From 62fad6a6e64459e2d71ffc718c8fa7aa25a9edc2 Mon Sep 17 00:00:00 2001 From: TrueCharts-Bot Date: Sun, 1 May 2022 20:59:12 +0000 Subject: [PATCH] Commit new App releases for TrueCharts Signed-off-by: TrueCharts-Bot --- incubator/netdata/0.0.1/CHANGELOG.md | 10 + incubator/netdata/0.0.1/Chart.lock | 6 + incubator/netdata/0.0.1/Chart.yaml | 26 + incubator/netdata/0.0.1/README.md | 37 + incubator/netdata/0.0.1/app-readme.md | 3 + .../netdata/0.0.1/charts/common-9.3.2.tgz | Bin 0 -> 44113 bytes incubator/netdata/0.0.1/ix_values.yaml | 118 + incubator/netdata/0.0.1/questions.yaml | 2731 +++++++++++++++++ incubator/netdata/0.0.1/security.md | 142 + incubator/netdata/0.0.1/templates/common.yaml | 1 + incubator/netdata/0.0.1/values.yaml | 0 incubator/netdata/item.yaml | 4 + 12 files changed, 3078 insertions(+) create mode 100644 incubator/netdata/0.0.1/CHANGELOG.md create mode 100644 incubator/netdata/0.0.1/Chart.lock create mode 100644 incubator/netdata/0.0.1/Chart.yaml create mode 100644 incubator/netdata/0.0.1/README.md create mode 100644 incubator/netdata/0.0.1/app-readme.md create mode 100644 incubator/netdata/0.0.1/charts/common-9.3.2.tgz create mode 100644 incubator/netdata/0.0.1/ix_values.yaml create mode 100644 incubator/netdata/0.0.1/questions.yaml create mode 100644 incubator/netdata/0.0.1/security.md create mode 100644 incubator/netdata/0.0.1/templates/common.yaml create mode 100644 incubator/netdata/0.0.1/values.yaml create mode 100644 incubator/netdata/item.yaml diff --git a/incubator/netdata/0.0.1/CHANGELOG.md b/incubator/netdata/0.0.1/CHANGELOG.md new file mode 100644 index 00000000000..d1b6ff67016 --- /dev/null +++ b/incubator/netdata/0.0.1/CHANGELOG.md @@ -0,0 +1,10 @@ +# Changelog
+ + + +### netdata-0.0.1 (2022-05-01) + +#### Feat + +* add netdata ([#2595](https://github.com/truecharts/apps/issues/2595)) + diff --git a/incubator/netdata/0.0.1/Chart.lock b/incubator/netdata/0.0.1/Chart.lock new file mode 100644 index 00000000000..7f1543eaa93 --- /dev/null +++ b/incubator/netdata/0.0.1/Chart.lock @@ -0,0 +1,6 @@ +dependencies: +- name: common + repository: https://library-charts.truecharts.org + version: 9.3.2 +digest: sha256:4514044d0d416a02c0029081a25943395114bcb29df51a2ede27d4257f71d412 +generated: "2022-05-01T20:52:25.980307332Z" diff --git a/incubator/netdata/0.0.1/Chart.yaml b/incubator/netdata/0.0.1/Chart.yaml new file mode 100644 index 00000000000..d0700922c5f --- /dev/null +++ b/incubator/netdata/0.0.1/Chart.yaml @@ -0,0 +1,26 @@ +apiVersion: v2 +appVersion: "1.34.1" +dependencies: +- name: common + repository: https://library-charts.truecharts.org + version: 9.3.2 +description: Netdata is high-fidelity infrastructure monitoring and troubleshooting. +home: https://github.com/truecharts/apps/tree/master/charts/stable/netdata +icon: https://truecharts.org/_static/img/appicons/netdata.png +keywords: +- netdata +- monitoring +kubeVersion: '>=1.16.0-0' +maintainers: +- email: info@truecharts.org + name: TrueCharts + url: https://truecharts.org +name: netdata +sources: +- https://github.com/netdata +version: 0.0.1 +annotations: + truecharts.org/catagories: | + - utilities + truecharts.org/SCALE-support: "true" + truecharts.org/grade: U diff --git a/incubator/netdata/0.0.1/README.md b/incubator/netdata/0.0.1/README.md new file mode 100644 index 00000000000..5f0a59d1f18 --- /dev/null +++ b/incubator/netdata/0.0.1/README.md @@ -0,0 +1,37 @@ +# Introduction + +Netdata is high-fidelity infrastructure monitoring and troubleshooting. + +TrueCharts are designed to be installed as TrueNAS SCALE app only. We can not guarantee this charts works as a stand-alone helm installation. +**This chart is not maintained by the upstream project and any issues with the chart should be raised [here](https://github.com/truecharts/apps/issues/new/choose)** + +## Source Code + +* + +## Requirements + +Kubernetes: `>=1.16.0-0` + +## Dependencies + +| Repository | Name | Version | +|------------|------|---------| +| https://library-charts.truecharts.org | common | 9.3.2 | + +## Installing the Chart + +To install this App on TrueNAS SCALE check our [Quick-Start Guide](https://truecharts.org/manual/Quick-Start%20Guides/02-Installing-an-App/). + +## Upgrading, Rolling Back and Uninstalling the Chart + +To upgrade, rollback or delete this App from TrueNAS SCALE check our [Quick-Start Guide](https://truecharts.org/manual/Quick-Start%20Guides/04-Upgrade-rollback-delete-an-App/). + +## Support + +- Please check our [quick-start guides](https://truecharts.org/manual/Quick-Start%20Guides/01-Adding-TrueCharts/) first. +- See the [Wiki](https://truecharts.org) +- Check our [Discord](https://discord.gg/tVsPTHWTtr) +- Open a [issue](https://github.com/truecharts/apps/issues/new/choose) +--- +All Rights Reserved - The TrueCharts Project diff --git a/incubator/netdata/0.0.1/app-readme.md b/incubator/netdata/0.0.1/app-readme.md new file mode 100644 index 00000000000..f274ca7e29f --- /dev/null +++ b/incubator/netdata/0.0.1/app-readme.md @@ -0,0 +1,3 @@ +Netdata is high-fidelity infrastructure monitoring and troubleshooting. + +This App is supplied by TrueCharts, for more information please visit https://truecharts.org diff --git a/incubator/netdata/0.0.1/charts/common-9.3.2.tgz b/incubator/netdata/0.0.1/charts/common-9.3.2.tgz new file mode 100644 index 0000000000000000000000000000000000000000..938077bd9aa112c4bda3eecd30d24b99059d7e56 GIT binary patch literal 44113 zcmV)RK(oIeiwG0|00000|0w_~VMtOiV@ORlOnEsqVl!4SWK%V1T2nbTPgYhoO;>Dc zVQyr3R8em|NM&qo0PMYcciT9UC_aDdQ{XC@+jd{;X<4?loBgfZNq75n9zL;?-rdAOyb_@0ut6;!)5fB z`+xfVet$d~iGTb3e(~S_c)$Ob!DzTYI5->~3=aR&9}Gu_gTH|O1K?76GRh$NOaIPo z6+8C_d0>h^B0_NzPrz!}f@x}gMvx)OS|OqV!6_5(zR%)-{{PPL9wQkFM428;Q`%z$q23ZwhDcAnm#o;r0dGiyfGfx# zpf*;dw?NpX;q>;6Fn&gIUCQ;R}So6h+BRD@jqjO5?L7oTEt#00HYl zz*qyeKtL4$L4;Av0Okc-01%WW6tje^Ct$t^NEauzd{DJIvQ|^LfI&VX8Jug$^`CSB zhX>=yG}wm+vhCqv?LXF$QTCMIcQg9IRVF{5lsuCg5!LHeu%kQQo1Jfc7&c=!XoFa9gV1V1nkn zVl~}!*bPZ;U^ake6M8l1_PfLWaL_*~K6g zLbK6qFdZF^ro-WIdelESME&Ez6!xbhbTAtakB^U=;II{`Q<5wh#L>2t*7d3hZ6G(K zvo60GmP6%X_n_O?tN3(S9%p(QG!GqQe0k zhND3MkB5f`0U8dE`@>`J5Et6sin=jkbde-%Tk7h1)zmeR8&X%7-wdl-SoBAu@zH1+ zhNGh+7#_gE@E9E&hR1^ggbv2RJ`9J`(LsMa9E}E}V0v(P814^`hX;d07>o|WQG>Rt zse2OLz%^BL4U!O1L{^AwOWC|;HEnsBjsoA1yjGP)5FHjCb@y`?9uB5chz4PQG@gcG z7z9TL19$-8@xdq@1i^857#<%U4MxN8U;szc>G9z(K>LUN{&0V^KkEn0n%|0xVU*$+ zZA)octD4Fu5^6&NOK6+mIAq=L4i36QL)T*z?vIZ8u#eDae|89G=;^xJ;e;9^GM@O^qK{$ZnbTI25jYhNMqy5o- zI6DZZXf{H}!(jh#(5U&XNWFvv!*IGSomI7JB5Sw}DXfZbgyhn;-#zT^Yucj0a5UbZ z9qtduM`3?|&=2A9a4;MV#)DZO!TsYPJlY=~?*}6|9ZnC12cy~WaMquO!-M@09?v$n zy&Ykbc%IyXu(DbWVHMn_gq6iNLUIUu(Cv4RG+hsl(eZRNn~nyvx;b^#jG(H;lgAh%R!hb?3$QfoSwXX zH32giQPgS$Nz6zRMTi)$eggSc{AuHIcMK-r%h!tDMR1CuZNSP3 zckRq7PB0(pVGi(jG$F;oVT zgO|Ww3Q}+|0MFxu@Tr3-|EBThQ;XOj_zSE1IgJY~E#YU7#c&02#HXI9W&Pd;49&<~ z0uX-{s#-%^sGCBbD_&nNVI1zzT?0q!R6Y%a zBetaqiK*;?0m+=!)aIY9swZJ6Yv9<37{C$@DHC%F@Zq1XHMDN)88|1Hn-bC5(_!?P z5qRRZ!};J;BLOb)68$rYQS0)5Cg8*6sZ~hoI}Use1WhC3SATnQAzNw54@J#1M=_Gd zh*p&ffHYK=FtwGHRCEf0q2M`W3y@Jh)(aFZ!HU~U(+E*fGKFk00pIk#Db?exEfUK1 zB+qCxlJFcs#ZUTCWzIZ!QBULuCb632*wn+4*8&S#CB9=s|bSxmtVW(#n6`QMtGx-G`m#&)_L zILbmC=K#e|7o?c0;KzjEe{x6>I8Q=wlCgvaFhZnYf&Y7msett#EvU-iSct{a6kw3d z5u0#E%5{aZ3YIv2Z4QoH?TDrP(uU?B%q5Vi$X9(K$;6-3#h-$ zFeqpiFLPN5!%&ON0!)udr(s+!lxeO+RS_GOfQ%}$3Oe4sU*{W-|T@piZ8fBCr@;-^AePjLp4#y#m=aqyfQy3U>zY-iq zx&5xVkP2KHz%Q|MY-R0|xN3}r?uZLdz1a<8fy)(|P5*%cMl~asap)>V6GU04h7(Scm63Y73#?0lNLf= zcVY<41w=vsK}$|A)n&evrCsnYRU@cW_#Qy&U-hCRe{-u={kj!A_}gLsAe0=%|=9G7@cVV)LN}_d&zv5fHsQhep@YCaSE3c^|$g6w8KS^ zwkzsRNx!ZtU-RHVmjLqT+4-sM?V_d<03FcQc3i(Z81{R^QK9ntBxA^}5+cfQ3}qxq zyWbW6*E4vDXAT*m*Z-yEPw|@6><* zwt&LsrpR98a&3d+fUHwKv2)9RPwF3`Cxt0Gvc=3`eNjlE@kl!THI>#n12Fznp;Oy2DxICLy8f?i(nqqZKAeES9pyGVg**rP*@p z=^40K#|(bfKBh_Q893Pmdb#loe77rGdpQB$eE9;p?~<?pv-YzkdCu^$eVvA}uu} zC|-R}lBM|#K)2g%p?IYv+%xb|BPIKbu*7uwhI^8&?sjh#^TR%&Rlgx3gAZW{<;g%}89s+DB|J}HyrdrTD{ zQh=#tb9>NM%L2J=tW_^XkOT{4TLRM1>M0{jpzS(dyh2(qx>ogEKL71+1kL{b_njJ{ z5hQVdQbv2aUPl>oIG*#5F&8G59HAXmu=h+V9vsg*Y=QLa-Iml37xL$89A8tHVYCD4 zoFqbVeV~YdvzK7!{KMJHUEVV;p8!RvSY}0QuE8=sEjfjGp$Rw`AGHAZ@aE*=rwQoy zhuZRmF*k!UiiEYq*<05=O=5;Vvu*%WIK>fWe4UzPjN;HN4}bV@#s}SXgURW9YE|QC zgd|DT@WIe_6XwRZ@Yku+dxPl`vS6_t)=O?5~TX8$8$b^@e%>Z0FEhxQ3R4WT6bIOm+{!rdu|Q! zr2`7F*y79Nj)LNJv9{{A)LxGl1HJJI6F$U zp9NeYfVtqkiNQ4z2J+v>e$b$C zhkTXl`c;Qz4$F({IZ39dwCUgJG!f;}{?m1(RcG+E-bZ+aV!r6*6BCQSD1(G$X(#2) z)81}fh~iYQvN|2`T7d$o2X9`+4+Q{?gS8d*D&P8!9I!39EO7U~oefO6K>Nf$ed6{5 zw{31PT?i$hMt_}TL=2J!er{k(5ueK&1)Cy9b+qCXiIpq3;bs+IxfOOCazx!ew=Yl6 z+pT=zdwF`EH*hus5d3&~d9GT(RH`oR4-w*tfA8`CTo~29E4!RRw$OEaP50Vr+mM^% z`j_#Ga=J)+T{AVc*RsXUEr)7d1?p_3%*Y4@d=dLeQ&Nn?o?+Oy0`rM7tpp?(y+jdQU!Wj~LplM2zWSOXf`yVTyyp@!$(Z?Ypx)0QjxvHS7X(p` zF#nS8wT2Miir39F^E12o{2<(Jpg*zuHtg<_?VkDF5B&GW@E1}iY|ZXUm-v~T+CcA_ z)fMa~M&E|fZKB;XoBKfD2a^|>d8pn$dnP^KO9W#IFary2Cxa#YjF;JxV|DQDe*eYb zpwCx@ysls)jwQ%aFqMv0%*3pq{uxz0amM{tOIobZiP3SF9%5`E12+pCNZ;`c^Qn6ull0|h8==vl92$> z9ycLZgWfZAv}FXV4TGv4)`Ktk=!)zNWLSi9qeIM{Ng9Rdi*5ZN1wij zQ8b0Y^=0xpnbUXiD?$?T={F*Sj&f3szf@up;5g?rx#tC9ge2c-S|BhdFhH{`iq?;W zy}(_xdS22O#r3ka_R(T$tBpje{Xi9CQxZq({IjS9$u$c3dRL(!L8~7ntesdX z>2uCzGyGYC*Sbv(9i|Q;+yH0~NTY?+cCOR}CX7$+pBG|Pbx*kBRbS2i?gd_^5!!j3 zz;Fs97zc>#?g9SuJN0ur*ZOvmr2>W(Xz+=zGCu9ee=qnSm#62-jQa5M{F7Z>E=c$%wKPfLO$;Dk z-{jGAaR}y!<#Jy{qi|OG@cy;tI)u{kOsJ;2tA2gj5l7=mPGwZlt) zN<|Z5G`f6*RX7KyP^hM!4hEre=xk*w7Fjv&Io3sfaE|{ft)`+Fv{7YiK`}~N`#Bnw z+LXHM{-N0_e|XJ?%t9*aXCL9DlAT$|BlI7&?08qvbf|C zGNIu+DmJqlB>{|bE2)T73fUq@iUY{)U;Zgy@#L7DL$>IGW+(yU`|mmLqz_i;ijdpO z+@!RU&Vm1U0S4W{sM9Y&lF{zx;sCt!(Q<>8TGDFLaeqloXPlEcEAVCtP-L`XW5~iJ zZwA>~Fcl2A%hwl0cIkrexWbm9q#|OMi$}>>d<0SzrUu>7k>kN4YDohVs4Cgl;hGMM zsD+U}45T8-#kvKG05r4f;_9>j5r${NzixyK5NFa(5n;~mnalnr8s5jmMFThGyh0hL zaE5j4Rm>7vF&p$@2(zvg0jm%eK61q0*FZ z*3*YVuF$#{LlYt0V5MP|z3oy%g7^j`;yh9HTEm?4#bIj8lUs%3 zer{DK-vQWkRM4&KvlIjXQw)TVL7+2!7UZ!x_`vJ&f{wW{OOgqgLQ=g@W9txDRh-TY5iffg|hxWaCZ_q>WZ?$y#1CwyIwIsbU7`2J7m zZa1Bd%gz&ytr2iR5kuZJ4x+z|pygo#^0pxOy!+C2C z=oTc#N$Lz{VK!bbDAy0X`F~63385CCWR zLSuIi#EDZ?7@;DJM{K9^$+Ad{f5L~pY{Z5k7f&6Vw^dZn4U`Ap3ChG#9DqJ!Dp)dz zAYSg}qpZSs%y&N1oHdEHqofO+au}lVb&`>e0BPayLAeZrB>soa>@8dtpBw<6x>hm) z2xvC#$e^g0YCbe8fiRz;+6OPY$8bt=jz;nBL`2! zDVH~iohnRAL{{L{H@Pb_QHH#*j^zo>WfCGYXL4u%RE4mq;gjPUBJzI}(5;;C5=Jk_ zup=>~`nXPqV?m`09-6LAz?q4ntfKnPJGlQe<1=lo)=35q(w4wN) zXabIpkAJ`hxO62XV(B6|l1o*2Jm%vm$kHSRpG1O~ELLYFJ}F7X3l?)1oSM~$);5|m z_+Ts`;Z_Q}K_~_=vcvyd7L~UlvZ1VKFT`ZGJ}#1@5Kdeh$1K~Vw$qpw#e7dz_PAk| zD8!lYS+-@ik9MxUAYjXMM#0YelQ*3y46gY&nFBbxdd4WACTdR(u?EaXn%AXfZ%HX3 z@m;gu zIm~RC{tgFNjqaasa362#lPsQ8t$Z6yeUimbe9@dQTGnQOFe(L6(gaJhSe!=9eU%*N zUPei8ieoTKq7V@oeL7nWHloa$NT8Mu7+@*PkqGR2xJ5gwHP z5)tpyC=rAx;l`nNGDQ6+i%~76aFk*@Y{00Z#nwT$iGr4Uy>Psxf^P! zQfocND2mYt(Q1PNxJTlLXk{&Kbzp&TZls7TF{Q$xC(l6zi{vJj`G^+FM5+Xe*m+*C zFbPDe zR^<#&i1vQEG&Z@zsvL5H99y{KbQDjSWo5YgZ^*gQ&D(&1wLkc-3@m$m|7@(`J~8ue z#?0!(WzNG@oF@x*mOA-p4cl4U34dV!zSZA{^YXtGzG>-)mm~2}flN^#JiT}DM{3z3 z{f_b%?|`#|YPN(X<`vN1Zt0{P4g1z7x%IYOcXY0&3ck`C)=gMTmvuKWtNF{>UoJ;t zTW<6m4Y~8iIV2w@QD1&|tGbovLHh&q??bb%cf?gt&F0}&`Qw_6wJf}OpjGP)N4W^~ zX@si;RG14W69z44w6ynTEP6Vkj zojFOew6|P$Op(@xZ7=JR7sX|H1i&XN#tO$FUg0o<5g(areQScqwnQ0>1JrFv3X2Ui zovf3pe2XGlMWjx&y+{15cxi70wVj=yw)if0Z-o2g*)#Bt0I_ulB21Z;Dt-!s>nts` zV!bw7acqGumaOiM}C;sd}iFt3gW%a|1 zD^9I!%!BTr-Li27X2$qnWrWgrFcRqcfFmmr zW6X!Qs{=#A#KeZ^epuDASoT#?ah60;awC%FKLZgL7kdDP|HvqlM`$1gG2${ElC{id zt&U`oWH6F6gtfNyddf72D|;rNJ1y&I(21dRIq{!(o)EXA#LM?YYZTT70j zRdi4&c+h`?^Q?;MGISMzsiH6_plF2%jQG^(@I|mrz$n9AOzyl;1o5aqr`jk>7=|W; zd2P!kw)5lpTh)9QoUsN?19h2}I8}$^S+b`*0!hZe-;#{*MLw02dD0WJw|jj=JCJo2 z$x_UYUXqbco^4;>iQmz8*ei1Mo|y}qJF7JIJBF;x<1GMIseKI5wv~B5#VvKd8|qXP z*PglXIw8QmEZW>orwZEV{^~Ckm*uKYrmF_?wWr)X3{lK5lwp%99j^B4@Ww8jOan!3|mEgVL$i<=$43&Go4TZ7Ui#3ovE#=)`LrMHe@i1q;hDk3NfgB0`lanO>cp zuSO<1)%SH=%!Ht%BJYZo+EP=nkl?j~hVH2?Hd4bqWUN>eU3?mXu zuW}bj`MxGl3MI}j<_HDi<&bZ+ED{_(HFH?5)@14Lab%A2ly{W8n;5t90y`TSt2E~S z>v9y-*Ye)g1GrMRcczxyshnQzmPa=zx$Dsm_I1-zDhs<$Mi$Dz{NJC}u#j$|GxB@H z%gF;t7RO~u^Kw6hvjcO(k? zFTcl7d!+b^4RhAh{-%!bipYy8LQLfGc`IBrN>siMmVlJVMx4RWfC7=vTy{*{v}oKj zoes>5eCdEVi7hEmM8NveRx$Lw?uzmj+ZD-z)G`MM^cRqsaplGX*Z&I?yC^e0KNK)^ z!a> zRlb81jYl06a|(vV+Fg02g~+au&ogc`iV%6Rwo`3hBfd(%MwIhWz)d)vn#gKhwpPU9 zl@4}SenB-M`5S+4WEOL2)1%L+xZVqEw{I%%pf)lXfloNRA{2hove-fCLfzD(jlRP1 zTU#9Fi6`>I6Ga8l-Kde>WM@L)Sln(78Wa*qX(QE6#YwX;N%C= z`BW9QdEOhV9jm~zXAhDAM*t>hHmSRI=N1`ooCfS4c}5(tKOXcCB_CMnT}pfqn{*^w zFhcHGuS%Z)wn?B+IFng8eGk;_U~=fXb!X{4C**l;-)VOtP`5qoUU}SIpX1)nCQC`O zWDrM|L6+NOQ8JfqAG*LP(1}H&7-3R07Q{B?H@QCf(91GC*%- z6PenNXAxNx_Sr+ZnPMFql??Xb{cGOq*U2>&A2@Tk!4{V$pM>C@xj8c`EdW)^g{^uK zCHhF9Nf)7v9A2UKZI>7DuGdw^t&3>-+s%s@F}g_P8B9GdNRn|D5U*o%wUfAK=?1ff zusP0?@ZRQz#-VO*7(5?h8DW6m=j1RzZ#6kg?T7U-JbTtsnYd}b^(GUMi}QEfD3eWc z3}(WG8#A5GDMTrXxygnR<)GBPC<$d;|NIi=1=gi|QYsF-o4VeMnf1v-V||6wfS{1J zHO~j`tx_Ui8I0wf^-|aizKRou)H&=A?_Xc2%Y`kCz=z=Fcbs`M5?LE=?@@^9_T3`9 zTC*OBqL16DCFkpKx_!4)#bzB-g&(Rsh` zt)C}he$#rFrO_?h==b~m@n|Ie?f3h|e~0_ygTD+$!~Ma*;pkv+_?P~$KRoFF1@!N^ zuihu443fX}@7z|gbAOQM%a`7_EukDtUKO!cQ5&MuC_^d1u}sLb$gkl~6PX52GKUJH zQi;bP$*+^o?__t)ly2+W-q)|KFJDX`QCk-1E>hSAov&Ok^RIXYx*w$}VO{CpRTEYf zltrH}QYa4VPhRLdyA4#irLOOVZ-cH|Q?6*6SN{67)#-FvFvV(xGXWNMz147v7#y^& zaU4!S#f)k#5rZ-kNC!`T`I2`+pr@8{2GJsB@;k@qR}f<^{TLYWs`~m4(bT2row^wo z00-+drM=ZaZEA6BzkI3ae;ymfS8R$309d&D21-&E{A%16HmwDKC63=Cksg>7>@8ig?2edB;bbK9BFcNlsD(S+C$g& zyZV{0rq%trX=dKY22NIpz&WxS*+AV*81XKlIJAG(_D~)Oyw6T9^W%qi=w}1GoUZC0 z9VKb>-@moc{T)4J{STw)4!Yj=Y|#JxgJIv*|AW!s@Jata$|Ll@x@Vq|wLEQ^yDlBi zg1n^^oT+^lf`k`_*Ys(%$O)O z#-VNMtHk=>_H3J>pufa5(Mn-?;1aY{dkWf&sfEVZuNOANKeA{k&wq0;;@+gdhWS4j z4)zQ4|6qT-|1|#};}P@!y_m^`%#da>==60u*hF1cTs46W|5Qz5dDnuKA`@C|I5UsH zc#gnxUSSVB&rj@3UKk@Gf9V=GdFj$pL7DuffP}<>T1|Amer=i3y>Df*F>4df&ZJh# zZYj^72m<8|s$G#{yIluTj-$fzisQu_FX7v^E4C$-oIVn5;9g=p+T?>zDJS{A>bBQ3C@$yGZ zSwhw-vyZiex7zcSm4MCtf&z&pWWnOKH8gdD)75ofd&X)k!E3%&;4Ov$phWJf=6odY zax%D09=U_=&^}GVlQPX~=w1M3IdELwy#tAkif9xueqCVYCdii1wXYKP+6_6Eq)F%* z#3v)+!5)wPH|ekM%K+G*|My3S2Sxoq9*my!|6@G2(f@`)?$-b?V4GL~rtp&q@Fy?< zh;RGGsj0SZ3>wcVBaor_ny+W|qP+bcNd|2DfS4Ng-Xe@cuoEK-UJhip^d*TR9M3`|LMT;``ZKDX#ee({6GD}gD3m%F&^RE zw*CKS>i9yf_a9Ulaf*5BUH|z#ybV47`bdT4_t&oqUVqKJ6+VCU+4A^nI6i-WsFOIA zJ^9jXNLT@+%9Li<{N$go!dG8&G5PHHFf;w)q&fx z8cr@oKktF(EV726NJ3T?@puNh=59Uvqw1Hlg)(^oc7Qg-{<`Y?b=3xK7RgS9=reHX zT;iQg+cLg3OHGPa>mY8#s9^V$Mlh$Lj~VJP-@FBc2>VfFRc>4Dc*#~|1VmU@9@Vq< ze!N|(Gs67)LoFq%SVrPfmbc<<*ec!I204{azg+Y@SF+>GNGZO;;Dot_cEF2D~Xe5x75*uc&l}-sV_iO6?yeJ zY;cf;$UdOE|Y!}dNv_SI9eZ@B5K3i z9@|^6j;%c!F^yHB%r2#mE~6A73RW>M3rfg84KT2STNby{#*b1(6`B}##oy}mm*(~6o&kT_mMrScYWG3>@Tf4xO z+l=LEZO{eQjO+vFpr=YS+K?*t27o@*SMQEUi4OJ+zhW`V!bWMrmHq5ny%3dwPJ3wEl|@{o1>;{ zY(VY13`b#pB5(=QdbZAw%XO=nI0u@au&zI*yb9bS&*f9mA{XXK5F}a53T0=$FhU=p z9M5Or`XtaU1oc|hLjf7PV2KK{lF!vzZqPYKRMTEw?k>$)*F&{IeTz=f+BO|9)q$l& zWMnL91**HnjdsB}CH^g8O{OrY;>%KDk-Dd0S;c*g%NuWhrKGobR%Hv$MWCm78Kh8# z=9$&iQ&w1uFsj6=ylLcagq1q~*!G~u{#yl)oBv}l>>n2Me+&mt=l>t&DV_g6&ojWQ z3rEEbcDKz2AheJ_7%*K08v_7!#Mt@AQ#-uIq^S>3K^bwYm6tZUY6txScFX|*fsXht zg`#+|t3vriHI?^Ibh_jWvf8y`2sv_{qBlT5ER}D3+P~aVG0aPbj%`}x}f*((1dj3P@v ze9Z4Rz1M?)(&Y4n2no(CLhm`GD8PPSOlKr)0#-LUXJiO}!p;GjU*^ z4hIISTG;x$UrAb*VT#K~`DgKm-h!(RMN$B{eSEj!`wqt;j^|IKxLq?OiI7SJ3RC<8 zNwTzt@-3Yd)Sfq6hs0%4I84NrtAuyq_#On38-TjrinsPKf_y_xZi~K05rPzT-|E*T z)1!*G8rQsxhpxj)OXiOkIb7ENa%Fs<7QhDm-#_S&i~9d?FnH4ckMSt|kHCfJntY|i zt5vo3qIi_Ck=YXPZzHGWY3X+<{3SzW1*W`2Tttamr(Y`c>ZbjlZTaGx|3c6{-uchr zs9&`I5BlS$`TrNMN@jHvER(=(!O?;a>Wq#0nhxu$NSyt>y0_KVk+;!<<+Pwz`p zhgml0=mq`%!!KhuM! zlYX~(D)m2<3$6Pw12)$ zAC8~S|31odi~N5Vib3u>1F#byql!FV8B<+NE%Sv)C!fBv$#MGm1dE$M(CWnR$c21g z83gM9-=i%0ohAWva@XA@6X3h}C5q4kW&*UQQiD{0nP~1}i-ds9viohy7}!lAVOU%p zs$hHb{h3mgBUlgg%OfV@QwsX+meajHe_v_ZRi)YUB>JnIc2Al2@=;smTh5o-Vkw^A zGciM}fZ3~bUtOE?c==c<6BS%jSkJEl+g$Y2@)fWM&?zyDeea(JWC&=}3#gky-y|V& z4$p`~c{{S{yohzhUHd(P;m-s!^iD+h?1EpxFIi%z0nM*%b3luWfSrru1y(E}aGvAb zrTCvtd&kGeKj5~n6<-*pgeKiXZLkA;F-d$N+w&-y!l(_Nmm*pJEUx(9m!5D->_O`>k|p#uEipeI7^q`g-4jlQiY>KrTP>p5zzHD;GWtLt%oz=v03) z=^nqRTcT7A&%Llke7mN!)Lt`^EQN}6j-gmE9sj2B2U|TYBi9yG#p z!d-4^q*1c|39Z$pukyO0Wy;o0@6`@zldczF<~Qu--ta<9eh$AJH0tYtHKwYbROxyw z*3AVgx$hn3 zLe<~DwH@@Y`ZTovm3?u$4S`MZKZl3oqWwSUKiU6}@|gWU$3(y(3Shxp7D+!TBDEWV zbrvz7=IY9O^SyDEb2G2zfgK}IlJb9)z^uYy5BB=buwnq=XQF_r^73|lYZBbO6H;=SzHKm zR_A)w;h1f$27y{i5|#u>Gy#{V=PgL))aH|F(7dGBypp-L{9WpRcBdmO1ODfoP;IN0 zDgmgpx-T)YeSE#Pb0VZJ?=TgtvyMNWW19KP~xwXHO&fFBSE}$^ZT0`maA4KArz~l*h<_<<8zAXod)i102u6 z9JAcG*)1#r0ghQ>ZJ-PQruXl?9O>E29zChU_}?~nFW$$y>d?#|A?2J(MA zD%t-B!>9QFM|q6=H;EMQ>ijcl6}_%M{nh9A)896@{oG}=l75`=D z)qTw1uRO(Wb?8?qaj!q{%XHyEqP~1;?tx>za@y2Jd~IcnSIvK&g<05tD%a^l*?*(a zpfvx-PxpU6%46(5ljB>C_m)0iljhq>W?emjeM!M9UACtJ;v1OW{+w1vH|Y3mxANHP zb`9!lxQr&?SGl7j7Vg>tTrieiMI!3&Diynl$Ni(e`ZyA zQR)_sHZaI=;KCR842poU!U2aU31GBHC^K)1$6f$$%-0TouC7wZ7FSnlt-*hY1w+LV zf`2g=MkD$Eu^@b(xYf*30_{vUfqd;k6)pPBQ({-2ySTc7wd%kt{8etD5bea^3} zDs@zWaXOm6-ukd#(KB)PQ-7u(tA{%3SJ3nie&FxctJlr)|Bk^w4gCN6!_xY%KYTj> z@hDGi{EuYbdkXyVPP&fRd{Yj-JNWgU?8RF?Rr7z9#=R?Xm*j)ze;o9O{bK&d;oH1&Q-Tm|wo;vxjra|vYvgw1Z{|ASoqWw2Kc)I`V zQJyOKua5)Cp$A$CK$F6vu%wPKWgwY(m)0#9hoUC*oG#*$RQjK1c=P6hk<9)jf1(dD zJ;aJ%wf%?-e$(5n*ZcI2iG6fm>3t{jdD1n%ucwjxf7tvF`-kIV{Lf%;@D%_3C{OA9 z=UumdJyJ5?{Z$`*o4@MQhP_{>RFkb=r^4NmJ!}#9t>0Yy_r=wlcP~G@eznD}F{j=i zbHkYP&wcF`D=IwvHgUx!18@HtN72O%X2HU3?fbL$uYNvx{n~D={qAksD)Ro_hs#%2 z1E<8`aM&G;yZvszHyF147hOwYRxrh98I1Q<-XTw~&dygO7c<%HmoLKHQdw+=KDty4 zxfv2aL3|jD^Xkv_cXi7>U5(|HG^T`iCw@cUs$stXV8==r_HTb(wY}xKV7J)Edm;YV zL;P`p`h(k0znV)E0(N}pX|bD8M8tI8tuL2CN^cSpO3I*k^*u?JGFCy_aq5y#u=!@r zf=^b3MW$9by!e?RN7zZVan5*hV!!`cS%d-rmj?&#k$F1u2AWC0V$*SGrs9zLtj zjn8!5>-aaE|9A2LZSwz&_lx>}FgkdO|9_On=>L3j-PHr+ojth^$b9yBfy~DZexO3R zCZ3=|m2G@M2jioHH%Pv@vp*scfR*l(k#L{5exnERrHmT-QbvAXO1YC)um0=w^@o?QUcP;G`SZK?KV4j% zoqrsa*r^P^K>I(xAF3hk#s%6nrpjh!{zJHD5DP4W1uHIc!{ng zMyUn)-TeSa{rn#chT~!J{KvumQ~cMXJX_m;XX@g( zhp_(46=U~d`zc^sT7LGucz3q@ikIyD4y-<#DrK9`{@TFevk-iq61;?DeWC99o4f#X zYY#+U0a)5_F&EUx>V<8V=P+Z*YaCzSGgy`G`XavszKTVPgfDcnGyv}Rnt|}3P#zCY zp$07!nW@y8z8H~{vItMy6y(Vp;@*gf5X$wPvScefQnr-;-T9+R-ljGq5Y6zl>2uCad{Il1jEP$o8CjvzrA^~{$J!R2G`+gEH@}U}tXF2mw+?lx^`9gC zEUm=!(6XqMJ=I7(7FjoSm#YHM0pd>SJkO~G#8g)IPUnmSL>@bqa%w$ysqGObwoJ`o z(f~&26zSV60VrKJQxI?V{}(F*ek>y^5A2D&*q zl_&}lSmg{c{DRdpqUHz5qI@4ujljx7emP=!>*A_#&mb%qOY>nB*MZyFY^@z?c~!VI zdgidDSrGZm)K0lZs*HY*nd)A5?l48^+I}w$- z%~QQmEod$h{CXMR=5-?%3g3C{OL05jmoK>_JSS*|Ker`t{@Dk%gc$%+7+j+`oH#Ex zBLVc4`NfL1g3^R8)dk{){c=?R;%qrZL{`u5sx9@yv1|$$z1`eC%^7QBQ$>kg}9W79_?9xR~hkkWZ5n$Y&fNO+O-$e^|U;osZt+%}EV&igk>lGOc0z~PXBt+&$ zNwJ17y*A(N_2+v8!=DLe=v^G3wm3Rv*>p~P9T1twkhNN(EFmJi+*-&{{7i?(x-^Y5k*8h4>H=O2}^<`a))9Uw12$3Jijm=+Ik1ACcC__iqc?# zIGq-ZrL@AODKXJ}QEdEm0>kfM1mge^g99IkD4KS&81q(8m(6-Gijtd-JQvWxY2$Pf zKCCtyOtS>F6~w0)t_ zmoIjb67BPJP}8w)Zv~|+R0PkfQsOnTO1e&e>qB`j$J^T3d3!@i4?|SoRh&##MNJ3y zorAouc%4UHclMIN*$fBy$-kUH&L=OWJeBL(v~j!;w(5Hr&-JcY)z?XtG^v7C$>JS% zs5T8oRW~T2T;iV0R;(k`rr22eEl~l1usM?M-t-Y={YpXV0Hdq3cM)|8a zlz|5KZI+ivL$fJG`rs-wBGa6?SH@;px*PV^vSv$ZQzvg^(>|G#3zMV1z4ui;hx|L# z_p~{-(f@NLmuPqK0&P0~xnI2hb8vWg(0}s(JjNsZKkpICNUSbf5=&0Oy3*&P?r?DZ zK8<}j#TCBgzEBh9T+FD+3+YwOzx(H5*O`Z%x`|kbx;J@w+=k_JtB%C4xcQ+Eb|MtJ zuy*ZfDw1F9Xs68EM2Z>VDbomY@@hBK|F-{1|F`{r+9v*iOUCL5S%N4RAu_6R6V2QX z7ii{2xAPipJy^TOT#!6bAgIFOg(BfL1msFz*LNIn2Ie(d(*okZf*B^1RR_6S0Pn>& z{;%+q<-b0wOnXA~!#iC3sGbe-e{^_QJpXmrA3yp3ALa2$aFh5!j(qQ@&^)r7{v}eEA0jzUU3_I0Kz+Ydc zk!{&>n^yGj1=z{MB6*?bmEoPDydOs4TX88=DD9H8BJxZlUkbL&N%{ipNbMsF?aDC2 zN|<#^Dm#aiP@Vo`IL=`BLXgY#%V%%=m3KW0i05kOKu+I9l3a6$QIcF|DQK?-ZO}GJ z9NKof?Yu@i@0S%(&O7FYk{9^Ql(cO_^YVqaT#=Av0i=2@q=N<7o(wPQ>gY!F*@iNG z>^ZZeL_oQi%;aGA$gvX(2;Bls4ST88yO;~bnP7b{2ux-$_MDjP{ z-9M^qDD^kuYv$bNZ*%Qe^HoXFcGW7|Nor>hv&XG0J((LVQ)-M>Cb$FUem3K&DsZV7 zPVF5mj;+NM1*z)+^1LJpDkf8EQhYfg(Fa(?UzY%PI-S<`$zdeWLM+oZd$y$zE|Nr% za-pb3OlKmgyX)i#8^{)7TFYcE4T|S%Qe+R=s(f%I}pYp#x z%Hy;D5n)d9b{*|vPSP|Eb}`b#O^1aD`!R_^C)2SN$5U0ZHEM@Nv>PZ5;wOaI1rB~fYe|S-0ZT3z!SOu5U%*i; z9O5-v*FhwB1sQ4z^2=jnCx3b#`q`lW?<4)w#{BPtgK_Ep@2C4;ALr5gKLn!{0$iN- zW>778IRoGs4j@ASQLf^b}c=S20cP06xMQ-#zd;&ZP?xIGz% zzvstq|1BUl04>+qL&pE~$HP+o_woKy{@+J=#2s6w@|>1^ltP}=05BklmF%fXK_Dk`9gQxpHALWsE>_t&>1AfY;NcqUrjbDlMgN7*X zR!)6y#!pPGPUNS(lu&e7p4&R8jII^Cd`qvM_J|)X9H! zg5b^`z)kYMU-thU>_6rId6dVt|I~Tq?My$t$H6C`&VM5Kr{;*S_^!_PR&JYkPOjKu zrhCePbWhS$%XhKMlNL@qudHOD$)#c#u<+17#Ta$Ou#2IBy^J+s5io}}xa^{JEpl64+D|I6s`uxS5}NByVxk4Jfg zoO<;+h3bxNag-yO$@DFp4JyTxEm*8j0h#~ktsO;CJf&iVdVDNoO>$y7JfL2H9dj1f z^I0z&SVW4H3$NWLl&>Osgo(~5@ZgoSvT7W?HSivuv;7k}dAMK+t^&!F9D`>pWS zsmPcEpuu34MbR4klEDbiFjo|5Dh8z6`WZ>+qCDem@WG*AiUOEX1Zc8EVgV6n6@=~@i&%eNQ2ERN^mg5KS3>ud&y)BqBQy2F_&ZV>OVx(j}a zKt?