From ef288913727cf8dac40e6caec31da488f95a0f36 Mon Sep 17 00:00:00 2001 From: Tom Date: Wed, 8 Aug 2018 11:34:24 +1000 Subject: [PATCH 1/8] Added ADR for viper config decision --- doc/adr/0001-record-architecture-decisions.md | 19 +++++++++++++++++++ doc/adr/0002-user-viper-for-config.md | 19 +++++++++++++++++++ 2 files changed, 38 insertions(+) create mode 100644 doc/adr/0001-record-architecture-decisions.md create mode 100644 doc/adr/0002-user-viper-for-config.md diff --git a/doc/adr/0001-record-architecture-decisions.md b/doc/adr/0001-record-architecture-decisions.md new file mode 100644 index 00000000..24f85c0d --- /dev/null +++ b/doc/adr/0001-record-architecture-decisions.md @@ -0,0 +1,19 @@ +# 1. Record architecture decisions + +Date: 2018-08-08 + +## Status + +Accepted + +## Context + +We need to record the architectural decisions made on this project. + +## Decision + +We will use Architecture Decision Records, as described by Michael Nygard in this article: http://thinkrelevance.com/blog/2011/11/15/documenting-architecture-decisions + +## Consequences + +See Michael Nygard's article, linked above. For a lightweight ADR toolset, see Nat Pryce's _adr-tools_ at https://github.com/npryce/adr-tools. diff --git a/doc/adr/0002-user-viper-for-config.md b/doc/adr/0002-user-viper-for-config.md new file mode 100644 index 00000000..f7e545d2 --- /dev/null +++ b/doc/adr/0002-user-viper-for-config.md @@ -0,0 +1,19 @@ +# 2. User viper for config + +Date: 2018-08-08 + +## Status + +Accepted + +## Context + +The solution was built using a custom toml configuration solution, should we standardise on a library for less maintnance overhead? + +## Decision + +Decided to use viper as the configuration library, as it tightly integrates with cobra which we already use for helping with command line integration. + +## Consequences + +A few known issues around managing missing files with viper, but our process is set up to always have a file available so it shouldn't be a bit issue for us. \ No newline at end of file From 2ad35bd299ae65163428712aa3c63becdeadda72 Mon Sep 17 00:00:00 2001 From: Tom Date: Wed, 8 Aug 2018 12:47:47 +1000 Subject: [PATCH 2/8] Added contributing file outlining how to contribute and code of conduct --- CONTRIBUTING.md | 58 +++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 58 insertions(+) create mode 100644 CONTRIBUTING.md diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md new file mode 100644 index 00000000..84765828 --- /dev/null +++ b/CONTRIBUTING.md @@ -0,0 +1,58 @@ +# Contributing + +When contributing to this repository, please first discuss the change you wish to make via issue, email, or any other method with the owners of this repository before making a change. + +Please note we have a code of conduct, please follow it in all your interactions with the project. + +## Pull Request Process + +1. Ensure there is an issue linked to the Pull Request that explains what the change is and why it is needed. +2. Update the documentation with details of changes to the interface, this includes new environment variables, exposed ports, useful file locations and parameters. +3. You may merge the Pull Request in once you have the sign-off of two other developers, or if you do not have permission to do that, you may request the second reviewer to merge it for you. + +## Code of Conduct + +### Our Pledge + +In the interest of fostering an open and welcoming environment, we as contributors and maintainers pledge to making participation in our project and our community a harassment-free experience for everyone, regardless of age, body size, disability, ethnicity, gender identity and expression, level of experience, nationality, personal appearance, race, religion, or sexual identity and orientation. + +### Our Standards + +Examples of behavior that contributes to creating a positive environment include: + +* Using welcoming and inclusive language +* Being respectful of differing viewpoints and experiences +* Gracefully accepting constructive criticism +* Focusing on what is best for the community +* Showing empathy towards other community members + +Examples of unacceptable behavior by participants include: + +* The use of sexualized language or imagery and unwelcome sexual attention or advances +* Trolling, insulting/derogatory comments, and personal or political attacks +* Public or private harassment +* Publishing others' private information, such as a physical or electronic address, without explicit permission +* Other conduct which could reasonably be considered inappropriate in a professional setting + +### Our Responsibilities + +Project maintainers are responsible for clarifying the standards of acceptable behavior and are expected to take appropriate and fair corrective action in response to any instances of unacceptable behavior. + +Project maintainers have the right and responsibility to remove, edit, or reject comments, commits, code, wiki edits, issues, and other contributions that are not aligned to this Code of Conduct, or to ban temporarily or permanently any contributor for other behaviors that they deem inappropriate, threatening, offensive, or harmful. + +### Scope + +This Code of Conduct applies both within project spaces and in public spaces when an individual is representing the project or its community. Examples of representing a project or community include using an official project e-mail address, posting via an official social media account, or acting as an appointed representative at an online or offline event. Representation of a project may be further defined and clarified by project maintainers. + +### Enforcement + +Instances of abusive, harassing, or otherwise unacceptable behavior may be reported by contacting the project team at info@vibrato.com.au. All complaints will be reviewed and investigated and will result in a response that is deemed necessary and appropriate to the circumstances. The project team is obligated to maintain confidentiality with regard to the reporter of an incident. Further details of specific enforcement policies may be posted separately. + +Project maintainers who do not follow or enforce the Code of Conduct in good faith may face temporary or permanent repercussions as determined by other members of the project's leadership. + +### Attribution + +This Code of Conduct is adapted from the [Contributor Covenant][homepage], version 1.4, available at [http://contributor-covenant.org/version/1/4][version] + +[homepage]: http://contributor-covenant.org +[version]: http://contributor-covenant.org/version/1/4/ \ No newline at end of file From 58df1badb4431a7e08c5e085cdca51644c177514 Mon Sep 17 00:00:00 2001 From: Tom Date: Wed, 8 Aug 2018 13:14:11 +1000 Subject: [PATCH 3/8] Simplified the initial readme file, and moved the technical details into the doc folder --- doc/readme.md | 119 ++++++++++++++++++++++++++++++++++++++++++++++++++ readme.md | 105 +++----------------------------------------- 2 files changed, 126 insertions(+), 98 deletions(-) create mode 100644 doc/readme.md diff --git a/doc/readme.md b/doc/readme.md new file mode 100644 index 00000000..dd8f554a --- /dev/null +++ b/doc/readme.md @@ -0,0 +1,119 @@ +# TechTestApp + +[![Build Status][circleci-badge]][circleci] +[![Release][release-badge]][release] +[![GoReportCard][report-badge]][report] +[![License][license-badge]][license] + +[circleci-badge]: https://circleci.com/gh/vibrato/TechTestApp.svg?style=shield&circle-token=8dfd03c6c2a5dc5555e2f1a84c36e33bc58ad0aa +[circleci]: https://circleci.com/gh/vibrato/TechTestApp +[release-badge]: http://img.shields.io/github/release/vibrato/TechTestApp/all.svg?style=flat +[release]:https://github.com/vibrato/TechTestApp/releases +[report-badge]: https://goreportcard.com/badge/github.com/vibrato/TechTestApp +[report]: https://goreportcard.com/report/github.com/vibrato/TechTestApp +[license-badge]: https://img.shields.io/github/license/vibrato/TechTestApp.svg?style=flat +[license]: https://github.com/vibrato/TechTestApp/license + +The Vibrato techtest app is a golang application used for testing candidates applying to work with Vibrato. + +## Tech Test Application + +Single page application designed to be ran inside a container or on a vm (IaaS) with a postgres database to store data. + +It is completely self contained, and should not require any additional dependencies to run. + +## Install + +1. Download latest binary from release +2. unzip into desired location +3. and you should be good to go + +## Start server + +update `conf.toml` with database settings + +`./TechTestApp updatedb` to create a database and seed it with test data + +`./TechTestApp serve` will start serving requests + +## Interesting endpoints + +`/` - root endpoint that will load the SPA + +`/api/tasks/` - api endpoint to create, read, update, and delete tasks + +`/healthcheck/` - Used to validate the health of the application + +## Repository structure + +``` python +. +├── assets # Asset directory for the application +│   ├── css # Contains all the css files for the web site +│   ├── images # Contains all the images for teh web site +│   └── js # Contains all the react javascript files +├── cmd # Command line UI logic is managed in this location +├── config # Contains the configuration logic for he application +├── daemon # Contains the logic of the daemon that runs and controll the app +├── db # Contains the data layet and db connectivity logic +├── doc # Documentation folder +├── model # Data model for the application +├── scaffolds # Scaffolds for deplying the application onto the cloud +└── ui # Web UI, routing, connectivity +``` + +## Build from source + +### Reqirements + +#### Golang + +Application is build using golang, this can be installed in many ways, go to [golang](https://golang.org/) to download the version that suits you. + +#### dep + +dep is used for dependency management in golang, please download and install dep from the [official source](https://github.com/golang/dep). + +Linux / MacOS: `curl https://raw.githubusercontent.com/golang/dep/master/install.sh | sh` + +#### Docker + +If building using docker you need to have docker installed on your local machine. Download from the [docker website](https://www.docker.com/get-started) + +### Compiling the application locally + +Download the application using go get: + +`go get -d github.com/vibrato/VibratoTechTest` + +run `build.sh` to download all the dependencies and compile the application + +the `dist` folder contains the compiled web package + +### Docker build using docker + +To build a docker image with the application installed on it + +`docker build . -t techtestapp:latest` + +## Continuous Integration + +Continuous integration is managed through circleci and the build on the master branch will create a new release when a new version is defined. + +## Creating a new release + +Releases are deployed and managed through github, it's an automated process that is executed through the CI solution + +To create a new release, update `../cmd/version.go` with the new version and merge that into the master branch. + +The commit message on the merge, will be the releas message, so make sure it contains the release notes. + +A tag will be created on the master branch if the build and release is successful. + +We use semver for versioning, `major.minor.patch[-pre-release]` and the CI solution has been configured to take note of the `-pre-release` tag of the version and upload it as a pre-release in git if it's included. So to release a new full release, make sure to not include `-pre-release` and visa versa. + +Builds will be produced for: + +* MacOS (amd64) +* Linux (x86/amd64) +* Windows (x86/amd64) \ No newline at end of file diff --git a/readme.md b/readme.md index 72b33dc6..03afdab4 100644 --- a/readme.md +++ b/readme.md @@ -16,107 +16,16 @@ ## Overview -Candidates are provided with this simple web application. +This is the Vibrato techtest application, it is used as a simple application to help meassure a candidates technical capability and fit with Vibrato. The