From 8140d00ade262b21481a152796487bb535957dc3 Mon Sep 17 00:00:00 2001 From: Jennifer Travinski Date: Wed, 27 Apr 2022 10:38:00 -0400 Subject: [PATCH 01/22] Added NeuVector page, linked to Security page --- .../v2.6/en/neuvector-integration/_index.md | 79 ++++++++++++++++++ content/rancher/v2.6/en/security/_index.md | 7 ++ static/img/rancher/neuvector-architecture.png | Bin 0 -> 121627 bytes .../rancher/neuvector-security-containers.png | Bin 0 -> 71277 bytes 4 files changed, 86 insertions(+) create mode 100644 content/rancher/v2.6/en/neuvector-integration/_index.md create mode 100644 static/img/rancher/neuvector-architecture.png create mode 100644 static/img/rancher/neuvector-security-containers.png diff --git a/content/rancher/v2.6/en/neuvector-integration/_index.md b/content/rancher/v2.6/en/neuvector-integration/_index.md new file mode 100644 index 00000000000..9ae34e2eac2 --- /dev/null +++ b/content/rancher/v2.6/en/neuvector-integration/_index.md @@ -0,0 +1,79 @@ +--- +title: NeuVector Integration +weight: 22 +--- + +##### _Tech Preview_ + +New in Rancher v2.6.5, [NeuVector 5.x](https://open-docs.neuvector.com/) is an open-source container-centric security platform that is now integrated into Rancher. NeuVector offers real-time compliance, visibility, and protection for critical applications and data during runtime. NeuVector provides a firewall, container process/file system monitoring, security auditing with CIS benchmarks, and vulnerability scanning. For more information on Rancher security, please see the [hardening guides and benchmark versions]({{}}/rancher/v2.6/en/security/). + +NeuVector can be enabled through a Helm chart that may be installed either through **Apps & Marketplace** or through the **Cluster Tools** button in the Rancher UI. Once the Helm chart is installed, users can easily [deploy and manage NeuVector clusters within Rancher](https://open-docs.neuvector.com/deploying/rancher#deploy-and-manage-neuvector-through-rancher-apps-marketplace). + +### Installing NeuVector with Rancher + +The Harvester Helm Chart is used to manage access to the NeuVector UI in Rancher where users can navigate directly to deploy and manage their NeuVector clusters. + +**To navigate to and install the NeuVector chart through Apps & Marketplace:** + +1. Click **☰ > Cluster Management**. +1. On the Clusters page, go to the cluster where you want to deploy NeuVector, and click **Explore**. +1. Go to **Apps & Marketplace > Repositories**, then click **Create**. +1. In the Target section, select **Git repository containing Helm chart or cluster template definitions**. Then enter the index URL of https://github.com/selvamt94/charts.git and the branch **neuvector**. Click **Create**. +1. Go to **Apps & Marketplace > Charts**, and install **NeuVector** from the chart repo. When configuring Helm chart values, go to the **Container Runtime** section, de-select **Docker** and instead select **Containerd Runtime**. Finally, click **Install** again. + +**To navigate to and install the NeuVector chart through Cluster Tools:** + +1. Repeat steps 1 - 4 above. +1. Click on **Cluster Tools** at the bottom of the left navigation bar. +1. Select the **NeuVector** chart and then click **Install**. When configuring Helm chart values, go to the **Container Runtime** section, de-select **Docker** and instead select **Containerd Runtime**. Finally, click **Install** again. + +### Accessing NeuVector from the Rancher UI + +1. Go to the cluster where NeuVector is installed. In the left navigation bar, click **NeuVector**. +1. Click the external link to go to the NeuVector UI. + +### Uninstalling NeuVector from the Rancher UI + +**To uninstall from Apps & Marketplace:** + +1. Click **☰ > Cluster Management**. +1. On the Clusters page, go to the cluster where NeuVector is deployed, and click **Explore**. +1. In the left navigation bar, click **NeuVector**. +1. Under **Apps & Marketplace**, click **Installed Apps**. +1. Under `cattle-neuvector-system`, select both the NeuVector app (and the associated CRD if desired), then click **Delete**. + +**To uninstall from Cluster Tools:** + +1. Repeat steps 1 - 3 above. +1. Click on **Cluster Tools** at the bottom-left of the screen, then click on the trash can icon under the NeuVector chart. Select `Delete the CRD associated with this app` if desired. + +### GitHub Repository + +The NeuVector project is available [here](https://github.com/neuvector/neuvector). + +### Documentation + +The NeuVector documentation is [here](https://open-docs.neuvector.com/). + +### Architecture + +The NeuVector security solution contains four types of security containers: Controllers, Enforcers, Managers, and Scanners. A special container called an All-in-One is also provided to combine the Controller, Enforcer, and Manager functions all in one container, primarily for Docker-native deployments. There is also an Updater which, when run, will update the CVE database. + +- **Controller:** Manages the NeuVector Enforcer container; provides REST APIs for the management console. +- **Enforcer:** Enforces security policies. +- **Manager:** Provides a web-UI and CLI console to manage the NeuVector platform. +- **All-in-One:** Includes the Controller, Enforcer, and Manager. +- **Scanner:** Performs the vulnerability and compliance scanning for images, containers, and nodes. +- **Updater:** Updates the CVE database for Neuvector (when run); redeploys scanner pods. + +
**NeuVector Security Containers:**
+![NeuVector Security Containers]({{}}/img/rancher/neuvector-security-containers.png) + +
**NeuVector Architecture:**
+![NeuVector Architecture]({{}}/img/rancher/neuvector-architecture.png) + +To learn more about NeuVector's architecture, please refer [here](https://open-docs.neuvector.com/basics/overview#architecture). + +### Limitations + +* Currently, NeuVector feature chart installation fails when a NeuVector partner chart already exists. To work around this issue, uninstall the NeuVector partner chart and reinstall the NeuVector feature chart. \ No newline at end of file diff --git a/content/rancher/v2.6/en/security/_index.md b/content/rancher/v2.6/en/security/_index.md index 0cd5e3dcaf4..8b782b613c5 100644 --- a/content/rancher/v2.6/en/security/_index.md +++ b/content/rancher/v2.6/en/security/_index.md @@ -24,6 +24,7 @@ Security is at the heart of all Rancher features. From integrating with all the On this page, we provide security related documentation along with resources to help you secure your Rancher installation and your downstream Kubernetes clusters: +- [NeuVector Integration with Rancher](#neuvector-integration-with-rancher) - [Running a CIS security scan on a Kubernetes cluster](#running-a-cis-security-scan-on-a-kubernetes-cluster) - [SELinux RPM](#selinux-rpm) - [Guide to hardening Rancher installations](#rancher-hardening-guide) @@ -32,6 +33,12 @@ On this page, we provide security related documentation along with resources to - [Rancher Security Advisories and CVEs](#rancher-security-advisories-and-cves) - [Kubernetes Security Best Practices](#kubernetes-security-best-practices) +### NeuVector Integration with Rancher + +_New in v2.6.5_ + +NeuVector is an open-source, container-focused security application that is now integrated into Rancher. NeuVector provides production security, DevOps vulnerability protection, and a container firewall, et al. Please see the [Rancher docs]({{}}/rancher/v2.6/en/neuvector-integration) and the [NeuVector docs](https://open-docs.neuvector.com/) for more information. + ### Running a CIS Security Scan on a Kubernetes Cluster Rancher leverages [kube-bench](https://github.com/aquasecurity/kube-bench) to run a security scan to check whether Kubernetes is deployed according to security best practices as defined in the [CIS](https://www.cisecurity.org/cis-benchmarks/) (Center for Internet Security) Kubernetes Benchmark. diff --git a/static/img/rancher/neuvector-architecture.png b/static/img/rancher/neuvector-architecture.png new file mode 100644 index 0000000000000000000000000000000000000000..d690a1af3b9d85e8ea998e8a08b8ae0bcc3b2b14 GIT binary patch literal 121627 zcmeFZhdH{7f8XDK@bft5aZbl|E}!f3d5!0Ki`3RsBPL)VKtn?#zKT%MMMJ}yKtsb+!NY+6 zf-}>Q1^+;I*Hu$Sd(q9b0)N1=RnkyGL#v7-Jhs4wKjXV1Zn~qPQFx&KMxU}_^+7{B zE4Zqnr0;Y4dnUF&)u)NT#%I3vCA~DI$Iq#fb#tWJu0`pU_3Gx-+zP?=#wWSwU0-w5 zHaWR2RBPh)M`nMXBCxiv~9R(Xd{nDp@e21^EUw^UKc>g+MVaE$*``2Fx??BbZ zfBqdW*n`v#`JZp?{r}(k|L+E>HtNDngoMwZ-`(DxbE|#&^y$ZsA1$kDs;c^?ryFZ( z=tM`y#|sMznlVC}bF}#`Uc6YzL`9X9l7dG#J3D*f!UfS(qW(-%lYI;&1B0hAF)=C} zvp)}lf`SeX4&uMGwQ0^*33>oNXRPhkEd4DXNQiCzDfI%o}OMw`a2^7 zLs~-W)dg=)&oHNW5(5f6tjdbaOlGDld{mFZ!juRW;^N}M4fukt6(|!dRJ?f6-PIM6 zw7tC@8j58Uc*x7k`_o5ubai0?%MU#@HPzbMx{`YJY6j11RZUG2ChTV?$Hy~*ISdI2 z3B5e=y1Kd;ycmSq+26lA8QD2FJdTZ}iB!=o8EkFEBnUs&#?x`q(IM}{(9RAH#%RZ+ z_xJao5oW@Oo$BpHyXEfgo|{#PCey;6gC)gmXVgv_33sqP@lP*F<1EwrBs4Ufeohrr z%D6lA?%;5(B80Q8t?j|#O40D}@O7S_lit&EZVPx;IAe?#9jHdx_9+AfZ@;4}TZvOR zO_B4HK;#q@ELK{yHhp1YV!|P!LmS5lkn!1^(JRty9-eItuP~~@K<@2t%`2SjP%eM1 zb{xs_`*Dd(q;mM|WaHsXop$O{_QTVS#xtDzw`$!MpPj#@`0LmD1a4dK59LW55+=Mf z+#lnO4e7UmblKZzN0jA}2mj-k{tP@5to9Lnm#H2D{5-$=Y|yx-Wx1d6E*kd^R7fSq0K5jzfm5{soatM;1_+3 zK$EU?!E#hRyTCCUd4HZcwPx;^HD3q7uyk zD+|XLzl#VbzoCJJhKFHUCw%Ak^ z0i}`M6K;)QSCwkU8FP|Al5xJRM5_;32^v?b(w6^@J(k1A5ynS}mifp4s*)@}P1`x| z)K&KbJ-SLJx|Gm`n$q#oYv>UaXj0Nlcr^M2N^-d*m1rv}2IzBE=%2J7uZkouRWB< z7|}K-X4_qM>#gR+WI^=s*2sv68o#}}1_sorNDo6q=rONWmdCw&C1qt?;&JW%2iuF6 z!%0$8Qj(rMqgcTRVmp7HSeLEw?OVwhRnC5;K)4wi8XCg4-z_h$Yg`|iVCm@S&?XMK zQBzyne1k9ki%k&{DeJ%QI^FPKsXLPp53l&e3!c~K`S~M1JDa<1Ovw?1JxNWydfn%F zerR~OR<=Cz#`qPukt7WKsExXeW9|VnBr7XxRgCdza&pLc4Bdsf7|AKLAuc^ux$VtO zIuY}xk1>p-Oj4VZHTSxbg>9>hI1<`>dtFB>Euv`78&_Gjy`2t_v1q}X>(+(2Wn}us zX$-ovIe*5*+4+1DB@NB5#bh&hBs);XOky^lyEA2~-}PawzOnhj(EiS6Yff_7pV9%l z3oYV;Q~C4fn3I`O_vVBfk6&7MJu`cFvRl8=kS=Dc>F+PAKeIaYT=@MCg_Ci$1GQ7y zg*zWVu|6b{p{U62yOM+M?CgwRr3Mdj9P>}_;8ZFRvwOI@j=uMM8yOk-C?S|Qm??NA zi2RbYbin>>cu7f#lLTYZ_J>GHVq#*;s?mvwdb7rW8#ivuXyyd_?ft+W2{R2232A2J zr+TcyK@W}J`SctkBV%sH=B8_Oo)i`q!bCHx_lhwJlWr}% z_4ck(d2~!nO#g+Q8rLbpe_H=agiS+B_tDe90Cfdl$-Ti21Kr8C;gC1LuVnctnm)g%2zQtu z60W4@OBbhvJsJ%G_Ef`zbd!fW5nYQU^rBW1Z=6>p=Yr8}t*xo4s1!R^RjvJ4eZ`om*eIAetl0H9}f%+>`3IbwXva~PfJVlS|9hEX$mSXE|!0A zXk}|lxzePiaDv4_aIvJKB0S`cB+lqKqSkj8-+4>86PZ5q9u$EUSY2xpPtNO_o(&8&mI{CnS1}Mfzchaxe#qLcgiMc&+8g zSzcDgB;}fupU+u4MIh2|c>6x~bt5w~Gc7Hb&Ln;)*Zx>$8LPVEUr7=Qf-uHZnEy^H zMVBW}p0u>Ih_i5Gi$_x>Z6|8U->kC44rva2|9ySE8Rz}`_mSl@KC&zod3keCd6+mv zuCA_lcz7w|_PVO7I0?BWCH8P3xTGvd-4b(TsRx<|)njhM@uKPkWsMmlQdW7ck@TQW zvTl6U!?`Ho?u<+BTXSs>kGDRhzOucntQ;XLO_123e-@4g7lzd6MZn`EQ<02Ea7o_% zI@<6+hK@6JFdF)%=GWRt&%i*Uk+Yp09ei)x~3Ewg{rbulTQ;Vj{t*Fo{bI7euXvsxgfkwJSNn@QVAC;=A zYViG*;o+WyRq3j#s-NG!3{2JrqY8`o@6#I`9)^AJhQ(_@q#wq0r3@w}W{b$HmoFcY zFcUoYkbVHAm6LRxM~^3QabdxKyMtFPj>TGpPCZ#@vg!_Q3K!Ln_4SjJz3Eo7b}@L) z-0IKB4wUZU64Av2?rT#f80B2xjV)GkkI=8$`Pfyq8lXY8Y zFUk(60|;{GQ|yQ>Q<75!s4#0t5cS^B4>;)`fXtWd5R{0 z=6A35YfX(5p9AcyBF#(!e0+9QGmCTWj7(u|mgK2^=<@RN0QYJ?p1XxAM&ds;X$za} zMR76OH0MYH3lUw-p?DjNNJRRdQQ6%)IQYR_Btq#5GMtkpDpDpJ^*^8g_aNnPu(Zsp zsECscUd38jS%E>WEw>W|EATb`-&F{Jd3t(!d_1jZDe)?Tlt);2f={%z(3x7x(Sffz=~8WW+^&>iz@>gv#b(cbGY%I$FfEF{cG z6}KN>YoSggB_y6)y%zDdbZ~GGFHBkVDt_Fjb9{X5ot>7Vsin=*sn>B*)vsOa9~f9$ zUDa>E3Tyg7gu^K#lip@o68C{(abU$GNKuie8Z*2#$U*ZF(yXU3T-;j2_zv+|u|re+nlPok+v9AC0WGsi_HO zcO!sks1B>ue6<{_J0GLzFIawnx(X*|^!oOhURz1KqP@M{exUHd!D8}sz|s0Gm-p2! z)AE*CTx5gL7)o=+I{6=CnU6MSFDn-)E*0yq9v}Qv*q^~vP*AWQTeq~ak#Ji;@Eu19 zH~6d+Bp>c=kajgaB4#u{r{6R(;yv3E_CeLo`FHx1~wS2nSTNwE{Pm8 zBp}idG|IZ$w{M>|0v&+~9aOFz1W?AmB@`bA2d6h$MJF@rV>k-4zsC9dm{YGmd-8;W zh2@3(&DiAR5nvNu-$!#Tkm}C_(djYAFlXO+tuyRf1q8@PwHeoYolm(9uvST_8SdnC zz!EblDd}dF!s-4z%#F^D4tqO0piAg{LORAaHs9c3JQFk}_*HxtSxHFs;({}2rlyvL z2KGr*WF$KOWaC2xK}=V{V%g>8z3GRIo@>L!#e8I4d3kw1mwGP0SsSSc5eiO#aZdXE zZE2~1urTQdiqH39-&PWFhdexeY2G~c$`+q%g|~LSFaPDsm$mLo!7he3ZcwPMe*30+SFd4?S~uWi*U;_#&p=Y_ zG;+-tlizp~J3rR9DM9-HmLn8f{xFmr|!C7q|Ki(aGZ4a$cTBKz` zE1yj&?W=6|uqhBdC%?J5*&JzaZ?A$=+2B0!1_o5snA2S0SV{^VF{g&6CJrXo-5O^N zN6vzQ6;}VvW}wL8cdfWrNeRni2FJ$eH9NbzV~w(;Jq1QNEs%f)xVFgvIJFM{ilz$u z0LuilifW1ev^0kH#=Dc!aQQP^KJZgkzeWFd+2V-2mzZ`L8%HSd7?vCF4&QRw-I!)w z5D^vCEeJM$aL(`r0G*l9sypsKx0_t}sR-!oZ``0s2x_xj2Rv}}Ydzqdvh;C zdAr!zu_dPUiRhBOx)Me608j`}o0;r~XD53(N+E2dRZqJXg9GKDkOc33h#-eM4$CHy zN26b)|H09(lET-{&d70lXQVj8dI+g}7i9akwOX1+ppFgt(>^HZ!7t3*Cw}lOFlH##N?+h85amQ|hHgMjw zj>?Por>6jvA8hcuPM6M$py)07pASN$qoc#Z!cxwvF({&|T^4Y1n3|qW`5eR+^DJLq zUy4X%Y3XAhbpo{KGxjpxKSG(+qM7JvY1NPeD?6}K05D|rEK%~GO(AA;a%?}vGV8I< zW4DGL0=ZPyXhNWn_|A?8NjN4)X@I+nlhbz)btow)%;~xA1Ev6~m3;WUMqhxMfcM7+ z+=-kLfR>C30seqAEs&t~RLaDC3em7C6bfuMZ&J&-mn`~^tIvs;(JALH(%{_P+2Oj; zECLtc2U-ijsNPF{etsf~2wZh0QLA>4GP*iDzkN=1UmHF@SEA|KxH3?5Sz<_|wmgPP zBC>7nm&bDeiR3+5az~&oVPj*H>k=FV3se|auL2#KNiEOj zdGn@ega6INOF2fM00M<8(#j54d};`51Fs7NJvRGSwmn%A&J67-$!{gwM@P&aGBYz1 z&%FiyPR^+s*rL?^C0&w~PJ~TFglzB!)a?An7)<`^>T1(^uk|O~>I4J?Gi314?gHT3F1&qTtcWDyyg1Xz_t?H(Bou z%%H}1cNH`ZC|YviV{r+IN1|t6D=o&h7gY|rySueD5ePgZ%bPb-Uvi{1HRODP23)A4 z*qj338*eeU{2@qjA|gGWpQ^KN`XPv_DmK)x5#TPmxw+}ad{Pcmx|VzV^qirPQ6<_j z{kY2FM{W1w)sGtKIi(+JC&tEx1_#M*t*x!Sy*pW2r%ywr@h6G>>d?g z20@yx>1o!p1GN95#f%89C!kjy|C(@t4{k-#9}*cAl`d{i!Dx0BY?eIgzgrxHH&avQ z7*$6(_VfLi(~8lad-f#3x81V_=X5yymyJLCNnVaWvN!1e>~h%WzmoX% zP^15%36l?*Ot~dpaRWCW^!^y!BeEq@BGH^FwDVM^OgFXPn3ep-L9E_h}kpn!H4YJhp ziU!}+9eX2eUReNs@$8qQqoV=gNjQ&-KRi7Koqp5<7GSUO{@S;1aPJ$NgCg=nZYw_! zXL)j6UEL4x-Vuym9Gs2!ds8qI%;{SO1}NQZtgX+RyvB3-*%C$wl*_dYP?2(5)16!l z!;0IeZC7DZYkBwXT|2uP6afptIoWI_t&_P#HhKiYnL$N3it>$P{RJx`iY_iLVq#)h zTyu1H%ra1(k^SmGk8Q532 zK3)+M6}9Qkuy=O;GV3aTu#ngqPI_+7Pv6-1u#MJCN?JPjwvCNV@YUg=A@X!_GCZt* zV>Bj5K$s(Y^Pk}BxhxGqsEU*j6JGQVJWC;des&3T;QIgsc~V4bUpOW`eF{&NxhNO( z;(u$GL^EyznVd6jwU$*Zf}|4MfhE2^QZWq{5Fq&o#z@bEmVPP8I;!H_;)=0 zk>_gNc_T6eu(3#)hWh%psz+}70Z9}b85|U$i*63Vb@^ITm6L;ZBQqnTVSkQrziWQW z+@K9+(XaJs($rd$A6asKH1OmKbU{ZGGHZ}^|8|{^faKnCZ|=SMk3laBi;A-4A22*F zFE7U~2%SGXIs(mt;$mM8U^5|*ytM~m0Isa95jp@EdH@U@pwQQP@3@|&J$cSBN|QHE z^y1jHu_%Ip{dYxxT?H;`>52o0WzhZssE!3Ku$5FH1Nu&|9@HWn*FhklJpg7qo^XRy zcgbhde2v!c6qN3qnh&CQOLd-WY-d1%&1pf3wmbz)TuRI+@fiRZK@i55&!5?JcoLg+ zZdBYReya1MJW`u4L&p0>NeO@L3#``zV2N@$gW?4pm@0LTgNZ~iO|z)=h7sCi7$ukJ z9!Ardr?)W==p42(~a~>YzPp@gHtKR{^#?RUS znr&!!n4+ta`r4yOi)3JdmHZ$SW9aGXTHd(>*Q#`p9a~h4j%bvbE3rKv-74^N`ScBf z>eAxkh^VM2*btGCK@6qW0`nE+{03wdd-2|1tpwashxd00D=v{RON+Zqy&KNYM39Cm z=K>YPExlC+FN&A=+ePeha&iI!1b`PPL8RK<+kywc<{bRT+QLl#0_&l7($M3yD86e^ zDlG=^2K!$qj403rND1Xg?oPrkmjS>J04%xI)PI|2b?9^@;o)GN*!%s&XP0{nEe*_T z{`~MiS~*8$%3;_9X`3f+{ZFtG`sk4~tc9c}YhSQ%ao4hCZ|dqQzc_bQQ*(G^1Z9bS z@Av&U(%IQL&#MW|AHViRB=s}Y1C(FlS{%!jD_5AMT+IO}Bnz49zCT~6QLHbZKkp(Z z7b7Am$t&7!C0b0K1SGfaz2Ba+lvME##n|X*{Y3?EeammXh4+onkS0j(s($&B;~!9L zQc;j5Tk4)A2xM$AR{i;EL^$&xU;%mepO29owDl^`<^wQd`r57!dbAPD8x&*o6BImy z{Vfa)Rx(i3!NsjxveTZx`QUITNHmh_^5s@=1FTmEOMp5bFXzXBLY23eWnpMI06gEm}e6=Sc(t z{QNEwI2gb=FuFKUDmx?vgu&r0Q^tqF^S*Zv-Ckc3qyr|AkB%cR%8jcZi|F=fM#G?m0J6B;B=+TaVm}dA{p&fbt&u&@*e{yEV+^D>wg7*eG**j(#uRt2j6cKbJ6%`eQfhq$ls{(kSO*w1` z7iVNVA4TM-)0@=PF<6<1TWL%wnBfq^IU~L z2+&2ELC>;IQRKjNRv8gm&iY`d4@_*om40r9m}iNJn4(vcIH?H2iReM(p|Laol`W}f zsVC(^NX<&}b=|4(>jk>G;}9v@bw}1|f<6vpVCyL=d-WH~Oe*pu-uLlINlOc!Bl3T+&6iw! ze0X0YufKc+7&}eGq6K&Wc!e)ty~-VhyQ*(!7=i;1Zvc2*IkB#Gz511EQqnq<#Kw&L z`cuu#7WO*%ZW4FD`am;*O3p0nQ@Kke1CfCe?M6r1&nS=D%zvv5 zoGq|P<>2ui{9FprQa+fHm%sJK3B8T`S3iITjNRQ`KtIzD_9j8s0F6k|1HusRELwr3 zULPF?cP$WyEBPPhlww&%@-n=*l(sm~3I`Wg!S1TDaa#W^Ye??^OltI6PfJWpbeJ;r z%*f27OnlP*)F$V1PEOALzK>;fNl8a*E7SyIvap%N#fx9Qdc+&|xTt?wIe&9G znDN&M38P>FJ#Xx%q)<8=WXFnA#L!CQe_6twnFw7 z0W`Uaii!f7XtTV4@|dKUG+kXQ51UXr+Ek z$5Bz-6jvb#Vq%hUohO6{7Dqh&GxmZPFEj;dAj<&qkm3O*3L*$c0-uZw0MWGKe!bSEpGxJk!urAx`8&mcq=)w9Q366&0&Vo-`}gl(${<__ z6==qYY7-C?q{73BC)T82Rn<=!t!ik<67ez$WVS$eqd3T|jd-P}K=ztc90Q_iRGQg* z3YRX?zf|g|r1lE6M$EcORdP}dK^9L&IUvv9C~!DXwpVl$T`2$)GX&J1RskmzZU0Y7 z3PEDWJ_?@3m&4sPrBF~6fDNI)#1eY#FeCu61Ch5^6L}fw>8r-R4_s5M5)>5V(agY0 z2gY@y%n1GT#qAN3NW=JKZrxU88hNrel{1iA!e)sQ_U#z`1kE7oNOa#0DSE2Yb z04mt(Si*Amx4A~ytU|_>ClxDU1cU?!=Uf9NaH%IdoY~aWv?t>dCN9QvS=Sk~V{ARs zS2o0mi%iSo)s8@gVrcVM84#hPP6eAGnqc65ZGC-+x6-4)K(tM1L?~4}A0O7^V2oU&`1g?g>Aln| z>uQQXKf=C(Wgm*|D!Wf;Oz1^`L3FEwK#p45Lh2f*gUjMfgr!(>xYT_7{6SB0$058` ziN=G!q?}=HXUC_{=pRQ{6N{ERi7PE_Aac~e= z2;a`-?z;lqAdBf=<3mXr4XIv@=KF1J?HmxsHFnsVp?l&(ye)|VmEkyDO3LYOUWkYea?>>yU z&I7qTCK6tD_E|IeN2t8_4#U4z71n)@50>}9kcevI7&&7f8ykZS6B!rBi!!Il{zzN# zyt##i-(YW;BNq-8ipt8qf30;tE5t&LmAya74a6s8K|u_w!W0<(CTHPTI5@!rPf)`N zub=2&%#V$kjf&tBQ>+Sy&ij;|Y*9cFut($n`I>REsJ7G7Q!s+X8Dg&cT4G@+-MmR( zEco;qSantc@OHuCfAoY13AjD4Uj5vf{{(&4f#k(e@tCah)T-h{-B;E>aS`pU8I_>??GH*Y4aX%QjHqN3C-EjjSk z^%NfbzF)q7?w37ndSp?Ob$oB*!}76-m9m zeUu;4YbU-f4qK;0UteFg%|nHWqzJNDkmP`1NLg95;97R8&8rTIgd6eBq01zjjo*uE zHkg%833u2yL7p*w%+{^|Y5?KFo*M2=$m!i@fXAnA^Esu;d*k-D`q2k%z9d-s=WoAD z5nQytzv`WRO3OBZ*T>wQtq?b$!HGzRH+l~e1ju$oW`pXGeeo+c)A!P$2Fd z(62*ySEthzN~Bw@thDqYaJ7X~tv1j(k9ODg!1+!L<0ub2!zQ8=33L)heiAdgYH!bf zaKMh2r`jXh51GS66O`oZ8mJncCVQ007Hp||Ta8lNOJ8_=G ztIxLer7m510AR}wX$)^0O?M#}^|tOOhn`UCztg9E2B>?!qATGviq@E$ecU0LtL^ja zYb|g{{Tnx)T#-F*hhz>`Ek%*D2pV{;iXp20k?L2~)z1kEay3>lqtA8Pyt*k!Q~R?K zGv@W>UW6why!&sbb6Ehz(mlvw3y~)zK(!s$$)f`f0_O2JB7!Yy-#aJ43y-1XE~>zd zQP9{F)vEDA98yyIM;ncMo11KnFN{ID_m^+X$!QuLtpRmYaBezCbsPkMI+RB9dq#Tv z7X9lYAdL=C3Q~pJYo$*i3z;c<|H;=^iHe--07oWKmiOK`4&d(tt#m9@!?1aY2O+)n%2HG%SxqE}xDcd~l-#>|cdYvD z+eY7A2gtnEy4!~QpZ8RnoYia^qGupyCz$nl0kC;hS(!631fM*?&kO9S|EoGEBV%Ky zsvT)z;5Fv0yDoJz?`M13*znZe8VUTLpE9n<@$hw{c6{fv&W_M5Jk%J=RK9cP4mdY8 z#U@ifE|N;%hbgnfeXVn8&d0a2){aCeM9&_Z(H*t9 z{;IfntlLcaK6zsdH3|_$+Ba@^f%OaF3zG250SdSJMn`>sIJDm|HP!er{PchBcKoMy zR=GThtGrx4vq)`25|nqM=9Z}m*V^RnR*hDYqna?mosAt{&9kn2P+SB7UviUk(Sg@=oPo$B~ebp!(D1jS5UmB$jBr zj4b6ptNKmQaUW-uem8adm_L2G@Dl#w6BfBefqwjU7P*%Nky(!FYLWXKu@h`RZjvVD zK^k~l*g`b5widjOlw;#JSSB8zEr8#_n|eea{EsSljqP^8S=qZo(I?0HE6?3Ck#wN& zRO4tKr&Tmm&*=QOs9tqH-p$%aqTCg#0ybj(6a%{V#dS!Z=>EQXZcsR<{eNm`Ym*&R zJE;mKhs45;2fhe!H=#Bg=EQ%OC~NDtjy(5JLzA2CyDOaDL$TUXv-J*!w_h}_ebGEe zj_}5Es9WK(PIk zbN}a^5+I9M=m^V8^wJ>g9*+4s*>Yv*&VKi}neY&!Pvxsl6^^SFySi2S-;xci>2B`F zM?|#Xl83RBP*Yru^NW9}*FN9z4Y`%&$er!{F^@P~Q!5ICN`Yeg( zj2YEG(gHB#vdI4oT5H|SdoBsHkg=CLgsOsY#28ML@kpv+g4vx9glOu+>H~<|%ifjppft=D7iB5uYDIqG_GN5!yj!t<$2xGI^2vSHPp-F}*2+cd z39%=S6!{tWw>>~f0UhOVf8S$XE>$3hL|A2r|Ckhvw#H|Uyw!xDmcDkfiQ&oi;r{BADQn~+#@Ki9tVb5g z@2I*@*~4sapSx?vvUNA9J#+0tqt)hw|L~4-Z6%`_E{s%JW}w5U1k4UAVDY+0NYumP zf@EF$_qHnW`X zV0ZTqpqD6X9ZXNmGZ{8_zHHA>&e9RAoIX3?XkhTUN^yiq(O5l)^9C7kVhe6u<#nep zk9Pd$p!cfSt4O1B@$m2{*E#gkX=0Vpv`g z7^QsYj|cwx*#A9Lrks!_L0^S}k0z=QSxMwpYKncMzv^{Swm){@dN}2qcR_cTuD0Im zQ0K6YF*?wyq5Epdbs=F}S5X1R2!x^Pg-q^&Nei=!p)b|^2(X1;d(!^6rNi`d+>5s_ z#{S8hgGVV9^R)rQlVV-us1gTV`xs&T#wj%`YwETAfNBiG?!fWEOaTn`FxGk~?R)O- zA+l^Xg@uLlyw~XvMFJqEkSS(MLWNNPX+Oq65~{(L7E8$8 zgDcB?$!#GRn^6B(aSIr1rRW7gB+UXw1<#*9fAvbNU8GET7V=Zf3IVcAtEZ%>HI+QtSa@;#C4=`*BB-5 z%6hIQ9X4L{5dQBK=35S<-7OKVdq3oLLb=Bl{+;FSG>1oA`PX01xxN2b$QyU>$g!fn zs$JTX(lU}u>eX?I`Z0R_^2r;k47WTQ{r>Xe13%{yKd1IlXALZ!3}CGcWc1S2p3(4%RQ~E_YIP4n%(K=-;L>y!OrS z5rAE-a0uMO!Ag{&q{jLH>&M=>V};z=@z0!Ovj@A>$J`#|+gw~+{&0K(>Ng9{WdhO4 zhSQRj)gY~cR6%yhC=;||h@gRlPFjEYZCP%hAgdV?g!IF<+tL+K>Rix%Jj%`Vt@Hi+1j=N~-`RFrPVwWBq zz77gfY797OvPpdM1P)eM(05}q;C2tTwS^VyZUnYj;@^@FV<*FNb9V=`M?Yp71W_+M zk2~VJ%)j|YuVc*XB%U$XsNC7`Gd|VzlJlkHMahq!nUxKU?!;NPup3`>_HN);;iE|Z z_%yCDd1pOlzjss)N1AzNrV@@blO;JkJD`B zcZH6bfW&15537Q2^!r$2jNr|eSpBG^07SrhD^aK3qRF?LD)<~79sT@{P-1sfJElCo zU$dv**P45k!XeEy{s*E9ywM(eKPJsRP{%cTI(m9=b^MRkQO6;l8nERKtjs)zY@blg zn!50NthV6Gw`<)BUcRIt!3qzgk`h`VA|#xsy7LK~bETU~w2;qHyx7&%Riu%QbH6)N zp+dCZ;Q0-uQ^?oSi`ghzgU4o0-JjbCR%#$0!QdezRKK*h*TCV|WxnIWmrV-W6+oD_;y#VEDd<-ofZ-w@oFWO&K;eI7a@dh zmj6&h!3Z)lv$&&G{OF_TR_2kc;as@Y^{fHnqFpQu^@X=#c-dswzkgh36(+iDCh`c@eje;MNJT= zFqL=%?Rpqn?>Acr+1wtxrKc%UK{)n&3j(YHk}<{29I_cWD|80FtZ}*)cpxAwCnWTN zOb=ra*Y(Z}_&sp$2NFTS6iqfAWnaj=>Oc&YA{!N4xO9IT*@*y;9{>J~?KFfN(4Rw+ z$-Ju)&e*B3OFV#6hrK6FPP396PQhopM9k7u0{9x})Q>3o`}-Ah+2we6RPTSD!t}Rt z4c`8?bd@1JjYjzP_a8qr@BX;(yBSQEUt9UH%dwzz0p$&G-F-7>ySkbB8!pcDFNk7P z46gU(yVOs+cBC#+_h_A`8M>ITXVK4CuyvpujyH8-?V|z_op}m_j6ud_l;ma=C?xI$x`Ou9#C5<@-); zF=a@0fH8e`2}tHP)oY1<02*noSKwGJV)~6Uqu{5uwisp^nj7}wX&_WPR=fxI2$e}A zAHGJnf;u1xcG1vt!*iX^4j79ePN4}9ude8k+xrS(zq^u{n&}xC*B7`D2*l>zo|cvt z?+q|41I|vo`TXJhRQxGOK`m}dO6X3d<>g-hq;+(lhky%BwLAxQkIQ5O@zZeGRaFNU z7t#X@>TZl1aE2Caia`em+rN49rn022?l3=2KKRGd>@51(bdaoT8o1Q#j`xow#0f2s zV9Ii4*{w4tB`06j3yGqT7I=D1NdBGbeUM^7- zY^pzQQ02J{?4O{2(KuHz`26_S7&xGfTrsbWClLzocSaFsZrvQXh#tLZLxvTODBg>@ zLkjQrn7Bj_eg(g=71NDF@5``y^CoWPXu)e^pL;HmPSa=p)ltrW9u4f0mZ2f)XA|PO zB6ScKZfyy|#8qU7l!f{wAR&Px?^Avo?{T}pm;|T;Zh-z|H5|*l+5X0^FR!IVIbN|H za{L7s?!`_eZ~{)e)fgbh6a@+J+bH<(e#Yf?z$s(|EDk`J2YsK0h6WyV7y%VEwbC3| z3YZuemX>!S?+t>1^TrkxBL|ZO4%FXt4L)ac;|;gvUrMSRiX zZ|08bBTLbBMf&+ATkjBx$L!pBnjp;|vm^VIj&1$nkE=1SvpA#ATT8fNE%=h65gj#4ubWC{>bGlZH^0NQXpBl20sE(ydkmfQunW*OrwD7O$gZ*Mf5Roealba6BCh zk@x+G68%;1UqF#Iq2{K5lWI|MaU(wDnmy>ie{%ft6IRK7Q{^dpq^CyzC0_Aqc>-g) zY~iFX)_Y+uf5vKD_8yG>YEXYb!dY*E^hM`(!nP*9wm7|Gt|Xn1qRl2wVjf;VC>8vv zkUgPOFX{?m4nlFL3B7>2b*H7t?Ae-nlj+RgW+;?~ue=}#oCIegft^-s8w?DV8PoX11t`k@J( z-!+D~t?N@d1PW@sh=d|GF)?>o)==oMHv@-u;UHhFk+HF|v=5v0uElP4ESCgdP6liM$Awu;c%Vj=to zr?E$_aOcg|8-IPN{-JE%Bg&jaig#fvV&2sA&Z5DSJC>pc`9LPo!!BNllkhK^lfT_- zXqhPXv?yb^*k*9bSX<9`e!g$8)VG6$v(Qv3xh-)kbi3E1xs1|d)NsCrtmu2%>#w9= zZz7PQv5G`C#RNvwkGTbf8cSbP1$XPKVybw`>9J8Rz(Y_ov#!A}axN>W8x~nUN+N@dh_~R;FZpX2oLeKJjNB3A(KO zj-vT?HZR#ZR*t8gtW^bWLsVCk$MSuvGI+UrxazJR26*5G9Jyin*#^zfe?}=B9x~u7 zQxUW^HRV76IW)0GZx4R|3ELp~3OjJc?zD?*;ES5WF>P@;awlJsltks`9*6Z``T;ES z{)uuH4uiJd%!~EJjGb%7?_$F$k~*wuSM^y4Z=~v6BfeV3>`=8IcmZd5S}Qg0PmfA)<^ksBsgj@+@){&Q* zbyXYp^TLD)Q(XeJFJNmFf(mCH&9J3OwWOF3xW9xE^j$|WWZ|t-K;iaD9$VgCsmf)_ z8a4G$;!X=KGW~f6oinc~yHbM6;d%p(09tj>YWmj$hZK1MI?&Fdj^@Izix~hA20pD= z>UB}ve$3*Ml6#(>Ux32H!Mms4&-4Dv5LwPtEj`gd=4ASQyDs{iB3q^5qla3n*KpF{ zlh&e!$Ya(xxdvRi9k=GOx?-mw2c$mR6A&0b+GmD%uU}NvyppW-fx%2yazM&DMM?I9 zcE~=vV!1c3eu33A`VpP`r3jzc zose&rVh*$O8~kGHdO5foQY0p%YNu0+CAHMv-;;j1QPMu5b>%im``o!~;YB=d-1lx~ z!=${?J7M#)8`=4{Nrh+e>W<4Mkg8l0@w`4I`JdEqRoyk85u{#Y#h&m$Myc@#eAJ&@ zrNS^4h$nt*(7tp_C!=eTLs?|4ZM*eKizKH^d_Vh^iOVCT`lq%&L_!wY(`%C;6QLqb zf<|b%tKYw0&+h}d%lq=zXG{zXowKep>b6!^;=tVCu(z8#Db9ZvtFSnzuJQ*i&Tdlv zwqJ<7X;N=py;ijxtT$j({kDy0Oh<1-7D=D+G5h)1D58it*VMyi(IC>=LDhFMbLh}o zY!%%A6EUxGME#5a=?vXZO=@e1na zcegwX&*`dTy^Oolu6(F>Np)zU@;<)V8`-EcOSQzkfb7p-bYiQ$$nB5_(x7H@KrM^k zzO9C?9v211eFLNlqp_pATZoS@(5w}LggGS(-&lzLd+LG2${*HZu?|BIYngkCuS8lf z>$5}#;hU=q^zYt3;^m4Fh>pN@0L9fdwj>}yn_SFhj-c#YBqpi43ca^ z=TZRiT$dNhXPTY_q{-*2wSHVk`boHC;P%RZ8J-UvHz*xOp~Kx_!4`GrR;r2q4Y z4NcO;owPZHq%V@k!f&xCq>0kk3VmF#Jt{lU5EHa7gdp9BHP z;coRPKj{+^-$mTTexDW^(k(A(dZv}<32AP{^s`PQ(ibf9DQb^>A~&Bt+uM6%k0di| zyEh>9_+fWo`Id$*pV|Y*H6Qut_Y&dLS6E^}CXevi{`nJr0gS!?sE(pyV)+9r|Hmz1 ztd>`ib~4m3s+()$(jDXM@i`?8x8Hj=7W4H}o{QVWgp^&g0G5W63Z*6cdMOq zl5uGmObsSxm!6VSDI<--TpJW}*6+>&MYG;{@w6(mzwYKoeomK{Cq6WzY@rerFX9R1S#fyp4S#LV_A*hGmR?6zvAZhVocYCoX zZ>;c4_WkUQjEB3gWts(sV|@|4@_N_BiEQn~wG_rkr+9uBn%)CSdf>6Uo#k?%E&Pc&nbS zd$~%&V))e7=C;=EF46foVX2Z}7n!d=ZG@?)>sfyHwA<3ILk!|A!)=PQUF21xh)(K` zKXwrRsNYmYhS&igVj7=E{Z-RC{( zjg!%xOMw+`LMs$?vB?JXLX=)C_RE6A*_gS1#mJVdjZZy`0WX`(9Gk@Ea6Syj_6Vmu# zUc>+5`nG$7;X)=(nwF+EB_?FX zNuKvBUR^FbWY=%L^Jin{IF}i}rJ`3jjjnsB&T4xj}9U35J5KtZ(Rgc=Xjpwk}h z!0z9;@CQvVWsSQVf;mNT`E(?NyHk<3kvUG(g4d`R$6*RBK`S{3YHB#EAl-TLNueB3>6WEL5x*b_i`mBeIK=2DmTDAxo6YnMk8=346pknN8tWt6 z5Y+fLa;2HEgiAjaHJ|0mKKot7Tgcsan&^L%Lf|Fv2Vc0P7LUNe!885W)lg&6s8tTi zY9kPf>sY*ol`@nx&b^qtXhRv+j_PArci#RY2EaYIaiUZ5Z9pj9Zl_p-T&zBdH0b{} z1v$LG+}i{GfiCw2Jpht-fCv01X=teZ9H7*sk6@-~1d8316b*U#Xrb|%NGLvcx0Gn2 z&r@tIC{zWeC_iijn&8U1r^SDmrrYLdK!b*VJ3Z&wp=fwC1IY=V`jnVegF{~hAu`P- z>f5I5u(iWND9m_qs}gzbiuLNJlj}oTCNs`~Qf84Q2^@YNZnqc@^gX$*Y7twM70t-| ze{PE^Gy0^h^+iD=<(&^FA?I`QMjm$5|28B;*rRDE*&9)KSD~-IBfR{y{A3p~|7kL|c6Xo2ROoUmzwSggso`Sh=)?m@AE9jF2VO^xtKn%fg72GyTQ#JO5%sA)6Fw6L$`Y_W$ z*cv;!7^-Euk@KlzK&Y3aG^&nvDEaox<4T;WfY2AEpxq5>r(iWFSk0iPuXo50yLheK z05r0H+orQ4);~PLO>v8{I#h4HGVOhSBzy?bUOmC;yQ>MW9G;N> zrA>>!xGzlmI*W7qC`=EUR4Q1+E8GQ*Jb*(dFLA0+T8QbcIsR`B3WI-Dc#4kMzmxw6 zu%v-V7FY$u@+TbEr?P=p>i-I&vIOW8j19j%0fWS;U;&8F1G1$hfNyGE78Mt}@}z$y zL8%duVA4ENpfqSQ;_|4yP;@$NzbDQ|Txk|- zO>VpkzjVrFYtc+8<{U!nv|l^?^|otL;`s$}=2!n~$n>Jv{i3kigOrr>{lEH}q6uIg zLlMRbotmAU{q?p)0N~q*hRUTrTz;zi2M2#;e*uRDej`XBgys0y05q%x1)o2E#sPT* zfP}r+FD~zZ`NGPI*%`N3^8J#A97!5|kV|GJ>gyGbchooHKOY`qy5b6#h2|+EP!~ae zlw!p$w|=W`RkMY#Rg};(D`HbKQp^G-5iJI+=mv$}JX@9dTFV^JB(DE%S8Oj@!*rd}1U%PiHxifQoh&+nM*8t-)MdeKN5;i6&R&q*RL~QHvlqH%v2guEZ%q-~=zQUFSyrF(UCGBrJJXk(rzkck z>ZzqMdFcQ4Hjc>j2^xxu7{tUU2M6Y+rmld713^(`+AVG%@uBDy<{}_vfkOp2Edg2z zRO$T#0}ISj!9vivL%1 zsMKbZFe*Pq*R%<)W+6mW={2~*G=MuO=od?IysU`kbEY`_&a5Xgxjz3EONZnzYvCPu z^E48)2A-gv@w4<~DKFSuwhH{YpLDXU5+o0}OoQ>8zh2pe&_q2(Eq1TcbsorD#0=Lv zW4~O^W%&ONAB{k343Xx|{8H4s9&QU2^653}ZETr=D$=j> z#c~GX9Iczrx`8PV7zW+`U7BKJC#GiA|oK&1Jmvc`VGiphb%6pBq>qR9vB2H z9>BPQ!7n&Ge5xzO#XT~*(xuXqQc6zF@iE2I?--|RpcpM-MtnCM5+y!m{3c!8Kmr}! zzctvSSne1J{yxfe;~ExeIoQLL+kPYw)@~aAGsyy`O1vvd&!=?kgpVbL)i{Ux7e<&@ zKNlrz1zJbxQ@Jk^xA7(NcgKQY)wl!D-g;*%AZKRpzs}Jq-lO9DS~Mvibe&G}A&-g7 z@$yVjM3&|2yt-({7qrSD&X(wft(*6;2!^Zi4AmY}@SUM+A$5UlwT;9YFbcHn<(S?H zotE}EF`vhod=HCVhCV9Z`&Z@XoD=M>=UpSf%C{&{yVcQc91#ySsC@9tj!}F5Pjh*x z{9hH&(cR?K6fQpg_sJJhC)N^hT-pHDWANg`Tm*xD6N^};*~F~a(pB>=ru7e-{D6Uay-F%Zr{sDk%t%5HF)=o}rNk!zBMC7G<5_QWn zlWoyWW|3-a%UAm0bF%nVqKwk0ou0&Oj1atpkCQIP4%hG8zMgMHKqO*fCx}<>k`$@l zWGIe&aniBWhvGyu!R$}6k;|;fzL|{RR&9FJ`^$$;N!qy2=wK{;5FDG1SNqk0Gsk3d z2)vDyWTOOpKsmv1z{rv&RO02Az$xs0wRe!Oju=&Io+ApzC(Qj6?J?7jcW-<))Fwk# ztnc_BLD(I03l}h9-#lqiduuV_mczGGX)ueVF!{p2=H++~c)lYq#p?f9fNT1UBO_!G zih8V@x9M%0N*cWQ2{VhVb^Xc8SIVnN;_@3teoaJ#>^fzY#@$)lOIFJNt}(pm6{;52 z)?a|!A6wf6D(q~tF9!5pQMU}%9x%a16{>*20=nYEiTn}Z!G&*goi5jr1;81B*6UsR zOBRlG5F7Ff+OUXz)ICg*HcrRR$d}9vNB2P0wlLiVE4C{p&DjiZ>fs48Iz#v##DwRk z7M8^LsFu}hW~hn4BN6BiO<`FljMbScTDiV~IrbI|$wDoT86nN?a0)mBox-;Y9!zV(D`!wyW_`&^ll<wn(=+Atw{M@QlPx)DXxX2c!oJ;5VM_<1)zR9<{ z#)KCd`d<87GES}*aKAL+LD(AMHE3s$H|~0GzcjhNEgAlgknw-jXkMhKZs27HUgBmz z>b~T0w6^la^ik9~5^2)k0GU1r@_qt=-p6};;(1OVKuFTBRvSp8L6!lcrK_UKIN zC(QJa-2>ov=ZN0Qfqhr@$ijVKcBjXef z%@CtnXQp2jHbywHe3fXvgmGXwB>50CydE9rzWs*rg92neUADjxZ~^HF!}dk!6G9>0 z@UKU5*uWnpO&P|r;<|2ZfD!L61xuM;cuu! zaHM}3*Z+4#l?N^lV`Jmnx1PYl4}`qNK*%;T^p+x~59mKZV*tP8Beky&D8a8jFX?46 z-hIL|W5r<@a5CtFe3?fupM@S=Qqxs`B_1l0#obe$1=l6|CC9V04U#vA6(mzT&vpG9 zv}59}gCO1`FQ~n!%n~)n=?3iDDsC&QTv|cUp=8E=-Ut-$kwOxo- zxP}w4Y(+6!eso}TEr76zk)!z7#p>hd(G-p77$>BGT@WH8H3kQT&fj zqV&JL{`! z(Oirg3l*J&e>;V!vu&#(W(4dQ1AaE zLW!4+s&&~56%f?`7sH$7vSx#{P2;1n5@T-URp~+jMlUkPyOkibn=Sg%jZltbaLds& zY^!YDKSuS&KgIrW&rZ{@*XXG`)6_^-oi$1zdFi9wKK&PdxJJQ2>;_Zw8g?%renC#- zyt{KjnLW@E0wXS1T>$^a4}=PCZW@9pOqCBn=?M}vNQ!yQ-qh6LQj>tWb&POoENCmS zr3O|iDeh|1vQ7z+x&qOq`;78=spE4#Q6{z`^(Cg=I9{$2;=9c3(-}U$dqGiX9y{kF zZG&&pg2wM7*%X%A)r@1#hiX&>MBAFLZ@skiWyr&w0q9y(mJLs?)%wpBo)`#fdjB%CIY&vboL$!oSM1UnyqsGeVUYTxp7`uLsy%7g_KXr@7`c)sH`S z)iUbHyEAeIV0Xtl46RcACv>$1^S>RkJM<|(0gnrcA`)LHP;QnrDby_hbA>AqxdER( zCpZ%z1?H`n6){o-=-7tbs`J+ekXFnxCAUtn685yTZF=Mnh}*KBNjx{7$3W z?y@AzzL`$9H#1wWxyAOw%X3JB65MFX1I6RmW41f7)g94!^B6e-y5dw*E7OjrHq^&D zR>y6QU8T?xIf}+=?n63>67x7Rtk^qpC1R2Q69b=1li5$AuWz_NoC%M((PSe>_is(J zoV9<9A5S2kbw^lulyRGuOxF}O&N)AK)w0_8|3CLmz?=(`DZYyS>2xqBn$K?s%8X6) zGPD<=F3>!(SuZ0dOrT4=MA;bjq1Cs)%qhRy|p+4pL`6{Zav*97j+~F8h*^;%( zmU2Vc3)()her9U=jp? z9<@JP&vGHVQu4mlvW66V0snYyAqz}BPGanM)N`*Lu+CZ1fhlSUp1yMmS zF5$u!>|Ik3g$SH6>J%}5bV1&|@2{7%7|_x?0RbT}H-k{a?ya8}ZG4hIaMr&WNyY>N zNolR<@^)Vs3T_ zwUY)?)V2BZyK$_#Lm~wCd&6CZZrgOzI37~hI{U~E-^tUWyWPc)rWh={?-gZms+OX) zcjW-p#iW6osfpU7<*4bW;PjU*J(asn|nw~;;d zt4x#_1Lk-+gUMZF`9VX^MX6uuV}L$16xI5ir8axY`GRuJ^X_9?!lY}Jg8QML z^27W^aI)fDdI%v5G@mOI?{_O!NS1d|$nh;HVF8{l9+y*~OY#5#@y4fS1b*69 zIj=-Xn)b(YGDG((R{X^kmW%IZv;t{tXJxwHG^`vcEIM(!Me2VepQ1b+uSSdhO3}7H z&eELL7Za2e6=Js9C_cG9M;b4IU?SbaGcKYX`f!L=bA{1FL;jy}%JPCR2cDc4^{GF2 zG;;V&IdkNdG()k$SuPh7OA$b(*o%Q^ZUz-@=hjdgK0n-B=vSyAx`GSdU9e9}Ud}n1 z+Bkihavg{XsJRF`nOD+??=`eBA;pPO9FFeAK~wuKH2>@NlXBZ z=buC=unGC11g#c>+C!z5J;&@M&Ka+=_kerhK?6*#@K*s7_ zD?iF;&c%Y6xDnNOoHX8fmGx$GXLTs83}567Qr*63CVmgdB?|s3mzMVY`Ljoj>?sd% zCGS+DNoYKU-)m`xv$j#6_&;AgZ*E+p>0B+)E;1)6XjAMv) z{^qOBO9+(x2ydPDvlmn0r#o33>L@Mxe|s2OfALA5KI?8O2f>gvKm|-K`xqZ^nDm$E ziv{T4O>-mRrI6(9kEIpzY_%Obezdu>T7?TELr6&O3~wa5+uACSrH8<#=6l)D??2kh zKgOLMb9Oy8o}>nQAgnuVrsR{5E%OncEhhyZT+7(VqqbBeJQhRvWZCGG z?jhVG0m#8S%Y_(5_D1h$_padAf`rOM-jXecty}b?pEmB(RS|v{DM~wLh9rp%_V#

7hOSFxz=W_0}SPBz}kQMg_fzt{I(pYP?hE;Y-fa{h&p$L_*a^(3Dc#4 zEYIZG8?mB9mnf${g?$u0%xgZ|+T=Hr>Ay|&Ydm^P*~#K0%<+<;CnU??7+Tj#YFglZ zdDI?EG)G<0MtnT?IDH;|>*+;*TYN#fq76^z$!j-$w3|UB@@$%BGtNE1)=E{Cy4<^d z$%L&WPa5?Y|Mvv@D#!ZMRM2ymUAc15>T|TA?GhAd3mON+)^_;PqW6g##>brNV@^JQ zT*-_G!6^&V>)*vDRk%<#l4<+x=y)Z(*?0M>aZD_L?3+ZbZ}tg} zC~;QsuPa^tQeI5z{%%Fq60&F$h|#w;Ju6>@O1q=pm_1yFl<0m6rJCqvJ%lH5><{yr zQ>!6^dW`q@i8Y&j4s2l9IA6gh$E@Pqiv4vL;w7dHPom2|7M`M#!T{6hx6Tj^OAjqX zOmvK2TOAlLnBK<>lxZ41=~ZCoiA~Y&t_jn-yN@8jNh*Wy5x~*4zklzJ&pAJT5`kwq zGXyM#!qc=v?;1B|48AFa6OQFE3^g|rei1IOEyOfaOv<=2F*r>x2`Ti81n(esmh!ezsR4dMSsobdWXx5IUT_`Qf7UAqHAO` zEqnee`IO8}c(lYP)66ociKCVu3wMY$H@JK2UxvE8xpM0NjVSuBNMW~`(t9aP>4&@= zYEN&QQzD}iUW|@U4th$`c;J-!Sg}Bm+d`5b>auuSe(=X|-N`rvTr0Bdg>7G_j%D$B zVtS`x9&vV!?QpxF=#8e!cp1bnAO8fEf47wpBCgjE8v1PLeuC=6CrIESQn#Dsg)*9M zrlmNRUPR9|_QyS^VSL+A9-=#Ey&U$n~7FYbnzU4Lj82obg5zQc^^-Wz_9m5 z{e~o%A*Q-pOw@Nx;`G$z?;I}E%r;mTyAL$D%M0Ubpp>fRMkhn&SI_s`$NPQO?VhtB zZGLDg5BevI0wbx=63XfBA`uz_`<^P#cWmi@EqQ;qzhO9x&yYU)qtE&-0J@8=+Adg# z#>7e%EVIwA6ui%#NBNX`MdbQdsjsKprmW2nBn@rX===Yan3fIT1cI)&DD_3alQ`}S@M8_&81gP%m{3|D* zizIz>vM2}tz|xlrlJW>*Z)2$m=6|4v*_z_-_d-a3u3Xv1grjOYbc)*+xbQNAUWPmiSUdPQsAB1y&;dz?ebaIuU3_l@_d$T~;Us#o&KkrM_ey=cyEtNqX<3@g2K z2akPrwV)=`467Ru5%vc<{q!4LeKnU+aaulcU3sV(`O8hhwGGC8Nr9sLag$0OQw6t$5_$(sn$WXj(?HACR9I1w>D#CKd4GQ&gfoF@&DF`Pz`Wf~GBP?o zoqW*`TltcMe5->&tT0SPP*$qH5go1W*|w^B$;6WGZ^y>gc4^2gYP<~x^GaT{Qc0@3 z0`wP=xTAL>>Ud~%BjffI)%i6&y$@(Azm*FWDWc*0$%ryW*3N>&eSIp zRC#7nFtg*2s+o){3pGx=?3TFn+0y2ooh`)*D$Jh&+F`rlF(WiMcQII zswNY;!Lr%vPjRe_WQ>>XJz5xU23Emor8gLoBYLAbvF%e#oGH6mWV>0=m7$fh;dolr zl|{77Gb?|b%W`|*cC(&9n=QePS7=vhM5ObTf#xPyhBv#u`sd^C(t~{c%u<TxlfRmu>}|)cVa1ZN!IN*Hs@QBP!X4dYb5YaT{+ z;;xp7aWjhc{h#goj8w{z{#Q4IN@n}XEhE#BjIZvfI_!%@<&UL-kchkm1%XC=4* zN4C_GM#5IpyU5gQ@mG4O8>WlE!Vt56OMmMBLC>0e?5mX)hV%a zAdC+d5(9{~r&?C~Y|z(^@Tzj!Q{TfdbSq4v`-}&9x~nZh;w^<)BvbeeNxqv1*4XK) zMH?puA5d|x+yxjdqrKCUV`8hL<+%1KJP=d3AL zlkQ!praKHYrHY_l5Fz?VC3Ql>9qth!TkRpbiLA`np<=VI;iJ8aGT5y0mw!*l(PV91 zF#8vr;|y}TkmHFI;<%CRkx0T6v!Rp*HlcB-(_|$3POHvRB^~55;8@0wbMC{cqr1w$ z!TVM+w>9ZT?q8H`=I<7W)x-{~c4&h>QxQA5(y(Z@#VwYJ9x`CwQG)U4#Bq3l*_u9< zxUeWm>^!MFPzfX*9qUru<(S~l_+@Ax$+)G&A@WaW4Q!hLz8#R3N!k#>LpS;ZtY3KJ zMvQ{;O6N0E&Bbjb9`$H%obb1IngyEq1>Tt2XU!!{(Z5ob#eyB^F`?(u1^B&dxLp7T z3)^E)XWr$P&cY?(BT_^tB50)gK&?<0Old_Pz9fR*6wc)IBS78^D%c>|poB>m3QaVH ziW$W_<@L2vBx;CFK&pYXW=~R+>FVx_M^r7kY;E{w`0xC-vgOwqy)MM!=Lhb?z zD7ce?Q;9-fV+7V!Ih+khx@mKti(rjavufB6`=sNBvPM(hjE4_Y> zLuY)>dLPDilZcWwUzJX7#1ea}aFbLY&Tjj|UZvLfht?z}RuH9<;VrCIEK^lI+1ET5 zw)ZGI@f_-Md7r-YGs-;a<`9llyb)0cORN(24Yn9ZI*}T8aZXNOAVPo`nz}r=qR*V! zm|7nDj;<&^Mg_$`Dp!npP>&84E}I6+c@ScF4mze*9MtxrZPnEY`$zl0KjZ3u!MqyB{1hPoL*eq z0|zKr0@Ay2)|)fD(Po|lb~89sJg5ikdTwco0ud3Q(LHc}5*1{>0^O7ZjsB9~Omc%P zQ?}IST&d4aNqYO0C>?`FzDWZD_A>$7Rw$vgi`Z&%SQ?Oc0af{UHCNiY>xZfC0~HOp z6HF%*zE7lwo+@0orFN$pd#i2zW8O6i?RYyrtlLD)gH#(sROr%6-f+K&HqK4^=RE(2 z36?Z(^EZ+$?(qB>@zj46lAegCyVKGid;T5Q=%+$^Id8vMQaGa7IgBbXtSSK65t5MlQsR_f}HV>xY{Z)jPa?uqyqs8&+X z6^tyy)=`KHe+#(xF+Yu&D|XK311M+24TL4 zr_f&deZH~Itsd`b;g*Httf8ZKT9@qhk)}oTczDj*Qpnt)_7bUdygMk;NJ&QL$j0*V z!ChI&$@{m4)}JC_`uRThaoc?)46nZ5r6&)N^sU*^G-?Ci-_tMn)1`)RWI$WqsOi*w zsk?pKmE4s^J)B7c2Gze(g?2OZlLpG;QR__aC*7S#e4VcIVTi6!fc!83Y_CaOp)>+pS>nVh2U_tjv!~O!#zK2V*Cr3A(KT7Fd5Fi8uK9I|2ejp*-x0I`p&vPcAX!>RVOcbz)g;GF z;+v6ritiS& zB`w&=?j4!=DUFW>sk-975HsyWP@*+a^^L^ZMKIrAi+9$rsC!gqq}^}{Tk;xn!IV)S zh>P@_6d*~~TgdpvBtzwYTd!=NzAH+b&@zF*&fLo!2htOX953e)wQg%a#VAH%>+eVCqlO#!l$E#ThSMYy z*pVqNt!Zq8!69y>nWQjDQ}*lirq>GUSYF z`Z~sHjd4U^%-T4yQMS%u&UD8^@^O5B-*mmKx!UdSZ|+oJef8S_?)F^Puzi6`jjmkQ zxlg3RuBJnZn(EAU->c3A?cx8f?c-tCPfvO#R~`(r*lWoRh$&smGHR+@He+kJ$S~g| z?xWV$L?lgl5Rx#!7`Ax|IjDE#z8VDaGi=Q4eIe&54LufA6N3iob(-p9Vi~x=dTTtK ziVM~?0e<8qiZwsKXXm2NvbXIe9vMX7gY03jXUq@+0@FfBEJ>oj&|vrCQE1uZdw~Bb zN?Xj*b$^bFU%sGi+0k%$FkHKJRuvM{^3*~HD+jAc+f_0CY}wRn!qLm35)h^QHK=r{ zQMw#lT#ri4YENDNwfIvvsCj&~`DfGvgiPQ<;(O|Ab~U%>oG?zT^w6r1v;i~yezPpJ zO2pD;ESiZOyha&@B1Eb(_z&4kVYeC(TqSAQZG_@nG@Dn^Vq_(SrQzb26&Ftv9T&!u z<#)sU2mLhe$U60}~X5 zrzZ2^x>yQ@5VaJkuoM-Qgu0qET+1pi{pkP2$ZkThj9ca4hfhLmJ->V1#}wXMnD1;r z@wbLchj->G`DU$DvNDuvcICzmm6jF`3^O2EUqIx39X4`yc|DDN9Hbg$#(bRUw3LBF zz-X$Ft}`Q*wj`+D4c49}AK~0;n5D-7NMg5o)V)uVU);zLhA#S3L9E0bq)?0oTV+Zy z-}r-SeYwK*ooik!anlx{82(wjQp4l4qfngyHB%4dpM!mr*z&HCPptWpF0QUfcq|~{ zUU1XxKPM672NpWng@8KfU3IBtvDY-YXdYd-5nYfd#;3DDp2n2q&rmYLfZ%YtVzzr; zmARlPSeFsDxJ~mK3q$YlI_8~!F;g1T#JF>G?g$#fiZCUSefW|Wi&Fq%Rru0Q^8H}l zr51Eb7_S$LU5dea(XCc)*c_!*6$V0?eYoa!aw9!*WZR$h$@Y=Q{p9@u7Y6){aI9rX zI?s467)#nxsSg19lzT6d?6TBhOgcF0pZ&6g8_;n!zF0`*CSruiDE1K?cT)e{-Xr z@f8b;@zU^6oI7}2&zpyBEd^u(6l+x+AhQ%P!ABu}`O{j}?{f{TxN{$#q;!7Gz<{i0 z6s<}7!iJ5$&doQOatlb+kfg+qzle_g@}x*&2ff*f+d{3diq~%Y6M?lH+LC=aD%KQz%mO+2 z(C^jM*|}kiu!H_b&lf^{XO+q3D_JboL0cN(gfxFIXKR|4Utisbu7&+nyIc3$Vx6(4 z!`*isvf4B{Y0z51eW_93KI}WV9d+D<(wGqpdswiWJEW!JNSOHgak|q;Pi_##O)y=E zrl_P$LOhb${`qgeF{dKF(_y^iCp=RXu*elGB{~HH%`33UbM|ZlWLPiyI1r8c0twMQ z*c2FjkOm8EMK95q^HAiDa1RsRV2{*4#8>(7vwDl`T+sEbJFeyX^DD$<=|0}OK)5+$j)=yZm zcp!b|(r8tIyW1mHhZBMOaE1oT`&Y~jg9_V&2u3YtP_nB6<3E8vKkmWd8@&Y=Zbds-$ z?DN!gYg@7_J==|D)&ofpWdNIsejaLoK|`Da@l0vz|uEXt3}pQh$cVrxc- z`^4@gGS!tA_rk#pyL>-8FmIjv{tBlQ zIlOvdSA@Lg+}Er4_GhvieXR{2CLYmZI^f>X3Z**N6=8d{7;|YWFLXpbnrf~!c2oO# zHgmt)nzCM~BJznJ3m=!MTIH_@lvJFnecNc_%Z`F*Ca1)rnQy;+=2p!wsOovJYN!U5 z-IrZpVBgQnCOe=Az(hg$nn#v~WbzC`@^svfSZ{UEk|xE0IPxVJv?wh#OD=zv&I!tU z9`?y}tFC);%|*&W${mQIgJH5L&GrR9Ww3%z=U^=4jtg!j{r^?c1PR^yd?|UHp1reV za#Azhx=8VC7pXz~jj8`VUXIATrDo)0Qt0DtgY`zs(6mlPxnys|cu2ZY&RU-|vzIrf7>yssc#!A$8Mgu8*dh zm5Or`X3|Buyst66F^_QTp-PrNJxB>i07gJuqfOe$_drj<&`uVgyr%L@2LZG8y{7eE z)$rn(g`I@mfBu$P9(9v-Bo5XlpCPCIYl|wVscg=(_vR~8PERRFX zVOVXyr4GqXaii^I9M^tpG7j{DW*BxYlKMNMG*%CSTd%AjR402AJ#G`bGtajR_7+qlfzca-mECicq2MP)MBKO-M z&V3`UUg~y^ah|jtIo(j!_EvK#tvc0y?WBi&i*5M*_obHk+G9$?