From 3e503bc6fab34ed89415df56f9293ed3eae7c5a8 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jos=C3=A9=20Guilherme=20Vanz?= Date: Tue, 5 Sep 2023 09:45:32 -0300 Subject: [PATCH] feat: policy reporter MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Adds a Kubewarden controller subchart to allow users to install the Policy Reporter UI. Therefore, user get a UI to visualize the reports generated by the audit scanner. Signed-off-by: José Guilherme Vanz --- .github/workflows/helm-chart-release.yml | 5 +++++ charts/kubewarden-controller/Chart.lock | 6 ++++++ charts/kubewarden-controller/Chart.yaml | 5 +++++ charts/kubewarden-controller/chart-values.yaml | 16 ++++++++++++++++ .../charts/policy-reporter-2.19.4.tgz | Bin 0 -> 27865 bytes charts/kubewarden-controller/values.yaml | 16 ++++++++++++++++ scripts/extract_images.sh | 5 ++++- 7 files changed, 52 insertions(+), 1 deletion(-) create mode 100644 charts/kubewarden-controller/Chart.lock create mode 100644 charts/kubewarden-controller/charts/policy-reporter-2.19.4.tgz diff --git a/.github/workflows/helm-chart-release.yml b/.github/workflows/helm-chart-release.yml index 62e5b2ece..4b2fa2c96 100644 --- a/.github/workflows/helm-chart-release.yml +++ b/.github/workflows/helm-chart-release.yml @@ -79,6 +79,11 @@ jobs: run: | make generate-changelog-files + - name: Add dependency repo required to release the controller chart + run: | + helm repo add policy-reporter https://kyverno.github.io/policy-reporter + helm repo update + - name: Run chart-releaser uses: helm/chart-releaser-action@v1.5.0 with: diff --git a/charts/kubewarden-controller/Chart.lock b/charts/kubewarden-controller/Chart.lock new file mode 100644 index 000000000..ce1b29507 --- /dev/null +++ b/charts/kubewarden-controller/Chart.lock @@ -0,0 +1,6 @@ +dependencies: +- name: policy-reporter + repository: https://kyverno.github.io/policy-reporter + version: 2.19.4 +digest: sha256:145d113d1448d3c2217db65df2c2bc6ec91ba57ef9cbdb69805c2466187dbaba +generated: "2023-09-05T09:47:29.471541497-03:00" diff --git a/charts/kubewarden-controller/Chart.yaml b/charts/kubewarden-controller/Chart.yaml index d2df448bf..12e8f3e34 100644 --- a/charts/kubewarden-controller/Chart.yaml +++ b/charts/kubewarden-controller/Chart.yaml @@ -44,3 +44,8 @@ annotations: # Valid values for the following annotation include: `cluster-tool`, `app` or `cluster-template` # See the Cluster Tools section to learn more about when to set this value to `cluster-tool`. catalog.cattle.io/type: cluster-tool +dependencies: + - name: policy-reporter + version: 2.19.4 + repository: https://kyverno.github.io/policy-reporter + condition: auditScanner.policyReporter diff --git a/charts/kubewarden-controller/chart-values.yaml b/charts/kubewarden-controller/chart-values.yaml index bb78366a4..ec21c9e94 100644 --- a/charts/kubewarden-controller/chart-values.yaml +++ b/charts/kubewarden-controller/chart-values.yaml @@ -91,6 +91,7 @@ resources: replicas: 1 auditScanner: enable: true + policyReporter: false # The default audit-scanner ServiceAccount is bound to the ClusterRoles: # - view: Allows read-only access to most objects in a namespace. # Does not allow viewing secrets, roles or role bindings. @@ -114,3 +115,18 @@ auditScanner: logLevel: info # Output result of scan to stdout in JSON upon completion