application itself is a simple GTD Golang application that is backed by a Postgres database. -The candidate should then develop a solution to deploy this application to a cloud platform of their choice via an automated process utilising tooling of their choice. +The technical test Vibrato sends out to potential candidates is focused on deploying this application into a cloud envirment of choice. -## Assessment +More details about the application can be found in the [document folder](doc/readme.md) -Candidates should assume that the solution will be deployed to an empty cloud subscription with no existing infrastructure in place. +## Taking the test -There *should not* be a requirement for Vibrato to access a candidate's cloud services account to deploy this solution. +For more information about taking the test and joining Vibrato's amazing team, please head over to our [recruitment page](https://vibrato.recruitee.com/) and apply there. Our recruitment team will reach out to you about the details of the test and be able to answer any questions you have about Vibrato or the test itself. -Demonstrate regular commits and good git workflow practices. +## Found an issue? -There is no time limit for this test. - -Candidates should provide documentation on their solution, including: - -- Pre requisites for your deployment solution. -- High level architectural overview of your deployment. -- Process instructions for provisioning your solution. - -## Assessment Grading Criteria - -### Key Criteria - -Candidates should take care to ensure that thier submission meets the following criteria: - -- Must be able to start from a cloned git repo. -- Must document any pre-requisites clearly. -- Must be contained within a GitHub project. -- Must deploy via an automated process. - -### Grading - -Candidates will be assessed across the following categories: - -#### Coding Style - -- Clarity of code -- Comments where relevant -- Consistency of Coding - -#### Security - -- Network segmentation -- Secret storage -- Platform security features - -#### Simplicity - -- No superfluous dependencies -- Do not over engineer the solution - -#### Resiliency - -- Auto scaling and highly available frontend -- Highly available Database - -## Tech Test Application - -Single page application designed to be ran inside a container or on a vm (IaaS) with a postgres database to store data. - -It is completely self contained, and should not require any additional dependencies to run. - -## Install - -1. Download latest binary from release -2. unzip into desired location -3. and you should be good to go - -## Start server - -update `conf.toml` with database settings - -`./TechTestApp updatedb` to create a database and seed it with test data - -`./TechTestApp serve` will start serving requests - -## Interesting endpoints - -`/` - root endpoint that will load the SPA - -`/api/tasks/` - api endpoint to create, read, update, and delete tasks - -`/healthcheck/` - Used to validate the health of the application - -## Compile from source - -### Requires - -#### dep - -`curl https://raw.githubusercontent.com/golang/dep/master/install.sh | sh` - -### Process - -`go get -d github.com/vibrato/VibratoTechTest` - -run `build.sh` - -the `dist` folder contains the compiled web package - -### Docker build - -`docker build . -t techtestapp:latest` +If you've found an issue with the application, the documentation, or anything else, we are happy to take contributions. Please raise an issue in the [github repository](https://github.com/vibrato/TechTestApp/issues) and read through the contribution rules found the [CONTRIBUTING.md](CONTRIBUTING.md) file for the details. \ No newline at end of file From ff62b14145e42d8d71b995e3d986853c97f6fc93 Mon Sep 17 00:00:00 2001 From: Tom Date: Wed, 8 Aug 2018 17:08:44 +1000 Subject: [PATCH 4/8] expanded on the docs readme file and fixed a typo in the 2nd ADR --- .gitignore | 1 + ...r-config.md => 0002-use-viper-for-config.md} | 2 +- doc/images/architecture.png | Bin 0 -> 67419 bytes doc/readme.md | 6 ++++++ 4 files changed, 8 insertions(+), 1 deletion(-) rename doc/adr/{0002-user-viper-for-config.md => 0002-use-viper-for-config.md} (95%) create mode 100644 doc/images/architecture.png diff --git a/.gitignore b/.gitignore index 1304a7c4..1b93d75c 100644 --- a/.gitignore +++ b/.gitignore @@ -3,6 +3,7 @@ *.dll *.so *.dylib +.DS_Store # Test binary, build with `go test -c` *.test diff --git a/doc/adr/0002-user-viper-for-config.md b/doc/adr/0002-use-viper-for-config.md similarity index 95% rename from doc/adr/0002-user-viper-for-config.md rename to doc/adr/0002-use-viper-for-config.md index f7e545d2..666a16f7 100644 --- a/doc/adr/0002-user-viper-for-config.md +++ b/doc/adr/0002-use-viper-for-config.md @@ -1,4 +1,4 @@ -# 2. User viper for config +# 2. Use viper for config Date: 2018-08-08 diff --git a/doc/images/architecture.png b/doc/images/architecture.png new file mode 100644 index 0000000000000000000000000000000000000000..9c8c5dcb23d44eeb6ccc0fa79a2fdbb6806b1683 GIT binary patch literal 67419 zcmeFX1ydZ(@-B=^Ai>?;-5r7icMtCFu($+wcMBeZySuxyxNC5CxSQWO_xw-Qec!74 z0q$09)$YvnOi%YrcTYbZt|)6*8LY1 zD|v@~-qt?!#S@28oxp{SNG7+WT0D@6z`y{95fsp1$euqpysZMTjYv)4>nY-h`!Sue ziu!Y$vhww#jE>Q^rq9@R-sAEm_AO<~;9Bd;6myMrnN#7?Qoa zdpu(&DTzchL#km@5v=*f#EU;3GvZ3BQ+G=swA^=ozQI-|L0iLMgZ)$`q~b<35)GRW zYnf3B^z4!~q{cJS^kNs$?3P!I5%)-VZ5H`BV((-p_l0vNkI;0=RMwI=+WI*a4I$_? zY%UW|OrkY{)}cc!8xf-UdBv32l6H6RI{WdOI43p{*@q-73l_Jkk8gHCbfj0^3 zfC0I-0M=18fS5#w2Q#yOpSt;2Bx@qISnTuF-c_Jzl851dx6%%=U-?%ZWOOczF1ai` zK8x6fYv;Z_PqwhtqTnl0V=sg)6P1HVNJkNy9|?Gs*%RSmYEIo}!srG82HjAsORU0z z!!W(~ImLvJMW^u4_{88^{z&*R9HL|i7y_h^QLy4$3Sp1Jy!?!kGh?v9iXWz$W!}90 zvf}o6Mq*#wKRFVHLA6|dFUF?8jY)yZ5stnrIno*Cz~c1SRNyUsj*G$mibxrPCK}$@ z41ON^vZZv11D45l9`5z|>e)=eUHXWapHzp+1=UUg6H~_5U=qq$glZ3)H%)i&VR>79 zx(tsn=;iCjG}mPJXMf1^Ph`+L@63&O^S)DRoLN^*+FzbY`4W_B8F~C|Zpa`x_&Ayj znXaXM^bshkqPDGSLcDy(1MhU-+%E~93Md+}S7Wn#VvG-~)yv_TYYH^k+)()Fhx(j% z!;S0^#UoWNM*@6woNSu{VP;2A*s&X3^E2n+onCJzdkM)B!~ zsu4RyG4Dsa68#!SP5wnnd^Vn5END0`eb~DYu~c}GyKzaS(3Xqc|F+nLtm4-_WItvO6QgJwQLD@hF7lWC} zI06Ui(XwQ62WrZ%3EL18lDQ!hp}k0wCkT$@?8!usI7&hnqRwj1+RZA>Vkl!B2S)sk z2#=_f{w19eAz7qZq->fxijqu6JEi(Of@>mE%f%BiPNqP`L}pLc6vq_bHvEPz7r`-* znjkzqxb^F{Ln z^TzY5^IYt>6A_rgG6fjZDYI6VR2E1UMDs^h1@lW*{0%%-3s%uq8uNOki3`MCvM zU%R9}I>GG>%$X+*e)mWOs=x@4)qi`8+KQnjsIl)S5S^c%WS(>g*;en14Dpc|lrWSq zDrk_Pit>!Y83Z3(9xRKB#Rg{VAF!n%&o@6s4q85b=#8+LL3&$YtdSqhKoP{m;=s+DY@o zRb^s|N{~v8O61(;q}!yuFnLHhf(Nn{W(I~f)(YMMCMVgcCN~K`tGD>0Tq8>6Sf%NM zguB>y1UHUUbX2Sk))Vz8qcrLQD<%ORi`)K^*G$Sx{!uYDa$k%VjlhaVSq+bEmmsM8&c^Y8jC(Wc~B(~|g(FHP=7vPNF!;EzX+ z+h&EFjkr0oIuYFlpQH2`Bilk=60o|z51bslT+=;HvHGylvF4gTnN^Jc!F)uZg%
gIl5eEPt{!o%kT?Q~G;3b^Q?#=MnKd zsxiHo?Qp`Io6cb|WqJ5CYT4F#{E$9vj)TkQe9|MygXiX*+Ks-F+Luqr!*>j#0NNRg zUk|&nx>Bq{Oxejfekxxs@@k-W;7mp*rCj&AAxXotbG)X!_SBiD>GhRKzDxCuwVK`8 z@`d%m6fYGmH8N#WbGysPJlITJX<#?mSc9|DsFGIq&h2h*;gD9Bj;kWCJig+%JmR;N zo^_4e)5_Ed)JdfVtQuE2mrj?-+so(n&l;RCHszZp^`$m*B@?|9O^rdemgP0SOV^~= zw43ja8w+jCeeYfy+}e8XYtQuE!rWZWqgFj?7YiEQQnxEjT`jW9E4?0q)>9v#E-Whn zzcy#PEvQ!!?nm!C9~s`7@LotC8qOZp^!>W8yPpGZ1B;?1cW(zbC`DAvovoaQ^1?)I z83Y+%{fO>fV$|mr|Mc;OrV`}gYdM%~S^xBs}XRaR0}Q>EKX=+m()u@n8Bi)!t(eW2~`)$RNY2>5hyyP543>ri#uIrugT z8-ir@Zu(LcBL6VihZIPp=Z*exbZ&gUo2pQ#AP8V^m-fWtKDNC^zh@HI>uxsQ4crU3r#@7E_#DH& zA@K=$`tskK#peV-tPni?D$ANbGjGG1zJFgcaj00hs?QTn;jrB39})C-tl> zmU$5qZF>!}AR=Nr3xxkXL^sw*x9~?uKmgM!@$xDderA3<+NiiM?D{G7Hx1eQK%)K4 zANG#mBA7+vpr-@8gQS)-7#ITD-!C{=Miw?07zDJXs-}ykoGh=gy)C1miM^32qr0sG zXfzlYzdJAJr>&`rA+fuyjh!>Ey8!7wBX~i-|28v`68|&A#ae(=Q%;ds)ZWRIn1hj> zk(pHR6EQI{zmtg>ud7)MyXF6^ zWas?vZGkq(^tXqJg^`)*|BKAU((M0->~GJ%$o|>azn0_wI~lK{rMsz(mYAijshu;3 zH9;;8ZvKCk`9FI8htdC{)chYx78Xv<|0eyfuKyza%L=c8lcgz0N`GY`$imO`f3*F3 zJU`Q4LH(ED{-u?FT0v?N{KU`n9~BFJYL)+Z0|OHVlM)kAbq7E7fi}n*O24PmX3;c> zvyp0~U>h3;AF5e*V45~?4!(^5%6wSAd`vWqD5;DWIY_BU;<}}+v4K|7T)2KuGkkXL@}IMJ-oo=q}%7D1N1Jf#ZeOxAz;7*{YAQo4Umt3aE}is zE19EsQ2%NDiOd{i2lL~fer7mqC~q)u(Idg>@M8G?kbwpa{%eB&H^3i&Y;h-FQ>==I za#SIBUg2$HVcO4~&@4#K~y?k8}-?tBJttM4O15Rr3EMVow5)h&#TN zj!c7e@>isY5cgyTaO=L~a^e3G`jIOXV%`I9A*JZQmB$RX6zfmo^1{MJf&0JJ_Y;W1 z9JFx~mx1{CKUx-o2$?<`T1&F{_tY=}df&Q{J*z~mSlRzs>+ce8aM)k}FPK8M@QW`N z12NzacdJ%4=IiTQ90=N5fNz*T$*u2_W%1}69=P0|Pcrw5=i4*jB69@~ia!*@<&>ed z6DORGzpx*PbjP%T&)o|GuF?D7y*`tJ_@5eAP zu^=f;P4`uTD5KMgI_t92#YN20U%!%`LtsX-Sab)Y@#ymM41fEcpE+0;Kh6EU36LNG zTtH?U{ND0{YeqAGl)OHgF|Ku8<%D;Gk}^Ax#S!pKf`Wp&#o6cf^YbgMs7UsCxtCF2 z)C-S_N@#I5AG_QpBd4a8bWLb0?0N8T9{(qe-M-ArVQ=5AO;UcYD6CO!_9y z{m#BC+wt?Ku-nB7+2JI{h$_7VWfTz=3kwTYeGm1dYb)M(FbsGsDd@BnTxN{JLO^8D zbJVD5Xp9MFB@%JF3mX|5o8FgeB_#3dyuMYiIRSPa$R#?IFq8MMot#ZyVzPTFWph~7 zSXpN&n5Sn;UG2N5R*kPYL98-@PUr2Iv2iC0oDK>&fYjQ`X(#LT*Xc@wOh!hA$zpkW zLXM#Jk3dmX!Nt3^H$9eBy{Fj@JAOO>Z?-OP70?6fI*X`*mX0o&U=?7Hmq3xYGt3OnbVA`NkTb76oNVcT)y!{StEtlbET$EhGR^xz9rh|>Q>mS*Q)tGyljpw)gY%LMZ~8Z97MLFG-<*|etx)< zK)AWNN!>yYod8|C*Ut5|A#9r!%5_;K2buewURcidIu>wwW`rFZP-I zNupsE#ar)WbL-kr(L8cW>!O@`ef9SE2;{h4_j~VrJ?ZlOUa4P$n*ZUFHvH6d@zd4E zUBSRVcYc0R##OYeUz}GJPx3TXnm)G8kB~-j+x~1tVSgs~Rr6pfm+4^x&_%CRi;a+} z%Kht@+1XgI)h=~(&f5%Rd2YXe6yyc_Eip2d^e4Ounlc@Ff6V^D$VP`(QDvuIv2eY7 zEg}Mf8eFsf1?cXkRAP#iEZb|He#bCsi&k9+LX%Qq7(Dy&B9Po4}(ja$Aehc8+eF+8j8kd)l2bY#Kzv2DR+URGv@z?lvgn&-2Uf`_Bo;6%^;`H&Hxyi%1 zuG3DxR64UGsoQ=c1uw5Q$M?h{x*pF@NDsBYE*lN|U_3rL0H(lmf$QvxS2o%4Vrg&h zc2b*&C0C=j*Q-AMNwxX0^MaylDYtZdMu0T7%WB5edP2OC(?pP@6doot6?ac_qxc%v zY3mo4s6JJfM#;r0eX6eaJG6vsA4T8GHzHwHhYr~+X7I!NzA_Cpz|@@XRHm7tvr5LH}CRNMtR zyk3*K4Rv{3KU~`jd5Ec3>X3wo!y{M08fk1CDN`Wxz-98?)c&Dd_B?7obHK2X}LQtNqV^^{BH zhtO0*LVW*0CWFZoAH{<6xavz2f&g|)vN;uhx(zcYRziH39T-KYvn-exPxH|0(qj;PzoA1Z^c}u95>rgbUdzR7bwyGv1Cbs|3_cEQp z3-m|&>zzaSfb11FaLuS5b!hz>aDWOvHz_qW3fbvmV#N_|c%&vF#c)cQ4hL!)8g(;^ zkB4s`NQVz9`-`h~!5uI3@bK`#?j2g;OMKeV+0H+^*tx&&$vP&RV5p8#@nAS%^4(IO z4nuaYH7rGkHl9s-m{m#m2t(6%|W22*{FO6r{ zhh48qi^5VDoi9Xje0E*BX0o}I@ZsTq^n7CNHlcAcg#Nl~Mv#r@ka0+l^!W@9_{syQ z)Vx1k4z#ccHB=B(kM}Ubd#XNb-(b9UWGE{xmT>#}bXp?xW^ZZZGMWuoCyB&l_~9;~ zl%A*5BG(j5YoqFpaA}=<{hN0=S%bm;f+l_r<1;GE^_M}r?EJfgXEUi-gp|i$20VJo zR1KdeP{UrDMXM}q;#))^_wIwGSWPa8)9PG14_!Mv*t>Jv+xeFpT{BHLOsP^5Y;E^nMTG-leLf3-=?)iWvo|TqHxp7Z@q(^08$Aav}D(-1I z&ERQtM@)){MKX(_xhfI?CmQQy@Wz#@kTCSi{&1@Ta0JQk5i(uSC&c@z2iEjzXMp(u zkA?)xeXcGBlXt~*0|#VovPD4Qn7JY=@DULr!{Syx4tI-3(QUQCIh1uSgAed!a^$#j zA#df>w*AvNbhqk5lmtO-{I%v z5lfb@YCJxjzD13J7xCrJzS3~FJZ*HoSPL%-~@C92M4nn_PVF@x<*8R z%Y)fap*tC_f^+EBDFb}D#6HMxhKN2|);v!bP?4DIU5;j#mhw6#?=R`IOg!_O)j0{N zQ#z>1D5`pCX53rJz6xIxUq!&kfS*4*);KK`YQhH`y{+p~TuZ2zigjO)2dsPPs+5s8 z#6Km)vkyV0i*i=6^ub~kenD-*M4S&YCv!(4YhXF{3a2`e6A0qbWTy~D>uOo1sp`54 ziTK=gpQu32XCC&+q|X=%_;Tx&ocCl3a$`D}AU~fPJm|em2XYP0I6Db9{2AtLG^M3Z za}!+KSxdfv3aqVFi34&0-txS!%di)IKN(y8{3%M{=0;iBZNQvye2Ihx6KJoo-B-JF zDzDbrSk@qcjrc>3-kt$==89^EA(_#*uaekjIa+ z4mUZI9Y;@9pyslr2#*v5?qL@f(*C$Pg{XWT3c4+;&vFfZ>E3&8Rg3u?Q ziFZ$nO5cBW6B0UdTTh*yg-a%Nl{Xs%-FHx~a$RD(KO5onwVL`T^+xyu(l`NqB$YE@ zP2>PG01yQyWFj99W(OJ0CFLQ(?eqj@R>QA$_d<~PHi$WGT`1wau3-J|_%hs#T z#UewL*2nBDYgQ>yO4Ft%T5*8Kb>`-~#2_&_-TKIRh%^5EK)Z)CIRnGzV)vfk5bAzz zVK;nM|GJ}M-N>ytu!5ofeDNxdr;k^=pr^r?(z1#aP#iDXF9>cvQz<4wNTCaQkXWf} zzzY4DHY(Y{o=TUIkx7QY7oXM8b#0*6saFg^B%qZ?tvg zFs6yv$YZ^GcXx-@zT2f=r6|lrI~;i5?7D6SnjU3^D;19R#^vtf3Lo{?LjRVP9Cx&wJVPV_+@4iBFIV_LJf zXF^eVaL)a(=kYWaQkS51n&eL14sEP4Dd&I@wvK{MTs9aqR_+L&kOhWhKU{}lLW}Hk zF)m2gwW&zI)J~`5B@mYB_1x!l=&FQF(HHm-8TO^yUXXr&EsaG$%NGVNMZ2F zQ`5a!ySe4T>-*xt05LN$DBu$$Zd(W7o(bm7=~{EXW?uAEPNCq_M`AJde*qMtn$|6} zZ>;pJl2udiSj}+A?HyfYnaJ-mFN(rSlce9^zu7Nk1GisJD!+e;zI3p3ygB-@B7=|L zqr*Xg5)LO$yih=C^8%Zu?Whx$d`kuwz0>8G?Gj!_LsdpaeFcmH%|giBlU%~%$f z5Fcymd}4U&)dh^Q)_X1dPX5CuP4`Rqn=|Oy5Yp4m3_C>meV=-5bTSCgj+oVg#zk4C z|1_E7Ybr&F1NDsiH$S2soA&I28}P+RB8eHfFFcVdxlCz=SD{zlZr0>1e z_-m_2UL_tk!t6O_Rw7X9bN|W8R4XNEwm|sF(TwQzY2DNa0bs2(>5kC_*I0MtHKSUl z_(*_;L}w>o)D-3Yi{lm|LB35+Uf+^ze3|&c{&i}!`M#<+8bq~bzDLAbRj5k(@iB{2 zXS;l@!ouiwovYJ5dtCA>JKce)>hI2hF2390>Q%u+b0jATZT7%dk9T1?-B z4{n*UrX>zktLcV}NCX(gDv7X2RK5)i|4fr~g|WBnIKlj0ghgC9#GI%uW3O<2_9>TWI z2mxC3(ccYFpKg2Em+EaBQcGBb5{Z(0mfH0i?0q})&FSOqfu=O#obQd78q@7ogF&tB z=4=%(jA!2&o_2wzrt_SZhK+78zDA!kaS`x0Q5Udu@>V~QHJ{E-qOJj?2IQ~)>=5K; zA#5BUqu}6B)9urbfV%u$W&hC|!XI6prx&EU455yhy1bUq0%6uExf6-uUhKa>ix zXqb#s8&*a}?>a;pxWzJ>mN;FCPh?0JA|VY=Nm3tSvsTzSZBq*V3awuz2Hnalru!Y? z%pH}xsst{F?