&3x@TJ3@xiHGc|$ zpYwc&HS3BepI$c`UlW1fFT90Cft&bCDsrPq5sELr-_JwStztYRL|?pJc@+tCw3RTd zz8RTU+R^z(uj^RY^Rljj;uYzO>uCJ5N@Kn21Qj@7kIq6l4_4b27B}7_l(UZdOnc!6 zU4z}KSb=%wU|cS#xV}e%_aEu%H_mpR<#o^4xb_W+9Aq@nP^=_W_+Nc{Fdk&H6bo z3JMD`F%DCtjC*(9FOVvD&Gm+VN6}$PS;t#g;-Ye$yDaPonSY_A`S~(;{~j`;>TV5+ z4{QSTZq#-EK(^qivU%H;Iz0>)U$N!uX~8v{v%2$nRLm30brG+bL7s%n=xZhrLC*)Q z_|yt{on2j-5l*aNS1H)IW|!Z#jtRuIFL}a8n-~F2fyd7BoqYH0mfJEP(a<(vECGt% z&D83=36mei8#VXg(#MVgZp!Z;lOf4pYM02Glj&K+&@h4bVB3yw#aqPhB6Y(MZ0^}EMN z&Mt2|nKK6|f0#$dx}Lwayb9q-QCP=EasT^aQ_SV3nox+i?t|kFN^b)~g!x|6pFiF@ zUk9bX>|2`1W{3&9y9MgpAU27-Ygs398;-4<{$LR)ISYmV+-BkVRC_*qf`RDhqr8Nk zWFZBrHwoKcEH5W?I^CVNq46zEb&=!(X>!1X=*Jsxsu^cJ5{trWO){D!q&**ZS}at1 zuuGO7=>^{e)9>TDcJSH2jtLVtmiSC7A7rs(NP~J_+Kd7HN^6qZu&!Z8C!*E3w8gm{ zc8#EN;mb7|o+|k}X?; zn(Av@C|*mi>0wA!GzB73+yS*k?4P+nbMpJXy9^&Q;Kvc`jk=n8l1TdC3(*(~1Sk){ zQMkI}pOKLPBBT|f>0f&sfn1#TU_1N__q&&@D-f<-6Qh8!MwBNS%pnrYv5wQ+v$$ud zZ`KUdATg8E90AU{l7fO{^)Gb; znpeIO{f_p?+`B|j#Qeo?JqU!>8BIR*nr_zmC0ot5(~QuZ*IqASCYeEp_hB=c_Hdc=1_EAd%@_dX&DwTGzp?r>j!ygt_(QcH-2PyS6kxf*ghgptSN^`D-$A8$< z1f8k-!#K?LE0#klN9NtJt3P`XJXNTSfqoHis`;zDu|XR)NtM@2`a8CqT!HiRVwr)X z)@ug@sV)nw4^iqfN{*A$GjHlK2yEf!%!z-KxABy;R#4HdMP%OpTO8MI{f$aiMb*wq zKu_&9oC&M-Hv&VYTQEOBP7^jZL77q$9?#tVV!W_Vdz%P9Gtfp;GNY}8_XeN)IahOv z`9fU-IQIZ){jyNA1#Ao*Z3bz{Qo@Zt!Lp@Guq)8+G()-bPJlq_+vWYq4hu0k3+(JMGS+#DKfL^r7w zZjKzjl}S;?NpuNgRt%GRyNje<25|wwWTsfZa2f3OUV1HxaumpDGlo;>7WiX}+T$L$V?S2Q>a! zNe?>tyj85pDN;JvH=#~C!-`!>kKVx`cAEu5>NPAf{^H-rzp$Gq%?uo^#=N3mMbwQq+Q4+my#%QWRd;*b!Zsj5u}?e<=~ZNo42lt< zPiYWHt_%%fLU`1|Ae0>wmR_0(%^^@?{z-~{cDMN8$5Yq7V5K*jgc*?H{%Ew{I56)X ziGB6v)F(+ZX>ZN{(k>mosG>5x{@RA zKCg0(rmE^!>C39q*|#umkgKED$hh3rEOyI>!n|8pwuhMu=j-sz=5+}uxVU%6O()3s zY>1ARNqV}vry!E<{$=Z2+MEA7WAxF7Tn6!M;Cqg-Z&#Z8w+0-{RbS>fX_t~>4m7Ym z{b)8|aP6rkn5h>pIJ*4lN^R{k&h|AKQM9P6qc$S3WHex zctseNJnKQsj9mnJy&hh2hEe=;BZ$1EC%^84XGY?Ha%)r81l=F8%+DeQN^%{7<%w0` zs~-9}ala*2V9U-D&-@TKa5_Uv@-N+f6~^FZC<nly2S7;ozXGR`A--xH4t&N%Az2^p9<$xG}y8YE~P%lE9I0}u6M z-HM~S!Ex0Ry~&Ev!QS?=#>>x92L6m`E@no`#}A^0jnf0q9YS^rV$jD zaT(aBAFWPD>bG=I+7gtcT9Lp7Q|)SHMc=Ue|Av=C{UYqEO7CX=uMg5U1y%87JLAkT z3+#||%XZW@|CFc|hNo`_r$2(4_6R*ef8=0S2CE~-fKk!T^Lpdtu4m;swCS6~oUk?E z!XR=)J9ti565k26{zh^K5ZS|%uGcG^zRQn7AO4MEH>j4hi*7%~@Wd8-f@?qBVSP_H zgK0cOnfe*ebhSRGnkJ1WiO8ozY=ZDt?Pz-I*^Kn!wZFpSo&%kT*-3&;cFVQ@X=K|L zw(%;SQ~#H189H(mnyqQ}cv0ioyPl;0LDhT0UwLZiBJ-n)=&8EUOm9oye9=o2h(wXj zxA==L6jL-m!FyhY!|HWQrZnwcA7g>mu*}92=SAXk+MDtx49y zYPv0TD{bX_k$Dqhhed`zU)_PkO549RK@EchgDD^@Z*jZ;;JVtZ4s+e;C?Yg63~)I@ z+9Zty2o7W0*NW8?bHc&fyl-1(*pInlS2Jv4&^+e{oeu~Tw(_L``iy6^-4d>>Bc3kx zpIr@0COQ3H?&ytWo>A#l8T|S`^_>(di)&wnRkKiZ3As|6jA+94fIjMhK8%ag&$yq zjH(kUBhr)sfaTk+SHl6nw{=hIf0Nt)otIUG=lU4hzM>ZRaU9WVz2i#G)|_r(w9XnD zVTM;o2JgB5$bFLy&}XnigW4spyw_~!-fWvC{RjvTqr4xRi~suxMDYS=7|M%Y&RoWf7G5=dh&o7U%O7K^dqOUvtuD=mH;gSJvY3tIx7TnJjI}{}% zg9#e#^4Xepw;q)hx(g$ForCn;?ZIJZF3V&DME@++Yd(5s{dw`6{RPJ$In7Ng*o%{k zHtpi!@48o1dx1#Y0D-K@2inZevdDf{#X3&*qHNh;&_Z^iJg8LTeSV0sm(&E3iIK<` zqB`rbO~41RU9#&ZVY2fu%l);@G)}<)6)^{)$AtMcQpwH(4-e14g z_?~jn20Z_(@dASaeTj0m)iFo{E_7blQWsFwaViyN|AxTw42p1tkA0>Q*!mo zp?~(#>AtD#|4m}gK^M`@SQ(a>8K&q$QlA%@Otxz7Vlu>rYB6|85=}8PEJ^bTaQ`sT z5j~0W0AUom0pj{L^_{?Z6@*wf`qOTX5D|7O#w2f(+Fr z@>iI+!AeZIwfx)pj}JX6T9vONR4AZt!|BlgH%5)`C~u9 z=QCK64jU_kj94B*R*u^eWIgv++@;oUnu17;ufNCyq1@wQ$SXQ44sTnzW^kb(pUrV8 z2EKc4_PLv*WRxkyW4ehkxD;-yd1Tb>jKGCcT zX0Pj1tAs$Ix~A*sW}BrBJIzH#;BqUyD@qj1yWq;6re+KJ24u%mKEN3HaTtyQfDdAT zymgekhe>;E!{LU`w@2tM#KEB9uw(U-c`P=>+3LErp(P0+wJN$? z4#-~sV`UMzgaz*GMauu-bKd3vxG+oV0&Xhi6>^RaM!NAKrj>G>4M#a!H9oh4J~7ts zqCH4G1PK;oNX<17BkXL-(E;MBm04icqL@J|2otK}`j7iC)XS9}wXS&4Klnw4zf|dL zjVB8>#T#EO)}0C(?G)LqIE*cbE~h#Ej&L0Kb5I!C&tjCc7BnP*X3dpeo96UqySW1+ zh^$Fy7jg5#>8RtmLs#tpMRxMbr|y4q`)6Rn%!B7+ZwrW_wk9Gsd{iuH?fNmmB(_L~ z5VlJUHOaN67^I3EsBuAW`AgstKyCg_5B8xbtA>h=s-K6hLyaIzXFp(A3_d4?Z3G|5 z`0zbOSxx8tdn20-pZ2jmcp!DnmZTFh`;LS1RqhD9i?KT*Et-Ir458n+o!qsTnBxdV%|rex`R+)J%(u zD#@bhT*i+pWp!qSb2@C(diYxMWQS`mIW2WyjfFDOC4}Ke*8JI5c=JT0wp5_ytmt;Z z=(!#=m}&OeZ-R}`>$*Ke^a`v~rER+7^@+PZV(BX~nbh<{?z{h772S3&=bLhWv2#Xi z-o`y=7GV1~hZ=`%U=my&C#YY7FUnDto$o?Wt?qs)hw@}lut-p0g?_r9Kx6@eJ=FI> zq<5$BfWb&3F!$Z$G{vE62wbQ=<+a-JP#U$PeIF)WLVK>IzFi+C-7Zj|Q!rpk#&P?2 z+<_T<7|n0PK0R?}{{^8)z);=HSOz>bX*s!}0T>$|qc-3i0{QpUWMojcxASFFdoG4v z{{H}}JMa^%bE84{RUW>UV)+Kndd*c#2BfR@LcnCrjh}gxhPR)RbDo2eO~P~F@z?oD~sg5s4D_3t0(dR2dFnuepei&w`P(7Cnuof7EU^yX*cF;#yS$LvM zGbGlOD1fR>(NZ|8amygO&l0kaxaQ$cLB)oYThdJ*lx+TlZL6rS#alN+9%`iMSDPdlCw7YT{+3T8|jb@#(ugZ*?C+xREv-2zBC9Hr$6TnB>0}?C02rOab~wop8p!jT5DDC5A;N z(grR-K=`X{~a?-9k?|ys|5Lo2fZ;S?hx|P>^j+hU$A9+%B+O$!jrZ2Q+u~mwjX0ywM-w3h z-t2;rT|OomvqF=R+R`kE!UM2M_g@U(P~v}=5YL1$Hq_e=Z`>N|d{A4Cxv9iehj0V%~ zz-a*p8ysKc8^Wpim8zt?{9VE8JtD?AFR$~%X3@(90@pnLGAo(j`FzG8BuhhvY@8v{78Pxl<6SP0)(7wB zfQks@j+^zME2E%7x|05QY``ZB*g^!v4Q54C;<d=2xT4?dCqSPMq}E(XR<0qi^#J^~~asRKyw2;Ds-vm#B_Cxu!r_mnF}dG|GnsQHQ;dMZM| zisoR&WI833mol{7Rs=twbdIjyWEipEva+%WUcFi5Mw@|w4OjK)-kRs-c1?l`IU=-d(gyV z*$w>HOQf!o1~!!G08JnskXeX$HG#FGhn)Lq(BH{bI-mP|RnwgVer}Zv>iiq9)+mt_ zr4o7Ya*S36cE;+5_hu_(c7$;|T`Mfu9TJWN;crq`wcJMIMV`E(?i%6H*w_j*0(@E_ zTAt27Hw)!j%W*pAQ$0PVAS9q;PXa2R?h$FlouMLe;UyLf0nlfsGpEPQmaAvs6dHH+ zZEnMdvsS|y4|ZdN%}u61$c^NZaXLeinL#wKW$YVM|*s|1W@PRBvtG#s$h>m z-o>+Kd!fJnd(}pih~X$T1u@(N+~c4r!nH30Ya{j1!`ws?%-}hA!v+V4hWmUr(C>4Tr+3Fj3^BBMs&~0)4p6H^9$3ju0?SA4TcI{jNsE$*CqPY6Nhz0aB?obo(3h z#mBM{XSj3{<6d4OaM+DdjhuM8XgR<$+izvP$_Z}lsBTHpMsM{|uZNC(%8y8OYacvq z4=>r_Ick`c_lKrXnRTt>!p{VMpSQ;5YZviU8dMHbta?+dB0#Gd%E$%SPyG9facpu_ zv>Km;*v%}9p+P@dYigHUZb$xZyfIEBiDCN*b@O0s1gB&qI9@!;In7H-*j2cmSMeO0 zW1sgiad9PC*q}A2ZeYA9Z@S9_4x&pDImud`UOjb)oKGMwat8YHoT~VzL6~aZhWLtu z??mwZ5S%eD%A{%Hu5P-rTX+&I^)N|e443T1AYEScc8>iXIaU?G+K*vhS^=qnHr=GL z2=Mt1*WM%@YU%hj-38tC{`ldRkl@mZ0oY_gE!^C?$Mu7)AKipcL~9UP+~FcMSv2AA zMvII4)=LZ3kCHR)X~gtey}Z}EntoR~1L1EF5-xqO_bRQ`)WSYX-X(<2J;+xHbTD3k z!KeF8Gh`IPl}TK^H}-kHS!=k_#>LZ-k(D<`5F|SocH!=@lF_DP>T9S<$z)4k(q~~V zD-)ixz462*g>%&9d)aKSJ8}wsM&<0`&`*Xu)R2tWB%l>{SB_+7W}X?n_$`(Coc--* zp%Jf}=Yi6sn*;x5@U$%^fa| z(eY`YjUh*N{!=p$7j5W0-Kv)m7U|6_%2G>gA1P})C=70&L-?j&Rythpf9Sn4%{4Tu zh-F}hV#E&gE`B9y}E zg9ye@0LXqC_V(MeR?TX}#HDtiTr*I;b(??n70Y9N|0!oYKS);K$W$b9qFzzM&HHEI zL21l!)&he6GD1*L`2(ClnOdyYLU*MC52_d%U|& z3U*IFH4>j!rU$-zS*&!6Vz+?kbF!%Z4FHz4=(XK+60%wKAa(o3`24E>sEMDNMIg59 zqlf%KlV_%;3q;i~bF5F)r!H->!QseQM9F&*e4C-A4LiDAn7Ye5J5!gt;YTV1iAndP zbQoC$(l7=7pcWKzHZpoX3>^99h&ecfW-f{>wW$?p%9)1bs0#0PiWAg80A%K>23}E#Dq@@w@KZ#-geFXr9 z%V2pA9y8@@In6cT(;?}y*m5d;NxO4&VcCu)B7 z=zsW-U(1o@>yEwuK6U4c_XJiwTr?B^lMqWy^YiCH-}Jv&sW+!KnhQ7C}ZPkw>Vv8+O(wA3bi`}yh7IOZt zmO(9RK7D^M*))9%G^Qs8&gxUW$PuxFqXyBw3DZlZ2+W_Ws(Q+j$l2 za7oZQy6QJ=LDyc;KIay!>@Wb zBeoZMe;Ra}>YEE|HkEO(<%$|Bp|sB{37CwO0(84PJz5bPt3J1<0()z6d#*aL>Xqx6 zpI@06kMeOOMm3#E>oR+ZgOU2dCbJ8AxE)rDC;J&B&`>u~523oYYZ~1*anjc%+r7tgZtCFgX zqgQR1-f@l%OgOp8;2v#!UMgvDC+ohRh@V!hKt{Io#C$1BrsF+SF2I^tOpuvjY0^x? zK%I>!{!t-{qdg{J+Zp$<8;!cVoS$9EPLGV&%{PgTVUD`ZoUB3!??BbzR8Un>wXb6N z6==h8Z52yfAZ?0tL>r-QaU!U}Do_&c^kMANG(;yOUDs71;oT@s@EaaM{b zge|2ITVBD@^Zkfg33gH>?sye!6-7U_U~@%})*BeCBsxmNmaULitVoDfY~$vks9|Ns zxC>JBG~2@YjKD&%^2#Z*!!Ky0C_L{zTl#0^(Tqxsm1vuatlk*jwcC+8Ljy5sY zhuXjS#w`NgPA#LAC;4Wk*1Sa?w{_x*7Nk#F4SmaJw#jOnIHuYNt6DYYn#05b%pjqr zQ?@(qe(Rvv{8J&@xlf=xA;H#1b=!2^Ca+(s|32n@qrOAUQa_-pPH>7pv$Hn_l**-!1x6-X{)y`0Kk#JWYD08nv%ATE06O-`%{2@Deu9 z1k0{k5n)=F%p<@TAJ5$A$Cq&TSB@W%&0PD5NJ%qiWIz{wnD&2$q}+!8B6%6(9&UbK zD6^NYiad`9CrGCia^TEN`S8ez@CB7Qp9;2&XeQh`t=Qg(Pf4la;dU2@kIKY1#ox8^ zH#1x8^=hEFDhJa~?aKI8skJ`r8=pn6GcL_OOzl3TO#BXPHYpOS*GVH{Y6tJ`yOSqol`RxOO^N+`12Uyssb1;OBJl_KAN2SJ?xKJHZj9Yl{zuVB8OX(mI+Wp%v> zi+U)X$LnG40w5-ewT6DCqoa`5=X%e@JQn2fIA%0C3gw+bJ}c!3zbw=~;Z}P>qghgJ z_Ph()*;h(2V<_m555Kx}Ip>FJ#Vd9)4AVj8Tn*Y0I&^35IM~jmJl1oA#_P0Yyl`mD zMgGpXk0%zOCKqz|o&UWU;9TmZ4B9$UvOkYE2MKH#cBSnjbkbz0^TDm*bf5n|(8$?9 z`t1by@CKCK-44y?@!KU)_+?J&^j%U*m?fPK zno$GJ2?w0*5*}=$Zbz%Oiw@eAb`%wXQ&nefy{URJ=Af1X7t<484&RWzoq5!zn{97T zFmKDDOn^|3mO@6e^N~WjPMH7u$$EnQT`%&sPvIi$0!+3Ym68bb3d|hq97ffzPVP#+ z1V>g)Dfl_;3j#j7wZl_i&D6<+Lj+O%p;E|(>|>o?w4b(f@?&D!F8_*&7%KUIQ{pdN zr)xLv`_o>_EGhiF|2xu;Va<9P3!FGrh2?Z`O`mi>mvZT1Fza11B`TV(-m2q@Vw#!F zWW;LH-45gSdIO%DdW(TUCg^<)myClX&QOe40;KhS)Dn8NQu7wRF=nNrU=qE&_m{6e zJ+nj|Z1K(z5_10gt@Uth6a=R0r$^mcHtV}q9H)+eF-!T_FAD~|K}}|{X=)7J(Q$Lz z#ABL??0geZV}KA9P$MSg@hbSeke+tatXjUnmywvE)&|8Lb@scI>zr-ou6FAkUZNH9 zO4^TYd1))e7pES-LbBO#bKVHv4-`h~lxH@8@yL-B8%DeR< zYqr^Qc(xbTth^))e9qz3wCRHBpDA;(lylc|!;$w`lx*{Ir;BF!61EY^kMM{g#+&q{ zL~+WXb?p3urW`J_0*ZrzCUvCr-h3XucstMZ@=`kLMw=XHS68c(bERIZ*^4KR*u3=A zv`iA}cCcsv+4*k)%Lz?n#l?pJTfxQ{Xo5x?)RbYC?FX8oZnR=Z9|1A3!}ODsu)}4* zmtb+PyQ=iY64wyNLM}D36cvS(+0P)K`}LiS>Qu8M6|5iI0U!Bm>1jjyA#7FSc$!xR zjJu6|*yTdJu=rS|3aDx8qJzsUvFVI)@C%-n2hn{pvVNvM$UsCke_M=5(wKyBzr16( zD+apH-XPhV6iax9?vhyr39P8k-N2jPUnD2pW5wL(EClm zs&3sJV5UmT%bSIZ$)>W7)x(&4mKr5}4O8hU{x51T09;$30<&58X>c8r9afb#e3cO4Py>RFuKmemi*O}21N zHSzP+uO5G0q7#<)-InnUqSK<~@#GwaEVo9w*f-S;Xc}$0QXY_0)nt}!nRez$l|y+2 z1xF#lqi8Ui+Z|mdPc&GwD_TKv5Qgq11Z;_ELk1z$V_OHi9Vnd# zX|wY<m=RqS}xs<}q*X>8s-s`N(V z)Pw24ey$1SFjEEF3Fqj%Jh-n}V$K=lb2;EOTvX;%`g-u^uE1iL=mFyKI^++bg{JB5 z=zRY8%>#3XlJ7yKMWv)eXD6kMmDR5eH6Hhj3k3edf7+m#SxcNg$i>~!bBK|HN(}Fi#QAO~ zVLvU+GveGwSmW@wPJr20x(QT8dXw};_A@oBPht!kN%Q8L)mM;IV>r8&-|_M25EhZC z^k~JmTZsYf_SqUmSAuR_3XZ?D&x>4yWXJ49d}| zOJ5h#Fpf_H5KO$aP~aoq#rDUj_fc_t0H?qLa5#Y>hM}zF?a?O~FhT`d zf}(Gjd;di+Vbw{UO$R7IWebwi5647gN zx(SPmAoEBO-4MoQK9-93D;}lYFkarD;0z(FHn*qt%iPp_4LWA>ViR(|iaAJ8)hj{^ z0B2tQegXk_eYdx5D+kQth>TRe%8bal3Iyo4KYskUzP?UNBSyxjgX`y)>s$HBq+cNy zIu#1)AZp09#Q0Vm1KmX4@tLJ2S4H!Mu+JoD&{6 z-h_n);|22nNVWig@Lwr1vTbQ$b_hir0b_a|N^efDja`qB(JToo}0JnuLs$JLDH;Svs||n{q9k=OjqJs_VKo!TkH3 z_?FxbICr8*?WhQGaC~l>7DY-N;us2rEU1ye1)C!!+AX@PhtMT&Pur;>!3pWOy57Mh zj=zZR>?FIFyC|bS#g;V^1FT$B(mnd#ZtXAy7A~ZSYTh6UTvG{i0+9kqNw4ZiI8zXj zw{d8r%}k%JigY}E%m$KA06WVI;BEy-3g_yQk`@4`96-ZI5bFXbn#({t2dLylyl}G$ z3$OQQ*)&sAQko1qk>|qLqdQhcw&5iuL_|b)yOSloanx)H08pA}t^)uHw|@qFVH5q< zqkDRK6qJ?Y5)ypQw=uQO+n&V5#863D*QfRTObEeN)N*O=r|Z1{(^FGA7{Csb0sP`F z6Wp`1s;GC85tRa58c?9tGl~WI)ImooL$ntE;{*$D}%==-##l08NUes z!@sDES}_Jh<<*a@td9FVil$v!@}zvN)u2~VuaT(tn*s6*&j!vqi=NqbBk}SrDLZPIyF?eHhkaePL&>vuXJhEYZ7{%ANHC8$AEWz8-h)VAfVkGf-0Ja7ntl=5$Zb`)W z{d@AB7Yy;68qwAt#V#<+Wr}ffeiyC0Pq(JCThmw49%@GW?F<1ON7Vd!C=Z@(M@zvy zwGK(?Yrd0ig36_GGJO2_k%nd)pjQBf{%L|fyn_gUyIu5R@W_JD=lHKM9{J&7a}o?D zX$A05dhq4bdBx980Yfo9KE9MFyV)vAVBZj*P$a`wAflvgT3J{a0=#T{SJ(W9^S$X| zARHba{=zSU!3a18mX|XL{|TIGt<;rJKA`Tfj-@T^d+-c}G}U}kJ#MNkUL3t|NjiX~>7)&9aIQdg{K=NC4h6W~O^>k01#7T)!}1${L$y9! z=`^c|tOx)e)W3fHiikiR8?s$&T5NO*){q7swJAVV1!$AXXrR2~3~q;2U^vr@Z=tD4 zXaS&JjV$J;EA&!RQ{&?2=I6)hHr1%pnf&+?0mo)4PoNK!!36N`j;5pC-NCD~gM*Pv zNxgEk5gosO7moDwYy%$hRdsdwHocI^i3yrV+6YN8TF+i}+KJqpoaA&rPjl=PJ~zgT z*XeTNB|d1M^|P{c02(WrTGEdB^FV%*7HNuVt1gW^Ji;w%HI3InOoOtbOe z`&Y^yD}O2^2{b8t{Cd2#zl&Pj);*TDPWRKLI8??!1-;K_R{w6&ZWd$7xHG`abL<;| zB<=TU5E9z`-4^9Ca^osBCx{@Odt69{44F5sK5cn5YQ}g?A3&=5;$!#j{|D}$K$!a8lTwB!@%Yq ziXvynaCQ2P1JYa!UJl#mHy(kDC8fnTJeFbXoa*7f{YBKd+^|wzum-p%MCPai3)hK? z0D`;*m)4&r37@%PU{FsZ50M1uuP#Lp`qkL8ZDk2B#KQD@!YOfTkg6IO5S67 zRL3)49=N}GtWXoj+$Uoj7ouw^sUx8~iECeSEB5+LXg^EmOD#cLh8!)mm^oPvua{ZY z+=yWfxhvmvMBxIonMZ*N|RoD=%jZd{1r--`Uv# zCJ!?R4>k*GBRH^##Gdi>^-b_53y+A{UuxkCB-^m#<58p;b7`Ni!e!EH1@2V^Jx)J0 z-?u%Pn3|5k{XfOsa1p)^8wMEAap6iCkAO%%;^vCP-!s<#68J25++VY7z<$eP+%Ts* z0+_X<#pZ5c`PnfvbO?Mq|A0x&pLzA+h7fBf@mGG%I0T(Xv2lzIU|XI?%blnsl)4se z{Ts`ja`Wo(qNr#oW!70K3V(s`@+gsIYPgAE#5V>n-yAGep3SU)oJ@xt`Tc$}Plda= zokvPIhRo}pU93$6o68gXSl``h@=EotU98b3p~J{n_1JtC>|uujQDg#Ci4to1a5Uww z$z;R_M)qH=N<+uKV%hY7gcR+a2Vqa7#B*~FXQ3i2)SSPOqh;~u}z+6;dI$1 zOwSbSU;Rz~vjn0Xt5%NYIY>5NI$D!^??7lq(WZYiBSBv7UvB=v7;Z-~tW%Y4Bj}m- z&TK&q>9+ayI&H?dw?#rzMf)$&iFWOKoU#Ka5P zqHn0FsmaJPfv#d1h*uUeHXuqTeBk8s5PA(95fp24aOtS zf#PM|1wc|8B$WVoc>_X)4oE1lBv<|=nXwqN>mCx0~>ATbvu0r+a-A zefhswBBI3rmPSaGBa+2vF-^zys7ANV^+9Ejw%|%@J+L{>W;4huZKlO#6m`%nN&@Si zSSi5PZ$HPn&*vZ!Ycu8HRL;L`ZA?R1jgiYdQeu|~323bY#l=lFC^17TriiuJJ*!t~ zjD~v396|N0ey~sR1+`siid~K>Hu07BJq!qOs>m5SiO}7*tYoKM#AtE8&E z->KwN+{b-Vq86H;ez|9kx??3MYOU`y_O+ zlhAB;M6*q{bRWqN^)Q_Jf5`XGVuPWkawU?qh#Q==(nk9)hPyArCL&1lVCL?BQpfRz zEK?&)b^nZZInqZDdeFCnHMNzL)D&+|bw*uZuc79qAapTwwP7`)zIW=ddhaREJc z9WG<|4U*gtBiL(7L0%~&YBPA7B$VslqH;_u4f`Arr2~Jp0vJ|shXK`wF`74F+gAeD;68#HwnlC@8$grxj-50kAJX zL8&1r8G6~_-H7>+$Cme!#l=!#9%8rH`k-DQ=j`m-h-(a=c&4YP$D2Meq0$7oJKxC# zJc72~6bn&0=Q}$9N+R{OuE_AHC{t-+`Y$VD9fW9byCsA{xELT)Mh&$o5BZB${)B2P zZgO}wGNM8C8&^}$vv#2A6H5!hlfH(~{yT3G^Bzt%7FA`X)-B&8ZRfmpDJiV3$TnX? zJ|p<(uF7~wx3J; z_nO%?QN76-dRC6@_5*4gm|DgX)=;8K4dHpqfz9!ffuXWoW6S0sNh%RPTG)Jfu8$y^ z&sWW%yDDMM($u%h5P`$R;2^UVzD& zzcz-iU{c%2TiK9s7>3^;4ca-@9DK zE$I1WKLVS#8v#ipptb?9Rpv1oKrIDIdqrRY^eY&|+`pa{h^2v-0E$FC=Umy^l5hcx zbfmBrT=u3|SbvTDgvJVa19M(Laj4-92?a*JZdK@-o%lO`k7t=j*9xFsVqy{!SZbw` z865F!#qlisj1;Mv%>E~9+s|z9pHnP5nHhUczq!k7L<2{DL&7vW3F78lN_YWTVm~7L)w%Tlhvlyt1zZ@7xoC5_ZHuWo{vwywVy*Um+5g?2-Np2bKbl)5xprKVQKNqziI zQeIvUp}!J~gmU%u$kaJLwrhKIsXmG=2=>99@BSpOG|8- zw^gzI_Yh4zO>@}8N+j|l1`#ts@$g~r=_KV~8}2oD*LS+ZeEOC}D}IuT_B5K_?=S;S zL|bvNaJ5j3@t|Ng# z-m#IHoZKS6k`I>I3{_xu>UttcB06XzlchrI+Rr1DOr7ilgK3hf94mAihw z#%T~E2igc`6dFs`$67}UMPAP9wB|19Cwjx#tGK{8SCF8b+NBmd7Fea_JFL3eUQarwKn9^(vdYDsFi)KVS>i3dIuk_{CpEN+_0YMGd|-z+kjqM)Y;g!fpx<<=+9DIDF7X zH{nA?7+2>ef|B}&Q;VU8ZPGm|5=Y*#P76SyTLLI7=~Xa;wAf&Eh(90 zM#=o*1>aQE0-SXMVh{r5&#NXag(^KkN}(U_k6Pg6@6YL4_Rhj?Ld)z=Mq$E4JffU^ zqaJ9>Ss$RsVFf9ZIF>e@(uhT0mEdU%>vF}0g`esb(P_Mb9^*aPU}9dHmUz$L9th=C zY9#O-iWYn(&hbZW-#qJc>`Fx?kkPReBQI{)3-gfFfC3V5_jfeo@$YT2f_HG->=72` zwT?78*w!JAY2I)^BN14GrJ^+}ygTmg)n0QU6R)sdvu^{-h#-n&i~flI(0@VTf=^MMYaO29Mcvxy~C@e0>`m+4f#+R_6NIdh1z{ z>{`G_84nMy3!|45z=&8F8;d2qeB!=PnuqlF_XB`PDPhWc*8f+d>liL()k8xxDqkB{xDo-t1&4Q4`hc zMdmBQXuwUw*>reks^}~hDZEEq{j;91--Yus>NwUw=v6qDw{6Cv(|~1qXm)u*9;K{=;E7~Agb3UNAqv!LXCSiTbpPua z_y~3kn4-58s3&ixN#(?=11bLY(Np>Az7;jkOW$EYl<=lJiLBv!($GSJzZYEAU(4ib zd;b}TXIGxL!eDPgw=)cjGCs*xq;bY4S$ z31-)aUtV5L=x-LtA|c#QRsrE%zN!tN3xtSx?x(QbzKq}=7~x&kqz4H-tofyVpuJ~V zKH0PhZ`tgaDneh4d`T=dHBEU)N_!@D2(0ZF78U@!H6XTuRBQ&K;F&jxfEYxzwHJU{ zE@1a6Rw;Y*)|!^A*xK4!1|6213^7_Et=_jsy z4QLGC0#+8!sd96tc)7XL+UyOM5FS8Hig&iCA8QAHrSs^Ft5t8C0EOP1bdz;Qkw`Bc zZf`>@`@9jj_f7!%>FJ<;8JScF^WFaseYC&}*+egT;n;N}tU@$Z#S!T?Zfs?Ue2Iq0>b^0}WM zyXRs)O!tlp-<55B7G$O_KEStl>?sS_M$m}8DOH^_HJh6QOEDmP7ngn+^0Y+Bgj{Md z`JLUMg>opR*rueU{2M}g1~RNZ6|SA{jKlQ&$R~*bg$8iqW;&EYnYOUFDEZRR$jEJf zCcCHzXaYW_#LH*!&-V2dcd6HnoTo=5F}`wbBy7?IT9zv7S=J`gSqi}kag|K|#Q5Ze znS>{_!rE+6D|7Rh*VX;9qI41Lf)D8{1U`=nAE*7&V~6C*&JpabP)_H)){SGPcW=72 z@~83xri)LzpX)9hBB&g|QY={b_>dQpOac~5z&R8!MxnnSCKCh3;z$OOT34tjxS#bO zzXx1m5fVz>5pdgo3_Juxfk5V!!J{gxT0=4RVZ#bL0E$9B9-hj6@9i(2(tz?1FlGm^ z-$X2iuR0Ibx}$e!YAykNLQqi9dasO$WDwP}$H&L{db=%q?x%+%KMQ7HZ%r|tkCHYN zVw^D)ScaT34Aha3Swlm^856~4|F8{E>zkYN z?2V;tYHB(^l*`4K+)`7?*KWBoT$gfr3vh-(g?ok zZb`O&E}D(*L+uAzR1qp`FVb4Au({H8lT>@|8bR&OdJR?IZZD~NrWY6e-^nh@*v1hmQ$Uwpi<6!egU zA4SQpe75_4J_KV#X$T=IvMF4sNIbLA2#QqrYqh2ceA1Xc_Y+l`Kr(BIeM9Ipw3%r? zGh{hp25n1tEXi|i>9x2T!C=0bF2ue`j<=<8Zs$~>4IeWm)kJm><#us}gG5M*)NQ*= zAMEus*naB=YYl`jCLuu_Hn%CsR{&#ly5*purOnQr&=n6HXp0)vvwWs?%TklbczHWD z73>b=;xB%IY#jQ1y%6n7(gv>*A1EWuG5gIhE^kn=-yFuyvNAgjKfiW;*M1LlB>ZGM?u4SlO)$EtU|;;=FiGuZkYzvKfBJm3Km zq`cZ+GGVxzKT6_Gn?F76Xma86GcK4W;p;wobHtN2hR=cU%M={8ty;EL0USokIPc|}IZ-tJ$6*a-)**-n=<*CqzgyRE zfIIJEF}1*j1dj2NQtI^h>DsBiPe0@Io0uGXfRTc$uC3*WU1V5Fc1|B*RB`s|JFY3n zyIyvse49uhC%Zg8@~Da;;fO|sW#4~Or33hiWnR(e4|g#!NnRKSWQ|~*L4{ECVnh&| z-||AwpE`%=a~}hbq2s}hYw|uttuk{{EA3xTRAW}x2eqQHEUD@6 zux$Sg928d$vUe;>$D!E`xuNZO(n$cYf-8dI>6J2D^}nhe82as3(U>2BoAz(NNQGAv zPSMy+{`=egT(de0UGy1s`^LDI*gnp+bsMB;;O>46oE8VV#7m;!F(9L&!oztEHbHH| zo&##WqUVxU9vyz+`tn&E**q=b;o;U-q*MZ)rk4j^YHF^d@RL?j^~60H^`nY9)80}B zdfW)&nXAW*hnssnKMScopAFBAnAueVEMWFDq89oX^(JvgJ8{n^5;VRQErhCGmcvDQ zd0dA2FMXN7H;$wyxuO+xJE2_h>Y8~!53f@q5a(fiVPVC{OKqJK{`FEJj#NG}8Xg2p z@7@n3C776P&G0QvEap_078WC<6x$Va9THX@ra6t^+Vgi?*y^-2<(o96iAU8+lplA2 zA)<$gs)>n?PT$@zp-!KIe8nj%>LhHeiuLK+H&wBv!zrpIh!d~_P(s1P3U796TS3sPlLXjMSDJ_R1k7s z33j2-4pOb3sXU)qidb_XGz_zdd92}_J7BFpL9PF6)vOjVRcFzwA&K~FtxsI&MWg>T ztl&gk7}WKBtZEE+C*>SmN?O_AfJT4v;8oZ84IAr#>tB$0HbCbB45Ggl7j!cQY#Je4 z_WYji^q82KTs5$3+(3&vmDjr{sf$+^>N6N6mBknTyJd~482q87NKol11WJtmt-jA7 z3CSf$&C4@E!!wEP`tc3``!P~2QQlz~9hE9cwK^wh>2`0)rM~cbQTCdIf|JuVe=4Ha z&n@(5oVqf47rNAf>S8K(*Q`Bbw`yBI?YfLxkK!fDZ(S`Sbl)od(3{JAiy0@6;W}r9 z5b;_qT*u>D7HF%~GE0d=?9;0vo&67cZyA+ko3;&OfQn+#ARvMuAYFoVcZYyyuu3xk(>?V?Or5#dLU?q1tA; znV6StkaePDg;agHQJOXUjE+l2NhfuUWF<28Q^#uG`>Q%JwSnmj!LXt}#D$o!bG6%_ zGkoUWy+R#7zZ%ywmNiugvlp)<%oJXk=_yDE==B7mt#qU5*5UKj4rJ7JS9??^xwyG1 zdb#p?{ytjz)9)9W^s?HaNiSdj!uTDI`cGvqJGC}OzHf6@=1==6b2yYRd+Ym76}4L6 z`4|d0>@3r7-v4dx_hgS6JMEqg5mql6Kfj>Ak{71WlA(_OlxQQuc>YMYi37+p9{&#{(c(Dly zX#nHO$Y_GoS?qqa4QpemVBLl`9{T#EM5vp!R98T#Y~X96W%qjfc3QVRB3w-h6o{~P zI3`1TGfucvfd?EPPx_Y~}uefq~pUmWvq-Z!GL?Zsi+Q{U-HE z0(pYPHP|ikyPNc@1u3yp<=w=p8TLgifz7wP))AWqRnIq$g0J%XiFk>VFIqk^_N%~e zIl-&`qlcF~$-`lwmmCF06Dk-UwX>Z2i>0|~p+(hVS#qqIveein|2UZ%VwyUtwZCIi zC+xUJ=eLX6x#IDZ=>dRn()T-Zp)0okm}y!b_v!11>zI4HWPc~M3E@J#mi0 z=hcW#L5hZV#A@T8wJN;U+iEPZ_6ZoKYc!`_Gp4$5rJV_utaWQgl)QR5YJ3(dZ+66V zuxfucEP564$9uGS$JDy7mnk-lqt0t{{=w*cz^?PsLih$F&(%BnQl;T)c6sjUr??;K z+K75aTiXer5G1n}fBV+(`_ze5i>}|^(u*jW#qijEmf3JcX{Ec=k7K)X_xrKx$#DKe z`H~c07kd$g9EXr!K%UU^k zRm@`+VZZ@4OgW`oqZy~-W9r+NadIkybBoQ;ug=C$L72FMgM;yC|N?2KZEE0)SiFOA) zCjR8gsr6Lm_auQ;fs;FT?oe~RoJ<$Do962^Z!-$oz_jak-T!85XBu%KyO0nNpTt1Q zMCb1=5C;*okgW6thx3YJd+E{4hG!Qw*0UO66&$mRsI@txIb+xHq~`}WtRw6H4y8p( zYN|&M4^w{!@Ua|k*X(lHwMR#(@6BdJpGC!%1RSW_8tZc8FXeslj!CUM9q>yYz){Oq zioln{p!IINC)XbBwo11*klsME+ov9-o%!u_BsXde=lp4ip93*M)mTh$-@7Kz_+#&= ztDWk;21p5u_@s$VUv z89+VQdyG5J$wPv3YhdIqyMl?3$~V?!#_{B|>xvce$ zEXTVs#d^usa{9ObezCV|%31hdXoirzL);s93#6xWK#ph{@IG87SiVN_7!&hm(Kbtx zXjR-)Z-Jund(@CfuVvVzKL2w7Q^`I5c?*x#-y=rxU-LCfbAA0W?_*^SC_es^id&TTC+PqWo?3D}8CDJ03?H#{rYO z^CwmWPUGV_xyRw!Lb<_FCTY>pst3ZP*@U;(yH=HEiZkW%im$A;b5bbEI}Oh|WE?HA zG!0U78in(zw!Cp5260b?B;gH=mSHw>5t!DPve3)$?#?a08u&^P)WUzulk&koZ)%TY zj8;_D%o<*taqi@9RMkrR4N>*Pds^u)6-KHD5;<{xIuEKVycq4~{Vu%a`0^H0pHtWN zd^>8&o|5v=iIB|?EJ%_)j}ZVc0m2ORtLxUE_>o=z`bX#3d4o83xL`ZN8}beDJ1xV@ zo&MvxXpkXGdKjI<32pi@aqwgy=E8Ax9H%&MyAR!#ZY9bSZq zuZOrS!w1`s#f^V}u5|74%M&?(voFh#Ja<}p zV@0fPQk_eaY#C6UOlEtq*AN(5KoYcHP2_Y@Uz(2RyuL5WTXX+tt_`soOo6fQVmG@* zn}0*x?Eq)(B0BfCXB;Vo@9iD;70Jy;OAF0wFh}VroiL*C&=pP91{~)>hTAI*`784b zt^wM+bHwt;rBdcdS6T<{HhEV}?N$bd=#zX>*S>if4OOmjB0i{0s#AZTot*ymE+$<( z$tM#Fc#(c>WT5Z%X;?0uf|t{*F;3MAjs5O1!$dlMBp%%Zw5S*p3S(imCsePyHqa-r zqAG`O_i~?rC-&3py$q*!Ri~L2+8S2ptJU|epaL(6n3Qe%d~LhGZnbXVA|{b0OpK zc=sUxI~MLw&U{@`d@pP{mT-D`3g;uUk`C=tnNGP%T=%wmtAZcFKiD}=ssC~J79wYN zwwwHMgTj>p*tnJAV|6qXZ4b9*2*<|QgB%t?|pqLOL(VY(x=Y0oU)gn zePI0uZi3aSLl!`DjzPx*UssCR#BDfYIbC*{_Rh`A+=8K0;E~H*^bqBmIjf@md3$wq z71$N|X9Cxuc?noO=2g;ve>2Afce9q1lYw4;vD5?msmU!iqWmJ)?Cq5wGD;e}NT=E^ zp&54%TorXJMJ;xt?_)FR!PH%2`6o~26dxZnG>IyVQ}#=&u1ThuaK(7>scr^JOK%*0 z>z*!GnS7DnP2_mKd`B@SPd_X7ycdUZY=?Glpey z@x|)X&nK#K)%@!vngUTM#di@Q4<_6tmN~3^)y?AV;sYK2XSU-(g2XM^MBBbo%G)+#5+)Vs!=SuPG4!RJQZ+MyglIkHS@1fI>>(?y1 z&W05qx3s)`20#Pe5y`^7HBzRpX3W&D#b7avRsV)3*OA6$iuqs-^rK#yLYr&JQx~r? zvTOhAwksQ8|*i&vv#2m^0K=R7J#r zm*I+EDhdSYUeK?f&tJ_M4ywF&R1AAPm7P21v@T-%$@xcu8!`p)L+(;R)=pk<$x{Ae z0(DHNX8umC<67Koue}?mR)Ma$$+xA6TKbsV@vhT6Nu+Bfp37_V+Ewp!ipU-r_pv@c z;(|5Bw(k_>-VqTFXt;sk; z-*%>eafAK22zs0=?U%Dw-=)2AJ_g1#Z_L1(PlPO-X@XR$C7O7ZFp?te@@OkmnQ1n8 zyh*h^e*e6U?)~ue+3nSz1L|*+7lZTG6a=bj7Pi(tI)Ag#lpFK=cJ|CkAG!X(HI#tc z!3=FKal50wAecSaxGyF_sowp*~rYMmn^mLjrzrw2c9~~?GqgC5C@^wvQNQa+APx_Tb760Iv8Yvg**74cR{cK$E zdz~eh;IulFzaTHU>cjh1Ev2ZaZ)nI#Xt6GtmR2msP`^uQqAz$j`$|8m(DA?zI{YwW>0#I!Qcm%>Cuy z6k`{|z<^oAzW*TQv)(|>_-O@q{#o-CpdEwy@NS9z;}|VPRgE7RDnI09#10EziG|rz z3uP$yQkk!jTl7)|?Oqv3W+R(-7Fy@a`T8PVX#KeUG4AR4+~c;M&oR6@^h@l~t`xXw z=XY_tZWiJ);GE)iUEd}Xit^GenYs(O0X_|j(j^?3YTGx#+vb$^mG5t_z{2da-gNQNN4=LQ^5b?3?~E)VU7E*F zWtIHDOSt5uJgj@j&quK@`MzH+^f9uKox{=3r(*&j;4J2S7mH+t zQ{kh+Fj|;`TaT4|U{;a>GNXTBpkdkB;uq>3%pRU@yYVtE?aFEe#eloVcXM80sw$3* zS1ks(uuh@7;fV24HgtH*I}KY;=Ol`?GFq!iFHd&djk%_7$-$8DT-kp2X=m^1$F4Gd z>o~mE&)arZ-rswt=9uU5E~-yj6@68Qmnw)D|Ni~H+^id@r_Nidm45ldqnM~I-p&?D z+b0b?&dqf9+Pr>V->&!a!8?+F*~ftRa8S-Y$UmI5FOeBOG#V+A&fBrsP3!4Zlt{6Z zOcYq}bL!rCyjxx=eMIMy*xG%4FY8xNy;YbIMSk&*`hh2=+;8Qo)ci3Q<2-Y;4^vqp z5f4RH5w{C@QHfE9A_IddT!Cy)HRW|4>9vuEIF0&=KQz)6p2^2)+O`K>alDmZzy3D- za==>#?aEsOOb@B3eCaO-3wmV0h?KQ_=(-^RVp8(JJb9iIBXOH0SUMDsfJRs9=JxhZ zUvWRF_{7v4PerqutPF~-`MkC)YWvfvdL>!Xq_L8JnXRA%jxsqdZNTr)zk-}@t$Uma zc}K1n@aXf=u-JU_)EU>u)-!UIg71W5W>sO@?ci|9Ir#r-N;Il%^u3lEjLu%S?mw73%N;zk>82*a~XQo;BZQJZl(#x+mbtsPaY}Oe$y~8;= z_$$O|ZLmK#br_xVSL|@fI{uU+L441mjq$Kcw%WjVU;wUsa8rSEl*3}h14EL3< zjJ1ab5EXV8nov#~2ns~-Z1(CUzo|@7qeWw8u{O&1MB_!1>DzqD>7L5}&;-!?ozyb% zaEQ3&35a`KTdIBjI{2b+_9+Jk$6Q)alsN+Nn3D1f-8pKmcA0ILQ9I3|Cx6^Rb*ejT zNKQXDAW3Rl3mjk0#y4-8%DNH1E`PXkZ#FsSZMn1M0KZ8o-;ZJPgXo0s(s3f@$Jk>v8H|J`cZq~Y4&jj7*Z@E)vH!^Y2mE+$M^C<==~_N*0z|abWi>KO08@d zPDA^Cm?{yM<5F5Mh5E))I#*%)^yFgaC(qY0%aW_~)J{bCLvh@0uj)3uPDl3&>%_1& z$|c;=Ha@rRWFa~ddDLpvyOZk9;MOhLCUVnZk?>D^FWMY<%3A=&M&-Km##_F(wp6R#xk$r|wQ9$){o2 zz~S{KMl$1NRp2@v8VLz`_cjN6k0akdWR#d~4$V5V8LJ*`YRW(&-%l2KqMpn4&h~E1 z3jM~|DM|n*vDQSES0(q#Axj&7>?v!NT`;2YH`|B zSelxaIIY`pg}kdi)!?ddoOHW&yu*mg6^E{g{dAa7yF$RC$a3>tjhh<{%~V8;^7@#v zar3rdAm_nw-)gT`Z?<^(_mzgk@Myw<&)Zu+t`H!ue3!U{ws(ob3Wp%a;Sxo(fEmLv z^p7(Qeiz&Aj4h#LHiJ1iQTOlNW42%D0C%rX1BnAs^j4^ANqJ^*WuKSnHK_+DGsVZ3 zAudMhddMHP-R1)}Qhy2X?9@4t!l9(Rn%`cLV|g1MhJEMpI{&17cJ85y7^Ry`yi9@> zZ>h4);G=!OY*bcIP|#mmV*bJ`5#d`_1`RdLiK}dRQ3(+T7dKzG%6fk~u_pSp?sF0D zO8HE`<7BTkrx?YA6jpps`{PJdS~7HY z6x!yp{VmcgO4uAs?7T8Sq=qM@VXv#q>`}RBpW+&)cv|uTqMI zL&X@8T%z#ImTj>;IIdS!Za(bu+Um-k6pXwlNh|cvt9GWlqi{GKR?P>C)%^qPu6jkA zn6fC5O!*SoyV|M9|J;9spRs)x*T;&tN*MR|3FK1L93IF^S}H1y1$RlRodX2@F5xLf^3F5=AR?Rl`X4zTrQ*ab>dQx=30=xKHe^zx6hn;8 zj#~?z2}In$b%HP`<>j?+m@7YXLJ$PJq&GtWWQGS|bXUmjL zE~s)?Msc5#`D8y<4K^Beed5BVlEab6fhi7jKiNA~Q3R+vyA)sNxi|KuE3wetHS!Uk z>hIID7F~1fg@};-V$GUz8z0gp z?2TQ>jE|TnU0<=`_fXY{%aTzwR6Ld^Z69xx*YFfAF9^hEkns;SB_7~L-AXH50z~?E ziHw_I?}Ckuoempik}pn8`;d}v-@bix^cFjQ6==JzE-to*VNqo(YwBn*?KQ4@EAsqj zBG~j-uDpYcO+`r=X7mx#<-r{l|E zJ2sYJxIZ!Me6uR{W26wX2xLWG>Uqcdn^|G335i()BVQ{1VtTi0%RX5fD%9jS8ZY<$<7}+;D3ucosVndyI*544r0@rh`&|7IFU%gTak9$vqk?6IG_w`Tdpp05rB6wl+&|pth04l45Up;se1zT}oX9p-%6x-S`l`}g8vi@SN0%psV5)RS>ee$l@YT-Q;?jtVF#i7kzd zfV)fAS>TfyPl-$3+1(h;u;@N#{fITls`@FH?sE$Jebe97`ch|;I9#c@m|d7fAEl&} zTg=VndhP0Fi4K4J4EJYoh|4|w%3ZWk((r~k(nwrxUglHx^7D=~^@E<3JK;JryQGcb zbw;M@ii$rtvK>)jc8vDFvUbiJog9#Aptwk}pmG3uT8{`PGxOKwgBytZq`0__dn<#$ znsiC1M3^bGFC6flcI37FI1 zzd7iDLV_!}z-|x}$nGcW<-ibsT(SByoFZqGEz&e|V~vy_Xll`_w;Sa7##gZIIl1Tx zzWA#|9grC!D~`A>Z6HEoV2pk+75SzM!*jE`CnQVyr+Lqv|NSWW3hsvsF1im9{;k+%v{&>)*3@ z@#Jwuucmjk%!T4k)j`ktae3wg)2TMuRk`PKy;@bS(fTql_I22;$lIs8qdnnz_TyJ; zG1u(k&){TU8J#^$ao-BTVi?gyspLD)t}|!?;|)+EkvRlg zx=y)uVq&7Uo}M0PpRJzfXJ<>u$$1{{(sTwxVa;zj@?{#x6$jJMkeh|4ryHu_ZHk{G zB4ldCeQ<8%b6(3FEesD=gcfJ9Ga)7-q8_Jj=E-G{;PUeF7HU_C1ye4LF*JgTr{HD9 zHi&rq{r$lb!6Z*!#*MSjYJ|T0UYOT#S!iNUXfg``863;u>Ef+=aaKP1@+poff9g929bZj*K6i8U%1I+gN&E7peY!@~ z?^ge0E{kED0N*IGBE`?3j?aFGDbS9{ejX!eqfgajEFjn@39mfas`?j;-pEqQcLBPa z00hL`3e`=pGRk-+mq6Pd@+ot&#*gtr?&)L3$02r$b({s$0w!G?8IU3W?Vc>B6&112 z(0rim?CJRe(S*(LXgMqSr`&Ryva)iz%jT}RSTIor$mgl4hv7tms_9R0H(xp?jY1dNT1IdCcJ z7s!tU_U2i9dlD&BQifCeA)Onlzm~%Xz{BvrTk`t!@K2=s5>a}4=xO9=9g~U#J53Qn z9g^K;3J?o=xVmx|8k04^usS>}?2FkC@7~1cCv{$W;0l$Z1s^(2bfTKF@07mMO`0j-R0kl7r8%7xNre9TnxM6hwb$X-sLM}Vq1dCfz zXkvpSY)U?KH!lzy=LRcukl2DXxvr8PW^}}b!R*V?E5oiJJjfX8E#aTEWH9Q>^*{@piB{$+)2v5|Q968kGle2r+i z#HzNu-Ss@a%#&&Ds)LBt0&e8u8)n|)+nWO!S-&^y?!+wfT5aP<2U?MCIFqccvp0u~ zSGmbc(s{)YU7|ooD}i4n_%cN_gC0_VfJGkDmqI)Qkc`9yAvOvk5D9^92%eQ_{~`2T zhbJfEVq&OD*S)!^NpY&BrKO=^w%+Ha8kh}gmSlrVZAmn+4`lapm{?gOCrcgrrh*+x z8~jT-TUK<|mD8(L|MD|hNxX|w2mvbS5tu-9j*iA*1{&PI!ah6VpV=(=BqLMP z$SXix;FOkr&P|(J+I{cedon?*pVH7twDJSvpAF1;fkNItummO3<8Bp2MRIWxURSox zT`^EYfl~VM;|vgFIW6_PUFj*6f8+}NC|EWr4asxlSo4lmg$F!FrBe5blj}2^V~?c) zJfhZkR9-|oI1?^E-Nf!NV3Y0Xo5xvRv^|usg)Hn)!#Ts52N5|l~~#FiOX%~fhqzGZR|o)L{O!{HC_1Hoyl6q)ry0iFENbM)h^gg z)Q@-`F+JRx$mzFx&~&bOyxl+*M8tJmQGO618hCqc`T}a-hHG~)uAxVR{L`hz^UO71 zffDR0wNBcD|GhoHVH1EqLsL`J$Y>4}!Hn9KC7`B+VzT=amom(1w6(RBmFC;CuBzF+@(aCef;7_&Z;dPmIR3QWDQbM`qy>lYu(az$vt5?H9`oG*vBqP>C`1> zl_MhYJCp0&h6{!~U*Z3cbB3MDMJ+3W;Fju{i+rnLM3rq>QwDw2-#Xz{C0P(BpmXwk zh^A8q-oBcON>6S;b^T{?MkNx`h2y$~k2_L!_V!j*R;^aCZF6yyCCJiK-of_;n7Q&^ zlI4K=0tV;yyYU9d@>!U{3TW%kpSZkqik@De?bf>P1&o$q{Pl+ug?#uh`o+2?=$7eH zeK2L(nsU`(PJ&R~*4C>sV@JWP2iSx;sa&F}ZWR;R%U;gwdn{}vDJgoXUDc=6JS&mA zB_-geWw+T8)UoGlF_f<%J=H~8`#+l#G@^g9xWClzG9Mis)t5_tFmC_o^7=I;H8qs{ zP%P%=n)wI$`#&yoglV>?OU&?!eh@5oXq;~TB1xaDaN9H#4?$8s?o3Ku-FpplYaYudO<2T8Dds9H|z9%TpnWgc^FKdfpcn- zgGNM$aLl}{3t3KG4a|X8l}ON8~h|vpyOl1VGj2e+-k!F-ZeuKhN^HhOA&MJt2l}>lX^{5&`@cTfr?2XuhW_}IJXFY9R~xYa&}g(q zI(*>b=I%q6279h+iE+iE3wLH`SG;dl1RwH z<+tH>R9(qAyn*l>6z+tD7rdyb1n>p$G3S*&VO7P}`ib9b%dFQdZ_5yH)+XnU^<28* zcZ)#c$WT0#g}3$ZH>h}znAk#JKNX1-DU`^POEfYz-rL;;3ESu({ci}?pp9D-inO(} zJ3gqp;PpCpFZvBNf;*sE;5}|K%pM5>-M!Ue=hdO$g%(RiohbkaPWIRH($gClcKEN> z8Z-r<{6{t>6J%oP(SKtArfb022Q@p$GkVaadv@Q@AP;I?b{0@wt%`&?p7QnUP|9Nc zQ!zxKYyJj2jft+Yv$JdLeQpAgIyej`^LyzmHdNLlv$8hFN~I6o94x4@u&{EKr%lD7 zPyB_gq@v;gb`i_US&r+c2awLEMAa$|ej>I9b-0ZVpDdijt-J@0P;e02RLOF;uGhut zFo00!ZnGE^3#%^6My-y?01`my2kHL3pCA5~d@`?j9+XUvAd|j5-MKj5yr_lkif^x6 z%gxJEPD%+Ur=)zJKOke4dpsYb3zNRD?XnAyk#R=gl!XKaK7YOSYcbi2&vJwb050;Z zj5y|X*%v|bpPv1JO?$xv%--5v?Kf}UR902ZFn4G(s^fyO8RkRqo(X>BMA6yNfyDQ( zaH>68NO*Z(ij9NAruY3#H{VH68^Zj@0P>*i%^NgRQ&ZPMquhH?6FG#N7#a1v612E- zArE-I4TC=HWFMWIJ3KsG<>yAsg-}@O z{d$m@)l4@?{NP`N$pBmGS}zQB@a^sFvfrEdv1Oftl=H!Z2WC{_ZBmXOL86=X&3ury z(mi%jkBsNFfDfp4U4fJZk;lxE3(!L)yP~S9DsYxtF9s75u$lvf8=HZGY`m`Z$d|Xi zu9X;|T$U#8V-h++O46@Kx)_x4Q5Y|Lh7}bhQqIeLbm|2?Pb1rwUz9Aulmgt6dOhE7 zu5$EB_m=zpKw5=B zbJ?DggdcaYlYG(RgK}N$jAef39%0@$e^KalW&z!43CihRat~oAq|Plk{8T##h4$Rx zKivWy)Mu^o5Dcs_+~|Ih@Q^_eR)}! zQR0WPh-XvVB4!|kDvS;7pG8EDQX~x{V^(h%l@(jL;dxGkcCXCODl@4S=z0Os1fePR zD2(cQi7{pkW#5DI(ruD>9A0*I*gEPM8Q$CYhv>@5zOu5K;@nT&vZ}_Ce7XBmHO0Ih z3*c3&&Zw@pPibJ_OWTJEeBaz;y5Ei58DyQ{FA2K9K2dU$b zgkOApF|b5VS$~l;^}#qe(v-y#(k!&lU|DHr$0F;WlLPi`)RP$p52dB0i3s9K1%hBM z<71#D6cok4OeFmCINPYf7t2Ak-$x#dZydto6B1yCC9SR=Q(#R*C_#i$1Sdp>_hpFV zGa7$0pJ+4pnr2sl4OT@gzi)#t+ztj#N<= zB~4Ln!IlhJa3+HNg(rEF`k$!7kum z2`t8#H|XhE#H5skuU+#?Nl5{J(MWHI6r(LI)W8ejNR^~sW}vZ66qD+IIYzF*935%e z_q5pUU}M0t&!kxbVW0bJdAW7snekl$1i&W`oq(=o2}1$( z!KA!H^Pw2T&ia?imR=vOybYg%2}~&eIoMvN=V?LT0JAX%MP)8RnqV}xXJOt+&z-wq zPSAXnHmekFZcun1x|~g;!~AVR?kKfza|i}~X2SOMs1xSjo3F)5WOSR1Z*5^g%q6#B z!T{xl@_~UqBAgGLsaPJ|Zh`g|7+t^x*7ewn&dH%MM3w|NHI-<<`S_2Q@omPg!YDN( zBV(w_2_c*KG2&BwSs`BB@-p0yqN&=3;c>UV*I44$#GUXByr+!yk-w6Ki#dth5M_-F zUbkqTh>pFvbR{c^%<^m>v27KaD zJJRqxx7((Tryz17?tojS0p8@~B-|w$();(ZSJ{->7y z;lc1kFSv9}T?H?dvNTx&Gt3i+H%wwuR(!U<8v$XOhAzEgE7d~@y^YBY&EP5|d>PB) zv&XluiX9L1D?>{Ujc{pE(aJ={4xCVU{gQAupqxUczr(;8LS?xgQ~ zV}G=5+@>H4_h2jl<0>X8cffZE#4Y`@`xO70(Y};X`hbx(Gmq=xtEl5G$n{^=^F(#5 z3uc3fT?1p*roI*z2CQTRI<0;DuSd@+6ps)2fSislkfyb>^YPB^{yx>sNkB?2{?u*z zX^8gI#IJaRny_n{-c} zDEJ({f6pDvMnxqiF7DR`WYb!s*8Ap6UttfpmzP(wgd~Lpzd0RKANZSzstMcA-zMRP zXO2AzK%9~fNR@oq5>jF*bu*f8R$lhMiApX@QvTsnds|z(yQctSAta~~4t9113^FWA z{QPxbCtfxqYEd%`uQefKa9A&lNxboV*@1t2T*gC z&+C_vBw3dFT3VXHQ&StmsO!12Ad5xeu|0QVXHZ=F<5O}Ha3Mu{6zJ9^QGJ7_Y-NX< zRc%J3eS#Pbpw$2+;0*D;Wg`-;mVgOMTI7WMdY8@?NeUBMh|5b03u-5sbca!>1e&H^ zEf%kO=7xk6lhFh{elL>{Bcb-sYquZhd4{q*dlt*^stt%69|}H0umNA6ui~MkY(!5X zV67Bt6#I@6j}ob-|7jT>j-l--y=Z{}3@B!xP=)H*W=W=1j?-#PWERb855~&<1oaav z8O*fw^qq~3@AqXW?gwM2BsV{x_1gM%N%HABo*3qv_x+hcB_8!7iENNN8wJLe*VcF} zw|*fasT1O2b-t83RyvM1oE22%CCp--^tZ@cPM29tedYp2jNA6%4Fqjf+~Hpt^zMz+ z)KoTSaEwb)M?#5dXJ19+K14wUwB07j9dbYA z0EJ|H`R)76tA*}l`FYB06B84UHKmKvQ4)BR&sRX4@S;T5fLj>y?%kCSPj(ub z0K^7TbCuTx-~6&r<~CHr3M73(yu39q0)sm|2iXV8Tu|rdWo0b_n1*%h*3}CI(fiT~ zJ!X+fN!B(t@`m-miK0OnJE><>R2)Hlu$%^78(Wa0mKm+&uGHh}x(kMgC-nOZJ}wyq z6AN%A={UVR0Dv4lJw2k_p=RgKBM=$=Rlu(3@5!Oo92ulg0qgR?m#=Z0&Kuu)4KeNz zNFWY-^eKFE?vSxW^^GW|n^<)7xNqI95tI@-(MJlrS5V>iJdI`hHCAfDmJoDtsJ;vy zW;Tn97NVntPU2j7defEb!fw~E zUr#CRcpr_T%EpVFAUhG>()PyjkBV0hnV#dUk^L3k{U;^(nc2E}L~PGbkKFdx$Y%@7lQQjr82yfXq~8W@a{W&+S8I+1km;i6@ggTd$Aj zZgf^7%Hk6ur3Xi_8Zm*$*Q53}oI}cuwGYHa*wk{TTMbaCIxJ1sUBFF3fqwwUO1ID6 z`a6|k3dl;tR=EG@0fX#QmI{n5~R_)td)?Jhrj91ShS z19j%n9(w-u0fCdNaMsZTPXGGAoBbQ8&%ZhR>jP-(sCh3M+Mg?^51@@v|MmIbaHrsZ zmB|0^5B%RpiaKTgduUMC>i-AVq9kl$;-w7)ihBthRwzEp2s)ZTq@mt9}P`b53ngz zE+mHRrFq>D2{@i{%q6s6WN*45gTD0k_J%m}h6B=W2{;_13A~3uWX6E{#Q0yIfOzy! z2)=|3AO1DP3Nj--Dq`IwhcAi03IE!|@dkb`R7~?neS^-wayRjJ3BjAFAO^HooHq-9 zWqF`trud-3+#~n~0``BUR}9o|jtXS=;7d{}Q2%Omg@DEk_1)iGhcD@QiTd@*F8#my z>pfBwgNi&ZCPq9CycIx-&<0d=Mc;EJK5FVk;Ppn)K;g;2kSPOmVC8%mYrqUL7Y7B!I~J8l zC(+Jyo>ITo9_u))98H)S8ZU{M31{*;h?PhXj?qWn`;_=lcpjF&bs+jk&G@5I_wPof z7Gv|tnpml+;YFrm#hF}}i#%spPsQlz%^~`+OG<8*|BEedQptCSB}DvaClSn^OaGxk2}%6(vnoI>>u%tJ3&W(I}%t=qRrIV?vYy&~xIf&cRG zM6=W!cRg8V4aOpXk@ffYcXsB(p@WGE$;h$L`6$oQT zUmRSV>nbVTUr!#hpKZpv-vxDO_)26wFbnCmE2Cuk+S;Umj1+?Xvm05TfmB5ODiG%D_DF1Rvyf=wcMYDiHQmKCjFy=2lq<@gWq85_mrN# zl{8Bxt}k8uPG22-xL;Dyt-87z49clt#IlkMGoQZYFgztOY3acD{Jgy9jw>o{FRPqn zfph_+nAX-0h&zeiKoKmBbOqI?XCOXf<}DIqKpdg`hTS@c-CpO=fKNx1CZSJN>v zhVlfrwH|Ct*U9f-<%;dK9)o{oA1ez$$tbFAfeX!r@o;< z(ib2jfc^o260ws=P`H^xSTYXHEII~;l0^=SpxZ-rke~1vgC`=)2y(DsQwm@U>?aHP zTG0KLq$VdP=jG8^Nu0aPx8ZUdzzB7a8kdrv2l`S#m6qIdMkzm)T-%mkxthCwyk}v4 zXT2=tOPFQYigG*2g9l5mO0>93;jAgJo8L0d_KHweGP^*A0DL&0x$SQO*Lv53oT>rc$}WCcK?~YeaL+wAS_rCjVdQ$=gM z{qLdVzA#vZ@dZtgCnio#R6cXwcxh|PteT>YqLbYQ$(77;6(F34hp$bv+}zyC_9rSJ z2&I&9J%7HqxX5bJ$_ik(nUN9By?bBbeu58h<|lG4E|=akQP>z2#SiDb7<;S^m?U74 zdF37KB1gxCAVgiS@^E)|7oc-IZ0v^5xLh#Q0V$|=F`59tC;yrSA?HCNeEe z$Pwr~k|X=TVuxh}5V;~%_m}%k!Sp)l;P~VOc>TM8q=1m5;=Ncr=*v(=Z40%&AKQ6i0#H z+$T+&)#gxCLVxk*DKZB&>d4Qhp9fs0(s5PHkc4mz_S^Vk5mNzfWo6Ylak96)jY9oF z)`2n~O{@TL8xGNmz}v5Zc;e#XE3dX+{a=qR4MH_IOQ4kpJXV1T$ZpUG=^x|TwaAo+ zF_`?>0@1Yzh)S-nUx(?O@Ak_BWg*)A=Rxhs#`EnCNZCb#ENq#4R_EY@%LlNI6UxeY z>;mv^a{`*UEf|WA_?Vk%nRGi`-xlM3P%KgP`0E2eB~cjYrwF0PGO{){n=op(1PMtA zJt0c4L}}BJ3oKc?_PUGn1g@OeSOS3T0LxJ#CSq4ovgorMyAub=8)wNuLIFWfNQ2l4 zCgzMySMY);l!vmxe|(zw;XbzrR0T<6==U%GM?itZ24SgwqtQKd6{fd96{KP6gJC1k zXFg%JuKv^`At3>l1@Yax-#;5aBzzA3m2fa3BO`M>0n;Z$HwGlI0pLU$Wfc_>oyFh3 zl^P@*9Ub9mkNRkaaYt|}4S#LFI6+0?4`gxlRWD^x1q3-oB9m>}uOE6v-{9~lv&O#T zbKAH483qZOJSaSg&m%skSs?47B@$U%f2R#ECh8UmhYaN1?Vxb5CT7a>2iOqn!Lu*X zwLhLwQ~OzJY;`c9{r=CuW^Zp#LXtR^Ed5y@i3~@+FiJ(bfCIhJOTg^CO+6sg{A2>R zToyzh<(R&$?H^#8NHDfa$6<;9DFckcM|>{M3d_QQKtEmS7^s~s3X5w_Pp zS|!|emu&z17UjkakBG2?`Fr0sFnCIvd6k|&ukt)Q?o}N5zea!97m4&XGF!7_XAg>c zxe7@|MM$X}<~NRxdjOwZ-w=ZzF9%S1N${;L$j|fh^T0e-1QT++F4*~$|FR-NJG&hW zu*$-fZq~u6U1<2^C?qCj@(t$AfYgF-lN9ihgoPWXrfP$_!AY9_>CR zb%pr*XP;Fx5{XF-<$nHL4TTx(A+v)O$Z(FPzuCUikWPpk2C1R-cv(JFH87#r{__Xu z7*KBL)82(=2}9B~?)J$LrCnhZo6>sL3 zAE2gCaMpG>4N|Y5q;f{XQHA{y!0$Y6+RcQ3xD!A;@=(uhZd>09_W13y9~2F2yC z9PNkX{}DqgUD`havK+birG0RKsSn;>cs(!$nFFEl0+t+Qw!XeTrQ2me*FV2~fZSD~ z3qu^3Rs&b1Au1*+3bln-B~pX(ydqpoRMZhj;?Nc#MOc`Eojv-< z>2c=e1_&LXCSqY>rP0;YJccoYnS}*w9sz{oGl(^Pql&d<;Q;U2J$tb5k&zGqL#$Tq z!?12yB>vFQQ|L=c-~iIy0s_+A-Q7wz?>_U4-{&{a%zIsP`OoON z@B0%w)?RyUoeaQXSuN*LlLqlXY5f2%T%B$y)R(d z);O@A;&Yz(paQ=ylCFMa1pMh(cek{pB+wdd78e&`PoOFzA}L8jNtt}}Y0A6_xW2ff zns#MKoqX0dHzhNefe52qsE54W?GYoXDJf7N={bjxPFU5SkRyB>DvNK| zpnqjKeV=DrWU>;P&B0NDThRww2u&erK|z?r!|mpQdfVn6H~EYWVIoi5n~0-?`ydUE zFikIpplA(rc%e&z+I~J#G75utQ1l}b^oH^jE3mEL4ATic;Y~>fnQXc+Rf5%@-@b7! zc3=8L_>Uk487)9Jh;!ElT=z7|1RO-4e&_Rtks%>-%gbe^W6W@EAs|UhOJmrhq@Y;e z*jTYfI`K`4vMyx}jm@PceHcHm0Au3BwRm~o$5dASJSX?8aug7SmYum#o&}<5Af!al zXm)0u(>&8McvGm|grTjiO+XL>J&$=Qr$V1r%8F~Qel07DEGlojA)Ov5>GO23u5K2p z1a*(Dx-4!`8&LS$&o|Z`sJG-pTpfLW_={&ALPQuJ;=UF7$G-$9qQMR@I+ODn1+~3{ z1M~(yufa$Amk2ksZGrjc6^a+VUxqRvBsnBEz62H2|BaYotXKN4ewsj?huqF(mJ6+e zCpP$(qObkq@4-fQ_weJt}2+i)Kb z&mJNwpaX7S%9=#+P&HnuPHadU*bM`T)Raf5G|KqMfrp`o9FMG(_4K2qYUkb?p(s9C!W%8#Vi@4le$IC1bxnKtgp`Zn6 zH?Tn>i?5=tLXr;!ofi~hzE532ehS%J%wis2UF`}Ec7JQC%bCwaPj353Wh2+E-vNR3#R?q+p}&OUO@#`^xxB-UeFwYLyU3}jk1yiZA(A| z?jIQVGZ2OjM34pwQ3#d_E&#%gB$z&!9iuGva&3D0h1XFVZH>LXy|jpo3?}|G1iBCo z0mfkX1*Q}67?2jVwzr!!`r$*9)8l&QgH1xW8=OEwHX6@(2DUCZIE1|CAu`2}u7BjoGuD-b%0d%^=QPM3Hf$VqmFMI5lRumJT=;DW>A>){$% zKw-XDeU;tz$n9chXD68tf(U_EY2-9f79JLcRTW_cgaoozZKDeq!G=Sl*4+GXWi1wJkR8zr zFy8#REG=y=oW_u*?b5|W=uF*jra9emEB4<7PB9QB*I!Z_5s;&E16}b$-rKeNJ`0MEDLDDk!kUa3tKf;w~1AgA#>1Q8^nEZ;8lH3<>Lv{*1-%wef ze#?poolk!ZGYVGyg525K`Wnn?Uwv{uE(gXqVdnl+daI>~{L(GOwz?_E$3Y5_; z$Pz0uf}|GaHpDVw-l-BoMxKR*Sm(?nhVyU_p;x)qZsXtHfQN^Ng@vV-HWlTo7IN?- z1YC$O?L_IR-@cs!QUzOc2*F73wxO{x1YyW11vYWnJA@R*#KP4kI{ad&tGfVV21RZc zu6jX-OM<}dJcDQfIBYOPysWbF#*G_tUVhd;K4C&0(0=eREIfSBl~sB5OMH#vp3#OI z@1++&GW?%(Ry0^~Ny>Wgxhyn~C@2g-<)7Xc2H8C!2340~SRHePLdduwZHtbI>Ooyx zSOC_t4657(T=1tkP$X_A`qkxMl$GTt9(mJq>jz*^v!zq649v`_-+nF$kKNjJ9B}<{ z|B?k19sdXCfRDDew)WU65Ap@RCGwj=PX*w)Y%u7hrFPcVyJZ%0U%Q){KHho@sj|z- zKK4GJJI*z!4d??O9Uex`j|LtnkeuJb_-ROC1)0NO&-C?$P7(lZKu&A}uuX0f*dDzUE5Y626UEy3LiM=3PB_o2U0Fb)_0)iQYs@hCPK(~3=srZv==QXJiPH=Bk*TD zPqC?B%w@#I0gsEz8R|&RoHMB@mFyNf#lbq~VA=`tb3SboA3IN5O z3!2b?mPDbY*psfTq5>2m24B+;;7j|^ew= zel!dRKo{tmkJ;O6{p9CDMadj|i(Yx3}LyM~8RSkGOmX4DbJ2HGyS^Co3o_%6cI} zTfVtn#MAFa0KoIbGS$POKq*jbwU44zn#tA1mQO|OnY@Jb$2*hQx?cmPyO~B`*ch#c zq<5`{kSEs2Z+9gU-VIH6F`&@F=y(v6PV!aCEnV84FG(;4l_HVd{cfuqY6#{ewwynG zJ9m2ZYb9~7n}*m5UreLwWl;a^2tfzu^71k$4)qjsTFwhoKqGDft3^^ogc6Lg0@l;k zcsY=QByFIi0uHaJxEM*=ljX-kRac*wpPvVhYrQtO0q8#1BnG{9m{*T_)C-N@AmLyI z9x&q(KA9C~+Xg=`bWtIKc?Kc<~*YPBg#S*A`tQybxk!W`>*15C>x(UXuY0=fhw>C}Bl z6@~`~_u)1oAwK{oifuu82CNnZ4b5h6N*hFu5VS#hXKH9D@)0B-CV=g0kO1IM41>O; zpx|{IF!Y=aBClURj@yHp$=3)#9Dz12s4mo$Vy4w~`Cp)5@{XGUFafLj0Q`5Vh>k8o z5D^4v6`-WGwY88h%YU>E;t!4e39foRL?@mx;&CCgg%1E5szs&cwV^3L|5beQ73id< zj2ec<0$HF_TUkLE1F$Ru0|U&yT806bG(rV{*U^m*Khjc3ZPuDK*w!GH4WY5Ax0XoUXVD2rs3+scUrSU5rsqsaf^Hw^5K>4 zetQ)GLXfbL3>Jxz_PS*Y$a)&|?A5N)U|0D+rORvLssiKJYcK6XZHpsl8W34rX>w;~`wY@#my z`oAIbV6w>?6mv!v+%8#} zTfrwo#p3_xZ>!O;KuFHRlb~)!4n7#x0<1Wk1`;M+vCEe_{>K{Q8CpGYQmb+-hV)i< zIBAh@TSQXK4bp;xjj^WiKQ5hL{<}r^E*ygv^^|QMP(`wO9Hs=oX#m{<(QfJ@L}fWQ?pZ!Ks4PRB5mFzZ5vu-dkt*m0yKboh%w#~JN}x~F(XOW8lRYA#$)_D%PL zv6#RN;XzkAhwLTt8HoK-za#Y^Ms%empmW9x*yu(B8Q~L?)^Fb~59iMT3$u1plD|EM zg_e#ki0k^L7bx&lNQT{j2(@_W-5?w;3^+3Ddn879#Of8+h7T`&!4{T~FjXLS*t=#NV%NE#MkQ+Zoe zmoCZlL0J~a1hTDZbiJfN*l)V>f?Y&RY;7QO2nr*^&1Uq_Sq|0=OxdpBKF}|1?UJ;? zp#W_F6yeT<>}L>fI2>6ef!RTF*PVI&IPg?769D0n z6#&p5!^4Y&Aa?U>7?Om6BwCK5!5;`D3&f@XYMRgl10tCPiQ{Ysq7@+VRBzc2qiFec^%aB=8m>N&w6sNUmylAV$Q;An#x756{iW@c%L zMYlB+_L2E50raUtu}f7&g#-@Tm@o41BUz~b{qYylpKJjf0HDZZdXNtS8pxsGLt_I2 z1A~HU&8UzB+rNMAC>xk+@Ic7j9dU%+b%77BdbR-xJNS7W#QHuo>i&lqYd{N&i&Q}U z!W9x1XZq$%0rXHh=4$bkJlx*dfi4|5sl(LIppg6bw{o`yu)^*EAtAC{9GLwP?i#?r z$WE9E@i)I2y8m}@3`#w`yn64^(a;2-4_3enRYgP$0kvdqZVtNkew^^p{&OR`%^aY6 z-^)u7LLY)Go7x3SXr`qD9Q)HJ6k7&V~o=5!Deo8%4FLE9Nf zz5w@z2Iv?MY{mZN-w=ZQDh(|yoPQ@~@iq5Bxcr^*TpTPc5fkD>|2Y2!ABRUqR@T;r z^bx?