outputScan: true + +# Values to configure the policy reporter subchart enabled by the +# auditScanner.policyReporter flag +policy-reporter: + image: + registry: ghcr.io + repository: kyverno/policy-reporter + tag: 2.15.4 + ui: + enabled: true + image: + registry: ghcr.io + repository: kyverno/policy-reporter-ui + tag: 1.8.4 + diff --git a/charts/kubewarden-controller/charts/policy-reporter-2.19.4.tgz b/charts/kubewarden-controller/charts/policy-reporter-2.19.4.tgz new file mode 100644 index 0000000000000000000000000000000000000000..bc93d68da11b9ce729cc5ee4814da0a5b209460a GIT binary patch literal 27865 zcmZs?Q*>rc7pR-0W81c!bZpzU?R0G0ww-ir+qP|Xtas=8&pzYaoOQF-)v7USRMnib zo@Ww7L81cv_W-DXXbdHk7>y-l*=0O9*^F4!7)_MfEVYz5+2z&L*k#pitPJf;JX93z zc_mD3Y=N%6EZw%)TPR^)RtNP1v@d*(Ps=rez`2{bd}@g|BjkC`T*q@Zf9D+MOQ@g` zCmH}LI1S&wna;MJ#___SKsl64mh`h{G#?-{*vZ8 z&h@>j9}f5uAWC2J!kJ|fk=k%Q8D;0%h)xf_QL_ zs+jE1N0dV}BM{7h=q^Zq$LEeMIO5ocSlsWu`^x~ge-8u^I@bUl5j(K1ixcTG&pEe2 zv94@?ZmsMPYCAw<0!^Po8FP?Ld}<)CbQ3dNpd2&xd- z74a|< zK!U7uWfzV1+3V--uCot-fS?2P#*|HMw;t@^IG)pKGUgJEi2G0P-<`R$@K+-cz7dvv+!i&7LD$cX5;gTp}4y<@@C@_gzVorzD_%E;Ns#x$3cwl zz>kad4c+5#=mMkZgdg3OlHLGl-c7X*6&IdDv>DzYtUqKg`% zDh#bdett%smY||Uz8$azMt3J(iB3fkSAb_H((aQm-UXB6B#1^M^PL1fn@1tN-p&6q zKu|yy<;duk6&^d*dIk#L|8NvDw*UHGT0x5Cps^`A%;=NnMB_lNE z$N+{6jCMr+Re|Nij6zKark*}awr4wxq7$VT*5p)5?e<64QgY*@F8CDj6Wp#}$YKI>H5aMvY|S z#60n0l!Q#Xz)8Y6x(-mT;0Yp}NC!e7LsFt95t}MP!3>YEVDkgzn2tYX5@B%kmkSgy z^4}_Vj0E8s4iBhm-vEYm;RPmEMEc7)UZ?<~6-zw>cae6Z>Efa^rC3Xt41<(U<9Z6L zpciN1$0r^+HP%#{az<-Bmgbr#FDS%e5MJdR7zk$O#Qp(P8O!*qU13pzf-Bcdk#v$X za#4b?be&0%#B+`M5om1_1)`EF*Hi^hcx-7(Y35?!%4QJy`TIlNiOaFKj20joh7;wZQi&QCxP^F4<2JJqF znEV{78Ipe1h!QfhKG0RMlx~*mUE!JxL)nJ+rXO-5NswX_5GojH>~MryJ_Cin~oS?y<5ht01DI|(OW=x~R1h5PJ ziHtRE!r1w7vQpBBV?!LIIC zGOK2t1Uw}7Lew)}#C;K!fPH(cq~m%_Lcu@^;f}Sm%Q8yxG%Z+jRxN+15M*}c{)ZlF zfv=Q0?ieO>EsX%oVWlzn_pdaKUYG@$uJ9*lzgfg8c6XPf75+#tDV~%qAb~sRdm15z zrg`CheCxUQJv!k=cP$@z zcRXk{Mm(til{xS9zJ@vjHbrCZP3LJw#ZmyF!%}WZwHw-MDqA+^MSu_I7$hl6c2`}^ z7|BXVKz1-teEL}SUyzN1xCEgrdQXHyRv}*z5KOEwVLtVIaDVZW)m)2-;)XJ{Gnctz zq{VV=*cNk4%WVxk5i^$TDOAE=$dS8=(~vPn2*trnw11XSrG}?x%rsM`W|DE>ki2_dDMGszT($BzwiOoQYqHr2hP0FM|t^s}9x z+5|)Z1EW|Y$qWZk;a6ym9Ulc*6vNJwW=VR^MdsDEF*HG@%Ij^QimD1e*yqO1ilX!{ zdBBx=c%@!5x9UWK*T3sV;2X0<lK-*O_5}z@d{CVZ%01 z(cE7v_P~6+fnQ0l-9{0;{Nq(ABa3{+VV$N(Wa0!HA5&;^0{>9r9SMY87L$dFS+2*R z*y|mw(+7S!*-&0)Q39uRh0GH*0U-%l3vrPl<9pj1o zt&~fpUEG?s*dicWMBrqUB=Nn`l$gaCqCqbOwA~1)5<^+iY4;mMJ)ZoeWMt27pu=n> zTuF$Rt&@cfe8t=qVHi<7^>q$p7?-pU-(5fntRyU-W=I6PU)1nV@^!!fGErwFN)F*z zx^)uxB+~Y^qH-~_ELxX*u5W|}qqx69ywC(wbl>aoTZVPqL-a~r>oV>Rd|cd-J{i8= z{(*p9POe5hS9_k7EhFskx;WG>X+F#~aK091OkO}RX$Y*5f4xL@C@B~-JQYS6YJ?lg zm;;ao`e-~o>lx_ZrKkk_@?wEseSw_NjS|(x2>3yD!+u84Wyz!fS#po|bQHN{TjlG7 z9lRn-#$-w|P;gxRLJG)GB)K_EFj6F)t9*tTX57(mlLJ~3cFE*1_Q17qmv@lS^tir& zCQ646panfD`7Iy^{PP*PQrvlSj(!_@^u@H{0|Q{H->Ki~LJX;4wR5PJQV%NjBGw;B zW=c3ElmZ$}j?WMkZAGmyt!$=_k%)AZqr^&^(D3-)4QCEd{%A$Sd_j)|Zh z39rY<1a_ZZ!KrmaaP%EP59vR50}cC3_EES#CIYuu`DKsP0z$u5OV_)!u6sJTi$`yK zZR0drD@x4xsfj*Q8tin83a3U@YvVEMQ<<8g3ru14;f?Q}`*29VK0%840yXsaYfm`R ze_<+u4u-HJa8Sra=JU8DfO?#O{-N&%lQ$KIGka8@8I`EWIwmMvhP^@vyFg{-4DzP0 zvdmHV?Tx5q4!*46naqEW9krB zN*$j&YI&b1@_c}loidEDFdWwoOZ2zm(`DX&$)CtN# z231BHiMah+HL`A-BcbK`AYa=}qZtTZnHFLV;`xu8C*yE;a$;MWnavK;SiBNx#dE>R z;L~$ek5Tp>M^qGxLfNlxdilM*+Y|3!-|!%gf1nINziZ{$oO~;5_%>*-u&l-n(!