From 43b4284401a09a47d0bf708f0c3cf25c0752f2b3 Mon Sep 17 00:00:00 2001 From: Piotr Senkow Date: Tue, 19 May 2026 12:20:15 -0500 Subject: [PATCH 001/196] Add zendesk-wrapper-service helm chart and nginx subconf --- .../zendesk-wrapper-service.conf | 31 +++++++ helm/zendesk-wrapper/.helmignore | 17 ++++ helm/zendesk-wrapper/Chart.yaml | 29 +++++++ helm/zendesk-wrapper/templates/NOTES.txt | 1 + helm/zendesk-wrapper/templates/_helpers.tpl | 55 ++++++++++++ .../zendesk-wrapper/templates/deployment.yaml | 63 ++++++++++++++ helm/zendesk-wrapper/templates/service.yaml | 15 ++++ helm/zendesk-wrapper/values.yaml | 87 +++++++++++++++++++ 8 files changed, 298 insertions(+) create mode 100644 helm/revproxy/gen3.nginx.conf/zendesk-wrapper-service.conf create mode 100644 helm/zendesk-wrapper/.helmignore create mode 100644 helm/zendesk-wrapper/Chart.yaml create mode 100644 helm/zendesk-wrapper/templates/NOTES.txt create mode 100644 helm/zendesk-wrapper/templates/_helpers.tpl create mode 100644 helm/zendesk-wrapper/templates/deployment.yaml create mode 100644 helm/zendesk-wrapper/templates/service.yaml create mode 100644 helm/zendesk-wrapper/values.yaml diff --git a/helm/revproxy/gen3.nginx.conf/zendesk-wrapper-service.conf b/helm/revproxy/gen3.nginx.conf/zendesk-wrapper-service.conf new file mode 100644 index 000000000..29e2509e3 --- /dev/null +++ b/helm/revproxy/gen3.nginx.conf/zendesk-wrapper-service.conf @@ -0,0 +1,31 @@ + + location /zendesk/ { + + if ($csrf_check !~ ^ok-\S.+$) { + return 403 "failed csrf check"; + } + + set $authz_resource "/zendesk"; + set $authz_method "create"; + set $authz_service "zendesk"; + # # be careful - sub-request runs in same context as this request + auth_request_set $remoteUser $upstream_http_REMOTE_USER; + auth_request_set $saved_set_cookie $upstream_http_set_cookie; + auth_request /gen3-authz; + + proxy_set_header REMOTE_USER $remoteUser; + set $proxy_service "zendesk-wrapper-service"; + set $upstream http://zendesk-wrapper-service$des_domain; + rewrite ^/zendesk/(.*) /$1 break; + proxy_pass $upstream; + proxy_redirect http://$host/ https://$host/zendesk/; + + + proxy_set_header Authorization "$access_token"; + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header Upgrade $http_upgrade; + proxy_set_header Connection $connection_upgrade; + client_max_body_size 0; + } diff --git a/helm/zendesk-wrapper/.helmignore b/helm/zendesk-wrapper/.helmignore new file mode 100644 index 000000000..21846e965 --- /dev/null +++ b/helm/zendesk-wrapper/.helmignore @@ -0,0 +1,17 @@ +.DS_Store +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +*.swp +*.bak +*.tmp +*.orig +*~ +.project +.idea/ +*.tmproj +.vscode/ diff --git a/helm/zendesk-wrapper/Chart.yaml b/helm/zendesk-wrapper/Chart.yaml new file mode 100644 index 000000000..7709d1ae1 --- /dev/null +++ b/helm/zendesk-wrapper/Chart.yaml @@ -0,0 +1,29 @@ +apiVersion: v2 +name: zendesk-wrapper +description: A Helm chart for gen3 Zendesk Wrapper Service + +# A chart can be either an 'application' or a 'library' chart. +# +# Application charts are a collection of templates that can be packaged into versioned archives +# to be deployed. +# +# Library charts provide useful utilities or functions for the chart developer. They're included as +# a dependency of application charts to inject those utilities and functions into the rendering +# pipeline. Library charts do not define any templates and therefore cannot be deployed. +type: application + +# This is the chart version. This version number should be incremented each time you make changes +# to the chart and its templates, including the app version. +# Versions are expected to follow Semantic Versioning (https://semver.org/) +version: 0.1.0 + +# This is the version number of the application being deployed. This version number should be +# incremented each time you make changes to the application. Versions are not expected to +# follow Semantic Versioning. They should reflect the version the application is using. +# It is recommended to use it with quotes. +appVersion: "master" + +dependencies: + - name: common + version: 0.1.35 + repository: file://../common diff --git a/helm/zendesk-wrapper/templates/NOTES.txt b/helm/zendesk-wrapper/templates/NOTES.txt new file mode 100644 index 000000000..c1e7e1aef --- /dev/null +++ b/helm/zendesk-wrapper/templates/NOTES.txt @@ -0,0 +1 @@ +{{ .Chart.Name }} has been deployed successfully. diff --git a/helm/zendesk-wrapper/templates/_helpers.tpl b/helm/zendesk-wrapper/templates/_helpers.tpl new file mode 100644 index 000000000..e82a1cec2 --- /dev/null +++ b/helm/zendesk-wrapper/templates/_helpers.tpl @@ -0,0 +1,55 @@ +{{/* +Expand the name of the chart. +*/}} +{{- define "zendesk-wrapper.name" -}} +{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Create a default fully qualified app name. +*/}} +{{- define "zendesk-wrapper.fullname" -}} +{{- if .Values.fullnameOverride }} +{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- $name := default .Chart.Name .Values.nameOverride }} +{{- if contains $name .Release.Name }} +{{- .Release.Name | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }} +{{- end }} +{{- end }} +{{- end }} + +{{/* +Create chart name and version as used by the chart label. +*/}} +{{- define "zendesk-wrapper.chart" -}} +{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Common labels +*/}} +{{- define "zendesk-wrapper.labels" -}} +{{- if .Values.commonLabels }} + {{- with .Values.commonLabels }} + {{- toYaml . }} + {{- end }} +{{- else }} + {{- (include "common.commonLabels" .)}} +{{- end }} +{{- end }} + +{{/* +Selector labels +*/}} +{{- define "zendesk-wrapper.selectorLabels" -}} +{{- if .Values.selectorLabels }} + {{- with .Values.selectorLabels }} + {{- toYaml . }} + {{- end }} +{{- else }} + {{- (include "common.selectorLabels" .)}} +{{- end }} +{{- end }} diff --git a/helm/zendesk-wrapper/templates/deployment.yaml b/helm/zendesk-wrapper/templates/deployment.yaml new file mode 100644 index 000000000..8ea246b84 --- /dev/null +++ b/helm/zendesk-wrapper/templates/deployment.yaml @@ -0,0 +1,63 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: zendesk-wrapper-deployment + {{- with .Values.podAnnotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} + labels: + {{- include "zendesk-wrapper.labels" . | nindent 4 }} +spec: + {{- if not .Values.autoscaling.enabled }} + replicas: {{ .Values.replicaCount }} + {{- end }} + selector: + matchLabels: + {{- include "zendesk-wrapper.selectorLabels" . | nindent 6 }} + revisionHistoryLimit: {{ .Values.revisionHistoryLimit }} + {{- with .Values.strategy }} + strategy: + {{- toYaml . | nindent 4 }} + {{- end }} + template: + metadata: + labels: + {{- include "zendesk-wrapper.selectorLabels" . | nindent 8 }} + {{- include "common.extraLabels" . | nindent 8 }} + netnolimit: 'yes' + public: 'yes' + spec: + {{- if .Values.global.topologySpread.enabled }} + {{- include "common.TopologySpread" . | nindent 6 }} + {{- end }} + {{- with .Values.affinity }} + affinity: + {{- toYaml . | nindent 8 }} + {{- end }} + containers: + - name: {{ .Chart.Name }} + image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}" + livenessProbe: + httpGet: + path: /_status + port: 8000 + initialDelaySeconds: 10 + periodSeconds: 30 + timeoutSeconds: 10 + imagePullPolicy: {{ .Values.image.pullPolicy }} + ports: + - containerPort: 8000 + protocol: TCP + resources: + {{- toYaml .Values.resources | nindent 12 }} + env: + - name: GEN3_ZENDESK_URL + value: {{ .Values.env.GEN3_ZENDESK_URL | quote }} + - name: ZENDESK_API_EMAIL + value: {{ .Values.env.ZENDESK_API_EMAIL | quote }} + - name: ZENDESK_API_TOKEN + valueFrom: + secretKeyRef: + name: {{ .Values.secrets.name }} + key: {{ .Values.secrets.tokenKey }} diff --git a/helm/zendesk-wrapper/templates/service.yaml b/helm/zendesk-wrapper/templates/service.yaml new file mode 100644 index 000000000..0b23135b2 --- /dev/null +++ b/helm/zendesk-wrapper/templates/service.yaml @@ -0,0 +1,15 @@ +apiVersion: v1 +kind: Service +metadata: + name: "zendesk-wrapper-service" + labels: + {{- include "zendesk-wrapper.labels" . | nindent 4 }} +spec: + type: {{ .Values.service.type }} + ports: + - port: {{ .Values.service.port }} + targetPort: {{ .Values.service.port }} + protocol: TCP + name: http + selector: + {{- include "zendesk-wrapper.selectorLabels" . | nindent 4 }} diff --git a/helm/zendesk-wrapper/values.yaml b/helm/zendesk-wrapper/values.yaml new file mode 100644 index 000000000..90a783eb2 --- /dev/null +++ b/helm/zendesk-wrapper/values.yaml @@ -0,0 +1,87 @@ +# Default values for zendesk-wrapper. + +global: + environment: default + pdb: false + minAvailable: 1 + netPolicy: + enabled: false + dbSubnet: "" + autoscaling: + enabled: false + minReplicas: 1 + maxReplicas: 10 + averageCPUValue: 500m + averageMemoryValue: 500Mi + topologySpread: + enabled: false + topologyKey: "topology.kubernetes.io/zone" + maxSkew: 1 + +autoscaling: {} + +metricsEnabled: + +podAnnotations: {"gen3.io/network-ingress": "zendesk-wrapper"} + +replicaCount: 1 + +revisionHistoryLimit: 2 + +strategy: + type: RollingUpdate + rollingUpdate: + maxSurge: 1 + maxUnavailable: 0 + +affinity: + podAntiAffinity: + preferredDuringSchedulingIgnoredDuringExecution: + - weight: 100 + podAffinityTerm: + labelSelector: + matchExpressions: + - key: app + operator: In + values: + - zendesk-wrapper + topologyKey: "kubernetes.io/hostname" + +image: + repository: quay.io/cdis/zendesk-wrapper-service + pullPolicy: Always + tag: "" + +resources: + limits: + memory: 128Mi + +service: + type: ClusterIP + port: 8000 + +netPolicy: + ingressApps: + - zendesk-wrapper + egressApps: + - zendesk-wrapper + +# -- (map) Environment variables for the Zendesk wrapper service +env: + # -- (string) Zendesk instance URL (e.g., https://gen3support.zendesk.com) + GEN3_ZENDESK_URL: "" + # -- (string) Email of the agent account used with the API token + ZENDESK_API_EMAIL: "" + +# -- (map) Secret environment variables (referenced from Kubernetes secrets) +secrets: + # -- (string) Name of the Kubernetes secret containing the Zendesk API token + name: "zendesk-wrapper-secret" + # -- (string) Key within the secret for the API token + tokenKey: "ZENDESK_API_TOKEN" + +release: "production" +criticalService: "false" +partOf: "Core-Service" +selectorLabels: +commonLabels: From 1e79ac790c3b7697c32285eb348d37337d2ad0a1 Mon Sep 17 00:00:00 2001 From: Piotr Senkow Date: Wed, 27 May 2026 11:41:23 -0500 Subject: [PATCH 002/196] add zendesk-wrapper-service to dependencies in gen3 chart.yaml --- helm/gen3/Chart.yaml | 8 +++-- helm/gen3/README.md | 5 +-- helm/revproxy/Chart.yaml | 2 +- helm/revproxy/README.md | 2 +- helm/zendesk-wrapper/README.md | 61 ++++++++++++++++++++++++++++++++++ 5 files changed, 72 insertions(+), 6 deletions(-) create mode 100644 helm/zendesk-wrapper/README.md diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index e7a8b01fd..48fc8a74f 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -116,7 +116,7 @@ dependencies: repository: "file://../requestor" condition: requestor.enabled - name: revproxy - version: 0.1.58 + version: 0.1.59 repository: "file://../revproxy" condition: revproxy.enabled - name: sheepdog @@ -163,6 +163,10 @@ dependencies: version: 0.1.4 repository: file://../ohdsi-webapi condition: ohdsi-webapi.enabled + - name: zendesk-wrapper + version: 0.1.0 + repository: "file://../zendesk-wrapper" + condition: zendesk-wrapper.enabled - name: elasticsearch version: 7.10.2 @@ -197,7 +201,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.47 +version: 0.3.48 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index ea0355deb..f67351601 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,6 +1,6 @@ # gen3 -![Version: 0.3.47](https://img.shields.io/badge/Version-0.3.47-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.3.48](https://img.shields.io/badge/Version-0.3.48-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons @@ -54,11 +54,12 @@ Helm chart to deploy Gen3 Data Commons | file://../peregrine | peregrine | 0.1.41 | | file://../portal | portal | 0.1.57 | | file://../requestor | requestor | 0.1.33 | -| file://../revproxy | revproxy | 0.1.58 | +| file://../revproxy | revproxy | 0.1.59 | | file://../sheepdog | sheepdog | 0.1.41 | | file://../sower | sower | 0.1.45 | | file://../ssjdispatcher | ssjdispatcher | 0.1.45 | | file://../wts | wts | 0.1.39 | +| file://../zendesk-wrapper | zendesk-wrapper | 0.1.0 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | | https://helm.elastic.co | elasticsearch | 7.10.2 | diff --git a/helm/revproxy/Chart.yaml b/helm/revproxy/Chart.yaml index cfe9c1634..521cc585f 100644 --- a/helm/revproxy/Chart.yaml +++ b/helm/revproxy/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.58 +version: 0.1.59 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/revproxy/README.md b/helm/revproxy/README.md index 9b35e5503..db7dc04f1 100644 --- a/helm/revproxy/README.md +++ b/helm/revproxy/README.md @@ -1,6 +1,6 @@ # revproxy -![Version: 0.1.58](https://img.shields.io/badge/Version-0.1.58-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.59](https://img.shields.io/badge/Version-0.1.59-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 revproxy diff --git a/helm/zendesk-wrapper/README.md b/helm/zendesk-wrapper/README.md new file mode 100644 index 000000000..7b8f1d167 --- /dev/null +++ b/helm/zendesk-wrapper/README.md @@ -0,0 +1,61 @@ +# zendesk-wrapper + +![Version: 0.1.0](https://img.shields.io/badge/Version-0.1.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) + +A Helm chart for gen3 Zendesk Wrapper Service + +## Requirements + +| Repository | Name | Version | +|------------|------|---------| +| file://../common | common | 0.1.35 | + +## Values + +| Key | Type | Default | Description | +|-----|------|---------|-------------| +| affinity.podAntiAffinity.preferredDuringSchedulingIgnoredDuringExecution[0].podAffinityTerm.labelSelector.matchExpressions[0].key | string | `"app"` | | +| affinity.podAntiAffinity.preferredDuringSchedulingIgnoredDuringExecution[0].podAffinityTerm.labelSelector.matchExpressions[0].operator | string | `"In"` | | +| affinity.podAntiAffinity.preferredDuringSchedulingIgnoredDuringExecution[0].podAffinityTerm.labelSelector.matchExpressions[0].values[0] | string | `"zendesk-wrapper"` | | +| affinity.podAntiAffinity.preferredDuringSchedulingIgnoredDuringExecution[0].podAffinityTerm.topologyKey | string | `"kubernetes.io/hostname"` | | +| affinity.podAntiAffinity.preferredDuringSchedulingIgnoredDuringExecution[0].weight | int | `100` | | +| autoscaling | object | `{}` | | +| commonLabels | string | `nil` | | +| criticalService | string | `"false"` | | +| env | map | `{"GEN3_ZENDESK_URL":"","ZENDESK_API_EMAIL":""}` | Environment variables for the Zendesk wrapper service | +| env.GEN3_ZENDESK_URL | string | `""` | Zendesk instance URL (e.g., https://gen3support.zendesk.com) | +| env.ZENDESK_API_EMAIL | string | `""` | Email of the agent account used with the API token | +| global.autoscaling.averageCPUValue | string | `"500m"` | | +| global.autoscaling.averageMemoryValue | string | `"500Mi"` | | +| global.autoscaling.enabled | bool | `false` | | +| global.autoscaling.maxReplicas | int | `10` | | +| global.autoscaling.minReplicas | int | `1` | | +| global.environment | string | `"default"` | | +| global.minAvailable | int | `1` | | +| global.netPolicy.dbSubnet | string | `""` | | +| global.netPolicy.enabled | bool | `false` | | +| global.pdb | bool | `false` | | +| global.topologySpread.enabled | bool | `false` | | +| global.topologySpread.maxSkew | int | `1` | | +| global.topologySpread.topologyKey | string | `"topology.kubernetes.io/zone"` | | +| image.pullPolicy | string | `"Always"` | | +| image.repository | string | `"quay.io/cdis/zendesk-wrapper-service"` | | +| image.tag | string | `""` | | +| metricsEnabled | string | `nil` | | +| netPolicy.egressApps[0] | string | `"zendesk-wrapper"` | | +| netPolicy.ingressApps[0] | string | `"zendesk-wrapper"` | | +| partOf | string | `"Core-Service"` | | +| podAnnotations."gen3.io/network-ingress" | string | `"zendesk-wrapper"` | | +| release | string | `"production"` | | +| replicaCount | int | `1` | | +| resources.limits.memory | string | `"128Mi"` | | +| revisionHistoryLimit | int | `2` | | +| secrets | map | `{"name":"zendesk-wrapper-secret","tokenKey":"ZENDESK_API_TOKEN"}` | Secret environment variables (referenced from Kubernetes secrets) | +| secrets.name | string | `"zendesk-wrapper-secret"` | Name of the Kubernetes secret containing the Zendesk API token | +| secrets.tokenKey | string | `"ZENDESK_API_TOKEN"` | Key within the secret for the API token | +| selectorLabels | string | `nil` | | +| service.port | int | `8000` | | +| service.type | string | `"ClusterIP"` | | +| strategy.rollingUpdate.maxSurge | int | `1` | | +| strategy.rollingUpdate.maxUnavailable | int | `0` | | +| strategy.type | string | `"RollingUpdate"` | | From 8dd38db24b970679e7d65fe46dea797d759c9003 Mon Sep 17 00:00:00 2001 From: Piotr Senkow Date: Wed, 27 May 2026 11:43:27 -0500 Subject: [PATCH 003/196] Decouple service port and targetPort, add zendesk-wrapper to gen3 umbrella chart --- helm/gen3/Chart.yaml | 4 ++++ helm/gen3/values.yaml | 4 ++++ helm/zendesk-wrapper/templates/service.yaml | 2 +- helm/zendesk-wrapper/values.yaml | 3 ++- 4 files changed, 11 insertions(+), 2 deletions(-) diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index e7a8b01fd..5390b0687 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -135,6 +135,10 @@ dependencies: version: 0.1.39 repository: "file://../wts" condition: wts.enabled + - name: zendesk-wrapper + version: 0.1.0 + repository: "file://../zendesk-wrapper" + condition: zendesk-wrapper.enabled - name: gen3-network-policies version: 0.1.4 repository: "file://../gen3-network-policies" diff --git a/helm/gen3/values.yaml b/helm/gen3/values.yaml index 731e9869f..1aab54baa 100644 --- a/helm/gen3/values.yaml +++ b/helm/gen3/values.yaml @@ -398,6 +398,10 @@ wts: # -- (bool) Whether to deploy the wts subchart. enabled: true +zendesk-wrapper: + # -- (bool) Whether to deploy the zendesk-wrapper subchart. + enabled: false + sower: # -- (bool) Whether to deploy the sower subchart. enabled: false diff --git a/helm/zendesk-wrapper/templates/service.yaml b/helm/zendesk-wrapper/templates/service.yaml index 0b23135b2..764b0af5a 100644 --- a/helm/zendesk-wrapper/templates/service.yaml +++ b/helm/zendesk-wrapper/templates/service.yaml @@ -8,7 +8,7 @@ spec: type: {{ .Values.service.type }} ports: - port: {{ .Values.service.port }} - targetPort: {{ .Values.service.port }} + targetPort: {{ .Values.service.targetPort }} protocol: TCP name: http selector: diff --git a/helm/zendesk-wrapper/values.yaml b/helm/zendesk-wrapper/values.yaml index 90a783eb2..db8f264f1 100644 --- a/helm/zendesk-wrapper/values.yaml +++ b/helm/zendesk-wrapper/values.yaml @@ -58,7 +58,8 @@ resources: service: type: ClusterIP - port: 8000 + port: 80 + targetPort: 8000 netPolicy: ingressApps: From 82939b3b384b394cfdcf984a2c286b7a93c2927f Mon Sep 17 00:00:00 2001 From: Guerdon Mukama Date: Mon, 1 Jun 2026 19:24:12 +1000 Subject: [PATCH 004/196] fix: requestor g3auto secret --- helm/requestor/templates/_helpers.tpl | 7 +++++++ helm/requestor/templates/external-secret.yaml | 21 +++++++++++++++++++ helm/requestor/templates/secrets.yaml | 12 +++++++++++ helm/requestor/values.yaml | 11 ++++++++++ 4 files changed, 51 insertions(+) create mode 100644 helm/requestor/templates/secrets.yaml diff --git a/helm/requestor/templates/_helpers.tpl b/helm/requestor/templates/_helpers.tpl index 899b723ce..3502e57ea 100644 --- a/helm/requestor/templates/_helpers.tpl +++ b/helm/requestor/templates/_helpers.tpl @@ -77,4 +77,11 @@ Create the name of the service account to use {{- else }} {{- default .Values.secrets.password }} {{- end }} +{{- end }} + +{{/* + Requestor g3auto Secrets Manager Name +*/}} +{{- define "requestor-g3auto" -}} +{{- default "requestor-g3auto" .Values.externalSecrets.requestorG3auto }} {{- end }} \ No newline at end of file diff --git a/helm/requestor/templates/external-secret.yaml b/helm/requestor/templates/external-secret.yaml index 4a8f59d38..f33265c08 100644 --- a/helm/requestor/templates/external-secret.yaml +++ b/helm/requestor/templates/external-secret.yaml @@ -1,3 +1,24 @@ {{- if and .Values.global.externalSecrets.deploy (not .Values.global.externalSecrets.createLocalK8sSecret) }} {{ include "common.externalSecret.db" . }} +{{- end }} + +{{- if and .Values.global.externalSecrets.deploy (not .Values.externalSecrets.createK8sRequestorSecret) }} +--- +apiVersion: external-secrets.io/v1beta1 +kind: ExternalSecret +metadata: + name: requestor-g3auto +spec: + refreshInterval: 5m + secretStoreRef: + name: {{ include "common.SecretStore" . }} + kind: SecretStore + target: + name: requestor-g3auto + creationPolicy: Owner + data: + - secretKey: config.yaml + remoteRef: + key: {{ include "requestor-g3auto" . }} + property: config.yaml {{- end }} \ No newline at end of file diff --git a/helm/requestor/templates/secrets.yaml b/helm/requestor/templates/secrets.yaml new file mode 100644 index 000000000..797200873 --- /dev/null +++ b/helm/requestor/templates/secrets.yaml @@ -0,0 +1,12 @@ +{{- if or (not .Values.global.externalSecrets.deploy) .Values.externalSecrets.createK8sRequestorSecret }} +{{- if .Values.requestorConfig.enabled }} +apiVersion: v1 +kind: Secret +metadata: + name: requestor-g3auto +type: Opaque +stringData: + config.yaml: | +{{ .Values.requestorConfig.configYaml | indent 4 }} +{{- end }} +{{- end }} \ No newline at end of file diff --git a/helm/requestor/values.yaml b/helm/requestor/values.yaml index 9a24d751b..8f6488fbe 100644 --- a/helm/requestor/values.yaml +++ b/helm/requestor/values.yaml @@ -104,6 +104,10 @@ externalSecrets: pushSecret: false # -- (string) Will override the name of the aws secrets manager secret. Default is "Values.global.environment-.Chart.Name-creds" dbcreds: + # -- (string) Will create the Helm "requestor-g3auto" secret even if Secrets Manager is enabled. This is helpful if you are wanting to use External Secrets for some, but not all secrets. + createK8sRequestorSecret: false + # -- (string) Will override the name of the aws secrets manager secret. Default is "requestor-g3auto" + requestorG3auto: # -- (map) Secret information for External Secrets. secrets: # -- (str) AWS access key ID. Overrides global key. @@ -111,6 +115,13 @@ secrets: # -- (str) AWS secret access key ID. Overrides global key. awsSecretAccessKey: +# -- (map) Requestor runtime configuration. leave enabled=false and provide the secret externally. +requestorConfig: + # -- (bool) Create local Kubernetes secret from configYaml + enabled: false + # -- (str) ontents of requestor config.yaml + configYaml: "" + # -- (map) Postgres database configuration. If db does not exist in postgres cluster and dbCreate is set ot true then these databases will be created for you postgres: # (bool) Whether the database should be restored from s3. Default to global.postgres.dbRestore From 6a0191ef34c89dc1366b81c0bcd0cde3d09601e8 Mon Sep 17 00:00:00 2001 From: Piotr Senkow Date: Tue, 2 Jun 2026 13:14:47 -0500 Subject: [PATCH 005/196] Fix duplicate zendesk-wrapper entry in Chart.yaml --- helm/gen3/Chart.yaml | 4 ---- 1 file changed, 4 deletions(-) diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index e8f5a8315..940c1706b 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -167,10 +167,6 @@ dependencies: version: 0.1.4 repository: file://../ohdsi-webapi condition: ohdsi-webapi.enabled - - name: zendesk-wrapper - version: 0.1.0 - repository: "file://../zendesk-wrapper" - condition: zendesk-wrapper.enabled - name: elasticsearch version: 7.10.2 From c0c310be06405a8c52ba50cf5db9d42c9a60f8fe Mon Sep 17 00:00:00 2001 From: Ajo Augustine Date: Fri, 5 Jun 2026 12:06:24 -0500 Subject: [PATCH 006/196] add karpenter interruptionQueue support --- helm/cluster-level-resources/Chart.yaml | 2 +- helm/cluster-level-resources/README.md | 3 ++- helm/cluster-level-resources/templates/karpenter.yaml | 3 +++ helm/cluster-level-resources/values.yaml | 1 + 4 files changed, 7 insertions(+), 2 deletions(-) diff --git a/helm/cluster-level-resources/Chart.yaml b/helm/cluster-level-resources/Chart.yaml index 445cde6d8..94fc2b4f3 100644 --- a/helm/cluster-level-resources/Chart.yaml +++ b/helm/cluster-level-resources/Chart.yaml @@ -4,6 +4,6 @@ description: An app-of-apps Helm chart that allows for flexible deployment of re type: application -version: 0.6.43 +version: 0.6.44 appVersion: "1.17.0" diff --git a/helm/cluster-level-resources/README.md b/helm/cluster-level-resources/README.md index c902e0ac6..da054208d 100644 --- a/helm/cluster-level-resources/README.md +++ b/helm/cluster-level-resources/README.md @@ -1,6 +1,6 @@ # cluster-level-resources -![Version: 0.6.43](https://img.shields.io/badge/Version-0.6.43-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.17.0](https://img.shields.io/badge/AppVersion-1.17.0-informational?style=flat-square) +![Version: 0.6.44](https://img.shields.io/badge/Version-0.6.44-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.17.0](https://img.shields.io/badge/AppVersion-1.17.0-informational?style=flat-square) An app-of-apps Helm chart that allows for flexible deployment of resources that support Gen3 @@ -173,6 +173,7 @@ An app-of-apps Helm chart that allows for flexible deployment of resources that | karpenter.controller.image.digest | string | `"sha256:0c142050d872cb0ac7b30a188ec36aa765b449718cde0c7e49f7495b28f47c29"` | | | karpenter.controller.image.tag | string | `"1.0.8"` | | | karpenter.enabled | bool | `false` | | +| karpenter.interruptionQueue | string | `""` | | | karpenter.resources.limits.cpu | string | `"1"` | | | karpenter.resources.limits.memory | string | `"1Gi"` | | | karpenter.resources.requests.cpu | string | `"1"` | | diff --git a/helm/cluster-level-resources/templates/karpenter.yaml b/helm/cluster-level-resources/templates/karpenter.yaml index ed28085ed..882c078b7 100644 --- a/helm/cluster-level-resources/templates/karpenter.yaml +++ b/helm/cluster-level-resources/templates/karpenter.yaml @@ -38,6 +38,9 @@ spec: settings: clusterName: {{ .Values.eksClusterName | default .Values.cluster }} clusterEndpoint: {{ .Values.eksClusterEndpoint }} + {{- if .Values.karpenter.interruptionQueue }} + interruptionQueue: {{ .Values.karpenter.interruptionQueue }} + {{- end }} controller: env: - name: AWS_REGION diff --git a/helm/cluster-level-resources/values.yaml b/helm/cluster-level-resources/values.yaml index 7386c66f7..2063625b8 100644 --- a/helm/cluster-level-resources/values.yaml +++ b/helm/cluster-level-resources/values.yaml @@ -115,6 +115,7 @@ karpenter: enabled: false awsRegion: "us-east-1" targetRevision: 1.0.8 + interruptionQueue: "" configuration: enabled: false resources: From 0b2d47061d79d0f5c35d5ff6f3ad5fd6af21d157 Mon Sep 17 00:00:00 2001 From: Pauline Ribeyre <4224001+paulineribeyre@users.noreply.github.com> Date: Fri, 5 Jun 2026 15:23:07 -0500 Subject: [PATCH 007/196] TES endpoints check if token is blacklisted --- helm/gen3/Chart.yaml | 4 +-- helm/gen3/README.md | 4 +-- helm/revproxy/Chart.yaml | 2 +- helm/revproxy/README.md | 2 +- .../gen3.nginx.conf/fence-service.conf | 27 +++++++++++++++++++ .../gen3-workflow-service.conf | 2 ++ 6 files changed, 35 insertions(+), 6 deletions(-) diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index b6faaebf8..05050d5b2 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -116,7 +116,7 @@ dependencies: repository: "file://../requestor" condition: requestor.enabled - name: revproxy - version: 0.1.58 + version: 0.1.59 repository: "file://../revproxy" condition: revproxy.enabled - name: sheepdog @@ -197,7 +197,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.50 +version: 0.3.51 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index 01d70606a..4a136d40b 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,6 +1,6 @@ # gen3 -![Version: 0.3.50](https://img.shields.io/badge/Version-0.3.50-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.3.51](https://img.shields.io/badge/Version-0.3.51-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons @@ -54,7 +54,7 @@ Helm chart to deploy Gen3 Data Commons | file://../peregrine | peregrine | 0.1.41 | | file://../portal | portal | 0.1.57 | | file://../requestor | requestor | 0.1.33 | -| file://../revproxy | revproxy | 0.1.58 | +| file://../revproxy | revproxy | 0.1.59 | | file://../sheepdog | sheepdog | 0.1.41 | | file://../sower | sower | 0.1.45 | | file://../ssjdispatcher | ssjdispatcher | 0.1.46 | diff --git a/helm/revproxy/Chart.yaml b/helm/revproxy/Chart.yaml index cfe9c1634..521cc585f 100644 --- a/helm/revproxy/Chart.yaml +++ b/helm/revproxy/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.58 +version: 0.1.59 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/revproxy/README.md b/helm/revproxy/README.md index 9b35e5503..db7dc04f1 100644 --- a/helm/revproxy/README.md +++ b/helm/revproxy/README.md @@ -1,6 +1,6 @@ # revproxy -![Version: 0.1.58](https://img.shields.io/badge/Version-0.1.58-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.59](https://img.shields.io/badge/Version-0.1.59-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 revproxy diff --git a/helm/revproxy/gen3.nginx.conf/fence-service.conf b/helm/revproxy/gen3.nginx.conf/fence-service.conf index e76dbfcba..da23fcea4 100644 --- a/helm/revproxy/gen3.nginx.conf/fence-service.conf +++ b/helm/revproxy/gen3.nginx.conf/fence-service.conf @@ -20,6 +20,33 @@ location /authn-proxy { client_max_body_size 0; } +# Hits the fence API and stops the original request with a 403 if the provided +# token is blacklisted. Usage: `auth_request /block-blacklisted-token;` +location /block-blacklisted-token { + internal; + set $proxy_service "fence"; + error_page 400 =403 @errorworkspace; + error_page 500 =403 @errorworkspace; + + proxy_pass http://fence-service${des_domain}/credentials/token/blacklisted; + proxy_method POST; + proxy_pass_request_body off; + proxy_set_header Authorization "$access_token"; + proxy_set_header Content-Length ""; + proxy_set_header X-Forwarded-For "$realip"; + proxy_set_header X-UserId "$userid"; + proxy_set_header X-ReqId "$request_id"; + proxy_set_header X-SessionId "$session_id"; + proxy_set_header X-VisitorId "$visitor_id"; + proxy_set_header X-Original-URI $request_uri; + + # 4xx and 5xx errors return 403 (see `error_page` above) + proxy_intercept_errors on; + + # nginx bug that it checks even if request_body off + client_max_body_size 0; +} + location /user/ { if ($csrf_check !~ ^ok-\S.+$) { return 403 "failed csrf check"; diff --git a/helm/revproxy/gen3.nginx.conf/gen3-workflow-service.conf b/helm/revproxy/gen3.nginx.conf/gen3-workflow-service.conf index 859a68bff..6c148250d 100644 --- a/helm/revproxy/gen3.nginx.conf/gen3-workflow-service.conf +++ b/helm/revproxy/gen3.nginx.conf/gen3-workflow-service.conf @@ -2,6 +2,7 @@ location /ga4gh/tes/v1/ { if ($csrf_check !~ ^ok-\S.+$) { return 403 "failed csrf check"; } + auth_request /block-blacklisted-token; set $proxy_service "gen3-workflow"; set $upstream http://gen3-workflow-service.$namespace.svc.cluster.local; @@ -12,6 +13,7 @@ location /workflows/ { if ($csrf_check !~ ^ok-\S.+$) { return 403 "failed csrf check"; } + auth_request /block-blacklisted-token; set $proxy_service "gen3-workflow"; set $upstream http://gen3-workflow-service.$namespace.svc.cluster.local; From 7a2acee74f97f3a5ffd55eddd0ad0e8201ec9173 Mon Sep 17 00:00:00 2001 From: mark xiao Date: Wed, 10 Jun 2026 17:15:56 -0500 Subject: [PATCH 008/196] add gen3-embeddings --- helm/gen3-embeddings/.helmignore | 23 ++ helm/gen3-embeddings/Chart.yaml | 32 +++ helm/gen3-embeddings/README.md | 98 ++++++++ helm/gen3-embeddings/templates/NOTES.txt | 22 ++ helm/gen3-embeddings/templates/_helpers.tpl | 76 +++++++ helm/gen3-embeddings/templates/db-init.yaml | 9 + .../gen3-embeddings/templates/deployment.yaml | 210 ++++++++++++++++++ .../templates/external-secret.yaml | 34 +++ helm/gen3-embeddings/templates/hpa.yaml | 3 + helm/gen3-embeddings/templates/pdb.yaml | 3 + .../templates/secret-store.yaml | 3 + helm/gen3-embeddings/templates/secrets.yaml | 17 ++ helm/gen3-embeddings/templates/service.yaml | 15 ++ helm/gen3-embeddings/values.yaml | 203 +++++++++++++++++ helm/gen3/Chart.yaml | 8 +- helm/gen3/README.md | 6 +- helm/gen3/values.yaml | 4 + helm/revproxy/Chart.yaml | 2 +- helm/revproxy/README.md | 2 +- .../gen3-embeddings-service.conf | 12 + 20 files changed, 776 insertions(+), 6 deletions(-) create mode 100644 helm/gen3-embeddings/.helmignore create mode 100644 helm/gen3-embeddings/Chart.yaml create mode 100644 helm/gen3-embeddings/README.md create mode 100644 helm/gen3-embeddings/templates/NOTES.txt create mode 100644 helm/gen3-embeddings/templates/_helpers.tpl create mode 100644 helm/gen3-embeddings/templates/db-init.yaml create mode 100644 helm/gen3-embeddings/templates/deployment.yaml create mode 100644 helm/gen3-embeddings/templates/external-secret.yaml create mode 100644 helm/gen3-embeddings/templates/hpa.yaml create mode 100644 helm/gen3-embeddings/templates/pdb.yaml create mode 100644 helm/gen3-embeddings/templates/secret-store.yaml create mode 100644 helm/gen3-embeddings/templates/secrets.yaml create mode 100644 helm/gen3-embeddings/templates/service.yaml create mode 100644 helm/gen3-embeddings/values.yaml create mode 100644 helm/revproxy/gen3.nginx.conf/gen3-embeddings-service.conf diff --git a/helm/gen3-embeddings/.helmignore b/helm/gen3-embeddings/.helmignore new file mode 100644 index 000000000..0e8a0eb36 --- /dev/null +++ b/helm/gen3-embeddings/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/helm/gen3-embeddings/Chart.yaml b/helm/gen3-embeddings/Chart.yaml new file mode 100644 index 000000000..0f565b1d5 --- /dev/null +++ b/helm/gen3-embeddings/Chart.yaml @@ -0,0 +1,32 @@ +apiVersion: v2 +name: gen3-embeddings +description: A Helm chart for Kubernetes + +# A chart can be either an 'application' or a 'library' chart. +# +# Application charts are a collection of templates that can be packaged into versioned archives +# to be deployed. +# +# Library charts provide useful utilities or functions for the chart developer. They're included as +# a dependency of application charts to inject those utilities and functions into the rendering +# pipeline. Library charts do not define any templates and therefore cannot be deployed. +type: application + +# This is the chart version. This version number should be incremented each time you make changes +# to the chart and its templates, including the app version. +# Versions are expected to follow Semantic Versioning (https://semver.org/) +version: 0.1.0 + +# This is the version number of the application being deployed. This version number should be +# incremented each time you make changes to the application. Versions are not expected to +# follow Semantic Versioning. They should reflect the version the application is using. +# It is recommended to use it with quotes. +appVersion: "main" +dependencies: + - name: common + version: 0.1.35 + repository: file://../common + - name: postgresql + version: 11.9.13 + repository: "https://charts.bitnami.com/bitnami" + condition: postgres.separate diff --git a/helm/gen3-embeddings/README.md b/helm/gen3-embeddings/README.md new file mode 100644 index 000000000..0dc405d04 --- /dev/null +++ b/helm/gen3-embeddings/README.md @@ -0,0 +1,98 @@ +# gen3-embeddings + +![Version: 0.1.0](https://img.shields.io/badge/Version-0.1.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: main](https://img.shields.io/badge/AppVersion-main-informational?style=flat-square) + +A Helm chart for Kubernetes + +## Requirements + +| Repository | Name | Version | +|------------|------|---------| +| file://../common | common | 0.1.35 | +| https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | + +## Values + +| Key | Type | Default | Description | +|-----|------|---------|-------------| +| affinity | object | `{}` | | +| automountServiceAccountToken | bool | `false` | | +| autoscaling | object | `{}` | | +| commonLabels | map | `nil` | Will completely override the commonLabels defined in the common chart's _label_setup.tpl | +| criticalService | string | `"false"` | Valid options are "true" or "false". If invalid option is set- the value will default to "false". | +| dbMigrationsEnabled | bool | `true` | Whether to run database migrations on startup. If false, you will need to run the db-migrations Job manually after deployment. | +| debug | bool | `false` | | +| env | list | `[{"name":"GEN3_DEBUG","value":"false"},{"name":"ARBORIST_URL","valueFrom":{"configMapKeyRef":{"key":"arborist_url","name":"manifest-global","optional":true}}}]` | Environment variables to pass to the container | +| externalSecrets | map | `{"createK8sGen3EmbeddingsSecret":false,"dbcreds":null,"gen3EmbeddingsG3auto":null,"pushSecret":false}` | External Secrets settings. | +| externalSecrets.createK8sGen3EmbeddingsSecret | string | `false` | Will create the Helm "gen3Embeddings-g3auto" secret even if Secrets Manager is enabled. This is helpful if you are wanting to use External Secrets for some, but not all secrets. | +| externalSecrets.dbcreds | string | `nil` | Will override the name of the aws secrets manager secret. Default is "Values.global.environment-.Chart.Name-creds" | +| externalSecrets.gen3EmbeddingsG3auto | string | `nil` | Will override the name of the aws secrets manager secret. Default is "gen3UserDataLibrary-g3auto" | +| externalSecrets.pushSecret | bool | `false` | Whether to create the database and Secrets Manager secrets via PushSecret. | +| fullnameOverride | string | `""` | | +| global.autoscaling.averageCPUValue | string | `"500m"` | | +| global.autoscaling.averageMemoryValue | string | `"500Mi"` | | +| global.autoscaling.enabled | bool | `false` | | +| global.autoscaling.maxReplicas | int | `10` | | +| global.autoscaling.minReplicas | int | `1` | | +| global.aws | map | `{"awsAccessKeyId":null,"awsSecretAccessKey":null,"enabled":false,"externalSecrets":{"enabled":false,"externalSecretAwsCreds":null}}` | AWS configuration | +| global.aws.awsAccessKeyId | string | `nil` | Credentials for AWS stuff. | +| global.aws.awsSecretAccessKey | string | `nil` | Credentials for AWS stuff. | +| global.aws.enabled | bool | `false` | Set to true if deploying to AWS. Controls ingress annotations. | +| global.aws.externalSecrets.enabled | bool | `false` | Whether to use External Secrets for aws config. | +| global.aws.externalSecrets.externalSecretAwsCreds | String | `nil` | Name of Secrets Manager secret. | +| global.dev | bool | `true` | Whether the deployment is for development purposes. | +| global.externalSecrets | map | `{"deploy":false,"separateSecretStore":false}` | External Secrets settings. | +| global.externalSecrets.deploy | bool | `false` | Will use ExternalSecret resources to pull secrets from Secrets Manager instead of creating them locally. Be cautious as this will override any metadata secrets you have deployed. | +| global.externalSecrets.separateSecretStore | string | `false` | Will deploy a separate External Secret Store for this service. | +| global.postgres.dbCreate | bool | `true` | Whether the database should be created. | +| global.postgres.externalSecret | string | `""` | Name of external secret. Disabled if empty | +| global.postgres.master | map | `{"host":null,"password":null,"port":"5432","username":"postgres"}` | Master credentials to postgres. This is going to be the default postgres server being used for each service, unless each service specifies their own postgres | +| global.postgres.master.host | string | `nil` | hostname of postgres server | +| global.postgres.master.password | string | `nil` | password for superuser in postgres. This is used to create or restore databases | +| global.postgres.master.port | string | `"5432"` | Port for Postgres. | +| global.postgres.master.username | string | `"postgres"` | username of superuser in postgres. This is used to create or restore databases | +| global.topologySpread | map | `{"enabled":false,"maxSkew":1,"topologyKey":"topology.kubernetes.io/zone"}` | Karpenter topology spread configuration. | +| global.topologySpread.enabled | bool | `false` | Whether to enable topology spread constraints for all subcharts that support it. | +| global.topologySpread.maxSkew | int | `1` | The maxSkew to use for topology spread constraints. Defaults to 1. | +| global.topologySpread.topologyKey | string | `"topology.kubernetes.io/zone"` | The topology key to use for spreading. Defaults to "topology.kubernetes.io/zone". | +| gunicornWorkers | int | `1` | | +| image.pullPolicy | string | `"Always"` | | +| image.repository | string | `"quay.io/cdis/gen3-embeddings"` | | +| image.tag | string | `"main"` | | +| ingress.annotations | object | `{}` | | +| ingress.className | string | `""` | | +| ingress.enabled | bool | `false` | | +| ingress.hosts[0].host | string | `"chart-example.local"` | | +| ingress.hosts[0].paths[0].path | string | `"/"` | | +| ingress.hosts[0].paths[0].pathType | string | `"ImplementationSpecific"` | | +| ingress.tls | list | `[]` | | +| livenessProbe.httpGet.path | string | `"/"` | | +| livenessProbe.httpGet.port | string | `"http"` | | +| metricsEnabled | bool | `nil` | Whether Metrics are enabled. | +| nameOverride | string | `""` | | +| partOf | string | `"Embeddings"` | Label to help organize pods and their use. Any value is valid, but use "_" or "-" to divide words. | +| postgres | map | `{"database":null,"dbCreate":null,"dbRestore":false,"host":null,"password":null,"port":"5432","separate":false,"username":null}` | Postgres database configuration. If db does not exist in postgres cluster and dbCreate is set ot true then these databases will be created for you | +| postgres.database | string | `nil` | Database name for postgres. This is a service override, defaults to - | +| postgres.dbCreate | bool | `nil` | Whether the database should be created. Default to global.postgres.dbCreate | +| postgres.host | string | `nil` | Hostname for postgres server. This is a service override, defaults to global.postgres.host | +| postgres.password | string | `nil` | Password for Postgres. Will be autogenerated if left empty. | +| postgres.port | string | `"5432"` | Port for Postgres. | +| postgres.separate | string | `false` | Will create a Database for the individual service to help with developing it. | +| postgres.username | string | `nil` | Username for postgres. This is a service override, defaults to - | +| postgresql | map | `{"primary":{"persistence":{"enabled":false}}}` | Postgresql subchart settings if deployed separately option is set to "true". Disable persistence by default so we can spin up and down ephemeral environments | +| postgresql.primary.persistence.enabled | bool | `false` | Option to persist the dbs data. | +| readinessProbe.httpGet.path | string | `"/"` | | +| readinessProbe.httpGet.port | string | `"http"` | | +| release | string | `"production"` | Valid options are "production" or "dev". If invalid option is set- the value will default to "dev". | +| replicaCount | int | `1` | | +| resources | object | `{}` | | +| secrets | map | `{"awsAccessKeyId":null,"awsSecretAccessKey":null}` | Secret information to access the db restore job S3 bucket. | +| secrets.awsAccessKeyId | str | `nil` | AWS access key ID. Overrides global key. | +| secrets.awsSecretAccessKey | str | `nil` | AWS secret access key ID. Overrides global key. | +| selectorLabels | map | `nil` | Will completely override the selectorLabels defined in the common chart's _label_setup.tpl | +| service.port | int | `80` | | +| service.type | string | `"ClusterIP"` | | +| volumeMounts[0].mountPath | string | `"/services/gen3_embeddings/.env"` | | +| volumeMounts[0].name | string | `"gen3-embeddings-g3auto-volume"` | | +| volumeMounts[0].readOnly | bool | `true` | | +| volumeMounts[0].subPath | string | `"gen3-embeddings.env"` | | diff --git a/helm/gen3-embeddings/templates/NOTES.txt b/helm/gen3-embeddings/templates/NOTES.txt new file mode 100644 index 000000000..1aabeafed --- /dev/null +++ b/helm/gen3-embeddings/templates/NOTES.txt @@ -0,0 +1,22 @@ +1. Get the application URL by running these commands: +{{- if .Values.ingress.enabled }} +{{- range $host := .Values.ingress.hosts }} + {{- range .paths }} + http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $host.host }}{{ .path }} + {{- end }} +{{- end }} +{{- else if contains "NodePort" .Values.service.type }} + export NODE_PORT=$(kubectl get --namespace {{ .Release.Namespace }} -o jsonpath="{.spec.ports[0].nodePort}" services {{ include "gen3-embeddings.fullname" . }}) + export NODE_IP=$(kubectl get nodes --namespace {{ .Release.Namespace }} -o jsonpath="{.items[0].status.addresses[0].address}") + echo http://$NODE_IP:$NODE_PORT +{{- else if contains "LoadBalancer" .Values.service.type }} + NOTE: It may take a few minutes for the LoadBalancer IP to be available. + You can watch its status by running 'kubectl get --namespace {{ .Release.Namespace }} svc -w {{ include "gen3-embeddings.fullname" . }}' + export SERVICE_IP=$(kubectl get svc --namespace {{ .Release.Namespace }} {{ include "gen3-embeddings.fullname" . }} --template "{{"{{ range (index .status.loadBalancer.ingress 0) }}{{.}}{{ end }}"}}") + echo http://$SERVICE_IP:{{ .Values.service.port }} +{{- else if contains "ClusterIP" .Values.service.type }} + export POD_NAME=$(kubectl get pods --namespace {{ .Release.Namespace }} -l "app.kubernetes.io/name={{ include "gen3-embeddings.name" . }},app.kubernetes.io/instance={{ .Release.Name }}" -o jsonpath="{.items[0].metadata.name}") + export CONTAINER_PORT=$(kubectl get pod --namespace {{ .Release.Namespace }} $POD_NAME -o jsonpath="{.spec.containers[0].ports[0].containerPort}") + echo "Visit http://127.0.0.1:8080 to use your application" + kubectl --namespace {{ .Release.Namespace }} port-forward $POD_NAME 8080:$CONTAINER_PORT +{{- end }} diff --git a/helm/gen3-embeddings/templates/_helpers.tpl b/helm/gen3-embeddings/templates/_helpers.tpl new file mode 100644 index 000000000..23381414d --- /dev/null +++ b/helm/gen3-embeddings/templates/_helpers.tpl @@ -0,0 +1,76 @@ +{{/* +Expand the name of the chart. +*/}} +{{- define "gen3-embeddings.name" -}} +{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Create a default fully qualified app name. +We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). +If release name contains chart name it will be used as a full name. +*/}} +{{- define "gen3-embeddings.fullname" -}} +{{- if .Values.fullnameOverride }} +{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- $name := default .Chart.Name .Values.nameOverride }} +{{- if contains $name .Release.Name }} +{{- .Release.Name | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }} +{{- end }} +{{- end }} +{{- end }} + +{{/* +Create chart name and version as used by the chart label. +*/}} +{{- define "gen3-embeddings.chart" -}} +{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Common labels +*/}} +{{- define "gen3-embeddings.labels" -}} +{{- if .Values.commonLabels }} + {{- with .Values.commonLabels }} + {{- toYaml . }} + {{- end }} +{{- else }} + {{- (include "common.commonLabels" .)}} +{{- end }} +{{- end }} + +{{/* +Selector labels +*/}} +{{- define "gen3-embeddings.selectorLabels" -}} +{{- if .Values.selectorLabels }} + {{- with .Values.selectorLabels }} + {{- toYaml . }} + {{- end }} +{{- else }} + {{- (include "common.selectorLabels" .)}} +{{- end }} +{{- end }} + +{{/* + Postgres Password lookup +*/}} +{{- define "gen3-embeddings.postgres.password" -}} +{{- $localpass := (lookup "v1" "Secret" "postgres" "postgres-postgresql" ) -}} +{{- if $localpass }} +{{- default (index $localpass.data "postgres-password" | b64dec) }} +{{- else }} +{{- default .Values.postgres.password }} +{{- end }} +{{- end }} + +{{/* + Gen3Embeddings g3 Auto Secrets Manager Name +*/}} +{{- define "gen3embeddings-g3auto" -}} +{{- default "gen3embeddings-g3auto" .Values.externalSecrets.gen3EmbeddingsG3auto }} +{{- end }} diff --git a/helm/gen3-embeddings/templates/db-init.yaml b/helm/gen3-embeddings/templates/db-init.yaml new file mode 100644 index 000000000..0393aa732 --- /dev/null +++ b/helm/gen3-embeddings/templates/db-init.yaml @@ -0,0 +1,9 @@ +{{ include "common.db-secret" . }} +--- +{{ include "common.db_setup_sa" . }} +--- +{{- if .Values.dbRestore }} +{{ include "common.s3_pg_restore" . }} +{{- else }} +{{ include "common.db_setup_job" . }} +{{- end -}} \ No newline at end of file diff --git a/helm/gen3-embeddings/templates/deployment.yaml b/helm/gen3-embeddings/templates/deployment.yaml new file mode 100644 index 000000000..8dc7b15fc --- /dev/null +++ b/helm/gen3-embeddings/templates/deployment.yaml @@ -0,0 +1,210 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: gen3-embeddings-deployment + labels: + {{- include "gen3-embeddings.labels" . | nindent 4 }} +spec: + {{- if not .Values.autoscaling.enabled }} + replicas: {{ .Values.replicaCount }} + {{- end }} + selector: + matchLabels: + {{- include "gen3-embeddings.selectorLabels" . | nindent 6 }} + revisionHistoryLimit: {{ .Values.revisionHistoryLimit }} + {{- with .Values.strategy }} + strategy: + {{- toYaml . | nindent 4 }} + {{- end }} + template: + metadata: + labels: + {{- include "gen3-embeddings.selectorLabels" . | nindent 8 }} + {{- include "common.extraLabels" . | nindent 8 }} + # gen3 networkpolicy labels + netnolimit: 'yes' + public: 'yes' + userhelper: 'yes' + annotations: + checksum/config: {{ include (print $.Template.BasePath "/secrets.yaml") . | sha256sum }} + {{- $metricsEnabled := .Values.metricsEnabled }} + {{- if eq $metricsEnabled nil }} + {{- $metricsEnabled = .Values.global.metricsEnabled }} + {{- end }} + {{- if eq $metricsEnabled nil }} + {{- $metricsEnabled = true }} + {{- end }} + + {{- if $metricsEnabled }} + {{- include "common.grafanaAnnotations" . | nindent 8 }} + {{- end }} + spec: + {{- if .Values.global.topologySpread.enabled }} + {{- include "common.TopologySpread" . | nindent 6 }} + {{- end }} + {{- with .Values.affinity }} + affinity: + {{- toYaml . | nindent 8 }} + {{- end }} + automountServiceAccountToken: {{ .Values.automountServiceAccountToken }} + volumes: + - name: gen3-embeddings-g3auto-volume + secret: + secretName: gen3embeddings-g3auto + containers: + - name: {{ .Chart.Name }} + image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}" + env: + {{- toYaml .Values.env | nindent 12 }} + - name: PGHOST + valueFrom: + secretKeyRef: + name: gen3-embeddings-dbcreds + key: host + optional: false + - name: PGPORT + valueFrom: + secretKeyRef: + name: gen3-embeddings-dbcreds + key: port + optional: false + - name: PGUSER + valueFrom: + secretKeyRef: + name: gen3-embeddings-dbcreds + key: username + optional: false + - name: PGPASSWORD + valueFrom: + secretKeyRef: + name: gen3-embeddings-dbcreds + key: password + optional: false + - name: PGDATABASE + valueFrom: + secretKeyRef: + name: gen3-embeddings-dbcreds + key: database + optional: false + - name: CONFIG_PATH + value: /services/gen3_embeddings/.env + {{- if eq .Values.global.dev false }} + - name: FENCE_URL + value: https://{{ .Values.global.hostname }}/user + {{- else }} + - name: FENCE_URL + value: {{ default "http://fence-service" .Values.global.fenceURL | quote }} + {{- end }} + - name: DBREADY + valueFrom: + secretKeyRef: + name: gen3-embeddings-dbcreds + key: dbcreated + optional: false + imagePullPolicy: {{ .Values.image.pullPolicy }} + ports: + - containerPort: 4142 + name: http + livenessProbe: + httpGet: + path: /_status + port: 4142 + initialDelaySeconds: 30 + periodSeconds: 60 + timeoutSeconds: 30 + readinessProbe: + httpGet: + path: /_status + port: 4142 + {{- with .Values.volumeMounts }} + volumeMounts: + {{- toYaml . | nindent 10 }} + {{- end }} + {{- with .Values.resources }} + resources: + {{- toYaml . | nindent 12 }} + {{- end }} + initContainers: + - name: gen3-embeddings-init + image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}" + imagePullPolicy: {{ .Values.image.pullPolicy }} + env: + - name: GEN3_DEBUG + value: "False" + # Admin/master connection – same pattern as db_setup_job + - name: PGPASSWORD + {{- if $.Values.global.dev }} + valueFrom: + secretKeyRef: + name: {{ .Release.Name }}-postgresql + key: postgres-password + optional: false + {{- else if $.Values.global.postgres.externalSecret }} + valueFrom: + secretKeyRef: + name: {{ $.Values.global.postgres.externalSecret }} + key: password + optional: false + {{- else }} + value: {{ .Values.global.postgres.master.password | quote }} + {{- end }} + - name: PGUSER + {{- if $.Values.global.postgres.externalSecret }} + valueFrom: + secretKeyRef: + name: {{ $.Values.global.postgres.externalSecret }} + key: username + optional: false + {{- else }} + value: {{ .Values.global.postgres.master.username | quote }} + {{- end }} + - name: PGPORT + {{- if $.Values.global.postgres.externalSecret }} + valueFrom: + secretKeyRef: + name: {{ $.Values.global.postgres.externalSecret }} + key: port + optional: false + {{- else }} + value: {{ .Values.global.postgres.master.port | quote }} + {{- end }} + - name: PGHOST + {{- if $.Values.global.dev }} + value: "{{ .Release.Name }}-postgresql" + {{- else if $.Values.global.postgres.externalSecret }} + valueFrom: + secretKeyRef: + name: {{ $.Values.global.postgres.externalSecret }} + key: host + optional: false + {{- else }} + value: {{ .Values.global.postgres.master.host | quote }} + {{- end }} + + - name: PGDATABASE + valueFrom: + secretKeyRef: + name: gen3-embeddings-dbcreds + key: database + optional: false + - name: DBREADY + valueFrom: + secretKeyRef: + name: gen3-embeddings-dbcreds + key: dbcreated + optional: false + + {{- with .Values.volumeMounts }} + volumeMounts: + {{- toYaml . | nindent 12 }} + {{- end }} + {{- with .Values.resources }} + resources: + {{- toYaml . | nindent 12 }} + {{- end }} + command: ["/bin/bash", "-c"] + args: + - | + set -euo pipefail + echo "Running gen3-embeddings migrations..." + /venv/bin/python -u /services/gen3_embeddings/db_migrations/run_sql_files.py \ No newline at end of file diff --git a/helm/gen3-embeddings/templates/external-secret.yaml b/helm/gen3-embeddings/templates/external-secret.yaml new file mode 100644 index 000000000..e77eaea6e --- /dev/null +++ b/helm/gen3-embeddings/templates/external-secret.yaml @@ -0,0 +1,34 @@ +{{ if .Values.global.externalSecrets.deploy }} +apiVersion: external-secrets.io/v1beta1 +kind: ExternalSecret +metadata: + name: gen3embeddings-g3auto +spec: + refreshInterval: 5m + secretStoreRef: + name: {{include "common.SecretStore" .}} + kind: SecretStore + target: + name: gen3embeddings-g3auto + creationPolicy: Owner + data: + - secretKey: base64Authz.txt + remoteRef: + #name of secret in secrets manager + key: {{include "gen3embeddings-g3auto" .}} + property: base64Authz.txt + - secretKey: dbcreds.json + remoteRef: + #name of secret in secrets manager + key: {{include "gen3embeddings-g3auto" .}} + property: dbcreds.json + - secretKey: gen3-embeddings.env + remoteRef: + #name of secret in secrets manager + key: {{include "gen3embeddings-g3auto" .}} + property: gen3-embeddings.env +{{- end }} +--- +{{- if and .Values.global.externalSecrets.deploy (not .Values.global.externalSecrets.createLocalK8sSecret) }} +{{ include "common.externalSecret.db" . }} +{{- end }} \ No newline at end of file diff --git a/helm/gen3-embeddings/templates/hpa.yaml b/helm/gen3-embeddings/templates/hpa.yaml new file mode 100644 index 000000000..c3dee2ad8 --- /dev/null +++ b/helm/gen3-embeddings/templates/hpa.yaml @@ -0,0 +1,3 @@ +{{- if default .Values.global.autoscaling.enabled .Values.autoscaling.enabled }} +{{ include "common.hpa" . }} +{{- end }} \ No newline at end of file diff --git a/helm/gen3-embeddings/templates/pdb.yaml b/helm/gen3-embeddings/templates/pdb.yaml new file mode 100644 index 000000000..2ef2de13d --- /dev/null +++ b/helm/gen3-embeddings/templates/pdb.yaml @@ -0,0 +1,3 @@ +{{- if and .Values.global.pdb (gt (int .Values.replicaCount) 1) }} +{{ include "common.pod_disruption_budget" . }} +{{- end }} \ No newline at end of file diff --git a/helm/gen3-embeddings/templates/secret-store.yaml b/helm/gen3-embeddings/templates/secret-store.yaml new file mode 100644 index 000000000..771c7760d --- /dev/null +++ b/helm/gen3-embeddings/templates/secret-store.yaml @@ -0,0 +1,3 @@ +{{ if .Values.global.externalSecrets.separateSecretStore }} +{{ include "common.secretstore" . }} +{{- end }} \ No newline at end of file diff --git a/helm/gen3-embeddings/templates/secrets.yaml b/helm/gen3-embeddings/templates/secrets.yaml new file mode 100644 index 000000000..1c2245ae5 --- /dev/null +++ b/helm/gen3-embeddings/templates/secrets.yaml @@ -0,0 +1,17 @@ +{{- if or (not .Values.global.externalSecrets.deploy) (and .Values.global.externalSecrets.deploy .Values.externalSecrets.createK8sGen3EmbeddingsSecret) }} +apiVersion: v1 +kind: Secret +metadata: + name: gen3embeddings-g3auto +stringData: + {{- $randomPass := printf "%s%s" "gateway:" (randAlphaNum 32) }} + base64Authz.txt: {{ $randomPass | quote | b64enc }} + gen3-embeddings.env: | + DEBUG={{ .Values.debug}} + DB_HOST={{ .Values.postgres.host }} + DB_USER={{ .Values.postgres.username }} + GUNICORN_WORKERS={{ .Values.gunicornWorkers}} + DB_PASSWORD={{ include "gen3-embeddings.postgres.password" . }} + DB_DATABASE={{ .Values.postgres.dbname }} + ADMIN_LOGINS={{ $randomPass }} +{{- end }} \ No newline at end of file diff --git a/helm/gen3-embeddings/templates/service.yaml b/helm/gen3-embeddings/templates/service.yaml new file mode 100644 index 000000000..9d470fd62 --- /dev/null +++ b/helm/gen3-embeddings/templates/service.yaml @@ -0,0 +1,15 @@ +apiVersion: v1 +kind: Service +metadata: + name: "gen3-embeddings-service" + labels: + {{- include "gen3-embeddings.labels" . | nindent 4 }} +spec: + type: {{ .Values.service.type }} + ports: + - port: {{ .Values.service.port }} + targetPort: 4142 + protocol: TCP + name: http + selector: + {{- include "gen3-embeddings.selectorLabels" . | nindent 4 }} diff --git a/helm/gen3-embeddings/values.yaml b/helm/gen3-embeddings/values.yaml new file mode 100644 index 000000000..045c1153f --- /dev/null +++ b/helm/gen3-embeddings/values.yaml @@ -0,0 +1,203 @@ +# Default values for gen3-embeddings. +# This is a YAML-formatted file. +# Declare variables to be passed into your templates. + +global: + # -- (map) AWS configuration + aws: + # -- (bool) Set to true if deploying to AWS. Controls ingress annotations. + enabled: false + # -- (string) Credentials for AWS stuff. + awsAccessKeyId: + # -- (string) Credentials for AWS stuff. + awsSecretAccessKey: + externalSecrets: + # -- (bool) Whether to use External Secrets for aws config. + enabled: false + # -- (String) Name of Secrets Manager secret. + externalSecretAwsCreds: + # -- (bool) Whether the deployment is for development purposes. + dev: true + postgres: + # -- (bool) Whether the database should be created. + dbCreate: true + # -- (string) Name of external secret. Disabled if empty + externalSecret: "" + # -- (map) Master credentials to postgres. This is going to be the default postgres server being used for each service, unless each service specifies their own postgres + master: + # -- (string) hostname of postgres server + host: + # -- (string) username of superuser in postgres. This is used to create or restore databases + username: postgres + # -- (string) password for superuser in postgres. This is used to create or restore databases + password: + # -- (string) Port for Postgres. + port: "5432" + # -- (map) External Secrets settings. + externalSecrets: + # -- (bool) Will use ExternalSecret resources to pull secrets from Secrets Manager instead of creating them locally. Be cautious as this will override any metadata secrets you have deployed. + deploy: false + # -- (string) Will deploy a separate External Secret Store for this service. + separateSecretStore: false + # -- (map) This section is for setting up autoscaling more information can be found here: https://kubernetes.io/docs/concepts/workloads/autoscaling/ + autoscaling: + enabled: false + minReplicas: 1 + maxReplicas: 10 + averageCPUValue: 500m + averageMemoryValue: 500Mi + # -- (map) Karpenter topology spread configuration. + topologySpread: + # -- (bool) Whether to enable topology spread constraints for all subcharts that support it. + enabled: false + # -- (string) The topology key to use for spreading. Defaults to "topology.kubernetes.io/zone". + topologyKey: "topology.kubernetes.io/zone" + # -- (int) The maxSkew to use for topology spread constraints. Defaults to 1. + maxSkew: 1 + +# -- (map) This section is for setting up autoscaling more information can be found here: https://kubernetes.io/docs/concepts/workloads/autoscaling/ +autoscaling: {} + +# This will set the replicaset count more information can be found here: https://kubernetes.io/docs/concepts/workloads/controllers/replicaset/ +replicaCount: 1 +debug: false + +# This sets the container image more information can be found here: https://kubernetes.io/docs/concepts/containers/images/ +image: + repository: quay.io/cdis/gen3-embeddings + # This sets the pull policy for images. + pullPolicy: Always + # Overrides the image tag whose default is the chart appVersion. + tag: main + +# This is to override the chart name. +nameOverride: "" +fullnameOverride: "" + +# This is for setting up a service more information can be found here: https://kubernetes.io/docs/concepts/services-networking/service/ +service: + # This sets the service type more information can be found here: https://kubernetes.io/docs/concepts/services-networking/service/#publishing-services-service-types + type: ClusterIP + # This sets the ports more information can be found here: https://kubernetes.io/docs/concepts/services-networking/service/#field-spec-ports + port: 80 + +# This block is for setting up the ingress for more information can be found here: https://kubernetes.io/docs/concepts/services-networking/ingress/ +ingress: + enabled: false + className: "" + annotations: {} + # kubernetes.io/ingress.class: nginx + # kubernetes.io/tls-acme: "true" + hosts: + - host: chart-example.local + paths: + - path: / + pathType: ImplementationSpecific + tls: [] + # - secretName: chart-example-tls + # hosts: + # - chart-example.local + +resources: {} + # We usually recommend not to specify default resources and to leave this as a conscious + # choice for the user. This also increases chances charts run on environments with little + # resources, such as Minikube. If you do want to specify resources, uncomment the following + # lines, adjust them as necessary, and remove the curly braces after 'resources:'. + # limits: + # cpu: 100m + # memory: 128Mi + # requests: + # cpu: 100m + # memory: 128Mi +# -- (list) Environment variables to pass to the container +env: + - name: GEN3_DEBUG + value: "false" + - name: ARBORIST_URL + valueFrom: + configMapKeyRef: + name: manifest-global + key: arborist_url + optional: true +# This is to setup the liveness and readiness probes more information can be found here: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/ +livenessProbe: + httpGet: + path: / + port: http +readinessProbe: + httpGet: + path: / + port: http + +# Additional volumeMounts on the output Deployment definition. +volumeMounts: + - mountPath: /services/gen3_embeddings/.env + name: gen3-embeddings-g3auto-volume + readOnly: true + subPath: gen3-embeddings.env + +affinity: {} +automountServiceAccountToken: false + +# -- (map) Postgres database configuration. If db does not exist in postgres cluster and dbCreate is set ot true then these databases will be created for you +postgres: + # (bool) Whether the database should be restored from s3. Default to global.postgres.dbRestore + dbRestore: false + # -- (bool) Whether the database should be created. Default to global.postgres.dbCreate + dbCreate: + # -- (string) Hostname for postgres server. This is a service override, defaults to global.postgres.host + host: + # -- (string) Database name for postgres. This is a service override, defaults to - + database: + # -- (string) Username for postgres. This is a service override, defaults to - + username: + # -- (string) Port for Postgres. + port: "5432" + # -- (string) Password for Postgres. Will be autogenerated if left empty. + password: + # -- (string) Will create a Database for the individual service to help with developing it. + separate: false +# -- (map) Postgresql subchart settings if deployed separately option is set to "true". +# Disable persistence by default so we can spin up and down ephemeral environments +postgresql: + primary: + persistence: + # -- (bool) Option to persist the dbs data. + enabled: false + +# Values to determine the labels that are used for the deployment, pod, etc. +# -- (string) Valid options are "production" or "dev". If invalid option is set- the value will default to "dev". +release: "production" +# -- (string) Valid options are "true" or "false". If invalid option is set- the value will default to "false". +criticalService: "false" +# -- (string) Label to help organize pods and their use. Any value is valid, but use "_" or "-" to divide words. +partOf: "Embeddings" +# -- (map) Will completely override the selectorLabels defined in the common chart's _label_setup.tpl +selectorLabels: +# -- (map) Will completely override the commonLabels defined in the common chart's _label_setup.tpl +commonLabels: + +# -- (map) External Secrets settings. +externalSecrets: + # -- (string) Will create the Helm "gen3Embeddings-g3auto" secret even if Secrets Manager is enabled. This is helpful if you are wanting to use External Secrets for some, but not all secrets. + createK8sGen3EmbeddingsSecret: false + # -- (string) Will override the name of the aws secrets manager secret. Default is "gen3UserDataLibrary-g3auto" + gen3EmbeddingsG3auto: + # -- (bool) Whether to create the database and Secrets Manager secrets via PushSecret. + pushSecret: false + # -- (string) Will override the name of the aws secrets manager secret. Default is "Values.global.environment-.Chart.Name-creds" + dbcreds: + +# -- (bool) Whether Metrics are enabled. +metricsEnabled: + +# -- (map) Secret information to access the db restore job S3 bucket. +secrets: + # -- (str) AWS access key ID. Overrides global key. + awsAccessKeyId: + # -- (str) AWS secret access key ID. Overrides global key. + awsSecretAccessKey: +gunicornWorkers: 1 + +# -- (bool) Whether to run database migrations on startup. If false, you will need to run the db-migrations Job manually after deployment. +dbMigrationsEnabled: true diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index e7a8b01fd..1270afaf4 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -75,6 +75,10 @@ dependencies: version: 0.1.24 repository: "file://../funnel" condition: gen3-workflow.enabled + - name: gen3-embeddings + version: 0.1.0 + repository: "file://../gen3-embeddings" + condition: gen3-embeddings.enabled - name: gen3-user-data-library version: 0.1.14 repository: "file://../gen3-user-data-library" @@ -116,7 +120,7 @@ dependencies: repository: "file://../requestor" condition: requestor.enabled - name: revproxy - version: 0.1.58 + version: 0.1.59 repository: "file://../revproxy" condition: revproxy.enabled - name: sheepdog @@ -197,7 +201,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.47 +version: 0.3.48 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index ea0355deb..0b1adb111 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,6 +1,6 @@ # gen3 -![Version: 0.3.47](https://img.shields.io/badge/Version-0.3.47-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.3.48](https://img.shields.io/badge/Version-0.3.48-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons @@ -38,6 +38,7 @@ Helm chart to deploy Gen3 Data Commons | file://../frontend-framework | frontend-framework | 0.1.28 | | file://../funnel | funnel | 0.1.24 | | file://../gen3-analysis | gen3-analysis | 0.1.11 | +| file://../gen3-embeddings | gen3-embeddings | 0.1.0 | | file://../gen3-network-policies | gen3-network-policies | 0.1.4 | | file://../gen3-user-data-library | gen3-user-data-library | 0.1.14 | | file://../gen3-workflow | gen3-workflow | 0.1.19 | @@ -54,7 +55,7 @@ Helm chart to deploy Gen3 Data Commons | file://../peregrine | peregrine | 0.1.41 | | file://../portal | portal | 0.1.57 | | file://../requestor | requestor | 0.1.33 | -| file://../revproxy | revproxy | 0.1.58 | +| file://../revproxy | revproxy | 0.1.59 | | file://../sheepdog | sheepdog | 0.1.41 | | file://../sower | sower | 0.1.45 | | file://../ssjdispatcher | ssjdispatcher | 0.1.45 | @@ -122,6 +123,7 @@ Helm chart to deploy Gen3 Data Commons | frontend-framework.image.tag | string | `"main"` | Overrides the image tag whose default is the chart appVersion. | | gen3-analysis | map | `{"enabled":false}` | Configurations for gen3-analysis chart. | | gen3-analysis.enabled | bool | `false` | Whether to deploy the gen3-analysis subchart. | +| gen3-embeddings | map | `{"enabled":false}` | Configurations for gen3-embeddings chart. | | gen3-user-data-library | map | `{"enabled":false}` | Configurations for gen3-user-data-library chart. | | gen3-user-data-library.enabled | bool | `false` | Whether to deploy the gen3-user-data-library subchart. | | gen3-workflow | map | `{"enabled":false}` | Configurations for gen3-workflow chart. | diff --git a/helm/gen3/values.yaml b/helm/gen3/values.yaml index 731e9869f..9200cf6e3 100644 --- a/helm/gen3/values.yaml +++ b/helm/gen3/values.yaml @@ -249,6 +249,10 @@ gen3-analysis: data-upload-cron: enabled: false +# -- (map) Configurations for gen3-embeddings chart. +gen3-embeddings: + enabled: false + # -- (map) Configurations for gen3-user-data-library chart. gen3-user-data-library: # -- (bool) Whether to deploy the gen3-user-data-library subchart. diff --git a/helm/revproxy/Chart.yaml b/helm/revproxy/Chart.yaml index cfe9c1634..521cc585f 100644 --- a/helm/revproxy/Chart.yaml +++ b/helm/revproxy/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.58 +version: 0.1.59 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/revproxy/README.md b/helm/revproxy/README.md index 9b35e5503..db7dc04f1 100644 --- a/helm/revproxy/README.md +++ b/helm/revproxy/README.md @@ -1,6 +1,6 @@ # revproxy -![Version: 0.1.58](https://img.shields.io/badge/Version-0.1.58-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.59](https://img.shields.io/badge/Version-0.1.59-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 revproxy diff --git a/helm/revproxy/gen3.nginx.conf/gen3-embeddings-service.conf b/helm/revproxy/gen3.nginx.conf/gen3-embeddings-service.conf new file mode 100644 index 000000000..257470395 --- /dev/null +++ b/helm/revproxy/gen3.nginx.conf/gen3-embeddings-service.conf @@ -0,0 +1,12 @@ +location /embeddings { + if ($csrf_check !~ ^ok-\S.+$) { + return 403 "failed csrf check"; + } + + set $proxy_service "gen3-embeddings-service"; + set $upstream http://gen3-embeddings-service$des_domain; + rewrite ^/embeddings/(.*) /$1 break; + proxy_pass $upstream; + proxy_redirect http://$host/ https://$host/embeddings/; + client_max_body_size 0; +} From d5b24fbfc2159e7ecb0b864ccdc72f2d821c27b3 Mon Sep 17 00:00:00 2001 From: mark xiao Date: Fri, 12 Jun 2026 11:21:52 -0500 Subject: [PATCH 009/196] grant db service user access to newly created tables --- helm/common/Chart.yaml | 2 +- helm/common/README.md | 2 +- helm/common/templates/_db_setup_job.tpl | 2 +- helm/gen3/Chart.yaml | 2 +- helm/gen3/README.md | 2 +- 5 files changed, 5 insertions(+), 5 deletions(-) diff --git a/helm/common/Chart.yaml b/helm/common/Chart.yaml index 7902de9b6..797834d62 100644 --- a/helm/common/Chart.yaml +++ b/helm/common/Chart.yaml @@ -15,7 +15,7 @@ type: library # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.35 +version: 0.1.36 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/common/README.md b/helm/common/README.md index c1f8b9407..1438d8d0c 100644 --- a/helm/common/README.md +++ b/helm/common/README.md @@ -1,6 +1,6 @@ # common -![Version: 0.1.35](https://img.shields.io/badge/Version-0.1.35-informational?style=flat-square) ![Type: library](https://img.shields.io/badge/Type-library-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.36](https://img.shields.io/badge/Version-0.1.36-informational?style=flat-square) ![Type: library](https://img.shields.io/badge/Type-library-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for provisioning databases in gen3 diff --git a/helm/common/templates/_db_setup_job.tpl b/helm/common/templates/_db_setup_job.tpl index fecde9db8..392279092 100644 --- a/helm/common/templates/_db_setup_job.tpl +++ b/helm/common/templates/_db_setup_job.tpl @@ -163,7 +163,7 @@ spec: psql -c "GRANT ALL PRIVILEGES ON DATABASE \"$SERVICE_PGDB\" TO \"$SERVICE_PGUSER\";" psql -d $SERVICE_PGDB -c "ALTER SCHEMA public OWNER TO \"$SERVICE_PGUSER\";" psql -d $SERVICE_PGDB -c "GRANT ALL ON SCHEMA public TO \"$SERVICE_PGUSER\";" - psql -d $SERVICE_PGDB -c "GRANT ALL ON ALL TABLES IN SCHEMA public TO \"$SERVICE_PGUSER\";" + psql -d $SERVICE_PGDB -c "ALTER DEFAULT PRIVILEGES IN SCHEMA public GRANT ALL ON TABLES TO \"$SERVICE_PGUSER\";" psql -d $SERVICE_PGDB -c "ALTER ROLE \"$SERVICE_PGUSER\" WITH LOGIN;" echo "Creating ltree extension..." diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index 1270afaf4..b219f6038 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -41,7 +41,7 @@ dependencies: repository: "file://../cohort-middleware" condition: cohort-middleware.enabled - name: common - version: 0.1.35 + version: 0.1.36 repository: file://../common - name: dashboard version: 0.1.19 diff --git a/helm/gen3/README.md b/helm/gen3/README.md index 0b1adb111..10a5cb538 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -27,7 +27,7 @@ Helm chart to deploy Gen3 Data Commons | file://../aws-sigv4-proxy | aws-sigv4-proxy | 0.1.1 | | file://../cedar | cedar | 0.1.25 | | file://../cohort-middleware | cohort-middleware | 0.1.21 | -| file://../common | common | 0.1.35 | +| file://../common | common | 0.1.36 | | file://../dashboard | dashboard | 0.1.19 | | file://../data-upload-cron | data-upload-cron | 0.1.5 | | file://../datareplicate | datareplicate | 0.1.19 | From f42041a90740ac73c1c45bc6877554e9013073cb Mon Sep 17 00:00:00 2001 From: mark xiao Date: Fri, 12 Jun 2026 12:29:50 -0500 Subject: [PATCH 010/196] remove a value --- helm/gen3-embeddings/README.md | 1 - helm/gen3-embeddings/values.yaml | 2 -- 2 files changed, 3 deletions(-) diff --git a/helm/gen3-embeddings/README.md b/helm/gen3-embeddings/README.md index 0dc405d04..9c24a0db2 100644 --- a/helm/gen3-embeddings/README.md +++ b/helm/gen3-embeddings/README.md @@ -20,7 +20,6 @@ A Helm chart for Kubernetes | autoscaling | object | `{}` | | | commonLabels | map | `nil` | Will completely override the commonLabels defined in the common chart's _label_setup.tpl | | criticalService | string | `"false"` | Valid options are "true" or "false". If invalid option is set- the value will default to "false". | -| dbMigrationsEnabled | bool | `true` | Whether to run database migrations on startup. If false, you will need to run the db-migrations Job manually after deployment. | | debug | bool | `false` | | | env | list | `[{"name":"GEN3_DEBUG","value":"false"},{"name":"ARBORIST_URL","valueFrom":{"configMapKeyRef":{"key":"arborist_url","name":"manifest-global","optional":true}}}]` | Environment variables to pass to the container | | externalSecrets | map | `{"createK8sGen3EmbeddingsSecret":false,"dbcreds":null,"gen3EmbeddingsG3auto":null,"pushSecret":false}` | External Secrets settings. | diff --git a/helm/gen3-embeddings/values.yaml b/helm/gen3-embeddings/values.yaml index 045c1153f..2a18fafda 100644 --- a/helm/gen3-embeddings/values.yaml +++ b/helm/gen3-embeddings/values.yaml @@ -199,5 +199,3 @@ secrets: awsSecretAccessKey: gunicornWorkers: 1 -# -- (bool) Whether to run database migrations on startup. If false, you will need to run the db-migrations Job manually after deployment. -dbMigrationsEnabled: true From 2e8ae667d3175d81aaccca5d033e877243465797 Mon Sep 17 00:00:00 2001 From: avantol Date: Fri, 12 Jun 2026 12:40:38 -0500 Subject: [PATCH 011/196] feat(embeddings): update nginx conf to use /ai route --- .../gen3-discovery-ai-service.conf | 30 ++++++++++- .../gen3-embeddings-service.conf | 52 +++++++++++++++++-- 2 files changed, 76 insertions(+), 6 deletions(-) diff --git a/helm/revproxy/gen3.nginx.conf/gen3-discovery-ai-service.conf b/helm/revproxy/gen3.nginx.conf/gen3-discovery-ai-service.conf index 6e0827dd8..eaf41d89b 100644 --- a/helm/revproxy/gen3.nginx.conf/gen3-discovery-ai-service.conf +++ b/helm/revproxy/gen3.nginx.conf/gen3-discovery-ai-service.conf @@ -1,6 +1,32 @@ -location /ai { +location /ai/ask { if ($csrf_check !~ ^ok-\S.+$) { - return 403 "failed csrf check"; + return 403 "failed csrf check"; + } + + set $proxy_service "gen3-discovery-ai-service"; + set $upstream http://gen3-discovery-ai-service$des_domain; + rewrite ^/ai/ask/(.*) /ask/$1 break; + proxy_pass $upstream; + proxy_redirect http://$host/ https://$host/ai/ask/; + client_max_body_size 0; +} + +location /ai/topics { + if ($csrf_check !~ ^ok-\S.+$) { + return 403 "failed csrf check"; + } + + set $proxy_service "gen3-discovery-ai-service"; + set $upstream http://gen3-discovery-ai-service$des_domain; + rewrite ^/ai/topics/(.*) /topics/$1 break; + proxy_pass $upstream; + proxy_redirect http://$host/ https://$host/ai/topics/; + client_max_body_size 0; +} + +location /ai/discovery { + if ($csrf_check !~ ^ok-\S.+$) { + return 403 "failed csrf check"; } set $proxy_service "gen3-discovery-ai-service"; diff --git a/helm/revproxy/gen3.nginx.conf/gen3-embeddings-service.conf b/helm/revproxy/gen3.nginx.conf/gen3-embeddings-service.conf index 257470395..00fa18667 100644 --- a/helm/revproxy/gen3.nginx.conf/gen3-embeddings-service.conf +++ b/helm/revproxy/gen3.nginx.conf/gen3-embeddings-service.conf @@ -1,12 +1,56 @@ -location /embeddings { +# The Gen3 Embeddings service is deployed as part of the overall Gen3 AI +# support. Everything in Gen3 AI is available at the `/ai` route. +# This file defines routing from there to the Gen3 Embeddings service +# for functionality it handles. + +location /ai/vectorstore { + if ($csrf_check !~ ^ok-\S.+$) { + return 403 "failed csrf check"; + } + + set $proxy_service "gen3-embeddings-service"; + set $upstream http://gen3-embeddings-service$des_domain; + rewrite ^/ai/vectorstore/(.*) /vectorstore/$1 break; + proxy_pass $upstream; + proxy_redirect http://$host/ https://$host/ai/vectorstore/; + client_max_body_size 0; +} + +location /ai/embeddings { + if ($csrf_check !~ ^ok-\S.+$) { + return 403 "failed csrf check"; + } + + set $proxy_service "gen3-embeddings-service"; + set $upstream http://gen3-embeddings-service$des_domain; + rewrite ^/ai/embeddings/(.*) /embeddings/$1 break; + proxy_pass $upstream; + proxy_redirect http://$host/ https://$host/ai/embeddings/; + client_max_body_size 0; +} + +location /ai/embeddings/_version { + if ($csrf_check !~ ^ok-\S.+$) { + return 403 "failed csrf check"; + } + + set $proxy_service "gen3-embeddings-service"; + set $upstream http://gen3-embeddings-service$des_domain; + rewrite ^/ai/embeddings/_version /_version break; + proxy_pass $upstream; + proxy_redirect http://$host/ https://$host/ai/embeddings/_version; + client_max_body_size 0; +} + +location /ai/embeddings/_status { if ($csrf_check !~ ^ok-\S.+$) { - return 403 "failed csrf check"; + return 403 "failed csrf check"; } set $proxy_service "gen3-embeddings-service"; set $upstream http://gen3-embeddings-service$des_domain; - rewrite ^/embeddings/(.*) /$1 break; + rewrite ^/ai/embeddings/_status /_status break; proxy_pass $upstream; - proxy_redirect http://$host/ https://$host/embeddings/; + proxy_redirect http://$host/ https://$host/ai/embeddings/_status; client_max_body_size 0; } From 788397b65aaee4e3ab7dc3e564facdfec81b7d48 Mon Sep 17 00:00:00 2001 From: Pauline Ribeyre <4224001+paulineribeyre@users.noreply.github.com> Date: Mon, 15 Jun 2026 13:36:48 -0500 Subject: [PATCH 012/196] 405 => 403 --- .github/workflows/integration_tests_on_kind.yaml | 1 + helm/gen3/README.md | 15 --------------- helm/revproxy/gen3.nginx.conf/fence-service.conf | 3 +++ 3 files changed, 4 insertions(+), 15 deletions(-) diff --git a/.github/workflows/integration_tests_on_kind.yaml b/.github/workflows/integration_tests_on_kind.yaml index 943299ca4..052c7c5a4 100644 --- a/.github/workflows/integration_tests_on_kind.yaml +++ b/.github/workflows/integration_tests_on_kind.yaml @@ -6,6 +6,7 @@ on: - .github/workflows/integration_tests_on_kind.yaml - helm/funnel/** - helm/gen3-workflow/** + - helm/revproxy/gen3.nginx.conf/gen3-workflow-service.conf permissions: id-token: write diff --git a/helm/gen3/README.md b/helm/gen3/README.md index 93298f990..8ca3bbc01 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -47,20 +47,6 @@ Helm chart to deploy Gen3 Data Commons | file://../manifestservice | manifestservice | 0.1.42 | | file://../metadata | metadata | 0.1.44 | | file://../neuvector | neuvector | 0.1.2 | -<<<<<<< HEAD -| file://../ohdsi-atlas | ohdsi-atlas | 0.1.1 | -| file://../ohdsi-webapi | ohdsi-webapi | 0.1.4 | -| file://../ohif-viewer | ohif-viewer | 0.1.12 | -| file://../orthanc | orthanc | 0.1.13 | -| file://../peregrine | peregrine | 0.1.41 | -| file://../portal | portal | 0.1.57 | -| file://../requestor | requestor | 0.1.33 | -| file://../revproxy | revproxy | 0.1.59 | -| file://../sheepdog | sheepdog | 0.1.41 | -| file://../sower | sower | 0.1.45 | -| file://../ssjdispatcher | ssjdispatcher | 0.1.46 | -| file://../wts | wts | 0.1.39 | -======= | file://../ohdsi-atlas | ohdsi-atlas | 0.1.2 | | file://../ohdsi-webapi | ohdsi-webapi | 0.1.5 | | file://../ohif-viewer | ohif-viewer | 0.1.14 | @@ -73,7 +59,6 @@ Helm chart to deploy Gen3 Data Commons | file://../sower | sower | 0.1.46 | | file://../ssjdispatcher | ssjdispatcher | 0.1.47 | | file://../wts | wts | 0.1.40 | ->>>>>>> 0dae1a3a0e5825dabcc3eacc26d0c680f210a88a | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | | https://helm.elastic.co | elasticsearch | 7.10.2 | diff --git a/helm/revproxy/gen3.nginx.conf/fence-service.conf b/helm/revproxy/gen3.nginx.conf/fence-service.conf index da23fcea4..1de9f7516 100644 --- a/helm/revproxy/gen3.nginx.conf/fence-service.conf +++ b/helm/revproxy/gen3.nginx.conf/fence-service.conf @@ -27,6 +27,9 @@ location /block-blacklisted-token { set $proxy_service "fence"; error_page 400 =403 @errorworkspace; error_page 500 =403 @errorworkspace; + # Previous versions of Fence that don't have the "/token/blacklisted" endpoint return 405. + # Returning 403 forces the deployment of recent Fence for endpoints that require this check. + error_page 405 =403 @errorworkspace; proxy_pass http://fence-service${des_domain}/credentials/token/blacklisted; proxy_method POST; From ad00d9800dda5697190eec0cec86fd248d3ba039 Mon Sep 17 00:00:00 2001 From: Pauline Ribeyre <4224001+paulineribeyre@users.noreply.github.com> Date: Mon, 15 Jun 2026 13:40:36 -0500 Subject: [PATCH 013/196] version updates --- helm/gen3/Chart.yaml | 4 ++-- helm/gen3/README.md | 4 ++-- helm/revproxy/Chart.yaml | 2 +- helm/revproxy/README.md | 2 +- 4 files changed, 6 insertions(+), 6 deletions(-) diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index 42f368c1c..2d902fdde 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -116,7 +116,7 @@ dependencies: repository: "file://../requestor" condition: requestor.enabled - name: revproxy - version: 0.1.60 + version: 0.1.61 repository: "file://../revproxy" condition: revproxy.enabled - name: sheepdog @@ -197,7 +197,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.58 +version: 0.3.59 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index fa0a39e29..1c103cbb2 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,6 +1,6 @@ # gen3 -![Version: 0.3.58](https://img.shields.io/badge/Version-0.3.58-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.3.59](https://img.shields.io/badge/Version-0.3.59-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons @@ -54,7 +54,7 @@ Helm chart to deploy Gen3 Data Commons | file://../peregrine | peregrine | 0.1.42 | | file://../portal | portal | 0.1.60 | | file://../requestor | requestor | 0.1.34 | -| file://../revproxy | revproxy | 0.1.60 | +| file://../revproxy | revproxy | 0.1.61 | | file://../sheepdog | sheepdog | 0.1.42 | | file://../sower | sower | 0.1.46 | | file://../ssjdispatcher | ssjdispatcher | 0.1.47 | diff --git a/helm/revproxy/Chart.yaml b/helm/revproxy/Chart.yaml index 2c06d4186..37cb46c45 100644 --- a/helm/revproxy/Chart.yaml +++ b/helm/revproxy/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.60 +version: 0.1.61 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/revproxy/README.md b/helm/revproxy/README.md index 0bb27d15a..6fc8ada53 100644 --- a/helm/revproxy/README.md +++ b/helm/revproxy/README.md @@ -1,6 +1,6 @@ # revproxy -![Version: 0.1.60](https://img.shields.io/badge/Version-0.1.60-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.61](https://img.shields.io/badge/Version-0.1.61-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 revproxy From e5393f786065f66e35351fdf2ae072975153df08 Mon Sep 17 00:00:00 2001 From: Pauline Ribeyre <4224001+paulineribeyre@users.noreply.github.com> Date: Mon, 15 Jun 2026 14:01:13 -0500 Subject: [PATCH 014/196] fix? --- helm/revproxy/gen3.nginx.conf/fence-service.conf | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/helm/revproxy/gen3.nginx.conf/fence-service.conf b/helm/revproxy/gen3.nginx.conf/fence-service.conf index 1de9f7516..280ccfc0e 100644 --- a/helm/revproxy/gen3.nginx.conf/fence-service.conf +++ b/helm/revproxy/gen3.nginx.conf/fence-service.conf @@ -35,7 +35,7 @@ location /block-blacklisted-token { proxy_method POST; proxy_pass_request_body off; proxy_set_header Authorization "$access_token"; - proxy_set_header Content-Length ""; + proxy_set_header Content-Length "0"; proxy_set_header X-Forwarded-For "$realip"; proxy_set_header X-UserId "$userid"; proxy_set_header X-ReqId "$request_id"; From 99152438e74aeabf739d4d0fe53d2711768a053b Mon Sep 17 00:00:00 2001 From: Pauline Ribeyre <4224001+paulineribeyre@users.noreply.github.com> Date: Mon, 15 Jun 2026 14:06:54 -0500 Subject: [PATCH 015/196] fix? --- helm/revproxy/gen3.nginx.conf/fence-service.conf | 11 ++++++++--- 1 file changed, 8 insertions(+), 3 deletions(-) diff --git a/helm/revproxy/gen3.nginx.conf/fence-service.conf b/helm/revproxy/gen3.nginx.conf/fence-service.conf index 280ccfc0e..ac7da24f6 100644 --- a/helm/revproxy/gen3.nginx.conf/fence-service.conf +++ b/helm/revproxy/gen3.nginx.conf/fence-service.conf @@ -25,11 +25,11 @@ location /authn-proxy { location /block-blacklisted-token { internal; set $proxy_service "fence"; - error_page 400 =403 @errorworkspace; - error_page 500 =403 @errorworkspace; + error_page 400 =403 @block_blacklisted_token; + error_page 500 =403 @block_blacklisted_token; # Previous versions of Fence that don't have the "/token/blacklisted" endpoint return 405. # Returning 403 forces the deployment of recent Fence for endpoints that require this check. - error_page 405 =403 @errorworkspace; + error_page 405 =403 @block_blacklisted_token; proxy_pass http://fence-service${des_domain}/credentials/token/blacklisted; proxy_method POST; @@ -50,6 +50,11 @@ location /block-blacklisted-token { client_max_body_size 0; } +location @block_blacklisted_token { + internal; + return 403 "unable to check if token is blacklisted"; +} + location /user/ { if ($csrf_check !~ ^ok-\S.+$) { return 403 "failed csrf check"; From b2e7d99d17eeaca84e98e2453a6b8c0f1b4456c3 Mon Sep 17 00:00:00 2001 From: Pauline Ribeyre <4224001+paulineribeyre@users.noreply.github.com> Date: Mon, 15 Jun 2026 14:10:21 -0500 Subject: [PATCH 016/196] check if specific 405 is needed --- helm/revproxy/gen3.nginx.conf/fence-service.conf | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/helm/revproxy/gen3.nginx.conf/fence-service.conf b/helm/revproxy/gen3.nginx.conf/fence-service.conf index ac7da24f6..85d9588c8 100644 --- a/helm/revproxy/gen3.nginx.conf/fence-service.conf +++ b/helm/revproxy/gen3.nginx.conf/fence-service.conf @@ -25,11 +25,10 @@ location /authn-proxy { location /block-blacklisted-token { internal; set $proxy_service "fence"; - error_page 400 =403 @block_blacklisted_token; - error_page 500 =403 @block_blacklisted_token; # Previous versions of Fence that don't have the "/token/blacklisted" endpoint return 405. # Returning 403 forces the deployment of recent Fence for endpoints that require this check. - error_page 405 =403 @block_blacklisted_token; + error_page 400 =403 @block_blacklisted_token; + error_page 500 =403 @block_blacklisted_token; proxy_pass http://fence-service${des_domain}/credentials/token/blacklisted; proxy_method POST; From 012e1a0fd42d00252e693b99b567272a6109c301 Mon Sep 17 00:00:00 2001 From: Pauline Ribeyre <4224001+paulineribeyre@users.noreply.github.com> Date: Mon, 15 Jun 2026 14:16:01 -0500 Subject: [PATCH 017/196] yes it's needed --- helm/revproxy/gen3.nginx.conf/fence-service.conf | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/helm/revproxy/gen3.nginx.conf/fence-service.conf b/helm/revproxy/gen3.nginx.conf/fence-service.conf index 85d9588c8..d1abfd31a 100644 --- a/helm/revproxy/gen3.nginx.conf/fence-service.conf +++ b/helm/revproxy/gen3.nginx.conf/fence-service.conf @@ -25,10 +25,11 @@ location /authn-proxy { location /block-blacklisted-token { internal; set $proxy_service "fence"; - # Previous versions of Fence that don't have the "/token/blacklisted" endpoint return 405. - # Returning 403 forces the deployment of recent Fence for endpoints that require this check. error_page 400 =403 @block_blacklisted_token; error_page 500 =403 @block_blacklisted_token; + # Previous versions of Fence that don't have the "/token/blacklisted" endpoint return 405. + # Returning 403 forces the deployment of a recent Fence for endpoints that require this check. + error_page 405 =403 @block_blacklisted_token; proxy_pass http://fence-service${des_domain}/credentials/token/blacklisted; proxy_method POST; From f361fdf89c51751914fbaee58cc398110da200eb Mon Sep 17 00:00:00 2001 From: Guerdon Mukama Date: Tue, 16 Jun 2026 21:21:17 +1000 Subject: [PATCH 018/196] fix(revproxy): bypass CSRF check for REMS webhook endpoint MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The REMS event notification webhook (POST /requestor/api/v1/rems-webhook) is a server-to-server call from REMS to requestor. CSRF protection is designed for browser-to-server requests and is not applicable here — there are no user cookies or browser sessions involved. Adding a more specific location block for the webhook path before the general /requestor/ block so nginx matches it first and skips the CSRF check. The webhook is authenticated via the x-rems-webhook-secret shared secret header, which is enforced server-side in requestor and required — requests are rejected with 401 if the secret is not configured or does not match. Resolves: ACDC-113 --- .../gen3.nginx.conf/requestor-service.conf | 29 ++++++++++++------- 1 file changed, 18 insertions(+), 11 deletions(-) diff --git a/helm/revproxy/gen3.nginx.conf/requestor-service.conf b/helm/revproxy/gen3.nginx.conf/requestor-service.conf index 4f38b625b..1a5fbf110 100644 --- a/helm/revproxy/gen3.nginx.conf/requestor-service.conf +++ b/helm/revproxy/gen3.nginx.conf/requestor-service.conf @@ -1,11 +1,18 @@ - location /requestor/ { - if ($csrf_check !~ ^ok-\S.+$) { - return 403 "failed csrf check"; - } - - set $proxy_service "requestor-service"; - set $upstream http://requestor-service$des_domain; - rewrite ^/requestor/(.*) /$1 break; - proxy_pass $upstream; - proxy_redirect http://$host/ https://$host/requestor/; - } +location /requestor/api/v1/rems-webhook { + set $proxy_service "requestor-service"; + set $upstream http://requestor-service$des_domain; + rewrite ^/requestor/(.*) /$1 break; + proxy_pass $upstream; + proxy_redirect http://$host/ https://$host/requestor/; +} + +location /requestor/ { + if ($csrf_check !~ ^ok-\S.+$) { + return 403 "failed csrf check"; + } + set $proxy_service "requestor-service"; + set $upstream http://requestor-service$des_domain; + rewrite ^/requestor/(.*) /$1 break; + proxy_pass $upstream; + proxy_redirect http://$host/ https://$host/requestor/; +} \ No newline at end of file From c3b7a47ea2f4c71d3e85c47d14c33ff1eafe21bc Mon Sep 17 00:00:00 2001 From: mark xiao Date: Tue, 16 Jun 2026 09:25:49 -0500 Subject: [PATCH 019/196] update image name --- helm/gen3-embeddings/README.md | 2 +- helm/gen3-embeddings/values.yaml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/helm/gen3-embeddings/README.md b/helm/gen3-embeddings/README.md index 9c24a0db2..9236bf607 100644 --- a/helm/gen3-embeddings/README.md +++ b/helm/gen3-embeddings/README.md @@ -56,7 +56,7 @@ A Helm chart for Kubernetes | global.topologySpread.topologyKey | string | `"topology.kubernetes.io/zone"` | The topology key to use for spreading. Defaults to "topology.kubernetes.io/zone". | | gunicornWorkers | int | `1` | | | image.pullPolicy | string | `"Always"` | | -| image.repository | string | `"quay.io/cdis/gen3-embeddings"` | | +| image.repository | string | `"quay.io/cdis/gen3_embeddings"` | | | image.tag | string | `"main"` | | | ingress.annotations | object | `{}` | | | ingress.className | string | `""` | | diff --git a/helm/gen3-embeddings/values.yaml b/helm/gen3-embeddings/values.yaml index 2a18fafda..5245f52d9 100644 --- a/helm/gen3-embeddings/values.yaml +++ b/helm/gen3-embeddings/values.yaml @@ -64,7 +64,7 @@ debug: false # This sets the container image more information can be found here: https://kubernetes.io/docs/concepts/containers/images/ image: - repository: quay.io/cdis/gen3-embeddings + repository: quay.io/cdis/gen3_embeddings # This sets the pull policy for images. pullPolicy: Always # Overrides the image tag whose default is the chart appVersion. From 5128e18d0c9f8e88cf3f1b508bf8944ac88c061b Mon Sep 17 00:00:00 2001 From: mark xiao Date: Wed, 24 Jun 2026 14:54:51 -0500 Subject: [PATCH 020/196] update db migration --- helm/gen3-embeddings/templates/deployment.yaml | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/helm/gen3-embeddings/templates/deployment.yaml b/helm/gen3-embeddings/templates/deployment.yaml index 8dc7b15fc..aaaa229bf 100644 --- a/helm/gen3-embeddings/templates/deployment.yaml +++ b/helm/gen3-embeddings/templates/deployment.yaml @@ -51,6 +51,9 @@ spec: - name: gen3-embeddings-g3auto-volume secret: secretName: gen3embeddings-g3auto + {{- with .Values.extraVolumes }} + {{- toYaml . | nindent 8 }} + {{- end }} containers: - name: {{ .Chart.Name }} image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}" @@ -207,4 +210,6 @@ spec: - | set -euo pipefail echo "Running gen3-embeddings migrations..." - /venv/bin/python -u /services/gen3_embeddings/db_migrations/run_sql_files.py \ No newline at end of file + DATABASE_URL="postgresql://${PGUSER}:${PGPASSWORD}@${PGHOST}:${PGPORT}/${PGDATABASE}?sslmode=disable" + dbmate -u "$DATABASE_URL" -d "/services/gen3_embeddings/db/migrations" migrate + echo "Migrations completed." \ No newline at end of file From dc4804cf375271ab4d8808df9ebd460efe83cd0f Mon Sep 17 00:00:00 2001 From: Sai Shanmukha Date: Wed, 1 Jul 2026 20:55:30 -0500 Subject: [PATCH 021/196] Rename `/blacklisted` to `/denylist` and deny public access for this endpoint --- helm/gen3/Chart.yaml | 4 ++-- helm/gen3/README.md | 4 ++-- helm/revproxy/Chart.yaml | 2 +- helm/revproxy/README.md | 2 +- helm/revproxy/gen3.nginx.conf/fence-service.conf | 14 ++++++++++---- .../gen3.nginx.conf/gen3-workflow-service.conf | 6 +++--- 6 files changed, 19 insertions(+), 13 deletions(-) diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index c21a8f708..c8f0df14c 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -116,7 +116,7 @@ dependencies: repository: "file://../requestor" condition: requestor.enabled - name: revproxy - version: 0.1.61 + version: 0.1.62 repository: "file://../revproxy" condition: revproxy.enabled - name: sheepdog @@ -197,7 +197,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.59 +version: 0.3.60 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index b9a48b561..83c4907d0 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,6 +1,6 @@ # gen3 -![Version: 0.3.59](https://img.shields.io/badge/Version-0.3.59-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.3.60](https://img.shields.io/badge/Version-0.3.60-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons @@ -54,7 +54,7 @@ Helm chart to deploy Gen3 Data Commons | file://../peregrine | peregrine | 0.1.42 | | file://../portal | portal | 0.1.60 | | file://../requestor | requestor | 0.1.34 | -| file://../revproxy | revproxy | 0.1.61 | +| file://../revproxy | revproxy | 0.1.62 | | file://../sheepdog | sheepdog | 0.1.42 | | file://../sower | sower | 0.1.46 | | file://../ssjdispatcher | ssjdispatcher | 0.1.47 | diff --git a/helm/revproxy/Chart.yaml b/helm/revproxy/Chart.yaml index 37cb46c45..88ae26629 100644 --- a/helm/revproxy/Chart.yaml +++ b/helm/revproxy/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.61 +version: 0.1.62 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/revproxy/README.md b/helm/revproxy/README.md index 6fc8ada53..a6f204c94 100644 --- a/helm/revproxy/README.md +++ b/helm/revproxy/README.md @@ -1,6 +1,6 @@ # revproxy -![Version: 0.1.61](https://img.shields.io/badge/Version-0.1.61-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.62](https://img.shields.io/badge/Version-0.1.62-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 revproxy diff --git a/helm/revproxy/gen3.nginx.conf/fence-service.conf b/helm/revproxy/gen3.nginx.conf/fence-service.conf index d1abfd31a..86020bcb2 100644 --- a/helm/revproxy/gen3.nginx.conf/fence-service.conf +++ b/helm/revproxy/gen3.nginx.conf/fence-service.conf @@ -21,17 +21,17 @@ location /authn-proxy { } # Hits the fence API and stops the original request with a 403 if the provided -# token is blacklisted. Usage: `auth_request /block-blacklisted-token;` -location /block-blacklisted-token { +# token is blacklisted. Usage: `auth_request /block-denylisted-token;` +location /block-denylisted-token { internal; set $proxy_service "fence"; error_page 400 =403 @block_blacklisted_token; error_page 500 =403 @block_blacklisted_token; - # Previous versions of Fence that don't have the "/token/blacklisted" endpoint return 405. + # Previous versions of Fence that don't have the "/token/denylist" endpoint return 405. # Returning 403 forces the deployment of a recent Fence for endpoints that require this check. error_page 405 =403 @block_blacklisted_token; - proxy_pass http://fence-service${des_domain}/credentials/token/blacklisted; + proxy_pass http://fence-service${des_domain}/credentials/token/denylist; proxy_method POST; proxy_pass_request_body off; proxy_set_header Authorization "$access_token"; @@ -55,6 +55,12 @@ location @block_blacklisted_token { return 403 "unable to check if token is blacklisted"; } +location /user/credentials/token/denylist { + # Not meant to be called by users, + # but by the `auth_request /block-denylisted-token` location above. + deny all; +} + location /user/ { if ($csrf_check !~ ^ok-\S.+$) { return 403 "failed csrf check"; diff --git a/helm/revproxy/gen3.nginx.conf/gen3-workflow-service.conf b/helm/revproxy/gen3.nginx.conf/gen3-workflow-service.conf index 6c148250d..db296bff9 100644 --- a/helm/revproxy/gen3.nginx.conf/gen3-workflow-service.conf +++ b/helm/revproxy/gen3.nginx.conf/gen3-workflow-service.conf @@ -2,7 +2,7 @@ location /ga4gh/tes/v1/ { if ($csrf_check !~ ^ok-\S.+$) { return 403 "failed csrf check"; } - auth_request /block-blacklisted-token; + auth_request /block-denylisted-token; set $proxy_service "gen3-workflow"; set $upstream http://gen3-workflow-service.$namespace.svc.cluster.local; @@ -11,9 +11,9 @@ location /ga4gh/tes/v1/ { location /workflows/ { if ($csrf_check !~ ^ok-\S.+$) { - return 403 "failed csrf check"; + return 403 "failed csrf check";s } - auth_request /block-blacklisted-token; + auth_request /block-denylisted-token; set $proxy_service "gen3-workflow"; set $upstream http://gen3-workflow-service.