|fGie*DL94bXlUA{LGu6H25c}=fP|8hk-ffBL<83zOf8s(dNbmYe;nx|${dX< zcD?pUsLC+E@SL_R2Y??8B_<{&7$s3DDgDwQlYc(qHoO8t0qU(rFpl0#4}0d;zU z=$G>gOSkc!PXo?uVw(QPKlY#li-2HleLXfRs^xmh9cX%cnpxyCX|PQ3nkA6ppTEwD zNai`)#quN~2pxdz{Ila#cyLSAJUnFxmnP9Zqm zkqlWR+YHI+{y%fbOF+WRJox?lcQAqILQepefZ{Uv4rs6dY2tdb$4Exn->q|z7GQzR zgV5yC>6Ls3cs&|L2AHZ+(f>RMA%I>52S6@e`2LlIpkO1Qdt~b)j=ewv{-3vq`O(!S z#m6@Xv8~Bt#hvAzWT**VyK$p%4}s(e!&NtJ0|7c*Q3hmY7W~Ys)AER-nKD%9cy54q*bTX)J5HAta|Bky2FL0bZ35L zBk;cuGGuR4L%Y@AWs(zboY8=N^@zQcC|ZLz61>2^&VRnA`>U|4fJ>Xk?MK99=8B%j z+kf!CdXET2L~}(cK86N1*kwoo5ybR2pv4Vj?*cx5cH3KpL>EUjHyddk!DgG{Hwrgg zjYv4hgu3@%D@S8Qu#&crpi#pQ1P~|s=|@*!HSvgbX}zTUQ6}A0VVv{P^Il2dJef9N9A%-AAS1=BNN+&gD!5oci$=Z6IPw${Sd)1i?4>? z#WZd@8{!=Ha(-b)-9Gihf0l7)ca)yX1y0FTq%PDCBLudB!ZU|!Gd){0 z*J?&PEA4sI>eiXs)JmA()vrC&dwA;T)L%(ier-me;n0%)_Xi;CvBMOOR-(G;!JuJ-bo5`m}k6-p5^M zD|LO7jf;CEf1*!JE4wMl8;yOaI&7hRkXe9L{H>S)eok9YAOK)5O|1)h`6{WAYcKX3%t@L??f z^5#S4n=08}6m=@HPmY+p*HY3SR~<|`Z9Tiw>m*kx&s&QbALQQ?Z>3Es8$j_bO+3v|sgMyWstP+ffykS5 z3rh8BYVI9zWX<=*QJM93D6zCgbw927uSBsuS#N3fhMX}rHWpMd9b0>Di~0ih^|Qaf zu9BSrc(S*bh&P($m6W`FL!=MOGE-WT{}wBaw^8!L#OXy@%$w+Ft%z{lglNNvV6Bi)v#>zhGczAu=ir7o{=TxS zA(8gUU&jP7^SyX6NpmaxSZw6!Z0_H`Q-VDAw_hVpp>+8zCqPy(-{{T_e{TXMm6(oV zYfbjLS#Ez{jLvc2r*#8N0<}FS5)TH*>PRH{{&-oMChf`~fGOFMCm~rXDPAZltV?9# z%F)BfT+4bKpe6r6;MEl6>*Df0VL74b9t_`d{!KR8A=b0O*2{{$n+QCe zMTbys;q**5vU|+Z+L<$R_wPy)-;f{{!qyfVc$a4iL&nnIGBft~4=N}QaRSi|*Db|a z*-%+T#1PWwGxxevrvuAEEBY;x6XgnVI!kF5OZh6yiVtjhBSQNWKv1pZJu8y4+g@IJNOUHqD5S5JA8!7_s|DsPYc{Q@+(rO_2xB* zZ=e%5B{pKLmWKHK(5zAwiy0VHR8-(`mRHtz;`7$fP}#ylL`$pZ?Btq*!x5V@Tl#yg zCGoiGFQ?J$w?7B4yzabK1dN0&h}(FtJoDX_S5lM>4-8s!#MqDOnWRbG!?Q5gw0Gc3wC<8hz?Ol}hMvE7`eaGtF}}%%ywsfPjMPOL zU4@2vA#2YkxK!lSlmJPQQ9*Ir)yz!8R?jx+!_rIQk6QP%gr@NEM=Tk7A$EjBq^YrS z@Dm%9y@3`LCM1LkZt1~yVGeo)h0m)5tvkLionNwaKj``H8u@w3`Z+0fan1gxgch11IOrQfmE*4hqvvGRRmD5W&;5JnGNRqTe|0(D zzkiIuhrT{wP8#z`V_xfsv@Yq=1=h^!$J>-33u5LG%V2rvzHPkB$az&woHTGQ4sym^pt1@w^ zGO4SEkw_?vKXqxbFZ5^r^5J>qbN}mxI%;p*QS)u-A30@;wB`-u5A+vfZOr0Q(D#y> zQ@(k9+@6G>ZEtJ)?0>*)dn(hUsNN*mKx)t7MDpU{ci|%ehocWdVFGrt9UbGOGNC_? zbnlY(A#TJ>OegHmKkoH!{HR=U796`Gt)$fX?N@F^>htGDH38XPITO-cs(WQmgMzqQ z$ocxJmuXS-b@dOg#|@O8s5OPB))EL?>ycVJUL$?S=hs{2vjNN8C;1@hboP{V` zB)rBIx!Xs7H+vjsc^D)4uE`t|7nc}@pd*kffp90e*Hdd^vRqlfSDZ9xXO)FqzjDn%#XQN}={|=z<|D;=4!i{7FzDiO zmC?`$kHdYlwwK20Xe3Vd!$sz)%?5v|gu95#O(!wTa1)XVFJHwGKU>sSGTV=X77IcJ zgMtJfcIPK57+DiU7*H`en4)Ug*huKbBZ!u#qE{GsU#X~s2jjR+*t};wxj(2;)6yUe!261W zfS~9#B6T2-VpK{-{XUphHDrz7XDGQU^ZTvW1r5e-RT^=*8;;JBY<{jV;!+uJR4Yzm z-p?3dHI*UQ(fKfwq?$RSl+BpH$d17zQ8AF3WWXcZv1kFZjP`$;8*>T_9g{wj9el<510SMF%rY zM$_?jSM`hj0lvU1m`+D7cL>(pJ%#4z0zs|#2pi5r8N2EnDPN=4gNA_N}33*+kZ9r-Ojb7(wcuu_HL+%od>iv5&1T2JC z+||rH?Y%r4J_?L~K@n=Y-Z+U-Va0N2CTs9UlwVZko&YNY2RHe|Mf4u-F~-~;VRdhD zJl=h~?9~1D(qvf~pJv_RY-brX1VXjl$eO( zkDud86ROPLk=4Dg&Eb7A`9zC*Cg?n<=iW?=g`N8>*2_&2&u1z8h*Y68{YJgTasM*Y zByB#-bJ3}pHRB;t-6=F2(xMqxi=wzLXNu%|T2`f+3_IpN)nQ7(urvwZZfjE12{bg= zg}mu_fV(;-g+LiQZkOu1sVlWuj)IOJ$7t9K6;OcQ3}sMxI4IBoYsPquAdLD{Dd>n1 zax0bupH-?tkD;gi*sn6p$h!c3&|&+-$EdJ@ zYkPZP@{b7~vUE#fKUjHVz|+>fQnRb=^zp%)uB**}%GQ)=M$TY=`?xKj{M`Cn@#NSo zd;OOAwHqmj)YOzTU!vG&K5ucbX2!>3Ib}R{wq!gCt+rD1b*3ab{DfO>iFDi)>k4RY z_I^VY8-^RQ^R!MRs(Q$T1drXte3?;X$Slcx_`Q3tLF?98Fy2=8+4TS(JXR?XAX(Jg z9SPp9?BFjWDn6C5m5}hxOY|aAQ&tZP4W3@L8||J^x{|i#r$+K|ica_Ud1<*>v>RzW zy-N)-_l&Ab<^o3NpoN`TT55{V-B@z(wdvQKQY@k^-UjV97ZNO+!|ZyE{NX8(JI1pK=K9X~_*~ZXr~-T4XrMLf0+X3O|zX8nmI_vvh-`8v8+?6{g*ygKFl)Y9-P#Cxm`Ylj`Yym!>F zhLjyKc=|pCt;t_mBCo)>V6r^!7&aUXVeT7Vv9pLVU8(No(9v|x&=zqJtjY_JKT?bg zsXkL92EjPZ+-YI}fE+FnFW~AR;%iUHcm-+t{M6hkEYC;@ZuHHE>X2maMl!@TqO7fE z-fWZIM2t9itTWqPoQPPaY_EyWq@Z*$TSjY7A72w=*%zdmW(T3qHuP(2w9u){;JWHX8ed41%KTI7D zO|ABIUc|f)+71Y9e<9Z8AV|X_6P6trq=;};^q zV?E4eu{ncL%(|k_v1ZDT1Cl)GBT&>oZlTAeMOCyjSwxvGb549eBE8RO9hJIt_@TPK zs1Z|7^e2_vP))2^*5|U!1l2pL>Pj-w@_2Tnb=|JsL2b8u^5UjimzaA26a@AZ65xKu z#KcZQLQXEyqWSpQ?@-61fdHTN;>|2`+mACl(=l?AL0q$I6GldeHwHz#WLcEdUAw-l zulB_*^} zB955yQ`ak>91oGZ6BQhN4{sK+^<3)PiFj_H_V0Z=xY@_Whk;k#dB?LEwqWYz=j#TaJZ&yQpYToGp&gv0)DAW+unc+grXGDgBD(C1_hfYHRRr8#B( z0G2nBP-|>l$R~=Fjrj9!b#n*`<}lL6nlB!GESc!iV~+Un;e#rptd_csX}MCfjP?+l z-X>Z*=Q;CEB)1%Z)tGx%VeT6Z)%Zy5#!Y86ED;qH-aMY}Fov6Lb31=Uf zq;0*hqrSh3!B!iO8h8UDO^e*;^$hcY-UQc-;-iLQ+lJD{*pz`%R&r;?F)^>Ch-hrm zJlT6JLGR%`t(8v}EHWPcYI-narZ+#za8=Tmkqk?VB#gS)!K>3M_UwSaVY1+WU2Fa2 z!Fhz|Qr%AuoZr}yNYv$_st9^idh0XwE~BcnQdKd*<3kH|7ngwvYdf*7XQ`W^RP`Yhhj`Qfjx(x`g+z zjAS;a*mFo0Eq7tIM0`ALOgDToNi|(?F1Vz<&Z#_qhm)bSVNxqC$0?`yr<%@6adVv$ z>O^jtjDCJu&+9(HIW+!KjW)lD^XGOW>rQJG)%8Tbv?7i?;s1f?wHgwasQcXVKoT5PG)8omsb~rvKZMw4xMkD^p93 z+?C~aS?idrj-NL)(a}w>)C``UuIU>O>3vF5d+$a1Pf;f3Z%H0L#3rlN&CM&cHJ|zh zHO8noae2J+>_3oTmN@rfvfNL*OXc&NEib*zvgR?RI>E2o(^dWCua#63uR76p)q(Jd zro#fZ?PX4++V!8vjBspzRMQ*dDfB^CW9xN&RW@~KB-a;x#5FDc@y?zn`t3}gb!R*E z0}a!S%E3{)s^Ts7U#5ko*~L>v>?9K^M>&;x2WfUcy`55eu49PhzB)_Pu9P1#tJQ5w zpspGkKFnd0B{K@%~p*V(w z)pfg`?-t(03ClFjb)AL!f6QO@3)Kt^a`cSN+f@-sEc~UKqRZ4b^1+XBE@4>oiOE-5 z@~#R!F`1-OS$no^F^PK`79L8+N0}viQ%YIDva%qd^LV~=DT z{Aq%wUtvXej!q7nE!7A#ol6lc8AJ6^9M$9{pV;Z>8Mg+}Tw7iy3O?=eYE+lHA*@!nL{+|RV2`s-Id>LxW1s5;lt6#TV` zpZs@=!n&@@?4GiyS93QF^nt2Eh`))pM_mPn;bb_sF}aX`-?7xk6)`i@Q)X5BoT6=w z7$s{CV%pt`A)Ku|H0-cz_ht%wIBSHd34HP{^!Q2}Scs4>N$K)77eSRkr1mP953^b+ zGAt_Yo)gQDahn?*nk$jv)y8{-5v!wFdAo=PYM9Daw>exudS&z$#tP7dR_L^n|Ij6N#$EQ~o#)DbI*#?uC;GHI5mK zb@@uz=489c%P9rL<1SjSy_@itC}Claameu&v(*>PBddE>?%BX5@4khtLy|Tb;B&jb zBwk3QbZ^RNz4}M9#e_oJHE~qiDjPCtN*}JMw8xZ`#xV8@G~8%uX!Jh5y9WhS)^|a+ zI__^I4B6N4^1A5Wmd4k=RK=Zu7T}WOmfjcF+MgYIoOP%Nyf1PoG~Egryyea%!9S0)=&ds%Yv$5f0b32rA?UlkFrb7dP1+JbchI?ls ze7`nA!XvGlh^43cP0d|$bNORdb6^J3uSBcPq5<&eQ&o_iR)Mc z=46V^8Lgf9NqajLbAf;2xMzdvh__`?rG-h#m)Lp0_A@zA}bPBvcT;p8PAjYF0SQeg|Ta;a%z!xW1}8z z+_m<|$l&{~fwpBMGQtw=|5j2`k>BJ?NeAaIt%FyNru~KLNxF0i$MUrsX9ox!?)pkw z=;45FX%ihCd1%eYxJ>>#7#sJY%l|dD>A3butXqq#Nq7IDBlIGf?1gyxF^*I3X32Fw zSyB~>Hl-;ID4S$obzIBq>!?rNT>CI5F4|W3NFhw{8GGf`xG#SgZjv+iHtks#1-{}q ziE)bifT4V{@!Upp2{*@zq4CwYxLISQPs~^IEvv?1!Kf05tz$=8B@+Lv9w23?oF5bJ5I zwU4uSGZ;U`)~aCIN9`-#=S$~24zf7JS~WbvBReQzP%cnmg}s&5o<wnz#=EZiO{YX1}aTzdy2VTBg;iqf+$ zxIcF@Y$m4d#VN8m;{Rx9$RCix(NfVs=>HHX?Upl3)K@XuOw>;|!!I}aBx?CJizXw3 zT%!Hf?#({i+gw5nDpp+^Z-}v7JY9ri3tgr!S7=5|V==SXjvdO5L0UCJX;x`+YO8v( zUbH{9VZBzSy3BTv7b3~qB+jXnP#Ep{W4TS8y`HMdHvhk7w4kp8V1v@`J{3h@=RaaW zrgFHM*~^b{J|No|Z=tjS3TP92U949h7VU8b#^cJWDk=W@`kZRAk$RpeyWr>OB9^Uy z3F2jb(EZ@4UJXfJp={?;5dr(ptTon^ZKHM(VO^3j1Wsxnx@0{jUVa|Cwmx8?VZC_V zf99CHzv`d#A@48iIWAGTf@lAOYyOtNaHCs-ci-d}>5FjxqIJQd_pEhkDcY11WNA51 zNOPUGc2R3owjWm|&di(z_kYL3Itbjc#vOVP-uSFgFgnU^?AfxPYO~0wFOm61B_9QH z!>CnGHUas#wr+>UCUvlO*ZH(!YEZ1iN;2B5Mo4JKeQyiZ@VRU`^q2g(StO4~+h-PK za#5&rKeZiq8ppZ#14X@Fkw@9Xuv~^)X6PFcO;4jl^fHPDCayYPS7e!~R0n!aPWso( z-1dq`bGX?{_=y|X77bkUS>;PPr}fqq3#h_?dX?>I`as~jqf4ypDR{Q#yi7IklJ zR5A4O4rL^hOl=PK3@2unsH--No{;^9*3Zvw<>qDPJkkGg`5QvF>c>{NG4PZKMjEA; zUz&|M2+F#u`sL~WxRy2@5*~lD8TNE=(3{%?CvJTeUj!e4Vyx`A^$VjfC+jZ0p@gaK zPg5t#nktPM@t3q*ExBZclQS2HSI#=C-EkTgs9fnAj9Xu3mN;@{TnB8|Fm8V;dh=Ig z`AMp3#d-~)R7U2qe_2R8_O^$|4d|iy^JeW`xiG+z=?O)rWny<Qn|VS9YqL6)2e>VwetWjAp=cK26~nV4 zadXFKyB07a7CcTGR;NAh&bWcW*AzwRXcx-O3eBSG zGJJavO}d@&IAVI)o+$z6!{wml3;Z<#Czm%x&dIsQg2uk)QMMA_nwb*})ThX}npB&l zR69qVZGH|?8mZT`EG~|KJa&d97QRy@_ zPWV9cgw#blhf{pL(y2 za+T^CV^8)vl3j zGD{AaAfe7IUdqOKz>-j*?({>CdY~f$)KZ*XdQX*zhq7DPo`fkZ{N6%`0|w_h8Kk!XtBrK?r`VSVC!#TCDV%JAY?qwv?a!0(neKmQRTL#oDQ<|-wW0A zB4rg78XmnU)BlRG!`9nWcf1-cHHFMHi+2?332HoHF4L14@6 z7~0z@DCU*)r-3sE`c$r^I~?k2(4leke-2HuRpOxAmqnYO+zOrBeAAJUh@JlpVmDIE z?x8}$whUnb|fA|ec^ehgKZ#_RTLp=bUf1I5qo%~Tvm_m6*#NrLPV$HqFAMUb?D zZfn$qD$D6-9^-mRW&8wl$yE+%SAl1*9?aMz-5WFgW>j@PySJd95b@@TQ9Zv zBzfJ<5$~ObpAAj7vAhv?pEY$C=wN<2xi}cNw*Q`#=&o8u#v|$C%uKh?cmm?d?~>pA z4Hzz7F<5ndctf0>wn7zF@8!i#QKgIB&~SU(w{_cx-;I$d_si2ISBuWGq%0@T5r=Ea zEPSVa4=_wCSdHoh2KFMn%*qg2ZgbWSx&SWNe30H%{ax%q10QwRgm+`A7`58irU6F6 zy?xYsm$}G4@!PoM9_a>R5i^4jPrv1AhfiCZq$gTeZv>;ja6j&>EHZLhD%U_EOd2R8lzw@7;A*kYW#JLhw{<*W$z}Gl$;-E% zSxsKqO=jWC%x6s0%`m2gy(Bx?ZtQ8yzw*GQxKP!2Eu{}z!&fJYf1y+wZMxFaGiQN@ zFS@CAhS5Wh9~@;LWl^i=2@`3_Yx~LSBzg5?uh52aeIqsbighNK&Pq&GOLs^UHVt*q zrEk;}JqjiW6OYVHGq>KWQFjr9FPDLr#i?B)7uPFBp~(S$v5|PK;cGKhw$ioKZZ3p zczRoqySmEgNtV)ZOjZaB(Cy}^+XsilU5tEx<(n~jv&ZYR=e3lmAXKv%ZyM|QW`3pA zi3(HgO@~A8Am&dRg)?3OyN4F9_{;Loe(fy@WtX#BZ!|nHrZIB#(r_xs%}Y)7`itJ; z?$^&!cc>U^!yk+$@T$$0?`^1C?b#m|>^g=9U#VRJBcdMR22C&G>rLD5B*_IXD~Zi` zOX{RyT-Fbcu-PO{>O~9a+r}$ZDS0j2@5`DJK|qfwT}fvZ6r8oa6kbk zROhL#=cG@e75ZRFjYB8X{A$NoxV-xWpUs0SU13VH`vT9(k_zU{jyrzxFMZ;-6M>5U z8poEO_*=}X7ZgTPGVY$ALI2zNRGm5g!g=FbF_XMI?bj97?Cf-HjRx$&p&>5kPo-?l zP(%FBt*gdd%t=(z?)?V;wR7G+@?ZtA4Ahty_}8)SREIwE1B(Ji*o~Du_6hBS6{0) z@|pC7vN?II2acX((il|u`h~(2dQBizz-AE3(?0GbBIzJy?%46!NbQdNUg!Rj`Junz z9Yuj>J-hw6sU@?u^-jtMb9066RdwQ7E|QuDY?yKLB6CFM&-}B>9>uH%e{5i`R#>#p5an_;_+6Se$M~>eQmwseP+kR;Jtc9?=3M7D8Su^%)>H(q_ zX(&^ln2UEgaqU{o;sCXhU}@Xuu4kP} z#sJeEQ`Es0cZ+#43PHts7=7>HmrrPqNS{4(I%dn|IyuU)GNSCdt>K^{F&5+(dWO2T zw)W?9|MFq_9zBa~Sdz+A*61~Qvo_yp+sTQE{nHtHyFW-_btAHbBcx3)3^EP7tk?Kdy3gBR@;{smgE&<2`f&&rK&a;H%XObXJ_mF1uiyMB_wW@STzk? z7;%`EN4<6#aJ8}@??@sV6kegzXTKFHePN)wB%NJW^zQh2kJIAXS|(-Y!%&5B+MMRh zoa{Si%BfB0p_@Olge_dtC!CQ5!wJ4yTrbgwhlFDumsh%NDv{C4)?C^;8#-5W5VSfv zs-^7ASZ6TNK`|OiwdzeH*ZMWYZHf! zdouQZK=l?eo5aZMa?YR4I^MS83r~=%oCT6J?e93y-iv^mBfDa~=(ty|UNQFJ2KH=Z zRMg12F@mvDyfwg20_`n&IgVvhbxCzad56bsO0f{Dx?n5fV5_8Herh6e7AiJUPBsn- z=7FyE6MnB|;kEcx+@jebVe@Mf6?zs1M=L#IT^Q=Ng1RI4=%uf}365$2+vOVm3e%EA zn`9<67njLMx)uSAxL+9-%v}7@m`n$b?}gt)Tzib!6L#`)%)PyPeE4L2b-g!^enq`+ zDG!=O5h7Xe;PHOzAru*;`n8t0hlQZ0x!1B6d#&De99mZt&X0ewZb6CiZW8 zIEm{crlZYoUfxA1F4~OYD(jxW&&okW&e7g{CN1plE4@pQqUW0a6pc{h@Njd2U&(GP zEUl56Be{BaJuoG0plBVYtk(&TAzPLHq;Nf)5fqb5r(#bj`5D?c8&dC5_rR*4Fos1| zi|>u1j=ay%L{{KhwLafwg}fq{juO{&hb_Lrn<4^Ahq z(k(7K&Af>~i>-j4%6^PL7dt2yZ$!l2FJ9gaY)JE>VM|`Qd-cy<23sRPX4v;e#)Anb ze(;r*nX~mvdl3;jg3pa8o_j3K!iA^xcR3%JX^6CV2L;LAbX72Q(5dr3%nBS^d7q!o zk`!E3e|Ow`BL5)Zc?lY)-K1@?>Gzb611VDGh-;pn8URG)wktb}TJ=Op;U>sVWM44& z6~zG*ghAg+$UY_Kfg69nWVt^NZ7}Ap+*XMJB21UXoa2Z7#4ZYh?d?8V$_N)XZh`<4~_W>SSsZ)w0I4b#@qwx!cLB;;1O|3}rHBu&=xb9uww;gS!=b!Oq4J%@>bJj|B zGUggHX;eQ))1dg-WMw#z-E$ENT2?QsYua-VFkEycrD4tDFfBa&+HlHsy~ecr*cF)B zIPrMZ(;kiPauiOt^tkAH(;_>48isiuPZzAb7a$ev+eDL+9T~K)zV>_BcQfV|JxR&y zR^1Z%U%BjOmLZl4Wa%6A9ux0*7gQM3sEirz;IA#H*sAvK%&igdKjOp^Dtk}#Ampxn zi{XUBNik`5_yhVgtF+B7V;ad<)|R{ObM=v#9^OMe`p;z(^S*rfUO#5jv`~&FWkAEq z6zSR@SJAhrcdCs5Fzx}eP#QV^-E@?P>W;uG?b;SC+-#UGMJl7NJ=YWYQ9+maJuWRr zR^?*B#+P4@QsYS>nx^xqRYfxuC!6(*$eu5={g9c{Zz!OVt6%5b!r!53 zVDXXC$w^tGKiTJR-<m_gCE!;GoJ7=oHvBYd;lDBDTIDcSo^h;Il_z;vR+74z zXopy6wVG<@$YHxETjew&m0wD@V;3MNnIJZj)c+3}g1X?mcgwE{XNo3wSd_G4iczo|N z&cp%`OLO8oRcSlp+?Yq_F2Wk;l)XWKwg|wf3*^|N3xBikU-B)ir6W%f2A5HkiO4x$)JzkdvNuQs7i< zCXK1Ltc-(MauMyb3$M@@3UQt#2Ry^d|6640{`s!tRksInXFFe4za_6;?wLH;MpL2h z<%mj*$vHobFmMXv`J8@gqvqnf-}T-?lF4S^rPf~6>@F5g+c`UX?0v!=DR#Z&RKZe? zUA?raO6vGd?u|;@Di@bdyv;Z}>;8nMkLNbxd%0NA0W4aGjcZT{njdc~)2Z3JeRD|0 zD5Fiv4Ku;^fLECf)>V3$lc@cIlii(Jk4T(hh>yfqc6)ZUp>L$S(kzo!{8;XumIO&2 z{n6RZ@^d~Z?;vi^5M~q@+OjpjSax(8%k$ar)WNw~v#GyC?SxIERrptqI@=$xm_4wV zYEe`)wMK4)3YD*`n7AmDL9ftXNV{3MSbg7TE}bGEZ*{hB?iN?TByF4Fok2#%{#QqF zCt~;BQq%Xt-zFt0`=XqY-@7$Z2InQ&QYaQ#T_51eRr8Jh6 z9kOvM*paBZNb9kvg3aa{DH?>G=}%YvO9J+IC-vu>#6`RkDu?&7X|7CznpM}^Anu_y z{Kt0sv#|)10{?VxTi#5*z4WH&^M`)zgy2{BN}qpX|LST^ifTchxzS10*$#TYcHX4V zT86fcuKS%;;w;=qHp@Ka-SUHb0w!%rVWplK7fk!`V4pY-^OO!z`Lsm8jo7A%t>{Kt zmE?EHTW*RqM>}Gr=9m6?M4ge0bP7|Zger4A-UYJXVX3O!YBOat`xAXHUV3y#;rnph z9*Hb{*ilsb6}w$G%kk19;q4h+*8@R3@^Zgv1FyxcnZQyB6&_=S$`Jqdpkg?QIzk*q z@?~*Vk6TBgt8LJ%`TLJd^M1*qSUY8b`V10PRhF9b3VucF<;%a6#_FQ+ZnnGL6e3Z6 zSI=%JbLX-yJb?I6*#v|06Sjj_$vqdTjIFJGOXGf4JeZilw+gtBLc3Z>TGgLk`FGRe z#8oqaxxj{&y4eE4tX3h^%egkcq}pc~Hq49Ia`PyVLMM({}GTTr|_UihBMZB0DyZXt%xDM$>vE4=WZ^G|ABc`Q>;XN3nMIOSgt>HjQ~dY9b>g@lXM1?p$($Wq-!l+L(3u{RhH-wT2{uZEp;TiEH7rK&206iCl$4x zAGvlCdMNpF=2`_Lv;Xo~;+ntf6s5uVWnJF2`OdT|I49+ zmU@Gp_ii*-8FQDCCSuE~%2NHYi#M)hIR9O)pCB<4n0P&~?ru^|trBM=B6v^e)0gzZ z{$9x+*DTXKbF0=TEb&wfuc{E2BvyMxvry~){9#ERcVNJ`A?EkEnbSat^I-6JSnDIh zv`N81Qm(LXq2VOFY$?Dp&q&i@ChkY{q3u+%;Ey=A9@E&A641)$brRU+nvI z#TI&!21L6=xGVPkA~RTtxi>E>P`^XXH*ri(RpPcFc9^!Y;e&rCQ*Cfn`r6=e0>P3A zQq}flN@H#9DnIw`fskr!v0I-do@d9)9uurJKSADK6E(`-YVzHoJh{a77M!Exw_05@ zF`etP=S)rdJpXyZ0^@;9P3J(9{>n?%$-cKG81_m^Bf+fWUhSU5P{qOs-ND4zyeRL- z!1J^c4I7)HzKanwWvk->om*KQ4PEJV>uF2MhZ|ozbO=A3(KN$*FF%@ACIw|3 z|LtE2Z~7#)o@fPV_iqkX5m$RJ`ZVRdZzZ^53>ze_y(%rcWS_xkq%+{el4MNy&9UZBb-E+K#QCMeJN<u7B^iybUM|1slKRR^6<5KJwk=nW zy!U_E$U}#O-9nel&dm(SHP<1~?Cf{Bv*>us@7zdZVl81}&0`YGQy=n1W1n3mPrxn} zy0CO^dJnYkJzS8|QAGz)I&;V)RDNs{4!_cu@4;RVTH)ySrCL#wzkS=Yuozor=P~0s zB(r89H%Ij-YU7lzN)@h8zOAz5F8848NLs@~`^B+#M6kQ^tBHbhAq76jdSbF05ngvT zTAkUj6_1_|R3!!%Hi@g61TNftNoIb>dY6U^5pXvkv)L$qHPVGL`bL0nx%Z+Z~yY;)Zu5#8Q9XzZINR-3GD_I<>=6rql8&_xH+f7W8UG6&y4T5sVkFG|^J! zA!EwNYZW?)?oefYFLntQjVc zgM&D}V0j&tF^(!&Naz#tn$-@=K)WmKDsN`U6H{RDd+#(yJKA!voWx#kwq~m3T{5_EaF&v{wh33%-da<7c(=a=UI!M$Hu(aQWW}85Qo) ziP~w*XRFt2VklG!PuUH=r_i6qVYAc`W(?4t6}{SH5Wc_4X)O@OB_>~CaQ<(7oTc4 zPk698s+Hs}JCgBvW~eZd1YA#?ZyP`pZb+`zB788qWNXUdWy&4aN+`XhIq=%+ZrHEG zMYTih@^;_)2ScVBc!lTA^`LuqjrWYamw(4uGj(Gd?w~jS?}MsN*3IJOCieKW?ejVG zE=%!uRhg$`$nU0Q2#O`QcDeN*?u48Abgo{SolDp)De&0VDp%v?9&9(;)-7kCUMQz# z39&Veto!5fGl8CBZbsRoXqTGBsh+bqlW85KU}?RJ zi5XE3Cu0C}YuBNgFDg6ce&Q}|Wu1Yh9c50qRIc93f)R97W0k(lvTc#qASaKO<}H?* zUDheP@|sM+hB;`yA8D=7(tI@7C5}l5TacVh)q7Z*fjtY)q|NJ~jz1`{gT|s?{TztF2^ymEtiR zi)lk_t>rq=Y*pr6=N`%xS~{p2Yn>#$Pu$`n$U2V6D@~b9oiME)&feKj+sG@@Y5#K=6MG1xn`XU`;}LcDL2GH&%U==iGC9GTbgn*B1sFW zq^R|%pKdqVqWy|)e$eh7Ui?qKEo`cib-+YP#?S8OX>f||U;a0O9jP=)>@t0k>m_Nh z`Fg?~4py^GuY{_;q}6VNu$352!k7g|b=BLdzfmQIF@aO4ByzR*$vD?b-^5K!Eb_;` zN1u)1tR6_(oFofd(d_c81Urli1tqC6n5vWRNK2@5vKWUxEPvX}R-CTvUp0`u+nPG| z=A{q;!Nzzcs$@S+AtSAF=6gG}E(bcRtk+;6md~|-^75Flzk=WEKTgXvb|i6Y=+mF+ zC}r)(wq1_x#`nBRGr{4am|-9A2R4}=gFdS(AukRoNw5kV>{YNuOLzy z!@W-aMCy2asu7wgW2%l(Z8TS-s($HV>HDa%YxK=iBj;1a4R{vj zPlp?&*(TD|BD+SdG&@n;%Nvz1SBEkzxqV5(e#vDfm?MW%OH#|;W3{-Cyrn;$T9Bh( zp-mDJ;mXgg-@?$X6r<8$-Z5lZu_me?rMOOyv8r@Mv%s$C=PRd1`(&s7Olv+>_e`$v zAWHXj?;m?=v`%Sks)$^8o6YnvnJ2@)KYep@msp5BeuKbf9A9{Ej#1&kNebg#ee)d5 zV48EWQru$bqDxP{@fcFvyZ4V>;Dp=YYP#7>q`3fVMSuRx#>$+;bf})ssDE?CXBNwu zz}iM3A=k#X_-zxcq|#Zk5>`i3SRMR-Cpo5~d^tI|p6&i*PUcSc@B7GS8#kq0N39>0 zvS5T7e?WDGBCoH+d0wMcX|7w`LXo0CRBQC|pXFO$K$&44xRFi}is%la>T1ZL9wVJ> za~3JA^i^S!m656bXk$DOPAie8oK{X#Bs#g3tXvmzG=<=#Use!JSycdYO>(cPbH1&$ zt&&>Zge@nsjMLs}k4DI5eXR%~k(Y*_<*$)fCPn@a7ukUfK`Ng5{?O5A_Crx-^jw#C z?$5rI>dJK`C&~xEd}g(i=gb~ofuhCPnF#(`9F9lTL%ZM?j`%4e&Y1ZXu!m!Gdh^x%rCP+10Fy#a_(-W>7&^1;_!VzI6vXITU+{r zih)QcC!Ygxrf6&C&Ci<>ggVLB%0{_n=L&n(#>#C6@&3-eD;!cXcUMFfMrPop zW#%E3v{Evwq+JR&rwZrShxRLCD~9G{W3%VyTR=g##kX*My$hsXy1IUchN6D|_W1S< zaO2zMc9xB!Uga+Q+>5rdW=~YCW%cx|AL^;tKh!g_e<*3BE-5*a^XpfPs3@pOo%`a@ zDNMI4F7kSb;1JR1ub^{KKJ`kjyF1gmnlg(^)>*bc;jB1|C5+X0ls3Zr;<>o{u}lw5 zvK}f?7Qc#g`S?KIHJ+)ql$T_z<(Bsg14nW3%zL$=IwoEqJ>_+F9KUh23L2k#~)3?-^25k{*+K%UF^Sz?!Nh+jVhxG z=|?ZSRi)~tX~W8I^*X2tCwg{N41wYSLBPAHcaN*7u`V;`x)YmKRUf6d^5=hT!Iovr z**qsdk6^SqiKpzse_2a2*|cZ(QQn+ZepjU#h=%>>UTe^pzQ7j8{>2`-G;}tups}d^ zYUQil4?REJBLbGH?X3@Y5KisX11?iv+m!c868Z`@wio3j>?{N-T(C9fbDNghm3DRO zHwrx4ujYJ~g*)IXGwlwmb6-4DAbiuPx;rIu zWBIae#($+e-($NvYo-rnxaZM9Vcr z^yqOepWcn(qJhzAGD9-G&$!#dRj(TFQef($rOmfYS;jBPmYCdpALaNY4L|0KIwgM; z74mE`&(F(ZeIkR>hnXq4;X6e#sgKwcJ^XGbaDB0sKHQgLsp)OIN-DPfJF%IO@B=-h zQVod~`6}HSy($O&m-?Npr&AI9+*b#R7r%yc?QtIzS*#ceyCs&%x-TkS)!n$6J5aPy z)DmzC5rz}`J8FoI$8e!%-$z%9<8`T-5NhW(6^b@@ona*}su|bxXDE7OGQmJ$TqfOR z)L7Hph4FuXtNUYpl;^Z+x9ZVT{Tb{k@qy*^s@-0}Y69ZPAg@o+*K31&G{Tv~TFg5c zC@c%#FjaRwPGz^wct173PJXp$ma-3X3*>)rc49?VT!S(Dyf4wN!CFbu=e}1SDVkO< zEkYGn&Y0<-DT$D0Q^&J7?ECLDt$Hj7KTK@v!zX1KHz>YLEAs-}ojYv}FyH6~a;Tu9bu>CywC4B7&}MX?288P0=(hb}Ge z+1xL`6-$VAIB`JpCo`5RE*)@p&~%p+HkCc=poZ^UI=AnY*YbW#shCZi(L4sV zjE2Lnk`cEa*N#va-EB8O)i(ZqOEMPh%@HHwDXhS%q`46#JCiObq0-;;#6$RTI=6lP zR76bmXl4l`A6KT@dUur{{e^$cL`dcp?Y=ME_gy2@7+pBn5tiZ7hv$h7C|G~mOy&HL zSX+`f&-Uf1>`D&T7+$1uw=B718swBoZn0We*)G zcQj^pB4_s^F-|ewlp9h0ElGOtg4+H4xH~R$U3Rg&yr-D<>Gy~E+Suqa$_&2mZz2DT zOL^O;+AVN&1VYbBZq5&u?`NgY6`XyA%I5OUvAz_uz~etFEN5~O!VO~XQr$7)1?m{r z@)^ZtH{R*C#lr6g_Cw1ZBU=Z&qG@O7j%q|H3ps%t9gm&GlNc zH{8cpctTzU-(VS1=Zqg(Elr8U&zMe zuSS{y6I9Y~j(1b{CWWhDJ zofNLIR`bWTG(dC;=>)1XH1~UH`A+{iD2qG1M{-Obm(zB`trkd`;aY!Bi#)~^W1tP` z*fOZ};`Za?ie$L|!tKr#fBH?4$3k(93;VbknfGU@{qIj5ja3+&<9-X;YugN{l$3nU zLRm${4gdkQCkWG0Q@0WxcRhhnmH(~>YEm=j6pzlJ(7^xEm`OOm(Fs1wG&l8K`}*L| zt57`$FR}`|Ij9hG2Ur8PK4f&~Rh5)@LN1fMN855jW0Z@Tc)J=Zv2`-Ba2>AjhEoQJm(dITQtA2?oP|7|~+%<6C9`jUr z2WMm82mf_#qf2Wb+IRlci84y*0sthy<$*0E4Wu$q6OV|FZqnka@gedJtp)-{y47XJ z&G}NBIW^o(nl5x@gn+b5c(@w$(et0PhqO<%;s$8F8(0lS-ZgA{QSG1$VlagisxLBo z;qK>|e&O^d!CPQCeF>o-k-~KI=Gw*vXdP!j)fA-Ry-9B#0J#;8o+c&HQ%2pPZl$!h_CTk0{;kmmgSVyqUluK3KHodx9HVvIoS z(8kK@CKJ;~R?H`0NCLtJcTb=v8y6cJ`7*P|x)<1h)$lD~d#(_UZGw)Q4k3+zmTcgMAN=Q_*c4gNotI8--4` zw%pXQ#Vt)uNr(Qg{D8fL~Y6-zo)lI5rYI(BAZ31~wgLcDCt^x~!Tl_aqD>e`s_|i|jdavB>)m ziBl_~fixY3_V*!UP4YnFi`|2BOiWDQJ3B+fB`qV5p{qh00r{jMv!W+`H^j*M(~SS; z&ygzV%|Z(E2js^o)9^d#CZiX92qmS+#e_J5&%A*m9?n##Fb7^??q)GQcm8|^p;qau zcWN%z43>Y@aJr@V2?_`RBm`K_fZrVg6blHL{uBjO-_-%rJOWD2nYp}b*QLrWZI=yI zj;oo5Dr+Sy-o#TU9~P6nBC`}qe7W&AD;_GgK{-m18_;_ z%wU$_PS7$$k}!GG+=v!us{Ne=x^joWwPdchtXOFP$`KCZ5q-SV=5>;s#5Uk^aK8+Y zzRura1}UIQoahmJ`sa7h+xlT_e0vUUKue)HNPzhIeDkR7eKNB#E6ZFiLU*6C5l5_BKho13Wn~x(P8gBJV1dJ zO$>aK$`@nz!OUbPt1JVT6lBe-gQ6)ZDdnR%F~EpUX;sTs7Zn4TM2@vmDr<%UDIel) z2s^Tj&D`8PGtb(2Qvz=lw5D{fAh0vZ0d0~mfuj^HE$wR!y11M-Q`}CkDjA zj9^8@o}pB<0eDe&X1j#~Ei<)u8a}6HEmI#vFZD86%zHUUvn0|wk>2g_=RT^@qz9#XDdVIM?hOfRNQNkS3| zNW!8(LV3JchWERua?Z=oeAj*0s-BLhof-h;7dKtsLRg~KL7^g-JK+SZjBn_{OAx#@ zYLkwlkJ9UUYmmhT01lXy>D7Rxjh;FHYFOy*XFMWn8yhK6W7huU@NhEfHzy=ZQ(1v? zVcaHNV7RKTf!aqmSc^sbZp|gGGXAk%!-d5QR~IlG*@s z*=&ESK7kCF4j3Ijb|g#r%F0S%6R5P@-YyI$!+gF7$P41sJ&?3YZP}dbwFC)o65X;! zpt4~BD|HExQvSeW(2KlNk|J+{ZQl6U!AXSbx$EMNCG0Bu*TrE?s70%x8-Uc7T7UXH znWD~sWS&;}CYU-`po7Vl(pSc^KR;s*{HW$D%&i7S+_G6P1^hPF*Nv3!gFyWw9T%}1 zQF@W5B5^w;P%wOhY7GaVQ3S>u3~aaDIVfH2oyKjGXo=EzZgWajAh&iV6$WuspB(tC z?=$m(h{oR0v1+Z2zwie28+Nc<5gZBR8vrj8yVUjR(;b87XJE*K>G|+mjn0-mQ%+a} zID)6|x*yNT7oe$>GY9hAK_1YvquHM~T%n>WIBsio9v}bd$f%I*yt;I!*JZ|Zg%iBi zGl~P-AW*;|UIw(pS=cb+9f(fk;HaaR+QnbLzFxtA__A^A9UdMxF#SyN)|>_&Z@NPL zMN}h)R4?h45lZ@o+J^R@{(gR>Qk*3b!!0MFp%F@B#)n2Htv~G~juPu&|Cc`ycm)Hz zlqk!49|>8xxsc!ofX(~`XemP$rZuUbum|pKZ+F}Zw@vH^hwEYvz0l$Q8qP{@MC`); z2UAoh|Jms%#=ACEjvFkGZ;~3H$#jE6CU?u?M?q*tjY!+M%6yiE71_if8!6%==VuL6 z8WMGe0gsfFNlnX2F->W01Z;XYN^j&m(}p>aOvp+`LISt|Q0Ugwu9hc%0~18a^@gH{ zF%<`rFFH3jcc$YbHT*Pr6aLn;WEz04yzLM69Snll(IJcqO;<4WKI9qIApbtKRZAkP zag{?4{|D=H6f7H`?PE!!Jg{$m=n4NY5e0~M;O*Xs-`QYK>HG1+i{QmecDa+V0N&9+ zQ)|U*@g_;?Jdnd!roD1x<1d||fOh|=UTxr!-S5;PCyxL!nl(^V!52iWK+d5%!uI-U z_#-;|aY4F*Y6wGBp`@x6(DOiN>URpKyzt3kHs5u(W3YwY5zoxXpcsh+?R>8w^wrSf z-*=GGd?~)!4ULVSsr4i!u${TWE9cY-XGepSdNglPC|W;i@h#!~nzX^!uU``*#Br!S z@EEO6y&3@Ccwk)zF(l3jj`qj(th}mM08;L}`To^I`M&HRM0 z0GSNyfH@PGkU%~R;s!<>Xb38)FzU>gI!&)M@*`8 z=%Nl!F7u-QhuKu5*n@pb*qksk6eOv;U@Bi+GkpZTcx!3WMG#JQb%8GYHK7(9B7s>s zHLy=nD%qStA$}eRsuCaRC44wp!=3e=jUV@Cs%E9Xs5(5@qjgy)Zgn&+doZEm0?wmC zqcd>JjL*qPJRdRnVl^$FSp&{0=@P*JL`^v3$;?^f;)qCjeF%0j&*xhH^*7h+Q;xyR zj;4=^jC5Z8!I)RIJG(qqXWYXNJSPBnMQ6h17A*4?Xp!pDJj0J9CGi)4hJ(ux!^S0- zNH1y8pB)5yQ_~dyv@?(@o}(0t+(C1Ae@aZemc#dQ{8Z~lm@|qV8K>+P2EvLHwPqrL z*|{E~uCA_FnOff2(eZIYk(ZEw;9bxG(XV$w9GvA$6exdG``26C{7j;S3jFgow2Amm z+(D+iZn`3;5Et!kq5uk=Hb(TC^auRIU5WL83Ydj#FnIJg=;%b8uMn&78|P$XF!wX( z=$|o`pj=;Dd#8 zIT2BSTH44`GeT*u9x6(HSmjQWdDa6V5x z$x;3E!~!UoR4dv7%J`v|`CET~!tRIO%eh+R*NKEMH*%6VmA=f+&!@NVS9wXw$aMDf zq#gs1fFsV|(Wm=?dYM@bE-<(thTI6F*mzbFZEqIpSe9FBs>HIDsV-3nMc&jJfT**~ zSxcz+Kx*lmk1@)(cZGbD^VlKy*&hM@cl?2rG2n(*I$QXSk}aS zeqC`L&~$yLs?;7LS2fs=(I+qh+%4Q zOF){4n>y(6DQX-};~yXVH~aB#e_3ASLjHv0hjp`cw7=wN(=9Y>r!iP(`r%jB*Gpva ztS>;6%7lZJYy)cLn0DQHguanYem_Apbtv6H8ujL-JUr^-|9-V!F@6Il|M{%Ha9Lt| zg8yGV#4qjZ(Ze6R-8sue3*0X~+i(A(vtorB&o>~8@h>c7672i?{c!kveE#pbmuT`1Ns0_729NvK2A%i@oSZgg z|L+v}YuIRY5MkDmBtAYq7?!cAsqnx+MI9Zsepz(T5Jw!qHDE!KlarU_q^Ae=XJekp z$;ml8R}>UjiHIB7vX~Iad%EK|~9N zCF`Fj$y-}jUr&vZvVb=NL{|tz z84dQ}vjANVdVI4o3Wcb||Ie{@IPMo3RF;-lR<;WiatMpTZE6HAbtf9#N6Jb^at?UX zlDBZ=UvRnj`O60eG;Fobdw6&RenD?qR%5vZ)rOYNg@27d`#| z4)jE@|L<_jMeCm5xj0%#dhp918c||z87=|7#yaPDaT;-%`2b8FYMk%&?*nRv;`n}n zdw7a>GpXKy$H-Rktx-Z+-!bcB|6v6X2=lPC{wxglLOyxU>Hjo0%ez)6wp(x#9NgxA z%QRNG`G=P3^Zi#R@Siv07knkdNNYl@?C;Np`bz%SIa~t;-jn}j%>)4D(clw?yFH(r zmHV$1E>M5w(tev}84#>yJQuZ_y&oaV($MIqoi_xdw@=5;mh6aW|Q2+MyNbERNQ z?%>D&!;Sra^a`0i0r>0b!YK zoDSYUQoo_UWBl~UQt69HFXA5VNh_befyP@NkD zuzhRBevp*9eEG61&&Z`qmulk`_`ljAz!}r0Wf&R%^-EDv@oPL0V_`oeH?IBSg}l$= z#$0bdTm%3JkZtfA4k-!b`8NVkO(1U=;K`z3f6?S`ifZV`6K_FhBd|l{4T1&iw zX~#no5X+ypsCdUh<|MRmY}C)XDU^A>?wcmg15R^p4P-}hl)-H!OfX(%ly@dX=-W+Q zgZrBwEMfBvJ((J~Lg~2QA7V^kX=w?ol6$A(-Gx~Qz2}*W&Ik(OemL_w+}+pnrl?~T z_)I}T0NgEzxH@vbSDKNLano7D{V3`NUt?{I5weyar|SwRnYC8>u{-bKNG8|~UDVaU zAo&<>KbH#o@3FjA@!gUbW@;Eup>NL5o5NY#by4$e0v=D^`4Wpa9oPJ^-2#j%+#NMY zx^0i)+1c4`Uix~|*UwMF|LRV*_-;M9&ZoV#K!>%d8YlvgH0h(BH~6lst(CVcK$bhc zP7;#AO+r=9?iUuo(z~c3Ha0f&x2CC7Qqt9GBzfUz1B6UYZUTCMcf5lHZIL1CV~7+t z9hP-7sflYi#GM)f3n@29TlINHJ_6lX9PhW?1Q!LJFBc|C+{Fhgp~MssJXe@O3{UM%5DVEAW(Za-_}&N2&dhw;YJ4!_Fb#73pu1@CCxt#qaP-d{$g$r# z`q$7`Nm5A8!DNIl;xf*w0NdjEw_kgTItM8Rh){4d7RnzECvpEY&Vp}3>FLim-$6q5 z4DLfm=lCm*oAjr+Vg>6MIUe}6Oc1&r9yhj0nlP@bcI7N7G~$^ZMCs`vhWC|oO76V=h@ zHBXCYs{j2>maBh;=zoXfXw3e<9gbE&F++Se0~|Ih7k(ΝsxRSk* z+RdBIqobqXFSPXz4-2xeWCD;~i&a?rB7*eXJ4l43t)=*+K~V(6Cyb1khN;UnT)#@f z8*f5@ivM2#kK+5CkNHyb^H(5OW7OcVGA?%WW)|4j=*@i1?_T8JBx!|RWep|DBoDP! zVie*9jGsNbf7$V0f5lXME+{Y_cLkpgDiO5&wk==3(s6Jg7aJhpBrT;f252zkLVI$x z_yH>k#jR?HzV#FnTz4^G1i0J|oTC++wjN{YuQ31E1VWloQbtnJ>cQSp=Z-5xwtzlN zb>lyO-e-07l`X%+#}|kcA5}-kUC0)~FEB!m3zrY~9ZwDrN|LbIUB^VQ>ENnWJYl#+ zZw#40S*8Az;6lT88Wv}OOkY=e#U}O5=PAls8))8~mp?Mz>27q#Bbvov#2!BUUU|Lp zp18C`D&86Z7(?~%%g8jhx95HS91Nq1b6qZ8F^>5V5CB+KZmrr8D4RjrXnnpvE*Y{#RWIy{Wp(Y2Ua~A+~Vm5P1Mw0sXAr&^c*H?uvu7O0} zUn7ccMn7Bzzi{qnG9LD3^-2R3r&k(9j|1c2?$K?Pp|fS>;gJeL12fFs%L51HRAvLfd*98x2AK7NXq6HQQcYVZv?Q4LZJ2 z%ZPo$84n(v*`HCDuoD5o4Gj&rYk-maJ}e1*7_}UY6v)8nM|dlNiJ!S7H)-GTQB)-w z2Y*}m?NRGj2%3h62iWN7==G3}%aLsn@guTQNv1y4)xv*q3^-9b-#rrM!C#+6$y94rR99hMq?7j@cLd*i;TQMuCj zIoHxngj+J+7Rai$bKJ@5xMcu9Uu$vembSdgwaxV+_pQOq_!SE04%e^QtXd=cAHk_t zxh^XwH@OjG{Eo`l*0wl0S_5+NqvZHKXHU7F5G@wD$a>M}{HcjkZ!O~ZLq2LlHEXyG z6hk$|s>G$qVH7ZMlF0w**nW6mbU~Kj9;_8BJuVqQ8b9w#C@%uUXwEpuF7zQb){cZMg zg+ayaAn}I}1FLNo`ghiZh1A_#_SMq7g4a?GC=2r5%R7hUYM`=LSZ=9WLDlueLn)9^cBe;p)jrh2}SMgwo|cbE}HJD%7UI+R&= zR*+#g*-XpU9pX}7TXPxOnNpqOL}p@LU0rEi*OhwRHk|B6MuHloIHviVZY^L*)5vf!XJCp`J~e)Y7V(9Hcq@L5V;fT{cO6;ust3p%VB4F^3Q(zS^k_KH*nbQQ`bOu%=SS4b$l7{-aXAE!3FvU;%wt(Up8& z&~kFM=?-k|zx7e;`xo%>uW%Z@h=|Z}usf&4Q^fR z=O!^im6nzQlzqM@tN9c2$sP^o?)4u6&+{Cs?Q|G)hD)u|p169Ysv~Ytr)24~y?L4{ zqBw*)b^i2Q{5QXx-h3<<`Q(aqba1&q^Y^Hu4BgKV%nJQVz9tc?e=ZT_$06k~y>v3p zshaQEw-2?o_ifv`KZ+nyqBz(3 z%FMh27FlPp3-d)?NZ%w8Re%0e<_S?)(-_)!!vzGm#h@*&@#Kl@-TK_TiXDuFOjKIF ztg68i4HF_<2lMiWi+(;-OU>cNu2P3p#qrsA`}-T%S)4ov zDkFGARb9zzU;39UZK9d1{L$vvjg`8zs?Md2UdW~m95`{}EKf6(<)GT>gy}930_hFZ z%OqK|CM2wn*cH=1c| zxO&qXgPjFt`@jLE&k4WKDOs>}dzy6V#>f-;8i67mP{)Suib8AzA#U161Zk+NuYdR7sr>l@5u%**SjdE%Aw(YP<`9K1UG&SZ_lH4vtq{=}Io|70?xA ztjdSc+Mc~v3$f7jmP5~mNWmC``BwEW`!3)VWB!0}z;5pF zC)9&*h)rw)`MWC_icE!th4UkGDYQHnh8NNMdyi5E4ff6sA9P0y5FwPqsnEk zY0?Qr3gzLqxWYZru+Fr26WmF$dE2P#N+TX@YQ^u~oi0CIOMU1rV8da;Wu zqm)CA>Ecz=YP&5!xXvG#X4_NFKN-2puf(Ixccj|J43%!+gYw<$vsDCu~C)i&5`}_aCj6O<* za`yrS{}UcHhMd-7xAx(mrPI~f+1Y(@gRk%Vh7xYT&uzLEn93x42sd_%qu4;^-Nqxl zYBaI*j#M87y9wmx_f+VX&5$o*%%e`!+&oe9<>f>lb`a3q$4;L>xNsZsW##25boMLo z%r%8ph7VAMkP}?J*U{e}CHM_D9Yb`F#`aYiEL=AYXn9>@W@lrTXe@vQ?u_Er;>HuA!Ykx_h1i1o z5WyvJ85!Yvv(mI(@D?~jn4MUQw#cp~aTq**UPm*In=WPL<#vlb6QgeP;kC{G7b36$~zaGWBfE5w_~5s+=ZXuY^PK;EgJG=SW* zE~%Hv+t4X-6)bn7Qv49az`)=Sm6wi3dCdYgnkF|d2)Rk*w8O+5+!nVMqhJ<%a@Vkx zlI=i~jib9bC6(b~1vuM~yPUrkk840YcS?M>1u!3|y3R~a z)-N7bzy^VF<+s5MSfX{3TN7rTN8_tia*wW@xBD5(BN5!Wy2F<7{MyFDE@GOR)$u!}Ca@Vw^xtW<`)ezRR zoArR21XEnIJC`fS=XaGi_&~J(fdCs=JdT^9jBf_)EQ8FOVzoMp8|JfWbgIOD8tp}d z)WE)aTU=VfxXDtdh%J6KLV8>$xJvr+g+G%aMWzN2^&{Kq5iQCkDaG4OeO1_U%aMvw zKVr3CrYLJKh94JAeNr!qvFiH=Ojr>_Ht*xyo9Q*lS z+J2~1r7q-)ypY`=e5`!;?q5@Rl>_@CnyB_lH@_vY)vC%XD37M)Wp z7uU(~$!@8CT^z;nw;}w)+y$Kdja?a|yhBaUbe>$ss!o^Nx)`sF*P9=962t4fzdnot z7wEwIE{9=np-aW%yg|*A5Y23HSG@~^$3a(9r-PLW9H;VC-EY+*8xr0-&o(+D7T#xaBkwK%B~IvPo#L@ce8@98+O=kbY*qbWY6*{ zZXUBC1fg;sq3tq)eZFPXsS?%FR9LfT?nHQ%1Khx}GCthTT}0fFWCKT@-?4$8L*ZAd zdBL!UTh@Bwp84J*URXw6pFVwZ+ghrYq+>EeTImm*eDkzSq$5R{(Q)%Le+jO%ceEPs zRDX5C`tj`gVvR|rsqDJjwr$+@+#hK>h~0Lx(0(KC2$y)I?UEDF&})+BqTi-eX8h!w zqs>s4kc&>D^w8#3J6!85%U8(luEd-Wy&tm6I81Z?l+39Uj%XSI`%epJ2qEv_K*3B5 zD9lQy0Gg9{hlUb9ZX)-wv2FoxSbiS^n__bWzSJ-6J=R^` zNt+m%8A=H$F18(9lL40o)4vT}gBvrQ8!`2?mY+=z6z*Br#NJztuq)egHm-Y5V7)XS z4_h?^>Kw@66v##_Pl_h1`j`IrrdCE!era=;=PrMB*YLnV^dEl|lMtUfGVEv*)jL4@ znt}@(r(NlUR)#1kdU(e{>0=NXDJiQ)VS0kd({_-kbA0owV%yZupe>d;V)WkML2x2O zAp?cRzn$`ABl$Dmjs7%wQn9h>CVuWzoP4|ha|9;tgkNEC@#Z(L%Wvi5c3rq!`odmB z-PIq!$MRbq*c~^2(AiOZc;mr+@Krldu{4#}PKY{&uzcrC6#4XkZsyiS=godY^Fx`i zQ#en@2<74DCkLHkWmPL95X612aIp)0Jis{UTUN1e5*1s2Rr~-Tthk+_n7I_{>(94yH@$lf^J!>61MC)0E7jO=1gO=Drm5z)x z=&Jbr%8P+SALRi-p9r1(LYy{hC3zfjzdm8fZgxmYS@|w>EDh%nz{@<#G6|89qYm8% z6QpyLIG@Swi~E{%+sp1m0|!M`7yjBHc@s^Wz^f>$>dGmZDtSP}YohH#V;p*?iBlgn zruC{=p?GF%S3TKo$t_1c|Gsu7Kkix9o(I2yvS6ja`r5TUbIv^R4{g2Iqb#_J5UT!P z_D%b~fh*r0$Ik;4>ftnVCeVb`@tf*|?9nym6tAy>Z$2XTn+GW0e3Yg8a2fxA1Ydg* ztq%>e5a!McnVW4p-Iiw|q&}md&>kSPn{Eh6pvuv;tR31mLGJOTwPd%EL_VYaxnW1Uqb4jyvpw>A zQjljrdca{kAVaT%P1>SfMn{g0#<=KhR}>_>4d)2WryXb8nBQ-@nYRy3u@JS+6N0An z(bP|Z91ldvD#4C~ShHpAn@Um~6*pO=8oZ)=lT-qn)+shlhM_Q>Y0Z{cn0PAruG*guK}h?8^xuzP+p=vJ2DxfAmjyLXFDS*Z!Tn_qGSQN zX~1S$F>Q?svUXxJWg*E97AwDqoa zx4XI8wQUlGU)|eUiaAJGkt-28YB&B>M;!7SHTtTei={{MZ1hjG6;f5TNM~zt^xUbv(kDdJ!#PFHexY=O7tWv8gg&ZIx^+gmqj3K7Gx=@=^ykO$S{Xovy*w^f z@k`L9sHi9^ZnGHk`p<8fZc;;wzS}`46A83WBIGggS&6e6ISg_ z=RRtXTUbXb1V>FaM}(;5Yc`*ROi2>QL7HN#1dbUcLtzRmh6E9PCVk1!oWQ0ROu4iD&9F>%`Dx|4Zk1kZ;?dB}ji^ zph(AMqdP6ZRk{? z)!vSdz}sq2>7F;)S%Gx4=$d`B=HS2pF5$N-CjNVD?B{0n1{&l_vcC69o;}AFhO(LK zaan8SQE|q*aAg@9yIsL-Lgg$OeJi3pKoatgH?H6C@_y&-Ee)v>cwM-5aN)y!WgQ)z zDrU7WK^#L>E|6>;ww}BSZ(Z=fS}O43q*MI~2=78GFTSU&MAcc$AWTb8hiTmV?@Lwm`Q@DRU4)EJUl#Q z5i>J0a2mp)Qcm&&*z|!Pl81&BbmF_h6Q|kHhZMLpKzR^H$BpQ0FIQIu1qET@>d43| zyj43-DBn>rKY;Tl-J`HDM}r80)Qc=gd=DgKz<|E*a4ZvpTBy?Q1T zx1k(y{P=Os-M2qX&eD$=AN?&{c0p%SQA0Y0Xeg0~P)q|A+{3C!w66*jVSuCQ@8? z#l?$X|8!Syv9s$!cg6ijiLiYZOrQK(&;do}96jgv$d-6n)9VZjCdS6>HPdWR9K!hp zxGn|W{$cy(owaG`8Nh?+>BYx~;?fPzeptoE#dUUe_OBiPMKSh&+B?&zCa*M(2f^_) zj-WynhT$NqArylWr);uRf5*L;kg?0c1ga&mem4F5(QBc-HA_fk)5GoeM zNQ*2Z3}LB~9t)+44G2XDs|fRdL+WAXy7TiAhDP$-3@C~&M!LZ2I)2oVAAB67Qw{M-Bo)N?kiA)yD1C$+{=CSed zYMBfz3_o%teqlZ({1}&8oSxnYRm<(8J%7b{m3eu;56}CO&o8<6b7KF{P%ZTK#wxyU zrjffLY?@G@poUvgQnIAUt%6IJB9Ko@nizzD9kmMHy26!I^{+F3B+1|EccjsW|&kjXC6R6zmoxN zlBf@2q9;maTcIZpUBelo$Uw@L{KWpB?uUu%CfB`hqu!CDM)Xiy#eFF zoN9n-)O7YFVhEq|NK1dGD=2x?GY?S0#4TsOW%A}{A};4dD`jV&jh`{_sNpTtUAbba zqA?AXRb#|5{uP#dihF9o0V_o=;)|3Z{GcwfmO<9fIQyE5+khpus8Yd z)azwsfBxl%dv5WAaT9|<)M|ZweYWuR#L(2ti$XYtGGyR;Q>ON_*=&?;ph|^ibMB#O zOuOfE08da!>TAAHGo$EeoU|=1J^f^2qQY84wG?gVBtI7g&rS{l2P??W4}kb+sx-sc z+&qTMRX~0Ufh;utIXO9~+F;wNY$~ z+k{;cy`Z4L-fRte0TESpexQJ#kwH;fyU^~b zJK(6t#>T=Y4x+ZB<+dxI-sgF$D4FU8g2~1b+5X$LR+yOx81F!f0C9WdtM=mU(D-jl zQg2v!q|W=2SZKRh*3#ZS3O~6k^mepaH-m%ICK-Ikj`b^yrDH(;22M6uT3P~<+QA3u z1Pc$*FY<0p%`|>1L)y7TAXq&}FbiBRS4Q2mX#`=#>FhcpwEd~rv3@y+k&k(>+1x%pE>6tQOjC9u zpwn@kJ?7@-P|R_}&F$yR+^$u{sRC_Fi;Ih8&c|Oqk;~;sEu5OgMK2Hv=_#{uOCEw> zSWcd@r$=FFA_ea#5zXR^P5LLmB<40vLrQELDrrNw2#fPCr_`h45@**8=@%?TL+c4pge;4y+nHj~~Ap z1oX&=yST^^=ZqGaSo61}4_= zc)S6AU}QI9;=1X6J{DrID^87i(8ZOp9etJP4d7rikK}0>$zYe%u)F`lg|!#3Lm)Nj zELck{w1{y#4bQCU!YUIOKMzz#`ssNSr>ltQG*+$I2#M!IFk0*%uZ=0(<53=b)a!uq z{4|mro}dj8)1Qw9a+xsnox|@+tF7JPhS_Cx#$B96$?pMhB*}u(0_u~%=de!fXaIre z+a%eDr!;%W_3N~N^DwpWurTZfjhTipHUd5c{ECJ6y}|DCVB);GN?r0|zg!PD2@s41 z=Gy?DH^;gpZ zuLo}@3k1?QDi(VR{lg<3t@Q$t=sB{#(a|G#{Zw*1d3$tpB|^5eGzP@zXRl>tt!n*? z&3IT51b>9ly?R}wubau13X;zW=Q^8va>tRLdlfY-z-UefrV^^aa5x&9$r&&)taA4zkUKTCJX2<4WPJ! zqY10Av9Wo%x)0u+WSOt>6=Frgr=jbHQd&QUnhbjQ9t$}SehuCtAr0KaX8YJUdwQDR zHyUx&e&teeHM~P8Gna~{wL;6KyouJ4UkbCl`znkaXc~8my2C@GxUS6AF wQ`&n9k%rV>4e+G2x9`6EzaAF7g(=>GLFj(T&4z%vUBr0$F<3s8ABCO%7Zy;W_W%F@ literal 0 HcmV?d00001 diff --git a/static/img/rancher/neuvector-security-containers.png b/static/img/rancher/neuvector-security-containers.png new file mode 100644 index 0000000000000000000000000000000000000000..1750a2444e684e0f63d35e8978eadd0bfb55e1ee GIT binary patch literal 71277 zcmeGDV|3+Dvpx>Twr$(CZQFJ-(ZsfG+nLy&*qYe3{m*>w^E>y^`{&KG*V=1;&|TeK z-CfsJ)wRPFMVtY6(og)2^5^{ z%`9z90RSYzlT*M|lr^zNu6~}tLI4&ady0D|BY6T8t1Ci6k|rSl0}h6aqz7W%pw4wlGkrkdWQ)J=mQWQd{cXKL+EEV@^iSc>+|F5 z3rj^#hYK5k0$@i&j*A<0=T4%z@g)ETKw(uvmzg?{fBXPq90I`~A~*dY$m25YV8sJ3 zEfX1OKjfMNz?~_QR06>797dl@63iZjP9%+#0i^kdC?Wp8VS>x<;`r>&jK7&X{Ll{`nsi2n|0uwc!w^B~- z4waeSHTVn2nbZ01h(qxhx4rk=rKJq?ux{NOT_X)=Ov50>;6~35jM>B=)KYNwvoi_R zXZO=lhH<3$CkVX*&vIg0FK0O64s_Nitag3x$!K49r1SdV4}S)UDo(v^N}u6{dr@1P zrClw|aKg<@M%NR5TuUDBFTbFj#(Nddk(P&uO)5Sm9w zge!OmU>Jj#cN%}zyg-9(zyJW`Hlj+iK~wVyC^zZ7T4V=gB<5q7{r$n&be`sL#EtcZ z2`s-=XO6FoE%=FSdI`854e3+RUc6bz3%x4GCE%I$Xs<}(NY)J@0E$8Ym*%?QfQc6@ z&&L2j5dugPKOhCr3;}oyVyS9>UPjGL4MFz|ie^moq zcS;**W&?c=5Is=xUh5qk4){&j)LztU%2vp3sI3tEUZQ7Ko^T)vBq_M!7$&jRf^~(@ zG71$QDZf8KR061lR0ouxy)X=R1ABM$@ z66?Hzar(LX@%kl&sCVED(->rnkbZ>63?djIIYQS5 zX~>_G@R4?t$4g+5a4QjnOOKHz$4$lA#eqrYj?S3?H(+yS(2!h_smHJVj{SW_i4p-f z6pSP~ns;8ZpirZjqs%8cLn1?xhJ+J7iDZf-i{wVSDS<@NM2eYEN$N}zNjfdL8IO}n zByl3qCRty^CYda$8+V$TQ8ZU(rs8Ww^#i>r#WRtMDmrl~{xR-Q;z%+#uA7WkM0l3P z(vF4A7W;yvI+2YgFnKoFaExRWWh^V@BtAVZIi)EHHgPhAHnEF@Izf2!9m(XXDyp3-&s3qRHRVy2W998- zWaW4YT~%BqV#>}+dlk3}9R-gObkgQC%EzSlaIZn_4ec%M3LmYWv9G^EYQ)Nh)uO?o z%`-$~wI|&tfio^LkhQF|#+%qI7A<*~$Sl^Z$gS|_F6VOQW)~rsS8L|0m@BAj#}_7N ztLMEd#AltCv@6x~-SqJ*?JIMud_{Ve0odx8Bv>ezTa6*GwXmIFV=*2v4WrJZ+{IAE zK88(ScZtu(|uz&!gXC^dQ6vzE<1s-^ac@5-kHDsi&PQ0{r<+2;P_n)D6qE#}xrr_`^^In$=lulg0<{x$^0PPhq-X0()6cH=kDoqpy+5G8sXu+-L;xGe577C5 zWsqesUl>Q&RpeU|6?zqnKX_!AXt-*~Y^axbdMI=e8d&v=yRJn>B8 zbH)dK$pf=$voEvo>L)d0dOw_-c2AQQQ%cEb$Zp~He$c)qL59*O^ z*dGZWtz)2%0L*Eo7;7l(NH!U}DSTM^7!7^xs;@kW;ovAs{gKaANKn&K@ zfjS6cV%cm(?EQceA*}!_{X$t^VfXIPcQ1NHW`h|h(-WQI?}T#re)b>C%=44X%v)55 z^|62!ZyZ-+leV|pTje~P$R^Ac&uDi8?U zJDC!&(y`Dn5b;3~5D@SwAFof8WqE(lOBgr|j>lJb#~ZDOkFj+GvPa+M3!qf49NM!OFn% zPx=4#=HD&;mztXYuF1^F`d@4QmpA`WlZXEA0RGE>{-v#do_?!~4~mEWKUL2MMMTX$ z1^^%cASoiK;tqJ;1@4|T;z9Rnr+>f69X7Qo8IM9*U#30TVAD2uQ8p;&WOpig*~KY2 z)y96Xo|rY_D7S7Z-GHOnK&shLrY9TT#U2L$5pXP0yY|$5M~?;~n51jquj{uZA$|VI z{Walr_0G+FHKFdJM<#&;0s<%~fPnDdejqRay?Z%H3ke7yAbaI9gNRQs|DOu@7UoZYh(Lr&VvwNwKa}&g zAws2FnE$OA0t6Bup`ri~nFi?pr8NQq5viR2LoXl!A_8G5aek7n|7#WyzQ;Mr{C`Y= zKpX@_JQNbcDBb@tJ>Qc9_Wz%p|DR3{M&JbfDmo&NT?_Wc#>VmSv4FZd`s?fK_Je0> zvO?|hUW&Gz|Bz8STdfHKh){HIzHq3+!C0~aI<|tx=~H}SVqh}0I#`lE6Xbs`quyOn zfv|<$i#177=QbS7P(XJPy*a!; z5xP3O_0I0q4;?)mZ=-n#m3##DYyaO?a{wkL5IF@qdw+fP?0mcIkdT)j8IHzAL`4l= zS<#4AD1Y)tpae~yrHGw^eLNP4YCQ#M%4?vextNWY_|b`jn$ljZ^zTI*MgwBPilh0# zSX#~L^Um>ju@A(Cv1gJ$;w&(^ES2A8*b6r zDk@WHf%9!{FQDY}RNY_IckxO*;r|Vd0Ak(!dyljWzUpL)c;C;8x4s-^DypfK(3S|7 z=aimT(y{CIUvj&O@)X!#dT2L-E0a6;mn4$Q6ETv)t#YpVZ!+1xyn4Q|uuh(YsmRO2 zXJ}#7J3rapEj1fZy*@zGCl+~85)grAlcyC3r>17qjy2cy^ypJ7e}p7?R+0Q$E3G#O z2t+@C@7uU&Jzow|>wlc7si>;-Ojh{ufoBVHl@PR=_I6?l?eAfrD#;pEPPS2oX^yZ~wH z;&T6M-`{$d#o+ zR?9N2OsD$zE4)A1sMblpmul}jL7rUT&!0b=Qhk|;<1!XGl=SrYc3Lrhe-QFgM!Ql)T!S~f!PmVoN4vyq9RT{NwvMPl#?$&d#U$l(T$1^Q0!3m=o zEJBm?K`JxRfM9cjMl`o3(n#vATs#QB3l}c8NhCOBBn2APfQdHB@;^Jzi zL0J`^oqBwH%wuH`QnY6qyuFVh;Z0(6`zqE!p3d-8u3YU~0b&RimX>{M z_C3|MF6GFitV@(Y#pl|At0s!Z1-?3M@x7|pA@aNrC{R#$d9mAZq_mUO?z=bSK%3{P zjv%={hvvVh#{;Jje9ZY%v9asVnsqhWT`U!*HIr(${}0ePeez zfR=!(enF%H&MY>8kcc^Hm+byVS%1)Izpe2qCCTZru{pg67)m9U4YOJIKGn~g(>1nC zSb6@BUnTJje7;3KYWp{LxnEwrlgil28{QkO#WvOogUs7dLP!L@ zA^o>NX~Y7mT^~}Ju3A{<>&01UO&AsNszXQfJl-(V0ymIkxoelAPxKptJNPm$>_U2k zN|BwZi!tIpKA%LXN`uHC!$bm2vFLA(Csp7f$0y|EPjTpu+{Oy^ocD4X!_88g-yket z0I{&JU~skBwbEb;EhQzz(tv!5Tholtx+07x!A<}FO?i5eQ z`v*`UmDjOpQT-({M0pTX_C9ym>#l3I8L65FGUO}BWdeRGuEl1J;d(OAz@vDG9!cPv z28li*)r<=wEGw=u$@+*;ruda|kgED4BP0550UVz`*-lx5$YT<5(%G&R%1ovMr8(+N zhf1fV{yZ&G#q#DwjWye?`|ccO@0!z|$<>?!>pTwX$QuLZ6cS)gX+A-A+v4#gcr| zJKSP$1Fh;KTJ%n$7@y#$vQH#Q*DU%FNfh8i-|jzBu7d5UepIeth~>_S*UD=Lv*ty@ zn`cgS-ESY3B~*mw!44g+wU0})D;p+o4h3DsW4X&^$wG;=Z_`q^!^+K7_ITv1BRBVe zNe$IZpEa~lCU7f;pkV?*K@Rle#}D`0QSzZ{?}YA$pXRDT!rALGZbXGCC*AXITOE=S zuxFdVOih1= z5gJFWQ|-S=n*kZb`C1D+wR+8hj^XtFr@__iQmmog0N9$@S9lVU(kY2K7ZIw>OM>qs z1W1d2HJ(7ahFPrVv(z_JG`Kwur6@nNj;co%E2@P z0k3u(>1cnEO(-BkL4oor$$xwrgZyvGZIyqY^o!XAf(D=gJ*v(>?GZ$Ivw!+b@a&Au zMgKZrD(u&O>$%Wchn$i%XASz|{14ZaZp9eK@&Sk1pVWbfd2cQY{1+o-+?H#8cc zXQP%lIT9EA{U>4!m6zuMl(!JlMKGbXe9Ljd_cRh@L4cSS;ZLPVZ3GA$BPigRE>h!A z>O6!9FSS+7_e`W!-WKcp!x0W~{gbj8HQFP%ya5}Cg`*IS=vc2dNKn7GPcIKa-oiIq z;o^mtg)55~qFQ#};Z;B9cv)b`S}4On#=7}q!{$@eqIKZCWXznm4{scgP^+Ev;Zwc6 z^F<;;_3mBwTWdRVs_}Oa7NWQ3q*_xA<2~8(lpvyV4I)-nR>46LNYU!$6h$Sa0?@F|#|p1+_4;Fj0!G_7 zJZnc$ZA+C%#91$qs3M!(lFxA;i;S1Tap0_DXB9E=KFsmH>oJnYj{9YebP>d63`aW9ua?YlGP9D^0kr?}nf&_>VW*+z^vxphqgQ0^()!2MIVW(Rw zj5DAl>ox&Lz~ErzN2#51p;N+e_ipY8$%%eCo;T2Bpn)#FzWgm<+=_ZQctooD%a8|h zT7Q|UOq8FNwO9rEJft?x1OSU6ppzpVLYniG(BfTHCQJt3goW;@rh&lWC9o^YWlLdh zjskS{udRWr+^xdGRwESsJ`-6Cw1yNel+V(_uFb z@jyR%*kBbQ=BwXd8eE4&=`e2)#tgR*$ZU8BD?S|$TLm|N3iY(LHk#Gg}` zAPxUMin5=Q9|EN zWEY8;ChO0>M|$oQIuR>B#}-2qh;cPCoq`#cn-#Xej@3QN0~oP<(OBLfv{($~_DpvJ zGe9kSUsV4F8p)s|*Qi=5Y#1#wan222rthS3d5*#ohhtBQGF$P;--Q)J{l0WT$>F|RD&c%?DsA3}XpX#6) zxzHV32rRyeXoMnGimuk~LA!Iw;?p~tEMUZp@V$Yfd>PBaCq#;TEw0=Ae>gu*Y7>>_E@*2(M&vTSmuVp1ID{ zM63)91UiNc2=Ii8fI{S%zBlr>k)?!iZ_jGIzh$_{(>dn83fU+T9=l-ttvzILD?J$| zd!Qr!vwSp5Q6vH<e&?k9eMAMpKSX!^taCWD>7 zxctnfEQP(Z`ZmB!HtYpot#SlNPqr_e3#VK3+2$m0ji90#<`ebPN^%(jSie-E<1>6G zipBoIiZY0c#Gl^$i#+6uXgreSvlF-!)C84f#U&5f9eG({ad*TOAl7Js0RjRM!sAPLn=I|oLErS6=5U$W&U0wUllm#pMQzy)r zm6Vk7)L+jK<4i~q0ka8Y|2hpbLu~J%H=ZIJ#v($f;Jd#d z&2nehgr$)GMuP|@ASiG_wtNlkB*H46q*1A4LsnVr?bh<-S%|!&Ap@H$AC6&Mf@(_Y zDpSQkuUpHK1&>htS0rT}-YhtgyIww@x+4n;Fpz#-$ETg1(!HPLe&vQmL}ZkO-}%Uf zEp!Ug{bQPShz(>|3E$X=U9x0U8q~z{NwOI^WVkSlT~wY51?