+>x zx;4gKI1(oBYz}B&FEy@8g-wmH+2ydG8BAK^6*Mz%ZyQGEP#Z-*IaG{EM2-DCj5f*vC4g}@###agH zaW}S}?w|wrJ4sA^?k^Y+wO^Bw^u5V0&w}EFWv}YQM)P`k9o7&*megADRiN_;iHHaG zlP7PkWz-|8>L-Vq<})5#7f+xY?+1RmZ#5P!jAt+0dXh6oHP&306tU@-NQ`q?} zNL&75lNg+zpB?p8gxM~>NYF$Lc)QLt8D9@c=0>8X)1{&|JUwyP`?>@)$Z)wnh|h?>&h2ft3f>1)DQd>deHptzVP zgwD&y7;oi`WU#H1S?dM5JAA!C9L`yWCqf(W}rCjGxB}SoX9rx+$`Mm1h~l7 zy=05s#?zCE+(PhL5I_pUTu80yF8T*Kt`7Lr5THre^3)t5_W1ITHIv{p-sYg22yC!c zzx4?>7Q<-%CW0ahzLkj6LP#9MwNXW$XLZHv!(NP7xD;}=oxfxIIt9DR9aT<+v*_JmjiR19|)rt1Q=i6kvmcgif*zl_>qbqgUltbhX17jwXRQl)yg}{3m<25EdzwUW} zBZ!>QD+JQy4g`h#=wQ*I4^Z9O*?@(SlRp#uyz;1O9r%tiaUCtBj-fYF0d}vDA_uxD zy?->fwbVRn?=FT*Uoy%xt{!oWB#EG5_s%X_HDLauv+^r$r}z7*&d*i9=Zeq6=!*xi zAEt;Khxu>a?-`=VcXt&d+8_Ve7Z-jM;w4qKF^Kzg?#e)Y>J5Yr7pJ{C$1S+|^H}r5A|@mq)1Nz>yDhY4&**0x^Ai z5-YNEDeX6mAVEFeqvr>(iZTO8n4Z*DQ2CT9ik5R;vE^$h&8vj|0bNX)UItY##aum+ z)XyfD8|zlWR>yiyyN&SvCAJsUZH3wT`>AOYG>kHmub?cMk{R#1=vHwTymQxq%8ee> zYUzehE6pm%)C_aX7r`EBGQ(w@DfgmIettY)y&d<9zG$y~h#1Sp+1aR$%iyw$0k_94 z4JPU+4WX{3hv1$lh(2Uzf*g$M?V&?Bei+BTZhEk8Zrt3z$X(7d4oQxifpb&}A@p*DA?9~9 zg@8v;0(fFt_xLUwSW}A@5%4F%cRrwK*+)pty^Nbk(Na?4Mlj5>z`>|5v+PJLX0)r= zD83A8RPJlXZ6UV57g?6#ugGNK^(<24=mq<-9{x! zsfC&-6h93bk#m*qUR~)ls@{K+99LKhQ87P6rO(r^(uF*9=v5hzX^yWuro!Urj`{uT z+{-ZNTly1gRPjqC&*@Vgg)IJQXIe3tc)~kZj|KHA@^v;29z3k%wQe+S;}y{Q&-- zaj#HN!?aK)KJc+6q0*Z89mxrp>;2owqn`K+k|Djq!(?d?Ng+r6@_I3%x*nfWig$A_ zx$-e`lirCSG zB0QH4yfWu6?h=lD<+(SU%kLOhDW3|#)pJE66%;$oEb=9IJPI9~^ev7Uu*y`GRWhp?ergTf(}4GVeBMvt<@&;Cdoke+w!@%GrEPsrqhp!9co zV89d?{Z;?hZrdy`!C^aR=CE4Nys@rckUJo|(cQU669dH5&WthZbv3?Vs!8X`wZhHa;s|Z@l#PU@1L{S2sHM?;N+s zxEU=x+S48TysXXgg)b|RjL6O--#~q^4%ny_a2@t0l~dnPpLIV;g_Shyw{*nZRoVu` z46Piw_8vrjwkLw*9epF0;m`1?^e?rbxh7AI)Pncg)7>?Rv3w&xmaCidpiI7Fyj^}^ z3S%sx8^i6BKdFbS3to}um66MY1TQ~*_7HlI9u_0ruVG^3{^9HRhy-wTY!L~mE+iZ0X_KtGoZC%0-775$cm(ydC{i9HM5&l57<`x_zss2^Oo z^|UweTUeWyi%$>mX)|xNvkQ3#i#CAydmyTaIkrXMnh5~M89(*9A3h$zv-ZcVEsr%- zmednHvgiU7tha?%?*~TQ@|)3~?jGsXqE{CY(u2{EAtWcRM)*xJ0&hr7rkqERQJ^6OQ?%0P$CsSe? zdGb_j3avR>C8{-pNYiiRoX)+fy52+rvKk;IT?4n_N_$Ug)Hd2V7adzgbp_Tg5tl-U zEXlBd+RsD=zp>~vy2~%z+~!vRC`Cd1fOcd+$|vCO5Fjk5zla^MS;Ir-OPf*5Ii?qP z?N=5*vj3g+Fw~ihpKc;+${1p1D%sDmW6U!W33bamI7k+0pKfW;bnLKuFY@h z0kG-L>PNpR&tlZD((y;bpsnSh@bZ5cpgJxjOyOk~h=1ja9P zV+GDbgw`D5j>12CFDzgGaVOo!WZ5Ju)cGVw8k95nmyZX_3^ByNwKdCJQw=TGX_|OT zMp`lb?WAM%mJXEBe{}Ymwdcg&6LNSCY|*Os4V%aAXdP_wjN<)ZlLxuunr4pK5DN?t zub~~Ew}isXU!vwEB_flS>|ujN#;L>fXCZ3$r&(XWPNER z@|McTP-BuQ>)1?s<`Zvf^4b=XTpLo}8J3M8B$=x}q0oOron|~#nJQ6NPDc*qOc*Yb zVhR(=OeQ~W6L7mICAw<@*Q=amWvHfLJk|b0mMI?$Jr37)+H|HoZu4bk(-FQh#vLTZ zP0@>rx$0-VZvVBqG?5gOqDO;Dog%?-W~mS?WqzSz}%7^m|C9d2E)mU8o-_q(n2z6F?;$-PE zuaC#W=Wyq5`B}YQPJ&*XULJn0m%+<>4^yLu$UPRRgNx^MN(lbKkZ(*iAE&}y?}v+a zfv5x*;#xX3U}3BN7L$sD(=VM$KE!Lg3j0y{-7YSVw?|+4)h+wo>zmx@QT}es$M~=ZSgU9$yc>^lnm;U5h1rKCbU4`sSyz`n?@_F!Trbc0E^Gj^3JE$P7Vcl49pY zvZ_h>7R}F{J85mrD=M5oYea}!s$Bg@e~Mq#9X3genBm|0a;x~{X5(hD{T0eB>=1sUqQAo|+MN#87&{B} zItGf?*njd?Shq4mwHNPVQ-9vK^G-jX;FET;gEf|~rpZ(B|IK{@F=>4kq z0Y2Uww4(qH9{iT)pVPs{m`_GoZS5iN=)-TCW=lW)UN3CZ?fP5}_Pe73ZHfH^)rocS zAoRQ!yG(u2;jJ6(WNZ@i!QgwKp2yzWd1VA-bxoJuB`s!a6aKl4cA34&R(+$+c*PE} zKBY$u>V+)zswT9YO;3N(p}U~M(}(4$*1v6vxqBG1g{gxpRnFS^2l>jlE2y?A6`%Qz zuja!|ZB3KkEYnm+cWPHXZ=hepRj^?LxM9R32kJv|*c{ zT(Fa_Fiw542J_OMFOjTT+0tHggZcdw#gh0{QK-~45!