap' - - 'secret' - - 'emptyDir' - - 'persistentVolumeClaim' -{{- end }} diff --git a/chart/deps/redis/templates/redis-master-statefulset.yaml b/chart/deps/redis/templates/redis-master-statefulset.yaml deleted file mode 100644 index ae138c0..0000000 --- a/chart/deps/redis/templates/redis-master-statefulset.yaml +++ /dev/null @@ -1,382 +0,0 @@ -{{- if or (not .Values.cluster.enabled) (not .Values.sentinel.enabled) }} -apiVersion: apps/v1 -kind: StatefulSet -metadata: - name: {{ template "redis.fullname" . }}-master - namespace: {{ .Release.Namespace | quote }} - labels: - app: {{ template "redis.name" . }} - chart: {{ template "redis.chart" . }} - release: {{ .Release.Name }} - heritage: {{ .Release.Service }} - {{- if .Values.master.statefulset.labels }} - {{- toYaml .Values.master.statefulset.labels | nindent 4 }} - {{- end }} -{{- if .Values.master.statefulset.annotations }} - annotations: - {{- toYaml .Values.master.statefulset.annotations | nindent 4 }} -{{- end }} -spec: - selector: - matchLabels: - app: {{ template "redis.name" . }} - release: {{ .Release.Name }} - role: master - serviceName: {{ template "redis.fullname" . }}-headless - template: - metadata: - labels: - app: {{ template "redis.name" . }} - chart: {{ template "redis.chart" . }} - release: {{ .Release.Name }} - role: master - {{- if .Values.master.podLabels }} - {{- toYaml .Values.master.podLabels | nindent 8 }} - {{- end }} - {{- if and .Values.metrics.enabled .Values.metrics.podLabels }} - {{- toYaml .Values.metrics.podLabels | nindent 8 }} - {{- end }} - annotations: - checksum/health: {{ include (print $.Template.BasePath "/health-configmap.yaml") . | sha256sum }} - checksum/configmap: {{ include (print $.Template.BasePath "/configmap.yaml") . | sha256sum }} - checksum/secret: {{ include (print $.Template.BasePath "/secret.yaml") . | sha256sum }} - {{- if .Values.master.podAnnotations }} - {{- toYaml .Values.master.podAnnotations | nindent 8 }} - {{- end }} - {{- if and .Values.metrics.enabled .Values.metrics.podAnnotations }} - {{- toYaml .Values.metrics.podAnnotations | nindent 8 }} - {{- end }} - spec: - {{- include "redis.imagePullSecrets" . | nindent 6 }} - {{- if .Values.master.hostAliases }} - hostAliases: {{- include "common.tplvalues.render" (dict "value" .Values.master.hostAliases "context" $) | nindent 8 }} - {{- end }} - {{- if .Values.securityContext.enabled }} - securityContext: {{- omit .Values.securityContext "enabled" | toYaml | nindent 8 }} - {{- end }} - serviceAccountName: {{ template "redis.serviceAccountName" . }} - {{- if .Values.master.priorityClassName }} - priorityClassName: {{ .Values.master.priorityClassName | quote }} - {{- end }} - {{- with .Values.master.affinity }} - affinity: {{- tpl (toYaml .) $ | nindent 8 }} - {{- end }} - {{- if .Values.master.nodeSelector }} - nodeSelector: {{- toYaml .Values.master.nodeSelector | nindent 8 }} - {{- end }} - {{- if .Values.master.tolerations }} - tolerations: {{- toYaml .Values.master.tolerations | nindent 8 }} - {{- end }} - {{- if .Values.master.shareProcessNamespace }} - shareProcessNamespace: {{ .Values.master.shareProcessNamespace }} - {{- end }} - {{- if .Values.master.schedulerName }} - schedulerName: {{ .Values.master.schedulerName }} - {{- end }} - containers: - - name: {{ template "redis.name" . }} - image: {{ template "redis.image" . }} - imagePullPolicy: {{ .Values.image.pullPolicy | quote }} - {{- if .Values.containerSecurityContext.enabled }} - securityContext: {{- omit .Values.containerSecurityContext "enabled" | toYaml | nindent 12 }} - {{- end }} - command: - - /bin/bash - - -c - - /opt/bitnami/scripts/start-scripts/start-master.sh - env: - - name: REDIS_REPLICATION_MODE - value: master - {{- if .Values.usePassword }} - {{- if .Values.usePasswordFile }} - - name: REDIS_PASSWORD_FILE - value: "/opt/bitnami/redis/secrets/redis-password" - {{- else }} - - name: REDIS_PASSWORD - valueFrom: - secretKeyRef: - name: {{ template "redis.secretName" . }} - key: {{ template "redis.secretPasswordKey" . }} - {{- end }} - {{- else }} - - name: ALLOW_EMPTY_PASSWORD - value: "yes" - {{- end }} - - name: REDIS_TLS_ENABLED - value: {{ ternary "yes" "no" .Values.tls.enabled | quote }} - {{- if .Values.tls.enabled }} - - name: REDIS_TLS_PORT - value: {{ .Values.redisPort | quote }} - - name: REDIS_TLS_AUTH_CLIENTS - value: {{ ternary "yes" "no" .Values.tls.authClients | quote }} - - name: REDIS_TLS_CERT_FILE - value: {{ template "redis.tlsCert" . }} - - name: REDIS_TLS_KEY_FILE - value: {{ template "redis.tlsCertKey" . }} - - name: REDIS_TLS_CA_FILE - value: {{ template "redis.tlsCACert" . }} - {{- if .Values.tls.dhParamsFilename }} - - name: REDIS_TLS_DH_PARAMS_FILE - value: {{ template "redis.tlsDHParams" . }} - {{- end }} - {{- else }} - - name: REDIS_PORT - value: {{ .Values.redisPort | quote }} - {{- end }} - {{- if .Values.master.extraEnvVars }} - {{- include "redis.tplValue" (dict "value" .Values.master.extraEnvVars "context" $) | nindent 12 }} - {{- end }} - {{- if or .Values.master.extraEnvVarsCM .Values.master.extraEnvVarsSecret }} - envFrom: - {{- if .Values.master.extraEnvVarsCM }} - - configMapRef: - name: {{ .Values.master.extraEnvVarsCM }} - {{- end }} - {{- if .Values.master.extraEnvVarsSecret }} - - secretRef: - name: {{ .Values.master.extraEnvVarsSecret }} - {{- end }} - {{- end }} - ports: - - name: redis - containerPort: {{ .Values.redisPort }} - {{- if .Values.master.livenessProbe.enabled }} - livenessProbe: - initialDelaySeconds: {{ .Values.master.livenessProbe.initialDelaySeconds }} - periodSeconds: {{ .Values.master.livenessProbe.periodSeconds }} - # One second longer than command timeout should prevent generation of zombie processes. - timeoutSeconds: {{ add1 .Values.master.livenessProbe.timeoutSeconds }} - successThreshold: {{ .Values.master.livenessProbe.successThreshold }} - failureThreshold: {{ .Values.master.livenessProbe.failureThreshold }} - exec: - command: - - sh - - -c - - /health/ping_liveness_local.sh {{ .Values.master.livenessProbe.timeoutSeconds }} - {{- else if .Values.master.customLivenessProbe }} - livenessProbe: {{- toYaml .Values.master.customLivenessProbe | nindent 12 }} - {{- end }} - {{- if .Values.master.readinessProbe.enabled}} - readinessProbe: - initialDelaySeconds: {{ .Values.master.readinessProbe.initialDelaySeconds }} - periodSeconds: {{ .Values.master.readinessProbe.periodSeconds }} - timeoutSeconds: {{ add1 .Values.master.readinessProbe.timeoutSeconds }} - successThreshold: {{ .Values.master.readinessProbe.successThreshold }} - failureThreshold: {{ .Values.master.readinessProbe.failureThreshold }} - exec: - command: - - sh - - -c - - /health/ping_readiness_local.sh {{ .Values.master.readinessProbe.timeoutSeconds }} - {{- else if .Values.master.customReadinessProbe }} - readinessProbe: {{- toYaml .Values.master.customReadinessProbe | nindent 12 }} - {{- end }} - resources: {{- toYaml .Values.master.resources | nindent 12 }} - volumeMounts: - - name: start-scripts - mountPath: /opt/bitnami/scripts/start-scripts - - name: health - mountPath: /health - {{- if .Values.usePasswordFile }} - - name: redis-password - mountPath: /opt/bitnami/redis/secrets/ - {{- end }} - - name: redis-data - mountPath: {{ .Values.master.persistence.path }} - subPath: {{ .Values.master.persistence.subPath }} - - name: config - mountPath: /opt/bitnami/redis/mounted-etc - - name: redis-tmp-conf - mountPath: /opt/bitnami/redis/etc/ - - name: tmp - mountPath: /tmp - {{- if .Values.tls.enabled }} - - name: redis-certificates - mountPath: /opt/bitnami/redis/certs - readOnly: true - {{- end }} - {{- if .Values.metrics.enabled }} - - name: metrics - image: {{ template "redis.metrics.image" . }} - imagePullPolicy: {{ .Values.metrics.image.pullPolicy | quote }} - {{- if .Values.containerSecurityContext.enabled }} - securityContext: {{- omit .Values.containerSecurityContext "enabled" | toYaml | nindent 12 }} - {{- end }} - command: - - /bin/bash - - -c - - | - if [[ -f '/secrets/redis-password' ]]; then - export REDIS_PASSWORD=$(cat /secrets/redis-password) - fi - redis_exporter{{- range $key, $value := .Values.metrics.extraArgs }} --{{ $key }}={{ $value }}{{- end }} - env: - - name: REDIS_ALIAS - value: {{ template "redis.fullname" . }} - {{- if and .Values.usePassword (not .Values.usePasswordFile) }} - - name: REDIS_PASSWORD - valueFrom: - secretKeyRef: - name: {{ template "redis.secretName" . }} - key: {{ template "redis.secretPasswordKey" . }} - {{- end }} - {{- if .Values.tls.enabled }} - - name: REDIS_ADDR - value: rediss://localhost:{{ .Values.redisPort }} - - name: REDIS_EXPORTER_TLS_CLIENT_KEY_FILE - value: {{ template "redis.tlsCertKey" . }} - - name: REDIS_EXPORTER_TLS_CLIENT_CERT_FILE - value: {{ template "redis.tlsCert" . }} - - name: REDIS_EXPORTER_TLS_CA_CERT_FILE - value: {{ template "redis.tlsCACert" . }} - {{- end }} - volumeMounts: - {{- if .Values.usePasswordFile }} - - name: redis-password - mountPath: /secrets/ - {{- end }} - {{- if .Values.tls.enabled }} - - name: redis-certificates - mountPath: /opt/bitnami/redis/certs - readOnly: true - {{- end }} - ports: - - name: metrics - containerPort: 9121 - resources: {{- toYaml .Values.metrics.resources | nindent 12 }} - {{- end }} - {{- $needsVolumePermissions := and .Values.volumePermissions.enabled .Values.master.persistence.enabled .Values.securityContext.enabled .Values.containerSecurityContext.enabled }} - {{- if or $needsVolumePermissions .Values.sysctlImage.enabled }} - initContainers: - {{- if $needsVolumePermissions }} - - name: volume-permissions - image: "{{ template "redis.volumePermissions.image" . }}" - imagePullPolicy: {{ .Values.volumePermissions.image.pullPolicy | quote }} - command: - - /bin/bash - - -ec - - | - {{- if eq ( toString ( .Values.volumePermissions.securityContext.runAsUser )) "auto" }} - chown -R `id -u`:`id -G | cut -d " " -f2` {{ .Values.master.persistence.path }} - {{- else }} - chown -R {{ .Values.containerSecurityContext.runAsUser }}:{{ .Values.securityContext.fsGroup }} {{ .Values.master.persistence.path }} - {{- end }} - {{- if eq ( toString ( .Values.volumePermissions.securityContext.runAsUser )) "auto "}} - securityContext: {{- omit .Values.volumePermissions.securityContext "runAsUser" | toYaml | nindent 12 }} - {{- else }} - securityContext: {{- .Values.volumePermissions.securityContext | toYaml | nindent 12 }} - {{- end }} - resources: {{- toYaml .Values.volumePermissions.resources | nindent 10 }} - volumeMounts: - - name: redis-data - mountPath: {{ .Values.master.persistence.path }} - subPath: {{ .Values.master.persistence.subPath }} - {{- end }} - {{- if .Values.sysctlImage.enabled }} - - name: init-sysctl - image: {{ template "redis.sysctl.image" . }} - imagePullPolicy: {{ default "" .Values.sysctlImage.pullPolicy | quote }} - resources: {{- toYaml .Values.sysctlImage.resources | nindent 10 }} - {{- if .Values.sysctlImage.mountHostSys }} - volumeMounts: - - name: host-sys - mountPath: /host-sys - {{- end }} - command: {{- toYaml .Values.sysctlImage.command | nindent 10 }} - securityContext: - privileged: true - runAsUser: 0 - {{- end }} - {{- end }} - volumes: - - name: start-scripts - configMap: - name: {{ include "redis.fullname" . }}-scripts - defaultMode: 0755 - - name: health - configMap: - name: {{ template "redis.fullname" . }}-health - defaultMode: 0755 - {{- if .Values.usePasswordFile }} - - name: redis-password - secret: - secretName: {{ template "redis.secretName" . }} - items: - - key: {{ template "redis.secretPasswordKey" . }} - path: redis-password - {{- end }} - - name: config - configMap: - name: {{ template "redis.fullname" . }} - {{- if not .Values.master.persistence.enabled }} - - name: "redis-data" - emptyDir: {} - {{- else }} - {{- if .Values.persistence.existingClaim }} - - name: "redis-data" - persistentVolumeClaim: - claimName: {{ include "redis.tplValue" (dict "value" .Values.persistence.existingClaim "context" $) }} - {{- end }} - {{- if .Values.master.persistence.volumes }} - {{- toYaml .Values.master.persistence.volumes | nindent 8 }} - {{- end }} - {{- end }} - {{- if .Values.sysctlImage.mountHostSys }} - - name: host-sys - hostPath: - path: /sys - {{- end }} - - name: redis-tmp-conf - emptyDir: {} - - name: tmp - emptyDir: {} - {{- if .Values.tls.enabled }} - - name: redis-certificates - secret: - secretName: {{ required "A secret containing the certificates for the TLS traffic is required when TLS in enabled" .Values.tls.certificatesSecret }} - defaultMode: 256 - {{- end }} - {{- if and .Values.master.persistence.enabled (not .Values.persistence.existingClaim) (not .Values.master.persistence.volumes) }} - volumeClaimTemplates: - - metadata: - name: redis-data - labels: - app: {{ template "redis.name" . }} - release: {{ .Release.Name }} - heritage: {{ .Release.Service }} - component: master - {{- if .Values.master.statefulset.volumeClaimTemplates.labels }} - {{- toYaml .Values.master.statefulset.volumeClaimTemplates.labels | nindent 10 }} - {{- end }} - {{- if .Values.master.statefulset.volumeClaimTemplates.annotations }} - annotations: - {{- toYaml .Values.master.statefulset.volumeClaimTemplates.annotations | nindent 10 }} - {{- end }} - spec: - accessModes: - {{- range .Values.master.persistence.accessModes }} - - {{ . | quote }} - {{- end }} - resources: - requests: - storage: {{ .Values.master.persistence.size | quote }} - {{ include "redis.master.storageClass" . }} - selector: - {{- if .Values.master.persistence.matchLabels }} - matchLabels: {{- toYaml .Values.master.persistence.matchLabels | nindent 12 }} - {{- end -}} - {{- if .Values.master.persistence.matchExpressions }} - matchExpressions: {{- toYaml .Values.master.persistence.matchExpressions | nindent 12 }} - {{- end -}} - {{- end }} - updateStrategy: - type: {{ .Values.master.statefulset.updateStrategy }} - {{- if .Values.master.statefulset.rollingUpdatePartition }} - {{- if (eq "Recreate" .Values.master.statefulset.updateStrategy) }} - rollingUpdate: null - {{- else }} - rollingUpdate: - partition: {{ .Values.master.statefulset.rollingUpdatePartition }} - {{- end }} - {{- end }} -{{- end }} diff --git a/chart/deps/redis/templates/redis-master-svc.yaml b/chart/deps/redis/templates/redis-master-svc.yaml deleted file mode 100644 index 8bd2f8c..0000000 --- a/chart/deps/redis/templates/redis-master-svc.yaml +++ /dev/null @@ -1,43 +0,0 @@ -{{- if not .Values.sentinel.enabled }} -apiVersion: v1 -kind: Service -metadata: - name: {{ template "redis.fullname" . }}-master - namespace: {{ .Release.Namespace | quote }} - labels: - app: {{ template "redis.name" . }} - chart: {{ template "redis.chart" . }} - release: {{ .Release.Name }} - heritage: {{ .Release.Service }} - {{- if .Values.master.service.labels -}} - {{- toYaml .Values.master.service.labels | nindent 4 }} - {{- end -}} -{{- if .Values.master.service.annotations }} - annotations: {{- toYaml .Values.master.service.annotations | nindent 4 }} -{{- end }} -spec: - type: {{ .Values.master.service.type }} - {{ if eq .Values.master.service.type "LoadBalancer" }} - externalTrafficPolicy: {{ .Values.master.service.externalTrafficPolicy }} - {{- end }} - {{- if and (eq .Values.master.service.type "LoadBalancer") .Values.master.service.loadBalancerIP }} - loadBalancerIP: {{ .Values.master.service.loadBalancerIP }} - {{- end }} - {{- if and (eq .Values.master.service.type "LoadBalancer") .Values.master.service.loadBalancerSourceRanges }} - loadBalancerSourceRanges: - {{- with .Values.master.service.loadBalancerSourceRanges }} -{{- toYaml . | nindent 4 }} -{{- end }} - {{- end }} - ports: - - name: tcp-redis - port: {{ .Values.master.service.port }} - targetPort: redis - {{- if .Values.master.service.nodePort }} - nodePort: {{ .Values.master.service.nodePort }} - {{- end }} - selector: - app: {{ template "redis.name" . }} - release: {{ .Release.Name }} - role: master -{{- end }} diff --git a/chart/deps/redis/templates/redis-node-statefulset.yaml b/chart/deps/redis/templates/redis-node-statefulset.yaml deleted file mode 100644 index 5a83a62..0000000 --- a/chart/deps/redis/templates/redis-node-statefulset.yaml +++ /dev/null @@ -1,507 +0,0 @@ -{{- if and .Values.cluster.enabled .Values.sentinel.enabled }} -apiVersion: apps/v1 -kind: StatefulSet -metadata: - name: {{ template "redis.fullname" . }}-node - namespace: {{ .Release.Namespace | quote }} - labels: - app: {{ template "redis.name" . }} - chart: {{ template "redis.chart" . }} - release: {{ .Release.Name }} - heritage: {{ .Release.Service }} - {{- if .Values.slave.statefulset.labels }} - {{- toYaml .Values.slave.statefulset.labels | nindent 4 }} - {{- end }} -{{- if .Values.slave.statefulset.annotations }} - annotations: - {{- toYaml .Values.slave.statefulset.annotations | nindent 4 }} -{{- end }} -spec: -{{- if .Values.slave.updateStrategy }} - strategy: {{- toYaml .Values.slave.updateStrategy | nindent 4 }} -{{- end }} - replicas: {{ .Values.cluster.slaveCount }} - serviceName: {{ template "redis.fullname" . }}-headless - selector: - matchLabels: - app: {{ template "redis.name" . }} - release: {{ .Release.Name }} - role: node - template: - metadata: - labels: - app: {{ template "redis.name" . }} - release: {{ .Release.Name }} - chart: {{ template "redis.chart" . }} - role: node - {{- if .Values.slave.podLabels }} - {{- toYaml .Values.slave.podLabels | nindent 8 }} - {{- end }} - {{- if and .Values.metrics.enabled .Values.metrics.podLabels }} - {{- toYaml .Values.metrics.podLabels | nindent 8 }} - {{- end }} - annotations: - checksum/health: {{ include (print $.Template.BasePath "/health-configmap.yaml") . | sha256sum }} - checksum/configmap: {{ include (print $.Template.BasePath "/configmap.yaml") . | sha256sum }} - checksum/secret: {{ include (print $.Template.BasePath "/secret.yaml") . | sha256sum }} - {{- if .Values.slave.podAnnotations }} - {{- toYaml .Values.slave.podAnnotations | nindent 8 }} - {{- end }} - {{- if and .Values.metrics.enabled .Values.metrics.podAnnotations }} - {{- toYaml .Values.metrics.podAnnotations | nindent 8 }} - {{- end }} - spec: - {{- include "redis.imagePullSecrets" . | nindent 6 }} - {{- if .Values.slave.hostAliases }} - hostAliases: {{- include "common.tplvalues.render" (dict "value" .Values.slave.hostAliases "context" $) | nindent 8 }} - {{- end }} - {{- if .Values.securityContext.enabled }} - securityContext: {{- omit .Values.securityContext "enabled" | toYaml | nindent 8 }} - {{- end }} - serviceAccountName: {{ template "redis.serviceAccountName" . }} - {{- if .Values.slave.priorityClassName }} - priorityClassName: "{{ .Values.slave.priorityClassName }}" - {{- end }} - {{- if .Values.slave.nodeSelector }} - nodeSelector: {{- toYaml .Values.slave.nodeSelector | nindent 8 }} - {{- end }} - {{- if .Values.slave.tolerations }} - tolerations: {{- toYaml .Values.slave.tolerations | nindent 8 }} - {{- end }} - {{- if .Values.slave.schedulerName }} - schedulerName: {{ .Values.slave.schedulerName }} - {{- end }} - {{- if .Values.master.spreadConstraints }} - topologySpreadConstraints: {{- toYaml .Values.master.spreadConstraints | nindent 8 }} - {{- end }} - {{- with .Values.slave.affinity }} - affinity: {{- tpl (toYaml .) $ | nindent 8 }} - {{- end }} - containers: - - name: {{ template "redis.name" . }} - image: {{ template "redis.image" . }} - imagePullPolicy: {{ .Values.image.pullPolicy | quote }} - {{- if .Values.containerSecurityContext.enabled }} - securityContext: {{- omit .Values.containerSecurityContext "enabled" | toYaml | nindent 12 }} - {{- end }} - command: - - /bin/bash - - -c - - /opt/bitnami/scripts/start-scripts/start-node.sh - env: - - name: REDIS_MASTER_PORT_NUMBER - value: {{ .Values.redisPort | quote }} - {{- if .Values.usePassword }} - {{- if .Values.usePasswordFile }} - - name: REDIS_PASSWORD_FILE - value: "/opt/bitnami/redis/secrets/redis-password" - - name: REDIS_MASTER_PASSWORD_FILE - value: "/opt/bitnami/redis/secrets/redis-password" - {{- else }} - - name: REDIS_PASSWORD - valueFrom: - secretKeyRef: - name: {{ template "redis.secretName" . }} - key: {{ template "redis.secretPasswordKey" . }} - - name: REDIS_MASTER_PASSWORD - valueFrom: - secretKeyRef: - name: {{ template "redis.secretName" . }} - key: {{ template "redis.secretPasswordKey" . }} - {{- end }} - {{- else }} - - name: ALLOW_EMPTY_PASSWORD - value: "yes" - {{- end }} - - name: REDIS_TLS_ENABLED - value: {{ ternary "yes" "no" .Values.tls.enabled | quote }} - {{- if .Values.tls.enabled }} - - name: REDIS_TLS_PORT - value: {{ .Values.redisPort | quote }} - - name: REDIS_TLS_AUTH_CLIENTS - value: {{ ternary "yes" "no" .Values.tls.authClients | quote }} - - name: REDIS_TLS_CERT_FILE - value: {{ template "redis.tlsCert" . }} - - name: REDIS_TLS_KEY_FILE - value: {{ template "redis.tlsCertKey" . }} - - name: REDIS_TLS_CA_FILE - value: {{ template "redis.tlsCACert" . }} - {{- if .Values.tls.dhParamsFilename }} - - name: REDIS_TLS_DH_PARAMS_FILE - value: {{ template "redis.tlsDHParams" . }} - {{- end }} - {{- else }} - - name: REDIS_PORT - value: {{ .Values.redisPort | quote }} - {{- end }} - - name: REDIS_DATA_DIR - value: {{ .Values.slave.persistence.path }} - {{- if .Values.sentinel.extraEnvVars }} - {{- include "redis.tplValue" (dict "value" .Values.sentinel.extraEnvVars "context" $) | nindent 12 }} - {{- end }} - {{- if or .Values.sentinel.extraEnvVarsCM .Values.sentinel.extraEnvVarsSecret }} - envFrom: - {{- if .Values.sentinel.extraEnvVarsCM }} - - configMapRef: - name: {{ .Values.sentinel.extraEnvVarsCM }} - {{- end }} - {{- if .Values.sentinel.extraEnvVarsSecret }} - - secretRef: - name: {{ .Values.sentinel.extraEnvVarsSecret }} - {{- end }} - {{- end }} - ports: - - name: redis - containerPort: {{ .Values.redisPort }} - {{- if .Values.slave.livenessProbe.enabled }} - livenessProbe: - initialDelaySeconds: {{ .Values.slave.livenessProbe.initialDelaySeconds }} - periodSeconds: {{ .Values.slave.livenessProbe.periodSeconds }} - timeoutSeconds: {{ .Values.slave.livenessProbe.timeoutSeconds }} - successThreshold: {{ .Values.slave.livenessProbe.successThreshold }} - failureThreshold: {{ .Values.slave.livenessProbe.failureThreshold}} - exec: - command: - - sh - - -c - {{- if .Values.sentinel.enabled }} - - /health/ping_liveness_local.sh {{ .Values.slave.livenessProbe.timeoutSeconds }} - {{- else }} - - /health/ping_liveness_local_and_master.sh {{ .Values.slave.livenessProbe.timeoutSeconds }} - {{- end }} - {{- else if .Values.slave.customLivenessProbe }} - livenessProbe: {{- toYaml .Values.slave.customLivenessProbe | nindent 12 }} - {{- end }} - {{- if .Values.slave.readinessProbe.enabled }} - readinessProbe: - initialDelaySeconds: {{ .Values.slave.readinessProbe.initialDelaySeconds }} - periodSeconds: {{ .Values.slave.readinessProbe.periodSeconds }} - timeoutSeconds: {{ .Values.slave.readinessProbe.timeoutSeconds }} - successThreshold: {{ .Values.slave.readinessProbe.successThreshold }} - failureThreshold: {{ .Values.slave.readinessProbe.failureThreshold }} - exec: - command: - - sh - - -c - {{- if .Values.sentinel.enabled }} - - /health/ping_readiness_local.sh {{ .Values.slave.livenessProbe.timeoutSeconds }} - {{- else }} - - /health/ping_readiness_local_and_master.sh {{ .Values.slave.livenessProbe.timeoutSeconds }} - {{- end }} - {{- else if .Values.slave.customReadinessProbe }} - readinessProbe: {{- toYaml .Values.slave.customReadinessProbe | nindent 12 }} - {{- end }} - resources: {{- toYaml .Values.slave.resources | nindent 12 }} - volumeMounts: - - name: start-scripts - mountPath: /opt/bitnami/scripts/start-scripts - - name: health - mountPath: /health - {{- if .Values.usePasswordFile }} - - name: redis-password - mountPath: /opt/bitnami/redis/secrets/ - {{- end }} - - name: redis-data - mountPath: {{ .Values.slave.persistence.path }} - subPath: {{ .Values.slave.persistence.subPath }} - - name: config - mountPath: /opt/bitnami/redis/mounted-etc - - name: redis-tmp-conf - mountPath: /opt/bitnami/redis/etc - - name: tmp - mountPath: /tmp - {{- if .Values.tls.enabled }} - - name: redis-certificates - mountPath: /opt/bitnami/redis/certs - readOnly: true - {{- end }} - {{- if and .Values.cluster.enabled .Values.sentinel.enabled }} - - name: sentinel - image: {{ template "sentinel.image" . }} - imagePullPolicy: {{ .Values.sentinel.image.pullPolicy | quote }} - {{- if .Values.containerSecurityContext.enabled }} - securityContext: {{- omit .Values.containerSecurityContext "enabled" | toYaml | nindent 12 }} - {{- end }} - command: - - /bin/bash - - -c - - /opt/bitnami/scripts/start-scripts/start-sentinel.sh - env: - {{- if .Values.usePassword }} - {{- if .Values.usePasswordFile }} - - name: REDIS_PASSWORD_FILE - value: "/opt/bitnami/redis/secrets/redis-password" - {{- else }} - - name: REDIS_PASSWORD - valueFrom: - secretKeyRef: - name: {{ template "redis.secretName" . }} - key: {{ template "redis.secretPasswordKey" . }} - {{- end }} - {{- else }} - - name: ALLOW_EMPTY_PASSWORD - value: "yes" - {{- end }} - - name: REDIS_SENTINEL_TLS_ENABLED - value: {{ ternary "yes" "no" .Values.tls.enabled | quote }} - {{- if .Values.tls.enabled }} - - name: REDIS_SENTINEL_TLS_PORT_NUMBER - value: {{ .Values.sentinel.port | quote }} - - name: REDIS_SENTINEL_TLS_AUTH_CLIENTS - value: {{ ternary "yes" "no" .Values.tls.authClients | quote }} - - name: REDIS_SENTINEL_TLS_CERT_FILE - value: {{ template "redis.tlsCert" . }} - - name: REDIS_SENTINEL_TLS_KEY_FILE - value: {{ template "redis.tlsCertKey" . }} - - name: REDIS_SENTINEL_TLS_CA_FILE - value: {{ template "redis.tlsCACert" . }} - {{- if .Values.tls.dhParamsFilename }} - - name: REDIS_SENTINEL_TLS_DH_PARAMS_FILE - value: {{ template "redis.dhParams" . }} - {{- end }} - {{- else }} - - name: REDIS_SENTINEL_PORT - value: {{ .Values.sentinel.port | quote }} - {{- end }} - ports: - - name: redis-sentinel - containerPort: {{ .Values.sentinel.port }} - {{- if .Values.sentinel.livenessProbe.enabled }} - livenessProbe: - initialDelaySeconds: {{ .Values.sentinel.livenessProbe.initialDelaySeconds }} - periodSeconds: {{ .Values.sentinel.livenessProbe.periodSeconds }} - timeoutSeconds: {{ .Values.sentinel.livenessProbe.timeoutSeconds }} - successThreshold: {{ .Values.sentinel.livenessProbe.successThreshold }} - failureThreshold: {{ .Values.sentinel.livenessProbe.failureThreshold }} - exec: - command: - - sh - - -c - - /health/ping_sentinel.sh {{ .Values.sentinel.livenessProbe.timeoutSeconds }} - {{- else if .Values.sentinel.customLivenessProbe }} - livenessProbe: {{- toYaml .Values.sentinel.customLivenessProbe | nindent 12 }} - {{- end }} - {{- if .Values.sentinel.readinessProbe.enabled}} - readinessProbe: - initialDelaySeconds: {{ .Values.sentinel.readinessProbe.initialDelaySeconds }} - periodSeconds: {{ .Values.sentinel.readinessProbe.periodSeconds }} - timeoutSeconds: {{ .Values.sentinel.readinessProbe.timeoutSeconds }} - successThreshold: {{ .Values.sentinel.readinessProbe.successThreshold }} - failureThreshold: {{ .Values.sentinel.readinessProbe.failureThreshold }} - exec: - command: - - sh - - -c - - /health/ping_sentinel.sh {{ .Values.sentinel.livenessProbe.timeoutSeconds }} - {{- else if .Values.sentinel.customReadinessProbe }} - readinessProbe: {{- toYaml .Values.sentinel.customReadinessProbe | nindent 12 }} - {{- end }} - lifecycle: - preStop: - exec: - command: - - /bin/bash - - -c - - /opt/bitnami/scripts/start-scripts/prestop-sentinel.sh - resources: {{- toYaml .Values.sentinel.resources | nindent 12 }} - volumeMounts: - - name: start-scripts - mountPath: /opt/bitnami/scripts/start-scripts - - name: health - mountPath: /health - {{- if .Values.usePasswordFile }} - - name: redis-password - mountPath: /opt/bitnami/redis/secrets/ - {{- end }} - - name: redis-data - mountPath: {{ .Values.slave.persistence.path }} - subPath: {{ .Values.slave.persistence.subPath }} - - name: config - mountPath: /opt/bitnami/redis-sentinel/mounted-etc - - name: sentinel-tmp-conf - mountPath: /opt/bitnami/redis-sentinel/etc - {{- if .Values.tls.enabled }} - - name: redis-certificates - mountPath: /opt/bitnami/redis/certs - readOnly: true - {{- end }} - {{- end }} - {{- if .Values.metrics.enabled }} - - name: metrics - image: {{ template "redis.metrics.image" . }} - imagePullPolicy: {{ .Values.metrics.image.pullPolicy | quote }} - {{- if .Values.containerSecurityContext.enabled }} - securityContext: {{- omit .Values.containerSecurityContext "enabled" | toYaml | nindent 12 }} - {{- end }} - command: - - /bin/bash - - -c - - | - if [[ -f '/secrets/redis-password' ]]; then - export REDIS_PASSWORD=$(cat /secrets/redis-password) - fi - redis_exporter{{- range $key, $value := .Values.metrics.extraArgs }} --{{ $key }}={{ $value }}{{- end }} - env: - - name: REDIS_ALIAS - value: {{ template "redis.fullname" . }} - {{- if and .Values.usePassword (not .Values.usePasswordFile) }} - - name: REDIS_PASSWORD - valueFrom: - secretKeyRef: - name: {{ template "redis.secretName" . }} - key: {{ template "redis.secretPasswordKey" . }} - {{- end }} - {{- if .Values.tls.enabled }} - - name: REDIS_ADDR - value: rediss://localhost:{{ .Values.redisPort }} - - name: REDIS_EXPORTER_TLS_CLIENT_KEY_FILE - value: {{ template "redis.tlsCertKey" . }} - - name: REDIS_EXPORTER_TLS_CLIENT_CERT_FILE - value: {{ template "redis.tlsCert" . }} - - name: REDIS_EXPORTER_TLS_CA_CERT_FILE - value: {{ template "redis.tlsCACert" . }} - {{- end }} - volumeMounts: - {{- if .Values.usePasswordFile }} - - name: redis-password - mountPath: /secrets/ - {{- end }} - {{- if .Values.tls.enabled }} - - name: redis-certificates - mountPath: /opt/bitnami/redis/certs - readOnly: true - {{- end }} - ports: - - name: metrics - containerPort: 9121 - resources: {{- toYaml .Values.metrics.resources | nindent 12 }} - {{- end }} - {{- $needsVolumePermissions := and .Values.volumePermissions.enabled .Values.slave.persistence.enabled .Values.securityContext.enabled .Values.containerSecurityContext.enabled }} - {{- if or $needsVolumePermissions .Values.sysctlImage.enabled }} - initContainers: - {{- if $needsVolumePermissions }} - - name: volume-permissions - image: {{ template "redis.volumePermissions.image" . }} - imagePullPolicy: {{ .Values.volumePermissions.image.pullPolicy | quote }} - command: - - /bin/bash - - -ec - - | - {{- if eq ( toString ( .Values.volumePermissions.securityContext.runAsUser )) "auto" }} - chown -R `id -u`:`id -G | cut -d " " -f2` {{ .Values.slave.persistence.path }} - {{- else }} - chown -R {{ .Values.containerSecurityContext.runAsUser }}:{{ .Values.securityContext.fsGroup }} {{ .Values.slave.persistence.path }} - {{- end }} - {{- if eq ( toString ( .Values.volumePermissions.securityContext.runAsUser )) "auto "}} - securityContext: {{- omit .Values.volumePermissions.securityContext "runAsUser" | toYaml | nindent 12 }} - {{- else }} - securityContext: {{- .Values.volumePermissions.securityContext | toYaml | nindent 12 }} - {{- end }} - resources: {{- toYaml .Values.volumePermissions.resources | nindent 12 }} - volumeMounts: - - name: redis-data - mountPath: {{ .Values.slave.persistence.path }} - subPath: {{ .Values.slave.persistence.subPath }} - {{- end }} - {{- if .Values.sysctlImage.enabled }} - - name: init-sysctl - image: {{ template "redis.sysctl.image" . }} - imagePullPolicy: {{ default "" .Values.sysctlImage.pullPolicy | quote }} - resources: {{- toYaml .Values.sysctlImage.resources | nindent 12 }} - {{- if .Values.sysctlImage.mountHostSys }} - volumeMounts: - - name: host-sys - mountPath: /host-sys - {{- end }} - command: {{- toYaml .Values.sysctlImage.command | nindent 12 }} - securityContext: - privileged: true - runAsUser: 0 - {{- end }} - {{- end }} - volumes: - - name: start-scripts - configMap: - name: {{ include "redis.fullname" . }}-scripts - defaultMode: 0755 - - name: health - configMap: - name: {{ template "redis.fullname" . }}-health - defaultMode: 0755 - {{- if .Values.usePasswordFile }} - - name: redis-password - secret: - secretName: {{ template "redis.secretName" . }} - items: - - key: {{ template "redis.secretPasswordKey" . }} - path: redis-password - {{- end }} - - name: config - configMap: - name: {{ template "redis.fullname" . }} - {{- if .Values.sysctlImage.mountHostSys }} - - name: host-sys - hostPath: - path: /sys - {{- end }} - - name: sentinel-tmp-conf - emptyDir: {} - - name: redis-tmp-conf - emptyDir: {} - - name: tmp - emptyDir: {} - {{- if .Values.tls.enabled }} - - name: redis-certificates - secret: - secretName: {{ required "A secret containing the certificates for the TLS traffic is required when TLS in enabled" .Values.tls.certificatesSecret }} - defaultMode: 256 - {{- end }} - {{- if not .Values.slave.persistence.enabled }} - - name: redis-data - emptyDir: {} - {{- else }} - volumeClaimTemplates: - - metadata: - name: redis-data - labels: - app: {{ template "redis.name" . }} - release: {{ .Release.Name }} - heritage: {{ .Release.Service }} - component: slave - {{- if .Values.slave.statefulset.volumeClaimTemplates }} - {{- if .Values.slave.statefulset.volumeClaimTemplates.labels }} - {{- toYaml .Values.slave.statefulset.volumeClaimTemplates.labels | nindent 10 }} - {{- end }} - {{- if .Values.slave.statefulset.volumeClaimTemplates.annotations }} - annotations: - {{- toYaml .Values.slave.statefulset.volumeClaimTemplates.annotations | nindent 10 }} - {{- end }} - {{- end }} - spec: - accessModes: - {{- range .Values.slave.persistence.accessModes }} - - {{ . | quote }} - {{- end }} - resources: - requests: - storage: {{ .Values.slave.persistence.size | quote }} - {{ include "redis.slave.storageClass" . }} - selector: - {{- if .Values.slave.persistence.matchLabels }} - matchLabels: {{- toYaml .Values.slave.persistence.matchLabels | nindent 12 }} - {{- end -}} - {{- if .Values.slave.persistence.matchExpressions }} - matchExpressions: {{- toYaml .Values.slave.persistence.matchExpressions | nindent 12 }} - {{- end -}} - {{- end }} - updateStrategy: - type: {{ .Values.slave.statefulset.updateStrategy }} - {{- if .Values.slave.statefulset.rollingUpdatePartition }} - {{- if (eq "Recreate" .Values.slave.statefulset.updateStrategy) }} - rollingUpdate: null - {{- else }} - rollingUpdate: - partition: {{ .Values.slave.statefulset.rollingUpdatePartition }} - {{- end }} - {{- end }} -{{- end }} diff --git a/chart/deps/redis/templates/redis-role.yaml b/chart/deps/redis/templates/redis-role.yaml deleted file mode 100644 index 080a7f9..0000000 --- a/chart/deps/redis/templates/redis-role.yaml +++ /dev/null @@ -1,22 +0,0 @@ -{{- if .Values.rbac.create -}} -apiVersion: {{ include "common.capabilities.rbac.apiVersion" . }} -kind: Role -metadata: - name: {{ template "redis.fullname" . }} - namespace: {{ .Release.Namespace | quote }} - labels: - app: {{ template "redis.name" . }} - chart: {{ template "redis.chart" . }} - release: {{ .Release.Name }} - heritage: {{ .Release.Service }} -rules: -{{- if .Values.podSecurityPolicy.create }} - - apiGroups: ['{{ template "podSecurityPolicy.apiGroup" . }}'] - resources: ['podsecuritypolicies'] - verbs: ['use'] - resourceNames: [{{ template "redis.fullname" . }}] -{{- end -}} -{{- if .Values.rbac.role.rules }} -{{- toYaml .Values.rbac.role.rules | nindent 2 }} -{{- end -}} -{{- end -}} diff --git a/chart/deps/redis/templates/redis-rolebinding.yaml b/chart/deps/redis/templates/redis-rolebinding.yaml deleted file mode 100644 index 835aa03..0000000 --- a/chart/deps/redis/templates/redis-rolebinding.yaml +++ /dev/null @@ -1,19 +0,0 @@ -{{- if .Values.rbac.create -}} -apiVersion: {{ include "common.capabilities.rbac.apiVersion" . }} -kind: RoleBinding -metadata: - name: {{ template "redis.fullname" . }} - namespace: {{ .Release.Namespace | quote }} - labels: - app: {{ template "redis.name" . }} - chart: {{ template "redis.chart" . }} - release: {{ .Release.Name }} - heritage: {{ .Release.Service }} -roleRef: - apiGroup: rbac.authorization.k8s.io - kind: Role - name: {{ template "redis.fullname" . }} -subjects: -- kind: ServiceAccount - name: {{ template "redis.serviceAccountName" . }} -{{- end -}} diff --git a/chart/deps/redis/templates/redis-serviceaccount.yaml b/chart/deps/redis/templates/redis-serviceaccount.yaml deleted file mode 100644 index 081691d..0000000 --- a/chart/deps/redis/templates/redis-serviceaccount.yaml +++ /dev/null @@ -1,15 +0,0 @@ -{{- if .Values.serviceAccount.create -}} -apiVersion: v1 -kind: ServiceAccount -metadata: - name: {{ template "redis.serviceAccountName" . }} - namespace: {{ .Release.Namespace | quote }} - labels: - app: {{ template "redis.name" . }} - chart: {{ template "redis.chart" . }} - release: {{ .Release.Name }} - heritage: {{ .Release.Service }} - {{- if .Values.serviceAccount.annotations }} - annotations: {{ toYaml .Values.serviceAccount.annotations | nindent 4 }} - {{- end }} -{{- end -}} diff --git a/chart/deps/redis/templates/redis-slave-statefulset.yaml b/chart/deps/redis/templates/redis-slave-statefulset.yaml deleted file mode 100644 index ef653b0..0000000 --- a/chart/deps/redis/templates/redis-slave-statefulset.yaml +++ /dev/null @@ -1,386 +0,0 @@ -{{- if and .Values.cluster.enabled (not .Values.sentinel.enabled) }} -apiVersion: apps/v1 -kind: StatefulSet -metadata: - name: {{ template "redis.fullname" . }}-slave - namespace: {{ .Release.Namespace | quote }} - labels: - app: {{ template "redis.name" . }} - chart: {{ template "redis.chart" . }} - release: {{ .Release.Name }} - heritage: {{ .Release.Service }} - {{- if .Values.slave.statefulset.labels }} - {{- toYaml .Values.slave.statefulset.labels | nindent 4 }} - {{- end }} -{{- if .Values.slave.statefulset.annotations }} - annotations: - {{- toYaml .Values.slave.statefulset.annotations | nindent 4 }} -{{- end }} -spec: -{{- if .Values.slave.updateStrategy }} - strategy: {{- toYaml .Values.slave.updateStrategy | nindent 4 }} -{{- end }} - replicas: {{ .Values.cluster.slaveCount }} - serviceName: {{ template "redis.fullname" . }}-headless - selector: - matchLabels: - app: {{ template "redis.name" . }} - release: {{ .Release.Name }} - role: slave - template: - metadata: - labels: - app: {{ template "redis.name" . }} - release: {{ .Release.Name }} - chart: {{ template "redis.chart" . }} - role: slave - {{- if .Values.slave.podLabels }} - {{- toYaml .Values.slave.podLabels | nindent 8 }} - {{- end }} - {{- if and .Values.metrics.enabled .Values.metrics.podLabels }} - {{- toYaml .Values.metrics.podLabels | nindent 8 }} - {{- end }} - annotations: - checksum/health: {{ include (print $.Template.BasePath "/health-configmap.yaml") . | sha256sum }} - checksum/configmap: {{ include (print $.Template.BasePath "/configmap.yaml") . | sha256sum }} - checksum/secret: {{ include (print $.Template.BasePath "/secret.yaml") . | sha256sum }} - {{- if .Values.slave.podAnnotations }} - {{- toYaml .Values.slave.podAnnotations | nindent 8 }} - {{- end }} - {{- if and .Values.metrics.enabled .Values.metrics.podAnnotations }} - {{- toYaml .Values.metrics.podAnnotations | nindent 8 }} - {{- end }} - spec: - {{- include "redis.imagePullSecrets" . | nindent 6 }} - {{- if .Values.slave.hostAliases }} - hostAliases: {{- include "common.tplvalues.render" (dict "value" .Values.slave.hostAliases "context" $) | nindent 8 }} - {{- end }} - {{- if .Values.securityContext.enabled }} - securityContext: {{- omit .Values.securityContext "enabled" | toYaml | nindent 8 }} - {{- end }} - serviceAccountName: {{ template "redis.serviceAccountName" . }} - {{- if .Values.slave.priorityClassName }} - priorityClassName: {{ .Values.slave.priorityClassName | quote }} - {{- end }} - {{- if .Values.slave.nodeSelector }} - nodeSelector: {{- toYaml .Values.slave.nodeSelector | nindent 8 }} - {{- end }} - {{- if .Values.slave.tolerations }} - tolerations: {{- toYaml .Values.slave.tolerations | nindent 8 }} - {{- end }} - {{- if .Values.slave.shareProcessNamespace }} - shareProcessNamespace: {{ .Values.slave.shareProcessNamespace }} - {{- end }} - {{- if .Values.slave.schedulerName }} - schedulerName: {{ .Values.slave.schedulerName }} - {{- end }} - {{- if .Values.master.spreadConstraints }} - topologySpreadConstraints: {{- toYaml .Values.master.spreadConstraints | nindent 8 }} - {{- end }} - {{- with .Values.slave.affinity }} - affinity: {{- tpl (toYaml .) $ | nindent 8 }} - {{- end }} - containers: - - name: {{ template "redis.name" . }} - image: {{ template "redis.image" . }} - imagePullPolicy: {{ .Values.image.pullPolicy | quote }} - {{- if .Values.containerSecurityContext.enabled }} - securityContext: {{- omit .Values.containerSecurityContext "enabled" | toYaml | nindent 12 }} - {{- end }} - command: - - /bin/bash - - -c - - /opt/bitnami/scripts/start-scripts/start-slave.sh - env: - - name: REDIS_REPLICATION_MODE - value: slave - - name: REDIS_MASTER_HOST - value: {{ template "redis.fullname" . }}-master-0.{{ template "redis.fullname" . }}-headless.{{ .Release.Namespace }}.svc.{{ .Values.clusterDomain }} - - name: REDIS_MASTER_PORT_NUMBER - value: {{ .Values.redisPort | quote }} - {{- if .Values.usePassword }} - {{- if .Values.usePasswordFile }} - - name: REDIS_PASSWORD_FILE - value: "/opt/bitnami/redis/secrets/redis-password" - - name: REDIS_MASTER_PASSWORD_FILE - value: "/opt/bitnami/redis/secrets/redis-password" - {{- else }} - - name: REDIS_PASSWORD - valueFrom: - secretKeyRef: - name: {{ template "redis.secretName" . }} - key: {{ template "redis.secretPasswordKey" . }} - - name: REDIS_MASTER_PASSWORD - valueFrom: - secretKeyRef: - name: {{ template "redis.secretName" . }} - key: {{ template "redis.secretPasswordKey" . }} - {{- end }} - {{- else }} - - name: ALLOW_EMPTY_PASSWORD - value: "yes" - {{- end }} - - name: REDIS_TLS_ENABLED - value: {{ ternary "yes" "no" .Values.tls.enabled | quote }} - {{- if .Values.tls.enabled }} - - name: REDIS_TLS_PORT - value: {{ .Values.redisPort | quote }} - - name: REDIS_TLS_AUTH_CLIENTS - value: {{ ternary "yes" "no" .Values.tls.authClients | quote }} - - name: REDIS_TLS_CERT_FILE - value: {{ template "redis.tlsCert" . }} - - name: REDIS_TLS_KEY_FILE - value: {{ template "redis.tlsCertKey" . }} - - name: REDIS_TLS_CA_FILE - value: {{ template "redis.tlsCACert" . }} - {{- if .Values.tls.dhParamsFilename }} - - name: REDIS_TLS_DH_PARAMS_FILE - value: {{ template "redis.tlsDHParams" . }} - {{- end }} - {{- else }} - - name: REDIS_PORT - value: {{ .Values.redisPort | quote }} - {{- end }} - {{- if .Values.slave.extraEnvVars }} - {{- include "redis.tplValue" (dict "value" .Values.slave.extraEnvVars "context" $) | nindent 12 }} - {{- end }} - {{- if or .Values.slave.extraEnvVarsCM .Values.slave.extraEnvVarsSecret }} - envFrom: - {{- if .Values.slave.extraEnvVarsCM }} - - configMapRef: - name: {{ .Values.slave.extraEnvVarsCM }} - {{- end }} - {{- if .Values.slave.extraEnvVarsSecret }} - - secretRef: - name: {{ .Values.slave.extraEnvVarsSecret }} - {{- end }} - {{- end }} - ports: - - name: redis - containerPort: {{ .Values.redisPort }} - {{- if .Values.slave.livenessProbe.enabled }} - livenessProbe: - initialDelaySeconds: {{ .Values.slave.livenessProbe.initialDelaySeconds }} - periodSeconds: {{ .Values.slave.livenessProbe.periodSeconds }} - timeoutSeconds: {{ add1 .Values.slave.livenessProbe.timeoutSeconds }} - successThreshold: {{ .Values.slave.livenessProbe.successThreshold }} - failureThreshold: {{ .Values.slave.livenessProbe.failureThreshold}} - exec: - command: - - sh - - -c - - /health/ping_liveness_local_and_master.sh {{ .Values.slave.livenessProbe.timeoutSeconds }} - {{- else if .Values.slave.customLivenessProbe }} - livenessProbe: {{- toYaml .Values.slave.customLivenessProbe | nindent 12 }} - {{- end }} - {{- if .Values.slave.readinessProbe.enabled }} - readinessProbe: - initialDelaySeconds: {{ .Values.slave.readinessProbe.initialDelaySeconds }} - periodSeconds: {{ .Values.slave.readinessProbe.periodSeconds }} - timeoutSeconds: {{ add1 .Values.slave.readinessProbe.timeoutSeconds }} - successThreshold: {{ .Values.slave.readinessProbe.successThreshold }} - failureThreshold: {{ .Values.slave.readinessProbe.failureThreshold }} - exec: - command: - - sh - - -c - - /health/ping_readiness_local_and_master.sh {{ .Values.slave.readinessProbe.timeoutSeconds }} - {{- else if .Values.slave.customReadinessProbe }} - readinessProbe: {{- toYaml .Values.slave.customReadinessProbe | nindent 12 }} - {{- end }} - resources: {{- toYaml .Values.slave.resources | nindent 12 }} - volumeMounts: - - name: start-scripts - mountPath: /opt/bitnami/scripts/start-scripts - - name: health - mountPath: /health - {{- if .Values.usePasswordFile }} - - name: redis-password - mountPath: /opt/bitnami/redis/secrets/ - {{- end }} - - name: redis-data - mountPath: /data - - name: config - mountPath: /opt/bitnami/redis/mounted-etc - - name: redis-tmp-conf - mountPath: /opt/bitnami/redis/etc - {{- if .Values.tls.enabled }} - - name: redis-certificates - mountPath: /opt/bitnami/redis/certs - readOnly: true - {{- end }} - {{- if .Values.metrics.enabled }} - - name: metrics - image: {{ template "redis.metrics.image" . }} - imagePullPolicy: {{ .Values.metrics.image.pullPolicy | quote }} - {{- if .Values.containerSecurityContext.enabled }} - securityContext: {{- omit .Values.containerSecurityContext "enabled" | toYaml | nindent 12 }} - {{- end }} - command: - - /bin/bash - - -c - - | - if [[ -f '/secrets/redis-password' ]]; then - export REDIS_PASSWORD=$(cat /secrets/redis-password) - fi - redis_exporter{{- range $key, $value := .Values.metrics.extraArgs }} --{{ $key }}={{ $value }}{{- end }} - env: - - name: REDIS_ALIAS - value: {{ template "redis.fullname" . }} - {{- if and .Values.usePassword (not .Values.usePasswordFile) }} - - name: REDIS_PASSWORD - valueFrom: - secretKeyRef: - name: {{ template "redis.secretName" . }} - key: {{ template "redis.secretPasswordKey" . }} - {{- end }} - {{- if .Values.tls.enabled }} - - name: REDIS_ADDR - value: rediss://localhost:{{ .Values.redisPort }} - - name: REDIS_EXPORTER_TLS_CLIENT_KEY_FILE - value: {{ template "redis.tlsCertKey" . }} - - name: REDIS_EXPORTER_TLS_CLIENT_CERT_FILE - value: {{ template "redis.tlsCert" . }} - - name: REDIS_EXPORTER_TLS_CA_CERT_FILE - value: {{ template "redis.tlsCACert" . }} - {{- end }} - volumeMounts: - {{- if .Values.usePasswordFile }} - - name: redis-password - mountPath: /secrets/ - {{- end }} - {{- if .Values.tls.enabled }} - - name: redis-certificates - mountPath: /opt/bitnami/redis/certs - readOnly: true - {{- end }} - ports: - - name: metrics - containerPort: 9121 - resources: {{- toYaml .Values.metrics.resources | nindent 12 }} - {{- end }} - {{- $needsVolumePermissions := and .Values.volumePermissions.enabled .Values.slave.persistence.enabled .Values.securityContext.enabled .Values.containerSecurityContext.enabled }} - {{- if or $needsVolumePermissions .Values.sysctlImage.enabled }} - initContainers: - {{- if $needsVolumePermissions }} - - name: volume-permissions - image: {{ template "redis.volumePermissions.image" . }} - imagePullPolicy: {{ .Values.volumePermissions.image.pullPolicy | quote }} - command: - - /bin/bash - - -ec - - | - {{- if eq ( toString ( .Values.volumePermissions.securityContext.runAsUser )) "auto" }} - chown -R `id -u`:`id -G | cut -d " " -f2` {{ .Values.slave.persistence.path }} - {{- else }} - chown -R {{ .Values.containerSecurityContext.runAsUser }}:{{ .Values.securityContext.fsGroup }} {{ .Values.slave.persistence.path }} - {{- end }} - {{- if eq ( toString ( .Values.volumePermissions.securityContext.runAsUser )) "auto "}} - securityContext: {{- omit .Values.volumePermissions.securityContext "runAsUser" | toYaml | nindent 12 }} - {{- else }} - securityContext: {{- .Values.volumePermissions.securityContext | toYaml | nindent 12 }} - {{- end }} - resources: {{- toYaml .Values.volumePermissions.resources | nindent 12 }} - volumeMounts: - - name: redis-data - mountPath: {{ .Values.slave.persistence.path }} - subPath: {{ .Values.slave.persistence.subPath }} - {{- end }} - {{- if .Values.sysctlImage.enabled }} - - name: init-sysctl - image: {{ template "redis.sysctl.image" . }} - imagePullPolicy: {{ default "" .Values.sysctlImage.pullPolicy | quote }} - resources: {{- toYaml .Values.sysctlImage.resources | nindent 12 }} - {{- if .Values.sysctlImage.mountHostSys }} - volumeMounts: - - name: host-sys - mountPath: /host-sys - {{- end }} - command: {{- toYaml .Values.sysctlImage.command | nindent 12 }} - securityContext: - privileged: true - runAsUser: 0 - {{- end }} - {{- end }} - volumes: - - name: start-scripts - configMap: - name: {{ include "redis.fullname" . }}-scripts - defaultMode: 0755 - - name: health - configMap: - name: {{ template "redis.fullname" . }}-health - defaultMode: 0755 - {{- if .Values.usePasswordFile }} - - name: redis-password - secret: - secretName: {{ template "redis.secretName" . }} - items: - - key: {{ template "redis.secretPasswordKey" . }} - path: redis-password - {{- end }} - - name: config - configMap: - name: {{ template "redis.fullname" . }} - {{- if .Values.sysctlImage.mountHostSys }} - - name: host-sys - hostPath: - path: /sys - {{- end }} - - name: redis-tmp-conf - emptyDir: {} - {{- if .Values.tls.enabled }} - - name: redis-certificates - secret: - secretName: {{ required "A secret containing the certificates for the TLS traffic is required when TLS in enabled" .Values.tls.certificatesSecret }} - defaultMode: 256 - {{- end }} - {{- if not .Values.slave.persistence.enabled }} - - name: redis-data - emptyDir: {} - {{- else }} - volumeClaimTemplates: - - metadata: - name: redis-data - labels: - app: {{ template "redis.name" . }} - release: {{ .Release.Name }} - heritage: {{ .Release.Service }} - component: slave - {{- if .Values.slave.statefulset.volumeClaimTemplates }} - {{- if .Values.slave.statefulset.volumeClaimTemplates.labels }} - {{- toYaml .Values.slave.statefulset.volumeClaimTemplates.labels | nindent 10 }} - {{- end }} - {{- if .Values.slave.statefulset.volumeClaimTemplates.annotations }} - annotations: - {{- toYaml .Values.slave.statefulset.volumeClaimTemplates.annotations | nindent 10 }} - {{- end }} - {{- end }} - spec: - accessModes: - {{- range .Values.slave.persistence.accessModes }} - - {{ . | quote }} - {{- end }} - resources: - requests: - storage: {{ .Values.slave.persistence.size | quote }} - {{ include "redis.slave.storageClass" . }} - selector: - {{- if .Values.slave.persistence.matchLabels }} - matchLabels: {{- toYaml .Values.slave.persistence.matchLabels | nindent 12 }} - {{- end -}} - {{- if .Values.slave.persistence.matchExpressions }} - matchExpressions: {{- toYaml .Values.slave.persistence.matchExpressions | nindent 12 }} - {{- end -}} - {{- end }} - updateStrategy: - type: {{ .Values.slave.statefulset.updateStrategy }} - {{- if .Values.slave.statefulset.rollingUpdatePartition }} - {{- if (eq "Recreate" .Values.slave.statefulset.updateStrategy) }} - rollingUpdate: null - {{- else }} - rollingUpdate: - partition: {{ .Values.slave.statefulset.rollingUpdatePartition }} - {{- end }} - {{- end }} -{{- end }} diff --git a/chart/deps/redis/templates/redis-slave-svc.yaml b/chart/deps/redis/templates/redis-slave-svc.yaml deleted file mode 100644 index a67ebb0..0000000 --- a/chart/deps/redis/templates/redis-slave-svc.yaml +++ /dev/null @@ -1,43 +0,0 @@ -{{- if and .Values.cluster.enabled (not .Values.sentinel.enabled) }} -apiVersion: v1 -kind: Service -metadata: - name: {{ template "redis.fullname" . }}-slave - namespace: {{ .Release.Namespace | quote }} - labels: - app: {{ template "redis.name" . }} - chart: {{ template "redis.chart" . }} - release: {{ .Release.Name }} - heritage: {{ .Release.Service }} - {{- if .Values.slave.service.labels -}} - {{- toYaml .Values.slave.service.labels | nindent 4 }} - {{- end -}} -{{- if .Values.slave.service.annotations }} - annotations: {{- toYaml .Values.slave.service.annotations | nindent 4 }} -{{- end }} -spec: - type: {{ .Values.slave.service.type }} - {{ if eq .Values.slave.service.type "LoadBalancer" }} - externalTrafficPolicy: {{ .Values.slave.service.externalTrafficPolicy }} - {{- end }} - {{- if and (eq .Values.slave.service.type "LoadBalancer") .Values.slave.service.loadBalancerIP }} - loadBalancerIP: {{ .Values.slave.service.loadBalancerIP }} - {{- end }} - {{- if and (eq .Values.slave.service.type "LoadBalancer") .Values.slave.service.loadBalancerSourceRanges }} - loadBalancerSourceRanges: - {{- with .Values.slave.service.loadBalancerSourceRanges }} - {{- toYaml . | nindent 4 }} - {{- end }} - {{- end }} - ports: - - name: tcp-redis - port: {{ .Values.slave.service.port }} - targetPort: redis - {{- if .Values.slave.service.nodePort }} - nodePort: {{ .Values.slave.service.nodePort }} - {{- end }} - selector: - app: {{ template "redis.name" . }} - release: {{ .Release.Name }} - role: slave -{{- end }} diff --git a/chart/deps/redis/templates/redis-with-sentinel-svc.yaml b/chart/deps/redis/templates/redis-with-sentinel-svc.yaml deleted file mode 100644 index e1c9073..0000000 --- a/chart/deps/redis/templates/redis-with-sentinel-svc.yaml +++ /dev/null @@ -1,43 +0,0 @@ -{{- if .Values.sentinel.enabled }} -apiVersion: v1 -kind: Service -metadata: - name: {{ template "redis.fullname" . }} - namespace: {{ .Release.Namespace | quote }} - labels: - app: {{ template "redis.name" . }} - chart: {{ template "redis.chart" . }} - release: {{ .Release.Name }} - heritage: {{ .Release.Service }} - {{- if .Values.sentinel.service.labels }} - {{- toYaml .Values.sentinel.service.labels | nindent 4 }} - {{- end }} -{{- if .Values.sentinel.service.annotations }} - annotations: {{- toYaml .Values.sentinel.service.annotations | nindent 4 }} -{{- end }} -spec: - type: {{ .Values.sentinel.service.type }} - {{ if eq .Values.sentinel.service.type "LoadBalancer" }} - externalTrafficPolicy: {{ .Values.sentinel.service.externalTrafficPolicy }} - {{- end }} - {{ if eq .Values.sentinel.service.type "LoadBalancer" -}} {{ if .Values.sentinel.service.loadBalancerIP }} - loadBalancerIP: {{ .Values.sentinel.service.loadBalancerIP }} - {{ end -}} - {{- end -}} - ports: - - name: tcp-redis - port: {{ .Values.sentinel.service.redisPort }} - targetPort: redis - {{- if .Values.sentinel.service.redisNodePort }} - nodePort: {{ .Values.sentinel.service.redisNodePort }} - {{- end }} - - name: tcp-sentinel - port: {{ .Values.sentinel.service.sentinelPort }} - targetPort: redis-sentinel - {{- if .Values.sentinel.service.sentinelNodePort }} - nodePort: {{ .Values.sentinel.service.sentinelNodePort }} - {{- end }} - selector: - app: {{ template "redis.name" . }} - release: {{ .Release.Name }} -{{- end }} diff --git a/chart/deps/redis/templates/replicas/service.yaml b/chart/deps/redis/templates/replicas/service.yaml new file mode 100644 index 0000000..fd9c617 --- /dev/null +++ b/chart/deps/redis/templates/replicas/service.yaml @@ -0,0 +1,46 @@ +{{- if and (eq .Values.architecture "replication") (not .Values.sentinel.enabled) }} +apiVersion: v1 +kind: Service +metadata: + name: {{ printf "%s-replicas" (include "common.names.fullname" .) }} + namespace: {{ .Release.Namespace | quote }} + labels: {{- include "common.labels.standard" . | nindent 4 }} + app.kubernetes.io/component: replica + {{- if .Values.commonLabels }} + {{- include "common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }} + {{- end }} + {{- if or .Values.replica.service.annotations .Values.commonAnnotations }} + annotations: + {{- if .Values.replica.service.annotations }} + {{- include "common.tplvalues.render" ( dict "value" .Values.replica.service.annotations "context" $ ) | nindent 4 }} + {{- end }} + {{- if .Values.commonAnnotations }} + {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }} + {{- end }} + {{- end }} +spec: + type: {{ .Values.replica.service.type }} + {{- if eq .Values.replica.service.type "LoadBalancer" }} + externalTrafficPolicy: {{ .Values.replica.service.externalTrafficPolicy }} + {{- end }} + {{- if and (eq .Values.replica.service.type "LoadBalancer") .Values.replica.service.loadBalancerIP }} + loadBalancerIP: {{ .Values.replica.service.loadBalancerIP }} + {{- end }} + {{- if and (eq .Values.replica.service.type "LoadBalancer") .Values.replica.service.loadBalancerSourceRanges }} + loadBalancerSourceRanges: {{- toYaml .Values.replica.service.loadBalancerSourceRanges | nindent 4 }} + {{- end }} + {{- if and (eq .Values.replica.service.type "ClusterIP") .Values.replica.service.clusterIP }} + clusterIP: {{ .Values.replica.service.clusterIP }} + {{- end }} + ports: + - name: tcp-redis + port: {{ .Values.replica.service.port }} + targetPort: redis + {{- if and (or (eq .Values.replica.service.type "NodePort") (eq .Values.replica.service.type "LoadBalancer")) .Values.replica.service.nodePort }} + nodePort: {{ .Values.replica.service.nodePort }} + {{- else if eq .Values.replica.service.type "ClusterIP" }} + nodePort: null + {{- end }} + selector: {{- include "common.labels.matchLabels" . | nindent 4 }} + app.kubernetes.io/component: replica +{{- end }} diff --git a/chart/deps/redis/templates/replicas/statefulset.yaml b/chart/deps/redis/templates/replicas/statefulset.yaml new file mode 100644 index 0000000..4fd3029 --- /dev/null +++ b/chart/deps/redis/templates/replicas/statefulset.yaml @@ -0,0 +1,405 @@ +{{- if and (eq .Values.architecture "replication") (not .Values.sentinel.enabled) }} +apiVersion: {{ include "common.capabilities.statefulset.apiVersion" . }} +kind: StatefulSet +metadata: + name: {{ printf "%s-replicas" (include "common.names.fullname" .) }} + namespace: {{ .Release.Namespace | quote }} + labels: {{- include "common.labels.standard" . | nindent 4 }} + app.kubernetes.io/component: replica + {{- if .Values.commonLabels }} + {{- include "common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }} + {{- end }} + {{- if .Values.commonAnnotations }} + annotations: {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }} + {{- end }} +spec: + replicas: {{ .Values.replica.replicaCount }} + selector: + matchLabels: {{- include "common.labels.matchLabels" . | nindent 6 }} + app.kubernetes.io/component: replica + serviceName: {{ printf "%s-headless" (include "common.names.fullname" .) }} + {{- if .Values.replica.updateStrategy }} + updateStrategy: {{- toYaml .Values.replica.updateStrategy | nindent 4 }} + {{- end }} + template: + metadata: + labels: {{- include "common.labels.standard" . | nindent 8 }} + app.kubernetes.io/component: replica + {{- if .Values.replica.podLabels }} + {{- include "common.tplvalues.render" ( dict "value" .Values.replica.podLabels "context" $ ) | nindent 8 }} + {{- end }} + {{- if and .Values.metrics.enabled .Values.metrics.podLabels }} + {{- include "common.tplvalues.render" ( dict "value" .Values.metrics.podLabels "context" $ ) | nindent 8 }} + {{- end }} + annotations: + {{- if (include "redis.createConfigmap" .) }} + checksum/configmap: {{ include (print $.Template.BasePath "/configmap.yaml") . | sha256sum }} + {{- end }} + checksum/health: {{ include (print $.Template.BasePath "/health-configmap.yaml") . | sha256sum }} + checksum/scripts: {{ include (print $.Template.BasePath "/scripts-configmap.yaml") . | sha256sum }} + checksum/secret: {{ include (print $.Template.BasePath "/secret.yaml") . | sha256sum }} + {{- if .Values.replica.podAnnotations }} + {{- include "common.tplvalues.render" ( dict "value" .Values.replica.podAnnotations "context" $ ) | nindent 8 }} + {{- end }} + {{- if and .Values.metrics.enabled .Values.metrics.podAnnotations }} + {{- include "common.tplvalues.render" ( dict "value" .Values.metrics.podAnnotations "context" $ ) | nindent 8 }} + {{- end }} + spec: + {{- include "redis.imagePullSecrets" . | nindent 6 }} + {{- if .Values.replica.hostAliases }} + hostAliases: {{- include "common.tplvalues.render" (dict "value" .Values.replica.hostAliases "context" $) | nindent 8 }} + {{- end }} + {{- if .Values.replica.podSecurityContext.enabled }} + securityContext: {{- omit .Values.replica.podSecurityContext "enabled" | toYaml | nindent 8 }} + {{- end }} + serviceAccountName: {{ template "redis.serviceAccountName" . }} + {{- if .Values.replica.priorityClassName }} + priorityClassName: {{ .Values.replica.priorityClassName | quote }} + {{- end }} + {{- if .Values.replica.affinity }} + affinity: {{- include "common.tplvalues.render" (dict "value" .Values.replica.affinity "context" $) | nindent 8 }} + {{- else }} + affinity: + podAffinity: {{- include "common.affinities.pods" (dict "type" .Values.replica.podAffinityPreset "component" "replica" "context" $) | nindent 10 }} + podAntiAffinity: {{- include "common.affinities.pods" (dict "type" .Values.replica.podAntiAffinityPreset "component" "replica" "context" $) | nindent 10 }} + nodeAffinity: {{- include "common.affinities.nodes" (dict "type" .Values.replica.nodeAffinityPreset.type "key" .Values.replica.nodeAffinityPreset.key "values" .Values.replica.nodeAffinityPreset.values) | nindent 10 }} + {{- end }} + {{- if .Values.replica.nodeSelector }} + nodeSelector: {{- include "common.tplvalues.render" (dict "value" .Values.replica.nodeSelector "context" $) | nindent 8 }} + {{- end }} + {{- if .Values.replica.tolerations }} + tolerations: {{- include "common.tplvalues.render" (dict "value" .Values.replica.tolerations "context" $) | nindent 8 }} + {{- end }} + {{- if .Values.replica.spreadConstraints }} + topologySpreadConstraints: {{- include "common.tplvalues.render" (dict "value" .Values.replica.spreadConstraints "context" $) | nindent 8 }} + {{- end }} + {{- if .Values.replica.shareProcessNamespace }} + shareProcessNamespace: {{ .Values.replica.shareProcessNamespace }} + {{- end }} + {{- if .Values.replica.schedulerName }} + schedulerName: {{ .Values.replica.schedulerName | quote }} + {{- end }} + terminationGracePeriodSeconds: {{ .Values.replica.terminationGracePeriodSeconds }} + containers: + - name: redis + image: {{ template "redis.image" . }} + imagePullPolicy: {{ .Values.image.pullPolicy | quote }} + {{- if .Values.replica.lifecycleHooks }} + lifecycle: {{- include "common.tplvalues.render" (dict "value" .Values.replica.lifecycleHooks "context" $) | nindent 12 }} + {{- end }} + {{- if .Values.replica.containerSecurityContext.enabled }} + securityContext: {{- omit .Values.replica.containerSecurityContext "enabled" | toYaml | nindent 12 }} + {{- end }} + {{- if .Values.replica.command }} + command: {{- include "common.tplvalues.render" (dict "value" .Values.replica.command "context" $) | nindent 12 }} + {{- else }} + command: + - /bin/bash + {{- end }} + {{- if .Values.replica.args }} + args: {{- include "common.tplvalues.render" (dict "value" .Values.replica.args "context" $) | nindent 12 }} + {{- else }} + args: + - -c + - /opt/bitnami/scripts/start-scripts/start-replica.sh + {{- end }} + env: + - name: BITNAMI_DEBUG + value: {{ ternary "true" "false" .Values.image.debug | quote }} + - name: REDIS_REPLICATION_MODE + value: slave + - name: REDIS_MASTER_HOST + value: {{ template "common.names.fullname" . }}-master-0.{{ template "common.names.fullname" . }}-headless.{{ .Release.Namespace }}.svc.{{ .Values.clusterDomain }} + - name: REDIS_MASTER_PORT_NUMBER + value: {{ .Values.master.service.port | quote }} + - name: ALLOW_EMPTY_PASSWORD + value: {{ ternary "no" "yes" .Values.auth.enabled | quote }} + {{- if .Values.auth.enabled }} + {{- if .Values.auth.usePasswordFiles }} + - name: REDIS_PASSWORD_FILE + value: "/opt/bitnami/redis/secrets/redis-password" + - name: REDIS_MASTER_PASSWORD_FILE + value: "/opt/bitnami/redis/secrets/redis-password" + {{- else }} + - name: REDIS_PASSWORD + valueFrom: + secretKeyRef: + name: {{ template "redis.secretName" . }} + key: {{ template "redis.secretPasswordKey" . }} + - name: REDIS_MASTER_PASSWORD + valueFrom: + secretKeyRef: + name: {{ template "redis.secretName" . }} + key: {{ template "redis.secretPasswordKey" . }} + {{- end }} + {{- end }} + - name: REDIS_TLS_ENABLED + value: {{ ternary "yes" "no" .Values.tls.enabled | quote }} + {{- if .Values.tls.enabled }} + - name: REDIS_TLS_PORT + value: {{ .Values.replica.containerPort | quote }} + - name: REDIS_TLS_AUTH_CLIENTS + value: {{ ternary "yes" "no" .Values.tls.authClients | quote }} + - name: REDIS_TLS_CERT_FILE + value: {{ template "redis.tlsCert" . }} + - name: REDIS_TLS_KEY_FILE + value: {{ template "redis.tlsCertKey" . }} + - name: REDIS_TLS_CA_FILE + value: {{ template "redis.tlsCACert" . }} + {{- if .Values.tls.dhParamsFilename }} + - name: REDIS_TLS_DH_PARAMS_FILE + value: {{ template "redis.tlsDHParams" . }} + {{- end }} + {{- else }} + - name: REDIS_PORT + value: {{ .Values.replica.containerPort | quote }} + {{- end }} + {{- if .Values.replica.extraEnvVars }} + {{- include "common.tplvalues.render" (dict "value" .Values.replica.extraEnvVars "context" $) | nindent 12 }} + {{- end }} + {{- if or .Values.replica.extraEnvVarsCM .Values.replica.extraEnvVarsSecret }} + envFrom: + {{- if .Values.replica.extraEnvVarsCM }} + - configMapRef: + name: {{ .Values.replica.extraEnvVarsCM }} + {{- end }} + {{- if .Values.replica.extraEnvVarsSecret }} + - secretRef: + name: {{ .Values.replica.extraEnvVarsSecret }} + {{- end }} + {{- end }} + ports: + - name: redis + containerPort: {{ .Values.replica.containerPort }} + {{- if .Values.replica.livenessProbe.enabled }} + livenessProbe: + initialDelaySeconds: {{ .Values.replica.livenessProbe.initialDelaySeconds }} + periodSeconds: {{ .Values.replica.livenessProbe.periodSeconds }} + timeoutSeconds: {{ add1 .Values.replica.livenessProbe.timeoutSeconds }} + successThreshold: {{ .Values.replica.livenessProbe.successThreshold }} + failureThreshold: {{ .Values.replica.livenessProbe.failureThreshold}} + exec: + command: + - sh + - -c + - /health/ping_liveness_local_and_master.sh {{ .Values.replica.livenessProbe.timeoutSeconds }} + {{- else if .Values.replica.customLivenessProbe }} + livenessProbe: {{- toYaml .Values.replica.customLivenessProbe | nindent 12 }} + {{- end }} + {{- if .Values.replica.readinessProbe.enabled }} + readinessProbe: + initialDelaySeconds: {{ .Values.replica.readinessProbe.initialDelaySeconds }} + periodSeconds: {{ .Values.replica.readinessProbe.periodSeconds }} + timeoutSeconds: {{ add1 .Values.replica.readinessProbe.timeoutSeconds }} + successThreshold: {{ .Values.replica.readinessProbe.successThreshold }} + failureThreshold: {{ .Values.replica.readinessProbe.failureThreshold }} + exec: + command: + - sh + - -c + - /health/ping_readiness_local_and_master.sh {{ .Values.replica.readinessProbe.timeoutSeconds }} + {{- else if .Values.replica.customReadinessProbe }} + readinessProbe: {{- toYaml .Values.replica.customReadinessProbe | nindent 12 }} + {{- end }} + {{- if .Values.replica.resources }} + resources: {{- toYaml .Values.replica.resources | nindent 12 }} + {{- end }} + volumeMounts: + - name: start-scripts + mountPath: /opt/bitnami/scripts/start-scripts + - name: health + mountPath: /health + {{- if .Values.auth.usePasswordFiles }} + - name: redis-password + mountPath: /opt/bitnami/redis/secrets/ + {{- end }} + - name: redis-data + mountPath: /data + subPath: {{ .Values.replica.persistence.subPath }} + - name: config + mountPath: /opt/bitnami/redis/mounted-etc + - name: redis-tmp-conf + mountPath: /opt/bitnami/redis/etc + {{- if .Values.tls.enabled }} + - name: redis-certificates + mountPath: /opt/bitnami/redis/certs + readOnly: true + {{- end }} + {{- if .Values.replica.extraVolumeMounts }} + {{- include "common.tplvalues.render" ( dict "value" .Values.replica.extraVolumeMounts "context" $ ) | nindent 12 }} + {{- end }} + {{- if .Values.metrics.enabled }} + - name: metrics + image: {{ include "redis.metrics.image" . }} + imagePullPolicy: {{ .Values.metrics.image.pullPolicy | quote }} + {{- if .Values.metrics.containerSecurityContext.enabled }} + securityContext: {{- omit .Values.metrics.containerSecurityContext "enabled" | toYaml | nindent 12 }} + {{- end }} + command: + - /bin/bash + - -c + - | + if [[ -f '/secrets/redis-password' ]]; then + export REDIS_PASSWORD=$(cat /secrets/redis-password) + fi + redis_exporter{{- range $key, $value := .Values.metrics.extraArgs }} --{{ $key }}={{ $value }}{{- end }} + env: + - name: REDIS_ALIAS + value: {{ template "common.names.fullname" . }} + {{- if .Values.auth.enabled }} + - name: REDIS_USER + value: default + {{- if (not .Values.auth.usePasswordFiles) }} + - name: REDIS_PASSWORD + valueFrom: + secretKeyRef: + name: {{ template "redis.secretName" . }} + key: {{ template "redis.secretPasswordKey" . }} + {{- end }} + {{- end }} + {{- if .Values.tls.enabled }} + - name: REDIS_ADDR + value: rediss://{{ .Values.metrics.redisTargetHost }}:{{ .Values.replica.containerPort }} + {{- if .Values.tls.authClients }} + - name: REDIS_EXPORTER_TLS_CLIENT_KEY_FILE + value: {{ template "redis.tlsCertKey" . }} + - name: REDIS_EXPORTER_TLS_CLIENT_CERT_FILE + value: {{ template "redis.tlsCert" . }} + {{- end }} + - name: REDIS_EXPORTER_TLS_CA_CERT_FILE + value: {{ template "redis.tlsCACert" . }} + {{- end }} + ports: + - name: metrics + containerPort: 9121 + {{- if .Values.metrics.resources }} + resources: {{- toYaml .Values.metrics.resources | nindent 12 }} + {{- end }} + volumeMounts: + {{- if .Values.auth.usePasswordFiles }} + - name: redis-password + mountPath: /secrets/ + {{- end }} + {{- if .Values.tls.enabled }} + - name: redis-certificates + mountPath: /opt/bitnami/redis/certs + readOnly: true + {{- end }} + {{- end }} + {{- if .Values.replica.sidecars }} + {{- include "common.tplvalues.render" (dict "value" .Values.replica.sidecars "context" $) | nindent 8 }} + {{- end }} + {{- $needsVolumePermissions := and .Values.volumePermissions.enabled .Values.replica.persistence.enabled .Values.replica.podSecurityContext.enabled .Values.replica.containerSecurityContext.enabled }} + {{- if or .Values.replica.initContainers $needsVolumePermissions .Values.sysctl.enabled }} + initContainers: + {{- if .Values.replica.initContainers }} + {{- include "common.tplvalues.render" (dict "value" .Values.replica.initContainers "context" $) | nindent 8 }} + {{- end }} + {{- if $needsVolumePermissions }} + - name: volume-permissions + image: {{ include "redis.volumePermissions.image" . }} + imagePullPolicy: {{ .Values.volumePermissions.image.pullPolicy | quote }} + command: + - /bin/bash + - -ec + - | + {{- if eq ( toString ( .Values.volumePermissions.containerSecurityContext.runAsUser )) "auto" }} + chown -R `id -u`:`id -G | cut -d " " -f2` {{ .Values.replica.persistence.path }} + {{- else }} + chown -R {{ .Values.replica.containerSecurityContext.runAsUser }}:{{ .Values.replica.podSecurityContext.fsGroup }} {{ .Values.replica.persistence.path }} + {{- end }} + {{- if eq ( toString ( .Values.volumePermissions.containerSecurityContext.runAsUser )) "auto" }} + securityContext: {{- omit .Values.volumePermissions.containerSecurityContext "runAsUser" | toYaml | nindent 12 }} + {{- else }} + securityContext: {{- .Values.volumePermissions.containerSecurityContext | toYaml | nindent 12 }} + {{- end }} + {{- if .Values.volumePermissions.resources }} + resources: {{- toYaml .Values.volumePermissions.resources | nindent 12 }} + {{- end }} + volumeMounts: + - name: redis-data + mountPath: {{ .Values.replica.persistence.path }} + subPath: {{ .Values.replica.persistence.subPath }} + {{- end }} + {{- if .Values.sysctl.enabled }} + - name: init-sysctl + image: {{ include "redis.sysctl.image" . }} + imagePullPolicy: {{ default "" .Values.sysctl.image.pullPolicy | quote }} + securityContext: + privileged: true + runAsUser: 0 + {{- if .Values.sysctl.command }} + command: {{- include "common.tplvalues.render" (dict "value" .Values.sysctl.command "context" $) | nindent 12 }} + {{- end }} + {{- if .Values.sysctl.resources }} + resources: {{- toYaml .Values.sysctl.resources | nindent 12 }} + {{- end }} + {{- if .Values.sysctl.mountHostSys }} + volumeMounts: + - name: host-sys + mountPath: /host-sys + {{- end }} + {{- end }} + {{- end }} + volumes: + - name: start-scripts + configMap: + name: {{ printf "%s-scripts" (include "common.names.fullname" .) }} + defaultMode: 0755 + - name: health + configMap: + name: {{ printf "%s-health" (include "common.names.fullname" .) }} + defaultMode: 0755 + {{- if .Values.auth.usePasswordFiles }} + - name: redis-password + secret: + secretName: {{ template "redis.secretName" . }} + items: + - key: {{ template "redis.secretPasswordKey" . }} + path: redis-password + {{- end }} + - name: config + configMap: + name: {{ include "redis.configmapName" . }} + {{- if .Values.sysctl.mountHostSys }} + - name: host-sys + hostPath: + path: /sys + {{- end }} + - name: redis-tmp-conf + emptyDir: {} + {{- if .Values.tls.enabled }} + - name: redis-certificates + secret: + secretName: {{ required "A secret containing the certificates for the TLS traffic is required when TLS in enabled" .Values.tls.certificatesSecret }} + defaultMode: 256 + {{- end }} + {{- if .Values.replica.extraVolumes }} + {{- include "common.tplvalues.render" ( dict "value" .Values.replica.extraVolumes "context" $ ) | nindent 8 }} + {{- end }} + {{- if not .Values.replica.persistence.enabled }} + - name: redis-data + emptyDir: {} + {{- else }} + volumeClaimTemplates: + - metadata: + name: redis-data + labels: {{- include "common.labels.matchLabels" . | nindent 10 }} + app.kubernetes.io/component: replica + {{- if .Values.replica.persistence.annotations }} + annotations: {{- toYaml .Values.replica.persistence.annotations | nindent 10 }} + {{- end }} + spec: + accessModes: + {{- range .Values.replica.persistence.accessModes }} + - {{ . | quote }} + {{- end }} + resources: + requests: + storage: {{ .Values.replica.persistence.size | quote }} + {{- if .Values.replica.persistence.selector }} + selector: {{- include "common.tplvalues.render" (dict "value" .Values.replica.persistence.selector "context" $) | nindent 10 }} + {{- end }} + {{- include "common.storage.class" (dict "persistence" .Values.replica.persistence "global" .Values.global) | nindent 8 }} + {{- end }} +{{- end }} diff --git a/chart/deps/redis/templates/role.yaml b/chart/deps/redis/templates/role.yaml new file mode 100644 index 0000000..dc61b44 --- /dev/null +++ b/chart/deps/redis/templates/role.yaml @@ -0,0 +1,27 @@ +{{- if .Values.rbac.create }} +apiVersion: {{ include "common.capabilities.rbac.apiVersion" . }} +kind: Role +metadata: + name: {{ template "common.names.fullname" . }} + namespace: {{ .Release.Namespace | quote }} + labels: {{- include "common.labels.standard" . | nindent 4 }} + {{- if .Values.commonLabels }} + {{- include "common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }} + {{- end }} + {{- if .Values.commonAnnotations }} + annotations: {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }} + {{- end }} +rules: + {{- if .Values.podSecurityPolicy.create }} + - apiGroups: + - '{{ template "podSecurityPolicy.apiGroup" . }}' + resources: + - 'podsecuritypolicies' + verbs: + - 'use' + resourceNames: [{{ template "common.names.fullname" . }}] + {{- end }} + {{- if .Values.rbac.rules }} + {{- include "common.tplvalues.render" ( dict "value" .Values.rbac.rules "context" $ ) | nindent 2 }} + {{- end }} +{{- end }} diff --git a/chart/deps/redis/templates/rolebinding.yaml b/chart/deps/redis/templates/rolebinding.yaml new file mode 100644 index 0000000..74968b8 --- /dev/null +++ b/chart/deps/redis/templates/rolebinding.yaml @@ -0,0 +1,21 @@ +{{- if .Values.rbac.create }} +apiVersion: {{ include "common.capabilities.rbac.apiVersion" . }} +kind: RoleBinding +metadata: + name: {{ template "common.names.fullname" . }} + namespace: {{ .Release.Namespace | quote }} + labels: {{- include "common.labels.standard" . | nindent 4 }} + {{- if .Values.commonLabels }} + {{- include "common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }} + {{- end }} + {{- if .Values.commonAnnotations }} + annotations: {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }} + {{- end }} +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: Role + name: {{ template "common.names.fullname" . }} +subjects: + - kind: ServiceAccount + name: {{ template "redis.serviceAccountName" . }} +{{- end }} diff --git a/chart/deps/redis/templates/scripts-configmap.yaml b/chart/deps/redis/templates/scripts-configmap.yaml new file mode 100644 index 0000000..7e98d68 --- /dev/null +++ b/chart/deps/redis/templates/scripts-configmap.yaml @@ -0,0 +1,450 @@ +apiVersion: v1 +kind: ConfigMap +metadata: + name: {{ printf "%s-scripts" (include "common.names.fullname" .) }} + namespace: {{ .Release.Namespace | quote }} + labels: {{- include "common.labels.standard" . | nindent 4 }} + {{- if .Values.commonLabels }} + {{- include "common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }} + {{- end }} + {{- if .Values.commonAnnotations }} + annotations: {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }} + {{- end }} +data: +{{- if and (eq .Values.architecture "replication") .Values.sentinel.enabled }} + start-node.sh: | + #!