`>>{oBy=|JsaiNJjz8 z^}Z5v0A>BN@3$!uq0`vJt!832wkgSw{~YPrS~B5+%0w?;UeL(d=lGg=nPL#GqOHyA zx}ham>$kHO_Wr!bl`|nrzN*S|_?nGS-X^9omWu|sJOhAps3Ah%Q0iDe#%dcXCIqIn zj)m#9Jf1!x%1sFmn>=CM-`NquGm~h7DOpAG*FB34_p=AY=7erI`AN89T032{?CZ+x z{Q^xMs!#U7zHZ58t5E&aLzW!a;ln8E>27Q1lKZ2eX9%`5dn&P@%uvxnfT?RXW7rnv z^qCXEB*6O>)qiX%>L6VG8O;W5oWqbD)Xt|H0w3v)ICp_*8lr54vyT+~@nb*q*`+t= z{h+emOcfQX5t%U+-mH!mCpokMly2*N6cuN`?{^+a=|Bh|xseg^9)$NV`jTv-bqh~J z4BFCG^OKC$k!Wq>y2F|_ueq9LwaxFL2<#K)y-!qpp-E-9lVo;3SmoD#YRgDUHe&2U z{Ze0_WXpOkhaDhMd<5icyBDfF63YueJxwtIm--|ClcZER%G{GvI}HE}xmT!lAjRdK ztMGfGL-$6Thql+z$ugryr3;m6h=5p5tfM%~UNx}2;*2dE!D)4cjR;y{QL)wV zKTsw8EqT|W1I=&n>CZirGLfm%$3O{%I1zN(+6lkq{faPQ>7mi%ikhOfPaLnfM9ll6 zhb;`6o|9qa#JW5@C%Q(`6}~`S1dFq?B=}bF+msyw`Wp-ncv!@!5JKq0`mF{3xq{7) zh9i%&6w=BEw|(1SNJ%p|cifd?l`q?c)p(<&u1axq-gqbu-j1+mMF|Kn(;2+Jo(bE7 zCE()Xs)`{e@)czL`R8F zZQ~ct_*g_77W(0cDk2)Gv4G|0K2)ouO-l-U7`6+{Z*t%>YJ_xc^i@Yp_t}{O7H{EqeBf|B6pPNoxy4}ZxN`F<#hM>cmn6RvlJ88yK_BH`4`66uRhaI zk)}fAK9O+T#kl*+2)AFbsd0vS=^@fKY$STT{I!2vAX$WI#P9+}~o&?|APC$(Qq%>~^h zV2kE4g|A+`r_;Elh6i--H_OXYXZ;_4(7+!p8GjcymKZ%8!ctVzh%aW)czxCS`kN^; z?f%H-aC`sgX6l zQHK;2NE(Rfnc&5vsSQThc$@Kl7qr~=Mw6Sm$GMr>2N1`cDxekP65C1?f0fYz{PzXmwX`|%_ zdiiFHT36u!csH2bn&Quu;O4CxmNCnK)e3LYuL?J%TQQGR;t7$l$SHL%F1W`#IUUbo;5&D1I=ibA`|v(leGLow zxxwjF9n^my%mt#Afni%fMkc8l6QkX!xG0?zaV03NJ{W#@c|56Wa9C-)tv{gc|l?kso> zJG4Po+fjN5$)u#1sI*mq8&eY_fu5)h1}wUl%}q~G`GNt?*9qarB=7N_IXU-$G<#7x zDz-wpnDsJ4X<0HEAGO}`Vl%G(9y$5}*HRW~siNT}S-Bp9MjZrA5{JJOsZEuk4}l+d z2HdXrG;R<%A9AI7Z4vl}5XndyQIyI{7Oc#bMQ?PUAUJP_=26v0qk4I!)|a+9W5K!n z?##%FBAM;gwBLG1HAdZya{!>@OB88S2)WX5`FMKkmATXOAn8V#da%Ss885z|Q%mkM zL~WNNkb215tY>{H?Onl+7ci7M%}Dl|v_f2BOwzeaQ7H-0lGWj^yCIDqdZG^A8bQ~i zt^oW`^XKPG_X^F><`T7g*bcs7M10*c#fmz0qdBf7M}{+93pz>APcSWi|CSO~@`9NlY5PN| zuq`ktDd(JlSW>>pET*GfxP_1RNkB9N8187Bnl|64?Wc92)Em;}{k zu5Z&Ba3toB;=prg>C;s)t{GN}oldxEly4fhIGkGmk#HeVG)$0kbZDW6w|!K(^v&W( zPuOrfR~DBCkh$E#o)GQGN1}Lq5<+NygQ-TnD`m=lX>S4i-S8oc)5$v9LJp6xl1AY8 zVg$-Cabcbeaqxk(6QcP}yHVD=pl{Yk{K7BQ_6*!I@2MDnK|atb`}=y;=w+LU9~!sj zjuK`QgPP;aw$>yA8X)^3Ry0_*d@v9gaSCyPsGQacnrePgQ7R@yr9_N;SY%BUrFssn z1*+33n!AoF8G8q{ggQTz=n!t7@H)GYm>nS^rG!%>=6!NhtSRh@*6tG1 zDlIi)=+P1w4U6Eu5=A?Zl8p!*Dw8k_ijM}ESx85YQ~!m8T_L3ymmc%$oTaFkj39)Z zLyMoX09$}_XJYr1#DnWp;BABs2A=A6zmGv5uNIEcI_h`Nc+_BV5_wj1Qv3I*vjHGs zp73n~>Pl7@Nb)#U{K#{ty!Y?t(DWM&j-MGf@Mn%MbC|>YG6G7jluNc+W6z;4&;*}5 z66jIx*3t4!1Z-sZXm(a5svAMz_R^yI>MhgS)T&+bcr~IQ#nK#)Csz({%b&emA|r!W@MDguKHFLmE0|0D60r4qcS-uv;3=0iyW!6cJ15> z9-^>gK#<3JEJSTGVlFzGiAYT!9}Cq{I9?!_T1|H{@I2&P=E= zw}!Y-ac5HnX(K5mDroTm!`b?=enM~&2E0{e=B%WA^~MFQ#+>EApU#!vjq{k|P?IJE z<*J!C+c7Nni73r1I{hz8!-& zN*>@}x5O^D96=c4Ld1v!Z9a}Ycp7U5mc2xQc#GPUD>R1poWDkv6%ZI1X*w-F9Qo;T zwnvp4(dk~h!>SpG+&WOhMZq+f?!ykpk;ajQit+mj%OKW7VE1R^dHx0h%s_@mAY~>g z1w;+;BB)>Ev-_Sybr-eX2gaLtElz8Ky!{a=Vf8$%RWAeExwvOE_QW3IiOVcc#pt`5 z;2eczSIT-nGPq5(o_ZI>?eTuKkdzSi6yczWLPdHP)tSLi(wtxnw|fu; zM-<7K7n@5k3OSbMGt+VKTNi|k4`vWl&^#ot^!$x!>US2i1^ZDV!+(t;AMeSf&Mlqs zzkzjs&3WWGFys9+;oTKid0zLPbbk=1FBnb{k{6_mkKG_53={5>Sf9d6)xn+aJK z7xLC7Wy|NUcH7i|xwO`1xc7y0Tp61;S}==2H6_L;#0*Q4MItIcB;15mJNF&%^ z^=^GS;K%434^9;vx7jS7kL!_uFnaHKKL<|u$QA>K0CqlZ`2;wNn4h6{hdhWnV!f#T zw2*z%8=>E<6xPzjoFk&Dsm42j*O>j#25+Z#sI3i*-_i&4+-xE?OUAUUjFO=FPP@wN zSmn=A3iuAQ1YrRVL)zHmMEgF!Do6RQEc>IOej(ITtaZY+yzb$n(dIpeHp6*!9?{~I zlUbhHiFeF{%BwS5@w92Q?5HKB9?mLTb1|LZP*F05u&MmAJsh?mA?K$&FGvj9nZMGN zhvIL$0KXQ`|HM0z&zl8ucPw7*&j`X`#|Yw}(IEGqn-+c!KVsGh0x?~ERR(nz!QX}c z+&@0kqDVEy4VtMqGx&#NUs?=C23mcWxlD$2O=U<|>n-fx!M&8+B9JfGP$szGt`;ul zuu!)7AzL&QHBE*cs8!jmvX40imo4c%tt`185EozFnNT~%f>a1q0g0$q{|0VofT-lQ zD}Tlm4zT$xap`~W(Ifh|UHna{BOaB9`#cbBF{o>BLUKvT~Uq@8>jev(J z1qC|`MqW2r3DtI7Kw07a6}@AsXz#NgL$QK=H?vf=Wld#|{(-Zx51K!31t zx-)iqqaLe`a-r$aM^E3J8Se8D7A7v^_#y@~iMP8((?>1H6zc`1q>@-i{tZH~YE0l; zxfV=A1upYYMIYP7F2CSqv=5KH6T2b7?oLc+X6=4+>}oGEE>v=YQqqua0?L1e@JL53>L-t6?SJm5wM$EhDieWA9C(+I5uG>XcR#(SFF= zbblzWWE!(f_<2Z?bcrhp6BPq(8FRh-+W~QM9jW^mJKFvABz05;MrZ z?=HDE7mWHfvrNh5*)&e8TB}yE86K3RR$a@e`hJa^mGDC`?`0Ox|)U0BKiYhEj)db`G_|qT{xR|jrhOu~b zP2oH3g=!&8%0rOIVDOaNeu!S)+m9K)GuWIC@8B{!J`k|bZ4GSJvmB4@wR^3NjQO`y z=~zujR-2rQ1w!>Hp`h3603^h2CNan?=Q3=%>WgQiB)4Iu$B}4frVsv7s;M=1yq!2d z)-+C^eQf-pC(1?k*1qE9Q;D<{+74xUy55USIgdXTalMwAz^NLv%_NBui8Aib?BmjE z^(|9iC^x3CD;HBRg$oza-%sDDQ8$CQEhcM7r*>E)tg6XpjL$^T7U7#Fkj!wf>hirB z5vkrZ?5i1rTR%2UG?0;xs~5+jS;s_F*=r*mqr_70+7a!mGctrtAX&xGO6jmLJya>y z5=Id4Fn=8xLBz6zT-RlIi=;AVjhqBC8fB5n0+6y>6grobh}QVn@!>ZYdh=(yHN~y_ zCNnljEi`fndN@%Q{f$;oX0f{(cC(t*QOn}asbBQ($qyP`y@fhHPH?WUZkTW#+-t>U z=?8=3twvp#QV9svnT9s=d)WyA+Xf<5UPAa0)Tn_l&M=Xuh zHU?9{2=Wzk_RU7Eqv3?$Zd$-)^Z~^%c@GJq-$4wsK)=KrcyD8XJ^W24a3#yDOeQip zfYK>F1$tGY(y;{%^%C5N58cP~gFPok>&35fDNu zVhgFtypbmz%$spgL@qP>m8AHHP}T<4yM*nKw=b)RY5IIcQpo)h$)fo*lPjAtFO1&w zApi5kIio$zfS-*A(-e0Ocjt2I%%uHNpLy2v9dy9j!7lguvU8k#Q$X%~uBjo&F;q{H7XfXW*eMa`N~rTHhl$4FQpxaIi>J+CTX zWo{Qg!PJ6o#yhp(D8WM)xHeX9A7yOn?v-)W3kU=?X~ za(Q0X9L3vxoIFU8cEHiKDv5F?!nQbPErG;8Jk8#oCuk;cgi6p2YiK@&i&LAdDZD&B z^5e83QZb>9k*)ixfnUE#iot-bP-xP!d3~>RNW%_}k1+v6OU#Ky5t6YlMfT$e$l?gZ zbPBYBvICpwJrHx1V>0dJ1$HVPR00bTunq_)cY>0#a-z>Cg8by157p)1wQ_KU_6*r= zc-M7{(T$Std6JpPPvTu_QB7GkRSVL}r1{){3CYVT$-ML{4^Q>e367vNDWAYZzLm$} ziG+@EJcIr0nm&@6yU8?5n!lN%FYb$+Vtp7lG-TxiVd-=@dkOBy*BxAL z_RA-M!H?MN0{|(pX(V*bL|}j?w3&Z|$(5*UO@=PI9K^5*Y)%0Aw`ucF6ev2K5sCM% zM&*9q)v}O-ElYDfhWh?+iPrMvcYD08nZ`3zCnF03O+*qoC=`sZl#rsu@AfnQ0Q6`I zajY}*f`!MtR9z#H<2uL7W|~ak$FnM{pV4JPGs=UGb*utX9_acYTs)(r2 z6A$1^UIN2&TPm*??dyIB>m@(LPh<8zFkKD4+^FUB#J^RnS0Jz@a41AkV=vB%&Si!=Mmo57h6-%F84BlCt(G1Zz#RR$n z4!DGrtma-#vp(@%!DqeEnfSIg@j#zNvu34*FdRFxF_pAe3@m<9`02>}^NHaV`C&-OLA;%;V|LU1cJsC9v6Dxe|Lm96%>f1Gc|`5aQRVp2;%X!8RO+b-F6H0&{ ztB4_dosVw(1DZxX53^eXAqCHftbFWPPZxdkn_XcGw@gLiD(_I9UPa49_63kH9Z_Mi z#m-SQa`Er{p5c&=qg=l}6Q-Dw+&m?}(fB)=Jjf3YY;TcN`3lvPRyFD%%GX`i9eS9b zW_9p83iu46{_EQmqT(5pyl9@D9apPn%jmvun|9{9(zDS_3TGwb=_K!kIFHmFN#JM6 zopt`ShD9i{ZaA^HD*jz7pE7MAjA|N=6o|FVc+;0=DzsTG$Kt!) z&+xzi4xhZY`nv^JvSu3FF{1z;pAMlEUy=;5Br;_rxy zbUBa^*o#%=GJ4dLL;`xye<43ERwHR9oxQGMQ40#23$!ip_vDxf~otQlcPIMA4;*9yC3} zI!7b(&B#6Fnem8(-8f+AU>Mkppf7x))5p{z1P?!oqz+r^WBanYzq1iaucda7i5cw7 zYjrQqQ4KXk$qL@vK~Kdl&y(%6A{OwchNdAT{3 zg46;*yV6QV{ahgI9qJlZ{0aHaGHxI{bSd5w)mrtj(s4yI#mZ_?twgG^mr&=jmc7#8 z3_Vvh#_PF#5Te3Tt@SXy@bG3Do~w`|qN0>iokW`bsA!mI%4NWzDtdrn2|eUdnUM3M zmLBgxEvZ@voK2p6ybqcDMkBeXN&W|=eD_3Umc8H@#)|6cVP2JL3q0c6`4EUt@Ny3F z15{MBBDe>w@qT_>{4E<^@|p(zkuA$ncSK9;P~G?aM?l*cEyN5Xa>B3!WQ4(Jk}#Ez zV~Dm>aSM{0)B<+xUzQbz+344Hr`{UsIRk#3_wy`BaZgPH-F}_%i`-l!c6oEpfb3jY zT@qBKwUl5wDmD0LzH+I@lXz*CW!epvBB2ZPHXNT^Z`bc`)7wPoB=c{ldHMCUaIrqt zl(!$?fjbtB3zQHvR3IgKVe&Lod-yf$!Q?qneVb2kdlRe9b&mCw&1POV@Tt3f^bDVd z9?yID6_3=Afp;o)B2qg_Ha*;^#n$YF_P?i?I7*a+j8QhMOHB!=nIX+Ct3cIjtYnXs z44hs}+R_`6C^SPTBiRQV>Ij)VB2bVrV2FK7MZ{Rs>4Cc@#71sKx3nR7yruN41*dTB zV02vy_R65M$=#tU+z35eP$4ZR_$PgKWY&01we9QZzt1rYaPd5Loy@N;*RK21pBx`Q zTCUGUn;Ok=Hdd{x@mE*1aRIr13i`KjKooHP1hvzDrP}1uj^5&XdjA3Fads^GyWIu1 zp~M_eFrR&GqJFKQZhcn}h8!u`NG&sde$PLr!e>c_7^wnALMq!Vb_;Q3+zu^Sm~UEQuD?i* z(&VpqkC9wMdYomB*z10r+=%xTld(LW*ovD3`ctVhRDY!@%rZfw1Vxt+Zw5-Sog~va zG1<@HRCq~+>2RQIv9D#`0!tgjuN}loflVQD2a%(@>pD$t$)1J7P zK}iLV$H7T(mx`i4@u{TOI9EelX3-8smbWq=D^-pQ5+xWad)obSl{P@LgHImBFj_VON6Kk<%k ziK*pE0~<8n)8KR~l$7_Q5^H!;$p)guY=Zo^e{*9a;9F+IAAFQ+4U{|bJ6v9Zvn z1u(j~6`(vaC174O!dKw}{}c`T)6gGnD>+4f;M0BJ=FCCA>~J4puW;1q9j3Haz*IAG zT7-k%fsG+$L75F^p19gOj$C$KdEOD!K5BU&!DKLjKSGG8iROOcppn8B`pc7ea7D^- z`R^ZLJZ1LBU=X+EGu`Am5wbcZxW7|ZMxKkN!#azp>pf*T$Cwigl=c8xo))C1Rg1U^ z;M}0p_`Fr1zB4CaHA%v7yOxm$&vlAl^HFlmDYa(?8CqXmJlhebe~a00p})e6onhyz z_LTA6UUW`rg&?@uU2(gzbY2z6#=|*kpNxi0k>3w`Y-d5^x(G2k1Os}cVkj!0eXfeF zrfM3?z^t-9)Z_6!O8w2fbRgWW&wp64%sK)~AVM`uh|uFN&ohS1fU~q*8UFtO#6Ua0 zqk@sNY2yR_w-Nt0ecj#oR{B^@$j^s(P8^(!aYSm_ii^Mq)?i?Ilp0r~5LJ$xH6auD9eE!d#VEjXlh5V@E zAAaxG7l5M8c78t#w$Pg6>3!c!;%FM|8S&tt!af=k-|}f>u`J1CwPVfX6`Ky z;NG3an#XJ04xl|BR38&!W|~6$$iqr^ePuO5{e#1BX)0(mbhVff z6BEl<7Ir;)4_4+y2Jxj+K`kI}!A>LM7?9ULvshE;1SH9e+MhaMAEUW4chA){bjB2m z)dj#Smz(g++ZlLbR|faC$0sLFym12WUgp_VY9i9a(ZqOwc)F)>Iai zAu}lkrZHhjVlxV{yfhW>Rd>Ly98QefA4z|%lZCCUD4a-^0xT~{!~2xQ##5h2lttm{ z8Fa(RbwlzU7NjkwEfia-G(s$?dL*te!t?;+O8vW&^KvBh!j01wAyPL^Uq`5v&RCS(=B1z^Obg4s0CR zcKqH~P{Fy>&3!wAy%Ep<;7vGI-Hu1M=K?g4@n3V&V^Soh?vs1)lV^X23zxfi65^$! zhC<|}CBi_DbKNaXs5#e66~9a9?r%fiy7FTz`dfU}bOfi--Mxb>J(V!bOhF0)}x407F;VmYEP_MKoxcgN1 z{>ykT6ol;TcBWZ7U)7c3b{)}Xp zrtUeBd2tmgQ}W{K&jl%s3IH1w69;Q_EDAEzM3s!&9)196ySR94ZAIOM^Qb<33Kwb` zP=D?Ol1q2tkH5Jlf>g;SgI&21NXCi{Yp|RLHELqgF%HlhBvQk9l~}*7gj-D<3`edF zOjb-duY0aw&(j~^{G}emRNRDz?_7zD_xw4$^8F96 z?7!cMq;R&Gb*J27#09GE)%?JL)W0&1IRNya_B#%30g$os>Y^xo&DA4oMLC|l--(~T z(u!l9gJ^8&K%7OnO{TkZ2V;Y@4r7Q$-D~e$j?ZmK5YOk~>ny2R5Ewz=YIuuhe)b_g zd;2QnrN(faVf@36g%g zn~@nEd1`&*r7>q#Vdv5q>^Y`nd2v!%GGf9h%hY5>uiTuIC-v8nFs)S*`l5OboU)_- zpd0Ob-HesUlPWq>k~IGa2$7n9%;&X6pL2kDs*(%8DeXa~YldbfgOyLY)uByGG)V`YAo&u#-u3X^ zP(wDl%U5l@N<#sI3PlegYe)379VN&2K zKz4dOod4^GIB@<$oV~IWn^Wg_Xc=vQzaeA)(!sbX>(dzqHCY`zv0Ak?6Xlg@ zs47oI4r7K$5(ET+a3f&C8h`x55B%{D4IEB*ifkLAEonVnQCP5XP59#=p-0WtspKmbWZK~(MxW$~RC%^e8(G!x=tz;S;Rot^k5rsHvz63d?jWjyMJ?QMmuYY(Jv>?IAgyR?Xu{CtQ`mo~4m|_?=%BHs z8p%DD3~b#|!d>~<)HAbteFP-%dp+9OK`V})Xhr4549exgxsUd1M9OoVlkZD*RMG=a z!$yGE0_Y>$+U* zd%X!Qo%C9jI=2h{=_Jt89c<2Bdbml>RZGU^Pu^ib!(Z8OG1G*kyXLl?{yv)WFWVTM z6pxi_qES$sioSjahG~OFzRLY=J!0Z4NKCXMhNo25!9Qie@}(dk2+R!vdZaV{;gi1~ zi{HI_2xrbQyv1lmW`?&|hKIhm8QaPuBmSXscH|4HJKD%;-sq{qU4?BisVG^q8U1vI z^gc!EdBFn_JbbU5{cW$Iro?uj)X)dQIFUH#*U(fg*j5p$h{6!pJ>A|#=V-J7g6)V zJ%k;Oa!MKj^KtOqGviJD8B`^=%r^pcb#*8xD45r3gWC1Frez+wq;AH!+Fo9@Vb4#0 z0bPG5+OG6dcR3bio44YYiehA^B_pdS4@Rzx$1aYqDQXTs1S4N+c?nxmk57O3EP9UQ z!R)w#hVwPFm162?#wTyQjWawk8ECu0YsuKMCX*Ax95#NW=wRyb(!y0W$r=|6GZ*}m z-K*1?5uc_UO)$m;PA}W43W}Tp+Avw&;_G%FG5dcR_AFu3guHtfdghrWVa^6fbK=^6BK;7+0!q}^-R4Jv}z`4^h{hP118k78Pqna$*|3@b1W3hh~jrXgeR;JQeczhcjvFw6aW)!P$ma|Lr%Z<#~cSgp2|8SYDMCx3?*-#m`)?tTo?^Q?mo9F!CWt|?-o zV-OviMceE3drkRO~{UTVq(LG|MrjgZHou-JHCa#yRURo&=$fM4Gj(G?CeBkWo3jn z*M{RSzJ&vH6U%)eq!d(O*X}Bm7G)weBN?g5iHs{{(RRQz4>b`k&DiGYqtbBeXFrd$ z%38E`+qiglBQ851OIIyLPOKZ*xuwc!A9uryNK8*byoy2`VabqEikpgnHyS?0YezTX z^Q$M0bkue9Exc1R2qdh>()76}Qd6IJdC~ng<7`~iA>{$8*)SOI=&=;{M|9LFulo^^ zFE^v;R<-gm1bo6db-gp_JjUjF<*D;HS~m!9TmrVNPC*I{xQDpIePUlbj_U^S{a?l7 zufLQtfm`$$)F-zH0)jvY5Mcbn{(77~Mq~emHpV|ZfH*Dw;c_frUP8wclW#eNpz^sd z!ZSc;J*RPk&ThufN^W)XcFoF>F%n(9*zUN4GkB!vmR$=`_nEix^nd&gXY1OjM&_le zUjcG+sha4ac0wCNuUu&6JbW45y{+i|#@DgEI1ytVFDj4yU`vgU*kg=%Nz}=MVK*{bvlwt5g^wAgK*OYqSYw2Aa339fnDgGP6_UFEUy^ zNh7DZe9g~cn!J;K-BK)fuARhfr0bI#r|U zSw^lh8C6NCOYk*kPsA(=HYQ@n=N^P(e+#0i0x?SIy5X&Y`?bu-dbWc4{uQ*F(9 z;p`?s_2`lRkcC8?jqzt^({#g5T>24Dq>2p4zSXzi8uFdv0Ohy0wBY^PL70m3@Z>{< zC`_}^l`^gA_`Gb{kdBvrauO%@)}rBabiOk8{4~H;OEy8^Mn{104X-b>A<@rQRiyfU@cvb`**KKHtoCOqb$(VA(Y)Vh~CaN9C_p@yhDpTfj$XTCVg56FA~jfzfBVj}I8@zC zUE@4F_}JrEnV&?JJ_kB3p2OQOy?~P+*TMc@l>f51OS*wte0<;l+{G(L*G$3HX2s3l z`U@ntI}ly5B)D56D7W&`r$|(Baj|w9rEDuAJDE^<=RL^PMI$LOjvnFkBpHf8MS8mf zLsbO^w9u`)+0SQ{Y}&06OrEY0&47&Mn{jvcAoMYlJ2j7AvKIHIxe=3`907)xIwbBe zqU)p%<^;aR4?KLv;>x%~R!GC$Fzc1Olov-5?3?L8WkXfGQhE11A6&SkXGCLQeI1Uy zXVdI2#P9hv52kz&1j2{_;~y4PVMAsiDykU&(C`$V`hf8ddCD=Q;vZh{#XtNsDFKN& z#aO>d#Xrnn5b+QFpekyVTwIRTYnCHQd1~ccmeTSuetWnVrE6AUMKXy9uO({N1|n89 z%Xy^+`!99Dp1cZQ`@-#5U7AUG#%$11&A?NXuaPUycYlOWYWL!N`z=V%GieTg{CI@( zud?By$q|xwF(B_M&Ra@*MO#Qv1)P4YoEvPo@@wU^VLn>vb1*WclM!PKJ^boWTi1eL zyqk{4c4t!KX8fs?6Q|!fjrZyua3-fBMcXJ;Wd|ZdK$!w5C?t7iO{8i*cmcnwZej-} z;*mf7Biz5W6e&s-i<O#;8;jmzAS1Lv0<8 zBzGUGk5^+bz8Gst;?QvBILZbq*>HpSpkLnkuA>U!?KA?uKfdRW>DT4veuVu2{x)jPc$xMz)ptdK}+> z5G^b-y?ia!m-yxKw;=Gp{rz+~`RiZ9VzJ=nn{U=^)B?XdTsd`!P0vCMpBP1;7H3k# zaN$a(v&14Tld39H2w@`0%2Yq{2+=K1zS|1R79K=hcA%+7#k=z1Z_Lmmsmh2Ye-H&- zI)}e`>6a-6eQtdCzSV(F`K~6m%Rocu7z<}lFTD@WaC_)#f$~le5ClSrfENFdn`G9g z803${Kin}A|FEsC6&KH+$GOv|8UOGyE>)jE65}8K$v4-AMfpuFdZ%3Yjt7Q=k~&n- z^VG&dS8$e*MXG=>;Cwd42pX18W|}Zqux)ofUj2SOj=p^s|8lMkYd55#AeC!tZXDYBhj98}E6!c) zMDwr*8y_e@Iz1C!(=Vd}M*f@G5h-^wUVnZ+hDeo@H#~#~Z(W8oMvV5aw_<20UA}57 z3izY*YtGu558%7sc>(o3{4oyMM+~d2h)+z!vO9THzPsG#pu*9JXTJ9Xw438mR%pWI z+D>#2DhH!RL?$95F*^DsXC=kMUH-ZmfFJ^S&4@6^+<-wngfe}wNoT88Sk zevF^IMZ^BSehk~3TAc<<3=)%a@a4bwORP!ptzg;?KaZz>dj-jNB;g+(s?f@7-v11K z@OlSg^GlH2dl?O#-LNSgVRH;pURjMl`0K||ILiM9@yT=l3%}mqOkLZ4@YIzf5szWn z-ilq{#FKYlFIzs10~@HfJIpezE38=gXEz7E@$4dj+`D%#PMtc1^73-(XfH=HPX-oB z($x1BN@H)xcBCl?uMAF?B zlvMey&F#OOVyVVCS+bD;7d`{Ezw4;RwIY#bcd#6N6g{KGY~Jh7jA zEE#RjxHmomrS1#j-jQR0-hHRgat}AT6HRb;)#ANly>PnhcP9dm;gsb})Wo@njmXv^b6E+# z`56bEd8HYrP7I-io)Y7%4C+i=-3}MJ+J`Ynd$mguG%`(a*%4eNaB*Y8TV|@LiL_s;aKx!wDtW0+c*6s${DpXbJa4W zyzUGB1ro2qB}-uCz!sOK3_gc({MkJ?-0a4xn{UCUvTPXoYVq>(@8PoUBEI*^G5q`2 z*J|X=(bLJJ$O|0&6k+ovM{gJEcujZtGK?+**57pxvWBbitM`tf@lq?Ediyr~?foTM z=7x`dh9AHDF)npEneQvuQpS_C{jcHIpB^Ov`wmK${uA!dSl3nA8fr)~Q>(Blmmb8N zK4R&wd$PYnLqquSkADoO)5()SH`3D5ke;57?c28_KR+LFadBMKj_rxbN{a039-D(Y z*gWr@ZV?~ZVqDicO)d-NTHsyeW&h|@;EDiu?XCl24lfMubD;iB7l!+R*v%#+XA*3Z zso@$9;Ky7T>SVy%;uvI8{b26XM?WuHdC-kK@w>qwjI&WHZ>+kD3lQ za<>(rKp81W5(E}G0`nR`eiX~u|F(Sb4_oMUwh==Or?Kx)EqVqS|FAif@efBE9P}H- z34-ATFsETzfev-&kK&ns9Y8^*8J(>ysAhNub%x$teFU%f)^Wpn2v@Gq)A9Os$d2NP zf~qIz*3JBeK;$xWLqDGEsH?641MX$8dM7*i7(&hQCU{(CByk)jJq`}D8H%Cs^1mi6 zg4h;)+lpwe7o*g&mOy*`3kb%M%3w^Xj9fD;BPIm%*$0!g*$@?tP1`Hz>?sY^bS74R znStg98IzJrA1B>Dt|-Ysc||%Z%Tq|yRgA>>n2RTC?d-14l1SNMQy%)LxL01B?(fz~ zThw{vO}urgjwe_d_}X9nXWY6n3vosd)~zf>?BD+#-fKFC=U+L3-G6=yW7bfeg=9$a z{DjqC#2-9z8839Xf|S`x;23D)}S0Dw{p;4*bO*-G>5taU0ZS1aumu+SAn3gn@wp zD8~{lG+5ucbEkG1Wi+Z2!G-%kDw5$mQw`UpCK^&wAB(Xp^hrrDm6yVlleu8Yhli)B zj#FphYHm^6UFt{^hLmKOE6TV@kUHsaCepr8ayZYje;Qlhb+CVQ8~}OxX<1qsL2`J} z@wy$uy*gw*8HKzx%1({H3C_CCUK4uXvEl5?Zd~3+&x!f78vns)junA|i_=k4v zc}m4U?DEAw9%$)y`e&ftxV{3s>Ka4Y#dBB6X7^aphr1F2=?pJ$`%f0Nyyd9*=Cuf_VaW z+}$VM!+RHc;EY{?igfGfiO+OU&CB-$Hg3Iz>jlObOyIOTW{qdgG9xk0j@mtTByWsH zA{Vm}(GP566ytU+Tgf??ra1j7&^%qvtESVC16G;GW@jTtjgBNNDlOT5 z3knUiiEs~Kpl^U@R8dIcgQt>*i`qcgd)AK6Qgv|yQh5TV^QL0=?zJRRuVH9#P$PR_ zu+_5-y-NKPStM-w!45PHsLlFlA0#{@243$CwJbrrF;RpG7zMcUn=hVi^6@@m2Q1>ZQCprsX6c zH(lABN)iMXHv;ErQ?!KIBnu_^;vb$s=kOrf8)!Sk)Lh#_d+KGlYgZ`>vS~oi-*#$J zyw6jsUl(gZ2xve`Nmsz>X&mZ9mu%F1kbtMX9QYvu?*NbNdPqz%Ch)v4TKypEjx}fxfHx~2Nn;GlbOtN3^L)-2 zJT2|inm#JGZ$(6acOy3b}Zd=Ysv0=5Nu7gxTu}Z0Y`rQ zBU~o0r1~e@LH~ulJcVEy<_-?Ei?rmEEgmbYau}>ExSy1!Pa>R-YyHg)*y+A~>fA}eM#%5THvN7CN&j@-Zl10iD%M;hQ4h+A~)6>FS=(uo> zSQr7`*4+YKj}=}sPuJr4n~J0D;5$@PE%*Xu^*!C;lZ8J#rJbvS@lt1eWIx5%9R7e! z99;N~8YUtlDMR9DdSP-hn0b5a5Y+aN!DL2EQ8ZF%oU07FCCw263q62*C)KLb7e@g3 z4?p}6J9g}tqmB-Bu{Iogf${pvZ%SbWcHh2~@eeZ?zJsygQs`bgnj0YeZ7O`+08eO>=A~zILu1DRC6V zvaK51>XmAgL`m#ouOKQx07S3b_kZUs7Fe{!F0jDv0yBKT-92Z{%=f)>&YAh`cj3qCYw5q6SUCf#F_uskIrfroMM9TLO*zst6$llMcW%z zsJRAKEz{FqkEbIz$#ru*`m5j9P&+FU&GQZ-%_2aHIo^Pzgfx8qz6z8iQj0kY=C>&c zQYvO;^WJVY964T(&y~*`9N5uc+zj*}RyXunphjgRb~?rIlP5J?WDdKBg%Z%ews>fj zX2$++lwzy}PyfTu@yhv1H1{Q7?Y66#EH4SpD-LRqPIv{cv0EB;R7H=xVcq(O7?9sQ z^k(P1%#wmt>o*`r%Nz{87Cfu5fiGKA&ebDAz-tDh;rOZs`zgYX`j@P%EG5819K8*9 z@7}HWNfk2bTr3sq!A}vtr4TlnN;uCkk=xQ`a5Jf}{p2~=b9K5^T(@OQiDeICO_B#;+TXXnj}-gn?|cp3e( zgpqrTMgGGAWTvNZGn4rb6HL%>=f*2s48J1wesS$ZANM%ADEP|Y1~u0|vE#yBGiYTs(g8 zg*+q%NY)!c$V2LSN`e#&d00)w2sQFJ^}@5bu>A*^=e<|`h_Iu*-HL={GYU$xfvU@B zy?jLxGW_?go2sk5*D#zY18ap|d||nIx|PjnVa+3oz3C{PKY9kOZX@pe?qA}jWx2G; z)WcKb#2-xE3GiD+YUXoPaX>2uIIX7Yipopst?ZEdLV`bDG$T& zL-0iNH{1DsSZ=rjn!HR#*qMi(r~e2~Y75-dPC4so&KSjll)G2>Ly-?Vg}(E4SZ=)y zn#@#q`nlWm8#?IPTi`MDz}3_o1%eciekU`$GyhV@>o%M|=VbCi?_KG(dC+%GxJxrx z?*{)j&}8r0DPGs#ir@UM5=U!kCXJ8~De67YXF+l?3ubpbRCD|Iz<9oeAXa*#G2D@cfBBZ2S7(U|T^TOO7Gx zhJSP7G84g`q_IQ7La$lb@bj_rOPHsN+=tt@Z&y-x#0KTef5^a7c`CX!&?&`0Elu=m zW+sR1pzt)g%cJC~2{zybm6Wh1v-AuHgWP8qF1+IwH=_vBH6C&6b;zZ;I$djr1Sw8q z#!GfIo%0~&8Us?9?op>KfP)N{5vb#FDGGeT*4Ts(tGb~o$ip{w6`?GffigG;J7^KM zk#pROzdeCZ_g_Tq?KxP)(E1S-`U0~O)Y+-6>otkE@%HU_^2e{Cui<0->~DXK2flS1 zDrown7YTW5&)}UuJc)gm*Wqt}dOOv`l)B!!jQ+z<;>E)ixP7J9m#3?0FaGoS(+a^w z8{EPnxB-`K6r@IJ+lShb--1Md3FLqIuTS96IST*o0^Iq) z*M}#N|Kqbb@gWn)v$@HLH^EWiM#GU0vHyq@3%(R!^%Sr%BQ}5Q`$%H~c~eDcz?#v1 zQsh3&%ge*Ug|X!SO7s4727w{CvqR8`_Pb;@)8~5!_&!JTs?F3Qb*T&LG&PgV)7Qv< z<<4o$#C)ViF0UE1TKV&8-NtXvzlYIV{{Ckt_ua{LS_gewR&6fE+C|BT(+>%$nHh2D zU0sc1Z`olJ{x7qj_z%Y<*wG+o{pazOZKv_r+ch|I_$562)8j~@Z7|)?VeRQa!^I0| zi7QupgEFtW85_)du(zWM|MTxZ!2wFE*+wgBYN~L&o;%)HjxX$5I7(|Xd>J%0nc9>r zr1Mmpvks5_!w>Pcp%>bXU&CK)pft?m=g^1W|MW*_Seb|VqfG95s?ys~xE3dxOx*n0 z&3NmvJ*ayBN&K+&eH51zG0#F5sxLL7yR!%D9{d-4aiLFF=IuTh-n=z~|6k9L;UX0J zFMjb0#pc|?{0Y%sTwT44(no=UyCWVZ>gs#%6TU6DQ0E?z{X)I6su8|mZYFZ`a92a6 zpW>}MLx8xbS@6(NSMcTTWzdP;A1OSE?j5x)Pz|hs+#TJlM@QI*`xlK3jG#~15>v*& zhTb>#4)Wo;)Cv!G!Gu`i7W{JKLKULl-`KrQ;V8}aQa0+L&(k2kg?THK2aPXnn%#&T zQ4^aEO|DfBYsOT|6S%|>k5QjFCVbl6s8JMkZP7Sqh=U2z^C?q3FMiy(+{PtrVBW8t_JOW;wEC^ z_Pi1-swl=_E_YE^NwR)sAc1@WYEOQO)Ad()A_3X+7hq|zH!`QIw+U6%r}5%B8&g+M z&_8zqXX(Uma~e=u!RW8zmFKdep^84Ymm6v7$v(AaSn;>z3Iwcz^{3FJ?muO3VwU%Ft)7zyOPye%uxFoFDjC4qc86UeWf=jF@SRw$n~F1DU~ z?m2FFT9qJ4!lELUiWHz?X|!USR#g%=|GvU`AweznVZD>BA4{e+Ml33%Ngw@x$1`2@ zt3Lf-#Rjq>BXPdv2CTmssEXzxaRx^3<9XpXrBs`Kil()PDX&Jg@wwP}&z~bc?^V3^ z()&2iP?>`R$<@`utGDB`H(o1zz8UFj5x)9^Z^QWXvv}v!2{gB~!eqOmB+1QKb`$R2 zbvv%g8?p`b>K=qpHoVw5&81`~4i~tLWw`6J8}JWL@5RNVdqHmvlrH`fwDAjY-#2#Q zXOBFO%1;l|Pvr=%w5zdV(_&nD?+ACFM+EL6V=NlmVfoAsYIdS?^0n?g z0^5o6jA+*hPmisa;>+Rfd=>OmltrOchK0R!P##|)m7UnYY9Q&hb2G!w{kl22LtC%ALVBBTu_kk`-`BpvgY@jcA| zLf$vE75kt41)lw=n*M7&6n4Z|F_gX~fq7;YfFNieamLA3yu$tEdsL1eQa8{1qDFv?MFRO7zl$ILNd>jS!O`IDS^VFNy-)m1 zNg&_B1oC!;JwCUjx8nNy@l7UTRk-tOS4kjW#RT$v>*sQUnn*BwLV3LEz->lXyFQ5jHV5tVt~7-A-I$WbSA8_j7ZQu@ZP}XwHiu!Bgyd z%7T=Tnv!!D;<{UsFn{S*P96*|&h1kT^W^A_7NjuXYWxF@X`+nU;7 z)y6~9&s+q$I0{DjC@o^xa{_uy?BgLb1*jm|$YajeSSWM%=jN&1o3$#^U zcgI)p!^PXs+s{Qe`_GzR$U7|#OK-dzf1SS?ZB`WwDykE82`I>o$F0{j!)+=YG~p=N zb|3zsxEq!dUN=z2IwnpT3%22hKU{+Nq^!Z+OG8QlHt+l#@+;QkN@p)4oKf9H?TMN@ zZHY|0Swf*pDdY0yJspn!#ctX9_3QE5-~KkL1u4e`1}dnphO4~?&SWNcKEg!>$Iqke z#B!l41Xv0k#(opjP7Spky|5oY$CWXUTendV8Fq7o1G=!ZVLN*c4w_dw`>CNxqyG!} zax)yIuyqy!2-ilu$F}oIO|2 zZ1~(IVfi2u$ZtT}hy?OtE)&l6z6A2M?>~lL{oy@Sw^~uS<|bUfjL}3Jj^d?P_M=)= zkDmXVgCGC>Ez~)&a9(M@ScQvR7Bp1z@y%L~o401+?5o}c^36;jzvZeQpxBa)1*K*5 z^{mD@l9HTLj0G7cni5(V4p_)S2l4vB!*CTY$Cj(FMozLC7e9C&Z=b9~RrA9*cdSRRj>PhQ3!KK_&mxe0PQRNhFca&COK=sQmnVBr{K-)b4nP zQ2s9w7!LtQjSZ(BbHLi@hMm(f_al^PR%3C%kfO!B?{S?;1#y_CsPV`NcwC#9iCeC+ z;MaRw@zOKLaDWMpHGIE{9nHRu9#l3tkbQMI3g{0U>;6#!h@n|KAS{7Tsu<`XE+rQg zN!hgiVQwSZJ&Lg38nMt45p4XBQd4NkEnAG764v8>mzp*=Zbs_U(iBL|dV@ECnu)yD zu4Ts~ca62kS-cY2;>@t^WJ=~~g;<-M0|%3SiEU@SV*W+pDItq(r8DP}a51M=gSt^2 z`zp#~FasX(fe@Fo5bKy{M&-AN9qX7tLmQWawM^`$B7Z{ARtmqHle4jKWu`J|D2rik z8>nf}DtHrrN*R|o@9A*;pPik}tm9Y0)!fAG5O(o!hg9q~MzK@zAM9C0;80^WE|KV)B*#F?7|LeAke|!JEq0`}m(?hc}cGN_7>VVSNdo z?}Rcqn1jv3XgeB)y;bgHg@pk=7}Zi7)EDQWE$t)dFJ=dg)gbMm5H@(x*k9~TF0|7P zQsZx<#j38pA*_<=m>cP$HYVWi`!DmZ>7(V6;Z% z9t$FYysHVX|M#1yy3&WtYrcZ-erYSRnJdTLw+8d+$M(06y^nMIpTU8K>#;3|n>l=_ zeF@}~L<0HGZes#@6BEdr@%_Jf9PRZV<5MP(pI@*HcYZbxx?{T)L2B6zpTVD$o2YTr zA&sgXUB(LB`<*o86qO)1GX-Ye6WvSm(D}W;#r`W7aPCS!1u3towl7({FLrLQG?bT7 zIHGp$#s6jkd4^A4cIThtzT3SCxsGO*Nm~jV=(ceEogY>nG+(%z2 zcbgln?>W(4>B8A3)L8a)J&ZFktqHq4@i$)48*tUlOW=yH#Or&SaEclOuL8i zc^lUG6n_Z(+`?9MMvL!p3BFTZ2199QX3`8!jrLk@d5%$hJC;d{uSIX=L3mmTtg`M5 zy}vP<5AKlCRgnGhJ}~5^a3P-#dv6!In`_4GV~DS<=&d4OwZ5Aw$bQCbb)thIw9RKk zn;r+#q5`;Se%RYyJ7(j9d@LClpIY%Ch0xEKtxonJ!@%BaM%=BuMMk_{oR=Ip|F6uj z&ZgrsM?CD4?QTlfaZ+5Eh0TR77>pj+Y{DSXThxik*tk9sCi?I=czoy#7u<%y<+HE4 z{G0%RkP^uE)ZrkLthzlZxb3c;SXeByChQG=u3bS3=PWVG^szM@CRfuza4t6ppL=+)M^tG$fqj_ zZD8Vkl%5@r zTy98d)S{iqtP>`4O_*38qnQ!Qj4^7+LlS}MM1YG8x6=j{4QNfNIkXtd3)q`6n;OUS zR%ogDjP~Mm_Q8;3hK8B#-G=sn1>7<)}e%g2wOj?eOWx$MR zoW6`%+2o^-d_=aG%Cw+dGOBnM(D{`RANqwI9o77@CbFv>M?)?Ch2i6Uqz>0fd8e3> z$Ef$i7rwg+r8BYfI10hoJ)n+D^h+Sm``DY=eN2X|jptD(G{f{y%g;$3vL@i}je%AN zskB}dqtntVL~?Eovv{{aOeo4p<%XPh)KrE9&~lH(w_va-SRvG~P)t{S#a4l@U4JENHP z(}$Pib}ofEbkbqE{u-w4P;P>#XU)YZqSieh(FC2AEXF?0Ms}!b;-Nm60^_E2Ox=-1 z#i#G?je2&56UgV;cIX%!=PtsnW}qh%P1T#Z`F}DE>eOr)x2}s?VbR019m0n(bvs>J zR#I8P=T(e?*qbor(8qcsO^aXPGb|*PC@JE-W}+K|gH}h)jXkiERxK0F=N6ifoMK=Q ziYOs83}i?_Dhwb-a}&cR>1ZUBZvwSWM9t#MfDx!{z0CosbUON>V-f|=NL53?t0Hq! ztLNm&x1H18F)?2*ngSY(oVX&pupbL4HD7+B*sX07^5LTSl!1IlTpT2fV@>y}I5pzu zi3KvFxHFnxq>Gz))t+pDjke-qDV|_qK9B)xT$4~+h)9+rN`JovcZ@zfqL%zQ5&;$c zX1!0B4Tq0k3Yb9NX|pQ%2u0LAlVQZ2q%y!l>o_Gw`lw`*;!WmXUkFYkDH-}rJBgtm z{MK^lDg5lQS5R4d1qt)lV*SDbB*oGE{rnjm_qultt3URSiD~d~#pP`-1*XZJyu%v^_>9=QA4 z;OOn9Npv&%-t0l#owq`h6y4gJ@o=+!bO`pwPnoPehf#m?;IcO`okt&B-BoaOTmtrZ zV7hiatr((kSv(LX+|9>N7cizJVJl@woHeMOc)slRi>2JT9`k*@yriEU}oR7ZC-CcxLR*2*{;QZ>IlQ zKeV18w`c>lHoYgE_I~OP7y-a2j9F2nT&p=*D`A9yMG8l zkQ!(%z=ud6FZ_%}0{QZd+p%$s1oFCRP9Se)R1e`NB?3@9`Q(#$@WBTapQ!+3N98H& zn;$@5#6U=9ZZuW8;p}9vBoQVwo$t*gI~-@v!hW_gsuQjYVC@HvQQO4C@OccXQd0+a zlbD<7lM~1JIh6v3mig5_-cJqN7O2K`$%x7!Vlb<2SWg~9{F+Sq$}|1Jc{QBfe6C2Y zCzJdoGD0R(5$G2$fHqr1Y?$1J!E|x2Wq=u-%7M;5SW%m9M9vZsR$LJ8LHDQBSidh) zd~gFLTJ~YN>H5^uRXBX1k3qx|uxV8WG8s*$zpEQ34>aSXNHqUcJpStI#mHdP;#e<{ zUrEF|f|CBJA;1YoXr$EiPqW(?Vz_r;JARy2om`~rsPXWK7}il)64Fd=v5I zqIsiNlM`JpZ~?KJJ`KXq-`3wgF&|Xp8w_#E1SPJG#v*cZQrBl(N)rH%B@@f{SOoc+bFq%0vKpiRb&cQAqck6uG>!$_?=z3$6kVf$ z`B+joN)ii#C^K@)nLhqf8xDV31=m&SOdVx~#^^$GHH9c{-I_C)d#b#cyR|Ab9eoM! zw*=8_2vz(O$iKh@@>er~e40;IR1(Nn(RXBtHzHvO?S@)a_)7`1zq1rJKKS4RY~8vw z)FvWYU-%Q*FV(@cA|1WQTcOQd4de1+KBI2*zV;H_rB~oi>4Np}v8WfMY$s2{ydnYp z4U9H>*$mUwn`w)sf%WL8OgnNM&Ul(_+a_WjTT4gh*$eO(ukbG()=#=%SaJ=F zDQV1I$()F9zYfnlj+3DYBHFGdgYVlY(@LpQ^eEV3$NAk()IHjd)+Ejd!s>!^fve4h z&N`a-Z8IRAucKjeMTDLX+m%inVE`pfX+FMj8zXXOn_y=2WjBLxtzVmiH-B>!dyikn z<^Ce&y%Vd}qCR+I>uK;&EkC0a0cC$DG}?R`Df&F=P27F81a>?Y=5h{dZgd`D+cb&( zLZfbs+M>@O3g2)-=+ko{q%$T?$d`tE4cABo*-sFpjII(|+loetjp$8Da858j8VbcW zYcDl%>AWJeen!(dO-Cq%=q#LWW@N?@7zDh&vl~HX~M3rEJUfh84o{R zhdnQzK(Dm|58RMGB0^f=Hm3=>7;jdC+^c;FF=TZFQ zl{e7aZNUS7_aJj0(pTuzIoOUpgCG8~223B1qbJXxPPk%)P$r~7lZ9J8Jbhz$U0t+w z!^S+ZZQHh;#x@($QINv zK3!G^Lw}B>(5!gS45s%(D|U?_ntfPPl&}%3oYQGisk}iv#_Rbiq7vBh7HDcj29==( zQ0}9kim_eh(fouuUQp$F8MC-%JWep!gbGe?v84copv$iC&=X+92MsPU4Vq*jsz;2BDNH!{J!lrN=$fA}$HM%Bfek;P zMK2qHMs36Fh-Gee>c>Vm(PJqRce?dp$X@$SwOYhU0s?uKu}eplwQzT^eZrQATx?K< zx1&=02h?x!$ejJE{VzWUUP=vz3dzHQ7ZeD+j)EVsy!?@I$>Dc@(a&CyUT-KE%C1yw zyu^dcBCs6wEqi-DOHfL!PV#cHBfkHo?)yD77XC!KL-ZHzy=QxIw@_nhzhv?>jRT9O zK0+!@g^d+xLhktd0)pQ)uGfI*q~9%Nm3t>gP#E+9M%8xg^mc0u^g)cK!-UT>EP0Ig zUR#Uf-Zfeyd%8o2M_JY|txeCR2Yct|)5^ML zL>Ix*jFdOiYnuVxwu^wBz?a|6Mk&Vi?iT;xEQeT93yO6lc5RK;{lRj6jd733P2aqM z;7hF6&GH}phd=YcdpcpJXAI~ZJ`_~w0VXOOe=I;fb_vMdOXRaS1Axb6%x== zMD|?og$^bCGr9@*8yMl|3lO%9lj#-HaWo8`4nX~(wXvX#X49=Q$ObHmWe zc$RI&QuFi=D>p(tJufCiJ4H_0|G-(M71};e&6jf_w)17C9fJTtp8c6$z?}&ooA)Oe;m6|ZD?^VH(FZN5hbijaAcnqx88DO;8+JC z{+IuE+L6~#iN`a&w)?YNbP?K-F9oShvpP_%jLIIQnF^R3;^heDVBajrlE;?{R@me* z_r3mF{{*~DG#6COPaT|7J3G4@NXZK6Nm11&0ZW@;RAuWw%>`bO2hOy`$>O&kXSR)? zH5@;o4<~EvO3VP6V+yp-B1{ngp!&xz(<<~mz?tr;u0`!5`JIZKgnjk;wkT3MX$Pt}4M+A~t zjTz`(m)Fy9ETI_DxMN*xh0~40Ps0hM>5r>R9PlBf#k^o)fcd8GheMOIVA3yEcYdqx zctH&nnn{_&BZ^fu8n7zz!&Ol;lG zva+x?#Xc`mJB=~OfuMJb`2ukBY8<__(e`7M)Y$Tr;@lY8h}k=Kcz5=kFDH3Obd{cb?hrI&MD$Z&H;FZkGkauD`K~r? zcPg7W7hzdfxQ;M!^mkhlpG`JdVr7lqWHEWoQ}r~Y0V?!?24ii|N(7##tLhpjfL1RC zmtHnyC|**!CToeL!GviJ2D4njS#Yf}(%6p(=2`bZWNPfQC;k+T)RQ_wzDa#+uxpex8zkM&Hw&wNQ_dDvNcRG02iI15~Es4>r7b}HNc zSa^G3rNjj$mnU?OsIHql_GxutSnLR?5UT#47Qj)CX4)P9%z;v2;qHgVN?f;sUYL~v zC~J8+2Qfat0#=Is8TcicFJ*^aPj^(&Q{{zZ}Ptt06)X)dI_1nDc$?Nc|jJ}D)F z3QqBx&M$bl%2^R!J&%MrG#}5;19A%#OI@Z5A%e^r#p94VZLF`dj;&DCuU(Vs$(wVi zqewpk$h%fpb`q@xINav*9I?^zI_A+}_Zox*V@c_LHjWfy2_j5K?%W|J4-jA2314~vm~MLsL3MD;v1-Lh z!w@;4BRv6n_h9|A&-^C^Ta3_FWi*dWOPkcMOE}{Cg?lWecmoQOqg#PqPFFUq}dX!j%E=mPxUo=cwDCvn7dOGV`<%O0Y zR8K4nl0FQ$2J$j0=XNYZH>J4Ifq|DjALl;~%O-iQ`SweJBql;%$W1bCI>VoXdk2a? zU~PdJ-;uo{Ww4qX!*5LDlCTxtW-Ij#JpG1pCnQBN)eq`flr_vdJxp6|Y;1LK%mS83 z&l+$30XQZ>lcVY(py`#_o^hQ4esqO$Oa*re7hcj~Cp-KNk1Y_g5+i3nY6JM0WNvav zwo&s#YgEbk^H25S7RYN-4ZKF?{KfthPQ7w(^b@~@4tKR7^G3@{~ zWNK}-e^XTkHk`cVhIOEj1;_Uzitg!jnIE%~r?gxr)O>J_uwxpX9ptkVH85^B4tL6# z14BTsIYal;fXT5lqme99bS4n-6PiDmJeavheS&nLobH5WNl+j4P)Nwav-~K{V#&(z zOjo>z81l_6kz>C1HlUK~9ICGbQ-J=&CE~{kD_-akv)mgwiJ^k4zjtG_Qx~^(T!>#` z@h?wNh}Wv7ZbPxnH-N7b7P0QdKx`$;UZRqKNR`0vfZ6Z3F%Qo}Ne{JixQ?=(gO>uo z_4y_TXX4vMREjD=ybxz=UW>*#H!Ak5Sh?_ z1<>BKTWd`Mwfb_K+1YoiqPiH9(f8JK3nyFKz$l*ZMhecU9YmxV^giPhZe~BZbzX%* z#tUSBVDYBbmxvN_f+r7oIjE6n$)xd}!KN#6T4QlPUJ)28osdnpsLSefVr^m|3fiJx z(QVI$*E7y=HJL>-mrbzD+puELrPwpa<8efa(>nVAN&(4zON-*^v!H4saI^%LSVpum zK~#oJ^aKJ@Dtbh#vGn|(dl-5#-7>7kR|bqU+kLZ(=I`N=_G^!`0AQaiXrymP2qPlXnP7USt93hC=MULH>XmpF7gw?JT%Q%vqj%@w z+tT8jf^ZfxYv_9G=iJ3T@3HMki_(;ofB9>>=?#bV{PpK!hH1SHqR>u;`U3;r>h7Y2 zB}s`2O;(Kh(`1SP6jOZzZ)ME1-?gMLa9xgtqhy=$_<(3jcih5i-+E)xL#%d@Bd?`A z)a+SA+;m<@gL6%lsk3cl$Z>p^^C3BwM)KvA`S75Bb4OYBy}-8Q$*Jx>p~4#*t8TiN zNQEg;zY#oa!PI2`9FeToi(=K`>~h|{yNRF?TWoC2qt)~WFDeXTs;VwMyfjd~Mho64 zG=P6E3|PALjo42fKY%9sUB#!)>=ypdOo~QEIt}sQ-X6~H_TTh_6=o%#UfLAdyB}~d zV9x6sD=1CI3tLm8(n85L$m;IB7yaYB^msRYx)`GKEczj+QE9dFbFy&kgyiUuDLY?U zLw;eu1XI19WiHLXPv_Q4f|G(Gi~9=+!jaSK*q&Uqvl7wC^Ar-#QOHj=V$P~BVE=B% z!W)psuG&ncw25Yr#InU>jcX8^5Zzla6~mz^Jh_>vQ>d6q5^Ghzia^+iXDk&9Q@49F-f?)HkkR=|&LK2TsgaMpn8 zZzRKz_&|S582ICS1uRoHHrZAyMQTm0hP8++%q}BB^1_j=hSUmV8 zZW>%tRDngD5jH=3=cv$>xP64XriC#QLm{hY1zxp?Qf*MV;>ZME@4Xez3&Fuv6dR@J zM{Z!uy81HeI7xo@=nMq)FsTHJ0|so~vTV6?<=QFURoU zhCen{ArqF5^Pr>F8)lK%AHV$;o)7QWSNu!{q0AY{wk)`B1<@*7!Pr9C`~m$;U?iJaLmP3wPOsitsuF~#kB99_se{1o+hH+;J%*VQRVDWUT#{QJU!7nsu zdP-3_X_y-E;V|jzcP6OQDSO+}wr z-if-NK!zsqi8_i!$k3jJqoIb`-Ua=Nh#WHNt7`d+UAeTiH6{DFf5nfWo|VsVMkWHP zT&sJAwJD3rxTjf5Cs&M|j@pBnFz@x-F@Y<1?G=9I zVUgJ+#t>g%mH*HMX#D*JK$Cue!^WuM7Ct@{_B3qu)G_t&RPk-a-v-faj@@&a%?sfJ zK4LaYGXfLpxmLE}X_~A98rg>zT&>(};H(5CaEF#`-d%%8Z6X&z9~4Af?HVJJLF~fR zuu3CjY49HHmdwG$^$M{8fKtglIGt)HiB!ftJKJ6o1)aeFeqw& zK*nQc{JiSX-?qyJn`5vvlaVryygvu1A*lRV51yn*2wB01dAe%Chiq$)%(|`3Zdn!} z9B}zKeflHQoSpw<6BUdMDI*&v52a?*h`wRIoWR{vxuf{iX{o-7dLOM%C>=L4n$p1D z*>AWT^JAwy@DYuLzrT~xmPrZ&Y*~k?7ZU9vdO4w@=?tP(Ja!m;iYP@b;n4?+0pF{~ z8$4A&ArSGh;Ntk3%6yXY*=E>S$#LY9qXLE7vypx!s0K5?3Ty+Te z5i9GEvJvgiQpSEqG5GL6+Ad7_ZU~7w0jivLgXJq9)Q`40YNn%oXj;j>n{jz(aQI$e zJXp>N>x4N}@O0@we#j8fTPZAf@G);S8ELREuf;-SAMv3pJFxsco7!pSw_$&jSpg^- z7B+kp%X4>A((qQZ77Wh5Hq}Ye(ZJHW6h9oGyI^|T8en3DcjuYFXT&f}72hnUgEL(; zPTZ0(o`j^k&l*`bijM?R%?t9A>x`NCCgzP+azaK_s3gJTj5A*;56vj)*OFjV4SjzL zGwx_HxtztPJ9SAEpvcJcxghl!_)9}70uL1K07xT)hF?QRE$uPTLKH9of4@g0(=I1N zj4<+}H7miUT0=Rz3bIj#vGF@#HyBC?H1By_X=F#gNI{*xf#`}sSB}UNdgSM5WkvWD zIS;#^bf~m)B}3S5#jExH5hB|n-?Mk0Jv_{FdxAcxhm%FXQ}CvBe9&2SkVRS?BuQ$1|7 z#ONafZDQg7lhk4L{#fEF4x_9xprFTx0NUV#Y{NL%Yq!B^ywAhCJ~BFD&g#cazqm)y z)4>Z8;pu(4PNPVB`9|I=mGcYg4;*M{N>o1c$;{)s1c0182bP-wFQ|l$;3#`NzdraV zm&Ya6yMNdsKq5OAVtzQL7Jmg%O@(ZR2E6cw!}j&;e5dlMxAP401bwPhojOrw^yWpG zabG;^rKGC%?{?VKW^TVNnl}V~MKyJ7QYmJMH3!pfg8Odlu&kxmf?wYfj!QnVWcUnv z0t$Q?B21TkzA#LgxN_g@hQB_qcG%G`U*{*LdjSUI3>~LVeCS^$-jAO!$z$k8_2les1M`(T8LgqyW|-UeoK+cVgsts9@xP z86R4;2<}0N_jV?KKGWzI4eDa?P$|D@`h?n)eGy_`+$V1L``!O0D0n zR~pFQ54%DnS^mIH1^FusU;xMRfR#0LNg*fHG&j38H&DGKL4k`3iu%$rFd%B07bLa+ z(eZwpM%~3u$ckt3a=gGJXW|t-zTe;s4bLtk^UxzEL{4J@Z;h#rWD()1iHFu7L7ZX~ zMLa)m+sOFy_@+pb^fv5Le+_}ZZ2qG(q$J*O8ZR&|0)6p7L}oHp{BqG)R@LVx;JZr- zk|5|U+e{=i4SdGJ0mvs9DlIGdA3#O)e5-qmn6BXEA59E6Je4F;w#)NDeNvds?7*cC z2$|fbHY_jtM`7LMu$pb%@ctrtRRV#4J-RzbpAvX`K3_Nj{O;h;j=O{c^WL)Szlh*6 zW-Dh>Lew^jQ`w>jZyC6#O3Vs9b8;GinWPG}*oI z4~ng3*Xt31B2sxNXXOiZzvar^JnBRZ>_~Q+6k$4B5yInFz8SV&7(~uZ0MIuI;>L8g z9Lka31o#2L3=XxN!G4SDi;HaCc^n9>Y-$fH6wgNVJrOdsoe{r;kFORY8Z=wjZH<_R z%Vu5H;3qra9FXB~jCBMSMc~#XlcuhZIGi4|XQi~e)iUquyzzamc8ZAAA!O>2#fryT zJ-kr)eLLa7{`RSu674NZSey_~wU8RXKs7ct8Ynp;NJrh4&O~;q5+kicbzZ+}8yX7A zG8RU`jB!OsB7-!(rd5y&ccc`aCQ6WkHhc%koDAjX*RNB~ibltgMz-W}-E{pPO&(Mq ze|dFf{y8wS236cMw$ybqoEeC8AF4GyI@3$X#z>4&hT~z!PDF^`xllw}L`F7E z-b~7X5)hBXDDR{yghr8_(n2R(AQDAf9s^@(V`3W7D+(13e#qT~?B(iLpo(TmBDxl0 zLC?jNZ>txXCy9e4D=hjG?atNOng-(x&XzF<_QBv95cRC6><9%iJAokw_x%|r`H=(@ zyF^PO%`;4EkgwHc-z5@7b~h+I{yI0DziSAJ1Y%(PH-0O62BC8^F{J(F zsaB_R8Eo#1{`irsc;_e`+Y>}GR32ZgX}mZ>{ODIgSu=u zZ;H?%7k{p@{)khODbz*!!|?I(1r6e04N-Rn0zPtLv`jhdYf)dsfOY{27Ssq?TT6?3 zA!9AS=*?Y^i2cI-uDN~b6e zBOJdBV%e2IkEvo1&3o%T-?EgY&ezL z#t80G4hw`kSZ1L_uHvQ%P?F$A-$AyGbQEcGw#R7wNrtNOHgi7>PLQ-X4Y|?JT>2XE zs<{K375}`8_VkO=XZ&FfDc>_;ME4f;#7A~k2z}h$uMyJnpiazU?Q#xR#pkYE)ASE< zj+|qnE=V`DfQQrI#A#Ftw5O7UC-8Zp(F7kXP@=~T5|dd<0$!UG6eWOCoG`+-M@3(7 ziZ&=82G=NnU?~rjW#VsZ*CcvQ@UR0rVC0bdeXkr+^U^mns=Fpgni7m3I0+;zH!op# z+I%2S1|N7DV4w{2JU~m^0rdwm>318CXX2fOaPOsa-mVP~_sRBoQZC?CwBV%=tbA7V zHrXNpyPT?z!;QggN1B;n6FK(i?}_A;Ib=W|mZ4dDQrCaC_V1j8loV%MKG^sG zaO%2qkaOq0Yk+~9ZbqJws`OUiO-bf4ALVa;pf_;uN}-+lKTq|4w-as!z5t0jj)56w zT?jtp{C!MjIlt%Q+m^+NaK&T{ZW0td%HoBrWY&VD98^LjBRc4~_`v99XdSSYl*Qja zXm%fWCUbIT8vSY#OVD;)7u@ITyRPFnDZD+Q@&`hx@Mj{FD0TqYcZ8jfr|mGPX2Pg{ z?l;&Uia#+sJ0{bO_+K`r;8d_fvctRqtOo|*%2+H1pTGQEs_^%-unOc<^ z{?}hkD4ATCJK8z|3t@k9h;pnp7ZZvG=zz~hEnNO(NHbD=N-fRAB&GP&D3hQoOapta z7>S&Bq#M|ly{P3$6=pBQZ1{N&H<~Ta7s}YC42Psy|LXSn=Mx(Y>7{BT)~tlM7S!+h ze)u)&=ML-Uu0}uV(LYk-b}$q!#NLM)c5?0M5m1%t(}}=?Yte#x*_?%*yT{5hb_bN3 z0rOCrRqC|#qav1uda`#!5vfqYI3P4hSRGkYSa2QH!dr7TCZ1^)Ib0=18^0B>ViRbp z9O4pe6o?tmky;zSOnI9-AVj2)RA9}KK_SXd zDfu2GZuBbfatf?#Y1M)zI)E}o9qV;n2FMUp6XEn#oNs^mz2^#s6E8V{#LD_sP*f^* z!nP@alE!E9e_vMv6i5@g-NOYG17DQ5SUrj%_=Z(#V$g(mz<4U$YHF)TyW~8UnMMK7 zfXXdr6R&4CL9KLjC@wEVqb+a8+KNHmyRaEgTVL&n%8|6^=!O?>>wuxQag-$QHCx-x z939HVu}3PQDqOr^;;Fhku&`Y>Vm#4=4dYLi~p>)e~9WTwMC>T4;QgBO)RiB1cZm zfYI`N%r&j8zT-z)VTlNU2e4b{y!z9IlBMsk)<~%Yd;5KPv#iP{G^Ul(D3S|o0=*+& zW?J#gt8%kdaX#|76SOEF&zxRQycAw?a!kZSey)~h$n>%|TBXsj(mAqjh~r4^aZH33q_) z_{1l{R}8$DQ`zc8glulZ+?`pG(3Y_^q%kF&X(y@Rh0w#aHG~I_T$Fk4`OWM(gMI=} z(0kRdaGz8h_)EhB&oB1;p|J^taJ7XE9Rvt=@n>>ov@4z%_#0U@KqY~nFkkojHHCE@ zi1%P28LLzK^Xz*BJq;k@JxUjxe%~b8br>0RgAT`7f85|8MoJF&dNDZd^b+U|TJu5j zs@@<$G~`pe5Ojz42<-PCPU)@a0zTm!C3U>PKBqTjlKF#*$KrTj)PN>59!eAubnoNj zDK;9vpOg$GV3e4UAgX+q0iwKom&3e9T_s+5dN$9X8xxgcT36IqhuM<{=jOJ-E7{9% zYz>7J2_ql*R+GoEx*h)otD>E=y%vpB$u9JXbn8+}+NchB!pWB2Fs`AXfRZ?Y17 zN3A`_V{UbSpd80uwOIK{C4UUZZ%@KNQiRhY8_q^Af!EbFI-FF&o6tQE0$bq>96o;e zd!2GIQx)tGvSzZi{ai}E$&{7ltl-NQy`Y6|>G#*FeZg~BcPB9>*A%V5qOtWQofmyF z^V~M(g~aI}LH^zr=97xj;{9QQ;c*anpeFcA0{6v)hu=frv9Uq-3^S5U{V(V3`N9bB zX8KI8Bz!*5AR@C0oKGMfl*$+MzDQn)s2Fkrwi(g)wV$>lD#k6im$d_P+H?08C(N%; z5B2^q%;h~gv#|tvDb|}nu+z(gbX9^!wKv^&pfJ<~%&9~iE4bZ^2UpQK^BffFu&+&GVN()(e-lSAb8-X9CF!Y|u@nz;w51iTI`o2(IjJ-j!AH#t=VFrC&EG`?Y*Mn*{dLs{I);UU{>)9IQ!BjW|vlrA> zVsiQ-oCS8$kxF{#lHQohT>w<;43->zTQ55oC{L8Ldb zTsRVKy+oHs*o0wTfo&O_MgWi_a;2(}`OoKLi3rkuo^Wv+e~iVFg4PB2Yr28!zb_N@ z>7#9B%nAkxNGQkON{IL(VuRSn2cE2V4vgnToeG(xhV{zI03nnFn=WG<%TT5wtB`EuR-TF9D) zK8ts}6IT2BxP{><<2wI4!394&1z%P5y6V)I4_yOBF+*P-C%dx_?oDZ*# z^G|ARD=kvv+8&DRVp@2+y>RVnn%AmJm0XEFlX-GeR9=*?Y5aWyAP5(h1yeESQ1=I(neJ z_{)^96{E6bL2&{SD2d(1G<&+t!z$$fvX>SGJt<5ys4^I&g{%~KIid6J&!cES_`tGS zCg`^h!5&PePNyN-&&C2F0RY9W+R zrVTjN7Mo31>rZB?M1!*numKDU0hx5b1yc96>u+lTwtvcjIR zF}FG`jj+x(*+q2;3qa+STE$fW<=(i?YTY~WFW+BMc-%H07{2NR>4(Uo%XJ^Yj&EXIqX(kP}R-S z^3ow~mCnb&o(~qd491ve_%Jq8r}mPZvMDv&0e33Vm^l<%5hV6q(iu9fpX_sk8!@@O zcf5L*v-{mW?F193@cqhqzbwUjDMZDT<0DPBjr(XI%Ig#pMo2+HkY>_4=? zJwAmZ7#(eC!;{C?TMgs&5lb%JX~1G{I1V7md>5EAJyMUH@Z&yTzhsvi*jC zCPRl}f>916QRJ_~OEveuMi>{NL#<|dD9)+^ZI$e-O)Uk>r}zU?LNkNk6k>{~Rx611 z8)Z;g*eE5&h>^oFL4ltQ=6&5(ox9V^W1~@a>dXm8shP3IxaKmWb8BMp;+wigW>T$p zz%>_2e<%)#-*YL)I8;RIL4ts8*xHsuTG!eDR`3hU5=I+g-^W> z3qT0{Uy6tX26dfXy?=iYF){ecHj!Yb+SgnQmrLID(w)Z|H-uPova(uimFbg2iAjqMGeeQ6h%wvmnFA0ToKaw>qP9gj|~_;MPuPl@KTag9FTkU*04-qlT6BCoi*2_@`N$8b7o!2s~5V* z3fsFiGI5en$=5Cy@uQwoJuQqVi7rkrw8XYh^pyk`78Zn2Ch8-jK_ntXUvW~2N5O>a z$_qonI>KOcSka!Q(S+CKxL=4Vcah*-xKKB}#Id z5xu`UzJKuJao)dAxL2XIUNLkBm}G-24Hvo}M8xgRU>YcL&1}wp#{omfiZ=VxV}|i* zV+{?b#evZC374~`5!Q@fGL>gwQnb4B=!M_=XcSf8a!b4vfVjo`J#0Sk+;Yj>C@(xB zDz!vIYF-0E&T|_L*fV4ACkL-V(e6bB#k^M;GV6TRdQ7vDY@Y8rd01@ehqu;Y>i|FF zJfF+&k4N^&`m&akixMz{6d$N+;SP*K14fDRq=u)~n+I&AgI8(b#bVJ{8~#HG!im6D z`#-I#*ZmXxOwU?>f*hZx7Nnk)zd8}@A|6-Pb{rWxVoyE~ej?GKzG|H*so{Ljj4^ZV zoHD-b8+wJjUlYAwmbK|IW!tOC8g}~rd-i%wlc@`kUtOui3$;R6+?w_ z0_CJmS65bj#jY5(_;c~d6t|Eth7(}$A+(5hJkWmt8y07IqBbmmod7TUk=ICBOq;`6 zwoe?rYW^_eR4>M9oj8`uh1a4(!+~}*K#{)~*D@`N8U;XVRinUtLxIH2+2!*ZJdIM8ov=b3vWtKZvf6Q6Vfhy} z>62dnD#Bc{aK=)#V1kEDMqq$F`w~{{jm?3>s|SpDF87D(D1He%NQr|pV(ks+0+ z7`W?d`Tx9OA8<%=Bx7`Srom^miBzM_IhZ0#QG^nf=R*R7{2--!(90#$nhpO+8Q6qO z3n48tq9ul@P<3Mo#E)WDxJp$aU}5<=74JL2^iFXQ+qXE=jF0z}EIIePAWzP0tX5xB z{OAGVI|yO-gM;I@>_EKbs-eAiR??v#@!IXU)-04r?Kp~?yZ+p!{w2*S?gtvvJ3~Q> z_ur?)Lj~jl+Or>yy*Z~m#Yp=ez5!8~lPg-V>j$3wV%KjLfWn!_Kd_m)((0bbU zyM6oJi_ed;b{7bgB+IE%)gpE22>#u-A_Y|)-o2ERLid((1NQKDIU^={0U8m6?)Q}J zneJP1er`A1Nn7~moe$@dxmMUr7}R{zuIe)d$J$94pD}V;xp}WU75M0=76zvA$g1u5 zU(#6abNqry9K@k<;#yXNEUN8_u(g5GmqPY&&sIT;XMyAKFAAOtWO z{4yDlovc)o(~DmRW^c(7djCR9#&#UdPIsnQT&}?L>JIw%V1&;1{_R>DC1OS%B&0i_ zjQ=!(D=7v_0H(Nqe=jG9r%_t@jN}s)L8I2-P-cRKi6}q0p2CkNmXGLjHx2_3!XDq!CFz{qAA*ZIVHX)I#N5ehnpDC@ zqYgjk+!obGpWNNq7*}Adx!uq@wbP1VKrbLHZeSO+M>K%ug<)c1l2=wHiCofbw~6fq zCmBfw$`s?D=Kmd?j%6xLGkNqM(Lsxo3&~qLdf}L6YORuq!Z5O5R2F=Dm zo+1hA)1WjS*|Uy~U}QR%E8t*5n0CA+@AcWRk%v;acu+*4p}T}d!l8OSMARz$h+?kN zK8v2;{l(AWly6gzp9<#{{?Pq8r^zAuMcS$0Y{u)^(TPueieqnKY`*N$kvPKV56k(k z%|=+RfJ-7P8YSyud+>X8>IsT#%5Ck5uhJB_Xz!1UJJ4$tVDVSu9(Q0GE>zg(Sj} zrRa~aH7dro-P&^G+>DTOH=ChHIhpiaslf|in|kg{zlR>vr4wQ}A8=0euaEu*SwLOd zLdIVHS=mr`yLi^KYEXAIJ?3rd?q?>A!P1YLJ|2ph2@9Wfj$caQcNtgE#ql*|O&3A^ za(6%#r#n1Sx@u0;SGmK1_+DQQ9*L zR2J>LqAFX=8!b*Cd(OltyBod=2rtF(p!7Y#;r@UkVQ^aX3UgCa!;x4#_q_-Thi#uH zIj-yAC@ymB>PEs?=nsfVrm%RIZ#-~*US=3vuJbxZ1;a5iBJ!#T%!L)HNTkaRk_-hko!I31C zT4?3rbH~+zNM%XySiGY5Uc zz*%Kt?65F%i>+2JujICn0OwY#^WY$%B8rzl2KjhV- zkLk`yx55#Ee~1*7n+XXg`zzV$4M7lcRUiFRjv00!4EawTj!9TpSpHOvACZDGMSjDG z{>@eG^UWtOaw3w;|8p*Axl^w0=iLBBVJ+rqWeG~R@Swb{>|kO&xR`O#vm!hz^2qg( zjB-;g{h%bfq-qd zmmC>Dtrmd(G7D~U?UtckC3+zvCmX7wIsW`Wb)s%5sWQ958gb{;Rfee}`m3Di-v-&m zV9_{#@T@d4$q5by$K`Q_d&4?X1uxKSbs*9g9_W;&IFM>oQC2SKsJtAOmX@t=EKk>5H~jj<@BuSNQzpo){}~7<;OFv#J`2smdz=>^U%T~?Wy>#JuLuZJ>nu&7?yv-=tf zqMuC6Sgv>>ux@J$rf_x?9uIMEZ;!B1`M=^m5vcHEQh^?WYyXu$X_i7(wN5~?j`0|I zXHUzDkk}QYXi`5)VA7FD8Hez&yD_^lDMEMAq8}nVvOQ77=enOp09)t{h|!Xn?L>fq%43#2Y|Rp zua39@v8~6wZ+8ip}k|C#2gEBk5t0E^a|3m3mVt{tR4BK%v_rIX(f813e5|WlKk*u7nioI&k z?SJ`{FL*FSVxutjpc;&Fkm4vqAMwomd=QOBHMq9!eUD9~tlhBoNrU{(m_z8MvsY|GHfVyaL|?p!=!oO6Y(ePD9BnYsMW23exkM@-%>f z+~|bgkJiiLg8<1I{Ejvsvh2YBE>wUM@b|A>V@nH-Xrx&As!gn2AeoC3en4a-%)-LL z&dmtHh|kj|MsqK!)zpu@|LVkhkw8(4FEM|gKFL*n9bh{kApu!eVWOVkP=85&Y)%kM zi%Vc;1jI_*krf9{o%^kts3#+J?3LqT82am*u1N?{I$`z8H#^++6D08aj`^Rsii%_> z2{ZJ$bT2wqE6GeQN|<9-uH9lc zRA)SL-Ld_FKt@Kk(rk+(OFkdG9IIyd@%lhXN2f-t8F`#nQ2~n(W?cFE7KpOS6A`il z2A$AsoR@2SE``MWQ8H+EgJ{^#i0i2G=T8gGvVe=sCPD=LkL3P8hL|uuD=XUNe2IvI z10y9RC2~8NQ3Y*;g_$`%Elu*gV2Axqw5!Q_S=gduut1^FxM7ua=HG&aLjf=_5cOtP zS0lQ+yZg4C9)M+UM`xol-DLkqJtGZ4h3}x=9ZiaOdbSh4-#`Y5@jz~D!jGxb7W&J4eR-lkTBn*$pl zwNX?)vw>+nW@dfC$+tIM#QYjd{LrfmE#eAY_| zK4>JBb{x@Do?NackkWnFgc4vOP6)`C z=jj=bU4Gi<^4LPns;o@I_BQh4=l_p!