-a*7K^al)-GL_%TQCypPtM_ z42U(tIb*i~^h49?Y~D5uFME?)f0`&OLSL~8^mK=qwrE;Eo?l-5vc6kec)@S%G_T9+ z@^XE6IDfr5TKa;YvtUda=d^+=X%GRP!i9|drLT&tNjp3JqBgXaJDz^p_3ZzI2#eog zP0Mgmy3z={LKbE7>nX*wKE<>`bGW9eOXiY}$R)RVyqKUm2f*A=ml^9OwWW%r*dS%U z){$FTXMChw<$KizFgzYjJW^}@sf!0Vb>QHsJpyoX*j<){tyKCFj zPc=R8ntGZIL%`dtx^jRwJ$Za+Yk8|wmcurdtuc0eTXi!^fxW->vexrkkN+r0L@I!1 z-K~bnl={00`X725VycIHc<-O^RrB55Q@K%hT1BYSGHHnS z%tU1uzIbX%oSLO?pB#?doEe1Z+Z(ZNi?QFf!DQs9i;j#iys}$*UG6vqW1E2L=(4Jg zYfXk4or>10>TI&C&A1OJLxr=55;)WHPWYDR?l!iy7+;mT^^~Cc^tBUBD9vD}SXix8 zQ|C%#Pj;CmU=>+YwQc-0Z?J#fk@Nf1!C~$vlHVs6r|!5srIep9nAcd9Kh~)K`RJ7Y zY>-LVG`vW)brml<9<$Go)x%nS8dabR=2<$|iI$`FzEEgXKE9RKJaGY&uT8QRJ56-Wjxfz zKN(-s9m(h{J=R8Vuz6ykWCKjgvDcmM6C;tF11bFHX00O+GZ~dRli$kM&_FX&2 zrzTr1GoCbQt7HP+_xqwszw*5uyN*1}FK4A2{cG3Z`z1(_4B!PQZwBm4I8!|K!sOWg zR(Tq)&(p22F}-WX-b{O=Jp^26-^Y9a5Mo2WA_0C?fbALO_KzC&?udTvH(%3X`QNNE zF|9$G-kkKKP6X$kzxU8;x6I08blcso2DUlkVmj$K?fz}yw6Y@4;yLRgq&BolEvt(1 z=;&Qpx1s1oPAa-aC_-|b^3-@YZ9T&r?^E3DHzWdtYryq{VgJiyi+%#_*rIh~w zi8sAc&}SD}P(eAD0j=&RWuT>A1H(9FjdU!4;5V(0>X+mq>tu$M9Lz4iOjVSF#(e;pzCeh@g5v01v@cRy+56jP+E;X=Wj zQIJ=^z1YyrmVt^Xh;+Zxk7gi#yk-sTn)IC|6h-IaF{kDe|WAI0U;S={vwoC=J%1CGMcF4sjhs4N;G|cDa z#eCJ=kAZj51$q{$(FbB91-|5j4Sm87tm1?}dBZh8BrM&3ycA^@1dj84>UX2`H}aen zEve&3KOhA~WW+5)0*MyM$cCjb2pu{wqZC9H^Vfk^46g+(e#2$in^MZ;y#8&EI7vM7 zJj~&wTVOQ|6(MpeBf$>?29ynH(2?T=BE*wJOifzJmCuN{4+HA^ojX7!L-?b7IRF=C zcwRz~-XM*5BDME*hkfjwmLZwoLcj`QPer|}tE=-ViTVn75?v5=8r>GGz2uD|!O};H z$$V0Uxu5-tD3O9aPJ3_ zBW3=&f>j=l!aDh9Lp)bR>uH7suUN-_HG_D{k>P4Ofr)wp7F=l8s?wdcAJ(I@`clb- zS#|NS{V&)Nv!aU#y4_bm5tbf-XO^mCNFk+bT=+iX*=vs!_Snh95UFhT<7ri&B7VBN z-2=e@GjL(6ZzHPZeZE$)_xrsnv)?U#zfUv#6sj}5?)RBD_I{ofnCXMk{b9sH^gu_yo9c}Kxb7FCs(qR_ ze|2_bsbxEKMd!AOr;dU z03|H^69gXr&EWQ&tPmzKUpYNHF<6;roC5?nyD*`@2=~=UBt~R-1D*6RgI};)@bmD% z>UsL{Y<*eSEB*J~MPM*wS6`Y1sIR}|7?9+I#6=|8`Z=g1r!$xbBcN{59>Cx;J)76# z{$#|Y{N;y{u+H!^_r6dvOKMP2w}^*((F6X6K$dKM`F=#z*5G*}CMWs@lHv57y$M*6 zh$p_`M<2QHP3vsH5}k#+wL4q%G6N5MPx!tS5L?WI7szf~HlKj+y|cdu01t<`9Y9aY z=!_c60}y0kw4+E>!qZhXyIKi&lnNPCY!4-BmIR44PO(T8Z7fl<&>jPpl_j6Tf1#d^YD*=~2C?i?(hA@GovZ}E*Vv(w>HRq&q*M7>XrM3h)6J(x<#pCFMxf5?rqhyH}3d`yRecn)ij z^R;W`;;neAldLuLr^0q#?56yxMb*%cag_NpNjX!|#(Ca8-C7{n3K51WdosN|EhFou zk~HGv>ZR=b>wM3n=880jI&+ZRnD{N%a zr>^m!fUS%a#c`@sg7`fyCdEqPvCr~mJ9ZL#F%1Xj86;EP)RE)B^5!bY+98z0Nrd5w zncpLD22F-v8ft4-LSrNFRk_`wQm3Ua-*L(JM~K&xElW8DeD^y4Z|<>dVk!0kc*S6U ztF@A7xF%uorc=jU^97YLRcu!3rct}4A1}|W*E&?`sr3f#s_dfnz_WMh?}%Hoc$}eE zTpR9wk642#HG{6|MM9`l>&D7scCBiwbBj7@OX=0!#0Hhi%lVWWV+s}3YG2{Z1)yHM z$c4r(Nlzu=EkZU+|LfpXSSUJ9ybJ2AJQ&$QTZ{1~-Mq{PbnS(tpMfJMeg>9ZS6GX$ zeE1pj;thTm{yuZxF23af?K-%Fd3A362shVIk?e&^Ur=rR&!3rUlVhD<8I8Ib@QpRF zVe4`-9{Ajdbjho`aTfQVlGo>_eXUk&S0_VV_yO;KN~|t%aS>Yh+3=GwlbQGPHG_b| z@LnqwR7ExzstPKp)KVxk9p*V;R4vs1V{FtAxh1lZR+aanw1zuNW2iWP7o z{OK3SJ5z!knyJUGKa6|Attz7MUOn1t<>paWGq*)_HQT-ez6{jMo`Py(FCczg=B78nwx5aIO3nI5vgjMJvNV+~bLh&MTyfh#^&guW z_9^b_>sr|u%B-`cK+Tdjac-E-+9AEp6ts)*pLX~yG5i+!$JlQr*N5K(MRo?{7^f+s zur^O!MYncAcq>(#l2i>s+k!l0MZ26*jX=8|tTU)N1*2-3{HkB`?u2$g^U@Bqled75 zv}^lQOthPA&UW0}dMpd|`+4He0GC;SlS{G0QlCOu1XT<-OuD_QW{{R>lx>Adlde$C zbVsj+1r1>OqQ1Pnz?as%8HFqH?|QbcNn=(qPWxo5FoRJ!PBBV*V$PhnDX1yIJf{D$ zS}`_(-oTQMgZ%{9Atnb@_nhX1%1or4wfpQeYt$2Xv;|if^ewXs?Xu% zpyfgK7nJsI#Cr)VT2VLda19$&3M}|9S10JC{G)k=i*^;&=Cr!pGwI|>EpD{wHK-2H zKm*KuP&$J3N{bDr4h~_|BnOYlE-hZ?e9ECj zNybg`Dh+EH8n*IIp^-H~SmnOB^EQvo{VtPW!z#24d8K+!Z6zEZwmKGhm%3pZq>9!Ye`9^|-L7U9|?} z7o;d@6!9>H*xuVC+P*m|Q?f$=L4SrJO)l;$Z4@zC-~aUMv^<&`*3X<+9?Ij67f4th z1`$gUbRm5lXK2n$I9#KGR5Geb!