>)WmtI0gEU-%Ht+s`ybsc>h>Ug8k>yFU3&?M5P+WR4eUimq~zcwadD z*=Z(zz)jdLDKG{x@d*vpggq?llY@@1uwyR%*q;Vqwyhzbdwn;rvxumr7_BTEk;mQ; z^TJEQc&-pp=j~7_ul1|WsyszcPheyZ*%G{Se?eGCDk$o~i5qnZvh2V=z{EXh z66tON<-gCrza1x5IA#wo3!~!MrahdkA{ki(XaOOXn9aL&%N{1CCHL-@qE)t|&39x| z$uJrt&8$>|yk4>adn?ve@#8q@v{1BDD>Bm3N$E@Rec$HgbMs9Ta=-NVdP^lmusrpO z?Lf7BUDm}c4j%P*^kfL;^yCi1C)&06F>0+C2Duutldr^$kjqLA$N6WQ_(Cx}_EKeI z?KWPRgMAGNQ*}6ojH31!eFd^q7;$o@=PF`&YS&wUg;er94VTH8HJ^fVmQ|_1oq$8h zR^tsQv9^|sg@sl2c#VN!s;s)F*e?rc?72LYC(UIuuWWzZk-2=5XKReR5B48aiVY=} zq#TUGfh-!zvodV*eUljB3A(vUPse(~Qk>Q_xT=tX0nZidPOEq_X?m6~;PyBP&#Iv1 z*P`azcG;(wbfB#-7>dQCQ&Lj;-Q$@L=-6N+*K~uFOuOHU&K21!Pqf22dEO2s8uh8} z^F1!oNYc`^)GBpqN5#dZL_yhBj^vM=#3&uMBKsDtY6fVp!r?sK8b`RCIV)PqzT(fsZ9~#&F~KlK)~oI55oK98M5&^NLK5?A|#gc0T{sGXQ=vRshQ=f0P&d z4Jtf5F!@EpcS7&TLC6O%a{ za|4v=j1o+8HmQ>x03nKaU^fB*d{Uda9J2;(@Y(Kp)))KEw=??!fx7*{OuK}T5Kq(0 z$(yaCBMS;Eb6@tp0yzOGN9^$yiGU?CQZn>B6_U7-2A!R}ufLv~q$%ow517Om8TxgF zh%s?sNix846oc!f>Y(S;U4`LvwiRdxZ{K zF}hEeJ@KG)+s{risS{pieYw4)Us?Q)%4hi}CwM66X2_Vd{Q6Do^EA;GHbK}#cM&n+ z>TTDXf=_t#jM{s^uJ;D*?&ern4IAAqvUjSQqt#kd1m?2tr)TmaVjL99-umAQD;POE z8nP2F@8KZ3^uBB__}yB5QZ@tos4{uyPQdG-y9tmqp1~t3Aw0LdNyKVO4jj?(+1l2x zJV8cPBj7KYnZxU7ubFJ!(D)5=BKu;UvD9%5O4DBUeUNrNFQ9>-gWqm@H8qaXrkrdM9VI8@nCrIDe3u{La0KuR@xLqp>czh=<~{uuau+xm za=yy16L&bvC~M#3!6%8xl3LRVYQ87fOy#&iKw|88icCaQ;?}$}KastZ+`&gX=)HnAYUr+- zk-d*e8fB%Pj$f$Y9)~}*<{>Z7R!<8DM%mA2;weqeKRqxuEz&a#duO2j=t$wj$gk%YNdPq=I*^j zlR{HhG0eFoNyw((*3W(sQD4kcU}9ouDRkafh`SkJtEuTbJKQbbUm&cF@uuTbn?i4i zLUwPAcNJeukA~`DR>P5CxTFwM6_UF$=7oPpJ=6`5$sw+GJ@7FR+W2?++ zFF?PyPTm`ecoyB5=J`YVx-;1fGu!^(h;8>`L1c170@_BqJM%5ru^BPiZe1?UuV%3_K?;w|$wbM2+`H)FoojlC z2tPC9+xqGS^oHZU+(LJ^mJuz6V?0LndmbJTCRX{JmHkbT2E}%$txv7GWL72x^M#0u zA0{OoDoz?MwZw}5TC+SmJZW#Nd(tbFy#eKkR^hN20QL{vV2qnSqzqLCiZO3i-#EP8 z6RxpSvXbT}zY-+6m{aF*1vD6W%ppeK@5yG9B#$llKRB7^`W*d?BH+_I8*iyoKWqEC z(JCvqD6+I)Qdrn~&?%i=b+hIUb&DX;!={J56H~_D60E-G#bWkT(>)v^N$IL5f$${m zGyw)4CSKH$z{t~2i-lK_m91J4n-H3fJrs53q;{Dza-MH|QXXF@&u#y3D)(C^4BeTl z-i7DXKtnS&#f~sM%*1S3{rvV09n%MVjT3>s3yBxQD_UVJZiP2y`};HAbVx1@jxno) z%ND_*Xlhl*(;)G*07%;aBrazSBxHwdi}cSJJ+*bt=<%=yr237g+EOwyYNXn}7rp{Q zb#(EvNe8@cdoC)!r5dTwT`aKsMl6m%^pm7`sd-e8Uok4c6;%tsRe0!;Lc;tzD{i3~KC!8V0_RZ|P$kaY%qI_Y z`?=SX@$@-OV$(4ii-Fh>?3^9<3e}Q}84oS&7t!wm(lCADSws*qoR@&UbAjPr(!{Eb3vt$ zl7vD->pum;Qc*@ZkofL#MvHZg3y1U-#yB7FpiaMn5+=HmNS98xCcml1NSm$KQyYlR zwQuqY*>x&g?zO{WcG0EJfu6X$!0_*F))o6a9+_?Gx`!K8-(XdaIRPbzYC>@sQ(H8@ z3BmL8e-KQpHQKJz7R=3&WDtQXAMS1_6TRtTQS2r8g1JiBC9E3Iaf_F&8lQpk%k5pEk%P0 zu|X)AX1pWbx0bc?P3=)T@-vx*&?nXu4`>$x>@fjBMm;0rUA4^`9o@!r>uhU)K9gGL z`N6&?(a9k%BPKN2Y(x9Y1pC&n9iP@V{X>j{Dj zM-CyNbf{!~Mb0k0m&oizg+E(aGHJDA^9{}H`2R{7dGox>``jgoi(cydP5zL%Lh+Mv ztE141ow~UCw z6Vl6n`O&7HlQ@?SuT#d!u6;G)V_Iv*Cn*?FUF|O|E31lo6^|0n>M?2}E}b#XxSmLm ztBfZI7X?6kjmGc8gW?oi;_q7T9$%Yf2Hfge@|G1&ejCiCfr`> zllH5;!q1H~bPxGT$Y0Zu*nlj4p?j-YzFocYpuvzlIFTVkCu(D=Q4%GMIWPG9`=Uvy6V30h^T~<6n)s} z9TaJ?F_>Q`Jx|hm*3Oa5W#l|8xVXBxPRDsv&Y5LK){f+^5u2fiIJ6!u9@SU!s^n9h z({G2`BpSV>c~~MQ3gXVbgoqEUMm`%t0W2 zhKCDJ@-IH97nelku?(11dDVBg3zM};^xk*yWqVw+LEcPWL-W0jS3A+PudrAf|;{(ZHDDi zU2?FEUUKU^1=14D4$S*K)p27Zfp!s8^=QVM)xI6m##Eod0W}cLi_hmK8xo6M>Ah!GWs(`iSBjvy6!32I-)Y_^SucoC^{+lk{7uHFuwLKXAMaEQ;h8a}>ArPFB^ zEaZ6W32G-s2Jvo83!k9@3U|3F|4AR(=}>kLm#_H-fSu-<-5k>)LlKt=4vpPI+*1FG zXP|l)C0|Wi5xHnA3-IKuvWmuji`2mF2(sy-ZQe;rsJMfART~r9-m!rcZt$5(pDe*ar$H`Z8w?qsor5 zgIr;TsM$H9Vii<1Sw}NUpy5+RLw!baLnuqQ>B^Fnjj3ah+T~7l@Mm;cuq0r&nJv#& zT%FK|aOO%BG-48OowuG5bt|I}oCAdw{+0!)K>0lS3cw#rg=b89-JA3P00B;)obMJi zMA7lekhdCSpSABo<+?OE8y2leu5EtwVt!DPq`R;{oD%IAr`LSen3<7|h%}{k%OH30 z9kPCWr#4D=E-3{ZZjd?y)tTiHP9)$FUCAF=w~)6&u! zoq@sltzNE4617)EK_HMN{DZ;^TMPmu&Et} zc|Ek}yjZldZqZV5ldb$2kk?PcOx%?@>0BG$2muC^rMmnSq^)+|3lG1MCYS<+nTSEY z155ZenV$aZX_^JDaKaO_{Ys-xCe$PBaBnaIN(x(n57(Y=M~UNfBIQ_KOR}j#Wq5nR zMowkuw`*V-S*(fgv1~Zi#1aSyhqU)CscEZUYf)EIqpNW=5mV(Gc@V#zaotgpQFE&sBoO|!}*C4(yo@T@7aJSTthNDrbfnj)h;US>rvYJK!r$%@zXJI{jbURRMoB@-C zRQDSqy)rFJ&7#0GC6|ic97-xO#6Kk5nK+1tY}?W(mEfedR(*-|FT9zPC)DJl3YbCVI0<|kPNB8Hp8sZdOpcB@KKpY}Q6N;vqy2{}#% z^VMn62;N@2^@b>~2ufd7qMkfUGX54js>*GU0jdIu`Bd(HeLhvB z>&mhJ2=h17Q$WPG{^wpzSt`uwk`;3=unv+=na58%o(Uv>^XN9I?$0ydjyvsrId`{A|3cRiT zii~{a)ABU#Cy($Gc6`W#WHW<#HG_|bh578yWv#G*!?pTV8uFpNee|~OR)wqSYvI{B z2QWx_F>vlJwFoPhOdYoo${CrU3WUqkY~acJ^uvmlzKZ(C*Y1s(wXW*phX&VNIE#a1 zNZW&nrDV3GgId!ugAh)bHdZV)-1?Q6@W70Y6@$>bLR7Tm4OLB*EI)1XjqKyLF1O4k z$$2%-*@v1FDcif|;tC&eQ;z;s2QoZNt8D$%)3D*>UoPrvbLP|;g) zx(VlxWaY_PgVv{R4;c3NT}q|L_s4J)+a2!cO5CU_Xu^lAP=w!Z>#6a5@{6jA*7Fkr zJUj>%sIONo%6ca0ztr)+@sN{|Q5lUaPi-Z%)_p^~VgnV1|3$fDqag)P7sU+E?2co- zE;a;4@s^q$jrT!$?d1M`u>~uE_@nRvd1`G3PWcMg^WjY9yx-ZW@fEAf(2$+<0_Uaf zQnv22VYBlL%whK@_Y}HFZ~U`U?;snTRFG@?y=g4-l9P+@nPIM2PK7e05_s}(zp$7z zpZeD)rh1hixXvX8_;%Bk{YK99E-^X8S8lB2+HfahxBlk7ju?Hn*RKUx#1*krDkWD} z8bGeorP`#eoGjyGEO^5Xf$xVO%Awe6)4jAOF97kr{luf9(EqAi+UD!_6m=<(yr*87 zkEi8sz1AwX;rl{BT^W-ao=DjP@J?zSd~3Oo_Bhbq6a|R@>9#ZnYzbWgkI!@O*QpqL z{otTyx_~w2xCtd~JZaa%AkQd)jOif8UhlRDB z$&4DSIg84%N*UjjX%ZtR;oLI|@U-4^6~>NE-{=*DO6qwH*!xi60GZLwt`a=_V16iT zJ+XuW+8zbQor`z;m49q#4tVuJ8u1i5SCiYz0?QDIEBT}_axjq@ys<$koAz^Z7aLld z%BSOfwNfKTO}TJ{m{vY3oo!h_YGq-uGP%H9-zwEBlAo#R<5t~A2c^CFOKMrgiLQW0 z)eyzh!dSN2B|ES%Y4(Uz!w;DF%I8(ZC?izoa+}Cw98y?RJQ72&x?d10n1V04X>pK} zloh3kU^^Ssxb9;<#sYl8{EJE&`u!Qv7rF%%7LUC{zU+4g1hQJ~Nov(w+cUk$jfMU_II+CI zH<60cO7)$lGd?$I_OFJO&Au(y!luwg(?;AEaTWq$Svwz|VT|7mH*F+Ob^;cs!E$#$ ztNY`uh|UdEcoFG)YuNkc7eSprUEf3khR-$b4mMlQ_}jktzi9c1JsMlteMh`E)5;!^ ziPb{&;t0!r>$`Eyh+jUIP`^XQ#Kt8O+DiP?btxM9MFhQxjQGC83A>7|IUezET{VrfiN#scvV zg;|puV~)yNS~UCn`>Ym&Dtb z-{iO%jo7(z>gEzN*Jm+wk>uw4BT%j-qH!q#uob>H+KBjPqjfXGMN|jQ{|I|HIyoDx z0K$Zh{F;M%%&R-o4FR-T9egG2K6ms%whU=BJ;CJplDmpVDIb@fo}T6pOH=Kl(W+;U z6)~Y{qUhYwchUNWR;6ouX35j4Af>ow*wN_OfIl{oOc9B-+iX&EjXY?5l#@CV^KOC@ z989%6)&a&jRp7bOFTYteL_ZRKF-4|x0lERg@|k;P$WPZN8j?CXI&Ie)C2aRw!R6+{ z{$0P(2-u-Kzh^$Xq@#+2iJbj*b1zf90vVHAURZspt|Wk%$(R<(T(Q$>K$e+xj|#mw^n_2 z$Yl8J!=cS&E1A@e(I!kpA6KLGeGMnHXH|!Ka%ma!K6m}N_pnA>9usqP@H1XfdAY2( zQzozJC(JjN-`cGkKJYSaSJ(U3peV9t!_{x=SDZ8bLz)v1_mjOkC`+P5E@NWQ5zBQu*$_}2~Qx_74q=edb!DPUrp_@k1W2s!m0ECVP8+Bb3-V zqa~Oa(W>o@_m4f6;~&qX>p$DO+sy6bre|Zy5k5DE6XNIs&GErTM2Y8t=k?2LbAZ3M zHS~G#j$~KN4gb(^wbAw)d%aW90I%sadAM*AWwuTgFxTU?A$qvH`(-3XW@`mSry}r-9_D=*1q4$A)bAPBTcddKn=+UDv zPZ=wd5!!Ufkin{^O5wrAmA@-IoP?>luIjLaFz zjjaA&jXyrm`UCUYFA*?=?!|6X4-v}OlX6v6HA0$Z!S{NWQgoX;XSR$;NohNq^PZTD z^{j;^HpTx#g_19YmB1 zE}Dm-X$xKzg6y9VS`(*+_lp0 zx>>_}9CVjHx6ao^ii*xEg)#2f)6+-G^5rYknJ9^p;%WYLPYmxFLg$#(JMt!k#-%p@ zCTOpdNbb4k9+@|HzC=N}llA7VoJkXp`ojl)DGVra0kP9|-CM*?mR7xtx-ivYVa4#Q z+js23q9YJNU#7!7^n`Y4f;Z z@$vCWiqn3+-ZpV}u715s=(@gKh%_N=FUL1`~%3jyayxNNZ z#{z#i(USZaID}&Ox88hHa$v@I$DMbn(3-Kav5NG$>t*U3QT7g@>+ww@XF7krM7D3= zCTrKOmFus+URJDJC247?ipVXAg0(A0E!((F6CCgMy`=G>go|hE^v$lZvb(jci|g1p zefo@&4jzG&aO}7-%9U&a7Ku!{-mcf%U0+jP=MgZ3-g&ILb*1|QK`&|~ar$AV$Z3oFv4I`2$#FKo=M;DnrFxRo)Nk(gZ1KqqpGS>DRchy`Dfw5aF#Md zn+!W>5*Q^6YO#TOfl|bQNM;OM>TGII#|74=bzl%X&(|r2XEZha?058u=iljm(_@1{ zlMWv`3}WAjKCA($XDa;$Z%GS1kAQEMUf=h}fgm#n+};LN=EAv-NK-@_g7`E^i?gwtdH@%iXX{+> zxc0kU_1E>#WmjW-9fH0C9n(a|#K_z^b7bVGk;3BwCim;@s;4QZa|jqh?;K8Dx{8Bd zKOnsE)Tz_31Kq7Aya^M=D=lS;N143&fN&D71CdulNrwKZJH(%=YUY<+2w=Q0*ayc9 z$AcadO>o#l6R*I3cI@6rx*i&LMsVD>Z@(Nmlq1PFSI?X=U6K)|RVO_L^xx*SZy;a@y%+nz z{h_Epu#0{B_Q}D6*%AwX>+|N#!8y4VK!wG6>!Dz|_4Rd_JZXl8ol)Ba-HT9|th$H* z&&5kh&P&nRvseHY%2~WtLy|+E1jmmT$olo`E}7%4Ao3qQ@<@BQTn1R#m$eU0X0as?*iOeK+#JUImw!VT-L4sRJL#1s%+$Mz3nz-oxvR^ z#}yZhyvN@^P#hqvQ2z$;FWMt5xgU!&|8eniOcil}B$~EMVAB2KmvMvC$4*oh6|JnN zC4;|YyM66LN-!vT4-3PBCnVJNFs&L-_Lm+TEr^nM=FDl?uwjETpQJltnoR205xmFs zdYy-P^&SF-(0d7c*MUvn=0}en!LDVO^4C2RXNjXJwsLXTsvnwOD!xQES znCzRIE&tfws7t3RJOD0YpU~cXFFbj@{mwgb3VyiPe*BS?gP2`YD9**Bq9WCfm(jFn z#>Vv8Yj0pjJYR{lNeax1c~TU=Vf}h}@BR0cpYdC7vB;L+>$B|k)9N;{{*`v<%u}C} z^JwPi(ZjN4%^D>tzT?h2W%lgZ>OHU1Vt$URKnJ|01v(|TwoqF0KN4r&o6^#FUIK=! zlz=feio_xi%!v)sxZ`&53tc2Z)BagnM=X%4Izd~T+R4Qg3txRt?1&i`OpL!yk8^y_ zq`$MP?XKl9%x_+9zU5;*H%CBKz& zzeK68sZ>W1x();7Rbxmuvf=O#9~9(hKi;qt16>bI)O38cckf;$b)@bOk5*DsMyN$3 z>&5H!wRYCil+}TNA@mL`y7bO{uyZ1&ZSW!3bdH0&*6GuyDceq+ska7ubF)*$aOT-0 z9oR6LhfeoO-+1NN;O&+45M}@Bm%o6f_|3}X>wlm6U$v8Gt!d`?KTkdh z3yG1+jLo%A_1M&TQa>UG@x|Z&-~;(|?Wc0rU3W<)!tOGbHWvc?;kB0{bghA1Qc?_w z(+-IKKb2c{1fhyz>zD(F96!_XSZSJj!1L<`Qn)VjI@rqNh<2GKxn8_ z`D3kt)Gklp9|Iz(IRh-ob8>4J&+=JbU?8H7A%Kvh^03r@`ekW3 zkMr?S-<80Oo5UG6Mp_$d#sB0sX)XK!-~Cxyd88i#vQNHM{9}^DKYpY%ITEmQ4;H_$ z1n2=YD18rqw%THL)&7CIM2u2#1X>1=_PhJQ)qO}Eh;YVVhvFfzv^(i~=zgaz&Jpa?w{PE$aU391 zrcPGDUua*?gUH{O*WY+U7A;yR_uv13 z42P+Z-UV|9&K)|Bb^h>&r)9;8mC((Y(kU``g-`d9J`d;l`kD{c;OBjH7CwIb1m%l> zeYke*Cqi>HYOXI?vP6mJIhHuCn65OgR5^YKE)$H{-~ljQ!vfRU2vY znHF~8CpJjaftRKE%u`T`n}(hGa%l~Vk=BX=X*u_y_=k;`z-ix;hQZUM7EYPy0I5AA z*TxNy_tZS6w>jE{QzJeE8u7X>^tiGE3O$x|*%cL*MGrSPNlD2#5}GL~BSy3@I_#{Q z9qsR{Wf(%gLeIDl+A^5w&?M*x!kW@G;v7Un8!}`_dk%IETGz5T;WLs|EwqnG>YOn3 zgVtU-55CbjarZ#!09Wc15xOc}d9e6?leNZ)J7vBvDK1gO`R70XS(%-E@xcdGsN6`1 ztl6jTi!%0YBaTmKtE`W7y3=^(&HMSo9ac8XD&K}=fZhv9@?)R_k~w3B+m{&UhCo-EkE zOGpqFh6kRP#$Df(fTY_cWYJ?%88B38D$CUP;*mOX9gyVC=bI*h0az??r>?@Z(my=$ zusONTLoAx+mRq-Ohd#y$NgFvzX3v_Xd?Dy+xnHk8H?O^efFblt;HW2FO^V7)hvIeY z$|EBqWGdXXra>Wy6CIQL^_R%fBOkF`o{y8r8z5e{`(e@TCNXeVcOFhpwr}4Gt?Njo z;U5AWqEfysLsQiA(H;W-S^5u?93_7CZ?CdOZP4B zCn58vCwRK{9rLNd?svn6^@`jVEL^B002G^Eu0Gv`oB7d+P7J(|$@XWYVcSCzIQr`n zy!hKv7nX`M^Ck%iXc9;5IceJYTWQY!h4?3~l90v!B{gB`80S!w!~InBYXNrBj32dN zu%FDji$QPQr~8o49<|{~>>M9VY9VD4!RvbH@yLZ}US7UBBH~!5UeUO5V=;F|T6MD? zh#rk!m67>%5dwzLT_ABEn4DOTA3p(Y<84w2<)G>CmNXGcM18^jlDl7?lQTv+>#ZLq zm*#lvtt(F4l~==@Wj_?BUV7mr`SjCI$6dmn_cs=*nF`NGj{r=CSp(3!Sw;uJH=x-e)#aizssYK{#btU=%aG= z)mJOxdhgx$=k8P^;XKy#4kLE{QIUmrCYzU+)l(2ZJ53d9P>%pYUrU%6R`?6%;{)3X7 zG)yvQX2KFErM+*g>v=45rCiN-ok3v06T180qw|D)@JXEoG9Nr-sLYx@6N50ReQ@%6 zJy1IXaBp419URX)x$13fw0668)3B9seLpmMldq>_qiF+oSXBEsXj?K6*Tn$k{&>IWi*J^M8F_ zIgEMu;fEpVnW1pv;)Xad+1Zzu!%5fOj{2}Hjw1)ofPtG|8B*|mgjnfknC)$~CmO!T+I#`1D23xCAE~DqLdYqHf z@4B56l*UOD6m6Mzz(nPR7haHhND3bMr?1I0IMLyQN!<9uL=iK|ijlY0!x!{_{nvj& zL1vEJdh0D%q0dyu7R*~;-`^i(cbur(K<688Ky#h8-(ULjmvBzLSg2P(-3y~Ih(Ut> zSK~R*ApsaKdJL!|tvc+&3)f3fJS00qriou!zSM7gT$)e)PW&?-7stY{i+}ksY1sS( zw(}6#XWT3;gC-(NjK8vD;@5xxFiDH0E+_%xv{sGDf%HqwS7*Jo+SXoz?1F5FAIV*fH;lEI=qL#Unb&Vv zE`HH>NyvilOJHJ#G#q>bKHt9&k$bB+=Ke}TCfXsOX77851}4p4{vkuT^<(Tl)#hgp&a)C&eZowz=%7f zrK$*8?+~*iQeg1>=OsAvPH8MVBhAPDCe8c)1D|7O9z97~tM|jy4Vv@Q@0Gf6IHhT9 zZZ`q6i@D5bR1ze3zoiCr4OCOsrv)R zx9(KWAI^Ov!b8MSe@0pg_e10TkoYx0!`(kh{0Gm51DbTWjy)-jdwvZEG=CGnxCP>$ z{#6MaGD4*CoHz?U5&xmH#4-5}X^xXK$8zxVd{8n~`zBIXU~z{(%E~a){L#39TNX3MnSDvkv-!A>mR)US3{-BZyt{ z+UnPox!!|cdJq8^W~w;I4EEApg3^7#a`;0rJcEUN?Q0Lo?YG}9_uO-@OvITQMS~>u z?v~@J=TGCrzTrg3;}DwVtbX+scyRlJ{Nk6tLd^Sl5FMteNr)B+mQ>TI?{>9MEUe)X z4Vv144rpuROgx~e6yE0|u!9ek#;n(+Dd)Qov8TgV{C(n|x=eLw( zM1W`IQBhF}4Q~#VW(-`$C$EEe-3byS(b<)ByEVa*M6FCkvz`{?Fy0?j4 z*O~36^n&%thlr3kJ@)8ND?lqth*4{sYnGzN_P)Q`eJta3S%he|SHTPDD7w z#ia+N{)1bjrJ+y))4wC3bH6D~p~IyN;b-yGOJrD}1Xbio^N|m5zW!GPRzD>EgO-bb z#3CrzO%NGAOKJrENw~(*8_XvABbILgac+-P=ssR{|p8tyrT_YEPi8emex?% zrbDD2RDE0;HhvEp@$X6C_#a8&r2EAWi$~|dHxbVD8_APr&3Qrkcs5d0_+ zuzic^zJ$B>56_)C&(|4$-5W_iYkI>_grh9#+~nouD;+0>q-Mxpop`;zR)03oUww+u zT|1aNKl)tXxnrmD8$A``^${Q_PRvZM*V;JWjdze^RMShVuF=ZZ+7Dq^I~1}oXDt_ zj4!Zt%N98gpAJ)SB*%zuk?=Igr0cD(zhcG%;7gw%^a}?-GX}s3_z~WRv*0q}Ir)SM z6O`v9Zwvs}M}an&jGx{BBDa4aa)$$*qP86|9iALGa1e@Ik1N|~2I5$>XpwqPqPJTy zP4}S|X;WhG_YXgmXP^BG6y~PNJ@?)NG5lz?6V@Vas5W_Ip3!v)48)NDCVA>zyzu-B z^2$pu%D;T?d$N4_a!E=~wzT{q-O$$$fcc_NG?93dbV37Q%2^0PFItZkYOu6ark4zNrJ{KgGfG9nv3>{Un{)P)k7R#y+!<^zW{IKx6A=lBCR?>|#NrL2*m-t`A*%e`3)QfFCX_a&mH1h|k9!dsKe( z$iE?U=n5PKq$o0N-xXU8bj_+;?{)cFT0n1j>(_69&-I_kz4tsI*T9ACb6M7jlbH*X^5^n4Z*g>CksHB!Isb_p2rIh>{60WT^b@H4w%+V&X4@ZW*B{bunG zgt=f1ywE{M1*=){OB^GCgD2u#y#{1|NSxU(NOSHJ5;Wzf5s!tcPp4<%oDmVm|<@k~o+c&x9MiOgatvrGTGUe zszCFL+e88nl7V)1#bK#mkDx9sH4?JqSK^@&?@L?5agA471garMytAECu%z;Ue|hY(rLu%o{nMY9#x6mZJZ2r zyD2IoNpV%XdGjXu>$87FovP$}-}_gXhfP!pXC%X(5~8QZv1>cHQ=+~1=FMB=v7bC9 znQ%byd3dX1Xhu#nB-ySKt4_#M^JZEpNT?j{MtC9+CMA=Brrcytc36 z^ z@K>vf=%$wCeH9vy)Js1n6vL~dj*!qkLF{z8m7kv{JD?|3U0tOjVbY%kLtHcIdfPGo zdj$AyWZG{CT|LAuq*z#Z3LUv!N@1!pWy(}#ibk7CCU176Qg~~NPp$|6b+&6=uiH(6 z;*avo2A|3AzWXkAxI5&buYFw>$m6%@c5%1PI@1L4tvBD4 zS6^MNqPyLA(~VH*8>>iJ6Z>a9#CklD$SIx3%gcwOo7J-B{WZe;Zo26vxN98&J7|Xz zy<$E$J93Zrbmt4O`p+MsI2{t&S}Xpgxi~+66$){M(%Ou;+c*pNL;UTavA0X$@Jw+Q z?v{pK|0}I$pBD+AkIz3ZexsJd*Ly5Nu?Axk042NDY6)n7@*Fk_evKvYPzN%1#NgaL zO`4!dSA$?L%@}{5HMTn6ivD$_eh$4Irj@Aa=a=tmv2n^dlp~urZI% za=u{F^&SZQ*5?V`y)$T|$Vh01A!->ud^kF9x;jhoM#ou`yc#oV_trr1x^h}!1t_s| z0O<}ehEII z_bH$0*Ijp=GHao<#_5Cw0g`(k=JvUg^btW~r#3v@$>K?