|A!4{BnNI8Y*cg)2V(HxSB+;W;2r^TO;n(_ zH_>we2_}=Qpb~NTYPZT#J!R?QdXE&yPy(R+6lWFsAJq4+Cr|-E5xwiUn+*%42yPsm zlhrnm@B?LHBwZ+XRb^9LT@vE*2mmOBe3oD&SycW4EU{SNg$D3ep-@2?dOjt{PNIPs zGI*H{IWtsQni}^g06&39@sS$XUI-O#uKEvF{w6(ozi{AfQfw~6`S0N{C3^Q`tL22t z6C!VLsFe?3=lQYpxH?aGJhc_IwIf1*p|50dWA33Oq^HNdzvHGE5z|KF07dzBjCA?d zJl~*W5gehhMrr89e5KzhYuhuXb}xpkoVD;~u=f+vRbo9t(mSPp)e<7~8jCdNpD zlgE8Kt{l^+t@+3E7J!4?;6|}R?I{4h79ht1us#)Flv&`OZBFH7rIL$HpkYDfRS7)t zYw-BPy0`T1*V9RcND{@*($5FMlga^K0$%o?xXX@*UcT1)iXp|dS2!T?gwXLj^md7q zV{5e9KRXsTUDvyK72Jn??TNRdUU0~be7%_P@bFk>uiDn}TTHco+0gxJN?)T)+=EFZ z6hiq{cV&&HScc|wtB&Rxm=|9B`+5@UTg%_cOpn_njF!JoM`KA0?~4_bGOLQJZa`fG1bbZ0fd%YBVHB$qR-FGJX>=_&XGSo48gva|uwE z0t(gX-yImHPItsbbMX4Y+xxgef1vs<;C}J&s_27hSi#78;t2;}tE&I)-^!scT0IEO zcYhn1U1b4x5=Z_yf3(&6JmNLOb|&E}gq770VB?K>VK>s7hC|eag|$jXIitxFob`NlIy86ye*d9+a>YR$3^+J!t##L-<#dL)(p4cIk1S;P zAi=Mo4xBd&up{@c@Be9%<`>$6OD4U~p&iZnF-()t>`Z*YeF$pcwTmA4o@e9q{gb;1;kRB;NcfSB4yShptEr39 zjqQElB`0WyyHQK8)%K@n1%9IG<{T^9GK)y{_BwxW9|oh8O+qQIY743JQ0=Tn|912p zg%ISwBcPSE_WAIq4z^UGBq0~{^Ni~;!op7hmoRx^3hILXeE;XqS2MqUW=NCB&(cuP zq!XNr059g+Z&DWHF#&ycveaV1-|XH`%{kp#AU0V-I9<<7d3_uxyt|$p-Zsvk>jw(6 z*F8SKHcnf=TaO8O@1Gt!wo(&(`fG^iL{nDU_df37(&h4Zp)@sl)jGMIUf@z(3f?cD z%;YtzwH4asgl9|`IxQAZYy12i=prJ3D@R+Y;tzYhHg|-6Ka?<^VWF3fjsTbR|K9^8 z{F_7(N?C)2RXsA)K$UnQDTGT&*;6+nhVPp~D<_wqs(9D{!zaMY$pn`I+i9zo^08AM z<3(f1RiR~n-a0!CMq_U=wI>8`^>pStO*}Ss-`86o8fz2$o=F6>&(j(!a;knCV$)(e z6uL%%_c&#tnpyG^frR`KE5EHxKtn4?*i&j$idlkY)I8v|gP25PH63;n(%k9Hdllnaj&>%=zzdCXgI*@x|M=)#S?OMQDH}$;wb`*2o*a18+0Wd2%9-0u6j*X z8t~CjGJ4-f3OOxC=Z*_F86(L_zkyr|$2L@Ofz;BmI?~_f50reOp(#Wdn6nacq9#8p zgG7(Mld<`#vX_IW{vam%e^k8%P#(e3H5@E>aCdjt;O_2j!QFy80fM`0a1z|z-Q9w_ zyF=h#l6&v_{Z(6A&r`KKJJZuM-F^DZj999b@BYKYNA#FKe5rx6WrsC-9R#Y6QgCCP1~p&$ky8gP7&SI32X@AE zGPMlj76{-4Eg6dqYx)LM=}8jq@q5WT8nJ|MpP6CqH*pyDbL#(mZ0EYi*J>7La zswmZXwQk#cDjGL_dIC4C2(8cupCI+$A*x&{qjJ|8NQ&u9B0{uVw?S3X-ka8b4(`u7 zTxj1ZQ_97cD?-D}2p(V|BOW4x=lJrBQjtrTgZuQtc~9_$(VhT8fHq{ybl#W!WmX7z zjJ&$Jo78r-2}D}}H3Ci*E5MM`*fD{(=hJosKE!iJI7ZQW@AH0no`n%+n@#e@PvD@L zEK5IGnDof32AS2W<_|P5;njYdL~s$!Ov*pUbuzqSiqGOoB^qd$DAT!EbRH8W#s&p_ zhCZ!Wd12UPScwfJB20bF#YY=Kt7+8mAqU2kzbf+gQt!s$(NVGYN#z%*08yQk0`SL5 zzB3}X+6W7+IdFdB?R!=xzlcA$rNq!+cyohn&u0uzqrM}sc6X;jBU@jpkc&Td*?we4 z5mBl2+eby{;wi-pk%TZjVS$bMG6J)^;0FguUED<&53)g1Aq6lh?t==~EGb7-tCh z{dfBN2+m1c_YqMO96F|x2NX8jau08V9Qf^lGD%c%=78$s1-Xhmb=J_~gTdf?jT&aw zljce0)_cVs!LHlCQDSL4;(MX-JNt5c%zr5&DZvx~>x$PX+*+^pm~hG+LxwowB>F-oozIY%%dK7te|z|0){NV|7nL55 z2Jdm&K3-EO|I6lt0+bgiWP)_fA(hgC+;Lq6q ztUWcqL}rB-rv9CC_IKvztAH9@QRaPh0#7QevNc{ej0Wv<$$V{oxOr6LeVd;8X;2O0 zCgj3MQbc_Qk%z(RSnq6+uc9lYTgOInBCY+icy60bC=W{n{GxWp6c4KvcEohN+BzE| zgz$Gi7Vs?QA{w`-_V!AtQMaNGvKsyL+xCP-JwDtopXW}L$%ai|9h}T@D#eGnraxc2 zp1(rd%zYh1qhp(1@E?ygRN=oy;ZbA_{MGTs!K&@3pr;Cw{=J-rx4J%Fg0N*3lS-VR ziMP?NEs*0@f9R#a=3&H+K$CgPcz8K_|2`}J;ux>-uFne7dRRnHkACA+{CpD815(Un zteDsBEOeDo5~rW5qc>T-(4=bfJ~mSuro|Ty@6XjPY3`Jc3)JIYfo(+SVnezu%Ns98 z8?3p&3!=g`HEYAx0~3`y9dyK2&BW_BkW~Sq(kuPdDy9>}c zhp`p36F_>TKq+{Fug_n&>0P3Ytd){JAT79l9bv_$t6avTT=|3B?(W8+q~b>^*|y*t z-Oz5`JK2cSrGUxR27+!y9fshI;5(%Ns?3_5l-f~`3Yc%YxmBx0ji&9c%7`dV|rd2<59T7OlnG9p43oWEPG~4 zO@5cgWC}7IwW!}282RsB0G(OY+KrBOLhYPz)ust(p4m@Cg>W4MhlS`mSOf_i0e*Hs z3e}VBQ%ZtD98xYW3Rk&q-{ghvL64qWtINsfOBl-;;@q(W)#!m?zOGcyd;48W4A3ar zv0$=^{btk?zE|FZOoGkpn*FJ@wP-%~k&sDNFAx+d%k1tcu;?FLJwG$EYyN=$)Z*_= zltc3S!^=4OP*+zDW0~Dof-H?4d6&=85Jo=t*CT9(MRN$! z#Bn7j%jH(NkUPj?^h{BQ$ngf{Ft%Q|f0)iU3ePFGSNQ|H>p`!r5Y~jH_^=N_DoS7X z``Jtn#~ikgDYxpt>h@y4`?J7>Ea#gQP86{3=;HiFu=;TPv;niUfm1lxQu$zq z_uRH`(3=WB{jqAv)9i0HZXL}ad&}^*pKgdtoUbR*3UuL5QYWyFN<-OSmu9F_??=+q zzOO#(3-~-D$vm}c`KT84SqAk0NyrFRk?S>~(ADwEdnE<3~niP-R9 z{1x`LaUb5TGU+FfOXnG*c5G+q^L^@zSj!>i0Z?V+o8k(6o&DCUInzKI@!XNZB8k%c z&kIfV25`EWcyZ!-#LF`Z8XBcd-#x`387CLQneH*Is|$_nvSkD2hK0_Tq{RzCNfs_Q zZ`tAG(;aq#2sWxtcL(h?c7lu$6OqT*XRcsdziR3c`n;e;*-nTaJ?O5e22kx1X7M?q z_N8v&6BG+t47oh?d9R^9J4$EZ=N4E=_z79U8&*>yKQx0oi{UU=o7gI=X=opdv~4Jr zgN1w7sy=>1(jzOdfC}~WH;!wtl`=L7LySlIwZwo6hFea|$=nTP(M7%kD@!Avh$wk? z1Da5@D|$R5XvawVG|fWD)`A-~8p9q?cjH!?KdA2{MGmt=L8~u@gpsy8oY3m=Dgq5F%-Uk^KG5PXN*y6W+IUwVw2-TB$O^|8-HrV+sEo5xdkclGqf zY998gzK81?+>ra+&i}^5b&|%fQ~3^EKb!Z^rB8sUeyhK+rO|PMK(unlF8*ONZSUA0JZ>`Q&eUdbY9QhF?_&7={MLip8KXtDd} z#7V6LyER4G@4Ur)ZBUgVl1~RKKOwVfj_Ua;Nlo7!YJW87Vs&=ICxfy<^V3gafgWxx zQ!9?JRMnK8JG`k#{RR{(%Okv(R|3cJXS~N6XL;!u(10b^ngD0)*8#!3K(<;`S{g3q z7#U;u2d$O!JZ4vQx^u;vyX z1UmkFJLSS|{{&w92KlO73bs@r+Rx~DzLAIUL|pErMSmHQa%m`o?htLP7!Mv$?Xw|% zfQ>Dd6@yL{kUBZ)-sVSfv_qE%FW}tyKX0dIjoLT(zwvWsush`lCZt9oOgJ#u^ zFY7ETR+2HTjmiwFagjAVK`-y-ZBMlaktO}Wx6=HWFzUFENv|@~XbO5GIG<$Mw(~0b z_fzpiTsu#7S8ntdzLO}1qm`YNZYi>s{}Ek zI*S`kCTO0R4?(kFNK9bw&Kt4>Ro83q04b)3jPZBQ%l#jRSGvw)<*}4!-XLgtR48Ph zx2QSns!RJ45kf{mvg(Vk;Rlzl>3Aqe6bLd}!nD=Jrxsiw%zkBc(nJ#o{Di`~mC23d zEpxlB$;lyvZEmNRg$nAaKH5TVV~ZT3x~*TNmX4)#Aa^+)wckzdNsWzM$;GZ6xx(}1 zbOp=l!WXm$7&IZK!%X5wIDpcW|e~?}JC2IEPn>M+urI6+AAeGi+jhXnN4i zB4nCy7(EbzJssW!`i}7z(k6jd@NMOdQQ}A!l{=}V_JL0TIDC*F=jJga&KXE@Lh6k&ET0&Ol6%Rc-k5{sAA0uu*CA_hc#}iEFWCkph_td z7Jf}XCrcB3^=0P~`rDTOw8$15u6WrKyguFT%gfpGL$toDp{FFan1}6;GH-zZ>7A`b ze`;v#&4D0S-%xEXiZE(w1BBa658z@f>q@xlh+u2?GcP~ao5%}rnv1LJ zkh(#yYqG@8zd+=HGitSw2XhZsa4>CO;hLJ3CLzTp`8oZvvIM`Kv|Nl{axID)+&b%b zK91xyP8|p&mD=n=wM@+|M0HU?|In+}@118hTw935fQ{k+MOC_-C#enjFDhVQ13hRS zq}32*0S0hZA&v9JQfSUVr(wJYVWStqR>k#uqnsVk6Sl<`=y7SEarIYh2I`Jiq4M)d zisuvK2EA);t;QM*7h=zak{z-2v$#XXqd;yDH2nX%bYTtIy_sE_<+d9V>jLXC6r^2@HWdddXRtX34AUc~0 zfm-{B44`igk_P_VvN~E4c@hTOP`$r<7W(VFP%N4EwwpR$*GVVcsFjQ}3n7U6QyOkk zriiS#G6gL6KFPRIn4n7Wyxkx-^N_&oxw)caCFLr z^0o6e2gXu49gjka7mLtuGyR8RVF$LJ@;FCJ9vAEGaRzC)DFbMg_9N5^A>_o-nT_!i zKV$QD$JN0`^T&ttzI#+#<7V|;scDh4q0HtgU6d*8NdmYQR4^rxr%(AMvMs^e2SRe# zmDW)2Zq~b}#SD@O@7|X<(jZ`_dzaD`M?H0+6pNSiD0gN3VbYtzQGzO_k$q~QcldWR9jo2jjEkNQZJnD47LU)Fm2``ZfH-7{}^xr>;QX~pC0&d zm}C(~Rn1jRh#mnnZk5sJ>rZ@@;~HzKvv?!J9oiwCVC9QtU;%XA8lXp+aJtXFwVNeFl*=1}~bP8E|=!4wXbJ?+}S#=OvBjj-cM#zmb z937(+alDL96ffZy0C(~Jkf4~wM5F*v(H;E2YQ&S81__WV! z-3Hq^JFB4M-`m8_*QAohaDqpOt!<$cHJBeZBP$Sx30dkQ)z~91B7!>H`HtEx!5`l4 z{1l=1!S@BhTuK6qlv(b?$+0e>j0iw;1R4r=4yEhA{T+IQd{7D!ed7G2rD#$rR78n! z#ISozu^*s&=|JL#P#fx}82^JoN{9eMHgwS{-TM0Bfz!j&)2s|?Xn6BoYL~JCZ8r-3 zMk(yUenxFJzuB4BF;_~1-pgkX0&HBNf&7Woy5~8sv#aYnhoK5b=osiQ34=^1RyMXx z3jRlEDJiM>l8@-m3gEr)ygWT*-1uQwEb#)k$T2~1Tf@{aC5=Z>y^N-AZW^AP3W5~x zfE#cnAvbzIvlkW>CF5^o$r9!8di5<_FBIAv6acldk_Nm)8+Y5(>FJr7O~;HDb)zPwiY2J}Mn=SNuhkRBZ}zQ>kS zI#Lkihcxh6ZRO~JJUWf?Fvj$;oS3IHMuN-QcnWzV&oP%!MyuKOhFRh(e}N4o>D@!1 z;^~5fsGquws;tH4M&>1n>S)o=bm0BnaP)K|$3}(UXM7w{0a4aSQMTPbj(NolW#SNG zVG!az2Xl9{*g0UKQ*?k99~?69pV%~e<(9NNe+0zs%=sFZZMLWC~0LoctZNRX*=eR7_IeJllQv)yV50cii#i?D)h6x z7nRmfZ;BUtKN-%EUO<7*hQ|npeCjffkVqLrRs4yCsuVq$%9Hq4)qpM|Y=_SH?DTP= zTsJ+F0&RVMnhU6GBGgLrS6JZis~OOT(geG_C`AbyREzn)Eq(u9LkOcN>;x+v4wA;vDUmfck9+CX%XtfDH+BvlYhsrC(|@wL6gBYh zz}Bl!e^z8DW54c06VKl|Ud~}7t&9PHEsk+EBjN&Z$RjCqu@Gp_oyEl6XgXRldVYuy z+YR-OKX6pPv%5J6*6S;6aLlV3ogt@iRG5c%WrgUnJubd9C>Tb# zG;G;wV+8ZgAa@P=zZ_*QYQ`~1+x4&dvt)DR&Z&HVyR)7<@v;3kUB?LIA}c6MZ<%;N z2dU)hiKbgOH2ZN}!*`N%_-_Bahu{3e-yWj)%yhD>3penR=IwpY&(5!(Vf#FAwxOhq z0;dcR`i;rp(v8eMEUdjD25!f@RsR5O!+3+X%Z4>7DB${fD4$cvg|H`E#i3^Lfn)8} z?B%i(#Oqbp4z!iO zoMSVD#@AFVa(J9)MRHX3UE>f41&D4x2=I9Mf_f=5@~78vBm3DI!;yUCceZ@+5bWwg zi=rFEOePpDr{?h?h7#7Jl967n7bKVey15d`)TtB#mMF(rD!-L)g8ea2P%MMzVTZ$4 zgdl_Sb*qN562$P^hnfgD+oZM{4X?)gIo;ahpAJVm4m(-M*bN(6yLmBC1aX02 zv07iHJljLcP?6j;ZgN|_woJ^cG)1LY1oz-9+07E7mE$Y{OGB*c6Azi2`Y)6T{$aT) z5iWJPPWHG&f$)83bAyhwE*jTAI@-X1JlfEgV44QZf~Jxh6DyNPWd$8;@rkh(%u5^v z1>kfqw~4EIx89_+V!C=Am4$DHgTq-i+KU`vo;I17_hEVt`9B)-F-wvj*&!Hb=R&iP zsy-Y0(b3_MnLNgrjur0OEc>rKrsg(LaA8le!*kxB2$pL?3Oj&(+6}4=;{JMJw84U; zGnZY?UqkFzf>-osqaFt6du3U6^^K`6clSyvDWewrfZK{?5o8*@`Av+2tOCs z^X6rUL4A{gjvlp5w#|GlJdI1+6~batR!D29vj)7O^~lWjxUVnR*%Z;JY$$V{$NHz7 zOP=v8V0UU2cE3QSaD^+9|M(nUvVaxRN5PdR@sA|S5tBeC!(vO7_R)F0_1!p0z<<{N zLzPuhIe~Bax?$#aE%xEo_g4SHD+mcgwcP^4Wg*4>R}+Gs{s$H=uoJ3J8BfOqU+jEt z4p$e#8+`AuZKLE2mkAPhJW|TojZb{geeX}?kgVDzH1$YM*uh$D5nc@OtidXb)`8Q^ zv_HL#$zK{D@@Vs+YNrv`XE3vEjWtYkEng%*FvxQw#e7zNdkW__Qqh?MWxmMcNHZAW z49kA47$E6ZIB`EW>*&9&qH_CVbR7Xj5D($vNtE^6rElaJ90zq@Lk00Rz%gu^+ROg& ztge%Rz-2B`RI~)E-rcni6}}1|Jru?mi3m+{hO-7{z9<3%V9I_DkHBj&wCxDuE7N6R zOflh2KP|f0wmZ*6Yi&zj@3$gY?@e&U?z(`xA=a{?YI1w3c>DOZX{3Y-493b8nq<2a zYK)rt8}VsU_9IEM#V&VD=ryLTZTuH_dr|E!{(lo2aE}%<7^+#yLmQ|8%r{{8iZD2g z+0Jn|Y(;!+H|KBFWX9D@#RN-`yxVjiZbn+R0?=js^>jFY`>*lw>y$`Ae`DgE3S2wW ze%KnZN|E^;ye*F_=5GjxM@+r;bc?YyS*Y|O((VOt)Dw_?*@NKwUXt;+wxYL>yR5w2 zzAbT~v$>VNOPA5=GJ;&#=-qANgz&4oM$^w&@3{ySj>b4_=GS zP4E3(y9}>V^<*F%SoZ#f`+5UbMtlNcqk8fBa17m9X0h`Afr{t4*T?v&WpdsTtKx0z zx_I@z#zJn?BGID5>%jahi4K-Je0tAi!Zs8))IXy_#@J=nQX?cV{^0Of^m>WGzU(Wq z3H*RVWBZ3cVGGH2n<$Y#V(^FzQF&JCXQjt$X{qr&}M zZ+nb&8L*0s(gs)PYd&p|9`1^Ky5O1f zMq5Z+re2~TVUI!lw~+GYR#2zRr<*IgXfBIw+b?8%sPlu@U0y0DefWh+hx4cy-_NCO_32|_h&;Dm)4;x7d9ui6J)~o4W3JjufOi~3uhe7bwI9bT_3Ou4y-cfD-|1l zA{~7sf)kAnnU!n4cb7fA-lKd)PCGHq-i2I>c*|vrv~VL4Ty}|l&i1s0GrVl>*6jM0 zw)}}$a3f(71}D?>2SY1;6`HKYL1Sff)fG*^uWvXANWw$H^Xh+3VRo zq*3y}q4mWrG|%Wv&q76z8GtbJV1p?09U+_q%R+EZ#_>>j+HRfBAX5^hjec%%DBj_C zsLX@F&>~mRNe^q;XBdV#q#ulplt0 z-4_Fo*%j(w;1)JpIP$lImrY|u!!J7L)g!-ioLsHigwXvCcjN;1aZL`E6xT2Ed*>HR z_AJ=kJd`nnkT&}hqSl|Q5iA_{r^2F>KBP7&HUbDQ zNDV{;!!YVfO2}R3nQxt`YYv}(ps)Ls%ZU`K8Q&y>6dq*ybe%nFHvTp4?~}{LB!JG~ zV`IsGM=}7<#|*uF!NK!)Oxjrd5@On;&N)4#d;nb|??s^q$kSZ2^(YhP$_1m!M2O^4(Q_KZK)w}97!t=jlThd*2= zK1fs^ym0=E8CNpdahbWI<>85{F?3TKd*anB`P-ebmR@&vHeQ!=yk5d$U&i(D6Rxi9 z-Q;JJ4i3^x6GvUCIbWFd?plLf`7OHZrjTw}^##>V;~!qbJ%7MH*G^HZi!xpVqR`1V;7Z6x##W|O62Gm)ks2%stEo%E1?{QqV`AUv3W8<&EI#q zXbval(TrMl_`7c21pW2Y>_hG+!*mpMUoKqJwj}wH+8uRFo9q`Dy9^7Y1u=@O=V!Yi z^YvDrxvPrFD6(CL0WGABKMrLQ07eS9tiX||0Lb#2qc#G3FZUy+>IFzkgxRPxa;-qP zFC+JKzOdXML)5oIq|C8>`&T0ZTlwI=)3Xnj8R2hpU{DqTBx-ALq_%+vl;Pm^F<@N> zi$T{PUN1cdddcXRH6<8~U^WRON?pt^U2;TZD+#v= zT{K8yM#%KQB5R5I@jPzwa`>mh-s!|fXHhvEY;#Z|qsU3aNk1JY`|?YpJpAhSp|r>v z#yznC;y#9FZel}5?(qieLKD~WtgnQKzsQsnG%)Jc%n@-!8ATzdu=O6rGiZUGL;|U^ z^$yjR*oip2%Voo554oPTTkob+;bhY6ujV@Xs&t!1%I(l<2-&lm8gc(7{{a*ehyvX} zNBF0Bygu^;0&agEbZ@XpF2dGNkH9?S5R=uM@qTvA(gt;>Z0?&ydMqSO>lIF)w-APy z`_(*&t9BLsFxMBebYq?!g^)22ps8w74o(O+o}>FLaDJoe_}&HQuph5; zwkGdTb2jdCKhzTG9kHukj19Gn4nNU8zgKN>s8waa17Nc{7Oa>StKgsx=LWe9m9 zU&rO(B4mk474^oVoOdwLiFLiQzb<<%$<{~D4ehDMK>qpAP2Y{mhBrQ%;B8FII27vnnYL;w$(4qS2f<#v;=5Hq+_9E*qh$ z*V#U8tolA<)Xtv@`NR3b4`a)nf{`p3%ruh$ab4^k&= zz2x4p@mo*lWtYLeCob}*?rx=fi!q2M*(|L+r_5xL-N1Godg~l(*uC%LTTY8h15_KI zj#YD@ViouKpmK3&FSY&>xkn?;uc&J6t*{J`Y3{tmY@19f+Q8A2QpX(w);uGNQ2UvDK? ztM<-91B^BAXSinZIT>2sC#~_#$lqqfnlH8~mRUXba<(&kArw!OdGrwKRLpJz(TrQ? zbmD&HNe+{{{)#$W-sqWULxa^gj*zS=JI~@trkqzdOvb5^lMHWbl%FDsph+uvKzz#R zCxSc)1PIsGpm;i0dU2;n?9yyu7Y*#}u<9@q9JWj>SY20|ijbZ>@7-^*w?-n+H*9q;#;~VtUds`k zP!4=S4@{tfUFbj2bcsTWsXP8KEGkha$+zHB)yHKvGAiTjCIXk1%G8}`*WCuYz{oiZ zBRm)$Dv5K)|7>%TL{x+24fDzS88U^nH6*&CE|j-ttDBw9-MN_ej=9}IN^G^ZNtp$q zmddocv@|@x=C^VLRhW`@-ULbTHB>I$yvN50PmJenL)&UhewzkTyaoN$yRoPvsw zMxEyN2D?bBR%~eah~;>WeQeRk1|7xPHo3qvl_uud!1zveSb2<|cHSixp<+5YGPk=)x*b8!x| zhz0`!xtMUiqJC5g*Yj0Xg&-@YA!OKF4k53P7CaEqo~T9De-z=*l_3D|xJ zF00oIJy(KSX{xJBj}HgB9S%~#Maqc%P7KTF_CoSeG-Y;FZ`#My8!JOMJVe=DS5MrV-8^ z8Lmv0GwqjyLok}98xfMIB=HQU4U9ES=QV4(nz;&#p=TgJ3}}=~mIy$XCQ8h~6R&B2 z0)TMQ#KaK}HL=Jf?!Clf?}mgz`!hk|Lr2)DpIZ?U4tqH~G}14#CaB_B{rm0CMstUo zqqKy#K8D1rdaDej!%Y5Fxx&?$)2Vh zqpT2Bx-#j#OvaX)Sv^>R@`$V=49%D+w_NVMG_lldaLni3K^XnCVbQbiD$+k(SJ@y# zOv4=8i4MfqP@kn5n=ClMtMXL0e>F|sd&Pho zvSMqa-87I)HsSd+5^%2eSPrvs*2FNyRS-aWxET*sOca{`Wptz`;yX!O6P!F>o%CL^ z7zL#K?M4kt@+K_$*6j6Hd+^mpuRWgT{#K}O#0+O}VkjAXEf*TPCA6wYI_)paU|H+& z3?nAJC%fxogot);1JZ>#b{|pa0bjjR4IH%buFDL0T3`>J4Ogh%;s>f?os1Q}VLa4N zBouc84otX_@05uwX(FFXcs`P8C81-C)Uo>(fO?mfKPPgoXFcy~p88~BacA=oIZlLx z`?mg!yePd>8KhRAsZL@rPb3eF?Le?j-kBQ$3!EpQ38gHXo%?gt@`UtcvS>Ll6hFvb z;ksWoPQFL%KSqp*qWpq`l!!AT7&1C7bZW99G6C;(w`tb6#_nfvyG2XwIJdsxhBMAO zT#XObBQaFby%y|&%4x>PH5*E^Z#&eg=uSjN6Asz7jfsMB{`x8iPKz}-BqglofqjF5 zf{AA?m|aSP8J5I7KNGweizM^AtlC-}>J(#Q!^MmsxJORqbS?ZT4Rll{BDducIn8r* zIlRYYMBU1F@VN5v&e3z*-Fp7dw$H7j$dQk6V>UQ)oFBM?xf}L+DQFm}dCxS48TyIO zCAY*SHWLG)zEHh$Sw#KrdC&TrFm~(Hil|dQzDmzvn^+k>@3U@JBCBF55MSF72 z7Z#&=#XRwY5ZO2_lC6(({f&`W@KZR=wLt=9;TYbq$z)KE_+1Vui|R^|6ItOQD_{Fc zR5>4q%UU7Dmp{VGa?#~ zk($*V`>a%sNZ>smNl4&{6tW;VitPh;AB(;PKWS&ki3+HVvG*I_uyV5C1gHk@Fj!PCx_OSi3 zAqUy2O3zsYImt&|?i(zmvQtR7bJ+QvmX@D{$gTNz8q+d8s7x!N7jNK}8ed?QkLE9X za&%o6i^uf7sM~%9|HV1X4)kee08}n*gd1mtxP2wUc zy<-2$5-(@w=inr}IJ)(*PNzc;61x*c4MN>JVdSDP=y#*?8#LL;Q;*8=#&wEiD$M_oYZR`w zhYrb0NqQvKG|6eT%8%RU=H{-uRHq_Qx~UQKXU`sLiCNIqHXOxRC>ZEVSY)7F&U-rT zKUXCg)F3Q=x^jRFr?q)8PQT~A*5<9m4UeJ(vVgpFAN)WSi8iRTdA3SEPaRAUh+OF8 z&*aCFD%M}_x!lfsGAgLtlMCdwfv36vPBxrD0VYLLZJ1;r8H@ERZb>U_JES3;F+3qh zbSu6|-NTAnhM9mf2|bzM_e2LNB8dPI8cA2j|J4P^KgkpF5FOvv^{8nCZ_z>vmZOHz zf-o&JoOx1Hm$KhWbf=mP>6A<{MMOVtuIPPBNGXPfWMsojLOei-V`p~#s?BtRhjP$D zc1-%z2DLPzuvKlPnxdp55j#Ba!Yn_0AQ1bLLCe@cYhIFd2nu5sW>1E+k_%AgU)#Mp zBZwOr;U+ou7=K|?ffb~U)-~BPWKH9?x?OfJJUnwLNzvdQ&^oo5i;H5B1(w`eQsLgj zPoL4yD(iHDTCTDAZtqF>S%g>4$jLbSpjx|hGTb~GzOf~fUFMD{)@WhyhifoPD_XaO zvPWyTqmLjOu z_;Oe}W-92p1V>2W@}c(bjw~?E(p{$qdx)?>nEbfIGEPhu-De0z$pLn|y`#kt9!Lqh zs-|^jza=3g8XqyaTwgNxtlkk_TI;zuWY~UcBdV2enj*>a66_#gnU_fz&R2@nxkAA! z)GB`w@9b12$P{Q@)uzhFZ8PHhKOecRr$opz9B>TWjRlG;3Kh_uVo=sG!qlK%nRG0-DlGx0(*18%VV zvmXVlH#3Zhh*p|buPc4DDtcZ;IX^AEpWXu~HFl23$Al|ca#*DqS*^7zVVXpKb@Yb6 z8Rowk%Kv0`I-8Lhmon^!qSH{&unuC)-LKK)YF*k!m4^qbiM;jrGI!EvggiKzoi;SO zwBmX3KHoi?OiEXV!$G^mM%g=SLS=q$UL;KBIu_hruP{Da_jo7E=w;XR{hvNpQh_@o z^V-RwuC9NZ+iUTKM&KkKmgLvxg{5LL;QF3CWw#IcU3eiwe2^kpd z>K|fbkseIoKmMJu3H?8V)>y5Mo^H*PBPmQR30-YP1It(ltDt*-zbM0$^tNZQk9o9- ztSUpl$8Z_8BDr3&iX{b z19|{_N)yQ6lS#|l8gRcK66@@GBRSh%3SXM23Z!{s1hx>(o9Dh~zwT$}n4m~_PG>NibC`62TY-KKSRsL!E z{^}5rRHt@-cG1;NI+78#w0vrw@9KWf50&US_wqWDY)$HS<{i>vhp(>=U6U|T zogQ!I&Tg<-x545y>A5jGz~$IDMlmo5teCKkoLFh|$EsIknfGTrvYg`&w;}Tz`zVugzB)C9_3z+xRO2j_eu&1+ACpyEM1OoMA z&j5%K!6aru|M~;Crwamzf61ez4xu~CL5&=;1RpR*4lNW}BmH;k>GXczY`FMQ>78^D zD&J|&YI_t89Cp~-5zJl$p_A~%sj)`w-PL#}=@~FGZk>>T>3KFPJTnIq%ySmvWul=TEiIOwmofzM?FzIH88`SdYN3VsJ z!MW4`y0OkZ0#U^6ny8f-kaX578G{nn!Uu3B#VtqrGG5N8q~8mZOB}&|!^hOU^*>Js z(c>Y{g=uUY@-?*ZAuExg#t}W&N%xb?&W3+4(WKTc%pG2 zR5M-Gx63oS@7Drh#!yR`cZBGIR#4_;>4vJ`{>Xo!S^*iatbAd0{BmH(sAb^Fsi5+P ztjAXkR)akBJE-BcLqBJU#lOUY-;~gOOf7>~-M{1IxkI?ix5Bi@ZVdfgz|u zl(3qRAse+Fy)~bo%0)XhRx}+$pJappRt`S5r2%1^dFu<~Qf#7j*b3`2sFL9u6c;x) zDFSeag}9+0Q-*0L?`*XH8orE-oWS}*=o%lGkc6OKlyrX-df~<-TC1yUC?!o)`%Sc4 z=})K<7g*=b55q9Sv9?cGYqlp{ef*hSLuq#1&;(kxY=WQPPQAC#aEr%6Lm3*CfoTBHyveZk6DR1IRS zp$FB;bt^DM|FRyc{P6Q~|A3$=jDEstag(u|+}6vFVD+90aZMX8ub4&LBkQGD8Ka&- z3Dfr<@8?}BAV8}I(#j^)>SF<&1%rlj(HU6Hfe=LEqsD?4bG~;cCdlmwB*D1+g}^6x z{~f2`>%?YNHLc98UVnCbb5z%*K1st)$EHXqSmpwMXJ(WqrL7y1yzNLp%Q08`(cSQ1 zJW|jt{KcKlKxZ+|(~ZpgITdzg-?!bUisL3%i*gU zB0Ad*DOKH;Me9=|WJPAX-}qg4%7ydRRjLuL_Z`~o?&n&bmw%=kumF{}fDyB4<1-7F zG!TZ`Njep@Nzz3T_$hR`D11!O5mKnk3L9`>eLP?9aXh5dInCYm1AekY%o! z25BTT1X-e^Ba5xi)p^R%a$w-?a}}NZby;9n5~v1A19RXMOvs4`V*cDx)+AN+eXh@C$E*oh|5io#`OcR_UDc~`jOn-ZHB+| z>bro;0Mlt{b$h>Dr*GJ_=iY?2S3VI`-SS5*Bvia!c zxrk_=H*Bq^-xrU!^s~HrRgH)~S)G+C6!Gi*apj_wx8_+AUgbz5_#eB|sxqhUS}2A`85&n#_4{SV3XOIOurQJe zSVRM4@(Z_{D9$#s*Z4w0FNcEMjUX=nS)zAmWg0~T7mxE0XY?bGXtjp(H^H#hW7IGf zRulY*xjoQSlU#?mjWoj3=y>Pka0tdcJZxf339M7p1Gj0SEGri6*~GXMk)`flBa(T> z=*LGe4?kY(@LrnptRqC4;Vrs6d;E>O;zjQ+Zo4(c|AJ*HK%IBTw4-edN5}fDhM+B6 zyUpoSX!QZ=({FAPiX(T}Op-ym|MdEz7C0wyUENc98JRyPv4Ox?7YZXsTjb^M^9{3( z){x~m6*%V=0juZY#nk8l1oa+5k@Hamn%Krs&vb7LOXr5|NrPIzyY*8zI{xqbrX9j z>#lOAvQi?3l|%<+T4+wi`V(g*;$lJNGMeU#TG7rJ8O`^Ai03--C4T{YJs+oeG}GVlNubvc5h95KhU09)KuDg~Lpiwe5 zZ{3&Fs&#l@2Rb0zu1UOn?s%4eKTj>J6O+i#TtLWBmUzR6Bk%-MCzBbq@DYgLpLQNz z?@zH$2I{5Opk-tUF&2OiWclDj!s5ny#hPAnK#wAS|3ff(w(;?=zalV=G&yv144YvS zR~}?NnTGPP@B3=DldqaX*x@!dV(K3%Z{Sgi(zZP#F;eC?(#*)UcGHN9qwPk!gEJuT z_JN0wLFEKGa1HcVsY`lhCRmGNP;pAvtOmoA_`v2pr15F-U_e`WsStEBzV;Z^x6rOn zH_<}@ZA!s?snJ)U7-#!#``NhtlNV6rd0(ZZZysJW0>L4<9F2 zlf`B0p@Y?bj!n#jEP|pTN7jhyB;a=gn`nOk2N=DzJ!(zu%*@P5Bg5YRMkchBpF9Zk zvV()+U4+M=39)|=c&P;$Wi;JP?EzaPn`%^vg(9_RG}h?hAcI_TY-SF6qhJw>Kt;5k zwiZ6#iA9j3UOW2}3yI>(&Bwr(EE?gYXHiQv2;A}*wO|)7#Z_ug+SF4`%9w18%oP2? zVb*gUr?8#G?8@(yr)}|a3`Pv>wdgdlzVANw->V)QNL-Z7Z(Gglg%z_24+XG-di(*i z1)R#8;O9stQNp7+BUOZ0e2x9qYW(^W_aevm|1mtFp-W#>;=aL~#{Vnp|Lz-#&^#Mx z7kTIt*YSydjt(#rw3)-%rKct>@6T*(LXBP{csHV?0$$>KKq2@Z*hq-?rKhqWSILW> zeR*Gf0uV8!{0uXam^T5MD-Zy%gF2r|*W;Ub{@-W*wqQOJaIc$5OdawvNd>hfk1rU+>1-u99bNf|j= zvf!@Txc7(HQ~Vb8S2wUV@&5VXVn7tSY`!I_pf4#2t!3*f#DO}gg#!2Sa4#AB&oDXQ zjg;bn)Mz4v^i;V(RFnRllKdOr5hqt&~^)VtM0@w+K!sp8(=wJC#fT{s- zzh&lPwZ{8@0Jg-9U8cQ~RH~3G3hXlQ8#0!PL$AVm7ir}k_$(CPU(R}rfFlsqO94Aa zC(JLNx{Svzqh6K%1}BrkWB05Xpn%Le0q>#X%+Bq1I1(vxCq*{Hp19emT zAIS(1CL$zwqmTivGpH=k!hgE$HI-n^JAC)IhDJa)XvuubR+lvp8!I&ZHyHjs2{?Tc zekAWf%#!i@oBwzDivwzMYyRTK{EvstJ%Bt@8*m61f=A)g)u!+tf}lxnhiKEz2!1)QOAh>TYC)%pdjF@ zNd@4uxK!iuTEjt}XTpRB{j2@t&T#N!FjO^T{t=^Iv#0CO6m_%SoemuTZK6Oca!yRx zLRP3#3jn*c25ybE4waMZG%tUXRK^~rfidLxwt;`xbBcqXa9R@7gKGA11{c{)1k`Kl z=KBYCuJ>Yq%{yR9zz_1>SYw5#@jc1(Y+!yA)j`A?>5bQ~7XQ`-Z{dTxH>YQI{9}JG zd$5;rO7w=hawhp8%)*FSW?xv)ZJok>mYw0pVH_}H5nyJFIzz;(G_8bqBiCd8mAH?K zp@tL5gV*-KQ0!;V$4oUDC}k8|8M$YsJeJP1Es>wAJnDjj(a;ST#(9oUTbVzG)kMJV39Z7Jga>*m`3nQq_swvai*W`;ca zZjO^YMv-$YhYCy|sV*>LBDoTiB=Rpv_+g#XY_d;3PaNvh-dJ;Q|29aXnX5?jtMS5nZ^(-kVy^qhS9nia1u z_48n7`9(Yw7(P=b;eECTN5ZMJJx;oHvj%>LY0`g~+fZ&~WesD?qn-R@^{WNe`js^k zsgop?JB_Y9lL)w3RA}#wo2aX`zB%^kD6Ah*%f>TKl6vHV;W8<5X|gYaZP~Q!q+G|r z(i7)8CaRioH>)A#Ji~leT8fy7v+Kdk!m=m$PyNrc0utpWI>N3GX%hy8=MMEcsiVd? zKCu)L!YL)@H7>s|<@Q=eyuhB(z-Id9bv*XK;C9`-f!%SQX3Q!xkUMSZAElMtab0)% z#NoZWH-!JWeJ<#AT9e~3OK+x>(%~#4J8amOi>NKPMtntC9QQ?S+=QEsa=&ch-$IwS zMubffe6~) zXLF&U6&u|CO7_+*ksnTW!x?ArDhenZ(50-`xy zbk{nT-P5qZ>KBQ$0w{ZUDL&nxU5u2Ky3KI6%!et>=9xkk51e#Ly>cmNDoCu39mba%cc`^OZ|k2yHcGwgr!G4fRX$aR zYAVYTKUOD#EU}M-G3hJfWsh`NmYei`z^X+K6G`P&*q)+DE;Qld$FXc@q!<^kBXrVt=MP6nR(BjALtHsYDFM2} z6S6is?yn;hnZ+~TlPE9mimpuKj1Pz~qBn#`aQZYhENH22J@_(2qJ`S)Hf7l0;;QPE zBqwtiSv^^lkbHW^!+r7Nrc-IJBhX~!Ax?71tKW6b+Th)pqpf6&V?Ud4qzmbP;-4|GI9}2>$f zmtcFMqq4WXrH`A@36!le(QqNCzGggaBBZeG)N#}+V1!tN%hUtf>>K*=`80Ud<7Xd} zUok0_ztRp>a<#9A;GU6-+xdYp63E)RP`Ppz*XAXcFaIxxvkU0==d>Txm$J4Q+a6V) z9c`sbE(T4l@2%Zrb>QyKja@;Ev(QsBiJh4cnpRC> zck($01>I4Wnrlbi@NDF**WyHTS@9l7932tZZjG-Fa++KaYkAbmYwWHnIxrBmsRAzC zyi~b2Q?#nVVJMNmqc&jUe565J@}#KHSTN2^!e&GILsAa0?YQ4rFRD17FNqB9Y3EJ0 z8@H`{Su9{9rhWq;vk};HZv6e+%&i~cd*aX5r^w1udJIi$kFt)QzJF%W~5FY?UoqPg7r$qH{}qwm%oom>x7H zYmL!vHnbOg=fc3-%S+*q=R;a@g$(HN>KMBm-wF6**s-+6KjjeC3eA*v6u=WLI%RlYb)UwjEDIi~yHut) z=vnD@-=Ct~tKAQz1Gq%n;=9N+1s!zA|5it zS$%>?OfDYF}j}Z8m zmDgM>6atax#jmi=4r*Wmrg6+UAyH|JMLYxwgMU!T1=TYI&9(2kH8Bh)od5a{K!a#O zRP%v<>may66BDhH8C3Y*MbH;1?PBNtO~k6K0vKUFDct6VU`T>c5($~NJ`iYB#Ag|o l6d=}SvN|FLiv7Qwj{Ftv52jKGh&Kd$?5v%vSOo9He*h4 Date: Wed, 27 Apr 2022 10:46:57 -0400 Subject: [PATCH 02/22] Updated link description --- content/rancher/v2.6/en/neuvector-integration/_index.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/content/rancher/v2.6/en/neuvector-integration/_index.md b/content/rancher/v2.6/en/neuvector-integration/_index.md index 9ae34e2eac2..8514291c823 100644 --- a/content/rancher/v2.6/en/neuvector-integration/_index.md +++ b/content/rancher/v2.6/en/neuvector-integration/_index.md @@ -5,7 +5,7 @@ weight: 22 ##### _Tech Preview_ -New in Rancher v2.6.5, [NeuVector 5.x](https://open-docs.neuvector.com/) is an open-source container-centric security platform that is now integrated into Rancher. NeuVector offers real-time compliance, visibility, and protection for critical applications and data during runtime. NeuVector provides a firewall, container process/file system monitoring, security auditing with CIS benchmarks, and vulnerability scanning. For more information on Rancher security, please see the [hardening guides and benchmark versions]({{}}/rancher/v2.6/en/security/). +New in Rancher v2.6.5, [NeuVector 5.x](https://open-docs.neuvector.com/) is an open-source container-centric security platform that is now integrated into Rancher. NeuVector offers real-time compliance, visibility, and protection for critical applications and data during runtime. NeuVector provides a firewall, container process/file system monitoring, security auditing with CIS benchmarks, and vulnerability scanning. For more information on Rancher security, please see the [security documentation]({{}}/rancher/v2.6/en/security/). NeuVector can be enabled through a Helm chart that may be installed either through **Apps & Marketplace** or through the **Cluster Tools** button in the Rancher UI. Once the Helm chart is installed, users can easily [deploy and manage NeuVector clusters within Rancher](https://open-docs.neuvector.com/deploying/rancher#deploy-and-manage-neuvector-through-rancher-apps-marketplace). From bb4ce4514a90c213f037eb0c1368db5e97e96e71 Mon Sep 17 00:00:00 2001 From: Jennifer Travinski Date: Wed, 27 Apr 2022 14:40:19 -0400 Subject: [PATCH 03/22] Updated NV limitations --- content/rancher/v2.6/en/neuvector-integration/_index.md | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/content/rancher/v2.6/en/neuvector-integration/_index.md b/content/rancher/v2.6/en/neuvector-integration/_index.md index 8514291c823..89a0ae2f08c 100644 --- a/content/rancher/v2.6/en/neuvector-integration/_index.md +++ b/content/rancher/v2.6/en/neuvector-integration/_index.md @@ -76,4 +76,8 @@ To learn more about NeuVector's architecture, please refer [here](https://open-d ### Limitations -* Currently, NeuVector feature chart installation fails when a NeuVector partner chart already exists. To work around this issue, uninstall the NeuVector partner chart and reinstall the NeuVector feature chart. \ No newline at end of file +* Currently, NeuVector feature chart installation fails when a NeuVector partner chart already exists. To work around this issue, uninstall the NeuVector partner chart and reinstall the NeuVector feature chart. + +* Users cannot access the NeuVector UI from Rancher for a custom RKE1 cluster. To work around this, restart the controllers; note that while the controller pods are restarting, it will take additional time for the controller pods to become active. + +* Container runtime is not auto-detected for different cluster types when installing the NeuVector chart. \ No newline at end of file From 9fd2aa46d4551de9208e0fe8a20e856c7037fc61 Mon Sep 17 00:00:00 2001 From: divya-mohan0209 Date: Thu, 28 Apr 2022 13:51:27 +0530 Subject: [PATCH 04/22] Update _index.md --- content/rancher/v2.6/en/helm-charts/_index.md | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/content/rancher/v2.6/en/helm-charts/_index.md b/content/rancher/v2.6/en/helm-charts/_index.md index d225e2f5854..ca9a26eae82 100644 --- a/content/rancher/v2.6/en/helm-charts/_index.md +++ b/content/rancher/v2.6/en/helm-charts/_index.md @@ -75,7 +75,7 @@ To add a private CA for Helm Chart repositories: ``` -- **Git-based chart repositories**: It is not currently possible to add a private CA. For git-based chart repositories with a certificate signed by a private CA, you must disable TLS verification. Click **Edit YAML** for the chart repo and add the key/value pair as follows: +- **Git-based chart repositories**: You must add a base64 encoded copy of the CA certificate in DER format to the spec.caBundle field of the chart repo, such as `openssl x509 -outform der -in ca.pem | base64 -w0`. Click **Edit YAML** for the chart repo and set, as in the following example:
``` [...] spec: @@ -85,6 +85,7 @@ To add a private CA for Helm Chart repositories: nDxZ/tNXt/WPJr/PgEB3hQdInDWYMg7vGO0Oz00G5kWg0sJ0ZTSoA10ZwdjIdGEeKlj1NlPyAqpQ+uDnmx6DW+zqfYtLnc/g6GuLLVPamraqN+gyU8CHwAWPNjZonFN9Vpg0PIk1I2zuOc4EHifoTAXSpnjfzfyAxCaZsnTptimlPFJJqAMj+FfDArGmr4= [...] ``` + > **Note:** Helm chart repositories with authentication > @@ -128,4 +129,4 @@ If you have a legacy app installed and want to upgrade it: - The legacy [feature flag]({{}}/rancher/v2.6/en/installation/resources/feature-flags/) must be turned on (if it's not turned on automatically because of having a legacy app before upgrading) - You can upgrade the app from cluster explorer, from the left nav section **Legacy > Project > Apps** -- For multi-cluster apps, you can go to **≡ > Multi-cluster Apps** and upgrade the app from there \ No newline at end of file +- For multi-cluster apps, you can go to **≡ > Multi-cluster Apps** and upgrade the app from there From 982a23bcada299ce0d2b323d3ac89f4400009ed4 Mon Sep 17 00:00:00 2001 From: Jennifer Travinski Date: Thu, 28 Apr 2022 09:17:51 -0400 Subject: [PATCH 05/22] Fixed chart link --- content/rancher/v2.6/en/neuvector-integration/_index.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/content/rancher/v2.6/en/neuvector-integration/_index.md b/content/rancher/v2.6/en/neuvector-integration/_index.md index 89a0ae2f08c..7f726bf15b3 100644 --- a/content/rancher/v2.6/en/neuvector-integration/_index.md +++ b/content/rancher/v2.6/en/neuvector-integration/_index.md @@ -18,7 +18,7 @@ The Harvester Helm Chart is used to manage access to the NeuVector UI in Rancher 1. Click **☰ > Cluster Management**. 1. On the Clusters page, go to the cluster where you want to deploy NeuVector, and click **Explore**. 1. Go to **Apps & Marketplace > Repositories**, then click **Create**. -1. In the Target section, select **Git repository containing Helm chart or cluster template definitions**. Then enter the index URL of https://github.com/selvamt94/charts.git and the branch **neuvector**. Click **Create**. +1. In the Target section, select **Git repository containing Helm chart or cluster template definitions**. Then enter the index URL of https://github.com/rancher/charts.git and the branch **neuvector**. Click **Create**. 1. Go to **Apps & Marketplace > Charts**, and install **NeuVector** from the chart repo. When configuring Helm chart values, go to the **Container Runtime** section, de-select **Docker** and instead select **Containerd Runtime**. Finally, click **Install** again. **To navigate to and install the NeuVector chart through Cluster Tools:** From 3492e0cc0c84576dc9d310f7106c1a0c392e4ec5 Mon Sep 17 00:00:00 2001 From: Jennifer Travinski Date: Fri, 29 Apr 2022 14:08:31 -0400 Subject: [PATCH 06/22] Updated per QA feedback --- .../v2.6/en/neuvector-integration/_index.md | 42 +++++++++++++------ 1 file changed, 30 insertions(+), 12 deletions(-) diff --git a/content/rancher/v2.6/en/neuvector-integration/_index.md b/content/rancher/v2.6/en/neuvector-integration/_index.md index 7f726bf15b3..49a79259a09 100644 --- a/content/rancher/v2.6/en/neuvector-integration/_index.md +++ b/content/rancher/v2.6/en/neuvector-integration/_index.md @@ -3,7 +3,7 @@ title: NeuVector Integration weight: 22 --- -##### _Tech Preview_ +### NeuVector Integration in Rancher New in Rancher v2.6.5, [NeuVector 5.x](https://open-docs.neuvector.com/) is an open-source container-centric security platform that is now integrated into Rancher. NeuVector offers real-time compliance, visibility, and protection for critical applications and data during runtime. NeuVector provides a firewall, container process/file system monitoring, security auditing with CIS benchmarks, and vulnerability scanning. For more information on Rancher security, please see the [security documentation]({{}}/rancher/v2.6/en/security/). @@ -17,35 +17,40 @@ The Harvester Helm Chart is used to manage access to the NeuVector UI in Rancher 1. Click **☰ > Cluster Management**. 1. On the Clusters page, go to the cluster where you want to deploy NeuVector, and click **Explore**. -1. Go to **Apps & Marketplace > Repositories**, then click **Create**. -1. In the Target section, select **Git repository containing Helm chart or cluster template definitions**. Then enter the index URL of https://github.com/rancher/charts.git and the branch **neuvector**. Click **Create**. -1. Go to **Apps & Marketplace > Charts**, and install **NeuVector** from the chart repo. When configuring Helm chart values, go to the **Container Runtime** section, de-select **Docker** and instead select **Containerd Runtime**. Finally, click **Install** again. +1. Go to **Apps & Marketplace > Charts**, and install **NeuVector** from the chart repo. +1. Different cluster types require different container runtimes. When configuring Helm chart values, go to the **Container Runtime** section, and select your runtime in accordance with the cluster type: + + - RKE1: Select `docker` + - K3s and RKE2: Select `k3scontainerd` + - AKS: Select `containerd`
+ + >**Note:** Only one container runtime engine may be selected at a time during installation. +1. Click **Install** again. **To navigate to and install the NeuVector chart through Cluster Tools:** -1. Repeat steps 1 - 4 above. +1. Click **☰ > Cluster Management**. +1. On the Clusters page, go to the cluster where you want to deploy NeuVector, and click **Explore**. 1. Click on **Cluster Tools** at the bottom of the left navigation bar. -1. Select the **NeuVector** chart and then click **Install**. When configuring Helm chart values, go to the **Container Runtime** section, de-select **Docker** and instead select **Containerd Runtime**. Finally, click **Install** again. +1. Repeat step 4 above to select your container runtime accordingly, then click **Install** again. ### Accessing NeuVector from the Rancher UI -1. Go to the cluster where NeuVector is installed. In the left navigation bar, click **NeuVector**. -1. Click the external link to go to the NeuVector UI. +1. Navigate to the cluster explorer of the cluster where NeuVector is installed. In the left navigation bar, click **NeuVector**. +1. Click the external link to go to the NeuVector UI. Once the link is selected, users must accept the `END USER LICENSE AGREEMENT` to access the NeuVector UI. ### Uninstalling NeuVector from the Rancher UI **To uninstall from Apps & Marketplace:** 1. Click **☰ > Cluster Management**. -1. On the Clusters page, go to the cluster where NeuVector is deployed, and click **Explore**. -1. In the left navigation bar, click **NeuVector**. 1. Under **Apps & Marketplace**, click **Installed Apps**. 1. Under `cattle-neuvector-system`, select both the NeuVector app (and the associated CRD if desired), then click **Delete**. **To uninstall from Cluster Tools:** -1. Repeat steps 1 - 3 above. -1. Click on **Cluster Tools** at the bottom-left of the screen, then click on the trash can icon under the NeuVector chart. Select `Delete the CRD associated with this app` if desired. +1. Click **☰ > Cluster Management**. +1. Click on **Cluster Tools** at the bottom-left of the screen, then click on the trash can icon under the NeuVector chart. Select `Delete the CRD associated with this app` if desired, then click **Delete**. ### GitHub Repository @@ -74,6 +79,19 @@ The NeuVector security solution contains four types of security containers: Cont To learn more about NeuVector's architecture, please refer [here](https://open-docs.neuvector.com/basics/overview#architecture). +### CPU and Memory Allocations + +Below are the minimum recommended computing resources for the NeuVector chart installation in a default deployment. Note that the resource limit is not set. + +| Container | CPU - Request | Memory - Request | +|------------|--------|---------| +| Controller | 3 (1GB 1vCPU needed per controller) | * +| Enforcer | On all nodes (500MB .5vCPU) | 1GB +| Manager | 1 (500MB .5vCPU) | * +| Scanner | 3 (100MB .5vCPU) | * + +\* Minimum 1GB of memory total required for Controller, Manager, and Scanner containers combined. + ### Limitations * Currently, NeuVector feature chart installation fails when a NeuVector partner chart already exists. To work around this issue, uninstall the NeuVector partner chart and reinstall the NeuVector feature chart. From 8983a4e2ce0dd410397014c17a59d585a9425c05 Mon Sep 17 00:00:00 2001 From: Billy Tat Date: Mon, 2 May 2022 19:22:17 -0700 Subject: [PATCH 07/22] Remove RKE2 tech preview verbiage --- .../v2.6/en/cluster-admin/editing-clusters/_index.md | 4 ++-- .../editing-clusters/k3s-config-reference/_index.md | 2 +- .../editing-clusters/rke2-config-reference/_index.md | 2 +- .../v2.6/en/cluster-provisioning/rke-clusters/_index.md | 6 +++--- .../cluster-provisioning/rke-clusters/node-pools/_index.md | 4 ++-- .../rke-clusters/windows-clusters/_index.md | 6 +++--- .../v2.6/en/installation/resources/feature-flags/_index.md | 2 +- 7 files changed, 13 insertions(+), 13 deletions(-) diff --git a/content/rancher/v2.6/en/cluster-admin/editing-clusters/_index.md b/content/rancher/v2.6/en/cluster-admin/editing-clusters/_index.md index c9e257784be..cab7cdd0d06 100644 --- a/content/rancher/v2.6/en/cluster-admin/editing-clusters/_index.md +++ b/content/rancher/v2.6/en/cluster-admin/editing-clusters/_index.md @@ -12,8 +12,8 @@ For information on editing cluster membership, go to [this page.]