&96hMKz!nU4e@*p9LZQ|OvBG2_MatOXxH+I|;ua&@+`K?r>z;n8HoB2*257*U; z^(xzQ(2iwDPLW%;1m?K+t$129_Ue$FV;U4rgDFh>Wl9aWmGVUJB5K`*(e!kgSt80g zD62J_i9pRni^aJ-RJJ2$Z^7nj&d5^2I@=%|m7QDg6<8g$B#!z!w@e92BN1Q!|JtB^ z)!tsd=w21Yx-wZ$f*{Fa#zg{`AoV?=PMx=f*=xCN-GW`26wDbt&8sCRK`DfAw+d?P zCY3C)uE|kk&Qml5ROv8rPRJ%HBGDQIkTZp560I|nn2{uk5D}?XHZh1PeYs9Ojuh)Y zQdLgH&4(zBlJ(MT#THyaFH4`lxCwiz0YkJ*Vu~u@imw-FYp|3-hGtnL0Q(?cr~*FN zotk5{3_!4g5e`AI&7Hr}-F6j5KB-)(p!vAAB~Si8(C&)=n)5GhF#9EpH>tc|!Z@F$ zxfJMfDbQ#l*dkG$ySbZ$(Dq-Q{ZA3g?tc68X8+G%Sjzu6+JB1wdX&e*vSQe+$nV~_ z;0+>kIS-;FfRR#xDo{c%9aOeQ`Atb)3cl^-fd~aY*XJv{z-sCwW62!Fi13-0CX~$y zqQ68Sg_PbTB&6c}I6@%`>tKf{MRADY0E?3;8cY|*{}A4kx>gAaF}+iR0z#vObzIDGQ|KguJl+dGMO zzumJc<>0jz2?~_6l2s7%8<9d4dRbd5qlkE_>?BLf@)f_VSxkVx5_+RKbGK?%M( zz9E>QB35>D4k!~7+6C?WXpP3kX~}1KwgjBsw?GsGX%e2~!6dISWio-7`(BbhKQ3#3 zdx-;PQtITT)SW`+yk@Bx3t%4R>H#emPI8c~O8JRgjT4OHM9@}r%-^!N1s^76Jl*mR zsa2c16?B!GC=N;Gs}eQk>qdmM))r9?zlxR?;KpQ(;IvG|QnN+yH8iv;gSOtnbIBON zsh5g*O)ryrKfBcR7TK24unFr{x73XEd3`@4`|+u3x9OO`3jTI6+Au&xZZCeR8kUFQ zeJ}iN$D!#=@HSQ}R6Mi5X;#r%X0gg;N`47MPG@mpiM&ikQCLo7M9MV%Qoa}vGqkL@ z=ti_r_5eG%KO#(-a4+uYTlcJ^e7kP;36ZaWp=CFAZql=zv*qt!%E=dO5vO`7>&wm* z_t#w-hG>O1lWzl&EFc@`BTN3yDU`E}M}1nC6&YZj)4sXBv~Mc0r92{qr5>isR8zxXHE+Z zhSnKa6@Zx!r_M}fD=Qq&Z>6kk;JMz$BPdZH9WtMmH7hxXpYX&K(V zh*AaCBSy;&ZYM%>$j!y)D?vwb=om+6jzS=k+F`clD+TnKftv-2ZF?50&;d)bI-BLP z_NlDhwE&lPS3P!awY(`p7CC(t=yoxTzCmqqd(XKB@rnj864Rjs%i?uGF$z}*&@4?O zv_vt3(GMiaQVLiC#NOpXX7`rm;>l#)pk`P|OhF!)*0HHHTww4=P4FO~Q-9V0)n50LE`IWOp=z8*R-=!0P&49nLJ+#W@7X#R)u51VG1F6QF^h2Lld2K~cI+=65| z#j%VGlHOq$MHRfQ)xOQmG)r@i3z9g1%w=(B&@J*=nAXhMGH-x(8M(HNN2g>Ns_>Xx z8|l2fjvFH(%%d_Is3;q}voYXPQ@>NIG4K6myU{fwDOr_`NKIf1Zk-uvZb-B=86~S- z&sYk8wx^pgx`jW*y&ti9oVHGdG+1d+m}}t zuik$=JAGAF*QYQ&2}6&<4Km7-W#wlf`zpVN>liL^Q2AXq{gNbUUE3Akb>kJE^Va)BQ7nCjPydWQwf`1zmO(>g%nYX6&L-q7IF3U_Bf}v#&)ALGzf`%+;XtH zR#N6gLfKn+blJhdm03z=w2Kn7oCdny-n6G;m8F@BNyp4ouN}ctz|w)Cg`n_Q3Y)#qQTqgDk$?uCA=TcH-O`udJfsbO#t7eh@B&{#Nr}NdLdv{0CJ1A zH`Of(YmGr|BRQItYWew%2}4e|f``-g@6@58}(_;ml%qdelA%jE*oJjJQF9G(J5 zMcC&w%8)#xGfRkgvrMwsmipiy$rP{!6iz~t#jPotB}AW-6UhZ4=`OChHP8yAav9D_ z%qU!A&Q5aKA3CGLxs_MaD&!5v+P!D6Y?F(wRqa)GiUztYZhRE#r>hcck8AG8H;%7D zK`9-2w3hpYE-8W-Us8Uq7L?9DvGy(xK}w? zBsVeWyaxy4qshVe2=rEI+|w=m8weK5B;?=c|L?~A27dh&$Uez3Gl=zNma8;YS)%vE zsq=M`@qv$dKi__Tu^NGs)7SL>6P=W#lqvD}47}O{&ljn1K^7U@!j?0ik^^7A%DY$6 zWmifhd6^2;8C?o}sK&Yse*=jsT=@^-2NO; zz5O>B9E=P3zlQz&(Nq4%M|r-;GlG}gu7fxRX1Mhcz!2cLc(UC(C|GUBad4*^nzZ69 z!La%MATfP&yQEk_e95z8xi!wSC^}Cf9IPFiMttk0=3}nd9m7B=caNr5l1ck9sW941 z(_HfL)*Q*>Tuu4qOO1iCX$h{~kQz<&nGtwG=G1XVLis|};(vQhA5qBN6T4-f?$jd( zr@TAAJ!0kuV=f0VrkIAZ5Xa6Z@us40#ekY>J9!HmwA4z3XDC<)+EHeH-W@XIMrthA za7#ofpJGPmS|8u!-zL`RY!BR;o*wYl%=Y=vP`sKrhRFGcvzKZH3b(a8ZfY31yp)>} zFo*Er;??`BI|I2hfHx->KWzpfiq*onx_EVYM>yv{)byriVO|05hxhM3oYztK79j5f znosZ+_Yeqz;k!6mzfTgz&33w`3@sh0T&lvC!*7$AR{g)gH9{;fm^J{he~yQ>lr!AJ1N%om_o9yEyyq^{cCwuRflgzPc#1vr2H7H)RRe z0+g5U&py6-e|36te)8Sf>$A(V5+oQ!9-IxF%m1kysmuQB1%p#%93=;wm<5z zY=!|ZIVlc=Vp4gV<4+V3aU*qCs=6F?Z&iEZsEUEU z9JzqF{eBbTcG+zacj|6NyeJkcr{GaFlb2XlF$#)TB2ds}66;KY$cAm$@`)iUK@aiw1iV#4I7erzCv$keeUkZxpXIub20W)kk-` z0w@Nwn5YBHtDJuv?#b(TnZ{;T;N{a!1(&+5Y~)UtxL$!)k&BR{->kn4{Si*%B5X?! zLg~tb+!LY#GrKA)n}6{oY?|`L2{{zok(>ily2s~bwpyuLht(lXk}2|IZQ@#c-?o5E z9wYY(FG+^po?L*7)05Y)fX+D;0ui4d&l1^5Ub4Ig!?kw{IB`t*N4;y;7I|z%pl`{< z{nc!%iK2EWRu0HS)#k4%wuAh8N6&A+Y4rPaK5z8@E)vR8$b!W~`G5O^gM;G!e}Dh! z{@2HO9(n)&^4-gK6A+>ZF$BUSxJCp7$udnSl5a&S)i^)^{}*360KKOLFl!P#V7S$F zIGfkM`Bpb08QN<9cn8om4Oj#^H(*A)I8GRzt-DM3`6{D`T;1?)A^PHAI2s-unQhKC zA|xSzA|`g3Rkijm_`m;mBS?K81buNZ7&e5c_F6xK9;bCLqeOH`4sk~haRFA81lJsv zTdD%&?ZJ8VW5?M7wUKVwrUC!Z$tdaQ51xA7I{fADQ{+3(M){v6;axKTZrK0pkNU;@ zuZM$C|4IHo#v}LtT9*rv9!*MCETnMt{$ID%Xag`!LOcJT3@5^W2t#B}UPF9NMn(y9J9RzcmAvh5LBS@*fe5drX`L+rT7AVXjL^Let zMRPdz`G&7wTh`C*VCaRl{=2reeYQBJ`F4=`;V5vYh`TVY=!FI6G|DJLqc3Ye`BJ#{cFySZuY>I~bM-4aTk$olpmOm6BL5L_O_J z!hTgAsiUujuZHG2%dPE<9Euxp49Zc*d3)+Egfh_5riq6_F94KD9z5TyHheBnHQmz) z?C7nc5{zBpJlv#sOS&fKh7akSzz})4A(P)KxS{;@mfTPVbQf+YL;KCRp^Qq-4IVVN z=7tiCTXKV$N46*~%zWq5t*5;MzyalTHLr8VQ&QX{QEziQ zIB%!%8s;RzkV<3J`g!-YUz~)z9cj#~?7WHE8>c8&}l_hBsCG+(~N)QZB zlbA9Bu{s7&`SCv5jS$Hb{#ie_g#8Eb&OQ9o!2d_s9q$0ywEuHBD&GHkcrbjr|MgKG zvHx=}@{bsYpT6hNariZG_laF@E3cr*WE8pSo&4w93wKYNvrq1ok*>N-RUQ_VL8V3& zijs~NEESe8*jW|cuHuMR|?dF>wIYgD;`ro;cNlw7LQ&+~p*ofW-! zZj!_l3FIEEumV`VHv1Cfw~F-5QhWJlBV{Pz9eMuH$AiL{fZ^F$vKO9a;i zmvzI!LMAu#D2Rx#L+Cmc-NNxjiWjj(m;>v9r+EwTXL@8j0`hV`St7I+y>Zl1nFqXq zWYK_A?E1?(FeN)a%?KkQDZBO}l^6YDJnejUb931d`MTBLuj?M%oQd`_3q<{T0&dPO zE7>Z=Q%-o5plbOXH_(#WvJ{x>?_KMExBM4*AP-UiyUzcQ#(i7UDAHr43V8-RczRgv=~s zG!>BXp7NK=jg{W0IukLZv>;bDD`O)BrT z7E&j_mQg7O(d3m z#h!o}ULmq(PLj*d_XL`jck^tRrN{LU_w*y`|9l+%ztjFRGpAZwfjjKKe&7x5`cK~2 z|6>1rijQzn-^$SFmI#3Jo=<0jy6x`oe;tq+>z2j2i2z!%IEu0%C*Kra>akda0@I-# zP(Z(!r3IgAw^7#UlZecl;cGDIip?5I2}5xT!H8MP_63A3pnDZ)W%7lcQ!2mxG(jea zPPcO?V*yr`6|2HZapXl-PcM;VP+h94Vpd)0?btvtVCa*vvVs2A6pCaZBPm>nK(B0Q z|GERJOSsyKy_hXEw+pK3j|?(2U&j=&&Xz5|yRdXr$z5<#&4#;><%d&CL!)hsyO32% zl9%49Yfzm@VquA<#k#6Y8vfilaWqcb78h?h=S}tLu3_3TP+y|=kMr46|34@Iv_t<7 zhU2k){=*x6IsfrVJ|h0JTmSDB3(EIht@yPTh^D4@8vwaSRs8G-b(>PM5Zkt9H{nPH zZm=ZxDwai=)c2S&oGgT(FN?Y3zkt*D9&RW|Gc-pTfC(r!$MgIk z4Mi-!{mUlvn{6n&cEqG>6Y-iYQFf0h0+I|y#Asi>J(Hn&3$4u|Z}a*NWf_iY3kis0 z@*;@fdP$fn)wqnoUvAO;naYbj_81i>zQby9g2diessslfgCNTgb>X%3%n}*23;CaUig=E(yh)+sW7gUN9kfc><{W3`^`(C;m0vAedM2n9 zitxG;DJ(Yga&R5lvQuL{Z^uCKztKy)!uGCSEt0%(9Uk#jw>`1gt%+z3sy#`v>UxpA znIDbr9J-pwL(QGi6*qq(vwxwGY5{4B)30l79xEW1X&CI5c4>)o>DS)DgZw|q~c{5|8RlWIk> zT>yD6=Wc-ba$-!!nmm?~+ce&~FsZYVQl1Te?T{=G5Xb`E`PT;%H1(e@94>D9p)~d8~RHOqZLj-cg}P8Q&wImG|@KOX}qWst4u zf8|gk0%(j-3i|rDh$N`4vhBtE6=9bdq9|c?`lWULk3;_dOXMRr*8w}^|B%akOa70) z-2d@uJ~i@R*X^MIf(#}RSph8^#4d!^5147ohyoa9gi^3hBQc3kgc;Rw1(7z`R5$!f zRdp^>VHR9aa(5>8#P7O)zUvfcw}dg@Q6M@%=gI8QEZyz_Oz~UJ2uV)BoquqPxrmX6 z&<|FK!3Z+QWsAH;+(>P)LIC=f@ftB!Ba8)C(Jal-9VTm;CrilfIt86OzXLjw0E<7G z!mwac0P5%^|EFkn2`N<>Qu;?Ol*&I#c68vuprA;cQjop@Pl1fF8O?h9{hWkcZ*;&R z_yA_3L4-o%GQR@bMbDrlESE}iGge@$d$Xiw*IBIkB2TyZB|bSm{`1|*pYQ(9pYOT~%SjM; zBeCUbFEI808;UYn&`l9tUaO9`&LM*{NDqt=5)PZRn7vEqLNuV0D(4Zh@meUi^-7XQn2L;Luj1W_OVtI;fy-bbLA4FmSzsO(tW%@WFj!~yMGG8z2kRb)#}%yGV}x5`b4BYO9b>gjN{3nL&9`&<_|EFvFwhjR9ivRUTmH1!af2sfVNj`hU|BC9)j}ro{ zREuuxF)Sh()9Ap+vh~5l#H;18^$P)~UUArX%8RAYJ^7X@+35 z0o^yCmT%+FT#@|t8|W_O@ew(ozy0=KMl22dmk6VE{)6IZf7DMS`QI`CxI_Mr{L#pg z|9yY_CI9b}d_J%EUr8~v4gp%qVNdPwDFcCz5d+*W{Fg31M)1#2p}XRLihzBgsXw=Y ztwFvcbmt(q0?kI=0BjxItpkI3pVc;T@xMJXxRXzfwMBTafNlDp#;?Oc&@XwQ+s%jV zerWBxdqv;638|!&X%L?`<#p+f`}Vp!@$q-yWoHm>t2BR{NZ~#ZU6D_#)9a_o<8{~` z!9~M4GdOD*Vypv}nxJwa(EwD#7^6Kr?J(^dX?z@Pu6QG#6CV+!E9m%f(AGyDKRe;y znlGUq>Y4kavgQc1epD&;CFc4E`t0HVXDGt$o&P=RfBSx5$A1U?FZCZk$>;O(|HV{$ zi0dx^)O!6A^zY^H3+xZ~`3o>R-2P~GA)MBeZ}R&QI$p=>4Dqj#Hu^}x0ReWK17B{i z!^y5fYvWeepxovz@9=j8G}9!IKa7I$v}6q!-MqsF$Oo)_@&d>1S`UxoH*E#Bho>Um zS72KDC$dMI`4a}&jp6U>MLYzD%Xio{psf(OJcb6yz8H1?L7!UtZ_RK_kAGHo#o-5D z|FU!cXVkCU|26n>|I4TOi2C1mcy%Icz~LBiLH^B(cT2cLC$bo%xXJ3^3bA#T00=0V zGmwx7o$8wfg;6K&b3CZIbKjUq{4Lt!0P<^8ZqcR#I^Vv2-6`%zc`EM6>O4EW>hOR6 z(NQ;~xU5JAhOW3mAI(vgq3C>_;bd_wZ^6gO;$o4I{O9NIQMeXmqz?e-ssf!T36b8J zUqKcwpTAEtB(K>vckIPso?m|jz0w7#{6kW1N|WpaTqMTNl1=llkXb>xCm)v~aXg}E zT1kPIUpK1F-6OnMvJ>E!M6@-IOPECu8b=P`GmH+^A^n;l&$i!MSq~N z+%kF(7`S}Q_+syXj$ADtWdzNe090LdRk%{%Gz&uRCpCHoK%-EgE^{d6OB1N_jS|$F zd(`SAU`it0|Hu6AgyH7nk&?)ghap*|BtZ$w#{#`)8T_74+LzkVR3@JNL{!gY=snBp z6z?%k1_`;tofA=VAv>T~JjmNth%jCeJRO26q3uO;(d&Fs>xCy=@baCxx!9H{WpUO@ z;a=&x_g1CuRlRs<`18I8Diw?KYR9XTZH!Jkw43JEHcZpr?Rti?1TjQ=m>lOXoycmd zMF&^V)!xmcifrGa%@O#MSheCVfJ%qk6sg<1RcU_lUadH)AWn2Vq9ixDJX5_^6S=5B z))xf-or~LYhj15#<7lYI9&a_4wA$~p8Vj}e=~iQN1>3D(b&t2^Ccsr*eA|M1_;RaR zY%Q1C-V4n_SzTlem)JfFY|D~*wAJ)!Obvgx*ly&S8N$X~p`;KFLffB66y zxfWMs=Pip%AWnqxurLWgTRjKfc}1^*HRaIxk5uWk2!*B z`k#~V7G*#j`~X*Ifho&2YWolf#SETCD9um^8H!H8nj%mhBzYDx!| zEYrB(-9a_<{NBochyGVq`p4G)-Y~H5e;*CUU+TYnl1~Hu|M%R90F=Qb;!d}mBF?F= zW{_@fl>2ffP}E8e!%4kT)n4 zuyJ!vy&GU&L{&HgV5^?BaCLR6!k^RwK_oXNL9cWbnEA9YD9M_oYo^kwx<*3T)7<1O z5ov-cuFKcCR3#+V^?^^(FQC)ylp9s9Ay)K!13Lfg{Ik=kUh}6RU7wx4eBS-Xx7QX# zV8qDE5Q|(8{JyJR>55(ySKR?+1(uUT4yzP6z`L2Z?`g|x&l)etE4zfPt{_@bnK}Tx zc@30~EBK=NPcaJ2q0`K(N$TXK;CJ^MH8^uO>;2ghW=tI#2ek+uG+tY9EAH+2S=*|< zBX)GfwpZ)sgSs2f0mka8Lw7?e)&y{`smE9W_ASL_0Z^K|EoXa8xbVRS$2R@X(pb7& z53~Sw+5aPNZ0rAE_{IMJB%en5pF6NrUW>Oz@}^qu14En?E_v_Z4TTGIQfCbm6G}S6 zg+U;Gt~Uk5PkTGtRTP#$;p|;dzUnfZEIKMd!`_KuX{?{f9rd%?h7|Ne0NW&MAOPlNUUgPaZk&d8dn&~--QScI_Q zV%x&cXOe1v0~cGu|5t>tZEL(1nrWhoEn+(Y`~hTWf!=?MlL&OW*+2go{jWcLpi9^v zj!xwDxj&p#x8JJ*zrEvf$6*5lDq;z;P?lh~+)rEF;Mx z-hd2o^0`oo03!h25gb)}kpe8XUo#S|LxxELP;!SelB`g|dI$dtCvyUpjHUGC_&6dV z?aeSt;0pIbvN~4M7-jT$N$$Ih9Iu7UW-y7m3QLz`=^8D~;QQwxl)ijE*+!am@eGU+GKiX$|MiBlf2Jr_NV(zHa$fCbh6KC zRC zK7k~na}rW5Tb|)8dImGZr3w_A78#zcx#`E{?`*vg*u2Sps!(I|Cf=bX(=)UpcL=;A z**ob*6YbQ(Y_VRUM9MCI)Nt~SwoG1^#n#?nE03dTu6gYQfj4NzuQ%AjuhU*@%dc&% znf&IS$hQbGF`eR=+=CU#5V(AEaen;f;#_Phi2w@SB%uswyx`AXT%1exgJxEZ7fjvk zyX?4@W}Igax3`u3*?N_V?79@PaH&SUD^5{S1XPL9yqo9}W+(zURo$?kd?~siaCL*{ z=mxJ{H%xl|xGb~1az6ytI)8Tc{Pgb^uU-HdIRW4ERWIxnl-zaiU`7F1Gm0Yw$ejNM zD3bAf(Gh#v+<8a%UVTSMx@&quK4{$)hOa3hZR-o}X5ah+%n(i%;9hNa$UU2g`!&j} z;gd#*N6aY5D=bhj&&W!4UWQf>i(RJEG^Mhyyk>gO^Bj6lGUn>5R>D%e>05nOh|7Mr zKWQT_{b@5r#M^J-xlUfn2d#PbES`On=b<$}LXu@DWPDOc@c=|IH%oK~zDN5RTshyP z!4|&jB!qm>lJ8MvtUZ(OK}A-^B)qLdbJd!LECIquV!@&>SgFkW&{;2if4^96_LNb~4 zD|SK@0k~!)#>p+`nxtI%GXik3$PlHH=YFF=7H{w5d06Yk$Oo-?4oW-^4M(Qm^;?B_ z{K>SDK*D7bu-+yZXEJ)*jhdg z%#fFaWcFv{9UaN@py3=EOb=@XaU!%UhB3eiVR*h#{)_C`W{PJrbSs`gZCFk|Xx*`8 z#WOG>bA7`aZ`QFvLxB{y1=7H!cm}N%&%jbV14Hrn-N0|mvw9#htOWo4h6}ata787t zF8{`~F5+4JiY(77Wx>ZpiR zLcoj5Hvm%rDa8x!q=_E!8!k29Ev^SH6*XwBq6U_V8W<|dZ@Js#k0;Gm!FaN56*yGX zptXt`SSo5@s3^bNxBYPCXMq)_4BjGpmFW1TKC7$LdcR3rd8`EjU-L2DHe zSSn&*sE86jhUC^na|SdsG({nv<4|yNwu_O#C6a^IA~~=`a$tyL-*9}IO~!`K?|6&z z8@NPr&{`x1mPigtBDvpOBnzI0%^ckE(Cy#`E-@Um7Q=xhhJ%tA_NVQ59yH{6u#IPj zpbc6J+Q1UDK}pcI<+osYl$6L5<4hK>~_1T{7Y_rffZ!bJ3^j-wk%nNq8{^N)QSg+v(^xW1>-?ixatruP2T6F#LqO0_w zJbxW;_=I1lKvbaX!fcTz=PITfP8`oYar&;s(r>+3`qpCUmlsRl5&#hij3RL$i_bCHMs&z%&m=b8AtT=%ZtJ^NQor>|@+%$U)pv-o zl5TGP`v_d$oL{^WU2t*vEnHzfF-r5G;hOT?+X?mikMcoFwmmbmNJ6sNt|i5*&DxO< zT9Z%8ZblP#;Kp+qvtDas*0YRRuVl=&<#{}A#`Ac*g=dE`>$Ns! zJa|v@o~2g3l3MlJ1r0`nhCC0p@$As5UTdxDSxUq!Y1NkD!cnvQ9o~Km z&khaJI(K8*>yIs-l?LJJquZa>DNd~*xrqReK!y@>$NND*XLuH)BUP$VmwJ*t(Qhc& z`cA>d$*%1Q{-AYFlyoVFWcEZm2V~?oRA9bSfpG#|JhxQZ(_VjQ@jNnlZn?_6hU4sw z_uk1FHrxRnx_3Z1^RE7EX%I|%{ejh=L$g2I83eT3QOzUf;9&!#De*oux2r zb}ECn-@R_;2+u{DCKET}gLM{vO~tC$ht>3Dtxk68jv>hh4?1fwwpf~&EIBtLDjULL_!_GE zp|?d$`!18tZ*9`~mPzNECY@)CX_jqNSrG^*5_eXi!n$2#WSxou%rD;E0G2_VI2m%; zYkq5c&A03|e^kqmd+_+E4JOSN-C(k9(YcJMJuTllCM_e%H;pKFdXdHCxLMeGFm{Hm zr}d|}<%0(;MSFSpa3L0I)bl1NR5aa`<;n@Q@7fSa?kD@kp` z5Wrv{&$Y>`v+Lo*41sb@jJt!sfG|cdS*P+MZ7de9ye=SIXP9k3${kb)W|---8IoUd z6p3Ycu|Szlz}M#qT|?09OcHNzdOQ}ehKXB)!E_t2W_IOZ5NrX~(19QH$J>B4q^w_} zOpR4Zev4Tcp_GckBz)Q}mZ3bSmXQ0NbI!ZW!*-|G^Tlns2)=0|)~umNoLP_3D=q`F z-J$oqS1d=uH;qUUVyh>|W!km2>@34>YLihOoaW-^`(rpWqO*H zr?-dY*<+-wmA6pU0504hCJuS!>(OGR=ktgMEA71IG7oLsf<) zuy)FzIzhEXs2;m^4eY3ntD)yQyQ(YT9<)*IZMqcJQpDzLWCc zRSy8>)Q4-z$g0>!lvl`bHK916JvDp{1=H9mm|UlRTOazh&iszI51&p&7t_|vN0-T1 z-@_CvVG_k^K$S`nebDgKSl~W2<~jk~`T+2#oE7+S*g2vOP5_+f(+`z=^V&(u~ZwPZz_D=mCaTh^*y?{5^uV zCeNQV&Zmbie>O|7h4YM|W6O!o%Lk?9195X}K+bnx>NPhDQMc_fdeMLzNEOs#2@S z#IU4F-D#=Tz2AOys?{_Tk(_#@u|ueq16m!ASIM7GDLrgK}HAzDWvqCWRZ)9dPUy4NQG6SVpvk- z`);}Q$IUF2{@7`$xJpvAu1H}Oq!^YIc}*>WYv~zp@`FY4f>7={AC+usWonDfGktTI z=!{7-q0paf5eoH6zjdh!t5U_Vr1Wb#L!6Y0BFr#JU<_c4A*D#_eGx*)iw-SIeIxs! znNsLaoN-%MjfvJJCI)stc(whYS1wMNxJ5<9P0;1rGdcYH+vdB=a>tk*AIE^Ab{3`6g`IHqgUlJHSgE34(lz~&;FN*zUCSczkDGgkS zO+o9#roc*U3e3bNzw7N8FYJ$+1w{KJXFxP?r8@;J)1AbdV~fd&$>g3JPW^_dnSFO^ zX5h+k3R>ql1y+tzVCFcPOzIT1!kqz0M3~r$^u_At#zvG-lFAUNaRjtKYGxMoM^48z zaAidWt+S#6D=R86v!c8$HzKI}pNgcpc1-b15tFrE)avNsy;K=#Wy z728if^@D~>D%iH9>TT?xb#7K*DLtHkz1}UOBb~YYh5N58rHAS9!4r5Nr1d;RrFB9Py%QL{ zQ*?RNGTXLBEh8qRG z+$gAv(96-1x7=Zph)oFw8Je%-m?GvJje3JWXn9SDc+Fey%&8((hVqI0o<$X zgE9ibC5|ImQr{6r4qUlYLCf4J@ut1-{CZ}TZN?Q^esQ;6R8qfHnBvx|95q$Wi7mx8 z3Iz*%hZ4D!RM0jf%1Xu$jEpG7MLiiVE3&l_Y1xqD+Rn_E zoDLZn+H9T0>WGIv?&&u?`0Be4z6Op+XwWtiYL(LpdZxkXKEC5Fisv_s`1|gNzpLn0 z>zZ3u$*rJgnr!ZKJC@#T7(e&jsaUQGTdfOhS@pGoo@uIy)A;pdxXhx~R*_{C1^bcV zvIp9m17$M$`;p<)m2PyL6!(a1 zr^9pkbzW<~&a?bF&+zNKsZ8*7kW#;1yw*;QXE`;V;neIPrG9w4)+V=CHn}~+J3+~t>NmG4Og!)TsavdCmHpItJl_Wwd!Aah2grL zjCymjb@40D9+c63WYpV1t!pz`rJ20K4&r3Eya`u*q?YB8@_9Na(-Q1Qi%X8Q7b9gd z`umYluW4GB7P2Y}d4;CgPKHaAJ>&?MZ_g5MH!WjMa@}l|586;Ow)CEaWRT+9m%Xmw zEdnBI-wsw##HcvjDbHw=`$QbwG;;T+(?PNXbQ; zHrs!my0)LkE_FU`t9?&4TGl}#0~*jGeG9*N_{6wb&_D* z+Nc?qjheA-)Koa)@5hLtc%v^OTPJIZqMSPszt2}3O2lPVr51CN@&0geSZ6Ga+Zs#b zvVk(T?4$~NiYF2~a?8yd*CZRN-7yU_oYu$3#}0dE+}7S1m+hUgW$)Asn%t&z@(bzJK9OX&HTMjZ>MZoxrgEASzZQZ714@?rm#BrgQm@+xT#qksQ zRW4&Ljna&Sh*DKYTV2!^nP(8D&2A%~x-KIhJ8Z^rTbprQwi(Bk&A4Z9aM~qAmO60)uC1PHcPd5pJ@39)aM%jK- zSF+#OVQP=tn%ewD%Wx>!4b=n}A>~97cp1Q6u4l$|7QCZhe0O#QRyfPl&<-0No|z6O zj%$6RbsFQ4PaQ3ZLX|@(j^bGsovZs?W=VUiq}+Wao5ZsxX>n7je8uWIvd*~aS-KxY zynlt}P#(7Xi`v>&ZWvG;p^!5n$D>ht$kcU_)!5Dv*?Uwl3*Cr*2c)z z$titBk}E>QSQIkIPIqPcV5P`hwg#q|gWy+V{_ z>yXK!7h ziXs`~yywS=WSCg zANa%ZVCav(^8CKnAASYAk3o$6SyKkHue=B2vYGpXe4c;{bxeXQ!-Iow*NMynjPWdk z*+y70H`yAUsSLVZ4X&{`W&>g(0z%vfDxS()-MRWz-{(YFA`no#!ZFN13K>ILas=2C z(;UY=q+qtju~5w!5{Eig5GM>JkfRF;WnhNbJwl1JyCirKt>UJcQu-|002nSYy5l4+ z2#h(6^5XjQtN-qC*$J-Xg;HEt(u0G)uV*Mr5JU6?y!+cXzPR|g>%9|A&kgNyaPR?K zp_EX}NVWkVfJoN+0N$dEdjsIZ!H2H#`B3_g|0N(^D8-?S1(S$&36~q;Ox88s~d1}4PL#z0pCAAeRTtFUV~@P!NsfVo70ys zpPz&Ci>v2nH!uHNV7!*+VGjdx55$l@s~9YZ@YYnFtAwT2+=|n6!O1E zvc>TVCTkcU|G(mmYyQTc``!!j&avlrPooGYi*7L&jt{{cXO#60y5Jfi!S0Vg;9Km% zaCp!KX9a2Jn1&>aiq?_*p|@BZv$yo}=DQzmSjJy^ouULl@S{*rO;lNe?vKMIAru`R zbi3Vy(>MlKc(G)Zo0cfMLlNkLoAMM_Ny2{+4XEV*62+^o3LQMU64)yLeQ)3o$CmsL zg1-Mn{(p)Omtiu`m`j%KTQLO=4vhJXDM&NCf*FoCLI_7(2n&O9Bj)|9(`%KF%%ywp z;5%}U?of6F?vXk@E8D_2R`Q<$%3u<~ERt9yrXILRq}b1I`r;7qO88^u7^Zb>4vw;2JTIUu_C*@CyB# zB#1*cT-W06Q}98BYB`W!e-jYIEvXv-lTEF+OTiLl;`|?XcKO3>1297?+5^vFxU6@P z>5{DD{Hir7Vnw%T)03L1s3j4?1kB{-Nl#PFolb*JF7;=K>;Dfzi0XKh7&KL;fda}W z6O8%$U6RlqZz?YO6YymyWu2i2tdj_3asmm03Z%V|L{eU7Hhwc)TB1Um9yuLQC@=s4 z2i8^4BvB%y5{8IUFvl_CGnwr{;I|}`VN9IN$x*I$8TgUU&WMCc*>c@RLfSK2b)mJ$ zI_nC-tyGut3KivD)nUg^41y2qd!;9?4*UROOvMEHvD59sHCuL$ItfWo=O;ZQjgI8l z#2Uc~0x(;MF2xp?RisQBn#6;FJlS@&8FLkm8B%_Yh z!Ga7vM&JXO5yA)a-5kagamt^oxa2xXszX>zZJem91tTYlySjBIiUVu_O73t*5+SAT zV1_wPs%{`G(1|tY1piVFKt2wlycu8)1nr+^$aX9bFJ^!sgxvA4{(!Tt``ViUug9{6F2 z5-=ldX$%~cx7Hqse$Es@oDf+YEzMAfxG#YmqN_~WwcOLKlJ@*Pree9MU0*fu{1>|i zZnUQa(EC(u^I_p(&5&G(3Cm>`0`GA2b4KC2EyA^jlSPIo-D54n1gOSFtlXBXE;Q=+ zdJP(G$eUR5Qi08p+>`7UCyR5Ol{@*kV=7k;Q?&#_xQYA-wI)f55)`SEN~S<#!m_%U zgM=`7YD>-vn5Ob&ZQ-c(ydvv_rEsZNsc@VONg%TmzUQq>ZW6@kl90-xY@zgWP=&^0 z8Cmm*Eq+!P`R1ivFk6b{dr6`_wP6k2jbwUG;Vyx0KyN3`b4<1@Hz7ZgB+qd*l;in( zdrI*%BP#}R{0LJe2W3o^+&+rQLYmfeiN&o3!n%*iEp9$dG@^?2lA9|zDfPxmEwCnY z&Vavt&Kc0#&AA+tJ?Biwk2L3UTn*=3{$9g5*AtV%rkl^T6tX3i6J#L{cycsS*f{{* z;u@96LA|+p$pO6-Es9s~(q!)`Z#gFUgnxVaD%T~SmEoT!9(M22gY}F&PnI^E=`X0yPe_@cZNGB9S%#l3_=s>_nCZ{gAp_SQu*9a701Q@ zMlydzcblA9V&`01B-(}NQ{e68tDc*kUcL=qR@^1xIT1fBakvzdOwTR;rgm{>O7E5( zSQjo84>0hF-Y{$hIax~WVH9x_SWbW$n)5lqGSQL|iCwNN$d)}ZIg4<#wFdcWQ$Gt=zh+5g&!egAxu=5gS@FyB=7NyUK~&IIyMI zS;pN1hG9%qf=9x!DtCLY;?aeN;B^w~E5US~I)Eua30W_eHX(Ml$X4OV z^_E6%gorf96Wu+F`}S<_LK69(W659O;=Zd@B9Y5zr$-G9%|&Af3-~g4w2K z6`Z3vPPlibn}j5x;zBeAvb6~2{P<&r=06o12e|r7#^l?a%5T%SB({PERb&Qim z7v0IQ+A()$7fClIQ8ytGI)0*Ybzu^9VZv}%|DuF+oZQ(yuRHBe8f|Ij7u4@W2cDT;!@#Dg9}gJ3>}^U=hgqi7fn=3(C-4*e0F&HZrTBN(C4G?>i# zqi7ON!+tm(PJ->!2<)7qIvex#9m+DU#)R|6TWCL1J8;FS5J1+9&=AIwlYC(Rs;BVZ zxTuRF0Ks=8!~f>*#@vMhr|Lxor*KoZP7*T=$0(ZuVc;dIs?O@{+-IvVz;5PB0d31(;(^*wJ8!O>_iM`#LXqj2i` zXfPl0KL?XNsM7ODdm>w>l4|sn9`2Y>MJAzR3Y=*xw5YsqL|lYH%XMgvPdg*nuUjfx zR%+JSrm%U9ErVOM$+z#7GWuGA_*&7_E7PjXr(ThpUblU5YCPrsV`M}(^&JAWU?a$2 z4ZPwl(Lf~bCd}HmP${gDgW{dOAq7S9Jl%&_brnRF+?Vpf4$fId;uvK+x{|ADU^Y?K zZc!xlSl4`_h#f}|tw=%<+k&OmN)v9ZQF!#>7~K&*m20eeMYp%#cXlr)wYY|(4QcZ2 zefr^Hcrqk%&N&m@Ciwu~`5ecqwJ1bP<{&~8b1yR`5v{&_hbbn>cbIZX`x382h+Y8- zL}*;XzZM6CWNWaL%|R^NTQG^pPkAGfDSIi*7?!%kkgo}jbw?OXf-Cb?V7$5w16^ke zHRVyZbdS**tp=9r!H8hiws5xjmf@I2Titg8+Du z2w!!HX=TmTnDsdq9S8GH+ukVST&xh1m1dQ|FQN!%FoiQ5V}_Bn=sPfqIwwE=bkvD5 zlJdWV7&t3-sYO-;pRZ-7r5Bno$(nJeQhSUq-dylyUCx5wj~YL|}G_gkgSLuFU1k?frOC?9rCI-*)@=cpqlU+1LbcYgcns6!FV!X={lxajRdaQ^CA z@Bh-H+<4XLakBQSL<3fE12RNOe1||nV?u7%soswui9GURgik19>r~C&D4{hLuUf0; zIwOP;&^e3Ol%ecfoKe;RcrM~Ouky_gAnXCLj7m*^z-;-QY+3gfS89?Hsn(Pu{}Ly+ z)NO1WD?>vb8kc3uR5-&ONG@)iYUI|cx4LSd2PcbT6@ci%R33`rL)}#kkDthRKlg*# z66v206_0h{sP7?8>gn!*n~HgMEsnNnS#bhR55dhpPQaU+Gw|#XT%KNE|8RZ+zW()B z(7RGs4~Trs-+ucVoD~hk2PJpkW@M$l0nqE|u@Jvk)VqFolg2fC=%*rKNWEX*<~>7M z0^^H>p==IARP`_4P^2=VusV|r855~FVuL|sQpk0WHISap;^b@l9%kqSh*YTACY8m` zZznXL1e%Tvp4Pdy!WHEYa3OfKDOzlzaG^QdXa}VSF7s?LEz%^3TwZZ}i5lO;pDSx#-3NyfmSOqpF=F8{Z%IKHtYDgQvMw%p>kLu#Dt|6y?8DbCjH0eW-(^IE zrVtCef`aZnW=rvB7fQO14|7hn(5mU@ABqDdX3L`B#fGe9U*k|IbqAjRRWcF*VH;IZESNY;#SgZa zvkam+zBQk49VR4U3PYr&Dj%Q~WH=OAW@o}=rov{e^Wj*^xayQPbfPCn!aNGJ*6n+)*3o25yGh>YmtpbsIqZa8ZSyBkw{tXX(6?L z^nMb5ltqVFl3ny3uF@FwViLkw2of%2wQ{jTU}}{LbD?e_h|iTP{~p(idi0U!#W`haAl}Z-Tdtv;P?DN*V_k?&MR|i9BnzsnXi|&Xq^{&P|^@n zxv$&+t2mmwH&)SlZ>;J|QAB);v1PWE`D{9YK1Y%ZDRowgnvRt?BsHzl;Ecu92x!%I zU)j8>7c<(3)lmPyLZ-sKvU3H8>%kJ)CI>C`Y% zQ&z^9?R`GPYP{oMNU62^M99q&*${+zr!rg_%2qg$6O?2T%66Y2QI`d7WlJ3oDVpf? zkZheCiK`W46^OjWkvM*uEV#vl`EWChM@%`1ImUAoZbCa(>bG|lySQkn2ba%7Yu`>^ zM(VJ%^<(2=mFm8&YSde2bzz9G9N83W2`17{kg*wIBl1P5#O#}^m)E@Mnj#}%lQVGs ztY>1}y62o&pZPrNY-L(?@2HVW)y&c#p7^-{AzSkS~0=>CB3dVzA=6f(4 zj{397d=$W06hw2_AB_6bNjMsfC*d5;rf57IPQ%f#KN`-5-e?p|hVyVf+Ch(YAa%y? z*3l`_iQU6f0^}T@)A$~4XoWT_@7NxiGVBIpqhH*Gu!^KIJVLfGJvu{g7zKmCL(w?& zqd_o7kw1xMk?)Vkv+)Rpv(Y>Z#v|VkX5qk(f3!UemuJH^Uws-P6X>*yD-K@n8{x5B{U6IyLzuHf$xXAf^WydpM?P&j%NMPpAO+*HVDx$ z9F6BQFYJ5Mc`)&U(Xj8MSrquAXx@k8Xf&A(`oq~Y986|`w;xq{`Iq+4b}fFh@xv^{ zJ=1jZlNAPLm7(IIRv&z}X|3jOQy1u-G%>y>mIu?hLNNLv!wkJnLK*lxEn4Ow`Qikr zJQ2{74vBOah+3h-HItUiibN>)epD8}?5+)2XZeLn>NI%vKbkFP`Sx)^Racda)mvd* zj-MVn`(k@C6n8z#2~n4C&+=yVAX^A>b2Np$?gFh28J@)uuj<^-i@6B*-@`=JY!LvKo@9#;LbrJ&$S6p zNbmGy+Fy1cbVf7yP{n!j*6vXfyY-dR3aT4_5T01+EPy)xqT&{1-=bIAtbTX=SI*c3{g8j6`O8&Ggn{ z8P83oD(5-?htVyZyc#SN|J#~U)9LgD&W{yAIWT0N%MZ;=hJINi%5sisC6)`TdGTgl zs7~RM4a&tPbJ!PivD?NcLigPfh&Bma;ZVvqibHzGHAgm_2n z2#C@>I#r~G19$hYXRZbLMg_G(lKe|o!V>YmcO{YduBYZ8w__oo>seO>X0fP^AWwkn z*lkoS>AXTHW>l8vbWm8$u}bekom^EF<)V2dyXvI482w27`Q7CaNbkZUfL1Bnoa5|B z1;UPs+|#3?%qiFRaxc4{&J|4c=7Y~-!|8u0L$&~D%T=(O0|O~J<&u42-3)gbRPG2|?B%nAeAf5e0^`T2w+(USl; zROdk{Ilbg)yjA#kd(p9N3}$U5R}Ev4filC+19smL%7jpr)e#6zjM~O|4kV}dm_wP9 zSe(Ko`Tn@99^U0fA)z_-ZHRxeRJ0s|o7d;Bfy$;8W(*Ow^#2Ezkb+svQARdq7w4{n ztTUXnIKNtpp?FKLi>i=^jq2F^v1 zYY-xI_ZWj<^?*w`DYhPCJ!(u_Erl|^k3P|*Puj?}RMpVx zJ%}>Ao{ANyz_dCnHy)2ga%Eu#=NXj(=E@9CD{MRP$l$%PDfVmU7Hv8w9bE;YbJR&? z<(1W@E9&+iuQuKM>2E(-hPgs3;coZ&EK>dh+$M`7w-YTJZgrqlNABf4TX;XR!$y}d z6EXezJ*51gm=54*B#Z#@YF;M2bWs(3kbD!kBAitX2uW>kg(AGJ-6zmVhpGi5pz}Ri zk!;f`<{JcTmCh-6dUg7JcLs%w6dOw$%Fyc2jGKwEQ^8RUatRsWZ>gNWj72E*X|N$?|$vf=?iXXcTR?*$&vncCQ6UXB&p6x=e4+I?|V#FkcG?6 zQAgaqXTB$XctcU9zMB_tiFUgKWFv)!k_8P}L+rm#S;|gOMKva5fry^DrFv(|!<6`|}|1!fDX= zCjI$nGz^dz_z2A-KMei8-w$9k^ZVZ13#$d%DpciJb{QsOWp6v@bS8JNbXySSNfgDY zS;lp;s6wDBj;eG`mA)^Jw790l9@}6H(p#aO<;oW+pSfZ;evk1TN)V-8?h#_~mna^- zPP>u@y>BMI^mKCTL0t0Wv6C+qY( zby%sjacbXhBA(ANlJ~Rov8F}Dt6Dm+)LlKDQ76+HQ3T$}u{jaNL*A(i(0${=Tw74<_^^{pIyYyRy#HvPS|YknG!wP$6T(#VHs7hQj7>g)T|IP#B8c~yoH?Y& zot-(@%JeJ{?lnIPPTigGX=iAG_K~M(xz8SLj@n>rS@|flR0&sC7hS8zJ7%bY^0@O; z0j4KeQX_rjS!wpvqs_@O&>AKleLjkk_S@~xyiorZ>(d0(()KLZ z^{-f-B@9jMPW9q0gjFO}i?iPw6cvH}v5&k-6h@IBjY4lao6o0%X&8({G?)*@!_jPt zkmm>e`6QYQMu9(_jOGyb`@wM3hc!n#EP}MTna!Yc-s-3hQ1xxDNGwkh8{ePdB+}Js zIILb+JlpN6m;GB4O&vUi>j7Z5QLCP9b?Hy5(SSXnKLBh2uf=JICPOD`g*!;R63?~~ zN7v#t*Li~cvDzc864C=W3FEb{5&>uA4yi4*NQ+|_hWYMih9bPp6vK48TQ1)JgdTZ@ zC|PG=rL3cxbs^n za-wnSRDKGMWkpo#INB{q&0R&816nOyl`DY4&CKhI>8<2SH|NFS7y&6s*Rhm0s(oIB zLMch110}{Dc&2K@$rvjWC+3ZEpjygaM5WAJ4bc0B&xx*BzazilL z%t*A6$n_{1+xqI_fH{tp4%Njrtx>&vb8)T$XK%hgz5aXWq+c4DOI3s64MiEaI0sMp z3x@zDcilUf0bN}u-jtBk$NNN9$YqA_aEun{ISpYfrn!ox9d*nCpnUpND~TR;QvH6E zzoz$ruLxn^=0R_LDT;^>z9J%yD1U1b3#_RqpzFfyRl6&%|Fd^f|i&W;dWH~%>BAzpGxRp0o5v?2DF^R03z7NW<`0wv|a!jl6;38tm0_6 zVrc22sunfEcB~o=f6s+O-Nim~C6ou3^0qdV>X}UCrd?c?GA2wZX)5Yf8l$INxXzSt zJv=JO+9Qy|J1S(ZLB^@}@3uxHYMjCH`>pR~$ydD_v?^rpOpWA*)BO_hF*l2+Du9JG zr9Imk6pq`|ZYmj`W!TdD?CDE+smO(hbme_jqx}d#2?SFuv{0mic+4yeomaaw2yD0p zx7z3eEQ>@6e5EVTb!oMtFO8%jd8;;wK($~(dVa~jfY*B;$yDtV*;aY?