$namespace.svc.cluster.local; From 91ba76c851321f733da119110edd8b956cc970a5 Mon Sep 17 00:00:00 2001 From: cmalson Date: Wed, 22 Apr 2026 10:33:04 -0700 Subject: [PATCH 022/196] feat(vectis): add jeg, workspace-proxy, vectis-overlays subcharts; revproxy additionalConfigs - Add helm/jeg chart (Jupyter Enterprise Gateway with RBAC for workspace pods) - Add helm/workspace-proxy chart (per-user WebSocket proxy + namespace + netpol) - Add helm/vectis-overlays chart (guppy-compat, siem-service, search-auth-proxy) - All templates use .Release.Namespace (env-agnostic) - Register three new deps in helm/gen3/Chart.yaml (disabled by default) - Add disabled stubs in helm/gen3/values.yaml - Add revproxy.additionalConfigs support to configMaps.yaml: - Keys matching static .conf files suppress the static version - Allows per-env route suppression or override without chart modification --- helm/gen3/Chart.yaml | 12 ++++ helm/gen3/values.yaml | 15 ++++ helm/jeg/Chart.yaml | 14 ++++ helm/jeg/templates/deployment.yaml | 59 ++++++++++++++++ helm/jeg/templates/rbac.yaml | 35 ++++++++++ helm/jeg/templates/service.yaml | 16 +++++ helm/jeg/templates/serviceaccount.yaml | 7 ++ helm/jeg/values.yaml | 34 ++++++++++ helm/revproxy/templates/configMaps.yaml | 10 ++- helm/revproxy/values.yaml | 6 ++ helm/vectis-overlays/Chart.yaml | 11 +++ .../templates/guppy-compat.yaml | 61 +++++++++++++++++ .../templates/search-auth-proxy-secret.yaml | 27 ++++++++ .../templates/search-auth-proxy.yaml | 64 +++++++++++++++++ .../templates/siem-service.yaml | 63 +++++++++++++++++ helm/vectis-overlays/values.yaml | 68 +++++++++++++++++++ helm/workspace-proxy/Chart.yaml | 14 ++++ .../workspace-proxy/templates/deployment.yaml | 61 +++++++++++++++++ helm/workspace-proxy/templates/namespace.yaml | 7 ++ helm/workspace-proxy/templates/netpol.yaml | 48 +++++++++++++ helm/workspace-proxy/templates/rbac.yaml | 29 ++++++++ helm/workspace-proxy/templates/service.yaml | 16 +++++ .../templates/serviceaccount.yaml | 7 ++ helm/workspace-proxy/values.yaml | 31 +++++++++ 24 files changed, 714 insertions(+), 1 deletion(-) create mode 100644 helm/jeg/Chart.yaml create mode 100644 helm/jeg/templates/deployment.yaml create mode 100644 helm/jeg/templates/rbac.yaml create mode 100644 helm/jeg/templates/service.yaml create mode 100644 helm/jeg/templates/serviceaccount.yaml create mode 100644 helm/jeg/values.yaml create mode 100644 helm/vectis-overlays/Chart.yaml create mode 100644 helm/vectis-overlays/templates/guppy-compat.yaml create mode 100644 helm/vectis-overlays/templates/search-auth-proxy-secret.yaml create mode 100644 helm/vectis-overlays/templates/search-auth-proxy.yaml create mode 100644 helm/vectis-overlays/templates/siem-service.yaml create mode 100644 helm/vectis-overlays/values.yaml create mode 100644 helm/workspace-proxy/Chart.yaml create mode 100644 helm/workspace-proxy/templates/deployment.yaml create mode 100644 helm/workspace-proxy/templates/namespace.yaml create mode 100644 helm/workspace-proxy/templates/netpol.yaml create mode 100644 helm/workspace-proxy/templates/rbac.yaml create mode 100644 helm/workspace-proxy/templates/service.yaml create mode 100644 helm/workspace-proxy/templates/serviceaccount.yaml create mode 100644 helm/workspace-proxy/values.yaml diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index c21a8f708..4d52acc9a 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -182,6 +182,18 @@ dependencies: version: "0.1.2" repository: "file://../neuvector" condition: neuvector.enabled + - name: jeg + version: 0.1.0 + repository: "file://../jeg" + condition: jeg.enabled + - name: workspace-proxy + version: 0.1.0 + repository: "file://../workspace-proxy" + condition: workspace-proxy.enabled + - name: vectis-overlays + version: 0.1.0 + repository: "file://../vectis-overlays" + condition: vectis-overlays.enabled # A chart can be either an 'application' or a 'library' chart. # diff --git a/helm/gen3/values.yaml b/helm/gen3/values.yaml index 731e9869f..ec99ba442 100644 --- a/helm/gen3/values.yaml +++ b/helm/gen3/values.yaml @@ -472,6 +472,21 @@ neuvector: # hostname/service name for our ElasitcSearch instance, used to allow egress from containers ES_HOST: gen3-elasticsearch-master +# -- (map) Jupyter Enterprise Gateway for vectis workspaces. +jeg: + # -- (bool) Whether to deploy the jeg subchart. + enabled: false + +# -- (map) workspace-proxy — per-user workspace HTTP/WebSocket router. +workspace-proxy: + # -- (bool) Whether to deploy the workspace-proxy subchart. + enabled: false + +# -- (map) vectis-overlays — guppy-compat, siem-service, search-auth-proxy. +vectis-overlays: + # -- (bool) Whether to deploy the vectis-overlays subchart. + enabled: false + # -- (map) Secret information for External Secrets and DB Secrets. secrets: # -- (str) AWS access key ID. Overrides global key. diff --git a/helm/jeg/Chart.yaml b/helm/jeg/Chart.yaml new file mode 100644 index 000000000..0c3eb6703 --- /dev/null +++ b/helm/jeg/Chart.yaml @@ -0,0 +1,14 @@ +apiVersion: v2 +name: jeg +description: > + Jupyter Enterprise Gateway for gen3 vectis workspaces. + Launches ephemeral kernel pods in the workspace namespace on behalf of + user Jupyter sessions proxied through workspace-proxy. +type: application +version: 0.1.0 +appVersion: "3.2.3" + +dependencies: + - name: common + version: 0.1.34 + repository: file://../common diff --git a/helm/jeg/templates/deployment.yaml b/helm/jeg/templates/deployment.yaml new file mode 100644 index 000000000..903c59920 --- /dev/null +++ b/helm/jeg/templates/deployment.yaml @@ -0,0 +1,59 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: jupyter-enterprise-gateway + namespace: {{ .Values.workspaceNamespace }} + labels: + app: enterprise-gateway +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + app: enterprise-gateway + template: + metadata: + labels: + app: enterprise-gateway + spec: + serviceAccountName: enterprise-gateway + automountServiceAccountToken: true + containers: + - name: enterprise-gateway + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + imagePullPolicy: {{ .Values.image.pullPolicy }} + ports: + - name: http + containerPort: 8888 + protocol: TCP + env: + {{- range $key, $val := .Values.env }} + - name: {{ $key }} + value: {{ $val | quote }} + {{- end }} + livenessProbe: + httpGet: + path: /api + port: http + initialDelaySeconds: 15 + periodSeconds: 30 + timeoutSeconds: 5 + readinessProbe: + httpGet: + path: /api + port: http + initialDelaySeconds: 10 + periodSeconds: 15 + timeoutSeconds: 5 + resources: + {{- toYaml .Values.resources | nindent 12 }} + securityContext: + allowPrivilegeEscalation: false + runAsNonRoot: true + runAsUser: 1000 + capabilities: + drop: + - ALL + securityContext: + runAsNonRoot: true + seccompProfile: + type: RuntimeDefault diff --git a/helm/jeg/templates/rbac.yaml b/helm/jeg/templates/rbac.yaml new file mode 100644 index 000000000..c620fcf80 --- /dev/null +++ b/helm/jeg/templates/rbac.yaml @@ -0,0 +1,35 @@ +# JEG needs permission to create/delete kernel pods and services in the +# workspace namespace. Scoped to a Role (not ClusterRole) for least-privilege. +apiVersion: rbac.authorization.k8s.io/v1 +kind: Role +metadata: + name: enterprise-gateway + namespace: {{ .Values.workspaceNamespace }} + labels: + app: enterprise-gateway +rules: + - apiGroups: [""] + resources: ["pods", "pods/log", "services", "configmaps", "secrets"] + verbs: ["get", "list", "watch", "create", "delete", "patch", "update"] + - apiGroups: [""] + resources: ["pods/exec"] + verbs: ["create"] + - apiGroups: ["batch"] + resources: ["jobs"] + verbs: ["get", "list", "watch", "create", "delete", "patch", "update"] +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: RoleBinding +metadata: + name: enterprise-gateway + namespace: {{ .Values.workspaceNamespace }} + labels: + app: enterprise-gateway +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: Role + name: enterprise-gateway +subjects: + - kind: ServiceAccount + name: enterprise-gateway + namespace: {{ .Values.workspaceNamespace }} diff --git a/helm/jeg/templates/service.yaml b/helm/jeg/templates/service.yaml new file mode 100644 index 000000000..1c0179636 --- /dev/null +++ b/helm/jeg/templates/service.yaml @@ -0,0 +1,16 @@ +apiVersion: v1 +kind: Service +metadata: + name: jupyter-enterprise-gateway + namespace: {{ .Values.workspaceNamespace }} + labels: + app: enterprise-gateway +spec: + type: ClusterIP + selector: + app: enterprise-gateway + ports: + - name: http + port: 8888 + targetPort: http + protocol: TCP diff --git a/helm/jeg/templates/serviceaccount.yaml b/helm/jeg/templates/serviceaccount.yaml new file mode 100644 index 000000000..793d0b228 --- /dev/null +++ b/helm/jeg/templates/serviceaccount.yaml @@ -0,0 +1,7 @@ +apiVersion: v1 +kind: ServiceAccount +metadata: + name: enterprise-gateway + namespace: {{ .Values.workspaceNamespace }} + labels: + app: enterprise-gateway diff --git a/helm/jeg/values.yaml b/helm/jeg/values.yaml new file mode 100644 index 000000000..7964f4f68 --- /dev/null +++ b/helm/jeg/values.yaml @@ -0,0 +1,34 @@ +# Jupyter Enterprise Gateway default values. +# Override via your environment's jeg-values.yaml + +# Namespace where JEG pod runs AND where it launches kernel pods. +# CRITICAL: must match hatchery user-namespace and workspace-proxy workspaceNamespace. +workspaceNamespace: jupyter-pods + +replicaCount: 1 + +image: + repository: elyra/enterprise-gateway + tag: "3.2.3" + pullPolicy: IfNotPresent + +env: + EG_NAMESPACE: jupyter-pods + EG_KERNEL_LAUNCH_TIMEOUT: "120" + EG_MAX_KERNELS_PER_USER: "2" + EG_CULL_IDLE_TIMEOUT: "14400" + EG_CULL_CONNECTED: "True" + EG_AUTH_TOKEN: "" + EG_DEFAULT_KERNEL_NAME: python3 + EG_LIST_KERNELS: "True" + EG_KERNEL_IMAGE_PULL_POLICY: IfNotPresent + EG_SHARED_NAMESPACE: "False" + EG_MIRROR_WORKING_DIRS: "False" + +resources: + requests: + cpu: "100m" + memory: "256Mi" + limits: + cpu: "500m" + memory: "512Mi" diff --git a/helm/revproxy/templates/configMaps.yaml b/helm/revproxy/templates/configMaps.yaml index 590b733f0..39757c7af 100644 --- a/helm/revproxy/templates/configMaps.yaml +++ b/helm/revproxy/templates/configMaps.yaml @@ -3,9 +3,13 @@ kind: ConfigMap metadata: name: revproxy-nginx-subconf data: +{{- $additionalConfigs := .Values.additionalConfigs | default dict }} {{- range $path, $bytes := .Files.Glob "gen3.nginx.conf/*.conf" }} - {{ ($a := split "/" $path)._1 }}: | +{{- $filename := ($a := split "/" $path)._1 }} +{{- if not (hasKey $additionalConfigs $filename) }} + {{ $filename }}: | {{- $bytes | toString | nindent 4 }} +{{- end }} {{- end}} {{- if eq "gen3ff" .Values.global.frontendRoot }} {{ "frontend-framework-service.conf" }}: | @@ -22,6 +26,10 @@ data: {{ "robots-txt.conf" }}: | {{- .Files.Get "gen3.nginx.conf/robots/robots-txt.conf" | nindent 4}} {{- end }} +{{- range $filename, $content := $additionalConfigs }} + {{ $filename }}: | + {{- $content | nindent 4 }} +{{- end }} {{- range .Values.extraServices }} {{ printf "%s-service.conf" .name }}: | location {{ .path }}/ { diff --git a/helm/revproxy/values.yaml b/helm/revproxy/values.yaml index 7d84f02c3..fd9b343a7 100644 --- a/helm/revproxy/values.yaml +++ b/helm/revproxy/values.yaml @@ -271,6 +271,12 @@ extraServices: # authzService: "protein-paint" # csrfCheck: true +# -- (map) Raw nginx location blocks to add or override entries in the revproxy-nginx-subconf ConfigMap. +# Keys are the conf filename (e.g. "guppy-service.conf"). A key matching a built-in static conf file +# will replace that file's content, allowing disabled services to be suppressed or routes +# redirected to alternative upstreams without modifying the chart. +additionalConfigs: {} + nginx: user: nginx resolver: kube-dns.kube-system.svc.cluster.local diff --git a/helm/vectis-overlays/Chart.yaml b/helm/vectis-overlays/Chart.yaml new file mode 100644 index 000000000..b7e1c2b98 --- /dev/null +++ b/helm/vectis-overlays/Chart.yaml @@ -0,0 +1,11 @@ +apiVersion: v2 +name: vectis-overlays +description: Vectis overlay API services (guppy-compat, siem, search-auth-proxy) +type: application +version: 0.1.0 +appVersion: "1.0" + +dependencies: + - name: common + version: 0.1.34 + repository: file://../common diff --git a/helm/vectis-overlays/templates/guppy-compat.yaml b/helm/vectis-overlays/templates/guppy-compat.yaml new file mode 100644 index 000000000..045e53789 --- /dev/null +++ b/helm/vectis-overlays/templates/guppy-compat.yaml @@ -0,0 +1,61 @@ +{{- if .Values.guppyCompat.enabled }} +apiVersion: apps/v1 +kind: Deployment +metadata: + name: guppy-compat-service + namespace: {{ .Release.Namespace }} + labels: + app: guppy-compat-service +spec: + replicas: {{ .Values.guppyCompat.replicaCount }} + selector: + matchLabels: + app: guppy-compat-service + template: + metadata: + labels: + app: guppy-compat-service + spec: + containers: + - name: guppy-compat-service + image: "{{ .Values.guppyCompat.image.repository }}:{{ .Values.guppyCompat.image.tag }}" + imagePullPolicy: {{ .Values.guppyCompat.image.pullPolicy }} + ports: + - containerPort: 8000 + env: + - name: SEARCH_BASE + value: "http://search-auth-proxy.{{ .Release.Namespace }}.svc.cluster.local:8000/search" + - name: GUPPY_COMPAT_MAX_LIMIT + value: {{ .Values.guppyCompat.env.GUPPY_COMPAT_MAX_LIMIT | quote }} + - name: ARBORIST_URL + value: "http://arborist-service.{{ .Release.Namespace }}.svc.cluster.local" + readinessProbe: + httpGet: + path: /health + port: 8000 + initialDelaySeconds: 5 + periodSeconds: 10 + livenessProbe: + httpGet: + path: /health + port: 8000 + initialDelaySeconds: 10 + periodSeconds: 20 + resources: + {{- toYaml .Values.guppyCompat.resources | nindent 12 }} +--- +apiVersion: v1 +kind: Service +metadata: + name: guppy-compat-service + namespace: {{ .Release.Namespace }} + labels: + app: guppy-compat-service +spec: + selector: + app: guppy-compat-service + ports: + - name: http + port: 8000 + targetPort: 8000 +{{- end }} diff --git a/helm/vectis-overlays/templates/search-auth-proxy-secret.yaml b/helm/vectis-overlays/templates/search-auth-proxy-secret.yaml new file mode 100644 index 000000000..c2b0f9918 --- /dev/null +++ b/helm/vectis-overlays/templates/search-auth-proxy-secret.yaml @@ -0,0 +1,27 @@ +{{- if .Values.searchAuthProxy.enabled }} +apiVersion: external-secrets.io/v1beta1 +kind: ExternalSecret +metadata: + name: vectis-search-auth-proxy + namespace: {{ .Release.Namespace }} +spec: + refreshInterval: 1h + secretStoreRef: + name: {{ .Release.Namespace }} + kind: ClusterSecretStore + target: + name: vectis-search-auth-proxy + creationPolicy: Owner + template: + data: + postgres_dsn: "postgresql://{{ `{{.username}}` }}:{{ `{{.password}}` }}@{{ .Values.rds.endpoint }}:{{ .Values.rds.port }}/{{ .Values.rds.database }}" + data: + - secretKey: username + remoteRef: + key: {{ .Values.rds.secretName }} + property: username + - secretKey: password + remoteRef: + key: {{ .Values.rds.secretName }} + property: password +{{- end }} diff --git a/helm/vectis-overlays/templates/search-auth-proxy.yaml b/helm/vectis-overlays/templates/search-auth-proxy.yaml new file mode 100644 index 000000000..4715ea3cf --- /dev/null +++ b/helm/vectis-overlays/templates/search-auth-proxy.yaml @@ -0,0 +1,64 @@ +{{- if .Values.searchAuthProxy.enabled }} +apiVersion: apps/v1 +kind: Deployment +metadata: + name: {{ .Values.searchAuthProxy.serviceName }} + namespace: {{ .Release.Namespace }} + labels: + app: {{ .Values.searchAuthProxy.serviceName }} +spec: + replicas: {{ .Values.searchAuthProxy.replicaCount }} + selector: + matchLabels: + app: {{ .Values.searchAuthProxy.serviceName }} + template: + metadata: + labels: + app: {{ .Values.searchAuthProxy.serviceName }} + spec: + containers: + - name: {{ .Values.searchAuthProxy.serviceName }} + image: "{{ .Values.searchAuthProxy.image.repository }}:{{ .Values.searchAuthProxy.image.tag }}" + imagePullPolicy: {{ .Values.searchAuthProxy.image.pullPolicy }} + ports: + - containerPort: 8000 + env: + - name: POSTGRES_DSN + valueFrom: + secretKeyRef: + name: {{ .Values.searchAuthProxy.postgresDsnSecretRef.name }} + key: {{ .Values.searchAuthProxy.postgresDsnSecretRef.key }} + - name: SEARCH_PROXY_DEFAULT_LIMIT + value: {{ .Values.searchAuthProxy.env.SEARCH_PROXY_DEFAULT_LIMIT | quote }} + - name: SEARCH_PROXY_MAX_LIMIT + value: {{ .Values.searchAuthProxy.env.SEARCH_PROXY_MAX_LIMIT | quote }} + readinessProbe: + httpGet: + path: /health + port: 8000 + initialDelaySeconds: 5 + periodSeconds: 10 + livenessProbe: + httpGet: + path: /health + port: 8000 + initialDelaySeconds: 10 + periodSeconds: 20 + resources: + {{- toYaml .Values.searchAuthProxy.resources | nindent 12 }} +--- +apiVersion: v1 +kind: Service +metadata: + name: {{ .Values.searchAuthProxy.serviceName }} + namespace: {{ .Release.Namespace }} + labels: + app: {{ .Values.searchAuthProxy.serviceName }} +spec: + selector: + app: {{ .Values.searchAuthProxy.serviceName }} + ports: + - name: http + port: 8000 + targetPort: 8000 +{{- end }} diff --git a/helm/vectis-overlays/templates/siem-service.yaml b/helm/vectis-overlays/templates/siem-service.yaml new file mode 100644 index 000000000..56f302fb1 --- /dev/null +++ b/helm/vectis-overlays/templates/siem-service.yaml @@ -0,0 +1,63 @@ +{{- if .Values.siemService.enabled }} +apiVersion: apps/v1 +kind: Deployment +metadata: + name: siem-service + namespace: {{ .Release.Namespace }} + labels: + app: siem-service +spec: + replicas: {{ .Values.siemService.replicaCount }} + selector: + matchLabels: + app: siem-service + template: + metadata: + labels: + app: siem-service + spec: + containers: + - name: siem-service + image: "{{ .Values.siemService.image.repository }}:{{ .Values.siemService.image.tag }}" + imagePullPolicy: {{ .Values.siemService.image.pullPolicy }} + ports: + - containerPort: 8000 + env: + - name: SEARCH_BASE + value: "http://search-auth-proxy.{{ .Release.Namespace }}.svc.cluster.local:8000/search" + - name: ARBORIST_URL + value: "http://arborist-service.{{ .Release.Namespace }}.svc.cluster.local" + - name: SIEM_DEFAULT_LIMIT + value: {{ .Values.siemService.env.SIEM_DEFAULT_LIMIT | quote }} + - name: SIEM_MAX_LIMIT + value: {{ .Values.siemService.env.SIEM_MAX_LIMIT | quote }} + readinessProbe: + httpGet: + path: /siem/health + port: 8000 + initialDelaySeconds: 5 + periodSeconds: 10 + livenessProbe: + httpGet: + path: /siem/health + port: 8000 + initialDelaySeconds: 10 + periodSeconds: 20 + resources: + {{- toYaml .Values.siemService.resources | nindent 12 }} +--- +apiVersion: v1 +kind: Service +metadata: + name: siem-service + namespace: {{ .Release.Namespace }} + labels: + app: siem-service +spec: + selector: + app: siem-service + ports: + - name: http + port: 8000 + targetPort: 8000 +{{- end }} diff --git a/helm/vectis-overlays/values.yaml b/helm/vectis-overlays/values.yaml new file mode 100644 index 000000000..8d012b516 --- /dev/null +++ b/helm/vectis-overlays/values.yaml @@ -0,0 +1,68 @@ +# vectis-overlays default values. +# All service-internal URLs use .Release.Namespace so the chart is env-agnostic. +# Override image tags per-environment in gitops values. + +guppyCompat: + enabled: true + replicaCount: 1 + image: + repository: quay.io/cdis/gen3-vectis + tag: guppy-compat-service + pullPolicy: Always + resources: + requests: + cpu: "50m" + memory: "128Mi" + limits: + cpu: "500m" + memory: "512Mi" + env: + GUPPY_COMPAT_MAX_LIMIT: "5000" + +siemService: + enabled: true + replicaCount: 1 + image: + repository: quay.io/cdis/gen3-vectis + tag: siem-service + pullPolicy: Always + resources: + requests: + cpu: "50m" + memory: "128Mi" + limits: + cpu: "500m" + memory: "512Mi" + env: + SIEM_DEFAULT_LIMIT: "250" + SIEM_MAX_LIMIT: "2000" + +searchAuthProxy: + enabled: true + replicaCount: 1 + serviceName: search-auth-proxy + image: + repository: quay.io/cdis/gen3-vectis + tag: search-auth-proxy-service + pullPolicy: Always + resources: + requests: + cpu: "50m" + memory: "128Mi" + limits: + cpu: "500m" + memory: "512Mi" + env: + SEARCH_PROXY_DEFAULT_LIMIT: "50" + SEARCH_PROXY_MAX_LIMIT: "1000" + postgresDsnSecretRef: + name: vectis-search-auth-proxy + key: postgres_dsn + +# CDK RDS secret in Secrets Manager — used to build the postgres DSN ExternalSecret. +# Set per-environment in gitops values. +rds: + secretName: "" + endpoint: "" + port: "5432" + database: postgres diff --git a/helm/workspace-proxy/Chart.yaml b/helm/workspace-proxy/Chart.yaml new file mode 100644 index 000000000..2736f76b2 --- /dev/null +++ b/helm/workspace-proxy/Chart.yaml @@ -0,0 +1,14 @@ +apiVersion: v2 +name: workspace-proxy +description: > + Per-user workspace HTTP/WebSocket router for gen3 vectis. + Replaces Emissary/Ambassador. Reads Service annotations written by Hatchery + to resolve each user's workspace upstream, then proxies traffic from revproxy. +type: application +version: 0.1.0 +appVersion: "1.0" + +dependencies: + - name: common + version: 0.1.34 + repository: file://../common diff --git a/helm/workspace-proxy/templates/deployment.yaml b/helm/workspace-proxy/templates/deployment.yaml new file mode 100644 index 000000000..6df9e1dbe --- /dev/null +++ b/helm/workspace-proxy/templates/deployment.yaml @@ -0,0 +1,61 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: workspace-proxy + namespace: {{ .Values.deploymentNamespace }} + labels: + app: workspace-proxy +spec: + replicas: {{ .Values.replicaCount }} + selector: + matchLabels: + app: workspace-proxy + template: + metadata: + labels: + app: workspace-proxy + spec: + serviceAccountName: workspace-proxy + automountServiceAccountToken: true + containers: + - name: workspace-proxy + image: "{{ .Values.image.repository }}:{{ .Values.image.tag }}" + imagePullPolicy: {{ .Values.image.pullPolicy }} + args: + - --listen={{ .Values.listenAddr }} + - --workspace-namespace={{ .Values.workspaceNamespace }} + env: + - name: JEG_GATEWAY_URL + value: "http://jupyter-enterprise-gateway.{{ .Values.workspaceNamespace }}.svc.cluster.local:8888" + - name: WORKSPACE_NAMESPACE + value: "{{ .Values.workspaceNamespace }}" + ports: + - name: http + containerPort: 8080 + protocol: TCP + livenessProbe: + httpGet: + path: /healthz + port: http + initialDelaySeconds: 5 + periodSeconds: 15 + readinessProbe: + httpGet: + path: /healthz + port: http + initialDelaySeconds: 3 + periodSeconds: 10 + resources: + {{- toYaml .Values.resources | nindent 12 }} + securityContext: + allowPrivilegeEscalation: false + readOnlyRootFilesystem: true + runAsNonRoot: true + runAsUser: 1000 + capabilities: + drop: + - ALL + securityContext: + runAsNonRoot: true + seccompProfile: + type: RuntimeDefault diff --git a/helm/workspace-proxy/templates/namespace.yaml b/helm/workspace-proxy/templates/namespace.yaml new file mode 100644 index 000000000..6f63729db --- /dev/null +++ b/helm/workspace-proxy/templates/namespace.yaml @@ -0,0 +1,7 @@ +apiVersion: v1 +kind: Namespace +metadata: + name: {{ .Values.workspaceNamespace }} + labels: + app: workspace + kubernetes.io/metadata.name: {{ .Values.workspaceNamespace }} diff --git a/helm/workspace-proxy/templates/netpol.yaml b/helm/workspace-proxy/templates/netpol.yaml new file mode 100644 index 000000000..f30ebe066 --- /dev/null +++ b/helm/workspace-proxy/templates/netpol.yaml @@ -0,0 +1,48 @@ +{{- if .Values.networkPolicy.enabled }} +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: workspace-proxy + namespace: {{ .Values.deploymentNamespace }} + labels: + app: workspace-proxy +spec: + podSelector: + matchLabels: + app: workspace-proxy + policyTypes: + - Ingress + - Egress + + ingress: + - from: + - namespaceSelector: + matchLabels: + kubernetes.io/metadata.name: {{ .Values.deploymentNamespace }} + podSelector: + matchLabels: + app: revproxy + ports: + - protocol: TCP + port: 8080 + + egress: + - to: + - namespaceSelector: + matchLabels: + kubernetes.io/metadata.name: kube-system + ports: + - protocol: UDP + port: 53 + - protocol: TCP + port: 53 + - to: + - namespaceSelector: + matchLabels: + kubernetes.io/metadata.name: {{ .Values.workspaceNamespace }} + ports: + - protocol: TCP + port: 80 + - protocol: TCP + port: 8888 +{{- end }} diff --git a/helm/workspace-proxy/templates/rbac.yaml b/helm/workspace-proxy/templates/rbac.yaml new file mode 100644 index 000000000..c0826c679 --- /dev/null +++ b/helm/workspace-proxy/templates/rbac.yaml @@ -0,0 +1,29 @@ +# Role in the workspace namespace — workspace-proxy reads Services written by Hatchery +# (one per user session) to resolve proxy upstreams. +apiVersion: rbac.authorization.k8s.io/v1 +kind: Role +metadata: + name: workspace-proxy + namespace: {{ .Values.workspaceNamespace }} + labels: + app: workspace-proxy +rules: + - apiGroups: [""] + resources: ["services"] + verbs: ["get", "list", "watch"] +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: RoleBinding +metadata: + name: workspace-proxy + namespace: {{ .Values.workspaceNamespace }} + labels: + app: workspace-proxy +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: Role + name: workspace-proxy +subjects: + - kind: ServiceAccount + name: workspace-proxy + namespace: {{ .Values.deploymentNamespace }} diff --git a/helm/workspace-proxy/templates/service.yaml b/helm/workspace-proxy/templates/service.yaml new file mode 100644 index 000000000..2f2b29ada --- /dev/null +++ b/helm/workspace-proxy/templates/service.yaml @@ -0,0 +1,16 @@ +apiVersion: v1 +kind: Service +metadata: + name: workspace-proxy-service + namespace: {{ .Values.deploymentNamespace }} + labels: + app: workspace-proxy +spec: + type: ClusterIP + selector: + app: workspace-proxy + ports: + - name: http + port: 8080 + targetPort: http + protocol: TCP diff --git a/helm/workspace-proxy/templates/serviceaccount.yaml b/helm/workspace-proxy/templates/serviceaccount.yaml new file mode 100644 index 000000000..d9d0ff5b7 --- /dev/null +++ b/helm/workspace-proxy/templates/serviceaccount.yaml @@ -0,0 +1,7 @@ +apiVersion: v1 +kind: ServiceAccount +metadata: + name: workspace-proxy + namespace: {{ .Values.deploymentNamespace }} + labels: + app: workspace-proxy diff --git a/helm/workspace-proxy/values.yaml b/helm/workspace-proxy/values.yaml new file mode 100644 index 000000000..ffba7c0f8 --- /dev/null +++ b/helm/workspace-proxy/values.yaml @@ -0,0 +1,31 @@ +# workspace-proxy default values. +# Override via your environment's workspace-proxy-values.yaml + +# Namespace where the workspace-proxy pod runs (same as gen3 helm release). +# Must be set per-environment in gitops values. +deploymentNamespace: "" + +# Namespace where Hatchery creates user workspace pods and services. +# CRITICAL: must match hatchery user-namespace and jeg workspaceNamespace exactly. +workspaceNamespace: "" + +replicaCount: 2 + +image: + repository: quay.io/cdis/gen3-vectis + tag: latest + pullPolicy: Always + +listenAddr: ":8080" + +resources: + requests: + cpu: "50m" + memory: "64Mi" + limits: + cpu: "500m" + memory: "256Mi" + +# NetworkPolicy: restrict ingress to revproxy only. +networkPolicy: + enabled: true From 605bad48e066307a82e61ba2e27e3ebe6d4de6c5 Mon Sep 17 00:00:00 2001 From: cmalson Date: Wed, 22 Apr 2026 11:38:48 -0700 Subject: [PATCH 023/196] updating tags --- helm/jeg/values.yaml | 6 +++--- helm/vectis-overlays/values.yaml | 6 +++--- helm/workspace-proxy/values.yaml | 2 +- 3 files changed, 7 insertions(+), 7 deletions(-) diff --git a/helm/jeg/values.yaml b/helm/jeg/values.yaml index 7964f4f68..3576e42de 100644 --- a/helm/jeg/values.yaml +++ b/helm/jeg/values.yaml @@ -8,9 +8,9 @@ workspaceNamespace: jupyter-pods replicaCount: 1 image: - repository: elyra/enterprise-gateway - tag: "3.2.3" - pullPolicy: IfNotPresent + repository: quay.io/cdis/gen3-vectis + tag: qa-jeg + pullPolicy: Always env: EG_NAMESPACE: jupyter-pods diff --git a/helm/vectis-overlays/values.yaml b/helm/vectis-overlays/values.yaml index 8d012b516..fc3b57537 100644 --- a/helm/vectis-overlays/values.yaml +++ b/helm/vectis-overlays/values.yaml @@ -7,7 +7,7 @@ guppyCompat: replicaCount: 1 image: repository: quay.io/cdis/gen3-vectis - tag: guppy-compat-service + tag: guppy-compat-v1 pullPolicy: Always resources: requests: @@ -24,7 +24,7 @@ siemService: replicaCount: 1 image: repository: quay.io/cdis/gen3-vectis - tag: siem-service + tag: siem-service-v1 pullPolicy: Always resources: requests: @@ -43,7 +43,7 @@ searchAuthProxy: serviceName: search-auth-proxy image: repository: quay.io/cdis/gen3-vectis - tag: search-auth-proxy-service + tag: search-auth-proxy-v1 pullPolicy: Always resources: requests: diff --git a/helm/workspace-proxy/values.yaml b/helm/workspace-proxy/values.yaml index ffba7c0f8..bdbeb4b37 100644 --- a/helm/workspace-proxy/values.yaml +++ b/helm/workspace-proxy/values.yaml @@ -13,7 +13,7 @@ replicaCount: 2 image: repository: quay.io/cdis/gen3-vectis - tag: latest + tag: qa-goproxy pullPolicy: Always listenAddr: ":8080" From 39d76e6e9922f07bedac49aaa51f18e32aea238c Mon Sep 17 00:00:00 2001 From: cmalson Date: Wed, 22 Apr 2026 11:50:54 -0700 Subject: [PATCH 024/196] fixing race condition --- helm/vectis-overlays/templates/search-auth-proxy-secret.yaml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/helm/vectis-overlays/templates/search-auth-proxy-secret.yaml b/helm/vectis-overlays/templates/search-auth-proxy-secret.yaml index c2b0f9918..d7552a13e 100644 --- a/helm/vectis-overlays/templates/search-auth-proxy-secret.yaml +++ b/helm/vectis-overlays/templates/search-auth-proxy-secret.yaml @@ -4,6 +4,8 @@ kind: ExternalSecret metadata: name: vectis-search-auth-proxy namespace: {{ .Release.Namespace }} + annotations: + argocd.argoproj.io/sync-wave: "-1" spec: refreshInterval: 1h secretStoreRef: From ded0d134d20bcbe8881fc03fd6b793924ebecf87 Mon Sep 17 00:00:00 2001 From: "J. Q." <55899496+jawadqur@users.noreply.github.com> Date: Wed, 22 Apr 2026 15:32:12 -0500 Subject: [PATCH 025/196] Update search-auth-proxy-secret.yaml for secretStoreRef Refactor secretStoreRef to use conditional logic for name and kind based on externalSecrets configuration. --- .../templates/search-auth-proxy-secret.yaml | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) diff --git a/helm/vectis-overlays/templates/search-auth-proxy-secret.yaml b/helm/vectis-overlays/templates/search-auth-proxy-secret.yaml index d7552a13e..fa92218b9 100644 --- a/helm/vectis-overlays/templates/search-auth-proxy-secret.yaml +++ b/helm/vectis-overlays/templates/search-auth-proxy-secret.yaml @@ -9,8 +9,15 @@ metadata: spec: refreshInterval: 1h secretStoreRef: - name: {{ .Release.Namespace }} - kind: ClusterSecretStore + # name: {{ .Release.Namespace }} + # kind: ClusterSecretStore + {{- if ne .Values.global.externalSecrets.clusterSecretStoreRef "" }} + name: {{ .Values.global.externalSecrets.clusterSecretStoreRef }} + kind: ClusterSecretStore + {{- else }} + name: {{include "common.SecretStore" .}} + kind: SecretStore + {{- end }} target: name: vectis-search-auth-proxy creationPolicy: Owner From 86944a0449737b4883e5a81227a60925c571fbd1 Mon Sep 17 00:00:00 2001 From: cmalson Date: Thu, 23 Apr 2026 10:07:58 -0700 Subject: [PATCH 026/196] fix: correct image tags; add vectis DB migration Job; ExternalSecret sync-wave --- .../templates/migration-configmap.yaml | 235 ++++++++++++++++++ .../templates/migration-job.yaml | 67 +++++ .../templates/migration-secret.yaml | 31 +++ helm/vectis-overlays/values.yaml | 5 + 4 files changed, 338 insertions(+) create mode 100644 helm/vectis-overlays/templates/migration-configmap.yaml create mode 100644 helm/vectis-overlays/templates/migration-job.yaml create mode 100644 helm/vectis-overlays/templates/migration-secret.yaml diff --git a/helm/vectis-overlays/templates/migration-configmap.yaml b/helm/vectis-overlays/templates/migration-configmap.yaml new file mode 100644 index 000000000..8e071c95e --- /dev/null +++ b/helm/vectis-overlays/templates/migration-configmap.yaml @@ -0,0 +1,235 @@ +{{- if .Values.migrations.enabled }} +apiVersion: v1 +kind: ConfigMap +metadata: + name: vectis-db-migrations + namespace: {{ .Release.Namespace }} + labels: + app: vectis-db-migrations +data: + 000_create_schema.sql: | + CREATE SCHEMA IF NOT EXISTS vectis; + CREATE TABLE IF NOT EXISTS "vectis"."program" ( + "id" UUID NOT NULL, + "submitter_id" TEXT NOT NULL, + "name" TEXT NOT NULL, + PRIMARY KEY ("id") , + UNIQUE ("submitter_id") + ); + CREATE TABLE IF NOT EXISTS "vectis"."project" ( + "id" UUID NOT NULL, + "submitter_id" TEXT NOT NULL, + "code" TEXT NOT NULL, + "name" TEXT, + "cloud_account_id" TEXT, + "cloud_provider" TEXT, + "program_id" UUID NOT NULL, + PRIMARY KEY ("id") , + UNIQUE ("submitter_id") + ); + CREATE TABLE IF NOT EXISTS "vectis"."subject" ( + "id" UUID NOT NULL, + "submitter_id" TEXT NOT NULL, + "asset_type" TEXT, + "cloud_account_id" TEXT, + "cloud_provider" TEXT, + "hostname" TEXT, + "environment" TEXT, + "project_id" UUID, + PRIMARY KEY ("id") , + UNIQUE ("submitter_id") + ); + CREATE TABLE IF NOT EXISTS "vectis"."security_event" ( + "id" UUID NOT NULL, + "submitter_id" TEXT NOT NULL, + "timestamp" TEXT NOT NULL, + "action" TEXT NOT NULL, + "severity" TEXT, + "finding_type" TEXT, + "src_ip" TEXT, + "user_id" TEXT, + "http_request" TEXT, + "http_verb" TEXT, + "http_status_code" BIGINT, + "http_user_agent" TEXT, + "user_country_name" TEXT, + "resource_id" TEXT, + "rule_id" TEXT, + "cloud_account_id" TEXT, + "event_source" TEXT, + "subject_id" UUID, + PRIMARY KEY ("id") , + UNIQUE ("submitter_id") + ); + CREATE TABLE IF NOT EXISTS "vectis"."audit_event" ( + "id" UUID NOT NULL, + "submitter_id" TEXT NOT NULL, + "timestamp" TEXT NOT NULL, + "user_id" TEXT, + "src_ip" TEXT, + "http_user_agent" TEXT, + "action_name" TEXT, + "resource" TEXT, + "result" TEXT, + "is_read_only" BOOLEAN, + "cloud_region" TEXT, + "event_type" TEXT, + "request_parameters" TEXT, + "response_elements" TEXT, + "cloud_account_id" TEXT, + "event_source" TEXT, + "subject_id" UUID, + PRIMARY KEY ("id") , + UNIQUE ("submitter_id") + ); + CREATE TABLE IF NOT EXISTS "vectis"."telemetry_event" ( + "id" UUID NOT NULL, + "submitter_id" TEXT NOT NULL, + "timestamp" TEXT NOT NULL, + "src_ip" TEXT, + "dest_ip" TEXT, + "src_port" BIGINT, + "dest_port" BIGINT, + "protocol" TEXT, + "bytes_in" BIGINT, + "bytes_out" BIGINT, + "http_request" TEXT, + "http_status_code" BIGINT, + "http_user_agent" TEXT, + "packets" BIGINT, + "duration" DOUBLE PRECISION, + "disposition" TEXT, + "log_level" TEXT, + "cloud_account_id" TEXT, + "event_source" TEXT, + "subject_id" UUID, + PRIMARY KEY ("id") , + UNIQUE ("submitter_id") + ); + CREATE TABLE IF NOT EXISTS "vectis"."threat_indicator" ( + "id" UUID NOT NULL, + "submitter_id" TEXT NOT NULL, + "name" TEXT, + "description" TEXT, + "indicator_types" JSONB, + "pattern" TEXT NOT NULL, + "pattern_type" TEXT NOT NULL, + "valid_from" TEXT NOT NULL, + "valid_until" TEXT, + PRIMARY KEY ("id") , + UNIQUE ("submitter_id") + ); + CREATE TABLE IF NOT EXISTS "vectis"."security_incident" ( + "id" UUID NOT NULL, + "submitter_id" TEXT NOT NULL, + "incident_name" TEXT NOT NULL, + "description" TEXT, + "severity" TEXT, + PRIMARY KEY ("id") , + UNIQUE ("submitter_id") + ); + CREATE TABLE IF NOT EXISTS "vectis"."security_incident_security_event" ( + "security_incident_id" UUID NOT NULL, + "security_event_id" UUID NOT NULL, + PRIMARY KEY ("security_incident_id", "security_event_id") + ); + CREATE TABLE IF NOT EXISTS "vectis"."security_incident_audit_event" ( + "security_incident_id" UUID NOT NULL, + "audit_event_id" UUID NOT NULL, + PRIMARY KEY ("security_incident_id", "audit_event_id") + ); + CREATE TABLE IF NOT EXISTS "vectis"."security_incident_telemetry_event" ( + "security_incident_id" UUID NOT NULL, + "telemetry_event_id" UUID NOT NULL, + PRIMARY KEY ("security_incident_id", "telemetry_event_id") + ); + CREATE TABLE IF NOT EXISTS "vectis"."security_incident_threat_indicator" ( + "security_incident_id" UUID NOT NULL, + "threat_indicator_id" UUID NOT NULL, + PRIMARY KEY ("security_incident_id", "threat_indicator_id") + ); + + 001_rls_and_masked_views.sql: | + -- Migration 001: Row-Level Security + Masked Views for Vectis Search + BEGIN; + ALTER TABLE vectis.security_event + ADD COLUMN IF NOT EXISTS auth_resource_path TEXT + DEFAULT '/programs/vectis/projects/siem'; + ALTER TABLE vectis.audit_event + ADD COLUMN IF NOT EXISTS auth_resource_path TEXT + DEFAULT '/programs/vectis/projects/siem'; + ALTER TABLE vectis.threat_indicator + ADD COLUMN IF NOT EXISTS auth_resource_path TEXT + DEFAULT '/programs/vectis/projects/siem'; + ALTER TABLE vectis.subject + ADD COLUMN IF NOT EXISTS auth_resource_path TEXT + DEFAULT '/programs/vectis/projects/siem'; + UPDATE vectis.security_event SET auth_resource_path = '/programs/vectis/projects/siem' WHERE auth_resource_path IS NULL; + UPDATE vectis.audit_event SET auth_resource_path = '/programs/vectis/projects/siem' WHERE auth_resource_path IS NULL; + UPDATE vectis.threat_indicator SET auth_resource_path = '/programs/vectis/projects/siem' WHERE auth_resource_path IS NULL; + UPDATE vectis.subject SET auth_resource_path = '/programs/vectis/projects/siem' WHERE auth_resource_path IS NULL; + ALTER TABLE vectis.security_event ENABLE ROW LEVEL SECURITY; + ALTER TABLE vectis.audit_event ENABLE ROW LEVEL SECURITY; + ALTER TABLE vectis.threat_indicator ENABLE ROW LEVEL SECURITY; + ALTER TABLE vectis.subject ENABLE ROW LEVEL SECURITY; + DO $$ BEGIN + IF NOT EXISTS (SELECT 1 FROM pg_policies WHERE tablename='security_event' AND policyname='siem_row_access') THEN + CREATE POLICY siem_row_access ON vectis.security_event FOR SELECT + USING (auth_resource_path = ANY(string_to_array(current_setting('app.allowed_paths', true), ','))); + END IF; + IF NOT EXISTS (SELECT 1 FROM pg_policies WHERE tablename='audit_event' AND policyname='siem_row_access') THEN + CREATE POLICY siem_row_access ON vectis.audit_event FOR SELECT + USING (auth_resource_path = ANY(string_to_array(current_setting('app.allowed_paths', true), ','))); + END IF; + IF NOT EXISTS (SELECT 1 FROM pg_policies WHERE tablename='threat_indicator' AND policyname='siem_row_access') THEN + CREATE POLICY siem_row_access ON vectis.threat_indicator FOR SELECT + USING (auth_resource_path = ANY(string_to_array(current_setting('app.allowed_paths', true), ','))); + END IF; + IF NOT EXISTS (SELECT 1 FROM pg_policies WHERE tablename='subject' AND policyname='siem_row_access') THEN + CREATE POLICY siem_row_access ON vectis.subject FOR SELECT + USING (auth_resource_path = ANY(string_to_array(current_setting('app.allowed_paths', true), ','))); + END IF; + END $$; + DO $$ BEGIN + IF NOT EXISTS (SELECT 1 FROM pg_roles WHERE rolname = 'vectis_search_user') THEN + CREATE ROLE vectis_search_user WITH LOGIN PASSWORD 'vectis_search_dev'; + END IF; + END $$; + GRANT USAGE ON SCHEMA vectis TO vectis_search_user; + GRANT SELECT ON ALL TABLES IN SCHEMA vectis TO vectis_search_user; + ALTER TABLE vectis.security_event FORCE ROW LEVEL SECURITY; + ALTER TABLE vectis.audit_event FORCE ROW LEVEL SECURITY; + ALTER TABLE vectis.threat_indicator FORCE ROW LEVEL SECURITY; + ALTER TABLE vectis.subject FORCE ROW LEVEL SECURITY; + CREATE SCHEMA IF NOT EXISTS vectis_search; + GRANT USAGE ON SCHEMA vectis_search TO vectis_search_user; + CREATE OR REPLACE VIEW vectis_search.security_event WITH (security_invoker = true) AS + SELECT id, submitter_id, "timestamp", action, severity, finding_type, src_ip, + CASE WHEN current_setting('app.can_unmask', true) = 'true' THEN user_id ELSE '***' END AS user_id, + http_request, http_verb, http_status_code, http_user_agent, user_country_name, + resource_id, rule_id, cloud_account_id, event_source, subject_id + FROM vectis.security_event; + CREATE OR REPLACE VIEW vectis_search.audit_event WITH (security_invoker = true) AS + SELECT id, submitter_id, "timestamp", action_name, event_source, result, cloud_region, + cloud_account_id, src_ip, + CASE WHEN current_setting('app.can_unmask', true) = 'true' THEN user_id ELSE '***' END AS user_id, + resource, event_type, http_user_agent + FROM vectis.audit_event; + CREATE OR REPLACE VIEW vectis_search.threat_indicator WITH (security_invoker = true) AS + SELECT id, submitter_id, name, description, pattern, pattern_type, valid_from + FROM vectis.threat_indicator; + CREATE OR REPLACE VIEW vectis_search.subject WITH (security_invoker = true) AS + SELECT id, submitter_id, asset_type, cloud_account_id, cloud_provider, environment + FROM vectis.subject; + GRANT SELECT ON ALL TABLES IN SCHEMA vectis_search TO vectis_search_user; + COMMIT; + + 002_drs_auth_resource_path.sql: | + -- Migration 002: Add auth_resource_path to drs_object (idempotent). + DO $$ BEGIN + IF EXISTS (SELECT 1 FROM information_schema.tables + WHERE table_schema = 'drs' AND table_name = 'drs_object') THEN + ALTER TABLE drs.drs_object ADD COLUMN IF NOT EXISTS auth_resource_path TEXT; + END IF; + END $$; +{{- end }} diff --git a/helm/vectis-overlays/templates/migration-job.yaml b/helm/vectis-overlays/templates/migration-job.yaml new file mode 100644 index 000000000..19fbdf06a --- /dev/null +++ b/helm/vectis-overlays/templates/migration-job.yaml @@ -0,0 +1,67 @@ +{{- if .Values.migrations.enabled }} +apiVersion: batch/v1 +kind: Job +metadata: + name: vectis-db-migration + namespace: {{ .Release.Namespace }} + labels: + app: vectis-db-migration +spec: + backoffLimit: 3 + ttlSecondsAfterFinished: 3600 + template: + metadata: + labels: + app: gen3job + spec: + restartPolicy: OnFailure + automountServiceAccountToken: false + volumes: + - name: sql + configMap: + name: vectis-db-migrations + containers: + - name: migrate + image: postgres:15-alpine + imagePullPolicy: IfNotPresent + volumeMounts: + - name: sql + mountPath: /sql + env: + - name: PGHOST + valueFrom: + secretKeyRef: + name: vectis-db-migration-creds + key: host + optional: false + - name: PGUSER + valueFrom: + secretKeyRef: + name: vectis-db-migration-creds + key: username + optional: false + - name: PGPASSWORD + valueFrom: + secretKeyRef: + name: vectis-db-migration-creds + key: password + optional: false + - name: PGDATABASE + value: {{ .Values.rds.database }} + - name: PGPORT + value: {{ .Values.rds.port | quote }} + - name: PGSSLMODE + value: require + command: ["/bin/sh"] + args: + - "-ec" + - | + echo "==> Running vectis DB migrations against $PGHOST" + echo "==> [000] Base schema (idempotent — CREATE IF NOT EXISTS)..." + psql -f /sql/000_create_schema.sql + echo "==> [001] RLS + masked views..." + psql -f /sql/001_rls_and_masked_views.sql + echo "==> [002] DRS auth_resource_path column..." + psql -f /sql/002_drs_auth_resource_path.sql + echo "==> All migrations complete." +{{- end }} diff --git a/helm/vectis-overlays/templates/migration-secret.yaml b/helm/vectis-overlays/templates/migration-secret.yaml new file mode 100644 index 000000000..ff98ff6e5 --- /dev/null +++ b/helm/vectis-overlays/templates/migration-secret.yaml @@ -0,0 +1,31 @@ +{{- if .Values.migrations.enabled }} +apiVersion: external-secrets.io/v1beta1 +kind: ExternalSecret +metadata: + name: vectis-db-migration-creds + namespace: {{ .Release.Namespace }} + annotations: + argocd.argoproj.io/sync-wave: "-1" +spec: + refreshInterval: 1h + secretStoreRef: + name: {{ .Release.Namespace }} + kind: ClusterSecretStore + target: + name: vectis-db-migration-creds + creationPolicy: Owner + template: + data: + host: "{{ .Values.rds.endpoint }}" + username: "{{ `{{.username}}` }}" + password: "{{ `{{.password}}` }}" + data: + - secretKey: username + remoteRef: + key: {{ .Values.rds.secretName }} + property: username + - secretKey: password + remoteRef: + key: {{ .Values.rds.secretName }} + property: password +{{- end }} diff --git a/helm/vectis-overlays/values.yaml b/helm/vectis-overlays/values.yaml index fc3b57537..b1ab9c785 100644 --- a/helm/vectis-overlays/values.yaml +++ b/helm/vectis-overlays/values.yaml @@ -66,3 +66,8 @@ rds: endpoint: "" port: "5432" database: postgres + +# Database migrations — one-time Job to bootstrap the vectis schema and RLS views. +# Set migrations.enabled: true in gitops values to trigger the Job, then flip back to false. +migrations: + enabled: false From 01ab40b4df3cae697d5c2759944cea7d64b89125 Mon Sep 17 00:00:00 2001 From: cmalson Date: Thu, 23 Apr 2026 10:38:38 -0700 Subject: [PATCH 027/196] bug fixes --- helm/workspace-proxy/templates/deployment.yaml | 2 ++ helm/workspace-proxy/values.yaml | 4 ++++ 2 files changed, 6 insertions(+) diff --git a/helm/workspace-proxy/templates/deployment.yaml b/helm/workspace-proxy/templates/deployment.yaml index 6df9e1dbe..40bdaf1db 100644 --- a/helm/workspace-proxy/templates/deployment.yaml +++ b/helm/workspace-proxy/templates/deployment.yaml @@ -29,6 +29,8 @@ spec: value: "http://jupyter-enterprise-gateway.{{ .Values.workspaceNamespace }}.svc.cluster.local:8888" - name: WORKSPACE_NAMESPACE value: "{{ .Values.workspaceNamespace }}" + - name: JEG_KERNEL_SPEC_POLICY + value: {{ .Values.jegKernelSpecPolicy | quote }} ports: - name: http containerPort: 8080 diff --git a/helm/workspace-proxy/values.yaml b/helm/workspace-proxy/values.yaml index bdbeb4b37..8031b40bc 100644 --- a/helm/workspace-proxy/values.yaml +++ b/helm/workspace-proxy/values.yaml @@ -18,6 +18,10 @@ image: listenAddr: ":8080" +# Optional JSON policy controlling which JEG kernelspecs are visible/launchable. +# Example: {"allowedSpecs":["python3"],"costPerHour":{"python3":0.0}} +jegKernelSpecPolicy: "" + resources: requests: cpu: "50m" From f312aa0643873c8f1f5d32896a1a8edd125f0aec Mon Sep 17 00:00:00 2001 From: cmalson Date: Thu, 23 Apr 2026 12:21:05 -0700 Subject: [PATCH 028/196] jeg fix --- helm/workspace-proxy/templates/namespace.yaml | 9 ++------- 1 file changed, 2 insertions(+), 7 deletions(-) diff --git a/helm/workspace-proxy/templates/namespace.yaml b/helm/workspace-proxy/templates/namespace.yaml index 6f63729db..c2beca049 100644 --- a/helm/workspace-proxy/templates/namespace.yaml +++ b/helm/workspace-proxy/templates/namespace.yaml @@ -1,7 +1,2 @@ -apiVersion: v1 -kind: Namespace -metadata: - name: {{ .Values.workspaceNamespace }} - labels: - app: workspace - kubernetes.io/metadata.name: {{ .Values.workspaceNamespace }} +{{- /* Namespace owned by the hatchery chart (jupyter-namespace.yaml). + workspace-proxy deploys into it but does not create it. */ -}} From 92f9437016499a0374f2dda38caca37b35ab41c7 Mon Sep 17 00:00:00 2001 From: cmalson Date: Fri, 8 May 2026 10:52:38 -0700 Subject: [PATCH 029/196] k8 api's issue fix Co-authored-by: Copilot --- helm/workspace-proxy/templates/netpol.yaml | 8 ++++++++ helm/workspace-proxy/values.yaml | 4 ++++ 2 files changed, 12 insertions(+) diff --git a/helm/workspace-proxy/templates/netpol.yaml b/helm/workspace-proxy/templates/netpol.yaml index f30ebe066..5b3efcdac 100644 --- a/helm/workspace-proxy/templates/netpol.yaml +++ b/helm/workspace-proxy/templates/netpol.yaml @@ -45,4 +45,12 @@ spec: port: 80 - protocol: TCP port: 8888 + {{- range .Values.kubernetesApiServerCIDRs }} + - to: + - ipBlock: + cidr: {{ . | quote }} + ports: + - protocol: TCP + port: 443 + {{- end }} {{- end }} diff --git a/helm/workspace-proxy/values.yaml b/helm/workspace-proxy/values.yaml index 8031b40bc..19c43318f 100644 --- a/helm/workspace-proxy/values.yaml +++ b/helm/workspace-proxy/values.yaml @@ -33,3 +33,7 @@ resources: # NetworkPolicy: restrict ingress to revproxy only. networkPolicy: enabled: true + +# Egress destinations for the in-cluster Kubernetes API service +# (kubernetes.default.svc -> service ClusterIP). Must be set per environment. +kubernetesApiServerCIDRs: [] From 90f938e0d5d4c97d145309c9c30ddcd5bb681298 Mon Sep 17 00:00:00 2001 From: cmalson Date: Wed, 13 May 2026 11:58:07 -0700 Subject: [PATCH 030/196] search and value changes needed for aurora integration. --- helm/vectis-overlays/templates/search-auth-proxy-secret.yaml | 4 ++-- helm/vectis-overlays/values.yaml | 3 +++ 2 files changed, 5 insertions(+), 2 deletions(-) diff --git a/helm/vectis-overlays/templates/search-auth-proxy-secret.yaml b/helm/vectis-overlays/templates/search-auth-proxy-secret.yaml index fa92218b9..815c9cacb 100644 --- a/helm/vectis-overlays/templates/search-auth-proxy-secret.yaml +++ b/helm/vectis-overlays/templates/search-auth-proxy-secret.yaml @@ -27,10 +27,10 @@ spec: data: - secretKey: username remoteRef: - key: {{ .Values.rds.secretName }} + key: {{ default .Values.rds.secretName .Values.searchAuthProxy.appDsnSecretName }} property: username - secretKey: password remoteRef: - key: {{ .Values.rds.secretName }} + key: {{ default .Values.rds.secretName .Values.searchAuthProxy.appDsnSecretName }} property: password {{- end }} diff --git a/helm/vectis-overlays/values.yaml b/helm/vectis-overlays/values.yaml index b1ab9c785..36272c1c6 100644 --- a/helm/vectis-overlays/values.yaml +++ b/helm/vectis-overlays/values.yaml @@ -58,6 +58,9 @@ searchAuthProxy: postgresDsnSecretRef: name: vectis-search-auth-proxy key: postgres_dsn + # Optional separate AWS secret name for the search-role credentials. + # Falls back to rds.secretName for backward compatibility. + appDsnSecretName: "" # CDK RDS secret in Secrets Manager — used to build the postgres DSN ExternalSecret. # Set per-environment in gitops values. From 661af35d2c1d52154c7318fbe22f59f261ca6bf9 Mon Sep 17 00:00:00 2001 From: cmalson Date: Wed, 13 May 2026 17:07:44 -0700 Subject: [PATCH 031/196] changes to lambda urls and auth --- .../templates/guppy-compat.yaml | 1 + .../search-auth-proxy-crossplane.yaml | 69 +++++++++++++++++++ .../templates/search-auth-proxy.yaml | 10 +-- .../templates/service-accounts.yaml | 43 ++++++++++++ .../templates/siem-service.yaml | 1 + helm/vectis-overlays/values.yaml | 15 ++++ 6 files changed, 134 insertions(+), 5 deletions(-) create mode 100644 helm/vectis-overlays/templates/search-auth-proxy-crossplane.yaml create mode 100644 helm/vectis-overlays/templates/service-accounts.yaml diff --git a/helm/vectis-overlays/templates/guppy-compat.yaml b/helm/vectis-overlays/templates/guppy-compat.yaml index 045e53789..b37214aba 100644 --- a/helm/vectis-overlays/templates/guppy-compat.yaml +++ b/helm/vectis-overlays/templates/guppy-compat.yaml @@ -16,6 +16,7 @@ spec: labels: app: guppy-compat-service spec: + serviceAccountName: {{ .Values.guppyCompat.serviceAccount.name }} containers: - name: guppy-compat-service image: "{{ .Values.guppyCompat.image.repository }}:{{ .Values.guppyCompat.image.tag }}" diff --git a/helm/vectis-overlays/templates/search-auth-proxy-crossplane.yaml b/helm/vectis-overlays/templates/search-auth-proxy-crossplane.yaml new file mode 100644 index 000000000..164d85c3b --- /dev/null +++ b/helm/vectis-overlays/templates/search-auth-proxy-crossplane.yaml @@ -0,0 +1,69 @@ +{{- $global := .Values.global | default dict }} +{{- $crossplane := get $global "crossplane" | default dict }} +{{- $crossplaneEnabled := get $crossplane "enabled" | default false }} +{{- if and .Values.searchAuthProxy.enabled $crossplaneEnabled }} +apiVersion: iam.aws.crossplane.io/v1beta1 +kind: Role +metadata: + name: "{{ get $global "environment" }}-{{ .Release.Namespace }}-{{ .Values.searchAuthProxy.serviceAccount.name }}" +spec: + providerConfigRef: + name: {{ get $crossplane "providerConfigName" | default "provider-aws" }} + forProvider: + name: "{{ get $global "environment" }}-{{ .Release.Namespace }}-{{ .Values.searchAuthProxy.serviceAccount.name }}" + description: "Role for search-auth-proxy service account for {{ get $global "environment" }}" + assumeRolePolicyDocument: | + { + "Version":"2012-10-17", + "Statement":[ + { + "Sid":"", + "Effect":"Allow", + "Principal":{"Federated":"arn:aws:iam::{{ get $crossplane "accountId" }}:oidc-provider/{{ get $crossplane "oidcProviderUrl" }}"}, + "Action":"sts:AssumeRoleWithWebIdentity", + "Condition":{ + "StringEquals":{ + "{{ get $crossplane "oidcProviderUrl" }}:sub":"system:serviceaccount:{{ .Release.Namespace }}:{{ .Values.searchAuthProxy.serviceAccount.name }}", + "{{ get $crossplane "oidcProviderUrl" }}:aud":"sts.amazonaws.com" + } + } + } + ] + } +--- +apiVersion: iam.aws.crossplane.io/v1beta1 +kind: Policy +metadata: + name: "{{ get $global "environment" }}-{{ .Release.Namespace }}-search-auth-proxy-role-policy" +spec: + providerConfigRef: + name: {{ get $crossplane "providerConfigName" | default "provider-aws" }} + forProvider: + name: "{{ get $global "environment" }}-{{ .Release.Namespace }}-search-auth-proxy-role-policy" + document: | + { + "Version":"2012-10-17", + "Statement":[ + { + "Effect":"Allow", + "Action":["execute-api:Invoke"], + "Resource":[ + "arn:aws:execute-api:{{ .Values.searchAuthProxy.apiGateway.region }}:{{ get $crossplane "accountId" }}:{{ .Values.searchAuthProxy.apiGateway.apiId }}/*/*/search", + "arn:aws:execute-api:{{ .Values.searchAuthProxy.apiGateway.region }}:{{ get $crossplane "accountId" }}:{{ .Values.searchAuthProxy.apiGateway.apiId }}/*/*/search/*" + ] + } + ] + } +--- +apiVersion: iam.aws.crossplane.io/v1beta1 +kind: RolePolicyAttachment +metadata: + name: "{{ .Values.searchAuthProxy.serviceAccount.name }}-{{ .Release.Namespace }}-managed-policy-attachment" +spec: + providerConfigRef: + name: {{ get $crossplane "providerConfigName" | default "provider-aws" }} + forProvider: + roleName: "{{ get $global "environment" }}-{{ .Release.Namespace }}-{{ .Values.searchAuthProxy.serviceAccount.name }}" + policyArnRef: + name: "{{ get $global "environment" }}-{{ .Release.Namespace }}-search-auth-proxy-role-policy" +{{- end }} diff --git a/helm/vectis-overlays/templates/search-auth-proxy.yaml b/helm/vectis-overlays/templates/search-auth-proxy.yaml index 4715ea3cf..7558ab16e 100644 --- a/helm/vectis-overlays/templates/search-auth-proxy.yaml +++ b/helm/vectis-overlays/templates/search-auth-proxy.yaml @@ -16,6 +16,7 @@ spec: labels: app: {{ .Values.searchAuthProxy.serviceName }} spec: + serviceAccountName: {{ .Values.searchAuthProxy.serviceAccount.name }} containers: - name: {{ .Values.searchAuthProxy.serviceName }} image: "{{ .Values.searchAuthProxy.image.repository }}:{{ .Values.searchAuthProxy.image.tag }}" @@ -23,11 +24,10 @@ spec: ports: - containerPort: 8000 env: - - name: POSTGRES_DSN - valueFrom: - secretKeyRef: - name: {{ .Values.searchAuthProxy.postgresDsnSecretRef.name }} - key: {{ .Values.searchAuthProxy.postgresDsnSecretRef.key }} + - name: SEARCH_API_BASE + value: "https://{{ .Values.searchAuthProxy.apiGateway.apiId }}.execute-api.{{ .Values.searchAuthProxy.apiGateway.region }}.amazonaws.com/search" + - name: ARBORIST_URL + value: "http://arborist-service.{{ .Release.Namespace }}.svc.cluster.local" - name: SEARCH_PROXY_DEFAULT_LIMIT value: {{ .Values.searchAuthProxy.env.SEARCH_PROXY_DEFAULT_LIMIT | quote }} - name: SEARCH_PROXY_MAX_LIMIT diff --git a/helm/vectis-overlays/templates/service-accounts.yaml b/helm/vectis-overlays/templates/service-accounts.yaml new file mode 100644 index 000000000..29818dff0 --- /dev/null +++ b/helm/vectis-overlays/templates/service-accounts.yaml @@ -0,0 +1,43 @@ +{{- $global := .Values.global | default dict }} +{{- $crossplane := get $global "crossplane" | default dict }} +{{- $crossplaneEnabled := get $crossplane "enabled" | default false }} +{{- if and .Values.guppyCompat.enabled .Values.guppyCompat.serviceAccount.create }} +apiVersion: v1 +kind: ServiceAccount +metadata: + name: {{ .Values.guppyCompat.serviceAccount.name }} + namespace: {{ .Release.Namespace }} + {{- with .Values.guppyCompat.serviceAccount.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} +--- +{{- end }} +{{- if and .Values.siemService.enabled .Values.siemService.serviceAccount.create }} +apiVersion: v1 +kind: ServiceAccount +metadata: + name: {{ .Values.siemService.serviceAccount.name }} + namespace: {{ .Release.Namespace }} + {{- with .Values.siemService.serviceAccount.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} +--- +{{- end }} +{{- if and .Values.searchAuthProxy.enabled .Values.searchAuthProxy.serviceAccount.create }} +apiVersion: v1 +kind: ServiceAccount +metadata: + name: {{ .Values.searchAuthProxy.serviceAccount.name }} + namespace: {{ .Release.Namespace }} + {{- if $crossplaneEnabled }} + annotations: + eks.amazonaws.com/role-arn: arn:aws:iam::{{ get $crossplane "accountId" }}:role/{{ get $global "environment" }}-{{ .Release.Namespace }}-{{ .Values.searchAuthProxy.serviceAccount.name }} + {{- else }} + {{- with .Values.searchAuthProxy.serviceAccount.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} + {{- end }} +{{- end }} diff --git a/helm/vectis-overlays/templates/siem-service.yaml b/helm/vectis-overlays/templates/siem-service.yaml index 56f302fb1..4a331b54e 100644 --- a/helm/vectis-overlays/templates/siem-service.yaml +++ b/helm/vectis-overlays/templates/siem-service.yaml @@ -16,6 +16,7 @@ spec: labels: app: siem-service spec: + serviceAccountName: {{ .Values.siemService.serviceAccount.name }} containers: - name: siem-service image: "{{ .Values.siemService.image.repository }}:{{ .Values.siemService.image.tag }}" diff --git a/helm/vectis-overlays/values.yaml b/helm/vectis-overlays/values.yaml index 36272c1c6..fedea5b18 100644 --- a/helm/vectis-overlays/values.yaml +++ b/helm/vectis-overlays/values.yaml @@ -5,6 +5,10 @@ guppyCompat: enabled: true replicaCount: 1 + serviceAccount: + create: true + name: guppy-compat-service + annotations: {} image: repository: quay.io/cdis/gen3-vectis tag: guppy-compat-v1 @@ -22,6 +26,10 @@ guppyCompat: siemService: enabled: true replicaCount: 1 + serviceAccount: + create: true + name: siem-service + annotations: {} image: repository: quay.io/cdis/gen3-vectis tag: siem-service-v1 @@ -41,6 +49,10 @@ searchAuthProxy: enabled: true replicaCount: 1 serviceName: search-auth-proxy + serviceAccount: + create: true + name: search-auth-proxy + annotations: {} image: repository: quay.io/cdis/gen3-vectis tag: search-auth-proxy-v1 @@ -55,6 +67,9 @@ searchAuthProxy: env: SEARCH_PROXY_DEFAULT_LIMIT: "50" SEARCH_PROXY_MAX_LIMIT: "1000" + apiGateway: + apiId: "" + region: "us-east-1" postgresDsnSecretRef: name: vectis-search-auth-proxy key: postgres_dsn From aca48fd0173474824ccb3f678f6389d7dfea15d0 Mon Sep 17 00:00:00 2001 From: cmalson Date: Thu, 14 May 2026 14:23:58 -0700 Subject: [PATCH 032/196] modifying and fixing jeg bug and siem path --- helm/jeg/values.yaml | 1 + .../templates/search-auth-proxy.yaml | 8 ++++++++ helm/vectis-overlays/templates/siem-service.yaml | 13 +++++++++++-- helm/vectis-overlays/values.yaml | 8 ++++++++ 4 files changed, 28 insertions(+), 2 deletions(-) diff --git a/helm/jeg/values.yaml b/helm/jeg/values.yaml index 3576e42de..343c7980e 100644 --- a/helm/jeg/values.yaml +++ b/helm/jeg/values.yaml @@ -24,6 +24,7 @@ env: EG_KERNEL_IMAGE_PULL_POLICY: IfNotPresent EG_SHARED_NAMESPACE: "False" EG_MIRROR_WORKING_DIRS: "False" + EG_KERNEL_WHITELIST_ENVS: "ACCESS_TOKEN" # propagate workspace token into kernel pods resources: requests: diff --git a/helm/vectis-overlays/templates/search-auth-proxy.yaml b/helm/vectis-overlays/templates/search-auth-proxy.yaml index 7558ab16e..92ed5ef45 100644 --- a/helm/vectis-overlays/templates/search-auth-proxy.yaml +++ b/helm/vectis-overlays/templates/search-auth-proxy.yaml @@ -26,6 +26,14 @@ spec: env: - name: SEARCH_API_BASE value: "https://{{ .Values.searchAuthProxy.apiGateway.apiId }}.execute-api.{{ .Values.searchAuthProxy.apiGateway.region }}.amazonaws.com/search" + - name: SIEM_SEARCH_BASE + value: {{ default (printf "https://%s.execute-api.%s.amazonaws.com/search" .Values.searchAuthProxy.apiGateway.apiId .Values.searchAuthProxy.apiGateway.region) .Values.searchAuthProxy.siemBackend.baseUrl | quote }} + - name: SEARCH_API_REQUIRE_SIGV4 + value: {{ .Values.searchAuthProxy.siemBackend.searchApiRequireSigv4 | quote }} + - name: SIEM_SEARCH_REQUIRE_SIGV4 + value: {{ .Values.searchAuthProxy.siemBackend.siemRequireSigv4 | quote }} + - name: SIEM_INDEXES + value: {{ .Values.searchAuthProxy.siemBackend.indexes | quote }} - name: ARBORIST_URL value: "http://arborist-service.{{ .Release.Namespace }}.svc.cluster.local" - name: SEARCH_PROXY_DEFAULT_LIMIT diff --git a/helm/vectis-overlays/templates/siem-service.yaml b/helm/vectis-overlays/templates/siem-service.yaml index 4a331b54e..074aa09a7 100644 --- a/helm/vectis-overlays/templates/siem-service.yaml +++ b/helm/vectis-overlays/templates/siem-service.yaml @@ -24,14 +24,23 @@ spec: ports: - containerPort: 8000 env: - - name: SEARCH_BASE - value: "http://search-auth-proxy.{{ .Release.Namespace }}.svc.cluster.local:8000/search" - name: ARBORIST_URL value: "http://arborist-service.{{ .Release.Namespace }}.svc.cluster.local" - name: SIEM_DEFAULT_LIMIT value: {{ .Values.siemService.env.SIEM_DEFAULT_LIMIT | quote }} - name: SIEM_MAX_LIMIT value: {{ .Values.siemService.env.SIEM_MAX_LIMIT | quote }} + - name: DATABASE_URL + valueFrom: + secretKeyRef: + name: vectis-search-auth-proxy + key: postgres_dsn + - name: DB_SCHEMA + value: {{ .Values.siemService.env.DB_SCHEMA | default "vectis_ingestion" | quote }} + - name: SIEM_BACKEND + value: {{ .Values.siemService.env.SIEM_BACKEND | default "postgres" | quote }} + - name: SIEM_INDEX_BACKENDS + value: {{ .Values.siemService.env.SIEM_INDEX_BACKENDS | default "" | quote }} readinessProbe: httpGet: path: /siem/health diff --git a/helm/vectis-overlays/values.yaml b/helm/vectis-overlays/values.yaml index fedea5b18..de9082998 100644 --- a/helm/vectis-overlays/values.yaml +++ b/helm/vectis-overlays/values.yaml @@ -70,6 +70,14 @@ searchAuthProxy: apiGateway: apiId: "" region: "us-east-1" + # Dual-route backend configuration: + # - Discovery/Guppy traffic uses SEARCH_API_BASE (API Gateway/Lambda path) + # - SIEM index traffic can use SIEM_SEARCH_BASE (RDS/ES-backed path) + siemBackend: + baseUrl: "" + searchApiRequireSigv4: "true" + siemRequireSigv4: "auto" + indexes: "security_event,audit_event,threat_indicator" postgresDsnSecretRef: name: vectis-search-auth-proxy key: postgres_dsn From 97b42a92a86bdf0f4e5969206fafe46667e673cf Mon Sep 17 00:00:00 2001 From: cmalson Date: Wed, 20 May 2026 18:26:32 -0700 Subject: [PATCH 033/196] removing guppy compat. --- helm/vectis-overlays/values.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/helm/vectis-overlays/values.yaml b/helm/vectis-overlays/values.yaml index de9082998..138072aa5 100644 --- a/helm/vectis-overlays/values.yaml +++ b/helm/vectis-overlays/values.yaml @@ -3,7 +3,7 @@ # Override image tags per-environment in gitops values. guppyCompat: - enabled: true + enabled: false replicaCount: 1 serviceAccount: create: true From 6ed0e57021d83f850ce1b8e112a54ed40574596f Mon Sep 17 00:00:00 2001 From: cmalson Date: Wed, 20 May 2026 19:23:15 -0700 Subject: [PATCH 034/196] adding snapshot directories for faster cheaper load --- helm/vectis-overlays/templates/search-auth-proxy.yaml | 8 ++++++++ helm/vectis-overlays/values.yaml | 5 +++++ 2 files changed, 13 insertions(+) diff --git a/helm/vectis-overlays/templates/search-auth-proxy.yaml b/helm/vectis-overlays/templates/search-auth-proxy.yaml index 92ed5ef45..8e80692b6 100644 --- a/helm/vectis-overlays/templates/search-auth-proxy.yaml +++ b/helm/vectis-overlays/templates/search-auth-proxy.yaml @@ -40,6 +40,14 @@ spec: value: {{ .Values.searchAuthProxy.env.SEARCH_PROXY_DEFAULT_LIMIT | quote }} - name: SEARCH_PROXY_MAX_LIMIT value: {{ .Values.searchAuthProxy.env.SEARCH_PROXY_MAX_LIMIT | quote }} + {{- if .Values.searchAuthProxy.snapshotsBucket }} + - name: SNAPSHOTS_BUCKET + value: {{ .Values.searchAuthProxy.snapshotsBucket | quote }} + {{- end }} + {{- if .Values.searchAuthProxy.snapshotsKeyPrefix }} + - name: SNAPSHOTS_KEY_PREFIX + value: {{ .Values.searchAuthProxy.snapshotsKeyPrefix | quote }} + {{- end }} readinessProbe: httpGet: path: /health diff --git a/helm/vectis-overlays/values.yaml b/helm/vectis-overlays/values.yaml index 138072aa5..1f049b152 100644 --- a/helm/vectis-overlays/values.yaml +++ b/helm/vectis-overlays/values.yaml @@ -67,6 +67,11 @@ searchAuthProxy: env: SEARCH_PROXY_DEFAULT_LIMIT: "50" SEARCH_PROXY_MAX_LIMIT: "1000" + # S3 bucket for pre-baked /search/graphql snapshots, populated by the + # snapshot-publisher Lambda (CDK SnapshotsBucketName output). Leave empty + # to disable the /snapshots/* passthrough. + snapshotsBucket: "" + snapshotsKeyPrefix: "snapshots/" apiGateway: apiId: "" region: "us-east-1" From f8fa1c9901a70675d70a3da61a25c033bd01a23a Mon Sep 17 00:00:00 2001 From: cmalson Date: Thu, 21 May 2026 13:01:38 -0700 Subject: [PATCH 035/196] feat_crossplane for siem --- .../templates/siem-service-crossplane.yaml | 56 +++++++++++++++++++ 1 file changed, 56 insertions(+) create mode 100644 helm/vectis-overlays/templates/siem-service-crossplane.yaml diff --git a/helm/vectis-overlays/templates/siem-service-crossplane.yaml b/helm/vectis-overlays/templates/siem-service-crossplane.yaml new file mode 100644 index 000000000..53e90ecec --- /dev/null +++ b/helm/vectis-overlays/templates/siem-service-crossplane.yaml @@ -0,0 +1,56 @@ +{{- $global := .Values.global | default dict }} +{{- $crossplane := get $global "crossplane" | default dict }} +{{- $crossplaneEnabled := get $crossplane "enabled" | default false }} +{{- if and .Values.siemService.enabled .Values.siemService.serviceAccount.create $crossplaneEnabled }} +apiVersion: iam.aws.crossplane.io/v1beta1 +kind: Role +metadata: + name: "{{ get $global "environment" }}-{{ .Release.Namespace }}-siem-service" +spec: + providerConfigRef: + name: {{ get $crossplane "providerConfigName" | default "provider-aws" }} + forProvider: + name: "{{ get $global "environment" }}-{{ .Release.Namespace }}-siem-service" + description: "IRSA role for siem-service in {{ .Release.Namespace }} — S3 access to siem views config" + assumeRolePolicyDocument: | + { + "Version":"2012-10-17", + "Statement":[ + { + "Effect":"Allow", + "Principal":{"Federated":"arn:aws:iam::{{ get $crossplane "accountId" }}:oidc-provider/{{ get $crossplane "oidcProviderUrl" }}"}, + "Action":"sts:AssumeRoleWithWebIdentity", + "Condition":{ + "StringEquals":{ + "{{ get $crossplane "oidcProviderUrl" }}:sub":"system:serviceaccount:{{ .Release.Namespace }}:{{ .Values.siemService.serviceAccount.name }}", + "{{ get $crossplane "oidcProviderUrl" }}:aud":"sts.amazonaws.com" + } + } + } + ] + } +--- +apiVersion: iam.aws.crossplane.io/v1beta1 +kind: RolePolicy +metadata: + name: "{{ get $global "environment" }}-{{ .Release.Namespace }}-siem-service-s3-views" +spec: + providerConfigRef: + name: {{ get $crossplane "providerConfigName" | default "provider-aws" }} + forProvider: + roleName: "{{ get $global "environment" }}-{{ .Release.Namespace }}-siem-service" + policyDocument: | + { + "Version":"2012-10-17", + "Statement":[ + { + "Effect":"Allow", + "Action":["s3:GetObject","s3:PutObject"], + "Resource":[ + "arn:aws:s3:::{{ .Values.siemService.env.SIEM_VIEWS_S3_BUCKET }}/siem/views.json", + "arn:aws:s3:::{{ .Values.siemService.env.SIEM_VIEWS_S3_BUCKET }}/siem/default-views.json" + ] + } + ] + } +{{- end }} From f86bcdf21f44be0db3cce939b9880b5a1e869f7b Mon Sep 17 00:00:00 2001 From: cmalson Date: Thu, 21 May 2026 13:04:18 -0700 Subject: [PATCH 036/196] feat_fix error --- .../templates/siem-service-crossplane.yaml | 20 +++++++++++++++---- 1 file changed, 16 insertions(+), 4 deletions(-) diff --git a/helm/vectis-overlays/templates/siem-service-crossplane.yaml b/helm/vectis-overlays/templates/siem-service-crossplane.yaml index 53e90ecec..8ffc5a3d6 100644 --- a/helm/vectis-overlays/templates/siem-service-crossplane.yaml +++ b/helm/vectis-overlays/templates/siem-service-crossplane.yaml @@ -31,15 +31,15 @@ spec: } --- apiVersion: iam.aws.crossplane.io/v1beta1 -kind: RolePolicy +kind: Policy metadata: - name: "{{ get $global "environment" }}-{{ .Release.Namespace }}-siem-service-s3-views" + name: "{{ get $global "environment" }}-{{ .Release.Namespace }}-siem-service-role-policy" spec: providerConfigRef: name: {{ get $crossplane "providerConfigName" | default "provider-aws" }} forProvider: - roleName: "{{ get $global "environment" }}-{{ .Release.Namespace }}-siem-service" - policyDocument: | + name: "{{ get $global "environment" }}-{{ .Release.Namespace }}-siem-service-role-policy" + document: | { "Version":"2012-10-17", "Statement":[ @@ -53,4 +53,16 @@ spec: } ] } +--- +apiVersion: iam.aws.crossplane.io/v1beta1 +kind: RolePolicyAttachment +metadata: + name: "siem-service-{{ .Release.Namespace }}-managed-policy-attachment" +spec: + providerConfigRef: + name: {{ get $crossplane "providerConfigName" | default "provider-aws" }} + forProvider: + roleName: "{{ get $global "environment" }}-{{ .Release.Namespace }}-siem-service" + policyArnRef: + name: "{{ get $global "environment" }}-{{ .Release.Namespace }}-siem-service-role-policy" {{- end }} From 6342d16ac654889021b4772b2c0bf337210e1f35 Mon Sep 17 00:00:00 2001 From: cmalson Date: Thu, 21 May 2026 15:05:47 -0700 Subject: [PATCH 037/196] db schema change --- helm/vectis-overlays/templates/siem-service.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/helm/vectis-overlays/templates/siem-service.yaml b/helm/vectis-overlays/templates/siem-service.yaml index 074aa09a7..f92959d33 100644 --- a/helm/vectis-overlays/templates/siem-service.yaml +++ b/helm/vectis-overlays/templates/siem-service.yaml @@ -36,7 +36,7 @@ spec: name: vectis-search-auth-proxy key: postgres_dsn - name: DB_SCHEMA - value: {{ .Values.siemService.env.DB_SCHEMA | default "vectis_ingestion" | quote }} + value: {{ .Values.siemService.env.DB_SCHEMA | default "vectis" | quote }} - name: SIEM_BACKEND value: {{ .Values.siemService.env.SIEM_BACKEND | default "postgres" | quote }} - name: SIEM_INDEX_BACKENDS From f6b25c98eed91f0b3aec4d4c45f316fc2a085560 Mon Sep 17 00:00:00 2001 From: cmalson Date: Thu, 21 May 2026 15:14:48 -0700 Subject: [PATCH 038/196] siem-service: set DB_SCHEMA=vectis as chart default --- helm/vectis-overlays/values.yaml | 1 + 1 file changed, 1 insertion(+) diff --git a/helm/vectis-overlays/values.yaml b/helm/vectis-overlays/values.yaml index 1f049b152..88d29f43f 100644 --- a/helm/vectis-overlays/values.yaml +++ b/helm/vectis-overlays/values.yaml @@ -42,6 +42,7 @@ siemService: cpu: "500m" memory: "512Mi" env: + DB_SCHEMA: "vectis" SIEM_DEFAULT_LIMIT: "250" SIEM_MAX_LIMIT: "2000" From c8714ddf6336a5e097038d366dfecf2443f25e50 Mon Sep 17 00:00:00 2001 From: cmalson Date: Fri, 22 May 2026 09:50:27 -0700 Subject: [PATCH 039/196] crossplane roels for siem service --- helm/vectis-overlays/templates/service-accounts.yaml | 5 +++++ helm/vectis-overlays/templates/siem-service-crossplane.yaml | 5 +++-- helm/vectis-overlays/values.yaml | 3 +++ 3 files changed, 11 insertions(+), 2 deletions(-) diff --git a/helm/vectis-overlays/templates/service-accounts.yaml b/helm/vectis-overlays/templates/service-accounts.yaml index 29818dff0..3c7c3714e 100644 --- a/helm/vectis-overlays/templates/service-accounts.yaml +++ b/helm/vectis-overlays/templates/service-accounts.yaml @@ -19,10 +19,15 @@ kind: ServiceAccount metadata: name: {{ .Values.siemService.serviceAccount.name }} namespace: {{ .Release.Namespace }} + {{- if $crossplaneEnabled }} + annotations: + eks.amazonaws.com/role-arn: arn:aws:iam::{{ get $crossplane "accountId" }}:role/{{ get $global "environment" }}-{{ .Release.Namespace }}-{{ .Values.siemService.serviceAccount.name }} + {{- else }} {{- with .Values.siemService.serviceAccount.annotations }} annotations: {{- toYaml . | nindent 4 }} {{- end }} + {{- end }} --- {{- end }} {{- if and .Values.searchAuthProxy.enabled .Values.searchAuthProxy.serviceAccount.create }} diff --git a/helm/vectis-overlays/templates/siem-service-crossplane.yaml b/helm/vectis-overlays/templates/siem-service-crossplane.yaml index 8ffc5a3d6..9329df34b 100644 --- a/helm/vectis-overlays/templates/siem-service-crossplane.yaml +++ b/helm/vectis-overlays/templates/siem-service-crossplane.yaml @@ -47,8 +47,9 @@ spec: "Effect":"Allow", "Action":["s3:GetObject","s3:PutObject"], "Resource":[ - "arn:aws:s3:::{{ .Values.siemService.env.SIEM_VIEWS_S3_BUCKET }}/siem/views.json", - "arn:aws:s3:::{{ .Values.siemService.env.SIEM_VIEWS_S3_BUCKET }}/siem/default-views.json" + {{- $bucket := .Values.siemService.env.SIEM_VIEWS_S3_BUCKET | default "" }} + "arn:aws:s3:::{{ $bucket }}/siem/views.json", + "arn:aws:s3:::{{ $bucket }}/siem/default-views.json" ] } ] diff --git a/helm/vectis-overlays/values.yaml b/helm/vectis-overlays/values.yaml index 88d29f43f..ed90a58d8 100644 --- a/helm/vectis-overlays/values.yaml +++ b/helm/vectis-overlays/values.yaml @@ -45,6 +45,9 @@ siemService: DB_SCHEMA: "vectis" SIEM_DEFAULT_LIMIT: "250" SIEM_MAX_LIMIT: "2000" + SIEM_VIEWS_S3_BUCKET: "" + SIEM_VIEWS_S3_KEY: "siem/views.json" + SIEM_VIEWS_S3_ENABLED: "false" searchAuthProxy: enabled: true From b58cd2417faf0fe78b06506c8ad0a2d05d9ef97f Mon Sep 17 00:00:00 2001 From: cmalson Date: Fri, 22 May 2026 09:56:17 -0700 Subject: [PATCH 040/196] change to crossplane for the api gateway access. --- .../templates/search-auth-proxy-crossplane.yaml | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/helm/vectis-overlays/templates/search-auth-proxy-crossplane.yaml b/helm/vectis-overlays/templates/search-auth-proxy-crossplane.yaml index 164d85c3b..5960f6a60 100644 --- a/helm/vectis-overlays/templates/search-auth-proxy-crossplane.yaml +++ b/helm/vectis-overlays/templates/search-auth-proxy-crossplane.yaml @@ -48,8 +48,7 @@ spec: "Effect":"Allow", "Action":["execute-api:Invoke"], "Resource":[ - "arn:aws:execute-api:{{ .Values.searchAuthProxy.apiGateway.region }}:{{ get $crossplane "accountId" }}:{{ .Values.searchAuthProxy.apiGateway.apiId }}/*/*/search", - "arn:aws:execute-api:{{ .Values.searchAuthProxy.apiGateway.region }}:{{ get $crossplane "accountId" }}:{{ .Values.searchAuthProxy.apiGateway.apiId }}/*/*/search/*" + "arn:aws:execute-api:{{ .Values.searchAuthProxy.apiGateway.region }}:{{ get $crossplane "accountId" }}:{{ .Values.searchAuthProxy.apiGateway.apiId }}/*/*/*" ] } ] From cbe7890684fc28adde460b98a303e7d68ebce437 Mon Sep 17 00:00:00 2001 From: cmalson Date: Tue, 26 May 2026 09:41:17 -0700 Subject: [PATCH 041/196] troubleshooting a 401 issue --- helm/vectis-overlays/templates/search-auth-proxy.yaml | 4 ++++ helm/vectis-overlays/values.yaml | 5 +++++ 2 files changed, 9 insertions(+) diff --git a/helm/vectis-overlays/templates/search-auth-proxy.yaml b/helm/vectis-overlays/templates/search-auth-proxy.yaml index 8e80692b6..a5fcf7573 100644 --- a/helm/vectis-overlays/templates/search-auth-proxy.yaml +++ b/helm/vectis-overlays/templates/search-auth-proxy.yaml @@ -17,6 +17,10 @@ spec: app: {{ .Values.searchAuthProxy.serviceName }} spec: serviceAccountName: {{ .Values.searchAuthProxy.serviceAccount.name }} + {{- if .Values.searchAuthProxy.hostAliases }} + hostAliases: + {{- toYaml .Values.searchAuthProxy.hostAliases | nindent 8 }} + {{- end }} containers: - name: {{ .Values.searchAuthProxy.serviceName }} image: "{{ .Values.searchAuthProxy.image.repository }}:{{ .Values.searchAuthProxy.image.tag }}" diff --git a/helm/vectis-overlays/values.yaml b/helm/vectis-overlays/values.yaml index ed90a58d8..7f2c1ef6c 100644 --- a/helm/vectis-overlays/values.yaml +++ b/helm/vectis-overlays/values.yaml @@ -79,6 +79,11 @@ searchAuthProxy: apiGateway: apiId: "" region: "us-east-1" + # Override DNS for the execute-api hostname to bypass the VPC endpoint. + # Set per-environment to the public API Gateway IPs when the execute-api + # VPC endpoint causes 403s (HTTP APIs are not routable through private + # execute-api VPC endpoints — they require a Private REST API). + hostAliases: [] # Dual-route backend configuration: # - Discovery/Guppy traffic uses SEARCH_API_BASE (API Gateway/Lambda path) # - SIEM index traffic can use SIEM_SEARCH_BASE (RDS/ES-backed path) From f15dc24839355efd55a44d976a8f45b1de523eb1 Mon Sep 17 00:00:00 2001 From: cmalson Date: Wed, 27 May 2026 14:42:40 -0700 Subject: [PATCH 042/196] moving to fence arborist natively in the lambda function --- helm/vectis-overlays/templates/search-auth-proxy.yaml | 4 ++++ helm/vectis-overlays/values.yaml | 1 + 2 files changed, 5 insertions(+) diff --git a/helm/vectis-overlays/templates/search-auth-proxy.yaml b/helm/vectis-overlays/templates/search-auth-proxy.yaml index a5fcf7573..5bb97bcc0 100644 --- a/helm/vectis-overlays/templates/search-auth-proxy.yaml +++ b/helm/vectis-overlays/templates/search-auth-proxy.yaml @@ -34,6 +34,10 @@ spec: value: {{ default (printf "https://%s.execute-api.%s.amazonaws.com/search" .Values.searchAuthProxy.apiGateway.apiId .Values.searchAuthProxy.apiGateway.region) .Values.searchAuthProxy.siemBackend.baseUrl | quote }} - name: SEARCH_API_REQUIRE_SIGV4 value: {{ .Values.searchAuthProxy.siemBackend.searchApiRequireSigv4 | quote }} + {{- if .Values.searchAuthProxy.env.SEARCH_API_TLS_VERIFY }} + - name: SEARCH_API_TLS_VERIFY + value: {{ .Values.searchAuthProxy.env.SEARCH_API_TLS_VERIFY | quote }} + {{- end }} - name: SIEM_SEARCH_REQUIRE_SIGV4 value: {{ .Values.searchAuthProxy.siemBackend.siemRequireSigv4 | quote }} - name: SIEM_INDEXES diff --git a/helm/vectis-overlays/values.yaml b/helm/vectis-overlays/values.yaml index 7f2c1ef6c..0b57636df 100644 --- a/helm/vectis-overlays/values.yaml +++ b/helm/vectis-overlays/values.yaml @@ -71,6 +71,7 @@ searchAuthProxy: env: SEARCH_PROXY_DEFAULT_LIMIT: "50" SEARCH_PROXY_MAX_LIMIT: "1000" + SEARCH_API_TLS_VERIFY: "" # S3 bucket for pre-baked /search/graphql snapshots, populated by the # snapshot-publisher Lambda (CDK SnapshotsBucketName output). Leave empty # to disable the /snapshots/* passthrough. From 83388cd963427f54ae98840b3a29b7bfa08ae53d Mon Sep 17 00:00:00 2001 From: craigrbarnes Date: Thu, 11 Jun 2026 09:07:33 -0500 Subject: [PATCH 043/196] docs: add notes for running Vectis locally with Kind configuration --- vectis/Notes.md | 66 +++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 66 insertions(+) create mode 100644 vectis/Notes.md diff --git a/vectis/Notes.md b/vectis/Notes.md new file mode 100644 index 000000000..c511fc6c2 --- /dev/null +++ b/vectis/Notes.md @@ -0,0 +1,66 @@ +# Note on running vectis locally + +Need to support linux-amd platform as these do not have images for arm64. + +need to enable the following: +* Rosetta for macbook +* Kind config below + +To run a hatchery pod: need to run: `kubectl label node kind-multi-node-control-plane role=jupyter` + +# create api credential with scope "credentials": +``` +fence-create token-create --scopes openid,user,fence,data,credentials,google_service_account,google_credentials --type access_token --exp 10800 --username craigrbarnes@uchicago.edu +``` + +## Kind config +```yaml +# kind config to handle running kind with linux-amd64 nodes + +kind: Cluster +apiVersion: kind.x-k8s.io/v1alpha4 +name: kind-multi-node +networking: + ipFamily: ipv4 + apiServerAddress: 127.0.0.1 +nodes: + - role: control-plane + extraMounts: + - hostPath: ./coredns-custom + containerPath: /etc/coredns/custom + kubeadmConfigPatches: + - | + kind: ClusterConfiguration + apiVersion: kubeadm.k8s.io/v1beta3 + dns: + type: CoreDNS + coreDNS: + extraArgs: + conf: /etc/coredns/custom/Corefile + - | + kind: InitConfiguration + apiVersion: kubeadm.k8s.io/v1beta3 + nodeRegistration: + kubeletExtraArgs: + node-labels: "ingress-ready=true" + extraPortMappings: + - containerPort: 80 + hostPort: 80 + protocol: TCP + - containerPort: 443 + hostPort: 443 + protocol: TCP +containerdConfigPatches: + - |- + [plugins."io.containerd.grpc.v1.cri"] + disable_apparmor = true + [plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc] + [plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc.options] + SystemdCgroup = true + DisableNewKeyring = true + [plugins."io.containerd.grpc.v1.cri".containerd.runtimes."runc-amd64"] + runtime_type = "io.containerd.runc.v2" + [plugins."io.containerd.grpc.v1.cri".containerd.runtimes."runc-amd64".options] + SystemdCgroup = true + DisableNewKeyring = true +``` \ No newline at end of file From 3b0ff770dd5a29e72b68d999a8faf4f769b52f68 Mon Sep 17 00:00:00 2001 From: sowmyag96 <“{sowmyag@uchicago.edu}”> Date: Tue, 16 Jun 2026 11:37:45 -0400 Subject: [PATCH 044/196] Test if branch pipeline works --- .pre-commit-config.yaml | 1 + 1 file changed, 1 insertion(+) diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index e6605717f..b3defcaf2 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -16,6 +16,7 @@ repos: # rev: v0.1.17 # Get the latest from: https://github.com/gruntwork-io/pre-commit/releases # hooks: # - id: helmlint + # - repo: https://github.com/norwoodj/helm-docs rev: "v1.14.2" From 6ad6e9a58df93ad4769b033ca9da605f33b5355f Mon Sep 17 00:00:00 2001 From: sowmyag96 <“{sowmyag@uchicago.edu}”> Date: Tue, 16 Jun 2026 11:58:45 -0400 Subject: [PATCH 045/196] Adding s3 monitor code --- helm/vectis-overlays/README.md | 108 +++++++++++ .../templates/S3monitor_db.yaml | 177 ++++++++++++++++++ .../templates/migration-configmap.yaml | 25 +++ .../templates/migration-job.yaml | 2 + .../templates/s3-monitor-crossplane.yaml | 75 ++++++++ .../templates/s3-monitor-secret.yaml | 38 ++++ .../templates/service-accounts.yaml | 17 ++ helm/vectis-overlays/values.yaml | 44 +++++ 8 files changed, 486 insertions(+) create mode 100644 helm/vectis-overlays/README.md create mode 100644 helm/vectis-overlays/templates/S3monitor_db.yaml create mode 100644 helm/vectis-overlays/templates/s3-monitor-crossplane.yaml create mode 100644 helm/vectis-overlays/templates/s3-monitor-secret.yaml diff --git a/helm/vectis-overlays/README.md b/helm/vectis-overlays/README.md new file mode 100644 index 000000000..4f6d57515 --- /dev/null +++ b/helm/vectis-overlays/README.md @@ -0,0 +1,108 @@ +# vectis-overlays + +![Version: 0.1.0](https://img.shields.io/badge/Version-0.1.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.0](https://img.shields.io/badge/AppVersion-1.0-informational?style=flat-square) + +Vectis overlay API services (guppy-compat, siem, search-auth-proxy) + +## Requirements + +| Repository | Name | Version | +|------------|------|---------| +| file://../common | common | 0.1.34 | + +## Values + +| Key | Type | Default | Description | +|-----|------|---------|-------------| +| global.externalSecrets.clusterSecretStoreRef | string | `""` | | +| guppyCompat.enabled | bool | `false` | | +| guppyCompat.env.GUPPY_COMPAT_MAX_LIMIT | string | `"5000"` | | +| guppyCompat.image.pullPolicy | string | `"Always"` | | +| guppyCompat.image.repository | string | `"quay.io/cdis/gen3-vectis"` | | +| guppyCompat.image.tag | string | `"guppy-compat-v1"` | | +| guppyCompat.replicaCount | int | `1` | | +| guppyCompat.resources.limits.cpu | string | `"500m"` | | +| guppyCompat.resources.limits.memory | string | `"512Mi"` | | +| guppyCompat.resources.requests.cpu | string | `"50m"` | | +| guppyCompat.resources.requests.memory | string | `"128Mi"` | | +| guppyCompat.serviceAccount.annotations | object | `{}` | | +| guppyCompat.serviceAccount.create | bool | `true` | | +| guppyCompat.serviceAccount.name | string | `"guppy-compat-service"` | | +| migrations.enabled | bool | `false` | | +| rds.database | string | `"postgres"` | | +| rds.endpoint | string | `""` | | +| rds.port | string | `"5432"` | | +| rds.secretName | string | `""` | | +| s3Monitor.aws.region | string | `"us-east-1"` | | +| s3Monitor.db.database | string | `"postgres"` | | +| s3Monitor.db.host | string | `""` | | +| s3Monitor.db.port | string | `"5432"` | | +| s3Monitor.db.schema | string | `"vectis"` | | +| s3Monitor.db.secretName | string | `""` | | +| s3Monitor.db.secretTargetName | string | `"s3-monitor-db-creds"` | | +| s3Monitor.db.table | string | `"s3_metadata"` | | +| s3Monitor.enabled | bool | `false` | | +| s3Monitor.failedJobsHistoryLimit | int | `1` | | +| s3Monitor.image.pullPolicy | string | `"IfNotPresent"` | | +| s3Monitor.image.repository | string | `"python"` | | +| s3Monitor.image.tag | string | `"3.11-slim"` | | +| s3Monitor.initImage.pullPolicy | string | `"IfNotPresent"` | | +| s3Monitor.initImage.repository | string | `"busybox"` | | +| s3Monitor.initImage.tag | string | `"1.36"` | | +| s3Monitor.resources.limits.cpu | string | `"500m"` | | +| s3Monitor.resources.limits.memory | string | `"512Mi"` | | +| s3Monitor.resources.requests.cpu | string | `"50m"` | | +| s3Monitor.resources.requests.memory | string | `"128Mi"` | | +| s3Monitor.s3.bucket | string | `""` | | +| s3Monitor.s3.prefix | string | `""` | | +| s3Monitor.schedule | string | `"*/5 * * * *"` | | +| s3Monitor.serviceAccount.annotations | object | `{}` | | +| s3Monitor.serviceAccount.create | bool | `true` | | +| s3Monitor.serviceAccount.name | string | `"s3-monitor-sa"` | | +| s3Monitor.successfulJobsHistoryLimit | int | `3` | | +| searchAuthProxy.apiGateway.apiId | string | `""` | | +| searchAuthProxy.apiGateway.region | string | `"us-east-1"` | | +| searchAuthProxy.appDsnSecretName | string | `""` | | +| searchAuthProxy.enabled | bool | `true` | | +| searchAuthProxy.env.SEARCH_API_TLS_VERIFY | string | `""` | | +| searchAuthProxy.env.SEARCH_PROXY_DEFAULT_LIMIT | string | `"50"` | | +| searchAuthProxy.env.SEARCH_PROXY_MAX_LIMIT | string | `"1000"` | | +| searchAuthProxy.hostAliases | list | `[]` | | +| searchAuthProxy.image.pullPolicy | string | `"Always"` | | +| searchAuthProxy.image.repository | string | `"quay.io/cdis/gen3-vectis"` | | +| searchAuthProxy.image.tag | string | `"search-auth-proxy-v1"` | | +| searchAuthProxy.postgresDsnSecretRef.key | string | `"postgres_dsn"` | | +| searchAuthProxy.postgresDsnSecretRef.name | string | `"vectis-search-auth-proxy"` | | +| searchAuthProxy.replicaCount | int | `1` | | +| searchAuthProxy.resources.limits.cpu | string | `"500m"` | | +| searchAuthProxy.resources.limits.memory | string | `"512Mi"` | | +| searchAuthProxy.resources.requests.cpu | string | `"50m"` | | +| searchAuthProxy.resources.requests.memory | string | `"128Mi"` | | +| searchAuthProxy.serviceAccount.annotations | object | `{}` | | +| searchAuthProxy.serviceAccount.create | bool | `true` | | +| searchAuthProxy.serviceAccount.name | string | `"search-auth-proxy"` | | +| searchAuthProxy.serviceName | string | `"search-auth-proxy"` | | +| searchAuthProxy.siemBackend.baseUrl | string | `""` | | +| searchAuthProxy.siemBackend.indexes | string | `"security_event,audit_event,threat_indicator"` | | +| searchAuthProxy.siemBackend.searchApiRequireSigv4 | string | `"true"` | | +| searchAuthProxy.siemBackend.siemRequireSigv4 | string | `"auto"` | | +| searchAuthProxy.snapshotsBucket | string | `""` | | +| searchAuthProxy.snapshotsKeyPrefix | string | `"snapshots/"` | | +| siemService.enabled | bool | `true` | | +| siemService.env.DB_SCHEMA | string | `"vectis"` | | +| siemService.env.SIEM_DEFAULT_LIMIT | string | `"250"` | | +| siemService.env.SIEM_MAX_LIMIT | string | `"2000"` | | +| siemService.env.SIEM_VIEWS_S3_BUCKET | string | `""` | | +| siemService.env.SIEM_VIEWS_S3_ENABLED | string | `"false"` | | +| siemService.env.SIEM_VIEWS_S3_KEY | string | `"siem/views.json"` | | +| siemService.image.pullPolicy | string | `"Always"` | | +| siemService.image.repository | string | `"quay.io/cdis/gen3-vectis"` | | +| siemService.image.tag | string | `"siem-service-v1"` | | +| siemService.replicaCount | int | `1` | | +| siemService.resources.limits.cpu | string | `"500m"` | | +| siemService.resources.limits.memory | string | `"512Mi"` | | +| siemService.resources.requests.cpu | string | `"50m"` | | +| siemService.resources.requests.memory | string | `"128Mi"` | | +| siemService.serviceAccount.annotations | object | `{}` | | +| siemService.serviceAccount.create | bool | `true` | | +| siemService.serviceAccount.name | string | `"siem-service"` | | diff --git a/helm/vectis-overlays/templates/S3monitor_db.yaml b/helm/vectis-overlays/templates/S3monitor_db.yaml new file mode 100644 index 000000000..5cb2014d7 --- /dev/null +++ b/helm/vectis-overlays/templates/S3monitor_db.yaml @@ -0,0 +1,177 @@ +{{- if .Values.s3Monitor.enabled }} +apiVersion: batch/v1 +kind: CronJob +metadata: + name: s3-monitor + namespace: {{ .Release.Namespace }} +spec: + schedule: {{ .Values.s3Monitor.schedule | quote }} + successfulJobsHistoryLimit: {{ .Values.s3Monitor.successfulJobsHistoryLimit }} + failedJobsHistoryLimit: {{ .Values.s3Monitor.failedJobsHistoryLimit }} + jobTemplate: + spec: + template: + spec: + serviceAccountName: {{ .Values.s3Monitor.serviceAccount.name }} + restartPolicy: OnFailure + initContainers: + - name: download-rds-cert + image: "{{ .Values.s3Monitor.initImage.repository }}:{{ .Values.s3Monitor.initImage.tag }}" + imagePullPolicy: {{ .Values.s3Monitor.initImage.pullPolicy }} + command: ["/bin/sh", "-c"] + args: + - | + wget -q https://truststore.pki.rds.amazonaws.com/global/global-bundle.pem -O /ssl/global-bundle.pem + volumeMounts: + - name: ssl-cert + mountPath: /ssl + containers: + - name: s3-monitor + image: "{{ .Values.s3Monitor.image.repository }}:{{ .Values.s3Monitor.image.tag }}" + imagePullPolicy: {{ .Values.s3Monitor.image.pullPolicy }} + env: + - name: AWS_REGION + value: {{ .Values.s3Monitor.aws.region | quote }} + - name: S3_BUCKET + value: {{ .Values.s3Monitor.s3.bucket | quote }} + - name: S3_PREFIX + value: {{ .Values.s3Monitor.s3.prefix | quote }} + - name: DB_SCHEMA + value: {{ .Values.s3Monitor.db.schema | quote }} + - name: DB_TABLE + value: {{ .Values.s3Monitor.db.table | quote }} + - name: PGHOST + valueFrom: + secretKeyRef: + name: {{ .Values.s3Monitor.db.secretTargetName }} + key: PGHOST + optional: false + - name: PGPORT + valueFrom: + secretKeyRef: + name: {{ .Values.s3Monitor.db.secretTargetName }} + key: PGPORT + optional: false + - name: PGDATABASE + valueFrom: + secretKeyRef: + name: {{ .Values.s3Monitor.db.secretTargetName }} + key: PGDATABASE + optional: false + - name: PGUSER + valueFrom: + secretKeyRef: + name: {{ .Values.s3Monitor.db.secretTargetName }} + key: PGUSER + optional: false + - name: PGPASSWORD + valueFrom: + secretKeyRef: + name: {{ .Values.s3Monitor.db.secretTargetName }} + key: PGPASSWORD + optional: false + command: ["/bin/sh", "-c"] + args: + - | + pip install -q boto3 psycopg2-binary + python - <<'PYEOF' + import os + from datetime import datetime, timezone, timedelta + + import boto3 + import psycopg2 + from psycopg2 import sql + + region = os.environ["AWS_REGION"] + bucket = os.environ["S3_BUCKET"] + prefix = os.environ.get("S3_PREFIX", "") + db_schema = os.environ.get("DB_SCHEMA", "vectis") + db_table = os.environ.get("DB_TABLE", "s3_metadata") + ssl_cert = "/ssl/global-bundle.pem" + + conn = psycopg2.connect( + host=os.environ["PGHOST"], + port=os.environ["PGPORT"], + dbname=os.environ["PGDATABASE"], + user=os.environ["PGUSER"], + password=os.environ["PGPASSWORD"], + sslmode="verify-full", + sslrootcert=ssl_cert, + connect_timeout=10, + ) + conn.autocommit = True + cur = conn.cursor() + + cur.execute(sql.SQL("CREATE SCHEMA IF NOT EXISTS {};").format(sql.Identifier(db_schema))) + cur.execute( + sql.SQL( + """ + CREATE TABLE IF NOT EXISTS {}.{} ( + id SERIAL PRIMARY KEY, + bucket_name TEXT NOT NULL, + file_key TEXT NOT NULL, + current_size_bytes BIGINT NOT NULL, + previous_size_bytes BIGINT, + event_type TEXT NOT NULL, + s3_last_modified TIMESTAMPTZ NOT NULL, + detected_at TIMESTAMPTZ NOT NULL DEFAULT NOW(), + UNIQUE (bucket_name, file_key, detected_at) + ); + """ + ).format(sql.Identifier(db_schema), sql.Identifier(db_table)) + ) + + s3 = boto3.client("s3", region_name=region) + paginator = s3.get_paginator("list_objects_v2") + all_objects = [] + for page in paginator.paginate(Bucket=bucket, Prefix=prefix): + all_objects.extend(page.get("Contents", [])) + + cutoff = datetime.now(timezone.utc) - timedelta(minutes=5) + recent = [obj for obj in all_objects if obj["LastModified"] >= cutoff] + + for obj in recent: + key = obj["Key"] + size = obj["Size"] + last_modified = obj["LastModified"] + + cur.execute( + sql.SQL( + """ + SELECT current_size_bytes FROM {}.{} + WHERE bucket_name = %s AND file_key = %s + ORDER BY detected_at DESC LIMIT 1 + """ + ).format(sql.Identifier(db_schema), sql.Identifier(db_table)), + (bucket, key), + ) + row = cur.fetchone() + prev = row[0] if row else None + event_type = "CREATED" if row is None else "UPDATED" + + cur.execute( + sql.SQL( + """ + INSERT INTO {}.{} ( + bucket_name, file_key, current_size_bytes, + previous_size_bytes, event_type, s3_last_modified + ) VALUES (%s, %s, %s, %s, %s, %s) + """ + ).format(sql.Identifier(db_schema), sql.Identifier(db_table)), + (bucket, key, size, prev, event_type, last_modified), + ) + + cur.close() + conn.close() + + print(f"Processed {len(recent)} updated objects from s3://{bucket}/{prefix}") + PYEOF + volumeMounts: + - name: ssl-cert + mountPath: /ssl + resources: + {{- toYaml .Values.s3Monitor.resources | nindent 16 }} + volumes: + - name: ssl-cert + emptyDir: {} +{{- end }} diff --git a/helm/vectis-overlays/templates/migration-configmap.yaml b/helm/vectis-overlays/templates/migration-configmap.yaml index 8e071c95e..55e96a33c 100644 --- a/helm/vectis-overlays/templates/migration-configmap.yaml +++ b/helm/vectis-overlays/templates/migration-configmap.yaml @@ -232,4 +232,29 @@ data: ALTER TABLE drs.drs_object ADD COLUMN IF NOT EXISTS auth_resource_path TEXT; END IF; END $$; + + 003_s3_monitor_grants.sql: | + -- Migration 003: s3-monitor role grants on vectis schema. + DO $$ + BEGIN + IF NOT EXISTS (SELECT 1 FROM pg_roles WHERE rolname = 's3_monitor_role') THEN + CREATE ROLE s3_monitor_role NOLOGIN; + END IF; + END $$; + + GRANT USAGE ON SCHEMA vectis TO s3_monitor_role; + GRANT SELECT, INSERT, UPDATE, DELETE ON ALL TABLES IN SCHEMA vectis TO s3_monitor_role; + GRANT USAGE, SELECT ON ALL SEQUENCES IN SCHEMA vectis TO s3_monitor_role; + + ALTER DEFAULT PRIVILEGES IN SCHEMA vectis + GRANT SELECT, INSERT, UPDATE, DELETE ON TABLES TO s3_monitor_role; + ALTER DEFAULT PRIVILEGES IN SCHEMA vectis + GRANT USAGE, SELECT ON SEQUENCES TO s3_monitor_role; + + DO $$ + BEGIN + IF EXISTS (SELECT 1 FROM pg_roles WHERE rolname = 's3_monitor_user') THEN + GRANT s3_monitor_role TO s3_monitor_user; + END IF; + END $$; {{- end }} diff --git a/helm/vectis-overlays/templates/migration-job.yaml b/helm/vectis-overlays/templates/migration-job.yaml index 19fbdf06a..1a177af4a 100644 --- a/helm/vectis-overlays/templates/migration-job.yaml +++ b/helm/vectis-overlays/templates/migration-job.yaml @@ -63,5 +63,7 @@ spec: psql -f /sql/001_rls_and_masked_views.sql echo "==> [002] DRS auth_resource_path column..." psql -f /sql/002_drs_auth_resource_path.sql + echo "==> [003] s3-monitor role grants..." + psql -f /sql/003_s3_monitor_grants.sql echo "==> All migrations complete." {{- end }} diff --git a/helm/vectis-overlays/templates/s3-monitor-crossplane.yaml b/helm/vectis-overlays/templates/s3-monitor-crossplane.yaml new file mode 100644 index 000000000..6934c6502 --- /dev/null +++ b/helm/vectis-overlays/templates/s3-monitor-crossplane.yaml @@ -0,0 +1,75 @@ +{{- $global := .Values.global | default dict }} +{{- $crossplane := get $global "crossplane" | default dict }} +{{- $crossplaneEnabled := get $crossplane "enabled" | default false }} +{{- if and .Values.s3Monitor.enabled .Values.s3Monitor.serviceAccount.create $crossplaneEnabled }} +apiVersion: iam.aws.crossplane.io/v1beta1 +kind: Role +metadata: + name: "{{ get $global "environment" }}-{{ .Release.Namespace }}-{{ .Values.s3Monitor.serviceAccount.name }}" +spec: + providerConfigRef: + name: {{ get $crossplane "providerConfigName" | default "provider-aws" }} + forProvider: + name: "{{ get $global "environment" }}-{{ .Release.Namespace }}-{{ .Values.s3Monitor.serviceAccount.name }}" + description: "IRSA role for s3-monitor in {{ .Release.Namespace }}" + assumeRolePolicyDocument: | + { + "Version":"2012-10-17", + "Statement":[ + { + "Effect":"Allow", + "Principal":{"Federated":"arn:aws:iam::{{ get $crossplane "accountId" }}:oidc-provider/{{ get $crossplane "oidcProviderUrl" }}"}, + "Action":"sts:AssumeRoleWithWebIdentity", + "Condition":{ + "StringEquals":{ + "{{ get $crossplane "oidcProviderUrl" }}:sub":"system:serviceaccount:{{ .Release.Namespace }}:{{ .Values.s3Monitor.serviceAccount.name }}", + "{{ get $crossplane "oidcProviderUrl" }}:aud":"sts.amazonaws.com" + } + } + } + ] + } +--- +apiVersion: iam.aws.crossplane.io/v1beta1 +kind: Policy +metadata: + name: "{{ get $global "environment" }}-{{ .Release.Namespace }}-s3-monitor-role-policy" +spec: + providerConfigRef: + name: {{ get $crossplane "providerConfigName" | default "provider-aws" }} + forProvider: + name: "{{ get $global "environment" }}-{{ .Release.Namespace }}-s3-monitor-role-policy" + document: | + { + "Version":"2012-10-17", + "Statement":[ + { + "Effect":"Allow", + "Action":["s3:ListBucket"], + "Resource":["arn:aws:s3:::{{ .Values.s3Monitor.s3.bucket }}"] + }, + { + "Effect":"Allow", + "Action":["s3:GetObject"], + "Resource":["arn:aws:s3:::{{ .Values.s3Monitor.s3.bucket }}/*"] + }, + { + "Effect":"Allow", + "Action":["secretsmanager:DescribeSecret","secretsmanager:GetSecretValue"], + "Resource":["arn:aws:secretsmanager:*:{{ get $crossplane "accountId" }}:secret:{{ .Values.s3Monitor.db.secretName }}*"] + } + ] + } +--- +apiVersion: iam.aws.crossplane.io/v1beta1 +kind: RolePolicyAttachment +metadata: + name: "{{ .Values.s3Monitor.serviceAccount.name }}-{{ .Release.Namespace }}-managed-policy-attachment" +spec: + providerConfigRef: + name: {{ get $crossplane "providerConfigName" | default "provider-aws" }} + forProvider: + roleName: "{{ get $global "environment" }}-{{ .Release.Namespace }}-{{ .Values.s3Monitor.serviceAccount.name }}" + policyArnRef: + name: "{{ get $global "environment" }}-{{ .Release.Namespace }}-s3-monitor-role-policy" +{{- end }} diff --git a/helm/vectis-overlays/templates/s3-monitor-secret.yaml b/helm/vectis-overlays/templates/s3-monitor-secret.yaml new file mode 100644 index 000000000..b7a3ba5e7 --- /dev/null +++ b/helm/vectis-overlays/templates/s3-monitor-secret.yaml @@ -0,0 +1,38 @@ +{{- if .Values.s3Monitor.enabled }} +apiVersion: external-secrets.io/v1beta1 +kind: ExternalSecret +metadata: + name: {{ .Values.s3Monitor.db.secretTargetName }} + namespace: {{ .Release.Namespace }} + annotations: + argocd.argoproj.io/sync-wave: "-1" +spec: + refreshInterval: 1h + secretStoreRef: + {{- if ne .Values.global.externalSecrets.clusterSecretStoreRef "" }} + name: {{ .Values.global.externalSecrets.clusterSecretStoreRef }} + kind: ClusterSecretStore + {{- else }} + name: {{include "common.SecretStore" .}} + kind: SecretStore + {{- end }} + target: + name: {{ .Values.s3Monitor.db.secretTargetName }} + creationPolicy: Owner + template: + data: + PGHOST: {{ .Values.s3Monitor.db.host | quote }} + PGPORT: {{ .Values.s3Monitor.db.port | quote }} + PGDATABASE: {{ .Values.s3Monitor.db.database | quote }} + PGUSER: "{{ `{{.username}}` }}" + PGPASSWORD: "{{ `{{.password}}` }}" + data: + - secretKey: username + remoteRef: + key: {{ .Values.s3Monitor.db.secretName }} + property: username + - secretKey: password + remoteRef: + key: {{ .Values.s3Monitor.db.secretName }} + property: password +{{- end }} diff --git a/helm/vectis-overlays/templates/service-accounts.yaml b/helm/vectis-overlays/templates/service-accounts.yaml index 3c7c3714e..b741494f2 100644 --- a/helm/vectis-overlays/templates/service-accounts.yaml +++ b/helm/vectis-overlays/templates/service-accounts.yaml @@ -46,3 +46,20 @@ metadata: {{- end }} {{- end }} {{- end }} +{{- if and .Values.s3Monitor.enabled .Values.s3Monitor.serviceAccount.create }} +--- +apiVersion: v1 +kind: ServiceAccount +metadata: + name: {{ .Values.s3Monitor.serviceAccount.name }} + namespace: {{ .Release.Namespace }} + {{- if $crossplaneEnabled }} + annotations: + eks.amazonaws.com/role-arn: arn:aws:iam::{{ get $crossplane "accountId" }}:role/{{ get $global "environment" }}-{{ .Release.Namespace }}-{{ .Values.s3Monitor.serviceAccount.name }} + {{- else }} + {{- with .Values.s3Monitor.serviceAccount.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} + {{- end }} +{{- end }} diff --git a/helm/vectis-overlays/values.yaml b/helm/vectis-overlays/values.yaml index 0b57636df..3e407319a 100644 --- a/helm/vectis-overlays/values.yaml +++ b/helm/vectis-overlays/values.yaml @@ -1,6 +1,12 @@ # vectis-overlays default values. # All service-internal URLs use .Release.Namespace so the chart is env-agnostic. # Override image tags per-environment in gitops values. +#Adding global value + + +global: + externalSecrets: + clusterSecretStoreRef: "" guppyCompat: enabled: false @@ -100,6 +106,44 @@ searchAuthProxy: # Falls back to rds.secretName for backward compatibility. appDsnSecretName: "" +s3Monitor: + enabled: false + schedule: "*/5 * * * *" + successfulJobsHistoryLimit: 3 + failedJobsHistoryLimit: 1 + serviceAccount: + create: true + name: s3-monitor-sa + annotations: {} + image: + repository: python + tag: "3.11-slim" + pullPolicy: IfNotPresent + initImage: + repository: busybox + tag: "1.36" + pullPolicy: IfNotPresent + resources: + requests: + cpu: "50m" + memory: "128Mi" + limits: + cpu: "500m" + memory: "512Mi" + aws: + region: "us-east-1" + s3: + bucket: "" + prefix: "" + db: + schema: "vectis" + table: "s3_metadata" + secretName: "" + secretTargetName: "s3-monitor-db-creds" + host: "" + port: "5432" + database: "postgres" + # CDK RDS secret in Secrets Manager — used to build the postgres DSN ExternalSecret. # Set per-environment in gitops values. rds: From aa35f8c56a50aa34a798d2ce00b3c473bc5a325a Mon Sep 17 00:00:00 2001 From: sowmyag96 <“{sowmyag@uchicago.edu}”> Date: Tue, 16 Jun 2026 12:08:24 -0400 Subject: [PATCH 046/196] Adding s3 monitor code --- helm/vectis-overlays/Chart.yaml | 2 +- helm/vectis-overlays/README.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/helm/vectis-overlays/Chart.yaml b/helm/vectis-overlays/Chart.yaml index b7e1c2b98..ed5a58b4a 100644 --- a/helm/vectis-overlays/Chart.yaml +++ b/helm/vectis-overlays/Chart.yaml @@ -7,5 +7,5 @@ appVersion: "1.0" dependencies: - name: common - version: 0.1.34 + version: 0.1.36 repository: file://../common diff --git a/helm/vectis-overlays/README.md b/helm/vectis-overlays/README.md index 4f6d57515..af259b446 100644 --- a/helm/vectis-overlays/README.md +++ b/helm/vectis-overlays/README.md @@ -8,7 +8,7 @@ Vectis overlay API services (guppy-compat, siem, search-auth-proxy) | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.34 | +| file://../common | common | 0.1.36 | ## Values From 3d16f75a186e42fafaae41b549ecd62cdc547b94 Mon Sep 17 00:00:00 2001 From: sowmyag96 <“{sowmyag@uchicago.edu}”> Date: Tue, 16 Jun 2026 12:51:32 -0400 Subject: [PATCH 047/196] Adding jeg file --- helm/jeg/Chart.yaml | 2 +- helm/jeg/README.md | 37 ++++++++++++++++++++++++++++++++++ helm/vectis-overlays/README.md | 1 - helm/workspace-proxy/README.md | 30 +++++++++++++++++++++++++++ 4 files changed, 68 insertions(+), 2 deletions(-) create mode 100644 helm/jeg/README.md create mode 100644 helm/workspace-proxy/README.md diff --git a/helm/jeg/Chart.yaml b/helm/jeg/Chart.yaml index 0c3eb6703..e4f035160 100644 --- a/helm/jeg/Chart.yaml +++ b/helm/jeg/Chart.yaml @@ -10,5 +10,5 @@ appVersion: "3.2.3" dependencies: - name: common - version: 0.1.34 + version: 0.1.36 repository: file://../common diff --git a/helm/jeg/README.md b/helm/jeg/README.md new file mode 100644 index 000000000..d115af6a7 --- /dev/null +++ b/helm/jeg/README.md @@ -0,0 +1,37 @@ +# jeg + +![Version: 0.1.0](https://img.shields.io/badge/Version-0.1.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 3.2.3](https://img.shields.io/badge/AppVersion-3.2.3-informational?style=flat-square) + +Jupyter Enterprise Gateway for gen3 vectis workspaces. Launches ephemeral kernel pods in the workspace namespace on behalf of user Jupyter sessions proxied through workspace-proxy. + +## Requirements + +| Repository | Name | Version | +|------------|------|---------| +| file://../common | common | 0.1.36 | + +## Values + +| Key | Type | Default | Description | +|-----|------|---------|-------------| +| env.EG_AUTH_TOKEN | string | `""` | | +| env.EG_CULL_CONNECTED | string | `"True"` | | +| env.EG_CULL_IDLE_TIMEOUT | string | `"14400"` | | +| env.EG_DEFAULT_KERNEL_NAME | string | `"python3"` | | +| env.EG_KERNEL_IMAGE_PULL_POLICY | string | `"IfNotPresent"` | | +| env.EG_KERNEL_LAUNCH_TIMEOUT | string | `"120"` | | +| env.EG_KERNEL_WHITELIST_ENVS | string | `"ACCESS_TOKEN"` | | +| env.EG_LIST_KERNELS | string | `"True"` | | +| env.EG_MAX_KERNELS_PER_USER | string | `"2"` | | +| env.EG_MIRROR_WORKING_DIRS | string | `"False"` | | +| env.EG_NAMESPACE | string | `"jupyter-pods"` | | +| env.EG_SHARED_NAMESPACE | string | `"False"` | | +| image.pullPolicy | string | `"Always"` | | +| image.repository | string | `"quay.io/cdis/gen3-vectis"` | | +| image.tag | string | `"qa-jeg"` | | +| replicaCount | int | `1` | | +| resources.limits.cpu | string | `"500m"` | | +| resources.limits.memory | string | `"512Mi"` | | +| resources.requests.cpu | string | `"100m"` | | +| resources.requests.memory | string | `"256Mi"` | | +| workspaceNamespace | string | `"jupyter-pods"` | | diff --git a/helm/vectis-overlays/README.md b/helm/vectis-overlays/README.md index af259b446..2c8d30169 100644 --- a/helm/vectis-overlays/README.md +++ b/helm/vectis-overlays/README.md @@ -14,7 +14,6 @@ Vectis overlay API services (guppy-compat, siem, search-auth-proxy) | Key | Type | Default | Description | |-----|------|---------|-------------| -| global.externalSecrets.clusterSecretStoreRef | string | `""` | | | guppyCompat.enabled | bool | `false` | | | guppyCompat.env.GUPPY_COMPAT_MAX_LIMIT | string | `"5000"` | | | guppyCompat.image.pullPolicy | string | `"Always"` | | diff --git a/helm/workspace-proxy/README.md b/helm/workspace-proxy/README.md new file mode 100644 index 000000000..d4d2fb9ab --- /dev/null +++ b/helm/workspace-proxy/README.md @@ -0,0 +1,30 @@ +# workspace-proxy + +![Version: 0.1.0](https://img.shields.io/badge/Version-0.1.