({{}}/ The cluster configuration options depend on the type of Kubernetes cluster: - [RKE Cluster Configuration](./rke-config-reference) -- [RKE2 Cluster Configuration](./rke2-config-reference) (Tech Preview) -- [K3s Cluster Configuration](./k3s-config-reference) (Tech Preview) +- [RKE2 Cluster Configuration](./rke2-config-reference) +- [K3s Cluster Configuration](./k3s-config-reference) - [EKS Cluster Configuration](./eks-config-reference) - [GKE Cluster Configuration](./gke-config-reference) - [AKS Cluster Configuration](./aks-config-reference) diff --git a/content/rancher/v2.6/en/cluster-admin/editing-clusters/k3s-config-reference/_index.md b/content/rancher/v2.6/en/cluster-admin/editing-clusters/k3s-config-reference/_index.md index 47ee18b44e2..00d784cfa0c 100644 --- a/content/rancher/v2.6/en/cluster-admin/editing-clusters/k3s-config-reference/_index.md +++ b/content/rancher/v2.6/en/cluster-admin/editing-clusters/k3s-config-reference/_index.md @@ -1,5 +1,5 @@ --- -title: K3s Cluster Configuration Reference (Tech Preview) +title: K3s Cluster Configuration Reference shortTitle: K3s Cluster Configuration weight: 6 --- diff --git a/content/rancher/v2.6/en/cluster-admin/editing-clusters/rke2-config-reference/_index.md b/content/rancher/v2.6/en/cluster-admin/editing-clusters/rke2-config-reference/_index.md index 54539ceb934..7211d96d859 100644 --- a/content/rancher/v2.6/en/cluster-admin/editing-clusters/rke2-config-reference/_index.md +++ b/content/rancher/v2.6/en/cluster-admin/editing-clusters/rke2-config-reference/_index.md @@ -1,5 +1,5 @@ --- -title: RKE2 Cluster Configuration Reference (Tech Preview) +title: RKE2 Cluster Configuration Reference shortTitle: RKE2 Cluster Configuration weight: 5 --- diff --git a/content/rancher/v2.6/en/cluster-provisioning/rke-clusters/_index.md b/content/rancher/v2.6/en/cluster-provisioning/rke-clusters/_index.md index 0b5c79028c5..58b176bbc79 100644 --- a/content/rancher/v2.6/en/cluster-provisioning/rke-clusters/_index.md +++ b/content/rancher/v2.6/en/cluster-provisioning/rke-clusters/_index.md @@ -15,10 +15,10 @@ RKE clusters include clusters that Rancher launched on Windows nodes or other ex ### Changes in Rancher v2.6 -_Tech Preview_ - Rancher v2.6 introduces provisioning for [RKE2](https://docs.rke2.io/) clusters directly from the Rancher UI. RKE2, also known as RKE Government, is a fully conformant Kubernetes distribution that focuses on security and compliance within the U.S. Federal Government sector. +As of Rancher v2.6.5, provisioning for RKE2 is GA. + RKE2 provisioning is built on top of a new provisioning framework that leverages the upstream [Cluster API](https://github.com/kubernetes-sigs/cluster-api) project. With this new provisioning framework, you can: - Provision RKE2 clusters on Digital Ocean, AWS EC2, Azure, and vSphere @@ -26,7 +26,7 @@ RKE2 provisioning is built on top of a new provisioning framework that leverages - Choose CNI options Calico, Cilium, and Multus in addition to Canal - Install custom RKE2 clusters on pre-provisioned VMs or bare-metal nodes -The RKE2 provisioning tech preview also includes installing RKE2 on Windows clusters. Windows features for RKE2 include: +The RKE2 provisioning features also includes installing RKE2 on Windows clusters. Windows features for RKE2 include: - Windows Containers with RKE2 powered by containerd - Added provisioning of Windows RKE2 custom clusters directly from the Rancher UI diff --git a/content/rancher/v2.6/en/cluster-provisioning/rke-clusters/node-pools/_index.md b/content/rancher/v2.6/en/cluster-provisioning/rke-clusters/node-pools/_index.md index 3c89deb26c9..4b31f58bfa3 100644 --- a/content/rancher/v2.6/en/cluster-provisioning/rke-clusters/node-pools/_index.md +++ b/content/rancher/v2.6/en/cluster-provisioning/rke-clusters/node-pools/_index.md @@ -27,7 +27,7 @@ This section covers the following topics: # Changes in Rancher v2.6 -_Tech Preview_ + Rancher v2.6 introduces provisioning for [RKE2](https://docs.rke2.io/) clusters directly from the Rancher UI. RKE2, also known as RKE Government, is a fully conformant Kubernetes distribution that focuses on security and compliance within the U.S. Federal Government sector. @@ -148,4 +148,4 @@ In our [recommended cluster architecture]({{}}/rancher/v2.6/en/cluster- - At least two nodes with the role controlplane for master component high availability - At least two nodes with the role worker for workload rescheduling upon node failure -The implementation of the three node roles in Rancher means that Rancher managed RKE2 clusters are able to easily leverage all of the same architectural best practices that are recommended for RKE clusters. \ No newline at end of file +The implementation of the three node roles in Rancher means that Rancher managed RKE2 clusters are able to easily leverage all of the same architectural best practices that are recommended for RKE clusters. diff --git a/content/rancher/v2.6/en/cluster-provisioning/rke-clusters/windows-clusters/_index.md b/content/rancher/v2.6/en/cluster-provisioning/rke-clusters/windows-clusters/_index.md index ebd32e5397d..5db4add3d41 100644 --- a/content/rancher/v2.6/en/cluster-provisioning/rke-clusters/windows-clusters/_index.md +++ b/content/rancher/v2.6/en/cluster-provisioning/rke-clusters/windows-clusters/_index.md @@ -30,11 +30,11 @@ This guide covers the following topics: # Changes in Rancher v2.6 -_Tech Preview_ - Rancher v2.6 introduces provisioning for [RKE2](https://docs.rke2.io/) clusters directly from the Rancher UI. RKE2, also known as RKE Government, is a fully conformant Kubernetes distribution that focuses on security and compliance within the U.S. Federal Government sector. -The RKE2 provisioning tech preview also includes installing RKE2 on Windows clusters. Windows features for RKE2 include: +As of Rancher v2.6.5, provisioning for RKE2 is GA. + +The RKE2 provisioning feature also includes installing RKE2 on Windows clusters. Windows features for RKE2 include: - Windows Containers with RKE2 powered by containerd - Added provisioning of Windows RKE2 custom clusters directly from the Rancher UI diff --git a/content/rancher/v2.6/en/installation/resources/feature-flags/_index.md b/content/rancher/v2.6/en/installation/resources/feature-flags/_index.md index a1f92902d3d..25baf0c06a2 100644 --- a/content/rancher/v2.6/en/installation/resources/feature-flags/_index.md +++ b/content/rancher/v2.6/en/installation/resources/feature-flags/_index.md @@ -26,7 +26,7 @@ For example, if you install Rancher, then set a feature flag to true with the Ra The following is a list of the feature flags available in Rancher: - `harvester`: This feature flag is available starting in v2.6.1. It is used to manage access to the Virtualization Management page where users can navigate directly to Harvester clusters and access the Harvester UI. For more information, see [this page]({{}}/rancher/v2.6/en/virtualization-admin/#feature-flag/). -- `rke2`: We have introduced the ability to provision RKE2 clusters as tech preview. By default, this feature flag is enabled, which allows users to attempt to provision these type of clusters. +- `rke2`: Used to enable the ability to provision RKE2 clusters. By default, this feature flag is enabled, which allows users to attempt to provision these type of clusters. - `fleet`: The previous `fleet` feature flag is now required to be enabled as the Fleet capabilities are leveraged within the new provisioning framework. If you had this feature flag disabled in earlier versions, upon upgrading to Rancher v2.6, the flag will automatically be enabled. See this [page]({{}}/rancher/v2.6/en/deploy-across-clusters/fleet) for more information. - `continuous-delivery`: In Rancher v2.5.x, Fleet came with a GitOps feature that could not be disabled separately from Fleet. In Rancher v2.6, the `continuous-delivery` feature flag was introduced to allow the GitOps feature of Fleet to be disabled. For more information, see [this page.](./continuous-delivery). - `legacy`: There are a set of features from previous versions that are slowly being phased out of Rancher for newer iterations of the feature. This is a mix of deprecated features as well as features that will eventually be moved to newer variations in Rancher. By default, this feature flag is disabled for new installations. If you are upgrading from a previous version, this feature flag would be enabled. From 5b23b7fae53bcd5d0716e6cfe5e3446a319e7b52 Mon Sep 17 00:00:00 2001 From: Jennifer Travinski Date: Tue, 3 May 2022 11:30:59 -0400 Subject: [PATCH 08/22] Updating per feedback --- .../rancher/v2.6/en/neuvector-integration/_index.md | 13 ++++++++----- 1 file changed, 8 insertions(+), 5 deletions(-) diff --git a/content/rancher/v2.6/en/neuvector-integration/_index.md b/content/rancher/v2.6/en/neuvector-integration/_index.md index 49a79259a09..c5705871a5f 100644 --- a/content/rancher/v2.6/en/neuvector-integration/_index.md +++ b/content/rancher/v2.6/en/neuvector-integration/_index.md @@ -18,14 +18,17 @@ The Harvester Helm Chart is used to manage access to the NeuVector UI in Rancher 1. Click **☰ > Cluster Management**. 1. On the Clusters page, go to the cluster where you want to deploy NeuVector, and click **Explore**. 1. Go to **Apps & Marketplace > Charts**, and install **NeuVector** from the chart repo. -1. Different cluster types require different container runtimes. When configuring Helm chart values, go to the **Container Runtime** section, and select your runtime in accordance with the cluster type: +1. Different cluster types require different container runtimes. When configuring Helm chart values, go to the **Container Runtime** section, and select your runtime in accordance with the cluster type. Finally, click **Install** again. - - RKE1: Select `docker` - - K3s and RKE2: Select `k3scontainerd` - - AKS: Select `containerd`
+Some examples are as follows: + + - RKE1: `docker` + - K3s and RKE2: `k3scontainerd` + - AKS: `containerd` for v1.19 and up + - EKS: `docker` for v1.22 and below; `containerd` for v1.23 and up + - GKE: `containerd` (see the [Google docs](https://cloud.google.com/kubernetes-engine/docs/concepts/using-containerd) for more) >**Note:** Only one container runtime engine may be selected at a time during installation. -1. Click **Install** again. **To navigate to and install the NeuVector chart through Cluster Tools:** From b93e7d65a3886b201adfa319d8f8cad34a2f3e9c Mon Sep 17 00:00:00 2001 From: Jennifer Travinski Date: Thu, 5 May 2022 09:52:45 -0400 Subject: [PATCH 09/22] Adding limitations per feedback --- .../v2.6/en/neuvector-integration/_index.md | 16 ++++++++++++++-- 1 file changed, 14 insertions(+), 2 deletions(-) diff --git a/content/rancher/v2.6/en/neuvector-integration/_index.md b/content/rancher/v2.6/en/neuvector-integration/_index.md index c5705871a5f..a829c3d5b6b 100644 --- a/content/rancher/v2.6/en/neuvector-integration/_index.md +++ b/content/rancher/v2.6/en/neuvector-integration/_index.md @@ -95,10 +95,22 @@ Below are the minimum recommended computing resources for the NeuVector chart in \* Minimum 1GB of memory total required for Controller, Manager, and Scanner containers combined. -### Limitations + +### Support Limitations + +* Only admins and cluster owners are currently supported. + +* Fleet multi-cluster deployment is not supported. + +* NeuVector is not supported on a Windows cluster. + +* Airgap is not supported. + +### Other Limitations * Currently, NeuVector feature chart installation fails when a NeuVector partner chart already exists. To work around this issue, uninstall the NeuVector partner chart and reinstall the NeuVector feature chart. * Users cannot access the NeuVector UI from Rancher for a custom RKE1 cluster. To work around this, restart the controllers; note that while the controller pods are restarting, it will take additional time for the controller pods to become active. -* Container runtime is not auto-detected for different cluster types when installing the NeuVector chart. \ No newline at end of file +* Container runtime is not auto-detected for different cluster types when installing the NeuVector chart. + From b4fa08dbb5b546042bd2a71cd941c6cdb5ce2726 Mon Sep 17 00:00:00 2001 From: Jennifer Travinski Date: Fri, 6 May 2022 15:40:07 -0400 Subject: [PATCH 10/22] Updated issues per Slack feedback --- content/rancher/v2.6/en/neuvector-integration/_index.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/content/rancher/v2.6/en/neuvector-integration/_index.md b/content/rancher/v2.6/en/neuvector-integration/_index.md index a829c3d5b6b..5082c3b844f 100644 --- a/content/rancher/v2.6/en/neuvector-integration/_index.md +++ b/content/rancher/v2.6/en/neuvector-integration/_index.md @@ -104,6 +104,10 @@ Below are the minimum recommended computing resources for the NeuVector chart in * NeuVector is not supported on a Windows cluster. +* Hardened cluster NeuVector installation is not supported. + +* SELinux clusters are not supported. + * Airgap is not supported. ### Other Limitations From cc241d97cef8e322da65c660517e196d3979cec5 Mon Sep 17 00:00:00 2001 From: Jennifer Travinski Date: Sun, 8 May 2022 10:21:54 -0400 Subject: [PATCH 11/22] Updating page per feedback from QA --- content/rancher/v2.6/en/neuvector-integration/_index.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/content/rancher/v2.6/en/neuvector-integration/_index.md b/content/rancher/v2.6/en/neuvector-integration/_index.md index 5082c3b844f..2efefea8934 100644 --- a/content/rancher/v2.6/en/neuvector-integration/_index.md +++ b/content/rancher/v2.6/en/neuvector-integration/_index.md @@ -104,17 +104,17 @@ Below are the minimum recommended computing resources for the NeuVector chart in * NeuVector is not supported on a Windows cluster. -* Hardened cluster NeuVector installation is not supported. +* NeuVector installation is not supported on hardened clusters. -* SELinux clusters are not supported. +* NeuVector installation is not supported on SELinux clusters. -* Airgap is not supported. +* NeuVector installation is not supported on clusters in an air-gapped environment. ### Other Limitations * Currently, NeuVector feature chart installation fails when a NeuVector partner chart already exists. To work around this issue, uninstall the NeuVector partner chart and reinstall the NeuVector feature chart. -* Users cannot access the NeuVector UI from Rancher for a custom RKE1 cluster. To work around this, restart the controllers; note that while the controller pods are restarting, it will take additional time for the controller pods to become active. +* Sometimes when the controllers are not ready, the NeuVector UI is not accessible from the Rancher UI. During this time, controllers will try to restart, and it takes a few minutes for the controllers to be active. * Container runtime is not auto-detected for different cluster types when installing the NeuVector chart. From 7ee7ed7e479091860f0934468bfbcbf3f0c633dd Mon Sep 17 00:00:00 2001 From: Jennifer Travinski Date: Sun, 8 May 2022 10:26:11 -0400 Subject: [PATCH 12/22] Added workaround note --- content/rancher/v2.6/en/neuvector-integration/_index.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/content/rancher/v2.6/en/neuvector-integration/_index.md b/content/rancher/v2.6/en/neuvector-integration/_index.md index 2efefea8934..1c58d6e200a 100644 --- a/content/rancher/v2.6/en/neuvector-integration/_index.md +++ b/content/rancher/v2.6/en/neuvector-integration/_index.md @@ -116,5 +116,5 @@ Below are the minimum recommended computing resources for the NeuVector chart in * Sometimes when the controllers are not ready, the NeuVector UI is not accessible from the Rancher UI. During this time, controllers will try to restart, and it takes a few minutes for the controllers to be active. -* Container runtime is not auto-detected for different cluster types when installing the NeuVector chart. +* Container runtime is not auto-detected for different cluster types when installing the NeuVector chart. To work around this, you can specify the runtime manually. From f097d17c5bb694b22ece7fc352f47d64fa5ce5b4 Mon Sep 17 00:00:00 2001 From: Billy Tat Date: Tue, 10 May 2022 11:45:05 -0700 Subject: [PATCH 13/22] Add Prometheus Federator --- .../configuration/receiver/_index.md | 31 ++++++-- .../prometheus-federator/_index.md | 75 +++++++++++++++++++ .../guides/customizing-grafana/_index.md | 8 ++ .../guides/enable-prom-fed/_index.md | 62 +++++++++++++++ .../guides/prom-fed-workloads/_index.md | 18 +++++ .../guides/uninstall-prom-fed/_index.md | 14 ++++ .../prometheus-federator/rbac/_index.md | 29 +++++++ 7 files changed, 229 insertions(+), 8 deletions(-) create mode 100644 content/rancher/v2.6/en/monitoring-alerting/prometheus-federator/_index.md create mode 100644 content/rancher/v2.6/en/monitoring-alerting/prometheus-federator/guides/customizing-grafana/_index.md create mode 100644 content/rancher/v2.6/en/monitoring-alerting/prometheus-federator/guides/enable-prom-fed/_index.md create mode 100644 content/rancher/v2.6/en/monitoring-alerting/prometheus-federator/guides/prom-fed-workloads/_index.md create mode 100644 content/rancher/v2.6/en/monitoring-alerting/prometheus-federator/guides/uninstall-prom-fed/_index.md create mode 100644 content/rancher/v2.6/en/monitoring-alerting/prometheus-federator/rbac/_index.md diff --git a/content/rancher/v2.6/en/monitoring-alerting/configuration/receiver/_index.md b/content/rancher/v2.6/en/monitoring-alerting/configuration/receiver/_index.md index d1754f86d81..3a9daaeb6ce 100644 --- a/content/rancher/v2.6/en/monitoring-alerting/configuration/receiver/_index.md +++ b/content/rancher/v2.6/en/monitoring-alerting/configuration/receiver/_index.md @@ -24,7 +24,6 @@ The [Alertmanager Config](https://prometheus.io/docs/alerting/latest/configurati - [Trusted CA for Notifiers](#trusted-ca-for-notifiers) # Creating Receivers in the Rancher UI -_Available as of v2.5.4_ > **Prerequisites:** > @@ -33,11 +32,27 @@ _Available as of v2.5.4_ To create notification receivers in the Rancher UI, -1. Go to the cluster where you want to create receivers. Click **Monitoring** and click **Receiver**. +{{% tabs %}} +{{% tab "Rancher v2.6.5+" %}} + +1. Go to the cluster where you want to create receivers. Click **Monitoring -> Alerting -> AlertManagerConfigs**. +1. Ciick **Create**. +1. Click **Add Receiver**. +1. Enter a **Name** for the receiver. +1. Configure one or more providers for the receiver. For help filling out the forms, refer to the configuration options below. +1. Click **Create**. + +{{% /tab %}} +{{% tab "Rancher before v2.6.5" %}} + +1. Go to the cluster where you want to create receivers. Click **Monitoring** and click **Receiver**. 2. Enter a name for the receiver. 3. Configure one or more providers for the receiver. For help filling out the forms, refer to the configuration options below. 4. Click **Create**. +{{% /tab %}} +{{% /tabs %}} + **Result:** Alerts can be configured to send notifications to the receiver(s). # Receiver Configuration @@ -72,7 +87,7 @@ The custom receiver option can be used to configure any receiver in YAML that ca | Field | Type | Description | |------|--------------|------| | URL | String | Enter your Slack webhook URL. For instructions to create a Slack webhook, see the [Slack documentation.](https://get.slack.help/hc/en-us/articles/115005265063-Incoming-WebHooks-for-Slack) | -| Default Channel | String | Enter the name of the channel that you want to send alert notifications in the following format: `#`. | +| Default Channel | String | Enter the name of the channel that you want to send alert notifications in the following format: `#`. | | Proxy URL | String | Proxy for the webhook notifications. | | Enable Send Resolved Alerts | Bool | Whether to send a follow-up notification if an alert has been resolved (e.g. [Resolved] High CPU Usage). | @@ -81,7 +96,7 @@ The custom receiver option can be used to configure any receiver in YAML that ca | Field | Type | Description | |------|--------------|------| | Default Recipient Address | String | The email address that will receive notifications. | -| Enable Send Resolved Alerts | Bool | Whether to send a follow-up notification if an alert has been resolved (e.g. [Resolved] High CPU Usage). | +| Enable Send Resolved Alerts | Bool | Whether to send a follow-up notification if an alert has been resolved (e.g. [Resolved] High CPU Usage). | SMTP options: @@ -100,7 +115,7 @@ SMTP options: | Integration Type | String | `Events API v2` or `Prometheus`. | | Default Integration Key | String | For instructions to get an integration key, see the [PagerDuty documentation.](https://www.pagerduty.com/docs/guides/prometheus-integration-guide/) | | Proxy URL | String | Proxy for the PagerDuty notifications. | -| Enable Send Resolved Alerts | Bool | Whether to send a follow-up notification if an alert has been resolved (e.g. [Resolved] High CPU Usage). | +| Enable Send Resolved Alerts | Bool | Whether to send a follow-up notification if an alert has been resolved (e.g. [Resolved] High CPU Usage). | # Opsgenie @@ -172,7 +187,7 @@ The SMS receiver is not a native receiver and must be enabled before it can be u 1. In the upper left corner, click **☰ > Cluster Management**. 1. On the **Clusters** page, go to the cluster where you want to install `rancher-alerting-drivers` and click **Explore**. -1. In the left navigation bar, click +1. In the left navigation bar, click 1. Click the **Alerting Drivers** app. 1. Click the **Helm Deploy Options** tab 1. Select the **SMS** option and click **Install**. @@ -224,11 +239,11 @@ You can also set up multiple receivers by using the `continue` option for a rout To set up notifications via Slack, the following Alertmanager Config YAML can be placed into the `alertmanager.yaml` key of the Alertmanager Config Secret, where the `api_url` should be updated to use your Webhook URL from Slack: ```yaml -route: +route: group_by: ['job'] group_wait: 30s group_interval: 5m - repeat_interval: 3h + repeat_interval: 3h receiver: 'slack-notifications' receivers: - name: 'slack-notifications' diff --git a/content/rancher/v2.6/en/monitoring-alerting/prometheus-federator/_index.md b/content/rancher/v2.6/en/monitoring-alerting/prometheus-federator/_index.md new file mode 100644 index 00000000000..59d52d235b1 --- /dev/null +++ b/content/rancher/v2.6/en/monitoring-alerting/prometheus-federator/_index.md @@ -0,0 +1,75 @@ +--- +title: Prometheus Federator +weight: 7 +--- + +Prometheus Federator deploys a Helm Project Operator (based on the [rancher/helm-project-operator](https://github.com/rancher/helm-project-operator)), an operator that manages deploying Helm charts each containing a Project Monitoring Stack, where each stack contains: + +- [Prometheus](https://prometheus.io/) (managed externally by [Prometheus Operator](https://github.com/prometheus-operator/prometheus-operator)) +- [Alertmanager](https://prometheus.io/docs/alerting/latest/alertmanager/) (managed externally by [Prometheus Operator](https://github.com/prometheus-operator/prometheus-operator)) +- [Grafana](https://github.com/helm/charts/tree/master/stable/grafana) (deployed via an embedded Helm chart) +- Default PrometheusRules and Grafana dashboards based on the collection of community-curated resources from [kube-prometheus](https://github.com/prometheus-operator/kube-prometheus/) +- Default ServiceMonitors that watch the deployed resources + +> **Important** Prometheus Federator is designed to be deployed alongside an existing Prometheus Operator deployment in a cluster that has already installed the Prometheus Operator CRDs. + +## How does the operator work? + +1. On deploying this chart, users can create ProjectHelmCharts CRs with `spec.helmApiVersion` set to `monitoring.cattle.io/v1alpha1` (also known as "Project Monitors" in the Rancher UI) in a **Project Registration Namespace (`cattle-project-`)**. +2. On seeing each ProjectHelmChartCR, the operator will automatically deploy a Project Prometheus stack on the Project Owner's behalf in the **Project Release Namespace (`cattle-project--monitoring`)** based on a HelmChart CR and a HelmRelease CR automatically created by the ProjectHelmChart controller in the **Operator / System Namespace**. +3. RBAC will automatically be assigned in the Project Release Namespace to allow users to view the Prometheus, Alertmanager, and Grafana UIs of the Project Monitoring Stack deployed; this will be based on RBAC defined on the Project Registration Namespace against the [default Kubernetes user-facing roles](https://kubernetes.io/docs/reference/access-authn-authz/rbac/#user-facing-roles). For more information, see the section on [configuring RBAC](./rbac/). + +### What is a Project? + +In Prometheus Federator, a Project is a group of namespaces that can be identified by a `metav1.LabelSelector`. By default, the label used to identify projects is `field.cattle.io/projectId`, the label used to identify namespaces that are contained within a given [Rancher](https://rancher.com/) Project. + +### Configuring the Helm release created by a ProjectHelmChart + +The `spec.values` of this ProjectHelmChart resources will correspond to the `values.yaml` override to be supplied to the underlying Helm chart deployed by the operator on the user's behalf; to see the underlying chart's `values.yaml` spec, either: + +- View to the chart's definition located at [`rancher/prometheus-federator` under `charts/rancher-project-monitoring`](https://github.com/rancher/prometheus-federator/blob/main/charts/rancher-project-monitoring) (where the chart version will be tied to the version of this operator) +- Look for the ConfigMap named `monitoring.cattle.io.v1alpha1` that is automatically created in each Project Registration Namespace, which will contain both the `values.yaml` and `questions.yaml` that was used to configure the chart (which was embedded directly into the `prometheus-federator` binary). + +### Namespaces + +As a Project Operator based on [rancher/helm-project-operator](https://github.com/rancher/helm-project-operator), Prometheus Federator has three different classifications of namespaces that the operator looks out for: + +1. **Operator / System Namespace**: this is the namespace that the operator is deployed into (e.g., `cattle-monitoring-system`). This namespace will contain all HelmCharts and HelmReleases for all ProjectHelmCharts watched by this operator. **Only Cluster Admins should have access to this namespace.** +2. **Project Registration Namespace (`cattle-project-`)**: this is the set of namespaces that the operator watches for ProjectHelmCharts within. The RoleBindings and ClusterRoleBindings that apply to this namespace will also be the source of truth for the auto-assigned RBAC created in the Project Release Namespace. For details, refer to the [RBAC page](./rbac/). **Project Owners (admin), Project Members (edit), and Read-Only Members (view) should have access to this namespace**. +> Note: Project Registration Namespaces will be auto-generated by the operator and imported into the Project it is tied to if `.Values.global.cattle.projectLabel` is provided (which is set to `field.cattle.io/projectId` by default); this indicates that a Project Registration Namespace should be created by the operator if at least one namespace is observed with that label. The operator will not let these namespaces be deleted unless either all namespaces with that label are gone (e.g. this is the last namespace in that project, in which case the namespace will be marked with the label `"helm.cattle.io/helm-project-operator-orphaned": "true"`, which signals that it can be deleted) or it is no longer watching that project (because the project ID was provided under `.Values.helmProjectOperator.otherSystemProjectLabelValues`, which serves as a denylist for Projects). These namespaces will also never be auto-deleted to avoid destroying user data; it is recommended that users clean up these namespaces manually if desired on creating or deleting a project +> Note: if `.Values.global.cattle.projectLabel` is not provided, the Operator / System Namespace will also be the Project Registration Namespace +3. **Project Release Namespace (`cattle-project--monitoring`)**: this is the set of namespaces that the operator deploys Project Monitoring Stacks within on behalf of a ProjectHelmChart; the operator will also automatically assign RBAC to Roles created in this namespace by the Project Monitoring Stack based on bindings found in the Project Registration Namespace. **Only Cluster Admins should have access to this namespace; Project Owners (admin), Project Members (edit), and Read-Only Members (view) will be assigned limited access to this namespace by the deployed Helm Chart and Prometheus Federator.** + > Note: Project Release Namespaces are automatically deployed and imported into the project whose ID is specified under `.Values.helmProjectOperator.projectReleaseNamespaces.labelValue` (which defaults to the value of `.Values.global.cattle.systemProjectId` if not specified) whenever a ProjectHelmChart is specified in a Project Registration Namespace +> Note: Project Release Namespaces follow the same orphaning conventions as Project Registration Namespaces (see note above) +> Note: if `.Values.projectReleaseNamespaces.enabled` is false, the Project Release Namespace will be the same as the Project Registration Namespace + +### Helm Resources (HelmChart, HelmRelease) + +On deploying a ProjectHelmChart, the Prometheus Federator will automatically create and manage two child custom resources that manage the underlying Helm resources in turn: + +- A HelmChart CR (managed via an embedded [k3s-io/helm-contoller](https://github.com/k3s-io/helm-controller) in the operator): this custom resource automatically creates a Job in the same namespace that triggers a `helm install`, `helm upgrade`, or `helm uninstall` depending on the change applied to the HelmChart CR; this CR is automatically updated on changes to the ProjectHelmChart (e.g. modifying the values.yaml) or changes to the underlying Project definition (e.g. adding or removing namespaces from a project). + +> **Important** If a ProjectHelmChart is not deploying or updating the underlying Project Monitoring Stack for some reason, the Job created by this resource in the Operator / System namespace should be the first place you check to see if there's something wrong with the Helm operation; however, this is generally only accessible by a Cluster Admin.