~9RmF<>u0L(u zOp6le%V7Z*0n!ct5!E)~nQef_Ly)`j8y}1#7x;s3Iq;~oROVoJk1U2RgV_BZIHO6C zrrga?ocj+6O!>C>&G@p^w1&YUQhnRF(uMUOyn3UiuFoOEv?@2UGzkX&cF)BZl!wkf z0W-IqkW8L{QtPBili}sk3Rlc_>w3G+3B7?wU&*6S61r;#k%Ug3EQHsf9YWIuhU%pG z5?6;z-s&I{Id{T!I3rhKO*yGxCb3g`&9-wv!`%pv9`-^>5uaG&wegTmMoDGBSt7RNaQ;2ehkk5tUApyxnI99apKk=^W2@!C>_ZtO*niJ z79A_$=X0d~Z_}mKZ;}L#ykA-ZBc%1z?w=9U{Yh?y>ZN|d# zi4p}S_v?M7i~1Cy6J*^X1o#}3p!V-Spw3J)(nsT*e0=*3%9|a+!J@ppLBvikOLh~v z9(;U=8sHG);K2ikhW5HV_0-eyX31AQt?aG40o_ zTQ3j)%Xj66Km4IAyKcE!0CLfji|;;N_o@8g``?%E|KNvm&DB@Sn6YCoIEEl5u4Ayj zV`S>zfq*q$^c+KCZ;>!qF@zT%kh=GvAs;+lLRbA6cI*?S<>W4D%zi^!p*#mWHz?7) zgB|*};Hc(dsdpqm8rO)B#;wq=a6%G<;~nH>ar(d`bt0^vMS4%Wozh%o-1WOvEtYb!vN<-Z`Z0lJoeZA*v=-Cqb1fjck0(Vha`}QkSG@74H zh0+`2ZZo-G>sfd%%$eE# zIZ9bv@9$d4=IZ{8012IeU%~^iW5@Y=OZGQl`u2a|8g{7!j+g}xbWU;RZ<40Ne-;1O z$r3o>4)F^InHQ`Rsi~9}oYA+2$4g86G;u;{uAZLe+%_fs8K3UdUAd9PnuZY>siaIl z@!as(o!p;kZVvZhx1NJtdsX%~;5nq!j63#-hzRxG8+CK# z3`#5Mwt4gBt#TemloJu4YYObw`$CYe-onOmY~EYBbs?XNfj*<0hg863n(kW1L%hy2 zPbOZ=WXD6|S}&GKGbxH~xRc}RlXdV8m9sWhVjb%0Y9;sR5qbE#-;+VHaVnq*#Yo(p zQ`Ds~)AtONS4;FR>a4uFx<&=$x&8J#)L6O>E?XI6ndW>cciuIv@~s8 zCXHu)Bw>p_mVm)?q^h!tlNJZqMX+!IfiHY|?5S3x?c7+<7e^y33BtpzFs<67+eN^5 z=mY(Xb3Wv}n4COZZoF|Y{FfY6d~@t*t_s*iH?j^$YnasBiAH#Trtdl^wiCK08Vz)5 z>3L;pP;la;q@||HlEsUZEnz#bc%!fFdh@z|hbjx5PiX-seu{6Kv9e>bvmT#Sa}G`p zz@bBjsul3@f&!Reg~P{q5)|R0l%m`~QSjoJV&9O=xd1CGErZ7U3AGRlg%ga3h)8K^ zZC04@d;M^K7RKiLfq?+W4oSVH*OqPd4=cHEt(f^R4d-mqbVaxqOevLt-!+c4>Q zr9btDZG^7D)SXPtL!NW)-MbGS%MxVSvTOUqnFdLaCUT61#z;R*y3T#7W3d5fX4prp z_!-N17|w&}A~ioRUoD6d65=6Bid1!{sHxAkqX(c`4;)=|Tc(Sp=S$_xnX^(-Qli=& zfoN?cdG;v@oj9;B`(%Ii00(nx&k;~Q+d;TAWn*$W{3OI#CH@Hb(v2eCqJm3i~#wre4?0q)m# zr%~OxhvkyUxhvPv(DVT4PJZ^>V?8LWJL@_KzQ(xCWw7)#a|X_W@JNNx!U zm+&cHmXO5h(scA?srzURl;WmB9G{2PbP;USGn76}WqGCLY=#TVHc304Ohsa}j}HzF zgBQ9Ak<)vnCHGAU2#c2RQ8!3%e1_CF`AZ{|>GYWH*Z5tb@_-h}kH!FP#NMc4uansI zj`#|<_v%;dW8%%k_d|vZk?WQ%ldqAH~r}+HTsnc?*un^`$6sZSYq<5k3@p$D- z0X~EP9t=Dj+(EYlM@eYv)eobmEw&u}(cp>T$v* zg&qh=0W6qST9XSeh6hcglqLH7QfS#Z7Zl{ffk%q0TD7V@tf~98-EByB?jr$`_$Xed zmp672$-G}AYk}EbRo0yZt;Nd9bCWXRs#SLUB?v9c^LC!EbMW#yV&7K>W_!ch-srme zp?_L%6jD-hUQR;qqP)C9okfOXQea#3c;amu6ZgE#-v)usAizbVv!PC^8vP|G1R~fW zi4vHY4p*@7G8YgA&G#VnJztx^6rnDS{pH+&(&!tR`hz?%O<@W3-v%};}8%wOQ_cLAyhN)rq_(Qf?h zaAx*I&4RDM5j>2v^M1yRa5+@va4Gn8a5 zu!qBk4x^M(t#XOy<#ja9DPoj*v^F|uezak#Uz)QL+R5egRzt@co#bU+P#r}foP->4 zA$jT|ZIl9Be@;gP3j<1_N-{`O#Aibg9Vp!dnMrfh!h3il{A*r7VD~%38qR~e|3h#L zx&pP?{p+0Os*HmiI#S|qN8!ekgFp$>KbP%=rz3q}v=`}ga4POeO_Y#xgQQq)_1`RR?5A`j=M>J)T^^nZ| z#|J@{%rUlS9mJyN^5|H`4{vz$*07~aQx_85xwQI3(!9wHIJ^8G&(5FxDdZ#|S zZzZ#zv2DeLp=$+4Zwj$KMWbZdYL6IyjD$Ae=h@e&uOrEPGqAsYlPF-LIrgmD5~0Un4NG z5umZ?x`}*m`(gK`3?9ZNOqhUzf&!Cc(@)O!28E+m!`XuyyQUkJpj7f6fiRis2wq;hcVqoYZONJeX2Z}0Oruk=>exr3=g#)Ws@D}yuMjjz=91E5Gb9~7sMKF63bZf6Hx7J-)8f#+kHpiUdmf9Ko|)k7C|&wvu^ug_bG(~ zpMU;&Cfs@v!`xnc;YAD|F`PL^M%CNb)i+x|S^ZQy&0^@bqf%$@rV4k|s4?dBqR;JM zEHP}|#J`4(M6N|p%YIpPbK=`gatm<~P<0TKEikWRM-zj88u#y4eT=yt))~+QJ^(bK!?!~?d#P?4pX`&Qe)?d zNb5-W>cDpqKCqT*_*FcF)7IYgQMmF(a>)e(*3 zMNfMzr_0ULcf?MLv0zf*f^OGSI;;K4%}j@_Fk=QUWgcnQtUn=oTmP<~FUV9Nr{#s_0aAT9-H-`0UM~`O|x;x24w7p-3>YnRND1{CZAKdqdL* zeRXp+jk@+ma4{pA;>i!x$CDrCP12Asw8pf{em2QA(U>+;byE~LngR-SGy9UCc_74d zjfZ?1T%f??^dY!)J_3b*g{vDG_{6Wn(Q7h7`&J>e>QAWJ^cv{yPG7lq;mSP+j_lrs zfv0=Q5#&9?;{iMjb93@vl{br8NbPqz^fvK^Ji6*v6d*BP(^6 zn0jLur>$=fTJl&gDcNU|sAwMBF@cIyXsRcS`gk$ol!Sg-uKrVEP(~$g_$(Q&)-@&f zN+1~e+deArZfPG33GNzM}u|}k132|cX5pQ^3eQ0#dPZIX0 z_D#FD>3t{K*Dt>4VuKIAZ0S-w``q&wH*PG33>jjyo$5$*{djjQt_=OC&L#A~NUUXg zK1w}YMHQ_|^kL$tex&|rI0fo<1?vqja0l7fYZxIQ2-(A>rN(9?8@mO1IoaZj{$9*n zG32}GxvrRU`8g;Xny#gK^>yPWZRpgK(1qA=+NNr@VG3{!>fYiSuc#t2TKnPfjqC<5 z88(>o#lP}#dd2^q`rD37%X$Y~eJ_W<>sSOcnFxl`cX<1Us9kg`Gsb*ELhrc$F_L?z zmJ&LzYf9by`$?_S`<>nMg(>2v8eWl1CVrjR`S!bHP{6iTzkhKa`qBHnSC5`pzj1>> zoZGNr6O+D-!eBCXFSQ9O(e>li&-gHOuGQEQF9|F5x|+PoiVCJDtTmFNC1z~B)Bf*c z&^&Hqwv4@Qqwvwb-kA@Dx$W4o6Uu7VoiUm1sfL#q`tj`RTCkcQJ4eEn*YEe0>^Ew% zb`0kcn1o%}aqEBmg|rG2NvQgUQg2ceI4K3}eNZijT~|A#<&C3Bi<+>^G}MNRse+#d z2eI92(z_z;@WOMDncj*QBeeBZ?*5r@cDb5r_%6)!wgRD&LWaeyg}2Li1bHZ~<$lN* zx5#R5tBjqJy6o!`_T)4tzaVpvI_b>Br-GedyPtXKl|ORC2;}$4HzD0~=6sAT#l`f7 zA5ELP5K|*&VO!t+zB#>#4?{nO`d6yXcy6X4s$pf<74n>zy0+z+bz=VMg0 z4~Ki?&k^o>DI9dd@*LTX(C+yNr*$w)D-L3ln?8?2X4|?7AmTzk{yE zEFW5_;Z6Ly-;Yf0O^Vj}WW0$VyX8xEFH{=qGtWGe$;bv^@uDSo?X?*Msu>6+e(69c z?&$jVeN)$Kd>Hz%T8|Umr2bVrxfr=T97QA><9@7W+stRYA2s=6Sa#tgYV3BA$#!l5 zUKC;`2EA$Vdqhsaz`cJ%noAwQHA&K(KJF>Sv<+Y}-)Sor)cU z`6Km|qCiVifcLJ}r0%JT8aFE4?Rg*$A=}C9Y&#bbaqcUOO=rYM-*3V<=2rMKd!W3U z?r%Y+W6kXVZ-;?o{`8)&+y@t(=`vk8K+g+No7NG2GW{T#neMUZb+7B2ZJF)LkmrrI%mA zuwlbZG8mz$sy?TTugAV#Lq1I$LvKjyC#WMvB{h->L!+JCFaVC!66pj#Z4+N<;`I>7 zf|Z0d@I=x_*S6BS+EomuZkYZ14$#Ja$f)5v(&iov`b~cFT|0N1*m8NGikYhYij0Q2VvD^0m-*mMSRpnG`3MazSnW6Ft1zYXu$v*9zJ7Fu`-skO-I$Dlj;QpI zce!fesy+Z0B~Sr&UyyB}FBdR1SX|(OxtZueniJk`? z1odD2)XiH)upH5-D}i!!1E)%g0%&3+#r!=nbmjU*i(5fInvfoIQybKjJDbcqV{Z`ULUezYEuqoya)j8&t{Xp^A>f zPG((HqLWNd0M3IO5w0$UFDD;WzINP0sH&G%jeR&Biyc=Dk>+X$=95Odw!++$*TR06 zjB(qxEI-qpIhIUZ(6OsmufhlKe}Dn~`{T^B&NThA^%~o^R>{z{^D1;HSxlg@L~H5# z0?_H$u>)?q?GF6yZ~u!!3@w{{)?@>2puPo}uh}dJ{gI#>)htlW6IF(KF8~@Ps93*# zJ=N!u&cnn!yRm>72+3dP9Zc;j_y75upV`smH5~o!Lx?f$;T`YLN$vvxI6=q0ddFYE z`1Nc`^W70Fc>&(C%jq!J6}8OGp6Lt2S5b)2_9duZ^9wTc4M;oZpJ+ee8XP3LU67Kx zWjL*oF7fD-#;5&3&eZb35+IEZIo9Jm9&I$_8kWv>uM)n;*=L_kTY3k)`|i8wN2Xp- zklBz+9kWiWWav_fq|((M_<&AQR_zZ zIdI?rp%@q7op;{C=fChpOqntTJ$m#oeX^Q`qpy(qD@B3UK>@Sji}6%242$Y`r>_qW z$Z5z5R=|hd4K0^@B8$xgQJ_s)S6{_F4fDE1AIe8Em{tck>IEJ-(k?q(E zXW?wr7R}&c-~~84+z9W)pCZs{6vIaSJdmHh(s}HR8rt$hjafN9B(<9`H+sXj1dOcq zEj_eX3cO2R`P{ymRT9R~E%BP#I}OsDpm>r}yty2#q>5K*?zNlRr`Ga2jbD>nnz-;@h4!syYXjJjJ3Ms-yZMK^n0yFl%$IfW(An^x_pSVk^;{*tAO z@!`ywbT%1^M<4wSJxd3g!;haZnJH#&$d!6(?G(^KSr1AvVfv#~m6syyO+&_+{|?u7 zrf1#5)T>LLV!Bl#%JF-YAEYPzP=e500oRbv0UZlyG^f3N>w5?my@%T3Uz-s-^QOWx z@G?sC;}Q0Cg`d$X(g@i5x3!ZcUi~w)C4HsoETgGV(NhAZkuV~@ldKX=clD)iJ8M?+ z31jHmY@<8e)Lv?{7G|%3BPC<6Ao0c6b&!e2^_$wSmj0c_E(Rq#y67X@%b-C6F?a4< zJoC)cm_26}uDRw~; z8M$osx7~g_CQX_|JoxN78l}L8EZtJCrxFDsj9oi@wLb*EyCb}PE=A^mE8(bREc@Jt z5Ze3?ID37bdDp2*?=cY$Zw9b`6KYpIjnK~jC1XDTPyV-n_MH)~DMw((8u&NQg{S{T zXy5lDlsbIOr9dY;Y6IF@vHU|CV5#A2DY45NUcNW>yJXQM(q8kOd=kdc<4F)*OWuL) zxIufVmJrloEkOj@y2NE^tka#|cck6=iYu?g2!a{B^X@zN$xnWabI&;s)23ZUkMu5- zWFx0iZ4mai@ma8+X6Es^?x(L}rE+N}H16%&x8eQw-!n*d7hZHBrcS+-+2SJD$#N1@ ziSJlH-KW$iDGDT%0=%~+t;^P3MF+Ql(}Rr6EO@_$H$*E_}~?_N$Q z%^GoW2?b)MLYk`~jfGw*=xgzuQ?10O$4OiR@=o+JkGHaNRZwCVDv&npw!CR;>|%6c za9W)C1qJx(S8v1EF=Ocz_6EN9z3<_cTW+CO=uxt-1WT7J z!ORb4;_@pl!zGtoV!}Z*ewi3lzb&tcQ*9$k_4niyP|_F1xWUhGw6f|-W>p;mSI#gd zZDF49a5-FCUZV84);8Ii^p{IMe7TzN}5GpOEoqZr2?gI>C3(~QU zruVc=`nxc>R)Bk{7`wW{J*6!bJ7yEVPQIcrS9!zBuB|;KIi>kDj}Jp{zNVm2^pbi= zDtM*!6l2%PN)o%s(N;HcJ8o$$^w1)l!0bN*1`Z-R(IPzY#J@0S&TL$E+2yn^4>M}| zWQ4gjYGRL3*)npCM<-^X)NR_d3C}p=$^Jya|`j&aGc)avlPwz7sf$j5AyXKpOhFwjkx*Vj}RKdYewm|W72<(0p zt`3*NGv;Rqb{@e!(}m2+4e(bUMkuGBk>vd~ylxw`t!q)(eZ$ZA^-@Az8(z%EG3*agoz<-#c# zHhdUn&zgmY9{xVAy6PIL;?JSYeXwDYwyrK>e_wyW7J3uS$i>WMCttU2Ek63_Lwcwl z!Tk?>jgEh#4MLrmcuKwALKBs0w#6tQA=*JrRFHdK1@l|f2sSpSC(?;3=cUB$FZ>l8 zTfR++JeMFfhv+3g5$-X+fvey`I6C&BQ(YF}YG^+$euoZpzk@sP4tTnZM0&6BsCMR{ zhMIuZvL7Uy$adV76c`oirZlZWb92+w*P2V*7<#OR#u6kMgZB^tseQH^>9ms=()thjYfw&A zu|F*fStGuHG&;`(4{TuE`2l#d3*c`Ox5k+YQ7OYHZGND>#Vy=3;IwXXGQnkB>l`}OOGJMX;HFvaJee;$AO z(;so(c^8tL?E+ELq0e?UEt`!vrw~wPIG0C z!;yIn{QG+#uz5CI^p5xRzZi~TH=z3PTGXz7h`=_TkU98f1bkV%dL&#pM5#X<6ebA$ zQxdLzZavd#_dyFIE5@$)b@7{seZBSUJ8@y?8gLEmE_?Uxp+q&p3{so3m9&yMH6n0E z2BH0kb$o>0@N$~7XlBXmM@zJ28DebPqKO`wC%wwqW8}zDL?`Nqr=FUQ2OhYOp77J~ zxzB$A0|yL1yR3Ew6h_jqS*j;HmB(Q{tMBTYPQKEztXj2#cJk*;@`7)D`#a1`G|`w= zlwd+J1X!Glo4Jq-wtKZQ9WvhpWpO z@JzTLj$Vvuyw|3-002M$NklbSe2s}AIw5@cZ93YW31sKP?Mp|ynga}x zt3Z(V7~$WUs+CT)A!-9;mv3YDnq}+?Z}Zb<%j2m+HbaJmkKbBKTo}4G;o$`Gm^Xi+ z*;vPo8;eezJDV|DCS!?_tbt3)%c1>PDp_S}tES3C=5>?0Fj<{QayypBmVxV4^e->3 zATUn_U(3y-jOk4G?%iubzP4`NiUQ&Zr=?}!{`(%lRiC*W*Is)aVPyN5c+3D#qq@ck z8M_4JCNgz%Z5|k;S&8jH~0LSWrL5!}Co_jfgX*~5U|Hv(M-qADX7%InUo z$x?x~#1LDwP3=P_>t`z)db1e17>EWY<~fETQF)C2T||%S=U;e{D%^3#`&jtiDt05b zOeZOX2l1_71;)g%{vB}{p+q-p|(;Oa?ZcSL!_F7syx~2{m z3m4AETf|RLLxmW(Nt;Wxp-eiOPmk9Fr@s`A!|REHSq=vQGn|?9^6fkv zRjy3VGsACED)>*$bLxXONC7ch-nSK%wFtBy2H(hT@D`j0)CS>S`2_LZe`_${T|K@6 z_rUAmE;tJ{bchQRYBsp~G59zBn(^$H!rkvnw7(xl@Z+g)^}G}9M&HeQt^ieZ#xu8n z8(`{o&r*UHg|jJLv^6ugmX*~khOR-_4PF~_ettf)T6M+7jhnELj9uYHf*=)wStJ*2 z%P@8kU5*TzfGT<|N@7hk9BQ&ASc^=w7d-CFnI9O&y>sU-LcuP_%nxTCw;M{HvVZ@6 z6T)`E1s9mPQ(p5voWrX=b2WbV+uxY$U3Jw}_4x3jnV7qZo%iE5aGWpHUlnN&)bAs- zlP_Ps9Dn`azc8fkGW_H5f6-3fADL8TNv-9g2#`sj2d9%uwR%6?`Z)mM_wR@I}dzJua6e6p=t2Gwa!z}UWm>smFM0rj3 z@88eF@Xen;&!p0n%fB2m#0d0I{iZU7ru0|siHRt?j-+)>jzIdG%b=Rlmw5k1D z+s#G$&2N6g#QC@9=K`hC{HoabHghN@T{o|X4jtsRnB9qO*gB@ZBxe4%j64wVW9{0t zc=5#-uxHO6eD6QMk87zVC@3i4;m^g`+AuP_E~Hfy!CkTh&f@vN<_{6x{t|+_J|a~0 zUP=u&5SRK|gez+hE?vY;=1k&QpN*=Z8v)wc+ajE$nVi&9iUP-=fZ2P=bQNb_Lv5ua zJs0j?7r{ZNI9FOW0?QvGirg)5r;UQU^FTPWyCZaH8xz31&U?%aPtQrLe+Jd=w<4G~ z3V!gA&HG-y&<;Jh>h^}yD2CngsdP%@3IP`8yY{en7R`$UGVO=`nQcwZ$tq3Zj|^k1 z6Pe=FLrVaAxxL)1=Py`@l9CdW`*qZ)QB1Ab(R^*2Zc4}P^_%`0HV$)&-;~#)m{7~~ zqv<1v{-tOcts2*1MJjhm?SJ{pUx@X777kGrKV!zL#wNXQ-#*-X?|r!UzWWFn+mQ?~ z;zFZqiVpIN5X0ZHc?({A=|#Nx#%s9Z@~bfQ(o4~Wxy3!i05JCTx=!dfTIfYZg*;pY z>v7cewOtcB)haYj3|y-Jl9IhlYkDKjKId#60y`ULJXeTGcy`Z2c<%~?5A36p&Rm`Y z79h;%8G>DriQh#~j62}!G?-Y8yD2R^jzHnx34wVvd}nwjC&CY{ZyXU zI`XDoQWS_Q1G@7OdgqZ;xxc~#^mKa6Gm356 zGSm_()?ax99zRv>M~bN_+oKztUh~Xmn9~O}O!>wnZuDi*f!fIJaqV}qE*9YjbT6QK zT^{W+^?ky~Bl}7``eOG+X-gG#bSd}Od}>MU=Z$S6?hIWWP-j%^gi7+;Qe2GX%a-H7 z!2_7Y6rY0z4KhIZsux>dpCz(HPlwu;hkiL#v|{Wkw%>{DLp-l->8Ay!kS?9}HgDd{ zc=K0rkPGFaOD?88{4C5Ou*{dg^hMM3(4j-|Kg>oZa2CyviXFGTo*1w`lh^sOWy|pT zYp>z8*Jt2c-};W3!`$3l^S!hKs;BzV4BeVFbU4s8mDY6r{JB`lYfYYfmO-skHZ(bx zsIDRtGTn4)+cgh?qPLh#f}29tAcA0YhJ#t90$bjr#PBRUBYp$VplJloco+Uf_cA5q zMettmYgA_SBg|zPy-vNn77rZs#;xXoE#>`grZ@GJqQFrUF!y=gUM*jhG)kWtPD<{3 zmLjlqF;H0y2M^eA5Z7)6JGbrhIpiTZT58PGo47my6 zzSD3dKz|;2!t>rfm5SZ_JlwNnqLryOk?M7|CmOYChHfX&630%eAX+!9Uyr3rmm9`2 zapE{i?fr~2sNdMZ+21GgRZLBcOK5Yl-KyArC$k@oZOhVFs&FyIZQHgP{PuU>d6&}f zbw+hA$2Ku~sdRq)qaWh!x8KHZfA@QOvtMf#t0enljn&SF4hnk6+3q7EwY~E4D}28n zci(+49Uq68FgQ7`>E7L3RAe$2wQI+?SDu_aRG*g;u66b5)p&`L{^YaIHV$uN#*8s) zd8<{h1n43o zbMW4CmGeFdlq2ZPgS$gtILZhgyZDbZd;Oe;ZSL31%Ixm@Wq3#33WzGO1n(|`T=C-j~@0x@rEUzY|Z#JY-Q*Uc=r))%Ns+PP~N z?zr;~T*E`e0LHrO+G^X+I2BO#Uc0(tU_R=Y=I9@!Z^tK{o&2bfs>Mi{Q25q{^!_vP5qss zz^5o+?msd$-Xyx;YI#5pcydrn6INB239-00x;DKB|MIWHk#jxGUOxmnPX+c(Cu8qJ z6WBoBTug1fgHEe~BS`Db3~!8USCSLm*R8o|57PcGMy{x=3_89g(|cX?k?B`^WvjEH zM^BvHto4~k5nzr?kBS#pfW3LhYd;3{3Ue&JR z*N@N}zO_M%s&6V$}4#5%{L9BKL7j+co6a%ls+XbErJVTP*t(9TP-fZ!PZ6~9N=zXaZ~ ze}#ASEz}5bFWJS7gsQ;6)*sP;*Oj3*XHgv}=aqI0uNedY3E)^|%%3m;E=5>K&PLeFc%_o}nr1b*jN= zX!oy#ciiJ}489tr6#`(1nB!U_Y3-io<$e~)tVYcQO%E#Cf0A(w(f+HwToU>VFT7yV zKj-K7sTXuiXBzR8a2t9F0Ze4eEh^fKeYBy9Qh9kD(5qK(;)q{hJgRr?+D$e5GD>?D z7(H?%y|ahbqwiRvC+n1__H0{{AZ1?{FilIV;Vm6B`Fe;c78Y*88?V1kXw*gc(yd>@ zq)BI>BhlYNl&IBr6+0Ha*EOV?*JrxXqQ|Q58&abCAAtCLYSGIxzg-6L=C^zR|FYlFVP`VDlkZ26-u$6; zFAyl>ZKj5N8_q7b(2hs&3u07<=!NS%yphuSPZ2)!9;J%EAvEF!R0TB0OgBsCJ$b`N z03woc`!ZG7xfBDN_^6{%)L$2(v| z_v@tZwWeHNWTex^SF?+oh@YzWbxafaEO7V*+8%n+)17G{Cx0K6zD|s(h4I|=9aw^z z1;0gb`?GKj{15of|0bPxDkw`xrJe5)klrTGIoK}$kv-^ z7+JNcB1SH$TwdZI&-obBpL`PICydACS6pH2(PFA%^m?c?Wg(a!HsQ(6xB8&Ng!(97 z1dBOvQuTU++ax@!D})R;H#$C9~mdHyEBXziVuM?%FcA z4y=TK?c)d^e3$X*Obt2YN^F`?VbY z_7gSM$;1)8VJAtPE?`tif~7K5N>$f{a}1bvbW{i62Y797lehO}L3BzGr)aYA&G3lzS}?`AR7hJFaS=TLRe-*=>XKDRGw((>pV zK*^ov3bVGj&g9@%zd7lBim9Jys#4#b<`j^FELCN^4~P{{o-JV`NOf3<8Z#Ahf3%`| zM0=CCg#g7QkqaQE{(d$+PR>&_pU~d8ea8+8uJdvDa4Dpz9x`-@$+zCz-o%xmM|b*l z+IGcwRAi@+^H%I;sQO}9ojP?kIj>ds1>(S8d+jxPYgF8uHf~@H^m0y0nBLW6Fp%-< zk^oiodzIMhnhz8FBn?9q6TVbbRGKg?^`W`_h#rqlkOFquNc;564?dusd_Jzf;YI@x zBaKCCVC1nRw*9xCHrvrUgH;*GBa7k>UGUgNUkOTDHja7t02j!E(ksq1#@JLuZI zNT`!7nZw-lgJdFiFtn0@x_tRE?(2m#Ne(etFFSS0i`(=kjG<4TJ{_O`{O9QamuEcO z#hi|{5o*AC$OBqZyvpp^vzh<;?D|0-p@h0_-8w87iMZ~JEJQF&I#5F*7)u@N+_Z&x`JE$JNvx_G_#Bl8>|soNA(7^G z(DNPb;m*GYj**{(KeHPG#I(*xBT^Qf>8d~eB@Y5KsjmM!FzPx+H_$Ve2Z+oJUXymh z&}LqPb~i`wNvQU8=3EnMRyKEuC@rz*TI(dG`qc(0pu4XHHs0e<+U^tjTIzKPlM)(} zU2H$>9495*T=w&XMb3+Xt3>SO5!gF2_y-g7EJ?H-2{3WeB;*(L#ge5<2pjq)3JMCSif4wmyiWCm z5D_f_W130WpK_|u!%HqxQNiQ~b)jMn?T4NC$i#wJ?B%qR&t_!6D;!&A{QA*Hjh$Qz zQ;a;q%veN^_h*R3K=|pI?