/bin/bash + + . /opt/bitnami/scripts/libos.sh + . /opt/bitnami/scripts/liblog.sh + . /opt/bitnami/scripts/libvalidations.sh + + not_exists_dns_entry() { + myip=$(hostname -i) + + if [[ -z "$(getent ahosts "$HEADLESS_SERVICE" | grep "^${myip}" )" ]]; then + warn "$HEADLESS_SERVICE does not contain the IP of this pod: ${myip}" + return 1 + fi + debug "$HEADLESS_SERVICE has my IP: ${myip}" + return 0 + } + + HEADLESS_SERVICE="{{ template "common.names.fullname" . }}-headless.{{ .Release.Namespace }}.svc.{{ .Values.clusterDomain }}" + REDIS_SERVICE="{{ template "common.names.fullname" . }}.{{ .Release.Namespace }}.svc.{{ .Values.clusterDomain }}" + + # Waits for DNS to add this ip to the service DNS entry + retry_while not_exists_dns_entry + + export REDIS_REPLICATION_MODE="slave" + [[ -z "$(getent ahosts "$HEADLESS_SERVICE" | grep -v "^$(hostname -i) ")" ]] && export REDIS_REPLICATION_MODE="master" + + {{- if and .Values.replica.containerSecurityContext.runAsUser (eq (.Values.replica.containerSecurityContext.runAsUser | int) 0) }} + useradd redis + chown -R redis {{ .Values.replica.persistence.path }} + {{- end }} + + [[ -f $REDIS_PASSWORD_FILE ]] && export REDIS_PASSWORD="$(< "${REDIS_PASSWORD_FILE}")" + [[ -f $REDIS_MASTER_PASSWORD_FILE ]] && export REDIS_MASTER_PASSWORD="$(< "${REDIS_MASTER_PASSWORD_FILE}")" + + if [[ "$REDIS_REPLICATION_MODE" = "master" ]]; then + debug "Starting as master node" + if [[ ! -f /opt/bitnami/redis/etc/master.conf ]]; then + cp /opt/bitnami/redis/mounted-etc/master.conf /opt/bitnami/redis/etc/master.conf + fi + else + debug "Starting as replica node" + if [[ ! -f /opt/bitnami/redis/etc/replica.conf ]];then + cp /opt/bitnami/redis/mounted-etc/replica.conf /opt/bitnami/redis/etc/replica.conf + fi + if is_boolean_yes "$REDIS_TLS_ENABLED"; then + sentinel_info_command="redis-cli {{- if .Values.auth.enabled }} -a $REDIS_PASSWORD {{- end }} -h $REDIS_SERVICE -p {{ .Values.sentinel.service.sentinelPort }} --tls --cert ${REDIS_TLS_CERT_FILE} --key ${REDIS_TLS_KEY_FILE} --cacert ${REDIS_TLS_CA_FILE} sentinel get-master-addr-by-name {{ .Values.sentinel.masterSet }}" + else + sentinel_info_command="redis-cli {{- if .Values.auth.enabled }} -a $REDIS_PASSWORD {{- end }} -h $REDIS_SERVICE -p {{ .Values.sentinel.service.sentinelPort }} sentinel get-master-addr-by-name {{ .Values.sentinel.masterSet }}" + fi + REDIS_SENTINEL_INFO=($($sentinel_info_command)) + REDIS_MASTER_HOST=${REDIS_SENTINEL_INFO[0]} + REDIS_MASTER_PORT_NUMBER=${REDIS_SENTINEL_INFO[1]} + + # Immediately attempt to connect to the reported master. If it doesn't exist the connection attempt will either hang + # or fail with "port unreachable" and give no data. The liveness check will then timeout waiting for the redis + # container to be ready and restart the it. By then the new master will likely have been elected + if is_boolean_yes "$REDIS_TLS_ENABLED"; then + sentinel_info_command="redis-cli {{- if .Values.auth.enabled }} -a $REDIS_PASSWORD {{- end }} -h $REDIS_MASTER_HOST -p {{ .Values.sentinel.service.sentinelPort }} --tls --cert ${REDIS_TLS_CERT_FILE} --key ${REDIS_TLS_KEY_FILE} --cacert ${REDIS_TLS_CA_FILE} sentinel get-master-addr-by-name {{ .Values.sentinel.masterSet }}" + else + sentinel_info_command="redis-cli {{- if .Values.auth.enabled }} -a $REDIS_PASSWORD {{- end }} -h $REDIS_MASTER_HOST -p {{ .Values.sentinel.service.sentinelPort }} sentinel get-master-addr-by-name {{ .Values.sentinel.masterSet }}" + fi + + if [[ ! ($($sentinel_info_command)) ]]; then + # master doesn't actually exist, this probably means the remaining pods haven't elected a new one yet + # and are reporting the old one still. Once this happens the container will get stuck and never see the new + # master. We stop here to allow the container to not pass the liveness check and be restarted. + exit 1 + fi + fi + + if [[ ! -f /opt/bitnami/redis/etc/redis.conf ]];then + cp /opt/bitnami/redis/mounted-etc/redis.conf /opt/bitnami/redis/etc/redis.conf + fi + {{- if .Values.tls.enabled }} + ARGS=("--port" "0") + ARGS+=("--tls-port" "${REDIS_TLS_PORT}") + ARGS+=("--tls-cert-file" "${REDIS_TLS_CERT_FILE}") + ARGS+=("--tls-key-file" "${REDIS_TLS_KEY_FILE}") + ARGS+=("--tls-ca-cert-file" "${REDIS_TLS_CA_FILE}") + ARGS+=("--tls-auth-clients" "${REDIS_TLS_AUTH_CLIENTS}") + ARGS+=("--tls-replication" "yes") + {{- if .Values.tls.dhParamsFilename }} + ARGS+=("--tls-dh-params-file" "${REDIS_TLS_DH_PARAMS_FILE}") + {{- end }} + {{- else }} + ARGS=("--port" "${REDIS_PORT}") + {{- end }} + + if [[ "$REDIS_REPLICATION_MODE" = "slave" ]]; then + ARGS+=("--slaveof" "${REDIS_MASTER_HOST}" "${REDIS_MASTER_PORT_NUMBER}") + fi + + {{- if .Values.auth.enabled }} + ARGS+=("--requirepass" "${REDIS_PASSWORD}") + ARGS+=("--masterauth" "${REDIS_MASTER_PASSWORD}") + {{- else }} + ARGS+=("--protected-mode" "no") + {{- end }} + if [[ "$REDIS_REPLICATION_MODE" = "master" ]]; then + ARGS+=("--include" "/opt/bitnami/redis/etc/master.conf") + else + ARGS+=("--include" "/opt/bitnami/redis/etc/replica.conf") + fi + ARGS+=("--include" "/opt/bitnami/redis/etc/redis.conf") + {{- if .Values.replica.extraFlags }} + {{- range .Values.replica.extraFlags }} + ARGS+=({{ . | quote }}) + {{- end }} + {{- end }} + + {{- if .Values.replica.preExecCmds }} + {{- .Values.replica.preExecCmds | nindent 4}} + {{- end }} + + {{- if .Values.replica.command }} + exec {{ .Values.replica.command }} "${ARGS[@]}" + {{- else }} + exec redis-server "${ARGS[@]}" + {{- end }} + + start-sentinel.sh: | + #!/bin/bash + + . /opt/bitnami/scripts/libos.sh + . /opt/bitnami/scripts/libvalidations.sh + . /opt/bitnami/scripts/libfile.sh + + sentinel_conf_set() { + local -r key="${1:?missing key}" + local value="${2:-}" + + # Sanitize inputs + value="${value//\\/\\\\}" + value="${value//&/\\&}" + value="${value//\?/\\?}" + [[ "$value" = "" ]] && value="\"$value\"" + + replace_in_file "/opt/bitnami/redis-sentinel/etc/sentinel.conf" "^#*\s*${key} .*" "${key} ${value}" false + } + sentinel_conf_add() { + echo $'\n'"$@" >> "/opt/bitnami/redis-sentinel/etc/sentinel.conf" + } + host_id() { + echo "$1" | openssl sha1 | awk '{print $2}' + } + not_exists_dns_entry() { + myip=$(hostname -i) + + if [[ -z "$(getent ahosts "$HEADLESS_SERVICE" | grep "^${myip}" )" ]]; then + warn "$HEADLESS_SERVICE does not contain the IP of this pod: ${myip}" + return 1 + fi + debug "$HEADLESS_SERVICE has my IP: ${myip}" + return 0 + } + + HEADLESS_SERVICE="{{ template "common.names.fullname" . }}-headless.{{ .Release.Namespace }}.svc.{{ .Values.clusterDomain }}" + REDIS_SERVICE="{{ template "common.names.fullname" . }}.{{ .Release.Namespace }}.svc.{{ .Values.clusterDomain }}" + + [[ -f $REDIS_PASSWORD_FILE ]] && export REDIS_PASSWORD="$(< "${REDIS_PASSWORD_FILE}")" + + if [[ ! -f /opt/bitnami/redis-sentinel/etc/sentinel.conf ]]; then + cp /opt/bitnami/redis-sentinel/mounted-etc/sentinel.conf /opt/bitnami/redis-sentinel/etc/sentinel.conf + {{- if .Values.auth.enabled }} + printf "\nsentinel auth-pass %s %s" "{{ .Values.sentinel.masterSet }}" "$REDIS_PASSWORD" >> /opt/bitnami/redis-sentinel/etc/sentinel.conf + {{- if .Values.auth.sentinel }} + printf "\nrequirepass %s" "$REDIS_PASSWORD" >> /opt/bitnami/redis-sentinel/etc/sentinel.conf + {{- end }} + {{- end }} + {{- if .Values.sentinel.staticID }} + printf "\nsentinel myid %s" "$(host_id "$HOSTNAME")" >> /opt/bitnami/redis-sentinel/etc/sentinel.conf + {{- end }} + fi + + export REDIS_REPLICATION_MODE="slave" + + # Waits for DNS to add this ip to the service DNS entry + retry_while not_exists_dns_entry + + if [[ -z "$(getent ahosts "$HEADLESS_SERVICE" | grep -v "^$(hostname -i)")" ]]; then + export REDIS_REPLICATION_MODE="master" + fi + + # Clean sentineles from the current sentinel nodes + for node in $( getent ahosts "$HEADLESS_SERVICE" | grep -v "^$(hostname -i)" | cut -f 1 -d ' ' | uniq ); do + info "Cleaning sentinels in sentinel node: $node" + if is_boolean_yes "$REDIS_SENTINEL_TLS_ENABLED"; then + redis-cli {{- if .Values.auth.enabled }} -a $REDIS_PASSWORD {{- end }} -h $node -p {{ .Values.sentinel.service.sentinelPort }} --tls --cert ${REDIS_SENTINEL_TLS_CERT_FILE} --key ${REDIS_SENTINEL_TLS_KEY_FILE} --cacert ${REDIS_SENTINEL_TLS_CA_FILE} sentinel reset "*" + else + redis-cli {{- if .Values.auth.enabled }} -a $REDIS_PASSWORD {{- end }} -h $node -p {{ .Values.sentinel.service.sentinelPort }} sentinel reset "*" + fi + sleep {{ .Values.sentinel.cleanDelaySeconds }} + done + info "Sentinels clean up done" + + if [[ "$REDIS_REPLICATION_MODE" = "master" ]]; then + REDIS_MASTER_HOST="$(hostname -i)" + REDIS_MASTER_PORT_NUMBER="{{ .Values.master.service.port }}" + else + if is_boolean_yes "$REDIS_SENTINEL_TLS_ENABLED"; then + sentinel_info_command="redis-cli {{- if .Values.auth.enabled }} -a $REDIS_PASSWORD {{- end }} -h $REDIS_SERVICE -p {{ .Values.sentinel.service.sentinelPort }} --tls --cert ${REDIS_SENTINEL_TLS_CERT_FILE} --key ${REDIS_SENTINEL_TLS_KEY_FILE} --cacert ${REDIS_SENTINEL_TLS_CA_FILE} sentinel get-master-addr-by-name {{ .Values.sentinel.masterSet }}" + else + sentinel_info_command="redis-cli {{- if .Values.auth.enabled }} -a $REDIS_PASSWORD {{- end }} -h $REDIS_SERVICE -p {{ .Values.sentinel.service.sentinelPort }} sentinel get-master-addr-by-name {{ .Values.sentinel.masterSet }}" + fi + REDIS_SENTINEL_INFO=($($sentinel_info_command)) + REDIS_MASTER_HOST=${REDIS_SENTINEL_INFO[0]} + REDIS_MASTER_PORT_NUMBER=${REDIS_SENTINEL_INFO[1]} + + # Immediately attempt to connect to the reported master. If it doesn't exist the connection attempt will either hang + # or fail with "port unreachable" and give no data. The liveness check will then timeout waiting for the sentinel + # container to be ready and restart the it. By then the new master will likely have been elected + if is_boolean_yes "$REDIS_SENTINEL_TLS_ENABLED"; then + sentinel_info_command="redis-cli {{- if .Values.auth.enabled }} -a $REDIS_PASSWORD {{- end }} -h $REDIS_MASTER_HOST -p {{ .Values.sentinel.service.sentinelPort }} --tls --cert ${REDIS_SENTINEL_TLS_CERT_FILE} --key ${REDIS_SENTINEL_TLS_KEY_FILE} --cacert ${REDIS_SENTINEL_TLS_CA_FILE} sentinel get-master-addr-by-name {{ .Values.sentinel.masterSet }}" + else + sentinel_info_command="redis-cli {{- if .Values.auth.enabled }} -a $REDIS_PASSWORD {{- end }} -h $REDIS_MASTER_HOST -p {{ .Values.sentinel.service.sentinelPort }} sentinel get-master-addr-by-name {{ .Values.sentinel.masterSet }}" + fi + + if [[ ! ($($sentinel_info_command)) ]]; then + # master doesn't actually exist, this probably means the remaining pods haven't elected a new one yet + # and are reporting the old one still. Once this happens the container will get stuck and never see the new + # master. We stop here to allow the container to not pass the liveness check and be restarted. + exit 1 + fi + fi + sentinel_conf_set "sentinel monitor" "{{ .Values.sentinel.masterSet }} "$REDIS_MASTER_HOST" "$REDIS_MASTER_PORT_NUMBER" {{ .Values.sentinel.quorum }}" + + add_replica() { + if [[ "$1" != "$REDIS_MASTER_HOST" ]]; then + sentinel_conf_add "sentinel known-replica {{ .Values.sentinel.masterSet }} $1 {{ .Values.sentinel.service.port }}" + fi + } + + {{- if .Values.sentinel.staticID }} + # remove generated known sentinels and replicas + tmp="$(sed -e '/^sentinel known-/d' -e '/^$/d' /opt/bitnami/redis-sentinel/etc/sentinel.conf)" + echo "$tmp" > /opt/bitnami/redis-sentinel/etc/sentinel.conf + + for node in $(seq 0 {{ .Values.replica.replicaCount }}); do + NAME="{{ template "common.names.fullname" . }}-node-$node" + IP="$(getent hosts "$NAME.$HEADLESS_SERVICE" | awk ' {print $1 }')" + if [[ "$NAME" != "$HOSTNAME" && -n "$IP" ]]; then + sentinel_conf_add "sentinel known-sentinel {{ .Values.sentinel.masterSet }} $IP {{ .Values.sentinel.service.sentinelPort }} $(host_id "$NAME")" + add_replica "$IP" + fi + done + add_replica "$(hostname -i)" + {{- end }} + + {{- if .Values.tls.enabled }} + ARGS=("--port" "0") + ARGS+=("--tls-port" "${REDIS_SENTINEL_TLS_PORT_NUMBER}") + ARGS+=("--tls-cert-file" "${REDIS_SENTINEL_TLS_CERT_FILE}") + ARGS+=("--tls-key-file" "${REDIS_SENTINEL_TLS_KEY_FILE}") + ARGS+=("--tls-ca-cert-file" "${REDIS_SENTINEL_TLS_CA_FILE}") + ARGS+=("--tls-replication" "yes") + ARGS+=("--tls-auth-clients" "${REDIS_SENTINEL_TLS_AUTH_CLIENTS}") + {{- if .Values.tls.dhParamsFilename }} + ARGS+=("--tls-dh-params-file" "${REDIS_SENTINEL_TLS_DH_PARAMS_FILE}") + {{- end }} + {{- end }} + {{- if .Values.sentinel.preExecCmds }} + {{ .Values.sentinel.preExecCmds | nindent 4 }} + {{- end }} + exec redis-server /opt/bitnami/redis-sentinel/etc/sentinel.conf --sentinel {{- if .Values.tls.enabled }} "${ARGS[@]}" {{- end }} + prestop-sentinel.sh: | + #!/bin/bash + + . /opt/bitnami/scripts/libvalidations.sh + . /opt/bitnami/scripts/libos.sh + + run_sentinel_command() { + if is_boolean_yes "$REDIS_SENTINEL_TLS_ENABLED"; then + redis-cli -h "$REDIS_SERVICE" -p "{{ .Values.sentinel.service.sentinelPort }}" --tls --cert "$REDIS_SENTINEL_TLS_CERT_FILE" --key "$REDIS_SENTINEL_TLS_KEY_FILE" --cacert "$REDIS_SENTINEL_TLS_CA_FILE" sentinel "$@" + else + redis-cli -h "$REDIS_SERVICE" -p "{{ .Values.sentinel.service.sentinelPort }}" sentinel "$@" + fi + } + failover_finished() { + REDIS_SENTINEL_INFO=($(run_sentinel_command get-master-addr-by-name "{{ .Values.sentinel.masterSet }}")) + REDIS_MASTER_HOST="${REDIS_SENTINEL_INFO[0]}" + [[ "$REDIS_MASTER_HOST" != "$(hostname -i)" ]] + } + + REDIS_SERVICE="{{ include "common.names.fullname" . }}.{{ .Release.Namespace }}.svc.{{ .Values.clusterDomain }}" + + # redis-cli automatically consumes credentials from the REDISCLI_AUTH variable + [[ -n "$REDIS_PASSWORD" ]] && export REDISCLI_AUTH="$REDIS_PASSWORD" + [[ -f "$REDIS_PASSWORD_FILE" ]] && export REDISCLI_AUTH="$(< "${REDIS_PASSWORD_FILE}")" + + if ! failover_finished; then + echo "I am the master pod and you are stopping me. Starting sentinel failover" + # if I am the master, issue a command to failover once and then wait for the failover to finish + run_sentinel_command failover "{{ .Values.sentinel.masterSet }}" + if retry_while "failover_finished" "{{ sub .Values.sentinel.terminationGracePeriodSeconds 10 }}" 1; then + echo "Master has been successfuly failed over to a different pod." + exit 0 + else + echo "Master failover failed" + exit 1 + fi + else + exit 0 + fi + prestop-redis.sh: | + #!/bin/bash + + . /opt/bitnami/scripts/libvalidations.sh + . /opt/bitnami/scripts/libos.sh + + run_redis_command() { + if is_boolean_yes "$REDIS_TLS_ENABLED"; then + redis-cli -h 127.0.0.1 -p "$REDIS_TLS_PORT" --tls --cert "$REDIS_TLS_CERT_FILE" --key "$REDIS_TLS_KEY_FILE" --cacert "$REDIS_TLS_CA_FILE" "$@" + else + redis-cli -h 127.0.0.1 -p ${REDIS_PORT} "$@" + fi + } + failover_finished() { + REDIS_ROLE=$(run_redis_command role | head -1) + [[ "$REDIS_ROLE" != "master" ]] + } + + # redis-cli automatically consumes credentials from the REDISCLI_AUTH variable + [[ -n "$REDIS_PASSWORD" ]] && export REDISCLI_AUTH="$REDIS_PASSWORD" + [[ -f "$REDIS_PASSWORD_FILE" ]] && export REDISCLI_AUTH="$(< "${REDIS_PASSWORD_FILE}")" + + if ! failover_finished; then + echo "Waiting for sentinel to run failover for up to {{ sub .Values.sentinel.terminationGracePeriodSeconds 10 }}s" + retry_while "failover_finished" "{{ sub .Values.sentinel.terminationGracePeriodSeconds 10 }}" 1 + else + exit 0 + fi + +{{- else }} + start-master.sh: | + #!/bin/bash + + [[ -f $REDIS_PASSWORD_FILE ]] && export REDIS_PASSWORD="$(< "${REDIS_PASSWORD_FILE}")" + {{- if and .Values.master.containerSecurityContext.runAsUser (eq (.Values.master.containerSecurityContext.runAsUser | int) 0) }} + useradd redis + chown -R redis {{ .Values.master.persistence.path }} + {{- end }} + if [[ ! -f /opt/bitnami/redis/etc/master.conf ]];then + cp /opt/bitnami/redis/mounted-etc/master.conf /opt/bitnami/redis/etc/master.conf + fi + if [[ ! -f /opt/bitnami/redis/etc/redis.conf ]];then + cp /opt/bitnami/redis/mounted-etc/redis.conf /opt/bitnami/redis/etc/redis.conf + fi + {{- if .Values.tls.enabled }} + ARGS=("--port" "0") + ARGS+=("--tls-port" "${REDIS_TLS_PORT}") + ARGS+=("--tls-cert-file" "${REDIS_TLS_CERT_FILE}") + ARGS+=("--tls-key-file" "${REDIS_TLS_KEY_FILE}") + ARGS+=("--tls-ca-cert-file" "${REDIS_TLS_CA_FILE}") + ARGS+=("--tls-auth-clients" "${REDIS_TLS_AUTH_CLIENTS}") + {{- if .Values.tls.dhParamsFilename }} + ARGS+=("--tls-dh-params-file" "${REDIS_TLS_DH_PARAMS_FILE}") + {{- end }} + {{- else }} + ARGS=("--port" "${REDIS_PORT}") + {{- end }} + {{- if .Values.auth.enabled }} + ARGS+=("--requirepass" "${REDIS_PASSWORD}") + ARGS+=("--masterauth" "${REDIS_PASSWORD}") + {{- else }} + ARGS+=("--protected-mode" "no") + {{- end }} + ARGS+=("--include" "/opt/bitnami/redis/etc/redis.conf") + ARGS+=("--include" "/opt/bitnami/redis/etc/master.conf") + {{- if .Values.master.extraFlags }} + {{- range .Values.master.extraFlags }} + ARGS+=({{ . | quote }}) + {{- end }} + {{- end }} + {{- if .Values.master.preExecCmds }} + {{ .Values.master.preExecCmds | nindent 4}} + {{- end }} + {{- if .Values.master.command }} + exec {{ .Values.master.command }} "${ARGS[@]}" + {{- else }} + exec redis-server "${ARGS[@]}" + {{- end }} + {{- if eq .Values.architecture "replication" }} + start-replica.sh: | + #!/bin/bash + + [[ -f $REDIS_PASSWORD_FILE ]] && export REDIS_PASSWORD="$(< "${REDIS_PASSWORD_FILE}")" + [[ -f $REDIS_MASTER_PASSWORD_FILE ]] && export REDIS_MASTER_PASSWORD="$(< "${REDIS_MASTER_PASSWORD_FILE}")" + {{- if and .Values.replica.containerSecurityContext.runAsUser (eq (.Values.replica.containerSecurityContext.runAsUser | int) 0) }} + useradd redis + chown -R redis {{ .Values.replica.persistence.path }} + {{- end }} + if [[ ! -f /opt/bitnami/redis/etc/replica.conf ]];then + cp /opt/bitnami/redis/mounted-etc/replica.conf /opt/bitnami/redis/etc/replica.conf + fi + if [[ ! -f /opt/bitnami/redis/etc/redis.conf ]];then + cp /opt/bitnami/redis/mounted-etc/redis.conf /opt/bitnami/redis/etc/redis.conf + fi + {{- if .Values.tls.enabled }} + ARGS=("--port" "0") + ARGS+=("--tls-port" "${REDIS_TLS_PORT}") + ARGS+=("--tls-cert-file" "${REDIS_TLS_CERT_FILE}") + ARGS+=("--tls-key-file" "${REDIS_TLS_KEY_FILE}") + ARGS+=("--tls-ca-cert-file" "${REDIS_TLS_CA_FILE}") + ARGS+=("--tls-auth-clients" "${REDIS_TLS_AUTH_CLIENTS}") + ARGS+=("--tls-replication" "yes") + {{- if .Values.tls.dhParamsFilename }} + ARGS+=("--tls-dh-params-file" "${REDIS_TLS_DH_PARAMS_FILE}") + {{- end }} + {{- else }} + ARGS=("--port" "${REDIS_PORT}") + {{- end }} + ARGS+=("--slaveof" "${REDIS_MASTER_HOST}" "${REDIS_MASTER_PORT_NUMBER}") + {{- if .Values.auth.enabled }} + ARGS+=("--requirepass" "${REDIS_PASSWORD}") + ARGS+=("--masterauth" "${REDIS_MASTER_PASSWORD}") + {{- else }} + ARGS+=("--protected-mode" "no") + {{- end }} + ARGS+=("--include" "/opt/bitnami/redis/etc/redis.conf") + ARGS+=("--include" "/opt/bitnami/redis/etc/replica.conf") + {{- if .Values.replica.extraFlags }} + {{- range .Values.replica.extraFlags }} + ARGS+=({{ . | quote }}) + {{- end }} + {{- end }} + {{- if .Values.replica.preExecCmds }} + {{ .Values.replica.preExecCmds | nindent 4}} + {{- end }} + {{- if .Values.replica.command }} + exec {{ .Values.replica.command }} "${ARGS[@]}" + {{- else }} + exec redis-server "${ARGS[@]}" + {{- end }} + {{- end }} +{{- end }} diff --git a/chart/deps/redis/templates/secret.yaml b/chart/deps/redis/templates/secret.yaml index 043edfe..e639ffe 100644 --- a/chart/deps/redis/templates/secret.yaml +++ b/chart/deps/redis/templates/secret.yaml @@ -1,16 +1,18 @@ -{{- if and .Values.usePassword (not .Values.existingSecret) -}} -{{- $secretName := include "redis.fullname" . -}} +{{- if and .Values.auth.enabled (not .Values.auth.existingSecret) -}} +{{- $secretName := include "common.names.fullname" . -}} {{- $secret := (lookup "v1" "Secret" .Release.Namespace $secretName ) -}} apiVersion: v1 kind: Secret metadata: name: {{ $secretName }} namespace: {{ .Release.Namespace | quote }} - labels: - app: {{ template "redis.name" . }} - chart: {{ template "redis.chart" . }} - release: "{{ .Release.Name }}" - heritage: "{{ .Release.Service }}" + labels: {{- include "common.labels.standard" . | nindent 4 }} + {{- if .Values.commonLabels }} + {{- include "common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }} + {{- end }} + {{- if .Values.commonAnnotations }} + annotations: {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }} + {{- end }} type: Opaque data: {{ if $secret }} diff --git a/chart/deps/redis/templates/sentinel/service.yaml b/chart/deps/redis/templates/sentinel/service.yaml new file mode 100644 index 0000000..0f68fc3 --- /dev/null +++ b/chart/deps/redis/templates/sentinel/service.yaml @@ -0,0 +1,54 @@ +{{- if and (eq .Values.architecture "replication") .Values.sentinel.enabled }} +apiVersion: v1 +kind: Service +metadata: + name: {{ template "common.names.fullname" . }} + namespace: {{ .Release.Namespace | quote }} + labels: {{- include "common.labels.standard" . | nindent 4 }} + app.kubernetes.io/component: node + {{- if .Values.commonLabels }} + {{- include "common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }} + {{- end }} + {{- if or .Values.sentinel.service.annotations .Values.commonAnnotations }} + annotations: + {{- if .Values.sentinel.service.annotations }} + {{- include "common.tplvalues.render" ( dict "value" .Values.sentinel.service.annotations "context" $ ) | nindent 4 }} + {{- end }} + {{- if .Values.commonAnnotations }} + {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }} + {{- end }} + {{- end }} +spec: + type: {{ .Values.sentinel.service.type }} + {{- if eq .Values.sentinel.service.type "LoadBalancer" }} + externalTrafficPolicy: {{ .Values.sentinel.service.externalTrafficPolicy }} + {{- end }} + {{- if and (eq .Values.sentinel.service.type "LoadBalancer") .Values.sentinel.service.loadBalancerIP }} + loadBalancerIP: {{ .Values.sentinel.service.loadBalancerIP }} + {{- end }} + {{- if and (eq .Values.sentinel.service.type "LoadBalancer") .Values.sentinel.service.loadBalancerSourceRanges }} + loadBalancerSourceRanges: {{- toYaml .Values.sentinel.service.loadBalancerSourceRanges | nindent 4 }} + {{- end }} + {{- if and (eq .Values.sentinel.service.type "ClusterIP") .Values.sentinel.service.clusterIP }} + clusterIP: {{ .Values.sentinel.service.clusterIP }} + {{- end }} + ports: + - name: tcp-redis + port: {{ .Values.sentinel.service.port }} + targetPort: redis + {{- if and (or (eq .Values.sentinel.service.type "NodePort") (eq .Values.sentinel.service.type "LoadBalancer")) .Values.sentinel.service.nodePorts.redis }} + nodePort: {{ .Values.sentinel.service.nodePorts.redis }} + {{- else if eq .Values.sentinel.service.type "ClusterIP" }} + nodePort: null + {{- end }} + - name: tcp-sentinel + port: {{ .Values.sentinel.service.sentinelPort }} + targetPort: redis-sentinel + {{- if and (or (eq .Values.sentinel.service.type "NodePort") (eq .Values.sentinel.service.type "LoadBalancer")) .Values.sentinel.service.nodePorts.sentinel }} + nodePort: {{ .Values.sentinel.service.nodePorts.sentinel }} + {{- else if eq .Values.sentinel.service.type "ClusterIP" }} + nodePort: null + {{- end }} + selector: {{- include "common.labels.matchLabels" . | nindent 4 }} + app.kubernetes.io/component: node +{{- end }} diff --git a/chart/deps/redis/templates/sentinel/statefulset.yaml b/chart/deps/redis/templates/sentinel/statefulset.yaml new file mode 100644 index 0000000..e299753 --- /dev/null +++ b/chart/deps/redis/templates/sentinel/statefulset.yaml @@ -0,0 +1,580 @@ +{{- if and (eq .Values.architecture "replication") .Values.sentinel.enabled }} +apiVersion: {{ include "common.capabilities.statefulset.apiVersion" . }} +kind: StatefulSet +metadata: + name: {{ printf "%s-node" (include "common.names.fullname" .) }} + namespace: {{ .Release.Namespace | quote }} + labels: {{- include "common.labels.standard" . | nindent 4 }} + app.kubernetes.io/component: node + {{- if .Values.commonLabels }} + {{- include "common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }} + {{- end }} + {{- if or .Values.commonAnnotations }} + annotations: {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }} + {{- end }} +spec: + replicas: {{ .Values.replica.replicaCount }} + selector: + matchLabels: {{- include "common.labels.matchLabels" . | nindent 6 }} + app.kubernetes.io/component: node + serviceName: {{ printf "%s-headless" (include "common.names.fullname" .) }} + {{- if .Values.replica.updateStrategy }} + updateStrategy: {{- toYaml .Values.replica.updateStrategy | nindent 4 }} + {{- end }} + template: + metadata: + labels: {{- include "common.labels.standard" . | nindent 8 }} + app.kubernetes.io/component: node + {{- if .Values.replica.podLabels }} + {{- include "common.tplvalues.render" ( dict "value" .Values.replica.podLabels "context" $ ) | nindent 8 }} + {{- end }} + {{- if and .Values.metrics.enabled .Values.metrics.podLabels }} + {{- include "common.tplvalues.render" ( dict "value" .Values.metrics.podLabels "context" $ ) | nindent 8 }} + {{- end }} + annotations: + {{- if (include "redis.createConfigmap" .) }} + checksum/configmap: {{ include (print $.Template.BasePath "/configmap.yaml") . | sha256sum }} + {{- end }} + checksum/health: {{ include (print $.Template.BasePath "/health-configmap.yaml") . | sha256sum }} + checksum/scripts: {{ include (print $.Template.BasePath "/scripts-configmap.yaml") . | sha256sum }} + checksum/secret: {{ include (print $.Template.BasePath "/secret.yaml") . | sha256sum }} + {{- if .Values.replica.podAnnotations }} + {{- include "common.tplvalues.render" ( dict "value" .Values.replica.podAnnotations "context" $ ) | nindent 8 }} + {{- end }} + {{- if and .Values.metrics.enabled .Values.metrics.podAnnotations }} + {{- include "common.tplvalues.render" ( dict "value" .Values.metrics.podAnnotations "context" $ ) | nindent 8 }} + {{- end }} + spec: + {{- include "redis.imagePullSecrets" . | nindent 6 }} + {{- if .Values.replica.hostAliases }} + hostAliases: {{- include "common.tplvalues.render" (dict "value" .Values.replica.hostAliases "context" $) | nindent 8 }} + {{- end }} + {{- if .Values.replica.podSecurityContext.enabled }} + securityContext: {{- omit .Values.replica.podSecurityContext "enabled" | toYaml | nindent 8 }} + {{- end }} + serviceAccountName: {{ template "redis.serviceAccountName" . }} + {{- if .Values.replica.priorityClassName }} + priorityClassName: {{ .Values.replica.priorityClassName | quote }} + {{- end }} + {{- if .Values.replica.affinity }} + affinity: {{- include "common.tplvalues.render" (dict "value" .Values.replica.affinity "context" $) | nindent 8 }} + {{- else }} + affinity: + podAffinity: {{- include "common.affinities.pods" (dict "type" .Values.replica.podAffinityPreset "component" "node" "context" $) | nindent 10 }} + podAntiAffinity: {{- include "common.affinities.pods" (dict "type" .Values.replica.podAntiAffinityPreset "component" "node" "context" $) | nindent 10 }} + nodeAffinity: {{- include "common.affinities.nodes" (dict "type" .Values.replica.nodeAffinityPreset.type "key" .Values.replica.nodeAffinityPreset.key "values" .Values.replica.nodeAffinityPreset.values) | nindent 10 }} + {{- end }} + {{- if .Values.replica.nodeSelector }} + nodeSelector: {{- include "common.tplvalues.render" (dict "value" .Values.replica.nodeSelector "context" $) | nindent 8 }} + {{- end }} + {{- if .Values.replica.tolerations }} + tolerations: {{- include "common.tplvalues.render" (dict "value" .Values.replica.tolerations "context" $) | nindent 8 }} + {{- end }} + {{- if .Values.replica.spreadConstraints }} + topologySpreadConstraints: {{- include "common.tplvalues.render" (dict "value" .Values.replica.spreadConstraints "context" $) | nindent 8 }} + {{- end }} + {{- if .Values.replica.shareProcessNamespace }} + shareProcessNamespace: {{ .Values.replica.shareProcessNamespace }} + {{- end }} + {{- if .Values.replica.schedulerName }} + schedulerName: {{ .Values.replica.schedulerName | quote }} + {{- end }} + terminationGracePeriodSeconds: {{ .Values.sentinel.terminationGracePeriodSeconds }} + containers: + - name: redis + image: {{ template "redis.image" . }} + imagePullPolicy: {{ .Values.image.pullPolicy | quote }} + {{- if .Values.replica.lifecycleHooks }} + lifecycle: {{- include "common.tplvalues.render" (dict "value" .Values.replica.lifecycleHooks "context" $) | nindent 12 }} + {{- end }} + {{- if .Values.replica.containerSecurityContext.enabled }} + securityContext: {{- omit .Values.replica.containerSecurityContext "enabled" | toYaml | nindent 12 }} + {{- end }} + {{- if .Values.replica.command }} + command: {{- include "common.tplvalues.render" (dict "value" .Values.replica.command "context" $) | nindent 12 }} + {{- else }} + command: + - /bin/bash + {{- end }} + {{- if .Values.replica.args }} + args: {{- include "common.tplvalues.render" (dict "value" .Values.replica.args "context" $) | nindent 12 }} + {{- else }} + args: + - -c + - /opt/bitnami/scripts/start-scripts/start-node.sh + {{- end }} + env: + - name: BITNAMI_DEBUG + value: {{ ternary "true" "false" .Values.image.debug | quote }} + - name: REDIS_MASTER_PORT_NUMBER + value: {{ .Values.replica.containerPort | quote }} + - name: ALLOW_EMPTY_PASSWORD + value: {{ ternary "no" "yes" .Values.auth.enabled | quote }} + {{- if .Values.auth.enabled }} + {{- if .Values.auth.usePasswordFiles }} + - name: REDIS_PASSWORD_FILE + value: "/opt/bitnami/redis/secrets/redis-password" + - name: REDIS_MASTER_PASSWORD_FILE + value: "/opt/bitnami/redis/secrets/redis-password" + {{- else }} + - name: REDIS_PASSWORD + valueFrom: + secretKeyRef: + name: {{ template "redis.secretName" . }} + key: {{ template "redis.secretPasswordKey" . }} + - name: REDIS_MASTER_PASSWORD + valueFrom: + secretKeyRef: + name: {{ template "redis.secretName" . }} + key: {{ template "redis.secretPasswordKey" . }} + {{- end }} + {{- end }} + - name: REDIS_TLS_ENABLED + value: {{ ternary "yes" "no" .Values.tls.enabled | quote }} + {{- if .Values.tls.enabled }} + - name: REDIS_TLS_PORT + value: {{ .Values.replica.containerPort | quote }} + - name: REDIS_TLS_AUTH_CLIENTS + value: {{ ternary "yes" "no" .Values.tls.authClients | quote }} + - name: REDIS_TLS_CERT_FILE + value: {{ template "redis.tlsCert" . }} + - name: REDIS_TLS_KEY_FILE + value: {{ template "redis.tlsCertKey" . }} + - name: REDIS_TLS_CA_FILE + value: {{ template "redis.tlsCACert" . }} + {{- if .Values.tls.dhParamsFilename }} + - name: REDIS_TLS_DH_PARAMS_FILE + value: {{ template "redis.tlsDHParams" . }} + {{- end }} + {{- else }} + - name: REDIS_PORT + value: {{ .Values.replica.containerPort | quote }} + {{- end }} + - name: REDIS_DATA_DIR + value: {{ .Values.replica.persistence.path }} + {{- if .Values.replica.extraEnvVars }} + {{- include "common.tplvalues.render" ( dict "value" .Values.replica.extraEnvVars "context" $ ) | nindent 12 }} + {{- end }} + {{- if or .Values.replica.extraEnvVarsCM .Values.replica.extraEnvVarsSecret }} + envFrom: + {{- if .Values.replica.extraEnvVarsCM }} + - configMapRef: + name: {{ .Values.replica.extraEnvVarsCM }} + {{- end }} + {{- if .Values.replica.extraEnvVarsSecret }} + - secretRef: + name: {{ .Values.replica.extraEnvVarsSecret }} + {{- end }} + {{- end }} + ports: + - name: redis + containerPort: {{ .Values.replica.containerPort }} + {{- if .Values.replica.livenessProbe.enabled }} + livenessProbe: + initialDelaySeconds: {{ .Values.replica.livenessProbe.initialDelaySeconds }} + periodSeconds: {{ .Values.replica.livenessProbe.periodSeconds }} + timeoutSeconds: {{ .Values.replica.livenessProbe.timeoutSeconds }} + successThreshold: {{ .Values.replica.livenessProbe.successThreshold }} + failureThreshold: {{ .Values.replica.livenessProbe.failureThreshold}} + exec: + command: + - sh + - -c + - /health/ping_liveness_local.sh {{ .Values.replica.livenessProbe.timeoutSeconds }} + {{- else if .Values.replica.customLivenessProbe }} + livenessProbe: {{- toYaml .Values.replica.customLivenessProbe | nindent 12 }} + {{- end }} + {{- if .Values.replica.readinessProbe.enabled }} + readinessProbe: + initialDelaySeconds: {{ .Values.replica.readinessProbe.initialDelaySeconds }} + periodSeconds: {{ .Values.replica.readinessProbe.periodSeconds }} + timeoutSeconds: {{ .Values.replica.readinessProbe.timeoutSeconds }} + successThreshold: {{ .Values.replica.readinessProbe.successThreshold }} + failureThreshold: {{ .Values.replica.readinessProbe.failureThreshold }} + exec: + command: + - sh + - -c + - /health/ping_readiness_local.sh {{ .Values.replica.livenessProbe.timeoutSeconds }} + {{- else if .Values.replica.customReadinessProbe }} + readinessProbe: {{- toYaml .Values.replica.customReadinessProbe | nindent 12 }} + {{- end }} + {{- if .Values.replica.resources }} + resources: {{- toYaml .Values.replica.resources | nindent 12 }} + {{- end }} + volumeMounts: + - name: start-scripts + mountPath: /opt/bitnami/scripts/start-scripts + - name: health + mountPath: /health + {{- if .Values.auth.usePasswordFiles }} + - name: redis-password + mountPath: /opt/bitnami/redis/secrets/ + {{- end }} + - name: redis-data + mountPath: {{ .Values.replica.persistence.path }} + subPath: {{ .Values.replica.persistence.subPath }} + - name: config + mountPath: /opt/bitnami/redis/mounted-etc + - name: redis-tmp-conf + mountPath: /opt/bitnami/redis/etc + - name: tmp + mountPath: /tmp + {{- if .Values.tls.enabled }} + - name: redis-certificates + mountPath: /opt/bitnami/redis/certs + readOnly: true + {{- end }} + {{- if .Values.replica.extraVolumeMounts }} + {{- include "common.tplvalues.render" ( dict "value" .Values.replica.extraVolumeMounts "context" $ ) | nindent 12 }} + {{- end }} + lifecycle: + preStop: + exec: + command: + - /bin/bash + - -c + - /opt/bitnami/scripts/start-scripts/prestop-redis.sh + - name: sentinel + image: {{ template "redis.sentinel.image" . }} + imagePullPolicy: {{ .Values.sentinel.image.pullPolicy | quote }} + {{- if .Values.sentinel.lifecycleHooks }} + lifecycle: {{- include "common.tplvalues.render" (dict "value" .Values.sentinel.lifecycleHooks "context" $) | nindent 12 }} + {{- end }} + {{- if .Values.sentinel.containerSecurityContext.enabled }} + securityContext: {{- omit .Values.sentinel.containerSecurityContext "enabled" | toYaml | nindent 12 }} + {{- end }} + {{- if .Values.sentinel.command }} + command: {{- include "common.tplvalues.render" (dict "value" .Values.sentinel.command "context" $) | nindent 12 }} + {{- else }} + command: + - /bin/bash + {{- end }} + {{- if .Values.sentinel.args }} + args: {{- include "common.tplvalues.render" (dict "value" .Values.sentinel.args "context" $) | nindent 12 }} + {{- else }} + args: + - -c + - /opt/bitnami/scripts/start-scripts/start-sentinel.sh + {{- end }} + env: + - name: BITNAMI_DEBUG + value: {{ ternary "true" "false" .Values.sentinel.image.debug | quote }} + {{- if .Values.auth.enabled }} + {{- if .Values.auth.usePasswordFiles }} + - name: REDIS_PASSWORD_FILE + value: "/opt/bitnami/redis/secrets/redis-password" + {{- else }} + - name: REDIS_PASSWORD + valueFrom: + secretKeyRef: + name: {{ template "redis.secretName" . }} + key: {{ template "redis.secretPasswordKey" . }} + {{- end }} + {{- else }} + - name: ALLOW_EMPTY_PASSWORD + value: "yes" + {{- end }} + - name: REDIS_SENTINEL_TLS_ENABLED + value: {{ ternary "yes" "no" .Values.tls.enabled | quote }} + {{- if .Values.tls.enabled }} + - name: REDIS_SENTINEL_TLS_PORT_NUMBER + value: {{ .Values.sentinel.containerPort | quote }} + - name: REDIS_SENTINEL_TLS_AUTH_CLIENTS + value: {{ ternary "yes" "no" .Values.tls.authClients | quote }} + - name: REDIS_SENTINEL_TLS_CERT_FILE + value: {{ template "redis.tlsCert" . }} + - name: REDIS_SENTINEL_TLS_KEY_FILE + value: {{ template "redis.tlsCertKey" . }} + - name: REDIS_SENTINEL_TLS_CA_FILE + value: {{ template "redis.tlsCACert" . }} + {{- if .Values.tls.dhParamsFilename }} + - name: REDIS_SENTINEL_TLS_DH_PARAMS_FILE + value: {{ template "redis.tls.dhParamsFilename" . }} + {{- end }} + {{- else }} + - name: REDIS_SENTINEL_PORT + value: {{ .Values.sentinel.containerPort | quote }} + {{- end }} + ports: + - name: redis-sentinel + containerPort: {{ .Values.sentinel.containerPort }} + {{- if .Values.sentinel.livenessProbe.enabled }} + livenessProbe: + initialDelaySeconds: {{ .Values.sentinel.livenessProbe.initialDelaySeconds }} + periodSeconds: {{ .Values.sentinel.livenessProbe.periodSeconds }} + timeoutSeconds: {{ .Values.sentinel.livenessProbe.timeoutSeconds }} + successThreshold: {{ .Values.sentinel.livenessProbe.successThreshold }} + failureThreshold: {{ .Values.sentinel.livenessProbe.failureThreshold }} + exec: + command: + - sh + - -c + - /health/ping_sentinel.sh {{ .Values.sentinel.livenessProbe.timeoutSeconds }} + {{- else if .Values.sentinel.customLivenessProbe }} + livenessProbe: {{- toYaml .Values.sentinel.customLivenessProbe | nindent 12 }} + {{- end }} + {{- if .Values.sentinel.readinessProbe.enabled}} + readinessProbe: + initialDelaySeconds: {{ .Values.sentinel.readinessProbe.initialDelaySeconds }} + periodSeconds: {{ .Values.sentinel.readinessProbe.periodSeconds }} + timeoutSeconds: {{ .Values.sentinel.readinessProbe.timeoutSeconds }} + successThreshold: {{ .Values.sentinel.readinessProbe.successThreshold }} + failureThreshold: {{ .Values.sentinel.readinessProbe.failureThreshold }} + exec: + command: + - sh + - -c + - /health/ping_sentinel.sh {{ .Values.sentinel.livenessProbe.timeoutSeconds }} + {{- else if .Values.sentinel.customReadinessProbe }} + readinessProbe: {{- toYaml .Values.sentinel.customReadinessProbe | nindent 12 }} + {{- end }} + lifecycle: + preStop: + exec: + command: + - /bin/bash + - -c + - /opt/bitnami/scripts/start-scripts/prestop-sentinel.sh + {{- if .Values.sentinel.resources }} + resources: {{- toYaml .Values.sentinel.resources | nindent 12 }} + {{- end }} + volumeMounts: + - name: start-scripts + mountPath: /opt/bitnami/scripts/start-scripts + - name: health + mountPath: /health + {{- if .Values.auth.usePasswordFiles }} + - name: redis-password + mountPath: /opt/bitnami/redis/secrets/ + {{- end }} + - name: redis-data + mountPath: {{ .Values.replica.persistence.path }} + subPath: {{ .Values.replica.persistence.subPath }} + - name: config + mountPath: /opt/bitnami/redis-sentinel/mounted-etc + - name: sentinel-tmp-conf + mountPath: /opt/bitnami/redis-sentinel/etc + {{- if .Values.tls.enabled }} + - name: redis-certificates + mountPath: /opt/bitnami/redis/certs + readOnly: true + {{- end }} + {{- if .Values.sentinel.extraVolumeMounts }} + {{- include "common.tplvalues.render" ( dict "value" .Values.sentinel.extraVolumeMounts "context" $ ) | nindent 12 }} + {{- end }} + {{- if .Values.metrics.enabled }} + - name: metrics + image: {{ template "redis.metrics.image" . }} + imagePullPolicy: {{ .Values.metrics.image.pullPolicy | quote }} + {{- if .Values.metrics.containerSecurityContext.enabled }} + securityContext: {{- omit .Values.metrics.containerSecurityContext "enabled" | toYaml | nindent 12 }} + {{- end }} + command: + - /bin/bash + - -c + - | + if [[ -f '/secrets/redis-password' ]]; then + export REDIS_PASSWORD=$(cat /secrets/redis-password) + fi + redis_exporter{{- range $key, $value := .Values.metrics.extraArgs }} --{{ $key }}={{ $value }}{{- end }} + env: + - name: REDIS_ALIAS + value: {{ template "common.names.fullname" . }} + {{- if .Values.auth.enabled }} + - name: REDIS_USER + value: default + {{- if (not .Values.auth.usePasswordFiles) }} + - name: REDIS_PASSWORD + valueFrom: + secretKeyRef: + name: {{ template "redis.secretName" . }} + key: {{ template "redis.secretPasswordKey" . }} + {{- end }} + {{- end }} + {{- if .Values.tls.enabled }} + - name: REDIS_ADDR + value: rediss://{{ .Values.metrics.redisTargetHost }}:{{ .Values.replica.containerPort }} + {{- if .Values.tls.authClients }} + - name: REDIS_EXPORTER_TLS_CLIENT_KEY_FILE + value: {{ template "redis.tlsCertKey" . }} + - name: REDIS_EXPORTER_TLS_CLIENT_CERT_FILE + value: {{ template "redis.tlsCert" . }} + {{- end }} + - name: REDIS_EXPORTER_TLS_CA_CERT_FILE + value: {{ template "redis.tlsCACert" . }} + {{- end }} + ports: + - name: metrics + containerPort: 9121 + {{- if .Values.metrics.resources }} + resources: {{- toYaml .Values.metrics.resources | nindent 12 }} + {{- end }} + volumeMounts: + {{- if .Values.auth.usePasswordFiles }} + - name: redis-password + mountPath: /secrets/ + {{- end }} + {{- if .Values.tls.enabled }} + - name: redis-certificates + mountPath: /opt/bitnami/redis/certs + readOnly: true + {{- end }} + {{- end }} + {{- if .Values.metrics.sentinel.enabled }} + - name: sentinel-metrics + image: {{ include "redis.metrics.sentinel.image" . }} + imagePullPolicy: {{ .Values.metrics.sentinel.image.pullPolicy | quote }} + {{- if .Values.metrics.sentinel.containerSecurityContext.enabled }} + securityContext: {{- omit .Values.metrics.sentinel.containerSecurityContext "enabled" | toYaml | nindent 12 }} + {{- end }} + command: + - redis_sentinel_exporter{{- range $key, $value := .Values.metrics.sentinel.extraArgs }} --{{ $key }}={{ $value }}{{- end }} + env: + {{- if and .Values.auth.sentinel (and .Values.auth.enabled (not .Values.auth.usePasswordFiles)) }} + - name: SENTINEL_PASSWORD + valueFrom: + secretKeyRef: + name: {{ include "redis.secretName" . }} + key: {{ include "redis.secretPasswordKey" . }} + {{- end }} + {{- if and .Values.auth.sentinel .Values.auth.enabled .Values.auth.usePasswordFiles }} + - name: SENTINEL_PASSWORD_FILE + value: /secrets/redis-password + {{- end }} + ports: + - name: sentinelmetrics + containerPort: 9355 + {{- if .Values.metrics.sentinel.resources }} + resources: {{- include "common.tplvalues.render" (dict "value" .Values.metrics.sentinel.resources "context" $) | nindent 12 }} + {{- end }} + {{- if and .Values.auth.sentinel .Values.auth.enabled .Values.auth.usePasswordFiles }} + volumeMounts: + - name: redis-password + mountPath: /secrets/ + {{- end }} + {{- end }} + {{- if .Values.replica.sidecars }} + {{- include "common.tplvalues.render" (dict "value" .Values.replica.sidecars "context" $) | nindent 8 }} + {{- end }} + {{- $needsVolumePermissions := and .Values.volumePermissions.enabled .Values.replica.persistence.enabled .Values.replica.podSecurityContext.enabled .Values.replica.containerSecurityContext.enabled }} + {{- if or .Values.replica.initContainers $needsVolumePermissions .Values.sysctl.enabled }} + initContainers: + {{- if .Values.replica.initContainers }} + {{- include "common.tplvalues.render" (dict "value" .Values.replica.initContainers "context" $) | nindent 8 }} + {{- end }} + {{- if $needsVolumePermissions }} + - name: volume-permissions + image: {{ include "redis.volumePermissions.image" . }} + imagePullPolicy: {{ .Values.volumePermissions.image.pullPolicy | quote }} + command: + - /bin/bash + - -ec + - | + {{- if eq ( toString ( .Values.volumePermissions.containerSecurityContext.runAsUser )) "auto" }} + chown -R `id -u`:`id -G | cut -d " " -f2` {{ .Values.replica.persistence.path }} + {{- else }} + chown -R {{ .Values.replica.containerSecurityContext.runAsUser }}:{{ .Values.replica.podSecurityContext.fsGroup }} {{ .Values.replica.persistence.path }} + {{- end }} + {{- if eq ( toString ( .Values.volumePermissions.containerSecurityContext.runAsUser )) "auto" }} + securityContext: {{- omit .Values.volumePermissions.containerSecurityContext "runAsUser" | toYaml | nindent 12 }} + {{- else }} + securityContext: {{- .Values.volumePermissions.containerSecurityContext | toYaml | nindent 12 }} + {{- end }} + {{- if .Values.volumePermissions.resources }} + resources: {{- toYaml .Values.volumePermissions.resources | nindent 12 }} + {{- end }} + volumeMounts: + - name: redis-data + mountPath: {{ .Values.replica.persistence.path }} + subPath: {{ .Values.replica.persistence.subPath }} + {{- end }} + {{- if .Values.sysctl.enabled }} + - name: init-sysctl + image: {{ include "redis.sysctl.image" . }} + imagePullPolicy: {{ default "" .Values.sysctl.image.pullPolicy | quote }} + securityContext: + privileged: true + runAsUser: 0 + {{- if .Values.sysctl.command }} + command: {{- include "common.tplvalues.render" (dict "value" .Values.sysctl.command "context" $) | nindent 12 }} + {{- end }} + {{- if .Values.sysctl.resources }} + resources: {{- toYaml .Values.sysctl.resources | nindent 12 }} + {{- end }} + {{- if .Values.sysctl.mountHostSys }} + volumeMounts: + - name: host-sys + mountPath: /host-sys + {{- end }} + {{- end }} + {{- end }} + volumes: + - name: start-scripts + configMap: + name: {{ printf "%s-scripts" (include "common.names.fullname" .) }} + defaultMode: 0755 + - name: health + configMap: + name: {{ printf "%s-health" (include "common.names.fullname" .) }} + defaultMode: 0755 + {{- if .Values.auth.usePasswordFiles }} + - name: redis-password + secret: + secretName: {{ template "redis.secretName" . }} + items: + - key: {{ template "redis.secretPasswordKey" . }} + path: redis-password + {{- end }} + - name: config + configMap: + name: {{ include "redis.configmapName" . }} + {{- if .Values.sysctl.mountHostSys }} + - name: host-sys + hostPath: + path: /sys + {{- end }} + - name: sentinel-tmp-conf + emptyDir: {} + - name: redis-tmp-conf + emptyDir: {} + - name: tmp + emptyDir: {} + {{- if .Values.replica.extraVolumes }} + {{- include "common.tplvalues.render" ( dict "value" .Values.replica.extraVolumes "context" $ ) | nindent 8 }} + {{- end }} + {{- if .Values.sentinel.extraVolumes }} + {{- include "common.tplvalues.render" ( dict "value" .Values.sentinel.extraVolumes "context" $ ) | nindent 8 }} + {{- end }} + {{- if .Values.tls.enabled }} + - name: redis-certificates + secret: + secretName: {{ required "A secret containing the certificates for the TLS traffic is required when TLS in enabled" .Values.tls.certificatesSecret }} + defaultMode: 256 + {{- end }} + {{- if not .Values.replica.persistence.enabled }} + - name: redis-data + emptyDir: {} + {{- else }} + volumeClaimTemplates: + - metadata: + name: redis-data + labels: {{- include "common.labels.matchLabels" . | nindent 10 }} + app.kubernetes.io/component: node + {{- if .Values.replica.persistence.annotations }} + annotations: {{- toYaml .Values.replica.persistence.annotations | nindent 10 }} + {{- end }} + spec: + accessModes: + {{- range .Values.replica.persistence.accessModes }} + - {{ . | quote }} + {{- end }} + resources: + requests: + storage: {{ .Values.replica.persistence.size | quote }} + {{- if .Values.replica.persistence.selector }} + selector: {{- include "common.tplvalues.render" ( dict "value" .Values.replica.persistence.selector "context" $) | nindent 10 }} + {{- end }} + {{- include "common.storage.class" (dict "persistence" .Values.replica.persistence "global" .Values.global) | nindent 8 }} + {{- end }} +{{- end }} diff --git a/chart/deps/redis/templates/serviceaccount.yaml b/chart/deps/redis/templates/serviceaccount.yaml new file mode 100644 index 0000000..4f97490 --- /dev/null +++ b/chart/deps/redis/templates/serviceaccount.yaml @@ -0,0 +1,20 @@ +{{- if .Values.serviceAccount.create }} +apiVersion: v1 +kind: ServiceAccount +metadata: + name: {{ template "redis.serviceAccountName" . }} + namespace: {{ .Release.Namespace | quote }} + labels: {{- include "common.labels.standard" . | nindent 4 }} + {{- if .Values.commonLabels }} + {{- include "common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }} + {{- end }} + {{- if or .Values.commonAnnotations .Values.serviceAccount.annotations }} + annotations: + {{- if or .Values.commonAnnotations }} + {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }} + {{- end }} + {{- if .Values.serviceAccount.annotations }} + {{- include "common.tplvalues.render" ( dict "value" .Values.serviceAccount.annotations "context" $ ) | nindent 4 }} + {{- end }} + {{- end }} +{{- end }} diff --git a/chart/deps/redis/templates/servicemonitor.yaml b/chart/deps/redis/templates/servicemonitor.yaml new file mode 100644 index 0000000..fc142d6 --- /dev/null +++ b/chart/deps/redis/templates/servicemonitor.yaml @@ -0,0 +1,85 @@ +{{- if and .Values.metrics.enabled .Values.metrics.serviceMonitor.enabled }} +apiVersion: monitoring.coreos.com/v1 +kind: ServiceMonitor +metadata: + name: {{ template "common.names.fullname" . }} + {{- if .Values.metrics.serviceMonitor.namespace }} + namespace: {{ .Values.metrics.serviceMonitor.namespace }} + {{- else }} + namespace: {{ .Release.Namespace | quote }} + {{- end }} + labels: {{- include "common.labels.standard" . | nindent 4 }} + {{- if .Values.metrics.serviceMonitor.additionalLabels }} + {{- include "common.tplvalues.render" (dict "value" .Values.metrics.serviceMonitor.additionalLabels "context" $) | nindent 4 }} + {{- end }} + {{- if .Values.commonLabels }} + {{- include "common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }} + {{- end }} + {{- if .Values.commonAnnotations }} + annotations: {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }} + {{- end }} +spec: + endpoints: + - port: tcp-metrics + {{- if .Values.metrics.serviceMonitor.interval }} + interval: {{ .Values.metrics.serviceMonitor.interval }} + {{- end }} + {{- if .Values.metrics.serviceMonitor.scrapeTimeout }} + scrapeTimeout: {{ .Values.metrics.serviceMonitor.scrapeTimeout }} + {{- end }} + {{- if .Values.metrics.serviceMonitor.honorLabels }} + honorLabels: {{ .Values.metrics.serviceMonitor.honorLabels }} + {{- end }} + {{- if .Values.metrics.serviceMonitor.relabellings }} + metricRelabelings: {{- toYaml .Values.metrics.serviceMonitor.relabellings | nindent 6 }} + {{- end }} + namespaceSelector: + matchNames: + - {{ .Release.Namespace }} + selector: + matchLabels: {{- include "common.labels.matchLabels" . | nindent 6 }} + app.kubernetes.io/component: metrics +{{- if .Values.metrics.sentinel.enabled }} +--- +apiVersion: monitoring.coreos.com/v1 +kind: ServiceMonitor +metadata: + name: {{ printf "%s-sentinel" (include "common.names.fullname" .) }} + {{- if .Values.metrics.serviceMonitor.namespace }} + namespace: {{ .Values.metrics.serviceMonitor.namespace }} + {{- else }} + namespace: {{ .Release.Namespace | quote }} + {{- end }} + labels: {{- include "common.labels.standard" . | nindent 4 }} + {{- if .Values.metrics.serviceMonitor.additionalLabels }} + {{- include "common.tplvalues.render" (dict "value" .Values.metrics.serviceMonitor.additionalLabels "context" $) | nindent 4 }} + {{- end }} + {{- if .Values.commonLabels }} + {{- include "common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }} + {{- end }} + {{- if .Values.commonAnnotations }} + annotations: {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }} + {{- end }} +spec: + endpoints: + - port: tcp-metrics + {{- if .Values.metrics.serviceMonitor.interval }} + interval: {{ .Values.metrics.serviceMonitor.interval }} + {{- end }} + {{- if .Values.metrics.serviceMonitor.scrapeTimeout }} + scrapeTimeout: {{ .Values.metrics.serviceMonitor.scrapeTimeout }} + {{- end }} + {{- if .Values.metrics.serviceMonitor.honorLabels }} + honorLabels: {{ .Values.metrics.serviceMonitor.honorLabels }} + {{- end }} + {{- if .Values.metrics.serviceMonitor.relabellings }} + metricRelabelings: {{- toYaml .Values.metrics.serviceMonitor.relabellings | nindent 6 }} + {{- end }} + namespaceSelector: + matchNames: + - {{ .Release.Namespace }} + selector: + matchLabels: {{- include "common.labels.matchLabels" . | nindent 6 }} + app.kubernetes.io/component: sentinel-metrics +{{- end }} +{{- end }} diff --git a/chart/deps/redis/values.schema.json b/chart/deps/redis/values.schema.json index 3188d0c..7781b63 100644 --- a/chart/deps/redis/values.schema.json +++ b/chart/deps/redis/values.schema.json @@ -2,39 +2,30 @@ "$schema": "http://json-schema.org/schema#", "type": "object", "properties": { - "usePassword": { - "type": "boolean", - "title": "Use password authentication", - "form": true - }, - "password": { + "architecture": { "type": "string", - "title": "Password", + "title": "Redis architecture", "form": true, - "description": "Defaults to a random 10-character alphanumeric string if not set", - "hidden": { - "value": false, - "path": "usePassword" - } + "description": "Allowed values: `standalone` or `replication`" }, - "cluster": { + "auth": { "type": "object", - "title": "Cluster Settings", + "title": "Authentication configuration", "form": true, "properties": { "enabled": { "type": "boolean", "form": true, - "title": "Enable master-slave", - "description": "Enable master-slave architecture" + "title": "Use password authentication" }, - "slaveCount": { - "type": "integer", - "title": "Slave Replicas", + "password": { + "type": "string", + "title": "Redis password", "form": true, + "description": "Defaults to a random 10-character alphanumeric string if not set", "hidden": { "value": false, - "path": "cluster/enabled" + "path": "auth/enabled" } } } @@ -67,31 +58,28 @@ "value": false, "path": "master/persistence/enabled" } - }, - "matchLabels": { - "type": "object", - "title": "Persistent Match Labels Selector" - }, - "matchExpressions": { - "type": "object", - "title": "Persistent Match Expressions Selector" } } } } }, - "slave": { + "replica": { "type": "object", - "title": "Slave replicas settings", + "title": "Redis replicas settings", "form": true, "hidden": { - "value": false, - "path": "cluster/enabled" + "value": "standalone", + "path": "architecture" }, "properties": { + "replicaCount": { + "type": "integer", + "form": true, + "title": "Number of Redis replicas" + }, "persistence": { "type": "object", - "title": "Persistence for slave replicas", + "title": "Persistence for Redis replicas", "form": true, "properties": { "enabled": { @@ -110,16 +98,8 @@ "sliderUnit": "Gi", "hidden": { "value": false, - "path": "slave/persistence/enabled" + "path": "replica/persistence/enabled" } - }, - "matchLabels": { - "type": "object", - "title": "Persistent Match Labels Selector" - }, - "matchExpressions": { - "type": "object", - "title": "Persistent Match Expressions Selector" } } } diff --git a/chart/deps/redis/values.yaml b/chart/deps/redis/values.yaml index 2bbdac4..7f51a00 100644 --- a/chart/deps/redis/values.yaml +++ b/chart/deps/redis/values.yaml @@ -17,22 +17,58 @@ istio: monitoring: enabled: false - - - ## Global Docker image parameters ## Please, note that this will override the image parameters, including dependencies, configured to use the global value -## Current available global Docker image parameters: imageRegistry and imagePullSecrets +## Current available global Docker image parameters: imageRegistry, imagePullSecrets and storageClass + +## @param global.imageRegistry Global Docker image registry +## @param global.imagePullSecrets Global Docker registry secret names as an array +## @param global.storageClass Global StorageClass for Persistent Volume(s) +## @param global.redis.password Global Redis(TM) password (overrides `auth.password`) ## global: # imageRegistry: myRegistryName imagePullSecrets: - private-registry - # storageClass: myStorageClass + # imageRegistry: + # storageClass: redis: {} + # password: + +## @section Common parameters -## Bitnami Redis(TM) image version +## @param kubeVersion Override Kubernetes version +## +kubeVersion: +## @param nameOverride String to partially override common.names.fullname +## +nameOverride: +## @param fullnameOverride String to fully override common.names.fullname +## +fullnameOverride: +## @param commonLabels Labels to add to all deployed objects +## +commonLabels: {} +## @param commonAnnotations Annotations to add to all deployed objects +## +commonAnnotations: {} +## @param clusterDomain Kubernetes cluster domain name +## +clusterDomain: cluster.local +## @param extraDeploy Array of extra objects to deploy with the release +## +extraDeploy: [] + +## @section Redis(TM) Image parameters + +## Bitnami Redis(TM) image ## ref: https://hub.docker.com/r/bitnami/redis/tags/ +## @param image.registry Redis(TM) image registry +## @param image.repository Redis(TM) image repository +## @param image.tag Redis(TM) image tag (immutable tags are recommended) +## @param image.pullPolicy Redis(TM) image pull policy +## @param image.pullSecrets Redis(TM) image pull secrets +## @param image.debug Enable image debug mode ## image: registry: registry1.dso.mil @@ -40,7 +76,7 @@ image: ## Bitnami Redis(TM) image tag ## ref: https://github.com/bitnami/bitnami-docker-redis#supported-tags-and-respective-dockerfile-links ## - tag: 6.0.10 + tag: 6.2.2 ## Specify a imagePullPolicy ## Defaults to 'Always' if image tag is 'latest', else set to 'IfNotPresent' ## ref: http://kubernetes.io/docs/user-guide/images/#pre-pulling-images @@ -49,79 +85,113 @@ image: ## Optionally specify an array of imagePullSecrets. ## Secrets must be manually created in the namespace. ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/ + ## e.g: + ## pullSecrets: + ## - myRegistryKeySecretName ## # pullSecrets: # - private-registry + ## Enable debug mode + ## + debug: false -## String to partially override redis.fullname template (will maintain the release name) -## -# nameOverride: +## @section Redis(TM) common configuration parameters +## https://github.com/bitnami/bitnami-docker-redis#configuration -## String to fully override redis.fullname template +## @param architecture Redis(TM) architecture. Allowed values: `standalone` or `replication` ## -# fullnameOverride: - -## Cluster settings +architecture: replication +## Redis(TM) Authentication parameters +## ref: https://github.com/bitnami/bitnami-docker-redis#setting-the-server-password-on-first-run ## -cluster: +auth: + ## @param auth.enabled Enable password authentication + ## enabled: true - slaveCount: 2 - -## Use redis sentinel in the redis pod. This will disable the master and slave services and -## create one redis service with ports to the sentinel and the redis instances -## -sentinel: - enabled: false - ## Require password authentication on the sentinel itself - ## ref: https://redis.io/topics/sentinel + ## @param auth.sentinel Enable password authentication on sentinels too ## - usePassword: true - ## Bitnami Redis(TM) Sentintel image version - ## ref: https://hub.docker.com/r/bitnami/redis-sentinel/tags/ + sentinel: true + ## @param auth.password Redis(TM) password + ## Defaults to a random 10-character alphanumeric string if not set ## - image: - registry: docker.io - repository: bitnami/redis-sentinel - ## Bitnami Redis(TM) image tag - ## ref: https://github.com/bitnami/bitnami-docker-redis-sentinel#supported-tags-and-respective-dockerfile-links - ## - tag: 6.0.12-debian-10-r0 - ## Specify a imagePullPolicy - ## Defaults to 'Always' if image tag is 'latest', else set to 'IfNotPresent' - ## ref: http://kubernetes.io/docs/user-guide/images/#pre-pulling-images - ## - pullPolicy: IfNotPresent - ## Optionally specify an array of imagePullSecrets. - ## Secrets must be manually created in the namespace. - ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/ - ## - # pullSecrets: - # - myRegistryKeySecretName - masterSet: mymaster - initialCheckTimeout: 5 - quorum: 2 - downAfterMilliseconds: 20000 - failoverTimeout: 18000 - parallelSyncs: 1 - port: 26379 - - ## Delay seconds when cleaning nodes IPs - ## When starting it will clean the sentiles IP (RESET "*") in all the nodes - ## This is the delay time before sending the command to the next node + password: "" + ## @param auth.existingSecret The name of an existing secret with Redis(TM) credentials + ## NOTE: When it's set, the previous `auth.password` parameter is ignored ## - cleanDelaySeconds: 5 + existingSecret: + ## @param auth.existingSecretPasswordKey Password key to be retrieved from existing secret + ## NOTE: ignored unless `auth.existingSecret` parameter is set + ## + existingSecretPasswordKey: + ## @param auth.usePasswordFiles Mount credentials as files instead of using an environment variable + ## + usePasswordFiles: false +## @skip commonConfiguration +## ref: https://redis.io/topics/config +## +commonConfiguration: |- + # Enable AOF https://redis.io/topics/persistence#append-only-file + appendonly yes + # Disable RDB persistence, AOF persistence already enabled. + save "" +## @param existingConfigmap The name of an existing ConfigMap with your custom configuration for Redis(TM) nodes +## +existingConfigmap: + +## @section Redis(TM) master configuration parameters - ## Additional Redis(TM) configuration for the sentinel nodes +master: + ## @param master.configuration Configuration for Redis(TM) master nodes ## ref: https://redis.io/topics/config ## - configmap: - ## Enable or disable static sentinel IDs for each replicas - ## If disabled each sentinel will generate a random id at startup - ## If enabled, each replicas will have a constant ID on each start-up + configuration: + ## @param master.disableCommands [array] Array with Redis(TM) commands to disable on master nodes + ## Commands will be completely disabled by renaming each to an empty string. + ## ref: https://redis.io/topics/security#disabling-of-specific-commands ## - staticID: false - ## Configure extra options for Redis(TM) Sentinel liveness and readiness probes - ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-probes/#configure-probes) + disableCommands: + - FLUSHDB + - FLUSHALL + ## @param master.command Override default container command (useful when using custom images) + ## + command: [] + ## @param master.args Override default container args (useful when using custom images) + ## + args: [] + ## @param master.preExecCmds Additional commands to run prior to starting Redis(TM) master + ## + preExecCmds: [] + ## @param master.extraFlags Array with additional command line flags for Redis(TM) master + ## e.g: + ## extraFlags: + ## - "--maxmemory-policy volatile-ttl" + ## - "--repl-backlog-size 1024mb" + ## + extraFlags: [] + ## @param master.extraEnvVars Array with extra environment variables to add to Redis(TM) master nodes + ## e.g: + ## extraEnvVars: + ## - name: FOO + ## value: "bar" + ## + extraEnvVars: [] + ## @param master.extraEnvVarsCM Name of existing ConfigMap containing extra env vars for Redis(TM) master nodes + ## + extraEnvVarsCM: + ## @param master.extraEnvVarsSecret Name of existing Secret containing extra env vars for Redis(TM) master nodes + ## + extraEnvVarsSecret: + ## @param master.containerPort Container port to open on Redis(TM) master nodes + ## + containerPort: 6379 + ## Configure extra options for Redis(TM) containers' liveness and readiness probes + ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-probes/#configure-probes + ## @param master.livenessProbe.enabled Enable livenessProbe on Redis(TM) master nodes + ## @param master.livenessProbe.initialDelaySeconds Initial delay seconds for livenessProbe + ## @param master.livenessProbe.periodSeconds Period seconds for livenessProbe + ## @param master.livenessProbe.timeoutSeconds Timeout seconds for livenessProbe + ## @param master.livenessProbe.failureThreshold Failure threshold for livenessProbe + ## @param master.livenessProbe.successThreshold Success threshold for livenessProbe ## livenessProbe: enabled: true @@ -130,6 +200,13 @@ sentinel: timeoutSeconds: 5 successThreshold: 1 failureThreshold: 5 + ## @param master.readinessProbe.enabled Enable readinessProbe on Redis(TM) master nodes + ## @param master.readinessProbe.initialDelaySeconds Initial delay seconds for readinessProbe + ## @param master.readinessProbe.periodSeconds Period seconds for readinessProbe + ## @param master.readinessProbe.timeoutSeconds Timeout seconds for readinessProbe + ## @param master.readinessProbe.failureThreshold Failure threshold for readinessProbe + ## @param master.readinessProbe.successThreshold Success threshold for readinessProbe + ## readinessProbe: enabled: true initialDelaySeconds: 5 @@ -137,260 +214,288 @@ sentinel: timeoutSeconds: 1 successThreshold: 1 failureThreshold: 5 + ## @param master.customLivenessProbe Custom livenessProbe that overrides the default one + ## customLivenessProbe: {} + ## @param master.customReadinessProbe Custom readinessProbe that overrides the default one + ## customReadinessProbe: {} - ## Redis(TM) Sentinel resource requests and limits + ## Redis(TM) master resource requests and limits ## ref: http://kubernetes.io/docs/user-guide/compute-resources/ - # resources: - # requests: - # memory: 256Mi - # cpu: 100m - ## Redis(TM) Sentinel Service properties + ## @param master.resources.limits The resources limits for the Redis(TM) master containers + ## @param master.resources.requests The requested resources for the Redis(TM) master containers ## - service: - ## Redis(TM) Sentinel Service type - ## - type: ClusterIP - sentinelPort: 26379 - redisPort: 6379 - - ## External traffic policy (when service type is LoadBalancer) - ## ref: https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip - ## - externalTrafficPolicy: Cluster - - ## Specify the nodePort value for the LoadBalancer and NodePort service types. - ## ref: https://kubernetes.io/docs/concepts/services-networking/service/#type-nodeport - ## - # sentinelNodePort: - # redisNodePort: - - ## Provide any additional annotations which may be required. This can be used to - ## set the LoadBalancer service type to internal only. - ## ref: https://kubernetes.io/docs/concepts/services-networking/service/#internal-load-balancer + resources: + requests: + memory: 256Mi + cpu: 100m + limits: + memory: 256Mi + cpu: 100m + ## Configure Pods Security Context + ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-pod + ## @param master.podSecurityContext.enabled Enabled Redis(TM) master pods' Security Context + ## @param master.podSecurityContext.fsGroup Set Redis(TM) master pod's Security Context fsGroup + ## + podSecurityContext: + enabled: true + fsGroup: 1001 + ## Configure Container Security Context + ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-pod + ## @param master.containerSecurityContext.enabled Enabled Redis(TM) master containers' Security Context + ## @param master.containerSecurityContext.runAsUser Set Redis(TM) master containers' Security Context runAsUser + ## + containerSecurityContext: + enabled: true + runAsUser: 1001 + ## @param master.schedulerName Alternate scheduler for Redis(TM) master pods + ## ref: https://kubernetes.io/docs/tasks/administer-cluster/configure-multiple-schedulers/ + ## + schedulerName: + ## @param master.updateStrategy.type Redis(TM) master statefulset strategy type + ## @skip master.updateStrategy.rollingUpdate + ## ref: https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/#update-strategies + ## + updateStrategy: + ## StrategyType + ## Can be set to RollingUpdate or OnDelete ## - annotations: {} - labels: {} - loadBalancerIP: - - ## Additional commands to run prior to starting Redis(TM) node with sentinel + type: RollingUpdate + rollingUpdate: {} + ## @param master.priorityClassName Redis(TM) master pods' priorityClassName ## - preExecCmds: "" - - ## An array to add extra env var to the sentinel node configurations - ## For example: - ## extraEnvVars: - ## - name: name - ## value: value - ## - name: other_name - ## valueFrom: - ## fieldRef: - ## fieldPath: fieldPath + priorityClassName: "" + ## @param master.hostAliases Redis(TM) master pods host aliases + ## https://kubernetes.io/docs/concepts/services-networking/add-entries-to-pod-etc-hosts-with-host-aliases/ ## - extraEnvVars: [] - - ## ConfigMap with extra env vars: + hostAliases: [] + ## @param master.podLabels Extra labels for Redis(TM) master pods + ## ref: https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/ ## - extraEnvVarsCM: [] - - ## Secret with extra env vars: + podLabels: {} + ## @param master.podAnnotations Annotations for Redis(TM) master pods + ## ref: https://kubernetes.io/docs/concepts/overview/working-with-objects/annotations/ ## - extraEnvVarsSecret: [] - -## Specifies the Kubernetes Cluster's Domain Name. -## -clusterDomain: cluster.local - -networkPolicy: - ## Specifies whether a NetworkPolicy should be created + podAnnotations: {} + ## @param master.shareProcessNamespace Share a single process namespace between all of the containers in Redis(TM) master pods + ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/share-process-namespace/ ## - enabled: false - - ## The Policy model to apply. When set to false, only pods with the correct - ## client label will have network access to the port Redis(TM) is listening - ## on. When true, Redis(TM) will accept connections from any source - ## (with the correct destination port). + shareProcessNamespace: false + ## @param master.podAffinityPreset Pod affinity preset. Ignored if `master.affinity` is set. Allowed values: `soft` or `hard` + ## ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#inter-pod-affinity-and-anti-affinity ## - # allowExternal: true - - ## Allow connections from other namespaces. Just set label for namespace and set label for pods (optional). + podAffinityPreset: "" + ## @param master.podAntiAffinityPreset Pod anti-affinity preset. Ignored if `master.affinity` is set. Allowed values: `soft` or `hard` + ## ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#inter-pod-affinity-and-anti-affinity ## - ingressNSMatchLabels: {} - ingressNSPodMatchLabels: {} - -serviceAccount: - ## Specifies whether a ServiceAccount should be created + podAntiAffinityPreset: soft + ## Node master.affinity preset + ## ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity ## - create: false - ## The name of the ServiceAccount to use. - ## If not set and create is true, a name is generated using the fullname template + nodeAffinityPreset: + ## @param master.nodeAffinityPreset.type Node affinity preset type. Ignored if `master.affinity` is set. Allowed values: `soft` or `hard` + ## + type: "" + ## @param master.nodeAffinityPreset.key Node label key to match. Ignored if `master.affinity` is set + ## + key: "" + ## @param master.nodeAffinityPreset.values Node label values to match. Ignored if `master.affinity` is set + ## E.g. + ## values: + ## - e2e-az1 + ## - e2e-az2 + ## + values: [] + ## @param master.affinity Affinity for Redis(TM) master pods assignment + ## ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity + ## NOTE: `master.podAffinityPreset`, `master.podAntiAffinityPreset`, and `master.nodeAffinityPreset` will be ignored when it's set ## - name: - ## Add annotations to service account - # annotations: - # iam.gke.io/gcp-service-account: "sa@project.iam.gserviceaccount.com" - -rbac: - ## Specifies whether RBAC resources should be created + affinity: {} + ## @param master.nodeSelector Node labels for Redis(TM) master pods assignment + ## ref: https://kubernetes.io/docs/user-guide/node-selection/ ## - create: false - - role: - ## Rules to create. It follows the role specification - # rules: - # - apiGroups: - # - extensions - # resources: - # - podsecuritypolicies - # verbs: - # - use - # resourceNames: - # - gce.unprivileged - rules: [] - -## Redis(TM) pod Security Context -## -securityContext: - enabled: true - fsGroup: 1001 - ## sysctl settings for master and slave pods + nodeSelector: {} + ## @param master.tolerations Tolerations for Redis(TM) master pods assignment + ## ref: https://kubernetes.io/docs/concepts/configuration/taint-and-toleration/ ## - ## Uncomment the setting below to increase the net.core.somaxconn value + tolerations: [] + ## @param master.spreadConstraints Spread Constraints for Redis(TM) master pod assignment + ## ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/ + ## E.g. + ## spreadConstraints: + ## - maxSkew: 1 + ## topologyKey: node + ## whenUnsatisfiable: DoNotSchedule ## - # sysctls: - # - name: net.core.somaxconn - # value: "10000" - -## Container Security Context -## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ -## -containerSecurityContext: - enabled: true - runAsUser: 1001 - -## Use password authentication -## -usePassword: true -## Redis(TM) password (both master and slave) -## Defaults to a random 10-character alphanumeric string if not set and usePassword is true -## ref: https://github.com/bitnami/bitnami-docker-redis#setting-the-server-password-on-first-run -## -password: "password" -## Use existing secret (ignores previous password) -# existingSecret: -## Password key to be retrieved from Redis(TM) secret -## -# existingSecretPasswordKey: - -## Mount secrets as files instead of environment variables -## -usePasswordFile: false - -## Persist data to a persistent volume (Redis(TM) Master) -## -persistence: - ## A manually managed Persistent Volume and Claim - ## Requires persistence.enabled: true - ## If defined, PVC must be created manually before volume will be bound + spreadConstraints: {} + ## @param master.lifecycleHooks for the Redis(TM) master container(s) to automate configuration before or after startup + ## + lifecycleHooks: {} + ## @param master.extraVolumes Optionally specify extra list of additional volumes for the Redis(TM) master pod(s) + ## + extraVolumes: [] + ## @param master.extraVolumeMounts Optionally specify extra list of additional volumeMounts for the Redis(TM) master container(s) + ## + extraVolumeMounts: [] + ## @param master.sidecars Add additional sidecar containers to the Redis(TM) master pod(s) + ## e.g: + ## sidecars: + ## - name: your-image-name + ## image: your-image + ## imagePullPolicy: Always + ## ports: + ## - name: portname + ## containerPort: 1234 + ## + sidecars: {} + ## @param master.initContainers Add additional init containers to the Redis(TM) master pod(s) + ## ref: https://kubernetes.io/docs/concepts/workloads/pods/init-containers/ + ## e.g: + ## initContainers: + ## - name: your-image-name + ## image: your-image + ## imagePullPolicy: Always + ## command: ['sh', '-c', 'echo "hello world"'] + ## + initContainers: {} + ## Persistence parameters + ## ref: http://kubernetes.io/docs/user-guide/persistent-volumes/ ## - existingClaim: - -# Redis(TM) port -redisPort: 6379 + persistence: + ## @param master.persistence.enabled Enable persistence on Redis(TM) master nodes using Persistent Volume Claims + ## + enabled: true + ## @param master.persistence.path The path the volume will be mounted at on Redis(TM) master containers + ## NOTE: Useful when using different Redis(TM) images + ## + path: /data + ## @param master.persistence.subPath The subdirectory of the volume to mount on Redis(TM) master containers + ## NOTE: Useful in dev environments + ## + subPath: "" + ## @param master.persistence.storageClass Persistent Volume storage class + ## If defined, storageClassName: + ## If set to "-", storageClassName: "", which disables dynamic provisioning + ## If undefined (the default) or set to null, no storageClassName spec is set, choosing the default provisioner + ## + storageClass: + ## @param master.persistence.accessModes [array] Persistent Volume access modes + ## + accessModes: + - ReadWriteOnce + ## @param master.persistence.size Persistent Volume size + ## + size: 