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.0](https://img.shields.io/badge/AppVersion-1.0-informational?style=flat-square) + +Per-user workspace HTTP/WebSocket router for gen3 vectis. Replaces Emissary/Ambassador. Reads Service annotations written by Hatchery to resolve each user's workspace upstream, then proxies traffic from revproxy. + +## Requirements + +| Repository | Name | Version | +|------------|------|---------| +| file://../common | common | 0.1.34 | + +## Values + +| Key | Type | Default | Description | +|-----|------|---------|-------------| +| deploymentNamespace | string | `""` | | +| image.pullPolicy | string | `"Always"` | | +| image.repository | string | `"quay.io/cdis/gen3-vectis"` | | +| image.tag | string | `"qa-goproxy"` | | +| jegKernelSpecPolicy | string | `""` | | +| kubernetesApiServerCIDRs | list | `[]` | | +| listenAddr | string | `":8080"` | | +| networkPolicy.enabled | bool | `true` | | +| replicaCount | int | `2` | | +| resources.limits.cpu | string | `"500m"` | | +| resources.limits.memory | string | `"256Mi"` | | +| resources.requests.cpu | string | `"50m"` | | +| resources.requests.memory | string | `"64Mi"` | | +| workspaceNamespace | string | `""` | | From a354f63f5b75d9758a099f42765bf78adcb3ae30 Mon Sep 17 00:00:00 2001 From: sowmyag96 <“{sowmyag@uchicago.edu}”> Date: Tue, 16 Jun 2026 13:01:03 -0400 Subject: [PATCH 048/196] Adding jeg file --- helm/workspace-proxy/Chart.yaml | 2 +- helm/workspace-proxy/README.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/helm/workspace-proxy/Chart.yaml b/helm/workspace-proxy/Chart.yaml index 2736f76b2..03a81e0ce 100644 --- a/helm/workspace-proxy/Chart.yaml +++ b/helm/workspace-proxy/Chart.yaml @@ -10,5 +10,5 @@ appVersion: "1.0" dependencies: - name: common - version: 0.1.34 + version: 0.1.36 repository: file://../common diff --git a/helm/workspace-proxy/README.md b/helm/workspace-proxy/README.md index d4d2fb9ab..7ae58255a 100644 --- a/helm/workspace-proxy/README.md +++ b/helm/workspace-proxy/README.md @@ -8,7 +8,7 @@ Per-user workspace HTTP/WebSocket router for gen3 vectis. Replaces Emissary/Amba | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.34 | +| file://../common | common | 0.1.36 | ## Values From 7d3d2c5a51df41b52c026a24be7c611d4a25042f Mon Sep 17 00:00:00 2001 From: cmalson Date: Tue, 16 Jun 2026 10:33:40 -0700 Subject: [PATCH 049/196] fix(charts): align common deps and bump chart versions for ct --- helm/jeg/Chart.yaml | 2 +- helm/jeg/README.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/helm/jeg/Chart.yaml b/helm/jeg/Chart.yaml index e4f035160..0c3eb6703 100644 --- a/helm/jeg/Chart.yaml +++ b/helm/jeg/Chart.yaml @@ -10,5 +10,5 @@ appVersion: "3.2.3" dependencies: - name: common - version: 0.1.36 + version: 0.1.34 repository: file://../common diff --git a/helm/jeg/README.md b/helm/jeg/README.md index d115af6a7..b3edbd8c7 100644 --- a/helm/jeg/README.md +++ b/helm/jeg/README.md @@ -8,7 +8,7 @@ Jupyter Enterprise Gateway for gen3 vectis workspaces. Launches ephemeral kernel | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.36 | +| file://../common | common | 0.1.34 | ## Values From 923bae9885854ef8624f7f5ff3c3ac126ab8d5ca Mon Sep 17 00:00:00 2001 From: cmalson Date: Tue, 16 Jun 2026 10:36:08 -0700 Subject: [PATCH 050/196] fix(gen3): align funnel and revproxy dependency versions --- helm/gen3/Chart.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index 4d52acc9a..50d2e9f8b 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -116,7 +116,7 @@ dependencies: repository: "file://../requestor" condition: requestor.enabled - name: revproxy - version: 0.1.61 + version: 0.1.62 repository: "file://../revproxy" condition: revproxy.enabled - name: sheepdog From b80e0f0cc94b71fc9ef612f548ce88934d288643 Mon Sep 17 00:00:00 2001 From: cmalson Date: Tue, 16 Jun 2026 10:38:16 -0700 Subject: [PATCH 051/196] fix(vectis-overlays): align common dependency version --- helm/vectis-overlays/Chart.yaml | 2 +- helm/vectis-overlays/README.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/helm/vectis-overlays/Chart.yaml b/helm/vectis-overlays/Chart.yaml index ed5a58b4a..b7e1c2b98 100644 --- a/helm/vectis-overlays/Chart.yaml +++ b/helm/vectis-overlays/Chart.yaml @@ -7,5 +7,5 @@ appVersion: "1.0" dependencies: - name: common - version: 0.1.36 + version: 0.1.34 repository: file://../common diff --git a/helm/vectis-overlays/README.md b/helm/vectis-overlays/README.md index 2c8d30169..c69b57515 100644 --- a/helm/vectis-overlays/README.md +++ b/helm/vectis-overlays/README.md @@ -8,7 +8,7 @@ Vectis overlay API services (guppy-compat, siem, search-auth-proxy) | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.36 | +| file://../common | common | 0.1.34 | ## Values From f4cd1471cb25ce7d363ce5fd1661eb6a0712ea5c Mon Sep 17 00:00:00 2001 From: cmalson Date: Tue, 16 Jun 2026 10:41:22 -0700 Subject: [PATCH 052/196] fix(workspace-proxy): align common dependency version --- helm/workspace-proxy/Chart.yaml | 2 +- helm/workspace-proxy/README.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/helm/workspace-proxy/Chart.yaml b/helm/workspace-proxy/Chart.yaml index 03a81e0ce..2736f76b2 100644 --- a/helm/workspace-proxy/Chart.yaml +++ b/helm/workspace-proxy/Chart.yaml @@ -10,5 +10,5 @@ appVersion: "1.0" dependencies: - name: common - version: 0.1.36 + version: 0.1.34 repository: file://../common diff --git a/helm/workspace-proxy/README.md b/helm/workspace-proxy/README.md index 7ae58255a..d4d2fb9ab 100644 --- a/helm/workspace-proxy/README.md +++ b/helm/workspace-proxy/README.md @@ -8,7 +8,7 @@ Per-user workspace HTTP/WebSocket router for gen3 vectis. Replaces Emissary/Amba | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.36 | +| file://../common | common | 0.1.34 | ## Values From 0cef349eb1c4f2cb890f6ebe68589b9196425710 Mon Sep 17 00:00:00 2001 From: cmalson Date: Tue, 16 Jun 2026 10:53:47 -0700 Subject: [PATCH 053/196] ci(ct): set target-branch to feat_vectis for PR linting --- .github/ct.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/ct.yaml b/.github/ct.yaml index 2222586db..0658df013 100644 --- a/.github/ct.yaml +++ b/.github/ct.yaml @@ -1,5 +1,5 @@ remote: origin -target-branch: master +target-branch: feat_vectis chart-dirs: - helm chart-repos: From d4de7096dfef67352be3fa479f12fe6200d11f62 Mon Sep 17 00:00:00 2001 From: cmalson Date: Tue, 16 Jun 2026 10:58:42 -0700 Subject: [PATCH 054/196] fix(charts): bump jeg/vectis-overlays/workspace-proxy versions for ct --- helm/gen3/Chart.yaml | 6 +++--- helm/jeg/Chart.yaml | 2 +- helm/vectis-overlays/Chart.yaml | 2 +- helm/workspace-proxy/Chart.yaml | 2 +- 4 files changed, 6 insertions(+), 6 deletions(-) diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index 50d2e9f8b..552ce12ed 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -183,15 +183,15 @@ dependencies: repository: "file://../neuvector" condition: neuvector.enabled - name: jeg - version: 0.1.0 + version: 0.1.1 repository: "file://../jeg" condition: jeg.enabled - name: workspace-proxy - version: 0.1.0 + version: 0.1.1 repository: "file://../workspace-proxy" condition: workspace-proxy.enabled - name: vectis-overlays - version: 0.1.0 + version: 0.1.1 repository: "file://../vectis-overlays" condition: vectis-overlays.enabled diff --git a/helm/jeg/Chart.yaml b/helm/jeg/Chart.yaml index 0c3eb6703..5d2563597 100644 --- a/helm/jeg/Chart.yaml +++ b/helm/jeg/Chart.yaml @@ -5,7 +5,7 @@ description: > Launches ephemeral kernel pods in the workspace namespace on behalf of user Jupyter sessions proxied through workspace-proxy. type: application -version: 0.1.0 +version: 0.1.1 appVersion: "3.2.3" dependencies: diff --git a/helm/vectis-overlays/Chart.yaml b/helm/vectis-overlays/Chart.yaml index b7e1c2b98..c994590eb 100644 --- a/helm/vectis-overlays/Chart.yaml +++ b/helm/vectis-overlays/Chart.yaml @@ -2,7 +2,7 @@ apiVersion: v2 name: vectis-overlays description: Vectis overlay API services (guppy-compat, siem, search-auth-proxy) type: application -version: 0.1.0 +version: 0.1.1 appVersion: "1.0" dependencies: diff --git a/helm/workspace-proxy/Chart.yaml b/helm/workspace-proxy/Chart.yaml index 2736f76b2..4fba13e98 100644 --- a/helm/workspace-proxy/Chart.yaml +++ b/helm/workspace-proxy/Chart.yaml @@ -5,7 +5,7 @@ description: > Replaces Emissary/Ambassador. Reads Service annotations written by Hatchery to resolve each user's workspace upstream, then proxies traffic from revproxy. type: application -version: 0.1.0 +version: 0.1.1 appVersion: "1.0" dependencies: From 336336bc1d93f88dbcd86276098d578d3b02b8ba Mon Sep 17 00:00:00 2001 From: cmalson Date: Tue, 16 Jun 2026 11:15:53 -0700 Subject: [PATCH 055/196] chore(vectis-overlays): fix yaml comment spacing --- helm/vectis-overlays/values.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/helm/vectis-overlays/values.yaml b/helm/vectis-overlays/values.yaml index 3e407319a..6cab6e769 100644 --- a/helm/vectis-overlays/values.yaml +++ b/helm/vectis-overlays/values.yaml @@ -1,7 +1,7 @@ # vectis-overlays default values. # All service-internal URLs use .Release.Namespace so the chart is env-agnostic. # Override image tags per-environment in gitops values. -#Adding global value +# Adding global value global: From 64f51849fd233766080233b2176c8ad97d135e70 Mon Sep 17 00:00:00 2001 From: Andrew Prokhorenkov Date: Mon, 6 Jul 2026 11:26:54 -0500 Subject: [PATCH 056/196] change target branch in ct.yaml --- .github/ct.yaml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/ct.yaml b/.github/ct.yaml index 0658df013..750c0c982 100644 --- a/.github/ct.yaml +++ b/.github/ct.yaml @@ -1,5 +1,5 @@ remote: origin -target-branch: feat_vectis +target-branch: feat/vectis-merge chart-dirs: - helm chart-repos: @@ -11,4 +11,4 @@ helm-extra-args: --timeout 600s check-version-increment: true debug: false validate-maintainers: false -helm-dependency-extra-args: "--skip-refresh" \ No newline at end of file +helm-dependency-extra-args: "--skip-refresh" From bef96dc356c6023a5fb6c1c3860a3758ac846d95 Mon Sep 17 00:00:00 2001 From: Mingfei Shao Date: Mon, 6 Jul 2026 13:42:04 -0500 Subject: [PATCH 057/196] put email in secret --- helm/gen3/README.md | 3 ++- helm/zendesk-wrapper/README.md | 10 ++++++---- helm/zendesk-wrapper/templates/deployment.yaml | 5 ++++- helm/zendesk-wrapper/values.yaml | 4 +++- 4 files changed, 15 insertions(+), 7 deletions(-) diff --git a/helm/gen3/README.md b/helm/gen3/README.md index c79eb376c..5e0624739 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -54,7 +54,7 @@ Helm chart to deploy Gen3 Data Commons | file://../peregrine | peregrine | 0.1.42 | | file://../portal | portal | 0.1.60 | | file://../requestor | requestor | 0.1.34 | -| file://../revproxy | revproxy | 0.1.61 | +| file://../revproxy | revproxy | 0.1.62 | | file://../sheepdog | sheepdog | 0.1.42 | | file://../sower | sower | 0.1.46 | | file://../ssjdispatcher | ssjdispatcher | 0.1.47 | @@ -269,3 +269,4 @@ Helm chart to deploy Gen3 Data Commons | tests.SERVICE_TO_TEST | str | `nil` | Name of the service we are testing. Default is empty as GH workflow automatically sets this. | | tests.TEST_LABEL | str | `nil` | Name of the test that will run. Default is empty as GH workflow automatically sets this. | | wts.enabled | bool | `true` | Whether to deploy the wts subchart. | +| zendesk-wrapper.enabled | bool | `false` | Whether to deploy the zendesk-wrapper subchart. | diff --git a/helm/zendesk-wrapper/README.md b/helm/zendesk-wrapper/README.md index 7b8f1d167..8e16d0e69 100644 --- a/helm/zendesk-wrapper/README.md +++ b/helm/zendesk-wrapper/README.md @@ -25,6 +25,10 @@ A Helm chart for gen3 Zendesk Wrapper Service | env | map | `{"GEN3_ZENDESK_URL":"","ZENDESK_API_EMAIL":""}` | Environment variables for the Zendesk wrapper service | | env.GEN3_ZENDESK_URL | string | `""` | Zendesk instance URL (e.g., https://gen3support.zendesk.com) | | env.ZENDESK_API_EMAIL | string | `""` | Email of the agent account used with the API token | +| externalSecrets | map | `{"apiEmail":"ZENDESK_API_EMAIL","name":"zendesk-wrapper-secret","tokenKey":"ZENDESK_API_TOKEN"}` | Secret environment variables (referenced from Kubernetes secrets) | +| externalSecrets.apiEmail | string | `"ZENDESK_API_EMAIL"` | Email of the agent account used with the API token | +| externalSecrets.name | string | `"zendesk-wrapper-secret"` | Name of the Kubernetes secret containing the Zendesk API token | +| externalSecrets.tokenKey | string | `"ZENDESK_API_TOKEN"` | Key within the secret for the API token | | global.autoscaling.averageCPUValue | string | `"500m"` | | | global.autoscaling.averageMemoryValue | string | `"500Mi"` | | | global.autoscaling.enabled | bool | `false` | | @@ -50,11 +54,9 @@ A Helm chart for gen3 Zendesk Wrapper Service | replicaCount | int | `1` | | | resources.limits.memory | string | `"128Mi"` | | | revisionHistoryLimit | int | `2` | | -| secrets | map | `{"name":"zendesk-wrapper-secret","tokenKey":"ZENDESK_API_TOKEN"}` | Secret environment variables (referenced from Kubernetes secrets) | -| secrets.name | string | `"zendesk-wrapper-secret"` | Name of the Kubernetes secret containing the Zendesk API token | -| secrets.tokenKey | string | `"ZENDESK_API_TOKEN"` | Key within the secret for the API token | | selectorLabels | string | `nil` | | -| service.port | int | `8000` | | +| service.port | int | `80` | | +| service.targetPort | int | `8000` | | | service.type | string | `"ClusterIP"` | | | strategy.rollingUpdate.maxSurge | int | `1` | | | strategy.rollingUpdate.maxUnavailable | int | `0` | | diff --git a/helm/zendesk-wrapper/templates/deployment.yaml b/helm/zendesk-wrapper/templates/deployment.yaml index 8ea246b84..063cf696b 100644 --- a/helm/zendesk-wrapper/templates/deployment.yaml +++ b/helm/zendesk-wrapper/templates/deployment.yaml @@ -55,7 +55,10 @@ spec: - name: GEN3_ZENDESK_URL value: {{ .Values.env.GEN3_ZENDESK_URL | quote }} - name: ZENDESK_API_EMAIL - value: {{ .Values.env.ZENDESK_API_EMAIL | quote }} + valueFrom: + secretKeyRef: + name: {{ .Values.secrets.name }} + key: {{ .Values.secrets.apiEmail }} - name: ZENDESK_API_TOKEN valueFrom: secretKeyRef: diff --git a/helm/zendesk-wrapper/values.yaml b/helm/zendesk-wrapper/values.yaml index db8f264f1..c63db42bc 100644 --- a/helm/zendesk-wrapper/values.yaml +++ b/helm/zendesk-wrapper/values.yaml @@ -75,11 +75,13 @@ env: ZENDESK_API_EMAIL: "" # -- (map) Secret environment variables (referenced from Kubernetes secrets) -secrets: +externalSecrets: # -- (string) Name of the Kubernetes secret containing the Zendesk API token name: "zendesk-wrapper-secret" # -- (string) Key within the secret for the API token tokenKey: "ZENDESK_API_TOKEN" + # -- (string) Email of the agent account used with the API token + apiEmail: "ZENDESK_API_EMAIL" release: "production" criticalService: "false" From 9a031bd30c683fd4b150b2ee2ea46d007345d15c Mon Sep 17 00:00:00 2001 From: Mingfei Shao Date: Mon, 6 Jul 2026 13:55:32 -0500 Subject: [PATCH 058/196] remove env --- helm/zendesk-wrapper/README.md | 3 +-- helm/zendesk-wrapper/values.yaml | 2 -- 2 files changed, 1 insertion(+), 4 deletions(-) diff --git a/helm/zendesk-wrapper/README.md b/helm/zendesk-wrapper/README.md index 8e16d0e69..6dfbd9624 100644 --- a/helm/zendesk-wrapper/README.md +++ b/helm/zendesk-wrapper/README.md @@ -22,9 +22,8 @@ A Helm chart for gen3 Zendesk Wrapper Service | autoscaling | object | `{}` | | | commonLabels | string | `nil` | | | criticalService | string | `"false"` | | -| env | map | `{"GEN3_ZENDESK_URL":"","ZENDESK_API_EMAIL":""}` | Environment variables for the Zendesk wrapper service | +| env | map | `{"GEN3_ZENDESK_URL":""}` | Environment variables for the Zendesk wrapper service | | env.GEN3_ZENDESK_URL | string | `""` | Zendesk instance URL (e.g., https://gen3support.zendesk.com) | -| env.ZENDESK_API_EMAIL | string | `""` | Email of the agent account used with the API token | | externalSecrets | map | `{"apiEmail":"ZENDESK_API_EMAIL","name":"zendesk-wrapper-secret","tokenKey":"ZENDESK_API_TOKEN"}` | Secret environment variables (referenced from Kubernetes secrets) | | externalSecrets.apiEmail | string | `"ZENDESK_API_EMAIL"` | Email of the agent account used with the API token | | externalSecrets.name | string | `"zendesk-wrapper-secret"` | Name of the Kubernetes secret containing the Zendesk API token | diff --git a/helm/zendesk-wrapper/values.yaml b/helm/zendesk-wrapper/values.yaml index c63db42bc..7748f27ac 100644 --- a/helm/zendesk-wrapper/values.yaml +++ b/helm/zendesk-wrapper/values.yaml @@ -71,8 +71,6 @@ netPolicy: env: # -- (string) Zendesk instance URL (e.g., https://gen3support.zendesk.com) GEN3_ZENDESK_URL: "" - # -- (string) Email of the agent account used with the API token - ZENDESK_API_EMAIL: "" # -- (map) Secret environment variables (referenced from Kubernetes secrets) externalSecrets: From df197a915b6a5e706b132998cca09b94ec06fefb Mon Sep 17 00:00:00 2001 From: Mingfei Shao Date: Mon, 6 Jul 2026 16:02:13 -0500 Subject: [PATCH 059/196] update env --- helm/zendesk-wrapper/templates/deployment.yaml | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/helm/zendesk-wrapper/templates/deployment.yaml b/helm/zendesk-wrapper/templates/deployment.yaml index 063cf696b..af86abae3 100644 --- a/helm/zendesk-wrapper/templates/deployment.yaml +++ b/helm/zendesk-wrapper/templates/deployment.yaml @@ -52,8 +52,7 @@ spec: resources: {{- toYaml .Values.resources | nindent 12 }} env: - - name: GEN3_ZENDESK_URL - value: {{ .Values.env.GEN3_ZENDESK_URL | quote }} + {{- toYaml .Values.env | nindent 12 }} - name: ZENDESK_API_EMAIL valueFrom: secretKeyRef: From 1c8d8b26b2edeae1a1cf558eb90ccf4117cda350 Mon Sep 17 00:00:00 2001 From: matthewpeterkort Date: Mon, 6 Jul 2026 15:00:15 -0700 Subject: [PATCH 060/196] integrate funnel helm chart --- helm/funnel/Chart.yaml | 10 - helm/funnel/README.md | 330 ++++--- helm/funnel/charts/funnel-0.1.99-rc.36.tgz | Bin 146409 -> 0 bytes helm/funnel/files/executor-job.yaml | 144 ++++ helm/funnel/files/role.yaml | 39 + helm/funnel/files/rolebinding.yaml | 16 + helm/funnel/files/server-config.yaml | 198 +++++ helm/funnel/files/serviceaccount.yaml | 18 + helm/funnel/files/worker-job.yaml | 117 +++ helm/funnel/files/worker-pv.yaml | 31 + helm/funnel/files/worker-pvc.yaml | 17 + helm/funnel/templates/_helpers.tpl | 45 +- helm/funnel/templates/clusterrole.yaml | 65 ++ helm/funnel/templates/clusterrolebinding.yaml | 19 + helm/funnel/templates/cronjob.yaml | 45 + helm/funnel/templates/job-resources.yaml | 0 helm/funnel/templates/plugin-server.yaml | 66 ++ helm/funnel/templates/server-configmap.yaml | 15 + helm/funnel/templates/server-deployment.yaml | 96 +++ helm/funnel/templates/service.yaml | 18 + helm/funnel/templates/serviceaccount.yaml | 22 + .../templates/tests/test-connection.yaml | 15 + helm/funnel/templates/worker-configmap.yaml | 22 + helm/funnel/values.yaml | 803 ++++++++++++------ 24 files changed, 1749 insertions(+), 402 deletions(-) delete mode 100644 helm/funnel/charts/funnel-0.1.99-rc.36.tgz create mode 100644 helm/funnel/files/executor-job.yaml create mode 100644 helm/funnel/files/role.yaml create mode 100644 helm/funnel/files/rolebinding.yaml create mode 100644 helm/funnel/files/server-config.yaml create mode 100644 helm/funnel/files/serviceaccount.yaml create mode 100644 helm/funnel/files/worker-job.yaml create mode 100644 helm/funnel/files/worker-pv.yaml create mode 100644 helm/funnel/files/worker-pvc.yaml create mode 100644 helm/funnel/templates/clusterrole.yaml create mode 100644 helm/funnel/templates/clusterrolebinding.yaml create mode 100644 helm/funnel/templates/cronjob.yaml create mode 100644 helm/funnel/templates/job-resources.yaml create mode 100644 helm/funnel/templates/plugin-server.yaml create mode 100644 helm/funnel/templates/server-configmap.yaml create mode 100644 helm/funnel/templates/server-deployment.yaml create mode 100644 helm/funnel/templates/service.yaml create mode 100644 helm/funnel/templates/serviceaccount.yaml create mode 100644 helm/funnel/templates/tests/test-connection.yaml create mode 100644 helm/funnel/templates/worker-configmap.yaml diff --git a/helm/funnel/Chart.yaml b/helm/funnel/Chart.yaml index 8061230b7..92644a760 100644 --- a/helm/funnel/Chart.yaml +++ b/helm/funnel/Chart.yaml @@ -26,13 +26,3 @@ dependencies: - name: common version: 0.1.36 repository: file://../common - - name: funnel - # NOTE: - # When updating this version: - # 1) Run `helm dependency update` in this directory to generate a new .tgz file - # 2) Commit the updated .tgz file into gen3-helm in the same PR - # - # ArgoCD relies on this checked-in .tgz reference — if it's missing, - # Funnel will not be deployed as a dependency. - version: 0.1.99-rc.36 - repository: "https://calypr.github.io/helm-charts" diff --git a/helm/funnel/README.md b/helm/funnel/README.md index 1f168fe79..60d05674e 100644 --- a/helm/funnel/README.md +++ b/helm/funnel/README.md @@ -4,124 +4,234 @@ A Helm chart for Kubernetes +Funnel is source-owned in `gen3-helm` and is wired into the Gen3 umbrella chart +as a local subchart through `file://../funnel`. + +## Database + +This chart is configured to use Gen3-managed PostgreSQL for Funnel task and +event storage. The previous bundled MongoDB dependency was removed because we +believe the MongoDB event writer is no longer used by this deployment path. + +The Helm render verifies the generated Funnel config points at PostgreSQL and no +MongoDB resources are created. A deployed-cluster smoke test is still required +to prove the Funnel server binary successfully connects to and migrates/uses the +PostgreSQL database in a real environment. + +Deployments that still need MongoDB event writing must reintroduce explicit +external MongoDB configuration. + +## Cleanup CronJob + +The optional cleanup CronJob runs: + +```bash +funnel kubernetes cleanup --config /etc/config/funnel-server.yaml +``` + +It is intentionally disabled by default. Enable it with: + +```yaml +cleanup: + enabled: true +``` + +When `cleanup.schedule` is empty, the chart derives the CronJob schedule from +`Kubernetes.ReconcileRate`. Set `cleanup.schedule` to a standard 5-field cron +expression to override it. + ## Requirements | Repository | Name | Version | |------------|------|---------| | file://../common | common | 0.1.36 | -| https://calypr.github.io/helm-charts | funnel | 0.1.99-rc.36 | ## Values | Key | Type | Default | Description | |-----|------|---------|-------------| -| criticalService | string | `"false"` | Valid options are "true" or "false". If invalid option is set- the value will default to "false". | -| externalSecrets | map | `{"createFunnelOidcClientSecret":true,"dbcreds":"","funnelOidcClient":null}` | External Secrets settings. | -| externalSecrets.createFunnelOidcClientSecret | bool | `true` | Whether to create the Funnel OIDC client secret using the oidc job. | -| externalSecrets.dbcreds | string | `""` | Name of the secret that will be created in secrets manager | -| externalSecrets.funnelOidcClient | string | `nil` | Will override the name of the aws secrets manager secret. Default is "funnel-oidc-client". | -| funnel.Database | string | `"postgres"` | | -| funnel.EventWriters[0] | string | `"postgres"` | | -| funnel.EventWriters[1] | string | `"log"` | | -| funnel.Kubernetes.Executor.Annotations."karpenter.sh/do-not-disrupt" | string | `"true"` | | -| funnel.Kubernetes.Executor.backoffLimit | int | `0` | | -| funnel.Kubernetes.Executor.restartPolicy | string | `"Never"` | | -| funnel.Kubernetes.ReconcileRate | string | `"120s"` | | -| funnel.Kubernetes.Timeout.duration | string | `"300s"` | | -| funnel.Kubernetes.Worker.Annotations."karpenter.sh/do-not-disrupt" | string | `"true"` | | -| funnel.Kubernetes.Worker.PriorityClassName | string | `"system-cluster-critical"` | | -| funnel.Kubernetes.Worker.backoffLimit | int | `1` | | -| funnel.Kubernetes.Worker.restartPolicy | string | `"Never"` | | -| funnel.Logger.Level | string | `"info"` | | -| funnel.Plugins.Params.OidcClientId | string | `"FUNNEL_PLUGIN_OIDC_CLIENT_ID_PLACEHOLDER"` | | -| funnel.Plugins.Params.OidcClientSecret | string | `"FUNNEL_PLUGIN_OIDC_CLIENT_SECRET_PLACEHOLDER"` | | -| funnel.Plugins.Params.S3Url | string | `"FUNNEL_PLUGIN_S3URL_PLACEHOLDER"` | | -| funnel.Plugins.Path | string | `"plugin-binaries/auth-plugin"` | | -| funnel.Postgres.Database | string | `"FUNNEL_POSTGRES_DATABASE_PLACEHOLDER"` | | -| funnel.Postgres.Host | string | `"FUNNEL_POSTGRES_HOST_PLACEHOLDER"` | | -| funnel.Postgres.Password | string | `"FUNNEL_POSTGRES_PASSWORD_PLACEHOLDER"` | | -| funnel.Postgres.User | string | `"FUNNEL_POSTGRES_USER_PLACEHOLDER"` | | -| funnel.Worker.LeaveWorkDir | bool | `true` | | -| funnel.image | map | `{"initContainers":[{"command":["cp","/app/build/plugins/authorizer","/opt/funnel/plugin-binaries/auth-plugin"],"image":"quay.io/cdis/funnel-gen3-plugin","name":"plugin","pullPolicy":"Always","tag":"main-gen3","volumeMounts":[{"mountPath":"/opt/funnel/plugin-binaries","name":"plugin-volume"}]},{"args":["-c","# Create a funnel-patched.conf since /etc/config/funnel.conf is readonly\nCONFIG=/tmp/funnel-patched.conf\ncp /etc/config/funnel.conf $CONFIG\n\nnamespace=$(cat /var/run/secrets/kubernetes.io/serviceaccount/namespace)\nJOBS_NAMESPACE=workflow-pods-$namespace\nS3_URL=gen3-workflow-service.$namespace.svc.cluster.local\nDB_HOST=$DB_HOST:5432\n\n# `Kubernetes.JobsNamespace` has to be configured manually because of templating\n# limitations. This ensures it is configured to the value that is hardcoded elsewhere.\nconfigured=$(yq -r '.Kubernetes.JobsNamespace' \"$CONFIG\")\nif [[ \"$configured\" != \"$JOBS_NAMESPACE\" ]]; then\n echo \"ERROR: funnel.Kubernetes.JobsNamespace is set to '$configured' instead of '$JOBS_NAMESPACE'. Please fix the configuration\" >&2\n exit 1\nfi\n\necho \"======= Funnel configuration =======\"\necho \" Kubernetes.JobsNamespace : $JOBS_NAMESPACE\"\necho \" Plugins.Params.OidcClientId: $FUNNEL_OIDC_CLIENT_ID\"\necho \" Plugins.Params.S3Url : $S3_URL\"\necho \" Postgres.Host : $DB_HOST\"\necho \" Postgres.Database : $DB_DATABASE\"\necho \" Postgres.User : $DB_USER\"\necho \"====================================\"\n\n# Replace placeholders with actual values (in-place)\nsed -i \"s|FUNNEL_PLUGIN_OIDC_CLIENT_ID_PLACEHOLDER|${FUNNEL_OIDC_CLIENT_ID}|g\" $CONFIG\nsed -i \"s|FUNNEL_PLUGIN_OIDC_CLIENT_SECRET_PLACEHOLDER|${FUNNEL_OIDC_CLIENT_SECRET}|g\" $CONFIG\nsed -i \"s|FUNNEL_PLUGIN_S3URL_PLACEHOLDER|${S3_URL}|g\" $CONFIG\nsed -i \"s/FUNNEL_POSTGRES_HOST_PLACEHOLDER/${DB_HOST}/g\" $CONFIG\nsed -i \"s/FUNNEL_POSTGRES_DATABASE_PLACEHOLDER/${DB_DATABASE}/g\" $CONFIG\nsed -i \"s/FUNNEL_POSTGRES_USER_PLACEHOLDER/${DB_USER}/g\" $CONFIG\nsed -i \"s/FUNNEL_POSTGRES_PASSWORD_PLACEHOLDER/${DB_PASSWORD}/g\" $CONFIG\n"],"command":["/bin/bash"],"env":[{"name":"FUNNEL_OIDC_CLIENT_ID","valueFrom":{"secretKeyRef":{"key":"client_id","name":"funnel-oidc-client","optional":false}}},{"name":"FUNNEL_OIDC_CLIENT_SECRET","valueFrom":{"secretKeyRef":{"key":"client_secret","name":"funnel-oidc-client","optional":false}}},{"name":"DB_HOST","valueFrom":{"secretKeyRef":{"key":"host","name":"funnel-dbcreds","optional":false}}},{"name":"DB_USER","valueFrom":{"secretKeyRef":{"key":"username","name":"funnel-dbcreds","optional":false}}},{"name":"DB_PASSWORD","valueFrom":{"secretKeyRef":{"key":"password","name":"funnel-dbcreds","optional":false}}},{"name":"DB_DATABASE","valueFrom":{"secretKeyRef":{"key":"database","name":"funnel-dbcreds","optional":false}}}],"image":"quay.io/cdis/awshelper","name":"config-updater","tag":"master","volumeMounts":[{"mountPath":"/tmp","name":"funnel-patched-config-volume"},{"mountPath":"/etc/config/funnel.conf","name":"funnel-config-volume","subPath":"funnel-server.yaml"}]}],"pullPolicy":"Always","repository":"quay.io/ohsu-comp-bio/funnel"}` | Configuration for the Funnel container image. | -| funnel.image.initContainers | map | `[{"command":["cp","/app/build/plugins/authorizer","/opt/funnel/plugin-binaries/auth-plugin"],"image":"quay.io/cdis/funnel-gen3-plugin","name":"plugin","pullPolicy":"Always","tag":"main-gen3","volumeMounts":[{"mountPath":"/opt/funnel/plugin-binaries","name":"plugin-volume"}]},{"args":["-c","# Create a funnel-patched.conf since /etc/config/funnel.conf is readonly\nCONFIG=/tmp/funnel-patched.conf\ncp /etc/config/funnel.conf $CONFIG\n\nnamespace=$(cat /var/run/secrets/kubernetes.io/serviceaccount/namespace)\nJOBS_NAMESPACE=workflow-pods-$namespace\nS3_URL=gen3-workflow-service.$namespace.svc.cluster.local\nDB_HOST=$DB_HOST:5432\n\n# `Kubernetes.JobsNamespace` has to be configured manually because of templating\n# limitations. This ensures it is configured to the value that is hardcoded elsewhere.\nconfigured=$(yq -r '.Kubernetes.JobsNamespace' \"$CONFIG\")\nif [[ \"$configured\" != \"$JOBS_NAMESPACE\" ]]; then\n echo \"ERROR: funnel.Kubernetes.JobsNamespace is set to '$configured' instead of '$JOBS_NAMESPACE'. Please fix the configuration\" >&2\n exit 1\nfi\n\necho \"======= Funnel configuration =======\"\necho \" Kubernetes.JobsNamespace : $JOBS_NAMESPACE\"\necho \" Plugins.Params.OidcClientId: $FUNNEL_OIDC_CLIENT_ID\"\necho \" Plugins.Params.S3Url : $S3_URL\"\necho \" Postgres.Host : $DB_HOST\"\necho \" Postgres.Database : $DB_DATABASE\"\necho \" Postgres.User : $DB_USER\"\necho \"====================================\"\n\n# Replace placeholders with actual values (in-place)\nsed -i \"s|FUNNEL_PLUGIN_OIDC_CLIENT_ID_PLACEHOLDER|${FUNNEL_OIDC_CLIENT_ID}|g\" $CONFIG\nsed -i \"s|FUNNEL_PLUGIN_OIDC_CLIENT_SECRET_PLACEHOLDER|${FUNNEL_OIDC_CLIENT_SECRET}|g\" $CONFIG\nsed -i \"s|FUNNEL_PLUGIN_S3URL_PLACEHOLDER|${S3_URL}|g\" $CONFIG\nsed -i \"s/FUNNEL_POSTGRES_HOST_PLACEHOLDER/${DB_HOST}/g\" $CONFIG\nsed -i \"s/FUNNEL_POSTGRES_DATABASE_PLACEHOLDER/${DB_DATABASE}/g\" $CONFIG\nsed -i \"s/FUNNEL_POSTGRES_USER_PLACEHOLDER/${DB_USER}/g\" $CONFIG\nsed -i \"s/FUNNEL_POSTGRES_PASSWORD_PLACEHOLDER/${DB_PASSWORD}/g\" $CONFIG\n"],"command":["/bin/bash"],"env":[{"name":"FUNNEL_OIDC_CLIENT_ID","valueFrom":{"secretKeyRef":{"key":"client_id","name":"funnel-oidc-client","optional":false}}},{"name":"FUNNEL_OIDC_CLIENT_SECRET","valueFrom":{"secretKeyRef":{"key":"client_secret","name":"funnel-oidc-client","optional":false}}},{"name":"DB_HOST","valueFrom":{"secretKeyRef":{"key":"host","name":"funnel-dbcreds","optional":false}}},{"name":"DB_USER","valueFrom":{"secretKeyRef":{"key":"username","name":"funnel-dbcreds","optional":false}}},{"name":"DB_PASSWORD","valueFrom":{"secretKeyRef":{"key":"password","name":"funnel-dbcreds","optional":false}}},{"name":"DB_DATABASE","valueFrom":{"secretKeyRef":{"key":"database","name":"funnel-dbcreds","optional":false}}}],"image":"quay.io/cdis/awshelper","name":"config-updater","tag":"master","volumeMounts":[{"mountPath":"/tmp","name":"funnel-patched-config-volume"},{"mountPath":"/etc/config/funnel.conf","name":"funnel-config-volume","subPath":"funnel-server.yaml"}]}]` | Configuration for the Funnel init container. | -| funnel.image.initContainers[0].command | list | `["cp","/app/build/plugins/authorizer","/opt/funnel/plugin-binaries/auth-plugin"]` | Arguments to pass to the init container. | -| funnel.image.initContainers[0].image | string | `"quay.io/cdis/funnel-gen3-plugin"` | The Docker image repository for the Funnel init/plugin container. | -| funnel.image.initContainers[0].pullPolicy | string | `"Always"` | When to pull the image. This value should be "Always" to ensure the latest image is used. | -| funnel.image.initContainers[0].tag | string | `"main-gen3"` | The Docker image tag for the Funnel init/plugin container. | -| funnel.image.pullPolicy | string | `"Always"` | When to pull the image. This value should be "Always" to ensure the latest image is used. | -| funnel.image.repository | string | `"quay.io/ohsu-comp-bio/funnel"` | The Docker image repository for the Funnel service. | -| funnel.postgresql.enabled | bool | `false` | | -| funnel.resources.requests.ephemeral_storage | string | `"2Gi"` | | -| funnel.resources.requests.memory | string | `"2Gi"` | | -| funnel.volumeMounts[0].mountPath | string | `"/etc/config/funnel-server.yaml"` | | -| funnel.volumeMounts[0].name | string | `"funnel-patched-config-volume"` | | -| funnel.volumeMounts[0].subPath | string | `"funnel-patched.conf"` | | -| funnel.volumeMounts[1].mountPath | string | `"/etc/config/oidc"` | | -| funnel.volumeMounts[1].name | string | `"funnel-oidc-volume"` | | -| funnel.volumeMounts[1].readOnly | bool | `true` | | -| funnel.volumeMounts[2].mountPath | string | `"/etc/funnel/templates"` | | -| funnel.volumeMounts[2].name | string | `"worker-templates-volume"` | | -| funnel.volumeMounts[3].mountPath | string | `"/opt/funnel/plugin-binaries"` | | -| funnel.volumeMounts[3].name | string | `"plugin-volume"` | | -| funnel.volumes[0].configMap.name | string | `"funnel-server-config"` | | -| funnel.volumes[0].name | string | `"funnel-config-volume"` | | -| funnel.volumes[1].name | string | `"funnel-oidc-volume"` | | -| funnel.volumes[1].secret.items[0].key | string | `"client_id"` | | -| funnel.volumes[1].secret.items[0].path | string | `"client_id"` | | -| funnel.volumes[1].secret.items[1].key | string | `"client_secret"` | | -| funnel.volumes[1].secret.items[1].path | string | `"client_secret"` | | -| funnel.volumes[1].secret.secretName | string | `"funnel-oidc-client"` | | -| funnel.volumes[2].configMap.name | string | `"funnel-worker-templates"` | | -| funnel.volumes[2].name | string | `"worker-templates-volume"` | | -| funnel.volumes[3].emptyDir | object | `{}` | | -| funnel.volumes[3].name | string | `"plugin-volume"` | | -| funnel.volumes[4].emptyDir | object | `{}` | | -| funnel.volumes[4].name | string | `"funnel-patched-config-volume"` | | -| global.aws.awsAccessKeyId | string | `nil` | Credentials for AWS stuff. | -| global.aws.awsSecretAccessKey | string | `nil` | Credentials for AWS stuff. | -| global.aws.enabled | bool | `false` | Set to true if deploying to AWS. Controls ingress annotations. | -| global.aws.externalSecrets.enabled | bool | `false` | Whether to use External Secrets for aws config. | -| global.aws.externalSecrets.externalSecretAwsCreds | String | `nil` | Name of Secrets Manager secret. | -| global.aws.externalSecrets.pushSecret | bool | `false` | Whether to create the database and Secrets Manager secrets via PushSecret. | -| global.aws.region | string | `"us-east-1"` | AWS region for this deployment | -| global.clusterName | string | `"default"` | | -| global.environment | string | `"default"` | | -| global.externalSecrets.clusterSecretStoreRef | string | `""` | | -| global.externalSecrets.deploy | bool | `false` | Will use ExternalSecret resources to pull secrets from Secrets Manager instead of creating them locally. Be cautious as this will override any gen3-workflow secrets you have deployed. | -| global.externalSecrets.pushFunnelOidcClientToExternalSecrets | bool | `true` | | -| global.externalSecrets.separateSecretStore | string | `false` | Will deploy a separate External Secret Store for this service. | -| global.hostname | string | `""` | Hostname for the deployment. | -| global.kubeapi_endpoints | map | `{"enabled":false,"ip":[]}` | Configuration for kubeapi endpoints if you want to allowlist specific IPs for egress instead of allowing access to the entire cluster. | -| global.netPolicy | map | `{"enabled":false}` | Network policy settings. | -| global.netPolicy.enabled | bool | `false` | Whether network policies are enabled | -| global.postgres.dbCreate | bool | `true` | Whether the database should be created. | -| global.postgres.externalSecret | string | `""` | Name of master Postgres secret in Secrets Manager. Disabled if empty | -| global.postgres.master | map | `{"host":"test","password":null,"port":"5432","username":"postgres"}` | Master credentials to postgres. This is going to be the default postgres server being used for each service, unless each service specifies their own postgres | -| global.postgres.master.host | string | `"test"` | hostname of postgres server | -| global.postgres.master.password | string | `nil` | password for superuser in postgres. This is used to create or restore databases | -| global.postgres.master.port | string | `"5432"` | Port for Postgres. | -| global.postgres.master.username | string | `"postgres"` | username of superuser in postgres. This is used to create or restore databases | -| global.topologySpread | map | `{"enabled":false,"maxSkew":1,"topologyKey":"topology.kubernetes.io/zone"}` | Karpenter topology spread configuration. | -| global.topologySpread.enabled | bool | `false` | Whether to enable topology spread constraints for all subcharts that support it. | -| global.topologySpread.maxSkew | int | `1` | The maxSkew to use for topology spread constraints. Defaults to 1. | -| global.topologySpread.topologyKey | string | `"topology.kubernetes.io/zone"` | The topology key to use for spreading. Defaults to "topology.kubernetes.io/zone". | -| metricsEnabled | bool | `false` | | -| netPolicy | map | `{"egressApps":["gen3-workflow"],"ingressApps":["gen3-workflow"]}` | Configuration for network policies created by this chart. Only relevant if "global.netPolicy.enabled" is set to true | -| netPolicy.egressApps | array | `["gen3-workflow"]` | List of apps that this app requires egress to | -| netPolicy.ingressApps | array | `["gen3-workflow"]` | List of app labels that require ingress to this service | -| oidc_job_enabled | bool | `true` | Whether to create a job to generate the OIDC client for Funnel. | -| partOf | string | `"Workflow_Execution"` | Label to help organize pods and their use. Any value is valid, but use "_" or "-" to divide words. | -| postgres | map | `{"database":null,"dbCreate":null,"dbRestore":false,"host":null,"password":null,"port":"5432","separate":false,"username":null}` | Postgres database configuration. If db does not exist in postgres cluster and dbCreate is set ot true then these databases will be created for you | -| postgres.database | string | `nil` | Database name for postgres. This is a service override, defaults to - | -| postgres.dbCreate | bool | `nil` | Whether the database should be created. Default to global.postgres.dbCreate | -| postgres.host | string | `nil` | Hostname for postgres server. This is a service override, defaults to global.postgres.host | -| postgres.password | string | `nil` | Password for Postgres. Will be autogenerated if left empty. | +| AWSBatch.DisableReconciler | bool | `true` | | +| AWSBatch.JobDefinition | string | `"funnel-job-def"` | | +| AWSBatch.JobQueue | string | `"funnel-job-queue"` | | +| AWSBatch.Key | string | `""` | | +| AWSBatch.ReconcileRate | string | `"10s"` | | +| AWSBatch.Region | string | `""` | | +| AWSBatch.Secret | string | `""` | | +| AmazonS3.AWSConfig.Key | string | `""` | | +| AmazonS3.AWSConfig.MaxRetries | int | `10` | | +| AmazonS3.AWSConfig.Secret | string | `""` | | +| AmazonS3.Disabled | bool | `false` | | +| AmazonS3.SSE.CustomerKeyFile | string | `""` | | +| AmazonS3.SSE.KMSKey | string | `""` | | +| BoltDB | object | `{"Path":"./funnel-work-dir/funnel.db"}` | Local file database configuration. | +| Compute | string | `"kubernetes"` | | +| Database | string | `"postgres"` | | +| Datastore.CredentialsFile | string | `""` | | +| Datastore.Project | string | `""` | | +| DynamoDB.AWSConfig.Key | string | `""` | | +| DynamoDB.AWSConfig.Region | string | `""` | | +| DynamoDB.AWSConfig.Secret | string | `""` | | +| DynamoDB.TableBasename | string | `"funnel"` | | +| Elastic.IndexPrefix | string | `"funnel"` | | +| Elastic.URL | string | `"http://localhost:9200"` | | +| EventWriters[0] | string | `"postgres"` | | +| EventWriters[1] | string | `"log"` | | +| FTPStorage.Disabled | bool | `false` | | +| FTPStorage.Password | string | `"anonymous"` | | +| FTPStorage.Timeout | string | `"10s"` | | +| FTPStorage.User | string | `"anonymous"` | | +| GoogleStorage.CredentialsFile | string | `""` | | +| GoogleStorage.Disabled | bool | `false` | | +| GridEngine.Template | string | `"#!bin/bash\n#$ -N {{.TaskId}}\n#$ -o {{.WorkDir}}/funnel-stdout\n#$ -e {{.WorkDir}}/funnel-stderr\n#$ -l nodes=1\n{{if ne .Cpus 0 -}}\n{{printf \"#$ -pe mpi %d\" .Cpus}}\n{{- end}}\n{{if ne .RamGb 0.0 -}}\n{{printf \"#$ -l h_vmem=%.0fG\" .RamGb}}\n{{- end}}\n{{if ne .DiskGb 0.0 -}}\n{{printf \"#$ -l h_fsize=%.0fG\" .DiskGb}}\n{{- end}}\n\n{{.Executable}} worker run --config {{.Config}} --taskID {{.TaskId}}\n"` | | +| GridEngine.TemplateFile | string | `""` | | +| HTCondor | object | `{"DisableReconciler":true,"ReconcileRate":"10s","Template":"universe = vanilla\ngetenv = True\nexecutable = {{.Executable}}\narguments = worker run --config {{.Config}} --task-id {{.TaskId}}\nlog = {{.WorkDir}}/condor-event-log\nerror = {{.WorkDir}}/funnel-stderr\noutput = {{.WorkDir}}/funnel-stdout\nshould_transfer_files = YES\nwhen_to_transfer_output = ON_EXIT_OR_EVICT\n{{if ne .Cpus 0 -}}\n{{printf \"request_cpus = %d\" .Cpus}}\n{{- end}}\n{{if ne .RamGb 0.0 -}}\n{{printf \"request_memory = %.0f GB\" .RamGb}}\n{{- end}}\n{{if ne .DiskGb 0.0 -}}\n{{printf \"request_disk = %.0f GB\" .DiskGb}}\n{{- end}}\n\nqueue\n","TemplateFile":""}` | HTCondor compute backend configuration. | +| HTTPStorage.Timeout | string | `"30s"` | | +| Kafka.Topic | string | `"funnel"` | | +| Kubernetes.DisableJobCleanup | bool | `false` | | +| Kubernetes.DisableReconciler | bool | `false` | | +| Kubernetes.Executor.Annotations | object | `{}` | | +| Kubernetes.Executor.PriorityClassName | string | `""` | | +| Kubernetes.Executor.backoffLimit | int | `0` | | +| Kubernetes.Executor.completions | int | `1` | | +| Kubernetes.Executor.restartPolicy | string | `"OnFailure"` | | +| Kubernetes.ExecutorTemplate | string | `""` | | +| Kubernetes.ForbiddenPathPrefixes | list | `[]` | Path prefixes that Funnel's Kubernetes backend must reject when creating worker pods. | +| Kubernetes.JobsNamespace | string | `""` | | +| Kubernetes.Namespace | string | `""` | | +| Kubernetes.NodeSelector | object | `{}` | | +| Kubernetes.PVCTemplate | string | `""` | | +| Kubernetes.PVTemplate | string | `""` | | +| Kubernetes.ReconcileRate | string | `"10s"` | | +| Kubernetes.Resources.Defaults.Cpus | string | `"1000m"` | | +| Kubernetes.Resources.Defaults.DiskGb | string | `"512Mi"` | | +| Kubernetes.Resources.Defaults.RamGb | string | `"512Mi"` | | +| Kubernetes.Resources.Limits.Cpus | string | `"8000m"` | | +| Kubernetes.Resources.Limits.DiskGb | string | `"4096Mi"` | | +| Kubernetes.Resources.Limits.RamGb | string | `"4096Mi"` | | +| Kubernetes.ServiceAccount | string | `""` | | +| Kubernetes.Timeout.duration | string | `"30s"` | | +| Kubernetes.Tolerations | list | `[]` | | +| Kubernetes.Worker.Annotations | object | `{}` | | +| Kubernetes.Worker.PriorityClassName | string | `""` | | +| Kubernetes.Worker.backoffLimit | int | `0` | | +| Kubernetes.Worker.completions | int | `1` | | +| Kubernetes.Worker.restartPolicy | string | `"Never"` | | +| Kubernetes.WorkerTemplate | string | `""` | | +| LocalStorage | object | `{"AllowedDirs":["./"]}` | Local file system storage configuration. | +| Logger.level | string | `"debug"` | | +| Logger.outputFile | string | `""` | | +| Node.ID | string | `""` | | +| Node.Resources.Cpus | int | `0` | | +| Node.Resources.DiskGb | float | `0` | | +| Node.Resources.RamGb | float | `0` | | +| Node.Timeout.disabled | bool | `true` | | +| Node.UpdateRate | string | `"5s"` | | +| PBS.DisableReconciler | bool | `true` | | +| PBS.ReconcileRate | string | `"10s"` | | +| PBS.Template | string | `"#!bin/bash\n#PBS -N {{.TaskId}}\n#PBS -o {{.WorkDir}}/funnel-stdout\n#PBS -e {{.WorkDir}}/funnel-stderr\n{{if ne .Cpus 0 -}}\n{{printf \"#PBS -l nodes=1:ppn=%d\" .Cpus}}\n{{- end}}\n{{if ne .RamGb 0.0 -}}\n{{printf \"#PBS -l mem=%.0fgb\" .RamGb}}\n{{- end}}\n{{if ne .DiskGb 0.0 -}}\n{{printf \"#PBS -l file=%.0fgb\" .DiskGb}}\n{{- end}}\n\n{{.Executable}} worker run --config {{.Config}} --taskID {{.TaskId}}\n"` | | +| PBS.TemplateFile | string | `""` | | +| Postgres.AdminPassword | string | `"example"` | | +| Postgres.AdminUser | string | `"postgres"` | | +| Postgres.Database | string | `"funnel"` | | +| Postgres.Host | string | `"funnel-postgresql.default.svc.cluster.local"` | | +| Postgres.Password | string | `"example"` | | +| Postgres.Timeout.duration | string | `"300s"` | | +| Postgres.User | string | `"funnel"` | | +| RPCClient.MaxRetries | int | `10` | | +| RPCClient.ServerAddress | string | `"localhost:9090"` | | +| RPCClient.Timeout.duration | string | `"60s"` | | +| Scheduler.NodeInitTimeout.duration | string | `"300s"` | | +| Scheduler.NodePingTimeout.duration | string | `"60s"` | | +| Scheduler.ScheduleChunk | int | `10` | | +| Scheduler.ScheduleRate | string | `"1s"` | | +| Server.DisableHTTPCache | bool | `true` | | +| Server.HTTPPort | string | `"8000"` | | +| Server.HostName | string | `"funnel"` | | +| Server.RPCPort | string | `"9090"` | | +| Slurm.DisableReconciler | bool | `true` | | +| Slurm.ReconcileRate | string | `"10s"` | | +| Slurm.Template | string | `"#!/bin/bash\n#SBATCH --job-name {{.TaskId}}\n#SBATCH --ntasks 1\n#SBATCH --error {{.WorkDir}}/funnel-stderr\n#SBATCH --output {{.WorkDir}}/funnel-stdout\n{{if ne .Cpus 0 -}}\n{{printf \"#SBATCH --cpus-per-task %d\" .Cpus}}\n{{- end}}\n{{if ne .RamGb 0.0 -}}\n{{printf \"#SBATCH --mem %.0fGB\" .RamGb}}\n{{- end}}\n{{if ne .DiskGb 0.0 -}}\n{{printf \"#SBATCH --tmp %.0fGB\" .DiskGb}}\n{{- end}}\n\n{{.Executable}} worker run --config {{.Config}} --taskID {{.TaskId}}\n"` | | +| Slurm.TemplateFile | string | `""` | | +| Swift.AuthURL | string | `""` | | +| Swift.ChunkSizeBytes | int | `500000000` | | +| Swift.Disabled | bool | `false` | | +| Swift.Password | string | `""` | | +| Swift.RegionName | string | `""` | | +| Swift.TenantID | string | `""` | | +| Swift.TenantName | string | `""` | | +| Swift.UserName | string | `""` | | +| Worker.LeaveWorkDir | bool | `false` | | +| Worker.LogTailSize | int | `10000` | | +| Worker.LogUpdateRate | string | `"5s"` | | +| Worker.MaxParallelTransfers | int | `10` | | +| Worker.PollingRate | string | `"5s"` | | +| Worker.WorkDir | string | `"./funnel-work-dir"` | | +| authenticationSource | string | `"pod"` | | +| cleanup.enabled | bool | `false` | | +| cleanup.schedule | string | `""` | | +| cleanup.scheduleOffsetMinutes | int | `0` | | +| global.aws.awsAccessKeyId | string | `nil` | | +| global.aws.awsSecretAccessKey | string | `nil` | | +| global.aws.enabled | bool | `false` | | +| global.aws.externalSecrets.enabled | bool | `false` | | +| global.aws.externalSecrets.externalSecretAwsCreds | string | `nil` | | +| global.aws.externalSecrets.pushSecret | bool | `false` | | +| global.aws.region | string | `"us-east-1"` | | +| global.dev | bool | `true` | | +| global.externalSecrets.dbCreate | bool | `false` | | +| global.externalSecrets.deploy | bool | `false` | | +| global.netPolicy.enabled | bool | `false` | | +| global.postgres.dbCreate | bool | `true` | | +| global.postgres.externalSecret | string | `""` | | +| global.postgres.master.host | string | `nil` | | +| global.postgres.master.password | string | `nil` | | +| global.postgres.master.port | string | `"5432"` | | +| global.postgres.master.username | string | `"postgres"` | | +| image.initContainers[0].command[0] | string | `"cp"` | | +| image.initContainers[0].command[1] | string | `"/app/build/plugins/authorizer"` | | +| image.initContainers[0].command[2] | string | `"/opt/funnel/plugin-binaries/auth-plugin"` | | +| image.initContainers[0].image | string | `"quay.io/ohsu-comp-bio/funnel-plugins"` | | +| image.initContainers[0].name | string | `"plugins"` | | +| image.initContainers[0].pullPolicy | string | `"Always"` | | +| image.initContainers[0].tag | string | `"pr-1"` | | +| image.initContainers[0].volumeMounts[0].mountPath | string | `"/opt/funnel/plugin-binaries"` | | +| image.initContainers[0].volumeMounts[0].name | string | `"plugin-volume"` | | +| image.pullPolicy | string | `"Always"` | | +| image.repository | string | `"quay.io/ohsu-comp-bio/funnel"` | | +| labels.app | string | `"funnel"` | | +| postgres.database | string | `"funnel"` | Database name for Funnel. | +| postgres.dbCreate | bool | `nil` | Whether the database should be created. Defaults to global.postgres.dbCreate. | +| postgres.host | string | `nil` | Hostname for Postgres. Defaults to global.postgres.master.host. | +| postgres.password | string | `"example"` | Password for Postgres. Override this for production deployments. | | postgres.port | string | `"5432"` | Port for Postgres. | -| postgres.separate | string | `false` | Will create a Database for the individual service to help with developing it. | -| postgres.username | string | `nil` | Username for postgres. This is a service override, defaults to - | -| postgresql | map | `{"primary":{"persistence":{"enabled":false}}}` | Postgresql subchart settings if deployed separately option is set to "true". Disable persistence by default so we can spin up and down ephemeral environments | -| postgresql.primary.persistence.enabled | bool | `false` | Option to persist the dbs data. | -| release | string | `"production"` | Valid options are "production" or "dev". If invalid option is set- the value will default to "dev". | -| secrets | map | `{"awsAccessKeyId":null,"awsSecretAccessKey":null}` | Secret information for External Secrets. | -| secrets.awsAccessKeyId | str | `nil` | AWS access key ID. Overrides global key. | -| secrets.awsSecretAccessKey | str | `nil` | AWS secret access key ID. Overrides global key. | +| postgres.username | string | `"funnel"` | Username for Funnel. | +| rbac.create | bool | `true` | | +| replicaCount | int | `1` | | +| resources.limits.cpu | string | `"1000m"` | | +| resources.limits.ephemeral_storage | string | `"2048Mi"` | | +| resources.limits.memory | string | `"2048Mi"` | | +| resources.requests.cpu | string | `"100m"` | | +| resources.requests.ephemeral_storage | string | `"512Mi"` | | +| resources.requests.memory | string | `"512Mi"` | | +| secrets.awsAccessKeyId | string | `nil` | | +| secrets.awsSecretAccessKey | string | `nil` | | +| service.httpPort | int | `8000` | | +| service.rpcPort | int | `9090` | | +| service.type | string | `"ClusterIP"` | | +| storage.accessMode | string | `"ReadWriteMany"` | | +| storage.className | string | `"s3-csi-sc"` | | +| storage.createStorageClass | bool | `true` | | +| storage.driver | string | `"aws-s3"` | | +| storage.provisioner | string | `"s3.csi.aws.com"` | | +| storage.size | string | `"10Mi"` | | +| stsRegion | string | `"us-east-1"` | | +| volumeMounts[0].mountPath | string | `"/etc/config/funnel-server.yaml"` | | +| volumeMounts[0].name | string | `"funnel-server-config-volume"` | | +| volumeMounts[0].subPath | string | `"funnel-server.yaml"` | | +| volumeMounts[1].mountPath | string | `"/opt/funnel/plugin-binaries"` | | +| volumeMounts[1].name | string | `"plugin-volume"` | | +| volumes[0].configMap.name | string | `"funnel-server-config"` | | +| volumes[0].name | string | `"funnel-server-config-volume"` | | +| volumes[1].emptyDir | object | `{}` | | +| volumes[1].name | string | `"plugin-volume"` | | + diff --git a/helm/funnel/charts/funnel-0.1.99-rc.36.tgz b/helm/funnel/charts/funnel-0.1.99-rc.36.tgz deleted file mode 100644 index 208c61aac8ff9fbd9d774739f52541ddced41551..0000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 146409 zcmV){Kz+X-iwG0|00000|0w_~VMtOiV@ORlOnEsqVl!4SWK%V1T2nbTPgYhoO;>Dc zVQyr3R8em|NM&qo0POwib{jd8AddHEJ_Saq*^+yd$%}3_=kJ-7C6!B6zGy|cYGnD9A*Y;(za}9`@i-xI2cZ#tD9y7j+*v|nHU{fG5`A76D{f7Nw+_e+ybiI77iW_WOLIDB&O7?1b&_VE7rkVO4K zzkj&5*X!ZIVE=GD#uIW7_v8Kj-jiN*FgQ5c9}Id=9`6k%J^Z*gIUFB#rX(dCOAQO1M5`Q1pI`XV-; z<1`+cpNfJg^L})3mUYKDP2#Spp^I}lW1RkONH%aRlZF%n7>sF(IVHM)q0f|9uq2<8 zmn=`E@T>M4A7~(#i_l!bUtl>KuBxunN${8?fEQ<(lPNme=#)%wo=Ef^q@WSu3&PRP zm6B0TvBYC6$fM3Sdc`CeqN^Ddhzf*J%F-ZHOjbyeN)#JV5OyRHlBUycOy&$_InS6N zBJ318${>=C_;phi87M*Q$2GTa;h}$x;p7)}g=rWiSL{s!*J|;XR zl8Dfv7adzjX!fTo)09V9K1BUqZw|laWDb+|pg(v?b<46DnG=qaw?Z-wEX!uNvXP$14a@EzIRQLJ}6?WEah3#L}4YT_lp6&v#Ka7Q1N5X-v{7P022r<1|;0YC?{& zjApy&+AW*TiLPwur?rzt7HR}<)THH>mL2gZY^8C!`*}UKi>~qH8h6fAg|JApG!_&c zsD2bXNT4d~bY8IOlyC*Pjnv;XouY&+)b@j7GR~*Fh^7;^iwNgT$wMzx<`5F05Y(k` z2|abGKpB>^5S>pDnP+mjt25QAQ2iiDssM$I3Fl!4q1U<0a`_!i$PjI9Swa-In`1dd zzX_Hi5JTR}4np5SvQ$f3z1EWP4ORriD`z8bNFana>8n%TlM zg=!E3lAzFc3ibp*y&ZBJou^Tf#{^CCBteqSiI8}niAEH8l3ZDc5)w_Fma-g*5M6$E zvbVSQM2Ti*Wrk3|Au+8|ht=L;(Cfot^6NUI zD}YzNpajJfgI6+C3?zPkb#(y(N}ie>2l$u5cSFV~#$q;Rn8$$c>gqyo4_j)#*lNOe zd2v!krwU$PoS1TIUoqvBNIn_0d~q&NF4R26PRt7d&G`f>S1bIQ zAdz$6wi#y`;mJ}-6Oz+NnmxyIV$BqhV&Z^hhlJA*MYB1J(P6J=IxMujbDlf`uxEE*@ANkT~~b<@>2o58_x%!yEy>DhU#e;ejJV?qwKIHAg&a1yI=#)%dJ zpZy(;z8*by=-950Go(f=O-Td|Q4E0Pu+p#epPFmMImcQDeb^Jal-g_N_&uHHbCl-u zG2yVT6?Z^#h9$yQu0=OANzj-eP9&#h-Ayn}a;}GP8!AI%B5w#u4VdcgBw;rK;S`bg z8B6srz(&O;6Lpf{68c!810;yrQS}VUGu3f@G^c4URgb;I?=Lk{CDPfQQbaQn=ZTt( zqF@NBzhA=UTiw#b&d8Rq4DAN7iP=kdo+9kyl!QBmVhdivX`?S(@i|VHpuLB&wx!kT zU@2+FaWc!(YiNf>lCX5Dir-)=T`%TYjFp5vCKJZhQ1NR$AyXDB$qvJee8pmNLDT7q z(Qd3o^^`#c`zYpew_26z$y#OSDU~gi?e)~$Qb0qyR?OaQYC1o4Qwisi&9Pd5NwP#v zb*gGPKZPyaqHt8qu<8twA{r-Jsi0a!)QIC0z|8F5Mbyk$G0P>2*-ffvY0yV=f>SlW zi8|W}lrpzuP|s%S1Vrb+t|Up82u~!@Q)@!GkTBx)MW#8KJp@CQ$Ixk-nsS?^79(P! zj@IZ#tvGk61UaW9%~PqHa7rdLRfFS>q982Hh^|L-5Hli(EeKa4sn8PDn9T5kGT5pw z{qrmE$%{9ls8WjxCs{6r2pB1_;NzDC#4hXr&otmAoQB66j1

vM#ho^=5U15NVR}YQ=F*9 zdcl%}rqiMcx9J>`#!4t=x$F|o^|fNcrjD7I{ixP$+xD2MTPzvs>F(e}s6(utV?s@T zlEi8%DOim)R&0}|(?l;oz*ejmVh`}-J(aLqykOJnD5)YZ@q0908X`g9fd27XVQ=GDIiI;#0{~b++4-lP6iz( zgIip?%FQO}uc;RVFNm8TMtcV*5jv+*Gcvc)Ml6kT&OuSiZqkI|SakCY{?$9)1?D(O zNOHw-DkkbAruV+!Zokg9Q|hX%I_@%#;QWWo0kHc$PUD1daraesv^HdDgd4S}jpD-T zjQ>{hz3=0Bh70HxnpfB9bxfe+oK*he*9~RV;w2prsod74b z-0}G55vWL+R?ST8 zOz3;R4K$6(dm_+|S_QjWGaz9mwqf<0xXeIvx0;In|ra zHhK-q3@32*&zKMtwhkY-S%`?Kh}4b;h8){y!r5H6H(gN9(m6?C5A_ZNPF>J33OL>C z>O3LPj44J3S{Qx4Ai_H*kl6H`5rBVuEZlvFRo@x$Gu9K&Pzgu-d6ob>-l1umQtlBF zOtTnudec%|%+hZqn&AaZYpr2Q)M*Ns%Un?cv=7lQf6>x{T}D)tmlZ4x5Si6hN>i(W z^mwn{B2)=DrPVJ-wypGIv17P-vZsiOsA-N?O3;SWVvKHPL~CBONM%nkO2$oN1gA1} zeo&_Yb-DtP#z{Lu?b$32*vH5sF7pG1DUHDuLG?)Sych<@S&U+AXfVeXj#Y*%e zu{unv^wWYxk_4!HQ~qUzrQ*GU9x6A zS2<6SIvxXO6%tEz?pD$QO$ZOs&oh$R%duT6$Q24OA`0R7`->AmS)6GlLlc_D_P`3K zd`^&%d33E-7Dj)~Nv?Ps)T^X6&KXxCUK*RDxe+9-Af_P|OXsl?0+*gn=hD&b6qeh_ zB`Wbxt=Cy0!Om)Gc=(Mu5xOE+|GLrN3a6?!>sHQ~AaGO6WwA~Qpi<3Bn9}-P&5S+O zu}vDHk1+l6lqyC~&{MR)DNPa#$x|Xpx65;O<YsEQ$X&rMr95V`NF=KfWzm-NBeGB(d=qdV-vk~MgcK%kf0>B}D{p#)6e?Px^ z`}*?j*-z&uR{;Lu1D&9hpimt$Q4a;Cbss)toThSuwv6`aZKMF6qJNIJG_V5<5J_YA z%bFUnPRIk>l5o5)Ui7E`iOO@8fN$ji>=eScs6=i`+uWr zfBT=tH0_SDnCYJv&qgSCRa=ufovm9#8jP%4lIz!oMwDo||7m}iW$Dv9SRfYdoXnr9 zDLftD!P2lu6~id7u38rr*10LGJS`1N=Q*eG8QjJWKX0tRX&mWqHW}w{HW+0Eb&C=aq4LXcUG6^!mVLsl;f^?|oWDY{a zod_odS~<@Ov|oQsg3{|5meCC9hcII^?aTKR_C$RA^9X6^+RdHCbEga3)n{jabz!HV zFM!)Iy?%?e`!~OC{l+z}+HLd$8|(Wd7=;L@p!%S4M&NP~Og+rV%<=CmEzB!lsl1)z z%U6$7lS_DpXv?fBwX$O}*|K&0H^mpftQtU3t^v5MuA|V>T3x5eNJJ-;#OOCR){I%3 zn=o?^1W+n3E;<72uS+W4LXqpMYDzy$?8 zAb6b9LTN5hczrF@oQXom^Tey;htmr3odlqu5&xv=mm?g zRxTm26q3xt4kV3=$06J3=NXkGp#p9v;Udd3`N*)G33M}~(adssDiBT*c0*!wVNC=~ zx?`PqO6@Df0EJye#rIcN7p6vMjVPHj?J%#ZkXD+To4p${hG!WVJwLm$#+G5nLp3a2 zv#PnNc)^Z%nU0@7Ov*OK7k|jA%^ISsL-B zHp|%=jm{qVhWn$@nX_%ng=BNW(FJD<8k5-J-bUPi^`dwxyz;@&f$;pr_GK5Y>}6Mp zLDQVZq^l`WgcNkxs(vI(5zgdXKNj>-Jsk<`ATLLEL(Cf`ZT|RjRFG0s|KrP%?QFQx zw9=b>Q)Qoy*vDa+?j|mj>^f7j?Ms?cX03xxNH*(iqvvYJp^=(p+SvTGZ2zdO&Ck*} zW7O<+I?2+ae|f`evghJQvb0v9+U~?#4^8v=Z`ZQqYrZ1tD)FN;x}g)<+%azi;hxxB z+_S^a<6O?b=Eo@PQk+T;S|^xcu;*bfe;Xb2dg$dd)$m!KUXSSS5<6BxH)CK}uIA!T_&T>&9+e`0kqt~8!t9!j^9!-nlkP;U*Bl^jidlVPyJt>0K z=?a3xZuJIWNV3%PVv;9d;twzP%5`cF2pxk$Kbi7v%7T)SkN;*{r@X|Ol?2+0bvmma ze}kztSRQ`(1blLaRoe~3y6)1C%s;!+Oz|)7y5g<-rv2x?b|*5jj}c47^jk!@#LmYW zwjqCI?{4_0{*U&^aKE4F1ZU6Ief9e4Y!u4(^6u(b=l^F=^Z&EoKiqrp|8XDR6?5;L z%0}fhB6^QYmb*$8RtwrH5Cc#c>cjSj4=B7O3BiJd#S#3|CzLTRg9+m|n8!#gqV9(e zh?*B_M)?~mo}y4~p->f3XQ!cgR!*WBLt8&lL8Y~5?GKK^Uf2u!L;aNSkM6sFgs-;# z-_A&q5iUZR-IXh#HS2%xU{Lk{chGzA|8+m#hY#I9ch25t_5rW|I2c@Ug`GclKYi+a z_z)QDRkwKc!VQW{5C%f+N)E1l!k@HcpdhX2fQJ@}K(NBLwz-=nQy3mIG_ zjn$tWAnrt8@?ckk7DWD<<3wKz;Vc8P!_Ln{;|6%CYEVrOXiOrU3xWijmu_&NvF169 zl6$~+hd%Yg8=4(!r~7K8U}-u9(dbdwIiDb|nVv=xY2QXd_nA(k#mO6V30NSkpNVT~ z+xoR&ined*#C4_3blqt{TJtyQ?nF2|-vH^ur<;#wL8I#gjij_KI66y-w(;}lOx9E_L4lB8mN-k9=m5oBk#?g^X4 zaXKaFn`^S%Mc?R)+u>8!aFvceeFEerx0$q6v(0Ji*9=j$SA)hT>*G(upcH~uLn)dH ziPNZf5zw|Ks+)wB6>;g-WJMeN`;%8~Y_1Fznv4F*Rew$o#W=ZRIq;fy}#EYHLc{j#<7 z7i&D=-{&c?E%*9PY!!(ai>p7o37h&!&fTF=gssSn5=`elfB?;RIR&_dVTXQ>e&|^x zMo27kle!>$?6+u2qz9f*;s3nBGMah6^{9CX+77|5uTnz4qE-p@eg;kT)-Kv2?%E8>W8RhUq7;3(9hlEK$TbCy@j#{NGf2y=LyBEu3YmnpY;NF6O$*SJNb{F!llk+;*du^PRcMR(q1$18WFC~J|L=L*{D=8g z?f+&Te6bj?X8-RG_6{ri|IuFmLH~O%-`CpzpXs@?nHXRuTDvqL^6_sZvbRdQva%&s zr+)8-+woaoV+ytc&h(Eu{@XtCoXM6<%Fs?q)&n&FxXeeo&ac$Mb(FdG8lJ31=8{Z6 z@m~|~K1--WZmU``ogTJ@`}}JB|2H-coP=;UC%|?0f9mft|37@V|GTHJHvZ;1+`Co( z;yTvd|MYv+``^RC!~TCi--i$W_OA~%S42o-qF0dt)VZkG?oZt@sC}C^(@7E`&7A6N zy7eY4&hHygii|`ihy~c3YvXdOFV!gK>Hy+9)L)AgIZI}P!E2=Yk`l5F&>>_AMcQnr z6fFaJfg!5p^mmKs7=Fz|6S<*^>7p%E27>Sh+>cmcj(3)1>jD08&x2@=b>TOwp>wQj zB>(d*b#Rt-jZYa38%APLfp;cBs{n2M5A@3xykixh-UuRd&NoBIr=SkFnb8C;6Uo1# zm?4o6lA*oBUhiMQv5za`S&QAer8ToL{jDkA34)-sCf#y0;^J3Wi+0wQ7u4G6?oFWp zWt>SCv1Ev@PA)pd94pNtiTRXBZ*sLZ_QZDHX3e#Ize#H?vf5-CqK^R(s#12Z$#Pe# z|8}3BUF}}Hx!OHFdvSJkrcL>DVFlGUVEtYAA7oD$Q&|I(HQ4R%_Dt3o1MWSOwYS?- z|Ffk`?!L+0SH(<0oMbbsG7n7V0aU1qj){c4Lz8z1HR`-6p3fok$YdS?R-GA>M3;PQ zG9Lp${mzFE4^sNy|5ua$8eQ3aSsm--|D&4y-{IlW;6eVok8j%rfAXE2n39t8#%}uDlJ&iMwOW=`>=Uy?g20tmeDfqm8M~0)Bep9)l zYk|j(UNv3&7<LBE{qPnRw>_s0wAekj-Cj__1;d3I+imOLGZz11 z2C!!RANKaD=l`SL(L?;dd-*=|bm!?4joFp6pD4}MEq#>RaK8HoDp0&u>^l-?PV^C_ z{!Ff)|C$w^{sUx9nUEYyGBu&xbhxWa?Y{d>aec-86f3UJ@%uNa^Nc=3edlJHq$20= zNHAGK5P^)v@T9N+x4z32=hXLP){S|AeUx)`-0Rts!8UrufGHYu)(v`|N}2#Bmc%+} zfiPB*lJGfAvA%F!dme7;^SUWl(f5bC4{vu$-gICeTQxR9o`;D7Pc$RZwaDk@xk$<6 zX$S1<&^MudHXJ^~g1{5At!4?wutyz8R^;=da<3-+(8Zrz&f2S?sDIY4n>}r;#dmiQ zc0R+|JuJuDEP$KhaB39Vl5I0A#X(llR$bz%lv4$4`K6qWVoQ~SztN{pL-j-ADf;wj zYn2j0ffeyP{Tk0Fub8~xM37WgDzv?0&iCcaTF}o@S2Pw;O;?2YhJ5AHq*|mkQPG9@ zRFrc-$7uPZ1$&EX)+ek| zx>Z7hmgjP5*%YBn?d&dPtEv96YC&BxcwM;+YPz_FS*)o3RulYfHCZ#bS~AbmTAFnP zR?ArZ5YGp%8OYdVKcJ@9mMkyr&c$7mdkY_Bd36mG!82DEHEv-mrIV7MhV_(a_|Krj z6l|iRQJ<>k-Au}?N?TRY+UqqIdU6Bm*stFS8(6dc`-8gu&;H=y{qMbetL;D6-8Ea&#CFB^O6A5{1H}~Gf-fLN zX_@XTc1=>_>gfIrJ^$#=ZLt3Q+8zA&|6cAN?W^&B39b~uXrc(K^<~?@TKVs&cK>sD z^kDyYFJB`Ax?phw*V$U@z$K_mo2@TlDGh4>E&DKi#@O|iwvux~W>vFiMZp{UXvyjG z#<^II*?XrEw02?ND$sAOX_qkt`*v-sef^(3J;4q0r%!;a(b4fAJ?{3at$!UQ;6Cj? z`h)(UX8&>cAphOV*J%G?mXh<=>w;bSZZC{+h_(j#Y|98U-CPy7Hje0g_)r)?By4Og zAPnMcVXpVWW1-0@j35S@&8)=`twFH{f%Tt%djvHX{I^HZaGbk666Xxy^NRZK2-`9I z(JSHqo1fwTq1svLG-aIJeI4ude+L!*KR7&mu>ZN24;=4G!c*|muV(Sn<+v8h5r)N~SuX%1#Cmu1)x2 z^iPjM^xB!rXp&GyI7(tG^ki)6Sp&M`s)TggIro zKZZ6Z`(y){-nk%`qpB&_Dfh1$P2C1A{yTxTYcnA9&!K)KQpR4AG!B zI1G9R!CnpbRxSCFs3xdkLmzFx4fsn$oN9;vwn6oll;Tb(>TK}1uogE5eMDo%6eaH@ z&&fOV5us9va)`8#NDWJ>q|bNNC})jjb;z@}VmfqLy`XNrSEd1`9LlEz-S3IU0@GR( z8o*2phBh!0e;{;WA661uhc4nnfCR59de`r*DzPC!*0sDhqTpk`4mlc~g_VE|Yq6^` zI*LLY=rfkc(`O-=iIzaZu6J4uV#>|$Fdi4BZJ7B|$>L=~0qCOsmmuw$D#HmS^MsYC z1a0&e1unE?(h9gt@tmDL+iVInK(C&N4Fy)u09W8jjsG(&h_N`Wt+}GiS%QV6QFxxl z>v`oCB$YpNDhU_A^!~DL)Jov}3b#H4U$jCjDr1=Y6apxt=g+=m zomiYP71w2qElUMNMSrf>X4dMNzJ@{X`IGiXJh{f<70YO}dRO%90cv35FZ`${^R6sXy7ep5=VIKh zB(#~`G!`jaa;%5H6|5gla{U;2p&B zQd6zC;Tp0OK>CW}mB6d(r-EUCp$$N~ ziW7RJyg;WP!Goy+|K%@Du=-l_mJG@i`W*ITir#`bnG&0`CR1PqV*=BJ738g3tbWkW z(2KKKJ2r(~ztD6_c=#PC*JSlD@ta_24fX|DkfaPp(+R7=y$0c9)vjs)ugH6;2~c!I zz|8fqsLy(hh^M|39~MEUcS z%G>lox%351r=L}|{R_g(Hg-%Mwt=7dxb%v=g;0^HQ#Yr7)dGJO_&gYx6b`8EMbJx&q?7i#p_tCTCtCR0h0Jm4L0hd|5%TFOp zKkEBwT8Xq$1L|On=4aKOv35Uj$f7J4K}I+*$uCouI-GMd2d&MQseuZ7a-Mnk?rB>n z5B#c)0fJ12CSvqzpmH$iV!67Y&=vT#x_J%O%&V)F7g4HL!`a~0n?S9{X5(zPL7BtT z3xXHK%;(nDT39x{!ZcC+=yN>3`wGZSL_-7p62HH|9484$u8f+sd9Sg@QSH2FBiu#P zR$YG<#c(cXB$dV{V+2BTRdk38@Fu4-zx4iM9kJBTiBYzB+3H;zc#Z`lHsjM;bgjF2 z|B$;5ZS_)aMd)b2Z`_WquRuG;DdFD4vG01s^;6ZxMN7_iJOtV!$@=oz@rhqE5Blqi z`JN2aZ|DDaZlbU*^JBy$H`lv6~0yN<^E$|+u!CRX~RM#-%wRL8_9Gf z)(~2`QEB%nwW^eT_BWFy3y8fi5>&BQ#qa9{8(3toG(u7|8Lj0aAXrFWNZC{vS?M6H9bFsiDfL`#kH|4Wt>fE`P#e<+^|O)k$h2S0_kL)$)!H=G~Vucpc}Tb6Wr?S z9OsfvNlG~Qa-DECHxb3{n@N-lRpBo)lFWmcMFK7QVShjL4B4kt&T^21x+&u~jK#lo z9eCG7sux{T?veK}#SC>!7NMAZr8fra-hUnL_bcx|`U?Ev{l`6gIJ-tTj?t7#6y-cY z3p&?N=GA}PbAl-gW3uSRNq5Tn;b1=;gb7Xa_W|bf!~IZV9!`JnNX$`ig1Wij+ME^z z?|+}5RYgcNW9Zw97*9g2ImazVi5+^>5_pw=r3~)n1P8&;i`K_y7BcRsSCcgNOH@_w#9& z7}|BZIp3@fFx5dw;_1-NWEXEL(l&z~gt8`Aw%h0e0MU6$C332nPQ_uhcHMD{I9J+j zyHAi-!f_^95pSV|sG4Wp07aSmbEN{YfZ9wS*y(8V4^oqiZ6AYqAWc zjEG=HxQQvPA7f}RZsBxrpDO4x$aLNs{6Jz_oE{=aPN!qv+NhQk?Evpj9XWu%i(>DBbjlBGY!a$2T}*DV7A;g;z(+eRA;VrS)vC6SOB_2Gh0i!AOv? zIB>q^x>yK0O;w@@z-+O*tu>?p21qscf+>+A5XP)24kQae@``3mkQ9o!E_>&7p6dA0 z^9$GV)JrW#*3of9zPTpLUGxo{R`C4hAiHQxEX>zUYZ(zi;u zBAFCj(>XMq24q3Od0f)#L8WCGo#TA>34%@oUrH`39=v@ zCn#3qz*#PkSc(WIi2!bmA`MHl$2rA2Gfo#YAya~g0@S95j2CVnAw46GFhjlu5(F8#XMQ#z-55o4q2!DVmWaL!88U zq`Qn$agEr-pp-K*kx+0>MJ`Ba_xF{~b&F$S&DG=@iKYA!#Ep7WtSY^wk7_x^{@xT? zrxFa=9WQDkgBu)k^49?8>PJKVidZ?V(^QS=Gnjg+-|?6xYJ-;yO)*W;oN-djFhBGT zND3D==gdvLa=#w}ue}1*Ki?&XWPu{-%>Fo0I{Paxy9-UpiIX^Xj zJwHG7ifcDnIE_8N@vg)}6lZ!P$Y@5A#E+U*4_Xu;7kay#8bn1xH9A&+oVDfFKmTyXJqit3sQ0MK(-J{e)8Xv^21|+AR%;BKf=<;Lsh8q0P6Q^NG@YJOZYQ=9eqze? z)OK*CFj&=2ZrRt*%CWS(plxPb_e0C*jb_W==eOE-1KkSyxBH_p+*5O~Clg@lonk{^ z;agtIs1!{JptRX8fIX)rKzEBDm>XYL#@Oc83pGW3s*(vAFo@q#pjv%nKU7-$mb0N#-yue$uy=m04YO92G?;~7auyr+6Ct}C%Gw+;R6PRmV)!OiSyPcJd)IE5TU^@3_P^1!GH8`-% z7EuGnMv3Z=R{4~^lK#*6dA-{@*4+OL`g>LX&wKj^5BER!^7;Bcup6^i93bU{*N@?_ z=5&CUENKr5WY+@3rBM4^S;JQs`vNuLn$&}vss`b=c8SuUi0be>QLJJc{Qw?HQ#=Jn zduo}_sSt2V4G_-gbI$TiC=m&Co?FIkyV>Z_FI&H{v4GSC;bTbAr+g(cO^HaWZu#Uvq;Z2jdHwRVNXGOtu_s;t)VmriFJU9h;Nt!M{SSjI9iW3hNt zC8SP+0=sR?+nU*o-L_CQL;XzHw6V42YM`w}ba*8R8Yg4g6b|h;1sj~seq-ZukoOJR z?wsHQar%a=c_e@~-TgnE_}#Cl(DpmU-eNbgO?uxI(q&-(`TX(dY-^8W0`1s7(VY+1 zzg*IEx&cw(Rj8E+I~D(E&i3$a^40c#-&y+|)v?b0>u6B5|2pXPAL75<%l8@k|1&*9 z?obRcbM7lj0wM?FPBH8Rs4>V^`8u;*(Y201wS+FoMA7F-Om`$FS-!ktsBX)4OY6U6 zHG6j)V9ovi{$8&t{~rvFdJpUWK0f2Mwxlbzo@~{ryKF*Jd%fPKW3E4Qht*SaF}J3? z=Zg-?SIlvm%a-5FL%CP$L(0?*gf@W%A)KCEB9dW!jt z-~(;%Si7iwz2=g(L{yRdQ~fHoO_6uD;)=I^C0$&?8jxC6`?YN|1uF+(+Zd#P$reIo z=WRpuvGd^rl39Xwc3LenJXa$2Ue|?pBC<8Y)uTtg!O^~>$638-imE;?*U{AA6LSSs z4Pmp|=qeNl)>^BBio_=JT05Z}F>kA-!i%5$nhO7y8&%Xz+_DoD*<{llwO#!Hbmy^vN^tT?6Nvq>;9_5?wwC81>w7RA9k8}oDZQF zbO6}uTSLu;+^e+Y8xcwt?ho~?Uj@?hj;JpJoeRb$yoG;8z2`YEhMLWLZWEhIw>Vfd z+^gh1ab59}t3`vL;z)4~imKa1)w9}#gT6pxSf( zRc?2)e=se8``*RYl+qr^^r@ii(QHMNH}HbyFnS)=HpbZKl}+`H%2Zg+PfMk>SIoF+ z#N4xsDtOIPB@{0F4%JI|K8eift8`eY$@CT1nUN>P*M;~BF!$y52C2OQ9y>w3qve&M zk#mfdg)3L_YXlW|4w0H*eSb*+UvkgXRHE#^$(FIspIS;d-%uLfb1cdeDX9Fah{?z^EQ5f8bO_tAT?IjeXAAfN+rq; zY1`Xd_jBtAZiWNLRqd449oOo0Z2j&w0~c<23+UD8%ie!C9He$Hxu6QhlWSZ^mhLd) zYj+^*h{-RGFBO$e9jN8JQ=RPr+S;l@K#Y^JvdxQqqUbI?u&tBhvTYsZ4X(VQ`EPMS z^<#e3m}v{k^mm-%b*;+Le>-`}W8@WfJr_TcrIiQmuliB3GBW1*?Wa%mhq(R(Fm4U( z#_zwwZAKVsfa+Mc=^dL&tyDMGXM_Gx*bV;CHz9ndEoDoiT;du<#;ca6inYBAh$qlID z5aT6t0(d_5`t-G`URw38etj9KeK%z&0*PB2vI~ScL1Ut-7kQQ?)Ot^nGlH(pM*3m% z6`qPayWIa=>jQYNsya*%sdy-OIg4%RbLfoY%U8hQ-dQ$#j^`@ln5Py;?U^sR7G)O@ zps@@vPu&Ze8WK|juulJ-wCj8QN(&w&2{b19@e!6Z!b!5!M&TqzG?ff22>-pa+54nF zdY(Ug&0mTCH{N7?c^&KQzxMa`tNj1y=)wQPy?o|DJQct;jRSh~l25T#m1=K#gno@V z*3Z+v(;lw0mZ{UYkGPApwYFl$QJ;A=qj@K4W6P*?lwHl3ZKb8^U|#FHAN>+YH@mpn z(OCcJvAK`0Y5m`=_m{Qn|ES+TtgQe2!`{Ke`oE9w%l*B4v3nOi>(+`;a9ytjK<(=r z#6HHQIYPc$XZmvXUUF=Tex{wvExaq-2K8+n)-(hQ1WX&at7(WD2u0hR)o2~$D%UXH z@U0#~GlsYEd(#kw(dk9M#On?Gu6U&R@ZqyPoisZl`7Ey|Wh&meAdv8 z%AO#;eCb%%5|BjR%kH)yGLSP8RC9s}<9a={4u8c@MbU;<2Nn}yO#fAXRiHwX=?@#v z(_>NGC{#{^)>)fD-DDbT*aYd4(OXJbvJ>u{Tm<>&e%*~l46V^Ca&Vy#OPBQbwH zhbA@e6#+6XG`y4`Dt6|Q_ly92^j4+uN!%22tihYTcU1DDkhL}R_I@GUaI}PZC~*|u zCBv$MCRjtIY@>sQRcPu#BT5)oxRz+Z>V??2O`FPrGCs3Kte9e9+>`X8D(D!KY z{6l!N$79!>ozA0SNj zc=*2l*QEb3X6AQR$2$KX2S*20{m=g4L;Qz(`5N`M7ZqNyR(+c-8rj(A-j=PuiL+;S z;l&{`M%!Cx8(rFK#|h)$;ebZSg%;A6jSJJ$u;uUw!VGnA6pg76zv3EI{v$fnSAipYBk9@rrWxiAH3 z8gV062YHq-9J{hO%LrVrBFUNyn_A_Ja91j2X}}qig@atCC(wpl60Gk`jSIg82D-qFEdfw(dDJ<=5YLN5fsV8nVL2oz362Uhj!DG>dKGdkh zUU!_Zad*)V2ZL~+PNLnb%hzw7y*L|v|N8aS`K#yQJl>}10w**MW=u%6IN*#Kry@|I zUXrW1WjmVjhy)pyvp~pYLh1^~NKj)029ddjs2p6YQ;0m@<1|i)0)Tj6&1+SI9!tsT zIG2T(qyr21=QVBPR2Fhd-QE~Zw$S)BKFj%u_154Vx=-`B6=g?N&Ecd8B}{ZIhipDu{lRR(tbg#S`W0ON!MA4p@9!T~?|%medq)rJ z|31FTN++p)o&!=VJR#6gi5f23A}q-iv{%+N-d+~ch@^suAv(@*G$X+v?3qRE)ito| z+9e%^y-*8=`bsJuqOC!1a2WLZ!Qk;#|H*JL81@gs{iDNP|0w7^9`<_Le{D>ZluOcx z7E9KuXy$Vx8I?m^S>X&qEsD@Y@dY8x{B7@K@YGZMn7p8bcVSyF2;YbA4Mig2G}9LL z=5@l(?LmDTDWh6x=irp(V`fo3g4Zs|tGc3SEbuP%RsfkM9EkpnqqAB`e z^!inh&})KX7Uk*?AVPGkZT3ivz+bg-c8${*&FFL%WQ0!`pW`%gF2>Jef)n70Fhh>ivkj-MP7LMBg+#z&YO?o9~B2ZS6P4fgjZ zM^E-59E}g+=<(qZp6pNJXdF!r560ueqk~>w>#k=^4OfH6Y zj)}h}=5O=3#vP8J_XLsU1ShwvCY7!l>tJt`62N{`GCS&l(of-wzKAGg`-Eo*evL z@fh=TM{$rH`;14ko3zAabdcM?V?lA5dtayQCIwEwNkVsFQGVv@Q@-`{KCJvyV~A~ClzhC%O%V+?<^^!DYSk^jpax_hF2-rM`1 zgML;2f3SD-@c!pszRK3xxUDt{^p%~qF36WR%-Uvo>y6TGk_{VVWpli1;TutD6bg4M zc;8m&{&E@lZsp@*!z$!rZ(FkRaIyWAPeCC_ajM`?%LX?Bns1!|~qa@!sCv0U5{fQE$9=Fn)3{*y}$blO7%%JU$#( z#k0Mjw-@yHt_FkQ-e9~hp&14>le0nB>=8m|AWI`Z%|wR zhkFnAKlk!&Z=?Sz2w1SA=Ls9*1Z9}xIgx~m&i1xVJY~@};o4la0&xNEW#GNHjj^`%8LdM&n*pQZ%N;_eRV%ex)%sE*3r$-TD2_Szpmmu=KTMs$uzmat{< zFcf&nE<{0&aEhoDB$=Qwv6CStsRaekL#S4*>UK?%68KBqJ=88>wztt)I1Tk*)jl2S zWKh>GZNVSOQfI%yV63^l-9hz|=$F4#?hZ|bH5wtk<1e2R*fh(F!=F70h3n6eq{(KqP? zyi^Dxq31lDmD%0YV`w6&a$kv#kO%c`rFWg(ZZJ)e1*!q7#j- z7VNL|8q@FOyg^rZJOo4a8{TuLgv3yAOi-SxUM66)r5GHJW6f8;^@@J0&a{ljg!>$~ zIIf{@VMYXSDNp#fNYI!>n5!D$1iMrMpmq`wQxT~Vw(rNyTtXSAbIg}0W3ehG@~ILI z)c{dpYsF}Wc^pJ6Hq>UE#59t?-mgwBP{w!>Ox@xsj0UiE8|SEh$TZcY5WY$C3LAu zO~O4<{9^{DrTJ!(4bhh5IZ<4xYd>qGSu7M3_l9)K%X1{h;ENDmM z<3OJQz^#sAiV;iI8s{W_6rwXFbb(?^$s(oAz^`$LK76VXm3}HCcw}e1gb4lS>q!t?~d`W&=tB7|MX_fkwpk+vKF|Uh*8ryG|fo8W*Zbf=)EN}3K=wwP5` z-Ljy>)8-N?V~5V?xt2c^wZMfq(IQn$;zu=XTIbb_(Bzo`y1`4U8N)aX!_b_i?NOSF zVgPoPuque$Z8%sJecM*CS52my4x8if$CA3P6M50 zmt*F=`#qn$V)B9$VV5h?FGfJ37M3W}$?A+yJ-eF2upPH~E~MgcbDZXY!x+5Sx#xt^ zaI=Q3ejKk_q8q1V;sut(&6KXjPr|9;?%C&@)U(pfIQt}Qlj@}h#zjtsr_Q8j!fc9$31sO>! z$s|wI(D=jSj(0wQl8yUJx%!_s7lZe}D!@BC_?dNcw}Zf{qcdR%%K zQrXpTE@x%IL#0&3jq=-)hBc#xF|=wEwcF{H*Oj?soZ_Ub5e8*M-I~~;x~onNXH0^- zhDyuaGcAk90uJG?W<<^}bQ7}7WHvPMGjC6~1(8y5KXoWpbp*gAaT*7yfyJ>)RbQ<7-bX!lI^iqH4#(TLyFQ|}es+TC% zDjLh17tlx#+EVxoK2@!Fm%@D?dnJyNPk5Q(rv@5)rYt7CQ@Sf#kgxDC}Egj{Wg zbvsJUZ-=;G?M+>XPR}kb&rXi7&Q6EGO{#6N45hudT2MHGR-mv%wxDorD5LONZ>Dfo zp3$-MI&UXh1ZnC;Kix3KE=b9|V5WRD{GuP+4MIvwqo8xE9iR3gAjd_OlKoA*Rlci}CdiDD1 zY>0kV?Wgivy#Tb*kSr+6J=t0d^>mstPU6sUJB3U{b)%?s!PSeAHH$@K zB5w#uL2unAB{U7&6Li4_Q$uxxkH0n{A{?lEe`F)PZa}Hj=OJ^_w>4^p z&C*qa2{@1A*m@N_IrizRwK2jcgv(~&811Mve7KKD3aaZz4aL>!Ef+&ZRz}xk*^B{9 z@>IQsV!&elE`%X{q%YT3d^2_&igAI@ zZud0(%7>TYo@L z+MRX=y04~g)Hx4bxV8&1A5%$qQy-eFf4BwcsR3V2Y5Lx1|EkTeDD%!!Dhn;8YcLR; zXH^|t8#1Tj+Yp_FZ$T*WbTdpFsREnpFiO9Ts`+{f!e-h$HQ`3|`D(*=kTVMvzY>+!V2?fhZ#pf=p8uYxq2~DTtDMvLb&;1 zqN=E0PE1s_3{jDzDTD=h;ufH@*|HuB-~^z31m0S|9kF?q!{D0BTBGUxS+!2jG{+p_ z-d6RCUH9f@wYcat7ibB=3&YvqJ~v{ih}3CKzFzpEmG!)Sc zr;+|w@f)6l+LxpY%2^7pHT1TdP$?5)+ir;2MIw)8ih!3irK%U;)_2Kr6f<;#(^6Z! zV$ReCsGBe~fF`!hHcDu!U~v4KT99%^=BkF2L_`S8m%GpfoXpvR80`&DmT1f|bk9Vc z5x*@QPkbBJ=3v$9W0n0{dKI|6jn3ZVd6pCh z7~iobtVr;x+3)q{MUr)z*&jT9Nquf$3ZoC7D(DM@WltTquE7;A+c_v6a-2|@cxo#u zE?yxEVV$Q+Y~)>9-?ED!CGv*xYno2GIF1A3oFR}5I4+S9xPuabn#u5IU}}PU0gtMR zkw~HJsaT~#SCp0OA0jS#jnsW_>?wrRt(?9Zp_xmptGtXi z+pk4<8Qxks9fQ9Zs|I=s3X)PIT{DdK#54YbGUpeILo~XfGMa&#Hc0GR(H(MYH}kbS zrO#DuLv1vj>gwQ*GFu#ik&z?LyI65n3C8)`1>vX9+KE3c!`){y9Elm>U{2L36WxAW zG+GKt=I8~RIzx1=&c3tj1cOzPDWI|-Vbfqi_*lu5%OD{O;v0!-pcicVlLe{LtRYas zrpTc|RWxQ)MiyK9xV2)33&$EYL)7b3kvB~mfcOC~uzsMqdHoP9G!W`Mql%AoaRNT8 znntGWGA?4AbUkdrZ;qI*o+1?z>#fj~{=jmz_BU>Ufmg!7rnG{@N79INOS3RA0%CXD zz05S%YsPFn{7u(oIa0Bf4G}dqRKj1=;g>QeG$Gcm*xp237%N;Qzi9vc>X%kkZ*QaT z7qRjo;{+^^z*nElf2{zkBAR9)JcZ4572~7r|>)mOKga9 z>&xLILekWmXXvM=@!nmtF2Gi)V&xB zHEVz(3!f{PW*JEa+=uXql4x~KO61VD2OgrqQLlewlk$|l*9P<>2BC7-bgib>h8S<8 zTFx^Itv0$!_l#*8pJ&HO;^W;eNkwMDnJn)Ovm*`?3*n}C@@(@p?Jx0f5C!Iv;P^zz zempJL3hq#ZK-yp%#K}_SCjX_&F1lyJ_;saeD5LRrG$9x5BP!>a8_^L>QT^Q7a6nKoL$76DpLZS{E0JnR|CpVyuFYTWl-#-n2w(ciX>C zE%Vw5C5bj?s)_22-L>Xwv~}&LA7P`R6OPVB9fed;*3j_}s zC`%0v2h#5qFcFr~>`hh$*|Q+-U6NM(pV(la?wD9y71&4z&3FIh6|i1TXuGeswC7I8GCG9GIIQlL{Eyh+i)CMM6UK%mK4zn0((fRTgLl*AH&4G zdWlkAFYWXiCsT0avF{fkw}v0Br@q4do=hqEo_8a5N($`a604 z?CGF*C8P^95OkI7t6p3PW6xR=x~fl!{r6MH#T+W$dW}i(%u_AF_DWX1pu&~6Qw0U4 zs^juQt~;tWX?jd%w&D|rF#jr_kCiMssaBy)tG>485{MY0fp7bq#aNP&qe>CQA|a)zkWkafr@S zq%GNDGF$6`YC(T)>XMt7wmZGHIsqmO$B-mBOTdKPL)zWey%-4Hag=OiJHMuaqPg8| zgLqlxt>w|v98AA$y=3rm;|%~nI`>oTDP@k|k8(aGLo_(}=OXP*>YP*9oKCf_)|$-B z%2-?+@yuQQ1&jS-p}vrZjkm5}9l1+KXPpZJO4NBn{R5MKoYN$>JGQ4%w^waiyitO( zYC{7}L-d-%qfB+4U6$!Tp6It`aI;-|8l@V84Ft*nBy=m2PS87>`A*4tkZWaV?Wksm z-U&95`rX0|^Z4DZrcF~c&mvGN1U&6-gXRK$TWY`x9H)}H6w@>1)>gJ1m7hwwL67*D z{~@}i*6blt^nvWpVp5$0cTcSPZ;2|EP$8*w1zOM7jJ+~kP1M7p{^Id6H;w-y_ z$@1bS*Ua#}tUDdJ=CIH3jK2uxT%K9>f&VDuTJ@`>5}L{y(Ha2x5THld@J(TZT%^Ry zE(H2EGz0?b2%@5nuJ44PMq{Nd37wE=871U<#;yf=;s129LtQhZkJvi`9!p~5HMOEL z8j}g*L@`5c`~ner^9&9MrCO`AfbhAw4|&dUL@o%YEVhBAtMj4&MgWa8IP}3PMD=am zINhiV^ky~OYRK4v@C79|U1I>EZ9I%epsq&PH5+TA?+suC#o??`z$gOo-yLZl)~?(5 z+fI?S!1*Ox6n93lU?>8IX5RJVxW=9{78~DYpShsb>aZ0C87E|(xi#Go=)W`z%r!uB zbL<_#S8IedJTMgnP!Z5wrOT4taQOVzMNUUHaQ7y3e1+KQrMX-Q=f371%bNoJHX=>#rqrTgM+XN@`SuAE>Xyf$_6ASHtH#H@jnCE>3 z_@h5!*14i(+X$U@yBX;3aVzIxEB+!vKm5m=j%`(KjP(^uFB#Jh^xKeqE9&Fr7dCgP zjkPpQQP&(dNqua^#qf&xv&wpTqv^8Rc=_v@E`LSC<*#bC{56c0eT8ntT=@z#PqtT0 zVqK@@&51^AZgyyV@T27IY#qu@$xgY(HVYeNbD`=P5F5o`#eNw0WXU?YVw+sCOuiM~ z7Mo<(q6@~QGX!XDH(1}4*7SvT&sPM3D@=15#fF3~NJ@mzKDb)-`x`CPRVNoG`**h; zt%3IYRXUewYA%473a>6@wiYtl(o>S)r9C~I>ogRrL?leAnoyhJ%t~hweW3UZG}74! zKtXet{~3rTm?k+VS2Iq;j3qJpPA4GgQZ`2>aj?`Rl_A=>Nd z5ZwNeY@pK0odYHm2vr+8M2AXtsZcyb{nq)d&cXC=XM#I&8fSPpx4qcy=J=*q*Us`y z5p6KfH$}DKOy3mUhI74!u2W9gc(xzZCwsqXvLD=bu8$ISqg5+l+fXs2OLH zL~54H8E5%)X7wlf*kn*^?>14FS{ zMBVL}OlV3f$=+C-jK-Da=d~5N-KyFIt*kxYW=>lMz3{iQx`9zyPFgSDmP`~H#TxhIsG9F1Pi;w|p&Nyu;Ue$D}uPP^(tW?<0%%Z@qW)(cXq%HH~j^q3<2Sbo3OCqicaYGwfCV z?p0-=2GO?pmL1a;vUEsr3&?oGV}GC zagruv(Y<~wf)ZHZMO|1ki%Gh0GuT%7;`rIwi?^e*7iT9|uP=*PY!$mJyxl)FQ*O82 z$NdTrRlUvLs#5jp_~qH?;`rpOPEcbMg&Km>vuAIfHx#zs@*UG?Ff!HAa9*-Jm7>Yh zhPL-ij3Y#klP&y$8(egDN-7^~GV51g;c1ZXSkhd9n5R3r;9W8M|Fie*?QPr0!ua{y zp8_xAZmeBXzU0>9t#^-NyQxoo(PKI3>C^4wQX(vILy;^&I#Cni9vBGHc1 zwa)u)W0DvQ27|$1Fc&X{Tk1D><2{eUg)pYBmHV)gV42aQdOuHXq}78YY4r~SeyzWz zG&J8Y3}YW01}M!5^5AvuPemNKEo|3%xJdKJl}c{PhYf#BF97|q>LHZ)<37!&!VU-` zh{dzv#!}OnbQZSh@yu@ot|`4A?sXnS198YY4WeM4&p|}|Vz&~QPGFRIQ)qCJ#gdN- zE|M7rW!%+MK%;hBas|tLsYI3$sZ**FYe*?BkKok%xC~m}g66C7u{>>rmgZ@x`&hF= zBy_sd}xbxdqMTW!*E_k9^I%i5vYqm47e z3d0nA;J?Tg9ni}fJQiNIhUge4vFE?`LcEa`)iW>^QPa`4a8@)V_+Zbrp5Q)-4;Zn? zbJpPl(nw%oq6wdO8*O>g(c@v`(G^*h1oS;{7Ds};rNCN(0458A_aVJOtXG2C2`N`27wK<27b@i90FYRKnzu~-eRa7K&pz1T0ZV|kirjM7;ZgDArzG6lHcMc}6y2~(lPpU8LILW18aR3s8WBW2g?pM&QD1Ta9MahbUbK)^d8HPY zq<*nfaw3hn9t&0_;FZE}Vg~tJkTG?Pg{`z$534N)qEEX*t}8Q6>a-9{S)l@&64Irf z0B(@zTYy&Fj$}J95(Pnof;bX>;|DZ0iKY6W-4re@(|D7gst{JalGq1v3eq@_d^e59 z0dvQC$9&cgNc-a1G3hF`JtJ>2tSAk z8(`rWQL@-S+upVy&tM6D{Q-J@2oWlj%rs75ngvC^^BMa@Pw2}B&EG3)OLnyt7GJF| zC9kd_vhs*8j{&;_DMj7V;70v$yQU^0Q_m{qBxU?EOFCzW#VPX9S7T8uS}9n}cqA~T zsTX6#s-Tx=vCE5wF0}EH&j*oaSLX%xxcj*4L)+K9QDVS0(aEXk+sov{q|@`{oYK-*J5o0CAZHN(E(iJ)Kf zzm*d~KVz@8RM2F!RTb#iC#(Q9k{XU3jHbm*`$TYm`CKd5I01#V`qg8)D!wGpNMe5b#g7o167eh1V0qV z8kmA{8o!rPfH3)39F)Y(M#Zc*x|P6dRj8~K#d2snw~%bAwy-!=E-3`v=>3Ie>uG?f z?M|b(%MfWxHIy4!n*@HvJ%=OiwHqU7z4{mOz%op@u{YgBRiN)VHmFQjG9mzba-XAp)Z<3*#D}kP7{MPiADzmrH zqN{togDaG}OO#cvQN(aywu%F_3et`ex>Gy#WpVemZknCF2uH%H#?I9&&ch$nwPMn4_r{UBo(XV{+Y)-H*aRj}yL#TQTtv-lK^wSQb ztrlg6r&4uA=qJ+_qIJn5sw}_S9aA*~?&P#ue_mbf#43&6erjEs21_1a>khESBW&#< z);?6}Agja=4PlA`l)`AKBA6ZqFDxL6dO1QyQ&{qKF0zRJR!j$-4f5%4_F@r*H!>@;U4wE#qT_2obBy?# zn3!UBhl|@?m5GD>$ zLT}=LIV~{uK)mpo2WBvw10RMkgCI^=%44h-csC3dVE{Tf_8oyxg!2&>4))I1i$!yF zsA3qbU?V-aVS10~17HnBA&gI{UY;=-9JK{}CqMd!Xu({n9M>^5a-2<8#f^o8A|9F# z$O#7v9#I_p_!{I9!vJhxqA(Yl9+vT}qbLuu5PvrRCW#WCVOqud=w z^b1oFStrA)q%z$qPl?HH_>SB5@ZZ8uw)ldIVi#OM&;Kb6GI$Mrt<`M&g->m|X~%}#%Jd+P~JS;0u*-t4$@ zn0a*WNTphsc|nL&8?clQza`CuB6>jUn&IV9xDaMp8jSO-@Z}iAbI8(I$GH!8c-$=fpjo8!lJ^nSW++5={1s2kvzc!Yc;%3HgJ` z-77gU0g(OA6c?>ll8gRVwIIoUA*{oyJ6h z>rv2KQV2Zj%@_&K-l>TYibMzTwT7}K^#RfoAJ{_acz=UV3(fg93zZ-#4t zNH3efqc;fw0%Ccx)s6vk&FeZ3L-Ji#Or?nJx5bchbS+ie_!*TGr{&(Hcamo@k^d^m zFXQ(xqE|RH;D&7yrMaOW#t}P{Dbpsq5P}1mACRdgL|q5LHBIBd2^Sz8gddYxh#FK3}`)++k5<;sq$4V~SN9Z2~y@aPUErx*Sj~TzD@LH0yndf#I z!!Z6(m0gL{)SE$TVl7f2nW@}`D>9Q6hFn@a6>}ac<%7H=AnEm`+|1-TU+qA5VV1rT zVvYQL1Jkko#grY~#Dg$E+LI4nHkql9Xc0MaRw5X)3^~K1WB@zYmD1t7hJd6&Ar}lN zCafZJJKnm8R3t?KKLnW3@q}T)iU0AMvG#{JdMY1m+vUEcR(X>1RwU$S&$QA9>4TpJ7iY(3Z}trI3J~yNlEMiOD3KGG?(}ze@H)rRKiyOk)C3WE{X)EM zkjbZn7+L(oG`I;uIE6=O;)Qe@)NDioW1nt7#Sp|{zj)FNBsuTODMYSGAQyhh+J3xl0s>tOQO&5XmJ&#Bc6>)Sk~`lpPNbbS&`WGkRfYdNn*g)E`?WTFPE_ z5y#p0K?uGpKO3oAcWpVO#2?IAbpYL63>nU#K{9&eaUd{051RX^_n3C!}e3LIM@N~c%s7E#5Bo3mC6(D+4FQhn*NNv|>|I%R9?X2`#H{I(Y<5*Fg%%~T~ z@)W?s|E)Cq->PEwtq4~KebevVM4IhV;CB<~wpi~9_)@%geGi5ZZ!74AVczwfnj^cd z{oZACcRjN9fNm?oYEXBxE_lc<-{xuXwTQW8VcRs&mjsitxM9w_QVh2(g4-0o&Hn46 z84RiW1&!g}k>j^_m=}T;zg-)>-FfVGr;*z{bgU|B`yOMq?>=JN5dKh#)@~51EzwPl z({3H5-9e1@T}Ei%X?*q_M`zznY<86>s|&|ANXv3acC!v_QP@>oNRimeg=@k0rN}xd z0^1Z1ZHtEH!F6inbt&$;6m`8sALVFkjUuH|eB>jV1&H27#~*|ONA4Q0DLwcve^mC6Q=muIoFsVj-H6WL_;fm(Gb zV0maP{g4l7#am+ehUs639=XYkxp-N5#Es^+zz1&r+aCGv8}J!S@(j4X103L9?^4x~ zA%yXT3{&a^cAbYrcAO_L8qI?1j9rn>JOt2WLPY|%*cUo*XK@;M;g;w7u2dbtWpK7ihnCX)5l3qlqihfcWS=6pb_6f7 zZQxhHqwi?jW!%k&9bu1)58XSQJ<)Z%Y?nV*0r!68U=WCE~VDcx4@MivwNy#<4IN zeSUegM+G7;Q7^NRMijxNSZuKR_JTolw2A>7P%%e~T%^oBG0mfhGi@PUH<%>mnp7Yz z7<+xZ9GOOZ9j9~4B+{-*rEQ8X_$M1oa!Ni3?E0K)?>%D&1pf-?H11c#x^TgVTy-TYN?jH055|b8DAi18=4tBCQaN zP>=;TRHN#d(4p|GC|T~#i|Q_8;(bEz1@SuNQ>MCn)ZV7^{up36uV=eX!lEd@34RtQ zaTre*qa=l%e-K9~OT7ReiuCJZ@&S;)ASHWP&qKkHtCXDN*tm%FhL6y^HzDz@7+V=v z6teswj^872BL6A$6iMK#$uQ?$2DL4XdCTJAUo*0&SuQg3s{PqXPn28&@eMxO4VBt@ z9G}bLD?mPDRrdrrs-Rfem|okCvee7qbU}k~`Crte%YA_1oRwn2DlKV6=9-&IMvUV| z{PuW>>7UTJgb=1^OXA?IC$v8oQN(y|T%aP)WgQLgy@-i5>1}Z>4L~YCD=r%5-p5g% zPT?NdeesR_R4L)X->m^dzZJb|1W#iB)Qh|+xnp5Q%VA7Bu-QX?L0a}nq5wy;I1hb1 zC9JAo@CT$0mE#5Z57{}#c@X--xuM92%h~)oNKr;262z5f8M8fbp87C_{sr{>g>gJ+ zGJ}2|!t_k{eG+fLMojO&XI@lz5o1LqK#7-4X3{p+Fm}_Q2T_1B5}2yTY;u26S0Esz zl9sWxE{Y`fc>o5nG-hHE;+gVz7!8T4%lg74KDY+I@t41`lW{pp{Wla}XTM>Y@!QNx z{oh)y7B+$)n!3E`%$A2xFpY>pAH_c0dJ;sKH280hkLyLg>qS{0o=DTK4z`jkQ5IB@ zM(*HGM4!^A_W;I{n`(ThGsRsXjsLfV9e${xra6rA*(-lZr9GcN(=dos>tF(bnnkaa zWTpbg_i&-2NWG=;V^Yozi;qhDglVro75{z@7kj`_X9Vs-*ZYH1b#r8t>9;K~W_Pj% zq}dyecMV}ph%*|?_W%^{o$@0k84{lyi)JL|ontLx1@V57;H6F2aSo%lysc<v)o}-kgyMEjpIecG0hu9h2BUVdtIVpv!3460`UQrZ)ln zu*Ixk)X)`={|zS@+M*!0Bw2q_eM}-;CY}70%};fc?g~cC~oRm5e< z3Ys`N^Unau@*&yiutq7(051i&EMMSN&--$d6vBC;uto`8t16P_5msHz<6R^^<@ zt)z<)V;43ymhRgGBg=5*TdW3rRpnpOkeePIOdh6#iP(&Fw~|X@a^h5G53eQFxL}YP zfP!f#Nb(2tCEyiM|GXX~HX$;s%Jk=z?AmfYR~3f6u5G0r69zXhf(U^mjWPco;Vp{z z(~)(>Llhe>`>Oi^VOigLA~1JJuV#+om<w37C(D3EIfad3 z9km85xoeRg+V(cX%H7{)hq9l3cx=Equ2M=@M z2-J)#M}6A_K)bcm9)9iWX%Di&`e_fe;RKnIPJndlDE}VAY8Z4T202?ltc0e00mJ(2srKotOEtDcLck`99V_qpQDi(xk z0X^F`Yly^w>O|fm%YIm@_ExE{D@njAb*z1HSj0+Z84bHqOTN8O1X3AiZRc!{w0VCs zV69?OgZ4;bjxy4Uq-u|{NuC%GmT|D6iy2hJf>75}$uUlK-bN+chHQURo#j-xB`>r^ zoTn@fCi3P*Ff9v_lHO~thEgOD4OJ>W5V^;ttOT?>{6_7E9Kz%y4?cH2d(J7Sp>MmU zU}+snbmQqBmLeSo`qdFlAYSP=NIlI@<2=fcDR7HA?S%m%sbD0c-pCEDRyLieNOp>p z`!11}d?8Ur&W4twbPLVA6mIEX@gQ-@D#rZ?mEIcAWEpaxI>$d5mHILB0BRvG)UniC zl!vho4g-|tWF+8q?oX*trtUl4%z~Wek(};YwkZ4K;@Zd`+ngQ}f2<~f+G42>X$lS# zt~^PUESJS<6-F67frhQ~c@PamI*!vI3g-D7MEQIS)2#%i6BuRQl-yj&+AQ_FL)6hL zg~SNYU6+(v8!~vV6<82a+}XgX_puEsb8kW8Bz-6+7*SBs{N-wHzC=xtB6tH-7J?K) zmuD9D=1^>{mxbHCfE;PjkaB|xkB&xVGX(ZU6{j`Os>q?<-TfC-(lJm{Qi^o73t8yM zpU8Y6)u#tlm6e`60Y5;`53#}~NSMY6OtU}@`JJ)P%2i}^wE35+N4Az;8xv}#_1qVr z**|oQm0%-QAc#11XaPq>WuO8}b0Hu#+(@hN(=O(y5QUyg0VyF!b4b>;5aRZ<2@KP( zH3EsDuli+6)tnws5EAE!)-g!d;V>5|OB|AsG!HinNuYa2QAiB_y$2zQX%{g_@_ask zI3yXtc40{JK<+gZ$$;|RMj{zH{KA1qoSj?7AxWD~+fXFdW3x!4ntm+NNUV!hgOOP0 z4>1;r6R}As5?fw(ABn_}lI!DuGjcM(JSyuc_TmIZj0rDJP+uybC}>dJKolqlyT8U9 zmEls1W*tOJl{$WmmAa=`DMs&hp;8i;3d2CFh$dbz=1&yRR1i{gdzUxv|Hzmoi8AGo zrV@1?!hZx~h>^m&LNjpM+ z(I6*zQ!Ea5<=ybX#5r+fK!v% z`oi%|1{5E|oBp)nO~NSJG`eY~UelQ(oJueo1vpgz{?i9J>2jnp#%ZP-%sU8iQk0j6 z7vUuC6P5~aGPdq2zR3uDh43aLyp^Jxj1X52ZZbms&xvhP7R&<-Z4xqg$;c*i`_2NJ z%-~mvYcfMzEv(55bM>euGu%IOP}3-kKhW!1n$=vmj8AAi%Os66I3WcFXK9>IXKMTa z2IPw(Fxx{h>@m+>BTajB&XgN6TvGGD~ znfNJF+m6DgOrV#Ko-#pOC3wmNZ`If-6U;w*=oHsGmyDdMItwU%5mowI>)1AT4 z+M?Z6_>_Wp+vq7x|7e1D7co=}lp%ylkDFpHQFc9vX+Qr-F;sja+J{it4BLP9Fe=#v zvD+vr?_hnmNuU zD|yA%GZN*l5==vUR-^`Z4lj>*DenzZlZ-n+Vs)Q(73E>L38J{v9ji$#E(nSH%48PD zh{us|HBa;n)4p=)CqZmRcaNL^PKo#O@EsV?W6CM@6BTf!uXxOv3$WJuQyOIOJeo9M zJrw)_m6^SuR_z9JOUD-c0r$YSZ-NGcl7sc$9cWG&pe6{fV)gL7np{XE9t$$0xC)OV z@)h)fmu-S_q>LY2lW?g_-`HsEj53|FZomtkGNXJ0dgo(-D$2)xkP<(k1;6TMSZ6Wq z24t~7H;8}_ZCGHa(Y zN2d4Xut&r2O%3}00dK92s9o^ z#v~aCB9wVtzLdyII_n4HIf(-0MsRi}`ezm=!DPR9;9dtIykd}_kUy9(zfzT1g`V2w z+j8{8GHpcf!bdPOaWyDD(J?6AFdQsF;QZ7m#b}dlr6N4L6bH^5?E!~L8p|efPm$nS zZ}%Svt|9Q1#DQyA-%}X)Da_Jfg7gsZIeo0gfU}3X224e(Crli}6bqIa%n_O4G%E^X zn!>hU(_K>MLkxuiIbuM7WW-Pu|5-lnv$Eq@rlk7D>vA--Hzs4W?z!1#AR%$roDF4_usoa zFKI7QW1+G0vrzex$9^Q{Xqt|1ztGsKUrPreQ|II&y2?MVk(603*voiYWaqI&;EFpz zlhh;Ov{{<7s8#)wgizY~^a=FektooG8OrwJjXw?7lu%;6g^BQI}^ro66*r}CsWmU)bW0o-OfvR`So%^YA|1_yFd1BTL zmh`(eH}A^v+6;XK&ucTlm0YjQAXoOiHiP{#&euCeceNMoyhoo^dyke@i{{n!z?RF> zPS+Lyoq1hb;IHC#Z2`HO-?atk>W(ESt}$j#;uOYct2o!WaRO6Mv?IS(?YJ3~5$|xyYWJB%>UtKtVeOQrJkH)Na>(nIrH{ds-R|FQYc*5 z^Ls3Eug0EHGaki)W&^}6@VLokpy_r+0V*RyWuyAGDRELroMuQ$j|=*5n&y@!=1r22 zqzOaRPR0|1a&GCXrY`}?;1*!%pFX~juwZA9=Ewxm6e7H2R97$^aC4kk8mhO5rrbt$C?6W?FtBELPmbzF9Xd_wnQZsRA=f+FkJ znrtn_z1ns-^((Q%jYyLEfL>CjIYF9*7pN^t2J3j)ZB4_Z@MmJoVo0Bjg$Fwh68VAR z5_bFs*ALJnzJV!~G6lYhbzAGQg3&c(&3iCR%hVDVg~b-hoDSOV${GqO0Z%)j9LC^o zg2@a{-t%mac)Gj@KzdVim*Np)G)-fY=DMuTsm6SAiY^{)5vRpW&(s(~Vhy+=V^uCD zo;;zK0O>#$zm)-!21i1P0RDKBTro0|b3rqPVf+D1VjqHW7*F04R{?tc>5v{ADxfy$ z-66jkAE(~rJuDoO$){4zEP~}8_#v3in1lI=m%)g5=`b?Dk4d_R<;5Pm-nt6uCs*to zyElhk^kV+$-|=|gnJ@kwkDXia53t>TQ2@D)Nsc7x7LDyXGPx1Ffhox!nNV*t_NH`^ z!@tkxb1z*`^!eo*2$ca)<%EnHs{sG?`1{ZKUFT5*L#|seCzLHJT1am0x!3i^7epIAAeI8^XdBN-)#LNK{DB|1eIGsDxsx6-R5KYp6xDa9}<($!? z`~l4zEtOE9d-CljLp;xBCWNH{s|XMBYzCu@#d@m#1l2ej=tiD14NG|_VKR>65PAh{ z6&+?XR)^k2&Og!w7ILAKYt!X#Q(^Of%06NMLGX!0jduUx%(O- zj*5Z8*>4g9)IxNiKS7r_?83 z8yEl%;dqB>=bP%g#3Q^-czlarw4z~^%!3R8HaW&fqRyAHuUmRs2?_Q!(Cy>%=M3eAt_jA9s&tW=K(^*ONkws zn@?38*^*V3-B9)hZbrjD`2u8n)d*%k!o^ZF{Sht-2W|$A1Q2`8wuy&BRj1g<9UF0F zrNK#A(NM6)*Qh1o_9R(D_h-*e$IZ|~@sy4E;9>#26 z2hDYx6yozY29&{%*&v0Ure@L7qU|)Tq5}1*Dwd5d&6gBMrjj(3>&QT&hq4r;2-H?H zG?Wrdd?7{HMr~a|mWNm+-dd;sFl(bI_+vROqTJ00gKEiPC=7gk*QC!*13b(f(;M%j zLwvgp@7_iMmXXezpu0^`B5}>$XyjQM1wAbEnkJlEC44npo8Wo-MOped3NldS0jp$d z66_Oc>C@;vTqa_R!F3$^Ff}QQQd$ju)kqRQkiA_5TwVte@j5~oD*))!Od|LHZZLI~ zyRX4Rn8%$vNgcjhQ}VOfcwLiB+e@dsql!ca1aKcI*}{V%I5D;23ZCp;#RV^CdY~rY@U* z)n^>A-UFXO6huDO=bqy+^SIOwyCp%gRei3#VP)%ijz*FwZ@d8TBb?-T4<{sfpO4`r z3&9j-^b6N5?#A(KUqF&Rp-?p{QwQI83Ed3!`R zP4}S?IOXjTH^f^b*S%FiNoC|_yIs}rIi_D6!6@73$=HDVVQp=<56;JUkF$^nONu<1 zrk>9zPgFEUgcgDke|~a4IJ|m2I2oKB99>);53fFbA}(C(0oVbzxBJfeMh#iZvhVhm zJQvdO_SVIJ2lyXiF}gAMH;N;C(At0csgE)*%aO7N^n+-cLWF+V{-_#0HyS9o9^2O&69;_ZL1#|-Wd!^72g%(6l_#)kCNrR zN57Xot=x_5AD+cN9L8zp^zdfa+4kJ)sT;JHXR~4>zP(*@yZxhS_Xc{g6%BLiC9PvwDi2YpvEolH|`OqRg_QXnS!rN4J1^Fd88G4R2{X~ z8F!Svk(pz?jyd=ckjfa~Gw?pV2k!SzH=ly1pU4pxtg}sghfxaL-rhbfvk+fjM9GgL zI3czls^+r^+vFiDp5_!36455iG@5dr=21rrNVRpitY6nn=fHKdYysQ={{@MeX#eRM zyn*Rc;JPrn*>^0<-T2r6F3l@x#)G`#YuM!`Mq$aioWW?53|p1cs)4Gd5C%N4GMX_@ zNY|a=o!SxNc~gL$QUCQT2NH-JiXO`?(NVR&|VBsL}R z7a7D|*=cGP7&Avlin92rlws3RadUr6w6O%6-xvk7=r1QwSrHUjX9w zxAIL7XB<8zIGM$u-n8%)SZp?v*mrbeMv%cd`sJ^`_E7>S)Qtbj_OJbjt(DuS;4{cl z@D%^wzoMr-N8+&Hns1#*JF7NbVQT=KonId9f#W($8j#@wCLd(WT3^iAPhQ4j|B0oB z-qV4nf0`Nm@U(Vi+gFjabeCF3^3s1?KE?8>Hwu*7%EOT~#cyx6<)Q&K0gK4XuYo`-Bf!ksNJ>SQ3 z2FWw_$F0*Vp))+cxYQ6@6%~sFc0@%Z+u_`%f%XbzmMgLAjF!N4$ynCKU{=*u8)&Jm zc8>10iq3b61~dDi?OZ)oIDT|=@$UG*!1POD(-IYYBo&{3`b7RewODM>b9j}o1KT}t zdy8ck{STdbEL@zPa<<|OSqzo) z2^cSUHmtqo6KU2}*yKsx8Qi@VFB`k>OOM~@HOzs%*Wz0?^Hc|uhR(CmzP&i1$v*bB zwgf-4>7dBD&1^?;0;%zc9@3#t$Q(q#1LHLQfMD9M;s)J`?Sq%%$wB=z4#OatUV77F zB~m-rGA)(LI7>mObX8d%Y$*<51z1^VYt6av#tQ@A%OGvQyr~-cf7bc`Ud>>bz!def zBwW_VwA%mo`LkC$ySo4Ht5-XZ{=fI}`}Aq+uiz$_?~$O7>mY>WmVA!MGMT|W@YgNE zc3Xd4JNlS#cUn2+7Ga(K8vD*=d9d`uoNHlyB9X;`&y_@pOShA)zpe={ex4Z-kI)Fa#l7yhtU;7DyEX^b0x#?x#AF!X6IVNwBu znmUO~=LXAQ$8I?Bc?hfbz5d$qHDFhX6o^nZ=(Q?MEtaXJlSqjNj6B2EO0!~LsivEJ zAJLF@^ccZ!&Iy_{$s)VuWkt?>7**hBR%Besg3YYfnzmKazGMKRJ%>TBj~X=*YM&0H z=>><}PU)ZO0NgjTRteDiFCkS1-X12KVg2vMv(Ex=SLFf*rad=k4Q#u7UFw0Y_P|@fqRhy;TJ1LxMB{sYAv&jQi>zRGULIlWP7jc~F%9b+? zzs24eE96)ydI7pT85zT%L@;0Zg-cP7vz+>Vqv#1}l&0kQDy}$8%an zpVbki^(JWw%o@ogRpqQ5SR#Kb4-fxI?k7}fWnSrZE1*QBURyE^#FezH=}}7owM7=& zWKp|bGBOnI=?I^lC-Hnt&eHU>RiiUAi&DilO0n1eEZR2QIcu9$@0unvO2wAwR%?`{ z9OxwiSWFt_+V5j{yISTIJ?He8F-@HAf(kP#R)b*JOPn7s&Pd*ivbL>8BBq$ z^wFBoq|*WIvroO!)&fLRE61q-6Jrn`0#tR_Q-Pg{W1nHhjs2FUg?C<~xNaEFR~$C} ztXIzhyf26S!)XuJdU}zzDdGK5r2j%v3Tr7BnwAG`gXNmKj?=l9RqV@(gQ|?5?%GOF zvCI##xrKZ2A3saMYDBjRPqkDgpsbB;;;@GeoR@ea-+6$n?T9Fanw1XG0-XG}Rbp=#~&A+VFH z-Oi`6g{kp+1NCPKD{f0BVRY+^L+IeF?4fuK7=i{B60OW1JO_y;{CRc_%7~|4Qg>g1 z+xz1YZFX>K6d39^0y6(np2>zyltD@+WZcYUW9VLPV0!VylLb5Q=)HPty$DFuW2o8% z7---+loYMD5TPPpVd;#=Mrh)v{Q(YwLP+oKV9H#j*y99$lspY8oC!W)%n^qEMi zdMOCrvEc$dJs?10ry%v6S;pGY5Hu8dia^p84lczLQfZu|L>b0mFj=teMN1%)j=hO^ zgJH2Q_kaz+CXm|DtS}^u*z!5SN@@Y-Im+;ENz(3Ow0VL^0!u1psRL|EWOhlU*J^NS z&n(gxcz_U9DN5CN0#woXFo1avev8QP66z(C<^4aDsSxc$pW` z%9e76eV%BB)Dtn$XhY4=B){8tK7Rc8(dpGF1@$vU0@JlS5KLOloQg*jK`aElbg@>j zj;9pc!3~Asmf5Mxb#|KS8>RhK$ek~jIHgE&RnD7IlQxAXr>aQ1Qk8L~;7nz*Hno{5 z#6A<{W`qX@JcP7%4#;M~2e_$5 zq{b-_DD+q6hDg+k;!{!RJe={enHQB4DBweDV_vB^$cU|_bzW&1XjeIyzifJ9uzarJ zCV7q3ti}rOwxbqd=d&{FVAAP?r3rVb@G9}vJu)y~PVE@ibU0p~W6RJQaw~6mM||2| z=34p9FvOO;CdOLDWd%X*n7_y=xGEOochbXHB@9*P zCFO zt%jhS9JuT&U~SlhzjpSl?u43^s_`ghmQN=Uh}Ow#Arx0*v>CgRY{+En^Og)|Gru-r zt|m89Hr6ut+mx-$t=q5^gHXd+=6(cMSeP2A3fkq*F4hWD7|bz{x^HrIDf407PzP&a5JKEaY`sUeSYx*yz zw`T*v)3(%u_#b7c%G}!A+&GJGZGD5nc;bb#7-f6k_**20%s5&l7S%@Q?kS{?2oE+X4LpFY(4f7-RuN{U7r&WM$y`Z-R_hgj1a6aG$s% zr^2z0s-+RF>AH*q#^uSV&XuyxbMi7oHO`aD9w)2o6P(ru+s*F!eG>f=O9g zp%vVD*pL~UVJWVNc}$f_AvP;SbjAm-y6&tOj=6HNuJU+glF5xK{d(jN8@ljJyzbq1 zWD1Er4o?=Cve~L~yDU#?K|FD-hKbj()W~Nc`${ZUd{^Q&g>}{?&9t&(Mc0=)Zl&;R zee>iKtYgD6&>dC#JytKHa`3v(pLyg=gR*vRP(%%VH`Yqk-kG?N=Utu(K^l&w+h*-A zm;a|O{}V%LOE|Fg7v8*OCaCKCPun}spFdagKke?k+TDH3|8yTe#+LR~SaL6@Ed_Gtmy;z8p&v{k6e9n|0}Var)Y4g=c*pWQYDG$Lj88Lz63D`EAe z*XUjTn#zBk4#`C~leSwxjr`wzxwEaw|J`TLoV3zt;$o6cw zk3zpAp&zFeV%e5DP1GUwsx}E@2xenQD^jLWN9`!qbffHKPFw7bhKXf=paf3vG-Qhe z?iH>mYk(*8KOXLZvp9llfL2MNbLO(8nN1RxEhlEvD%C5{$y_Q_K-*( za0mRDrJlG;?`nrPK(8*nuMwEK!NzH&1etr;WJVX}DnjG|=on4+|HL0Jaq^?Ty8VCW z*-LHz-+r~a6UkDu(*&`1Z+*IOd&qq=$^@7rwoOk~?|BFxLI3ETXsPBD!A!vLju zf~Dl^+@Hd%;#Ao#aQ0Ed_|H04@}1JMAz>Dt2T|b_O4`d$jJu+_Srw6#mfpv=k*9U3 zJhOLdXlmZW$h1kDm2pwl?P)KIo&Iat)gFIMe@*v)lzADv&O-#V)_Oqo{{QUd&a+qL z^Z#T1|9knZa{jN|;ANh%?D8Y_$>?!+7ZeYd+21SAL}6)zU-~@!pp*~EyupX+84Mf^ zbd#$2xGUp@#a8iWHdV00`Ppi=!6f!iy~vxwIgB#uq+-^U%HLJ0WqIOz860J)m%%Cf zRDDLpLKgq*&CB_IwB}{#C&hh8=Vj>T`m=@DKi9{I%7+V%xyR2(gQAjODNh? z_*-O)&7?b-K|c>+dZu{5Dv!;UWu>8_h#3b~&Xv7aSr$`Cs@<<0hj)D)L_xNYn43Lm zY`v)7@;UtaSrv|MWmLqxV^*oek2RszHovI0kkRxw2F_#PhABiaBXFp=c7P-FZzqeB zIE<%@AK^msl`bCIhPSgVb1h-?Ea-X!63F`)MHKt6@eqjPe$5zUfOG&X=I_0XXT{g= zG3t~p8+}hdwT;lWotOZRm`+oCEI;jL2`T+FTt*GhpT#H}gn^oGS$fzF@^UZT;hx1I zO!du3de{x_axY!tPS@KgNulQ-#1YC;FNiW_B$iLQ8kY@&?narUL7WEJ;vn=8QuoNx zEAvst4xlLxX&z<492y|#Z;Tk&n>Qvx5m|6R39F~9#QVGQ0iEG^9+XpimZ1Sh*s4DB zGg{MGGqNU3=Rrg`{!Qvl;1H$(=`@byO#GFf8A;g?a0yK%^0lmM>)oiIcde#s&{sP` z*@7taPD}h!xHE89d^Zab3FJcJ6F`e{nJo@dJ+8hCmo>slvBAV3T9IN_%(hTcU-1t{ zH+#~b1;VF4Uk%R>ug(UiN2B53;7Iuh(7?R!(|Eq8y#Tac=>@zlzhUq28E8)&=?i0L z6&^pFk1nr>_ei%`up0At=hL7Y2ywSGkUphF!%p$p0I4AC2iL0T9DPiL0bSaQhT$A{ zO0i=RhzA2yLP1siRp26Gk#w?M2VeWbunJ3<*MT&*B!Yw|KCb{V4zkFb2V3PYF$gd6 z^#!B1*bb$)MG~ zY=c|9JMZk4kuEW*HWEMZrcsQtU~(G!(2O@{sFk)nts@50dOS1@1+Qk~Bv4S@zZ5dDq$U;9bX;~POgR* z$ESmfpNVQ~aTC;v(f9Ln@PVxg`e_k3pI+n73QgZ7|*>RvNETEM)v8E z6a*GqI$|Nzb!&iiGdO&Aba8n+I--Yy3Pw<9)$6Zs=nT}el2gJ`r$P1P4$m(xug>0{ zzCOCB9e+tDQL-#FrN`0P;PuJT)$#D%%X(?GfXD$(6iX$ki3mC#-n_JRsEd6$<3tT^ zI;)E$81=Nly`*uRy+tr>N(y6lJhMh~sYS#3e}oH*7n^WE3&jj?uo5`mURW2x|)a-ylH#Xp}{WeOi@A2*`!R zFxvCjhYA)Zx*4YMlgN=QH+Gy_vGsqK7lW(sPX=#B)|p;cCc-+KcC2i3)5LOTLi*t3 z_~`7i9(O|jZYQk8sEzD=6y3b@QeW=3A2AG`b8;sKrlS?RHZS(fp%Sj<-*iFt;RGLkPkzfC7yBxBZB0ef8ORb4b* z&X{V@bkrm;<^5Q%9%$o_{#047<0K<*8)h6uPzJ1^h)!mU}e zbiEp`cCDA(;>@BhZ&M(f3Zq#(Tk&J*l(90s2ex0lc%jd7x1z)mHRYOibJthG7YJPR`|LR`lPUfBGf8E*L-rdpjzrK9+nE&-&eoNeF#tBSmL@@AS0wX_&rXZ$oZ>aPlZGQO$tZz`@z-2EuWgLIZzjb_?&xB4e15jS{^|8#^uyJ~(dppw;D=v!ex>O3Rl5myOb&xF z>x4TcGdNeLga19h*mu@9rZBrgaPDQn;QKP!3(_3Kil3u$MllkV2q7#2u}3PF2IETJD$R5tvD0VMe~K$3?QeE z5;jYr6QENMWiTZe&B;F*BGQ{mT&{yP0Foe@y24-NYg@xhQ_#WZZGRp_2h@Fe<0&S@ zQ^KlsV=cu7)DW%ZN#FDR0B?g{coigQf1{^ACHf10{$Un`5KLhfCm8}xuovy2JqKKe z9yO)-v0%4}hahm)KjC+`4hSOkpx+}R9k`x`0r>8_@4)(}^Wo*-;?369<`%dGfB(B` zk}q0Tu*`(}>l^%^ zlva~O3W(YIEB}MO^D^)c_8?ARgizR@MAzWE?~cw-sO(SS@4u3NrSSKwqFNBx2RF~I zQusT?gr4E^0L`FJNC5UpgYpXj)$opX^b3Ow=$~T`1rs@bbRQfH_P!sSjHv(Qd$@Ru zyeaN6ilYmdVr%qzE0Jjru!aAFQLBiFmM!A4t<6FNG#`VE8(~u%2nK`nae5y6*8==kQsG z4$1f<;I9a>kVY8dbFdFYfiCj&c-Y^@-F#Bx;BNU#Ou(JpSN-k&c7KOFn@FHBY6lR!;1!@~aT$6HZ&iW?|_15V%#Fp;3q~ssC7@Qq`e|&Ppcb9$| z`B-;gIAEckA`iH6o&k9SBFPSRx1WDYCH#S?@d_qk0HbUR!Sn_zkKDY;0pexrM(_i0 zF@zGxaz_)C0vE49;A|c2za4Fz@1HKfc{=r?0MUcd*7@80l8uJe`;DWz!f(SRskXT*klySO+1H zFh}PI0uM=(42DOi^!0~XFqx5Rzq|l3ZZM9s8JI&-L=%&cweoVTd}dhp!TP$`XG)_i zamPPESx2JHeP!1|vpC6sivawXO~ZK1NA0H9;QwuC^YK{%_W59dK1<|c8{}*r`^03f zTke65h%Qa*1iVyXtT5>wAMQKbju9R`EjY4VcJQH!2WYt4&bqGOOWS8xAczU~|U)zyD{ z_DawHyS@AB)ua9YK7Q6iaEEo@>W#gRR|5ZWR|1`vczZ1Ew#=_i{u9RlHw;kwwD00q zBmcK|UcS)f|MSQCpZD{_Ya#WbDJnr~? zl>hJ}NeU3U-el6c3UH15fAwrzumAh(`D6W``}uvUs{hAUxvBggXNUpe2klF~;E5^q ztf9*nX}~TT58^z^?eh7!EvA!0hX`jkl( zAAVc`vJh4#OXiYbNpkWs#^iC^*|EUw5Ze)nYrep{lmTh^tr8&JMQ>FGS^&H-j3-_O zW!^fAeMoYGw54MuFgr~*;uLJGydZkZ!Ql8gJ;wjM(PipgUk4K@7jFyLMj+~ubw%z% z5MjMypj5HZ9=65W2(w!}solVcEq%3I{)Ckgs@}yE8YKBR4AAT>&Mu(mF9yD!LPW}j zWNB_Gz~62jFaUEFM^U!FB{V~NpOv%r9M{s#1)k5wD3TZ`4gYsFUds%>Wqi59vzhj+hX#upNF4S=UPyF$n`Ty*^d|vYZ zeD>^d|G$^tviCpiRU$k^b?w05Gc@rMZybcYnrj$L7X6|Ly9S~v#W3~{1C-_o7LTuU ze+sj1oC-kiQL9){tKeIXSuSIam4bZzE6ZP{AawR52CE{ zqMo-?Z-7n$l%2q6n$0kb5Jok=1-5%62A!KNm@bMc zQXAAV`nyI0`^b9q24eXOjMAyQZeNvGs%3K>u}?-_ZK_}GQJqadxXi9vb$$p-yXw+s z&xf$%+vrwl8R&wJ&3y_C`UzWBXI)vMlGs1>B5w-kFv<+&IJsU?{*1QgNfbf`u#1i) z_SF^IkpwB=u2xyQN|@Y_Kxvxnxs?lgnOX)LoxxHGs`CC+yS($}Bo7(N=Ua;Nv$Ew; zS3$7ezhpezf9)YS^s*Un%n=n%k1#2kdAl!OqI}+Na%-s26+>DKmP_S`C0Bt=P?s=N zN+J*QFr+zm?GnXeBAm>ipNB9#qtX2AW96~YPN}pjnKw(rVjIn1GQr}zBAavhLnWoN zc@(o4WrHyAkeu~bdf3TED|b>qwYF8P@7{{f2w9Jk6Uyq!0SDg@VZ|LlU?R8`Gk7I> ztO+$<`AA@g)pp}@VbF#tL^NSE+gcppIKau`Bo5>0;zziU5>6KntyKWFExJPEeOS=@4_utD_`^o-e0ulg45Bq@z*U5a?`-NgBkY1b^ru zq;7(xSH`1^y?sLr(mcw7IWz#!-xyCt*49l45c?xI$y4gnhiO`_4}sJV=-eu$m#n~w z`b*$5KXNslFB40`bRI;6(ch%r1P);ukUrzcm)WxFGZPsb!mZHFHGo(K9`H(mNVU1q zx)(#-CGn{&SL)#8geeM82BV2oroDyvuASwsA~h-i>Uc^gh3e6Ft7dD!S3CT5H7_z~ z?ifJfxk&*~d;$Pb+|5?NG9KjPQf(8V`x`7R78w0Rd~PnFIicBP^?E64T3Gt?(rKx# ziVG*&lh4ZE0LYNH8*X2Q`RPADvOF$V1rc-!75fo16F;jRCfd)PU8=eOe#^( zQ7&R?&@9dz<#8CJ>~Gg`9+6$)BW5Jvrfg>1i@Tc~iDX4U(FVxkQI-bL6l_$i zA7n+K*8>igsan11`dzcO6X1wmjQgjx9%DTs&2ebjZ%wJgaz{%QJ*)!L5#K`z04 zFZ28$)kRoQKF^>K8rN4VTa~3mB1cMO@6JNx>IJ(hwiOJv{YD~M)ovXyx-nBx&rGb5 zlkD>4!q|YwG#L8EdeQ71tFXu{-^Kk|6&@^oapzc|%*%2_>_i%L10n8~29229YUHgg z;|A(WxdBs|$*qHdq10qaUeV_~Ha+s;$4wSEE;A+9b(NZ9rRtOB;%J{fF~H?*w1l+% zW1~>9K3={cXKi6c9fVeLqmg>27U?Ke2&mKhP#4#SDh(xx*xKDe!!E$s{W}gK;A}eG zK&_a3U6hk-VG%i=n~;l)$kn!NvgcwTOYO31!&duhv$Ixr2iFz7M@%~`?#K0cN6mKE zN>tl#yY=9fKFaYmu8vY&<4yMRd)vZ_-bX(SE{+bbzCS)O_Pz(4Ej05|=x+tlb==QB zvJ}t?8#W^GQmdvR#Lm@JI_8QE!SI1-Tf3Vy;TIqmytaQ>cil-!=9X+s+8*9)J+@zR z%~qA!;AK6gnhW1IwWr#^R$En%@` zM5OER=J5OmrfJ|a1;w#;^~3Su;nCUE+4y~-ISAse|JH9*~oLmhrj!y>{KND86N*T$Ju-#wZ(23sbuW#rK(IfTFzNxn~ zh?@mdJ+vl-u+v{sCYiVL2wDPw>CYhNiiSV1>R6~U3_}%!R_VkCGB|v9ba8n+I--lY zf|nE$_t-4h_|ZNi6&2_j$v+YnGs#gF&)*`LB4eIR={;t1*AC;*%e*o1;j_aL-`HSj z`G2I|Yw3UVf0q}7tGA=03qmI=A1Onw;2ygPs*Ir+S3@ih2bY7_gHb(}1yPs6l=Fv| zXEU?Ts;ra^8|{0hSH++kj(Rv4jea`6I5dvhyu~15d;SqFEZdB|%nNNGbIG;`m@B#9S@E>0Q+9 zmrVqQ4X209po|P=9$oIXX>f9K{?pab>G1OB%Au==yC`;mvyeS}6;d}82&11zmq({p zC+Baj-W^@MJ|7)l8kds73TS~cI6sM}?_fHPQIJ{eaOLg}k4J;oCr47Z^#dhiB*QIE zst6Bq#L;Nm`~ME!4MqnS$3wezTi^TtdN&@m2sQ2g=#2J${`TT*aI#F-baMYU&araY zv|Fh#dF{;VHqD`ukB9GGEna(yPHz6b54|ZeqA;sDE!8>*Ia(Uk45w?{~0gvfZ2;G z38JYh4g+m3^OSkHfSw;%cp+8Zb;t}_r>k>=im90$x)_a-A5v{JUpGUHGB3^Y#J~^fO3Nn@!FNu}MVPpfOjN=P10Ykt|$k3Z{K||J9%4@0A_N#ECXFS4vj;bNB z&#W%Ft2@@3^vWO#GJiax--^nQ=GRu#$l7!9w+-;~uNx-iPpMG^;5=F(33jZH~L z%~-8rSkmFB1GdNpVy80xpaT0i$pnRYnmycTORmjmV*u+nH3qWg{%>~I90if8&%Q># zhGm=!J3AA%cb0E|w0S4Vue&;9`3|-(h!O+_nH;); zACoxEUW(j3A{V6T9QsSN_%7i)#_hr7V?6rf*|1t(#bMIf%{NIPQwxY)lX8!)|wWgkz zn)7UujN-|A!>qTR-=>qklpVI*xTCmh-2fi=aN>2ImP>$LDj^qDC=5ZLR@8P{z8#o+o0)s-hFmu1sQ8>}TB4n0y0igX?Z0)yv1Xs< zy%-c<`;Z>I(bZ~jCGNO~LAnP%RSwi{(r&RXG4W+%7X_`9jz% zC6rrW=m%=ne`%p9L#1EV-YQdg*4v4)aml!>4Wubr(zSXJdcmC6IS|D|^>Q7+LYsQZ z7>dRM(0!#DTbGT}n3q^eu518+M|MoioLX*Kxi^Z%e1*fKrXZ zn;lkZP<&EbXHYf@eBIRsD@vC?;EH~hLifw4Ssm59m$0Rbv&vqe@^sO2U+#E!1v&b) z{_5mEzf?sxlcfv5*U10f7q6b__1|B-daVC@FTZ-1JELG9QL|sISZDCQa)~b8p*(zv zE?Kw5B@;8!$_LvPg5NaoD$wodPF0^dbdT|=G3``z74mKC*pZMI0vzB`J^owSy` zLtJ+6SJ5t^A%OI0agNEnbPBVf;npxo<1C)U;U2g=;0es=VxMJM;#MpVy=!8C|n4>fg;c_ZK-TCjut8H!n-+8|Cxc}eF z&v5?JbpZW&!4emkB`m7KJdT1aPJ?LLpTsGQiHzJ53dB$WV%8&Svi;R-3>v120@0D; z@PPFJt2EZg;`x4n_be}53hzqMT-Q|#InDRQX&UE=*zH;{3$c3VVT+2n<|(m^jexGM zg8k5he-rtSTABKczZ&`f?D@`)D*tz0?d-mIl>hhf!z{U;pk#341tAvXU~eC6AUMB) z=|MbCyc7cGyPf{-3wK*S#j!;*@e*$wgtR~}R(_cL$A`Ke$=V}rFls-1IY~9mXiOC= zz^-p733<77vonU7C$ydCX8l}F7jxAp3TzwW6u75B2~_sLmdo!R$kvzE>X(j}MCn2_L9mLzd!0+FuGi|2zs8 z7jc|@AB2#m-75g6@b^4Op?{dh$$=!nxKc4VIawnWifMJiRS4Rs#G{q4OIk4jtq9ydzWu~m(yKBg5l6c+g)Em%U#|&DyhR{hC0`Y?NHm=R+5-%CF-Qf zw=haymQ^6%YZ!2Ad@a+qug+-Lps(fbYno7_J0`fBo0}$-DsFMuz~S%B+o=H;CI4k! zET926tsp47kyW2EVd2A%%YYQZ$8^Hv`_Gai@3ltgAoLI_50X4?Ja-m=rUAAEN1ZV* zh$db}Q+}(2+pW}1)#;iZStniwWx}7uJ|q`zjY(Ds#ZJDBI9-iD+BN1FIlLSI|N1iZ zuCIfMlp&}IP-AP=jI=DzAV>$}`u5b^cc zQz5PM7gRBCx(^6&Vh11&1nemtqJXS)s79$2EuuUO*DUVXiW@_XT4`Ud9e63U?CHUJ zEC3q)p26!pL@?7DB(d)n46o?IuIoP9S|0kZh5d(D)obkwTIc`ya!2?7e75~)|GA%E zap5;IQH%XQ@yB=K|A{w# z-T!lUcjs~czmMPY_dl2&%$_<1*9yf?C}GYFq6ypng-g$2fYLm{^7D1>Phs{II`#aC zw280C`=^96X3}{O6<%kgo%}>~EiryxMHJG)`}j8Uv@Voq5ppH6?i8lE4LKW_`)9{SxAFvvd!Vc?|;aGggJLVoJX3A1!@^#>y*F6zygTy_q%)U&aUYj6hfF> zWx*Wc&z|kMFG^pfFw4{Eim=cA&YF~_%JVS@*W=YNz<1w$2b}fE+%I5U$0^v@2*5tr z0e=Sp_->!$h5!89{toE%{to+pZl?G_f;D zW@6j6ZQHhO+nU(6pV&4gwrxCr-tYbDUps4UbXWDxUDX@iRo8Kyu-+%zNAtX1vQ~Ge z@717#QrX#6nt&6-10V2K2O*(5?eGTDbO^E~RoZ)_6Nh>rWw*Dq@o%K1L1TjgiaI2_uUT)u1`nC05)B3A z5eP4!5kCCKeD%BC#WOY6jA5L9r}N_Pb3i?kImF6NnjZbmqZ}lcN0vKb|vg13=qB*Tzy;--mAcJjBBUP7>VMlb=_R*p(iW3-0@=(hr1r8G~ay z!lH;`wdWq(Oh7(0{J|b-uwZ4QW4^r==t6t<>wA~%PY?uuQP(pwl7T5~3D8Ce+&9SR zFUpN9$K)0*Cx{ma|NBAT#?IOG_VscwO7VBNfx8@S$)~v=m#%WS(X{_0G)=0}8yjlh zN*O4FC3nu(aogWpnq~i&sH_|u<637)wP%sltiF|PU0p*-^IQ~-0Q*-DS4SH+J|3R# zr#)|nG1uO(+xg!jj?PPt5Cr1apT7t!JC9NOF$Bljx?S*E^l_a#djv2(l}_2WXWuWM zo+wP4(b{<3-zI8b;v{kt0KG~(y89~a^}gQFUr?@|JfxyO)v&ljd=}b~Yow)+h})n* zI|yTmfP7xS^{tkeOT@hEPYQa=4l6gUh8)&Y>+2j2zY$li-1UgK!;%HEPC1B(_+SPR zd+5yk}%1_6+6Kezo5*yU-%~k&F6&nQ z0oYwaXv7fwlE+N>{~+zfkEBafd&h(|Gs^bJ^Y7smdQ0L#)2TsB$a#nmVSZzai_fe4 z@sn!y*j7pxu8(BMbs8d-JVpBma~f=E{1M4I75Y$-!k@?hnv-;bZvwA`7671h*vD!E zITcxOP)n6_l1V-}A38;gxe7k1CK3T>$?J~+CDVtX*fTaWghe4FOur*oMGH7*E3L@i zpeX4Av5Qp8-w{|;D1MP+$d8s|q;njKn`unbhY(ZJ#b~6+VCu$*3eVWfn&Y03@82rM z&h4|lEihuNhcxE~Q)1Lt!+l46Vjm3WJPK}gh z1Y$(777ki~w_sg!ksFA53#eK}}#;msB~%+a)uH0|Y#FI=&0M@4(bJygRVIfb}vTPWHdp zuH5yX`p9&)KlZOQiCv3z*Ph<4D2$}%ldXOfGJ+Q~uq=y=@h&t3QD29Wb%GJ)fMHG9 zgLUZm>L4@T@j=V-n*odx|17{Qn}9=X(gLAK;Nu|Z4m(Xo*Zj})Y2!j|HS4gcNc2Eo zgV_EAoP-W3e?2EV)iPWod`4sN?O}Dt!z|trk5gop7m&sNbs7CCFq^$B@WKkRD=?tT zA}dvtsN3jshI&nRdulTWCAi{$9szzrc{}BW-h+4}-NWZ{f9_{}G(?Q-$So}tFr((o zcPrK749o-0ifeX#JxGDN8#(r*=30q!ApmCZWhE4<9S0y+f2(L;BiEV5`|sB zeQwY8p7svzHXo;kmd2*+43%F@3KmaSMz-JHX<7}W1P)7j-kw&s(ZaU)_pt3OIAjbb3`Fr8bfDF7oI(D;tH-CJ8vU+=uvg_#qmL$1V zyi;3d5@keK0!-8MQHR_7#q@qv=xyEhY+Hbkdx~A@P9}8*a}zf-H1#8?og+@~`H2^! zPaKKsRuC1SXX*vO5cu3K3mnEk^V4TK=4aSJa1z8IMK&>mlCbCJ5zgmE8Mh+{QZW^& zEF~cxIRb^A*$MB1^DjcC?I`DfFy@DkNrSYd09GIP6+v=?P9V)aYzVdz_pkMdq zGfk=}Sv>=oe&&43c0Cg>9C-?fi9&K=U;Z zI+?mMJ5=bvm#bvBf3UdNfxf;HHp%=Lqj4zir7U%S*z4N zF2Q>yK+=IHU@Bi~(qPHSx7h!1gHrF!_+ryE^tH?=JGr*zqm83eMc8Pu7J3n?c!V10 z`K+q_3ER_)7(70vc;P+$^}-{6)0g2Hsdk?nH<(-AF;L~6F`fa1*^W{CM{+O3TX+O* zGTwcEcoBtRwKaUqpnHKrwVpTihBkT?TY$j97F&Avkb15H9nrT4u7Xg5r{A z6zktWG|qd9koz2V4A~CkXj~ca3X6o1c*0n_Ai2}rjX8HUWD)lP?oZ9FpdSdE9>#`R z%YB%D!|K`PXg6I4<0|=I>YD=~cn1tvSe_+ewb`*)`0HU1+^Hc{)6Yl`)m86)E3xXV zMHwvIt?kU75tm;-KgTgc>6hjv$EhFD`Tq16%(uJ{I8i>UtsKd{L8DjaiEl8FobZ4% z{IPgkb$~k+G3slO?lk6s zb{1YOKiAwc0xm88wN~XVPH=l&qB~UCIDR%=Tvnf9s*e5rhsNLcFCv#5)<>lXNaERF zn&?YqOVg>^<$Oo2W?qKT7|??Ea=J~wS!#$>s~VM+ns@?BYES6sjWuTxlTC5BO{2oo zEU6ZwCsoKPM>Hz`*Caka!gB0uI#TkYT$RANnH6mK&LAW8X8@@GchE6NPz0=nlM3nc zG1w?d^mKib63SY(txk&~^U0c%AMLZT#;+d^`+_U7 zZ8jm37q`=#mJ#Me%N8<>nHiy)cPcQ##4fOM&wdq^E#SK)k08&MSzwM|c#*=~J~wWB zZ^cEMtCEi*Rx233cSc5(?>3XQ&{f+16%&Yl3imM>K|r&At?YhFI9qG;&tVZc99_j19PtAR!uj4(5{q8*XCnlFY^Q z;4!(&NdEYts+KIqt-^d0q_O z<{zw_#NY<_yV}gPt5m;w zI@B%87-7`~$y95c*H;VlcqUQP^ra>+&I)Yg4*^{TL9;$hP4cW=;i|>IjO>CdM#09CEI@g>{PperrXD3q)`L>!(#$6837Aw^vWnf4lG#ZR{fpC)uCV{0f zx|x`@us!_g4dKTnMhm(i&H*+c#Q|D|wurqsHVNhW26N6=4AUd0Q?-yCa#`3#C zZ65<=p}`5Gpidsm!IU^js*HT_P{+TVq>mzY)~;Xgkme=^Pu%QS*+7SXqsx(W`X}^w z!*5lup)bPe+aWr$D_yMeFcX-@#* z7rJ(TSd}i<*JO}@j+fNDoYmHmjinKd>IXM68qL2Cr4D6tSyKFrxj&(vm6q=pu~;-= zK+nAnD21?deRcX%yX20Ncd*6d9one`d^>pPV*ZY{|6(9&+@D9x_Q_}O5ZFJXJ7eSc z(2UXI)?3=8_ipGDEuU}(;*4)%JAvH7PD;IGcUs2P@v6v^u&{uof+x|^y zJa7tA&0oeyNfjCPR--p_zc?AF)j zr>0WrRi@z45`&vnCi!b1goJg=v-q?bM5b;dxmcRtUV~T_hkqIyr8EKN~!Dyt}R+*-}mWY!zW(k!p|Ksg72JaMuA$cXLqr$>t5M+oLZ$=MQICCN#VqV`eX+mifN;Ati+iz@U(xYMQg35g5S=wA`_;L z?>KPZtXA8kedvj9z%Bu8;_fU$SlUpo|HsN=K@#tDXR8PE_x8_bV-1jrgXTaN6?-WL zT|8NLa8%NwYF0C;GR@_5N(F#PxRjA4)+$!qoH;|}oE}U&RsNKp7NTQ$luNHy+))~4 zYprYz?N&|>;Ny_&`IcN7t^vaIyZt+#C(m_i1-uWMh&fvh2V*-oOU!qi5#L-U+q|pO zM_c1GidF>l<#p!M?ejj14YTxktDPMqVK=oc!S!F$vheu*l{k^%iNW=lE%ue}_uYf` zS($ilSeo;-{RjbYCTb`8`xa4sNxvzM`&8&~qz^SRl9Lgxnq_%rO%@z7Hjg$}qjlKT zu6&n`08erNcaSvLZty$gIpb4MK{Th{HRjvgaQ?P2d#iT7J~r{PJ}-;TsM-)w<1i_e zAlDT&OxSK({<1`&63n3!Kz^S`B|{!1paWCRWE|$Fb@4XrJM*X{;QV{Z<0IXkR5~R0 z!K~?qey@XjyUTRwJ0<^LzDU01l0w-p%k50mmS1~i2`YyUii1MgW{Npe=X399KjKi6 zXpg_Uxhb@B}4t9sv~w_O)|Mx}vhQbb7$ItB^?e(qH&2HLGx93XlA7^W#4Q@{!{1olj!O!u~V8f$1dX-MD&Xd1gUEFLPHl)h4 ztE$z>MKCiL@7f4sXFUhB`x3nxZvb0KP8nS0Q zV_HX%Q`@XJ7O*82S(}>X&K5;RYO&p+$E@SZBsT{ip!XQU46W_7oSokG$J5o@$I<56 z#8L?hs_9UaRdP;u)xNFV;QLY>L$>^V!1BwJLbq2ytQ@ONotM4a6CuDLVi81*SdgyA zmZKPiUZ$A613Mx<#83ixrRLvhu!K9GZtjON(SoK?cPP6S(}#(6X&UBnt!>t>&F`rJ z*x(3IPPwb?-pSYgj*7P#OE&pewc1YRMHkckQnl&Y;&vgCIQ0}*%i;Zp3eFXxoVOJU z{)0VmDI>b|M^!`AgkMF;Dyl+d>)Hs#_fiQ}Bh_uyJyxLiB+|nbWyw z!1di`L;Oo+r;sJx)E3u!3XzcQ`x%J*H0fsgxjY=4=BZ^gY-4>zVFwQ2Io5yyilsmN z5@bV9u4TXWfns8n!)ug{(OXYcl2zhIqLnr? z6s}nfZj-fFUg7(!X;5P)b?USb8S10)q&%T`^|yO=F!t=O0rZ8Cu|r6sH5_^?CFdcK zg^?A~Rk=klFj2L|BN-gnb_d4dKBa!h$%$Q?tOqH|8Q*AB(`|yoEVWCjfFOkc7jW;k z5oJHdj8JK06DxgHXgHR+%egK$ORSHs)UixEHG%6z=OE>2bhEj9-J-gGu5B+hI-%(u zR$oJD$gHgnsk(1|0+q&w*ktL;fcgPH3GoxZ&SoHP z-rT+Xuf0oq{A$dQ5S_r247Do{-no+qWyE~2gFbdhuMv%rJ6b{QB))U=2lK^{p!{V& z`8ZN>p3{ZCbgHJf@y+E?g}+DWCWfpDcUMt^y(0skP*7K3@!p*(a>-Z4UGm!ydEN&M zGwcn=g3V>~`}P}5=iH3rJBm?`V+WybfaYOS9By+>)->08L2O6O490X@Tz;eLQ+J}J z)wuc_s^Otd`gn@^mugkk*&b|y(S^opYDY)Q3I-`~zpQq%+fVi$@Uz)PCXQzE<7sKN zCRZ)fiBA5_>(E?%lw6Xc_Nx@A|yLB-YRu#*Z3?q`%Sk59Xr z+Lkc?(hq*NYb4Ll6Fz~EYBde2Nv|1uS9spV#G{p5x_V^IHBdfoucLj6P{U@H9>eA} z+4SpBEa5}kaJNWRIQj)7ZBgC3i*{;S-&~(*LzCzI_FsmfrYReVE^5vic@`37J(JS3 zQO99nKQGg0_VK3FqS!UvPQiGUgU&_;v}hWp6%|~-Os!9MZgIMscg|Z57tCg|T=_TE zV&QDR7XW7qZWgT?*PG=1uF`HsUK)dAiC<&+n?s`U4Cy$e}UIGo!5WyQ|^FxJU&kkQeOZY?`W&gRu%pUm&?6+K~!$g2=sXb6F>1 zZg}o7%z#6=jZRjdb>J#XguB2#kY>oLp=!SC$@(I74j1xk=(HPXc=CxZPt>46(1FAuNxCRK~|gHSOO9nF_}$jK@q? z5kaxEKI}&vTss?T?U>qBE4tvVC)3)cDz9vGyr69KOLe;ZO+!Bpu~)O>esj-q69u}-_W6hE5uQooGS`q~;Y~v*8ib8YS2kKr zAB?}EuW^IsEakN?%%gsChybcFKQTUTAKwR&uZ`i-3mC>=qLlnP>TqTf5)2idwQxJ} z3uJBHUFJb_xUB}^hWUt=NOHrvQfquE8yU=Av?yxy_JR^PPR1)`k?Msd52#|oFMJcB z{Z<&mSAdap6dyi&+Li+iGN_Q#bjnDt`8XSxoXpd|B}He+g(RvMz7?Y zL=D*2kVC&%Pr1J?h*N3UD~X3ABK6wOPj?85F{4*xfDz1B!6MMMdV>oOP&+{V7G?#D zi$?o8;I*6CXXlcQBBF`Kef(TsScQQj>igL#Qj$d^_{Qj_#Utob7yF;zjML5bBdX&U zq65mVaYF;vto;{(&-15&1kmZ_$oWo4-b6?qk42GW zE(E1z$^W?P41X{=wU%uBqPKUo+4;@{FuI(5y&*6kOcpn^s8|F;`Jt49?kc0Zk6!vP z!GQ5$u?M`{&2|;Df7H@X`T~{}0Qo+yqQ3mN2x@m@jBi`lQAD#gp>I3sN9s~`Xr;;; zXk_LhkJzM6-i#p1(QIF9FeN{5UrlOXR54qP?r`kDQ`AQr+zn9|-ZPH`QsJs%zjBq= z?@z8@$=eXwoP_brG?oO%_Pme&94&!{{xY68ztB=!X)P_+69nCcS|nMVhte$f^Udk^ zo1Tl+#ZakKz*yLV&Mk;e>3PGZxo}_muv##sWz0?f8~s~vZ-67VP{{y?O7q{;EZ;G^ z5b{a3zZcg2=n`ECf7-j!h=P7?J03zyO~&6j!F-yG(FhrO?=K!n(d_VC5M^5Oi~S47 zE}<}zLJzgmvutPv|F38y-pz!*y@3W2u z5IBIy=bZp-xqX$tPPlBU?}c&N&^S2LNYog{+6t3X@RTHX8uw>8{e2(Fmw1tu1*hf6 zd-RmN78;xrRjN&nz!Xj~ooqs^sWL>eu)OUQLqx6KtAZ}wyL3UJ z`}#g7O~I7WoPfKJ#guUiO3(f_kpLAcUT4Cw_?hKW7CG8bnCI>p)%r^To5xG~DZ8l_ zcHjLc@e@uZejaSmDlA>EZSGeiXQWs0o+Y?4)nQ1Ctt+oL`wPZDr2gLQ0(g05l<{96 zJv{VNg*7Qroy|B>D5ANw`D{TE;l)acEZSVN9nh%|NL1PaKb+^I|LsGII4ZdH)~Lti zaH|fu=r--ujxus{MHtP#Zp;4Qc1)lbEHnfuy3xW3{9Z)yX9s}{GkE0jYX>+mf;M_g z+T#!@1mPGp8{c7cuFt<}UYuoqbewr$H+ovCCI=K(Usq3UyTofAA<$-8jvwS{o2-im z-}R-DkY0Pt$UH=yt)6`r(jrdhyMvnJ7>(@@elewqY`(ZtV!#Qhs7AN`v)io0ke+@# zw}nbNA(kz@S@MR8MR@*KTlKVx1wTAznz59ex{mQGu1W1lfT$o6b!p%juM>&28iOP$ zC(*G3U!0_tHcGj4S--wfc__fjSEB-0>u4=rlAP$tpw2gYD=>QNa*>`EYNaQkjR1|) ztTgP-Y96W;VEK_8QKV1ki`5h15EgwW@=(51R@GZdO}B%RM)|BWP=)rhT<*J@UU2kt z2tPsbtk?!Yy!@OLlpayyjfrl9p0L<2(*gIOSe}PRD|T|z*6n9%C6pBXEXwxf{QDdd zS;DF}I_ZVGf%#+e8=Rg^N^J#Xk&Q9^oMcn>QiVx2Hg|QQAdVY1wG68cnwrd8WPuSQ^EE4oxFFT`Odl6%Qg5$cRl)dIDv+Ol@tN=lB>2lm_?1g2g z`98AwwoV$MDA*B-|1O9gdOV*OD*LMnhA16ML%ZV7=PhElgEcBQDBIMw#b7cv!!#C_ z?aNKAA(Q4}edLxdKL`x+m;Z$_&EKU%-p`L0(M%|Z%qKM}=f5$}sqtrgu$1Wm+@B6f z9K8M>J@fT7%O^%Ty}y(Hqew+>LVdX|P&+UTNd|B7Oi$~7Vkb!2rP(Q{w(}6p zm|md8Eo5v$6W-ceh|VT1B{u zRj-s7Kgp{HLf-?gp)t)$&Hc)-U3`+{1!?IX$%IB(>ZV3 zn--q{tU9UAudP>m)K=p5P($7Qp$Q`gDJH+AY80aC6QP%Kwhl}dHc@cqxl(6dm9<5{ zEc}PiSoK4bUgqzqQ!cF7DlE?azCH&6FYH-jWSb}bY;1|Sv)DHWrqYNTf@|WElM}BjuLhHO%i8DDiw;jlfjLg$XncCyNa#DqccFrsu+9h&w*7u-G-)i1#GHRm;I`KR8!NN3eyU90V7?s z;Va&NV%dMGFEr{tx2nLci8>)@{Th}nT>IQ2>ns_uVBf5V0fB4d9~f=OKmgM%hvcS1 z+4DG5S4lSYUSW~N`5n|d`eD=SrKeV(rJs-NJ%@wH|6pJGZ|qx_SzQ~)GDSZ|ua!L< zub363=G)-3`$EO~m@$PKD$?n$4%Lho!*q7#7=Nb)SX2WN3{iAhN|*mt?NXkmuMV9ohq2LlxY>NHVMrK)S(NHn~PCRv*yW39`wFlY`%K#)*M z-(mG2f5WOdejW-|Mz2`WP|D$UGt*s7hYgW|k}7cc?erm${SXo_9e$?IQoe(Cohy5o zDtu%EY3zhH%gb7i5D5NRYvq3Le5C1`acVv~DM~cWx<0Roq)+Wh&v{P)^nJMs+ckHmpcb z+O78yL4J?doSa(p2l7%Fa^Son-F4#C+)5T^>*DTMP`C1yn18I>>!rrm%kA^+VzV-- z^8V{_?9{{J*AT;}k*Mim(fNNUucCur4q$9|rDAcfz8qmhPw&}oJK}=p}osS zz50D6O|5t(oeYcl7#8XYg$HQ}K~~NjQZPm3CGj6VYqK8Z?mxRP9gbr|qO_MG7m`MEOlO8431RFSwH!0l z9c{~AseO&Y+B@21C}b7GnSYKWC%3!$B@Dko?uGe0VbsTY%7mE^e0w{ZlxTi;{DXJvD+)IQSvdW;7>=u^@_7>n z?WqhS)*KyPbK2?g`KC(EbM39klz?2Y55`WmwAO{+E$47kHEJkTHN&aK>@<`zae|~b zMRk4l@pQD;^!Gkw7^XrPxpK`tfNL`BR4I4PakODpqI!**EG@0p&&SQz#phj%=JW|U zJs#nNdh%G`stnvs9@zSI`MT6OvBKBw<>Y&R=K|b&Y8@`-$4t&&BgyCzSc{jRj#u`~g~n!VjsQ%!$3q2TWDdGvaAprgIb zr`Ish7?pLuu(84h=-6v8n3&O7nF!^(yfB2KT0;F|>+w-uhn>BJ zar!B#=9Klv!}x1+Q&yEWWu>CPlzX z?fhz#Yj?`3aM7gRBtY+HzNHgK@-&?Y7~C^WPem3)3G2P)kDpfT|6!k#*JuUOlvd2WGOm(zRUrn8Z3qf?D!Ikl-g&S46xPenSGJHhZ_VeTEZA|iouODpukF%1% zD_LFW8@#D?E~hFIi?4;zr#eq{y{EKx?nriX!Uk2C<|to(hXRPE2FsAE`fkXrQ@ymp zIX{k@M`gu!x82)0VDg<>rO-exm1l`D_uY(+xxTQY%NnF7Jo-w0Sp;SRgOFWP&2?T& z^wUgUzg-VI5w8TEEa{)m1Yb=T|4-e-25)JX18`jmK*0^4x6>uf!uq9^hgKZP;3eCz zsKsZZF-y<1%xMr;m3T~f8lKk=by6@DI*QGmyB09jDLPj0zX4PJx%E?P2+3aR7*(hW z5iD(0gO#egK(i^72PC_G?mkPe>UJmW_LP{1Az@112ZU}piD7xDj!onUBW6P#tdYH1 z4Onda;WDb^gv~2(oF~IS8qNl2CgF;+9Io`FQUH*zmqPH4*Br-O1GkexMtogG5rO|; zPW1M`&w;z^xg(juoVAf(w{$c0QrsiUSWUJcYY*FRG);5M9{=H-sg3{PoHV8X;hZL; z-<-3d@qanzhx0e*q&571an72C|8mX~+W+O8JVyWJoR6{p7tT3Pt4dXSJRmP1<`67e z$HRBg)t$m!R~)=+UwT7{e~)S4h3|AaCZ1~BI+uQ5-=v?sLd|y=*SFhf7IuhiBk&iy zWWt)Ty@IRZRy$=-6iBEc*LSL7%Ze=D+_OBz6})vsVtewcsdc29bvejqWe-mSH`w3s z0B<(3BUC(w?u~%^@$)ceAh&i8e^0}eTJ;G&w-eUXTork%x-x2_L6l(f(Ztm8FE1ar zwK))hCNr}Z!{IwgB$M@B11kD_y#87pUzwg1X8gH=k)fP4pN1Es*6Z!UV}X+PM*=gQ zc)%P(g`H0Er2&t9KJ>=iY4oSQ0-@BK-ng-lu86zJ%FaL6SOxMZ>1BHJ8f+nMINazi z&Ln9uQ?l}PtShAa) zDh~rt=R=N`QFBHS7styFpv-;`t6}&b8beDDpWy*A>C)4`Veidp*~dD zjAayOAct5}Rds%}@!Q+cxgq4MyObcU4(d!h#xgOOHN-&>7ZmeP*2HEmcmTjU>_ zf>mt!>=%ABl%zk=Q3QwE%^IV8uB*=Q&RN~iY0AlJ2BN?)8XfTvU8{Wn^cSm-&xHOKYPI~mBE@WOXF``nY%y0{TRB-o>& z^4Dd&M9^6k_V(ges$|&#hNx+?vfjiPpH-i>;<^S(r4=PedV%|L;R5)l6;_}N;jOuVyscfLL&@r%)AQw+{21xhn*K+rI zV=(o>cNm>JVG`i_!|lzHy49Qde9o3n&-onNQv32N%ecZI3awpHaDx5xXfd+)*RX3d ztgGxkhY5LS+tr1NWb}hwL-&WA8KAhoMnpC4U>-W@2*gNCK}l=%Z5n1m#inpoIQ){5 z`__d>u+TAQvbgfh-^oLnV?WBs55cu^OR+x}&Pi`nh)sLkan|PR%v;~anh{$6W>LZy zeZ&|7o6*lpgpl|jRZfz!7LoTqa+FcrpVqAgevUCr5ErGe*CAE`r1Kq3fQ5(3A%|Rf420K zh^}qub%OgHTThro(>=QQtgvS1MF}>}{xdn)wz$SHqrJbHWm8F{+<(mz^e6SDR z37}3(@bl)Z<=iEB{sM6DaddKCPZg-Xm2CpI@qC^?Zpxaz8Nlx8H*!ds0e+NkT;44d zReICEz_NS25@2V3u${O98yfFZzHFaOo_Dnti+x1vVAODxVope{msoyo=GPD7^xQ*msvWj7F;r3&;|t<_Fk*U z9Os07uql0Kp?~2Bu>dkzv<&j^eFl^WCjC$l5AlO=#!k@Pj}(1juN^gBSV5^Y(*t}l zXnup9hz8_PhVWZx5;Pb?gNB`#H8h1mDY1KG0*=0RqgVAGCGlYC;cKTAYYH+C{ybT0 z+{go5LF%6N(0LV;yzc3HbIQ}4Vz@-1dyskLA=t(RUen}#>_kl6x}IEIdOnc0bl>?+ zreK;xsEGWF{9F*wiA);`S8Q_RhUHL z3ATbvEL&+OZ-fSp%JdShu7hpi%YE@kq8d<2veQ~T2!@asVg!k&%A1gf|1n3J;{zlEsT&%WGsE)L6f1o!*IaE2ZA-g0XKG8~!| zCGVX4@5aDb3e)hb3ugfVI`%WX&lSHbXA|)4$J{4`SG^UxgS(?=>0}EIq3a9|%!z$S z0_f~$CUFf`Ojt{nN<+{S1C%^hS6hi5#+O#dT*ybq+OZVE>;tY-h&xL*_ObZ%gV?09`d3yb1Vi)rE^xgiXoC27)raVIWm1E>TeHD zJ<9z+-isFbu%1q=XT?J;p+rBd9LUbcZWlv4IW$11>XA_Zp&%imM#%9#91S5ZrNlsw zek4uX%q*rD0AxnwxyFr=La&PI^MvhN&)=S8wF1AfGT_;z0Xg>W5>L?`d~A)fzz z8aBXwNBGyqo>U?TgxJC!JX0rwyNa;rQw^2+aljOTW4&vjx*B_X-U+`ws({SO#g4ul zL#;R54IcoEFTzdD$n4^R8!Z3I!4JO=J5d)ZyM)FUKR{mDeUEn?$M@onrC0`IVYz$!}f4bI7_S8HN8hmwbV{6r& z6k~Vx^uXHc+)T%@ePs33TOvXNYaATMGC&`T>A8$Vj(dWRao&lTJ|TPdq>!+#O{F$d z$72h==?eKbA_fz-zxghkvz~)hoQSoU0YfDUuZ5DHkJYz|(kf1%{39;dPVrUS09Nj~ zfqgY4F&gPkj6P+>CAzGIJwF_>0Uwc-)F78gz9LOn<#Cqe?^5=1KwmZ`u;uaubDSDk~A@r4O5FR{H zeG&pM9koMxO55CzH4{}vE^Wewp^NdFb#zwsS@SiydB;ed;d+@_vq#N<)7K#v${j6G z+cD0K1gD{B59P3WXYcD)DRP`|$-KPIjzeSap&2fijU&a(=UScVA>J>k$j|loq^a!s ziK!@&*ySkCV@ay>R#K@8BT{z3} zPhD=SUdu7FNCQP)&Wlq$1nNa1?t$b^3detBRA;qsKxsj8`b%eW34~V9A3b+8H~)ms zQWSS=-^xNr% z|HuJi(2A7EpRh<6n7GG8irV2YFDV!=fb(B;I*e$C`FW?DmZ=e+2GtoXqX4yvMyh$V ziQ0-Stu!jC6rX55;LLK#qV?mdLVMjRwcn>zcA*Cnu>_Ftd8qm|Q2@Yw*w}P4A8bmMs{Eeiq&2aP4FlV_eElU!LKb?>BHp zthKbQfy{U&i|s3taEWP$N@+GQK9|SH@a(xz^EE2=ld$)02_-}pwh6GurMWTo^UmB0 zclo50QDJh7s=FnF!4Y2TNC63Lp~rEh*E2_&jm+hqD6HK|w38|PU6%Y={ zY!Subpre^1mJ>x51BLM#6BE9$Oe@lv_{LU zCN;!jylK_0Tqbk(XzK4N^?|?47LuH2QRGN&`PIkA*!$&^*4Ub+{(vduRjcf#0IHyb*nQ33i@Ux}I;8pT(DKB(IfnaPnV4 z9M;8BlIh^sy|!g?o(kd7Q^VgZi=W6|{N%_rIPG5wfOdXZeEDDZz;j11N~|Gu%{AhL ziuU=cR}*pBOziSn%9s;9kj3x0M0h8k9NmzW%d;X_$)VoJ}1dj5m4D4hl9`9LGi zYk|RWX!5=F&N!D4y|8+$S!nw$c9UFqqs%*1I-W-Y)|t)63&hVe7H%m5IObasSNCJZ zjI+x8p1R=y0`WAxz3*@&?nT9ZQP=+#k@D`lth`OEbbuHFJb4m?HSLX3B#8cas;m(q z`h*CtO8N8c=DW34C4oyOsN&eu;6=h_{(Og zXDL0eUCYu}bUMC4Dg#&~M$PUbXp?XPEJGwdCFt7X_wAHDKXh(AA1O`k=1FJ1H5N^NlJLf^}d^h0ZG2QE0j3XR4XVV?lvYye%pu=9xH_s%6MXjuaJ_q@=F)n#5k`P zDBY5#bVA(XveE@oj27}HDvRvnL6?SXOz`qO%)`ehlzbu4@?!7#K{{oNRb~b?{R^zb z+{bRwL!^RpEU2;5!BE2f*+u_5btw(|iG@#PfPv0}bNZh?%e?cWTu>85{sr-{?WbkW z3cMAuE-1f-5!}u>U$a-WylMMikxMlN6&!0lw?h(|!Z3tIRtrCsk}wk|`Qj%IucaUB zoC%yw&hsqR@8g^RTj9I9sPp$@UPwV8XyaV6leoqc{~9KkE=+t;)%p5SscIqmu5>Vx zhIZk_Me%*#ir9LF%3~pthFw72|F4tOcCXd8lyorU>pkGRbvyWANJomwJ%sIf6KIRYa!%QeK z2-H-m-WJY0?jf~Kib}d%6y6kz{tmCHF}Wikgc81O%KBcGn28UQ0!C&99(3b9oFK1Q zt8(Bf50SVI`3H7f`9$bUkOw&w4%H~Og_7Mc&t9EgG|cWH!pEkKDQgTB(5U}F8(EO? z+@*G2rEX+f(Zo`@6)G;*c?LxZnop^8h{&=WHx_pz_Op7`OBA0LWiVE+{XRg>HbBnw zZ6%XAEBMIJA;Uz&@e1*(HH(l16*=X#ZG3=uA`CVeT?$W?02 z9anrq`}xES`E6|YF8>4RO|5?|A0lULsQpo zu@bcMl)L$RUb9QGgp=gH$d-&ZQ0;yV$wX9~^{0#^PIYDW_Xlesar(RJVgZ_Q(G1(z zya6e}auegUBfO=_OjuiV2O7OS7ZfM1B+DS7x-5 zEU4sGP1^v7?{$-^D$_l34?%WKm4$vE?LzudYljq#u|7jZl7K)%vsK>Z%15I7i+Ax) zlafN?4_e{88R#7btP_GCAW>F&a=bBl(4+2v5q9hKN!u=% zflZkJ-$lMP_gCBcKF$?;$ZIN;{5y~+X-FH;r;x$2y>6#;>GoS#Q}T;qtb{-2xV^Nu zFe6kHcJlf-?k2Cl92Y>s_FY2!$=9vQbo#TxDp%z4;uX0imhb54_FZx?y}jQlU0p9d zcJcH&ut&G#kr~DX55gKmY!vK_+;z?cM#@e~u>REm0dY+z~#N%4KMm)s^CIJG4snTH?A<_%N|hc32;S5H?cZ!I1@atrJh4 zbtvlGq#X9Ie5+&w6p8ML$M2SQL=m3flwcZ-IepbU+rMrNel=G%L~q$?5Ar7O6{VQP>LXPfbqkGzFyI~=hu zma!u+A=*;5uJIsMN}+$q<-q&p{bmevjGMOsQjvfTqI#RUW$f)f@=zK*xqza3i`T|J zp^-5eC;gb-%2EThRX8wE2-4*&AXbGUFX^jg-g~a^+Xy8KUdwfmvUl@X+24vk30|9@X|1tHBVU{#av}oJLw5Dy_wr$(CZQJf?