+fiFK*kExtb2~mJ&Wm6H;u_BhN9XbECPDf2lm6U zX%T8RzJcJL>5Q`-4`1g3q-FO;bx`s0T+`Ijgk>*GG4%$_V5-XLNrBeK%#{sIc5?9^ znE_QI3^VaFVE1#oCx{;?N!be8$px$?gv-{WyfgPM0 zJYG?qU6e}Yt^FahggyWK3wYrE`;kpRd~KeZ7{#woz2p+(4LEP!Jfof;HEJ|QjT&hP zq-(?y^my&X?en^oBG^(f_DKG9!pIV~)SO*Uu-U7x8kd;4?D8vDuE2|oMXY3)oN|)u z5F;=cjlZ?U!^e$&jl7Vte~IP>t39%rh>q#$8OU-mgl)sq@UOZbp_&lw~fRku*X)c;<4(~$X&|i6{ccfF@opg}98R5>u;38b5yJP`^YZ(f+=Wj%! zn+Wfi-_llp5vqM%XooLH7J?=rg`euY>OjO9upw)_kwZ;YPf;L6fd)`O_rLBxsn;d= zWDvsE#*^EhpI{rdRhs>3`=JZT??=Mv0_HKBE;<^Iyk zFPrRHvIXm;bSxXX8Bx@e7?&nQOitOs6k~nqv}tD0B9@9JfDnk*tXW4UxYF3vg-NdX zJ*!@cCT>&{NqH-P7v&+Zq>Wu(-s-dMw>n_^CfZ2iF5a@m#OkkP*xr;W7Z`wk`4y+ke72=n8}s)22s5$HJ?M@kPHJAU*WpO%D94Jt)}Rzv~a_j-ttXHeqR!&MhXYlNvJ^;LaPvG@N$ zhVU+3x)keaCKfKoSUSB4A=MVuw{`7j@p?@dLs#h80}nhv6te}!n_b~(4JjI|)aW|Z zTy@oFjOtxjo$jA37C;-4o>n1~)dx|^nA3EhzP<5?$KS`YHDVvDpF znoyy(Nz?Em9RZbb?4pYUjaj zFj|c_JF~G84t5VhRRlQl(WahLK*rAcrNs<^n}xvIUm{$!p826a2lt>G5b8D#!St?h z_>aI!6QUH%s&%>j)PE5KqTWokqj~5RG5rZA5#=aFa;ES;-=uI zL`;&%r6IM2UvYo6exK;*v1rjEqgfq4ejNIdp<8W1Z2d&^EUpY)9aN{q zthR68f$#s|`}o)6kDL7HO4r$tBF3GSMWrSsTiF~w`e+u;J@*{*Q+sXw5&d3&?Z(L0Iq@?ceL7Uz)f|T;cA?ElgCJBOh2%Z`%+u(` zliStI13rBCaHDCEME*&C6W>=unA7CR(2b62((ot>frK>n^~mgN0mz<4Z3#KNB>FTz zap$)!M`+`p5iWU)w)Syw5BWC)yN^StJ>x;SVBBTJbgEmxc=kUbw0|LdlYR`(q;I1p zKr;z(?3GuV4e6?Oft@DQObsJNf!0R>yEn>bDT{V;Wr))~t)lM|CHa~L>Yi*LY+KT@ zZrQvU3kbn2RMANjC$?BN(S+I16=Y-*cZ)$8_MqLySD)@Fu=suV6=;dTj^=4BhB`9;%Brs5`;g+no!5NoI5* zDoeanv3nhEW_?^thq<@l8vYA7`d^G-hdv0q+rd?_3(oCK7a{>C`gVN#s>w-jvY;xY@eg++rB31HDMCEI{YkwP;R>ECewG>#w}9Z z$p)hhQcO=2#H&v!J9(Umf0D~-ZbWy5x}~EMzF;-{UPcjkvZ-FL zfqO4=K^HLz%+_BrquW5Hh`a@^{#U@C+mBbK-u}oAs_yqj{PKLcaJKJ*+K>|!1f>ZX zpNVK4%}F|w`Z`5{6a|h;0lT;Be$7Z1%3J2A82NF39LFzgKP+=DWhk|@tm~N$yc3+-}W4Jx;atr zhf2%D^)Y#wKe%SBjoFGTDA|^3WoVyTtI#ZIjJG%DKe;w5)UT6FE?TlYvYMjtUjU0`U zqejFXMmBchrHxpyU;+O5&&R2P$;D@`x*BJkdB#y*_&WVm(-U6a@S=->8BNA2J(^r? z`Y)-?Bha#5Mp!Tp^8VFK!#bNdG`$h%eGWo&o^yl(aISk9;dTGbu(b_zkiUr@@KX@Z zqH3+S0-^1UdEfqbxcl4z_k{aVo!OV>qFVZa5E_`+){zLiBjO6c-HT+Wl##!VZU5N0BQ@cS9(DE&6Ne)P3Y_CEG^!U0#ff>PnFCv5A@H{D3v z{)Ie1v^SSJy1s+ZqH^q@;+IZya-0h&O&Ci<#%U_1o|;7gqZy$+U35QOS`J^kLCBam zl3DeF#!Ege?1#Jfedb{Q62cBT%?)Kjn86n#kkyAELVgn_liB-h1UF1VkTL8$nK5rW zW8e=LqlO?g;f!wlhmbElEKW6 z-lJi1jjUL)!oYAV3hAN?rzBj{8$IU6ymvj!(wHCEx*D{Yj_ki5e>?}j{`IeM#~pXz zop;_bp+b^46?-RVwupZ05aZjF=%Er@*L;|Iia!OkUZ^n< zW3OhYn+}ki1ghfs`JUAX6ur!(FN2Xb;Z}sYj7Di0lk>1nEpw`Sv%A34lkx2NXTjCJ z8@2JP5d3%oJcnIy2bd);o%xotl+rbV37?wN_)lNzil;UO?A|C%Zo77w6toEAY@$+< zH!i!U>;BZEthCH%cHe*heZxP_J@;Ib{WFVvOeMO0@_KpVmYSq;x5U?_g*QHB$`sRz z1xm3^{_gj`$6aLd8z`v`A2o`A9ziBzQH=S%lS=7oLn%0AL+{$PJO1^r$8qt+7nw^( zw{P1z*=sEEOG-)%GTWw2MHoy^_~Fbe-YGBQov3S_sEycbDGY5k4=hhT^%S$_48vzX zd$S2!u$qY2`X}qFiCH1MB`UDUCnPPS9kLkS7FhOY1h@WyncHrs zZG92~+1;6?Z73&)_4Y7%P+19F42ARL^(Foy(G8E3BCul)g6r=iV%@E9jl2id9ft6L zTF!$4ug?u5(ui8IW~;i-BHyH*QxrJuDPZ?m!L=#`EsgQy$=>f`_h$*C8`f`N?vO>~ z129h2{Ra#%kxH77*!rz$lA6WPH*VN~d+xa#?|(281qB60ovy)&5$_=EoyyBEzr?I- zSK_r9Gfcd722$+n9i<|hsMGy1oZf|cfV z$>JqUV|SR?@q;16IXUC0#7iVkm1NhIlz4=o z{wXi`#!xQ)b-g|U);Rre?p?xUFEfDBMevUPCh^^e!Cy2F{>{XLubI!#wzC)ymj_pu zN$?Ds3TH+RYL+~X+7DGDT) z0(LKTQ*$cc6@~R$eh|G!C%RYBZR!1v9Xqj@j9gjKh7KD_Sn*NR5Fg82n&_T2?fQ+j zq1O|DgI~OOv0>&43EQ=E7j24>jA}y6vDwqU_VsTgKfeG|7$g4U|N3uy|9k&Q)i)Gsaj& z_4TlQ6+XQH_n&z3No?J^%|P6qfBtzU)K2w{a~of6|Mgj8in^zbUW;7gR$RV9@#IUO zYc}<|jp;+GZiE7w_Zm951-z8LI}z8t<0vLTa4=M@BPI5QsGfh9$%x-%uzRmepf*2wEL>|c_BY!P+m@n{7LlJ7ZQg=jy?Wvrrtt1UEEW5`>f86Nd0Lue zL)XBz(c|x5Pdq`)+9k#ju7dEF`dkkUUd&ov>N{ws_S4R&bf}|w+L2BCqmMqKZM{A1 z5^lq+jz=iP99CCXVK61)X$SB`l`Yy@Ll7 z0qI*uJlo#x-Mfs#+i!pSJB(p${JrnX-Kxpb10feQB`$9t#`3Np?8Ir} zJ+Om}6YH(JFU4K!MLIFS&{aF9sgH>8PHhOF5j$ zUj5KR593?k`X&w@IEbJ8^k?|@@`=yJYDyV>TE%gfOyHy=ZftH+LQ$d+eW7%a6dcX_qm5>-hRE=o%`~ zG^qbFZf__pQVlP7LFHgqNo;#@>-cGMp*jZ3spdQ4NT(s)MNjtwtKlp^h~U9p2o^ty zFgd@&%g?)ihJZ8|qo%_MW@U3CD?10?($%Q>=s|=ItmSDS6XDt-xO!ZMw6ng8+ROno z{giR7h2WM(K={;LSAKfW3ko?k*Qd!cYGcE&8cUPblo-!z4zz!g_sg?dK=m`{z z?4_4ZHF4{U7A~e2|KG56+ctB${QB1)ph}*(v0G%~9mZqc!y7_&SV7~~GIUBMwb>_X zbwppcPV*uaIzRT4_I|$c=8i>XABJhx9;Da%CWM&T%`@y?gu0JMg(I7iJ-YebTJOg=@GpPqOD3_3 zek--Iyx_&y_wLQXVHiR% zfo|Qp*E4h5X0n;7`X(sdNLXK$iC?!d`^oN$r9oSKN48mXVLcVr$;@d7skIk zJZT6W+=1#jQ{kW`$8*VAq-FQz0hb}4l-N^q+!j~csWWEn(<<8cl?hFuXx2`i%u!f= zVegm2hfB%GmtpnlHO9y5>Z?D)%$z;U{bc*By0(5Y`x>vd8l`f#1d?;sOE0~Qn{K?p zsMO_+t*leWBZMS)spZ|2HspNp@WT(`uDkDHm{=Zd@XPRz#~#D~J^eHeQ}u33R%RBy z@Wn6Ci~b&yiAX{`u#b()2=HPq6^X|HhS8Yegpb2&?T_lSw_-+;iH*9lhtg|K& zkECC#foqNDd^So#w+#o#K!ihXi$bhUR5ZZ~Ka+Z1j%E)Nn|;sTeYo%5d&wBbF+M&^N8vu9)a^ruV?_aFZ7 z5tBW~W{VSaYeB!hSTKJ+UVU{&B+QNKnsywQ7EkO#YG^;2T2Jk%UF$UGp=zt5G6ExO zziaBXQ@?8*1?=V_My{g2WjYG;up2Jl#aBu!-3Kz)`fvm@yCJ}EM4rCDfHgQP4Sf)}NmOO%4JC&xo9V4t%Y@d_ePt$mUo|+_~mvb``w)%bd z-D@Ot6H=uO$BMYe>8zNtyvC&}-oO6YMGK7D{1ZkpZSrh~9WQ2M!o8ur4=m@)ru%F#8rE zy5gDTFlX|w%f24f??{c*b22CpSzk_MrhDM4+>X$u_ozl^2wP?@9AoZ>JFgd+_YQ=2 zE{1>gKl$A&aAuzcXa3EEmc0VO^v~REwMIjKkObYN9=_Q7a2Qw|9<^2e!>KU6l&=ez5mC^Gihcj{OtzW^E3okmZD&79xj#K^tYp8->yOuW2 zv<#zdC@9FUU(m7j*<8|!v?vv%pCmlduqAG?qz$%}He}|X>rBwUX>Mv$N{gsXA+|w! z9%}b&MR>!L2yXi$J>u!`KJaI76`T)e*OAQk!kh?YyAeLLi4JpnslcaHo?QTEhkVrf za+vTn3x0-k+I84Uho9=!X-okL5foh*@=HeUlX{&|83YVVc8T3%r8!=^cAddU$)n@7 zgspzms#+M?*!s!tZ=&045<@R5JA%Le{U7+oH@?JI1 z>?y72n{T{fKgI(Od<}OK8-38=!R9kvqcIy=>_nE7>@%>nfBoOT;quF;;nJy7F?1-Q zJnKqqefzmyW7}53nU$+nV;vd$z<~oXl4B5Vye+Zy?dQpOl_$LH>%u2*$$lhbtgW&Q zu2b!Ova4&&XA^bGTfG}K^L~v$;iHtuzYS;qX;jA#GvG7MeZ-Al_bdXNe?&KWs_FCO z7}teRvTG3bGuA!-PB;dC78Tx(s1b~;@wc}cnmRR2t0Y9KQ>P0B%s#@wh=~j3tu-)m zMMrJixXFOS=q^x5wGj~6M-}y1r7=9i{NNOOY7#@2I`_#ZrZf4-9fqMxk`_T5ODqvt zDtN`KOLeUn>)4`eDqg*mK>1THxB!nn`Y6QoRT{#eVkc5SHM3^T#*1|7%b=Fv=9_Oa zaIe-*9$P=QKlbm)`uOBfp}%+T+`*IKQhMm`HcVapv}${H)@&KOSl-`35)fHl07XneK%$=FNb&**^av@S?vgokVYDmu{p7@^%Sk&#~q z_pr|a9S1NpjvzK6dbqEDnautXc!oX#*Z4b77GO$ZBGXCxB8`kt=By-g%F`<~fL2EV zyEiHtN&A{4bNO^6yBxLe^S&zHx|Pn=OHF!HVS@~(PnLjdRBWHy%6``*r#LacT&730 zrK##%5!nLLNChudygt(-qS1*st*ITs%YMK_FyH<6?~>b3aNm%nT>qDf1j5?jCSGRJ*k7g^*8r`HH$@7c2_Ix}_b<}F27ykr@Q zi?3{}T*8cP zf@|$W)HxOVd)ub@un|w6F!o44z04Xkc<>P8slR6R8Z212kPdW(bO0P*uP9Yolg>FK(JImN~<=CijLmhNflF^q)FWUCA=&VP8=x_cyk9fuCYV|nU^gha zetv$795SM5(Hh=2O69H&TShc@?p#csJlP=Zh`?gFmRTiYU}8Kv87kypAJdio;SYbr zSH5zq`ONkycH))R^h4stKSA&HNfRgHy6dmQ06N~;e%jx~v%j&|lsEtK70Xdnv>E*h z3JhcKK;%4?*#5?|A1Aw(+LoC_=9605*HeHcC!<&bzvo=IXm(1cUj%CdJ_5>a02vkF5nPV|QV$D$@ft^oX`gEj#*_$ZorjdbLMs68uGRGUep9&STxOfY_*BKeYNRMH|h8tLJ zfo!R?o?$TO1dA;d>=Wvxl9IMdZKpX@|~D^hYlU;9qH!H{TOGQ z$&{5W`pz=yii%1sU$zv#`~4pbtnBqv#Y|+_f{!*Il|)Z`M5%DJ1ipE*aDx}&;Gx6D z8-B>pAqK1_8T~PXj(Sr6C?uK^q6fUPe)gId|zsgiAIO z7Pg#bapA&e!__f|Xj^3N^y2le{Rd;)KZ2|4=iuyeA;M|t3~%!zxN|AOr60iEkGA&# zSEIt!(Le*Y#73NC@}-)K69p^-m7UyrueUT@t57iamh3gS>zg+h8PratH9cM6TH`cz z<}yuY=!(UDlHp#r(iScIg`{DHnk8fNP-e6}d-mYod+))|fA({#U2ME~*o2TNclz2j ztMJ7yei3I;i;&9$hf1OuxoIToDYiX1rfu3(Nc;L?;~6SU`2PL-*5ez;){nYW!rv;i zO(AZQ*aLhoexHoFO!&Y~p$5$S^Q7fw_>at54yS_}sC2lA5nr=q8A2QWh4Aj_j8`8H z_t0+;`+XezS-qLjtsOGF0r*!uhnl%xfP;oK-=zOVXu$P2T<(t?3hW8)D0=W@X9W1V z)7??urT%DZ6p&D){Nx##>Bd&xQjA=5w|mc_!-uhIg;wj&*Y(PTB+gwzLkvwf$Oks6c_3dvH zMaS6d3e_wtE7QbDD-xixDrH}frBR~)Hgm4^O^t~jD)Nf=gaUBxpG)wW>2MAGZ#ep2 z3V-{aRI8KO^E)qrYy5?an6CA0I9%Ce_*A`j7zsa9yb7Z3SnOIF0eaX)R5kLBS7XOy z`uZYOPFD(Wxv>bY)j@Nn@2ajvN#7@1`#NZ}gl>r`!ux5Xd*zjv>0Nk(8K<(UDJI*hz7sWgog9O7`jIN;JKy;( zRoLU{y*>k72|n{h;=e0{ju@2ft6uFwF(063z?>MyYbo|!vj)o?k8F0 zT7t2QG-}rX`;f6$)iL(gK))86wiatv^Pr7Z5_>w~WPCxw`g$^%d5sQn3|I5&2HZ~R{c0wM=|gQx6>U-SdXHl1yr$X1oo@I%PG)vvN?ukG#N+w5x9*vZ1)!vhQ=ruG4rF=N|NYf`=REfCD^j17>gDzz`g^AFn%o4nvNJ@FiZ5k z>Z+vnBSVHyJvE7;>ne56)x4Sn7Rm_NTQ2jYx33Jb=O^QU}(=g^UNqa zxg?Op_Tf|1Y~Tl$cB(GMxm|d}OP3Sxz7(U!jKL6k$qTeWr6m`z+E$obc{v^D6z9y6 z$T>9)q@IqVfaX9CH&f=i++OlrW@V$tak_su0?Ymn{w=>GH$Fn=_kUyD`i%&77>cT} zJ-u^uWlgX?Jki8xS*!GES+qU^T@BO}e&p&6aUTfEG)b6h8 zs^_Vw=d1qsqmP>r?;CF3Z$Z)PXB4b%H#NWOu&PFdbB8=iv3|$kU&HKF(BA>J2o|#D ziAunr&a+A9`^KZ40Xgd$RNowiX3nWh{+>$Qa|1%%Zgwe_2S1nu1c;1=V#HE7#mFd3 z1S@kBC|R8!HsmE?DJJwjZq=S&ruVCsIl_{#Fcm^{t-TN<75#h8zINup4 z0q^q=B;6^6164?hEt0I$spINZ2rX^S>X+8K)ZDAX1bgi9-E!nFZTT_&5Q0rQu@|!F zA|8bgA)L3ofcGy77&~voPq`_u1)1$rN51ufOVO4)`%^F$MPMmrqnTe$jZhIorV5-n z!7+(JY0+G|<+iI24XBd$pYqgI=OUqHd_GS$P%hE(6pVSytMwUWl75N45r}6EubSd9 zo6qZJ{cdXK)9;N#Bove*fwRvMQa^G?Fa@iaajTAfz8wGoebWz6*uBen%RGs~i!;+Q zWrFptyRVnS=XHk}JI?EN*b@g%Q%&=9D^rCs)|OUD%fu)^v+Y3Pc)PQ_h-Rpc>nkhd zTVjAOfN}X* z?Ff*}ZZ)Hrfo<1}lBlVg0jy-QU)UXVGBACzPI5v3p5q}Bq-B_S*Qy6QR=YG;VVJA! zwz`ftD}P9r25O38{!J}CPL=l1JYjXgm>YeKS>=Qs@R}`(&{mlZ<4K`F$ zzJ1IRo#7(@$^HquTpy6OEl#>#6(zNTH`7Ha0ky_kR_N=6K+7Ol7 z=JOlf(V^0;o$I|@{m4oc0MST~DDr#WQ|G&8t5GHS?Y(1VdS)f2CeE2_RAlot0Wx zn7>u8-$1GGoa7cp+ny~|n@L9eAaD;yHHxXssZcD{nQ+2Gy&=zws+CNv|BzP|SoP#t zJu20WS{^xLmtlYt!P+o$EF7D>CAql%uD^lsto8wu_dx_)cvJQ4V^!c0;>N$6QHq+{uMiPY~u=zoOtFPHUEThsf?y@_J*M}0LuCGtd z{c`2#`kE{*)$+FZe3^NwzhW#+u80ers@N^nAreHrJgE11YbKk{cG3`!BQ|8dO3m&K zY zHxz&V(c4Dp%h(L|1Ma~jPZnjpTe^#TW7?8Vgp`lb`~!?scjP2;*SDHr605X@5~iz+ z9V#7geU_I_;!0CZNLyZ?jhoOE`%2RhjbUVEGFrSDCpWa5jo=HO6Bbv*_37xmlhYRiMpR{mh5h?Pe(yI!u;1>A|4|Myz-r01)<)|rrKF3) zix@aocfFR~fFM0fk4GxL3#sQ5)Z7=#t$^vKF+|8J!%HZ#jE(*ZhlwJYzcseD@?*>8 z2e|``Hr*L(@~2OTh2JbD$r_o*3QK0_l)8RY<>ShZjLO<3y=|Yf!Nq3k_9T3apFe`r zVw2g7X4v0n1=dA=^FH}|iCigiF-ugpxdP)RfZd2ofNIb3hgJk%n*FawFJEM>aEt05uaazheQO`1JRDS90`cV+i~IP~aG1 z&lk&OTwk_dZEt;j@Q4?cbTrzo8Xw%0hDnR0`d87$$%PDq0H>h(Wna8|Gu1pc3f?mu zQRd`&kQCktc)Eu%tdw$s-M$HIm9PBCm#=ghV$at}DzzgtN>umB=Q4GJ>#M8GX9GKh zZAqIK*~IH%<}zFSMAU1tNjx?O3s&3aeq`EwgFPEIkQWEHo=AObc|ZD+#^-d|i1PUE z!sVa%>)U;xVtYAqX8~cSqmG+7cs9~Xb|+j*_-FnH#c31(S?#o;%*k+N4VE|4#dKBC z4WX;;-XQe}rUnxPk+YS8AA2K1xPHWICG)=eG^k%o!K}_MT&{gZq-v+_9Gl)h1YUQ5 zrYeaIE_Ht+brD7xknRqcvz_Ibox$#}3OnD#`M!PQER+%zQt5vMmCoIHJ*)mw(HeR_ zq4`h@PR=Qh4Fa#Lac-g!#gaPf9bhxyY8DKy{hpC^@gM>9m)`-^jCJHq9A#QxQv zQjKe>vI{@(C;u;htM?5~v`JEPxnEZbVt>Q4L`O$1)wCEN@QC1!yOO(uNy7{O-8(Q= z@K_9#1bo+~sB8A_8>WqrEwx|ca^gSqyxXRuoWx_Z7xWojSbjw`C;d~DfML#->_t{> zSGJb1Az!K@0{80&=pxWeas*>~oBTo#Dd;iIA&>UoDvEoQcSjwfaytGsyu#1vlw z=ME{7lWzkB&MNAUPXzpX5XNFo42Gxk5J>P1Smwl*ny&z22p)T5?W)k#jw~)x=RZd- zCF%y(PFM5#3&}7PF0PezCXHAEEZUf^xbI4irk@PAeyaE}VZxvYHz5=3fA>z7bif>6 zeIz9!>RY(b<{qG-OJWR5?mH8JQ4ps}AGU;5D(Ju1f2pg!^BO>vfP9+In?RuyQgB61 z%F?zF(SjhuhDn&gnpKlNoMLVOApc;;SRMOgoumBZ6Nn`?ZvyC>w()WmzJNU1Zy5SZ zql}Q+10uH>cP{B3T8|T8UubtBYk?|yfWce8N$sJE)?!NeIs0lJ#I+&AM*q+SLa?=5 z_t6{+v4k&dtN#P_(4EuCGZm(oqpwR_g=sb~dAc^bpj@Cv>{4noKH)1N zquxf5-?pIfscLtmXkwnP2*Rl@>J_!q@7!c@tcdN+CfB$s{(xpZh+EOB%0S+|uL8eJfYD=!Ur?i*~bZmP6*)_~>qg2f{7xp(#);Q7-5Bu`sl{qJn8< zeHXROoqNJ)b}%2EG0h`=Dde6QxYjg9s;N!VCo~AY#I#|V3!)|=0`8nZKINWmpZnn! zd5Z(AKX7_?J?vFbzq0cEgJK=+-9S(h0sI&2g7h6bIE6&Dj>y~gcD`s2GcQo2ss=HD zb*nfVPZ(@QUd%#nZq_?AZSAdvq&rTHU=4XJ6Em;yxM-nVEzjpoyKD*ePgc&Bp_gpO zphuZri5PBMIClH*vXSV&n)fSa*}aUuH%=mYE1^YIN&O6iw%AGX{}ySg=vkfHVT>#^ zR8=jn6PE0j{cUyH^-1^cwPflb2CBynRY&m84bRh+d8%D`|1I?^_Ecc5_GZ-qSrlbV z#j$!#9&=3(D~&IS5)!`RqrLGm``wW7mm|0P^yZX5tBr3rO0&Cza*%~nNtAX(GEk}C z365f+&m+1;N}ocgtMm311Oc*cD3f&rFs&V>kNf%Q4wv9%Qc0nTf|L?cJJR#yB^(?M zywPn11_E(1mCJl$eSPBG?0)aewTPTwMvzO==z3O?l$a@CIlI^v4xzRu*zNYxGGk1j zRC!syTRnHjSLI^O68S6y5p1U=5vo7TZ=igsJrJO1Fot78rNmZ1liqmEoVGgOgw1Ka zQ_HfJV&3@Nl(Ja}N9fJds@Cr08RlOv{mvY7mBGA47z(O+ z$MOt=sb}8Q1R%{O?F+L$l;=&6dv|6Xox+&x0(tWOT1B?&%j!OVq3RB0g4@AYAG*~ejw^{NRp)`i8R*f~{uc9L#t&pOd)5m} z*jWogtDPpwjO7lbd~O(h>jmYdd{S=nJtx({U&9Q+X`C|)KAgNCQ{ooCd`L!-GPXj5 zErw4$DDgX|ilz9_dx0S^Hfb?E#X~6TJQ>|D2-+WZLY3uY$TsY6hULZ5Q7)64^}_RP zI6wZ5YK_V>kS=@K6YXd&{k8&udEhQ_eH0gTaw=&>#l^* zKcGF~n?}PKe6%6DA7#1SJX8yy=qz+}AFiHV*XMj|fmy`_D7Zr7Kl~W_a!|UVPO+Ly#vslhko4TC&V4#G2w>_f*z@Xx+Xzrr^HY_1f zt)D~tkUUJ)($X58#4@-Q^)g2Aay7-%*4hm6J9!GnTY}E^RU?}x$q9FQ>G!?@6F7L<;aryl{U|aiAzodqochkF+t(+q4p2_^&x?&@Zl*A*NjlV40?JT~R7rRO#BpUI3{@`waKmrb^j#Xq*n zQ6aj2I;*h`q7J9N(aLTzD1zorebv>b?tjn2(*dt1mJvveGwh9~e>E64BqC}Jp+Qsy zr1hq&3$Z~vKc0SdAxYE};|FZeqORV57unFw7ui4^tl5H`>ap56@4L!6fw}e;30|3=w{|(iKuiKMCd#IuQVk3gY(9*-3F(t$G_UP+zNzUGapcn2 zn~Dn4%bOK5w1u0xk}ZUi{^jFp0pYsf$41Q#t|niv(a%6(<$%xdStD$OI>}IcL3?2Yq0O_;#)z4$UN% zi!8Y}XTG23!Z=!S+w{xj*Iw(v~7pyO1?BPFp8fhOfHVKB|t#Tf5vXNPnDs#d)9oW;8CjTi(!e zLyz?X`jAohukq7fL+srI053c~FmuX0!=>ND7}2w{&44o&!OZ0r4`m!+D; zzh;z>|IHsuzzU{Gz?E7q<5yK?c8~**}M!7H0W+X#%eBIco0FOVHskyXO zz;aUAk31SY{p-u_O2+?eyo@z&vuxvbwrMQ`Ypsq>BeBulD%}(|-Zs_rha_BSuu4K< z7_KQeIS@hSCju;qLF)K#kp&cCW`HxZF(m*@cm@(DcTUhNg<>s{&Le?BYg6sQ^UQn8 z=Zc^2!?wAR_d~&xyV<();`6KX%kAqc+iQ~Vh{rh>UKr*8h`r!dDaZR%C28!#hXst; zO>2QTY-J?b8q1N{?z!8wdhw5r6_g3X=G$HFN5@6=LwGxW#(#h$Kc@-Br2Lt8gUUbr z&&;Ejfq0Cn*e{SM>PInx2~IkZ?zt^CYpD7BWJ-gxYYrD#7&3wQ=DnfCNL_u!n)|+{ zmyA;Glqm{z@*cVy1-Nju{neJ#{pl82vMXQkQy9hcwJwv6O(2IYhmw>plJ}w?