8Gi + ## @param master.persistence.annotations Additional custom annotations for the PVC + ## + annotations: {} + ## @param master.persistence.selector Additional labels to match for the PVC + ## e.g: + ## selector: + ## matchLabels: + ## app: my-app + ## + selector: {} + ## @param master.persistence.existingClaim Use a existing PVC which must be created manually before bound + ## NOTE: requires master.persistence.enabled: true + ## + existingClaim: + ## Redis(TM) master service parameters + ## + service: + ## @param master.service.type Redis(TM) master service type + ## + type: ClusterIP + ## @param master.service.port Redis(TM) master service port + ## + port: 6379 + ## @param master.service.nodePort Node port for Redis(TM) master + ## ref: https://kubernetes.io/docs/concepts/services-networking/service/#type-nodeport + ## NOTE: choose port between <30000-32767> + ## + nodePort: + ## @param master.service.externalTrafficPolicy Redis(TM) master service external traffic policy + ## ref: https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip + ## + externalTrafficPolicy: Cluster + ## @param master.service.clusterIP Redis(TM) master service Cluster IP + ## + clusterIP: + ## @param master.service.loadBalancerIP Redis(TM) master service Load Balancer IP + ## ref: https://kubernetes.io/docs/concepts/services-networking/service/#internal-load-balancer + ## + loadBalancerIP: + ## @param master.service.loadBalancerSourceRanges Redis(TM) master service Load Balancer sources + ## https://kubernetes.io/docs/tasks/access-application-cluster/configure-cloud-provider-firewall/#restrict-access-for-loadbalancer-service + ## e.g. + ## loadBalancerSourceRanges: + ## - 10.10.10.0/24 + ## + loadBalancerSourceRanges: [] + ## @param master.service.annotations Additional custom annotations for Redis(TM) master service + ## + annotations: {} + ## @param master.terminationGracePeriodSeconds Integer setting the termination grace period for the redis-master pods + ## + terminationGracePeriodSeconds: 30 -## -## TLS configuration -## -tls: - # Enable TLS traffic - enabled: false - # - # Whether to require clients to authenticate or not. - authClients: true - # - # Name of the Secret that contains the certificates - certificatesSecret: - # - # Certificate filename - certFilename: - # - # Certificate Key filename - certKeyFilename: - # - # CA Certificate filename - certCAFilename: - # - # File containing DH params (in order to support DH based ciphers) - # dhParamsFilename: +## @section Redis(TM) replicas configuration parameters -## -## Redis(TM) Master parameters -## -master: - ## Redis(TM) command arguments +replica: + ## @param replica.replicaCount Number of Redis(TM) replicas to deploy ## - ## Can be used to specify command line arguments, for example: - ## Note `exec` is prepended to command + replicaCount: 3 + ## @param replica.configuration Configuration for Redis(TM) replicas nodes + ## ref: https://redis.io/topics/config ## - command: "/run.sh" - ## Additional commands to run prior to starting Redis(TM) + configuration: + ## @param replica.disableCommands [array] Array with Redis(TM) commands to disable on replicas nodes + ## Commands will be completely disabled by renaming each to an empty string. + ## ref: https://redis.io/topics/security#disabling-of-specific-commands ## - preExecCmds: "" - ## Additional Redis(TM) configuration for the master nodes - ## ref: https://redis.io/topics/config + disableCommands: + - FLUSHDB + - FLUSHALL + ## @param replica.command Override default container command (useful when using custom images) ## - configmap: - ## Deployment pod host aliases - ## https://kubernetes.io/docs/concepts/services-networking/add-entries-to-pod-etc-hosts-with-host-aliases/ + command: [] + ## @param replica.args Override default container args (useful when using custom images) ## - hostAliases: [] - ## Redis(TM) additional command line flags + args: [] + ## @param replica.preExecCmds Additional commands to run prior to starting Redis(TM) replicas ## - ## Can be used to specify command line flags, for example: + preExecCmds: [] + ## @param replica.extraFlags Array with additional command line flags for Redis(TM) replicas + ## e.g: ## extraFlags: ## - "--maxmemory-policy volatile-ttl" ## - "--repl-backlog-size 1024mb" ## extraFlags: [] - ## Comma-separated list of Redis(TM) commands to disable + ## @param replica.extraEnvVars Array with extra environment variables to add to Redis(TM) replicas nodes + ## e.g: + ## extraEnvVars: + ## - name: FOO + ## value: "bar" ## - ## Can be used to disable Redis(TM) commands for security reasons. - ## Commands will be completely disabled by renaming each to an empty string. - ## ref: https://redis.io/topics/security#disabling-of-specific-commands + extraEnvVars: [] + ## @param replica.extraEnvVarsCM Name of existing ConfigMap containing extra env vars for Redis(TM) replicas nodes ## - disableCommands: - - FLUSHDB - - FLUSHALL - - ## Redis(TM) Master additional pod labels and annotations - ## ref: https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/ + extraEnvVarsCM: + ## @param replica.extraEnvVarsSecret Name of existing Secret containing extra env vars for Redis(TM) replicas nodes ## - podLabels: {} - podAnnotations: {} - - ## Redis(TM) Master resource requests and limits - ## ref: http://kubernetes.io/docs/user-guide/compute-resources/ - resources: - requests: - memory: 256Mi - cpu: 100m - limits: - memory: 256Mi - cpu: 100m - ## Use an alternate scheduler, e.g. "stork". - ## ref: https://kubernetes.io/docs/tasks/administer-cluster/configure-multiple-schedulers/ + extraEnvVarsSecret: + ## @param replica.containerPort Container port to open on Redis(TM) replicas nodes ## - # schedulerName: - - # Enable shared process namespace in a pod. - # If set to false (default), each container will run in separate namespace, redis will have PID=1. - # If set to true, the /pause will run as init process and will reap any zombie PIDs, - # for example, generated by a custom exec probe running longer than a probe timeoutSeconds. - # Enable this only if customLivenessProbe or customReadinessProbe is used and zombie PIDs are accumulating. - # Ref: https://kubernetes.io/docs/tasks/configure-pod-container/share-process-namespace/ - shareProcessNamespace: false - ## Configure extra options for Redis(TM) Master liveness and readiness probes - ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-probes/#configure-probes) + containerPort: 6379 + ## Configure extra options for Redis(TM) containers' liveness and readiness probes + ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-probes/#configure-probes + ## @param replica.livenessProbe.enabled Enable livenessProbe on Redis(TM) replicas nodes + ## @param replica.livenessProbe.initialDelaySeconds Initial delay seconds for livenessProbe + ## @param replica.livenessProbe.periodSeconds Period seconds for livenessProbe + ## @param replica.livenessProbe.timeoutSeconds Timeout seconds for livenessProbe + ## @param replica.livenessProbe.failureThreshold Failure threshold for livenessProbe + ## @param replica.livenessProbe.successThreshold Success threshold for livenessProbe ## livenessProbe: enabled: true @@ -399,6 +504,13 @@ master: timeoutSeconds: 5 successThreshold: 1 failureThreshold: 5 + ## @param replica.readinessProbe.enabled Enable readinessProbe on Redis(TM) replicas nodes + ## @param replica.readinessProbe.initialDelaySeconds Initial delay seconds for readinessProbe + ## @param replica.readinessProbe.periodSeconds Period seconds for readinessProbe + ## @param replica.readinessProbe.timeoutSeconds Timeout seconds for readinessProbe + ## @param replica.readinessProbe.failureThreshold Failure threshold for readinessProbe + ## @param replica.readinessProbe.successThreshold Success threshold for readinessProbe + ## readinessProbe: enabled: true initialDelaySeconds: 5 @@ -406,384 +518,721 @@ master: timeoutSeconds: 1 successThreshold: 1 failureThreshold: 5 - - ## Configure custom probes for images other images like - ## rhscl/redis-32-rhel7 rhscl/redis-5-rhel7 - ## Only used if readinessProbe.enabled: false / livenessProbe.enabled: false - ## - # customLivenessProbe: - # tcpSocket: - # port: 6379 - # initialDelaySeconds: 10 - # periodSeconds: 5 - # customReadinessProbe: - # initialDelaySeconds: 30 - # periodSeconds: 10 - # timeoutSeconds: 5 - # exec: - # command: - # - "container-entrypoint" - # - "bash" - # - "-c" - # - "redis-cli set liveness-probe \"`date`\" | grep OK" + ## @param replica.customLivenessProbe Custom livenessProbe that overrides the default one + ## customLivenessProbe: {} + ## @param replica.customReadinessProbe Custom readinessProbe that overrides the default one + ## customReadinessProbe: {} - - ## Redis(TM) Master Node selectors and tolerations for pod assignment - ## ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#nodeselector - ## ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#taints-and-tolerations-beta-feature + ## Redis(TM) replicas resource requests and limits + ## ref: http://kubernetes.io/docs/user-guide/compute-resources/ + ## @param replica.resources.limits The resources limits for the Redis(TM) replicas containers + ## @param replica.resources.requests The requested resources for the Redis(TM) replicas containers ## - # nodeSelector: {"beta.kubernetes.io/arch": "amd64"} - # tolerations: [] - ## Redis(TM) Master pod/node affinity/anti-affinity + resources: + requests: + memory: 256Mi + cpu: 100m + limits: + memory: 256Mi + cpu: 100m + ## Configure Pods Security Context + ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-pod + ## @param replica.podSecurityContext.enabled Enabled Redis(TM) replicas pods' Security Context + ## @param replica.podSecurityContext.fsGroup Set Redis(TM) replicas pod's Security Context fsGroup ## - affinity: {} - - ## Redis(TM) Master Service properties + podSecurityContext: + enabled: true + fsGroup: 1001 + ## Configure Container Security Context + ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-pod + ## @param replica.containerSecurityContext.enabled Enabled Redis(TM) replicas containers' Security Context + ## @param replica.containerSecurityContext.runAsUser Set Redis(TM) replicas containers' Security Context runAsUser ## - service: - ## Redis(TM) Master Service type + containerSecurityContext: + enabled: true + runAsUser: 1001 + ## @param replica.schedulerName Alternate scheduler for Redis(TM) replicas pods + ## ref: https://kubernetes.io/docs/tasks/administer-cluster/configure-multiple-schedulers/ + ## + schedulerName: + ## @param replica.updateStrategy.type Redis(TM) replicas statefulset strategy type + ## @skip replica.updateStrategy.rollingUpdate + ## ref: https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/#update-strategies + ## + updateStrategy: + ## StrategyType + ## Can be set to RollingUpdate or OnDelete ## - type: ClusterIP - port: 6379 - - ## External traffic policy (when service type is LoadBalancer) - ## ref: https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip + type: RollingUpdate + rollingUpdate: {} + ## @param replica.priorityClassName Redis(TM) replicas pods' priorityClassName + ## + priorityClassName: "" + ## @param replica.hostAliases Redis(TM) replicas pods host aliases + ## https://kubernetes.io/docs/concepts/services-networking/add-entries-to-pod-etc-hosts-with-host-aliases/ + ## + hostAliases: [] + ## @param replica.podLabels Extra labels for Redis(TM) replicas pods + ## ref: https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/ + ## + podLabels: {} + ## @param replica.podAnnotations Annotations for Redis(TM) replicas pods + ## ref: https://kubernetes.io/docs/concepts/overview/working-with-objects/annotations/ + ## + podAnnotations: {} + ## @param replica.shareProcessNamespace Share a single process namespace between all of the containers in Redis(TM) replicas pods + ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/share-process-namespace/ + ## + shareProcessNamespace: false + ## @param replica.podAffinityPreset Pod affinity preset. Ignored if `replica.affinity` is set. Allowed values: `soft` or `hard` + ## ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#inter-pod-affinity-and-anti-affinity + ## + podAffinityPreset: "" + ## @param replica.podAntiAffinityPreset Pod anti-affinity preset. Ignored if `replica.affinity` is set. Allowed values: `soft` or `hard` + ## ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#inter-pod-affinity-and-anti-affinity + ## + podAntiAffinityPreset: soft + ## Node affinity preset + ## ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity + ## + nodeAffinityPreset: + ## @param replica.nodeAffinityPreset.type Node affinity preset type. Ignored if `replica.affinity` is set. Allowed values: `soft` or `hard` ## - externalTrafficPolicy: Cluster - - ## Specify the nodePort value for the LoadBalancer and NodePort service types. - ## ref: https://kubernetes.io/docs/concepts/services-networking/service/#type-nodeport + type: "" + ## @param replica.nodeAffinityPreset.key Node label key to match. Ignored if `replica.affinity` is set ## - # nodePort: - - ## Provide any additional annotations which may be required. This can be used to - ## set the LoadBalancer service type to internal only. - ## ref: https://kubernetes.io/docs/concepts/services-networking/service/#internal-load-balancer + key: "" + ## @param replica.nodeAffinityPreset.values Node label values to match. Ignored if `replica.affinity` is set + ## E.g. + ## values: + ## - e2e-az1 + ## - e2e-az2 ## - annotations: {} - labels: {} - loadBalancerIP: - # loadBalancerSourceRanges: ["10.0.0.0/8"] - - ## Enable persistence using Persistent Volume Claims + values: [] + ## @param replica.affinity Affinity for Redis(TM) replicas pods assignment + ## ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity + ## NOTE: `replica.podAffinityPreset`, `replica.podAntiAffinityPreset`, and `replica.nodeAffinityPreset` will be ignored when it's set + ## + affinity: {} + ## @param replica.nodeSelector Node labels for Redis(TM) replicas pods assignment + ## ref: https://kubernetes.io/docs/user-guide/node-selection/ + ## + nodeSelector: {} + ## @param replica.tolerations Tolerations for Redis(TM) replicas pods assignment + ## ref: https://kubernetes.io/docs/concepts/configuration/taint-and-toleration/ + ## + tolerations: [] + ## @param replica.spreadConstraints Spread Constraints for Redis(TM) replicas pod assignment + ## ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/ + ## E.g. + ## spreadConstraints: + ## - maxSkew: 1 + ## topologyKey: node + ## whenUnsatisfiable: DoNotSchedule + ## + spreadConstraints: {} + ## @param replica.lifecycleHooks for the Redis(TM) replica container(s) to automate configuration before or after startup + ## + lifecycleHooks: {} + ## @param replica.extraVolumes Optionally specify extra list of additional volumes for the Redis(TM) replicas pod(s) + ## + extraVolumes: [] + ## @param replica.extraVolumeMounts Optionally specify extra list of additional volumeMounts for the Redis(TM) replicas container(s) + ## + extraVolumeMounts: [] + ## @param replica.sidecars Add additional sidecar containers to the Redis(TM) replicas pod(s) + ## e.g: + ## sidecars: + ## - name: your-image-name + ## image: your-image + ## imagePullPolicy: Always + ## ports: + ## - name: portname + ## containerPort: 1234 + ## + sidecars: {} + ## @param replica.initContainers Add additional init containers to the Redis(TM) replicas pod(s) + ## ref: https://kubernetes.io/docs/concepts/workloads/pods/init-containers/ + ## e.g: + ## initContainers: + ## - name: your-image-name + ## image: your-image + ## imagePullPolicy: Always + ## command: ['sh', '-c', 'echo "hello world"'] + ## + initContainers: {} + ## Persistence Parameters ## ref: http://kubernetes.io/docs/user-guide/persistent-volumes/ ## persistence: + ## @param replica.persistence.enabled Enable persistence on Redis(TM) replicas nodes using Persistent Volume Claims + ## enabled: true - ## The path the volume will be mounted at, useful when using different - ## Redis(TM) images. + ## @param replica.persistence.path The path the volume will be mounted at on Redis(TM) replicas containers + ## NOTE: Useful when using different Redis(TM) images ## path: /data - ## The subdirectory of the volume to mount to, useful in dev environments - ## and one PV for multiple services. + ## @param replica.persistence.subPath The subdirectory of the volume to mount on Redis(TM) replicas containers + ## NOTE: Useful in dev environments ## subPath: "" - ## redis data Persistent Volume Storage Class + ## @param replica.persistence.storageClass Persistent Volume storage class ## If defined, storageClassName: ## If set to "-", storageClassName: "", which disables dynamic provisioning - ## If undefined (the default) or set to null, no storageClassName spec is - ## set, choosing the default provisioner. (gp2 on AWS, standard on - ## GKE, AWS & OpenStack) + ## If undefined (the default) or set to null, no storageClassName spec is set, choosing the default provisioner + ## + storageClass: + ## @param replica.persistence.accessModes [array] Persistent Volume access modes ## - # storageClass: "-" accessModes: - ReadWriteOnce + ## @param replica.persistence.size Persistent Volume size + ## size: 8Gi - ## Persistent Volume selectors - ## https://kubernetes.io/docs/concepts/storage/persistent-volumes/#selector - ## - matchLabels: {} - matchExpressions: {} - volumes: - # - name: volume_name - # emptyDir: {} - - ## Update strategy, can be set to RollingUpdate or onDelete by default. - ## https://kubernetes.io/docs/tutorials/stateful-application/basic-stateful-set/#updating-statefulsets - ## - statefulset: - labels: {} + ## @param replica.persistence.annotations Additional custom annotations for the PVC + ## annotations: {} - updateStrategy: RollingUpdate - ## Partition update strategy - ## https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/#partitions - # rollingUpdatePartition: - volumeClaimTemplates: - labels: {} - annotations: {} - - ## Redis(TM) Master pod priorityClassName - ## - priorityClassName: {} - - ## An array to add extra env vars - ## For example: - ## extraEnvVars: - ## - name: name - ## value: value - ## - name: other_name - ## valueFrom: - ## fieldRef: - ## fieldPath: fieldPath - ## - extraEnvVars: [] - - ## ConfigMap with extra env vars: - ## - extraEnvVarsCM: [] - - ## Secret with extra env vars: - ## - extraEnvVarsSecret: [] - -## -## Redis(TM) Slave properties -## Note: service.type is a mandatory parameter -## The rest of the parameters are either optional or, if undefined, will inherit those declared in Redis(TM) Master -## -slave: - ## Slave Service properties + ## @param replica.persistence.selector Additional labels to match for the PVC + ## e.g: + ## selector: + ## matchLabels: + ## app: my-app + ## + selector: {} + ## Redis(TM) replicas service parameters ## service: - ## Redis(TM) Slave Service type + ## @param replica.service.type Redis(TM) replicas service type ## type: ClusterIP - ## Redis(TM) port + ## @param replica.service.port Redis(TM) replicas service port ## port: 6379 - - ## External traffic policy (when service type is LoadBalancer) + ## @param replica.service.nodePort Node port for Redis(TM) replicas + ## ref: https://kubernetes.io/docs/concepts/services-networking/service/#type-nodeport + ## NOTE: choose port between <30000-32767> + ## + nodePort: + ## @param replica.service.externalTrafficPolicy Redis(TM) replicas service external traffic policy ## ref: https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip ## - externalTrafficPolicy: Cluster - - ## Specify the nodePort value for the LoadBalancer and NodePort service types. - ## ref: https://kubernetes.io/docs/concepts/services-networking/service/#type-nodeport + externalTrafficPolicy: Cluster + ## @param replica.service.clusterIP Redis(TM) replicas service Cluster IP + ## + clusterIP: + ## @param replica.service.loadBalancerIP Redis(TM) replicas service Load Balancer IP + ## ref: https://kubernetes.io/docs/concepts/services-networking/service/#internal-load-balancer + ## + loadBalancerIP: + ## @param replica.service.loadBalancerSourceRanges Redis(TM) replicas service Load Balancer sources + ## https://kubernetes.io/docs/tasks/access-application-cluster/configure-cloud-provider-firewall/#restrict-access-for-loadbalancer-service + ## e.g. + ## loadBalancerSourceRanges: + ## - 10.10.10.0/24 + ## + loadBalancerSourceRanges: [] + ## @param replica.service.annotations Additional custom annotations for Redis(TM) replicas service + ## + annotations: {} + ## @param replica.terminationGracePeriodSeconds Integer setting the termination grace period for the redis-replicas pods + ## + terminationGracePeriodSeconds: 30 + + ## Redis(TM) Master resource requests and limits + ## ref: http://kubernetes.io/docs/user-guide/compute-resources/ + resources: + requests: + memory: 256Mi + cpu: 100m + limits: + memory: 256Mi + cpu: 100m + ## Use an alternate scheduler, e.g. "stork". + ## ref: https://kubernetes.io/docs/tasks/administer-cluster/configure-multiple-schedulers/ +## @section Redis(TM) Sentinel configuration parameters + +sentinel: + ## @param sentinel.enabled Use Redis(TM) Sentinel on Redis(TM) pods. + ## IMPORTANT: this will disable the master and replicas services and + ## create a single Redis(TM) service exposing both the Redis and Sentinel ports + ## + enabled: false + ## Bitnami Redis(TM) Sentinel image version + ## ref: https://hub.docker.com/r/bitnami/redis-sentinel/tags/ + ## @param sentinel.image.registry Redis(TM) Sentinel image registry + ## @param sentinel.image.repository Redis(TM) Sentinel image repository + ## @param sentinel.image.tag Redis(TM) Sentinel image tag (immutable tags are recommended) + ## @param sentinel.image.pullPolicy Redis(TM) Sentinel image pull policy + ## @param sentinel.image.pullSecrets Redis(TM) Sentinel image pull secrets + ## @param sentinel.image.debug Enable image debug mode + ## + image: + registry: docker.io + repository: bitnami/redis-sentinel + tag: 6.2.2-debian-10-r2 + ## Specify a imagePullPolicy + ## Defaults to 'Always' if image tag is 'latest', else set to 'IfNotPresent' + ## ref: http://kubernetes.io/docs/user-guide/images/#pre-pulling-images + ## + pullPolicy: IfNotPresent + ## Optionally specify an array of imagePullSecrets. + ## Secrets must be manually created in the namespace. + ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/ + ## e.g: + ## pullSecrets: + ## - myRegistryKeySecretName ## - # nodePort: - - ## Provide any additional annotations which may be required. This can be used to - ## set the LoadBalancer service type to internal only. - ## ref: https://kubernetes.io/docs/concepts/services-networking/service/#internal-load-balancer + pullSecrets: [] + ## Enable debug mode ## - annotations: {} - labels: {} - loadBalancerIP: - # loadBalancerSourceRanges: ["10.0.0.0/8"] - - ## Redis(TM) slave port + debug: false + ## @param sentinel.masterSet Master set name ## - port: 6379 - ## Deployment pod host aliases - ## https://kubernetes.io/docs/concepts/services-networking/add-entries-to-pod-etc-hosts-with-host-aliases/ + masterSet: mymaster + ## @param sentinel.quorum Sentinel Quorum ## - hostAliases: [] - ## Can be used to specify command line arguments, for example: - ## Note `exec` is prepended to command + quorum: 2 + ## Sentinel timing restrictions + ## @param sentinel.downAfterMilliseconds Timeout for detecting a Redis(TM) node is down + ## @param sentinel.failoverTimeout Timeout for performing a election failover + ## @param sentinel.cleanDelaySeconds Delay seconds when cleaning nodes IPs + # + downAfterMilliseconds: 60000 + failoverTimeout: 18000 + cleanDelaySeconds: 5 + ## @param sentinel.parallelSyncs Number of replicas that can be reconfigured in parallel to use the new master after a failover ## - command: "/run.sh" - ## Additional commands to run prior to starting Redis(TM) + parallelSyncs: 1 + ## @param sentinel.staticID Enable static Sentinel IDs for each replica + ## If disabled each sentinel will generate a random id at startup + ## If enabled, each replicas will have a constant ID on each start-up ## - preExecCmds: "" - ## Additional Redis(TM) configuration for the slave nodes - ## ref: https://redis.io/topics/config + staticID: false + ## @param sentinel.configuration Configuration for Redis(TM) Sentinel nodes + ## ref: https://redis.io/topics/sentinel ## - configmap: - ## Redis(TM) extra flags + configuration: + ## @param sentinel.command Override default container command (useful when using custom images) ## - extraFlags: [] - ## List of Redis(TM) commands to disable + command: [] + ## @param sentinel.args Override default container args (useful when using custom images) ## - disableCommands: - - FLUSHDB - - FLUSHALL - - ## Redis(TM) Slave pod/node affinity/anti-affinity + args: [] + ## @param sentinel.preExecCmds Additional commands to run prior to starting Redis(TM) Sentinel ## - affinity: {} - - ## Kubernetes Spread Constraints for pod assignment - ## ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/ + preExecCmds: [] + ## @param sentinel.containerPort Container port to open on Redis(TM) Sentinel nodes ## - # - maxSkew: 1 - # topologyKey: node - # whenUnsatisfiable: DoNotSchedule - spreadConstraints: {} - - # Enable shared process namespace in a pod. - # If set to false (default), each container will run in separate namespace, redis will have PID=1. - # If set to true, the /pause will run as init process and will reap any zombie PIDs, - # for example, generated by a custom exec probe running longer than a probe timeoutSeconds. - # Enable this only if customLivenessProbe or customReadinessProbe is used and zombie PIDs are accumulating. - # Ref: https://kubernetes.io/docs/tasks/configure-pod-container/share-process-namespace/ - shareProcessNamespace: false - ## Configure extra options for Redis(TM) Slave liveness and readiness probes - ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-probes/#configure-probes) + containerPort: 26379 + ## Configure extra options for Redis(TM) containers' liveness and readiness probes + ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-probes/#configure-probes + ## @param sentinel.livenessProbe.enabled Enable livenessProbe on Redis(TM) Sentinel nodes + ## @param sentinel.livenessProbe.initialDelaySeconds Initial delay seconds for livenessProbe + ## @param sentinel.livenessProbe.periodSeconds Period seconds for livenessProbe + ## @param sentinel.livenessProbe.timeoutSeconds Timeout seconds for livenessProbe + ## @param sentinel.livenessProbe.failureThreshold Failure threshold for livenessProbe + ## @param sentinel.livenessProbe.successThreshold Success threshold for livenessProbe ## livenessProbe: enabled: true - initialDelaySeconds: 30 - periodSeconds: 10 + initialDelaySeconds: 5 + periodSeconds: 5 timeoutSeconds: 5 successThreshold: 1 failureThreshold: 5 + ## @param sentinel.readinessProbe.enabled Enable readinessProbe on Redis(TM) Sentinel nodes + ## @param sentinel.readinessProbe.initialDelaySeconds Initial delay seconds for readinessProbe + ## @param sentinel.readinessProbe.periodSeconds Period seconds for readinessProbe + ## @param sentinel.readinessProbe.timeoutSeconds Timeout seconds for readinessProbe + ## @param sentinel.readinessProbe.failureThreshold Failure threshold for readinessProbe + ## @param sentinel.readinessProbe.successThreshold Success threshold for readinessProbe + ## readinessProbe: enabled: true initialDelaySeconds: 5 - periodSeconds: 10 - timeoutSeconds: 10 + periodSeconds: 5 + timeoutSeconds: 1 successThreshold: 1 failureThreshold: 5 - - ## Configure custom probes for images other images like - ## rhscl/redis-32-rhel7 rhscl/redis-5-rhel7 - ## Only used if readinessProbe.enabled: false / livenessProbe.enabled: false - ## - # customLivenessProbe: - # tcpSocket: - # port: 6379 - # initialDelaySeconds: 10 - # periodSeconds: 5 - # customReadinessProbe: - # initialDelaySeconds: 30 - # periodSeconds: 10 - # timeoutSeconds: 5 - # exec: - # command: - # - "container-entrypoint" - # - "bash" - # - "-c" - # - "redis-cli set liveness-probe \"`date`\" | grep OK" + ## @param sentinel.customLivenessProbe Custom livenessProbe that overrides the default one + ## customLivenessProbe: {} + ## @param sentinel.customReadinessProbe Custom readinessProbe that overrides the default one + ## customReadinessProbe: {} - - ## Redis(TM) slave Resource + ## Redis(TM) Sentinel resource requests and limits + ## ref: http://kubernetes.io/docs/user-guide/compute-resources/ + ## @param sentinel.resources.limits The resources limits for the Redis(TM) Sentinel containers + ## @param sentinel.resources.requests The requested resources for the Redis(TM) Sentinel containers + ## resources: - requests: - memory: 256Mi - cpu: 100m - limits: - memory: 256Mi - cpu: 100m - - ## Redis(TM) slave selectors and tolerations for pod assignment - # nodeSelector: {"beta.kubernetes.io/arch": "amd64"} - # tolerations: [] - - ## Use an alternate scheduler, e.g. "stork". - ## ref: https://kubernetes.io/docs/tasks/administer-cluster/configure-multiple-schedulers/ + limits: {} + requests: {} + ## Configure Container Security Context + ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-pod + ## @param sentinel.containerSecurityContext.enabled Enabled Redis(TM) Sentinel containers' Security Context + ## @param sentinel.containerSecurityContext.runAsUser Set Redis(TM) Sentinel containers' Security Context runAsUser + ## + containerSecurityContext: + enabled: true + runAsUser: 1001 + ## @param sentinel.lifecycleHooks for the Redis(TM) sentinel container(s) to automate configuration before or after startup ## - # schedulerName: - - ## Redis(TM) slave pod Annotation and Labels + lifecycleHooks: {} + ## @param sentinel.extraVolumes Optionally specify extra list of additional volumes for the Redis(TM) Sentinel ## - podLabels: {} - podAnnotations: {} - - ## Redis(TM) slave pod priorityClassName - priorityClassName: {} - - ## Enable persistence using Persistent Volume Claims - ## ref: http://kubernetes.io/docs/user-guide/persistent-volumes/ + extraVolumes: [] + ## @param sentinel.extraVolumeMounts Optionally specify extra list of additional volumeMounts for the Redis(TM) Sentinel container(s) ## - persistence: - enabled: true - ## The path the volume will be mounted at, useful when using different - ## Redis(TM) images. + extraVolumeMounts: [] + ## Redis(TM) Sentinel service parameters + ## + service: + ## @param sentinel.service.type Redis(TM) Sentinel service type ## - path: /data - ## The subdirectory of the volume to mount to, useful in dev environments - ## and one PV for multiple services. + type: ClusterIP + ## @param sentinel.service.port Redis(TM) service port for Redis(TM) ## - subPath: "" - ## redis data Persistent Volume Storage Class - ## If defined, storageClassName: - ## If set to "-", storageClassName: "", which disables dynamic provisioning - ## If undefined (the default) or set to null, no storageClassName spec is - ## set, choosing the default provisioner. (gp2 on AWS, standard on - ## GKE, AWS & OpenStack) + port: 6379 + ## @param sentinel.service.sentinelPort Redis(TM) service port for Sentinel ## - # storageClass: "-" - accessModes: - - ReadWriteOnce - size: 8Gi - ## Persistent Volume selectors - ## https://kubernetes.io/docs/concepts/storage/persistent-volumes/#selector + sentinelPort: 26379 + ## @param sentinel.service.nodePorts.redis Node port for Redis(TM) + ## @param sentinel.service.nodePorts.sentinel Node port for Sentinel + ## ref: https://kubernetes.io/docs/concepts/services-networking/service/#type-nodeport + ## NOTE: choose port between <30000-32767> + ## + nodePorts: + redis: + sentinel: + ## @param sentinel.service.externalTrafficPolicy Redis(TM) Sentinel service external traffic policy + ## ref: https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip + ## + externalTrafficPolicy: Cluster + ## @param sentinel.service.clusterIP Redis(TM) Sentinel service Cluster IP + ## + clusterIP: + ## @param sentinel.service.loadBalancerIP Redis(TM) Sentinel service Load Balancer IP + ## ref: https://kubernetes.io/docs/concepts/services-networking/service/#internal-load-balancer + ## + loadBalancerIP: + ## @param sentinel.service.loadBalancerSourceRanges Redis(TM) Sentinel service Load Balancer sources + ## https://kubernetes.io/docs/tasks/access-application-cluster/configure-cloud-provider-firewall/#restrict-access-for-loadbalancer-service + ## e.g. + ## loadBalancerSourceRanges: + ## - 10.10.10.0/24 + ## + loadBalancerSourceRanges: [] + ## @param sentinel.service.annotations Additional custom annotations for Redis(TM) Sentinel service ## - matchLabels: {} - matchExpressions: {} - - ## Update strategy, can be set to RollingUpdate or onDelete by default. - ## https://kubernetes.io/docs/tutorials/stateful-application/basic-stateful-set/#updating-statefulsets - ## - statefulset: - labels: {} annotations: {} - updateStrategy: RollingUpdate - ## Partition update strategy - ## https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/#partitions - # rollingUpdatePartition: - volumeClaimTemplates: - labels: {} - annotations: {} - - ## An array to add extra env vars - ## For example: - ## extraEnvVars: - ## - name: name - ## value: value - ## - name: other_name - ## valueFrom: - ## fieldRef: - ## fieldPath: fieldPath + ## @param sentinel.terminationGracePeriodSeconds Integer setting the termination grace period for the redis-node pods ## - extraEnvVars: [] + terminationGracePeriodSeconds: 30 - ## ConfigMap with extra env vars: - ## - extraEnvVarsCM: [] +## @section Other Parameters - ## Secret with extra env vars: +## Network Policy configuration +## ref: https://kubernetes.io/docs/concepts/services-networking/network-policies/ +## +networkPolicy: + ## @param networkPolicy.enabled Enable creation of NetworkPolicy resources ## - extraEnvVarsSecret: [] - -## Prometheus Exporter / Metrics + enabled: false + ## @param networkPolicy.allowExternal Don't require client label for connections + ## When set to false, only pods with the correct client label will have network access to the ports + ## Redis(TM) is listening on. When true, Redis(TM) will accept connections from any source + ## (with the correct destination port). + ## + allowExternal: true + ## @param networkPolicy.extraIngress Add extra ingress rules to the NetworkPolicy + ## e.g: + ## extraIngress: + ## - ports: + ## - port: 1234 + ## from: + ## - podSelector: + ## - matchLabels: + ## - role: frontend + ## - podSelector: + ## - matchExpressions: + ## - key: role + ## operator: In + ## values: + ## - frontend + ## + extraIngress: [] + ## @param networkPolicy.extraEgress Add extra ingress rules to the NetworkPolicy + ## e.g: + ## extraEgress: + ## - ports: + ## - port: 1234 + ## to: + ## - podSelector: + ## - matchLabels: + ## - role: frontend + ## - podSelector: + ## - matchExpressions: + ## - key: role + ## operator: In + ## values: + ## - frontend + ## + extraEgress: [] + ## @param networkPolicy.ingressNSMatchLabels Labels to match to allow traffic from other namespaces + ## @param networkPolicy.ingressNSPodMatchLabels Pod labels to match to allow traffic from other namespaces + ## + ingressNSMatchLabels: {} + ingressNSPodMatchLabels: {} +## PodSecurityPolicy configuration +## ref: https://kubernetes.io/docs/concepts/policy/pod-security-policy/ ## -metrics: +podSecurityPolicy: + ## @param podSecurityPolicy.create Specifies whether a PodSecurityPolicy should be created + ## + create: false +## RBAC configuration +## +rbac: + ## @param rbac.create Specifies whether RBAC resources should be created + ## + create: false + ## @param rbac.rules Custom RBAC rules to set + ## e.g: + ## rules: + ## - apiGroups: + ## - "" + ## resources: + ## - pods + ## verbs: + ## - get + ## - list + ## + rules: [] +## ServiceAccount configuration +## +serviceAccount: + ## @param serviceAccount.create Specifies whether a ServiceAccount should be created + ## + create: true + ## @param serviceAccount.name The name of the ServiceAccount to use. + ## If not set and create is true, a name is generated using the common.names.fullname template + ## + name: "" + ## @param serviceAccount.annotations Additional custom annotations for the ServiceAccount + ## + annotations: {} +## Redis(TM) Pod Disruption Budget configuration +## ref: https://kubernetes.io/docs/tasks/run-application/configure-pdb/ +## +pdb: + ## @param pdb.create Specifies whether a ServiceAccount should be created + ## + create: false + ## @param pdb.minAvailable Min number of pods that must still be available after the eviction + ## + minAvailable: 1 + ## @param pdb.maxUnavailable Max number of pods that can be unavailable after the eviction + ## + maxUnavailable: +## TLS configuration +## +tls: + ## @param tls.enabled Enable TLS traffic + ## enabled: false + ## @param tls.authClients Require clients to authenticate + ## + authClients: true + ## @param tls.certificatesSecret Then name of the existing secret that contains the TLS certificates + ## + certificatesSecret: + ## @param tls.certFilename Certificate filename + ## + certFilename: + ## @param tls.certKeyFilename Certificate Key filename + ## + certKeyFilename: + ## @param tls.certCAFilename CA Certificate filename + ## + certCAFilename: + ## @param tls.dhParamsFilename File containing DH params (in order to support DH based ciphers) + ## + dhParamsFilename: + +## @section Metrics Parameters +metrics: + ## @param metrics.enabled Start a sidecar prometheus exporter to expose Redis(TM) metrics + ## + enabled: false + ## Bitnami Redis(TM) Exporter image + ## ref: https://hub.docker.com/r/bitnami/redis-exporter/tags/ + ## @param metrics.image.registry Redis(TM) Exporter image registry + ## @param metrics.image.repository Redis(TM) Exporter image repository + ## @param metrics.image.tag Redis(TM) Redis(TM) Exporter image tag (immutable tags are recommended) + ## @param metrics.image.pullPolicy Redis(TM) Exporter image pull policy + ## @param metrics.image.pullSecrets Redis(TM) Exporter image pull secrets + ## image: registry: registry1.dso.mil repository: ironbank/bitnami/analytics/redis-exporter - tag: 1.6.1 + tag: 1.18.0 pullPolicy: Always ## Optionally specify an array of imagePullSecrets. ## Secrets must be manually created in the namespace. ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/ - ## - # pullSecrets: - # - private-registry + ## e.g: + ## pullSecrets: + ## - myRegistryKeySecretName ## Metrics exporter resource requests and limits ## ref: http://kubernetes.io/docs/user-guide/compute-resources/ ## - # resources: {} - - ## Extra arguments for Metrics exporter, for example: + redisTargetHost: "localhost" + ## @param metrics.extraArgs Extra arguments for Redis(TM) exporter, for example: + ## e.g.: ## extraArgs: ## check-keys: myKey,myOtherKey - # extraArgs: {} - - ## Metrics exporter pod Annotation and Labels + ## + extraArgs: {} + ## Configure Container Security Context + ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-pod + ## @param metrics.containerSecurityContext.enabled Enabled Redis(TM) exporter containers' Security Context + ## @param metrics.containerSecurityContext.runAsUser Set Redis(TM) exporter containers' Security Context runAsUser + ## + containerSecurityContext: + enabled: true + runAsUser: 1001 + ## Redis(TM) exporter resource requests and limits + ## ref: http://kubernetes.io/docs/user-guide/compute-resources/ + ## @param metrics.resources.limits The resources limits for the Redis(TM) exporter container + ## @param metrics.resources.requests The requested resources for the Redis(TM) exporter container + ## + resources: + limits: {} + requests: {} + ## @param metrics.podLabels Extra labels for Redis(TM) exporter pods + ## ref: https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/ + ## + podLabels: {} + ## @param metrics.podAnnotations [object] Annotations for Redis(TM) exporter pods + ## ref: https://kubernetes.io/docs/concepts/overview/working-with-objects/annotations/ ## podAnnotations: prometheus.io/scrape: "true" prometheus.io/port: "9121" - # podLabels: {} - - # Enable this if you're using https://github.com/coreos/prometheus-operator + ## Redis(TM) exporter service parameters + ## + service: + ## @param metrics.service.type Redis(TM) exporter service type + ## + type: ClusterIP + ## @param metrics.service.port Redis(TM) exporter service port + ## + port: 9121 + ## @param metrics.service.externalTrafficPolicy Redis(TM) exporter service external traffic policy + ## ref: https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip + ## + externalTrafficPolicy: Cluster + ## @param metrics.service.loadBalancerIP Redis(TM) exporter service Load Balancer IP + ## ref: https://kubernetes.io/docs/concepts/services-networking/service/#internal-load-balancer + ## + loadBalancerIP: "" + ## @param metrics.service.loadBalancerSourceRanges Redis(TM) exporter service Load Balancer sources + ## https://kubernetes.io/docs/tasks/access-application-cluster/configure-cloud-provider-firewall/#restrict-access-for-loadbalancer-service + ## e.g. + ## loadBalancerSourceRanges: + ## - 10.10.10.0/24 + ## + loadBalancerSourceRanges: [] + ## @param metrics.service.annotations Additional custom annotations for Redis(TM) exporter service + ## + annotations: {} + ## Redis(TM) Sentinel Exporter + ## + sentinel: + ## @param metrics.sentinel.enabled Start a sidecar prometheus exporter to expose Redis(TM) Sentinel metrics + ## + enabled: false + ## Bitnami Redis(TM) Sentinel Exporter image + ## ref: https://hub.docker.com/r/bitnami/redis-sentinel-exporter/tags/ + ## @param metrics.sentinel.image.registry Redis(TM) Sentinel Exporter image registry + ## @param metrics.sentinel.image.repository Redis(TM) Sentinel Exporter image repository + ## @param metrics.sentinel.image.tag Redis(TM) Redis(TM) Sentinel Exporter image tag (immutable tags are recommended) + ## @param metrics.sentinel.image.pullPolicy Redis(TM) Sentinel Exporter image pull policy + ## @param metrics.sentinel.image.pullSecrets Redis(TM) Sentinel Exporter image pull secrets + ## + image: + registry: docker.io + repository: bitnami/redis-sentinel-exporter + tag: 1.7.1-debian-10-r122 + pullPolicy: IfNotPresent + ## Optionally specify an array of imagePullSecrets. + ## Secrets must be manually created in the namespace. + ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/ + ## e.g: + ## pullSecrets: + ## - myRegistryKeySecretName + ## + pullSecrets: [] + ## @param metrics.sentinel.extraArgs Extra arguments for Redis(TM) Sentinel exporter, for example: + ## e.g.: + ## extraArgs: + ## check-keys: myKey,myOtherKey + ## + extraArgs: {} + ## Configure Container Security Context + ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-pod + ## @param metrics.sentinel.containerSecurityContext.enabled Enabled Redis(TM) Sentinel exporter containers' Security Context + ## @param metrics.sentinel.containerSecurityContext.runAsUser Set Redis(TM) Sentinel exporter containers' Security Context runAsUser + ## + containerSecurityContext: + enabled: true + runAsUser: 1001 + ## Redis(TM) Sentinel exporter resource requests and limits + ## ref: http://kubernetes.io/docs/user-guide/compute-resources/ + ## @param metrics.sentinel.resources.limits The resources limits for the Redis(TM) Sentinel exporter container + ## @param metrics.sentinel.resources.requests The requested resources for the Redis(TM) Sentinel exporter container + ## + resources: + limits: {} + requests: {} + ## Redis(TM) Sentinel exporter service parameters + ## + service: + ## @param metrics.sentinel.service.type Redis(TM) Sentinel exporter service type + ## + type: ClusterIP + ## @param metrics.sentinel.service.port Redis(TM) Sentinel exporter service port + ## + port: 9355 + ## @param metrics.sentinel.service.externalTrafficPolicy Redis(TM) Sentinel exporter service external traffic policy + ## ref: https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip + ## + externalTrafficPolicy: Cluster + ## @param metrics.sentinel.service.loadBalancerIP Redis(TM) Sentinel exporter service Load Balancer IP + ## ref: https://kubernetes.io/docs/concepts/services-networking/service/#internal-load-balancer + ## + loadBalancerIP: "" + ## @param metrics.sentinel.service.loadBalancerSourceRanges Redis(TM) Sentinel exporter service Load Balancer sources + ## https://kubernetes.io/docs/tasks/access-application-cluster/configure-cloud-provider-firewall/#restrict-access-for-loadbalancer-service + ## e.g. + ## loadBalancerSourceRanges: + ## - 10.10.10.0/24 + ## + loadBalancerSourceRanges: [] + ## @param metrics.sentinel.service.annotations Additional custom annotations for Redis(TM) Sentinel exporter service + ## + annotations: {} + ## Prometheus Service Monitor + ## ref: https://github.com/coreos/prometheus-operator + ## https://github.com/coreos/prometheus-operator/blob/master/Documentation/api.md#endpoint + ## serviceMonitor: + ## @param metrics.serviceMonitor.enabled Create ServiceMonitor resource(s) for scraping metrics using PrometheusOperator + ## enabled: false ## Specify a namespace if needed namespace: monitoring @@ -800,87 +1249,90 @@ metrics: ## ref: https://github.com/coreos/prometheus-operator/blob/master/Documentation/api.md#relabelconfig ## Value is evalued as a template ## - relabelings: [] - - ## MetricRelabelConfigs to apply to samples before ingestion - ## ref: https://github.com/coreos/prometheus-operator/blob/master/Documentation/api.md#relabelconfig - ## Value is evalued as a template + namespace: + ## @param metrics.serviceMonitor.interval The interval at which metrics should be scraped ## - metricRelabelings: [] - # - sourceLabels: - # - "__name__" - # targetLabel: "__name__" - # action: replace - # regex: '(.*)' - # replacement: 'example_prefix_$1' - + interval: 30s + ## @param metrics.serviceMonitor.scrapeTimeout The timeout after which the scrape is ended + ## + scrapeTimeout: + ## @param metrics.serviceMonitor.relabellings Metrics relabellings to add to the scrape endpoint + ## + relabellings: [] + ## @param metrics.serviceMonitor.honorLabels Specify honorLabels parameter to add the scrape endpoint + ## + honorLabels: false + ## @param metrics.serviceMonitor.additionalLabels Additional labels that can be used so ServiceMonitor resource(s) can be discovered by Prometheus + ## + additionalLabels: {} ## Custom PrometheusRule to be defined - ## The value is evaluated as a template, so, for example, the value can depend on .Release or .Chart ## ref: https://github.com/coreos/prometheus-operator#customresourcedefinitions ## prometheusRule: + ## @param metrics.prometheusRule.enabled Create a custom prometheusRule Resource for scraping metrics using PrometheusOperator + ## enabled: false + ## @param metrics.prometheusRule.namespace The namespace in which the prometheusRule will be created + ## + namespace: + ## @param metrics.prometheusRule.additionalLabels Additional labels for the prometheusRule + ## additionalLabels: {} - namespace: "" - ## Redis(TM) prometheus rules - ## These are just examples rules, please adapt them to your needs. - ## Make sure to constraint the rules to the current redis service. - # rules: - # - alert: RedisDown - # expr: redis_up{service="{{ template "redis.fullname" . }}-metrics"} == 0 - # for: 2m - # labels: - # severity: error - # annotations: - # summary: Redis(TM) instance {{ "{{ $labels.instance }}" }} down - # description: Redis(TM) instance {{ "{{ $labels.instance }}" }} is down - # - alert: RedisMemoryHigh - # expr: > - # redis_memory_used_bytes{service="{{ template "redis.fullname" . }}-metrics"} * 100 - # / - # redis_memory_max_bytes{service="{{ template "redis.fullname" . }}-metrics"} - # > 90 - # for: 2m - # labels: - # severity: error - # annotations: - # summary: Redis(TM) instance {{ "{{ $labels.instance }}" }} is using too much memory - # description: | - # Redis(TM) instance {{ "{{ $labels.instance }}" }} is using {{ "{{ $value }}" }}% of its available memory. - # - alert: RedisKeyEviction - # expr: | - # increase(redis_evicted_keys_total{service="{{ template "redis.fullname" . }}-metrics"}[5m]) > 0 - # for: 1s - # labels: - # severity: error - # annotations: - # summary: Redis(TM) instance {{ "{{ $labels.instance }}" }} has evicted keys - # description: | - # Redis(TM) instance {{ "{{ $labels.instance }}" }} has evicted {{ "{{ $value }}" }} keys in the last 5 minutes. - rules: [] - - ## Metrics exporter pod priorityClassName - priorityClassName: {} - service: - type: ClusterIP - - ## External traffic policy (when service type is LoadBalancer) - ## ref: https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip + ## @param metrics.prometheusRule.rules Custom Prometheus rules + ## e.g: + ## rules: + ## - alert: RedisDown + ## expr: redis_up{service="{{ template "common.names.fullname" . }}-metrics"} == 0 + ## for: 2m + ## labels: + ## severity: error + ## annotations: + ## summary: Redis(TM) instance {{ "{{ $labels.instance }}" }} down + ## description: Redis(TM) instance {{ "{{ $labels.instance }}" }} is down + ## - alert: RedisMemoryHigh + ## expr: > + ## redis_memory_used_bytes{service="{{ template "common.names.fullname" . }}-metrics"} * 100 + ## / + ## redis_memory_max_bytes{service="{{ template "common.names.fullname" . }}-metrics"} + ## > 90 + ## for: 2m + ## labels: + ## severity: error + ## annotations: + ## summary: Redis(TM) instance {{ "{{ $labels.instance }}" }} is using too much memory + ## description: | + ## Redis(TM) instance {{ "{{ $labels.instance }}" }} is using {{ "{{ $value }}" }}% of its available memory. + ## - alert: RedisKeyEviction + ## expr: | + ## increase(redis_evicted_keys_total{service="{{ template "common.names.fullname" . }}-metrics"}[5m]) > 0 + ## for: 1s + ## labels: + ## severity: error + ## annotations: + ## summary: Redis(TM) instance {{ "{{ $labels.instance }}" }} has evicted keys + ## description: | + ## Redis(TM) instance {{ "{{ $labels.instance }}" }} has evicted {{ "{{ $value }}" }} keys in the last 5 minutes. ## - externalTrafficPolicy: Cluster + rules: [] - ## Use serviceLoadBalancerIP to request a specific static IP, - ## otherwise leave blank - # loadBalancerIP: - annotations: {} - labels: {} +## @section Init Container Parameters -## -## Init containers parameters: -## volumePermissions: Change the owner of the persist volume mountpoint to RunAsUser:fsGroup +## 'volumePermissions' init container parameters +## Changes the owner and group of the persistent volume mount point to runAsUser:fsGroup values +## based on the *podSecurityContext/*containerSecurityContext parameters ## volumePermissions: + ## @param volumePermissions.enabled Enable init container that changes the owner/group of the PV mount point to `runAsUser:fsGroup` + ## enabled: false + ## Bitnami Shell image + ## ref: https://hub.docker.com/r/bitnami/bitnami-shell/tags/ + ## @param volumePermissions.image.registry Bitnami Shell image registry + ## @param volumePermissions.image.repository Bitnami Shell image repository + ## @param volumePermissions.image.tag Bitnami Shell image tag (immutable tags are recommended) + ## @param volumePermissions.image.pullPolicy Bitnami Shell image pull policy + ## @param volumePermissions.image.pullSecrets Bitnami Shell image pull secrets + ## image: registry: docker.io repository: bitnami/bitnami-shell @@ -889,71 +1341,68 @@ volumePermissions: ## Optionally specify an array of imagePullSecrets. ## Secrets must be manually created in the namespace. ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/ + ## e.g: + ## pullSecrets: + ## - myRegistryKeySecretName ## - # pullSecrets: - # - myRegistryKeySecretName - resources: {} - # resources: - # requests: - # memory: 128Mi - # cpu: 100m - - ## Init container Security Context - ## Note: the chown of the data folder is done to containerSecurityContext.runAsUser - ## and not the below volumePermissions.securityContext.runAsUser - ## When runAsUser is set to special value "auto", init container will try to chwon the - ## data folder to autodetermined user&group, using commands: `id -u`:`id -G | cut -d" " -f2` - ## "auto" is especially useful for OpenShift which has scc with dynamic userids (and 0 is not allowed). - ## You may want to use this volumePermissions.securityContext.runAsUser="auto" in combination with - ## podSecurityContext.enabled=false,containerSecurityContext.enabled=false - ## - securityContext: + pullSecrets: [] + ## Init container's resource requests and limits + ## ref: http://kubernetes.io/docs/user-guide/compute-resources/ + ## @param volumePermissions.resources.limits The resources limits for the init container + ## @param volumePermissions.resources.requests The requested resources for the init container + ## + resources: + limits: {} + requests: {} + ## Init container Container Security Context + ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container + ## @param volumePermissions.containerSecurityContext.runAsUser Set init container's Security Context runAsUser + ## NOTE: when runAsUser is set to special value "auto", init container will try to chown the + ## data folder to auto-determined user&group, using commands: `id -u`:`id -G | cut -d" " -f2` + ## "auto" is especially useful for OpenShift which has scc with dynamic user ids (and 0 is not allowed) + ## + containerSecurityContext: runAsUser: 0 -## Redis(TM) config file -## ref: https://redis.io/topics/config -## -configmap: |- - # Enable AOF https://redis.io/topics/persistence#append-only-file - appendonly yes - # Disable RDB persistence, AOF persistence already enabled. - save "" - -## Sysctl InitContainer +## init-sysctl container parameters ## used to perform sysctl operation to modify Kernel settings (needed sometimes to avoid warnings) ## -sysctlImage: +sysctl: + ## @param sysctl.enabled Enable init container to modify Kernel settings + ## enabled: false + ## Bitnami Shell image + ## ref: https://hub.docker.com/r/bitnami/bitnami-shell/tags/ + ## @param sysctl.image.registry Bitnami Shell image registry + ## @param sysctl.image.repository Bitnami Shell image repository + ## @param sysctl.image.tag Bitnami Shell image tag (immutable tags are recommended) + ## @param sysctl.image.pullPolicy Bitnami Shell image pull policy + ## @param sysctl.image.pullSecrets Bitnami Shell image pull secrets + ## + image: + registry: docker.io + repository: bitnami/bitnami-shell + tag: "10" + pullPolicy: Always + ## Optionally specify an array of imagePullSecrets. + ## Secrets must be manually created in the namespace. + ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/ + ## e.g: + ## pullSecrets: + ## - myRegistryKeySecretName + ## + pullSecrets: [] + ## @param sysctl.command Override default init-sysctl container command (useful when using custom images) + ## command: [] - registry: docker.io - repository: bitnami/bitnami-shell - tag: "10" - pullPolicy: Always - ## Optionally specify an array of imagePullSecrets. - ## Secrets must be manually created in the namespace. - ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/ + ## @param sysctl.mountHostSys Mount the host `/sys` folder to `/host-sys` ## - # pullSecrets: - # - myRegistryKeySecretName mountHostSys: false - resources: {} - # resources: - # requests: - # memory: 128Mi - # cpu: 100m - -## PodSecurityPolicy configuration -## ref: https://kubernetes.io/docs/concepts/policy/pod-security-policy/ -## -podSecurityPolicy: - ## Specifies whether a PodSecurityPolicy should be created + ## Init container's resource requests and limits + ## ref: http://kubernetes.io/docs/user-guide/compute-resources/ + ## @param sysctl.resources.limits The resources limits for the init container + ## @param sysctl.resources.requests The requested resources for the init container ## - create: false - -## Define a disruption budget -## ref: https://kubernetes.io/docs/concepts/workloads/pods/disruptions/ -## -podDisruptionBudget: - enabled: false - minAvailable: 1 - # maxUnavailable: 1 + resources: + limits: {} + requests: {} -- GitLab From d45bc96a4822faafc43e092a41dce1b641854325 Mon Sep 17 00:00:00 2001 From: bhearn7 Date: Fri, 11 Jun 2021 12:41:06 -0400 Subject: [PATCH 2/8] pull latest changes --- chart/deps/redis/Kptfile | 2 +- chart/deps/redis/templates/NOTES.txt | 9 -- chart/deps/redis/templates/_helpers.tpl | 8 +- .../templates/bigbang/redis-upgrade.yaml | 98 +++++++++++++++++++ chart/deps/redis/templates/secret.yaml | 10 +- chart/deps/redis/values.yaml | 8 +- 6 files changed, 114 insertions(+), 21 deletions(-) create mode 100644 chart/deps/redis/templates/bigbang/redis-upgrade.yaml diff --git a/chart/deps/redis/Kptfile b/chart/deps/redis/Kptfile index 229270c..602b186 100644 --- a/chart/deps/redis/Kptfile +++ b/chart/deps/redis/Kptfile @@ -5,7 +5,7 @@ metadata: upstream: type: git git: - commit: 7197041c0f82be53dfb9986565627b053988317c + commit: 83cc0db075039e40d78f5bb5fbcbe54c67ab9773 repo: https://repo1.dso.mil/platform-one/big-bang/apps/sandbox/redis directory: /chart ref: upgrade-redis diff --git a/chart/deps/redis/templates/NOTES.txt b/chart/deps/redis/templates/NOTES.txt index 07905a6..2c62195 100644 --- a/chart/deps/redis/templates/NOTES.txt +++ b/chart/deps/redis/templates/NOTES.txt @@ -145,12 +145,3 @@ To connect to your database from outside the cluster execute the following comma {{- include "redis.checkRollingTags" . }} {{- include "redis.validateValues" . }} -{{- $requiredPassword := list -}} -{{- $secretName := include "redis.secretName" . -}} -{{- $secretPasswordKey := include "redis.secretPasswordKey" . -}} -{{- if and .Values.auth.enabled (not .Values.auth.existingSecret) -}} - {{- $requiredRedisPassword := dict "valueKey" "auth.password" "secret" $secretName "field" $secretPasswordKey -}} - {{- $requiredPassword = append $requiredPassword $requiredRedisPassword -}} -{{- end -}} -{{- $requiredRedisPasswordErrors := include "common.validations.values.multiple.empty" (dict "required" $requiredPassword "context" $) -}} -{{- include "common.errors.upgrade.passwords.empty" (dict "validationErrors" (list $requiredRedisPasswordErrors) "context" $) -}} diff --git a/chart/deps/redis/templates/_helpers.tpl b/chart/deps/redis/templates/_helpers.tpl index cf6866d..b36fada 100644 --- a/chart/deps/redis/templates/_helpers.tpl +++ b/chart/deps/redis/templates/_helpers.tpl @@ -214,7 +214,13 @@ Get the password key to be retrieved from Redis(TM) secret. Return Redis(TM) password */}} {{- define "redis.password" -}} -{{- if not (empty .Values.global.redis.password) }} +{{- $secretName := include "redis.secretName" . -}} +{{- $secret := (lookup "v1" "Secret" .Release.Namespace $secretName ) -}} +{{- if $secret -}} +{{- with $secret -}} + {{- get .data "redis-password" -}} +{{- end -}} +{{- else if not (empty .Values.global.redis.password) }} {{- .Values.global.redis.password -}} {{- else if not (empty .Values.auth.password) -}} {{- .Values.auth.password -}} diff --git a/chart/deps/redis/templates/bigbang/redis-upgrade.yaml b/chart/deps/redis/templates/bigbang/redis-upgrade.yaml new file mode 100644 index 0000000..a8c63f7 --- /dev/null +++ b/chart/deps/redis/templates/bigbang/redis-upgrade.yaml @@ -0,0 +1,98 @@ +{{- if .Values.cleanUpgrade.enabled }} +apiVersion: v1 +kind: ServiceAccount +metadata: + name: redis-upgrade-sa + namespace: {{ .Release.Namespace }} + annotations: + "helm.sh/hook": pre-upgrade + "helm.sh/hook-weight": "-10" + "helm.sh/hook-delete-policy": hook-succeeded,hook-failed,before-hook-creation +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: Role +metadata: + name: redis-upgrade-role + namespace: {{ .Release.Namespace }} + annotations: + "helm.sh/hook": pre-upgrade + "helm.sh/hook-weight": "-10" + "helm.sh/hook-delete-policy": hook-succeeded,hook-failed,before-hook-creation +rules: +- apiGroups: ["apps"] + resources: ["statefulsets"] + verbs: ["get", "list", "delete"] +- apiGroups: [""] + resources: ["persistentvolumeclaims"] + verbs: ["get", "list", "delete"] +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: RoleBinding +metadata: + name: redis-upgrade-role-binding + namespace: {{ .Release.Namespace }} + annotations: + "helm.sh/hook": pre-upgrade + "helm.sh/hook-weight": "-10" + "helm.sh/hook-delete-policy": hook-succeeded,hook-failed,before-hook-creation +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: Role + name: redis-upgrade-role +subjects: +- kind: ServiceAccount + name: redis-upgrade-sa + namespace: {{ .Release.Namespace }} +--- +apiVersion: batch/v1 +kind: Job +metadata: + name: redis-clean-upgrade + namespace: {{ .Release.Namespace }} + annotations: + "helm.sh/hook": pre-upgrade + "helm.sh/hook-weight": "-5" + "helm.sh/hook-delete-policy": before-hook-creation +spec: + template: + metadata: + name: redis-clean-upgrade + annotations: + sidecar.istio.io/inject: 'false' + spec: + serviceAccountName: redis-upgrade-sa + imagePullSecrets: + {{- if .Values.global.imagePullSecrets }} + {{- range .Values.global.imagePullSecrets }} + {{- $credType := typeOf . -}} + {{- if eq $credType "map[string]interface {}" }} + - name: {{ get . "name" }} + {{- else }} + - name: {{ . }} + {{- end }} + {{- end }} + {{- end }} + restartPolicy: OnFailure + containers: + - name: redis-clean-upgrade + image: "registry1.dso.mil/ironbank/gitlab/gitlab/kubectl:13.9.0" + command: + - /bin/sh + - -c + - | + set -e + if [[ $(kubectl get statefulset -l app=redis -n {{ .Release.Namespace }} 2> /dev/null | wc -l) -gt 0 ]]; then + kubectl delete statefulset -n {{ .Release.Namespace }} -l app=redis + echo "Statefulsets cleaned up." + else + echo "No statefulsets to clean up." + fi + + if [[ $(kubectl get pvc -l app=redis -n {{ .Release.Namespace }} 2> /dev/null | wc -l) -gt 0 ]]; then + kubectl delete pvc -n {{ .Release.Namespace }} -l app=redis + echo "PVCs cleaned up." + else + echo "No PVCs to clean up." + fi + echo "Done with upgrade steps." +{{- end }} diff --git a/chart/deps/redis/templates/secret.yaml b/chart/deps/redis/templates/secret.yaml index e639ffe..a397608 100644 --- a/chart/deps/redis/templates/secret.yaml +++ b/chart/deps/redis/templates/secret.yaml @@ -1,10 +1,8 @@ {{- if and .Values.auth.enabled (not .Values.auth.existingSecret) -}} -{{- $secretName := include "common.names.fullname" . -}} -{{- $secret := (lookup "v1" "Secret" .Release.Namespace $secretName ) -}} apiVersion: v1 kind: Secret metadata: - name: {{ $secretName }} + name: {{ include "redis.secretName" . }} namespace: {{ .Release.Namespace | quote }} labels: {{- include "common.labels.standard" . | nindent 4 }} {{- if .Values.commonLabels }} @@ -15,11 +13,5 @@ metadata: {{- end }} type: Opaque data: -{{ if $secret }} -{{ with $secret }} - redis-password: {{ get .data "redis-password" }} -{{ end }} -{{ else }} redis-password: {{ include "redis.password" . | b64enc | quote }} {{- end -}} -{{- end -}} \ No newline at end of file diff --git a/chart/deps/redis/values.yaml b/chart/deps/redis/values.yaml index 7f51a00..c96c309 100644 --- a/chart/deps/redis/values.yaml +++ b/chart/deps/redis/values.yaml @@ -17,6 +17,12 @@ istio: monitoring: enabled: false +# Deletes previous statefulsets before attempting an upgrade +# May be required on some Redis chart updates due to upstream breaking changes +# REQUIRED for Chart v14 upgrade +cleanUpgrade: + enabled: true + ## Global Docker image parameters ## Please, note that this will override the image parameters, including dependencies, configured to use the global value ## Current available global Docker image parameters: imageRegistry, imagePullSecrets and storageClass @@ -444,7 +450,7 @@ master: replica: ## @param replica.replicaCount Number of Redis(TM) replicas to deploy ## - replicaCount: 3 + replicaCount: 2 ## @param replica.configuration Configuration for Redis(TM) replicas nodes ## ref: https://redis.io/topics/config ## -- GitLab From 067bd11bd057216cc6883bab3c64959667c52f98 Mon Sep 17 00:00:00 2001 From: bhearn7 Date: Fri, 11 Jun 2021 13:40:48 -0400 Subject: [PATCH 3/8] pull latest changes --- chart/deps/redis/Kptfile | 2 +- chart/deps/redis/templates/_helpers.tpl | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/chart/deps/redis/Kptfile b/chart/deps/redis/Kptfile index 602b186..11925f9 100644 --- a/chart/deps/redis/Kptfile +++ b/chart/deps/redis/Kptfile @@ -5,7 +5,7 @@ metadata: upstream: type: git git: - commit: 83cc0db075039e40d78f5bb5fbcbe54c67ab9773 + commit: 54a12935343a5d70c4529c7085a0a9da932bcabd repo: https://repo1.dso.mil/platform-one/big-bang/apps/sandbox/redis directory: /chart ref: upgrade-redis diff --git a/chart/deps/redis/templates/_helpers.tpl b/chart/deps/redis/templates/_helpers.tpl index b36fada..ecaba7d 100644 --- a/chart/deps/redis/templates/_helpers.tpl +++ b/chart/deps/redis/templates/_helpers.tpl @@ -218,7 +218,7 @@ Return Redis(TM) password {{- $secret := (lookup "v1" "Secret" .Release.Namespace $secretName ) -}} {{- if $secret -}} {{- with $secret -}} - {{- get .data "redis-password" -}} + {{- get .data "redis-password" | b64dec -}} {{- end -}} {{- else if not (empty .Values.global.redis.password) }} {{- .Values.global.redis.password -}} -- GitLab From e7bb725d4de74ac14bb4bd488c2e168993121e6d Mon Sep 17 00:00:00 2001 From: bhearn7 Date: Fri, 11 Jun 2021 14:32:41 -0400 Subject: [PATCH 4/8] pull latest changes --- chart/deps/redis/Kptfile | 2 +- chart/deps/redis/templates/bigbang/redis-upgrade.yaml | 8 ++++---- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/chart/deps/redis/Kptfile b/chart/deps/redis/Kptfile index 11925f9..c61c173 100644 --- a/chart/deps/redis/Kptfile +++ b/chart/deps/redis/Kptfile @@ -5,7 +5,7 @@ metadata: upstream: type: git git: - commit: 54a12935343a5d70c4529c7085a0a9da932bcabd + commit: 1cb1b6a0a407cd71e703361bba579c6f8c7d5c8e repo: https://repo1.dso.mil/platform-one/big-bang/apps/sandbox/redis directory: /chart ref: upgrade-redis diff --git a/chart/deps/redis/templates/bigbang/redis-upgrade.yaml b/chart/deps/redis/templates/bigbang/redis-upgrade.yaml index a8c63f7..bcc8e74 100644 --- a/chart/deps/redis/templates/bigbang/redis-upgrade.yaml +++ b/chart/deps/redis/templates/bigbang/redis-upgrade.yaml @@ -81,15 +81,15 @@ spec: - -c - | set -e - if [[ $(kubectl get statefulset -l app=redis -n {{ .Release.Namespace }} 2> /dev/null | wc -l) -gt 0 ]]; then - kubectl delete statefulset -n {{ .Release.Namespace }} -l app=redis + if [[ $(kubectl get statefulset -l app={{ include "common.names.name" . }} -n {{ .Release.Namespace }} 2> /dev/null | wc -l) -gt 0 ]]; then + kubectl delete statefulset -n {{ .Release.Namespace }} -l app={{ include "common.names.name" . }} echo "Statefulsets cleaned up." else echo "No statefulsets to clean up." fi - if [[ $(kubectl get pvc -l app=redis -n {{ .Release.Namespace }} 2> /dev/null | wc -l) -gt 0 ]]; then - kubectl delete pvc -n {{ .Release.Namespace }} -l app=redis + if [[ $(kubectl get pvc -l app={{ include "common.names.name" . }} -n {{ .Release.Namespace }} 2> /dev/null | wc -l) -gt 0 ]]; then + kubectl delete pvc -n {{ .Release.Namespace }} -l app={{ include "common.names.name" . }} echo "PVCs cleaned up." else echo "No PVCs to clean up." -- GitLab From 3da727b3e5185ed2e1ef75dd45a9091a5d188e19 Mon Sep 17 00:00:00 2001 From: bhearn7 Date: Fri, 11 Jun 2021 14:55:06 -0400 Subject: [PATCH 5/8] pull latest --- chart/Chart.lock | 4 ++-- chart/charts/postgresql-1.0.1.tgz | Bin 8687 -> 8688 bytes chart/charts/redis-14.1.0-bb.0.tgz | Bin 82358 -> 82989 bytes 3 files changed, 2 insertions(+), 2 deletions(-) diff --git a/chart/Chart.lock b/chart/Chart.lock index 5d3641e..72874de 100644 --- a/chart/Chart.lock +++ b/chart/Chart.lock @@ -11,5 +11,5 @@ dependencies: - name: bb-test-lib repository: oci://registry.dso.mil/platform-one/big-bang/pipeline-templates/pipeline-templates version: 0.4.0 -digest: sha256:0c10340f474ea0d7c14a56d06f6fae7be320def84f8a0664843498d193cd5af3 -generated: "2021-06-07T15:24:16.279073-04:00" +digest: sha256:95fc02eb4c73428f58530043f2ccea983eb2de36c3e2bed6566deaff6552285c +generated: "2021-06-11T14:51:29.578969-04:00" diff --git a/chart/charts/postgresql-1.0.1.tgz b/chart/charts/postgresql-1.0.1.tgz index 64b3ecbc3ec014c2e8d5db4061058d4276ed1180..d7fd11298b60bf3b2bee82f9138db02acbdeb4b1 100644 GIT binary patch delta 8482 zcmV+-A>H2ZL-0e8O$ig*NwwGeo*TQ7Ry2QOn177>ujYt}V2P6Wo2PvSgTdfnZ%_R@ z7!2zF4h~*C`(}4lBeDLgG@0-Ey^S#0IZ(#7mc(gt_7l?f``0Tdoo%EGvF~9~=a`FTDu!kdaKNcc+uT<52hv$4I_FF+@n93E~(Ml%g3!6&q0cEqkM?#6*iV_Kq2rY9 zWa-Si!pm#QB0ltdC~G@EJiq9y=YxOzmLiFmQ<&47g;;^G$jpeC=aV3$N&hOJV3uNm zc|VkEjkgzzXn2L0ACn0~Y}qfGU)X`!4F}V^5cKzQGAV- zd=to2f4)F7ARIPhBrq47JAh-3fnx!J!seUldn!f@bDWAzS)bvlUc$q^vr+;=<$~b- zoMYzCauVUbg3kLJ8N+^-$1zD~zJBLzY8?|=_iN_%!)lhO-K!#iXe$L?7K_d{v~3wlaK=zQ*)8TPM6=Pw?}NohsAiJ6i_TM zOC=e3ILA>QV`jSD80V_LAx)=bmNV=pc`Qg4W4~yJ z_x18BUc8sPvO?}OllcQ1e;Gp|p5}49ycgO9d$^|TDyAsn{fz4W^*1b3LQ|hkB{wi! z%K7kGwl~6z(CA!aH-zVd%A{g>DoBDsQvx!?P=WP@XcvMfc{ zC6_B3cE5iX>>j)f2Em~JY!8xXU-e)l1urfXe~=ReL8jj*rl%OASG)=F&;!7!WQ5UB zHi|s}hP7yDb|ioef3*?X*M6qn!%sL)0HrAvdb-jSM!&oY;1xo*krcdh6vs;=fkzf!iQO-nZAzv__Ig$L#!8)j;EV=I#B0ME2j&>v- zniWs58K0eCNxhY38~<}3WuS=ydb}#e`^!zb3qxJVTm~BO@z4q ztiGxx5C7%9`b$y6NE|)C*H)?5+kxvj3Fihn@eZW4(HKZs0f^}f$nrZ7&MD>P)}^48En^k{Y|XM~aw;7CdcIQ} zk$|Qa&g;LPf9%MQ@FzIUaC$CKc(tuQD&o6n3?&&n02GFp^LI4DLpZ}I`jruZPt#Bi zJSYFaLwNa`$iMT+2#NU+dL>WrqlpBeL;?M=zd)=XlS$t>O~^s*XEXVa8gFM>^C8^a zd0v7ABO$LW7cD3N7$NkU(H!#>#|7j|{3)YMU}g(lf1ueA7K30fIIyoA(GOfP(^-eA zRr&K{j=3`MN$kXiip`>!ki15fa#De*R{E? z=+uS;n$G+bU;74{zaYp*hR^y_5@QYDH2SV2qI?OGX-0)uVqXG$%(3iP@BHNL$*T*9 zf(QwDe|&|bbCCb;z^kM46ZrL~llKxthy;r1ESMu+fV<2XS&$gd@K#ZM2R2`wzJGu6 z>SA*nE^3t>R4(PDDywb7$=mZ27{JN;Q^Eq4i$!q%q1 zNhS{%gUuZ%e(cI0mbjbSJ%*MH4A%hkA66L+iQHTXhwQ!h102C z#|H0Str^+R%gIt;-rd;iqn}@&tZVFC60FvkB#46D(_*canTknYOn0>(#3UiLkV$nhUC2P9Dc>LG*qpmKh$xD=qH58F>J5K@4Gk@A)&yA3iDZ ze=>eE;zRiGyJmdv?CvA^?t2>H5oPia65H*o*yc<_fo{bXRa_}GKZc%{Vj%@MduUW3 zP84G@#}c_APvN~=tYj#GWw5M%ZUKC)|qGC9UQHX&Hh6J81A9==;2O36Wbp$PO>Ti@_ix%v-8PUPW3vId+wQMs~ zE?*_lfZY5%{7Eo$k}lMgcq09uBeB`tllR}BUYwi<;*)rqHrCjG_70v8e`@;Q{oSwj zpD*(`%s$kIOuc(xt@u-$hunna`9n^}DV3aCo>z|FYspb>29o!a6qYn+V6-+v@8$;V zq;d}s!8DI!S+xfN+}#B?HxQiR7$c4YDMj&2uFku=fG@(p01MPP-t%s5d>~T@e$mE? zs$viB?z}fsiGSx&&a4%Eo>Da#HKaP0f?WEch^-33Xeehm#f*d?G3{y@ zd_OIa@9Glxz9g5D;}3&=L!T*0rqtwjcishs85WwPN|zbaa0H>*?9? z;kR2BcUj9IelMKvH%#DD_&cX*hQ$1^cOyl46f`<;*MnP-(&)h+fB1fcLmJ^f0}khO zTa6t~BiT3EIU`U=MyL8%$gwQ1&$W;yiQECU^5UqB(?!8FjXW};3%p$&MhWT(Y2X{l z%a;En!mZ%n5Z@K;@5u`*l=rM6P0evp zSutWxxGSk!HhJ$w77;0;$4k9-XfC*vC*{ie>q}m;Z~!n9f74i5IP~lRsvHCNfMuqM z$toRwvw0H`ffN2=@O!`o5;+f06fwC`sdwhb-R8D!dvtnMZ<{Z| zKa3%6-UK|uVIVh5g^@j2N|Y=W6=$!IvN-YHkCwa7UIYVW{darmt`E6aH({x5T+Rs4 zYK4l@9#IhG4xQD9d=Q>r1TEc z^$+W?;O?$h-xyhDrq`#Zt+44iib1 zaE^!YUH|URlcl_qPnlB5%(0gHjrvi!G6kL~=Nkh}%S!gk0%}17+Tl>G<6;9w2`-cy zw;))ahH&s){YjGZd^#ncpy!vszD^2;P4Q0fIk2#9Tl;8+ZmMP=|?^mp$ ztMWp&e<3@$U*%GZ)$9>{5Jpaidpu!u=`J>!>2Q{G?fPOw0`J55z)A2i$dG-t?kAB+Q{eEX-4~!L0pBYh> zb=R!a0?iM*OB<$L6gQ&PuyJm)1?HF$p-k&;iF1AYl7(#lYLb)j6bLGQ78_0)@ky{_1$c4P8ZaS*#24s_}1K|D`qSNf^KyF#rF( z{eu_v^}qjo@OAxviN{_4cK%gFxuek=Q-B9QA+A(5QZ($r-5r>}OXb$x9h0sPAXEz^ zjc_Vp&lTA2?mT(S95&mqwr35tuteVvCV=&YFn&Bpg!8u!y&p#LwL~n@Q(gngPv;D4 zBb*0C8`i0)oHFu>D|kH=vo*Li=vs9$DB-LhxR;Y65Gpy3Y1Z}bDayFMFD;F_bsp1Z z<(fcQs(O0>dd>!0uhF}2?^ZeZJN;dK55Pg>o&XzomA97cO!FVglZ6l@2N{NMukdmQ zldupLf6bd41r=_Ar|1fY+LCxEU+ZS>?lx<ODUeJ$hl-HQ(^ zo5bm&B#<4{(dqfc>$8*d%b(9r&Yb$H8^ec~YFowxpzy1V>{SlJwTlJOYOgs)v6vh0 zv!IFI>pudoM(2-zSlz@51M+>qzj^=W;`oQlf1|V4=MQbCyh63IrPs$t7e`Il>wN7y z=3?zi-pamNr-aKN-@H9(!9dQ-7T1-^JT*QnYul)U|B=zeUGrcxV}HfVGd!(+Stl^M zy0V};iRE*Jm&4|b!fH3F%dPCi@uhN7ZlVr1+DIUgwSVhN62@$u(df+x?x3Nmx88kP ze@Lird&Sq4(u91J1-i)s#8kH5z7PaSq(_)se4zq^SX( zeNPiZgODL--ops7X4KP`|KvcQ*f74uA#m91O?GD`9`dZsNnx}0GtHO0F*P>ih zor`uwiE2NKt5zM=%y+la!+E^ra^*#$2G;$W*dfV#n#RlGVqn>Jjq}_`{3#Hb`SXds z*3^N97J?pxNQVZ`IA)b-SR~vFThK1wS{PQ&9d>=YK(oh)!4(**#o<J2&sS5ZP-is#{2=f7@%rM_q98g3t8#I2t5YjQSDGO;`+`W8{g>~I{7 zyEx@NXZo7?99lDyOPWV19srbAUtRD~68tKL;7-5pa_ba1o%`zQUDaMIe<%?t4?d`NSSy%+f_vxM zr`7&f^-lV16W|*A|L)#F{r=aBXM6i!?SEh5sT%^?E=iPjyULvhuWCE&Ft>Diuc?*Z zwEo@mic0Ta$^K`JJefS4e||}`8cAivBG|xD9MfwcsS3>EUg-8TFRKX4e)S4|!7lH4 zU#7%y>ZtVmCJpq{LJ7+>A8>DG2t9psriI_z?q`f9Sj=(GfrkubcxCU^IpBXI<9?#2 zmH%gp@F~MUuH*j)`wjp9-LL*1U*>5!47447D!1f1&oSG|e^hT3f1|cDl2>y#`*(2u zsCfp+I=wlLlYr0rwfJAXPScS?@oFfs7PXgK7*#zLnuqDG!fU)u+z3*pQ-0S`w=7xJ zYORUIWWrW;>qE&uDgakd!Ht0B6y3rfm4o)WD%;jar5QWSs~*BzigaOLMXBf2)R?tD z|1iJoR{n3|mp;`Vf3S}K4+i!4-}^6K?0x0`U*c&I>YBF$TAhUT=YIwXND(Y`HpazTi zXV1W|&p-2N=l@?;{(sTD|GWEq_bdPZ5>E$fSFG>fg16tte`eee;7c7sKxkj95h}We zY5}cE=zYKY@vGzN0Z}L??t^cel{2fFH3ecbEJii!TSaBk;W?xMwIFLF z8Pvg7>RZuUg=WDY+k0F_7%}l#wv=6~QP{@V*xoM8Vnsa1HVo}YsNayO`v{xzPS{CZ z#f?MRa+qqXe|K*e`-iNOmDBz~>)+x3XD3I;?@odwdTJiCn*Tq0aj?H%@ z@I{^tCy0>eeJFqYzGb5!R-?gh1K}zY!!>5pJl+AC;nc(d1=^h+Naq9!;EjMe;*d~= zLCjGKyZf-jh;g7(K%pQD3=v-7m}W)bN2CH`;}j4Jf9FKtP~^I{hJ_JJaRfvF0xlR$ zXTWfln;7a-%H(<>`byJsM~53HslYR)ej}v|R}o8<7nzC~dGYqo$7g@`yzzKEL459g z3v(PNDpduFW8gxvTZc5Vph=@47>#nJSNFV&Ik9mbCX@;;7|JC1S_!>A2hg?~5|gG9 zP#K~^e*>zAuiUn=oS=-I_TeWSCuO@v8?_A?3a`-2rgCDM5+jBg{+JU^1m>RSyFoE_ zgT4RMw_|?50>RPfO%Vpm^I`Oh8^|1Zo~bRuxQXX!gju|lIFWS95Em@h1G{ya#!I-K zuM$Z%P%(o)RNno*wNd%K4O|;=R778s(xS`^p%#dV z>R4pZh#<K8WI)vu?$YECWaoXSXFT5 zM^Fi!jqDA7IREkG43Yumgn8V$kvC(a|_312=M0T zmgm+c*0@*cdS&kx{Pst~?)cbQ<$*P-f7K;6W93;fZtv;XF3Pcqn9FcRIT4gCJ80w7 zcnodE*6Xuby#*VAW-9^0`1{}>c=m8qD%h0%qhlBL8y$@@k7F=-M%Dm?vCic+mO`=9 zQNm%Yvw4k8Hm|XpUt!$D#`wUD+p#fv=C#$nD6zO&J+Qhcogf2|5? z;=cxM*nH-^sVn_l+7yaF8v)y*)I`M8Xi4<7hMrYyYQAmNd80Fe>0QOi1~w%zuH^uO z1!9smDuDgtXL0>1mP;FTywS0fu1m49d#Ijnq{<6hV}~{>$=8uh^0gM=XV2owHPmqx zw#_}!o{8&^z@};>7*}Ao<#>|=e|My!Ef-Vi39+eO^{irZW-@1)YoMcYhwcFQ`Pf*0 z$p(;HiG|8>M5mC=ek)uQy8$X}V5>7T*7gcaH8xFi{@B7++1pfVCqb>OtY$Cn zW-I4PF3sl1+Jg;@QjNI17Ms#&J}ySeq}M`RrEF4%B+AP4O?7N4d7U0ar6x9|0(7kQ zsg?|5rSCv1ZEo%!IZ!PlMgCFQ8Ei5fHE|7*Rsw|a%h%+|=8e9WRjjG=e4=A3OVQID z0t`}ungp6iRIsV!*804We=6>eXkiT0B^2cneLo7_!g$RMs?~UB(ix3aKBMuD1Tlp1?qHCt!$@IM)7Dp{t#hGH zhrmgM{SYzNQPJiHtBurWN?Vn?XEll9#I~r2cUJXS0J%#~f~A^Hj6Aax2L2o1?C*cwGQLUoLJMUB)GC zj5G3^k&0@r6JJ56{^Sq$ zk6P{j)Ez_wYln4X&Z6^A{9cyrOo(Y@Ofv3mGL~rt=O0{1$7*3_8*H( zJ2v&8AmbKnOc@YG=mZvtgtg8S&oBOp!t{mSB8^?70RM^<4NUb|Vx&-yTBhTWJ z=5S5(ID(j5;UeuKP0Pfo(Y;Z;)mB24g3L7nCMdJu+=OM^rZJa{_=BZUVZgtKBR~K@ zQl`BqNIIn~F=b|gJ_cmeJ$Pt(CJJkZbf+1|^Afr0n0hvOy_hbfE|zS8*B#&M7Kh z0uc`6e*(7>q*2nhH+n&EL7AbRGssG>ru~Q<&jAidThG?3f7Gmk&Nvk4NHl?Qc~EWxO0lP1hw94L zcE_Ja^6oNfiEjd;^tUyJghNb2$L++Z2njFJX6h9lEmM?`(0(txdq_G9;Ei#3Xw}&B zxni{`6>?r_2cv4njvbrsVug($@JtFmm9ARjujeG3OZt&nN}2AdZCa8TnS4Jw z*N~hwx-%0zM+-u823Rds%>atSu-rE?oJQ8CNHY#O%{NMmTk8OD&)W^a zA2vD6NfhA}EIi2?RYpXT3e2Whxk@Q^JtoTJI}QL$j#rPJ>`N`iXj{+21kTSb@?g7q0XjjSe%6;X%f;n z)}IX}i`0@=Wok*YdbvVL{Y4TIBL;{Y?#@F-CR#*NVvN~iU{t@r4>c#b7Oq})-TiYC z(@8%;5}kfU(&?MF+|s_oU6)C`e{HyPL3X9H;iW@DUH_?b)RyW|xo>>Tv7B)MoMT*i z&~0)UJKNY;ji@q;Y66&zhRe;*P)6gxtMXbaC01zZHzaoH%un&P4U^ zvZ#9cc~$+KWSC`_TlPYM_!aM~oX>LYG2cwZeuTpqG3*-zj9qF&uV8;kbAN(oB;DTe zB<0VrC;898j$$84uG}m+1(h+3rZs)zq)=*kDzTjA zg~vEuLYb|yG@AvWw?@T>f7IrJ<-s7tF6A##9AD}jon~1TpiD+-n;+8vb_$di(^D*h z2^J`*61hsg!<*lFCjQ88y`lWUsrEMgtvCFw=XB?{-rZf#^L~|Fwn~B`rLJITIwfI| zB+tpd_jgIgB2T%YyPBUF!=c>1H9k9S16NVB9%>z~WQ>M{o=WA5Omy6kBB8G&o8AAT zsxr2kq_>>sf%XK~g={Ax!m}7HOBP3Sk>$!aMDB6Q17MoRc1I1qUe)~ie0{z?Px<`+ Q00030|M@4F{{Wr<08{F@T>t<8 delta 8481 zcmV++A>Q8bL+?Y7O$id)Nwqioo}0LlRy2QSn177>FBgc3V1<(So5y_ygTdf%e_#DO z7!2zF4i29^`DVC3IC!@IY&hJ1`psbYbbs*d8yGw?9<5K#1!CU}KD(`Y=l(?=l#yRB z+>0;|8OeltcQXAu4u#KfjN}UxLxcpHB90+JDVpO1rviWY ziVK{;&dKSkAKsnq!W9tIdF7I8nMNfr~7 zhB)vRG{GZS2$AtozkhXg6_m3!plsgvNGOq8QzF3;L4A_U`)EpY(a#v>ypLm?El?_g zES-Cocy&ct#7CYFWo_q&=NFyze2{Vu_>0jnk%u*~c z?}u`&@%Ca74KFeCV=`rkt@=gtOFJ;bU=R$w#~FWT{V!3RWBvy)fc5KtI6QndtgrvW z{ll;8|4TeuTgChZlAt;E)c?y_Ju+;-+uDM&42NX40;G$M^Ee*Un1n0&ar=KLzCtU$ z4P>T2pQAYt4%;yjn2YT_z%j?bu>e6~`_1e<6=Q}uPQ|vY&+tqy;ZfgNDFLB!LGXUg zG4tm+iEv**=l!jWVL!