+vc=wPusS2_WPZCpL_pB z)vk)j%FL>r5xHW;E%ELTOL{QkD;K6TpaTo>Zm5&~LHQe=#as`*!q*_wX!?tG*WT4I zGd5XOm0wd8WiU}V>%_;dNn87NzoYbRWq{UE7!6x*qM6uZvM;x$LYKb*AgtfgU91w{|L^3cM5@29W#@NpMHA|zs3+ zPQkr+12&uRUt&xj_tT_R+3pJMcl37(%56J5i@+C4Vm-Ry1kNfDKd`p@vKruDpKZ`L znEM`ig`1XPrzu0Ftw-W-s0QzC@Wg&#!6yj5m9gnFqT6N|+r6Kb*&gw~J>FOSL$dp?ooaX= zLc-Rm``q4!%Yr=LGXGD$51%G{9!vhESNFPmgorbIv5&Z*cD8_~{qLp$otuL8e9U32 zX6L}?g+1_P#ORNlpV~ln)Alq_?eHdh>9R9_?e4PF=QLa$BE5M>ndczu`*|`26Z~}j z5usYhZW6-hUkW4M+K^C(9IyePaA<4KNU+wQuAu?e*9q8rI$??WF&Bl;CtXW*r3Hxw4Z1%eptcs$92 z`UX&NR!cV{R&SAVad)~{j1=9p>^GcpKRl-yUyxv)%}!@(Msq32g9qPg z>t&{T;W9>YmuV6HgMnG?W{F_cPlFM<7CS0dIkMtgtgx^Bl{!k{`zV(AWOtOu#3&Op zOn$$5C8c4hm!!cX$_N8iA<;aX{;>IPQ`O;VAW`PKEVg8AU0)Q zIzj71@cV`?PYe_~7Gl}EPWn{a@`{AWySr0QqTf&y zsSJ93RSSC}^dLnfz=VMKf#lrGWX-5|B4|b3jV;kkt0dd(p&Ogev12P=Ej=~MCYuJa zD1enmlpzYaMA}woGoMarff5|&oSktORUpw!kRFDS<+a7!&pe-SJ7Jz2w9p#043 zozd)|=E(RC11RbDp+?MxnpvuQhYYJv=EczP`E$isf3wb8lo~E-jf^Z0-miMY{(ojR zs|L9hMXa}0s|&etbr)$QF{alpq*^$&Zuu{{GlJIB%hwORi>Vg2?Hj(^?w#0LxawWA zA9Cu#RR>lto;zn!&1^bXd^g;>kt<Mcw+Sd5_P; z8V1tPxUBfzs*y67)9ioWRCQR(##6>@@78%s6O>1UcqXw zp(j&9Ed1Ho?OEw2%E&JOhD|S+!4IIa!)VGn4uH6}ljdHNFeB%=>vqJD)xru&OC!L*8+(hW$Mv zPr$3>(Z1j2l#k^51u;g9aBGw;xcRw9q;>)^aJmY|{K$n>ICBF!`nl`R%9)(~;7n{9 z9nT;fZ*Y5(U;nURJT0GmtiRASe>y0L-}b6-wEBq$$Yfr+N%`xK4tzPBS`i@!yGtg- z`OX(_;80*o1uLuX+A|&Qx&-yjhJU=S=6a|lswj7KED3uE`7(UwSf$i7hsSDk%pZiB zY9)|C4ofY@EH)HD^4XahNy|DUIkbL9cP{H?wo;R^^Xl57x>Y2!lAVmVm~)AoGXZDd zgL9+~Kc*2D?%dkby>Kx%sF}L72k(+}`HACe?4?}us(6Z=9+{m^UiL$7hm1WvLCMUY z`Vst@f@)nkc{y$|)S)6=o%VU05N=3lT+^dK>jBbaW0Z{k0*OH?S%X}J8=$9z3)~e6 zFYv5vL{>*h?QALgOS5bn5SoLL<(n$Gjn}9m-2g$M*Oq-_2HW`kjYM5F-4ux8l zwu~fu6y9#3vzCin6g)VGanHF#H=PNE7~LEues_e!jk2&fQAa?J?}BWMm7Hior2_i) zVtl$PTAd$P-5)d~2&x1NJJK`^^}+S$8xSFgkf-2xZ}O$qL6IApoxRVWbXF=6;ThC5 zf5jWM2%0&A8sP$Up9xj|VitJ2!NGb7Pd7Ry zsz%w#G^fZqjw=inrfevBfJXVDAjdKZaz=y?qZHmm9kGn=uG?82Pl9p~YT*#hA+%VW zF0{p`m}W&)1%GA@R9?C>d(yrWz>NnFRvW` zf`b>^iP$?7gt&O=;OYFH@}TI7c>JO|3xFlCBkCP*73b9PJveN!iPK#n|G^xH7d?M= zzd2RAG27nzY>ToQp+bT`2Z(}3MC<1j4y5~W>D4uCYPNKX%Qt=y_)*1&J-x_WxHemQ zQTPk1x$>-uYI$?EK(*v#?tzcMv^&`*;%(We$D?u+>1t)-Ynz6l<>k)IH(j`=dDt6( zSUtSsQ=ztvtzhnp7ULpK$sNL6c-QVzqJ_;MN~EcSET~>XP|z>7h+UE@(JJd-yx5xQ z;TmCNQkJNVTuNnT%J=$bV1dZ7ze#klBdzy^^9!}Ye zm$-atDk=6aMH0lw=hQ+nei~Xq)Kcn!5OFLhillV0S;Al%BLtx>Cv4|0Ftzcp?fO3} zQ~q{2GHwD*=#6>ov6dFc&asxxl(RT)OFXdz!oF#OVPvp%u)D-_qQ%=+f~LL#%yhcr zM^xEKsC6z-zAaWCgjLVTaCQ>E4@~Z(Ei4U)WhGs}Q8@&2GC%&<^1*C9($H6+1I3m7 za~*kf{Z$Aj$_^zKEodooW)W578PoW_#`xT1s|S6F^47>48u<%KBEl1LV$n9nl5gW5d6$V9OYq znY37oWHI~;X$@g9Y~SSiC;pX-V<|*rGU#$$33B$Ik6i%6p4L*x7E=LwhU+xET%RCi zUCG^ybZlTGxH1U$MiZ}sqRaQ^w*-J&&t|azf}ke#ZBXd&mxOZ}^h|+LuLb2WDrH0M zizUaO*NkU)=?<~t;f#f}0X8X$hQyet2W5 zSIZ^_-Q%+C`hH8HEJGrdOvd6R|DugDOF!ZHmH~;3R-B2Hy}vo31t!|?I#k)@aI*@a zb0|ux73e+#67bGIHH2;zKTf*&@Q2y^XZp)}5L)P#xwW%_OHU#nP($vjHEhcV-R~OM z67dL#@o5557%oHmPOWNhwtJ!{V6W3uQ1Hd@T9Tf?mHMEm>+Fl4EzJixPz8zHqJ8HLXF2Y|D3K#jh9eyp=oHAo+$~g{*#byP?q9CBgU!wnI_-)P9LIzGv)8^g?yzesF2y>CKz^XIH$9wsj4+btUw4c<4s_M0WCg zbZm!OMXuckxQn)pp4xpL^BKWvTuKbe-eX7j`B{s&t*-sdL!XchEW=zK!$ zO5~jP+4{v#dl%=qH+0GSvg^ff@?f+64^8p5@lMmrW@zVBhF84r&9*(Nb?}lo;S=7+ zcFzveLT3-Xttg$W;NX{&T7&TXUuX&Nsizxd*%yky#}T7wIXYFrtfqz50tmt@oaEDv zY_){*vcuM}W@t+D!ZOcE*Q{*{rYkQScUUdOn(6`x>pAI)c5_)ZRP^FXy=((v8}DNL z1@ugH8`3B>y)qQzZUwwh01gnJkxdT^Ji2w6V{%@#Z^g~xKw(xqNNviWEde| zg_aO!1Os|f)U7v|d4`#@<;jN=o-7jezs_meU#$q(BxrFiVacdhC}+zBx_e-=$IJ;+ z=E5ns#S}P&Ap?;L-`b_-f6Ig9#(91bh7ia(1qW#1BtXp2C;WZsL%Yt#qjLq{p$}Fe zHOd`;((EmKlDN<#xyQ_O2xFOaar)LCT+H{XKZZ z1br&#;HBQ2OVNKdYgL5s*f2M3yS?~#Tx6mg^o!QT*`GGd)j1D?HL>~;2Ku1~P_M+( z;I+aE-L(Ke%+Bs%8&i;)WR9E|$W=NIOAv4ivy1aF%vwenpp=rCKKzzW#%P%2CX61= zWMS>y=6|}qi4(%X-W)s>+pfovL%cGZ9|HAoM-Ih67khrJqb`7i2>oa<53n3BT13~;n4$>j)pUCN$wy1}q4A*XYEAhE;nC*5 z-}^`{LczQ`PLE}vjg7zQ49h`z^t#L0_db+degC`2kFsz(2UccH1JdhnyMp}?u9@i) zT^%O>d77@Vz#2TwlyGT?R`o^f+XPGgY2Y>!-4f12Hgw`!5RbV|Is38jVz&@TkHvqY z{36dvARg;~7t}xt;2!J#$=2Q;HM5$P8>6;iK7oB~b}X!YXww9~U@8agv2$^jLaqKa z0ik1$W~IN4&2QzNAhNELj2|aDgIz8?g9%)&yUo$b880tqdAa%tc2+0Mgx}KN5|}cybYZ zl*4i3KW-ln%@Eyyj#Q7go5}sxCAx|ix{-*zzLEj%`FeWHc5{N-TnpOc>*AdK@&-%? zI_I_Ihib6=@A%7q2}Tp5W#_jBYn!J&!7h_Qt@sr?yc(c`=_QK%^y-x19}yM+N8%I` zsJ~Asi?cVo`xJK9F%Mb)6K@hkzHBNQYR!o@Z;4^{2?Mu9IyuPiBy zeRKnMzyz>cn9dbZ9BzJwR9q7be@Si1*_Za0p83-Rk1z9d_FnB3~DWr2nl+)M22*y`&~sj2WRx^Hooe5L?> z#c$W#x)hwJ`)?)SI!QC^Z!-K~onE%P$do-X=81r}_i0P``VIMh>!eH_98nLxD%^{I zJCI|4jrI^kYCoBC06nX-nP?W-pvPI_XL`CixzhXlT%Od?Pgc)oRiiEsuWxz2cHHj< z`$C=s+OPlO$Eo7lz6`2Zp#!+`Zs}J_5mywD$w$FC8uH#9rYVJ?DWi0!#s}w}Y~zR=*DP`wEgWd*GJbpx$^FI|=T+?!+`d zoO0ROeW0o|uAluCo+A8#{=4fl;jKrBPV~Cd0`&!f9SgvK@)i$X#~S)A0EXFHn!cqL z$EVa4Fg7{0g0#QO>yRdIEoz$o;!{`E^CvTCY-he3AEDGGK@@}e2k z3bo8k!ZuOIDwn6#Ense)`uZydJ%TLgtY<;7D^k^qp?;u|!CxIgzA79^V0B`m(SY-C z1LqOv=hqN)R5=xa>V-wiBm)3XaP8wde7i6eM}t>`quhZE>{+?tjHMqOJw`lx;49OAQe}#AB1sJNj&G799=#}`HZgy{vf??@_BBe1 zumq8$ikHEL$|Y7lGAh9Xhz(sSoHqA6wbM)3B}5q+MbJn(kXT0r>^eFj0!15!qyYk* z&~2FYc!(~q%gqZY7)JitnjhVd`@rjAe;OG@F4WZhlC|@I-%2$tQ0wL#zT_4Vd;anA zI%LqOR6ur8uhDyklbU&Yon&8g_Dc^F8kPVClcBU!>x2%Q4J|F2srf|yN2jF1jG;9? ze-DV7|37Ha+Vm-DF6=kk;n!wEQQNpEQgxNw88hihYz*|k9JV1oe`&KfI;!6{?$avm z@JFpCr8h& z4mcaO<5N4Lp@S%YMMWdNe$uACbydLb%aQy8Xgh%0%c1^l5q<+}JHcAS!;mL$BxMIg zM+xAe@AKD_wgCeg!9z8aZy;?4Mn?tWsS@EokoFIzQXrW1hwvLh+lkph5xKof_!F`9 z&~3Mf$iY4QmDpw+en51X%6acjel1Bm2+*c{A!2kq|4`ZvN`SdTMZ#}bLp#`u%?0jq zsAX~RS7xwI#%8&ZMwO)xcAN1ULwKqbgu^J3jKnGO%zT(h$GJ9`V4RY(lx&lf0W|Vt zot{52{;)l>7igvltJ*twy)J4%j3rPN$H}c0F7|Zp6!Qq)G*_3o(7AEgTwBgwV0?SEx@utX#_l zY#O2hsLgpdR(0QjJiBqF(6FInBB3F_Z(<}#z9B=!lm4~kNR=*68h&&0|*@!VL`MV z849k(Nq0t4h{@5e*YGu)A6+%q{qDu^FLB8flz&1?!^<<#{t1OZnpx4C6;j~E+YH6P ztdc2Tl5B!B{zC>Kb&Nn2uXp$+6xRD8_>Wd%!NhuD8+eDbJ5$DWYBlj0ELDbJ^)_?` zQt}K2>6jgEoe%x$vPMoSZW0)ucq9cN;q|TA5VO%P=&jS`wV(wfZH2M+@z^6SN z>?;Fyii+-fmlk=!yB1aqIFw;gWgT|uL=e|=`=J4EZu~zdH=saG<2oWlreJWT6nSTZ zhI63&NivI#eND`maAG8dBx2lVoDAA7%p|t!-|peTNnZn;+0RTuYb{Klo`kgZ&A4;D z6a}`~dH|^BxBXiU-C$qKq!7H3ifTxm=9fQt zNMMRWR5+9HtOZPRBn#u=J|Z5paghD}wK!Ik!e54%Grod{`IHAAUT?GnnzG>Qs^J%P zv{|p+6`O3Wn(SCA%619AW<)^vkF4g}SsX3R`{q)wuh2U!fY|cLIj6AJ2Fjpyw&9Ms zQfk8?&Uj@QI$$1-JfjgV%I0@WLIwyAL`S%#z4-}=S&oKYz$_*IaZsf3}&+Y~U zMZ}uRrlP!wnYbxjfFYId=S&X`@caox43uHml+0rauB28`PGk0E6~Ypw@0Cs6CI#I!EbM5N+`8m6j+vV%yuuP2Yq> zlSknhA8jfkX?^^rr=q=>SHJE=XEsGXr#;X2%!{tWX9oK!SQWWw}LNUA>jE=Y^qN|yYj8;oKVE&et` z)FBBlNkki+_h!jrE*5pt^T)4;1d*VUt$4+yG6xyu=GJ`x;b%tF+%{*qoD_o?5rm_R zxQ%#n15gjdItCSo5M)Tg`Q;%hrV;qLq%6eWk{^nx!86#oEw9 zW@4QLfT{(KW2~Ug@j9D~Lfx!kTbta+M1k$ zN1PZqV(m$VBgQ1g>_lmz0EOO;`;3$>t9j08DvW#F0So>9agN{=Q)fmsFH}4Y*<=60 z+R|3)imPA7e)VN(!;)y|Z}pXD;{a^)5qd|djNKl!$<=8dqG55ZjgcY%8-K*s2W{px zdU2puZRCf{RM;>i8s@qXrETA7q~b*gKV7oCXnw zPeRlhKQ}jqG54mf-`s6W9s!zUkD_1y-Bv@DsL-F%mDwaX06lXex6nq>{knm2^W1_0 z35T%>(-Ki@yp9nW`NaWNoZ(2g23@KX4bgJ743gUZf?39&qUi;Msx1Q!tYjOqK9ccX zOwpbeAgmj0nSdV(UnK6RCb-nl7OH7d ziGpVsZ^C8mZBd0z$g^N61|5dtPGigz=Sc<%QE~8iPJRs0lSGN#S`p5mKVFI!?avk~ z5jdJLi8_`!M-)B|HbtTF`Z}lUkHRtRJKm9(8V=nQu3eRrm0SA@94i_}i1Z2!_h`!s z87qAz31^1#5^cX5_`26vN{eitzo&!u`iV7H-^2+@y@GdCN^&C_Ced@ieX)C#Aho4M ze$z1|+UVy`r@{nER=hOSLJb?VVm;2}AYI?j2pI+YYoO)gU$H~jn z@%wy*PN7|aBfj0Ye+(>A$Lvj$gGe(>tlHw`@N)WX`bzZY^K$FIL}vY5om|ABb&8fg z1D<%}esN&ZKQ@FztG)z{`i}o-*m!biL%W*;b>w;**Zmoh+tR<-Fe1SInKDivmGK#= zQL$Q^LUHQqs2ouvDARL0y&Y=~#Pr<1^!;o}5U0jZ(rsM?;ya?Kj)w{}wGp0%KCiTo zYaILSB{{!O^|(#Fu7OQ1w=OX`5OyZ&;e=hEOzU1+4x8w%K0Zq#H&Kec zn(Ui;etGy(NYDYpQyyL1+-Jy{mPyh*Aq;y`2k4;6lfBVJvYLdGbt=W5R^aYA@zCS59H5NgRr5 zkPQH#2CR%a(%k7wzB$>S8Dr`5~&~^BwX7glOkfUF1_2c5SHVK{rz>JYrJ! zeY;Ns^*vpCFI%+c=6=o(oMV_LLbe9@3QWjyXKPN1Si)e@D6dRvV_BA(yTjLWm>QZw z)a20Kj+-eS;0r8BM2Qwhd5I7sOK#J&sk5t+rOr;mDblJW5x|vnVip~BmIKd)!VsE^ zA0PR|yL(FUbvW8VN$8*X`2Hdb`=1wEcRb>W~E8ag8hsS33HEtEi0l07B zYHUs04Xk}t#Mn%dDLn^gXOu=5fGd}u^Dub}!p%NZ>!P5yahmym| zQGYA#k*v%y2FN+`@#5zr&@IW_-8u~fREgHL_pl;F(fQnjYWVA$77zf*`_S^L33Y_` zB_rsfU4oi~~clR1r^51lRP6CcB_ALTy z_YwCNtFF!mGQVjmSG7?oQFBldfqzMK*(9PcjNB+Tt1rqvQSw$(n;JAV8TVcT53G>J zu1u?nzX?!E5v9Zo0S979%z^G;8c|;doBPOd+AM%RX@cxrI8p zI;?SXoqzcfgk9IaY#H9%1ov#m8C`v1PonWtWb`ad!qECkX@>2_Sm%|%$u3}HSbLfGZ03}iTxUE1VC+qj48uvcLDXw>fjsi9rvf*x$acZ z8RVTxcMLy8oia^QP}k6FKKxhy$-tW+RAIYR`dg-y(j~66Cm5os0KzAy+Tm~>F}O(a z4aVP$NrmN*dWqq_3?w!%3vjdTbF{QGi{4-aTz|&XA`vf_Rk@a;YK3Sm>Tza%xjQH-LZEJ2Lz(l!>12V zn}3u&cT7o!iRq@Ji*A;5Z>jaf;8h&+9{W>0rW;a_MrseI{ALb|a4nlE7&D!LoueAV zPFBLS%io)*e=e!|@3~saj^2G4g59AM&VWEe{{qYG^)%eTsCJgZVmvqBzo}A6YX6Wb=%->Za|V z#lg2}XhFd#9xT!CBN$s_DSmInRXTtN}E zJryw&@gHw-Xv>ts$O3fS*^Q7*7JTwQ3O`HR?(hXq7~N^k@wU{^mBKVO)3?sBtbZrZ zVJ@RQet($dj^e4La4q?XI%vBlUIgzE+&MlC+f==GaGxCPSPx$vGa(HN6Dzlzq&$e8 zrtkcrhxUEvq9>l-c+lKO>|aCEi>dD9i$b5Ey;9XA695L42Mu= zHsJKcO~CMRJ(KrR(oeUOo3qbOYKMHPRycOhK#xJ5MZoAXq^4=Wpf|PBTyd~> zIH7Ta&0^6b38i-Scd14dS7E%IQ6BQ|DC`9%=MtC?=$TR-#}q#{(*$DZ=;>C>fEWTc z6fKPOQi-Egs^fT`1qF8taVCshD(Z-;EzGC_!^v*YwBN2=j8pMds+xp?1?|2jH5h&p zM(`lQE(Q@^3n_&XFWqS_tW$8M3})TA;;;uiX4&w+aZ)`%L0;aiYZ1vf4!O`sI)@ja zU1y+CYAl|7M_U>#>g;@d5^(Oo5sWU#N2E5Kr84>wz?sS3kUn+mnvceBEZo~2ODdFc zI-{W(>XzhgKVNrGm+yLJrP!5%2C*8@wtYF-40f5r;nReUFk9RWs9LfPEbxTs3>eND z6v9ao?um)g=Ii=kkIQF z89PzAJ~!for)p~q%9qwF80i|e`RQ*H^+rzltrZ6pcQETjG%BBr9!Adp8<ESsT5(3E0@7B&a+orTN@t) zns1t%S0c?{Z+dxzczOD`9^Jm5S-F!~o!FQ+8Jd#?8xX92x3ulkvPvb;bC_GDD&4{lRFfClU;@tBL(Lspv4*XKTslYCt#`Ms-|}y{2U$ljXZFWCAN}as#K+;BwS+d+~?zI9yO zyw7qO`rQp8;TEJ%bem<)4yR-l+aSDQq)ZA9k+Cq)$q}EhC|x$w=ay3tf|k643z;=5 zs5$j9n+mz@Yz3_p2KH-%*30e@cEu8h32#TQg*blAWbZw0$nQ&@WYG{LSgqZuv~l5O zB~cJsjxu9ubK_yp8gp3OcyyNG21WtE@8?d?3)YZA4=h&mRdLm&8)}}u;O$4O4@^Sm zn_Jfs!$O%T-0asD{x)`g@73>?#6LB24csjaBHu5Nv(ooJnm_BwpZ+nkBM?*(-Ldc_ z#J4uM*SE#)9>qdb!(nuingSf;|1gez!u1zL?786RHvO}H;_p0vdS6I83!4ZvLWUreXm07vf@lU( z;O5hN5b?Qi6|0@)8a=66qm0VJY<`q25h2~PXFgscMg&<9q0glt?rCcSg^~1uPK#<1 zAh6E$l0`9G`+UDTqdT1{&WdQ;4LU!j2Rzk3Km6U=+7e&(gdyuaf3_DPUP);qsGvpE zib;5a6!Ks_rI}*M$&)iOM@R3`l7|=8NT?Gz2sVxx1~nOY)3iluXsuz#SvBG2KVHWA z$Y3A$f=w6aG$lg#Y{BFS)1KtzLjH8p}I(T<@X2zZjo9`O!&tybR z?g2bRE6*6z#6Yrdk+F!Mu!C=io$}M~?bc-MUho8woOT7$zG@KF6^8;UFZMY;W9aBL zlRHq&z(=(bAD~Nffuof}*Geg$#4n^TL%D~}T1n@Lc7-nbHa6rnu$tB0uQq*$Lcc22O~ZK}9W9>yJF}y6t}u1pj}`Wp z-d4@Vr=hN&=Bf-A_Z+7ha-G6)$XpwEK=nlC3&&=f^#$w{8f#je{5VtDBU7rC(QTL? zaX+=@A21Ha%n~i_fUGP2;DPJ!rlK!%|C{me2a0^|HUDa`Mz!{KF6hcs4TO`3Ckb4% zV`&~-oM|JJ2IRQk$jUyJgY~d%DfiVz1k2SsTD-T2wmkl0)*skWb_Ks0X*X1;FDwg} zw^c|bWHghMa*!u&r64E5Q_7q<5^<*op~pYnjLGVvo}E2r#vGZt2+s(!NjXT%KjH)X zxNqOL8n=~aA-`LJp*msDC&;|ngOSH?3oepcYHd7~z16jbNxDqWTFyPVsVcb4sZlPf zycelvPgmmfU=*?CKQHP8X?4iYf>MV28Wp9B&KBawwTTO>TZvQYI{EGoXNqVkO;jyp ziwBy-&8c!od}>0RK>lhePSoCI6f5ceV2UgVLR>)=ORpk{)AMmv7Ja9J52RQrirkR% zAq=Xqf4+FL>yXN=5{2fMKd)J@zOh4wzlomGnxmVzThQBI_iax?oUEsmP*q(@k=RuB z@+slv;kS?)B!p4V-F#Pvqh>XINflRBbnsQ;=H!-VgrzkPLNB9lB-i&Lpp=>z1%0WL z8o6#gCEj@tY|zX&fOX6u9Ag~-$4P7?RW5?n6(nBQNXZ#rw5V$cc5I>4pdGX1J=(by zj-l+QQ7t99S{^+Q4jh5gQdx3=<&Afvd1l4(`rp|5od5-K?6rcR=&Yvn4lmTL4qb#> z;F+^9fj@up_R$|;|HEwodiWFPo$}&X5y6{jKqqgz>HD)Mj6ryCczGe>1427-)vEd) z4DAUiW(QTE8d!3(GdQ-q7r^HuK#a1>NsiJe2TS(uD_czc7*ECx{63o3SLT#hKJ~2I zE^QkFIyOO+4C-R4#@6?6l%Afz0k)s9M+8z-^yLsn%(i}LA!f{#J*xWW?kJr$)he}a z;qP)L;xE(An>IVYYj6Lbm*;f;AAS7qucL58eV6$(VZ2Aki8WD(f&TL)p?=_J%l+1P zTj~$y|7P}tP5|}m_m^qM&(8MldV#^umhZ~X`S|w-X1?3AKGH+_V#+kRGNor!B!a0& z4^J|S``D?8D-sag8$>7&4zlLVjmx$J523K9g?BJ9b`X;T4fg5F{H^Gj2_^kds(C6s zc3cD^!E_`}cXHVrU{&llB7+_6*B9M+Pe<@@gqCC2X)INQR5?}zSm{i!o}h#UhyQh` z2MGfWHiSlJ)pV8m#Y|%=b7_~kI2MIWnQXAhyNkg!(D97J?oK4g2Aeutu!en~pasKI zZ2f*pnraFCuwax~dMBd4l^Qey> zPg0di=j2CJa|_-#J8vA%6W(z@ynk#*nU0D_u2DVQE_ZdIQWNe&lxk)G#u?1T(=(MH z=kMzBpYdj&i{+o^kKnJO@3t4TpAU|F^hf^5bE4$r@)S(QBS+bI$djM&!3Wvh8Jo2i)=6ueY*c<(^}YTe~uu0=;v$1kS3 z0w&Q0w6u-FWjnD2tk|RT-M{0vL)##m&-qrPkVlgQgcdn12Ra?e^j20&UX&U;qRyP9 zgt!%vHeu14o${N;}e0}9WD)SdYfYKfl(n>FN-7o5N->bAKv~jti6~XG`&#HEU zLHf8xIKd@ZT;eqCWRzTql4Xxj6`RGorMk_jWg|F3afs=&$|&I^yxHQ3)x#}{R$Ycn zWS)0_Q&_D0ud07vF7<70)n+%@mR1L+mI!Ij4x@oQg2_fR4<4hUyBW&^WsBwAvD3EP zg6xqX9~|>MQJ2MjR2{I?D6M*#7AJ`dg~ZLLT@l*^u7}-GB$;aTFIi%0%}YWN*i;0B z2amkJ=10&r%FvcyLJ6&}c1nOIr<;vzX!g_}>HghDf2A>ZdQ!939)>CE;|8sfUh0~u zAgrNj3xihTdKgQRz~VC*)lC-1cw_r|q#S!LW17b6;m)5k`C6MeT|AlRue$z8(VvyV z=_mc@GoS6HTK{=@$-npKnJ`EHxw+}LOGTEDqcVYr94>-~;K?GVik0wtX*eSAb8s_q zir6Uqxu>f2kZCbGtm!-z*8IDy{UqJPZETs=r`#9ye8xP9Z9BjcW`X~R*p5b?)@BZi zE}~CUZLrz0m!_}V<&I*`7bKo=>=IoOf|Z$&RPiB!G}G#=U+K*@Z0!qGQ`V-~uAyTOL=PXgextRG zF^D0}Ls;p9M2$99sC8p#60I%qgph== z1gsLtbQRl^VMYGi^+>@@+Lk~Cc-GI7`xIKqGJs`9$71uX%W=rz`BU?*#|}ZG<=-xT z&@h!t;ias4m&@K-wlcF>tC`v05+y>5`jNq9RtvS|YT9sx@ ztLh%%)6)c=5-A4d82P`;YT`&|c6yxUmO&_IgoR_hM;=N6?Zn!n^JxT&s^ph}3hM}* z1eOOArfnAa5K~fVurtrMdk{yiNXa#1^wSIohk=ySA`Lm!Mn_T1F0YfEmZ8z1*pi&Ovbn&a=m} zCZo|bCLKeu@Kyn%I8u#YbbOVaMAlMb4qpf{8uZZzv3Fs8*oUX|Mq#x|TGuTDCFkto z97r~>>Dg=aTr6k)Z|4#M*jXb&Ir#9pZog*3i+UmVCT`+R3*kPZ?-t$pcTIGseV6+U z8e0g?>>rCjzwCpExQew55@?r|n@ zt!Nc-a`Yma^&zArYtP)|#xH#Ms3wN7NuP>1NP(<~U^(m0aS21 zQ?@OWo4;Al6-u?g;Z3C~to4?{&A_p-y$1cW-7TQl4!S)P`#4v&P8XhrmT@#0rqE^6AFy{HI!$DTUu z!1K&XoKHSYWLM&C;iV5Q)vZ}fm+M-~V=d%>x4x`Y3n^S{$BRs$!b zVZ=0cVQnKsh`3+zLm2qA7^;RQ#WkVqy`>JI5)%0wS1335Y#UQ(zxb1HfmRp-v1%cs zoHyQXpOmP=30C=rC1rr3%1Jf``ctH%1(S1xv%DC&KaEtvfv`S>Bo~x87|HVpZ;U+9 z0DE3W85pr8v%NNr(S)3A?o2CivJwr$TE>945CIy5WmLvlYUrm}qGH>86*((D;nqvT zhwE7a^c085?kUV4tD1%530dDMt0X!mEPQSAYl<5wIyk4_3_x#Qfu^8MZX80bq0tP! zI(*{3@t3LAQ(oCUxhjj3-6A+|KsAqgx4I~k#~qQOt7A-~HI$QGaM$7?iv~M;+{Nkl z_&S4G3dZW5kCc^nAqgpT8#mO|`{~pn>zr;+VLOMU(>`=yro4J>;>w}pi52np?h7>P zl8mNJG?2C<5=pL+s-c`))EAjm9ClG!#t-6|eM=V7$0xEr8IMVRQ0(_+40xi@i|eN9ChLnl_dRd?H$ zLO`>SR85#os@z-HdfkpUcmL|5;H2a^{On zByZE$?w0J9mof~*5ta_~j2e{I_GDJ0+U_;J#p5SdBxu)(TVKuTl+YMfGULoXGOdoSWq3>9xb$d3ZPZ30s%><|5s^eG z7JOy<_Ta)tObI_{fMYwITBn5unZ+h+GI&J{Hpbe*lR|Y?V{>oD*(o9^;hF3Q;v;GVUNI)bm@)!Ec%)nyK7jQpM3Lr`k5O z*lEheWYztpYUf84*r~+UY$0XfXSx@(J5>YaWA6c1-TN$4`1I&|R^~RT*mSLj4q=8b zayS3(FY#t2#LXc(NGJ1|z-H5~zKLd(a}|!I#HjBQ{&BP(%hC%;#H`k~YV@6Ld$o~- zs#SJMM&Cj;m!?%pLzP|F5h*tgxvE28Zq;@kqa-Cal+Ag0SAy;BEpH<;WXWYR9+Wyxl-dHDag%oE%j=P{00ZXPLb`x(UM+V?J_dx`Iqi5T{{zvy@yy< zS8iIWF{|y(lVJb!J}b)qJQ>akE5H)@-+$i!s(An7VDS7&{y)ZNCHWtRBsC`r^1#L% z&uAuTa-^76(~1Rkl>{={F~eunoGVciS!#g?N-(8k#?0W|HkZm z{)K1Jc6IGfDD%>a^IskWtU3OxzuPaxe?8s*`Z%8z=D$qlL1TGe3WU;U3{AvdTkm|8 zO{ZQ0Nd8ggsR_x{yl>ue>!kPUDb(@w!v}#SK^6gVv{Arv+iwiTEo`PO!>mfmqPEe-QZN7s7rq{EW>b?4rGBSauoH* z%od)p3oaj;0w~M41aH76GKnY{D7g3nR|E+4S9RE`0Vf29n3HcyRpFq)D<%^xwqdUs zwb1hXfpsOekUXpK(RPJ?3_tT@i&`i(u3A~X5`$S?t(|fNmyTTHS+4P(lD}4(VkN-2 zfl2g6oorhp=yzS)Vzsdr)}QS4=vVRLi^9pGDW*o#v{Z88v*36YXS9io!b!;uB{DFF z#2HPMb)1dS=3n`yGASY&BYl1U7tM#U1uN;6Hm~N$xEx}=cu{8&bquFBV*GM<1X%?j zq6RanG|+1rT8n9`(z|=8cwi zHR;f&p@=?xKFViB{r?uHF^wmyZ2^|rfBPl-?^nA|`v0SRR?z={l4FnXh|M!~;aAF{ z2;wyHq)F{JY@^Cw;z`5x59f?!P2#;0nr$=1afr5zWumJC54y;@!eLuwT`u0n@Q3vK z_?E^Y>U!xfzl4AL;txK>yZg_FU73*ir-Sp;lhf~p=sfQ|3Q0zSjD%=Q=-}2>5g$Gb z#S>BH!-wr1q;!nf+PQcwsgf~8^6e$r3}D2D`#>42jlF|=3R~H(_9(52PVr4}O5TzV zo5eh@%ThsBA05eU-ca_pc8zRHTx-)=2!E^C!sHMX$WmaX15dg8wgM!}79fP9H=Lwr zDH+put-xH9g)b`=AZhPl+iy7E4CVf7g*IImR!}QgDiwz>im`u?fw~w)3TLd_`lTX> zOiJrU3zocidC^+6iU)M5yS47m70laRhFEU+D!;4tWzG*^mdgOhagvnoOVw~I+@)>* z<4X7Ah72t8cQm3nU06Xv(xwerS?FY%X&W0$3o*Zq!fokP(V2r9#MMU-8%xo4ENXs^ zqQx;qxBncboLj{>TW#Pjcp@}`Yz=5#1FvRo-j&tHUQ4&?L2o}88cvH*ux*3&BceOj zKzql?C?sD^SVxtK`@VG7Zq0JMSE9MS6le{?=n5(=_$NR6>`p8h^WrS48cz4klgs7P z=RW(t8BQqMC?65LbrhkHIu5I`zp$}V8XoC1CXf-r)G-%rxK@Q|^MKRM>B4>HnY|*dGO=pvt=TXq=I;t4o2%KM<*4T9FBwr=N>+`S{ruya;qGJq zk%jMT{~7e3mGXb@_xHYfvj05B=T7z?G4My<{8vgQ|Gj=Akm9OO#|UKiw%!sX(Y~iG z$ZqO^3_@k{u4WKY_19t$a$(gNgqqDbE{Ga4&QhaNp;PrnrBBTubc8cJ!n{~NRF5Ca zpmafWU`N@MB;PHCbTH4R$2qT9a13A6n4#eDaXp)@VlT0=Sh5#=0PB~uLD(pKl4da_ z>iz@FVzPog$?nstfwSBg2g#e|a-3u>OmewcT4sz>C0j7PEbnoW zc_yv=8ZB@Nktf?*TV-Q?wl`3|Mr+wNw!r%?HUS0p^R~UIPOLEQceTCMK)J8&O@aNy zZEvkDG<6#ELt1Foyw9oa!!k3CHKFccrg>14Xw#PD^BtP|+eP(|J-l7?W1D6k<#QkV zAEbV55eT}>|7(A*=>PR>|Es6?&qw*($^N&v_}^cy-|**T68`vRKj`FxdVWC*4`k*m z5_2^pAJkrpiO+^~M~^QDnLGP?*-)Omy`H?i$~%0R(fN2+_*g`8KPxj$F68vWUgW_uH%k%phPAJ<(!_ptvYjAxUSEH?rz@&6h;FWG|Ef)tiIzGWW9yS#3RxVW^tGD_Msu5cf<2Qvs>c zL}YfCro6rVS`Jl6d;OH>hK?m|SbL=g@1p9~Dh(^XyV!h0Yf8CTC1vZk`Q_sE``U`R zv8EI=Wh`9tilUG;kSlSaJ&O70xpst#CW_tOx~JvJ9;{E>e5H*YC6#c+A*fL+AJ7=G-t9r_9zBTk$cw%)2cpX*2OO_aFm?q|%!mHk@&& z^3HB8xx2`#+}nP}>{8pOB`j0J5=mj2+x*Z}?&H{x?_vKmk8 z{ipjMALrA#ivjptjQqod|4OF%WNg2HPQBR|Uf<8+D_eLNV{eI=?aZ>WT04tut;3xI zb@r}TFc{zy_@W1@3_SylWSS*I&6KdQH3XF|hF7icSYeuF!Z3jOF- zIZu0$$hLR?NHyJ&0jI9R^n zTpb7v-jev&39x#G#oBlSj1 z_P#Zx!6Ks;&IjCMtxXH5U-s*VS=O<~teNzOQxaTra|#3W2K)iyCf5|@QlHZTT+T_f zrE~`L&lhO$Y`gVHRH_~K;QvZ^ma)rTd9+Y>m#?iAbgpf=7ItfNFVTRy2lS3>M-kg* z^@EPmjp%#hl){8GhaU}%=7B~)l zu?x#tBOiV1nI>R~5}(Gtrj7pZPf0YRlbEICPHimF|NHy9#ruEzd;5D&`u}5mHqaT) zgrwqvx8)#!M8D&YeouSwuYNF{^u#~Kb z^gbi2M4S14etdBB>e!!!cWh%x{MUXd|M%dl{r=PZf0WM#`i5pPo>4s;UeZx2w3b7` z0-eqQ`uTej&D_WT-kN4v!iT+{SQ&gi?S(Ahy^JL^;Jru|eXE#gLzLMD`}ZVe^F)Xg z$yg|26B?iq$!>`dI0_M2&+l|LHqhnE|2{hJbgr(hgl63dNkZa~!~rErdlzf#P{D(B zUYSydXyCu|-)XNK#%adV#Sm%4RU@iRKVY+-`YsxS76TS@7Lks?ADNaHXr2f~)f5B7 za6*674c`np*E9}?NNnNhGUJ`0>B#ua-e@q+u~c@#-!NI25gwPp*c8=>y^ zB#IdNiKS84l}K!Cpp!UDSvZGth)xHjwA4hBl--YaA>xhjZ5isEAMM46KBShn5o*^Dg$qd7r4RkWY6LQX2 zmNP+0CX{FCLX20oNXQUz*avkG3JDKV3Y(!JI%2^!oVm#2)-I0 zc$P$Dh(f64Q`YHN485eOb5jziC*ceBvLP$R@5K`uzw2}|JXr=-!pZQ&1~c#n&;5ZH zk`cwRH|Trm^Sw?dnMctXi)gSES0MIyfv^OBW-6M)C(uzg529PV;G1IqV(<_&+XNeR zwz(sZk%Zzdil2;6S$38ZPU37+;v)~>d5#cHQ@rRPL^C4I0?nA}U2U{LTq7MzAc89m z`l=nYm51J7ZYCh#_B)-BjOG@(NAirWL>k!_I1iy?v|w{|%jQvtB6>~48%_u!@3Isl z8jo2zlRB0ZvD_Xcd3q;!`yfU%<{6FyqJWLau(M&<(&o4gM~1rmvLWbSGx{6I8h&Jt zL}vrZt}Bd`AlpD^LX7f^!~w}?mO7bTN+*4sDa#A}QN!|WA_zKmIy_@3o{+-`bH0o> zznd~HEg(698Tye$^BF-G5)cANJLqJrd9UkrcaYu8DaihASIOLva)BpD;X)8JkkVSL zA~c>j7{$WavOLD|Qn*Yu1s2zTpgqr0WK<2wNb)1_BBI(i^a&v6?kJ zd+a#&L;-m zy;Y8vh?AI8*j>V0gk&_fia=w872-RHvl&4doe?eo+~OD}JiyE2GSghwP&D-=$W_EqH&zE1FO zb7GXrd^Fy_M<&ui+h6}cqvy{^9GDo&4<9;Cr^6)5d+htZvip(vW@w^`wT6CnaB=a| z>+>V?0!d@vw<((qt%pbv8a%+p?wba3>CurrR+igRT7v43zv5wm+vGJ_G`4tcnTp#s zr~;sJPs0x%fPS3~`y2ttT9{GpMBwj4h4kFqEQ689f&dAwy(x&| zC_+N}MYDxEgaONSVW3`gyE_G1zUX#=<2MUMTbjm;4Sb;|`da~_U@osW`FG5$BkvNH zX2=5b;)^Y@FATB>D(fRO59C~e17d=Eb6!9mL%(ts3-n%e-@}DSzQu(fx_dA`RU&rW_-H_Rc zq-e0WgLeD7{T;c5zS-4QVRVZ*f-Q*H9*t>C`ILnD7Jovs>3jqR7s0&B5VOHEoXxq% z#$Glho-(j*@1Sf-Ihx^LS*k5NVyh=z{Db5V;w<0awte*T_ar6F zrbBHq6g+?vsygL?Sl@^d=3#kW-6<|t?J=e00DIPl%%o>tZIl{sz&s@)T zIZ>$LB*9%L%G97VXIYjMOQLbgW(bR}NnT_z(QA^n^{JV&1Mv7%Y#HLs42^~8!tnx8 z&gX=;Z&K>$Y91*@E1tWh;4dPSz#2hNl%s`p6Cg*>D}yl8B<^PdjEuF?IjIJ zEH;#fELlkR{QnAAviNVYjP2=J)9I*kA)3dbaxOnea4;nr!Vc1LK)Ze)ZHWS1^{Tu5 z-yOj=GrRx}6oMCqA7(ar7mx&Ie!yl)MCI;TuNn%3-}#pUz(yH{$u6+e%bY5OaMtMn zHHN+3?d`3P0Y#sslU^i?@ZQUl!{gJ7V{g~*|FhG16Gw#ee4QLEquG(+l+aTXb;xFZ9F7>Cp}%R9f@i38~2i zf^-I}y5G4V#A#exxuiXo1}MVuWR52UP1p@dV>rkr>5Ou@OyW4~M07?oB@9d5@js(O z+$q0qJUQu>PDi&bWD|}NOGu13n~QC?v}StJTLoMc^`*J!I%c<`86i_r5>c#d zgJOjTvm=c&GD&H+@X^8H$&sh!dA5USmb=G{SxV?6M%QG)chIkl#(YO$PsuIcL0L*C z6Ow``Qeov{*AS3UY&!hTlnE+UY@77)i<+}pN=R>pX>4BPv$#V8K@$zcUbHdiB;!4v z;o#bt_;fb0etJ;A+uiNI+ueKSC-J0nO%~u+Du&u>D*w^(3@tkzlJBg{7adO@)OG~g zVwEGQ#W;E?MrfW!EhwODWELuNhyi3%ZKm69reO|5th83v53$;Ia({z?|95||_n9pl zwesIGMBcZJM)^PZYH#oPeo_8Ed&>X(IG>FT^go=)_|@-Zdd4L8f!NqUXRt@v5&A6A z?%I?~%cRh(QW{E4EU&hsEUiN4ve$+k6o5y}Je4}8RFB>4nVpS|j{GfTzrYUQ>cm=b zw0^D~CltcUpF%nV=(PoEcMx)F3=vp6tHIhQ_AX@Osi6#SV0II`N`2}tVGZ8tVb z9ssH@VlkU7G%`OBWz|2G{unvBc1`s2zpF5|k1;j27xpu;c$E%hxA?YhsBjJ{$db=~ zdG1nb)RKKN`-A#z0_DvYt&W>4Z(W4L8I9r84Q*-0;pnOo(A9Q31oTx}@)T8`1_pDU zv6*ZrV<<=o&PcgQUA1jfNo^lnHkho~H=~Y}`(|D>G^fk7ZLV-erH`cx=bw7o0(a$_ zR*;gA#2LjAFJt0DzS{QNA!N=0xeu&k9dH@!)Uov%kZfq}O1maY*R?5$(N!xVUJ136 z%OmvFIxKkU(fV6x>?3ryBKz8d_qw{xwRPTH4>By|lRPtLw(8&wAuWomM@hMqp3v4K z7X|A@-p~95y~x&9afw3RyJ||AB25F$NqR#A;=_K(&dqEMm@0$75^IlGU1cNDI^}fWW zD?l;}G^kouH-HW=!QloSgrV}i5iRMX7TF@C&rw@W=#*7)h~9rF!92)qE&$lF!L)^L zfzVCJYXDG4@g!zEqk(k)(=nVG&d7Kkagqrrc`5Bqm?P=FGnsX2;BN_Zla!5!+7yh4 z_G=7{tC>3eHU$*3g(NomsPWU2{-6yAX<&!yZ^m-w70BfK`l`;W<`fVqDLlj@LXxIN zaXR7XK>Ty3=0tVf7LCU=rrE-kM)nd`Cz$lno>f+EdU8>OQZmkMCe!&yTi60N>!lUu zjb4T)yl3$!K=jR)r_`3&V3n&FU-ODe`dz77h9~9n;^7vZ&E}arr^geSelaD2IATW` zZkHg1bV7Jm2Bw~?(YeJ7#HV<7|M?JO-}imB#nn4p8Fnlwzk?_^^X^pacQZUGVUT+} zm$4A*=khc7wNSDPOa4hskI@$t#SdOSSeTlEnv?mVxe;V z(6zp$5#i_+o5z`B5C!`OB)S0CMuNjU;0ecw#5Xi$@k~0Ur&P=uYq4>lTWXm`!oH%~ zBDV8<>q@5mj95&r5KA4IcLgRHyZjL4#YI#0J&RiFl}-g48?Kb{0v#~DBbjmU^M2BF3 z5;AZC%dS|-a4ZnT`esWr{|*IHT~%#QD!e0LkD|gHdg(mQ=!|%B+`L;H`O|C`ZG89U z(7X88>EZY1uTNjUx$q8Ozj}3YX=Yk+2!^Q3#$zF3tI07${aOMlk4NzxB%S)+Ug4wDRAP>=O@z#3g*Z`HLe%4?VH-*5UE$x1GwV``li}s)G z?aCceNV6Qdjg58e8L$9KW82&TkNk*DzGplGh3h4opdg|`bWGJVURB|c#j!MbN#m!g z6S0X$!9y#}Eums*kJtnxRu!xx%7c1vY@YE|045Wlp6G~xzapIDiIC*-3t$nE8xp}5dWuuaff#hw3L?FvF;Vv$ zT)AYOFARJvzQ?BMXSC7B81y!c$RRvi418bc-7*R z+`{W}gY(=S+5A;bR_(J;q;oDFN@N@&lBO(`E#zcTkgTrh0}aq0OUsNR2&j?;<2Y1M z{(qwA(ec^&@!`Sc@sTV(Pa|}q1hZHLZlvW0qw!oUR3;)os4SbR2Hn(ab+K_y(i@VZ zlQV?FPDfs&6c?R1{zy{Q+ zF-vE9`W&4?_!N!HU7C+wpz5xMRbdthFE)=yrz_H4R0?B<{3WvqiZB z_~f>hYhTuzBWJ8lo7iiz+&1a-$*BT|iU_ zNm2s&jQ+p>_x~x8E{n{~8?}_P%AgBkEXx_wnO-hmULX<&=^|16=!km5s&hpt+l=cybX{Rqgaeq=hGL&E{6UJ0adeslg(PFVV*j-F#Xhvo%UBJ5i&BDZY%L6;uD;o7ZL|b69f;1-4LXBv?g-{zWzAc+U zSG|zj^!RiJbNTA|vsYJ5M+~w_Pldr6I`>p0-?PE{SK}|lLNe5MT zD{dYa^(=_R7wmE)^9+dvMR%%b>yeZ$xfzts4D!Y}{hhp|dbbbuzFg8^$Oxn;sdOgM zYBo#8ayO_p)$l?TRmvC?K!Mmkb0g;sNjA9}a0%Hs6f1%ll!j>V9W{I7{HdH)LJSu5 z)sB)dc~5O=dYsG8EXCt74UGP}+%ZD{!t;!MrxTGQ{Y@+^Y=(8vGAGg4<8%^}P~u3^ zjE=>slOMY}fa+RHAXfGQMED_1rb1Ndq+gatxs>snTs8*fkgQ7LfN+#zb#oAw11Pr& zoB0uNxtR)%5eV5mDcIO?g*6hQ{B6s16(!0rOEzWQ^tUu3pduXRbzpZJTPL)3!CFW^ zkVPf1YqF>WXqB&pd3cb6Jg7&}U6-t>3yYAYq5z-vE-qfG0pn=2fQVKishmy83}Kso zE10SN?mw4H){JCR7IM96nI7l8sqSzZncj*odYr+w>U92`+%RQEdP#Zil9U4|J1bgL zIZNpbr;CDrP$HkYGhIFOOGjerMSkSAMJD>;4w_*O&My(cq4?|jz7e1**h&_yY|Ifr zRfvOMpj%32)1dLMGFKVqR`S%OM8yce)KY$(T#5~4%&ho@aQz`hLn9_W1OT=5)2V5&23pd36YmzgaL ztIQT0wkCtW@A`x1U;BN(-`jnLX5qdOpB3oTkXTDdS$c+(O7Ur!L7Ka&2BA#u)7O{B zLv&Timde^*KhULP!Qx?`LAar7891uB40NoXF6{)`lC}>SD+O}~(&0)y&?&lI!C&{W z_eK%B^|TS$%a}JJp3rVdD3dI}36ckDrYF`=@Rd=Rc{w0~V@|dTVl3r~W2e^LxkIOXb0RJeH&%8hElnV;)W?kTt}p6!Lj7tV{PGjYgE6uUUQXF$ESHXx)?B&z#qL%ud=MuGC5VtG(7T_4&vh*6^h{coI z&cSK+5<*u|pb))N+kIGcHB%NQiSZp18`XCtn5%4Nm7Hxn5n4=LZL+Ot*LL}9*KXN6 zOiS84A)bl@+2lq~%?~6-B)`>lWL}8HQCdAz2#ExpvnH%*C`cLSx{Pz43kDRq2Pu@A z(#aIz8%!gW2SUOA7n@7au}Ya^yl^Y@AL9h8@>(flf=mu1^UO(3mbzLMhT4g#a=}#O zFxz@-Ppq1%r!ClO9cse*>d;eN1KilQ`u)977cZv-!I#`ALAva!HkH-VX`>BrIIy|| z9!ysU4q?v#ug2txkktt@JFK>wl)V(oTd=r_QG)T5i)WQ%jg0jPfpscWmY9XgB4C+; z>{cufZMi4=_Vw$ISu6By5hI*-EgdYcU5qQQ>d4`%vcq7$Qds+2(@W7iUbMiKyHr5t z@Kr0i*7-21=j+3##^{poBxK-`iKVlYa%FPWMYiVBk3{C$gHwN{^2nHj?P5Gq-LQae z*3cllZ{3>I+jLX809G+|i8MslkS$kBH&H}yNK822K`Fr@6<<|88=PkILL6RN?dm{VGVbbtTe5BiUTman`gBu z_xP6%Qmpub|X3_!6Jyr_l#ZhD&t>C0Kle6o-LDty?jK*EG3Y} zb}Y863io`iw;RiGs%T9oT+nBWQm2K3`Ifq@6>uD|Su%&nTb0G3SF<#z*S>5AcDd%E zYP=PR>ehA*Uw6t^4hNT0(@_#?FNC!=6eROPE8(w???4$Cm__IplZ9cDr(#U z8@J_P#{9dK%@ZX5JvlODPM8&sTC7&5J}78H^7aR2x2UG#$0MI9zl4an*l0!0TCnLn zK9IrA@Q+1RQ^h)2u7puXVFTKxaRIL>R3n65F7FF4X;UW*n5Kqo^i^xc z>`ALNSxlr<*X~&6?15AuSq;??R;A=EADJ8aZAL>CGBKs)utCnonLJLK;xxQ!Cs*@1 z9ZX3$hr}l2MxI^vFyv@}xg4{Q^fqXmkraMwd^{Y79*#3=p4en^`d{xbBM6$&mejJ_ z`V*3@M2I2Wq)@AMidKp&^bq|J|CSII4-44VoD7yr`q?5ORij+hBe+a*jl*mX7Uk7G zwFjCNXkU{>E!H5z!1>X{X0$?Cw|*>h0mFB=La^(O8`&iu{v9sxa*pt?D>ExLbV4P2 zYVJpVyBu_-CHbrRqDCTjOYo5F%Aovc*Y21e!n*Sf%_X{fO{)`nOaW}XUABc z8cQa&^6ai%7j~Kj;f^|Gt{clzCJH#mq1h%3hgp(Uo!aF}0KOm*2{M+VQ^N#}>;1|U zwKljQPdGFvh-ym|jYci58H-Gm?WOho5e8pq=@|@kj)Xzp!mE~LGnTN3O%@kPN^p3{ zVxFY}rs#=$gXAk@zY{%!)z9<-aajsWzk>yv=g01N#^Q;#YcsduFhyF(L8TU z51}DP42QfY=qmp4be}wllh}o6%zGQipX=i)zGAtib+ZtY?Ji;*kV0oa$5DKqv915f+hk8j;_LEu(4K4vPFzS_z zU8=}{DE$WDYFx1+3qz{z)VZ-MwlVnGp<2b3n|)Sf$-AJ}h*=?g%xb9?9Zo|MfFDp8 z+O4VQcE(t>Q*CY+eJf<2lc`ZRQE~zjtA|SYn8(+^DGMb3wB8q9omp8gWkSxpfJv&Y z9Z^kl;*Hx5m|E>zB||jW-Fs%_nnt{ictW>1%n4K=p?JGG{Zy7qjl;$Ua$6};F=U=` zu`Q8sH0O&EdzU}YeRnoPwz-2gP2J6Z>oyAwHgfVA3ojB9)N`^fuo~N{T8$?kIvIP} zTfI|AwO+yYDqlOuWh?FXg@UO>aACuyQt+IdErHrLg}mz@ZY6^+rOVNdzCuHm7j}UY zYr;5joq&TWV_YSuACc^qkQn`Auix+Yy}jM9o`3bvC8!HcxRmV2G+WShHLUh~{t6SW zde++zG={xRku(OUD)Q9sKXs1+J!t3x!jw?{0QMXzDa@4M5N@5+I97Sbo2o;oXd`L8 zT8h$&Mov}D31%pn0-M?sEA%%w!f^oIe#vl%M(Q^@Ig^Q_bH;}hWG}5cS0>Cr-3D&I zbgRO3oS>CPaF_CWSww?|2p>;(!6uB`)fQtx-bs*`GNM>z#MWmrGF(obu%4VryHI+g zMUC!S3*{P)^*t-iR<2}29y3oP;`R-aKLf5R&96kslPGyKu{&Sc7bCV-V3G@felBnL zK9C7}h|1K4QzAXo^`>8sKjjWz=;rQ48ngchA~p{_<@KI=W15m%97Vm2l<+L2LFOqi zVwWenq6z3#%$|)6RM%TG)jc%m`||(&-tMzH9&_r-m2wHUiN#F_@MBmW3&LFcgSV3c zIkXl{a{|}N8k^OH{OuaCtff%Z+kudh5kXxc@w!50b`OCEPtMHTIvHCJ;p#L_f;q&i zs3~N;6Y_f(QW-z1&yQd`&BFBxj2oI}a~ydz;b1;dF9ajKqr?gJDA31|@GWU7os-3c zF>165Ow8~6b!(Wgt13X2a;4WK%Hh~6)B!@ zSF{LuQ|xA?C-~WqhYp{YPNJ8ztK(iHOlOs0m}fs8Dr1d1pR9TfYlq#|Ol8sOWN=v3v{{)_rUlY`J~Alt`AE)1mYS=(74{jE zO`(iwpeolSjZsK$>{t=$cO+1!Bx4$raL2h+P#UiOVL$q(RY%?C(Dk}i)w~vpu^!ZZonB5mx|!BV>Lau@Np_Kt z_di|is7$q~7_c1DcRw8Oh}Y=9(CdW67a0z&-TSM`_b@ISI=L#pVj+0v>4C0aZE z-EKggi@eN_M=HQN&J{}uqt9K;0Zg9S%@&o#i#Y|;QZ5h4AY*yml~rbKQwJ+Kr$H;q zgTh|XaFPtsY$0?(cO`RlU4tokrTHoG3T;lzpN|%Jl?v=9GTykj~ovtSPRus%Oh1J8Q98S9oU& zv}yu89n>B(%F}816A1OpN%*-3dpeZ8bHryAJ=!+2uE5WRChiga*#PxkA)pO#?;Qu) z0Q*lL3|i1B?i>-i8b?1=U}#e#_lXW|f_uLZ(I&|Ej}vWz{^t)Cb$Wlth|$&f`XK^G z>l?Ux^k_ZI`-G6zL%nYtX+7jWeK4u3Lq2{)X+`^w9adU_!sEr37L;>Ym}J%V7PfV^9l5g0%*swuAkV zqEQ{>YC=-;iS+3QrIz}$p2*ZHYP5|_Eur)=0#w}1!c{XkryJqwu5Qc1Tnh@+Q=n@_plgX` z+C;nFld$)UcXd#18T9%vtZ?VB*FqPbVqfnb`|7G1cM5=QRt=Yiz`6$7&o&O$<;hip zVO<^Wvk8ZFI=v(&Ht%A)sMsdhwV|=qjr^H|W6M4)4;CR?VVYbiMz#*swFSyLv#4#T ztSf)+6E9oY{C`BmtV6^5hRs%!@zW2SEwlH1qGua-TDNgYAf+t*(AGiaBXF?PZ73D2=pHtX1kPKo?>m+6l+_@cdG{6Hp+&^ zklRWOp5kurA9ve^u%B!2t)<7^BmCAi)3l1g%^SXd6mEU<4-|@9+u$c3k6VlRCmfVp zkMl~Axdo1Uip_nz*xcF?eB1!tdPZ7%lx}^G*BPo?+sggob?fQ$X9(J@?cLfUca`6g z+Gbc5Tv6&E47HzBA_@qFWMiWf+jZPnT<2ABN!2b_29`F&6g|G{;LV88s`)awQh>{{ zXe&v<{zT^5{?!ON#xueb9OTE3KeN%VB*^}aUa^>FEEQa1N}0h^9O{cjiJRj}y^2D_ zv)GS@B+m4WyE$T;IY7S!j^Jh4fL#I+2zSQo%-{uQl)fG&)qJg&e!*B#qNFt!0F5D< z8Jr!XOR1tYG3*vBI<$ptS1~%~Ni6gaj?U*1u`XAKhw!YZL%PFam(*9<%EjSz94)?0 z*{sO0ss>8uk#drs;p>Kc-=GP|C4`FlR)X4c%N>xHWX}eiE+O8C%HJH~J*$3N0Ug;*zd*OJea@ zNaDpIi(|PJ;+O1LomXh-MvB5MB(d0Euz5CNV5pD>8{z?{A(7!a@|a);k#_+}c9V*4qqhQ|3k=O}s-(A~BNBtBiSDVi>dU^W*-SZ#S%v~OOK=8q84}~b zR#_26=T4GSrj~exErDfbR{TYZ>{UGFEV7njtc*Fk=?121W~t>2Rb(e;$E?f*XC$3b zFkSQFw)v#sn32C8ir3OIW7Qv`!zqp@l6}}Mq=Sh=G=V@nWz$S@JB6&j#kZw-GhsB& z#IKB@%{}GA>|J_ER#U zJWCe^N~`i-Vhs&cK)OOp=n3N#49e}{>ng2U$nc~!Xi;{H&SvursGs2phttlK1Z*~g z1X$ax8V%`$@T_&as<=A!yTuE{r+9b&`4D5@_kDC05zL7Y8iH@B#pOHl5I@_I%7Kpm z1~?g>v_dv9Zdk1m7FCoyY~6%R8O2v?gUd?BPyl{VN`H`SHbfx{u1V@srk-o|7$SY_ zq5gV&N+Nmkk>SY@4F+CFMij^1VBn?CWO@QQ7RFeeSUzee<5QM_1Ac5yXeykfaEvgd zJ7eSA&rS8-Xl0rjvpLV;><7nlfFeBtLd^`0v8vTsXme<;=#O&NOHz7+A>>_BvZq@( z&i($R=9A;^EE2QDxvKgDS;zvX*tLV(RgLFafdd{hj=#*HrC|Q${Am!jact3m>E8-X z=sGI~(_8j7yQ$5ZaBq3e2pZLt-Nt$y0UP(2MIlLr(h{;5PWqO|RZFO17=@xEK#fSm zZY!wM7FI2J?-1neuBz=Ky{)+JzN@3W&ZZPmAKh(1W`N-8h+;_edJI41({1TmGW8Ia5>Yi8$2_%Rr-J;MIO5sX59QyAdECErDCL|^)h|jq>+!RYUi=}bGAJ3x*3Oi9RCIe|9P@sS} zL|QKJ6Vv$%I(AHuM+zzJA-txQAfK#PqEHJ6qD{4>l5!*PK;C6(AVI#{zJFsoi+raa0 z4i4o;N`NxaxOpPdRPUnH@`w`(+k&DSyJj*euq|UQX!v6pK(=LZNJe^2j{0J zr{4|B?_jYZNlF5(3R$jbHv@lnfWWc_3h+F}H<(6hzXY%M&1*5(2~Wyn?TGMK>ip6c z;?@aV-pS&jC?rxs*g9SW556?Zmz9Psmxfl@XgOKq4cub|w`rGE1ZehFEkRaptX!aC zi_{9*%6lod9knGYdN@7OR>{T1+90*+dfo1*3{~#}Ooozm?|ihwmuIo1+WqwX!N7NR zK)bt7JD|te0TmcRE}>cq9f7Nt9et#hSXI1YPh@2azfIYk@R&qq?BD9K-w+_qTDE6=?X$6VFJCfDD*=N0b1zb0tRmf z9Ufd9qo2M%J{1rGoZ*N~{3+%J+FLOaG$IqSWvcIty<>1}VY{vy+n%wl8Dqw_ZQHhO zXU2ABY}>YN+v%Net=e_gIdyi`?*H9Yqq_SYqps_I?k8{Rr}(t==RKJlr}gq{{fBg= zJz7i6b9WO_MvG!2rD7nUch6VmM5?iNGkQH0z=6FfJRx+5yYwtn*oDeN+iGY`O7VVUA}x!}9)JPXyV;>bXYQ3H1jhlT**MXPf99Y`ScWa%*nP zyFuD@bL-B}gMW1`Cgy?hvsodZ81VV~5P9B;S-&8*Ch7gr`NX5FoU*C)c@BDAgvKEnY9}HXUuOyZuu_jg}2%>x^><0ZJIT z%&FCoklUj;HHT!+0)?7?&m+YA>YC+PrP#LH}@9d^`W5v_}HKRx&_{PLSh;BA@< zAJ$PXiq0B{4+qCBK3y*Rt&7KNjq97<&NI;B_L=~{T-p~_!ke_+Ziv$_r;Qb$?}yT+ z6}%oJ(GTw1TcM(+nqZ%o=;xH(>!itUlwF^PRW*<=N~%l9xb*(*trb4YpJLpz5n1h< z=5Ke-3#s)MY1{k*#Z)Lz9a_Ewl{PBvu60S-e7CpLo1mY`|0X}LNug`+{8po!chQKp zBB}*Gc02Fw%k1@zfw7k%y!%lshoeIe3sVxKPn(q2;!#eS>K*p%G0%cym!dLAkE~Uj z%elb;CbHnIsgf$np&axDMBH&@<8cVJNfbr{ZdpVB;E+Hds?3r6w0dM#qH?|pxB{*( z{}LswNOdRag(9<;IvGuWL%pjYg#%5^agd~kr1n1puvCb_*1^737^DtRyy0w$&mI-7 z+-$qTEAH|8gKR=6QKa##l^@?c_hj&2$K|(sK};l?;XShAkqw`>sv={ovivHhV}F#3 zqo+#|d||J$tdL>HgHD-aC_){nz4(9WWF{{qxK4>5-9>oB3+(}Q2JfY69!nF~IT6oP z!$DC*ud~#7TUt~RnoPsT&PIF(GXKnrQ6-l4roo}864a_gEc+J+-|0?s;VTJW#t^fe zPcf3(a2ob`i|$JoPs^0?!LnCysFAF7YoRDrublVX)BjrIjz^J)A&xwVS2jcT=(Xh( zZ@$Tl#B9>0ahCP5|488_Li*^_NNBhhrdBkMM~cC~XxTVj8g^Tm(+;awPYN6UGvL5U z?)IyEN~c*V%QWR>H5Jlez*9AutV~4TO{PT=gi?q;)#*(qgR>Y)HWBLH%ZUSP_x+fd zPHj^j1GJnNAS?55f7cc=Nb?~9t8D&j`Iyc^T;wL=sR%0s`F_-?Sp%`RQ0w6rE4| zmOmx@jU{m6LA1YZ!6Fvg+D%sIRJ2_k5`@9QkEda+^4Cg2n*95O=&Qi1R1@dHSyrfv zVcjKW8U=&sA%T+BUNZ<0$Z>BERXCfEzOL3g;6KSvET|XlX@rWF!DEschT!+Yp+xRK z-h#7ETE=?@QMs|hJEi7{eh$OxsFNL0_j}zwKcdH3(qacT(XAfGtIAmsEf$0V4{`aH z`SOOSPn-O|zWh9mFP%GL0AbLMtvYpl2<8t3W%SCyF?b1qE=0wQIUup;kHmJHb56)J z)g6DUogOi%IxzxX4tzOW5qBnJ&kJ)RAgFe4B9YNBL>&ds@#Av5%W^Kp+$sBZtoFKe zPTopT)zYB#%3B6Gg0EjQ2kF9^`C}APa@(fBZF^>`fRu*UX`9E7ukQ!5nO(b{9fnW5 z$DZ|#kN%50iB>$}+Rra3bELz?%78_K08zHk$-;GcT!PgnuV zPA-N=ih}3OrLcn}(kv=CynY^=Fqf=ceTZ4o-7S23!24pKC4D{`Z0!%(ak)ya8C490 zydH0<1{gz?$4xII*$8d6%Mo;(hiL=@aH01ULJ?4uy7Zw5cdBq(V$?|(UdYRzOw~QB zr_TPg}}N;2kD;>Ga;|zb_sU+qb}>zY4p^U9S{3+0v=O4re1RR*0yIeb0EuL2hd;Rq$q?ei z!DSKP8r3_)R@bs$QzuFHLoB-)p5|Ux=;!4=A+x`KcqQjz zsHLlsrdF=NAZMNA%(#{AVDO_gS1AwPk^}LBAqa$vA!O3e0t^NS{8+B)^_yfX)b|Fz z-j*rkZX_ol53=I;4`RR6D$!LHhuPLevMqbhZrqIT6~D(}fh*A06j8$Rf}A~s2lmCs z&1%Z>F7nRdeOJKQry||#3^Slxcjm59-v6R5rZ_h^;fcH1R;-jqw`H22wSL%YW|iwO zYl9bM>i2Pbw7H*oFoUwhT-?{WM7&9EFa5h8O@-x(o~`kM->lv6dv=ilow(dP5##jCpl*D3&gLS?^Yd zuc;t7)M!6v%ySSW7l|-s^nYB37%c4`OumQRG|O+B7+snx;wXq;A?jH!SNKh7^2c!j z>6t&b#YXzxpx&;=;`H#MHQ?eWdV<~h+_TkX)-jWN>Gz*b?`>2rme_&Bi)dbU8eX>n zo|aL&l3=>#&0;egpV!$w=r4sy4GhG&sXQl{1N$;VC*8fG2SCHizpd&G@q$zD=bB!X zd3IM*Dc?)6_gC3tS`k;*&i%0Ad)etMX$Bl(B50dPeW+RPa}K~4J&?CQDSsdu*+xX2 zDc3eJz6yW7d>OSe9dgj;yjRw6Ls?Uy@neN(0IjC7t7B^Yj-Q-NYS1Lp3zTmRlu*5^ zW#@j9QmyBpKz&j$2oEDrT<=Kt#L>B1JrB@bBRML`#&D>4lVrXVhI`#M4~B3ry?xz4 z;(*YO0fX=QGN@i44=T&3+Yw(=UO9qJfhzC#(0g75=wfdre`b6TXA60lV|BMH~)?C>B*Uf2WOIXbbfGzU) zbA`gRJ_Y2li)HGULOdDEwiyE4E}B>R-n_ns)LAmd1X0_kO4GbJ+}%W)sBR$Ied2Y| z7_zQpS)OQ|oePW4Xe?hQdJGi{Mf2YmhXuS=seV>3>Juf68a|W$m&Cv0C-IcXifaCV z1gdSCd8JWBDF|%pB@_#_UYeq6#pgY4^y)zOtu^fmDpSXXvN5rH+G9EJ)~(4S{7Fe= zSSI_u?3VokTbDHrK1^9=*PXq~3Vtk8H8;Uebke(0s^)t>llXj%Lxn-EWq^;<6?VMNnpBetQ}!} zkK|=F=`)Ib+vk9;8{_%=msACZ6Y5-(@4~7F&XMUPv$^c?SPaq%RzxqLpimvp-J&Dt zEQnd0IIO6n)pEF?Hv~>b9qL!c2=&6Jog*Knbfk)p@)n8!(Z)+NL)h3|HpHjIUs9k8 zMoFM$eLp|7BU5e+^D&5)0T{sc<#4jxnCxb(0Gsm;g1Zb_Dq1cVJXQ=dMb`JQaBrl- zK1s60ps@qSXj|!=Bf${s12D29S{seC!|p_%jPzL04WWq9C`KNI$h;s$gq)(C+-z2K zrCi~Wr&S3j2A3X3rci<96H2#MSS*w;H~BRwzwGiBR~o<5OX$Q_*k@~7)98s+`5)+U z6(>0Au*CT)tjV2GgGy5e0ZJTCEX5-E;QIqlN!SDVQ0OnOpZ!+ZH2St_%BO6E97%RFYfgn5CPPYnEe3HBxBhMn%*%O~+pxD<@J74PS6~CGW zx)N}z4yLBU!}|C0i$7P1u+QbQjgXPzCe@Ps0e>Wod=BlIl+VzFP_gh1aDvmrdtdO2 zlsjoBf6iCA<4P3~hM2tkX^^&ruzqiXw%jTCL#>l!im5Z85UER8><=tK$QUPqFlNoN z3e(WV`WI80zb0TbD+dzNFTU5D;4-G}E;n-)Q6sdOZt^ZWm zy0GD!&~a2wZ+j&F!>H&=^oX3vm#dFpJpQ{)gL51kAQY&wBS2IbsUdNk%M_6m+S$YT zm+8u+iZofVq>q@#!2)M-P65M(ZG{w;OsleP)Kh+Xq>u?LL<$*5&p#L0J_3*eXB;U+ zdOtX15vxtMT080#LS;`VlIp%xqBa&VZ(o|uRkO{Yn$#bMeA?mRWkPT%SJxwl8KU{4q#oS0N!9I;r&>O>cPZeNF4+xKtPZdp8CTjNc5o~uJ7@O zv|9JJ1C@@Lgk1rOFN!DFY&8IGu77vG8oeiqfCkH)dmO0#s>TxKo_&|2rfghjlIl#w zFZ7SuRE|knPUq~9B5%sSLyoMGryz9JiR`8ePd!H zgiF=QZV`ymE*@mV@W=6ivBxF1Rq(IVYxU0;5_d4!LH-?Zo>|bZwYhAKXC-;bmSp_$ zPaST)?s6~K&F|NPRVZx@%E(;PK)&x&uwvrhclDia4p8p`2f)uF&$ra@Wo0~y=;?(~ z>IZAyEMc$A%ovGlek6atCPa)veOerH^Lh?(N%djvq28rlweH=b(bCXxNS05k--(B* zdxoYwVP@OnK+gyK>7g!;e4n9A0K6m#3`G$D56yqTy>^UQO0$SR*rMm(5z#WOz{(pc zBh<#1?wbH7j3h;e#lllfAN!6s=(EmatsLe=>Oi?$<~{$#Xn>rfpazn<6KzFoQ7KV7 z21k0E8@IyN>K(>P*EfhMANFbSz}n7$WN>~+891X2L*Owin%>?sh?!#{r8WuwcjRI~ zl`$wuOvyXKKBB8Xme+6Vw8-4d+8bx`i9cFh*5|G5cwp$bU&Y!5@S|)ji6^YynZFY; zhs{s+cg+{$kA5|Gcd_?W*7z~|l}9#!$kK;8<;sUQC=^YQ?X|A z93RDhxgfT>rjzTt)q-eW-Z;Mx@f1|HVP?C)*?IW8l;FN0dj8yB&Dhfhq8c`S8qRoq zXc_M~j^1y2KtlxyLMu70&`%>4QM7M$=k|pQU)5+cR^>g*D$Q{m+@XnvNq4_G$73HRvD?et^Kuku+ zxp6{-OClC{L$3ZeSM}L6JfO-(-&S3IgkK#!CE|Z?{Qi_Cdhko0VYOL%=iNkQTWy8z zcE=p?vILG%=g1nPJ_WL)n!SHJ$927m@g?&t{!e!ou5P-968SG#T#DU=S^leZ|@ZtlY*icaOalDSESY5qh}!y6Bb{VH#+Jz4A_ya#RxxTlDCZ8DN~* zPm(t7p3YuMS6Y%5E^=jS?8M9t2xM!tKyiZ2hZ)B9Kw-o<)brxm;$1m83KuRi&x7g( zrK|;T?-==VzTGYqCOiJsA|b%6nU89e*wu;rY@2QdwKh)&@=D1@^^`H_;ym8n~ctZ@XuTYw2oIO3izjq#-!FWKRj$tM4j>A18-?VN` zYLKWzmSc1|hoqALaky~0EOZDrePx$ooSC7Q1JC6A;Cp7IE@bJz%joUylX_&>-f5zJ=2i&5U-R&qiXt` zJdY;}o)Y9)lOKcmRHs0fm6SUi$P2WsDRmv&D1W9jljk%4WyGqd#0oRkZ0w`aYiDsy z4!asR&J(n*O|Onw__x+A>cm0D*2Lp=9Oyf-{brh6=#UOBTB`9@e3R^3b&n*?Jcpj+ zWQONB%Foy{lx)-q@+FrQdSJX9IWDs_XcDd03g4#GE!WLDx&Q+;&ro;&B!2V-CVzfM zAR~12PowjmM{{XWhC%9=(rLgq2rj-4GY1wf90DvtS!!lG|8n+Jr{nQI_9X8uHjYf5 zC5ncLwZ{FUr_MWEK0*S83WM03_j0G}bb?lz=ky?r83Jzp%0K~6kH+tNT$IlG(U`hX zHH0>J1do`!D0o_?NuP@>F^tgbNQvY8Wv4NE#!CGp1KtT-UNHymMDm)sYughG=w1 zX(1a{hK5)Ci1}cxkp$=({JP=FDgpk}W@)d?cYL5N@E{n&_3-VOQl{=lUX_C5f?i-b z+e<%pT0bG(PZOR^IT+NnDob|ud9L@ZohJ`Bmd1ox5ndsLvL_a~cI#`09ILg(hd)y# zD|HJVIz4_Geh+3R_SG|`WdU!Pvlku#-9+6`v;X-J#~=Z3N4Xjke0d^ z6Nfplu{|<^Nv(Nq$DkMJ*Ie zp9{nBJB(SZ9AV5(-{jf`@!}iGTSjnh>bdp3YCYZcn~$7hc=d z7i5}u!zxnKCOa}NL)9vbOU{4sThUebo`NB-pq7b+oRsp(V{{cKL;L5;xt1xGL9;br zA4&(<;6l(zTe(TH97gXD-tR1$o(q4enq_n0{hDF{j(|ND(@e=jwY;mHV^ zRsFbpG#qoi@FW@6nG5Th0LqRILwMDtg9Icobi`kD_1G2T+*K~6kn%x+#!S76f^oZ?X@ln0^hwbj<@k+XY?^=TVqqeAX$ zRiZLcdv0FGMd#NUATm!Y^RBf4UcGpU)A)X7eY~qnj43u@WFL@9s=cOxO8Je+HS+0C zZ~yTqbnR<0XYaFIZeGGZ_%r#zVwR6h+=NhK`R^5{1n%P@0rE~!3e-bLay?Z-Sh(Yl z0LN#kvr|K_{s61cok^%2u}H8vlfz5(Z6hXgOT2oG| z+!Ixwz71!|X4d1sO1r}1>6RClEAUe-Ox9YGf@{@p%>s?mBjq3PK5Bmh5()8YkL;C(svca%JyK`MSXJdLq zYjhKQb1)Y81=hvoIY9(Z?X3PBo_eM$z7wV>TY)^9Gr%z9i ze;n3QbdP&YzU_h5%0r4~CUE)<=E={SUhoTAB)76gkW}352||7n(e1nNR1QI^7Y%rC zxbFZ%)R}!1SX5I&r6%&K>E6RM9!tZ@L!Br?k{a$e)--a` z@cKN`QlPeu;4VblAdNBM#=}m$_0oBCIVS*dhoFlg3t+e7$KlNbXi=!pWetH>{Iom@ zR46c6l!Ay%RLDhI-Bm|FM^(Pzi8;O9S9O8y7%u#g2j~bbA`kIxR}WcIVwe& zPV<@mR&7K)UU6RbnD>5mp6A7q)cd-SKC%2x)$a zbN98{TO%H{b=~C<5y^DT@WWDssXt4E$_?GPIWximAosS+9nZ8X2C>!6HbFiYBSPg4 zn2RT5V=tcX3s1>Uh3(WVTM1m|pQB1At$S^BpVDBpINZ%CMA%vDGeTF-){#$Na1gzZisGo&T3bX?b>xLUG1|sG(JpFv-Y>0 z&COQMoq)q;&p$h$_v(=(W1qMnBFI>fODSkI3MbX(6`^2a`yj*7U~HL77qQtbdcK$! z$6+qO3f}wc97>LQ>8}hVllh($1M!dbjA%f<@4zy2#CRHs6qjwqD`c(6hF&K;v^-f@ z@n{WcSaNYMvsu!&r8u40*n~Dld`35@OzN1+vGgY_kbSGc^@b;WTraq}tX&MLYuIgC}v(2P$11fTQR#hBqX-QTg*Z5fP>bG|m3!k{L;i z0?gnr-)N2B6#bZQR@nNJDX;Gq*idef=NscvvC*4)gTpKWPB*abQBIw98oNu>TR~7PixQ{&SI;V*#0f@EboWYh~&KwPac<_F*1_c z!NiC*4YY^lxoi(;-adZyJ;e$Emk!z?NYiL?oI!RrY1m4kc;~f8{tnlFAL8 z)SV4G>}cCHy`-8zUVdFRtJ>Qcldx$Omu?lp8*D8;(^+pgA_d7@Yk#bawNEupXDnrZ zzImh!(Uz^!hJ$ ztc1z7u02C17&thxFzX>+!^e|68lF^l%qCQE?K{oFd3c)j%qxF zM8fZKc)2>(Fnzd3O}bD*c&x1mn!K2!u^Q23y@zbn!gdmulFHy=N*-EoGgwaoWZ#tY zbd{R%vbwdyA)L~%fWU(>a%8hWbEb@Df@};GCuQ&7o>IFufoN{)C^o-t8-iey5VS6? zt8!;zOPNoc>hC-G%J=#TXd$io6TGyh=JT4Zct6{$Ygd~rT57*-N`6vX~9WV5=6yuIbx9z-OuEOLrrIWSWp*? z(U?DI$C)R-%dy#Z>XO!$UGtRMhI&Y|BS>84(Sp*O(2n6Z6_q+FGO)QOBgycrd zByHbEU^6Uw0w}~9`}GaRZS1pA9Tx#3hs{=E+MkngI+~5B`QATmI5=_9@YBPERZM2p zg@f+$-6>_NzgU_5re%~%>hK>#kZrG7P7abD(@iTW`Xr6#)R>oGktZovQXr9@V8`AM zbXy5aCA{=cjgX3#Tz+}Suq5$9&8$psN2ryv)enzTxhmtg*aJqvgP`YXkP(pmvvU9F zBTgm2Dl*4QKZpH?D?hCkU0J>eG<4~ow|I)F%YdJJ&AL6Pw)3v$8v5nZ!}L5SD7_xl z=|?(&)Xt>#brVj0)%5W~uYRL36VTULGA8Uq#b8S92O>g3l7pDy=4>dQqC9@m9=@@~5SdV4$xBjTi2>vu-Mv$nvhb7S(md{LC-BeKelN3dj_^l>pQ0T?S)NfjmgMl zK=gc~-vVMmq6SOiM_IUVbrrFyU8IITtr0)N+d4phD&{t_-$T$xVowb5PJbGJe>xL; z-B^$rDAS(#_jq;uP`PG3^ zT}#E~vt2Q>R^O`l1DQMje;_kh@DF4b1^VBRIcBZrp9$=;md?uCGF$hR>A%ms+J|{g zn{}-(tJ^8|9e*E8p38-y`Xl@EkfJ}cTp(LXxU3k)OSn-Lpr)Bc%OH--R<;xtINaO& zmMePMmtvq@&Kw_B$`QDYNKHT`S3J|+01E~ha`wP}R-i*W_6rFf*7!N|3OgLXGQ928 z00TSa&&^<=QYAIhiSr@(k=851GW~Uiqkb#?K$$^kJB0EkD6SpLccrX%MVmzY#)s;nea* z1QB%YAb27@Iduw*f6-@%K4d&?E;uE@mE0{I9v?iN9rjGyji{}#x1{CLcXM~Kfv5ox z27Ehn|4sAhWNqhUEg`DWwP1xd#_LAc%fVcaB<)Sr;&-C~P)B#65i0fPM-lY=4F)kr z&F&Vm@0-zo8KgwRM5c9!??gKK-ke1&Zd7W8Z^$J@KB;myWgd@zVl7n@M<#j$?-1jlpf-F~V-5)Z&`jxTBXOr%KSZlfd(zpSv^EORP${TSSPWyJ$BxcGC zD`0lNlU7LZuZF&cSH@OM4HMIhed%M+)_z0A;q8nVQlN7 zP^hl>HT;WDHF$l)wInyfRPtoG~C5>s;VO=4ar}X z@QpPu!Ch1PYH}ANpBmS7!Fj`TgXu}P4fA3j38pX&miGJP?K$$cjuqY5>h2kX5 zjw;45yZbWXuF&0`9o=?3ENm#MRO>eiHbQ#xjtLiNH*;{8ldcHsHKn`I!*uN|{jGe^q>SW6?<{5^4R{z~7ck=N5_|X6`;w&V}*xSLLIV-)X7R#Hf z8iLw^rzmZqNP|Di*?E$spXh1perh#Kqo5le>ej->{P=f)(ao{Uxz78%)h zQvaTh(qiU$Hfpk=9rj95I&d+E*fNlb!(21ZKrHf!;0OB))`cK6I>a5Db(It)@n&Y) zj{4P#3>_I!o*3_GDZO6jJt9LtI zc8niKmn}T)Nf>2T_=8n&5I9T>J0$3TxdY25laPft(i+dcKRRv1;g5zI?4XWXhIxqCcK*?n+5AWbcyU&9+{5e<~#0(IqeZX_kY;~ zn_}uMN~^7v1q8cWl&`4QW+yKvSBH1M8hV^rX)b=qTL>qC%@bo=qnvM!PiIHhfxhNo z)iYlncn#mjjk#OXRftGr<5_0V2k=(IPs(yo6K7vnPY)+A2Uia-2d=+xd^zj3Fe3w_ zW|*rz{K@^Cmi4F0G0y1@{fnOA7alR8o5w53KE!42?-e zjB_y8-DhXcE-h1Nt}dsJj7RACJkjsIS28Ohvqk)Cq?6F^nsNep?U=DRVN6p~f8P<- zhFvBO87QL{P$7gczz^c3qjcxTe|AN!jFY(T0+sYz+`4GvBxa6F?RDO>%GgKjWn}4uMvg8fjwwR3xRE+pZe`To)`Rz{!_xijMW)92#Vk~ z&OX!vk*^*g&<#=P?XBlA29)giDYhWr)`3#v9jD6bvVbEu4D6ZL0~98<1BUs|hqVJxpZ=rK4AD26X_0cP5(Z zS%Bb-vv@gIYUsxqP?CDT>PxsbH@>p`Tv4yPduUe5K|TRgTj`Jz>-X}MEhSvjG-~qt zNC|d!FwvWZ3{TRrxb2np`U1$@QH}=634VyrVS_z7(q)71pU94$P+cO#a)}20;1&iK zgsa}=#%c)N8ZyOw$dNt@mL^7%)!eiK_)K{f-6)KGaJ9S&FIvgZzpuHjm5ZZRY5^Kn zfF{qa4EOV97ThH)T=rKewH#Ho?iMZx+Gu%Lu$*s!$BT~V^)<^uye!FoNRxi)g51M% z!3K>-s27%Deu@Z_>oVC9u|D4soIX!4kl*~*^QNeP1 zy6Udn=smB!HFyPN|4WWfqrY#XR!R3edosE+ytNAMSK;%wp7R3rtlK0!sxIPADBdM- zu~PTcn6mQuYp&3H*CNpIPc>UU>j7t0iE-f_*mu22$3HyGn#SF}0IHb+$l~yL2lH$93rqDIqF`i8}C8=za>Qa$p4TKc3S_D5Pw0b|4Tv) zzFXMtY6oQQRi z$Vna{?nq|sX<^mudXjN-HSJ)lRPnzmxC2?!e8ASYr%jClH@T?C2xYjsEpH&x5Du}C zFrJJOSepIY^(0v)D{Jo#=WEyC9U0p7@j$%tmSN$lQkq|Iysa5shE83Qsg-BGsSn* z;twtMGBk4rdb7ktVRaJj2mYYcRpXIOnuQj50@BsJ)9Gz4^;+C7e+Fi-B(3<0>$=7+ zY<-5y&rX;}A|Z+~XP+_?mCc+;YLYL%Ndv@gHA<=n+oaE z3&O(`CQtTWk*O*;AZJ|RGjN9}CReC0&WfDnDhuD2=ONt{D*p``+S0m+*6%X-2EC44 zeUrgvu%xXE$Fwdz65*&8`*HDf^>CUmq}!fGJ60QSLdgiDw$?e5b@eNAtE*-Z{ySQD zT*P_Wp&BM@GU+@DI-jnmvu&i?3vRyhF_wD#H25(Ke@q`B zM@R{KDHxBKhuZL9bx0&Wx6Aa#In!H73ic)w`ZKKBr}ClGPj7$(cU?#Y<1>har(d62 zqR9vGJDod2Nf5y?CrM+uz4wTVMQ3xnTnIhn&0B7uplDT8vu3dgaz1Jl}qOtUUPPhmQtNm~S;et-1%z1laD+F6q5k{sT>2FVU>K#`)x@Sewj$@xN%1={X=)X^;{>y+|TpJ{*p?bWHeIbeQKR)L>xY)O{iTn3} zrr45r)XC3tS&h96}4-!BJW<3GyeGC--d|%gBa~E$tDTaOkhBij$B1p>krAonF z6(ad!Btk?=xH@;t#V0bon|USZ{ivQ_>>U8srO$E20l<$F;-b?QkBwJqi zLg;$7zt*?Elzpv4D+Wur`>KHL==04SJ!Gy0tAYQydM`QK)rOq|&FD2bpQ-MDdxUJ3 zYlthCR_}0A%zhzw&brC3ZZw$NOK1<)U`x2t`;v$7KH3U$WEzM){ApW_YZmd%{j2Sr zaZosxFK>NHB~w%fzpdrOt>9x+$+6K~!pOEYi9qzpn`!x1ap_)@UuB%-6 z9*~FFj1EnAX>DCe=Ctj~+Z~W)7W>nc!+lp`m2A}Mn*h=!+K9Mc&^X%QRzKW#o4|*19pL`-V{R}cVKKkc5$FxM z28ii#0i^;7nrpB- z<3sb!VT#V?w*xOuaeWTCeu7uo&#NQR@ z1R@W?`I;5I9&xSskWT_RYG+)Ox2h26vgL2Ux6K>?aC>@H`Pmbr=xs&4;)zw$)cA=L z^O>Y=<3+^FH-1#vCr(rSEpf^JQx0YaF+ZR+=Y!g7Fc=OcpHzB=;~4k(S$N*>j((-v zpReBs@EPPyy5&U*E#lqZ>39P8zD#`-e4kwH?a=^sMCX2e-oujxm$?EWjF9rGYFX31(|n8)P(oE1 z_-L`zkBMj8N4mlC=K8gv+Vv~ufC!6|KDcL8FE3G_eMvC@9p|+F*o0jk^kKz`Z!Qy^ z<^xfKxS1aro&?dw55Udkt=0&@#q)K#{f{wdtOXc9_P)qUeavvINK7rwIp6-Xc%ve` zzog}xIWuOjxPnP)1#U?84d(07XF`-fL+kXtbPJL9dT6L7k+C;G@87S}K)`)D;i3c- z4efuL>7pRiuQl<}{hSONg)KubdSP}uJ?{X!V&yJC;`&Y|DF(S2o!8j#_k6(as}`f! zw|N=cId?7Owy%5cvJ@6-jm=QIaHTx{_S%}yXZ4;aT|mON8-+1+9m6@fH^&Q6IX-v7 zCsL1coQhkT2;~)i>&UHOi-23_J1fkeOMauYS=0=N@sC?Z6Mc3CS#O?KoFl-9)_2Tv zGAI3vmapY=y)4&h0hriOXLDFprmR$LhH4d0-j&y+DIeKs{LqF~;0dpz7^Sf!D}fhG z!0pxWOW~R{iQ(HagfWap+WNnq*!*KM=(PK6DI($kv4xWq1YC}~mB%y$T&Q-h|CVTn zY05<)a+RS~|7;UwBo@Drs~c7HOor(&Vc!@?@iPo}j?~^{M*YHWcG9-}y1Ct#0M^B5 z?rIz%v4&4+CnKzPvu=q%*uPAK&B(N*-70ccgibu|w881FF$H2ul7-#etb~{SOz1MLhcvH_$it@f~pN8h`MjT`}qYwT*u|qD9EY zcsL?KP(0VWYeo)V_JJ6tG^lUML1>$J-Z~x+@XY)Ci*> z@zkegu^nHNs8__q{8h>}C;ZMTaTKqDIL0TE$N4=GD38&RVvKZ4Ff&~EiFnYEbQ#8Y zANGhUQa2)i<#CGT?K0(u_g+~uxDn-aDc1A1M@(QhpX~nEBQJGmVC%Vv@ZU1}K7^yF z_r)}ih%Y1i^o+Z-+ZLnSy|0g!8#kbI1&?9ZMV-Xus|+M^CXs4Np$TK^902ee1p~$j z;0naUJMOl6%QE`>0dTbuG*Ivb*!}8I1Kd<6@A&QftcBb?`kfaZ@aq}rCws9$mWyE) z5Zkx%;rChBFi?3FeMkkbgu~4ztM-$_@^lYPfYnC|M@63$$7XW;iL&a`srB(GAAk%Kj%@HJ&s9T@&@y zCf-xezKT5SM1D~4>-i!lk@`OJewQG08ie_IG+dd8~moysul zovbuK5dw%vOEPC0=n2r}3z8EiJ5?KnHL)nI*%XcRt7&V`8hDAgspkK~{`i-!(b9&B z;TapY)L9y*D#v!6Q*~_651>bpHY5>i0Y;iyKssoBg*IZK4a;oW!hBysH5E+PN$!AM zNp6LT(J#dzW*DThPg+3+mHZm{Dw!l% zH&FbFiFw1cri)-Y3BHK?PAb(yh7qwK$-a8%sfAMs2VOe?{nxLb*VKQ+NG9>m}Pf0wn915*j zu0Nnn6_Ip+QpVboavFvEEI8dJ(t$%Fc|+V{D(`{8 z(<~^IW|`Ex`+;_PBazG02` z@bpaq2d*QIG@Ga2#ir8Dx$&f0ro1-x-|`m$I;>|UI&yl~Dst-io;#+-nGVr-8c^QP zG=dv&RWNdf;v=>^`$lU)Kbv8Un4UF3!N`rsdS8x(hB`JK4U$9%^Z&&vxr1u20|GIIy0Ask{uPM zGB-87n~}uS#Ywbf6GRp!8T%(a2Jy%SwW`t9FUAb4=9c`Yh9!M7tNA!|SNFf;&SzQF zZuS=OO>T~mPJavAUC3F)Y}pzrc!Hi5+K*X)hZZRwd+K=T6KwZ)gZzGq6qAflqwIe+1VF|Pv(RQBeoS2 z=%oMqw29MzEiZjTCowo#9f1@2`RhV1LOb-DlQd6t*p~*iS^xuxFGI%97-JBml_*k2 z$n3V`aNOL)QzNdAy+IhkC4`ZtN2cXMjbwElW(&qWp0u&x($hrosV3}SR^4VOPZcl> z{c^6-i;8*O#NV4jGcm;yIO(N?(EJog@)}7cr}gXND8U89UnTfcrB2oK&KB5=wv9=( zjFp~?8?${1C|SA$RU1)ppLyM-$+e`2|7zI8la~r2KpnTFM;dqK0jNe+6@A1I(kBbC zA9ZG(N^yhj;2C}=|Mm##$Dfen&0BPmAC>m`9TzK~_!g?xEmoP)u9yJ%GurX8DAxq} z4r}lJIJK*9&&UDx#Sf40H{;et!{mRFbdAxKG~GJ3ZJyY+ZQEyJOgPCT6Wg|pi8*m{ zV%wRCZ5uc5cmM2FYjt(^kLs?fT@SW8|Ec-K@3O$@GnlfXw8>$w`Gk;#zQzIYz`%|F z@W*RkP?0%Wp}*>cES{Z+ANV`|e}Wek{c@73F9mRX!>_$SKmXz3)`(KCZrhwjB0ZQD z35vr9E4&v99PS5va5UAkX(6c8aCKf8M<^BNpM&@V#`mK)U_xi&p@6wD%UFT&Kyd4x zUa~Dy%O0CYXJ0hXkjwBTG!Sv;0LA}a2Hx8AA|Z+r033_!V!!Cz5rKaYyYzd@Rp&Cs z5)-re=L-Tq^?S<;JA#olO_jc9 z{N3T&TsXr~yo-_7mL1tAM*%>BU=;ZL~{59hZ_XNKsMrrCq(v_a=^ z0cP$j{XzwS*CLX8X9>)VXJVosX) z$P@9?ZcYYdUv>->yeeabj#$020;9V9tw5<8FK%qP(OTfgFCE*m2~$aV_~c4(qV`Pl zM!dfaQ#zjLFTE8i)0#aYlf8gA$Y{G5wl?B^&KWt;&kf$x+dhN9y&#N{A7tG@5ZA0? zg3yTJ>t)xcwZ3obxT73jL$vRRr}oRS2ug>E&( z`0$&s&9gQ9&SrUxSetF?n#t<;*q50qWI3@XxA!F(kUi>{9U=(Mn=D}ckq}xr8P?bFv{qksE~8kj4e7h&Z?m;FUNt0{mOC6m|Ma(b>+X2b2HG zXza0~PM{}oy}UCHbkj+o9R14t`Mgqw^b*U8xt|H|6dD^uo8ke!gTQraMVkX{$Qg6M zH={Wcj68%w9}4ojGJ>e-hUF2-4!m9*^$YYBar6#Xs-h>95=PXacs=!J?)|`eebtb~ z6%eqB2#ij+n?;lN-rVuX&*rM9m5o`zfCp^$(O~_dtU*WKF0UY#{_uya$gFbL^aDS- z^+6gOpu`n4r6p3egZMr8QQEg9xwr2iEg0v0@Jra&D~2{b#GK9@2Z#R_ZD8BwnU3zEDDV07LwhJMY!x!Yo`=HK#Qz%OrL+|xi+=mrHR~AIG^CT16}McL zw7xz1pUUMYZ^oPV51*U!v<~{Bh|6j1tToxH41Ljf+dO~2FQ_7(sr&q$*?ul)ZazT7 zYYSbGT#9rfpu0mSpeQ^bYw{ndpCE!|f^niS2l$ledy6ovOZ|IPVW(5fPwC~Hy#yC+3qwq)zuH4Njn z5JWPmi9L9Rby7HPSE{%YOXCY0#1Ea@4ItFgKcUxE0Os;qV=HS~F#! zP;4(6IvBPX^9G~JD#VA z;+Yt2V)25Y}7NGPI@ zUzSw!11W=2Xq<{`w36wG-s3`e#W+ov$KbWr<<;E9>wSJzwo$8U*zqUA9i~NEyzbMd zLdp?y&;18X;`=_GD_^hhWpZGUQ2o*MTA6a7AAqnHUCb(-hSR~Xz{>_8lKA)0-hNaP zQ+$i|(F*W}B(WSza1_+I8BI}T^}gck^RYR!m*1)-Jm2g*|dkcXb5rtN$rU?0{ zvi{zpa#;Md4+6(wBbbrwM;3|CT`Iz_;^y!PVHTp#DXL=E^kA<@lh0J9V4+2gn7;Rj zf=E6OFs9TLX0GJPe`J1M1pR6%bPTR!^?@W|eNo&5!`XQz3ej|v$A?cq42i#+cF*V9cht({Vc>@NiY`D{TC+XN3Y{r! zl^C7{GH&_=p?4MOm#(ls1^Hn=pqL{4i43={NY%aj3F2?|rytF-fPjaGhj>hv=mrMd zdFNrk{%_JUe#imP@awA?(L${suai_=4>n}tsGc+u;y&fdPySg5lhhlcN>=powORlAV z5u$X1-x&>NpT`2OiNAAra2duR(rivnH^IrHlhaerhff)cz)t~Q0-`Iw7{5g2e{XeC zW(|Lms?nam*c>SEPEnliIio4q~0+5tUz<4*z%KGw$?^_ygqA=Y4pfwV2s4il(jkq598Y6wsU&_M4+ z>$gAfMmFcrXiK^v+b*Dk$kOUi1hj0jxwUm#8wcVmRqPCiI1C;V*jApvCzbzxtRl?K zq@3)%=8+HvWQuObKzJXOat>FC2-|BPh-rA)r$d=d6eL5yz)+>(9_?2GaRN=>=8qT< z$Vvu4tUfeZ2{DGODx6y7R%B>uy~~f^$ZGeDG5?@G5%c8CI7WqEkM;nNu2)62nG*3+ zzWELrFKIkHi4qmX2TqUN!bFm91fcf=3QZ%Qj^Pa{ma+!dd8p7nrdfJr(3hkNvT|}{ z(94^5Cd%pKwxHzBDQG6rG)MwkN&JU%WM&+Vdii7W>HtoNcb7Y=BJB1~69|`#R&1qZ zyeM^@dQ@j_yHP9cf`J{zmng}zI>4_Q;iBm8Sl279R7%^b;j^qr+pZZ2GER@}OPn5a_>vA#VCYqcn7t4j*ybI(?tp-&X&UwKrWb z0%`Q_kuJRMk`#RU7g@rdm?`tz-zBk3gM5YY3f(b)ccVyv6wF+fqIIm@&vM6~@~-N5 zj*eGNM>>*qT?_?&aoRg2e_t9^xz0Ag44*gXyC0b29lPAqAtG1uiC;pVN<8)#H{o6e z%{uzJ>0VyqS3R<%H(AfV?g;9pW3@;C7t9p*IH+TPcrceS3GMDghz-6Tc%X0Hjxu&3 z)$pxo&2V_y(7G_5i%ulEXGVR~>b&|5+#z?*xitO0*SCLo5R0fj+Un7Ef{Csl;n)ur z>fP_j5FbxH^AZ!V;ML8rfT|E4GS*ydy3Qe%bf+0C8zOB<*%)G;(-zU}Kod;qQl_ng zL)&5usaN^jZe1|?{InrwoqVVZ-Hsn=P=H3M3zw8_H+O2(xj}Ek=P?U;M^TWlgFEil z&S_88c7S~-J<5_*mQ`>%^z0mRt5apCuxS!3n;Bre-uC>CipeRDuquE}K&9pIhYUY| zRzz`IW~1V%@d*t2tnUmwa)nRB+}AfzGu*>J>a7clAVJ~21|zeT5JicIK6+ZNJ%<;N zQ36oo)PTXylp>L;0{wlPDjFZ} z%C^`iH!j7vZA-l|tMRqZclN1xSv=JLax%HN0mvHU5Iogqr(Zpv`s6upBXQRYrCJL8 zVV8RnoL{rnp^j;L)Xz+nanj+QD%){rVMm&>!#d1NF>^w3zjncABR6K{P1AFg7>MIU zFMh_inab1igz^Zxgt>%;^}$tQyL$}_d%rsWC1shwu)D)o=p|*mreR}YUL@)MjHKhw zyfyoZI*f(_6SM$vnzYAeMep4S{u724=vdsFCNI@V+P&cypx&KY@dZx7Q%n;^;W;6< z;yXf_@3kTqUePecZC%*A%dPNAVm*f_sp)3eDjZR!LydqMQ`#BT}Ds<^=$RxW2Vj9+NJyW$udsEeIusj6WXN`b{}BblRn$O zqOH7Ma~4+r6=AnBbg|DDNE zT;SIZHt5zw1KU5$P3<$TJL7HNSblu>&>;a4=MAjOGJHSQ9s)pFx9T~260orwEnW6t zXf*!i$hvPKNC))t41QDYZvUO1D!Dbp27h$|j?>_QH8O%F{*jtL`iF=uT|v-<6--FJ zVR$~f8!G1~Gm<7m#%QpD9_N-=wu)J#&m(tTKp9;00?-VBNOrc@-J)d&PW$1c{@VPd zF;(U~hy1zRAY<~mysIW!pG0f4=}zqrdzNe7FC+YB!OU2F)lM7g@hhQ+c;(7xIA+OE z`9%#i-qnepkk_Hgl4n_iDtq~;@t^(@J5goHsH_8hk+=Hh^)p#?YeT>FznSW4h`3q>>yy+I# zo}*TKLobKloMgP2z2vkGn2;bGOWs~x!|``MW4jK6C8aGn#$o0BLT_|KoNO%KtocSu zg-0(58-<Pxui^)v0&b`p?pvR6BT*C z^XydJUZ{Alea+R7l;o+}p-Jvu0SGbS$Cp?>G^$@;GknI!Q+LJ5vuzK7=WCq+Ke$ME?VF1zZf6ei#CS5~w4)>!Hl1 z;SC<@wc4EPH*gn{nvPMf2VbN@qC)(SNz=SGIg;~;vt@73x;Rm?O#gp?73|yqUc0+W z+NE*x^NV`qAcyp=TDpr;pb*Sz zSU|5WDP5_Fe%_n*QU{_0(~A0@EHgr}*M|jHxJdU|xD4~PVYMOEeOh^h*cdYEgi1G3 zGe8C{hv@y$t(m}5-+SR=a8-g+I3Soz(z$^Poua^A9-#k$nX{u}Y_9|J`u%(?+fbgN zM^Ixx+EkK+tG2}1rj8x-H4oA~TX!?h5ezK^W{U49r>sy{nFVvaVwCT zcFI9UqPK_^oaxC`s9x25YS?<8JSrYAx5e$g}@vr~tL@8!{4L+xy z*~9b12DXl6gFm^;F!>Ff+w?VOF!_|Cb)2X#Y(N!QXEDqQw%Gm)mUDyE2sXTkaW%(c zh|0TRx~ZG;p0~vjkPdQlnTWFjThu&T7(^a_d@^uuxhaME>Q>L#4FwneTD5a5Qlw6b zN@jo``57{Gt=Z@G7RHUp>?E_gG#113h$m9*>BvqSfJb)f9fW-xR|NR&CK06`5*| zO_=WXGGfbe4XurqKPWw%T(uJ|_k{n_DOa$Bns_KH)eBfXar(vyX<~aFphq{1;(XNm zz6#pZe*La*;o2!tNhTS;n!Jp1nj_!GqC*!uzB+~0u9tRvjd6j_@I)`=mR4fFWT){I z(*lMEGtS+X3yFe)chH6>A zy%g;16O+$*EFs~^7d(i|Y33rE2nF;OMn|MYSvW}Ud#=f9c95Xoqq`k1dy5f6h15h& zAfk;jEIfB<{;?LfJ)nBgUML3OoIEL#UI^wyeA-Q2O96GYyq|Ay36$VZ20ls&|B zhtUSOep0J5C%>bMZY)f?7q8?2iIMb&mi&aG(e)pI51vRY316>*E`ml0X_9W{E#@>v zQj0Hphw}0y3r;{KgXADmhbawqqho2&h3#_LM<3ZdM_bvqA{FVWFLWswDNEmm^@W;} zZEf0DRC1b;X4Z5Hf0PKgN$PFu=hX+Y{;SVeh&SPZ7e4B%?a}NJ}hn(H(h>taW zOTxgAuA73oSc#)RwZbi#1@D!YuHhMCTfbVh-AT@Ice8D4}(C_A1dBgAcPU_FUV!VcA8)6wQ}*YtO(~3^l9!?5DF~nbbOD9^hnAqUrTW6qYNsL{(pvK?-2ikcOh?{A_0zbC_YYrz_MAsvHBuz zDhe9~+MDmtRDvkWw@q=x9|*iZPyyDN z(?=QVc7}B01=?fZBuAr1y)_WiAAi-~I_{tLI#H2W5_yNd5=!l{J$E6%=C#ts_4-!_ z0)G=CqjZ`%lY=>~(P3zx=7Y9LuyZP7c*B*LNytjbYtPW?m>itrF=>q{|BpJ2TV&VA$6vF@0eO`uTwc^At`m3vK0q`7PL{ggbF)`#pk&+p% z_=XsMD8Rw*n^X$nKKx*1-YTG{MJOmn_yorg2{a%@jW9`ZQ?e){$c$(iqA)X)7fZ}) zHX_*85Eju-*ec-fh(rOn@9Hc~B-kDJ9Ug*@u!v0~4;bUx>PD=Fb}}Gp#p9G0WBa#@zbH%Ih_nXQOE@_Kb%WTW{Q~QqQMT=!y|+%7glYmI$FRXJ zjDdWV%@}#bV8HlRDN$bi8B;#9Y_&lzNZdHm*~yI|)t%EU-VC-l<*E9SUGAz;bmktd zWEA5^1^pMUm(o2gKbW!Y$Jtlp`K;?O#0X%4_LASM*9;?0~R|j-@5oiA5Be?A!eZeIi!g$2BCdKZvOz zhU|`p@plIBaVg~0veyYh;d*t20J(?&yFfZsogz#kM)MeZ;wL@alVIU%U;f}gwo&V# z9_Zjw=Q*A>K7wsg^pf-^iJae|n*jsMow3q6Tu7V zihX~#fug>#tD@%U+{Rp|96FP8^6&G!32Y6iY#uP9HDY)^q<|rYFdEuU+u#bkm?pP8 z8uL(9A;LZQ(fi3>46C-ht^dO202}wUWIe`Zw%#24U>&KkXwxE^Ca$06C(6u0rOpeG zamvjgX@T(-bdw+|2c`B|AU{iuau(%c$&n(-Dq*i+J7Wwa@@+a{FTM;ldZ%Vc}#m~Hl$$+K{AizZS)p76cmIg@d@OADI}%$ zLsr5^EQ`#W#LNFh+Ouj(uUpj1>`@JmkC5La23hW*9W%N}OA8YB*t6O((xZ9mZFBq= z**O1;0so7$|BK{Y2;$##oVmFBTF%;*6i{l^LPnw@>;8)fjsI&m|F7MeAW>XdPMC$> z{M&>-1KrcCfM+7Sv+jw|Qqou#4TXb(g%KkRKLHmfmeSA455&gD8QwY3OGF@PZ0Q!; z=TmGEjxq_~8bC(;5bj1;R&;yYg-l@tb-DsYabQaPBfKeQr5@h7k{u|6l8{E!QiPI# zi`h|>Kj7O2E_jCK39csS63&UTpWtxp0CiipJmg538}^-m5gGY`XCRGefs&=rjd1l_ z%qR~z(6gbIc%!J!il6!GRoJ^lrzO@wvK|4#?Zc(`6fuQ9d$KmW*TQF$^Dz>>SZJ$G zGjU__q@I`grOqNZrJqVNA9W@PLm&}^aC_djVf}DT8L(N3hI%|QWI@s;1W0vW$#zsI z;B@m+EOdjO;TgJ~0NKb8dOe^zjR+gy7wd*YU`{C>DYWc0dM$QSyvQvp`w_gUnU3~L zl0XJw6m3PiDt=6sTq}Gb3~`pSp~9d1;mqTeO@b3a&J`&n^rB%MfhciZM;o2&41Lw` zF8)BZHe@7JJlri%%5`o{mMEb{d%&f!XU~*EU(y&TiOxj9!d4ZIlaPjIAQ>fl3Pw35 z*Asw7Imz>?5Y1jFwMP|7P+^pihT%BSL_rKieC*xN`SqPhlhljtNd=RRGLY&Ik&T91 z7pch-@FI0?i2|f0jrBP(C@EN&01@~J56*H32BnQ#c;{%IHXykPhMPW$2sGnY8=@$6AXe#Sso=yTs|Kye6a!q=O!-Hio(M@ysvB4SlzBD906 z;*7jFMOcI7=9Mdo2Q=Y{teSLsgk~goPu7&z?B8jhaU@>b=+}TUH ztnNk~ZTKj}e+2IviOMVZ0&M3FzM*|Ei~ml=U^+OrBG-dJ{~KvWb7Kl88-BRr8012Q zZ$M^O=;RrFY^?)~w)q_f1V~R|iKMDPltC%(k|4SHKlk8d1Tus;q+KAl>*`^Khy=1Z zA17_oRSOL+n&7TJMc~z{iE^j@cKNIOdO#JoLLDX4@Ec37$2sdvZ^P9D9>1yH!LG-O zA%4;RFY|-F8OG9POHNglz!yHc3W5CS`~G`#PWZ;O+n@b{c+x z!_`uXFyxB@gWTfLW3l`)il;}Wk`v5x5<);Z5jni@nkYGZ#{gXnRxzs!8-LxoNe#-S zufpHk#T(*ZC-?2TDv_d|gE+KMyIkfYhh+S}XPR0f1!48r7^IS9&J;NRQ!ChS1 z>#eF=ft(WfLYXaIX6aGxAX7-)N=<^{0r(j9Sn;SAf$ex}1({(m1KAG-{!1SS8=|lu zB6Hu z_it!6;rIGTkV*9{ZQ!Td8Y1M=q8H-p>ZP=!*^-*3zvGg!>{Jp|`C1)8p*p4-gh{0H z^{O^iY+gS8L&6I$XDS%xXMr+^$8cO>YkdzFV)Zr+#xrE78a14{(GmRv^(asGXlvZ~ z#1}e|1XOMoE;?TnNxj8z62C&8S`GbcEf4!?P1Y|4)C2h7B0sBPxZ3?_&+^G~6QIA= zwD?;gUE#a546}*$Ol;3H9ZN?k&h!-e^U}0q^@k$ch8>7U(i3)lvSQxr0lEGk$erUj zy+L&$&@uc7r6o&b7;Df7vRi44DCJhua`HI*o^wl(JHo}5SLLuxlwhV?$%_c{a8(l} z2_}1(nl3is)*kNTq0td2WH1>z?|-`j=&jfi%!1fVy@S#%%%1s$uj5R z$}YS0CP8kgQHmt|?;#|KEn9?Ax#tHhHVUuO3058W4vKvCC%rt8g6ost=1m_Q)R)U2 z(jCleZSraB<#dYzdt$P=VnDUZ8vivFxs-ZUrm*p~Y;9EkWVmG?KPMlpv0EiRkT;Ql z{(bVlz4Ew2xONq(+cy3gmDlim&<}DHc;&v3MR<}!NJC0MHk|=`^Zv<&dA`6f(h=Rh zIgA#MT8=!99N$b)w{nJ7^;9ajBl+9QYtgGW2oE z;YCA$?}InW2B8sGyxT6;(-#b6){ge85yH&>07zsnQzpV?3C=DL{?(J3r;;l_+ znkz9{(8bM~_k|FCz(*h*n+|>YA>|7mA25x0#yH0}rCt|)EOXILVsH*h0~=`Q(jKPM zXqST;P{wAGlttM*AA+nDdOB#Oi`3ChERqz2Nw}UKVBnXJgh~-?P~hfr0lAfYhrxVe z`cuQFAIVPrKo{iu+~%8vUqgQmLQU|8dcEB-derw#0R00rB0;DCBJ!Q^e}+@bL2AG> z!92C34njQL9G+re#MK)l31O_{QLasSRtP

8@0hDrg#iGjOr9ge){iI1v=#*@d zmVEbW!;u2-yD+R~Mz-t$^G(wD<3F5~-41=Vy#ETF%suspxRphuM;hhdCM&xn4tCzY z;GCP26C5|lTWAkmkTP?k8Efpe62!u7gcw6Uf4j58-M?=73iqLpF-QK#xISt1CrJK zR5|qXbM^J{qSe7%4J)tbna+uJx@E6?)ppd~l5_pl18Y^TX=mj{PQLSSr41)j(t{F+ zi3BEpF(91x&WuF@W%3@c-{A8ny_twBLZ(2KRudaRi*=7)@=y)!4cF`b#J^PVRi;BYGQ^#)k}>Ziq0LjmLL{)vgic7Bvfz3igaN(O(YFY zpp)*ge076=xC2L!NTM4-0Y{I6n$17Qg^>UPMXt(qT5>wIXyz;~mKlU5&$r5zImGYf zLB~h+^!6@u^T_1%f3WQ%!+65D8LjDmaZ2!J%tebUBYRcMfYbwy;P|X8de4hw99gHW zxqa{8a!$7D(Fpn#BaHSIirs+tVe4 zrN{KxmipM@YYQ^qh%Hi|;TmFeGeu{3{l5jWke5Yy*^vL04xIyYp*I?zIl&$$kq2Bu ziZuRb!6{G=j94Mnde6DU4I19Pe1E=^zW144+ z*IaC@$2BQJbq=$Q=AeM`8cs4{o()y7q9;3)Mux>a?Ej=W1eI#1NwKPPX5VIueC`~z z!Fp2ztI_YPmuDTbHsY$uR#rsAQUvL3HyGTGoZ9Q_12!_FS&o)9+%&HXm}r>H>cf#{ zSbywS82Rblkq}aPy(!0d2^mo+O?N{w_X339G~@qd@5$Jnz#&Q zpO(VfCMR6?Jlu@ABMoss`|<>={!FF96KqywnrOX3bK)H~8|#tjAi8~<1K^0ah>~D; zVh|hb1KSnBsc4*H5^h)`Q@w(g7{XB6i=-Jp_XD0`Ns?{uFIuIa|7}XCU~i=-;%K8! zBzz!b#h_VgQL@|-%wRi7YI+zw>{L6 z@&V7fLc&JVjM8QKqpEdHcb_o~ocb=2IwaFUf=<^2A*)^--C!_atqyTF^*q#w^tWl| za?^ty9wMP<@vapHnkrU#CF7Q2EyTTA1{5T5aiE@)>9ne<302V$GCmglQ&A!k*?i^XeRYFOL|=5n9SvkN)U=-OntIMgiu{z~;~a#qE3A zJXo1CCSdmU8`@4@xavAJ z(gN_ET!>D$=@K&23dON?xeifU#%M~!S_>GU`ku~HApH>Zr8DCEh<2EdipY4!i0F~= z5d-o5j$mdgw0#$Y9gkOX2byQ(Ie+K29Au%s*K`)e4xME95oYn_wxGRMJsB=14aTJC zY^-NndpAjFdZXF&uel9aa`rvclye~e>|u}kREQsuv~H)DV6qYA%E)V;g> zLoGCWKvXnq=Q7jRv>8|^GQJ|U_joO&1Rw0NA`@l-y%lxx!(%XSq^jrwI^)M8s^B1A z{GHIg`1f^zJ$+dJ>)w-vey5_Dzg{9>3~SHNo)hdKbqJ9ZR`l_O7IS_4q-ZAs9jDo( zildCnu3QWQuiyWy)J#$$fg3OS$iE*5DjRTcxY8TpM_c~s+ZNThuLu;43ng{VND1oy z?zW#BZLIs&WLA=xBWPrZT=McS%S2-@aH7wp74ALF(l)Yik>ImgIP%@LN-2Dv%#(#dK^ULw{W|@x zi;1cYhytP-qrkRaG+l(MjIgA1>mFF-pR_3piBI+6q{PYT?}nF#mt=;|8;yY2iM&Qc z+Z_qZ9!LbFhGg28iRC}SRaa;+f7#dv+)xBbSv)1*+JjPhyR+h3@vVFXmPGuWlN+ve z!7bj)TgI3GX7b}*#k!3B9ZQ1AUg741n%Ay3Fc+o9jw+m1?wUw;13GbEmva0~y#p_BS(|xPVEe`e6lYP|0Ou z#N>#>>qb1>heuo7B6U~$}R-|>Hl&%%? z;x+$xl$ZtF$L`7FPXm8vs*e}l!`)`tIwd=x9!^UsYOZT=@gL5t)}QvFF8{WuVo|85U9t_#GT1Uh_1_G zNoaV2b(-Vi6mZE8^Q(I?5kcV`MHbsEl7a8Y8GLz(M@1WPRe7h(+rj9d-7UdnOOX=L z;h-7h%x06Wa~(IOqgaS;k8&6UA_fQ%`%y>4pU9X7kVuZF{WB`G?+WHZ5{1A2rab-6 zB1?#8d`SVIyF-pc&|=P8wpo)nX?#i*KpoeFEX+_U(dSdjgl%(&11*ShT-V2c?as6AP4ZASr;Eff5KQz;y(xy6B(x0|+;drz6T! zeFw?CH#2rjO=i{A-xX$3iKy>r|ESfdT!3&@PB2-yT1C{WzblFn&!Wg_4YP9=;$veL zb?9(V^vO}$$h~k^hWP#HgzFk?0oc>pu$2y#$j~i8(U#Tl>ol^`-?t59lrgEo9J={L z42B#Tz|!>nlEyxv0VuQ42tkUf1hp3k#s1>Zz6&*1Y-Bp*TF8J`Wygf+ONXw!Ce6$L zRQ>#QqNm)O%YukpbF;0B|;AW==g4zQIMaiw~I26o{^+wof<7!CM)$I zqeY)kxI~4E3^$p+IN{KojCIJi4BcmUY>)gTez!26YFbrXDtAY(!nRTT09x{RaOAHh z33i1My;qkIkIWHU>(DrZIQzn1lQTWt)cilwpk0J6ZMb4yrnJZ%rXga5`t-+Gzx15J z^Z>Q$fYhJ9OXDNCq`G+oWGemP3!zA{(Hp}{z1HiY$<>->+3?N(ps0(5vNMl6-9oGS z9h~~$`F(x79{NY4<{x{qyLnfc{e(ZKUY)(2yj~9OM_n%$XDf>u4>!9+c%QeMo*yPb zNhnK2Rm1o}u2hXK z$XWvPTy?r!ES;=lh#bCrhlRE;i)F@ZY>F#}%q49diFihN5|&5VmYO7MT_=L#uuh5W z0DOG43I;Vbfu7PnS4Ln&3Q9rKV z_!D(HjYSdLc<^5OZy)LsT&S)oId}d7$_m!%^oU>e$nr_*Yj7dqprI2)jWh8=i)Xae|%16cQ0x3_;7Li#tVo)z!4Pp)Ah#WyBR%Y*UN%sGYYAAdr0# zXoRIw%2?ss9G2}R!*4k%5m46_V_R%_>a;`J$zXX(+PO~uG5YjXnZi$I#mN2#kl0-3 zHJ4tl?qVV+tSX+1EW2P%VCSfAxET(XZ5)`WpyoOS5}$Ei8rPfC2sHNVe^~0*o9oXg z7J9X0KnR2cKSU}~*A$9v;fqhcqB+HATg%(N>TCK_?e}bC4GxtU*{+th7OuzcsDSUx ze_kiP)ESdSQCwpuqp)af`qzJ2z9VS%+VsOEb){nztyweIF^!a6j*t|8d2`X)mQ;vK z)6v~38#_`=8Bb#Y7wWdWkJpU~s?00rw4SVwZ#VL`WF;Ia^oKCkR$g3oVf04dTJoat zY->Jz#_ns0MZf|-`0L^?dAFs^pDKA1Hn1#r3c?4x0c=L|wbkrL5Sbip^f`wi&S>d} z{hi61nSMO}7C!SC*IE)RHj35mY14|flyhM?YL1+<@X{nn^1 zL@MD9W`ysyoroSq#7z|l!3P?x_qAZ=R)UaX5_TM#d4=oAep@nvlNty*d^zQonc=QAT0 zSY?U3f1u;pWB03rqqE`Vp6mi1SQ;AG+NoIM?80T5qpSPMLm4ZXT9cf@Bywp1mWVS6PMM=84Nre73mmcAo^j%I6}xMVBNxHr)ay{&Wv;F;B`HlYdsuo5hJk;+-_|48l zameRB?wyXg(RXzQZ5UUoCdVsKCZTmKNM;tz1S*b#Z!$>clV?S=2Z-|Pa`qONBHU%l zm!=+xA`|WJ@;>jY(9_=}&zLgT_beX$wUd4u^z1y7qB!VNzq;GI^^=#)f6wlZqwg<0 zQNvMtjih8)-{gj(rypk3q`o6LDaYXbiDUMF%s#w0{N98qgp$aPJ}JyE%5oh4O?bYr zRoG4w0u~UrIGj-Tpw3-d-}nLLQMglYOAQ)B%Fv_Vz zFFzwuL=p5YCf`bifL1kn-$ZLUR!O@>x_s*xqX@x`YyJ;BM`@;kVIyOaB+zdqAba1O zw8V=fX#B+9?|Va+-_jl9=%*0u@5NVLz$bF9aP{>kXzTbw=(8uv>Ko)D@AeSPoKA+% z;Nw-f-_ze<)Ly+nmnk3x6kG`5kzW*Ira>6LEC!CfJ=BNecuv#oUapTf+jQdT<^{0u z(^z(Bo7=jZk>URzT~qzp)%7pu_1+J6+Qjdkv_OIXAM9)GT);y2r~U6443!aKuZ7P$ zI@OXuObD9wp@Yd}7x&*b;KZf6;ajymXp=ilvTz7o|0Gj&fm&peS+oW9k_CrN=!Hi* zU2U{JY>AACm~gP)5%X1FUxSZ8I4^f}tYG(NY)UdZT`GAHv=6=BV0g119D6(@TEY*C z<8HweyDP=UUdW$hoH?0u=U0?Z>$*FPM z8AJs$EVl@IgC5%*tati=3Nq`_|10gPy5i`XHNoB8o!}0^gS)%CGq_7|2pZhoVPGI3 zxCIS5xH|-QcjoY}?)m^^IeL(~MIyF5Bw)A4zy8VWWK_UBtROL1q`tOZYAgiLHc` z_+{K5%U_$#wtCRqT@iMgF2wXIQ5IjRkSBC+#sY-7o~SKnx$>Lop-M;vkP zrmB%7roP2!%N}t6UYfMUK;DqgsaRpUm}+jRZo6Y0d%}v!xYl&GhV@hf^~IJdDvtl{JR58EV+F!BlIO@vmLChwt!K>(?=jLP)@ zL7(NJe|jpAqTiU+%HEBlKu)l+E5)LMK7&+psN>jX6j8J>*hQG7-u;0cL6Z84a?K%w zX&s|9E;z*UtG=Gs*2Jsm^9eidQ<>Vg#g>uI3ywx_A5Ec(#jKL*TA+APG+;B6eojLO z+aXw6lZfwGO`7EFiGmChUb|U5XT-tLaIZyuv?1`h^?ltNp={;!vXq)rD^=eiHxST& zA%>io4izdff`Yx$suhdzS^dH(1Ba)C7S4y_V8030vf%*ZZ$&z$^bKtPxdVAI0GX?c z_EqhQLq+YeFx>9)$A(I4ND_N26(gfBux#Dv2WcQ+G?BE|SDMHD_|b7kBW@GA`Wipe z#*Q-dQ%f6`=nsdwy6=lNUKl-&;um$6i&XsdM)wt8`Yl~|_@Xe4;v6uNu@Aq{$Zwh2 z@rQQh3AKvHn~Hp)DxLXt^004|h0N;`6#nl$DtD@2b9`q+8vv=z6`ekUQQ#eStTsmT z2wWj~G@^4dsVBb5&{l4Ej2TxeKWa!s+?}b*cWSk`QPeh6>pW(s*PQOZN{cWQ4SOm z?wFAZXOuelwN|I)Pw8fvBy#hs*T>5Y8#oMCl{}Ir1szzpxR%cqkIg|Y(Kwl znwL+HW)(K^%yBvNcsQCrcN{{Ds~{g4e#bYv;+jVR?;w+u+BOkaSgZZZvi_OF%M&|p zDgg#eAx{b;Y~b9Gdql&}mTvAvDLl6AW%;}zH+_{T1IXN?)W(>XM3ol-8*Kn(60`@Mv{0_9JP+cDd74J6e(Q zJLL@>y+Fh)m$gzVQRbT1tDPCgAD1O#ec_d3CX-|rQT^nk-XrMslVqxg7skqx1QQR% zme#K6+NUnQDb;@>tudt2a7$n5-#(Bx<+G?W1f=wvRo&QY0&m*H84abZSYSk$_wTL$ z7T6WuC7tVFdy?3&xjW6;`=I|R4FAM74FYm|2g-Kxy+F3Ez^PsPPZwQ~&3s|zVF>uu zg&IfVa=Wkv5GJL1HBp0J~)!ANf*t zs$iH_RXZree+lRdvSWWN>#Ig5=N-5j#M_tmgOb!_vc>v(i8di~N}rfa;(gn0`p4c< zaBW)_?#D_Tq724Ez!9P`7THHgykei5!QanPugsQ;YwsVcq(nY-CXsT(Pln!!Cp)dO z>YqP!z$|%!^I=5_vy;MIl?Z|uozB${Sn?)Toc`?y!86r<6!$qY%8#EIT<+lhRr@#W z@`A|}#%e$qTXW`#D`)22(_Z506jRtR-j8QYM)@a3Ny{2a2VvvR10F@)&jc!j7er&m z9QfbO41cA#7x!GJtW-;6n0}of93$DEnXYp98gn<5+v8-YlYoP_x~SYVq|?tgo)J7bbcg?&B#bCwF>Z*`lwpV; zUSlMUdt98UH4K?cc++ia64Y!TU{n@9>xpCp&|oJ#q$AS5%aKL(BX$+r$GQ`n7Gdp4 z`2V~F>`>_y#yBg5*Brp!Z3VXd%Rshy8;t*rI??Br(NHa!=PaYja9n&rsE7ovQSQpd zY$b5y@{L{g9M;GTauc6TBwZQETM5jvl7~)lNk&CdO0}sGOeOvUO9+e;h(2d`$w^ek zl(1Bqq8j!*{F>87+ppECNbk_w=f?@Ew~_9IX%aYuJM}JxPj`TC^5c`CEHKk zTTmme4b^H%XV0xM`laaA6=o+z57eH}iZuCt!15?I?j0C81REU0~EsYWSUztHB3^8BfFuk`ijeJXVsifJw zf3Wj9oD4U6yQ41(p2hmDOgimZ)IcsL)=r7?TEtd!aDJV<#*SG^J>f2ZM6bHm(+kCG z-y4-qYf;Q^hu3Mg&N6GYqoCkG&tj@cV~8!5G&0lSr8%V?h@Xwyrk-uRIDUZ-`%S7m zc9;J&&UJ|34+M25EjVv)xEI+nVTNLw0xlJ{sa^Ty*Fwj5RF0rDyNZfQ;c35#qs~Cb z<;9Niq4hPly~b$;sHbO4LP%*<2$t>CwVAKLjO^w(yL(LCJMAvx=WxqFr!!2)+Muh+62h2CPWrAxNI&Q@VN<78|aeh^iwOeAqaF&xb;r2~}? zq_YTp6a{=o1L(Kn_U6B+t7)B z#F(~~1pI&w<^<)C(=m?JD3zf|c)k92ae=kkn*R1YMG>`7H>4PB<+#fA3 ze}i?zAiyt&Y+i`1Tdyt+FJ<2#H&+|r*_WH14qu%%$gW?i-1uK99cb#@+TX^3b*uHO zK2j&16?TEQtCuKX#(Cgo&gD15Jr=>+?bqsBvSl47gnZUTx@&9-{!??XpMsaSYk^0G zM{N1?>Us<(6(bIl@27pBd2;;0@+7lIM()z+MtXkR`&&mi$;-nD+xlRBTjD$DlxgGr z#?2apnH|a=U2Z^mY@K{}mf$w;&g{U}y>c%5apM!G?ec|FEA5QaQAb%FRmPQ-fYx%! ziR6#qp)TC0PGm(I`^!gg4Dvyn9&<^=KuUb97RyA%E3r=u6Zh?8C~d%zjR0)ZdY993 znDS47!cKgnYPwiG=J^AvrTavP-)>?@eeOmQ%BJNR=mC^^fsUTP({oz0BS~8S$HlpO z^8_75z*g(rluYvJ(^)MQ`&4i74Oo=W2Rq#b>th}oY$NY#R7Wb4;AI_A$zXT z9uCYbKl<{$il)})_4D5aPe2$6VoWnO*%52>NP?efaX3|wOtFEfr1g}^=XJ5*W>&P&%dDB5|EAUjP;({`Dc6Kpu>WR`=Lsp&!hu3rFuWL_i+zbb5mVO z%N{Y;P7d193n<1C?o=w~v_l6>oBXz1!(%3Hau_o6Tm2%FCJLKgJH2gMC>n{_Mp>CW z5m5Z6r0;?ReP%mk%eEZ#(ZuIj!Gi(yaF&6GmNP2Os>V7eA;0k$ZW>Dipr2C=S&O@$ zJBN{fpehKGuo5o^L<)B)r?lXfneG_`}KPT4zY4 zlkQ0;M1&C4o8+O#r@N~KvN71$_l7aKgtCmysp@&mJv}0YTDP>5W4k3>Uzy$5QnB)O z)}=>_lcGYyIXx#(87r_BEjaN`d1rv1n``jyrXS#U#+P;*)#!jmTwH-tqC}PZ4v|C1S|6}H$Voj#O{x; z#Jqcg{DUDM3lrWWBo3qPewG*9(mm$UqOf<9WwQGj^%$D}XNIKq^&Q=I9=+B4iRznd zFO`uj2iqc4McA@J*V39S_k+DBqgh!Tycu6wg)ZvaW(}$o1R(wVBZ){8>0+Co>XF$v zKy8W2S*z>_^-XfyY8M~M1X@zyz_0J8s z8@VmZ!jtQfx5vFlQ|9OQ+RZ8mj(caLPz%)!Gdbrzcow?LFvDj&O$1x zf07o+W(^Tc^l)lra1%juU+5%vwOLhHn)n`J5_p(h6T~eZ<>7I+%n@fO9~~MVIV_jY z?l10t+PuFTQmk&8_hM&kEwtA_%A5ll-;V>76AB`-Jd>rF>?bET&#o_Xg<~XJO|5Yb zSvJy&^L5})y1m_(&av_4njdLEe*o>xf*k*{(;Dg1`SemKVzFb!oH+nlRagT%z%4^# z>&~Ily7a08^nX3`dk`+Rv0s9Jpr3*dj#NY-iyN~p7rT)4kw%Tz9u}&#_0O{e_oVgB zxLhtY0HmYvnvXhW+dn~J96OJjVDr~z?;9dJAG>x}@}n}`uYTK!4tBU9zXdww2vQ_l zL55~MfnE0mxS#Cq?o8>EO)@^Q=s{EqMXL{j{X4l^Cn4?(lf19NoMrqn-zr?XkhhKM z0P6v?r4BK2ylP#dgx?^~UUrXP{Td-1;i+nGFToNx%Rt9vpWC9Ee|hnU2ef`BRd~U~ zs&X1-JR}t2d}=q(g9z9JNu5(hMGTlBrhh$kF_!dA4?9Qs3`@Rkfx4T2_%9;e^}9p& zGCfSI?{_WquRUyNL04xt1f*wZiDBy2y1P{xtPc`N9>z{xNu8I9KU@jO;Ebn|OzgtO zKeq_{!0~Z1tM6hJOQ?y|w3HE}33R~Rc*)s!2cNE+?X2a=e-EcP{%FbEhkuRAXr$i1 zVht2>20iEAxEs-26aNO=TLW`UbnLYktA4i+Uk$ka$)m%E1l{@2A06K$HGTYy{kH&1`JBs3?$?AmsFZY78(NT)_99J6t+y#OoG#@SU#d z(IIs9q}2y&@D;q3wYuPm;n34Y5SjuE4L5gco!kp;-7-41)>*;x5343G)JB`wud>Dm z1`coQfp<-{U5=p6@gqoI)x&G*BC1|NFi+ZN5o3|TRWeyTd!ED5?hSl|q73xs;R)df zMdt!l0q_Rv^$8ra`1x$^y+@-3PD@5CqwVp`zhw^FHaZ^eKCW)x{58z_G!bs_IF>QY zXN{7n(^n0rQ}^4p55h8^#AfJ7Mf6UMD7J4UCB`y84wo(6u2Dxv!aDqeMyud5jT6-| z=$?rR;F|GOP!^E{QbhiO!-cs}IxLa6&iXP2w~>(hiI=<32aL9HpdX ziR6xZxl`6`BGztGR*y&aYG3)zZH%+`9nsQ|L<6&gmR8uItXWm$C+5{TM8OK;OPk?K8M_!!b3UC-uUpHQD>!~BbfULw6VtUjk;BEXCB!E{ zR%Y@+;mbn{G_&{@{ob<3*B#wLvF~smCZ^VaS^YQn;Qsyhw&M4{@)86TFzkYm_0{F- zqhM9=DJwuGnhbDSa&4KnSX6hJ12oN1DzDG3MNO>2*K-(b#t|0*W`g)3FW^{mrrYk zUK5C;BaA2?tWik*sL!mjG z@EB_;dattAu(USr;?)t%Zv?Pzzlmnb?|S1JPM95>&7bA=IUoZ9NcgpEyh=^WsDVDh z`M}Z9r8)YjF)4EHpX_gcui;p$C%#yi+D+u!TOA+K~YxvlxugwT7~qy{FH zb0;T2mTcu|2LZOo`E0}VCmZ!}*WgZbLGBUc-DD8}rxyt6071lp+$kWt&IKn`5E(KZ z>#x%kDHWi4YoE^;C@)FYrTJvvO-u=%j6i%INM(|XEzpH{cm6^`=0w84@|Irz0Fu^? z46LViT9LECnb_QBDjtu5#R~BQd9K_pGV6|H%b@HH!BfU^y=i+@`-??IjOlt}y`o)o z7!;-Hop-OF3Ms;AW-+TBh`K-P=k}i6fn4BCu;4=OF7j^E}I8vf~Zd*|B*A)F=_ zY!|ZhymT_i zOjy)qo!v77@GnG*?e$3<-8lgg>LTdegxB=$bWFFl(*%I=*QeAiAN9f?0>h&ADI+Pq zE>z%hn?EEPC&kO{He~=SQwXPlghdXf&-GVaGY46or%}|roBK}spLk(eR@P0qw**!T zmZb%6d@iOPhZ?3m2-zloQ+`byv#jxOtF5xu4h;zLr$5nD6ty0RaTB5!x~&zg%W%_I0AJf8Wd_`WO(ad z)E&F-lfHZ3|8(eg6!m?GYNZ}Dx-zNpUyAUhgVr7S=%{i`FvM{ zp!nlZr&U(}mO$KBB*23J;gfz_8_&TM>-D1E1||`ZvulNkSJ5WFY<($mC7=^dWd{Yg zXi2B-_P|`Rvv5`WqvPqjN%AajQ06{glg+n-hYZugy{6-4Q_eQeMEg%8o=H+BhWnx- zgtN^_7I4yVR{o=cgu^ zGoBZ)kiBtA$FivN-?i1SnRKVF=5Bk?ng77d!iIt2S%t~?E>b$|^-orqB;C#p4JwB9 zMNNmZDv_@*vdzSis)VUz#W1Z8jJ3BbGl}V*jsRR0C=<0{x5u!jJE7Brch?oZK7XKT z1X_naNK|p%2jw+v-9}TAMud0Jk_|d8M3GW=|`MIBzw$@?5g}Db7YoliSU6Fq=Sk&;0OK5Aw!mn1HP!Il` z&U2@I$RQVCe<2tuoZ)0MA)_nw9dG|FXMX{t<7}7EF!60WN~bU%^lOMoVx83h-`TBA zJIXcHYyUzH$Woi=@5skkeb>=9o?&sXD*&W>M6sDWNC9x~_dq%`bDZrU*{rT_;kLH4quQpBzryT#B|>H{bu!>SyGF`Qz*If$hoHMzJpF-wk>&2_JnQo zRGUljU?uc;)0s$P&LCuC#lz*SnrWq>d(wO{j{h{B-;ovW!bK z(KT%osWgs%KeqAkQ%u~AGHoV1XrDwo6JsH1BzcCQdXrzAeN4;ns^@27K37I#@1-_x zPd+U;Pzxz@nU;vxva0}$8MDnP>VH07ic!V%{<_>~+0Txg=-R8t92gV)CtA6O9H%Ti zob&MWAH4O9lGNnS0ZEqQJDi(mkdjiR)Vq|;*$~|uz+4d_GS7F>smq(x*pskg>n@L^ z9k`?x_!-|+Mz2Lg$&fw}vs+Fw+uRERqh#G4)-&up19Y_g8LFbL0~qGjbKX?ZU7ha! zte79du^NZ!MQ3PWRl-e|N$GFg&G7xS_Y}0uWee5TGQ!I2R6EIp(6{KyTCWL#tx=BBd3&g8VS&g}=jSNe3`WYo#AE?%tQ|}jk26T2uBp?^4^2w*=y1w!s)cGl ziZ|iL+*ueV`+EKi<5Xh{x*mLx84|ZxjC+?ymUD{D2KO}=$T{@ituha>J>-~v4Be(! zA)b7%N3jJ(!HEFsLj4H9(shiJw6LbQqAE9OVR#xkNwNgOgtD(J|0Wh+5AH)8|HR+qxp? z1j|2)PkEdPBa120m!jb5Q}9WNymWB`Rf2>gI0RoE)ea9C+NGRL=YCju?v0%xO0A-cny`|(Xeq4xH` z?nq*`h^YIx=XGd=ZaeI?%;a25a=(&MyPT`XE-0m*NT;3ktI##H!mPUEt1WMlt>A%i z%c}tup>(6obTPzF66LJaz%kXuX;4TnYc&oQ`JOC#0y2wfc!P%m8ynpoq-infpWoL z=}MrHM)dhqY`^31Dy7iDLi_9}%B0daixc;LK4AG^@KTN$ZI{!mxRASxm%kUsq_r(w zJmBER4VzKLF8_9Mm25p!UD8(l^(~n$LQ)1)a8zFDf8i34R*O~HHQ!he;`n6BaP4yv0PW3cm_m7C}U;0sMx@9w-UV+8?|Qz`6DEowepY& z)@-);U#F4BUl~w3{6Mso8hTaU-p*MTs1uA=FV_2pI;>+^uGz|sL)iZ`2{N#GbOT)}{d~!`kxn>KbS}TC2)sr{PRPyx0SZfTr6dW*! zr&?yJUK`|pIQ6D|?-Nf2iErZaj3tj#Gthnq!mJ0|IEe|`DxsltkJ@&L)kqW5_tRX( zMU~c&LdU~besBbjY(k=6M1pRf|2;AKySZOKTT#5_;`xj0f7n|hiint7$NDrun=90d z**aba=024}0l;T27LVuFgY?u;L_#WAY>nv|CAqu`j(fns4D4VYEo~}pCG>~t7VE2w zT*;4$e-Y!St0*aobVPd*C``2fa4qaP={~D)=EpXLyan}c*D8(Z1=dt^4`m-0qKO+Q zU}mh(WP(@I4W<>{bx<{_>ElN>BFbjTPrF2zq{O9yOGyJ&Q%x@%Bs6C{ZY)M~v#}Nl zcQzf<l5A@?6dKyrDJ~ z#ncD~#;^p(8eL&4Yk#)3Brc^&){U?lZjj3#G?Wr=_!$Z|c|UoQ$IL4%oV?^g!%kry z{1V5=xg!--X|?$q;dHEQW6w-w0XpOJi$6X0kuk{i}tsRK0#| zqYG@~xu2;rgOs_DMl|_yYZ8p)rQ7`;M`RE`->9{ya^rqz>mx{J1omMAN#W9^V8t=2 z-+g6hvFtF>-k+4GX3?TOf0F%FXE$wgR-n%?EgZ2ek=5r?(c_yLdDv$);a zR@qU{Xa?IQa^vpMBRn{Q#8{X=VW$}mp^o7N2@~vO=(Iz=X{qfgbcPrQOCi8dWup^f55TLYGl@aR0O(+qWAk^aozR6mA_jwg8V>OAth-d#WeRpnQPJ@ zspohU^D-04y9r9K3Txk$DA13?H8Hri_q&rRJDWYEc^?FZ;^zlQgyDf5+vg8}4Egi% zpmBIg;{bJeX!-}JmD2qzl=>Tu3qfJLLSRgep6qKm$j5{(T}6#YgIKRkM9oZ`Y=;!X zzWrZ{gFefmf#sMO0O)oV*72laAdB$s^q0JVX0UsL&)0+k^dViMqT9Em4)S)oclurZ zkoBcJR(9nEAm}a&XM&+{FqySe=FY6)iJgB^_s9M@-*qU@x~I`x>wM(^;JPDxz;b~5 z%dDfMfq5Ap#CgH|NB=y?OD!{U)^Qtu8y8!Vi%CQLID`$QaJH$7~c=vimO0U4ehv%D|a1Mm9O>*RS>s|EpyMLmEbI> zk(jMx8x~7}}_@RBQE`Tk_`&}|NN6pLFJHqOQcy*;L(fE6Sl_1Y;~FUZqn+)OjL z;__$Sn^~VEg}|R25`%G(0TP1<2di?JVH@Pj4m|+puSDRiHFttfcj*aXsfbOeli!D8#CIh4Ps{rwW)ZhdeQ63N{Zdx!BWLDFvBir4Y)!P2jb z#MRm}{Ry5M0ltTNnWE2yqhUO;cOSw-T1Bv71=JhV-+cwS7L?f}VXh|3k-5G(TV97% zTYn-7QVIcizb5+@ppKpOpx`zKe!I_KRJJX2P7E||9pmn%BK_v7XK+>-XEnKx9g3cm zesI<=w_qRJ%gJ|e%UiG5^Os7I`sTywTK+?{f_sr>(J|WhtwcNvYBds#x^Hgrd;gp= zQaxNkT&q==PzGdrhn2;H7*RVly>Mvt`wbk_1-dV7$u%aVC@S<2n;Hv!sL~gZL3nKt z3ULRe)>r*P%7P>@WNIr$UEZYQTPSUyEjl?Cn2Y`{Hq^`g{u&oa5UeC1Si&hit zCeqw^GGBk5(ev<2lBF?Y@Ru11N(W9^7|SI#hP=PwiiGas;+Gk{3sBQx12tT&)YcwI zwOrV5T_~{uE(z3tjlQ27gbJ(4vK#YpNZD>p<+w2O^rOH{>!R2KF*M>D*os5IrZg2d zHnv@d>>EFLvLvlc9E?S2qD8TN0|IN75~MS)Vj>@uQ{;(Q5i1i5ln5`#A={Hf~Jl4A1 zy9`YAKOI$#DiHFM1R{PBqX()9lX@nQZ4dZWK7&dzA`wp9G5^f*f!VxR51CX^+(h)< zH%56@4qlu5`gx!59E_PoZ-~awh(>j*OzR#Wf#RD2mro^?-{zl+k!m=DooheOf5%&; zR-U)CA>K#$gdIEm{ac70&bjI)KJ-unLHhGYRWHFu#*8mp;2R>`@lN@O+niJWEuI{> zX{BT)omxi>S}8sZ8~+;gmiHxxUjid&4=V)!c+zm{;5>sP@k?^v$0#6(MOGPtlQ*u0 zDkO{jDz-SrRYqUeuSV)Op?X)O_lo z-2s%Hxa0~IQ=T0CLeK%sJ)?MRcdS&Y%GQ0UC#5mT<}fAP%QMo@LFD1fQf6^refE4q zWR)`QU|3kZT?*3UO8jdTB$`!dJ8N8cuz#?8$23q|NgJ!l5_r?;Qpi6W_2;+7N2m!5 zZmPG;5uTlZh5%d7dvn`%`q>wqPsoB}n(Na!R&DHh4u+|%cW@{=qGY4Oye$HE#mV&2 ztvnYcT)oPC1m1rHR$dPJq!AeVfGcc8B;_lcMi5LKoid~u%B)qFid;aYR{WQzQp#*4 z+h%tobwMyi9?)3Ro+ip6IN9@O)1kL&+=9%ZVitjO^1p?J->LzuS2MSu^S-v_KNuhT z6LJey&d+rnPlOZnv*uCyO;Q; zPWxaq0?6bA=pOFk%;(K$_qhKclT_3PVmh_UodNfWQ;@1PpzT;DlFdtDB^}&)eLEPeS9bEX_vNmXUOqFs;MN^Va@J6=LY^V zXrB>=@Z5cZmD7b2AKDh_Z+e@d*9JO(*>NX#;>pAH+rEIO>)O09+se&xj6yv_I8-oCq2)lh0r)QUnWVmG(ItQhT4it+2V`VI(DVr*=yX+XXa=3 z2S2cG&nC{tcsQFkfLr+;8eUqMN|U8C*Q%zPD-es{$KW0&;vWmc3;mKsh?<7VVs{s! zWgH1HY!7oQi6oo?(b^|uOlpct9@P<1g(4j(eN5lvEPPKd4R|%32&0X>Ys2Qy{6@|R zQP|LdUFnHqZ(8z~3DlC_S-UC4;iR2f{-vX<$^h{s0{fbJ3w8(GB#|7d+FUVjJmU-& z4m&Ynx%x{b;fSnseDui1Xu+5Men5V=0w&Vn51INb;eDwjCDFM{LfN0#l;Z*gaER*i zo*@%YNh^V-N2o|Bo)skGPFi6u?DlPr%JO%jnz*n?MEK2?-r-bWul%~8%KP=+&K_6JVwr9SBT>0JK)PE{s2aU9U)nW*Z)Vd}{t; z3H-rx0xi*BkFmK=Z793vQRGZXv4j?pr&W!-oYp3moGn@2M~ABSN$0c5-O!qp?oCCO zKYdkMrc}Lj635$?H|E4xu$g+IHXuko7@?Q7Yo|B~F%F>89qm{`@_~zT6Oc7ots><7{ zXKVEKKvhG6#*_td*5w38iQuZ04PABaFK3gk6Hh*JbGOdp0@F8 zoDNP6;r0Y{z<&`OANLR0iQ+XXHKb`#H|nCkzfA5&7)0yxC&FG7(y`2LdhN8gzn6aQ{w{e{jbcJz04Yt4Q)yv8+q z4p`}Zu>cBVb5u(NrT>hWuP~Bo>b2isI(lN3A=4X<0m*-9qZg)QZWBnKHYYf3j_R5r zbyz!oEW0Bl@Sr3>dND$12_R_1d2bvfQ$GSx13vT zreb&}sjO@A6IfeI>bdtU4YFw6AokL=9Bp`}FsoQrjsk8U#!^&vA!zBRi^Pkh+cbSeMVjU7}EbsnXI1=h*8 zT)9Vxh(9i@h^N!rKdTA8U}_Yqr9;WvFk0_l}qff3C+7s4(ebIRY52f5V}FKt2C_@R)N}}<TC2NLWETs4vZmJ4>vSy%+o%Ejp zq-o}!<}1tT!w*Uq)Eu+WCS_GESDym~ISCqeHYb4*T_&wH6LdSfyPJ z;Mf6lykh!@T*KwNJX|H!=H6C%5RIh+M@nPDoE9@M|F#o|=^8AB6PBO>SeW4ZUAgYk z7>%8PyW6*ndPIvh=2LC$*%*tOADd;BrMWMW)9wqEwB85I=b+Yl$S_}?|K6CL^A|hb z9d|{wyM5uc_=vak5B|*-h`PUAnGDN$dCriJSe-*q;%CHQuh$92k3RL8+*AQ{l=MW=iyK@t_KfJ}qMk@InwC?HVr)JEDcNEV&kea*SuendTA@=c76?1O`&gNT(T{4%A&8 z!uprM`FG?>KY3&r!9#H5I6O9)QWV(#B2=rVNIrO5%5qJIT}_@SoVo&l^~ftlL)(>Cy3tTBg2~8~M!4$Wm{YP1X)Ei`+*ti*f js4>7o_4ZOG`!M- - database: - # -- (string) Username for postgres. This is a service override, defaults to - - username: + # -- (string) Database name for Funnel. + database: funnel + # -- (string) Username for Funnel. + username: funnel # -- (string) Port for Postgres. port: "5432" - # -- (string) Password for Postgres. Will be autogenerated if left empty. - password: - # -- (string) Will create a Database for the individual service to help with developing it. - separate: false - -# -- (map) Postgresql subchart settings if deployed separately option is set to "true". -# Disable persistence by default so we can spin up and down ephemeral environments -postgresql: - primary: - persistence: - # -- (bool) Option to persist the dbs data. - enabled: false + # -- (string) Password for Postgres. Override this for production deployments. + password: example -# -- (map) Configuration for network policies created by this chart. Only relevant if "global.netPolicy.enabled" is set to true -netPolicy: - # -- (array) List of app labels that require ingress to this service - ingressApps: - - gen3-workflow - # -- (array) List of apps that this app requires egress to - egressApps: - - gen3-workflow - -# Values to determine the labels that are used for the deployment, pod, etc. -# -- (string) Valid options are "production" or "dev". If invalid option is set- the value will default to "dev". -release: "production" -# -- (string) Valid options are "true" or "false". If invalid option is set- the value will default to "false". -criticalService: "false" -# -- (string) Label to help organize pods and their use. Any value is valid, but use "_" or "-" to divide words. -partOf: "Workflow_Execution" - -# -- (bool) Whether to create a job to generate the OIDC client for Funnel. -oidc_job_enabled: true - -funnel: - # -- (map) Configuration for the Funnel container image. - image: - # -- (string) The Docker image repository for the Funnel service. - repository: quay.io/ohsu-comp-bio/funnel - # -- (string) When to pull the image. This value should be "Always" to ensure the latest image is used. - pullPolicy: Always - - # -- (map) Configuration for the Funnel init container. - initContainers: - - name: plugin - # -- (string) The Docker image repository for the Funnel init/plugin container. - image: quay.io/cdis/funnel-gen3-plugin - # -- (string) The Docker image tag for the Funnel init/plugin container. - tag: main-gen3 - # -- (string) When to pull the image. This value should be "Always" to ensure the latest image is used. - pullPolicy: Always - # -- (list) Arguments to pass to the init container. - command: - - cp - - /app/build/plugins/authorizer - - /opt/funnel/plugin-binaries/auth-plugin - volumeMounts: - - name: plugin-volume - mountPath: /opt/funnel/plugin-binaries - - name: config-updater - image: quay.io/cdis/awshelper - tag: master - env: - - name: FUNNEL_OIDC_CLIENT_ID - valueFrom: - secretKeyRef: - name: funnel-oidc-client - key: client_id - optional: false - - name: FUNNEL_OIDC_CLIENT_SECRET - valueFrom: - secretKeyRef: - name: funnel-oidc-client - key: client_secret - optional: false - - name: DB_HOST - valueFrom: - secretKeyRef: - name: funnel-dbcreds - key: host - optional: false - - name: DB_USER - valueFrom: - secretKeyRef: - name: funnel-dbcreds - key: username - optional: false - - name: DB_PASSWORD - valueFrom: - secretKeyRef: - name: funnel-dbcreds - key: password - optional: false - - name: DB_DATABASE - valueFrom: - secretKeyRef: - name: funnel-dbcreds - key: database - optional: false - volumeMounts: - - name: funnel-patched-config-volume - mountPath: /tmp - - name: funnel-config-volume - mountPath: /etc/config/funnel.conf - subPath: funnel-server.yaml - command: ["/bin/bash"] - args: - - "-c" - - | - # Create a funnel-patched.conf since /etc/config/funnel.conf is readonly - CONFIG=/tmp/funnel-patched.conf - cp /etc/config/funnel.conf $CONFIG - - namespace=$(cat /var/run/secrets/kubernetes.io/serviceaccount/namespace) - JOBS_NAMESPACE=workflow-pods-$namespace - S3_URL=gen3-workflow-service.$namespace.svc.cluster.local - DB_HOST=$DB_HOST:5432 - - # `Kubernetes.JobsNamespace` has to be configured manually because of templating - # limitations. This ensures it is configured to the value that is hardcoded elsewhere. - configured=$(yq -r '.Kubernetes.JobsNamespace' "$CONFIG") - if [[ "$configured" != "$JOBS_NAMESPACE" ]]; then - echo "ERROR: funnel.Kubernetes.JobsNamespace is set to '$configured' instead of '$JOBS_NAMESPACE'. Please fix the configuration" >&2 - exit 1 - fi - - echo "======= Funnel configuration =======" - echo " Kubernetes.JobsNamespace : $JOBS_NAMESPACE" - echo " Plugins.Params.OidcClientId: $FUNNEL_OIDC_CLIENT_ID" - echo " Plugins.Params.S3Url : $S3_URL" - echo " Postgres.Host : $DB_HOST" - echo " Postgres.Database : $DB_DATABASE" - echo " Postgres.User : $DB_USER" - echo "====================================" - - # Replace placeholders with actual values (in-place) - sed -i "s|FUNNEL_PLUGIN_OIDC_CLIENT_ID_PLACEHOLDER|${FUNNEL_OIDC_CLIENT_ID}|g" $CONFIG - sed -i "s|FUNNEL_PLUGIN_OIDC_CLIENT_SECRET_PLACEHOLDER|${FUNNEL_OIDC_CLIENT_SECRET}|g" $CONFIG - sed -i "s|FUNNEL_PLUGIN_S3URL_PLACEHOLDER|${S3_URL}|g" $CONFIG - sed -i "s/FUNNEL_POSTGRES_HOST_PLACEHOLDER/${DB_HOST}/g" $CONFIG - sed -i "s/FUNNEL_POSTGRES_DATABASE_PLACEHOLDER/${DB_DATABASE}/g" $CONFIG - sed -i "s/FUNNEL_POSTGRES_USER_PLACEHOLDER/${DB_USER}/g" $CONFIG - sed -i "s/FUNNEL_POSTGRES_PASSWORD_PLACEHOLDER/${DB_PASSWORD}/g" $CONFIG - - volumes: - - name: funnel-config-volume - configMap: - name: funnel-server-config - - name: funnel-oidc-volume - secret: - secretName: "funnel-oidc-client" - items: - - key: client_id - path: client_id - - key: client_secret - path: client_secret - - - name: worker-templates-volume - configMap: - name: funnel-worker-templates +rbac: + create: true - - name: plugin-volume - emptyDir: {} # Shared volume +# Resource Requests/Limits for worker jobs and server pods. +resources: + requests: + cpu: 100m + memory: 512Mi + ephemeral_storage: 512Mi + limits: + cpu: 1000m + memory: 2048Mi + ephemeral_storage: 2048Mi - - name: funnel-patched-config-volume - emptyDir: {} # Shared volume for config data +# AWS STS Source + Region for S3 CSI Driver +authenticationSource: pod +stsRegion: us-east-1 - volumeMounts: - - name: funnel-patched-config-volume - mountPath: /etc/config/funnel-server.yaml - subPath: funnel-patched.conf +# Kubernetes Service Settings +service: + type: ClusterIP + httpPort: 8000 + rpcPort: 9090 - - name: "funnel-oidc-volume" - readOnly: true - mountPath: "/etc/config/oidc" +# Funnel Worker + Executor storage (S3 bucket) +storage: + driver: aws-s3 + size: 10Mi + accessMode: ReadWriteMany + className: s3-csi-sc + provisioner: s3.csi.aws.com + createStorageClass: true - - name: worker-templates-volume - mountPath: /etc/funnel/templates +# Funnel default settings configured for Gen3-managed PostgreSQL. +# +# These are passed into `files/server-config.yaml` and made available to the deployment via `server-configmap.yaml` +# +# - Ref: https://github.com/ohsu-comp-bio/funnel/blob/master/config/default-config.yaml - - name: plugin-volume - mountPath: /opt/funnel/plugin-binaries +# The name of the active server database backend +# Available backends: boltdb, badger, datastore, dynamodb, elastic, mongodb, postgres +Database: postgres - resources: - requests: - memory: "2Gi" - ephemeral_storage: "2Gi" +# The name of the active compute backend +# Available backends: local, htcondor, slurm, pbs, gridengine, manual, aws-batch, kubernetes +Compute: kubernetes + +# The name of the active event writer backend(s). +# Available backends: log, boltdb, badger, datastore, dynamodb, elastic, mongodb, postgres, kafka +EventWriters: + - postgres + - log + +Logger: + # Logging levels: debug, info, error + level: debug + # Write logs to this path. If empty, logs are written to stderr. + outputFile: "" + +Server: + # Hostname of the Funnel server. + HostName: funnel + + # Port used for HTTP communication and the web dashboard. + HTTPPort: "8000" + + # Port used for RPC communication. + RPCPort: "9090" + + # Require basic authentication for the server APIs using a password. + # If used, make sure to properly restrict access to the config file + # (e.g. chmod 600 funnel.config.yml) + # BasicAuth: + # - User: user1 + # Password: abc123 + # - User: user2 + # Password: foobar + + # Include a "Cache-Control: no-store" HTTP header in Get/List responses + # to prevent caching by intermediary services. + DisableHTTPCache: true + +RPCClient: + # RPC server address + ServerAddress: localhost:9090 + + # Credentials for Basic authentication for the server APIs using a password. + # If used, make sure to properly restrict access to the config file + # (e.g. chmod 600 funnel.config.yml) + # User: funnel + # Password: abc123 + + # connection timeout. + Timeout: + duration: 60s + + # The maximum number of times that a request will be retried for failures. + # Time between retries follows an exponential backoff starting at 5 seconds + # up to 1 minute + MaxRetries: 10 + +# The scheduler is used for the Manual compute backend. +Scheduler: + # How often to run a scheduler iteration. + ScheduleRate: 1s + # How many tasks to schedule in one iteration. + ScheduleChunk: 10 + # How long to wait between updates before marking a node dead. + NodePingTimeout: + duration: 60s + # How long to wait for a node to start, before marking the node dead. + NodeInitTimeout: + duration: 300s + +Node: + # If empty, a node ID will be automatically generated. + ID: "" + + # If the node has been idle for longer than the timeout, it will shut down. + # -1 means there is no timeout. 0 means timeout immediately after the first task. + Timeout: + disabled: true + + # A Node will automatically try to detect what resources are available to it. + # Defining Resources in the Node configuration overrides this behavior. + Resources: + # CPUs available. + Cpus: 0 + + # RAM available, in GB. + RamGb: 0.0 + + # Disk space available, in GB. + DiskGb: 0.0 + + # For low-level tuning. + # How often to sync with the Funnel server. + UpdateRate: 5s + +Worker: + # Files created during processing will be written in this directory. + WorkDir: ./funnel-work-dir + + # For low-level tuning. + # How often to poll for cancel signals + PollingRate: 5s + + # For low-level tuning. + # How often to send stdout/err task log updates to the Funnel server. + # Setting this to 0 will result in these fields being updated a single time + # after the executor exits. + LogUpdateRate: 5s + + # Max bytes to store for stdout/err in the task log (10 KB) + LogTailSize: 10000 + + # Normally the worker deletes its working directory after executing. + # This option disables that behavior. + LeaveWorkDir: false + + # Limit the number of concurrent downloads/uploads + MaxParallelTransfers: 10 + +# ------------------------------------------------------------------------------- +# Databases and/or Event Writers/Handlers +# ------------------------------------------------------------------------------- + +# -- Local file database configuration. +BoltDB: + # Path to the database file + Path: ./funnel-work-dir/funnel.db + +DynamoDB: + # Basename to use for dynamodb tables + TableBasename: funnel + AWSConfig: + # AWS region + Region: "" + # AWS Access key ID + Key: "" + # AWS Secret Access Key + Secret: "" + +Elastic: + # Prefix to use for indexes (task, events, nodes) + IndexPrefix: funnel + # URL of the elasticsearch server. + URL: http://localhost:9200 + +# Google Cloud Datastore task database. +Datastore: + Project: "" + # Path to account credentials file. + # Optional. If possible, credentials will be automatically discovered + # from the environment. + CredentialsFile: "" + +Postgres: + Host: funnel-postgresql.default.svc.cluster.local + Database: funnel + User: funnel + Password: example + AdminUser: postgres + AdminPassword: example + Timeout: + duration: 300s + +Kafka: + Topic: funnel + +# ------------------------------------------------------------------------------- +# Compute Backends +# ------------------------------------------------------------------------------- + +# -- HTCondor compute backend configuration. +HTCondor: + # Turn off task state reconciler. When enabled, Funnel communicates with the HPC + # scheduler to find tasks that are stuck in a queued state or errored and + # updates the task state accordingly. + DisableReconciler: true + # ReconcileRate is how often the compute backend compares states in Funnel's backend + # to those reported by the backend + ReconcileRate: 10s + TemplateFile: "" + Template: | + universe = vanilla + getenv = True + executable = {{.Executable}} + arguments = worker run --config {{.Config}} --task-id {{.TaskId}} + log = {{.WorkDir}}/condor-event-log + error = {{.WorkDir}}/funnel-stderr + output = {{.WorkDir}}/funnel-stdout + should_transfer_files = YES + when_to_transfer_output = ON_EXIT_OR_EVICT + {{if ne .Cpus 0 -}} + {{printf "request_cpus = %d" .Cpus}} + {{- end}} + {{if ne .RamGb 0.0 -}} + {{printf "request_memory = %.0f GB" .RamGb}} + {{- end}} + {{if ne .DiskGb 0.0 -}} + {{printf "request_disk = %.0f GB" .DiskGb}} + {{- end}} + + queue + +PBS: + # Turn off task state reconciler. When enabled, Funnel communicates with the HPC + # scheduler to find tasks that are stuck in a queued state or errored and + # updates the task state accordingly. + DisableReconciler: true + # ReconcileRate is how often the compute backend compares states in Funnel's backend + # to those reported by the backend + ReconcileRate: 10s + TemplateFile: "" + Template: | + #!bin/bash + #PBS -N {{.TaskId}} + #PBS -o {{.WorkDir}}/funnel-stdout + #PBS -e {{.WorkDir}}/funnel-stderr + {{if ne .Cpus 0 -}} + {{printf "#PBS -l nodes=1:ppn=%d" .Cpus}} + {{- end}} + {{if ne .RamGb 0.0 -}} + {{printf "#PBS -l mem=%.0fgb" .RamGb}} + {{- end}} + {{if ne .DiskGb 0.0 -}} + {{printf "#PBS -l file=%.0fgb" .DiskGb}} + {{- end}} + + {{.Executable}} worker run --config {{.Config}} --taskID {{.TaskId}} + +GridEngine: + TemplateFile: "" + Template: | + #!bin/bash + #$ -N {{.TaskId}} + #$ -o {{.WorkDir}}/funnel-stdout + #$ -e {{.WorkDir}}/funnel-stderr + #$ -l nodes=1 + {{if ne .Cpus 0 -}} + {{printf "#$ -pe mpi %d" .Cpus}} + {{- end}} + {{if ne .RamGb 0.0 -}} + {{printf "#$ -l h_vmem=%.0fG" .RamGb}} + {{- end}} + {{if ne .DiskGb 0.0 -}} + {{printf "#$ -l h_fsize=%.0fG" .DiskGb}} + {{- end}} + + {{.Executable}} worker run --config {{.Config}} --taskID {{.TaskId}} + +Slurm: + # Turn off task state reconciler. When enabled, Funnel communicates with the HPC + # scheduler to find tasks that are stuck in a queued state or errored and + # updates the task state accordingly. + DisableReconciler: true + # ReconcileRate is how often the compute backend compares states in Funnel's backend + # to those reported by the backend + ReconcileRate: 10s + TemplateFile: "" + Template: | + #!/bin/bash + #SBATCH --job-name {{.TaskId}} + #SBATCH --ntasks 1 + #SBATCH --error {{.WorkDir}}/funnel-stderr + #SBATCH --output {{.WorkDir}}/funnel-stdout + {{if ne .Cpus 0 -}} + {{printf "#SBATCH --cpus-per-task %d" .Cpus}} + {{- end}} + {{if ne .RamGb 0.0 -}} + {{printf "#SBATCH --mem %.0fGB" .RamGb}} + {{- end}} + {{if ne .DiskGb 0.0 -}} + {{printf "#SBATCH --tmp %.0fGB" .DiskGb}} + {{- end}} + + {{.Executable}} worker run --config {{.Config}} --taskID {{.TaskId}} + +# AWSBatch describes the configuration for the AWS Batch compute backend. +AWSBatch: + # Turn off task state reconciler. When enabled, Funnel communicates with AWS Batch + # to find tasks that never started and updates task state accordingly. + DisableReconciler: true + # ReconcileRate is how often the compute backend compares states in Funnel's backend + # to those reported by AWS Batch + ReconcileRate: 10s + # JobDefinition can be either a name or the Amazon Resource Name (ARN). + JobDefinition: "funnel-job-def" + # JobQueue can be either a name or the Amazon Resource Name (ARN). + JobQueue: "funnel-job-queue" + # AWS region of the specified job queue and to create the job definition in + Region: "" + Key: "" + Secret: "" + +# Kubernetes describes the configuration for the Kubernetes compute backend. +Kubernetes: + Executor: + Annotations: {} + PriorityClassName: "" + restartPolicy: OnFailure + # Setting backoffLimit to 0 means no retries. + backoffLimit: 0 + # Setting completions to 1 means the job completes after one successful execution. + completions: 1 - Database: postgres - EventWriters: - - postgres - - log - postgresql: # default bitnami postgres pod - enabled: false - Postgres: - Host: FUNNEL_POSTGRES_HOST_PLACEHOLDER - Database: FUNNEL_POSTGRES_DATABASE_PLACEHOLDER - User: FUNNEL_POSTGRES_USER_PLACEHOLDER - Password: FUNNEL_POSTGRES_PASSWORD_PLACEHOLDER - Logger: - Level: info - Plugins: - Path: plugin-binaries/auth-plugin - Params: - OidcClientId: FUNNEL_PLUGIN_OIDC_CLIENT_ID_PLACEHOLDER - OidcClientSecret: FUNNEL_PLUGIN_OIDC_CLIENT_SECRET_PLACEHOLDER - S3Url: FUNNEL_PLUGIN_S3URL_PLACEHOLDER Worker: - # This lets mount-s3 pods unmount and Complete. https://ctds-planx.atlassian.net/browse/MIDRC-1214 - LeaveWorkDir: true - Kubernetes: - # Timeout for task creation (worker pod creation). On timeout, tasks fail with SYSTEM_ERROR - Timeout: - duration: 300s - ReconcileRate: 120s - Executor: - restartPolicy: Never - backoffLimit: 0 - Annotations: - karpenter.sh/do-not-disrupt: "true" - Worker: - restartPolicy: Never - backoffLimit: 1 - Annotations: - karpenter.sh/do-not-disrupt: "true" - # When a new node is ready, worker pods may start before system-level pods do. This ensures - # worker pods are not preempted by new system-level pods on that node. - PriorityClassName: "system-cluster-critical" + Annotations: {} + PriorityClassName: "" + restartPolicy: Never + backoffLimit: 0 + completions: 1 + + # Turn off task state reconciler. When enabled, Funnel communicates with Kubernetes + # to find tasks that are stuck in a queued state or errored and + # updates the task state accordingly. + DisableReconciler: false + DisableJobCleanup: false + # -- Path prefixes that Funnel's Kubernetes backend must reject when creating worker pods. + ForbiddenPathPrefixes: [] + # ReconcileRate is how often the compute backend compares states in Funnel's backend + # to those reported by the backend + ReconcileRate: 10s + # Kubernetes Namespace to spawn jobs within + Namespace: "" + # Kubernetes Namespace to spawn jobs within + JobsNamespace: "" + # Kubernetes ServiceAccount to use for the job + ServiceAccount: "" + Timeout: + duration: 30s + # Master batch job template. See: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.17/#job-v1-batch + WorkerTemplate: "" + # NodeSelector (scheduling) + NodeSelector: {} + # Tolerations (scheduling) + Tolerations: [] + + # Job template used for executing the tasks. + ExecutorTemplate: "" + PVTemplate: "" + PVCTemplate: "" + + Resources: + Defaults: + Cpus: 1000m + RamGb: 512Mi + DiskGb: 512Mi + Limits: + Cpus: 8000m + RamGb: 4096Mi + DiskGb: 4096Mi + +# cleanup configures an optional CronJob that runs `funnel kubernetes cleanup` +# to delete orphaned Funnel-managed Kubernetes resources. It is intentionally +# turned off by default; set cleanup.enabled=true to enable it. +cleanup: + enabled: false + # Leave empty to derive the schedule from Kubernetes.ReconcileRate. Set a + # standard 5-field cron expression to override, e.g. "*/15 * * * *". + schedule: "" + # Offset the start minute so cleanup jobs in different namespaces do not all + # fire at the same instant. Must be 0-59. + scheduleOffsetMinutes: 0 + +# ------------------------------------------------------------------------------- +# Storage +# ------------------------------------------------------------------------------- + +# If possible, credentials will be automatically discovered +# from the environment. + +# -- Local file system storage configuration. +LocalStorage: + # Whitelist of local directory paths which Funnel is allowed to access. + AllowedDirs: + - ./ + +# HTTPStorage is used to download public files on the web via a GET request. +HTTPStorage: + # Timeout for http(s) GET requests. + Timeout: 30s + +AmazonS3: + Disabled: false + # The maximum number of times that a request will be retried for failures. + AWSConfig: + MaxRetries: 10 + # AWS Access key ID + Key: "" + # AWS Secret Access Key + Secret: "" + # Server Side Encryption (SSE) settings + SSE: + # Customer Provided Key + # ref: https://docs.aws.amazon.com/AmazonS3/latest/userguide/ServerSideEncryptionCustomerKeys.html + CustomerKeyFile: "" + # KMS Key + # ref: https://docs.aws.amazon.com/AmazonS3/latest/userguide/UsingKMSEncryption.html + KMSKey: "" + +# Configure storage backends for S3 providers such as Minio and/or Ceph +# GenericS3: +# - Disabled: true +# Endpoint: "" +# Key: "" +# Secret: "" +# KmsKeyID: "" + +GoogleStorage: + Disabled: false + # Path to account credentials file. + # Optional. If possible, credentials will be automatically discovered + # from the environment. + CredentialsFile: "" +# Available backends: local, htcondor, slurm, pbs, gridengine, manual, aws-batch, kubernetes/Kube +Swift: + Disabled: false + UserName: "" + Password: "" + AuthURL: "" + TenantName: "" + TenantID: "" + RegionName: "" + # 500 MB + ChunkSizeBytes: 500000000 + +FTPStorage: + Disabled: false + Timeout: 10s + User: "anonymous" + Password: "anonymous" + +# Overrides the default volumes configured in the server deployment. +# If custom volumes are specified, they will fully replace the default values. +volumes: + - name: funnel-server-config-volume + configMap: + name: funnel-server-config + + - name: plugin-volume + emptyDir: {} # Shared volume + +# Overrides the default volumesMounts configured in the server deployment. +# If custom volumesMounts are specified, they will fully replace the default values. +volumeMounts: + - name: funnel-server-config-volume + mountPath: /etc/config/funnel-server.yaml + subPath: funnel-server.yaml + + - name: plugin-volume + mountPath: /opt/funnel/plugin-binaries From c426b0bbe6371e1e08706c96c448d8d74c01162a Mon Sep 17 00:00:00 2001 From: Andrew Prokhorenkov Date: Tue, 7 Jul 2026 11:43:11 -0500 Subject: [PATCH 061/196] Change target branch from feat/vectis-merge to master --- .github/ct.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/ct.yaml b/.github/ct.yaml index 750c0c982..17d1fff20 100644 --- a/.github/ct.yaml +++ b/.github/ct.yaml @@ -1,5 +1,5 @@ remote: origin -target-branch: feat/vectis-merge +target-branch: master chart-dirs: - helm chart-repos: From 9a33ce86164e89438c13cbea4596f0af6747b324 Mon Sep 17 00:00:00 2001 From: Sai Shanmukha Narumanchi Date: Tue, 7 Jul 2026 13:06:08 -0500 Subject: [PATCH 062/196] Fix typo --- helm/revproxy/gen3.nginx.conf/gen3-workflow-service.conf | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/helm/revproxy/gen3.nginx.conf/gen3-workflow-service.conf b/helm/revproxy/gen3.nginx.conf/gen3-workflow-service.conf index db296bff9..14a2bee34 100644 --- a/helm/revproxy/gen3.nginx.conf/gen3-workflow-service.conf +++ b/helm/revproxy/gen3.nginx.conf/gen3-workflow-service.conf @@ -11,7 +11,7 @@ location /ga4gh/tes/v1/ { location /workflows/ { if ($csrf_check !~ ^ok-\S.+$) { - return 403 "failed csrf check";s + return 403 "failed csrf check"; } auth_request /block-denylisted-token; @@ -19,4 +19,4 @@ location /workflows/ { set $upstream http://gen3-workflow-service.$namespace.svc.cluster.local; rewrite ^/workflows/(.*) /$1 break; proxy_pass $upstream; -} \ No newline at end of file +} From 490319ac84e0b45a36d867cb7b54efcef0f174c2 Mon Sep 17 00:00:00 2001 From: Andrew Prokhorenkov Date: Tue, 7 Jul 2026 14:06:12 -0500 Subject: [PATCH 063/196] bump revproxy chart version to 0.1.62 --- helm/revproxy/Chart.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/helm/revproxy/Chart.yaml b/helm/revproxy/Chart.yaml index 37cb46c45..88ae26629 100644 --- a/helm/revproxy/Chart.yaml +++ b/helm/revproxy/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.61 +version: 0.1.62 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to From 71647b3fc74fab0a356bb4d2112e246ba448549e Mon Sep 17 00:00:00 2001 From: Mingfei Shao Date: Tue, 7 Jul 2026 16:58:41 -0500 Subject: [PATCH 064/196] add external secret --- .../templates/external-secret.yaml | 24 +++++++++++++++++++ 1 file changed, 24 insertions(+) create mode 100644 helm/zendesk-wrapper/templates/external-secret.yaml diff --git a/helm/zendesk-wrapper/templates/external-secret.yaml b/helm/zendesk-wrapper/templates/external-secret.yaml new file mode 100644 index 000000000..b6e5c865f --- /dev/null +++ b/helm/zendesk-wrapper/templates/external-secret.yaml @@ -0,0 +1,24 @@ +--- +{{- if .Values.global.externalSecrets.deploy }} +apiVersion: external-secrets.io/v1beta1 +kind: ExternalSecret +metadata: + name: zendesk-wrapper-secret +spec: + refreshInterval: 5m + secretStoreRef: + name: {{include "common.SecretStore" .}} + kind: SecretStore + target: + name: zendesk-wrapper-secret + creationPolicy: Owner + data: + - secretKey: tokenKey + remoteRef: + key: zendesk-wrapper-secret + property: tokenKey + - secretKey: apiEmail + remoteRef: + key: zendesk-wrapper-secret + property: apiEmail +{{- end }} From 837a625ebb2e5d3626b88a30169d1a267ef43bd8 Mon Sep 17 00:00:00 2001 From: Sai Shanmukha Date: Tue, 7 Jul 2026 18:41:06 -0500 Subject: [PATCH 065/196] Change `/token/denylist` to `/token/denylisted` --- helm/revproxy/gen3.nginx.conf/fence-service.conf | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/helm/revproxy/gen3.nginx.conf/fence-service.conf b/helm/revproxy/gen3.nginx.conf/fence-service.conf index 86020bcb2..7a30e6869 100644 --- a/helm/revproxy/gen3.nginx.conf/fence-service.conf +++ b/helm/revproxy/gen3.nginx.conf/fence-service.conf @@ -27,11 +27,11 @@ location /block-denylisted-token { set $proxy_service "fence"; error_page 400 =403 @block_blacklisted_token; error_page 500 =403 @block_blacklisted_token; - # Previous versions of Fence that don't have the "/token/denylist" endpoint return 405. + # Previous versions of Fence that don't have the "/token/denylisted" endpoint return 405. # Returning 403 forces the deployment of a recent Fence for endpoints that require this check. error_page 405 =403 @block_blacklisted_token; - proxy_pass http://fence-service${des_domain}/credentials/token/denylist; + proxy_pass http://fence-service${des_domain}/credentials/token/denylisted; proxy_method POST; proxy_pass_request_body off; proxy_set_header Authorization "$access_token"; @@ -55,7 +55,7 @@ location @block_blacklisted_token { return 403 "unable to check if token is blacklisted"; } -location /user/credentials/token/denylist { +location /user/credentials/token/denylisted { # Not meant to be called by users, # but by the `auth_request /block-denylisted-token` location above. deny all; From 0c263eba05fd9e92c078b5b818d183f4102c6064 Mon Sep 17 00:00:00 2001 From: Sai Shanmukha Date: Wed, 8 Jul 2026 08:58:04 -0500 Subject: [PATCH 066/196] Update funnel chart version and remove funnel-chart-check -- irrelevant since funnel as a dependent chart no longer exists. --- .pre-commit-config.yaml | 10 +-------- git-hook/funnel-chart-check.sh | 9 -------- helm/funnel/Chart.yaml | 2 +- helm/funnel/README.md | 39 +--------------------------------- helm/gen3/Chart.yaml | 4 ++-- helm/gen3/README.md | 4 ++-- 6 files changed, 7 insertions(+), 61 deletions(-) delete mode 100755 git-hook/funnel-chart-check.sh diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index e6605717f..ac0d4e5c5 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -36,12 +36,4 @@ repos: entry: git-hook/helm-bump.sh language: script name: Helm Docs - require_serial: true - - - repo: local - hooks: - - id: funnel-chart-check - name: Funnel chart check - entry: git-hook/funnel-chart-check.sh - language: script - pass_filenames: false + require_serial: true \ No newline at end of file diff --git a/git-hook/funnel-chart-check.sh b/git-hook/funnel-chart-check.sh deleted file mode 100755 index 9f59fa783..000000000 --- a/git-hook/funnel-chart-check.sh +++ /dev/null @@ -1,9 +0,0 @@ -#!/bin/bash - -funnelVer=$(yq '.dependencies[] | select(.name == "funnel") .version' helm/funnel/Chart.yaml) -chartPath=helm/funnel/charts/funnel-$funnelVer.tgz -if [ ! -f "$chartPath" ]; then - echo "$chartPath does not exist. Please run 'cd helm/funnel && helm dependency update'. Existing files:" - ls helm/funnel/charts - exit 1 -fi diff --git a/helm/funnel/Chart.yaml b/helm/funnel/Chart.yaml index 92644a760..076eed37e 100644 --- a/helm/funnel/Chart.yaml +++ b/helm/funnel/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.26 +version: 0.1.27 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/funnel/README.md b/helm/funnel/README.md index 60d05674e..da731d5b6 100644 --- a/helm/funnel/README.md +++ b/helm/funnel/README.md @@ -1,45 +1,9 @@ # funnel -![Version: 0.1.26](https://img.shields.io/badge/Version-0.1.26-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.27](https://img.shields.io/badge/Version-0.1.27-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for Kubernetes -Funnel is source-owned in `gen3-helm` and is wired into the Gen3 umbrella chart -as a local subchart through `file://../funnel`. - -## Database - -This chart is configured to use Gen3-managed PostgreSQL for Funnel task and -event storage. The previous bundled MongoDB dependency was removed because we -believe the MongoDB event writer is no longer used by this deployment path. - -The Helm render verifies the generated Funnel config points at PostgreSQL and no -MongoDB resources are created. A deployed-cluster smoke test is still required -to prove the Funnel server binary successfully connects to and migrates/uses the -PostgreSQL database in a real environment. - -Deployments that still need MongoDB event writing must reintroduce explicit -external MongoDB configuration. - -## Cleanup CronJob - -The optional cleanup CronJob runs: - -```bash -funnel kubernetes cleanup --config /etc/config/funnel-server.yaml -``` - -It is intentionally disabled by default. Enable it with: - -```yaml -cleanup: - enabled: true -``` - -When `cleanup.schedule` is empty, the chart derives the CronJob schedule from -`Kubernetes.ReconcileRate`. Set `cleanup.schedule` to a standard 5-field cron -expression to override it. - ## Requirements | Repository | Name | Version | @@ -234,4 +198,3 @@ expression to override it. | volumes[0].name | string | `"funnel-server-config-volume"` | | | volumes[1].emptyDir | object | `{}` | | | volumes[1].name | string | `"plugin-volume"` | | - diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index c21a8f708..d922ad155 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -72,7 +72,7 @@ dependencies: repository: "file://../fence" condition: fence.enabled - name: funnel - version: 0.1.26 + version: 0.1.27 repository: "file://../funnel" condition: gen3-workflow.enabled - name: gen3-user-data-library @@ -197,7 +197,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.59 +version: 0.3.60 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index b9a48b561..960496337 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,6 +1,6 @@ # gen3 -![Version: 0.3.59](https://img.shields.io/badge/Version-0.3.59-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.3.60](https://img.shields.io/badge/Version-0.3.60-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons @@ -36,7 +36,7 @@ Helm chart to deploy Gen3 Data Commons | file://../etl | etl | 0.1.23 | | file://../fence | fence | 0.1.78 | | file://../frontend-framework | frontend-framework | 0.1.29 | -| file://../funnel | funnel | 0.1.26 | +| file://../funnel | funnel | 0.1.27 | | file://../gen3-analysis | gen3-analysis | 0.1.12 | | file://../gen3-network-policies | gen3-network-policies | 0.1.4 | | file://../gen3-user-data-library | gen3-user-data-library | 0.1.15 | From 38f12395cc440be94725232933b729a2a0a1f28d Mon Sep 17 00:00:00 2001 From: Ajo Augustine Date: Wed, 8 Jul 2026 09:37:25 -0500 Subject: [PATCH 067/196] enable linklocal for audit and dashboard --- helm/audit/Chart.yaml | 2 +- helm/audit/README.md | 2 +- helm/audit/templates/deployment.yaml | 1 + helm/dashboard/Chart.yaml | 2 +- helm/dashboard/README.md | 2 +- helm/dashboard/templates/deployment.yaml | 1 + helm/gen3/Chart.yaml | 6 +++--- helm/gen3/README.md | 6 +++--- 8 files changed, 12 insertions(+), 10 deletions(-) diff --git a/helm/audit/Chart.yaml b/helm/audit/Chart.yaml index ad2c2de58..d3e1b9c5c 100644 --- a/helm/audit/Chart.yaml +++ b/helm/audit/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.42 +version: 0.1.43 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/audit/README.md b/helm/audit/README.md index 1ca245644..8276e9fa5 100644 --- a/helm/audit/README.md +++ b/helm/audit/README.md @@ -1,6 +1,6 @@ # audit -![Version: 0.1.42](https://img.shields.io/badge/Version-0.1.42-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.43](https://img.shields.io/badge/Version-0.1.43-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for Kubernetes diff --git a/helm/audit/templates/deployment.yaml b/helm/audit/templates/deployment.yaml index dd740acf6..d8b335841 100644 --- a/helm/audit/templates/deployment.yaml +++ b/helm/audit/templates/deployment.yaml @@ -33,6 +33,7 @@ spec: {{- include "audit.selectorLabels" . | nindent 8 }} {{- include "common.extraLabels" . | nindent 8 }} internet: "yes" + linklocal: "yes" netvpc: "yes" spec: {{- if .Values.global.topologySpread.enabled }} diff --git a/helm/dashboard/Chart.yaml b/helm/dashboard/Chart.yaml index 6a39369ae..77909501d 100644 --- a/helm/dashboard/Chart.yaml +++ b/helm/dashboard/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.20 +version: 0.1.21 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/dashboard/README.md b/helm/dashboard/README.md index 3d87f0458..14cdca949 100644 --- a/helm/dashboard/README.md +++ b/helm/dashboard/README.md @@ -1,6 +1,6 @@ # dashboard -![Version: 0.1.20](https://img.shields.io/badge/Version-0.1.20-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.16.0](https://img.shields.io/badge/AppVersion-1.16.0-informational?style=flat-square) +![Version: 0.1.21](https://img.shields.io/badge/Version-0.1.21-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.16.0](https://img.shields.io/badge/AppVersion-1.16.0-informational?style=flat-square) A Helm chart for Kubernetes diff --git a/helm/dashboard/templates/deployment.yaml b/helm/dashboard/templates/deployment.yaml index eb445cbed..a00b72977 100644 --- a/helm/dashboard/templates/deployment.yaml +++ b/helm/dashboard/templates/deployment.yaml @@ -25,6 +25,7 @@ spec: s3: "yes" netvpc: "yes" internet: "yes" + linklocal: "yes" app: "dashboard" {{- include "dashboard.labels" . | nindent 8 }} {{- with .Values.podLabels }} diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index c21a8f708..85617b262 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -21,7 +21,7 @@ dependencies: repository: "file://../argo-wrapper" condition: argo-wrapper.enabled - name: audit - version: 0.1.42 + version: 0.1.43 repository: "file://../audit" condition: audit.enabled - name: aws-es-proxy @@ -44,7 +44,7 @@ dependencies: version: 0.1.36 repository: file://../common - name: dashboard - version: 0.1.20 + version: 0.1.21 repository: file://../dashboard condition: dashboard.enabled - name: datareplicate @@ -197,7 +197,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.59 +version: 0.3.60 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index b9a48b561..d60ce8d74 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,6 +1,6 @@ # gen3 -![Version: 0.3.59](https://img.shields.io/badge/Version-0.3.59-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.3.60](https://img.shields.io/badge/Version-0.3.60-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons @@ -22,13 +22,13 @@ Helm chart to deploy Gen3 Data Commons | file://../ambassador | ambassador | 0.1.37 | | file://../arborist | arborist | 0.1.34 | | file://../argo-wrapper | argo-wrapper | 0.1.30 | -| file://../audit | audit | 0.1.42 | +| file://../audit | audit | 0.1.43 | | file://../aws-es-proxy | aws-es-proxy | 0.1.41 | | file://../aws-sigv4-proxy | aws-sigv4-proxy | 0.1.2 | | file://../cedar | cedar | 0.1.26 | | file://../cohort-middleware | cohort-middleware | 0.1.22 | | file://../common | common | 0.1.36 | -| file://../dashboard | dashboard | 0.1.20 | +| file://../dashboard | dashboard | 0.1.21 | | file://../data-upload-cron | data-upload-cron | 0.1.6 | | file://../datareplicate | datareplicate | 0.1.21 | | file://../dicom-server | dicom-server | 0.1.31 | From 0506d421e8736c3896ab8d9307452efaa34ebc20 Mon Sep 17 00:00:00 2001 From: Mingfei Shao Date: Wed, 8 Jul 2026 10:11:53 -0500 Subject: [PATCH 068/196] upadte external secret ref --- helm/zendesk-wrapper/templates/external-secret.yaml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/helm/zendesk-wrapper/templates/external-secret.yaml b/helm/zendesk-wrapper/templates/external-secret.yaml index b6e5c865f..89f8b7e0f 100644 --- a/helm/zendesk-wrapper/templates/external-secret.yaml +++ b/helm/zendesk-wrapper/templates/external-secret.yaml @@ -15,10 +15,10 @@ spec: data: - secretKey: tokenKey remoteRef: - key: zendesk-wrapper-secret + key: {{include "zendesk-wrapper-secret" .}} property: tokenKey - secretKey: apiEmail remoteRef: - key: zendesk-wrapper-secret + key: {{include "zendesk-wrapper-secret" .