{Og!N z;&vBuRJSofN|9-Pnw*zRZI$wGR)qL-1s|V}L5{qDw<` zgVpV8&^8n65GbQip|#P6cd(+g{tEAdLb!e>fZW8+K&Hm(;r&4lGARW~IAh5U7^6D` zL}_nl!Cew^cOl74HxoqOQ;uQd5iILGl0DML#md|fioX|k1LjDFRLJ18%~5x)2jHz& zeNbGk?=9;c9`Ibm>4jZgo1CMoT`Rt8Q?G5$sOoG6R=6RfaJ%Y~eJMQT>vtkd+8-q0 zB|-t3vw^VC7R1aR{StP)LB42PLAda%fy0^+dN0VNPdQk5f+fk5m_oDXe`oj^@&OKL za(>$!cAM6aoCGL(uP;+Y?IjYA7i+YQ#PQU ze*5i_hp#)kPjMy!EIl6j(YLN+o)j%9kKE`*nZ(;R~Df=>?$q z$?ph{Tj;C&-p)^bBbXM9{E^mg`#}K1xJm30@*}tRNd}>h1o=(#Q|C()+~s;2k(`%% z0><#R@BHswVAfLlr{Eo{h#DwWi5ZXQS6%T&y9o~qby^`x_3xY^I%9*cb5US0@1B0T z(JppTf{x_8-og6F0ISA0oPOxjMvx#8H*LVGo8iFw z-fp!wS;tgx4o6UG?VJoM80|fS_2c-;A$onkyBQ7aGQ&BNs zq$r+VNWTC4j>Y+_3s#LU;&+2mVWsbdRZc%BSZQHk-gG%DsOfbgN(}w$zJHYeGDw3q zb|iOS<7Vj!`>UxrytzWSPehU^&AIB9_fz$zDo?PRF*`BFT`%f)rVVU#?nXvuH?Lqn zpCDHG3l;ytzTTVQnpDJ_Wo6~KnKsE#EFmE0^Pb8y=i^)5fz4(I>@<0e6m|nVZ1e@u zn*ODkX(lPu^>cp<>Lu!6HDl1na!9|s>XE!=b>CofFJsrPBMsdewJ*7Cf>#h)`+IYu z+M_8f|3jGMYaOVTYfg&&P&2vf71DQoYt7PvfsilAuL$8 zlEKbXFkbafs}-+Dh9+<0(<9X|H~ZS(06`nt+E}j!IheC1ZoMZD#|c0*IEfgbmX1yq zEWoJQy4%JFyS+@#1ScSKVLC#YE)bKy!-{XZm z5r|eRHNIdUtH{rpi-_L335wUq+JP?ay(JNYe(r*5ZlM)L=c9#a0qjn7b4>lbKWyC8 z07hR75J_14_76XVO7H5Mzj509G(*OLkJnyCFc&lUe@f z>D#Osg2#v@0@- zJ?z1T956;mw#T330W?;aQ=^&@7}Wp=JzPj0U>BNd>iC2ErP=Ps;MY18)eRhLeybb; zaFZv8i@S}0$5&Q9ix=wkJj>qG>buTa=zK_B7e6))r{kfVExhx3Lqy*nK4BAmPdJw^ z(fkcR;;wXoWc|H%+2=X;ErSUB*T4N&A8bPSVL{%%hyXoRdcbyXSeJLA{t7?ccX~gH z-r^^by&-GBs+t+RjG13tXO@+NJf3XsoX6|ml@zkpDP7LVKdPi=u1Y*3hlN6TD-L^z z0s+DNKbMcV51sg9rwD^Rg%l$&`t^0YXUJ-;N>B+s;nLRmzez7I`Af4C-)J2P%HAc4 zwxL|IZz5hkZGB_x7XYXW;bxbm_V)^7w|+zP1ztrqe>NL;6lxAqF=rpXpX<10^S#lj zZ@RE_z6d6rxz>Kv^m&+@OSW$hbhOR9xt{Y+c~1ATR~_aoC~0q}_e z5_+y@4_Z`pA)N8H!Cf^eNbs^s_VH7Aw{xqf{wZ+3a+xZ?=L;fj{c%*Zm)klbNm`L# zv`qjhK$md`UJv-V#7(oTLxG;~E!@)FH|*WAs;J4d1f%zTYPaIb)vuAy4Q1FSAUihC zW1B>s3D#ZBM&UykS<^_||=9SnP z`jC9Kpq?~Yn28vF~1U^qH6zOA5zbMVYRThtyITa*TRu=o>$4i(rWCB#vY z25>>~F+=7dJAJ6WjKepRVXR03k({I?XmKST>O?a;VPBcPQ%sOCbdknhW8cTJd@h%@ zy1IjXZky1ljIVD^{tY@kjk7AiE6c5Iy;$aG+!cL}Xh1ry?SDoB2TKHAM0TZ8M%wk; zxj$VZbUv6L&rkci?>cwamLV&7>2{*JUheBi^NQj+YOl_BpOjFOx-vO^A95V`Oc^Cmx65^M8>l!tBg&nuivUj6C%V(yr0eGFUt5 zyucwCXbrS~=tkQ8hareFN>1`_P~$5W!(&39ZpL^5!2=IeTI$_u^;oZDSvUXLa=$Jp2l0eTR7ERXxO z2@RdFI*t0KrR!oU6x$id-hF+SAG;M4glaR&l)FvN&`Fg8A7mpU>V~KPFd@%+*1LA? z4!mxZmSqdq+v*@HepO0^^drtQBEq0?R|-_{ReaZ~IU?jx@_9{*nazGn_iEcF|E5;0 z3qdmhdw!M03Yfec+z`*$wp+<|N3+nh2+i@wN?FD>>27EV{)W|cA8wX+r;RFmQVY)* z6kd$Iehq_Nw5M&K6x^;Cuf8^vm!#MKbcMa8$~l2qeTYczh->QMJ_xNTKvrw8Z^;RD z*LlQ%f5s0R_o|mPyy}Vmhy^BvNWL4*82v;E#nri#hDg72%yqYCwmwbvvsgeOn(FF` zC|%>mTM<0#Ai7BBw$4xiM#iX$p!>;pG={4&{u7iWT|SVG90=Q@`Z|Hw&Y&LfRp6nsxA6jlgTqozD);aeXE3v#*m=@gR;v#E?FSGI%^+X>{FUa7 znt8=WB4J28=r8_lh!E~>8E5%8-Xn782nuw`ksKVsFer z43-tx%myJSfB?P$cldH45%xq{TZC6wN|`Np2DcPz_!h=wOdF1c>z83#OYJyoB#Y~C z2GW1(1+uUKm}2(k5YVE$vO^r^7go*w@PyWJ%OAJmp`w$*sZXDfgm*snsy@=*Jhex< zpPp&`x^Fn)7Wq3QdkyRWhlZ!@sT6&peJuZtC|7jG$Dof!pDyUO#mTvnn4~BRxviH; zH_1PL4%pgMAEy@G>Z?~5cSQt$-K*iF7gX(~a0cJWrLH6QRXh>!{-Q9$=TC&S%)A6SLw%}7HT-m_4;I_U`G1vhBwwCv zC$c7Qow;%#a2m{Z9@Ez@B}-mE_F(oiJQ~-X-15QLKzkSJ%RY10n5Y;SsoL1z09M7UlKe z$wn=PH`ScW`t_>@ug3$0!fQ&>v`THNjtQnzFbAya21mA5KP{@)8Q;=Rm(-@4(W4wG zy!$a|dNe0NeTTcy6y*KMe_*@!f1w<{_$(Xw(Jmh@%6OkQiGKeC>-$83`SmFr*uIql zs${eup<`$ePv4KEZ+)}805_D;M~-ExFH)>QV!zef%;8wQlx3qv z78)VzG-5}v1R8`Spg$j)q?Z8YY&sS_+?^)|DjUQ{%09I^4m32QjE@KeshFmch1`Z8 z10igIs=6p>z<%@k`YZ}L`1x*AGSBOAF-MhtbGi{;-rHec60ii`w2yOc`g$Ke`ng^u z?nG-5@jv1;4kUVAe|dn*yM$*Uvg^m$8L?`LWm;nxQvrr=4@Gcfi4&6V6*n|ayLqU{ zDL0S#ycWrQafP_$(|6K115NEgCnraBPWCb&Jclr(i66FiQY#>sRC8UV2S$gNgFjdh z3k$N}uLPc-ULbG*{_v@+#F(xclExW55Z?`+a3Rg=Ah{}uBxyyxhU*FxqqrL00fr@P z)M$a2(oNMj*{zrLn-IfWdJVtBV?K#XXlYvix2z-K_LR*7H-ZDgK$e?ZHHz6!*b%KK zTbk!20ko~v?^--BcmN!hwt>!&?FxRHo3$hIYIA}PN5* z)MosYlvJRS#)7c{UY!sfbFvraEFD5x)nyf#EPmiA*0OEqB#o5m+f*n<)ogX5{Tqgm zdXDcFXvp8aO?iwF0yCW_qXlzfh?|`&_jUCU49tPoKRD;+qQou~Mbt%PFeB2uyMm(t z%Gd2tT}@4YQGN&T=gbHX%i-e*xz{KQcfXS>3Hu@!vVCcIA1L@2qj??Khq4NDx59+W zt^=m?7z3JL?|whz29UOE={giZB73X8YvqXR6nkgcqNXZ5CHK|JSMG6lY^VJW^g1Um zw6L*|^SE1$K&*Fj#NEEcOpFed(i>(^A*Ri{OKkU1pRA-9B=Y|;eUtfn7(E^r0emRx zWuz5);wvh^Ez7{%Y$^)?s=7M{X*iZvoGPDRl&fM|`{dPxRacDuY9>XJ3+}TB9EgB~ zE~0eo3Xr(S@`cU$iV%J6f?|E0ibuOW8=ib5yn)0?58+!WCtz8*bBaKIM=Uk2CQbfO zBbo0di`&Q8yloDEJ>wf5>e`T1`Ue}?_mMP;Kv|>4ZC&eol-a`hf`ow3^X@KcyV*j6 z81tZ{w?#~=mR!UTFl20$Z?w)vkbKO^VF2l67+p7$f`K!3DtG&`_iJjKtL8~6u<948 zLUv4T-A9ec0MjHo%-(tXGGqIxWsw8N3+`fiPS#WqpST`ofCOkLABr%1w@)-DlisJb z2|OsrB-Gmj_P$z(l;sA6CLgfN)m?BqA79(DPuw-5B$!qMVB->!BpwHaqE}A=kb4BX zv?lIaZ72$rc*ReB<~Q%BB;5+torU~G3f{*3+!Bc2->>h5ZEY=CG@KfGEQ;bAwADwOyy8Jtv2;rc(n9bn*Z&HJi zHfW_DJdekE@bKS&?PxOo=X!poUiwt*<&}SlmtN7KAIBEUeinxD(lHXtS(%s=fyh0f zO{EK0`-Mlj0!*7EkOeX#^g_QMhe6Cy)4|<`mc$<|b1u3e3q*Xf*g>8@JMmiMq{mP- zQ@Nd4)IQO#9e4q67dJ_Q)EHzCGdDC73OWi^o<=TOj;#(+ek1ZZsmluhn4`#Y?)H7+ zCpze60)q78cxX4Xrh36HUF@fsY5jw1juJ-V{(>`ePQ`qkE0C`~<&an3%b{#f5ktR$ z!bqPurf+tEC9hhq-3ye+vg|gdbj`(;#u@PMhE$fc`zH>YOKys>1a<&g5Q&lf zHtfH(KU761uXK~I@aud-CwpjtzfAtB)Qxw?>e+M?U_KaqN38+>YhX?xCKj&aCLqAY zIOK7)5#rGaq3NM!hTS*aBrPJ+X&}>(V*6$za8^#rqz9=YlEWB?%)|dL+e7dJuLA5v z_Jz=Vm7~8sAOGe=^?3K!3%dc*zTRILM^|K>l3#>r>#l)BpG!4F-LSE43dGr+(tT84 zI2Cx3LNBWdLdtqMoP(dg;9-4hY?g_V56dybUF+^iMV6Xu){OTCV<`9LBOYDRhc>}0 z&3L*LI1KPGwEqC^WYLgAe?XC_P%n#&9}dpgHxkJ>RhX?=(W2au3|nZH*oACFWnZ)& zDsOFOxJKjdE^jQ*P~|42Bqfc^4J+s>>L%e_w9-o-g^}iJse{TPa zG0-L51ELvCK5TQts*r#o{A9`6H(tBbFM1<=9ET@=?$43Zf6KUrf36Cvmfj!qcTdO~ zZ7){J&j#OjutT>KVy*-JQTTN??OIYsH{doo60eE!MES2)?XO*e>2G6I6_rAU3HjH5 zjN0D78gfq{YevRpwHcCoEKN!m|GpwMLm*Jgw>KYUUv|s0_KS2Gd96o_>F30?_LgoZ zkaPd$H0#Os5M_py1{@Y-y0<%0>Ay<-+!EK>^D?)lgoLYbBBAtv{fvandCi1uY7h)U z?z{U)jQ05|Kwc>y zSDq3@gcg_%Vwr{G#Mfze#eB&_Ceu0lvjQq6d0tkX@~gbW-d?Mwq`E{H#tFnd0r|M( zqLlNtks7PRUzdkD*MW4zu?caQkpA}1%%||q*D!rM7U>e8mvDNqCbXi-XhMr6!QQK( zmq}P-jC$>hWis;UJK~Hlu9mL-l7qIU4wrZ!tZ$fv(r2KMo!`=?^Rjm)Rzd1ugk z=tZGSGDXl*0neya6xH1%;G(>+aNgKitI@NOd7v4HK@_sYB{0YJQ&FI{jHQLQEy80# z5~-Fe%wax|i!P6Ja}(cT;R|JHR@O&?)U8FcOft>O(k-%5U~+zXny6xe~v}X zCsA6wa@ z`wRBax}3H9bhdz-9zQ4p4bBThn1&!=9M;G_591>J;Geh1U}6H7yjq^xQ8tG^54E6H zmz!mBA1@?f>cMU4HyySl&M;#sYmNxkgyJxf&@x85tOoKHi?Bx%$>C zmg<$;9q+L8*VeU&hWM=@k$fW_RE4QqSK^9hlL^)!uROuLF=`ZIq41+J_RQZ5pjZoV zJ-yJKD__DL?7#|0lp#x=Vtg7NUUZ{KYoJSra7PmlI9K@0i}+Qx5`)Y^wlKnCn$C#UYaA0;Kh}hh;!Iv`{7xCCM1=< z{4yNN6cZ@!iU5iraI4#`Jbz6P*Fb? zHeT}fA8tR2n~B*Ru@+4fg>3bw1sKS3!8c5L^lG`}!I9G@3PjWdsovn3CVU`BtOPKo zLYt%9#(45ZkR|ue%?9cpJ0-~?YS@i^qI6%lgx9(tB-%1|x9;d+7rTJQjs@50uD*9^ zd?T?;USbF=&nB;s<8z7PkDSY`RS3FZ1EyrM`Hgj!2hwwfu2kDCvVk_S>ma^XVZCpd zkg$1@aw(fUR}6cPXB5jpK+Y{dN5Y@CdblGzJfT8{y?q^ zgKjajBn8T{_DA_Cj7h9o7m@Y;iw5|7V?K9__xeEJt@eOcs<#!(elSSgQV?1GDiE#q zoe6F^z-%BD|Jc}FyDxO-XfpKcB3}48B?d2;jr}%~ecpdk%)Qt5qa?RD;{HA4&hh#{ zWOyDkA^8yNA5hnfAM$%teHXk=rX{$M06#O*P^&|5E3+5Ql3r`;a(de_^wtV9OwUqo zOUpFOEr!rs&;s`Pk2PeT@5W%fa|`q~RI3OHGa&AER0SlNI9xJKv}H^RG|d{Y8T2U} zFwA4t(9wZNsU5vPJ)&S-spp`IV=b-ZG37+Dvnvu%aok#p$-Ar2fGQ|wo0V-Gz#Whp_{kBiFDxW$O zgJ74WPuqY6u?XUgyeqAa6l6#J9gr<|e>Cf=w45PQNiLZMO*qfAC4Th)(rxmDF&&iM zquLN(2w`6e$S*GMOVq19qQv(SetKP)2mF*H8skjBLreyTTw*l*(OXS-m)PSuNzA#? z+^LyWoiCFdZHVtBeH&V{BYxkSQLr)U@D-R3y} z5STjP!B}LA=TiV7Z4MKkj_8f*Djg|2;smt5p)c(9)i6L>6$3>FbwJaE|Gr;rl zuk!++vz9tC<4fc2+B)&gbbPRa4?2<)BWdGVj!ezXM`=(zSGE9j$N*LBgfHx$#mJ3^&LmXwqfI+!%XdA4@fa)SqKf`#H)IUGjso`;IO z@FU*ls9lYssH71gn9Am(+GnKh0T24;*=#$|gprS|Ugv?_;*ewUqcy-E?!JgUR*GbN zzQUltP~z2(#>3$}t9muU+S+7zAoj|u8(ArxF{=4=%dq>M9(a-*Qce@zIJP)+f9MHy`A}=+i;u9*?6I@qGI-JWIfkE<(fFM9eAVV*6yzP zzI8fRN&zl>RCp4$yTqG)EI$ri8-a?Vpq-$jNxk^TSl2?D*i^`$Yvs)u1K;2FDz3zd z8WF|xtNwF(X&p8A7z{EG^wMW7n5XWj)c2R^(NA4(QqZ^`T+Y+JV31tGEw#QF$-jPe zQ*|}|;)F@MMLW{}IMC&^ScA=0*9P;ULbuXBKLey^@t|6*Qax zSAM7=;L}&+gbS&%1x&b;@co*c)1WqRbkPl6pouS{#RYAS34e;Fbp3oxWUcQaHTN>1 zpP$Qpsh(zdMS(|E1PBbZFFlfttL<-SU>gC^olX=PJ82U|7JcTzjHCRw<3L(EsIt}{ z-d73fP%XU~ujv6{FVSI~XeFAOswMTIhs{#QUTuoo4zv%Z6r*?xQe3>F=t#eT}*q?DpJTkF3@a_*%6~IRsDtAK_mihaA=^zN^8C9 zDaiSSQH8)N+2+tYB@)wzB?WZ{7HPHI%|jYGGC+snk{+Wvhj&hStNZol)ruSZBrsqL z89_UcgylAAKL5)5VBVDo3G|Ru3Kla0A zu)1E|fMe-QL15C58B;+wzU}hf6aHiK5vZ#L@`{Zd@l`QGA7_pX&K4`B!gzVnwAb^O zU*R_d__|5ADZzhEZ-{EGjlx1^3hz8-@oa|**e(x%+@S9yfozp$i^Ww*4;vW7Cl_L* zFitoh&4&y*kBG{tf)B=7hPK~0TdB<9i5 zzuOjZ1OF{Jf`jy(i#gg8bw!X^CwH1TCRR-%7C$8~?@dWd4f^wnn}&XZ|BK^oU3OA8XxuF>J2C^SUF;X!6DLWx0G!9gnBjGFkKBA3kVl9iC7^+qDe{2p0%w?u?;p+ z5l{cCouZVZjl0ud8#ET7{h922U2RrSLqvyV6?*PM>ZHpP{4$zkGP~TO^|SYU$et_N z+R%nO*AD|M1#|{qvTUzv+mdc$us;DTG!=xGD|9=>A1|zu5Pxt)q&SzL$YRK;GPTCQ zRKgYv-|&GQab0p1P#up2b#DK<5qKI&6Qm$Yf3g1c20g{yY&RR?1o=_21Okjmm>7Di zq-&=5f;IW6M<&&Zs_+^E=(bcBsTAR;#(U50fFOApIE=Zl340OAP`ngIJjCcy5Ph^++ZfZ2x z4ZGKqAw#RJEoxlu|DX=LfZWKVSD3R06GX6*T*@cz7a+1o4R&BrMNzAUrK?KG^89}< zXpx$OQ^HHHw=gUro(lEYhyZ(fk68JqEQuP;)bR24IGTKWYjNmO-q{|J(o_UPCk_(J zIH)+oe}Dn%y35t2PEAVIU-^A~s+jXGpSL_4(juF>nyw7tpLt33H|Mrsg?es*RS$_E zOsS-}xOl>76KdL(<+e_>bLAudjG9`EEHDAQKQvTZY2?r|Bd)@ z$u0fE#nY;u6B`VEzDUeL^QdtXQpaj7!nHNr+U?JuB-1Dm1IR*gwW-9$0n}9fHz}Sx znDKA_?fu`R%BjKAgnMW@Qi~tfU+!j+z+AsReaz3iKnTgOh&$7aIc%`B(}7*iIP|EU z1l0ID;(g?CueeGL`U(0pJgf>Z#;WZBNpI&@ZK>h=H80oK^%B-xZW>%7y zpaYAy0;(1@ayS9wBop<|RLeGf_sG*Gj(gJMB6>r>?Grq4vtj2|6b}z?n@t^Y>h<69 zhj#0ugh4?!E%==fXhZUzo-@J>@Bpc}Ehx7xaqjw%-|ezvMa>TUY-LZ9!Ej7zNh#~& zzewNXqw9{#)#@MU&`wPn`Vs#2>;Wy%1!ht3f7S~dh=(FmtOv%mv?Lm`L}VERia0n1 zW%TU5BEq!k%r5_C6pJDrx2b~I#@Kh;!C78hq%_;^?Xr1uwXn5K{3U5Mdd8u?{R_JS z)oDN`P8sqr5G1uVw|Iye9NynwIX>;f#rzb+9>G%C=#Lt6bC$e6py3DB#&)I5{l+QY zrt1DQ2dAj5ObJo$jh)(DApSHYd34*Cx!*GUdGYy-|=Uo0}xK0LO z+DvWo)j0q|E#A)7y-c51RG8bUW*jeGGP{MK2i4|~(#sOPCFs+J)|O5%i(?hOHeRxa zn7GEjbu1zia$DavHa9fkOnvI(4e_1bsMAOKlQMCDUN(iu!6%KXZVy>O+=#f*;W3xG z1I?(HFj@vz2veET$X<>^yJBAzHeycerzdB6tF9Gy)NqwmebP;_wf4EH<~#AURISI6 zeFmXFR$f)?(TO{vqIzqlJbSiw1^TFdLz>2cW@g2xSb`e7ibT+0$ne*aIvoQ9#D}<` zZnrPGwNtx^mrEn4sO@MY|3pI`D3a0Bu^HiW%Ubt&^FSPCktmnJUWBA3lpQDxvW{^< zI^Zd;KMw%SbCkbw4Ztfa@D@dOxmW*plWk=%?4}vpZpg(*!PMjc^wSrk_A!JHDBZ%{ zYo@!*!nu++N~e(bHCj{TzkdCOeV=@c84musEgtC*wB z*37tv(lRn~cavT13sg1|sOk*=ZA2hQ*ixD@%x_LjL=LQiWuR^{3i1n@9f%4qCZf7;4bp8K^IA z1dcYpLBqiS13fv+3pzYm(jt`R-CrasRgkZ0Wx Date: Wed, 8 Aug 2018 17:20:34 +1000 Subject: [PATCH 5/8] Added section on the scaffold --- doc/readme.md | 6 ++++++ scaffolds/aws/cfn/readme.md | 4 ++-- 2 files changed, 8 insertions(+), 2 deletions(-) diff --git a/doc/readme.md b/doc/readme.md index 4839cc37..79b50226 100644 --- a/doc/readme.md +++ b/doc/readme.md @@ -68,6 +68,12 @@ update `conf.toml` with database settings The application itself is a React based single page application (SPA) with an API backend and a postgres database used for data persistence. It's been designed to be completely stateless and will deploy into most types of environments, be it container based or VM based. +## Deploying into the cloud - scaffolds + +The scaffolding folder contains some base infrastructure that can be used to help deploying the solution. It will provide a base layer that can be expected to normally be already set up before an application deployment will be started. + +Currently there is an AWS three layer network solution available. Details can be found in the [readme](scaffolds/aws/cfn/readme.md) in the scaffolding folder. This contains all the information required to deploy the scaffold. + ## Build from source ### Reqirements diff --git a/scaffolds/aws/cfn/readme.md b/scaffolds/aws/cfn/readme.md index fdd67534..d5abf7f3 100644 --- a/scaffolds/aws/cfn/readme.md +++ b/scaffolds/aws/cfn/readme.md @@ -4,7 +4,7 @@ This scaffold will deploy the network layer in AWS using cloudformation. ## Requirements -stackup - https://github.com/realestate-com-au/stackup +stackup -[https://github.com/realestate-com-au/stackup](https://github.com/realestate-com-au/stackup) ## Instructions @@ -18,7 +18,7 @@ To remove run `teardown.sh` from the scaffolding directory A VPC with networking, routing and nats. -The VPC is laid out with 3 layers, public, private, and data. +The VPC is laid out with 3 layers, public, private, and data. > The template assumes 3 AZs, so if you are deploying somewhere with less it will need to be updated. From f2714c7e328eb617f4172be63bdc08026f256ed8 Mon Sep 17 00:00:00 2001 From: Tom Date: Wed, 8 Aug 2018 17:20:59 +1000 Subject: [PATCH 6/8] Bumped version for release --- cmd/version.go | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/cmd/version.go b/cmd/version.go index 3db48f61..97e06f6e 100644 --- a/cmd/version.go +++ b/cmd/version.go @@ -32,7 +32,7 @@ var versionCmd = &cobra.Command{ Short: "Displays the current version", Long: `Displays the current version of the application`, Run: func(cmd *cobra.Command, args []string) { - fmt.Println("Version: 0.2.3-pre-release") + fmt.Println("Version: 0.2.4") }, } From d92443dcabdf52ef5779f301c6961c50a2060bd1 Mon Sep 17 00:00:00 2001 From: Tom Date: Wed, 8 Aug 2018 17:28:49 +1000 Subject: [PATCH 7/8] Added assessment statement details to repo --- ASSESSMENT.md | 100 ++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 100 insertions(+) create mode 100644 ASSESSMENT.md diff --git a/ASSESSMENT.md b/ASSESSMENT.md new file mode 100644 index 00000000..a3394a58 --- /dev/null +++ b/ASSESSMENT.md @@ -0,0 +1,100 @@ +# Assessment + +Candidates should assume that the solution will be deployed to an empty cloud subscription with no existing infrastructure in place. + +There *should not* be a requirement for Vibrato to access a candidate's cloud services account to deploy this solution. + +Demonstrate regular commits and good git workflow practices. + +There is no time limit for this test. + +Candidates should provide documentation on their solution, including: + +- Pre requisites for your deployment solution. +- High level architectural overview of your deployment. +- Process instructions for provisioning your solution. + +## Assessment Grading Criteria + +### Key Criteria + +Candidates should take care to ensure that thier submission meets the following criteria: + +- Must be able to start from a cloned git repo. +- Must document any pre-requisites clearly. +- Must be contained within a GitHub project. +- Must deploy via an automated process. + +### Grading + +Candidates will be assessed across the following categories: + +#### Coding Style + +- Clarity of code +- Comments where relevant +- Consistency of Coding + +#### Security + +- Network segmentation +- Secret storage +- Platform security features + +#### Simplicity + +- No superfluous dependencies +- Do not over engineer the solution + +#### Resiliency + +- Auto scaling and highly available frontend +- Highly available Database + +## Tech Test Application + +Single page application designed to be ran inside a container or on a vm (IaaS) with a postgres database to store data. + +It is completely self contained, and should not require any additional dependencies to run. + +## Install + +1. Download latest binary from release +2. unzip into desired location +3. and you should be good to go + +## Start server + +update `conf.toml` with database settings + +`./TechTestApp updatedb` to create a database and seed it with test data + +`./TechTestApp serve` will start serving requests + +## Interesting endpoints + +`/` - root endpoint that will load the SPA + +`/api/tasks/` - api endpoint to create, read, update, and delete tasks + +`/healthcheck/` - Used to validate the health of the application + +## Compile from source + +### Requires + +#### dep + +`curl https://raw.githubusercontent.com/golang/dep/master/install.sh | sh` + +### Process + +`go get -d github.com/vibrato/VibratoTechTest` + +run `build.sh` + +the `dist` folder contains the compiled web package + +### Docker build + +`docker build . -t techtestapp:latest` \ No newline at end of file From 486a6661a896d05a72859798df6d2a500b450811 Mon Sep 17 00:00:00 2001 From: Tom Date: Thu, 9 Aug 2018 15:13:56 +1000 Subject: [PATCH 8/8] Updated with changes based on feedback in code reviews --- ASSESSMENT.md | 4 +- doc/adr/0003-removed-scaffolding.md | 19 ++ doc/readme.md | 12 +- readme.md | 2 + scaffolds/aws/cfn/bootstrap.sh | 4 - scaffolds/aws/cfn/parameters.yml | 10 - scaffolds/aws/cfn/readme.md | 41 --- scaffolds/aws/cfn/teardown.sh | 4 - scaffolds/aws/cfn/template.yml | 495 ---------------------------- 9 files changed, 26 insertions(+), 565 deletions(-) create mode 100644 doc/adr/0003-removed-scaffolding.md delete mode 100755 scaffolds/aws/cfn/bootstrap.sh delete mode 100644 scaffolds/aws/cfn/parameters.yml delete mode 100644 scaffolds/aws/cfn/readme.md delete mode 100755 scaffolds/aws/cfn/teardown.sh delete mode 100644 scaffolds/aws/cfn/template.yml diff --git a/ASSESSMENT.md b/ASSESSMENT.md index a3394a58..9b2405c2 100644 --- a/ASSESSMENT.md +++ b/ASSESSMENT.md @@ -22,7 +22,7 @@ Candidates should take care to ensure that thier submission meets the following - Must be able to start from a cloned git repo. - Must document any pre-requisites clearly. -- Must be contained within a GitHub project. +- Must be contained within a GitHub repository. - Must deploy via an automated process. ### Grading @@ -37,7 +37,7 @@ Candidates will be assessed across the following categories: #### Security -- Network segmentation +- Network segmentation (if applicable to the implementation) - Secret storage - Platform security features diff --git a/doc/adr/0003-removed-scaffolding.md b/doc/adr/0003-removed-scaffolding.md new file mode 100644 index 00000000..adec64d5 --- /dev/null +++ b/doc/adr/0003-removed-scaffolding.md @@ -0,0 +1,19 @@ +# 3. removed scaffolding + +Date: 2018-08-09 + +## Status + +Accepted + +## Context + +Should we provide scaffolding for the test takers, or should we expect them to be able to set that up themselves? + +## Decision + +We decided to remove the scaffolding and rather suggest that the test taker uses the default VPC to deploy their application. + +## Consequences + +Some people will spend exta time to deploy the network infrastructure, which might make the test seem a lot bigger than it is. diff --git a/doc/readme.md b/doc/readme.md index 79b50226..d2f0b329 100644 --- a/doc/readme.md +++ b/doc/readme.md @@ -46,7 +46,7 @@ update `conf.toml` with database settings ## Repository structure -``` python +``` sh . ├── assets # Asset directory for the application │   ├── css # Contains all the css files for the web site @@ -68,12 +68,6 @@ update `conf.toml` with database settings The application itself is a React based single page application (SPA) with an API backend and a postgres database used for data persistence. It's been designed to be completely stateless and will deploy into most types of environments, be it container based or VM based. -## Deploying into the cloud - scaffolds - -The scaffolding folder contains some base infrastructure that can be used to help deploying the solution. It will provide a base layer that can be expected to normally be already set up before an application deployment will be started. - -Currently there is an AWS three layer network solution available. Details can be found in the [readme](scaffolds/aws/cfn/readme.md) in the scaffolding folder. This contains all the information required to deploy the scaffold. - ## Build from source ### Reqirements @@ -118,11 +112,11 @@ Releases are deployed and managed through github, it's an automated process that To create a new release, update `../cmd/version.go` with the new version and merge that into the master branch. -The commit message on the merge, will be the releas message, so make sure it contains the release notes. +The commit message on the merge, will be the release message, so make sure it contains the release notes. A tag will be created on the master branch if the build and release is successful. -We use semver for versioning, `major.minor.patch[-pre-release]` and the CI solution has been configured to take note of the `-pre-release` tag of the version and upload it as a pre-release in git if it's included. So to release a new full release, make sure to not include `-pre-release` and visa versa. +We use semver for versioning, `major.minor.patch[-pre-release]` and the CI solution has been configured to take note of the `-pre-release` tag of the version and upload it as a pre-release in git if it's included. So to release a new full release, make sure to not include `-pre-release` and vice versa. Builds will be produced for: diff --git a/readme.md b/readme.md index 03afdab4..7f7bc34b 100644 --- a/readme.md +++ b/readme.md @@ -26,6 +26,8 @@ More details about the application can be found in the [document folder](doc/rea For more information about taking the test and joining Vibrato's amazing team, please head over to our [recruitment page](https://vibrato.recruitee.com/) and apply there. Our recruitment team will reach out to you about the details of the test and be able to answer any questions you have about Vibrato or the test itself. +Information about the assessment is available in the [assessment.md file](ASSESSMENT.md) + ## Found an issue? If you've found an issue with the application, the documentation, or anything else, we are happy to take contributions. Please raise an issue in the [github repository](https://github.com/vibrato/TechTestApp/issues) and read through the contribution rules found the [CONTRIBUTING.md](CONTRIBUTING.md) file for the details. \ No newline at end of file diff --git a/scaffolds/aws/cfn/bootstrap.sh b/scaffolds/aws/cfn/bootstrap.sh deleted file mode 100755 index def3e193..00000000 --- a/scaffolds/aws/cfn/bootstrap.sh +++ /dev/null @@ -1,4 +0,0 @@ -#!/bin/sh - -echo "Starting bootstrap of network!" -stackup vibrato-network up -t template.yml -p parameters.yml \ No newline at end of file diff --git a/scaffolds/aws/cfn/parameters.yml b/scaffolds/aws/cfn/parameters.yml deleted file mode 100644 index 86efaf56..00000000 --- a/scaffolds/aws/cfn/parameters.yml +++ /dev/null @@ -1,10 +0,0 @@ -VpcCidr: 10.89.32.0/19 -PublicSubnetAz1: 10.89.32.0/23 -PublicSubnetAz2: 10.89.34.0/23 -PublicSubnetAz3: 10.89.36.0/23 -DataSubnetAz1: 10.89.40.0/23 -DataSubnetAz2: 10.89.42.0/23 -DataSubnetAz3: 10.89.44.0/23 -PrivateSubnetAz1: 10.89.48.0/22 -PrivateSubnetAz2: 10.89.52.0/22 -PrivateSubnetAz3: 10.89.56.0/22 \ No newline at end of file diff --git a/scaffolds/aws/cfn/readme.md b/scaffolds/aws/cfn/readme.md deleted file mode 100644 index d5abf7f3..00000000 --- a/scaffolds/aws/cfn/readme.md +++ /dev/null @@ -1,41 +0,0 @@ -# AWS CloudFormation scaffolding - -This scaffold will deploy the network layer in AWS using cloudformation. - -## Requirements - -stackup -[https://github.com/realestate-com-au/stackup](https://github.com/realestate-com-au/stackup) - -## Instructions - -Set up AWS credentials environment variables. e.g. AWS_PROFILE - -Run `bootstrap.sh` from the scaffolding directory - -To remove run `teardown.sh` from the scaffolding directory - -## What will be deployed - -A VPC with networking, routing and nats. - -The VPC is laid out with 3 layers, public, private, and data. - -> The template assumes 3 AZs, so if you are deploying somewhere with less it will need to be updated. - -### Exports - -* vibrato-network-VpcId -* vibrato-network-VpcCidr -* vibrato-network-SubnetPublicAz1 -* vibrato-network-SubnetPublicAz2 -* vibrato-network-SubnetPublicAz3 -* vibrato-network-SubnetPrivateAz1 -* vibrato-network-SubnetPrivateAz2 -* vibrato-network-SubnetPrivateAz3 -* vibrato-network-SubnetDataAz1 -* vibrato-network-SubnetDataAz2 -* vibrato-network-SubnetDataAz3 - -## Tested on - -* MacOs \ No newline at end of file diff --git a/scaffolds/aws/cfn/teardown.sh b/scaffolds/aws/cfn/teardown.sh deleted file mode 100755 index d6fb90f0..00000000 --- a/scaffolds/aws/cfn/teardown.sh +++ /dev/null @@ -1,4 +0,0 @@ -#!