{`n51)Gzw@@XysbKNqYCcD$1@xv zk3~5!UO93N5G-k& zCm0f%rvgaI1x69j8Q^qD7)=%1Um`}(G{#=ev910iiSY<#DCStT@-u(OaQumILDD&B zI=SFN*?;+ordS~*Aj!Fa1zJj~SmgZ7Vt0vGU`9n&6AKIx=7ix0Y#DD0uxU|KegxaP zD!X1d+ug0jnAaF=x^5WnPo6eT1jvY&n!=c>OUO=o1DGwdgMEJzk(zi5Z| z_3|oSyqCMOLhdA!`U4w(IYS|y<#D{a6WRrPxT5SbrYPe5jOzdOw=7gbQ=iTxH!xhv z`S4n{H^z+6=uBfbf~SMZq+)q0NP}Nx&nx@x3hoh-rvoK(YQ$u$&9^enGh?UaLatO|3w(Dn-{7 zmn$2F-#-b4htGpSFz7$oha@^sJs3;Diwngc1@9ci@ybZxk;PYH_lsuRQoMc{Ba-Mkr}$$|BtLVo4(cdN?mL4B&q#`+J&A{A z#Zzp?Cn{T>;u&SwZW31{j%Bea&C^IiD)_I$VPr5b$gk*s+C=(HP=@AMBF=deA+A5G zuWHG|f4Q&zQq(XKN6+uIRqFNj;A%m_1w@2P3UG*4DN0BP8KX-gMQ*umT4;G{Fn}Gs z*{G?zE62q&l;&}~2Pthd22xf4V)_EI{2qi0N_n|;DQIQOm<0ek^X!S73P-=5?G;BP zps9uP`me`-d-5av2~IMco(U9Q?y8T9_%0eFNd^x9g(2qr9gXk^PBDspWkleUG?W9+ z$v^N2p1&sY?|eE&VljeV$rJo&DnTewK!5Bn5$nff+ILP9a!~u(T>hiR+nLsU1lPBo zmtet2$Scc53km>62)$x7$2`Sx0r>)d$|w_<*+S=kXg-4FAlMHM?JGz016Ry+)}d-u z{`{C@F3c~01SgcOM)2g|@EtMl!Ym)ba4<;JZ_TYpiUCCtG22U+b3qd@9kS)RHup81 z+LA!ixu4=I-$3)11o_DDS${@itl^tR-<3p^FF`WRs1Qr+OMs6#mL2Pz9lt$(c@9w! zAt8@{uW)n*^4~ppd31IRzy5UmUV;dbKrx*M3&aa>7a1c<65~1EDXQrvn_Cv z$pgk^YQOFq6LLG_(~d~&X4VejqH565qNjn5U$NKdVBI@9ae z;N7b=Bl~$VT?x#)8+(29^XubHjh#t?)f$roQLuYjthF*zG3krxuJ(hNB&2ry*?95_ zX_Dmv`^7R+vR7qMRhLwAL6ytN-}!y|a9#l1IU4?r%65ghD4eIoh8Cna8g z#&5=a1Rs9ajPIS@eI(y~Pa{00OddjFyL}bgoM|Y~t=OW9E2ZYg$n#PxqyT3RjS9rE zVoc^(A~)n2ymyP03?;A(x5mpfobv?+QzM}fj+GdZW$`M2Ul%yFTZgK$2Q-aWQa0sU zb0!Blq>SNEXlP+foxJhU5%y& z3%T>}xn&h>2`&>-eoJwv_&3ZLm2%1obmujgojS5|&I%*qDl~QrBB3~@SI1^ljmROV zq8uCDFFi>Gjj-RCB)jw^{XnsB<9ceN>7EYNWL|l*M$VbPIAas38ix^6gPgq{wJg zf2EHX1sJuc7|vo8V&H-yf#<6Sp7G>?hS69ZK}($aTP4_{1v_p=bTINlo9;v{+YFV< zS4lJ=H$M-55)2)uOEo1PN&n|aY5CPn*R4-_|^XN zWgdswhx(AIcMq%;e`@oPo3K28$muwvl5@-R%B%NUa@3oFtAa2Z$~jIkBOypkyIKa{ zPYdL`x&*#2$))7@7eT+F&y*xnYVzA#@0`LM3r$j`o+y-_EKfDIFn&EgIy?LI|e8q+D5lea=f34gh9Ttv-28XQZn2fS*62owyy&saKb+feh;`nBIf~$A|^K~_0Igb-QKlrk55kPZS!UL zhcU$M>wsrC4CIEXFtP_riISzF;_MYt7AM}j(Q^3YSujx6f47(J`jC5d6PDV><%|HW zRyh8I!(8Bhb}p+#Pe$$c^4w>%WLjATTxB2p8D&?9MR&vZTiau}Gr>pq8yaWreku8{ zRsO$N;5fsK2O@h6SC9?z|I@*fr*--N*|Vo#<^L~#@myc`zk?-7MoI-G#Zt+4UL=w% z;R27~yZ-I1Crf$9pE9MASzs;q8}*}dWePk~&Nl{{mX++61=NBFw8NoV$HfMW5?m-Z zZa}a+4dL*q`jaGQ`D{i$LC-IN$>rkf9l!sbSDNxo8_I|aA9ECw8Nm^tEK|q_-mh3g zSLKC&Y(sX0!xV=o=NLFmF#NSp1el`^!EwX^F|5_6@;qVo;+^SAk;5E|lzT&l!`(oh zNDTkdKnm`!D5u{MQCQ7#dG=C9U5UKGb{%!gUC9!~IUw1O1yOC8&H{I$y4=X@k8f2E zMlbF@unwLDF*KAacQ0_QyuCMq86&BfLGM3*xc?tgaI8Sn?cQgqb^WcU;3*b4)8`kI zWsGKws3}(XSt{+85j3^gcf;bT%A^IH%5Za>EHQgYlT6Od-d|n}gMELn2mdt;p810w z1TRsBl&>YhJdo4cKnY$GVG)z?dd4r4ro6u#PO(74p6ALgwU++hy&Ew7A?ZB0e6AFK zY)jijCsED1b{34}M8+XfE*7L ztm-vRF)KS|&g-&oYjM`)-aE^^Sav%k4dXoO6j^uIXiZ%F{@Gj7*XIj9t@58XX(T9n z9B1H7{{PSR_iOUs;nT1B-!Jpj{Qob1Ng9oe>G&PWJbQ+cM?dZDez&u+2gZu0&x|O` zx@%Tyf#!$Zr47?AiW|{t)Ht`<0t?KDP^NXa#F;*R$wIb&HOa|%3Ir8D3k_7ivK|_0 zk!XbJ-%t{7fN%pJb1Dpa71de|fx_WUe|5a!My?{dEY<~i-T1ez|I(WEC=6gRga7~j z!Qr#|`agKO|8@O;iN{_4cK%gFxufwLQ-B9QA+A(5QZ($r?JbzUOXb$>Et9SfAXEb+ zjc_Vp-xb(yZ#{X;95vgpwr35tuteVtCV=&YFn&Bpgp0Qhz3)fyjYKTbQ(gngPv;bC zBb*0C8`i0)oHFu>D|p=(vkka4=vs9$DB)}#xaX515GpwjY1Z}bDayFMFD;F_bso}Y z<(fcQs(O0>dd>!0uhF|}@76i^JN;dM55Pg>jsP2YmA97cO!M!{lZ6l@2RVjsFY#&* zldupLf9>mQ1r=_9r|1%g+LHJ}zShm$-fq`$sSvqk0@MV!&bAj*bfFvq`dY^8yB8nU zHi^?^Ngz9@oc#aj0_o2pbO~i0rL#_Xr~xKx7lM6}t*^Dcqj}o4uqs@)axKb5 z)wyU_l&JQzxN6l=&3tz&-Ji!>E>~V8YGB>3i5-%>CuzJYE(Vru*Er8z#Ge9@xxbj| zYfT+!Xd&och;(T1jAK@bhDE}?um$b%t%YIb+)>xJb2NX57+is|UL0-}_N0(-e{pv5 z^XbcD<(tynu1m&0>i6&Er}uvgccYQq8U7FFaY7^f!d#T>8uvAd(<<)c*B8hCGd?*z zKR&%U{-5*X_pdJg`{(1+zg>)v&VTBXJ6d$F>*i#~Zdf1r##Z?K@cFX`cd(sdl&x3$ zP~p{U7UF%DV&~?)5F&exMRg0we{_3o_~>g`^)KC<)?>k6!>=v*JNb5l9(p_)r(cJ2 z*I8HdUUX$r6?c{ORb_Ln*_ll8#d|B9wnBApM8nNJjJVZveofBCNhVgWh`vSCF*_Vb z<1S8l$CPF~{qYg7wqzm z_hm{PXO2qGZ_+?NEtIfK^B(tRM$pqYXIl8Z?S95+g2e*o9C*l3hS&C9odf%0&^%0c72e=&;zp1%o$|Ymx@F0# zR%=5nCKI-*TOUgPQ31Gy3T^}}r|1s;s2sF6RoS&ZD$UqoUiA>(Qlty}DoQ=CrpB!O z`G@&sxAK1zzx1*8e}GN=e=w-W|2~wTzw-Yt@U#eZ&D#O3PQv>0zXc1|{%9u|`j}(K zUAV$->S1%W&u(4gGJ*;_t5>>#>ES+3!@4W4!(v)MUSF$tzejPlK<{%E^|u>PgT?%_ zXW-Z8pZT=&|1T^5KWpCq9X>ty%KyK_)4|#m>-)Fh?RT*me>Vj9Qil)_+Sh7?iteFW zK&ujZ-w&TZ>$SvGMKx~f1xMqE;s7yLMhcuuTWNjpa zI`~R`D|)NYEcj!4kIM)nCO*rKvTHR8+ZY?WyM1-JE^O< zaVT33Q*HI`f9zs^pH;GU+TUyaJN*Cj_~_NU;~}tO)#wR6uN;0%GBUe+V3kT-VmHFk&f=fCxaq1*7R4 z7|wDNLw!b>TrWglX7PAsGMP*fUwGfb z0>_C;Re|CdxRC7DA&o3((r5@qqg?6LJ@0%$Y@CNFrGg8FGD*HxLT}CiwCje%q^Sf{ zhN#ehf9l~YcWo>uC}XF6_zA~J*{;z>?LvmaOEkBsoS3G>m|=!L=7bZ0x##(AP>f-) z|DXDH%nw)~I2ykx!eDtmjDK+hnFG%=wM7^=@jQ(%i&qjSlFk_7g5`Q(cTUoH1y>84 zT2BjENDkYsA+Z_++Z%N^Uj@6eqfU!eOh%n!tb+nUS+;A`&sCHp z9TQEDPbD;$iJa(=&5nqngjM)eBFP3SX7Go~yWe-VD!+GuYXgpo=xb71l$jya0x?k? ziwqhOL^;z$SKZW&dEQ^(yYJ3P_T6_QcuP$F1k-PBrp`o>M>eIW`p+rp8j0L~>PI-n zeH%GwKDT_Dh%y2@Nn1dZ|m%22`Xo^$80dY=4qT)W5!HLzx&|?*=3eNlp zDxtHHUBqsbEHwulf)^tqUpv${;c?s;ZAHssfe9b|HBQ`0CA4D00jqBDrslk@-Y&5GBU+F-re}bC$ zuR$9&pE+;pNKz_utg5ivDd5`Ar;XBC^8Z(DWV=!{@`S8=j|%}9)EIly3v zn52ygVE^!0T)&Ft(ncL`bnK+7QmpJAs>d6t^1{}{p^ZxNb!3x#Z3Ot)v$%2%by9_G zb5FEq;`$@7sTv6;71(V#-sHd?f2nB8#Z-DkY^qm1tJs{H%vt6d=(yaWI{iD28D#U{3Kzw0fC?Mf>CB9^y9QH@P1Bq|v9MM4HkH~*P%CTe^HC=@g5?ie z;4Rp=z5|mR7|X*#r1HtxPwj357215(NOf3bCva1wp9+`!b^qHe=jdPXrr*% z$+?nCvjwvDU<0F6Bkpd*rZk#QijgwuwGdY+o75qRvNC;B9h*vCr+ZPUiA|{hov3}P zCBs)QtoRLe+_e^hn`n+!)yTtlR_0Acd{HF>moqwi%EYw9eY>e$Ls^fZS6 zgOs2qfhH0aY%006K5wLofBPd^7z1?)MY%-ZjY2mt*>J=7KK!QYt0Gs`=VraT$D&u* z6iy~>ymE%!=^c#9c()0a1)!yn#Gk{L5ANPb!Elt0{HoIantBBDQRPz zk>89}RCAs93Oe;CH!%6|`)BP_t}(2B);xbX)(KVa3J@j-`%fRH6sTe&RvE5ibNReT zjHV2bipeNFpRzTYfAqZ*Yl@rPz@&&)e{Ym3*jO`M<#boc-=+i2Iu=2~9ZcX+=1uEW z2Ls!reXFK;SO@U4dGQ)gdbw@BqUp9!3!5-p&HpA(R&H*#$B@$9$WHZn(KRt=M!7)eTIZJ~B4Vp=x5& zF;tI0n@YUFf2wY)EoowTYE#R)3h=YJUu)#b$(^uqOxKTvjg5-bx-+CJP~SW9EUst{ zS2T|!h{+``(k{}pOq?3s8O0lIB~&TMTq9tDG7HX4SjKG{bIFK5SQ-@u{5v=T1n?te z+KYmuGs+T^WmOxh8J=k~hO+iQ1im@jL^M?TZEGdAf64qY3KwNR9oK@1@5>|pC0@Ny zlH7;A;?LhFfQ-6aqBe1j?GxP}{0SvljQ8$glmE>F&~3VAo)^i=&pBp$b!*EDt&g@! z=)JndK~^k`3o1|9I;+1PZ)=m*%2^J`HTo)pl0-UE_U~NTpp-GXP=rsaI86fQ6cw+4 z2nTY3e_ILCzM2G{cVx8xWQpU|9w7MJ(Yv?WV57VNxEeoVjNaPtT&~q}-WsogOlxE# zxLR17k7MrFnO`0{aQ@61zE>#e^r&&%68=VWg;&mT#ckq)1LpS~=ZE$d8JGGfJ!rM{ za97V8y&$-t%uvr6WTjWrengJv00*S4XPZ@Oe^x(Zj z<4+@bcNw+BHvv)lyBb5nA*P|@c4Ab7gcoTu^$L$xDN0CazZc#;B%KHF#yC8*YV7$! zvD%ahIj^*XQ8i=7o=tbL#zqi$CIz2LSFLe!N&`-L;Tb0RJ0@a*nVrUf+N`fsW!G$2 zf3)_1%DPuXep6F9&mtu7L?`N*+w>hs*&~e^wph|v3lc6Q{m49}O!w3_ElG?_z8{@y zNX{DFnJHeNC80S3td^=~0L5Wg?i(3SBkNP78Hb$aTcyRVbpW{M4FfQFRN97V!)JYc za~N3Xt8(1BSG;1%U1RxT{L4$7O|6Zwf0_wqmN>6y&Jpl#6}w}WcHS~d)t-Zvltj*l zZ4L_(MK}cuPqIdp5s{<$n5niX4uWP{x3i>-dG&=E^^{-IPJe>;wx zu2cH1Ug<^cG|DJR1?(sd)%U~a&y=U9T(C+pgd@e^h)}66KV>-7*>nwyvv4F$LK?^V zv!P^>TJo|?EooLSS175!NJ3)70CB_JdC16Ai%3e0F?$S*>lgT;<|Nm`)yuBCe@oMbV#V{KXs1UQavj7jgL8&GcJHLj7tx? zZ4MJ>8=I&RRYp-w0JG6>x%nB&XdHM|UTdYq8ZG^n#4ertDZa8{lKdq>zK-uh<|@3= zuEItMo)H#^#KvK^8XCkqr^XS~rn<5ka#_3FIrluvE+C#a7mF_L@JSi7BZi&lbZ~%Xj{~Ycq_L1bu&5~148N+B=(>G2FrIx1>%V}Qt z3a2Y5vsIR6vjFtgsQ8fDe_XIU7=+lR`~`~R3!S6WEUN;P$tZ2}V;aCtf%0N{ibXKR z0tHnfSIPI{`nR5mKk{2|B!6(Ky-k1XjehGn-TAF|d)xE8UnQ5VlAuVbD;S#1NLVDv zbF%OKU6QfLQ*P+4=4ZxmD7SBo&tBWWRTQl+v<_D?MnghRrSe5OOKwP!&{vYp?*CC$ z8Cy-#Th8-9dxGmiwi6NIS&UXCi=(;7a^)K$_c-MNFw0}RqXu8EYJPpbK3|{5eExp` P00960+_pv;0G7OiwG0|00000|0w_~VMtOiV@ORlOnEsqVl!4SWK%V1T2nbTPgYhoO;>Dc zVQyr3R8em|NM&qo0POvHd)qjYI110-{uEdxJF)vUCE2;nXeaZo+je*RbmI7DJ3YUB zdio>~2}xK}1cw0aXcB+-^Wa7TAb8Qm?j&tJyVEfUR26^%PzBT_LlLHf!x_w2e*x$5 zpYGr{91e#so;?%)9S(=?fA^jZhkx38HheLB`E%N37{m;LbMBDbPbabMc@i8f@>J( z2v9~c)CVUFU<$~Dp#)@Tg0c)nfDr&GfFObl0?M*HWO;@FMcFmV0L4j&I3x-}n1GNZ z4B~{>!^xEHf*GVUM0Y`qDWki9B1QpBB0x#TP$d5DZ_NlF6+Hk`%x3x6?6?|}0m~2? z%pqkcD?W)ux`jjDO%1^uJ4iW>0c9|}qO$e?&!_TVfhZ34_lF<%pFZoS$#m-qEpA8_ ziP@5{1KvF`PFsN(1u^w=h(%XXCaR)2#PLY?A7%8v4I;LHn)vV4M3(hYl;QBdBSbm4 zIm{SN`jf0^V13wfNPww9L7T0!Xe_~S%j%T2F42zp$W`mCh$~f03e2A6w?v-bSwTe zg_1?1rUl=2pypw-eoncwd`|=3< z7?UxK!I6-@0G`7s0x8Vk95IwpUgIoAkfL3X5QYGoK_(gE2FEcV*C@+ygakjhjduY~ z!Z?pO#pXe^TQHN9-E%72PbDc*j(zk99OhYu5(eNk#4)E^*QghcTp7jKF^j2nu%J0^uExO`e&*HGALUTy~%rfYK zXcDWTU6^Hj+Ryl*O&K4mUr3zK(Kg+wf|8PS3Mu8vg9awpZu|1h4k*5C>q({H1I*d1 zX!C(X-ICxqGd;4$dj#eS{qIva=j+=Y5WURO3|~Wrf?_DEz(kSR{ZX-J>5bu0LGwsX zB$Yb=I27`a$;QTTT;*e=RABH{v+vLO7-flA)k*~7T{WtX3WKbsCce z-UDt$z_E^E$``T!#NMR(q+Khm|h zY6N2gEc(bYcqHfn2YlrLGLeOvI8L-A7~EhsQ|F!72{|4EzzF>Mo6UaZnmTc}Q(jML z*hV$M`TSFcCZ(Xx6=kUu3nAUPPZ%&br30f+0!Y8uV;tzdT}!vnI)bN-{#0qj;IvYm zmu=(uJZECF<^%$maWH(E`Su^}Q~;%U9G{UGhgJ0a6G+83Z!^8idfUl8mR1@@Xq->M zu{Z}+eOWXok(gRhCN~?sujzm7^&?99a~wOW70yU9hRKz4;{!nbZ1d5P6|6b$ct7%p z=4mRfrvg680ZgJGLp0?Kc#Txm364<^UrNz6qR_GA~Jm?A(C6V*>9r-Yqlh@yl&aXLC046cfm+{a`P zk&q5@in3su;|L7|0y=np3iIZs{%XCjlt{DMInZ)r{+$M@mnCi}{!<8>__dM#W zaZrpj&ne@=*&HUhfDvYhYpVb!VgnGHZ3;uw_e`CqOAOL0Iw*vlASF>yT)z!?A7r-z z_dFa(_^2-=&_|CzYM-Hx9*JYLJa2zS3;9_cykd~5&1w(dM|wpVYe7K~C8hN1-RI;s zZtDn+6uB&iTd>UY8)o4QGbFEgOA^fDJ~)VDa)Tl%OVSbeKp9LT7?T8j03-t+GL*(R z6u>|5Rc|)u3%>ZuF_%~layCN=Q{S8}uC|g9<4QunW+;#s)`6C40+Iw1oKY5JxsXS= zG^VCs4+fXdlu)myun^>+MXa7rTLq{9;|mriC~ko!^cGc>ZxBR-*M)WP3wTw@v%2d* zkijG(bFeoIxM~DLe&)kCoxvoZqYQ`Y8lP`V31NKuDYghL8-iZXGiD#TW}Hmr>HwE& zb@NRECP07HlDZH940g{@#JdS&we6g~y*wU)f6Pz*fc`hQLJK~CLepd!M%O3;lZ?#Wu9@^JGC-chh-#8;Tn^#J zaM#l0p+BccSNH+Ph=MmHPnbEZTq~N0PdK3r!H7>xPL(!|l52kC&bh{O4KvIcRny_Z z);pKjxUO)j_Nqf`dvO7V@wINAfNOoF9D;jMlpXjZpw#oFN!3^!nyU6ouD_bH6G0%2|>f zn8UP|^JR@UFqO=|AbAGDoH8g+;vumBCoWsY z`f`q;cwt?#Wr!av$rK%p+V{y-{$)%}a48yCKOaqGljlkY;|Ji)pE6;I`&JhLDOHX@ZwxcL54v@SUL3vwr)t~v?7503#gf)t@ij`g2*g(lKUJ~#E6vE*dw49Z`jzDxRZyS_B$~k^qp^Y5 z9y;CpjMs1#0qbMS05-zK3FcDS5sD#KGYQ|pPGlK~cp(=iMJXRst8F{*6lIu18tj?) zYaMtD&k@O)26!p|TnFL=;yBOH+eM^Dsn|mQXKbK`YcPU>A<; zw>7190pOXn5qK^>S!1pX?Sa#!E}0{+C(7MHk@YKmF4)@3q4wA1Sk!^M9FN+KJAiNH z(xoAG;M1jHcI4Eh;dbOz4_t9mYL?y=x9)9%Tcx1)+S)e{rSNBOrs5g2d?(|oz7{7* zQuN#dPCZ`LU_Q6kgF@}Bl4Wq)088YRWtJgnttTF)5mj%cF`i@Qo_MX-w_Hid#Ra3X z037&POnvQ3EJ7143KeR>R=kHkby1zy&A^NPNbuqh6d8!RVi25Mm^5;x(xA0vf)s~G zVE_4xH&~U0X+8pb!{J<7JBUtot#8RLXC$IrCKEcE5R%YGwh388>wTgKePn}26ft!j zX@3bOBnu#K?p1lj5)};;bulh%X>6m2U4f5#~-0GN|# z6Hdb!it-p`LK`}W8OjpK5Gcz1N)Kn_Wo8;ibDUt_G*BC6BW)L%YB(VjGC|qiHHW|un?Gexgmy&q7E@1-3#Y^P5NiZN8c$-N3Emd6# z6N?m$?5dJw%#ymJTU_FB_KP8w~ld9zTcW`weX7(TXz4eJ?S`U zfublVC@Qxv2vY>cr6>SZ5lBT@ADpOnFFXMs^i8p<^Fh6G`CgRC zgvqz$8O)*&OU}94$@y%fYb>5b29Q!bO~jaRt#|MUC;W)ue`|V#r3XwHE=o+6u=-lJ zhX~$b*f%gH+;4AmDxDqyPNjMQB@qHn_tX&F1?~KQD@5`_heCa(*;81pC=Ytk35R-d zwry?}og-7QST_o<&_WU@c3}NLJ%=oubt2D1euWlG;g%gT(W{bGC;-QO@t`LDt%gef z2|xhQJ__K!_o_wvW*77r*Su8eNz@&wKWuHWldj zpqfit6H!MfBQeU9XmM%$`_5;cpT11Ya!Eo#xj|JOv(hv}Fghd&7u#{dD7X+Mz$~ik z#p<0X)d@Zr{C@&QQWBHtB9J6;(LxiT?x57#ee?)as5TAj;Kz$AbR%yM)uW$={WITt z5^W$SK5@Q$mr%$soruTB5jY~Jgk30gt&m?TC~H_D#uF4S!WjKT$W@mss%^R>-aB(f z=3LLQ?IM&*3dsPRDE%*EPft&S$~cqaV|sL#$)KCZ=>GGR(mK09BlHnqJ-Nwi%) ztDATlA5vu^8WrP_S_7^;P%lWH zDQnV1tCoT}r9HFp-T8D@V@j)itx8nDK*zt>c*O0c{RX?Y|MXeG`uxPbNsXwmDt_ z7Wtfv5g0^}!FJ+lK0ed*(|jD^OvoAwt--6VaCukQTCUImoPY>jo5nU4xr%~%x!fYx z^kJ*crTPp);iRXaolHQ4COARSuH_geFUZe8DS_ zihJ&Ia2-dumf?ls74(f*FWM5ZI?A$^F!r}*(rB%psseD1VDyg+GxRnIJ1iz)=H;1K z{BP^xmH#~gfB6x2=#zO1XBf4~H&W=_%keQi`{mH;mdCfaxer=vFwn(?)11&7J-GBq zA&+Y<^OxG7Xs7NR%Ti(cI|B1X0MpbOAzN!`+flXEE#D0J!UeFj=sNr5Q1QBUbkY7T zg~N-I6vre_B6|~14$HJ*AGbDIxdWTzjB1{qwd1&RAPHXr@ui00)z`W=4h5B!F9XKC z#i4w5IXPX#9i+jNs#xMy{CLGNKCCU#cj4>B(f5XB4v${dGT1y?ZVT6}ETI+_r`K+y8ccE;K6H({K42I~;vamZz z7@7*$!aYu$u|^9pCNXUtzL3 zyUw&CtMi@dgz9d+XEg20y3bfFz08!~g#(T5M6(A?L2@S_ni`l7PBgx&qIxeHXX{(T zk49tjJJMKqzHC<-V~20|rCDK}ZQ7g0ptqYl&E3(wf&B|Nio%__7Gq|Kv zO>y)5Rr-xId(~Ksy`o#q*F8S%el=gNLyaE!H9cz9nn2LvQqw?VXP=rn0^6Nx8n7?v zRntPlox0Vyxa<6CYzg3Z_N=MhaX;+ZA8UPU>L+hq=Nc1o2k)Bo#&u2q8cl0A2b()# zft6is3dv)69~-kH4_-F@2Zt6n8&&as{A{e3$jv(1n5@v%)y6~4=6!9dmlsQU+Z3x~ z4R;&g*nHCtH+s<4^tkbk+k?+dqtDIRJ^S1gLc$78H}>=5hTLv^1g-3M<9~NBB&f}M z-uUQW%k`#fA69n0@lyQYeX}v|8{hcev-^#Air4eM@%HL&9dNw8_yRp}{BOcbJFyg^ zi{Fc-0(dz;78knX$WkS{t1F8OxYd`%u%uk_+UNK5W^udO=FUEVNCOU1Lr9pqJATilWF>fBP?HQkkWOZ9=Mn}3UQ zaJ{*wu)p_j03@7V69B8$2fKnLL63`bSG}cjxGisR;P)rG(Al->{fUYMS{7gF(n5XX z-SohE3`LjV$oJ+AJkb|t8>_#HZ#xzsq$xf$GA3?rbC3CL9Y&q zC%t9`PLXG`0g|0^(*e;b_htidZyHVqhnbJF1ynUPrw^9S(b)j3IbEl|deJF6&7_@* z2QX3PWx7s3LrAH*$dDOCXpCVJ>0%%Y8zJk!hOa^Jl`OdrWqWd_&G zT~y$@shOe4h4inSWcj>YX#Yq2t-;8zg(GQEi(%n3sf9Z()cCB zkk5sb2r+)(B~t*MjBuRmd3!(P3B)nEMwy0X!c0*%A=z94)z5xFxA4OgN$)Kuha=0m zLEHz5N*t`b-aI)I-QEJg+s_er!8OP&032dRVDB&TLj|jAJ73Vp|BPc4Uo4W48eYMr zFYpX95K0R?zJV9X^05>Zcw;kheu8d_^IJSTL3@NmHcSI&@#5xEM!8rUo*ZeWmVcMb za&jc)WZ`0~$lWTg2emV<_*&!<6_UmjB`A}UgUaZM#eJ^%LdIbzSzy<~prn-h;I630djzq@61m#Pc?nmRw>+U>V^uMd~v~i}ixlbG9+@C9Of%G1HflIbu-x>JA z8P_IfU~`_Abfommch!+{{~PzDEXHqDS4!WiX@Xyw(f3sp7CmNyKBc* z=Xci$*WLQv87F;AXGc&0?-&x8_5-%M)5)5k0$vxKwV=5$FKr7ujk0a2o;9M=&;NXLjxen=V(1R0 zSZ6jQhukmJ2%>mp6N91uFyEsZN1@F|qQZ*bsEtHrV0=armBCojNTPzI)=Hv+>C3i~ zXzW;xnM6w$AIu~wW)hWAUe!**9r~_z5(NQwW+;)!9eCv+pl{g>Wv0b8|9UDp9;nUD z5}LNwT|?@hGKL^V!iZo?6{;=A8bj-od(j~_Ki&^A(Nrs<3(cYF0p5!O#xc1$*1Pr* zNuDqr7aYj#Q~3e%nFvXeAoD@#A2XEb$4-H17my@gNIxqPz)(6yXBi5a4X?caR|IL} zS>=^b+7p;|-BieONWAipq%R5Jg7vOZOMvFkQf872CYj*-h1xwN@a+nj5u!{pBd21g zUtETpgH;IhwX?^?#FJ#2@m?K7krGC+D#>yc#F68+rqlJ5Faa4pD?Z1P)b<$>rM%mf zYSD#ZL~D4TNGC4KnAZ9#Yh)xwBMvxWNZXMt0sHtPKd7nLMf?ba<0{AE`wRd{Q3i$m z?n&aWQF@ztK5`5e@mi?YgX}6Do{2r)(7Yb6I<1U6Olqe|J?=86YW7Yq-jw46UORT_ zT)F03Kq1|V9fgQfrLcmaU9g;y$V7BTqKXmx63B$BQk8ynLf0S_Umrc`oN|jU&!m!WQ3@jxfz~ajgcv&!Z`- z&TL1WKFbqR`!esEqp{o^qOr3bMB`2JLUs9Z1aq7mTtgfS0s9S3KvLN52q9LyiwFxi z%9QUSEb7aPR6e{qiit*Qf^|)E1X}p4ejQIpTA3`TC-|6j>nw zD1ul_T~&iOROe0ym4X9+Ih!2{0iUb!rUF6LrSy#JhoQmgMib9cG}F+35CbOi59 zF7cbowFu=cO;6Rp$!lBrkR?XJfK+fs1$uQ{c%2_`j0DERvH_T=LKB#-=m+yNT6iJ- zj22#KMtwiP!-EpuK`U`(?JBfrCX`}Yz~lcggQ6e(B=4^&*v1JUS%joLPo9eV$fKXY z7*Z605T`Sgl~?61;E}D6zdC={9b^dAbY4W1U_BsB2t0q+=IQgZLck-TyGV{^1cVtf-UuKatX63Vm}eeMxYmy z5XLh?SPM`7>Hrdar2p^%)E3fn32>px}+pwgRol>P!VXp}Hee0S^`TXlJ8` zY*jOx>d3W#U%|+x2FD6EHV##tVzU<5f4|tQ2EArH)?X!{-x`9n-W~BBg0#w$v5@6B z1{!8i#8BjGqUWg~??!un-P_;m)vk}_6OyU{tg*qU0A4aDsRP|H!Kjk$jpe|*+yc1m z0l$Lj8-2ic$EEgZy)qzQ*weZv6?a3|Y97~HI{EOpUd^uQ4DzaP>+Z<6zO8$n<&R6X zLhWFFYo3y3$IpCK<+-4s)S^KpLYUU1Yjo*KFAAl4X|-DStEyi&jzYU9c)iZu32>8h zc#|I90eGECUI)LUZr%ZNvom?4zTOdfgMWFm4qxz~p~u&Ijd$@Iw>9@dcYoR6GhN8{ z_V?BIMi1=Ob^3L*`uou9ZOz`V+qY`>x{@)J9*^wWEv=)rU9eKE+HEP`Rn@zj@@)zy zmIA(v3jX^k;f+JRj_rO|#e6jaTFv>FSJsP(Y*yHPD!WfhGJ-;2XzwZJ!yh z#@!L+I$kujc(*Dq-yVIxqVcy*lvj}irM3Qs_SP=urun3PGQ=8~Qw zVlxL7k70OK*lCyZrX7a!Bu11fMF%UGkAT=du3^ljqC%)KqifyFAbY}lCbP>dNDd}M zm_Qzq486SozZy((l28WYSo}B3rG@uz+n$NmDqc8)8KVQ1A*3f)fATQFBNj(lp&S2d zai7ee#`raQK9V}@Neui;04Z>m9AuvLmu;>kj4KGF~< zO=FSLhziwJOYl8{Wj&*@#xEGvZef{&H+t z9Kg@JYm|vZX(-DIcBx3PPNRH2huLCeI<1M|b|C_vJ^@buV~MR_l;7U=!0oM$rf2|* z5Dhadu8vm$SVm~nFzqpaBO)*Vgr_qLtsMHl+oY(ekinYY^BwE`c)<`|Yi7O!d&8lF zXV8Rq4nMAs)7#4}bU>q=`csSY#a@!FoGmgn)T2q=>okeB@)C&(24%4qjbP z$V%$#e~KpzMh(k&Nmaj=^?pW+M0 zkTRv){eji>vtQi4eyDWzLl^V-iy4aJ&-atAHQc|z~g9JtD8%e^Jqdst`Co!<;S@K-Pcwnz9&GokM~d>voVvCB>^cI_%a zm53!>LXuhe#7!Sx!%(FX2R)cG(%W?pFQFOp4W1DY&d7~esrm{(f((KQiIv+KhY&15wkZ3vIOcYBFl!ZodIUb;2n6|uk@)YA;4=tw27;&udLWqWf6y2tRpKg4ksB|7 z3X;uP>1~RViy5Bi%R4R;(J+)jPIQ99T=YAlV4E+uA%~U_Cf)e;e&6Z@U|0{x@HHZl zDqYZ!#kE3@xI$t?$JPg`y1bs@LY7EX8S$O;XU>eV4!=Xew!HWUl&kP~ENge9nQOr<;uPR$O%~ug9ED#%$A}pvYiVhVR5Awn{CNJ0% zU7MxAzwvA?V}V33)RCVEWfuzy-pG&(GX!RYGVozQ7xaU%^M4rda!ypCq?qlkE#&u< zid5e=CJI&H-JksPr-$FY{=^;EK;Ad>X*ff3*#BQjl1<_m4u``R&z_0@4u?bMzk9>I zXD|P>_iXrL`10v+|HZRE4fmc6_lAE0!%Y%V_sc1R*`J1M<8nLqmHa+!0nmFaC%!iV zJ+&Qi76=qOkZd}T|9sTj<<;3DMZB(bwUcFO#-%@o5$%n@C$X-3Fbijxp^)VnDoTy^ zlw~-XiuSS`vsipk3IELIMI|n9_M`!9QD)ph^5zFp0@eY%zz51;62X`x=mQ`b_@L4P z@%kU+X@9$`NY2^JN2<|Po796c(g+uPt?(z!M0-X|lq>nvDl{k=6A~j>!mfjFllhJ! zkU~mtNEVsVQ8<-FgWIxgPgkxZ!T;Po3kt_O}!YRuC*P(34_Rx!rRAb!)MbG!0pb znTnjMMfyysx~#@XMjrIKS#&6|sW~g#i}QVMQ`c=;Yls8&oDSN!y$PS)1EnFF15v5$ z@Ljcue$lU_!as~5p3|NM@YZ1>ivR5nK4@7+HIq=Fz2G318jp;tZka$AWB#v74O#vM z^C8%)`wBnygo{DV_jd_q9LJBi3cqIkftEE0%yp{O-C2wdPpc&B)yrFoijd%uzKTi9zUzl@ zaYwJ7)0IuHxSA1CAk$ZA6P$=VYDI|cUYpRS>@+%zuy0#0mq=-%rVRrl#2}98-Aqw| zSlKRm@M|;c#%Vb$)3Zk?2w`SVj&jnkLa${Q?;&6tur6~B+|}0IFn-#A(=nKB-L;FM zbPR170W5>zRjtKnfpNJVbt5vCBx!?t*cSi)hiknr_9yTEv=JK}oW8w0zUZ@$Y=bzO z@BjAqo(-Q>?*E3*9`66{3L~kcpfbH!~c|#Nfh}2Ve@uh;LF6N@KD> z5%})At*uX=0)QuF@Z0_`@)lVtYPQdD@3rA9*aNq>x^+TW(GccrR=n8Hn)}iWlk_jw&hoY#-)$A?yW&D^9X-Zv7-o6wY9R>AWvV|AAyc8-0Kb zK}r(33vLjgEF;M@UI3a;r--Vs$DBTTgH`%~Uf~(u1IjS9cd8PD_4?p|0vHRz7`{fk zqHzcl0Aor_DAqt&QP{3=B(wNm!x%^9btXxS>&ntnp}+Zw<~)m%NV9MCpPH-Dze=Vy z)b&DP5Hf_xS||$c9@Pd!wH*!-ha|SZ7=^x#UTGD?SXBagmE4<%+-!>np!8P zG6i7U9Y1HUQ=GTsAzNSA+y~)-!&Ozf6*X1DE6conVts4UKQ4E_A~kocx-hq#z0KUJ z+{1e7l7J~BJU(yimN11h^&5M)TC z)_wKl6kVh2322-p5CkZ>u1tdcHwPg*4+3d7n5;Vp+!BC zD;c|MWgLeGb-hquZ1x2Jyran3X!LY30w7~hieBD}eN7-Ww3iI`8x#NV^DuEt>-b&Q?(D1a?Dv4RiL0Dc=M*Te|BB1OZf<=|XnG zz#J|BgI5SZFhMukkGwEvHz9+QGZnq2xI^j}uU`Lc z?cM4{WpixVqmB~p*U!zyHF~$5P){@;fnY+i8<<7iW}9AzgU&PFVem&?Cg{)AY2Mp^ z*&p_Y{k?B>lB*(Fhx5<(j`nc+t**cP;ZMYRhI%*;>(9fL`R#W z<=W@t>KxEI8Kd^;TH?I?Mkd^^%v*}R9(}0*i#!?ULgi|W_0$)vGIsh4xJyP|4 zZyTK7^XJ-sy`P~tMH%h0G~N`B7W=Q^%c}j?irg0ZbV1T}D18v_;SLx$R^ zTX;rjnDv*P0c`DQI}+h#z=;5+qoSw)FF=TpjXR+c9Y*(S@ZHu=D4v7;{@xy-c`CGE zff7=Rr^y^843LSme$0_{i@t^#7Ow&-o;JV|%usa6Rfy3mk@e{91oXu`DdQ{o?q62x&0+ehbesE4gwUS|wc=Jk{DVL&@eyy! z)z3cYNiCrSX*|`LwfkljzvZb?k4R>plU6Jx?-RC~`>9V0nw&Eryz<9efEGR?~4(UE!99g%Jv)5u|6Mks}>uznObQ(Oo3 z422ZmSWFL5#!4K8t8(wKv|AN0gitSH6Q~*@blv6a3ofN;2TSX2jidiTxBOgOI}S+7 z>}1pfUXu>~)58tz{kuYoPJR3tE!w*IvjVkRSARx}JMHb^LB|O_=rW~;2Wxco@Ze5+ zdi0ZYd!ns$sGi+*15NMJL?N%K_h0|LAoB(q%`pVvwo7<}hu% z<0@*^ju-lfDZ|P1uz(jBDpUDH(gWKpjT@Rh-l=ZrRWN}aNv+c?bl>;0T*%VU7#$gH zz(|j#lP1-TnD|_D%NjE@PuZej2#g*JQrZds5izyum1B+cb*WwIrYnqRGUXGHqDx&{ zxC`A}&rS8Kr?TdQjZ9gk=luMV@6H)l3eYu*q*h&b9S441_%1C_%;}_2&6#9ousn-c%VB225>c+?(n;mlzH`eTe zLNG)LI`F`@s?_hG8BC&sIGw@Md=B=8?d$;#XDGblbg>!AkPP@OpHgK6a1}~N-m`+b z-LUck8@La!Y7@{=-uqcm+kN3#rKNK(zX}NZ1;a0(ka>z@1YjH&;pzcS#AU3y_nae2 z;S}wPeI(=+ClJTAdy)GfU927jhw}9kW6JzrV489Y%d+jp2k$;jGX$eUl2DdGoG@zb z!fS!H;?mVZ)e#BG!d|u0yyE{7oPgdxlb%sEFbw;Py1Fqaw#a`bzZ|@NcYFbUIe2|? zbZ~j{_H^{mgm1t_qt9YiI;@UgR3}w1*&@uH*hmB5j3;Fj{QMURu9afjY0`a@;+#j@ zj(+{Oz5d>duIlwp)z8^QDDVl|MsAmwjC+4ZB5+Ak5|ilyT!<>b1i;A>J`bgXJxRn^ zfWN;2oLm`U0w)oelMDfzOh`7DGAd-9(#7A9>?$TOqJxyk{|T5PDUeiisZotX|n16(}gFt*U%3k$8e*E~cw^NxMNAjxpjBLwevyE=cuY#KQAt=K6qgpaO&%6)TYEE2HYJ z+jr>)R2?$??{(}yT>GCfo{nKM9ZVrZH*nEk!1>yCK+X0)!@U>J_8j}47yB>wAMAhb z?D48`+4oypAg-Ui}}(V~h==drAk zTi<356F5atFkaZLRLH>khAGTgKqhL`YAS_fo{|J5%$%96iXXZ;vnrLdc|k$`2hQWB z%AWyFB9t)jOt$-Ey52Y7GSZdGx=#L5J`458&DISR&=iFnnB100COJg_8UbZ&UGkg^ z=OM5M!d`f!EZP$hzcd# z^`6?xFRY8|+AUo%Q9xnmUA>aYxTkmM86j7_5lAzn;a0x~HwaH>BJgvd(|OqyA`~Nr z0`>Gd0-})SVJMQ*?TSCSf{3DB8C*CJMdHpElVmFh0&7UJF$~2G4axAoMV0dXS`F4Y ziBaniWke**|276mrQi>WXLvdSzxH67(%x@YQYi2%S2h@$q3dB7N?U zR5;MGpRV}g_7(W@&GR3{5ei{eDgZd)^EU!dL{!r!qN2tx{#|*m_0FXb+bY&(viwtL z3sFsF)t0M6qb}B=7D3AyiOOG#sb~q`v>2^4?R)AMQDXc>l>!x6PA9>9oBRNAtZz|_ zyt2mR2dz9)Oryx2APuMY`Vl4lIgST7Bgq&hSA!{LF&yjvC=b5T-qZeH`$ID-xz6@z z1tt%`V2qOiojIjJ=oEZ*;+s>%K!BV=JORJ{3LO8@^0)#)%vG;f9@BLB-f0F+Na}qJ z_x}zC5xO2Ec^re!;3fn?yaR$M14HoJZ~q0@3?-Go?V2XJ=xwqZaCIlSf)Rx?0(uw5 zaSg;YqX^__-wha#WO_^=h*M&cD}`fh}E$*SY{`(f{{{FZW&j|H1$B zo__am|0}F=l{o#2WGf}Y*Gbk7x4*yl?Qiql>z!WwZuHt$UCgQ*UH6HhxOT0o113&U zt#r=%^a+4I_zeD)6NWrJXJIPQ&ABS6Z*|3Oa<}_qjVdF#R?Px4iB&1>npf1oe@*R= z2~o7+ee<%sHxlH-8UL;Q-1EOMh~3D`ul%)~|IeR2b>lxg-yc4l|M&7!+q7%jRk3as z@ofCh0J7E_n0k(LJ9^FvHr-;YY83{o%~%Nqz-Is`zxAc9M;7(OMxNNmNagI3ZC_WO zMqS`6jjy$#mB?-hwt@6Vm-*NH0DB=x82ZS1;4#>#qo(dym5>ga4%AJMY9eT%*PvFj zLg`{K0-poXr$^u&MOi@eG>tKefJ9@vE{y8u;?Qz&*xZ!ZaF?4I-l^jx0%YRt%@$Az zwC#b2aOOF!jeMeg;pkIfu!l{h#KTLs44ci{60EQ%T4eClMHmIBvr&EzEnPpB6XmXNK@z zm@dv$UQu65$+j1WEfd=}NJxZ&VZU?z8G=!aC|x}PShtw3)jI#mNtVwmLlTjjB!Cl! zvS5zm7*iAy&LCZes8WFgJK(V1n4nyg6NqDSjk18@IU>1#B3p53D3=O|izS5_jAIlB zbdiKB_D93G5Fly}mI7n@Zeua~X1ALf&?}$I{$6cW^CtXpG+bBzLmycNgBVk`IR&sq z{~PYTc<$h^+a3pQqm3@Tgjmooz?Imok(w#rx!um>n?)ukfdBBhC z4ebDJ?>~FPm+tz1vG;KQb1%Op!_Ln zXA~>>765?3Y>L>KAf+U((}37L({BISdAHOwUbR@exod4hY`LB5(#mV%2hG2vf zMCtpOgfQ;YS^2K>AHwuj=F#N^zy1n>iJM>I{SPOvkHK%hfj|GbCNFsJ@%G<9@9`&3 zyW8H5yg)Tu9=<+#fAH?|r&m1(RZm?B)089>y?VT@Peyga7EtgMJl>PZjIBHy|17PV zXFzmxMkoXS^hHf`PIA#G)xExaeIe5d84yM44D)Z57Q9FV9sWT zBHe~#xvtW5)WG*a2P%a}eG?Hm$wQMr1F17AYD7Gi>8Z3+0zf9a!4vQ+=sng`*aQFZ z3iQt2p8nVawk58#Pc19z;*XetJ@JPyX%#FS<7@Q5!4Dk#yK^vSpz6ohZx4=6PJh(- zH7JM)-*ROpa=sT+!~jmf9L-6#SZN`2)6)1_DRqs9RnoLdE{;zxPfm|t7t7`S>AN@I zAD=(08t*9meg^=|C@Q#`_TkM{!Pf(v4#1}$-o86MdVg~EYEKe1;0#!li)4rTOO_{W zonvq%apR?9V`6J!+qP}nwr$&*Ol%uBHYfJPP9}El=6(OWwN+dDrR!FI?pxK*`JMAL z7mYwZfR~^9&+eCL(BfRrk)^&gN*JY4x6rMPWBCh6|HOLrm@g1ArhW*hQuuIsO6;-; zMb80~9qW7phyg3MfSrXTqi!cjzio+$Y_1O5A{)69dj~%ZRCx{T)pv4fqqW+EOpNS` zM6F(&(9Na9PgXS?cH55K!PnCxENpj_R^Yd^yc0fa6XvGpY*AeA5A^Xh&Y!8=^tNR^ z@2LMYZmZf=e)BUrhPL<;$$Irf6Z_1ByD>)f&Vc@2^EW-C%yKD8a-l6W`X)w_zneT6 zP-ys*&s6y&PDzC3yvGur{Fy7PT}cE2YiHo!a5rLS1vms=)aSb|9mUu6tGbtGY$|uY zcChl00i%V!Kt@XMq(6u}K`p&NfS*9k29U1@xH~n+y;ucnsAd8&_BzB&qcv$iPJaAob%fhcTh{G01SoS0zL>fy(qloG<(bn zqM&Djns+W0oThjR#<%S!jWozH*KMa5uAMK{*(L4YG8pzqB28;P(zN_Mf(*C&5Y@9t zTdab7{B+35Yag`?XYT`hRK{6Yl(XQ|5EeF0z?2%BB#!iq)BJ|P{@+JigV@A5-k2uD zI6dQ}Yb4>|k|7umNRb8Gyh9@TCddisi4awKyA1IR8SH8=BSURubH65&zJjo~*T-mv zeF2_bUYx#m#}o-r zVU6PzL2a{P18yU|O#eX~y?(jlKS_8fjhW0Kvp!^yUKZ_o?g4kV>rrQ3O+x3CuqZ-_!AK%)v2(h0=Z3$wfZUM=eEiis%gWXt_$|#Kz&Rp( zRdigqic@q+Jeu^g_+G;J#I?`bN1jZB81@E6jiN1sbUQOErWU)Ec6>I8+v2KUNKyDA zc<#;XN}`StGGYv&MrS4l*>Ld;0ZrHpftvjQC3Z~WJ@vV$`Oi*DcqVoLSN30s=5S}T zij?>UInX{*fEMOCBzfr>el!y9gsOZ)OU^Gyce~`bc3Q|QI?mLy{jLW;C>>?Jpd z^u+>wqD(!;=Lk`@s#!@e?i7id4n=cel+mhKx|)MOn_BNMbg1fz^sABLdcv>E*GMDWSj1jDyc_i6(fC8DVl&g;t*O4Kcag>F_a zMQkbZSEDd&JG*1DadIsShWD(=ZD~qD>5p2zIqQ90L3#m=$X@}|rhLMCKjRh@!}Pc_ zjz`+#8yZ6^9lCexRj#B~5J{{)C721DKgow1c^YO!)^$FU_QY$ecnFp$EJR4PEZ}IU z2XgLAVTn@H-;kOshr)WySXJ<$do?m4sTBfgvjI?K=Aq0Muz9An%E)3}&HZ21Ydo70 zaOA5D8lB~SfiB)Y|Beqo7jB<#0$OZ9vK8J=l>9pWO6)O!&{()2aGf^@ z^Y(1uxjvD%A^k7afS!P4y@Q_m0q$}6<>l3@IlZ>KWTMwEN9}y5giy~+!CpZ>e-}R= z@5b{VSzngh%tVBRh8zunxr;h@FNKLfOY+kIiu;AY2ELC_+&6wb)R|c$sFO5DifHn~ z6&1IK#rNjW`%q3SSu~G_RI#?hJDXi|j+p_(B{gyg6tO3+&M!!d^eZoLl@Q3j;+A>3 zJvBs1dHhJnoW4olr5G-y?WxVN^MCU08t|@8H`j$r6}mG@ngw!(hTO?_9a`BUf@>SF z)#$jGX5{h#`AAtjM)}+6oQDC6*w%~_&2e$bz`Vw)wU(G}CTyZ2YzAC5J-q1hWZod_ z+*vzOxli2Y4}LI5GzhZ~-yf-FF)aNSOba{`dyoIE&?Z@&=F|^S%Pg@Y6QlieWFazz zQ1ONjw%Q#m63T)YqS~-6+i*Bcp=Zfb_2HiSk)O6#4)6SPk(d#5!G2FfjA#lv zH$|L3C-=~nvXS{;C0CPDuk1<(X#1aSwx+VrqHZsj$?=a?*eYvswk*;YVtX-PM!$~Q zM;rE*>Y5e<0=itS2Bh&(j7?{DZsJu#1*CrY8cOKH%*J0;&JY{ahPKlAx(z~T-E9ms z&?^xd7#JL9OXTtxoXYBL`YGsV{Lc}G()kcZ+ZSA^JSSJP#JTZ2Td>|mvI$lo7nKdO z^b!7`3yr)_1fwh)U1C_mP#4PXibfh=Rsz?5wA8DM6(&bz5kp>LeuFSStIS_A<(3Z) zT2RkNg@ZH7aVX+}bQ)#?I+TLll}7(TL?#v0*)g0QBW`1ETy(&UJ1n;6-TjMgl+aXz z#;Xmkk~+V%;IR&OP{fZVE-otoQ6B-(6CmI|=EU8&W0caEDm6?|JBSAWTKc#9!KYCZ zv3I7v=8$X;qGPHaOO7?3VP9sD%t`{kh%*w~MaP8@YY3pjqP)z$#2%kfStbQAUcCqn zi$)l{=&%Xn4AeW5?>~b5qCtiKouyiVIyf5M22NVEw@-c7&k_iF1h}obk}s3c9F{Nq zbCW!=#!dowezFC7Py1QX%|YBublp1%?ivHH{R{(~+|*cQLsY)a8GN}}FCNq%4*@^Z zf;Tr8R92bT(O03&Tq^~>0G5t(jEQqc;Y}Ukfa2H-AHUq5$eWi-lT_!1pRn?oXH#1< z>WT77z4`AKJ6{IxoozYS%GN#1M+XLCALbBm^-5Kj#5t8G-uOlH-ZpDt@|jSZ4wLGp z0*_q6RKHbN_(j+8RcS7_CF<#N?`_*fmfw1+aF^99+g%LS(aWEbAtuI5cMj|%Of&n!;1K>PkoV}-58M@oh!(fuefuVt7NOLxxDq_r_>p~0St zIjWFn&suGqdnjjHRdDFU?;UbzvH1 zv$6|t!*=5cjWN#TuobY=ql_kip6+1}*y8JP8s8DcI3bOTCUe@L?Pu%Ki*JbrdDW)C z6-ynvmqq_TjFiSG0>qGyg4*y_zHm*bQ7Fd*+?@<<`5zC`lBo24jQvu|z z;!@u#x8!bGNR4rk`MugwCX+_#XK_cR_{@J{jDa?_JtQc&!Fy9DbF>f|2BsOm?9S{w z^jo)sf)KpOMV3MKfO^Ah^B>h*Hp@{6RZU0m(pMvo{3sO{`5&JxrEU~MVg&)n(Kz};h5-Z zni*Y$VY%1#!%ud{&O6!t?xb!LkHBZ?$Kw$8pFhQ$LYrc!r}CyO5zg9@Usvm|0^Y7W zA3MoQeY1w-Uxj`s)G9rY4?KFDU`DbZH|2AN9k&2Of$d%2D4-`1Kyev_EB$5n+ID>u zJPd2PjLEMy`F$(E&fDXQktw3^wdO$KRzD2+Cd3qtbP;xeh_l3N`!s7{1e~+S$+Q^b zAZ~R)k8}S8wdJ~{U55kimBlIG8S_k$U;B&A`{`8Q_!O%Y*P&ccNi;<-Jd(VV^_r zHD1!ewUS@AZRM4)Ry9GI1Iq@Kcr&7`nXEK}?WAEYYWGTsx2ed=4UKN?PnAz$vC8_p zlgYqnIpyq0zPj9G5Zyz-chWmY`wA=&91r}?c@?DCKWXCYNg!n!ZRmVepf^d{(JC!N@Lmj}MY~)=Y`(^sN?X83Z7tEmpfpJcEwiEqnZ`p# z2WpA9Qrh7zkvjbtJA@L0#b8Wzo)x5}OTd!-hJIJ0`cPaNRsW)V!rjhD(7EhLo! z5$^JY4H`D1REE}ZJ5e-qn&GtIa%Ihz2!%KwdmjJqDyVU|Y}J_UQ#W_-iN^-7wx)T- zq$aYj=?N4>0ReNRCo~oA!mn3upE=oCfp+J_wDctHiX!8{Qu4{AW~ZybMVJa7TapI* zl%Lg|mXel&yVpw{oqMdhFQ8q=a}x00AYfKw zsN9gk(zP(4B!InR2ago$k#!y?`g?$KmnIv&d$Q2Nz$SRii^jm6Y$1Xx{l~uTag} zn=QB72JS{V$$aiRQ5TxUdeMoph=xKcifh&gZI8T9NM0X*CvQi-!&bvy+4&k%G&9*e8aFOeQKpTfDOoS zfdNn7QoYl+Kta4dza-$zf#=B`04Gek_Vq`ZQ=Dn`*Y06+Olid*e6{r0uGLcLtGzv% znokUWb;hQvu_2rwZ_wPG-y@9JqQb0U~sgubN^@T{^;l9rd9;kAO(@Xsd?arsyAT z9XnwEhhP16SV$mEaPXUWHM9j!6MFhfz|1@(OL1$$WT9R!5@eQc*pj}|PdcsF5AQBq z!nS5`dtwuogA7YeEsQu~DLOx5`iEI+Og{HCSescz)`jCp*biE9!Y{7lMEt9BV5fbu)^BH(gGgsCd03hZHF!NtudD*0 zc^cL)2T`El8n83YBd9WCjZ^Kv8E4mUdkIN1vA=y>lPa_s#Q2paX5PTpCT06X4|z=| zip~rwDZ}0?!hhioe@yuV7r`lC23voATkDdcU?tQLsAtOfRQ12g(8RKnL z{?=rpkKEnF5ACNM4R4*{5b;URm%GV@6Rm#kXu8M=$0^zqZSLB#_&<^lbDUuf9_If# zJ@yA{o3g*um>nB5S+j~*v;97oIBZZ)qHmgkGMzX|mOlTRTVG8u-fwjgH|H=Snz$7p zGC#5ge&jDxY%r`fvR>BaRIYt=3K*fM6#dznAOX*XhfU`5Y! z6|Qi^zi!wkFS*FH>7ZfY?nZeW(G!%ZeQOEcMSA6ly*kcHF&V0 zhXPJ8->zG30GEK?tHp~3$IF)Uz1OH|5``Q|$;XRtK0JC~^mOd2mo?OVOlmVI(zWG z4?NS0+k5wpKX)Cf_C{|%-?~q>b8KU;20HxwztQ;N@B8W)fkvg)FO%AHce669vo0J|!5v_{LF(*b;*sQR2#OR4b_Nx3o7jX~^>$oqP$wtqp5kiux|!TaYU4 zW!+4PcHc1DG-8=K7M3T946yzx6IEIUCu6@blMbt{=*C7boleuNHiPRmVpZUB!Ur>- zB$*`z8@9MFJ@J(WgIrGRgLq~$!U9foF%nysyj~Jo)B&I9RFGRP*N+8BR`pbipNZ#; z+;h?|2!6OtbZUybq3D#0&p9Q}%&^8EgcJ+DwWu>2-SceIg?!PIa2j*er1z^7H56_3 zEWx+I8`JJe--isk8JYT)t&c~4*T=zJjU3FvxtTZ{hVi5Dv`vxZ+T-Ex12nXS)mF{h zhPB%3n_c0xNWt6d*`U|TGB)6Ff~w;=3z)kZ@)?}&-r9C}eTp<)_PUJtF;+T{D&@5| zmk8cx&2b*PWxH;JPnsF?y>6Gb^Az#f$gAydO87X;ZDJi`od|r^aoaZ0;lv7>V35R|6hR2;|}~E zfOO#`VkgUOUx+s&0`4}qpJa}m+;M2?1@A7@I`j9*8-#fJJv2;kX(fl19l9$G%Xe4;+-YmyIN|b)Jhav}mpwZF$$u|E zyiF!Hjc5ua>9sid?vWnSj{(HJ4q|*&VP;{(^tSE`G*y?)Jpsz##p;V%8Um8`U~lC= z5hgi|4nw|Y5FuAkJht9kQ>ox@3BM68FM|lDan97|W}GA(P=DlwB6EQWe;Jc~y_3Em z4CVzBgYnOU510W(H+x0TJKZV*Y1w~pN((&d-^I!mlnNFJT97Gr{%-I=wqdxuHci=R zoxffasux<-C#{_>$o!2FwVsr3gK;49M+q$}e)pG0Cxl+K?rI0QT_)#wLS2*L#}yHZq8m^r4SV6!pBM1J$)e`E8UFpT>=hja zccfUG&PgUh%H&s>;uBPsnelBju;-LpYqBw|o~*zhp?^5)UA$XW$tv;=KUnE31tZ4T z(pm&Z7F`iIY>_X(>k{hT_U-E0^0Cu$?UABuueHg9wpflxSP@_>@}9($y^b0XB(!a0KfQ7euM15??D!P|<~?=Cu%a4+4S?#h4eK z@B8DGYbmPN&L&Zdn9QV5?Nl4Pw8b=92snx24v91=RaUww5sU}i%t&fUcI7061GWuGe)pJ!*Kj%Ujq9-ZPXev;FBFrA)!cnAUHtgL$ax|hViJL z9ysMR7Z3chyEzj5c=mnm%-zS1V2ADB0OO7+V@JWCo9N;;AVdxIPjAFBXZfMHUw8MU zb(Bw+ogn*zX+#j$TFPqyEmpS*^?@=1f=X)MQjvIul7x`jjPqTvfgJx@Hnbv2r3XQ1bhc(F zdVL90rgB6EGa@HaLHW@x)ZA(&-!klY+v4^d7+A6P=)`sdoO>?l^*cTW`n)CqF9HH~ z)bu0Y{EOMQzV7NRka=G;J40nDURwOxqV~@TT52r0WD~s$FhndG-5&Wy{2+U`6dON>; z`c_GYSVDMNR=-qi34S5^B(|4F-5Q7YP(b#M2@(+D_X_lNcm+E9eN9d5IV1Z)Eh2my z6M+I>!$sd?MuoW>LKpDnVQ?@p2<2Oy;)0Rk`_%~?VzhpXtdKM@(qBcJP*_n%+F&vV zmP6iR5m5KPa)sfJ;hkKLL90MyF5-2$$ryq(d*5T%$f;8!&SZ-X!K)7~{vk(Y`z7=7 z^n%2JV2isbI86c%(MrRRltr0xy1b3n_djP4#>S`OQA3Xy4xy}km(d2+4u8hKP+!t;#$s(JwBNbLDFJ>}{9B$4$!CeV}=QR*8(aDjz#IOi_nMcJ9@~NQH zn<7|TCXW15=r>hlV%_z^NYL*c+YAKn9V_I!a`5HtrLi)6VIhJlF9;on7XQ0R(_X)0 z3fy|?r~Osl-X&ite-Pq$&6N$-rykYy)6IEq{Uoi#A{+mhC88f*bH-qCjqE$Hl>nS?oH;vMq$NF1K>luv>4>e#Dq zp4_;vIoWenc@3Y*)_y!R*l8V_DSNO{8Q}bYLTV;l8wQQX?l*(dmo71kmYgv0rF@Wu z7cC)ny=yq;isV)12q3&+<4MSWd95FvnIITdLK!m-D|n6Ezhu$}YcQeY5Iq*q7ZSW} zw2H{FM3!$*kVgmz2y}TH+SJ@kY$x)CHnkkHwiHA2FFlzGdHkLO=mz4Es#wY|_U<~! zW?!RlWzQ*xk%-=c35`O+j3)j|B7=p?7MNir+p;5Vy?Pv&fH0yEYdM4k-^b46kZmHM zkOsZ__G$}d%_u=xFlFP8OH+s>jfY+HH!hq=M;LJ(EbgLNUZ5MgYJ)lj_aZY`R=}8( zrglla`0-zK(Ef!oY0S6IrRMcnD*mIG;OQ6_=DI9GJeBn0uQ=`W+qWVlgin-MnA2w! zi^|k*1lk^|9tE2;4aE2}=y$y(Bg@OBvEW+>lxMTA%Fz$UwWtr43DTKopWdOQBc=o_ zm%SSre>zfAt^_Qj1S65BiM!{L3$@LOhXZe!3Vkumx zkJLlXThNZFKco*?v&y85=`-84%D>wT=H6c9Mii&G=0QJ8R$JQ3{r@2+gq0XYu#lFa{g+dyys>EMpi8Z%n^w;kbb zL*5K|Hn7L5bsHW`z@C2|@5v+P4p{ioZ&D?g6I)oQ*S<69R|rFqMFhhS)HtyB2*>Qx z7$H0ygS=QEU~4((hS=p-8mw5Hjl;Nbv@>9uuxjLWFV@G}U4p`%2~ktKe;i8i^s)Wx zk}{fmt$W>qIhoIFTlcgke2`M*=e|naO=^=QUH|*|HvX|q#|}maNaTA1*lDY!hbsU) zqI0?2MCaQ|w=I^`UMtMG=eInv3Gz8_^gfsLqL7K8wo`}Xet&g=GuzR?)WC$$gwVXe zOrQobh!|F737OJ5@$t%$lLFQVR7*<>kQqFcSBd$`cIVt`>JFw5iJ{%rl_PaY`z$LQwEj&$aD$a=b7$zJ_I*o`pT!gg{Z%%Hzy0WAnhrL;#>;U# zHjy)j-c>~ncr652j~2xh&O@_E#h4pg%cH^PAsIIL&DvWJ%F0|HCt`f7Rh_1QRAxT3 zS#+lZB;~|srH3)}M4o_`Pp_B49~(GxOK6e3gUADPMSZ+DPjMOOozb$mkt`orq{ew> z3S^n~pg?SdfKT^-7xjRz^9Q}JeL*O|*BcSyP2lI;!1ulKd(b3kdnRwWE{UPa&Cjac z&kgs#>K($Am-g5I_1Gic2oKdgz72v1Qt2+B?af#H{udUYTKwndyAbT&F77n4KG-8q z3t?{;3L6X@-T;NGLSM(TtzZ572=Fq+5ulGnVOheBb!UHi26!KF&g`MoV@~?{(?lV0 z!dJwxZoGHb-FhDFD)4!4HsN=mr$?Io6;*qQo*}&eTV5uOg|~Th542_l)lH4M6iXOQk%PZBRa#bCFt(TW0Wn&E27 zq?5~+*+>XuhVd`Z-PIQLh0x5*dc!<{zzzO2f{%z`M@uX*iG!8+G`wWz#K*>q;uHF- zr0f05MdB*eh#9P3 zBe<{ga@-<4LHhDa?sZI#O@uG?<<8T|0W0UK|J(gNG>7z7w$zPW2|I;K^ZD#};g-x> zXL5~xuI$bDNH28hT6XBLy7~#z#Uf_pM4Qc1KY&Fh{J1c?Bi$0B3?#O}jgqW8!r6HW2V^XW&LW6s7#wmLE2yAkIDZd#{bvo`PYXstQn z{Nbw~ImtM&+A!l%p{0G`K8qHK>051Q&1O_$4Ra)t(6Rbqnqp;*tb%1}p z9x|?@iQ3NC;ZSdA6Eqdas+F}m|DoVl=!40h&;1V*)9IGLI*FP4*w$+hP2N&=RminG z)hJae(pC(-SVJF(E)0q;{Z3i*I-kS=-`00A#EXTM#KF1LnggZ1BaIc81goP!W$e+D zs77C`*ukVLfBKlfx2W>fsI8Cnsv!D8Yft`f*(ZMo;XPL|8O#W!j^%JV#yRztPm$>#Id@TRGKE13LfaRnucMA1uN8!=Z zqrBVjV@_jZC|_<>uD7@JRWWOw z%VrcT5jxXOdgyD@k)cq%Rj)2iXM5I38m2KWcilWkx=+cEV4N9^5MFAYOFH{EA4xpE zCha+l{&(t*&EGARi?< zWvzH$7OGmN z&`4Lz(AhB>ze~<@-z*7-(&v1{_s{d8zbOi<87s9lcrpe*@icwY==8&we>@PW@EBu- zhg2s?H^?UNFJWQ({ zQe0u>BVhh%;;${8KV&ts`71 z-hLmi4Q`pLw&3fRyq(xpd2YDG68K`x;+@|THm0)RY|O8yNzLwrXs4-wS_PKFoyoRe z`;?s-f)*JGxEy~K(^N~Z{5O-N4>FppwwS?z7+JxBzDv~W?uVy^)Fuz4jU)wJb8}Qu z&7gS}8fI5NW+IXWyu*$Qxy^mZfwXB|8}^V%>aPGrLVl`MpqJO(KL+5%*o!yUIN17* z=SARNu4hq_G2hT{E9erJ%@qOqo^roZpl4Y47Pj3_8H~t^77>nMq6alBT#_W6> z4}T+rPV;W%-4-)y^ErF2#m&E`CT-6hYnB2xJV&^&FaJ_#2?L1=_^1|vlE{kJ=YoD| zy9um3t9lSYGJ!Rd$now(ri2ZG_{x>G%xX@aT<{LW|yzAZU zbqhX4L+Dq-o2?T>a{kKY!jFMl{-f6a2;!~ylv9J-F7wT-<%(CexL2v+4L38}rOkgr zrXPLfGIIQRCLYltFM*VP`Y0(*PcYCLOkx;w;Y&>xn{haS1AdY-v5 z1F6-XRfmTafo&dAw5-PPq=c+g>t=5>%j9PL22?_i{v!} zyfr!?|J(Utg&y#xnvsaFD-|d(dV_fcP=^H9N2spE^Qsi=tXU-GDXk#RxVf(teWXmI z6topDLCKb5x@-^^tMpwM0OR7^u;AP+{z$P81$nCq*b{b4?QujzuWu|jmlh)LPNPn@ zD-&b=}uiXn>-Z0jk5QjuHs)Mxn8|WnZ>~O z&z2jKzFt%g=zBj?^WCxI!5~jz9r{cW2Z^08$Yx37);K^$C5Wwn^4y?DHZsm7NN=LE7E>b=ArA4ZHh%E_%Uh6|-As(xecnKJkozy0n28-_KBJC;;; zU!*)AXV^nKwX)s%V8rE?=SSfGimUj+h~LgGWvSzLbW~PFfbMnb-WH@#Zj3)!>gst) z*)5E}87N!h>=%izbh)l_(ug9kEf&oWiyQ{2$dHQLRodM>FHJx%3(jEsSNS*+-y{bv zXoO{p-AN%+7py|S9+9BLSRb@tlVq?A!%)+1{oEENNzBaVkv~9(bEplbo~LiANm7~F zbG^bx7wZ=O;4;BXhOn{4Z=D<26TF9a^4bVXdeX{i)RaUOceIHqG)&U3t%okKDfd-P za%ZpRn9UrEx{#@4gu*(wQ`)b-SIu8svUV?fT02Rcj(&$OeC+EM9#M0bDxRb;fZo?N zt>S7uLW1j0Y@;o@?J)}2N9wan1ZVjBT0s2^ePS)f&Li4;Qx^>41!1@WB89z}I_VHKt+a znAqgq_Ui>!`P|&DfcM+>oFIDNyt+MGy0mEygS2LujdGU~XPNF#60NXdS^m4*^AJ9p z$U1&GqdI-&jkD%&^~>AS*?sJ4V7oGYH6@NKLCArpP909OxR=agdA1SOhWz6@lgV#y zPLS` zej@so8zMSC_Yl`GyF^=28sZSNm^Ayb%l1w#GD_vJMcp#c8u5dWtunUD zE~oaU$nLVq)~L{ zgZ_-y{y7M*=87p-_eM9EC_*vRB&t!d?B>x13lSH?;ri@Asq4AT>DRlb(rq~5i@mr$ z3$dwfX-r}}37LFt2-lh2TR_2Brl&7gU0VCjEDxMO(^~>65VQQm6-R4z zE^f~Mic)ygnmeJAv&(5Sq!<*b+2qz;bfv|X6cyfWK4ReTywb^>h{C)n`9?a?^^e}gK@8a@l;EF zt+*1jwveVR>UiF*)VL`~20TH4bhi+3lB?8Fedb>UYR&*Sc(MgYCO`F7SFk)N^o0cjw=ZYVTXFnQEtv z`ec-C5#4;B8X`pOE`+pjJXSGT;4NuY*L@_7NDqX$uYz8ebx~}BY$o`2%Ls}rvT7d+ z*!>-q=;Cn6Q6Lrt{ZQnll9tw~S+K(pR*b2Bk937>tE^Q@Q5_dBiSXD)~xw^Sk zd08ly9@}G8TV-8E^vi*ebITcJVaGcwd^&+%%R0SOm*v=aYf^l*H*sX15-FQ(DTnD% zn%c6{k$5dyvlNIr7|Y+pmA@LcU7uF#g5(m32SX z!iHyD;G)SL=+o|MK6Zm|zvFh<)(1TM!vY%N)f$OP8oZG!db}kx2vHt4Zm1k_=?8|BO2dE-J8$H0?KF9u@)mJ${dGXWt*g38{O^ zNXvdaxKfecl<_x&*mn~J$!V#&I0di9qO7C=18@s)8~8WclbNdF-N+5UP{n=l*u4`a zwcE|*y}Hn5l$&}#eLvo5E9HNH$99_@v&88J4zbDa*gNR#_ykSDP(g?N0da6$c5pLYXQManrzoxH(=Tyt_^eZi zS51vOj?HQm`Xz7_QW~oSGfvFrr?*ylaR;4_cz1Sb1E`!M(WL!R)AM=`jylAZX34=X zf0b5SWlc@-XGjmdyYlc>>?y>;uH)7CwGPt|@aQxwOnS+M|-3R`ae)Vg7S2b;6W*4W=i#Fb1Ew7zoZR_t0 zw{G)a8_E|f=a?Fd(nA+aCajoVYH&|~5hj%R8ElLk7SaJ+{S2lw4JR{~7e{TpppdhJ ziF)HxM;kpadGJERPz+o5(s&F#cOb#HhvYTQ=bJ4k;`9FD>~06_aL9*({u%}ML5LFz znh7vk7itYqW@{c}LABMVdeq)$Y3Jd4uFJ!35@||J;*bYzjg>!AKsZ*W`$Lmj8DOh9 z>hlhF$ts@Z+ z>MDzq=; z-Jummgv#sRw~Fm7YQAQH%V(#hLytcR(+|J-g!nkmD474la#SoE2Q8&M;@%NmVldFV zNw$3hUwLA)ugYluEnUuUs8y!HP;yk}$C>%L;!m18^!M3@c&6lQx_wjJBci=s!u|99 z`*;1?F~zUymB6q+Bf7o!Q^M*JAtMs z5Q`6qTu~726L|hIFvRj1==5?FR(?gto*8Gri!!tgjK|Wc44A2 zBZW+Y?6qEPqw=luw8wxMnZ0SieX;%#7L&AKReWI|jx2w# z#I7PEn*zi!n51QxnXCR_jtvcqToGFU53D0ePAxg)*g#4i)M|Rjk*J%35wLcRtE%nI zh+j5}l9oYx!UeY?pbvlVKonyCw1ZjB8{?zT+;Jyt3m)Gbi}+W9U?qh<>YzgV@q*E( zT93;=k=s>M3vFZET5{W@qk(r?ys-RWBSrae7j5H`d*2ul>rubD`AB|>yZ;cCn+XEw z#=WT3hkYY&e} z`3!n_NTCy??XiO+(WQaE1VR87iGZ{O{lHx4`*oqu!dF$j zvCy7k=6pSK*z5=twETB}=Tx`r=dp(>R{$fH^vM@+eVz21j}NnnPre1x3WCzFf@@+P zZ^r$nAOP7{!LO(Xq&c8swAvz|lvyJm$e1|w1UQg1*n;=hLCEn4^Pn{wFbDfj5t=07|xrF%uQxryNYYczr|>E-)tc++G5dF-C6m;<~bo;CeH*N)CCa4Qe11k9@hrrK3 zBMvh2W+f@8ztmNYzs@lBRP_Y!;u0XeDMG)jd&sQ0a%F`N^GfOBVC8Y7aX^q&X}7L@s{$EId#L8AaOA=rEtWKo%-v>7=DgC5icG=+#q>Q zK^js)+Xwh%Vgn&#nn_F?^DzR>m@W#CIMwl)a#F+Ncm)O|2#f(-fw!D4gmWqs!z5nV z&kqPl6Ks=Obl}*}Kab!kPUuu&q{$SQ{xuNpe!AUOafOl{fzCq;)$zMX#y_!1lX8_u0vvK+T4yRIX zVS7=qQ~vJz?E6jxARbSH=e&n9Q-aOVEEyp+Y5;?$?0m;c4|+2Rk7SGOGW8}4bxfLz zT(%&&Q$$#1bPquQMGkW{STEw1&g75+k(~6GG37g0A;~rVQvbiL{!2Ctvt0#9UHHKJ zp9sKf(YICHqkv6hEY|oAD8zSZK3-yWL_~=fp7|`pYnbb%*fimna2Rs5e1*irXL#;w zqQZ}71!Tp)pUKSH&v&|D;<&+E~q!$fwc_1X$hl3hw)5n ziS)j$L%l&1b}%c1q{63loe32(^W@F(LW9e5dw2ix8M||l6lB;^Ra@ET4L_(WeBQB6iX`q1`==c5sef1_9Cq&~T*rqSw+QxwSs}<~)WTn# zA5xj}4T<|qxaz)u@!v3_)x#Bky00{$eS^bc4vEP{O5C!azmC84I1hD0oU=b^hNIAp z0B#1LsjkNR9ApDQ9sZdmZ$^>>vk(ypTRVGBH-Lb;7kxkZr&o5_MJA(=IAWg_4n8NJ z)jZ-VBTdpp2`e+Faqs=HviN@$8!%Y%&OJKi98EzzOSbz3GqxXA7?>DEMAR)zz46nT zJnxZ*Hq_}I6%5X-C99Gpb-wpIID=OPy$0*<;16|)!QlpY?&NTp=Ykp0W}tfqfeq2< z=_9Y7Ls2i?o*!UK%&yxIItj|F{5vX&9s5c%-1l21pngL8JXKkq%aN0dZymx(=V(FH zV|l7vZ!xeMj`SrdcpTj>xw>$BB8eyTf^{cCQx0c;UlR=a;<|Z)9%r1mnF%CyN={$l zT1t;Q3@f-#BYQ&rSY(C8D!E{fbH;gZ^T`F5<2*#g%Ld}zK!(;#f#!TCnWlug-VioX7NQvdvct!OEZm0FWSwPGj{YyWg9i( zdt=g5??mnxyZ!DeGnN@Qz=493Ii@_P=DIv%Zdf}EfoA`RWkpb{rAt)f*Om&6sj;>7 zm`G^DS#8rUa`UtS^EkbnHG&Sfk(KVH)+xGLw-$AjNr2 zON5o1l?-W=y3+G*V;YjuDWpgU(%~l4ofPXdXq`K7>=Y-ELCC)O?| zbn(8lHFW$h0INV$zsz8zk%uYV{`a1Yx?N{DXOG^6LWc1SDM|6(1CbH#VLnxiwE5OB z*>HI}XE$X5>f2Z7ONz`*9V|}X6-D37pX7=y)dfCQgjuE`yJi8IrhHKWuid)Tz*5dy z<1QY7#6^YqQh`1YAPh4as1-w5SFKxo9i}`6J@Yk9LqIkkECnK|xf-0)nMw9CDmSXz zqcf9D2DfR+vy@=DsuFcoVokn@F=Q90u1lFvqdsXnLS2~0t!a~UcGI&%bTyHS3J=`2BA<0eunxL;RVxh=4A?^+W>=(-6-O_5zsz9 z-d#x;sb&pL4_5GWRBD(C(W;O3Gr^`=gl=DW;`J#57HNgTwHZj7&iu>Q7Dytp&3HBnq{@+r^dD*FF60fjoQe2UC-N5W6e4k&}kW!mr@2 zS=Aa~n@Nxhq=&Jo1M;$xC~6A`R{~kc@!mwt^NcE@0@17x{wuL1HBpWiBw z$Mrz^t2dXvH>bP!@h*>d^XXn)`gzoNx=V0xv62nj-Be0CKRBM#y(8#00n&TC{il1U zP_BiO-s4?&x_1cXS}W;2-gT#Yw?H)EJYEy#8gozq z$YKTUikjE}Sz5XsLfH(YO_|t_!bK>(+&OAu@(kMerOhnr)0~*<9J>b6By;pJy$B?{ zXMqFm&fshYvc9y7YngefvjS9rNq8Xc5z_-Pg$UOEHQzY(MJQY#FPZcLcu!OTG&L;N z1@idl=(q;RRh4f>%`2I2>vrqeyppS{W{m1qvJt?%=*A9KQcUJ7$Rd_1fv{E(JB=hu zV=5W3-}~i3g`?}NpaW!sw3sCUmF!ZcRI=H!FPDjrm{))il1etsBEcjPx-kSAZ2}8xc^ZXOuqK6-e_K^sLb372 z;8`G>v}!yk_<8tycnazX3{2lGGUh-w6Z3+%h`$HdgXA_~Tmht*)0ADLTybJH0YF8A zajCu{lxSbu1i#M{4OoAB8b!u0-nkh=k1$l6R@DSvUdicHi8f2H`1|xh@5u!ZAP7Z$ zMiTh0PtGAOHz46O*Bk3^MkEvjKB^jc`Bb85cTRIdWb?s+?UrF9pc=?nhP~T@^u2lJ z1yYHiMF^|3@;!OM16E#2Ad9<#vUw#vKwhzBS?&fP;cy$9Cj^AI0t#9I721+2ES$!q*l^oDydiO=PTJnC%1sJ8A!<^mNrpx z6d&@hZVkwW?G}j=0nd1>c$qNvN@DNHC45Dk&uU@a4Akb8jKV3KEGH5Bk@KtCYjL%} zwJ#39jFU;eP<&_6);?xao-&L})SO-_T@j-hNVld(Jx;z%&Qt+98Ci`N?X96OW8zoVA<^3iY~Zw0Bp$_6bxwso^?TCCfN_mR~aD_J8p79B-U=}SxUqr%XOU(U7wvLy);H7r{J$jF9Y0Mok*2-l;N z#z9aKv;t@Tvrq!9b#71q-OR(uoGdaSA(9UYR6rDb2DhhXDaJgD+c=#z9~_#F&7hw#e{gBcLyYRRUyeH?eWHT69N)sgQv?Mdtl%U&zy@N2wzMYo!JsCYXDgjyc z`PN|`VrO38AH(f?d%y3G;rLza`E3fu>HnT7hP*+Clr6?AwV9QQyOu{iZnc`D2OgIL zr||!l9_kj{t$fsLsFwkA_de>Ifn7tt^40t-ywq2L`I-2suLAQ{J=N|0ul}t7^HzP; zcMRrjdaJiQQEPyCtN!XMz+FL*K90xw>LpzP=I(sfw-xACH+Oel z?yEF%+j_Zgiu#0LJ9c(2Z2FG8-M4|Y z#@*d?xl@1lE#O?SnmhD(uLH97*c8WD7tAeu-ZzJImBD2julM4i-OBHM1wq=@?|oO0 zt^jje&-WdI*|h09@_l!q-3ZtftGTK7yKaBm?(YSI%SZBmcbB~EDBZ?<^)Wr*s}c%8 zyb3pO%Ll$`>AYh!Zu;$b!LJEp3x0Dae()uY_6DBttJDd%<_W)^nx@7T-UsH6ec{)F za}~e&d3eLGlG8sEfB2P><>%oMU*{6v;vt9XX%3T+O!5 z=M^w_Uw?rSgXtDtPgxsJXC7GBD0tHj zUT;mDT6mrMIP1aNqH<0e*HChNA!sc4-{JFHf%l}&x1a!Tz;EKysbuN% zFp5G^@**~!8P`25D=pbXI%TD8nGzBTqWaqm-bY7AM@K91VM@b@U$az0ZpPDGl_Dl8VnlY{p8_Jt>N8i+>>jISTF8r19*260JR~=?eSs5*c}gC+r;j)zTY+p z;%Nu#T0uP37@it)t%PKOdjcE<NK0^WA|hqBX-x;KKb>`+$cw6n8c zYkgl8-fE%#GQ7K4((T}F>uppyZ@cj}syZ93fVZvNQ3c-JxE-y%zHR-FD)8>c|7a_C zn;el=z`Lm<(%SdM?mUtzGinKMJO1I;U6W!YEi2+OtDZ>?yy&9zQqEaQE;jN*+KmTN z?qsxvPtk6?iSk}>|6(R@czT6ovEE6@YPuj5wVFGhk{51UN0@1tw=sr!#->rkZ=PzR zTlA%W!sB}qqB2R_S5RnA7gCY?TgFjR8Hnjg!g;$tmGK3BoMVj_Bx!Vd_g#zB^#0~ zDr0Nn(KPl24+_I$tZvycecka(V>=l&^!S)my<+jX1Ti6GU~Pxqse-52n20&gqQK3~ zUYfUy=joVE{KKsr`_*@+XU@rL9=3LDz?v17TCMrP0S%V54c5)ac5zMLGpCb@lBsG} zz`y2~g~qFAUOL~UvE!PQ8mN(pb+$%zs7m9aW5Nn|$2?%jH}M_EJ$X*wdB@fsDp}k-teLlFI$>-Xi8k)F_6~jh?9x)PwST2GS7Xym&d=ad zY|z}iD%_qzYn0}SeVb6(ni+J@m>PS+QW;L6i@J2EaK_@oA+u>w(Zf;i0P0mxzpU2C z?c2BJ>izd&#Oe+=(zU!3GSwfiwc!5!R%8FfmQBMK$Nq^eHyXcY?6cFxnZGAzr`u26 zGj=cs##uCs{+_6pZmQcSKcd^eAp2oVcp5NtOvw^Z6+HQojHzG&nS{xlrRYTCj*Wc# zb0*VpA~xjQ%P@Y*NP_&EbwdhvD-3Ks1meX4H>OpHfwMf9lBN>!+hBBglJbSRi84Xh zJB1jCCF8XMDqXi!{PoOCXq1^;-DH_3S?5J@9 z%~1*73DizyyFdlSW%N&u`bTbj!ttXbA6K0~bC`m60wu6NLcGGN3Dn0ew4T821~B+1 z0EqUQrZXmg>ZP?(R7wAST%`^IdF&Q&-{)ql86o0oj{!m&_97Tre${m6&tf9|F>>qUULGD zt=Z|lXmoA|{H~17{t2{ko^X0^=|xeUSsUQVCMeX#o1!v-Hf|Lg&SC8dv`Lug^xlv; z(L%gcPQpzlurigR(|dhR#ofTa{sh_>+@0P%0Dm;gd-DXEEb#3nu$wd#@5$(!a8+wLmicx{<@`+)r23dd{9#M?*c?^ZajjnH?5~GjO`AumdRr#cdSEKEC?BbzE@2a|$Ut z^I&n1@Nn&d1e>Z=%mn5<=4q|E+W3ksiSu2a$I;GYi)n0oi1R2e-z>Zdk6oWH!2%+9 z6Oqzi2BDbnYnHNrjF%31+CaT-+rG-8`sDFu0-B6ca|;xklUEwl&57ySJ5ZXy7G$(E zmybn8OA}Zhg^VOnf`8NBwkXu>%oOV>y6>8f|> z+SrlnBY1MvkAV1uajzFFU4%j?zOtpR+T?;PRNc^obq-8891ngIvve?n+LPM-^Wqm> zqXBOT$;rs-EQYqwWj#r%0lS@s`a4vG0fg=`a zB=I$1??72tqAweQU30ar1bZ75;kJ;k4R(9oauGCNx#0Cm+m^ttjlg_QMq()@vYkD& z&}q$e!^wgNN;vt6r5M}_k)<2irkk!C4fa|t!k@u)Qv$n{WAJBi-4wuX=??rETsH-< zTRH)M2G>mm>=v%SpTTvb!ETd@w$N!M$*ZC%J?w2432NJc4IJ=~T*yn$w)nt)jsb~t zhGm~e1ECsDd8ET>Mg#S{Ct7vq9ia^YT+6leGq~I!(BVGM+FZ=b=y%XDT7jJWC?JWWgZ` z;qRC$F;j>TXg}AYDGW~&NbD^`9^VtD?%gD10gGiwBXLMXHklJDNG4bc+AG3y*uL|xcEboB>0e@On$GXTb{jiLH)oGyObcm6o&boTa2sn*qMYe4Wpz$6VLf$FR`uQ<-> zmrHV9;52^QpG%pD;b0K(iRf!c)txoSeK-ble$$hDki`K@g`{!NOR>YA>Z9j;dC=*c z16~W6@^}_4T{gy~(JwJOYU9;D1Q`Y~v-mnpITRD_lh<=Fo`@`Ef-HIFq9zGA!xN-2 zTj!t)Cy-GsL~V|s3uLlFL9!$OrR_~9=Y*0VoK9J)dP3f!(=jXqXnD`(HAs~^Y0Fc2xl<_y~b7z1t(*Yh5$FY&Z3y5bR0&ZR9FnL z$bH<$Gn}S}F6mJ_o!3_2sG(p6J~**q?2@OY#zY%x1UMK5Iis4R%RC$RHDj-kB^?xy ze4sXVaNu4D4zFxaVew=+-#q?X|L^_(W2CpACP~WGO{4xD32w-TCYhLI1DPEXg;&g4 zn1xw4oqJ01ghzZ9GCUW1TFPu^hI>GXVK+xj)oY)CG6sDts=uDk=eG&eYjg`Y0bm!K4$J(FoRMs@NHrpD~3Zj)dy|G>d0&FBGfL&f?os_)eg! z-lGR!eUrN_mDigFJsioQDRF=;Pi#|U)NMhNn)U2-zSo(-%Y7aiRv(xbJt4eEEsS_^ zmQRAhzI%eiOf{z|gbh1=HSLYrLN%X%W-Qg5e3k-tq<1F2&5fuuW)Z(3`}hLG1tw9b z_!$u{!ic5^L*SP?mrq~3K7aA_8JRKJ!|r-C2-4no*@K|vznJ_hz~enP)zkWf^=Ct3 zYM6a%WH!J>gh8`vGD~B`nIM2%Wcqq5&cUFcrWv?8EWm7CVJyM`5l^p2>7FR9N8!Hk zCBz2MpmbLe#nnmBtjW)~u|}R$atttW8StHj=XHpw*tVD!}ljQ{EAM6ig z)cZC{PBsEv7*lGorX`7LXC{yOn=CozocHZDK-0UD}K>8oP8S$Yq<`Wo%PDTh>@cqCawF zQYq+;7EC-YH# zdncjMur7H~sddK@Zib!C_hBmJp*f+>TG$g-NGPQ`6~%*am5mwbfUyhRe8ysyhLb|; zo{U6Kzwh-FaRaP>+#jf~`UzY39;=loJ*Mhgt0;>Pt(L-vghgl_JbK(!=cwE9W60xf z4d{6Tv-bF@f+>IJ?5uu$#g_T&eB&N>aXQ`nKx@}W)B@u9+P<)(`ms9$DMkcpmP<;rr(J90}Hp6LK|~>_3e%1 zNWl2;FT8{aHAOMRBn`*;IBzs|x?We>N3xK`KcCzzluGhfB7Z(l_n+g4j|X_o4FWy^ zH81or&||q@_pYpj)L$;5gFZQ*+O<;Rn&g#f^Gud+>BF+Lb$W5G2;aMWX^vvV?y=nR#eYVbEoX7X+wkHTw~9vwYGZOvQL$)4t^dQlj&9`trl z(9sM#9RmpqLG5B@TZOtWuEGRP^EFHHbca0FtESfJDog-Q_cbW6K_zQ$$DGh;T`p)L zz3FJo#B~N0ZEbaJ_3u&zSm)fe|>3GGxrA-d3 z&Zc!g)2HwX`_LC87|#}TG7n?G{~MlOsRPX3C2S(WZ~%o#WjM*y*$!iM9prj8!58%1 zgvap+7YtbXAQW^QY0f1U2?aKGp3M|nH&YkxYp#$`@WWgS$Rx=UP|b$dVZ>%YH$r(< z6dG|*uwtDr=!}gt>CoF%48BBR!1;REA?COZ2{2oPxRyuzP-Es0%s4$V7>Dsd%=KTr ziT=m?UI&d-+FIJXAu*Hv2~SzyF3jWOqoboE{UMvo)zQ6XDfyOI3*`X!WUyEaoCSNU z7EG%a!eaMN z-Q``ZfSU=Lx(M1U|kbR-dyB1Caj-=By2bsIJZT}!C*1S1WS9fEDYEnw@vl5 zZEA2pv?Mbc1XNPRW6L?-$oPr6dyOMEUY@}+ri*Z5-UBTXAy*O<+)k8K;3H=d4Htw) zN}6Ay!d@I&${0!#pw!?RXtenE)MOgXd&N$n&ravKZ+z>)F}3tj=cMs9_VJ)k&b5ik zE_W*<78q5vb~wp*&`MX({o{*Y&fdN_eg4#E<=WdL-_gmHq9R}o6q2V5CyviS)YXbR zLdh6ER)+-<%t*DEK^>I+u@xn-V4>=nyesVPBFs~?UCeA)RT zS6pLO>(&R*U{`@xnB+Was5il{SK2Gxgju&DHtL7^0;? zy&zj8R>WWAMFn7r-dRnO>U@TPsfA03i#stxew*s8}lnO3|B5IO}#Kc}lmmKQV`;$5?6 z1mx3~-xI@W;bMe*AbAo_#K1W`dk75Z{E(j@B!`d09Qu5siR!B--w~(rA&lZY$Y~DV zM}0-+)wR&oRJ*4$wwS`@6Ke=_<Cc58#fL8 zsIUKfrU?Jz2L|33fCrjvU;J`LZdhs$${`VwCu-vqeoc6?EFe}gA{_C-tWiMJkx)!L zQg^DTU4p9A0JqgpK<(vV=htygTbjkB*8@SDN}fJWv$&V=U~qj*dLilcQYB7Hxl{<9 z@PPDswi@B%d!66mQti?t`~_{V-682-A9oM&`BfMP>d6HU%%cU9Q~}-{lHWVV@20En zZ1o|4ha+|2?FZdV-8jW2xh}FhByaK;`X#Vb>P@HYal0h z*xnAMd38!N{LuMukMw%5Lys%_(HEg9CcjHc+Dsd#K~r!#ys zSY1sD58cG|-um0${?<3o9aGgl=m*0%APW>Brr>|aV?xI~lO-6e+BrXOq@W{iBzqGc zPgo-1AGvCJK!pfrz>Yx)w!xkmtw-aaM`IcG%#(wDr*kSw8MJeSS0=1znWRjh^)w#| zH82VxO@D{@mpcTKR&=B>vvw-BAY1#!T(61)tI@98Pt=BqflL`QYV~4kGvAPj1LLon zEAxbwG+_f19-L~RAh(5E&B(IJcjZSxN(#)hSuffACZvB;!n}1>=42KD<8epY$J)-nZoX zq<_>uIv`;jXsezPZBkG@(YO=F6TV2O1pn`G$|&#+x<4i9LZ$>7XEY)di^yr!(Q8hQ zzf}DLFQwQ|8WoJl=rN@zTcCC_2!)a~X^J<(lwNai*->&KkC{N(DHM8wdTOXHe68ys zlKY@`yiev-kTGL1uvK)DJAdO>n#sBky0#Sfk3$!>BxTd^opHn+L8l|I_{99C{MI-+ zjrst~nd7XUOZgZv#nTy$!O(+N0ziG5$+_!v3cZYshlk~P9GwQZ>8ET0Na(Ir!7I#d z0{coQK%j`c;hIMsl9A)4hn{1uFPVm=tPs9GYJx$Z*isOs?p?jCi?hs!(@sdnhH}5) zeV~@IZtO~)sQV*8p1u;@*^S$c&by*76)kKYy58O7nx-MBi4RRiS#em3ToH$a$w?ov znFaw1)KKV1q8S7IiYA(5Oml708<%9@PNasRaD16rwCIbuzGl?NZ^ul?w@Io_+=Ph% zwixW0E_(RjK*8clBSvs1H&oPsgrv|oQ{cgQlQJ4CSWG2Pn{ER&tQa^SEBbWCW5NEJ zv3LUh0^iZe)eTJpaF7DR5=LOi9p)>os) zzy(W&H{T+hrADm;3jrJ=a2H9+u0x)Q+?nO?#^8G5UdVtsaD9RD&!(2q%3%$L>U<17 zj*e=Xgwkk$T*%RS7AbtnP2W|;^l$rnI0kSI`r!c)Si7?ieuT#T;o_Gw^q`lV%y|^J zUcoSL9@ot}zno2Hqg6`wg3El-1;|+NsSps3V|8a{^59$*3eC@shPA4Hl&=d~d~aaY zn~T%S%fG&S_2jpi=WQ2eJ^2_%DUcRp@ccuu`;)JND@TCluc3V{Km5!kNPJ$wsOfF%AC@h zK9a#quvA?NES4B>0%0cj|Bw17gQKI~tEbPNo?bqE@$&W4%L8YhPWlh*KAF`9eMJ~c zh&o~-kM>4JbaY54c@u@>l%`8u#+vIwtN8V&Z#BEVr@lE*>qymA%Hn{p=O&OIC!UimiI%YW42Y5QUcHA_EWlNOcD?I}e zO2MKjN!g61)<4E9+0&QL`kl`G`+s#4906-&(L9g$DlEc(-oLLd+6zPJ^keNo9g3pw zu41UIC1Xggk4I$R7`8!%S&}iAb8K`1(|cgn-swo~ti>o^>hq-9Cp3Kk3bcd1;_KYw z;5(7#Bq|i3NvJ2)1NF^;mHDR)LMjRm7OoMheiR?@y12Kf5lS#!yP>`JVV=Mi-bb6L zm6@QzBnt?Qk~tkS8?P7>O6GjQm58b~;)bHO)0pl}aALlULhZO>0K>qBBw!u@Be9ww z3A3xX*V^0dhUyZ+ITz@Di`Nm&??4{g2w5YYX*5PHN`AjgQK_rgP9;aTA2JVFCf6q# zZN!AdG!41oVRPOY92=e10cS!DZ|H|P95i04P0qo{XQ9rxF zK#LLRiws(s>yw`3`kxO5`F(PX_sL)La07#x!sZ(;Xx}NZx!%x$#0knbtdeGF2k2v! z@(4KSIgJCyogcaZcAj4IFvxi+9Uzm-UWeMLS7-jgV07)>f#UWoyk@G`lxH*JQm4l5 zzkB!YT|qbxJU5RfDH|p^XwUh_%g}@wa!Bo$ZxiQsBY`67YoWSKEV+NBW#oWp= zv+3dNoQ(4U>yxuNn_QL7LPBTj`KS&sC3Bf(7yYdBI5lLl)ooLldtL8v6?;p9l6_5n z?+FO%mMBgpbaJIe;M3YZ9bWV++@y1-%5bh+X74|#vG&*Ep{UsPH7lrDLW)L zS`kw41hIjzCZG%&3AHR#k_Dr&mJM$hS@3JK4o?aj??e&`ZBx>A4n=n9bgH-zO#!v> zr%XEYxGSv`Fs|oj96^E*`^&=-mqn)*Fi`Y;9J@ALz=>WFVOI#w$H1<74aNlz1liY2 zn(=7_)r>Y49zf(_ZNM;UN<1BdCBR0)M&QA#*2Dx|yO>ZLcefvFBbs?o4Rbs=EJ)JW z)fD`uiot1G>q-3D`8S3^)Jl)v_V={^0H9M(5ms9e$d$2NGOVKz^jBtagvKqftLVrv zu-J^?bmmN|Mm$_JMN=JSrp%Do+ZV)JptAWeNLuw+WzX3@`4P{JaWgUwt!Q^NGPgSL zAj<^ghHJq&WlC1>mpPg%#uA;Of=cS~o~!sdS|>Sb6^UT7iJR;JND8`3^j`Wy&Mq9l@Ae(1#TL=$#A<%!X;(yA}h)U;_g;N(}9% zXrBdbcPYZ;kj(iFcwwVgo|_WKx)?+324tBs`CM{67%)MgF#K72dO3+WiiNC5l7<{p zQa$V+^^Zpm`jqBsC_)KCJ3aDO9gwb0CE8(y-RLoMMH|D5+Tn|1VC;!;Pb)AUI$gyQ z3~`?A#n8J$5_4@D!dwI>yyn>QwVLGDUTi6aJ8F#46dS!HB%RsiX2mj5z{1>+(e-iv zUH_fQ*5PPX7K*gzY{DeU0yptD7~Me)d=FAAXvsh@ZQ2W{n2$M4{StpIgW!fB0cMBe z!7Qay8q>FV?2-25wPW=EA$WYCCS+70L@-2(Hzghcfmok)*|UTU8QY_Gil;q(=WsMS zZBK<`C|rdTnyD?M#!OhxfIY8f8VDGgi`AJEoVd~4pbjhiz5c=}h>^|z+yPLDV-CW;-9Zd#>75^zGb4+p=ANg9f)gQ3o>rrqy)y(CL# zY?S9rO4-8jooZFlk0MucwZbOE1JGP)6Vzd4{{gpb2%|!Sf*hTjDk>{k1fBdvD|o-H zEVX@83PLdJSEJgp2|pO<&`o5z%Zr+TOkk$62^0uhSIR)np06Xhi2gmK2Bjw9x0ljB}CCzEPog?AudurX8nYvAsB~w z90+uDXNyD$p*N1l65M{832p44oPsH$lPiTJHr!{j)Cv*-DzR_^mj<^oQlEUUW~D9) zMRJTTONTGzg00OekcY4T13U|bW(fdutYQ>lSA_DCFKnJSP*fX1j|y_bq6nkfjgbmU zdSM0^U<2_1v@1x+kn~+4(FJ_44_U;JiBjYTRGej=QXDuV39oq`2d%vGk6-@G0YWrF zQHim#_-eRZC(Yobm>g@FOF9L8ooGxT;<$pccS#gZLK!Vhv|G8vtm|E>uenEf&9ynG znpKK1EovdvvNNkB&pU1U&>q=FzMvYV+u7PABj ziOExdWz@u}=zno&f~)j(qA_XY1b^avR$HdwacQd`=87tt;1=0Qy*TF9T+k&@tD6wL zJ{1cB5=6YzElSxh)d8uIiE?3bD!#HP8=0oB-8KpZqLXWi;@{!xr|D+Dt}4 zC27?NCiDa*gOgyfOqUSpjy`?5X9%7CKB6=9xK#ol$?MGMXmU#k&00ZP42_g$`gR`~ zSpX_|B`MQt4#gs-DP4jVOQxXyG%)k2wkXFl^>3Jy)kp@$t;VI@4#$*GIUm7@1u+xD zJT0zC5g;6Ipf+IK5Zqso0A`M8`q%S~O!_)r4@k{RDv4dwOjO`T@D2AiBg!Xh5 zZ-zd&h|(xpLe{jkVEp>%fg*>nn;=o@&B$HF5dM7(8(8&&A@r+ zWV5b%PEXM0!>wVGT}03}aVz#Y&Nrp#7*}o8SNKDEy$KZ)8nDM8<~!mpvM7W zK`85hLT+mxJhZg%t@uJD&mfD?xL6CuS#&D;*AAY;H4gh9Sy9Plm?!Vps58YTM;Xo6!o@3$J)fh)d zM@Nso{1X0qbaYhy@6qwYqklX8^61ggR}YR(9)0<5N5@}2e0cP4WD-_qv(n)MK4OT4sq30*v2aJfpO^Qc!OK&on~@g2zA59pL#|ASU-FI^DOw*TD2=W z(0u+MJ~%oq-~V47Klt+Q{C|w!-X8fO;$s?-C$4LFt{sIWO4>g+_GDu6$ozTZL&x;y zy6hg7QiYmugc*VYcn6gxv^PQ?$2e;Qc8E`2nJQvXn?gOg$V)eM_Vzm1%Mdc26j}_) zVrl;Uf-YG8h0_DJQ#369_$Ri+x3-m#Jf$-w0SckIy>$NW*s$B*KVYsR?O&PKtS`9e zt4~rk9g=lwAgGCkCevAJCunP;!BbPWY*?{hG(aWk3_mEqmH=xu~pDQLGGb%*}X%;B4I5R_s*v;xV%6I+k2&1uS^Vvl_3UuNy>UjhILEunVD8z z3T;T-p>U*^c}7rM8N<u+$%VjYtF0ZV znc(DlNg7^LsU&1Xx`CPP9!b_YMja?pkZNCI$UF%1urvqb`=?nHK`f3{knaO&GIpR! zP||@q8hh|hQ}JwA8cg-MdLZn_JTCTSDt{Q~%Z^PlQjN|BEe7NT8IlJW_bZHxhjrd? z^Ibs_A;(+EI;!LzVtJ-MTUvw0f$Cf5U*d5-gsGb#=iox)1>>0mih+G!FQJ zgaM%v6NP7q?ZZYL6o$Y)z}$~+GvFR_{zTDW987i7)BUJR2>?HTVgzgG{>&za#X2sS zW?JOQsT@knA`*qyEM`LJU}x>^L6Ve@y^FmzZs*U8Z|n^m?8$G3QZ$m`jXrz4QDbFy^jf%xyt- zya8mGRN+}+;gl3(-n=S8j<0|ds33qs)O9)S311``5H?+o6t3mGI;mkc z%~0lVLQn-YBqt9aJrC{ENsB*S0! z^7M1&*}|N?oCXv2Xb!2;^ltlP}7`kj+bNE45im^6ZFt zGPm>dLm0}} zhM;B<%NhC}p-K2d%Cp2_@=1^6UN-sD!u@IPM$!W;(f*2Hy9t@o=$fVDa)V5;YOjj$ zls}wJSU-#N!Vh@s!34;g-+;2^M=#+4F`1@_cAWGTASkm=Qvvgb8(uLxX%?S~p9M?p z6LmFUA%{ZnthWk+J+FJ@=NNtCr5ksvYt>I9h*IYSauUb37 zXpw4EFP*B|q`0)E*}m7+_n=dfOC5}rGMR?V#=Pdsi({bvu-KL9SR9$7Nai?Iwgy&x`uKk#sZ4V2A(1nYL~GfgsT%2#W<9z?odg?Y#PQ& zlD+ulEO*n_+7dgm_I1;6n~>Kr&*A_q&rXDkTG0aiNM)zOQmajIztX`c1)EqWH=Gx~ zH33aDok5NTmpGgiI8duQGEJf|W_i0(^%|>gz*;nJrVwkk>jJ2 zFBju((N95LH(KYhSkPYXAFLQdTXELib>YN})=$|ehCI#HjLr2$)J*|7H*+B3Ag_Y%vq2{5NOe#^+{Jqo?dm=G6s55!RN}hMHb00 ziCE8$BpgeiefRTK@IXmv=!h?LLcEAovaUmb z^1`}hw7!5=W!JCJ)K!1M_bk8QiCxhzjr-_DQG%@&;_~( z9(~ybmA<=DIj>aZnt3oNB&8n|vep|Y%->DBwXVj!)T~k8p8Ppf>hYb{d~>ZiE}{GM z5;(6{5J)*BZ@QTMrhhc}y8BzFVDNP#_fcP1Q><}qw$M{t(mIdTdPv(_Tx&-Ysi^q&y{DMk2%~x8-roLu1#uordx0@qd0LfgWuXd(($Rx%iv!Zlx zJvf0$C4X@ree1N*hKX*k>uc8S9_mA;MI~X2eY#aXo&K^|LqYbP7@GqE@*xZrXHf+C zcgn+oNKHaJBSj+RA(_lMw|Z<7vtvhRX`hh&S#m;nOiurLd6=iHH(F%X(+@vAJyfsB ze~_06i!UXeTpg5*dIh)FZV&eYZ7t8$eK+hFRj<0I|C)x9y^JS_tx6allCOUVE%mDG zn!T;fC#`4+0_8hPd(H(+$f9E0(9fQ}OHzi><<1rLGvr!Qk~NiVwmh`e(s7Soad0ux zU-6Xi_z4DG<^lCu+-j0hY%)v}s@a1aSg6MxK$h&DeI=M2>_HAFCGfhzo!X^C|B2gx z$)YYb{KF!|b`xkS;oi`n+xf1u1&V|#(kcczg<@F8A1GE0 z5^RNXX^(@YmE{-4_qwR-yF{&i&SC8B>2&d?GCo{yp@588aX^8(S=C@i)4r7D$q-8Q zEp+vAV__pag-j{-#2+GY)~Q*DoO7WLEYw#67qRlZ)f_-4Z_H0Hg;vZ`dETv9rM-#< zwIa{l@lSXBQ%nBIF^On{8th3?JpNpC=Lq7iRp+ScGKzAa2Kre`jq`Sz*h^#4+)!X^ z=^F^6{AqP}4~~2)vg4!AR(n?intptzzq`}leTMowB*d>+?pn1AJBfdkb@hY0(x?4_ z%r@0aJRrFR4b}~Xs?CgTd8c0XzK*xQ)6d-LXYTYf04+h%zIXbWJN?YZ*3Y2atkYeS zrzU&#fIP=+S>Qm0|E#)aZW~Hza$X}_OJ_rJ+<(}A;07xme~E5Kf^Yf%e|s%ij#i0(-RA zsp>2m)5(<$#K;MUxdyX1VnXD(PIXIAVqMcnaqsrJaeb0+=2YGjR!Cg(%#_1D<0*T2 zN!~bA>Re~^R{u>g6OP!l?4f5(_hb~L<}NM_Y(xdbmt79&dDc75VfZNnuM@6XyXt{;1+Tv z=XFXHhk&VS6sy&LWl9jIqz`rPJYrU>Gqs1Zts!N3Ed(GCg?ZJUwp{;QVu76Vl{43l zl0M&Kh@^0&0D)y(|AFbVVKwwewv-$clZO2AYQZ6svpU@Qb@x0k+sQGqIHjQufk;iv zid$SL;X=+*CjJ>&tBT<$3Xv+LM`*+p;e)w6;Wx2;MHJ~xhbTh4&63}BPmjC5|DGoT z=@t`rbV;9l_+WB&c0Z8EkI9kKfynrzY^Y$i5vfB@>(N#C>vnbX4qr&@kMBzT0B7V#nW-Zwez3C=VXyh=31du9H4+6?~CuqHlv#FkWS*;{|0=pV*G4|E`+IHhhIOj z<_v4#>Bpy64B@v)l7IRo58I zo2Yr;?q0j2`L-KCFw#pzg(MHjB8)R>bUaR=UOk(b<>AZmK5ld#-4C`ttkQ=8m#^ zk0y$NhH9Wa7@H7$1R?uNwD6KACJ^e$cdn}Z5QZs~<&08BgQdYVRJ4$d!-|YVJUx;7H6&4}g4HtDz^Bebd-wY^Kb!w~*GZq9-^%(AC&%Ub z4_|%x;4c63$N1If@2s`Yqfx1XA|kzt1QZZRLJ6RWl!Q)bfq)2v zKtk`m7!?F*0gM*p`gjrk@6PeRwtuiPSmj@T z|3Mj|@ISx*@W17XGcndVaa@3I?kDtgwaoy4qg(*M5q=gX0040Deeom!z>pAtzyx@P z(1|<%2+{iU7Z9xA;_V**glGf7V62aioRce-;D`0}m-BKC0D{3lu)=R{?dt6GM+U3_ zR=B93co77#04V?=8j4ULL<0hrQwD=={>Wnq&R%~Fs3fNV1S_03!s1-L0=)fQF8q;j z4!{!r2p|=(*f5Bbxw4{`wF?GkqNM8n*Q|g2SMNV!Ah4XO90>HMCm__v`A@TxbC4^} zncfOP03lj`sSX4yxc;TAy$0S>8{`^_CxDc^vCeuf-YWKg2BA~oKQbnC0t@;xh?1p? zv7@Sgu(pW;$i!1Q*iYLf#LY7Z>*wP{u!5L)JG+?rhq+i2tQ2)z^-XMmU`-$xi8aGQ zy`0UAJqV7-Fc1>2Y3&2GK|&EILl;X+8>k1^+|iGKMye3dK(MBvMF>>I6s_q=unYr& zkya>Ee|J4sH!W|1yLA}W!W0~AjRAs@ngl;3q^e?=mY<)onHCOV35GaoTA@spLJWMh z5$0Y2w|B{v_ufeL*wHhw@b5`)x7S@`OkDg(ht zoQpOD2-Y<7a{_{qXbls*pQn+L4-kyR;}vuiwY-c7cpYe1fS;4457t=2)eD3QMq7lK zU_w9^`kq>0HjW6TzyLEO2;}CA^HmJ+(R2oRcw&Prtik3Q7^J_7la8^Ov$88%)7@Lg z+$R7;(A7m+JKH$o0^Hmc0!%$aLjsUix_X9s1b@7xiLyVz*bL+2VukTGwhlJY0(qKy znQAC`E2tn9+@bnDp+Sn;=AlZCp{n}+p_+OIW*#oeMoI=+?pS3k4g&E-TA_7=&|yY6 ze-nKTv(P{{u!pLri-8SR*Tcs+(Amo-#4HpD*7OH^dpX*;T6kHjAibP?2-XHZ5U{mx zkfNiNv!7`gHoy^M=H&0~WuxmCs^W}uGx73Pbn$ez7m&(%Fp3!4JTX{LNjF-#l=oQa z!2^DgEB7V9hK8p8?#?z3#xod{9iPme)iUHVIm2`7*%Gz&$Uw@Cz-sbj<@0`a;&RY< zQh#u-trpvWqR}zu0(b7*xg&53ck9lbJ02|{4Q*|0<>@RjadGi% zAH!3eoOg|&l6UUh>68@W($>~?;v%t%i;KTxr7&=Ea*jv;Kj=0Fj4V%KaWU>-d*x12 zQv33FB`9ba!_KDwki5rAqtWKaD$ad;Fn&h;_6zmS*)+tM$f@?I>f7ym9-o!9-tvu2X8ddl6qHw$!v7?d{mU994zvUOq*aQ<_>@1JA4> zyZif&ohfItKsct<)YO#R+>3|mnti{u@fQ~23d(r+kmTHxfgLNyhD_aLJ|!f?ey=Nf z@8{e(Ads<yZ5x=(rAGWhheT7w|&GqBkk}fYT>6_!1`B&$H!N!FX}gr*9NbW zo?ojIS5!Qct?Zc!OInPh-j&$aNry@b%-=)7np4hd`Sf4j5tEQ$(9_ea4qADzX??

=VheBFfTBa5jSS!a9U%gUXxW}@b>{J0SJweeHer8?C^fqj(r63s=UtJAd@XwJ} zR_3`JzTJjPz8tf=8?xYUd-?!JOdS(Fc*;hKvyru{=PSEf)iG9qyZhjQbR_ACR_w{M zVDM>r<6x0NQNJ(i@+!~vTm=1dX9p_jwnjTxo%s^J+WyLQ$Y*O2z2G14tvg*NWaahf z`+NkOtX(~3Ur5W57)+rFB~w2OAJnOn;@nQ3KK;HJC0f7UA=uq;ztcKCK3>7|qap(n zlQ;-ux-X>VKn$eNmXoO?!UqR3Bvt?=SyX5B%Ue!P&Stn$*+YGO{Zk?$q^71T#YB!8 z)AGg`9Ptf~c!EOn^4$Z0a2@QsdwbZ)hRDI<^Pa0;-p&t~aN+wOUW|-48zV=SH^yLz z+s!oF5W^g`z~c=K4H1x}+>6#P8LnTyzPnO2S%?}?+MeTEe&IDn##Q?f(c-uq{n~w0pPX;7++Q(fzcNO~)wmJmR3zWwA@A^&oBVRvcUho2 z@$soJEvqr|&+^7bM`GWM8?|OQi-m=y>5b<^VZYCX3l}cT4-~|1^4B)ea+0Z^TWC4` z>HGe1AZ!I@YI^$SyLW~Q=C)>GVQTgD^(J<9a*^>Y+foVC3b@|$LGm;uy4~?+U7h;I z&!0soUsql^+Z);0**%d<{0BqK+Z38ajV3Whgo}}pacyTO6BbpvFj&MEA0J=X?{j>+ z7`~h=!CwQ{N{&M&2{gOC)+cL>q@}0l>D`kYBtRJthD5h@QWHOsu@vp44`u5VQKBwc zL#ea3_jXlP)h7SRcG_kF^{zz0HlY&)@|)EaQuWi`XD>yBg{if)v=sLHuxu9->2p-T zTa)5cCL_4mc;(VyQHu`Ew-~cvk+qxrLG85RW}0s5z&>O+YwT^f%Kp}pR3y_#E2RHY z)M~?l@jiQ<191^cl<3l>^5YFLWtOkpM&iApW`@?*{2yPro{Nm>9V0&&6V(Ij6K~w? zXv+fOY=87?s>F{xwZa|lt`8E%qNycxJ9x17*w;nwbTYv~eQ%jPmcO}vfo)#Wvja7Mzc94W+ zBALdUd*mAvk1?OrC7a4G_d~}-^~@?77t=(!B=526>FEs;QiLTWCB-jYvfWP%!xB5_ zD~+e3i#M~*U$~(0^LuYmznHq)U?FRFcXwg`6RvH-CAucVleuXkTp$oAOVKrTlix{a zhLTKK9C=#wuOe71Ru_fJghef%S5o5UXP64audcY2?pf#s-WeuBSu5CjpCv7^z`YyIdW`rGDm!TyuhYA0gumr^r%UM zu-Lu1FjV2td~^Zg)=nEEOKekUo5*nx2;0K2{N?S{{lv!foE&zep{do?C{V*Xja(b%5z-xdOgjtkO-2qlglP;MC1~oBYJ5 z8|{Uz0whtm-PUNP+_kWYgf6$&;&O7&7gv)=B&4hBg&W!SgPR*0w;sEO{OnaRwY80y zfRpdvXPx>k>M%1i6UB4U#$o)WbG7dblfHq$`bYN{)9_z=91#%_DGwePySl_Jktrn|wjtHSC*?78Z} z8T2hnrs_Eomr>qn!dxOEBAxyHnXnme&rj8ylJ{6+PYT~6lSR9GdhVvDGs5BU!&Tz1 zr(vL6SfoHKhbR-k_H7tov^HX8pI2WmG}lk2j8_tld^#Lj9UL44 z0PvOkmH6J${hc4v z+q&_s$JEv~5klyDR9`PdAqlr$^?rN%%iD0e)l|LBGL+<^s ztzR0jX#JB}u%f^8)(0+qDCHe`?LJCBXR_C7&j5VBwy}nUhE8{<%Z$|p zuX@@)45x05=D7-7KU~*I6jb@~Mt*W-ypp-8ELdCgQpl;IqM|BlBCf-}`Fxq0n(9Z810&Dy^3Dtv8I;?U0dBaDK1WlDdwYA(;2%P=JUyPj z48K*O(7z5Wb~gx~K`S3`ciodRAe+i;2Xh_VYo>WQ68H0#v$9mYzj&^G0nUURtW>T4 zs9V*iix6z-e(t@!QJOGU`1Z2KWJ6?8zZmoU=Q@?`l?f@jHIjWR;Hib0L?zQ8L)*sd z!baK3>98oFsfXb|G!Tf}oBXdGi5=}U-PGgM5$$o%5y15HGQqJZS6qJcX=9a@}utW*HBHE9_&8%{atWR(- z-Q#xl_O84k%RM3dZ3KXrqT-pQ(HC?Hv9o87{PD?b2auC=pS=7+?Hi?yMm^x<=f6OY zA5TmReAcEk79fkasr<}zpS*3AyMa3junU=H^q6>Kw9o#s`Fn3RC}7^?Z*j=!4#@X# z*LQbsPmipjytcmH+;vZ?sNdz(b}@`T(~lRaXFC`GiGnI8eSLig2`0y$+18vkH8uTv zICL=t+$b(Cez_VQh~`OP^!)hhF055_7A;8ex!)k*ot zm}}+mt#Wv(Qz4CANfHo9)Qy(`f8~&IBrZA-CAwUw{9cBDD;P|c8NBfechTd=($vc% zud&2^3Qaea^8hlN1ps(^d(VFVu20rbg8F}FR|}XIi;U5#fKwfb5?xQI{6U6*EB7Rg zOe`%WBbm_VW@fj(_huWAr_U^-h;-fj=&%NXK>P#Ne5!%OCnOa89oDb{&R@KEJ3CuY z&bC@CGTuNv_=k|9QR~*yXc5X+db^l|exUts)7asX0J_cF+1cqD7~F%k1B)I%&c9X{ zG)TCECBCG4{aI;hO4p#0Bu#UbYTc7-US~xtI!TH{p@9Wg!xY zIqJd2`)97*y!vB| zJX6tFha(14K&A=KJsEkC2its?!xT@7Tsj{~dLl|ZcnEqJ@|87U^^35K)$`~Pw{%$71!-yNa>w@L3=9lYT~cIiP0d@I zdUA1e3{58)j1=w5PEJl@($dF0KfY@2ynF6$PL4-4?}sEom2%%1WFjBvXqnCHmbN&q zyZ7&3h~&9Ry(_z|^LjeVEhvo$pKs zA1nf@>@gf+TmVwWxnU8@U1j6S~xavhY2pzX~;iM0AnSEcTrp4ONXf(pK0 zwJ&XSo|_*iU=|k_Pf1M`j}%Y>9GufzP6m)z>(u>bSsWc5*S;pm=Nn}!^Qi@#*VNQh zAoK~*87YM%?7w(=Db**FJ!b9UBATSw;{6v~&Y9vqXMEodmowZF5P+}Wx7?tv29Q_HfJ4`o+GMnP>AdJc^R43&b#MK=^p2J zjo5GcF94N1v-Tx?mClGlc0LCeq0aLD&NP@GqeLHlpybYEH1z(NHDtlOld%Gx+D030 z0_FLyzTFXdpzL|vXz2YbSM%roe$u}OQ-ewdJoihty6%&E5AsL48I*?`vD$;v);az| z%mykM@XU4S@!IBQbXAp#qLEfz(8~K#w2Y$XM~i($zazh&&ubsU`C*mGh+`-eNeh)#N$ueOe zbLu(Lsd8V15o%;J^>{CE_EUd`03|3b&O2& zH9UW-|Bl4()odpJ&s6_2)&KjaI@{z}A$Iw)@I;ljj)#XVzW-rT1&-p_bmNG^eZ#e# z9UTfuc;Joa)mI+lr+@tTvD^6T0A5{JSK!=};WF{&qFT^0Jve6>O0x4Q0A@Opv;qPY z9dWpd$b%p!C#OfRURms$1BHJp!p}vCj-qb#$m{Csw)I?Cay937;kW z)~4npiB;VIg`&K4?osdO$K;TpB1~rXv9P zhTWq?+FtQys8Vgny126E$7n0NP{z-7!8)VQuWyeRLzxTU9Ux@3(W|tJ% zp)=)d_1wd7dLSz-l(4M}GTMK}R1>x({o#du^3;@r%Y&Fat=O+aD0n(7!L9lC&Fa2} z!>#@BUx~gm9nC#GZ1Qh6PrvaP7mrNU^7vBEkHuo?es`rU!IH5w^BDo2tg#f`SPTFNc4vponNiMAUDp{tZH0(y% zYh;uT(;3dwiao{8A4hLo7%Uo`t7g~^W;^hQ(LWEug}9VLeo=RPSKsb9ethLx9kx}v zsaoszt(&`k`=h(dKt3anyq#<$>FjSrM554skf@)9DcVY`tgQ1x#T;KkW==Ry8qUfh z5Qr>gPl2Pyj@`}5Iv+_oTTaJa+Z5U&iAv?BFx;4-Bo_p)ez|k!&J_89B?<@xvT$(d zI5<2SYK;AKe$2kL0zOgE7=t5LRUc+$fpAQRhll0flduKzv^T-4b^(jStd)fR3>f0V zazAX$zO@{F;6RkSBx#(h#%OPE-*CU9FGJS)C>#zy+@A0rES?uQ@Mqt)Qd#Z?+1AkU zYehxH{8+^~KR>@h6sT~9l01_aE7J1uwR_ROVqHNld?i1=l8&zx@bCDv5ePkUp3HK8 z=-8xv1$@r;HOA0g`izy1;R8P7nE`zZ{nzxb$InCK+DX|43l=`}dZKiL3kUv5v%jIyp6^6CyrU zKM9hMs(2*Ri1_8pbn71^Kp75(;Pg4h$kQEd+1?Ftx7m30$r^#>4$Vgm$*^nt>~;T1 zx!eqwzq}Qs?r+_LMJ-O>Cp>Hpo{W_G8&`u!KC_gudF|G&B6Q*LvuEso=pKFg+!=&bFqT$JW1P+Ut`wly&v=G)zoVHu+Dq(1z*EubYZCyKcBVQN@9ykkVmM%TwPn z?K^HBV=nA}!n;inqVxSR`@rsG)_Yyig@qCekj|5*xwtq*MC2loZ_D8`4nzsPc3P=< zm|n~lDDA<6_&ax479fk!RDSxlNpA&9Ia9PpDUjS#nXS|Xi4 zbMHTmdx`rx;oaC?*$kccRHwlGwTYre(!kA$ti(Du%b z#rzA&Zc-d8m!!kakI#dI;e>X_n~ja|56`b9g(%G zOiaWgOP^e;3tFHhIWPBDkCAcZjkTtKGP@$gL*K*AA=DsY*udD>c!aIk41r*jG|ak@ zlan)HXK4A9+t=3@%?49b6DTSw!qf$=c)}fbzqTjPiOuoj$4zW)6N$eLCf_Tb=!gHh z^z!9P37Ao~Fw_Tty1bS4I|rju0q0*{mE0~C?Iy*=ieBfFGR{eX71+^@rR=K8E0=+z zJ(=>9>DE|N3o+npd7s>-+r(|M=>Kq?fps z)>f@9l{MS?5KcN)udlB!wcJU&U~Xb(cYPvZVRK;!8nLSYm|7fpN@t&rj*dPnAC-1@ zcO51hBFk;cc1Ig&x9QYR$~fo7V^?VSw(Rfx!LP$Pc!lSLau=#fL+)BF0}6%umjpN` zAK&>%&9~gVyfYi$deFb>9z6nND|_C0>^k5J!hOovLlFKiCSVS~*lUTVk z_x87zrsw8jH#RmVXtm=W9belMyu<$^-%0u_-+2UZ|NecK$%f0Y{rPjzF)=M}uf^5X z1?}wYphViG_=E&(1;%G>O2f83WMF|@TxNm!{?9o;X_`vwr%$#n4`P4@8FcQ)lfXDh z{B>E;sP)I^I`42$5f)XE#=kJqDPX zBNJmDyF$Y@vu8x?0RZMtdfFNmPsZjZO#U^=$vxT24zQ2h8nJIUQ{~ux+`_`b;%!!Z ze0+KE>X(TI-h-`C``E{>(17_<05KR$1O|guMWVJj;D`Isf2G! z(Zly!(;!1_1meO@%z5P4PU=H+SUfJT0Z3l_^f<5pZ~iXE26Z;bIU0Be$}Rnyu(8rakzhblf;w2_~XY9 zx<9R{siA)3cs(HVw|>AW0fG3frBS-GOi4+(@yA*IEotfai$=YZn3x8OT6P$IVhRme zd$h^F)j~^*qC3ljr^b7rBLMmOwOgrhVUpK)eJCX6q_A`(GO8TDRRK>e^dqLTgCt3! z@RM*joE~3bFc>s+qwsG51l*PdxZyj~aaK;wc%R+vM!JlZxU{tXK6`dKJg@?u>J&`_ z97|#atZi;uZ0D9g?{=(sWR$HuNEl;0F#jEo7yC_cj;mkZvaqwK(Ie$TF}Z_AJt*og zXWK5O2ZzLAa$X0+qaPf4z6j(Y7O{*HriaHecxw_XfQ5}s3yF-`cV}!T>Q!6V;pFY_xK%OuW`f@a4PYM_I`<&k{wxT3ryP$}4yCLTwvOD1kacqN-**-JVOu9R>6~yqq9+t=3^6A2C?W*WGfPZF+Sz z*?+E2kDTwm+z%SF|6C5I_5GQ=o=kZIa)CP|BV(3Yp!ELMQY;;f__N=njtC!A!ndu0msejvCEeDVnMJ1> z4t}%_mzbMkFy|vl&u8c6aNTJas(;ZADm=!)3;yhJ)X%~P{+G6cgO^u-KqcMi&9A&C zMGAD1JDQ`Ii~2dYW|HCJ;^IeFKE9?q<$tfUSe%+khIeqGF5Ud`xeoWOJH6bdY*0!S zfj}@?KEvF+aRYE^Z}y(9u5Jpf3s~{Tvo+REWj%>aOk~$aAo7f|mFWO8_1?V`J1w=o zGfc`}pYCv;Lq0-3wakM0ii07LqJHsmcxpTCi87sTjT6XcB_tS<1e97*&T6G(Wj$HW z&N$A-b~h#E#-m4Kie8`iT4OmVF((8I`}1we>EwIfScogA+_{G*IySbzef0VK$Ja8F zMh~L<;lG6D`pKEFGGu6IDBa&n8t2^65ea3u9JYByTbsem%&ZVqz~n%upqx!0Y_JYV zNW;*O-7aDs@yd0GNh|gwLRXjN`@8#5M%l{KV-+~#w^Hirf?Zu*SrEcWO-)TYZGPi9 z;n;SE6I0>H`10k;zfn-=SR9vBN={DV{JaYTGjoCeT%V7>e^i%~<}VtRlb=7%x)P5a zDMgRf2Fjcig(bdwXE-}ME2g5tySKM@{=$VLfV8wUF*sbbrlzK|t4jlqm!yl8U9EEb z)}5ZE>MtpN?%Y5lk(el?dOAr^1(_*#jZRYM=UpVEq|Ql6>Ffqa=lo7e%&9>o8PYN{ zXFBhm8>{h``Z_a14;6-43P+-tIgl6(-_fH-rmmxY~O`{(!G>FMbs z-rnB3`}^WzVgM`_%XcY6AwNHVtxtWGZglFwKeR0^dAvSVpQVL2(LwyJnq1ckN^MxKo4Q8{an-G)_-^1^#50`f35%judMt3$Mt_w z{|{DCQu^2L|0zR2|5N|}zvKG%`u`(n006N5yZ%3XTfz|lV37JRum1-DAsP@xAVdQU zmQz&*{a>j6H&?poVS)|QGe_c`?NwF%Ocg_1{~PQ7RV;1(v;N=9G1yEg#3LjO6994# z4ED3|P%ts|wz3HhH1$JkT3LHK1HnkVhZzzG*0eB22KXYijSS6|%yfgz4e*8`1dM^H zpHUFlABC&c^5f13ieDn~^2bQq#uW+FAkR4N?Rf0l`QQ%`kkRr;$>ao@PKu zpeYV-rj0`)&5$}lj*7b0u2879ldhgK7#*ew_4L+Kw6=sQXqbB{YugxrEsZ>tECW0P zO+DPgOk9Crq=|~EQAnVNlB-T=P$()`1!n-#1%q6jm4RSQGYudZ=>o-}e6>*+RZB;+ zP-{~qBNbl{*U$iKoQbI=R>j;OW$f;4t#9mPtY;eH?-Uvu78tAm)^*g?^3XI0(9(Bu z^1xgBhnU&~c8OAW)iVgTHr6r( z>uDKjDj^}>UarPC1OfyEBTWN5jr>i)e%j6i8^;iWp{1#x7YgIA>FMTYgFu4~QD~4E zUeCZ2{dtBgTd(U+lwLTQ8sKm!A8H1NSFq+%G@(A&rpYUUhZ7_5NDc>uvk za~mL76AuJyx)_CEd{j`XCZTA8q7M*^3_wAVRz4o?PUhfHBXhbMT0tgGVSbhn14~a6 zV-&_82-ftqcG7Wo3bNF9g9aOUV%@@&osBWR5PfKnN}#j3MwpVar@5(fu!bQ9qhk|{ zarZPC$D}hyAjZ{okw4wSC zye<%|864)TMAsZmKluOa+WfrXzK8!@o9}L6u_eH?R(9p<1uIFluSM_frfAt2SY_Ue z8MnD_^TdI4#f7E71@By(@c4<2x`8>QmF>LD0K32Lg`Y0piWDl(`Khv;P03^j8C~Jz zn+5mpO*y8%bi{AJBd%WV_b%HLQ-JhO)pN*0T1E6yCDz)wP?y#vCiISSa;lPw^tC0< zWk_@0O~jOHYl9t2PIGqM`7dmgh#vPq1_dbxt$e&49nJ8L3>O_37@*^3cBW%Tj~yGR zB%lHo1{qf-s$#3ERBqk6MJIdPD-#6QLk_>W;3SUh}6Ke@-ExM7y_P%@Y%X)6>&@m%|hjk>_~i zZ10>9RCd_;@tKY`uV055=c?Tv95l1AuxRp7K2~kl!OhKm{^G^<67%8|GC4UXM`-!W zTfw-vI83?2kwoMJ=gDj(qG)iGnI8bJYSh zb#+<3MDARhot>>#b|#7N(_CB#if>7DGy}U3^b{R* zo0+A~LkoRm(fj5-nesYweYu>%!bypV>;t~hYGIq_^YioH*Z32j+18i^2$`MFkp4V8 z;oX>Y)%z`XC857#cVwxsn^?a%*(@wK4Xr(-2&u_q27mFz!HuUoY$D9<7x3UXG zyhf?j=sPO7^5L~guD@vtyAkGgY*g@KW= z=1{4+@RBUL5tV}gW&5u0g{oYTOS3AzyW)_GmHqO08CX12-?vBTE z%S^4VCW{geO#{xHzEQOJ`1I-1?<)zYGrYVBq

Gw{KT3J+CYGok0$mcD7?my*gbK zTU-?5Nz*)!4e#F?8^a8MI&Wi2y&ii{HtcQ=p%4@w8CO?VJ_Uyx^L(@7vS<~oa`r%; z7W3@)@A0Is880g<^M)2o?Cs^%j;rz;jGV~o#fOB47d(4r7;vU4Xu5?lBrI$L=q^Ap z8>!yd@MBACtA-9>Pd#FQK6m{1@l&Tx ziK#KEHud)>Ggl7)GD?w&0!qipk=ys@`DSmtdZoy~%$z{dIO$m8b|oxKEx(`uK@sD> zwDZXy8nIhG&o>LmC}rYfXDTc#q^mdf(wR+MTwI$X#$0ZJe*X9|ljp=6Zs91W*>B%& z*Vd{HfI5w3(dh}v$&^HXh&Dxx-zZm&duj9quW;0In;E)hZOzAtKu92IfV(?8uQ)js z&ht4*Wt7H`eE5)Wl&zePOW~q(%Dg;{0QQ&14AAY{tCPtTk#NHRcE4MBTCrc3UNrIu zM=dv*p(}2)@s@tQ{5^Q}%L%>I>pP=%fq{V`8(mU)qf09=7k@7=x$d5xZ+A-0`+tAe zoC-A1riiJRTcABYzH%L_@+Qyo5xbng8mSTtOiaq*$&XhXe~F|@XcP~PUrQ`NCbbL{ z=zNPWfhqz~ka#trw#O*Xn}kZcRWyz~t)HgiO0I z)?a)5#7Cn`ckkXkJA2@e&>G7zGaW1XkA;T+s9{DR5c#-6;JvQs^%=^{>ruPkxp7+} zq@}6pipN-avrVae#5$vdUdwcA?A^@F*z44N?9gMQ-EW!pVtS`f3PEq&x^;AOX_SNR zKe5=eOdKMKySpKDqTl$7DleheLK0R_Nl#~dYnKc($iTcXNR@bYwdy3Vyxo~Y;XQXL zOu_sGIVux2Is#+Zsrsf9<)^>JuA|o$vY;4d?`xkYU_`&RQiUJ_-FPE0K zM4&!^u(u-I+}tee>=q+j@JzXDw~~{S=lPtNGfLwb85!e9@5Lvoymfqh6iS~y%^O`> zZ{>hHjK6daS$(^+Hj@muG1w|5UvJr6pDAmk8Kg$*w1&6 z4-^YRU(Wb)y%EQWw2X|>@1r!ql5f8z=JAHrNwQSp9h3+nro z!I%v5yofFsxbx)6`6W-AS1z2EFYJ;Q7u|AH{h7A5e#_W}uPCwegBeboIMJ&=;-E0~ zId~Eg8F~2~9@3Yq9@`qr(dwc6^tnY%Nhz-Zx_x*f%gww*Sy@?JMusg_!djH+yqw&d zjK#DI=4;=xy;~eB#8gyxQzfwN@!ZhshtL2uVSRml0Dv61&A-336x-2(TxxcbBkv_U+}$IF82~kG&;||@j9l) z4+wblzoeh(VI7K z#z!yjPDND*ETnG5mFDCK-JN90UK=NFIhK@SJUpIB+ZDSdEH1j))&_L#!>*#y=nwtr z>FLv-YWx+ldwctaHeWs!Y&1T>k#KnbZTQaDy*V=PU*{c>z@rrYCi~S)lFFB+tKM&c zYE0udi%K1tPYN}aV_UT;Vp4oyCzipXp}$V!^2gWi)!#C%(tGGZT0l_nuO2yZ@s|Au zMuRbliR^|C6!ikwUve3szkPUS9kno2O!q@zfh1jB-BW-3lWOHSySKOZ07w`4@ZrN= z(s#sSi`mGH@^S@_&$V>7s^RAcp43Nt!;}j6%)dXYjX=baG{9MkuBS;ts^V%)syB*C zIZ>Cl&cLXf<^!P4BkDoRO=A@}1VxOw!a^y(y!;f6M$5;g9NP@LZ2a)j1vMtsJ4K~u zK_HN>q2U?fsO9pY6`Qt>4!UP|C~-?nPUax1TJl$pv)kL-{|N(0sv&D)9A3}B$(J@* zP713@s4;a#7nN#U;)@Midj$R1YBus@ZOsQQ3?CMDc5+%%DiLTi8!7ktTx*@2f$H}A z{*Hfhen2aL-S22dX-8;iXx{VZ#sTcL8b(GZKECmkQDahNH9*fu%gAu@@ts#=`ur$( z^~;mz&v}HSa-xeCncUpnrxzCD*m&jckiLHC%T;IAOZ8d#s5D^O8HXwL%5P{8QOhM! z?6@V)ojZ1|E{Iz=%JxRlBA)4_&>dm*pgW{#OG8O6rV|1ZYD_gO1|uhovXzr`Ui;nE zyC=DR&Ga+7!H5wM2%PRyU)9#oxH*6RK^mEy{QO#-Sh? z_hiJ8@-G-<${`#a#QJj8rPPkIHkkq2+S@f=jLtOOJeFVZtJ^zLqbK6a){wA~q~|M$dss05!u`h)S>K$%;&ZmoSy zkpH^zttWrxyiI7RD!%u@?djIob3ou<@aXff`f7dDgmXevcN)ux=ijV&1@+q`z;t_@x#b={MyqY4g2((NlTQG4|HwTiGUw*g<>JWT1Z z_-f-Xm`KE$#^&mzsQc*i+wG2=!d*ZCLBR@qufXQY1TV+s%~PrO?jdx|_05y*uCn;};}TL*=b%tN5fKqS`1MO~JSQao;8~{%|2boAZS6-WGHiaR zm;?VV>t-@+pJlF}%qzU|Sl_^)!gE5|kPH*v`4TSA#Ljo4vs1UQs3?wvl%|*g$A#h7 zh1S>CL%!c9Of4-XRNyG$ii&60cx11*xk(%6K&J;UF)}hL+&82X1Whe1I`5FXR_o9b z&5EhSpV-*guze8wDyc}{*vi6!;a*pCbu~0PI+}hq*ETn!n;n|&aGpEG&3$`*-i6MK zvQ@m1c)X;azrU%iZDMNb>9q9pyvL83nzjnQXQrp;6&5nIx3_op_9F0jNoDUZiJ?Eg zW4qHX+=-8Gxx;x*!S}0nNJxm7m>3{0FYiu5LR6QNrmt_s)GCWBzd?F5J$S9pP$~%h zA`(F0bez<~8?mv>HdS6H^ito~2D*oYg|+nb^n``Y-qm>!`EF>aa(pyAB*bC1^RBMG ze#^tl;VGG!u`w}B11jmC*bUOp%zVqVM^Z?_*+0@gm}e_{D&RWU0izsO#~vGHPevvs zCv(vD`iaLI7`0{5W?5Etp^Ule!EZ8(s;X4-3ktF$duO}uO|PtYQU&bo?dxg#OSevQ zDN)RT(|>|O?9F4$j%!oR^bMELyOo*Ai%jJ69s0>G3KJ3$5lN9?6%i4s{zW_Ros8VU zQunvyj8Vfv2I*AC}yHyBQ4VIV}mj?a5!-*q9ntGwkyXa#3 zO1e#ak-kd$-McrlviPdT^{>WH$WXa6q^+qzGDdWdtvBHH$&TyvX}Wzol$@?IV|K>l zTU-?V!hrx;bX9xVuxj<&(*`5GJ~DwPyk7iBC|YEC@MiGfM_uyO62K?B&uj+h*6VfY zcsxFyH2b0YZ7p*~DU+`Z8s_!lW4qbNoyTPssS;jA(k(0Ka7?K*rOZOT`mNhB1N80c zbT`2&t3X^yDNB{vPU{Lf5>t9SczF!uRn)eEMqo;hkGx9%Li|Pjq+i1C^`g7O41LP0 z$SFav%BoO(-=brRjIWtxwhI0!c`(A_+FH7hfwZt|eZ*P;

GnQ&jK1+c+(mRvi=0;Q+vxwi2 zeSCr80+T3I{EP?}VMNn|A@Iwc%cn11pTBtejLewqVRt_O1-UrhcL;PIZD z>S=w#`m-T1HO#&>G8^C`!k}3-nWZt}Ob|dWGJU-j=U{)(Pty!s9Ts4=t}qs1fQYBp zqjXP{)}wG=_!43RXi&PVh~nxbXx8Ls+*l(|Dmez2xD5Et!t*-BRBT(!kiDK5M+}|0 z#>sMm@(=b0GU|OLq~0GAWZ1)n!Y&%?Y&Ys_7!)Xj+ZNLxjTuo~HVeoI_ub0Boz7_t z?l!R@f~tSD5<(UKs#s`?MjA-idg}P>Aks{DEO^8^AlJKO7N2B-UFb2t4Iokg0qnsV8~QDZJ(qHY;6uPUxU0bmp@7%kusD_1&n`Qi*Uv6(#u$xVx)bEG&FwO_ zsh%xsEF;k$xw0wBqL|AN%D-tz1lhVNS9b%VjctG8B*V%}m`SckY{JrLse!S{iwvkP zY(Ogu>7s^iPAJ`^Z@6Z-q_s}YH1yxvF(+U`KZ3Vlh9~bm%OOdy5k5p!%pY>FctF9oKR;i>W>V$1w>zHyJcIGt{Optb8GY60xcXRkF0-fZ9EV6;qZNPd~$r?Fe~OX8s}^4nyCqj z@qvZgN}-K8z54b>awK4U_!nNngqorlVv>gAe4IBLJ6*3U?IT&p;-61$7D^@gE0I5+ zr~A)w#K!}?<^}H$}kH5g%r`@h|G4VYaTccGN;!$-Bv`eNUmMth#Wt(0;Pnxf{pe>wMJyJ z!b}N=`d0TBaHNRWA@wC%$v>Qic(+#Z@$A_-nMQPm%1$--8znP&w~j~QHA|0<9-+48 zt?6V>^HjYkj9CwQJ1FRAhMkUqgoS^gb}_T9LfscvVFIW5nx%NULmul@Q|ojUCIF}V z8Wh-|k~OzuPH40)7qpPxbTnq-Is>nhKQQERg*f%_v)&b3B1_;rQ-s5LNSz0kcKpbN zG*W zGMr@UY=^PB4st!4;0yY0!sB>^3kEEG5DGeuH0KhFgaR8o&t{6Po2d);HCIR|_+hRE zWRheFsAj|KFk&;H8=*Wa3XM1@Sh3C*bjC)Sbm;9W24A8u;Cwyo5Odsy1eh&CT+5?< zs4;U0W}F@wjKg>!=K8PRME`%|eXoN?Ds3(8-H@2c{)DHjZx`nA@zK%Ik^YcP=IZEP zvy^;Gtc7xbdooxo2F`-LRSTxpYoI|!WGGoA)O;OUblg8a`R|2A9f^|r3j!-fu4rtz zI6W0S)3p{|Jkp`V7B8@_2_ zBIIDO7-WK_y;&9pY>?ZgdfGNMI3QY*84Us|sp7Ha9B*X&MBTl{ksB}1U>VazI5F>m z7KxB62?}l}N-FS?vxt9&3qm6$%`Z`5FAgnb3?&IrYH$rSTKs!zGL7cFVyDn&r*qsl zzV+akTKcGS()b$tc+e;3+C*iSyOj|OjH+5Yoa8%br7P(E@x?D^Z(p1~f9kVx?d_58 z=;TUK5wHdd$y0_C$LApGYQ-I)WQ-rH!-5EAq*~0N4$A)6iV}ZVuu%2P-myt0HU8^q z8D?3%BfU`K)RZ8o)elDmzU+LFD=s?6CtvlC`bYia;iCs%ee*3`A)t|Xt405}cwrh@ zvh(t%N*h71nR;%S=IVTA4AIh{UXU#kE8;Kmq5?2Q@2n%u&VbDJmiN<+QqXNj1h*M-)Mh2jfVTkaM zDGmcurx&h!Az30oBn8Q-3XNb^d>uLF(NWRTOGY$FSRC*;TEf7in2!!gIMoJtb8OY) zoJ=d;1PGmiqMy@MB+Cn$4DqhnGXnDI%kPQdv~V#(K9GMr2`6IU9G*P{26TSNPY{yB zM`8|rKG8(=)sydt)A$fZaUSF}2k)c4BJ=86=xVCn(-~V#;qr+!gt>C)#V=o}(^&0^B)fuKz# zPamgQ+)H>cxIQMmko0<~5~rnHDuhmWKzcn}jqvfk&hK!kc4-p+g0|Q0kaVw)yNCGv zDvSg56Lk~jGa{SsIz z^`=vH^65$%MjD*L^WN0=bP%xXL7YWVxA5+_;-_7((W)t!yJ8W>VZg?vF6~SgOFMz` zCvG*g>fCS@)yoSi=c=p0B9=bL3yTVCUijw2Z=L*~dGoF!nlzQ@KdIWkP%NY~fCkXF z?$v)GOLI$n_jqAr?WYs<>V?~3PxaWdXl!qX(!4sQ8Gh(|xJP>7aV~$gdw5<+#g!NsUn!RM^ui4SHi>A;dK!Qp zg1m<%7<)^e^~P)##s`N)ySdfY*HPCb2e2;(swX18v{MsF=KLke>{@3pC*RC_2U%MYZbUU5DDyg`* z1bSVyp;8-Uwd|~K6&4f=2N~uj-Q5Q-$C%Us*XGnv>JbxL#z<7pNd zu7&lW5<@&N%B%VVT{jMkdIYzAOiENv(wPhny4N# zTfGU*wg!8stZkzeLPl!^Mlluzg~S9*YLZo$oKLgiTS?Stz+gk0ZpHn!xHit`8aCa# zW2C~vcEN*tg3#$Sj6=CJMpN|7R6I7g(-}S*tga@7hi>9}Z~g6Wf9sp)j;ViYAM}G^ z9FPTy5L58K<1wLQp2-pnR_&ahH&W0MHblCo*|&N$+Zpwkgpd}4l6erp_^Mty+g%yCxFrF@K-;^~aWVCX?B z0iZt3SglP4_)tWa!u0^)WnA-qpUbAMXrcL!sMin*i3_f1!^dCB+-n4enk^aGN!pU z>5WS=a3@m3P&j|S%q&{;#av%A>f^U#Cgj^BRVQx3!~k0i_DmN&d~l#(aitL>xRVlBZ3#ff`l}oR1ZKI^(fm|IAoC0e^w-=;Z2#rU5ue0bvOv zxO>r4ewNXc#*(oBu89mN8*rE-q$Z&At>x_&Ze``DkXct zWxnVFWGsL9R0s&ivAQ!ed2p@@h302R!&=op%GU)gzBjPy&Bf{E=Z?eg5Kyw->*h{f3K~y9{-}R4I<)94 zFlI(K&{wOzG;^-RwJhh6Sjcjq&=TJR_dOaf%M1rJ45d0SFt);*F%>$Vh7zHOKX_|r zYPXq$J3)bqf>@c`J0uArValecb$;Vnjz|5I99y|$4rNa1O&`f%CRnO21r|#TIDs$| z{QrMP{gc7bQSa5$XHQQrpT2nc`sw9?vri}e2X>##YJMCV%z~afWPoApRm; zwcvUU)GaMD(c{yeoU>k%@_(?2JUH}lw+g|LSc)u?hKy)ujliA?h&N(38=m9KiVlBD zMoFWX`847A4QS)bri@AmVFMOM9W$Kj13aBvJ8l}ovL#CJm7W0!rC`yNq-;i0>mOs5 z?CHyA{Z8lp{lB^ij(|0?Xr9M=6&B$?@84G!?S-Lq`my$)4n@&-S25Jqk})LL$0M?D z4BH^XEXkP5IW{_h={+!O?{uVg)?$AYFZFp+?Gu_l00r7XU-5PBaqyi;a}pH_&?MB8 z>Vf*^z{>p71|b!N2MgB-RX>UkcwO9E)CeV*uHDey`!G*n3-6;%)XGdyVUh)eM#-Fx znT=PB2_Yf7XyHi6HR$z-JxQmNXzV?9QGx2;rj`(b##R&982CdBX zNl$Y9&j*A2J~_twiY@08eFZ|Fec1mzo6Nwc&A^s#?Rc?2BvoW_CU z&JW!HJ5R59805T^4v@)ZuS4zBt26&#FuL~cKyiB(UNhBe%CnhqsZ(S3-@SYHt{|L; zanaequEaNn8};~xTFQg>LSPQIV5(=y+?Z-5w%htHPT+EoF@wpGVs2%b+4OLBPR99w z^~u?sO|D93A)&MNd{lo2n3B0nvx|P#d7K(D+3L0_%)PF6xQe|cLCL-*zxMieGQ)M_@Bq_gU#%%#66k`t3i59yN4W~4WvXmW?8?6W_c!JnK zSQAhNjf7ejD#?P;Sj&btj4b%IS%)Wujdvmmg|;baJBK2>bUJ@kT!^NC+W1o@oq61q zRtgx`b2E-0L5Th3;fTwkQwta<`aX_b8!q5PuZXZK1m|O5SG@+~f(L@^YbMS3G=geI z8w(F0@~}2w7&RrHj=>UOBVi-(;8km4g05XmsExbZkF^oaJg9~_9vl`VY3ynWepAKZ zG_Ca{e(n4l!ytcZrN?jkd)j{h(5a^gt1SrR%2+NL)=>!hE3-I4;}+OebmSOVY({W8 zb0$?I9xj@qsSYz!W=QPq3*s$M*?brzt$M7o=WL(+i08(*85xIGv^yG^TOD|iWdd@; zwcwmGC9C(#9L*JDiOx_#CG~jERs0;SlN_}QEUPy&8{vPXlyH{&2$vf}NP*YT7Uhu> z6^DjFtw2Cu@Lculdw9kUJ zyA)w^Nap+oys*(L&rOMAU5p`i1F}q+d@i{j445EL82+q1y_`fG#X?pjNkfh)sUG%^ z`o|*&eM*0GH58$Qp`9N2s}4w4rxNY3!fy1KxuT8XMeXp#F);STxTh5u51p=J35Gb& z_G0MWA&I#*4Ph<<6kc;|`C3i#YcIBx!W}inXo`(q5|YmBazm`F8Ly!Qo!|`C2 z(kYGU+dTG2d-B>b`u`9-K2Q@fst_U=BE_2$kAOg|&${ecLWYd((L2S{9=~%q8lASM z!Z8%C!U@gP7E)s-tY^TUS2GO+49&&r%n451Xl_sk8v*CW-uvMGq+|CDW9Nxz$W6s*l_~oOrI7zl&ea`rvLf8jaL{>Rjo4 zO7(hm`Cnc<{j2KwThnu=N1PZF#STa}tRT6};b8 zmfF541tFOAt5I#)gdYra=q57V3SS70AQa{{fzbLbHDafH_t%im)p}dC3PsF4ce6+#|f^ z+8k8PD#e%oVKrJPU zL1}|L5|yRv3B8+GGXMVaAkWU@Nff8$Wm!zKqwu~ejgozg6s!v83oh(E?a15*Mp{XW zSptQ`1YT{J%zc@6(Rr-HA(U>%Hf{Mi`R$tXq$|_9YeEB&dI{j4S|^ypoh@HHTsm)08ejizQP~e;SziR9lqenff=($!a76<5uI+Ziiz^sGN^r z#DbWKVV)Y-zVxupxWa#^lN!O18)>&`xOm@zLr>+Sy#_ zA)Syw%$CusBG)-cH~B50eq75g0Ln^JU)tG4PZ{2{&Ggo+6b*kcg$9dV)% z*rP+x+hi)vBaG;4< z&$00AYK)_!qoYS(ehL3QIyx%<_vrZH(Z3ykdGzS$tA`8^PQLo`-;R#IeE9H_jI>;T zJUqHP{~zOrS2;wCS(e;ny6N>6^xc9jc)HXPiG)Vc6ivF>F_Wb8r@U69KS9GBH{6BnfbX>mwzdHW%>id}L8G-_M2bCtYH$ooAIBNuU zh)-UbDq>KZLOr?2OE-1)_Bz!BbPW zY*?{hG(aWk3_mEqmH=xu~pDQLGGb%*}X%;B4I5R_s*v; zxV%6I+k2&1uS^Vvl_3UuNy>VENrrVx@R^xbUJ7kU+@Wx!mw84|TN%UAYn2hRuUA9Y z7&AITjNy!yHtAD2aY5g+o3+^=?8$||XRECpsF~p8dPy2yQ>i3mM7n{Q?H)I{)IvRWMPgC)1SQ<=!^|^W=?8iJV z_GK!680X85O)^rA&Ic_9K@uUyTgf`A+BYl6_JzqO>pXgRTpR}D3_R#qPHbgb zbO@>V9n}#pv=~Vim56J9b+l&kY8fO=XEkzLT3bhL8|ZD%nNJJSyD{;#nx z@k&~}b85UxdTb}yK$AD6%A3>W+o#NS-WBS+n$205Y6*Fv1V|tfDoPDb*RR6`mih+G!FQJgaM%v6NP7q?ZZYL6o$Y)z}$~+ zGvFR_{zTDW987h8)6@N^O9=o!e_{k{=>E(mhs8QBm}Xk!$*CMl%OVnm*DPj2=wN5< z?Lm^1kG+e%Hg4z7%}_l%Ob>?{>^Y6$$$^=oX#?&jB_)HtNh~%$VG&(k8Z>=~l)`mb zF%KnTZ0V`adGvaoGBM{-fS5~+Z@u&UAu#5yW6W(qcDw<9WSCUpSz+On6l31JDngF0 zfD@=7hbbLus)-_&U>($TIqeBwBpDDkU5*s4<-9tnVK&WB=5In!1vMlm4<9`b?bAt; z4axD*(V`amOU*Q4nF|>LKAYM;hHy7El*e9yFU)tsfk?EzbZk~6!(aCD^mFFfU{Cc4&i0B(7jGLg zM+1ksa$t`6Lj%tR*2@H2wc{(0=Wi1_i?#ONuOKmH)SxfTlh|T9$dgfHhZaFu_2kpgOt5ONitv;_oK09ii}S({cve0rQ6&UNJjq7N3fr1xxJ{bv0liheGhIw+ezi zuY2U@7=7cV8+WT~)nS%~lo^lDY6%3b__oL2shhCZTsdK{T06mLk!n;govPZTxU{C( zzSq_Fpi`3MtxR%!1bIE^1Zznqa~fxV3n&w%J?_Hd33T8v$FQRAZmn9z1&8Dt=rfqt zUV{t_sgS)ii`8XkUJT7bnNSE*-D*Fa#XMyqkNGoA4mx|JSm+HpvD3I>OC5}rGMR?V z#=Pdsi({bvu-KL968UAcU(E6va4{s_sxp!)zMHN|L?!EZ-Q$`mK?F3lu_6HGG$5B8`H^E#AiJb{)>_0qmwTe<8IMUL0vam z=doDOUhW^P7(-ie*4=gC#EjNY*(ioQ&DD&}^+nW80Xa8wAmSjekF6ws-iS#SEen47 zkaiQ&v(d>M&UUO_x{&<(Y&})wI)bogi#PT7v}ZVro&ncPvE-3$96Y{%_VeYBPrh^i zI(_!6Q$`$px*Ys*GB3kX%H^MS8Y3%s@oU8hvYUaHx-f{Gk0D;qWL54tU~S?&BkT z=~?hSzrMAhvj_gp%osk*+9MEyWr21|;c1~Uuk+H&Lw&l=`!Ur_ivGJdasSE-cY_wf zoHE#Q@@sb#P{~HWcFB7(OIbo*{?y$}1zkhFU+_RlY3PVAbV9s{RkE%_fbzn+WwgG4 zR^*EZ9!!tE+n&{bmPoYfIuq)RnWR0PSt3VU)#OrxF(kitJ%uS~I)Tsyx(FV9*#(up zyHYu?ROOm^FeoIY9~83I8z{`*O}n+O#=X?6QQw~YIaKQLoz{GFtvN2C`}7hxuU8OA zIV5konEj@IH2AvvTc=>~btCstUszMDac#EHQ(V$IkJWmANZVUnYey5Rwaz6W846Xg zfKUlJp{H4-lQ?2UN|R{PY9Nc=C>pU<=R*PkknWfw8)FDFPnX3&Xb95Rs#!a37?Xfq zySfbHlmRD;$BbP3f=W2eS6auWzGgMX7XV4On$K5-hKX*k>uc8S9_mA;MI~X2eY#aXo&K^|LqYbP7@GqE@*xZrXHf+Ccgn+o zNKHaJBSj+RA(_lMw|Z<7vtvhRX`hh&S#m;nOiurLd6=iHH(F%X(+@vAJyfsBe~_06 zi!UXeTpg5*dIh)FZV&eYZ7t8$eK+hFRj<0I|C)w>lD&*4h^eK)zWc~UU6_S(qHkE z@c0P^UFHGxTHI=qQEW0y6RO#R99XEw9YB`so_!^l9PB|3C?)W^!JXQrL;s1}fXSjR zHT=VWBE)tRXe!~}(4X7+uCoP-ge%f220G;zh=UG5gT2IzV{8ej3ypq?+gQb<_7smIxsO!5#t$xm7?Ct4v@uo69TyLR(j9GC&fx21MU`Nxwl;z0~O7$&t z^>SljBRqvnDfYx4B5~HKS%{o-p$;t6R|6M+vGTmt96%>;%ug_dR?Jd)-mO@ry^034 zBG26MPj~!NOa93*iD-iw>`75P{#D^4@BOk@ zV(pxJ9Yjnk^25bb2GFAiK+*Ix&7H@8$YjnYSG_B?gftC5vE|`n`BF(JKQWMYohJG4 zm9<#G^0+Jx;+{PpYBj_prHQ(U)CuT%K0tA!`_1vmG4kI5Kf^Yf%e|s%ij#i0(-Q7*Qx3( z8q>*@4aCR^hq(r`IATKNxlVOUP-0!vNOAA>x^aDyZ{}3q6IMuE^30UOJ>w~Rc}d3P;W&SCf|8#D4z05PXT;Na#; zH>^h9WJna1=;aTLQUO&7Ik2yPGAzq6W`-Z^SjHB0%%LDm{fnA}ur_Gp5K7<{awX?= zN)(5HscICf)qiD55T~RMb?-c4R;x3$hqA39WqB9b)q^hdUo92Ap={PJqSA(OK@-1&9)JTKeHF|s&+rJ)XiNKMR& zTU;pNLe5eq{ux=Tis2{fynrzY^Y$i5vfB@>(N#C>vnbX4qr&@kMBzT0B7V#nW-Zwez3C=VXyh=31du9H4+6?~CuqHlv#FkWS*;{|0=2uwwjdhAxDuUx!~m zvE|e2aNtZ&l9ShznR_(3il13YC{+ox3-ww#Pq`K$F;>|$s&w1X>>eJpk6(jyp9sDWV5cZNB=CWvgujDD5-89 zEu0W)VD8ByK{%NCf$C#}SRMJQhu3=UibP)qVx%g@Ojc%~YpeR|*#l z$yr`Ug5Sg}wN3;&VoNLNKsyJzdeCFo@I@WisD`h0Ud@%cv7~LH@5G!%Q7&kAkB_<) z$r@Aq+{x6HfH6&4}g4HtDz^Bebd-wY^Kb!w~*GZq9-^%(A zC&%Ub4_`ezzRUmoF@E*=J8SJTd2%YBQTtO*=QGN;Z*M%7*0sXYaj(n*6%`(Wq2G5s_X+0tyHup#;!GN<>1vw+07tn1fFt}YOaK7j;``!B0DvJO z0D%ec451Tw01%?}=U+guf{V9*01%=L1cR}Y!^b`Wp_2m0EPt#1^}l-m5d(qcROLXR zKX(E`eVqRcJ2?lr;+*ND5CjmS^_S{Eu!8Gf%Gzt-J+(oup?CsF$s6me=i;qm|7Q|9 z75*b*LMO1GKa(g~x)?jE`Uh*9D1b~nm4p4XT|(SEgRp)+P6R86iMO+hsehP@HNi?z z$5r3N1_;&!f`5@%Gc450+0593;D`(ZA@Q2lK2RGZ6oE2yv9z>-dVtLx{Rn8J3IPoS zYZ_XFKvhi9nw|v9Fd!Idg);Sb*K>8#@+P=jhhZ&D!NJxTAQ-7h@KZvnDu!wK`5BvO z;SiQ!h@++z%2X-Dz*ie#?uGPs3<_`qf;F|B&?-20f`6$_u&b#%-kSgfYa00mn0X@b z-o|(W&fnY#q91DLgf|M*16zT$FbG#)l%c5`-dUI6;bN(6Y2X@Q6|4bLa`V9(sL(fK z;|ByIF-U!sg|EJ;G7yZ!xoAUxU`;bWCm*MWuw z_&HhnV1JD@T)jZ3V6;Vu2_^(&q3@{`X5)xZ3Jfqqf;+CW9wiOEs&?Vm#K!5w}J{%!5yma6Mq_{sBIpqxqHLsO zpyiHL#^N9lU!)aUHwYbOg!4Di*DwnWbOU>+db$|cV0Arwj02s$Y(mUJfnZI4u(y|^ zjjM&1wF=V9$%kNV-~$0$`vxgGS~>ffhG7F7F=kHw-d;AkexWMPI5!h7Z$%eRHykD~ z)PD=93PNEuw5^>LEKRj=1XVW!9R-4zj{;brD$V2##wG;l+j8|gXeDSD1j2Ar517)rX@rRlP4>m_p=k1 zgT|A8`h$CIwb%v}jgG;0n>ntpMTs6x#hwrqxO3;u9f4c8TX*i<@n`{QXlrXLPiKjV zi;HLb7@p$fylVuNymRMHr=$>K>~g@Ka*sz6o0lXE=!|3Qy2U}Sj; zi;Hmw+begHlG>NYD?vfa7Ig*o>v2w$2e&;n!v!) ziIw@_Tc&+VT3R$e1TS{}JWH-x;H|nk^_G?v1()|?S-tpox$3;`AD%Ungw<2--o06% zll*nKf5g1Ar$-BmJuAz@b|YK9rKLr4_S?7V;SzIb*yedK7+j8{oNQ}v$M)r@DrEQa zDY~4})Y2MwW)0ch-*@axIhzH-F{P%arsU>cJXF{0`>lJ#>0ms=bjAgSUEOi z>L&9kAtCmAUD10#=gt9vjE%JYr{=3&U0ux?e;2PR5NQ!vhLY@p%Isw}uQh#q6kvyI zT24+*&@B-^*=?QFG4j&ata4KXf-&{py{8SAMhkQ}40F}E?IYG1X@@^i3qRcg*1sY= zKE7goQNMA#Hh7iv{92v3qT-osWzSSt(qbI-uEe%ZI#g0%{vHa}oN`vnr~mSfn1lp_ zf1aLRbPiV!SY%eBXmyYBax%Kfe46+AyGGB7cTgFvSHLRt>QKniU+nK~kTa3Dis1yGVjbymN;<>cgShAWjl z)YsQPB_cvCDc~>XIFGDaoP~Eso34uiZ!W$@vD${S{;OD`R9_jT=!; zMe-dU@(y3Q$uEa}mj${LAD;@-vKk}*EN^UdB=*g?QEP^?SXfw^-gr(FfA;%axNzaZ z{6InMCVy=cEhm}!xrLU~pT6%O2f|ihrlzNFzI$i5U~X#`7N%BTUvFY(Cl?vdvMrTB zt$^!2A0$sxqT3yB*43$R{QOyj@^$5vv%Qg>o!t|;#D6fvyiK7=)Myf8M7S6k8P|4p zGGS4r3xh>$@$vD6{XWOHe~aPE$rAiEaINGxWRgI$+iQKY#z?sf5{)zP8)8f>81|s zLx!`)-iE8}Z!JkhGL5uC`Y%PTHXIo5v)4Hg7qLW%E?p`=-Vjq}`O0l1-WzIWXl>2^ z@s;bj$e7+S@`Eu^J+MCU#?6klED+B2N57^@{K!))+~Mx}AYm+;T0+Ev>(L{z1&Ba2 zwIrE(S0er3Y2jhkSe3VE2T52al4-oTN4_!f81qS8vZ?%XKXgn~&#aoQvA{-+x^5aEU|;W(|9Vncr)w#g$o)#zxNjPe~YQR4HmL?cXt=|KjGRY zT%v0-Jeiv&!UY0>vJ_oYH~F1(W+=&&#gV5)|0;sTVs%ldOjy+Nc_k%oPEO82!Z7Or zL}Xhh)nakgxSJF=IB2Hm{=smc-S0+6lHg27lHed=IG)PSdvH!qdee%_nbKA@c|CzZ zj5Lp z-kT%GCMR>m$Hxn7x)bpD{6~+PL+t2Z69H49j2M zUfoY@OwY+-HyWB+T}|HD*eGqJ^~g6~8Bz=h4OQA@e+2nVT@g|X=(HZ|!@ zFNxEwu`^{=Us}GlCmaFrBrwuwG)yJlXe41_=|yAAV^^rp6yW8{m+#B2syw?|b&^Qi zlTtKleRw%MB{w(8>vJuZcDM(U)AFdLAJq-ip!XgD?IYgNNwr|6@3v`l^hKB6MWY`I# zf1$MzEBn0qdZD>~GG)AyaOBhB(CXmeAOL``cQWuqG#8_m4u zYXTNdU%Gs`sQ(G~U#VqC(3zs`;P7aZHSneH43dG7F|WFs4+ewnZjIVkxD1F#Y!2wq z!)~daVdF2FdJKoC-Ig=VXy_Cd*RiJ~fALvaS*4B20rT%mdEY0F z?g5+X>n}Ms)LZ3#A;0*t`m~KEfL!gjTHQfA5>FI#|12{e2jvZdIoR2wN8H*s7lt^w zxfw-8MTOLZ*o#r*=V74xy?AXT(lXNc=l9;$jc+}swzi27Lf@nMdLar)xb>>{f7{z% z-iFh?rs{2$p(Ga_AEaewwmMc!eX8-NAE_))f}gx3cZTXeZ8uu_S8w@7yM?Lg%~!7! zT^?9&eQU_c$tmR>$^zjO{J+zKm=hkaIix6S{gOe4By=+~lh@DR{|LbT`W~=0a49A} zKE70R1NYjd!fix)cXxNH-D2o@{=LZTn&zy-)O+Ee1&QSVLMeCp3f))Lxw?1&` zLn-gjYxhyQos&A&Q-5dsGBq{Tk01v|p5f)487wj=wS!^2{~A) zTK`eEs!tao*wW+NdwZiaVXpA)WsS*($fABR=K0TcD%&d)Qh#)BB>PstQwueTN~S@E zwvE??jk1-~VNpU;55s?GAP~1V`CmH{JKAZwsmG}!+T)-jfa&RJ^rXLGN6Lc-@umex zJ+i6Pa(@Ut%#}2%U$`u3`3!S2j!R0PtP$j-oXsgHC=-dyEr-uwi4uB6v>%0=S>+g6 zpWtA6#O>_uU4MB)mU}|@+YA6PMa45qqc7+ZVrS1D`4f}b4j?D#F?sog+BZrYje5Yz z&wqiQKc1Kt_^eH7EI<}-Q~87pY=rQreXrKLM^Y`9tP{6#&-|~>t z9gy$guJ7*No*r34d2M~Yx$B-(QNPQn?P3^xr5`U+&wq9>01^dNPWt-#4iZd`J+rMj zZE9-z_jKrD2)I#PT>Nr1IuOm1!07q$)m>Pt+!#5Go=?q)F#=rSJ3kO~_vN?XK*6bs z+pClEkulfG;albKRHs53yOJazkf<9k1OCb(<49a|AWC$(Q2D(K0aq}XEHilH7w)3R zkEN-XM}J;piTf0qZYt*iWHt)`@b>ne{r+8_tf2(;|IV%!FfSGvqg4T?Iua$io>2LN z3;|c}NgA10T1rMTq0P+=I0P ziylADzg8DCNVtO~zNAO}S!rrbTh^1|N&?E`OTG0zduD1*PNLo0Fg4p#0Bu#UbYTc7-US~xtI!T zH{p@9Wg!xYIqJd2`)97!W%9GufzP6m)z>(u>bSsWc5*S;pm z=Nn}!^Qi@#*VNQhAoK~*87YM%?7w(=Db*?%|(dUJNxNn1zf92Clzs~#Maoh@i6$+f?;n%vo``|g1f z+f&Q3mJelDeRtQePI$byloWGKO-*NizmA?BE8tOKA;aF@UT1GF!r1sE7y_Y-d3>(r zma%%?_U=A}lb=71Mm@mIcHVXQR1K;PSh$sva*Dp3sw%&#s%lH)xqn&1>^J=vfJ&ZO`x3rNXG9@8pM#4~XL)~D8qAMTqK`gMa%VCc zdjHHCvS8lHSOHIMqYXEK^88od?ua~4_B?Jh^!}Br`E!3i>EDy7K_vs8`=wi5_sP8n z`6Jy7%EOIV?ZIj59RDF^1Cv(v` z;`<*aRp2O&O*f7x+&5g?+0mhpga_VuUVY^;e)`9cAG?je4&c>wbp_5n87>oVE~*7B z)010$`>iNh=^g(GiEMh&%{#a&mg~>XpU5Ie$?2w<7#pl;|kxMvuI%zJ5z0 zKjhSzGttJmYR#WN3uCcZK1G*P@9+>h_f~TM;6Nb>cXoC*4HW43E)HLq{q`-dy!;eT z0%KDzFBXeEyRot1vp9S~=yKQ@et!P33LNv-uV3lOAgdS8E}+PgmzU@A;TeBKWF*L` z^VGX6(0?&KJ-yDpJ|3FzS;B8^YEF_^)eTT6%1h@S1&=X>OKVNXSWcdd>2hj0-1~Vq zHT9M~kvdYcGdnx$(35d73r>U?N^-@V5R9=bvpEZe@`+yGJqredbHX@OdFZdUKhW23 z>`8w9(XOs8wEe@SfdXba0+4UmJxZkQ6>o+r)qjSpiz|D6jJC21W&B(htTX!j8mE9j zyivBY9vQjy`@9SEg}6>^c1e*PI#bS8&piyMC$hpq3ER3Lqy1-0HDO!QA70oePfaO>dPkwl29cA}6Yfa#5MIL#(#1Caxam!;Bx<*FnFrDE%t=Loi{BiWbg~6i1xoU>(V73E)82#@- zxDc08$S>-S@9Ntf$B(aEtHZWRH&tu>zJGOd*KdDxcNxfMDjH*O#H#AUtSk_Y>3{I> zu-tnRwqTz2CV15@U~!nWlF*+4LtI$yhmF~{mctJmh;o-CjdRr)?d|Ow?sxQM$XXwT z!{LY96W)Wx^8yF{?Aul<%l#nR8ajThsHm79t2pQ9=U0dV70ytSXYyi2T0XvZFZx%k zE69bfS%2;i9hQ`*Ma!tLxz26$P5~&Nv=#1Vr53ZFQck9;C-G74v1G2^l z9fTtgh`&`w^C;Q{$Rvl?Hbwo9+`7BF-xum}EkJT^Q5QH4&gmh4^q1rE1D8JR&LqPN z`yUC+e*fMwF>!UDJ=T%9Pba6QbV9_Z>L)=GQWcM68WF#IneP3A1SrG75S+fo7x?lv2*K3OBM+@blXA%7WmZJ)jFKPi`+;qsTag4F%3d$6d*>HCC-&B2qAQh(!W z5XonjGB&T>+Es)uJbw0!{SV#4FQbg;jHw9TbOq=5E(;{LL&y_sUmSS~x_%h40P$#{ z4b%1H+&{(+mV8-RIZ$N4y8!8AYG`QarcIswXU5sqbo1Eyw@iC|vVVrMuAZKTiAl;P z|A`jbFrE2zQ_*JE4VNdXIB*nFIxK2=>RYCL$IWBRh5b)>w+TXYzCUIk*qzLJuPeH+ zP+|endGa(D7pI7bTqN>sIef-}D52L*D>V-@OiN396#Db~AR$Fq$#syy+1dH;l~4WT zxU4Kb!v~6b`|K|Z)_-RxxUI#Je-kM$S12qlHXv&Rr9F5Mf9DR%0%S3o%1=Kw>8)TX zXNtC~>xBnO?vjyAs#j(@l6>i)5#rWPOQiE>?)|56FL7Tdyc^pq`(ZMX$SCeJXT;!e z`+fFni$ld64ZmpN|BzM{IjB?r^MK=zPc>PW!{2Q3Z)Id;Fn@`PlDj8ELPA5))bV90 zFr3itc(bt) z{^9wxg#3JQ+lB~!5D4^M@kD57DAe~WLw$X{iHV6=Wa*P@bwLZXBM=5|ys_5w zPi0qxc<6h$Ie&y2Bn%rE8ykeMMrJ1ObK9Du09|9_7&2M3ySsaBxw7AJs_ABDUtdQ) zBH?{Lf-MJ5v|AkVEXPqudH!>KzhB{>SiO++64%n&s@0{kW?LV^NyqB-_4TEeJ82ip zP3-KhPk$sVY%UBzBX$)4Q;Q={>Fm?d(a~q+qtfo~uES(QWVub*?r0T5BgW#qep;j zWzSoWUB_Oz4tdHyo+SPfZjI%55!USbASNq|4}YLC8KLC?%%)fGTCq$wm*L^Iwq#Y?X|eNx}cq%9h6AB6rYfQt-$!KO=;NH zhkpz#kc-PKFyH^V1}IHaY5nxc*5yGA&>(}({df`>CyBoo$uH=PWpU2%0?xb~~z>sLqH+5lF|r`!Oam5;C0s2_RdY;UwXR!qF@d*ePTXMgzc zlJ$O~O+{nfuaC?9>tmCjiJse1TH_#)_m@lW9w-^?v-{nsn!GN!+HmmvU(1mdgnp6D zl?f}l%$K*}xXFgdfBS4^YiV@gm8 z%|UL%=l>qYiYRUI+%gKjU$yBX?|<+RM;z|oK1t$9VEpmp2R)wF)YMSFal9Uo`P+TK zDFK1_t))?VuuMrwx$!4h{;g=~_=`rplbDzWi&}OVeqss@S$nj}ztuuZjG_n2gQv!O zpd$eJ`n6lBaAA_yczq}&=A^K6Br>WTzEuHFE%YO%vx6i_qVSV&IGmneV1FWDVg;;iZdz>TmOt-y ztaxOUtvpB=V>~ebosSp$O>mB@U*58?v!~HBMv*8E~Y1k#9?w?2g9Qu z9D2S8Wu2o(}{TdV113MC9gt!1x zD=SH#KG`lno-h&max`L33K#bKoZl|Cr%&-3-b!KxxcuYuzDI8Q`ugwdL;e4T7T)9X zpFClq(P)DN6Qx}BV5F~a#U{UTGi@`LdROAy4q+a21W;5|7D^?la=ahAP>Lto)jt2N$zNlVlL|E+?q*- zi;IgNUHSN$9+dyR&yykRF9M&)lTz!H0`z#3=<>=gl3ljrO|AJeG^|IoIy zwU<^$CjDo=a zV62L@uaRP?mIlh%%-`KuLB}Wv2u3;?0>MZ_6FmiU9Y1|teGNZ?B}73(+uGGfRl^$L z=8f^v@-_>0Hbw^+=t0cfj4Y9snl|p%f7S{hZ;&F`2na@cXolefJ&lyY^fUuP0!?vv zGi@9aX@=AZa#Yl{c7;N zX5tD2BTZCPjY0xFlw5T}gF;ckDmVj>E*RwMtPBKenrQ&RNEav$<*SXts9HLje}!6` zDjBKxdboxLSmR7gEwL)*{wQO2Z)<&HCu2R+5Pzr8(6GQ@1+cE8u9kJdJMH3W#fM8?*3W~Jy@o;xC2ZtJ&)78)lGI0v?f3t)bSbCZm zqcHwJu%@rIla9MnkfpvGG}y=!>lUW$Y>e@R=tF~40-en@!jzOf%}t$yH4HHr9h+c` zyC*_f6Ji|b>#v}K3Usk{_SJXM4KN~jn(64`9DTh4-3bsp60M~L1Z%n@{FPi#eh^bv zO(f3K*%X2g)bS)ZX?yGFJS!q_+A78x7RrXcp+QP2UgjXYA5O*9SP87^YNTSSq7BuD z;B|pu&EPO!CA#Kly5aw?d-L;#`yT#tZ%^3voZ0+1p$YX_Vy$gHX8n;h8clC z2;$F^!y#H9GZPAr2%Lw{N0^2gWi z)!#C%((lldw1A-CUw4x``X38D4uJ)dbai!4{fU!h`X2$qlZEwl`}X|23!N8b zt9T>vcu7Bhe^XoA#MIQ&Y3b>Cj~_ENZ54daOi#}%EM#bJZ}05wMd0z0%HCfRLw|n9 zcBfsq6CdAlhx43*?^o@RkPtC3F+g5k-kpSms4gc>U*C$URTfu%gY;;6@>-vvR1o?_ zet)qn&}5Fp?51YlNXuD=R5S1T@)rHA|jF^!73smQvHi|;5!+) zgQf0o$r+=Dg$&Z8Rq6DipkSaBEn}Fie8Sq=x;kPH{PC4*)Q7UG1>Tbl#4uXpe=q7P zed7B1dJ{DI_Pck6hPi6osS;-;C7CEBVgG@PXZN`c(rp*3t}eu!5PT5X@Z%SE?Oc3s?k(PTT_E%jOY>288mR)M&ZQkE*Sf1TD9bR?$qc<}NV$g8Mr1&zRz9v^v?{)PC9`bocp-|Izp zhZ*{mSCLbKV3k$DK<5hjET;5$N=iyoS(;F4N=no3fm@%d(*=@{UPTgYUN62@SX@iI zdZFfcl@$n6D%Vt&ru}t$(MA?6_0>{ezjb9~4^s+O4_d}lmfg5|f8hdWmDL=!qv+N=19r&LVo#m$MbGPk?rmL&lbh!7EPIm8}(`j)~5K~Y%bvb-nJ5%o3`-aHy zknr%CA9brSv9Ziv33V&V0SkkS^t+b`0s)EvkGGQo0jvQCxfsGxTK8|ow?_m4V*vr> zm#YN<$^jLZb_M}SfAem(!RtR&nAb{z7qT)lc^4NKwJGlz`eL`o)I^mt-6A3`;ooIp zQOagdO3aHLsry^`IG3YyTHzkK9N7j+mo5p7kB@IVoxA-X1(^p;d+$ZA&b2-^D=RBQ zWGj0v_acvfpPs%+M=KzUq@Q`$-n@%7Dyk*^x_)VU3`cU}e=4o7&tYbw9n*?E**