}} property: apiEmail {{- end }} From ce78e71e561b25cc169f4c9ebe1499a2ded4f279 Mon Sep 17 00:00:00 2001 From: Sai Shanmukha Date: Wed, 8 Jul 2026 10:39:13 -0500 Subject: [PATCH 069/196] Update funnel values.yaml with Gen3 based installation overrides --- helm/funnel/README.md | 160 ++++++---- helm/funnel/values.yaml | 644 ++++++++++++++++++++++++++-------------- 2 files changed, 525 insertions(+), 279 deletions(-) diff --git a/helm/funnel/README.md b/helm/funnel/README.md index da731d5b6..699695ebf 100644 --- a/helm/funnel/README.md +++ b/helm/funnel/README.md @@ -32,6 +32,7 @@ A Helm chart for Kubernetes | Database | string | `"postgres"` | | | Datastore.CredentialsFile | string | `""` | | | Datastore.Project | string | `""` | | +| Datastore.Timeout.duration | string | `"300s"` | | | DynamoDB.AWSConfig.Key | string | `""` | | | DynamoDB.AWSConfig.Region | string | `""` | | | DynamoDB.AWSConfig.Secret | string | `""` | | @@ -53,11 +54,11 @@ A Helm chart for Kubernetes | Kafka.Topic | string | `"funnel"` | | | Kubernetes.DisableJobCleanup | bool | `false` | | | Kubernetes.DisableReconciler | bool | `false` | | -| Kubernetes.Executor.Annotations | object | `{}` | | +| Kubernetes.Executor.Annotations."karpenter.sh/do-not-disrupt" | string | `"true"` | | | Kubernetes.Executor.PriorityClassName | string | `""` | | | Kubernetes.Executor.backoffLimit | int | `0` | | | Kubernetes.Executor.completions | int | `1` | | -| Kubernetes.Executor.restartPolicy | string | `"OnFailure"` | | +| Kubernetes.Executor.restartPolicy | string | `"Never"` | | | Kubernetes.ExecutorTemplate | string | `""` | | | Kubernetes.ForbiddenPathPrefixes | list | `[]` | Path prefixes that Funnel's Kubernetes backend must reject when creating worker pods. | | Kubernetes.JobsNamespace | string | `""` | | @@ -65,7 +66,7 @@ A Helm chart for Kubernetes | Kubernetes.NodeSelector | object | `{}` | | | Kubernetes.PVCTemplate | string | `""` | | | Kubernetes.PVTemplate | string | `""` | | -| Kubernetes.ReconcileRate | string | `"10s"` | | +| Kubernetes.ReconcileRate | string | `"120s"` | | | Kubernetes.Resources.Defaults.Cpus | string | `"1000m"` | | | Kubernetes.Resources.Defaults.DiskGb | string | `"512Mi"` | | | Kubernetes.Resources.Defaults.RamGb | string | `"512Mi"` | | @@ -73,15 +74,20 @@ A Helm chart for Kubernetes | Kubernetes.Resources.Limits.DiskGb | string | `"4096Mi"` | | | Kubernetes.Resources.Limits.RamGb | string | `"4096Mi"` | | | Kubernetes.ServiceAccount | string | `""` | | -| Kubernetes.Timeout.duration | string | `"30s"` | | +| Kubernetes.Timeout.duration | string | `"300s"` | | | Kubernetes.Tolerations | list | `[]` | | -| Kubernetes.Worker.Annotations | object | `{}` | | -| Kubernetes.Worker.PriorityClassName | string | `""` | | +| Kubernetes.Worker.Annotations."karpenter.sh/do-not-disrupt" | string | `"true"` | | +| Kubernetes.Worker.PriorityClassName | string | `"system-cluster-critical"` | | | Kubernetes.Worker.backoffLimit | int | `0` | | | Kubernetes.Worker.completions | int | `1` | | | Kubernetes.Worker.restartPolicy | string | `"Never"` | | | Kubernetes.WorkerTemplate | string | `""` | | | LocalStorage | object | `{"AllowedDirs":["./"]}` | Local file system storage configuration. | +| Logger.Plugins.Params.OidcClientId | string | `"FUNNEL_PLUGIN_OIDC_CLIENT_ID_PLACEHOLDER"` | | +| Logger.Plugins.Params.OidcClientSecret | string | `"FUNNEL_PLUGIN_OIDC_CLIENT_SECRET_PLACEHOLDER"` | | +| Logger.Plugins.Params.S3Url | string | `"FUNNEL_PLUGIN_S3URL_PLACEHOLDER"` | | +| Logger.Plugins.Path | string | `"plugin-binaries/auth-plugin"` | | +| Logger.Worker.LeaveWorkDir | bool | `true` | | | Logger.level | string | `"debug"` | | | Logger.outputFile | string | `""` | | | Node.ID | string | `""` | | @@ -94,13 +100,10 @@ A Helm chart for Kubernetes | PBS.ReconcileRate | string | `"10s"` | | | PBS.Template | string | `"#!bin/bash\n#PBS -N {{.TaskId}}\n#PBS -o {{.WorkDir}}/funnel-stdout\n#PBS -e {{.WorkDir}}/funnel-stderr\n{{if ne .Cpus 0 -}}\n{{printf \"#PBS -l nodes=1:ppn=%d\" .Cpus}}\n{{- end}}\n{{if ne .RamGb 0.0 -}}\n{{printf \"#PBS -l mem=%.0fgb\" .RamGb}}\n{{- end}}\n{{if ne .DiskGb 0.0 -}}\n{{printf \"#PBS -l file=%.0fgb\" .DiskGb}}\n{{- end}}\n\n{{.Executable}} worker run --config {{.Config}} --taskID {{.TaskId}}\n"` | | | PBS.TemplateFile | string | `""` | | -| Postgres.AdminPassword | string | `"example"` | | -| Postgres.AdminUser | string | `"postgres"` | | -| Postgres.Database | string | `"funnel"` | | -| Postgres.Host | string | `"funnel-postgresql.default.svc.cluster.local"` | | -| Postgres.Password | string | `"example"` | | -| Postgres.Timeout.duration | string | `"300s"` | | -| Postgres.User | string | `"funnel"` | | +| Postgres.Database | string | `"FUNNEL_POSTGRES_DATABASE_PLACEHOLDER"` | | +| Postgres.Host | string | `"FUNNEL_POSTGRES_HOST_PLACEHOLDER"` | | +| Postgres.Password | string | `"FUNNEL_POSTGRES_PASSWORD_PLACEHOLDER"` | | +| Postgres.User | string | `"FUNNEL_POSTGRES_USER_PLACEHOLDER"` | | | RPCClient.MaxRetries | int | `10` | | | RPCClient.ServerAddress | string | `"localhost:9090"` | | | RPCClient.Timeout.duration | string | `"60s"` | | @@ -134,51 +137,75 @@ A Helm chart for Kubernetes | cleanup.enabled | bool | `false` | | | cleanup.schedule | string | `""` | | | cleanup.scheduleOffsetMinutes | int | `0` | | -| global.aws.awsAccessKeyId | string | `nil` | | -| global.aws.awsSecretAccessKey | string | `nil` | | -| global.aws.enabled | bool | `false` | | -| global.aws.externalSecrets.enabled | bool | `false` | | -| global.aws.externalSecrets.externalSecretAwsCreds | string | `nil` | | -| global.aws.externalSecrets.pushSecret | bool | `false` | | -| global.aws.region | string | `"us-east-1"` | | -| global.dev | bool | `true` | | -| global.externalSecrets.dbCreate | bool | `false` | | -| global.externalSecrets.deploy | bool | `false` | | -| global.netPolicy.enabled | bool | `false` | | -| global.postgres.dbCreate | bool | `true` | | -| global.postgres.externalSecret | string | `""` | | -| global.postgres.master.host | string | `nil` | | -| global.postgres.master.password | string | `nil` | | -| global.postgres.master.port | string | `"5432"` | | -| global.postgres.master.username | string | `"postgres"` | | -| image.initContainers[0].command[0] | string | `"cp"` | | -| image.initContainers[0].command[1] | string | `"/app/build/plugins/authorizer"` | | -| image.initContainers[0].command[2] | string | `"/opt/funnel/plugin-binaries/auth-plugin"` | | -| image.initContainers[0].image | string | `"quay.io/ohsu-comp-bio/funnel-plugins"` | | -| image.initContainers[0].name | string | `"plugins"` | | -| image.initContainers[0].pullPolicy | string | `"Always"` | | -| image.initContainers[0].tag | string | `"pr-1"` | | -| image.initContainers[0].volumeMounts[0].mountPath | string | `"/opt/funnel/plugin-binaries"` | | -| image.initContainers[0].volumeMounts[0].name | string | `"plugin-volume"` | | -| image.pullPolicy | string | `"Always"` | | -| image.repository | string | `"quay.io/ohsu-comp-bio/funnel"` | | +| criticalService | string | `"false"` | Valid options are "true" or "false". If invalid option is set- the value will default to "false". | +| externalSecrets | map | `{"createFunnelOidcClientSecret":true,"dbcreds":"","funnelOidcClient":null}` | External Secrets settings. | +| externalSecrets.createFunnelOidcClientSecret | bool | `true` | Whether to create the Funnel OIDC client secret using the oidc job. | +| externalSecrets.dbcreds | string | `""` | Name of the secret that will be created in secrets manager | +| externalSecrets.funnelOidcClient | string | `nil` | Will override the name of the aws secrets manager secret. Default is "funnel-oidc-client". | +| global.aws.awsAccessKeyId | string | `nil` | Credentials for AWS stuff. | +| global.aws.awsSecretAccessKey | string | `nil` | Credentials for AWS stuff. | +| global.aws.enabled | bool | `false` | Set to true if deploying to AWS. Controls ingress annotations. | +| global.aws.externalSecrets.enabled | bool | `false` | Whether to use External Secrets for aws config. | +| global.aws.externalSecrets.externalSecretAwsCreds | String | `nil` | Name of Secrets Manager secret. | +| global.aws.externalSecrets.pushSecret | bool | `false` | Whether to create the database and Secrets Manager secrets via PushSecret. | +| global.aws.region | string | `"us-east-1"` | AWS region for this deployment | +| global.clusterName | string | `"default"` | | +| global.environment | string | `"default"` | | +| global.externalSecrets.clusterSecretStoreRef | string | `""` | | +| global.externalSecrets.deploy | bool | `false` | Will use ExternalSecret resources to pull secrets from Secrets Manager instead of creating them locally. Be cautious as this will override any gen3-workflow secrets you have deployed. | +| global.externalSecrets.pushFunnelOidcClientToExternalSecrets | bool | `true` | | +| global.externalSecrets.separateSecretStore | string | `false` | Will deploy a separate External Secret Store for this service. | +| global.hostname | string | `""` | Hostname for the deployment. | +| global.kubeapi_endpoints | map | `{"enabled":false,"ip":[]}` | Configuration for kubeapi endpoints if you want to allowlist specific IPs for egress instead of allowing access to the entire cluster. | +| global.netPolicy | map | `{"enabled":false}` | Network policy settings. | +| global.netPolicy.enabled | bool | `false` | Whether network policies are enabled | +| global.postgres.dbCreate | bool | `true` | Whether the database should be created. | +| global.postgres.externalSecret | string | `""` | Name of master Postgres secret in Secrets Manager. Disabled if empty | +| global.postgres.master | map | `{"host":"test","password":null,"port":"5432","username":"postgres"}` | Master credentials to postgres. This is going to be the default postgres server being used for each service, unless each service specifies their own postgres | +| global.postgres.master.host | string | `"test"` | hostname of postgres server | +| global.postgres.master.password | string | `nil` | password for superuser in postgres. This is used to create or restore databases | +| global.postgres.master.port | string | `"5432"` | Port for Postgres. | +| global.postgres.master.username | string | `"postgres"` | username of superuser in postgres. This is used to create or restore databases | +| global.topologySpread | map | `{"enabled":false,"maxSkew":1,"topologyKey":"topology.kubernetes.io/zone"}` | Karpenter topology spread configuration. | +| global.topologySpread.enabled | bool | `false` | Whether to enable topology spread constraints for all subcharts that support it. | +| global.topologySpread.maxSkew | int | `1` | The maxSkew to use for topology spread constraints. Defaults to 1. | +| global.topologySpread.topologyKey | string | `"topology.kubernetes.io/zone"` | The topology key to use for spreading. Defaults to "topology.kubernetes.io/zone". | +| image.initContainers | map | `[{"command":["cp","/app/build/plugins/authorizer","/opt/funnel/plugin-binaries/auth-plugin"],"image":"quay.io/cdis/funnel-gen3-plugin","name":"plugin","pullPolicy":"Always","tag":"main-gen3","volumeMounts":[{"mountPath":"/opt/funnel/plugin-binaries","name":"plugin-volume"}]},{"args":["-c","# Create a funnel-patched.conf since /etc/config/funnel.conf is readonly\nCONFIG=/tmp/funnel-patched.conf\ncp /etc/config/funnel.conf $CONFIG\n\nnamespace=$(cat /var/run/secrets/kubernetes.io/serviceaccount/namespace)\nJOBS_NAMESPACE=workflow-pods-$namespace\nS3_URL=gen3-workflow-service.$namespace.svc.cluster.local\nDB_HOST=$DB_HOST:5432\n\n# `Kubernetes.JobsNamespace` has to be configured manually because of templating\n# limitations. This ensures it is configured to the value that is hardcoded elsewhere.\nconfigured=$(yq -r '.Kubernetes.JobsNamespace' \"$CONFIG\")\nif [[ \"$configured\" != \"$JOBS_NAMESPACE\" ]]; then\n echo \"ERROR: funnel.Kubernetes.JobsNamespace is set to '$configured' instead of '$JOBS_NAMESPACE'. Please fix the configuration\" >&2\n exit 1\nfi\n\necho \"======= Funnel configuration =======\"\necho \" Kubernetes.JobsNamespace : $JOBS_NAMESPACE\"\necho \" Plugins.Params.OidcClientId: $FUNNEL_OIDC_CLIENT_ID\"\necho \" Plugins.Params.S3Url : $S3_URL\"\necho \" Postgres.Host : $DB_HOST\"\necho \" Postgres.Database : $DB_DATABASE\"\necho \" Postgres.User : $DB_USER\"\necho \"====================================\"\n\n# Replace placeholders with actual values (in-place)\nsed -i \"s|FUNNEL_PLUGIN_OIDC_CLIENT_ID_PLACEHOLDER|${FUNNEL_OIDC_CLIENT_ID}|g\" $CONFIG\nsed -i \"s|FUNNEL_PLUGIN_OIDC_CLIENT_SECRET_PLACEHOLDER|${FUNNEL_OIDC_CLIENT_SECRET}|g\" $CONFIG\nsed -i \"s|FUNNEL_PLUGIN_S3URL_PLACEHOLDER|${S3_URL}|g\" $CONFIG\nsed -i \"s/FUNNEL_POSTGRES_HOST_PLACEHOLDER/${DB_HOST}/g\" $CONFIG\nsed -i \"s/FUNNEL_POSTGRES_DATABASE_PLACEHOLDER/${DB_DATABASE}/g\" $CONFIG\nsed -i \"s/FUNNEL_POSTGRES_USER_PLACEHOLDER/${DB_USER}/g\" $CONFIG\nsed -i \"s/FUNNEL_POSTGRES_PASSWORD_PLACEHOLDER/${DB_PASSWORD}/g\" $CONFIG\n"],"command":["/bin/bash"],"env":[{"name":"FUNNEL_OIDC_CLIENT_ID","valueFrom":{"secretKeyRef":{"key":"client_id","name":"funnel-oidc-client","optional":false}}},{"name":"FUNNEL_OIDC_CLIENT_SECRET","valueFrom":{"secretKeyRef":{"key":"client_secret","name":"funnel-oidc-client","optional":false}}},{"name":"DB_HOST","valueFrom":{"secretKeyRef":{"key":"host","name":"funnel-dbcreds","optional":false}}},{"name":"DB_USER","valueFrom":{"secretKeyRef":{"key":"username","name":"funnel-dbcreds","optional":false}}},{"name":"DB_PASSWORD","valueFrom":{"secretKeyRef":{"key":"password","name":"funnel-dbcreds","optional":false}}},{"name":"DB_DATABASE","valueFrom":{"secretKeyRef":{"key":"database","name":"funnel-dbcreds","optional":false}}}],"image":"quay.io/cdis/awshelper","name":"config-updater","tag":"master","volumeMounts":[{"mountPath":"/tmp","name":"funnel-patched-config-volume"},{"mountPath":"/etc/config/funnel.conf","name":"funnel-config-volume","subPath":"funnel-server.yaml"}]}]` | Configuration for the Funnel init container. | +| image.initContainers[0].command | list | `["cp","/app/build/plugins/authorizer","/opt/funnel/plugin-binaries/auth-plugin"]` | Arguments to pass to the init container. | +| image.initContainers[0].image | string | `"quay.io/cdis/funnel-gen3-plugin"` | The Docker image repository for the Funnel init/plugin container. | +| image.initContainers[0].pullPolicy | string | `"Always"` | When to pull the image. This value should be "Always" to ensure the latest image is used. | +| image.initContainers[0].tag | string | `"main-gen3"` | The Docker image tag for the Funnel init/plugin container. | +| image.pullPolicy | string | `"Always"` | When to pull the image. This value should be "Always" to ensure the latest image is used. | +| image.repository | string | `"quay.io/ohsu-comp-bio/funnel"` | The Docker image repository for the Funnel service. | | labels.app | string | `"funnel"` | | -| postgres.database | string | `"funnel"` | Database name for Funnel. | -| postgres.dbCreate | bool | `nil` | Whether the database should be created. Defaults to global.postgres.dbCreate. | -| postgres.host | string | `nil` | Hostname for Postgres. Defaults to global.postgres.master.host. | -| postgres.password | string | `"example"` | Password for Postgres. Override this for production deployments. | +| metricsEnabled | bool | `false` | | +| netPolicy | map | `{"egressApps":["gen3-workflow"],"ingressApps":["gen3-workflow"]}` | Configuration for network policies created by this chart. Only relevant if "global.netPolicy.enabled" is set to true | +| netPolicy.egressApps | array | `["gen3-workflow"]` | List of apps that this app requires egress to | +| netPolicy.ingressApps | array | `["gen3-workflow"]` | List of app labels that require ingress to this service | +| oidc_job_enabled | bool | `true` | Whether to create a job to generate the OIDC client for Funnel. | +| partOf | string | `"Workflow_Execution"` | Label to help organize pods and their use. Any value is valid, but use "_" or "-" to divide words. | +| postgres | map | `{"database":null,"dbCreate":null,"dbRestore":false,"host":null,"password":null,"port":"5432","separate":false,"username":null}` | Postgres database configuration. If db does not exist in postgres cluster and dbCreate is set ot true then these databases will be created for you | +| postgres.database | string | `nil` | Database name for postgres. This is a service override, defaults to - | +| postgres.dbCreate | bool | `nil` | Whether the database should be created. Default to global.postgres.dbCreate | +| postgres.host | string | `nil` | Hostname for postgres server. This is a service override, defaults to global.postgres.host | +| postgres.password | string | `nil` | Password for Postgres. Will be autogenerated if left empty. | | postgres.port | string | `"5432"` | Port for Postgres. | -| postgres.username | string | `"funnel"` | Username for Funnel. | +| postgres.separate | string | `false` | Will create a Database for the individual service to help with developing it. | +| postgres.username | string | `nil` | Username for postgres. This is a service override, defaults to - | +| postgresql | map | `{"primary":{"persistence":{"enabled":false}}}` | Postgresql subchart settings if deployed separately option is set to "true". Disable persistence by default so we can spin up and down ephemeral environments | +| postgresql.primary.persistence.enabled | bool | `false` | Option to persist the dbs data. | | rbac.create | bool | `true` | | +| release | string | `"production"` | Valid options are "production" or "dev". If invalid option is set- the value will default to "dev". | | replicaCount | int | `1` | | | resources.limits.cpu | string | `"1000m"` | | -| resources.limits.ephemeral_storage | string | `"2048Mi"` | | -| resources.limits.memory | string | `"2048Mi"` | | +| resources.limits.ephemeral_storage | string | `"2Gi"` | | +| resources.limits.memory | string | `"2Gi"` | | | resources.requests.cpu | string | `"100m"` | | -| resources.requests.ephemeral_storage | string | `"512Mi"` | | -| resources.requests.memory | string | `"512Mi"` | | -| secrets.awsAccessKeyId | string | `nil` | | -| secrets.awsSecretAccessKey | string | `nil` | | +| resources.requests.ephemeral_storage | string | `"2Gi"` | | +| resources.requests.memory | string | `"2Gi"` | | +| secrets | map | `{"awsAccessKeyId":null,"awsSecretAccessKey":null}` | Secret information for External Secrets. | +| secrets.awsAccessKeyId | str | `nil` | AWS access key ID. Overrides global key. | +| secrets.awsSecretAccessKey | str | `nil` | AWS secret access key ID. Overrides global key. | | service.httpPort | int | `8000` | | | service.rpcPort | int | `9090` | | | service.type | string | `"ClusterIP"` | | @@ -190,11 +217,26 @@ A Helm chart for Kubernetes | storage.size | string | `"10Mi"` | | | stsRegion | string | `"us-east-1"` | | | volumeMounts[0].mountPath | string | `"/etc/config/funnel-server.yaml"` | | -| volumeMounts[0].name | string | `"funnel-server-config-volume"` | | -| volumeMounts[0].subPath | string | `"funnel-server.yaml"` | | -| volumeMounts[1].mountPath | string | `"/opt/funnel/plugin-binaries"` | | -| volumeMounts[1].name | string | `"plugin-volume"` | | +| volumeMounts[0].name | string | `"funnel-patched-config-volume"` | | +| volumeMounts[0].subPath | string | `"funnel-patched.conf"` | | +| volumeMounts[1].mountPath | string | `"/etc/config/oidc"` | | +| volumeMounts[1].name | string | `"funnel-oidc-volume"` | | +| volumeMounts[1].readOnly | bool | `true` | | +| volumeMounts[2].mountPath | string | `"/etc/funnel/templates"` | | +| volumeMounts[2].name | string | `"worker-templates-volume"` | | +| volumeMounts[3].mountPath | string | `"/opt/funnel/plugin-binaries"` | | +| volumeMounts[3].name | string | `"plugin-volume"` | | | volumes[0].configMap.name | string | `"funnel-server-config"` | | -| volumes[0].name | string | `"funnel-server-config-volume"` | | -| volumes[1].emptyDir | object | `{}` | | -| volumes[1].name | string | `"plugin-volume"` | | +| volumes[0].name | string | `"funnel-config-volume"` | | +| volumes[1].name | string | `"funnel-oidc-volume"` | | +| volumes[1].secret.items[0].key | string | `"client_id"` | | +| volumes[1].secret.items[0].path | string | `"client_id"` | | +| volumes[1].secret.items[1].key | string | `"client_secret"` | | +| volumes[1].secret.items[1].path | string | `"client_secret"` | | +| volumes[1].secret.secretName | string | `"funnel-oidc-client"` | | +| volumes[2].configMap.name | string | `"funnel-worker-templates"` | | +| volumes[2].name | string | `"worker-templates-volume"` | | +| volumes[3].emptyDir | object | `{}` | | +| volumes[3].name | string | `"plugin-volume"` | | +| volumes[4].emptyDir | object | `{}` | | +| volumes[4].name | string | `"funnel-patched-config-volume"` | | diff --git a/helm/funnel/values.yaml b/helm/funnel/values.yaml index dc7267300..04e5bea99 100644 --- a/helm/funnel/values.yaml +++ b/helm/funnel/values.yaml @@ -1,87 +1,245 @@ -# Kubernetes-specific settings -replicaCount: 1 - -# Global configuration shared with the Gen3 umbrella chart. global: - dev: true aws: + # -- (string) AWS region for this deployment region: us-east-1 + # -- (bool) Set to true if deploying to AWS. Controls ingress annotations. enabled: false + # -- (string) Credentials for AWS stuff. awsAccessKeyId: + # -- (string) Credentials for AWS stuff. awsSecretAccessKey: externalSecrets: + # -- (bool) Whether to use External Secrets for aws config. enabled: false + # -- (String) Name of Secrets Manager secret. externalSecretAwsCreds: + # -- (bool) Whether to create the database and Secrets Manager secrets via PushSecret. pushSecret: false postgres: + # -- (bool) Whether the database should be created. dbCreate: true + # -- (string) Name of master Postgres secret in Secrets Manager. Disabled if empty externalSecret: "" + # -- (map) Master credentials to postgres. This is going to be the default postgres server being used for each service, unless each service specifies their own postgres master: - host: + # -- (string) hostname of postgres server + host: "test" + # -- (string) username of superuser in postgres. This is used to create or restore databases username: postgres + # -- (string) password for superuser in postgres. This is used to create or restore databases password: + # -- (string) Port for Postgres. port: "5432" + environment: default + clusterName: default externalSecrets: + # -- (bool) Will use ExternalSecret resources to pull secrets from Secrets Manager instead of creating them locally. Be cautious as this will override any gen3-workflow secrets you have deployed. deploy: false - dbCreate: false + # -- (string) Will deploy a separate External Secret Store for this service. + separateSecretStore: false + clusterSecretStoreRef: "" + pushFunnelOidcClientToExternalSecrets: true + # -- (string) Hostname for the deployment. + hostname: "" + # -- (map) Configuration for kubeapi endpoints if you want to allowlist specific IPs for egress instead of allowing access to the entire cluster. + kubeapi_endpoints: + enabled: false + ip: [] + # -- (map) Network policy settings. netPolicy: + # -- (bool) Whether network policies are enabled enabled: false - -image: - repository: quay.io/ohsu-comp-bio/funnel - pullPolicy: Always - initContainers: - # Plugin Init Container - - name: plugins - image: quay.io/ohsu-comp-bio/funnel-plugins - tag: pr-1 - pullPolicy: Always - command: - - cp - - /app/build/plugins/authorizer - - /opt/funnel/plugin-binaries/auth-plugin - volumeMounts: - - name: plugin-volume - mountPath: /opt/funnel/plugin-binaries - -labels: - app: funnel - + # -- (map) Karpenter topology spread configuration. + topologySpread: + # -- (bool) Whether to enable topology spread constraints for all subcharts that support it. + enabled: false + # -- (string) The topology key to use for spreading. Defaults to "topology.kubernetes.io/zone". + topologyKey: "topology.kubernetes.io/zone" + # -- (int) The maxSkew to use for topology spread constraints. Defaults to 1. + maxSkew: 1 + +metricsEnabled: false + +# -- (map) External Secrets settings. +externalSecrets: + # -- (bool) Whether to create the Funnel OIDC client secret using the oidc job. + createFunnelOidcClientSecret: true + # -- (string) Will override the name of the aws secrets manager secret. Default is "funnel-oidc-client". + funnelOidcClient: + # -- (string) Name of the secret that will be created in secrets manager + dbcreds: "" + +# -- (map) Secret information for External Secrets. secrets: + # -- (str) AWS access key ID. Overrides global key. awsAccessKeyId: + # -- (str) AWS secret access key ID. Overrides global key. awsSecretAccessKey: -# Funnel is configured to use Gen3-managed PostgreSQL. The previous MongoDB -# chart dependency was removed because MongoDB appears unused in this deployment -# path; runtime PostgreSQL connectivity should be validated in-cluster. +# -- (map) Postgres database configuration. If db does not exist in postgres cluster and dbCreate is set ot true then these databases will be created for you postgres: - # -- (bool) Whether the database should be created. Defaults to global.postgres.dbCreate. + # (bool) Whether the database should be restored from s3. Default to global.postgres.dbRestore + dbRestore: false + # -- (bool) Whether the database should be created. Default to global.postgres.dbCreate dbCreate: - # -- (string) Hostname for Postgres. Defaults to global.postgres.master.host. + # -- (string) Hostname for postgres server. This is a service override, defaults to global.postgres.host host: - # -- (string) Database name for Funnel. - database: funnel - # -- (string) Username for Funnel. - username: funnel + # -- (string) Database name for postgres. This is a service override, defaults to - + database: + # -- (string) Username for postgres. This is a service override, defaults to - + username: # -- (string) Port for Postgres. port: "5432" - # -- (string) Password for Postgres. Override this for production deployments. - password: example + # -- (string) Password for Postgres. Will be autogenerated if left empty. + password: + # -- (string) Will create a Database for the individual service to help with developing it. + separate: false + +# -- (map) Postgresql subchart settings if deployed separately option is set to "true". +# Disable persistence by default so we can spin up and down ephemeral environments +postgresql: + primary: + persistence: + # -- (bool) Option to persist the dbs data. + enabled: false + +# -- (map) Configuration for network policies created by this chart. Only relevant if "global.netPolicy.enabled" is set to true +netPolicy: + # -- (array) List of app labels that require ingress to this service + ingressApps: + - gen3-workflow + # -- (array) List of apps that this app requires egress to + egressApps: + - gen3-workflow + +# Kubernetes-specific settings +replicaCount: 1 + +# Values to determine the labels that are used for the deployment, pod, etc. +# -- (string) Valid options are "production" or "dev". If invalid option is set- the value will default to "dev". +release: "production" +# -- (string) Valid options are "true" or "false". If invalid option is set- the value will default to "false". +criticalService: "false" +# -- (string) Label to help organize pods and their use. Any value is valid, but use "_" or "-" to divide words. +partOf: "Workflow_Execution" + +# -- (bool) Whether to create a job to generate the OIDC client for Funnel. +oidc_job_enabled: true +image: + # -- (string) The Docker image repository for the Funnel service. + repository: quay.io/ohsu-comp-bio/funnel + # -- (string) When to pull the image. This value should be "Always" to ensure the latest image is used. + pullPolicy: Always + + # -- (map) Configuration for the Funnel init container. + initContainers: + - name: plugin + # -- (string) The Docker image repository for the Funnel init/plugin container. + image: quay.io/cdis/funnel-gen3-plugin + # -- (string) The Docker image tag for the Funnel init/plugin container. + tag: main-gen3 + # -- (string) When to pull the image. This value should be "Always" to ensure the latest image is used. + pullPolicy: Always + # -- (list) Arguments to pass to the init container. + command: + - cp + - /app/build/plugins/authorizer + - /opt/funnel/plugin-binaries/auth-plugin + volumeMounts: + - name: plugin-volume + mountPath: /opt/funnel/plugin-binaries + - name: config-updater + image: quay.io/cdis/awshelper + tag: master + env: + - name: FUNNEL_OIDC_CLIENT_ID + valueFrom: + secretKeyRef: + name: funnel-oidc-client + key: client_id + optional: false + - name: FUNNEL_OIDC_CLIENT_SECRET + valueFrom: + secretKeyRef: + name: funnel-oidc-client + key: client_secret + optional: false + - name: DB_HOST + valueFrom: + secretKeyRef: + name: funnel-dbcreds + key: host + optional: false + - name: DB_USER + valueFrom: + secretKeyRef: + name: funnel-dbcreds + key: username + optional: false + - name: DB_PASSWORD + valueFrom: + secretKeyRef: + name: funnel-dbcreds + key: password + optional: false + - name: DB_DATABASE + valueFrom: + secretKeyRef: + name: funnel-dbcreds + key: database + optional: false + volumeMounts: + - name: funnel-patched-config-volume + mountPath: /tmp + - name: funnel-config-volume + mountPath: /etc/config/funnel.conf + subPath: funnel-server.yaml + command: ["/bin/bash"] + args: + - "-c" + - | + # Create a funnel-patched.conf since /etc/config/funnel.conf is readonly + CONFIG=/tmp/funnel-patched.conf + cp /etc/config/funnel.conf $CONFIG + + namespace=$(cat /var/run/secrets/kubernetes.io/serviceaccount/namespace) + JOBS_NAMESPACE=workflow-pods-$namespace + S3_URL=gen3-workflow-service.$namespace.svc.cluster.local + DB_HOST=$DB_HOST:5432 + + # `Kubernetes.JobsNamespace` has to be configured manually because of templating + # limitations. This ensures it is configured to the value that is hardcoded elsewhere. + configured=$(yq -r '.Kubernetes.JobsNamespace' "$CONFIG") + if [[ "$configured" != "$JOBS_NAMESPACE" ]]; then + echo "ERROR: funnel.Kubernetes.JobsNamespace is set to '$configured' instead of '$JOBS_NAMESPACE'. Please fix the configuration" >&2 + exit 1 + fi + + echo "======= Funnel configuration =======" + echo " Kubernetes.JobsNamespace : $JOBS_NAMESPACE" + echo " Plugins.Params.OidcClientId: $FUNNEL_OIDC_CLIENT_ID" + echo " Plugins.Params.S3Url : $S3_URL" + echo " Postgres.Host : $DB_HOST" + echo " Postgres.Database : $DB_DATABASE" + echo " Postgres.User : $DB_USER" + echo "====================================" + + # Replace placeholders with actual values (in-place) + sed -i "s|FUNNEL_PLUGIN_OIDC_CLIENT_ID_PLACEHOLDER|${FUNNEL_OIDC_CLIENT_ID}|g" $CONFIG + sed -i "s|FUNNEL_PLUGIN_OIDC_CLIENT_SECRET_PLACEHOLDER|${FUNNEL_OIDC_CLIENT_SECRET}|g" $CONFIG + sed -i "s|FUNNEL_PLUGIN_S3URL_PLACEHOLDER|${S3_URL}|g" $CONFIG + sed -i "s/FUNNEL_POSTGRES_HOST_PLACEHOLDER/${DB_HOST}/g" $CONFIG + sed -i "s/FUNNEL_POSTGRES_DATABASE_PLACEHOLDER/${DB_DATABASE}/g" $CONFIG + sed -i "s/FUNNEL_POSTGRES_USER_PLACEHOLDER/${DB_USER}/g" $CONFIG + sed -i "s/FUNNEL_POSTGRES_PASSWORD_PLACEHOLDER/${DB_PASSWORD}/g" $CONFIG + + +labels: + app: funnel rbac: create: true -# Resource Requests/Limits for worker jobs and server pods. -resources: - requests: - cpu: 100m - memory: 512Mi - ephemeral_storage: 512Mi - limits: - cpu: 1000m - memory: 2048Mi - ephemeral_storage: 2048Mi - # AWS STS Source + Region for S3 CSI Driver authenticationSource: pod stsRegion: us-east-1 @@ -107,25 +265,236 @@ storage: # # - Ref: https://github.com/ohsu-comp-bio/funnel/blob/master/config/default-config.yaml -# The name of the active server database backend -# Available backends: boltdb, badger, datastore, dynamodb, elastic, mongodb, postgres -Database: postgres - # The name of the active compute backend # Available backends: local, htcondor, slurm, pbs, gridengine, manual, aws-batch, kubernetes Compute: kubernetes + +# Overrides the default volumes configured in the server deployment. +# If custom volumes are specified, they will fully replace the default values. +volumes: + - name: funnel-config-volume + configMap: + name: funnel-server-config + - name: funnel-oidc-volume + secret: + secretName: "funnel-oidc-client" + items: + - key: client_id + path: client_id + - key: client_secret + path: client_secret + + - name: worker-templates-volume + configMap: + name: funnel-worker-templates + + - name: plugin-volume + emptyDir: {} # Shared volume + + - name: funnel-patched-config-volume + emptyDir: {} # Shared volume for config data + +# Overrides the default volumesMounts configured in the server deployment. +# If custom volumesMounts are specified, they will fully replace the default values. +volumeMounts: + - name: funnel-patched-config-volume + mountPath: /etc/config/funnel-server.yaml + subPath: funnel-patched.conf + + - name: "funnel-oidc-volume" + readOnly: true + mountPath: "/etc/config/oidc" + + - name: worker-templates-volume + mountPath: /etc/funnel/templates + + - name: plugin-volume + mountPath: /opt/funnel/plugin-binaries + +# Resource Requests/Limits for worker jobs and server pods. +resources: + requests: + cpu: 100m + memory: "2Gi" + ephemeral_storage: "2Gi" + limits: + cpu: 1000m + memory: "2Gi" + ephemeral_storage: "2Gi" + +# The name of the active server database backend +# Available backends: boltdb, badger, datastore, dynamodb, elastic, mongodb, postgres +Database: postgres # The name of the active event writer backend(s). # Available backends: log, boltdb, badger, datastore, dynamodb, elastic, mongodb, postgres, kafka EventWriters: - postgres - log - +Postgres: + Host: FUNNEL_POSTGRES_HOST_PLACEHOLDER + Database: FUNNEL_POSTGRES_DATABASE_PLACEHOLDER + User: FUNNEL_POSTGRES_USER_PLACEHOLDER + Password: FUNNEL_POSTGRES_PASSWORD_PLACEHOLDER Logger: # Logging levels: debug, info, error level: debug # Write logs to this path. If empty, logs are written to stderr. outputFile: "" + Plugins: + Path: plugin-binaries/auth-plugin + Params: + OidcClientId: FUNNEL_PLUGIN_OIDC_CLIENT_ID_PLACEHOLDER + OidcClientSecret: FUNNEL_PLUGIN_OIDC_CLIENT_SECRET_PLACEHOLDER + S3Url: FUNNEL_PLUGIN_S3URL_PLACEHOLDER + Worker: + # This lets mount-s3 pods unmount and Complete. https://ctds-planx.atlassian.net/browse/MIDRC-1214 + LeaveWorkDir: true + +# Kubernetes describes the configuration for the Kubernetes compute backend. +Kubernetes: + # Timeout for task creation (worker pod creation). On timeout, tasks fail with SYSTEM_ERROR + Timeout: + duration: 300s + ReconcileRate: 120s + Executor: + PriorityClassName: "" + restartPolicy: Never + # Setting backoffLimit to 0 means no retries. + backoffLimit: 0 + Annotations: + karpenter.sh/do-not-disrupt: "true" + # Setting completions to 1 means the job completes after one successful execution. + completions: 1 + + Worker: + + restartPolicy: Never + backoffLimit: 0 + completions: 1 + Annotations: + karpenter.sh/do-not-disrupt: "true" + # When a new node is ready, worker pods may start before system-level pods do. This ensures + # worker pods are not preempted by new system-level pods on that node. + PriorityClassName: "system-cluster-critical" + + # Turn off task state reconciler. When enabled, Funnel communicates with Kubernetes + # to find tasks that are stuck in a queued state or errored and + # updates the task state accordingly. + DisableReconciler: false + DisableJobCleanup: false + # -- Path prefixes that Funnel's Kubernetes backend must reject when creating worker pods. + ForbiddenPathPrefixes: [] + # ReconcileRate is how often the compute backend compares states in Funnel's backend + # to those reported by the backend + # Kubernetes Namespace to spawn jobs within + Namespace: "" + # Kubernetes Namespace to spawn jobs within + JobsNamespace: "" + # Kubernetes ServiceAccount to use for the job + ServiceAccount: "" + + # Master batch job template. See: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.17/#job-v1-batch + WorkerTemplate: "" + # NodeSelector (scheduling) + NodeSelector: {} + # Tolerations (scheduling) + Tolerations: [] + + # Job template used for executing the tasks. + ExecutorTemplate: "" + PVTemplate: "" + PVCTemplate: "" + + Resources: + Defaults: + Cpus: 1000m + RamGb: 512Mi + DiskGb: 512Mi + Limits: + Cpus: 8000m + RamGb: 4096Mi + DiskGb: 4096Mi + +# cleanup configures an optional CronJob that runs `funnel kubernetes cleanup` +# to delete orphaned Funnel-managed Kubernetes resources. It is intentionally +# turned off by default; set cleanup.enabled=true to enable it. +cleanup: + enabled: false + # Leave empty to derive the schedule from Kubernetes.ReconcileRate. Set a + # standard 5-field cron expression to override, e.g. "*/15 * * * *". + schedule: "" + # Offset the start minute so cleanup jobs in different namespaces do not all + # fire at the same instant. Must be 0-59. + scheduleOffsetMinutes: 0 + +# ------------------------------------------------------------------------------- +# Storage +# ------------------------------------------------------------------------------- + +# If possible, credentials will be automatically discovered +# from the environment. + +# -- Local file system storage configuration. +LocalStorage: + # Whitelist of local directory paths which Funnel is allowed to access. + AllowedDirs: + - ./ + +# HTTPStorage is used to download public files on the web via a GET request. +HTTPStorage: + # Timeout for http(s) GET requests. + Timeout: 30s + +AmazonS3: + Disabled: false + # The maximum number of times that a request will be retried for failures. + AWSConfig: + MaxRetries: 10 + # AWS Access key ID + Key: "" + # AWS Secret Access Key + Secret: "" + # Server Side Encryption (SSE) settings + SSE: + # Customer Provided Key + # ref: https://docs.aws.amazon.com/AmazonS3/latest/userguide/ServerSideEncryptionCustomerKeys.html + CustomerKeyFile: "" + # KMS Key + # ref: https://docs.aws.amazon.com/AmazonS3/latest/userguide/UsingKMSEncryption.html + KMSKey: "" + +# Configure storage backends for S3 providers such as Minio and/or Ceph +# GenericS3: +# - Disabled: true +# Endpoint: "" +# Key: "" +# Secret: "" +# KmsKeyID: "" + +GoogleStorage: + Disabled: false + # Path to account credentials file. + # Optional. If possible, credentials will be automatically discovered + # from the environment. + CredentialsFile: "" +# Available backends: local, htcondor, slurm, pbs, gridengine, manual, aws-batch, kubernetes/Kube +Swift: + Disabled: false + UserName: "" + Password: "" + AuthURL: "" + TenantName: "" + TenantID: "" + RegionName: "" + # 500 MB + ChunkSizeBytes: 500000000 + +FTPStorage: + Disabled: false + Timeout: 10s + User: "anonymous" + Password: "anonymous" Server: # Hostname of the Funnel server. @@ -265,13 +634,6 @@ Datastore: # from the environment. CredentialsFile: "" -Postgres: - Host: funnel-postgresql.default.svc.cluster.local - Database: funnel - User: funnel - Password: example - AdminUser: postgres - AdminPassword: example Timeout: duration: 300s @@ -403,161 +765,3 @@ AWSBatch: Region: "" Key: "" Secret: "" - -# Kubernetes describes the configuration for the Kubernetes compute backend. -Kubernetes: - Executor: - Annotations: {} - PriorityClassName: "" - restartPolicy: OnFailure - # Setting backoffLimit to 0 means no retries. - backoffLimit: 0 - # Setting completions to 1 means the job completes after one successful execution. - completions: 1 - - Worker: - Annotations: {} - PriorityClassName: "" - restartPolicy: Never - backoffLimit: 0 - completions: 1 - - # Turn off task state reconciler. When enabled, Funnel communicates with Kubernetes - # to find tasks that are stuck in a queued state or errored and - # updates the task state accordingly. - DisableReconciler: false - DisableJobCleanup: false - # -- Path prefixes that Funnel's Kubernetes backend must reject when creating worker pods. - ForbiddenPathPrefixes: [] - # ReconcileRate is how often the compute backend compares states in Funnel's backend - # to those reported by the backend - ReconcileRate: 10s - # Kubernetes Namespace to spawn jobs within - Namespace: "" - # Kubernetes Namespace to spawn jobs within - JobsNamespace: "" - # Kubernetes ServiceAccount to use for the job - ServiceAccount: "" - Timeout: - duration: 30s - # Master batch job template. See: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.17/#job-v1-batch - WorkerTemplate: "" - # NodeSelector (scheduling) - NodeSelector: {} - # Tolerations (scheduling) - Tolerations: [] - - # Job template used for executing the tasks. - ExecutorTemplate: "" - PVTemplate: "" - PVCTemplate: "" - - Resources: - Defaults: - Cpus: 1000m - RamGb: 512Mi - DiskGb: 512Mi - Limits: - Cpus: 8000m - RamGb: 4096Mi - DiskGb: 4096Mi - -# cleanup configures an optional CronJob that runs `funnel kubernetes cleanup` -# to delete orphaned Funnel-managed Kubernetes resources. It is intentionally -# turned off by default; set cleanup.enabled=true to enable it. -cleanup: - enabled: false - # Leave empty to derive the schedule from Kubernetes.ReconcileRate. Set a - # standard 5-field cron expression to override, e.g. "*/15 * * * *". - schedule: "" - # Offset the start minute so cleanup jobs in different namespaces do not all - # fire at the same instant. Must be 0-59. - scheduleOffsetMinutes: 0 - -# ------------------------------------------------------------------------------- -# Storage -# ------------------------------------------------------------------------------- - -# If possible, credentials will be automatically discovered -# from the environment. - -# -- Local file system storage configuration. -LocalStorage: - # Whitelist of local directory paths which Funnel is allowed to access. - AllowedDirs: - - ./ - -# HTTPStorage is used to download public files on the web via a GET request. -HTTPStorage: - # Timeout for http(s) GET requests. - Timeout: 30s - -AmazonS3: - Disabled: false - # The maximum number of times that a request will be retried for failures. - AWSConfig: - MaxRetries: 10 - # AWS Access key ID - Key: "" - # AWS Secret Access Key - Secret: "" - # Server Side Encryption (SSE) settings - SSE: - # Customer Provided Key - # ref: https://docs.aws.amazon.com/AmazonS3/latest/userguide/ServerSideEncryptionCustomerKeys.html - CustomerKeyFile: "" - # KMS Key - # ref: https://docs.aws.amazon.com/AmazonS3/latest/userguide/UsingKMSEncryption.html - KMSKey: "" - -# Configure storage backends for S3 providers such as Minio and/or Ceph -# GenericS3: -# - Disabled: true -# Endpoint: "" -# Key: "" -# Secret: "" -# KmsKeyID: "" - -GoogleStorage: - Disabled: false - # Path to account credentials file. - # Optional. If possible, credentials will be automatically discovered - # from the environment. - CredentialsFile: "" -# Available backends: local, htcondor, slurm, pbs, gridengine, manual, aws-batch, kubernetes/Kube -Swift: - Disabled: false - UserName: "" - Password: "" - AuthURL: "" - TenantName: "" - TenantID: "" - RegionName: "" - # 500 MB - ChunkSizeBytes: 500000000 - -FTPStorage: - Disabled: false - Timeout: 10s - User: "anonymous" - Password: "anonymous" - -# Overrides the default volumes configured in the server deployment. -# If custom volumes are specified, they will fully replace the default values. -volumes: - - name: funnel-server-config-volume - configMap: - name: funnel-server-config - - - name: plugin-volume - emptyDir: {} # Shared volume - -# Overrides the default volumesMounts configured in the server deployment. -# If custom volumesMounts are specified, they will fully replace the default values. -volumeMounts: - - name: funnel-server-config-volume - mountPath: /etc/config/funnel-server.yaml - subPath: funnel-server.yaml - - - name: plugin-volume - mountPath: /opt/funnel/plugin-binaries From 00a873107b82c27b2ab6752bdb771e51a4efefe5 Mon Sep 17 00:00:00 2001 From: Sai Shanmukha Date: Wed, 8 Jul 2026 12:11:23 -0500 Subject: [PATCH 070/196] Fix helm values error + indentation --- helm/funnel/README.md | 3 + helm/funnel/values.yaml | 216 ++++++++++++++++++++-------------------- helm/gen3/Chart.yaml | 2 +- helm/gen3/README.md | 2 +- 4 files changed, 115 insertions(+), 108 deletions(-) diff --git a/helm/funnel/README.md b/helm/funnel/README.md index 699695ebf..0e031cad1 100644 --- a/helm/funnel/README.md +++ b/helm/funnel/README.md @@ -100,9 +100,12 @@ A Helm chart for Kubernetes | PBS.ReconcileRate | string | `"10s"` | | | PBS.Template | string | `"#!bin/bash\n#PBS -N {{.TaskId}}\n#PBS -o {{.WorkDir}}/funnel-stdout\n#PBS -e {{.WorkDir}}/funnel-stderr\n{{if ne .Cpus 0 -}}\n{{printf \"#PBS -l nodes=1:ppn=%d\" .Cpus}}\n{{- end}}\n{{if ne .RamGb 0.0 -}}\n{{printf \"#PBS -l mem=%.0fgb\" .RamGb}}\n{{- end}}\n{{if ne .DiskGb 0.0 -}}\n{{printf \"#PBS -l file=%.0fgb\" .DiskGb}}\n{{- end}}\n\n{{.Executable}} worker run --config {{.Config}} --taskID {{.TaskId}}\n"` | | | PBS.TemplateFile | string | `""` | | +| Postgres.AdminPassword | string | `"example"` | | +| Postgres.AdminUser | string | `"postgres"` | | | Postgres.Database | string | `"FUNNEL_POSTGRES_DATABASE_PLACEHOLDER"` | | | Postgres.Host | string | `"FUNNEL_POSTGRES_HOST_PLACEHOLDER"` | | | Postgres.Password | string | `"FUNNEL_POSTGRES_PASSWORD_PLACEHOLDER"` | | +| Postgres.Timeout.duration | string | `"300s"` | | | Postgres.User | string | `"FUNNEL_POSTGRES_USER_PLACEHOLDER"` | | | RPCClient.MaxRetries | int | `10` | | | RPCClient.ServerAddress | string | `"localhost:9090"` | | diff --git a/helm/funnel/values.yaml b/helm/funnel/values.yaml index 04e5bea99..bc2837836 100644 --- a/helm/funnel/values.yaml +++ b/helm/funnel/values.yaml @@ -126,112 +126,112 @@ partOf: "Workflow_Execution" # -- (bool) Whether to create a job to generate the OIDC client for Funnel. oidc_job_enabled: true image: - # -- (string) The Docker image repository for the Funnel service. - repository: quay.io/ohsu-comp-bio/funnel - # -- (string) When to pull the image. This value should be "Always" to ensure the latest image is used. - pullPolicy: Always - - # -- (map) Configuration for the Funnel init container. - initContainers: - - name: plugin - # -- (string) The Docker image repository for the Funnel init/plugin container. - image: quay.io/cdis/funnel-gen3-plugin - # -- (string) The Docker image tag for the Funnel init/plugin container. - tag: main-gen3 - # -- (string) When to pull the image. This value should be "Always" to ensure the latest image is used. - pullPolicy: Always - # -- (list) Arguments to pass to the init container. - command: - - cp - - /app/build/plugins/authorizer - - /opt/funnel/plugin-binaries/auth-plugin - volumeMounts: - - name: plugin-volume - mountPath: /opt/funnel/plugin-binaries - - name: config-updater - image: quay.io/cdis/awshelper - tag: master - env: - - name: FUNNEL_OIDC_CLIENT_ID - valueFrom: - secretKeyRef: - name: funnel-oidc-client - key: client_id - optional: false - - name: FUNNEL_OIDC_CLIENT_SECRET - valueFrom: - secretKeyRef: - name: funnel-oidc-client - key: client_secret - optional: false - - name: DB_HOST - valueFrom: - secretKeyRef: - name: funnel-dbcreds - key: host - optional: false - - name: DB_USER - valueFrom: - secretKeyRef: - name: funnel-dbcreds - key: username - optional: false - - name: DB_PASSWORD - valueFrom: - secretKeyRef: - name: funnel-dbcreds - key: password - optional: false - - name: DB_DATABASE - valueFrom: - secretKeyRef: - name: funnel-dbcreds - key: database - optional: false - volumeMounts: - - name: funnel-patched-config-volume - mountPath: /tmp - - name: funnel-config-volume - mountPath: /etc/config/funnel.conf - subPath: funnel-server.yaml - command: ["/bin/bash"] - args: - - "-c" - - | - # Create a funnel-patched.conf since /etc/config/funnel.conf is readonly - CONFIG=/tmp/funnel-patched.conf - cp /etc/config/funnel.conf $CONFIG - - namespace=$(cat /var/run/secrets/kubernetes.io/serviceaccount/namespace) - JOBS_NAMESPACE=workflow-pods-$namespace - S3_URL=gen3-workflow-service.$namespace.svc.cluster.local - DB_HOST=$DB_HOST:5432 - - # `Kubernetes.JobsNamespace` has to be configured manually because of templating - # limitations. This ensures it is configured to the value that is hardcoded elsewhere. - configured=$(yq -r '.Kubernetes.JobsNamespace' "$CONFIG") - if [[ "$configured" != "$JOBS_NAMESPACE" ]]; then - echo "ERROR: funnel.Kubernetes.JobsNamespace is set to '$configured' instead of '$JOBS_NAMESPACE'. Please fix the configuration" >&2 - exit 1 - fi - - echo "======= Funnel configuration =======" - echo " Kubernetes.JobsNamespace : $JOBS_NAMESPACE" - echo " Plugins.Params.OidcClientId: $FUNNEL_OIDC_CLIENT_ID" - echo " Plugins.Params.S3Url : $S3_URL" - echo " Postgres.Host : $DB_HOST" - echo " Postgres.Database : $DB_DATABASE" - echo " Postgres.User : $DB_USER" - echo "====================================" - - # Replace placeholders with actual values (in-place) - sed -i "s|FUNNEL_PLUGIN_OIDC_CLIENT_ID_PLACEHOLDER|${FUNNEL_OIDC_CLIENT_ID}|g" $CONFIG - sed -i "s|FUNNEL_PLUGIN_OIDC_CLIENT_SECRET_PLACEHOLDER|${FUNNEL_OIDC_CLIENT_SECRET}|g" $CONFIG - sed -i "s|FUNNEL_PLUGIN_S3URL_PLACEHOLDER|${S3_URL}|g" $CONFIG - sed -i "s/FUNNEL_POSTGRES_HOST_PLACEHOLDER/${DB_HOST}/g" $CONFIG - sed -i "s/FUNNEL_POSTGRES_DATABASE_PLACEHOLDER/${DB_DATABASE}/g" $CONFIG - sed -i "s/FUNNEL_POSTGRES_USER_PLACEHOLDER/${DB_USER}/g" $CONFIG - sed -i "s/FUNNEL_POSTGRES_PASSWORD_PLACEHOLDER/${DB_PASSWORD}/g" $CONFIG + # -- (string) The Docker image repository for the Funnel service. + repository: quay.io/ohsu-comp-bio/funnel + # -- (string) When to pull the image. This value should be "Always" to ensure the latest image is used. + pullPolicy: Always + + # -- (map) Configuration for the Funnel init container. + initContainers: + - name: plugin + # -- (string) The Docker image repository for the Funnel init/plugin container. + image: quay.io/cdis/funnel-gen3-plugin + # -- (string) The Docker image tag for the Funnel init/plugin container. + tag: main-gen3 + # -- (string) When to pull the image. This value should be "Always" to ensure the latest image is used. + pullPolicy: Always + # -- (list) Arguments to pass to the init container. + command: + - cp + - /app/build/plugins/authorizer + - /opt/funnel/plugin-binaries/auth-plugin + volumeMounts: + - name: plugin-volume + mountPath: /opt/funnel/plugin-binaries + - name: config-updater + image: quay.io/cdis/awshelper + tag: master + env: + - name: FUNNEL_OIDC_CLIENT_ID + valueFrom: + secretKeyRef: + name: funnel-oidc-client + key: client_id + optional: false + - name: FUNNEL_OIDC_CLIENT_SECRET + valueFrom: + secretKeyRef: + name: funnel-oidc-client + key: client_secret + optional: false + - name: DB_HOST + valueFrom: + secretKeyRef: + name: funnel-dbcreds + key: host + optional: false + - name: DB_USER + valueFrom: + secretKeyRef: + name: funnel-dbcreds + key: username + optional: false + - name: DB_PASSWORD + valueFrom: + secretKeyRef: + name: funnel-dbcreds + key: password + optional: false + - name: DB_DATABASE + valueFrom: + secretKeyRef: + name: funnel-dbcreds + key: database + optional: false + volumeMounts: + - name: funnel-patched-config-volume + mountPath: /tmp + - name: funnel-config-volume + mountPath: /etc/config/funnel.conf + subPath: funnel-server.yaml + command: ["/bin/bash"] + args: + - "-c" + - | + # Create a funnel-patched.conf since /etc/config/funnel.conf is readonly + CONFIG=/tmp/funnel-patched.conf + cp /etc/config/funnel.conf $CONFIG + + namespace=$(cat /var/run/secrets/kubernetes.io/serviceaccount/namespace) + JOBS_NAMESPACE=workflow-pods-$namespace + S3_URL=gen3-workflow-service.$namespace.svc.cluster.local + DB_HOST=$DB_HOST:5432 + + # `Kubernetes.JobsNamespace` has to be configured manually because of templating + # limitations. This ensures it is configured to the value that is hardcoded elsewhere. + configured=$(yq -r '.Kubernetes.JobsNamespace' "$CONFIG") + if [[ "$configured" != "$JOBS_NAMESPACE" ]]; then + echo "ERROR: funnel.Kubernetes.JobsNamespace is set to '$configured' instead of '$JOBS_NAMESPACE'. Please fix the configuration" >&2 + exit 1 + fi + + echo "======= Funnel configuration =======" + echo " Kubernetes.JobsNamespace : $JOBS_NAMESPACE" + echo " Plugins.Params.OidcClientId: $FUNNEL_OIDC_CLIENT_ID" + echo " Plugins.Params.S3Url : $S3_URL" + echo " Postgres.Host : $DB_HOST" + echo " Postgres.Database : $DB_DATABASE" + echo " Postgres.User : $DB_USER" + echo "====================================" + + # Replace placeholders with actual values (in-place) + sed -i "s|FUNNEL_PLUGIN_OIDC_CLIENT_ID_PLACEHOLDER|${FUNNEL_OIDC_CLIENT_ID}|g" $CONFIG + sed -i "s|FUNNEL_PLUGIN_OIDC_CLIENT_SECRET_PLACEHOLDER|${FUNNEL_OIDC_CLIENT_SECRET}|g" $CONFIG + sed -i "s|FUNNEL_PLUGIN_S3URL_PLACEHOLDER|${S3_URL}|g" $CONFIG + sed -i "s/FUNNEL_POSTGRES_HOST_PLACEHOLDER/${DB_HOST}/g" $CONFIG + sed -i "s/FUNNEL_POSTGRES_DATABASE_PLACEHOLDER/${DB_DATABASE}/g" $CONFIG + sed -i "s/FUNNEL_POSTGRES_USER_PLACEHOLDER/${DB_USER}/g" $CONFIG + sed -i "s/FUNNEL_POSTGRES_PASSWORD_PLACEHOLDER/${DB_PASSWORD}/g" $CONFIG labels: @@ -336,6 +336,10 @@ Postgres: Database: FUNNEL_POSTGRES_DATABASE_PLACEHOLDER User: FUNNEL_POSTGRES_USER_PLACEHOLDER Password: FUNNEL_POSTGRES_PASSWORD_PLACEHOLDER + AdminUser: postgres + AdminPassword: example + Timeout: + duration: 300s Logger: # Logging levels: debug, info, error level: debug diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index d922ad155..31da14be7 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -197,7 +197,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.60 +version: 0.3.61 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index 960496337..d404869df 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,6 +1,6 @@ # gen3 -![Version: 0.3.60](https://img.shields.io/badge/Version-0.3.60-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.3.61](https://img.shields.io/badge/Version-0.3.61-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons From ca6b1786c6426ddf6c78d8d10a356e6b3c277e37 Mon Sep 17 00:00:00 2001 From: Sai Shanmukha Date: Wed, 8 Jul 2026 13:35:08 -0500 Subject: [PATCH 071/196] Set TEST_REPO_BRANCH to `chore/fix_setup_script_for_funnel` in integration tests --- .github/workflows/integration_tests.yaml | 1 + 1 file changed, 1 insertion(+) diff --git a/.github/workflows/integration_tests.yaml b/.github/workflows/integration_tests.yaml index c327cecdf..eca7c3d59 100644 --- a/.github/workflows/integration_tests.yaml +++ b/.github/workflows/integration_tests.yaml @@ -8,6 +8,7 @@ jobs: uses: uc-cdis/.github/.github/workflows/integration_tests.yaml@master with: HELM_BRANCH: ${{ github.event.pull_request.head.ref }} + TEST_REPO_BRANCH: chore/fix_setup_script_for_funnel secrets: CI_TEST_ORCID_USERID: ${{ secrets.CI_TEST_ORCID_USERID }} CI_TEST_ORCID_PASSWORD: ${{ secrets.CI_TEST_ORCID_PASSWORD }} From 58e8632ce9c037bc52e996eac8440f26289ffff6 Mon Sep 17 00:00:00 2001 From: Mingfei Shao Date: Wed, 8 Jul 2026 14:31:47 -0500 Subject: [PATCH 072/196] upadte external secret ref --- helm/zendesk-wrapper/templates/_helpers.tpl | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/helm/zendesk-wrapper/templates/_helpers.tpl b/helm/zendesk-wrapper/templates/_helpers.tpl index e82a1cec2..557d987d6 100644 --- a/helm/zendesk-wrapper/templates/_helpers.tpl +++ b/helm/zendesk-wrapper/templates/_helpers.tpl @@ -52,4 +52,11 @@ Selector labels {{- else }} {{- (include "common.selectorLabels" .)}} {{- end }} + +{{/* + Zendesk Wrapper Secrets Manager Name +*/}} +{{- define "zendesk-wrapper-secret" -}} +{{- default "zendesk-wrapper-secret" .Values.externalSecrets.name }} +{{- end }} {{- end }} From 7aee14d3ea42ab66fbd77fe247eaf0db68b559e0 Mon Sep 17 00:00:00 2001 From: mark xiao Date: Wed, 8 Jul 2026 14:50:38 -0500 Subject: [PATCH 073/196] update fence config --- helm/fence/Chart.yaml | 2 +- helm/fence/README.md | 4 ++-- helm/fence/values.yaml | 13 +++++++++++++ helm/gen3/Chart.yaml | 2 +- helm/gen3/README.md | 2 +- 5 files changed, 18 insertions(+), 5 deletions(-) diff --git a/helm/fence/Chart.yaml b/helm/fence/Chart.yaml index b544257f8..4ddc7e484 100644 --- a/helm/fence/Chart.yaml +++ b/helm/fence/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.77 +version: 0.1.78 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/fence/README.md b/helm/fence/README.md index b74809cbd..670a21bed 100644 --- a/helm/fence/README.md +++ b/helm/fence/README.md @@ -1,6 +1,6 @@ # fence -![Version: 0.1.77](https://img.shields.io/badge/Version-0.1.77-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.78](https://img.shields.io/badge/Version-0.1.78-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Fence @@ -15,7 +15,7 @@ A Helm chart for gen3 Fence | Key | Type | Default | Description | |-----|------|---------|-------------| -| FENCE_CONFIG | map | `{"ACCESS_TOKEN_COOKIE_NAME":"access_token","ACCESS_TOKEN_EXPIRES_IN":1200,"ALLOWED_USER_SERVICE_ACCOUNT_DOMAINS":["developer.gserviceaccount.com","appspot.gserviceaccount.com","iam.gserviceaccount.com"],"ALLOW_GOOGLE_LINKING":true,"ALLOW_NEW_USER_ON_LOGIN":true,"APPLICATION_ROOT":"/user","APP_NAME":"Gen3 Data Commons","ARBORIST":"http://arborist-service","ASSUME_ROLE_CACHE_SECONDS":1800,"AUDIT_SERVICE":"http://audit-service","AUTHLIB_INSECURE_TRANSPORT":true,"AWS_CREDENTIALS":{},"AZ_BLOB_CONTAINER_URL":"https://myfakeblob.blob.core.windows.net/my-fake-container/","AZ_BLOB_CREDENTIALS":null,"BILLING_PROJECT_FOR_SA_CREDS":null,"BILLING_PROJECT_FOR_SIGNED_URLS":null,"CIRRUS_CFG":{"GOOGLE_ADMIN_EMAIL":"","GOOGLE_API_KEY":"","GOOGLE_APPLICATION_CREDENTIALS":"","GOOGLE_CLOUD_IDENTITY_ADMIN_EMAIL":"","GOOGLE_IDENTITY_DOMAIN":"","GOOGLE_PROJECT_ID":"","GOOGLE_STORAGE_CREDS":""},"CLIENT_ALLOWED_SCOPES":["openid","user","data","google_credentials","google_service_account","google_link","ga4gh_passport_v1"],"DATA_UPLOAD_BUCKET":"bucket1","DBGAP_ACCESSION_WITH_CONSENT_REGEX":"(?Pphs[0-9]+)(.(?Pv[0-9]+)){0,1}(.(?Pp[0-9]+)){0,1}.(?Pc[0-9]+)","DEBUG":false,"DEFAULT_LOGIN_IDP":"google","DEFAULT_LOGIN_URL":"{{BASE_URL}}/login/google","DEV_LOGIN_COOKIE_NAME":"dev_login","DREAM_CHALLENGE_GROUP":"DREAM","DREAM_CHALLENGE_TEAM":"DREAM","EMAIL_SERVER":"localhost","ENABLED_IDENTITY_PROVIDERS":{},"ENABLE_AUDIT_LOGS":{"login":false,"presigned_url":false},"ENABLE_AUTOMATIC_BILLING_PERMISSION_SA_CREDS":false,"ENABLE_AUTOMATIC_BILLING_PERMISSION_SIGNED_URLS":false,"ENABLE_CSRF_PROTECTION":true,"ENABLE_DB_MIGRATION":true,"ENABLE_PROMETHEUS_METRICS":false,"ENABLE_VISA_UPDATE_CRON":false,"ENCRYPTION_KEY":"REPLACEME","GA4GH_VISA_ISSUER_ALLOWLIST":["{{BASE_URL}}","https://sts.nih.gov","https://stsstg.nih.gov"],"GEN3_PASSPORT_EXPIRES_IN":43200,"GLOBAL_PARSE_VISAS_ON_LOGIN":false,"GOOGLE_ACCOUNT_ACCESS_EXPIRES_IN":86400,"GOOGLE_BULK_UPDATES":false,"GOOGLE_GROUP_PREFIX":"","GOOGLE_MANAGED_SERVICE_ACCOUNT_DOMAINS":["dataflow-service-producer-prod.iam.gserviceaccount.com","cloudbuild.gserviceaccount.com","cloud-ml.google.com.iam.gserviceaccount.com","container-engine-robot.iam.gserviceaccount.com","dataflow-service-producer-prod.iam.gserviceaccount.com","sourcerepo-service-accounts.iam.gserviceaccount.com","dataproc-accounts.iam.gserviceaccount.com","gae-api-prod.google.com.iam.gserviceaccount.com","genomics-api.google.com.iam.gserviceaccount.com","containerregistry.iam.gserviceaccount.com","container-analysis.iam.gserviceaccount.com","cloudservices.gserviceaccount.com","stackdriver-service.iam.gserviceaccount.com","appspot.gserviceaccount.com","partnercontent.gserviceaccount.com","trifacta-gcloud-prod.iam.gserviceaccount.com","gcf-admin-robot.iam.gserviceaccount.com","compute-system.iam.gserviceaccount.com","gcp-sa-websecurityscanner.iam.gserviceaccount.com","storage-transfer-service.iam.gserviceaccount.com","firebase-sa-management.iam.gserviceaccount.com","firebase-rules.iam.gserviceaccount.com","gcp-sa-cloudbuild.iam.gserviceaccount.com","gcp-sa-automl.iam.gserviceaccount.com","gcp-sa-datalabeling.iam.gserviceaccount.com","gcp-sa-cloudscheduler.iam.gserviceaccount.com"],"GOOGLE_SERVICE_ACCOUNT_KEY_FOR_URL_SIGNING_EXPIRES_IN":2592000,"GOOGLE_SERVICE_ACCOUNT_PREFIX":"","GOOGLE_USER_SERVICE_ACCOUNT_ACCESS_EXPIRES_IN":604800,"GUN_MAIL":{"datacommons.io":{"api_key":"","api_url":"https://api.mailgun.net/v3/mailgun.example.com","default_login":"postmaster@mailgun.example.com","smtp_hostname":"smtp.mailgun.org","smtp_password":""}},"HTTP_PROXY":{"host":null,"port":3128},"INDEXD":"http://indexd-service","INDEXD_PASSWORD":"","INDEXD_USERNAME":"fence","ITRUST_GLOBAL_LOGOUT":"https://auth.nih.gov/siteminderagent/smlogout.asp?mode=nih&AppReturnUrl=","LOGIN_OPTIONS":[{"desc":"description","idp":"google","name":"Login from Google"}],"LOGIN_REDIRECT_WHITELIST":[],"MAX_ACCESS_TOKEN_TTL":3600,"MAX_API_KEY_TTL":2592000,"MAX_PRESIGNED_URL_TTL":3600,"MAX_ROLE_SESSION_INCREASE":false,"MOCK_AUTH":false,"MOCK_GOOGLE_AUTH":false,"MOCK_STORAGE":false,"OAUTH2_JWT_ALG":"RS256","OAUTH2_JWT_ENABLED":true,"OAUTH2_JWT_ISS":"{{BASE_URL}}","OAUTH2_PROVIDER_ERROR_URI":"/api/oauth2/errors","OAUTH2_TOKEN_EXPIRES_IN":{"authorization_code":1200,"implicit":1200},"OPENID_CONNECT":{"cilogon":{"client_id":"","client_secret":"","discovery_url":"https://cilogon.org/.well-known/openid-configuration","mock":false,"mock_default_user":"http://cilogon.org/serverT/users/64703","redirect_url":"{{BASE_URL}}/login/cilogon/login/","scope":"openid email profile"},"cognito":{"client_id":"","client_secret":"","discovery_url":"https://cognito-idp.{REGION}.amazonaws.com/{USER-POOL-ID}/.well-known/openid-configuration","redirect_url":"{{BASE_URL}}/login/cognito/login/","scope":"openid email"},"fence":{"access_token_url":"{{api_base_url}}/oauth2/token","api_base_url":"","authorize_url":"{{api_base_url}}/oauth2/authorize","client_id":"","client_kwargs":{"redirect_uri":"{{BASE_URL}}/login/fence/login","scope":"openid"},"client_secret":"","mock":false,"mock_default_user":"test@example.com","name":"","refresh_token_url":"{{api_base_url}}/oauth2/token","shibboleth_discovery_url":"https://login.bionimbus.org/Shibboleth.sso/DiscoFeed"},"generic_oidc_idp":{"client_id":"","client_secret":"","discovery":{"authorization_endpoint":"","jwks_uri":"","token_endpoint":""},"discovery_url":"https://server.com/.well-known/openid-configuration","email_field":"","name":"some_idp","redirect_url":"{{BASE_URL}}/login/some_idp/login","scope":"","user_id_field":""},"google":{"client_id":"","client_secret":"","discovery_url":"https://accounts.google.com/.well-known/openid-configuration","mock":"","mock_default_user":"test@example.com","redirect_url":"{{BASE_URL}}/login/google/login/","scope":"openid email"},"microsoft":{"client_id":"","client_secret":"","discovery_url":"https://login.microsoftonline.com/organizations/v2.0/.well-known/openid-configuration","mock":false,"mock_default_user":"test@example.com","redirect_url":"{{BASE_URL}}/login/microsoft/login/","scope":"openid email"},"okta":{"client_id":"","client_secret":"","discovery_url":"","redirect_url":"{{BASE_URL}}/login/okta/login/","scope":"openid email"},"orcid":{"client_id":"","client_secret":"","discovery_url":"https://orcid.org/.well-known/openid-configuration","mock":false,"mock_default_user":"0000-0002-2601-8132","redirect_url":"{{BASE_URL}}/login/orcid/login/","scope":"openid"},"ras":{"client_id":"","client_secret":"","discovery_url":"https://sts.nih.gov/.well-known/openid-configuration","mock":false,"mock_default_user":"test@example.com","redirect_url":"{{BASE_URL}}/login/ras/callback","scope":"openid email profile ga4gh_passport_v1"},"shibboleth":{"client_id":"","client_secret":"","redirect_url":"{{BASE_URL}}/login/shib/login"},"synapse":{"client_id":"","client_secret":"","discovery_url":"","redirect_url":"","scope":"openid"}},"OVERRIDE_NGINX_RATE_LIMIT":18,"PRIVACY_POLICY_URL":null,"PROBLEM_USER_EMAIL_NOTIFICATION":{"admin":["admin@example.edu"],"content":"The Data Commons Framework utilizes dbGaP for data access authorization. Another member of a Google project you belong to ({}) is attempting to register a service account to the following additional datasets ({}). Please contact dbGaP to request access.\n","domain":"example.com","from":"do-not-reply@example.com","subject":"Account access error notification"},"PUSH_AUDIT_LOGS_CONFIG":{"aws_sqs_config":{"aws_cred":null,"region":null,"sqs_url":null},"type":"aws_sqs"},"RAS_REFRESH_EXPIRATION":1296000,"RAS_USERINFO_ENDPOINT":"/openid/connect/v1.1/userinfo","REFRESH_TOKEN_EXPIRES_IN":2592000,"REGISTERED_USERS_GROUP":"","REGISTER_USERS_ON":false,"REMOVE_SERVICE_ACCOUNT_EMAIL_NOTIFICATION":{"admin":["admin@example.edu"],"content":"Service accounts were removed from access control data because some users or service accounts of GCP Project {} are not authorized to access the data sets associated to the service accounts, or do not adhere to the security policies.\n","domain":"example.com","enable":false,"from":"do-not-reply@example.com","subject":"User service account removal notification"},"RENEW_ACCESS_TOKEN_BEFORE_EXPIRATION":false,"S3_BUCKETS":{},"SEND_FROM":"example@gmail.com","SEND_TO":"example@gmail.com","SERVICE_ACCOUNT_LIMIT":6,"SESSION_ALLOWED_SCOPES":["openid","user","credentials","data","admin","google_credentials","google_service_account","google_link","ga4gh_passport_v1"],"SESSION_COOKIE_DOMAIN":null,"SESSION_COOKIE_NAME":"fence","SESSION_COOKIE_SECURE":true,"SESSION_LIFETIME":28800,"SESSION_TIMEOUT":1800,"SHIBBOLETH_HEADER":"persistent_id","SSO_URL":"https://auth.nih.gov/affwebservices/public/saml2sso?SPID={{BASE_URL}}/shibboleth&RelayState=","STORAGE_CREDENTIALS":{},"SUPPORT_EMAIL_FOR_ERRORS":null,"SYNAPSE_AUTHZ_TTL":86400,"SYNAPSE_DISCOVERY_URL":null,"SYNAPSE_JWKS_URI":null,"SYNAPSE_URI":"https://repo-prod.prod.sagebase.org/auth/v1","TOKEN_PROJECTS_CUTOFF":10,"USERSYNC":{"fallback_to_dbgap_sftp":false,"sync_from_visas":false,"visa_types":{"ras":["https://ras.nih.gov/visas/v1","https://ras.nih.gov/visas/v1.1"]}},"USER_ALLOWED_SCOPES":["fence","openid","user","data","admin","google_credentials","google_service_account","google_link","ga4gh_passport_v1"],"WHITE_LISTED_GOOGLE_PARENT_ORGS":[],"WHITE_LISTED_SERVICE_ACCOUNT_EMAILS":[],"WTF_CSRF_SECRET_KEY":"{{ENCRYPTION_KEY}}","dbGaP":[{"decrypt_key":"","enable_common_exchange_area_access":false,"info":{"host":"","password":"","port":22,"proxy":"","username":""},"parse_consent_code":true,"protocol":"sftp","study_common_exchange_areas":{"example":"test_common_exchange_area"},"study_to_resource_namespaces":{"_default":["/"],"test_common_exchange_area":["/dbgap/"]}}]}` | Private configuration settings for Fence app | +| FENCE_CONFIG | map | `{"ACCESS_TOKEN_COOKIE_NAME":"access_token","ACCESS_TOKEN_EXPIRES_IN":1200,"ALLOWED_GEN3_EMBEDDINGS_BULK_URL_PREFIXES":null,"ALLOWED_USER_SERVICE_ACCOUNT_DOMAINS":["developer.gserviceaccount.com","appspot.gserviceaccount.com","iam.gserviceaccount.com"],"ALLOW_GOOGLE_LINKING":true,"ALLOW_NEW_USER_ON_LOGIN":true,"APPLICATION_ROOT":"/user","APP_NAME":"Gen3 Data Commons","ARBORIST":"http://arborist-service","ASSUME_ROLE_CACHE_SECONDS":1800,"AUDIT_SERVICE":"http://audit-service","AUTHLIB_INSECURE_TRANSPORT":true,"AWS_CREDENTIALS":{},"AZ_BLOB_CONTAINER_URL":"https://myfakeblob.blob.core.windows.net/my-fake-container/","AZ_BLOB_CREDENTIALS":null,"BILLING_PROJECT_FOR_SA_CREDS":null,"BILLING_PROJECT_FOR_SIGNED_URLS":null,"CIRRUS_CFG":{"GOOGLE_ADMIN_EMAIL":"","GOOGLE_API_KEY":"","GOOGLE_APPLICATION_CREDENTIALS":"","GOOGLE_CLOUD_IDENTITY_ADMIN_EMAIL":"","GOOGLE_IDENTITY_DOMAIN":"","GOOGLE_PROJECT_ID":"","GOOGLE_STORAGE_CREDS":""},"CLIENT_ALLOWED_SCOPES":["openid","user","data","google_credentials","google_service_account","google_link","ga4gh_passport_v1"],"DATA_UPLOAD_BUCKET":"bucket1","DBGAP_ACCESSION_WITH_CONSENT_REGEX":"(?Pphs[0-9]+)(.(?Pv[0-9]+)){0,1}(.(?Pp[0-9]+)){0,1}.(?Pc[0-9]+)","DEBUG":false,"DEFAULT_LOGIN_IDP":"google","DEFAULT_LOGIN_URL":"{{BASE_URL}}/login/google","DEV_LOGIN_COOKIE_NAME":"dev_login","DREAM_CHALLENGE_GROUP":"DREAM","DREAM_CHALLENGE_TEAM":"DREAM","EMAIL_SERVER":"localhost","ENABLED_IDENTITY_PROVIDERS":{},"ENABLE_AUDIT_LOGS":{"login":false,"presigned_url":false},"ENABLE_AUTOMATIC_BILLING_PERMISSION_SA_CREDS":false,"ENABLE_AUTOMATIC_BILLING_PERMISSION_SIGNED_URLS":false,"ENABLE_CSRF_PROTECTION":true,"ENABLE_DB_MIGRATION":true,"ENABLE_PROMETHEUS_METRICS":false,"ENABLE_VISA_UPDATE_CRON":false,"ENCRYPTION_KEY":"REPLACEME","GA4GH_VISA_ISSUER_ALLOWLIST":["{{BASE_URL}}","https://sts.nih.gov","https://stsstg.nih.gov"],"GEN3_EMBEDDINGS_API_REGEX":"/vectorstore/collections/(?P[^/]+)/embeddings/(?P[^/]+)","GEN3_PASSPORT_EXPIRES_IN":43200,"GLOBAL_PARSE_VISAS_ON_LOGIN":false,"GOOGLE_ACCOUNT_ACCESS_EXPIRES_IN":86400,"GOOGLE_BULK_UPDATES":false,"GOOGLE_GROUP_PREFIX":"","GOOGLE_MANAGED_SERVICE_ACCOUNT_DOMAINS":["dataflow-service-producer-prod.iam.gserviceaccount.com","cloudbuild.gserviceaccount.com","cloud-ml.google.com.iam.gserviceaccount.com","container-engine-robot.iam.gserviceaccount.com","dataflow-service-producer-prod.iam.gserviceaccount.com","sourcerepo-service-accounts.iam.gserviceaccount.com","dataproc-accounts.iam.gserviceaccount.com","gae-api-prod.google.com.iam.gserviceaccount.com","genomics-api.google.com.iam.gserviceaccount.com","containerregistry.iam.gserviceaccount.com","container-analysis.iam.gserviceaccount.com","cloudservices.gserviceaccount.com","stackdriver-service.iam.gserviceaccount.com","appspot.gserviceaccount.com","partnercontent.gserviceaccount.com","trifacta-gcloud-prod.iam.gserviceaccount.com","gcf-admin-robot.iam.gserviceaccount.com","compute-system.iam.gserviceaccount.com","gcp-sa-websecurityscanner.iam.gserviceaccount.com","storage-transfer-service.iam.gserviceaccount.com","firebase-sa-management.iam.gserviceaccount.com","firebase-rules.iam.gserviceaccount.com","gcp-sa-cloudbuild.iam.gserviceaccount.com","gcp-sa-automl.iam.gserviceaccount.com","gcp-sa-datalabeling.iam.gserviceaccount.com","gcp-sa-cloudscheduler.iam.gserviceaccount.com"],"GOOGLE_SERVICE_ACCOUNT_KEY_FOR_URL_SIGNING_EXPIRES_IN":2592000,"GOOGLE_SERVICE_ACCOUNT_PREFIX":"","GOOGLE_USER_SERVICE_ACCOUNT_ACCESS_EXPIRES_IN":604800,"GUN_MAIL":{"datacommons.io":{"api_key":"","api_url":"https://api.mailgun.net/v3/mailgun.example.com","default_login":"postmaster@mailgun.example.com","smtp_hostname":"smtp.mailgun.org","smtp_password":""}},"HTTP_PROXY":{"host":null,"port":3128},"INDEXD":"http://indexd-service","INDEXD_PASSWORD":"","INDEXD_USERNAME":"fence","ITRUST_GLOBAL_LOGOUT":"https://auth.nih.gov/siteminderagent/smlogout.asp?mode=nih&AppReturnUrl=","LOGIN_OPTIONS":[{"desc":"description","idp":"google","name":"Login from Google"}],"LOGIN_REDIRECT_WHITELIST":[],"MAX_ACCESS_TOKEN_TTL":3600,"MAX_API_KEY_TTL":2592000,"MAX_PRESIGNED_URL_TTL":3600,"MAX_ROLE_SESSION_INCREASE":false,"MOCK_AUTH":false,"MOCK_GOOGLE_AUTH":false,"MOCK_STORAGE":false,"OAUTH2_JWT_ALG":"RS256","OAUTH2_JWT_ENABLED":true,"OAUTH2_JWT_ISS":"{{BASE_URL}}","OAUTH2_PROVIDER_ERROR_URI":"/api/oauth2/errors","OAUTH2_TOKEN_EXPIRES_IN":{"authorization_code":1200,"implicit":1200},"OPENID_CONNECT":{"cilogon":{"client_id":"","client_secret":"","discovery_url":"https://cilogon.org/.well-known/openid-configuration","mock":false,"mock_default_user":"http://cilogon.org/serverT/users/64703","redirect_url":"{{BASE_URL}}/login/cilogon/login/","scope":"openid email profile"},"cognito":{"client_id":"","client_secret":"","discovery_url":"https://cognito-idp.{REGION}.amazonaws.com/{USER-POOL-ID}/.well-known/openid-configuration","redirect_url":"{{BASE_URL}}/login/cognito/login/","scope":"openid email"},"fence":{"access_token_url":"{{api_base_url}}/oauth2/token","api_base_url":"","authorize_url":"{{api_base_url}}/oauth2/authorize","client_id":"","client_kwargs":{"redirect_uri":"{{BASE_URL}}/login/fence/login","scope":"openid"},"client_secret":"","mock":false,"mock_default_user":"test@example.com","name":"","refresh_token_url":"{{api_base_url}}/oauth2/token","shibboleth_discovery_url":"https://login.bionimbus.org/Shibboleth.sso/DiscoFeed"},"generic_oidc_idp":{"client_id":"","client_secret":"","discovery":{"authorization_endpoint":"","jwks_uri":"","token_endpoint":""},"discovery_url":"https://server.com/.well-known/openid-configuration","email_field":"","name":"some_idp","redirect_url":"{{BASE_URL}}/login/some_idp/login","scope":"","user_id_field":""},"google":{"client_id":"","client_secret":"","discovery_url":"https://accounts.google.com/.well-known/openid-configuration","mock":"","mock_default_user":"test@example.com","redirect_url":"{{BASE_URL}}/login/google/login/","scope":"openid email"},"microsoft":{"client_id":"","client_secret":"","discovery_url":"https://login.microsoftonline.com/organizations/v2.0/.well-known/openid-configuration","mock":false,"mock_default_user":"test@example.com","redirect_url":"{{BASE_URL}}/login/microsoft/login/","scope":"openid email"},"okta":{"client_id":"","client_secret":"","discovery_url":"","redirect_url":"{{BASE_URL}}/login/okta/login/","scope":"openid email"},"orcid":{"client_id":"","client_secret":"","discovery_url":"https://orcid.org/.well-known/openid-configuration","mock":false,"mock_default_user":"0000-0002-2601-8132","redirect_url":"{{BASE_URL}}/login/orcid/login/","scope":"openid"},"ras":{"client_id":"","client_secret":"","discovery_url":"https://sts.nih.gov/.well-known/openid-configuration","mock":false,"mock_default_user":"test@example.com","redirect_url":"{{BASE_URL}}/login/ras/callback","scope":"openid email profile ga4gh_passport_v1"},"shibboleth":{"client_id":"","client_secret":"","redirect_url":"{{BASE_URL}}/login/shib/login"},"synapse":{"client_id":"","client_secret":"","discovery_url":"","redirect_url":"","scope":"openid"}},"OVERRIDE_NGINX_RATE_LIMIT":18,"PRIVACY_POLICY_URL":null,"PROBLEM_USER_EMAIL_NOTIFICATION":{"admin":["admin@example.edu"],"content":"The Data Commons Framework utilizes dbGaP for data access authorization. Another member of a Google project you belong to ({}) is attempting to register a service account to the following additional datasets ({}). Please contact dbGaP to request access.\n","domain":"example.com","from":"do-not-reply@example.com","subject":"Account access error notification"},"PUSH_AUDIT_LOGS_CONFIG":{"aws_sqs_config":{"aws_cred":null,"region":null,"sqs_url":null},"type":"aws_sqs"},"RAS_REFRESH_EXPIRATION":1296000,"RAS_USERINFO_ENDPOINT":"/openid/connect/v1.1/userinfo","REFRESH_TOKEN_EXPIRES_IN":2592000,"REGISTERED_USERS_GROUP":"","REGISTER_USERS_ON":false,"REMOVE_SERVICE_ACCOUNT_EMAIL_NOTIFICATION":{"admin":["admin@example.edu"],"content":"Service accounts were removed from access control data because some users or service accounts of GCP Project {} are not authorized to access the data sets associated to the service accounts, or do not adhere to the security policies.\n","domain":"example.com","enable":false,"from":"do-not-reply@example.com","subject":"User service account removal notification"},"RENEW_ACCESS_TOKEN_BEFORE_EXPIRATION":false,"S3_BUCKETS":{},"SEND_FROM":"example@gmail.com","SEND_TO":"example@gmail.com","SERVICE_ACCOUNT_LIMIT":6,"SESSION_ALLOWED_SCOPES":["openid","user","credentials","data","admin","google_credentials","google_service_account","google_link","ga4gh_passport_v1"],"SESSION_COOKIE_DOMAIN":null,"SESSION_COOKIE_NAME":"fence","SESSION_COOKIE_SECURE":true,"SESSION_LIFETIME":28800,"SESSION_TIMEOUT":1800,"SHIBBOLETH_HEADER":"persistent_id","SSO_URL":"https://auth.nih.gov/affwebservices/public/saml2sso?SPID={{BASE_URL}}/shibboleth&RelayState=","STORAGE_CREDENTIALS":{},"SUPPORT_EMAIL_FOR_ERRORS":null,"SYNAPSE_AUTHZ_TTL":86400,"SYNAPSE_DISCOVERY_URL":null,"SYNAPSE_JWKS_URI":null,"SYNAPSE_URI":"https://repo-prod.prod.sagebase.org/auth/v1","TOKEN_PROJECTS_CUTOFF":10,"USERSYNC":{"fallback_to_dbgap_sftp":false,"sync_from_visas":false,"visa_types":{"ras":["https://ras.nih.gov/visas/v1","https://ras.nih.gov/visas/v1.1"]}},"USER_ALLOWED_SCOPES":["fence","openid","user","data","admin","google_credentials","google_service_account","google_link","ga4gh_passport_v1"],"WHITE_LISTED_GOOGLE_PARENT_ORGS":[],"WHITE_LISTED_SERVICE_ACCOUNT_EMAILS":[],"WTF_CSRF_SECRET_KEY":"{{ENCRYPTION_KEY}}","dbGaP":[{"decrypt_key":"","enable_common_exchange_area_access":false,"info":{"host":"","password":"","port":22,"proxy":"","username":""},"parse_consent_code":true,"protocol":"sftp","study_common_exchange_areas":{"example":"test_common_exchange_area"},"study_to_resource_namespaces":{"_default":["/"],"test_common_exchange_area":["/dbgap/"]}}]}` | Private configuration settings for Fence app | | FENCE_CONFIG.APP_NAME | string | `"Gen3 Data Commons"` | Name of the Fence app | | FENCE_CONFIG.AUTHLIB_INSECURE_TRANSPORT | bool | `true` | allow OIDC traffic on http for development. By default it requires https. WARNING: ONLY set to true when fence will be deployed in such a way that it will ONLY receive traffic from internal clients and can safely use HTTP. | | FENCE_CONFIG.CLIENT_ALLOWED_SCOPES | list | `["openid","user","data","google_credentials","google_service_account","google_link","ga4gh_passport_v1"]` | These are the *possible* scopes a client can be given, NOT scopes that are given to all clients. You can be more restrictive during client creation | diff --git a/helm/fence/values.yaml b/helm/fence/values.yaml index 036ec51e9..2aeeda76e 100644 --- a/helm/fence/values.yaml +++ b/helm/fence/values.yaml @@ -1436,6 +1436,19 @@ FENCE_CONFIG: # this is the password which fence uses to make authenticated requests to indexd INDEXD_PASSWORD: "" + # allowlist for Gen3 Embeddings URL resolutions. + # use this to provide the prefix for allowed URLs for Gen3 Embeddings + # for example, if you want to be able to resolve Gen3 Embeddings from + # https://example.com/ai/vectorstore/collections/... + # you need to add "https://example.com/ai" to the allowlist here + # basically, everything BEFORE "/vectorstore/collections/..." + ALLOWED_GEN3_EMBEDDINGS_BULK_URL_PREFIXES: + # - 'https://example.com/ai' + + # this is used to identify indexed record URLs which are pointing to embeddings, and thus support bulk content retrieval + # unless the Gen3 Embeddings API changes, you should NOT change this default + GEN3_EMBEDDINGS_API_REGEX: '/vectorstore/collections/(?P[^/]+)/embeddings/(?P[^/]+)' + # ////////////////////////////////////////////////////////////////////////////////////// # AZURE STORAGE BLOB CONFIGURATION # - Support Azure Blob Data Access Methods diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index b219f6038..36ef8e9d2 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -68,7 +68,7 @@ dependencies: repository: "file://../frontend-framework" condition: frontend-framework.enabled - name: fence - version: 0.1.77 + version: 0.1.78 repository: "file://../fence" condition: fence.enabled - name: funnel diff --git a/helm/gen3/README.md b/helm/gen3/README.md index 10a5cb538..7b645a8af 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -34,7 +34,7 @@ Helm chart to deploy Gen3 Data Commons | file://../dicom-server | dicom-server | 0.1.29 | | file://../embedding-management-service | embedding-management-service | 0.1.6 | | file://../etl | etl | 0.1.23 | -| file://../fence | fence | 0.1.77 | +| file://../fence | fence | 0.1.78 | | file://../frontend-framework | frontend-framework | 0.1.28 | | file://../funnel | funnel | 0.1.24 | | file://../gen3-analysis | gen3-analysis | 0.1.11 | From 26af3cb436e7c1595d9626cb3acae2893c57c08f Mon Sep 17 00:00:00 2001 From: Mingfei Shao Date: Wed, 8 Jul 2026 14:57:14 -0500 Subject: [PATCH 074/196] fix typo --- helm/zendesk-wrapper/templates/_helpers.tpl | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/helm/zendesk-wrapper/templates/_helpers.tpl b/helm/zendesk-wrapper/templates/_helpers.tpl index 557d987d6..b0e3dafcf 100644 --- a/helm/zendesk-wrapper/templates/_helpers.tpl +++ b/helm/zendesk-wrapper/templates/_helpers.tpl @@ -52,6 +52,7 @@ Selector labels {{- else }} {{- (include "common.selectorLabels" .)}} {{- end }} +{{- end }} {{/* Zendesk Wrapper Secrets Manager Name @@ -59,4 +60,3 @@ Selector labels {{- define "zendesk-wrapper-secret" -}} {{- default "zendesk-wrapper-secret" .Values.externalSecrets.name }} {{- end }} -{{- end }} From a518a9ffd71bc5d93c6842e46e85b5ffdc4b286a Mon Sep 17 00:00:00 2001 From: Sai Shanmukha Date: Wed, 8 Jul 2026 14:57:54 -0500 Subject: [PATCH 075/196] Add tag, and update yaml indentation --- helm/funnel/README.md | 19 +++++++++------ helm/funnel/files/server-config.yaml | 9 +++++-- helm/funnel/values.yaml | 35 +++++++++++++++++++--------- 3 files changed, 43 insertions(+), 20 deletions(-) diff --git a/helm/funnel/README.md b/helm/funnel/README.md index 0e031cad1..2ae08d6d4 100644 --- a/helm/funnel/README.md +++ b/helm/funnel/README.md @@ -83,13 +83,12 @@ A Helm chart for Kubernetes | Kubernetes.Worker.restartPolicy | string | `"Never"` | | | Kubernetes.WorkerTemplate | string | `""` | | | LocalStorage | object | `{"AllowedDirs":["./"]}` | Local file system storage configuration. | -| Logger.Plugins.Params.OidcClientId | string | `"FUNNEL_PLUGIN_OIDC_CLIENT_ID_PLACEHOLDER"` | | -| Logger.Plugins.Params.OidcClientSecret | string | `"FUNNEL_PLUGIN_OIDC_CLIENT_SECRET_PLACEHOLDER"` | | -| Logger.Plugins.Params.S3Url | string | `"FUNNEL_PLUGIN_S3URL_PLACEHOLDER"` | | -| Logger.Plugins.Path | string | `"plugin-binaries/auth-plugin"` | | -| Logger.Worker.LeaveWorkDir | bool | `true` | | -| Logger.level | string | `"debug"` | | -| Logger.outputFile | string | `""` | | +| Logger.Formatter | string | `"json"` | | +| Logger.Level | string | `"debug"` | | +| Logger.OutputFile | string | `""` | | +| Logger.TextFormat.ForceColors | bool | `true` | | +| Logger.TextFormat.FullTimestamp | bool | `true` | | +| Logger.TextFormat.TimestampFormat | string | `"2006-01-02T15:04:05Z07:00"` | | | Node.ID | string | `""` | | | Node.Resources.Cpus | int | `0` | | | Node.Resources.DiskGb | float | `0` | | @@ -100,6 +99,10 @@ A Helm chart for Kubernetes | PBS.ReconcileRate | string | `"10s"` | | | PBS.Template | string | `"#!bin/bash\n#PBS -N {{.TaskId}}\n#PBS -o {{.WorkDir}}/funnel-stdout\n#PBS -e {{.WorkDir}}/funnel-stderr\n{{if ne .Cpus 0 -}}\n{{printf \"#PBS -l nodes=1:ppn=%d\" .Cpus}}\n{{- end}}\n{{if ne .RamGb 0.0 -}}\n{{printf \"#PBS -l mem=%.0fgb\" .RamGb}}\n{{- end}}\n{{if ne .DiskGb 0.0 -}}\n{{printf \"#PBS -l file=%.0fgb\" .DiskGb}}\n{{- end}}\n\n{{.Executable}} worker run --config {{.Config}} --taskID {{.TaskId}}\n"` | | | PBS.TemplateFile | string | `""` | | +| Plugins.Params.OidcClientId | string | `"FUNNEL_PLUGIN_OIDC_CLIENT_ID_PLACEHOLDER"` | | +| Plugins.Params.OidcClientSecret | string | `"FUNNEL_PLUGIN_OIDC_CLIENT_SECRET_PLACEHOLDER"` | | +| Plugins.Params.S3Url | string | `"FUNNEL_PLUGIN_S3URL_PLACEHOLDER"` | | +| Plugins.Path | string | `"plugin-binaries/auth-plugin"` | | | Postgres.AdminPassword | string | `"example"` | | | Postgres.AdminUser | string | `"postgres"` | | | Postgres.Database | string | `"FUNNEL_POSTGRES_DATABASE_PLACEHOLDER"` | | @@ -130,6 +133,7 @@ A Helm chart for Kubernetes | Swift.TenantID | string | `""` | | | Swift.TenantName | string | `""` | | | Swift.UserName | string | `""` | | +| Worker.LeaveWorkDir | bool | `true` | | | Worker.LeaveWorkDir | bool | `false` | | | Worker.LogTailSize | int | `10000` | | | Worker.LogUpdateRate | string | `"5s"` | | @@ -180,6 +184,7 @@ A Helm chart for Kubernetes | image.initContainers[0].tag | string | `"main-gen3"` | The Docker image tag for the Funnel init/plugin container. | | image.pullPolicy | string | `"Always"` | When to pull the image. This value should be "Always" to ensure the latest image is used. | | image.repository | string | `"quay.io/ohsu-comp-bio/funnel"` | The Docker image repository for the Funnel service. | +| image.tag | string | `"2026-06-22"` | | | labels.app | string | `"funnel"` | | | metricsEnabled | bool | `false` | | | netPolicy | map | `{"egressApps":["gen3-workflow"],"ingressApps":["gen3-workflow"]}` | Configuration for network policies created by this chart. Only relevant if "global.netPolicy.enabled" is set to true | diff --git a/helm/funnel/files/server-config.yaml b/helm/funnel/files/server-config.yaml index 84e0cbede..997c464c9 100644 --- a/helm/funnel/files/server-config.yaml +++ b/helm/funnel/files/server-config.yaml @@ -79,8 +79,13 @@ EventWriters: {{- end }} Logger: - level: {{ .Values.Logger.level }} - outputFile: {{ .Values.Logger.outputFile }} + Level: {{ .Values.Logger.Level }} + OutputFile: "{{ .Values.Logger.OutputFile }}" + Formatter: {{ .Values.Logger.Formatter }} + TextFormat: + ForceColors: {{ .Values.Logger.TextFormat.ForceColors }} + FullTimestamp: {{ .Values.Logger.TextFormat.FullTimestamp }} + TimestampFormat: {{ .Values.Logger.TextFormat.TimestampFormat }} Server: HostName: "{{ .Values.Server.HostName }}" diff --git a/helm/funnel/values.yaml b/helm/funnel/values.yaml index bc2837836..73dee32a6 100644 --- a/helm/funnel/values.yaml +++ b/helm/funnel/values.yaml @@ -128,9 +128,12 @@ oidc_job_enabled: true image: # -- (string) The Docker image repository for the Funnel service. repository: quay.io/ohsu-comp-bio/funnel + tag: 2026-06-22 + # -- (string) When to pull the image. This value should be "Always" to ensure the latest image is used. pullPolicy: Always + # -- (map) Configuration for the Funnel init container. initContainers: - name: plugin @@ -342,18 +345,28 @@ Postgres: duration: 300s Logger: # Logging levels: debug, info, error - level: debug + Level: debug # Write logs to this path. If empty, logs are written to stderr. - outputFile: "" - Plugins: - Path: plugin-binaries/auth-plugin - Params: - OidcClientId: FUNNEL_PLUGIN_OIDC_CLIENT_ID_PLACEHOLDER - OidcClientSecret: FUNNEL_PLUGIN_OIDC_CLIENT_SECRET_PLACEHOLDER - S3Url: FUNNEL_PLUGIN_S3URL_PLACEHOLDER - Worker: - # This lets mount-s3 pods unmount and Complete. https://ctds-planx.atlassian.net/browse/MIDRC-1214 - LeaveWorkDir: true + OutputFile: "" + # Log format: json or text + Formatter: json + # Text format settings + TextFormat: + # Try to force colors/rich format in text output + ForceColors: true + # Include full timestamps in text output + FullTimestamp: true + # Format for timestamps. RFC3339 is default. + TimestampFormat: "2006-01-02T15:04:05Z07:00" +Plugins: + Path: plugin-binaries/auth-plugin + Params: + OidcClientId: FUNNEL_PLUGIN_OIDC_CLIENT_ID_PLACEHOLDER + OidcClientSecret: FUNNEL_PLUGIN_OIDC_CLIENT_SECRET_PLACEHOLDER + S3Url: FUNNEL_PLUGIN_S3URL_PLACEHOLDER +Worker: + # This lets mount-s3 pods unmount and Complete. https://ctds-planx.atlassian.net/browse/MIDRC-1214 + LeaveWorkDir: true # Kubernetes describes the configuration for the Kubernetes compute backend. Kubernetes: From 48ad388933d13278aaa6e009787e21e273a5f92a Mon Sep 17 00:00:00 2001 From: Sai Shanmukha Date: Wed, 8 Jul 2026 15:07:12 -0500 Subject: [PATCH 076/196] Fix lint checks --- helm/funnel/README.md | 1 - helm/funnel/values.yaml | 6 ++---- 2 files changed, 2 insertions(+), 5 deletions(-) diff --git a/helm/funnel/README.md b/helm/funnel/README.md index 2ae08d6d4..4abfbfa2d 100644 --- a/helm/funnel/README.md +++ b/helm/funnel/README.md @@ -134,7 +134,6 @@ A Helm chart for Kubernetes | Swift.TenantName | string | `""` | | | Swift.UserName | string | `""` | | | Worker.LeaveWorkDir | bool | `true` | | -| Worker.LeaveWorkDir | bool | `false` | | | Worker.LogTailSize | int | `10000` | | | Worker.LogUpdateRate | string | `"5s"` | | | Worker.MaxParallelTransfers | int | `10` | | diff --git a/helm/funnel/values.yaml b/helm/funnel/values.yaml index 73dee32a6..8ea8ba567 100644 --- a/helm/funnel/values.yaml +++ b/helm/funnel/values.yaml @@ -364,9 +364,6 @@ Plugins: OidcClientId: FUNNEL_PLUGIN_OIDC_CLIENT_ID_PLACEHOLDER OidcClientSecret: FUNNEL_PLUGIN_OIDC_CLIENT_SECRET_PLACEHOLDER S3Url: FUNNEL_PLUGIN_S3URL_PLACEHOLDER -Worker: - # This lets mount-s3 pods unmount and Complete. https://ctds-planx.atlassian.net/browse/MIDRC-1214 - LeaveWorkDir: true # Kubernetes describes the configuration for the Kubernetes compute backend. Kubernetes: @@ -612,7 +609,8 @@ Worker: # Normally the worker deletes its working directory after executing. # This option disables that behavior. - LeaveWorkDir: false + # This lets mount-s3 pods unmount and Complete. https://ctds-planx.atlassian.net/browse/MIDRC-1214 + LeaveWorkDir: true # Limit the number of concurrent downloads/uploads MaxParallelTransfers: 10 From 9c58a7a431da163e7fd6608fcba19c467e186696 Mon Sep 17 00:00:00 2001 From: Mingfei Shao Date: Wed, 8 Jul 2026 15:24:33 -0500 Subject: [PATCH 077/196] fix typo --- helm/zendesk-wrapper/templates/deployment.yaml | 8 ++++---- helm/zendesk-wrapper/values.yaml | 4 ++-- 2 files changed, 6 insertions(+), 6 deletions(-) diff --git a/helm/zendesk-wrapper/templates/deployment.yaml b/helm/zendesk-wrapper/templates/deployment.yaml index af86abae3..a0be8f3cb 100644 --- a/helm/zendesk-wrapper/templates/deployment.yaml +++ b/helm/zendesk-wrapper/templates/deployment.yaml @@ -56,10 +56,10 @@ spec: - name: ZENDESK_API_EMAIL valueFrom: secretKeyRef: - name: {{ .Values.secrets.name }} - key: {{ .Values.secrets.apiEmail }} + name: {{ .Values.externalSecrets.name }} + key: {{ .Values.externalSecrets.apiEmail }} - name: ZENDESK_API_TOKEN valueFrom: secretKeyRef: - name: {{ .Values.secrets.name }} - key: {{ .Values.secrets.tokenKey }} + name: {{ .Values.externalSecrets.name }} + key: {{ .Values.externalSecrets.tokenKey }} diff --git a/helm/zendesk-wrapper/values.yaml b/helm/zendesk-wrapper/values.yaml index 7748f27ac..bf7014e0f 100644 --- a/helm/zendesk-wrapper/values.yaml +++ b/helm/zendesk-wrapper/values.yaml @@ -77,9 +77,9 @@ externalSecrets: # -- (string) Name of the Kubernetes secret containing the Zendesk API token name: "zendesk-wrapper-secret" # -- (string) Key within the secret for the API token - tokenKey: "ZENDESK_API_TOKEN" + tokenKey: "tokenKey" # -- (string) Email of the agent account used with the API token - apiEmail: "ZENDESK_API_EMAIL" + apiEmailKey: "apiEmail" release: "production" criticalService: "false" From da89eaa48edc29b10d3cd0c5f7c0c749c20935f4 Mon Sep 17 00:00:00 2001 From: Sai Shanmukha Date: Wed, 8 Jul 2026 19:23:41 -0500 Subject: [PATCH 078/196] Postgres creds template update --- helm/funnel/files/server-config.yaml | 14 ++++---------- 1 file changed, 4 insertions(+), 10 deletions(-) diff --git a/helm/funnel/files/server-config.yaml b/helm/funnel/files/server-config.yaml index 997c464c9..3353892ae 100644 --- a/helm/funnel/files/server-config.yaml +++ b/helm/funnel/files/server-config.yaml @@ -154,16 +154,10 @@ Datastore: CredentialsFile: {{ .Values.Datastore.CredentialsFile }} Postgres: - {{- if .Values.postgres.host }} - Host: {{ .Values.postgres.host }} - {{- else if .Values.global.dev }} - Host: {{ .Release.Name }}-postgresql - {{- else }} - Host: {{ .Values.global.postgres.master.host }} - {{- end }} - Database: {{ include "gen3.service-postgres" (dict "key" "database" "service" .Chart.Name "context" $) }} - User: {{ include "gen3.service-postgres" (dict "key" "username" "service" .Chart.Name "context" $) }} - Password: {{ include "gen3.service-postgres" (dict "key" "password" "service" .Chart.Name "context" $) }} + Host: {{ .Values.Postgres.Host }} + Database: {{ .Values.Postgres.Database }} + User: {{ .Values.Postgres.User }} + Password: {{ .Values.Postgres.Password }} AdminUser: {{ .Values.Postgres.AdminUser }} AdminPassword: {{ .Values.Postgres.AdminPassword }} Timeout: From 10b24cb7d6c3d8e4e1c2d873a92f3d2b4ca29412 Mon Sep 17 00:00:00 2001 From: Mingfei Shao Date: Wed, 8 Jul 2026 21:35:36 -0500 Subject: [PATCH 079/196] fix secret --- helm/zendesk-wrapper/templates/deployment.yaml | 4 ++-- helm/zendesk-wrapper/values.yaml | 4 ---- 2 files changed, 2 insertions(+), 6 deletions(-) diff --git a/helm/zendesk-wrapper/templates/deployment.yaml b/helm/zendesk-wrapper/templates/deployment.yaml index a0be8f3cb..cfdf6f0f7 100644 --- a/helm/zendesk-wrapper/templates/deployment.yaml +++ b/helm/zendesk-wrapper/templates/deployment.yaml @@ -57,9 +57,9 @@ spec: valueFrom: secretKeyRef: name: {{ .Values.externalSecrets.name }} - key: {{ .Values.externalSecrets.apiEmail }} + key: apiEmail - name: ZENDESK_API_TOKEN valueFrom: secretKeyRef: name: {{ .Values.externalSecrets.name }} - key: {{ .Values.externalSecrets.tokenKey }} + key: tokenKey diff --git a/helm/zendesk-wrapper/values.yaml b/helm/zendesk-wrapper/values.yaml index bf7014e0f..3fb6595a8 100644 --- a/helm/zendesk-wrapper/values.yaml +++ b/helm/zendesk-wrapper/values.yaml @@ -76,10 +76,6 @@ env: externalSecrets: # -- (string) Name of the Kubernetes secret containing the Zendesk API token name: "zendesk-wrapper-secret" - # -- (string) Key within the secret for the API token - tokenKey: "tokenKey" - # -- (string) Email of the agent account used with the API token - apiEmailKey: "apiEmail" release: "production" criticalService: "false" From ee039b881b5188d4317eb84e3fb7603519152d72 Mon Sep 17 00:00:00 2001 From: Mingfei Shao Date: Wed, 8 Jul 2026 21:49:55 -0500 Subject: [PATCH 080/196] fix secret --- helm/zendesk-wrapper/templates/deployment.yaml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/helm/zendesk-wrapper/templates/deployment.yaml b/helm/zendesk-wrapper/templates/deployment.yaml index cfdf6f0f7..ef5ede042 100644 --- a/helm/zendesk-wrapper/templates/deployment.yaml +++ b/helm/zendesk-wrapper/templates/deployment.yaml @@ -56,10 +56,10 @@ spec: - name: ZENDESK_API_EMAIL valueFrom: secretKeyRef: - name: {{ .Values.externalSecrets.name }} + name: zendesk-wrapper-secret key: apiEmail - name: ZENDESK_API_TOKEN valueFrom: secretKeyRef: - name: {{ .Values.externalSecrets.name }} + name: zendesk-wrapper-secret key: tokenKey From 5f43d36d15c66ce8d38179d085f83d0316e77af4 Mon Sep 17 00:00:00 2001 From: Mingfei Shao Date: Wed, 8 Jul 2026 21:50:33 -0500 Subject: [PATCH 081/196] fix secret From 60dedadcf37cd8902a2f24d3ce68fa6043dedbf1 Mon Sep 17 00:00:00 2001 From: Mingfei Shao Date: Wed, 8 Jul 2026 21:54:04 -0500 Subject: [PATCH 082/196] trigger chart update --- helm/zendesk-wrapper/README.md | 4 ++-- helm/zendesk-wrapper/values.yaml | 4 ++++ 2 files changed, 6 insertions(+), 2 deletions(-) diff --git a/helm/zendesk-wrapper/README.md b/helm/zendesk-wrapper/README.md index 6dfbd9624..40a919e8e 100644 --- a/helm/zendesk-wrapper/README.md +++ b/helm/zendesk-wrapper/README.md @@ -24,8 +24,8 @@ A Helm chart for gen3 Zendesk Wrapper Service | criticalService | string | `"false"` | | | env | map | `{"GEN3_ZENDESK_URL":""}` | Environment variables for the Zendesk wrapper service | | env.GEN3_ZENDESK_URL | string | `""` | Zendesk instance URL (e.g., https://gen3support.zendesk.com) | -| externalSecrets | map | `{"apiEmail":"ZENDESK_API_EMAIL","name":"zendesk-wrapper-secret","tokenKey":"ZENDESK_API_TOKEN"}` | Secret environment variables (referenced from Kubernetes secrets) | -| externalSecrets.apiEmail | string | `"ZENDESK_API_EMAIL"` | Email of the agent account used with the API token | +| externalSecrets | map | `{"apiEmailKey":"ZENDESK_API_EMAIL","name":"zendesk-wrapper-secret","tokenKey":"ZENDESK_API_TOKEN"}` | Secret environment variables (referenced from Kubernetes secrets) | +| externalSecrets.apiEmailKey | string | `"ZENDESK_API_EMAIL"` | Email of the agent account used with the API token | | externalSecrets.name | string | `"zendesk-wrapper-secret"` | Name of the Kubernetes secret containing the Zendesk API token | | externalSecrets.tokenKey | string | `"ZENDESK_API_TOKEN"` | Key within the secret for the API token | | global.autoscaling.averageCPUValue | string | `"500m"` | | diff --git a/helm/zendesk-wrapper/values.yaml b/helm/zendesk-wrapper/values.yaml index 3fb6595a8..660132ffc 100644 --- a/helm/zendesk-wrapper/values.yaml +++ b/helm/zendesk-wrapper/values.yaml @@ -76,6 +76,10 @@ env: externalSecrets: # -- (string) Name of the Kubernetes secret containing the Zendesk API token name: "zendesk-wrapper-secret" + # -- (string) Key within the secret for the API token + tokenKey: "ZENDESK_API_TOKEN" + # -- (string) Email of the agent account used with the API token + apiEmailKey: "ZENDESK_API_EMAIL" release: "production" criticalService: "false" From 5e7c86920572cb518e35542eda654b272497e288 Mon Sep 17 00:00:00 2001 From: Mingfei Shao Date: Wed, 8 Jul 2026 21:54:30 -0500 Subject: [PATCH 083/196] trigger chart update --- helm/zendesk-wrapper/README.md | 4 +--- helm/zendesk-wrapper/values.yaml | 4 ---- 2 files changed, 1 insertion(+), 7 deletions(-) diff --git a/helm/zendesk-wrapper/README.md b/helm/zendesk-wrapper/README.md index 40a919e8e..79d68e565 100644 --- a/helm/zendesk-wrapper/README.md +++ b/helm/zendesk-wrapper/README.md @@ -24,10 +24,8 @@ A Helm chart for gen3 Zendesk Wrapper Service | criticalService | string | `"false"` | | | env | map | `{"GEN3_ZENDESK_URL":""}` | Environment variables for the Zendesk wrapper service | | env.GEN3_ZENDESK_URL | string | `""` | Zendesk instance URL (e.g., https://gen3support.zendesk.com) | -| externalSecrets | map | `{"apiEmailKey":"ZENDESK_API_EMAIL","name":"zendesk-wrapper-secret","tokenKey":"ZENDESK_API_TOKEN"}` | Secret environment variables (referenced from Kubernetes secrets) | -| externalSecrets.apiEmailKey | string | `"ZENDESK_API_EMAIL"` | Email of the agent account used with the API token | +| externalSecrets | map | `{"name":"zendesk-wrapper-secret"}` | Secret environment variables (referenced from Kubernetes secrets) | | externalSecrets.name | string | `"zendesk-wrapper-secret"` | Name of the Kubernetes secret containing the Zendesk API token | -| externalSecrets.tokenKey | string | `"ZENDESK_API_TOKEN"` | Key within the secret for the API token | | global.autoscaling.averageCPUValue | string | `"500m"` | | | global.autoscaling.averageMemoryValue | string | `"500Mi"` | | | global.autoscaling.enabled | bool | `false` | | diff --git a/helm/zendesk-wrapper/values.yaml b/helm/zendesk-wrapper/values.yaml index 660132ffc..3fb6595a8 100644 --- a/helm/zendesk-wrapper/values.yaml +++ b/helm/zendesk-wrapper/values.yaml @@ -76,10 +76,6 @@ env: externalSecrets: # -- (string) Name of the Kubernetes secret containing the Zendesk API token name: "zendesk-wrapper-secret" - # -- (string) Key within the secret for the API token - tokenKey: "ZENDESK_API_TOKEN" - # -- (string) Email of the agent account used with the API token - apiEmailKey: "ZENDESK_API_EMAIL" release: "production" criticalService: "false" From f1e706f7011a676a5fd1133c33ba85c94a19d9af Mon Sep 17 00:00:00 2001 From: Guerdon Mukama Date: Thu, 9 Jul 2026 20:00:49 +1000 Subject: [PATCH 084/196] fix: requestor service account --- helm/requestor/templates/deployment.yaml | 1 + helm/requestor/templates/serviceaccount.yaml | 12 ++++++++++++ helm/requestor/values.yaml | 11 +++++++++++ 3 files changed, 24 insertions(+) create mode 100644 helm/requestor/templates/serviceaccount.yaml diff --git a/helm/requestor/templates/deployment.yaml b/helm/requestor/templates/deployment.yaml index 7aedbaeee..213e6b733 100644 --- a/helm/requestor/templates/deployment.yaml +++ b/helm/requestor/templates/deployment.yaml @@ -45,6 +45,7 @@ spec: affinity: {{- toYaml . | nindent 8 }} {{- end }} + serviceAccountName: {{ include "requestor.serviceAccountName" . }} automountServiceAccountToken: {{ .Values.automountServiceAccountToken }} volumes: - name: config-volume diff --git a/helm/requestor/templates/serviceaccount.yaml b/helm/requestor/templates/serviceaccount.yaml new file mode 100644 index 000000000..8161fb049 --- /dev/null +++ b/helm/requestor/templates/serviceaccount.yaml @@ -0,0 +1,12 @@ +{{- if .Values.serviceAccount.create -}} +apiVersion: v1 +kind: ServiceAccount +metadata: + name: {{ include "requestor.serviceAccountName" . }} + labels: + {{- include "requestor.labels" . | nindent 4 }} + {{- with .Values.serviceAccount.annotations }} + annotations: + {{- toYaml . | nindent 4 }} + {{- end }} +{{- end }} \ No newline at end of file diff --git a/helm/requestor/values.yaml b/helm/requestor/values.yaml index 8f6488fbe..4b584e60f 100644 --- a/helm/requestor/values.yaml +++ b/helm/requestor/values.yaml @@ -190,6 +190,17 @@ affinity: # -- (bool) Automount the default service account token automountServiceAccountToken: false +serviceAccount: + # -- (bool) Specifies whether a service account should be created. + create: true + # -- (map) Annotations to add to the service account. + annotations: + # -- (string) The Amazon Resource Name (ARN) of the role to associate with the service account + eks.amazonaws.com/role-arn: + # If not set and create is true, a name is generated using the fullname template + # -- (string) The name of the service account + name: "requestor-sa" + # -- (map) Docker image information. image: # -- (string) Docker repository. From 327e09c48689096f71ee28081d7acd1732bd60e2 Mon Sep 17 00:00:00 2001 From: Justin Barnowski Date: Thu, 11 Jun 2026 15:33:20 -0500 Subject: [PATCH 085/196] feat(pgvector): use the image built from docker-bitnami-pgvector repo --- helm/gen3/README.md | 2 +- helm/gen3/values.yaml | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/helm/gen3/README.md b/helm/gen3/README.md index d60ce8d74..fae5406a3 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -250,7 +250,7 @@ Helm chart to deploy Gen3 Data Commons | peregrine.enabled | bool | `true` | Whether to deploy the peregrine subchart. | | pidgin.enabled | bool | `false` | Whether to deploy the pidgin subchart. | | portal.enabled | bool | `true` | Whether to deploy the portal subchart. | -| postgresql | map | `{"image":{"repository":"bitnamilegacy/postgresql","tag":"16.6.0-debian-12-r2"},"primary":{"persistence":{"enabled":false}}}` | To configure postgresql subchart Disable persistence by default so we can spin up and down ephemeral environments | +| postgresql | map | `{"image":{"repository":"gen3/docker-bitnami-pgvector","tag":16},"primary":{"persistence":{"enabled":false}}}` | To configure postgresql subchart Disable persistence by default so we can spin up and down ephemeral environments | | postgresql.primary.persistence.enabled | bool | `false` | Option to persist the dbs data. | | requestor.enabled | bool | `false` | Whether to deploy the requestor subchart. | | revproxy.enabled | bool | `true` | Whether to deploy the revproxy subchart. | diff --git a/helm/gen3/values.yaml b/helm/gen3/values.yaml index 731e9869f..970133464 100644 --- a/helm/gen3/values.yaml +++ b/helm/gen3/values.yaml @@ -418,8 +418,8 @@ access-backend: # Disable persistence by default so we can spin up and down ephemeral environments postgresql: image: - repository: bitnamilegacy/postgresql - tag: 16.6.0-debian-12-r2 + repository: gen3/docker-bitnami-pgvector + tag: 16 primary: persistence: # -- (bool) Option to persist the dbs data. From 4f30c9deb6e53de1f044dbd222c133e2dc942820 Mon Sep 17 00:00:00 2001 From: Justin Barnowski Date: Thu, 25 Jun 2026 15:39:17 -0500 Subject: [PATCH 086/196] fix(repo): quay pub --- helm/gen3/README.md | 2 +- helm/gen3/values.yaml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/helm/gen3/README.md b/helm/gen3/README.md index fae5406a3..ab58d7204 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -250,7 +250,7 @@ Helm chart to deploy Gen3 Data Commons | peregrine.enabled | bool | `true` | Whether to deploy the peregrine subchart. | | pidgin.enabled | bool | `false` | Whether to deploy the pidgin subchart. | | portal.enabled | bool | `true` | Whether to deploy the portal subchart. | -| postgresql | map | `{"image":{"repository":"gen3/docker-bitnami-pgvector","tag":16},"primary":{"persistence":{"enabled":false}}}` | To configure postgresql subchart Disable persistence by default so we can spin up and down ephemeral environments | +| postgresql | map | `{"image":{"repository":"quay.io/cdis/docker-bitnami-pgvector","tag":16},"primary":{"persistence":{"enabled":false}}}` | To configure postgresql subchart Disable persistence by default so we can spin up and down ephemeral environments | | postgresql.primary.persistence.enabled | bool | `false` | Option to persist the dbs data. | | requestor.enabled | bool | `false` | Whether to deploy the requestor subchart. | | revproxy.enabled | bool | `true` | Whether to deploy the revproxy subchart. | diff --git a/helm/gen3/values.yaml b/helm/gen3/values.yaml index 970133464..8d3b36ea5 100644 --- a/helm/gen3/values.yaml +++ b/helm/gen3/values.yaml @@ -418,7 +418,7 @@ access-backend: # Disable persistence by default so we can spin up and down ephemeral environments postgresql: image: - repository: gen3/docker-bitnami-pgvector + repository: "quay.io/cdis/docker-bitnami-pgvector" tag: 16 primary: persistence: From 021bf4c55b6dcfab856778263dc09d024fc890c1 Mon Sep 17 00:00:00 2001 From: Justin Barnowski Date: Thu, 25 Jun 2026 16:34:02 -0500 Subject: [PATCH 087/196] feat(pgvector): let it pull from quay --- examples/local_dev_values.yaml | 3 +-- helm/gen3/README.md | 2 +- helm/gen3/values.yaml | 6 ++++-- 3 files changed, 6 insertions(+), 5 deletions(-) diff --git a/examples/local_dev_values.yaml b/examples/local_dev_values.yaml index 1250b2c51..cd39f9cb9 100644 --- a/examples/local_dev_values.yaml +++ b/examples/local_dev_values.yaml @@ -29,8 +29,7 @@ fence: portal: image: repository: quay.io/cdis/data-portal-prebuilt - tag: brh.data-commons.org-feat-pr_comment resources: requests: cpu: 0.2 - memory: 500Mi \ No newline at end of file + memory: 500Mi diff --git a/helm/gen3/README.md b/helm/gen3/README.md index ab58d7204..14d71151c 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -250,7 +250,7 @@ Helm chart to deploy Gen3 Data Commons | peregrine.enabled | bool | `true` | Whether to deploy the peregrine subchart. | | pidgin.enabled | bool | `false` | Whether to deploy the pidgin subchart. | | portal.enabled | bool | `true` | Whether to deploy the portal subchart. | -| postgresql | map | `{"image":{"repository":"quay.io/cdis/docker-bitnami-pgvector","tag":16},"primary":{"persistence":{"enabled":false}}}` | To configure postgresql subchart Disable persistence by default so we can spin up and down ephemeral environments | +| postgresql | map | `{"global":{"imageRegistry":"quay.io/cdis"},"image":{"repository":"docker-bitnami-pgvector","tag":17},"primary":{"persistence":{"enabled":false}}}` | To configure postgresql subchart Disable persistence by default so we can spin up and down ephemeral environments | | postgresql.primary.persistence.enabled | bool | `false` | Option to persist the dbs data. | | requestor.enabled | bool | `false` | Whether to deploy the requestor subchart. | | revproxy.enabled | bool | `true` | Whether to deploy the revproxy subchart. | diff --git a/helm/gen3/values.yaml b/helm/gen3/values.yaml index 8d3b36ea5..75127d799 100644 --- a/helm/gen3/values.yaml +++ b/helm/gen3/values.yaml @@ -417,9 +417,11 @@ access-backend: # -- (map) To configure postgresql subchart # Disable persistence by default so we can spin up and down ephemeral environments postgresql: + global: + imageRegistry: "quay.io/cdis" image: - repository: "quay.io/cdis/docker-bitnami-pgvector" - tag: 16 + repository: "docker-bitnami-pgvector" + tag: 17 primary: persistence: # -- (bool) Option to persist the dbs data. From 5a90c5b919ae88395ccd82a34c6a07d6053a682e Mon Sep 17 00:00:00 2001 From: Justin Barnowski Date: Thu, 25 Jun 2026 16:58:58 -0500 Subject: [PATCH 088/196] fix(pg): daticulocale rename --- examples/local_dev_values.yaml | 2 +- helm/gen3/README.md | 4 ++-- helm/gen3/values.yaml | 4 ++-- 3 files changed, 5 insertions(+), 5 deletions(-) diff --git a/examples/local_dev_values.yaml b/examples/local_dev_values.yaml index cd39f9cb9..29f02a1cf 100644 --- a/examples/local_dev_values.yaml +++ b/examples/local_dev_values.yaml @@ -1,6 +1,6 @@ global: dev: true - hostname: localhost + hostname: jbarno # configuration for fence helm chart. You can add it for all our services. fence: diff --git a/helm/gen3/README.md b/helm/gen3/README.md index 14d71151c..643144c89 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -172,7 +172,7 @@ Helm chart to deploy Gen3 Data Commons | global.netPolicy.enabled | bool | `false` | Whether network policies are enabled | | global.pdb | bool | `false` | If the service will be deployed with a Pod Disruption Budget. Note- you need to have more than 2 replicas for the pdb to be deployed. | | global.portalApp | string | `"gitops"` | Portal application name. | -| global.postgres.dbCreate | bool | `true` | Whether the database create job should run. | +| global.postgres.dbCreate | bool | `false` | Whether the database create job should run. | | global.postgres.externalSecret | string | `""` | Name of external secret of the postgres master credentials. Disabled if empty | | global.postgres.master.host | string | `nil` | global postgres master host | | global.postgres.master.password | string | `nil` | global postgres master password | @@ -250,7 +250,7 @@ Helm chart to deploy Gen3 Data Commons | peregrine.enabled | bool | `true` | Whether to deploy the peregrine subchart. | | pidgin.enabled | bool | `false` | Whether to deploy the pidgin subchart. | | portal.enabled | bool | `true` | Whether to deploy the portal subchart. | -| postgresql | map | `{"global":{"imageRegistry":"quay.io/cdis"},"image":{"repository":"docker-bitnami-pgvector","tag":17},"primary":{"persistence":{"enabled":false}}}` | To configure postgresql subchart Disable persistence by default so we can spin up and down ephemeral environments | +| postgresql | map | `{"global":{"imageRegistry":"quay.io/cdis"},"image":{"repository":"docker-bitnami-pgvector","tag":16},"primary":{"persistence":{"enabled":false}}}` | To configure postgresql subchart Disable persistence by default so we can spin up and down ephemeral environments | | postgresql.primary.persistence.enabled | bool | `false` | Option to persist the dbs data. | | requestor.enabled | bool | `false` | Whether to deploy the requestor subchart. | | revproxy.enabled | bool | `true` | Whether to deploy the revproxy subchart. | diff --git a/helm/gen3/values.yaml b/helm/gen3/values.yaml index 75127d799..750a38a67 100644 --- a/helm/gen3/values.yaml +++ b/helm/gen3/values.yaml @@ -61,7 +61,7 @@ global: dev: true postgres: # -- (bool) Whether the database create job should run. - dbCreate: true + dbCreate: false # -- (string) Name of external secret of the postgres master credentials. Disabled if empty externalSecret: "" master: @@ -421,7 +421,7 @@ postgresql: imageRegistry: "quay.io/cdis" image: repository: "docker-bitnami-pgvector" - tag: 17 + tag: 16 primary: persistence: # -- (bool) Option to persist the dbs data. From 00d880b5eaa6d44e4c77b7d7fe49e50d78bff69e Mon Sep 17 00:00:00 2001 From: Justin Barnowski Date: Tue, 30 Jun 2026 22:06:39 -0500 Subject: [PATCH 089/196] feat(install): install the extension --- helm/common/templates/_db_setup_job.tpl | 3 +++ 1 file changed, 3 insertions(+) diff --git a/helm/common/templates/_db_setup_job.tpl b/helm/common/templates/_db_setup_job.tpl index ee610ef60..2de20e43a 100644 --- a/helm/common/templates/_db_setup_job.tpl +++ b/helm/common/templates/_db_setup_job.tpl @@ -170,6 +170,9 @@ spec: echo "Creating ltree extension..." psql -d $SERVICE_PGDB -c "CREATE EXTENSION IF NOT EXISTS ltree;" + echo "Creating pgvector extension..." + psql -d $SERVICE_PGDB -c "CREATE EXTENSION IF NOT EXISTS vector;" + PGPASSWORD=$SERVICE_PGPASS psql -d $SERVICE_PGDB -h $PGHOST -p $PGPORT -U $SERVICE_PGUSER -c "\conninfo" kubectl patch secret/{{ .Chart.Name }}-dbcreds -p '{"data":{"dbcreated":"dHJ1ZQo="}}' fi From ccaad0864c855faffc3229cfde9550012021a2c2 Mon Sep 17 00:00:00 2001 From: Justin Barnowski Date: Tue, 30 Jun 2026 22:08:09 -0500 Subject: [PATCH 090/196] fix(dbCreate): need that on --- helm/gen3/README.md | 2 +- helm/gen3/values.yaml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/helm/gen3/README.md b/helm/gen3/README.md index 643144c89..f6c174db9 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -172,7 +172,7 @@ Helm chart to deploy Gen3 Data Commons | global.netPolicy.enabled | bool | `false` | Whether network policies are enabled | | global.pdb | bool | `false` | If the service will be deployed with a Pod Disruption Budget. Note- you need to have more than 2 replicas for the pdb to be deployed. | | global.portalApp | string | `"gitops"` | Portal application name. | -| global.postgres.dbCreate | bool | `false` | Whether the database create job should run. | +| global.postgres.dbCreate | bool | `true` | Whether the database create job should run. | | global.postgres.externalSecret | string | `""` | Name of external secret of the postgres master credentials. Disabled if empty | | global.postgres.master.host | string | `nil` | global postgres master host | | global.postgres.master.password | string | `nil` | global postgres master password | diff --git a/helm/gen3/values.yaml b/helm/gen3/values.yaml index 750a38a67..a1cbaf472 100644 --- a/helm/gen3/values.yaml +++ b/helm/gen3/values.yaml @@ -61,7 +61,7 @@ global: dev: true postgres: # -- (bool) Whether the database create job should run. - dbCreate: false + dbCreate: true # -- (string) Name of external secret of the postgres master credentials. Disabled if empty externalSecret: "" master: From cf0e202e8ac1b1b0a3fecd6a9a6b5f5ffb4cd5a2 Mon Sep 17 00:00:00 2001 From: Justin Barnowski Date: Tue, 30 Jun 2026 22:10:05 -0500 Subject: [PATCH 091/196] fix(local): localhost --- examples/local_dev_values.