diff --git a/patterns/gitops/getting-started-argocd/README.md b/patterns/gitops/getting-started-argocd/README.md index 3cdf8e6d16..292978fa6d 100644 --- a/patterns/gitops/getting-started-argocd/README.md +++ b/patterns/gitops/getting-started-argocd/README.md @@ -4,10 +4,10 @@ This tutorial guides you through deploying an Amazon EKS cluster with addons con - The [GitOps Bridge Pattern](https://github.com/gitops-bridge-dev) enables Kubernetes administrators to utilize Infrastructure as Code (IaC) and GitOps tools for deploying Kubernetes Addons and Workloads. Addons often depend on Cloud resources that are external to the cluster. The configuration metadata for these external resources is required by the Addons' Helm charts. While IaC is used to create these cloud resources, it is not used to install the Helm charts. Instead, the IaC tool stores this metadata either within GitOps resources in the cluster or in a Git repository. The GitOps tool then extracts these metadata values and passes them to the Helm chart during the Addon installation process. This mechanism forms the bridge between IaC and GitOps, hence the term "GitOps Bridge." Additional examples available on the [GitOps Bridge Pattern](https://github.com/gitops-bridge-dev): + - [argocd-ingress](https://github.com/gitops-bridge-dev/gitops-bridge/tree/main/argocd/iac/terraform/examples/eks/argocd-ingress) - [aws-secrets-manager](https://github.com/gitops-bridge-dev/gitops-bridge/tree/main/argocd/iac/terraform/examples/eks/aws-secrets-manager) - [crossplane](https://github.com/gitops-bridge-dev/gitops-bridge/tree/main/argocd/iac/terraform/examples/eks/crossplane) @@ -17,49 +17,58 @@ Additional examples available on the [GitOps Bridge Pattern](https://github.com/ - [multi-cluster/hub-spoke-shared](https://github.com/gitops-bridge-dev/gitops-bridge/tree/main/argocd/iac/terraform/examples/eks/multi-cluster/hub-spoke-shared) - [private-git](https://github.com/gitops-bridge-dev/gitops-bridge/tree/main/argocd/iac/terraform/examples/eks/private-git) - - ## Prerequisites + Before you begin, make sure you have the following command line tools installed: + - git - terraform - kubectl - argocd ## (Optional) Fork the GitOps git repositories -See the appendix section [Fork GitOps Repositories](#fork-gitops-repositories) for more info on the terraform variables to override. +See the appendix section [Fork GitOps Repositories](#fork-gitops-repositories) for more info on the terraform variables to override. ## Deploy the EKS Cluster + Initialize Terraform and deploy the EKS cluster: + ```shell terraform init terraform apply -target="module.vpc" -auto-approve terraform apply -target="module.eks" -auto-approve terraform apply -auto-approve ``` + To retrieve `kubectl` config, execute the terraform output command: + ```shell terraform output -raw configure_kubectl ``` + The expected output will have two lines you run in your terminal + ```text export KUBECONFIG="/tmp/getting-started-gitops" aws eks --region us-west-2 update-kubeconfig --name getting-started-gitops ``` + >The first line sets the `KUBECONFIG` environment variable to a temporary file that includes the cluster name. The second line uses the `aws` CLI to populate that temporary file with the `kubectl` configuration. This approach offers the advantage of not altering your existing `kubectl` context, allowing you to work in other terminal windows without interference. - Terraform will add GitOps Bridge Metadata to the ArgoCD secret. The annotations contain metadata for the addons' Helm charts and ArgoCD ApplicationSets. + ```shell kubectl get secret -n argocd -l argocd.argoproj.io/secret-type=cluster -o json | jq '.items[0].metadata.annotations' ``` + The output looks like the following: + ```json { "addons_repo_basepath": "argocd/", @@ -81,11 +90,15 @@ The output looks like the following: "workload_repo_url": "https://github.com/csantanapr/terraform-aws-eks-blueprints" } ``` + The labels offer a straightforward way to enable or disable an addon in ArgoCD for the cluster. + ```shell kubectl get secret -n argocd -l argocd.argoproj.io/secret-type=cluster -o json | jq '.items[0].metadata.labels' | grep -v false | jq . ``` + The output looks like the following: + ```json { "argocd.argoproj.io/secret-type": "cluster", @@ -100,19 +113,25 @@ The output looks like the following: ``` ## Deploy the Addons + Bootstrap the addons using ArgoCD: + ```shell kubectl apply -f bootstrap/addons.yaml ``` ### Monitor GitOps Progress for Addons + Wait until all the ArgoCD applications' `HEALTH STATUS` is `Healthy`. Use `Ctrl+C` or `Cmd+C` to exit the `watch` command. ArgoCD Applications can take a couple of minutes in order to achieve the Healthy status. + ```shell kubectl get applications -n argocd -w ``` + The expected output should look like the following: + ```text NAME SYNC STATUS HEALTH STATUS addon-in-cluster-argo-cd Synced Healthy @@ -122,7 +141,9 @@ cluster-addons Synced Healthy ``` ### Verify the Addons + Verify that the addons are ready: + ```shell kubectl get deployment -n kube-system \ aws-load-balancer-controller \ @@ -132,7 +153,9 @@ kubectl get deploy -n argocd \ argo-cd-argocd-repo-server \ argo-cd-argocd-server ``` + The expected output should look like the following: + ```text NAME READY UP-TO-DATE AVAILABLE AGE aws-load-balancer-controller 2/2 2 2 7m21s @@ -142,15 +165,18 @@ argo-cd-argocd-repo-server 1/1 1 1 109m argo-cd-argocd-server 1/1 1 1 109m ``` - ## (Optional) Access ArgoCD + Access to the ArgoCD's UI is completely optional, if you want to do it, run the commands shown in the Terraform output as the example below: + ```shell terraform output -raw access_argocd ``` + The expected output should contain the `kubectl` config followed by `kubectl` command to retrieve the URL, username, password to login into ArgoCD UI or CLI. + ```text echo "ArgoCD Username: admin" echo "ArgoCD Password: $(kubectl get secrets argocd-initial-admin-secret -n argocd --template="{{index .data.password | base64decode}}")" @@ -158,30 +184,40 @@ echo "ArgoCD URL: https://$(kubectl get svc -n argocd argo-cd-argocd-server -o j ``` ## Deploy the Workloads + Deploy a sample application located in [k8s/game-2048.yaml](k8s/game-2048.yaml) using ArgoCD: + ```shell kubectl apply -f bootstrap/workloads.yaml ``` ### Monitor GitOps Progress for Workloads + Wait until all the ArgoCD applications' `HEALTH STATUS` is `Healthy`. Use `Ctrl+C` or `Cmd+C` to exit the `watch` command. ArgoCD Applications can take a couple of minutes in order to achieve the Healthy status. + ```shell watch kubectl get -n argocd applications workloads ``` + The expected output should look like the following: + ```text NAME SYNC STATUS