pa>I-|-ld)G`V!=tnI_ivALSVn zrM}ppaj>Xz`r<3sp>pp@n9j?ZoN*7NgM*l|*QYz(-TJl-5&Y}x>nRefMMXvDrKN8f z7i)!v*33WAe_Z)omx(He-uZ`i`%T9k7q)z1m-OzP zp@oG722PyG{hlD-a6>{58nLUev9a;~g+1Kk<15z5h@U3{)P#R`i~jZ1jceD0MZ%Xs zi2_Q;85tQdZ#?)vzIKoOIoF?1TN9-2`;{SV=f|HH3>CeRRP-@Vix~||iCq7RI6RpA z6=Pgne@RQrRrQx#Tw2Qh>}pJg(X{|HjXbpig>E>tQ78qarN_hGiYzQFlw)K=zQ#$d zO~;DnKY7BEDlxr0UJ1CdzaMruBl^qa+d;K`Z2&6_2Fu4i5txhmd1MSzs-dAlnmwIg zTPu($Z~ul?S6?qwQc{v4!CF#M()&XZPTl0{e@GVfev8xlU2y@7lB2U!yhY@$)jCmK zCjyH1R$Nrk&;P^? zzx%@bzqk7~^ShagFTVI+9(-{9GoQV$^5tJVa?iEj)&KnLt`B|aLm$8G(0w1;^5)x* ztX%=tuRrCxpP#<_=+ADy?317Dee;@=e@{B;q&MAo{||n1?5U4@;uDvC+qmmJU0dz{ z_~DkTzqfPip$YF)0{dt0EZ%hb>8HPY<@3+n`|&sJ*zux&EcM^<+h0$ebLAzo&pf^M z^Y?GRrtgoeJC2>P=HwSR7~lNk=UnvP-`sNL%AbDk3#WbYKR@`B!M}X*cRo{nf6j_i z-%xwul`CI&)>#*R>xo-WIn8hVZ-2Mq=f{5h!QVZ(@7-&s9{8(Ied@j=H-7ZvAOG^5 zfBL*@Z{Pc~N3Oo`(v_ndj{LHF1;}Qff8_Q%zCHEy9moFt+S1jZNB5k3-unArH}mxO z4qbQRz0aF0e)O)p?z-to@9>UKe_ZhSOYx8I{lSkvc=6fQ>Jz73bb;rsCAgfu@cNr> zy6NN#p8m5JoHDuYT6E9j2ao>h$*(;1^|N{?Z~XSZKK)&Nqp|v%Ti$Up{I|caU!isV z*^wW;bN$aB*l)f4it7(vcj6PDM&$c*p7-L(Z+#My@2?V06=@>gI`yD^e^2hV4OhPN zq?^3QAE+3{Nv|3C=7!TALifykYvzsLy!`S%))4ykweLKsyQ}LtSDmrrPhKbHz@u0URL{7|7o?q_{sGnm%ZfW zFGu&+&$;G|9q+%SYwH!4UvYi*x)Y!HWO?IHSMOPI_$ME|ad-XiUis^9Uh$eY^wxg* z=KJykZ-46gi=MvsvhUt-{+r+Y#}{9G@wH#y`v0zf@bN>xcz9I)f0|jrTrq$5_}{O5 z;GtWmUi#`+pE-ExhYxN1mwVoG%>Kyk6TW!&-Ism+)Q|o7w~b40x#gBeUtzxOsp~gh zaqngSaKn+Ge}8z-Yp;9oFNc2d)vgWhqwkhKW_~_->cKDl=|!J??T<%>9)916Z#nnn zE57s(|L~rxuKLl>e;;}GQyTTt{BN5rVmI$T;ji}JW_D+@?;&eo`QGb>-}Ty|&3D^V z*PZytm3X6;+q2^5zxc(b3oiIe`_Qv;~^CVe)&t%RUvictR z)syf1$xjXj3vADx6(70z=0Cgf##QQp&jPZ3%RZb(pL^Yjf5?7-Eb?!A{AZu|$o-EU zHb#g0`uhI))~S8>i{?JzV?NuZg|NXYCp9fdgT6}U9rE?q zs}Bvl_SU<%oU!BmU!LBw=au(f_V{ND8xM@%^u_=D)gON0se9jW-q_gpfBCqx_1Ljv zk3Mwknd_<#f2|zMeEV%r{oueSt~>GSzgWHEx}l>dpK!tnZ~lyN&9+Z`{em?Y{NIz_ z_O`cen11rQN4p_Q=(b-uKtf zJ2`j$%E8RnE`REEC!Y7z>;7i<3EzMCYgfHuo$-nQ~QkpLpoy zAKQ1!$$=94!*g%_+A}}Y#+RRJ-`a`&E_)<5() zyh>4&f4*_oX}^5z{^#|V{_%@jPn*4jtXfypCT_UlhHrhQ`sxqw`rs8ue|GyR&w1_( zf8V5OE5GrLZ*1P$^`alnT>jS&jo*IXfBfj~m!5XoyUHJ^KlhG1?jUx=rje0PP2Twj zfAirF|M1Iif0_DE6Juj5uKL;~fAoTr!N9;tciwsDqu;pU1!ru3-~U=W^#JJU`T7m@ zD{dKoaK(xfywT0WyT5w-p^XQ&z3hfxfA8P2WlQfh+b@5|J4Vhq=Z}y4>d6=F+O_Ky zFMRHwzasw!=bd*RS)CrZdH-d*HXi%KYp%KGtN-**TMiw{pL_1PV|({r`u_L7YQ=-^ z%Di>&-b=5%@=s1W<&>`V>rc7nnrr^+;j4Civi8LJe}C-XuWjxzy6=_^r`>zQf7ixu zzvkD!K62_=7oB?a>7NddkN?TZx$`g4@Bi=*9=q{_XCFSi;nz<;@q)9?I?H|hffo@C z{5zkizLZ6cerV*f7eD&I&9DB=Z+`R7w^pk{^Ig;&hFStEw|?b zM1%Oi!>|AE(;j%`XTS2h$8LITMdP4Jp8uO&=UB9=Rm<$5_Z)Wc0)Qs@zw^DZ_`kKi z>jswN{}$tkTv}FyE-KT@Pe#p>1KCZeo`W*b*7vf&xd zuw5@W(5ZuSkWmGcq3DI1WykVt-7EvfYQV6{dJzftUA3ls89#Gi;+=MGZm|f60hTI;kr@=NJcLbxJ48EBW**orcHJ+wqcbm?BC8) zh0c^}o8`7uRK*=-Ny>~e=(o7ZV;&L!j9aW)j z3`#eKy-9*3!|wSU1eFNRzN!Zl|Myb4Y&>>HEkVYi!f5>Rh$Y$VLmcj0L zw;ij9Fh*F-@LPlT5~dN-C`TD;SzavtCu#nRB@6dl2utjmYJ^qSo~txyGXK}EkKX^( z*P9<$zW-rSo})*5R)d;e9RwJ;^qxqf0Sr|MT8b4k2v+yZ&So;CSY{l#o?`+CuvKz_ zX=!Mfu}2*Q*O`ONf6=2rH;aa+A)qjhQYAJb)v!uhP(Zh)7hRxCp}GQ;vv=)MfWp=u z1#}xac7d{Kcw8a>p08xHAU8Xkq2L@nn&Y>=H|v2^u^m)Gj)Sz#o}-)PiDCt5o}ruN z(XwgzueTgVMUQH)831yCRYIn?cou*vbc>ZOhiwN1*Qv56e+Q;eeGnWy3e+i72eY%8 z;0|7K{X0>prPpkjgVGxS$fz88`>V=6hg%~3kS@RsIOJI_ihd>4k*SH-(?~B@+(D4f zh!43qAuG_)(g@iS9Z3TVOGnlNsUp^+*2zd(m_P<9x|XvWIaQAE+_Q<64X8H{!ud2K zvt0oSn=K1Me?dk(HYU9U&>^6bPDP)5R#r0EE`q<8llM%{V2B~7i>@}Cl#afe^L5dEHUbc4Cl6>wklc?9i+A_PfFfP zXL@K!H6_%6w(VH9qeGYc78^Ho1BPv&RFUbbt&vKq5HuAc8b;L`az?DG4IKoOH|Ev+ zK(1Gbub}BHpl1CB=_&{mbl62Ewat2J`2uobUI}A0QXbkiDXDY}QP_npDtQJ*tzt^9 zf3cXT;zK_kNYc$RF`-*TkSLvk9KrUySc6Ye3x25e8;TPyv`_*1Bt-F>6J0)QWgqGotd2mwpSa^DaG2pm*Khj$Pge;w#1 zb`jKoRU(EjSw+%d0JF28fQrz=h_$SnWy(cl+*61}v52y|3EtSR_LF()87_eUK%nTR zi<}ZMqX|YzmS<`TK#pTMYG(E7-4-Yy;Gn8iLmHT_AjZE%=t9FPufm|Jn|jqVlc=$J zb&KkUXWN$JVhPp|FH4wFj&|4ffA{8Ie?fNj{EGUHe#+phxHjql2^nHc&+cxSVw4qy3T}u^E_4X=2!KmmU*Z;8- zR*?dfl8y|GR$)bRy}e4Xe8(WnFBF9NHXzLV5XL~^la~<*`OV`vB=WF)KWYL+;wZ?5 zJ^n=B7#DFvqC;Rq2eQrAe;kPR26BKeGdUn?s$e?-z$!_li3*^bWlWS3x|R}sW(`@` zbQ-P1SWkDsv}LYxfm?B`X|Vv4emRsN2S)r~L4RY=L8dDTr7MojP#XAVqo~4!Sq@sd zNp~^gSdcx>(9{y@$6WWLcn^aktw z%VYD=cC4DNAyBtG2NXSrVj-Bnkx5Q;7KeAPq<1>R_0`Zz<$wvI&rZulOgNw#G65{P z$N>%_iW@WxI`%cdGBi+hkcLcGhXw{!SSJi%BBU{;&#j=kcsqq`qK^WbC_vaHqp4Yj zS4E&`K)s4P0`}RSf8$n=19Y=wIaS7;MQD=#tpW|))c|z;FkH z&bd~P>sVgFK)7OAZmxoiDvO@W=@@$m_jCn=&oTDPO;>aS<$SvE@|-ew4nsUWQi*Rx zg^I-)at4&3Zgh4(V)wg0SYu88hf4{!<{mc5_Vmxi=f0E?*zxx56(OEKLvCHrftwa$1TfMe3z}zf7}XUrGdhBZ-h#bwi<_f@bxqY zm38bob)qwo6;Sp2RK+K`ux(-8wNi?Uk3j_&mLsLe8_8Uj{np7FS$uDbwICo8Tlw)J z45ida-F1?Ff9s`4W3or71eDWp&*^xOMiqpLMe#z1o$i~WEs16tRBXko$C+!hRh&W& z7^Mv1k9mS>!+=IDfNl-h4k|(yX@h_|Z$fPW;za>bGzaD8S+rnGwh&OA>Y9=$I&9HgxrZf!LNGGz>XFY}+A#^&4NKIM4B3d})G_Q`3uxdqVkF{ulo?e`Yyu@Qwc!^-qpT-bkrU-w~zFREyrdYrT$}Xc*X|iLT@}z*M8tq@%K@fWEg&aLnj{N6ucm@g7fkDh0SXAX z4m2^DbQ*9ipy?%g`p5-!ST%r#h!iGJ`0h@~{h`2e2$;I*qB4rPIyV!<$$rk=736;w ze;b@)y8G&cWu`koW5n_8B54DDaHz=+c~T@$5KArDE|vqj(V^L_eWH0Bq8hYzUI6Hj075NU6m75OLgz0E8kLIjTg1 zy6J{n%Ld;{h6UYq1JUoIJIbo@4rd69eP*G2V*8*6?O58?PoYT6aRI$A-2;Jz}vQC1_yOIH-dm=XmX@H(CGr zp@#+a|K;=fzL@`SZGL(EUyP>>|DUv$V;7nlbToFB2B%Iv&OV|zWApg=7GK6if9D!K z#6th&bG(9#s){R&VH;GT-+7&Qe{_S%EONOjpM*&+Uxg+tBP~~`higo5ogh*6u`@zs zHTN(AmdQh}Rcxc8iuv&)`8W~X_QSPexI{DDhR!3+7rpJG>VLFp^n39%k^hWC<|qD} z+JC)q`!Angj{jMdrw#eP<*-d8e-zQ-Ol~02AV!)kE>%p)GA0*03PbBsX(GICq~xv| zavWVlUeQ9B~jaWmwWM3MPSBL{vh|!dMIS0Ccv7 zH5&k5P~w{&xzn){9tis_43Qb&AlraN1e7xspj@cTeNfOxT*)(xIymG(e}i7I3ZQM% z!K#^kh_z13yQB{SIrhU_u~kK~RZdYvwQvlG;%n$tog1NUMaQ6q z)y!x~#DcI!`~Y4F_j+L9QoPd;T>?CZwlU60!7$@UM?u6#pI4#>L1G13!n>@XuQd6N zV9Wd}!Re!ewGv)BeON%Z^*WlX_EcmscpU>+vJxffSBR3~_RYtk-axC~IZ{3T+Ii7y2x)w=() zk%KqVR1Rzjz3A~{Pj}hu#0m3}5@^^Oh-4SAh$5ixr8J44tk;k!f7A*OBZsF@@K-+R zFbXLmRus!bDi}5lYZ|iyl`gMjG4G&=jqN_@VV66PedK3pl>#hIO+!Zu9PqlKyLFX9 zaHejStofxz?Goc>JyWd42qH)E2AE`d1nKxK)2NeWaT2nsbl6kWTymJqMkrnZ>l$E~7#A1EetCpG4I4m_8v zzA39I0%kQ?O^EAEsYPW#0}P1aCu_e^xif|8Er}hPA!Hs>hh-RX1fVM3H z1*OOf0?QE4O${AxRBNRVbb9ba)9EIfXg=HgLmZX^9OODWsv*K#^qhj>AgI+rk=mzP zOS3XKGQqs6()MoXz)OzF*T^gc3O})+?G5MriJqa!C!DM4Q?fuYkXd#s3dr|T8d`*g zbe9GwlwSeRATQr}H-Dku4L6Ya zg-FW@lYwQhlo17T^i0hgSz{Z+twqI>i1Zh6WeH+w4M1vnkf>q!kl|xkQNcc9@7sED z3Y2sQyX@=_a*@M>0{HyYSYr%SMiY>udyIj+Brvlte57U0n|~T`ps86^A91W1Moy3e zn=H#f&0#n&BrlFAOE>lX;t#$3dm^rLRMRaFORG4akwQbI>VGtDML%UFn`x!TO(pEGiXcXtTdc)t zIf2O1dYbwFUCV)Gw4m|d`TV+g{P(i|e{r7n&wt8ilqMK^fDr@Y#Pddie~P3)aLC9% zo?k@CzBs8stA{}&T?M8N|3G1+P9LdpHS{szxZH!#xf)uGG*)N+oE# zmVby@MTe*xI8-DXaVv?HRW8GVo)0Jo6#1N$yxKRb%hZcx$WlkMEaI2m(?tFUN4w^+ z0yL5TMDR!RKlk>pTbBQe@w6rXO$|91K<*Tz=YIS!7r``Y106fzpdbjJ6iiqOn6seO z1EujUA`(32zpn+3i$L_ZP+uCB*_CiNo!+;Lkmg9n>M}r1tXNOjHPk9AYbPb9e;SR|8 zH*&Om4+lSm#Vu%%v%o=YnM61aDMzWNRwX6aA*$KgSq0310>o(D0LbMuRJ1gdO>m%W z@|VRW0YCz?W0wae0apep93&rBMwetJ0VD)fr{h(Zj3xnc0d1H6CIKxWj_=b%|DT4A zshj2bnE*}wzr8X4@4A8I`@a|EX+!_t$Cphf0T%(?mt`jbC?B(RQv*uQIdDKbbL9-K zz`nKX1{IcWXy5So&e5G)2bZiT0UH4Zm&hjpSbv2@h%q!Z2e!KyH1q$gU%NKq|LyDV zUC#fyC{G*mpGW8*Fd`TMIMGz^><}pttg#gTt;8?|Eao?u<{T1{vypJsz6ZQbVk4qy??82P0?9K_&fgOU+E7 zy2>g=S`v|ba*SVK6$SCjkv_vo2&q~@-3if{f0}(tjF)Bf2_FQA1=QiFSE`+0#Mo$3 zBM}pLQ)vcR;NXgXOAaecy}~wu3#*>t>VJ0ZIttq)$qy*MxS6d=_B_QX3wB-L!sl^QCe9abz2Mk+MkIaN;H6tsWnfC`yD>vnW(B z-8AAXkRufAuyquIAUqlhq|66%Idd4}rz8t09QP(C&=0|ojmIx{+6Wbxj(;P$qh@F{ zoLU|}%MUFJ7e!)qr2!IB=1e;GC6sT034>Y-fTkpv8e{DD#gK1hf$Nwp-@&!M6}abM z%!_6d+MA0Z-(oWzHsi%0+MxR!P587{=4rr-W|z46E{oH4=2%E)TR`J|0jFDN2=kd| z@`}{X#7e2xVaE)azim)9(0`(zl~fJDZ$eR7N+wZEe!s+zxVGc}vCOj7dH+wow?DT3 zn_s_t{&R7jIr)DGBW&K(J)Z5n3yAaB(s2O=V@>x0F`(z^2MRh`AXiWvwe7irc>RvJ zg2HX3xPlrxaKcTbIB=S}lOlskcPA}1SI}nY!UDw6`Wk<|SgxcAB!6Q2<4z>@t!Ycc zo?F=x@QT!q&lf2UDEfL!I-9lQN|B*xVy3q5_hQ}$xrZg`5aV*}_rM{>D#&waKE3+w zGz0`I$|)k0Dt#fyaBw~XSdgl526ja&(-Ue(#m|jZoJtg?saR~HYQ99a=kaLXp0tuNM5W$o(FTJ?J88Zzl7DRSi5x}UQJPAyB>Stf;o&qe z3sd`Ox8V-E#iSv&$uVhEv>qo5{`TBY z$!*NjHe-!0Nv9KA)mWljhxr5P!%IWLu_0qG~Y@{!eUAKEEIp5JEk?M0K~J zS7q6Hr=;jtqywJwe~xQM6xzlr2D`g1se5_G`uBk@Wh422@Y9C$W`|6SML z8;$>3w>H0Q|1ZWf7xSOn!=wzg^b06%>@($^mZ!6R#4=00z4Tt;s6Oal_d#DNX@ADP zAM3#Nr(AC@*P&B-%XhZ7yx&_Z`e2$G$Syod#7)u=;+LO9$N+3f6A+_J_Hyj5@C$8R zOQJvKEXyUhHHMm5-u>$6EnYe7K;cRa{ zrqr=0(G+z}r)21YFJ}4g{sk>i)4-}+j;KY%78_bgigPJIpn#^P5)&<8jez>n zJAuF$CYFZLlcfKv6=YQPvVUngs3Uze(f@nb_C?Nrq%{dhz(x)*bQ7r=b$|23g%f0v%XEPe z%B5iM$OO=I2WQl>?)K1s8Tc8saK!1M|B4rtau4}O{E2I3PtZ^S7NGOTeUN*FUoX*z0lDu4};OoTX06T9qS+}x*1j15bR;)9P404t>L1jp`K@v z%OYw1k8c^?ykm=6)qgtFN8|awwy%F6djIplK>zanZ;SGDflcgQFfkjp>jj5sEhB^_ zGMQnp{~Tmg!>=#s7B`ELl|sc8dc#mcY=537eoP!7M0ZP33GjdvnnipGDF&S;MXh%1?ufPfGDj_bg)iJt10qHsZ5-z)m9 zTiT*lwa!!{pqzsY!vgy( z$Iui8L{}FWHGf_IBDhS33TdW@*p5}xHG}~aI2X=6GAz(muW9{dVA$_+94XT>4`s?daGi46B~o>V*#>TTM*i4}W9?7ZH3AjzFMf8HP2@t`962>^@(%eIhsk)}U_CZ`|sg(#? zerCXy!#2BZan!Uuw|RxkOs?_M?0cuG&17c4B!8dr(8rW&S{hQZRdOf63}6>E0|>|q zKt6Gt)|vUMCt+&_Ov=I6XYbmja5qbE&GM$_QinJOiUJn5{x7*Izg&b$^o{h6y7wO7R9ziu&y#vRx>h0xZTrYy-;i zO~WI=LD=$~B5DWNwxBFJS`v^gLpd_Oc@Btdn=iTlf+$Qfr~*pNq7roGtEL(&)vap5 zyzN)}&+HVGRM2m69Ls4-#4osX@6^+_w$@s!ZLBj3zQlCuSr|a&iGV1dsh(YSpnryf z;BdBILS*x(3#N6$0La814S`RL@Gt8%WHLwLG@@@dra&!It>}b08(Q^4K%7~2hlxt@j=>Q_h03+AgqA#**IE- z<>m_4Vp%V9ewxjZ#WH&4{K%ZEQ-7MU|0aD@O6v+)RS;vHl4lrzmZbicI0ZQG&?4iO zjn zEHUY0dB%s8YYtl9)oJ`!xxz@g0nf;cWmL#4>CzYFs-kli0IG? zy?FAXV^2fD(;@NktXb59Cp0Oz*-(JRDP&S_%T^xG0ic)*oXY?&1dvJQ0&_-_mDXZ2 zXLxMXS5AH2$H=MaMI?e}EPqS!-;G%`NTvWCg^M)O%6`$C5H6%S({lA<#Q(``URAex z3Wing>FdqEzNdG6PkuuWwDp`+8|QR0m(S(b^+>|8Zo2TW?>;OdET+_USU|>NF1m}j zJj#?e=r~1ixE3-!WS@d409b|OQ8hMucvo~2mZ5jfGPi;4LJKsa+kdGzCOjC+*@=sQf)p=5^E~Lb+8gd+6Lz7LZ7v2#fVd={>(Z9X#NvwtA6@TB%v;^?&I5oe8QBUa#8TFe9;GkR*5Pi!JmC%h6p*rQbI z{!dvGrKZT1Q2h(KyF`PSr;=kB1gcp?d4R&I^5hVm+$%98VlI z8li-~zyZUywkH$N=SRd^4sej`=%|KhoRnSy&~Omc>Yzwh27gVJ^}kRMb&e-s3S$T; zJVHR*8{VK3NEUtPmH4|pB?}Y-nPs=4fP61duf9dv@qbx#JGZlcd{({A#RK@9YZE;UyTrCi7MfCl1n1UR@b!Z3E~#vagNt(0 zZkuIm>y%!%gf+Mhsa{K1$&z`}wGBU;jHw}q@gw<#{i8wj5C;*AP&WfVT*yQ3rLZCk zg%7U?{`nUFTn)e#%QG~4pZ7S<@ZMtg?e6j!q-jsItyBryx@w z+R^2FmQ6Zq*3N<-A4cS?3YkY^j&8ctHSe%+L+l3+3jKtgookyHnkX@1bo?#tBqv^m zo!!x4M1M|6F?H1qWI@TXs=mKt5?FkEKQE0%E3@A9IjqS zrVHt1EhR-z&G{U`p5&|98h)&p*!ccY$*^rdYJwuf)bCag;!M^^Vd^X_q#SIORjg^T zY)VV13MPm#vsX^3a6xyMIA&a9Y1x|4FMPg#GKqeoNP1EXFzNz_uPqSZ3M2|Fi*lhi z$A8h_7ykfxJM`;JR*A{hP_-nVX7r1s7QlRGgB}l&*(oj7iBd@1ofl4QI(M?hwKEQ9 zE|_%<@_$VRbBCYO$NmIj?lWpD6%dPJB=AsoobK|CV+<^lXBMbi9z%eK5#Ug8t4VBX zF*GfZJZeI}q|2%%+oqp%U0Fv+7^k0f{eRB!C83l_dr_#^gnp3(wEq4;d-S7;8sCUL zd*kjMZ|oue&yS9A`mqF)$Cq?cdb`D$do9qf2r-7H=D-jQ+oj)#Xr)6EG)_Ms&f`o& zACASMW3%;-U#&XN^^aZZdxnF`Z&=7hkYB`poEJd`#o{i4)U4kJ9aA^U&29P??0@%p znb=K@(iRNB`32!fTs_UPqB@pg=w^90EE5fYBMZQS<+=Q5GA{vKSf)bWkJ6oNKWaDA z)dePORMepXbc#V-te`5yQhYdRDmVh}@TjT53;=H3MuVh5-7IGS&;oJ|icl+2TuSl8 zqK$P742wqgW&l8kVbwO!Akb(nRe!fK8R;~8ldi`7l9Z8ycxbt0e(Jr)EbHdsOvZ)f zX3es8Tv(Qy$*cKwYCfl-f)34GzBlKr>(69t&oIU;LoYUkl_I-T2aq*C=2!I7(o*N> zs$pXq*6}K!mjXBl&Q{UTUw73SmS7emmlhu_?X=u62VrEos~9{y04V?nI)4tVX8_P$ z#Bzc)hE$}qGU@;epiR~Yuu1{=BJ{dDxRx&zrL1N$8Y*}ax(h6OZwxhTEaFTO6<1Wc z8Tu3=UkG=j!>$8?Zk8;k$|5&eeg!NOiRJYrygh7EV;P!7#2YK1!AzIWmNLh6g%T)) z`K62CKZW{TKq5boDUs;{Y=7t+BA&*e3rKs9!OY@0o15ZEBsym0fwXg}%19u1%w#az z{vI(P#?5$hYsJDW{aFB@3-(%uS4CnU9nhB6fYFlRJte2C0dhAxY32t-;m7GU9TPY) z(CP%CMV6}p>lP7gA&8ZnlF7hg5n;T;(oi#ShiOSrwY1=Npj5a+9e<4@sO@uf7ww`1 z!1|GfxhSx42AvS`5 zE$u6B`GAb;BP~9AC&}` zbif2Kk4UP0{CpYBZwN3lu})J<(YZ)9OgTY_Zu%Q%YXG*Y2)KF`VbZ`fH0h))liIFD zT6fqUv29_j)1#qv)-6>bDoA&56dPC#sM{4t@*a*W`aYM-C4Xmw;aHh_Dj2}yz}X4~ zZM*fVjD)*vc*sM3N|}HfM~_N-^IY+t0flt~$SnHztIp15LW9<9BN(x&syyi*GHZkW zO~WER&)D$9#J*kQn=^ruSreOxgBe-(WT>QfLzKc_8lX##;PlfrrbQ2?UX!wt=W&#u zDO7LRG{ z$SivP6(J_dpn)70hsefrQ&C||ENz5cP_6SEtTb_Dgnv{+in1nx%^^jhJijVZw8hMr z(GFIMseU18B9bjLJ>zG_pLgi6Z8?Zp(KTpgkwKTnGGH4Pk$)H>;0BPh zz(H)81iT^Ts7hp>D)Hg0LIfPdXx#wFZ8N!7r2)i zB7c-+iSX#~!)^A(+hn=PfMpu>tP1v@gB;X2iJ(XxNLT>cIv*4ZQp!>rxCl+cQyQpR z6ib2S%bY?4yOVM<5*7`X$$>ot3rr{C8O|nSFxC3i5LhL6sHcmU&QaiUoXeX)Lpt0Y zW+oQYZZlh0Xx^(SV(Hqyn&u)6lGa%ckAHeJ>|p!y3a<8xkkC$fosts7ek~h3;vSA?dcf>#t0(o zAD=gCXnQQI(_H0(5)og}tOFfm58>9kWcoUvMVwD@5t-1@EkD5$BNTVQ$h9>KVSm!S z5LjY1LbFcj7=RIsf}NTS&oy~yY|ap{aU;0H$l&XVgG$H|VrsutD(Tb#NsDP#(IZw4 zrCQ^;Q|r61)_-ADFEbMNbooDX9!9w$#0Y2kEa9KbG9#WCgKL3WKVgC{B+cvl1vr q#z6ba)%tR-#eeocn-cOaKg-YZv-~X5^Zx??0RR7b7(EF9=mr3IQNsNI delta 74579 zcmV)KK)S!Jhy|^P1&};{ds`eik~j*_-+T&f**k`Q$+}={&(x0RT^i^%r)|s+aL;d_ zo<6oJQ&puUE0vQ{fop8O`+0QBl$6R#UBH*7p51Aqlp;b>NQ#i+lA#FG-r*Exth<1- z_)mB6>-YQp=llEOzx{sS{qJDE-~ZEKzyG}d;_3ci|LLFlgT1{17yFUDCKwT9a0DsZ zf+_wLWfYTS2(I_GV4CKCKJStHLoKZ_54s<_AGabz!wjcP6unJR0w|ehA=(8nx`s)J zB5;Kk!8MHM2v9~c)CDJ#YXKht*OQ9@S$`FkwR?Crk^c%raj>`7|G4*bzndnLtt+&+ zAz375OTrF#_ry4D1!5G$)XyLmT}7Fwie?bUL*0Lr(f>Ax*aB+ee^e7$)JIWs!Kv%G=zVM~@ts^n}6+%*HIxg;Xt70LqLA>LxxlVi}uq_n5BvXp{5HLL8$0wfem39W{<0crS#{{t5@rMx*_| zK0{CUo<4v6{IC732})1~8H$FWvwzp$8wCC5LI1_&U~kxeHr)G5_vzCY&!7J#=szF! z`<*}h;%@Pi>tF2r^sWTJ+Vwwp{&a7zB>z3zfBLZg@8kCf{D>z%!ep|wH6@hE0{}4`p_mTA zr(5x-DbMP%31sL7E+nY{q$FcQFnG4V|5Oowd3eUjOHe2pf`}wf7?{Fq1o)tUDS{Eo zxM)Yf51hUX{cDah6p8k{ihml10CaxnY;Da*!uL#^Ogsa(^#~lH7%@aanxSh<<`hr{ z85+-HAv%uGm}Ce*#?UNfIGF&LfO$H}V1%|Ffj4jgMkpr%5H9u35I7fuDK=*?Pb0_? zs9Bk(lw}Ccz$ioTibD*iFqt5_^$46F|DSg!=f_82Ofn$k0B}9n&wufSF@niE`G?gR zmd$xz9)X`@GJ-KU64DpIGdMvYg&CY7hBC@)oW%%IvXrn@ndy-|-a{~3=zpKW8DHP-faqnGW`Fn^G8E)PSq3JG%K)kC))u91_&s*N| zLa33PjZ>}x!8l$Nt3nE5T`|$!@jQOWk0 zj-(D9$9$c}WPic;rP2SQkns&*%WNeE-vxM3?ApNmcU#a0&aQ93kLO&KJ|bL~HD^hE z0FnHnJ8#t=>RMbig0TS>ePkIt67+xrzVZMW%R)^YCt4B=ZZMmw^G@u99FGBD2!8wB zX1`)how(a6uctI@qnhA+{wYJ_LQv<5vQ&zNknY?k^nVzf(4NsJ0i>JnF%ER!uBBUO z9l_H^e=4Iw<;(Ib%BXXv9x;utN?+h5Q^epUys7^HHu%ER}O zUVjnBT2N3#Ng@4u_c^(Z+d6_HMJ~(X7A*7phFLhp49P3rf&{a;3l8F#+@MIxl5_|@ zPzI9-#w0->0Lj3I45cv+1@I4i)tk-vg3rHl%mtQ%Ih&${sc%jfS6j)5aU~&OQxwPx z>p)920ZD=}&L|7AxsXS=G^VCs4+fXdlz&jKr!W`fphc{nPg?~j0pkl6Cn#=!CiE6n zm2VJ4gV%*s@N;-&$+NucK#;*CA~P`P2V6CRAwTnBoK9gfpP>wg>KdPKO9^3o`^mQm zEgOPP$1`Rhxn`V9k6l8uR6507kBaIuMUi)IMiEsA+TDlhv0J{ zHdnP`4&MG$2`JU7T8JLOl&i!6N#aGo`?>{yEaD|#ArCunB=1td`O%NSXuT`Y7zF^v z8G_M5uWx=tQFx6w_nU&RoF&4IRmQ^1fTe5=9N3yJIH#)2#Okt7ql~3=A8COhYq45%;uDrPB36qF|--OKZ zyV5S){X^H{N`{(Wl6XkW!HLV3k-nT`C|+2XY#HJQOELinhEuU|CIHP+wou!nPhN3* zOi?(`Fk3v5fccq3#(|WgaDNzRnsc$h?y%PEe|r7y;?>cQ=3fV|U;C#{v@CRRbyHY8 zQ0j34+jEM>^BCOl4OZ>~iWQ|)xKqrNXdqNF4@#I#XdOQBy)`mky9!g9q2rGzJe)-o z97GY8QmHlZ**xK*7|Hk_l!@olNr_?e)2skkg;VIHKgC?@GPn+wut$R!CkTv1Mc*26 zWzPbx7Ci&d34$5?I72g%Edr^cfol>&#&r(H;*MF9OH;uJhF39}1Qh=pfkA(7e>UnA zXGe~qu5ZW5^^+V68Y_LPi-43WhoCcpncWB7xn`%H`De`N zk3-4f8tC@uFU?;K+M7)p-lcJQ5snxa_c#1Mi zA`SLT{Iw1|hG&S(nFe?%|6B*+7~*)Iq05sG3>6iHiIw0I}us=gK{Ns{;615Q0&RbW21lc5Y>EVJituqq4F`49~H z{h73O5S?mU-;!Om)(sv!6Q%9?9FinNDWkm`l3m3FMxuyuNW5eTOlt}(jlsh&t;m0d?qBI_9^z-yDe4j3Dj5iSv*>ZfaP!Ak)I6ep7y zfmD7k-nPLAu^W@{4mc! zOb=op3N0joVh7d_)HBG!X)E$flWh_Vw)x%^T>S-}c19;0v( z#^@CxSCh~XH33?a1`$htXBDQj+SjT;1q^iji;YLzUfOT4gT1HwIqz%2E7*(g;fKYj zIOE2@E<0$eZX_I6p_I^)Ev`*zVG~h557pDqGz*1M%M&_%vJ0LBA^%?#P6_BtQ5+L+ zL$WyPJo#M@wnJh*%G8`klvN-i6T56BjMWS zcm-JGb25gY7eNM_iKp|?nWmr4M-k41tg+AK?EYbbQS^on3G<#o<&N zv{4W(5;(&lNHcPcDJBU{CI-BDqNo7d#?#vlKV227WFE)6AR#4m;%HLJ#4ZS@ga~#p zU+{9I;-0%0T*ncvVR)f<1$`sdi?&28kFu;KjQy>dG+OI_r>X#)BN+W7!wkJm!WN53 zn0a|77XRD2c;$Z&!C!vHE&62M!Wl+w@{JTa_i}tp&wf3$y5;dLuJ41^8Vq!C?ldR# zMh`B1Qpn?4%lw5lDB7tz$D&l&{tm%x5x_LHM#$D0ns!ueb;~zHzHk97EV|BqJyg7| z9bL44OYZQ0q9nx;nJ1CG2`GnUTC%}6PtV$M+&PehFM;?{!SL#9)fKD(Tp)q@rmXw?Lh%(|6GO~bPqsQergrfxzT6*wyFFqgb}^4#L9vfd-! zZ=u*5RI8~K8<8SJU;h5>X}{m^2T%82Jb&?bvy+;C_=ZVAAH~~Qe3^0mJS=(mIYX(d z119Thx4)J{pq|ylzQq@icHSwT*94;n8co2(yVZ&jK+c)sKY7E3QRm(IQT3`0%WDE7peq)*HpFV;VzxBOW`Art zm*~`gg_x3a5&fWT_ms_sMzR(g22U8R6xQ)~aEzKWod^T_~I3MAZ2? zgCRPzEbLAah9&~GaE}vbtkD8YcoStAmLI}@GGLnfD76JZEv_MW+OP6WQI3GL#ydq- zv0vj=VORb4P{`b;^VtYxTq5@%$oGoePs$hTg_R<)L(t>GG+LGEBMP)A$jnasc^{1)uUxxX7W*P;WSf&!0$C< z0)OzEsglH3n5@>WGmXfqd}msrx?ArVP5ZL$GZsrPGv#;TK%+ZR??IE3+{%Zh0_KAg zjqj?c+Ka~7`quEH(b)WsG!~w(+m*)H;hTMFR#<17_NFoDZRbvNcQmiyP?K+eaCh!e zv+|aB=RP&&3@+(ZlixgllYS%hUNshDujp3uZI4g0U(MI+P@_kFO^=$jCJ;2Z)YQ<} z+NY+9z-FhK8thAY)ils>r*1Va?kc|;TLSpPo;8&_?uT9bW2J9R_2jMVTw_9R;a#)d zxUT76qiJpDU~?xdu(FFyE_p0}?_*BfFu+>qOi zkD!(PZv5{Kh6J^F&l?~8Yq{RE?Ze8>H(rV#yl*zOJ4hYNpBXnn@#R4 zr2+j;9a`LR@p-hA#$rjI78ggQQ%eca*X`C)*RKk{mWCcac(#;0Tiiij)wRVP`L@n2 z`CZdpdAF1wh}!wLI0x5%n|liTd;bPN!s#^uuxx#>D_9bAxHxy!St^Iy@&*Tff1(SW zU8~xkC{Lhe@s%#k)i>Tv4_pfyXA#xSlQ(B?&o2*7FNa37HFqSYW=IX8&=Kv9W<|q8B0rR{ zy0-HJNKu|d%e0tWgCXQE04-51nam|R>54)r?Lv_`c9Qq zkiUDc%HpWHf452p_ZRT1%$MCg`c)dNwwhz5d6DOHtn?sQ!LzaoOZj3|U6bl()%>0{ zAMbB}#_O&ux3zb>^Nd%6+g&rZD!;o{xbD{P&N%5C3>j&O*t@i3EH0}zZ_4PZ0JS!Z zK0-Ec#8~Epc1DaI2uqt06so)5j-Uj2IXi+9c*l^yv>&k5omSQaCGfi7tO3o1d1;&5 zX%uY>^{f`1e*Wj1bA)M?5kq@0`8u;9IpltSrA83>E1MV${fGG;RXYkzHWDRP{7!8o zN(19Fk|+(vl136GB$ZYYB}`wpl|*gFD$FDry7*uwQ8JS#jq<8?67JBqwUfvRxHChE zMDD;V2LXM{rYJKlw)xjn$?-sKZkEurweA{H|CBKVF%m`uTdGiPIo23jpWKTMvH9_T zevq-IS`nRV4s{RkUKB8n$<49ewU0>hgz328KyIJP50KA9NRkAZ4@&=-qC`J-3QW6z zB=JJ}S&0CK(lI*AP{?d}#r?k`NE^>8uY|&$z_jb8LY70~m4_r4Wl zlVmW?1m7>z?jeD1m&l9|Wttf|6+7L3{4(4etX!b4oINfko+Oiu_v#>ulrV}_Nj6tO z964@lI$ci*6OiGv;&UuXZJ!ZQ%DY{v7F`%dw1)SIbmFp%X|1oaMn+;ZnM3 zu#Z3TgPMw6#E(EYu5v8C&j64VWl-4fo+SPng}15aBgbG7uZ4O&$ga}inb_lh4bAKE zs?*BI!=$#F)Z;dDs%G!>;!QD5;I(6y&XsGv1?1AL*inc$RdOo`+6K!RiA+RiBq|xf zFM&+BDwXM1Cv*i;@%7Ooj$7YbtbGJZXpFs!CQKq;>JTB0w(m-~gf zm6b5{4w45}DE18T&DbqqibXUocgN5nEdX%t741cB_$gkaY~Js12tNm5C>)|ngG;UN?t8iUt!~mCER926I-wm@d>x6q+eF0$=6kk(gG3r-baQ)# zgfJoUz$DVPlb9+Q1WG`d=GGCBdR>eg>lEk5V zdA}XIQ@KFni1U`P#W$rROtZPTRs%oIqX{a{Y)hR!n4u$ zHx&q~E~TejKMV~{H=1~sDhC>(jN!3pq$7A=a*5wuu6ZbLX?m)E22Nhv%7-j53I?Q{ zGfL3Q^ z(;OcEhZz+8=#{*`reGTax{L;pW@N@UhB+11>KT*t3CndWlaz#0$J1py^#z1 znMUeWw&wa@gKk7gcZTDV%{k6UGJ?rfKHD&X@q*!yI`dwCn4u54gTHk9C9CZ`Qi15) zgT1zGuPvusZx#9Sz6aBSE%k1439|`euLxyB(1}S1<0+x6=tAHV##- zVzcJhzg%oqgI+Tp>u(a!?=?YM?~eEuL0aX>n9Fh;0}V4MVkq)8(eYG}ccY!Z4)z9} z%Js2)LQ*w=6*d?pz)R*Nb)Y*Y7-h1(u^f1p8vr+dJ>ZuxeWwrj?zmJwt(OMmD|=e^ zq~fmWTE*jfLnj{|*UQ;8ok3ppZQULD#P4+EHls1h3Y)TLG?f4zJV0TL7<8$*bVE)XiI9u6HJ{ z)z@2pLa*^Juh-#o9yIj$YOnD&e&e?0p6l)}x&zaNe6Y8tzSnwSuddUtqt)MsUTDXZ>zs=LW8e=9ow~iX1p4AOO)$)(NyByD!qJr^!<{? z-#AfTMG_SD>V`5|+xsTl{%Qr&*ercYW-F|YzFE^vt$3PSv{XKyK6}<4VQWM3r4-Vy zMkO^yr-fSDYQ&n2zuT#*_oJ*D15lx`F5T%S!|)}P*so5FwH4VGs%(uiTQT%rg|^jy zB&=;W?p1OPGQEoKS)qg~%MS2{BwS4QTtZGTZl_($n|2tU zCo!T_DLPoed<4YyaSdZG73D&W8C~mU3fU9hGnrjxLFQmggbCy!$UhoxwP>9ecLn9TEz>eFk`gGGKBQx>Q5dfc*No;%XQ=5EbdeRjK$UaCQ*8S%7Q^b z!!Pp@0{23QUchw67H-V2%jPxw5b#YkC5=tItE5x2y=caid z-|#4@I|5YA2-A>UqYOo0v@rGp>l)cXZkPbb6TE14K95BbgAvk+09HMJYadDJK$9$> z;lfd9%iJwE)+&y&Yq@76)Ix||4V-K3dBZ1VJ#oe9d1>Ci0h}01%%N20zbI@}+wU$8 z`W8&4^=7+e3ubA7-ZEP^P9;%p+^6Ne$t~A&Sr*2KYm!2OJd&XVbCC^wOtYc1zIi`S zKdA-wvh(RvzBPl6*Pyz81G?b$Hc(`DZo$i!pl^a6lWYj~W@b@b&K$tcyK9t*L}@6? za&{?6uuh}-YzDK%&~#c8!RK79h5{>KtqH!r`v?SR``9Zk^y79kpDSX>>i0o{b<1uU2A530E2#i-@((X!#jf?*GKCh z_&fNkO@oI&{0vgZAvG+r4v%2HoiRedY%ZjTnelw&W1P>g#`sCk#dn z%Xmpux03aKL5t(UeBI?emtvgo{gR?>$qd5q9Yyc2(1N~agu!?ncKGet?Drk;ci>@y z0sShOU9RsI}BMy;3o+-V>mkQ z*-vDomNS&iu=Fl`;v_ON?_#->GnH3HoEUPGr~v4bjLcK*GEijR(wUrO8YdwDs-TtX z27gS2dzErM+!6yRP2Gv??+=F8ntB`P{ZRF4V3WF4>Y8nT^j`YxdTBW0AZ1Fo`#r1c zXTQ3A{ZQ)chc@Q%7gH3+%Ui^&{|1yd_ZY;N`|P~ed+__M;;SL$5A=RmUeow0Xbeug zV3xLuuR>rvy!-G}na0kNH^*YPrdrez@93RDUzzbeSio;0V)>&-atF=H zc|z~g9JtJXXv@7N+Iv`Q(5>GLJ@8jB1GY!_Ycrv5JA5r)(6P%-4R-A+K$VCkT|kmq z`NT~hU&BzP5(gbPXQZ?19$rE-<{LaCAe@pLu~PLFegqi=V-hR3GY%n$kc|E!Tx?PH zXK~E!>R{F?0`(Alz!3=MABN(;KZDO8oHGza9nb-P!Fcb3#vrK@S7D0WcmY(9Y|ct= zQ>eW0q#>lrR&iBy#l-${Sr%oywNI}~ioi+@153Xf;f^Bi6i9Dy5{CA`j# z@Zc7IARW(bQPw1uRH6QYVum7oRoTL6zKTF$f!LT7VL@F{bSS}ikQcr)dBL9O$}9!` zjc0Qi3nY4>j=Un2T`VYgBSS7s5ttInz=s}P&=1DW|DngrIZ?TiVz#%okS{3}slIJY z6e_{HKl$fR55If;i94>Iyl?2zaEfNI`@fWbB%8$1@Av!9_xHtr`~AN2-$8${|Kd-B z{r>a*i>Ld8{ilEG5BB?m{+~d9lSEYg=9IzgPyMxVxt;q)exJ4g=scDa-x-3A+KxC2 z1d1ITHoBURS!>$+9%#(jUW!c81`SSl1nxg;UH>$mSW!OO5uFWjL9C zi1xA^vsipk3IELIc_l7zcBBDpUS`}u^5zFp0@eY%zz51;62X`x=mQ`b_@L4P@%kU+ zX@9$`NS?E)k5r?pHmL_iq!BLoTH#OXiS~?`C|B~SRcKH$A|ytzfL#UOCi5LdAcd6P zkSsEzqi`zo2De4qj;>rqhBJ4*`O86nv?A4+L(@_xPx&u6( z*Q{qi@`30S$5qGLk=1@=9*eqv7mb^NqVJHaFIBq%ma&qTJX(tMgZ4;NoGTmNlpLH7 zd(y+61nzH7Qhax}n^Ng!z0LM?uhOMrQ2S}!S&R-(t0e2?%Ug=_kl>NNib;#U>xXc0 zN3WjKl})d>nh{bU(^qL@oQOPXd5G;!lhCH@G+KxNMWL;4Fe;8#2}98-AqxA zSlKRm@M|;c+G#l~(z8b>2w`SVj&jm3L$72Q?;&6tur6~B+||}yGk)5D(=nKB+_m$e zbPR170W5>zRi(vfj&Zpibt5vCBx!?t*cSi)hikpB_9yTEv=JNaoxZ(1zUZ=#Y=b!J z@Bj7&`~CgW{a=6o;r{OuK7K#^0M23rDL+L)3Yo~6aWj)ID;R(J^eF&%Tm--E{wi;g zrJ`p09CuzD&Vn6qd#hU~gyjw4oK5rBT~USC5U)RGHE-6E9kA{HZe`Kf;b6Cd&HlE) zKMu}MPfmZ9en>y&&w_l!I-b#ZX%7bPV8`tHOR-INgiG2KUduCdMkoU@zC!Ur9m7#6 zMW5}%94~~ufN+1sNfyqnpM;6RDNHb(btUOPkql^~50D{9NkVtQ4FZ&9B$>nuKEQOE;yh7#)2@0uhFh(9Kr;^m=Y6;H4s)5wrd>8 zEdJLp#!+#dNfP6_vanR>ZhoRU&!QyK>|6e)=4$k>f~kKEbv;)Ygp6RU0$sTjJc+|J z5`as;9O?6mB5;kN%+U7fQyGNieSdqa1!w8wD55N%UdYhaBGm(D6`b&C$#l}Nq2!9T zM$TPM#W@nYN%u5&P`SPB((ABmkf^{Pkr~7ZCru~cmFawPGZMPB^^^M2yU8#^#;08{ z#u;UK8lQiPe2Nm&t}>&+rqMV~n#az{CU|>mMAxT$;3C-rF^F(Pu2ENV0E#JUn7Yc@ zpe?2&&2YlTp!1(JP}|FYQZdN?NjqR0Ct*B~YUXOkH%*O`Q?T(+b*D221@sO=A zZ0>{bz~QPg-HMtr;iYBXJh8qt=^vN7Uy+(SR$YIXTh88QZdLAKy>&^z1Tjf&zBgy{ zMA0nOPjG&GbaL_j?BL?!A8*f(UOwKwnvYP(V$oK`)DMEfy{(FLdklmW+oicpitIiJ z2>4%060Y66?0o7*kU^QJGtdOycED$0VgGy|1VMyC5+QrqdB0RzFMd9W?%8Lqn3h2o zoX>v~0F7@ciHdWQv&ozy>Fz6|ddPv%{mwz7yCD?KRBVBc^;4;B4uxClCaDIXEkT*M>!X#ks}C^9Y># zq8%cWeE z)p5=!j?@L8${Nnk`8lhQ6X?($&sK-tPVGVGULF=#Mb*2sxJgtpjn*el-yR*mKRI(0 ziG)OmwmkK19RV{mqrdfk?@|WYoOWRpWn8fnW$KUH&Q6Jhv$yA$4iT%Mrzw95#bGV* z>Ad>49eue+Tl0`4(OUM8)nM_{@NrJHE0%o4>$~7{i*@Yl)HduRUC2%tn85{L@CpG4 z#^^@-k>}>@CS-7OrlQy6cSzm*)$1QJiRu&q$v0xv55W^lyS)xu^2AN+S$<+IhKu9# zUr!D_>!CI3_5xK<)cf>_OX+_ZOeTn*sS)}J^zt!d1nPXWpf8Wru3#WJwVhkNsBDfc zdel@0qJk5i>7u|lh-yM9f zlUx?bTAY8rceIDoZ*~3U4}T(7Gt|R*SbZL@%x_=(jI4Ne_~yCWb3%XC?UievkE?S) z<75n*r)!Dx@;jMuzcOzr_ImWC0xa@moD&hi^Ab*|+zWg)h3NofNcKq8`_eWzU-IYL zf4!fgI7J!lvNYZljt2X${)@8x*Yg)I9_+vFfzGez3_LcS4-4B(3ZCNb7?Ns&4 z%4fZHw=8I1L9aGEYkshI(oe@HLOMAFrVm8@2vh`PTYCs9;I4l*1}e~p47F3W@Qlzf z>n}S4*xJ)}B*M#p69G&|MNt7>fDj>TcS0jNjP6(OhpksAo`JpYU;yYm6| z%usa6RfyqBk@e{97<9!vDdQ{o?q5{v%wYPPbesEKgwTH<3$@}_Km3D0Eb$?4%hk^= z=twQ00BJncnYFuS6~E=FQjbVxpOaQBCGRHfts$4mN#*x8kse#lgtuY2_fCIp7}XtG z9#&P?mxt7HkQ$-tZRla1|3LFxb@afLA3hltPGu?n6=fWyxSCUM)-t+Uw|w+CZ`yg| zPL36i0Yz%FYm^<5Sqd`*I)8sT=HdtF zrbfdPS0d$7X1!evt>Pd-WF)3G3QyvBEIPc*=Z`&Wgy%XH^50 zmg;B_O+z)Cr3c_Cy=|dh|+@J2Wi<`#_Uw zG&Kf@DZ|O+Fq5S;bqs41NwY@NE2qWaoGFtgH7E{rAJuHXE2j;wza0~DHIrO5C4Zjp zM=10UnNqJ4!oaq@e$|bUJvKY$BCf6328CdV0(9VkZB?n>K{J>{2XQ)ur}G&Y^qbiO z98OVq#pz;Glpz`LTRx@A2;eG|j=X0DRl8y71vYRWVAUp|qr7*sytezovr0?nUVar2 z_6vqzKq0df#|XeU&coFMoQTUnFyP z`M8c>V790{nXL`sC=~^5pI5@Sh3afb&M5#jLbg9e=;7PO4zC zd6+w~kp{pSPs%9xNPnui)Tl}7tv9nGO25jyp2wW9ydBz2uDvYWc}-A-CxsCM za;K)6?QmhtqFGIh{7K^Jf=sfEqOKebJrvNPfYT}idYJgSI&us}%s)cgK_I>vWiLA) zKYsk!*(ptqBYBm4Mz-a#*~;@o9L`k(@lLpOimyOp;k;V(7tBb6^j9mDdL2WNG;X{k zDhQ4PVHc!&Fk<0(Gj)AHIZy#Yjfxe>^QBRB*X_IX11b-h{`WfeAFln+2v0^Zne--* zp&Pj9F5ql!JD_^|pZ?(a{=l*SdA|2z?~~LwB?7K+llwP-1pBhxCzF3TP=7o;ll(`h zPPP+(&JP{qf$)ykf7SjkiJqsE3`S_pQ=no0e?HiI?(F|Bo<4uD|GbxQYPb$-l3<2Ty=&Z&5(v${vO;QJei8X&w)PLkMiIf4xV=Z+U=WB$#u3zD=>Kg zdLx|l=+r3zyJPUfK5?S3f!(~l8fFZs|Htll1ms-I3=KSVI0>$ zOf!nWJngyxu^}Oman}KLN-GW{kI5OiFqkeod1h$hpf&IDh-~aE-wits4g2 z*Yt=aNIt)+g$*b}Deam%>mS;q^4t1V>HpU_V{?9BOIPBxE&v+z|GoZ;Jy-vK@c+E0 z-#y&_3aeZtPX8*|N{R4QlJ&#w@0Y&)t-pJ{(~IAYUi+$xS#_i9J~8Ciu4Q$=#3`y3 z&RL&60ni1X!N2B&A%9QLS(r+6GpR8wv8^jQ`$#?)je^#BSu}SN;6j-IoEO}E&p8ifICGgd+Y@EHKgZ(V8Yk$*)Uv5_bCF;Y6aWZT!J zr%@L;OXF*8XeF{+f^8uE(PjQMKfq2%5{5pq4tNZ9s;H?tRwbl^x&w6+q?!mC=ryR- ztWdZZ48i9>^yv|JM^P5gd78!;ML?plT^EMcb8%?7IBaf8Y`DwK4DZx&5&<&y_GSyH z1lsmML^$)D)_+Dm(XMdx$uZc&rc!b@51WB{v*YFkyzIdFiH$JjYQ~|8K@4mwXVW>j zwtgnOkMax^>T(oxI#rbTX4E&(g0rPTW!;qOI#qK@V|a~%B2mo(QSV$UI4vgIq-wLX z?T5VPbZelk=ewc7Mkd@l+U5P%pTi+9E%8OC$7ZP{WPgN{2=ql9xBiwE=DpER^PBcF zLwL_k7iTK3sIR4D+Y7{&iR~LCBtk*I+q(V~!6-(QuATs_UCh^Voqx?qHlLM-BqBFS z0LKhv!3@VSrYIzwLD~#asR9Rfz+t^HLAfZ$5Xa;iWdXx8MCSg9Y{aFZTq+;_?o<4oZ|9UUK^64r#;7HoIEBgq~8CDQ-p_x{11U}> z?=u7=oFGcy$0UStmrjd!o&OM~w=$0|FZk^@5RBdY67PRHd3_9i{~i4K&lP#WJCC>j z20D*FdD`7}cH{-B+4Au9$@_zMm#1W>Zv#z8F!eg+Vqj)*k$v*&aa`y7^;J-lrwf|r0 zlO7!%L~h%l#RegBF%JGKFEDBr;9NkGavM?+Pb+^oyGqDSlHX1=KS2H`m4E-&*##$O zyMne|@VKvgD6u-7ytR445jpimOxwNa&B4Xx@pL;I8s{MFkF z>ugTl&Rd&N%YE$+vsHaT>GOe^ADH{{5Q<*oWd6}2TabK^EI8G|W?5vZgt3YT_Ko#W z#wW|?>q)4eU!Uj_ndl(@QzQ>K!dYHW#5(&`z&eZ}o;_(}a#?ZyZzS%6{xzKc`+Iw( z_y56*{*#nKPd}Q#=tmgCB;@@N4bex2vINGL861yssH419gE6a=T8Tv_-}*$lbS;yE4@Iz zNb?U0$HVPn^X;OY1jIPHRy*RJ7pG~v300@^>1JH%{94&OjUYo8ljTE3e?Ki1UQD+V z*+l7lRz#z-j*xAc`~PwGQZZonM@Z2bWK+;_0@!gK27Cr|3iqBpr$wlciV4XPOTU)( zSiNpjb;xr}^0}S1N2MC9giBl_FM&$tQEoGk-gW1>Y1!c7YjYOd%?iAee)++#(lIl; zf<=>Dd~S+^%0taRuTw(Ve?g2PMMme1!q(?}-SnDBtUwap5hzV;B}ck1F(q3uYFCh* zAv4UHfq{;K)&ZaO@!F1DUkVJ58CbcR6(7E$(-|g$$QV*;#v>MwjrJ$+LuaYIB?~Vx z{BS(R31$o9$WSF4VVN9!OMbB|)N@J-(>W3y)RL!~U}-f$bL!Y4fAw!y3fftQMEcKM zj_H7oR#+-XAM`DwKE6XRykY7Lh-*`rkO;LVk5_J>&x9w5Qx{uT!XmP<@)cSruAyzJ z%bHc)Ysu{#?uF7f>|3{s+IzJnx!yvvv7M5U7-jAOXB2LPbQ8(OC@-hBHt3hRqA%Pk z8|h6M@#gw8g&8`_e@KYr4r~O#7pI5sv-dK&9!^_o!YPX8G0N=2#47e;x7sxyA`E3S z74ZD$42I|oWmufKB#EdGL2ZKqZe!je!y;Q{D)OAg;!7z#ODq z$9RmwMHr)3gj_k6=J~gcu(5-wYP;VnQ|(CBH6dvIMll|^jx{CIMCdhq7t{n7D{?|!yw0GV%J?JrpZvjymgT<@SG zjQcvy<`JRMe|+NKHwt{xS?2us?Dfgv!R5)@)Aw)Q9v%A;I~Qmsn1k1^-~QwM@td>D z|H=J*nyF7n2Xq#um<8u-ny>8&(j6|dnzX1or|1k)dPA~E*hkinjOF&^?@`BM5BWqU z??R|bjGQWbof2_nhO8pMhx@0D%!bYfu?uF1{el)Mf4`>tt4wqw8wi2m7x2X%t!yh^6(ET z==X3*e>6RV8JtnRnIx8wTS?K;tM_LI=Lc^tmL}}zl|;7W@@n2?HqF5`)RZLz5k&Sl zx&9SqrR{hFQi27(rL<5l;gk(0O&o`B>b}Z*)RH(*-piZE>hMi@R&#T3@9v*es9W_= zSDs8?UpbNTxLBD&KiJ9%D-{|RWCcxroer2fe_)l}l{e&m-56;v$+L`%kpG;qs@SxO zyD%6Zp%^Y|G+Y~rr;$5=X_L-uLrnb|v-~{*WSvz|UR}_oaVG?K3-0co;O_435Zn*$ z7TgKJ-Cf=w!QGwU4#Ayw_-6j8nyR_&>vQ(rPp{RhoiJg{UwuC(n+LQ1E@7SFm%O-B zC^aXMBAb}zGK#=VDYGLH9sIjx&fSMlbd3WwQxo{y~hWwpzj*JCz#$o%bIB5)gcCds{R`#A9O+DMca^42zZaK|1NS;{(o`#aQ zf=;i4lpia0nCcs{Wo%Oa#8xBk^In|wP8V#gwRCK{`L((0jfoSR8Cv#jT|{d@IYfck z+De~>Yt6(`cM&+%dKQ!TTaAPGJskAaKUJYt(*yMOv*mJG^fiSQ)}54ev%VLonKT+0 zf$p`t@+Yya0wMPN_TOpt!kGDf!Bv&^@wejL!-|hxEPLXOS)XDUz~EO&E(izdTovA^ zWDi#8V!Nwy8`^#z(87X^Y)=oij96jB#^II=l4LydHfhk&g&uzEc>NQGR29M=KExY} z(hOL*%J4WHwM-ihd5d~v_w1)c7{zgQ{NmTPLsgelwcwePWpMM|(T2h2x`QdBhx@y8 zJj@1~nN9=58g!Z8l8OkNUf+r#FW^Xw)4T@$8QudP+Jp%j>eV#ZtsP3gFFnX8-frOQ z{kn+1!qFR_^OA`VP~6Z|fYK9H?&+q6Zh%K5CXZgT-halA4dZb+hiH3pCe0U1ArYtZ#lw?+7pd*~U(mEq8YX7V`BC@CN*t zSyKKmy%HPfYwfP>3Hgm#;bzB%V9S(s${QUx*7(^6U!SiV!TW|BxH@oc6wZ5@jSh83 zK8_*WZv9kW`O2v_b;J9$;AXxKF`F5+WhJGu&+p`Wu(Eiuxlecleu?^WC#sPy_u-Ob zSi_yS4p&8ms>6O)1D)bN1)?IWz&LKn2>v?Q~3crxO0O+lkX zU~w+-bdakg|NaeoPEs}u%;8_?cu`g`D;D?--w$p(Cx{H{!?o~XTIiR3AOtjOo8UIF zDI~r3idL=7E0c}BpL&vF&R2Q048ig9b==EZ+njV^Rf~>?kAEJ+(@F|F`ECFD<^Hr& z&OVK`BEIUE*6RR*c{8_O3)FHzzGesWk(>Un)$=*#UEL5XI3mUDmKviSZ5m z0e%E->*Ol3+9nrS2cECd+K7NYd5`wAMfy^Ta&IJ;YDcLoVSA^#aTp^E)26Nq1x~h` z(JkD97oyVRPU+$(Aw~iD5y+}9qT?-I<8;J7%u;6wvPcqjkXF>45S5a zM^ogF>W&s7l-`vsov_yK(9^+FZq~Zfe9HN^`|*?H#(i*RNl|?t2Xf#Dt1HAD)aV2j z)eeQC=zE2+$Dhyx9=gWG?aju+u`Mn+g4+i%jdUpqVdLq&7Uqk#E=u)g#-++ z$YWCS_=?nDupI34H${OK?wGKyVa%_^&@DQ;>{YSna-Bau(+-k({c?x;i#WgAI$IX3F5z#Zky(!j5!lBb$s&0;Dmm8t=sWeosjJzZ(^T{wsNMMV`X)>FISmu1~HFXC(g8M`8kDh34 zzdHp4_W(HH`K+A~{PJh6yZ75G=;hI$9{xAoAFzkf7&i%-pcQx6wqD%&;l0^d;|&nT z_Bw7w>=}Le#m@^MB+ACi)Qo&@BmYw=IfTMY(zYFDM_7$#)rEA>fj*S})4jBPp+RLh zJ?JK^v(Yj3y7>G2P-+zdydz;u3UsiRib({V5=Wo3^bUEOprD$CWt;Ox*YB1f-esfO z3|%^KHOu`zi2BLt@=s4T_*@5k9P;W(3bIr?yi*1Ftw8}Bo@7HC1&~PS^y@a}(%TRsYdO^|v^OhRDHVtn!AZ zp;~!YZ9gNf4wlZPHUoc z>Ni+qL zZc$B(nWU!v@XGSLF6r6)i~VQGTR80=tY0&7z_vQBGF=D0JWss@@-KwWzz^3qA7MAt zqT@PyIgQd`<-cPoGk&1ZBs)s8ix0rfjiDk;GLoGV6JUSo`etQnB`EuvnWWp?Yye26 z2{cyuTkgVZ!@jXbvu@3qbj_}4=GQeqYJ^4fsw&;1(OmP>T%%gfmDucdcAxyFq_~;) zrl>KDbDl+sQn3zLgck5*zo)(YV_t2>}Kjy4Wr?{gl zl$?($X}a!f*fD7~)aTN*mHpMwJ}-GY2X%ej+bw%-b^4GM=UIy4-F%T!gBnZX*jexr zs?k^Q>F?p7HcBaN*RLBL7PKoXVxcwDtH2=x;`z!KiXv(8kaH|RA@pbe9nL@eX}Wda z`=VhlUFoU?IhBvBu zJCC$sA2s+b;Vc`ilg3!k!5nWRPjnk%h) zApP}<#T>^OTq%&{?&sxuP184%h?tTYS;8?&Xud6{)`ygpQHL2bi)k|5QvEy0E{=}r zT%T7I|Oa7r<{LanoU+By+kgd%vC7{3oQ}``OIZe#I7}JcB ziY=3od7VD{SPB0I&X?drqSX&& z^N|=%-NjA;)=+o^%D6MS#LSl6BykcxWyY;sL*hMveZ-%?v75 zJz6c*Y5e{Sf?W#F9|&;=$@Eqt0>IwW)yipdf5=#JYw6`ymr#W?q0C2L-u7n~Ut61? zFaSO||6_r=@1So{9P)kovc<9BQnB-W?0s#Gx%*S+pkgISUcxZSPEmlHI%sk;&!|Vl z{{c7{s<>^oK(jf;?l7VLWC#j)Nq87?nq&r-a_dx2Kp-9mPWE9LRf~6F^X4||rgtuB zH9HK-3EVg;e4SNP(DfC_moEJyxIruoroMhFA*dnVasv5oR=0n^YwZ66ucoQdu=I-+ zhEkT%X&y06?gy5N_*<0(JV1GpwA-R-HhbcK^je%mvP6YbOAO7?=;}M3Enj~I3Gm<- zDmNvUG!w_XZa<|YGH++Rq z!~Q7i@>ZD~gjaQJvKzLg8d;6oEu;yePU`1r&iBtuRdzAhoY9K~mbSC6*AHa6yCOtY z-Kmt(Jnrc3Xp)fTb(;C(0@_mNTI3DgA9f&98Y_61<2)V^mT1LN@+{2v6c}LxHU5-n z>i_L~MEK*Z;)!WycGcuE#OlzsUN2ViUP=69<`q7ilR0gSg-Rg0TCJbq#ypE_pvWO! zN*S*^eZ>7;>_eIc4)Jy2iq-~#B89Wcvp6xm)qxRj#XhUQbBPuOKF=4$yqR4~l-&s* zQ#%i=QJZ$D)~oAb9VYL4GU{oK&pGVuz7BmAW^4SIc%)?$`tTpgIBh20EAEU1X=?Z*qv`=T>~9#%c~P1 z+t$5y@f#~=kD+L4op!qmaee4;YmgV!Omg+|MpK&IH|j6-(^NjJ@PwD%!Y{K?he{iF zPXl5G4XX!+(Y3TlpIx2O2xt4aLp;Qo0W0Nfl$K10&1r{TT<{vDp_fZSEmu(C_;JhJNy=IBg9J4UObKg}E8RhET_+7Y;F{QgX zlt1;!b@x9(^K)!(ax~#C&EJPDFmfH8Y);xyp%+};Wu%et<|lG!>^cvk&u03%w&*37 zROTuEwy`vst`vt)&`+H3!JGf`2XlK^X7l(vh%5oY^5u%hU(=JoYyS`5)@8v zZQnt9jdzTzymGk4=-MxgP#Elurkvj}XK^Lf6y^~Fo+KF)KA+~^1{Y{fV~xh~l+dlm z2=>I@zM&$eO*H5@)&@~v@h`m+)<4ZTXDhtX$DWeVAV{bqm0Hneo5+Sq?ENd=FLOTE zq-|$>|fukX&7sFItdOR$CTTIQ@a+l{oS#h>G`vk6U=w4 zL9wF(P*GCA*r-&-X{uP}@888B;l*VQHeB=BVoZzdn<%$HQs6T7kHFY3P3w&GuL$z} zyrdodJ^AVAHy=grbvwS|hyqlw>pw^-vJ3z(8vKqT9O67F`Z?&+QJ`_xL&5PT`JFz$ zIw+MO@{}_Fg!xH=dTN$*E}w&4sr^@-4;no)aCTvql+`?azbr~4wPZ-aG?AD73p;Wp zG1nG|B#cg^#eIuH7i*D4{|OtpXwH- zTRsvDSqFbf2ux$iAwSZ(`Ss=CLcW9;hLBTVD^W{VptyyQT%roLhSZ4hr~%m?kS#MF zAjsTMD~`i5q)#01B4Vn@<9Ct6_yEtppBKEMB9Z8LUqy~<@bRE5$NV8$zu)UXb@bi?LbCh6JJ|PR7x|t2SY_gADFq@wb!p1xCtLzo& zNJ&Ev7O3QvO1><|3gA%B1AeqC4i4$~hEW2_KFBrz9_5Pz7=q%ZPeba2q;0v_@~ z&L1lI)II4nXk+a1eG*Jcr6m*z35c@=4oKrOotXI`Q1*|nq?kW$L76|Cur$St;6Q{g zw{fOVKOF%ov`%PH##E%L=$~6fyPM4=ng%Yfn%o`$pltchdHxbS1^2>ozwv6sLUIjk zOig81oGOEyIK$VB-WSeH;K2a3r}GF*e%chy50E`y)E7#)C+F-$1ovaNGR7v7Hz|`j zDx{78_*T3Ggaz`Ziqiq}S^Z;zLEfao*#&FNzRkjf4EASX*(2YSI{W%=XyN^b+D2H# zk5eQMV^sWKEX1Y#K56R95J>Fs>K=woxGHg}=;zJj!d36g>26HS11>Oh2+AWO@%(MY zI--ok|M47EB06z^KXZG%Am?F~6C@KA|BPMBb)q9L2;}BKvcuU&(@D#4!Vq*gI0r2Y z%88o1+Vdt1PaBiCsY&u4#;DsInsL~r>a*|iw@V@vdT z<;}84EAc;!qhlr~HQTwizu5wc)PYXeziJQ+*1xw5gZ~QM_*UJgB=Dz8zIB>pa6iuI zl4aGm`I1G`Rh*`q{wNl(tgAa(K_YGxZ4%vG+q}Xvehv_qjy1jx2(lL5m7H&gw_3jg zzQ2>um|YvqP zld&<+vU>8;cqfnr}oL0V8v|n}YkVTNnaBJ&^Nve z9-|xmwlZAAj3I0^#ead+7Nl)&wQ4yUPjXlGFL`%^kbGOe`SUP4C5+b$QX})@_X08{ zbm{51%{$mpJfkbI?2kZFNdziUZIPcxYb!A*!oJH1J->Q4&hpgx2kf}NfaI^GZ@LXH zS`gR8i^7JYjJQ820R zC1|synh7Znbce<3av7CtC(|-lRDGd1<(}Jg$0;KCeYN|cs2iQ~D@H3_a5lubHBY9K zp_!p6i7AOip1E)pY#O2~aO~T!|6Av|_F{HM(HYh!4ETNtZ54=!;ARh|L;bzS~nw9Q4~v*ezvacTq~)@*+JP69}~j z>-DhMd74HhfkUwb|9}#Xs(xZTbV6u>79dh{0!|a6LayDJ+v$9t;}s@x#2|l`Oc8C| z`Ix0b4KE9DUk#090aI8V6?CAde2~pxL2UjsJiBzXg^7&oNcHD*n_wW<+-%S}$Wkj{yFCY#LU3 zlpH|>`ztPmNshT9Wx4|-7!M`j&HdkLE$IE^R{woR1P=5LJd>hc0&i2jAH~ue$V7Mt zR&V(Z$^P=Sw~DQ|RrkLdZDKTM4tOAqn0+8M zDB|`O!8n=$)E$2lNp}Z2Cjt^-FSV;;Puqi?U+v2u@L7@*$N-nxs)!Hw+TrLJ^z!F> zdKZm8TO#n~i>YG5i0@aYn&Iv(cbjR5<}aPTN|fZ^R_bnUhX$>1`3! z1+P^`d*8I!=Fx^DNYLwLSGNo%(9^-^b^iS4J^R@x-Azk&Bn@D%M8LB24AfihN)#ZX z?(5VuUQ|R(F9^OY4DN3Y#?&BLT0A7OPb0Y40_t(H3-s+; zN1A|V*gHuViQ)>ol}#t*9|1dDwh#*@qT&M?pslE{pNv`_ z0*822#DB}hcuohKBl^`t`+i@DonsA@nHIO<~A>bwBjSkp{@WRv(SP$y9xFXs^FJqye6md&$~HLugOrJ>=GO_HF0Y)NH&7 zsF9qwiD|xo&=M%-QiEO2QHxZgrDz7Q31f_WU^=j=I}F<8uxfk~dVQN;#8FRY78ClW zlB;%=xA!#{UE;0x0TsN#!^nDH+?c+^bAP62;5o8%DRTXFr6Q0i-^NqOS8PhC4RzSC z4i7g-dcJuwnQ7vWU1qR131+J0m0kot_ISCkip>zZ8wk7 z<4}u@p{bWt70_4uRH>$vvBGOR2$cYzZZFgSzUIW7uhFbu6RW#1=`4d#ADg{mktNfk z>_MBH%W0RZLzwF zP}cAZp_Xq7qd_R!=UY-$eiPiV;L1dqI=OhEc^q6YU(Hhv(memMY}p*6ZlAig==d2O zV&8E}P!Qv`7)TGBIpL(-z=XF`nm4qxG&)1~Xc`~IFuPLa@cZNP!y)e~N6J0=DHCX{FWGVJ=nT%Q+ zv$9h(S;YP42q{nK0Q8$wa-72sVGGg%ZFS!JPX&AN^U~}v$$99xs<~^wc|05y zk;&+vk)v9j@lnoW0o97^dz+&zKX+)_(?l%O;t9C_Dy66upZl*R%Iu~!Sg*4|gRwJ$ zM11GzR^0cF^65BDZz<}@^LVGGXr&t=b1XH@&p%Iu{}A>LJ;>*?@Sy@Tq;#x0z$R)u zfs{yuXqUiVUf2JUxosQ)rHd00zm%cch2XKyftu- zpf$$nAkP2Nl!^de+sR^evrJ&6ldERNr=TC}d|<74gjC*NrBv(=Soa^a`9~aQEvS+l z)N+<%Zy;5=aaoMeeh)^3#nj7GFW)<5@#Qz0Sj$_ zQdv&uRW8zAHAlf;Tt=35c~kxEjwXdh#O`BMI#ZtYtWE+DFZZ44h2rH|wdC00ska=t5eI?jN zTJ|d^b_j{$=C*f20lGZ>EeN&zJ@XAxDr}xBWj=biSIE0(@#eB5^-X>&d}yA~T>_&Q z#<()0*3N@w+p-Cshg zdOLGmCsBftX_GN*==};ARcnhjjyykr$=5Zd?0h9$l6N+y-VV#|03GTz`N1WeC+uZ8 zp!Sg|p&EPh4)dj<0|E7vButH4NAb%&#i7=(<$<0xRQ~kvib61rMw=XpX9$C{g7Zgs z#^D>kpsoREB4^cugN~Pr5GEv|a|M;7kAF?s*i}C=M+)iiCbD9}QfW>H5qlw-xZb1U zvYHyTF2!;^J0<;hI_6j0Yr5Csn6+A6Ivk_)A@R}cji*!G(y6H}VejXSDG{umX$=R? zR2j1@W*My#Ta^xFo)Wz;r62{hA7@5P zawoR90dh!&>%e7WGaC)Pe89410c?Z%O2Szl(_tT2hG)_K$yh01pm$NwsIvTMQl)L7 zJ;3Gp`Sv{d=04re;L&5^9SeZM%pY6=O*gp!7vlRycs~_c3@xFvGqr|x&I$L=ym#&9 z^R>LXPf}-0|4im-d7?WAPTB0VTkP;>cC^pI!5BjRbZS77?n>)=FlNAeds}qW-7nZ> z$%5X;U5{co(jvNfrK!y&il{pG40t{?O-m%o}Ucei?MPvQm|g#qu)8TG$1_5Ps0YfI+PIB8rjSw9@&)4(Z9@TfAxPAfn+ z(ju)=wd&;8feMxo$LD=(L$B$&%KEK;L#tPJC>V2kaU5)0-Bh2*c^EwUR2QZ@xh7yL z@vSuvtz`xsdx43mRBe8_s()|S88WpgpbRy`PeN(1TKDww8t>_p>K5L`)M#!IIW@v;6V!>? zZ(e^hHOzjjo~YAo*lL%{IFl;Lv7i4Z^1*1LtffHnqaBYY&va_n6Tk(-Hrq~tZI}dzX&_lNkv>g%LDj_bg%&5N2CstJS%!dFJGRk9TL+%}$O?StQo?6Lnv`;~OwRU?L_of2Tm?;0>{Y29@~ zZ@dt6*wqF+_#=YqkrbR{FBWJ?E`MwV+|1+r$p=8oGq^99^fC$ne6ge3O6F_CAHI64 zw0Flbb-(X_(jxYdfBUlg=}X9jJ(iXQ({z6b=HHO7xBJcRlab0C8*zq{vShIyvon)|er%)8xlRhczee@Hf4u{xnL6R6{J?^ab#YmbL6K|STa99zT5{|`Oh&!vPe6D- zxHv``VVI25Pk*`m^cp@D_4@eC7F0e(uEp@Vs_W?l8l#^##fn=<;XI|f!iJ7|wqGBs zvwZJJpY0^xvuFNA^2JH4Ru3J`C@gYX?z(o>SySUyC%?Jk*o?}lxkfUoT9xk2(QfDr zbA-i$V34C>3&JXYMGCUl8u|1d7MT`nZFJrRG+yqiGOkr}Oc1npDxIym!X zkD@V-@e?NfgTl)5n9qI|0^U+k^xmh~eXjm_Bt^}uk z20eC*uzC9lN;zqq+NgHBqxUBkaoeKwog^Z}tn96zGQL$ZS$;~=3|t3mNhe9WZM@Ea#A$v(ilL9TU`NM&TL zr^0yWIaS`Tzgf1{D3Vg8bbFxxle7ugf^ zm_fE9?&rL|h~~`@mbX(yHV!@R; zdDX>zM`W&d3O*0qFk}!4; z+LbaAY7+pH?jFhlm0D3}@Mk{G{_=(9ig76wKl&;16c0F4a~aXuEwG??_SsFou_IeV zl!2vM#Mwv-h>~_k9=%>8NoH6Qda_`Qh#PC;Nd&#z1WD#1jQlygIp2J)HU2qYbMX%r zF>ZfjPiIH(?-hM>Uq^$vWa+a`6jxXD?l`*2Kpot!;wiZT>_wBsQDEXi*Z`j4F&|hH zB*s}6X*dK{4-w)d#>`?);|y(Zf|pM#c>4*syS*K`DSeZ0W-#N-11H0yk!YNW3?=k* zb%I4kof5iK@&4idpxWvQcux;{X5mvC8d!gU#Ag}t%s?!d^HzI%ZS{AT-A?@K?<>qp zRzSu{&DjQ&T!q4Zw3U7FiiHc3`Ji2sm6yEpbL8&W@?~)t-eLKa+)|^p26{5`j@iwcWIaq@L{=m(7PGYD69g^ zZ#E-p#<)ku9gdkxx4ckOj2Y)%)m+m(@Ec&vO=$r%DoextrK_m_d5pcSrY~|G8xQME z9rA9|MQOvEEhn~@Q_L8PsDLkn4}qq}&`ee#L!Hq$X*)ot^j$2aN`fNE+@=o}Gn9c_ zMvTOn`u7BTEVT0)C8r_AkAK?#)W`exlo3q@vF&?Jy`{ZmkK70($z6=isGaa)#{RnT z`}*zyca7kyJ&jThf;h5(f5^XJV1AB-!a>eNu`znXbN8t7Rnq+1ENze&gf>h$iiPp99}SOYokyg>`UhH#jkH3S(- zKxzJ89m&?4+f@Z`2<86AD7R>hkPG*rK6zkFpafFN6g1q;3~e|1Q+n>?mUlQ7HeALJ3ku5!MCsQIg)+@Z1C(B_H{oi=1dzhp^OMx~dcBmZ=U(FMXqLrjX;V;BMzX0Bqw-UBk<1!?~4gCd&J-;nq3;IcUiTu>tA z{!&5G5LRJG_AlD@uTPAhv&K%t3A&&I7~>((u+m? z+5$>n7Wouu{F{qx3w~qIDJnWI%_0t zSP-y-mA=xWcK+CfzR-k0C2A7YWHoZ^>H;990<3JX-~0K%etmP>`4SXR^Jw6waR0<5H^*um982c2$SvsXvy?+tVGL+d%t>0CI}dyB z43)(FD_cdtRrubeTgu%K*fnprlQ&`aYK@J9T|i3L#M&JZ`c#t$sc$(;mpTIETvm?^n}z@e9&f8#&;Ca6+CO1 z5gMcHf;Y?)>%Ac;A5==95%I%~+ogvEjp8`=EFwmN`j|IZBn;3LDNpX*34|35CB0L6 z9_kK^`$q5(pWt&GB1PeuAs7+m$$i2l!#X50XFplW($*!NXlp6fM+14X@>F+p8OM>-_B%FfPXB)$cIscA<`I5lp3 z!9&V*!|^-FnjgrFND5NlU73T5Z`-;bvBA0`#4+xXW22d$aI|Jcp(ra~Nlmu(=T|azgc7e22heOI_Qzaq*7` zy7l*myx0x{D_*OF&9JZGS15EcSDVm3&@W7cHDa5d7FmH6XK#Kh9t+5mHLWAL=y3&N zM#W8RiLLSck4td@R#-Dsr-Z!I5;C*IPX)4eqhtQJ>ZI;2GfB{ZMA(yRknm?R6b^zi z>~A_+)p~x!C4z85H(UzeM7c>BVZW5O6XeWg%G|Tl^Hi)AawIFjwc3m{rWm(ZV7P0T zD)dCLnd1UwHFBBCg~B!hUkx&bs;AF(J~P2)wWvSf1h|``*LZ;HR)rgo<^=7Q4Z9uM z#YoMw_)d;4=j*=twDsuZ_w^^qE8D8ZyLzpm0O}JplSYdQ@71P znyE;*=jbib33W8`+PR~H#<2 zoYk<65R^#GJ!^kb7nX!x&w~VgFW}XZ13q^$wEjpAAL*<8Tcfi;V4N+Jh+Gs=Uk-iU zkVFgEA|q%)=?q_OijUu!z}bcGh0>sC&l01%Q%ws$o@BGTmId8v%GdlO%L17Fy1sp` z>~h0Q%v-G^i^$(~#VEs#mI@s$u$7B(c6#+yl0=Jt+(hgWLyJ4o3}gGLSAF!Z_y_X-HAR|@}&3hly*K| zF(-K592*)ud(V4y$T>UJC!wxwsLS$;@aD~RQyg(a&iZz}mHL({*Muc+?izS@cp@C= zG8_wSx|jO4igH&Km7aA=ogW=rDv8G{ih0a8-sJHibQp&RT}h(d__; zzpkJZDP%4u^hwZmuk+cOUZbo&7Edsq%;jX95Ou=MQo7!*?|7L>u3=8q^T-@z&QLRjXtPO^Rqx4rJNZ(e*M+JTUdP=d?9@Imq4wVd{0%VX1(ghThlutHHlIWZ6xCtsw2A z_oJ^D(g`Ap{1y}YfhafTO>k=@2!1JKkK0%uvM6IN#h^(4yD2xMs6@#3@}4g#)<$bE zpeamLZNQg6VvuFC9sgSbt9p*+0*s;I$gz49w_M%h%dObu2rL>If`q>$#$%1rBsnt= z**51A;i;1(B^Hcu1%cO-`Y#*6Q_=OC`Au)od725uPl93X@b0zX+ivdzSkDMvIFKbqk>;#9eYw`zA;XF|O>1ByzVrx18n+7If<<~=>xeoW zevT7`0XgMW<(0{LFKc=^LggosGi7VCfii!P8rw&g%}9g(^5dp*)$V)q?`D=yzhjgC zQ+KUq7KJU<^4MeL=5q|`4bThmrCUp+gcN(^rx9?NKJsRG4Q!L8v5+D&UC+!rVpZP; zFi6hQtK*nr6+pbrzq)|6ZsEjboiQfusN{~}6C?~Q7-pi5A7kI7Hv?9>zHvHu){|H> zRcgYha;=hwRz8i`hG8ben&mX-AR*m#ST}iUb=@PX3zTp3Yth2XQoWwIizW6;FyVb6 z4u6QlUt~3dESN?15(pdfWha19pCt%r(50JhOhS_W5$BKu-@gpldM!wNidQ83)*hVi z7F0E0oIz6ITMD95b}Y1sTYbygzsP!KpbBU}q6|RpsTTg9W=b|3yt?^I z8{+zuv`>>khk_f2SVH+&PVTy}Z#u?kvIU}n3K4^gQ4ex>INS(gt`iwysW5p^Oc}ii z%IdvQ8LHadQ5gc*81Em+VPq#KPeMad7sc{}Yb~{;8x)LLOxS)jIDK+J8axK)(S>)3MWiqdGB#(XMt7!32{|@r6~dFGLzn&o zr;(iCtXKQZ+m)q5x;_Y>WCt0116?n?GIq^t1wCaxme)evXbLTyzt_H3L)>WkFLtdjeUUxEpVP&c1kS|6qTiY1d)O#dGE01i$06dCs8e zs6Xd?_B%cdCFb-)VnQR@o~~`-A<4JCFAtD4VTB$)9|8_ z(`C)4-6=qZn$5@8q&rcXY$+RiEvBpwIHm0*eTc;z4V6_TV1^L*GjB` zaMhc7AP!z>Iu^M0_bk{zSjMhwFMsHC1lBGtVME5Gt^v>Vt~1(=LBBgTp}&j>ml>zy^SM`VEutB6fGbVFKdQKUxV(Rr^N6hnh@iZzl0ocE_=9-=?WJH> zY|xXpSAT8NoCqfHn3}YIxQ%Xfh;eB!p>&7|`Xu%oYIwx}`5r|~ZclXY@~#hTM6jFvpZbXe#mGO#WxVd|O!Hr4?%QH(y_Wff0l07G6(T8&7{{ z9$42Xc+(DEZ%v$9c%Aw<>%rTia!xyVi#1F0avDB(3x#&pfwxr&o_6p)>L2yLDOBnC z8eLgD@D?ietOIYWT0ZUI^_Kf-fY+A(SsUI}MS#ZA918<>*kf*baiVCd>Z#(*c z!BUrAqg3A6a}x$8>&ujF3-4lyuvCBKtOC6M%y^nD8p$s>A!sc4-{JFHf%l}&x1a!T zz;EKysbuN%Fp5G^@**~!8P`25D=pbXI%TD8nGzBTqWaqm-bY7AM@K91VM@b@U$az0 zn@DR{nol!@IkHqpk2*-ESpbnIGO=MILQ=>Z+ETR`7mCr88Q= z`x#ZyXa(aF#O}1d-!=*2X$R|CK|IwMo*H;J^{x~Zn74ATY>f{e)6KF${A?|6esq7!Dl(~! zX$|kXE-!Yt-MYL~JziG8+t&A`;PO&bOl=8ojW}NeuX*58Lo~wMUMI2w-gf$jveS;b zH-fP2P*&%(v$J1oeP4eS-fE%#GQ7K4((T}F>uppyZ@cj}syZ93fVZvNQ3c-JxE-y% zzHR-FD)8>c|7a_Cn;el=z`Lm<(%SdM?mUtzGinKMJO1I;U6W!YEi2+OtDZ>?yy&9z zQqEaQE;jN*+KmTN?qsxvPtk6?iSk}>|6(R@czT6ovEE6@YPx?Q6}6f>pOP1DTSu5_ zn71*8dB&zu#BZKzqFeN(f5PK?66B^ZWn>bCES5T~PvOXf$1z%Oo5$9IhHu`ACp?d5 zDH9%-Zp|`=_@1PhPK2j$v$zKJW9vg-H}=!&&>v%L-R+CZ=TuJSPK5V+@~q?-t|Sn( zL-snHrhGv-oF#u7k}N7?YvR!~_5}|L!(*&&*)e_H@k?Vn88!6ym{h%D@wo&sA!J}} zhu*1zr`VW?InScN&COn#w~OcLm`?n|tsMK+cc*90$!Z?9c5J|!6_#49`N07VmbDGm z&Bu0eP2V%8lZle4YFEI&=9h)Wt7l$1-=(qRnv@!-k%@nGwnlZRO5>tq!U}iCJYdK- z_O{_7C5WnH7w|k7w?MVst+|V9YV1WApI*~2QkO-o75I4=lh}HSz?}{%MyPinq>eeG zrXQ`@P;0@iLv+(|6t(%-^xe-fZ5;hQc~0MX$JQPyS=>CVnYU&-VQd+RHtx0d4t@RX z(o(Utf2DslS7Xym&d=adY|z}iD%_qzYn0}SeVb6(ni+J@m>PS+QW;L6i@J2EaK_@o zA+u>w(Zf;i0P0mxzpU2C?c2BJ>izd&#Oe+=(zU!3GSwfiwc!5!R%8FfmQBMK$Nq^e zHyXcY?6cFxnZGAzr`u26Gj=cs##uCs{+_6pZmNIVCqJUwzaaZzOn4eFbWF(-P!&A+ zk&LNe0hxr!oTcbQ_ zmy)Iu^4nl^d6M#lx`{GD*gJ(7h$ZUZg{TBQT$>?keeVi8U?$1Sv;!0iSw_$L5}_L`CT)B zxdHd^o{S8u~ zd-DXEEb#3nu$wd#@5$(!a8+wLmicx{<@`+)r23dd{9#M?*c?^Zaj zjnH?5UvGC zkS$k%F;K$z}tAW?O%E&fQ8j zo8QE@=-;`HWV5MS3FDa+Uvv&+EB(Ao zSV~n(-vrhbXbKaEYwB;9-i?0{mfQ$qax)JnbJsD)Ov>a+u650-TccVJ=2jC3W69EM zTGIngz5Cl^C&LgEW8PiU7s((0wQ=5k41mkxQ_K)ru%+rG-8`sDFu z0-B6ca|;xklUEwl&57ySJ5ZXy7G$(Emybn8OA}Zhg^VOnf`8NBwkXu>%oOV>y6>8f|>+SrlnBY1MvkAV1uajzFFU4%j?zOtpR+T?;P zRNc^obq-8891ngIvvhwjgW8kY{qy1%U84bS3CYRG>MVw~&}BVIssX#5hWa~HzLLv1 zi*}tYmNY7;SAgBDm-d6b8#gUdR7>ms_JkU0)C~42ZL|;UUFD7?Mvqmm!L0*(l@8hm z_O4vAG}x!n4PAOvVz;5Xd{25#~1+ZH>0e=S9O$F>0uD_qbb)&&Z5Ih@+kt-#9Pp1^$V<<*_`rUS0f}>lWuHd_p&Cwkq{C@O1NFQoT6O0gp$!3C z%eC|~xZEpXw{R%^)R%jwV>E7%fI3&TA@-@^N4=h4l3cOnW2kKV=FtB0w~;m716s^k zv>;(DB#oj`pM0O&>JK}e(P%WLV&3_JxSx^5vX`=mQNe%6uN^{gFq+AEKcPb0@HBXg zXWaY=pAk~!(BVGM+FZ=b=y%XDT7jJWC?JWWgZ`;qRC$F;j>TXg}AYDGW~&NbD^`9^VtD z?%gD10gHcSNF#AbL^hcdDo7?+3fe2ebJ)b8-j5$ywCI!9Zr`HNyW6Q&VI!Doj}A$| zA|@H3@iMOwDQ)_!{fl430qQ8nODysYb5$#uvL1FsLV2iQGfC8oQyXVtBzs{@Xs`(5 z5Q^`I*J?Rr ze%p8cIOuft_DZSN)oN=%@Ik;N4I_c-tT(SX&gqv+a$evxe%qf*nTX+F5b%lUYe?0d zHOPN`I0kcm)02FV#Q{r&q;b$ovBRF~qvw2i(CM55UJIG>cor>PHpZmUFEKl6gpwefPFbpYLf)d&F)RaUdChiGNcw+|XbnB6rBv61Th4x}Kf6{(1QU>`(HAs~ z^Y0Fc2xl<_y~b7z1t(*Yh5$FY&Z3y5bR0&ZR9FnL$bH<$Gn}S}F6mJ_o!3_2sG(p6 zJ~**q?2@OY#zY%x1UMK5Iis4R%RC$RHDj-kB^?xye4sXVaNu4D4zFxaVew=+-#mZ* zTmSF<|6`=LpC(Dl)lH-R9SLs8hbEbrWCNKU5`|aHT9}1dH=TP*@`Oix7BV~+d*lh8 zwV^J=(tD+=LUcNRRos-18X)eBXgZmPl1*fmvd6jv1C&Mp!Vc)8Ngws?g03KODXCP< zo056=c^oYvVX1xz8HFg;%Rhhudf%zcDt8l+hrsp=L2uz*fAz;l?7L zw?I$cVA$#Od}G`CHPCEGE_kSe_w$|)6=$02!Ee$~GQtyE0o{;cEOx>I|2VHo)#}P4 znK_xUU@4(~xigd!s`PU9JDu~GOsFQgdch|t6?1hSWo7YhXedb*%P?{qnBspiDH933 ziCIACOr3Xq5&o2omC!Gl0JVjpnJgvGX-sDZaJZ5Vmov;mkIG4Zmt*0OF zwnDg5qRx86tXIdULm^z)(vij`G)^d69B^2eO5wW4;BUFR!@ub^oEwTx1w%xJxF&!} zUqgh(I&D)fAHbY_h+?LRl-Pf55J7gU1))Ue1XKj2p$kkff2b|1&^}4|f=hG3>Y0bm z!K4$J(FoRMs@NHrpD~3Zj)dy|G>d0&FBGfL&f?os_)eg!-lGR!eUrN_mDigFJsioQ zDRF=;Pi#|U)NMhNn)U2-zSo(-%Y7aiRv(xbJt4eEEsS_^mQRAhzI%Uy#7s4(DTEC> zeKqZk*+Mm+e`YMzoP3r7ccgbFzs-%PG-eUMA^Z3O!v!W$sQ4KXF2abW2SebOJC{#i zygq;N^ck5k*~9L7Gzik(c-e!X<-eHxE5PGDH`UYng!N}bVrrOuYh*USMT9}KYBEb> z#F-#~Tx9xsE6%~7pQe8qxH>GrY+Ye2!T=FZuSe;gD6L1~zVIc)2GF2%R}sb4Nzkmx z&$zKho>X!SFmW01orULhh^g4Nm?3*TF^(8IbB&Yb1mz#>4`kH)N=UswB*?Ib3x!=Y z*4b{<*Dxqh2DdGyK^ilnxNH`X5$?N{e>uZOKXPSLltnR@A(Vg9k_fVO zQ?Bj?L>t@0Nrr!wmoSrDk=TT#(NY6rlNT9KUD$wD7Scrx-JDRmN#AhIa7k;OoN4IE zw=_hD34I)EGb*_)`{V^TaYq+;7EC-YH#dncjMur7H~sddK@ zZib!C_hBmJp*f+>TG$g-NGPQ`6~%*am5mwbfUyhRe8zubmWGo;>z<56PrvW=6mbKr zf7~CaulfmF_#Ug3C_Sd?TdOFG53QEMhlE9F9Xxv6Rp+SN@ngv2ZVl*p1GDz{se&ng z=j^P0eZ`jf>wM!LcX2x1{6K5hN7Mr1`Q&*@c94a2#G`Rmv(C$k7{AGVoN~!Hf7TEA z0UlY~+IW8+?!)2x=J@3Jz+qO*X*AB))-_WT6ypO6x0OO0b9(jdjpRtc`0y{hgb6i8 zF~lSd$N4yKGe2%K2P_bFW^WKuS4ofw32@~4e@TR z;^Wz~b25$S43(W~@Ha|k@@^fE!fTcu9X&#A&0EvSp601~Q5drx^mb6t(F{8s0|^U3 z?P7msTZOtWuEGRP^EFHHbca0FtESfJDog-Q_cbW6K_zQ$$DGh;T`p)Lz3FJo#B~N< zCx2kb;|g)=;b*-ownUb|d8P=5^N>0ZEbaJ_3u&zSm)fe|>3GGxrA-d3&Zc!g)2HwX z`_LC87|#}TG7n?G{~MlOsRPX3C2S(WZ~%XWNo6?6)Y%SWbsgk-Ho+J4-Gs;S2p0@k z`XCf^9BIxa76}D5cAm`?TQ^e|?rW})Q1HWC3&U;C*I~qFKsQ2pRumd>P_Sa1 zFX)VoH0jXWRSdpFVZix%*dgY)4GAz?gt(SR`%q)%5X?9|G8l*PK+N@Dy@~$E`(A$s zja1rN+Pfh!ll=)#S>GB4_H>D%%Jm&`~8p_Xi7E;VMcDqewt9~H3V!kCRF ztkd~!X?UbVhb>-UT@y;)T;w(;te=7;Y&aM=w?)XoU@^!9OM9~{4A>yIP4%>GYH&cb zBr_TWR8qxb%Q@c2_=&oEjUzW+p20Gvi*RDz11%CER}vK5PLx#OBWDo}7leOCN}6Ay z!d@I&${0!#pw!?RXtenE)MOgXd&N$n&ravKZ+z>)F}3tj=cMs9_VJ)k&b5ikE_W*< z78q5vb~wp*&`MX({o{*Y&fdN_eg4#E<=WdL-_gmHq9R}o6q2V5CyviS)YXbRLdh6E zR)+-<%t*DEK^>I+u@xn-V4;8NnZ09^Olths(=yDmdPjPp#HlGkP^%w~2z=T3B3E2= zj!(YoAN7y=$HPYtzWU}{xI#c9@m7oeZ}Gx3vSjDwPn9-;UNiOFGR@Wb%ow7jLA@Yb zBv!;<yyj+G&EnfJh3GQxzJ)toS-| z%%h{CrI(ColCU`7akPYiM=>8Al5naG@aEX6$2pl+ya^CG1w}unt4Nj?G#TPuvu6b4 z)0f{9!)f7SgnS@*5>9`_z&Sj72n^`_ke?tVhmXV@`h22^>Z>Q;5vTDXjN&}VX%5~; zeMRQgwb0d6yQed@n8M`~YY21Y(2HNrO5*Avaj>pHAYyidXh+Ic?!Ixus8O67Hx2!$ zum5|d2>;^;2HqEd2byeO{BlNaSZWW-ArX=%YU31sO?a{_AXa}eA{_C-tWiMJkx)!L zQg^DTU4p9A0JqgpK<(vV=htygTbjkB*8@SDN}fJWv$&V=U~qj*dLilcQYB7Hxl{<9 z@PPDswi@B%d!66mQti?t`~_{V-682-A9oM&`BfMP>d6HU%%cU9Q~}-{lHWVV@20En zZ1o|4ha+|2?FWC|Ox-xeCb=%MJ0x%N7y2czRO(Hq?BvsxG>kMjh3CDg@97|5*Mm5V zqHf{cZ^ci$V53!2Fn7fwjKhG9OI_NTE|zuzeUOk!=CD~ zXVKW+4yAc@N;CY>`EZZ)day%}EBn(aUOo0^aZqunR@h!X&iDFYsdIr}7D*FYOdV-n z3kj{M&JM`V-d?d-3EYcXVXCWw7*|)n4*t+W`i7boKxLwA2D77*go?0Y!kUu0qF5+J zo#I?-_wawbl8P%aFuqbO?dgRZ1Z)z~l=UA$4^+ibRsVEv;lphM2(>% zX0Uk5Q%I&^ci=6JqPJ+-)W~DI8g>Am4fg4d-ROT#<6zZQ;?I~#+Al70arqwq{%cp) zg88*ORDTGLEc~zC;jdk1I=^;5eCT#Me^pX(aS8OgYD1+q$ZFYH-zqF977jAjbK~UV zu)tOH)7IHy%ODgJ3XEbb3JQq{ znA9YzFgc%Q!?%*C(SX5*Hr*Cq%pI0Dz+e7`^H?aiUX_BuG>%4hKYep88d42Vrzdh z-;jv|dnQUOHwU)bYGdc{Yxim~*bs zuhS`_MOwg%x#IFU2^fu#65?D4OH-a=CJKo{o_5Im|NgK4Tc8aY7et}b8@M85aa;n* zpa!>Aq_>grX?2_T6wlFv0eYbj854g8IJcjZSxN(#)hSuffACZvB;!n}1>=42KD<8e zpY$J)-nZoXq<_>uIv`;jXsezPZBkG@(YO=F6TV2O1pn`G$|&#+x<4i9LZ$>7XEY)d zi^yr!(Q8hQzf}DLFQwQ|8WoJl=rN@zTcCC_2!)a~X^J<(lwNai*->&KkC}f!*(nry zf_iGGE_|))Ad>r_cDzsKRFE-aF|bv1k~@FnSDMMX54yG#_>V&uwj^cK@SSnQ9YLof zu=vFMru^18I*s}O%bDY>o=f={F~!pvjls}^RsukMn#sBAbPBzUjE9Hic^sVvxap^C z0!ZktRlzIFZ36pBCqSTxyy1VEM;(%pU<17j*e=Xgwkk$T*%RS7AbtnP2W|;^l$rnI0kSI`r!c)Si7?ieuT#T z;o_Gw^q`lV%y|^JUcoSL9@ot}zno2Hqg6`wg3El-1;|+NsStk$cflsat)-mbdv7-g^AoOk{+A|MJWC0bahZD|e<2 zGpY5u#JC9^RZ)M4$AHr^delEc5&TjAWOQiJSzyeJZlJGLeQD-giECNTBe9U>K%phR z2kv_`UX~dSXc$U$U|?*8H)ASvJPjp65r6R3&eU!*33q}57X`60w|7VqM8cF!QS1E1 zvmB55Cporq$sEd@(wjb#!A!7JT?#Cg7;pk%Ciwr4`X_&bqodxdr_Y|AUOs*C^7Yfp z181L3`VZ_rnbih;MHownI$|P^_C`i@bVw+96NTfHrb}GLn(IQV`1Pl6HM_p2zBy3q zNYz!!;(*1IWuH7(3sew!G(!xGm)d0TRFO+EG2-QvXK~Qr%h6s?Fqa7a+0!5+zkARp z7y5)O=oNn>B1^To*Lua6*r^<`?94)@xIx9`X;U2N+T*3UUJ9E5hvv=8n7rWE3<_Ny zKR6^OM<+*z$l+g~Snou2jRH0){8RFWn6tpU3~Isk8mL=ZW}?TZJvnE+B<25L6M1mx z;cgXzBe4`&Bn=tS&KiL|6%cR4Y&JZ{mlYk9jFNvwG4pA{^Bd5{mrWU!5W)s5j5=mG z)dzSwxpv$%hGk2X;43`?5=z0MDM{Ikrq(~kEZNhS&-$It{ri7)6C43+WYIj2_bM#H zf8M{ZF4_x2>GWgmK^=;s@2+B~ttDefu8&7#-x#(*hFOv^mvd}%0@Hh7*52tz?X1Np zUh04Iq}nGmeE(^S6rf3{C)ES>&4HEqrwu|X3J(^p5vqO^AMm=k zx2O?HFkQQ$z4u|Bz!u&|o2ZqUpu!{z2#u0C9WxuR7!yk7e8H87sy5<=qPEkR?oDuF zzKlZcxMBdqz=kAX9snb;nji_YtGL(N+wFgb>Jq{^7wCSA*AdO{Kpxu&StFfkG)65- ze!omnsjJvdB}ca(G7niM*C!fn#Dv8(4Y}cAbKV&o8=ckxXF?5c=!ZERG+wGr&cVoM zq18PF)OV+bD6GI1O>h?%qkQcF$H}MDa1zo8KdVuE`B3@#rxFK#LLRiws(s>yw`3`kxO5`F(PX_sL)La07#x!sZ(; zXx}NZx!%x$#0knbtdeGF2k2v!@(6!8=sAr8$DJR#0d}5V^DxMHDIFk_%U*}tsaI$I z!C-Xl-GSovEWBo_*OX^7<5H)_?!SBY?p;AR596YAY%rTBgNdxGPCL7?3|4A0qc{qIh$OS&O$-ne-FeQI;nPwOL ztn)ZEWU|$5Q+CCj#^efz?bEnF1xJXid z&5YXuOen@2q!TT6BN|R=7-cCtBsW?SQt$+^fv_f^3>pcwEL4&Oqp_9^Zx~tdYqJhd z3LEc45(;fo(sm9-cIkAgxDbC$0k!d`Ogi(pE3FhTuIFYPL4pwb%fk_uMW+@pQ1pEq zyEa_FiCz(5R|w9>z^-}?#sv=q+1E^(@o5Crj5Zb?K;&UmpPg%#uA;Of=cS~o~!sd zS|>Sb6^$GR9p>;`0+ zGWlF`Js2=SpfLPddwMyEIEsa=NRoyeQ&K(bAN7w%4*HblYAAm~2}3(Q@>d;@u1+P| zVTIl3F>^&5!;9MCi(_EyiE&RWFdjNx#S#p0p6$iZyF(IlZ5qN{1Sq`b*z&cSp`rasOTaoypeWXjK-9wC8NXB+3Fe@i!RVK@EHl zQY>i6Krn6E3#fmXk2y{K5`Qg&;D#UpW{2a!ETvN#)3a5Oq?PlaPBT!j;wsV$_&Ojyr=J+EdO2pF1+ z)tM8VxY6984mJYLjlK85{Yl9d`u-gAcYWfqqdTtI&bfaydaQuQOb6rJgg`?laeU-7 zub+t`)%#P|=R-%vql!f5e?j!&v44A5AlP!jvviPLPkIozFlFfhhUqFFqd6H2Bj z6LYJXR8$|idpPl2F@G1oob|!oXfztB|J1qC`;_YS>hiz5c=}h>^|z+yPLDV-CW;-9 zZd#>75^#S)wGRisiAfrYtAnA=tft-Xdc7n|XKa+`OiJ0p@SSQ^(T^fma<#%H!~@V= zX%p08W&Z)UYzU)5gMu8Ln<^?RSp=Q@MJsr}tt_>DQwl;b>sO=NvI##J=+I4My3322 zfJ|Vf^?`vrQtlz4L7=WJT)0J_oW>?4kqN0c2UUOb;IXj}1BVjEbC!nEu;iLkQ8$NX z;R`-aVN4z=nxG{_(N`>g7&9R*Qa)z=gry-Ehj|i(*ewqnw?4X>2 zDWa1rg(NoIXR_1^5&s_j^xkrC^&9ynGnpKK1EovdvvNNkB&pU1U&>q=F zzMvYV+u7PABjiOExdWz@u}=zno&f~)j(qA`DI zeO6nh;c;oJALfcGo8T7NNxeAc)?CmfP^+5|y*?ES0un^L)GbQcO-6>#Pp?@z z>S%8p?I}4T<1nUas1V?MTKd*#mSqK~r!QW=`uoMp^B1oV?a?+FeLIF`nVge>N$T}o z$*$^>APTX{4mHpZK%4;8OrQKLSY>}S@W#Uy_L165MnNTM)d(i^1SW%%V6jY>5b2IS zeY$4|o&G+eGxWGs0w2li%;;!xO9;(cL0SxrlxO;O9~oHyDtRR-(`pXIBBm)_f)-1r zp#C&4^QpEd$20YBn3L5=2F9(%rQHt4lu$Vz!H5Mh6T>_;u6^lYopFUxCpCY9BRA4+ z({T494M^CeFF;wt)BeKoOYY#YgKRk_g{24;pD=P+Y?>ruaD6;xlAetE6#j*G>rP>k}=Y3`W$FA{8wL{JnBO#PLS58;X8FX zwr;8gV(RLJN9>(sF`R5Yx8r{iFm>wOjO`T@D2AiBg!Xh5Z-zd&h|(xpLe{jkVEp>% zfg*>nn;=o@&B$HF5dM7(8(8&&A@r+WV5b%PEXM0!>wVGT}03} zaVz#Y&Nrp#7*}o8SNKDEy$KZ)8nDM8<~!mpvM7WK`85hLT-O+A3U_Q@U8el zB+v)WHhUmUKq2NTa4Vo-_r0E6ChW12qe(A$eDBTgU7lcEk~(zVL()x5G?v<(fkBXg zbH;F|yB~hLw+;YiQo9C0E$+YF{tw+)CgDI6vz}w&+0__FM@L7GzWfsYdvtVE{_oN8 z!=ryY{_^P2(N_e8>`F*#-XF*4Q{D-n#p+~)D0hh>J|NC{p|VAv*256 z)voA3^Z9@H;OMw~|9^G-;LE%7|1o}hd*p|Rk7-1nxUS*3b`+8*Y5&~VlZnYA^XH8Z ze;w1C>#}=TN)>9t5oQPq;2l(&(B24n9OJAJ*dac7WvYllZ3^||A}`(4+1u-2FGI+9 zQfM(Gi>3MZ3%X$W7fuh@PSLRZuRclHbV$~zfuJTDnoMV@ouI9We+ExY-LhfDe$fDxq%-`W0F%cv-1vRtm?$yr zSszL);h`g564Z6-PZcNH15ZI1s6*74Lr~y-(+k)*q;c=~sFxlg9GA9igxxEhP61xK zS!3^ExvzVWhR0Sx3kA7{zGe3g35$faRNOnCzTol#9c=HFX1y{o7*>WD>?JAdeEyOI95Tv z52VT1fhs{s2kL0-!9PvKvtem4f7R#efv_L*xY(De{9&9gJ2uHkH98-(7?2laNFHF^ zuP`ni)_KFtcLhm=9B(D-sFHh#<(c|yX$=|&s&ActiO2a6rf!0qgC9-RyT-VuVgu0R z#}g)OGHc(gAlnxvpRDuf;c;;oj5F|{V>z*vY0)91;&)U>ywGAKSyUpff7Q{N$*X0M zG@aGRZE0;CwQZocJ!d{GNbknP*N(G371pzCqQom{@y@C7F6ptIU;|Cwlqzpdmv5gk z+j&>0^J+F{VX7tMg%TivNT?_^I9@V8cAh1$;UZ=f);crU}zEyVB_;?ZgPd!wh<6{ zldp$RlF~Tf3lau|N=y`@YnXX0Ycp zh9?JRilz;?pOlmg`X;g1{Dehxd1=t}AyNw0VZ}U@h_R)oI_J^rdCJ6`M*(6kF~0TA z^M}BgyN)rp1=;Zie~@8Pg=d9@Q&Nn1^Qs6rz5-65f*huFsHrB3Sb}v>*X6V)e34{8 z*mOBkxR&$kq=wlvLz%w`K^4@HoIHH=JhV?INj4&d2>5Jj`xwIA z)KD%H+(z|}q2U+LFK|=z*B1rSro~2l2+zv5uE|cTK5?9ef7Ih=oCe>~NbzmR9lkK% z2?rw4`qHskkqm#?%hS)9XM;V}CpgjF|bA3vr}FrAt#MTNz2*8_uVF*g>3aqW10Oy9kT)1WujAh-+VOi&*u zqOHyOpAPire-~PoDO4kM3&J6y-4o;qhZ>RUF7GQ*MoTF8cxWRwB0ix}rdYnG174Kl&1y(+>}{%|&7{VdK4Kj5tge-j{Yegn#uAH9SJ#AKQx+HulXfS}Ae zO$E#!Zg|D)q*;6_eikgXPt?_bg&YdOv)(EQ_Pp+qpJVimmu}pxu2qLw8d7FFKC2}V zwBp+yf2VH3UUTJyy=v_QqeZGwy>zN-lj72vX8T@O--Av`lD9I+@e$5!yLnky1TV%85bOqZ=la$UV9BPFr-5E(kxb&op~`d3uQtfOm(aM za2E5Fi9F`dG&$((kz%1Y=)_LriY;|8R?1`=G8^-nFE5UP`om&Zrk9`C5-;-SNDsC0 zfa>~Ot}~-Iv00~7rOr~7yebC9`@!Z_f6A+q{Tx_~zBuTVEVAkv%9R)kC@vd#id3jw z#)1&8PEZu%P^!8^B@MG_7%NHk;+M1BOHpTr)2cHydVx8P@Uij7oG|_YhITl>va8}?zt?tM)iNcuW?Ml^athxbff6uwo2t#aVaPg%dMcKV_pB z@-$a7HrE$XHwEO}%z=o5ygs&)e|RG%S+p$p=|kF0NY6$mb2!_vcIiU$>$CM#mFoz? zo-N+gMBgk$BTI#|eaz2K5J(F1x^oK!#p@pQhMWL$(>OYVQLtSxB+$1Ane==u57D1pz zf7T~mA$fY$UCS8gNd=!P+ZI_Q!z5xoJCblLf%f4GWT4kjFY3j=Q!f6wl#68)(D_?& zSpfymRzpmTBm5DCSDIl+=VB6Rd)kAOUOH#dSA~ZU@tL-*$I((JT%4Acq+fI?BZJ~z zmR{#5?bD6oag>wfQZcI1e;(Q-XE@-Ace#&`@TF(L_x$?ShRz=NJ2PYWFl&!M43-7j zDTSwn#=Oo;FAw$UI`79+Gb#G--o*VYFWe1U2y@C{%gL|ZQ9vad{n{n($t-0FdHGX! zGZl0V`F_CzC8ePwzR(HrB38+|4gtyw>z2{_0$PzT9(XW4`fhtxe_JBas_RUsH)fLd zbY_VhZB>&?4aSiC-t`owpy>oc7w95*^ko-R`tC~Qyi%2G=E0zllzvdiT5q5*e>d&c zx*GRVvqpV;^5;;g$9G!u&9&yZgznQz;JjWzAmxy}>0pWKLe<5veajhLqsMb1{gk&gG#R5Vl6)8=kNvnY@dZTE> zR-F$C1VFlDifoJ_%sgEd1EC>EU#n*AxM55JcJ1mij8g`jEFLp*@e3;9G+${QoBEp7 z7+(M+-ENL-0VH#gzS^1EA(I%7%!<;%_22|1mHfqh^sUoIe;X#cy{@lWw|l4$nHH6V zE%xbF`E>frVhsh^cVcV~2*`&pRGdW-2I?Ti$Ol!s(8=iKVCP0WrRouz$3 z_Gifn;W0V=>*ZmdvfgNsRZl>`baHi2GU^rFUb{Wq3$(R7SNGkp zV^qEBp8jhZe@gZ;o*=d=VSGrw{vou~tFmkMwl<%%q9q8F?=0;(7ce1jrmfmk#|WZUZKZy43Iwe~S>?O`xfSdqaP2=ey1pC=#wn zs~G5%Umy-T01fsMGmfz(q%JfTieVjppjb6XuocRsJr0&umR}g(>!Pmj61Dm{hq1S( z)5V+0_;9_20y1XB0R`%2Rf8Q(`%;!CLnzg^(ACS0g^lnOGNsrPe~83cr)D8?&V@R# zP+tvPf5gi3R&xNIyfHt)6k0J$<$1SamG&wc)QUWF$3NZiPc8W;$0VW+YOp6o@%VGm zog;|5R-L1&%P7iy8t7*&HO|{?HnC*3}R0N}u)ze=^%tFY$on7BpBl6sk5ew&k6A+50-) z{!Tx0r=Pjg&)n%}?({PsTR($xvrczSo|^2{1M(cRWq|_~{au9sott(=>M; zeq-{KS@ri{(otq5Q-^+I5=b!&lZ~1J$ z>-hl1jqW$cC&$Qt7uhIyq*)!v%@IP*)q6H+t;dsg!c)e@ARnj46UBf6snu8aa~`WR z=FPuD%JIH=SV1_2iUitwdoO=8Bn#}(e_p4mvuI2wS2hqMCmiM)%;Ja%k>@(qEkTKO zO(Vs<+v~>lNxqp=c~4j&amh1N4)=_w?BykS<4~z{ozYwUH^odiV$-sRo;BT*QIMLu zxG=C06%b!`Ii%-V?>L9yr)#GF!e8L62jV`jYBAbTga81*C|mP0;Z}_tXBV(DM6f)KGePQh*_=9 z)E>&VhLq*C5P(1w=2d&za{Y6O1#-?;&Rjc6`h1TelERS!1eS6A2d2-4)zBZ=QgTpC z8uH7l1&2(|>Tu`R-SfO`C&$R*f0Twg1R^ytD{gV2gbO)KnfPa9tty72C`77|9-$Fa zgb(KOgx|#W6;Y%&9ij;FHcNijJw5LJ{(GJXq+3kf(ItKI;e*N9+5JEsKPE>`ms2IM zpDdgwTIKCLQRsWkQc!)eG}VkLzN2L-Z<}O`1y!tyBcbUW8szuiiGukHe;lfBpMUt! zB_BROoP43LfQd;O0&B8Ke~{1K?XtMY&p}7>V>p|;gW_6$TYy6^Jt|e+DkA%Kyp&9A zwiEZs@zGJS|3SlW3;J%0(TW{^OTHzC${RZ~q(cf5D3Jvl+S&rhXlM{lu0}ufvHGo#r4|30xB{wXciWsCF!P zt5~(Sl1mzGwE1ryE`B>8-;(N{AB)d!&*xNKV=!-`=6$<+?T+T#ZUDhZFA)`zJS2-S z&ZN=tIDvZgZ1Orvypqkj#vc8%u*#-q1*4?8d9-jssEv&@IXTWRe-2F#V3N2A1tSsU z!yQL7zVcW!jh%Cac~tuqoEHij2scxmdR-}8FeGPr9SMFDv(!2f=!h+?pabn3=;}d_ zVZ#@7V51to+Icls=Ejn?iM|ta7Dc(B-90|)RwQdo@pC6rSCZ!x#o9G(7{@1H`)wGd za5Ob5h#0H{Ro0lRfA{t}xv84G@42Go>C5kHn>)(xJ(?&68mfWzU~EG05rph7(ZWlf zm_Vo}-?^&tLl~w|mNQBj4VDIb)y@iaNV^#2dWnI$>ad-eeN)ekvw*37r~`VDBUeH? zsJR1$fu>;O{Pr0b%ZJN7 zTHb?omno1SMf{NqdASt%7Tnqqy8sI;M9Jxd6$Oux%3*6#y<)uLKrNDqywfp^ki#=6 z57m%Fp$b;ZTmzpv5AEIW)BJ4y=Upd#c77}CKb#zw>py(;<%7HY&mZGgpTD!#K9eV> z@)@;1^@Q$ze{22n^AGmqh{tT_6kyf)KYCC;{|`?d-qnBjC_kD`=AmR0nWbzL|CTGx#8~IV zaRIuypU~6QHUj{TasdEG_*s|$0Kmof#ghO4LqY%o6W|#_C-MLwMC;FAK(K;~w|@W- zq74Ltlf=hA0icrv$Si-e{`FtI|A>LWa;kD5(4U@wP#@<%%}&lit~h6UD+B?AX#J%+ z5Uk+(m$LR6cu#GRYbc%oQu4++>$!NV*#8-XPKE!-n9vC<=+7WZmM+GQs{X;+CJG=E zPvu}gZI=)?&mgRyj}yTPV&d)WV(K5}Vok78)N$1}u>pcLfna|m)(i{vayB#eAUGn! zKuEl%wGY$=2}Pg`T`VnapdMgzM?V4@sX{;l!J38^Ay5@lw5BJ)G7JbtTA@t+-Su4E zw7d!K)?ru+Q*f{~1_(xK68w~qs)}J+etyPgS~!Fy7~-gDg)&tNG4Rz!n0q1p9fJbg zfM88+C$tLAonU{e6YOg0j`t=2!J0;=Jj|$mL|&n1YidUk>KT}MxF{Pb8ECm-AMEYrXya<(Wvznra`GWq8~8xL*1kcCj#kco zreW9sM~s=1zqgl-u3xB%GtSM#%UjXK(+!6S4E29Ps)A5h4Q*>@1xr&c96{C1Kt}-r zc6UXDXn2|V8Caur9Sz)&=0`icni5K|x+>8xxGvQp3of|0>!3oX34InoRWM$+}r zch&=$`B?b^!J1&xAe>ehhJNJSbOSXFToiQ(Hp*CEcNO}^X)8HeAa$`=7XwdkPl%bB zDi$?t;uDBLs^C3*LaZRldKlLLKUeoaEr_xr#5pif3!)XO=*_0Du@kPg}zxBxmJwxJmlf$BuQ1cDt)Ozl2D6 z1VS^mt<`A=TZ~n%G%~VK$h_k6#9%!o-Du@f-eaW)5BNo{+?N0w8k+jMJKH=M&tOn? zd@_4h%aF_D49~4+OVrjQ11UEGtI3m<&->Yl%R%EwfBnI|wpwfhibluayUiTe*P=uZ zr(#ct3f#GK=Z?TF+^suz?s&8S+dw40fHbtVwUwu{#KgtLvwaLtadO@@f=b@GbEi{M zh)Y{r+lhKJ+HYgV}_0>PMi z@7~jfOQQuk9EQ1S-1ZUcjI_g_sD+IzpX{|Gy6u7=H}-2 ziYK&UPqr76uS-YrjNJNtbMV)!C$VHAjen*iDJnCQ*Dh=U=rR5hu`dxjRv!v!X=#~S zSYWLjPki-Cap4}za8!664)~=qf>}plVSOxCxg9p-)q$gUjC(nYxr|FG@MFvIv zzO2iuJlk^-^v|6gsHEE(?O=80OZaO0E7u{Ptwr>Lf55lybeWKq*Q4+A5p1${^_YDj zEk|N7g(j3t{VaS?r%sAaoiVRFl;vkUezL1s! zF_1!APNt3s9~{V#SOJt|QJvKaxYrHWVn9)`tC~AWFcxmX?u=u`GwaQ8CUH`lv9;-#Nh@ia5}TIv$|wQ zT}rYjMT_Hd^lSG~eR96Ra(~5`{mK{_SK~&MQ;~d!hrGjAZt}}v-(`XB#K)(?w5-O+ zKg$~%9f^H2Zq%CLEEX1)rZ=7wg@64%7cN}5Fh5WbyUAbMM9WF0er}=V^r!Fp$APdF zn5pUMoA2HkE|}Yzg@vir*Vmia*~vx5vusNxP%Gei&j-oVl<0QHn{{>S8$W**p?qC= zF>h075;dB{7!fW;M#iB3+UTYP+cVZYDu?SEqUa{6xl5w3j}Vty4sax?~Nd&febJ zRaI4+{3qLKn+epr5(V3YP7ug%R#!;XPkW!e6cHAt*3!~a*zd!#T}-6UQ2}pFic^`4 z;9}#IOM^u%IyB#6%z{PMZh!IzwbO>1X}YNc`;g(RvA5wW`&&y=kxV14kp4?is|^Rn z`|NcN#6>JoqDz;`k2l1WS-x@`iT8$@8CqNOe|+V7E;6QfjQn6sR1d6Aym7OmEenLR z{n4+f5K1djgrk2q4Jh#cr=Va(aAQTv6$_)}yPDDgTrhikLwU$wl%gGWY zpX`BJiE%fNF@NomZ%l(ld8DMK-g@*%Yylz=O)W{L-jzr{cv^UvHCE*<+CdVQiDVjY z?vZayJjQ%dmuxD(+z%ZS)ibMTTuc+?lDx;Nr>8eaND-EhloY>o$#y?63`^{wuQZ;D zF5b*Kf8m10&+olO{eNQWZi9ua-QC@V{ZF{I376=a3{U2!iEx2Hpe#k#)J=XTof%3p zWpU(b(Z7mdu~=OcDiap9d|pY3o0F4skTA@801?^NNwrv9HSQ+G4Gx+qx_>a-XZO3& zkt8_Nkt8@s7>=j%^B$bjlisxAa;CIZOay>Vb7%6w9& z$sBbV7>O(!6Fs=sMjIo4Ij=4$a(x$@1NGJXvzEl^*4UY{sxK{H+Y^oecoG z2WQZ?ESak3NL)sFrwMb3h=_Fd_h-Upygffvb4uQ0jXf!Ri%b^n?&-Okp3Vq|!w*-9 zzn+GHa$%7Iu^ggI0Nb}=+yy$xNJB$*V>0Z7(SOj|h?RX_eZA0JKbbOKNjUQ9aAQjg4mB^ECkrr!QT;T-5)B`>)V4Bv&am+pO+AJ~)NaceW;Aq)i|g3a zk$?ECtgO;T<$(G3rM&MGCjx__1#kAw0C!5r-D(Ial{n+rpn+}w&CYpQ(N0a2%+y$eZ3HcB;0z{`+x22FK@%?R#Wvh%TSVwjt|l@Gg}=irasm9 z)3;QXC&5o%k~>57pOzaf{j0Zpqus*P^yaHqiY^Z36%W@jjUsG{{xX2FX7(pw+6^r4h@=(YPO{hX6L)>D7y^JQvksvkiP zj6B23J2O~hP;OHOxZytf98D$e?d?H>e+bF)^mzU<{8oiR|2nYP-5_`dt$e)Qbx+EG zY$~%I%yn?Dndaq4+|OIi%2M(E;<@?-I1_TPQnmi0ZdIQyLa?R#x%c))X~JCL+shi0 z4Ut9tV$AcO>r}Q^CZvDp)=2iPfTtE}5|vDY3~d{)3mauCr^BLzrXGg>&_Ez=Z}Pu( zBzCmZbW@L0N3_R5M*!2))96Wm!;X{(58_P=ka}cOspb9i?ZxEnr?OGDfQcPIV+obUmT+2N?pc+>(slEr!x{tv@ef$@sRk0CkWln@Si=f9fAQk&>})|f+iJ1Mcmws|A3};oty@c@ zMJQkC?P7lp`hoVlO=E{k0_ZkxXJ@BtU~muC4lH{7IR9E*&>-OsmiUtH^=GB2HEmf> zhARmuk1zGs`|O#iIXQ`TZ^QJ+d2Gx5dt;Lqm;3i@OW>ITTmS`Z3j;0fvJ}6P+ZjpJ zL)plf=jHG@ERonw%b|?y``3Vu0M^&nL)My^@8*BzUW|-CD||WZ%*w~tt+jzmg{T4G z_8eyUMbL78h3#v2rVtmvXM5Q?U}2Ckf#+f>tlfl1&X$EpB<83G8}FaFh9i=iX^Syb z)fkzbxtF+nvw#4_h=_=CLchp@dD?cb%H$)h*ppc*-VZk~=>LYk0x{Ha=7X6m03hd5 z=;?pRgKdP1%lYTm>LepcX7Tay4&eK1pZxo$-`$4{&Yh2=DhVA_3Lm&bw}aUz+Dc2K zFLWFn#Oxxs(6$W`*84)&WX_*&8ZI#(cwrBh00Q;MIF{uXKgP(^ipE+Tk=PD0jpBgq z0(L$Ji#|5ajc;kuT<{M7!r`Lkj}4otJClFO&OI4=WSs8u>W?whh>3k&Vi74@qlarIvW%RjlhP=I8B+0;mSXB<6!x5{>8yhJgQ)W@( zA?RVqSJr^lFTyfb&!b1&(qUZ}q@|_H9ovsHFfdGYNs+ZRHE(U|$;HtzG@WEHQnY_B zJ2^RtNlPF1{P?Q5^X|F3IXNEHydRPTRmy#5kcoVtqh&U)TiW8d?%uzDA(H1N^{(u; z&g?_X+o^!~=rg(0dl=Sp(!{MD3W1@PF#ODdPmS%tB9O%v2 zSto5BopVqqU#@y^Om?=Qp(NM-&T4XJr|!E4N^DOp%UV8^UG?2v!#d&d;!;w~H8nMz z{rx(6daQs)g@p`zdwZR|y$ECDlVAvhF6QyMmRrW^dE2}D5KeynI2!c;H`{sFbg(vJ;)#FW>6k(#A**tTj%%>F&n64z%$pO z$7`FL(N$F{ibh&>K`VdnOVKilo*ymt75$FgMd64NanzDnoF-=kQsQ?eqL?Ve6+Z zr9_MGChDH1pDxrdsN|Vuf_Ccfld(?$<*~rdrT$*{5S+w{SmS@EpX1aqGR@cU{H^{w z62DionfyOf{m)eY@1N>ylVgS0<;%hoRo*%t9Hv2TA46#lIUKNlrBin`GwudA=$lE@D^b>>X8ajshP=g-1eES68v<{PpWsdN9c9#j^`2vgGCExqNuW9}yV|a_T(wE(?EjOixd*v#*bbCVZCgTbr7b zBvy3;6pHfFxktfcOySa6(=nElCu6#tS`PPq-c3!tWlyAzl_Qno*9Gg0KEK8(AP{eqt*l2zZvEcx0(~K_6PsO9WQWd_ zv(V4x!-bumrc}-#4rK8V@oPy$zcl&=E!0+U9Jk8gmN@COo_x{Vf%XmGBYVLO=Zz#m5cJO~%!QVRJ+-SJ(0yW{xrm1}j_R_Uf{ zt>1sQZtnW+kM1r5`HVdBcCwMAv%e7$i9-89qJ9>pXe+U@vd#|`b9@PzIpI8MI4g@l zAhMJ_1&$s&b~h{Qd?e{?IURRxQ)r7MDwUhUaASs&ToAna<<6ZuQ{)GhC?F8X!oi{A z;P7auG4|8>G5gjE_(Vlx431b;eVCO6!ZCjx9v+r^Pr??=)7}KH+662QvsM!NGhm1d z%l)u1`_^*!fdf(QlB9928l%0veZ&2Zz6@FGqi{I? z{h?!%_7(6s-`6x-H$w&n28W3^o`Zzyw6wG{oAU!&`|Q^oho31OoB5>}VcEy8xNw@Y<%R|B+jF zclY~3J+1{v&MoQ!$H6&0;YK z*Zn8uax+~1@>Y<#zjY55wK#pB@US^}GE(YqTn!@m%u>eYwOhN2(1pj(p0WR-d-!FP z5uGs=!JDq&9N%Su;t=#S?_g47Zyq^KsryJ=HlWM5s`~TzAcB(I1nZD z+G(ZcVTNgGX^%pGejg;H2rIb`GB`Us|2^}mpB$H!#b@|HQE#99Wx;>?3d;6#l;3>ji9s#5906KVOfAIMpOCe+a|pgEagnmc6Gh*K*?P)l1cT-Oh=M09W+AR z+G&Y&{>;7qH0~wt>x6e>du2aNCK4INeddf99B#kQer<86n4{qrE&LzSsv-w<>VIx< z{PC$K>vH&;P5!Nnj0}G!QBiXDWJpM8D4IIHEM=T? zw*ErfJ3AKhFC@E3ajaaD4m&?S4-$qG+8u8;Ho`wVzm|}nFK*iq!4Cp~-YcF64Go3* zer2eyuQxF<5sNH+a;+|CftKXF++RIL#+5hLn*Pb`iVzQd4>x~@P=kbF17l<35w>D8 z1cFi0FzZH6PR@j#q2*Ip;> ze6M(-AO7po%a<=DU`E-(P#*y5@>bgK9E?f@oPT*$a=Tcxn-mu-dYwGU`IEW zva2euTn3KzWXgY2rdwl8F&NC&FDoJ_lDakeUhxF;Nuev2mOQnAOEG~R%GzoP2!eBQ@W0^YYGYeCt8~s(bVZkge=_>#^(DE7u`U`NxyQU&5`i952F} zT_40`W$}LjR3;;o+&{?L)&`WgMOrmv{W!!_;**Ap-MQYv?cYvXacx@#hY=gX8ed2* zzxZJh(a=p|<<8vO-&&fUn~UAp*qETzj(c=`ZBOtH|Brkp>92g}5y1WX_gy9%F2nZc z&qc??w79(%S63Ibv$KN|X_w*?60j8*pS39s+xmZyfdz7LnFZ$iKj#3YX)3LsKH0iF zhyfa8(77K^0^=m{*JVYc)*qkiyu(3B{17Gxp)Y#G4S~nwN8rq#_D?^2?7F)>;eF(j z?Vg>T-B>yH7+`9SOpJN#3Ju%Lo)NJJ0GL1NX=_+K8Jn9h`PU>T_hc_Sz&>(o#J=H7 zm1BSVaSICzi?>cn`Kl?PDLiLIdVc0mNW15f}_s6^YvBfFJryyvWYV zI=|)mQTuib= zYWb8K;Is1awHoy!ubl0TcE^f|w|#HiN9BJEA6~NFPqe9Mto!wGxqp3Z@-xwMTS{vj z1oHlJ>D>b*gMD_t8 n1y>smp8sn)vVzbrvbi#0MVI;VHXJwE5czNKX110_2VS|F zFF-nv{HU1|v9Pev{ny+m;FO36>D4R61xP2!%-kI0Hhli?ZmfvX7SAoC;QLjZF7kg4 z4{^ld{_RZ?PXgnQA3x~+w5Fzp`iCQ4GCFRB+XZg3JrQ9A+p*%2QMU3RVT|#>{C7NF>^H$Vu6}vT z!p@#XkCY3=cL1~--=Cs<7V1s zEcLF$xgEkh=m?;wsL03Pzx5h68*d@X*LAKhH|nu#^>u3P<^|(++UCvQuakr6bOGj* z`01VjWs{fcY#=wk@}3ka&`IuSj$$tA=iHh}hKq}fA6@zQn(mbUz0Q*(>n{Qy&y!T^ zlmc{rlj`f|7&|F3rv{Z|NXyKe>AZVxtj1sJ>&y&2RFmoKKOfPl2mjEvwB+&nRDG6O zl6vxYJ|r>jzrQBUB8l}+eUnG+AAfbz|6jTOwf_IVvhM#M*Z)cVKUhUc>0iJ9rwjr8 zPyPS@j_cp+|Bs*n0Koe1`v3542}b~cLF&J}{vQN{Xh0N!5DhR`PE{H7f1&>0T;}Uv9$Tm`hPFSU^Ar6HzqpD$zaP!7^X?dFk zI~$_|4D=voZbp_!OHCVhYkzA6kT*yXYy<=&Jv77cfu2T6VS1VYA%UhiyqPu*i8Mp% z1UV||TDwA_+D^K9&R}$yCe+hgOVQdAs-R)+sjO{d0Jb#pRI&{43^es{3o~&Af{`XF zszxD!9!jn{p+TXjU=^GJNEZxpbyfy~HO(}DV5AEahw{}%VN@+0&3{6zO_hvPd_7!4 z1FUf-rj}S0bAObvySKHzv6Hc$X^6j5XlPhqumV`uQCG`D(;z@g-^s}XZ|xsqY7^kC zs{mG3c5~BkMZGd1+JP@qu zVibb$Q9-GigrW(GK0q)s00l)_`FOZHnS(=(%;{=q1(`U7`F~kL3@klOj8PbWAXwAa z+DXUVDacaa4H|6ZiFFH8b~eWNLiC|QDuK@C8evMxp5~^`!5W4bjE+q(#@!R4tO+p= z^z~OzK?S;4JNxRp=mr=OJk4};agM%Tf$jtd9*Ne{0)jQ&5&lXpC_jj)t0ofX>1+zY z2kLkdoV2}l^gI<2IBgYU4GU#M-_Rf>6)$rT-VdkZYODlSbv05kRndm(L-4vlux4RE}-crie-Lft^?ehlc(-jmsZjyH|h9xJvJ# z2WbI8!M}QwJ^CLD-4B5Ul5}--PyO+eXZjxj-IIsCC6&FuB!>R{j_ppna3?;# zdjQAt51RVq$>2yu3RJ2~k~6n!dgjQ>!el{08aK^x(BVL#ZJ2i+@M}fzxqP z4{yZAGTT&nozP2tUmNHi5*F6d)6)|cHhWj+LFBukp~~^m@Q@IP+0MJV`uZ&oFNddO zX2!HJVR$X0)IU)EUvf;@SmZ~pdG68DW66E?R z6lUVV#H7#Sa0y-%WoS6Nt*=>b(FOE+lm5lf*w{FM?X@0-Bz%`lCJy!ch6Al|C8A{=9gCBLtS4#k&>^`#@pj)rkrQ`AV zc+%{L>bJGb8Kq3VGH96Bi;wMQBX=H`S)@vM6-l?Opu;hx(v&g__3F27#|+T7tJB>C ztE>WXC8aD?W`8@aE9gi}>G9y@F_2eL+X@&D*X%b7xj~V3BT8i?hZ5bDX$`@ z1i>n+f`QHz^jS>l@syO5rm{4l)RdH_-wn4uRi_IiA-#$u*t}kRt+2S3c=bZf@hU42 zrc|z}EKU3C_M(j}TI#E%zJBY<$R4H?tRA$CsVuv3^?$+z&MK=pY)SWQM_HO6poF!` zDzw5vxT!4dRrJKuOPJCim;J83vb0z66Hlp_(uH7fq)x*eoa?bx9M>2C!OrxJ*U&+pdhB8aO!gSwsxl6wf7B?;UVGSGe7E9 zV`5{Oy$R}8lmiw98R@;33IYL&0k^l60s*W62ss(TQCjzJ$+t-a0b>CH>6fhq0m=a- zmv{yNNq@69+u-$|EX->q!3$ZLnY@dOi`ta;41KZNV``$xnQjpgm+dCEozC6dDwEFR|d2vwhONlhxndear5JcWuS{g@6x@D;K4uHFth|{!A0=`;YXDiBex|&^TCB zIeqb!>rlD(BuwXJP0qLn(!oJY+3VAt?rweCh6w)k_4O19)}o@K^U~6{jEl8GLu=-r zXn(GJuFFJ~L+|`UyZxqP98-0x4gM0@J>0y!S69W11Ox>^o*xy@@baqE4Pj(?BqSwm zh>n!@_PjT5cm!3vJc8!mB=E{R9`3H6mzUQG3{8 z#)@9Y1hAuLB5db={KT4QuuFRP&d|cb0s|+` z)C0cyg(t406%>c+Ke!Xn|zphN+slfkHQ&+9;HQ($eE$Z$%as7RoWQAz$O9)}~`c^PfCn zNtKvh9)>AkCi6udNlxl(&CF ztE;aUDk&*Rkzg$;De3*82&Zmxb$=v_dcVc#{m!@mM#<4xD&8V;*J_=pt`h;pdn>N3 zF(>l9o@)*7{(36mc1Zg_*n9UlNs20AbokuWwS1r}f)8}U?1AYTrn0-bdmgs-U{B95 zH1le@=b_9X9aR}smD5?7IT@MNQ#0Lgy&ntsb43OBBEst8eu$!ox{K&_L4R=-^sban6YoCk}7A;8QpL{!1VH z!JgaA?`JN#`^B-g46eKlu$ZL|OV$6K%Y z!LDtGC%n@M?4Q4@c=H)&obldOFFb4CC*QJj=S%*f)PLuH|90x!t1g{=_L+5Gd|=15 zeSd7-dHl?^r@qL+_?DkO@8bXZ_SUOb{rm@CTKVPw`0&pL|MI2Z`+r>Zc`HtTQ|-l9 zt$M@RXJ7Q4CvQ7#rQiDB{C>qRkN@<;zkh1~d)G}p_*b9#%>74i`uHb5`PIAr_Y1DO zW8W_xz2>6JR*h~v`s?l$Ae(*R(L3(^?$k4P9{;!NO4oc5-Fxc!8ySB;!#}<6M?d}WCFfMDPp-W9LeE=Aa5;O?4L9F>^Qjj; z^JgzQZF2o}=-wv|9sA8wUwitSXZKLv`0xMx?DzFe#+q+$eb=e*U;nOtrPlRlM}P9} z4ZnQwfc4HRZ#Z=Q$xnV3k?+rY!AmE<^Jz%FzeYG!q=|Uj)PFrUiI!%ZuXvd zuwodeyl&*%8&^Jz?w$G0%$vV`#T9>|A@tqr-hE1USJ(5dK6B@vzHa0d8&^JDd}8K1 z2XCHw@RN7_`tb*zyyBem(7>m zC0Eb-HCMds)PGYiyXC;`4}b98r*yyZjn`T?D*g9eUi(h}%GzK2?1qucU-rsZq6g~d zUVG-w4_?}}?aC{zydiu2$xnW|yy@p__O3Ycvyb1jr~bFE{_VG~eBGORYd?SM{rQ1+ zK7GT*&)j$U_iw!5t#AF4OD?(Ox^Hg#|898biNn8oWPeotnpweIF@O8S->rJ^;oGKO z{@T}`HF()a4{!SCd*655{@9+AzI@L;mw)s0PyG3JjmvJm_14E;WxnI-8#Y~e-{pUQ zr2;&+CV_++$B&fAXVO z;Z0g@?}}gk>Q|dDyznoLYqnkaiI0DL_U;DzPrdtR zKRXmGuswTMeC(E6{_LikR;vd;56Jp0`*0q6{(to+Bl|(J$iL%>UwrCg4?KRv7#;5G z>-(qMruN^Tf9zzg1KhIbx)-0m@nvtS{oH=|(FcBU?T#~F{F;GtB~9Y(H?QceK0NUH z+wR$V=FSg(b$aXGSKoK}6Q3_^Iyipwm;d88fApoN?|akvV`D%3^%Ksv-FH0wql2Hi{^V=^V$F){hmM_k(n%-1^>fCx+duWq3)f!w|DN)Wcf4cc z^i$VA*8Rwe`!2_yKf3AQ1vl^f@sEG}R}VdL_=jIU>6*9S`ryp*N3VJ8{=a^~sksYQ z4Q9S^#nW#%`TVEf@PGE4^utHKarLX#8-K6*%2&QJws-HNzj|W--$dO$kNnZ~CqMhn z51kBed{`q|Z6@=TclF$P#l6?`yy)H=p8x2hkA7g?)Tx)9yz7d;85h|F!W%RT46|FfU%`-kh__=@R&IsAfsw_I?>;D1YB z_~qmOSv>E$lfU-nV0?7v%k6L;oGL*XWqJHoAb`Q?>^^~Z~L3)&p!Li*G5hr zy7ZApwEN#D)a3u?(AC#pfBIMNzJL2G4?T3+D^~Bi^c&i@{^fNayWxhDzIVHI&!sPX z1u+zMe0bCAzVL-Fe5ClkjJ@go+y4E=qko;`7`p4(G{?}Zeme5%J$rB7@bDM#YDH20 z>89N)fBpCaFX%7*!3m-=b-& zzV)qdZQ0iKk{{1p@z)QJ-*NxH|Ky&RuUz?_@`virzw^#Ji5;{>G(${GwCAz`!YY-F4Sv-@5TdXYTmG|Fv%FLD19l%^T}i-a7u! ziWMh$qg#geeEp8Yn+|S&#ea>zJ+O7_*4}G(T=A}VjhuV#pB(+oQ!m-Qd-tne{QN(E zRsMgSfByMob$alY1DEgKbo`I5z4qF#|KmSyJ$yKS-g)PZ?b~(QuHOCW+LIUj-SL0BuDQqP{#!S$ynpY;Z;an@?Qeg3 z^z^eYKK{qCP`w=TN$^2>ihsu;%F|Nf6#FL^^Y`$E#-+u#2B*SzL6 zTZnagc+(?4S%2esTYnzOtlg_9ul~%QcV3}=b^HwFs+Vv7i!07Or(-X*+};ln4dO$O zyz#$QKKSa-f9>~=-~9NB#zB)j|2MnNv1nDRmf1t^IqcvC08R3L=X+!Ef9rbJtzVA+ zTZ|`iX;~4vs7xqHQ~NTZtH_4I4!z(& zrw-0VMio$oq8DzK9m}(IvkVxk0mCZmMNmNQG(x7h00%I3RKcE#j@chT$H25)pds6^ z>h#v2LLKNXMn*}^RIDmWypFSl>q;3Q8NEp07ESPvv<=OgHrd74hE=w(e>+bVI#a4` zmNQeRK5aP~9)HZ__^>iLP(g-`oJ`KYl`fM5CC_B{-sQwdGgYXI%fU!>RE4@RDBT$L z773CJyXSKdZ042OU%X5IR-0UNMDQ|$Jw4OY)2ck!47*^>VARXh!Zbe7%)0z^{7I7k zi+%q?zCR}a`}529KP<}A)deDwu&WD{;%5*z5l7NH{ZW} z|HGm@$By-^0X4lk2rzQ#J&{BM7^)Jq6f0;Dtm&DZ&16Wi%s6sA#{>{ytKoq8#R}3qLpRH#Wz+Is zZ#{yF9@Snm0OSCxgiLYqEC5yL7Asqi*bWM=Q-5Vo4oso?AUJjms8gs8W@j_O9lYZD zccM^Buh}pMr8fYOQ91PXSCxGZw?z6OU4R*I*t1*|{Yt7MQxmVJkzTI2gCL&~A98U* zR-mJ$5wayZk_Hx*j;se#MXX1ylaaJAfeci1EoTpMsvP0D=MpU&P;VZD^JzwAy8;w8 zTYnaWf{b`DShzhAK6P42;69GJa{NRaPU^D#v#N+*1)~TbjUs z5BY7ndi(USEiEDsi&oXPOk}z~Er>ygj<^a~)iUm-X2noe`3-}?AyO53h6@x0sKJN1 z3(No)WU7hjK<~sBb1;}AbOP=W_hlc;fq(8OhWHKTQb7tQ#X}a%08=+L0&u=JJb5^q znU)K>QPp*ndT6!-8(i z&jM^>|Eaf&0xopQ$OYSdu>iQMICZXtIEjc8zJCzNe7ywJ zea!V(Hmm|PLX#uT(1&e zLDN}4&H4?}RS+oXh>J{WoAuQ41?0lK62@wzJhW|6Qt23?unS#O@(hex#ebAsV=+<1 zhkhcEq?=`8Lbr$@Q91=Vg6(;+2A`xB{8B9x5o_>?Vc6u3-#G7%P2^5n&XjJJ)v1kC zJ!^>G@Z`834J-1>x`cWD>&=v|C zRqq@sN5;3biol|ywSm9+vwt46^?>c$LS0JD*0F|x>v(ih5%hT&X)Hj4D{nx@pkM7j zOU(>}X;=rY1&S3^oJuJ@4OvizZn}=8c}1iF&vbReFVL^{tG!@acPkOChcv@6v=&TP z^kPNCJYWD#05y$ThtL4ZvDsM#06!2#&G4WQ0+x>Dz99w>IH-({?0+OSI?zq*BB%kY zL=0cDilo5+W@kYG6`_X_YgsqTl#9r?rx1%`5oL7~yt!ZPC-c-ZTmk`rK+#PXIVEC7 z6O5EB&(suv9LI9h%$hZOEKoqeK~<}UG%#I3jDL&Jg@#pLjX_m6^{QtkQDe=T7S#{W zwk^lS609L!mN26n>wm5t=*_+H!t9y@Z=bzz&Ft(d1$2kd17?70O}Gxh1b0-Bb}0Ka z;=dA_XWV z9T^&}!iwg4dzE1MjzO4TCGq#Oji_2R~(z6H1N$vQH2S!9I|wi?qbBT zAbXynsU_5px$Z~tUIs_V|Fnw2$Z}!E#XrSmI4VkVE4GgNVP8h&MNMlN$TS0a4b_&@<9|bm1fUrwOQ?m@Oia^nT zdKGsB?0<7S$E_d-=w``ss*F2}&?Nm^1sb@k0qFW+xSCbOp&;8bGLZv~o{BY{bFCiN zvAlwTaK*CRTm>0b7Co2KG4>Gd=?Vs)W9*lkuIL8J`E=psIc4x1hImG#65omn6^k?E z3@Aa}=vt*V7zS*0Jl< ziOxh;K-KS46`$n7wuN=qN+~Wr1{GXbj+7#ABy(BzTPJU1@x3Y5f`CYD<;RCGlu{#g z*MCX+t(PK=$sVN=P|mo?)hKVbV_k<}acm$_WUVoE0kjEv;EG6S8=f{-9dKd!Gwh7%rZ`DLb z4F8o0bZ+Aiv);X0^M>@j?_$+(j$tN!3d-f`5|L42u^D+RM=>L7>TSWgK zSicV*bB@{^j+5F`hR3f6`ixU1)01(b!oUoI3S5`-tL<&Ew}=e191ioonr{{xc4lpZITT|MkZ0 zzkGf<{%291Hst@-BY!rLP(+6_xq(E37-_b+R52yXm|W~A46RG0iSW9SlDlijadZuV z8Q?meSp@6*=})~n;gw4I5uoJa8WRI@#6iTAVM)U%m;`1KQ3){%V=dGJ(AgT+Yyf;g ziEn!3&cI4|Andm=L}q}4Yy%b%P|i|-a*;CkK|vpJCC@PG;D4|O4SK;UfVNEst7i5i z);cZkl0FFJ*bi^TRu#!sIYklG!Z9Fw$qw@lHc@3Gf`+#yBSh!;B*x1rZ;8UWpzAi4|xG@3Mlv%H%tOE%U1c zr;iTSN_gq?VSf$1Z5zNS7lvA6{kFqw%OMc&o#64UNxO*QGC<+-mxwhcz7(KT>;BJ14&F#p zIj}YKqQ{Rt-EFfIC(K7mpkZqul3lEWUG6;gk)Nei3a~ge4IM3T!0U$Y)>R6@S-M%W z=9e0^ON^iOOtBgxh#bWmV3Oq#q~o_tqfVB^X#^^;Mut&C4m6@T#bnKr&nPdnKRe8$ zv6VmO{eO#UCSk9&ucRa(DAe>&bnWI^LcCs^+G36$w~F$8pqS8|)R^Zv@LaO`rmUt2 znAK!8A+9r}7L@@FFd&AXto=si&J?P*Bz9A@3Cr<-V^`E2tKaaay;kn8BEh6r!ba|(uopjHP(YM*K?&C1}& z1oNs&+q7fjFPMU^W9*&f*iymz66eS46thvc5gHnA}uFO z2A086Mij`=Gc|8!jcp3I78Oe((qF`tC5WZ90IB6cqK4tahL2%I1^bD;Z|lV=P|_Xj zva>(PMGg-N;PX>sjWJLeO+b$BF$VIIz|6kzk(PfsZ)(7Sre;-r#Ia@=IYAC=wk!id zGu+hv3ZkbrTnj)=1Gru-Sj<1)LeoAwBq=%(dNBV770vYg42HTEWU*(;jqrtFufY9h z&CV!+T+4@)(x;j)3|9FpH#h_oMF@;l0-nh0VEEB&Z2kvPR5Z*fCza3l0+mzRFU)y# zj8}i!&ct$5c6hFCV6}|g?Wlf^V^s+!%UMUU0@Mh*OOrNG(bBr5bsBa|OOUR&OG*V5 zO^IV@*gF>)M7uOBYs#~MQX}F@=q9Tgm4ugN$}>>#DA6f!>p3hM`uS(J0o9g~0ZCrRkswN73^~#@3JN`FHK$Xi@loaCwAq(%M3Ei+ zOa?^KhB|fBG#!@2Im954*n!LZ2>B;m#~(|#VND|kbQ8HgY}geD^4To=bC*{|j$VHR z`7G%6Y&%|RhM(BHD3qvA=51OY7j-=*`O+$&GCDHOwgiR^V~6fiJ6Jh*aKD5Npu9x^ zGh}(dt^?M!+IXPjQ7w;SA}A4>a=7A^N(M@te91}DVgo0L+T~Sa;5BG6IczAToZ2$W zriIGW!>M#Zhro7FO}9KOt>Sz}3Jrgis?)d?{gjn#rj?#Bm9WDqf*5UXu@30#d+F4|0$nQnqce!Mhu7(&l?H;DUt%gAtV2Iei0@6 z;-mtt9tMqc6_`5w1BH<~eWb?K(8q+6n^A8LKNJ+JCTC#|_c+wJQbQLhm7ss|S|Vl@ z9j0#JP?2oJtt3`fxeN<>KByd2-Lwu1Bl_n--kCv-+^E$-NdK;`7+2qNlq z`3?Dj4VNe-0Yq8H+G^JJK}TG}fR5OfD$4#@d8a)zF*G#?w!0WK^Z#sEw=UxU?d#jHod0!E zo;Kt^kI+G2L@)wyqN(25AyOh(V=4YyiD3#@%x^HwIV2K4`9W49h&OC2v=*2VjxOir zSTIH~Sdn7UK|CTu#K8Jc`;HHsM$VXnO8SwOnwdg%l~szg zBqI6b7{93>CRz1Vjf9=?H7^2;T$VE96Fml|g*>&y1-Vxo7N{Wm0MjWV2G#)gA!i~He{Lxe)=94H z`QlxiUSafZ3+J+=7Yc%}3hFm73His|4; zpOjFq3GER1EW!+=Haz~iY5nHrOXK?E$TsvMWs$Vu#7o3mJuxOxlnAM2QK(?LX~bC| zM=01~>nH?4cr+A9nGfc2<}k)jNfuH#?oCdhAA%tpk6-Sz5h^epe@Ajh&CqB#wLE;5 zA6gbJip1(l10YaZ*D+hZgKK>&aL>V*7tJQL zHy1;`#b!Ee#*0C;LH9YD@M*2g(|{MvE^+f+7N_mZv5?NTfX4d*PPfny<}=Ua6{($x zl~S+6ju|q4+n{Wqe?>nhsTzRagrc&POrn_leu*D(ZO8v(nPsc<{-1nre{BCZzhU|O z=i)qb^8XM<*s{5MJllB}5a+R_;{poCn(hT+K+n?;6m+yeuAn$-+j9l+`W!44@=S^#^u-_fJ2N`kmt~RdiC3B?uH|b z6B%*@mWB7mMV6~2<&DG0ZNV8ANS$VGI9{>^rf21I7`Zt=S7--)Zyb19-E~ZLb?2L>qLUtJf{1mHB$zc(Y5~>(;VwCQU(JNZ(9HjhNIC zG;_~L(`gRwnFV!)HnKOKBTlnMLzs{7TX>zyDXwwDQ#Q&FH zw_$zs{KvY1<@`U3^328mH^vxY;`|*Q_y0*ewq#s@e*sMCF2JD7{JeltUkl>}Oh#~9 zjzFo2c^(5vXerSX=o`0wdD#|j-YU@?#9JJA=$iB)1x+;YF(vnw7)GU@z~HH5)TO%- z;>FWV=mh5P&>@pJ6yecv6iJk7i_K&*1?&*^QY3T{B}fBgw;Mdvko#Jqz`_O+H6Gbg za&F8`f4|pIQP+^4TAJS=g#gb6%HeFZsKuGh!$=h=Ohf5*rcga+m2%=+qlGK=Rvel% zh+pg@pw(zX7v1Dgi!~}DrBhdp#v=%8_z_(^C24A6DXAZcJsGFaD{z|D;@Nj($3~dy zC(OUqe2Hw&{If}ZYG?idU_E%-Y!)ag^ruNZp z!yR^uNkeRtW9H@@YtYa<{bMq*o*OQ*n9kQG2~zaN1@zN&R{w8#L<=H4f}(rNpuwACg}by(iXz1edYd5OmBbC_LH$JB&nQdq){OmmqZ8kJj;4(T@hzqIIF62Ub& z|GU0#pg$V_Ik0^GcX6J~TpYmTgcG{=?CgB}C*!dty06^ zHLonI)|x{$H9Rxa$P}t$)uv@54bhBqf6&p7B5faXaEb#j)RC{1YY$+l4CI~bcI zNiNzldO}d{#c0@LSBkbrPtL;4Ve~K>YYWWgzI;lsPCE3x01NX8Sqxz`-G}Ore~-W~ zy5^c+*l8!lyG1yvL5QAQGTpl!7PF}xw;h)!_x{{>T{m+?F(KM$Jx&(11YgWSTWb{YV8Br-Ca!DZVNE zw8hm}U=%Z*O$cc=CqXyY3&5r!e~=%@woHjc)nXp}pV*#!enBcAgnD?1>TW}?%ChxN zNzt!J2R!Hh9M_I0w2f5^c6VJ;_wtPO?*m=RM)LpQrw#jGUiI4Y0yNA2yS~3S8vnI^ zpnuu^UyNri=0CTGNf~PC7f{^TXUaP*PiOszWtMt->Ak{HebB$|gT7MIe~f)U)`9C! zx!zu`L#OnX?`&^*zqeNO!8A3HU3ij+o1`JcFF%Qp0oalzAV!(&<=9i<7uvX%P*W(> zW|=poo09sX)?w8MAoALC)wCv>XO#BaxHaEX3n1q?CS-ebc!Ubz08# zil$)3r5*8P`nDLDWNiPQfz5YNiY9spuGB&$cbc#Q;~3VbG8mP=#)>qMPNlz(EFd^%`F`gZI$X zGF`w#Wfnx;&HNTTSQWe>tAgF8Q3sYuYZ8!vjT~U;CQ>u%f0l`hCdeX}=>j8^OToU8 z383i?&ZuSG?VA5oaqAlprczJ2BTZH;*4rL)*)1MGpep3*u%;>)}f4A!$nI&JzFFTfJ6OqCg4H#BgFM7jsGT{(H;vBS2C*r0U!7s*MVmfJ=HHo;exilPxM>MXQp&h z8wA9H*ULMhov9)h6789Q%m7X>ndtSExp(zZA zt}ZZYf4crfaG4Ah(o7Mt9jm5m2m>f^E}VO0TsCqrn6Bu>3MfL8s6cdYfS!Y>A;YqP ziKaO{_!V@N8)Ed&ibVocp$W^#Q8Ss%A##Q~pc4PUcCUb-ZR4P|DgK6%gRzW;Y{RNo ziE>DkRn|QH(<%YVnIo)y-2_F$!!B~L%9bhmf0d!30x>8M9&-^UHU{0vu}KpL1egRG z$3!l|U@W*)Z`?Coy^6vh+K#2Ey48~f-J7?Mjb~M`g+d9)U;drwo@-U9L9=Ja1SlfM z)k}I2x(Kf&d|#$FDVj8G0%1+^CmCypBbu&r z)}N$#*nFzZcM7%pBy}JYx+vjTCGwpw<&)u|a=H__=t75xcu59}4d-sQN)`>BNJeoc zNiX@A-Ae5P9aGN(Ms8Lm9HLIL#SDlmz*C_NRz)>XJtiYiLfdvM+tH~P*Dn=WRn>MW z-UgJ|g)S<221a2pTZK}tzi?3MeSd4+#29)EQhev>e zu;n>L)DEz1L0NRPBp_Rca%6nV91z(yUvmEiQJ7><1(cXYCFsmoO*K}kTh)Sj+pqSY z)hQ^cpx^2^meZDqUvTN(si$pit+iI$SZ5Y|iRsj{Fo4Pv0Z~3vJ-h5ce+>n};cUNz z$mUTOOzVaLkcmAS0-qS+U)F2LWRAjVMBlI`saeCUE)|THz+|vP!&rP$EPHI{L+8D@ z6~~$e&;%4fY8lb@nAmA_8Zw9hq{fCCXjIV-qI>M(gS5l$zshGpSOMd+akL7{%@wZ2 zvR>x=G@B!fW%SJXkvUhVe>7qLP5P*m))lg7=Y~=28#{HlZgY^ zVil*5!*~#kqq2@&rw({n|1MZX7<6mMc2E(zNE;*z6bN_WAX7ume^}5F&`sKrt6MmjPY~Ad}1m=8PsQt;J@}@YtxY zocg?vkyF!)NCeMVf0p9E8?$JTOaVFy7ipxG1EMz}Tu5`Kp7`5&go_@pUbcBk%VL2bm0--eON?TOsO5PfQ-dlbQf`Xlqqk} zaf;w@Eo6GgJ_S(#unNheYHarKuIMH#L+_krZUfte7HCAbe|ZVQFy$EO8c}Xua-kXR z*d`76cQOEuXdDEYrWE1ipR6FO^Q2f^NQvDwkvM8JLJ56= z1BPvFPbQ$xkBGG#;2_u0Q4P^JDZK=s;UK8hL6NQuf0`=mf1x1i98bU$#t=|=gn+g$ zyg?_BEc(tX@ppYn7AOWX%Wg#h`Cg!4*RjlUkd1-Jf8I^#cfiDJ0js|ju)5TGXJv=0 zJPesRoGd?1If?ryMe$_Fi7O5d5^WmQX!w>NF)dIl(8ublpeg#2ck7-@k64FY%YkLo zxjp(5f3xUzZfF0*ta_b`2k<%9CVConiEWiEG^GLw&aJWF>xJE2QrQ#-7v-isHp|x5 zDZOq9Yj7P>y_T?&CG(_f8-6w!Q$r5pNAe5%M}z1g4k8$#ZU%n1kcZw&VMP`SA6^ms z^DX|l8h|U7XJ~+dz)r7=Zr1t+M#({kJ!HB@e_d2Ah76F&Rg+`|C6)>2+P$vc+~KgW zTWuX<^cMER7LesS*0juf2`5b03cuOY4Gkc(raP8dWd}zbokp%vWu0wKL8d;mqs#d$ zn{?K!odrKWjL2CPGLOa_-E^sI-eKW}*bg2Q`UyKb*ETOSQDVgC_*>dZPP_~|yQ9O1 zf1HwH>Z%*af|6rZeSgO!unLDz(d7iuUCh$5LbuY^Fs4EWciCUn|RnXHw<)LB?aIoK+zSkq$Jl$KHz zOb}ycpPW+R!tO3{%(%wVvNfS!_qEN93{UQly{r!RV=tmPZz8QP=rae2~ z+(Z7KA06ZLV+kftEa{~5c8fFjTA*JMVhl~qfgu{UOTQ7(N{1w9oPIu>Czysl9E(NA zX6qlnT6Lc5AG_4|Ob3=o7JvoIbNSI^UIMtVOohB3r90Vv)NZD$3ryIk zs6zwj6oa@}K~;#Q_;Auxa0J}pQB#8%0NlEb21$duS_nOp;n@}l;Vj+8|xSt z7LDx90Dz9bs%@Y_pwU{Ye{N+m(rNZ4U5)!CDI*8*&~nTC)O(Lv*3BcCj0?-nnq}>{ zuq-!|SM%%Dd`?3J9h$j(Z_ZiYpUK#sVT@UZUTg|0MRutUAZvciujr?xrOwgS!^SkM zWw~Px!pL-2GkACaQUDNie;ioP0HC{w+cZ=yi8+Eng@~S2uBdb~^eIHX z5bj1tTn7T(ELl#KMQ*bE3Ror*%j-*cd)TDLGBk^bH&#G{nJ%9#Wsd6#B~S?SOBca^ z3iZ2yM1CMsBGU!ff6zHZJdHsYkoF#fnZFY3EXvkwEa6$zZnqJz_wN zoAKthiiKJFvj9LB?6VB7io`xTpe?Nhqb0$6N={h|9CU9b))d@n2 zELQ{8Eh5-L5Gy$)lYzw|!g!~pp=RI?(~_WSX~FG4sc?rne;P+n+wbTu+D!?7^`lKY zo6wJjTq;7ql4M!IRY)cb;G#RCw6Hf#si5N3^u+=(meG1igLfh6&DmFrG@%Mf@71k!# z0;W)%ZH*fC*q8 zkyQKn`7)Z{5MX3tou-zebCGJ8a)J=u^f%7d0&GqZTdG1-knZ3pHn18{w=0n3Jsel`eJ+5mFo4H_vlR;3cI#Cc z33uD@u!sDVG66M?9h3Ivx#B+q3hM`uS@iE$ot@2u2CdmfFk)3zdD1^*)&~8XhDCaw zvEhk{{kzAvWCA6#CN>cVGqUc8EW>iyln9CS?`R<0wB_zf6~$M3ka6GNZzizu9a8A%`xXV7qqj**c-RN0^){S|+v( zG@o?My}gT@u(>xshm_4N=4@_yhsV5=H&fb-mWV_uSx%9xoEG-?4)`t3^js{FS@irX zLQIrF134}Zk&Wl3qQaP1+6cR#TIV@fY2wNVf2oEPWo-nTLyAIqes!d1il z{UXvtBwJ>B#?OpD@6Zw3a$F!aGqkFE$}6CvYtYIfgD#C_z&0!*|1d6*;=@^m2snt*`T>y3X{cyvD4R(_M1D?)$jgYxcLovp1wceT84)6_*j{m@ zf13ySSs<_Ws=b-af!!w9Wz|r%fE%ED3!gK_r-l7*K0Ml?0zbifhpt~3uC1PShN8?(CkFu@1cc_`nnl<}rEFA}Y8aW8)JhvO-`Iw_f zID5^SOeP1$M2s_kjTt&b9yB&ydKf9Jo=k#nEs=F1dYL$_R2<4|?J>+&3sqLgR zd4$DA2%~Dq;g{vm91cP920BS}pN$xEjdHgG*P=x(hDcc!{3V6k(=!T;5k%HMK5y32 z_E=b_x!MIKBEFzm2Rg!bhn=WGkRxd0GG=N_rORz{LgoE|}DB~Xrxf%ccH l_2pcP|LlJ*CFEUxmY?Nk`B|jr{|^8F|NljBA{GGX1^{K9GPM8z diff --git a/chart/deps/redis/Kptfile b/chart/deps/redis/Kptfile index c61c173..87f6d28 100644 --- a/chart/deps/redis/Kptfile +++ b/chart/deps/redis/Kptfile @@ -5,7 +5,7 @@ metadata: upstream: type: git git: - commit: 1cb1b6a0a407cd71e703361bba579c6f8c7d5c8e + commit: 424349e5f1d571a2dbddf8c6c0621db120986c1f repo: https://repo1.dso.mil/platform-one/big-bang/apps/sandbox/redis directory: /chart - ref: upgrade-redis + ref: 14.1.0-bb.0 -- GitLab