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/examples/local_dev_values.yaml b/examples/local_dev_values.yaml index 29f02a1cf..b08994dd9 100644 --- a/examples/local_dev_values.yaml +++ b/examples/local_dev_values.yaml @@ -1,6 +1,6 @@ global: dev: true - hostname: jbarno + hostname: localhost # configuration for fence helm chart. You can add it for all our services. fence: From 9b4cce6a3293103f3ca1d31f05e6135512f0e6e9 Mon Sep 17 00:00:00 2001 From: Justin Barnowski Date: Wed, 1 Jul 2026 15:00:41 -0500 Subject: [PATCH 092/196] fix(registry): its all getting concatenated anyway --- helm/common/Chart.yaml | 2 +- helm/common/README.md | 2 +- helm/gen3/Chart.yaml | 2 +- helm/gen3/README.md | 4 ++-- helm/gen3/values.yaml | 4 ++-- 5 files changed, 7 insertions(+), 7 deletions(-) diff --git a/helm/common/Chart.yaml b/helm/common/Chart.yaml index 797834d62..83fcee7d4 100644 --- a/helm/common/Chart.yaml +++ b/helm/common/Chart.yaml @@ -15,7 +15,7 @@ type: library # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.36 +version: 0.1.37 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/common/README.md b/helm/common/README.md index 1438d8d0c..c9e00ec28 100644 --- a/helm/common/README.md +++ b/helm/common/README.md @@ -1,6 +1,6 @@ # common -![Version: 0.1.36](https://img.shields.io/badge/Version-0.1.36-informational?style=flat-square) ![Type: library](https://img.shields.io/badge/Type-library-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.37](https://img.shields.io/badge/Version-0.1.37-informational?style=flat-square) ![Type: library](https://img.shields.io/badge/Type-library-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for provisioning databases in gen3 diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index 85617b262..dac379a99 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -41,7 +41,7 @@ dependencies: repository: "file://../cohort-middleware" condition: cohort-middleware.enabled - name: common - version: 0.1.36 + version: 0.1.37 repository: file://../common - name: dashboard version: 0.1.21 diff --git a/helm/gen3/README.md b/helm/gen3/README.md index f6c174db9..56c34f865 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -27,8 +27,8 @@ Helm chart to deploy Gen3 Data Commons | file://../aws-sigv4-proxy | aws-sigv4-proxy | 0.1.2 | | file://../cedar | cedar | 0.1.26 | | file://../cohort-middleware | cohort-middleware | 0.1.22 | -| file://../common | common | 0.1.36 | | file://../dashboard | dashboard | 0.1.21 | +| file://../common | common | 0.1.37 | | file://../data-upload-cron | data-upload-cron | 0.1.6 | | file://../datareplicate | datareplicate | 0.1.21 | | file://../dicom-server | dicom-server | 0.1.31 | @@ -250,7 +250,7 @@ Helm chart to deploy Gen3 Data Commons | peregrine.enabled | bool | `true` | Whether to deploy the peregrine subchart. | | pidgin.enabled | bool | `false` | Whether to deploy the pidgin subchart. | | portal.enabled | bool | `true` | Whether to deploy the portal subchart. | -| postgresql | map | `{"global":{"imageRegistry":"quay.io/cdis"},"image":{"repository":"docker-bitnami-pgvector","tag":16},"primary":{"persistence":{"enabled":false}}}` | To configure postgresql subchart Disable persistence by default so we can spin up and down ephemeral environments | +| postgresql | map | `{"global":{"imageRegistry":"quay.io"},"image":{"repository":"cdis/docker-bitnami-pgvector","tag":16},"primary":{"persistence":{"enabled":false}}}` | To configure postgresql subchart Disable persistence by default so we can spin up and down ephemeral environments | | postgresql.primary.persistence.enabled | bool | `false` | Option to persist the dbs data. | | requestor.enabled | bool | `false` | Whether to deploy the requestor subchart. | | revproxy.enabled | bool | `true` | Whether to deploy the revproxy subchart. | diff --git a/helm/gen3/values.yaml b/helm/gen3/values.yaml index a1cbaf472..f01e94db3 100644 --- a/helm/gen3/values.yaml +++ b/helm/gen3/values.yaml @@ -418,9 +418,9 @@ access-backend: # Disable persistence by default so we can spin up and down ephemeral environments postgresql: global: - imageRegistry: "quay.io/cdis" + imageRegistry: "quay.io" image: - repository: "docker-bitnami-pgvector" + repository: "cdis/docker-bitnami-pgvector" tag: 16 primary: persistence: From 27892c1b948c31cdae48db60f17afb6fa2957816 Mon Sep 17 00:00:00 2001 From: Justin Barnowski Date: Thu, 2 Jul 2026 13:28:04 -0500 Subject: [PATCH 093/196] feat(repository): less config, tag on seperate line is nice though --- helm/gen3/README.md | 2 +- helm/gen3/values.yaml | 4 +--- 2 files changed, 2 insertions(+), 4 deletions(-) diff --git a/helm/gen3/README.md b/helm/gen3/README.md index 56c34f865..fd43ecc2c 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -250,7 +250,7 @@ Helm chart to deploy Gen3 Data Commons | peregrine.enabled | bool | `true` | Whether to deploy the peregrine subchart. | | pidgin.enabled | bool | `false` | Whether to deploy the pidgin subchart. | | portal.enabled | bool | `true` | Whether to deploy the portal subchart. | -| postgresql | map | `{"global":{"imageRegistry":"quay.io"},"image":{"repository":"cdis/docker-bitnami-pgvector","tag":16},"primary":{"persistence":{"enabled":false}}}` | To configure postgresql subchart Disable persistence by default so we can spin up and down ephemeral environments | +| postgresql | map | `{"image":{"repository":"quay.io/cdis/docker-bitnami-pgvector","tag":16},"primary":{"persistence":{"enabled":false}}}` | To configure postgresql subchart Disable persistence by default so we can spin up and down ephemeral environments | | postgresql.primary.persistence.enabled | bool | `false` | Option to persist the dbs data. | | requestor.enabled | bool | `false` | Whether to deploy the requestor subchart. | | revproxy.enabled | bool | `true` | Whether to deploy the revproxy subchart. | diff --git a/helm/gen3/values.yaml b/helm/gen3/values.yaml index f01e94db3..8d3b36ea5 100644 --- a/helm/gen3/values.yaml +++ b/helm/gen3/values.yaml @@ -417,10 +417,8 @@ access-backend: # -- (map) To configure postgresql subchart # Disable persistence by default so we can spin up and down ephemeral environments postgresql: - global: - imageRegistry: "quay.io" image: - repository: "cdis/docker-bitnami-pgvector" + repository: "quay.io/cdis/docker-bitnami-pgvector" tag: 16 primary: persistence: From 6008f988934832e146e560f8919019ee2837c9fb Mon Sep 17 00:00:00 2001 From: Justin Barnowski Date: Thu, 9 Jul 2026 09:47:37 -0400 Subject: [PATCH 094/196] Revert "feat(repository): less config, tag on seperate line is nice though" This reverts commit 27892c1b948c31cdae48db60f17afb6fa2957816. --- helm/gen3/README.md | 2 +- helm/gen3/values.yaml | 4 +++- 2 files changed, 4 insertions(+), 2 deletions(-) diff --git a/helm/gen3/README.md b/helm/gen3/README.md index fd43ecc2c..56c34f865 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -250,7 +250,7 @@ Helm chart to deploy Gen3 Data Commons | peregrine.enabled | bool | `true` | Whether to deploy the peregrine subchart. | | pidgin.enabled | bool | `false` | Whether to deploy the pidgin subchart. | | portal.enabled | bool | `true` | Whether to deploy the portal subchart. | -| postgresql | map | `{"image":{"repository":"quay.io/cdis/docker-bitnami-pgvector","tag":16},"primary":{"persistence":{"enabled":false}}}` | To configure postgresql subchart Disable persistence by default so we can spin up and down ephemeral environments | +| postgresql | map | `{"global":{"imageRegistry":"quay.io"},"image":{"repository":"cdis/docker-bitnami-pgvector","tag":16},"primary":{"persistence":{"enabled":false}}}` | To configure postgresql subchart Disable persistence by default so we can spin up and down ephemeral environments | | postgresql.primary.persistence.enabled | bool | `false` | Option to persist the dbs data. | | requestor.enabled | bool | `false` | Whether to deploy the requestor subchart. | | revproxy.enabled | bool | `true` | Whether to deploy the revproxy subchart. | diff --git a/helm/gen3/values.yaml b/helm/gen3/values.yaml index 8d3b36ea5..f01e94db3 100644 --- a/helm/gen3/values.yaml +++ b/helm/gen3/values.yaml @@ -417,8 +417,10 @@ access-backend: # -- (map) To configure postgresql subchart # Disable persistence by default so we can spin up and down ephemeral environments postgresql: + global: + imageRegistry: "quay.io" image: - repository: "quay.io/cdis/docker-bitnami-pgvector" + repository: "cdis/docker-bitnami-pgvector" tag: 16 primary: persistence: From 5499d0e1fb422fd7236fe9dcab0dede6ffdf54a1 Mon Sep 17 00:00:00 2001 From: Justin Barnowski Date: Thu, 9 Jul 2026 10:16:05 -0400 Subject: [PATCH 095/196] chore(versions): reverting borked things --- helm/gen3/Chart.yaml | 2 +- helm/gen3/README.md | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index dac379a99..92e89d246 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -197,7 +197,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.60 +version: 0.3.61 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index 56c34f865..c327e47f5 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,6 +1,6 @@ # gen3 -![Version: 0.3.60](https://img.shields.io/badge/Version-0.3.60-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.3.61](https://img.shields.io/badge/Version-0.3.61-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons @@ -27,8 +27,8 @@ Helm chart to deploy Gen3 Data Commons | file://../aws-sigv4-proxy | aws-sigv4-proxy | 0.1.2 | | file://../cedar | cedar | 0.1.26 | | file://../cohort-middleware | cohort-middleware | 0.1.22 | -| file://../dashboard | dashboard | 0.1.21 | | file://../common | common | 0.1.37 | +| file://../dashboard | dashboard | 0.1.21 | | file://../data-upload-cron | data-upload-cron | 0.1.6 | | file://../datareplicate | datareplicate | 0.1.21 | | file://../dicom-server | dicom-server | 0.1.31 | From fca3561531f130ca686e31020f2b8f387cb5ee72 Mon Sep 17 00:00:00 2001 From: Sai Shanmukha Date: Thu, 9 Jul 2026 09:17:38 -0500 Subject: [PATCH 096/196] Empty commit to trigger CI From 3b6f1d6023ea6c6f6de96e785494f1dd8791ed6a Mon Sep 17 00:00:00 2001 From: Edward Malinowski Date: Thu, 9 Jul 2026 09:41:36 -0500 Subject: [PATCH 097/196] Bumped versions --- helm/access-backend/Chart.yaml | 2 +- helm/access-backend/README.md | 2 +- helm/audit/Chart.yaml | 2 +- helm/audit/README.md | 2 +- helm/cedar/Chart.yaml | 2 +- helm/cedar/README.md | 2 +- helm/cohort-middleware/Chart.yaml | 2 +- helm/cohort-middleware/README.md | 2 +- helm/common/Chart.yaml | 2 +- helm/common/README.md | 2 +- helm/datareplicate/Chart.yaml | 2 +- helm/datareplicate/README.md | 2 +- helm/dicom-server/Chart.yaml | 2 +- helm/dicom-server/README.md | 2 +- helm/fence/Chart.yaml | 2 +- helm/fence/README.md | 2 +- helm/gen3-user-data-library/Chart.yaml | 2 +- helm/gen3-user-data-library/README.md | 2 +- helm/gen3/Chart.yaml | 36 ++++++++++++------------ helm/gen3/README.md | 39 +++++++++++++------------- helm/hatchery/Chart.yaml | 2 +- helm/hatchery/README.md | 2 +- helm/indexd/Chart.yaml | 2 +- helm/indexd/README.md | 2 +- helm/manifestservice/Chart.yaml | 2 +- helm/manifestservice/README.md | 2 +- helm/metadata/Chart.yaml | 2 +- helm/metadata/README.md | 2 +- helm/orthanc/Chart.yaml | 2 +- helm/orthanc/README.md | 2 +- helm/sower/Chart.yaml | 2 +- helm/sower/README.md | 2 +- helm/ssjdispatcher/Chart.yaml | 2 +- helm/ssjdispatcher/README.md | 2 +- helm/wts/Chart.yaml | 2 +- helm/wts/README.md | 2 +- 36 files changed, 72 insertions(+), 71 deletions(-) diff --git a/helm/access-backend/Chart.yaml b/helm/access-backend/Chart.yaml index 210286dfb..5866ff8cb 100644 --- a/helm/access-backend/Chart.yaml +++ b/helm/access-backend/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.20 +version: 0.1.21 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/access-backend/README.md b/helm/access-backend/README.md index f8b4ed90d..30f68f5a1 100644 --- a/helm/access-backend/README.md +++ b/helm/access-backend/README.md @@ -1,6 +1,6 @@ # access-backend -![Version: 0.1.20](https://img.shields.io/badge/Version-0.1.20-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.6.1](https://img.shields.io/badge/AppVersion-1.6.1-informational?style=flat-square) +![Version: 0.1.21](https://img.shields.io/badge/Version-0.1.21-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.6.1](https://img.shields.io/badge/AppVersion-1.6.1-informational?style=flat-square) A Helm chart for Kubernetes diff --git a/helm/audit/Chart.yaml b/helm/audit/Chart.yaml index d3e1b9c5c..a3e32cf3b 100644 --- a/helm/audit/Chart.yaml +++ b/helm/audit/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.43 +version: 0.1.44 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/audit/README.md b/helm/audit/README.md index 8276e9fa5..e3cf0d017 100644 --- a/helm/audit/README.md +++ b/helm/audit/README.md @@ -1,6 +1,6 @@ # audit -![Version: 0.1.43](https://img.shields.io/badge/Version-0.1.43-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.44](https://img.shields.io/badge/Version-0.1.44-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for Kubernetes diff --git a/helm/cedar/Chart.yaml b/helm/cedar/Chart.yaml index 1658e0ec1..bb528bb01 100644 --- a/helm/cedar/Chart.yaml +++ b/helm/cedar/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.26 +version: 0.1.27 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/cedar/README.md b/helm/cedar/README.md index 170b9741e..e21b9ada6 100644 --- a/helm/cedar/README.md +++ b/helm/cedar/README.md @@ -1,6 +1,6 @@ # cedar -![Version: 0.1.26](https://img.shields.io/badge/Version-0.1.26-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.27](https://img.shields.io/badge/Version-0.1.27-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 cedar wrapper diff --git a/helm/cohort-middleware/Chart.yaml b/helm/cohort-middleware/Chart.yaml index df20e8914..84065898e 100644 --- a/helm/cohort-middleware/Chart.yaml +++ b/helm/cohort-middleware/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.22 +version: 0.1.23 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/cohort-middleware/README.md b/helm/cohort-middleware/README.md index 8b5e69dcf..4d19c1c02 100644 --- a/helm/cohort-middleware/README.md +++ b/helm/cohort-middleware/README.md @@ -1,6 +1,6 @@ # cohort-middleware -![Version: 0.1.22](https://img.shields.io/badge/Version-0.1.22-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.23](https://img.shields.io/badge/Version-0.1.23-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 cohort-middleware diff --git a/helm/common/Chart.yaml b/helm/common/Chart.yaml index 797834d62..83fcee7d4 100644 --- a/helm/common/Chart.yaml +++ b/helm/common/Chart.yaml @@ -15,7 +15,7 @@ type: library # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.36 +version: 0.1.37 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/common/README.md b/helm/common/README.md index 1438d8d0c..c9e00ec28 100644 --- a/helm/common/README.md +++ b/helm/common/README.md @@ -1,6 +1,6 @@ # common -![Version: 0.1.36](https://img.shields.io/badge/Version-0.1.36-informational?style=flat-square) ![Type: library](https://img.shields.io/badge/Type-library-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.37](https://img.shields.io/badge/Version-0.1.37-informational?style=flat-square) ![Type: library](https://img.shields.io/badge/Type-library-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for provisioning databases in gen3 diff --git a/helm/datareplicate/Chart.yaml b/helm/datareplicate/Chart.yaml index bfe8a0d0e..b0965f8c0 100644 --- a/helm/datareplicate/Chart.yaml +++ b/helm/datareplicate/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.21 +version: 0.1.22 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/datareplicate/README.md b/helm/datareplicate/README.md index 7f4e63118..d40846245 100644 --- a/helm/datareplicate/README.md +++ b/helm/datareplicate/README.md @@ -1,6 +1,6 @@ # datareplicate -![Version: 0.1.21](https://img.shields.io/badge/Version-0.1.21-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.22](https://img.shields.io/badge/Version-0.1.22-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 datareplicate diff --git a/helm/dicom-server/Chart.yaml b/helm/dicom-server/Chart.yaml index acaa6c980..618d7bcac 100644 --- a/helm/dicom-server/Chart.yaml +++ b/helm/dicom-server/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.31 +version: 0.1.32 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/dicom-server/README.md b/helm/dicom-server/README.md index 0f9a08d23..d949c33b1 100644 --- a/helm/dicom-server/README.md +++ b/helm/dicom-server/README.md @@ -1,6 +1,6 @@ # dicom-server -![Version: 0.1.31](https://img.shields.io/badge/Version-0.1.31-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.32](https://img.shields.io/badge/Version-0.1.32-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Dicom Server diff --git a/helm/fence/Chart.yaml b/helm/fence/Chart.yaml index 51d761e48..f71e67e79 100644 --- a/helm/fence/Chart.yaml +++ b/helm/fence/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.78 +version: 0.1.79 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/fence/README.md b/helm/fence/README.md index 5867fba2a..088636b29 100644 --- a/helm/fence/README.md +++ b/helm/fence/README.md @@ -1,6 +1,6 @@ # fence -![Version: 0.1.78](https://img.shields.io/badge/Version-0.1.78-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.79](https://img.shields.io/badge/Version-0.1.79-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Fence diff --git a/helm/gen3-user-data-library/Chart.yaml b/helm/gen3-user-data-library/Chart.yaml index f9ac80c11..28b313f2b 100644 --- a/helm/gen3-user-data-library/Chart.yaml +++ b/helm/gen3-user-data-library/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.15 +version: 0.1.16 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3-user-data-library/README.md b/helm/gen3-user-data-library/README.md index 81f7fa1af..e05c78e0b 100644 --- a/helm/gen3-user-data-library/README.md +++ b/helm/gen3-user-data-library/README.md @@ -1,6 +1,6 @@ # gen3-user-data-library -![Version: 0.1.15](https://img.shields.io/badge/Version-0.1.15-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: main](https://img.shields.io/badge/AppVersion-main-informational?style=flat-square) +![Version: 0.1.16](https://img.shields.io/badge/Version-0.1.16-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: main](https://img.shields.io/badge/AppVersion-main-informational?style=flat-square) A Helm chart for Kubernetes diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index 85617b262..2a15e7d9b 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -5,7 +5,7 @@ description: Helm chart to deploy Gen3 Data Commons # Dependencies dependencies: - name: access-backend - version: 0.1.20 + version: 0.1.21 repository: "file://../access-backend" condition: access-backend.enabled - name: ambassador @@ -21,7 +21,7 @@ dependencies: repository: "file://../argo-wrapper" condition: argo-wrapper.enabled - name: audit - version: 0.1.43 + version: 0.1.44 repository: "file://../audit" condition: audit.enabled - name: aws-es-proxy @@ -33,22 +33,22 @@ dependencies: repository: "file://../aws-sigv4-proxy" condition: aws-sigv4-proxy.enabled - name: cedar - version: 0.1.26 + version: 0.1.27 repository: "file://../cedar" condition: cedar.enabled - name: cohort-middleware - version: 0.1.22 + version: 0.1.23 repository: "file://../cohort-middleware" condition: cohort-middleware.enabled - name: common - version: 0.1.36 + version: 0.1.37 repository: file://../common - name: dashboard version: 0.1.21 repository: file://../dashboard condition: dashboard.enabled - name: datareplicate - version: 0.1.21 + version: 0.1.22 repository: "file://../datareplicate" condition: datareplicate.enabled - name: data-upload-cron @@ -68,7 +68,7 @@ dependencies: repository: "file://../frontend-framework" condition: frontend-framework.enabled - name: fence - version: 0.1.78 + version: 0.1.79 repository: "file://../fence" condition: fence.enabled - name: funnel @@ -76,7 +76,7 @@ dependencies: repository: "file://../funnel" condition: gen3-workflow.enabled - name: gen3-user-data-library - version: 0.1.15 + version: 0.1.16 repository: "file://../gen3-user-data-library" condition: gen3-user-data-library.enabled - name: gen3-workflow @@ -88,19 +88,19 @@ dependencies: repository: "file://../guppy" condition: guppy.enabled - name: hatchery - version: 0.1.69 + version: 0.1.70 repository: "file://../hatchery" condition: hatchery.enabled - name: indexd - version: 0.1.47 + version: 0.1.48 repository: "file://../indexd" condition: indexd.enabled - name: manifestservice - version: 0.1.42 + version: 0.1.43 repository: "file://../manifestservice" condition: manifestservice.enabled - name: metadata - version: 0.1.44 + version: 0.1.45 repository: "file://../metadata" condition: metadata.enabled - name: peregrine @@ -124,15 +124,15 @@ dependencies: repository: "file://../sheepdog" condition: sheepdog.enabled - name: ssjdispatcher - version: 0.1.47 + version: 0.1.48 repository: "file://../ssjdispatcher" condition: ssjdispatcher.enabled - name: sower - version: 0.1.46 + version: 0.1.47 condition: sower.enabled repository: "file://../sower" - name: wts - version: 0.1.40 + version: 0.1.41 repository: "file://../wts" condition: wts.enabled - name: gen3-network-policies @@ -140,7 +140,7 @@ dependencies: repository: "file://../gen3-network-policies" condition: global.netPolicy.enabled - name: dicom-server - version: 0.1.31 + version: 0.1.32 repository: file://../dicom-server condition: dicom-server.enabled - name: ohif-viewer @@ -148,7 +148,7 @@ dependencies: repository: file://../ohif-viewer condition: ohif-viewer.enabled - name: orthanc - version: 0.1.15 + version: 0.1.16 repository: file://../orthanc condition: orthanc.enabled - name: gen3-analysis @@ -197,7 +197,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.60 +version: 0.3.61 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index d60ce8d74..19423a8dc 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,6 +1,6 @@ # gen3 -![Version: 0.3.60](https://img.shields.io/badge/Version-0.3.60-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.3.61](https://img.shields.io/badge/Version-0.3.61-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons @@ -18,47 +18,47 @@ Helm chart to deploy Gen3 Data Commons | Repository | Name | Version | |------------|------|---------| -| file://../access-backend | access-backend | 0.1.20 | +| file://../access-backend | access-backend | 0.1.21 | | file://../ambassador | ambassador | 0.1.37 | | file://../arborist | arborist | 0.1.34 | | file://../argo-wrapper | argo-wrapper | 0.1.30 | -| file://../audit | audit | 0.1.43 | +| file://../audit | audit | 0.1.44 | | file://../aws-es-proxy | aws-es-proxy | 0.1.41 | | file://../aws-sigv4-proxy | aws-sigv4-proxy | 0.1.2 | -| file://../cedar | cedar | 0.1.26 | -| file://../cohort-middleware | cohort-middleware | 0.1.22 | -| file://../common | common | 0.1.36 | +| file://../cedar | cedar | 0.1.27 | +| file://../cohort-middleware | cohort-middleware | 0.1.23 | +| file://../common | common | 0.1.37 | | file://../dashboard | dashboard | 0.1.21 | | file://../data-upload-cron | data-upload-cron | 0.1.6 | -| file://../datareplicate | datareplicate | 0.1.21 | -| file://../dicom-server | dicom-server | 0.1.31 | +| file://../datareplicate | datareplicate | 0.1.22 | +| file://../dicom-server | dicom-server | 0.1.32 | | file://../embedding-management-service | embedding-management-service | 0.1.7 | | file://../etl | etl | 0.1.23 | -| file://../fence | fence | 0.1.78 | +| file://../fence | fence | 0.1.79 | | file://../frontend-framework | frontend-framework | 0.1.29 | | file://../funnel | funnel | 0.1.26 | | file://../gen3-analysis | gen3-analysis | 0.1.12 | | file://../gen3-network-policies | gen3-network-policies | 0.1.4 | -| file://../gen3-user-data-library | gen3-user-data-library | 0.1.15 | +| file://../gen3-user-data-library | gen3-user-data-library | 0.1.16 | | file://../gen3-workflow | gen3-workflow | 0.1.22 | | file://../guppy | guppy | 0.1.37 | -| file://../hatchery | hatchery | 0.1.69 | -| file://../indexd | indexd | 0.1.47 | -| file://../manifestservice | manifestservice | 0.1.42 | -| file://../metadata | metadata | 0.1.44 | +| file://../hatchery | hatchery | 0.1.70 | +| file://../indexd | indexd | 0.1.48 | +| file://../manifestservice | manifestservice | 0.1.43 | +| file://../metadata | metadata | 0.1.45 | | file://../neuvector | neuvector | 0.1.2 | | file://../ohdsi-atlas | ohdsi-atlas | 0.1.2 | | file://../ohdsi-webapi | ohdsi-webapi | 0.1.5 | | file://../ohif-viewer | ohif-viewer | 0.1.14 | -| file://../orthanc | orthanc | 0.1.15 | +| file://../orthanc | orthanc | 0.1.16 | | file://../peregrine | peregrine | 0.1.42 | | file://../portal | portal | 0.1.60 | | file://../requestor | requestor | 0.1.34 | | file://../revproxy | revproxy | 0.1.61 | | file://../sheepdog | sheepdog | 0.1.42 | -| file://../sower | sower | 0.1.46 | -| file://../ssjdispatcher | ssjdispatcher | 0.1.47 | -| file://../wts | wts | 0.1.40 | +| file://../sower | sower | 0.1.47 | +| file://../ssjdispatcher | ssjdispatcher | 0.1.48 | +| file://../wts | wts | 0.1.41 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | | https://helm.elastic.co | elasticsearch | 7.10.2 | @@ -155,7 +155,8 @@ Helm chart to deploy Gen3 Data Commons | global.dictionaryUrl | string | `"https://s3.amazonaws.com/dictionary-artifacts/datadictionary/develop/schema.json"` | URL of the data dictionary. | | global.dispatcherJobNum | int | `"10"` | Number of dispatcher jobs. | | global.environment | string | `"default"` | Environment name. This should be the same as vpcname if you're doing an AWS deployment. Currently this is being used to share ALB's if you have multiple namespaces in same cluster. | -| global.externalSecrets | map | `{"clusterSecretStoreRef":"","createLocalK8sSecret":false,"createSlackWebhookSecret":false,"deploy":false,"slackWebhookSecretName":""}` | External Secrets settings. | +| global.externalSecrets | map | `{"apiVersion":"external-secrets.io/v1beta1","clusterSecretStoreRef":"","createLocalK8sSecret":false,"createSlackWebhookSecret":false,"deploy":false,"slackWebhookSecretName":""}` | External Secrets settings. | +| global.externalSecrets.apiVersion | string | `"external-secrets.io/v1beta1"` | API version to use for External Secrets resources. Defaults to v1beta1 when unset. | | global.externalSecrets.createLocalK8sSecret | bool | `false` | Will create the databases and store the creds in Kubernetes Secrets even if externalSecrets is deployed. Useful if you want to use ExternalSecrets for other secrets besides db secrets. | | global.externalSecrets.createSlackWebhookSecret | bool | `false` | Will create a Kubernetes Secret for the slack webhook. | | global.externalSecrets.deploy | bool | `false` | Will use ExternalSecret resources to pull secrets from Secrets Manager instead of creating them locally. Be cautious as this will override secrets you have deployed. | diff --git a/helm/hatchery/Chart.yaml b/helm/hatchery/Chart.yaml index a555dade4..a32dff598 100644 --- a/helm/hatchery/Chart.yaml +++ b/helm/hatchery/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.69 +version: 0.1.70 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/hatchery/README.md b/helm/hatchery/README.md index b9c3f3306..1690e685b 100644 --- a/helm/hatchery/README.md +++ b/helm/hatchery/README.md @@ -1,6 +1,6 @@ # hatchery -![Version: 0.1.69](https://img.shields.io/badge/Version-0.1.69-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.70](https://img.shields.io/badge/Version-0.1.70-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Hatchery diff --git a/helm/indexd/Chart.yaml b/helm/indexd/Chart.yaml index 8645d8899..47be34377 100644 --- a/helm/indexd/Chart.yaml +++ b/helm/indexd/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.47 +version: 0.1.48 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/indexd/README.md b/helm/indexd/README.md index d6fedcd3a..90f97432f 100644 --- a/helm/indexd/README.md +++ b/helm/indexd/README.md @@ -1,6 +1,6 @@ # indexd -![Version: 0.1.47](https://img.shields.io/badge/Version-0.1.47-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.48](https://img.shields.io/badge/Version-0.1.48-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 indexd diff --git a/helm/manifestservice/Chart.yaml b/helm/manifestservice/Chart.yaml index b14ea2619..570862b61 100644 --- a/helm/manifestservice/Chart.yaml +++ b/helm/manifestservice/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.42 +version: 0.1.43 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/manifestservice/README.md b/helm/manifestservice/README.md index e761bd077..b4fe0f1fb 100644 --- a/helm/manifestservice/README.md +++ b/helm/manifestservice/README.md @@ -1,6 +1,6 @@ # manifestservice -![Version: 0.1.42](https://img.shields.io/badge/Version-0.1.42-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.43](https://img.shields.io/badge/Version-0.1.43-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for Kubernetes diff --git a/helm/metadata/Chart.yaml b/helm/metadata/Chart.yaml index 92caa5d85..c7eb02ce4 100644 --- a/helm/metadata/Chart.yaml +++ b/helm/metadata/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.44 +version: 0.1.45 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/metadata/README.md b/helm/metadata/README.md index c78de6546..df9074e60 100644 --- a/helm/metadata/README.md +++ b/helm/metadata/README.md @@ -1,6 +1,6 @@ # metadata -![Version: 0.1.44](https://img.shields.io/badge/Version-0.1.44-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.45](https://img.shields.io/badge/Version-0.1.45-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Metadata Service diff --git a/helm/orthanc/Chart.yaml b/helm/orthanc/Chart.yaml index dd0e5e5be..9ae57602a 100644 --- a/helm/orthanc/Chart.yaml +++ b/helm/orthanc/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.15 +version: 0.1.16 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/orthanc/README.md b/helm/orthanc/README.md index 6dd73a6ad..fc534a0e4 100644 --- a/helm/orthanc/README.md +++ b/helm/orthanc/README.md @@ -1,6 +1,6 @@ # orthanc -![Version: 0.1.15](https://img.shields.io/badge/Version-0.1.15-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.16](https://img.shields.io/badge/Version-0.1.16-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Dicom Server diff --git a/helm/sower/Chart.yaml b/helm/sower/Chart.yaml index 96408614e..e64a4f575 100644 --- a/helm/sower/Chart.yaml +++ b/helm/sower/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.46 +version: 0.1.47 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/sower/README.md b/helm/sower/README.md index 00ba738c5..0ca25fc50 100644 --- a/helm/sower/README.md +++ b/helm/sower/README.md @@ -1,6 +1,6 @@ # sower -![Version: 0.1.46](https://img.shields.io/badge/Version-0.1.46-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.47](https://img.shields.io/badge/Version-0.1.47-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 sower diff --git a/helm/ssjdispatcher/Chart.yaml b/helm/ssjdispatcher/Chart.yaml index ee4f425c1..cddf17f6e 100644 --- a/helm/ssjdispatcher/Chart.yaml +++ b/helm/ssjdispatcher/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.47 +version: 0.1.48 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/ssjdispatcher/README.md b/helm/ssjdispatcher/README.md index c606a0ff0..1be6baf27 100644 --- a/helm/ssjdispatcher/README.md +++ b/helm/ssjdispatcher/README.md @@ -1,6 +1,6 @@ # ssjdispatcher -![Version: 0.1.47](https://img.shields.io/badge/Version-0.1.47-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.48](https://img.shields.io/badge/Version-0.1.48-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 ssjdispatcher diff --git a/helm/wts/Chart.yaml b/helm/wts/Chart.yaml index 6b471f60f..64e172422 100644 --- a/helm/wts/Chart.yaml +++ b/helm/wts/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.40 +version: 0.1.41 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/wts/README.md b/helm/wts/README.md index 3b4497d61..7ee9c5447 100644 --- a/helm/wts/README.md +++ b/helm/wts/README.md @@ -1,6 +1,6 @@ # wts -![Version: 0.1.40](https://img.shields.io/badge/Version-0.1.40-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.41](https://img.shields.io/badge/Version-0.1.41-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 workspace token service From 3856b2531a474ef91f2072dbd949e3181581d7a6 Mon Sep 17 00:00:00 2001 From: mark xiao Date: Thu, 9 Jul 2026 09:43:04 -0500 Subject: [PATCH 098/196] update fence config --- helm/fence/README.md | 2 +- helm/fence/values.yaml | 6 ++++++ 2 files changed, 7 insertions(+), 1 deletion(-) diff --git a/helm/fence/README.md b/helm/fence/README.md index 670a21bed..642696dfa 100644 --- a/helm/fence/README.md +++ b/helm/fence/README.md @@ -15,7 +15,7 @@ A Helm chart for gen3 Fence | Key | Type | Default | Description | |-----|------|---------|-------------| -| FENCE_CONFIG | map | `{"ACCESS_TOKEN_COOKIE_NAME":"access_token","ACCESS_TOKEN_EXPIRES_IN":1200,"ALLOWED_GEN3_EMBEDDINGS_BULK_URL_PREFIXES":null,"ALLOWED_USER_SERVICE_ACCOUNT_DOMAINS":["developer.gserviceaccount.com","appspot.gserviceaccount.com","iam.gserviceaccount.com"],"ALLOW_GOOGLE_LINKING":true,"ALLOW_NEW_USER_ON_LOGIN":true,"APPLICATION_ROOT":"/user","APP_NAME":"Gen3 Data Commons","ARBORIST":"http://arborist-service","ASSUME_ROLE_CACHE_SECONDS":1800,"AUDIT_SERVICE":"http://audit-service","AUTHLIB_INSECURE_TRANSPORT":true,"AWS_CREDENTIALS":{},"AZ_BLOB_CONTAINER_URL":"https://myfakeblob.blob.core.windows.net/my-fake-container/","AZ_BLOB_CREDENTIALS":null,"BILLING_PROJECT_FOR_SA_CREDS":null,"BILLING_PROJECT_FOR_SIGNED_URLS":null,"CIRRUS_CFG":{"GOOGLE_ADMIN_EMAIL":"","GOOGLE_API_KEY":"","GOOGLE_APPLICATION_CREDENTIALS":"","GOOGLE_CLOUD_IDENTITY_ADMIN_EMAIL":"","GOOGLE_IDENTITY_DOMAIN":"","GOOGLE_PROJECT_ID":"","GOOGLE_STORAGE_CREDS":""},"CLIENT_ALLOWED_SCOPES":["openid","user","data","google_credentials","google_service_account","google_link","ga4gh_passport_v1"],"DATA_UPLOAD_BUCKET":"bucket1","DBGAP_ACCESSION_WITH_CONSENT_REGEX":"(?Pphs[0-9]+)(.(?Pv[0-9]+)){0,1}(.(?Pp[0-9]+)){0,1}.(?Pc[0-9]+)","DEBUG":false,"DEFAULT_LOGIN_IDP":"google","DEFAULT_LOGIN_URL":"{{BASE_URL}}/login/google","DEV_LOGIN_COOKIE_NAME":"dev_login","DREAM_CHALLENGE_GROUP":"DREAM","DREAM_CHALLENGE_TEAM":"DREAM","EMAIL_SERVER":"localhost","ENABLED_IDENTITY_PROVIDERS":{},"ENABLE_AUDIT_LOGS":{"login":false,"presigned_url":false},"ENABLE_AUTOMATIC_BILLING_PERMISSION_SA_CREDS":false,"ENABLE_AUTOMATIC_BILLING_PERMISSION_SIGNED_URLS":false,"ENABLE_CSRF_PROTECTION":true,"ENABLE_DB_MIGRATION":true,"ENABLE_PROMETHEUS_METRICS":false,"ENABLE_VISA_UPDATE_CRON":false,"ENCRYPTION_KEY":"REPLACEME","GA4GH_VISA_ISSUER_ALLOWLIST":["{{BASE_URL}}","https://sts.nih.gov","https://stsstg.nih.gov"],"GEN3_EMBEDDINGS_API_REGEX":"/vectorstore/collections/(?P[^/]+)/embeddings/(?P[^/]+)","GEN3_PASSPORT_EXPIRES_IN":43200,"GLOBAL_PARSE_VISAS_ON_LOGIN":false,"GOOGLE_ACCOUNT_ACCESS_EXPIRES_IN":86400,"GOOGLE_BULK_UPDATES":false,"GOOGLE_GROUP_PREFIX":"","GOOGLE_MANAGED_SERVICE_ACCOUNT_DOMAINS":["dataflow-service-producer-prod.iam.gserviceaccount.com","cloudbuild.gserviceaccount.com","cloud-ml.google.com.iam.gserviceaccount.com","container-engine-robot.iam.gserviceaccount.com","dataflow-service-producer-prod.iam.gserviceaccount.com","sourcerepo-service-accounts.iam.gserviceaccount.com","dataproc-accounts.iam.gserviceaccount.com","gae-api-prod.google.com.iam.gserviceaccount.com","genomics-api.google.com.iam.gserviceaccount.com","containerregistry.iam.gserviceaccount.com","container-analysis.iam.gserviceaccount.com","cloudservices.gserviceaccount.com","stackdriver-service.iam.gserviceaccount.com","appspot.gserviceaccount.com","partnercontent.gserviceaccount.com","trifacta-gcloud-prod.iam.gserviceaccount.com","gcf-admin-robot.iam.gserviceaccount.com","compute-system.iam.gserviceaccount.com","gcp-sa-websecurityscanner.iam.gserviceaccount.com","storage-transfer-service.iam.gserviceaccount.com","firebase-sa-management.iam.gserviceaccount.com","firebase-rules.iam.gserviceaccount.com","gcp-sa-cloudbuild.iam.gserviceaccount.com","gcp-sa-automl.iam.gserviceaccount.com","gcp-sa-datalabeling.iam.gserviceaccount.com","gcp-sa-cloudscheduler.iam.gserviceaccount.com"],"GOOGLE_SERVICE_ACCOUNT_KEY_FOR_URL_SIGNING_EXPIRES_IN":2592000,"GOOGLE_SERVICE_ACCOUNT_PREFIX":"","GOOGLE_USER_SERVICE_ACCOUNT_ACCESS_EXPIRES_IN":604800,"GUN_MAIL":{"datacommons.io":{"api_key":"","api_url":"https://api.mailgun.net/v3/mailgun.example.com","default_login":"postmaster@mailgun.example.com","smtp_hostname":"smtp.mailgun.org","smtp_password":""}},"HTTP_PROXY":{"host":null,"port":3128},"INDEXD":"http://indexd-service","INDEXD_PASSWORD":"","INDEXD_USERNAME":"fence","ITRUST_GLOBAL_LOGOUT":"https://auth.nih.gov/siteminderagent/smlogout.asp?mode=nih&AppReturnUrl=","LOGIN_OPTIONS":[{"desc":"description","idp":"google","name":"Login from Google"}],"LOGIN_REDIRECT_WHITELIST":[],"MAX_ACCESS_TOKEN_TTL":3600,"MAX_API_KEY_TTL":2592000,"MAX_PRESIGNED_URL_TTL":3600,"MAX_ROLE_SESSION_INCREASE":false,"MOCK_AUTH":false,"MOCK_GOOGLE_AUTH":false,"MOCK_STORAGE":false,"OAUTH2_JWT_ALG":"RS256","OAUTH2_JWT_ENABLED":true,"OAUTH2_JWT_ISS":"{{BASE_URL}}","OAUTH2_PROVIDER_ERROR_URI":"/api/oauth2/errors","OAUTH2_TOKEN_EXPIRES_IN":{"authorization_code":1200,"implicit":1200},"OPENID_CONNECT":{"cilogon":{"client_id":"","client_secret":"","discovery_url":"https://cilogon.org/.well-known/openid-configuration","mock":false,"mock_default_user":"http://cilogon.org/serverT/users/64703","redirect_url":"{{BASE_URL}}/login/cilogon/login/","scope":"openid email profile"},"cognito":{"client_id":"","client_secret":"","discovery_url":"https://cognito-idp.{REGION}.amazonaws.com/{USER-POOL-ID}/.well-known/openid-configuration","redirect_url":"{{BASE_URL}}/login/cognito/login/","scope":"openid email"},"fence":{"access_token_url":"{{api_base_url}}/oauth2/token","api_base_url":"","authorize_url":"{{api_base_url}}/oauth2/authorize","client_id":"","client_kwargs":{"redirect_uri":"{{BASE_URL}}/login/fence/login","scope":"openid"},"client_secret":"","mock":false,"mock_default_user":"test@example.com","name":"","refresh_token_url":"{{api_base_url}}/oauth2/token","shibboleth_discovery_url":"https://login.bionimbus.org/Shibboleth.sso/DiscoFeed"},"generic_oidc_idp":{"client_id":"","client_secret":"","discovery":{"authorization_endpoint":"","jwks_uri":"","token_endpoint":""},"discovery_url":"https://server.com/.well-known/openid-configuration","email_field":"","name":"some_idp","redirect_url":"{{BASE_URL}}/login/some_idp/login","scope":"","user_id_field":""},"google":{"client_id":"","client_secret":"","discovery_url":"https://accounts.google.com/.well-known/openid-configuration","mock":"","mock_default_user":"test@example.com","redirect_url":"{{BASE_URL}}/login/google/login/","scope":"openid email"},"microsoft":{"client_id":"","client_secret":"","discovery_url":"https://login.microsoftonline.com/organizations/v2.0/.well-known/openid-configuration","mock":false,"mock_default_user":"test@example.com","redirect_url":"{{BASE_URL}}/login/microsoft/login/","scope":"openid email"},"okta":{"client_id":"","client_secret":"","discovery_url":"","redirect_url":"{{BASE_URL}}/login/okta/login/","scope":"openid email"},"orcid":{"client_id":"","client_secret":"","discovery_url":"https://orcid.org/.well-known/openid-configuration","mock":false,"mock_default_user":"0000-0002-2601-8132","redirect_url":"{{BASE_URL}}/login/orcid/login/","scope":"openid"},"ras":{"client_id":"","client_secret":"","discovery_url":"https://sts.nih.gov/.well-known/openid-configuration","mock":false,"mock_default_user":"test@example.com","redirect_url":"{{BASE_URL}}/login/ras/callback","scope":"openid email profile ga4gh_passport_v1"},"shibboleth":{"client_id":"","client_secret":"","redirect_url":"{{BASE_URL}}/login/shib/login"},"synapse":{"client_id":"","client_secret":"","discovery_url":"","redirect_url":"","scope":"openid"}},"OVERRIDE_NGINX_RATE_LIMIT":18,"PRIVACY_POLICY_URL":null,"PROBLEM_USER_EMAIL_NOTIFICATION":{"admin":["admin@example.edu"],"content":"The Data Commons Framework utilizes dbGaP for data access authorization. Another member of a Google project you belong to ({}) is attempting to register a service account to the following additional datasets ({}). Please contact dbGaP to request access.\n","domain":"example.com","from":"do-not-reply@example.com","subject":"Account access error notification"},"PUSH_AUDIT_LOGS_CONFIG":{"aws_sqs_config":{"aws_cred":null,"region":null,"sqs_url":null},"type":"aws_sqs"},"RAS_REFRESH_EXPIRATION":1296000,"RAS_USERINFO_ENDPOINT":"/openid/connect/v1.1/userinfo","REFRESH_TOKEN_EXPIRES_IN":2592000,"REGISTERED_USERS_GROUP":"","REGISTER_USERS_ON":false,"REMOVE_SERVICE_ACCOUNT_EMAIL_NOTIFICATION":{"admin":["admin@example.edu"],"content":"Service accounts were removed from access control data because some users or service accounts of GCP Project {} are not authorized to access the data sets associated to the service accounts, or do not adhere to the security policies.\n","domain":"example.com","enable":false,"from":"do-not-reply@example.com","subject":"User service account removal notification"},"RENEW_ACCESS_TOKEN_BEFORE_EXPIRATION":false,"S3_BUCKETS":{},"SEND_FROM":"example@gmail.com","SEND_TO":"example@gmail.com","SERVICE_ACCOUNT_LIMIT":6,"SESSION_ALLOWED_SCOPES":["openid","user","credentials","data","admin","google_credentials","google_service_account","google_link","ga4gh_passport_v1"],"SESSION_COOKIE_DOMAIN":null,"SESSION_COOKIE_NAME":"fence","SESSION_COOKIE_SECURE":true,"SESSION_LIFETIME":28800,"SESSION_TIMEOUT":1800,"SHIBBOLETH_HEADER":"persistent_id","SSO_URL":"https://auth.nih.gov/affwebservices/public/saml2sso?SPID={{BASE_URL}}/shibboleth&RelayState=","STORAGE_CREDENTIALS":{},"SUPPORT_EMAIL_FOR_ERRORS":null,"SYNAPSE_AUTHZ_TTL":86400,"SYNAPSE_DISCOVERY_URL":null,"SYNAPSE_JWKS_URI":null,"SYNAPSE_URI":"https://repo-prod.prod.sagebase.org/auth/v1","TOKEN_PROJECTS_CUTOFF":10,"USERSYNC":{"fallback_to_dbgap_sftp":false,"sync_from_visas":false,"visa_types":{"ras":["https://ras.nih.gov/visas/v1","https://ras.nih.gov/visas/v1.1"]}},"USER_ALLOWED_SCOPES":["fence","openid","user","data","admin","google_credentials","google_service_account","google_link","ga4gh_passport_v1"],"WHITE_LISTED_GOOGLE_PARENT_ORGS":[],"WHITE_LISTED_SERVICE_ACCOUNT_EMAILS":[],"WTF_CSRF_SECRET_KEY":"{{ENCRYPTION_KEY}}","dbGaP":[{"decrypt_key":"","enable_common_exchange_area_access":false,"info":{"host":"","password":"","port":22,"proxy":"","username":""},"parse_consent_code":true,"protocol":"sftp","study_common_exchange_areas":{"example":"test_common_exchange_area"},"study_to_resource_namespaces":{"_default":["/"],"test_common_exchange_area":["/dbgap/"]}}]}` | Private configuration settings for Fence app | +| FENCE_CONFIG | map | `{"ACCESS_TOKEN_COOKIE_NAME":"access_token","ACCESS_TOKEN_EXPIRES_IN":1200,"ALLOWED_GEN3_EMBEDDINGS_BULK_URL_PREFIXES":null,"ALLOWED_USER_SERVICE_ACCOUNT_DOMAINS":["developer.gserviceaccount.com","appspot.gserviceaccount.com","iam.gserviceaccount.com"],"ALLOW_GOOGLE_LINKING":true,"ALLOW_NEW_USER_ON_LOGIN":true,"APPLICATION_ROOT":"/user","APP_NAME":"Gen3 Data Commons","ARBORIST":"http://arborist-service","ASSUME_ROLE_CACHE_SECONDS":1800,"AUDIT_SERVICE":"http://audit-service","AUTHLIB_INSECURE_TRANSPORT":true,"AWS_CREDENTIALS":{},"AZ_BLOB_CONTAINER_URL":"https://myfakeblob.blob.core.windows.net/my-fake-container/","AZ_BLOB_CREDENTIALS":null,"BILLING_PROJECT_FOR_SA_CREDS":null,"BILLING_PROJECT_FOR_SIGNED_URLS":null,"CIRRUS_CFG":{"GOOGLE_ADMIN_EMAIL":"","GOOGLE_API_KEY":"","GOOGLE_APPLICATION_CREDENTIALS":"","GOOGLE_CLOUD_IDENTITY_ADMIN_EMAIL":"","GOOGLE_IDENTITY_DOMAIN":"","GOOGLE_PROJECT_ID":"","GOOGLE_STORAGE_CREDS":""},"CLIENT_ALLOWED_SCOPES":["openid","user","data","google_credentials","google_service_account","google_link","ga4gh_passport_v1"],"DATA_UPLOAD_BUCKET":"bucket1","DBGAP_ACCESSION_WITH_CONSENT_REGEX":"(?Pphs[0-9]+)(.(?Pv[0-9]+)){0,1}(.(?Pp[0-9]+)){0,1}.(?Pc[0-9]+)","DEBUG":false,"DEFAULT_LOGIN_IDP":"google","DEFAULT_LOGIN_URL":"{{BASE_URL}}/login/google","DEV_LOGIN_COOKIE_NAME":"dev_login","DREAM_CHALLENGE_GROUP":"DREAM","DREAM_CHALLENGE_TEAM":"DREAM","EMAIL_SERVER":"localhost","ENABLED_IDENTITY_PROVIDERS":{},"ENABLE_AUDIT_LOGS":{"login":false,"presigned_url":false},"ENABLE_AUTOMATIC_BILLING_PERMISSION_SA_CREDS":false,"ENABLE_AUTOMATIC_BILLING_PERMISSION_SIGNED_URLS":false,"ENABLE_CSRF_PROTECTION":true,"ENABLE_DB_MIGRATION":true,"ENABLE_PROMETHEUS_METRICS":false,"ENABLE_VISA_UPDATE_CRON":false,"ENCRYPTION_KEY":"REPLACEME","GA4GH_VISA_ISSUER_ALLOWLIST":["{{BASE_URL}}","https://sts.nih.gov","https://stsstg.nih.gov"],"GEN3_EMBEDDINGS_API_REGEX":"/vectorstore/collections/(?P[^/]+)/embeddings/(?P[^/]+)","GEN3_PASSPORT_EXPIRES_IN":43200,"GLOBAL_PARSE_VISAS_ON_LOGIN":false,"GOOGLE_ACCOUNT_ACCESS_EXPIRES_IN":86400,"GOOGLE_BULK_UPDATES":false,"GOOGLE_GROUP_PREFIX":"","GOOGLE_MANAGED_SERVICE_ACCOUNT_DOMAINS":["dataflow-service-producer-prod.iam.gserviceaccount.com","cloudbuild.gserviceaccount.com","cloud-ml.google.com.iam.gserviceaccount.com","container-engine-robot.iam.gserviceaccount.com","dataflow-service-producer-prod.iam.gserviceaccount.com","sourcerepo-service-accounts.iam.gserviceaccount.com","dataproc-accounts.iam.gserviceaccount.com","gae-api-prod.google.com.iam.gserviceaccount.com","genomics-api.google.com.iam.gserviceaccount.com","containerregistry.iam.gserviceaccount.com","container-analysis.iam.gserviceaccount.com","cloudservices.gserviceaccount.com","stackdriver-service.iam.gserviceaccount.com","appspot.gserviceaccount.com","partnercontent.gserviceaccount.com","trifacta-gcloud-prod.iam.gserviceaccount.com","gcf-admin-robot.iam.gserviceaccount.com","compute-system.iam.gserviceaccount.com","gcp-sa-websecurityscanner.iam.gserviceaccount.com","storage-transfer-service.iam.gserviceaccount.com","firebase-sa-management.iam.gserviceaccount.com","firebase-rules.iam.gserviceaccount.com","gcp-sa-cloudbuild.iam.gserviceaccount.com","gcp-sa-automl.iam.gserviceaccount.com","gcp-sa-datalabeling.iam.gserviceaccount.com","gcp-sa-cloudscheduler.iam.gserviceaccount.com"],"GOOGLE_SERVICE_ACCOUNT_KEY_FOR_URL_SIGNING_EXPIRES_IN":2592000,"GOOGLE_SERVICE_ACCOUNT_PREFIX":"","GOOGLE_USER_SERVICE_ACCOUNT_ACCESS_EXPIRES_IN":604800,"GUN_MAIL":{"datacommons.io":{"api_key":"","api_url":"https://api.mailgun.net/v3/mailgun.example.com","default_login":"postmaster@mailgun.example.com","smtp_hostname":"smtp.mailgun.org","smtp_password":""}},"HTTP_PROXY":{"host":null,"port":3128},"INDEXD":"http://indexd-service","INDEXD_PASSWORD":"","INDEXD_USERNAME":"fence","ITRUST_GLOBAL_LOGOUT":"https://auth.nih.gov/siteminderagent/smlogout.asp?mode=nih&AppReturnUrl=","LOGIN_OPTIONS":[{"desc":"description","idp":"google","name":"Login from Google"}],"LOGIN_REDIRECT_WHITELIST":[],"MAX_ACCESS_TOKEN_TTL":3600,"MAX_API_KEY_TTL":2592000,"MAX_BULK_CONTENT_GUIDS_COUNT":500,"MAX_PRESIGNED_URL_TTL":3600,"MAX_ROLE_SESSION_INCREASE":false,"MOCK_AUTH":false,"MOCK_GOOGLE_AUTH":false,"MOCK_STORAGE":false,"OAUTH2_JWT_ALG":"RS256","OAUTH2_JWT_ENABLED":true,"OAUTH2_JWT_ISS":"{{BASE_URL}}","OAUTH2_PROVIDER_ERROR_URI":"/api/oauth2/errors","OAUTH2_TOKEN_EXPIRES_IN":{"authorization_code":1200,"implicit":1200},"OPENID_CONNECT":{"cilogon":{"client_id":"","client_secret":"","discovery_url":"https://cilogon.org/.well-known/openid-configuration","mock":false,"mock_default_user":"http://cilogon.org/serverT/users/64703","redirect_url":"{{BASE_URL}}/login/cilogon/login/","scope":"openid email profile"},"cognito":{"client_id":"","client_secret":"","discovery_url":"https://cognito-idp.{REGION}.amazonaws.com/{USER-POOL-ID}/.well-known/openid-configuration","redirect_url":"{{BASE_URL}}/login/cognito/login/","scope":"openid email"},"fence":{"access_token_url":"{{api_base_url}}/oauth2/token","api_base_url":"","authorize_url":"{{api_base_url}}/oauth2/authorize","client_id":"","client_kwargs":{"redirect_uri":"{{BASE_URL}}/login/fence/login","scope":"openid"},"client_secret":"","mock":false,"mock_default_user":"test@example.com","name":"","refresh_token_url":"{{api_base_url}}/oauth2/token","shibboleth_discovery_url":"https://login.bionimbus.org/Shibboleth.sso/DiscoFeed"},"generic_oidc_idp":{"client_id":"","client_secret":"","discovery":{"authorization_endpoint":"","jwks_uri":"","token_endpoint":""},"discovery_url":"https://server.com/.well-known/openid-configuration","email_field":"","name":"some_idp","redirect_url":"{{BASE_URL}}/login/some_idp/login","scope":"","user_id_field":""},"google":{"client_id":"","client_secret":"","discovery_url":"https://accounts.google.com/.well-known/openid-configuration","mock":"","mock_default_user":"test@example.com","redirect_url":"{{BASE_URL}}/login/google/login/","scope":"openid email"},"microsoft":{"client_id":"","client_secret":"","discovery_url":"https://login.microsoftonline.com/organizations/v2.0/.well-known/openid-configuration","mock":false,"mock_default_user":"test@example.com","redirect_url":"{{BASE_URL}}/login/microsoft/login/","scope":"openid email"},"okta":{"client_id":"","client_secret":"","discovery_url":"","redirect_url":"{{BASE_URL}}/login/okta/login/","scope":"openid email"},"orcid":{"client_id":"","client_secret":"","discovery_url":"https://orcid.org/.well-known/openid-configuration","mock":false,"mock_default_user":"0000-0002-2601-8132","redirect_url":"{{BASE_URL}}/login/orcid/login/","scope":"openid"},"ras":{"client_id":"","client_secret":"","discovery_url":"https://sts.nih.gov/.well-known/openid-configuration","mock":false,"mock_default_user":"test@example.com","redirect_url":"{{BASE_URL}}/login/ras/callback","scope":"openid email profile ga4gh_passport_v1"},"shibboleth":{"client_id":"","client_secret":"","redirect_url":"{{BASE_URL}}/login/shib/login"},"synapse":{"client_id":"","client_secret":"","discovery_url":"","redirect_url":"","scope":"openid"}},"OVERRIDE_NGINX_RATE_LIMIT":18,"PRIVACY_POLICY_URL":null,"PROBLEM_USER_EMAIL_NOTIFICATION":{"admin":["admin@example.edu"],"content":"The Data Commons Framework utilizes dbGaP for data access authorization. Another member of a Google project you belong to ({}) is attempting to register a service account to the following additional datasets ({}). Please contact dbGaP to request access.\n","domain":"example.com","from":"do-not-reply@example.com","subject":"Account access error notification"},"PUSH_AUDIT_LOGS_CONFIG":{"aws_sqs_config":{"aws_cred":null,"region":null,"sqs_url":null},"type":"aws_sqs"},"RAS_REFRESH_EXPIRATION":1296000,"RAS_USERINFO_ENDPOINT":"/openid/connect/v1.1/userinfo","REFRESH_TOKEN_EXPIRES_IN":2592000,"REGISTERED_USERS_GROUP":"","REGISTER_USERS_ON":false,"REMOVE_SERVICE_ACCOUNT_EMAIL_NOTIFICATION":{"admin":["admin@example.edu"],"content":"Service accounts were removed from access control data because some users or service accounts of GCP Project {} are not authorized to access the data sets associated to the service accounts, or do not adhere to the security policies.\n","domain":"example.com","enable":false,"from":"do-not-reply@example.com","subject":"User service account removal notification"},"RENEW_ACCESS_TOKEN_BEFORE_EXPIRATION":false,"S3_BUCKETS":{},"SEND_FROM":"example@gmail.com","SEND_TO":"example@gmail.com","SERVICE_ACCOUNT_LIMIT":6,"SESSION_ALLOWED_SCOPES":["openid","user","credentials","data","admin","google_credentials","google_service_account","google_link","ga4gh_passport_v1"],"SESSION_COOKIE_DOMAIN":null,"SESSION_COOKIE_NAME":"fence","SESSION_COOKIE_SECURE":true,"SESSION_LIFETIME":28800,"SESSION_TIMEOUT":1800,"SHIBBOLETH_HEADER":"persistent_id","SSO_URL":"https://auth.nih.gov/affwebservices/public/saml2sso?SPID={{BASE_URL}}/shibboleth&RelayState=","STORAGE_CREDENTIALS":{},"SUPPORT_EMAIL_FOR_ERRORS":null,"SYNAPSE_AUTHZ_TTL":86400,"SYNAPSE_DISCOVERY_URL":null,"SYNAPSE_JWKS_URI":null,"SYNAPSE_URI":"https://repo-prod.prod.sagebase.org/auth/v1","TOKEN_PROJECTS_CUTOFF":10,"USERSYNC":{"fallback_to_dbgap_sftp":false,"sync_from_visas":false,"visa_types":{"ras":["https://ras.nih.gov/visas/v1","https://ras.nih.gov/visas/v1.1"]}},"USER_ALLOWED_SCOPES":["fence","openid","user","data","admin","google_credentials","google_service_account","google_link","ga4gh_passport_v1"],"WHITE_LISTED_GOOGLE_PARENT_ORGS":[],"WHITE_LISTED_SERVICE_ACCOUNT_EMAILS":[],"WTF_CSRF_SECRET_KEY":"{{ENCRYPTION_KEY}}","dbGaP":[{"decrypt_key":"","enable_common_exchange_area_access":false,"info":{"host":"","password":"","port":22,"proxy":"","username":""},"parse_consent_code":true,"protocol":"sftp","study_common_exchange_areas":{"example":"test_common_exchange_area"},"study_to_resource_namespaces":{"_default":["/"],"test_common_exchange_area":["/dbgap/"]}}]}` | Private configuration settings for Fence app | | FENCE_CONFIG.APP_NAME | string | `"Gen3 Data Commons"` | Name of the Fence app | | FENCE_CONFIG.AUTHLIB_INSECURE_TRANSPORT | bool | `true` | allow OIDC traffic on http for development. By default it requires https. WARNING: ONLY set to true when fence will be deployed in such a way that it will ONLY receive traffic from internal clients and can safely use HTTP. | | FENCE_CONFIG.CLIENT_ALLOWED_SCOPES | list | `["openid","user","data","google_credentials","google_service_account","google_link","ga4gh_passport_v1"]` | These are the *possible* scopes a client can be given, NOT scopes that are given to all clients. You can be more restrictive during client creation | diff --git a/helm/fence/values.yaml b/helm/fence/values.yaml index 2aeeda76e..b0c64ded8 100644 --- a/helm/fence/values.yaml +++ b/helm/fence/values.yaml @@ -1226,6 +1226,12 @@ FENCE_CONFIG: # The maximum lifetime of a Gen3 passport in seconds GEN3_PASSPORT_EXPIRES_IN: 43200 + # Max number of GUIDs to request content retrieval for + # NOTE: This is limited by the MAX allowed for any underlying bulk content requests + # e.g. if the Gen3 Embeddings service is configured to allow max 1000, then this + # can't be more than that for embeddings content resolutions + MAX_BULK_CONTENT_GUIDS_COUNT: 500 + ######################################################################################## # OPTIONAL CONFIGURATIONS # ######################################################################################## From e032bc1c785d617f1a2d3867b5590c1e1bbe2e47 Mon Sep 17 00:00:00 2001 From: Edward Malinowski Date: Thu, 9 Jul 2026 09:50:26 -0500 Subject: [PATCH 099/196] Bumped versions --- helm/access-backend/Chart.yaml | 2 +- helm/access-backend/README.md | 2 +- helm/ambassador/Chart.yaml | 4 +- helm/ambassador/README.md | 4 +- helm/arborist/Chart.yaml | 4 +- helm/arborist/README.md | 4 +- helm/argo-wrapper/Chart.yaml | 4 +- helm/argo-wrapper/README.md | 4 +- helm/audit/Chart.yaml | 2 +- helm/audit/README.md | 2 +- helm/aws-es-proxy/Chart.yaml | 4 +- helm/aws-es-proxy/README.md | 4 +- helm/aws-sigv4-proxy/Chart.yaml | 4 +- helm/aws-sigv4-proxy/README.md | 4 +- helm/cedar/Chart.yaml | 2 +- helm/cedar/README.md | 2 +- helm/cohort-middleware/Chart.yaml | 2 +- helm/cohort-middleware/README.md | 2 +- helm/dashboard/Chart.yaml | 4 +- helm/dashboard/README.md | 4 +- helm/data-upload-cron/Chart.yaml | 4 +- helm/data-upload-cron/README.md | 4 +- helm/datareplicate/Chart.yaml | 2 +- helm/datareplicate/README.md | 2 +- helm/dicom-server/Chart.yaml | 2 +- helm/dicom-server/README.md | 2 +- helm/embedding-management-service/Chart.yaml | 4 +- helm/embedding-management-service/README.md | 4 +- helm/fence/Chart.yaml | 2 +- helm/fence/README.md | 2 +- helm/frontend-framework/Chart.yaml | 4 +- helm/frontend-framework/README.md | 4 +- helm/funnel/Chart.yaml | 4 +- helm/funnel/README.md | 4 +- helm/gen3-analysis/Chart.yaml | 4 +- helm/gen3-analysis/README.md | 4 +- helm/gen3-user-data-library/Chart.yaml | 2 +- helm/gen3-user-data-library/README.md | 2 +- helm/gen3-workflow/Chart.yaml | 4 +- helm/gen3-workflow/README.md | 4 +- helm/gen3/Chart.yaml | 40 ++++++++++---------- helm/gen3/README.md | 40 ++++++++++---------- helm/guppy/Chart.yaml | 4 +- helm/guppy/README.md | 4 +- helm/hatchery/Chart.yaml | 2 +- helm/hatchery/README.md | 2 +- helm/indexd/Chart.yaml | 2 +- helm/indexd/README.md | 2 +- helm/manifestservice/Chart.yaml | 2 +- helm/manifestservice/README.md | 2 +- helm/metadata/Chart.yaml | 2 +- helm/metadata/README.md | 2 +- helm/ohdsi-webapi/Chart.yaml | 4 +- helm/ohdsi-webapi/README.md | 4 +- helm/ohif-viewer/Chart.yaml | 4 +- helm/ohif-viewer/README.md | 4 +- helm/orthanc/Chart.yaml | 2 +- helm/orthanc/README.md | 2 +- helm/peregrine/Chart.yaml | 4 +- helm/peregrine/README.md | 4 +- helm/portal/Chart.yaml | 4 +- helm/portal/README.md | 4 +- helm/requestor/Chart.yaml | 4 +- helm/requestor/README.md | 4 +- helm/revproxy/Chart.yaml | 4 +- helm/revproxy/README.md | 4 +- helm/sheepdog/Chart.yaml | 4 +- helm/sheepdog/README.md | 4 +- helm/sower/Chart.yaml | 2 +- helm/sower/README.md | 2 +- helm/ssjdispatcher/Chart.yaml | 2 +- helm/ssjdispatcher/README.md | 2 +- helm/wts/Chart.yaml | 2 +- helm/wts/README.md | 2 +- 74 files changed, 152 insertions(+), 152 deletions(-) diff --git a/helm/access-backend/Chart.yaml b/helm/access-backend/Chart.yaml index 5866ff8cb..a40ac450b 100644 --- a/helm/access-backend/Chart.yaml +++ b/helm/access-backend/Chart.yaml @@ -25,5 +25,5 @@ appVersion: "1.6.1" dependencies: - name: common - version: 0.1.36 + version: 0.1.37 repository: file://../common diff --git a/helm/access-backend/README.md b/helm/access-backend/README.md index 30f68f5a1..ebcd90508 100644 --- a/helm/access-backend/README.md +++ b/helm/access-backend/README.md @@ -8,7 +8,7 @@ A Helm chart for Kubernetes | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.36 | +| file://../common | common | 0.1.37 | ## Values diff --git a/helm/ambassador/Chart.yaml b/helm/ambassador/Chart.yaml index 34024a11e..993c132f5 100644 --- a/helm/ambassador/Chart.yaml +++ b/helm/ambassador/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.37 +version: 0.1.38 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "1.4.2" dependencies: - name: common - version: 0.1.36 + version: 0.1.37 repository: file://../common diff --git a/helm/ambassador/README.md b/helm/ambassador/README.md index 63054f7c4..d579f27fd 100644 --- a/helm/ambassador/README.md +++ b/helm/ambassador/README.md @@ -1,6 +1,6 @@ # ambassador -![Version: 0.1.37](https://img.shields.io/badge/Version-0.1.37-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.4.2](https://img.shields.io/badge/AppVersion-1.4.2-informational?style=flat-square) +![Version: 0.1.38](https://img.shields.io/badge/Version-0.1.38-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.4.2](https://img.shields.io/badge/AppVersion-1.4.2-informational?style=flat-square) A Helm chart for deploying ambassador for gen3 @@ -8,7 +8,7 @@ A Helm chart for deploying ambassador for gen3 | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.36 | +| file://../common | common | 0.1.37 | ## Values diff --git a/helm/arborist/Chart.yaml b/helm/arborist/Chart.yaml index 261659d79..00ce7e41a 100644 --- a/helm/arborist/Chart.yaml +++ b/helm/arborist/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.34 +version: 0.1.35 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,7 +25,7 @@ appVersion: "master" dependencies: - name: common - version: 0.1.36 + version: 0.1.37 repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/arborist/README.md b/helm/arborist/README.md index 1409c32cc..58b0fd02c 100644 --- a/helm/arborist/README.md +++ b/helm/arborist/README.md @@ -1,6 +1,6 @@ # arborist -![Version: 0.1.34](https://img.shields.io/badge/Version-0.1.34-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.35](https://img.shields.io/badge/Version-0.1.35-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 arborist @@ -8,7 +8,7 @@ A Helm chart for gen3 arborist | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.36 | +| file://../common | common | 0.1.37 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | ## Values diff --git a/helm/argo-wrapper/Chart.yaml b/helm/argo-wrapper/Chart.yaml index 182ad309f..2f861a795 100644 --- a/helm/argo-wrapper/Chart.yaml +++ b/helm/argo-wrapper/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.30 +version: 0.1.31 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.36 + version: 0.1.37 repository: file://../common diff --git a/helm/argo-wrapper/README.md b/helm/argo-wrapper/README.md index a87b9c334..25fe50276 100644 --- a/helm/argo-wrapper/README.md +++ b/helm/argo-wrapper/README.md @@ -1,6 +1,6 @@ # argo-wrapper -![Version: 0.1.30](https://img.shields.io/badge/Version-0.1.30-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.31](https://img.shields.io/badge/Version-0.1.31-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Argo Wrapper Service @@ -8,7 +8,7 @@ A Helm chart for gen3 Argo Wrapper Service | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.36 | +| file://../common | common | 0.1.37 | ## Values diff --git a/helm/audit/Chart.yaml b/helm/audit/Chart.yaml index a3e32cf3b..f077a029a 100644 --- a/helm/audit/Chart.yaml +++ b/helm/audit/Chart.yaml @@ -24,7 +24,7 @@ appVersion: "master" dependencies: - name: common - version: 0.1.36 + version: 0.1.37 repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/audit/README.md b/helm/audit/README.md index e3cf0d017..cdff0298a 100644 --- a/helm/audit/README.md +++ b/helm/audit/README.md @@ -8,7 +8,7 @@ A Helm chart for Kubernetes | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.36 | +| file://../common | common | 0.1.37 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | ## Values diff --git a/helm/aws-es-proxy/Chart.yaml b/helm/aws-es-proxy/Chart.yaml index bf9421817..74160ff62 100644 --- a/helm/aws-es-proxy/Chart.yaml +++ b/helm/aws-es-proxy/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.41 +version: 0.1.42 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.36 + version: 0.1.37 repository: file://../common diff --git a/helm/aws-es-proxy/README.md b/helm/aws-es-proxy/README.md index 56c05879f..a679928d5 100644 --- a/helm/aws-es-proxy/README.md +++ b/helm/aws-es-proxy/README.md @@ -1,6 +1,6 @@ # aws-es-proxy -![Version: 0.1.41](https://img.shields.io/badge/Version-0.1.41-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.42](https://img.shields.io/badge/Version-0.1.42-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for AWS ES Proxy Service for gen3 @@ -8,7 +8,7 @@ A Helm chart for AWS ES Proxy Service for gen3 | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.36 | +| file://../common | common | 0.1.37 | ## Values diff --git a/helm/aws-sigv4-proxy/Chart.yaml b/helm/aws-sigv4-proxy/Chart.yaml index 09e4eb4c2..ff86a6524 100644 --- a/helm/aws-sigv4-proxy/Chart.yaml +++ b/helm/aws-sigv4-proxy/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.2 +version: 0.1.3 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.36 + version: 0.1.37 repository: file://../common diff --git a/helm/aws-sigv4-proxy/README.md b/helm/aws-sigv4-proxy/README.md index 8b48b327b..03244d9af 100644 --- a/helm/aws-sigv4-proxy/README.md +++ b/helm/aws-sigv4-proxy/README.md @@ -1,6 +1,6 @@ # aws-sigv4-proxy -![Version: 0.1.2](https://img.shields.io/badge/Version-0.1.2-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.3](https://img.shields.io/badge/Version-0.1.3-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for AWS ES Proxy Service for gen3 @@ -8,7 +8,7 @@ A Helm chart for AWS ES Proxy Service for gen3 | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.36 | +| file://../common | common | 0.1.37 | ## Values diff --git a/helm/cedar/Chart.yaml b/helm/cedar/Chart.yaml index bb528bb01..0c3ef57a1 100644 --- a/helm/cedar/Chart.yaml +++ b/helm/cedar/Chart.yaml @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.36 + version: 0.1.37 repository: file://../common diff --git a/helm/cedar/README.md b/helm/cedar/README.md index e21b9ada6..116283542 100644 --- a/helm/cedar/README.md +++ b/helm/cedar/README.md @@ -8,7 +8,7 @@ A Helm chart for gen3 cedar wrapper | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.36 | +| file://../common | common | 0.1.37 | ## Values diff --git a/helm/cohort-middleware/Chart.yaml b/helm/cohort-middleware/Chart.yaml index 84065898e..f2cf9ae37 100644 --- a/helm/cohort-middleware/Chart.yaml +++ b/helm/cohort-middleware/Chart.yaml @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.36 + version: 0.1.37 repository: file://../common diff --git a/helm/cohort-middleware/README.md b/helm/cohort-middleware/README.md index 4d19c1c02..fa9a946c8 100644 --- a/helm/cohort-middleware/README.md +++ b/helm/cohort-middleware/README.md @@ -8,7 +8,7 @@ A Helm chart for gen3 cohort-middleware | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.36 | +| file://../common | common | 0.1.37 | ## Values diff --git a/helm/dashboard/Chart.yaml b/helm/dashboard/Chart.yaml index 77909501d..018e9639d 100644 --- a/helm/dashboard/Chart.yaml +++ b/helm/dashboard/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.21 +version: 0.1.22 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "1.16.0" dependencies: - name: common - version: 0.1.36 + version: 0.1.37 repository: file://../common diff --git a/helm/dashboard/README.md b/helm/dashboard/README.md index 14cdca949..be89fa6b8 100644 --- a/helm/dashboard/README.md +++ b/helm/dashboard/README.md @@ -1,6 +1,6 @@ # dashboard -![Version: 0.1.21](https://img.shields.io/badge/Version-0.1.21-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.16.0](https://img.shields.io/badge/AppVersion-1.16.0-informational?style=flat-square) +![Version: 0.1.22](https://img.shields.io/badge/Version-0.1.22-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.16.0](https://img.shields.io/badge/AppVersion-1.16.0-informational?style=flat-square) A Helm chart for Kubernetes @@ -8,7 +8,7 @@ A Helm chart for Kubernetes | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.36 | +| file://../common | common | 0.1.37 | ## Values diff --git a/helm/data-upload-cron/Chart.yaml b/helm/data-upload-cron/Chart.yaml index 79e789658..b68c57e83 100644 --- a/helm/data-upload-cron/Chart.yaml +++ b/helm/data-upload-cron/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.6 +version: 0.1.7 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.36 + version: 0.1.37 repository: file://../common diff --git a/helm/data-upload-cron/README.md b/helm/data-upload-cron/README.md index a012ceac3..8cf2012ee 100644 --- a/helm/data-upload-cron/README.md +++ b/helm/data-upload-cron/README.md @@ -1,6 +1,6 @@ # data-upload-cron -![Version: 0.1.6](https://img.shields.io/badge/Version-0.1.6-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.7](https://img.shields.io/badge/Version-0.1.7-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for the data upload cronjob @@ -8,7 +8,7 @@ A Helm chart for the data upload cronjob | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.36 | +| file://../common | common | 0.1.37 | ## Values diff --git a/helm/datareplicate/Chart.yaml b/helm/datareplicate/Chart.yaml index b0965f8c0..68a31340f 100644 --- a/helm/datareplicate/Chart.yaml +++ b/helm/datareplicate/Chart.yaml @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.36 + version: 0.1.37 repository: file://../common diff --git a/helm/datareplicate/README.md b/helm/datareplicate/README.md index d40846245..1b94e22b2 100644 --- a/helm/datareplicate/README.md +++ b/helm/datareplicate/README.md @@ -8,7 +8,7 @@ A Helm chart for gen3 datareplicate | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.36 | +| file://../common | common | 0.1.37 | ## Values diff --git a/helm/dicom-server/Chart.yaml b/helm/dicom-server/Chart.yaml index 618d7bcac..e0ca4536e 100644 --- a/helm/dicom-server/Chart.yaml +++ b/helm/dicom-server/Chart.yaml @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.36 + version: 0.1.37 repository: file://../common diff --git a/helm/dicom-server/README.md b/helm/dicom-server/README.md index d949c33b1..497b87d69 100644 --- a/helm/dicom-server/README.md +++ b/helm/dicom-server/README.md @@ -8,7 +8,7 @@ A Helm chart for gen3 Dicom Server | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.36 | +| file://../common | common | 0.1.37 | ## Values diff --git a/helm/embedding-management-service/Chart.yaml b/helm/embedding-management-service/Chart.yaml index 85e740977..fd6fbad76 100644 --- a/helm/embedding-management-service/Chart.yaml +++ b/helm/embedding-management-service/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.7 +version: 0.1.8 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "1.16.0" dependencies: - name: common - version: 0.1.36 + version: 0.1.37 repository: file://../common diff --git a/helm/embedding-management-service/README.md b/helm/embedding-management-service/README.md index 0bc401fa0..48e516afe 100644 --- a/helm/embedding-management-service/README.md +++ b/helm/embedding-management-service/README.md @@ -1,6 +1,6 @@ # embedding-management-service -![Version: 0.1.7](https://img.shields.io/badge/Version-0.1.7-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.16.0](https://img.shields.io/badge/AppVersion-1.16.0-informational?style=flat-square) +![Version: 0.1.8](https://img.shields.io/badge/Version-0.1.8-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.16.0](https://img.shields.io/badge/AppVersion-1.16.0-informational?style=flat-square) A Helm chart for Kubernetes @@ -8,7 +8,7 @@ A Helm chart for Kubernetes | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.36 | +| file://../common | common | 0.1.37 | ## Values diff --git a/helm/fence/Chart.yaml b/helm/fence/Chart.yaml index f71e67e79..acbd322a8 100644 --- a/helm/fence/Chart.yaml +++ b/helm/fence/Chart.yaml @@ -24,7 +24,7 @@ appVersion: "master" dependencies: - name: common - version: 0.1.36 + version: 0.1.37 repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/fence/README.md b/helm/fence/README.md index 088636b29..9eed88fb7 100644 --- a/helm/fence/README.md +++ b/helm/fence/README.md @@ -8,7 +8,7 @@ A Helm chart for gen3 Fence | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.36 | +| file://../common | common | 0.1.37 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | ## Values diff --git a/helm/frontend-framework/Chart.yaml b/helm/frontend-framework/Chart.yaml index 5d2e3ca71..0121e0758 100644 --- a/helm/frontend-framework/Chart.yaml +++ b/helm/frontend-framework/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.29 +version: 0.1.30 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "develop" dependencies: - name: common - version: 0.1.36 + version: 0.1.37 repository: file://../common diff --git a/helm/frontend-framework/README.md b/helm/frontend-framework/README.md index a4c4a3184..ed4e5676d 100644 --- a/helm/frontend-framework/README.md +++ b/helm/frontend-framework/README.md @@ -1,6 +1,6 @@ # frontend-framework -![Version: 0.1.29](https://img.shields.io/badge/Version-0.1.29-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: develop](https://img.shields.io/badge/AppVersion-develop-informational?style=flat-square) +![Version: 0.1.30](https://img.shields.io/badge/Version-0.1.30-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: develop](https://img.shields.io/badge/AppVersion-develop-informational?style=flat-square) A Helm chart for the gen3 frontend framework @@ -8,7 +8,7 @@ A Helm chart for the gen3 frontend framework | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.36 | +| file://../common | common | 0.1.37 | ## Values diff --git a/helm/funnel/Chart.yaml b/helm/funnel/Chart.yaml index 8061230b7..582c87bfe 100644 --- a/helm/funnel/Chart.yaml +++ b/helm/funnel/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.26 +version: 0.1.27 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -24,7 +24,7 @@ appVersion: "master" dependencies: - name: common - version: 0.1.36 + version: 0.1.37 repository: file://../common - name: funnel # NOTE: diff --git a/helm/funnel/README.md b/helm/funnel/README.md index 1f168fe79..09dccc499 100644 --- a/helm/funnel/README.md +++ b/helm/funnel/README.md @@ -1,6 +1,6 @@ # funnel -![Version: 0.1.26](https://img.shields.io/badge/Version-0.1.26-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.27](https://img.shields.io/badge/Version-0.1.27-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for Kubernetes @@ -8,7 +8,7 @@ A Helm chart for Kubernetes | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.36 | +| file://../common | common | 0.1.37 | | https://calypr.github.io/helm-charts | funnel | 0.1.99-rc.36 | ## Values diff --git a/helm/gen3-analysis/Chart.yaml b/helm/gen3-analysis/Chart.yaml index 9c233f3f9..0a1e0da2f 100644 --- a/helm/gen3-analysis/Chart.yaml +++ b/helm/gen3-analysis/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.12 +version: 0.1.13 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.36 + version: 0.1.37 repository: file://../common diff --git a/helm/gen3-analysis/README.md b/helm/gen3-analysis/README.md index 143a09f27..f2d73dd2f 100644 --- a/helm/gen3-analysis/README.md +++ b/helm/gen3-analysis/README.md @@ -1,6 +1,6 @@ # gen3-analysis -![Version: 0.1.12](https://img.shields.io/badge/Version-0.1.12-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.13](https://img.shields.io/badge/Version-0.1.13-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 gen3-analysis Service @@ -8,7 +8,7 @@ A Helm chart for gen3 gen3-analysis Service | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.36 | +| file://../common | common | 0.1.37 | ## Values diff --git a/helm/gen3-user-data-library/Chart.yaml b/helm/gen3-user-data-library/Chart.yaml index 28b313f2b..db5366682 100644 --- a/helm/gen3-user-data-library/Chart.yaml +++ b/helm/gen3-user-data-library/Chart.yaml @@ -24,7 +24,7 @@ version: 0.1.16 appVersion: "main" dependencies: - name: common - version: 0.1.36 + version: 0.1.37 repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/gen3-user-data-library/README.md b/helm/gen3-user-data-library/README.md index e05c78e0b..e6b76cb8b 100644 --- a/helm/gen3-user-data-library/README.md +++ b/helm/gen3-user-data-library/README.md @@ -8,7 +8,7 @@ A Helm chart for Kubernetes | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.36 | +| file://../common | common | 0.1.37 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | ## Values diff --git a/helm/gen3-workflow/Chart.yaml b/helm/gen3-workflow/Chart.yaml index 09a68d39b..acca9917f 100644 --- a/helm/gen3-workflow/Chart.yaml +++ b/helm/gen3-workflow/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.22 +version: 0.1.23 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -24,5 +24,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.36 + version: 0.1.37 repository: file://../common diff --git a/helm/gen3-workflow/README.md b/helm/gen3-workflow/README.md index 3c3b8e7e1..4391e6893 100644 --- a/helm/gen3-workflow/README.md +++ b/helm/gen3-workflow/README.md @@ -1,6 +1,6 @@ # gen3-workflow -![Version: 0.1.22](https://img.shields.io/badge/Version-0.1.22-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.23](https://img.shields.io/badge/Version-0.1.23-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for Kubernetes @@ -8,7 +8,7 @@ A Helm chart for Kubernetes | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.36 | +| file://../common | common | 0.1.37 | ## Values diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index 2a15e7d9b..c3b1d65b1 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -9,15 +9,15 @@ dependencies: repository: "file://../access-backend" condition: access-backend.enabled - name: ambassador - version: 0.1.37 + version: 0.1.38 repository: "file://../ambassador" condition: ambassador.enabled - name: arborist - version: 0.1.34 + version: 0.1.35 repository: "file://../arborist" condition: arborist.enabled - name: argo-wrapper - version: 0.1.30 + version: 0.1.31 repository: "file://../argo-wrapper" condition: argo-wrapper.enabled - name: audit @@ -25,11 +25,11 @@ dependencies: repository: "file://../audit" condition: audit.enabled - name: aws-es-proxy - version: 0.1.41 + version: 0.1.42 repository: "file://../aws-es-proxy" condition: aws-es-proxy.enabled - name: aws-sigv4-proxy - version: 0.1.2 + version: 0.1.3 repository: "file://../aws-sigv4-proxy" condition: aws-sigv4-proxy.enabled - name: cedar @@ -44,7 +44,7 @@ dependencies: version: 0.1.37 repository: file://../common - name: dashboard - version: 0.1.21 + version: 0.1.22 repository: file://../dashboard condition: dashboard.enabled - name: datareplicate @@ -52,11 +52,11 @@ dependencies: repository: "file://../datareplicate" condition: datareplicate.enabled - name: data-upload-cron - version: 0.1.6 + version: 0.1.7 repository: "file://../data-upload-cron" condition: data-upload-cron.enabled - name: embedding-management-service - version: 0.1.7 + version: 0.1.8 repository: file://../embedding-management-service condition: embedding-management-service.enabled - name: etl @@ -64,7 +64,7 @@ dependencies: repository: file://../etl condition: etl.enabled - name: frontend-framework - version: 0.1.29 + version: 0.1.30 repository: "file://../frontend-framework" condition: frontend-framework.enabled - name: fence @@ -72,7 +72,7 @@ dependencies: repository: "file://../fence" condition: fence.enabled - name: funnel - version: 0.1.26 + version: 0.1.27 repository: "file://../funnel" condition: gen3-workflow.enabled - name: gen3-user-data-library @@ -80,11 +80,11 @@ dependencies: repository: "file://../gen3-user-data-library" condition: gen3-user-data-library.enabled - name: gen3-workflow - version: 0.1.22 + version: 0.1.23 repository: "file://../gen3-workflow" condition: gen3-workflow.enabled - name: guppy - version: 0.1.37 + version: 0.1.38 repository: "file://../guppy" condition: guppy.enabled - name: hatchery @@ -104,23 +104,23 @@ dependencies: repository: "file://../metadata" condition: metadata.enabled - name: peregrine - version: 0.1.42 + version: 0.1.43 repository: "file://../peregrine" condition: peregrine.enabled - name: portal - version: 0.1.60 + version: 0.1.61 repository: "file://../portal" condition: portal.enabled - name: requestor - version: 0.1.34 + version: 0.1.35 repository: "file://../requestor" condition: requestor.enabled - name: revproxy - version: 0.1.61 + version: 0.1.62 repository: "file://../revproxy" condition: revproxy.enabled - name: sheepdog - version: 0.1.42 + version: 0.1.43 repository: "file://../sheepdog" condition: sheepdog.enabled - name: ssjdispatcher @@ -144,7 +144,7 @@ dependencies: repository: file://../dicom-server condition: dicom-server.enabled - name: ohif-viewer - version: 0.1.14 + version: 0.1.15 repository: file://../ohif-viewer condition: ohif-viewer.enabled - name: orthanc @@ -152,7 +152,7 @@ dependencies: repository: file://../orthanc condition: orthanc.enabled - name: gen3-analysis - version: 0.1.12 + version: 0.1.13 repository: file://../gen3-analysis condition: gen3-analysis.enabled - name: ohdsi-atlas @@ -160,7 +160,7 @@ dependencies: repository: file://../ohdsi-atlas condition: ohdsi-atlas.enabled - name: ohdsi-webapi - version: 0.1.5 + version: 0.1.6 repository: file://../ohdsi-webapi condition: ohdsi-webapi.enabled diff --git a/helm/gen3/README.md b/helm/gen3/README.md index 19423a8dc..e1e1269b2 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -19,43 +19,43 @@ Helm chart to deploy Gen3 Data Commons | Repository | Name | Version | |------------|------|---------| | file://../access-backend | access-backend | 0.1.21 | -| file://../ambassador | ambassador | 0.1.37 | -| file://../arborist | arborist | 0.1.34 | -| file://../argo-wrapper | argo-wrapper | 0.1.30 | +| file://../ambassador | ambassador | 0.1.38 | +| file://../arborist | arborist | 0.1.35 | +| file://../argo-wrapper | argo-wrapper | 0.1.31 | | file://../audit | audit | 0.1.44 | -| file://../aws-es-proxy | aws-es-proxy | 0.1.41 | -| file://../aws-sigv4-proxy | aws-sigv4-proxy | 0.1.2 | +| file://../aws-es-proxy | aws-es-proxy | 0.1.42 | +| file://../aws-sigv4-proxy | aws-sigv4-proxy | 0.1.3 | | file://../cedar | cedar | 0.1.27 | | file://../cohort-middleware | cohort-middleware | 0.1.23 | | file://../common | common | 0.1.37 | -| file://../dashboard | dashboard | 0.1.21 | -| file://../data-upload-cron | data-upload-cron | 0.1.6 | +| file://../dashboard | dashboard | 0.1.22 | +| file://../data-upload-cron | data-upload-cron | 0.1.7 | | file://../datareplicate | datareplicate | 0.1.22 | | file://../dicom-server | dicom-server | 0.1.32 | -| file://../embedding-management-service | embedding-management-service | 0.1.7 | +| file://../embedding-management-service | embedding-management-service | 0.1.8 | | file://../etl | etl | 0.1.23 | | file://../fence | fence | 0.1.79 | -| file://../frontend-framework | frontend-framework | 0.1.29 | -| file://../funnel | funnel | 0.1.26 | -| file://../gen3-analysis | gen3-analysis | 0.1.12 | +| file://../frontend-framework | frontend-framework | 0.1.30 | +| file://../funnel | funnel | 0.1.27 | +| file://../gen3-analysis | gen3-analysis | 0.1.13 | | file://../gen3-network-policies | gen3-network-policies | 0.1.4 | | file://../gen3-user-data-library | gen3-user-data-library | 0.1.16 | -| file://../gen3-workflow | gen3-workflow | 0.1.22 | -| file://../guppy | guppy | 0.1.37 | +| file://../gen3-workflow | gen3-workflow | 0.1.23 | +| file://../guppy | guppy | 0.1.38 | | file://../hatchery | hatchery | 0.1.70 | | file://../indexd | indexd | 0.1.48 | | file://../manifestservice | manifestservice | 0.1.43 | | file://../metadata | metadata | 0.1.45 | | file://../neuvector | neuvector | 0.1.2 | | file://../ohdsi-atlas | ohdsi-atlas | 0.1.2 | -| file://../ohdsi-webapi | ohdsi-webapi | 0.1.5 | -| file://../ohif-viewer | ohif-viewer | 0.1.14 | +| file://../ohdsi-webapi | ohdsi-webapi | 0.1.6 | +| file://../ohif-viewer | ohif-viewer | 0.1.15 | | file://../orthanc | orthanc | 0.1.16 | -| file://../peregrine | peregrine | 0.1.42 | -| file://../portal | portal | 0.1.60 | -| file://../requestor | requestor | 0.1.34 | -| file://../revproxy | revproxy | 0.1.61 | -| file://../sheepdog | sheepdog | 0.1.42 | +| file://../peregrine | peregrine | 0.1.43 | +| file://../portal | portal | 0.1.61 | +| file://../requestor | requestor | 0.1.35 | +| file://../revproxy | revproxy | 0.1.62 | +| file://../sheepdog | sheepdog | 0.1.43 | | file://../sower | sower | 0.1.47 | | file://../ssjdispatcher | ssjdispatcher | 0.1.48 | | file://../wts | wts | 0.1.41 | diff --git a/helm/guppy/Chart.yaml b/helm/guppy/Chart.yaml index d12367a03..4bb0d83e7 100644 --- a/helm/guppy/Chart.yaml +++ b/helm/guppy/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.37 +version: 0.1.38 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.36 + version: 0.1.37 repository: file://../common diff --git a/helm/guppy/README.md b/helm/guppy/README.md index c4e08b164..8387fa9ea 100644 --- a/helm/guppy/README.md +++ b/helm/guppy/README.md @@ -1,6 +1,6 @@ # guppy -![Version: 0.1.37](https://img.shields.io/badge/Version-0.1.37-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.38](https://img.shields.io/badge/Version-0.1.38-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Guppy Service @@ -8,7 +8,7 @@ A Helm chart for gen3 Guppy Service | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.36 | +| file://../common | common | 0.1.37 | ## Values diff --git a/helm/hatchery/Chart.yaml b/helm/hatchery/Chart.yaml index a32dff598..bcb781391 100644 --- a/helm/hatchery/Chart.yaml +++ b/helm/hatchery/Chart.yaml @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.36 + version: 0.1.37 repository: file://../common diff --git a/helm/hatchery/README.md b/helm/hatchery/README.md index 1690e685b..0f4e859eb 100644 --- a/helm/hatchery/README.md +++ b/helm/hatchery/README.md @@ -8,7 +8,7 @@ A Helm chart for gen3 Hatchery | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.36 | +| file://../common | common | 0.1.37 | ## Values diff --git a/helm/indexd/Chart.yaml b/helm/indexd/Chart.yaml index 47be34377..495087adf 100644 --- a/helm/indexd/Chart.yaml +++ b/helm/indexd/Chart.yaml @@ -25,7 +25,7 @@ appVersion: "master" dependencies: - name: common - version: 0.1.36 + version: 0.1.37 repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/indexd/README.md b/helm/indexd/README.md index 90f97432f..f2864d67f 100644 --- a/helm/indexd/README.md +++ b/helm/indexd/README.md @@ -8,7 +8,7 @@ A Helm chart for gen3 indexd | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.36 | +| file://../common | common | 0.1.37 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | ## Values diff --git a/helm/manifestservice/Chart.yaml b/helm/manifestservice/Chart.yaml index 570862b61..74098c9a5 100644 --- a/helm/manifestservice/Chart.yaml +++ b/helm/manifestservice/Chart.yaml @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.36 + version: 0.1.37 repository: file://../common diff --git a/helm/manifestservice/README.md b/helm/manifestservice/README.md index b4fe0f1fb..57cacf1d3 100644 --- a/helm/manifestservice/README.md +++ b/helm/manifestservice/README.md @@ -8,7 +8,7 @@ A Helm chart for Kubernetes | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.36 | +| file://../common | common | 0.1.37 | ## Values diff --git a/helm/metadata/Chart.yaml b/helm/metadata/Chart.yaml index c7eb02ce4..2804cb8aa 100644 --- a/helm/metadata/Chart.yaml +++ b/helm/metadata/Chart.yaml @@ -25,7 +25,7 @@ appVersion: "master" dependencies: - name: common - version: 0.1.36 + version: 0.1.37 repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/metadata/README.md b/helm/metadata/README.md index df9074e60..37c09a64d 100644 --- a/helm/metadata/README.md +++ b/helm/metadata/README.md @@ -8,7 +8,7 @@ A Helm chart for gen3 Metadata Service | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.36 | +| file://../common | common | 0.1.37 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | | https://helm.elastic.co | elasticsearch | 7.17.1 | diff --git a/helm/ohdsi-webapi/Chart.yaml b/helm/ohdsi-webapi/Chart.yaml index 1f809e8fe..787b7cb53 100644 --- a/helm/ohdsi-webapi/Chart.yaml +++ b/helm/ohdsi-webapi/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.5 +version: 0.1.6 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,7 +25,7 @@ appVersion: "2.15.0" dependencies: - name: common - version: 0.1.36 + version: 0.1.37 repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/ohdsi-webapi/README.md b/helm/ohdsi-webapi/README.md index 81b80e7e4..b8ced56db 100644 --- a/helm/ohdsi-webapi/README.md +++ b/helm/ohdsi-webapi/README.md @@ -1,6 +1,6 @@ # ohdsi-webapi -![Version: 0.1.5](https://img.shields.io/badge/Version-0.1.5-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 2.15.0](https://img.shields.io/badge/AppVersion-2.15.0-informational?style=flat-square) +![Version: 0.1.6](https://img.shields.io/badge/Version-0.1.6-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 2.15.0](https://img.shields.io/badge/AppVersion-2.15.0-informational?style=flat-square) A Helm chart for OHDSI WebAPI @@ -8,7 +8,7 @@ A Helm chart for OHDSI WebAPI | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.36 | +| file://../common | common | 0.1.37 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | ## Values diff --git a/helm/ohif-viewer/Chart.yaml b/helm/ohif-viewer/Chart.yaml index 8422373ce..e7e74d5c7 100644 --- a/helm/ohif-viewer/Chart.yaml +++ b/helm/ohif-viewer/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.14 +version: 0.1.15 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.36 + version: 0.1.37 repository: file://../common diff --git a/helm/ohif-viewer/README.md b/helm/ohif-viewer/README.md index 144fd1937..f34240e62 100644 --- a/helm/ohif-viewer/README.md +++ b/helm/ohif-viewer/README.md @@ -1,6 +1,6 @@ # ohif-viewer -![Version: 0.1.14](https://img.shields.io/badge/Version-0.1.14-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.15](https://img.shields.io/badge/Version-0.1.15-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Ohif Viewer @@ -8,7 +8,7 @@ A Helm chart for gen3 Ohif Viewer | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.36 | +| file://../common | common | 0.1.37 | ## Values diff --git a/helm/orthanc/Chart.yaml b/helm/orthanc/Chart.yaml index 9ae57602a..6eb037602 100644 --- a/helm/orthanc/Chart.yaml +++ b/helm/orthanc/Chart.yaml @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.36 + version: 0.1.37 repository: file://../common diff --git a/helm/orthanc/README.md b/helm/orthanc/README.md index fc534a0e4..65606e438 100644 --- a/helm/orthanc/README.md +++ b/helm/orthanc/README.md @@ -8,7 +8,7 @@ A Helm chart for gen3 Dicom Server | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.36 | +| file://../common | common | 0.1.37 | ## Values diff --git a/helm/peregrine/Chart.yaml b/helm/peregrine/Chart.yaml index 4b00c460f..7bbd00870 100644 --- a/helm/peregrine/Chart.yaml +++ b/helm/peregrine/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.42 +version: 0.1.43 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,7 +25,7 @@ appVersion: "master" dependencies: - name: common - version: 0.1.36 + version: 0.1.37 repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/peregrine/README.md b/helm/peregrine/README.md index c3d1d8700..3d28cd896 100644 --- a/helm/peregrine/README.md +++ b/helm/peregrine/README.md @@ -1,6 +1,6 @@ # peregrine -![Version: 0.1.42](https://img.shields.io/badge/Version-0.1.42-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.43](https://img.shields.io/badge/Version-0.1.43-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Peregrine service @@ -8,7 +8,7 @@ A Helm chart for gen3 Peregrine service | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.36 | +| file://../common | common | 0.1.37 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | ## Values diff --git a/helm/portal/Chart.yaml b/helm/portal/Chart.yaml index 691b48c51..64b141088 100644 --- a/helm/portal/Chart.yaml +++ b/helm/portal/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.60 +version: 0.1.61 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.36 + version: 0.1.37 repository: file://../common diff --git a/helm/portal/README.md b/helm/portal/README.md index 8ed456fe5..a2bb09d96 100644 --- a/helm/portal/README.md +++ b/helm/portal/README.md @@ -1,6 +1,6 @@ # portal -![Version: 0.1.60](https://img.shields.io/badge/Version-0.1.60-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.61](https://img.shields.io/badge/Version-0.1.61-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 data-portal @@ -8,7 +8,7 @@ A Helm chart for gen3 data-portal | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.36 | +| file://../common | common | 0.1.37 | ## Values diff --git a/helm/requestor/Chart.yaml b/helm/requestor/Chart.yaml index 8096c4287..5c4671a4c 100644 --- a/helm/requestor/Chart.yaml +++ b/helm/requestor/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.34 +version: 0.1.35 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,7 +25,7 @@ appVersion: "master" dependencies: - name: common - version: 0.1.36 + version: 0.1.37 repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/requestor/README.md b/helm/requestor/README.md index 6d30a95e0..acc0f1a79 100644 --- a/helm/requestor/README.md +++ b/helm/requestor/README.md @@ -1,6 +1,6 @@ # requestor -![Version: 0.1.34](https://img.shields.io/badge/Version-0.1.34-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.35](https://img.shields.io/badge/Version-0.1.35-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Requestor Service @@ -8,7 +8,7 @@ A Helm chart for gen3 Requestor Service | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.36 | +| file://../common | common | 0.1.37 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | ## Values diff --git a/helm/revproxy/Chart.yaml b/helm/revproxy/Chart.yaml index 37cb46c45..36576de88 100644 --- a/helm/revproxy/Chart.yaml +++ b/helm/revproxy/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.61 +version: 0.1.62 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.36 + version: 0.1.37 repository: file://../common diff --git a/helm/revproxy/README.md b/helm/revproxy/README.md index 6fc8ada53..3c1b453c2 100644 --- a/helm/revproxy/README.md +++ b/helm/revproxy/README.md @@ -1,6 +1,6 @@ # revproxy -![Version: 0.1.61](https://img.shields.io/badge/Version-0.1.61-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.62](https://img.shields.io/badge/Version-0.1.62-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 revproxy @@ -8,7 +8,7 @@ A Helm chart for gen3 revproxy | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.36 | +| file://../common | common | 0.1.37 | ## Values diff --git a/helm/sheepdog/Chart.yaml b/helm/sheepdog/Chart.yaml index 93c897e0a..8b05d4381 100644 --- a/helm/sheepdog/Chart.yaml +++ b/helm/sheepdog/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.42 +version: 0.1.43 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,7 +25,7 @@ appVersion: "master" dependencies: - name: common - version: 0.1.36 + version: 0.1.37 repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/sheepdog/README.md b/helm/sheepdog/README.md index 828400373..4fffd537c 100644 --- a/helm/sheepdog/README.md +++ b/helm/sheepdog/README.md @@ -1,6 +1,6 @@ # sheepdog -![Version: 0.1.42](https://img.shields.io/badge/Version-0.1.42-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.43](https://img.shields.io/badge/Version-0.1.43-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Sheepdog Service @@ -8,7 +8,7 @@ A Helm chart for gen3 Sheepdog Service | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.36 | +| file://../common | common | 0.1.37 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | ## Values diff --git a/helm/sower/Chart.yaml b/helm/sower/Chart.yaml index e64a4f575..35c158e6f 100644 --- a/helm/sower/Chart.yaml +++ b/helm/sower/Chart.yaml @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.36 + version: 0.1.37 repository: file://../common diff --git a/helm/sower/README.md b/helm/sower/README.md index 0ca25fc50..0cbb4b9e9 100644 --- a/helm/sower/README.md +++ b/helm/sower/README.md @@ -8,7 +8,7 @@ A Helm chart for gen3 sower | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.36 | +| file://../common | common | 0.1.37 | ## Values diff --git a/helm/ssjdispatcher/Chart.yaml b/helm/ssjdispatcher/Chart.yaml index cddf17f6e..a0a67f41f 100644 --- a/helm/ssjdispatcher/Chart.yaml +++ b/helm/ssjdispatcher/Chart.yaml @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.36 + version: 0.1.37 repository: file://../common diff --git a/helm/ssjdispatcher/README.md b/helm/ssjdispatcher/README.md index 1be6baf27..58539aa88 100644 --- a/helm/ssjdispatcher/README.md +++ b/helm/ssjdispatcher/README.md @@ -8,7 +8,7 @@ A Helm chart for gen3 ssjdispatcher | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.36 | +| file://../common | common | 0.1.37 | ## Values diff --git a/helm/wts/Chart.yaml b/helm/wts/Chart.yaml index 64e172422..b615b9cd2 100644 --- a/helm/wts/Chart.yaml +++ b/helm/wts/Chart.yaml @@ -25,7 +25,7 @@ appVersion: "master" dependencies: - name: common - version: 0.1.36 + version: 0.1.37 repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/wts/README.md b/helm/wts/README.md index 7ee9c5447..d82ff02a4 100644 --- a/helm/wts/README.md +++ b/helm/wts/README.md @@ -8,7 +8,7 @@ A Helm chart for gen3 workspace token service | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.36 | +| file://../common | common | 0.1.37 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | ## Values From 53fade2c27200b275f85ef9aeae9174dc33f642b Mon Sep 17 00:00:00 2001 From: Sai Shanmukha Date: Thu, 9 Jul 2026 09:50:52 -0500 Subject: [PATCH 100/196] Update worker-pv.yaml --- helm/funnel/files/worker-pv.yaml | 17 +++++++++++++++-- 1 file changed, 15 insertions(+), 2 deletions(-) diff --git a/helm/funnel/files/worker-pv.yaml b/helm/funnel/files/worker-pv.yaml index e0fba3a60..0b7e2e1ec 100644 --- a/helm/funnel/files/worker-pv.yaml +++ b/helm/funnel/files/worker-pv.yaml @@ -5,6 +5,7 @@ metadata: labels: app: funnel taskId: {{`{{.TaskId}}`}} + namespace: {{`{{.Namespace}}`}} spec: storageClassName: "" # Required for static provisioning capacity: @@ -14,18 +15,30 @@ spec: persistentVolumeReclaimPolicy: Retain mountOptions: - allow-delete - - allow-overwrite + - allow-overwrite # allow overwriting existing files + - incremental-upload # allow appending to existing files + - allow-other # allow non-root users to access the mounted directory - region={{`{{.Region}}`}} - file-mode=0755 + - prefix=funnel-temp-files/ {{`{{- if .KmsKeyID}}`}} - sse aws:kms - sse-kms-key-id={{`{{.KmsKeyID}}`}} {{`{{- end}}`}} + {{- if .Values.endpoint_url }} + - endpoint-url={{ .Values.endpoint_url }} + # https://github.com/awslabs/mountpoint-s3/blob/v1.22.2/doc/TROUBLESHOOTING.md#invalid-hostname-for-dns-resolution + - force-path-style + {{- end }} csi: driver: s3.csi.aws.com volumeHandle: s3-csi-{{`{{.TaskId}}`}} volumeAttributes: bucketName: {{`{{.Bucket}}`}} + {{- if .Values.authenticationSource }} + authenticationSource: {{ .Values.authenticationSource }} + stsRegion: {{ .Values.stsRegion }} + {{- end }} claimRef: namespace: {{`{{.Namespace}}`}} - name: funnel-worker-pvc-{{`{{.TaskId}}`}} + name: funnel-worker-pvc-{{`{{.TaskId}}`}} \ No newline at end of file From 9d14a770cfd92e0f6414a869615c2f500ccc3869 Mon Sep 17 00:00:00 2001 From: Edward Malinowski Date: Thu, 9 Jul 2026 10:01:50 -0500 Subject: [PATCH 101/196] Bumped versions --- .../ssjdispatcher/templates/serviceaccount.yaml | 17 ++++++++--------- 1 file changed, 8 insertions(+), 9 deletions(-) diff --git a/helm/ssjdispatcher/templates/serviceaccount.yaml b/helm/ssjdispatcher/templates/serviceaccount.yaml index 210ce30d1..69ceb6295 100644 --- a/helm/ssjdispatcher/templates/serviceaccount.yaml +++ b/helm/ssjdispatcher/templates/serviceaccount.yaml @@ -9,12 +9,11 @@ metadata: annotations: eks.amazonaws.com/role-arn: arn:aws:iam::{{ .Values.global.crossplane.accountId }}:role/{{ .Values.global.environment }}-{{ .Release.Namespace }}-{{ include "ssjdispatcher.serviceAccountName" . }} {{- else }} - {{- with .Values.serviceAccount.annotations }} + {{- with .Values.serviceAccount.annotations }} annotations: -{{ toYaml . | indent 4 }} - {{- end }} + {{- toYaml . | nindent 4 }} + {{- end }} {{- end }} - --- apiVersion: v1 kind: ServiceAccount @@ -24,11 +23,11 @@ metadata: {{- include "ssjdispatcher.labels" . | nindent 4 }} {{- if and .Values.global.crossplane.enabled .Values.global.aws.enabled }} annotations: - {{- if and .Values.global.crossplane.enabled .Values.global.aws.enabled }} - eks.amazonaws.com/role-arn: arn:aws:iam::{{ .Values.global.crossplane.accountId }}:role/{{ .Values.global.environment }}-{{ include "ssjdispatcher.serviceAccountName" . }} - {{- else }} + eks.amazonaws.com/role-arn: arn:aws:iam::{{ .Values.global.crossplane.accountId }}:role/{{ .Values.global.environment }}-{{ include "ssjdispatcher.serviceAccountName" . }} + {{- else }} {{- with .Values.jobServiceAccount.annotations }} - {{ toYaml . | nindent 4 }} - {{- end }} + annotations: + {{- toYaml . | nindent 4 }} {{- end }} + {{- end }} {{- end }} From c9e4964e3691f71ea171e8d320acc63d111ec22f Mon Sep 17 00:00:00 2001 From: Edward Malinowski Date: Thu, 9 Jul 2026 10:11:10 -0500 Subject: [PATCH 102/196] Bumped versions --- helm/gen3/Chart.yaml | 2 +- helm/gen3/README.md | 11 ++++++++++- helm/jeg/README.md | 2 +- helm/revproxy/Chart.yaml | 2 +- helm/revproxy/README.md | 3 ++- helm/vectis-overlays/README.md | 3 ++- helm/workspace-proxy/README.md | 2 +- 7 files changed, 18 insertions(+), 7 deletions(-) diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index 665e60b39..7155b5ea6 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -116,7 +116,7 @@ dependencies: repository: "file://../requestor" condition: requestor.enabled - name: revproxy - version: 0.1.62 + version: 0.1.63 repository: "file://../revproxy" condition: revproxy.enabled - name: sheepdog diff --git a/helm/gen3/README.md b/helm/gen3/README.md index e1e1269b2..71963bd2f 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -44,6 +44,7 @@ Helm chart to deploy Gen3 Data Commons | file://../guppy | guppy | 0.1.38 | | file://../hatchery | hatchery | 0.1.70 | | file://../indexd | indexd | 0.1.48 | +| file://../jeg | jeg | 0.1.1 | | file://../manifestservice | manifestservice | 0.1.43 | | file://../metadata | metadata | 0.1.45 | | file://../neuvector | neuvector | 0.1.2 | @@ -54,10 +55,12 @@ Helm chart to deploy Gen3 Data Commons | file://../peregrine | peregrine | 0.1.43 | | file://../portal | portal | 0.1.61 | | file://../requestor | requestor | 0.1.35 | -| file://../revproxy | revproxy | 0.1.62 | +| file://../revproxy | revproxy | 0.1.63 | | file://../sheepdog | sheepdog | 0.1.43 | | file://../sower | sower | 0.1.47 | | file://../ssjdispatcher | ssjdispatcher | 0.1.48 | +| file://../vectis-overlays | vectis-overlays | 0.1.1 | +| file://../workspace-proxy | workspace-proxy | 0.1.1 | | file://../wts | wts | 0.1.41 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | | https://helm.elastic.co | elasticsearch | 7.10.2 | @@ -232,6 +235,8 @@ Helm chart to deploy Gen3 Data Commons | hatchery.hatchery.sidecarContainer.memory-limit | string | `"256Mi"` | The maximum amount of memory the sidecar container can use | | indexd.defaultPrefix | string | `"PREFIX/"` | the default prefix for indexd records | | indexd.enabled | bool | `true` | Whether to deploy the indexd subchart. | +| jeg | map | `{"enabled":false}` | Jupyter Enterprise Gateway for vectis workspaces. | +| jeg.enabled | bool | `false` | Whether to deploy the jeg subchart. | | manifestservice.enabled | bool | `true` | Whether to deploy the manifest service subchart. | | metadata.enabled | bool | `true` | Whether to deploy the metadata subchart. | | mutatingWebhook.enabled | bool | `false` | Whether to deploy the mutating webhook service. | @@ -268,4 +273,8 @@ Helm chart to deploy Gen3 Data Commons | tests | map | `{"SERVICE_TO_TEST":null,"TEST_LABEL":null,"image":{"tag":"master"},"resources":{"limits":{"memory":"10G"},"requests":{"memory":"6G"}}}` | Environment variables that control which tests are run. | | tests.SERVICE_TO_TEST | str | `nil` | Name of the service we are testing. Default is empty as GH workflow automatically sets this. | | tests.TEST_LABEL | str | `nil` | Name of the test that will run. Default is empty as GH workflow automatically sets this. | +| vectis-overlays | map | `{"enabled":false}` | vectis-overlays — guppy-compat, siem-service, search-auth-proxy. | +| vectis-overlays.enabled | bool | `false` | Whether to deploy the vectis-overlays subchart. | +| workspace-proxy | map | `{"enabled":false}` | workspace-proxy — per-user workspace HTTP/WebSocket router. | +| workspace-proxy.enabled | bool | `false` | Whether to deploy the workspace-proxy subchart. | | wts.enabled | bool | `true` | Whether to deploy the wts subchart. | diff --git a/helm/jeg/README.md b/helm/jeg/README.md index b3edbd8c7..cc49eece9 100644 --- a/helm/jeg/README.md +++ b/helm/jeg/README.md @@ -1,6 +1,6 @@ # jeg -![Version: 0.1.0](https://img.shields.io/badge/Version-0.1.