HEALTH STATUS workloads Synced Healthy ``` ### Verify the Application + Verify that the application configuration is present and the pod is running: + ```shell kubectl get -n game-2048 deployments,service,ep,ingress ``` + The expected output should look like the following: + ```text NAME READY UP-TO-DATE AVAILABLE AGE deployment.apps/game-2048 1/1 1 1 7h59m @@ -200,50 +236,67 @@ AWS Load Balancer can take a couple of minutes in order to be created. Run the following command and wait until and event for ingress `game-2048` contains `Successfully reconciled`. Use `Ctrl+C` or `Cmd+C`to exit the `watch` command. + ```shell kubectl events -n game-2048 --for ingress/game-2048 --watch ``` + The expected output should look like the following: + ```text LAST SEEN TYPE REASON OBJECT MESSAGE 11m Normal SuccessfullyReconciled Ingress/game-2048 Successfully reconciled ``` ### Access the Application using AWS Load Balancer + Verify the application endpoint health using `wget`: + ```shell kubectl exec -n game-2048 deploy/game-2048 -- \ wget -S --spider $(kubectl get -n game-2048 ingress game-2048 -o jsonpath='{.status.loadBalancer.ingress[0].hostname}') ``` + The expected output should look like the following: + ```text HTTP/1.1 200 OK Date: Wed, 01 Nov 2023 22:44:57 GMT Content-Type: text/html Content-Length: 3988 ``` + >A success response should contain `HTTP/1.1 200 OK`. Retrieve the ingress URL to access the application in your local web browser. + ```shell echo "Application URL: http://$(kubectl get -n game-2048 ingress game-2048 -o jsonpath='{.status.loadBalancer.ingress[0].hostname}')" ``` ### Container Metrics + Check the application's CPU and memory metrics: + ```shell kubectl top pods -n game-2048 ``` + The expected output should look like the following: + ```text NAME CPU(cores) MEMORY(bytes) game-2048-66fb78b995-hqbjv 1m 2Mi ``` + Check the CPU and memory metrics for all pods for Addons and Workloads: + ```shell kubectl top pods -A ``` + The expected output should look like the following: + ```text NAMESPACE NAME CPU(cores) MEMORY(bytes) argocd argo-cd-argocd-application-controller-0 43m 138Mi @@ -266,7 +319,9 @@ kube-system metrics-server-5b76987ff-5gzsv 4m ``` ## Destroy the EKS Cluster + To tear down all the resources and the EKS cluster, run the following command: + ```shell ./destroy.sh ``` @@ -274,9 +329,11 @@ To tear down all the resources and the EKS cluster, run the following command: ## Appendix ## Fork GitOps Repositories + To modify the `values.yaml` file for addons or the workload manifest files (.ie yaml), you'll need to fork two repositories: [aws-samples/eks-blueprints-add-ons](https://github.com/aws-samples/eks-blueprints-add-ons) for addons and [github.com/aws-ia/terraform-aws-eks-blueprints](https://github.com/aws-ia/terraform-aws-eks-blueprints) for workloads located in this pattern directory. After forking, update the following environment variables to point to your forks, replacing the default values. + ```shell export TF_VAR_gitops_addons_org=https://github.com/aws-samples export TF_VAR_gitops_addons_repo=eks-blueprints-add-ons diff --git a/patterns/gitops/getting-started-argocd/k8s/game-2048.yaml b/patterns/gitops/getting-started-argocd/k8s/game-2048.yaml index 44e2d12e50..c261a166dc 100644 --- a/patterns/gitops/getting-started-argocd/k8s/game-2048.yaml +++ b/patterns/gitops/getting-started-argocd/k8s/game-2048.yaml @@ -59,4 +59,4 @@ spec: service: name: game-2048 port: - name: http \ No newline at end of file + name: http diff --git a/patterns/gitops/getting-started-argocd/static/gitops-bridge.drawio b/patterns/gitops/getting-started-argocd/static/gitops-bridge.drawio index 51f8e7eae1..9d1da3c514 100644 --- a/patterns/gitops/getting-started-argocd/static/gitops-bridge.drawio +++ b/patterns/gitops/getting-started-argocd/static/gitops-bridge.drawio @@ -1 +1 @@  \ No newline at end of file  diff --git a/patterns/gitops/multi-cluster-hub-spoke-argocd/README.md b/patterns/gitops/multi-cluster-hub-spoke-argocd/README.md index c61d2d2197..72cd798fc8 100644 --- a/patterns/gitops/multi-cluster-hub-spoke-argocd/README.md +++ b/patterns/gitops/multi-cluster-hub-spoke-argocd/README.md @@ -4,7 +4,6 @@ This tutorial guides you through deploying an Amazon EKS cluster with addons con - This example deploys ArgoCD on the Hub cluster (i.e. management/control-plane cluster). The spoke clusters are registered as remote clusters in the Hub Cluster's ArgoCD The ArgoCD on the Hub Cluster deploys addons and workloads to the spoke clusters @@ -12,36 +11,48 @@ The ArgoCD on the Hub Cluster deploys addons and workloads to the spoke clusters Each spoke cluster gets deployed an app of apps ArgoCD Application with the name `workloads-${env}` ## Prerequisites + Before you begin, make sure you have the following command line tools installed: + - git - terraform - kubectl - argocd ## (Optional) Fork the GitOps git repositories + See the appendix section [Fork GitOps Repositories](#fork-gitops-repositories) for more info on the terraform variables to override. ## Deploy the Hub EKS Cluster + Change directory to `hub` + ```shell cd hub ``` + Initialize Terraform and deploy the EKS cluster: + ```shell terraform init terraform apply -target="module.vpc" -auto-approve terraform apply -target="module.eks" -auto-approve terraform apply -auto-approve ``` + To retrieve `kubectl` config, execute the terraform output command: + ```shell terraform output -raw configure_kubectl ``` + The expected output will have two lines you run in your terminal + ```text export KUBECONFIG="/tmp/hub-spoke" aws eks --region us-west-2 update-kubeconfig --name getting-started-gitops --alias hub ``` + >The first line sets the `KUBECONFIG` environment variable to a temporary file that includes the cluster name. The second line uses the `aws` CLI to populate that temporary file with the `kubectl` configuration. This approach offers the @@ -49,13 +60,17 @@ advantage of not altering your existing `kubectl` context, allowing you to work in other terminal windows without interference. ### Monitor GitOps Progress for Addons + Wait until all the ArgoCD applications' `HEALTH STATUS` is `Healthy`. Use `Ctrl+C` or `Cmd+C` to exit the `watch` command. ArgoCD Applications can take a couple of minutes in order to achieve the Healthy status. + ```shell kubectl --context hub get applications -n argocd -w ``` + The expected output should look like the following: + ```text NAME SYNC STATUS HEALTH STATUS addon-in-cluster-argo-cd Synced Healthy @@ -65,61 +80,75 @@ cluster-addons Synced Healthy ``` ## (Optional) Access ArgoCD + Access to the ArgoCD's UI is completely optional, if you want to do it, run the commands shown in the