z3WO<@Ybs0A{<^(rBa4>$YN@Z^x-zndDFv$sEn_OnZd|=^fwRhL4qMVa+fkM#2qtz*jZeC{yCWto#Iwi2 zqE(-R1TS5>qu<=RO5d)HTBl5TSuEGIrHs( zVL1j|MGtawlh98sv7f4a=f^6}X=-XZDDahstUDGK6-~#AUiWc*`1Pyf@~0ZE1YY@= zW{0L~-Or!w-Kk>(6}s(E(e6jPW}a$% zamK~1mHn`UT=n31((D=apyeweA<&432nR)hyXombwbLblIjzt$S4#zzJ(?bAM19(D zkYHtH<%9Z&(RoT?p~Qf%?oFs@cP>YJ`r^j7o`D*Fg0_y%xpU{V0)+BNBA4TzJUJim z;}gG()$=pLv1e}lT$d^8i*?lBTB(}sD69GsKVC_gSsZzqKXbl2UB+r{&_F(q&chla zYUZI5fVr9E3!bp(Ot*hdhH#YD{aZ4`??|6c&jn{#bh;ZBdp3rh|5j(GZq=>~o9f8$ zu$Z{`Q4I|ZIbzb;8m76{>-lq9x+Q(N>bx`>O&5g7m2NiEnpjjvhT~Vr_jvjp^pkJZ-=J*yW;+rDz$9EYG-HvXGUP6|=m& z`~Zk0hXa@z4s*IV@>e<~xx(oSBb+TF{w%u3F&NW2@5UR#wcvQMY39&pcyN zU#wPP&xqtuX?SJ-9JD1_fM}) zx8~zqj?ZbSFW={=qtiz*Ah7-M&lIrd_)A7kPR{@A%{F-bCkyjhN$^5eW+w0A;-WU? zJwspY_L!Qea;95E#3lT@EG$ad>`94vu_JYVD<9`_bWSVWBbOuFKD$kn;l$7W?^Wr%EL&*fg^@$b{qH|b~vWRdhU@7kMpu|`F;#9!AhZI9td zPF$t+^*PK;v}0PaC)-Eui5JykN_}CkdNTIPODuThY@c-RWc7D<-?Dq*U0d;fA>c#f z%0+2u&7B{gKhwne{v$nOqSO}~G!7P3PG5ZGI#ljG3DbF5lQZstbZ`(;_WE?EyIbG3 zA%cH>eLY2jwWz4*ytMQ!<6^DQ(3<%tnk%2{GEwEwJO9vbzv&pqRNZQWzeIKqH!tti zRWTz0K|zq`N5wO|yef4=7+D?(Nl6=`Bc;7P@68(?K@~5Lp!qimyz-8RyX)uW<#hrB zmF$SrK;6`6DRRW=(9lqEug9$?MPZ4tqSrA2?C6;Y+qoY@@Hr~ImhkJZ{#X1@B^F)A} z@b7BTzrMP0?V7Mi_%bL_Kt7Lv2a~^IjEgI2X}PNYl8Z}A*`HmF$uPPWfToeBR-n)gr#1?uptSUO z*jtf>g@tmAY{=I*skP}?(flV*SW+dXm&YpsH}?0#4rfGvnS48_wyzCfg~4F?xF-U0 zQ9qB2VM;YLG)S|j^J{AbGUe^x(CX^zg-S|FQY2VQN=kZvD8i|mTph`x-fwYwzcVg? zQF3&ainoZ|wOS{t>qJ2D-im8$%!z!j=UT(Nzn)6C9n$^}_TD{ClA=l&9X@w;Eg$HL z-~*j7dtkbTsqC)qo`bK=B_!<#Pn)Q!LY(g%OA=XUe^nM*FYG+j{G6_j zeB>jay#4U~AKCiWJC3ef0XA$n?fYMxzUSC4?zsHZpYDC@+EY(C<&?MF^uUjPcl_y( zed<$}eb>1AeO=q^fB*5;Yksh6+u;fCbOQV5?<(GW#u;b4chw8e+V{z~?A-a1e<=0e z`QN{tI`^teXPGwWYecp=G-&A|?Rjb}`_SqMG=gHenTj{s{H@{!;%i}-&@b916|K4>|5B}9> zK6C%kn?C-@Pk!~T|NVmN?%4N>N3Xf)vQ?uSkN&!Q1;}P!c=V1tzdQBJoyY&}y3#dY zME9P0{)PwMF!Rh04qt!reJ_|Se*Esc@4opd@5s(iUHHYz@K5ji(N8~o$vM^PlPfR2 z(DT+2T+Uu}!_7C}eCmbI{Mn06n_Pb#y7!4g$A0tF*Pj07**%mu{`)^a`+a?rvF6)b z-*qbd*T1V@sdfF?(Vx6~!!I8^V7>Fo8xCE6@{^xMWGPuMtiaX(HY> z^^kpU?)HsWz5A4#y(b>57{)2D8~OIel@FtPXTCG@=5Jqd#h+*hefPR|pVHmc^}MUk z-1(=k8+paXl@Ax6nEB4Zo2MT9Xe|yh^$3OiA zzKA^ejdL=OKK}UeFP?VE)w6!h6)!vW)XQ!;aQnj_eD^8cZ+zpm){RR4eV5n1)4#Iz z7eBjU))|KyTOF1hZT+y1{B9(v;NuO1ndzh+i2 zSIpl&@pr2peE7Dhm%sM4XANHV(Ziem`QG;(w?DS$q%Yrd&*k4d{S$xwUE{J_Z@u-g zSDEj4`i4zc-go)m-+1(wKOEls`s*M1%b{O=y=$ZU*n8!VnO{zxe&{Rz`{K{P{-+~D zk9^?dx1IOO6<_)LzklD=SO4UfkG}V5jrwW+Z<{S*x9mCTuMXU9c4xEiBWqy!zUznI z^ZKDJ_t;a{pZw@mc$1dfyW*F>`qkzOFZ@g6nr&Bp;^QA5{@&-RTkiq(ruU!w6j^=G zV$K_~`X2qwQ}6!S&kh9(Y|q{mAG_t2KfCFs)#|~|1G0Y0KAgv%fBnhGevmBk?|9-D zpZeGXj~_8chx_{a{^_=<{rBe|JDKYMx9qv@#iwt4*_&!Vw;z7=fnQv^;Nwn!i}H;`*Uur=E1uNpJm}aqad`ee=S# z7yiGeyyG43*f{;v^^bKwvf{qW@#l|jI(Wg&JAeG+AOF=uPaOW?mruIp?YBNSbNtb3 z9=rdqUvO&ff>nc=Z(Q;88%{p|={NkJJtzI}k#Ai6s`bXJzVel?jP2d~=&zpG|2I*$ z&m(_y{mIY1^Ft@Y8z0t)R-4IucbM@Bi#)`~KnjH@;%}Uk<-u z-z^uMG5FFKe);%+7SFrx~HRQ__itdnYV7)=DhRnyU+RL+y3VH zv(G;BwULvDE`8(??f&-(HTnNJboKSupZ?Xm@BYd|51sak)w?eJhW4$0dELiuxZ$Ml z-EQ4;=?h;$422yZ-t@XJeBlcpDZVdbZ+ic>f4}kQUne<+?s_)OG4!gRj=Xx$-kUc( z`~|#PQIvnWY4^%sKmNcA`b+=tc*Z@lq4pR2z1qq{$R<*{GfaoY2q z|Khi3+Ny7T>swp4b-m=rGgtie!{c|{|L;G!=jAI`zNh@5`t$F+^G;$%Y#tf;%;a7F z>;HW8qd)%YJ71yx;L$VTMr-3pLgDQWBc}9_Q4OnX2nDA z$-I5vzRRw<>Q7HO?X<298&13S+H3#wk*jxqy7uG+e|P-fu50cwy8qUVEAPAU8{>Ce z``h0hJ^k#9Pe1m|&xgmy|Mb+{1()g%eDp_;-}K>gjvU$e+h?A9(b;F8?LP6~ONa*k zz0Xx&&Z0&?GIIG#AA9hY*Z%Hzzx$`#t&1+b{PLfWDu%K4zyIUbOWu&pzK}Hd_P4+O zHLrQi7Gm8V-t@>%*57#EmPayc_bSS(KeOkZS7=`yKSR0d<=g+_igVBD*h?+9_d`U3 z_|PM7{I8V{zWVcD`~BlLKfa=I&?L|Q&8~ASTGgs$_RxC{J9q&=ll7uRK*=-Ny>~e=(o7ZV;&L!j9aW)j3`#eK zy+wi~!|wSU1eU(+FvlqYSkyFP8q3H2=ktg?lc7C3a0U!m4Y}RT?yz|LZnH?|0*qXGPbAR*hN=WD#R?h(YkFp9GZ|7WGmc!(F#!bFD!IV4G&IcE zqYi@W%t7YZF`%18!_yE@7)PlR8QB`qkRThog!P^M5_0m?bMcPl_)YmWlD4IR5c z**rY1kbf^wvRROuoy|~ijvdSKTi=`YK&sddDj~-~+7{2z&GJOCf;7+2&GKm3wEWjw zkD#JQwbu*)Ilw9*Q(Qa?Koz>h%GM*cgM#Z+*^>iPs6Gge9RunVs)O0tOmGLUxc;3e z)Y5A<%t7f50Ay4Sz5P{XpTjMYen=N!1|0S*7e&94>d4f@>uIEyEAAl3XT*nGoRAgh zXlaCOiH@X!g{33wfm9LeQR`$REleN-6Qh0T@) zp&%n388R0G#g)Pae)@rsaZe zRJGl@H0*4&D6k#fbW1>iwylP*X!R=%f-|rp<1W^nBy~Y>Rc=VAkjc)0SI3coAV%sg zQ8F$C#3|hEL>7hNs#ut)>!?j3-#JzdiTuv7Y9Qy^Vb%86gj_O9c8(!8$_&ynH_o3I zBb*rL!#26F6&`HBbsb~4#aXIYPaRmPB)QwUg-V(s&DN+^lRQTuP8f7$=PD9;@1KevK_3!O4@!FFFP0PZSIoogXZBI1Pa9|SUAF9CHQb3K*~ zs{oDAKhA8Yp7nM8%qgF8`*H}zc@u8mxBVi-2L<2TN`V-va4mNTWBWp!#JRnJ=Dg`{d> z##qMMT(CBu=`_B1cmz0zZ{@Z)tDFKXwjpme%o}yAL(i>Pj((Je4zz{BM%6oq%8~Ic zts=1KXl>wc{;UUWJz)E`P?u7(b*y3FIv$-=1brSx8Vk_i${Wxz=vVvCQZvI~8rFep zfno&}r&3B!Ll%^wo33MNUJ+@)GhN;A3-qh~YA=}9-AY93AYQQQH!X}K@ShJ=@^~1Am%W<&;YlxR6 z%qYjYYX^FBZ@e(O=D^!$FI+P_yGjAwA@qP5;93)|LomS|6{H=?K8?8TMB6jVPkT=j z`=4^~eD;1_Cmk2oIBg znTykg7}JP2zBLBi3UmQ!k_yKHV&&9KW-o?iG{`)@HE8G>)d#kc4tjgR;84sb78JsK zV@)L;8%U*1`o2Q?Z98=l+R&}2uB8g7dV3Y1U{rLF>;KpVt4IM#Nk@i8tFWTE-d-hG zzGD#P7Yf3B8xZDw2xFk|$;*g@{N`~S5_wp@A2op@aTH|39)F^5jElG-(IK#*1KH+l z4n%tcIlz~h91t~Cu!8_#m88-{1<=hhCQ1oiONlP_BmS?TzcJ__(-no%6~|^M4ScgvRAIs_hb-NsyBKjS$ew3tY69pd_G=%sSd1kq=g%uYwv0^VK%=K(P3K&z$8{{PU?5zvEH_s{MwLa+ z<#dcagnPPz!RHwJ<)$mTfpR`wczI44Jcl8k5vjztqC&;u3^@ZzP&YceAF=!_?$bp7 z)2pyNuh_p8&Go;5fpr_A`d{Drb<6tSVmxi=f0E?*zxx56(OEKLvCH zrftwa$1TfMe3z}zf7}XUrGdhBZ-h#bwi<_f@bxqYm38bob)qwo6;Sp2RK+K`ux(-8 zwNi?Uk3j_&mLsLe8_8Uj{np7FS$uDbwICo8Tlw)J45ida-F1?F>!nCzvPY=|lrwP8 z8F-LJ6@-dK@j{24?wg`5iDnv9Y{jd`nQMzxoI(y5r3~SZd4g)gfJQBVZVlNEDnb`& zgMd13LVV#MQ$x;}XBey&7A~P|19r88;t{6x72{OC&96=W)|U;qI=n~O3X6xJl9Wv8 zJz+`;9>Hmp*JKXlafvcZ$vDdSF(t7ch5)o}LbuRcHIWg+e`P{lvq6Qb@h|ow0iu^c zw;YrsHIt?Eh@xdM0%@pY+Dnd~&Z2Rh5ja9%bdLWKF(RQ$gbuf~i8?G+?*>dBn;9Kv z^@vf}guN5sY0l*Qt1#?{OcuXGgcc>zg9|uG6U%jAg2Z+UT-)HT0XFckQ$PW#j6V@# zmR%~-Y|)3ageL2WR@XZIG}Hh2Zu-0ofF}BXANdy1{|DAD$A2x#(@y-?HtM%<5h%do z6qymoBuf%?;OLkrUp930f`QnUA2bX(Kx}wyRP1bF+4UP=qd3p;UVLeSkyF!)h4sa&2H#4C1>N-n(eI)=%Bt}WX9$ZW ztdxzdx-k~F;5tMN;86!e4iJ@bPu)g(qBvvo`1uxJ#zp5EJ;Xx)<#W7(jH-$&jA0v8q2GC(cz<+*$t-fY zDxZW&E?%p)GA0*03PbBsX(GICq~z`zavWVlUeQ z9B~jaWmwWM3MPSBL{vh|!dMIS0Ccv7H5&k5P~w{&xihd59tis_43Qb&AlraN1eCKB zpj@QPeNfOxT*)(xIyme>gI=%-pl#E^s+s+WwNA^sqz?i)_QPATRYkH@PEka)a14mz zYv@&-8=-DR$Do^|YRj$(QkGi6HY#S-%xFo(g0M#X0A30AdSKvEywea}0z8MdG0sWB zFylx^LBvO&SE2_&Vg*{lyR4wEGWm{R%ls7#?S5?(reSVM2y1~AHnq1ITx?J(PN z2*)4Z(`5Z;!G{a#|IPRHMe{%9Hw>&>&i}M1PaEsM@BU>>!9{oje~n-sCd0WGS2$EB zczkQpE@HS0P`LahVvUI}1t`_J|Fe;UH_}uNYz@8W@ncVS+w8;%^N|v0*cymr7qEyT zpzozLiJ+|4kSWv(4h(&C{8h1v*a_%3+>Mi^Jr}4k9q&1nn~De?JFq>2nsbl6kWTymJqMk zrnZ>l$E~7#A1EetCpG4I4m_8vzA39I0%kQ?O^EAEsYPW#0}P1aCu_e^xif|8Er}hP zA!Hs>hh-RBhc(1oBt7ngwk-k$rN|2c%Mj2_4IODzYn2aldhkTk=_Zj&zNJLJwNa z>6B@FRJk~9_9YxqWJf=f0g<$!P8~H(hb3_iF$g4f;4(i#{t4Id$I@+B)5rncM6M4T zb_IfbHp~9pXUh!md8b1k4e6?3aE^ZjI%9)VZ+#= zyVMR=4j$YuVFM^{QNRpY9c%_no5+`4BlC;>s38Hp+ z)fjjUnoJHG3Mr?y%(7{r^7L>jUC<%09aPgT4@;{!pOHdCrRp?pML%UFn`xydOeO5F ziXcXtTdc)tIf2O1dYbwFUCV)Gw4m|d`TY8L{P(i|e{r7n&wt8ilqMK^fDr@Y#Pddi ze~P3)aLC9%o?k@CzBs8stA{}&T?M8N|3G1+P9LdpHS{szxZH!#xf) zuGG*)N+oE#mWWwJhp8JlR3sa5D~Xj=F2jPJ4=M*0`J9!!+Bd7q)Qe=uQb)5a;+Njj zME(ayyXLV1G?D*A@JI7M_xATL%m2lA+LHgKh8zqacM8&TKYo~tU>dc7j-7B&5QI+( zCM*TaS@ zTt4p`8`~o38GlRb0CJ~N9$}#GxRY?hUh-!9rRsl1h z05MuW0CG7E6)g>A6C5a;J>Ad%GHaj)9Tup`Hkl!d1Z_&c2rd}$1VO6xoWC8^oFb8? zBqt^PLIWXeL#G}IOn%VJa763n!IsaUkdO8uFBPe+1&89(N^}F} zOjJQO?NEE*S4?dsWp~yM7T}U&RmGCYDA<&84YxA<4O8}4TQe)xaNtoQqv0Dn5(QNy z*nQ_SkZ-~$Qf0afxw{L8$cI%C=f7W!Q`7G$wrel7lZ&T0Q*0K-?4X*CrdeQy>FN&O z6tzlV^%;0I_aOq^1meCKwiTb61}#Vg=pir!y2VaQ08E%eqz^-)T9T{Gcb3)&{es;% zR)w|*8u(4wzO29@89~y{EU+A2l6x!Z6r!8{1~4r%$4j@ua_QT4k=^?#RL_U`knY*H z%ZZ`>qA?$Q_@w{fn}ce|!Du^qIXDFPpS)C<%jBX_BF}9LQBB+y%7%9IBzA}djHoFa zb!pypKIy>H&_9=-6ZSlR1yS{(<{_jP3+R*>^GhP6&V0kW2 z`0QAQK{La`awE0hXCq#I4=guG|2J+~ZX-FL*qZD!g{B6&eb0mcBx{n8?)FDJ)pCbS;i;e(!)yFF&9eXpvdd z9m`~4(=<3UJp(Pr4RWwZLhDiAjtfmK$9u_1!jb!%Xv8#j1df0q*!zikH`=)us+nj;{)e7w5(qd{go7% zs``PcK~Lh)48%cQ%OPl0!4_uk4YKj3u92-GSF%1Mq3;Q{Owa;vGIp#Y)E*DbYpEet zHqwGt*o%=f=Ae>(q@`x2P+et}A}xtXJ~_rOu!@5CR~Wt9!nrKzg@WL#0z9YMlAnF@AezuTI?IyC z8UE5*Y-Jnze-%19)C%ppf|}_68`eeR|N8P9mhb;woM$fj|4zaPTQ+xG`xgwhWORQq z&{WNzo_?F3)-U>47@a=>rEO{aqCRg9dTwRTN`IuSWR)K}#ft7Cde>(w07=E8EqQJw z-E@ewLnJY&kYYBBTb7$*IyllNCDdy|J48NaTdrC3U=5!3PBJa4Fyu>gSnhJjPX;Fg%pl^lN0ENV93Vf zmpg5Q3QWh5+)*<$8cr<_pXG;^g^MDwy3zm%DRU;B`x45xz=T1q1wd00OpP)2hhoUL zvcPrBmha$N-wNDwFy=+G3GL0rkZ-Y>4x8~}5N*(XjwXCsEAuqqMYBuXe3!*(J98|g zvn`#$>n%-=RB8)(tbNva0mH=(F3C6g#7zhB}jZ9?y2(1;lx5>9~M`v8H>07|`?d0|gx| zkSi#T+V)&QynaVqLE*MiTtST;IN>Hz95_wgNs&RNyOWlhD`*RJVFBW3eT~0fELYM5 z60!YpCldSCw54Ist!xc=MQX?AixdYGeZ4iE&DwFL$WSyfQ``4@G4F%i!;*A}aXIz} z;1FXKzShdE+p0TX4n&Qm2_4j+bnK=~?+4MsCi} z71}}H8wX_B>(;6+(K)Xh)vO8~F&JBbdoJDp-t2SR>&6Gs2HofCbxUbwzFs%p>=O67 zwd|WoQ;-+ZH`7rgCUpeO+%wX2nuB|0L0zGZ?2YG$)2z`D<|F(T-W7VHoh?i7X~X|# zTi7i-2p=}ubOAQ;|K-jbzmME~Wfkcf*wv?P3bJOoNRMa)(rn)MAZ_Na@s7qwxsB8h%63|lrn|6RqJKJd&>guTEiw)zDWD_Uv{t+VI-EE(;W$k5w$JMx%INjg$)RZRFiuU! zvTL#}RQV3Z=17u@wv3(-lzTB6_Slu8?a`C7aB~|rm7k1i7@oo{0Y7n9)mrVC=hsA7a$8E>u$-O`KUDwSVQA~(7T91K{EmI;d8i z(Vz>HyGRdW-&g_jxlCL()o`{q zA5-dBlxT{&rc*L>!I-QnOFx$<&Eig)h#eAZJ#zECUzA>eA&pP+B$E-^)I2Gr-(%l& z?nIrIbG@P|m~m-GJej^N1|~VF6h(GCsY+lOWkp6d=}mkyycXLAmv1X1(}6E#p(17E zj(CoP%)qOt#4baHrshkI(0zKbp4z$=QK}yWBQS8lp1_tavLcMN2M?MDO%bek20mye zm_aGmIjY%|IIysLfHhAqb&H8L|AH2%X<&6ON7N!>iw&(J#kmw9P(V{tiHR1lMnHY( zoj_m=6HCMBNz(t-3NosC*|Z$gkv^K}|Gn$_BIiHy>-yF&-~X{FPZt=2E|FC9GFL`) zvh0|k;OT}&q__=>Q?QJ%n&|?2Dmn((vu(?9F~AjM7&IgXRH0j}=w^8>aF79Ay~dZ# z;5{_8OcyXwnFUdIGrt87Rt0a!s$jQi)PZHvngk?ZBL^6|iPVg`W#XaFos%r@LuyT%dD5KVJ(b7=QbI4_p zH2=r94sY4HRjq0r>Z9@eU)R?^5WW9-V4!dL{w3ZRV5}C{} zIB+g9s^Qlcc8ih$F*#|h*b7<=I4}Fh&E0Ro083 zfZSt}d`=$D6i{XEKwMlSH%5XvjvUhRmXlxb{xg)G*d)u$ExWX!T<`K3+EmgmyH|@rYm}}0*cTiDiGZppywcJ$gpf+ zqG?VKegz%nh8X>`Vvztjb)J$e`h@7DgsKh_8-76qy+c;=#ioc=cU@W5{+py|Y zq8t)sl{HWQv`T<-<_K$FH$lD)CV|E= zk&7@G3og|g_e@u>qA-ZIV`-{x^<+W!=IvwSSru%dPy+Ioek*sX zwm53qp4+@aW+vD8Y4*KS)n+m?V3N;x=wnJXEe)yID!G$j2C$2o0R-d)AfGr+>&*Ps zldv@dCgtGkb9V1mxSJ)oW_k1QxI+HDK*>&mMvzpXqlF+LFBTgT+tN5nVmPraO#sqE zew(hI1egy=(W=^(iA>jrCvXr=hWR875{8l(P8JRlI+;eG4GX%_;&h4;VotNG^(Sc_ zHlJ$qokHzCNgc?9E=o97iG1fv`DA#gobE&}y3ipaUXsCL!?~NSl0`!&l2M#V(o6nj zw^I8+$JFzHk(*Tshp3ZmF$3ZX@Kh*+RZ$I8kI4v>(6$}Rc692+^-D!oRkdA;w*e(~ zp^HkMfl(ODR-u&ZFC3J*Ne{z>5gDa;11LrP_7K@FluiK_V<5Hx<@n~|5#S(fc}@|v z18iGR79A}K$d;iT8Q(GoM7GVB+pmHv?byfT)KDaX|L2x+RFCnsd)CJSJ zVE|-ekA}b}M);TY8Zw!qa2nA!tVwFtFsn-iqa`pI?9eb4pA^d;+xgIWZ*Il0rU5ho z1&~@s^gSka8l8p=VgRYJp#~aNw1em#yZ9jOu=}s_SrAsh_-q`l!g6zkYq6}CIX}(j z$YL2ibADvb)hSKbf0I5crFDg@Du}U8$ukT zB2Krinp_JoLg2utsCHp@7cJvhmYenCKe6k0G#!}=5(Z#@}F46|c0tLcdILOqHGZu6NbQ8M>YT3xp{mGI#`uy7T zZ++PSH{mP|lSu=QK{fZ`i%b{6*&OUUws7YMnIs{Y*4I!(bZCWMJbBTvr=j5Kkob7c zEb74%niSk@D8S+rGO4#^8;|DzP|O9+Wq=m~$Ru-tIitx+Yq6O#JT~epr#|mvYp8qsZDf-p=uM!H6no0nW@Mmx4iL;jr%fFl|Q zL8d81IQb_l$m%>PRu@uYcMUm?uA#}M)C=zjk@6!BV)8+FmdM9CIP5`#;9DcMH3cJX zM7P!%1)FmuD@zAu8(!e!YKdm4%);0H#?ySBE9Y}?#ccCwEV|~oG(HDc);1rR@mUaA zcvAZ-adcYqh_lAD5i4*kEoOp_89lYjCpHnO6JCiP>`|(9|EH{pQd4AWsQ!iBU7|tE zQ%NQmC7s~D82YAAeG){`$3qLJP`&kD=Y>8$u^v@>P9%;RjZi{g;DBLU+mi|C^CMy{ z2RO)ebW}q$PD(EUXgCOJbx@=$gQm**Unqz=#}hDxF$5GIA)xIGZ_o)Oi@x(p{9T`t z1&V>pvRhF=z85Iibu6 zUgzQge9pCro`zjwTO|uksX&5rYb^MBVRx5QHpRh3xoMBhvbA+euUoL;ELrL8ekx> z)9a#}wZ4H-a?oK9nXXY6m5U(*WOCIcSwV?q!nt;@t2cKzEbLZW#~8hZ{jddOxsEk0 z^IpOU6Sl%{_H;u7$gJs(Wmeh25l5$yYgAchn^Taf5AEo3KFcPZHEUY8_0xFPm~2ZesZ&d#;X3r&<5F*^R1c9Ih>!_MyLFe0aFs^##q+%}|&GgZkAU|MEQl$M7PSFop0Js%z%RjZSR$EDW3;LKawAz@$%1P(0W zwSBRlwu9w5Dr@KXoap|S&?5_$CPz`_V5k-jS1%;fh4iwPk|L<)e2!pG^3`lDKUPd^ zeE+Cq*tQ=vK@no=cdG|+CTpcIbru#<4z|iF*0fkQrKMB_6U3O=C#O`nu)9kfGp@0; zY)$AFKHoo?L_bj^Jt+nlb%Ddz76@_0btbFCWNWBel20@G zMN$i3zOzA(hsf-d7VAVQB<{`&CpMisS>xInhcg$|H$rDRDDZSm| z%)J)qSA-ZtQ*&U5hV9aCM6}W&2^y!L59bM{p%2Gm(XrY3$FEkM=laJk^*z%;oeh3-KuAb&tQ60-LbhEq% zmWc+ykp*DE@?3s2nU?@AEK?!xN9j(sAGMq5>H-rsD(cVxI>jI^R!|jUDL$Mu6&wL~ zc+}Kj1^~Biqe0T3Zk96uXaTtfMW~f1E~R*4(Z)IkhD9TLGXS6?uxcA<5NNcPs#}?i zbeg?MSL1$3%E&=HwA?a3_197n{OLkzJ|-$eJJXEBa|^sdIGourUqmcs0;V0UQKpt7+)3yLv54FpH5( zi;tFeS?-vFFf!fM3?3eU6aWMr2i7wH=q_S8!5Tvb~(j}B-{ zYr$wq@Sc)W)&jYkT{QE9qVVJNnvMya7-)5Z&?3v#fOU%qwh+WhPRV3ov4}9wZl(dj;Aa~-4Ux?< zoA{u10U6jX0DP^I6cSnRx1+j`N`gx|U;>y&B-MU?zKrHK1Q?lEr>UjrT%;PNoFGIu z{f)D=09#cAT)m1gX|K*_9$O~k>Bta~z4(z_u_ z;V%u)B}Z`jX&cj`2UD*}S;g}>%Fh(4H|%jr$`jdYhhj6+zh`82mf|ndB_|Q3XpPLM z@Z@hcn?T5+%O}{b-Fvo9sO}Lar;3(|Ed$LbU2|{m;wEhF&CelabBj5fo8I9u@8r#t zHlrmXkxG_RBrB(d{k;Qzi!(hJOJo*3|B4V3Wzay5i$i4Nxv8iyCYCnBE~wUd4py4D zGD4~$MOhoc=8&RLo?jg)+G1wRXa}prRKJKc5y_UBp7Ar|&pUL)wj38o%?z#Tp7IK) z=o+-L$e>GO8L$nD$Uh7ba0AF$;1IS<0^X2vOeHc;mH2R0Ap#C!w0;2OavCaH8p>vp z5Rsn~BJwgK@|{6MegP1XPez1DE4Ei0>E=Ox7Ral;YHucUV7Cc&Sv6EGAP408*Mh#@ zzTUMwOG2MW5DBIs2Gk%S#!^W)bzDJOaF(pByA`iMlYJ3J<~iBAunS!e=d4oBt)Lvw zwU}KC+=`At6&|u2ITHiB8U&MJb9Kh|VihaUEF;X)X|cR!}cjL$e~F1QvE5td_H ze&BzQ;;Mw8>p7$;O=Ib=*iieKK1Ew0vyv;oG+e~*ijM&3E=ER)m{`!!xR&9gZ0qhF zY9_O0&3+n7#{r*44gxyQ?S^EuIE9TY6L!YcLA;q?pLOAQgqvP5`v_~ADD;%&0rWWX|wdR7Go&P5JtoJ3G04!oY6z?n zJlxa8OXnzXInL!xpdlUZ2{RK5YPXp!EHv*m6tQ&eUqf?|21)BIhetgcb_EuYs~72n zqUvtNs#;}aB0~9TSP!{fMQS@KO&(#f5yGe%a`1cwyn#*<-De}lT%+9Wz_nbn1Yl#Wbtv5i5sMt?}Hc^<7l!zo@F08Hszk{GT}wqg)YUgtL5>@K0u$5l@W4 zwLq<(Fw0(yN}d4>-JHUV7evpb$58$OQUI<0OxJTQM~4RPaS*nQ8p;vi`sly?IorZ+ zE&znlxkqZRm60SAr$>-k36vvap#9})eL2_SKl`6c33->FeirHZ{{sL3|Nq|z JQl|ju1^^Df;YI)e literal 82358 zcmV)bK&ihUiwG0|00000|0w_~VMtOiV@ORlOnEsqVl!4SWK%V1T2nbTPgYhoO;>Dc zVQyr3R8em|NM&qo0PMYcTiiIZFus5DDRes74a_g@Zpdx7&t}hIfSK@2Lihohea|y9 zFA=u7TL-u0wPZ*y;k&<&Znh-Lm%c!f8T{-{Xj`f(Nu^SiR8`7Qgy~>!3NzN9!&&^N zJ9vh};qc}2=i=YtaOnQK{d_q5)AsY>i&xKIZErt+_NU?Y&a>h0PhfZ##JEpR8O;7P zTp5?!xNqcvNkSN8m?U(x0YC^DnviTh0{f7`3rNuhO!3bsqnIQkaJ91m)3o^cvcJ>c z*@#ezk_aUsMs&0hfCSFa2!v!dBgqB;8A=JoOaPrSmeSE+5ORK_{R_+zIK%yr%m(W3 z4FDLN2wDQ5-US7$D~)-(|Ed3JBSJLHaLUB1_bEyMC3zO2rvOG*FbPovF3~)=f^m)j zWh6s=aL53rfQ%VRK!(OB%TNRu0gwU+BFG@1EXzZdX9!S~U7-w6oP>x&q9B9`2uZ>q zPIx(-Oz2ZEg>;JOQxIdy=uicfbU*X?|fgT=mI-We5#s zkTR4NpTs2Hz#(s@hG6y`q#Vb9G8kS`S$cqH6ZuylUI#ln!%sWUp7+yavT=##*CdO? zXi3-sZ=UFJ5gR}a{P$`g%kn77aQNR5q8!`| zW(+6&aaL5YK5WQ$k}5fx0(V2lX)cLKc!{z=H;C654P+nmF&S)>%=5gz-5&-Q7yaSJ zm!5xL`Z48yOv1~%z|kWAhtHn9aOMBbtLG2$|302|3vWY0zu;>Fo*>FbfKK7gi-+sCCYWUop|1Vy=c$ok9@jL?GFyZPLO5jDzC*Byw6bac7VWFr2@CZaX;#w4&A}&1A7=6NQ4q!&|Bm!)T zDOVfDc#>yA*?cNW3JBl|XDo-Y(6(@hxOx_0Dv*JTIf&30<}nj^Dl`BP!wVGC5xBV( zKTUmBznegYuHjsg3P4ISHUir(o-oP=>6;ba0#;r_H30IBch zRMwwJQl#$p=n>e1&#`BKLIeypa-H!tcG@Kz8jMa9P@>a zGTv1`lQ^HDO}bSDCAH5KQpy!>4eW%!-8_4@1&S}5dQd6&2y-?q>U`u-HzYXDO^@vU z9)a0h|9u2!d``F>qFFP|@D*ezD7vx=OuRCiKPu+Ao=lGlnn!XVshl-nPv{IL8ynqm znO`7fHiGw>eSgX?P?jKus8$_Hv5%x>d+OZyqvO1jbeiH`KJtxOXZdu zm(q|FimhXV4;Y-#fzc)bq+iGw2f9yc=^9$E_SDgzDzzA#REqO=n|L zu+ef&|FzwZDCy5|?3g1sBgq9!E}dNx0P07Z_l_)Jjd{mCg-0|`Q?aEJ@LmpJ5(OEe zDQCbdq>7GljDi>^my!~>ouzlm1nScig?Ky%uoTpCDCFmTsqTom@MJf>hI9G^;IT2< zn1UxUWQejSPXUT40u(V({BV3k*l~s^O4t*pp`*dzvY5$zOa>7N=^&>l3nn>^&_E!d zgGXtG0zQ~HnFR8kZb`{CBOoc0INpmLI3a|oZk$?N`4o58qrU0~#YnT9GH`*w3?{jN z5oU;6cmO9t00?25!VvX6L+5D{gY=RP3S}oqNfZ=YRs-G!*{r}_4+j!H>I<#y(Ib%B zYv`j#Vi_&h+n>-}epU;w=%i}3+Qs*go)N}eP*B7hQ)BeVIVr|%z1qZiq&1A$F=WjMef!yQ`v{n<4BpBn2vLMTaKEkyzHT=3WxPGRzdOd`N zA_pyE^>`LG0LyYz1;!^VPEgze4Uh!rqFg`_4PL*jgI~a_YMxc813?Cph|IwDFbJnG zgCSq@VVq83lFv|vL$&qI#Zp2T7e9rF(7GY$^*nv{iCdG&M9vOyre-%65-rOc(VTbS1z&wxhS3#@z&Il_w`nH*iVTn^F`}Ae8<#`4(cQH)dFan6 z(gl9NF{0od$rEOFE4PZq;uB6NLonh4lT%JNAD-ljFS#>r@m#?Sb4Jy4xUjY45`yaz zr%G1sS>nZ=yv0sEBPkBG2rm^@tM&+d4uo)3GiLYw54C_&ZK{Rn5lp#B9FQcQ2fVEt z0LWMT4VcTt4(!YQ2XM0gJuqrN6=;kX0LB@D(Ol1OzC=-Yg*f+{imx0c*?<{LYdK$* zcn4F-{Bx3LAj~NvGe^vG3$&aX35gJu8nT0FRJVA@6Q=sbV?!3O`AEL&+m-ej2vb-j zebv>wX2ca!S!le3sBI!{dBP;3;1{8D{HCl6SAOVH+{jSlOA-%>1vs(Ua-lc07>eiC z##Dy*!jen?g5gvM&IF)Y%H~Qu`t%jI#T12khS~g)1kBeYG7h8`g~LG8T&M+hgSBP< z!`lz1Z}z`8f9<|~>mNE%v$Vn0?pk@Mr~3(P<`j+d7+iA!E2V&9MX42TmE$BT2$Rf% z5@r+Hgin0$jEtAA!<1&|;1de>W)TIuQG}&dY7KmrCtMXH8UI0tF>th;f3zSQPZl5m)yt;cC@00KFiX!A~A*&~IKf;i+eb0vW+veh>`=Y~5r4^*N%5BVsa3Zfc#1MiA`SLf{8|Mb!!ty3 zrU9PGpQ}I|LmcNBI-6#QPDvbrALI+biZ@F@rFj@4N=vAx@Kp>;k|u zY9sJMe6spnzqC6}zjetRfo<{L?G#zQ(&mD#y&P(PU5rH?$cyo)UAY7JRxVu_Vh285 z7-mOKT^MdhUiH8gJEi8^yW-aEb#SXx^xj%>b5AONwlEdPpyfFkH}$nTNs^-F9&qaL zss{6kJs%WmXO=92+Xh%7uS~NHNe?%1o{XqED~<6CGk3*n-M-~UN-j1SmDk+B&tmFp zUt$rKXz@~^7Hq{^=rb49dfg1XXpaOhexS%e)D?r^vOf}+lm_EEKqQxef9HLYreKBhlrBu~L9VqVBks{I92ox-ZBK&=x`s-hU1 zZFg)+mGx^LpaSB;!({5lT?VTbQJi zm5F(ZMs`ujGUl7QrCV&`aQ2HKrGjy4%H$g@JG}3$8Jnia!H|t6))s#M;d<5-H!4 z17VO$zqwVXR?!%)8eL&@Jy0!?#45jzfkZYiR)Dvr+n$fuI`@|QA=q#uG^uudW_;3Y z3Nv(^5v~y*>7#3K%HIMAC{89Z0;&97o^68*#I6xagwGBcD?dstm;v_KXp73f+Lexz z7AT5>f}&FV`5IJuV0y=HJm!|gT(}}Iu0;W;UV&7+>w`me?uEzTquwc2Wj?A?F5ihV z88dm7JcU{GaltWHlAMn=y29c}WB@6}lSK3hw|WPUaKe`e{#(-{JUw8-aPh`u39GGj zGDPqW!@iC&;r{-5r_$&V;8dy;P!b{FG*5NGUC_?|TOpFabSTtonmvTof^wl3jc}+J zYuoxp(OEJDi*=*$63r!nLIUdp>KSC=v=ezI@=G*d2)AsIiC(=~h5~TV7YAzMZ`D=$ zCjbFJJ1Btv-mbpdF`J0hlE0g=~x^-j=(-SBJ5O|YlZ$&L0Q8JF&?9E9>(YmA(vgYs5a@AIPc6E znQ=SE_KUbcW0DEu2ac8fm$7me#Ku-flQ=w+@dec9XDJWYVoaHEB`J@cuT-7dR-`1_ zERWSqJdFpbvW##YT81E1u~XlAXp_}zrv#2rD9);*$V9E)n+mlGRch)Lv+>>ebX?;~tK*YORKP&Tzu0)h?xlSOyS?-5dBOXd@EZ2wGJLP> z6{p|$*F`&RSwX^al|~7z_~P1>mOc^9<4`{gZKF^+wLGEICr`nXAmsl=;go>h6vZ(C z*CdOh-jm;SXFDVoU4Cr%iy0nP3-0e1US}*&bGtN5O9VB#t5KrjxN1;WdlaZ#aw;)T zU@wMvMokr~x&_!sO$ymmoDzsXID5&~6>7+gPk9sp$h_oP=LLp_^r7NU6yfn0iO@DD zD!?M2lQ9B=2r}4CJk2kTHT^Wdh;Sx!jk&hqRa3aWD|{`NXaG(?gsx0y8;e{;LA_pX zk!!}VRmW0&2B8SjQ_v2_AVOoDpy;U;7$!H&{%*edhfzoE1NMTRuUfD76kJbnIMohq z6h!j`&Tt6Qj9g)gNrID!0WVJ!6=2gidfVcwt3s9Jar_h{q=HT?P0E;f3c@KNf*s5g zyaK7%=Poxwl-e*?-BUxkGMmd%w0IcsZE}dLT6u&_v!J^dseeN@wm-x&{l(iE-r%Rgx%=D zrB@2MTx*@bv<5{zwdYvA6~4bCFq;Q3O|2fXt%f##z|y1Z_~$*v>pIXy z$F~##FG^FqAbAqmLO{hC(*`+i30f(EO>#yxN6$Lg+F6i9EP?n^!|>{B-5H01%F2@g zW8Y#=9=jYKH-i=)X!Qh>%-WSmO~{Z~p%M*>E@<2G4e0y?pf#vyqzkmO(+E#MxPVmT~($tVH-ZU8#!$Cd=!v zzm8p?j@5+R;uA;*@07=Dg3$wwCgAE`Z~w46KftNY(w>GD z4AtBzq2{{!j!;h$6BljRE;>}BEqq6DSOO(D6^?@)N?dp**7S^vN7RGAc8iHYbv+Z8OVSEi)PdtpLNi7jE zK3dik64OqMFDS;4?F&Z5`0@R*;$n2~EgKl)n-h(o*A*M%hrU8^j33}i(J_9ID~HGU z!T!$UV@eHi*#Maita?{5GBxm536iM+xmuJ=4bauYWNHBa?&D;N#p(V7Wo*=6AX287 zZ}%80Q}Wqz!7`@(>I;{t!e1g@rVhzN#7s>|&uIB3vsL?&YVnoeK0|;6|Y8q(l98*(AV0%za z1NH@@YFcQx)36#BcU@eKtpR-D$eLP-`|+v$u{O4*e(+Wet}!8Zh^|?!UssH;(X@68 zu(=Z!SUSX}&^#88u`wI+5M|>(aA*m$Q3dZO&c-^4TyLO_$qHRVZ9L?xKh~zYd9hHm zO))!G2)FU|&F?zkMt9nZ5jWm`dx*JdjJY|!=a`#9NmwH2#y(zLQ`n73Zkz&tfi@4HE}I1EqsVf5#Ix!p2!dHS_S@@%xjr-J`RSaeJ?hyy4uXqNb#0x6S*4DI^%V?38DnC9ZPe zOQl|YL6kKo$_T&(m13Kt*yeF>Quf}OSk#rb59(W5t7F)FZDyc5Qr(~F?c>_3G#w)B z8}#a+c&^v1z$xz8Y=C56x#@uDboXWhaPKvo4i57^&K6MBt2uqJ^c|fIz?!e?)LSq5 z%1-mrPQ?S5sQ2Y{oqmRpT6J+lW)PtZ43l7c7-Tzzr%c0znWDftugqLf{5D>iSt|C% zo|lPG<6GhaP1!TcT%oyu0ABJE&5Ajgx|dP6UZrVuovvyq9=?k+i#pcjnO-)Ra`zN5 zy(Ck0Gq`5%q5!u|%^R9rNdL-7me0zG_Wz6D8jSop0{ZG#U5a55G^v$4uGIL!N8~!$ z9W#`@!*PtM!A6lG(Q%_LBL><4rW zKfEwTFtLIh_O0Lsu^%W3ajMBZG;H}hx=UHk;pihpgd{Q?P#2N-Gir#_IC}QHrAB3@M(jb`wImw zklsTqaLM+o2Lqov{n``^Y>xASfs~%{t_D)>{LUjOi~d_Sl+rhAnqjXima+!?3c-{$ z5Lb$(tbw_5IAsmo-+4S`(dy*`D!VZ3T}4#ZAy_4(vJU2IF_m>tR}ZSJgZ#UXsw|hP z`wy#haDRcg%3|8xV_c=dYRd&ynj3k(z)BB-B_b>9uv9lz)i$Xu%%jjFrB{ky-QEVaEumN0k2;ix1c#SH*E_)jk0cOo;9M= z$NyY7N0`<*F?0u0%rhI3L+)4V1W}x_iO$eJ%=4(mUTE`?sIcPi)JLMyF+L}WN@pzS zBvC<9>m^aa^mThlG&ZcpO`@fV4{j0_H;GCwFY71ac70briGqMTbCgJ=1YSA`=zBIr znd!03zaB}B2THhEO4G)wb4dLua|mK2oCr45OC@rwKD0i$8y!OU@ph20rdknQSPo4G z@Lm)!j>+|bmfHIydBSvFa3IB}iUZ^$5t1Z9=7G{brzp{fodVNSK$3VajviMN50gp8TeTZSN*TrKO_r-9jvTi&oNlCq3CM_9 z@dcKocFc%)%bQ&(7M&VSv_|xa4C1n!X|1oaL`GsX;(!x|v>(X=un#`*g_;T};zu9? zS2-5nX8=fwGAR6a4-3K6SH;RQjvU^ym{iRhR_6({%wkcm*GD*bAOu0blk zK6=D)>wSxrmq4lQi-^)E03t#G@vKPO~=f3hylRi2aiF1C@0nkG>osv9`j5{!j z{TcC7uZ4U;`F?k=(#nnO0)|fhpbHq*(;%RfTYVkTSKv!|p>|~@Of5l*#0sU%5Z?@G z0aGlpak&yhr?ddT*;lkDwGpRyg|Z8`#6%OIU+~qp*sc_$@M$HSPlWQb8-^kvs?xdC z`tF{Wo8OuS-NDk@<&_oMLB;2h*t<9VF5zqhI(lB!mf-2PTpBoy1h>AW#Cr zwD69I)aklZFlIB72&A+>&f{1VW@whiI%(7fQ1OpWN)m_e#p8DDMimN;qt08(78gqU zm}a@yRs-MX(F9dTwxdm-<%wy1nS0IAg%l3ag(D84i*@osb^37xGo0*RK^zMO`yEa| zQuyu&C03k^2oE^QRO})w%FB&Z-n}}DiAHLIbzO4=TKMThQUZDhKY0-=hoL;_gwujK z;$w66_Ov<`S)l=ylQ-fDj>rMxgf&+j#o9+n(pPTWf0YTNK^px9&p~2}!70*=V zKtq%z!@`vYpdwVJ+;YZe#I!sXHj@ywt0Zs!r-YP^Oc5ov*q6Yr7v&(x2hD;&YBO zl3c*#vKVcczx!BnJ3C%6LSJe9UoCS18F5xRs@J44}fmUR7t^%D< z-I1$+hl+djv(a6)teZ`>=UTuo;bc>TV+kJ{hpJAwSqto6E;p+|ubGea7YXRMh9s?b zM|_7Qt#V~7bUBWJh8Yw&6#1O!c?!tA(ca&-ceZ=A^JDP~NmU2d_+V53FL)=Z1Kn}K zsFLl?<-nWV0=Vq}zk=y^dVuftOYPBmr9-~5qjk?!+zm~uIb3gP$6Clb1bP zcYD6|Y~6D#e^8ngN`m>lc}kj{IP+zV=YoRLiUySoVcL?ev85}mD2(cb&1&7Qs(szq z3+<8M^)`1Wz)iv7O?G$(;B_W>9sG{Ac?ZnR!Q_qhdPnFD@#W1ne8Gc;9bX?c-X(6_ zw%iNb{Z)V43?bj%*-_scBe0jZ=~uDp@58RQEqlLh-)i0KLPl45BC=~mT1RWUV5M5K z+cLbXrgt~v+f+_01AGw^{L2~Pja|Kp?|xUqd^rMI-T4I9d-4W#~Q8cx9H!3IJ9(%uH@wX0?*N_CIzq(;eHnzUax4+)NG=!zk z$n1pGu{Rr%xt0a|~a=i2dr!Slf{8V9GWavo&4sHE25x!peT*UL)5a(`)D+mqw`a>;Ugb!qs%o zCgcP&ZX9x}FeDiwbWqx`f%YRbJeL-#H@Jw&#Xu%s8SIl#D3t2jj}-T3(Ib>ZDZ!;1 zjcTW&w`D6)l`7PxJ>}wJeJxh5O}ZtzS!{#iWTK(zncX0*04`pLRKJI$$_YVnnGjbg+W?2ng|U1!Jxi6-tenUF&)Z z*%RI}dArP<K+xQoYJ5>T>vGu-Al%99Nc1goe`2_;^LWrKgbjwz5%(TnqHv9;1p&FDg zHcC}W99c-qM>+zfX)LZZqQdl|IxbZ+xYqz$)4a_jHBy>uL_fng7cP59xEDtNQUFb_ zyrKijY0+(lYlatkZSey#l^E5c zuHa?0lROre7+fHI5x}x*?IWojXp#jqTm}kln9_n{t>Y-Wl)FYkt%TUcz=^h=*Su0T z6IZUDXXgGJz=<)%97^^57p0GCcj@Aw@4#f*ZnkT7V3rQ(Ew^=JRTA%w{j{Prh39&q z%fc9OOHyc%`!bbap|YV*X*QDHH|KeJqbAtv-px%RnnBO&P~8K4aC;jlvU|7S^=mLR zL61o`0y{JFRb0I}fUkE~C=(Z@p)4!drJ}()mGapPX7iC5v?h|79mAHc%|+w`ksf+?gx^#S00aMy!x;`5EaAVQx*#gH=a0?crd zGgLUIN~Nv{7_ywe4-;(WaCE}6pU6xt$0(a&8D03qxya1ii{)C*RBjn@V#sx(5};2q zlBYUkpuBlY-{d5(aS{rkN?NIQ@W)hySEcXg)*HmMtx zrrA#KmCtUJhSLvHr*xY?u$q4Sv)k5>mBxPT;vRoGMRB~iN4)wspuD=rA->vX=e*v7 z-|rP)52-ky_rvnK#@9h(aN-5CuvdH?0^{J_ho{apz6qQ@Qm%#9#Xr717rQmoqLesC z?`;p28{dNm{5mq0KYAo3XhF^sdY|sVRYqIvEYX%>ok4d#GxWe;!VTE&;jhhwzH9e& zJVD1UJGJ<=s{~admvjk9-pVI-`uH4%>MC*2gE=F;r|#k70UhGUdV)fhnO3d>qg@{b)%3j|2Xm z6IB=~W_?S9d`YcHwQX&xPzB!o=|6v3;Su{a18F<=X*fkQ*#BQjl2u^3&u};#zI^^% z{5u>DoqxB7+s|M9Y5V!`#jEG9wzr=@`_pjy`EdLBpTKaPMASVwWib2GaAjO>$4>5$LI@#aSRw>_D=~K>qot_mmfB^Az#2GHgt~OEa#?FpOw#1a1V6_FxuH zF+(BCGgQ1a>Qk2CWFqRz_n5`vgSx!VtX>r2%2Q7|a~AK6{WM;ES88)Q85Q_Q8B8J= zlLUPPBm*DS6*s*6N4av{K2;>=Z0aM`XsS)>ZkaWMD{)pTk7lAhJtp2OUCVlDP;x;? zj9>}74!%w12Z}%nDZM6HWM=x{R2CI(%ep;XxQ+~G?0n-_fapZ3Glr(uNpXGA_Am&i zFoU7EZYfTuFv({q!y%C52qzht{KrN*#ZiP3r!4^V1c&t0n)KBEmO{Y_f+YreP>dqC z8}47X7Ar|NhlQA_xF58*3R0@!%Q2F1r+3{bI+WPd9GCUQS~at&>o%-4#DRKF2W{Nm zgwJk)vUbdls1$biu3AN(PFJpV--{uh(VhkH)?p%w|Lt}@XqiSegHWJ7}4+&-*$B(!Qzh?e{mN^K_d8pimjFIupN?^@Q z_gCATRlL2>q?N*M!8z;ckfI}c<#N@tB(jo6=CY_;(JBlSeS2ILuagE?=KWo8X(_ML zvwNauU0JhGa&SJ#qz9Pfy(z5OPP*?0XtD|A%pDMN)gciv3w$K!z_R6cqBNT)%vj;~7oL8aOGK_Z-u$?g%SqJV)bT{;$ zc1CoZKU<}C(Up$VC?kMnFubhwek?F9CQ;X-V@Zek^6tzA&U-< z-k%+u_Sq-4MjXxie>*!bU%ja8|Lr_`*#Ena=ezH~af~44t0+hz6Zbz{PjM_SxfWq5 z08?;*xR8oa8k0GSz<1wmY~0)g0FTQ=uKl0oF0wS#?D*NAacu!-6`b&4$@B$SBgqwA9d`SiiW4NHN&lz_wz$3R)2py=kf^}# zlNrPbCrw`@E3c+0Tq5Yk#t-Vt;5x$$8K0hlG0rF}uB55C8&G0;s$4>_=>UzB_P(=j z#=E^WGR0Hgagl6+=tOuyu25fc0E#JU8M@lhpdE%I&2YlTp!a7QDDm=VDmwYkvVQL+m$`F7}xBnbjr#NrRL$=?v@UM`~2LS>9OG(15o7cUYegqkmcTNVHz}p`9EWE{E zJ_kV%p^!w#9(LX?bww3lpG5QQHCGJFb|0MN34q48ltkq^$=M{QNQSP;3>C6tbo;YB z>DF-B0CiJW5M)SP6Z`tf5xPRz6VNzHAP7)$RT%{PHwPgb4+7}}<5etWPgdI{8kT+ z25gp^U)O=<63y$8T*^FDOXJwvt!st)VzVy*-~&aDpwYv{2!M=1sd{-k8ht_`2m;3D zAiy^7{kkDUQBWx9Z3=q55?@i$gFr^QED$avsgf!q_|@nF0J`;X5O7H_-PqXagFQ9l z%LTuj*L!adM~iEEWnVQZdpewsw*~~$&XOJkX%{81ML0mqXNAARX4j~z%T61`Am2<6cr5XCFH9R7M}(mfIK@fmTplU2bO@N0OIGELs>`iq zIwOH}Ft@Z(sfsy9r$=GsnlIOK)eVI?qc~C2bQ*0>9KGK^I6pjg42gt9h<04{Z5shIG^4)^f9q2QSx);fiZX84iFfM9 zZEveW!twi)Glz&}(9;x!VzCzZ^d0fHJ-xX{JM)kv(VF&;RcGI2vCS-7UtTM3_dr1A_)a#$}LeMD!l5fPU zAAu*9b$b&2`k49d z^xdjpD3{f~U?4fPy<0u0Y>q8k)KSCz_PN>EM(-vG^+59;2*xD4hFR2YwCPni=se;b zI)BtSeZ(H>U62{d%}GzkTsF zvgX*~o9AxN3fUwpS6&~N=YZD17_|@A0_)}PWWfE#yk*$y-j@cjxbxwJh-8#!a6+Xl z@Rby<1CSxvBBR`6?Q?ppkFG|q#a-$k&?U;_CH~C;Y@aH2c@J#LUeJJh z9s+wRqel-s-YSR3K_wE5(SDvzG8mzv7pa4%q)1ZT1Dk@^np(D1rC<&IU#|b(`4q(| z%4naZ@fyI3r^Wwo`0QE5|L@iC!T;}Go|~J&ci;-oM#AxajAJA`)MmU}!YLYo?*>xn z4!+wsK`hS_ov$=SI{HSQ5sTZ*MQJ`UWVTx8usBdoea@tj*$8wYHATd)6G9AwNaE>D zVsZiF^0oZE1sqAyOmlH=(oVd66V}SDu)(d|oRWU9snvAtSuVb9)wRpIn|tMESL}Zb_TGOhizY^ z$^nN0n9lH`lGOlVLNrQ3Bh!s;*WkO2Hz=Ngo&NSVpm{2GK?F)jDV`)VlrTWX()%?> zGA#ZIW>}mGsodZICjf#7kH;wEBl*{>XAdIn?OmNuW*o`R>-oYVE1R&wx1Sn1>v9Q=KPzd?E82)=M zbN9<62|DRk0*Hu~Df`MWHspwSd}QT^N=NdN?z@qwD~;|B)qy%eeH>;eI^!nf=(V`P z>HSz~z(%6FzOq$IIOy+FAk|=C$&N~ zjh=^b{)3Ej-O>Y7zW8KV1Qn+EXOwZ2Vry3UEXYi8{p!-=_%sxid*(I+MYAiE?U7ju zGX#47c)i_!9t@v?zi;; zgRAWe#Nc+%W@x8;d8b+b@~pCi}l+hsCx@!CRvV9~+ zt+`*yeq60LOr}}7KRPncsy)(;V;VWEOAn=x72dC6XOi2%p01GU8;j{4%2gZGqAatKPgblHT5Snzth(4?RFf{-7Z7Ax4S}9_jd2JrTcGW*c)wa>;4;&yq{W= z*Q7R@$^r$w)_iNDx)Y@OX{kcybwW>_5nl&3!Z4J{CkZz->bGk|>0Mb^?#O!@YZvRw ze4?h3uXAj63QO_>6^(F(mjk}1{^)fA(nX?KIq1}{8B81ZxQbG>{iTl<_6m4`VKS9R zWIeFS(zv0Tv3u_Hi3ujKGwF32h3;}c%Y`ltjoy*jCXB1z^aW6LJtjUE&9eGTZ1y*F zfze_?N;}~{BBo}&I*pL$F11tLJdW}VrsuGzGSSWX+*H20Dr-Ji%aB!C&et#LcaU+T z09~O-y0w~7SsgmZI&f<|ZnN9n@Xb92TcA6ARlPlH$FD7*>==P*s&ZZbRDr8N{Y{&( z)mDmKY0Kp9#*!7&)`P-2i`=qgg||q(Xvts_?Z)X89_2HzJ#6ncus22FC8vu`QHEqz zZ+XTn(|oHOLvjNW)QO48(RAI>p-$!A&x+FS(Z@11oek?{K-gRR{*{}|QXC@yH)p^MV~Vl?=~Af0s1t}5RCRn zLRkiJ!l)&lRswA$?5l;UQ#F(?d(}qsg8xf!0(!qDJ)>w~L_8E_b!AYACIC)D; zDKig{MDzvt$7{gJm8myy5`h`X5WvZpWHYI}LDuO`_-m3~#so%mkP`WyfGLs!Ni|oe zG)aTiMpmTaSJ$f-$vCVqkZyx(PYZWk6I2soVkF1hYA9w$q8OuS785;xn0T5XZ&F54 zU-pLX3g}S4X_c8yOniNvQimeu@1e~g5Z{buRvqryjr#w%t(av@r^n*LXq_PJR>SQkOSczm<|)f8%qk+z=iCWBXnf7aRB@QTwxvOPoX_@T26b zjTvGvf((u}fI1tIhK=I84fD3;S_j=mWQxTrZr@vKj$@)mw? z1@XnGQN^Y2o^e2U$Me5V{$JsY(!W{u-l^bUtJqh9SxIzP#VEwC$7#jDDTk;HsdgxQ%(RLwHwj|nR3@V0qb-kS-; zbX@t;lI!7F$K$U5#evvbEI;|Qtp6{bKYQ-1|1Wm7AJ+eSd6bxTx3DXxnCJ@BNsSJ z<14+NEN(Xen`U%f&kxXu>H=GJ)YL7j64Gwdg1Qb;O$06U8q{i5C|wLj;Bz3_^ay;Q zC<|zwrZGklkZ5ezg;D)j>{%`j>l+dq?qVau8+DLGfQ-GZ*#PPSHM=7soOxDj<35?b zaP%oK*xjbCWNYs>1ND0Q%?o(Zj`I^6Vam;nJ(YtB*oV2Mb8ut%On4s^8A_E4F6i~@ zDDjP`ucHNL%X6cqA=PE-#+1hJ3I%1N;yI$;u~u+847N$tdPmz2dBx$@Ks%3jONF%z zxVN{f^4Fikvv^zKi{60EQc1`KP9iWAas0y#t;~C~-xRT6$A$RL5wL|p8?on{|&cay7B)no;@Ev z*nju&R99EQ0sHbO|Mqr6-h0wz4%<`M&Q|fqn^@n-Su*Zn-+9i95)8GAoRGt0wP&hLFIN1vy#d5T7$NWiuMbOPza;}JL_3F>MhrTImS z>GX)O69l9Au1+*r+!|_imB@xLvV!ATmvw;rQd$=3k@3}zF= zjs+~TC6s|* zeNofSN-ip;y47cIPi0zZ1ENTsYW`MfQ9X_rMufW9$1ZDm2!T19?um4()FcMzG_5u8 zeb9kQ;aXosr7Eq^q&{qFwZ(T_U6CIvBp zk-mwJ%VLTczzLY48Oi2LO@wY%8lNkrt?@8Rnr6xA!O_{_(ZSndx||<Ey%F z;lBR%9|N3z<~2X-LW&?f2Ac(n*V|jg2LKL_Uq9adPf&av{-^q+dq>C0ZyL1NAmm*f z+y7a-FiMu-TtJd?8&VlITpXNTCgeIPb|=~oApcC||9Vfs;qg;J+f(p(s9PwpI*q)w zdBRaS^+rrrS@drA^z7iIT_ic>9LeN^(oH})HPNegIMjhqaA4XJt zLGAN_nID+>D`Dm@ril7C70zK2d8P*qGn}&X2xpw9BbLR_(|C)mpuvuc5wZ>|^7D-vqtO_EwDDg_>IxRtvTEOK)&KJdKaL z|1Sr5kkT~S| z$u4~&-@;^qsE&&azziq8kVu1V_avQt1>97jX7JN8m8XQV!{fb@ZvH}D7jC~iKHM)~ zq`K)*`Ht%w?~{0bLWoEYOy`uLnfYC&qTSC(YG%FC{t~-y-||wte?Cx@t)b@%hjh0K z3M3tRuqzOX-r^+xWRWdM-c9D5YT>giZmEE=7y$aMwNR#!FUIRhsE=Qt=r=NBW${zw zNZiL+@uG+=VLuC4dojebCtX}FYu5j@c zB{#vZei3g>o}eP%zm3J-xE;jtSThqRET9tj+T8$ojUk0T@GC}|)wFjlqkO$nbY@)_ zty@VdNyQc0HY&Dl+qP}nwr$(CZQItn^Zk3D+jBSCyjmBlt+AdldhfH@cl!XHy(Yt` z>m#pwXSp@1w5-qpx3M&on?8}4j(cL)HBz7~hGp+jxwJ9&)FE!j4!^zmd^{bM2p6Y9 z%%;mCe?#R12ZH-QGd*ISv!WPFPqgP-b34Dad^M_tzFUXA)dysb4#bu%P&F=C$@Khn zSJr*{>zD17H=de@4pPd!4fQxilUIpN6K&X%O?tXYm6HL{^fh-OccmE42xijOVN)yU zkE9h>KcIV2p#<=6be1)STwMT5x8WP`dDL(v{@rr5C-6Pv;U?Z?SI60(A%!A9tP)A; zOUL-&ka4Np;Nn^yo=NbmYwO7cHp0@>VM+?blw5t3+?sM^zHY_4RPNcBEz91clw1OD zc$#Pwn-?}ebLArCUaZieRJoj7%yxk?c!6F}I&DS|a86K*A>hS#7qL5&W_q8nfJ^47Eh?i#eUJK{9D>Sr_J zms}e3dYb0YN&H9AQ9`1gNpJW}in@!SXlK7{Ifo&P9Sp`~ZI=5PKwqOj_1#KQ z6BDZ)h}Nx$WR&{mE&Ndy>)g&!RUp^xf(NNdgK!o=xU6ayW4pN;Gv8YSbzP?x(f_Ix z)8WIPOXARO^5;OvAe1mS(*%haTI@+Ms%Q#yAf*srq_4znux%zH%MHI2zy$O*eYM?4y8++QtW@g{fCxskf>L898Z+b{W}U-yfsKA zSg-i^^cBcEe0jVJHHuECFRLj2tVR!DDc&#K=PDYcmS7 zGu=|yM;66WwDDG~|MCsef!&4*SUV*IgSMSD zt$}2+ImaXkEaE-O#oRvYX;M0ssNFhdpfz}EODbiAJ1_dAsxE*+&_qKf?{IvG!f5;@ z#6+ay26pBJt{ZS$paeW>0h;7FhLAeNC!=Ww?%v-v(*|h5{c(Qpr(hCuqf{R9L3=q#fq8Zx?x6z4F5w|4gf3cj5bdYx3NTZTi0-^+) zcOT7D7%q-?!OY7s{6z^oVl}^@8^T$&1Cn+9Zc3>cEm)OC#1KceJBn-UahvjC6^-0H zbgsH8qRsbUuamyTqS}_AozD6mo01U8QzDAU9|NkeYsV!90xAo~Y!-kPz$za)?u$2V z&Iz%J-7@2#4s}c_37D(&X`zQd$buihpjL$U%MP7&*Ny*e{8i`~qRJ83_44mT(jEd%`c+HQu-eODkm!yv_yg8$+ znX=7rf%7nRx)?oQ0YT)dYj@ceKN>&!0h;>PT-6@GV9q#5M!XPLa>k*>1lk-eHlj$k z;z>M{UT>8n%Twi<RFCIf?qg}-?^1kCjxZc&T6?Fck$i*9w~D*}lr74Qjml1h+z zyJ6={DcI4ak^~T2?1wR+Hz&zba~wbCag}s=QWUD$!Ro4nalfWwHK8CGb|*1~nv7D4 z3mVbz$ZQXh`$B1u+GnRszN|a$vO3$6SJ zynv_Db{$=1ZpNNdc{SvU0_pQ%C@25d@cdu&E()`jbQwkc1IGBXp+O+DlFSmAzuI(A zcUon`oMeY@(L!SLsx4{Gj*+)8*w0%y-zODSo(htQS3GLU>1piM8UUIE4nfF^+A{z$-p=nm9hnRn z4wt;GuGE10c)&h%Ir+NZ`ua+jLrDC|w%LW(-`_|JUGNYf18Hd~2x`_dC##kkJ(l;n z^@-le$;8eag)ypw@)5yYd3s%LgWI`V9U?Js5kp94UO-*TsG!NnZRdDtxyrhFcCupI zD3Euv8XoB?eT^V{+{sm5<6}}7d0^$wb6Bi}&7py5-b$(%_ByxomlZ5Bc8{z_FIIf* zh|<>JK2fpuD}QlYVl1bWzd7n`q?EqGhmfY*pu{RS&(Qb{Ic+vdfr>l!)yNg2lkC%o zU3h`*0RAdZsPk8Q1s4a3zn(WXxu_itQE6Chv$E80&RmzOJh_0mOVbJC9d-40WM(}y zDPrv!uSv*n2@Q>0a0g-cr6-2W_>14aNp}gOd1HOB!hC#w=kTTe`zx3W?v96cOm2c5mVQb#36g4l{GT%3H&`vh}A5Ix8igI8-eGQy=+29zzx} zwaI4C+sh;D3PX4+Ua9$~ANo-(3mH=SZXGq&JMq<=AS_8qcSKq^WvAKJ=EoT1W*Y(|B#}pb4ZlCu_zCqZnV|*Rf`# z?uH9OPgi2KPO>8ZCEpjtM14zVcx5NEvD;>M!fw32usC#VFp!BTrsW30QZ9v)Dujul z?(wHc!6&*`swvqk_K749 zTqaj?RaI`iaa#uXGE2I;SCK`w9FD0We&MHSSWEi=MwIMHZFn$q3VyPctl`KW$`e4O0B_l63c)kvyTUE#2ar z!cVFbqF}koBi{9(&Cutpa;*p;9!coieC^bPzn?|BF>kV1bl4NtTiz7!0b_`9`{6CV z+Cde@zbwZ9UzbA?EP$5^6AoIOd%)I+gMyT=!WiHxJGqLB&$Z7Ia-b!>ZN_ROSmfR( zi0yOI0NW+>hQP}e73<y9ISX1@3*vi}R{_x#)q|qSU9D7`!|J_8>WFeHkQf%lYw`Go=bPkseihg3{>?6T zv4aXpR5f{M7%11tAzYPA1m0nf#0alu# z^5KdhY(!{St;#h6E-_1C8B@bA2YYSe&i$f&95nBbE>@Xg?#tw2Rc2-C;pw9mMCJJ| zA<6-9dnxs&8@+mXG-};kkvZO~C{WFq%gU5hOK_$E!jgO=)&~X@sWO{0gVSv$T5j_B2Arq!D{$iuy)6ZKWlj5~5!1Y~0sCc;|SyXVhAw)oN>_3QVdYkxbUV{r5F8 zll_DFe$?1ScxQ|NDX-`*P#m5>drzmBj_(Qw2=-Z#FN@h<>dSzWne4VZTv{Dy+^9?X~N`kuiPIN&S}-Lm?8c~IHl5McTKczbRD|N041 z<5&Sq5lNa)htLI~vL>$pGCY;|Z)xJrcevt7FR!P4 z5ARpwfEM>J#GH^M;Uo10QTOgKBB*2tM`y_=@B|Qxk~eNJm?TQv8*s{0(3c9NnTv`@ zlat^o9uCcGaBDeZ5O1rNIMap9f5gR zM)X;KmQ_L? z2?EX|6cgZEaj2<^{*%|Gia|xTV?;h%a$)yb?DISioE+2_nciB-u^njvE_1aQw-bz$ zl9R@BL?t?Lsj9_Fl{%Z|!p`Dk8&ULy#@);ZN9O3$o~rBrURKybJXVXJf&-sDkDg}J zYevlpRLlN!=#4%l2R~L@(^I~fX*K+l{GCK!_&C}Q-gQ4#p`Zk$_!-s#3xpM8=fAe8 z%CVU7L?;c@L%5>4wg)92-Zpe%KJ-IkTiC`%2^es0lE1TP^AwXy=d+plH@_5Wz>CL zVW@LhSxPTB`snCFq*)mwf^8e^Dk4E2tMuxIIdBURrwp*|=@TV$h-I z?5>11KsA__$bdq!Eg~wBMudGO-ADsF_-VZ@X5>?R&zpx_Bm3RZ3RnU)+2#0#TApkh z0?eaQSWKZWy5|~Ut}(0`tE|SfwDR`!RSnT7SoWxF?-mHELhfl43h;ayNWP*6w9DrF zQA&oAGK@EB{;Kqd)2}b9HMul-`?xwceq7&r0(L*(c+`n6H!vH18#^G2L%RQr*b00K zk-}z$xXYlP8*XAa*;u_jT3bAvU%yX3w?4koEeOq^Yh*zZT{=okz)4Sj#*5iZvfIRp z%3x^VKa+n9_nXF>oy#AM`G2xCQFW)=P8s9Bq*Gl5>rS8FhnJtH106RP)iqVZq8cT$ z)P!{(&sQHl*|?n?+#fl^6XsT6qM~q*$HnjFT7wz^3uzTnE-&xl&Ruu&-EJ*={PWra zP0!C>1YNKPjxMjC{D&_dOST38?~kd6@ZE-oI{^{?+Mz7RDElG4-)cbqhp zM#qf8EF0_NL_4)5ib4vCIXiHABfPaQ+h<`d_f5w-R|DKs77mw@&S}bIuHBpCVbg@~ zt*7nj%UUr;u3+>`IhstwiQg4PrhuupyX&#*j)fqI4IjcdYSy0hqSJM?RzIwmeTsw{ zA{8DEmcIeWgqEGR929j^9!5O2qCV-|HSK*cTgy&>p5?M z#t%+|Ziw3OTm)T-`w#bUgo zRRWdi;id6{-8D<;ve&N51**JuRMu7BT*mgCJwb5nl5#N&o;}ljF&I&Bef%-Vw_wzC zRfVJ@hlF>0P1T|awE?>h+V+~wcVJX|_4_v58ixCAhxBgK;pG+K{e5QGQGFiP;u*I> zzwDv$+%S5}QQX@E)-S6Vn^EguO&+y(z3GzXW1yUh_Dh~7<|Y%?IJIr%5!dJ2B^}Gp z?!g96jvM&9 z{DDra_6i}60zU))e*~$Dtn{q5+5I0uno*VK6flE+6^jPcL!hx4p-YqKHuz1e<4oTh zrg-O)f&70Q>GbdapCc_dTtvAtV4qBi!1hU|O1j0olg9o%jXaJ-9+I;lCEM^#1#fvl z%Xc8JV`H8opSEihCe1y_H~yx#xL2ss*A&Mz2X1)AUZlzJm9V>j>VhtpA9 z(dwV^N~~@-7eU!CxBnkq9@GpvZj>^+>7rPfnqJ)@q!(Fs$27pVmJxRi&)ygwy69#@ ze^HL0hx7i2mme&e_=XC22(uI#iW_|Xe`ILl;!ZVScB@0dzKlvaEpY17?se);zA1vS(*z!AWOVAQ23 zUEx3l3STZjav>HhI#VH^>agWk_w%8TH9BvU+8+3L*w9?iu{I)DY$f;D&RyZqHcQjr zImr*wtuLbkqtaEj{i>vnD=1Y@=(`K7bRU@*7}DJ_ycTjp4?WqhwtrFG;!tD2 zUcu81_hGEY->b=1-INE-tq@IitKVCq0lp<7j@!;aa9P(AG}@y~)Jg?)2)88jUlZO< zskZ#kn7A_1A4Ws1sVsg<={*lNInmqmcFi1V`PSJb>K`+-GUwg+%9+vWwqFLI{)iMd z0nW5DUsZq|iE4LQknd3QUtw|f>WdSPe?)`F))Eb0cYqClBxsE>KS|2L>#cMtv!DAu za%3)Wz`9!8g$#JszQ#6V>6T$VBTMs1fN#aRiapb00Bv(lkNfpD;OTttyXM2KQ^o1( z>>+B|@gpK9olErAM&4h7q*d*+IdtD}qK%ASKNh?NB1|?%T4Y?{V$LU#TWeov2X`0c z0E*uUvg)0IKCKb8-Jd?%u;!6zJ+Ri{5kf(DrXVo8AkgSxirQA;vS<33)$7aEL7WV6 z>>qGvlbomG9xec^Ya|14(6xnMJKlf$fCaqc!v;=TW<~~1+M9cmk}YASAqpL#|D|4{ba; zlJ7CHTSuCfR?`#STfKcS)f2FNfGN|pv8`MKxt`KJ8PZ37f_Kjc|H>?Wx8!k&yMf~h z^LVQ~l!$;)qS<<22;5rw*GTAmKbw#M5YRG-TgNU-f3Au7Br!l|6;{y1+h|~Cg!iNI zH&4-z3&J$6tucJxtren(?RF77G6%9Z5pjv?=M#+MB}RsIZ63+l z>E-R|?$z7g9NdkL4fnR^f8oQ>0`TlTwRM2enhX$gVB3 z0DLg?ki#!@6+ASZet~!*GDCN!nbrBxG zzH}M+(2{x#^sxz&g?MqO?Jt43GYQarw&Ni^q|3_?-TUppyO18ZKRK^)r<#owXc35Eh21Cav0ewf zh=mf}lS?WT)+R4#OfEp^`_^-IBGDl_1~Kr$&pWJd%yYkzitx+R385p9NMj{ffO8V| zb4%eTg<|&&&Ow|J7(#}>qfk6TG?a&xk5okT7irm1o-3m&Rg`W*dJo{$YzaBP9F8ok zWOU)}4lILo>Dg4c0svufRK@QFY;SMlP8ZaZM}l<2o_wcoLQyU2#OWXA$PA+~P|F1y zR;43Fzf*9?^cKrZj>Df+m|0Q{n^&vax2q>?%t0cH`6$BQ*7Z&}x|nR)Qie13G_Gq= zhO_9+tDjc;_T!5^mCh5V;E6|DRp=jDb-Sv%nUV0MQnD4W@68fjlMI|FGGQs3EuFB6 zHh1Z`7}=UUvncZl(e?P5!TwqQ7%=*_@6?9UsprbFRD_ znYExjGSeV#KwnJ{toPT`iVn=EbyyGdPe}{2W~2=vPL;Xr&wao&>CbbSYD|&E`1LLP9if_d~6BCSqa~7rJx}Qe`5PYF48g zvT|ya)6E3e5bxvY7w)C#=^eU$ns3IOHN^Lw}Ao51Qczl0Li=fwlbKy@QB@n(l3 zSg_Jo;~YF@md$&+FIcoGTmkA{Tqdjz)d$cxcT{w|lJu865(^Ihz%f0j-c!csALgJN zdmyMan>MY{$F|{$9gd)0h&z0aIsqag}G2I)bzZWt$K>gtP}Q8&4{%Me!8| z)V~p~HQ?Uq4xd~9g6i$>f7c227`xm)J~@D5S@HUQcmQV>+e{O^kt{?ek#9Jk9?jVj ze=mxww91gU8C}jIewvPV4@g#&FFqx{QuIH{qjlTlRnj$!4~V$>6gbg0OCea^LBt__ zPy`X=x(QewF)|BFZAa>WY*#d?PQmYijViJuUr(s{XgZ-9@MEvgvQ95u zq`D;QJXVR6R2$VVr$gU$6y)!;`DKozdc-Ne*{F+iMrU91!gE}_`fz=Qs#D=pUFbXO z*|rQh;kHOpQBEfwXx{fN4Lfdu&Q#uk)l79G|U;yZBaQ&8L?^ zTTYV?k{`ychexf^O8jmoCTX{7lQ67)M+kVae+h$JE-1qlVw0&47Z4(EsgHLMBm_iE z(iuggZMf8pLa%ME5PX=R-%&9UtoSrj=~hfOcBFUZ9^h;J!ycy6!+{c+VvR`3 z;pBit;{*TVc5{PlOx2uQRr%eYE--*Vs5*yYzRpALdAX|eaKi|@^1M7*`%Ww5IiX?W z>%&QmL|P@(9qQ3LMdJ#5pGx2!hcI$nDPj31TFB*}=!V?bD`NbGQ_d?tQKW1Fp?a8n zG5MZ&c|gcN6#wZF3eQWHbB|PE^CDUf%;%4zkUrw9YU(O2RhGm~K?aIvGBwT@0lZV5 zLC48y22d6J1l^2BiBf8sZ%WMvbmUT}`6O9Vv0C3Ux|q~8h5fe#2oMmp!7l3#GEE#s zg^o#E=Q!KY_-sgh^I`!LI#;V|;jEFp<{KfZy5{ww)^V*>9?wm#Qyj++TT0KYC(!EF zQ}de^;uZB{W{o|BiQcq3Ppt=ehQyDnjFg$2U86)b3xo&XI2ps?QW5qq#kVWl%+GvtZ1f8)ZAlvDGF=D{hAegh1adv_2V)d<&^^Ns7*{9WJ6QnBg zX_(O9G!VtoUNI`+Mb_Jv1+wN`k^!RT_0qbx;dfXTgTF2Gols5hWw1@}M_};D{k~BM zn62>?4H901qxhNZD@u4w5isT6&fN3hmwFd38pXNGVIoR#OvGdb_bRML1Y3=Il1b6+ zZHzQz?;12GTGEON{9#^6$IIp)yQ{_u?F7^quT%X1e+p%~ zvUOx*jbT`yDo4lh)0qgpp8rhw94DRyeb&gHn|C1dCLaO39TR5&@4I_*b6Vdk8?Q;W zvFP<(7t4Tt7F;j*I`FJI(bjl$z#C{2}D)VJ=!(JgM*b;sNU4b|1tg+X@)7wv{9xR%;?- zKgk!Us%$IdP&#WWW(oa2@9)GGvK}Qq*YQQ~j~7sK!FRI3{d8h|hhglC8BGb?*(%HEQ@AO14uNh97O>B;Y?t})2(jv~(B>ZJg=@;u=k z$Wb=(jL>MT=+Cey31TX!7`7zK44asb$6DXg2#9(|6lLr-dg_K zByKy9WZHT%5(F{g&NK!TYl;!3YbHg&!a@)3X8oE}?rd3vmEIOP!^YsLA!qf-P zrpFjndyu>Pkbda95@p{ne3LyA;>?Hw1&c=x7QY&rK&k&cOfubScKb}%#9?s&v(eW_ z-m3XW@4$ni+kbE}bC#Gz%;!t8cy3XpZ(^c3deB?q&(`3A!+Z>F&a#R-oAXi6XH!_!VUZwnoNNVVTgP~3jvRSWg8hM&3tjrR2D^nx)Fj`K53441@wh^EuNMEoG z0T&cmhC4n9O@MQIw$BL|b3RtUa*Jq4pG(ae@|=uC$tVOpCL#CG5?@MjTtv&hi*ys~ z-M^fQchltdF5bJxEMh+V`D|(95}SK8=fOum>R)24rMm_G0w}t(4P;DuS@x)WDu-1e zZ#xlw)VKa&y1;owWY&%Zc_utbA=nt~-hgF42``IkF_k^MfJISGs-b_SxPvK$p*uF! z`fr++Pfhxd)+p&i3XOG-Ws$0D5-uY7#KJ*bOwem!4`U|9}5G-ZZcV+UboU6_oZ zj^JizG4~u+^tVtxlOm?Ra(23l9Q1#+At(75`%-kdX2VpPXk$mXtdWt{nCs+lz>^-2 z^jGXB&FKzFYa_eBTXEKyD%wv3Dls^Dl`#G3{M}nWMuB&yPSFL9*{8Z~b5x9s!~UI5 zE_>w9VF&u9~nMQzG!wyS(b9z@9@E>`i0A)K@xcTZDb zzx3zZu_^Mn%LwzZV?pc>tuZ~~zn}RE`y|Vl3tOId?4V^5&4ZLZSA9$wHuX>rLK%7- z4dI{k5Vk!8T=M`s+WUbsaFBWM(%g0AhNJDnGGR+tbHib6s2djIp?dh_5-mUdI_YAdQbx$qt zTKg=k3qy!MDDZB(j|b|l^TU+D4nqNk)7p1LmF*?}%9}Qa`R6nLQJ4gPnYYbv!&92K zQ@`mVV$1!gE^XP>qNXS$xnWP_#41A61IAPy4HrwBzN;a*4fR#j!ARxgrxK4i&kexj-^Y5iwBqs-X6jYn5q%_yEy7R!G@GZ|}Z;tjc6}Zvm|hiYLe%$9eB&rL7odZ49FO=8S7lu8V+Sxw} zn%t|cLnoQFmI%x=cKpTa%`2(biMIN2G?>I`u3SHq#Y{#s7$i`FU*j+1QCc(TB#k)$ z{!|IlplL=IP7TXrSXyOF3f~QAci#o*OUsMlEG=*WWkya@E^12oN3Na~#Z~3+MiNO+ zLm7sk8Y)KAwN5G~P6aA%NyX`RD~;Ys%WmpUslvv!_2P1rFpdt-wdwqp6}+lw&KoEU zP$q;5Yvv-l)CYXrSH5pb8t@dp=A)cDh1hxesZo#F$X?YIFO{d(AYCRxF_>pul<%Jm zkJ+#XEqmk1W}FI_+ne#S8!O3%+4dU!%aRaE2bL$2R%5BMOFPWcOUzRcN?G6FoGO^< z2+4wzWfnl`PsRl2e&`Wk3128ON4(Cj13^B?Eu6POGDjdheE84;?<2 zA63Lx;($#h|3X@<2Xgp`$Ki^Ogn7h%P3P*|N{0c3n2?W0o3-Ow+GEHNTb&6Cz<5H@ z(`yXnXcI>lCFxCI@IF>PfnMc$K5COISQYOhrsyc`CW5ap;ck`46t1%$uB4M zC8bBdp@;+|WWSv!xQ_|i<|e~P{e!A7w3hzSn*L@0klV!Zq?(%b(5EBSjP^+N(fm8o zyH1YP#w2>-?1U7(eaoJdT;Ci%rr|Hu0Nio$-x~Un-W8><28d8M)w0l~y*~>Hg0i*a zW7jyW`kLPG#AeM5#4@ez`6R7~N|fZrFew=YHlqr2_0T#hJ(~J0Bzs31bf*c9 zoC~k2ua;buDp3fXpWC3q=4;Yzm4zPFvYN_I4ajYp%7w$I70ADgEk-U8#%7EzLlo*Y zKuiM4=R7^No#%x99YAs1&m6`$gneiw(2 z=j2IHuf!rg1m2-;2;|pRU+9XP%q?|d6Khw;1#!*T)odeLt6lP;%fE~zU>AqrSK@ar z+Sl6aZY6#UC?_oC)zyyL=i8^dCQ^S|u4~zvmc!NOtxx>Sg{vM)Gt|1so@+jRrP5UL zfxN1yvW?Hr&$!t-)5Balcm5+x^G=C8++wKwPFz)q3 z!Tn8*?+jE@_R3%;fO1#UgV}No>IXTK$w^Y#Gyt)`U4;jt%z{+*h2F46uT?_Mk|3td zlIQy8S)Q)C6}m6MOsl&|!i>yM&^sKCo``2yB+*|#H9`8u0&y-;+`jHs$>wklkJX}V zH_r94kRG=DCQ|E0ggW!-%IjUxAFiZfWFRKNqlJ^v_T~AWHqA0wtaI{I%QZUTv4e1m zOcEk|91JFiZ|o!Und(;PRjGrXm9GDI6bavA!>~us+3D&gO@y*X)Gg}KmRJ0hK+>TEj}m3~%LPH!$GTi`^*#2j{9mDa zA{eL{g~XTPL%K}?RaAp2@scA1IeC*}TuNSf1;r^;>y2^*UZ6jC4Szsp^q(n=rh*cw zhKVI0v%E+H8n#e!(o{V-KsH^R$#CFd-QK4~5Ig{vc&!N2Dw^!jN=KQ_?n#`)Xn;w) zR!3;q{_mO5c{B*cJkrN>Z4+JGGvh8HMj`Ir4)NfU-$_e{dQ8rjN+sY=kpNjT?3(Zs zpy&zk0f&on4#4GRZ?6EjV)g*D94kl93AK*K_kX`%7(IQZEEl(3#Ygsh)kRP%U#j^j zl~Qc=bjBYjANP0zeIlskc^6|sK_zX~Xte<(dJZT~0huA)hj&%8fRV3)5Vv<9M^{@B zfX#u*etm6abCz(N3Wg9xIlvtHe!$FS(qPyR>+xPCr5iv@89HdHH1XO zHlsyG5|>IxGee;Mg^Mca=i-B>(5Pwc@>BC*NU?V*BzY137yy{|h&bgqMd>>=NPE!B zBLCEvXT^8aF3|zgDp=H;OwCgWWX0%r4kMfJ&~j07)RAteog|^NA5dd-a=+K+@7!?j zw& z5A0qXd`bal)2ehYCHOIGFp+hF0EgS!oD~2T_vOwRz~-n$V7fGs3Kldj6Av=CqL=Ir zWCpH;DE~l$-6(%!9Ut|d&fhq}zsQ1vk)S|nV4i`6BXA`jf^&RlI`p@-cG(NF7FV&c zQhWU*9deT--y+9x7CO_TJ(o^nKmP=Oarh-b5yDg@fq4wKlwa1~LL9~nme=t~c_&6Y z5*+s5>P($Vx-a{D;6IgJ9%EX;0Zeel3)$~6Zwi`0U5y3s*g7QeX|F(tRUcY**iF|i zB9HY>J(MSM7vF%zb^IIC%Ll>O1(O+}3e2HT8%rt;tsR5Lke#2}N6BimP<-~h70+@o7Guy>=)Sb|09evJry+Dr0-9LCc z)aSCusEd;a48@EdkLx#DM-H?of|S8Iy<{aogtIFHaQoTg<^6fN^l-h|5l3%61Na%I z6!?FY08aO|zI-Tqu(#+)^^dpXhT$QOX6z_EX)$k@Ngz z^G9Le8Kj39!qDXqP$R-_2j~^NAQ_7D?7|gy$k!}#CQDQ4>tuj+MC)XJ2LSF>8Ds$T z_eYt+z`Lo`1SsI17`J7o&FV9r^suEoCUw&E_degabeISYWwb;fw@6E=3$O9F5Y@PD zVj}*XiP|r$nz5@n(}j5U!}`Y|fy0r5(7qvMN9uoDrH!oqphWzDuWs(C1o;Bp>ia8xbOXdX8Le~01OU!)VDK5i>6bta3 zM9o4IQi~s}&I|UBlMz67phc(rt3kcXlIOy(uL+4h&>Sbus5mR>#U>$4gLDkQj)|dF zi~Q{q<4Ohj%1;fumv{a|N_neZI6d0yVTeTp2_Z@liFo~it41dSuF`N7zLw3#Z740k zZe-W8#E=nD0oux;Z+^lA2R%@sL3MQ{&*L|C2_((ROG(swZ3l~(uiJM(8H$TxDwM(s z#a7@Sxi~CALZpAl6hjLiyuy>&{r!&(ri30*AD1(d!yW9y5P^s)5hv0E<$*2XUou%B zQM`z`t7=RMPgd8|G+uZcxFb-kMM&l(tID5U0^MZbq6go;anr=@(8meo3tCRTaNnxKF6^`Q@~k4GoQtE&X798&AW8v#@Jw~jL3$4c<4Ts2@&(KKG%ouqaKGRX zS^phJLEaiwSa1nn)|K-#ugzHDiWc}*Y#4c*%k((n7}wqsC_xVTf;t4|j;e?>b_Q=z zl1PgDnrpEBQ`h1;6?g@v3J5r0@2ijnzKW+Z%UqJ4`CzbqCGQ;d9CnNEWoy;b(xp;fwl{^64?yI(TG0$D4h8Jg8UOBKgm4_QYWiH*j@(A zdPkiuC4_kgq@6*z1vb|zeD{+4*32kItFs`RQI4h>=sqRT=XFdIKb%%_WSI6b7%zqQ z9Agw28PVjH{f0k1MQl^DhM@at18LJto7joEbVPeLcs^&UV6%G*tb06W&tn^0h{E5J zY7Xg#PIrsR#H(ewA-GV$d9y!l5fmoS&LR-4RUN3!;$8c$mZ0DXZG(45%Xp@gppWo_ z&$c+RkgmUtQCr!&NNAACe91WUu}BZ8Lh{Vq%Snb&KnCN{SW%oJ=8nX6VMENCx=CMdbYADaK0xm0QR7R)F4Ul; zoI`3U%*hTlykWn}VMHe@vPXbP;=J1`t~Sqxf>x~NXCf%E8`ygE{ZqA^SC+`GK=b%- z>tu@bSmZr>w;*%<0#HUFizlK|Uf_1uZm6pAduot@m9Q>Mpb15nmKgzF1iIFK3z}m0 zqEj91IcDHpaP-PR1uZ+kDY&%3e*&^E|LJ1VV`xGF-{r$T>z#rR=--%#{na&1LPK$H z`8wC7t^MnVRVWymN;AK`17Igg+je>#7UK;Dt7f?jh8oZ2F}>B~0g^{OSV-+O1d>|PM&O}n`WwGZU7VPvTw)Vi?VM14smtvK zde6B=oA#<5%zb5~m%k>e9U(~KiDyEPA?9{&XH_-4fB*COBR0|H<`uNm;J6)v5v!ow zqq8X6ZYVF^LD@dS?G^~4qEvrf36(~DJ6+&S5vIG_3CB6l{I-F z6jyf3V{0}rbw^%+iu2>V(dIHxrFHN`*ct0Sm5_`|E;-Z47ylIB$_Z#9^MIh{Yy1GO z(Ln0T(}1CCxt<-GSc$;N$0uF9^jI}d4rzQe@T-F9Qvy3W)nh8S;H%tA?Z%C(<>5l@ z0?+B7NKEiGof&Mx{95S>Q9l-`Qv+L8=kYz2v44=gYQ3r4GdC5sFll)OCP~O;kX~-C zp?iLIz(6(*NQBgMn@V2~>j3Z4_^0SlLJ%X_L_4!_%BAUros@+4n}XVerj;|J$`#5> z#PC5HExITZu}69z{L2On8!WK*6z8N1IhbMSwjU7OTI_8qw9{(2W3^Gq#-&Bzkl4H` zY=kh;#9Ju}RbqQa(~BwDL7-8L1WA-3dOdAGP{^{G$QHJzf~ux*?QCfv`R3F_k__md3>Q-RK6@p$^YX!TM?`^98d=R0 z&OBkSdE-F#e=(SOYisxzkc?7g*D#;ug9Msa*2YZ}qZE=4g~lFF&3iO8J@G~RVPNwQ zLHxIfi#4J0bTB5_C3x*Hbf>FP1l<-uTEin9ln{hUm3e14 z)i0p4Rza6N5lMgG9HBupnEshr|97%U1MLtyyi=1 zJEJEhI3EW*8SSKiGBKXet)Puju>r$96A#L@2b^CN@CkmTrqs)&pr% zCUygV?#oi{95pd%25tP(W)>~eoS5ny+Xm7kb1Y+e5lDE?JO|vZ!C4Pvb!ivZGV@$# z1t2^4kU|1DjBigm&=0+M^{-v2gn*} zF^N1X*}06VWYa}gE}}AGUI0c&D%m6n1d~MQ#t>+<4ulBgTMm9&KLbF+oG!@cu*(4z zqGB~mfW%W>XuKwfMQcZPC1+g7W3 z27&R5cWy?%L>S6Wt7rnxujFK+M4JUz{LAz~pU4^aAP7Z$Mk4sGOHLs!*CYNU)f?+? zhQt>HJ}Me``9z{=cSch~Wc|T`?UsHmpc=?f`kkAC^pkm33ZxQ2vk(?(agu`uYo)8e;2*j$hk{e=0AaT0G3Lx?Aw&7f2BC-9|^1U%uP z;${4>R1*6{&fzQKd{znTdZ5;?WZ+NOcrgyxkDOmtUW>~Gu3fPQW}HOwx#Bysw)PR5 z@R(s-qUQ8s>53TjK)N+Os&Vp7ghsGn0aXnA$wHe%0$)JPoMR``Wt6HX7IAMkZ*6Q~ zYw#9XYFQvvqb)+X zoS!UKI4O~FjI)+gL7`d~jrQ(>*FJ%2Cly@h66HXygkQBT2y(cn1w*96@V*hl8fMHR zRF(qXOyTm040|4xw1S^3RthXxNd=@xMmEWVVQe+L>LLe6r?sJ6!cV$D7Gf|=55>LH z-x4UdQMX3Te)V#9Mg5f=KUoA4zXjjeEx@=;TFljADaXl@mGu9yxkWJpeC=+s!_Lnl!k;DrzOG|a4aY@DYk+*osYgt^ z4M1HT$a63yy`|w4@5jbK8XMGFK-O{Q8px{KhBUl!DyPvH$U3>3#dAM|(SC^On4Oil z4tye~p=47SSxOTm?X)CQ)s&#yfxUw;$iA7D^%EH$9pr$_`+Vy#53x0`@7r+u-rVo| zHXOezJ-0MNzNh}BRv-z!8`8t+^`Pn?zR|E62 z`L3@9=4bO>Uk%L9=D%L$;+nF>Tk>Gv@Tf02>0gKs`?5{{LcG{l1oLzGv9E}mpUabd z#nt>=zU<3Z^9%82uhQmZ!Tjw0?90I1sz(y?-*^*!T zl3QpUzjhbIZF#m=xMLTDj1@iGOE!0-HC?ir>-e@e193I)_9d&iE${XWuCB0(4w!Y4 z<*NSe7Mv}6xK}v1r#ht7Jlu09d}}`L6`mCa%vF8dvzxm;FZX2{xlO&?H$}=6%q8S~ zBR}^oLAeaf+xK)YpIC*fyStiO@O8J!=Pf(CXEuFH-tL>gTH)?)y4Si51aNSA=QsptC^!K~Z#E&0B? z(5?mSlGR+-`(3xcY4`Vx!R40x-`yq8J4!b(U)`n$d{IIHh?n8!P5HprEnVptwVQr3 zUhpfz*nr>MiXVJVqrHYF{4#aIjd{YarlzTIg)akh%f9d{!MTjz{4%`Zm&xg0h(G*N z$@0tah_7;qFI~;g=M%pQLHdkd@k<5Z6P86HD zov+|%v>ePjg0!mRd0{oT|p7-?R&QLj`CPA9PcmaeF@KpC|Wt`f5dI^v{!q+E7a(&zrN)KMhvD~cuUIKlyp`C>k0*Ln!#II6Q>ehr#{YV@HVKN z(+u8h&C;}-Mj5=BLOZL#+o%LjGk70$54zuFs`Pw|t}G?+W-9iq0&k;QKF#1QE%#Fc zuPyzvGQ7)*0yTrTv~ExZyqOw8C7rERRA@zbo6!dhmO3vrN~N8>GGSn{x=h)o@Xi+q zOF_=c!29=v$H}~w{DKpL#)5x?&u;|Y!z$l`47?t{4v#02#jpGz@I}sx*mP!G_pq$A zWMk=+m9}L{h%bohZ#{S)9UL4SEX9Wj^#gvzVhvI09JBC7ES_-16)Av0R)!cS-On1Z zYIytKHi35>FdF7u$cvpl%Q%=qzzsB1K%=(s^lVf5@URg+D84NSSa7}w$5q;6H>@oU zW^+o?s@uU9rS*{+RGkvZNg}XhY{;%n^d=e%sJkac-@^)cg<{Lcr_bsY-I|`^$LZ-i zeTM8jROB}HjDlJ-cozCi;_-^&TqV3;M8sR;`|S$}eQONwjmE%PR9X6K4Da>= zjyA$$b-(3wW##a0EAnW=Q&+UyG=ldFDxJ{?-Y=+%Mk9E?pn@8W;QfMXYczuQ3o5fw z0q@r0l{O;~jp@S|61dbDAHI+Xrgh={a!PVEgZIm+&e06sFQ-sP1-xHKlvB}QPz z4|i$|?^ffUTwBCyaZhW&yPW{2H9>BU4{OHml)$w~>`vqRZJi*VX0Wal#8ZsnsepG~ z?@CdCc_a7A#`tiXZk9FTXJdKu*8MGu$fP!=F}$m~yx8Hk>+(|ccv%8(Q{R`2%S%=< zwIRF};(P_X=0TYnq88rfI*}#tHq$@kop#i{;rV%ovMQ&Yt^FG7`-<=u3-#yW-OiG3 z25(buqr!RHj<-?K*=Py8P2G+P@NUQLXyx^7>VH&#cRT(^8^K%Wh_nRWbsdpbzAv`t zkyMybLwK9<4>#_b6e4L^5|>%@Omg5w7o|6H#$s}|mLJk~Jdjc+qZNFLw&P8d_JaEt zGI`D8OC*ccPC{1G1*xdj-1&sOcH26_OwGKFF|1^48U+0MxhA?dY)w4s#y;a-W_XO% z%{!*AI(}|!C!>ZQACsyVEI#KTCio1j?a(__@MIekG2=<#xw+YM^LFt(9?^06a7)L2 z`}Fw4Ia&3?R*nr=v&2%XH9t6@!Lp{oy6M<1uIYQ`csy1zRpknlulaeV@$#AH&UbF? zup*@fYGgv4tx+AS+_>nNu*BUl4HzmLd(&`{97M&jGkETe8lc+t*4)K4HTK*OkFTg7 zsLP_#3jE3sNoYMq;7$h>Bh)((QpcQ8(~s6{sI_2MKDy~RirRE+`tj$G){g#(yrLgV z$JQPyNmxIunYU&-VQd+QChoQN4!wAJZmHPHzucOuv1uY_CvYj&Xl~wSZcm{#N;Ad2 zjj3$R47z7bjXh?u^e50oRXS8SV`1iy*|ezW;iz{2^(v@eR%_(;UAE@x{R=-}Rfikt zTG|Pj=#N)g@bdjuWB*kkCJl0={?c=jV1QNcVi_M;h#(TT<#8~OHEOve6LtjW3OVf>tt z1nD=ch7@d97}$6S#EUs@OrsD3XL-&gjV0u_!RYcR=5uuuC4#Vz3Na8%)W0)P33|9D zLsa_SWp=<$ph?Vu(|Zcia|7?K1s~K;pe_iZ*#vGV8o_Mruyz9VQ3<6JsGQ1XfeMPt z=pG()58U{K{-Z1(SDZk7m_q3Ua$w&=yuz{xRL3nep1{opFqBUK5bc7-Qzn1pqAolD zd2n(~A%T&x57CfNonz0xa_P>D3%LgO@QDlqKBmE}2AC`vRTBSk19w&I9h0unc$&;v zF^P;haQo=b{E^P1fDKliK$Qxxd;(2O%kBgUHfBryZ`{Vb;shL9v(tOl=-dqWZ5f@* zC(y)s!s)%C7e#SqO@JrspimQUioyh%xK*q6UZAq*O|Z#SU>A0P-g{odSAsHT9{(P39L$mR*Ju0S0=W$-DSe@ z$};ih0r}e%j#rk6H;>TYu5er#q3;OCbrWbFvcG&PYYE376F=_uGa~W9chxfS<}v)+ z6^>Vyi8l}G->z`H1{rm|CYQ*T%S1{$sr6;c^~vbQZp+(|EmsyPx8ujWJ=t<)k@AKe z^H-M3)<>Zm^VDB$4(m@~ZCB#$N;YcaAbz>_WPK+HgK8~9-vU;W8CF1X)0g_NCnu+WRRzj8r>b=4|n z0y7@+xKdqhe8m>T`7X`lXlJs)G&ViNX%tu4EJ_m|yFOonc|`C!BBj6dd@<%%EM^`V zEgbT+hI-w$eVYW;$>YrgG#RDl7RWXyZ#Agv6VsJlusZz7UG9Y^bX?xgaxDH#A|L0TT|#gI|X%?oFZgq;~&2d#7tO;4L9J8Cspiz!ti! zCP@`wH`7o*Mdd3wpRr)u*-b3`m?YEc-m{3Dt1I107B? z?5XD+(Wtx95tR=?kB4Tr-K6|>gY#QluS7oC^|j0#5n+9Cu8 zqluh#BPzr-kG&^&#?7Db86g?Z7S(yHr52Ko_!YAUN+{A`ZK!_|N%Z~2t3UPB|G{Lz zVq&{h6UdGeS|d{0^jW)S@5CPJC`St{@(puUD;cv6c0_!+uV6Dt)U#6? zC4L|~en_Y{_d_3w@B3G3Id~w5KS@JvyRFu78vGC}_6a3_IezsL;s;T-7dCJhsxD$# zWvdIbiX5XdjbeV~d(0!(GauMDKrn;GFqPGDvNO>GcNcUXlwsZXorL z0LHA1q5AKgE`Hs0{@81^c6M^9*41ijK=6UbB=rM<>a6!~InL?bIXTU68o%z&q>RL% z*Yo&TbTy>v&g!K;9K9L8?nvHCLXX8l($MR~*kMQY(Q&@qYqd@RuZ4_xI1Lsq8)MSw z=a?O}@oFEu1cR7ac;&|&iV1hg#SDxmB8izG3!b>BNj%Q*1Zm9HIq3W`WK{D}nfeFjhJ0v}iAgq)*&%^{$*hH0n03>+rzDSfz^6XL zbFo97;aMB#LM)xPx++Ag^^4-B%BTV2&XC6AnJ?K`CNX=WOE5rb1R(5yKAQB=vR%*> zB+ez3ig{Bq?=BC61tcuhFCn84#d`UBaKcNwvXv~H&bpdE&~J>*B4*S}Yp7Wa6|fZ- z*W6g-(-!E->kV41PTAPDehoAmkTdS<;Qh4ceZ`r^dhqMmmyGbpRzNpo7>k`SuY8=h zxoUO!k<6UTSg@2(zuXy02~~PIyRFt~NXAr?T)p7qn2MP?kFv0M*VLCJ38f#n4NUQv zn2Cs9hs+~%s?NK<2!BdOO6ZqNfZ9UQOcs+@G^A4&cQp#0D|$);9 z;+g;^eGL&B>aO|j42dx#8>yHSv-S#zF3BK7T=!3cLH7Y9vwaYE_GYVuQ&BN zIFdtCLJwOW+NQ{;+kz$)>)C3((3!#WeeN4pAD9ApqPT44ksqYbAs#{#CKi7L7EJu=UjO z*+HZk^HA`BwLq?S$t*re1Uu7XzVHJkoL44)59$e@WC85J8XNj8vOVW=h2TTLIk>CA z3Za14-mo~8i#3x~PGh6G}Jf8m<{GX|0np4NLMZ z4bWjiAIHj!N^Z+8dCiR+EV^#rHm}d1G<{HYLpK>xw(X^p`KY?Rlh9~TmAoj|y5$Hr zgI4Q>9}Br}PN=gM_Jm~;N~umo_8?p)BL+HP>_Ru6vXI68IMcc#1JTj%I~_&b0PCN0 zd+Muh#O7s>)k@?ZQ}wM?l!g0NOHqb|S!f+RdeT+?N4 zvbMGHJluuD_g(+6zvnP3<}@1TYwMb+35xN7h1*J@jXAyg_C|6fV0`!&Uc!W$q8MTv z`=fN6_ZmB0uPf~%naSdxPHyT;CHX6nKb@!h&r!ffJ-p_69v_367y9VwvD~jamsUdR zF6O~rmz+-QS}Ac&^1`%vBJ;QOeqP!-K08%}@8iO{P)a}W|A7?I;fTz3sB0cL4>F@y zDcx2?FH5dn;)onSv;w7sxq^-MM72g_vcgObhq_kx=W(QnS3WIEw32=}@$qgg;^WE7 zQ!)wY6qTK7@b^k)D&0CB_*X1GICzBGnh&Ov9nDj90zYIO=xr~fqZzbX1`_6j+QrPa z2z6In`VpMwD;DGF_IapRO|8?V9|4^1YfxZ=O4i(tDWTE2T+l+6rlTnBz7ez-$rXS|05~jhO>5<8(-Gm(|>iw`X8SD%%(m&`~8zLso4E;VMcB3^-l9~H3V%$SYFtkrtDFg((} z!xqo6t_daY&r%x`)=xnaHt6-7+rsByu;?X%#hq#5d#sn*raIa-)!QRlk{R|qDyibJ zb3y|p%`Z@4FZL~E^d<37 zYH$rSTKs!%GL5FaVyDn&tJUus-+FLN&3)85tbL7r9CgX5Hc{E-Ze+v)qpH>pN9hh) z=?c1ka`x`z!|UT$&&#Y_J3Hhl9bYOc0@gqwdCYL)_#8xCt+*qUjPPT1SP;RCRErtZ zLD?T#Q34AVs-D?LHcq6*e?2Y3EUR~<<4c^H5(KsS;ef!Gt*=wXMXP`KxO>n&==KMX zjvjyaJzOE6k@%oR{||U!8dvra-(k={6p6-p zP@@7!qJUFmS%wCnp<#&dkSPuWQ>SOHdm&jQKqLjpsR)f=R(u^g=Fwr+(o2Rkidg9J zFj&CA!;la6i9gW>cynyk{D>oNo)WY>sxByZ*J8aIpz#kq0Q(2u(M|0jy@KRGh+z6Lzd zWc%#h3AtvmJt+G`NFJ$;Q}{LJ(ISIb(U5S&2eU>VQAa{C@krgNqIMCgQa#*OLjkpy zgPmW?Ic;$gl1>K%Z7O;EBu>Ik#J%2CpLBfE>BLH$mU5vGI^rJbbZj-kC-+*v!KK=! zk^c^Duk8V8U-jGj`25ljJ@w>_d*;!cNvZ&E56EvV<9E|mceeTvz{8Q+@b-7zOx-xy zCaEs6Js|JX7y2czRO(GD@8r{#)DJW`ndhBJ+0&lKu6kh-1ntbbU$dXK!A7g5VD5^! zANn2}<+`*poiFSJ@}IcX(28@zRa7s}sGO;;dh<}0L7rJuSo6#`zyI1w|Cu&#E22qb ziT;zS{cFWSIs<3`%htU(WNvOz**%`wSo`T%y?X6-*ik)pEE?O}Avdp9Zic_Ne!oXL z9oV5Kh5cz|uO54|IH)*KD{LP%!kV1AB3md$o#Iq#FX4G56_=uCe5F|2 z(F@n}*f^ju>u3Nv2=We=VC*b-(iyR-AMWiF?dDclUq@Y&AgJqW!2$NF-+f5_RsHV~ zatL4!01XJ3V0f6D&uEb;r=*p~&sex{A}-Uk0bQa*je#R(uyDd-NTy+T-~$bU4`|uc z$YZ-2v;dzC_UVq@=uYEc)mGxqh)LSbE^>DHp8WRLwyp*9*Y-gDAvm(|e{B!`+IFV% z*Y@wfw_B}WlvJEu0==%u6eI$ClNJ(o#Eqh|idpj+JvD z0`sf0)6mkIsGcxey$Q{>279QiY@-!IMr#E|F&224!~{%gl9icUnP#JGB~haRgAHuD z75Cfh+BlzU*mUoXkqQsn8Tal9LMIbH^yR`BP0=?~@z~%_XZUEax|$Rox{2$(_2)nT zxoe&~rm9`g5Bi};<|sl;!2gbigpPP3b1+!7b9&xLMn_yr_QpIMvq-`}Qq^>i3gJ(I z9fJ~Vy&W@JhlXBsaJ6Xr~IVL|D->ikU#`X*v>WU=%`{{`T=NcL*e{ z=tyH`?Nn?*w)VZbUKIycpe<$2zCIIs#$Pp6<_Rrn!Ujg%JJvu! zZaF#JPhW)6FTCV2zE|_fy>!ezsN=bac`^!^m~pPquhq(;MV!Hlnd0&}@fZz|65?D4 zi(?*RCJKo{o_5ImfBxtHO`r`K7et}bd$=NGc3c9=pc=PUq_=_bX?2@-6wlFt0Xn`A z2@`ubx1XbFOg)&@F`3i9@mL=u<4maq<6ZDRyy|xkyGNw+J-IsU9&``(h#z{|s%J!- z7*tO*Z294s&m$_q|9ccO3Veg^Pf5CvDS?Iw4G6^|a$0qC!Abvt>K}M1#eUKtV?;)e zDMi^lwUeGNl%z>xyb&h!ii69Jk_&mr1jptk(V&FgaUD%?SP5h6>5qAik4#DCR^6UItGBh3@mgjMF8sMfMvoRo{yH**mFt-WpD;)!YBJ!GR9(6#5 zj+-8Oj=8>M8kW35`2MgC27O|4L6o|8^|C6?G96AkAsHLW{fzg4TFR=i3wfgM4*_|) zN_1z}ZZ|sbioR5|u(|Jgcatj``=BP?HyLHcelBuF>=P!(UBqVUdCXHop(BZA4D>4+ zX_7HXwMp+?l7TxB8-~L1WoE&=D`xtdQ6GO8F(E%hu{v>MCVJSSw`02K;DbE{iz|&7 z!JS-FQ2`Q?LgP$<2j_jvs5fUJl{~Jy4b-rr=X|W_(+Lj+`+LH|G58BSrQ^$M8hhX% z1%$;9;O<3F`DsF98cN1IxF!;yY`|d-k(vxsSq9aCMjx!N#u5V;EE(Q>bAK8ewGu1@ zaEQQNL@~Sac_LD0mcJN->!Eug1LnZ>178uy2@cPHpUFFBdz&hINZ1B zEHGw9H_%tBzBE&=#I-D^kyyxbpwJTD1NS`|F7gZqH1wr9Ffg{ln-LW{o`w>kh(CC1 zCu+BuggZfji-K65+uJ7*B4NxXsC9l{vK)`Phbgvl$sEcY)9Wsh!9=iFT?#Ce7;pk% zCive+-NW9&LFeuBm(P#SpTB-{@%((x*{8$qk=-Y=+MuuSLkUqwOr+7?$cPU22_^3X ze-zVrfy-ENU1$}*{`7-p*LT!6duko2x=LB-v2eWTl2>YhG9r&=h=K7^n+%>RazVyM zyqxeP^lE%LnhOf%62U(^8f4^m_qyavpO87dWJDyfHuqYu7!x~{B9@(*&lESPxIAr& z16_N#FxN|FGvLs?e-o0|{E9)L%l^?mIXpN#*hdck>d<;8s%sRmN#UQ8Kg5iArOTie zT(5z;rDY;IeA1CK)`?>NH#U}g`z741LU1IOA_=4+BidQRv!?>$jhM}b=lHUsgOX9w zC}uv6czOfc__7J35<=L3g;B>0r+S2^lWWIKV_3FC3BJ-ZAifkVn2?xFX>9#t%#uBS z^RnA&-M{~fo8SmoBa7x~yjNxs{`>p))kS+|D4l++J*a(=_1#qrwY6jn$W?zxc8y^h zWS9jRaXG_AhcLY(v-VC$YG*A*@m!yW#Xh0w5h&31x{9xJk3-psG$&D^0F8V-sSc=b z_N>f5sS#39c(8B{QT3zvfQ#(jqDCmfbnS-r-iLVtTX-LBqE=>t3X{wuG>B$&#B97` zNGO@{Iaea8+K6k4+D>D-H^GVNG77chiUIUJ8BaG`$0PXd`5ebf(c5wJ7QRGC`%TVmp-_-F(P2WSLwYYP1n!7Sh<~hKEggXK-wE zT6>%cHN2r8=5Ww(p*A@MBb|j-_heAtof@LB0$bFumZ4Z5{VjchoJ)@!Lxbs6dz|PYv z?t3XOr2}MA*=t`r_3F$&7>usHJ5b!7`d3W#8uMgoTXs-@Ms$3sM&Ogm zJ{?~4F>cbSQ)SqnM=`%*#%%#66k-n2u@<`#4JXtOl9=t2Ypn>$c!JnKSQAhNjf7ej zD#@JDP|JqbjLi9!S%+ttjdvmmg|;baJBK2>bTUy~h^Bzr_>(7{Y21}o3K-XOGmaph zkNu_Lh>NUK3m7Q6WgNRUT)>H55@DAK&d0#6Y7NF2_XOG1Oq%g&1l5c-7VbghVP(KD zYD!8v21|gAgbl!hSFMQ&x^^+4GVX3S)J8P(pcv-3x1W)uv8xIAO=W}AwAPc9Yv=lcLeO8C#St2}z^TPD%-9xesu;F@zL&4Q){#I#F?G7}N>`^aW2< zzs`5yu`OdB0PhIK+>AaX>qqZoU|=>(+upSpAO;)gxlv+hKSld2XuER}Ci`T@ufYo& zz4F|YIM&4&VmBbml*#9k>cM~s0)^qv+SAKP#E~szMWWc}n3C#Y_n_M!I_Q&|tDy)v z3~hDDFFGJyol3OB3cJxG=886k7q!D@$H3SV1sLK=wiiS1_DRUKX$W%> zpzxYv%eQKh-N2RhcW&p0Ww! zAo1M9-(YkHHSj%1v7jXb!L(`5qhdDVG%lC;D;Weg1PL(PAN8g&ozReeNMnz*C$Al& z`!~VEJvAYt3L%0aQoPUc2nfXLtjmriWXRYad{jJb|D(gv=(Ifrjv;duj%lK{kQy^# zH3Rmlm}$UcXf9S~PH^HzbAvkA2sqdF-Us(5C0pqGbHqP(Nr@fZam{wlrO{(~JY+f; z-zEeaIEmu}r+M{E6sg{wxIP~`G9FbVI{yoz4-d^ zJ-0f^fOOL;?Guj^s(m>4bx2}gT<#5YW;N}8*Xcw_JY~Z)XHv}OhVN9XihdNS zlB*FmAs&F{N}Hhe3;PeaWkVPh8f4_?)KpPe$t>vPPg=qIePOBXn_LirS-%R^mQDD< zK!L-I(`1T7(ou44K9kO^@X^AYPtEcU@T%tKG0qdS{NN(jAnJeJ`0 z(@bb>2l*6C0Uci|B(dQ>OlnS;st3VpQ z{x|R}6q+Rf%(045gk2HJb3V6u-at`p1U)LqH46faYBxqIDCvb6T!0P42hc7fAw$x4 zg+yoY!7gMGLnca*A5d}Tc}lV8j3i3U^EhbXUHSO=&m15`Efj?qD~qp&%XQKWj^voj;E+! zCaKrcoL$u=K@?(@9crK-fH(oFnJ)QRu)=8IjfXAlBej`~f=be=5lrX_Oa>>xLK!b0 z(j9&Jbk7hv{UV@K^te?5A4%)X=xB0F2+dkSS`3YpC;E0D8d(4;c||ePY7WIB#xY%h z7E8vU{xmT2iMA+*Q}u6{lhsIi#;wMs-44eTQ8^pJh#4^x!#p*vJt$$FafMMQHH0HK z)Na#o_aY65*tjb|S;OP*-0@3p;jx2kIVOdr@D-mhbXjZ~MWT1rA2CS}hh1_iQw6La zQtyhzl7%u@v_Orw5B$8bn2KbCtdw+34HN1IU2@JCsW*N0v>N{L@Ms0#m2X&B$Ico?^ zjubhB-2{nJZ$|1WjvzSkGZ&g}ca4u$H_*=JLMLB9HUsCOlg+y7IXyv}54VCzb`e3_ z#I4xpIN#)=V_daWSK$xobjDPSsmGpxnD2-anZO<$f*yK=dA_Uy3c0Oa@X*r2x8e(t zK<_!*TmoSP3NcrKTL1;S?{wrMVo#JDO*+w&d+&d1^9bXT)S+wdlXhgHvDEJL41)BW zGlo0e{{7c`s{mjowQUg8;(m4WKXhXm`#nv}I*x^BTVos?92`7)@BsdQaBz_S|3UxZ z!B_nU2M-@Vc--$lIQr_K|KQ=n2VaqcZ2?gCON6BHR|gx9m7m-nf`3H^+6Yp%B1}r=O zM~8>G^Z)SZ!K1tLe;Yr%${}LRvg9VyO{X)bALne&?3^q678k|KZU=KY#x}?msxVJO8)w z+u0#M1bjpT^2~J&Pqm|vL`nPSh9#MpN@V`D@xEhvb6s}#bE!g2IKmV`0lb4s6WSXg zjbohF0z1GbZ%q|3s7;}soTa6kT01)}>}3EMPckhAWWF%}eof~r{le)1+bJ5Be*6<# z;9J{DNFLLvk^qHJ-JUytw`|z$Z@*)%BJE$9)~wIC=&Mg+HW`prY9OeI`Xv(MB)3DP&=)?yI$GI&VVfRX>Q-IfQ*4TSk?&}_;;jvZFd_nG^Z`r+l!UAC} z757djuem%!2itqOSuafthLs_DJ5kI!QG#_#@R^xbS_*AI+@Wx!H)%#tTN%UAYvmEM zt5-wU7&AITjNuFxHtAD7aY46aH!HJ0*pmx^&sJO8Q!~NIb)wk6qEbo7h;%(O+Z__E za*SF~q#)M5#E^Lq=3!|L#`jN>Ab?mLt03P6(q!yFg`lK8bu@P1pQhs3AUBxmbNN8n zk9nN!%T)d_&X+BlWTY6K4_XY!3o;-_822lTi-&dIaPwV35+TQ1$vUc}9%5;xK3iIY zhMwwM=U?JsI)tg4AZOr5Q}nJe?y1-SH2L9}37gEiY*vu%3zJV)dGzowI}FAdl%Qii zv6X4jBBbDVR7JedVkB9RBd*2K>dC8RkTjju$ZctD6}7FQw;g9b4M^|W#Mh3qIu+Kl ztfRzBY4O&n@iytPonQ@3UY9DbPnU0=GTV6g_;bb+ zIUo;Pg#10>aWWr}!xkYPzYdQllEtt5An*km{RiZc&X78xexS&&ZQuVEUnp)b2v~5w z2*+YT`sxvnF9pcr38SVJ~M(fbbn%#!(ts5OfxOg#bg;Ab z_8?KrN2QCsGH$2O%}^aXOb3VQ?Kq9$$)1^_X#?&jIVFR>Nh~%$V*y>98#H~0l)`mb zF%KnTZ0@Pfd2}(0nV9jwL(C<{x88aF5EygUG3KTq>#qSBCRKQuSvV!dm^W{;kmD=h z1PaJuN{5^F< zm@5b7m_9V{oMF98uvI(00%`s>p|e%{go@rSoQ;pOu2#1JvPmpIEYDB8LysJbR zEurA!fsNP*_?QN*Vve!QAjW^6=5q?B)nSm!F|;>J&ak_S86&#goO>()$NMM>7F`1I z9hwb<`=~Uf-I&KQ8*AygnAHw$Ka*C`RAWF%2OQ-cZd;H5l+S*sbsap^Kqz?koll`> zOu%Du&*7B_5hLM(APK@=cJrVTj|u6A$do7`_PVLG3_(ZFb!N8AN*zO1m%?!Qgm|J$ z{)^%^)xv3K6CP)hA9}fWu%5f76iEt9X#zRKzp8w3pxn}kevIK0HE465`LG&q@XriW za*<2Mk?RT-j9tqgK_D;FnS4 zdfB8;Gxw*t8%YPSMEfg(?Z#(LqbnAV@(mKfioGhrlmBo!X5A!A3qRnk2NNLge+9~x z9=(Wr#AKQx+Htb1070I0nh2Ob-0+IoiIebH{47{(pQx(=3pr$hXG^Of*z>wWeh$$$ zUb=C&x>g-#X^5He_$-z{(28$+{GGZ9JN1+Y|LxAyf_Bx z53^mFUVdT=yvSc6J=Dqrs_S#P&Wxpr&04uCb(X56RWUH$4>qq*UY+cwz+&{pUMpvj zRo76e#F#^IS+Ar>h1z8-2;u4kMK%tls5?~BFq`O zhb(QEt6pQ(4OokYw0m(9cEzl{vckhD1i87oBOT1)$TJfHkCGJ^0os%=z|Kz2m0$;M zw04O%!4)J+4p>LZpzVGcvnc3{==d_=(~j`}!ASq$@WFi4&iW~+>qhH5=5yLf{eu-_ zXe-XTyDprV(dsE1#ZXCeHDhyq5p`2Q&dn5v&`axMD~UH?k_C&5pFX7Bg!F85JcF|x zYL_k~zh$zT}opg;673@s$3%?e!=Q2&8c80w01 z;wBjp;~Ddk00J$#(=KTX$>YoRO2)vFRPd>?ZJq?uj{?@QBMHY6Xdk{t26_ecqF($v z<>Eh=axsqrI)5uJE1&?{YKVz(gg*lRQZo$kOpF6G@! z;v}~u-K1Fpa_c}%CGTkU1M>&qp6{9Ncp^Z|81D=#FcmDuimMr*AxxTfgv!n9P z%ot^uwL>5V%L46`!qY-yTIZ#chWfOf_amyA6#aK+?EaM&?glM{Ic2cr=BM_0D(DLG{hE79N<&9{p%dZ-tdMmb0+i?0Eu--Tv?O0V@L+oM?e?s; zM50yKnNVlMB<<+T5-HlMCg&QA0r{<6Qka6qV+dWKbMMiEHmLO7l}dS~BG=5lUM4Ah zFO#+2KwPtSq#dJBP+1MAcBy>HvU zwlW4^H*z2Kg%!mbS7r-Kic4DOu}TkVdy8xBXhgNvIVU7Tp(^GPDj_HIBnfm9N32L` z5=~kSWY!x+Bev>%Kp+6p9aAJD3}NQ+A{z(|LHb%XYsd9N;;}1NmtmYT;AHWTk+XNG zgwuSbb!_TtR%3JqkhI$=vU!lqMV8gh)DD@%cw`oo4z33$FsbBE?xXLWHrg=J?zGFA zwcGppkZDm#*kYenTla3E3>-_A&pNV!kOGtR9Z z+r;eH(OKLjWOo`J5+0J{U(WZ_l=Vi7ta|$4r|0|XHThTaCSu{aq~puIoKY|1_S){? zUZAbzmAdZ+Eu-pH_w+BZFWH-LjM%D#@d5ev2j5b!!miod+I-T8mLO1NXKBZ|fC-rw zj2rsd^N&%?FuL5iqJD;4OG>h)l1&%;wpu#w(OV8KM*1rr6COUppvyF%UW;3GGKx)x zX+kwSkOK?#xIM^{-LbC(lf50t0i^_9H@H)~bm%{E8!%baxrTp`h1hNajV0V0`g1$q zRklEpa79{0PpA9>anJ#%w-cFhj4dH{p|Ma5s`vxNszHJ+UoPx%u(UG&!uVcib$#ck z)lWH$ogJMn-c-hi>&+LCF)Q>aP&ca@Y-!pTvosk(uD*q?UT!RGgvXF6#h&;EUDX zRe+`+-|6q}^mkvN{tgN8Tb8<3ZNpAdKFX^4!ENc&{y=7%;wA2p)Pe@31J?kKACz{sSb8cY%J*0{!p|yvi4Mxq0uGog8cD-0L7>T9F?vo;-jhdH@tn zkK@#NjErY&eA&5V3rN%O6I<-h7jKk=@)HAT*J+XtUs#JJERW0LAnw`op;kkTV;ZTO zNS%Oo$pMJOj~N%ebes;46axyRR$tw( zc&N@;Y5pCOkM~W(3j7IFB+%a5JL#JNnPZRkI#rzoBRamcffy;_FxOxb226-F*Qss^ zN~|jyDDK@}H?B|e^^D4U!U~BCo|tmDCp>0v&dGa+N}cMA-s=A`X2KEcmOU(4(;XRj zvAK&g0~=8R@nxGsmOSh9Qy6|qMvUAFAm)?^9Nb*#hSf-$42Yr)% zWjRL7@PjSO*rJZv7lf&QQIinX25sy^3EWJsnaS_=UPL}p%yjpO`cD8>fPo9tir^|^F z*bnCbNI|#0&J(TjcAhBoy<#z_K3N=V#uVStJe9XilKGq}R>hIfbPf&j+iyg{{51~M zwaV z52J--V!fTXPx=Q3+5USq!_Dc(4Mxj${5|Y9R)PJEU{=BJLeMfsP-#3%@i~cZl*f*x=^@aKu*#+68t)3v2`NQ5nEb82iiH% z)q@_xhA-;CMm2n~^J1>dwIyv6eJ5rt2vR}2-9Km-Bx_9Zb0antbZGqUG_M7nRK&W%mw^6ax*_KszutA@~SF_7`a3 zCC^MC)U&6qs(c@Y$&}>`Vn)4%!CtkqLLJgJM!BA2psqS>CuZN&bK@*vsvqirUgXG? zkPd2YPodyX3Mrge-(3`6iBOEQKSvf8i|t<1I8@*4wXnZabAk$I%Q_r@8NYc3#{A)O zk5=iyy2}(ukRtxbg*;z~bPI0mh@F827NX>I!itQ?Na3*6sa`Q&v8NWvMBeEbM#$kA z<%ginIR_L(#} zRhd!yb5H2*x6&^?|6orJc*wR+0hXQrgQNWUe|Y%tuKvTV{AfI$`I3!g60-qGk>Kte z|Ht^@`S<73o^j;^)k?>fOb7d?|(Ua{lkB1{kQ74 z|EJR*pS}I+tN-tR{nc0hpa15+`u~6R)mNSW>wo{hzxwL`_rJ>Lf0px)N|68Ro1+u_ z*Efd;GcM#eN6)@FJfu<7^?W*w>0ER}Ccim6{O0fgWNV*!_|4(L;X&u%L8pIo(Lea+ z==j06-y9tu9d;ib9{xLiPp2%@9X{+Hd~93J=@*bm2( z`Ln*im`wW*Ic29a{`doSqC{c*=1d8&eeC4nyV>i}cjEfl*+Kto{^&Y>Hv9Ou`4x>L zZ~Dv88E3P96aSd~W%|p5AN>Dv_V3>uKKi(lUSo47pn|8~Ns zmw)*Oz4*7o>%aW@o5L4Rr}4uV-#z%pNgTg^doq6h?(k^z^p`jP_VD9Re}DG;Jp6yz zch9J%y0vXIDpgQKdPg9jfIvbE#Y9R%2k8Nk76`rfW>k<)K%_}A(xfN|qSAW_ML?Q> zh*YIl>5yx)Ib)phjq{#!#+x7fSo2?}GMl0D_fuynGGZ;AjtBv;)e=&`we_NZSsr9`6AQ*u}XzCexY3j=W!3dP2sw5DsY~XDN1S5=< z?xDTibaXs{U<4X1p(dr`uH%4Kg9Q6}+nIRU=qfq6gY*K7jRNl>13^ZbZYsg%ws2`b zUjqaP+B-otM3*R=!-B_*U;8*@Ijm0lksuTH9&egnj$@P%>wSJfZPn-^_8SOBxDg1E)Y%6 zAb%-U!yswfAURE+AY~0L16M~G9ce8U7aJKHl%%8=!qiyZ-#AzY<#SI{$sowj8SEu2w79%v8*1S|W1J=|^0os8VgWD)Lmo(^VOo|0fQFMlapQ+sdyU>jds zq=B7}hr7ADcaW?-%K4tVhm@n6GYaV!Def$n%PU3=&PU{PlLy`P_oq)L#Km#uxUtDd18$V<=MPs`6s-SID% zHd75U@k0mu_-m^LddjM}L-f!{Jzu+f-XLiY2vQCyVXW;JbWcj#MGFxmi#GIAlK`Uw z?-{Fs{DEMEo20TX5R8B*0VP#{V8lP8@=u78hX2YtlJJ=|B~t)^7oef4WE7aaF&%O* zb^lw}4qmm>Nr6p(yCM{>9M#coH)2y{BU7cLV%-Ul>YyEZPexBqKN<1=qT9%jqRa(FMX1w*jp&4g&h^PEkpDW8 zmQ?~E_?((ZBrZ=>@_+l}7MFJWe%tgk*W<^JJp%&N`qFL>eR8|+yFNirBoZZFXtPRK z1G*A8qL!B(JG#1TPY*V_ySwi?IhE`cY07sH)vupQ3Sy}#Pk*LcC8eZ9ut}nMZ{DQJ zk@tI2U$4;C)+XWjg*T%g{W(X0#pUbURxFo7(z9oe^VJgPM@tO5`}$ODY;K4$(>%%& zZ)`A_4M?#rro|Tfgy%wXbaME$k3LVe^mDLlz^UXtJvAuLH4=5MGw@HCva=?85R0) zIC=8(=Wm)6$MenCUBsZ3K3*qey#^?O}e4tIe6!gS3rPFLqns+eArPiL_VUIDsJzK5R(L`^gVNw&4M z&91CaS53x$_#n0NoN7JMt`b&y1+U8W)~t%6F?hc%KM@*RQv+G?$rhH8VZIY`(1A+4 z6M1wLxZ-1R{S<{sp5QrsLxYVm7qx6)ExTXcHBpIrmYFFWhAmc!x_Sc)zD~M0T&Ptz z=taH0#eA?7O8R?v2oZGNCZ29B{0Q0V{NOa=xxZ?>;^X_XH&rBXlLsu&eyMB|5BvK)3DRU(cAQ*+blLVR>JL@6d45t9|)v>!l`17 z@xv3>6A5Enr>7!VY5+cwM{VmzBRxHRD@?lVrKYClHEwQfOUvCN3|*~$MROzy^9hBy zf+xCr9fLrqF508xW1E?#u;HScZd*SZmq$w&(1R~;hs7F9;KC}JBW*ATtwf7J?QD6! z%S}y9p^^zXx6R&@J$(4^Xrp?jKyOI;V2O48o%;k1RpX5jlM}Q>p@u3^YKx1D>Ns0< zd?F8Ch3-zoN0)I;T%OkYVC96>#sm&k>x>bT75t2r{EV*JV-vIaoB@iCjZKECm`>n+ zS2Q=lJo?|1Q+?a$*s) zc$Afu)fcwLb~-|NfF}ynDq|wK8OX`Ww+|1~q2Z+~!-X`lv9Se%o|g}bVC#tjY_%|z z#27>Zd#m$DO`OtLN@{AZ#&f}82MGD;2+x69a{PCk4PJHaYuOH-2cwQtlJ4&Be_CB# zy~lR7leia0cqWj4;Lr^Mc`vGS%6Y4v(3Zl3gXP=W+6o3esSb)Tq&X^K?FlimGocJL zEMh6p@Kx*9C*&E>u(~}q|4!m)D^Wdp=tOcfW1=xc_GEueD2!sPU2;${e5>hH_k_0I z8nbGH5$I7Tu%We)WhNh-$6`Go2HIw3Y~MaO@rOnBPv9~qcr?J8m`9JhIx;{gi_Jl0 z+1Rl+rl_-{oneQG2to;Io&0;0tajRV4i5QR>0-kUNmoL{!cqyXD(iY->xlv-->rZu z@iC7tQO@^?H>W_uU6YcNpS*g-yCTURK`2QiJQGMgeN%9jF;VTo(}m>{38R>7?GtZ~ zzeIUe9j7n8J_woM(J-iNUQOX)5PVLpp`kJCki;b*D9ER%XmJuBY=h|{?KGBPT(p;Q z^VTh;-@p0`2YD5ohYP5CdwUB8iy00a6iF)?oykezW&nXe8B$Kkdu(=U3;0C*>e!pY ze>btQu~FC4ONWN9-;|bSqNk@Hb{M5TmE=B9OEy~F((T2@3=bPfxqQ_=q4j>$mB6vk zmB2CVFd9o>V>#v55Z*Iou*Y{)&peECz=fHRY@lH$v!`3l>Ck+W^}!m_esY^LZz>4> z8pw&8ta8x8?Ns}(Ph8L$A?_B9q^73M9WUXc5)c;X&n5(KhoBU}H`c>g56IW;?*R%c{(Yb$Ygcek{e*eBk6cSI^M zC`kH<9OOBBms8%i+p=i2tNcN|?|B!PO%)yxHw6aAL>u zz%2L2)5RVHPsQ~(f8-MrD_`A8z+w?jPPZOqSq<;)?ml_#6!^PeR^P%RbP9%h@q&8x z7mxMA!a_LnZFB3%_x3ej3ly4KT07rd-p#?zkLf}~Lz6Nyg?CTy@lamnY%$ck0}Mly zP4JvP?;uX#e%w?L9oJR6OxpZli)sGXG1(YhCDojaEGjeIyyRD zy?O;WCv0JIo!DhOevp#;(a{kpY>dyvbVe$i$Am2!0`-pq7Pq(*{AqI(0@6rFmPpXB z#jNXjq;N5Cb8~kO4yHpFJlww5&|3*s9R| zr6-4*lU0;ZDDmAjrtc zb8Bi?p-|}2{b(*wWCTXy4Ren)3tq?#I@f4k9~ZYtVG-(AXApCBOG~ zneHSgcNk1ZOB*rf+_|?hLeIoR&cnmQso+mrq=zdH2EFJlBz%66l9(MDtvn(nYWAK?4a@mB zJ)Ond$L9jT>ftf4&TlO;Ha51DXBYL+ywZ70_~__pw(Tj+&D*y-mxuD{85tvzldu1@ z)D}LIRr!~&pf>)|-{80QwUlM#qsutS&qN>8F#O zH~slv{Yzh8Uo#Zv7sklKvM^kzRbgHRc;qr(ZcM-&A0I;kHaSI^``pg8e^%=mpPw2X z?K-&mZ+v^&^IS*^r!R64z;OD!mFRAZImunm$dL8;;kNYyxDa@{QN6QSzokhsaj+oe zxi3~aDO?O82kS~RO<{$Dyp+q+^|A*WQ$nO@#CcW1k_(hE()#||7R?X2bh2bpq2Zjf zFGDt!;P9t=Y#(hgU7bYr9Df!#UWYKeQh=d_>DqssX7y*q!;%32KMg>yTGa!JJal8BbH$LIS ziXHy;1OTs;6yw_XJCX(OjT;yK%E>gRl2=JNdHtRIPkaZFa7xd{c8gR$iuLn7w`Y}B zBv+pj*eFRk`M@-17j+R}88}DoI`v8Cg!X;wul_8M@AAFB)gilRkk{Ff*U|B@22M$4 zduOM$=ebbfpyRcJA}DF5&3DN+y2t?W9I{uvyu5}T?p=CoQF~oqU;ppr&`}%ksHmvu z{Z@pZF>@Tb+qVzTpzUH4xL{H}HNZr&GlU#&!b#!FW<;k4BS;-=&4`CZKB$20SHP0( z3W&7Qf&f2^daMX|o=(ITvuceI=y4>lxoZRNB9R#eu;w33g|A-=6Yh+Cw85O{q0Dy;w$KtPFnm8qCh|e!tdEaH;ut=3k7{L}J&{Irc^VbI4eJ-eT&%{J9jKbK^ zz~ITR{wyur9OJqkhO{Lc%7OSNY zu*oT<)4snpUa03Kd{9J3a%k_TL|T|2fE4qVmX_*TTF;@Kz{1zB^B&au4?9HLVBV9m z{-Q9Uwj-l>w8}xx^+$u*32l0Ec6PjFW3UD;mu7wNcw*-E`rxre2`rtR0U%-1Mn+7z zBg7`{%qXb$QZy{GyaKjlgTZtXv+-jmKDD3=fSsM4!0lGbXE`~y!(wl6-3eyg`1Y~A z&Tp+iZwPp>gj|2;zdl%L@e!8J$pG*?SU2-s877ZozMTy1yvHnNL50C!vK0b!PZ%Gd zFxXb&Y9v7}Qsi*yJu1(@*HVSBx;e3JZOSV?zCaj^$MCgwE8%b^(Y`ND1BX&y-`bqOEmStwqc8z@ zkbazfUs`V1=>hAVV5zIziZ{cs#XOiZdU|?#$MJHmG;u4jFszm}rn&;Qgu+x;G&kcx z`jkAFGtkSxd1~LSA6z1)1fsnDKV!otE8ww;&B$jD}Ugm9|L%1`z*#9~MonnW_l z@v3+1?Cf}jg)h5(`_S6`jQ?47wrdT`*8~pP3a14TZ?KPVoLK zqpJwNeg6}$q9W&mdVlzM`2&#Cus|sBcnN|bHtab`_xAO*M_%EO@S0au-0kLH9?GZW z%u+;Sm-iuVWwzk{zapHM8Su(8hzBiSXl_eYoI7y5YkLB`N zy)!vEsjjQrl`ZFU?fP{Rn*HE5#mtY0Z;53RNlH!qIU3SkIl-f0iz$yowYBPILmn?K z+Nr9k@k1c2ISK)hSy>#~f($2zTZ!G>>Yp>EY2KKWwS6tS?{&0oV~0lb2?N@cOiu%T z1X1qn>`c`92)%#*-gBYr%8Fj9Z#3yh9JDzZF5eUpY43ib@<(Yfyo8Uqm?`Z-p)>O3t(oMCVK;dtEV+X?+5*b;*=juG&XjSx ztTXcEgOg#okGJrjhsi?(eapR5O&@yZJeT~-x)qd*8Z$kH5qIeR%gh`i==;`baTaw)h4?cqL zC|>_2nea{|ySB6A-_MehpIBiCVh|U@$m4m`;wF^lAtFytF5Z^YSkC^z;~8y<8j0rz9Z&@us7T7~*l!UXXNM z;0~XR+qVc)%OLXU`T(`@@(1+n?6EpoG8#C<{-5*C*W_flvezSov+hp1QM2?igjC21 z3Ir_b{dG>>Qq%_T3x9oQl{h0Gd-DDCzHM2q%Md;5p&YYpe0l_S*-in&AD?J-IsXpS?^C2j5&A zhw{jo#Vtj{us8l7A}pS`i6u;P;Z>!nsi~Jois*g>E?lvn(OwjV!{He+ZtNE?U3!+0 zaWf2iqk@FH4)DZPEP=p;CwsJjPs|V4`Vk!+J&VgU(E|d3RCIJ|*4D2^nxnqooUm%I zgiTd8N1`y*HD?(aAQZ*f*;$3h40OdXNE0=?2!p}S4yHVYieP|C%W!DEm7PTb&T3K1SJW`;@ElES#RJfw0$`@kAAfG4`!U>y?0CO)}1?C zmX?+`#l_R1aI(|qemBDRPn{8#w^fcG;@$qm`%?BD5v6lY+{+~_z@r0F2Bt~zM z3sXsqdGh4q(dnrcPHBt;!r^fE-_+4uylOro!TO_l;ovLh-rn9X1sV)1lG#rPD|Dy) z8i>uo3RIro+Sj9nL|DP#EB3`-zuKmz?w`;`*ZmuSI)@2jeY3bj~PB)ch^nwolvvp4>gadxykzO?f* z-AWUuB%`jOp>*$F(jMEDHsUCW`SlWv4IXN*PgT>Q@Yqyn`1kJI^+}vVeh{g)of;C1!qmx)_7_6O=lJY9(_pf1x zBra*EVKRGr`@bunnu#$P8LZlwQW__;@AG#S@TmROvHvissE{ZqD$>F!`KM%N#zsd| ztw^p$5ZFk^CcGaYWRF*Ma=Mi%?IIXPA$ND7E5VBd8YP`OiSZ=<%yjZ5<~?eD%A>in zY7i%|J4RDv0Ed$cYG*vk&d#2))HZp;Fw>^UauOo zoo#vCJuuLf2ao%b2dBw~VJufi+$vCbY_8AJz@Jz6SFT=3c#mppZ&&G&-L_~5q$gqZ zhK7bxlf#r-hW9KjA5O)s?5&JILXRW>v#VooNbJ+r*4A_5oAlAqk@ZYdScQ4n(RefQ zDT(?C>1IEA?F0!q5dEVcoS!YhD&3}Jdi1K5#2(a<>FMeHn*dJF%6c+d#=LYsQA)J*BeC;Mx2OG{C^ySr1w zx=Gir`OY|xkpI#I!0ZwZ6ZzT+61?sMZngNsV0`w{c)?P z*G>@Mbfrv%fYz^uft+MY8+CX6+KUk&%)5ziXp_Yuwz}48{K2j z1%P&U6ao-lUX^=nx~;^$D8e%V{zHdl&;>wYVWFpwPy16EmI6I5r=@|M@YhZ? z4+(X9w{$y+dyoHo9{z%x!;=A0($m}f`e>Y-oQ8{P3PwkbKDdnQp3s8U^_c$voI+SS zD?@7V!Fo)8maGayXIwB?Ht&fS`6p3-0}rKt3X& zZL#Nh;oujhgC)iFt#=c+-!tai`YyH(dg zO7vM8(7@%ntPg@Ftfnhq zc+a0i3x92+SS&U&F_G?IeUd*ccDU*I7l-fimkYmt^*{eRGUa3dJbEsqm*+9lM0Mp# z=SP?Efrp>@Q!C8NhK1zda5%ZiTjb+Mj{u6ti_g{7 z)svt-z{mm!y_;-kc4rmXlYe{|LUKco4erQ;c;|w!pF-Cu(7dWRScBK z%gfsyP}m{`okGB-s)-4+`}dj~gp%Z|fAo;}nE(EsG@}ISzxwMaVMncrkq^&cb?}nc zUFb0^0001Jz;#v2m93xrclS;I|K<1Z{r~?v`~Ls=`@iV_2g^!J|NH;{$w*57Pyhe_ z6TkoL|G!`i004IW^#6w(2-pGuWJ3Sj`~N{eNhL`sprjHQEG8!d`oGctZzz4+^`1?z zh9LrNZzU(^tuGbm^xxS3FKc4{zxw~(Z37IX16>1yk-i`ozW{F|SBZQ29;W62e)`_V z%BE&+_CPQK?P`Dkf|ZSQ5x!msRUK_ZX#@2DLoKv+paW7%-&@BY>;txuHS^Mu3Q|$h zvp4W@(Unls@dtttcG^HNLi?VEgrS8|2o5MZxs z?5m|AY2d75f-q4wcQG@Q0C|9cZhrc%&cXMbfMCQuSvj3R zKUZldwIKf>y#QI17DycoaTFz@-;)< z(>Jk^HT2Qbb@4FM)V0&q&=2&n3knMM3y=V-+p4R$Dr@luR#&>C89AX_;nEh8C6 zFBv4#Fv3?4f-v=Tb+I!92k97+mZ9Q*&o0>8L{iJd?Vhe4(gz4u_A;|m zbFuR`(R79c=(yQ92g}&&BE2LvA^x&{_J&Hq(lTy_`t|`z+DN3Dc>vPI4KAZBsq5$E zBO$Bj=V)f{rRk{dtK;Bipr($p^>X)faganKj8#;CU}YD$kF=wnx1_$4G6LmhuP=%A zQ*(2$Q}s~Ol!BvFWp$N|WVF44{H0~x4MAvcl&q7kG+53_M^;}}6{0DLRtJKW1A@Jz zNh>!dIsX57Z+`CRz{`K_&37>}+GnTOF1tH_%T!Q)zVP$2Bo#|7)AZ+&ljbkXi>N)P(fX+0`tA6$P@;<8TaM~RQaUY2=Po_#B6#q4);9UQ zE&AXyX6w$NN7*s2gyi6C1D&{JJGVx%z;*|Np5l(cl*UDRdO2*Nrm6scnlSydcx0)n zD%iHevQM5oA(6dwj5&XT^MASQq0%4j(Ko zF4joVIdN#Ea(%tnV|kXD8OvfBc!6+w zsD^`vU1MgB933?p8dCp>EVZld&yq!b&Hy=1*GVg@s60zfeo|U0JXE>vy}xSgI$g(f z?YTkZt(@sIlE=6@XgMnRVV1VPjN+Kf2XgML*NTA!mAbA;5;3;Z+ zV%V21uC_FgL(j#P5FbxF)1y-!%?bBC8kwpb z2D`@In8NY;DI%ujvxVuF%Ju#m6`{x8Ltg4O$kI`5Z*OqqRjyc5%OLniJ^5NqdwU>y z@MXfQSG=y1@8Q0j22^Rn7XX)OXh3$|*HjUR-FHc@Muvvr(a}_76nT>SMb7CWEz zzN#vBWaXZfmAL$6IX11aD;fRhz>tvqw{Nw58LR#0+Q0?0AE*n%!M*G75@V ztdcAh71dpP`@&_`MFCOc1edW=CQ;_NWmeztx;pv5pr9D6l5U&9Sj9k&!om^`!^{=# zo>x#nHeKh(z!jeTsIXL@K}fe_X8{k#zk)r>$w}DW_8bDKqeYFc1n-ZTR{E|O41tQt z(?rdl$oc$=#wvkrOPoJ9g`G--9(fLdx+xN&CpVi;Rz-$D>Vl%iS1OUB%cCU>xD10A zb#?MbCnvF3C9qA2b9c%u!=vh7!XFXzxzN!k1Cc~ z7XfLd6s)uq1qB79(@M;ESWr15(9}-=H@E-(!Rf>W!!nNHIsWbUjbV`u4p7bJRG<5^YaVb?GefyU)z8>`nbD`_4f7sj4rw9^XqeKGEhqu&#O>j zWbFFwgVRK{2X2`a(_;r#N){lappXeke7)6t&YdivR5UXAAU+?F&^DB>_A|DWHRN#f zCqt5Or-5-LC3hfTChRb0nH5t~Vg%Gswz0|GUl1`ZcQq+xjw6qWiTV02Aug_}2{%F{ zoaTJQ4BIz0GBuS|z>ILPzb-0Lc{iT_px&R9*4WwE@7=#2mu?wMeSSQMc{RTF z?Afy$i>KCc?NM|Kb5T71+-S&VEhQWd&qJL7pZ7%UEZ`SDj$8iG#w{?CZ7nT#T_-A9 z%}cF9cgO`a+UDA$o~5TpJtUmijJ(!4`k8LUt8x7*C*;wSCl~kD#_34;)5hio1s!+% z(NQ3Y=r^Ae#050kuv`jBsj1|RmWe>EG~_$2WP!K$tFN+%TQZ(;9lHqWX5ZcV(Fp(R zCB9XOx>_0-HM%iX-EJ*0yF8S?eR!xA7ItTMcb62}=Y%cHSA#oYCsJTZ$qN9}cb1)t zJ=Hbg>6d5)%`bS?ws(N@K~%$z!lz_@=5o)I2>UO5eQ69bemNr-NBfzPAtD zYCPOtNQ9Yd?HA!5wjJ#(lrh(^JCP+1bdnG*sKT5m_qyI?dr6cD%^oQet9koNLwm5LxRD1iUIPrjpOO zYFcj5+8R!oMfgVC?Gq;*)agcbbWDuXfeYdBB}%~A$>k^fYS>qwK7E=TzjHJjUgNux zydP7Voz3}dh9YZw60>hxQi^nSeJgBPTFTx+j9cFZ)|M*bucwGb?$quk3?2~ z|G>!J`!^iTx>xAp&R#Tz9L^sv;aL9R@9;Qg>5xxZ9~Kg1f3)29XaverOg=6wwWYku z*-~NCu8QXsVg=h#4Udfc!yDJXeRQe$nRcHvLMqbi931}`5#!@)JIT};j*O3|)y|aC z@TGmvpk@5?>szz%m60M+9s;u`sH>}A`zt@mRZY@*cz6tf)DbUVzU;^Tg0Hq2j6JHT zkZ_%@Bc)X(Z*TC7Cj2L|l-+ar%MDdHJO---&X97tj^&i&lc$h-R9H%{cW0jwO4u_T z0(Dyp)wj(s>mX*N8-79xCb5Uho~=mx{OKDdeIHOK*TcAa!kRMy~Mn z3jYoBj;=0JX16YJj!#Ua!^xSjRZY@bSy}y61`^}~w|VK@-+~hrcd4#&$qUF+^h6Yv zDk-u?1#iECd}}utE8gDrH0FYha@pJ2ZA+K1cNmOSxKG!aC8p{1djI;&wzoW_;!Ep& zF|D*KC@3hmyj<6pwoXY$=gPNFZX)s&a@1PJ3&J8I^sKBm13eS!x zT%~Y!ahY3LiJ@T;i^k4>9mr9j)JXQ+_$EE1-yMT2b&LwZ?RS zK;Ybf!j`I%(&OcunJGA2V)=u5+mY8gdHG3kl}6JOlT{A%*RDOX?@Nop=H1dt7lT_{ z^A6-F2+3cjZZQCMbapDe8((O7d?_!#_*=Tw!x-*6!PY~0@Vxw_yQ0Py|8y0%M_y4u zB3VmIOI7juslC0Lth5x0#G?g>&#(AphybfrYUX5}pU9IZPqydd#OHT^_T??yG!F`r zL-%JsookQc2Lk^AkETZzwi?2xJes+x(EZAA_|s)btbvJ1jj3u>TLd);G`!ZsVZVR37^+kUk{~S|?Ce@@Zm#24DN|QGTlnq!pNbE9 z%3@v9WE@^!yTD z^QwV?fxNuDfZW{N=(xD>9y?_(ugcjiDknCr)Cf}X+F8I?It+3P0D*HcLN6ahMNyhp zyI;{r{!-`X5*QrZ*4Nh;9K85UEi>%%$Vk=Xct~KN^Xh{uDN%T45}qQ(Xp zrj|kEISK)v(h94qW%Kg$v%>lpd!Em2Y`78Ft*opXh$m}Lt}{sE4S;ih6@{qBmndzw zXIn`JE}-!wJ)H#+&+0Yuo0bR4$<583BtXs0&0TX&JoTChJG3F3?2GB@jdE(GM#z!q zMSlKJsj-N5mdq71Gqak|WAL{RPT^n6?&o{VG+}~?&F6$I(t{fs8txezKmGh!TRTUd zDOuo#pdbYv%jGk4`^E{AR;tBn_5GE|D;$|&O~u7j)jxtoeB~d+i4EfMl$g`08PCJM#QUEMgEj~aL^*E1XrGcxEE0yIUHB#)epnXEd0x9nj; zmI~Cz$Hz0f73O({03B>gl11IWYf@fe7YG$`yXF2)KsHTSPIcwJla^Nqu(rae2hAKu zzBc~OblT*b!FS6ZdQoHNN{;H`62qcW|37!w(WMC!Zk2fy-tOE;HIFUSludp1>~Tg0 zYxSh&{n#lH0#ll>8Npvfhm^53hTOkfGF-n-if`+Z>(vI7_GomQqm*|D5Flz?-B~s& zSJQZ1YpmZ>#P5pxyUn=5Rf^0{!>60|iT6tY-z}$Uw2a#y)~BM;=veIH*P6yU%Cu4n zFA-y?`@3(Q24m5$%Z!o*+zW-wUniBCMPAe{JHStdrc~P0>ZsefX4mZe5KKY`1`kNFISs_kfmZRWhtuj2dn0y z#zONZnwsq!W5>u+u!8?Ova0OS{ad%_t4)_|N_rQ&%2GH0CDhfXL6t^aEoCVmBBtIb zB1`=pPkIK*Qa;2^y&)h=Z|_Z&rNBCSxI9BXa%t_0dx`+-uv0F5H994k{b)M}2h@1^ z19f%vmb2sEB(nRAU#-nrf>%P~+MSRC)pW53Uz)-~0z*O;HtV+{qoOF?>o;V4SBA++ zqt@2Ev=o;RSk9P?4Azd$&KoywT&VZoP}bGG>g?hIpE2UgngsJyPy2HyDk^#&P6xD4 zO>t~YRWF5pzx%xKgm5^+4+N6?EDgXtJtczoSIIp*JR+i^PjU_OgeZ@Xk0E}mjG9_n`uh48swQb?Pjbrg@-7w@7Lu;-{{H>!`SWm+F$hFY!z}t} z$gyL2D4(90Ia0>$Tg%`e9jYt7^?R+)v*hF_Po7+CouSXO@`7e-F%)LzE-;q?fUmxhBy}S$X4r?8n1;fC5A!~5fOjz zrmikl>vvMfLTF8zu-3=QN_xTPJtrgw*#zM)zl2URsSetv!xU(Q@C_np|{;+wvk-`PY=%Ne<%7$5!K5h)yqven$* zsGjL6tNsx?S>>>>I`$@S;bw2Di0SsQmUu3Shc$)PE<*$WOACp&+@KNZ&i^Wg(3RHz zhZy30VL+|#mOV5g)!D}8MkFoUlkRTy>LU>vxv|kvUOv8yN=iy%n1ma(6ie+7^OjW9 zO9pZjScpWTx}ILZ%D!`dYdGc58&mPmIGB|$V>11c3U}VG_QJy8)zMo=$H%u;mF#aL zD{aZo2!x%5L|80V`RZ&aBW8DiZV}%C32dYno^33iw}XQvgv@yAyB*9WB-s- z(tf^Iw*&%#%U{c~mRa2se&5>3M5-@}PEJlz(b2JRwcqxFrs$O) zClwl5h3y-QKBya=lUNMZN)v6(mh(}?dx~V!?I)q2oMK~Prw2Ai+jCc+@{R}Z4XN#n znOenQ=a?Zps|(Aa5F-+k&yn|=zqBQ6XlhFN2X#v&{?66K4n(OG%G>uc63c2e%dDEY z4U2S{xKu_UJgYyuLnj`Tl9Q8DQBhT_X=<>Yot*^&=!E7%i*b#=Z30TL{}5gJm-v6G zYiX%?dR8p6W_BFkgM}=$mmBEl>8bhpe&{zv^#1OLsoFNL1XqMK;zf_oy(j2!k($iU1S65Z>U&scc4kqMzWYV2OLlx1V zGi>x^42nw(i);xe`*|qGi%TjYt~qpBTGEP&oRgE22X_2V|4Wd`Y&rhIeSfL_wLw`~ z89YnIZM`3H`PbasV-i{c872JAeemgXlultC=KP`J!2}9x$57hPkWEQJyrdF!wR7AG zb6Y;L)C>BdFYUOZ#E3=AqPX`kW3adPiRC+wy2>vrzF(U+ZVL-5A8t-h6L|;zOP;wW zJrLzT3FeVWUH#xRQsFTJReN8XJ?V+b5m{3(t_-1h8f=cc&0nxCJvC5GUqo*W^B3%wo`6vXHL zy8S8-G(L*wA<~!Dcp=ncY4f*@VaX4l!8R4M^yb#P06ymv>e$*KZ%FXF`8p@s;QL(=Gasf8BWSfQvh19Td+l zeVLq`9QnzW?b}C}sNYM2adox+3SRSM!H1iFyqlCh5xhj;#(4?@PdHC7s%z314 zQ57*IN6trZb!{zc+DR7&C9ML`GWNz46trvCfyd{UmR=5SsX&Sb&c_IC&qeX% z6&F(_3(T!gRskNJoCKdO@SNZKd0Jyt=SvNRLi13?>`URlFH9gym6VjQi`Vn&>e$o8 ztv(U!8yYxEN=lLhs7p#p`ZuLuggu6?L>`Yul*S*$1u%|_$dL8m7JE=G}YC$W~)iMTG=Xl$nu{@ov$`+}ZK(;_~vyN!PAt{A!*% z^YHW;T{SO5KTguxYg$pIKp-$lfLg@l?Oh$6E1%JlO~exy_2h`K(*x=H5$zXXa*w8C zK~ZKJZy%qsrArS9WAJ2w^_ga#mVMl+e9qOWPi~h0oC^N5$pSZEFsq4;k1Ra@_4KN9 z!1nPH?tIfUN!sP>tIEou;G&YZZ#!DUDYF_)wtl8tMG9y@g7gp=p^b6D}e^4LkvotWbgu@`*+%|X~KJfFC zCcVortK8DkQsxH-Pia`JWwPx1)|^8QH#>h1!o>gh2Jz_qv=h`-cnluLZ1bZb2y4gx zG>h`)*f5k`ow9{noxZ zy1FuQsfB<5jqU~ovB#6Td9 z^Wt?E2oQqdl9&K@CNaq!0sCTOUV#K+Nbc@eukPyCJa%VS>#+TYG}~Q|ufFfAufFfA zufF=p+g^0_FFb$tX_sC6K;_YMe|_qGi}(M|C;sV?FMjiu%dbL{&w2Bk-UOyz_o86W zAKiQZW54$iwTOK4vzHehdgPJE{@XKObK7!QbIVgMy6AOxU;Cj4-to&%AAa$RZ^w68 z6ZhTR`s;~{Tfg%4J7;fx$}^sUzSzF<_7`3Kj+=(Axb>D>?;N?~!f*awZO=EhAK!B3 z>%aY;W9>hB_7DH(t>0I{94!|T`_<3=pS#r|A7xIKJ~fJy>#kz?>@cffBgBI9}C`l?1GQqd+*Jk zd*1th>2JK(-E+@94?oL)?f357bL)LK|LI*fe&;JQ$6s*Amwt8nyPp}lj6M7&^JC#V z3(vdZlmF?}AAZ3<%uYY}_6uKm)ibty@=yQt&9~k5weLLirtdkzPxBuGxrp6;?1Epv z_Cx;g$jF=d8d$sUj+r;UV0z!Z!QvekKJ*s4$0;7)@}2K~ckgxA{i^r2D{g)NZ~ykp zmp|Cpe=i93y!Fa&@zwWI>Ac~q?~OnB)-Qkk>o-IT?C9|=@4fr(|NNf!Y_m^&81VJm z^x-`GggY)o!To%Zf9<2+{@wR}@sTs$ftm5~@xS`O;>pjK9==fN0CyjI=aZjz*;8K9 z`bO};Ltp&%?T23UE-@ET6FQ1$H%0E3yu6XRR#~yy*1DEbw-9i!Qj}f>(UdyZzwre(t&**ZtS0zxK7Sy=>`QcRW1&;FkMtrXRj>zPclB4l z`qf|m(xa!p^6?Aa_NsgCKlj)}Z+rOjzxl+Aiq~wNDtz{q@4fKCmw)etzjf?_uRQqK z+n%+{d)6mE`N_HC#~=FcqbL6`>GpZ>r|!7$N3Va^h48Ki9In+C3ZHz#=*MpP^S6yY z>Cf+c!b1-|^!A;L7rpMni*J4FTc7^<)1Ue2%Puay=dF)DK}cR z7uddi`@VZ${?7->C1oTm4EnzR){P zii?+T;;YuJt)q9{b=O~iu<_h?ANjRg&wl%(&-}?JJoy(LXX_Wf@P&O>4E@|!&)xEy z56pk`^Z)p@d!Kso#c!;=tNnzJee7f0j@Uap`}+%@_=(?o_q)IPsn!6tb6alv z>`g!Yq>I4h04?7p{2cx5(yQ_WcJ@a4MvgLy2fqgT_KJ(Gj zdrlpE+Fd`qcK`nUW49l=l{N-QnKYhA%)m2x`ojCEjcf8{{TfX$h!mCc4c->px@(WLY<}-(O z?|$a(x8MFR58ig<_gde)=8qryKkw}BG5Y*HmtB0{U7wx*=FG*{h#-_WR$M znVG;lgLv12FaEcS?|=4( z|Lp%g^1es5bPk$S`M>3LjuqT!V1HEHb2z{Y0J`M=E{&z)|8|b;8sCinTaPDkX;}p_ zR1=q<9Pq0I%9~J|1QlT5o{)icQ=m0ofI$%cS+aN9z`T7DJAlcCd$LcPXe*l*PA2Z;fz{72EYf!ljTt<;s zwF`CJK$+KZ_HbRP1f<|rINZ7k^-;9p;3Z#PjP2nXrs3^84M-O4z^@e+QF{p!hfWoW zYFLFLs3R{xq)-fRr7ILcwdu=y?}~b)g$8u>{XTJ zU#iRSR-0mXM5r=TqoYepOSU=Kg1lhOlhiA;;xswW)2X(A>6CrX?5 zKdj3$Gz1coaA*h|5b~Cw(@mEkhfCVo1EaJ10K?dmcf1D#R}iI$+68rM@CnW|S{fAv zLv6~7jsIlLf4yYU(d%JVUQ>;z&4QImgD&%b=kDbFPvc{y$<6y8*5x^Sc62*vxs546 z5fk@Bat&a*!O>Ewqbaa`ba}Z@;Kd5_h&721AfUL)fR7zCBiW-3qU+2-;p|!9`W3I~ zAYe(3vJE!k)u_!|u)wh6Rv54rQQHF6;f^1%^GBGGOhUnYZ}A*H|MXpt!tT z5a66WTU58cck6*y2?(kpLXfksNnF2nv{FY-({ugWftruQ*Za?)N>gaB1ptabRzkkM zcou*LWR?2_)9sPO_~AdHInoFuxkHnLNS{q2gi_?nGDi1H?E!+6P%dl!#=sN7ar`ubpvC# z^;xQ9PXkz~47oeFh02&A-PWl-_5UvRUj+uR?0T!S0K3?KyGr9@N&9bda?}66F3$?= zKUPP8K~h5u91O(*P_E+KxfbIjE>6_`K_v6tDzHyT*JI7YW$48wNAjcDhFP#fsiIL# z%tzyIy~NnFCY%SO+O}>*caYn%IVn{ygXy6s)s#~Q1_8kVaUtWs^~R0ZfRP(04dgSs zH&PiDqNZX*qo~nBWEM99ND#1ITCz)%#W5?rg66Y;JrXu3RzYB)GYt8{HXCh~%80>| z6~}6#JPZO}(i#||D1!`Dn;u2IV#=(so~TkoKOabP{Ter+dqj{for4_B_NrKiPeu!2 zsUC{xHTe86Y<9;lUUkPlVoR7Tx_-@GyiBNPJ@GuOTmOaaj9LH0ZXtA7zUL(sx0P|UV<_x!}S@#PP2j> z(Da$>g#{+;3407IxvZYhdU!JmLp#7y-L2Gh%mW3`2heeZbqGCRon2nG00;w7?1Bmk z;b6Jc>>E-50YNo%=4x)E1J|bvK?mR}H+=ajk_Q7=UIt}UflZ2J%dTG&T*Sw{h-4It zF6;W>r4#l9pQlZaaR>kemg_S_s@#m`7^&i>?^pm4f{9(&zWo>mWdsOn;1+VgQXNVD ztw07nT-!!L!}Z-p)6b&D_U%2YAI%`Zgi!<57%v-`vCa;+t{p4B__~qp*S>1`y6wx$ zTP-jgLk~Cy7(U7f$AofJ@OA|IbmF%2ZO?2z{XJdmf5E}4+56qn-Tt2_O(yn#OS>n= zH}n6k%hQ|vFP4yFb%L9T+Zbjl|d6{2cm&E_3@$QDh8zC!Wspl}fekkxI5 zZ4K4fm<23~Dg?3c$6?q&7O<)=@*Gh`7A=mAS<&*Hg0Qq!5SIFYuoOa=0!2+;NhB0D zPt%Z?!wUVV85BvQU?lGG=laIHjvLY)f&daIH(!e&*&8SVwagTOu4#iq8~|K3N^=#! z^=p(XC1Ne*`pgc#u(={yNwS{Hz!LViF~I5sFX;uC_p6`;MKBxwiu#*_1o=!C%2yn_ zp)~T%CQ(H>v)q7PU+iL}v0!?hq3>kWPr2?7(Bl%0nEz?3fKlOeY8qIl{JEK@+M(*M1bp8F=16O7<%*)m;x2L%OK)iZXNs zL%bwWNo_^NilrIy9H>Iq8|;3>=Ci&}7yZv|z}l)}|F(43|0XAQ?oR4|9@|_$WnV#vIPy1 z-pWr8VLGQq?yi&Z+pQ)VGd)UGU|m8-FQHQ+svuS@i5D^KeBYF4NjKA>VlQ4j#a#Pv zWf2i@Krlo&=A%Lz1|n(!3_B3Omi)h?lt4(u94#S=^$ zD#p2dTiTKTZG0r+>i8aIFDxE|%1|?MKj?X8fY{93 z0ll+DP1kRFjZ!?PdI_ZoMWp3ckn)78uj()LZ4MI_eN%rW{gZQsH_~V`bVS->bp^Nz zpbyX)mx={emDFQ5Yx91>+M@@2W&`nxix@DB3GkbZG9n|qNxs0VYBo5)z>@2Epo{<` z(5HOTIe=l{xK(lbh=De2c)&qi3UeqzcPCW-P=E;s)Abpup_Hq0A4i<&=R8(N;b*YWb^d-mQcne=bAXgBK}o# zypFtvP3w|jJ5&+hRh@KyVuQ)AD7k8$gvl=7fIh4tr&w;sYaCTNL8k1JXN34_-lPa% zUxi-VG(Z)bs^drIaU!wpM_ZM6iEg-!okvmYCr zFw*oZVAq8B={Alwt5x?5u!?DoNdh@b5I1FH(l7xghgnBdLMp>p%k2nsxrTKcfLc(} zn;ykWs1+ZG{H+a@Y#FhpFn>3MB%x(PjT!76}3AO>p}P9oX5 zD9?Bw9C8|lw^H0drd2LbB(!h}xZ>-%4ObbVtnN}UtWdS@@KIh?Si%9SjM#+(RUHc= z8wmq=4cxntfh+JXLUcLs3fj&%=LO@8V;lw1A46VA9t24h=n3zpg1*&PJAys)s{v<- z4%te4=?r0wz3m&oBp1e7ll}I?Y?~n*KYmY_^^P66R{oUt zFR7Wtz1E?Ul7XOD)6>bdTWJaDdVOk(MRnXN$@h_BB6dDnxbL0v(<#O z&Xil!1T?~c9)7m=o0L0?sNIv;5g9^OA$4Sikwqlpn5<3FvOc0^5w)|A1ROSOPF_e$ z3{kcF1Q*l{xs*3BH7#?z#U^gXyoqP=NzI&ijd)l?x<%gO)i4Njpr8?X!C{#OuJ52T zooa0jfzA(}=sMkW6WwQ9c!&cNKoBD?Y9Y>B;+%p<5Omt0BJ5MAr&$>tnUG#pV|zDt z;H4<#Yho4xOPyG7PQ-KmB+t;4GS1bETO+{okY8hU3zWtL4Kb&o*rfrM;8)d6?03fv zWHtFy91Dsumfa>Pxh*{34VLPNAQ|zcaqLn+8RqQXX)YvM&X^1`gQbZmP!wlsUMd^g z6K^dkmUN`Qjw{O$OFICvYg1eeqo=(P!=!hIXw(x^4svB06Gs>67fUPJU7FIkurz#zkVmT>0n#}d6T|?|3 zYF|!pgLAT(b(C7bPO!T%X(JUauUk>4W5=Qd@A{yjR0z?OIfjnCE0MvqOAq74W&o@f z7gt(0+1epTo1$&lm|G3oGgm6Ph^Q~N0~s{Zna1fq-Mw&1+2g%t<1n*>oU%s9{5eqG zHHrL+nS<`Ekw3|ZXHEoZA|IAL)qo(<=WX>T8fx!++ z<|oL1l#y^O!yaBj1PpVzKH~*-2udR(^3TJ~1|n_+lt#dCGYHb9&Z!fd*T)j|nY=B^ z(~9e+Bwt4Kp3w3XCZZCt zDM#zgYSlxTlP^0-T58}NQHPt26nGt)%nlohDW`$SvU#EM;&7^1&>;v2YPq;cja6LD zNUfm?b(;2~pURTmw9@mY5)N2J(4#G`*W$F9KxAV*-TeOy6IerQ8vk7??MlagZ~Fh& z=js3ar+G%{sALZ?>p_}%-bnLLg%^kp8HLC5D=6C+XB6o5FleHy$kb6E1dPJzV>E8Z zK4zTUOnP(Fp`cVXGYfOP$LY?MI=V=O1Wnh{F{|jba0ADRj3nGjdSx}s$e`y_)+x(8 zXJxMT-Res9A{(;Y(QJzNjrVks|IyK|RjdGANvE9l1&tnsloAQ4>p1$P2?;t_} zR8B#0?k5a$(M)4^(6KWP3WE4a!HlIqItzL|P@3){A;DAr`&Q(*h$J5iJpIKyRGO7N z+N?6H>To;jm9XKBWY^w6=L);bf9U{Q+xXAPvE=+O?Jn({*qs0C@$@nOI}{C>L@%E=IZCh~D$hhFSD? z4Da__Cm_++FrYI5CJdZC8#S=JJiT>zu~|kH<_Y9zcR(?`k)!8(IMgXDWkG`?1~*Xb zbKy8`ofV#1o0pJ>sFs(PEpQH$Aw|0;L9ytd3U<&)h6819)AbyH{1#|IA_Fz$CNq?g zpk3*gz=b59CP<@Q47Y>2QzX%p;iME_L?A@qxxyns`45p9j%&SY*hUTE!kdK@U7o5c zJb|eb^2t8Tr6RYr=umuKiD4j}i8dI?JJcTe6?0q3*_~z40$e4yp_fca!LF3+xRnuZ zn99HUnpvraBaadvjoR2TC}>;J?z@_SY7@pXDvM=^9Vy?yKWt4n|HER6nqg0=U3;UQ zVmi&47057Vf?6(Gl7SgMbBWp%#Z|EF61q+K5P|Checz1SiqB1h79|2~A}|ex^-fC! zOq@fE57W9@ma8mumbN(kqTM)IMYISy_)X=$ti~Z9LDtSJz(kc)-byir#HPOoeC!uh z>0Veaf7>pxd%uXmXX`ud8rQ%#>7EKa) zWm|}L=C;sCY)8*vheW`LowHGw=UrEm4r~nlbMraBPZ#}v2@>D+YpXK>y83^|QvTmv z6Px#cuglYi{(n;P0)S=QWGdk^!Ja2F!@^o8wLfGdRsI;Pbx8j=k1^{c=QCR~eWuWN zz;Ni9uyoL&1&oA#BPyp*GJD@SxkG!o>pQ?Il2fOgOShh*bvV9r*OVpG4V|2sKYZZu z6;oh78a;3jLluS`Fw9kQBXQvJ@)Uo=%PcRC>;OvH@Wb4DKbrRa9@a-_@J4Mw?k@r$GN)`;? z#pdGi@8sz$|BWz{(d#RaQs_Gb_PZE#^Z)GLxijJa9iJH6%>TMBPapDMMd%B(j{eGuOtr(n)Tk$YXa>@#E+!nUHrOZay(u}~+%>XSWY%WBx_{VhAJF!u`E z3@&UmJ>~|f>o9b?8Ig--C}85aRk!QfXPReR&xNE7s!d<2Ny=p{t}<|Ib*6o3m?RGL zbd+6PXF_;CcD^(^4^p8k*fGzU9f4?Gu$qX#joOq`CwYWMyR#F42A!JhxuHQ3Ud`NS zDE-l13$JXV_f8DmP7hQteSrBC(F5y%`nvCHYVod5uSk0Lg>zHVYXu=x z1yoM84L|$LL3E*ca+YP0GybKw*vdZi{{|#3bjtm^g1YGcyLTqz|HezZH}C&mpJyfd z|J9rk_U#?G_OBUi!|48cpt+jAIQ_OdtzY-CHadR>O8e6Ib$!(wY_j@_mHtFq*(yII zmAcE2xa+eQfQ;hFmYS@dZ#pE};gXnF$T1t{F=jcY12H~Xv0gLU;qqCB85nIe)$6YH zyPGea>(8UWb1Q;H@`jTxk#6<;m_$h;P^T%ly!$aIp+lw>lspXU^nvUq<;J zm@ulf258EHsWZlYTnzbM7Px`g@&jD!dx3ie#=LGeqrH_F@;x>)U^8A1q7S;S(1g!x zWt9fJZgzv4@1{8IXO6{mwly@~*KoSUhOnA>X0Ay6Ost%G19r^t`P&C&BQ5%IN!1Aa zE)+GTWERED_Z$3(Yd`)U?AP$%{XeC#iPZjYY4_&&&-Hm$Hxq{ND?avjY>JP*f6mKiX71Y^*6K^8Nfz#EUlo(XLJ87f2 zg7!fM%aA7PJL>g%xsr||9owIFBFS%ETbgOI`u>PljCMl4$ZsLFUuDxV#P35=m33h3Xn~&Td%sr;Jj`^vnmh7VC(_zm3RYGvyX4Dn;JwP zbYH30EvJ>$dfimB8{F&Gvu`F(L0(JW%s`Ep+!1th&luBb1@4(Ob%l1aHy$TWvra=; zjqqE0SLpe6wrs$s5C30)DXS4gPkVj30K54AN;`M&N}m7NIk}ntXI-9^`2Xf4BOHDC zp@IAV3?ADsF2D$;d>3F;W_4abqp!8`0%jw)FGrx!#43-0WVDp&2@H+fu)JvtcW;$z z4*D&PJak?9FoGsJ_?WVL%M7Ek&tvdZHtO=-2d1XPQDAKYi8_yLBRMx#rr$fL;yNfyEv;^lLO^8$Rd9A% z)Y8n>q{!AOOk?SG7E!y1t3~~-)54W|D~?DSq%QW+&^jWai|Z?>^%|9s(z&Zf=Mls; z{Ddx^lQcE6l+lmDo|03<6*ygMsq8zZVAo+LZSv_HMZ-y&8n9&ht489(>0lP-_R(*{19poUL+q1dR^}Y*(9kOVVu$*@16?Imd#O${0`DnpG)X($8h> z)GCzS;~Gd3Q(0Y^D2c1Pk7F**9M9mSn~CT?C0(-BE=>(s-kH4xD;Ig0#_QvlU2@0N zg=KPBB1lYglOH;j+mH_FKK#F;=t>g7bvggLYkYDd8UH!CdH#2Op2A8T!1J6FhL2r6 z`1nuBV;jcxE5OP3`ijr1bNI?0*2dSHLS}DXSy`<&hiqh*#cs(umP~@0@4{wW|0HcNoVXw@F%By$pkt(Kt#k!+I&)~+ahT_A zU)4R7$?L1LL($SpCS);&(R?3jI6e-)?pkSnai^UT@0Q@G4k3DG$$am2T+HTn+;?1_ z+56+)b=}PoC533G^*CGb_ve1fZex|UnQU}JI-TUICKJVLQ%sJ&XG{y9j9MJm(8?N^ zrjft2=aX61F=^Hr^|N(US&Xju6!;eKix#(0jZrFfHZ7#(oCL#4F93U{L1}WNXG&zM z7OUX@%=XOl3q}Dg)Zy{p`mq1aRj)5EK)3wAyC%kx@n5?pcW>JN>+!6_{8#ocFC#4dGD;i!Qh68U#jKyj zesye2+$)^a2gB<=#49V$*bieJl>Ss48&f)TPH&~b_Erje>qQ^TQv>CNCz-g(8bbQ= zlLQ$+U}yq*l-XX6V|8_*4Z~VZ5m5Uz)s*WS>Wkfm4KJ4GEVA};94e8{k?T;&?$@}u zd$jiiYwG@|ZvD$*YHSJ^2Qrx5MSfUB4@!Tuj>)@X?9e?Hv!?pJ%Rj}#c1Y-4qeg!rWqka;M$iM-|B3rs5 zi%8a1yYp9VGU8cFa(a(T?%M32ryw3&^q!w5fTF$ zkX7ogU)uo)@*s0tYT1n5L*FS30Uy<55cRP1Tc}`F@WK%r9Pzz2z`m%-K>`6Hz;k_M z7wmmUuRqEcxxx^b6%CxLDY3vqn(Z{_4UII01=^n-m<_x1Sd5fZ!WYg%xbqL2y)- zBlw1b-J%ujpwY*X%OY$3&+nhvclCa|;S8vc&hvlg_{3!L{^!Zb@y+|+*5w%jd*!`g zdNv$#%Y=z(-4p9_k7@!3`<;kLX1LG@uV_h}ea~-WWM!9SDhk?ZIXl!62Yf zYm4fQActfb2L&E(H@I@hl~vii_!C!w;LKUszUzaE*Q5*)YRhFxe3fXZLkh~A#~7mA z#t=I>0dL}34JL<%_=q72=AujW=9@lq8z>H9K(J%Gcyt5|?>#s-KVpM@0!qOD3hzX3 zGTaab&9OsAK?M=!R^19@i0+b5b6U<kX`8fynp9$n`iwFFm$+}l4oGW&Ix_uv1wR44YU_s4z7-Guyv4d=it84+B1M;F~ z00Dmi_$P(awlsg;ENqvK^69YGie^{uPu4u_KGjw`h5CK6Ixq=cF>q{i`L34oh4@ev-ML(3kZ=)i$Y8zUJS;<`)0euB{E|k%#Xh*8YLIO${1Ox}f6<*x1 zRAN=N`=xjvP*MgNsy01};$Zd)rCERNpmcq47$%O$B*i;Gsq6QL$bO+DWmrjp*awvJ zduL_=K@>Mh1@!}LUr<(vlLchYP|nWpTLB{b=1b+j;0luos)mxvs03H~s)fcXbgNc0 zZzt@DO9us|5cK;A!K5z{zvj|?P*305T5qlPvCgdd5;Lf0Z2&bV0up>?H-j314vK=q z<$ej5%?B7*ay<_qpEgAZd}f4y&21rHItrJNcq5w>W{tGEY;d3o7NQ**$>Ixo*^@gT zuIi1|30?xw2LeE08Hx9l+i7ANN{9gz#)chfRLKsKd+hpyvBMs|Dvf}+0;Xo;fd;H~ zSGd;8dRg()ZH}y$(X-;mr|Vb2SiEXZ%I=?@s21mk1?}C z1x<&CusV``0ZX55-MX*?P=vs>2XwXThKEEMf-xHj<3A}QO_7ew1{nhgnw}?P!|6ii z0QTX^A|jFp!91$Dl#w=2Vf}|;15q&Spn#wXWXPG~3lxZVL6GktG8c6OT%R%oosq=Q z!^x66`qGa4Z{s5oZsJ)Q7P1DOf@AfL|#>5S$pEtWH9X6`_! zoQAwl5ox&n)d(*;&H|JyKRucYCY4h4H9xZ#gHab35 zdhzJk?$Od^qcCubMr~Sj{bH$D+BIqj$F|Slnb3V$K~ztvL$Hjz^;~q5h z;BY5qdYC>1T>!`m*`w-g_NcDJCags7ie+vG+eH-UM7LE5!Z_t5={iwvRdS&l?c^p6 z|92q*j%yqonZ6O>6rQZ$tMh_hU3iHjEkuaxpoOl~i|+{W^0Nd<`Jg>Z{9_xOZbFaa z+u^pg03&Tg_tu#JTXCc;D+U#K&B({q6U}m&MXmjvr}-*Z&d1@3+2_+)bggn}d>pQ< zeLg1R%OJA&qz+f&D)fbk^@Q4UK5^7(ga-N|2aMd> zUdTXS7!ivJAczqcwUCIDa;pG(1VN__Dq>}DY*YV>1yL7O0;V{IfTbb?oD=a4I*nxA zcgae>8@EP)J})C0gEz%{aTcbfy;l@P3(8X#5;hjzXQm+!g`lwXBsLDSvs6> z7^j@YeS)HNA?C!@hX=VfjanjnD~y=dsMY9`^=;4|1Fol0#%-%?p=lJzaBj^-U#}Y;GRo#SxCA#H3uLyoLFsiHSc4mo z>a~HDER!c$;Dy;_d86XQ=7x)UwEfdAH$C=yR;jp$_Z3AQU9`?i5 zkmUx}w8?uJCrsoDzqjdn4nTg(CD?DsgCoQhk!wO(mzz^ist^6>av{rRoi*!c!A}n( zaaM)TqdDUGOt|KW3^$}<@SxUDI@PP=zUixQxoQtdQ0F8pdMm;I90uA4M#47za_C58{wZ%?L9JsxG0-7y^e_ z1gt`J_{>p5#YB}=wxLj*g-Y%LANxgJ+8jn&!Cpk|Qhabitq5Wy`Tm70`spJ1Nio0y28dc)AfR=~6<8VNB5sZo!7t$f@_y(yn5+^Dy`gGD zKHcb-NG(9s&W1Q1VzN_StdpRSzB@0T*mUJ&O>1Wg&SEs{I^_Rah~|zurBA~NB;9Ai zRw^SI#mM0i?l_mJjbjS1uQCg?aZ@6oNfA&`D62_tYDqM$kv!@`zpTru7W$^2ab4L! zNSLOdasAHuC83c?dtIp5g?@Fw5M?)5;w3ZxYJ4uLTm_DjE6-O7L@XqtW@oadQ_Asp*P$8PJNx>|LW>z};T_eBKN zUb2>ppt^|tJTHP0iuGLtg;{?R65sV}-EI0F?Dtif*jqQ6y`->W6YP1e zUpoeCTmw+Z0;mpA>_j--G%<6b_+v8;Ans{8%i5!qV+0G)x2z(Z5O5w&a= z7YfE{_AXt`hb09gNAb{R%j(qos9$saGlc?!wQkMIb{MRg&6MoYF1u88P}zlku{2gB zyCw>Spy_#Y*mEmgVHL=(wgHsQ&xIAkw6wxGx^2c=f^E7DxYY;_jJI^f{J^9{VF<{fD~MDYgCSt- zJw`K2Yj;lN+$%?f zbYd-q={h>Gvt}Jh^r09zBwmMrf!G8BhJe6;0D4I5S{U7iJR6TLir7{p`sgxBGbf%7 zO42cA=3pCb)%qf8Uk!u6^@Z4owWZ#N=~QH!N()#-ZMij;6|2fWx_%xI5`MXn(-GM+ zvq=c*5HNuq0wB~Xc_Ezz{~&6IsN}d51LlA=xuiO&&X_z(7n8EaYctGSCvuNCz?8b;XlPq@D^!R&atTdhgW3^whayQn zs&FOV7mLO0Y%mHdD^CRjR2;Zmp?#@@VA{Lg{%u1Vxq z!uwU1mkY5$JAoIC*tTtz^bh&1sqm&@ot|fI=IGIrN9OkxA|HxZ`_rtT?GDei`- z#=mqxml?qsrftlN9?ZQaWvj~LXg-Um-Lc0-BTrg3IW zHV3L)B2_V|@RbwOaPL6f;w;X^a+xL0zak_>8T1fgG)6X+n@R{{ZfPURK%=d4u!_W$ z2~tg4){X==r!7nH{I*2V9y4PmJJ_nH`t`htM7GTQjGu*Y-k~!ACJY$OOm7`tY?e`l zd7`q;pete-XaFlHJPZ+W11Mr}1I0cEZ`wL*bD3uwe7J0J0S77CH3^DE2UW0xMhaPo zD6I$)B@+>)!62fv28bwSBSNPYJFbs(s~|rNO7@sNRw!J1#0Q6Q3pL7!fYQVcFg`Xu zwnJq}7}p6R!4jlE7$n?Ss=B^Q>&S`DlGR*RZNI;wUX6MA`l$hwMUO z`}UI}mQDe_ga`tz%I$_!KISA6UbcOEp-=>KI>uSOrV<@G51JgWIE)lmPZq$i5+DK% z6`md) zQl*OmxT50nF3|7}kHwiu2DJy$7S@{gc7a&2_HP%tNTZ~6n5d{nFQ~&ZVs1rDD537w zaRb+ok2vL*U_0h^)v4`_GeSZv&UoCZfG}DfM+Vixi*I3i2UwahPC9 z5=uE>%-Rk{ly|QMmY$8!Z*w|EU__&krzYcb%^aGXGaPK%3GO&D)Otct6%j3_uEo`= zD;$ubn1d@#ZsiE7b)Gw|@#|X?*EignB=P7___Nrgs91p%(GfLE)F;0tiKoZFFlbG1 zW;sq#wdn!R^%tq+1>H06F_u4*H5n!@^ynx-6niaH yGKz~M$g%_~@-c}1immY?!|Lb6<0&EU=Ck>1KAX=vJ^w!d0RR7x0A2n7*aiSA(gEB6 -- GitLab From d5fc8814b1d8d4125cb13cc5d6268852ff64e888 Mon Sep 17 00:00:00 2001 From: Micah Nagel Date: Fri, 11 Jun 2021 13:25:10 -0600 Subject: [PATCH 6/8] password stuff --- chart/charts/postgresql-1.0.1.tgz | Bin 8688 -> 8688 bytes chart/charts/redis-14.1.0-bb.0.tgz | Bin 82989 -> 82989 bytes chart/templates/enterprise_ui_deployment.yaml | 2 +- chart/templates/enterprise_ui_secret.yaml | 2 +- chart/values.yaml | 3 ++- 5 files changed, 4 insertions(+), 3 deletions(-) diff --git a/chart/charts/postgresql-1.0.1.tgz b/chart/charts/postgresql-1.0.1.tgz index d7fd11298b60bf3b2bee82f9138db02acbdeb4b1..2dc53941f3f33ee7e388f24dbd66e99debdfecc6 100644 GIT binary patch delta 8581 zcmV;0A$s2ML-0e8w101R@A)@_-RFCQ=ik8KiScNCaxM`2X7Jf<)jRhu@}P|Tf*B_? z9l~PQLs?e*{607cc3*lC<{=}QQ14DBf5)Nl8IF;Bfntb|Koi6VdLz-kUL1~Bs zZ%z|Dgt-tIANKp#*VjQgYXiz=eUF3^xfLZ691+wf$*hkiG#CAhVb1$F#@QUDBFNI2 zcZHYNltp~#`B2t&et3S-Sc(Gew{|9@| zzOMf-@oa1q^A|{hX4q5zFK6}8umNvl1I{xXlIaqVE;`ENctm3oF6GC~qxc#v`6iI5 z{(OOEKsap1NMJ5DcL2v61IGdch0Qn9_f(7+<~S9bvVT6qQ@wc|Z%xECMKamcXXm8N-n+aXOuoC)=ZKqSSC z7f5gox4=On#5HK2ratmB8r9G;Ee|1CGCU((u;mqADlA_yj06T$vQ^n{`Q;c-Q67tO zV7zkVet+he4J(BhN+X)U?f@jGL7~75xL_omIn_ppbII~Ff!?H&wKqP(f*?S!pmCmH zNNAo4ASo9ZML?&3(*c!UaiZpy}j- z3uXW1Cz@h~lz=4X0_JETsbZ1yGmG67UV<4FS$|E;F+`XXh9j_LybZvnMNRo3Z0eRb z+i6~*q=Zh?_*P;Hp5aPq6r{2%OzR(4&Y!GfbUEAemKYB70;9A#OvMy)Fhn5 zbka`{7nl`$f|`&x6+seh*msw@{Y%7V%{E%LMm@uG#&9b7Tp&ThKFTs*g9+v$iJdOL zQGaib*o+U0@kA-0SYVb)GV*YaqddmUbi2m|Wmmo6KI=>%e#QGJN=Qm%Km9PyRewX8 zPRT51*iZ6UkSxZ2(GKtHN{BJk8^Hc`vjJ_Ha$vRZLOD`x({$>wj-psD!3Iol0(CxRmqZwQO&M8KKd+#%>7D z2bD?1@>GxngQf&zh@k`v%s3z}r!EP_4&+>}fe zrwNjPhj8nA8vqc~5XFFE{hwet7wY|-a#6fih18o`fn-^Vu1hXgHtc@?EZ9AG84Q9! z|JfcS(Z1@zND5wDDE=TP3W7|(QA|%UMz44i;-LqCQ^^RUp==a;01Ru<(CkP68)_r8 zul-EDho5kq07_FT^mL^ujDC3)z<(>0!URJ~VxSCqR~TnK&jZ-lfFmh*=O~VsMgos4 zz7o4%G~1Tq^{W_>MAtdPA9Eu4nS*suM_F>;DMWZmQXK6_JTxnwU^6~Z+42NWDZ_S? zxF&Hdi%n>rMiNrNe-#cxgLy%IMb{?M=Yldc!xC}Mn+S3JS$$PY9{$UH^?#S5hLJdW zey^=kueSr&a}v%WB3x2{L$pj$LPE$GT@Wd9%Wcy_%Tt2^Z0XHLP2FudE~cS0kK-Lk zX`?ZavH}p(7m($5Ae>Xm%dJa6D_h1a0N9#k&*W4%`t^LLI3fW}Eu7bXJ=u{T;ZJay z;q+Xf@M>FqRK$1D7)mmD0DmY9G3W1Sgokj3QS>V#0-vU#9C%Ltfrs$&HIaYklMxd0 zA@oX~;71b)LWu(UV}F5IKPHpDbDEHY+RtY4A2r_2wB|#&x%0dP3r0d-SuR>o05C%6 zHKRG^DUJ)sm-tggnZV2zx#X zXZr{5hD_7zL@T6KZr>}YR8|oC$EquSuU_&EF&d*RTfos zNi`Q#xtu(X*@Ec(QY;${41#E0AF9Y~>j#ImJs46=^(|9RmQ?4~-jPznS|L?c*NFJ+=wtv{wXlk&KJO7SbR>79wG9l%+ z6o-m`!<11erz}BtUW3`HBP-{uFe0u(W4j;{ieq|xVn)@79C9kkvC;j~lT^?cYtfx+ z!I4IQI43i8;(X}YU9ATNt*?Pdaom?vpuZvi&vA@HLD^Hnl_yideUwJN(;0t)1@fmD ziJW0imVZ1qZL7V}DXHc=noi|$Y^gWS4LDt3#z<5O3^7^YR1W%|fMFC7^>@bT1anXS zBPX;irPro}NKkx?W3(K?!9cx~LOsnzaSYj4Z>NaFIl~uohWVVv(GU*QQa3HN!P{>I z_guZrsz;rDN$;alJWwO8#i1;wOQl+;Lzt@tZ-V7w~Cn+px&cJAGhThE$*h%FcAcAQg$Fgb<0=T;i zZf+nr!!br22U3dSnOvQBcL867fdLk%bG+x>-1tDI5d5Nz6;;I^+}(L^rVi!35i zM30wx?a*9sDNo9k_1BlYWZ?i{CZ@5naOl|sR5=Fj0n1Di$(w#UJ-?