** + +- A HelmRelease CR (managed via an embedded [rancher/helm-locker](https://github.com/rancher/helm-locker) in the operator): this custom resource automatically locks a deployed Helm release in place and automatically overwrites updates to underlying resources unless the change happens via a Helm operation (`helm install`, `helm upgrade`, or `helm uninstall` performed by the HelmChart CR). + +> **Note** HelmRelease CRs emit Kubernetes Events that detect when an underlying Helm release is being modified and locks it back to place; to view these events, you can use `kubectl describe helmrelease -n `; you can also view the logs on this operator to see when changes are detected and which resources were attempted to be modified + +Both of these resources are created for all Helm charts in the Operator / System namespaces to avoid escalation of privileges to underprivileged users. + +### Advanced Helm Project Operator Configuration + +For more information on advanced configurations, refer to [this page](https://github.com/rancher/prometheus-federator/blob/main/charts/prometheus-federator/0.0.1/README.md#advanced-helm-project-operator-configuration). + + + diff --git a/content/rancher/v2.6/en/monitoring-alerting/prometheus-federator/guides/customizing-grafana/_index.md b/content/rancher/v2.6/en/monitoring-alerting/prometheus-federator/guides/customizing-grafana/_index.md new file mode 100644 index 00000000000..f5cc1e5653d --- /dev/null +++ b/content/rancher/v2.6/en/monitoring-alerting/prometheus-federator/guides/customizing-grafana/_index.md @@ -0,0 +1,8 @@ +--- +title: Customizing Grafana Dashboards +weight: 3 +--- + +Grafana dashboards are customized the same way whether it's for rancher-monitoring or for Prometheus Federator. + +For instructions, refer to [this page](../../../guides/customize-grafana/). \ No newline at end of file diff --git a/content/rancher/v2.6/en/monitoring-alerting/prometheus-federator/guides/enable-prom-fed/_index.md b/content/rancher/v2.6/en/monitoring-alerting/prometheus-federator/guides/enable-prom-fed/_index.md new file mode 100644 index 00000000000..867e126ea0e --- /dev/null +++ b/content/rancher/v2.6/en/monitoring-alerting/prometheus-federator/guides/enable-prom-fed/_index.md @@ -0,0 +1,62 @@ +--- +title: Enable Prometheus Federator +weight: 1 +--- + +- [Requirements](#requirements) +- [Install the Prometheus Federator Application](#install-the-prometheus-federator-application) + +# Requirements + +By default, Prometheus Federator is configured and intended to be deployed alongside [rancher-monitoring](https://rancher.com/docs/rancher/v2.6/en/monitoring-alerting/), which deploys Prometheus Operator alongside a Cluster Prometheus that each Project Monitoring Stack is configured to federate namespace-scoped metrics from by default. + +For instructions to install rancher-monitoring, refer [this page](../../../guides/enable-monitoring/). + +The default configuration should already be compatible with your rancher-monitoring stack. However, to optimize the security and usability of Prometheus Federator in your cluster, we recommend making these additional configurations to rancher-monitoring: + +- [Ensure the cattle-monitoring-system namespace is placed into the System Project](#ensure-the-cattle-monitoring-system-namespace-is-placed-into-the-system-project-or-a-similarly-locked-down-project-that-has-access-to-other-projects-in-the-cluster) +- [Configure rancher-monitoring to only watch for resources created by the Helm chart itself](#configure-rancher-monitoring-to-only-watch-for-resources-created-by-the-helm-chart-itself) +- [Increase the CPU / memory limits of the Cluster Prometheus](#increase-the-cpu--memory-limits-of-the-cluster-prometheus) + +## Ensure the cattle-monitoring-system namespace is placed into the System Project (or a similarly locked down Project that has access to other Projects in the cluster) + +Prometheus Operator's security model expects that the namespace it is deployed into (e.g., `cattle-monitoring-system`) has limited access for anyone except Cluster Admins to avoid privilege escalation via execing into Pods (such as the Jobs executing Helm operations). In addition, deploying Prometheus Federator and all Project Prometheus stacks into the System Project ensures that the each Project Prometheus is able to reach out to scrape workloads across all Projects (even if Network Policies are defined via Project Network Isolation) but has limited access for Project Owners, Project Members, and other users to be able to access data they shouldn't have access to (i.e., being allowed to exec into pods, set up the ability to scrape namespaces outside of a given Project, etc.). + +## Configure rancher-monitoring to only watch for resources created by the Helm chart itself + +Since each Project Monitoring Stack will watch the other namespaces and collect additional custom workload metrics or dashboards already, it's recommended to configure the following settings on all selectors to ensure that the Cluster Prometheus Stack only monitors resources created by the Helm Chart itself: + +``` +matchLabels: + release: "rancher-monitoring" +``` + +The following selector fields are recommended to have this value: +- `.Values.alertmanager.alertmanagerSpec.alertmanagerConfigSelector` +- `.Values.prometheus.prometheusSpec.serviceMonitorSelector` +- `.Values.prometheus.prometheusSpec.podMonitorSelector` +- `.Values.prometheus.prometheusSpec.ruleSelector` +- `.Values.prometheus.prometheusSpec.probeSelector` + +Once this setting is turned on, you can always create ServiceMonitors or PodMonitors that are picked up by the Cluster Prometheus by adding the label `release: "rancher-monitoring"` to them (in which case they will be ignored by Project Monitoring Stacks automatically by default, even if the namespace in which those ServiceMonitors or PodMonitors reside in are not system namespaces). + +> Note: If you don't want to allow users to be able to create ServiceMonitors and PodMonitors that aggregate into the Cluster Prometheus in Project namespaces, you can additionally set the namespaceSelectors on the chart to only target system namespaces (which must contain `cattle-monitoring-system` and `cattle-dashboards`, where resources are deployed into by default by rancher-monitoring; you will also need to monitor the `default` namespace to get apiserver metrics or create a custom ServiceMonitor to scrape apiserver metrics from the Service residing in the default namespace) to limit your Cluster Prometheus from picking up other Prometheus Operator CRs; in that case, it would be recommended to turn `.Values.prometheus.prometheusSpec.ignoreNamespaceSelectors=true` to allow you to define ServiceMonitors that can monitor non-system namespaces from within a system namespace. + +## Increase the CPU / memory limits of the Cluster Prometheus + +Depending on a cluster's setup, it's generally recommended to give a large amount of dedicated memory to the Cluster Prometheus to avoid restarts due to out-of-memory errors (OOMKilled), usually caused by churn created in the cluster that causes a large number of high cardinality metrics to be generated and ingested by Prometheus within one block of time; this is one of the reasons why the default Rancher Monitoring stack expects around 4GB of RAM to be able to operate in a normal-sized cluster. However, when introducing Project Monitoring Stacks that are all sending `/federate` requests to the same Cluster Prometheus and are reliant on the Cluster Prometheus being "up" to federate that system data on their namespaces, it's even more important that the Cluster Prometheus has an ample amount of CPU / memory assigned to it to prevent an outage that can cause data gaps across all Project Prometheis in the cluster. + +> Note: There are no specific recommendations on how much memory the Cluster Prometheus should be configured with since it depends entirely on the user's setup (namely the likelihood of encountering a high churn rate and the scale of metrics that could be generated at that time); it generally varies per setup. + +# Install the Prometheus Federator Application + +1. Click **☰ > Cluster Management**. +1. Go to the cluster that you want to install Prometheus Federator and click **Explore**. +1. Click **Apps -> Charts**. +1. Click the **Prometheus Federator** chart. +1. Click **Install**. +1. On the **Metadata** page, click **Next**. +1. In the **Project Release Namespace Project ID** field, the `System Project` is used as the default but can be overridden with another project with similarly [limited access](#ensure-the-cattle-monitoring-system-namespace-is-placed-into-the-system-project-or-a-similarly-locked-down-project-that-has-access-to-other-projects-in-the-cluster). +### Prometheus Federator on the Local Cluster + +Prometheus Federator is a resource intensive application. Installing it to the local cluster is possible, but **not recommended**. \ No newline at end of file From c1537b0af822dbdd2d42f5377f3ac49d1c63701d Mon Sep 17 00:00:00 2001 From: Billy Tat Date: Tue, 10 May 2022 18:36:26 -0700 Subject: [PATCH 15/22] Rancher CLI not compatible with feature charts --- content/rancher/v2.6/en/cli/_index.md | 16 +++++++----- content/rancher/v2.6/en/helm-charts/_index.md | 26 +++++++++++-------- 2 files changed, 25 insertions(+), 17 deletions(-) diff --git a/content/rancher/v2.6/en/cli/_index.md b/content/rancher/v2.6/en/cli/_index.md index 89928a7dc9b..81b7b55c876 100644 --- a/content/rancher/v2.6/en/cli/_index.md +++ b/content/rancher/v2.6/en/cli/_index.md @@ -1,5 +1,5 @@ --- -title: Using the Rancher Command Line Interface +title: Using the Rancher Command Line Interface description: The Rancher CLI is a unified tool that you can use to interact with Rancher. With it, you can operate Rancher using a command line interface rather than the GUI metaTitle: "Using the Rancher Command Line Interface " metaDescription: "The Rancher CLI is a unified tool that you can use to interact with Rancher. With it, you can operate Rancher using a command line interface rather than the GUI" @@ -36,11 +36,11 @@ Before you can perform any commands, you must select a Rancher project to perfor **Example: `./rancher context switch` Output** ``` User:rancher-cli-directory user$ ./rancher context switch -NUMBER CLUSTER NAME PROJECT ID PROJECT NAME -1 cluster-2 c-7q96s:p-h4tmb project-2 -2 cluster-2 c-7q96s:project-j6z6d Default -3 cluster-1 c-lchzv:p-xbpdt project-1 -4 cluster-1 c-lchzv:project-s2mch Default +NUMBER CLUSTER NAME PROJECT ID PROJECT NAME +1 cluster-2 c-7q96s:p-h4tmb project-2 +2 cluster-2 c-7q96s:project-j6z6d Default +3 cluster-1 c-lchzv:p-xbpdt project-1 +4 cluster-1 c-lchzv:project-s2mch Default Select a Project: ``` @@ -78,3 +78,7 @@ The following commands are available for use in Rancher CLI. Once logged into Rancher Server using the CLI, enter `./rancher --help` for a list of commands. All commands accept the `--help` flag, which documents each command's usage. + +### Limitations + +The Rancher CLI **cannot** be used to install [dashboard apps or Rancher feature charts](../helm-charts/). diff --git a/content/rancher/v2.6/en/helm-charts/_index.md b/content/rancher/v2.6/en/helm-charts/_index.md index ca9a26eae82..68f8c757fcd 100644 --- a/content/rancher/v2.6/en/helm-charts/_index.md +++ b/content/rancher/v2.6/en/helm-charts/_index.md @@ -9,7 +9,7 @@ In this section, you'll learn how to manage Helm chart repositories and applicat Starting in Rancher v2.6.0, a new versioning scheme for Rancher feature charts was implemented. The changes are centered around the major version of the charts and the +up annotation for upstream charts, where applicable. -**Major Version:** The major version of the charts is tied to Rancher minor versions. When you upgrade to a new Rancher minor version, you should ensure that all of your **Apps & Marketplace** charts are also upgraded to the correct release line for the chart. +**Major Version:** The major version of the charts is tied to Rancher minor versions. When you upgrade to a new Rancher minor version, you should ensure that all of your **Apps & Marketplace** charts are also upgraded to the correct release line for the chart. >**Note:** Any major versions that are less than the ones mentioned in the table below are meant for 2.5 and below only. For example, you are advised to not use <100.x.x versions of Monitoring in 2.6.x+. @@ -20,25 +20,25 @@ Starting in Rancher v2.6.0, a new versioning scheme for Rancher feature charts w | external-ip-webhook | 100.0.0+up1.0.0 | 100.0.1+up1.0.1 | | harvester-cloud-provider | 100.0.0+up0.1.8 | 100.0.0+up0.1.8 | | harvester-csi-driver | 100.0.0+up0.1.9 | 100.0.0+up0.1.9 | -| rancher-alerting-drivers | 100.0.0 | 100.0.1 | +| rancher-alerting-drivers | 100.0.0 | 100.0.1 | | rancher-backups | 2.0.0 | 2.1.0 | -| rancher-cis-benchmark | 2.0.0 | 2.0.2 | -| rancher-gatekeeper | 100.0.0+up3.5.1 | 100.0.1+up3.6.0 | +| rancher-cis-benchmark | 2.0.0 | 2.0.2 | +| rancher-gatekeeper | 100.0.0+up3.5.1 | 100.0.1+up3.6.0 | | rancher-istio | 100.0.0+up1.10.4 | 100.1.0+up1.11.4 | | rancher-logging | 100.0.0+up3.12.0 | 100.0.1+up3.15.0 | -| rancher-longhorn | 100.0.0+up1.1.2 | 100.1.1+up1.2.3 | +| rancher-longhorn | 100.0.0+up1.1.2 | 100.1.1+up1.2.3 | | rancher-monitoring | 100.0.0+up16.6.0 | 100.1.0+up19.0.3 -| rancher-sriov (experimental) | 100.0.0+up0.1.0 | 100.0.1+up0.1.0 | +| rancher-sriov (experimental) | 100.0.0+up0.1.0 | 100.0.1+up0.1.0 | | rancher-vsphere-cpi | 100.0.0 | 100.1.0+up1.0.100 | rancher-vsphere-csi | 100.0.0 | 100.1.0+up2.3.0 | -| rancher-wins-upgrader | 100.0.0+up0.0.1 | 100.0.0+up0.0.1 | +| rancher-wins-upgrader | 100.0.0+up0.0.1 | 100.0.0+up0.0.1 |
**Charts based on upstream:** For charts that are based on upstreams, the +up annotation should inform you of what upstream version the Rancher chart is tracking. Check the upstream version compatibility with Rancher during upgrades also. - As an example, `100.x.x+up16.6.0` for Monitoring tracks upstream kube-prometheus-stack `16.6.0` with some Rancher patches added to it. -- On upgrades, ensure that you are not downgrading the version of the chart that you are using. For example, if you are using a version of Monitoring > `16.6.0` in Rancher 2.5, you should not upgrade to `100.x.x+up16.6.0`. Instead, you should upgrade to the appropriate version in the next release. +- On upgrades, ensure that you are not downgrading the version of the chart that you are using. For example, if you are using a version of Monitoring > `16.6.0` in Rancher 2.5, you should not upgrade to `100.x.x+up16.6.0`. Instead, you should upgrade to the appropriate version in the next release. ### Charts @@ -86,10 +86,10 @@ To add a private CA for Helm Chart repositories: [...] ``` - + > **Note:** Helm chart repositories with authentication > -> As of Rancher v2.6.3, a new value `disableSameOriginCheck` has been added to the Repo.Spec. This allows users to bypass the same origin checks, sending the repository Authentication information as a Basic Auth Header with all API calls. This is not recommended but can be used as a temporary solution in cases of non-standard Helm chart repositories such as those that have redirects to a different origin URL. +> As of Rancher v2.6.3, a new value `disableSameOriginCheck` has been added to the Repo.Spec. This allows users to bypass the same origin checks, sending the repository Authentication information as a Basic Auth Header with all API calls. This is not recommended but can be used as a temporary solution in cases of non-standard Helm chart repositories such as those that have redirects to a different origin URL. > > To use this feature for an existing Helm chart repository, click ⋮ > Edit YAML. On the `spec` portion of the YAML file, add `disableSameOriginCheck` and set it to `true`. > @@ -116,7 +116,7 @@ After installing a chart, you can find it in the _"Installed Apps"_ tab. In this Most Rancher tools have additional pages located in the toolbar below the _"Apps & Marketplace"_ section to help manage and use the features. These pages include links to dashboards, forms to easily add Custom Resources, and additional information. > If you are upgrading your chart using _"Customize Helm options before upgrade"_ , please be aware that using the _"--force"_ option may result in errors if your chart has immutable fields. This is because some objects in Kubernetes cannot be changed once they are created. To ensure you do not get this error you can: -> +> > * use the default upgrade option ( i.e do not use _"--force"_ option ) > * uninstall the existing chart and install the upgraded chart > * delete the resources with immutable fields from the cluster before performing the _"--force"_ upgrade @@ -130,3 +130,7 @@ If you have a legacy app installed and want to upgrade it: - The legacy [feature flag]({{}}/rancher/v2.6/en/installation/resources/feature-flags/) must be turned on (if it's not turned on automatically because of having a legacy app before upgrading) - You can upgrade the app from cluster explorer, from the left nav section **Legacy > Project > Apps** - For multi-cluster apps, you can go to **≡ > Multi-cluster Apps** and upgrade the app from there + +### Limitations + +[Dashboard apps or Rancher feature charts](../helm-charts/) **cannot** be installed using the Rancher CLI. From 95ef4af25166a8a264de9488313dc5430b0b8a50 Mon Sep 17 00:00:00 2001 From: Caleb Bron Date: Tue, 3 May 2022 06:43:21 -0700 Subject: [PATCH 16/22] Update language around scaling cases --- .../rancher/v2.0-v2.4/en/installation/requirements/_index.md | 5 +++-- content/rancher/v2.5/en/installation/requirements/_index.md | 4 ++-- content/rancher/v2.6/en/installation/requirements/_index.md | 4 ++-- 3 files changed, 7 insertions(+), 6 deletions(-) diff --git a/content/rancher/v2.0-v2.4/en/installation/requirements/_index.md b/content/rancher/v2.0-v2.4/en/installation/requirements/_index.md index ef77bd8dd89..fbf442d663e 100644 --- a/content/rancher/v2.0-v2.4/en/installation/requirements/_index.md +++ b/content/rancher/v2.0-v2.4/en/installation/requirements/_index.md @@ -78,7 +78,8 @@ Performance increased in Rancher v2.4.0. For the requirements of Rancher before | X-Large | Up to 1000 | Up to 10,000 | 16 | 64 GB | | XX-Large | Up to 2000 | Up to 20,000 | 32 | 128 GB | -[Contact Rancher](https://rancher.com/contact/) for more than 2000 clusters and/or 20,000 nodes. +Every use case and environment is different. Please [contact Rancher](https://rancher.com/contact/) to review yours. + {{% /tab %}} {{% tab "K3s" %}} @@ -93,7 +94,7 @@ These requirements apply to each host in a [K3s Kubernetes cluster where the Ran | X-Large | Up to 1000 | Up to 10,000 | 16 | 64 GB | 2 cores, 4 GB + 1000 IOPS | | XX-Large | Up to 2000 | Up to 20,000 | 32 | 128 GB | 2 cores, 4 GB + 1000 IOPS | -[Contact Rancher](https://rancher.com/contact/) for more than 2000 clusters and/or 20,000 nodes. +Every use case and environment is different. Please [contact Rancher](https://rancher.com/contact/) to review yours. {{% /tab %}} diff --git a/content/rancher/v2.5/en/installation/requirements/_index.md b/content/rancher/v2.5/en/installation/requirements/_index.md index 3c8c1dd3f20..41eda67564e 100644 --- a/content/rancher/v2.5/en/installation/requirements/_index.md +++ b/content/rancher/v2.5/en/installation/requirements/_index.md @@ -126,7 +126,7 @@ These requirements apply to RKE Kubernetes clusters, as well as to hosted Kubern | X-Large | Up to 1000 | Up to 10,000 | 16 | 64 GB | | XX-Large | Up to 2000 | Up to 20,000 | 32 | 128 GB | -[Contact Rancher](https://rancher.com/contact/) for more than 2000 clusters and/or 20,000 nodes. +Every use case and environment is different. Please [contact Rancher](https://rancher.com/contact/) to review yours. ### K3s Kubernetes @@ -140,7 +140,7 @@ These CPU and memory requirements apply to each host in a [K3s Kubernetes cluste | X-Large | Up to 1000 | Up to 10,000 | 16 | 64 GB | 2 cores, 4 GB + 1000 IOPS | | XX-Large | Up to 2000 | Up to 20,000 | 32 | 128 GB | 2 cores, 4 GB + 1000 IOPS | -[Contact Rancher](https://rancher.com/contact/) for more than 2000 clusters and/or 20,000 nodes. +Every use case and environment is different. Please [contact Rancher](https://rancher.com/contact/) to review yours. ### RancherD diff --git a/content/rancher/v2.6/en/installation/requirements/_index.md b/content/rancher/v2.6/en/installation/requirements/_index.md index c60d529b881..6cc10d26f71 100644 --- a/content/rancher/v2.6/en/installation/requirements/_index.md +++ b/content/rancher/v2.6/en/installation/requirements/_index.md @@ -110,7 +110,7 @@ These requirements apply to RKE Kubernetes clusters, as well as to hosted Kubern | X-Large | Up to 1000 | Up to 10,000 | 16 | 64 GB | | XX-Large | Up to 2000 | Up to 20,000 | 32 | 128 GB | -[Contact Rancher](https://rancher.com/contact/) for more than 2000 clusters and/or 20,000 nodes. +Every use case and environment is different. Please [contact Rancher](https://rancher.com/contact/) to review yours. ### K3s Kubernetes @@ -124,7 +124,7 @@ These CPU and memory requirements apply to each host in a [K3s Kubernetes cluste | X-Large | Up to 1000 | Up to 10,000 | 16 | 64 GB | 2 cores, 4 GB + 1000 IOPS | | XX-Large | Up to 2000 | Up to 20,000 | 32 | 128 GB | 2 cores, 4 GB + 1000 IOPS | -[Contact Rancher](https://rancher.com/contact/) for more than 2000 clusters and/or 20,000 nodes. +Every use case and environment is different. Please [contact Rancher](https://rancher.com/contact/) to review yours. ### RKE2 Kubernetes From ac1bb4ccf1290bb4d198e684dd7be15395fda937 Mon Sep 17 00:00:00 2001 From: Billy Tat Date: Wed, 11 May 2022 19:13:30 -0700 Subject: [PATCH 17/22] Add dual-stack to RKE2 config --- .../rke2-config-reference/_index.md | 24 ++++++++++++++++--- 1 file changed, 21 insertions(+), 3 deletions(-) diff --git a/content/rancher/v2.6/en/cluster-admin/editing-clusters/rke2-config-reference/_index.md b/content/rancher/v2.6/en/cluster-admin/editing-clusters/rke2-config-reference/_index.md index 7211d96d859..3e1ee54d5db 100644 --- a/content/rancher/v2.6/en/cluster-admin/editing-clusters/rke2-config-reference/_index.md +++ b/content/rancher/v2.6/en/cluster-admin/editing-clusters/rke2-config-reference/_index.md @@ -41,6 +41,14 @@ Out of the box, Rancher is compatible with the following network providers: For more details on the different networking providers and how to configure them, please view our [RKE2 documentation](https://docs.rke2.io/install/network_options/). +##### Dual-stack Networking + +[Dual-stack](https://docs.rke2.io/install/network_options/#dual-stack-configuration) networking is supported for all CNI providers. To configure RKE2 in dual-stack mode, set valid IPv4/IPv6 CIDRs for your [Cluster CIDR](#cluster-cidr) and/or [Service CIDR](#service-cidr). + +###### Additional Configuration {#dual-stack-additional-config} + +When using `cilium` or `multus,cilium` as your container network interface provider, ensure the **Enable IPv6 Support** option is also enabled. + #### Cloud Provider You can configure a [Kubernetes cloud provider]({{}}/rancher/v2.6/en/cluster-provisioning/rke-clusters/cloud-providers). If you want to use dynamically provisioned [volumes and storage]({{}}/rancher/v2.6/en/cluster-admin/volumes-and-storage/) in Kubernetes, typically you must select the specific cloud provider in order to use it. For example, if you want to use Amazon EBS, you would need to select the `aws` cloud provider. @@ -103,12 +111,24 @@ Option to choose whether to expose etcd metrics to the public or only within the #### Cluster CIDR -IPv4/IPv6 network CIDRs to use for pod IPs (default: 10.42.0.0/16). +IPv4 and/or IPv6 network CIDRs to use for pod IPs (default: 10.42.0.0/16). + +##### Dual-stack Networking + +To configure [dual-stack](https://docs.rke2.io/install/network_options/#dual-stack-configuration) mode, enter a valid IPv4/IPv6 CIDR. For example `10.42.0.0/16,2001:cafe:42:0::/56`. + +[Additional configuration](#dual-stack-additional-config) is required when using `cilium` or `multus,cilium` as your [container network](#container-network) interface provider. #### Service CIDR IPv4/IPv6 network CIDRs to use for service IPs (default: 10.43.0.0/16). +##### Dual-stack Networking + +To configure [dual-stack](https://docs.rke2.io/install/network_options/#dual-stack-configuration) mode, enter a valid IPv4/IPv6 CIDR. For example `10.42.0.0/16,2001:cafe:42:0::/56`. + +[Additional configuration](#dual-stack-additional-config) is required when using `cilium ` or `multus,cilium` as your [container network](#container-network) interface provider. + #### Cluster DNS IPv4 Cluster IP for coredns service. Should be in your service-cidr range (default: 10.43.0.10). @@ -166,5 +186,3 @@ Option to set kubelet options for different nodes. For available options, refer Instead of using the Rancher UI forms to choose Kubernetes options for the cluster, advanced users can create an RKE2 config file. Using a config file allows you to set any of the [options](https://docs.rke2.io/install/install_options/install_options) available in an RKE2 installation. To edit an RKE2 config file directly from the Rancher UI, click **Edit as YAML**. - - From 52949fea225db8859efb0c9726934aee7e6bae04 Mon Sep 17 00:00:00 2001 From: Billy Tat Date: Thu, 12 May 2022 14:01:49 -0700 Subject: [PATCH 18/22] Update feature chart versions. Add Neuvector --- content/rancher/v2.6/en/helm-charts/_index.md | 21 ++++++++++--------- 1 file changed, 11 insertions(+), 10 deletions(-) diff --git a/content/rancher/v2.6/en/helm-charts/_index.md b/content/rancher/v2.6/en/helm-charts/_index.md index 68f8c757fcd..c15af98f328 100644 --- a/content/rancher/v2.6/en/helm-charts/_index.md +++ b/content/rancher/v2.6/en/helm-charts/_index.md @@ -18,20 +18,21 @@ Starting in Rancher v2.6.0, a new versioning scheme for Rancher feature charts w | **Name** | **Supported Minimum Version** | **Supported Maximum Version** | | ---------------- | ------------ | ------------ | | external-ip-webhook | 100.0.0+up1.0.0 | 100.0.1+up1.0.1 | -| harvester-cloud-provider | 100.0.0+up0.1.8 | 100.0.0+up0.1.8 | -| harvester-csi-driver | 100.0.0+up0.1.9 | 100.0.0+up0.1.9 | +| harvester-cloud-provider | 100.0.2+up0.1.12 | 100.0.2+up0.1.12 | +| harvester-csi-driver | 100.0.2+up0.1.11 | 100.0.2+up0.1.11 | | rancher-alerting-drivers | 100.0.0 | 100.0.1 | -| rancher-backups | 2.0.0 | 2.1.0 | -| rancher-cis-benchmark | 2.0.0 | 2.0.2 | -| rancher-gatekeeper | 100.0.0+up3.5.1 | 100.0.1+up3.6.0 | -| rancher-istio | 100.0.0+up1.10.4 | 100.1.0+up1.11.4 | -| rancher-logging | 100.0.0+up3.12.0 | 100.0.1+up3.15.0 | +| rancher-backup | 2.0.0 | 2.1.2 | +| rancher-cis-benchmark | 2.0.0 | 2.0.4 | +| rancher-gatekeeper | 100.0.0+up3.5.1 | 100.1.0+up3.7.1 | +| rancher-istio | 100.0.0+up1.10.4 | 100.2.0+up1.12.6 | +| rancher-logging | 100.0.0+up3.12.0 | 100.1.2+up3.17.4 | | rancher-longhorn | 100.0.0+up1.1.2 | 100.1.1+up1.2.3 | | rancher-monitoring | 100.0.0+up16.6.0 | 100.1.0+up19.0.3 -| rancher-sriov (experimental) | 100.0.0+up0.1.0 | 100.0.1+up0.1.0 | -| rancher-vsphere-cpi | 100.0.0 | 100.1.0+up1.0.100 -| rancher-vsphere-csi | 100.0.0 | 100.1.0+up2.3.0 | +| rancher-sriov (experimental) | 100.0.0+up0.1.0 | 100.0.3+up0.1.0 | +| rancher-vsphere-cpi | 100.0.0 | 100.3.0+up1.2.1 | +| rancher-vsphere-csi | 100.0.0 | 100.3.0+up2.5.1-rancher1 | | rancher-wins-upgrader | 100.0.0+up0.0.1 | 100.0.0+up0.0.1 | +| neuvector | 100.0.0+up2.2.0 | 100.0.0+up2.2.0 |
**Charts based on upstream:** For charts that are based on upstreams, the +up annotation should inform you of what upstream version the Rancher chart is tracking. Check the upstream version compatibility with Rancher during upgrades also. From 7fb7f8c7e24093b47cc25b01c6b997648e1dcd31 Mon Sep 17 00:00:00 2001 From: Billy Tat Date: Thu, 12 May 2022 14:04:26 -0700 Subject: [PATCH 19/22] test --- .../v2.6/en/monitoring-alerting/prometheus-federator/_index.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/content/rancher/v2.6/en/monitoring-alerting/prometheus-federator/_index.md b/content/rancher/v2.6/en/monitoring-alerting/prometheus-federator/_index.md index 986023efb5d..46d47432504 100644 --- a/content/rancher/v2.6/en/monitoring-alerting/prometheus-federator/_index.md +++ b/content/rancher/v2.6/en/monitoring-alerting/prometheus-federator/_index.md @@ -3,7 +3,7 @@ title: Prometheus Federator weight: 7 --- -Prometheus Federator deploys a Helm Project Operator (based on the [rancher/helm-project-operator](https://github.com/rancher/helm-project-operator)), an operator that manages deploying Helm charts each containing a Project Monitoring Stack, where each stack contains: +Prometheus Federator, also referred to as Project Monitoring v2, deploys a Helm Project Operator (based on the [rancher/helm-project-operator](https://github.com/rancher/helm-project-operator)), an operator that manages deploying Helm charts each containing a Project Monitoring Stack, where each stack contains: - [Prometheus](https://prometheus.io/) (managed externally by [Prometheus Operator](https://github.com/prometheus-operator/prometheus-operator)) - [Alertmanager](https://prometheus.io/docs/alerting/latest/alertmanager/) (managed externally by [Prometheus Operator](https://github.com/prometheus-operator/prometheus-operator)) From 49b7b59b43d825b75e6c0332ba245ca6b5ff0cd6 Mon Sep 17 00:00:00 2001 From: Billy Tat Date: Thu, 12 May 2022 14:24:22 -0700 Subject: [PATCH 20/22] Update min versions per feedback --- content/rancher/v2.6/en/helm-charts/_index.md | 14 +++++++------- 1 file changed, 7 insertions(+), 7 deletions(-) diff --git a/content/rancher/v2.6/en/helm-charts/_index.md b/content/rancher/v2.6/en/helm-charts/_index.md index c15af98f328..aab00dd91dd 100644 --- a/content/rancher/v2.6/en/helm-charts/_index.md +++ b/content/rancher/v2.6/en/helm-charts/_index.md @@ -20,18 +20,18 @@ Starting in Rancher v2.6.0, a new versioning scheme for Rancher feature charts w | external-ip-webhook | 100.0.0+up1.0.0 | 100.0.1+up1.0.1 | | harvester-cloud-provider | 100.0.2+up0.1.12 | 100.0.2+up0.1.12 | | harvester-csi-driver | 100.0.2+up0.1.11 | 100.0.2+up0.1.11 | -| rancher-alerting-drivers | 100.0.0 | 100.0.1 | -| rancher-backup | 2.0.0 | 2.1.2 | -| rancher-cis-benchmark | 2.0.0 | 2.0.4 | -| rancher-gatekeeper | 100.0.0+up3.5.1 | 100.1.0+up3.7.1 | +| rancher-alerting-drivers | 100.0.0 | 100.0.2 | +| rancher-backup | 2.0.1 | 2.1.2 | +| rancher-cis-benchmark | 2.0.1 | 2.0.4 | +| rancher-gatekeeper | 100.0.0+up3.6.0 | 100.1.0+up3.7.1 | | rancher-istio | 100.0.0+up1.10.4 | 100.2.0+up1.12.6 | | rancher-logging | 100.0.0+up3.12.0 | 100.1.2+up3.17.4 | | rancher-longhorn | 100.0.0+up1.1.2 | 100.1.1+up1.2.3 | | rancher-monitoring | 100.0.0+up16.6.0 | 100.1.0+up19.0.3 | rancher-sriov (experimental) | 100.0.0+up0.1.0 | 100.0.3+up0.1.0 | -| rancher-vsphere-cpi | 100.0.0 | 100.3.0+up1.2.1 | -| rancher-vsphere-csi | 100.0.0 | 100.3.0+up2.5.1-rancher1 | -| rancher-wins-upgrader | 100.0.0+up0.0.1 | 100.0.0+up0.0.1 | +| rancher-vsphere-cpi | 100.3.0+up1.2.1 | 100.3.0+up1.2.1 | +| rancher-vsphere-csi | 100.3.0+up2.5.1-rancher1 | 100.3.0+up2.5.1-rancher1 | +| rancher-wins-upgrader | 0.0.100 | 100.0.0+up0.0.1 | | neuvector | 100.0.0+up2.2.0 | 100.0.0+up2.2.0 |
From 33867c087397e6ba0efe539ac723e15e9fab791c Mon Sep 17 00:00:00 2001 From: Billy Tat Date: Thu, 12 May 2022 15:00:40 -0700 Subject: [PATCH 21/22] Add warning about field type change --- .../configuration/route/_index.md | 20 +++++++++++++++ .../prometheus-federator/_index.md | 25 +++++++++++-------- .../guides/prom-fed-workloads/_index.md | 4 +-- 3 files changed, 37 insertions(+), 12 deletions(-) diff --git a/content/rancher/v2.6/en/monitoring-alerting/configuration/route/_index.md b/content/rancher/v2.6/en/monitoring-alerting/configuration/route/_index.md index 4fc0019c79f..4366f20a9a5 100644 --- a/content/rancher/v2.6/en/monitoring-alerting/configuration/route/_index.md +++ b/content/rancher/v2.6/en/monitoring-alerting/configuration/route/_index.md @@ -42,6 +42,21 @@ The route needs to refer to a [receiver](#receiver-configuration) that has alrea ### Grouping +{{% tabs %}} +{{% tab "Rancher v2.6.5+" %}} + +> **Note** As of Rancher v2.6.5 `Group By` now accepts a list of strings instead of key-value pairs. See the [upstream documentation](https://github.com/prometheus-operator/prometheus-operator/blob/main/Documentation/api.md#route) for details. + +| Field | Default | Description | +|-------|--------------|---------| +| Group By | N/a | List of labels to group by. Labels must not be repeated (unique list). Special label "..." (aggregate by all possible labels), if provided, must be the only element in the list. | +| Group Wait | 30s | How long to wait to buffer alerts of the same group before sending initially. | +| Group Interval | 5m | How long to wait before sending an alert that has been added to a group of alerts for which an initial notification has already been sent. | +| Repeat Interval | 4h | How long to wait before re-sending a given alert that has already been sent. | + +{{% /tab %}} +{{% tab "Rancher before v2.6.5" %}} + | Field | Default | Description | |-------|--------------|---------| | Group By | N/a | The labels by which incoming alerts are grouped together. For example, `[ group_by: '[' , ... ']' ]` Multiple alerts coming in for labels such as `cluster=A` and `alertname=LatencyHigh` can be batched into a single group. To aggregate by all possible labels, use the special value `'...'` as the sole label name, for example: `group_by: ['...']` Grouping by `...` effectively disables aggregation entirely, passing through all alerts as-is. This is unlikely to be what you want, unless you have a very low alert volume or your upstream notification system performs its own grouping. | @@ -49,6 +64,11 @@ The route needs to refer to a [receiver](#receiver-configuration) that has alrea | Group Interval | 5m | How long to wait before sending an alert that has been added to a group of alerts for which an initial notification has already been sent. | | Repeat Interval | 4h | How long to wait before re-sending a given alert that has already been sent. | +{{% /tab %}} +{{% /tabs %}} + + + ### Matching The **Match** field refers to a set of equality matchers used to identify which alerts to send to a given Route based on labels defined on that alert. When you add key-value pairs to the Rancher UI, they correspond to the YAML in this format: diff --git a/content/rancher/v2.6/en/monitoring-alerting/prometheus-federator/_index.md b/content/rancher/v2.6/en/monitoring-alerting/prometheus-federator/_index.md index 46d47432504..1d61b9b90ca 100644 --- a/content/rancher/v2.6/en/monitoring-alerting/prometheus-federator/_index.md +++ b/content/rancher/v2.6/en/monitoring-alerting/prometheus-federator/_index.md @@ -21,13 +21,13 @@ Prometheus Federator, also referred to as Project Monitoring v2, deploys a Helm ### What is a Project? -In Prometheus Federator, a Project is a group of namespaces that can be identified by a `metav1.LabelSelector`. By default, the label used to identify projects is `field.cattle.io/projectId`, the label used to identify namespaces that are contained within a given [Rancher](https://rancher.com/) Project. +In Prometheus Federator, a Project is a group of namespaces that can be identified by a `metav1.LabelSelector`. By default, the label used to identify projects is `field.cattle.io/projectId`, the label used to identify namespaces that are contained within a given Rancher Project. ### Configuring the Helm release created by a ProjectHelmChart -The `spec.values` of this ProjectHelmChart resources will correspond to the `values.yaml` override to be supplied to the underlying Helm chart deployed by the operator on the user's behalf; to see the underlying chart's `values.yaml` spec, either: +The `spec.values` of this ProjectHelmChart's resources will correspond to the `values.yaml` override to be supplied to the underlying Helm chart deployed by the operator on the user's behalf; to see the underlying chart's `values.yaml` spec, either: -- View to the chart's definition located at [`rancher/prometheus-federator` under `charts/rancher-project-monitoring`](https://github.com/rancher/prometheus-federator/blob/main/charts/rancher-project-monitoring) (where the chart version will be tied to the version of this operator) +- View the chart's definition located at [`rancher/prometheus-federator` under `charts/rancher-project-monitoring`](https://github.com/rancher/prometheus-federator/blob/main/charts/rancher-project-monitoring) (where the chart version will be tied to the version of this operator). - Look for the ConfigMap named `monitoring.cattle.io.v1alpha1` that is automatically created in each Project Registration Namespace, which will contain both the `values.yaml` and `questions.yaml` that was used to configure the chart (which was embedded directly into the `prometheus-federator` binary). ### Namespaces @@ -36,20 +36,25 @@ As a Project Operator based on [rancher/helm-project-operator](https://github.co 1. **Operator / System Namespace**: this is the namespace that the operator is deployed into (e.g., `cattle-monitoring-system`). This namespace will contain all HelmCharts and HelmReleases for all ProjectHelmCharts watched by this operator. **Only Cluster Admins should have access to this namespace.