{v;V^aM9%pL-BmryYS_s7=H0y1kbzkEq5y-0x; zPD~Lgb?4>E-Q6g!i`Su22%27@ z^#Fdp1vCd1T7pXhR3X$s_;ErBNFpfZu}87e3LSFNi_0$Wtdvd8pfNN_Xz_CY3A1!s z8#Gr#D2q7nUj_)Q0F%(9mu57Np$^9QBt)Q#vtL^H*y=eeq_%GJUYKP_52j5hDCg)8 z?M8V(cVnL$G)jWyXk2(M9z!Z*)_-}I^;`c`euV!wR5q6$!h|U*n%+q|LEJ*q)i)oB9d0o^12QW2O(Up;G}Z1 zlo$WS9wl1Rya_%7O-78t-XSP-Nc-WxlSPXe zDH_uaA~kAYIhn`-6dW1jJ0#iR)Qq2W#tl5^zepvyM_mRO8|B#?= zlY@bnL(P%BBd6((9gUnjs81CBBkbhkYCnYiG~<{JJU0n4!`((ZCheb!xWeO4J4#xB zvpb*AERC=AwJfA!Y^MX)Fx1a&09Kr&5`>g73Nvju<3j(K5oJiPMr1S_>2WEd?R%9! z<(-V%FtIXn!a7K_az9BQl_X}FQK*cis?OuMN&(^TxJ&fP0M%U??twH)!RQ=CW1Ca=02i8Lo-cgIVZ)`Ir=9=d^s&V!>l7)wU$FOLzdGnL#Za5k*$y)l>;vcTu!pVc z=xwsg?R^rd*ecj|p~Xm0+j--WNB$x{l*UWSSx|>h17gN?979A~5uTlLLzAeeaO_G< zfV`-cwt1oqiGitHp++px@1hHRconh!(zWenzB-Te4f%tND;4ai%XXU~))WO>Bu;}; zMsL*6+`t^i94Dof(^o=kSh>!`AX7cBfxfbO-thg{f1u2$&_{lrRGO7gBAl8>Cn*qs zS9BftPjO#B0fn)z)~+PA6ddw)7d5ekb$BI@q9$p)UfH>?pIJ{1827CECaN5Z4BR*2faJmML^Lz05|a*m~-0H7dK{b=Z%;>Tuj8j_z{ zIjHDjHAArXbJ>)#&#E-IY#D0VL|@&gY;!uuo|rtKl7BJiQ-B65PlW3!8O8n}aHLDyVe4@5PB(vmxtTBZw=>QT`4jb0Q5(;7%$B zw5eOEf=k1ina_Q4jx`E&`uwnrheydIlWGCYTuLILwXBpF!OE=QVF(`1)>Sx}why&| zlRV;TsB!TX;moU?tXtiAX+-V1F_Jy`OBQ{ zLq7raU>jGIs&MM`{JpeK^}aWb<{1$5{Zmm4*6F*bY#ytc*$R!Hun$q4J-rWQIQ73fTY^%kc;ZR9CzgWrtLeo{yJAvlB8Wn zbYsbU&Oa;b(}ke|En3-42NjYSn$sw?8vnH}brkO!HI8Y~=ByO2xGVk?#&TDdeDwcm z5I{1Xvj1ri2(eWsmWdhR5i^RYA2zjZZI{G~og6v*brouC_X(n4R`a4`-anl;#XVk? zQ~b|9uL_Gp59Ce$3fE+Wj#9`TkaMR6RymmD4xs}#A|K4yF3X%&7u<40$GXhA8RjEe zorm9r742h~&-=prpGp(58tZ1xp8C#3lb!Q5x{7SKa(EGMPkZr-B`7&=WvN9RFdQWN zna;D^-s9cg@k?Rcm5G%q`YrT8dbMRbx1 zLupFNYv>z1C10AJ zCw>N0E!8POZ)H}0FFgKRUe#Ac`8d5ndM4lcl$hM5k* zNr&8^gVc&+bSL<4l^SeF2toI|1eNCnRSoRwJqLAC{dbJlkA9;%P?;^|)_@)AxcE z?tC&%sVhOlTi((@5xIRJHK$A2nN;78tW1%1+IjyWlG?ljwjO&)lxdE{_IsV;SobDRjVx7)iVVmLO=psjV*$&3m>0&k3Q$3mK7 z0}}&y5A5=>Bj&*mnPSazAk90O2Nhcc4!>(j_qH#groHsKN&hx&F3<&=esKk~rv9<4 zC1!j1BUwl*#sKz{nXuv%g3Y0dk73C*WU;u;1D96hR4!DEHbhh|tMqTtI=`Y)p8YZJ z510x{oa_k6?e=}RSstG(n>jiHYcNk9Dnh1~q>!@ZuBK9yW}iqMIv^8{ot2Zbx6w(t z*#@f`j6?4eGS9S^r$!t5hfmC5JyWceAny^=Y@OF1N& zO+9Y~-*g!>M!g_XFw0*0+5vr-m(6#y7D83HB_e3()j2nM+_f6+&GjC$|8o5QE+!cdCn>l`!cuIf2!VuBF;tW^|Z!=AT8DG(6EoM&BL? znc(VWYceu)`hKSsj8giDz=mSsuQtzw84~p zU1$38vBu7o@SbXO;V=D3%VjI^Z-SsAV{HKcxAadRwS&ulZqR))XqvO@Hv4Gp5?so_ z@m8nXQY}yBimOYp_5(zFj{TO{w4@}5-6x^fw0wP}LI}^2-k=x>dT(B4o?3JhefkM| zpPj4K@p(#2nOPy5TU&MF`Vqi~o%{-zpa1XBJ)VzttwF#Jh2pNf{pp>g!%PSKGC4uE zy>*)7t{SO3Pd1g*+iYi3)GpeO)@PCW^4K-Fm-V2%okNrp??OQ(gFzEq0OzJ1Xp`W?}K5R zI=?%_e=FJ_3R$WPu8KfytEIE)O2a`G5XogKcQuS$X+V&T=1#dN+U-t{i5lja@l*?84DFkBz%6Ic`+)V49JNG?=d4zwA@* zxQG=FqB7NSg9Co)Qcm?lf|Jz9HCk%##_4R!%s+9));?=JYw>^UBGooytm6NJ zgM$+P??39d{Qp*-aypqBdxKr2?Bvj<*}suA`@77I-xTBa##7_pHEOrd8czfNk4b_# zp*WdcH~ITI`QMK#{J%eF`TwmvOY*<>{l4E{p8x%2jwVVcO({~LwL^0>&^6=-hVLny z!UTE%Jb`RJA&`bl=Zr7#ZCS$jq5sGqw0vck&uaR=X7cwn@;?n8mHj{Z!=s~?{%_;i z19=9bB0-KcrpdfHQ$f0RE^p6HTBI^gE6qY`k6PET(gyA%TR3xgiOPZZ14)ck4g_;T zm`OgTvsY?6E=fQ@q6kX|MV+Hvnh{O<2>|9rPj-ejm9~@DWZ@QTKjGikx4Ix zIO#nhK_;|1mCRM>ZgIFrksK-ym!SW~$*jmL%}{v}zE#ZwdJEpvG&NBd3OJed+pu%8 z+B(fxKw*l`ag0bN&A9g8qq@2PCmhjBnJnA<6cs&#svZDU^x7?gHK5p9u&mpHH5)c< z!^(|l-ioE0QL`N@HpJc%Z>F>ZwTmv9DRg`ZQ$Z!V9taB^qC|H^iJ61W3n{j*2$t8_ zSv7OM=tFLwAmu4eLaTw5ng8N30}O{KfC`Kf@*^|IyS$Aolw5HHI)hG8_Zf~jqWM0> zS;Vmpxo*5^E4d`Cfpk@C38t0cVV4+PIpI!HD?