Terraform output as the example below: + ```shell terraform output -raw access_argocd ``` + The expected output should contain the `kubectl` config followed by `kubectl` command to retrieve the URL, username, password to login into ArgoCD UI or CLI. + ```text echo "ArgoCD Username: admin" echo "ArgoCD Password: $(kubectl --context hub get secrets argocd-initial-admin-secret -n argocd --template="{{index .data.password | base64decode}}")" echo "ArgoCD URL: https://$(kubectl --context hub get svc -n argocd argo-cd-argocd-server -o jsonpath='{.status.loadBalancer.ingress[0].hostname}')" ``` - ## Verify that ArgoCD Service Accouts has the annotation for IRSA + ```shell kubectl --context hub get sa -n argocd argocd-application-controller -o json | jq '.metadata.annotations."eks.amazonaws.com/role-arn"' kubectl --context hub get sa -n argocd argocd-server -o json | jq '.metadata.annotations."eks.amazonaws.com/role-arn"' ``` + The output should match the `arn` for the IAM Role that will assume the IAM Role in spoke/remote clusters + ```text arn:aws:iam::0123456789:role/argocd-hub-0123abc.. arn:aws:iam::0123456789:role/argocd-hub-0123abc.. ``` ## Deploy the Spoke EKS Cluster + Use the `deploy.sh` script to create terraform workspace, initialize Terraform, and deploy the EKS clusters: + ```shell cd ../spokes ./deploy.sh dev ./deploy.sh staging ./deploy.sh prod ``` + Each environment uses a Terraform workspace To retrieve `kubectl` config, execute the terraform output command: + ```shell terraform workspace select dev terraform output -raw configure_kubectl ``` + ```shell terraform workspace select staging terraform output -raw configure_kubectl ``` + ```shell terraform workspace select prod terraform output -raw configure_kubectl ``` - ### Verify ArgoCD Cluster Secret for Spokes have the correct IAM Role to be assume by Hub Cluster + ```shell for i in dev staging prod ; do echo $i && kubectl --context hub get secret -n argocd spoke-$i --template='{{index .data.config | base64decode}}' ; done ``` + The output have a section `awsAuthConfig` with the `clusterName` and the `roleARN` that has write access to the spoke cluster + ```json { "tlsClientConfig": { @@ -133,36 +162,44 @@ The output have a section `awsAuthConfig` with the `clusterName` and the `roleAR } ``` - ### Verify the Addons on Spoke Clusters + Verify that the addons are ready: + ```shell for i in dev staging prod ; do echo $i && kubectl --context $i get deployment -n kube-system ; done ``` - ### Monitor GitOps Progress for Workloads from Hub Cluster (run on Hub Cluster context) + Watch until **all* the Workloads ArgoCD Applications are `Healthy` + ```shell kubectl --context hub get -n argocd applications -w ``` -Wait until the ArgoCD Applications `HEALTH STATUS` is `Healthy`. Crl+C to exit the `watch` command +Wait until the ArgoCD Applications `HEALTH STATUS` is `Healthy`. Crl+C to exit the `watch` command ### Verify the Application + Verify that the application configuration is present and the pod is running: + ```shell for i in dev staging prod ; do echo $i && kubectl --context $i get all -n workload ; done ``` ### Container Metrics + Check the application's CPU and memory metrics: + ```shell for i in dev staging prod ; do echo $i && kubectl --context $i top pods -n workload ; done ``` ## Destroy the Spoke EKS Clusters + To tear down all