{&C4VKu-IG;1 z{ATkeAOa`+!{GOT3nX$LpeSN;qf+n8kGsun+xF=6tll#VYTn;(d}HXLEIaI?c1h_Srt2TpVZq&9uf8u8^CZCn zsZB}(y6c&lVR4mx@TZhrBNp8c-*0V?;obxvK5S^5wfm*yzgGGGa*pE+GaiWSDO^F; z$p6m=&z{%i{}%@@zRLe!;<>r$e+LVa43!E>ilvh8943-1;T#X)yMO-OohM6qC!aE< zl9^*I_Z#)2a%BoUQ_eRAnwFL9mj%><2(-hYTF1o(j1pWZH*P_&JPqOCx%!hN=lOI> zK0(hffyw3K>m9%UomZOjO&iLH3mLA6N&^f*2Y~mAeGKQ9GJi%hM${B5{4AAr%Ltm< z?7L?1RAtfvPGz_`P8OKGqDdy_X74YDyTP76*n$7r4PN+z9t5vYhLo=*!90-D+CT|j z6JZgP@Os8Clcv1C*qva3c6**HyVP3xe-CcJ^oOLg;OeDPuq|v8okTV3+F3A?6B&m{ zxmeVqF)L7)Qh!qSYRamDz0PUk&SL$y?Z<7QLhSu#4|}i~V*ZKdy*xRege+SRM z>VLn?Q}h47B55=wo|G;OqMT5|6w7 z?fk2Va(_poH>Lm&enMQSY@}$|gS$I0f0xRwyE|wKknUX645qZm{#$Su*?*-9wrjT4 zgss83ZgQT(Q{Waz8sSvHo-453-FfnuIc&CJZOny_vlUURc4N>`gJAv=vWnsOab%0d;ll$ItdwI0)~>)lh7aeZG}8g=VDrp?MV zfwENf_5k#p4YppRci-Nva`1QhyZRo0gUCGrHt;HME!mmoKa|z#$9Uzs#LRNKD%=83(G?E0CGk+c*3I1AZPsw95V>Un)C9QBw&xRcsT>0OTE^?U7avwOiPJ?% zAUmj|)ANhhXD8>EKcAnRIrUXHh7U2-wttKXK;c&z*{d9cYZnWm)n0RqVlg+~XF(Ia z*M9_Fjm{tcu)2vA2ITvIfAjv$#qkf9M`y3kAKFfNg=%F>uaA!|j+(I7`Pz5P#oCp; zm3^~L370>VUUtP`mwn1Rmx3q0*G|a~09Dlgwt0Q0cNL>M>TC@tL=@GjEP`z+f_%u$m|4MW& zkp3(}mrzzwI_s2&8ep<^fv9rrr@6F>kLB9h9k{jiwYGOOPumt&h3i(XMY*Ut7ww7? z)qWONtvafi?{1}s^LWeU%8Nt|tot>wLz4G2jhDs6z_RTc=edvgQy?<)=YJD@t*HYI zEd)IXkq!->am*^wut>NUwxC_UwJ@xlJM8*)fo6{pgDWsri^HwLo)i);&rg3odv&6G zQ<~d#$@qu;{)7DV{%_%KG?Y8T|KU7NXoL^VMaiylU!gdy;y!wPdGbG_)3b|{v&)nJ zxj1=$eEHu$pPc>ea&&a@Q-7D-(V}}@H77fE!}`cKw!-gsU%q&B2iqA&*?P4P6<)n! zAwFa&c5dEtA+pz4RJV{!x7UV`zJ^u*(!FUt75o+a+LFJMZ#U?n$D?ujbvSpObv5rr zS0+_)S6N?GHrJY+$s}LAx58;FRQE3I``GpyQ;lbP$E(uNFH@)>83&V zDaNHhSE+UVZ`sIKZR1~N*xPj^PG=k6*LAZVpQkL?h}_fIPwE=6Rxtkr_s+FXtNpL) zo%Gozz%};&-MxeQ{eQ0)&-V7e+W)@9Q#S;(U6Ls6c9lC1Ue$KkVQ%U4UQ;W*Y5lwB z6_wtJ|KgUEcG)Oo`*v zQR(?j8tA8m5|(K`;NHv-div%}3%|GB&lpXxnB$xS4;jkv%75OgbHM*b#{EQ3EC0_H z;ZufzT*vq)lgzBYA?4is(LCk57S+R*La(_5u{9~{H~*JS+c6tS`&-O zgstk*M-4C?W}_g}o&`^x{n#M2_wHE##BItlB~{}wD<`=gy^=wpr@ci{@V zsfW$gKD%{|%MdE;tX}CBCI@>s4ePGF4vT34d2^%U{eK?C*&MykRn*^ZKn)i2&z^x_ zpMU1l&i}ux{QshP|9AKK?pOZ*C7uq}u2|o{1#iEP&A1`JmpX)i(7sk9RCEv30$P>O z`+oQ3i(Z>7t@jt#<+Kq4qEJrU2j4a;XI3?93dCkujB3`mipr$Jb4UYfLDohxsDrQ6 zx1zTS&3}SFw)eP}|qp*#!vAtcG#fo^2Z5Y~*P`@El_YpSbov@R-iW`Tr zodikr)I4T2|9|%4V1K{H|DV0s`x^h@i#!`n z5FyX|Q2zLR%SJ=2MuXo5!c``QYs{v3yaP1Dseg$B3bZ>tkj@Ddz#9Q`#37*!gP5Zf zcK2b45#vCofI>kQ7$UsDG0lp=k4Oc?#wj2c&WXUG$aQTE3nP}|2#5d#Trir>fZ;4R zG1RA&$@N0?m8Rv64mVCxfoDwpMoJg1B9OehsxFqBF1wGw)L4xnu}BqmKIpfW^- z22>AUxou-PK^Z&k!%sL)%65%5Y8x^XUZI&y<-{~4Mhr9jF(;e|%stO{gJSFkd;h6# z$NYc=f}_!!A`F)2!{`?`kU8)?Q(J^_6MxUs2(x%8aU$uIAud?12X^Z;jhApe$Eo$S zkcH&1Z5tA+L9o41ck@-SD?2)66o4WmZ6yN7I9dAU#dz2`#yThvlx4d{{X#`a(lOEW z_*6o3naGI_+3biIN?3(oC6a8QVg`Sxy!(A?qw;$jxHjOZh`uJJMVT2wEf5pcv46;* z5kZtQO?1^w-I(Y71-|?4f@I%)H-xvu8Jt*63_Vt{s^H9zpb|P8 z*+uL|$x?H`A$Tz&^0h;K6CTHn(SKI7EasT7V%$yQEzi4!k*yDn=N6935a7+vEzhk@ ztZ}c>^~&BY`0bB|-SM%r$^&aut4nOg%ClnJ-qW#Nlw%Vym*I?ZA}CvS(8j6p7}|`j z*JrbO3pN7HRsw|a_rXE%?BS?XuqpjV$1dzQIvQmj$6)e|tN{pPoy%)1g@0nFqlCj) zXY(4HY+hqGzrwhQjq!mQw_{`U%xkepN&G0v7;Id()^QECd}pIsrTAJ0S{2m9e+}BO z`OJA!SNgfMDHMS=0=7k|iHNDulIUv|zKu6^c-2w3Pv9bP=4IsA? z3zg%DP9dB9R=6m3160_+R%d3c?G>16Y?|i$v4yR&x2e=lf?8QypMQ@!u@NkP+yZaG z#`PT--@-^979y2T&VFilBdE~kvqq}JB0GlLBK=gTOtf?g6BJ%4lzw^DK^uk5R?d}N zn$3~52OAir8gY9qHl@*gT#S@SuZ6fu*`y9hl$Gh5>ey8BIz5O=O>9a9=veJjEg8m2 z-+@-z+}u5Kpjt+X{C}geGuUJ}YT_Cqtpo_;m#@i_%^Q6$t5{R#`9#N7mZGOQ1Q?_Q zH3>A4s9;mct@U{$RooxZ!WgJaD9R=JeiXWe@tPaP58*deUlqBkJ~!*#0~Wo)rf@Q8 zU}O0M_pO*x&VH@T--Fej7!=WXXG~{ z71dlPzJgBu$$u@3Km7h#`;==8tDiM5UX64@mHPsO@&4ZP$0-G>*ob9@>)2eqEE1zB z1EgXyO3$ZkjV68X*qY+Tw=gcE)jt@e3O3dZS2^8P^0(m_J0&ox*OT4K5yINwc!KNgvGZ0bQl z#x2;GGJhb7$RQ=Cp2a22;hN@g z1Tne7McPH0mWflNd!u-(t%NECnQH`0P-elo34hDDO=B(@@drzz!hnAdM}Po+q)dBJ zkaS8}VzR7iLp8%wZN^a6{>Q*KXPbzIO22Kb#5S2fM&Z2dr{h{M_I-K8zrxEyCCPo* zDgOL@49KXK?0Nti*<~dB3e$Fx5sasnPwLaP^p?B&Q z2Y*?yFfOP(Wvi_Idc3VoS}SKcAlK-t3`!E|NZG%0WrI@2=t2=buHrNfoKsZ11R@;B z1#Trs`)V9`-jUJ%lLd~KJAmMCNAKQhgN^bA;A;GcF?wsmbGcT_d274|GOdw~;CgOt zK90FxXMTC?!1+^a_+Fx<)1$_5OZXej6@Oki#}&7U4-S~$x11l^TVzz~qx7KF*28^0 zZ}fuTf-*xrXONX%P5Ti!o&y|^ww|q5saXY`aVXG{XaeK%pxg$OVo$pc)s?U9jz5j$ z-DT7g-vmVIZ)*$*hnR+r+lf&T5?-Xu)GIt%rYIqy{a$$YkaQNn8{_cMsIc9bm18TFrQk7k^VbR(F zD(hYo`AtpbJd2RPW1XmHX47{dWsfvw*kVav&q+9!^dqyBGTl?#v?MVy`F?b+AvtSw zXC`=#7KG*uuv)5`0ThQ}xo>1Rjeo39k!Bonns1aAx7GpRp0^u-$)nOXOlv;t>zliQ zb-pUct$W2Qrrb4_hofI!>1=9kjMYpqv&4BtbB=&_tJod0wDXoxs`ebTpd@lWY;u^B zD8eaNc#<`$jEE!^m`$;Al~U|_Oq9uY8~~Ucvxs5Hvl)|u;7l(gy;c=~34fl--PtCo z84rTJU@+cM8t`@lg4`5)y|MN|GHNx41JJD45+obsMqh08YlV(jvhxq6^4M|Ybe+<- z^-3>lr%^^pDqu@#sJ`EQ`9gVm$_1+wLpV|ljtG_N@>7OGolV!UI15M8B&2byKO0IG zsU@$<)RJcPa)pxmizFmQ41W+e+?|JvOtgrk#2B;3z^HzKA8Jl=EnL0qy8GuOrjvex zBs%?yq|-NTxut!FyDpP>+i>TC>`G_DONWHI{!{0uE!CrP-}sngIpYF2$GG&M+vG5I zwz07qQDqd>1TY&7mz$rVjK+ai<+WBytkBYLNbJ&?pWs2!}CZ*f$6myVQnW!Tyrw{shlRy1nB`(yImB zp*@sKSn1vZ&y#YI6qbNukv8RAM>J3y*QS zgfd%YX*LT$Z;gr%sm%q;gF%R0%3q>5zSKE7&9W*$nT*mlKc)ff6eusIr&t6NEKpD- za+Q3CH^22v{E^>!L-~VK?QQy7Z}?l!>CSJxyStv}{VKU^m3{<8N?pOwbV|Y^NuHB^ z@9&a~MV@j)cQrpVhC{i1YkYRv2CkxLJ=8i}$rud@J(bEA>9`?9LSIQXyZ=X3Wo$J` zZ#mBc?Fp_6*-k`+XE9oqERNT#`h0z!^7;P(00960 LNNb*+0GYe)+c~C}v!Hg4{ z4q>tDp)4zYejgkJyDz;6^N^8DsCTE6zvEE&497^mKruu}pb6p_5|pADPH-xKFS)=8 zY@MDR|M2d78?K3%14;oW*&K1gfu?{z37m2=Au$n4Kxrgja({u+2(gI!Ax*NFpftpR zH>U|6!d!@q5BvS=>+7JLwE<zjjtJ_LWY$L$nu~tMFz0<7<7|#n5oGDi zyTZ$B$|64Wd?;%>KRmzatmlLLmLiFmQ<&47g;;^G$jpeC=aV3$N&hOJV3uNmc|VkE zjkgzzXn2L0AAgexLu}bEnqSy~*$oE4uJ<(K@2vj?igV2W00yvn{qOD`yx6U;|AW0} zU)TSacs4eQ`3odLGwiAVm$Q0k*nqdO0p}SG$#e-w7aiqsJfblPm-6H0QGAV-d=to2 zf4)F7ARIPhBrq47JAh-3fnx!J!seUldn!f@bDWAzS%075sb0dvzOzySLgj+s{hVXw z&vFvszJkvC8yUlXmd7zkXTE;tZEScOb>xN>+>4LrIAmDxO4Gc(?U1G+&V>3yAd+In z3naLPTi_rO;u^G1Qy=*mjcRC_mWPlm8J-a?*zyW56_&3UMgjvW*{bZf{Bn$^D33)s zFkU%wKYw$~hLu7Lr4dbFcL0*ppip22TriT(oN6P)xny~oKyOmX+8ZBXK@cEV&^S*p zBs5P2kdzCIBA`>i>4GqtDz?8sjG#%3y_{oP{YMhxAxu%sv1;XKj^X4J;ewlIkE|4H$A7z=Z!31-W#7>vr zsDHOdY{rMhc%l?gEHFzY8F@IzQ66Jvy4~Y~va4QjpLHe>zv6uqB_t)XpMDtUs=pyk zr(~8h>?e6FNETziXovUp@+w}um%Fk;?liMPO3swL0wk4_j;0Ye0~g87 zgUY00c`8VPK~n-U#883-W*iWgQTPvdn5ha=${?Fv&L=34l`D%aqL5Odxd5(~f`4rG z(*#MtL%8+54FHH~h+;so{!g%+3-x|ZxhP(%Lh4PeK(Z`F*Cm%L8+N~c7VI9p3yTZa}>u*BY{U2 zUy0o>nr%z*`c;fbqU)UDk2#V2%)vUSqb#}a6e2t&DUNm|9-0+Tuo<7IYi&*V}>XISJ|<*C5{w)AGBrtY>J7t>Ih$MFuN zw9yzySpkUY3&`?25Y8#(<<_O3l`Ufy0Bp^&XL2eW{d&Gr9Fc&g7S8Lxp6tkv@FzIU zaC$CKc(tuQD&o6n3?&&n0DlyQnDciu!b3R2DEgHVflt#=4m>CSz(aWXn#jNN$q0%0 z5PBs~@S}+Yp+o`wvA;m9ACpPnIZenx?PoLjj~Z`hTJs^?+<9Jt1tTG^EEg>(02m?k zn$aBd6vqYROZ+LLOkidUU7*<9aJvmq$;az z!^zw86BxkB`(ufL{0cvwoxba+4iQ|>F;lEUVJ&wFlET)ez)2<#7=z6nD1Pk9AC|bA z+dYR4Nu6Hu@f8WG@8pwnH4A%hkA66L+iQHTXhwQ!h102C$A1RzUac9~&&$bDVBX!> z>!Y7vpR8-_ToSC-m?VgT-P2;Nm6?i3UrcwkAH*afwd2p)lUGQSEEm`>mXVUZDvPSR zq?!w=TuvUxY(eyXDV7-?!YeKAy%~7`azPAXfA9G-$sax`@iKlh;zRiGyJmdv?CvA^ z?t2>H5oPia5`Ww6tJvmDLxFC^7FAp+H9v-)mtr9WID2SRAWjrxGRG3RAy47GTdZU# zfn~TgUZ&w(%rTf635{^9#E2}5mjV1b$En>qRFxf|X}pxODc71aImjVp42MEP3u7Yp z$rw#=tan>=J~ACJ%w37JO2%aZMtU)v|My#YB#+fbTYv0oG&NYroqxwIt6)oTnUL~Z zibKV}ValkKQ5MJQ)uYb7r1w!N9;lJl;!qaTrP3|P$)JWP@PEp;M>UZmqfz~pK3)`H)S_ZIi&2Py z3x))qEgyNtlLs0`V|4^Aaq4fBV2c*)xEayG$O~<{6SZtJR4!j7(SY3iJp4&8bdoOA zlz1ZjpChr^-IMpnl{$hfA$WZ4{G|~{oSwjpD*(`%s$kIOuc(xt@u-$ zhkx9J<@rNS$0?PZTb@^r-)qTHZw8Y0lN6RTXJE88L+|DW?4)uJ5WzH$V_CHa0o>gM zH#ZQR;TR*111UxEOs>wmyMQmkzyJ%>Io|VbZhRn92!7GVimGA{?(V!dQ;CGx5UBtZ zOE$GE&a4%Eo>Da#HKaP0f?WEch^-33Xn!bYIK_;FATjM~8GJu2knide_`W2UlH(79 zenX!rNv71~cX!?eg&7u_q)I(eC_P!8YHVTjdUSMt{_E-4@!_{y7I#_8Abu~L?l(-} zQ}{clX@tqmp$oiS9YzW232ERP$;+1#us}>4zQ+s9 zSW1*E6%}W%kg_=O-j9~M&t3!rW&L-1>8=mCS2tm)ZCuU>&}xN~PdLm4Zs)Q}^kme2 zFVB5OOQw}oFgiWHe1G)rq<=zk>xyhDrq`#Zt+44iib1aE^!YU4Q@X&Xc9QlTVpa z$;`2q`;GchxiSTwDd!slP0LF5%K~aa1lr+Ht>ao`!JnT>VLs^L#ob zpP=WLz~plA^^V{F&MQs%rVVApg^xLk$&}y-P?jm=1MgR?p{w#jwjn#hVS+=Ha}1m& z82(x)0?bi|;5g!d7=PC4Q+b{+d-2v}smNiDMasP)!{K%yPb7waX&?pnSCrH5h$yUP zxjcI*qpn2WV7rRC<*sCj;vA6d$AYM~OlN_6QC)6i_Q$uX2gAer53GY{K@1J0%H0cG zD{mi+V8%!)rqKHj?*E4r94pXtyAPRaU4QE-c!ovJ^!Wv48GoZ0BWj8jewIqRWdu!a z_Fc1hsxoN-r!w3eCkxD8(Ik^|v-g+7-C)lj?7)BR1~2?U4}w=HL(12ZU>?Y6ZJ-3N ziLi)Ccs=8nNmJfm>`t&iyFJg9U1}};zXvy9`a{xLaP?9t*cP^lPNJH1?JO9{iHt*} zTr6tQm=&l?DSxSZHDy)7UgtD%XR-d<_T#otA@=^W2ffSQBUsgIoMKjX%AD6_-&W$R z%e{A&d$H`cNE*g@)G4xVuh5#f`2DlDq_58xd|Kr{ZPG|k_B77G>-_&;?CsU$zk}yr z^}k={srmn3ku(|_)A2i$dG-t?kAB+Q{eEX-4~!L0pMM!qmUY*x)B?>9yGt9UT@*K> z)v$4Hvjygu5ur@$Zi#b!{E~%i|7wzx@e~Lueij<2eq}v0)FROc)4!o4UIXD4KIT*y z^eU>g8UlsGoBrx}!wp?UbXlwm@~ZJ~UH_#u>q!{E8vp;j{eu_v^}qjo@OAxviN{_4 zcK%gFxqqY48&iM>KOwGEHc~X~!QCC0zf0xT-5oRqNOvx322)yO|1CI-?7vb4+cn#2 z!q(tiH#yJYDR2uUjc_Vp&lTA2?mT(S95&mqwr35tuteVvCV=&YFn&Bpg!8u!y&p#L zwL~n@Q(gngPv;D4Bb*0C8`i0)oHFu>D|kH=vwt z-#UFbO;|S&uesS2rK`=Akex;wO}P#zWub~&N=uWKT90Yg_3kOkxV|qfjkjIVp@WaZ_ z&6^tq6>fp2=n9A0l6WXz>t^omHfy+4h}<#(Y64tm+w%#!R1N`sE#vjwiw`TC#Ob0W zkR8;~>G{R$vy=17pU+RuocgL8!-tq^TYts`pzy1V>{SlJwTlJOYOgs)v6vh0v!IFI z>pudoM(2-zSlz@51M+>qzj^=W;`oQlqqEoN4{fKsLbbA`*T+W}M@`u4eC<2tV(m)a z%D!2rgv%e_ygg~bK+ek+*OkgVH9jnB+o*&8kDO!>PsK^y!N8P_v8x+ z%H<%wudZf&+aR#(TiUiY8fIg04u9P8)se4zq^SX(e zNPiZgODL--ops7X4KP`|KvcQ*(_C7`$8v4$4&2)MTH8CCr)>+X!gVXxqFhv+i*`kc zYCnssRvp#Mcem2RdA#Lv?VjVA*z!^V~=LDG-_Y^M8rH*3^N9 z7J?pxNQVZ`IA)b-SR~vFThK1wS{PQ&9d>=YK(oh)!4(**#o<{A8p@sF|8O2BG{T4GqGZ>&uTY#;aUZ?DJo%r|>Dk4}+2zUq zT%5c=zWnc>PtN{!IXb%dseeoEXwki{nv)&7VSVHqTjBS+FJC;mgY68XY`xlt3a?(V z5FfG>J2&sS5ZP-is#{2=+iSx|U&E?@>E5)S3jPXyZOPxsw;S}(~I{7yEx@N zXZo7?99lDyOPWV19srbAUtRD~68tKL;7-5pa_ba1o%`zQUDaMIC=n?SB#%0@bkm^w z6ys8$tJJ#ww`}CAw(&1B?Cm-dr?ZXk>$+Kw&r=p`MDA(qCv}ZjE0}+Rd*|Ax)&5uY zPWo&U;2Qh??%qND{(sktXM6i!?SEh5sT%^?E=iPjyULvhuWCE&Ft>Diuc?*ZwEo@m zic0Ta$^K`JJefS4eo3<$NoB<%*uYU7(`z893e4hO==L-(s|d?}^$LE$F7J6?ro?gT zsPz0M4fNAO3ClDeaBpS^J$-Ygh2PumXN)FT%yG_vhYV$SWq5!47447D!1f1&oSG|e^hT3qqZ}WS93S}cX0lwc?QTj zy*ZAPfY1B2_+PzF(~(2*YACT5wU=8MRXr7&hv}}uYrIX|2vVj~e%DdAELqiRt%=2C z!d7+bL&-lX0Do6d!Ht0B6y3rfm4o)WD%;jar5QWSs~*BzigaOLMXBf2)R?tD|1iJo zR{n3|mp;`Vu#W!^2KD&g`!8PXedYgO;%O1;nzsX5orLx0e+w3_{n1V{^fAYdyKsfw z)Wha#pWV8~We62^R2+hILn7hsCsjytz^Fet(bRY>wXND(Y`HpazTiXV1W| z&p-2N=l@?;{(sTD|GWEq_bdPZ5>E$fSFG>fg16ttX50|qOC3T$XkV)lD!PYi0j)~t zeZTwiMXybk*87X=a@vRiQ79+wgKwLaGpm|41!6NSMm6hOMP<_AIivx#AZsHT)WKKk zThUvEW`DsS+k0F_7%}l#wv=6~QP{@V*xoM8Vnsa1HVo}YsNayO`v{xzPS{CZ#f?MR za+qqXcW)Q_hpdv7)BZv0-{JpfCr8KcPJ$$QY96zi|37+)fD1ZFEWuqZhqrqC@%GQhXMgs*@pwEzeC~Y#nJSNFV&Ik9mbCX@;;7|JC1S_!>A2hg?~5|gG9P#K~^ z1FDCw+_tftpp2dN;U^p?WxGZjwG9~xuh7h6mDG zd@7;2Oyop|Y<5HpC9J})5=k~tF@rx;-u=F{QTe?MTpMsyL|>EAqRb4T7Kn-JSbt>D zh#<jh90X}RdD7>_rfWT`pe5WE->`P!kr36JB(Xn!kO7IREkG43Yumgn8V$kvC(a|_312=M0Tmgm+c z*0@*cdS&kx{Pst~?)cbQ<$*P-)g?A#$6$C1sj28D*?jz``{pW_Ha}x*p&XGV;A-t9gQ-NV=#F})&PXD&gC_hLVvN-QNm%Y zvw4k8Hm|XpUt!$D#`wUD+p#fv=C#$nD6zO&J+QhcogtqN-5zXomC zeCE8VEB##B6pBC_0o$U~M8wo+N%Xabo>gpWzHQZcqcei(UB$@;HYG8x$=8uh^0gM=XV2owHPmqxw#_}! zo{8&^z@};>7*}Ao<#>|=cch{%7gOm8v8i75tYUL!GH01*uqxX+f-^NL9MK<&wodq*a((CZh^O8 z;}7!Ax;yU z%DJk6&Dw+2ZObv~ao99xvx7~?9ByLsRI|8pE6DJhqpqxYT>w8{E^ZoK#wBfxGxD2} zifXPCUqPq-K}|!1siLItDNpC`P+1$S;rzsxPu8i$-HU3>R@1- zv~SfE532xvHZNY`NiVm}W14OXwXg}p)%&(DLs ze!XegZ$%i6f+@eXx$0DD8*&076+*(L&G=yOd1r=|@jS+@*qAZ}bsTK=AB#*oHuaz& z;}&d88GjH(J$Pt(CJJkZbf+1|^Afr0n0hvOy_hbfE|zS8*B#&M7Kh0uc`6 z0=E*ReKig|@5pHX$pXjA9YFB6qjzt$!A5xla5a9!7`?UOxm>H|yft0}nbycga6Pv+ zAIIFUGrv4`;QXmId@oVb=~3gjCH#%%3V*Mh*2nh zH+n&EL7AbRGssG>ru~Q<&jAidThG?3)U1NeI27neG=Xt>P;LWCv8P>!>dM!4$Dc;> z?lNkLZvvw9w>5@@Lrg=*?Zl`E2`|!S>J=U>Q?r_2cv4njvbrsVug($@JtFmm9ARjV3qo@SSS?k}0E)w~+&40uMt|0)NHY#O%{NMmTk8OD&)W^an8+IY+>|RqT#g+Ih<;ReKIvP!c&GHaW~m z6yX#sJjohWMnsYd%%)hmN-1_dCd%YH4ggG!S;R2p*^Eg+aHf}$UaJbg1bc#b7Oq})-TiYC(@8%; z5}kfU(&?MF+|s_oU6)C`ZMbtmcBQl7r9(np|EY7-mg-TtZ+y(LoN)o1V_bUBZE_ep z+t^r*s4|Lb0+@}4%gxVFM&rP%@>(k;R%q!rBzEb{Pw}-4ljJW5@_%)FA2L(njkXmw zO7M)ZKqNK}v(?Zb-UT&|pf=T&)sV~D<<7a|S$6ROL75o}vN)fqaYq7(?6h{WsCxQ& zRsEb~m}Qq+_CkU974NH@&vNZC-%Q1Rgu@sy>>C7(U1~$GV1G$-e}ZQu-QMve>D2=6 z&>qSqtaNXI=SjK9aeqr(><0VrC;898j$$84uG}m+1(h+3rZs)zq)=*kDzTjAg~vEu zLYb|yG@AvWw?@T>)aHWa!63vgX2=q5Q$A_BQ>kH~g*VbmzC;-CfV~ewAFdN`8VOrLJITIwfI|B+tpd z_jgIgB2T%YyPBUF!=c>1H9k9S16NVB9%>z~WQ>M{o=WA5bli|4p|2#H-T$MiGPate zx18sJ_5|03Y$qbZvluN)7DscD<;pii?s3WkV4BBvM-9GS)%^N=eZD?V`TYL?00960 L`6rnF0G|TO2u(I110-dm6K9|Yiz#zd34K^l*&t8z?Y_;-D#tgB0^F~ijd-xp$OC7;S^@9yMVL! zPj~R^_xt_l`}^X*{eIv5?_j^*|I=W<|GfX=>Hc8<>7V+8y}cKI`+oxcyCBB>%_)P~ zpZaU#ay$2p{9uw01{o#^9c}>-LWU+JTMWSwWN-v2+JY(m6=f8YWC*VJwqTm(e?IT- zb@#R+l%ga;Nr(|0ZUrELGc*JtnaxPD1we*ULNOCSr;Md^*z1Ly-)MJ)SpsLc87Qr=) z=Lk?nGSmep3}6b#n4tt@XpFK9MSu|iDS#k?3xoI2w?(3 zk}!x9UJoY|x(lX|P7&P&F{X^}0*V*~Fo^&q8AFlyySp`iC45x$08B8O&PQg))tK~H zhEQ(?DMMNQNi5PW9P(~z2`7|G4*bzndnLtt+&+ zAz375OTrF#_ry4D1!5G$)XyLmT}7Fwie?bUL*0Lr(f>Ax*aB+ee^e7$)JIWs!5j#iX}YFwcH>(Cr7K zQMbSKrPtq={+auKOv0n5BvXp{5HLL8$0wfem39tF2r^sWTJ+Vwwp{&a7zB>z3zfBLZg@8kCf{D>z%!ep|wH6@hE0{}4`p_mTA zr(5x-DbMP%31sL7E+nY{q$FcQFnG4V|5Oowe|dPu$xBcu8iI%|h4E<}4GZcyTyowr!0CaxnY;Da*!uL#^Ogsa(^#~lH7%@aanxSh<<`hr{ z85+-HAv%uGm}Ce*#?UNfIGF&LfO$H}V1%|Ffj4jgMkpr%5H9u35I7fuDK=*?Pb0{G z5vW<2r<7#~&cG-`@QOnWr!biyy7dU0AOD|sC+EjUU`#R~GoJ>EkwTj+nE!Wm!R?ttiJmS*@GG8E)PSq3JG%K)kC))u91_&s*N| zLa33PjZ>}x!8l$Nt3nE5T`|#r-SIq*`M)@16NCv`*YSYopW1+SL73oWqt{~31?oRs zd5)wG9mjl~#$>_wrP2SQkns&*%WNeE-vxM3?ApNmcU#a0&aQ93kLO&KJ|bL~HD^hE z0FnHnJ8#t=>RMbig0TS>ePkIt67+xrzVZMW%R)^YCt4B=ZZMmw^G@u4gdC3nUJnF%ER!uBBUO z9l_H^e=4e=R_BP&>Q-tvCr5uK;0xSk65C(=0zR2InFO*-_oU#OA&`_w9B;*K zqS%C~?wmSY`4V@}qplhU#YnR`Wn4I$!DKFAgc;)6D!_@@0K{gS!Vq;mQ|IXtgY=5_ za$zS(NfhMQZ#~|B2idK_Jr8>lKI#ey^wA@b+GpsaN8%VQ&f8zmLVi{UuNb6qv&zHw zkzNtTT2N3#Ng@4u_c^(Z+d6_HMJ~(X7A*7phFLhp49P3rf&{a;3l8F#+@MIxl5_|@ zPzI9-#w0->0Lj3I45cv+1@I4i)tk-vg3rHl%mtQ%Ih&$?gsE>%7gt-!h;bz$U{e&x z3+q5jH33P2G0rFpvbm5)xHP7wUk?VC&y-NFr!W`fphc{nPg?~j0pkl6Cn#=!CiE6n zm2VJ4gV%*s@N;-&$+NucK#;*CA~P`P2V6CRAwTnBoK9gfpP>wg>KdPKO9^3o`^mQm zEgOPP$1`RIAGv0nOyrZX2p@lfe@syVFndBd8B#^gRYXUUE;xtpp?H!IsgBASvS{;7 zxK-gy0sRFnfc`hQLJK~CLepd!M%O3;J8W!~sd-MZo*I z1%NE#C14>BJ8&fLQo#AqkHBcXE6^AP0LB@D(L%3pene4tjX3w4g0Gw<*?}2MD>+}* zcmq?({0lPAKscw2%$$F1o@=1R(nv^zsFaW$Ov9?fL%x<(A0At>g3U*=tZO$qtRYNc zk@S^M?}`~$Ol6_*5~8lWxaJ9yh=SjQ%<;R@F5LY?*WyZsnqQK5NX)^B%a)P8oMR|n zSeI-W;s;AI0SJauv2i8<%~G~d+oMljaeGWrIL|O!Jd%LdyGmJ(>3j-jq^$I11tFtd6mb#~u*VBS8|?E+3e z6%IqlmUrquy?v{TfRrkSpfiG*-3Q&eMK2EDfK#>YdiH-@#gk%5>n`%H`De`Nk3-4f z8}DvqR#6gAi5OMBDN208OtFc}1$ag>#s@(yN3P-W=_4r;@@73U3(62YfBNFDdJ|Rp zm%iai3_DuY> z4m^fuh|HM=cq#u}2jUpwc%GrlX@=;O#1Z&O766u)tN@kH!w^wgK)sL!jZn9MT{yJg z)|A=>fM?c*;F>z9A}oU^r;L+!82v8V%iIUcnew*cSB zrAtF>!KX{ZY{{uh!)?i{9=PJB)GWO#ZXIlbTcx1)+S)e{rSNBOrs5g2cqikkz7{7* zlK0#LPCZ^#U_Q6kgF@}Bl4Wq)01M=$WtJgnttTF)5mj%cF`i-Oo_LMdw_Hh?iwj0& z0oZ@@vzYqYl~{x(nine6f~|NDed?k*uj_&5{gL3sA1E>qwZ$MfIX7wKOr=3<%LFM7 z55eBE=Wnno3)A@!4Ep_G$ACRk8BgNh}Qc=5&Fn_k0@g5 zI@10Uj7b(i-rTG5h$Si-DC(TuJ}M7!N+N&yq@q`i(8u)WjLcJTftVNalk#{0)h5@f zN>Hn|C)H5Q&A^?TLS+4#Cn$%w^fZ~Wahu7i#FWjG1Nx4Nf$~gR9UhRkEeZTBr!WU# zPNGdX4W}rY$0!rp&_T>lmOzF;UhY?VI2$iB(=eLh1oNhWdZ9KZe>RU9PGc10NY#J- zxdnhlpI4WXrb8DjgA7d;UA9O)JDXvz1gNSCcvS^a+>`nNW<)&4y%VMF`W%uZL@A@a z8!jjl1e>8YMbVwGJ-Pa^9XC%|jd1kp!qm3hnk5Nv;#M4D8) zHZ#86Yzi}UmJu!ypX#S;aKTFf1QaKe7=cuNFW$Dn2(cT45@EAL#>ysCZ_EIDbhKsn zzsi%2lNKn7f}Ema`}1|EuqO4+-FVD3i-j;nU|fmedR4Z&T|&i}VWBrkL*)MuJKh2@I! zpckERs26A3=4R13G6jpZqwoqXB!OZF)(_M($iitW@=WAcXt5M-*&%-uy((FS0&v_F z4{GAyYN+&|00aQ-p#c7SP%hdtyP(Io;-yMYqV7obVFM&{%}}x|r&_O?Wgcx|glalV}4u@rm>0yM#i9=~z5I4#5#QCG0|}Yq|VVLRo*o3Nap|a1qAn6(Lt` zuBf)@j(G2!Gcx0Pj%^pATvA8|;8^K@87poj=}KRR~fITaB%UHrc##N#F>D;;lN0Ow_8}6sVQkRo$o< zkJK7)>4ADd=9z!8CQY9k}a-HX<-vlKM&Q@&@>B$QOgrLeX&Ya6_^<>OA>f54J;MKICVHy_jKPwdDPNZgqdg0=2da#k4?BA-ftiN`|Wj zb(K$n$|R@c^8^lKh-cIkvC3C~wbZ1LO~osL_y=b%*}Gf}neio$A^@3}JnOx{kdWS$ z?1>^g9wXt}=6D5I~n~A6M(V3>7&PNf>gsid98ocTXmv@D&4PWt0;e{mdh=2O&_-MT&m9?6i#{y+Q}G1Xp9pS?OKju^1|$IX3^h`HtHU*6Lfsd zI-Ol`GsWRl8?;dnEfP4xAxJZFjVUGxP9_Gtd7`KQ+s4z|4nJKLs$?F=yC5MYbmC}I z%ET@Rr-TT0FkkR;q~e~t7+l8@u3>ngcm;hU){B3(L@bZ8tR;;7t(i1h>!+#!oFf?h zBf|{6O~Mw7Ntk(gCKmtOx_IS(55Zr4#x43}-ohD1ZSsv2I`?vXOwWEjw7TW-Ew1l_ z)*1|SaqcuH^hOUZeNxEdTFd-}HYnPuJIA6_*!~W|Y!SdTwMNL+8k%-gZFS2xL%whU zEG&Pz&VD^qysjNxw0}$P@S-He5t%2Ey$L9XWm>b3TN|z1flYFT6;IFFaojnOgfD^k zQo-=*Yt@b(S zdGg%itFqoB-fyAU8&s>Q6&sNvL|^{??P-6%-|q)c_g*}I@prS6n)rrEK_A82S$vss z{X8sr_&GzVs{z z#+VB?^07a_sm;=!j^zwhKPaK*y6S;Ya6rzP;y-!AhEeC;`cd_&4$Er-BcLl5xHf;p zYT{zHG|FawY&w_d)P zO;L`3w8lF{Rk2^=Rbf~C_fW{(r}NneWn3cnAjtjA3uB|A=@9IB!MAsR$?ymJPYYG!x@jx-jYuiKTz*x{RfX;xTgoA!UEG3agQPIGrO zui#LVZ*X_+QM2-vc;`Mf<_s?BRFmI4f0KSA^rkUdeoc>> zwI&cWxYX3p*xIM2ioj;4ni}j&det=0aHnoHF77J78e0PR!k#siJMM>F`(veVP4(oh z>s(_(ZsA?C-ng#mU!#9%ZRcQfCoHhCi%l+hEbn7ucI3g!#{b~Z;AW#L-jAP+^%A*R zM;ntB+Pd0!$l1KFP5JU-DQ}y6b*$lT;~Sgr+TlhI+L|6W-f?^IxvBNJIlE_{n_Ng( z!Rf|+Ufht|jgO#}{cim44u%A^dCwak{cE}2wC%&n&Np6)AH08WHs*cf8{d0&zwu7- zdj2=wUfrz&j<*+Ip$CrtO?YW1mRxl4d$E)NFXzYNLU$Zl%4D~7WpM#F`mz|7luKUw zd`WK>x0_AwETsYcP90j@aq)Syl*VF7pB5KKrBh1@(bw(PQrE8vzm|p`K6tj2JX_pB zUe&e59r?D-E%|?4(_MMDlpl!N`L{R+*PD9^`+NTeK*H%Y0kCX+uq#*+bhtQo)mbWs z+wuknet)71on5QipD0hDW$~3R&DA&FO%GfP8)p&K&6780Z_h6ePA`W>_FnCI!?{a& zO-ajcoA(7%NHFr)Dc(8@T*bkcO1XMOlr|?b8*{)pmEwPzBfsWxvqF2bCgyEr_CcMc zwLFLQX)^;okSc$scZ@4jX*xvM8T6{4c+zW@;N*EWYarPvHyseIa&OiE_om@=aG3cx z8$gv)bNXQE9Gx}5>eF@Vs~4TJ(@ff_cmNYsUZm^vGlZ0?^9-3mghm)9!Jr>xd%2}d zO~Oo3VUvF;Gnd?cYm;Ucg1vF)Wg^u0R!E>JM`o22noDfJD<;t_se`GTjJh$ErZsfB zsUdjy5@+UZtmK(qHkbSE1!DS0rYbYIX70QK*GNZoN=vl1~%t;Nk>Z0e3u<5_r7ya%6$A* zb*1#JntIrq@};Z*zlJkq1;n+yDJx*E?M_(%_dEBe%zM4MLuDI=y(^E(Dg^7eR93-U z&!@5q>iSNVRgk}Xugc=6x_`Gy2lp57tIU_(J^ED|thSnCrFoI(bFB0rSi!Th3QK?a zVpUy}>Sxvbo;4ruZ^rAcEVs3HyYq}!gWFv*wkp57R=Dog@6I^s8w?p~iP*ceWGpVL zH*d=5ssOb%j6Om(Z^T&Ugmy-Z9tcaD5frMs-;SUJc{w|R5_rduz_cH*)ty$>1SRmg z;H&}7g?VY4+i4VS3-zoPoqqo3n{$7JX_XN}docMrvmrU;ex*hb`74_k4E=}s9#uOE zO*RrGR{TzFBuWG0Gm*lj-nEZN@`UNQ;6QGl$`6pwL`aeZnGZ_; zn4&~Kb_z_pfF$uk`dNtphSD)Q%TUN{c*Xs{B1jw0DzAjXp1`#0rb3oO;+2OaT}c2J ztapuC0yKw~GLvL5&II2t)b4*Ffp3?{j1Xm-895a@-TX4#9IRZRube$DCY~gdjQ8pw zij**lRY^8iK^!@5YdT#|2@{avv*L3sNo}7IQOdhrsuo=sMzn_aiFD$!jA^Z}vPMQ? zG~|F2hO`~Y60nay@`IX+UBr(-IIeOmzRv)V6lGA@@17+78ilv1=Ocf|U=go{dOgUl z(&3rd;|q*4c5`mO<$MZNAl^L3)u?`xw z1(g4z6OzQCdwIVdyHmM9_h4O#$;|OLrIk<*676SGgoPZ>^-4Q~pcoz{CaFi+EMVQx@7pZ)Bbrchg z)CB9A<_NU#J8 z+scP5F$xBxoHI($%j3f9{Dfm9Fdh~Sz*rTUz;s1Fm|xJs3+WfM@Io`{`vD#v6z~oj zi7RTCp+!@n6w@3Y|A!eA{pgjvzouXtCxB!TlJ-3FRNO}%y#gahQ3OJqPEl4|mAin4 zwnF{}u?&BQ)KbZ3vdkt@73OSu!C=OO&AN;RkY;4YH-+}*BuXVZ&$Tm)|gtfGpx{bwarS71p zvQjTYDjTW$K$%ABRkr5(UxRK$Nq2_hlFd2JNHTwd$yGkvFoE%c;gCA>UYMZ|x`V%T z`z5RGJW_$^+=IQgZLck-TyGWm^1cVtf-UuKatX5uVy_5gL(qvy2;(WCtmEIIxXO8u zO?31|m`&!wx8J#C)&1C&*0&$wERFTfjJlJqc}Kv(<&t?gMd4L&g%)%OW_+l2XA5z$ z`3rwqSbDE$_3ar8=z(0pRv_n%*0utT$f`^QTA{ilQvnYZ_h@IMhip|doASstfM3DL zrUJ(bHZ~4btzxt0*uPwCR)bzM9_w!s(C;-tTJMhd7C~C&$(YM>90LtAC}Jq`HPP`@ zkawewcB>>)KIh_5`oixmy9Qa}KZ5!&?BaQpta- z;J4JxTVSqtCa=}kTSBk#FR$0(a~?GG_-e25Hh$x_=AP^BFS-NMg?zBLr@q&EV6U#z zucOu9hhA@M_I};IQM=cbjG^>+WLIu!Ew$~Ol`7S4OYttN-tClcQ#i2{@MTo+FQ=`)w8T)d*-b=U-k~&nL28VfTNj>^`Nv>L_okzi&c=uN~X9eP+BGcT1G(c+phi z-739&d-VO1#@{$mUPTfV_UeW*S=;+2+x}_=)7UJ1N@gppj=ovbO|5vETeMU@pFVrm z9${-k@}(5guSO*`MyG{Z+G@m_jlbKes`sO;8Us+FurA%{Cd2S0l-RFMjkSLj*%qp7 zjWSy?^j?Lw)g-KKH||w(4Klro?pdLPD$5S=h9q1}_gq3wFyqQ0*9t?DAwqkF4jX7Y zLc?-tsdl|lOh!E!e5H3pLLpG9v>z$%&Z0*siBf_KGaA)TMQ_7ZqN3v-i-=c6Ix9Q|2|^K)QeaXfjhab%@`%kGR6K&= zRc@zU%$s%?o+mM)R4F=G!F&Y7_HhkkE*0fMjTv3*W(wI8-ZPn9WS#};nPu*>E({1EU>H7E+U3Qsd0H%*dbAQs9(ikubZ7%*J0`L7wJU3iz9*55*8CH=|Gb#py9$%Xv^F!IMynTvTM0#B-BEPT@9RT?Rmo|Wj%4l>3M11zX6;WOU$8E z=f5ayRNL<^4*C{MruAmKWea9$f!;D(H%=u{ZrrEky~!=tb6FO~h-;EUf;^I;1apxM zeN3~Vw7z*iPd|UD1@^M@=~KQngO1mrx&yl4_BK#tcW%MUm!NNg9+PYc_GV^LT+ST8 z&%0}si9~5A%W`%pNw7|%`D_NW#n5zG6T$651U`KNoc_lWTQ@Jiz3qV8TOCc&02Uz{ zW>{PuuL7`$(5PYBWBx`&UVeoqQwyye`oG(xsHu>_n%_6`9qavQ!4O?*W_|#Je&4~< ztHV2kAJ<3gAox4@t4)K4Kl}_*$00Q=vJQ`6y`3>az-%t0h?$d2B^wC0lJ$N;i{rwR zZzUdo?b+=29q@PHVS)kuDw$vkDNtho_!!*v^Dl_d?@%$M3_JrfoXi=@jZ>vi zmpcquM&Kt2He)zC?%7Xdq?R+3&9L+?eBvZBGw))#lrxoAMw}ROlc)gblZ?z$?J`hg z-qM+zWEv+S0IHys>IQ#Ig?p89J=_ulDNWsfiR|wWhS!>U8|eK|^=e>~x>f3$ZS-FH z?0RW9;~-^9xBES->u0~Zef?1C?1why@fTAR$IDy9tN#X+H}@FCm;3Cz*L(2$t>UX8 zmFW0Gv*sSBOsiT8?jRL6@CO61Y;5_ zw=)hQh>(o_B3x`y_GfX-?do9GDgyO?5PZN92<9J#;=ezG&mf#L5JVl&0l|3hgT^4K z5?5i0+;{<0kZjIMZ&Q?9Oz~J>-f@|ThM^2{q7xj>MZY5ow)t}Fb7%=+(v4s5_l-^f zhV_69Un3H!(gh7!Tq*R3DEwvaC=6{)^$OcW}?yFdAV=T8s6d;N(!uAaPa=+bbCX0ZFelq8$P(eL;B&-eGm zfBXHu^WQ;#u>ayugZ=*V{)?ykgZ-y}>JRq&gZ`gDf0IO1{pOUx>`(o*ak-uQMt+~R z0O&lH6W1_@~Ks5P%Yv~9Yr98l-`gmGNYq#D)R=nMca<9Tt$X6 zcfR?{L9`;(nM2c3Cr|k_=m+5xW-t^fs^WACllcr~I0TX$VOS&sCfP`*IEql>^aX&9 z;E;|w$9L^-DHMOKAXuWOC&j38yXF4t)?y`T8nP5K*dQ^it>=)k-myai@xiJaB)Ykp3{|0ueh2KQXtb;X=9v- zJZgD}?M{=>rtCCYjIeK8FP2DQqNWW4Bg7z%>D^3Gj#$|)dhlyA>)L5KEYh<_C>G% z`~c2k1Svm7K?<43nQ=44u}lmuTzLSdV1)Q46`?dH3lxDLe%RXj^eF&%Tm--E{wi;g zrJ{dk`y6*(8_t3qaC@s;Cxqn<;hatL*IiMC*ATBiW;Jitk{z(^|88Z`*x_Keg3bQ6 zz&{SoPft#NmVQV-=FftB#5$hQcxev??_kI5`%AG+cZ5sY6kf|SbVeuxF}_0aLLI|V zDMg>{!yGS!y?}7VNfyqnpM;6RDNHb(btQl4KamV*qYscFNJ&C>!3_eGWh9xz3qa?S z38E_OF{h8-V3j_glY54DfHF+&oT|iNoh~?_0LFqahOg1CXdJ=>z?c#fiZu{c6t-&| z$t?cYFvd}Fok&+rqMV~n#X_6$|iVwYed(leBdJ412KqjM6OX+asY}cYM8pp z*`O_^Bh7Ha#-Q_`G*H{ie^N2X|4BPw8z*5rk80*>$2U!llT(@ku&^z1TlX}ZoW5X z^F+}s)lYDKd~|a0{_No5;va9%k6u3BzM79v$YRk}#ncai!o97EbbAbh6x*e_O^WP3 z2nhIJN)oQ!yzG4HMvy_7r!&w5-gdxeVPXG#9|S>!LJ}c++IhcJS}%S+iSF5Fu9%iV z7o5)%0F7@ciHdWQv&ozy>F$3kqk71J(f!ZnNxP2A4yf#AL69MlTKDCXQ*@28C!ltg zKoFqhx-<#)-yDSOJP4%SkZ-WX2R+V#Hq!|LKx2ebfD_@9x!7`#I5YhNA6@{!AxRf< zVBOpaMS8Z#9<4BKH&{JB_dP~>a=b($18W3_JvK|tubaSfg%;IFu4I4gu9a~d9#r*0 zeX-dW0Pv0?XQR>6#R!0mK`DB92O51uAqWD-79hYj@BMR2Y(+sXq&ErZ)k1tpNDl(( z9khgtm843FjNqTf5CG6_goA+Z1kloqS;IfDxLu=36Je0uWx5m8akc76@G`^t`JvOT{enAzL^p5 zXyThbn6|b~2}470fs@clxG5u>2$-eBv@#3rYG;{_;vkLkEopyLieiq^=@D4DX-cId7=UyHbS4Gvkw75xBGL6Ad>49eue+Tl0UAB+**-kJVuD)9`UlwJVl<#p}D^bBlHC>(n;vBVEW&7?{BYVDJh7 z2*&6}`;q77>?UMza;Bo!sfwcEryHZ z^IuO6J?o)0>h=OvP}KYMiA(7jOeTn*sS)}J^zt!d1nPf$w4g7K)vjP5IklZzy{K%C zEqc^a!u|HS*|#)~)##;>ju+0ShxjfB-y%*hnx8EIn zuajIB$y%I$zIU{T({FYCo0#h1K8Trb|k{ffD-{sM@3NqUVsoGYj;8;I*jgD?}x2dD4v16?qC4uJQZ57KnW?u zlVpYx2FO@iKhBYKi@t^#7Ow&-o;JVd$7X1!evt>Pd-WF) z3G3QyvBEIPc*=Z`&Wgy%XH^50mg;B_O+z)^L>Vh^gF#B)M{P*1ugEh zw}%HUC-k7rlpY?e(bdC)JMHPwE9v$`8~b|nN(8*8*5Wm(ji$0fPOr7zny79Csd`x| zmuVdYQ%8~4j%_duWxz(lRgLQFe;QHyKvtIC0G`g;)w(hUrzzy?xRkBjQv5(gC)~}; z0pC&o=(GaTW=FGPkg30BFs;4g%4=1Q7y5`P!^z|@hZh(sQ}IO70oyE%YnnaYDR1ay zFo7LOt<@~F-}ke*kfot9Ix^aTkseJaO{y9(@j367HD+j*vPI1h7(EuGe>4;RGh%Ah zE5{n?>r%PYO;;GtWXdNXMVGp^a2L9{p6lwDPi4&q8=10F&-wW!-<>nA6rgJqNwY@N zE2qWaoGF0TIj1Zf>-t^u%>cRVaQd2hN7nXVT0+<{9FtVzs_`iUe_Zer7`}8L)oi~j zrwy;a9TRdjPeF%E^BvjYe~$0X)x@)7PKpMmi-b|FS*X{OxLy&#VM-(Q8H}FqM=10U znNqJ4!oaq@e$|bUJvKY$BCf6328CdV0(9VkZB?n>K{J>{2XQ)ur}G&Y^qbiO98OVq z#pz;Glpz`LTRx@A2;eG|j=X0DRl8y71vYRWVAUp|qr7*sytezof3r$U=U#pl5cUg( zUqB(V6vqg_IL^b>1DuGnFyP`M8e|Y`w_yYWT@cQKF;PT|{>F}Qk-+=Q*pT(@SSRKErPO4zCd6+w~ zkp{pSPs%9xEdrl zb`=vC(OydA{{&2t6iBMM)Tl}7tv9nGO25jyp2wW9ydBz2uDvYWc}-A-CxsCMa;K)6 z?QmhtqFGIh{7K^Jf=sfEqOKebJrvNPfYT}idYJgSI&us}%s)cgK_I>vWiLA)KYsk! z*(ptqBYBm4e@3?DvDwP=L>$gl1MyC{bc(M)W8u77^cT!Xg!C(wdL2WNG;X{kDhQ4P zVHc!&Fk<0(Gj)AHIZy#Yjfxe>^QBRB*X_IX11b-h{`WfeAFln+2v0^Zne--*p&Pj9 zF5ql!JD_^|pZ?(a{=l*SdA|2z@4^1(K7O91$JG*&f3G{cRBmzl8)v@aLU;&_>w8&U zT;Pj9-A}i!a1sr{&yugUW{5#9rVqD(dK;1Ay5hSnGedEuf##N-B@?D;*FHb;R~I*W zL18g0T24_s>(Z&rT<>ilz8EdaxO5)NGP%`lW-x&h6a}M&-AaWFtZtaXj0I$@My;Y! zNM&B2?P7G-6zxaz6O_(u2j}_@|W^i zs77wKuAzXYDCEH8woEd~DFVZW5pR+#07{TP7nsvin*WBf=2Wl_Bur8`Aw{*os0fnu1^-?C|j^3fC zgj{uoAkC15TmBy0AUv6hz|VnB=Ve!jP>dJ~)YIz_h(bCKLy??rSNzEpL=^4H;KG3@ ze-d}Tm?T?45LiQ!jbJElXh??tEvgjn*J`lNNsJnYC?g_a{`WCRDg}R#Kf}`@_^kue zly-i%l0t#sxU#{}cpg*4qqhUT z+Wh{AlZYR&ZKgRGsmkBYbdwmJqcNvVf6q+Kz-<9wtc#k}K)|mXDk!SL06xkD`;q;&zQPQ2^ zxQ8>6j9_xrn_w2hk^YbJ;2RE}cK_P#n^DPiwnr;4c>sDNob>3_DGfrW;Ik9ooFWDS zUIH6$oOkdcE|Rf2Pa#PBUmiQtfNF_jk~X&~-1F$1(T}ZbA^mJ0O@a z&B^B7p)rx-PiPpBuGBLs)Y?Ge?uwlnmX$r z+N1K@`c>)w*EnNyeqc*i;>RVlLo80dHSfk3we_X3(ftkdrkao>0YT&=7_Q!787^5KmC-hS@+ zpBuz(+IE$!n?*bu|1*HB^#-P%LILm@0LpJ&Y3q?i9kG!o_AydAyJXwfrKeFBI7{Pee{EidCcKaG3>E5f6m&XOl=x=U zH_(E!r9oxglq&HTq`&&CflTHv$O4oyykRkpsnY-p}|Hb+&kLk z{nwwvAulcQMW@GRsU&2ClL+)h9Jl_K7UsRtPxG7hGedaKe@z!>DzB)orDWR+#FmNe z8zdw`LBHF&{uIF|MwG6e0IXfi*K(bI%}F+&m4+lDH%S1;3}wL#$1$cTB%DFo3{j~9 z2X??=y)i+#D8~@T+ge=0z)d@lQYwN=iW@W;_`UHuPzWEl)%OxflXzy|%VKY0Gk)&HJ8eaQcM zFTe8XDmdUs+PEwG2+tdpXARp+*j%MMf53(Hjr`p8ug~&;AK4q)0h-=_2K^WA`hPxn zxc|AAU!7rR<9&{1mWQjH@BJz#HyB%_XbAEE+*?2=e-Ju38-i1kptdSfIv>TDPEQFt zM=)9(=tKiU5fQ8t&@%#mf_mz6o?ULjv+p5NA6f5}_0D!@4g4mfL zr68`=fY?3Lb==NX((Yui^Uz~~v_?1gji_5^;xS9|xo4?;>22)cx8l!p{>N+@Z1fqZ z{`?>8e+|n1fBXASAI|^#_^tV(BiZHQ{Qut1f6W6aPA2a&1S6avO5evMgmITni+7#> z5T>^>k1j9x?KcpN-TV^oe>!=641WI|{Q1undBHo6xBmt@k3V_Z-F9~51*+Nd@b$_2 zgLjv&UUnQ*9d#v4Q<6~h^6|Dl8PyG2K*3Y+e|R918C!Wa{#jTxPl4#@lu!o#>5H1? zoaCZWs(XF;`a-4^G9Zf78Rp+AEr!Ps!-!BP?y>)AnQ%LVz&V>9igX)}<+@7KQ32lv z9jFu@)lEd?Bo9sg45ZGes1fm4rl-_Yw29LpSpz~NyVF&!jOVBxcd-`(+*p|4` ze?GOSsEa>h1_t5}VbUsCIL6oLfrB47_=|HeXQ1-O*KZGwPELQ;`86nr3Ey&MCUU+P zQ^WvHzzoeuwpeK)wA0e~S}AmmhgDLyN-mC1FHcU7U+2r^{pq_mKOUbytQzkqeYpbw zW)$UIO}p^sD(CASPJ7_fPjBCy9=$&~e|tHQMD;iW=H(*Uq5hK16CCBA&flG$9O-ZW z(ZlIy-tx1qqzJ-eu$`lLIoQcR0B~|-ePeJS!P;)@Y-}4F+qSjw#x^#_#I|j1Y-3|? zY-eNJ`f}=g_tvetKjzO=Pt|l+*E{{Z59ZyHqv=!sB$1GSK+J9}ZxD*anfcqt zcSa^F%xztv1SdQd6vgiVSBK1qe8QFjo1oAKRr2T33M7?zM?mw>tJWGX>N=k6&L$6_ z4~6?)TyCxF=x^`f{H#Dj7dq z2(h9)F&?o9CW~_gb*hLyKk+gT?-m*XtZW|}@2iSDx0S7g`VKX>@yrF4uJ>82ETo>* zT(3_?s@o3uFoF#MaH#HzRu6B@hR@PF<5;yBZ%SWex9O}h5?vT>E~)C8Sc5K z?podM{m{o?`+FbZHLO2el$_=`-9yY7dB(VXn%X&FDEwyde$2`F!9_>hu`|d3p9gE{ znRgDp63$PF<%WG_X)vb#@F|K}gEdiUa}7{V@iLsZR+%q_$JyRlZC)l;mW-fo$JNVIG%l?yQ4yw6p|QLQhxgL&yoV}F)6E%z{LmDFZ155wzv1Da+0mVo>Sm2 zHy9^!dWl+k zmgnSYM6~S_ONZ4;o6R+VwmN+4+Y%vk0(RhvAb2Xwl@+J0c(WSNZrEvCmIx=Sot_hOQ0wFpYMl?(8W*ofghqDv0l#@ zPPqsC zmL0G^N^g$MbdTS(SNNid|LX-y^0rG|7)@6=_558g;Q2IGvB!9@puLu?QdLqyUav7x zf<6!CfI;;!D1IE?dk(QRFHOC1mD&FG%~Lg?Q`@a`W?PURLr<;+bw%vhTV1TMAtuf? z{q@uFQH9yy5s;Lc!7)*tb_82?B!KdU`UUrx!(S?178e0KiXz*S@}Sver|L4|EO*nE z-7Hy*TNxy)OUCFgbD(U;8n@|k*k-x1{mB7GGGK-#cGHQGdB8*4-z&1-9-V<$o%HOHw0@2zdNEt zfoGVG?=9p>*12@NwN-&>LnqgqcF6?}=OnPsx0k^6ZBK9(+8*}UzqpnFSMRZ4B zDA4`Iz;zm)AcR?~rp3WDQO0W6J!H<)Ckh$ zPC0mPiLR{+{B6~-^)1f)CxLo(f5$0LZ5Ic#@lTp_svD8CEGjinTZV`S`xY zlPLj5vBaR>R{G}dFj=Vr+0sJZSK*2laSyQ1>nW9piB!~s@eM3eZS6Z82=o7_sRIJCXOeQLe);k;3 z(KMuz^iSyPm#I2r61ooFEbKi1leVYiwLp`{T{zp4}K2X0* z7(Bj&bs4LOIT9#91#343tE?b)@ z5nLXF{f>c)X#y$loBb_~#~^tlnRCx~1KW~uv>_@g?lY^de7P~Ag9)1m$j4@|V$;P7 zFOBE*vrL?{5tVz#ZFu7cvqyt4dGkU}Gznn&Q^GXEBXMyrUur@qN&I)3T|X2psmz*C zXlQ%Ogrg6p=mryPraD;Ep9wZZnXRmJ)ow3=o+VAyllw1nb^@0bA!JK1yd&KlF(c@V z?T&~TQ6zL`fH;3f=AJbbP{(}ro2y=_OIE!VlymkcXMM?geuw)(Qv8ZFn%ag;8MEY- z@M_pY&Z~pY>4KGohL&X)k0wW*0YO~T_vU>oC!y+|EPTIAO~r2`HO9ipyD)63-HQo4 zEe8HPuC}^r-zpKSXlZR`f6HdjRu`6Abdb}`dR-uFGo1nm*K0GpCluk@ zzr7cOUO*8Vq__`U={*3hns~84)T*d3TG|!=T)GmIz28FDd3O?sK+zhUa}kRTklj+1 z_oT)tKhR7K-#)?7yY?FQUKu>qPef-OBJIf{zyv7fiorX00j~+4svI3%KQF38T+g=e zM};?{O(L@#D)cVbf;v061Rm#5@|m-SCqjpA{FER2F);GVUwuk)AYh@wMl)b%mg zl^GR?AzjuX2k0NzReRe6+?=oLLwf}tINP#s6wbRFj}3Q)J&nWMZRM%0h_I)PoBcc427r4Pr%%Dw;3CCBk!TT1MQYn7 zg|qC^)u^leu~1`5!5CLg)UAd>e22FImtfEgNrYXl&TkO+E6ygE_IH-x*}rAUO2~wO zINS!05n}peLjQcn@rK&T@+SuSukff}<`M5lO(WDM2APD%UeT(BNkyW*)FqITSu!xQY0L&~(j#nE1p7&HxV#hecu~aZRI>j4h`~geI&m zNw?;-Y3fpvQg0Z$N_(jcUR#HnK`0jyM7#?aq$x)B{ zL#3F(F}oS;Sjwd9Qb?^S#-Id+vd6RbQDkJv{$)OsXankSl`}o05N&H+0W@JqrT2wp z2H(=9?yHT1}k~V??m~(j;2VS)a*kRS1)+~}1J}Wz15TQT#howb z|M(U=w!J*wqg9Imqd*}VNn^&Et? zi(s0P&!PHc$M}DqJKEW>GB@tgt)mCnk7m*{)~kQ4|L`gljm0gn!xq(c|AhxwoJxUZ zOUp?xF`SI_@bhj_*-vIN5=ft~y(Rzq9L0*~8`Kf1>31Om;TZVzeK~8x`+Oao>*^JK z>v?_hp@sfKGx+JMKh8l&%xBIKyrUDne)wQK-f#;9Grvuk6SzfOl6t%2;b&r}tA~BG zk_=Wz3?ncQw(bO5<5gjscftV&?I^>kc`l`G3-!t)ss6XY9SwF-H^q+g!^xE}&~|u{ zN#Fq*%7&p(ivPENt7>Z2>afxIr`extS-&Pto945M@nOG*^4b1!usiefTfxYpt&+YS3aVtJ z)u|#?c^4M@ZGUq(287Egr;qVfXU2oz?e!c6c9|Ey0aJu~Jzme;R7DxS$wNzVV8zRB zR=(8=FgBtz6n9r}(Y6~Ags5-6b2MB*#V0>acH(#!_etqDtrZibL#Ue|_EKQ&$}xjr zw8-*KaA5z`0Yd=;f^_+97#xTvC|qI2PT&PW5vil@lY-yrVzA`%z8#w@{$09#BldOs zW#&)r%t3lf4n`u4iaxet41vrcp02PxL>0PNsM9At-c)+chdVDcRk7690zQPAsTVqP zXKx#V*Er9Ct7Tp_sEO!fdJYbfg-uuK0Zm1*`0ScK02q_*W~p~h4a-c?tVYuhPoJK9AZKb1%1!pI_}k=(A^7h*^u$;>2V8T~I!o*|T~DT@VdO>(Bn zh4^Yr08pM?=8wKnNg=P8OmH;|9gb>yaY8<`oysjkh<5B3@&*Hq&$4; zR*xPquTCgW*M44}Ctm`&7yM_Rk2kkp>2H)m6Iy#&4N}3s|3s0e#UoH9+DWm94M5F} zBf?D55uXy^Vvu%1 zFpdc}R`^F0tBOkUErcjbwqEKUgc8m|xQ5~Pxl!8+63;Y|-tkaX2Ea*0Ebar(#B zUPD50*(|_XN{NFhkmS4RrBhzBx`>t9*mB}$%O)A+vO`*hmcuC_;U;RJBCOuttZ7Z3A`nGwA zyE(9%o8B&&8}rl0jA*w~1dpbRq-w+{Lc5Oq*PtJL`QNq=hcppNsXGg9wHT4E%?bF| zjIRBLe-g}Bypk13i3Ogc%LnE4-(z0kOw+7;J!DOqBcdgcrSy`l87JQZfe&BcmR88j zORcq2jmc4yWg;v zC+ZDGx#}*w{bEWuqB4p=72i>@qF#DALY|4@x+~nadlcFP=Fm#M3`ai~_gjjtv3Tf| z^ym_%er(g-Z%SQI8EG|$apTBFqb-%~Nft2_G>0O!xzU9Ng$@H>qZ$MExjP)!Sfzy0i^giPpnnIe8W#C!q0Qxt73%l3^lQ$4u!>uOIJ0B3<*mMkw&=uo z&EgLZ4xd5?)`3h-4oO~lR)|8;1f>*Vn_@I$ath{jI)-)H%wt8ITPQE~FI<~Ax}<1Z zNa>jKB=B03bPC#3LX}luL0C8;pkHYu=v!fU+t#PV(I38@kjsi)&@d*p#;vo^L=6&} z(4Wb${6G|g~j(j8Ky-WugD^CwKL)b=Rw5-z#Unt13f96fc%*w(T{bl-p2 z6v_wwNUyjbP8^>LE^OydCkX}G&&Zt*bD2Z^-ig1o@q z^YzMUVt?RxVoT}eRwsYC6rS`K-C&j1$=%w@Cjfk&oDZ5J?%V2`76&>`UpCw2Un+Eb zjDM`HF?4ic^%n&8*l)5AUB61K6N4+eNjtS;Nu$YjNS623PF`eIL0;R7H&?23kZ*%P z;FI#^y#%+KV9UP8YqP5D3%o}CKj76UIRcV)v0P8mEF#4%o+l4)&^&<2_RFh?hF**#3_`2LE^~FUNKCx@PuOJD)e?%pu?z4 zC@9ppoccD2w5dxczdZ9j+-CHCp)=AhE7*GE8m5}%Nyh2DBGDha^4M@UcuOU$3ag7> zy@xWPpR*~~Cp}ro>F4H*PSny)=FR$nbXRAnkctb15|ZmZ%{^5D+`Lv34-oC!nmpGm zr|0tc4>YNvoRcBi^$})?S~w}k)MQVd4$|+(V2Qf!cHa}spo6j-nz8Y9qth^xZRdKO zaLGpn!LzY@$VgWDv;jIIuFz_gZrU$~S*)K5tYW3)G1}8d9FD?Yx`{&^ZK$HP0sk<8 zjNch-XdY_7sE0zI`Sx6#DUk2^a#75c-nm5H75n9+dt?gVv`)5IT@P+I{MeILOKEt? zVqx*J?JGB4<3YnFD*LMo{S_kDYUr`zqOPO=Ehn0e3Hm@nJq_F$Tz100HJ<(8&#$#s zrc3kWeX*vWX0lN(w>-QpehVxPw=&LtwpPEZ;y_#1-FI;sDrS$tsDK*#-L66`Pa3Rh z_(fI2Y@M93q$Zb*x=Y;@umU;;>P{+fbh@y)dRhV8frLXXZsYq**=ay zS78RgTqzTwIUQtk+O`+#bB$cj-6^()xaQM}t`y_G*7LQFC52YDLj7d9RK53df~K~= zF|eKO7I*cAF;acp6wt?Z*_9U@WAEMgQ@D;grM)?vJN3395bfro;3QiDFpYf3uj@4EEH$8ketYzM>{;J` zDo(8hNdJ3w(K#Ug_P?G9m^j*%G(eP z{p*|6_2X^!CjlW7XtJA7syBRAf7*A_-STSKKDm#7ko{ApASZ*cRIZ3tS2oMtzmJ5& zj?NgWzu~q*ofZW44V9Wf$*}19Mq*89J0;IOVR#m&oSG$?%VlLz zY%8esM51LlyD(13XqtXl7NU||(j%k)o0D3A5w;SSZG{8u%FHSeq(yJ#HMc?NhU+Y~ zQrM($md8{V=)bN12Xf-Id_m3@^>W7lLe52oQ|-dkuRzpcivZGCzZAwSk|T}V0@8yE zxe@{hJT_g8I1O#y;$}P&@k+>QB7M4}dUzX|GJ^r!^bOVGXmmZ=xB+*3`tlqeCt1`l z+zD(WFSv(?!3`=_C3BLCh)x6f37&rKsVNlHiME__%k@^qg=1y-gYzXs*NTTWjdu;MKci?VNN9G1AiSuNWWkwko&a@uwYiuLD8C}hWgy9Lq4hX66a&gro)peor?r!C4NY`hT!X&SP*4v#TpL;Mqv++5e{Sgob^8WbZa}h8xhb9~Nj7Z_V-J{Eq zEI46Qjv9_$l{X5Qa>EobY5#Jg*~mMO!UyS1LE6Jj(y4Uxj!8ijRZx#RXyWI-kwUCE91k) zn?57q4X`mal?jxeD)rd2g{rFl0!W^WX8d`9RDh# zYb1P^G@PS=Yxjk2!H$JlAZaW=9Wa^IJ;oj4N+_INut4kEER0QKc@dB~@=B_;sp|q4 z*ng~PfK>RZmpQ0oVpmZhmp1!E$*;pb!iU!n5X=IValleh-tE)Eb??mSZe-*m*6?9Z z4nCpVA9JQrB{-h1gSR67i7oWmueS>lP9|ACVj(ePj2iY6Ejd0QI}4Nr$|izFN}3G< zx82skf0<8K$nedED|Tesfbf^9RId%F!X%#%hLB~K`DKJ?a`)eRJ$I$4r0s5 zONyO|AFz+Z(t5yWS;ut*vj_ovIHQ>z8&(eOsB&Aqph|>!cdY2;ZfX3HKYzZA+Qz>?QY2`~1RUAi=ts&u#p*vifNxO>=t*gYTK>|I`QT*a9Y(?5BxH+WzC zd|%ue3Y*uO`E~VbOESj~M%925!DK?M2QtzM())x$m_RN}GFR#m5|n9M)cobTzyY5K z3QOTL6vE$~HIr`cCm+q<_)6i1X`mVVgHDMC&OIsygPK0wMaJ>skwAj2@OQ`fJ*lubPd;5Z;$vCGKwEk?iO;A&;<-L%7et zH84Cm<`XNTNKHp?-b0RI>t73JekGVoz)%Qj3g#WHtwbUScrC|v7xZqN<*4xtSaXo} z$lXZYcIjO*nK)w)!?#_zB@3kJ#iQU4!ZV37fY=Eb2oi9Sf{Jo;gvwIarcNM*b+^z|w>1HT;y9MDUL*4{w66khs z+kgcVuqBv2c5}VC`OJO#V^l7f5t*B-+p;<4oeMLRMg&9fslIFL8jRVk{!F+x3|TQl zFrTPrh{^q<@F&LBJQTKkpqkq4eSeIbr}ef|!cgXg&PC(FST?hD^~18rZbG@Y#}Z9D znN^%)Y0<%T^nJ5#LzUs23ee5>ansvFKma^n?acJV7ybmDz8eoJI_@E`wFFhJtvl?mj0q99JrvWm2#p6kK=XcJOd6+Dm5n=f0iCN~zsXQxqYJ(_ zqjypNvoxQl4_+bv_%gJd3&2spubH-0~Ro@&_Ev0kV?61sf`p0Y^(8#3mH}y zhKFnm?KXY<1{)dFq_)nR+r51QMqqQ9Y}UoXjIADmeMUiZN`bRT-)nBB?LpH>;uzW& zuXlhWY-@@DNY?z2nCR9+{AoOK1j8J{s=ZpIxIX~tGiA4E2Gmkvf#p^;yXKh%B%V@O zy2}?Q#GxERnKgTnYaL>{NEc;zwQPnkhrnaj6S;BNdG<`_l?bL!Vfj z^$N-lHW*qmEgYWs*Am^fE~ox}Gt6S-=OJnYu;Z{yqzDbxYnT`a7d`s_x&f5O499iZ2H^6WNwoF~srI=nYaSY9w^khHhUFA{ z!KlRkQf1WaTt9ohVMUocNfEljJev>A*)Wq+5r}~KqU9=3$mWJBqroJEfg5R} zx#s)*B|KEQ3Z5Y9xYDLvqr==l0Ol`h0}E6HgWa!ZoPw8{QII_nYeJP0X1TWEQK5ol zg`-sFzp`fHW1hAeWLN_6 zRHaVT^pR5NdJSo?`GMI@Ezr^`0uKxitF76BoTB$WWKw4rfk1#s;z^L5&!gyYDA&L;s|8#4xu&u3SUK z8L9-E2M4RFM0wnn!*F+lDdYvh_PuC?!^KRazF@DcG3#{9VtkP!K>G#Sxs7Gi3Ia(d*C=oVMK`rFA)!M?JDN<>rzRezszzug^TX{XSr zk-5P4krZs8?ZJlP#-A`;epd!0WT~IrEyy@X1@e_kGmI;l!mhVU_p<^#T(I|?5YFin zSkEr*vrsnddciUMcYPAX#s&PJzWs&j^VyTP{S!Kt9T{#@^icH(2kk0t-PxT&WI(EuTq>Y8^_``R+&}~fVP>I#3k&pR zpckEQH>yn9?BH@c3s1u zk5ApgR*-A-BnG~!iz!e!jQ7^?C#jQxVwc(_7;dP0KbANy^;oW(8eWuxv8ig_jDEC% z>|pe$91bMl`HVOFmmC$))Zlf$ah$G7)3LvfPV}enjm0Bb9Q!dK*WU}No%d7?jIaKi zA+-T_jN)v@b>y(&rM3&z2 zF4{iT4+jpzce+VT$5{=(ya^sa9&&=n&VBH#NXwhn z7n80@ael!s7$2^;VUrf-q4Od>*Z3|v)o#72`bVf1u8J9-Km`SIsPr|;=kDpvsXQhtw06ogcg?3Ym~kFJhV!R^a;x>`aHR$hgSGVs%igz z{QijcjwUM{Ec^t(K5xoE&kK=-sYv8umQFo2+k=@6-c*D{&ZXkr0rNH~obOqrQb-SB=zf~#CUTkh17K8ck-fJ&05G=r&X#} zJgJi0Neeaf+I#S0tRnFpUo)zk>nMq?{sea{85^FO0nZ(XP%Ha66o6cO4(i)NRTm>{;eBcQ=Q0b{mF=L`GjSKhfB$u-xh<)?a|IK( zXt?bKa^rgdh9cX_^#`Ovc%NWr=gGRT58D!_o}IAOBw9`bo+=VQAIFm@lV`VB;P~ds;{q%07K>^3{?%3&Sc(fBik|q^cwT!CV9<0G28?l4ZKItQN z5(shUPt-!W3l;YNQdc&L=T|_T2*$yQ{&ZAWCnqyvF&D-Z&Jza~seY1pcrN@L$3BvV z%>53mVQP{0lN<5#COFXfKkUGpHnf33;d^-qIXDrJ{SGZF)49R zg}Ho|aFyJgYdhSnEjIS5*u3}g?PW1!lJE)OWi@_cvW^u(NP%3X2`&vD>YS8iM7lrb zxg1twrFpsB9C-iExQ?g|<2+_CK3cP(EJT6#zDjX9N@oh|@vQ2`it!8a*|!&*qBx(d zdm8qdRDHDl8|WDPY0AtCn07oPp*s`*i=CIc4(Uw!sazSSS;E6Fvv7RdABnPvLve4w z<~@2z-Z6v-))A@uohg>u%Z1E-r%JN*L2q7MlCRQ;wtXHGzrI|-B8nth@zwPDWCc& ziLJe36@h%&B2Q|N3ANfFmvZ8ukbGngGRnUy278%v(REdJsSxYLa5z1!X}Dj zg6}6Lcs_}geude2tDzj2>-h;wlqysf9U-gJH9YMOo4zGM=1ax`wmt~?hFy#eD7kZd z_iFkoNg{UaM8s_G{Wb(;^4p-#UDccf9%Xx1b&XbwR~b?|W^xey!?F7Fua|Ma2oZ9{ z&B*2(%t$DcT9!D<-WClKG$}jmc@%nhQm6^b;rdCP{6q{vcCnAhgZU`z4m0=r>Aqo3 z{ia3y4@JSZyE~;W%1>cEO1kc(UrsJcEGHQ2dL8`h@QqD;8jl;b#%f(BIUm-zG7l^{ z#LcvZ-csEkB#rYG_0|u~9J!4^0R>FbCEYnU786NigrlgS*9(I*jzlW2#{5*AwY2o2 zTK&q+w7Tptzvp1@pcF8u+P6!E{VN@M-rBK3TB2^0NxsYs$;lv}&<#YZ-s>URz^N9R zJ1^bG|)J8;U#_W3KMNaQv7yx&1yqJZ6D$0Q~-YPD1a_E8d`PyCGs1n~it zHKvZDh=C0=!jJ&S(`1*b#TYB*|CXYjqL00GT2Ot7+VsL5TGvuKH<&s02FdPZ z7VJgWW|rOeXfaBDpv48|Blw($1vjo0>7S{F$qNvzYN^DppPXm1$-+9+vkS||smFY9 zkId=WC)X^E7^B6VMg6Oa?TMpqN*6Zxxo&=s#Ka2doc~0$c)8C0xKIEdaZWDdkb8{U ztQQ#0$Ul@97mzMwavz{s*3=lU{q``~G&#}BIar(bvprW{c{YI$1wrT1+_t%?^<(pk zJ60kc!9b@51vmMejI#ys8~g@Se{hVChLfB&Tk7Ibk7yhEY{XH=Ps2}tyh`^s3e=$v zp&nO%Uw5dS)X0wY?#FSx@FwRA7i8wD5hN@{9HCf35b?P=Ha9}DMD9%8`|4%XS+=)< zl+eh1S&IC(0U==3C1bB&W6=n5e7Bw}%{9QA{hCLA~Lz)#bH@Boaox8Iy6X3R62|{=m++D;fs|ftYAI(+ao%5-R+?%%oQ8~ zvFhc;2(XgFpUvo%mN!^@m2nPaGAjH7+=+i-uXhNtD$JQU#f0Ak`@L{&bJk(haBK_|_WZ=*%;R1~A<- zTA}u><^j>7)c!gn$yrM@%J^U<<;s=npUE`BSqTF3UAJLcRg?3CW6dE+`%TDxLg)uS zyjGpwox>rWCN(B?d1YR_V@VSF;=v$N9N(c!ra~5`iB?pcl;m)4#w#F0;^V_B2c}3zZheNr=Vm8xbY#vHE zPd(d06is)bDXo2`NhIWt$_TRjV|?7b$F1;yXL$T_`&{5@nu16`D9by)#xGnN7tFd| z8UW&^HqYx@N2Y`&Z;ZJzI|Bb{13G@9jQq4eHfc#;T|1NHY?{#?N3Um;>pq419pGQ= zB4;890NHMuDBVFYMqIXSVSZAZK-heye2c6^agKEBV0A}7FwaiLZnCu~t8P)AaQjcZ ztKNv~2Ap=}5?=z}_kk3}n*MOK>;qy=09F@`p{XWvrOcJiy+X68B|#R~w(;4XkinOi zcq`!~hbVH&Zt76&r!kX#!GTYQ*LlprnjJ{56e9{o0v~xK(`3=iHJ88Vz0D1eOlQL1 z_94RehT5?bbI8J?c8^8}k+SG$Hg4`o#&7aS1_`aOkYp%({REP1-8Y(S(b>+yfQQ;E zMiv$vE)1t?w&zb8T_$pK4+2{G$`$Si^oS7lT6F?o|(Vjf0_t z=J0MbXH4<7ybXSV6LoTHxoc-CRgHv0^ubkjTkK&f{a0J;Vh1+%?_t=L5I+{vDjpwr z+J0wrUbYqNACF&JXY!6+@Mlm%0l4M<4+b_OS13Vej5B?*IcY*=R9kK3H=@`jN-3-| zIEX1wUJH|OE>a!X`<~(c?I*R_={~Ac(G7mTeapZ-dp{=s!j@;zpE`h;y*=PykB5%)Yi|a+q|(F@1LAM-@E&dG z&zS40C>SQJR4D!svJ61)$(@U?!wxkY-| z3mdjMME`0F33@6Cd?G0l0-FoK6SZK5!a=?XT6(dKloNR?@9?Lf*CoOH-qLxjL@``M z*c~mZk`OU0g&(B~Do;Kn7%4IsY}cca8gdb&SO%Cx224ainc6XOgdZEIGN|yeN|ETl z?4w8i!}spXiOb1#uLCzb?kOT1v&;Llu7`$4?bBPWDY)m);rrna;3q%q%_sH#YqoaV z6OrKP@vit&&({mAe)NtRBm?j7(57L1pKl-ipDEub2Q&`{96{ULa;N7OIKV+-oIpV& zpS03IK>iFq4km(th>C!Kp>5-cP~CtKi=9sC3)Kchwg4c=1&9!VbpirT3e}ncM2mC! zljGbVFi_yVa6N56Q$@oZ5l$_b=1xJtKXK#%up*Ek3u+O6WJDNE1ssItXR=rdF0Xg? zyo4+;K}036>a0JsdGS7ZiaYH z+uSRbKXHN-fF{TFts=daa*KtZ`HKY!EJ@ogtYcc zTKB$!qP-hjegf^4LQo+x-KnrIM}Q!6WLQNe)|{J|f`ySNV3)h{&5@805Mn}&)tFYE zzhNQWcF8jY^;Jj_&@@KWU__?HwnZ@tfCbe$^0EqE;UY}}1D}W^j>}}6)L{N2Ift{i z6OLF9)Iw!i8^nFkD)0=MO^#Jt$h+ASIOl>O3u|Cmp4;q(!8z%bn-Ai@f1AD`fy zpuAnDP>y{-7_&yjMq&)DE%Pjk!S7jKn3m`7RpkY!IfS0P20_tSWrosnhm@bZhFYEA zq7MYals5=Sq3j6iiG0qyvg4I>=Pp38-EDPa~PmFG=Cxy?FyMQW+FEz zeNB|;?0ny1*J{VKD&WrPhC~zZN$AgFw{S#^`lN4(;WCJ1RC;1hOKNnrepv+TCZTtg)Rh$>v0DXo(eBO z1k5e6DlztPr43@e$~1I9e6IyOePl z4<60~%aVH&lG#*>qLl!(#m2TOusE{wL-^5~34KECcTGZRL7;?;9Ca6DfeYR%RR)Dz z00}|%X_(w2pS1Ztd?|#SD2uBO;)gAysMAkMZoco_D*duJ9ODw<+EKyN6C?$AK!~t5 zS1nk==tTXfW@D*W8tMFZGho0^v0<^VvT0lljr1g5y`Bn!hnw-z!MnzXJ!PQe>doS% zJ{~u|hcH!TE<3+S22R5XRxz5GJoUN~J}$f~{odQvtZf4xAu+t&@fUw-sXz>=)JQQ5 zZoSRa@I0AUTKar^H#slQ6oEGvOz4L2d$dF*Q3coI zb+oz2&|n39t|0tYr^g%>mu4x|?!P~HQx%}&##wB*@;lumxdGsLWYSE4tM6uURbl_N zfmd-u!)-)`^{820w>F;q;~l72!oZmK75$t51wDNRQ2-V%kVBzCf2IC2+f!CHGGN@R zu2S!?Q)ZDTKa=W*JyKPt}u8oCwbqnBc6V1cD8`~^?dElA)K4d z=9Ui|fniu#p}DEW_|*we!>IRqM*pc`X=RDX*AQ}camnjilJysCCrw3FRn^Ivk+9tQ z;eByPUo-4G_3n;ng0mu&Yb8D&i%a5jQXKMYSM^a>uJfUv(2&IHhwAM@b#?VYRHOz* zSYsHSsI;rF=>tpVQigy4Tx~x)JrxzzQA$|uS+l|kw#TuxdK(P@)|=*exj7diTL{U6 zAJS&E{(y2C)!3g~7MyDbda92?NTgraUAD!ghu10N>070st9&ijTyIWGXUQDnsbQo; zMLh{CH*1ZQb!nXavAP=&APeJ|s< zLpbhKuL{|D2O+NWl`*=gd!ZX}@R{1_ac z*+uSdn+A_&Qev?>r{>J+$FL^k#YG_WY9>Y zk4dZV`&V0I!Gy$0$kHpu{yBIF8%N_@GD$W07cj5`MeD%R(9qCsBKcFMo?1L|*Xhps zQQ60-yVnUAOnV>u8oMizq#ExX8rs>fVRtibxMk{pF)&=(*H}3;A~=qRM-cAAYB!&; zLx+i(Qo@;o7W^)N#h}~DB&dYkF{-~NHZEP_YnQ)&S9|cwK_WSra^Kui1A#E)K z2oCVD_`mQFr>_Mn|x z$()dqlT+%Z=oANH%7=}*u_!J7CN`u3G^Pq9RjG=Fx0@gqPi}6m{rK@C^NniFG81;b z0~K;DNCA1oUR^_KLD4I>3mpZsWN~&@W%;td{-<2glrpHje1vLx)V9%XvTUF@JrCQK z(L{jwqTLO2(_BcVW&3aN*SMX^x|SWQM%Q;z3EcgTGK7o%qtcyf0NYjtq;bTTePXGcnOQj%mUZ1Z8DWx=B-){ep53@mmH>JHWJV{@5`SPtG;>bxC2zl-}GD zX3ZsTHvV%eY5XCtr$`(}Mt{swJM#WJaA8PJ(|_LyVE5toh(?;MkoCPBm&dLl$BtX7 z2uK-@!A6|nhzOmXn*&N84@T-nNAa((ufZ}eAov76X9_7%`iveA`jmo2Z)YIGba-u} z=<4M2ZApiPiEZHfZ&F({9?|gToSl}VLrT;&5;-|IWbiEcZ=y9q&_zW=lU;Fy1ynVH z=D~Q*Bd~aL^ef<>7C=jK_u-yg>tr}-Vn}7s15`OLZEw(W?SMwCcDOjP9ao*gbf=|0 zO4Rmsy~y!Vetlhe()hUQYAidGH6%Mbn|04K+?xiC!TCiFBQS+-AlK!jqpW{oLJoaO z953`bb#kGbRqh1}>Xc|hU#=fGcN7y7E8=q}?s7CB9rIQx8^w3Q!49XxL*s81R#BYD{Qxp?B@W{d81Rl;y^?zzf_GE`u)pIYiJ?%@i;Fq3X1|qi5qV#lwsT z=J3CvRBeNCtiW#f7Wp$aeat>OK`hrp`{Z`~(f2_XKt2)np z7sm9m4M--B34~yFQ=Ohp)7hV8;L2vMtwrYN=gS;RpY}6DuDPdR$RS6>KgoYSU;8+m z475#hEWop625u#c?>6Jk?LDw zlmBq8EOA>}+VBbZ0zfwg{0Ma@|Gs%mLu16+7T{y2zAgBnv%Otx-Z|s!xj*9U8Vw`U zYU00=;%vC36|-My{;is2cQ|}TkLK@9UZTfg(-Si+bJ!55kU+b9Tp6GsrVw4v;^fmJ z>p1?2;LdClNC&ez!W<2lzJA#sq7zUt~a)uR(W3%9v)s^8ds`vg6F(w&C#6t z^7ZTGc1E)v)e9qVptBfo4}8{Un%Io6~d>?^KK>P?J%yMphuLNSD2JJ)_| zf*06p=5Wf?7Cp7z-^u^%(cfMjrAWY!Lt4DC>zosfW^Km8!v)2=s$V6f*2GDwfp~V5 zHMo=(Y$d(6qP{5}IAKd_`qNtFCfH>4zzq5kCyBXOD@K~6U@!%g@Psh2_xBRutz z-QBJ+tIMnHkP!C!pvx8_6w~lL*?b3;|73=6Z*j8W)cmS^7F-oB$xrSh@Vb6J_2 zySdn&>VM@}@b~Y-zO^fDI#a;(^=?IbtrpPAh4Suk0$32f+f6 z4_Hg!=dEi@j5L?Y$VgjK`j(SC?b6ti>oD=)y#zUv~r7&=X z6di1(MOLlrhCI=3w`gR-<*W2m3gnoLj?PR8paFO7pUgs4P!9zitgK3Gj2#IV2-v-! zg%P?2Q?%Oz$q(`8w^l`E0(RfkLI5@#<`}Nqg{RZBG7*t5cZc4aAuroen2%WkS<2JB zt;$v!sy+&aEiM|zS^XPO{3^N991>DX1@B*qu*WTZ9?gq9eOmk#jk2(~D7%oJc5!fE z7#S(W<|}eKHZr(a)fAu-T>4_`j>_^;Zps-5KC|&Gens}r%4b>B*d&%G005h^R;~vr zOe6;@(jSy!QC{SRr zefr^l0XmulIlV*`Bb1aZwCa{$citbG3~4X?n&;}_)tW3&Ser31AS)~?8hy7K!^h37 z>ZTOeBp~2mcRbub&BLE%&i$>COANV=N-8w>&kyCT*XOP6A|llD9W?Rinj?Nzv0=Ws z1r~xedMi7B&o@B8dmtXncw2qiJaKZwo}vJ&MZ0UTnry?9+Kw~a>x(l8Xo`RPh~wz^*+GQ-qbX3OexG6CMQoNPfNVH zap>L7A~DPNj_w2F{7tspr8*p6{?26gF3aT$vr)CTqpEvzZXW$2e8SqSaKB&f5+2SN3V)8a3$xsBf0I8oGvjwX^`#x*J&wAhoLLSOe^M8Dcd4o0?8Pl4Ytl{#yZqjTQD$~5-*)$w?B(Ugbf5{p@ zJaDKcBVBaf7iJu#;evUe7!*_5SK!`ILXZ0tLjdJzQf~VXvC~|VxJviZEPuNnUnJD2z1Xk&H&FyP ze0Y`F7p}8glCwL@I(np>XG8iOYASMecP-b2!Cg0W>R;0Thuuayn$C?OOY{%hPO@A)l}4M#t#vS zxE-iAI#uglgC~1**ptnp712jbBIL^o7 zx16}Hsz~*tp(ZAj(Kq>0FC#sHUds*bO*mwxRiWEVb$dp4mM1xZ$*e6?m*C!i1Nii* z(?YEP_dPX?1!d?7Mu~@2vGUN z=Kzfr6}WZ?$Dg^s(xOrJDBWX_Oh$i3o^sRslbw-lnu4lR8FHybjFU)7&;SeVE9BO$ zRFJoaZCs%Gy{~?qVerj7bRw|`u!oFgy<`% z3@U`}6sNGkc_q87xdzb*u8#XEs%j;y#&-8c3ZUwAGO7LHSeuCC=CSmmOyrZU0_EGC0 z9h==iuUWxhCuq*vY42dpva!}dYgo` z`2FDQ9W5?HUab#q+i$a`R}Z?I;&<)WMcaHFjXy5D%?ory22L%f zKd9x}QPTD?4XbT;c@KSz(JE< zd-xO(JUE$Mhsg7Jut+4z;vwnIsNSMN>RWs6*j~TSBIwkl7YSuaX{k9HP1>?Ep9Yt@ z9iOkt7*CuZGCskpA|vq_zkYSTH&;~r!JIDI#cq-5vTy9uKi4Dk zA^&i>=L=8uBk8UbaWha0W(2r0k z^h;on37VPNE>W{7ANudFGu$WgpFd9oW##Rw+Z!1f@l&dP`jlH*imgu8xPt?Dtie{Y zKQajp#?T1WHGQIoi>CV4c;?f8qoD3<@cT6hO?*9vO zkC4sY7k?E2ki{GB=<4b2!8=bHN*s)coUMF=YOGs&4 z?Qt-n�%Wj*6=%-GHXg+~Vqm1|wbKn$*zB0%qc0Ib8vBm~fxQPC`h;dh15d+2&_m zCp$fiP$J463L`~M5b$6^G(Gjnbbn%PbyGJzJ0oI!X(=^#KHA6C*G}z{01@NMbX4OD zCi(|^x;J2?Ga=A_X&kG9ksa6^_)Lr_kMGLut1)7|bj$Ub{XW$hhb{>~^AAZ2#uEN$> z&YhZ+?`d1R#J1mF!dZ4!*1C?!-CJYpXw^us)0gYBch;v=+`HA?n2@&4mrY2hfjfcO+T29Ye*s_E@ee)9f7XwQlv@put0szDx|+RWkDc7w zuaGC%ST-liV;Q!lbA1$zc`i+RT~}K>1zTKW-b(y~eKgP3kDd~z#rAic1K|v0BUdx2d4V`K5J#wY=f6W> zbo!43i~iDui+}r4wq&1;CtDcF79{50FJ=uXp=>UOLJ{~J9fSK)UOh4e)0jAn%B{!U zibk8^pZs?%S1j3YtNU8t^@ty0BTd@S;3nu+kkaA($f8>{m(X#Y&8?gD*#X9``^v%i zW=-g3LJ14rug0;lg=}g;ZSBSGonxS9+ayB!yZ~8{$hCMg>F`S(eR6MCnQ+xG`ea;- zhgL14Xro=|a!%R*1+im7Iji>lG}rtwfAh}CY{P!vo?;~WXGR}9KnMfR-S(4 z>cdIm@n-7&()ssVlWu5$Z=W%bk;kZA^U?ggIigik!ny0oS?b3a+(jgF=Q_%g()13kR`JDL!IFr;}awvDO z9{I^Ue9QeDY8_oJsjpV@aB2E&MQztoGW6cW1`XOXOr_^tzQ8l)~l2 zN-y7HaXmB)ewD(dc`#ZbATTt9A#W-W0ztChuuLhP|A;o_JO;0&143fNPUC)> z$psy;q+5DHo;U-_fFZsStzxvXIiLH_r;T&a32qi2zqVd4f=6uF953!M8$rm&aA^PN zcG+1Y(}-)Ez-QVVASu>Zk@$l>xj!o2lZeQjr z_S4B0mXd@EFSGa6xz1qf?8Buc)ca}hHI31zB89}C^H2nF`U#U&&q!=uUY;w!^)u5& zL4iJT+j;4L#Lf%aB%X>^hw>_&vG_>N=iy%JOLk{i}Qgx#w7z2oz35fM3nzV9IY3i*pBC4-8B zf+7)AcjxjcR1dN4Hj6N7g*U+wp!#zJ%_2exCZ!{%bYuiVl;FL9slgD4=#$M8L`*L5 z0_7j{0*bh_!%;x_C4CI)fYYD{{rLC>34n3yeAXnt0rKFR`bYVpID)E^RAC;?+M2g~ zns`nyhf0KYUE|{<6yO>(<|}#?6U(iNG9dD%D+5D}vH%V5hSt(vK3P%a z6QzfZ4MwbxB9SffehL2G%YbZoWfSl87w-d#g*(y&3BvegkI_X~k9FH+fV`E@ZQc{c zuBnW3vwAAiE5zlwCg)|9c4jEe{1AY(aTNKyZBoP{WI9B4-pr{IZCM z0tFwhcKRPyL2S5*v8)4~T4|cgFOynSYVZqmx^X)s-X{L4^2qef@2juUW$8irIN?b8 zj28t%PWRFCuUJ~3Y}DA1^$(0R;o!&bGI;C~pCZ4$1(1urxS}+;&NB3E6Q9C%FU$>B z-Cc0tLFOh;nl)eoIG`|59?3o^p6I3sc^eu1iF;uEbzUV755di?_7`c4HXX62{wT#Yq<%0)pE9ZmXvH zVn#}H@;%{CfMi-FNylba#y~eEbxLexxJ;RKW-(bf<^8yq5RrO$6}~&W$oR4w7*zZ9 zgZCO5`I|zjM#z=BD}S#TufD6X@vrEN<+SK`67IIS@xNZ`yfxQPD-EwI|JLeuLYj4I zSEKrWE?_)HTN!x?Ud6wXEuo6lg#|`NCXe`}B)3zbNvtL(CuexRg7+y#y`hewOg0Ww zD%R%hJ)UFzED{_fF#x=MhrZEHNZoh65=@mxeR>#c5?A8sX&MsB zfr;q~GEvSd_ioU1yr}=knPZd0-_&?sT)e@`kwjgpbGNGdpO0_#zNF8cZ8$nxw2ZYC zY1AwAT^13G*z@fcaZGC)oAz(w{1TsOTaY3&o$K>X@O)q&rvdTrZsV7zN?GgcB|z{l zyFJN~k#Crtg(=w=^W`-99yJ%I_sm@k)6;mTGE?fVQ+AfgqJ$hbadHmN*6W$o%d~-!nq*ZWnir059rHW)k#>}1> zK71UCWRQhoZwXUU4wYRe3KF+oedzD)Srb2=ct?sUKaeh4bljs-f0(Q$0C%BXdXj^$sV$vdS)3nV7;u5gPw(u` zmZ*Vh=yNA7A&jw*Tl>u}gU*|d>NO8c5#yERXqMY!*RQrtUn7}5U5g8L05-OGd??2q zQ7pIKrxMGx?IJ-kUwqB=4GbRNP}z@NkB5)uYu1h|qj~9$HEe5K|jo0;g#v|I*5Hk4Oh%Yisdy+fn*$3%$*HV*5QYWzsAfeupiHBua}cY%N(=i;o_38u;7dNvCZ@QO;~LeQAPMK44~n~)awDH0H{|E z-@J(B{};_*e?jqq@XZHzKg^F=s>8LgYy77OUNl+*CFET%BTt_lamYkQPyOwxR?gx6 z;!0?d98M>y?Z#btw+2vTyq{`PO(FVA;`YxA=o(T%SIZJ*C>|(WncK`6)0aRQVwPik z$^4EP~Qg>zBoTW?bz7^G=wL?^hsYSq#)a}U0<7> zB{_p5CRnZ^{HRMt)O;UX9BMu@s{hx6kG2G}-~ZX~Z{R&WL`T)MW*$=gcYHt(dJDPV zn&)D=`Brlgxq^X-8Di_Iv>(M;^-uq~vttig1nXL75xGFX3|v^JK4yF)iu3z()S;x!@qWp@=IBb~@&ykHRlhlM z=X1qqP{cOob!PI&j?wvM`eJUj&-A+4(!4U;M<*FV&ppuJ@8=np82e@UBX#~)LP!W{ z-_7S$Ir}`0%1Vv7FxlUzF%c0>hLNQD6}b8B0xw>?01_&+U-O>z=m2N8uW6z<*E@ag zPfr76Wo+07$6PB9rAR5@1tH`CANO_%0`A-L7p<82Y81}=!2@<-vB|~7Y}97^#QzMhedXD)YVA~of*w(?qD^H#yy1_WA9=AI}SE@vR#z; z{B?RS&ooi%_(Hj!iOcZIo&Ut6J(nJuJRlJZB*mGa2{XU^)dAAiT_FyDqV#NpJG!_u z)HdivI(GBzSFbC7{+tbVF`ZzJvNAW1r0XQhDTORtU43QtgYrAL{_IRbJLiVah?w7= zO{}Q$t_>Jhr22MRc=#1p##zQvbhcCej@$oP@TIyZDKMGm+`~j_Q(E#1JGP(5?&z&N zK*cn}%c~5EnL$_Sf{pn8Vq+Qi&J~9o#=VtK2Cw^JyU5A)KNWG5UT9;Q@s3@8XfxiL zNMHh|h}#*qI_h@Ss_5#wj()whT3LZ|n2~km_e~I53OnumR|EeO*fR&-Qu@z)Z{NdH z5m^bfwP9DN2!+goNd*{+Ixr9Kwxieqp=)9b3kxT5@@5Sjo3F*!&dv_Jq_dooTO4n(QZux2~6zP ztxQ$ftAaubJXY#bGlJfGN0e^0-`touC)`%EyszK#Z8;(ys$4`16&yA?$Z0w|#7H#X z)yB4wXs0L8xq8I2_}FFs-PidRes$@|Xs3OeT>JOXQjc<~iLgCfzCh{*ndqniHON~}id)!rbCa-OJ7c2+lY zNtQW{XuJ91KT1~tSvr`ZA#l;CQ5vImZD91T@R)fnkeZ@Vo6aw>hNhyiOQ^5%22erUtuGD^J=zMdp7nHkeuW|1;PSMJupR zC;TNEQ;NkQ6s5WK>J87qOWdMo2t=Kqf`cZ-*_Q9L{;F4nY%W#f;!RREM!?6mkPxe& zg5=RaE!!1Q(ZlTZJfM$*M#d zwb9ydGp|z0MR*n`$an7Vpev^m?&*xVYRHb?X?6Vg%OZ( zEK4X7;yW4DO!+1@v0{#CYvZu!$s;=JdadK%oe-0Dx48QsXQ&9?9v$)l)kFC)@M>23 zD3QG2?#ra)WNUTR+4lC^$E7sRX?Lq!_~vVH9x>pHc|~*?t;nQZtyXG$H-KmHI8Gj(M zp#U-}67tUrCLLPDoL_ppz(B`fyX-{GV0+y`l_I2u)ZRj;h(J+nN&=AUYcU4qAxj4b zhg7uv#Eug1r0^9S7L^pns;|P&_Ksg%K28a#brWbDq8=eZbAL}(F0M(7!o+sEIH}{E zc_Fpt_K}_47!^gOtU#GZBp&*(waC>8TxG^S2U=yZK7%8XML?Roq1wkhQ-bIA%8cP! zzvNbb-kQr1Ge5Mzmyn1)eoZRqqYakcYtPFYxthL=eHFSq(cT7yau9NbmY7=( z4D@m1mlgu1LW)v+*BrCdO7C&35Q^OexlDLpST7RqL0R5d z?sWGRPVPA37{0OiA>3Y7^WA)};3#6zr65Kw8pj9~{Q_oPk z%ESEj;WzO#my4|Q#9Vs<6z#4{D?EQBf%>< zDC-fjS!Zly2dJP}1W`!6m))O;Z7#+femgDEyzy(1NvwLd-tu_|HOj~v=n#7LrS}zG-jBGW?u_n08n6_lJ)$p-RVy_&_M-Kz)B znbXkYmZmZCBGoS5AE}EGF=v)^9@Ht{3za=dlv*ltdjX!JnM7XP+v67dLAECyT(=T-x`c~EcP4>K%8NXs>dsVDa zUB>#VgdN3~dUmx~slX`|7n?S?Wwg#%qh8mv@{dIhTt)n0gRN-ha9?K|X3t zUxxz?J6;F;qV)6sq^;d@oYyBDuD-Q&k?zu(^GlRDNi zGc`-=Jl0A?BgG^?>LegAJyjiyrO*3Y$==m`_kTo=x(ru$nqN@z=-@m$wei&?HCBX{ z9|3WP>rwpV1bAy945vFOti1J)n)W%#nYsrf(uhYQ-`oX2BNw;orVPWe1-Cb@#gw+i`9Spb_Pz~2h(t{vgWrqJU@Hg zZ*(%Zabx!l577CT{VTFVqIC(OO!CXuX6k?xRyAGSqk0r#eQr*##r~aL_TE^_eenKU zM-qvl@lP^RO@035cUj0bwUV;3qg>#hHg)~Ej*bTZJ2vn2!Q1V{n&{CS>%YXF`)29y z(#!piUZ!pe_OVH*&r=T1(%1r8WkZ9cf@Gc~}{n;!1J1HrN z@R&{>%n}?-jMmjAl$XEWN_7StMNn>fV_HAsAOj-sMAq!fS0i*``q2Pn&-Y)9+B1^6 zoWvf?ZoP6bC@$q%_zKt*S=Sd-9;-ZiGMHE*8%W?|kLRxB6;0A;kK&?)Hh)UfLX}Yt zEaSO6d-D0#;UeTcUv=*thF^i`{6r~&6;-@3!~va;GV+W}tNa=PAL)14g! z0e=3yKT1|MsRz0>;K`py$w+PKdgcc|vNy%kWVEV9B;0GOEa_Q{cTI9jl@*+stO&nf z$j`6s-^OkC@gXA>$mB9*r6MORo4ZA_EaFPndm8BccSrgaF4KX?dJ57pfVH(_I3oS& z-dUMlzw0E8%sNs8Mz|D-Lc;I-PByNm*@zTnAPny#&Qfd2ggtT|0~wM^K9no*Zt9VR zOKN$oDx7k?pW@r z@=HoW322zQ*0V&sZ%V_OZZQOkGo-E?VNkP_2+8Dp3uFW4uJf>rmX_8S1Oh>$O{O9+ zwiX^c+8HuBN{n>iay$F=aqBs>{?tpdrZC5=+25~@TF$!5s3~}B(ay}(%3^SE@Vl_E zXRsa@vV)_Gfn@me|LjY>i@ELxyX^NeTW93)venc_AwiVZrtx_X&uOl-%8>=o?qRn z8DO11l4egtlyZ4dU(0OKz{GISA3X=F^35Eb7O8TK(T}!8D^f`b8WBS0eskS#^gP(ZuKy|c7hx0|Sy7RI zhrcge_4Ub9%uQt2HzV6AVI2(-zpJE^FRl0Vs$h#x6MwO0x}{Z@PiC{u?fq6mu;IvP z;SCOQQ{-RI%(O&CG|9-?9OV3{_N^ZMFG=>|S+*TkY(}N-R)G&EUY1zv=+FkV`yZFN$`NW#LpI>StsEItb4^Q7f&&`F0N*dDVQqJBbz&zM;qpO)cq< z3@Q4r8jz!+R)vT2a8?%)YFWsGIMM)h4<5udUm_d1JKiG|4rSX1}M2kf+V7^Q}8}(%?S0$YI=n=sDi; z|C9fxE#lBk+KJ?*J|dzr_ir_qjx@S~las>QEqo`5{IOgC@NiRWaEJ4#XOYLe24@O8 zO@zH>B5-KiQWt{5RcM~OvscG2tT>EGOso?xx{TYnKtWPz$);(IRFeG+>h5P zIJ5lj(%g)EjR%|j0NZu1=dq@euA%OS-t`4$ucC zsmJ+t_&siQyV)ieb>~6;s8*D{IP~P4gf_!(ds^)L`FxJggBsCtqP*x!wC;2KNJ;J4 zJH{s^>>oPLQYb!2MJ7<{N;RX}IyQgt=BOhpn)%}-^hYQ5>>HY1efpiB4zs0gkBSf`- z(Za2j0suM32l-z9x}9Ki5O#$PtND}0T}=9Pt1yACe=2r?RrrYIHZE zosV@4HuO1|AT(TQIvZiD?s)I>|KHTsaRj!xs}_bd#B4T}z*}nIXDv0p>lxlQQosr9 zF~CF8ueX14&ExUjp<}Dc0hXYGd|lfd?4J4EleIDScZ?nq#a(lJd z5WcdQE#SGVKnOTM!9JTFYw)G)gf8Dni4@@aM(z30BWl#X^LAm-(4uSih*HqNYjYm} zcBhTtj-D4MHNYWPsQ>M4b=0}pMUs@Izlaw!ujct8LJ9%RiN=$F1SD*_Z?I|m?q49_ ze%eN`1S3i4Mv1_2$s@?F`OkVixDX`j*uI=K-W3B>2JAmo)A&!Ggf_34sTlx}0`2Wj zy7m|0M(|_p46cq#t|*&kgU7HK!1uu?r^3DyYbj#`I9E5nm52~=7&`X35mM`XLXM7k z!(J=lqwRZ|tOq|W&d{pBk|G>}ay&Uw`@nCR=$@qOhd{ewM!v^pgyQ~vZ{MAtoII7R z76W&iIl!rTHQHJ|xQ#5Q>&n8R9Jc2FFpcH!bQaBL^qd~x!tiP5OsM9tN>cn1x_Z9s zja(srH}8`T?M;uz*Ew9aqQd^yDTrMm;HIeL!e{o;%uMR}_Vq;b?qH16-KCvXRgGka zHTU(phd8VtFsBW^X9G7K4?hWw&hnlCl$bhiT?U#~rEbS@7Y&g!H6YO*9cH^X>Wfkf zu%YlL&cPh1wxcZ!p^N9M7~ol(P{QdU)JXCuy=4=+HFl*?<8=xL`FEGK;%ebrb~*LW zItV{Lmuy}FcbPZ63SCaO6$_L#&=Kt}-e!-B0+6>UV)MUs$(ZNqTPCTe2|^$X&%sxR zPS=j{I?3a9&8xq2@uuT&gEAX&SP}rjE&7fFTPj8m`@4wm;umcR zpgXv%_64l3i!vH^P)67Rw8ED!{EqN9K`<;b(8-CB)FSenFKvHQL{$l<@@dRu`x)gV zd`IQNt9v9Z1-94#Y6T--;4Q0-Hj9kwiS`RgaDu~A26$5PX>3vcGj-cdoI>N%Cez#= z0z5UpXaqpDkw%D(P{MVEP3xlVhH|9^zVAlUz8#X#<ADQ& z@-2MmitIdst-@gg1whu`+qRQs{=umVe^JP>gpb3<7jENeCiSlt z31c>$5FiAwmz`3h|CkL4J)Q(zPl$!RtMfA7<3n1S8pQQ<4E&+u!Z#QigB-lWRt+C0 z0-p2LyZ`-T@mP0TG}~;ulCwI0_=jk+KbD@Fy&k7L(cTb+Plb~(c@^k|-21|!dou{^ zf&M6vM6KJ&!iJ59{#CU{RHn~)4i#)%ool(%2e_{=e14V!G~qxN0Dm-h^S(?*OS#x^ zeU7Q_yj!V3>`K{7_zD9XUf`&+RgYyXsfTnD!cL~^JHIE+_TzFXiT%deHbGnAvlW{f z*rY=B2JC1hf$Vwx3TUrx9Xy2V2~~Go3^+t?I-NNHJ~uZFT#~RQJ}DY%8pN!+3mKqa zE_FFgBjGrF@o+Dx?I#jJ0UH|H=kh!4)-!x+--Mm# z*tc-D-9SbGnew*-D+qXu9+#J_;FHYE*6Jo4y4Z0bp!dhk$8(lW>N~LOrAIwnxn99s z10T!wFwFCFd&b)@PjNs*uuVvm0A^fGYa4___&c&O9akVN$%o@f;OstT^Z6lsKsrGj zA=Exm_d~NHd0F;C--+5vRk@_d1yl&kh4Q=! zMn39o4x*l5N>_2A*{ve@YO2+rc=IZTLb?e$w?38-OvuTTdbSTwS!$=*&ZY<8+E84v@-Nv z{=4K2l#oF72$zd5;k6r&8_$i-_3%qhkF`C!J}bo|BK#1tT~dsQr|Z#sDfW@sd5jP7 zwH3IL-@Hz8d$Z4JqZC)-rnBQX{xz`&u3y=UX%U%3)~0W_U|!Iv0(6C6qj~4*J9MCG zGtXoyr01>J$x8zB*cH_h+CQhv;WewTIuT_xLYp98L~p+MVDxR}3xQ5iY;NZxiMapJ z-j)+LzG3@;E()R9xvfU!? z?1K(|4hv{yredW*R9HXt#1(`_U-!S95tkJjEwGq{7&%D%4yT?soNMxdGpr4@F^D^)Kgu(aaqe%G-B^~nFCQUfe=V-*RZ#C{dIxzkSa zBWU>#`rhCdx#LoU{u`KbIi33Jnvyuf>c4@sIYczhPBL1#1w};l45IOvq{-2hSl{F- z6{-^A8o2}TG+a5X2%XERwp+o(9F$)isDrM5%3HRhz7fDShzhAK6P41bKmtulUTr&U%X)GEh!1Kd*)Xj_`Ve-HU>x_bNcuq`bj z4~tgSwoGKYJ}rnrh>o}lSk*G_rDnxYR{0Hs!68x=dWH)W1*pM?xeLqy7i6l5=|Jzq z7IQF|BXk1p5cg#t%Yp7FhWHKTQb7tQ#X}a%08=+L0&u=JJb5^qnSYiGx>413>(a2Z z(W1b1bki*X1=_Y6zM|EyGziYXij2Ehcaqcv!Bx2-p+Y7*2VNaV27(x=yF|&j6cDFy zw-Z?uhO1&>qOPMhg?#5&H6-#o$EtyxZ--UeUlVf4EZI4R+$b|h%iK7BUW{;JoDbXN z!d7^&0oQem;TC79Vt+k#V5O4eZs!&%X@)dgr`pv2o7jIvXv2bT%+CUBV*jnr_w`2Y zzk&W`|No*qbFly13IZ;4%E$%VeX#(zt2lM8g*b_b6TW{C$b7v7)P2nLST?KzG(wXj z`cZB}F4&+{PAW#{qx82}V$=~C&h0^MRkR{HNNri3l)RVD^ncKjYD%aBZQHSIM~5!? zEjDiG1`OLksUp)=TO*ZJA!sT@G>ob>FmKec4n4PGIr>o=I?xsh8&&TdDo4h*w2Hu@ zqqTv*`LiCh^?>c$LS0JD*0F|x>v(ih5%hT&X)Hj4D}Qf5$Dm*BKTFLFgK1a?t_6w} zRGdmFJq=kMT6ZfEt%o$jF|-y;SM*{<#5`aCO#n5G zT8Gd8%CXs51pq$~Ma}S_5CWEt<-Q>X5ICrej_f2hI?zq*BB%kYL=0cDilo5+W@kYG z6`_X_Ykyfc%an`AxTg?{Vi9F^6TG=!?I-ipGh6}zfI!hr7da(jMiY#bEYH*wfE>qi z)XbVSdn`~uz(G~3hBPo;L5zQk(1nIoUX4LjH}$G#CQ)O}nika$&$cbc#S*L`UY0PU z9P6$f=*_+H!t9y@Z=bzz&Ft(d1$2kd17?70O@Fu!!31|ykaj5hG~%`sZO<$}?LAHG zf6Br0+5275-2U&+4@CBV^Bem6mh=BD%F~+tPnVEA702?*6(-e~5cBM^12rNeJWT#& zE>0U_Oe5m>));Ur&;_JPDjW-ll~XgBy%?6!AoKXvprLD2AJ|Gd=H7-lx9!wLXhXN6x|S-S>g`p4f>F^yuK!~ftRe*{B^?o2v7YXNY0F&g0=ME= z(_#T8{c?14p)~N#Mp1Z;$p5s8!pLztI0Te~=GgGW#QxpmTPDEP@$uc`gWzqJ$L6E$ST$Wkpl*2%D1Ukm z#X>NDBa@uyEDrBnN$+%s>#L!c%0UxEpIw%Vm~cQfWCB=nkpmn=6gOxXbnI(^WoV%2 zAPt$W4h;;duud4jL`Y*wpIbq7@pcN?L>~nZMpLs4uZlp?fO-{o1nhG>$E_d- z=w``ss*F2}&?Nm^1sb@k0qFW+xPO{e#GxSDGBS|^jh>1%opY@o*Ri~UfpEpL+*}12 zRTe#$(=qlC?&%5!pJVKoo37{v%K3ER!MW1eBKT3EP*vJKeP4vI&Z)>n*E`8K~c{aar);Og)mWh*Qm zf=W^{rT2s>DR=~@QC^cdkjEv;EG6S8=f{-9dKd!Gwh7%rZ`DLb41fQX33bf|6{^O+ z*oy>+UIN{6P>$40meM1Nmca<5p^j-UIet2e#&t&E2!YW#{zt@!gf0;}+|nlMuvont zFnMfdbez>AMqv~7PJpL5lk=~_up=^A{0RQ;3Q2f*MSKV+bwWygS!UUz{5@f z1*kIqM2J~-sZ6s)AAimgnye>UUF-PMO#kP*>GLuGn&|(1fAyQC;K_~RFMB!Y;cO{?yD1)neG6M5y!WS zqz(ANp(Z=zNq><*K`gaoyI2nBMu$U0uYL1ZTiREgO6*85VTc4@AF< z?kKCqJDedbmatMbw(7=M+=A;6HGoGQ5II0p#yxc#0e`xmLHL>PUL&mq!60_J$9O9W zTf>{NY`mJpXx#~+9vj;Z^@zoKl%Ro8;#9R$Z>QHff?XBo>>Iz`{_@; zI^mT{`VpYy;u;eJa>PNzlwnE3D3}Ch5m5;-3u7(R1JKzT)@%TLL5XjAfo>k4SK;UfVNEst7i5i);cZkl0FFJ*bi^T zR(}=ARyjox)xt3#im#zpb#8>Z6&-_aj;bxYCP-Oo3EQZcRWqX{5evc^@dJ1z-0OjX zOYu%abP4br+Qv911;dOZ9R(2|eO`$k1c?=B3GcFkzRKh~f-Uo_1gDP<)=GHk^kEIX zZ5zNS7lvA6{kFqw%OMg3)1o|WtpC3ImoWtw z;SKyXf_az>=U!alP@UlMtx3Cx;W9ws@|TD;CcYG)RO|lFMh@OcQ#r6T^rFX)J>6}y z6DQ0^N}yqDAd+3cB8q^%m(nDHvR*@`P%Au)9G*hKU-_iND5Qv3Q7jXwVAwFMX@ATP zRJy#9#k_+eHn#hahh6SG_K}~ZRSK{;H4PmtaKP(^?$%Wb!CAUlvgVf>wM&ej^-QrE zBZwTu8(@;<5v1d{OruVg#c2d8uttVaLk={eIK^bmlFukFv_Ct{qp_7g=KYImCSk9& zucRa(DAe>&bnWI^LcCs^+G36$w||QAeV~}ooz$4;Iq+Pv`lhU=2$F6cQ4HR&74P zDK&jAB@GM?u^exqiJLHQ!dZM`Gbdal9M%wTk@UC|+O`N3lp-$(EJHvyHGg!ZQLR-z z(CNVwO{be^qWNs|4{=xyaFFZhsD=n{(Q^uhgP>LiMQWdFEzQc{$OQAMO53}k11~uy zUn8>+DE!2NwlAFXCwhh^pKz|GPsswsKxWykC?MZUX=o7|(p?&$P=4jzgnl>NK<1M_ z#<3t5V%gP(PMGg-N;PX>sjWJLe zO+b$BF$VIIz|6kzk(N1cYQTY}W>tN}v1S-KK@M!TECWF^+|>RGqJO70Tnj)=1Gru- zSj<1)LeoAwBq=%(dNBV770vYg42HTEWU*(;jqrtFufY9h&CV!+T+4@)(x;j)3|9Fp zH#h_oMF@;l0-nh0VEEB&Z2kvPR5Z*fCza3l0+mzRFU)y#j91#u#Bx-2c&=_>wT#^D zsD6%PRS74{Sx2z~)PD%OOOrNG(bBr5bsBa|OOUR&OG*V5O^IV@*gF>)M7uOBYs#~M zQX}F@=q9Tgm4ugN$}>>#DA6f!>p z3hM`uS(J0o9h34WN%72)AWdY#f`K$SG9h5%A(?a2q6=4v9Djmi(v*mv(M+bYSh6@( z{NtGveTo1>kswN73^~#@3JN`FHK$Xi@loaCwAq(%M3Ei+Oa?^KhB|fBG#!@2Im954 z*n!LZ2>B;m#~(|#VND|kbQ8HgY}geD^4To=bC*{|j$Q=$Ea>)ZJ6>vrpV+)8l&DYU zZCV}|bv-8e(tj$TGCDHOwgiR^V~6fiJ6Jh*aKD5Npu9x^Gh}(dt^?M!+IXPjQ7w;S zA}A4>a=7A^N(M@te91}DVgo0L+T~Sa;5BG6IczAToZ2$WriIGW!>M#Zhro7FO}9KO zt>Sz}3JsO2)3_D=l$C6zm7Xw_u)`{X7;SE`7N_L|B7aNkY3BcTEeDp-g2sR6^XudB z-^>30#d+F4|0$nQnqce!Mhu7(&l?H;DUt%gAtV2Iei0@6;-mtt9tMqc6_`5w1BH<~ zeWb?K(8q+6n^A8LKNJ+JCTC#|_c+wJQbQLhm7wujB4!mGrf%R+k!-}RBvw|r3=4Wb zs2o(}bAMLyYTv9bQ!kPsOC8O!h+le76Zsz;?V865&_w-Lwu1B zl_q76maBC0I>gR;8>|}H&m3S28-M>f&>Nlq`3?Dj4a@U?F`hQ&KRe8$ zn=BWnZkg11UM5zyuz9&pKV1Sae&VjiGIII6Z)|Lfq-Xpst&kvZii^hEL;gkM@Zw{&<2czxe<=_zD zfAUgcE|ZH!i9EM0L^W|+C>z?*lYiJD5-_5sY}BQB*ZHIaOGE!$eopMuME{?Lj;WjF z`I!Js{lC32|L^+#<@>)E|&lH*(==MDmiU>MXfRxZL%X11vv-i!g9olnrQv*uQIe1VzYk$=YuE4%^ z>jxEZ3c!6FH*M}0dk zG_@S>B}aP6NhLFq?_zoJ_IbF;3guW-(GC>Qx$=I=qPgoVJ}9`n1f3Ck(Qd7LUol@ zinJsm`Q#YCz$yyjmm__KlMqt1g1Qr;G5<9Clo&6|=o3B&5DTcoQLj`x!HBWZq(&kp z@TSrXu)x6;|CSt9n16bOZ2}ioJ;T-Q*mW49-GsW(CG|Pz`=xHdsn$86Oe(ZEXdjB0QhD!BEL~orKqMa6~Ao~E*DSsjc)&Tb*XCe`9DG}C5 zuI%~ZU7TKF^ll61vZNOZg0BkjoN7yc_Q`{2Li6Y>OCo3ZOKY)}ZRr11=;%-@wC@UP zqW^DL7mfex%Wqh||9f$sx#<5p2_tOT+;Qz+FxZmO{l!32HGg{gZGKw6=wo4Y{sfe^ zrSXgUygBH(m47)a{gJkkRetCcE4qv5U7xK0Bo&Xg^45T(Z{<>-X=H^S|`s2tp^de=EwBf`{#9KWvCQ+0Ksb*2AV7h6< zSs+I!*kS7^1VMN-6iAs5=5ppR#!pEWQaJ8SPM{xxA%7c>U+%OKDli>Ka!1Y3XgIYz ze3lPiD7q|BLg?n@}&0uu(c76462Fg3>5ABrL0$^zFhTfT#9eJgO!!I&4# zCbTyfL%zjkI&8*^L9{{lIhyckt<2Ma7tJnl^IaCF?aZ-|&bENY`vOk4&=BS`&*T-U zor#rFuYbdi88Uy{plqN;KPRagfZv3ovXo4snEZZ;A8~ER|6`eDtMmS!d~bhj|2My3 z`TXbNJah8@5JuRtxqCd@c^44pv8Cez3dWl51!6$Y(+?DMv_P()IBMH-1@ZbFaRr6j zN^u1>cHo4YNO9mabtgpzmF`YjYObIy(1itvqkr`^{(7-oNfSuK_Q#z_>|4{8hCR2k zHQ*Jg9iJ~!98mQ2)^s*&$CV;O(Zoz`-|xk|4{{Gn(jms>*dKsHj8%~5(0qFJ+iC8G zBa9Onas-xz_r^t*t0m=)!^myH85c;MW^OoMvIVAR<#QOhIX_ou2YqiGkY%r1tGYzz zynk*~vnq7NU~B>Ixp)J3v(Ig>8y`d)bf2r&Ev1$Ddfj-lOWf<$vTr6$L0(ATOh=8F z)Dbju&q&j04(^!+b%i#vH=ZL-vqnRhkMLV~SLlg$wk*M?4ga5QVYloceAsBy1=z&@ zmtVJGef0dtx`E~VKa29r#s4?P7-8c49e*A7|4BTyWL$s&OzAGbpv?TdfKp!z;{{Ac za9fT*sfl?W14(Ep(G%z!w|;rq7H-}u(Hz8E9C+xO^dSXJH1IJc_m&t&rJlgxsbtip zyAk5W(@p3E=I_uUlQlxmC3WHJTp5cX0ebP**;17x=wJk*f;TB5+h27eMY z9@$cIZp=-;*HBT{ke^zb-ynqm&j!ljY_zDwna#sU6)8+Z>2{`2J!h42;#;GIEA>_! znly-C>?5GnXhIj=Dk7y*SB=Ia2y6HeT|6aeYGNs=ABjB~r_d{Kn%3gkcVx## znCd6Yztwz+Y|rD-ygg|pV~9$<(|@83290*od|xEl2tK z(Qd;Xc8f_vY?EW=<{WF#&^-NPGO?Z;F0z=;*Cq*4^u`7B({xt%-L3iYWw8%J=q=1fW(^~Ng=y2lDgyS&H+di**D5KX`Cx@cN!#Fh^%dW|`P~|%q znU6M{GwyLp2@xl~iqi-40)F;Ci#|5;qI;Lr)FYW1MW_4tmHAekN1r?`)D?TZ{ zDg3m>)mUH@Go4KcX@52+K{wY6z@{OPAIP>$iA2?69{iu!o_u~mDjknjwrN^RSb4_T~hb*jP>sWUCKuC|KO($`(Ix5+VTQ4%m2H+zc(8H zwSJ&~+5TUQXD;SHw}(j?YUvkH+}LNzJ1tLV{fK3jdVA@;!hcbH(7*13zEaYReLvQL z>rc7fUamu@^p@{zZ+XABR`kI%HIQ9+l8Bq6A;d2~iI4%I1B`l8lh)d=M|3#`2qhf1Jxq&ifR`;{*4?rA;28o&RkS^umU9~%cogDy<& zB0Vgk1*Jb&$A8#eF{bcFB6diu^~lZleo=Y>hBQ9OlT1cvQ}d*hevf_Axf69- z&h?6>V8*2#@nrh87?|XwQWV+oq$+`Bloc7-q&M-+@PArt8(hAvkW2@@l!c0vkvrl! z4l)C;q7u6d6`GnaIYRg8#d>P%T12US6pX;Y0eb>ly2y$!)*d`)9yCR;;u-j$nP3K` zT<54}Q{uqF?g7?3z0@rx*8B@vpr(PiWKKkfItCFO(iB;z#0MdrFQ~> zF-$BCqkkt!|5q!>sOn|Ya!^P5Xrll3uIr1O|H!ZFTfcn&$D%x4U<|rMQqjv?8PUnI zV}gRG8yb<~HY`rTGQw)63+$=r7+}w~Eyu+GSCC=QkQh*fZn2`9<+Z>;26XirUp9mH z(9|+rz(i#hMBUB&7CcxLydkTC-KJ3omPu<8kbi)U9AM}sQZwq7iHj!4BA4j`Ba}1QW!>$e|1$71YT>BUL;n>oD&-#XkN6YU%$}g30xV8>Hnn|lW{rxc?aUgr z0H-o*RJUqp)?A$F0{ft&TOJ0ZTejkiYCF~;RCF_{t|8dN$~o4dj9SA*OG7=+A(utc z{C^+cI=p4)R<){isE@|;e_dbyK=l6Sfq}l|``;Gj=>nVCyKrdSmS+=@!Wa!0R#`8C z0&=Gj5jY$WR!_}jy1Kxg9dFt)p25`t!kaAMnE|i8HNS+TYrwB zDGZ3NE--4k{zY(^3>DH$5wRVsrfUcTC~z*Edt_WTaxj>#=*0>sLX)UKbZ>y3gQy|H zvVn=FIX(Clbd(!n^v{Y#0#u<1%g9kPnav?`hB}}U|G;*yfS_&TptULfhLVG^jD~E( zs#l3}NR(C9JpI!u0m_*ptbN@CMSsJ?E^@HSmMQv`p`ijXC=ecV5hgYU-N~^@69)vC z1RBRgF2Z0exKwZ4GhMxk!XVm?rK!5rlLg(Iw~viyRj`FZ3CLgmo#>uxRjEOPHZCIgARK`}$ubOUnq41QFxY**Z2LrT0<1yZpx?OR$7eEU5gPwe zv}{BTLrpK05LMbSDh7~tf#Fg~H+5GhaLy2*$SSUD$Rr3r4v?Q2um$0wqf;vpwEWC~ ztw(Hj+v2Ecdv5aznVDSUr+?Y^PF0)9%z#NgAQQSM;aDZ|oiF8+;h}Q66S?R@hlqGd28#{nZnjDm4V_3v zaVAMG`Ip^F?E@WC&jUtoRwW#wPO`-eh%3NTp$t|N)WKac^m_;S%%vVh{R;pXof_dAo z_Mg=$D5;>|>Nu9umWW?)>E5ZQZEdZ!R@+!-7JP~6)Uz;v%6}69Q9e^WyX-&>1;OEL zzl6xh5?X?JsJX^7~x;mYsh4d!f8a`uqLTl!>le9jF!M;utURGd{QiXZ0AGg zy}1>~ng-AW6hLYj(f63xX>=MghykR=h8k#8(GH?}?Bav8!|uPzXF*s2>{XT zBSZHmOX}$JYtz5=Wdq!VvouU54LkKRi&My?-j;1Vo&!KJ7dV#zUI-wQ%mwC*CM&JQX3p@~ zsIQ#*ynm08Q`3t`1kYHO;=dcSXpl?+ItmwQq?H4rHz8a|bEf6$#fblt*}ST5^%M-N z+|$>ae`8PYhMxS!9%$=1sW#5(W-g!0ukVqBW8HM&5#N1SL|9Cz9k76m#awh3ae0&} zZ_sgy;BYNuddNNnQ2?+C$)jp)_VBLgCM-kmoPT9*1KWibXhgSp3BoYt80i{OZeDVs z8SU664f%I60FG!J1evB3;pCsJAglAFSY1eo-8JMmx`rm3QZKwCM9Pmih{*@xSt1|n z;IIb`f^Uu3))b7m5#3s66l~6stSlXrZFqr?t0kJHG7De(8&C6juAI-o6|>E!vFMuT z(tr3ITv^+EWX5MfWZ_Beuf)-5%_Ghl(?+bov9y>8I%f3LE}z&$q)vDxday^S*8QKd zCQ40_t)coCc6W&eF;69#V3c%%`(o&uLiI@yMIR3>oI>^1dz}~h{KR@x?KzP+YBWL# zeSrgpZEa5`pwEwpwH)9e*U?c8(Kso+1b?96AgI+rk**AyD(iotAnF`Xz!b(1PZ_nB`jU6+o=cBdhksqm zfo0UWJ^B-~=yq;r|HQ0%or?$XIoBq78g_|ol`J%+0twEovEb{4-Ca`I6bBdOrad;x z*48P#ZV78}9a6oPu#zS7q-z^~HW^bx4&z7i3;Rcd=phaw7@=+kez=f_-b-Oc778C; z5&ZKl{<#`}E0$+yfPuhHuZwQh`hNyS$w7xbWV%LOR4#@LkjYh(WCbOb3Fq3quHM|? zu&`Tg9b@zs_QMvCSPc* zbSy`hVNlW?>`Fr*5YvEF$Pb@se5jVg%W~V0D$Z0TH-KrGIZ;|3MqI(3LiK!ja8#{M z8XlKg`+_rXZHI(`B@j5Ugn!re#eUijmg}gjo#S(&`(HwjELfTxMU{i0S~y(2kW3fS z%UVi`pqleJf<4Jsv$gzKF|qOeqmp6Ue$)g-h^gPL9>kffmBQ3nSV%e8Dyvx2V%e0I zQWZ=PV`iV6QsKhxE^*Ab#?rDipxH~VL*mUk>jcaEd&Rj6- z8sz_)4CW3$rH}my#N21pRw^JC#Yo_x?l|4$8^;(}CeJKTw>*Xb4#;8v5^)M98_ zAbHe;eo2>AO}0%x>3_Pij*u`;Kk53N6H7uVllG!eu?hVm326QOf%fP}6E(gWd-kS1 zJKx+x{+}Nm&(o}E++~HAEgBbwax{U@&gSuJH0H6ir8Wf>cqPUdeiA5Xh z7#J3f?9Bjxj(@(zWtLj@h0xqNTVS>K<@*q&jGS%zM03M)l+sSY4(e$21vr=_LN(bdDo zG_2#*KraPw5S*>1p}+3xwJgCbMlLNrTH0l~V-CW|bbnVfcz6I(01$K>SkC~UyNKlk zYYeGKX=T&_7C@V<5nz=9@I~l#cW^CVC`wt)WHeOpBy<;8_TCt3*jU7wBr2|`bTjlR zM7|L2Mn_x+0^KZGPL)M&viu5ICKAi*OL%+Oq{cEdi-k1`M2=hx9 z!G8+%yMKU0ejrmK(*@YjIYc~-K^Ktr9)p?1b2c}{lSp*T$^&WVQk9WF@R-S9w*5U~ zK#ZI5=C+E3S^Bd8Ko{(@46lmBK02T+tp%ec!Fx(hSqtQDcG1iaio%c6YdR)yVxZLt zLW?X{1J*4f*g_C1IVF>U#UjFZr=_80;11K0pnqyOLw7F6n>? zU>=cF`}z4Yn%@v$WMZABmZEc!YM63@5Z&}Q&ej5KRS|IYD#E0JX=u_(Sthkzi?r^r zJ!0F!Sf@ur>#SREza~@ERk9C z{3}9CltBYIE)J26=cb~rlAh7@IO1e-&OLV135q-cwoF{2%< z5>x#m(nKU%W_rfYj6d(t5!-THAT=|zs(Z>SprUKg$|8d$NkT+^PKe0Mh{$&a5%~o`M1MXR5hAVF zUU8(G2l-hbulB0FnaqLRCfH@wP_=*@kndj$`g;3%*YYe0eIh|5n1&cogM=7MCEe6< z1!=)qva;@0yaG-3MHrdqWb48%bUmE2N;$WJay-{!b}eu#ItEpE$a3UN4D4zUOoq+X z8Q+UltU$AjFiWS!@|uzFL4VdTKI5pl;95jPSdMM^f&W2@s}h2)=a8l}jitY0L+xk! z6m5mfO0EFYa1p;NJ_4Y-7#SsEVnIjaT859Zt-E)qnar9s`)Mp42Yebi2jcNP_WzztAEr-hu1G~FEvCc z%M#(y;fLGoi?_*glL5;#>RA;WI2SpnaS}n1Jdm&ev~@lx7NnG=HgFM|gr_u6wJ4SX z%a=KY2zDpsWF#yaERzF!2^N@6#50^t#$c-Tt0AyT@NiETFP)>n<~)pYMTim3@>#+^nPo;iF$UKHwSK}Zdoe0`1~7DU3Nv01 zJ(C_o`7>S5wN4xz8o0+n*fMG;M}X_2|Mur>3%j`h5Ju-7sl8T4l2Du;L1raTj*Nl! nm#g*VT#Ntge=a5DU4E9Ir04$+00960MQ|b(0O$q)vRevQ delta 62112 zcmV)eK&HQ~hy|^P1&}>|d)qjYI110-{uEdxJF)vUCE2;nXeaZo+je*RbmI7DJ3YUB zdio>~2}xK}1cw0aXcB+-^Wa7TAb8Qm?j&tJyVEfUR26^%PzBT_LlLHf!x_w2e*x$5 zpYGr{91e#so;?%)9S(=?fA^jZhkx38HheLB`E=I@$_A0_SK1LNcF|WD9@{rG#Q8fX*08>1Z$rIls~V7_$V@ksX{W%R!dBDR2<`0v$3mi1AT;qbpB zL^-%Q%ot98`jf0^V13wFJ8R(>u_s|5|lxPq7mrr5BK+i;frAS@^Wu~G<-hV|4aYr)0Zz^{3RH^ z7!8NLKm6kE@RRFb?ELhu1i;4izxU$l{(eRNd;aX{!}`CE-y`rno_-IL>DJbaP$rlE z7*EH4Fq!rvbiIWs!-R`tD1qacFT4qiDH3}_goU66z#|alh)YpyhWO@@#^@tv3ji~c zClO#XOu5)F!P7hw!sf21DIkDroUt6nLfXP1;^J9^sXzwC3lO0R%ws0-RA>MohGP`d z5%_c~{xs!TT{eXb-N1z;6@ZjvYy|e6KYR9nR1tr9c*e;~P$(LLh$K%Kn89lV_@ICp zf)UENXh*-}Sb(<|N^JCQhcFf!lfnj!=vkq9D!CH6}R) zltG3jc`QW7F`AGJ0mvAdrwk`k027d>(+oyv>k)VZ7hsGE5&+>+?;L@1F_>a=26-BP zL5@JpN}f`dAvg!)48bc7F`U6g_1?1rUl=2pypw-e zoncwd`|=3<7?UxK!I6-@0G`7s0x8Vk95IwpUgIoAkfL3X5QYGoK_(gE2FEcV*C@+y zgakjhjduY~!Z?pO#pXe^TQHN9-E%5`+fOAaQjUG}2pr~Fh7tzgHN-KeTi2)|b|g#A z(G*jbEq3LfXL%f7pfD@MdPXuhMTaq@RE)rX3kV8!-vZ$solJeKX=~!Mo9l*viqGP( zrb2T`0L(JzfoKw|p_Wp-mYds$WQ)&(SvBse+P{bP6fu%7X?b*lzoO^34t? zzHIABrQie1*{o>ufkWMr;5aiqvd4P_<_rDrQ#j}A+Z_x+qh?oaYK=Ktc5O%Nt%UB?5Sf9e9-1!01hjb4jA7pVVm z7zBxoZRS-(5i;IJ>?9KhC)-eMGn}YtEAT z03!KCciyT$(zUp11Y-j%`p7bPBM zo6UaZnmTc}Q(jML*hV$M`TSFcCZ(Xx6=kUu3nAUPPZ%&br30f+0!Y8uV;tzdT}!vn zI)bN-{#0qj;IvYmmu=(uJZECF<^%$maWH(E`Su^}Q~;%U9G{UGhgJ0a6G+83Z!^8i zdfUl8mR1@@Xq->Mu{Z~RRef1BCy|(1Q6@JVy|3wi?e!x{`g0sRsuj*iGKR^ObK?U* z{cQ8mkrk{t?|47*h~{Z3uBQS%$^lHGAVW0e40w%H)d`MK5aZ-ZQX;SB^sS#jeUYLN zPZj`{8?~GY`T0nSZelGwIf!rIf<6IwV$3$C;7QCy74~EopqL_mKoJwwPbQ~?on?rk zggtROIvNbFij~~QWDt>%4swdJV4C9y4Fm!@c$8)+;FF1yX&}pVPfD&C0ZEy}@mAa> zicOg6&Z)zdFLC!g>Z@^3j5N zdPNv(K|v8ErS$9F=j1kS>j;h%xh#iUu*~xtX5kDoB(Hc&63pU0IEZ6%gCZ$Q(h>MT z8B8J=lLUPLBm*BZl*Tv|z(4R+Z#L%(zWB;9msk#RHbV)2Q{S8}uC|g9<4QunW+;#s z)`6C40+Iw1oKY5JxsXS=G^VCs4+fXdlu)myun^>+MXa7rTLq{9;|mriC~ko!^cGc> zZxBR-*M)WP3wTw@v%2d*kijG(bFeoIxM~DLe&)kCoxvoZqYQ`Y8lP`V31NKuDYghL z8-iZXGiD!uxn`V9<>~;JYIXBX0wzFz)sngp0StD}P{g|lW3}y^zP&sifq%?U0x)|* zIT=z#E>uKEk}f%i@1b~_5UGyJ8M0{eO}JIzOac8FEr9+vxIzm)fI`z`8AjJA0+Wo) z-L9GRD>6Wy#E5E=ZCnoF#&FltNe&o)%#&Zob%o$bF;lkECm)N+jaH{sILu-3+7jNqEbS3 zFpcUC5BXYFe|T)k3N|0fvcBEuuz@gzMbcM2y=!J%F_neJONhGi;+iK+A_{&LGRJR9 zyKwgpU5hIjYJN%LA+Z1_E?dU>a*m;RVO_F+Wr!av$rKg>Mrz`T8E+6A0{ekvS>kS*`je|Y;=7Xc|%jzDh=GrJGEb%$OY zz5%Cd+x6_ZiYLXA)?MUX^Us*kABU2|H{RXKtfC~K3NfmDQto9RHp0aT=2F=aiXm4s3E#m^ zWEqHfAr~e^DIZg-Z9DK3Wtc=7?3ws$9e51S5y_bbcq#u}2jT?cIM2}KEJJig;t2d8 z3jixhR)9+LFhrD=P%mUbE7UE2U>A<;w>7190pOXn5qK^>S!1pX?Sa#!E}0{+C(7MH zk@YKmF4)@3q4wA1Sk!^M9FN+KJAiNH(xoAG;M1jHcI4Eh;dbOz4_t9mYL?y=x9)9% zTcx1)+S)e{rSNBOrs5g2d?(|oz7{7*QuN#dPCZ`LU_Q6kgF@}Bl4Wpz+W<@Cm1UM8 zX{{$7rV&+dr7@mk=AL-1*SB0r$;AbuvH%?TSxkNHODsYYEeaKC!B)J7K6O!@*Ui9- z{z&lR4-^@Qx?&KVT$nU+rqZCbWr7rkM_~W?i#J%6g=szld&A*eT04kNb**p7E@vd7 zTqYAbnh=uEN45!BMC*Njq6mFtgGUrGbscGc2__^9AaCwfdBhSG4HR|GZXZ>LI3*E% zQq!we=o9*5M)DL~Am)Yqq&i+ewJEf!3e>voNi`I6v**rDDYAaa6I4K4dYVkxxXWbK zV#@O5fWD(*pgfb-ga;IDD*}JVDJ%e(lV}r8!x@V57-d2mI*1v6$`Z&BD9Zgx4`<_L zW*SCwoM7HGP%qTRw~ld9zTcW`weX7(q)D}FGvnLMW-vo%8Q~J~seZZ!7rYceKyfmS5lH3t z@@*T85xYSs5jHzyqHIF-#tg7WM_YFPt3ByBX@R0BC@3noKVOGRYf|srO(tBkSO`-D z#-%6#RS`&kMOh!5sCO?s0Uz{Dv8wYyy>j_pl*xq2x8xbjq7O^Xx!TG3Y@=%|om~gFk@CYaTh~R%~dW5A1Oc*XoOqQ_vTDOM?-eK4`Fecn@Z*(f19sy3JdI2R7 z0#5hT5Zndr{C_J%@{{O{tM9|ExMKKFJ8K_`S5Ix2aAO)+ z6wh#fs!`o3$N^uV7=?^v1_v}8-%F3EarYq>HWldjpqfit6H!MfBQeU9XmM%$`_5;c zpT11Ya!Eo#xj|JOv(hv}Fghd&7u#{dD7X+Mz$~ik#p<0X)d@Zr{C@&QQWBHtB9J6; z(LxiT?x57#ee?)as5TAj;Kz$AbR%yM)uW$(hW#_&dlGFRCq8k$e3wwjFrA3U#}POp zr-WT7b*+$JDky7MA;uFFF2Wf7M95W_E2?d}Bi=i6M&?}4vF#$1OA5&VoGAS-W92P~ zjjfI*@pvZv3#iY|Qa-N5m@;8XQa(Fht2VX0NJ+F^KC7E}8Xr<+9br1O3PGx2r?K^a z&?cMLE(si=P`p(~k%?NBn*z0RyJ{L0>ebXH?Z zt9`9XRKP&Tzu0)h?WO$&ySM-JS;707@EZ2wd-!2FD$cm^ugebFsv8N%RVpR4VvB22 zTG~W3&qMt*w9P_k)bfPRp6r4rLCF7q7lktddNUNq1l*7;j(Sgi(}V4hSPc1@VJ~J_ zSS@+KUs#>7K&|akF)b0)$gW0>is7n3UF}n#GRdjjo5nU4xr%~%x!fYx^kJ*crTPp);iRXaolHQ4 zCOARSuH_geFUXyg1xVaBnYcSBoh0~nS8$G!6Ngg%qD>foUh`#*&+tcB2 zI1HZdzkKoX?`9`8@hy{rK8m-q_%h@Ad06rAbB0n^2Ta!2ZhswzKs~F8eTy$3?YvVy zuL(vEG@5{md%+mSFbPp69L)qJ$`2=uF&A#+V}F2Co25M+D;TPOc~C;lb@c zf5XB4v${dGT1y>&wPA#pJ6h|8z4@%IUU#8vjuTPm#|(z(%(AdMNf??6*up(doUuj= zFy&2@Wms_t%YbR_qtq4vjkreO>9Ec>ML7b}2JaMA#eR)fg?;tkLm_jY=JPSixJ2$j zQ23jd#ztk+5!m;F@9zFm;MuqXjHYE19xy&CzeyjMasuyv&k083yaz8BjcNmKFq$Pw zTZwu{7>#y)PZ$g9m*NX!b#DXCFuv7xFYYkDj%>ys#?z%1j~E{<8*+(hC&uR#W9;oq zdd2wh{jvOF^ysbX7~@+Lji5K>8{>z*hI5P`;9A}>evoUs$N0g14t zxyw}Hui!6JhvdOyrp6(oP>+^znJGrOgVRg{0>9Uc3H-rtrcM%HVX`{A&a@({^PTC0 z>TbPfH0{f}&sZ$I%#`1S1C8!Pvj&B|Nio%__7Gq|KvO>y)5Rr-xI zd(~Ksy`o#q*F8S%el=gNLyaE!H9cz9nn2LvQqw?VXP=rn0^6Nx8n7?vRntPlox0Vy zxa<6XYHSJMclNBQ-Elwc+8=9uYw9O&UFRATatH64^~QBg{~AqeHwT+LVS$xhYzoO^ zc^@0IBM)9S{s)H^Hyc&)e*A2#m&naJ+L)}+)z!vB&gOk>s+Si_dD|4LV-0s3-`IT9 z4mWzx*7UgXj@yIJO{34v***K*6hguZPB->{^WuiwZhQo-?04gTcQ7QV&3oSX=wHkA zrfVNocE0ga{NR1FG4C7S_};VojdzOI^S|-->TVryyuJ7WJ#hSQ!b>}`6rzjYi=_g1 zIX@N`y5q=FCA+IDiwn5bm&LH8T=LrI_w;6QyV>T>QW?;1)S<;47oSHoCX z)H=0P5PjKhElvHZ@oQ=6;e%&O#k0j7!6<+)~^%-IaGs^?|6He~WW)y}75b zzxQtdB%EFo0ISvqyMiS_kBf6xy`^%vEpKq(_b0m0*|qBZiHZbT7GLSoLVe@i^uV>S zaTZbCJb82W_WbhT^m1fm@710+oV%2N*OavEws~JLg#;syo${@-#8n=Asg$e7L}_y} zvoQx;P${lCifbM>E3`LjV$oJ+AJkb|t8>_#HZ#xzsq$xf$GA3?rbC3CL9Y&qC%t9` zPLXG`0g|0^(*e;b_htidZyHVqhnbJF1ynUPrw^9S(b)j3IbEl|deJF6&7_@wiU%-J z1~KSM~Vy2y|jL}-j*66_6wY`?ISX-JqUDr_=k=91fQW75o0us80!OoSTW3JEmj z$gGk=bBPUj#Uz>)bue|4QMabjw1!SMH3Sb|;>@Crl|0kS=5pV?KujOWRAmO&%w1IA zx~Z9=$%XWInP5qQBh$SnXIVn<-_FY-eLt7|)7(8vFbV-#P1ERv8KUcsd= z@C-5#N((%`ffvd0u@n_}V>5Anf^LfQTRc2LdxS(bOao`};^tCDxmX*X9BHPOf0xX1 zawO$s;bN=E-72mJwKJ~xTI3NGlExGzD3g+d%IJy3eXjXJ#$hN~VAsN+q?H-G=IzC6 zBTN`LIpWfeM8?4c+U>V^uMd~v~i}ixlbG9+@C9Of%G1HflIbu-x>JA z8P_IfU~`_Abfommch!+{{~PzDEXHqDS4!WiX@L$& z+YwYCFK0(k0q+=p5}5V_wz|{FnxFz+7o4@AxiBwn3pL}g%nMiQ05Skg$Mf~3|;qJrtm zwvuSRPQo4fu67ay0e5C7k;ol?c;z6VZ`llGro}e@dMY^{ zsLjn1nzq(mL+YP0h9E}5h+s<-Do-iF39LVic`2q5o2uYG4^Fiq!GnDAZPJw9`kR)D6KPwTyP&!6u848&Vue|?P z1Zm@0<&{u>+7p;|-BieONWAipq%R5Jg7vOZOMvFkQf872CYj*-h1xwN@a+nj5u!{p zBd21gUtETpgH;IhwX?^?#FJ#2@m?K7krGC+D#>yc#F68+rqlJ5Faa4pD?Z1P)b<$> zrM%mfYSD#ZL~D4TNGC4KnAZ9#Yh)xwBMvxWNZXNrECKuYBR{CA*hTyZgySm5;`f|r)u_2FW!{n z1YSFK>0G(yTRCzipk1(>k;p`JMxu%l{1V87t5TJIbwbx56<;4c;<)v_ z#o9-Ipp^E7M`>|2q{{fgm%6Cz!>{tWuWZw#jSfcQonH(9^pH(wB#$E_2S#x}BmUH9 zAwN*QKRB%Paw{9d(1{;3hG9Jo0!n$+*AaaMzT7X=t*nHpcaS2mLb+#%Z^mu`Q!Ju! zxjTjqX#s$9uV^o7!%y)VWn;I-R1=^J_~~1JTvrNG__7klCqno+2t(lzRT*4reRto> z&2LSU?qF#h^2!PApyKOD+}$QBE->G-9VF5yqhHuFB!mf(2PToWoy1hhAW#Crw6Knd z)a$wwFy?cT2&A+>$>Ug5W@w(qI%w1uQ2vijND_zc<^6W-P89-;BhFjG7T=VPFwJs* zajgcv&!Z`-&TL1WKFbqR`!esEqp{o^qOr3bMB`2JLUs9Z1aq7mTtgfS0s9S3KvLN5 z2q9LyiwFxi%9QUSEb7aPR6e{qiit*Qf^|)E1X}p4ejQIpTA3 z`TC-|6j>nwD1ul_T~&iOROe0ym4X9*fH|8T3IU(1@umVn)ur@|>xZGi=|&UJQsqEH zlrcOJjdTR>OD^%7%e4sQElp3=z{zV{`H&?>!GKh7Mg@9xTzH)yaEt`T!?FRGs6rE% zuILBzGg^2d{frh~XhwZMz{7(Q-a#vIW$h}oXeN|mTEOG~FoU8W{UqsDDAP#2&emN2Yp)+s(x2nFVsnl& zl8j+;Rm?U_V7y>Bq|UsTX6SqUy}$H_6|3zcQi15)gT1zGuPvusZxzMzz6aBSE%k14 z39~6;KM~4Cpcj)6#xp`$&%Z-)mGdB*>gbIyo94o|-??Sg{n(Y(w;$nuJdO3vjQZ2Q zc}Kv(6_R;4L*Z3$g%)%K=6tAj=L>PM`7>Hrdar2p^%)E3fn32>px}+pwgRol>P!VX zp}Hee0S^`TXlJ8`Y*jOx>d3W#U%|+x2FD6EHV##tVzU<5f4|tQ2EArH)?X!{-x`9n z-W~BBg0#w$v5@6B1{!96P{dH=Yoh0=An!(df8E>P>(#E0WuTRQphxL(b!=?wC! zZ|m;Jx4x}=p5>2AwLFw!dD% zG&W10lGzEXqi;5JQ!Ae47A=*}r_Y~vN7&hrd?|(Wi&05`jnV0#mUbGkcH{4Es_OkH ztHuD-D6C6&y3H_r2_^Q6Q)6vKwu36$pv=|`y;q^_Gzn|ljeC_`gG{fYdsZr;%CZBz zAqf}LJ(rME%(!yMwZf2Oh|oc)!v@-p(6C%us@-55lkq?XUl|;cPzaPN?MI6H^XL&u zqLkp$j7If;Q_4B{6quArqvn#HB4RTK6^~(fRoH2l^QIk!^CU);Dn$n?n2&(iKCWTRrJ_Qp zF{5kU%piNhdnU8XEJzL}M3_Jxk_^4Q0KXbca*|Mg2IE-#H_N4k_ix*tiPkD!ID;9Z z1C}AACs%*+Fu@}hM_Hj8|7vlk3Sca*-ZzQTQx@!%H2j>85x5sZ^a7?kws2#HT{f@b zM}TjtL0Pa>ic;dqLTWzJ5GYM!k0Qn&D}?rfkY*~3w$2{fOh@TwtPp#DVx61jeSE{Cr0EDyH6u(za*Z++f$_rF z3#@Bo2f1MaAW!hJ*?As|BnD%o69KGx);^NbfhJi%!=&kQ?WIJp4Xtd2m0Xl zHc({uZo#WpU}%D#kZc6@=Vnn{%^bkbyK9t*L}@6?3U;YTuuh|VK8M+2WIC;h;C3Mb zpFROj|6_@*UzFe8_Q36}j;3e;ix3T2Gc2x-R{>Z?Xw)$6F@GZ>FaLz6GYhR8`oG(x zsHu>_n&0ys>-~7a5M66#z5{#1p@V18gm(@$LmF6Q9Uj4Y zJ7a`^c`l@gxsy*N8-Kr+^?pW+yn^|N2xzJ925_Cpu*_=_2el)qexZn|lo6t9^Ff>pl4WR`K zEU#&N9W(}~UVku4TgBHQFdp80cc-PU(m73PAzur zDnONpC0#<2S^30GA78^zr4k1{m^0Gbbq_D08S@RE5q}WQ$c3YZZZd1U}#h1o?-N`0tP4GYE4Af~W_2Aeiib&=@3D;wns$ z8!vzglFeD^ZHkhM8J_6NJ1!H^FqA<~bb`ZN^gE(pn=iK^hn5f~-T3u>-|7TlSP#hX zH6oEJU4PJ!#kE3@xI$t?$JPg`y1bs@LY7EX8S$O;XU>eV4!=Xew!HWUl&kP~ENge9nQOr<;uPR$O%~ug9ED#%$A}pvYiVhVR5Awn{ zCNJ0%U7MxAzwvA?V}V33)RCVEWfuzy-pG&(Gk*kTgfj49Ko|6bvGacz@N!O6p`@7Y ztu5sDl!{c}HYN&H;N746^QVX3z5c`<*FfGk^l3OlbJ+i1N|H_D7!HTS7tfxF{|<*k z=f8Wyy=O1~wD)ZIV)*juaR0@#KMnVu4flqB0>e!bQTNL!gV~>kYvXb|_m%uUZ2{1G zEKw)EHv&Di9dQ;26g!Y?I*|W-)Z69N*&;=}u5`7NWogExKZX(Qjld_du6r;GXPBXo z< z@F&egdqzx@EBVwaG$SFR(&nLFS7 z6(Bm1>dc{OsZ*qU+8YMp3}!GCDXQXh29tb_G8_U)jxa2e0h4T`GaN-Iary#4PjE<2 zo#VUqw-gG0RuC*P(34_Rx!rRAb!)MbG!0pbnTnjMMfyysx~#@XMjrIKS#&6|sW~g# zi}QVMQ`c=;Yls8&oDSN!y$PS)1EnFF15v5$@Ljcue$lU_!as~5p3|NM@YZ1>ivR5n zK4@7+HIq=Fz2G318jp;tZka$AWB#v74O#vM^C8%OtNRK+_JoT;&G&Z+W*o2+Vb;Os$NW@vTZ=txWf?wl%AGd#Ob$H@hX*tY<)qf#{XTRnOXy)qZ3ii@F!B zn}MS5kgG3sy8)K5l9xPM%JhTwNYtDw8{U*0oDX}_!=420Z%1cC z(yv0VWf<=vU>mS5a}M0q*4;3E+JMtBm~GvEwTq#23~dQxv3-iJTcXGaSpr;KG#$U<$^FZ&DFTW3oUI`0l%{txulx^+TW(GccrR=n8Hn)}iWlk_jw&ho zY#-)$A?yW&D^9X-Zv7-o6wY9R>AWw0N&kUlKpTC43_(f~x(jX)pe!TFG+qFjPp62g zu*aM}dV^K^fL`Gl-UG@owRfr#gZ290fC3l`!Wh0ryP|Oj698jMOeoesSW(!naU`?& zU&9zj<#i@WjO)tMQlY>3iRL_ul1Q^}^`Dxn(Z5QjHq`Y(VGuHcu?lqMO7J9q4%0{g zF8y+(&o7F=HHI=n+ow-e5SI7-?X4D^rH`YCvV3|WLtBef51dtS!lxzENyA2xE4msv z_c;~kNbDy4)51aJ_O?&2!@fbH0)Is25GR~8oqSiO^C`?o=+@Q`>dW9J!weapcEJQ^ zloe@wYVs*cOuNdA2Af9XIB6e$J1d*u?X3}ApYnl=WDmq3!ZEo}aQ&3pgc5?fJF2P|dIv4x zVkN1PA|v>xF$4f~8{r_}JHc#gYrhW;)rv0<{Bm6%zCIZ(FX@$I)g)T;L>h5^l=KCIV(9F|Eu(yV_Z%qc}*Td`lXCm7P2O9Y}uoZ z67JW}&Bir)x1CT=G#`OrLb4l}McrnbUWbFuGu~nFM_nf9&(&$(+ke>~_J{qwZ*`KZ zB3Xy?&-ae@aQdyTzx?4(#CnE$I1lU3!)~4s{PlCmoFdezwYDr>C@mlaE<39VR${kF%lL^b3QEL42{5d z1G(r1-))^EmS>5M@tGp+eIefnMFwzDo3A^68R6A=EDV%Um$P?D4}M)~JHjCYJ@MB$ zA%;LK@${xK8N;|NmVfVrg0ZbV1T}D18v_;SLx$R^TX;rjnDv)` zodIm^X*&|(Wx$C5rlX>$053p@kc~T`5gkVNYw+FHPbi*){r=t_pm{2^V1W`+il@mO zB@B>>w0_Kybc?=*85XYsDxNmL34kENlL^XreHxM!?QV^81{CnWiVOVx{@xHo1j&F= z3LC&|7f=FjkVwwJG2nR`BY~OC_&z^>34|~nlPM1STL&>E!a6jBi2x+*TL8t$G!_#3 z7=@6R#qi$?8Sh>?$?HH>2_V8-q8uwj*pxHkv5}M?Dg()Dx@9BLRw`W`ngjKM_BhN? zbjekS(JPVl=TT#@p8r7e zTzB-qlpj7B7EWa;{smsHTz{E>9{R{oB1UF#y*EY- z?)7YjcIuaT!1`Bz5s|R2%@!*RlZ>a#2kESgoP1U{P-&%(2GKTDd(T!KBROl$<5G^} zdZS@7&C27^k$Kh~k!~E*$YEVZD21%BeiS!TTnF|Hg%sadOb=1UN*sl&a__LTTNN;b zP%mN=s2U=4-GAll3ofN;2TSX2jidiTxBOgOI}S+7>}1pfUXu>~)58tz{kuYoPJR3t zE!w*IvjVkRSARx}JMHb^LB|O_=rW~;2Wxco@Ze5+di0ZYd!nsER7qQJ>IEq=v6R*9Z9XzEOg)Zvs}p1&=?&VZNNy6rjsVsjhOgcbjunuG*8*0 zVF-*K3x87D3I7o>wd$2)jr4V?UFxPQjAt_C6Of`yU0b*d-CWO2^{c0{=7Wt)S*7Rv z{F3j^8CMF>HHxHJqv@5?VQ|hAK==$os&U=; zRDnM(`3a0(xsPhL-<8vb*WZo_xyn<}gI<9di*k*6e~pFhmJD@W8gJ)bF4fOrnE0 zox#(54)%ua>;VpED7@lyu^Gyc4EQadQe^~i6-r0mvx2(au<`;MxDT*u6VOrK`&m)j zeShIurKNK(zX}NZ1;a0(ka>z@1YjH&;pzcS#AU3y_nae2;S}wPeI(=+ClJTAdy)Gf zU927jhw}9kW6JzrV489Y%d+jp2k$;jGX$eUl2DdGoG@zb!fS!H;?mVZ)e#BG!d|u0 zyyE{7oPgdxlb%sEFbw;Py1Fqaw#a`bzkeLOes_EUemQu3a&&Nc^7eG}&xCKlMWfGR zRywSXUsNYmFxeu^o!CeN;EX3_6#V=b3a*u6+iB8$lj595+m3$yx4r(}i>~VRPSwxZ zMJVtI+D2}dn2dXWMj~)YQWBHt0$hkHzy!d_5pc+pKBL?J7Lp9ss!k9&~ni%<$#M1?tWEn+$IU0H>phE$tRR;7h@%44&7>byG zgtmh~d^5^k^*(<5__4QBnH)#*s(<*5Y|CS_ljn&zoa+YSop9+CUxCKLd9~~>n3D+U zS1R>7h9YU)cu7?D48`+4oypAg-Ui}}(V~h==drAkTi<356F5atFkaZL zRLH>khAGTgKqhL`YAS_fo_~@ACCr?et%@JIIkPI2vw1;5{s+$ErpliIP9l^r@JzP* zWV+rr;4;#c%DPVeQa%gy$j#Ob6wnlf9GKjeNhUc(02%>hY+dr44Cf)R2f|)>q%7JK z5#)Ge8rz!0=-pD-QRvaL8JmAn#c4(u2}wKxmxpJP{|ME|b^_4*u777d5Z>|nuiO76 z(Rn(}V1(8@1zPt17km3Joc;gh(-#l+pZD@})@K+an7mW7Zn*23yZrT@+RHDji|X1f zT`^HWVdq`FlF7KIcjy@*SG^HPGo;~GzXvx6PiG?VbD-0C*%cxbBZdO?^g05fkmg}1 zlGE*qKe>X4qFotWIDZgD;?5V7WGe^)Ye=#&48;u%$?(5LmGb>s4c0k{QR@(8L?q1r zHU>$h;17ytcsc^V_F$UQ-fvb?DDW#+HW-@ZF-1&%y++wse3>HF+XcNCQ}JI(RPQ$z zY!zggc3GNfgfcXGH{h$y@Ao)~_z~M>nuD>b{LM@^iP1TlaDUqL%rp$#768V&Xjlz2 z7Y{Rnk-Xc^nwyO~)nmxQSvjr$4;j}^r`RlwA;0f=eBNamy>q3dB7N?UR5;MGpRV}g z_7(W@&GR3{5ei{eDgZd)^EU!dL{!r!qN2tx{#|*m_0FXb+bY&(viwtL3sFsF)t0M6 zqb}B=7D3AyiGRvpi>YV{-?SL5H0^up7g1vTMU?^-SxzUxe4G3Lajb7qjJ&eOYI3vjzCRc+gW-%P=|0oZ>(caVkU;9HdD!I<~Xayz@z+jA% z0i8LeLFg2GcH)~;#6W{InOdp6-Vv;K&{Ru!mFcZAhVN%lT@JpHuLC#%H!r3o}YYe_<-7@IDrbi?} z^7&OQY=1x*N@?HJS^v-;m0#DdPXE8g8O!;BEnSJ%x&Ua=|M!P4_g($}!Tnpf1oe@*R=2~o7+ zee<%sHxlH-8UL;Q-1EOMh~3D`ul%)~|IeR2b>lxg-yc4l|M&7!+q7%jRk3as@ofCh z0J7E_n0k(LJ9^FvHr-;YY83{o%~%Nqz-Is`zxAc9M;7(OMxNNmNagI3ZC_WOMqS`6 zjeoDTp_RyP3ATasN0<56`~Z6)Nf`Rbdf+kGsiUUuSe1|tnhw-WkZK}mq1T{RvqI@& zFaniWulq|qTabya5_x3N!4a&+Yfoo z>DE9y&v#3MjZCYPDepT|EIh^+a3pQqm3@Tgjmooz?Imok(w#rx!um>n?)ukfdBBhC z4ebDJ?>~FPm+tz1vG;KQb1%Op!_LXA=3&O5Jl~^v>R%{@4SyC4a88Pc19z;*XetJ@JPyX%#FS<7@Q5!4Dk#yK^vSpz6ohZx4=6 zPJh(-H7JM)-*ROpa=sT+!~jmf9L-6#SZN`2)6)1_DRqs9RnoLdE{;zxPfm|t7t7`S z>AN@IAD=(08t*9meg^=|C@Q#`_TkM{!Pf(v4#1}$-o86MdVha%_G(WOHQ)?bT%A*J zC(*y{GjTGR*mg1#+qP}nHaoU4u_l^mVjC0N6Wg|bC+Ga{se9`_bU$?Me%oDLYkk-H z?38HJ@E4h%RGdHfbGmu>xMnv$OakVnI`%E}q);cNpK&PIg za}$l_DpY)UTR3XP+z6nPMTMWJVld#k9=(CDt4o;I>>wr2XJK(8blfDwMaR*g@UI8( z_A$ztC|mWiVL553em80=-&A_>H9UYZ{}4`p_COPTPlLZSLiPFy^GN}ydqkP!RFL3A zo2m7Q52tuFe$b~>_oJ97_l_SE56*mzCOn*-%Bxz82Z5?4z5*|}E76nu?EFt^)9q&t zV*m8Y+ZQIR%QikXu(FZ52lISD3{+kTv){M_8ahGUzWkLdAl?qp=GYY1TsfS9sxjoy zb3b=cX8izcsnqiyMJcYim#!M!uKn=G(CT|Xp;fFNPD&07oUTEp%wHzBeVW?2;3$0N zUjyJ$3qp&IGJqjV$lQ*R?>tk<5I+jXV11fMe@KBHa9+2H;@bL9AD_`|mB6xv6KPoS zlBMKi6Z~|&4N^G{x53KI!B2%MyYN>1>EyL*hsrPshjJWv6vWKR(LJWhDuE+4;W)jb zzq563qaPhV#S>NcEk@TU;Q~=8u&5u_9ZGn{CVP*Ft`2}2ff)%>p|kxd_EQ?W!qd<| z3(3s4&bTW#3um2_j4y7&Har-fu`psPST_U1$XX0 z&0<$-WzdI{H1%fZJFP1e#Kp@lR8IOc_nbP^TIDt(v>ccE?|V6p9$ywlKxUSM_ih2^ z&!B(Nr9P=o4nFXH)jI*suX^m$ZA0;-R{V#kra=a8H8Qq=2LS#58K-YS6|+8!M< zTLN?#`m)Wa|3t0$8472#B!-*D-$5-v8Gu~_;ww5rsKYtp`f}ES2*D4*9sD|FFwLwg zIT3;$QEVXNQK{ctM!5$?`Mf6IUa0&{y^rEgVwxbuEwu-Zv+bfp4~f4f zKNi%_ZX|`KVf%AtY(dtCI+^}Ximj3T(nZ#-iFpD=QGARaiHJL*B3ILpnGfY=oA}a9 z19eU-Li%n&GIS@XKtsz`boq_0kRRw0VeBwEL5Q$XNl$=vqm0+EFPI9Uid4bU(dZ+s zYrMhGrv6i)S3Z{MwthN%j(-t4%WTwj}$l!$G1@x=n&KExGmWRSYL zq>23~t@Rhf+7G;AIgIOr7uH}L?lH-TJw#i`9<0*v%lb#=RvdW^>%RZ)5&~uqM#dOE zwL0f3NGM@-t?-^7CeR|TVa&9Xx=Et*;rX>faLsHEiAIT4%otvi#@EG3xy8s;yi-;? zIs$b3>f!nR<0ia9+oUlw3L&~&KM(#k$JW#am)W;(Rx6)NE`B4id>3aTtbeB%sO7Gi z5dNqAp0F)eRnASYKxr;arU{tC|M=dUd1C@cl$`p4SYOs3(qYP?j1SYPo(A<@9-ztS zh9)-)W-^D%HmOoV5^byR`KVatUKNL@SfW>NE%gPQy}Yju_TFc%A20nItiduI49*#} z!0VxoB6TnGsbXHeCl62xocQlA@hJF@X(!#cJD=~&6^S4UvdQ+BkfK5qe?74 z{!ITWC?j0zyZ^mn0C$+yq;667>heoe+v}?B;vSTqot;0M z(P_C!#CzsDXyri11$(3kbPD+TIs1Bh)t(@ye^{(D5fSDYu-5=tbJ}=MdGR0%iX(r@ z+ZmvS_bnLrg-;iCV$u-$FvWo~l45UB+4XMjwLbVZm;*}&Ky$xK7H!(QvEDRepXmKI zuSx-lBKpAD`T=F0dhQ9K90b)>*f34It@@2h4nN!>vuo66K8jOueQb5;{i}=P z{P!<_Y0jy?Z5Y%7M5`k0tR zP9uKN>=RmlIWPzRlK>z zkaH3_t%;zTL%%wa&Jik$x0IA%gh4yY^Z9PuF5#;6gy=WTfQ{UuCvya zyce{4I*$&&HNur!QLv_yJrUc9`Y`ymRNY&%HB?kK=o8RpY1SYP4`Qr3v2hVE8OS5{ z$W>Co?4{M_mpehOd^fO>%F(G2L~C!N{{gcYrjCKZemqYhhryww)})t&e$4k6wkMSX zX}AuYawc;ho=*~I#d5E~c@@aSS%RIG)lAZb`F)wG<#`|&WL{|##S(%(RdQ1>RR6H# zznIljt0zFI2EwID(bIsW|SJAcN8mce=UR7YZQcu4(QV-{#SlNW zA6nNE+FclZ>g}7=5q|k}W}NI)Lkb7Tr5%s0O{m4oDR$<(o^E{TzqU4IUMN|0FzxT^ zi@upbzEmrgpAl!49eUvxOnX@`hsdQtuiB5Qneg9p3Q_-3X66(5hp+PEY+byXHtW`= zS$N^4qa1fZt*qHu{~vnkLn0(qIsqoMTH`t$J`@(KY3hK)4gdMHN!os%9n3Lcez^9f zYjzwfWGOaWA~=B-xyY=FepEEo>8A#bwPC{#?6Ii*-*WUC!C@azO<%~cX!}RdZ8@g@ zk@U;+tord5;mVFSYbnRApl(yN@ zV=_*WkhhKzZ{mJtYxaL+5;~6pEIe%UHS$mYgs7KH%FMtI*bXDqMmbTy{e~MKWH9dT zXdiHgE4&!~;qzA^Mo|5<&Wt8t{n4uU^b^8CQNGH5&iseX)4ZoQN>Y6g0kYp)UUgtC zN2oH`FqnM={zjUnbk?1$C?d57V<#F)&)sVR79(bvxY(!MHL;xrN_|)unBJ}`W;Cvq zdK7a|j7_@=VF0YFI!I7(1GmQxr)VJ6^-X@}+aB9`=)vl!E7_`{rlwVgc6C^4e-Og6 zuvR;+aW5%@6$RnhcyAdEuN>w!jkvr|HcmB^R*Y2*g|SfuwcQ}vtF`koRjcOH9AE@bvf(9Aoe=j@1{X*8;FPwEBpK8lzJ6cQ5m;at=?d1y z6-oJbAknMg%{62#{gat(2rdMG+Bd!6>%|7AYWJ@XH-9$s%6ob7F1}eGuA)ri^IO*_ z*VOn9q->l15T0=#-2Y~3Q?EH3%}b){ZJ1SzQ6J=;G|u>=xB<`uel4J&L=C&zhoC8L zCL{JLSoe=EcQxR_1sWp+QE5|w2KN-8y`|Y7=qTSRL z^Jxbvg8L@bScImb=2ASo(@4x?)KQaV{5;BXMR;?FcQHweEWohXZbJ5z*|7CWbh|nH zvx-OHJ&%0fk3BmJ6s`)cilQFLnJ|YrX-RyX|9j^5a@ly>NSyDQG@$s%^F{ft+yQmR zt;+#!DD!q%I%Uvu-EF|XzUdPI@*wI~SODWpecHUR`8Nm=f;C>k=v$Tey5?`|<^I9I z7?$^3xhsFI7lL#dWP(OE2RB2+QRKOPl-~Onf}_LHq!42lh*|2@<=A;bZMbM?)@Fx) zW_I*Hyr{%0^tHmDaH6p33tSx}T?p86Q(Z3Tor_^aP4a}KN19U2z@gXWV5qetMtn%4 zDOnr^PNV()R?B^?0?*?UpayoB8gMc;OtvU4HL3W5}S z<`rnM`foCTsf-l8&8R^ZYWrf5mx=J=Yx8ulD0Sk33oHO?fJrP=B%mqmLS>6PPv(d`v`H=FB<&|+lRVAFp-J&!$~ooFT?>f^=gN(?TxTI_d~Asy*hhRUZZuRhlw6&jD&Q5k zPZ9l|p(NHWfPUOhB!*YCKn?8-ehJL_&Nt5qb2F`|v=RfF6#aWZHm9!#t<+NjM2 z0^lZ8(k#ppwqefjmg&8!83>u9Hs>X(o{4~aVZJ?;HHjF=u?ZY;;cMIk`<0@}F6`tt#@ZFx)p-Rk>Ks`r-~P+GX;`4{=KwQS&# zLEp1X<3xVeQ*KgZLN^a*8tAzWgWW;l(-(YetV1KcpNud8F*Ba}0o23yg)C^X1|WcF zlVV!PC{-=dGt>8`q-$df<8PW5zxo46_|M17M5S(erI<^!o3oFKf^#GacxEvKat5?ffC&^D=)A^1Swa z+5$N-bmLZ}m6S5k^!)NsXsT}-$v^0+UNBdj0j1)bhfU;@zR}x4X9+qO1NfO+AR{~I zbs?)doV!K63G->F#*zs`m{E6Y8U`zt<>Keg*^bW#7Sj{#!7}$ZiYutu*=(*%^KRsC zJ5z%rj<{~M)~qTZRl<0^rzW{Vt8U96rlCG2s_Xcn?~%wb{YaA(T1Ea~XiyDB8fmQV zwJT@IDC0(vW%t{1H=GXu-;G_*LH%vUYrY8WYegCe$J8=u2)(xb9_0V<3F|w00R-^6 zd=o&IyB>!(-8dmqRnN#Jjxi<~ADesiQN_P!@l{i!+m?!9&bPOJRKEX^tq*&QPzCXk zd-Yvhe3K-MC%_RT=*m@;=tbzI7I(#=ubvscVGTmit3hC9RWk-!^%kkMxF@pqCH+Q! zqqzP0Ue!@k>8Y86r4jryGwHWAeIv?yLr90OV|CQqzvoW#-SskI{VJYR8;HX2Rr@1; zqg2P=5Kpa4nEg2L)t3B3=p-MNg%&!rgjX%q!QS`X;pmZ;HJx>l$gV9L;QuRbeK(j% zpp0?w>v#ZlErFxBj-DcLQ+J7C+{zFc=;zZo>G@06gpbt2R;zz|H>b`aYZJH~(Qyj_ z2E``khV0Rlt#4611I(4i@7wAu^(?~wgknh8b{la*PsKQIjjZC=3@q?3jItIH;Lfi{ zPYc*ehpkC9BVl2ThWCGlUH!3Vqj|8>Yi5y!Ol1O!?&e2>^`G}r%gVuiJPhcSg2_{I z_Sza{6O@~>#HjRK4zsDdJ_V&1+g;x;OXgYkVdSTXn$_?&N!mQnL0!;_pfi1ukY?)? z<~w!!dO-C6AI2e<_r=){7Y(&w67pu$4m}f$!s|r-R9ckUzS=JoGs?@d^rg;P52?M5 z55^Zziu`Kz(?0B-jyG$S6DLyb#KB~a1D->qBht*JVeUVa5Hp+sb#A8rfr9MxRn=vD zs4_X!Xt1Oguw?kY&$C;j9!6f)gQQz=6fL~}N7b4=JR4)YUh8~Yox%vKYcs2F&DPA4Bx{ZKkB91l=}`|F4wQ7y8>g;aDGR9Xx`^ z8YXAKY8Tud7*o>7*ZQez=)=rP3XqwsC`t>X3f-p;mQf2GU zzYi=J?6a@1Yc{rOcMG)g@_D-4d>lQ!dI)Ha z>-FC=*;M?LejYxdZf*ykAL!s*Np3|Fx8G(SY=5Hn@Ba1kYu<*wF1zB!Uo~}ZY?yxk zL(G?phRg1=?#}bM(;A1fhLi2*h;b76ObLnm(@*WV|2pU4&{ZvCpmU$lq+g(8{%Ojc zHiJBYw}Z1A0KiRNSV2fgAUvXzyock~|jn z2PxN`bpljs=ZFietyt+$R=4?F zgOzJ7=%k4^`-Iq}5KB)nGe1!N1n(&~R-vJHH1Z8GZn12OtgZFbZZ%17(!W?HRsk)< zy)p4hkXul)VvG6E5udBm%VtL3iKW#e%-}>8BC@v0=_a5>?DC3?1-NE$BF{*$s3n_| z#-A{7O-Vf=_yV|fw5kf5!RS7}}eLaxrq$4B$uLX_+9(HphOw^;g#t zQe84@8qjR6u6OyWNe0ne%?h(z@^b|qC!ivhBbTY2J_n$8ym@Kb;PEcdaNce+@;tsptI$%#M-;@fQ}t8 zT!q{E6qvr(-EupjRF6;aH!lo>&e}>yHcdno#%1*lCq;37C+KgJ+2A~~JeJZd)dh5* zI!mBY_aRh?W8c>Z*oW`saN= z_mAli;^#-jx(@CB^+S0qQceMbo#c}K1lX`rZL%c79s4@y1F!Df15|i`#`NN$JWLSr8$;eTQJ?B3o7yf!