** 2. **Project Registration Namespace (`cattle-project-`)**: this is the set of namespaces that the operator watches for ProjectHelmCharts within. The RoleBindings and ClusterRoleBindings that apply to this namespace will also be the source of truth for the auto-assigned RBAC created in the Project Release Namespace. For details, refer to the [RBAC page](./rbac/). **Project Owners (admin), Project Members (edit), and Read-Only Members (view) should have access to this namespace**. -> Note: Project Registration Namespaces will be auto-generated by the operator and imported into the Project it is tied to if `.Values.global.cattle.projectLabel` is provided (which is set to `field.cattle.io/projectId` by default); this indicates that a Project Registration Namespace should be created by the operator if at least one namespace is observed with that label. The operator will not let these namespaces be deleted unless either all namespaces with that label are gone (e.g. this is the last namespace in that project, in which case the namespace will be marked with the label `"helm.cattle.io/helm-project-operator-orphaned": "true"`, which signals that it can be deleted) or it is no longer watching that project (because the project ID was provided under `.Values.helmProjectOperator.otherSystemProjectLabelValues`, which serves as a denylist for Projects). These namespaces will also never be auto-deleted to avoid destroying user data; it is recommended that users clean up these namespaces manually if desired on creating or deleting a project -> Note: if `.Values.global.cattle.projectLabel` is not provided, the Operator / System Namespace will also be the Project Registration Namespace + + > **Note:** Project Registration Namespaces will be auto-generated by the operator and imported into the Project it is tied to if `.Values.global.cattle.projectLabel` is provided (which is set to `field.cattle.io/projectId` by default); this indicates that a Project Registration Namespace should be created by the operator if at least one namespace is observed with that label. The operator will not let these namespaces be deleted unless either all namespaces with that label are gone (e.g., this is the last namespace in that project, in which case the namespace will be marked with the label `"helm.cattle.io/helm-project-operator-orphaned": "true"`, which signals that it can be deleted) or it is no longer watching that project (because the project ID was provided under `.Values.helmProjectOperator.otherSystemProjectLabelValues`, which serves as a denylist for Projects). These namespaces will also never be auto-deleted to avoid destroying user data; it is recommended that users clean up these namespaces manually if desired on creating or deleting a project + + > **Note:** if `.Values.global.cattle.projectLabel` is not provided, the Operator / System Namespace will also be the Project Registration Namespace 3. **Project Release Namespace (`cattle-project--monitoring`)**: this is the set of namespaces that the operator deploys Project Monitoring Stacks within on behalf of a ProjectHelmChart; the operator will also automatically assign RBAC to Roles created in this namespace by the Project Monitoring Stack based on bindings found in the Project Registration Namespace. **Only Cluster Admins should have access to this namespace; Project Owners (admin), Project Members (edit), and Read-Only Members (view) will be assigned limited access to this namespace by the deployed Helm Chart and Prometheus Federator.** - > Note: Project Release Namespaces are automatically deployed and imported into the project whose ID is specified under `.Values.helmProjectOperator.projectReleaseNamespaces.labelValue` (which defaults to the value of `.Values.global.cattle.systemProjectId` if not specified) whenever a ProjectHelmChart is specified in a Project Registration Namespace -> Note: Project Release Namespaces follow the same orphaning conventions as Project Registration Namespaces (see note above) -> Note: if `.Values.projectReleaseNamespaces.enabled` is false, the Project Release Namespace will be the same as the Project Registration Namespace + + > **Note:** Project Release Namespaces are automatically deployed and imported into the project whose ID is specified under `.Values.helmProjectOperator.projectReleaseNamespaces.labelValue` (which defaults to the value of `.Values.global.cattle.systemProjectId` if not specified) whenever a ProjectHelmChart is specified in a Project Registration Namespace + + > **Note:** Project Release Namespaces follow the same orphaning conventions as Project Registration Namespaces (see note above) + + > **Note:** if `.Values.projectReleaseNamespaces.enabled` is false, the Project Release Namespace will be the same as the Project Registration Namespace ### Helm Resources (HelmChart, HelmRelease) On deploying a ProjectHelmChart, the Prometheus Federator will automatically create and manage two child custom resources that manage the underlying Helm resources in turn: -- A HelmChart CR (managed via an embedded [k3s-io/helm-contoller](https://github.com/k3s-io/helm-controller) in the operator): this custom resource automatically creates a Job in the same namespace that triggers a `helm install`, `helm upgrade`, or `helm uninstall` depending on the change applied to the HelmChart CR; this CR is automatically updated on changes to the ProjectHelmChart (e.g. modifying the values.yaml) or changes to the underlying Project definition (e.g. adding or removing namespaces from a project). +- A HelmChart CR (managed via an embedded [k3s-io/helm-contoller](https://github.com/k3s-io/helm-controller) in the operator): this custom resource automatically creates a Job in the same namespace that triggers a `helm install`, `helm upgrade`, or `helm uninstall` depending on the change applied to the HelmChart CR; this CR is automatically updated on changes to the ProjectHelmChart (e.g., modifying the values.yaml) or changes to the underlying Project definition (e.g., adding or removing namespaces from a project). -> **Important** If a ProjectHelmChart is not deploying or updating the underlying Project Monitoring Stack for some reason, the Job created by this resource in the Operator / System namespace should be the first place you check to see if there's something wrong with the Helm operation; however, this is generally only accessible by a Cluster Admin.** +> **Important** If a ProjectHelmChart is not deploying or updating the underlying Project Monitoring Stack for some reason, the Job created by this resource in the Operator / System namespace should be the first place you check to see if there's something wrong with the Helm operation; however, this is generally only accessible by a **Cluster Admin.** - A HelmRelease CR (managed via an embedded [rancher/helm-locker](https://github.com/rancher/helm-locker) in the operator): this custom resource automatically locks a deployed Helm release in place and automatically overwrites updates to underlying resources unless the change happens via a Helm operation (`helm install`, `helm upgrade`, or `helm uninstall` performed by the HelmChart CR). diff --git a/content/rancher/v2.6/en/monitoring-alerting/prometheus-federator/guides/prom-fed-workloads/_index.md b/content/rancher/v2.6/en/monitoring-alerting/prometheus-federator/guides/prom-fed-workloads/_index.md index eba115a9873..18be42c63be 100644 --- a/content/rancher/v2.6/en/monitoring-alerting/prometheus-federator/guides/prom-fed-workloads/_index.md +++ b/content/rancher/v2.6/en/monitoring-alerting/prometheus-federator/guides/prom-fed-workloads/_index.md @@ -5,7 +5,7 @@ weight: 4 - [Display CPU and Memory Metrics for a Workload](#display-cpu-and-memory-metrics-for-a-workload) - [Setting up Metrics Beyond CPU and Memory](#setting-up-metrics-beyond-cpu-and-memory) -- [Custom Metrics](#custom-metrics) + ### Display CPU and Memory Metrics for a Workload @@ -15,4 +15,4 @@ Displaying CPU and memory metrics with Prometheus Federator is done the same way Setting up metrics beyond CPU and memory with Prometheus Federator is done the same way as with rancher-monitoring. For instructions, refer [here](../../../guides/monitoring-workloads/_index.md#setting-up-metrics-beyond-cpu-and-memory). -### Custom Metrics \ No newline at end of file + \ No newline at end of file From 6b00613262b41c7170ca6aac91f4ace3fdfd6ae4 Mon Sep 17 00:00:00 2001 From: Billy Tat Date: Thu, 12 May 2022 16:19:39 -0700 Subject: [PATCH 22/22] Apply suggestions from code review Co-authored-by: Jen Travinski --- .../prometheus-federator/_index.md | 36 +++++++++---------- .../guides/enable-prom-fed/_index.md | 16 ++++----- .../prometheus-federator/rbac/_index.md | 8 ++--- 3 files changed, 30 insertions(+), 30 deletions(-) diff --git a/content/rancher/v2.6/en/monitoring-alerting/prometheus-federator/_index.md b/content/rancher/v2.6/en/monitoring-alerting/prometheus-federator/_index.md index 1d61b9b90ca..cc88321bee4 100644 --- a/content/rancher/v2.6/en/monitoring-alerting/prometheus-federator/_index.md +++ b/content/rancher/v2.6/en/monitoring-alerting/prometheus-federator/_index.md @@ -34,31 +34,31 @@ The `spec.values` of this ProjectHelmChart's resources will correspond to the `v As a Project Operator based on [rancher/helm-project-operator](https://github.com/rancher/helm-project-operator), Prometheus Federator has three different classifications of namespaces that the operator looks out for: -1. **Operator / System Namespace**: this is the namespace that the operator is deployed into (e.g., `cattle-monitoring-system`). This namespace will contain all HelmCharts and HelmReleases for all ProjectHelmCharts watched by this operator. **Only Cluster Admins should have access to this namespace.** -2. **Project Registration Namespace (`cattle-project-`)**: this is the set of namespaces that the operator watches for ProjectHelmCharts within. The RoleBindings and ClusterRoleBindings that apply to this namespace will also be the source of truth for the auto-assigned RBAC created in the Project Release Namespace. For details, refer to the [RBAC page](./rbac/). **Project Owners (admin), Project Members (edit), and Read-Only Members (view) should have access to this namespace**. +1. **Operator / System Namespace**: The namespace that the operator is deployed into (e.g., `cattle-monitoring-system`). This namespace will contain all HelmCharts and HelmReleases for all ProjectHelmCharts watched by this operator. **Only Cluster Admins should have access to this namespace.** +2. **Project Registration Namespace (`cattle-project-`)**: The set of namespaces that the operator watches for ProjectHelmCharts within. The RoleBindings and ClusterRoleBindings that apply to this namespace will also be the source of truth for the auto-assigned RBAC created in the Project Release Namespace. For details, refer to the [RBAC page](./rbac/). **Project Owners (admin), Project Members (edit), and Read-Only Members (view) should have access to this namespace.** - > **Note:** Project Registration Namespaces will be auto-generated by the operator and imported into the Project it is tied to if `.Values.global.cattle.projectLabel` is provided (which is set to `field.cattle.io/projectId` by default); this indicates that a Project Registration Namespace should be created by the operator if at least one namespace is observed with that label. The operator will not let these namespaces be deleted unless either all namespaces with that label are gone (e.g., this is the last namespace in that project, in which case the namespace will be marked with the label `"helm.cattle.io/helm-project-operator-orphaned": "true"`, which signals that it can be deleted) or it is no longer watching that project (because the project ID was provided under `.Values.helmProjectOperator.otherSystemProjectLabelValues`, which serves as a denylist for Projects). These namespaces will also never be auto-deleted to avoid destroying user data; it is recommended that users clean up these namespaces manually if desired on creating or deleting a project + > **Note:** Project Registration Namespaces will be auto-generated by the operator and imported into the Project it is tied to if `.Values.global.cattle.projectLabel` is provided, which is set to `field.cattle.io/projectId` by default. This indicates that a Project Registration Namespace should be created by the operator if at least one namespace is observed with that label. The operator will not let these namespaces be deleted unless either all namespaces with that label are gone (e.g., this is the last namespace in that project, in which case the namespace will be marked with the label `"helm.cattle.io/helm-project-operator-orphaned": "true"`, which signals that it can be deleted), or it is no longer watching that project because the project ID was provided under `.Values.helmProjectOperator.otherSystemProjectLabelValues`, which serves as a denylist for Projects. These namespaces will also never be auto-deleted to avoid destroying user data; it is recommended that users clean up these namespaces manually if desired on creating or deleting a project. - > **Note:** if `.Values.global.cattle.projectLabel` is not provided, the Operator / System Namespace will also be the Project Registration Namespace -3. **Project Release Namespace (`cattle-project--monitoring`)**: this is the set of namespaces that the operator deploys Project Monitoring Stacks within on behalf of a ProjectHelmChart; the operator will also automatically assign RBAC to Roles created in this namespace by the Project Monitoring Stack based on bindings found in the Project Registration Namespace. **Only Cluster Admins should have access to this namespace; Project Owners (admin), Project Members (edit), and Read-Only Members (view) will be assigned limited access to this namespace by the deployed Helm Chart and Prometheus Federator.** + > **Note:** If `.Values.global.cattle.projectLabel` is not provided, the Operator / System Namespace will also be the Project Registration Namespace. +3. **Project Release Namespace (`cattle-project--monitoring`):** The set of namespaces that the operator deploys Project Monitoring Stacks within on behalf of a ProjectHelmChart; the operator will also automatically assign RBAC to Roles created in this namespace by the Project Monitoring Stack based on bindings found in the Project Registration Namespace. **Only Cluster Admins should have access to this namespace; Project Owners (admin), Project Members (edit), and Read-Only Members (view) will be assigned limited access to this namespace by the deployed Helm Chart and Prometheus Federator.** - > **Note:** Project Release Namespaces are automatically deployed and imported into the project whose ID is specified under `.Values.helmProjectOperator.projectReleaseNamespaces.labelValue` (which defaults to the value of `.Values.global.cattle.systemProjectId` if not specified) whenever a ProjectHelmChart is specified in a Project Registration Namespace + > **Note:** Project Release Namespaces are automatically deployed and imported into the project whose ID is specified under `.Values.helmProjectOperator.projectReleaseNamespaces.labelValue`, which defaults to the value of `.Values.global.cattle.systemProjectId` if not specified, whenever a ProjectHelmChart is specified in a Project Registration Namespace. - > **Note:** Project Release Namespaces follow the same orphaning conventions as Project Registration Namespaces (see note above) + > **Note:** Project Release Namespaces follow the same orphaning conventions as Project Registration Namespaces (see note above). - > **Note:** if `.Values.projectReleaseNamespaces.enabled` is false, the Project Release Namespace will be the same as the Project Registration Namespace + > **Note:** If `.Values.projectReleaseNamespaces.enabled` is false, the Project Release Namespace will be the same as the Project Registration Namespace. ### Helm Resources (HelmChart, HelmRelease) On deploying a ProjectHelmChart, the Prometheus Federator will automatically create and manage two child custom resources that manage the underlying Helm resources in turn: -- A HelmChart CR (managed via an embedded [k3s-io/helm-contoller](https://github.com/k3s-io/helm-controller) in the operator): this custom resource automatically creates a Job in the same namespace that triggers a `helm install`, `helm upgrade`, or `helm uninstall` depending on the change applied to the HelmChart CR; this CR is automatically updated on changes to the ProjectHelmChart (e.g., modifying the values.yaml) or changes to the underlying Project definition (e.g., adding or removing namespaces from a project). +- A HelmChart CR (managed via an embedded [k3s-io/helm-contoller](https://github.com/k3s-io/helm-controller) in the operator): This custom resource automatically creates a Job in the same namespace that triggers a `helm install`, `helm upgrade`, or `helm uninstall` depending on the change applied to the HelmChart CR. This CR is automatically updated on changes to the ProjectHelmChart (e.g., modifying the values.yaml) or changes to the underlying Project definition (e.g., adding or removing namespaces from a project). -> **Important** If a ProjectHelmChart is not deploying or updating the underlying Project Monitoring Stack for some reason, the Job created by this resource in the Operator / System namespace should be the first place you check to see if there's something wrong with the Helm operation; however, this is generally only accessible by a **Cluster Admin.** +> **Important:** If a ProjectHelmChart is not deploying or updating the underlying Project Monitoring Stack for some reason, the Job created by this resource in the Operator / System namespace should be the first place you check to see if there's something wrong with the Helm operation. However, this is generally only accessible by a **Cluster Admin.** -- A HelmRelease CR (managed via an embedded [rancher/helm-locker](https://github.com/rancher/helm-locker) in the operator): this custom resource automatically locks a deployed Helm release in place and automatically overwrites updates to underlying resources unless the change happens via a Helm operation (`helm install`, `helm upgrade`, or `helm uninstall` performed by the HelmChart CR). +- A HelmRelease CR (managed via an embedded [rancher/helm-locker](https://github.com/rancher/helm-locker) in the operator): This custom resource automatically locks a deployed Helm release in place and automatically overwrites updates to underlying resources unless the change happens via a Helm operation (`helm install`, `helm upgrade`, or `helm uninstall` performed by the HelmChart CR). -> **Note** HelmRelease CRs emit Kubernetes Events that detect when an underlying Helm release is being modified and locks it back to place; to view these events, you can use `kubectl describe helmrelease -n `; you can also view the logs on this operator to see when changes are detected and which resources were attempted to be modified +> **Note:** HelmRelease CRs emit Kubernetes Events that detect when an underlying Helm release is being modified and locks it back to place. To view these events, you can use `kubectl describe helmrelease -n `; you can also view the logs on this operator to see when changes are detected and which resources modifications were attempted on. Both of these resources are created for all Helm charts in the Operator / System namespaces to avoid escalation of privileges to underprivileged users. @@ -69,13 +69,13 @@ For more information on advanced configurations, refer to [this page](https://gi ### Prometheus Federator on the Local Cluster diff --git a/content/rancher/v2.6/en/monitoring-alerting/prometheus-federator/guides/enable-prom-fed/_index.md b/content/rancher/v2.6/en/monitoring-alerting/prometheus-federator/guides/enable-prom-fed/_index.md index 867e126ea0e..ae4ff801de2 100644 --- a/content/rancher/v2.6/en/monitoring-alerting/prometheus-federator/guides/enable-prom-fed/_index.md +++ b/content/rancher/v2.6/en/monitoring-alerting/prometheus-federator/guides/enable-prom-fed/_index.md @@ -10,17 +10,17 @@ weight: 1 By default, Prometheus Federator is configured and intended to be deployed alongside [rancher-monitoring](https://rancher.com/docs/rancher/v2.6/en/monitoring-alerting/), which deploys Prometheus Operator alongside a Cluster Prometheus that each Project Monitoring Stack is configured to federate namespace-scoped metrics from by default. -For instructions to install rancher-monitoring, refer [this page](../../../guides/enable-monitoring/). +For instructions on installing rancher-monitoring, refer to [this page](../../../guides/enable-monitoring/). The default configuration should already be compatible with your rancher-monitoring stack. However, to optimize the security and usability of Prometheus Federator in your cluster, we recommend making these additional configurations to rancher-monitoring: -- [Ensure the cattle-monitoring-system namespace is placed into the System Project](#ensure-the-cattle-monitoring-system-namespace-is-placed-into-the-system-project-or-a-similarly-locked-down-project-that-has-access-to-other-projects-in-the-cluster) -- [Configure rancher-monitoring to only watch for resources created by the Helm chart itself](#configure-rancher-monitoring-to-only-watch-for-resources-created-by-the-helm-chart-itself) -- [Increase the CPU / memory limits of the Cluster Prometheus](#increase-the-cpu--memory-limits-of-the-cluster-prometheus) +- [Ensure the cattle-monitoring-system namespace is placed into the System Project](#ensure-the-cattle-monitoring-system-namespace-is-placed-into-the-system-project-or-a-similarly-locked-down-project-that-has-access-to-other-projects-in-the-cluster). +- [Configure rancher-monitoring to only watch for resources created by the Helm chart itself](#configure-rancher-monitoring-to-only-watch-for-resources-created-by-the-helm-chart-itself). +- [Increase the CPU / memory limits of the Cluster Prometheus](#increase-the-cpu--memory-limits-of-the-cluster-prometheus). ## Ensure the cattle-monitoring-system namespace is placed into the System Project (or a similarly locked down Project that has access to other Projects in the cluster) -Prometheus Operator's security model expects that the namespace it is deployed into (e.g., `cattle-monitoring-system`) has limited access for anyone except Cluster Admins to avoid privilege escalation via execing into Pods (such as the Jobs executing Helm operations). In addition, deploying Prometheus Federator and all Project Prometheus stacks into the System Project ensures that the each Project Prometheus is able to reach out to scrape workloads across all Projects (even if Network Policies are defined via Project Network Isolation) but has limited access for Project Owners, Project Members, and other users to be able to access data they shouldn't have access to (i.e., being allowed to exec into pods, set up the ability to scrape namespaces outside of a given Project, etc.). +Prometheus Operator's security model expects that the namespace it is deployed into (e.g., `cattle-monitoring-system`) has limited access for anyone except Cluster Admins to avoid privilege escalation via execing into Pods (such as the Jobs executing Helm operations). In addition, deploying Prometheus Federator and all Project Prometheus stacks into the System Project ensures that each Project Prometheus is able to reach out to scrape workloads across all Projects, even if Network Policies are defined via Project Network Isolation. It also provides limited access for Project Owners, Project Members, and other users so that they're unable to access data that they shouldn't have access to (i.e., being allowed to exec into pods, set up the ability to scrape namespaces outside of a given Project, etc.). ## Configure rancher-monitoring to only watch for resources created by the Helm chart itself @@ -38,13 +38,13 @@ The following selector fields are recommended to have this value: - `.Values.prometheus.prometheusSpec.ruleSelector` - `.Values.prometheus.prometheusSpec.probeSelector` -Once this setting is turned on, you can always create ServiceMonitors or PodMonitors that are picked up by the Cluster Prometheus by adding the label `release: "rancher-monitoring"` to them (in which case they will be ignored by Project Monitoring Stacks automatically by default, even if the namespace in which those ServiceMonitors or PodMonitors reside in are not system namespaces). +Once this setting is turned on, you can always create ServiceMonitors or PodMonitors that are picked up by the Cluster Prometheus by adding the label `release: "rancher-monitoring"` to them, in which case they will be ignored by Project Monitoring Stacks automatically by default, even if the namespace in which those ServiceMonitors or PodMonitors reside in are not system namespaces. -> Note: If you don't want to allow users to be able to create ServiceMonitors and PodMonitors that aggregate into the Cluster Prometheus in Project namespaces, you can additionally set the namespaceSelectors on the chart to only target system namespaces (which must contain `cattle-monitoring-system` and `cattle-dashboards`, where resources are deployed into by default by rancher-monitoring; you will also need to monitor the `default` namespace to get apiserver metrics or create a custom ServiceMonitor to scrape apiserver metrics from the Service residing in the default namespace) to limit your Cluster Prometheus from picking up other Prometheus Operator CRs; in that case, it would be recommended to turn `.Values.prometheus.prometheusSpec.ignoreNamespaceSelectors=true` to allow you to define ServiceMonitors that can monitor non-system namespaces from within a system namespace. +> Note: If you don't want to allow users to be able to create ServiceMonitors and PodMonitors that aggregate into the Cluster Prometheus in Project namespaces, you can additionally set the namespaceSelectors on the chart to only target system namespaces (which must contain `cattle-monitoring-system` and `cattle-dashboards`, where resources are deployed into by default by rancher-monitoring; you will also need to monitor the `default` namespace to get apiserver metrics or create a custom ServiceMonitor to scrape apiserver metrics from the Service residing in the default namespace) to limit your Cluster Prometheus from picking up other Prometheus Operator CRs. In that case, it would be recommended to turn `.Values.prometheus.prometheusSpec.ignoreNamespaceSelectors=true` to allow you to define ServiceMonitors that can monitor non-system namespaces from within a system namespace. ## Increase the CPU / memory limits of the Cluster Prometheus -Depending on a cluster's setup, it's generally recommended to give a large amount of dedicated memory to the Cluster Prometheus to avoid restarts due to out-of-memory errors (OOMKilled), usually caused by churn created in the cluster that causes a large number of high cardinality metrics to be generated and ingested by Prometheus within one block of time; this is one of the reasons why the default Rancher Monitoring stack expects around 4GB of RAM to be able to operate in a normal-sized cluster. However, when introducing Project Monitoring Stacks that are all sending `/federate` requests to the same Cluster Prometheus and are reliant on the Cluster Prometheus being "up" to federate that system data on their namespaces, it's even more important that the Cluster Prometheus has an ample amount of CPU / memory assigned to it to prevent an outage that can cause data gaps across all Project Prometheis in the cluster. +Depending on a cluster's setup, it's generally recommended to give a large amount of dedicated memory to the Cluster Prometheus to avoid restarts due to out-of-memory errors (OOMKilled) usually caused by churn created in the cluster that causes a large number of high cardinality metrics to be generated and ingested by Prometheus within one block of time. This is one of the reasons why the default Rancher Monitoring stack expects around 4GB of RAM to be able to operate in a normal-sized cluster. However, when introducing Project Monitoring Stacks that are all sending `/federate` requests to the same Cluster Prometheus and are reliant on the Cluster Prometheus being "up" to federate that system data on their namespaces, it's even more important that the Cluster Prometheus has an ample amount of CPU / memory assigned to it to prevent an outage that can cause data gaps across all Project Prometheis in the cluster. > Note: There are no specific recommendations on how much memory the Cluster Prometheus should be configured with since it depends entirely on the user's setup (namely the likelihood of encountering a high churn rate and the scale of metrics that could be generated at that time); it generally varies per setup. diff --git a/content/rancher/v2.6/en/monitoring-alerting/prometheus-federator/rbac/_index.md b/content/rancher/v2.6/en/monitoring-alerting/prometheus-federator/rbac/_index.md index fe2b2fd4fc8..d656246d982 100644 --- a/content/rancher/v2.6/en/monitoring-alerting/prometheus-federator/rbac/_index.md +++ b/content/rancher/v2.6/en/monitoring-alerting/prometheus-federator/rbac/_index.md @@ -1,10 +1,10 @@ --- -title: Role-based Access Control +title: Role-Based Access Control shortTitle: RBAC weight: 2 --- -This section describes the expectations for Role-based Access Control (RBAC) for Prometheus Federator. +This section describes the expectations for Role-Based Access Control (RBAC) for Prometheus Federator. As described in the section on [namespaces](../_index.md#namespaces), Prometheus Federator expects that Project Owners, Project Members, and other users in the cluster with Project-level permissions (e.g. permissions in a certain set of namespaces identified by a single label selector) have minimal permissions in any namespaces except the Project Registration Namespace (which is imported into the project by default) and those that already comprise their projects. Therefore, in order to allow Project Owners to assign specific chart permissions to other users in their Project namespaces, the Helm Project Operator will automatically watch the following bindings: @@ -17,7 +17,7 @@ On observing a change to one of those types of bindings, the Helm Project Operat - `helmProjectOperator.releaseRoleBindings.clusterRoleRefs.edit` - `helmProjectOperator.releaseRoleBindings.clusterRoleRefs.view` -By default, these roleRefs correspond will correspond to `admin`, `edit`, and `view` respectively, which are the [default Kubernetes user-facing roles](https://kubernetes.io/docs/reference/access-authn-authz/rbac/#user-facing-roles). +By default, these roleRefs will correspond to `admin`, `edit`, and `view` respectively, which are the [default Kubernetes user-facing roles](https://kubernetes.io/docs/reference/access-authn-authz/rbac/#user-facing-roles). > **Note** For Rancher RBAC users, these [default Kubernetes user-facing roles](https://kubernetes.io/docs/reference/access-authn-authz/rbac/#user-facing-roles) directly correlate to the `Project Owner`, `Project Member`, and `Read-Only` default Project Role Templates. @@ -26,4 +26,4 @@ If the `roleRef` matches, the Helm Project Operator will filter the `subjects` o - `helm.cattle.io/project-helm-chart-role: {{ .Release.Name }}` - `helm.cattle.io/project-helm-chart-role-aggregate-from: ` -By default, the `rancher-project-monitoring` (the underlying chart deployed by Prometheus Federator) creates three default Roles per Project Release Namespace that provide `admin`, `edit`, and `view` users to permissions to view the Prometheus, Alertmanager, and Grafana UIs of the Project Monitoring Stack to provide least privilege; however, if a Cluster Admin would like to assign additional permissions to certain users, they can either directly assign RoleBindings in the Project Release Namespace to certain users or created Roles with the above two labels on them to allow Project Owners to control assigning those RBAC roles to users in their Project Registration namespaces. \ No newline at end of file +By default, `rancher-project-monitoring`, the underlying chart deployed by Prometheus Federator, creates three default Roles per Project Release Namespace that provide `admin`, `edit`, and `view` users to permissions to view the Prometheus, Alertmanager, and Grafana UIs of the Project Monitoring Stack to provide least privilege. However, if a Cluster Admin would like to assign additional permissions to certain users, they can either directly assign RoleBindings in the Project Release Namespace to certain users or create Roles with the above two labels on them to allow Project Owners to control assigning those RBAC roles to users in their Project Registration namespaces. \ No newline at end of file