#lO#32^gX@~Ao-JLC|HYHJra*`?H zu~}LERTaQEp>T$lK&xQ;1;|um-M!WyO^-MMS92`5Dv`bG{dIRzhrMz2R*54VD)u_E zx2j;j>UN40ZO_9INb3sJjY+GG=heYfzzI{v$1=0P8*-(FoFhD&^AUKg^3;CODa`RsYZf08vWlnzg+pXqbbc z0@UL#2|_l~y*8AtXNZ&8IE!OQ7qy6|tGGZi6=cq0T|`mE|LPT zPJCF}8c9zq&c7mm()I~{6 z^5(`4N(nO^mZ6R{HQ6v%*D!Rymwec~2wS2!y zW|!t|TUqhG?A~1~A?`Y1+D4NvWSBED4{itY?Em|>vikP5i7I&Rvdo> zr_A4M)nBgY)%ek#8UyzV7uwq6iwbaEN1I*S;@sd>Td$`yC*i3qURh%;zf<7i1m z+f#oX-`I^WVYq(4D>1BTx>h~)0kaf3(Qz@ZIhj-@nkNQRTh%SG-s-0LzcGO&f2!f+ z|2yyA;UvvC>x{t91$dm;dmV`uBhYy=es}if^~>Kb>^m~RWY65V+ zGChJdqYe%m3e1LlUoFySMN#_5ANWVs#P*jBpTY!1wS%YghN0a8Yv5~+$vEV7Lyk-D zcQ+yzY`t#C^KwD`n9i14ET=QFClO)Bmyy{d!x4Wj`W}>tqrmzR=ybdJm#c2KjKNAo zb(CGdR5r(9LkSK@a!MjXMgMd*fe-roU^p1;gW=K9J{UYK4`TpiXH5G4fs+VP&YEdg z^Pw{2B=kIM_c|!Vyt0nYEJ0inc#=htc_;AjoREm)v@-&I{W`+Qg(Nw%D{|)>iO>b` zUq3jU&gK#wX?j%R)!ALujk5ExYDthWPGa%?V}u?VZxy-ciJ|h<{Kozx|(ocmAq= z{=2ge0?5&fQ1#mUAqp6}L=SYF@Zp31@uO@ef5~b}PX-?=GD6wbc!R{zjyiQ)7oizS!e@lWkk^${G*x=u zNvDAm{9^A4j%6MqM{eXL<2j!4x*{&6Pe*%toI%Eba;I>1T#GiTvaHZSS{ZZGGKNTu zZH0{U?tRU>6+-5)6*5kZR>WqGmkfuGsmr*acZ=3X6JH7 zUan{bO-ax^6;N4U(v&@)S27QC$D}UH|Gp)yV1yx)U$vE%QrTEfsz>) z{A|!Km7w}2w%f6>LirlY^^40eghJru2f^v7vKHslp9DjIN!}9Asl02$i+8l== zO2&xd+FgCl>ZuW4&Z;Bmt)dh)5%C;{=xLntMRW20MU>Q+ z#_)Z^m`cH^E1?3|Jttut1{XD>37s)T;R~G9E$|bTmzzsR@DI>`2qp{gKrxUSX}P{Y{P5w| z4CD$S7J$#RAq{bu*E))j4%LMkJNOMOGpl_w?|n6X?O<|*y#I>6f?Adu zt9L`OLXKKHAgE`ZLQ6#NmrTf>RKJ0V=7Mn0P{AOndvJ5A2n=`KB%NZdLmoC1D_U{C zO*$0>6;;jB#R@bzEty~r+eZx*%-%d+3+@z&B`w1Q^j=;E3EvgBaYhOd>W>uytLd*_ zYK{Pk?ysvn{MNdAcYPKfCEREoz-o*fXDQeayp#3-qw-W{EV9=}pIbYCP4d`ZF?Qc{A z0$-#GWIX&^9jM%-)qz?aXh%9w5$d?rfDC|J4d})+APe1gqyHQ)(SHW5{_}b0KVPK! zBRzs!6Hu%EwCc~M>W|f?!-6@AVZphF$EJWUB4n-)X_Dx0ICF`qQ_5b_aXQ!GIdL-E zEP9m=E>)Ijd04n7jgi~d3NKd>bVa%OJwp+J@_F_VpKCAVvA+awAf(3!J{C(Rh&r4PJ%Xr}n6fO>m|( z$^XBZe+A!QgX#`vOB!h;RZuAvW(=LHPF*>)E%x3LiW(`kb0j@A;%{>_4H}y67*QLS z-lFQgL{+1&>>O3cMiJT^RaryR9iwXF(pyx$m#8Wf`<4gFR} z8vO5!UAScbIdbf-gTC|Uf&1scnTI>8f&1q{-z{}+gASd)238F4DpdX;^6qmdw_q9j z@oDud4A7rpOx;Y`h4JFQ*&pA(eVJRqioos4y~H-I-F42C&*|AD|BuPerSn?pI*n<6 z@@GZ<&x3w{Sjzu%bksj?^Z(q&qd(IVntwV~-x-;&ce|W-tX$kJ<+QOfp#+2?!u){5 zy*$&+*vW~ub-J5UqPTUk+cYp4@u$vd zE7SIirpnFXg-Y0O5<=$9(+CDAmT6NVLQK>^}da!IC!H zB)DG558G7+@LyE<;^ckH!n+Y5h!tK%^hCbNUbjgugz&=3b8omjRxO{O@C@&Ki^AiR-_DtCWDrRrENi}Sy%ODzAR z;+Xuob)5Mkl5Ta>n~OoOLhe>a+)4P|YlkAi$qdLZi5M{fn!=iIx6qP&0_hB9vsFIe zZDy1&QaT=NE*(E13HVKo0IW#G`-L-{C~FzSqAm&f31ux z_M+R2ENw;>tEA1y@<|ELhP#%V9~)Ii8;ZUCb+_Q|L4P;L|J&W3@9t?Loyzh5`*QM{ zHlNNN=hL~h)HAzEsMBW6S)uTM8sC^c%P3l#8@@jAaP7-ZJ^J=Y7NK3Hym?$ZUwOKD zw2tlT4r6wGS-McuXOR7+k-mxmUnb<&{g3pu{PT;Tm#y{edPQz`pJXI?eh$&W*5Sn~ zgMSr~y=p>#*-^b}0)MTDsZ}4|swVuGi40Z~`pamNH9^0Mh+s7#zf3f+nn+$nn6J+u zj904-wc3z+?x8m1Ua8%!QZ!tm6t$^rZret;Mm*C`SIZGgarGMQHU8_zkDz-`RhIaHrFus@|tV>MkdXLw$yK^l9GC}9#H6!D&t;L$XDgc-&`TT zboi+#hRu;+mqdYG8Uc1m^j9ma>sI>S4r8u@Hqh#)A82)Ffqy<2-u3POfPZ)Dlz~5& zX$sBq`{QRDi}emb_Qi%9`kcw*vyKCMCxC0o_ARwYuY*-Z-u<69uh6UUt zETH^l`~}>gfHeTlS0-b<*=mFG4a#HKSS4mZzJnB03atQutK3;DkqFC!*A!IZ57v&X zocY!qzG3B+yL8sjZow8yZWy!d^_Gu$UM{E~)7kqr!eS#4-(G~p`x{fS4Fy%LwcH21 z^5!16W^3ivpJK}RSXvHN1}7}r3APAMXnFXx!3p!KZE(VMZ{+>ElS0PYsD$9!e&O0( z^b9fv6#YAR)P^FwXYyx_Ye8S0^r^huMP$HM{IueyQT$9Hj#}}vGx75b;%GDRz6R=?C*-36c4!Dxd!0=_)bG!`zey0JzWuC|~hTh}&-}fu3`MnJdzM+Pj zLZ&p3d-TDedYEnFX>K;yXB1Dfim1C$?!T#>q14_VuVd+H$=z%sfs;=IBHd~RuyYiF*D3v zsbW{k$LZ73#%lJY#>Qi=Et54m4K4szAPPD1RC0A<)gI1fm7Y@>`I&~}R zlytam4OBOzPUX76YHg}X;rd*)sn1JW0&NDoHUnNB1-nj0f3~^nHd^c#8?F0(qU2|t zFK)vnx2SoqQ1i3S(YE1|ThzQ)sQJZYP1}0;EyCU_g#GODm~F7k78UOmDt@N9!!