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 3.2.3](https://img.shields.io/badge/AppVersion-3.2.3-informational?style=flat-square) +![Version: 0.1.1](https://img.shields.io/badge/Version-0.1.1-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 3.2.3](https://img.shields.io/badge/AppVersion-3.2.3-informational?style=flat-square) Jupyter Enterprise Gateway for gen3 vectis workspaces. Launches ephemeral kernel pods in the workspace namespace on behalf of user Jupyter sessions proxied through workspace-proxy. diff --git a/helm/revproxy/Chart.yaml b/helm/revproxy/Chart.yaml index 36576de88..25df4dcf0 100644 --- a/helm/revproxy/Chart.yaml +++ b/helm/revproxy/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.62 +version: 0.1.63 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/revproxy/README.md b/helm/revproxy/README.md index 3c1b453c2..fcec75978 100644 --- a/helm/revproxy/README.md +++ b/helm/revproxy/README.md @@ -1,6 +1,6 @@ # revproxy -![Version: 0.1.62](https://img.shields.io/badge/Version-0.1.62-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.63](https://img.shields.io/badge/Version-0.1.63-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 revproxy @@ -14,6 +14,7 @@ A Helm chart for gen3 revproxy | Key | Type | Default | Description | |-----|------|---------|-------------| +| additionalConfigs | map | `{}` | Raw nginx location blocks to add or override entries in the revproxy-nginx-subconf ConfigMap. Keys are the conf filename (e.g. "guppy-service.conf"). A key matching a built-in static conf file will replace that file's content, allowing disabled services to be suppressed or routes redirected to alternative upstreams without modifying the chart. | | affinity | map | `{}` | Affinity to use for the deployment. | | autoscaling | object | `{}` | | | commonLabels | map | `nil` | Will completely override the commonLabels defined in the common chart's _label_setup.tpl | diff --git a/helm/vectis-overlays/README.md b/helm/vectis-overlays/README.md index c69b57515..5a66a5bc0 100644 --- a/helm/vectis-overlays/README.md +++ b/helm/vectis-overlays/README.md @@ -1,6 +1,6 @@ # vectis-overlays -![Version: 0.1.0](https://img.shields.io/badge/Version-0.1.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.0](https://img.shields.io/badge/AppVersion-1.0-informational?style=flat-square) +![Version: 0.1.1](https://img.shields.io/badge/Version-0.1.1-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.0](https://img.shields.io/badge/AppVersion-1.0-informational?style=flat-square) Vectis overlay API services (guppy-compat, siem, search-auth-proxy) @@ -14,6 +14,7 @@ Vectis overlay API services (guppy-compat, siem, search-auth-proxy) | Key | Type | Default | Description | |-----|------|---------|-------------| +| global.externalSecrets.clusterSecretStoreRef | string | `""` | | | guppyCompat.enabled | bool | `false` | | | guppyCompat.env.GUPPY_COMPAT_MAX_LIMIT | string | `"5000"` | | | guppyCompat.image.pullPolicy | string | `"Always"` | | diff --git a/helm/workspace-proxy/README.md b/helm/workspace-proxy/README.md index d4d2fb9ab..b72ab5c47 100644 --- a/helm/workspace-proxy/README.md +++ b/helm/workspace-proxy/README.md @@ -1,6 +1,6 @@ # workspace-proxy -![Version: 0.1.0](https://img.shields.io/badge/Version-0.1.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.0](https://img.shields.io/badge/AppVersion-1.0-informational?style=flat-square) +![Version: 0.1.1](https://img.shields.io/badge/Version-0.1.1-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.0](https://img.shields.io/badge/AppVersion-1.0-informational?style=flat-square) Per-user workspace HTTP/WebSocket router for gen3 vectis. Replaces Emissary/Ambassador. Reads Service annotations written by Hatchery to resolve each user's workspace upstream, then proxies traffic from revproxy. From 6977ebf3b44d6ec93b5b895e01d0bab70bfd757e Mon Sep 17 00:00:00 2001 From: Edward Malinowski Date: Thu, 9 Jul 2026 10:16:01 -0500 Subject: [PATCH 103/196] Bumped versions --- helm/jeg/Chart.yaml | 2 +- helm/jeg/README.md | 2 +- helm/vectis-overlays/Chart.yaml | 2 +- helm/vectis-overlays/README.md | 2 +- helm/workspace-proxy/Chart.yaml | 2 +- helm/workspace-proxy/README.md | 2 +- 6 files changed, 6 insertions(+), 6 deletions(-) diff --git a/helm/jeg/Chart.yaml b/helm/jeg/Chart.yaml index 5d2563597..bd5e38f33 100644 --- a/helm/jeg/Chart.yaml +++ b/helm/jeg/Chart.yaml @@ -10,5 +10,5 @@ appVersion: "3.2.3" dependencies: - name: common - version: 0.1.34 + version: 0.1.37 repository: file://../common diff --git a/helm/jeg/README.md b/helm/jeg/README.md index cc49eece9..b6ee07fc5 100644 --- a/helm/jeg/README.md +++ b/helm/jeg/README.md @@ -8,7 +8,7 @@ Jupyter Enterprise Gateway for gen3 vectis workspaces. Launches ephemeral kernel | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.34 | +| file://../common | common | 0.1.37 | ## Values diff --git a/helm/vectis-overlays/Chart.yaml b/helm/vectis-overlays/Chart.yaml index c994590eb..35b9bd13e 100644 --- a/helm/vectis-overlays/Chart.yaml +++ b/helm/vectis-overlays/Chart.yaml @@ -7,5 +7,5 @@ appVersion: "1.0" dependencies: - name: common - version: 0.1.34 + version: 0.1.37 repository: file://../common diff --git a/helm/vectis-overlays/README.md b/helm/vectis-overlays/README.md index 5a66a5bc0..f479b22ca 100644 --- a/helm/vectis-overlays/README.md +++ b/helm/vectis-overlays/README.md @@ -8,7 +8,7 @@ Vectis overlay API services (guppy-compat, siem, search-auth-proxy) | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.34 | +| file://../common | common | 0.1.37 | ## Values diff --git a/helm/workspace-proxy/Chart.yaml b/helm/workspace-proxy/Chart.yaml index 4fba13e98..40cc5ff62 100644 --- a/helm/workspace-proxy/Chart.yaml +++ b/helm/workspace-proxy/Chart.yaml @@ -10,5 +10,5 @@ appVersion: "1.0" dependencies: - name: common - version: 0.1.34 + version: 0.1.37 repository: file://../common diff --git a/helm/workspace-proxy/README.md b/helm/workspace-proxy/README.md index b72ab5c47..22fea5d7e 100644 --- a/helm/workspace-proxy/README.md +++ b/helm/workspace-proxy/README.md @@ -8,7 +8,7 @@ Per-user workspace HTTP/WebSocket router for gen3 vectis. Replaces Emissary/Amba | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.34 | +| file://../common | common | 0.1.37 | ## Values From bace66d5d932a53c5c16666e8f55b9f3b034a6aa Mon Sep 17 00:00:00 2001 From: Sai Shanmukha Date: Thu, 9 Jul 2026 10:17:55 -0500 Subject: [PATCH 104/196] Add ConfigMapTemplate --- helm/funnel/files/server-config.yaml | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/helm/funnel/files/server-config.yaml b/helm/funnel/files/server-config.yaml index 3353892ae..c585576aa 100644 --- a/helm/funnel/files/server-config.yaml +++ b/helm/funnel/files/server-config.yaml @@ -53,6 +53,10 @@ Kubernetes: ExecutorTemplate: | {{ tpl ((.Values.Kubernetes.ExecutorTemplate | default (.Files.Get "files/executor-job.yaml"))) . | indent 4 }} +# ConfigMap template + ConfigMapTemplate: | +{{ tpl (.Files.Get "files/worker-configmap.yaml") . | indent 4 }} + # PV template PVTemplate: | {{ tpl (.Files.Get "files/worker-pv.yaml") . | indent 4 }} From e4a71a172eb721e5f18c16120c84d586021a0c42 Mon Sep 17 00:00:00 2001 From: Edward Malinowski Date: Thu, 9 Jul 2026 10:22:30 -0500 Subject: [PATCH 105/196] Bumped versions --- helm/gen3/Chart.yaml | 6 +++--- helm/gen3/README.md | 6 +++--- helm/jeg/Chart.yaml | 2 +- helm/jeg/README.md | 2 +- helm/vectis-overlays/Chart.yaml | 2 +- helm/vectis-overlays/README.md | 2 +- helm/workspace-proxy/Chart.yaml | 2 +- helm/workspace-proxy/README.md | 2 +- 8 files changed, 12 insertions(+), 12 deletions(-) diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index 7155b5ea6..6c1b84662 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -183,15 +183,15 @@ dependencies: repository: "file://../neuvector" condition: neuvector.enabled - name: jeg - version: 0.1.1 + version: 0.1.2 repository: "file://../jeg" condition: jeg.enabled - name: workspace-proxy - version: 0.1.1 + version: 0.1.2 repository: "file://../workspace-proxy" condition: workspace-proxy.enabled - name: vectis-overlays - version: 0.1.1 + version: 0.1.2 repository: "file://../vectis-overlays" condition: vectis-overlays.enabled diff --git a/helm/gen3/README.md b/helm/gen3/README.md index 71963bd2f..e8a84b8a7 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -44,7 +44,7 @@ Helm chart to deploy Gen3 Data Commons | file://../guppy | guppy | 0.1.38 | | file://../hatchery | hatchery | 0.1.70 | | file://../indexd | indexd | 0.1.48 | -| file://../jeg | jeg | 0.1.1 | +| file://../jeg | jeg | 0.1.2 | | file://../manifestservice | manifestservice | 0.1.43 | | file://../metadata | metadata | 0.1.45 | | file://../neuvector | neuvector | 0.1.2 | @@ -59,8 +59,8 @@ Helm chart to deploy Gen3 Data Commons | file://../sheepdog | sheepdog | 0.1.43 | | file://../sower | sower | 0.1.47 | | file://../ssjdispatcher | ssjdispatcher | 0.1.48 | -| file://../vectis-overlays | vectis-overlays | 0.1.1 | -| file://../workspace-proxy | workspace-proxy | 0.1.1 | +| file://../vectis-overlays | vectis-overlays | 0.1.2 | +| file://../workspace-proxy | workspace-proxy | 0.1.2 | | file://../wts | wts | 0.1.41 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | | https://helm.elastic.co | elasticsearch | 7.10.2 | diff --git a/helm/jeg/Chart.yaml b/helm/jeg/Chart.yaml index bd5e38f33..8567c3d50 100644 --- a/helm/jeg/Chart.yaml +++ b/helm/jeg/Chart.yaml @@ -5,7 +5,7 @@ description: > Launches ephemeral kernel pods in the workspace namespace on behalf of user Jupyter sessions proxied through workspace-proxy. type: application -version: 0.1.1 +version: 0.1.2 appVersion: "3.2.3" dependencies: diff --git a/helm/jeg/README.md b/helm/jeg/README.md index b6ee07fc5..b092d8e47 100644 --- a/helm/jeg/README.md +++ b/helm/jeg/README.md @@ -1,6 +1,6 @@ # jeg -![Version: 0.1.1](https://img.shields.io/badge/Version-0.1.1-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 3.2.3](https://img.shields.io/badge/AppVersion-3.2.3-informational?style=flat-square) +![Version: 0.1.2](https://img.shields.io/badge/Version-0.1.2-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 3.2.3](https://img.shields.io/badge/AppVersion-3.2.3-informational?style=flat-square) Jupyter Enterprise Gateway for gen3 vectis workspaces. Launches ephemeral kernel pods in the workspace namespace on behalf of user Jupyter sessions proxied through workspace-proxy. diff --git a/helm/vectis-overlays/Chart.yaml b/helm/vectis-overlays/Chart.yaml index 35b9bd13e..19d954e8f 100644 --- a/helm/vectis-overlays/Chart.yaml +++ b/helm/vectis-overlays/Chart.yaml @@ -2,7 +2,7 @@ apiVersion: v2 name: vectis-overlays description: Vectis overlay API services (guppy-compat, siem, search-auth-proxy) type: application -version: 0.1.1 +version: 0.1.2 appVersion: "1.0" dependencies: diff --git a/helm/vectis-overlays/README.md b/helm/vectis-overlays/README.md index f479b22ca..de4f5289c 100644 --- a/helm/vectis-overlays/README.md +++ b/helm/vectis-overlays/README.md @@ -1,6 +1,6 @@ # vectis-overlays -![Version: 0.1.1](https://img.shields.io/badge/Version-0.1.1-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.0](https://img.shields.io/badge/AppVersion-1.0-informational?style=flat-square) +![Version: 0.1.2](https://img.shields.io/badge/Version-0.1.2-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.0](https://img.shields.io/badge/AppVersion-1.0-informational?style=flat-square) Vectis overlay API services (guppy-compat, siem, search-auth-proxy) diff --git a/helm/workspace-proxy/Chart.yaml b/helm/workspace-proxy/Chart.yaml index 40cc5ff62..7f7258ac8 100644 --- a/helm/workspace-proxy/Chart.yaml +++ b/helm/workspace-proxy/Chart.yaml @@ -5,7 +5,7 @@ description: > Replaces Emissary/Ambassador. Reads Service annotations written by Hatchery to resolve each user's workspace upstream, then proxies traffic from revproxy. type: application -version: 0.1.1 +version: 0.1.2 appVersion: "1.0" dependencies: diff --git a/helm/workspace-proxy/README.md b/helm/workspace-proxy/README.md index 22fea5d7e..f25bc9531 100644 --- a/helm/workspace-proxy/README.md +++ b/helm/workspace-proxy/README.md @@ -1,6 +1,6 @@ # workspace-proxy -![Version: 0.1.1](https://img.shields.io/badge/Version-0.1.1-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.0](https://img.shields.io/badge/AppVersion-1.0-informational?style=flat-square) +![Version: 0.1.2](https://img.shields.io/badge/Version-0.1.2-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.0](https://img.shields.io/badge/AppVersion-1.0-informational?style=flat-square) Per-user workspace HTTP/WebSocket router for gen3 vectis. Replaces Emissary/Ambassador. Reads Service annotations written by Hatchery to resolve each user's workspace upstream, then proxies traffic from revproxy. From 69104e32e3833c31059008b2ec5c97f8f951fb17 Mon Sep 17 00:00:00 2001 From: Sai Shanmukha Date: Thu, 9 Jul 2026 10:37:26 -0500 Subject: [PATCH 106/196] Add Missing worker-configmap --- helm/funnel/files/executor-job.yaml | 2 ++ helm/funnel/files/worker-configmap.yaml | 11 +++++++++++ 2 files changed, 13 insertions(+) create mode 100644 helm/funnel/files/worker-configmap.yaml diff --git a/helm/funnel/files/executor-job.yaml b/helm/funnel/files/executor-job.yaml index f65ef175d..8bd6a3da5 100644 --- a/helm/funnel/files/executor-job.yaml +++ b/helm/funnel/files/executor-job.yaml @@ -6,6 +6,7 @@ metadata: namespace: {{`{{.JobsNamespace}}`}} labels: app: funnel-executor + taskId: {{`{{.TaskId}}`}} job-name: {{`{{.TaskId}}-{{.JobId}}`}} spec: backoffLimit: {{ .Values.Kubernetes.Executor.backoffLimit}} @@ -21,6 +22,7 @@ spec: labels: app: funnel-executor + taskId: {{`{{.TaskId}}`}} job-name: {{`{{.TaskId}}`}}-{{`{{.JobId}}`}} spec: diff --git a/helm/funnel/files/worker-configmap.yaml b/helm/funnel/files/worker-configmap.yaml new file mode 100644 index 000000000..25d5a3264 --- /dev/null +++ b/helm/funnel/files/worker-configmap.yaml @@ -0,0 +1,11 @@ +# This is the config containing the templates used by the Funnel Worker +apiVersion: v1 +kind: ConfigMap +metadata: + name: funnel-worker-config-{{`{{ .TaskId }}`}} + namespace: {{`{{ .Namespace }}`}} + labels: + app: funnel +data: + funnel-worker.yaml: | +{{`{{ .Config | indent 4}}`}} From df35d5ba74587d0352ec3c57d8b47afc22e47f59 Mon Sep 17 00:00:00 2001 From: Justin Barnowski Date: Thu, 9 Jul 2026 14:12:33 -0400 Subject: [PATCH 107/196] chor(bump): version bump after the version bump --- helm/common/Chart.yaml | 2 +- helm/common/README.md | 2 +- helm/gen3/Chart.yaml | 4 ++-- helm/gen3/README.md | 4 ++-- 4 files changed, 6 insertions(+), 6 deletions(-) diff --git a/helm/common/Chart.yaml b/helm/common/Chart.yaml index 83fcee7d4..3dfd2f1cc 100644 --- a/helm/common/Chart.yaml +++ b/helm/common/Chart.yaml @@ -15,7 +15,7 @@ type: library # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.37 +version: 0.1.38 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/common/README.md b/helm/common/README.md index c9e00ec28..b48fb0ddf 100644 --- a/helm/common/README.md +++ b/helm/common/README.md @@ -1,6 +1,6 @@ # common -![Version: 0.1.37](https://img.shields.io/badge/Version-0.1.37-informational?style=flat-square) ![Type: library](https://img.shields.io/badge/Type-library-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.38](https://img.shields.io/badge/Version-0.1.38-informational?style=flat-square) ![Type: library](https://img.shields.io/badge/Type-library-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for provisioning databases in gen3 diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index 6c1b84662..4921a5c3c 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -41,7 +41,7 @@ dependencies: repository: "file://../cohort-middleware" condition: cohort-middleware.enabled - name: common - version: 0.1.37 + version: 0.1.38 repository: file://../common - name: dashboard version: 0.1.22 @@ -209,7 +209,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.61 +version: 0.3.62 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index af9895917..ee719cccb 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,6 +1,6 @@ # gen3 -![Version: 0.3.61](https://img.shields.io/badge/Version-0.3.61-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.3.62](https://img.shields.io/badge/Version-0.3.62-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons @@ -27,7 +27,7 @@ Helm chart to deploy Gen3 Data Commons | file://../aws-sigv4-proxy | aws-sigv4-proxy | 0.1.3 | | file://../cedar | cedar | 0.1.27 | | file://../cohort-middleware | cohort-middleware | 0.1.23 | -| file://../common | common | 0.1.37 | +| file://../common | common | 0.1.38 | | file://../dashboard | dashboard | 0.1.22 | | file://../data-upload-cron | data-upload-cron | 0.1.7 | | file://../datareplicate | datareplicate | 0.1.22 | From 8aa3c997bb65591f2e2c26f7a842c72caa728ea9 Mon Sep 17 00:00:00 2001 From: Sai Shanmukha Date: Thu, 9 Jul 2026 13:27:58 -0500 Subject: [PATCH 108/196] Temporarily point funnel to local funnel image --- helm/funnel/Chart.yaml | 2 +- helm/funnel/README.md | 6 +++--- helm/funnel/values.yaml | 4 ++-- helm/gen3/Chart.yaml | 4 ++-- helm/gen3/README.md | 4 ++-- 5 files changed, 10 insertions(+), 10 deletions(-) diff --git a/helm/funnel/Chart.yaml b/helm/funnel/Chart.yaml index 076eed37e..9af349867 100644 --- a/helm/funnel/Chart.yaml +++ b/helm/funnel/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.27 +version: 0.1.28 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/funnel/README.md b/helm/funnel/README.md index 4abfbfa2d..b6718d038 100644 --- a/helm/funnel/README.md +++ b/helm/funnel/README.md @@ -1,6 +1,6 @@ # funnel -![Version: 0.1.27](https://img.shields.io/badge/Version-0.1.27-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.28](https://img.shields.io/badge/Version-0.1.28-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for Kubernetes @@ -182,8 +182,8 @@ A Helm chart for Kubernetes | image.initContainers[0].pullPolicy | string | `"Always"` | When to pull the image. This value should be "Always" to ensure the latest image is used. | | image.initContainers[0].tag | string | `"main-gen3"` | The Docker image tag for the Funnel init/plugin container. | | image.pullPolicy | string | `"Always"` | When to pull the image. This value should be "Always" to ensure the latest image is used. | -| image.repository | string | `"quay.io/ohsu-comp-bio/funnel"` | The Docker image repository for the Funnel service. | -| image.tag | string | `"2026-06-22"` | | +| image.repository | string | `"quay.io/cdis/funnel"` | The Docker image repository for the Funnel service. | +| image.tag | string | `"chore/remove_debug_log"` | | | labels.app | string | `"funnel"` | | | metricsEnabled | bool | `false` | | | netPolicy | map | `{"egressApps":["gen3-workflow"],"ingressApps":["gen3-workflow"]}` | Configuration for network policies created by this chart. Only relevant if "global.netPolicy.enabled" is set to true | diff --git a/helm/funnel/values.yaml b/helm/funnel/values.yaml index 8ea8ba567..7c27bd07f 100644 --- a/helm/funnel/values.yaml +++ b/helm/funnel/values.yaml @@ -127,8 +127,8 @@ partOf: "Workflow_Execution" oidc_job_enabled: true image: # -- (string) The Docker image repository for the Funnel service. - repository: quay.io/ohsu-comp-bio/funnel - tag: 2026-06-22 + repository: quay.io/cdis/funnel + tag: chore/remove_debug_log # -- (string) When to pull the image. This value should be "Always" to ensure the latest image is used. pullPolicy: Always diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index 6dfa0eaa2..d854ced32 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -72,7 +72,7 @@ dependencies: repository: "file://../fence" condition: fence.enabled - name: funnel - version: 0.1.27 + version: 0.1.28 repository: "file://../funnel" condition: gen3-workflow.enabled - name: gen3-user-data-library @@ -197,7 +197,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.61 +version: 0.3.62 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index 08612ab0b..05512f0d5 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,6 +1,6 @@ # gen3 -![Version: 0.3.61](https://img.shields.io/badge/Version-0.3.61-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.3.62](https://img.shields.io/badge/Version-0.3.62-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons @@ -36,7 +36,7 @@ Helm chart to deploy Gen3 Data Commons | file://../etl | etl | 0.1.23 | | file://../fence | fence | 0.1.78 | | file://../frontend-framework | frontend-framework | 0.1.29 | -| file://../funnel | funnel | 0.1.27 | +| file://../funnel | funnel | 0.1.28 | | file://../gen3-analysis | gen3-analysis | 0.1.12 | | file://../gen3-network-policies | gen3-network-policies | 0.1.4 | | file://../gen3-user-data-library | gen3-user-data-library | 0.1.15 | From 0b5e7bf223fb73119d69b4d4fa127ff7c35a84bf Mon Sep 17 00:00:00 2001 From: Justin Barnowski Date: Thu, 9 Jul 2026 14:42:17 -0400 Subject: [PATCH 109/196] feat(PR): heed comments --- examples/local_dev_values.yaml | 1 + 1 file changed, 1 insertion(+) diff --git a/examples/local_dev_values.yaml b/examples/local_dev_values.yaml index b08994dd9..f0f96d86f 100644 --- a/examples/local_dev_values.yaml +++ b/examples/local_dev_values.yaml @@ -29,6 +29,7 @@ fence: portal: image: repository: quay.io/cdis/data-portal-prebuilt + tag: brh.data-commons.org-feat-pr_comment resources: requests: cpu: 0.2 From 0b4fe275b6930e2eae3a08a688606a9bc028e6f1 Mon Sep 17 00:00:00 2001 From: Sai Shanmukha Date: Thu, 9 Jul 2026 15:48:51 -0500 Subject: [PATCH 110/196] Update funnel image name --- helm/funnel/README.md | 2 +- helm/funnel/values.yaml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/helm/funnel/README.md b/helm/funnel/README.md index fa28a640f..628474325 100644 --- a/helm/funnel/README.md +++ b/helm/funnel/README.md @@ -183,7 +183,7 @@ A Helm chart for Kubernetes | image.initContainers[0].tag | string | `"main-gen3"` | The Docker image tag for the Funnel init/plugin container. | | image.pullPolicy | string | `"Always"` | When to pull the image. This value should be "Always" to ensure the latest image is used. | | image.repository | string | `"quay.io/cdis/funnel"` | The Docker image repository for the Funnel service. | -| image.tag | string | `"chore/remove_debug_log"` | | +| image.tag | string | `"chore_remove_debug_log"` | | | labels.app | string | `"funnel"` | | | metricsEnabled | bool | `false` | | | netPolicy | map | `{"egressApps":["gen3-workflow"],"ingressApps":["gen3-workflow"]}` | Configuration for network policies created by this chart. Only relevant if "global.netPolicy.enabled" is set to true | diff --git a/helm/funnel/values.yaml b/helm/funnel/values.yaml index 7c27bd07f..0cc5c5440 100644 --- a/helm/funnel/values.yaml +++ b/helm/funnel/values.yaml @@ -128,7 +128,7 @@ oidc_job_enabled: true image: # -- (string) The Docker image repository for the Funnel service. repository: quay.io/cdis/funnel - tag: chore/remove_debug_log + tag: chore_remove_debug_log # -- (string) When to pull the image. This value should be "Always" to ensure the latest image is used. pullPolicy: Always From dd2c334fcad073397bbee847764ca673eef02bcf Mon Sep 17 00:00:00 2001 From: Sai Shanmukha Date: Thu, 9 Jul 2026 17:57:16 -0500 Subject: [PATCH 111/196] Targetting a build tag based off of OHSU's latest `develop` branch --- helm/funnel/README.md | 4 ++-- helm/funnel/values.yaml | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/helm/funnel/README.md b/helm/funnel/README.md index 628474325..12047f444 100644 --- a/helm/funnel/README.md +++ b/helm/funnel/README.md @@ -182,8 +182,8 @@ A Helm chart for Kubernetes | image.initContainers[0].pullPolicy | string | `"Always"` | When to pull the image. This value should be "Always" to ensure the latest image is used. | | image.initContainers[0].tag | string | `"main-gen3"` | The Docker image tag for the Funnel init/plugin container. | | image.pullPolicy | string | `"Always"` | When to pull the image. This value should be "Always" to ensure the latest image is used. | -| image.repository | string | `"quay.io/cdis/funnel"` | The Docker image repository for the Funnel service. | -| image.tag | string | `"chore_remove_debug_log"` | | +| image.repository | string | `"quay.io/ohsu-comp-bio/funnel"` | The Docker image repository for the Funnel service. | +| image.tag | string | `"develop-2026-07-09-19-49-55Z-97d1df55"` | | | labels.app | string | `"funnel"` | | | metricsEnabled | bool | `false` | | | netPolicy | map | `{"egressApps":["gen3-workflow"],"ingressApps":["gen3-workflow"]}` | Configuration for network policies created by this chart. Only relevant if "global.netPolicy.enabled" is set to true | diff --git a/helm/funnel/values.yaml b/helm/funnel/values.yaml index 0cc5c5440..b539afd15 100644 --- a/helm/funnel/values.yaml +++ b/helm/funnel/values.yaml @@ -127,8 +127,8 @@ partOf: "Workflow_Execution" oidc_job_enabled: true image: # -- (string) The Docker image repository for the Funnel service. - repository: quay.io/cdis/funnel - tag: chore_remove_debug_log + repository: quay.io/ohsu-comp-bio/funnel + tag: develop-2026-07-09-19-49-55Z-97d1df55 # -- (string) When to pull the image. This value should be "Always" to ensure the latest image is used. pullPolicy: Always From fd44dbf1cee68a98edafd09e27a9ab8b142e2681 Mon Sep 17 00:00:00 2001 From: Mingfei Shao Date: Thu, 9 Jul 2026 22:49:13 -0500 Subject: [PATCH 112/196] update revproxy conf --- helm/revproxy/gen3.nginx.conf/zendesk-wrapper-service.conf | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/helm/revproxy/gen3.nginx.conf/zendesk-wrapper-service.conf b/helm/revproxy/gen3.nginx.conf/zendesk-wrapper-service.conf index 29e2509e3..962f89931 100644 --- a/helm/revproxy/gen3.nginx.conf/zendesk-wrapper-service.conf +++ b/helm/revproxy/gen3.nginx.conf/zendesk-wrapper-service.conf @@ -5,9 +5,10 @@ return 403 "failed csrf check"; } - set $authz_resource "/zendesk"; + # this is the old policy, retaining it for backward compatibility reason + set $authz_resource "/kayako"; set $authz_method "create"; - set $authz_service "zendesk"; + set $authz_service "kayako"; # # be careful - sub-request runs in same context as this request auth_request_set $remoteUser $upstream_http_REMOTE_USER; auth_request_set $saved_set_cookie $upstream_http_set_cookie; From 98297647a99351a116b88ac3f41ecb9ceb1eeeb5 Mon Sep 17 00:00:00 2001 From: Sai Shanmukha Date: Fri, 10 Jul 2026 02:08:18 -0500 Subject: [PATCH 113/196] Add Fence URL in manifest service's deployment --- helm/gen3/Chart.yaml | 4 ++-- helm/gen3/README.md | 4 ++-- helm/manifestservice/Chart.yaml | 2 +- helm/manifestservice/README.md | 3 ++- helm/manifestservice/templates/deployment.yaml | 2 ++ helm/manifestservice/values.yaml | 2 ++ 6 files changed, 11 insertions(+), 6 deletions(-) diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index 4921a5c3c..3e02139ed 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -96,7 +96,7 @@ dependencies: repository: "file://../indexd" condition: indexd.enabled - name: manifestservice - version: 0.1.43 + version: 0.1.44 repository: "file://../manifestservice" condition: manifestservice.enabled - name: metadata @@ -209,7 +209,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.62 +version: 0.3.63 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index ee719cccb..358a05a6f 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,6 +1,6 @@ # gen3 -![Version: 0.3.62](https://img.shields.io/badge/Version-0.3.62-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.3.63](https://img.shields.io/badge/Version-0.3.63-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons @@ -45,7 +45,7 @@ Helm chart to deploy Gen3 Data Commons | file://../hatchery | hatchery | 0.1.70 | | file://../indexd | indexd | 0.1.48 | | file://../jeg | jeg | 0.1.2 | -| file://../manifestservice | manifestservice | 0.1.43 | +| file://../manifestservice | manifestservice | 0.1.44 | | file://../metadata | metadata | 0.1.45 | | file://../neuvector | neuvector | 0.1.2 | | file://../ohdsi-atlas | ohdsi-atlas | 0.1.2 | diff --git a/helm/manifestservice/Chart.yaml b/helm/manifestservice/Chart.yaml index 74098c9a5..cf02f0d21 100644 --- a/helm/manifestservice/Chart.yaml +++ b/helm/manifestservice/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.43 +version: 0.1.44 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/manifestservice/README.md b/helm/manifestservice/README.md index 57cacf1d3..2731a0d38 100644 --- a/helm/manifestservice/README.md +++ b/helm/manifestservice/README.md @@ -1,6 +1,6 @@ # manifestservice -![Version: 0.1.43](https://img.shields.io/badge/Version-0.1.43-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.44](https://img.shields.io/badge/Version-0.1.44-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for Kubernetes @@ -54,6 +54,7 @@ A Helm chart for Kubernetes | global.externalSecrets | map | `{"deploy":false,"separateSecretStore":false}` | External Secrets settings. | | global.externalSecrets.deploy | bool | `false` | Will use ExternalSecret resources to pull secrets from Secrets Manager instead of creating them locally. Be cautious as this will override any manifestservice secrets you have deployed. | | global.externalSecrets.separateSecretStore | string | `false` | Will deploy a separate External Secret Store for this service. | +| global.hostname | string | `""` | Hostname for the deployment. | | global.minAvailable | int | `1` | The minimum amount of pods that are available at all times if the PDB is deployed. | | global.pdb | bool | `false` | If the service will be deployed with a Pod Disruption Budget. Note- you need to have more than 2 replicas for the pdb to be deployed. | | global.topologySpread | map | `{"enabled":false,"maxSkew":1,"topologyKey":"topology.kubernetes.io/zone"}` | Karpenter topology spread configuration. | diff --git a/helm/manifestservice/templates/deployment.yaml b/helm/manifestservice/templates/deployment.yaml index 1b0de1072..75df25d76 100644 --- a/helm/manifestservice/templates/deployment.yaml +++ b/helm/manifestservice/templates/deployment.yaml @@ -85,6 +85,8 @@ spec: {{- end }} key: secret-access-key {{- end }} + - name: FENCE_URL + value: {{ default "http://fence-service" (printf "https://%s/user" .Values.global.hostname) }} volumeMounts: {{- toYaml .Values.volumeMounts | nindent 12 }} resources: diff --git a/helm/manifestservice/values.yaml b/helm/manifestservice/values.yaml index 721082f6d..5d0e22a70 100644 --- a/helm/manifestservice/values.yaml +++ b/helm/manifestservice/values.yaml @@ -26,6 +26,8 @@ global: localSecretName: # -- (string) Environment name. This should be the same as vpcname if you're doing an AWS deployment. Currently this is being used to share ALB's if you have multiple namespaces. Might be used other places too. environment: default + # -- (string) Hostname for the deployment. + hostname: "" # -- (bool) If the service will be deployed with a Pod Disruption Budget. Note- you need to have more than 2 replicas for the pdb to be deployed. pdb: false # -- (int) The minimum amount of pods that are available at all times if the PDB is deployed. From cf140aabe557e895f38c677aadfe29eb9761b25c Mon Sep 17 00:00:00 2001 From: Sai Shanmukha Date: Fri, 10 Jul 2026 02:11:01 -0500 Subject: [PATCH 114/196] Update common chart version --- helm/manifestservice/Chart.yaml | 2 +- helm/manifestservice/README.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/helm/manifestservice/Chart.yaml b/helm/manifestservice/Chart.yaml index cf02f0d21..839aa16bc 100644 --- a/helm/manifestservice/Chart.yaml +++ b/helm/manifestservice/Chart.yaml @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.37 + version: 0.1.38 repository: file://../common diff --git a/helm/manifestservice/README.md b/helm/manifestservice/README.md index 2731a0d38..7cbc9a1c0 100644 --- a/helm/manifestservice/README.md +++ b/helm/manifestservice/README.md @@ -8,7 +8,7 @@ A Helm chart for Kubernetes | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.37 | +| file://../common | common | 0.1.38 | ## Values From a7c341c235f811d81f24e522538b436b33c0dc49 Mon Sep 17 00:00:00 2001 From: Mingfei Shao Date: Fri, 10 Jul 2026 09:48:41 -0500 Subject: [PATCH 115/196] update ports --- helm/zendesk-wrapper/README.md | 5 +++-- .../zendesk-wrapper/templates/deployment.yaml | 21 +++++++++++++------ helm/zendesk-wrapper/templates/service.yaml | 10 +++++++-- helm/zendesk-wrapper/values.yaml | 6 +++++- 4 files changed, 31 insertions(+), 11 deletions(-) diff --git a/helm/zendesk-wrapper/README.md b/helm/zendesk-wrapper/README.md index 79d68e565..c06009b5f 100644 --- a/helm/zendesk-wrapper/README.md +++ b/helm/zendesk-wrapper/README.md @@ -52,8 +52,9 @@ A Helm chart for gen3 Zendesk Wrapper Service | resources.limits.memory | string | `"128Mi"` | | | revisionHistoryLimit | int | `2` | | | selectorLabels | string | `nil` | | -| service.port | int | `80` | | -| service.targetPort | int | `8000` | | +| service.httpPort | int | `80` | Port on which the service is exposed | +| service.httpsPort | int | `443` | Secure port on which the service is exposed | +| service.targetPort | int | `8000` | Port on which the service is exposed for Cedar API | | service.type | string | `"ClusterIP"` | | | strategy.rollingUpdate.maxSurge | int | `1` | | | strategy.rollingUpdate.maxUnavailable | int | `0` | | diff --git a/helm/zendesk-wrapper/templates/deployment.yaml b/helm/zendesk-wrapper/templates/deployment.yaml index ef5ede042..658c296da 100644 --- a/helm/zendesk-wrapper/templates/deployment.yaml +++ b/helm/zendesk-wrapper/templates/deployment.yaml @@ -38,16 +38,25 @@ spec: containers: - name: {{ .Chart.Name }} image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}" + readinessProbe: + httpGet: + path: /_status/ + port: http + initialDelaySeconds: 30 + periodSeconds: 60 + timeoutSeconds: 30 livenessProbe: httpGet: - path: /_status - port: 8000 - initialDelaySeconds: 10 - periodSeconds: 30 - timeoutSeconds: 10 + path: /_status/ + port: http + initialDelaySeconds: 60 + periodSeconds: 60 + timeoutSeconds: 30 + failureThreshold: 6 imagePullPolicy: {{ .Values.image.pullPolicy }} ports: - - containerPort: 8000 + - name: http + containerPort: {{ .Values.service.targetPort }} protocol: TCP resources: {{- toYaml .Values.resources | nindent 12 }} diff --git a/helm/zendesk-wrapper/templates/service.yaml b/helm/zendesk-wrapper/templates/service.yaml index 764b0af5a..7e2fa975e 100644 --- a/helm/zendesk-wrapper/templates/service.yaml +++ b/helm/zendesk-wrapper/templates/service.yaml @@ -7,9 +7,15 @@ metadata: spec: type: {{ .Values.service.type }} ports: - - port: {{ .Values.service.port }} + - protocol: TCP + port: {{ .Values.service.httpPort }} targetPort: {{ .Values.service.targetPort }} - protocol: TCP name: http + nodePort: null + - protocol: TCP + port: {{ .Values.service.httpsPort }} + targetPort: {{ .Values.service.targetPort }} + name: https + nodePort: null selector: {{- include "zendesk-wrapper.selectorLabels" . | nindent 4 }} diff --git a/helm/zendesk-wrapper/values.yaml b/helm/zendesk-wrapper/values.yaml index 3fb6595a8..e4662c7c5 100644 --- a/helm/zendesk-wrapper/values.yaml +++ b/helm/zendesk-wrapper/values.yaml @@ -58,7 +58,11 @@ resources: service: type: ClusterIP - port: 80 + # -- (int) Port on which the service is exposed + httpPort: 80 + # -- (int) Secure port on which the service is exposed + httpsPort: 443 + # -- (int) Port on which the service is exposed for Cedar API targetPort: 8000 netPolicy: From 89506ccc7dd05e648af35e55deb265a04245f0b6 Mon Sep 17 00:00:00 2001 From: Ajo Augustine Date: Fri, 10 Jul 2026 10:20:16 -0500 Subject: [PATCH 116/196] netpolicy updates for fence --- helm/fence/Chart.yaml | 2 +- helm/fence/README.md | 2 +- helm/fence/templates/fence-deployment.yaml | 4 +++- helm/fence/templates/presigned-url-fence.yaml | 4 +++- helm/gen3/Chart.yaml | 6 +++--- helm/gen3/README.md | 6 +++--- helm/hatchery/Chart.yaml | 2 +- helm/hatchery/README.md | 2 +- helm/hatchery/templates/deployment.yaml | 1 + 9 files changed, 17 insertions(+), 12 deletions(-) diff --git a/helm/fence/Chart.yaml b/helm/fence/Chart.yaml index acbd322a8..af131482d 100644 --- a/helm/fence/Chart.yaml +++ b/helm/fence/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.79 +version: 0.1.80 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/fence/README.md b/helm/fence/README.md index 9eed88fb7..1277c030a 100644 --- a/helm/fence/README.md +++ b/helm/fence/README.md @@ -1,6 +1,6 @@ # fence -![Version: 0.1.79](https://img.shields.io/badge/Version-0.1.79-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.80](https://img.shields.io/badge/Version-0.1.80-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Fence diff --git a/helm/fence/templates/fence-deployment.yaml b/helm/fence/templates/fence-deployment.yaml index ab7a59dc7..e4113ee3f 100644 --- a/helm/fence/templates/fence-deployment.yaml +++ b/helm/fence/templates/fence-deployment.yaml @@ -33,6 +33,8 @@ spec: labels: authprovider: "yes" netnolimit: "yes" + internet: "yes" + linklocal: "yes" userhelper: "yes" {{- include "fence.selectorLabels" . | nindent 8 }} {{- include "common.extraLabels" . | nindent 8 }} @@ -133,4 +135,4 @@ spec: {{- with .Values.tolerations }} tolerations: {{- toYaml . | nindent 8 }} - {{- end }} \ No newline at end of file + {{- end }} diff --git a/helm/fence/templates/presigned-url-fence.yaml b/helm/fence/templates/presigned-url-fence.yaml index a230188b2..6d356f8da 100644 --- a/helm/fence/templates/presigned-url-fence.yaml +++ b/helm/fence/templates/presigned-url-fence.yaml @@ -35,6 +35,8 @@ spec: authprovder: "yes" netnolimit: "yes" public: "yes" + internet: "yes" + linklocal: "yes" userhelper: "yes" spec: serviceAccountName: {{ include "fence.serviceAccountName" . }} @@ -132,4 +134,4 @@ spec: - gen3job policyTypes: - Egress -{{- end }} \ No newline at end of file +{{- end }} diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index 4921a5c3c..e72f87d63 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -68,7 +68,7 @@ dependencies: repository: "file://../frontend-framework" condition: frontend-framework.enabled - name: fence - version: 0.1.79 + version: 0.1.80 repository: "file://../fence" condition: fence.enabled - name: funnel @@ -88,7 +88,7 @@ dependencies: repository: "file://../guppy" condition: guppy.enabled - name: hatchery - version: 0.1.70 + version: 0.1.71 repository: "file://../hatchery" condition: hatchery.enabled - name: indexd @@ -209,7 +209,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.62 +version: 0.3.63 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index ee719cccb..13b6ed8ec 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,6 +1,6 @@ # gen3 -![Version: 0.3.62](https://img.shields.io/badge/Version-0.3.62-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.3.63](https://img.shields.io/badge/Version-0.3.63-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons @@ -34,7 +34,7 @@ Helm chart to deploy Gen3 Data Commons | file://../dicom-server | dicom-server | 0.1.32 | | file://../embedding-management-service | embedding-management-service | 0.1.8 | | file://../etl | etl | 0.1.23 | -| file://../fence | fence | 0.1.79 | +| file://../fence | fence | 0.1.80 | | file://../frontend-framework | frontend-framework | 0.1.30 | | file://../funnel | funnel | 0.1.27 | | file://../gen3-analysis | gen3-analysis | 0.1.13 | @@ -42,7 +42,7 @@ Helm chart to deploy Gen3 Data Commons | file://../gen3-user-data-library | gen3-user-data-library | 0.1.16 | | file://../gen3-workflow | gen3-workflow | 0.1.23 | | file://../guppy | guppy | 0.1.38 | -| file://../hatchery | hatchery | 0.1.70 | +| file://../hatchery | hatchery | 0.1.71 | | file://../indexd | indexd | 0.1.48 | | file://../jeg | jeg | 0.1.2 | | file://../manifestservice | manifestservice | 0.1.43 | diff --git a/helm/hatchery/Chart.yaml b/helm/hatchery/Chart.yaml index bcb781391..1a0c2af6a 100644 --- a/helm/hatchery/Chart.yaml +++ b/helm/hatchery/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.70 +version: 0.1.71 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/hatchery/README.md b/helm/hatchery/README.md index 0f4e859eb..117ac8ca7 100644 --- a/helm/hatchery/README.md +++ b/helm/hatchery/README.md @@ -1,6 +1,6 @@ # hatchery -![Version: 0.1.70](https://img.shields.io/badge/Version-0.1.70-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.71](https://img.shields.io/badge/Version-0.1.71-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Hatchery diff --git a/helm/hatchery/templates/deployment.yaml b/helm/hatchery/templates/deployment.yaml index 0e077bf40..742352cd1 100644 --- a/helm/hatchery/templates/deployment.yaml +++ b/helm/hatchery/templates/deployment.yaml @@ -33,6 +33,7 @@ spec: netnolimit: "yes" public: "yes" userhelper: "yes" + netvpc: "yes" {{- include "hatchery.selectorLabels" . | nindent 8 }} {{- include "common.extraLabels" . | nindent 8 }} spec: From e913653650b2050b5f3c61e226dc6fe30b16c96e Mon Sep 17 00:00:00 2001 From: Mingfei Shao Date: Fri, 10 Jul 2026 11:18:36 -0500 Subject: [PATCH 117/196] fix port --- helm/zendesk-wrapper/README.md | 2 +- helm/zendesk-wrapper/templates/deployment.yaml | 3 +++ helm/zendesk-wrapper/values.yaml | 4 ++-- 3 files changed, 6 insertions(+), 3 deletions(-) diff --git a/helm/zendesk-wrapper/README.md b/helm/zendesk-wrapper/README.md index c06009b5f..94dbd1093 100644 --- a/helm/zendesk-wrapper/README.md +++ b/helm/zendesk-wrapper/README.md @@ -54,7 +54,7 @@ A Helm chart for gen3 Zendesk Wrapper Service | selectorLabels | string | `nil` | | | service.httpPort | int | `80` | Port on which the service is exposed | | service.httpsPort | int | `443` | Secure port on which the service is exposed | -| service.targetPort | int | `8000` | Port on which the service is exposed for Cedar API | +| service.targetPort | int | `80` | Port on which the service is exposed for Zendesk wrapper API | | service.type | string | `"ClusterIP"` | | | strategy.rollingUpdate.maxSurge | int | `1` | | | strategy.rollingUpdate.maxUnavailable | int | `0` | | diff --git a/helm/zendesk-wrapper/templates/deployment.yaml b/helm/zendesk-wrapper/templates/deployment.yaml index 658c296da..400867ff2 100644 --- a/helm/zendesk-wrapper/templates/deployment.yaml +++ b/helm/zendesk-wrapper/templates/deployment.yaml @@ -54,6 +54,9 @@ spec: timeoutSeconds: 30 failureThreshold: 6 imagePullPolicy: {{ .Values.image.pullPolicy }} + command: + - /bin/bash + - /src/start.sh ports: - name: http containerPort: {{ .Values.service.targetPort }} diff --git a/helm/zendesk-wrapper/values.yaml b/helm/zendesk-wrapper/values.yaml index e4662c7c5..52aed5ca5 100644 --- a/helm/zendesk-wrapper/values.yaml +++ b/helm/zendesk-wrapper/values.yaml @@ -62,8 +62,8 @@ service: httpPort: 80 # -- (int) Secure port on which the service is exposed httpsPort: 443 - # -- (int) Port on which the service is exposed for Cedar API - targetPort: 8000 + # -- (int) Port on which the service is exposed for Zendesk wrapper API + targetPort: 80 netPolicy: ingressApps: From 31fe320cc59e04532d9b7ea6a1722f0a62f955ae Mon Sep 17 00:00:00 2001 From: Ajo Augustine Date: Fri, 10 Jul 2026 12:35:28 -0500 Subject: [PATCH 118/196] bump chart versions --- helm/fence/Chart.yaml | 2 +- helm/fence/README.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/helm/fence/Chart.yaml b/helm/fence/Chart.yaml index af131482d..72889afce 100644 --- a/helm/fence/Chart.yaml +++ b/helm/fence/Chart.yaml @@ -24,7 +24,7 @@ appVersion: "master" dependencies: - name: common - version: 0.1.37 + version: 0.1.38 repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/fence/README.md b/helm/fence/README.md index 1277c030a..97e6d01de 100644 --- a/helm/fence/README.md +++ b/helm/fence/README.md @@ -8,7 +8,7 @@ A Helm chart for gen3 Fence | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.37 | +| file://../common | common | 0.1.38 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | ## Values From 67f12244dc19369eb49a69b3b3bd66e47450085c Mon Sep 17 00:00:00 2001 From: Sai Shanmukha Date: Fri, 10 Jul 2026 12:51:47 -0500 Subject: [PATCH 119/196] Use AUTHZ_AUDIENCE for sheepdog' audience field --- helm/gen3/Chart.yaml | 4 ++-- helm/gen3/README.md | 4 ++-- helm/sheepdog/Chart.yaml | 2 +- helm/sheepdog/README.md | 2 +- helm/sheepdog/sheepdog-secret/settings.py | 1 + 5 files changed, 7 insertions(+), 6 deletions(-) diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index 3e02139ed..ee3bb021f 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -120,7 +120,7 @@ dependencies: repository: "file://../revproxy" condition: revproxy.enabled - name: sheepdog - version: 0.1.43 + version: 0.1.44 repository: "file://../sheepdog" condition: sheepdog.enabled - name: ssjdispatcher @@ -209,7 +209,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.63 +version: 0.3.64 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index 358a05a6f..26a412536 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,6 +1,6 @@ # gen3 -![Version: 0.3.63](https://img.shields.io/badge/Version-0.3.63-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.3.64](https://img.shields.io/badge/Version-0.3.64-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons @@ -56,7 +56,7 @@ Helm chart to deploy Gen3 Data Commons | file://../portal | portal | 0.1.61 | | file://../requestor | requestor | 0.1.35 | | file://../revproxy | revproxy | 0.1.63 | -| file://../sheepdog | sheepdog | 0.1.43 | +| file://../sheepdog | sheepdog | 0.1.44 | | file://../sower | sower | 0.1.47 | | file://../ssjdispatcher | ssjdispatcher | 0.1.48 | | file://../vectis-overlays | vectis-overlays | 0.1.2 | diff --git a/helm/sheepdog/Chart.yaml b/helm/sheepdog/Chart.yaml index 8b05d4381..91f155b9b 100644 --- a/helm/sheepdog/Chart.yaml +++ b/helm/sheepdog/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.43 +version: 0.1.44 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/sheepdog/README.md b/helm/sheepdog/README.md index 4fffd537c..e7db9f3a1 100644 --- a/helm/sheepdog/README.md +++ b/helm/sheepdog/README.md @@ -1,6 +1,6 @@ # sheepdog -![Version: 0.1.43](https://img.shields.io/badge/Version-0.1.43-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.44](https://img.shields.io/badge/Version-0.1.44-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Sheepdog Service diff --git a/helm/sheepdog/sheepdog-secret/settings.py b/helm/sheepdog/sheepdog-secret/settings.py index ac896e523..f2e9b0f64 100644 --- a/helm/sheepdog/sheepdog-secret/settings.py +++ b/helm/sheepdog/sheepdog-secret/settings.py @@ -74,6 +74,7 @@ } config['USER_API'] = environ.get('FENCE_URL') or 'http://fence-service/' +config["AUTHZ_AUDIENCE"] = "gen3" # for use by authutils # use the USER_API URL instead of the public issuer URL to accquire JWT keys config['FORCE_ISSUER'] = True app_init(app) From 613b3836994f3742006f65edf01814f964e3e29b Mon Sep 17 00:00:00 2001 From: Ajo Augustine Date: Fri, 10 Jul 2026 13:15:27 -0500 Subject: [PATCH 120/196] bump chart versions --- helm/access-backend/Chart.yaml | 4 +- helm/access-backend/README.md | 4 +- helm/ambassador/Chart.yaml | 4 +- helm/ambassador/README.md | 4 +- helm/arborist/Chart.yaml | 4 +- helm/arborist/README.md | 4 +- helm/argo-wrapper/Chart.yaml | 4 +- helm/argo-wrapper/README.md | 4 +- helm/audit/Chart.yaml | 4 +- helm/audit/README.md | 4 +- helm/aws-es-proxy/Chart.yaml | 4 +- helm/aws-es-proxy/README.md | 4 +- helm/aws-sigv4-proxy/Chart.yaml | 4 +- helm/aws-sigv4-proxy/README.md | 4 +- helm/cedar/Chart.yaml | 4 +- helm/cedar/README.md | 4 +- helm/cohort-middleware/Chart.yaml | 4 +- helm/cohort-middleware/README.md | 4 +- helm/dashboard/Chart.yaml | 4 +- helm/dashboard/README.md | 4 +- helm/data-upload-cron/Chart.yaml | 4 +- helm/data-upload-cron/README.md | 4 +- helm/datareplicate/Chart.yaml | 4 +- helm/datareplicate/README.md | 4 +- helm/dicom-server/Chart.yaml | 4 +- helm/dicom-server/README.md | 4 +- helm/embedding-management-service/Chart.yaml | 4 +- helm/embedding-management-service/README.md | 4 +- helm/frontend-framework/Chart.yaml | 4 +- helm/frontend-framework/README.md | 4 +- helm/funnel/Chart.yaml | 4 +- helm/funnel/README.md | 4 +- helm/gen3-analysis/Chart.yaml | 4 +- helm/gen3-analysis/README.md | 4 +- helm/gen3-user-data-library/Chart.yaml | 4 +- helm/gen3-user-data-library/README.md | 4 +- helm/gen3-workflow/Chart.yaml | 4 +- helm/gen3-workflow/README.md | 4 +- helm/gen3/Chart.yaml | 72 ++++++++++---------- helm/gen3/README.md | 72 ++++++++++---------- helm/guppy/Chart.yaml | 4 +- helm/guppy/README.md | 4 +- helm/hatchery/Chart.yaml | 2 +- helm/hatchery/README.md | 2 +- helm/indexd/Chart.yaml | 4 +- helm/indexd/README.md | 4 +- helm/jeg/Chart.yaml | 4 +- helm/jeg/README.md | 4 +- helm/metadata/Chart.yaml | 4 +- helm/metadata/README.md | 4 +- helm/ohdsi-webapi/Chart.yaml | 4 +- helm/ohdsi-webapi/README.md | 4 +- helm/ohif-viewer/Chart.yaml | 4 +- helm/ohif-viewer/README.md | 4 +- helm/orthanc/Chart.yaml | 4 +- helm/orthanc/README.md | 4 +- helm/peregrine/Chart.yaml | 4 +- helm/peregrine/README.md | 4 +- helm/portal/Chart.yaml | 4 +- helm/portal/README.md | 4 +- helm/requestor/Chart.yaml | 4 +- helm/requestor/README.md | 4 +- helm/revproxy/Chart.yaml | 4 +- helm/revproxy/README.md | 4 +- helm/sheepdog/Chart.yaml | 4 +- helm/sheepdog/README.md | 4 +- helm/sower/Chart.yaml | 4 +- helm/sower/README.md | 4 +- helm/ssjdispatcher/Chart.yaml | 4 +- helm/ssjdispatcher/README.md | 4 +- helm/vectis-overlays/Chart.yaml | 4 +- helm/vectis-overlays/README.md | 4 +- helm/workspace-proxy/Chart.yaml | 4 +- helm/workspace-proxy/README.md | 4 +- helm/wts/Chart.yaml | 4 +- helm/wts/README.md | 4 +- 76 files changed, 218 insertions(+), 218 deletions(-) diff --git a/helm/access-backend/Chart.yaml b/helm/access-backend/Chart.yaml index a40ac450b..ed6b5ee8d 100644 --- a/helm/access-backend/Chart.yaml +++ b/helm/access-backend/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.21 +version: 0.1.22 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "1.6.1" dependencies: - name: common - version: 0.1.37 + version: 0.1.38 repository: file://../common diff --git a/helm/access-backend/README.md b/helm/access-backend/README.md index ebcd90508..803ef603e 100644 --- a/helm/access-backend/README.md +++ b/helm/access-backend/README.md @@ -1,6 +1,6 @@ # access-backend -![Version: 0.1.21](https://img.shields.io/badge/Version-0.1.21-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.6.1](https://img.shields.io/badge/AppVersion-1.6.1-informational?style=flat-square) +![Version: 0.1.22](https://img.shields.io/badge/Version-0.1.22-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.6.1](https://img.shields.io/badge/AppVersion-1.6.1-informational?style=flat-square) A Helm chart for Kubernetes @@ -8,7 +8,7 @@ A Helm chart for Kubernetes | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.37 | +| file://../common | common | 0.1.38 | ## Values diff --git a/helm/ambassador/Chart.yaml b/helm/ambassador/Chart.yaml index 993c132f5..f00cf59ae 100644 --- a/helm/ambassador/Chart.yaml +++ b/helm/ambassador/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.38 +version: 0.1.39 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "1.4.2" dependencies: - name: common - version: 0.1.37 + version: 0.1.38 repository: file://../common diff --git a/helm/ambassador/README.md b/helm/ambassador/README.md index d579f27fd..370aa3b2e 100644 --- a/helm/ambassador/README.md +++ b/helm/ambassador/README.md @@ -1,6 +1,6 @@ # ambassador -![Version: 0.1.38](https://img.shields.io/badge/Version-0.1.38-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.4.2](https://img.shields.io/badge/AppVersion-1.4.2-informational?style=flat-square) +![Version: 0.1.39](https://img.shields.io/badge/Version-0.1.39-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.4.2](https://img.shields.io/badge/AppVersion-1.4.2-informational?style=flat-square) A Helm chart for deploying ambassador for gen3 @@ -8,7 +8,7 @@ A Helm chart for deploying ambassador for gen3 | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.37 | +| file://../common | common | 0.1.38 | ## Values diff --git a/helm/arborist/Chart.yaml b/helm/arborist/Chart.yaml index 00ce7e41a..c7e2935d8 100644 --- a/helm/arborist/Chart.yaml +++ b/helm/arborist/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.35 +version: 0.1.36 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,7 +25,7 @@ appVersion: "master" dependencies: - name: common - version: 0.1.37 + version: 0.1.38 repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/arborist/README.md b/helm/arborist/README.md index 58b0fd02c..889dfb6fe 100644 --- a/helm/arborist/README.md +++ b/helm/arborist/README.md @@ -1,6 +1,6 @@ # arborist -![Version: 0.1.35](https://img.shields.io/badge/Version-0.1.35-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.36](https://img.shields.io/badge/Version-0.1.36-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 arborist @@ -8,7 +8,7 @@ A Helm chart for gen3 arborist | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.37 | +| file://../common | common | 0.1.38 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | ## Values diff --git a/helm/argo-wrapper/Chart.yaml b/helm/argo-wrapper/Chart.yaml index 2f861a795..45fc36aef 100644 --- a/helm/argo-wrapper/Chart.yaml +++ b/helm/argo-wrapper/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.31 +version: 0.1.32 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.37 + version: 0.1.38 repository: file://../common diff --git a/helm/argo-wrapper/README.md b/helm/argo-wrapper/README.md index 25fe50276..8012e78eb 100644 --- a/helm/argo-wrapper/README.md +++ b/helm/argo-wrapper/README.md @@ -1,6 +1,6 @@ # argo-wrapper -![Version: 0.1.31](https://img.shields.io/badge/Version-0.1.31-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.32](https://img.shields.io/badge/Version-0.1.32-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Argo Wrapper Service @@ -8,7 +8,7 @@ A Helm chart for gen3 Argo Wrapper Service | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.37 | +| file://../common | common | 0.1.38 | ## Values diff --git a/helm/audit/Chart.yaml b/helm/audit/Chart.yaml index f077a029a..8012a157d 100644 --- a/helm/audit/Chart.yaml +++ b/helm/audit/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.44 +version: 0.1.45 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -24,7 +24,7 @@ appVersion: "master" dependencies: - name: common - version: 0.1.37 + version: 0.1.38 repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/audit/README.md b/helm/audit/README.md index cdff0298a..99780afdf 100644 --- a/helm/audit/README.md +++ b/helm/audit/README.md @@ -1,6 +1,6 @@ # audit -![Version: 0.1.44](https://img.shields.io/badge/Version-0.1.44-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.45](https://img.shields.io/badge/Version-0.1.45-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for Kubernetes @@ -8,7 +8,7 @@ A Helm chart for Kubernetes | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.37 | +| file://../common | common | 0.1.38 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | ## Values diff --git a/helm/aws-es-proxy/Chart.yaml b/helm/aws-es-proxy/Chart.yaml index 74160ff62..a74b9e9d0 100644 --- a/helm/aws-es-proxy/Chart.yaml +++ b/helm/aws-es-proxy/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.42 +version: 0.1.43 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.37 + version: 0.1.38 repository: file://../common diff --git a/helm/aws-es-proxy/README.md b/helm/aws-es-proxy/README.md index a679928d5..7e9eb06fe 100644 --- a/helm/aws-es-proxy/README.md +++ b/helm/aws-es-proxy/README.md @@ -1,6 +1,6 @@ # aws-es-proxy -![Version: 0.1.42](https://img.shields.io/badge/Version-0.1.42-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.43](https://img.shields.io/badge/Version-0.1.43-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for AWS ES Proxy Service for gen3 @@ -8,7 +8,7 @@ A Helm chart for AWS ES Proxy Service for gen3 | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.37 | +| file://../common | common | 0.1.38 | ## Values diff --git a/helm/aws-sigv4-proxy/Chart.yaml b/helm/aws-sigv4-proxy/Chart.yaml index ff86a6524..6b2fb249f 100644 --- a/helm/aws-sigv4-proxy/Chart.yaml +++ b/helm/aws-sigv4-proxy/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.3 +version: 0.1.4 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.37 + version: 0.1.38 repository: file://../common diff --git a/helm/aws-sigv4-proxy/README.md b/helm/aws-sigv4-proxy/README.md index 03244d9af..cc7b9213d 100644 --- a/helm/aws-sigv4-proxy/README.md +++ b/helm/aws-sigv4-proxy/README.md @@ -1,6 +1,6 @@ # aws-sigv4-proxy -![Version: 0.1.3](https://img.shields.io/badge/Version-0.1.3-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.4](https://img.shields.io/badge/Version-0.1.4-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for AWS ES Proxy Service for gen3 @@ -8,7 +8,7 @@ A Helm chart for AWS ES Proxy Service for gen3 | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.37 | +| file://../common | common | 0.1.38 | ## Values diff --git a/helm/cedar/Chart.yaml b/helm/cedar/Chart.yaml index 0c3ef57a1..e6ef00600 100644 --- a/helm/cedar/Chart.yaml +++ b/helm/cedar/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.27 +version: 0.1.28 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.37 + version: 0.1.38 repository: file://../common diff --git a/helm/cedar/README.md b/helm/cedar/README.md index 116283542..e16124399 100644 --- a/helm/cedar/README.md +++ b/helm/cedar/README.md @@ -1,6 +1,6 @@ # cedar -![Version: 0.1.27](https://img.shields.io/badge/Version-0.1.27-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.28](https://img.shields.io/badge/Version-0.1.28-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 cedar wrapper @@ -8,7 +8,7 @@ A Helm chart for gen3 cedar wrapper | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.37 | +| file://../common | common | 0.1.38 | ## Values diff --git a/helm/cohort-middleware/Chart.yaml b/helm/cohort-middleware/Chart.yaml index f2cf9ae37..173211886 100644 --- a/helm/cohort-middleware/Chart.yaml +++ b/helm/cohort-middleware/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.23 +version: 0.1.24 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.37 + version: 0.1.38 repository: file://../common diff --git a/helm/cohort-middleware/README.md b/helm/cohort-middleware/README.md index fa9a946c8..6e6286b5d 100644 --- a/helm/cohort-middleware/README.md +++ b/helm/cohort-middleware/README.md @@ -1,6 +1,6 @@ # cohort-middleware -![Version: 0.1.23](https://img.shields.io/badge/Version-0.1.23-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.24](https://img.shields.io/badge/Version-0.1.24-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 cohort-middleware @@ -8,7 +8,7 @@ A Helm chart for gen3 cohort-middleware | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.37 | +| file://../common | common | 0.1.38 | ## Values diff --git a/helm/dashboard/Chart.yaml b/helm/dashboard/Chart.yaml index 018e9639d..3273f5320 100644 --- a/helm/dashboard/Chart.yaml +++ b/helm/dashboard/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.22 +version: 0.1.23 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "1.16.0" dependencies: - name: common - version: 0.1.37 + version: 0.1.38 repository: file://../common diff --git a/helm/dashboard/README.md b/helm/dashboard/README.md index be89fa6b8..d6019d2e0 100644 --- a/helm/dashboard/README.md +++ b/helm/dashboard/README.md @@ -1,6 +1,6 @@ # dashboard -![Version: 0.1.22](https://img.shields.io/badge/Version-0.1.22-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.16.0](https://img.shields.io/badge/AppVersion-1.16.0-informational?style=flat-square) +![Version: 0.1.23](https://img.shields.io/badge/Version-0.1.23-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.16.0](https://img.shields.io/badge/AppVersion-1.16.0-informational?style=flat-square) A Helm chart for Kubernetes @@ -8,7 +8,7 @@ A Helm chart for Kubernetes | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.37 | +| file://../common | common | 0.1.38 | ## Values diff --git a/helm/data-upload-cron/Chart.yaml b/helm/data-upload-cron/Chart.yaml index b68c57e83..34423931b 100644 --- a/helm/data-upload-cron/Chart.yaml +++ b/helm/data-upload-cron/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.7 +version: 0.1.8 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.37 + version: 0.1.38 repository: file://../common diff --git a/helm/data-upload-cron/README.md b/helm/data-upload-cron/README.md index 8cf2012ee..45a39bc5d 100644 --- a/helm/data-upload-cron/README.md +++ b/helm/data-upload-cron/README.md @@ -1,6 +1,6 @@ # data-upload-cron -![Version: 0.1.7](https://img.shields.io/badge/Version-0.1.7-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.8](https://img.shields.io/badge/Version-0.1.8-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for the data upload cronjob @@ -8,7 +8,7 @@ A Helm chart for the data upload cronjob | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.37 | +| file://../common | common | 0.1.38 | ## Values diff --git a/helm/datareplicate/Chart.yaml b/helm/datareplicate/Chart.yaml index 68a31340f..93c1d56eb 100644 --- a/helm/datareplicate/Chart.yaml +++ b/helm/datareplicate/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.22 +version: 0.1.23 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.37 + version: 0.1.38 repository: file://../common diff --git a/helm/datareplicate/README.md b/helm/datareplicate/README.md index 1b94e22b2..a97ce6eb8 100644 --- a/helm/datareplicate/README.md +++ b/helm/datareplicate/README.md @@ -1,6 +1,6 @@ # datareplicate -![Version: 0.1.22](https://img.shields.io/badge/Version-0.1.22-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.23](https://img.shields.io/badge/Version-0.1.23-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 datareplicate @@ -8,7 +8,7 @@ A Helm chart for gen3 datareplicate | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.37 | +| file://../common | common | 0.1.38 | ## Values diff --git a/helm/dicom-server/Chart.yaml b/helm/dicom-server/Chart.yaml index e0ca4536e..148be68e9 100644 --- a/helm/dicom-server/Chart.yaml +++ b/helm/dicom-server/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.32 +version: 0.1.33 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.37 + version: 0.1.38 repository: file://../common diff --git a/helm/dicom-server/README.md b/helm/dicom-server/README.md index 497b87d69..97b8ea659 100644 --- a/helm/dicom-server/README.md +++ b/helm/dicom-server/README.md @@ -1,6 +1,6 @@ # dicom-server -![Version: 0.1.32](https://img.shields.io/badge/Version-0.1.32-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.33](https://img.shields.io/badge/Version-0.1.33-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Dicom Server @@ -8,7 +8,7 @@ A Helm chart for gen3 Dicom Server | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.37 | +| file://../common | common | 0.1.38 | ## Values diff --git a/helm/embedding-management-service/Chart.yaml b/helm/embedding-management-service/Chart.yaml index fd6fbad76..811efc0b5 100644 --- a/helm/embedding-management-service/Chart.yaml +++ b/helm/embedding-management-service/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.8 +version: 0.1.9 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "1.16.0" dependencies: - name: common - version: 0.1.37 + version: 0.1.38 repository: file://../common diff --git a/helm/embedding-management-service/README.md b/helm/embedding-management-service/README.md index 48e516afe..35c52913d 100644 --- a/helm/embedding-management-service/README.md +++ b/helm/embedding-management-service/README.md @@ -1,6 +1,6 @@ # embedding-management-service -![Version: 0.1.8](https://img.shields.io/badge/Version-0.1.8-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.16.0](https://img.shields.io/badge/AppVersion-1.16.0-informational?style=flat-square) +![Version: 0.1.9](https://img.shields.io/badge/Version-0.1.9-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.16.0](https://img.shields.io/badge/AppVersion-1.16.0-informational?style=flat-square) A Helm chart for Kubernetes @@ -8,7 +8,7 @@ A Helm chart for Kubernetes | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.37 | +| file://../common | common | 0.1.38 | ## Values diff --git a/helm/frontend-framework/Chart.yaml b/helm/frontend-framework/Chart.yaml index 0121e0758..cb6c0f6eb 100644 --- a/helm/frontend-framework/Chart.yaml +++ b/helm/frontend-framework/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.30 +version: 0.1.31 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "develop" dependencies: - name: common - version: 0.1.37 + version: 0.1.38 repository: file://../common diff --git a/helm/frontend-framework/README.md b/helm/frontend-framework/README.md index ed4e5676d..eaaef8f41 100644 --- a/helm/frontend-framework/README.md +++ b/helm/frontend-framework/README.md @@ -1,6 +1,6 @@ # frontend-framework -![Version: 0.1.30](https://img.shields.io/badge/Version-0.1.30-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: develop](https://img.shields.io/badge/AppVersion-develop-informational?style=flat-square) +![Version: 0.1.31](https://img.shields.io/badge/Version-0.1.31-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: develop](https://img.shields.io/badge/AppVersion-develop-informational?style=flat-square) A Helm chart for the gen3 frontend framework @@ -8,7 +8,7 @@ A Helm chart for the gen3 frontend framework | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.37 | +| file://../common | common | 0.1.38 | ## Values diff --git a/helm/funnel/Chart.yaml b/helm/funnel/Chart.yaml index 582c87bfe..030a4d7d1 100644 --- a/helm/funnel/Chart.yaml +++ b/helm/funnel/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.27 +version: 0.1.28 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -24,7 +24,7 @@ appVersion: "master" dependencies: - name: common - version: 0.1.37 + version: 0.1.38 repository: file://../common - name: funnel # NOTE: diff --git a/helm/funnel/README.md b/helm/funnel/README.md index 09dccc499..db1dc4e72 100644 --- a/helm/funnel/README.md +++ b/helm/funnel/README.md @@ -1,6 +1,6 @@ # funnel -![Version: 0.1.27](https://img.shields.io/badge/Version-0.1.27-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.28](https://img.shields.io/badge/Version-0.1.28-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for Kubernetes @@ -8,7 +8,7 @@ A Helm chart for Kubernetes | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.37 | +| file://../common | common | 0.1.38 | | https://calypr.github.io/helm-charts | funnel | 0.1.99-rc.36 | ## Values diff --git a/helm/gen3-analysis/Chart.yaml b/helm/gen3-analysis/Chart.yaml index 0a1e0da2f..f4f850ca6 100644 --- a/helm/gen3-analysis/Chart.yaml +++ b/helm/gen3-analysis/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.13 +version: 0.1.14 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.37 + version: 0.1.38 repository: file://../common diff --git a/helm/gen3-analysis/README.md b/helm/gen3-analysis/README.md index f2d73dd2f..2c3fdbf11 100644 --- a/helm/gen3-analysis/README.md +++ b/helm/gen3-analysis/README.md @@ -1,6 +1,6 @@ # gen3-analysis -![Version: 0.1.13](https://img.shields.io/badge/Version-0.1.13-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.14](https://img.shields.io/badge/Version-0.1.14-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 gen3-analysis Service @@ -8,7 +8,7 @@ A Helm chart for gen3 gen3-analysis Service | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.37 | +| file://../common | common | 0.1.38 | ## Values diff --git a/helm/gen3-user-data-library/Chart.yaml b/helm/gen3-user-data-library/Chart.yaml index db5366682..7694a491c 100644 --- a/helm/gen3-user-data-library/Chart.yaml +++ b/helm/gen3-user-data-library/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.16 +version: 0.1.17 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -24,7 +24,7 @@ version: 0.1.16 appVersion: "main" dependencies: - name: common - version: 0.1.37 + version: 0.1.38 repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/gen3-user-data-library/README.md b/helm/gen3-user-data-library/README.md index e6b76cb8b..31820a4b8 100644 --- a/helm/gen3-user-data-library/README.md +++ b/helm/gen3-user-data-library/README.md @@ -1,6 +1,6 @@ # gen3-user-data-library -![Version: 0.1.16](https://img.shields.io/badge/Version-0.1.16-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: main](https://img.shields.io/badge/AppVersion-main-informational?style=flat-square) +![Version: 0.1.17](https://img.shields.io/badge/Version-0.1.17-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: main](https://img.shields.io/badge/AppVersion-main-informational?style=flat-square) A Helm chart for Kubernetes @@ -8,7 +8,7 @@ A Helm chart for Kubernetes | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.37 | +| file://../common | common | 0.1.38 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | ## Values diff --git a/helm/gen3-workflow/Chart.yaml b/helm/gen3-workflow/Chart.yaml index acca9917f..071088100 100644 --- a/helm/gen3-workflow/Chart.yaml +++ b/helm/gen3-workflow/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.23 +version: 0.1.24 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -24,5 +24,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.37 + version: 0.1.38 repository: file://../common diff --git a/helm/gen3-workflow/README.md b/helm/gen3-workflow/README.md index 4391e6893..0e624fbb3 100644 --- a/helm/gen3-workflow/README.md +++ b/helm/gen3-workflow/README.md @@ -1,6 +1,6 @@ # gen3-workflow -![Version: 0.1.23](https://img.shields.io/badge/Version-0.1.23-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.24](https://img.shields.io/badge/Version-0.1.24-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for Kubernetes @@ -8,7 +8,7 @@ A Helm chart for Kubernetes | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.37 | +| file://../common | common | 0.1.38 | ## Values diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index 26148a95f..3a903c8cc 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -5,58 +5,58 @@ description: Helm chart to deploy Gen3 Data Commons # Dependencies dependencies: - name: access-backend - version: 0.1.21 + version: 0.1.22 repository: "file://../access-backend" condition: access-backend.enabled - name: ambassador - version: 0.1.38 + version: 0.1.39 repository: "file://../ambassador" condition: ambassador.enabled - name: arborist - version: 0.1.35 + version: 0.1.36 repository: "file://../arborist" condition: arborist.enabled - name: argo-wrapper - version: 0.1.31 + version: 0.1.32 repository: "file://../argo-wrapper" condition: argo-wrapper.enabled - name: audit - version: 0.1.44 + version: 0.1.45 repository: "file://../audit" condition: audit.enabled - name: aws-es-proxy - version: 0.1.42 + version: 0.1.43 repository: "file://../aws-es-proxy" condition: aws-es-proxy.enabled - name: aws-sigv4-proxy - version: 0.1.3 + version: 0.1.4 repository: "file://../aws-sigv4-proxy" condition: aws-sigv4-proxy.enabled - name: cedar - version: 0.1.27 + version: 0.1.28 repository: "file://../cedar" condition: cedar.enabled - name: cohort-middleware - version: 0.1.23 + version: 0.1.24 repository: "file://../cohort-middleware" condition: cohort-middleware.enabled - name: common version: 0.1.38 repository: file://../common - name: dashboard - version: 0.1.22 + version: 0.1.23 repository: file://../dashboard condition: dashboard.enabled - name: datareplicate - version: 0.1.22 + version: 0.1.23 repository: "file://../datareplicate" condition: datareplicate.enabled - name: data-upload-cron - version: 0.1.7 + version: 0.1.8 repository: "file://../data-upload-cron" condition: data-upload-cron.enabled - name: embedding-management-service - version: 0.1.8 + version: 0.1.9 repository: file://../embedding-management-service condition: embedding-management-service.enabled - name: etl @@ -64,7 +64,7 @@ dependencies: repository: file://../etl condition: etl.enabled - name: frontend-framework - version: 0.1.30 + version: 0.1.31 repository: "file://../frontend-framework" condition: frontend-framework.enabled - name: fence @@ -72,19 +72,19 @@ dependencies: repository: "file://../fence" condition: fence.enabled - name: funnel - version: 0.1.27 + version: 0.1.28 repository: "file://../funnel" condition: gen3-workflow.enabled - name: gen3-user-data-library - version: 0.1.16 + version: 0.1.17 repository: "file://../gen3-user-data-library" condition: gen3-user-data-library.enabled - name: gen3-workflow - version: 0.1.23 + version: 0.1.24 repository: "file://../gen3-workflow" condition: gen3-workflow.enabled - name: guppy - version: 0.1.38 + version: 0.1.39 repository: "file://../guppy" condition: guppy.enabled - name: hatchery @@ -92,7 +92,7 @@ dependencies: repository: "file://../hatchery" condition: hatchery.enabled - name: indexd - version: 0.1.48 + version: 0.1.49 repository: "file://../indexd" condition: indexd.enabled - name: manifestservice @@ -100,39 +100,39 @@ dependencies: repository: "file://../manifestservice" condition: manifestservice.enabled - name: metadata - version: 0.1.45 + version: 0.1.46 repository: "file://../metadata" condition: metadata.enabled - name: peregrine - version: 0.1.43 + version: 0.1.44 repository: "file://../peregrine" condition: peregrine.enabled - name: portal - version: 0.1.61 + version: 0.1.62 repository: "file://../portal" condition: portal.enabled - name: requestor - version: 0.1.35 + version: 0.1.36 repository: "file://../requestor" condition: requestor.enabled - name: revproxy - version: 0.1.63 + version: 0.1.64 repository: "file://../revproxy" condition: revproxy.enabled - name: sheepdog - version: 0.1.43 + version: 0.1.44 repository: "file://../sheepdog" condition: sheepdog.enabled - name: ssjdispatcher - version: 0.1.48 + version: 0.1.49 repository: "file://../ssjdispatcher" condition: ssjdispatcher.enabled - name: sower - version: 0.1.47 + version: 0.1.48 condition: sower.enabled repository: "file://../sower" - name: wts - version: 0.1.41 + version: 0.1.42 repository: "file://../wts" condition: wts.enabled - name: gen3-network-policies @@ -140,19 +140,19 @@ dependencies: repository: "file://../gen3-network-policies" condition: global.netPolicy.enabled - name: dicom-server - version: 0.1.32 + version: 0.1.33 repository: file://../dicom-server condition: dicom-server.enabled - name: ohif-viewer - version: 0.1.15 + version: 0.1.16 repository: file://../ohif-viewer condition: ohif-viewer.enabled - name: orthanc - version: 0.1.16 + version: 0.1.17 repository: file://../orthanc condition: orthanc.enabled - name: gen3-analysis - version: 0.1.13 + version: 0.1.14 repository: file://../gen3-analysis condition: gen3-analysis.enabled - name: ohdsi-atlas @@ -160,7 +160,7 @@ dependencies: repository: file://../ohdsi-atlas condition: ohdsi-atlas.enabled - name: ohdsi-webapi - version: 0.1.6 + version: 0.1.7 repository: file://../ohdsi-webapi condition: ohdsi-webapi.enabled @@ -183,15 +183,15 @@ dependencies: repository: "file://../neuvector" condition: neuvector.enabled - name: jeg - version: 0.1.2 + version: 0.1.3 repository: "file://../jeg" condition: jeg.enabled - name: workspace-proxy - version: 0.1.2 + version: 0.1.3 repository: "file://../workspace-proxy" condition: workspace-proxy.enabled - name: vectis-overlays - version: 0.1.2 + version: 0.1.3 repository: "file://../vectis-overlays" condition: vectis-overlays.enabled diff --git a/helm/gen3/README.md b/helm/gen3/README.md index e3715a700..8194c3265 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -18,50 +18,50 @@ Helm chart to deploy Gen3 Data Commons | Repository | Name | Version | |------------|------|---------| -| file://../access-backend | access-backend | 0.1.21 | -| file://../ambassador | ambassador | 0.1.38 | -| file://../arborist | arborist | 0.1.35 | -| file://../argo-wrapper | argo-wrapper | 0.1.31 | -| file://../audit | audit | 0.1.44 | -| file://../aws-es-proxy | aws-es-proxy | 0.1.42 | -| file://../aws-sigv4-proxy | aws-sigv4-proxy | 0.1.3 | -| file://../cedar | cedar | 0.1.27 | -| file://../cohort-middleware | cohort-middleware | 0.1.23 | +| file://../access-backend | access-backend | 0.1.22 | +| file://../ambassador | ambassador | 0.1.39 | +| file://../arborist | arborist | 0.1.36 | +| file://../argo-wrapper | argo-wrapper | 0.1.32 | +| file://../audit | audit | 0.1.45 | +| file://../aws-es-proxy | aws-es-proxy | 0.1.43 | +| file://../aws-sigv4-proxy | aws-sigv4-proxy | 0.1.4 | +| file://../cedar | cedar | 0.1.28 | +| file://../cohort-middleware | cohort-middleware | 0.1.24 | | file://../common | common | 0.1.38 | -| file://../dashboard | dashboard | 0.1.22 | -| file://../data-upload-cron | data-upload-cron | 0.1.7 | -| file://../datareplicate | datareplicate | 0.1.22 | -| file://../dicom-server | dicom-server | 0.1.32 | -| file://../embedding-management-service | embedding-management-service | 0.1.8 | +| file://../dashboard | dashboard | 0.1.23 | +| file://../data-upload-cron | data-upload-cron | 0.1.8 | +| file://../datareplicate | datareplicate | 0.1.23 | +| file://../dicom-server | dicom-server | 0.1.33 | +| file://../embedding-management-service | embedding-management-service | 0.1.9 | | file://../etl | etl | 0.1.23 | | file://../fence | fence | 0.1.80 | -| file://../frontend-framework | frontend-framework | 0.1.30 | -| file://../funnel | funnel | 0.1.27 | -| file://../gen3-analysis | gen3-analysis | 0.1.13 | +| file://../frontend-framework | frontend-framework | 0.1.31 | +| file://../funnel | funnel | 0.1.28 | +| file://../gen3-analysis | gen3-analysis | 0.1.14 | | file://../gen3-network-policies | gen3-network-policies | 0.1.4 | -| file://../gen3-user-data-library | gen3-user-data-library | 0.1.16 | -| file://../gen3-workflow | gen3-workflow | 0.1.23 | -| file://../guppy | guppy | 0.1.38 | +| file://../gen3-user-data-library | gen3-user-data-library | 0.1.17 | +| file://../gen3-workflow | gen3-workflow | 0.1.24 | +| file://../guppy | guppy | 0.1.39 | | file://../hatchery | hatchery | 0.1.71 | -| file://../indexd | indexd | 0.1.48 | -| file://../jeg | jeg | 0.1.2 | +| file://../indexd | indexd | 0.1.49 | +| file://../jeg | jeg | 0.1.3 | | file://../manifestservice | manifestservice | 0.1.44 | -| file://../metadata | metadata | 0.1.45 | +| file://../metadata | metadata | 0.1.46 | | file://../neuvector | neuvector | 0.1.2 | | file://../ohdsi-atlas | ohdsi-atlas | 0.1.2 | -| file://../ohdsi-webapi | ohdsi-webapi | 0.1.6 | -| file://../ohif-viewer | ohif-viewer | 0.1.15 | -| file://../orthanc | orthanc | 0.1.16 | -| file://../peregrine | peregrine | 0.1.43 | -| file://../portal | portal | 0.1.61 | -| file://../requestor | requestor | 0.1.35 | -| file://../revproxy | revproxy | 0.1.63 | -| file://../sheepdog | sheepdog | 0.1.43 | -| file://../sower | sower | 0.1.47 | -| file://../ssjdispatcher | ssjdispatcher | 0.1.48 | -| file://../vectis-overlays | vectis-overlays | 0.1.2 | -| file://../workspace-proxy | workspace-proxy | 0.1.2 | -| file://../wts | wts | 0.1.41 | +| file://../ohdsi-webapi | ohdsi-webapi | 0.1.7 | +| file://../ohif-viewer | ohif-viewer | 0.1.16 | +| file://../orthanc | orthanc | 0.1.17 | +| file://../peregrine | peregrine | 0.1.44 | +| file://../portal | portal | 0.1.62 | +| file://../requestor | requestor | 0.1.36 | +| file://../revproxy | revproxy | 0.1.64 | +| file://../sheepdog | sheepdog | 0.1.44 | +| file://../sower | sower | 0.1.48 | +| file://../ssjdispatcher | ssjdispatcher | 0.1.49 | +| file://../vectis-overlays | vectis-overlays | 0.1.3 | +| file://../workspace-proxy | workspace-proxy | 0.1.3 | +| file://../wts | wts | 0.1.42 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | | https://helm.elastic.co | elasticsearch | 7.10.2 | diff --git a/helm/guppy/Chart.yaml b/helm/guppy/Chart.yaml index 4bb0d83e7..611ee6452 100644 --- a/helm/guppy/Chart.yaml +++ b/helm/guppy/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.38 +version: 0.1.39 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.37 + version: 0.1.38 repository: file://../common diff --git a/helm/guppy/README.md b/helm/guppy/README.md index 8387fa9ea..38a7b8c35 100644 --- a/helm/guppy/README.md +++ b/helm/guppy/README.md @@ -1,6 +1,6 @@ # guppy -![Version: 0.1.38](https://img.shields.io/badge/Version-0.1.38-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.39](https://img.shields.io/badge/Version-0.1.39-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Guppy Service @@ -8,7 +8,7 @@ A Helm chart for gen3 Guppy Service | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.37 | +| file://../common | common | 0.1.38 | ## Values diff --git a/helm/hatchery/Chart.yaml b/helm/hatchery/Chart.yaml index 1a0c2af6a..364ebfdf6 100644 --- a/helm/hatchery/Chart.yaml +++ b/helm/hatchery/Chart.yaml @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.37 + version: 0.1.38 repository: file://../common diff --git a/helm/hatchery/README.md b/helm/hatchery/README.md index 117ac8ca7..a271caa5d 100644 --- a/helm/hatchery/README.md +++ b/helm/hatchery/README.md @@ -8,7 +8,7 @@ A Helm chart for gen3 Hatchery | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.37 | +| file://../common | common | 0.1.38 | ## Values diff --git a/helm/indexd/Chart.yaml b/helm/indexd/Chart.yaml index 495087adf..a4cc5a487 100644 --- a/helm/indexd/Chart.yaml +++ b/helm/indexd/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.48 +version: 0.1.49 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,7 +25,7 @@ appVersion: "master" dependencies: - name: common - version: 0.1.37 + version: 0.1.38 repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/indexd/README.md b/helm/indexd/README.md index f2864d67f..4525e81a5 100644 --- a/helm/indexd/README.md +++ b/helm/indexd/README.md @@ -1,6 +1,6 @@ # indexd -![Version: 0.1.48](https://img.shields.io/badge/Version-0.1.48-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.49](https://img.shields.io/badge/Version-0.1.49-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 indexd @@ -8,7 +8,7 @@ A Helm chart for gen3 indexd | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.37 | +| file://../common | common | 0.1.38 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | ## Values diff --git a/helm/jeg/Chart.yaml b/helm/jeg/Chart.yaml index 8567c3d50..1a6c63308 100644 --- a/helm/jeg/Chart.yaml +++ b/helm/jeg/Chart.yaml @@ -5,10 +5,10 @@ description: > Launches ephemeral kernel pods in the workspace namespace on behalf of user Jupyter sessions proxied through workspace-proxy. type: application -version: 0.1.2 +version: 0.1.3 appVersion: "3.2.3" dependencies: - name: common - version: 0.1.37 + version: 0.1.38 repository: file://../common diff --git a/helm/jeg/README.md b/helm/jeg/README.md index b092d8e47..3491f1b29 100644 --- a/helm/jeg/README.md +++ b/helm/jeg/README.md @@ -1,6 +1,6 @@ # jeg -![Version: 0.1.2](https://img.shields.io/badge/Version-0.1.2-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 3.2.3](https://img.shields.io/badge/AppVersion-3.2.3-informational?style=flat-square) +![Version: 0.1.3](https://img.shields.io/badge/Version-0.1.3-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 3.2.3](https://img.shields.io/badge/AppVersion-3.2.3-informational?style=flat-square) Jupyter Enterprise Gateway for gen3 vectis workspaces. Launches ephemeral kernel pods in the workspace namespace on behalf of user Jupyter sessions proxied through workspace-proxy. @@ -8,7 +8,7 @@ Jupyter Enterprise Gateway for gen3 vectis workspaces. Launches ephemeral kernel | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.37 | +| file://../common | common | 0.1.38 | ## Values diff --git a/helm/metadata/Chart.yaml b/helm/metadata/Chart.yaml index 2804cb8aa..b9e069cdc 100644 --- a/helm/metadata/Chart.yaml +++ b/helm/metadata/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.45 +version: 0.1.46 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,7 +25,7 @@ appVersion: "master" dependencies: - name: common - version: 0.1.37 + version: 0.1.38 repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/metadata/README.md b/helm/metadata/README.md index 37c09a64d..11abf0322 100644 --- a/helm/metadata/README.md +++ b/helm/metadata/README.md @@ -1,6 +1,6 @@ # metadata -![Version: 0.1.45](https://img.shields.io/badge/Version-0.1.45-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.46](https://img.shields.io/badge/Version-0.1.46-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Metadata Service @@ -8,7 +8,7 @@ A Helm chart for gen3 Metadata Service | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.37 | +| file://../common | common | 0.1.38 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | | https://helm.elastic.co | elasticsearch | 7.17.1 | diff --git a/helm/ohdsi-webapi/Chart.yaml b/helm/ohdsi-webapi/Chart.yaml index 787b7cb53..afa082a61 100644 --- a/helm/ohdsi-webapi/Chart.yaml +++ b/helm/ohdsi-webapi/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.6 +version: 0.1.7 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,7 +25,7 @@ appVersion: "2.15.0" dependencies: - name: common - version: 0.1.37 + version: 0.1.38 repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/ohdsi-webapi/README.md b/helm/ohdsi-webapi/README.md index b8ced56db..fbaddc8ba 100644 --- a/helm/ohdsi-webapi/README.md +++ b/helm/ohdsi-webapi/README.md @@ -1,6 +1,6 @@ # ohdsi-webapi -![Version: 0.1.6](https://img.shields.io/badge/Version-0.1.6-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 2.15.0](https://img.shields.io/badge/AppVersion-2.15.0-informational?style=flat-square) +![Version: 0.1.7](https://img.shields.io/badge/Version-0.1.7-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 2.15.0](https://img.shields.io/badge/AppVersion-2.15.0-informational?style=flat-square) A Helm chart for OHDSI WebAPI @@ -8,7 +8,7 @@ A Helm chart for OHDSI WebAPI | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.37 | +| file://../common | common | 0.1.38 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | ## Values diff --git a/helm/ohif-viewer/Chart.yaml b/helm/ohif-viewer/Chart.yaml index e7e74d5c7..a89d13a7e 100644 --- a/helm/ohif-viewer/Chart.yaml +++ b/helm/ohif-viewer/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.15 +version: 0.1.16 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.37 + version: 0.1.38 repository: file://../common diff --git a/helm/ohif-viewer/README.md b/helm/ohif-viewer/README.md index f34240e62..7a396b6d7 100644 --- a/helm/ohif-viewer/README.md +++ b/helm/ohif-viewer/README.md @@ -1,6 +1,6 @@ # ohif-viewer -![Version: 0.1.15](https://img.shields.io/badge/Version-0.1.15-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.16](https://img.shields.io/badge/Version-0.1.16-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Ohif Viewer @@ -8,7 +8,7 @@ A Helm chart for gen3 Ohif Viewer | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.37 | +| file://../common | common | 0.1.38 | ## Values diff --git a/helm/orthanc/Chart.yaml b/helm/orthanc/Chart.yaml index 6eb037602..d93626c27 100644 --- a/helm/orthanc/Chart.yaml +++ b/helm/orthanc/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.16 +version: 0.1.17 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.37 + version: 0.1.38 repository: file://../common diff --git a/helm/orthanc/README.md b/helm/orthanc/README.md index 65606e438..fd3bda1cc 100644 --- a/helm/orthanc/README.md +++ b/helm/orthanc/README.md @@ -1,6 +1,6 @@ # orthanc -![Version: 0.1.16](https://img.shields.io/badge/Version-0.1.16-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.17](https://img.shields.io/badge/Version-0.1.17-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Dicom Server @@ -8,7 +8,7 @@ A Helm chart for gen3 Dicom Server | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.37 | +| file://../common | common | 0.1.38 | ## Values diff --git a/helm/peregrine/Chart.yaml b/helm/peregrine/Chart.yaml index 7bbd00870..2cede462c 100644 --- a/helm/peregrine/Chart.yaml +++ b/helm/peregrine/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.43 +version: 0.1.44 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,7 +25,7 @@ appVersion: "master" dependencies: - name: common - version: 0.1.37 + version: 0.1.38 repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/peregrine/README.md b/helm/peregrine/README.md index 3d28cd896..74a8d38e0 100644 --- a/helm/peregrine/README.md +++ b/helm/peregrine/README.md @@ -1,6 +1,6 @@ # peregrine -![Version: 0.1.43](https://img.shields.io/badge/Version-0.1.43-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.44](https://img.shields.io/badge/Version-0.1.44-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Peregrine service @@ -8,7 +8,7 @@ A Helm chart for gen3 Peregrine service | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.37 | +| file://../common | common | 0.1.38 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | ## Values diff --git a/helm/portal/Chart.yaml b/helm/portal/Chart.yaml index 64b141088..138282dc4 100644 --- a/helm/portal/Chart.yaml +++ b/helm/portal/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.61 +version: 0.1.62 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.37 + version: 0.1.38 repository: file://../common diff --git a/helm/portal/README.md b/helm/portal/README.md index a2bb09d96..cc9de621d 100644 --- a/helm/portal/README.md +++ b/helm/portal/README.md @@ -1,6 +1,6 @@ # portal -![Version: 0.1.61](https://img.shields.io/badge/Version-0.1.61-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.62](https://img.shields.io/badge/Version-0.1.62-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 data-portal @@ -8,7 +8,7 @@ A Helm chart for gen3 data-portal | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.37 | +| file://../common | common | 0.1.38 | ## Values diff --git a/helm/requestor/Chart.yaml b/helm/requestor/Chart.yaml index 5c4671a4c..30d94c866 100644 --- a/helm/requestor/Chart.yaml +++ b/helm/requestor/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.35 +version: 0.1.36 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,7 +25,7 @@ appVersion: "master" dependencies: - name: common - version: 0.1.37 + version: 0.1.38 repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/requestor/README.md b/helm/requestor/README.md index acc0f1a79..d747042db 100644 --- a/helm/requestor/README.md +++ b/helm/requestor/README.md @@ -1,6 +1,6 @@ # requestor -![Version: 0.1.35](https://img.shields.io/badge/Version-0.1.35-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.36](https://img.shields.io/badge/Version-0.1.36-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Requestor Service @@ -8,7 +8,7 @@ A Helm chart for gen3 Requestor Service | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.37 | +| file://../common | common | 0.1.38 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | ## Values diff --git a/helm/revproxy/Chart.yaml b/helm/revproxy/Chart.yaml index 25df4dcf0..83236df41 100644 --- a/helm/revproxy/Chart.yaml +++ b/helm/revproxy/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.63 +version: 0.1.64 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.37 + version: 0.1.38 repository: file://../common diff --git a/helm/revproxy/README.md b/helm/revproxy/README.md index fcec75978..0f6e4fbda 100644 --- a/helm/revproxy/README.md +++ b/helm/revproxy/README.md @@ -1,6 +1,6 @@ # revproxy -![Version: 0.1.63](https://img.shields.io/badge/Version-0.1.63-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.64](https://img.shields.io/badge/Version-0.1.64-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 revproxy @@ -8,7 +8,7 @@ A Helm chart for gen3 revproxy | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.37 | +| file://../common | common | 0.1.38 | ## Values diff --git a/helm/sheepdog/Chart.yaml b/helm/sheepdog/Chart.yaml index 8b05d4381..fe94062ce 100644 --- a/helm/sheepdog/Chart.yaml +++ b/helm/sheepdog/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.43 +version: 0.1.44 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,7 +25,7 @@ appVersion: "master" dependencies: - name: common - version: 0.1.37 + version: 0.1.38 repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/sheepdog/README.md b/helm/sheepdog/README.md index 4fffd537c..895cfd808 100644 --- a/helm/sheepdog/README.md +++ b/helm/sheepdog/README.md @@ -1,6 +1,6 @@ # sheepdog -![Version: 0.1.43](https://img.shields.io/badge/Version-0.1.43-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.44](https://img.shields.io/badge/Version-0.1.44-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Sheepdog Service @@ -8,7 +8,7 @@ A Helm chart for gen3 Sheepdog Service | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.37 | +| file://../common | common | 0.1.38 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | ## Values diff --git a/helm/sower/Chart.yaml b/helm/sower/Chart.yaml index 35c158e6f..77a508b11 100644 --- a/helm/sower/Chart.yaml +++ b/helm/sower/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.47 +version: 0.1.48 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.37 + version: 0.1.38 repository: file://../common diff --git a/helm/sower/README.md b/helm/sower/README.md index 0cbb4b9e9..2d63351ee 100644 --- a/helm/sower/README.md +++ b/helm/sower/README.md @@ -1,6 +1,6 @@ # sower -![Version: 0.1.47](https://img.shields.io/badge/Version-0.1.47-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.48](https://img.shields.io/badge/Version-0.1.48-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 sower @@ -8,7 +8,7 @@ A Helm chart for gen3 sower | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.37 | +| file://../common | common | 0.1.38 | ## Values diff --git a/helm/ssjdispatcher/Chart.yaml b/helm/ssjdispatcher/Chart.yaml index a0a67f41f..42e293b7a 100644 --- a/helm/ssjdispatcher/Chart.yaml +++ b/helm/ssjdispatcher/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.48 +version: 0.1.49 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.37 + version: 0.1.38 repository: file://../common diff --git a/helm/ssjdispatcher/README.md b/helm/ssjdispatcher/README.md index 58539aa88..fa2ba9cbd 100644 --- a/helm/ssjdispatcher/README.md +++ b/helm/ssjdispatcher/README.md @@ -1,6 +1,6 @@ # ssjdispatcher -![Version: 0.1.48](https://img.shields.io/badge/Version-0.1.48-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.49](https://img.shields.io/badge/Version-0.1.49-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 ssjdispatcher @@ -8,7 +8,7 @@ A Helm chart for gen3 ssjdispatcher | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.37 | +| file://../common | common | 0.1.38 | ## Values diff --git a/helm/vectis-overlays/Chart.yaml b/helm/vectis-overlays/Chart.yaml index 19d954e8f..f54394788 100644 --- a/helm/vectis-overlays/Chart.yaml +++ b/helm/vectis-overlays/Chart.yaml @@ -2,10 +2,10 @@ apiVersion: v2 name: vectis-overlays description: Vectis overlay API services (guppy-compat, siem, search-auth-proxy) type: application -version: 0.1.2 +version: 0.1.3 appVersion: "1.0" dependencies: - name: common - version: 0.1.37 + version: 0.1.38 repository: file://../common diff --git a/helm/vectis-overlays/README.md b/helm/vectis-overlays/README.md index de4f5289c..7cd448d11 100644 --- a/helm/vectis-overlays/README.md +++ b/helm/vectis-overlays/README.md @@ -1,6 +1,6 @@ # vectis-overlays -![Version: 0.1.2](https://img.shields.io/badge/Version-0.1.2-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.0](https://img.shields.io/badge/AppVersion-1.0-informational?style=flat-square) +![Version: 0.1.3](https://img.shields.io/badge/Version-0.1.3-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.0](https://img.shields.io/badge/AppVersion-1.0-informational?style=flat-square) Vectis overlay API services (guppy-compat, siem, search-auth-proxy) @@ -8,7 +8,7 @@ Vectis overlay API services (guppy-compat, siem, search-auth-proxy) | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.37 | +| file://../common | common | 0.1.38 | ## Values diff --git a/helm/workspace-proxy/Chart.yaml b/helm/workspace-proxy/Chart.yaml index 7f7258ac8..b3ba0e68a 100644 --- a/helm/workspace-proxy/Chart.yaml +++ b/helm/workspace-proxy/Chart.yaml @@ -5,10 +5,10 @@ description: > Replaces Emissary/Ambassador. Reads Service annotations written by Hatchery to resolve each user's workspace upstream, then proxies traffic from revproxy. type: application -version: 0.1.2 +version: 0.1.3 appVersion: "1.0" dependencies: - name: common - version: 0.1.37 + version: 0.1.38 repository: file://../common diff --git a/helm/workspace-proxy/README.md b/helm/workspace-proxy/README.md index f25bc9531..c78d16322 100644 --- a/helm/workspace-proxy/README.md +++ b/helm/workspace-proxy/README.md @@ -1,6 +1,6 @@ # workspace-proxy -![Version: 0.1.2](https://img.shields.io/badge/Version-0.1.2-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.0](https://img.shields.io/badge/AppVersion-1.0-informational?style=flat-square) +![Version: 0.1.3](https://img.shields.io/badge/Version-0.1.3-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.0](https://img.shields.io/badge/AppVersion-1.0-informational?style=flat-square) Per-user workspace HTTP/WebSocket router for gen3 vectis. Replaces Emissary/Ambassador. Reads Service annotations written by Hatchery to resolve each user's workspace upstream, then proxies traffic from revproxy. @@ -8,7 +8,7 @@ Per-user workspace HTTP/WebSocket router for gen3 vectis. Replaces Emissary/Amba | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.37 | +| file://../common | common | 0.1.38 | ## Values diff --git a/helm/wts/Chart.yaml b/helm/wts/Chart.yaml index b615b9cd2..91349b28f 100644 --- a/helm/wts/Chart.yaml +++ b/helm/wts/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.41 +version: 0.1.42 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,7 +25,7 @@ appVersion: "master" dependencies: - name: common - version: 0.1.37 + version: 0.1.38 repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/wts/README.md b/helm/wts/README.md index d82ff02a4..1818784e8 100644 --- a/helm/wts/README.md +++ b/helm/wts/README.md @@ -1,6 +1,6 @@ # wts -![Version: 0.1.41](https://img.shields.io/badge/Version-0.1.41-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.42](https://img.shields.io/badge/Version-0.1.42-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 workspace token service @@ -8,7 +8,7 @@ A Helm chart for gen3 workspace token service | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.37 | +| file://../common | common | 0.1.38 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | ## Values From c619709671122e2626f3c5077e678c9be3d53d8b Mon Sep 17 00:00:00 2001 From: Ajo Augustine Date: Fri, 10 Jul 2026 13:34:36 -0500 Subject: [PATCH 121/196] bump gen3 chart version --- helm/gen3/Chart.yaml | 2 +- helm/gen3/README.