/bin/sh - -echo "Starting bootstrap of network!" -stackup vibrato-network down \ No newline at end of file diff --git a/scaffolds/aws/cfn/template.yml b/scaffolds/aws/cfn/template.yml deleted file mode 100644 index 2ef6eed6..00000000 --- a/scaffolds/aws/cfn/template.yml +++ /dev/null @@ -1,495 +0,0 @@ ---- -Description: Network Layout for Environment - -Parameters: - - # CIDR inputs are limited to between /16-/28 as those are the AWS limits - VpcCidr: - Description: CIDR range for whole VPC. e.g. 10.89.0.0/19 - Type: String - AllowedPattern: ((25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.){3}(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\/((1[6-9])|(2[0-8])) - - PublicSubnetAz1: - Description: CIDR range for public subnet in AZ1. e.g. 10.89.0.0/23 - Type: String - AllowedPattern: ((25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.){3}(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\/((1[6-9])|(2[0-8])) - - PublicSubnetAz2: - Description: CIDR range for public subnet in AZ2. e.g. 10.89.2.0/23 - Type: String - AllowedPattern: ((25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.){3}(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\/((1[6-9])|(2[0-8])) - - PublicSubnetAz3: - Description: CIDR range for public subnet in AZ3. e.g 10.89.4.0/23 - Type: String - AllowedPattern: ((25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.){3}(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\/((1[6-9])|(2[0-8])) - - DataSubnetAz1: - Description: CIDR range for data subnet in AZ1. e.g. 10.89.8.0/23 - Type: String - AllowedPattern: ((25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.){3}(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\/((1[6-9])|(2[0-8])) - - DataSubnetAz2: - Description: CIDR range for data subnet in AZ2. e.g. 10.89.10.0/23 - Type: String - AllowedPattern: ((25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.){3}(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\/((1[6-9])|(2[0-8])) - - DataSubnetAz3: - Description: CIRD range for data subnet in AZ3. e.g. 10.89.12.0/23 - Type: String - AllowedPattern: ((25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.){3}(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\/((1[6-9])|(2[0-8])) - - PrivateSubnetAz1: - Description: CIDR range for private subnet in AZ1. e.g. 10.89.16.0/22 - Type: String - AllowedPattern: ((25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.){3}(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\/((1[6-9])|(2[0-8])) - - PrivateSubnetAz2: - Description: CIDR range for private subnet in AZ2. e.g. 10.89.20.0/22 - Type: String - AllowedPattern: ((25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.){3}(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\/((1[6-9])|(2[0-8])) - - PrivateSubnetAz3: - Description: CIDR range for private subnet in AZ3. e.g. 10.89.24.0/22 - Type: String - AllowedPattern: ((25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.){3}(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\/((1[6-9])|(2[0-8])) - -Resources: - VPC: - Type: AWS::EC2::VPC - Properties: - CidrBlock: !Ref VpcCidr - EnableDnsSupport: true - EnableDnsHostnames: true - Tags: - - Key: Name - Value: !Sub "${AWS::StackName}-vpc" - - InternetGateway: - Type: AWS::EC2::InternetGateway - Properties: - Tags: - - Key: Name - Value: !Sub "${AWS::StackName}-igw" - - InternetGatewayAttachment: - Type: AWS::EC2::VPCGatewayAttachment - Properties: - InternetGatewayId: !Ref InternetGateway - VpcId: !Ref VPC - - DHCPOptions: - Type: AWS::EC2::DHCPOptions - Properties: - DomainNameServers: - - AmazonProvidedDNS - Tags: - - Key: Name - Value: !Sub "${AWS::StackName}-dhcpoptions" - - S3Endpoint: - Type: AWS::EC2::VPCEndpoint - Properties: - VpcId: !Ref VPC - ServiceName: !Sub com.amazonaws.${AWS::Region}.s3 - - ############################################################################# - # Nat Gateways: DO NOT MODIFY - ############################################################################# - - NatGateway1EIP: - Type: AWS::EC2::EIP - Properties: - Domain: vpc - - NatGateway2EIP: - Type: AWS::EC2::EIP - Properties: - Domain: vpc - - NatGateway3EIP: - Type: AWS::EC2::EIP - Properties: - Domain: vpc - - NATGateway1: - Type: AWS::EC2::NatGateway - Properties: - AllocationId: !GetAtt NatGateway1EIP.AllocationId - SubnetId: !Ref PublicSubnet1 - - NATGateway2: - Type: AWS::EC2::NatGateway - Properties: - AllocationId: !GetAtt NatGateway2EIP.AllocationId - SubnetId: !Ref PublicSubnet2 - - NATGateway3: - Type: AWS::EC2::NatGateway - Properties: - AllocationId: !GetAtt NatGateway3EIP.AllocationId - SubnetId: !Ref PublicSubnet3 - - ############################################################################# - # Routes: DO NOT MODIFY - ############################################################################# - - # Public Routes - - PublicRouteTable: - Type: AWS::EC2::RouteTable - Properties: - VpcId: !Ref VPC - Tags: - - Key: Name - Value: !Sub "${AWS::StackName}-public" - - PublicRoute: - Type: AWS::EC2::Route - Properties: - RouteTableId: !Ref PublicRouteTable - DestinationCidrBlock: 0.0.0.0/0 - GatewayId: !Ref InternetGateway - - PublicSubnetRouteTableAssociation1: - Type: AWS::EC2::SubnetRouteTableAssociation - Properties: - SubnetId: !Ref PublicSubnet1 - RouteTableId: !Ref PublicRouteTable - - PublicSubnetRouteTableAssociation2: - Type: AWS::EC2::SubnetRouteTableAssociation - Properties: - SubnetId: !Ref PublicSubnet2 - RouteTableId: !Ref PublicRouteTable - - PublicSubnetRouteTableAssociation3: - Type: AWS::EC2::SubnetRouteTableAssociation - Properties: - SubnetId: !Ref PublicSubnet3 - RouteTableId: !Ref PublicRouteTable - - # Private Routes - - PrivateRouteTable1: - Type: AWS::EC2::RouteTable - Properties: - VpcId: !Ref VPC - Tags: - - Key: Name - Value: !Sub "${AWS::StackName}-privateroute-az1" - - PrivateRouteTable2: - Type: AWS::EC2::RouteTable - Properties: - VpcId: !Ref VPC - Tags: - - Key: Name - Value: !Sub "${AWS::StackName}-privateroute-az1" - - PrivateRouteTable3: - Type: AWS::EC2::RouteTable - Properties: - VpcId: !Ref VPC - Tags: - - Key: Name - Value: !Sub "${AWS::StackName}-privateroute-az3" - - PrivateRoute1: - Type: AWS::EC2::Route - Properties: - RouteTableId: !Ref PrivateRouteTable1 - DestinationCidrBlock: 0.0.0.0/0 - NatGatewayId: !Ref NATGateway1 - - PrivateRoute2: - Type: AWS::EC2::Route - Properties: - RouteTableId: !Ref PrivateRouteTable2 - DestinationCidrBlock: 0.0.0.0/0 - NatGatewayId: !Ref NATGateway2 - - PrivateRoute3: - Type: AWS::EC2::Route - Properties: - RouteTableId: !Ref PrivateRouteTable3 - DestinationCidrBlock: 0.0.0.0/0 - NatGatewayId: !Ref NATGateway3 - - PrivateSubnetRouteTableAssociation1: - Type: AWS::EC2::SubnetRouteTableAssociation - Properties: - SubnetId: !Ref PrivateSubnet1 - RouteTableId: !Ref PrivateRouteTable1 - - PrivateSubnetRouteTableAssociation2: - Type: AWS::EC2::SubnetRouteTableAssociation - Properties: - SubnetId: !Ref PrivateSubnet2 - RouteTableId: !Ref PrivateRouteTable2 - - PrivateSubnetRouteTableAssociation3: - Type: AWS::EC2::SubnetRouteTableAssociation - Properties: - SubnetId: !Ref PrivateSubnet3 - RouteTableId: !Ref PrivateRouteTable3 - - # Data Routes - - DataRouteTable1: - Type: AWS::EC2::RouteTable - Properties: - VpcId: !Ref VPC - Tags: - - Key: Name - Value: !Sub "${AWS::StackName}-dataroutes-az1" - - DataRouteTable2: - Type: AWS::EC2::RouteTable - Properties: - VpcId: !Ref VPC - Tags: - - Key: Name - Value: !Sub "${AWS::StackName}-dataroutes-az2" - - DataRouteTable3: - Type: AWS::EC2::RouteTable - Properties: - VpcId: !Ref VPC - Tags: - - Key: Name - Value: !Sub "${AWS::StackName}-dataroutes-az3" - - DataRoute1: - Type: AWS::EC2::Route - Properties: - RouteTableId: !Ref DataRouteTable1 - DestinationCidrBlock: 0.0.0.0/0 - NatGatewayId: !Ref NATGateway1 - - DataRoute2: - Type: AWS::EC2::Route - Properties: - RouteTableId: !Ref DataRouteTable2 - DestinationCidrBlock: 0.0.0.0/0 - NatGatewayId: !Ref NATGateway2 - - DataRoute3: - Type: AWS::EC2::Route - Properties: - RouteTableId: !Ref DataRouteTable3 - DestinationCidrBlock: 0.0.0.0/0 - NatGatewayId: !Ref NATGateway3 - - DataSubnetRouteTableAssociation1: - Type: AWS::EC2::SubnetRouteTableAssociation - Properties: - SubnetId: !Ref DataSubnet1 - RouteTableId: !Ref DataRouteTable1 - - DataSubnetRouteTableAssociation2: - Type: AWS::EC2::SubnetRouteTableAssociation - Properties: - SubnetId: !Ref DataSubnet2 - RouteTableId: !Ref DataRouteTable2 - - DataSubnetRouteTableAssociation3: - Type: AWS::EC2::SubnetRouteTableAssociation - Properties: - SubnetId: !Ref DataSubnet3 - RouteTableId: !Ref DataRouteTable3 - - ############################################################################# - # Subnets: DO NOT MODIFY - ############################################################################# - - # Public Subnets - - PublicSubnet1: - Type: AWS::EC2::Subnet - Properties: - VpcId: !Ref VPC - AvailabilityZone: !Select - - 0 - - !GetAZs "" - CidrBlock: !Ref PublicSubnetAz1 - MapPublicIpOnLaunch: true - Tags: - - Key: Name - Value: !Sub "${AWS::StackName}-public-subnet-az1" - - PublicSubnet2: - Type: AWS::EC2::Subnet - Properties: - VpcId: !Ref VPC - AvailabilityZone: !Select - - 1 - - !GetAZs "" - CidrBlock: !Ref PublicSubnetAz2 - MapPublicIpOnLaunch: true - Tags: - - Key: Name - Value: !Sub "${AWS::StackName}-public-subnet-az2" - - PublicSubnet3: - Type: AWS::EC2::Subnet - Properties: - VpcId: !Ref VPC - AvailabilityZone: !Select - - 2 - - !GetAZs "" - CidrBlock: !Ref PublicSubnetAz3 - MapPublicIpOnLaunch: true - Tags: - - Key: Name - Value: !Sub "${AWS::StackName}-public-subnet-az3" - - # Private Subnets - - PrivateSubnet1: - Type: AWS::EC2::Subnet - Properties: - VpcId: !Ref VPC - AvailabilityZone: !Select - - 0 - - !GetAZs "" - CidrBlock: !Ref PrivateSubnetAz1 - MapPublicIpOnLaunch: false - Tags: - - Key: Name - Value: !Sub "${AWS::StackName}-private-subnet-az1" - - PrivateSubnet2: - Type: AWS::EC2::Subnet - Properties: - VpcId: !Ref VPC - AvailabilityZone: !Select - - 1 - - !GetAZs "" - CidrBlock: !Ref PrivateSubnetAz2 - MapPublicIpOnLaunch: false - Tags: - - Key: Name - Value: !Sub "${AWS::StackName}-private-subnet-az2" - - PrivateSubnet3: - Type: AWS::EC2::Subnet - Properties: - VpcId: !Ref VPC - AvailabilityZone: !Select - - 2 - - !GetAZs "" - CidrBlock: !Ref PrivateSubnetAz3 - MapPublicIpOnLaunch: false - Tags: - - Key: Name - Value: !Sub "${AWS::StackName}-private-subnet-az3" - - # Data Subnets - - DataSubnet1: - Type: AWS::EC2::Subnet - Properties: - VpcId: !Ref VPC - AvailabilityZone: !Select - - 0 - - !GetAZs "" - CidrBlock: !Ref DataSubnetAz1 - MapPublicIpOnLaunch: false - Tags: - - Key: Name - Value: !Sub "${AWS::StackName}-data-subnet-az1" - - DataSubnet2: - Type: AWS::EC2::Subnet - Properties: - VpcId: !Ref VPC - AvailabilityZone: !Select - - 1 - - !GetAZs "" - CidrBlock: !Ref DataSubnetAz2 - MapPublicIpOnLaunch: false - Tags: - - Key: Name - Value: !Sub "${AWS::StackName}-data-subnet-az2" - - DataSubnet3: - Type: AWS::EC2::Subnet - Properties: - VpcId: !Ref VPC - AvailabilityZone: !Select - - 2 - - !GetAZs "" - CidrBlock: !Ref DataSubnetAz3 - MapPublicIpOnLaunch: false - Tags: - - Key: Name - Value: !Sub "${AWS::StackName}-data-subnet-az3" - -Outputs: - - VpcId: - Description: A reference to the created VPC - Value: !Ref VPC - Export: - Name: !Sub "${AWS::StackName}-VpcId" - - VpcCidr: - Description: A reference to the created VPC - Value: !GetAtt VPC.CidrBlock - Export: - Name: !Sub "${AWS::StackName}-VpcCidr" - - SubnetPublicAz1: - Description: A reference to the created public subnet in az1 - Value: !Ref PublicSubnet1 - Export: - Name: !Sub "${AWS::StackName}-SubnetPublicAz1" - - SubnetPublicAz2: - Description: A reference to the created public subnet in az2 - Value: !Ref PublicSubnet2 - Export: - Name: !Sub "${AWS::StackName}-SubnetPublicAz2" - - SubnetPublicAz3: - Description: A reference to the created public subnet in az3 - Value: !Ref PublicSubnet3 - Export: - Name: !Sub "${AWS::StackName}-SubnetPublicAz3" - - SubnetPrivateAz1: - Description: A reference to the created private subnet in az1 - Value: !Ref PrivateSubnet1 - Export: - Name: !Sub "${AWS::StackName}-SubnetPrivateAz1" - - SubnetPrivateAz2: - Description: A reference to the created private subnet in az2 - Value: !Ref PrivateSubnet2 - Export: - Name: !Sub "${AWS::StackName}-SubnetPrivateAz2" - - SubnetPrivateAz3: - Description: A reference to the created private subnet in az3 - Value: !Ref PrivateSubnet3 - Export: - Name: !Sub "${AWS::StackName}-SubnetPrivateAz3" - - SubnetDataAz1: - Description: A reference to the created data subnet in az1 - Value: !Ref DataSubnet1 - Export: - Name: !Sub "${AWS::StackName}-SubnetDataAz1" - - SubnetDataAz2: - Description: A reference to the created data subnet in az2 - Value: !Ref DataSubnet2 - Export: - Name: !Sub "${AWS::StackName}-SubnetDataAz2" - - SubnetDataAz3: - Description: A reference to the created data subnet in az3 - Value: !Ref DataSubnet3 - Export: - Name: !Sub "${AWS::StackName}-SubnetDataAz3" \ No newline at end of file