%^M&BJQPv1d}#3^0a4s&S3p&}(~P7fCX3B=%AMk~ykJt5 zJbfFV>y0*7^69=4T_*cYgYQxSzgyIB(i`fG)h2K^URpOd|6N{K>YA62UcwN;a0yU^ z#ce5Td6$bm9nJ-bq(gNNB-tcoHclA@@;xv zukZDJZ|V>7`c`9z2J?yMPlCyCf}&9{p3X+|$$UJTPtbfY_h*CgVAk*VXA^HYM&8t) zL2oud!}+K`olbXBCU-#&PU9F{;l+|sa3!yQi9lDV+na2S&IG^UG9!E-55D^H`Mf^z z>gZz~BJHiB$H(D$o;Ml{#Q&b>+5dZk(fBKW&=36Kcrf(GUwM9iJQ#ijyvHY{`dL#3 zv#-1dZL{@~!R;);W1hUVXNwBjvf zT90IlmyX lND?p~)lu_%58Ic|m(Q2am(PPg|2F^t|NrAA%WD861OP^a1sebW literal 0 HcmV?d00001 diff --git a/incubator/netdata/0.0.1/ix_values.yaml b/incubator/netdata/0.0.1/ix_values.yaml new file mode 100644 index 00000000000..0d4ccb07fc9 --- /dev/null +++ b/incubator/netdata/0.0.1/ix_values.yaml @@ -0,0 +1,118 @@ +image: + repository: netdata/netdata + tag: v1.34.1@sha256:f6cac082c234ac0fac0d0d464a4b4fe68fe3ec53d18a03b553307c8286e92f0c + pullPolicy: IfNotPresent + +securityContext: + readOnlyRootFilesystem: false + runAsNonRoot: false + capabilities: + add: + - SYS_PTRACE + +podSecurityContext: + runAsUser: 0 + runAsGroup: 0 + fsGroup: 201 + +serviceAccount: + create: true + +rbac: + enabled: true + rules: + - apiGroups: + - "" + resources: + - "pods" + - "services" + - "configmaps" + - "secrets" + - "nodes" + - "nodes/metrics" + verbs: + - "get" + - "list" + - "watch" + - apiGroups: [""] + resources: + - "namespaces" + verbs: + - "get" + +service: + main: + ports: + main: + port: 19999 + targetPort: 19999 + +probes: + liveness: + path: "/api/v1/info" + readiness: + path: "/api/v1/info" + startup: + path: "/api/v1/info" + +persistence: + config: + enabled: true + mountPath: "/etc/netdata" + lib: + enabled: true + mountPath: "/var/lib/netdata" + cache: + enabled: true + mountPath: "/var/cache/netdata" + passwd: + enabled: true + hostPath: "/etc/passwd" + mountPath: "/host/etc/passwd" + hostPathType: "" + readOnly: false + group: + enabled: true + hostPath: "/etc/group" + mountPath: "/host/etc/group" + hostPathType: "" + readOnly: false + proc: + enabled: true + hostPath: "/proc" + mountPath: "/host/proc" + hostPathType: "" + readOnly: false + sys: + enabled: true + hostPath: "/sys" + mountPath: "/host/sys" + hostPathType: "" + readOnly: false + os: + enabled: true + hostPath: "/etc/os-release" + mountPath: "/host/etc/os-release" + hostPathType: "" + readOnly: false + +initContainers: + create-config: + name: create-config + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + volumeMounts: + - name: config + mountPath: "/etc/netdata" + command: ["/bin/sh", "-c"] + args: + - > + echo "Creating config file..."; + export configfile=/etc/netdata/netdata.conf; + if [ ! -f $configfile ]; then + echo '[global]' > $configfile; + echo ' memory mode = dbengine' >> $configfile; + echo ' dbengine multihost disk space = 4096' >> $configfile; + echo ' page cache size = 64' >> $configfile; + else + echo "Config file exists, skipping..."; + fi; diff --git a/incubator/netdata/0.0.1/questions.yaml b/incubator/netdata/0.0.1/questions.yaml new file mode 100644 index 00000000000..416c2cbee9f --- /dev/null +++ b/incubator/netdata/0.0.1/questions.yaml @@ -0,0 +1,2731 @@ +groups: + - name: "Container Image" + description: "Image to be used for container" + - name: "Controller" + description: "Configure workload deployment" + - name: "Container Configuration" + description: "additional container configuration" + - name: "App Configuration" + description: "App specific config options" + - name: "Networking and Services" + description: "Configure Network and Services for container" + - name: "Storage and Persistence" + description: "Persist and share data that is separate from the container" + - name: "Ingress" + description: "Ingress Configuration" + - name: "Security and Permissions" + description: "Configure security context and permissions" + - name: "Resources and Devices" + description: "Specify resources/devices to be allocated to workload" + - name: "Middlewares" + description: "Traefik Middlewares" + - name: "Metrics" + description: "Metrics" + - name: "Addons" + description: "Addon Configuration" + - name: "Advanced" + description: "Advanced Configuration" +portals: + open: + protocols: + - "$kubernetes-resource_configmap_portal_protocol" + host: + - "$kubernetes-resource_configmap_portal_host" + ports: + - "$kubernetes-resource_configmap_portal_port" +questions: + - variable: portal + group: "Container Image" + label: "Configure Portal Button" + schema: + type: dict + hidden: true + attrs: + - variable: enabled + label: "Enable" + description: "enable the portal button" + schema: + hidden: true + editable: false + type: boolean + default: true + - variable: global + label: "global settings" + group: "Controller" + schema: + type: dict + hidden: true + attrs: + - variable: isSCALE + label: "flag this is SCALE" + schema: + type: boolean + default: true + hidden: true + - variable: controller + group: "Controller" + label: "" + schema: + additional_attrs: true + type: dict + attrs: + - variable: advanced + label: "Show Advanced Controller Settings" + schema: + type: boolean + default: false + show_subquestions_if: true + subquestions: + - variable: type + description: "Please specify type of workload to deploy" + label: "(Advanced) Controller Type" + schema: + type: string + default: "deployment" + required: true + enum: + - value: "deployment" + description: "Deployment" + - value: "statefulset" + description: "Statefulset" + - value: "daemonset" + description: "Daemonset" + - variable: replicas + description: "Number of desired pod replicas" + label: "Desired Replicas" + schema: + type: int + default: 1 + required: true + - variable: strategy + description: "Please specify type of workload to deploy" + label: "(Advanced) Update Strategy" + schema: + type: string + default: "Recreate" + required: true + enum: + - value: "Recreate" + description: "Recreate: Kill existing pods before creating new ones" + - value: "RollingUpdate" + description: "RollingUpdate: Create new pods and then kill old ones" + - value: "OnDelete" + description: "(Legacy) OnDelete: ignore .spec.template changes" + - variable: expert + label: "Show Expert Configuration Options" + schema: + type: boolean + default: false + show_subquestions_if: true + subquestions: + - variable: extraArgs + label: "Extra Args" + schema: + type: list + default: [] + items: + - variable: arg + label: "arg" + schema: + type: string + - variable: labelsList + label: "Controller Labels" + schema: + type: list + default: [] + items: + - variable: labelItem + label: "Label" + schema: + additional_attrs: true + type: dict + attrs: + - variable: name + label: "Name" + schema: + type: string + - variable: value + label: "Value" + schema: + type: string + - variable: annotationsList + label: " Controller Annotations" + schema: + type: list + default: [] + items: + - variable: annotationItem + label: "Label" + schema: + additional_attrs: true + type: dict + attrs: + - variable: name + label: "Name" + schema: + type: string + - variable: value + label: "Value" + schema: + type: string + # Docker specific env + - variable: TZ + label: "Timezone" + group: "Container Configuration" + schema: + type: string + default: "Etc/UTC" + $ref: + - "definitions/timezone" + + - variable: envList + label: "Image environment" + group: "Container Configuration" + schema: + type: list + default: [] + items: + - variable: envItem + label: "Environment Variable" + schema: + additional_attrs: true + type: dict + attrs: + - variable: name + label: "Name" + schema: + type: string + - variable: value + label: "Value" + schema: + type: string + + - variable: expertpodconf + group: "Container Configuration" + label: "Show Expert Config" + schema: + type: boolean + default: false + show_subquestions_if: true + subquestions: + - variable: tty + label: "Enable TTY" + description: "Determines whether containers in a pod runs with TTY enabled. By default pod has it disabled." + group: "Workload Details" + schema: + type: boolean + default: false + - variable: stdin + label: "Enable STDIN" + description: "Determines whether containers in a pod runs with stdin enabled. By default pod has it disabled." + group: "Workload Details" + schema: + type: boolean + default: false + - variable: termination + group: "Container Configuration" + label: "Termination settings" + schema: + additional_attrs: true + type: dict + attrs: + - variable: gracePeriodSeconds + label: "Grace Period Seconds" + schema: + type: int + default: 10 + - variable: podLabelsList + group: "Container Configuration" + label: "Pod Labels" + schema: + type: list + default: [] + items: + - variable: podLabelItem + label: "Label" + schema: + additional_attrs: true + type: dict + attrs: + - variable: name + label: "Name" + schema: + type: string + - variable: value + label: "Value" + schema: + type: string + + - variable: podAnnotationsList + group: "Container Configuration" + label: "Pod Annotations" + schema: + type: list + default: [] + items: + - variable: podAnnotationItem + label: "Label" + schema: + additional_attrs: true + type: dict + attrs: + - variable: name + label: "Name" + schema: + type: string + - variable: value + label: "Value" + schema: + type: string + + - variable: service + group: "Networking and Services" + label: "Configure Service(s)" + schema: + additional_attrs: true + type: dict + attrs: + - variable: main + label: "Main Service" + description: "The Primary service on which the healthcheck runs, often the webUI" + schema: + additional_attrs: true + type: dict + attrs: + - variable: enabled + label: "Enable the service" + schema: + type: boolean + default: true + hidden: true + - variable: type + label: "Service Type" + description: "ClusterIP's are only internally available, nodePorts expose the container to the host node System, Loadbalancer exposes the service using the system loadbalancer" + schema: + type: string + default: "Simple" + enum: + - value: "Simple" + description: "Simple" + - value: "ClusterIP" + description: "ClusterIP" + - value: "NodePort" + description: "NodePort (Advanced)" + - value: "LoadBalancer" + description: "LoadBalancer (Advanced)" + - variable: loadBalancerIP + label: "LoadBalancer IP" + description: "LoadBalancerIP" + schema: + show_if: [["type", "=", "LoadBalancer"]] + type: string + default: "" + - variable: externalIPs + label: "External IP's" + description: "External IP's" + schema: + show_if: [["type", "=", "LoadBalancer"]] + type: list + default: [] + items: + - variable: externalIP + label: "External IP" + schema: + type: string + - variable: ipFamilyPolicy + label: "IP Family Policy" + description: "(Advanced) Specify the ip policy" + schema: + show_if: [["type", "!=", "Simple"]] + type: string + default: "SingleStack" + enum: + - value: "SingleStack" + description: "SingleStack" + - value: "PreferDualStack" + description: "PreferDualStack" + - value: "RequireDualStack" + description: "RequireDualStack" + - variable: ipFamilies + label: "(advanced) IP families" + description: "(advanced) The ip families that should be used" + schema: + show_if: [["type", "!=", "Simple"]] + type: list + default: [] + items: + - variable: ipFamily + label: "IP family" + schema: + type: string + - variable: ports + label: "Service's Port(s) Configuration" + schema: + additional_attrs: true + type: dict + attrs: + - variable: main + label: "Main Service Port Configuration" + schema: + additional_attrs: true + type: dict + attrs: + - variable: port + label: "Port" + description: "This port exposes the container port on the service" + schema: + type: int + default: 19999 + required: true + - variable: advanced + label: "Show Advanced settings" + schema: + type: boolean + default: false + show_subquestions_if: true + subquestions: + - variable: protocol + label: "Port Type" + schema: + type: string + default: "HTTP" + enum: + - value: HTTP + description: "HTTP" + - value: "HTTPS" + description: "HTTPS" + - value: TCP + description: "TCP" + - value: "UDP" + description: "UDP" + - variable: nodePort + label: "Node Port (Optional)" + description: "This port gets exposed to the node. Only considered when service type is NodePort, Simple or LoadBalancer" + schema: + type: int + min: 9000 + max: 65535 + - variable: targetPort + label: "Target Port" + description: "The internal(!) port on the container the Application runs on" + schema: + type: int + default: 19999 + + - variable: serviceexpert + group: "Networking and Services" + label: "Show Expert Config" + schema: + type: boolean + default: false + show_subquestions_if: true + subquestions: + - variable: hostNetwork + group: "Networking and Services" + label: "Host-Networking (Complicated)" + schema: + type: boolean + default: false + + - variable: externalInterfaces + description: "Add External Interfaces" + label: "Add external Interfaces" + group: "Networking" + schema: + type: list + items: + - variable: interfaceConfiguration + description: "Interface Configuration" + label: "Interface Configuration" + schema: + type: dict + $ref: + - "normalize/interfaceConfiguration" + attrs: + - variable: hostInterface + description: "Please specify host interface" + label: "Host Interface" + schema: + type: string + required: true + $ref: + - "definitions/interface" + - variable: ipam + description: "Define how IP Address will be managed" + label: "IP Address Management" + schema: + type: dict + required: true + attrs: + - variable: type + description: "Specify type for IPAM" + label: "IPAM Type" + schema: + type: string + required: true + enum: + - value: "dhcp" + description: "Use DHCP" + - value: "static" + description: "Use static IP" + show_subquestions_if: "static" + subquestions: + - variable: staticIPConfigurations + label: "Static IP Addresses" + schema: + type: list + items: + - variable: staticIP + label: "Static IP" + schema: + type: ipaddr + cidr: true + - variable: staticRoutes + label: "Static Routes" + schema: + type: list + items: + - variable: staticRouteConfiguration + label: "Static Route Configuration" + schema: + additional_attrs: true + type: dict + attrs: + - variable: destination + label: "Destination" + schema: + type: ipaddr + cidr: true + required: true + - variable: gateway + label: "Gateway" + schema: + type: ipaddr + cidr: false + required: true + + - variable: dnsPolicy + group: "Networking and Services" + label: "dnsPolicy" + schema: + type: string + default: "" + enum: + - value: "" + description: "Default" + - value: "ClusterFirst" + description: "ClusterFirst" + - value: "ClusterFirstWithHostNet" + description: "ClusterFirstWithHostNet" + - value: "None" + description: "None" + + - variable: dnsConfig + label: "DNS Configuration" + group: "Networking and Services" + description: "Specify custom DNS configuration which will be applied to the pod" + schema: + additional_attrs: true + type: dict + attrs: + - variable: nameservers + label: "Nameservers" + schema: + default: [] + type: list + items: + - variable: nameserver + label: "Nameserver" + schema: + type: string + - variable: options + label: "options" + schema: + default: [] + type: list + items: + - variable: option + label: "Option Entry" + schema: + additional_attrs: true + type: dict + attrs: + - variable: name + label: "Name" + schema: + type: string + - variable: value + label: "Value" + schema: + type: string + - variable: searches + label: "Searches" + schema: + default: [] + type: list + items: + - variable: search + label: "Search Entry" + schema: + type: string + + - variable: serviceList + label: "Add Manual Custom Services" + group: "Networking and Services" + schema: + type: list + default: [] + items: + - variable: serviceListEntry + label: "Custom Service" + schema: + additional_attrs: true + type: dict + attrs: + - variable: enabled + label: "Enable the service" + schema: + type: boolean + default: true + hidden: true + - variable: name + label: "Name" + schema: + type: string + default: "" + - variable: type + label: "Service Type" + description: "ClusterIP's are only internally available, nodePorts expose the container to the host node System, Loadbalancer exposes the service using the system loadbalancer" + schema: + type: string + default: "Simple" + enum: + - value: "Simple" + description: "Simple" + - value: "NodePort" + description: "NodePort" + - value: "ClusterIP" + description: "ClusterIP" + - value: "LoadBalancer" + description: "LoadBalancer" + - variable: loadBalancerIP + label: "LoadBalancer IP" + description: "LoadBalancerIP" + schema: + show_if: [["type", "=", "LoadBalancer"]] + type: string + default: "" + - variable: externalIPs + label: "External IP's" + description: "External IP's" + schema: + show_if: [["type", "=", "LoadBalancer"]] + type: list + default: [] + items: + - variable: externalIP + label: "External IP" + schema: + type: string + - variable: portsList + label: "Additional Service Ports" + schema: + type: list + default: [] + items: + - variable: portsListEntry + label: "Custom ports" + schema: + additional_attrs: true + type: dict + attrs: + - variable: enabled + label: "Enable the port" + schema: + type: boolean + default: true + hidden: true + - variable: name + label: "Port Name" + schema: + type: string + default: "" + - variable: protocol + label: "Port Type" + schema: + type: string + default: "TCP" + enum: + - value: HTTP + description: "HTTP" + - value: "HTTPS" + description: "HTTPS" + - value: TCP + description: "TCP" + - value: "UDP" + description: "UDP" + - variable: targetPort + label: "Target Port" + description: "This port exposes the container port on the service" + schema: + type: int + required: true + - variable: port + label: "Container Port" + schema: + type: int + required: true + - variable: nodePort + label: "Node Port (Optional)" + description: "This port gets exposed to the node. Only considered when service type is NodePort" + schema: + type: int + min: 9000 + max: 65535 + + - variable: persistence + label: "Integrated Persistent Storage" + description: "Integrated Persistent Storage" + group: "Storage and Persistence" + schema: + additional_attrs: true + type: dict + attrs: + - variable: config + label: "App Config Storage" + description: "The directory configuration files are kept." + schema: + additional_attrs: true + type: dict + attrs: + - variable: type + label: "Type of Storage" + description: "Sets the persistence type, Anything other than PVC could break rollback!" + schema: + type: string + default: "simplePVC" + enum: + - value: "simplePVC" + description: "PVC (simple)" + - value: "simpleHP" + description: "HostPath (simple)" + - value: "emptyDir" + description: "emptyDir" + - value: "pvc" + description: "pvc" + - value: "hostPath" + description: "hostPath" + - variable: setPermissionsSimple + label: "Automatic Permissions" + description: "Automatically set permissions on install" + schema: + show_if: [["type", "=", "simpleHP"]] + type: boolean + default: true + - variable: setPermissions + label: "Automatic Permissions" + description: "Automatically set permissions on install" + schema: + show_if: [["type", "=", "hostPath"]] + type: boolean + default: true + - variable: readOnly + label: "readOnly" + schema: + type: boolean + default: false + - variable: hostPathSimple + label: "hostPath" + description: "Path inside the container the storage is mounted" + schema: + show_if: [["type", "=", "simpleHP"]] + type: hostpath + - variable: hostPath + label: "hostPath" + description: "Path inside the container the storage is mounted" + schema: + show_if: [["type", "=", "hostPath"]] + type: hostpath + - variable: medium + label: "EmptyDir Medium" + schema: + show_if: [["type", "=", "emptyDir"]] + type: string + default: "" + enum: + - value: "" + description: "Default" + - value: "Memory" + description: "Memory" + - variable: size + label: "Size quotum of storage" + schema: + show_if: [["type", "=", "pvc"]] + type: string + default: "999Gi" + - variable: hostPathType + label: "(Advanced) hostPath Type" + schema: + show_if: [["type", "=", "hostPath"]] + type: string + default: "" + enum: + - value: "" + description: "Default" + - value: "DirectoryOrCreate" + description: "DirectoryOrCreate" + - value: "Directory" + description: "Directory" + - value: "FileOrCreate" + description: "FileOrCreate" + - value: "File" + description: "File" + - value: "Socket" + description: "Socket" + - value: "CharDevice" + description: "CharDevice" + - value: "BlockDevice" + description: "BlockDevice" + - variable: storageClass + label: "(Advanced) storageClass" + description: "Warning: Anything other than SCALE-ZFS or empty will break rollback!" + schema: + show_if: [["type", "=", "pvc"]] + type: string + default: "SCALE-ZFS" + - variable: accessMode + label: "(Advanced) Access Mode" + description: "Allow or disallow multiple PVC's writhing to the same PV" + schema: + show_if: [["type", "=", "pvc"]] + type: string + default: "ReadWriteOnce" + enum: + - value: "ReadWriteOnce" + description: "ReadWriteOnce" + - value: "ReadOnlyMany" + description: "ReadOnlyMany" + - value: "ReadWriteMany" + description: "ReadWriteMany" + - variable: advanced + label: "Show Advanced Options" + schema: + type: boolean + default: false + show_subquestions_if: true + subquestions: + - variable: labelsList + label: "Labels" + schema: + type: list + default: [] + items: + - variable: labelItem + label: "Label" + schema: + additional_attrs: true + type: dict + attrs: + - variable: name + label: "Name" + schema: + type: string + - variable: value + label: "Value" + schema: + type: string + - variable: annotationsList + label: "Annotations" + schema: + type: list + default: [] + items: + - variable: annotationItem + label: "Label" + schema: + additional_attrs: true + type: dict + attrs: + - variable: name + label: "Name" + schema: + type: string + - variable: value + label: "Value" + schema: + type: string + - variable: lib + label: "App lib Storage" + description: "Contains the alarm log and the Netdata instance guid." + schema: + additional_attrs: true + type: dict + attrs: + - variable: type + label: "Type of Storage" + description: "Sets the persistence type, Anything other than PVC could break rollback!" + schema: + type: string + default: "simplePVC" + enum: + - value: "simplePVC" + description: "PVC (simple)" + - value: "simpleHP" + description: "HostPath (simple)" + - value: "emptyDir" + description: "emptyDir" + - value: "pvc" + description: "pvc" + - value: "hostPath" + description: "hostPath" + - variable: setPermissionsSimple + label: "Automatic Permissions" + description: "Automatically set permissions on install" + schema: + show_if: [["type", "=", "simpleHP"]] + type: boolean + default: true + - variable: setPermissions + label: "Automatic Permissions" + description: "Automatically set permissions on install" + schema: + show_if: [["type", "=", "hostPath"]] + type: boolean + default: true + - variable: readOnly + label: "readOnly" + schema: + type: boolean + default: false + - variable: hostPathSimple + label: "hostPath" + description: "Path inside the container the storage is mounted" + schema: + show_if: [["type", "=", "simpleHP"]] + type: hostpath + - variable: hostPath + label: "hostPath" + description: "Path inside the container the storage is mounted" + schema: + show_if: [["type", "=", "hostPath"]] + type: hostpath + - variable: medium + label: "EmptyDir Medium" + schema: + show_if: [["type", "=", "emptyDir"]] + type: string + default: "" + enum: + - value: "" + description: "Default" + - value: "Memory" + description: "Memory" + - variable: size + label: "Size quotum of storage" + schema: + show_if: [["type", "=", "pvc"]] + type: string + default: "999Gi" + - variable: hostPathType + label: "(Advanced) hostPath Type" + schema: + show_if: [["type", "=", "hostPath"]] + type: string + default: "" + enum: + - value: "" + description: "Default" + - value: "DirectoryOrCreate" + description: "DirectoryOrCreate" + - value: "Directory" + description: "Directory" + - value: "FileOrCreate" + description: "FileOrCreate" + - value: "File" + description: "File" + - value: "Socket" + description: "Socket" + - value: "CharDevice" + description: "CharDevice" + - value: "BlockDevice" + description: "BlockDevice" + - variable: storageClass + label: "(Advanced) storageClass" + description: "Warning: Anything other than SCALE-ZFS or empty will break rollback!" + schema: + show_if: [["type", "=", "pvc"]] + type: string + default: "SCALE-ZFS" + - variable: accessMode + label: "(Advanced) Access Mode" + description: "Allow or disallow multiple PVC's writhing to the same PV" + schema: + show_if: [["type", "=", "pvc"]] + type: string + default: "ReadWriteOnce" + enum: + - value: "ReadWriteOnce" + description: "ReadWriteOnce" + - value: "ReadOnlyMany" + description: "ReadOnlyMany" + - value: "ReadWriteMany" + description: "ReadWriteMany" + - variable: advanced + label: "Show Advanced Options" + schema: + type: boolean + default: false + show_subquestions_if: true + subquestions: + - variable: labelsList + label: "Labels" + schema: + type: list + default: [] + items: + - variable: labelItem + label: "Label" + schema: + additional_attrs: true + type: dict + attrs: + - variable: name + label: "Name" + schema: + type: string + - variable: value + label: "Value" + schema: + type: string + - variable: annotationsList + label: "Annotations" + schema: + type: list + default: [] + items: + - variable: annotationItem + label: "Label" + schema: + additional_attrs: true + type: dict + attrs: + - variable: name + label: "Name" + schema: + type: string + - variable: value + label: "Value" + schema: + type: string + - variable: cache + label: "App cache Storage" + description: "Contains the db files for the collected metrics" + schema: + additional_attrs: true + type: dict + attrs: + - variable: type + label: "Type of Storage" + description: "Sets the persistence type, Anything other than PVC could break rollback!" + schema: + type: string + default: "simplePVC" + enum: + - value: "simplePVC" + description: "PVC (simple)" + - value: "simpleHP" + description: "HostPath (simple)" + - value: "emptyDir" + description: "emptyDir" + - value: "pvc" + description: "pvc" + - value: "hostPath" + description: "hostPath" + - variable: setPermissionsSimple + label: "Automatic Permissions" + description: "Automatically set permissions on install" + schema: + show_if: [["type", "=", "simpleHP"]] + type: boolean + default: true + - variable: setPermissions + label: "Automatic Permissions" + description: "Automatically set permissions on install" + schema: + show_if: [["type", "=", "hostPath"]] + type: boolean + default: true + - variable: readOnly + label: "readOnly" + schema: + type: boolean + default: false + - variable: hostPathSimple + label: "hostPath" + description: "Path inside the container the storage is mounted" + schema: + show_if: [["type", "=", "simpleHP"]] + type: hostpath + - variable: hostPath + label: "hostPath" + description: "Path inside the container the storage is mounted" + schema: + show_if: [["type", "=", "hostPath"]] + type: hostpath + - variable: medium + label: "EmptyDir Medium" + schema: + show_if: [["type", "=", "emptyDir"]] + type: string + default: "" + enum: + - value: "" + description: "Default" + - value: "Memory" + description: "Memory" + - variable: size + label: "Size quotum of storage" + schema: + show_if: [["type", "=", "pvc"]] + type: string + default: "999Gi" + - variable: hostPathType + label: "(Advanced) hostPath Type" + schema: + show_if: [["type", "=", "hostPath"]] + type: string + default: "" + enum: + - value: "" + description: "Default" + - value: "DirectoryOrCreate" + description: "DirectoryOrCreate" + - value: "Directory" + description: "Directory" + - value: "FileOrCreate" + description: "FileOrCreate" + - value: "File" + description: "File" + - value: "Socket" + description: "Socket" + - value: "CharDevice" + description: "CharDevice" + - value: "BlockDevice" + description: "BlockDevice" + - variable: storageClass + label: "(Advanced) storageClass" + description: "Warning: Anything other than SCALE-ZFS or empty will break rollback!" + schema: + show_if: [["type", "=", "pvc"]] + type: string + default: "SCALE-ZFS" + - variable: accessMode + label: "(Advanced) Access Mode" + description: "Allow or disallow multiple PVC's writhing to the same PV" + schema: + show_if: [["type", "=", "pvc"]] + type: string + default: "ReadWriteOnce" + enum: + - value: "ReadWriteOnce" + description: "ReadWriteOnce" + - value: "ReadOnlyMany" + description: "ReadOnlyMany" + - value: "ReadWriteMany" + description: "ReadWriteMany" + - variable: advanced + label: "Show Advanced Options" + schema: + type: boolean + default: false + show_subquestions_if: true + subquestions: + - variable: labelsList + label: "Labels" + schema: + type: list + default: [] + items: + - variable: labelItem + label: "Label" + schema: + additional_attrs: true + type: dict + attrs: + - variable: name + label: "Name" + schema: + type: string + - variable: value + label: "Value" + schema: + type: string + - variable: annotationsList + label: "Annotations" + schema: + type: list + default: [] + items: + - variable: annotationItem + label: "Label" + schema: + additional_attrs: true + type: dict + attrs: + - variable: name + label: "Name" + schema: + type: string + - variable: value + label: "Value" + schema: + type: string + + - variable: persistenceList + label: "Additional app storage" + group: "Storage and Persistence" + schema: + type: list + default: [] + items: + - variable: persistenceListEntry + label: "Custom Storage" + schema: + additional_attrs: true + type: dict + attrs: + - variable: enabled + label: "Enable the storage" + schema: + type: boolean + default: true + hidden: true + - variable: name + label: "Name (optional)" + description: "Not required, please set to config when mounting /config or temp when mounting /tmp" + schema: + type: string + - variable: type + label: "Type of Storage" + description: "Sets the persistence type, Anything other than PVC could break rollback!" + schema: + type: string + default: "simpleHP" + enum: + - value: "simplePVC" + description: "PVC (simple)" + - value: "simpleHP" + description: "HostPath (simple)" + - value: "emptyDir" + description: "emptyDir" + - value: "pvc" + description: "pvc" + - value: "hostPath" + description: "hostPath" + - variable: setPermissionsSimple + label: "Automatic Permissions" + description: "Automatically set permissions on install" + schema: + show_if: [["type", "=", "simpleHP"]] + type: boolean + default: true + - variable: setPermissions + label: "Automatic Permissions" + description: "Automatically set permissions on install" + schema: + show_if: [["type", "=", "hostPath"]] + type: boolean + default: true + - variable: readOnly + label: "readOnly" + schema: + type: boolean + default: false + - variable: hostPathSimple + label: "hostPath" + description: "Path inside the container the storage is mounted" + schema: + show_if: [["type", "=", "simpleHP"]] + type: hostpath + - variable: hostPath + label: "hostPath" + description: "Path inside the container the storage is mounted" + schema: + show_if: [["type", "=", "hostPath"]] + type: hostpath + - variable: mountPath + label: "mountPath" + description: "Path inside the container the storage is mounted" + schema: + type: string + default: "" + required: true + valid_chars: '^\/([a-zA-Z0-9._-]+(\s?[a-zA-Z0-9._-]+|\/?))+$' + - variable: medium + label: "EmptyDir Medium" + schema: + show_if: [["type", "=", "emptyDir"]] + type: string + default: "" + enum: + - value: "" + description: "Default" + - value: "Memory" + description: "Memory" + - variable: size + label: "Size quotum of storage" + schema: + show_if: [["type", "=", "pvc"]] + type: string + default: "999Gi" + - variable: hostPathType + label: "(Advanced) hostPath Type" + schema: + show_if: [["type", "=", "hostPath"]] + type: string + default: "" + enum: + - value: "" + description: "Default" + - value: "DirectoryOrCreate" + description: "DirectoryOrCreate" + - value: "Directory" + description: "Directory" + - value: "FileOrCreate" + description: "FileOrCreate" + - value: "File" + description: "File" + - value: "Socket" + description: "Socket" + - value: "CharDevice" + description: "CharDevice" + - value: "BlockDevice" + description: "BlockDevice" + - variable: storageClass + label: "(Advanced) storageClass" + description: "Warning: Anything other than SCALE-ZFS or empty will break rollback!" + schema: + show_if: [["type", "=", "pvc"]] + type: string + default: "SCALE-ZFS" + - variable: accessMode + label: "(Advanced) Access Mode" + description: "Allow or disallow multiple PVC's writhing to the same PV" + schema: + show_if: [["type", "=", "pvc"]] + type: string + default: "ReadWriteOnce" + enum: + - value: "ReadWriteOnce" + description: "ReadWriteOnce" + - value: "ReadOnlyMany" + description: "ReadOnlyMany" + - value: "ReadWriteMany" + description: "ReadWriteMany" + - variable: advanced + label: "Show Advanced Options" + schema: + type: boolean + default: false + show_subquestions_if: true + subquestions: + - variable: labelsList + label: "Labels" + schema: + type: list + default: [] + items: + - variable: labelItem + label: "Label" + schema: + additional_attrs: true + type: dict + attrs: + - variable: name + label: "Name" + schema: + type: string + - variable: value + label: "Value" + schema: + type: string + - variable: annotationsList + label: "Annotations" + schema: + type: list + default: [] + items: + - variable: annotationItem + label: "Label" + schema: + additional_attrs: true + type: dict + attrs: + - variable: name + label: "Name" + schema: + type: string + - variable: value + label: "Value" + schema: + type: string + + - variable: ingress + label: "" + group: "Ingress" + schema: + additional_attrs: true + type: dict + attrs: + - variable: main + label: "Main Ingress" + schema: + additional_attrs: true + type: dict + attrs: + - variable: enabled + label: "Enable Ingress" + schema: + type: boolean + default: false + show_subquestions_if: true + subquestions: + - variable: hosts + label: "Hosts" + schema: + type: list + default: [] + items: + - variable: hostEntry + label: "Host" + schema: + additional_attrs: true + type: dict + attrs: + - variable: host + label: "HostName" + schema: + type: string + default: "" + required: true + - variable: paths + label: "Paths" + schema: + type: list + default: [] + items: + - variable: pathEntry + label: "Host" + schema: + additional_attrs: true + type: dict + attrs: + - variable: path + label: "path" + schema: + type: string + required: true + default: "/" + - variable: pathType + label: "pathType" + schema: + type: string + required: true + default: "Prefix" + + - variable: tls + label: "TLS-Settings" + schema: + type: list + default: [] + items: + - variable: tlsEntry + label: "Host" + schema: + additional_attrs: true + type: dict + attrs: + - variable: hosts + label: "Certificate Hosts" + schema: + type: list + default: [] + items: + - variable: host + label: "Host" + schema: + type: string + default: "" + required: true + - variable: scaleCert + label: "Select TrueNAS SCALE Certificate" + schema: + type: int + $ref: + - "definitions/certificate" + + - variable: entrypoint + label: "(Advanced) Traefik Entrypoint" + description: "Entrypoint used by Traefik when using Traefik as Ingress Provider" + schema: + type: string + default: "websecure" + required: true + - variable: middlewares + label: "Traefik Middlewares" + description: "Add previously created Traefik Middlewares to this Ingress" + schema: + type: list + default: [] + items: + - variable: name + label: "Name" + schema: + type: string + default: "" + required: true + + - variable: expert + label: "Show Expert Configuration Options" + schema: + type: boolean + default: false + show_subquestions_if: true + subquestions: + - variable: enableFixedMiddlewares + description: "These middlewares enforce a number of best practices." + label: "Enable Default Middlewares" + schema: + type: boolean + default: true + - variable: ingressClassName + label: "IngressClass Name" + schema: + type: string + default: "" + - variable: labelsList + label: "Labels" + schema: + type: list + default: [] + items: + - variable: labelItem + label: "Label" + schema: + additional_attrs: true + type: dict + attrs: + - variable: name + label: "Name" + schema: + type: string + - variable: value + label: "Value" + schema: + type: string + - variable: annotationsList + label: "Annotations" + schema: + type: list + default: [] + items: + - variable: annotationItem + label: "Label" + schema: + additional_attrs: true + type: dict + attrs: + - variable: name + label: "Name" + schema: + type: string + - variable: value + label: "Value" + schema: + type: string + + - variable: ingressList + label: "Add Manual Custom Ingresses" + group: "Ingress" + schema: + type: list + default: [] + items: + - variable: ingressListEntry + label: "Custom Ingress" + schema: + additional_attrs: true + type: dict + attrs: + - variable: enabled + label: "Enable Ingress" + schema: + type: boolean + default: true + hidden: true + - variable: name + label: "Name" + schema: + type: string + default: "" + - variable: ingressClassName + label: "IngressClass Name" + schema: + type: string + default: "" + - variable: labelsList + label: "Labels" + schema: + type: list + default: [] + items: + - variable: labelItem + label: "Label" + schema: + additional_attrs: true + type: dict + attrs: + - variable: name + label: "Name" + schema: + type: string + - variable: value + label: "Value" + schema: + type: string + - variable: annotationsList + label: "Annotations" + schema: + type: list + default: [] + items: + - variable: annotationItem + label: "Label" + schema: + additional_attrs: true + type: dict + attrs: + - variable: name + label: "Name" + schema: + type: string + - variable: value + label: "Value" + schema: + type: string + - variable: hosts + label: "Hosts" + schema: + type: list + default: [] + items: + - variable: hostEntry + label: "Host" + schema: + additional_attrs: true + type: dict + attrs: + - variable: host + label: "HostName" + schema: + type: string + default: "" + required: true + - variable: paths + label: "Paths" + schema: + type: list + default: [] + items: + - variable: pathEntry + label: "Host" + schema: + additional_attrs: true + type: dict + attrs: + - variable: path + label: "path" + schema: + type: string + required: true + default: "/" + - variable: pathType + label: "pathType" + schema: + type: string + required: true + default: "Prefix" + - variable: service + label: "Linked Service" + schema: + additional_attrs: true + type: dict + attrs: + - variable: name + label: "Service Name" + schema: + type: string + default: "" + - variable: port + label: "Service Port" + schema: + type: int + - variable: tls + label: "TLS-Settings" + schema: + type: list + default: [] + items: + - variable: tlsEntry + label: "Host" + schema: + additional_attrs: true + type: dict + attrs: + - variable: hosts + label: "Certificate Hosts" + schema: + type: list + default: [] + items: + - variable: host + label: "Host" + schema: + type: string + default: "" + required: true + - variable: scaleCert + label: "Select TrueNAS SCALE Certificate" + schema: + type: int + $ref: + - "definitions/certificate" + - variable: entrypoint + label: "Traefik Entrypoint" + description: "Entrypoint used by Traefik when using Traefik as Ingress Provider" + schema: + type: string + default: "websecure" + required: true + - variable: middlewares + label: "Traefik Middlewares" + description: "Add previously created Traefik Middlewares to this Ingress" + schema: + type: list + default: [] + items: + - variable: name + label: "Name" + schema: + type: string + default: "" + required: true + + - variable: security + label: "Container Security Settings" + group: "Security and Permissions" + schema: + type: dict + additional_attrs: true + attrs: + - variable: editsecurity + label: "Change PUID / UMASK values" + description: "By enabling this you override default set values." + schema: + type: boolean + default: false + show_subquestions_if: true + subquestions: + - variable: PUID + label: "Process User ID - PUID" + description: "When supported by the container, this sets the User ID running the Application Process. Not supported by all Apps" + schema: + type: int + default: 568 + - variable: UMASK + label: "UMASK" + description: "When supported by the container, this sets the UMASK for tha App. Not supported by all Apps" + schema: + type: string + default: "002" + + - variable: advancedSecurity + label: "Show Advanced Security Settings" + group: "Security and Permissions" + schema: + type: boolean + default: false + show_subquestions_if: true + subquestions: + - variable: securityContext + label: "Security Context" + schema: + additional_attrs: true + type: dict + attrs: + - variable: privileged + label: "Privileged mode" + schema: + type: boolean + default: false + - variable: readOnlyRootFilesystem + label: "ReadOnly Root Filesystem" + schema: + type: boolean + default: false + - variable: allowPrivilegeEscalation + label: "Allow Privilege Escalation" + schema: + type: boolean + default: false + - variable: runAsNonRoot + label: "runAsNonRoot" + schema: + type: boolean + default: false + - variable: capabilities + label: "Capabilities" + schema: + additional_attrs: true + type: dict + attrs: + - variable: drop + label: "Drop Capability" + schema: + type: list + default: [] + items: + - variable: dropEntry + label: "" + schema: + type: string + - variable: add + label: "Add Capability" + schema: + type: list + default: [] + items: + - variable: addEntry + label: "" + schema: + type: string + + - variable: podSecurityContext + group: "Security and Permissions" + label: "Pod Security Context" + schema: + additional_attrs: true + type: dict + attrs: + - variable: runAsUser + label: "runAsUser" + description: "The UserID of the user running the application" + schema: + type: int + default: 0 + - variable: runAsGroup + label: "runAsGroup" + description: "The groupID this App of the user running the application" + schema: + type: int + default: 0 + - variable: fsGroup + label: "fsGroup" + description: "The group that should own ALL storage." + schema: + type: int + default: 201 + - variable: fsGroupChangePolicy + label: "When should we take ownership?" + schema: + type: string + default: "OnRootMismatch" + enum: + - value: "OnRootMismatch" + description: "OnRootMismatch" + - value: "Always" + description: "Always" + - variable: supplementalGroups + label: "supplemental Groups" + schema: + type: list + default: [] + items: + - variable: supplementalGroupsEntry + label: "supplemental Group" + schema: + type: int + + + - variable: advancedresources + label: "Set Custom Resource Limits/Requests (Advanced)" + group: "Resources and Devices" + schema: + type: boolean + default: false + show_subquestions_if: true + subquestions: + - variable: resources + label: "" + schema: + additional_attrs: true + type: dict + attrs: + - variable: limits + label: "Advanced Limit Resource Consumption" + schema: + additional_attrs: true + type: dict + attrs: + - variable: cpu + label: "CPU" + description: "1000m means 1 hyperthread. Detailed info: https://truecharts.org/manual/indepth/validation/" + schema: + type: string + default: "4000m" + valid_chars: '^(?!^0(\.0|m|)$)([0-9]+)(\.[0-9]|m?)$' + - variable: memory + label: "RAM" + description: "1Gi means 1 Gibibyte RAM. Detailed info: https://truecharts.org/manual/indepth/validation/" + schema: + type: string + default: "8Gi" + valid_chars: '^(?!^0(e[0-9]|[EPTGMK]i?|)$)([0-9]+)(|[EPTGMK]i?|e[0-9]+)$' + - variable: requests + label: "Minimum Resources Required (request)" + schema: + additional_attrs: true + type: dict + attrs: + - variable: cpu + label: "CPU" + description: "1000m means 1 hyperthread. Detailed info: https://truecharts.org/manual/indepth/validation/" + schema: + type: string + default: "10m" + valid_chars: '^(?!^0(\.0|m|)$)([0-9]+)(\.[0-9]|m?)$' + - variable: memory + label: "RAM" + description: "1Gi means 1 Gibibyte RAM. Detailed info: https://truecharts.org/manual/indepth/validation/" + schema: + type: string + default: "50Mi" + valid_chars: '^(?!^0(e[0-9]|[EPTGMK]i?|)$)([0-9]+)(|[EPTGMK]i?|e[0-9]+)$' + + - variable: deviceList + label: "Mount USB devices" + group: "Resources and Devices" + schema: + type: list + default: [] + items: + - variable: deviceListEntry + label: "Device" + schema: + additional_attrs: true + type: dict + attrs: + - variable: enabled + label: "Enable the storage" + schema: + type: boolean + default: true + - variable: type + label: "(Advanced) Type of Storage" + description: "Sets the persistence type" + schema: + type: string + default: "hostPath" + hidden: true + - variable: readOnly + label: "readOnly" + schema: + type: boolean + default: false + - variable: hostPath + label: "Host Device Path" + description: "Path to the device on the host system" + schema: + type: path + - variable: mountPath + label: "Container Device Path" + description: "Path inside the container the device is mounted" + schema: + type: string + default: "/dev/ttyACM0" + + # Specify GPU configuration + - variable: scaleGPU + label: "GPU Configuration" + group: "Resources and Devices" + schema: + type: dict + $ref: + - "definitions/gpuConfiguration" + attrs: [] + + - variable: autoscaling + group: "Advanced" + label: "(Advanced) Horizontal Pod Autoscaler" + schema: + additional_attrs: true + type: dict + attrs: + - variable: enabled + label: "enabled" + schema: + type: boolean + default: false + show_subquestions_if: true + subquestions: + - variable: target + label: "Target" + description: "deployment name, defaults to main deployment" + schema: + type: string + default: "" + - variable: minReplicas + label: "Minimum Replicas" + schema: + type: int + default: 1 + - variable: maxReplicas + label: "Maximum Replicas" + schema: + type: int + default: 5 + - variable: targetCPUUtilizationPercentage + label: "Target CPU Utilization Percentage" + schema: + type: int + default: 80 + - variable: targetMemoryUtilizationPercentage + label: "Target Memory Utilization Percentage" + schema: + type: int + default: 80 + - variable: networkPolicy + group: "Advanced" + label: "(Advanced) Network Policy" + schema: + additional_attrs: true + type: dict + attrs: + - variable: enabled + label: "enabled" + schema: + type: boolean + default: false + show_subquestions_if: true + subquestions: + - variable: policyType + label: "Policy Type" + schema: + type: string + default: "" + enum: + - value: "" + description: "Default" + - value: "ingress" + description: "Ingress" + - value: "egress" + description: "Egress" + - value: "ingress-egress" + description: "Ingress and Egress" + - variable: egress + label: "Egress" + schema: + type: list + default: [] + items: + - variable: egressEntry + label: "" + schema: + additional_attrs: true + type: dict + attrs: + - variable: to + label: "To" + schema: + type: list + default: [] + items: + - variable: toEntry + label: "" + schema: + additional_attrs: true + type: dict + attrs: + - variable: ipBlock + label: "ipBlock" + schema: + additional_attrs: true + type: dict + attrs: + - variable: cidr + label: "cidr" + schema: + type: string + default: "" + - variable: except + label: "except" + schema: + type: list + default: [] + items: + - variable: exceptint + label: "" + schema: + type: string + - variable: namespaceSelector + label: "namespaceSelector" + schema: + additional_attrs: true + type: dict + attrs: + - variable: matchExpressions + label: "matchExpressions" + schema: + type: list + default: [] + items: + - variable: expressionEntry + label: "" + schema: + additional_attrs: true + type: dict + attrs: + - variable: key + label: "Key" + schema: + type: string + - variable: operator + label: "operator" + schema: + type: string + default: "TCP" + enum: + - value: "In" + description: "In" + - value: "NotIn" + description: "NotIn" + - value: "Exists " + description: "Exists " + - value: "DoesNotExist " + description: "DoesNotExist " + - variable: values + label: "values" + schema: + type: list + default: [] + items: + - variable: value + label: "" + schema: + type: string + - variable: podSelector + label: "" + schema: + additional_attrs: true + type: dict + attrs: + - variable: matchExpressions + label: "matchExpressions" + schema: + type: list + default: [] + items: + - variable: expressionEntry + label: "" + schema: + additional_attrs: true + type: dict + attrs: + - variable: key + label: "Key" + schema: + type: string + - variable: operator + label: "operator" + schema: + type: string + default: "TCP" + enum: + - value: "In" + description: "In" + - value: "NotIn" + description: "NotIn" + - value: "Exists " + description: "Exists " + - value: "DoesNotExist " + description: "DoesNotExist " + - variable: values + label: "values" + schema: + type: list + default: [] + items: + - variable: value + label: "" + schema: + type: string + - variable: ports + label: "Ports" + schema: + type: list + default: [] + items: + - variable: portsEntry + label: "" + schema: + additional_attrs: true + type: dict + attrs: + - variable: port + label: "port" + schema: + type: int + - variable: endPort + label: "port" + schema: + type: int + - variable: protocol + label: "Protocol" + schema: + type: string + default: "TCP" + enum: + - value: "TCP" + description: "TCP" + - value: "UDP" + description: "UDP" + - value: "SCTP" + description: "SCTP" + - variable: ingress + label: "Ingress" + schema: + type: list + default: [] + items: + - variable: ingressEntry + label: "" + schema: + additional_attrs: true + type: dict + attrs: + - variable: from + label: "From" + schema: + type: list + default: [] + items: + - variable: fromEntry + label: "" + schema: + additional_attrs: true + type: dict + attrs: + - variable: ipBlock + label: "ipBlock" + schema: + additional_attrs: true + type: dict + attrs: + - variable: cidr + label: "cidr" + schema: + type: string + default: "" + - variable: except + label: "except" + schema: + type: list + default: [] + items: + - variable: exceptint + label: "" + schema: + type: string + - variable: namespaceSelector + label: "namespaceSelector" + schema: + additional_attrs: true + type: dict + attrs: + - variable: matchExpressions + label: "matchExpressions" + schema: + type: list + default: [] + items: + - variable: expressionEntry + label: "" + schema: + additional_attrs: true + type: dict + attrs: + - variable: key + label: "Key" + schema: + type: string + - variable: operator + label: "operator" + schema: + type: string + default: "TCP" + enum: + - value: "In" + description: "In" + - value: "NotIn" + description: "NotIn" + - value: "Exists " + description: "Exists " + - value: "DoesNotExist " + description: "DoesNotExist " + - variable: values + label: "values" + schema: + type: list + default: [] + items: + - variable: value + label: "" + schema: + type: string + - variable: podSelector + label: "" + schema: + additional_attrs: true + type: dict + attrs: + - variable: matchExpressions + label: "matchExpressions" + schema: + type: list + default: [] + items: + - variable: expressionEntry + label: "" + schema: + additional_attrs: true + type: dict + attrs: + - variable: key + label: "Key" + schema: + type: string + - variable: operator + label: "operator" + schema: + type: string + default: "TCP" + enum: + - value: "In" + description: "In" + - value: "NotIn" + description: "NotIn" + - value: "Exists " + description: "Exists " + - value: "DoesNotExist " + description: "DoesNotExist " + - variable: values + label: "values" + schema: + type: list + default: [] + items: + - variable: value + label: "" + schema: + type: string + - variable: ports + label: "Ports" + schema: + type: list + default: [] + items: + - variable: portsEntry + label: "" + schema: + additional_attrs: true + type: dict + attrs: + - variable: port + label: "port" + schema: + type: int + - variable: endPort + label: "port" + schema: + type: int + - variable: protocol + label: "Protocol" + schema: + type: string + default: "TCP" + enum: + - value: "TCP" + description: "TCP" + - value: "UDP" + description: "UDP" + - value: "SCTP" + description: "SCTP" + + + - variable: addons + group: "Addons" + label: "" + schema: + additional_attrs: true + type: dict + attrs: + - variable: vpn + label: "VPN" + schema: + additional_attrs: true + type: dict + attrs: + - variable: type + label: "Type" + schema: + type: string + default: "disabled" + enum: + - value: "disabled" + description: "disabled" + - value: "openvpn" + description: "OpenVPN" + - value: "wireguard" + description: "Wireguard" + - variable: openvpn + label: "OpenVPN Settings" + schema: + type: dict + show_if: [["type", "=", "openvpn"]] + attrs: + - variable: username + label: "authentication username" + description: "authentication username, optional" + schema: + type: string + default: "" + - variable: password + label: "authentication password" + description: "authentication credentials" + schema: + type: string + default: "" + required: true + - variable: killSwitch + label: "Enable killswitch" + schema: + type: boolean + show_if: [["type", "!=", "disabled"]] + default: true + - variable: excludedNetworks_IPv4 + label: "Killswitch Excluded IPv4 networks" + description: "list of killswitch excluded ipv4 addresses" + schema: + type: list + show_if: [["type", "!=", "disabled"]] + default: [] + items: + - variable: networkv4 + label: "IPv4 Network" + schema: + type: string + required: true + - variable: excludedNetworks_IPv6 + label: "Killswitch Excluded IPv6 networks" + description: "list of killswitch excluded ipv4 addresses" + schema: + type: list + show_if: [["type", "!=", "disabled"]] + default: [] + items: + - variable: networkv6 + label: "IPv6 Network" + schema: + type: string + required: true + + - variable: configFile + label: "VPN Config File Location" + schema: + type: dict + show_if: [["type", "!=", "disabled"]] + attrs: + - variable: enabled + label: "enabled" + schema: + type: boolean + default: true + hidden: true + - variable: type + label: "type" + schema: + type: string + default: "hostPath" + hidden: true + - variable: hostPathType + label: "hostPathType" + schema: + type: string + default: "File" + hidden: true + - variable: noMount + label: "noMount" + schema: + type: boolean + default: true + hidden: true + - variable: hostPath + label: "Full path to file" + description: "path to your local VPN config file for example: /mnt/tank/vpn.conf or /mnt/tank/vpn.ovpn" + schema: + type: string + default: "" + required: true + - variable: envList + label: "VPN environment Variables" + schema: + type: list + show_if: [["type", "!=", "disabled"]] + default: [] + items: + - variable: envItem + label: "Environment Variable" + schema: + additional_attrs: true + type: dict + attrs: + - variable: name + label: "Name" + schema: + type: string + required: true + - variable: value + label: "Value" + schema: + type: string + required: true + + - variable: codeserver + label: "Codeserver" + schema: + additional_attrs: true + type: dict + attrs: + - variable: enabled + label: "enabled" + schema: + type: boolean + default: false + show_subquestions_if: true + subquestions: + - variable: git + label: "Git Settings" + schema: + additional_attrs: true + type: dict + attrs: + - variable: deployKey + description: "Raw SSH private key" + label: "deployKey" + schema: + type: string + - variable: deployKeyBase64 + description: "Base64-encoded SSH private key. When both variables are set, the raw SSH key takes precedence" + label: "deployKeyBase64" + schema: + type: string + - variable: service + label: "" + schema: + additional_attrs: true + type: dict + attrs: + - variable: type + label: "Service Type" + description: "ClusterIP's are only internally available, nodePorts expose the container to the host node System, Loadbalancer exposes the service using the system loadbalancer" + schema: + type: string + default: "NodePort" + enum: + - value: "NodePort" + description: "NodePort" + - value: "ClusterIP" + description: "ClusterIP" + - value: "LoadBalancer" + description: "LoadBalancer" + - variable: loadBalancerIP + label: "LoadBalancer IP" + description: "LoadBalancerIP" + schema: + show_if: [["type", "=", "LoadBalancer"]] + type: string + default: "" + - variable: externalIPs + label: "External IP's" + description: "External IP's" + schema: + show_if: [["type", "=", "LoadBalancer"]] + type: list + default: [] + items: + - variable: externalIP + label: "External IP" + schema: + type: string + - variable: ports + label: "" + schema: + additional_attrs: true + type: dict + attrs: + - variable: codeserver + label: "" + schema: + additional_attrs: true + type: dict + attrs: + - variable: nodePort + description: "leave empty to disable" + label: "nodePort" + schema: + type: int + default: 36107 + - variable: envList + label: "Codeserver environment Variables" + schema: + type: list + show_if: [["type", "!=", "disabled"]] + default: [] + items: + - variable: envItem + label: "Environment Variable" + schema: + additional_attrs: true + type: dict + attrs: + - variable: name + label: "Name" + schema: + type: string + required: true + - variable: value + label: "Value" + schema: + type: string + required: true + + + - variable: promtail + label: "Promtail" + schema: + additional_attrs: true + type: dict + attrs: + - variable: enabled + label: "enabled" + schema: + type: boolean + default: false + show_subquestions_if: true + subquestions: + - variable: loki + label: "Loki URL" + schema: + type: string + required: true + - variable: logs + label: "Log Paths" + schema: + additional_attrs: true + type: dict + attrs: + - variable: name + label: "Name" + schema: + type: string + required: true + - variable: path + label: "Path" + schema: + type: string + required: true + - variable: args + label: "Promtail ecommand line arguments" + schema: + type: list + show_if: [["type", "!=", "disabled"]] + default: [] + items: + - variable: arg + label: "Arg" + schema: + type: string + required: true + - variable: envList + label: "Promtail environment Variables" + schema: + type: list + show_if: [["type", "!=", "disabled"]] + default: [] + items: + - variable: envItem + label: "Environment Variable" + schema: + additional_attrs: true + type: dict + attrs: + - variable: name + label: "Name" + schema: + type: string + required: true + - variable: value + label: "Value" + schema: + type: string + required: true + + + + + - variable: netshoot + label: "Netshoot" + schema: + additional_attrs: true + type: dict + attrs: + - variable: enabled + label: "enabled" + schema: + type: boolean + default: false + show_subquestions_if: true + subquestions: + - variable: envList + label: "Netshoot environment Variables" + schema: + type: list + show_if: [["type", "!=", "disabled"]] + default: [] + items: + - variable: envItem + label: "Environment Variable" + schema: + additional_attrs: true + type: dict + attrs: + - variable: name + label: "Name" + schema: + type: string + required: true + - variable: value + label: "Value" + schema: + type: string + required: true diff --git a/incubator/netdata/0.0.1/security.md b/incubator/netdata/0.0.1/security.md new file mode 100644 index 00000000000..3d2ebb84fd5 --- /dev/null +++ b/incubator/netdata/0.0.1/security.md @@ -0,0 +1,142 @@ +--- +hide: + - toc +--- + +# Security Overview + + + +## Helm-Chart + +##### Scan Results + +#### Chart Object: netdata/templates/common.yaml + + + +| Type | Misconfiguration ID | Check | Severity | Explaination | Links | +|:----------------|:------------------:|:-----------:|:------------------:|-----------------------------------------|-----------------------------------------| +| Kubernetes Security Check | KSV001 | Process can elevate its own privileges | MEDIUM |
Expand... A program inside the container can elevate its own privileges and run as root, which might give the program control over the container and node.