}y% z7mJbwM&8G)U-f(VdFSieWX&zwUN_U$QJZLMd7>?#KlzzTnfjz~J{_=&?;pSX!@R$l zJY0A6Y?A*=r@PT*tFnF-&+`0V{o&E!VJZLDVSjkk=Ks2l$IeP+WgH3!MTGeQiF6$GI>SqhS+`6{6)<|9v47awv2o)$GWf57LT17E?=Uv0VoMod>hfS z3&e~^V9t3eJDQWkOxtncD9z5Q=H%F#HZ@=Yg(*76F(Mf^O`Mm@hO2E|m*cB(d?R2@ zZS(iCQOj*g15zYW4JR{=6E0x1dq)MNY^kc2~=AgY@xuMr8- z5l~(T0m_@F5e!g_5`D4JO=LzyFQu4J%onE- zWbBn>58^eB;S34sNzn{5P8TCEn+Md#M7~Q26Owo_0vC%*L=)00CpFEm2S6&LE{cK? zcs_ka_!&hECENpm!0aJO+dZCZ z4Qn4T#6cf$B6<^m1DJcIN+U232q3!o5iJxMffQoO0G~q+AVmOj4ud%gMNbYmea}9| zfDa!%FCsGmwLKtRyXCIP<2VPyeji-I2!|>Oud<*qfD>8i?Q`&g%)}u9|A9uLvY3+E z@1B|dB}P{aKn4|HGF>0EI9-bnaPIW3P%xu5i7u<2Zju!8JlZu(UYTyMdaxp zl@?_?TrVPsaozyw9)%J=l& z1vTw~6V6eh#PS3ImQkeeYe6y!PR^b)iD?Pp00seKYJUX%in)-CGeP55ghrva2i`IS zI3W=O5xzj+pJ%W3K}zu@5ivpi61*TV1mD3(90RC8XY@WL3|X_l z34nm1KuquoE<_!LC1z1fI_~d*t~Mh)eXqyR0Q2_5!6C)!_{T=QGH39SZsF@5LH)A_ zD1yOU0>U(@p!%Dq<8v`_IjY|6lO=<9b)Bw4lImRczyoC(htb1zCh()`51h&V-1)Ez zoSwfJ8|)LW0z^5U3YAM>Mh~WGPrPD1N(lD@X!sdU5KuQ&fcoqqaX~ExsKw+QWC8`+ zk_0@^Tky~^lq%DOU?%Tlm_`V61)c*4$W?-{`WF}c22vI1f90HDD zEOWcVFx1RVG>6O~2Yce)p0@{Vz4dCQmT~cz`Iz)B2QW(KaOmv;Ww^2@@9lxYa3$bp z3_W}5e43{IMK(b+K^)26Vwk`g3cHg+GU>WMX5xaXv$$PPfzh^=!L}Vu5 z?CF0;(v}jCQ2Z9$hLH#XOFo)H#V5NqePBC9~7byCsQG~Ls3Ffb>^2? z3HCrtC<5~=hC(R8P~tn|Gz)k}(LSIkCYOjwIl^F^igUH+2?|%E$!Y7(G~p_-#WX83 zl@towt7lR~tF9w4H7TpnBol&=Tq1f!F-JcT#uaY|d&OIpgK$n5mk^MB{h#hLLa!hV zQP}PNV2b`v_cg^coTxW*c_D|1-4LWeQHZ5j&8b|jl@khQNSaL$3;~$}mTgK>D1PON(3)Z2?0}zrucpCylX3FqH@N>O0|3fAcc%w5gHnC zW#pW;zETt^@+X$Uk@G;o?^5TL%5qQn2t4jT?yv6fjoYDSs+y;Y?l0^&&AlU=4PBBb zixHDz&Y$@pCRxG_bFvt*g_q|q#-45_$yNP+DH^I5N-sXkqG*f)ip*QRou{JW2n;+g zL}^48g3iXALXKt&9a4V}P!b6edYgtq2*_6;hVRE2oe9P7=x_O}w+Xz2I1-y)6sUvy z8@m(FlLA{P@g(8sJ(qfWmYlG+Oz@q-@ZiwAc}0>pgz!Qoqxcd>Xy%}mV1;L<;QwRq z*_zw7v3}RDz{u@1?pIQh<0P%;OK04q+s(Aide+|QV@p$z#0^QX1eiwa_`mPq;0}Tp z$&Qn4#g{N9aL&Q)+z<3UO_Mwks*7sD`NTiUe9J-oEz2?8Qicno(OFzn=#I;pRLU0@ zq4S@90(W?tlA^k($tugS_$o)&lq@UoOUZD@>gE+$(s)vl<+-nw?+QTss&Dz)N^M`S z;4j>~YLYzPn!^vO8zYETIL%gD%O;V%fekT&a-6*7j6iUl1Xy^Qk%j{3bVIV#D1Q8u z#^?$fbHzO?(;6ofQ*P>&srZ)*?7As|bChqhnv{IsQNecdjIkVxji*TY3ehIraP&WC zWyS?)j9v--c1h45N$HHl>eiHEvzr6;NjD?N=~< zAxng<+SK_LUDpZB&59rUFU(Yb5lf&&CSnRl;N302KWFl9Y1N#eC-Xv%P>2=3 z!xOLlVqWkw13u;RG=)o69KBOYYIzY%Jfkf*_A9=`+Jf_YmmCb>wH|oT7jL`m`oAai4fYfDQ zT|i@Q$*ggW%I3PzM<9%&ufm<>uK6*-RRJix&K#zszXefWH4-vs`1j4WbCW zP!dJh@I_W;MN=TnkbzfNO1UjxxqU66Qn5lWU;_A_5hmse{pRxb-}qoCX1sZkmFI@< zFS;m7-T_5Td5<(%m>r5-Su~j(9idAMn-J78E@4aIU@6yJBLTixFV%+2NC}G43Nd0# zGgot8l9bL;Ql_|KI(dOcrLbJHay^rV?c6-xP|mC z*pTHkN>U(#PY@@BYpFV$ZeJyALuG|L%hlTv?@B@M5F>N| zL@cM0$r)rvO5}!cO^(oOvXnNQ+Bi#;P@1hlhKNP$T`?}9qIHuk@vJ0E9El)xM#|ZQ z|6d1`r5L^q^2>0@9N6kX#qX(&dN6d3)exvWqW#ZN`Z89qzEs`JM`Ve&XoPVAM z?jKs`G9VS5zgcJoSmAgDdoXQ~N)NOEH z#B?J#u$viah7k)y&Zl-3pS6X>n9g-t2mjV~a_dZuo0~wF_vrVAFzk)74J9Q-MN04l zH(B7j?Mml})IO7mrD32I*D}e4;b~LOUU#N#mf?_kL6&_~Y6sS?TlEfG?OwKmH%K?qHn=_m z>9T!m<)=U1d4;^N;2`bNzb&JZyO8b%H1AHig@(#mGB^jaBk zpxQjLx2lzze%uA7w8v#hO$AWh3^*MHU{FXpaS6#8Uw5c0?n)h0mk+19*ukiQMe$C4 z&#GJ}=^G1m|5r7oBUg50vp?NJd2uU;Pf%RE#q|qPRNNAo{{JFge8W{hE4CDK(?trS z*ixB{*ndQdj9EwBL5HSp2x@xVo(sPw#Rt(h)Y+Hl2h21p6+iC^rVa}6O>-MVh+WF9 zVE{!|>UwV@Js_uty`)}SPeY3K8jZ?B2o5HxpaEnB@Xyi0rP3agY^MSC()qCs^bh=u z@&5={-u{`uL-l{p=6?O({PfBE;Qx7u$I1U!m3|^H^m9@T6#2Ot6uP~Q#8&C9@pGBd zr&ZZ!+2gH>9yJHnQ8+{IBLI?<^(Ca(S|wUJS;sW{4_4JcPL8qF&icD;`-o~PFRj?> z=6zFLoGekRx%GD+i%!i2D&6$lK#Hyf6ne(Gi=!erb&cU{+#X1w4hEpe|7~@LR43hN zi0lqxN0Qo4U@O76)!