|q&kMU<69wQAZuS7+sbc5O7ji%~_13uf(U2}PL z!M*iLPH#HF%Xnnf@JFr$ohAqGE#h73K{s)yy(n*ah-nBhosHYfkMgtn4u2(xLbW+f zb$$su0Q{wt6k(Lza4+byI1zLX&28hwIhG9Z688(?>@0wA9OqbVYQj<69u+w|7>N^H z=);KoaK8GPBVS-qU$=wA0%+xa5>sdizS`4jGtWfWsH$P1p45%Bv8RjC~0!eorTWl7!vC22oDVF-2{vdeYWCKaQ<@&D4@?RU=IEGefK zc!lmRwibgEW2|Y;K_H1N^6xds<>Ivowy*oNwXJ#EYPxht(l%FFr@@#ngvBlLGZc7@ zVoGr01u8TaEm6PZq`V=HCl>(woFXVk0KspCmyfWoA+})wa606>+o5UI3}DHLFkeb2 zQnGNQ2PCoscJ_PDqTnVR%FO8gydN^Cx5zURrmz#8_kef#N(Lw_$Xdy1Ks2gcMCc>Z z{By2e+d?vlIOJ{-MOmDR#ez7gb%mu+$%D1CoVpbUAI09?hx3CEpi)(itr8;m4YVPu zdd|e$f`Oq!Gh~P6_#i)X&PR0GTE}Y=lN;x$9%*40H<&~Uf<{r?pb$qTONv*;1Mxts zS*?}*d(%Z8B+9k_Dw@45wIl3}Ul zVk5uUJqzS@dLI9G&OyLu805~-{mKLCPSd?7hJHi&3x-N&*6=(27$pHAxgO^;rvo+o zv0z|HluQSPQ0rtxU-0|{C{a5gfg4f~DWf1a3)VN9$~6o)TsM41?}6XT_l~TWpsB~) zPTzwAkoR)}=+qzZ-%!;HfAK41Tl=`FHb>%l(r68qp?qraZHm}28B7SO@coy;lq2EBt%%hUKqavAj0qD?`rV` zoP0mVMz)=he4*zMK52{~{*Qrz&)%c_)Fq)aMEw8+xG1F3wRU0d-+|ku5gcN)9`p2| z6j8GLf>mg&h0OI{FVQgQ+x#pc_=B&G&Ie!0!K6=Pb-2js12j5cqn9bZCx;!& z6dFKO?3n{sND&#niM-sMU@>6WV$Sl8qo6&s;t)h75ys3mFT;O3?-K|^!(*|i!Ta=k z(3U<6XuZpO$h1=ly=;e4(SL;$YABy>^Hv#UkWAPR^U9Ux(inyJRwo|d&-o#;YX}%= zWyzeQnE5};An?TEof*nXm;KmUN%&Qc6yQYQds$ z+y0_g{LmqW)sz(?K9dVD_oN}ju67B3jnx-dw1*zu-4ztLZn*S~eV#l=KQ|j7?DhwoU;0-yR^ywAd|*s0hO8_^(fo=J z$Aa!Z>jgRh9+|R*++63Ty-dah3TMWYQV5C2HMrm)6zpL9RRTF2dySA z?+BzJrD($*9K;TG8oNv#0j1QJ^G}YqVETk2v^ir2?ywZ4aKdoN1z+vVp;VY5=Pod} ziDq$%Zs4Nz#WAoGiQeKjtQlEyo8*%(-)RfY7PN6~j#buo9`E_WS%o+chnNtT1!3Z` z1mrC-n(>!U#z+va2(b`{_YxMhiSJ(+JLqZ@Y_b$EqxXPc)fNoQPiIB~FG0{A^*+k` z$PUX9Z_FcP6OZ1V{R#VwaahjVmp=^sXvs`C3XOL&5Vk zRmg=51Ji>OtHslgb0o4vlQ>cDzxO+>!8jx%OYO0wmq;4Xr8R4oe&!*}ygVrkDUWc? z0!WLN8k$S}u8`tFiVVY&j}7s(9SVerm@3MDdv~?L>aL(SliItXG)4_pZ8am@tjL)n zO#&UBjq6{*`R(|o@gCfxZa{fYJ;vn%nbCQ9y3HG-zIm{e=|r%6AoX24_fX6(^}mFB zLr|wP1gy#WMwnb~g?d<<^U&B6L8_{^_x*7m-Zop#NrPDzIu{L?qd81Ae;$^Fc9Y6| z-Il($lUXN7RsTA;j=gWvuCFqhQwHMX3H_cOB!&$5eLe3S_AE8PSl^jRtX>=>bmG-= z*NFC-C32Y*pUNuWeW3(RRa9YAh{yuDd8n)~O}fqm4fnFCndzX4%YOwUQr-(d|JZzI zfBJWegpWhH@sI7BrrQTmc6Q1ns2|24cP$4Lf8Ae!PdZ2|W6!*P=l%7?z8Apc)jNq0 z6)rrAq7!3~u19oQP+K1SaU1A#bmSSVbCP53tPktfKa}S!2GSJp`M9NhTGVc&;hy&W zAmZobrr!h^5C}ZoT)Y7>n;V4BBs(U!iBx}VJpT}cl1r}$a6FhA-weNb?TQTD9kiVh z{!|XlbPT}>0{4VTrEK63CIp5!Z6Mtv6!bHG7%OH8^R*7kaJW4@a4(M`Gv}gfBa9eZ zeY^+JYkq{zK{Tnb(t@6-ng*JiQWJQKSt!217qoS{eq1cqtZoVz{vka#$XKdmXgR7- zP-Z7ca9T`SBr)5oLY4fXBMWxwRv(|uBkm49YfVyYz8iB)qlM|qnmi1W-N0sqB zib#WW%Xv}x8~Moc#>0P7ECD-IOowOmC|#-&uw=iu?4x;c zN?5dAt2QkxbWz~&uT!Lt)QAq_ak7-5r9%*A)u&jiS{5NJl?2*HYSddQ%uVJhBST#u z-cE9@z_BRJOI%S0ryrQHNkyrz)(~03X5ki&*^c?ieyqafB(zzd)%cI-Y$UYDqN0l6 zcgEJ9w-m0vN*TGSXj@>$Iib`dmpB2na)Pyi@h~s!Z4E2T?rW(Qx)5!gTEZoS6|;N3 zwBl?aH?Gf>g37h6Ca&y#t2go45HJ0M*$)8wa4b%aSvhtRh7N$LQ3S0I>uzMUSPy^CTD(2W7NPTp=!_x0tlQk&`)?UIFaf|A(&p%6oHG0` zH+{OfHn2BRhA%xviW<5^Yc70bXmNfnl#~+R8QsZle>gRv$j2j#6pnMo6}vqWnDNUB z;)05TBDhP6mR-OIMNc1>)h{BY&rOpFiNe_SxNOqv&O4Wx=};*kT_(n%^Y)E|@!*fi zxSf!D#~0Id)om@K?G$vAjgB9}an%86zlp=Y69Crbk)%Hj3Fh6n&fyHmagf>d;?V!> zcW{>(u}>%-I0!33v5`|D5%D3N&q*bH8@ZmD`Gxr+Gr?+<@f8Q0KWl|Q%#njFWel=e z>D|Qg>F@2=HT3s;vA_naS`?zb`kN}7y18-%{8EzpC!Eq=4_0MgJm+wRagV-0$%Zah zTXlfE-{9fq&gI~rp~5}fwN2h#R@}? z4LZfOM`>fb2`W06^m8T+@lLF4q^!+@%4^&6(xj6p9Tv2z+>YJeqc5Yd0Z3JIT za;JjDSBhYdE`{Zrqm1Fa5Ee*1iHz0{7~M$4@9DEY&-J}qU5L*@(9V2B8Meb^%pGMG z?>Yy|)>v0ZU8M+Q%V`Qk-}WJSp7ufxXKe=5?MpChe__ffiEz)p!yu-vmj_h7+=k=n zGx1nq=0)W}$(*CPu^Ezt3tv?>!w2zI`|KTJ`|TFvc~sae82t=O!HJ);hJ&nnY8u)s z%c@z@BV;hX(L7Hf@|@W8m*Y` zqHhPzb&GMR=GTRNmG&T1_#S|F#FDy4AcjX&*l z{7BAr@w-}Cy(&d@RN%FLjaTZ;iKze#W+4M2H$`-1TbMJ&Ab8XmbS^-OVVzb>98!UX z{+BbQ{6bNx-xhaJI;rz%pVnh;X$6(1?!j%&F)Lw-X=(?Ic1k`ZT6+fkUDB+yPq{+Q zse87U3MxyJiX$7Vi|vaXYmQJHR2pYC2B%^L53}4aMsu%r<$K%;`yOr9A|A>57KVfM zMhrrElHv0Of@ecS34I_P*)yfG6?S^C8_dUtLL-Q;Wu}eLA;?DZCw^^iiqg_MvzgR9 z-rR`VfCV4QM|9$DVKM{OuKkRHkRFHjVXfx0{smDbwup|?;=0@RK+K}TKk6{viG`Sn zd$D=BFI*fh#5=^*@m1s-5mK0RU;SSa+|g$1XGZWR-7EFl65fCpTRydY?w}frXpZ}* z1`E#5BLbFWYxffE@Ois{hui&lg)SEmx8Fmhia5Ss8~&RUGef`9=zg9%E*XvIwas7H zx~#yTZHy7w@g(|Frs|OIMv8`(B;W0nj>-dHkc#>gHL}q-Mk3P3wGzaTEobuXr8FdS z_1%`3p}m!RKWB_hVwfY0k(yI+yM{M)a-q)8Y(E$CvF%FdLhq|u1;FpF4 zWVBsaKy*9R9DBAkU34Y)VXG)@QtM7_dt1b}#O~CoVIB^vw3y-;OK)^Iza_1BiA(y` zwa^oPpS)Eyro17XeFO*5b4TxDm(2HA>x!?ttFfRS<^z}<$L1ejAwv!}3v`#>wklw% zzMUNt@oSrWWm=Gp`e^5H0*!w42*&(8QexTp#>N9(aYVe^eZ+@ZMoU=#V}4y0N>8NA z;7U-+>L`N2Rk$NUt?rLVz)fG9SwmNV`d%~)p=^BDYVN{M$%Yedw3FD3BEB3gQVE@f zJ>_5~@@~L`FZ8=5ci=Qs8!VyUKd98Mc4e+=)%{E_Mr!h6BJ|H%0rmK%Tzli6!Or|sY7JybE^>#q^!E~g^{MSur_}JujqFj$KvSjC$*yTy zMR%4ve!*LERY%uG0k+dkn|^5MSG~E%baZx3rwmx zi%bV>M7OBgy~KT(e2}dEm#ZTmXP^`X;6&ti+AtFqX2tDLrXF-79kRV`KC_z4ZjP?gg$_ew3iIMJ;WQ=n)d)uPbn@Ct#b6o) zW>`{Z3{^yxG&WIEH2_O@Uw)R^Sv5gb1z5s?@AJs`OhU;H|1w^ip33c#Q4X8gpTxLl z+0#}|VoSAc;%!)%b&A(_a%7q{xK6oxf`isO_;RnkW}T#D%Pfml{x29`^Y;*e;Lo#M zKZXB$S-=fw|>$AcQnf%+Z)q)tIvPxp`t=)W`96)?*mv7 z!H9yvodYo@ws2)%V?&KKhlr@vzoFWOI$OmD7pLxH4L-L0K5ZAR@}D$1J3n^4E@9@^ zbtnjk(Q*ayfJi&90fAL} z)3JarNaZlDz!<7NuI#l@rCHn=1r0QkPOV)lc)Y2|e2g$fS_b2uNh$Gu=(--l?)*_Z z{C&b4<(vooq9qf1>z=tRV=}X*XlQec2V3}N<>rAD=li2>w{S|`M*||$-?y~8eQwh) z?1hJXpjz`nyYVYeB#`2EAKX4$`W`sWz97R(+zRz=@mpy5M2wwRss2M(Tr2n{zJ7lZ1B^U~-Y_qV(leTi!C)1I!5OH1umVqs3 z8bTm4wZ|E~)4bRmr3%pL1Q&d{*wB&9|t zO;ZT#H-XyyZR2NUDQW?x1i(Fq^7$&YQM31^g%)uqmygJrZGgNuvMq8R?#P>8(5dis z;(CPXW>btEp3q7i#@Qt#!R0p+^LQhdWy53$zg9d*1aUj z_1tUEZjZbSt0PQxoW%u*pP%)3l#VX-w(z9#=fM_Q6;a#N0DR()A_>a@^zGnQ-ffOr zKQZ)Uxo~RXj)|mAH--52Zcr{2_%SA$hpSYc?~|dkySqTbQ2a>Z+`cN@8P(UrNOdnB z1@ssFdUVx1S~)h8s7uR?(N)TS#zGhsJCc^%;n2_T9={Afz{5{g4~h6)N5YYisSJ*2 z42_e*dNOTi0iwNnk9J!68<*+CH|)uSi~N?wP0X!nnRw~c=BVK=0tO1Stn-1-xT&k^ zC)tW|EvReNxWRa6Gsyv-Ory3Z8v2{3Vm$1sp)j>9HSVElqTGRYff{~(0O4iy1$t;7cJg=cmT(U?Inrh z*?nY%M{gnyHy5=X4(-&h-g2oeVUK71_S(GAZ!dgq!V_eil@SdkM;alGVX<=MmCx7b z%j$?jtv0RyQ!4?Yt*krN>ZLBTC#1_pwl*P?laITN7MX)cC$|^wm4tkD972h$=EamV zIn*@*2p9aJ4nu>W`zBON^)=wJ5Jt50C4x2wXdC4rxs7FLjs$sN+PtStmaoJJmVbv; zyX#M+w$>Ke{kj~;7E_|P^oWmd!x+I;d0QKqPu=4Zt96&d8@wJ_^2ZbZjxRR>PYO*V zl*)E+(%C6*Uru@H^T*Qb<>qzeAg<0Qo-!&B2(!-T!_GqXg(P{EX}C(FqC`F!@%U5z zh8*@iWj{t)Jh-@5zp-AJV3uCIRo^)O54Wv_`R2UKF0ElX(Mf>*-tcEh&iX>IU`ql1 zd$#7LAG$%LVvI|RASPz?`NlM>`X;_>O}C3n&<~3-Zu|h8Za?V3n{DU#pO1#?X7J>a z01B`ttWPi21=Z|6K;HxYRmqv#NUYbS$ay(awHmvcQ!(0<^wJf9Z0|~TRD_LO>37fq z^HNXgq=?VsE2}^j$ZJU|FK2V~1&L~C{{_jw?|F+JbUXC4aClkSIQ1zmeZ|ie_zK!L zwY%Tmg88_1m{z%8zLxt*@=w-Y4s(sBp{J8=oj%1HSQ2nVmU!o zLB%%o;{;Et7r!a5?n|EAc9zH7=Nz5MTZyoLK72ma?`NHhFTRWQ!XF@~_gVnZPzZVx zkbd?rRj2e z!zOT(`oOo}$cbAH_grC-jC2-X3lg zRX|Ed?W8yT#*YU8xTiobq>)eB#c5Wf+Zt^ z_Zwz;Z6-cIyc~I2um&h85QA0yi(YjsRf7N#l&Jp6vGL&3;GlB|YInn4>_f-5jr|go zmN%5*W${;~>^lS%s?#a-m8;fo#ug z+wFuCtSL!!2*{uUzqE^?+IpMFA$}{|wphU}WXdQW_iHS(a zF$238uIP;&F|eKlmYM;1$;C*En*9r3L*T`ALedR|1u z5Uyrip}jnfgK2@v-UD3hqVA~VxY~^RIvVY{b)BI#DlpOM1u<=&Rn8sowKWWISw0aF z@C5a?PtXk{&`}&&C(yf$u)AvB+dz-`2pYRrv*7`!plpe1HY*+^$&4Q z{~MzmphbsWyo2%a;aX|Y_SC8%?#%XuU4-UGu4!~g_*Ix%pJ#>5-h*Otuy=WGR(Oh4 zz7ylZa($!jdhOb81TNB}lF0#6!)jO;DRYK8?Wm+j9U|kP|1XthOA9~SJPXdCY zs5LP+xeFle;~hYU73ZeW39dxH3p6xkToL~2U?0c&xfxvf?sD!0&H2^41ZyalSz${t z!U~AEIMxN_Ah5&;f?}B$m-IrroK~dcFeUY97ytImt)dy5mqbBjJwX~L{P0A|L#BzS zBOGMwnOfje{Q9dB)(H_|KFBik#|t-ixL5wTnh?-Moh2A7XrPxSAhDv&GtZ1nbUKyG+L-v~Hu7<5QTGCq>b z!OzW7{w2inOYbnCx$l5h>;bywK_1vk3c~;+hMt~VtbrZTdd9a;>bkEr$@#T@Q9j8) zq6`oQPRH2UxZ(C;nxxXi#?YcOSGVvoX(~u@Xt$<3Y99AO_$SglQuKs{m3&-GvLg+$ zV5bn|jpr^f?=f@ryPW<*ZM+{A9F6U^QKp7vA*9ILA^R|9^{Fg@9`4BamNJsq5&JM8KKc;1Ja=Nx9>Q~9m_K3|-`doCJg1$4m zxaht^S{oG|-ECUT=;-VmCjk;TVuy~QRWNd5x-j(FmseJPz44@=w#4b5ECoyG7?LiW zIT-pe>F2wfk>GS~{h8tJ<8auxgF{?A9% zwr4E^5yOrC;5PdWaFd;1QCV-7>U@HLLWYJkDj7~V;+CMRlX49z&@@zeldH}$;AOO9 z3O7=h7p20b;m0>cdNWlft)K4ax#NzcBC#&0zYQ>y6y8+g214<6s)-ebc*|N>o=rXvObZ50mM_uW!ez z+j8)E0h5p=K;!cq6_2VY1dw0QV(o@-3oLiKaNyC8>u(E0<64u4HJcwx*1My zeoQ^+LcY6L!2CFF66ev(c}DG8`51K@wy;6z+#G2^@Yr;)Z;TZkQ__I zmMwszP!ae_G+&myvnHR%|K5d7q20Yfvb^rtJ;%+@uitxHND6_L%n57S#!$2`h)^{B zGr5ec4+e&rTpf%;3sAMVAJdVSpEPe#{wLz+_pU-pT2xX(^H($uckX5o8~^%SoM({m z?aewwpd-OqyN}QENZ4@i&TVdm!Nw#~n&b8>k$y}J2OgQkPmV#u$khqfRpfsB#-818 z-@c(F6s<)sGT{6%=>D`d*t8;W6<2b1b^N#4#0S-0QTA0S2mq&+K=|y*v$IP2e@bad zw9+#>E%@&%eyVxd4mE2AOy=Fp;)4q^>*y&u1RI1$@InOl3m z9JG6ceLZM02aJrY@9*y^-QArNuW476;pX96Hg1J(SSi}pug&#xUIwS~#HbB4^to2? z{{8#MmnicFBQm~9IkRgS{a8#=C7+X|DFP|aTlWWE^ZVpL zIHAa-07tXMH@n}M%zjp{iSKk4n1?Mcz7ZL;=0?XH6OajDqb)$3qB*RcS&o5k+X8ns z-*Vw_qrgHzXE+Ckq@bZBCLYh5SDC5qIoFAfQ2FGm z8?Q~6j2rmu;msK;5q>W#YbNAF)d_$VRgp<513V~Zk#aE!&12QPqTLfh%t$i^vp$!i z#WUs2Q)G=YJcb{6IF$Yg9)EVG84kYQK*YTowG7v2X3@3QgT3k%8?7WQIeV`s&+<9&BiN&Y5G zD;DdCCrr&_kTeF!x9|LoJ6t*e_je08wrBoPNF^j7TBc!`kQ71;YC@rX5dW#EI4f`alLiBQr3KRtpu58awsLJwM; zbZk)czbHEEu&BN!juRpZ2>uYIK?!M)?vU=3Zjg}fUam-Ymvl%vwt5D192n%(mJ^V@+G~RwHYU{2m z?>Pd#p0pfw6W_2X6dm#7r>brI=rN$8qRM)HPOm0*oK%_5On~Z`t6*(XB}%pV`kWON zbM|aq^lENb6`ST7=oE@Ehtj|6y0a(p3{d8nnTlIa!x1#)s^>AY$k8@t<62ZHiqgi9 z@e?4^BPSz!fpU@jlzhK2^PEMwlRWl?=%gL^Yv*QeUXTv;Q|jtDR7hnbycOMoGu7j~ z7SO0CC!?^hec5@F^_Alb$G)cab+<|NdW9McD;4!JY#f!mb(N)o)9y)1BX;X;!>UUN z@tdseZGk&C8WAR@@_IFX6F7+B9QNYj<=6s^Z_O46{Q7=g*hB;LObZF|DPLpTB{T-K zavG;!#Fam5l?z(SY={3k%dr^P$!-7o1yj)XCQKi;-}9D^m$#s#q$JMgtuK4TlMs#@ zn6N5ZQcs!$@wBnpdRZ|zx4`qC_<`>?V>Zc8ubYf+{e5Aht4^)+-#W%Ql6LcV0_(@d zv<4$eRk-0dEXjLv7m2C66ROX}d(sL3;)rF_y6Fpd$HP%_{wVrrh2tB3e*Qo061pEV ze<3_u-?{eeaEB6DR2Xv{#05E6T3$Uqz$j6dj5pC2Ub6Q04GyM8IQ%nO{ni{UdwzDN z+^}XT2wa-Mp2Scg>73K0rN!W7VtL9k>*qw>>U{9c0wybnevjPeR776Xs&)~unMCpH zY^(_h3Q_hf9*vsEsPb76#VK}(-fzJ&5H(noBlz}kDedoK(Voy!%B-V*qdrucpP$cY zLvu7E5V+Q$7s*o8(bG za9>~FsehE>wL-$#U>vY!-V_+XW%l5GmHm~8($RB0k>g{=h#jUY`I>E!H$Oh~I;F1m zTRYgR(jRpqi0tpT3Pg$id~xJkyF>r8jt;foU$pPpcI&j=0y*zSQO`lg9x+Ti>Hf%NHsfs+D{FG~bZfEX4;M95Qzpk4b zE}xmrYU;i2K(AS}LW<>YHZ7t-XZ!Lb^K1qw^?o5O#DlbdR2E*js88$@5Fp0|?5Ffv zRZG6^pjwIT8UO1N^;gB|%leMT-Cbq-r%~ZgPxdca4?1<0 zyvU+_)%tLy@09!RTmR|2+`~|s?cPO&i&vS(r)Wbt{I{}m(W$7wUYs)xtH4{@R)dl! zqmZ9WM2acI?U&e|(>sGRbEDK%HGLo~CEny~6pjoG6fa-jNq`elIF6Z(Q* zSwJ5h4Z$<{LN(fial4nGpuXxvqaHKIhM4euXk5P9@xqMteOIryj zt>df9%ZDUHYk>{ukrbj6U@bx}+2%mn&O+a3-5)ke`U{C$fIQmBjzY(+h_9uMvU2|V z>K9=bid7fH#?o&89$a`8->V3PPz-goM@*rOxxZ@HLmK~9m4{>Bo8J#tfu?cRg`OG) z=gy`6iFBgk8Z7tQT3QIHcP6onaRuwHF5PYI|EYhnL1`8a)%E|ce$ChvMv~3YhjFoN z)QGD?^j+~E(2|B_%exg{XYmO?od2kM0A^LW6;^1uVuqv1Ep2IaM$5X%{85aZiYh;I zimlcpyK%jo<3X0`?t4lEw09i)5u8^ghU1?3VDcFoWvGR~N8rkYbZgrM{?H&WESsQ< zG^^pncRbUHg#&k6VV9F%p72oV`8$m4YAbQO9b6^PI0GS zLoz}X#xRYRdTD=(33J3)JoLx1b2Q}Fe2}4O3{))OGim#oHQAjX8|}KIug69Bg#Od1 zx#YpT*YarMd#$TV2nBI*Tl=GVl#s@>PAK(D4Y8uv6T-ya@tCWAsl5a$5e5R3az0e@ zLc6=b?yeg#h&A(*BO9R{hto%`Lv)qQZE_n~9W{@f|I*~9 zvxxEI$DzyM-3|^8j)tN7cYCFA{R|%$XEz)rI^rmT(@|w*WwV)?L1EEOo3nP`GY91u z8Se8?ny<+&o5bI#C=aaD$B$DQ`6}C>=f+_Ga*TBcQ(MKgkHF}jn&`>T=ac0+)?O7p z^Q8yJhK3)4DxI}mCTEf|oKq56=Zct=%xGmN?4R!@qbh}tw&!`xQdwUcmSc-YiGW|a zkSB%Zo{oPFuYXk1{&SX{y^!|q7gncn1Dm~Db_ONA$p=D06*;B%u>`7UWSO)2$}i(| zfaAGmOI6 zuo2f^5HgM$hHU-Mw8GD;PF`01X(idzm)>ZVf0p?$eOx^jLnEt7me(K%WFtT!F z>sh*|AwtWG^!BUVOR4eMxH}UGO3V?BkrwV6_ttjtDX zr$x7S?|V4by*1|n^E!>YtoS&nhJRY_6ZL`@kAZUteFJDd3J};^;^T;8Sd@ ztoZ!p)erWkr!4Wx+5Pt~mp3Nnih|!IC^)*py^KF1F$3mtk*d0ne8p-=fYMYpAb3eFT*|&7lOpeHp*D{s9)`yk0Mz1Sh2w1Ve>aNZw zkB8a|$>gS(&`{=1gejno5wpGIwiDI^>TSp(C&!ZW`WFqE*QVGh29S+PSMQHej10B4 z|E(o%aa``_>rHV8^H~wg*IqNASPCT6qoEOyJ2yuR1%9NXE0(D;(mlyQ4+fZeCZ)n- z@*Qr5j*pI;Xs#rbv-scHXO=HKJ=A^q5V@z}#(#^8m*?t83kC3S2@;&FtgL3m0%Fd$ zFM^jHH?KxURW511@Z4UR)hyMKl9Gx<_7VoMhGuO+Ae7}@?7;J5G6hbp&*ceP1hcod zH!EfKrHrKXuS@}zj!`u7+1c6SljEJd*EzIL3q|`h;hO6x!TIfOXKEKj8qM_!Zc%%? z!)dI=DZL#zo`8miQw1-4sO@$Ouq2Z zMM)%w!mVNGpf`iryAaCLqa*QEQ3DcslOk%AhmiFG$rYnZ%Mx|_q1NVF$e=Y-o9e)% zd$&NrWR)}4t3KqbeHlYCrQ*zU@aR|R}YL>Q|$ ze|4`u8QX7m=Q1fu?Ey8q@{I9W*Kcj45?bol@ z$mjt8DsscDr6lJZ%iwRs4R+(36rNN)-Zu$p<=K8u!ks0an2iwbpQMy=G$3Lo$t<^A z!nG8<2%Q$i>j`d768Bg0^wZuv`NIm@M#V&^W81UrXbw*t zB_;Ex{NqY;f*Dri|Ni}ZEzwVAEN-dHr$RCTj8MG|W42HUC>V@cA0I*51p$5KLBmyo z6{>Lgy`nE`$ju;pQRUy_3Yj2y2%yD!^`h3v>41+MT1%7C z(jve~F*G!EZzHi9B2AdgvW%Z*K?M#TNdVg_#U;p1LVVCSN7vNy25QO130p%WF7>^4G=r-MshJ4Hu zU|~5O+kg7GAOhpYG@}gO52n2vKLlpuefXt4?CnpnC=g!Pzt)0BQ-e=WP9{c2t$N<# zU_$+i3;%w2Ty$cId9RcsihX{1`sRZ+*lZ`+_UQEVd7(O4){sxy>ZZ}#sbaTTzbWR7 zf{ZARTl(N58PaiL5&SJP%_{bpzrB&+2-sa%Uw`gYjkQHhaE)y3a&}V2djJZ+WT}+R zH>RGSiH(*JvL<&hXi9i^Iqak+rVk{*&;92em58S3>x8&6FPhn~`@K=OV@jligB$Yi zhJRpamfU`M$PPC< zD(R6_J5W}nE~&=*bfJ>U4cNM@vpN9|DEx^nB&`&sE{d4=20e8@wvdZwo4~e*G^TEQ z<1oTxuX4310i76H(5I#-fbD1+c}+aUwSoxwzp{ zR8;4AP^q5^IUK9Xh~Q~+XckiI4=9M6F;yGY*yK1Bbf7S2Jpp=vHl?@u*U#**uCwn8 zzJ}Am!T8v56N$ww&3salyHxRxqg$M~NI&00uhcuuR8McEU@B)5^EE?{d}Scc#KZ(J z>32joXkl?lETTHMY6a+4i%4|av&1}Q$a=Skn>yE^>Qd96b_d=Idg>ru{ONE0kBxGU z7z+Fv^@fIQLaKmEYSef24vyLQT?NeOw@n^;R9T{~=c3WR;V^-%^(CWayu@%xY3Ce% z>X)Ib=XJ*VWQ_aP_fpu1(E75WuUU^dq-20!*>Ecv+%gehqNWa%`XVx zra%la;9oLgZ>Ww7qxWh2@-51?v;RIer~*87HxbkSgbfTksFN|J7WPiWP6h^T1$hi+ zL`PrXO;*wFLLygrBrgKRa-k7);t~>hoyNpR$Hz*FihWcHIR@p}dbzaxY*6jkc;~(7 zh9ZEYjjB&#vv>T{+(*-;uB9cfpo%4&0FxxHvDWy+L{3vH>xZP(#YMvLml_)H=ouM% z<}fO}dH`}ya3kGR`1s|{ppu>ayKpe>=S`;UgHS~4&DEa5>om2-FLRhbTicWG1ThQL zQ6a`g$!n}1PCxheM;Jj8IVR)+-Y-o@|2ZieVM+}s5Kg~JI$Y4vz7BE>Kn7qOkdO|>4d<_~uiK6$KgVb&@e0Bo z1+M;keSZC)9lull`gWWZe~kFZbIZB!ynYX-EPE1UU2oq(pho>j`XHu$B`woRsnFk}QEf+D_b#?tvl80Z>Lh))F8&GK-;oU2{eOJd#m}>Nlx=4YDqfTi-`kLG0k2k!@XNH{)bGqG+QfT#>Z~MBP*L_( zd{#(4s0{3XR)lj84+}4k;#SA5k<>WyY3wceul4lwY};%3`T2QY9HoZ8+z3QUMoWX0 zQ$HUxP}qqSU%U*|l*(`9{}(Fqjt!`-tDSIc@t^A?$0-eRRG99C>LX4K!7OdBpZQE~>Le=G@sv?)i{F2!Qw<^Y`OT zq+O+=&a_2m`YA@edJ+8Eo!qb$;`~`hT!JK;-jS!_qmmKMxBx4 z;N-<@d6R=^BW233?{^)gzxSUnifr$dAaia8d=vW;yY6=e@mfVIN=x(ncf5o@UN`x7 zF`x$ASNu_Hty7efYq=cM1>h_{4(}tSI}+2eF(6JI8UvB?)AF1LaU zN7NT!;GKQOV8q^>7hi4}PI)wCp1SC3G?czzpNBy@Q?|Bt`Vx z4CUl89ss2N3r ziAgR;WSLbg`^$fifD4zI3KroVEOV2!u^8`?WJBHzqxoqEv`Nj2%mzVk^WcC4_PO(e zN_O>>b^X_0;p&w>UuG7Y%n~=7(;JBuI+&atLcib%pdpX6t4pY3$M}GL*p++M@o2Qq zi5@6Rug$x=Ijhn88hX41-Ti@u{*i^VuAw+|e16`&y15l_@><$XhLv232wD^OUz7eL z=;nNAp6P8&-SMf@#2K2kEQOxE5o$;<{`q39uq=XNZoQ~1!J=`0%t;0{Aw*YcH`Ns% zW2i7?xzbna`MjkG!pc(BNkonK+xTguR2JUIkGoX4gfy8{1SQpCbo>ZC!?#5vOrF=` z_M}Sm0Rn({ewn4vdbUD8ImV4}d*(;aiUre;l0xBZeYT=E zx=Vl{HMMz)UhWNiL7kaA`o38 zxk)R?zSH^-!ZKhQmr-b-8ykM&JU7{c2~TYd3{2GqkQW_{SGChgVYwv;{w_$1eB^Jk z1QNEkx3^`qMLLTF_kgN8oy^~IA)Zcotm{vgEx6DM!H%^eJ5~Aj0b*bDM0(fSozb0s zINoJfRytt)#n!nTtm9r#wh#_iQvALs{qZWQHu(^R^LC@-oghm?C#T|wQO=oDwuFed zXv5gA$B4jBaryq2E?zc*r{Nq~4$<$1tN>aXqJ$Sodg>E4f4*A?>rPDYO$>PO((Vlu z$e2YK<=pF;^V74_y}*WD+m9UX`fliiF_o;fgwhG{GyNG7apOnJvrz||VDA;+GT%D}hvxe~?&ZfO` zOpE`kDybx)v#!`U6ciLOJk!6=2D4iWfam%RLc0>EKp?9A!VrVEfI0$COHKW8@f^V* zA%@UEAiz71&_@KdHGqOr4R3>s`sw%lhhh@<$X12GMEykaRtgD#;iPD2zI-+=LGWs~ z9+>`mGs`Knopq|I`K>fjL>AZhu6V3N7D}ZE|+Cz!)UoF&sk$!nk)ewy{o;>CjIR54$1o-qKDxfq+?d=j}lxEEx zw>r-Jj2M5$1JbA*5MiKp%hE}FB>G{UUu;sjQ(RS!99Uc(L~m`a-}YEyqeH#c&Tgc) zVc9(~aDaj?9G0FDPdlSNJFvc@hr0Vl{RJuVdOYMn=-lFX^|WkDG1*)OT*snl399ip zfv+(UtqYZ^KuKd_Wi}@fdC}|Jn+5gy#vn%PG+##BRid9P(L%}0=tAg9!fQQ>1_368 z$c~e0vbmuN<;vEo^o%+fRwy$Vfd*O00VYbEZ$1(oqV?zbHK-A3D#+BS+G@~JzcR+R@I61Sga6I|`*NSBOoPdPn1JPfU1;Bl7{%VTr)zplq%T<>?EHrK9 zh1W6T&*bFwHLkVkSH{0uGD!R0=h^1sNPR?3Mw=O>JUJ}+`DUK;RU^*=$BW}1#6K86 zecCXp9N>F_h9rTM(1oI(l)C*_CSH&ZzWtT=r!Z8MV(930To>K+g=R!cQ>#PoZ1%}ai2nW@^hW8HbtV0% z^A7KYZ7Wf*iQhNXvd?+ezw(jv8IIW3cr6i%Gv)n%s?@HnBzj*zE1UYKyhT?~d1p>A zK#AnI8a!s4J+W%%JOf{ndYi5HBxOajcfJK#$I0i`0WH#L3AM#7rLNT>pI#Q2zl(B) zO48ekN1=nB-+xmLU|pE#d}M7!m42bZNp6@~P^FzKi26$=zo8xp`gsO{6R=0{%#O;! z`@97*#4iE_vR}~IJCcK>UMTDL>-35*Pw{fe%Jq+u1wngDn@N}gG!3J_DQec|J-%&c zefyV~4A?K1TqIKxy+<6cJhg9ih9V3y&K*o^XuImQJob(;nB*F&q|VQZte1&(EH)yE zn_3*N`vTnhga344oEv0b+=s`s2JjaqpSF*ow1Llpb67Vc2pA_HN^3KfhQDJH8*c4p zU_j56_=`H-`W(U3l}2Y!*41|!KW|j#U56y}0I3^w+J%*7)zk&r&o?nHE@cT3Hx0BC z7P77zN_|N-wt?gd%B~*k4{UZxVH8lYmlzC~6@KmHY^*97+r+Tc;r7LXLy9zETy@vR~{T9|ys=`|t3tw+T4-`RQb=A4c`N zo16I*TYBRqclp29%Bp*}ppgq1g8~06ykAy`jns^|6p#I}bWUb2b$RLFV56z~d%pb! zQcsx#6J|LbLj&<&0Srg7XjMWp1JeH<&$wLoq1Y}i@rYfr)`-=2B5Axrl}W~ZP>kEYh#WZh3L^Lu~f7n0SbAAKbVXu z&y63ZDROLECbNYzsJbHx;#Sh7sQc!;A8qB@6;xkI&&3vjzsQA{^!1xX|0)-Vl(x zWu*U^kiZ6gpN8!t<4XZoP)lY{k6d{833}(WjcEqt`uciv@%|k$)s}|wDm`m54lX3L zwVviS4`cD9%>$e7mcIXG_WQH>tzQ}ata2Tz^&cU#Nyjd2!boKOE6>d}`d}tOOj9kk zRJ(NP{DGh#`sFiTB9algCIZ4=z2z_;juSycdIc|Cj)eY1OFFd6URHnMjcs)e4GxH} z*;g%Xy+~kg-P4E`%_4Smc!`sy_g9fyW;|AC?|DNdMO$!U#qvWK6VF74)aS?q^s|^j z*HOia%FmJbcuMFKKxU^}{r&yT;p{on>k`iP_Sc1e9ji@_+HAsAOwg>axM?1Z=JFi^ zh6MTs1UquGLa}eoH%Ul)aefLoB0s0_RpB{tz|DJ0KuN5vtu2BPN_y>Aw_R)f{;$iO zSoVkO6X^M6VHGhO6Vr9b2gQ@qz4@5(E7GXUp`-rLpin{~z}J$ZwOOWU?W^phu0LH$q;ir7&uB!HWLX2=)E?+FD@)cMfVCtI-D# zm7Q&08I?&lV25%O#EujIQ_2ufL7F$!=HaVtAw%fFVTL)Vs&pD0b_l;-c>WlQthV|G zP(B*9pr}EQ)C5PHv3_}D8<JQ2yu}muu!8K74Hv1{!`E-A& zQLG$Z%3jKI3#H@K#zWzdj}J$a9~_Qfg+d-I9oqq)KSNz(nPM}1hdSFHw9JYu;9Qii z|LuV5uZJl~YV<`Wd9jD+Ew;_A7@3(1%X#l+(v=Jh3^J$&3>*Ud;rHx`kUmm}E&5`l zZtk$SQ1<4hK(xj5;p^eyBuW1;9;v8JdhKZ6A2%3PPIE39#I2V0a2d@c)w+&j*v*WOmKL=(oCTpyNzy^N<*Hd~uOKEahft*a5qcfv z?CeZwL_a%4}-m9)+1iu8k>pfz58}tZr9GXSp{JM#^TYh0|zBBu`Xcu zXg)}>?aP9(?{l9_fr97xhOnUTzql!qQFcyprpMUe5JZWo^vAak%@Y4QDi3anN5+oT z+BRF9^{EQ~lpaP5>Uh^Fl_H_df*_+&H`|l-v9YD&Inc?JdBM74`kk3iu?p5#$F){> zH`gCYfoGz~jD{i^Rd`$5C%62~`$&M1EpJgAUrR+!#mdh%6^Co6tNn{?vX@805lvP5 zdb-4xuqVS#CKECarh*IgS?Sf#DM*-wB8`k5IYH4rCf0(7hZ_|&o1>lGloE{4J^8-- z#AUaWiU^G#t=h+QQDoIUR^uC&cL~v-dcd&ehR{pVP*8-vNv7ODMPz zXdlnnQd1fwb47kuH&LyvtuddRe4sYCP;9YnN=QtEJY=SE%I^>p6Yt2L_tTZNyZiYO z$mfWRlN#zd?)?;u0=wbrg4*hM5^g_wNzUZGDaciPLf zh=Lg|O?t-R5nziOPu#n7{09t%*GEOooELC)CpdyRDF4aJ*HO^N3i;54#P4}~QuY|A zsa^X2z&?T{cc=s&s?Tt#1V9Z0O4 z$v0gtx}E#wmfs8iKVt6(a*7#bCUli#bowao>83?WNsgfkwH4$=JqnDsOX}+C8c2t* zX!htO9kyq#WkmJYWAEE;)^+HUG4*}>=A}VfeR{bzbsRc{!flG=Do}oswTy$o4Fs#x z0R}c6345k6RgdI{3PTRks?Q$HLe4l=&z&}D_< zD{u)+c3uh;4dA`F8o=RO z6ZJpN#66tO;B_33VLMlr(!^vgbm&js-+i^7^?k&Ml+J-aCCN-kC|hpzeH$$^YwPmD zOSjYB%KYgAyk}&fGn-@c^uE^D7Z$=}Eb`utOQbvA$qQkBKLIRu@N=9SL&)R13JBnz zVe^U!BdJB@8;$`siaWfK^5p3%Slr3x`V9V774DcyN_VC9{w!Ns%rO^(VL--EAu zVyYKa6#UMYDbJYFf$T`L7=lM|i?(F!LYxZ*d0CP-eEFsbl`sjQF*ID)0G<+U_V|$T z9~4EF5Sau8dW~j0`^+MjhoY}sFk&Yg+?vX^Aeh;6GJd^DSocUtp*&iwFP^JQH=?pw zPP}Z}MzIWeuJfyPZ~(1rRhXEFO$^F)h)QiCS^y5 zoUVY&EN%10Cwk-=nh2Tn4k~cTkNl9nwzgi31kRCI>sef<|G}uH)q=vU?n4Qe$qI2O z!|jNp^;@-3TD6mAS|rHtQNbFf&o^=>Jx!H;SU5#)dYda)_(MTLj|`}g931Qguc15wdohXKY#wL5X|13Iex|?RNpq z!g$fVb@fp#c%S@eOA*$LQlj%knH|wA#5Akz9y^t9jA-506Uz#)aHVHXnb_5QZyp*V zs#%&)jn{<~53BEOcG%Kn`+g4q`$vT(u!HN>)0oU2Low8^-B^BAUHc<1*ar8;HIUld zCuG>LBd;F)^z@|s8mo4Bb(M5qjGy-W@PSjg9RSQN^05~2$K^5K#HxLtL2BLT?_0$L z3ip0eW{-@Hx)L+&oyqRTwtC%;C!SW;-rw)wtE)qDRYj0^sL1`Tf+HYAM}zpMTa1O^ zH%BG`W#~EV{7cf%5v<3S9CkStl{sTf?N>URUAaB3;>&S3?=~LrStt7@JPYbHnyO3a zV}g>3(ohG3w-$pJ78fNtH|Z2vSZKffqu-8*uv+r^Ue(+pM+y-u#$;pX;9y+iEqwPv ziG@YrJg!aacnW_!q7>-MSz21E2EBzbmdb7}jr9E5GSYT)=jIX+`0dZL$irKZLH--5 zVF~t+gM9rrf+r$tHQVF8+6!~Q;L-|vGn=Es`kR~f!PxZQjaZ#lMa7W!A2{lf^3L5I z)rFUw#W`E}|G|&8S=P1iSjU!LZ{==ixreN5SXvse)|Kv`TIDHs)1Irh&nMlylF z`fv$*RZOZfzIvv@7yIXyIoC^CQ!~b+X+(FUzPb3aH8d!=0m%&q1&?pcd%t~fur6`& z;}W9jGi|)CtnBn3?H%1>NKda}XIDgLJj_{oGc!4cEFqCmm+e^=oe@d1V)AADC$NNC zK&CxNL297_NPniKbDg?-3?C#VYOt8L)YbCHi$Wr?jvNtXW#6u_v1+M(t=i6%s{VSZ zW1O6x9{+$TG%33>sEz%c1%8R2Akpp^TaEFXH>p!?$?3z9io4h3kHf53@9_WoPcGi% z{eS3MpSW$wB{mCAW+9^5)f=%P@>m>`|MkIT|$B)K|(d6tG^Dm_VTbXQd67IO!<{a zn4Q;E(4QlPG{v7Q4KG^!v4YdRzOWzG@frLglp-dXa5%P2(RV}b*eC?pxp;V#O?)e4 zKE2)qXcNOFo;$b1m<;5OrnbWN@>l8FSRE8gB@NBYsA8?uI#u}M{^=wz9^cC4JOure z42ptaR1xAc63>*aU~3z`@#_uX-uqzamHlD>2|H@#u!#N!)gEsrNwsOd(t4AUMwt5Y zxwAK%TH?1)-dNj#8BD%a$uGWB{t;QMQ&)QrlnvZg4X6yMws00!lz!!qc8jgx{dYSY zbA0oo6(pFHS;=AUF|dOSKAw95P;}iieV40kZdYetQg?`O1kkk`J;~DRefPPry!a<$ zcr}mTMb|cI_wr!j*!|E;NFwMahj%8Kr`@NsRU!{Gj0t1NzXW41w=vkQ}t13GFkI2a! z{nFx!j#g=HX`}wk(pNXwov)b__=3%_b+_)CzuDbP+{q%}hIM;3*;fiSmo@Av_OSqA zK-n`W^U2OOetLCPP=Mz{6Tc{s`!O!4^p3y$gxzDu)$oF!fnmR+L)iM?HZcetT|;A* zI(g?r1J+{k@E{Wz5pi%zDhh0Lc(O&X;-ER#UJh*#IsHJQb^ms^!qx7cmgY7m1CC|w z;NNxtUhdn43VoRjI{xcZkSYI511UTg*Tg9mmYSS05CmDK_QS?TfF8I=4*e_m;lq2S z!3ZO$GwA-deCMi|r1FK)Lz-o1kfEfHH;ZmBZzzXW)!v+d-{kkaGX0!2j}$aI)BZC1%E`(3cdz48 z>LA0gzGDSp(MoDHbKp>dxcH}-pWX^FHkUxmZsx<>QSi=8D8~n_g$#TjzoW0U)$66^ zNUL(HI(;V7W|?i{=RD9~k^Ed8WN`b>YvzRbHg}Kd)2FGhuveH;0d0qeVhyvjKlv-B zIJFfpl7)X${E!5#IK`P*SnLHphE03Ro96ZXtU6OFvG!z@@dX~Y2b!`2NPu6BF%wA0 zrXDTmN|q{hCr5~%@?z&57)f1n_S9H8JQ<`i97Vd%ZR(Z&KA|sv#1}P^OG6fr{1$cX z6f_*Lv7ZtXiJj;rp|aV}!~fZmzKfk*eW2I`D2F&DEj;UU^qtG*C{JQo>A1C$e(>c9 z$wFvZ6+6sV0yr5*Ll@O)&G%}^f+>EpnPrlqmWAU7SG`tRq-N93MWRF)jAgXsa%>-C zM&V^ci-^H#!sAOE;V-65Ky);e(AzoR_nd8P1WUbvM5bZM3`j7#gFX{esLTlQzekM* z2`nBN+$?VSe5myI@mxaCym3rV7K{N+1Ea!d4H;%Li??Lj7*!UnIo&$qkta z?%Og>tXsiN)W}WWgub$lmtvz(N8DAE{`s>z)AUV+ ze-*Gn!3wsCo9Y&qYAen@{nOrXaCn&4I~eZhX%#~uY-45*`Wk(>KPhAnhA-{q$NsS< zj$)o{HmHqDPJUn4-u{FVMjMKrMuO|w%6FwLK)bW5U?}+UEgvF}**ANV>Ch^>!r1t) zO#JV2ZTnC6?yE%Wy33cB&L41bjkXpdJF5Y%x$BN3Dr^`M|2=6~+4>Q@{3;My>6Hx;;nDTW#=kp1?n3SiQyVYe{YzX9{W>oD&4PA@86<% z`OLnS))-i=$?R%U$Xwm{uU7nTS17TbZnS?os36R{hP|nJ;q5oKOMR=pr3Q6rX=&iY zhmMyQ|flrGNM{#&W3}Ev}nxZ*c1U{6-)T6!oX+UA+*!oDAYT zRRL7gDxZqDby3j=s7jSm)BcV@%;b+!woOP$!K@7X$Lin9*+=`-#>_0gd?FX_T|?~-Fi}EW+?1Kt zs8gv|#SUj^^DZwh?TcNT5Y(TpbAOz749&MJ3|d-PScKVGOzs)&UY^g+@*Y}ae2>53 zJYUK1tdW*#=rdkqvya`9RW|r@d&@tjSZ|ID-dAN#!wKijTXCEIX5*({00<;3^{b(z+tbr$+tyH4Y-vj}-qH-6e>0DPGITk>*qX=@332C#CrM zo-H=_f%kR$RZM8xF=TJg9SuGCBy3J>ea@P}rSEWRO4Ye)u!2s?G`uE%ksbBqApO;9 z3#DkyKCST+j4dZMl_|b%k@b0Gsc2NgZSlzEXR< z=i%Ym09S|l`uX(>5MN$P{``G$ZZi$;Y;`{UT`hahL9Zru$VW|0y&sKSqL9aT zHnzX!Kwyrb)2I9EpLzMb2@xXuKiCUQ8RCzP{|m)T1e--gGX40`QU*_mR8UyXF^nGm z()!_NQGBsh?$n!N9sui4ZvBndl74(}aIj01-OwUmX#)}vdZJU&QKv0R9b`h~y@U4R zT1f)weu5>9Rc}m!yGCjx&L}Q~&<+-`IWb2BrZEZ0)_D(maj*gCl<>lqoX>=6i z<$VD9p3)2h^5OgqM`s@}C+kl&7q^s%rZ8mL3|-l=q}b&K5MgUO7VcLC(d%skXUjK} z&%p8SHiVTE^5u!hMLgYEC=Vk3p=W*ZHE9hgJ*hm)4y_Pgn&re9Z~uMfP0uMSqbaSq z=cZ+;ENyu^r^st?K8OZ4Q0wjpt8Q(k%%{&kqw+CSHNfaN*`{KmuRO-qdizz|VC_H8 z4zQPnbm!4DV7NZ}Hwzg1W;L+W$4{r6>AKw)-kZUCKNk%~%wPi55RYqEx&mvqq^7l-u2_H1r^8s#kwz+Lu^9$3Tm?=5#N~pmf3@xE*6VXOG#KQZal>zb z*s9%g9(!^HI^1-!_K*P3-)=r^g0lpmWeQd~Aj@?^$|Yy}O-g-F3Q^b7QZ|<_oqNTT zZTH~Lj@vR#QABsDmj8pO$WvW6*zXW3q7B-JnBDy5d#PEz;dHl52!af+D(fFM!Fj=e z@#W}_=<~&S&I)3~T>}q3ZzbZ2n9dM^53Bg!RwAB%9iJ^hBW0>u4r(+XcL#GwE6++sF- ze_1$*7Y-8@g@HhcHT$djo9>KHi{NtOQupWO>6~`oUN%Z0laA{VQd~peDltcD7j|uQ zF*AJbN0M+}^`G+lA5k$a-J#yzLSB2qR$weVL}hlt{kx<@cT=)Y>(mjI{)$aY=XCQqYnH|uwF_(D8ss= z-%i6qv^)Zoy4X1jt_AK0McYhwuTnd%k`DqNTNblht^-p&?Axv)m>h?U{{Nd;9UmWl zcQC~~o$Tmzm(kdNzG#wr|4 zO5wAO)TW4&!IoNIw8u6@E9*-#>NArw99kvCqCEvZ+bYtag z{{tojYLGd6aK?0+%*Re ztGaV)z}DoU^Eh<#`Z13Mx}>p~^K_u;m6)>Hww(%ooZrW0ds5i>ZLjUWy+cU}-++|q zpQGLtL33aPx}Zt33DVj}isx~SbNKQkE(W&Ul-w!IY5w!@(oVO8=Vx zV}rJxF+#BAKLfc$FW5MfPdOf5JG{}i@&7wyoVC#kok#xXeGu#n+?dU$J;ePuCFt-F zw&4a}TEYXKgX&K2FLz>v{Z@64%kip6#{8hq4U*db7yNz`ht=;Y%y@bR%2zYgm3j$9&l!$o=6*Bl%s!Hqr zX_E+_>(jI?MH`~Z*vaPXmu6tPqrv43sj>*-koPG^nC|%^-qGN>>~^5M^D4P2>U14; zP?f!e;8kmyqz2rchbKF)B>=i!Qp$xet&Cy6JwstnBjm&u27#EBIQzV*o4 zY4&K03pUwgA<*D)q$9r_Z6)<4>1ROAE7$}mB5{^u}?455z*a$ z{`j~!>5lC4m7KE#9G3>*!*;G6U;}mF`x#%OYL|Tr#O;aWnfHAo!+m;_!}5On^;z5G z!|p14|DkSDd0mNYupbo=7klk;Ef;r`#cLi;tetR{> zYtAdz*@*2X>yp2CF z^9|s+j8GIYX`GBOhU5Sux>*$MdtG~NyyS=i+p3PcW5j)|J|5*nj^~EAIqc5xt{bn@ zvR~qSxE-|FIa=9zq@u!qT3`8wRJrYL#TIcLU+xLC-tA%lo==;VwrA|Eh=pjT^R`RU z9Zv(;>L!Ko^GT$N=-t?4=-?pYW^N4wNIk;yyOD|AyxDS%AzQv*waWIJUbf0P6}kMU z5cU$@F{x=hkuNRE;qstB>3fl~2tV@#!-`icB3V10u5#iSLu&58h@Az6jkxj7IIjD< zCNP}4%6t5S**e9>&5+8%rq@P_42Lb0aimr6ir9{Doje4V6j+*| z5|V-UQ`C-6RmpgrkJrYq=N(?r&V1)7nn}cXr7N@Ee3`}FlrOHJ7php|)8@m5&eLY= zhWl~q4&uX3xPhKl5G&*CsEYJ>0{XI2Np>K|)B?1otM#ku@u=A99b&Bfc&=0NfU(xJ zT7r#lsx;6wUJWBD?;tqCVi35pTW3Zeu<5EE@%fJ+PB1!-fwc=Yid?h0IN$sZbBg^7 z3!(K8&tHKK?h;kZ*2s7@b5-A7ftWk1KEoVZ;Ly^^BM5`=S8yr+Q&>(CU0))8S!{}S#>yxZaEshM5}Ps zv5Jxd3A+fhO+?&z>@WiUboGoEdFAFF5Jq!ygjVovL*SsgSWuQa!Q*?q)pu+smQfSW z_SG0oNh0dMmiHCiuvfFds~<@PI1S8fDey!tM1MlCFY7N_4<+uNGTTW_60UT_F^}Xq zaCAHlW!pql(@)lz3)_k*RpFvV8ThEsOrwO9yIi?ECzF_| zZ7f>r8}c@>Wg(%;IDk#HRyQsqYh2YShJ5r=e>3A&tZWIF@zdbfl@F8C<5!Y3zqlr+ z#;>fG>z@|&V{`Lm8WwR-_`4WCX&4A$i@k5{A6cMo4E%NcZ8;HLqeSFY3_1D{L0RDP zvZ51aRWm$`es0DV;2HaR_y*0xxV8cg{e$u zABU{^LJczG-XHug9Wdh0XlaCOiH@X!g{33wfm9LeQR`$REleN-6Qh0T@)p&%n38z*d#PD5lvRGi zU~q_3g`VL8MFDE?VeSGmzy+CVVmi<}vBew=<_MjDJH&n2$8w-MiXnbOxm1wCN%4>c zGr-hMjR2hQ4No4&Vg6Qk%1sa>Ml_-E(OFX-0egbh2g4Ln5gThO(EYoRt<^#&arAB=i6b` z_Sb}5GD~)jAvekl(lR&BpBE#X80W(_xv&);Y`}FLW4Ogxs#t$d9ayO(x!bvgN}3_f z)~Po2|0ecd5!$ez8}qXOo7jKr^L@Qh`){Cs+5f*N&m8POw}OBRoicL4c3&(2?kY~5 zYavb|;)L%X1TtSQ0d*g9J(dlt0FBV(h<=pYkP9{_m6M9m`6&G@mKb$JhI4yRTNSN{ z4pLi|CnfKtGd+K_q?!`yK-+dK+tHy*ev6G8x&gyBP^!pu)z(NQRS2325e=hi4LKuL z)rJlN%A50QejwMY#8=RC7ErT(gLD-H3OeEKhA8Yp z7nM8%qgF8`*H}zc@u8mxB4);l%bohV`*LyX}~jG-S7+atNm&( znAY7&MC&2Va15;l(-pl~5it)KKodYsqt+obfO2ehRsp~dL{T$5D1?BeW4UjL0R#>z zqa! z)lI$XnMu@Gv!+G$!?SJ6aj^tzh?gbID95^M2YPdFyfC}wz}sgpTr)enN&(#=^ne-Q zS`&Y+LomS|6{H=?K8?8TMB6jVPkT=j`=4^~eD;1_Cmk2oIBgnTykg7}JP2zBLBi3UmQ!k_yKHV&&9KW-o?i zG{`)@HE8G>)d#kc4tjgR;84sb78JsKV@-c09UDlcP5Qn<`fWRP5!%qLsIH|7sCs)9 zpkP#Vkn8{01*=E_N=ZkCMys%*x!ztSSiWNr<`)XWd>atveF$Tq@X5=Fg#6}l91?k0 zz8^J#B5@RC!ybR4Z;Xq$A<-eQp#$0GYYs$v13AE#nH&%`Rj`8qV3nlOLO=HI!HsNt3v~WDy$O*FcH$2(&tuCUA&z_Hql3c zO%x#PlF`&G!>b}tG@xF^9Rd3s&v7fr0lHbToGRnaA~Z?=R)GfYY5=-^7_NV26>%uY zwv0^VK%=K(P3K&z$8{{PU?5zvEH_s{MwLa+<#dcagnPPz!RHwJ<)$mTfpR`wczI44 zJcl8k5vjztqC&;u3^@ZzP&YceAF=!_?$bp7)2pyNuh_p8&Go;5fpr_A`d{Drb<6tS zVmxi=f0E?*xCx)DO-(^gji31Ey`zKgTW0ReYDN(0|+tVx@t?c5j4A zk+vF#d+_x%2bFc~I(4Emkrhz&`&7jzxv*_v-L+DRi;qDC7nUQX$Q#LAmi^Yr8(DmB zinSmh5?lH4Aq=I|NZoake(R-3W3or71e7yy&lz}-MiqpLMe#z1o$h~|qAiJL8dPk> ztH+sZi&dOL4j82j;g5NOYQum=Er4zf*$yf~7ioilI&VUJ;UH5(&X{KytQHn7p=<+o zwS(djru7x$RKCrxP5;)H4Y)eIN7)LChoF*_OzAygN(vsqX_VJw4&-r(GE2!g%K0%R zu^xs1v~5DS&|5W;5yO9fWkOxEL4~UEFZLnh5-r)xDGTinRFU(EuiTodiux(byzikhKLj7p`%#hmTU-;sWys%!bqva`Vev4 zi2#Hm89Ay%gSzR4TgwLDN`?j9^#jrGqC3i}@eXGQizTd-jjg&d7PsI!L=E6k2Sg4K zm2pqqMu30rXApkoyVpo-K`@A&?lInq!q)I+EE}&TF^(Lp@@#9wlgC)HtYv zA?HNxsW(~w`Jsme_5bDb`M#L{Z=ip9{a=iy4ga6CmSY#18gw*vmIkLzJ%p)GA0*03PbBs zX(E5TZlvVy8gd+6LtqBDj%OCZ`hNOTuTFTSl70jzxwyu}fE;lUF=bfNFbXDtSwvJq z%)(d;^#F9XhBX@iUr^$k9=S8H5*`TqEew$v;2_(8MFfj5;{% zL4#hf3ZQM%!K#`4h_z13yQB{SIrhU_u~mOXvQTEaFeX4TASNyLJ%M*IL?3HN$n;8MKP5M2U1hqf`!Nx?AVNJl}$N1s=s2SH*5 zTEe@mpszCdj$q6DD#7WagS8S~I(=9}Z`%ei%7vlUSikKs+j0oUAKues{b#|43+jLW z&G+?1^FQS`46Iwu|FkGi8|%OC{$)(TMR)^$jbI)o!?_n%I8-Nid~4D!Vz>-Yxcntz zjfpP>DAl_Evyp>0(o_y?4ZY~`V^4S6?8FK4krHUw8i-^Uu!tg{@1-<}psd%BDbxxN zBZsF@@K-+RFbXLmRus!bDi}5lYZ`yE1C=hXWHIlch>h(& zC{8h1v*a_%3+>Mi^Jr}4k9q&1nn~De?JFq>2nsbl6kWTymJqMkrnZ>l$E|;&d><$# zbSE|Dc@8|6tiCC$DFS9SSxt!ROsPd>Km!bj;U{aqQMogP>Me;KnjvH!Qio+2nL;#< zNm&*xiz8a5P(Arbz%I$=B!z^;pjDesa7s;|OGyKRLoCNzXyPW!n{XDN*vtvn2!}Pq zTO>X1gtjdL1*OOf0?QE4O$~n?X;f>K4|IC)MAPXenrJ@T{6id;103W!I;tVUTlAcQ z;UK8hL6O?0T1&GsI5NS!s?zpu=)g;k$=Ap%1PVW~pzRCi{E42S$tRqv=~J>mF_2ky zD+QW{!>hIE$(D3o7$H=*ARH<0<{k8v!>g;;hqqvUG;d^eb`AP0Z3h%bR-9RuuI zgxwp>g-FW@lYwQhlo17T^i0j0S!0{RtwqI>i1Zh6WeH+wEkJ5{kf>q!u;F7^QNey< z@7sED3Y2sQyX@=_a*@M>0{HyYSYr%SMiY>udyIj+Brvlte57U0n;LMSsaaJYajY3e zPLKneEz3aA3^%pEg6My#4c7ut(*Ukl3l{Uwx6riD4oQkmgdWWQK}9n?KZBvJ1zGHw zawB{p*eh`VS+g@rAlLFCrSz%h3xicY%MA_zMG*pHm4GMmIv9R58=L<@6cr6~%1Pz( zy+GxZ_6u_!9pja@GqD_%9iFQjSS=%WJF1`KSXIKwa@J9-05yNY?$V?URJ62iX`O~0 z(-NfX?UGVKMN{G!8urdb2GK4J%bN0Rpwx)C61vH%207X|ZT-gdlHZ=ZQn5vZe^E8) zLMfeTnEpe}3&)f_(rYpf6FW#LD}~I@fWrC#WESNdbjPIpNm4v>BuEpPuwWofj!X!c zcu3~lwCKWBB8PwAm^3A#XEc+kES4-z75{i9MV}(TP$Y;F7(dm^rLRMRaFORG4akwQbI>NIXeKV>DGX{9GjCG4<@AV!;8 zti@?LfyjT-dYbwFUCV)Gw4m|d`TY8L{P(i|e{r7n&wt8ilqMK^fDr@Y#Pddie~P3) zaLC9%o?k@CzBs8stA{}&T?M8N|3G1+P9LdpHS{szxZH!#xf)uGG*) zN+oE#mWWwJhp8JlR3sa5D~Xj=F2jPJ4=M*0`J8{1yxKRb%hZcx$WlkMEaI2m(?tFU zN4w^+0yL5TMDR!RKlk?cF3bPLc-oTxriL60Aa@GVb3cBVi(neHfsUPUP!NPq3MMQC z%vsRtfzo&v5eXji-`4`iMIiZH+Yn#mL#0XCqva~yybiIm-Uh2iHo5i^I#<|a{xb*I z!p47p4)jLne||%LV8inKUyP@X`OgmX=qAg>saqy>o|lQ0Eo@%y(@&QGjGwrxv5Z_k z?;9K2BIy}_OY7vs%NFHAO2@e%x0@sO{F7m({q3=~nzen<5!W!FBevzZ;MlRCf!W!i zRozow0To??B1gCba{i4RE#JezPhoKj8svX0a0pu_5spL3G3u#RNeOm{YIb&30W+Wg zFFN&O z6tzlV^%;0I_aOq^1meCKwiTb61}%R`1n40!1iHmeO8`umL!=KwqFR!x%y*X72>pWH zI97$W2pafJ*}km6AsIo^&MdGTUXpt&=@g=y{su5DGsjD}!gA@`c9GrtDOAsg`H=3} zx66s4{-QA-eE6jQ;G2VL$iZkkc{w-)_@BH~n9Jm%Q6kT63sFtn7RrWp^dx_Fhy;wN zDI0ZZ-gQ3dz|zn^m!A{+G|~U3p=0W1d4489Q~z&o%>TQ-fBF9JMS0rL|MxRq0I*HOEScX9}!@_bSwclqWUVaZOH%R|CZdq<4IiJ{?>@$U?2D*LEgd&0t6(A+_%krE; z(d>OQY=`z7-PC}Ra}FNV&RTypgDbFa-TFa=r5oBmJicpm*S0}09*iDn$VEjLX`q{^ zrvm13r#J@d&!Yra#G2R1!jb!%Xv8#j1df0q*!zikH`=)us+nj;{)e7w5(qd z{go7%s``PcK~Lh)48(syUCSY8Rlyc!?+vo?rmm5#B3H6LBcbmJwoK3hZ!&hQBGeua z&1GWvuM0>lF9aMUZ+PB3C@G^vq@3B0K^11xZG#lIzo6{de)VVl5(RnKsBJ9Zt0 zXg48pQ4R%+9JgwAUHhC&=l;D=S&SilrLC~MBoN(vZ)h2LL=PSkwAk+O}5-nrwGqyZZMSgXfK3UGSOQn zhG?e+D#$*-bc%n7fi=K=$eBolTS|m=k}G?@co(Nv7`@xVxh(00g5awHJg3@{pMCNm zn$SEt%aX_${?b}(WgGf`6*@Z93hldsn&|%<)RL!5Bew&}xFZx&*oj(DkZE5_XK5q_sZe@SYN`IuSWR)K}#ft7Cde>(w z07=E8EqQJw-E@ewLnJY&kYYBBTb7$*IyllNCDdy|J48NaTdrC3U=5!3PBJa4Fyu>gSnhJjPX;Fg%pl^ zlN0ENV90;Q%$D!qTHgxXb1>#bvkC3Z#gK2YnGT!rVi0Z6eU2u4S}XH3;6<}b z+yO;zwND@&8z6+3LLiC*Rv2+yBjPSU&%`IM1B?KZFssZ0;V&6Gs2HofC zbxUbwzFs%p>=O67wd|WoQ;-+ZH`7rgCUpeO+%wX2nuB|0L0zGZ?2YG$)2z`D<|F(T z-W7VHoh?i7X~X|#Ti7i-2p=}ubOAQ;|K-CVfaj6AgS!$-O0pQK=^|cq$on>28F0@pKb9f%!Xh$RrL$cyt^^5~bQ=Gnq^Q zJA}Oy30*`9(g4}*1`jplzLqGkuz`O>jYqbWoEvk~?=@7^HRPw3<~K+oz_WpJI2$c$ zac1){Qbh{WP`aHdRL@zZocPvg;Yz&~hb9f;7yAfkHJZ>xH#yW|jfzO=)K#PL2*MhE zL>EsPKQv#wqj)oTjyS_8r-=5vKYH^KUg@BHQzLG;dE@$rz$i@3entgF&O6 zG~X9VHu*%3qV6b7C0LUERoU=x8kmKteYD$fhuvb*5ZmOKxjDxgG&E2Dm`tqahKnqw z^R-EW6uof){WP7`|63l>f=G{`=w5$QySW6R`fz+|HsD(z&oMiuGKQ13CRK`;G*ekS zwhATpxB!wwR#xXGO2X>ybC`dN6UWmz=_Vt(O-UDRwMkPQmUnV*_S{8YqVf71W|!14 zHDQ?)marq!T;_*H<(8yFx()v?EjpJ(a81ttuJ0S@kH&uvET8{foF_9E2k;HG~qZ* z^S00H9?IzT)ybh~@i0zJ$Fgg(EmZjq#^y+pi?)oO5R`i{8ur+gqV3U>vv6}5J&eZM z0<*aP3_il&9Y--1C z$K}brKlfeN%^Xooh&Eb}lLdc!?x*B7=4qR;Mwg`1iLGiZQM@q4*yvlvH1)~w#c=_x ztd40K=}UV$nOPl~W{pulQbEP3;EGR*ZwfzcaWxhg#Y|@tLYjZgNzl#p0d8i(Vz>HyGRdY zaKN6xmM*d)jI{?3ng>l0tat`KXeO9JDc3ow*_1f2uzP?tPcLeotKAPzNz3ciS z=Rfl6`qnSs|FI}f7Z`&skyP|DS4MQQ?3ke7>4rw6xDAU_u#B*p=>mHyItJLYZOd^n zz!hW|G$aO8pFos%r@LuyT%dD5KVJ(b7=QbI4_pH2;6cw+?UFxmB%d9qOa;{9o7CKM=kDd0?P# z`Tn;>dAh)6b}yKi4LkILL$sC=!V;OxFgS27GOFR%7j}!A#mGvb;tIWCtjD!%y@-1Z zR`epyR9&P@mO97Fj^)`zq%cMUhE>*!pn%+IL<9~8gw<0snXWFdXUChijAt^Flaqf$ zv(9M9My7_$qK>%sPS(~z-X2}&xu10q^r}bHBO)k=U&c1*Ux~&$kuOE#ze#7b#{$Ha z%ql>@2Y$zO;Mqh^^-EE>psnu{{nqlCDc#ft0kPoq@=j=Hs>p>zdnO<=fD=q6dOfsS z@(hE8O42QDQL9>Ksu57mMTTL4{g!`YXbJpu743+CPRfZQ$%dXs_7cS01BK7 z=N=iCjT{W7D|)d4iqIq~5ZxP~=OAjxuxwzWX-*G*1s&yv82z(ikpNX_!ZLEyOlEV4 zoS_b=#6PgzD-fHBbMvN`P|a2y0(ALD7Hku!|h5 zvSo^XWoW2C3<`wDT!e{@L3eU&(!>D)CV|E=k&7@G3og|g_e@u>qA-ZIV`-{x^<+W! z=IvwSSru%dPy+IoeeQ~J_tu3P_hienr7Dr z77TWuFWWv5oB(T3H|RHR`0<&{S%k*F6fGN3!%)*pB}A2WjEVuIU0}FW(oNmf37j(o zD6)#{8Zrq2kOSmr25dpN=;+i+1T8-^VCxZ^-L^Pt+Me6ILS`n{_-TLky;Id@GBaS3 z&v@u#N;NGFsn{yHlVAq0i<$uhywOxw00VQ^!i%On>Q5b*BR-u&ZFC3J*Ne{z> z5gDa;11LrP_7K@FluiK_V<5Hx<@n~|5#S(fc}@|v18iGR79A}K$d;iT8Q(GoM7GVB z+pmHv?byfT)KDaX}^%^pnqi`D0 zH>^o&)-bC}1*0V}8SKz77M~Q$9^3iQd2epTv8Dku0R@m+M)W-vj8!1!z&t-^A1g=?{_mpMPp=E#3y89j4;WX{zoP1t{vJ}RYk zg{&%wu};Y|3_wd#e@mPKoOfuEam#WQUqKV$A#Me+zJMZ5x2~F83ot_9z^JHpVRsiT z<5-rP_2WOW>v%LBnF?l2FZT{1;Sl8$kdQC7IXx36T1j%*~rlS$&xzy{Mz(yec1pv;Vcc4Ndu2THTU6* zOc%k~9PB%`aOVe^Bq5mA*HA=sXoX%pdC{?_q2TF|_;}7N>cJD56x?hmz~U4#skdbt zkLLhT%mvP6fENPDBy)i|qsdBZv6(YGHtH*Nkjgf41gmV2SKJOML78gWy{uwlxJKZbY}%83mhjBr8h?WgA}L z<7$a!sm#LH{>IaMo-5~baK&u%X)LaPW?F16lS+2JY=LuL*q%a2n|;yy}IJQ;H0io=6Mn?^Mn zzU4UgzQge9pCro`zjw zTO|uksX&5rYb^MBVRx5QHpRh3xoMBhvbA+euUoL;ELrL8ekx>)9a#}wZ4CWQF72> z51Fn}7nO@417vd5Bw0a;Wx~03ud6qAI4tZ|TgMo^h5fJvWVwztE%RQ&2@|%$Z}xOU z1IVoDj%8Na!4XHNk!w_0XPZ-ysSoYwaz4u@oi%G`!H*9ka#n@RqcKM}UFw>5Shykf zg9n9v!p_dM%?nMG7%@8jmUe%V6EDNg?&vTgr=*y=>ISl)3|D$qisyW=@orhY?q>r%*i~9voGxlZMBo*1q7(TiYRFUC_`BMX)$M^WWqs1^=aFC^22^s<(cBB_0btbFCWNWBel20@GMN$i3zOzA( zhsf-d7VAVQB<{`&CpMisS>xInhcg$^7k=vRao zLsN5Lh=%RbZ$z}xAqg6%pAY8=rlAkVV$reL`p2(Uo#*<;F7-XrLFG3sn!QO^ z<9 z?wErxGTndG3?3eU6aWMr2i7wH=q_S8!5TvXgQD=`^qP(doET_zg3uz%)qr)22(}Q!N>0gSV6liW-f3y58Mwo= zB&dH{T5vm1D%_!t#u3!^JGzT@QvzW9Xw%Ln^rNVa9yV^%GZ`DYm1gaZ@tk{wfRI|K zB|lw9BX$<7!-(D$A_v237myGeK|mLv7@$CR(OnCvTc2mc(M18<(nKFkMk(jS6G2HL z#!Mb;wa#0gLiL@{wsn(=jZjhuf=fDJ0+>f6)qZ}yjOI547@1h7sio*#q#CB2AVfF) zjkC1?TU7*Hy^1htU>cfqQkF?=*CMSuY>(KsFxKhO&^qgust^^VJ2;9BtOnHW3M7Ad z562aKpUdTvv%zqz%smwh;Bnw=g@U%-dR0ck-8MYzAwQ)|K#gO^q`i5r_|JgC`T=AX z{rgpCXEUKeYqk-LSXEV?^beV}LI0*|K*_9$O~k>Bta~z4(z_u_ z;V%u)B}Z`jX&cj`2UD*}S;g}>%FllksyFO$O3D-2YKLMo)4ykAc9!BV(=h5fw)ev30b7fWOoJ^zXj6J^jqj*CNN3=wbx$XVbJwoC%vkaA2VGEbHGa8@A#4q~)^0OWESDq0%K zW|9z*pA#bTG9vPwK}3E55RrdRMubQ!wpSeK=0ScI$g90-ZzgkKw+VJxHB>Di2ju(L zg1+9q-nBeSLZ3(w38o(eGx|HIoZ0f3tbQAtWwUc zpd8P&m|Y9pijF}Q9p7$;O=Ib=*iieKK1Ew0vyv;oG+e~*ijM&3E=ER)m{`!!xR&9g zZ0qhFY9_O0&3+n7#{r*44gxyQ?S^EuIE9TY6L!YY6D(c$$A+)E7+%Cbawbok*m`{He~++@Hqje1rE2hK$fYMew+ zBo8Dk0BxNQiUlcUsSR9&CgCX!R4t07!185IA%fjWIT;Cy2Fv8YUV;Ut6Y&gZlQEcT z{b~rT5K9O`sti?g=v!3u?ESEi5$eH59RQ?O%UGbCCu~>nw*yJsNfe z7LcnK>4c){ZpErvWn>~k`Ds`Wxm`tSJ1I>bVX+ays2XzkWjQp5Ly)|IP7>W`BgR~# z-0i@%XpxH{QkDgON#XYNi~?f>k@b(yo3*q(7S?I5c0q}VFKE_*js>N^ozEi9 zr?`kr=;)T8V2OVbiaTKB+M0zh>0SsdF&m*-Cv*(J2u8t9O@`;1JTx|E2-vt0++k$! z^~6CXVTxhG^^+lD~D38@!YBPT~zD8sH&G4iF>;IpE(bsToGb~vwW8D zPiC1BPmIB}K&_uJ%U+C1o&gNqoWhJ3M9-whQ2tEUb1hCshX(F(5VnjO$`RoD=)e6r z+rn-x0EE%GM{2K?kt7tSN03 Date: Fri, 11 Jun 2021 17:03:41 -0400 Subject: [PATCH 7/8] bump chart version --- chart/Chart.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/chart/Chart.yaml b/chart/Chart.yaml index 9c01ced..5f0ac86 100644 --- a/chart/Chart.yaml +++ b/chart/Chart.yaml @@ -1,6 +1,6 @@ apiVersion: v2 name: anchore-engine -version: 1.12.15-bb.0 +version: 1.12.15-bb.1 appVersion: 0.9.4 description: Anchore container analysis and policy evaluation engine service keywords: -- GitLab From f303790a46143b9a98f92b6f6f55a69f1446a7f7 Mon Sep 17 00:00:00 2001 From: bhearn7 Date: Fri, 11 Jun 2021 17:40:52 -0400 Subject: [PATCH 8/8] update changelog --- CHANGELOG.md | 6 ++++++ chart/charts/postgresql-1.0.1.tgz | Bin 8688 -> 8687 bytes chart/charts/redis-14.1.0-bb.0.tgz | Bin 82989 -> 82989 bytes chart/deps/redis/Kptfile | 4 ++-- 4 files changed, 8 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 757147f..0cc235c 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -3,6 +3,12 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/), and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). --- +## [1.12.15-bb.1] +### Changed +- Updated Redis dependency to 14.1.0-bb.0 +### UPGRADE NOTICE +- A clean upgrade job will run which requires complete deletion of the previous redis instance, which means downtime can be expected for Anchore Enterprise UI users. Multiple values were changed and shifted around - most importantly `anchore-ui-redis.password` is now `anchore-ui-redis.auth.password`. By default your old password (whatever is in the secret) will be used and will override any values specified + ## [1.12.15-bb.0] ### Changed - Updated docs for BB documentation standards diff --git a/chart/charts/postgresql-1.0.1.tgz b/chart/charts/postgresql-1.0.1.tgz index 2dc53941f3f33ee7e388f24dbd66e99debdfecc6..89672a7c32ceaa26730e7451a05490010a0a6dcc 100644 GIT binary patch delta 7429 zcmV+g9s1(%L+?Y7vVXDv{Mn1WZw9;1_jY%`fx#2w(fZ_EAok7Rv)ih7?qB3V8Tkb> zPG~xW#jc04toZqTa1iXi^dihdMlzw^olgFaL*X+VBl!Zw5Fvpkh+{}lie@;$sQ|v@ z0w=I_dUpK7yYp?hCSndK1)OAa#0dwQ0{$d$%E^SpL@WWNk$-&21xh2tBJPJY$zp=i z5C`6zCU^*QAu>Mf_ph(7gL2jel+F4c2_D~IZ8#4 zr8DmeFRv+!_|WsAtnK{p{Gzj-5As`zBw|isPIDGw1;QdTBVwLUf{-Ttt9*i4iUsEV zP_8xJUM!;F6@O-aOePGmWxr^CVFzY67zDfC(~Q5f{ue0DG5-S?!0PqCyL<3rx4!-l z_6J|r|Ce|+Hj4QRBtbLmssER=dT7{yx3K}|84k&G2}lF-d2>e&=m$cpG)(h85h4kLNgKSnx{IyuIy^rXkLR`a>X+ zV#W(3xQ1KcAQ9pkv`@KjHf7% zML95DIe&6LbIgX7LJXx5O<;EblGC72U0eN|MC+}u|i5fl5+ubw2)M>$oZMY?g}r#jDL!(CgvC-%n8F0*fQP*VAGquTWA#ELMmfjNQV`jSD80V_L zAx)=bmNV=pc`Qg4W4~yJ_x18BUc8sPvO?}OvqDPFl)M5Ym6ML95jO)HL5i{bML}Se z5Y>knLm{5#alE`2+68;KrtB)FDB}H$>VN3{lVbf552p`&Jcr-ukoqRl2__&by=9H3RB7;n_bQ)D3Fyai!Gv%QlYs3u78$- zZ1&RxNx(z6^}P)Mh-rvoK(YQ$u$&9^eonb4UaLatO|3w(EJfEPmn$1~zke3&9=r?& z!Jz+a50YqK^GGyb1Bp1Hh?dgwaqoiah{^wP%X4t$dB+R zIL&Z+E>L*2tv)K^yJ!q08Gk$g6o#1dcQnF7IKwFVl@WnY(@+jPC;z}hc=?*hzw^lm ziTMzEB~S39i3FiU0sXPRK&&5=N#8k5$U*IAGx?7iZ)aNbA>7<~UV;T9A+IbKEhqpO zA@rKj9P<>%1>{ToDWgnaW(!@Q*$@_kU@thZuN=`2TrtyGhpJWi^M7NGxiG%~5}Z)B z9Ky5xgLlNd3$uI(yMsZZers+;QVb}Hh}mAkoC}(O>5whgwYjh8)P@9_&ioW#`v#i7 zAjn6C&-zmmV-4Rl`mQ9Rdu zt8K%{+w&6`z{&e#iGlnIKc1bw>!=P9T+cC6tU_TecL|ch)~3KoCJz{c%^fIy?8+aO zxSQKOhYm@dUh?r3399eplXEo-dvA|^ICk6 z-Pr4+pI@J>YwTPStk#$$h=SeIVy%^#ib-EgceNkHBq6oq&)Sn$NRuoV*e{lmlD#U6 zs=B0_3#wdB9>;7!^nNLp86LtbE$+P;c>r=j3}Juo`7_BMJ}L1sely}j`0%@CeDCb; zBl+%o8sQOT@_!H#+wH5^=1fC@Zp9W=Tq!j_hMt#VAq6;lXjC9h6k{^S61gEy;k{d| zWGI1UxHVp;;atoym>LO}-8xj29iVBvl(H$;nlm}bA!Q7QLPHB< zBKOG{O>nGtTXjA%9WcyYiL^?_WdcTeF`WPRTX`gp)qh4?>}oVMSje4!$1SU1OK_Qx z@>_~S#lK<7sFYKdpgXU@Y}JvKb573J9Ie(6anXpFV! z&b8o3BS4&!nL2Sk^z5$IgM!xAK%_YC%PG*`kpJg6#-X6>DdEbKso*|JBj4$aKfwa| zQ;bB;uzx2@o}0GS-sqH6^Bqm6@;J8C8|Ma`E-+&xDg}m^EO06Z{ZGI!iir9+=S)%Lr%vjm7H6iSB~Fn$x&|xlJ}DomNaKzv^GQU<_7Gfat{!}G>>ChwFd#* z-32!{5S-x{BaQJs?AB$txo z4}*R~pD9VE)Z}+}-UWpj7Mi3=Jy9qDlq&w_6r>S<4`PFP!c- zOyE=aJEv)e#Qd;#BSm=>G&*qCgIkc&=)oTNeuP6B;XeZo=X6_*9Zn+yS=o;;4+%MZq+UJTjpRyj>ke3F--H;2X)ymlCi*OdP()3(Vy2 z1bknJCHMq4gh-^-QPhf*vvn3-`?!0c%FK7VBVV+{V!l6+PaDZus$6kR)oB(|o<{Js@2S8;I45a{Yv%yMt>E7f-xcle$qOr#_pBmK&2dp#F=9@*E2&#HdGAFQ z5h;bAA1NVSsritWDKb@Xm)PMMrlHu;j zDjj~ac@q$U6aHcFd%y(}IS)`2F}YExcjm|4=C*Bnbb3~An=isYj3I8`1U$oGAU8~f zkv&*Slq?k$XRna5IPu<(mb=eh1OsLLcYEos54l%2VX19g&Ir(Ig_BP>%mr@evP$%1 z)P66|eMU>Bl~pi0J-&Q@^ndQ8Mr1Yb?>D|N^iY-^c2T>e^bXVY59_et?ygtgmx_6k zV1d*oB>~;_%*?R3%0Bp0%B~TM?uYNUw#RU9f)5`yG|t-nQu1G`{C_#eafTTWMD`S} zAZz6R=Ywa@>+=7L7yDo3|1a^}-1NVL1xbcV1trB&$#)JDNtSSqhkx*0|L)F{rM#0* znNrEjv6lOd`cb(u1)eGA8v{+tO7_bFYC#0r;ZUvPVgp7AE|eR$AXuJ;aPVCHNs{w? zIwhZ==a<0ba`E+!-~Y}lP5Gt`WyFP#If}`Y;0REbDdYq1SFE9{@GnQC2s>nV7KMb7m31%G83qZuP=iWPpAO1otQ zO>OpFvv{g9X#uA)+#Dwh%wEwXlXJ88m&4s)&mZi-f9(b@{6Pfh(phlzQYqLLwuw%nnsx0g7|Dr@ zL!?|RYSEY#sDDc-se3hLRl#28G;wFK{@eEBwooDV{<8U?p zH=@3(7l9TZi2r7OS8mN9{Jv7uJ(FoJOp(I`d;TAsT zR2cLssUhHqT}5f3^R8iKlJ|XuBj)+U+WL9=xjUu*2Na>Aj{_dei!M&nqgue1-rcGeVG!+siV^Kn>5f* z3neVme89b#A@uaknHGL;yPq+dU@^xz2Oct%;g!8t=YW6zjg0$=o>u;!EyAY^1G$d> zAM7{$|98Loe|(vzpaJ7EB{fwRgBusNM6m|?BBupqvjbP>-6S0P69sf z*W!QmI!#9o#jByjTGU={VN~^0Xdb4!3a{}taU)2XPWfF&-Lhm=tFKe^d_I>#A&9AC+e8Ft2(DZz$KU-|zRcv^(I=Iwx1Ct>~h--3l}f3(vKeax}rE?i+Z^{~0xXSc3# z8A64f)hpe?;1)bIc>y%D3lZT!MDxInN`i20fkH&t>~>nv*3^I zJuZJEjF|W=TgtB0C~RYFY;PB4u_B&h8;15H)NjbteS}SUC+wuI;>MwDIZUCw$vp;*@cs!mUKKH(bIgS&RsshC^a3O!$ ztwS1F(4^52j7GWAt9#zXoY*)I6G{aa3}upht%P2m18Ca~iAhrls0>k|0oB7-ZrfN+ zP{vOC@Dq-cvR$K%+J+2;S7>HaIWbL%5yK3B%n2s~bI@`4ddPxtTg+MIPCdp6WlRq-!K{`>7w{7@J5^F4>)l+#CT@ zr!3y2Gs6j8U=DV;UFy;#qbW`W2gErIiHiGJ1}9b%LyuLgDme2asD#c&b`iT#veX=K z2wseceC<%*gvW7Xv=uFjIVOLs7Jpo=@~jxQ_jGI*<=8~bWjLdp2+Ecnv~g-YhBjmC_1Uc6f{j44 zl>lMF{bzFlj-`QwZDZbW$Rs}WjUxPMmK6BpGm3}U5 z3PqrefNfD~B4TQ^B>GxI&nh-G-?r+!(HX(?uHs|^o01sUa)7}CF-aR0!2a>GxPBGO zrHwk?=-5furC8ZLR8N05QssrMu|pe`L`C1F`vuAPT8tS+T+vc8V&&2gdU{f^` zj4QC)a=gibJ5te>i>dU4*i^52RJlaeW8Iw=j~2 zg-GR-v!B}C2r9JstdZ)l$d2K*NIw-S6D^&>1cg@$rC(lk&_-dim2)MRW^-ii!3IXD zM%-SDO=&bA7b9iTYay;uHmO4rWo7!NIyRNOP7k6|6Pr>2I#&BsONO!1cc7IvH+PR5 zsFsl;|ETN?HW`18nz)8YD*?jz&&_)GfJLvcDV$8&c=71x{yUYR zsF@V)jK(UT(RfFK7{YjWFi6&6q_C-J>nnfK*11rpL*OLBeu$XssA%(p z)kf+wrLD@{vzkP4Vq4Vbm-PT)ydtmJ8XTM0RL)h8!e%iDc7xr=5T}VvSxW1S0kNJ<-P!6yubJSaY}(IHe#9KIyP4?i^OQk0I8Ua((@@> zqe=$ zW#ZK6-YDK`E1^n3<{AMLlv!|Y!ZL2tm`i^~{K3+wFyPpcDbrpQB%M;0m@KQ> zP|fgEn=zEN|1t2**(Rc)(r;TUu}$WWQ8+LA>9`h*eP15&uki9vNpc@{ia&oJ12XDz ziQ3pTwvTmx@F$dHG2VHAP5w6zK)30dc@C4MpL5K1>eiM+t&g@!=$*R7K~^k`3o3t4 z*($5Q9&c-t*2-B9$Tj*ZgOWr#Qugm$*`Sm$x=@6Vt2m7V=M)t$fd~h3fm;dEz8VLf zcVx8xWP#)54j}m3(Yv?WV57VNxEeoVjNaPtT&~q}-WsogOlxE#xSm^^k7MrFnO`0| zaQ@U9zLzNJ^r&&%68=VWg;&mT#chA$g9GOGE$4^!78#ZLC_QMk^>AO$8@(X7pv+Lu z8Dynb(|$yb=Ku$!t!L|1YF0sK913(Kn!va`D7OKn*wd~(Zj<4+@bcNw+BHvv)l z+Zsc{A*P|@c4Ab7gcoTu^$L%cDN0CazZc#;B%KBD#yC8*YV7%3vD%ahIj?`TgHbhO z$Bs>RvBE|WcqRp(N>{CMa!LbEdEpr*`8y_Jj+vdtfZD9DRAtv}ShRM4%DUG?ep6F9 z&mtu7SSRY4+4LPq*&~e^wph~Fa}v%a{m3k(O!w3_ElG?_z8{@yNX{DFnF*ew1)(_u ztd^=~0L5Wg?i(3SBkNP78HazI<{PEOt#tsn=j{ey@~E^8)0)rv`sQw6ov+Gq>t6AS zDR+(K;pmrFI-6P>V>J`ZEOB1ZoFm}fDt5;#?Yw1_syzoSD2bd8n;hmOif{@Ro@9+G zBO*x!W>c(Or4+j!6J_!p2LL9=EMge)Y{sM@IMd5WuT=$Lf~RtKwn=|##)Dul7>sw6 z2E5&XAUDNcZ>)Wgj9Sg%05mJM1jz=u(HC3&TA?GB?EFKiJa!y8U8nSIz0!-?X_Qft z3fNK_s_%DSzEGZ?a=|La5RMdsBSNLR{FLEPXVWz-&ccy2327Yb&xVpkYRRiIwWL|S zT%n}?A_<8R1H=t?=OKS16D=YsF~;mMFsfhRhnkaI3s*0@?*2K6>7<_^iB7*F>GVxo zZfW1)uFE9eHr%-&yVBY4(jlR)|I|5ZOZBMSH$LWA&bR>1F)lsmHaU!)ZEUPYR2fAz z0nA3j<>qH7qjBI>d99TaE41_*61#Nfr})~2N%9v2`8vK2nW=y9M%xM-C3r?yAQBsg z*=lGI?}8dfP@C$?YRF~na_8LfEW7xCpv(*fS)9+*xFZ2Xc3L}GR6YH?s(wx~%(BZZ zd!a!5iuYB{XSw#6Z>C~D!eNXU_6-8YF14Xou)n0aKfyDSZtr-K^lAZjXbZ+GwcH-p{hdxPiSz~G7TXnk@n5c_8E*=^N3_b>9GjQoNb zCo~$=N#4#i&MKhe>Q~+Oc zffLv|Jv;v4-T5|L6EO#r0#33y;)DZD0e=!Wh)e$iRa2l*{U5;3PRr#TC;0%4Jv5i!pvK}eJSRX)Ki#RBtw zDAyWqFBZ}83V$;{CKHC(vR^d6umiIj41!(nX~y4K{|gl7nEwF`VDK_bL8XrHD&@-rIM&@wF#Az3m!BV4fM6<#VVUongX22`?D*>Cyf7*A0i zi*jJRa)0E0=9mpDg&0aBn!xS=B&R{4zzn!xB%L|cMu>CC@-%_oq>{BaKEi?^K(L^3 zo?u95o(do-7Z^oAr-0K1VKh~2e}Nc5lNftB$F};9B*sISqL^dV%Fi6b$tS`ENoSzx z1PyOZa{`$Ke&vljg+h-U8Gl zoWyj}PY@TF6?=l3kT?}V5^dObm%9B+#AeMlTDC?#!*j-PD*9X?LBc-DGGBuU<|2um zE`PsKZ;#lF4~y|cDWF(jmP#`6aE_xq#>{lP#|33qz2H9UOdx*6`zT6CN@PF%FwRwf zLz+&>EN9qH@>q~8#(vQb@9X7Nym&8nWrf^nW`&fTDR~7*DkmLHBW?yZf)r!ogoGvU*l7sC9l-m>as9X6{eIyHoKfpP#`N;7F$Fir9yK7Tz@SE z+3cqYl7NSB>w6mj5YrIFfMWfhU^y4+{hV@9yjF$On_7WnS&FVpE>||}e*Y}kJ$M-m zfcL0~UR)^tASVifOutb~PccTXcoX8G2Y^$_2&18F6ng*+Ythi`NB|pZ zBebvmOudJnaGU^2Q!4ayr74Vld4CnaE0n?nLrP+x40=}>XFbmY*w}z0DR}27j+aIP zk1W0tyI(Zhmg4oR7?DKRIl~`wBKetvbx=oHa^ERLcuGyan73vas63+RZAZJ%YS|Km!gJ| zIC_4stx~VI1J`pB&LJXPQh-CWOi@BY$QWG^DRRqg(?ZKrg8^*m%|=b#Z8b76h~BsigL zIfQ5X2k(e^7iReob_at*{np%yq!>^X5wpF7ITthm(;-`~Yja=GsSODrW@|C5R9S6o1oMFh{%qcbPG=ATgfdt)lu4Y`!{u|Ni9F#pX6#)G9luT*^sR zR@;V?x92A?fRp#f5(D`aempyU*HIlJxSnICScSq`?h+)0txbWGOdc=>n>$ea*p)vl zaW}Vn4jqy@z2xI75>(&GC+BJw_TC=-aPqd-_*~J9^wbKcQ-8gV4c@(4GqRtTlcm7C zyRp|tKfgX%*VwrvSgkQh5CyxZ#ab&f6_dW0?rJ}XNkVGJpS35ikS19!uwN`AC3{sC zRdq=<7gV{NJdW9d=>1YGGdzS>THJdx@&M$57{dPE^JkJjd{W|N{AR?5@ZopO_}+&6$P*-HI)$xKe6<3_UN!LJDy9(5OJ1D8^)tC2~Wa!h5$^ z$xs5zaBI9w!?~DaFf|ey;aG_gSr#t?_;rp`yLG54J3!NTDP>cxHD_{=L&_Kqg@zW! zMDCL@n&4RPw(5LjI$)T)5^0r;%LI({VmSZrxAI6HtACBQ*wtuiu#h|dj$2m2mf$iW z<+l`vihskDQ7NY^L3dt**{UNe=d3Uyu0mtGAQFmWdVOL>)rcH&D$23Z{nC?E&=_mc zoom67Mu0dcGj-y8=-FMZ2L-LKfk<)Oms6m>A^*>Dj6*@$Q^J)eQ^9?dM!wS-e}V<_ zrx=NxVSi7SJU4Btz0oPD<~y2B<#BAOH_i<>U0}vYR0<3+S>RL-`k#Pd6cP1z#^?ld zPyZt)v@NCAri4gPe2inX9Kyjsy_7;d%|&qx*;j9;h{QR=7juUBoW{`*4%AXNEw#bh zZw2>Uz0Imeoqb8~qf$IjBdx`uET&7PTac4M4S!MKm2Zz~B1J}{`YV0BD8Q&i#c&p* z5Cazs2|Qaq@{A`BG>pdT2wLLQ-zdQrE!c50qJxna+H@ys*=DF*zDlA2x%qkclVIp1 zU8pJXMEXBRVzav^@4r92I5`i*C-F3Gtg-*>9Xub@^uPPNU+q6%=5d&Ps1KQX_rO~5 zr++pNxe3ejhn$X6Dmk}2uN=SElB3=XB=09FENRZbXl;hx%?;Q|k)g|zKNiHSF z9|rw~K2wrRsmbr|ybB65EHp`#dZJKzvOLw;!szwr==}WG)3f8lZ?`P&vX(*oUO3%v zn82s-cTUp`iTPpgMvC$%XmsGN2e%-l(Stqk{RoFN!hZ%F&gr%qJDf(cZ?bbnpns5z zPW7>nV_9CGYavY%xdUwF#Zeiji-Ktyd1OKtc)L1`64VpYz&DbYFC}1sm^gfo7nsT4 z3HZJcOYjN!+7eJsv)?32zAsVkxg%Eo-GkrE%vRmBldK|=S`E!MY{`k;UZx^gZA((C zrnN|Q*n3bn52aXUFf-$(fZ5UTeSgUK#~A#dCHbr4VsfKW@63<8&28KE==7}KHeZB)7(?8=33!IXKyH`{ zBYUuvC|N2h&R!v9apJunEq9;22nNdf@AlGNA9Am5!cyC~oDrba3MZd%mP-CeJ~FBS77 z!2+pGN&>p;nVDg6m3{E1lwBhh-4EYyZI9vJ1Rp+ZXq>hCrR2X>`Tuf`;|wz%i0mm` zLDtCs&j-(**X92g2QR+L|6k&{x#@og3z7_#3QCHllJ6WQk}TmI4}ami{@tA?OL-@s zGNqE4V=ea^^`mlS3OrNJHwK!PmF$-V)Pe}K!=YNo#RiNLTqrkgL9jdx;o!OYlO*T) zbV@!!&o6<=<>KodzyF%7_aea}<*)!4aS=Q^*J2uUJD@<%MiRc7($OhbZS5 zI88A8wNM0@qYlAw#D4)XtktLTJYn|Yt;tf6!yJp0dqal9?LeML4FA$V3hu8cr{57# zSj}>I_EJV&iM+vf6?My9$r8mmAlZ)vQEi#d0{5c2+{o;YZ&eS5hxZ>?2hV~S8cLPB z7r0j5J{ZA_kyK2f_aEH<4=FfSpy_rWGS#~N)>H5di=6563xCQoMl(j#6f68Jm3GSr zn%eBUX7N;I(gIFpxH(Q1n7yJ&Cg*1FFNeFqoG&H8;cPR7h8A=}gw72{H&c+@XD}SCoGomc(u34!CnjdzTHcY!H zZbYkL@XFq+bHIQ9M#lX_Pb>e=7U5Hdfn3M` z5B3}W|GQuPKfcVlk4iIkm{&c7w-o8ZzKT-MtEn+-fBs>9*{%HF#4mlS zJzyRG9}Md8zxQ9f*!#-=zr@ob)HQDhv^ojv&;J%IT>GP)X6R#%9e3dhyQzoG)jqp* zjmr=!?5tkt7A6OKI1THrybgSd41cw~ET7!*fUjYC+aUGN^;E)VHFy3eAE) zw)cOyj4)#2vur85R->?uv9Y~fn8k{Cj%^s)k5IoMQ}+=z<(;sTx{4czvgI(} z_77PlE2sT~*1yC5&rXhx-<Ne_3bcPaJ&?``6u=t+bHpK`41<`X6n6Jvi4o&K zr+`9178oMDz%k8=z>i1;#KtKg7S4&lp~!V@4GSZd;s}TU1Y9th&Vb=8H!;+wl*#o% z^p&RNjt)0YQh{eo{YFX`t|FEyFESM~^5X5EkI(+>dE@bTg81C~7UnokRH_OT$H0Gu zWVa4!WI>ZgLogcUO0VvD7jt6cJWMDRTriYL^0g9reGZ^)HzX!aC7?1yg$7g)U%72# zIYAja?ZZzvPRe$THfkF(6keg3P36QiB}NQ0{4pn-2+TdtcY|W=27CXhZ^!(A1%ji| zn<5OB=fmh1H;_5-JX2eQaTCwe2(y29DRCm{lp!uyt_ODOG>w;VJ;$l_w2+15ux%R> zt3j~6QFrrIuq!({WfXuSByA-E$2eK~=EZo}ImS9D5R_%RM*TuXNzyUV^!QXlbD7AA z4%zI87)n@$UnP=kpkfApsJ#1qYoqde8@M*$sEEEMrA3(;LM;#z)v?H+5kY^HGfi~W zP2HI1{RO`J?t*0BeK&-+#NV~6&w)fG$bnSV;P)SO$%r|+}_i%U6f-JF_+dJ8rJ z%~k@0@%O<&@a*BJRIn-iN5?MgH#!<+9>-wvjI03&W1Y)uEQMmHqlACMSZDJZn`~ZV zH^0KTiH-4r8Mk9&^vr9qNlE-D${1{1x7KkDwtQ!!S*7?|2U-=>#D5Liu=&h+Q&;-A zv?&yUHUhRqsfmcG(URzE4Lz&a)O_2j^G0U`)4Ph34QxtcT+0Cl3&bRCQ~>+O&*J)3 zESEOwc%x${U6*2I_fUU5-AI)ew#E)^RFbbFo8)UPz|Wq=m20TuDr}p3qCFGWAAwEP zNHDIzZp-l|2kuBkTP~*36Jk@n>RH9+%w*0o*FZ<*4&4Fp^Rco1k_{lY5(|~%h)yA! z{Z_arb^}z{z*c8wtnC$;YHXV3{IP|tvbU+!PJ&ulTc3|Qu@QePf7}9Z!N&C+7~jH3 z9u^{%PtJa7cO$6K=Ceks!y-F|+amo`s7$nU3KJAwDU^PB)j=DD%~sBpT$;_1wFes* zr5bU2EjFdmd|Zr_Nw0;tO4+0iNtBi8o9ft9@;W_;N=T&ouA`#O z4^|tg&y=<*ch71P#ffcEpI_Dkgz<{JW@~V4VpBO+Jqnw}AlMCdA48lbHkET#1Dmx6 ztJ{`i(&Mmc&SnRjjyc@K=BZ|J< zY>g&;@7S8+#m$cDY*SjYpzI-EWq8z%tOxQ@+5@$G&Tx`hwFe^~Nnc5LcFLB=iEm@*)W z$RU3vZJq?1_COwX-keoa33d(DlhLLtAjr5Cn~tHnh4J$z#-=$`O>8=b>IrC5i8ol) zZM7v$EKhA}SyusmHur0dTsgiMHje4~sj#t8ky>|#bP4KvN1nwc&EcBnaRf2B!bRFe znwE)EqkE%xtF4481(|CEOi*UQxe3d-O=Ev98Sw{8qr!lH4@ZCiexyu$QIK>>Sz@xR zYC|={Q*Fjj*8a!9H)orOhDyI}t;9B&KStra?5E>eF!p_U#J|GJLnX<5*eU+}eGJH` z%Oz@K*VsPR{lTA5lErxE0XF&HJOJIMYvwsjmVVAL+o@Yy4z)hoDxr7k76)0eFfM9uaZC6c%@tlb#}$9Ki4P8#-?y9}+FN8)>ZA0a)z-s(J#X}a;DRzk zJ!g=WUQPQEIi3R?khY$!SE*SAopC78k!S+r@}S%Xlwwc24%L;f?T$Z<2GTc35S@5j@yY*5fWac&D1MATBax=q5WQX_mFfJz#HT6(5kWLbH!>?D&&8>(hf$| zj2$~R-NgzULExDbd@5bF#>puSIOT+74lfpxwr$E|zC zE2i8vmWQKXUg>OVZH(1SFtfyYMRSgTcdOVPv$XS;QL6SFw4fw%K5TNBlPJO|Sa^~( zs*H#v6_`!2a+Ol-dQ6nbcN_qi9J7dF$g>%fg5XRqBfVA?fC-+;-PwO8sTmJ~y6hk;t42}qu>he>DL!C|6us91x(j=sDtUnt{7O5q#%G8o( z^>T%h`imqaMhp-)+?{`ij7+qMq{JAr$H1t5fgfs4axGlF?7I8sB&L&of+RZqiloyw zZMmg=hr2G5c-wI2g6v9X!%K&Ry8ct=s4dl_a^LuvV>#mjILEm3pxfjycDAvx8c}5w z)dVmb4VRmrp^V0XSLL-MbLA(oU96@cWE2|-wwacAz$FuC>1A;O$6l8HeQ{#>V5ZP(%WKs3>^Q!te$uP?< zx9o)i@hjd}IiKa)W4@V+{RoFKV%Rqb7`xPlUcvs7=KciFNV>h_Nz$tY+@U>`OIYdN z0?(6jk>i%Q*bRU7;ZO3PgB`^_l3cl2atbPA7)@*X#z~>n@>F6u%?polx`Z-YWob4G zKyQtT52?)s%Y#9PUCLjgIKI?5I?b{wK$(ovHb15T>=Y<3rl(j06D&|rC32N~hd00V zO#G4GdPDhxQ|)c~TW|PV&*{!@y}P@f=lv?VY?TB>N?m%v&~!?|B1xW;eeds*j76Su zLw7YlGloOCeQSJn+6JzoXg$2|bm{7wNbmMM7UmHoN~vRb^~7NpCsN1MLZ} z3)xOYgl92YmMo6uBFmL;h}`3p2f#Fs?T#9Jy{h^3`TBf)p7Qzs0RRC1|43_|o&cTz E0AO%!iU0rr diff --git a/chart/charts/redis-14.1.0-bb.0.tgz b/chart/charts/redis-14.1.0-bb.0.tgz index fad75bfde1107060bfa90bdacaa924e7cec55904..17bf82418273919f219a9f3e18ebf21b8e9268ed 100644 GIT binary patch delta 74602 zcmV)fK&8K}hy|^P1&};{X?Ghrk}wMQXZ;Ec?P*K(D!Is8H>ch2s3cWcw`^IDBv(Ik zs_WWdCP-qGOk^iO$!uBw{T^(Y01~-yk-U_6X1XjS5D@?ZKm-s=h9XRR2UD1_?gGx@ zKi$Ev-|zQdJbNbo+wb??{|=t@`+pid>%Zu~eExLr<+DHa2YXKf`+JeSCKw@Pa0DsZ zf+_wLWfYTS2(I?FV4CKCzUYzrLoKB-54xYapSB`I!wjcP6unDP0w|ehA=(8nx`IiF zB5;Wo!4-_>2v9~c)CI?rYXKhtSCfkYS$`#!wR?Crk^c%raj>`7|Frk?SvO54TbF2Y zO|nSLmV_Pf?ul{Q3dAUgsh>eCx{5MU70n=yhr0hLqyKFXu?5t`|EMOisE?uyhyNWR z%E8TG#&FUdXL$qb!;z3ij$vzKV}5=DD2(Tnkm7o-03zm7-!aX1+7h4A@b;o$jb z^z5(C(bK)BFJ8R(YkzBk5|lxPqJJUi?Dh8sLH|Y2e|a(38}^?M_x{p-`t;?C7k>%* zFNXbo=MTTQTm0nu7dt<_D*>=}{SRI|-Pht1V0!CR`jt2^__I;f-NTk=Pp|ECe+G9)W0%xD>^vh;JTgjDJ31wg50A z^CSXniYXTx#&|N%gs{0QY6=M83TJE%VLI6@QxYtS*~ChOXg4k_tddGByN*=g*!!Rm5K$oO1FK6pDr*BFPg5rtk^@J}6*{ zV1zO*+7a*rr!PbQn&S*bqJKTFqQ)TrogX?|TQidIJrgGr&%kXx0*5F@3{j9~=n9iL z1(ZRC#`9Q+jw3WC83K?oG)oyyCIBX2o=!3tp{+;YEnI*R%1Ho(OT9A$&ctAf%^A$o z2yz5!R^};X8GwEJFzc@CxFX)2(Y%5IdA5 zXJ~>c%ND!x&(nDvpMRq;%f)&|GB`m8F{D(Cz<&z}3U=25;T@e!eXM9};If^vE9XA($=nzfa(duWxri^nWr-GkgUZ3i6>W0~1AN z_lNnOr8kC0In6^kkyP#g;6TVfCL0^WaXB9$r2>O@ntgwnk5HC~RjouI-c_UO(15__ zEpK@))JV?8Dc68t950GhAqBCnnCR|!9>@G&9I^?*1g-0M!1GUSK)WDJ@UqbxvF8Hy zAFez{QiqOXzJE?*vf%sD=zmej_y(|Lwi1Ky0^BclZD9VpE$Dq`*EitDbFNAs60Xad zv!p(NNPf|sx9SgdEv_2D*Z_+@u?!vxdcZzkd4P;%p(c(KEeQtKm`&ArCw4-P#{e({ zzx{5rU$Lf+-R+duQyR8WO>jQ{l%a7UsB=YGD#b!bcYp2^dJIlz&*+l?(#`i62fA<9 z(k--(;Ax{jm0B@4DOKlX+juscGqG870s+i87(UH>`;T@?fYNy!pOP4dW%T?LNX0jA zGrh}t+sQqamKsKAG@pPYaSp2bvS>ykF}0#hZZ>*f)BhTDBTBk696PEN&PXzX$)$7S z13>j`^MBEi6|6aLc|Y=q&eK#}PX&CG1DHfXhG@ze@CvD_V;rL(#>u6mL|)D5TR(yN zJVhZMF90kyYB?41^Pv>o#9DZ=A78@-eFE^s{t6xr<3JA|dU~DawM$97m`p5P#6#qclSSpG=%g0$HYeQgF=>NXjIR zcj7itY{FD`P93g%iM!`fSB-;Wq}iM@E}YF^G8Zty3~_B0;6!WyVzW(Qh`OGs^K^+p zdP#e^uoI*t3i9i>9`A$fR^Xn8JqaImg#`NO5lHPb^wA@6j27qZFK8h@tAkezQn^{> z;eY!`uLxr;C@7+&kbb@UoZQB39l?ZoMtz^Wwk`S;d z3gm@#prx9CB*7SGlm*#b$Rk`DQ`4^pgMZ6sN~qUUm%uDdIlQvuS>AOZ$Y2tY85r~ft{TCRpZPFOr!bk%P=-TwjnB8GgfPDS z|W4X_Q>?BX`C%o-3GP&ZwFW7k{?ixx~hGiBq*#9a!6oyLj_g2S!pH>MgtwSgqDW z@Hr5ht6DMp?|!NTlxkHiM2}#~RpNjo@gm@T-2y-s@e;6*haEVScPZfP@JC>@-W6z! z0s!L-!Dyk^H$S2%yh5D&O~F^rlI*|?rj?v8YrKW2Wc~%2XCRzYMrO`7&wn-0Vre8K zLR3n~4yIw%;UQnkst=DXS;6KbS=O~19n=t}ut@sKr+3ASE2gs0cnMKgUR?8pNkqYK zLgx5gX&3JPp=)s^L(MNqJS67e#AVA!U(PWUFRV+p4Do{{nE(XCsn|FZfMzLMsO`}w zued#?D4b`QEgnh0{7fR_Kz~Y6I1Dt+xmaL#SZnq_y?KBB`tV2dul+Y~{8J}d7CN}P zDJ&i+^*Dj;IYr}n46gYGD|Z3Kic%`vDdtHu5Gt7mCCnzY4xjkm8X2!$g(=O@(I*rh z%pwZ*qX)SCEgo^Vl&Wc&}x#PjK-#IX5kRsgKRDRk1GVy<-=Tz>~k*g=dF1jeGG zZ;iOJX8~7>o&o3t!3=(yp&7{*fmG4J6^S9^ItOEM$E?YvsbB=d%a}|8ivNwkpuhKQ zHtG~-M~C2-z9~w4!c4J=%LRB! zGR6l%Ek~~5^64Wf67ps}G7HKOymU5%@_K0G5}m0F}S{)vcw=D_$EvGOC zU{0b zfx?xus6k@oS^AFuLxko=9SqT}MwM>lr7&8`A{QM{JdO z%l!~+m_(XXyEZev-E0aobea(^5ufO%YjDm>0R$8$lNfc!a)n5B?*ZNjkeIIwl6~o8MS^Jp3dTPUjYtz6Y ze}+?ys!l-;_#Bfb5F#N9VwMXMa>@;=s+g6g8G_LPNx0aK6Gp+glWGtv zIGtajYk7O99{n`zU-;gWXahO%iSy|Cj9x%^T>S-}c19;0v( z#^^O6my^v9H33SK0})FBr;|?+7Jtuj-q(azuovIM4~kK7#*KencF zT$|FuCZc{Gs;8l877C-5Cv^H`7d#0<{=X=k6405VI40nlWO3Aa^1B{vhs1oyPYru9 z!@_FG`~BSNj0I|K7m8_tph9*vYLpCD4eBbN0+mTl$>#|i#1PM@DPonc0Do(#NgKlCqaa!&aE3#WX5k9$fmQkjJ%_`3r4Ov{QGE zMX9j;9fH{+fN5%tkgYW|?Wo%7mT!i9;R0A#be;Zspm<$7x@iBF+~Gw@iX$>lB6|~1 z4$HJ=AGbDIxdWTz41X)0p0(q+b07&{0`aAS;nmlwHx31r6)ywEy~Tlib~!$+2Q4hn zstG2Ubt{pYhG#WU`8g&`-GnwOa8%e~E_w6hxy4syy+^#?La{ffR#PiBB1MS4{QcY0 ze!t%jp6P-e=UbVJ*$a*i!UJU zyi+`{2}Tbznt+RY!3f4M2~j2-%>*UN4=0Q<7jEQZe}Ge)r9BQx<964OkK&nd>( z+n4l;@qgp{WBJAC(OcCq#X*Kv}m0J)x*Oa;*O-DD~NfA@Ye`Qdc`jxsjtFW@PYueW>jl_~gaHD?)9 zfAzV`l;N-7FH?o&!DFVvAtP6hmT{TMN4bU5On(gmzt@Zj{K0RgN)lgTvRb>&G$O0= zooR*YZoOwT?aR8)SS-EFl;4E|jqXIf2Te|LD<7H)m=8`gzN?~YFB)g-Tf>h=WAi)G zSa`l}R~lo7Z}z2GVV!N-o5rBGojc9l(Y%5~O}@e1xkt^)TjHJj)R;54q*G0P^ZZTv zjepd8)mV(ZqFc?kJwDBTHD9kojUM?mJ!;mPK+xb)Q$u5GpPDKHo1JQEurKLV(?G+W zy4AS2tNdzg3E&HR)>Q7eA9wAKmA*CAleeyOjS0Dhcg=d^x~6}PrnQ}e&7H8o$}Tp! z!ps@xMD564d5BZ+!Hx z<$BY$4=X$0cqxAHzS)@fjcES%VpvixdF}Hhy;w_8hHzbgD%8hZHP*;4XsaR+%-*A{o=+d8-8cTIQY-BNxaYUkhL99(bj zDeUk48vqHX*95?_^}()SNzmcq+<#?fsT^+08yxukiOzL)t!jUwJb{+QSGqJ;-*`7Y za4l?{MN~JB-=4lZyVyUu7#i7owdW1zF6A{PExT>r7fd0+$YZB?>nv~;2VW}X>Jd@e zoXl*@0q0bTYmWSy$IS}u&6=3EmDvY%me%qd)~C%3^gyconcgw3Or_}%VSi`PtAgT5 zuUUeV=h>`*WT)J8K(xxeSp(dghSR}e=HqMtRZh+6gQatH)&Q$d*Qu{wbjnUMX{X`= zOjLQ1uG7yDQmW1~WCjr$VVDGievs|umNGR7Gew0>rp#P&`>joySqS#VotKGF<69wt zrW~17QfMx*0k4=uv!o8DZhtcB##EZt(CMaz;NeT0nYXc$XL{LO?z`uR=_8q{%;1{2 z^9o!yH8V81kp49%*?d+kwErXi)?nn<+>tb|#jtRi)WRJXYW(0Ma-Hmt8Oq+`IL6d5 z$mc>zgcv{Yk_muLMmWy(yuBat7~+^*p-jUvVWub>lWZn|>SsToTYvcBiKO?Ilf$9q z+#v1)MI{baUT+?sif(TK;O*xSyx1>V?9oS&fU{QMRVPtYDAkqy(pnZLNXlu<6$hR27Rspa1V zvm75vIa#>aDss2->wiJ*j4Qt8c|?VzF+mB+q~xG7dSY>(Yrc?i7)ln{wJ<1YWeTr& zd-2)`69$eCxwIpZaWFyg(x&@SyYkvQPv`w_>pX3oDNXLv208cV3Y;Uo2VdZV?bmk( zK6l2o&KcO8=OrB}J@Z|5q}=t+@CV<_393lZ5Z~hJSwXYtm9Hy1#>;0$||VqJ5^Re{_edhi=*oP-6|d2U%;<2 zUv~HCS81@?YL1oWMV`;G(t}_H&&nz+<%?ByO{$+&^Ly5OyuTT*yRzKY-tEpaUJY({ z&Dg5^?pooxTYtYhrm2-&<5W0@1$88LbwENw>&%Aako%PyLFBJ&Vlea{=6h7_C^XqflvwdQwSSQ)4UEr7qBIyw8cCFpR9Z=t zFn!%t615$xFq3HL;)9t)$xNa&%B$K*xI^F8P9i7Z&I~0IxdX2p1oR!7qRh0|=3h@F z#{;#wSwhp+x@$=NQ^pX)NEi`psY12oSYv2?axXf>=EwU%#+qtHbgntnJ-~ZWz&Iw? zM|#&jB!9^hrsIMGxqT`>Kt2;8NfKl}DE(uK68+dIFzo`8#0%+XB?1^q$LK6WA+zBX z_y39@Z9J>I5(;|))2^EeSq_O;9+Gq=0bH=&HEIda99qgulEF9=e7{h;hXlS|A~Qmi zX=db9>~!My zZhddD_7Nzhec@4>Uk#};e(9* z>a&m^C_nBWlzO?9jbP}+4;sO+ng#)-xPR(viM|A1?icD-R>IUfNFG?B*fYd8W4C}Q z7SXue9Ycq-0KmCdv=_DEr+9_3ky~S;3D5=n^v$m;1u1-43F8wX{OpIJaEK}mF15b9 z@8#yVx=DAiG!A*`gmzHzbtLX?6BQSj@7WF#X_V2;?HLlngvbMvNZU?gs$>u-0e@kd zTSr9dbzKS=vl&SQQraEQ<5*N?XqLu0Xw()^{*O*b5{K^P{dVk53I}UtXm0;eXXpOf*sxtZSMh(85pelLF9N_{ob{84S&nRyZw~ zLq0bbZ_dk0k>wJAB8bJ*RW*1+b?&rKDL4Q)XVU{A;Bz(JR3NCjl%8_^Ff=&bXyRF_ z9B7C#hR33jj^KU4C4O_c=Apc$>8Tnxd2K5nvcxDDkaEr_K`)OBuk#a*k$=E=P&5Ez zRcHd!75!j-K?^UWU(mt}&8Y7Oc(7l<+ixVUs9lB@O@&fSb9nq8W>ECQ*Yf_Ff^D1t zl0`_`^UPCmA9?s1j37l32yr?^S#eeF0v_55`CG&?98yaqpUErr0xS{8mU*=n(KcJx)CMa8IDUf z=QtzD2qu^LY{LY`3x-4L%zI&mKIjhq((RY5w)02@qH_=S+P1y6oPTn?RpiV29!v|i z)Vs+A%qEDvCX@|9Cnh0`r-ZVOe~02K=YBTP(HmhlnG4^3=ayCXV^><=euA?!);lxm zPP*nD0SA{$=HV2Dm%$}k&>@)dq1v4-#Kq<>XkqESqSd!&ET9K+1zUlfH(J{YG$N}q z6=;R(j!XqSRNSMTjej1pRn2V5Bi8_a1tXgZ94pw^I8?QY&6;EXa{C8HBUja<7d9A@|;spXwje)Axvx16}oh(7r9csv|6qE zRo1U-N1@phyjtgO1-Q;RyiN~q0lZ2juY%uFH*bNt-kH2sUvCM$#=pE?htGM?(BrGU z#@qOf+nRf>yMMpz4onyF!QP(wUh9Fqx=z22R(~IQy{*~%b^Au`URN@P(&Ld`xuvz# zwsTghRJ$$3yR3S*Q@%~%#8SYQQNh2Q5?(vh>)7tMRm@i-pwXOvd1XDH$a;m{r?UH$ z_Nt@2t^U3V4Ze14*Y=t5YTPYRuH!{hiFd2?^6k<0OMe=F<3xECNl@6U8_HyD@0)D< zs})RRv-ByMt*|=!W=%J>;%RQtQu%!P{CRtXtqsYSQb@lVmDCuW7HVm$5ok z73r+-7$gWqNJ@c8ku+*1>B%EDb5QXJhL^dWc7HK%+F^K}#E4R*=wJo&5fIzQ6^yx5 zlnXUxbgkH6LjRl%}yrX+(wUMYUh5W^k_pw4rsINowS7t`YqTOp{A-ETz&K_D%N8x9z5PM>so92Cd!=t3`2v9X6Oha;oG8BQ) z!q^L}Yh(wxVFDme@S@q-JQhg|Mo1?DSoN%ZB&7pQvVevQN1-iqx8PW-ILfZ&o_~>0 z3n6wjaHh5A4WE?t#1*IKg?ax5aAGVmhff-TQHf{o9&h@n56}J%WT~^ zl|;F5pO*I~w_MLigV|zeI<1M| zb|C^cH-OXsSYqqu<+ryTaC@txDH^~cM8gb=tK(Gw77-dXOnc1Vipa~a@nmYDl|%n` zn-nz_GFbBmzGHnDEf}I}&CCyA(C<5VdUbeb@YDKe9Rz;|f3<1w@Q0s4>VG(-hDFxl z5v;c}MhKYAg%mL}o{xNt^V#_b*1@am30X;f{ZH|P!Kh&wFRAKQvfeLfaa5SEyS(R8 zj1#_JQnW3ZK^VTH=))yi&<~6-7_Y+)zdfJ*z61UaJWMd4UnLVvAq8p-03U<9o_rIZ zZ~g@l`W-5Ul!519hLbr%xqor06zXz^A2|+ob^Y{Lx33>doqzq<#ytLfisE>A zi+J_lfb!-ZgZOfvo%ebVe!o?GHKhE3-Ve)b8eavC!HE~l(pK?R2#kk!AD$}H_&RX< zNx2eU8~ga?SnSqRi(29xy))=5Grk84_)SDCfAmQ1pgB2D=zW?4mlf zo1q8(3TD9e2!CxR^nY!KujLCmcG;=Hu3ZJF60xKUNHQy*xas3-7^+m_pabWObavgt zOK8S?gJ%SUQ*tdS*_ zQ2h62@EL@227;&qIv^PDebg8vRpKg4ksB|73X;uP>0OGF^M5HG>&rVX6VWh~K~8jn z!@1~pM8P&+Zha0dAxygQ>;1mb3Ba%(kl|}YB2~JeA&V=89&v@lh>oofRCReh!-Xu7 zsxsm`=`WlaV;z2nf^B*64=7jR@l1N2!z+R#a1FDB*Vz#s+ybQIxh=|?#F8r1Ur@|Y zgs&=FIL%iPD1R&v8_SP2iC8Z+Ow~dKHC3yEI|NQCUcdtKj$JLYf z4P6>e(F}I~my%?YIQsp5|HZRs;=lcV-}&#LKX~@?Pk)1F{TKb0&!6tSeD$(H8aEciU**rsesnMRY3?~!OUY27Piw`Q{pV>UG#0Acd zG=R;^jDI^w-h5w5z&d~z_(&N{A{dhdeFP)}A5~f)UjL&!?QeG#$#XXKk!p0+CUw7v zG{Oa6EBr}4(Vh_#$2Ul0{~86i#K{;I?Sn(Uq&n zaOTc8e>sR&q&jnGTI%E}p9cLPoWcx-B1Ki4PJdxCpP>wgK$0U2i)6qg8|f5B5lWoC z0MHQ}(oyI5uKg{Af)xZy^z@_{Rc^Q3f8AQFBuzt>Vx~N&YMwq*sxGTBl930!Y8D+z zY-&!6_Tqe>+0?b0)(YZ4HK&6nZm+{<_dscg=0KDxJA7AeqF?k&sqhbCh-b880lamX zh=1aLyMqrJmQlqd=1$fd?3itp}rQ!3r8 zx7nWVRk~CRYCo+zi_zg}m1Mnqc}r0q5lZR^DnDNNL~VPJ$9#4){_DasKm+eHt4ZDw6NEeAz<_J0Tk zAoPJp^n6)@9CtyV|;I#!nk?ItH_iyLLX5j-f3hfMqbeth5--F)p{G zZbZhCByDgH+v5NKaIN>%{^b3iHe#c_lXn+K=Uw)RZ4gKO{omf;S^ru2{%`N${_j41 zKl}hrV+1KbML`Og$eD3H#j#8bE|W1U6Mwq72>>1!!Ed|2%3EZqsM$Wpoi~QFUedNic|$m7)BJT;RN*zm>yKH@o3&&IZ2P}kSu}Py*sWl*zb){O{j-zflb@v@(vSJG zARn=gXEa{fgTXu4G5h{XY||a#k~W1`@(i63%0P@SQM^#ca8ydsXZtY63t=xHTz_$r zg>&mCVWMyf6HI4aN%~JD1KQ{VWC&7{&|Pqi0A(3TCh-E$`DB8q3VY1yqt{ra59s8c z;T@n1Q#&UrF<7Sy_9=j|AdKNFv@05iFaa>8#DroEgcXJD3P&=F{}qgJR9t70#JH|3 zEET$&pJ>jrD2X)tmj9`_8vUzaYJWpr&lLtCBN(edS1tul;xLT_;L;=COX+4{ofJ_rvSt}4^5s3{X( zTIS6Y>syolak={yskvj-g@3u_>}}>&KcCh)ccJ_`%`7tcTtL?|Q?vZtN*OQrSV=acB3edda38FazfJbwYu_?D8WI43!q z%qf!YzA~zZ92njIY@W31xa@$+ZWaU?5~+1xJvl*FD0>2GX9)xWO0G(iVE@fQ$j*a6 z+70;zTYS*t9B4D0AOJK*Co@aDUiiv()^$2`rarQH|tM#_n1f$H9J8FVq*CeE|UPDRMR%Jzb0d z$QYEOmv^AiClrDpU~B;bZ1dhfx5QQy0$~OVdmhO52LBN-TvjTW+SkzaXTWma!z?n}TysP1H4Rx&>x3{g1m`#j zorIe*vWb9MN`Fi%v(T<~mgy)C(kS1OMx`j`D4iaGl}o-{%2in%=ZxY=UGS-_;ryJR zvkEzZ4(;)5b?EKX9(3;IVR2Pdy-SOmL?zQ`ed6TZ;n9cVQ%8|VNQ7w1Q{UDRFheu? zTmSbiWsuEj7e-OW6+2O;{i5?3jTWTmS|y5rANfuC*U|Zq9B(2FIr= zdQEcz zCz_8yFeceG%%XO)O|QaU>ltq`_`^06^yl(45B6Sm``vzb@V!oQStM(5{`ua~9!|g2 z^_M^ViCE2059eX^dAKsaeepB0;@RPw=WfplS%0@zu6;hP&H;^+F>Ic$CCu44bPe% z?49(}@rjU54uRl4@GT>MM z(@{}WfEOS{$l9IIhz_Is)%#)VHHv3ouR9n3I!}cbEKov9@g$j{gaI;^){k=}-J-8x zhQ+IZil+^50w9R+c#JY$pN1qwyIZ3<0}A+G#RdLechCnBK{8;J!Uizg1(bkmB!7}K za13~s#z<_iG{>ILLua3G5q&J#=DnJ z@;Xpe0*LUID8|YVHsy?XY$WA}(m?W>ZrM<@l}cBO=0LrmJq|MzU2qj*_)26wdN&4L zF;B|)O1}FS)jBhn{wCe#eitG1$A3btxYZB;AP`G@$lG%DvkN*>ODI4ZPjzPPu35!z zd8*VSlG*2^6-&vxNqcL^WpZ5ky-lRYmNVgPSnj>kUmHeshn9y`)%E2ewH%~IsCpZE znCCyxJXak(Fy)6&hJ{mEiho5JM=7r6)SI=8uGTFdJ}d*R2V|DQ z41vzyUk$p?g8nY}+o1b0=yyQ(0H$z+W6Ut3-CyP-q@Z+v#!OSA;fX5~&_SOVO2o+Y zt_CB-;GknOv{S#x1J=F#i-?4EWwuyhm}ERE358a!K*o-;2S zKp87=gF#B)M{P*1ugEh zw+H(zCv?BflpgG_(ba?fJMHP=Yw7kx8~b|rT9Y|6EdqOAlV~(G281cY$>boDqcn94 zD-=nyM$;>&#o(MOlO#1L4ssvWY`-g~4X?i)6LL9|S~VqqUObCX=pQnrUMGZsZF~Ky z8zXyccFaXwTeA%c!4L)LzysT=QoVy_Fp2i#bP7-AGcf2kvj;esqVST_#il4jGT^s- zN|h17RVW>K&kCw`!_o_E;6A{rO+ZI^?`C;z_l0Mbmd?HWDj@6^48MRvW+{#lfN`9M zs|Pp{m$B-9-gAa1g%h+Z_K}cR977ye?nUl{biR5N9Lm>Ej4AVffoaMqEXuZPAH2IX z%@B+ZNJ3c#al)vz3$F#*ic41sRYxQ!3OnUa^NRmVZ~{92Ogcu@z%cC3>*~fJ-y;8+ z{JQ_<{n0u2b^p!r;r_+(yOZHR6TSiGjXsN6X|XzgepQ`R!DRC=cVZ(AfHR(yQSi%O zD7aFJZL3N5O^S0KZ9Dq)-v-^mi?-_ZPT9}dMJVtI+JpbAe4BL?J7O*Px$!k9&~ni%=x z#M1?tWEn+WIU0H>phE$tRR;7h@pX0N7>byGgtmh~d^5^kbv}Li^r^E`njA;+D*23T z%VV>Z=ZQF+s|Mn|aOo6ZfyTmlwdgOHkqGHmS1R>7h9YU)ctKPU90$TKNcCXE!t-Y8 z`haqv0)!eBE0E_aqw22Pcj*UI9y0y!b?iS}`=1e>j9@b9O&~+paM4}B+1hqM_4Ysg z!HZ`D$NuNV(|-Sx(l;dnE^(9jH-H4sWV;)aeK=49I5?G)&^RDNG1z6FF&^~sw=m2#Y6#xt#|cOCgYCYp{Imgc7`C$kcM0S z9$X`nGdV&5NRxIsDFG{!pgA=Gp_A4*F#+3?2s%4|-?X+6)l`;kxmq-8V;yP{w49Ns z{56=07Vu4r(Nfc{r+ywK#$Qw_P?6< zDCy2{+`}13MliYTO)!h$NdHH9@C^q~yMOKW&8Xx$+oKhjJOI5BPI`3elm?+w@Y#uP zP7wot0dflQ82t7daQsJ$;|c^ZSG`_&Ow;9irx`RMsrEJ8`#b1G=&F~@;~0Df*C7bv z9S}?y=!4&X|1ZF%C@BSQ*EGpRZMPQzG-GK2(rpNSw zI3XsvBGR7#_t0xE&FJrEJjJg2pPkx#TM z9DQ;O_OPjx+|9#gpx*4bc>ymwaDHMVOu3qIpkfdM+sfH=4z8`A3GbskLxs8=1)WY6 zCB7N;4Yc5FX;4`=rMgbloYELxp`b`qvq024*9uOH$u_Cl>}>lXuQ}ZsXzTfIXt0q9 z_l|aX|Mll^$V*Fn(dn^SDhU~X;Uofm5y!2+rGAxaf~Sn31^Tt zLsY83f$eixZ%t4x$}z+-xk6dM@C=c;eInK8H{5T2Xv8tge&$(!#Ecp zDh`$$WAkofG5cn>n+nh?pUeJUZI$yT{Bbl~SN}twSO$X_Q?@w;utERp4_-WX^}naj z9`e85%ddR83Jy4wHtxzk!t+MuS;O`cHdpD+A8=uPBR_Zj>$5!INA`wxfTs7KLI0(@ z{$K1p-2dFmugV&#`$|3Pc1iM-ZB^qlij{l|0Ki~2 zLF`nJQV`c_Kt_6BADzh}<}59j}V{MLNYk?itt{(tZ1zvh7yCzB5uf)P#-r5|Dv!njMP z#kA$b{`}{Pyx^V3+kXR{$2XpKx1Ak%foirq zcys(=|NX`5R~-j`RYzS3)089>y?VT@Peyga7EtgMJRZno##Ww8FQy@AzC6s}G z`l6;eC%I^p>Rw;GIhSdL42U9ihWWQji{UZEFe226d+dK&Cfp7oaL%R&BHe~#xvtW5 zRKWK^2P%a}brTUe$wQMr1F17AYD7Gi>8Z3+0zf9a!DH}$8|XaNQ`iCj@d|WK-<|y2 z0k$Qsv`;N6>f%qBfr0o#n6wHOj`0_Q*s2*p)yj&zZ)L*iBf}{M?+53~@ zL;dYPdN}>eTYlD+6hU|lwsRD(20Qr&0FF;zJs$iQ$iMdgOMTL#ql3t88?@LUWG=?R zf8_;6%>tYYNK$S?D&lG74`-JNxlZ!iiRK5$|D^JN|2n(i_;gp$whJEjbq^(0r<1of zPdFl{zKChN7ros-zc@N;-jbYp&d%h6(r$xtT5f2cvVp&TcW#}{soQyLGitf7{b9DM zFDQLJF!KX5eZh5m>s<&VIg7e{5 z`*ZLALl{fTQy`+pYymK)GPIBsJ?AkRf+uh1 zl%36!eJZ2N2z$0XDoFrlIPtke8f<$Y>Fg@trU*5IpH^u+C6pbX9u#!*f)nY7YZsm# z9~K3v?s`;|ae3oi5--jO5$S>Gf-*ESzspoKhZ#xDaM0RbV*kw>UW<>Z9?JM+`FuSI_4Df!T_O`5 zmJ&i{?XebB##^Z(i2Ug`aR@bblzl0r{EhQR1Y z7{esw{SXb&Cx)^F#uphJk8!A@yjA1$HYoKVA9Io3U@5wGs_Mo@t>aU*=&iCkx_zzh zk>GO?k@QTHAVV@n35gJg(%D&-H7dt0Q6LLqbxB?K%B^mUj8g5V)Q2^h$MII_HhCjv z!EF!M2j8GC^{bNqi_nbg>j3rg|FaiQ2c`ILgTa%SLm(?XN4`k&4+_V_?PBxoqMZc9 zIJ#Cl;$9S|X}bwkr}D{WTmZmI^PXTZwFu925OCG#k^8A$KC^W3y-aPhS{3+`qG-bugw;8*FGnO(u6NiIG&#X;qv=AYLo zp=^IY#*iYT^G0FobG~kRO(a$z3GWD$Cbp6z-Ith>tr)c{$j*=%X3fArM?vd=&-!?6 zN3JgghQ|!7T+NCPU(x9d6G3DQDK+B}i^oR$llP&s)ZUVXml%FH9^(YFg>hu4l8vxT z4!$M7SQhFzC57o6iS}#BQ%$h6nxHv#Y>|KZw<`thG(#f&XD-KdKu0Sq6{HXPmQf$y zAsF5;bq2(>DNIO&T9d~sH_&Iolf@chZ;@e~dm`OgVE>hGolPT! zk}DUh+*5u$zBt)`d;H<>=*RazTQz{px3Bh>EP>eqbVROq&=JOc9cS~1&}e@?@$VZ2 zKItrTc69pY_+bCy_}$5ex9<**{D_?kG!xAJn>X+N@!{z0>Bax#{yxprC!_;93scO3 zb2iP_b_MAUmsw3(RGm|F3MsuNStRTu>qo|Nd-C_FW3h*PB9nI^R3%1E6~0c1xH3al z5#Yo9Q$}V(=Y!Y9 z^AATS`#-)pYQa{5qXcvL9KG6cRfTJqpR&_;XBU-ZRUJLzfxcmN8aVdfU%dWs@aFjF zV+G9RAI=iT0|0bukCh)%;{m)9!{Y>Vge}8%S`xW$ixFmm?p27^yDBnyH zOUSLH=wr!h@Z8d6aygT3b{|Ecp*FKqpbvkR-teelk z+z3fegN$VpMNvSs&O7OMPedrrcfl|jPEi75wNxt-s)y$yHO?5Sj|_H1bw8r)JP#VV z*`*^VkqL~dH}ZF@rM_H|RG5Bx!g)1&K9^Bkf(eGs)Nf&mGQ>PFK+sxW$meA1*p$G( zO->YfN`pTXdhIM$V!U%N%ItQ>h-w z?InDt{aY&UYVD;f+*nA5duP)AmA)?9eLkS`f2qV_0M(82F7)#i*j!=y17*~(<< z)QFI@^RhC+FaFfT0dRPa=V=shmQ*wv4C1km1s{?p5*QJC+LoMY-G|mP#dt}YTClFg zQixTc7u8HM^-x}*@+>^h1fnb&+{0OeP&D&xvU@5XXP!zF%rq(^_!)@Uco24(BA^D= z3nW_R@HkT@^*zS zm$ClpAwmNcl8Qz+Myk@fbn8N#HbH0Rpr|w-D0LiYrz^Mp)GaHk@osV*mXrV))o8x= z_gM%}Xf$>?kf|5ji?BdN^e|)DVnT%82Hm!&Ky2Lm(+_Q-O;ieKoEi^ebjsbhC#(hG zuOsyBqc>L|pi3gs;8L3%gx|&JN_F()|AYx0w0$Vm0MXoB{U~fvzqWR;$!I=&zeRkp zwDGlR1hM(#u1jI$sr;x-nRbp`A7qn*J3*BeOohw?mS%zoBhpx9<`&( zMsdMy9?ld+-vx(gqAet1ZAW7iu~3i!@8qHz@KE3SR}aaKrvL<{7RqF zYmR4)(-m47CyGhw5G2)Qi;C&fO=Lql*DjMRTmud?>GiTxH1f+B7c{4s(s$K`;j)2Suq89lK1^QXIq*LXj};`8sob3%SS812;+NRrQ%1!_WU{S2*&B2I8Z zy9h8hG2&NS*}azNQv?WoaTTB4$;X7 zOJBR3gnZlT;N+qyxf!GZyAhPyC}$eP64Z$yHq-8|_JMDR`6nZcK7&e8BAT}K7EFQX z57vdJL5jmPWg9~0oK-wt-+FrEziJMkz`WTgst>GZidOtE{=qwnbS=wNJnunO5SG*f z;OySO8hCgsAmT)6Qx*D_HN>^c!D^0({n@Rg;WMq3d60Bej!wA@W(%;X?4ZFQ40<0w znwEn}HZ)7lu{*Z&v`5g>RIyXXOiHN^>1wgkeJ4fY;%0JQ=U-BVCAL*UNUbMXMdw*L&$A-GzNR&G*OHlLriUXpBt-HZyZJ`^UQqQ*Nkq_J&>oR+(|H zDU}eCP?x`1k5=TQQFBGfQk)y%Sh-6CgE%vZc3{*W3M4NR#%eg5*v_TIa`1m_hc6-q z(kaJm$>t-e;@lN#SPaoZKp>5icj0Hskv+j^hIUw4$7qr#LS$2)>Fk6ATZa3C)2L36 zbQ0s_0Y%OjBf3wnTIbQIf;M4oCMecBGxj-^RETc0 z9|aRFB~;-1Ge5q~3_c_N_|@hora^E58>M$dbD&|!sT71=82Ih>37PNxVZ7LvjcgaZ zF?>-(3{i{?Uh`*J^9sDoSi%13$m5c|7Q-?<1;!b=`cvdDW3O! zVpkKAaJ6`C|HP}ZZ!pccVoW`iA~p(I%skW_m!dF&o5K4y)y6TFGNeMLRYytOV$ZCK zieM-iLP7|dM4+Mw58d9~R!{o9)8~EzwFb9q40M{>6uvfhEvJCf_Jvt*zC3MZp~0bD zZ~4EbDP%6mybgqo8Y8~m!DAG5jb<}}X*eY<7;jn}q@e6#!G#=^fwdBQLm4QcnjfGcV~8*+c=FUS_=F`B;l z@%Xk=3L8JM5;l>55KJwjOm7*3A+n5Z!T+5on^-r-0TGX7DQoD)N*P+P+7NjQ6<^NI zheT?wyOF@*kLns=WuDoHYsPb%)QAS*WLi^mNRpALeY9qQ8517ms(U3w#voX1#n(hE ztXG#}cDHz+h%C0#^I5%Dk~O2iPyg)MW)$Jc~Nc`X>mjk-0jv@hwl!82AE!%7+WuRE@hh@F#(M(r8X; zho*yUE1tE$2ZNsnr|MRp%q^(l(IZDjE!)sqo*?nV=#bu9d7^tTyBu6RV`X+B^t_Y< zM$77Ux&vFjb%wrXKU}*u5emI=eo241rMfHMT=?*N%ukCHQ}YjSrx)upzB-dCl*PLW zSv>#<=bJ#k0$0YFktp$vntBtL9JBMLQKy5l1oGptKNJbJrVc@P@n|&P-5p#teb>}Y zZ3FnoMS(YF=G(8JpKpL;wIBH9_PGE3gBgr@vowPm$dH`+9I2j)H1RcvVAP58_$Rfv zgdKb5df@gvRNZE-3PqoQ8?DDs{y;WEsfON~g*nj5HNI-e8xW}R2Q44rMv!EPDbxNA zk%>rI!waAJ&K&GSS?x+`WX5Zs#@n@4jw;W|sg%jLd$K^UwYw+Qj~6?SiT>W%-zHoo2;Io(z5IXD@k99^0qt~APvsLkxK4MidIC4mN^7p=pt{Vl zF}YQgChLG|?&^;PLbuMzZPiXtY!l3IF^>U?I|-sNxZZ;^L(0B_aB^O_aM%p5%YM#k zl`YM9qSk3b=5^0mjB=p&@`tMoZYgOGAOXqpcY&tSfSIqIBj^h=N25^3N37RB#*e7x z$($i(vjjyh&I86^kRNT~$K|7iNb zrfNe;(XukX;SNH{tViMGRxxcg&}7o#pFBPI>OWS3;hx7(*-=yBrCo`q6`hEqv#bEDJ$fo(0EM((vO-f{%5i4%}w zS4fj=YA{&|_NxUMRk{~Mp0%=$iYyYwt0ysB_-rp(`86Q}l79XEzQUZge?1P3HC_|3 z5UMvgp@?Yl!trxHYUvwx72eK7XyF$ZAj!EU)Si%wntPb3`ln_#W%)0_n1=E!lp;mX zrmwwip<=mMV`GXPLwzWA7K;hZ=Qu&Dh!L881*VE;PM@jr7yCP~g&64)aj;rc* zrSR-h^-PVe2P)Dz!g2_)si|aeAwGx>O zx~}PWrUM_5%45X;mLb$nDz2NR~AmN!r8DhB{d%+%T@%B%mmVKgi{DaS%In#jn4~{cU z^M1cd)v5(Q`S(v%+6)>@VU{^xde`5CINqZ__XSXWD;1G-Ge}c7CwYs}wE&zot2twh zLz}lN;BnU+e0~+$pHH?0wp*yF=lg~@fjgFj?KZ?-H1s%PKrNR4R4}$OJw@jI{~%PR zS*icf@`Ut`57TVFri3~IJOfn3y@|ARj*W?L+bi|{w$D|8>%jL-a@BoRwR2^mN8+46 zK9`b_EL8vJ?n|b)+5HC8GWy%Eh_CvDIHZPuG>L4!?e)*B%|(Js6*O(RM8x=W>e&ai zm@ph+6)h_l5B}Y0*r#93PIc%d#5SlUEN)KG&02FPd4^7Rhx>Jx{L+>L;_kTvA6T{7Tb1pC zB39i1asG#azwBFh0hGIDrD8sr!$AW}g4RZ-7sNruNwi%4hF~9#EP7!v0f9G`9Hg;E zZ7B|33%ig6hyMJ=z_K=|a-Bn-h|SY3wiIk5{f?hS!D&g$jW78FF4ltyk2W*%RuXRx zWriUr9@f^sS6`Qi62B$R#V`lHifsT&Es`v_`E_U}?nR zgh(NB1etkg@EdIJ-`RI~-iomu^tt!?FjlyZtNpHPsuH-*9OpdoOn2K8oVGOLzj`fg z7s~!zBB!~wE_a0^32FLo(nVZ%`P(1Xk%J2qn}l9otRA8^md9NnWdK>}-xbdOol*2b zLmsK7qp;?Xss&)ZAWPD2jq^H{0VNfzthfwqm68 z*oPyH3vNce2DIn{*gZj5xi8z@OYPtT)?uyAicMiqMJkOb1IfKlmV&%rJNi^cHKN7# zy+_OXq%`d4p}iZ+iZuA)c4K95=6A;=j@GuPo2`DdV?xUIhu6c7^InTO_aCkA@0XhE zR>Uzrz|=cf`=S63r7@^T*`b3&VaIU)%A(-HQMtx0dD6xA6LIdJ*2Ar^$?TtNb|+dU z`VXH)>GM=S3ren_s4+5AhE_96hcGpZjau{;AFD5xHboh2$d*4xL(!#@?B9DN8BF=B z;c=U1XzrddKnnEJT-eK&r0rhk9o zdPM2_0xb%|p939qwK-hm8#?cLto){FLtd5OSJu9d_ZuV!$OBU&po56M6Ty;}nsy*Y z#%57$%?vt|*uXcsf!o(GLX-TPxJQ{q6qAg&yD@LTkJUp=CmIKXz2q95%@Y2$h=40s zs@R29yLBYvmkr(0uADjNaGPem_6pl*!?YbH;(Wvi5R`70)6X2E$;gP*cCOzZ=yrdc z3`7mB&l6W2g0X9HTLS#La>iL}7;=Fi3|n&#r6gWeuTl}rJ?DlJpOX<58M|5k@8arv zG?a|k!i}1n@d%$j8EIKX?y{<3@5OKflrZ(mP5< z3RHJ8lSBid=sd;FaeF)bg*x}RI6iSXt^GE6MOnMvG-mMcw}vgh?o&tbN7EBPylaQx zz$jC#e5=Rs#F9$)KV^eC_0>YhFGQ^9bqr9nc5zXmc>e{SQlv2d7w}Ah{x9$>Om1ws z{{Wsl{Jmbvt9}j8$dA_)kPc(NXHTl&7>n02I*B#w4h&m+$v&!H+?>Ke71=~=aO!5( z7_vqD34VHk9P6N92QX?t;bV-snvPL~k=lF8drvg@-R|<5;{B!bbzQ+3rauD4Sm8Ud z)ppln<87?GQu=O!E6GDY6cAw-}EzgV{YiH@g9T z%QaohxuP{^_Mtf9q$;U&^m|DE zzQh?c6*1wQV2j9e5~qZ%?kU{Q{&!x!vh-NJTu>eLNr3u4GBDhS(1|thSR-bb5Hz*7 zB>fWV_-krfI0GQdeDm>hnupBpr50!S``R7j_<4Q}b@}*lL%hl)*-IoajGWQXcD_E< z>z!W+)*NLSTP-%;3W3{gZ5yiAJ2|lLam9%=F1Hu-wH5_?c zWtr0bv(i9{Wgj8GxR)*lU@RI~XuJ}B9RFMOzcGIJi z;2_7fOa6dyD{?F3s-e3CJMR~maV~SGLGM{p=RX(~h#$f&?Zj-qc67f&g1(^u5M8`s zZ&|DccaCgy*uOpRivE;?;HNiuzupl|GvR4PxNZVfKU2J2FecrLBEy7xGJoTsP;+{=y4| z{f(WHT8jOtMua=tnaW0InCss&@EIJK!10t5wQuO2m?RxV)Nv&OvEgo7L5nVbr{%v6 zQ`*YzY9bb@Fb_KhAj3dLG9UzZBK|>f9E9F;XPxPLE_thaY(`IB`&V8~NR&!mM5WwE zKNd7YiQZliqpowIzZ{31VS2U1$6iBp*4Fzot>AwoTe4qD0X`2lFTmBk*@f}h+2`{p ztGw!4Kb@L@Q*gkkqnX4>g%$tfTT|>Y>G!=A6iIweY&HmU{XpYa1T>lWoY>!?>b2D$h9+9#Y4=lwj}X{)fZ=O;}oTMF| zOD+WcBDM^=Hu<6PemTZBpQ9PtIO<;#{$ozWp1tkV5|~feMGUIikq0b`$1ofsE1(W+ zb}Y9LP7#b*+tsx>)<<}0F;#X+0!&6l;sjfG5S5s)0!30-W^{NyR(s^Kn(}<3a;{Qp zl7_mVkv$BnJrJRX*}NL2>%Av+sR!phNn7_~DV*KC`VR&&y9xF0t$={{6IjX5m}7x# za&TIyO3%@vO9{qo0xkF#P=3YRE`e-R?uT~07qsyA-gfoMAn1aW-elg|awy`CkC!dg zykR-BY^Ey0(FQuINR+Yc>Dgphpp(bxi_D(F1B<7wD{wHC%A@6Lm+LH}(baK^y@A0q z(xRq%^El+A$I1&suCN3i-h8QUwzrK8I&u_*{k86EdZZhF&TU=ZKIdvcXD>L3rj+4v zA!zLg6COKYAF)jewkG>|ChCB87OTCT-?PA ziz)R;KY;M5Wwn+cvbaBjS#LwSfT&CfO}qbFF)863H_KpFS$pA&rP_~|f|^}7#=Zj9ju0wGLDv~j{0I-~U$p01_0UBF|s zd8-OJfonDc`HA=TcI$1oMQ#(T3jZsBfx%Hcyf2u`r?tO%(Z>BZ{J#6e$x?czTR>o} z$sDdMh26FoW~|y)#^UoApw6@xZ=C&4;DzmK+23AZe0+&b zFp`Iv8(P|%@kHVTLy>=RzWaisyO-Jf+dypK5uY*Wpa6NBF?mdc z1{(zyJ#;@Zf}~8U&?ae}$*mj^n7`?*I~Q}*4eZqXuKQRfnxK1DnWwtYXm`O^@>TeX zkSFkjot)BiV(UVJB9v{-x5q4lo^rczP{2yG4yJ4QduNNy&~fswF`H8bPe}!y{!VNU z$CsO{-|449Z%D2$^3p{CO39(9b+%5N&9BAIwzb;ly7J8bWPR08GmNK1^a*S6D zJ~DhM#@@uTSxw3~+G+dSrp>Q^TD98@2c9j5=Ir8Z1Fg_I7M>r2p8wQj4I5lv#Jq|7 z)|ThVxgYxA+@vpS6KdrNKJB(#W#D{PwrqSW3fGh{3WG+NXfK-&G9(aMv zk@~K|iaDr&j2lZz^#BJ3%DD$cos_yC#ok<5V1p0G8#T3A<5_jILUu69U|;CITrW`v zfwQidHOqCd39Na_>x4QIwy)E17(yD@w=Hpd>YjC3@p!_O)G`6n_?JXNQ_$rBBBS`1fe#Nur{jJ zX^^x!hqpUd{qug_S)EGn9LX#?mt49q*?y63xbCJ$*>fFO?u?W)8M*Jm9TfH-n6s5| zc(>E&NuF+K&+5!MB3*|wXVZ>~6rn!RJsM3u+-;Qa1;vER)<0H?X9oH*84U@jeYrnW zG*j^O4bOfnp|IQl@|br*21)-`CDU{m{dQfOv_J$Li=VmL=Qh~hEt$@D6pK#D7OsgT zQaJXPnEeGl?I}1Gm+*goIemBBLq1GxxesN;hFg%wzU__=j9mfeHAWFJ-z+ zmsLxu(!sKYI#_#X@{Dtm+K9djbw3p`2A0|?qd;CID^}_kKmi3IsBbPaEsxPD z5pIUONXH8^oYziJa9U#C$G~vs^Hq$3Q>tVXqf&xlF42i*p|}4_r09_uj?g{PouE8b z^X$viM`igPVB#cGY%6!Fx%i2OEiSrTP&S#h4tc>yuZl$fa?s;rXy2TW1oG~5RGPF{q|Ga zPN6ydLwU*vcRMs*QnN^XfI)RJnlTf2`^)v9**4DSNgmm>m0*nE{g-?*^&H^Ny_5VX zTZJ0vn&mCa=|r>~WEdVqHE$n3sF7Hxc6%w|sh}s+nmo2{`niTKmH$D|kSV#%zrIqe z^p2ecpe!Aw{oZRk(5&@6{*05Sv6zCEyP& zZ{Gdfq!`u7ck4xKZy_6$$PzM3No9$Ha)V)s7K?68Isz9*3q9ql1pRR`E;;E>M3;19 zrL*^4_9F$(ays1qQonB+{V-iS=<8M4BH?gEQ?)!e8 z0lC&9z>W^rZPz^+!I@kM$Gz<6O&&kwLuEI+-)UF+am>0{N zvSIPUg)CdW73Kk z#!uz=rw%w9h+@TuRo*k8wbesSzS#)veWHKR0Qpqj$T@Fu%Rk%j}-K)fvPBxP+UZ;j5o@9n~3$RzY* zP5 zoDFW(zIEZ3)_&s^(lBaoU0ltqpjD$qi;%WEHPbwAMRo3WNO7y${yT0?sOXaY>-uIx zsd)9~+gvGqTn53v6lN&x;QNWh+=*I30Eqo7VjlUOMO~-G>E2!41KcRp^X{o$gUonT zAV9y^q|Qg^tu&C41@faN-x8Vox%~YoO3Gz3K>f9ADZoh}{?}(~;l%DR%l6tH%;q8G z)=sYlv1g?$>C>k1y`{tJmP{@$BCPV`fQ0bhFSSruq}@)UmS>calnuL!Mz%ZxfWVPh zmJ|if#P80V8Xn6(ExrHfrzqzuL@jJjYwONlwMR=CBgnSh9w`%9e5edI3{pDyn(YJv z%L~Jo%8l1S=iK`c77`&|J1v!>{ByfZYzE>U*0z7iKb<07uA^e`Rz9|wj%yl;2U1h2m0w)VwGlK)dM#WPCJRPHw2n(HthI$1 z;ahrAt6hf`9*j?Uw-9Y_sCdA)e^r(G!9|MvdzL*pgn$~fTYq5jl&~>T4Des0TJjV# zw10gHreNWfL7q_9^*t{G;KZ=#B6GP^^E~^A7fHm|Qj&ER)~M$1$YUK?$i25&&;iqxf!-FYw8Lhw99AMk!ZI(HH9o_iTmWs_ejPdMi$)5fV0IUCZ(v4M%$OG#~b0>s5=;q9vkxSg9o zxt>SNC}s=#J}osXWq-J^+M{>11xHg)(TTg~TqaXl`qa{dCSltDIFxOLVqi@ofAnD8 zOpoAU1wCVP(6>!^=$*}dye{R@0YAKypEh(pDr9-GZ22ikF zWSjGMlwgRWilgpRp&fox7%C^GC3DiJ&x&OnDW~_Feqmo}cwH;sm29^ka%2qVEubX^ z>Brq6e6Oicn+~6J6(l`>^;J&YCCn`qJ7#AzckiF}HQU}71L&!b++FV>MM*ENbd2CW z2zQ?=PNLL^?$kNb|cNUJ?>MXYHStfkTU$xL4IOC$*Y z1Pzhh#{Eusz23hU%^q`%Xe7W4F@5*8qP}SN?niRY`+VO?ekLI9n&ZaEIz%brPY_(9 zltU6JoBp5*0ID3bO`W%qel?&CSU`ApYmB<@#34#-pOZl_npUGd1R?3VX*;O?bCK<* zms{aCNKQ}mF~4vT(ETM$T1pUCMUIdbO0$DWX7l5U9C2?&4|-OwBxe=x=6rF{ouD$u zgO=I|kB?Wil_C5PdKAa8< zx_}luK*m{X%km?EzSLyQCGHlfP<74CV5v}_`qNwDR#o-LpHWL4#(wM1x$%vIt}uE$ z%+1Q&2NuLEp%O&|<)Q=+*0#UEct-=9S=3ti7IMz4%^o;xXNd-~S&7v+Tc75g;1_fx zubZ<@OA1MHGZxztnim^t^`oms->oXMPKhWZ0fnW;ud9n>z0^8UVT4kj^~gfvJLFX_&t6e`B5u ztxW!2jpN9z>NdzIGf2Za;eTWEs%qk<0k|KU4riYG%NI{1O@s%Rd!%-){Vl0mx#HK0 z;;5@7I>vNOh1N%mRq4Gt3I|?F?Z_33kHQ@s7A|MlCp42|X6?puPp4A8VcpVMlm}|< zb8S>QD$qCRFQpn2Ug$n`m2Hvy-CX)(;Ct78A@>-qVdbOdQZ04m74v$ZUfe|g4!jQj z>RQfLma%yjpm)z7pV}8@o(dPNzxC8B+Kpst0#O@5Y$ojNG0HLy2utFCj_(4%B)YL^ zWTfSQX+0X*qMGvFfMRxLHZMcf>H#^cgPk0U8%At4+v%+bWcn;~e3wa?%;UJ$-`-5Z zR#*zhN@qd;>w<475UL!+D4<{zV6*eXv?lCAF&c{2f2S|q3DIsdCzX@^e!hE9zNBQ7 z>ww|b*jzACLFSkuyQ+EeLWy2X1ofvt!$6u$yYsV*2FBy$)#%kpq&*cu{;HQH<&d<= z{*uWWIIzRQ_i!RbuNFiyUe8x+Ti76!^v-9w*5nFTdh4PWwLW}VRI>9Ii2cL~Vb_C( zLlZ>8A=SO4{#qLz@~}h?r@kX@LlC!a=jz)ra#ALCkZmH_!NPYaL71}CUPlzSFc#0N z@5fW|s@a_RTeV&9qPIWPHui_d(pC}cmrwoYJ>qBg_W_M?PU+6|G(#*My2BKi0fI9{}W`kfc5xCr)y*@>Q6yXxPSS3rX7X^RRR^9K$2a{T4 zvG_x|p!#ELn_@c+1v!p5(!;!E1sdt22o=wco5D@LRRGy%Bf{&EQ6ktd9$5HUUzRuh zT%n;r#^hb@&LeA=Bzx?sC-5!%YXHL>dsf^V+-E)YXra&K25B;zK;`B@lkP1&%2zg` zPdnYhu@C0)GPB5EQ`}@6eK=R;!G=d#yD00_#Y;+~Y}>xS-ql}YubEZW*ABT#TJ42~ zXe+-puf<5Ud9>UUds;knpxZ-C{30$Xr*fd~=5w!iHQPC|y3n0;oHsCd>X`4G>7QOj zci1rTwW-8uELdZK1{Qwlrl>U6_{b0%hGL}G_T;P9z*~O(b>gf7?HXD2Itb}Op!QwR z@tYA_^9CZl6K=r1m?7)Z;oy-z1SPN2PL|TD(@qjRLKGdFNv6hDQ8azfKc0(%=er8SO^z18Oj>Xs2b_Y3A@xu42+&=Tr4!kdv@|s#O92qet!XL@gh>|G;0N z-K@cpJpXchvOKYIG{@%FWx@MKTOGO~`tQPDI%g@BSob%PE_z7f8yB(~ZtTC(01G#p zh?x{usr9bWM4*eW+!JN4cLaAq3GtiJ?&;| zlH2qW&GZ2L^VI+JW_0;E5%flX3ohS-M;pHd_l}O%YkN{d0xB{8ZiUHqnx$Dw5}Bi6 z<1)yRa>{!?Bj=MxSyJaFF!7t^ZLLsMALWu$%8@gMg?)*nMh(yV!P)U` z+hh+^?EGhiiX*)@MBzRmQK8?HnVc^-BLNWpn~>t%Kn?ntj6@w@lPF;_@tpadFy5RJ zUtCcyJr$T72N+GU%AgnJ&1HwUK!9VmJ)if0Lg+`}##o4`1k43QoO;E2au+3(GgHj5 zo94N8vpK|1y}hRzy8nAPpgdj&3k&$}S}a`&qz3pI6p;y3{!~Ol>zJH_?|Z!eiONTr;LJ=kvK>!jwFp)F(#h! zF(U+~;kac6ME-onzw!LhQK5xi)I-S#PK1JLEPMu{Q$5Na#5ylxbczHu2p5EN!~R7*2ww?S zuSS~`GYgYH^QTG}@p9@Y(aP^BS7HF8X|A9 z_LYT@(dt`nhNT%E(#@7(51khCpe!RiwXw`Vij6Zuj7GJv&i5rscTqSY@&tfh?W+i< zNruzb>qwrYP)nM<(FEGW6$LWk9D&?R=C2ifeU_dL4mE*lZ)1GJ4O4GNt!G5}LkOon zNL>m@j~LffOju-6BhkKP5vJz>oslm%<`uk#oD>*Tj$S??>>ZCguY+47-XOW(=%L#t z>vLS6spsg;YEg{WBNN$DGwK0(3hFqJN`JqP-^1Ks`7TO)BD@G5MC<*?N``9)1S=FS zgR&4B{)BY?t<=7e2S0E`pbB$llnM7Kv16yP|L^(8lIA({oqttI{npbdC@K{Vk;IAc z3S*dfB(b(PsO%%V{0((P0bi1kR17g-4hy668x8R-gmdWvS7-}Gr6%CWyV+O{6a+$DB@88fBI+Ul<$^^ zeZb~VxIXuQ3xNw?qIX^g?c@$7M2q|w*->r>@Xvxu2q1(ihoTt8fR=4c=g6mrE~n9MPYN4H*c zs5?u2#nY_CCK1&`5JXk{&aK6f7>a-3d1IyB`m$!QeR7-DqFeyg=Q;3MaYP4IeC}3V zA&Lbq%!0v*`2^Q&|5IX$F%nk5+LqiI8N3AhHeu|=4~Oe!iK$X?tiV=SMOT(ls!tbb0YxOYLVbWXY}94|tbRZnF$IcGol>Cv zfRz&qLcuugva~aPbXlj7xk_-ZhN=4T#(nvZ&K@xsmsm^+)wT&=;ASlh+h=Kq$Pxp` zR065Sh`%~;w3XeNDBf6Py-QBjzb4<<5=va!;lioq!AMx^m9>lZZa78T;`j&OJky}zIsXv!R#rO>Qblo1G+DaF1AZbQ@-f+#T7tL|x$J zmGH7e#MtiZyNSf>hCl%1NouPD6w7eQDXC*A-A4gj$zg`KLoI|5xig8zMEi;OfwliS z`PVzdoTn<}>iHP8)c=*A=*w10Xq=nWeg7b3 zf*Uc=n=MwJJwIyf+yh147xPT_wrAKgL=o*fEZuqAn;$12pVdDgKy;Tzow`?G&3iP5 zr*BvwU!(mC6q$^DA%4NmuVOIAPGeq;0u4)ZgLQ{Ze1D6tZRgVagYbQj0Ip0kS-LEX zxj zvbyS^kl{sZ=?xM;J#GDOHM1lA*bZP{C8>=nu8ex=3o(j*ub+tpUKig-5FXgG8KqVM zKigEh7Eoq=dL6{wInynT5s zL<{FLzej0*tTpWG$kym%Au)tkKQA1G&*Da(rdhcZ2ku=rcVWsvpf8&236`#{lQ2kfg2 z1S>MKiz@0U_4=Ph@JwF(j6CuoRtwTEzm4aZ#hTebSI>!%kqu%yt0>e8mhT6EEiyH> z!WL>@k_at>@AEH(DO?`CXu%BKhqpf3VjcN-?)}nd=-Eo0@~FrvmVil-pvMP)iS)(# zz=Q@Uw$F2Mr6>JBkq7kt+~YG|+G3Cn1ZIft*7@$($tmgky-1ee!;exK;joRQwGo+q z^Bpaxr3#x*HIvjMu(SQk^N`+vjtq7qY%tSz=6x?m%EM>&A3WkNeOPeJ$G^hbFs;b^ z?i7B1nHTY4qSf+3pA^Ou+N226Fl5LvSH6CV1uVAhfEoJ|WSxHV z5`=g7v?I>Qo)7ukLb}{m`kcY5SIThvlUp_G8^{KYX z;#hF=eXdiDeyLC9;;KquLjcCLGU=A|qHV5IkDN$zR_%Txze7M=C+Dkc&vte?r9m|m zX*Hs2^p_F{^V%Q}Nd>z=fSF|jHP;Sqwn+X=dWSO6@E+Cn&J8MOG_g@Ck z*70ASQw?D-H|u*KJuRJhp>>Q_2OB3q3p$XDJ=7rdhp^-CsbVm;;55gKXG(0=*c5pm z$PT(Ph%`dnQz&mgH#dFg{f~i_`G-jp&F<}Yc7~%18eCHDOe+Y+fT5ciJQD-0E3P?) zT#|@3Q&^@{d?80t)bhpKbxz-myXGIrI#Jz;_&`|?1~tYNyOosj0qF^*9t0Vh^lx#- z@dz9EP|>{K(ZBl*_9~rPLRhKK!iErge904=uPB253R*}SA_~%O^uX3~nF;|#i!o{^ z^o?~_ma*h6dzoD_1F;IaJfzsKpjSZ<>>UhT(FHDnD|vdjcdy>S){j$B7b5m52-OMe zF;>;8&m8FxIeEP;>P8r{4b}ERTSwt=72Sf-lzVs=>ruJV_>79>Hc)KU`)*|t=``A} z{?9oN`$6#N!FfVdh<;0SN9ZX;u}*2H(RX}Qm`G4$8lO7+0LGaHf#Oz*x~J_PkMSA| z z-?cq8WyLEHsTDodp{ctzcruveshhfsNGG@n|DxegX5?b}|1jc0RAsW}Oqyr9ze%#o zOVI0CK`GeB0OZo?zeJ!tX*I){_j^Q2ga=xJG&|(+eQ9bR_A$FCrz{(59N=tjWTkcz z6_OLe-bS7@&Kp~Fw^#AtjfY16BkWC=m?N*eJ3kRfWx<6zI+6lhPT{TERpn zD-V)qur|t2Bf$<#eDUBkkSYx@MMS$FUmU_6Dl*CdbX7Lb4avTqRUF_}49FOmyTc+P zLE)ipj2uu?ExejH_JvCiaZKqd!iM-5aIdyA8NR@j zWzIWgG9^M6Vg}r`k&o=;;iAN$_P-3F*rwJ7Dj&mkWcD2h5`2PUwEiTlQ;GdoM+UZF zWQcbZ_+etl({VxxFI^m+tKX~CCZcJ|E|0d*Ik$yL-#pVGbsjM3;;HbKgej~8i`fmk zwM^2}BCE^1V0yJzU`f*t*gL8)Lp|zya5}0IwP}3UV@OFI4qYce)c!=Od)3j!}>lcaL|Ge>+3 z*DQH;LUzz#JfE~#cX9?gX8gO_BOr(7j{Hwk=!9o}Jh0W5>~6BBD%a@ACIHv)r2J!U z>g&ALcklA76A!Q!SToSOyz4{&?uNH>K`*O>r>8>$xWn15BL7M@Z03I#Uj^an2?(98 z#XS*z9}R3}s=l+o$Rkw9Bb!he@J&@V1)Lu*x5yznmqw@P7U%{ zMtbh|b{(h~InN4Xk=<*gzyJ2Ctwua7zBV($;uB7ydr2#QD)n2@sywvZoir?-WC(g1 zeOuA`-l`Vkp~covq~vSM?zuMybTJe#^{mgAZv@p-b>HJO|Dg>yXANt=wySm?u0kNN z^=b0u^(^Nxs7*_MY-)yf7QDE}DQ{)ExQD8$s*ONRRfs=mdq2m`An|Qk`rLBFUvLLn zm!tEu6#B=Lg#$O??!O+H-Y&rQph4Jb-?`o_IYvBzv+vI&{6HewiZl@eTpa()){ZW3 zZ%-4rbZ;IzA`xiESbV+m5n*Dk`W0{IYE=ptRb zZEU+Pddc_dkHf)3R}i`V=|dOOSFOO-%A*(5Uc1#>lBcc@1q|jaVqty$#h|&{{^230 z_kilDyIs!EBhkUE>p7JaxYR&|B{vL7Z$5zDYH-`+Amn@V=-6Hgu7&Mx#S(sum-2;H zdek@x*1HKdQc_UcL%M)=9qzic?QMTj$YqfhE=VTtN4U3Ju@ z3AhMWUxC~I#?6~VIE3hiS-Y2Ryy z9q70Q+gS+J5RKNxFx?_RcB_=&3j!L8xSoq;#Q$}urkagWa3^^=(Sqy$4*kji)mYtZNj!X$P;jCQdE9PJNv9;B8Skryab-nx%O; z4IjLPLObig+o}XlJ9r=UkNV#fs`Pw~t}GsS3l)3TfwxsHpLXzi%l$OKYfJyE4ezR= zK<(i5)(xtGw@^dK)7eHvh1P_(9eu!HsY|a>D(~#M2?LY$Wy-dNcd>s&SSoT>0p5RR zJk1u3mHVsmTV%OveLFp z2?+&J{cQ&Cqobpvqm}qDrD4RcS*juO&ant@!qO>MT#*78WMznP(*0}ztA_XZ>o)LC zB1Yqq3wgD(Cj|#n2)KWNh6-rZ7M@>hOCKJ#!Ux5-MG=cGm+_=dd+dg_<-u%DNm_L~ z*rK!{GJ~p9B00$fmW++rjfvhwg8_B-r0RQE1FukQ`Q-dbv!YwmGyFI|edkY*orj9t z#@?~fuQff}J|53PzfC+|Rh+AZ_p^w2Ykj|cCZTVw;l0%uIE#NOD}Sxw-Ce-ZR(P!L zx00^R5AUubkG4E@Rm)8)ct4}k8Li;`jH+m~g7-5jsL=}EOWD|kPnG8;AU?krwu zI|9*~K71yDORe$YGl^i@6yDFLBu6`VKcDIx?cn`<3U$=L`@P6`er`GW9 zH15f@MXVS1v;lv-y9t2W5ajmwuwm?u2d-^mcUs?Xn*{N+gLSPSo@xwF4ZNFrSBeVE zTe(-Z#)psTX4xQqww5-$o0c_}KUwuHAv zoUeh`Jn*R@8sTlP6IlUoJN-l1X-C}~L0EPut8?1f*{^@KzOM>zwNQT<-rX$ecJQ|K zHmaPr-FO>SosCw&+t%%<0`G3zj@Dk^w*E&Icz5G}v=zKfjz}xu-P93j?fYVP9!ZrM zwS>1F|8VQBNimX^6>*tW&m;$4bWwUK=PV@`8~Gva#sevLGFro@XgA(Oc`vwsF_Sku zy+X2B?<9X@HC>R3TFsqL$qTowBg{0++Ze+V{1XfH*dugp2xG436D#+W*I|#Ptr^$!c(|eT!Z?t^`WmD`)PIP zk1@9H_QmCMDkpO%!uvgWR&oqi5{TL%dmTW|l2aQ}X*v43LArs0cY|HPIXjbAhN*=gg<-;=Y`?WgV;JD3CGEE-0CPt<=) zH`VQvAJOe!ko_OLk&mlRpgByzJAo3|A0b|0)dcF}7Fti>b^{pv697beP16~ZKXTC& z9)LVJxuKB2$k>NyOsLMW7hbz`XU>J(fO~jPMiHOTXx;!!k&G&d|Fng>D)xVlN!MsP z%NDGfM8+JrL-c2UM;A%NhU-qCP6gWTw=u6d0ms(t^j+xq_;wT6O&W^#Wc1DP$r@CsjS05h1a93H z+dP3L8)v%-?9A9%N=&rD1jlupffz!ya5??y(U-4ma9ZcJE_fO%gxE?)^5wYkuBF2DR<+?ygS)) zZISYp9rM?g%Qi=$Tl3UkZw{MJU}IO}-AXna2s9h|7S~T;E6GL)G!Guug(tO{z}n8G zyOnG<5NNjb-rTKZvw?p=v#mSlZY7(|Z{l0@?_5W+*;K9aoX3gzHFEWpX9gx@Og_QLP7as|kd$Wa%}n=>aETz9Cd<_{~D+K0bf22kpTwOyI%M3Jqb? z1aRQGygfJp9d4^#a`G*}wj>k;gq8JyCp*}Il!4+l3S%E%{oXn*xZgR2l%097I7oQ7 zc0qzo)hcEJa~|`wR$Xm;#g@eRF3;m=XR^gKwmrmo6qj!n-h{`l&zE2U5xj{==`Vv& zO!zfRSwO~1hdh66pkB9aUu98!@^~`=O-8A?1&YndD-G)A#B}W)C{17sGFqC;$0DPp z39OGoMiMB&zv*vV6l!+zwGO@x(xRL1&VKEv5c+bR$DwqR0qw%2>m&Gd)w^_U?8x;I zJh|#eKzzcu*9(>|LLn4i*-}?+azPfVZfL?f2PPbj2fu%bSvr_O?MdzadGU*`(SWyv zfZa|*{T(V_$>p3yyUrF%8Wq$lz;4z{`@!Cgn-(dmrS*S%LJc)) z278q@+6VToa>o**$Ew%h)`7iB2kirUS1wr^?9=FmE!LGSlSAxBbif~)V*9N=2Zn+4WuUznYrEN=K*G6EzCnK>G6WPulTIjUq zy5VHO10|gN#8M1yg~-y4Y|~BGjRt!y7vay~x+#I($}#vexNZtyw{!>o46d63*e#ua zKZEP00(J}6-_PK>(O|d9L|f>zlH^s!7G#XPe?|ebr&&Xog zOId%!s9@yR4k0)g&E&kFP$6!38a&1`ZvKSN2q}2BsLnebwUBhoubDkiLXie*L;Z`$ zl5bx>|I0xA7fco`CAM2Nf#OJ`ey8&-dGYe~(;;~oPZ*K&P$-Erm5^tiB@th;;E;sy zcg&TTDMSdgpKH++hNlT6_Ld=!?+H`)ZjyhpfW>D7ML1UQ8`Z(E}>Vf-9x`=#O z_bs`9|8sq8Y9E3OgP2)-9i|+L3HQnCIT%kwmNG$>JabW#1f1as z(wMDt(1jDos1~9&N6-Z_S)m|V5`fb7CX{nRNf1t_ELA-rZ_()(mI1W9W;=f=B>hLU zh91;Xs%ye6XFt`SU8^I42}soF3mV4xcZWoTvlxP2W2=UOlQBs{fSX)rQOr_04x>;i zEQVO*KJMcgPSZn|^r)TAYb$WnP%r}@oY*jS$$h@&wP?P#0q9z0y@7I-S2NZpudu5O+p2oy~wm*v2FbtXf`AlJk-JadC!N6Gfnm2 zH)$vt;fbw)ZpbheJ7Ix;oL8l4b>)%FoXl9Tlu*Ci8A=INdO7=@&Us8GRFho2;FFY! zxjK)svUoQ%lq8E~7`cB9O!1hMiG<$7EFg5I&bz({f6B&6=$A}@+CtGxmXhZ*rZblI zH40uTdP*Z6vo(=U*oHow%isFe(~oysA>1iZXFX!ptK-w55H4)#NaGS3CzLG?I4n%1 zaNT3@x7^*~-*g+!4MnGdAtFOu6TqaeAwpxFwkeknV9q{7G1GrUO6)d>AiLFqP@;1J zDuU9`1tyq3)Rt9fpQL=jrMY1B%tPm3(uvGy1nV+Y>z(SxtP$=#O9>rI0mj^xmkIKY-Cwka~|wxCJPdUiVB>&)QgJ`WA656p|6 z5MHDfM!Y!7CqaK<-#tNMrkc|f!iJr`n)b$Qp_