Container 'create-config' of Deployment 'RELEASE-NAME-netdata' should set 'securityContext.allowPrivilegeEscalation' to false
|
Expand...https://kubernetes.io/docs/concepts/security/pod-security-standards/#restricted
https://avd.aquasec.com/appshield/ksv001
| +| Kubernetes Security Check | KSV001 | Process can elevate its own privileges | MEDIUM |
Expand... A program inside the container can elevate its own privileges and run as root, which might give the program control over the container and node.


Container 'hostpatch' of Deployment 'RELEASE-NAME-netdata' should set 'securityContext.allowPrivilegeEscalation' to false
|
Expand...https://kubernetes.io/docs/concepts/security/pod-security-standards/#restricted
https://avd.aquasec.com/appshield/ksv001
| +| Kubernetes Security Check | KSV003 | Default capabilities not dropped | LOW |
Expand... The container should drop all default capabilities and add only those that are needed for its execution.


Container 'RELEASE-NAME-netdata' of Deployment 'RELEASE-NAME-netdata' should add 'ALL' to 'securityContext.capabilities.drop'
|
Expand...https://kubesec.io/basics/containers-securitycontext-capabilities-drop-index-all/
https://avd.aquasec.com/appshield/ksv003
| +| Kubernetes Security Check | KSV003 | Default capabilities not dropped | LOW |
Expand... The container should drop all default capabilities and add only those that are needed for its execution.