the resources and the EKS cluster, run the following command: + ```shell ./destroy.sh dev ./destroy.sh staging @@ -170,8 +207,10 @@ To tear down all the resources and the EKS cluster, run the following command: ``` ## Destroy the Hub EKS Clusters + To tear down all the resources and the EKS cluster, run the following command: Destroy Hub Clusters + ```shell cd ../hub ./destroy.sh @@ -180,9 +219,11 @@ cd ../hub ## Appendix ## Fork GitOps Repositories + To modify the `values.yaml` file or the helm chart version for addons, you'll need to fork tthe repository [aws-samples/eks-blueprints-add-ons](https://github.com/aws-samples/eks-blueprints-add-ons). After forking, update the following environment variables to point to your forks, replacing the default values. + ```shell export TF_VAR_gitops_addons_org=https://github.com/aws-samples export TF_VAR_gitops_addons_repo=eks-blueprints-add-ons diff --git a/patterns/gitops/multi-cluster-hub-spoke-argocd/spokes/workspaces/dev.tfvars b/patterns/gitops/multi-cluster-hub-spoke-argocd/spokes/workspaces/dev.tfvars index 706f9b8432..755615e6ea 100644 --- a/patterns/gitops/multi-cluster-hub-spoke-argocd/spokes/workspaces/dev.tfvars +++ b/patterns/gitops/multi-cluster-hub-spoke-argocd/spokes/workspaces/dev.tfvars @@ -1,10 +1,10 @@ -vpc_cidr = "10.1.0.0/16" -region = "us-west-2" +vpc_cidr = "10.1.0.0/16" +region = "us-west-2" kubernetes_version = "1.28" addons = { enable_aws_load_balancer_controller = true enable_metrics_server = true # Disable argocd on spoke clusters enable_aws_argocd = false - enable_argocd = false -} \ No newline at end of file + enable_argocd = false +} diff --git a/patterns/gitops/multi-cluster-hub-spoke-argocd/spokes/workspaces/prod.tfvars b/patterns/gitops/multi-cluster-hub-spoke-argocd/spokes/workspaces/prod.tfvars index f1fdaa1ce9..22789479cf 100644 --- a/patterns/gitops/multi-cluster-hub-spoke-argocd/spokes/workspaces/prod.tfvars +++ b/patterns/gitops/multi-cluster-hub-spoke-argocd/spokes/workspaces/prod.tfvars @@ -1,10 +1,10 @@ -vpc_cidr = "10.3.0.0/16" -region = "us-west-2" +vpc_cidr = "10.3.0.0/16" +region = "us-west-2" kubernetes_version = "1.28" addons = { enable_aws_load_balancer_controller = true enable_metrics_server = true # Disable argocd on spoke clusters enable_aws_argocd = false - enable_argocd = false -} \ No newline at end of file + enable_argocd = false +} diff --git a/patterns/gitops/multi-cluster-hub-spoke-argocd/spokes/workspaces/staging.tfvars b/patterns/gitops/multi-cluster-hub-spoke-argocd/spokes/workspaces/staging.tfvars index 5fc3593f28..18a50cfbf3 100644 --- a/patterns/gitops/multi-cluster-hub-spoke-argocd/spokes/workspaces/staging.tfvars +++ b/patterns/gitops/multi-cluster-hub-spoke-argocd/spokes/workspaces/staging.tfvars @@ -1,10 +1,10 @@ -vpc_cidr = "10.2.0.0/16" -region = "us-west-2" +vpc_cidr = "10.2.0.0/16" +region = "us-west-2" kubernetes_version = "1.28" addons = { enable_aws_load_balancer_controller = true enable_metrics_server = true # Disable argocd on spoke clusters enable_aws_argocd = false - enable_argocd = false -} \ No newline at end of file + enable_argocd = false +} diff --git a/patterns/gitops/multi-cluster-hub-spoke-argocd/static/gitops-bridge-multi-cluster-hup-spoke.drawio b/patterns/gitops/multi-cluster-hub-spoke-argocd/static/gitops-bridge-multi-cluster-hup-spoke.drawio index 