%E;>gwhocXhX0b=JA*sExZt_9$&ms0)^|-`Qe}euo*9&D zpFmsNx!bJ+W8}X{J=;$Q7?A%@pPhL1ebq(IJBt6k z1hT4tmnk^Z6OUG2PDsUQCsT@MRHasSsTqNe{o2N0g}y)HzM6c=)YQp5Qx(d3aS(E+ zb5{gk`}Yyp9W5ttZy$$o>rQs7POja8Wr?03_?CD7jwo8HCdkYUPT$a`kcN=6r5}M~ z1I1TzP2%qoiZ2qjK~vjqnjQlYbd#Jsc}knYSHrsI?%daf?=U)bWWu=oqCHEOYS;6@ z6;e(uzB7yMIEt6!Y?`*RpNFo)___yg+fUqLKOtALHI$@b1hTp>opx8`4KCfgne@d7 z7Riy}j>MTUs-i|xT+wAuU94&*(e3Rl@KF^{qTAcE)@PQi(R-gDCn7lY zNw~18EL-qQ31)jsI^Ot}U(2-h)63h-0Rz|FjG*6$4Dk*b1 z{brt0^nAlubvB!MG z-O&br5Kha^F|?MUZQWN{>=fbzNY~$^4WVopiLlc=DB>vU8)M9)Pws`u>vdaHHDM$r z`5C%;abbPSv$wd!lwQ>28oT&7o*zWEuLCJzn=>@?|LR_5Bc2*3%j|AA1m^~z$JIqIL2U8a?gvFFw zgc*=3?wJhFXR6$4HqxEEYUAdsbFOH}KprE%?ZjKt%t^=HUv9Us>10|XmQ_CNXe>iG zI`d-<((V-6d!)i7FI#v`j`2R2cC!D**#9aEX5Rq7fc<~Ec-qeYd~(SDe2~ZECTgiw zk&6y*bB^>{hPb;pm2OPmrd+o2wq8zzP#moIT~aPv$aTd9dQ=jI9(i%wZ=WyX#n;ii zFLe7u#^meqvEu;%fSZK=h_@}gb_`+KQ>QVtKz{ZsA0@?Xe`wv~_uUCMt)IvYP0crB zr$%N083&Lljfr(Fy^|&oLU($v=&mtKywI)P1;1msp3twafYc6a7m_o zPAu<^Oxlh6=csOSY{3zil>13jmK;e7 zgM;U99i|8%vmKVqJPNQO1JH~!K4lV>Z#WHc&ry{6xU~Pt$JWh$+y@M| z)?X1So8lVRqQ4TYt?qV`QIM+FBWRFKg<(95&Y$mqy4#XmA6wx$JkB#l|Ce%FG~L4r z7|Q=y%%6Dr|H)$h?4bWY#N$aerykS(W%WTdQRrSyG3f`68~zWZ4JlQpBFoFpK;S+h zKyeniAe8rGE2Wpef3IGxvi1nAYEr0c_i9r(9`bcoivI_#Hy{98kQvdy{BinY_5FT( zTug5Kdn3mo9lZDBV!xNs_Sa_I*I>Jqd+(Hs3l{o~hLhHj*w^E9cs`|PjQp?2(%kiN z4Y!)?qy-Gf|Ha~&FaIAuo*(Z2evn6U#YbzXjAFqQnq#y$Ms`i9Z5y3mypoCmjsKod z#mZ-I7qg4@Z8%e3m(Z=9Dv4l=4tGxgOIYzx8~P(cHwu@u`^iDanH0j*2BcKW7f4+hRsR-h|A(H{OpyGt>fhO(AG~( zjTJ|y2Rmj5{x1vlcNYUg{D0o6|2sKZ9PDIl8<3xl5Q+fODE>rKHY l!o@qu*_WCBwb|a`IXs8w@ciYU{{{d6|NjFh>$?Du0|42gaSH$d literal 0 HcmV?d00001 diff --git a/charts/kubewarden-controller/values.yaml b/charts/kubewarden-controller/values.yaml index 9479c67f2..caa6441d3 100644 --- a/charts/kubewarden-controller/values.yaml +++ b/charts/kubewarden-controller/values.yaml @@ -127,6 +127,7 @@ resources: replicas: 1 auditScanner: enable: true + policyReporter: false # The default audit-scanner ServiceAccount is bound to the ClusterRoles: # - view: Allows read-only access to most objects in a namespace. # Does not allow viewing secrets, roles or role bindings. @@ -150,3 +151,18 @@ auditScanner: logLevel: info # Output result of scan to stdout in JSON upon completion outputScan: true + +# Values to configure the policy reporter subchart enabled by the +# auditScanner.policyReporter flag +policy-reporter: + image: + registry: ghcr.io + repository: kyverno/policy-reporter + tag: 2.15.4 + ui: + enabled: true + image: + registry: ghcr.io + repository: kyverno/policy-reporter-ui + tag: 1.8.4 + diff --git a/scripts/extract_images.sh b/scripts/extract_images.sh index b7a541d2c..56f97da03 100755 --- a/scripts/extract_images.sh +++ b/scripts/extract_images.sh @@ -12,7 +12,10 @@ if [ -e $IMAGELIST_FILENAME ]; then fi for chart in $CHARTS_DIRS; do - helm template --values "$chart"/values.yaml "$chart"/ | yq -r "..|.image?" | grep -v "null" > $TMP_IMAGE_FILE + # the set CLI flag is used only by the controller chart. But to + # simplify the script, it will be passed for all the chart. It will be + # ignore for the other chart anyway + helm template --values "$chart"/values.yaml --set auditScanner.policyReporter=true "$chart"/ | yq -r "..|.image?" | grep -v "null" > $TMP_IMAGE_FILE sed --in-place '/---/d' $TMP_IMAGE_FILE mv $TMP_IMAGE_FILE "$chart"/$IMAGELIST_FILENAME done