Container 'create-config' of Deployment 'RELEASE-NAME-netdata' should add 'ALL' to 'securityContext.capabilities.drop'
|
Expand...https://kubesec.io/basics/containers-securitycontext-capabilities-drop-index-all/
https://avd.aquasec.com/appshield/ksv003
| +| Kubernetes Security Check | KSV003 | Default capabilities not dropped | LOW |
Expand... The container should drop all default capabilities and add only those that are needed for its execution.


Container 'hostpatch' of Deployment 'RELEASE-NAME-netdata' should add 'ALL' to 'securityContext.capabilities.drop'
|
Expand...https://kubesec.io/basics/containers-securitycontext-capabilities-drop-index-all/
https://avd.aquasec.com/appshield/ksv003
| +| Kubernetes Security Check | KSV011 | CPU not limited | LOW |
Expand... Enforcing CPU limits prevents DoS via resource exhaustion.


Container 'create-config' of Deployment 'RELEASE-NAME-netdata' should set 'resources.limits.cpu'
|
Expand...https://cloud.google.com/blog/products/containers-kubernetes/kubernetes-best-practices-resource-requests-and-limits
https://avd.aquasec.com/appshield/ksv011
| +| Kubernetes Security Check | KSV011 | CPU not limited | LOW |
Expand... Enforcing CPU limits prevents DoS via resource exhaustion.


Container 'hostpatch' of Deployment 'RELEASE-NAME-netdata' should set 'resources.limits.cpu'
|
Expand...https://cloud.google.com/blog/products/containers-kubernetes/kubernetes-best-practices-resource-requests-and-limits
https://avd.aquasec.com/appshield/ksv011
| +| Kubernetes Security Check | KSV012 | Runs as root user | MEDIUM |
Expand... 'runAsNonRoot' forces the running image to run as a non-root user to ensure least privileges.


Container 'RELEASE-NAME-netdata' of Deployment 'RELEASE-NAME-netdata' should set 'securityContext.runAsNonRoot' to true
|
Expand...https://kubernetes.io/docs/concepts/security/pod-security-standards/#restricted
https://avd.aquasec.com/appshield/ksv012
| +| Kubernetes Security Check | KSV012 | Runs as root user | MEDIUM |
Expand... 'runAsNonRoot' forces the running image to run as a non-root user to ensure least privileges.


Container 'autopermissions' of Deployment 'RELEASE-NAME-netdata' should set 'securityContext.runAsNonRoot' to true
|
Expand...https://kubernetes.io/docs/concepts/security/pod-security-standards/#restricted
https://avd.aquasec.com/appshield/ksv012
| +| Kubernetes Security Check | KSV012 | Runs as root user | MEDIUM |
Expand... 'runAsNonRoot' forces the running image to run as a non-root user to ensure least privileges.


Container 'create-config' of Deployment 'RELEASE-NAME-netdata' should set 'securityContext.runAsNonRoot' to true
|
Expand...https://kubernetes.io/docs/concepts/security/pod-security-standards/#restricted
https://avd.aquasec.com/appshield/ksv012
| +| Kubernetes Security Check | KSV012 | Runs as root user | MEDIUM |
Expand... 'runAsNonRoot' forces the running image to run as a non-root user to ensure least privileges.


Container 'hostpatch' of Deployment 'RELEASE-NAME-netdata' should set 'securityContext.runAsNonRoot' to true
|
Expand...https://kubernetes.io/docs/concepts/security/pod-security-standards/#restricted
https://avd.aquasec.com/appshield/ksv012
| +| Kubernetes Security Check | KSV014 | Root file system is not read-only | LOW |
Expand... An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.


Container 'RELEASE-NAME-netdata' of Deployment 'RELEASE-NAME-netdata' should set 'securityContext.readOnlyRootFilesystem' to true
|
Expand...https://kubesec.io/basics/containers-securitycontext-readonlyrootfilesystem-true/
https://avd.aquasec.com/appshield/ksv014
| +| Kubernetes Security Check | KSV014 | Root file system is not read-only | LOW |
Expand... An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.


Container 'autopermissions' of Deployment 'RELEASE-NAME-netdata' should set 'securityContext.readOnlyRootFilesystem' to true
|
Expand...https://kubesec.io/basics/containers-securitycontext-readonlyrootfilesystem-true/
https://avd.aquasec.com/appshield/ksv014
| +| Kubernetes Security Check | KSV014 | Root file system is not read-only | LOW |
Expand... An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.


Container 'create-config' of Deployment 'RELEASE-NAME-netdata' should set 'securityContext.readOnlyRootFilesystem' to true
|
Expand...https://kubesec.io/basics/containers-securitycontext-readonlyrootfilesystem-true/
https://avd.aquasec.com/appshield/ksv014
| +| Kubernetes Security Check | KSV014 | Root file system is not read-only | LOW |
Expand... An immutable root file system prevents applications from writing to their local disk. This can limit intrusions, as attackers will not be able to tamper with the file system or write foreign executables to disk.


Container 'hostpatch' of Deployment 'RELEASE-NAME-netdata' should set 'securityContext.readOnlyRootFilesystem' to true
|
Expand...https://kubesec.io/basics/containers-securitycontext-readonlyrootfilesystem-true/
https://avd.aquasec.com/appshield/ksv014
| +| Kubernetes Security Check | KSV015 | CPU requests not specified | LOW |
Expand... When containers have resource requests specified, the scheduler can make better decisions about which nodes to place pods on, and how to deal with resource contention.


Container 'create-config' of Deployment 'RELEASE-NAME-netdata' should set 'resources.requests.cpu'
|
Expand...https://cloud.google.com/blog/products/containers-kubernetes/kubernetes-best-practices-resource-requests-and-limits
https://avd.aquasec.com/appshield/ksv015
| +| Kubernetes Security Check | KSV015 | CPU requests not specified | LOW |
Expand... When containers have resource requests specified, the scheduler can make better decisions about which nodes to place pods on, and how to deal with resource contention.


Container 'hostpatch' of Deployment 'RELEASE-NAME-netdata' should set 'resources.requests.cpu'
|
Expand...https://cloud.google.com/blog/products/containers-kubernetes/kubernetes-best-practices-resource-requests-and-limits
https://avd.aquasec.com/appshield/ksv015
| +| Kubernetes Security Check | KSV016 | Memory requests not specified | LOW |
Expand... When containers have memory requests specified, the scheduler can make better decisions about which nodes to place pods on, and how to deal with resource contention.


Container 'create-config' of Deployment 'RELEASE-NAME-netdata' should set 'resources.requests.memory'
|
Expand...https://kubesec.io/basics/containers-resources-limits-memory/
https://avd.aquasec.com/appshield/ksv016
| +| Kubernetes Security Check | KSV016 | Memory requests not specified | LOW |
Expand... When containers have memory requests specified, the scheduler can make better decisions about which nodes to place pods on, and how to deal with resource contention.


Container 'hostpatch' of Deployment 'RELEASE-NAME-netdata' should set 'resources.requests.memory'
|
Expand...https://kubesec.io/basics/containers-resources-limits-memory/
https://avd.aquasec.com/appshield/ksv016
| +| Kubernetes Security Check | KSV017 | Privileged container | HIGH |
Expand... Privileged containers share namespaces with the host system and do not offer any security. They should be used exclusively for system containers that require high privileges.


Container 'hostpatch' of Deployment 'RELEASE-NAME-netdata' should set 'securityContext.privileged' to false
|
Expand...https://kubernetes.io/docs/concepts/security/pod-security-standards/#baseline
https://avd.aquasec.com/appshield/ksv017
| +| Kubernetes Security Check | KSV018 | Memory not limited | LOW |
Expand... Enforcing memory limits prevents DoS via resource exhaustion.


Container 'create-config' of Deployment 'RELEASE-NAME-netdata' should set 'resources.limits.memory'
|
Expand...https://kubesec.io/basics/containers-resources-limits-memory/
https://avd.aquasec.com/appshield/ksv018
| +| Kubernetes Security Check | KSV018 | Memory not limited | LOW |
Expand... Enforcing memory limits prevents DoS via resource exhaustion.


Container 'hostpatch' of Deployment 'RELEASE-NAME-netdata' should set 'resources.limits.memory'
|
Expand...https://kubesec.io/basics/containers-resources-limits-memory/
https://avd.aquasec.com/appshield/ksv018
| +| Kubernetes Security Check | KSV020 | Runs with low user ID | MEDIUM |
Expand... Force the container to run with user ID > 10000 to avoid conflicts with the host’s user table.


Container 'RELEASE-NAME-netdata' of Deployment 'RELEASE-NAME-netdata' should set 'securityContext.runAsUser' > 10000
|
Expand...https://kubesec.io/basics/containers-securitycontext-runasuser/
https://avd.aquasec.com/appshield/ksv020
| +| Kubernetes Security Check | KSV020 | Runs with low user ID | MEDIUM |
Expand... Force the container to run with user ID > 10000 to avoid conflicts with the host’s user table.