083d637330..c1cdad1fed 100644 --- a/patterns/gitops/multi-cluster-hub-spoke-argocd/static/gitops-bridge-multi-cluster-hup-spoke.drawio +++ b/patterns/gitops/multi-cluster-hub-spoke-argocd/static/gitops-bridge-multi-cluster-hup-spoke.drawio @@ -1 +1 @@ -7Vvbcps6FP0aPyaDwPjyGGPnnE7bmc7JQ+NHxcigRkZUyDHu1x8JhEESvSWxIRMSZ4yWLoi1tLe2duyRF+zyfxhM4880RGTkOmE+8pYj13Wd8Vi8SeRYIgDM/BKJGA4VVgN3+AdSoKPQPQ5RpjXklBKOUx3c0CRBG65hkDF60JttKdHvmsIIWcDdBhIb/YpDHpfozHdq/F+Eo7i6M3BUzQ5WjRWQxTCkhwbkrUZewCjl5dUuDxCR7FW8lP1uf1J7mhhDCf+TDph9/b7+L/h8e3+TTO7Xa/QD7K68cpQnSPbqgdVk+bFigNF9EiI5iDPyFocYc3SXwo2sPQjRBRbzHRElIC7VcIhxlP90nuD09GLdILpDnB1FE9VhqvhSK2ZcrYRDTT+YKSxuUj9WIFSSR6eha1bEhSLmL0ga/56k7BHxTaw4SilOeDEJfyFeYlpB+eeLpoFErl2/BWzDpjYI7GbiDbTdwQTbsKkNAruZLFWz1sE2bOrbMzZ7g5bewOgtXt6C7jnBCQpOFi453tKEB5RQVvDvid9bqegiYjDESKu7nc5WzrhRt8RMDIRpIuoTyuSqWmwxIY0+S8cPwFTgGWf0ETVqtsWPqAlhFp/MQq54LLzGJ/iAyBeaYTX8A+Wc7hoNbgiOZAWn0nKgKm3ErBDTTUk+ofKHwK3KasXJW8IsLenY4lzOYyEcTCord3kknfE1PGTja4Yyumcb9GEj57MQxfJKb4Ues4sZr99iu/65TNe3TBeGIU2yzr0ccA2mpjZT8xamvHMxNbGYOlD2SCgM+0eW37KsLkrWtGVHmBCurFQja/J9T6uKq6yw5xvRwAVpXpBT1YurSL6vPt5VY4mplcOVNZYMglCuc617q4QmyHBtCrL8jumedjgM5W1axdXlfw19PcMYXFtf75L6VgM3yEahiAtVUe4ZNKIJJKsaNWip23yi0tcX+nxDnB+VU4d7TnX1BFvseC/7i21RFddquKKwzLXSsbEXqkHdYpwc88YworSu7iCu60Fk4aipKB/y1xoKTor95Bfkzct2HLII8d/FnvaaYIhAjp/0eby+wuAtK9yBWmDcqVx2yP2G5HojBgnmL5RYdf0izz+1d/fmunf3pobbLh9A9TIWymkaz18785bNuuOAxnN0SlzH3vAufMitQqrhlDuccodT7svN96LHXNCWxxsOJM8XeGII3HLgvOiBBPxBDrLrTawHmVpg53uGTWzYxIZN7Jnme9lNzE5B9iRZ6/kGVV0na4GdgOxPttZkq/NsLZgN0dE5o6PO07Wgh0d838xpdx8dVTIN0dEQHQ3R0cvN96LRUfUI/YuO/FnPoqPKrfUyOjLZ6jw6cofc0atGR/68Z9GRa+eO4v1DqZxwoYJlcpUSKLjspyblPatPX552EOvfoa96GgYtTqw1XDufbHYuK0sFEaVwIXp6z3IZnzPzJ52rZZ/IG2plHEY4id6zYqaB9UAyOy3QkCxlNHzPepkBcA/0sk/5NyyiwbLzmM7MeLnni4BFsf7KQPkJifqbF97qfw== \ No newline at end of file +7Vvbcps6FP0aPyaDwPjyGGPnnE7bmc7JQ+NHxcigRkZUyDHu1x8JhEESvSWxIRMSZ4yWLoi1tLe2duyRF+zyfxhM4880RGTkOmE+8pYj13Wd8Vi8SeRYIgDM/BKJGA4VVgN3+AdSoKPQPQ5RpjXklBKOUx3c0CRBG65hkDF60JttKdHvmsIIWcDdBhIb/YpDHpfozHdq/F+Eo7i6M3BUzQ5WjRWQxTCkhwbkrUZewCjl5dUuDxCR7FW8lP1uf1J7mhhDCf+TDph9/b7+L/h8e3+TTO7Xa/QD7K68cpQnSPbqgdVk+bFigNF9EiI5iDPyFocYc3SXwo2sPQjRBRbzHRElIC7VcIhxlP90nuD09GLdILpDnB1FE9VhqvhSK2ZcrYRDTT+YKSxuUj9WIFSSR6eha1bEhSLmL0ga/56k7BHxTaw4SilOeDEJfyFeYlpB+eeLpoFErl2/BWzDpjYI7GbiDbTdwQTbsKkNAruZLFWz1sE2bOrbMzZ7g5bewOgtXt6C7jnBCQpOFi453tKEB5RQVvDvid9bqegiYjDESKu7nc5WzrhRt8RMDIRpIuoTyuSqWmwxIY0+S8cPwFTgGWf0ETVqtsWPqAlhFp/MQq54LLzGJ/iAyBeaYTX8A+Wc7hoNbgiOZAWn0nKgKm3ErBDTTUk+ofKHwK3KasXJW8IsLenY4lzOYyEcTCord3kknfE1PGTja4Yyumcb9GEj57MQxfJKb4Ues4sZr99iu/65TNe3TBeGIU2yzr0ccA2mpjZT8xamvHMxNbGYOlD2SCgM+0eW37KsLkrWtGVHmBCurFQja/J9T6uKq6yw5xvRwAVpXpBT1YurSL6vPt5VY4mplcOVNZYMglCuc617q4QmyHBtCrL8jumedjgM5W1axdXlfw19PcMYXFtf75L6VgM3yEahiAtVUe4ZNKIJJKsaNWip23yi0tcX+nxDnB+VU4d7TnX1BFvseC/7i21RFddquKKwzLXSsbEXqkHdYpwc88YworSu7iCu60Fk4aipKB/y1xoKTor95Bfkzct2HLII8d/FnvaaYIhAjp/0eby+wuAtK9yBWmDcqVx2yP2G5HojBgnmL5RYdf0izz+1d/fmunf3pobbLh9A9TIWymkaz18785bNuuOAxnN0SlzH3vAufMitQqrhlDuccodT7svN96LHXNCWxxsOJM8XeGII3HLgvOiBBPxBDrLrTawHmVpg53uGTWzYxIZN7Jnme9lNzE5B9iRZ6/kGVV0na4GdgOxPttZkq/NsLZgN0dE5o6PO07Wgh0d838xpdx8dVTIN0dEQHQ3R0cvN96LRUfUI/YuO/FnPoqPKrfUyOjLZ6jw6cofc0atGR/68Z9GRa+eO4v1DqZxwoYJlcpUSKLjspyblPatPX552EOvfoa96GgYtTqw1XDufbHYuK0sFEaVwIXp6z3IZnzPzJ52rZZ/IG2plHEY4id6zYqaB9UAyOy3QkCxlNHzPepkBcA/0sk/5NyyiwbLzmM7MeLnni4BFsf7KQPkJifqbF97qfw==