Container 'autopermissions' of Deployment 'RELEASE-NAME-netdata' should set 'securityContext.runAsUser' > 10000
|
Expand...https://kubesec.io/basics/containers-securitycontext-runasuser/
https://avd.aquasec.com/appshield/ksv020
| +| Kubernetes Security Check | KSV020 | Runs with low user ID | MEDIUM |
Expand... Force the container to run with user ID > 10000 to avoid conflicts with the host’s user table.


Container 'create-config' of Deployment 'RELEASE-NAME-netdata' should set 'securityContext.runAsUser' > 10000
|
Expand...https://kubesec.io/basics/containers-securitycontext-runasuser/
https://avd.aquasec.com/appshield/ksv020
| +| Kubernetes Security Check | KSV020 | Runs with low user ID | MEDIUM |
Expand... Force the container to run with user ID > 10000 to avoid conflicts with the host’s user table.


Container 'hostpatch' of Deployment 'RELEASE-NAME-netdata' should set 'securityContext.runAsUser' > 10000
|
Expand...https://kubesec.io/basics/containers-securitycontext-runasuser/
https://avd.aquasec.com/appshield/ksv020
| +| Kubernetes Security Check | KSV021 | Runs with low group ID | MEDIUM |
Expand... Force the container to run with group ID > 10000 to avoid conflicts with the host’s user table.


Container 'RELEASE-NAME-netdata' of Deployment 'RELEASE-NAME-netdata' should set 'securityContext.runAsGroup' > 10000
|
Expand...https://kubesec.io/basics/containers-securitycontext-runasuser/
https://avd.aquasec.com/appshield/ksv021
| +| Kubernetes Security Check | KSV021 | Runs with low group ID | MEDIUM |
Expand... Force the container to run with group ID > 10000 to avoid conflicts with the host’s user table.


Container 'autopermissions' of Deployment 'RELEASE-NAME-netdata' should set 'securityContext.runAsGroup' > 10000
|
Expand...https://kubesec.io/basics/containers-securitycontext-runasuser/
https://avd.aquasec.com/appshield/ksv021
| +| Kubernetes Security Check | KSV021 | Runs with low group ID | MEDIUM |
Expand... Force the container to run with group ID > 10000 to avoid conflicts with the host’s user table.


Container 'create-config' of Deployment 'RELEASE-NAME-netdata' should set 'securityContext.runAsGroup' > 10000
|
Expand...https://kubesec.io/basics/containers-securitycontext-runasuser/
https://avd.aquasec.com/appshield/ksv021
| +| Kubernetes Security Check | KSV021 | Runs with low group ID | MEDIUM |
Expand... Force the container to run with group ID > 10000 to avoid conflicts with the host’s user table.


Container 'hostpatch' of Deployment 'RELEASE-NAME-netdata' should set 'securityContext.runAsGroup' > 10000
|
Expand...https://kubesec.io/basics/containers-securitycontext-runasuser/
https://avd.aquasec.com/appshield/ksv021
| +| Kubernetes Security Check | KSV022 | Non-default capabilities added | MEDIUM |
Expand... Adding NET_RAW or capabilities beyond the default set must be disallowed.


Container 'RELEASE-NAME-netdata' of Deployment 'RELEASE-NAME-netdata' should not set 'securityContext.capabilities.add'
|
Expand...https://kubernetes.io/docs/concepts/security/pod-security-standards/#baseline
https://avd.aquasec.com/appshield/ksv022
| +| Kubernetes Security Check | KSV023 | hostPath volumes mounted | MEDIUM |
Expand... HostPath volumes must be forbidden.


Deployment 'RELEASE-NAME-netdata' should not set 'spec.template.volumes.hostPath'
|
Expand...https://kubernetes.io/docs/concepts/security/pod-security-standards/#baseline
https://avd.aquasec.com/appshield/ksv023
| +| Kubernetes Security Check | KSV029 | A root primary or supplementary GID set | LOW |
Expand... Containers should be forbidden from running with a root primary or supplementary GID.


Deployment 'RELEASE-NAME-netdata' should set 'spec.securityContext.runAsGroup', 'spec.securityContext.supplementalGroups[*]' and 'spec.securityContext.fsGroup' to integer greater than 0
|
Expand...https://kubernetes.io/docs/concepts/security/pod-security-standards/#restricted
https://avd.aquasec.com/appshield/ksv029
| + +## Containers + +##### Detected Containers + + tccr.io/truecharts/alpine:v3.15.2@sha256:29ed3480a0ee43f7af681fed5d4fc215516abf1c41eade6938b26d8c9c2c7583 + tccr.io/truecharts/alpine:v3.15.2@sha256:29ed3480a0ee43f7af681fed5d4fc215516abf1c41eade6938b26d8c9c2c7583 + 'netdata/netdata:v1.34.1@sha256:f6cac082c234ac0fac0d0d464a4b4fe68fe3ec53d18a03b553307c8286e92f0c' + netdata/netdata:v1.34.1@sha256:f6cac082c234ac0fac0d0d464a4b4fe68fe3ec53d18a03b553307c8286e92f0c + +##### Scan Results + + +#### Container: tccr.io/truecharts/alpine:v3.15.2@sha256:29ed3480a0ee43f7af681fed5d4fc215516abf1c41eade6938b26d8c9c2c7583 (alpine 3.15.2) + + +**alpine** + + +| Package | Vulnerability | Severity | Installed Version | Fixed Version | Links | +|:----------------|:------------------:|:-----------:|:------------------:|:-------------:|-----------------------------------------| +| busybox | CVE-2022-28391 | CRITICAL | 1.34.1-r4 | 1.34.1-r5 |
Expand...https://git.alpinelinux.org/aports/plain/main/busybox/0001-libbb-sockaddr2str-ensure-only-printable-characters-.patch
https://git.alpinelinux.org/aports/plain/main/busybox/0002-nslookup-sanitize-all-printed-strings-with-printable.patch
https://gitlab.alpinelinux.org/alpine/aports/-/issues/13661
https://nvd.nist.gov/vuln/detail/CVE-2022-28391
| +| curl | CVE-2022-22576 | MEDIUM | 7.80.0-r0 | 7.80.0-r1 |
Expand...https://access.redhat.com/security/cve/CVE-2022-22576
https://curl.se/docs/CVE-2022-22576.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22576
https://ubuntu.com/security/notices/USN-5397-1
| +| curl | CVE-2022-27774 | MEDIUM | 7.80.0-r0 | 7.80.0-r1 |
Expand...https://access.redhat.com/security/cve/CVE-2022-27774
https://curl.se/docs/CVE-2022-27774.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27774
https://ubuntu.com/security/notices/USN-5397-1
| +| curl | CVE-2022-27776 | MEDIUM | 7.80.0-r0 | 7.80.0-r1 |
Expand...https://access.redhat.com/security/cve/CVE-2022-27776
https://curl.se/docs/CVE-2022-27776.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27776
https://ubuntu.com/security/notices/USN-5397-1
| +| curl | CVE-2022-27775 | LOW | 7.80.0-r0 | 7.80.0-r1 |
Expand...https://access.redhat.com/security/cve/CVE-2022-27775
https://curl.se/docs/CVE-2022-27775.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27775
https://ubuntu.com/security/notices/USN-5397-1
| +| libcurl | CVE-2022-22576 | MEDIUM | 7.80.0-r0 | 7.80.0-r1 |
Expand...https://access.redhat.com/security/cve/CVE-2022-22576
https://curl.se/docs/CVE-2022-22576.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22576
https://ubuntu.com/security/notices/USN-5397-1
| +| libcurl | CVE-2022-27774 | MEDIUM | 7.80.0-r0 | 7.80.0-r1 |
Expand...https://access.redhat.com/security/cve/CVE-2022-27774
https://curl.se/docs/CVE-2022-27774.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27774
https://ubuntu.com/security/notices/USN-5397-1
| +| libcurl | CVE-2022-27776 | MEDIUM | 7.80.0-r0 | 7.80.0-r1 |
Expand...https://access.redhat.com/security/cve/CVE-2022-27776
https://curl.se/docs/CVE-2022-27776.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27776
https://ubuntu.com/security/notices/USN-5397-1
| +| libcurl | CVE-2022-27775 | LOW | 7.80.0-r0 | 7.80.0-r1 |
Expand...https://access.redhat.com/security/cve/CVE-2022-27775
https://curl.se/docs/CVE-2022-27775.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27775
https://ubuntu.com/security/notices/USN-5397-1
| +| ssl_client | CVE-2022-28391 | CRITICAL | 1.34.1-r4 | 1.34.1-r5 |
Expand...https://git.alpinelinux.org/aports/plain/main/busybox/0001-libbb-sockaddr2str-ensure-only-printable-characters-.patch
https://git.alpinelinux.org/aports/plain/main/busybox/0002-nslookup-sanitize-all-printed-strings-with-printable.patch
https://gitlab.alpinelinux.org/alpine/aports/-/issues/13661
https://nvd.nist.gov/vuln/detail/CVE-2022-28391
| +| zlib | CVE-2018-25032 | HIGH | 1.2.11-r3 | 1.2.12-r0 |
Expand...http://www.openwall.com/lists/oss-security/2022/03/25/2
http://www.openwall.com/lists/oss-security/2022/03/26/1
https://access.redhat.com/security/cve/CVE-2018-25032
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-25032
https://github.com/madler/zlib/commit/5c44459c3b28a9bd3283aaceab7c615f8020c531
https://github.com/madler/zlib/compare/v1.2.11...v1.2.12
https://github.com/madler/zlib/issues/605
https://github.com/sparklemotion/nokogiri/releases/tag/v1.13.4
https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-v6gp-9mmm-c6p5
https://groups.google.com/g/ruby-security-ann/c/vX7qSjsvWis/m/TJWN4oOKBwAJ
https://linux.oracle.com/cve/CVE-2018-25032.html
https://linux.oracle.com/errata/ELSA-2022-1642.html
https://lists.debian.org/debian-lts-announce/2022/04/msg00000.html
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NS2D2GFPFGOJUL4WQ3DUAY7HF4VWQ77F/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XOKFMSNQ5D5WGMALBNBXU3GE442V74WU/
https://nvd.nist.gov/vuln/detail/CVE-2018-25032
https://ubuntu.com/security/notices/USN-5355-1
https://ubuntu.com/security/notices/USN-5355-2
https://ubuntu.com/security/notices/USN-5359-1
https://www.debian.org/security/2022/dsa-5111
https://www.openwall.com/lists/oss-security/2022/03/24/1
https://www.openwall.com/lists/oss-security/2022/03/28/1
https://www.openwall.com/lists/oss-security/2022/03/28/3
| + + +#### Container: tccr.io/truecharts/alpine:v3.15.2@sha256:29ed3480a0ee43f7af681fed5d4fc215516abf1c41eade6938b26d8c9c2c7583 (alpine 3.15.2) + + +**alpine** + + +| Package | Vulnerability | Severity | Installed Version | Fixed Version | Links | +|:----------------|:------------------:|:-----------:|:------------------:|:-------------:|-----------------------------------------| +| busybox | CVE-2022-28391 | CRITICAL | 1.34.1-r4 | 1.34.1-r5 |
Expand...https://git.alpinelinux.org/aports/plain/main/busybox/0001-libbb-sockaddr2str-ensure-only-printable-characters-.patch
https://git.alpinelinux.org/aports/plain/main/busybox/0002-nslookup-sanitize-all-printed-strings-with-printable.patch
https://gitlab.alpinelinux.org/alpine/aports/-/issues/13661
https://nvd.nist.gov/vuln/detail/CVE-2022-28391
| +| curl | CVE-2022-22576 | MEDIUM | 7.80.0-r0 | 7.80.0-r1 |
Expand...https://access.redhat.com/security/cve/CVE-2022-22576
https://curl.se/docs/CVE-2022-22576.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22576
https://ubuntu.com/security/notices/USN-5397-1
| +| curl | CVE-2022-27774 | MEDIUM | 7.80.0-r0 | 7.80.0-r1 |
Expand...https://access.redhat.com/security/cve/CVE-2022-27774
https://curl.se/docs/CVE-2022-27774.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27774
https://ubuntu.com/security/notices/USN-5397-1
| +| curl | CVE-2022-27776 | MEDIUM | 7.80.0-r0 | 7.80.0-r1 |
Expand...https://access.redhat.com/security/cve/CVE-2022-27776
https://curl.se/docs/CVE-2022-27776.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27776
https://ubuntu.com/security/notices/USN-5397-1
| +| curl | CVE-2022-27775 | LOW | 7.80.0-r0 | 7.80.0-r1 |
Expand...https://access.redhat.com/security/cve/CVE-2022-27775
https://curl.se/docs/CVE-2022-27775.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27775
https://ubuntu.com/security/notices/USN-5397-1
| +| libcurl | CVE-2022-22576 | MEDIUM | 7.80.0-r0 | 7.80.0-r1 |
Expand...https://access.redhat.com/security/cve/CVE-2022-22576
https://curl.se/docs/CVE-2022-22576.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22576
https://ubuntu.com/security/notices/USN-5397-1
| +| libcurl | CVE-2022-27774 | MEDIUM | 7.80.0-r0 | 7.80.0-r1 |
Expand...https://access.redhat.com/security/cve/CVE-2022-27774
https://curl.se/docs/CVE-2022-27774.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27774
https://ubuntu.com/security/notices/USN-5397-1
| +| libcurl | CVE-2022-27776 | MEDIUM | 7.80.0-r0 | 7.80.0-r1 |
Expand...https://access.redhat.com/security/cve/CVE-2022-27776
https://curl.se/docs/CVE-2022-27776.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27776
https://ubuntu.com/security/notices/USN-5397-1
| +| libcurl | CVE-2022-27775 | LOW | 7.80.0-r0 | 7.80.0-r1 |
Expand...https://access.redhat.com/security/cve/CVE-2022-27775
https://curl.se/docs/CVE-2022-27775.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27775
https://ubuntu.com/security/notices/USN-5397-1
| +| ssl_client | CVE-2022-28391 | CRITICAL | 1.34.1-r4 | 1.34.1-r5 |
Expand...https://git.alpinelinux.org/aports/plain/main/busybox/0001-libbb-sockaddr2str-ensure-only-printable-characters-.patch
https://git.alpinelinux.org/aports/plain/main/busybox/0002-nslookup-sanitize-all-printed-strings-with-printable.patch
https://gitlab.alpinelinux.org/alpine/aports/-/issues/13661
https://nvd.nist.gov/vuln/detail/CVE-2022-28391
| +| zlib | CVE-2018-25032 | HIGH | 1.2.11-r3 | 1.2.12-r0 |
Expand...http://www.openwall.com/lists/oss-security/2022/03/25/2
http://www.openwall.com/lists/oss-security/2022/03/26/1
https://access.redhat.com/security/cve/CVE-2018-25032
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-25032
https://github.com/madler/zlib/commit/5c44459c3b28a9bd3283aaceab7c615f8020c531
https://github.com/madler/zlib/compare/v1.2.11...v1.2.12
https://github.com/madler/zlib/issues/605
https://github.com/sparklemotion/nokogiri/releases/tag/v1.13.4
https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-v6gp-9mmm-c6p5
https://groups.google.com/g/ruby-security-ann/c/vX7qSjsvWis/m/TJWN4oOKBwAJ
https://linux.oracle.com/cve/CVE-2018-25032.html
https://linux.oracle.com/errata/ELSA-2022-1642.html
https://lists.debian.org/debian-lts-announce/2022/04/msg00000.html
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NS2D2GFPFGOJUL4WQ3DUAY7HF4VWQ77F/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XOKFMSNQ5D5WGMALBNBXU3GE442V74WU/
https://nvd.nist.gov/vuln/detail/CVE-2018-25032
https://ubuntu.com/security/notices/USN-5355-1
https://ubuntu.com/security/notices/USN-5355-2
https://ubuntu.com/security/notices/USN-5359-1
https://www.debian.org/security/2022/dsa-5111
https://www.openwall.com/lists/oss-security/2022/03/24/1
https://www.openwall.com/lists/oss-security/2022/03/28/1
https://www.openwall.com/lists/oss-security/2022/03/28/3
| + + + + +#### Container: netdata/netdata:v1.34.1@sha256:f6cac082c234ac0fac0d0d464a4b4fe68fe3ec53d18a03b553307c8286e92f0c (alpine 3.15.4) + + +**alpine** + + +| Package | Vulnerability | Severity | Installed Version | Fixed Version | Links | +|:----------------|:------------------:|:-----------:|:------------------:|:-------------:|-----------------------------------------| +| curl | CVE-2022-22576 | MEDIUM | 7.80.0-r0 | 7.80.0-r1 |
Expand...https://access.redhat.com/security/cve/CVE-2022-22576
https://curl.se/docs/CVE-2022-22576.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22576
https://ubuntu.com/security/notices/USN-5397-1
| +| curl | CVE-2022-27774 | MEDIUM | 7.80.0-r0 | 7.80.0-r1 |
Expand...https://access.redhat.com/security/cve/CVE-2022-27774
https://curl.se/docs/CVE-2022-27774.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27774
https://ubuntu.com/security/notices/USN-5397-1
| +| curl | CVE-2022-27776 | MEDIUM | 7.80.0-r0 | 7.80.0-r1 |
Expand...https://access.redhat.com/security/cve/CVE-2022-27776
https://curl.se/docs/CVE-2022-27776.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27776
https://ubuntu.com/security/notices/USN-5397-1
| +| curl | CVE-2022-27775 | LOW | 7.80.0-r0 | 7.80.0-r1 |
Expand...https://access.redhat.com/security/cve/CVE-2022-27775
https://curl.se/docs/CVE-2022-27775.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27775
https://ubuntu.com/security/notices/USN-5397-1
| +| libcurl | CVE-2022-22576 | MEDIUM | 7.80.0-r0 | 7.80.0-r1 |
Expand...https://access.redhat.com/security/cve/CVE-2022-22576
https://curl.se/docs/CVE-2022-22576.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22576
https://ubuntu.com/security/notices/USN-5397-1
| +| libcurl | CVE-2022-27774 | MEDIUM | 7.80.0-r0 | 7.80.0-r1 |
Expand...https://access.redhat.com/security/cve/CVE-2022-27774
https://curl.se/docs/CVE-2022-27774.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27774
https://ubuntu.com/security/notices/USN-5397-1
| +| libcurl | CVE-2022-27776 | MEDIUM | 7.80.0-r0 | 7.80.0-r1 |
Expand...https://access.redhat.com/security/cve/CVE-2022-27776
https://curl.se/docs/CVE-2022-27776.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27776
https://ubuntu.com/security/notices/USN-5397-1
| +| libcurl | CVE-2022-27775 | LOW | 7.80.0-r0 | 7.80.0-r1 |
Expand...https://access.redhat.com/security/cve/CVE-2022-27775
https://curl.se/docs/CVE-2022-27775.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27775
https://ubuntu.com/security/notices/USN-5397-1
| + +**python-pkg** + + +| No Vulnerabilities found | +|:---------------------------------| + + + +**gobinary** + + +| Package | Vulnerability | Severity | Installed Version | Fixed Version | Links | +|:----------------|:------------------:|:-----------:|:------------------:|:-------------:|-----------------------------------------| +| github.com/prometheus/prometheus | CVE-2019-3826 | MEDIUM | v2.5.0+incompatible | v2.7.1 |
Expand...https://access.redhat.com/errata/RHBA-2019:0327
https://access.redhat.com/security/cve/CVE-2019-3826
https://advisory.checkmarx.net/advisory/CX-2019-4297
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3826
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3826
https://github.com/prometheus/prometheus/commit/62e591f9
https://github.com/prometheus/prometheus/pull/5163
https://lists.apache.org/thread.html/r48d5019bd42e0770f7e5351e420a63a41ff1f16924942442c6aff6a8@%3Ccommits.zookeeper.apache.org%3E
https://lists.apache.org/thread.html/r8e3f7da12bf5750b0a02e69a78a61073a2ac950eed7451ce70a65177@%3Ccommits.zookeeper.apache.org%3E
https://lists.apache.org/thread.html/rdf2a0d94c3b5b523aeff7741ae71347415276062811b687f30ea6573@%3Ccommits.zookeeper.apache.org%3E
https://nvd.nist.gov/vuln/detail/CVE-2019-3826
| +| golang.org/x/crypto | CVE-2022-27191 | HIGH | v0.0.0-20210506145944-38f3c27a63bf | 0.0.0-20220315160706-3147a52a75dd |
Expand...https://access.redhat.com/security/cve/CVE-2022-27191
https://github.com/advisories/GHSA-8c26-wmh5-6g9v
https://groups.google.com/g/golang-announce
https://groups.google.com/g/golang-announce/c/-cp44ypCT5s
https://groups.google.com/g/golang-announce/c/-cp44ypCT5s/m/wmegxkLiAQAJ
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HHGBEGJ54DZZGTXFUQNS7ZIG3E624YAF/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/J5WPM42UR6XIBQNQPNQHM32X7S4LJTRX/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QTFOIDHQRGNI4P6LYN6ILH5G443RYYKB/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YHYRQB7TRMHDB3NEHW5XBRG7PPMUTPGV/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZQNPPQWSTP2IX7SHE6TS4SP4EVMI5EZK/
https://nvd.nist.gov/vuln/detail/CVE-2022-27191
https://security.netapp.com/advisory/ntap-20220429-0002/
| + diff --git a/incubator/netdata/0.0.1/templates/common.yaml b/incubator/netdata/0.0.1/templates/common.yaml new file mode 100644 index 00000000000..a6613c2ce21 --- /dev/null +++ b/incubator/netdata/0.0.1/templates/common.yaml @@ -0,0 +1 @@ +{{ include "common.all" . }} diff --git a/incubator/netdata/0.0.1/values.yaml b/incubator/netdata/0.0.1/values.yaml new file mode 100644 index 00000000000..e69de29bb2d diff --git a/incubator/netdata/item.yaml b/incubator/netdata/item.yaml new file mode 100644 index 00000000000..58b648057a4 --- /dev/null +++ b/incubator/netdata/item.yaml @@ -0,0 +1,4 @@ +icon_url: https://truecharts.org/_static/img/appicons/netdata.png +categories: +- utilities +