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index 3a903c8cc..633ef4665 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -209,7 +209,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.63 +version: 0.3.64 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index 8194c3265..de9986c60 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,6 +1,6 @@ # gen3 -![Version: 0.3.63](https://img.shields.io/badge/Version-0.3.63-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.3.64](https://img.shields.io/badge/Version-0.3.64-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons From 754ad0037059db736993708f639b7b8a99d3fc4c Mon Sep 17 00:00:00 2001 From: Sai Shanmukha Date: Fri, 10 Jul 2026 14:13:30 -0500 Subject: [PATCH 122/196] Sheepdog version bump --- helm/gen3/Chart.yaml | 2 +- helm/gen3/README.md | 2 +- helm/sheepdog/Chart.yaml | 2 +- helm/sheepdog/README.md | 2 +- 4 files changed, 4 insertions(+), 4 deletions(-) diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index 633ef4665..6d49b38de 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -120,7 +120,7 @@ dependencies: repository: "file://../revproxy" condition: revproxy.enabled - name: sheepdog - version: 0.1.44 + version: 0.1.45 repository: "file://../sheepdog" condition: sheepdog.enabled - name: ssjdispatcher diff --git a/helm/gen3/README.md b/helm/gen3/README.md index de9986c60..d37fb1b2a 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -56,7 +56,7 @@ Helm chart to deploy Gen3 Data Commons | file://../portal | portal | 0.1.62 | | file://../requestor | requestor | 0.1.36 | | file://../revproxy | revproxy | 0.1.64 | -| file://../sheepdog | sheepdog | 0.1.44 | +| file://../sheepdog | sheepdog | 0.1.45 | | file://../sower | sower | 0.1.48 | | file://../ssjdispatcher | ssjdispatcher | 0.1.49 | | file://../vectis-overlays | vectis-overlays | 0.1.3 | diff --git a/helm/sheepdog/Chart.yaml b/helm/sheepdog/Chart.yaml index fe94062ce..71a922a2f 100644 --- a/helm/sheepdog/Chart.yaml +++ b/helm/sheepdog/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.44 +version: 0.1.45 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/sheepdog/README.md b/helm/sheepdog/README.md index 895cfd808..d0d2ee5c0 100644 --- a/helm/sheepdog/README.md +++ b/helm/sheepdog/README.md @@ -1,6 +1,6 @@ # sheepdog -![Version: 0.1.44](https://img.shields.io/badge/Version-0.1.44-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.45](https://img.shields.io/badge/Version-0.1.45-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Sheepdog Service From dfc2973049d973e203c73a990faff5f5153193f1 Mon Sep 17 00:00:00 2001 From: Sai Shanmukha Date: Fri, 10 Jul 2026 14:16:07 -0500 Subject: [PATCH 123/196] gen3 version bump --- helm/gen3/Chart.yaml | 2 +- helm/gen3/README.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index 6d49b38de..6498b4108 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -209,7 +209,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.64 +version: 0.3.65 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index d37fb1b2a..c7ef35bdb 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,6 +1,6 @@ # gen3 -![Version: 0.3.64](https://img.shields.io/badge/Version-0.3.64-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.3.65](https://img.shields.io/badge/Version-0.3.65-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons From 20511945f32a8677b0dce99db059d06d2b23c6c9 Mon Sep 17 00:00:00 2001 From: Sai Shanmukha Date: Fri, 10 Jul 2026 15:24:23 -0500 Subject: [PATCH 124/196] Remove test repo branch --- .github/workflows/integration_tests.yaml | 1 - 1 file changed, 1 deletion(-) diff --git a/.github/workflows/integration_tests.yaml b/.github/workflows/integration_tests.yaml index eca7c3d59..c327cecdf 100644 --- a/.github/workflows/integration_tests.yaml +++ b/.github/workflows/integration_tests.yaml @@ -8,7 +8,6 @@ jobs: uses: uc-cdis/.github/.github/workflows/integration_tests.yaml@master with: HELM_BRANCH: ${{ github.event.pull_request.head.ref }} - TEST_REPO_BRANCH: chore/fix_setup_script_for_funnel secrets: CI_TEST_ORCID_USERID: ${{ secrets.CI_TEST_ORCID_USERID }} CI_TEST_ORCID_PASSWORD: ${{ secrets.CI_TEST_ORCID_PASSWORD }} From 9e5dc055030ccb63e90db1f411ccb59888475710 Mon Sep 17 00:00:00 2001 From: Guerdon Mukama Date: Mon, 13 Jul 2026 15:16:30 +1000 Subject: [PATCH 125/196] chore: requestor chart bump --- helm/gen3/Chart.yaml | 2 +- helm/requestor/Chart.yaml | 2 +- helm/requestor/templates/external-secret.yaml | 2 +- 3 files changed, 3 insertions(+), 3 deletions(-) diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index 6498b4108..1b4f5ef66 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -112,7 +112,7 @@ dependencies: repository: "file://../portal" condition: portal.enabled - name: requestor - version: 0.1.36 + version: 0.1.37 repository: "file://../requestor" condition: requestor.enabled - name: revproxy diff --git a/helm/requestor/Chart.yaml b/helm/requestor/Chart.yaml index 30d94c866..6d6090a1d 100644 --- a/helm/requestor/Chart.yaml +++ b/helm/requestor/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.36 +version: 0.1.37 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/requestor/templates/external-secret.yaml b/helm/requestor/templates/external-secret.yaml index f33265c08..1072a6c9b 100644 --- a/helm/requestor/templates/external-secret.yaml +++ b/helm/requestor/templates/external-secret.yaml @@ -4,7 +4,7 @@ {{- if and .Values.global.externalSecrets.deploy (not .Values.externalSecrets.createK8sRequestorSecret) }} --- -apiVersion: external-secrets.io/v1beta1 +apiVersion: {{ include "common.externalSecrets.apiVersion" . }} kind: ExternalSecret metadata: name: requestor-g3auto From f34010b2bd1ab23bbce23a6005211c04d3a625fb Mon Sep 17 00:00:00 2001 From: Guerdon Mukama Date: Mon, 13 Jul 2026 15:23:01 +1000 Subject: [PATCH 126/196] chore: version bump --- helm/gen3/Chart.yaml | 4 ++-- helm/revproxy/Chart.yaml | 2 +- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index 1b4f5ef66..01880063f 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -116,7 +116,7 @@ dependencies: repository: "file://../requestor" condition: requestor.enabled - name: revproxy - version: 0.1.64 + version: 0.1.65 repository: "file://../revproxy" condition: revproxy.enabled - name: sheepdog @@ -209,7 +209,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.65 +version: 0.3.66 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/revproxy/Chart.yaml b/helm/revproxy/Chart.yaml index 83236df41..4569a1b36 100644 --- a/helm/revproxy/Chart.yaml +++ b/helm/revproxy/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.64 +version: 0.1.65 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to From 3548cf145f27f093ca6503af4cab0e13d726b7e1 Mon Sep 17 00:00:00 2001 From: Edward Malinowski Date: Mon, 13 Jul 2026 05:32:59 -0500 Subject: [PATCH 127/196] Added EFS csi driver to cluster-level-resources --- helm/cluster-level-resources/Chart.yaml | 2 +- helm/cluster-level-resources/README.md | 5 ++- .../templates/efs-csi-driver.yaml | 44 +++++++++++++++++++ helm/cluster-level-resources/values.yaml | 6 +++ 4 files changed, 55 insertions(+), 2 deletions(-) create mode 100644 helm/cluster-level-resources/templates/efs-csi-driver.yaml diff --git a/helm/cluster-level-resources/Chart.yaml b/helm/cluster-level-resources/Chart.yaml index 938343293..c2790ed48 100644 --- a/helm/cluster-level-resources/Chart.yaml +++ b/helm/cluster-level-resources/Chart.yaml @@ -4,6 +4,6 @@ description: An app-of-apps Helm chart that allows for flexible deployment of re type: application -version: 0.6.45 +version: 0.6.46 appVersion: "1.17.0" diff --git a/helm/cluster-level-resources/README.md b/helm/cluster-level-resources/README.md index 42d8af39a..81bf3e670 100644 --- a/helm/cluster-level-resources/README.md +++ b/helm/cluster-level-resources/README.md @@ -1,6 +1,6 @@ # cluster-level-resources -![Version: 0.6.45](https://img.shields.io/badge/Version-0.6.45-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.17.0](https://img.shields.io/badge/AppVersion-1.17.0-informational?style=flat-square) +![Version: 0.6.46](https://img.shields.io/badge/Version-0.6.46-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.17.0](https://img.shields.io/badge/AppVersion-1.17.0-informational?style=flat-square) An app-of-apps Helm chart that allows for flexible deployment of resources that support Gen3 @@ -57,6 +57,9 @@ An app-of-apps Helm chart that allows for flexible deployment of resources that | ebs-csi-driver.configuration.enabled | bool | `false` | | | ebs-csi-driver.enabled | bool | `false` | | | ebs-csi-driver.targetRevision | string | `"2.48.0"` | | +| efs-csi-driver.configuration.enabled | bool | `false` | | +| efs-csi-driver.enabled | bool | `false` | | +| efs-csi-driver.targetRevision | string | `"4.2.0"` | | | eksClusterEndpoint | string | `""` | | | external-secrets.configuration.enabled | bool | `false` | | | external-secrets.enabled | bool | `false` | | diff --git a/helm/cluster-level-resources/templates/efs-csi-driver.yaml b/helm/cluster-level-resources/templates/efs-csi-driver.yaml new file mode 100644 index 000000000..fe5b330f9 --- /dev/null +++ b/helm/cluster-level-resources/templates/efs-csi-driver.yaml @@ -0,0 +1,44 @@ +{{ if index .Values "efs-csi-driver" "enabled" }} +apiVersion: argoproj.io/v1alpha1 +kind: Application +metadata: + name: efs-csi-driver + namespace: argocd +spec: + project: default + sources: + - chart: aws-efs-csi-driver + repoURL: https://kubernetes-sigs.github.io/aws-efs-csi-driver + targetRevision: {{ index .Values "efs-csi-driver" "targetRevision" }} + helm: + releaseName: efs-csi-driver + {{- if index .Values "efs-csi-driver" "configuration" "enabled" }} + valueFiles: + - $values/{{ .Values.cluster }}/cluster-values/efs-csi-driver.yaml + - repoURL: {{ .Values.configuration.configurationRepo }} + targetRevision: {{ .Values.configuration.configurationRevision }} + ref: values + {{- else }} + values: | + image: + tag: v3.2.0 + useFIPS: true + + controller: + serviceAccount: + annotations: + eks.amazonaws.com/role-arn: arn:aws:iam::{{ .Values.accountNumber }}:role/gen3_service/{{ .Values.eksClusterName | default .Values.cluster }}--kube-system--efs-csi-controller + node: + serviceAccount: + annotations: + eks.amazonaws.com/role-arn: arn:aws:iam::{{ .Values.accountNumber }}:role/gen3_service/{{ .Values.eksClusterName | default .Values.cluster }}--kube-system--efs-csi-node + {{- end }} + destination: + server: "https://kubernetes.default.svc" + namespace: kube-system + syncPolicy: + syncOptions: + - CreateNamespace=false + automated: + selfHeal: true +{{ end }} diff --git a/helm/cluster-level-resources/values.yaml b/helm/cluster-level-resources/values.yaml index 7386c66f7..3f4ae97d4 100644 --- a/helm/cluster-level-resources/values.yaml +++ b/helm/cluster-level-resources/values.yaml @@ -93,6 +93,12 @@ ebs-csi-driver: configuration: enabled: false +efs-csi-driver: + enabled: false + targetRevision: "4.2.0" + configuration: + enabled: false + external-secrets: enabled: false targetRevision: "0.9.13" From 81de6cd97ce2705bb7f96f1b5d698de3d98d3e60 Mon Sep 17 00:00:00 2001 From: Sai Shanmukha Date: Mon, 13 Jul 2026 10:58:34 -0400 Subject: [PATCH 128/196] Rename blacklisted to denylisted --- helm/gen3/Chart.yaml | 2 +- helm/gen3/README.md | 2 +- helm/revproxy/Chart.yaml | 2 +- helm/revproxy/README.md | 2 +- helm/revproxy/gen3.nginx.conf/fence-service.conf | 12 ++++++------ 5 files changed, 10 insertions(+), 10 deletions(-) diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index 4d7b05b83..e338e7c0e 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -116,7 +116,7 @@ dependencies: repository: "file://../requestor" condition: requestor.enabled - name: revproxy - version: 0.1.64 + version: 0.1.65 repository: "file://../revproxy" condition: revproxy.enabled - name: sheepdog diff --git a/helm/gen3/README.md b/helm/gen3/README.md index 0a6841690..987f48728 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -55,7 +55,7 @@ Helm chart to deploy Gen3 Data Commons | file://../peregrine | peregrine | 0.1.43 | | file://../portal | portal | 0.1.61 | | file://../requestor | requestor | 0.1.35 | -| file://../revproxy | revproxy | 0.1.64 | +| file://../revproxy | revproxy | 0.1.65 | | file://../sheepdog | sheepdog | 0.1.43 | | file://../sower | sower | 0.1.47 | | file://../ssjdispatcher | ssjdispatcher | 0.1.48 | diff --git a/helm/revproxy/Chart.yaml b/helm/revproxy/Chart.yaml index 0640343ec..dc98b48e2 100644 --- a/helm/revproxy/Chart.yaml +++ b/helm/revproxy/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.64 +version: 0.1.65 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/revproxy/README.md b/helm/revproxy/README.md index f3cc0ae9a..66237ac3d 100644 --- a/helm/revproxy/README.md +++ b/helm/revproxy/README.md @@ -1,6 +1,6 @@ # revproxy -![Version: 0.1.64](https://img.shields.io/badge/Version-0.1.64-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.65](https://img.shields.io/badge/Version-0.1.65-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 revproxy diff --git a/helm/revproxy/gen3.nginx.conf/fence-service.conf b/helm/revproxy/gen3.nginx.conf/fence-service.conf index 7a30e6869..c8a99787c 100644 --- a/helm/revproxy/gen3.nginx.conf/fence-service.conf +++ b/helm/revproxy/gen3.nginx.conf/fence-service.conf @@ -21,15 +21,15 @@ location /authn-proxy { } # Hits the fence API and stops the original request with a 403 if the provided -# token is blacklisted. Usage: `auth_request /block-denylisted-token;` +# token is denylisted. Usage: `auth_request /block-denylisted-token;` location /block-denylisted-token { internal; set $proxy_service "fence"; - error_page 400 =403 @block_blacklisted_token; - error_page 500 =403 @block_blacklisted_token; + error_page 400 =403 @block_denylisted_token; + error_page 500 =403 @block_denylisted_token; # Previous versions of Fence that don't have the "/token/denylisted" endpoint return 405. # Returning 403 forces the deployment of a recent Fence for endpoints that require this check. - error_page 405 =403 @block_blacklisted_token; + error_page 405 =403 @block_denylisted_token; proxy_pass http://fence-service${des_domain}/credentials/token/denylisted; proxy_method POST; @@ -50,9 +50,9 @@ location /block-denylisted-token { client_max_body_size 0; } -location @block_blacklisted_token { +location @block_denylisted_token { internal; - return 403 "unable to check if token is blacklisted"; + return 403 "unable to check if token is denylisted"; } location /user/credentials/token/denylisted { From 0e6de8a4feb3c964bf23df30436662997b3d5b18 Mon Sep 17 00:00:00 2001 From: Mingfei Shao Date: Mon, 13 Jul 2026 14:38:56 -0500 Subject: [PATCH 129/196] rename secret name --- helm/zendesk-wrapper/templates/deployment.yaml | 2 +- helm/zendesk-wrapper/templates/external-secret.yaml | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/helm/zendesk-wrapper/templates/deployment.yaml b/helm/zendesk-wrapper/templates/deployment.yaml index 400867ff2..614955806 100644 --- a/helm/zendesk-wrapper/templates/deployment.yaml +++ b/helm/zendesk-wrapper/templates/deployment.yaml @@ -74,4 +74,4 @@ spec: valueFrom: secretKeyRef: name: zendesk-wrapper-secret - key: tokenKey + key: apiToken diff --git a/helm/zendesk-wrapper/templates/external-secret.yaml b/helm/zendesk-wrapper/templates/external-secret.yaml index 89f8b7e0f..ad80970dc 100644 --- a/helm/zendesk-wrapper/templates/external-secret.yaml +++ b/helm/zendesk-wrapper/templates/external-secret.yaml @@ -13,10 +13,10 @@ spec: name: zendesk-wrapper-secret creationPolicy: Owner data: - - secretKey: tokenKey + - secretKey: apiToken remoteRef: key: {{include "zendesk-wrapper-secret" .}} - property: tokenKey + property: apiToken - secretKey: apiEmail remoteRef: key: {{include "zendesk-wrapper-secret" .}} From 56b06631138360cfd38211733c30b3d811036991 Mon Sep 17 00:00:00 2001 From: Mingfei Shao Date: Mon, 13 Jul 2026 15:03:59 -0500 Subject: [PATCH 130/196] update action --- .github/ct.yaml | 1 - .github/workflows/lint_test.yaml | 4 ++-- 2 files changed, 2 insertions(+), 3 deletions(-) diff --git a/.github/ct.yaml b/.github/ct.yaml index 17d1fff20..719c2cca8 100644 --- a/.github/ct.yaml +++ b/.github/ct.yaml @@ -1,5 +1,4 @@ remote: origin -target-branch: master chart-dirs: - helm chart-repos: diff --git a/.github/workflows/lint_test.yaml b/.github/workflows/lint_test.yaml index b89d8c7ca..011b08f17 100644 --- a/.github/workflows/lint_test.yaml +++ b/.github/workflows/lint_test.yaml @@ -27,13 +27,13 @@ jobs: - name: Run chart-testing (list-changed) id: list-changed run: | - changed=$(ct list-changed --config .github/ct.yaml) + changed=$(ct list-changed --config .github/ct.yaml --target-branch master) if [[ -n "$changed" ]]; then echo "changed=true >> $GITHUB_OUTPUT" fi - name: Run chart-testing (lint) - run: ct lint --config .github/ct.yaml + run: ct lint --config .github/ct.yaml --target-branch ${{ github.base_ref || 'master' }} - name: Set up Kubeconform id: setup-kubeconform From 52e9cdc874c0c3b43cc682bd623d0fed2318ed95 Mon Sep 17 00:00:00 2001 From: Mingfei Shao Date: Mon, 13 Jul 2026 15:12:32 -0500 Subject: [PATCH 131/196] Revert "update action" This reverts commit 56b06631138360cfd38211733c30b3d811036991. --- .github/ct.yaml | 1 + .github/workflows/lint_test.yaml | 4 ++-- 2 files changed, 3 insertions(+), 2 deletions(-) diff --git a/.github/ct.yaml b/.github/ct.yaml index 719c2cca8..17d1fff20 100644 --- a/.github/ct.yaml +++ b/.github/ct.yaml @@ -1,4 +1,5 @@ remote: origin +target-branch: master chart-dirs: - helm chart-repos: diff --git a/.github/workflows/lint_test.yaml b/.github/workflows/lint_test.yaml index 011b08f17..b89d8c7ca 100644 --- a/.github/workflows/lint_test.yaml +++ b/.github/workflows/lint_test.yaml @@ -27,13 +27,13 @@ jobs: - name: Run chart-testing (list-changed) id: list-changed run: | - changed=$(ct list-changed --config .github/ct.yaml --target-branch master) + changed=$(ct list-changed --config .github/ct.yaml) if [[ -n "$changed" ]]; then echo "changed=true >> $GITHUB_OUTPUT" fi - name: Run chart-testing (lint) - run: ct lint --config .github/ct.yaml --target-branch ${{ github.base_ref || 'master' }} + run: ct lint --config .github/ct.yaml - name: Set up Kubeconform id: setup-kubeconform From 62f71f7282fbfb292fe8cfeb5c59520e15821a46 Mon Sep 17 00:00:00 2001 From: Mingfei Shao Date: Mon, 13 Jul 2026 15:18:37 -0500 Subject: [PATCH 132/196] fix chart --- helm/zendesk-wrapper/Chart.yaml | 2 +- helm/zendesk-wrapper/README.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/helm/zendesk-wrapper/Chart.yaml b/helm/zendesk-wrapper/Chart.yaml index 7709d1ae1..700d28cff 100644 --- a/helm/zendesk-wrapper/Chart.yaml +++ b/helm/zendesk-wrapper/Chart.yaml @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.35 + version: 0.1.38 repository: file://../common diff --git a/helm/zendesk-wrapper/README.md b/helm/zendesk-wrapper/README.md index 94dbd1093..acd25f756 100644 --- a/helm/zendesk-wrapper/README.md +++ b/helm/zendesk-wrapper/README.md @@ -8,7 +8,7 @@ A Helm chart for gen3 Zendesk Wrapper Service | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.35 | +| file://../common | common | 0.1.38 | ## Values From f03bd5adae256cdf7e57d5c2b60b8f0ed644ef16 Mon Sep 17 00:00:00 2001 From: Mingfei Shao Date: Mon, 13 Jul 2026 15:56:43 -0500 Subject: [PATCH 133/196] fix chart --- helm/zendesk-wrapper/README.md | 3 +++ helm/zendesk-wrapper/values.yaml | 6 ++++++ 2 files changed, 9 insertions(+) diff --git a/helm/zendesk-wrapper/README.md b/helm/zendesk-wrapper/README.md index acd25f756..fc749c899 100644 --- a/helm/zendesk-wrapper/README.md +++ b/helm/zendesk-wrapper/README.md @@ -32,6 +32,9 @@ A Helm chart for gen3 Zendesk Wrapper Service | global.autoscaling.maxReplicas | int | `10` | | | global.autoscaling.minReplicas | int | `1` | | | global.environment | string | `"default"` | | +| global.externalSecrets | map | `{"deploy":false,"separateSecretStore":false}` | External Secrets settings. | +| global.externalSecrets.deploy | bool | `false` | Will use ExternalSecret resources to pull secrets from Secrets Manager instead of creating them locally. Be cautious as this will override any zendesk wrapper secrets you have deployed. | +| global.externalSecrets.separateSecretStore | string | `false` | Will deploy a separate External Secret Store for this service. | | global.minAvailable | int | `1` | | | global.netPolicy.dbSubnet | string | `""` | | | global.netPolicy.enabled | bool | `false` | | diff --git a/helm/zendesk-wrapper/values.yaml b/helm/zendesk-wrapper/values.yaml index 52aed5ca5..851b315f3 100644 --- a/helm/zendesk-wrapper/values.yaml +++ b/helm/zendesk-wrapper/values.yaml @@ -7,6 +7,12 @@ global: netPolicy: enabled: false dbSubnet: "" + # -- (map) External Secrets settings. + externalSecrets: + # -- (bool) Will use ExternalSecret resources to pull secrets from Secrets Manager instead of creating them locally. Be cautious as this will override any zendesk wrapper secrets you have deployed. + deploy: false + # -- (string) Will deploy a separate External Secret Store for this service. + separateSecretStore: false autoscaling: enabled: false minReplicas: 1 From b1f5cc48afab46319ea46f1175926bc81668aa16 Mon Sep 17 00:00:00 2001 From: Mingfei Shao Date: Mon, 13 Jul 2026 16:06:59 -0500 Subject: [PATCH 134/196] fix chart --- helm/zendesk-wrapper/README.md | 4 ++-- helm/zendesk-wrapper/values.yaml | 3 ++- 2 files changed, 4 insertions(+), 3 deletions(-) diff --git a/helm/zendesk-wrapper/README.md b/helm/zendesk-wrapper/README.md index fc749c899..3355b401b 100644 --- a/helm/zendesk-wrapper/README.md +++ b/helm/zendesk-wrapper/README.md @@ -22,8 +22,8 @@ A Helm chart for gen3 Zendesk Wrapper Service | autoscaling | object | `{}` | | | commonLabels | string | `nil` | | | criticalService | string | `"false"` | | -| env | map | `{"GEN3_ZENDESK_URL":""}` | Environment variables for the Zendesk wrapper service | -| env.GEN3_ZENDESK_URL | string | `""` | Zendesk instance URL (e.g., https://gen3support.zendesk.com) | +| env | map | `[{"name":"GEN3_ZENDESK_URL","value":""}]` | Environment variables for the Zendesk wrapper service | +| env[0] | string | `{"name":"GEN3_ZENDESK_URL","value":""}` | Zendesk instance URL (e.g., https://gen3support.zendesk.com) | | externalSecrets | map | `{"name":"zendesk-wrapper-secret"}` | Secret environment variables (referenced from Kubernetes secrets) | | externalSecrets.name | string | `"zendesk-wrapper-secret"` | Name of the Kubernetes secret containing the Zendesk API token | | global.autoscaling.averageCPUValue | string | `"500m"` | | diff --git a/helm/zendesk-wrapper/values.yaml b/helm/zendesk-wrapper/values.yaml index 851b315f3..e62e178b9 100644 --- a/helm/zendesk-wrapper/values.yaml +++ b/helm/zendesk-wrapper/values.yaml @@ -80,7 +80,8 @@ netPolicy: # -- (map) Environment variables for the Zendesk wrapper service env: # -- (string) Zendesk instance URL (e.g., https://gen3support.zendesk.com) - GEN3_ZENDESK_URL: "" + - name: GEN3_ZENDESK_URL + value: "" # -- (map) Secret environment variables (referenced from Kubernetes secrets) externalSecrets: From 2c82da1e9f25c825a28db09499a038e4bcc7a8cd Mon Sep 17 00:00:00 2001 From: Sai Shanmukha Date: Mon, 13 Jul 2026 20:05:38 -0400 Subject: [PATCH 135/196] Use current helm branch to run kind tests --- .github/workflows/integration_tests_on_kind.yaml | 1 + 1 file changed, 1 insertion(+) diff --git a/.github/workflows/integration_tests_on_kind.yaml b/.github/workflows/integration_tests_on_kind.yaml index 943299ca4..b4fcfd1de 100644 --- a/.github/workflows/integration_tests_on_kind.yaml +++ b/.github/workflows/integration_tests_on_kind.yaml @@ -19,6 +19,7 @@ jobs: uses: uc-cdis/.github/.github/workflows/integration_tests.yaml@master with: EXTERNAL_TO_CTDS: "true" + HELM_BRANCH: ${{ github.event.pull_request.head.ref }} SERVICE_TO_TEST: gen3_workflow SETUP_SCRIPT_1: https://raw.githubusercontent.com/uc-cdis/gen3-workflow/refs/heads/master/.github/workflows/integration_tests_on_kind/ci_start_kind_cluster.sh SETUP_SCRIPT_2: https://raw.githubusercontent.com/uc-cdis/gen3-workflow/refs/heads/master/.github/workflows/integration_tests_on_kind/ci_override_config_and_start_minio.sh From c44c6e93db6426ceef630d30a23e0ae7da4fff06 Mon Sep 17 00:00:00 2001 From: Mingfei Shao Date: Tue, 14 Jul 2026 10:10:31 -0500 Subject: [PATCH 136/196] trigger hook --- helm/gen3/Chart.yaml | 4 ++-- helm/gen3/README.md | 4 ++-- helm/revproxy/Chart.yaml | 2 +- helm/revproxy/README.md | 2 +- helm/zendesk-wrapper/README.md | 4 ++-- helm/zendesk-wrapper/values.yaml | 2 +- 6 files changed, 9 insertions(+), 9 deletions(-) diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index ddda39f96..07569038a 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -116,7 +116,7 @@ dependencies: repository: "file://../requestor" condition: requestor.enabled - name: revproxy - version: 0.1.65 + version: 0.1.66 repository: "file://../revproxy" condition: revproxy.enabled - name: sheepdog @@ -213,7 +213,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.66 +version: 0.3.67 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index d3adf4809..502fbc3d3 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,6 +1,6 @@ # gen3 -![Version: 0.3.66](https://img.shields.io/badge/Version-0.3.66-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.3.67](https://img.shields.io/badge/Version-0.3.67-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons @@ -55,7 +55,7 @@ Helm chart to deploy Gen3 Data Commons | file://../peregrine | peregrine | 0.1.44 | | file://../portal | portal | 0.1.62 | | file://../requestor | requestor | 0.1.36 | -| file://../revproxy | revproxy | 0.1.65 | +| file://../revproxy | revproxy | 0.1.66 | | file://../sheepdog | sheepdog | 0.1.45 | | file://../sower | sower | 0.1.48 | | file://../ssjdispatcher | ssjdispatcher | 0.1.49 | diff --git a/helm/revproxy/Chart.yaml b/helm/revproxy/Chart.yaml index 4569a1b36..225f7994c 100644 --- a/helm/revproxy/Chart.yaml +++ b/helm/revproxy/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.65 +version: 0.1.66 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/revproxy/README.md b/helm/revproxy/README.md index 0ef2c44f9..4c6b897ed 100644 --- a/helm/revproxy/README.md +++ b/helm/revproxy/README.md @@ -1,6 +1,6 @@ # revproxy -![Version: 0.1.65](https://img.shields.io/badge/Version-0.1.65-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.66](https://img.shields.io/badge/Version-0.1.66-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 revproxy diff --git a/helm/zendesk-wrapper/README.md b/helm/zendesk-wrapper/README.md index 3355b401b..0556c7c68 100644 --- a/helm/zendesk-wrapper/README.md +++ b/helm/zendesk-wrapper/README.md @@ -22,8 +22,8 @@ A Helm chart for gen3 Zendesk Wrapper Service | autoscaling | object | `{}` | | | commonLabels | string | `nil` | | | criticalService | string | `"false"` | | -| env | map | `[{"name":"GEN3_ZENDESK_URL","value":""}]` | Environment variables for the Zendesk wrapper service | -| env[0] | string | `{"name":"GEN3_ZENDESK_URL","value":""}` | Zendesk instance URL (e.g., https://gen3support.zendesk.com) | +| env | map | `[{"name":"GEN3_ZENDESK_URL","value":" "}]` | Environment variables for the Zendesk wrapper service | +| env[0] | string | `{"name":"GEN3_ZENDESK_URL","value":" "}` | Zendesk instance URL (e.g., https://gen3support.zendesk.com) | | externalSecrets | map | `{"name":"zendesk-wrapper-secret"}` | Secret environment variables (referenced from Kubernetes secrets) | | externalSecrets.name | string | `"zendesk-wrapper-secret"` | Name of the Kubernetes secret containing the Zendesk API token | | global.autoscaling.averageCPUValue | string | `"500m"` | | diff --git a/helm/zendesk-wrapper/values.yaml b/helm/zendesk-wrapper/values.yaml index e62e178b9..3d19275ed 100644 --- a/helm/zendesk-wrapper/values.yaml +++ b/helm/zendesk-wrapper/values.yaml @@ -81,7 +81,7 @@ netPolicy: env: # -- (string) Zendesk instance URL (e.g., https://gen3support.zendesk.com) - name: GEN3_ZENDESK_URL - value: "" + value: " " # -- (map) Secret environment variables (referenced from Kubernetes secrets) externalSecrets: From bd3e4a30f330b127e7e0bcae59a2527b4bc7ddbc Mon Sep 17 00:00:00 2001 From: Mingfei Shao Date: Tue, 14 Jul 2026 10:10:47 -0500 Subject: [PATCH 137/196] trigger hook --- helm/zendesk-wrapper/README.md | 4 ++-- helm/zendesk-wrapper/values.yaml | 2 +- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/helm/zendesk-wrapper/README.md b/helm/zendesk-wrapper/README.md index 0556c7c68..3355b401b 100644 --- a/helm/zendesk-wrapper/README.md +++ b/helm/zendesk-wrapper/README.md @@ -22,8 +22,8 @@ A Helm chart for gen3 Zendesk Wrapper Service | autoscaling | object | `{}` | | | commonLabels | string | `nil` | | | criticalService | string | `"false"` | | -| env | map | `[{"name":"GEN3_ZENDESK_URL","value":" "}]` | Environment variables for the Zendesk wrapper service | -| env[0] | string | `{"name":"GEN3_ZENDESK_URL","value":" "}` | Zendesk instance URL (e.g., https://gen3support.zendesk.com) | +| env | map | `[{"name":"GEN3_ZENDESK_URL","value":""}]` | Environment variables for the Zendesk wrapper service | +| env[0] | string | `{"name":"GEN3_ZENDESK_URL","value":""}` | Zendesk instance URL (e.g., https://gen3support.zendesk.com) | | externalSecrets | map | `{"name":"zendesk-wrapper-secret"}` | Secret environment variables (referenced from Kubernetes secrets) | | externalSecrets.name | string | `"zendesk-wrapper-secret"` | Name of the Kubernetes secret containing the Zendesk API token | | global.autoscaling.averageCPUValue | string | `"500m"` | | diff --git a/helm/zendesk-wrapper/values.yaml b/helm/zendesk-wrapper/values.yaml index 3d19275ed..e62e178b9 100644 --- a/helm/zendesk-wrapper/values.yaml +++ b/helm/zendesk-wrapper/values.yaml @@ -81,7 +81,7 @@ netPolicy: env: # -- (string) Zendesk instance URL (e.g., https://gen3support.zendesk.com) - name: GEN3_ZENDESK_URL - value: " " + value: "" # -- (map) Secret environment variables (referenced from Kubernetes secrets) externalSecrets: From dedfbc9b713e6596573563550d9f558d5841dad1 Mon Sep 17 00:00:00 2001 From: Pauline Ribeyre <4224001+paulineribeyre@users.noreply.github.com> Date: Fri, 17 Jul 2026 13:33:05 -0500 Subject: [PATCH 138/196] Add S3Files configuration to Funnel --- helm/funnel/README.md | 1 + helm/funnel/files/worker-pv.yaml | 16 +++++++++++++++- helm/funnel/values.yaml | 2 ++ 3 files changed, 18 insertions(+), 1 deletion(-) diff --git a/helm/funnel/README.md b/helm/funnel/README.md index cd3df1527..bf9088ee9 100644 --- a/helm/funnel/README.md +++ b/helm/funnel/README.md @@ -222,6 +222,7 @@ A Helm chart for Kubernetes | storage.driver | string | `"aws-s3"` | | | storage.provisioner | string | `"s3.csi.aws.com"` | | | storage.size | string | `"10Mi"` | | +| storage.type | string | `"mountpoint_s3"` | | | stsRegion | string | `"us-east-1"` | | | volumeMounts[0].mountPath | string | `"/etc/config/funnel-server.yaml"` | | | volumeMounts[0].name | string | `"funnel-patched-config-volume"` | | diff --git a/helm/funnel/files/worker-pv.yaml b/helm/funnel/files/worker-pv.yaml index 0b7e2e1ec..2241c3f17 100644 --- a/helm/funnel/files/worker-pv.yaml +++ b/helm/funnel/files/worker-pv.yaml @@ -8,12 +8,14 @@ metadata: namespace: {{`{{.Namespace}}`}} spec: storageClassName: "" # Required for static provisioning - capacity: + capacity: # Note: capacity is effectively elastic and only serves as a placeholder storage: "10Mi" accessModes: - ReadWriteMany persistentVolumeReclaimPolicy: Retain mountOptions: + - tls + {{- if eq .Values.storage.type "mountpoint_s3" }} - allow-delete - allow-overwrite # allow overwriting existing files - incremental-upload # allow appending to existing files @@ -21,6 +23,10 @@ spec: - region={{`{{.Region}}`}} - file-mode=0755 - prefix=funnel-temp-files/ + {{- end }} + {{- if eq .Values.storage.type "s3files" }} + - noresvport + {{- end }} {{`{{- if .KmsKeyID}}`}} - sse aws:kms - sse-kms-key-id={{`{{.KmsKeyID}}`}} @@ -31,6 +37,7 @@ spec: - force-path-style {{- end }} csi: + {{- if eq .Values.storage.type "mountpoint_s3" }} driver: s3.csi.aws.com volumeHandle: s3-csi-{{`{{.TaskId}}`}} volumeAttributes: @@ -39,6 +46,13 @@ spec: authenticationSource: {{ .Values.authenticationSource }} stsRegion: {{ .Values.stsRegion }} {{- end }} + {{- end }} + {{- if eq .Values.storage.type "s3files" }} + driver: efs.csi.aws.com + volumeHandle: s3files:{{`{{.S3FilesystemId}}`}} + volumeAttributes: + encryptInTransit: "true" + {{- end }} claimRef: namespace: {{`{{.Namespace}}`}} name: funnel-worker-pvc-{{`{{.TaskId}}`}} \ No newline at end of file diff --git a/helm/funnel/values.yaml b/helm/funnel/values.yaml index b539afd15..2ca35dc59 100644 --- a/helm/funnel/values.yaml +++ b/helm/funnel/values.yaml @@ -255,6 +255,8 @@ service: # Funnel Worker + Executor storage (S3 bucket) storage: + # type: either "mountpoint_s3" or "s3files" + type: mountpoint_s3 driver: aws-s3 size: 10Mi accessMode: ReadWriteMany From 2167f6dcbab4006b3bac6b20deaa1c6c0fd58dd9 Mon Sep 17 00:00:00 2001 From: Mingfei Shao Date: Fri, 17 Jul 2026 14:39:27 -0500 Subject: [PATCH 139/196] update zendesk secret names --- helm/gen3/Chart.yaml | 4 ++-- helm/gen3/README.md | 4 ++-- helm/zendesk-wrapper/Chart.yaml | 2 +- helm/zendesk-wrapper/README.md | 2 +- helm/zendesk-wrapper/templates/deployment.yaml | 8 ++++---- helm/zendesk-wrapper/templates/external-secret.yaml | 8 ++++---- 6 files changed, 14 insertions(+), 14 deletions(-) diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index 07569038a..07459f49b 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -136,7 +136,7 @@ dependencies: repository: "file://../wts" condition: wts.enabled - name: zendesk-wrapper - version: 0.1.0 + version: 0.1.1 repository: "file://../zendesk-wrapper" condition: zendesk-wrapper.enabled - name: gen3-network-policies @@ -213,7 +213,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.67 +version: 0.3.68 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index 502fbc3d3..61a16381a 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,6 +1,6 @@ # gen3 -![Version: 0.3.67](https://img.shields.io/badge/Version-0.3.67-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.3.68](https://img.shields.io/badge/Version-0.3.68-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons @@ -62,7 +62,7 @@ Helm chart to deploy Gen3 Data Commons | file://../vectis-overlays | vectis-overlays | 0.1.3 | | file://../workspace-proxy | workspace-proxy | 0.1.3 | | file://../wts | wts | 0.1.42 | -| file://../zendesk-wrapper | zendesk-wrapper | 0.1.0 | +| file://../zendesk-wrapper | zendesk-wrapper | 0.1.1 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | | https://helm.elastic.co | elasticsearch | 7.10.2 | diff --git a/helm/zendesk-wrapper/Chart.yaml b/helm/zendesk-wrapper/Chart.yaml index 700d28cff..6f6983ff8 100644 --- a/helm/zendesk-wrapper/Chart.yaml +++ b/helm/zendesk-wrapper/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.0 +version: 0.1.1 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/zendesk-wrapper/README.md b/helm/zendesk-wrapper/README.md index 3355b401b..441c13509 100644 --- a/helm/zendesk-wrapper/README.md +++ b/helm/zendesk-wrapper/README.md @@ -1,6 +1,6 @@ # zendesk-wrapper -![Version: 0.1.0](https://img.shields.io/badge/Version-0.1.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.1](https://img.shields.io/badge/Version-0.1.1-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Zendesk Wrapper Service diff --git a/helm/zendesk-wrapper/templates/deployment.yaml b/helm/zendesk-wrapper/templates/deployment.yaml index 614955806..42bd23a40 100644 --- a/helm/zendesk-wrapper/templates/deployment.yaml +++ b/helm/zendesk-wrapper/templates/deployment.yaml @@ -65,13 +65,13 @@ spec: {{- toYaml .Values.resources | nindent 12 }} env: {{- toYaml .Values.env | nindent 12 }} - - name: ZENDESK_API_EMAIL + - name: ZENDESK_OAUTH_CLIENT_SECRET valueFrom: secretKeyRef: name: zendesk-wrapper-secret - key: apiEmail - - name: ZENDESK_API_TOKEN + key: clientSecret + - name: ZENDESK_OAUTH_CLIENT_ID valueFrom: secretKeyRef: name: zendesk-wrapper-secret - key: apiToken + key: clientID diff --git a/helm/zendesk-wrapper/templates/external-secret.yaml b/helm/zendesk-wrapper/templates/external-secret.yaml index ad80970dc..0dc01be23 100644 --- a/helm/zendesk-wrapper/templates/external-secret.yaml +++ b/helm/zendesk-wrapper/templates/external-secret.yaml @@ -13,12 +13,12 @@ spec: name: zendesk-wrapper-secret creationPolicy: Owner data: - - secretKey: apiToken + - secretKey: clientID remoteRef: key: {{include "zendesk-wrapper-secret" .}} - property: apiToken - - secretKey: apiEmail + property: clientID + - secretKey: clientSecret remoteRef: key: {{include "zendesk-wrapper-secret" .}} - property: apiEmail + property: clientSecret {{- end }} From 64c11e5950517821851336441f34b127c6d15cdd Mon Sep 17 00:00:00 2001 From: Ajo Augustine Date: Mon, 20 Jul 2026 15:10:28 -0500 Subject: [PATCH 140/196] fix embedding-management-service containerPort reference --- helm/embedding-management-service/Chart.yaml | 2 +- helm/embedding-management-service/README.md | 2 +- helm/embedding-management-service/templates/deployment.yaml | 2 +- helm/gen3/Chart.yaml | 4 ++-- helm/gen3/README.md | 4 ++-- 5 files changed, 7 insertions(+), 7 deletions(-) diff --git a/helm/embedding-management-service/Chart.yaml b/helm/embedding-management-service/Chart.yaml index 811efc0b5..6e17d0aa5 100644 --- a/helm/embedding-management-service/Chart.yaml +++ b/helm/embedding-management-service/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.9 +version: 0.1.10 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/embedding-management-service/README.md b/helm/embedding-management-service/README.md index 35c52913d..f23c3c412 100644 --- a/helm/embedding-management-service/README.md +++ b/helm/embedding-management-service/README.md @@ -1,6 +1,6 @@ # embedding-management-service -![Version: 0.1.9](https://img.shields.io/badge/Version-0.1.9-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.16.0](https://img.shields.io/badge/AppVersion-1.16.0-informational?style=flat-square) +![Version: 0.1.10](https://img.shields.io/badge/Version-0.1.10-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.16.0](https://img.shields.io/badge/AppVersion-1.16.0-informational?style=flat-square) A Helm chart for Kubernetes diff --git a/helm/embedding-management-service/templates/deployment.yaml b/helm/embedding-management-service/templates/deployment.yaml index 9fdb690d1..2225b97d4 100644 --- a/helm/embedding-management-service/templates/deployment.yaml +++ b/helm/embedding-management-service/templates/deployment.yaml @@ -38,7 +38,7 @@ spec: imagePullPolicy: {{ .Values.image.pullPolicy }} ports: - name: http - containerPort: {{ .Values.service.targetPort }} + containerPort: {{ .Values.service.port.targetPort }} protocol: TCP env: - name: DB_HOST diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index 07569038a..dd6e36eea 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -56,7 +56,7 @@ dependencies: repository: "file://../data-upload-cron" condition: data-upload-cron.enabled - name: embedding-management-service - version: 0.1.9 + version: 0.1.10 repository: file://../embedding-management-service condition: embedding-management-service.enabled - name: etl @@ -213,7 +213,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.67 +version: 0.3.68 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index 502fbc3d3..165e8d89c 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,6 +1,6 @@ # gen3 -![Version: 0.3.67](https://img.shields.io/badge/Version-0.3.67-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.3.68](https://img.shields.io/badge/Version-0.3.68-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons @@ -32,7 +32,7 @@ Helm chart to deploy Gen3 Data Commons | file://../data-upload-cron | data-upload-cron | 0.1.8 | | file://../datareplicate | datareplicate | 0.1.23 | | file://../dicom-server | dicom-server | 0.1.33 | -| file://../embedding-management-service | embedding-management-service | 0.1.9 | +| file://../embedding-management-service | embedding-management-service | 0.1.10 | | file://../etl | etl | 0.1.23 | | file://../fence | fence | 0.1.80 | | file://../frontend-framework | frontend-framework | 0.1.31 | From 1a12ab3d70230f4b5b095260710122e6fe196540 Mon Sep 17 00:00:00 2001 From: Mingfei Shao Date: Mon, 20 Jul 2026 16:17:15 -0500 Subject: [PATCH 141/196] update chart --- helm/gen3/Chart.yaml | 2 +- helm/gen3/README.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index b40c458c3..14502aaf2 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -213,7 +213,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.68 +version: 0.3.69 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index 9a8d31535..909b663e0 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,6 +1,6 @@ # gen3 -![Version: 0.3.68](https://img.shields.io/badge/Version-0.3.68-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.3.69](https://img.shields.io/badge/Version-0.3.69-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons From 219c959740c1150c3a16f7f6f5896d4c48f92ced Mon Sep 17 00:00:00 2001 From: mark xiao Date: Tue, 21 Jul 2026 14:43:14 -0500 Subject: [PATCH 142/196] add envs --- helm/gen3-embeddings/README.md | 2 +- helm/gen3-embeddings/values.yaml | 6 ++++++ 2 files changed, 7 insertions(+), 1 deletion(-) diff --git a/helm/gen3-embeddings/README.md b/helm/gen3-embeddings/README.md index 9236bf607..60911de7a 100644 --- a/helm/gen3-embeddings/README.md +++ b/helm/gen3-embeddings/README.md @@ -21,7 +21,7 @@ A Helm chart for Kubernetes | commonLabels | map | `nil` | Will completely override the commonLabels defined in the common chart's _label_setup.tpl | | criticalService | string | `"false"` | Valid options are "true" or "false". If invalid option is set- the value will default to "false". | | debug | bool | `false` | | -| env | list | `[{"name":"GEN3_DEBUG","value":"false"},{"name":"ARBORIST_URL","valueFrom":{"configMapKeyRef":{"key":"arborist_url","name":"manifest-global","optional":true}}}]` | Environment variables to pass to the container | +| env | list | `[{"name":"GEN3_DEBUG","value":"false"},{"name":"ARBORIST_URL","valueFrom":{"configMapKeyRef":{"key":"arborist_url","name":"manifest-global","optional":true}}},{"name":"PGPOOL_MIN_SIZE","value":"1"},{"name":"PGPOOL_MAX_SIZE","value":"5"},{"name":"GUNICORN_WORKERS","value":"2"}]` | Environment variables to pass to the container | | externalSecrets | map | `{"createK8sGen3EmbeddingsSecret":false,"dbcreds":null,"gen3EmbeddingsG3auto":null,"pushSecret":false}` | External Secrets settings. | | externalSecrets.createK8sGen3EmbeddingsSecret | string | `false` | Will create the Helm "gen3Embeddings-g3auto" secret even if Secrets Manager is enabled. This is helpful if you are wanting to use External Secrets for some, but not all secrets. | | externalSecrets.dbcreds | string | `nil` | Will override the name of the aws secrets manager secret. Default is "Values.global.environment-.Chart.Name-creds" | diff --git a/helm/gen3-embeddings/values.yaml b/helm/gen3-embeddings/values.yaml index 5245f52d9..62fc4a1ca 100644 --- a/helm/gen3-embeddings/values.yaml +++ b/helm/gen3-embeddings/values.yaml @@ -119,6 +119,12 @@ env: name: manifest-global key: arborist_url optional: true + - name: PGPOOL_MIN_SIZE + value: "1" + - name: PGPOOL_MAX_SIZE + value: "5" + - name: GUNICORN_WORKERS + value: "2" # This is to setup the liveness and readiness probes more information can be found here: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/ livenessProbe: httpGet: From 0715e1550f9e5a8c385a1fc0e6a8979d11f96144 Mon Sep 17 00:00:00 2001 From: Edward Malinowski Date: Wed, 22 Jul 2026 09:50:07 -0500 Subject: [PATCH 143/196] Updated chart version --- helm/gen3/Chart.yaml | 2 +- helm/gen3/README.md | 6 +++--- helm/requestor/README.md | 13 +++++++++++-- helm/revproxy/README.md | 2 +- 4 files changed, 16 insertions(+), 7 deletions(-) diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index 01880063f..b9079bca3 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -209,7 +209,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.66 +version: 0.3.70 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index c7ef35bdb..b480e85f5 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,6 +1,6 @@ # gen3 -![Version: 0.3.65](https://img.shields.io/badge/Version-0.3.65-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.3.70](https://img.shields.io/badge/Version-0.3.70-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons @@ -54,8 +54,8 @@ Helm chart to deploy Gen3 Data Commons | file://../orthanc | orthanc | 0.1.17 | | file://../peregrine | peregrine | 0.1.44 | | file://../portal | portal | 0.1.62 | -| file://../requestor | requestor | 0.1.36 | -| file://../revproxy | revproxy | 0.1.64 | +| file://../requestor | requestor | 0.1.37 | +| file://../revproxy | revproxy | 0.1.65 | | file://../sheepdog | sheepdog | 0.1.45 | | file://../sower | sower | 0.1.48 | | file://../ssjdispatcher | ssjdispatcher | 0.1.49 | diff --git a/helm/requestor/README.md b/helm/requestor/README.md index d747042db..5a7be8f8b 100644 --- a/helm/requestor/README.md +++ b/helm/requestor/README.md @@ -1,6 +1,6 @@ # requestor -![Version: 0.1.36](https://img.shields.io/badge/Version-0.1.36-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.37](https://img.shields.io/badge/Version-0.1.37-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Requestor Service @@ -29,9 +29,11 @@ A Helm chart for gen3 Requestor Service | command | list | `["/bin/sh"]` | Command to run for the init container. | | commonLabels | map | `nil` | Will completely override the commonLabels defined in the common chart's _label_setup.tpl | | criticalService | string | `"false"` | Valid options are "true" or "false". If invalid option is set- the value will default to "false". | -| externalSecrets | map | `{"dbcreds":null,"pushSecret":false}` | External Secrets settings. | +| externalSecrets | map | `{"createK8sRequestorSecret":false,"dbcreds":null,"pushSecret":false,"requestorG3auto":null}` | External Secrets settings. | +| externalSecrets.createK8sRequestorSecret | string | `false` | Will create the Helm "requestor-g3auto" secret even if Secrets Manager is enabled. This is helpful if you are wanting to use External Secrets for some, but not all secrets. | | externalSecrets.dbcreds | string | `nil` | Will override the name of the aws secrets manager secret. Default is "Values.global.environment-.Chart.Name-creds" | | externalSecrets.pushSecret | bool | `false` | Whether to create the database and Secrets Manager secrets via PushSecret. | +| externalSecrets.requestorG3auto | string | `nil` | Will override the name of the aws secrets manager secret. Default is "requestor-g3auto" | | global.autoscaling.averageCPUValue | string | `"500m"` | | | global.autoscaling.averageMemoryValue | string | `"500Mi"` | | | global.autoscaling.enabled | bool | `false` | | @@ -99,6 +101,9 @@ A Helm chart for gen3 Requestor Service | release | string | `"production"` | Valid options are "production" or "dev". If invalid option is set- the value will default to "dev". | | releaseLabel | string | `"production"` | | | replicaCount | int | `1` | Number of replicas for the deployment. | +| requestorConfig | map | `{"configYaml":"","enabled":false}` | Requestor runtime configuration. leave enabled=false and provide the secret externally. | +| requestorConfig.configYaml | str | `""` | ontents of requestor config.yaml | +| requestorConfig.enabled | bool | `false` | Create local Kubernetes secret from configYaml | | resources | map | `{"limits":{"memory":"512Mi"},"requests":{"memory":"12Mi"}}` | Resource requests and limits for the containers in the pod | | resources.limits | map | `{"memory":"512Mi"}` | The maximum amount of resources that the container is allowed to use | | resources.limits.memory | string | `"512Mi"` | The maximum amount of memory the container can use | @@ -112,6 +117,10 @@ A Helm chart for gen3 Requestor Service | service | map | `{"port":[{"name":"http","port":80,"protocol":"TCP","targetPort":80}],"targetPort":80,"type":"ClusterIP"}` | Kubernetes service information. | | service.port | int | `[{"name":"http","port":80,"protocol":"TCP","targetPort":80}]` | The port number that the service exposes. | | service.type | string | `"ClusterIP"` | Type of service. Valid values are "ClusterIP", "NodePort", "LoadBalancer", "ExternalName". | +| serviceAccount.annotations | map | `{"eks.amazonaws.com/role-arn":null}` | Annotations to add to the service account. | +| serviceAccount.annotations."eks.amazonaws.com/role-arn" | string | `nil` | The Amazon Resource Name (ARN) of the role to associate with the service account | +| serviceAccount.create | bool | `true` | Specifies whether a service account should be created. | +| serviceAccount.name | string | `"requestor-sa"` | The name of the service account | | strategy | map | `{"rollingUpdate":{"maxSurge":1,"maxUnavailable":0},"type":"RollingUpdate"}` | Rolling update deployment strategy | | strategy.rollingUpdate.maxSurge | int | `1` | Number of additional replicas to add during rollout. | | strategy.rollingUpdate.maxUnavailable | int | `0` | Maximum amount of pods that can be unavailable during the update. | diff --git a/helm/revproxy/README.md b/helm/revproxy/README.md index 0f6e4fbda..0ef2c44f9 100644 --- a/helm/revproxy/README.md +++ b/helm/revproxy/README.md @@ -1,6 +1,6 @@ # revproxy -![Version: 0.1.64](https://img.shields.io/badge/Version-0.1.64-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.65](https://img.shields.io/badge/Version-0.1.65-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 revproxy From 52df1bbc640efbc37f7a8b2176413c80c0f5b22a Mon Sep 17 00:00:00 2001 From: Edward Malinowski Date: Wed, 22 Jul 2026 09:55:41 -0500 Subject: [PATCH 144/196] Updated chart version --- helm/gen3/Chart.yaml | 2 +- helm/gen3/README.md | 2 +- helm/revproxy/Chart.yaml | 2 +- helm/revproxy/README.md | 2 +- 4 files changed, 4 insertions(+), 4 deletions(-) diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index 97aeb5fcd..e669ea378 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -116,7 +116,7 @@ dependencies: repository: "file://../requestor" condition: requestor.enabled - name: revproxy - version: 0.1.66 + version: 0.1.67 repository: "file://../revproxy" condition: revproxy.enabled - name: sheepdog diff --git a/helm/gen3/README.md b/helm/gen3/README.md index b4f8248eb..d5a78b532 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -55,7 +55,7 @@ Helm chart to deploy Gen3 Data Commons | file://../peregrine | peregrine | 0.1.44 | | file://../portal | portal | 0.1.62 | | file://../requestor | requestor | 0.1.37 | -| file://../revproxy | revproxy | 0.1.66 | +| file://../revproxy | revproxy | 0.1.67 | | file://../sheepdog | sheepdog | 0.1.45 | | file://../sower | sower | 0.1.48 | | file://../ssjdispatcher | ssjdispatcher | 0.1.49 | diff --git a/helm/revproxy/Chart.yaml b/helm/revproxy/Chart.yaml index 225f7994c..f4a76178d 100644 --- a/helm/revproxy/Chart.yaml +++ b/helm/revproxy/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.66 +version: 0.1.67 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/revproxy/README.md b/helm/revproxy/README.md index 4c6b897ed..cd9c0fff6 100644 --- a/helm/revproxy/README.md +++ b/helm/revproxy/README.md @@ -1,6 +1,6 @@ # revproxy -![Version: 0.1.66](https://img.shields.io/badge/Version-0.1.66-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.67](https://img.shields.io/badge/Version-0.1.67-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 revproxy From f9154b95d188f1c5f5e86c65840b1744f37cb871 Mon Sep 17 00:00:00 2001 From: Sai Shanmukha Date: Wed, 22 Jul 2026 15:11:54 -0500 Subject: [PATCH 145/196] Add IAM permissions for gen3-workflow --- helm/cluster-level-resources/Chart.yaml | 2 +- helm/cluster-level-resources/README.md | 2 +- .../karpenter-config-resources-workflow.yaml | 2 +- helm/gen3-workflow/Chart.yaml | 2 +- helm/gen3-workflow/README.md | 2 +- helm/gen3-workflow/templates/crossplane.yaml | 51 ++++++++++++++++++- helm/gen3/Chart.yaml | 4 +- helm/gen3/README.md | 4 +- 8 files changed, 58 insertions(+), 11 deletions(-) diff --git a/helm/cluster-level-resources/Chart.yaml b/helm/cluster-level-resources/Chart.yaml index 938343293..c2790ed48 100644 --- a/helm/cluster-level-resources/Chart.yaml +++ b/helm/cluster-level-resources/Chart.yaml @@ -4,6 +4,6 @@ description: An app-of-apps Helm chart that allows for flexible deployment of re type: application -version: 0.6.45 +version: 0.6.46 appVersion: "1.17.0" diff --git a/helm/cluster-level-resources/README.md b/helm/cluster-level-resources/README.md index 42d8af39a..65b732728 100644 --- a/helm/cluster-level-resources/README.md +++ b/helm/cluster-level-resources/README.md @@ -1,6 +1,6 @@ # cluster-level-resources -![Version: 0.6.45](https://img.shields.io/badge/Version-0.6.45-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.17.0](https://img.shields.io/badge/AppVersion-1.17.0-informational?style=flat-square) +![Version: 0.6.46](https://img.shields.io/badge/Version-0.6.46-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.17.0](https://img.shields.io/badge/AppVersion-1.17.0-informational?style=flat-square) An app-of-apps Helm chart that allows for flexible deployment of resources that support Gen3 diff --git a/helm/cluster-level-resources/templates/karpenter-config-resources-workflow.yaml b/helm/cluster-level-resources/templates/karpenter-config-resources-workflow.yaml index 5d57392b5..7e361c80e 100644 --- a/helm/cluster-level-resources/templates/karpenter-config-resources-workflow.yaml +++ b/helm/cluster-level-resources/templates/karpenter-config-resources-workflow.yaml @@ -45,7 +45,7 @@ spec: subnetSelectorTerms: - tags: - karpenter.sh/discovery: {{ index .Values "karpenter-crds" "selectorTag" }} + karpenter.sh/discovery: {{ index .Values "karpenter-crds" "selectorTag" }} tags: Environment: {{ .Values.cluster }} diff --git a/helm/gen3-workflow/Chart.yaml b/helm/gen3-workflow/Chart.yaml index 071088100..96e7423f7 100644 --- a/helm/gen3-workflow/Chart.yaml +++ b/helm/gen3-workflow/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.24 +version: 0.1.25 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3-workflow/README.md b/helm/gen3-workflow/README.md index 0e624fbb3..c389c1d16 100644 --- a/helm/gen3-workflow/README.md +++ b/helm/gen3-workflow/README.md @@ -1,6 +1,6 @@ # gen3-workflow -![Version: 0.1.24](https://img.shields.io/badge/Version-0.1.24-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.25](https://img.shields.io/badge/Version-0.1.25-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for Kubernetes diff --git a/helm/gen3-workflow/templates/crossplane.yaml b/helm/gen3-workflow/templates/crossplane.yaml index 4edc9a438..736c6ac60 100644 --- a/helm/gen3-workflow/templates/crossplane.yaml +++ b/helm/gen3-workflow/templates/crossplane.yaml @@ -66,7 +66,11 @@ spec: "s3:PutEncryptionConfiguration", "s3:GetBucketPolicy", "s3:PutBucketPolicy", - "s3:PutLifecycleConfiguration" + "s3:PutLifecycleConfiguration", + "s3:GetBucketVersioning", + "s3:PutBucketVersioning", + "s3:GetBucketNotification", + "s3:PutBucketNotification" ], "Resource": [ "arn:aws:s3:::gen3wf-*", @@ -119,7 +123,50 @@ spec: "kms:TagResource" ], "Resource": "*" - } + }, + { + "Sid": "AllowPassRoleToS3FilesService", + "Effect": "Allow", + "Action": "iam:PassRole", + "Resource": "arn:aws:iam::{{ .Values.global.crossplane.accountId }}:role/Gen3WorkflowS3FilesPOC", + "Condition": { + "StringEquals": { + "iam:PassedToService": "elasticfilesystem.amazonaws.com" + } + } + }, + { + "Sid": "S3FilesSystemAndMountManagement", + "Effect": "Allow", + "Action": [ + "s3files:CreateFileSystem", + "s3files:GetFileSystem", + "s3files:CreateMountTarget", + "s3files:ListFileSystems", + "s3files:TagResource", + "s3files:ListMountTargets" + ], + "Resource": "*" + }, + { + "Sid": "EC2NetworkDiscoveryAndSecurityControlForS3Files", + "Effect": "Allow", + "Action": [ + "ec2:DescribeSecurityGroups", + "ec2:DescribeSubnets", + "ec2:DescribeTags", + "ec2:CreateSecurityGroup", + "ec2:AuthorizeSecurityGroupIngress", + "ec2:AuthorizeSecurityGroupEgress", + "ec2:CreateNetworkInterface", + "ec2:DeleteNetworkInterface", + "ec2:DescribeNetworkInterfaces", + "ec2:DescribeSubnets", + "ec2:DescribeSecurityGroups", + "ec2:DescribeVpcs" + ], + "Resource": "*" + }, ] } --- diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index dd6e36eea..d3be729d9 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -80,7 +80,7 @@ dependencies: repository: "file://../gen3-user-data-library" condition: gen3-user-data-library.enabled - name: gen3-workflow - version: 0.1.24 + version: 0.1.25 repository: "file://../gen3-workflow" condition: gen3-workflow.enabled - name: guppy @@ -213,7 +213,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.68 +version: 0.3.69 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index 165e8d89c..fd7ea3a69 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,6 +1,6 @@ # gen3 -![Version: 0.3.68](https://img.shields.io/badge/Version-0.3.68-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.3.69](https://img.shields.io/badge/Version-0.3.69-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons @@ -40,7 +40,7 @@ Helm chart to deploy Gen3 Data Commons | file://../gen3-analysis | gen3-analysis | 0.1.14 | | file://../gen3-network-policies | gen3-network-policies | 0.1.4 | | file://../gen3-user-data-library | gen3-user-data-library | 0.1.17 | -| file://../gen3-workflow | gen3-workflow | 0.1.24 | +| file://../gen3-workflow | gen3-workflow | 0.1.25 | | file://../guppy | guppy | 0.1.39 | | file://../hatchery | hatchery | 0.1.71 | | file://../indexd | indexd | 0.1.49 | From 156ddd22794be44bf16e72dcbfeefdedd435bfcd Mon Sep 17 00:00:00 2001 From: Sai Shanmukha Date: Wed, 22 Jul 2026 15:28:21 -0500 Subject: [PATCH 146/196] Revert cluster level changes --- helm/cluster-level-resources/Chart.yaml | 2 +- helm/cluster-level-resources/README.md | 2 +- .../templates/karpenter-config-resources-workflow.yaml | 2 +- 3 files changed, 3 insertions(+), 3 deletions(-) diff --git a/helm/cluster-level-resources/Chart.yaml b/helm/cluster-level-resources/Chart.yaml index c2790ed48..938343293 100644 --- a/helm/cluster-level-resources/Chart.yaml +++ b/helm/cluster-level-resources/Chart.yaml @@ -4,6 +4,6 @@ description: An app-of-apps Helm chart that allows for flexible deployment of re type: application -version: 0.6.46 +version: 0.6.45 appVersion: "1.17.0" diff --git a/helm/cluster-level-resources/README.md b/helm/cluster-level-resources/README.md index 65b732728..42d8af39a 100644 --- a/helm/cluster-level-resources/README.md +++ b/helm/cluster-level-resources/README.md @@ -1,6 +1,6 @@ # cluster-level-resources -![Version: 0.6.46](https://img.shields.io/badge/Version-0.6.46-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.17.0](https://img.shields.io/badge/AppVersion-1.17.0-informational?style=flat-square) +![Version: 0.6.45](https://img.shields.io/badge/Version-0.6.45-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.17.0](https://img.shields.io/badge/AppVersion-1.17.0-informational?style=flat-square) An app-of-apps Helm chart that allows for flexible deployment of resources that support Gen3 diff --git a/helm/cluster-level-resources/templates/karpenter-config-resources-workflow.yaml b/helm/cluster-level-resources/templates/karpenter-config-resources-workflow.yaml index 7e361c80e..5d57392b5 100644 --- a/helm/cluster-level-resources/templates/karpenter-config-resources-workflow.yaml +++ b/helm/cluster-level-resources/templates/karpenter-config-resources-workflow.yaml @@ -45,7 +45,7 @@ spec: subnetSelectorTerms: - tags: - karpenter.sh/discovery: {{ index .Values "karpenter-crds" "selectorTag" }} + karpenter.sh/discovery: {{ index .Values "karpenter-crds" "selectorTag" }} tags: Environment: {{ .Values.cluster }} From 2856d2e786ed56b9f4c8689fdb2a1acae552656c Mon Sep 17 00:00:00 2001 From: Sai Shanmukha Date: Wed, 22 Jul 2026 15:34:34 -0500 Subject: [PATCH 147/196] Update gen3 chart version --- helm/gen3/Chart.yaml | 2 +- helm/gen3/README.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index c6f38443f..19f64c5bd 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -213,7 +213,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.69 +version: 0.3.70 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index 32e84acca..0cc1c3024 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,6 +1,6 @@ # gen3 -![Version: 0.3.69](https://img.shields.io/badge/Version-0.3.69-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.3.70](https://img.shields.io/badge/Version-0.3.70-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons From 408fde01e320588caa131b8fe72bc0abc1ab165f Mon Sep 17 00:00:00 2001 From: Sai Shanmukha Date: Wed, 22 Jul 2026 16:32:47 -0500 Subject: [PATCH 148/196] Add event bridge rules for gen3wf --- helm/gen3-workflow/templates/crossplane.yaml | 86 +++++++++++--------- 1 file changed, 49 insertions(+), 37 deletions(-) diff --git a/helm/gen3-workflow/templates/crossplane.yaml b/helm/gen3-workflow/templates/crossplane.yaml index 736c6ac60..ff89ad223 100644 --- a/helm/gen3-workflow/templates/crossplane.yaml +++ b/helm/gen3-workflow/templates/crossplane.yaml @@ -125,47 +125,59 @@ spec: "Resource": "*" }, { - "Sid": "AllowPassRoleToS3FilesService", - "Effect": "Allow", - "Action": "iam:PassRole", - "Resource": "arn:aws:iam::{{ .Values.global.crossplane.accountId }}:role/Gen3WorkflowS3FilesPOC", - "Condition": { - "StringEquals": { - "iam:PassedToService": "elasticfilesystem.amazonaws.com" - } - } + "Sid": "AllowPassRoleToS3FilesService", + "Effect": "Allow", + "Action": "iam:PassRole", + "Resource": "arn:aws:iam::{{ .Values.global.crossplane.accountId }}:role/Gen3WorkflowS3FilesPOC", + "Condition": { + "StringEquals": { + "iam:PassedToService": "elasticfilesystem.amazonaws.com" + } + } }, { - "Sid": "S3FilesSystemAndMountManagement", - "Effect": "Allow", - "Action": [ - "s3files:CreateFileSystem", - "s3files:GetFileSystem", - "s3files:CreateMountTarget", - "s3files:ListFileSystems", - "s3files:TagResource", - "s3files:ListMountTargets" - ], - "Resource": "*" + "Sid": "S3FilesSystemAndMountManagement", + "Effect": "Allow", + "Action": [ + "s3files:CreateFileSystem", + "s3files:GetFileSystem", + "s3files:CreateMountTarget", + "s3files:ListFileSystems", + "s3files:TagResource", + "s3files:ListMountTargets" + ], + "Resource": "*" }, { - "Sid": "EC2NetworkDiscoveryAndSecurityControlForS3Files", - "Effect": "Allow", - "Action": [ - "ec2:DescribeSecurityGroups", - "ec2:DescribeSubnets", - "ec2:DescribeTags", - "ec2:CreateSecurityGroup", - "ec2:AuthorizeSecurityGroupIngress", - "ec2:AuthorizeSecurityGroupEgress", - "ec2:CreateNetworkInterface", - "ec2:DeleteNetworkInterface", - "ec2:DescribeNetworkInterfaces", - "ec2:DescribeSubnets", - "ec2:DescribeSecurityGroups", - "ec2:DescribeVpcs" - ], - "Resource": "*" + "Sid": "EC2NetworkDiscoveryAndSecurityControlForS3Files", + "Effect": "Allow", + "Action": [ + "ec2:DescribeSecurityGroups", + "ec2:DescribeSubnets", + "ec2:DescribeTags", + "ec2:CreateSecurityGroup", + "ec2:AuthorizeSecurityGroupIngress", + "ec2:AuthorizeSecurityGroupEgress", + "ec2:CreateNetworkInterface", + "ec2:DeleteNetworkInterface", + "ec2:DescribeNetworkInterfaces", + "ec2:DescribeSubnets", + "ec2:DescribeSecurityGroups", + "ec2:DescribeVpcs" + ], + "Resource": "*" + }, + { + "Sid": "AddEventBridgeRulesForS3Files", + "Effect": "Allow", + "Action": [ + "events:ListRules", + "events:PutRule", + "events:PutTargets", + "events:DescribeRule", + "events:ListTargetsByRule" + ], + "Resource": "arn:aws:events:*:{{ .Values.global.crossplane.accountId }}:rule/*" }, ] } From ec1c87e6612937f87dee38a6c7212100bdba2128 Mon Sep 17 00:00:00 2001 From: Jawad Date: Wed, 22 Jul 2026 17:13:33 -0500 Subject: [PATCH 149/196] feat(revproxy): add customNginxConfigs to extraServices for per-service nginx directives Allow extraServices entries to inject custom nginx directives into the generated location block before proxy_pass. Useful for SSE settings (proxy_buffering, proxy_read_timeout), caching overrides, etc. Auto-indents user content to match location block nesting. --- helm/gen3/Chart.yaml | 4 ++-- helm/gen3/README.md | 4 ++-- helm/revproxy/Chart.yaml | 2 +- helm/revproxy/README.md | 2 +- helm/revproxy/templates/configMaps.yaml | 3 +++ helm/revproxy/values.yaml | 5 +++++ 6 files changed, 14 insertions(+), 6 deletions(-) diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index 14502aaf2..8138649c6 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -116,7 +116,7 @@ dependencies: repository: "file://../requestor" condition: requestor.enabled - name: revproxy - version: 0.1.66 + version: 0.1.67 repository: "file://../revproxy" condition: revproxy.enabled - name: sheepdog @@ -213,7 +213,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.69 +version: 0.3.70 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index 909b663e0..a29a7816e 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,6 +1,6 @@ # gen3 -![Version: 0.3.69](https://img.shields.io/badge/Version-0.3.69-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.3.70](https://img.shields.io/badge/Version-0.3.70-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons @@ -55,7 +55,7 @@ Helm chart to deploy Gen3 Data Commons | file://../peregrine | peregrine | 0.1.44 | | file://../portal | portal | 0.1.62 | | file://../requestor | requestor | 0.1.36 | -| file://../revproxy | revproxy | 0.1.66 | +| file://../revproxy | revproxy | 0.1.67 | | file://../sheepdog | sheepdog | 0.1.45 | | file://../sower | sower | 0.1.48 | | file://../ssjdispatcher | ssjdispatcher | 0.1.49 | diff --git a/helm/revproxy/Chart.yaml b/helm/revproxy/Chart.yaml index 225f7994c..f4a76178d 100644 --- a/helm/revproxy/Chart.yaml +++ b/helm/revproxy/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.66 +version: 0.1.67 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/revproxy/README.md b/helm/revproxy/README.md index 4c6b897ed..cd9c0fff6 100644 --- a/helm/revproxy/README.md +++ b/helm/revproxy/README.md @@ -1,6 +1,6 @@ # revproxy -![Version: 0.1.66](https://img.shields.io/badge/Version-0.1.66-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.67](https://img.shields.io/badge/Version-0.1.67-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 revproxy diff --git a/helm/revproxy/templates/configMaps.yaml b/helm/revproxy/templates/configMaps.yaml index 39757c7af..3fcecd8cb 100644 --- a/helm/revproxy/templates/configMaps.yaml +++ b/helm/revproxy/templates/configMaps.yaml @@ -48,6 +48,9 @@ data: set $proxy_service "{{ .name }}"; set $upstream http://{{ .serviceName }}$des_domain; + {{- if .customNginxConfigs }} +{{ "\n " }}{{- .customNginxConfigs | trim | replace "\n" "\n " }} +{{- end }} rewrite ^{{ .path }}/(.*) /$1 break; proxy_pass $upstream; proxy_redirect http://$host/ https://$host{{ .path }}/; diff --git a/helm/revproxy/values.yaml b/helm/revproxy/values.yaml index fd9b343a7..b490970c2 100644 --- a/helm/revproxy/values.yaml +++ b/helm/revproxy/values.yaml @@ -270,6 +270,11 @@ extraServices: # authzPolicy: "protein-paint" # authzService: "protein-paint" # csrfCheck: true +# customNginxConfigs: | +# proxy_buffering off; +# proxy_cache off; +# proxy_read_timeout 1h; +# proxy_send_timeout 1h; # -- (map) Raw nginx location blocks to add or override entries in the revproxy-nginx-subconf ConfigMap. # Keys are the conf filename (e.g. "guppy-service.conf"). A key matching a built-in static conf file From 863665ff69702c113894a7abb5f1e4ba7b081964 Mon Sep 17 00:00:00 2001 From: Sai Shanmukha Date: Wed, 22 Jul 2026 22:35:01 -0500 Subject: [PATCH 150/196] Add storageType config variable and DeleteObjectVersion permission --- helm/gen3-workflow/README.md | 1 + helm/gen3-workflow/templates/crossplane.yaml | 3 ++- helm/gen3-workflow/templates/secrets.yaml | 1 + helm/gen3-workflow/values.yaml | 2 ++ 4 files changed, 6 insertions(+), 1 deletion(-) diff --git a/helm/gen3-workflow/README.md b/helm/gen3-workflow/README.md index c389c1d16..40db7bfe2 100644 --- a/helm/gen3-workflow/README.md +++ b/helm/gen3-workflow/README.md @@ -55,6 +55,7 @@ A Helm chart for Kubernetes | gen3WorkflowConfig.s3ObjectsExpirationDays | int | `30` | Number of days after which workflow-generated S3 objects are deleted. | | gen3WorkflowConfig.s3SecretAccessKey | string | `""` | AWS Secret Access Key used to make S3 requests on behalf of users. Leave empty to use credentials from an existing STS session. | | gen3WorkflowConfig.s3UpstreamEndpoint | string | `""` | Connect to another S3-compatible service than AWS S3 (default: AWS S3) | +| gen3WorkflowConfig.storageType | string | `"EBS"` | Could be one of EBS (default) or S3Files | | gen3WorkflowConfig.taskImageWhitelist | list | `[]` | Whitelist of container image patterns allowed for workflow tasks. Supports wildcards `*` and `{username}` placeholders. | | gen3WorkflowConfig.tesServerUrl | string | `"http://funnel:8000"` | TES server URL to which workflow tasks are forwarded. | | gen3WorkflowConfig.userBucketsRegion | string | `"us-east-1"` | AWS region used for creating user S3 buckets. | diff --git a/helm/gen3-workflow/templates/crossplane.yaml b/helm/gen3-workflow/templates/crossplane.yaml index ff89ad223..a99dff0ca 100644 --- a/helm/gen3-workflow/templates/crossplane.yaml +++ b/helm/gen3-workflow/templates/crossplane.yaml @@ -69,6 +69,7 @@ spec: "s3:PutLifecycleConfiguration", "s3:GetBucketVersioning", "s3:PutBucketVersioning", + "s3:"DeleteObjectVersion", "s3:GetBucketNotification", "s3:PutBucketNotification" ], @@ -128,7 +129,7 @@ spec: "Sid": "AllowPassRoleToS3FilesService", "Effect": "Allow", "Action": "iam:PassRole", - "Resource": "arn:aws:iam::{{ .Values.global.crossplane.accountId }}:role/Gen3WorkflowS3FilesPOC", + "Resource": "arn:aws:iam::{{ .Values.global.crossplane.accountId }}:role/gen3wf-*-s3files-role", "Condition": { "StringEquals": { "iam:PassedToService": "elasticfilesystem.amazonaws.com" diff --git a/helm/gen3-workflow/templates/secrets.yaml b/helm/gen3-workflow/templates/secrets.yaml index dba07eb98..9c2fb56ff 100644 --- a/helm/gen3-workflow/templates/secrets.yaml +++ b/helm/gen3-workflow/templates/secrets.yaml @@ -28,6 +28,7 @@ stringData: S3_ENDPOINTS_AWS_ACCESS_KEY_ID: {{ .Values.gen3WorkflowConfig.s3AccessKeyId }} #NOTE: This is not used when using IRSA S3_ENDPOINTS_AWS_SECRET_ACCESS_KEY: {{ .Values.gen3WorkflowConfig.s3SecretAccessKey }} #NOTE: This is not used when using IRSA KMS_ENCRYPTION_ENABLED: {{ .Values.gen3WorkflowConfig.kmsEncryptionEnabled }} + STORAGE_TYPE: {{ .Values.gen3WorkflowConfig.storageType }} ############# # GA4GH TES # diff --git a/helm/gen3-workflow/values.yaml b/helm/gen3-workflow/values.yaml index 79fe81c6b..22e38d08c 100644 --- a/helm/gen3-workflow/values.yaml +++ b/helm/gen3-workflow/values.yaml @@ -314,6 +314,8 @@ gen3WorkflowConfig: s3SecretAccessKey: "" # -- (bool) Enables KMS encryption for S3 uploads. kmsEncryptionEnabled: true + # -- (string) Could be one of EBS (default) or S3Files + storageType: EBS # -- (string) TES server URL to which workflow tasks are forwarded. tesServerUrl: http://funnel:8000 # -- (list) Whitelist of container image patterns allowed for workflow tasks. From d414bb8249af13e8521ef817a942c94bf3ba93bc Mon Sep 17 00:00:00 2001 From: Sai Shanmukha Date: Wed, 22 Jul 2026 22:43:15 -0500 Subject: [PATCH 151/196] Update config variable --- helm/gen3-workflow/README.md | 2 +- helm/gen3-workflow/templates/secrets.yaml | 2 +- helm/gen3-workflow/values.yaml | 4 ++-- 3 files changed, 4 insertions(+), 4 deletions(-) diff --git a/helm/gen3-workflow/README.md b/helm/gen3-workflow/README.md index 40db7bfe2..ad9643300 100644 --- a/helm/gen3-workflow/README.md +++ b/helm/gen3-workflow/README.md @@ -44,6 +44,7 @@ A Helm chart for Kubernetes | gen3WorkflowConfig.debug | bool | `false` | Enables debug mode for the application. | | gen3WorkflowConfig.enableOptimizedNodeScheduling | bool | `true` | When enabled, jobs are configured to run on specific nodes through Kubernetes NodeSelector and Tolerations. Disable this if using a cluster that does not support nodepools. | | gen3WorkflowConfig.enablePrometheusMetrics | bool | `false` | Enables Prometheus metrics for the workflow service. | +| gen3WorkflowConfig.enableS3Files | bool | `false` | Set it to true to create S3Files resources (default - false) | | gen3WorkflowConfig.hostname | string | `""` | Override hostname where the workflow service runs. If empty, gen3-workflow falls back to values.global.hostname | | gen3WorkflowConfig.httpxDebug | bool | `false` | Enables verbose logging specifically for httpx requests. | | gen3WorkflowConfig.kmsEncryptionEnabled | bool | `true` | Enables KMS encryption for S3 uploads. | @@ -55,7 +56,6 @@ A Helm chart for Kubernetes | gen3WorkflowConfig.s3ObjectsExpirationDays | int | `30` | Number of days after which workflow-generated S3 objects are deleted. | | gen3WorkflowConfig.s3SecretAccessKey | string | `""` | AWS Secret Access Key used to make S3 requests on behalf of users. Leave empty to use credentials from an existing STS session. | | gen3WorkflowConfig.s3UpstreamEndpoint | string | `""` | Connect to another S3-compatible service than AWS S3 (default: AWS S3) | -| gen3WorkflowConfig.storageType | string | `"EBS"` | Could be one of EBS (default) or S3Files | | gen3WorkflowConfig.taskImageWhitelist | list | `[]` | Whitelist of container image patterns allowed for workflow tasks. Supports wildcards `*` and `{username}` placeholders. | | gen3WorkflowConfig.tesServerUrl | string | `"http://funnel:8000"` | TES server URL to which workflow tasks are forwarded. | | gen3WorkflowConfig.userBucketsRegion | string | `"us-east-1"` | AWS region used for creating user S3 buckets. | diff --git a/helm/gen3-workflow/templates/secrets.yaml b/helm/gen3-workflow/templates/secrets.yaml index 9c2fb56ff..41aeb2433 100644 --- a/helm/gen3-workflow/templates/secrets.yaml +++ b/helm/gen3-workflow/templates/secrets.yaml @@ -28,7 +28,7 @@ stringData: S3_ENDPOINTS_AWS_ACCESS_KEY_ID: {{ .Values.gen3WorkflowConfig.s3AccessKeyId }} #NOTE: This is not used when using IRSA S3_ENDPOINTS_AWS_SECRET_ACCESS_KEY: {{ .Values.gen3WorkflowConfig.s3SecretAccessKey }} #NOTE: This is not used when using IRSA KMS_ENCRYPTION_ENABLED: {{ .Values.gen3WorkflowConfig.kmsEncryptionEnabled }} - STORAGE_TYPE: {{ .Values.gen3WorkflowConfig.storageType }} + ENABLE_S3_FILES: {{ .Values.gen3WorkflowConfig.enableS3Files }} ############# # GA4GH TES # diff --git a/helm/gen3-workflow/values.yaml b/helm/gen3-workflow/values.yaml index 22e38d08c..a7c7676d5 100644 --- a/helm/gen3-workflow/values.yaml +++ b/helm/gen3-workflow/values.yaml @@ -314,8 +314,8 @@ gen3WorkflowConfig: s3SecretAccessKey: "" # -- (bool) Enables KMS encryption for S3 uploads. kmsEncryptionEnabled: true - # -- (string) Could be one of EBS (default) or S3Files - storageType: EBS + # -- (bool) Set it to true to create S3Files resources (default - false) + enableS3Files: false # -- (string) TES server URL to which workflow tasks are forwarded. tesServerUrl: http://funnel:8000 # -- (list) Whitelist of container image patterns allowed for workflow tasks. From 96ce177bc7ab055166be628a229b8e6a14338b03 Mon Sep 17 00:00:00 2001 From: Ajo Augustine Date: Thu, 23 Jul 2026 10:56:47 -0500 Subject: [PATCH 152/196] fix root context --- helm/cohort-middleware/Chart.yaml | 2 +- helm/cohort-middleware/README.md | 2 +- helm/cohort-middleware/templates/deployment.yaml | 4 ++-- helm/etl/Chart.yaml | 2 +- helm/etl/README.md | 2 +- helm/etl/templates/etl-job.yaml | 6 +++--- helm/gen3/Chart.yaml | 6 +++--- helm/gen3/README.md | 6 +++--- 8 files changed, 15 insertions(+), 15 deletions(-) diff --git a/helm/cohort-middleware/Chart.yaml b/helm/cohort-middleware/Chart.yaml index 173211886..250941f1c 100644 --- a/helm/cohort-middleware/Chart.yaml +++ b/helm/cohort-middleware/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.24 +version: 0.1.25 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/cohort-middleware/README.md b/helm/cohort-middleware/README.md index 6e6286b5d..4e7c9abd1 100644 --- a/helm/cohort-middleware/README.md +++ b/helm/cohort-middleware/README.md @@ -1,6 +1,6 @@ # cohort-middleware -![Version: 0.1.24](https://img.shields.io/badge/Version-0.1.24-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.25](https://img.shields.io/badge/Version-0.1.25-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 cohort-middleware diff --git a/helm/cohort-middleware/templates/deployment.yaml b/helm/cohort-middleware/templates/deployment.yaml index 9c76d647d..1ec4451c3 100644 --- a/helm/cohort-middleware/templates/deployment.yaml +++ b/helm/cohort-middleware/templates/deployment.yaml @@ -15,11 +15,11 @@ spec: {{- include "cohort-middleware.selectorLabels" . | nindent 6 }} template: metadata: - {{- with .Values.podAnnotations }} annotations: checksum/config: {{ include (print $.Template.BasePath "/secrets.yaml") . | sha256sum }} + {{- with .Values.podAnnotations }} {{- toYaml . | nindent 8 }} - {{- end }} + {{- end }} labels: dbohdsi: "yes" dbomop-data: "yes" diff --git a/helm/etl/Chart.yaml b/helm/etl/Chart.yaml index d35774eaa..6785caabc 100644 --- a/helm/etl/Chart.yaml +++ b/helm/etl/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.23 +version: 0.1.24 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/etl/README.md b/helm/etl/README.md index 832f1a91e..6fd84ce6e 100644 --- a/helm/etl/README.md +++ b/helm/etl/README.md @@ -1,6 +1,6 @@ # etl -![Version: 0.1.23](https://img.shields.io/badge/Version-0.1.23-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.24](https://img.shields.io/badge/Version-0.1.24-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 etl diff --git a/helm/etl/templates/etl-job.yaml b/helm/etl/templates/etl-job.yaml index 685ee8361..f5b4a2e26 100644 --- a/helm/etl/templates/etl-job.yaml +++ b/helm/etl/templates/etl-job.yaml @@ -10,11 +10,11 @@ spec: backoffLimit: 0 template: metadata: - {{- with .Values.podAnnotations }} annotations: - {{- toYaml . | nindent 12 }} checksum/config: {{ include (print $.Template.BasePath "/etl-mapping.yaml") . | sha256sum }} - {{- end }} + {{- with .Values.podAnnotations }} + {{- toYaml . | nindent 12 }} + {{- end }} labels: app: gen3job spec: diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index 14502aaf2..b32bee897 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -37,7 +37,7 @@ dependencies: repository: "file://../cedar" condition: cedar.enabled - name: cohort-middleware - version: 0.1.24 + version: 0.1.25 repository: "file://../cohort-middleware" condition: cohort-middleware.enabled - name: common @@ -60,7 +60,7 @@ dependencies: repository: file://../embedding-management-service condition: embedding-management-service.enabled - name: etl - version: 0.1.23 + version: 0.1.24 repository: file://../etl condition: etl.enabled - name: frontend-framework @@ -213,7 +213,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.69 +version: 0.3.70 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index 909b663e0..d639f452d 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,6 +1,6 @@ # gen3 -![Version: 0.3.69](https://img.shields.io/badge/Version-0.3.69-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.3.70](https://img.shields.io/badge/Version-0.3.70-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons @@ -26,14 +26,14 @@ Helm chart to deploy Gen3 Data Commons | file://../aws-es-proxy | aws-es-proxy | 0.1.43 | | file://../aws-sigv4-proxy | aws-sigv4-proxy | 0.1.4 | | file://../cedar | cedar | 0.1.28 | -| file://../cohort-middleware | cohort-middleware | 0.1.24 | +| file://../cohort-middleware | cohort-middleware | 0.1.25 | | file://../common | common | 0.1.38 | | file://../dashboard | dashboard | 0.1.23 | | file://../data-upload-cron | data-upload-cron | 0.1.8 | | file://../datareplicate | datareplicate | 0.1.23 | | file://../dicom-server | dicom-server | 0.1.33 | | file://../embedding-management-service | embedding-management-service | 0.1.10 | -| file://../etl | etl | 0.1.23 | +| file://../etl | etl | 0.1.24 | | file://../fence | fence | 0.1.80 | | file://../frontend-framework | frontend-framework | 0.1.31 | | file://../funnel | funnel | 0.1.28 | From 9f3b9cca9d1b69414619dbe4ba3cce6f7da5a341 Mon Sep 17 00:00:00 2001 From: Ajo Augustine Date: Thu, 23 Jul 2026 12:17:18 -0500 Subject: [PATCH 153/196] Add security context where it was missing --- helm/argo-wrapper/Chart.yaml | 2 +- helm/argo-wrapper/README.md | 3 ++- helm/argo-wrapper/templates/deployment.yaml | 2 ++ helm/argo-wrapper/values.yaml | 10 +++++++++ helm/audit/Chart.yaml | 2 +- helm/audit/README.md | 2 +- helm/audit/templates/deployment.yaml | 4 ++++ helm/aws-es-proxy/Chart.yaml | 2 +- helm/aws-es-proxy/README.md | 3 ++- helm/aws-es-proxy/templates/deployment.yaml | 2 ++ helm/aws-es-proxy/values.yaml | 10 +++++++++ helm/fence/Chart.yaml | 2 +- helm/fence/README.md | 2 +- helm/fence/templates/fence-deployment.yaml | 4 ++++ helm/gen3/Chart.yaml | 22 +++++++++---------- helm/gen3/README.md | 22 +++++++++---------- helm/guppy/Chart.yaml | 2 +- helm/guppy/README.md | 3 ++- helm/guppy/templates/deployment.yaml | 2 ++ helm/guppy/values.yaml | 10 +++++++++ helm/hatchery/Chart.yaml | 2 +- helm/hatchery/README.md | 3 ++- helm/hatchery/values.yaml | 10 +++++++++ helm/manifestservice/Chart.yaml | 2 +- helm/manifestservice/README.md | 3 ++- .../manifestservice/templates/deployment.yaml | 2 ++ helm/manifestservice/values.yaml | 10 +++++++++ helm/metadata/Chart.yaml | 2 +- helm/metadata/README.md | 3 ++- helm/metadata/templates/deployment.yaml | 4 ++++ helm/metadata/values.yaml | 10 +++++++++ helm/sheepdog/Chart.yaml | 2 +- helm/sheepdog/README.md | 2 +- helm/sheepdog/templates/deployment.yaml | 4 ++++ helm/wts/Chart.yaml | 2 +- helm/wts/README.md | 2 +- helm/wts/templates/deployment.yaml | 4 ++++ 37 files changed, 136 insertions(+), 42 deletions(-) diff --git a/helm/argo-wrapper/Chart.yaml b/helm/argo-wrapper/Chart.yaml index 45fc36aef..f92e708d4 100644 --- a/helm/argo-wrapper/Chart.yaml +++ b/helm/argo-wrapper/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.32 +version: 0.1.33 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/argo-wrapper/README.md b/helm/argo-wrapper/README.md index 8012e78eb..82d62a70b 100644 --- a/helm/argo-wrapper/README.md +++ b/helm/argo-wrapper/README.md @@ -1,6 +1,6 @@ # argo-wrapper -![Version: 0.1.32](https://img.shields.io/badge/Version-0.1.32-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.33](https://img.shields.io/badge/Version-0.1.33-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Argo Wrapper Service @@ -61,6 +61,7 @@ A Helm chart for gen3 Argo Wrapper Service | revisionHistoryLimit | int | `2` | Number of old revisions to retain | | s3Bucket | string | `"argo-artifact-downloadable"` | S3 bucket name for Argo artifacts (allows pre-signed URLs). | | scalingGroups | list | `[{"user1":"workflow1"},{"user2":"workflow2"},{"user3":"workflow3"}]` | The workflow scaling groups to be used by Argo. | +| securityContext | map | `{}` | Security context for the containers in the pod | | selectorLabels | map | `nil` | Will completely override the selectorLabels defined in the common chart's _label_setup.tpl | | service | map | `{"port":8000,"targetPort":8000,"type":"ClusterIP"}` | Kubernetes service information. | | service.port | int | `8000` | The port number that the service exposes. | diff --git a/helm/argo-wrapper/templates/deployment.yaml b/helm/argo-wrapper/templates/deployment.yaml index 44ffdc0be..ab8c70233 100644 --- a/helm/argo-wrapper/templates/deployment.yaml +++ b/helm/argo-wrapper/templates/deployment.yaml @@ -55,6 +55,8 @@ spec: {{- end }} containers: - name: {{ .Chart.Name }} + securityContext: + {{- toYaml .Values.securityContext | nindent 12 }} image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}" livenessProbe: httpGet: diff --git a/helm/argo-wrapper/values.yaml b/helm/argo-wrapper/values.yaml index 95e7aae18..8837da919 100644 --- a/helm/argo-wrapper/values.yaml +++ b/helm/argo-wrapper/values.yaml @@ -111,6 +111,16 @@ resources: # -- (string) The maximum amount of memory the container can use memory: 128Mi +# -- (map) Security context for the containers in the pod +securityContext: + {} + # capabilities: + # drop: + # - ALL + # readOnlyRootFilesystem: true + # runAsNonRoot: true + # runAsUser: 1000 + # -- (map) Kubernetes service information. service: # -- (string) Type of service. Valid values are "ClusterIP", "NodePort", "LoadBalancer", "ExternalName". diff --git a/helm/audit/Chart.yaml b/helm/audit/Chart.yaml index 8012a157d..7630c13f1 100644 --- a/helm/audit/Chart.yaml +++ b/helm/audit/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.45 +version: 0.1.46 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/audit/README.md b/helm/audit/README.md index 99780afdf..d0fc1786f 100644 --- a/helm/audit/README.md +++ b/helm/audit/README.md @@ -1,6 +1,6 @@ # audit -![Version: 0.1.45](https://img.shields.io/badge/Version-0.1.45-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.46](https://img.shields.io/badge/Version-0.1.46-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for Kubernetes diff --git a/helm/audit/templates/deployment.yaml b/helm/audit/templates/deployment.yaml index d8b335841..cd85eaa6f 100644 --- a/helm/audit/templates/deployment.yaml +++ b/helm/audit/templates/deployment.yaml @@ -49,6 +49,8 @@ spec: {{- end }} containers: - name: audit + securityContext: + {{- toYaml .Values.securityContext | nindent 12 }} image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}" imagePullPolicy: {{ .Values.image.pullPolicy }} ports: @@ -115,6 +117,8 @@ spec: {{- end }} initContainers: - name: audit-init + securityContext: + {{- toYaml .Values.securityContext | nindent 12 }} image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}" imagePullPolicy: {{ .Values.image.pullPolicy }} env: diff --git a/helm/aws-es-proxy/Chart.yaml b/helm/aws-es-proxy/Chart.yaml index a74b9e9d0..09bc48ac0 100644 --- a/helm/aws-es-proxy/Chart.yaml +++ b/helm/aws-es-proxy/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.43 +version: 0.1.44 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/aws-es-proxy/README.md b/helm/aws-es-proxy/README.md index 7e9eb06fe..eb7f1c4b6 100644 --- a/helm/aws-es-proxy/README.md +++ b/helm/aws-es-proxy/README.md @@ -1,6 +1,6 @@ # aws-es-proxy -![Version: 0.1.43](https://img.shields.io/badge/Version-0.1.43-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.44](https://img.shields.io/badge/Version-0.1.44-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for AWS ES Proxy Service for gen3 @@ -69,6 +69,7 @@ A Helm chart for AWS ES Proxy Service for gen3 | secrets | map | `{"awsAccessKeyId":null,"awsSecretAccessKey":null}` | Secret information to access AWS ES cluster. | | secrets.awsAccessKeyId | str | `nil` | AWS access key ID. Overrides global key. | | secrets.awsSecretAccessKey | str | `nil` | AWS secret access key ID. Overrides global key. | +| securityContext | map | `{}` | Security context for the containers in the pod | | selectorLabels | map | `nil` | Will completely override the selectorLabels defined in the common chart's _label_setup.tpl | | service | map | `{"port":9200,"type":"ClusterIP"}` | Kubernetes service information. | | service.port | int | `9200` | The port number that the service exposes. | diff --git a/helm/aws-es-proxy/templates/deployment.yaml b/helm/aws-es-proxy/templates/deployment.yaml index 22af7d97b..a21dd8c34 100644 --- a/helm/aws-es-proxy/templates/deployment.yaml +++ b/helm/aws-es-proxy/templates/deployment.yaml @@ -43,6 +43,8 @@ spec: optional: true containers: - name: "esproxy" + securityContext: + {{- toYaml .Values.securityContext | nindent 12 }} image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}" imagePullPolicy: {{ .Values.image.pullPolicy }} {{- with .Values.ports}} diff --git a/helm/aws-es-proxy/values.yaml b/helm/aws-es-proxy/values.yaml index 7a96c025c..fb8bf58d2 100644 --- a/helm/aws-es-proxy/values.yaml +++ b/helm/aws-es-proxy/values.yaml @@ -131,6 +131,16 @@ resources: # -- (string) The maximum amount of memory the container can use memory: 2Gi +# -- (map) Security context for the containers in the pod +securityContext: + {} + # capabilities: + # drop: + # - ALL + # readOnlyRootFilesystem: true + # runAsNonRoot: true + # runAsUser: 1000 + # -- (map) Kubernetes service information. service: # -- (string) Type of service. Valid values are "ClusterIP", "NodePort", "LoadBalancer", "ExternalName". diff --git a/helm/fence/Chart.yaml b/helm/fence/Chart.yaml index 72889afce..29e19a6af 100644 --- a/helm/fence/Chart.yaml +++ b/helm/fence/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.80 +version: 0.1.81 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/fence/README.md b/helm/fence/README.md index 97e6d01de..2a16c0c1f 100644 --- a/helm/fence/README.md +++ b/helm/fence/README.md @@ -1,6 +1,6 @@ # fence -![Version: 0.1.80](https://img.shields.io/badge/Version-0.1.80-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.81](https://img.shields.io/badge/Version-0.1.81-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Fence diff --git a/helm/fence/templates/fence-deployment.yaml b/helm/fence/templates/fence-deployment.yaml index e4113ee3f..4af4c0428 100644 --- a/helm/fence/templates/fence-deployment.yaml +++ b/helm/fence/templates/fence-deployment.yaml @@ -48,6 +48,8 @@ spec: {{- toYaml .Values.volumes | nindent 8 }} containers: - name: fence + securityContext: + {{- toYaml .Values.securityContext | nindent 12 }} image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}" imagePullPolicy: {{ .Values.image.pullPolicy }} ports: @@ -90,6 +92,8 @@ spec: {{- toYaml .Values.volumeMounts | nindent 12 }} initContainers: - name: fence-init + securityContext: + {{- toYaml .Values.securityContext | nindent 12 }} image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}" imagePullPolicy: {{ .Values.image.pullPolicy }} ports: diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index 8138649c6..de4755032 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -17,15 +17,15 @@ dependencies: repository: "file://../arborist" condition: arborist.enabled - name: argo-wrapper - version: 0.1.32 + version: 0.1.33 repository: "file://../argo-wrapper" condition: argo-wrapper.enabled - name: audit - version: 0.1.45 + version: 0.1.46 repository: "file://../audit" condition: audit.enabled - name: aws-es-proxy - version: 0.1.43 + version: 0.1.44 repository: "file://../aws-es-proxy" condition: aws-es-proxy.enabled - name: aws-sigv4-proxy @@ -68,7 +68,7 @@ dependencies: repository: "file://../frontend-framework" condition: frontend-framework.enabled - name: fence - version: 0.1.80 + version: 0.1.81 repository: "file://../fence" condition: fence.enabled - name: funnel @@ -84,11 +84,11 @@ dependencies: repository: "file://../gen3-workflow" condition: gen3-workflow.enabled - name: guppy - version: 0.1.39 + version: 0.1.40 repository: "file://../guppy" condition: guppy.enabled - name: hatchery - version: 0.1.71 + version: 0.1.72 repository: "file://../hatchery" condition: hatchery.enabled - name: indexd @@ -96,11 +96,11 @@ dependencies: repository: "file://../indexd" condition: indexd.enabled - name: manifestservice - version: 0.1.44 + version: 0.1.45 repository: "file://../manifestservice" condition: manifestservice.enabled - name: metadata - version: 0.1.46 + version: 0.1.47 repository: "file://../metadata" condition: metadata.enabled - name: peregrine @@ -120,7 +120,7 @@ dependencies: repository: "file://../revproxy" condition: revproxy.enabled - name: sheepdog - version: 0.1.45 + version: 0.1.46 repository: "file://../sheepdog" condition: sheepdog.enabled - name: ssjdispatcher @@ -132,7 +132,7 @@ dependencies: condition: sower.enabled repository: "file://../sower" - name: wts - version: 0.1.42 + version: 0.1.43 repository: "file://../wts" condition: wts.enabled - name: zendesk-wrapper @@ -213,7 +213,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.70 +version: 0.3.71 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index a29a7816e..f9262ac78 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,6 +1,6 @@ # gen3 -![Version: 0.3.70](https://img.shields.io/badge/Version-0.3.70-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.3.71](https://img.shields.io/badge/Version-0.3.71-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons @@ -21,9 +21,9 @@ Helm chart to deploy Gen3 Data Commons | file://../access-backend | access-backend | 0.1.22 | | file://../ambassador | ambassador | 0.1.39 | | file://../arborist | arborist | 0.1.36 | -| file://../argo-wrapper | argo-wrapper | 0.1.32 | -| file://../audit | audit | 0.1.45 | -| file://../aws-es-proxy | aws-es-proxy | 0.1.43 | +| file://../argo-wrapper | argo-wrapper | 0.1.33 | +| file://../audit | audit | 0.1.46 | +| file://../aws-es-proxy | aws-es-proxy | 0.1.44 | | file://../aws-sigv4-proxy | aws-sigv4-proxy | 0.1.4 | | file://../cedar | cedar | 0.1.28 | | file://../cohort-middleware | cohort-middleware | 0.1.24 | @@ -34,19 +34,19 @@ Helm chart to deploy Gen3 Data Commons | file://../dicom-server | dicom-server | 0.1.33 | | file://../embedding-management-service | embedding-management-service | 0.1.10 | | file://../etl | etl | 0.1.23 | -| file://../fence | fence | 0.1.80 | +| file://../fence | fence | 0.1.81 | | file://../frontend-framework | frontend-framework | 0.1.31 | | file://../funnel | funnel | 0.1.28 | | file://../gen3-analysis | gen3-analysis | 0.1.14 | | file://../gen3-network-policies | gen3-network-policies | 0.1.4 | | file://../gen3-user-data-library | gen3-user-data-library | 0.1.17 | | file://../gen3-workflow | gen3-workflow | 0.1.24 | -| file://../guppy | guppy | 0.1.39 | -| file://../hatchery | hatchery | 0.1.71 | +| file://../guppy | guppy | 0.1.40 | +| file://../hatchery | hatchery | 0.1.72 | | file://../indexd | indexd | 0.1.49 | | file://../jeg | jeg | 0.1.3 | -| file://../manifestservice | manifestservice | 0.1.44 | -| file://../metadata | metadata | 0.1.46 | +| file://../manifestservice | manifestservice | 0.1.45 | +| file://../metadata | metadata | 0.1.47 | | file://../neuvector | neuvector | 0.1.2 | | file://../ohdsi-atlas | ohdsi-atlas | 0.1.2 | | file://../ohdsi-webapi | ohdsi-webapi | 0.1.7 | @@ -56,12 +56,12 @@ Helm chart to deploy Gen3 Data Commons | file://../portal | portal | 0.1.62 | | file://../requestor | requestor | 0.1.36 | | file://../revproxy | revproxy | 0.1.67 | -| file://../sheepdog | sheepdog | 0.1.45 | +| file://../sheepdog | sheepdog | 0.1.46 | | file://../sower | sower | 0.1.48 | | file://../ssjdispatcher | ssjdispatcher | 0.1.49 | | file://../vectis-overlays | vectis-overlays | 0.1.3 | | file://../workspace-proxy | workspace-proxy | 0.1.3 | -| file://../wts | wts | 0.1.42 | +| file://../wts | wts | 0.1.43 | | file://../zendesk-wrapper | zendesk-wrapper | 0.1.1 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | | https://helm.elastic.co | elasticsearch | 7.10.2 | diff --git a/helm/guppy/Chart.yaml b/helm/guppy/Chart.yaml index 611ee6452..0efebdf1c 100644 --- a/helm/guppy/Chart.yaml +++ b/helm/guppy/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.39 +version: 0.1.40 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/guppy/README.md b/helm/guppy/README.md index 38a7b8c35..33ebe174c 100644 --- a/helm/guppy/README.md +++ b/helm/guppy/README.md @@ -1,6 +1,6 @@ # guppy -![Version: 0.1.39](https://img.shields.io/badge/Version-0.1.39-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.40](https://img.shields.io/badge/Version-0.1.40-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Guppy Service @@ -88,6 +88,7 @@ A Helm chart for gen3 Guppy Service | secrets | map | `{"awsAccessKeyId":null,"awsSecretAccessKey":null}` | Secret information to access the db restore job S3 bucket. | | secrets.awsAccessKeyId | str | `nil` | AWS access key ID. Overrides global key. | | secrets.awsSecretAccessKey | str | `nil` | AWS secret access key ID. Overrides global key. | +| securityContext | map | `{}` | Security context for the containers in the pod | | selectorLabels | map | `nil` | Will completely override the selectorLabels defined in the common chart's _label_setup.tpl | | service | map | `{"port":[{"name":"http","port":80,"protocol":"TCP","targetPort":8000}],"targetPort":8000,"type":"ClusterIP"}` | Kubernetes service information. | | service.port | int | `[{"name":"http","port":80,"protocol":"TCP","targetPort":8000}]` | The port number that the service exposes. | diff --git a/helm/guppy/templates/deployment.yaml b/helm/guppy/templates/deployment.yaml index 8e6f7c0a5..680454931 100644 --- a/helm/guppy/templates/deployment.yaml +++ b/helm/guppy/templates/deployment.yaml @@ -52,6 +52,8 @@ spec: {{- end }} containers: - name: {{ .Chart.Name }} + securityContext: + {{- toYaml .Values.securityContext | nindent 12 }} image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}" livenessProbe: httpGet: diff --git a/helm/guppy/values.yaml b/helm/guppy/values.yaml index 763e93256..45ed2c3a2 100644 --- a/helm/guppy/values.yaml +++ b/helm/guppy/values.yaml @@ -178,6 +178,16 @@ resources: # -- (string) The maximum amount of memory the container can use memory: 2Gi +# -- (map) Security context for the containers in the pod +securityContext: + {} + # capabilities: + # drop: + # - ALL + # readOnlyRootFilesystem: true + # runAsNonRoot: true + # runAsUser: 1000 + # -- (map) Kubernetes service information. service: # -- (string) Type of service. Valid values are "ClusterIP", "NodePort", "LoadBalancer", "ExternalName". diff --git a/helm/hatchery/Chart.yaml b/helm/hatchery/Chart.yaml index 364ebfdf6..bb43e5f59 100644 --- a/helm/hatchery/Chart.yaml +++ b/helm/hatchery/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.71 +version: 0.1.72 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/hatchery/README.md b/helm/hatchery/README.md index a271caa5d..467281767 100644 --- a/helm/hatchery/README.md +++ b/helm/hatchery/README.md @@ -1,6 +1,6 @@ # hatchery -![Version: 0.1.71](https://img.shields.io/badge/Version-0.1.71-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.72](https://img.shields.io/badge/Version-0.1.72-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Hatchery @@ -115,6 +115,7 @@ A Helm chart for gen3 Hatchery | resources.limits.memory | string | `"512Mi"` | The maximum amount of memory the container can use | | resources.requests | map | `{"memory":"12Mi"}` | The amount of resources that the container requests | | resources.requests.memory | string | `"12Mi"` | The amount of memory requested | +| securityContext | map | `{}` | Security context for the containers in the pod | | selectorLabels | map | `nil` | Will completely override the selectorLabels defined in the common chart's _label_setup.tpl | | service | map | `{"port":80,"targetPort":8000,"type":"ClusterIP"}` | Kubernetes service information. | | service.port | int | `80` | The port number that the service exposes. | diff --git a/helm/hatchery/values.yaml b/helm/hatchery/values.yaml index f06e47659..ed2256acb 100644 --- a/helm/hatchery/values.yaml +++ b/helm/hatchery/values.yaml @@ -142,6 +142,16 @@ nameOverride: "" # -- (string) Override the full name of the deployment. fullnameOverride: "" +# -- (map) Security context for the containers in the pod +securityContext: + {} + # capabilities: + # drop: + # - ALL + # readOnlyRootFilesystem: true + # runAsNonRoot: true + # runAsUser: 1000 + # -- (map) Kubernetes service information. service: # -- (string) Type of service. Valid values are "ClusterIP", "NodePort", "LoadBalancer", "ExternalName". diff --git a/helm/manifestservice/Chart.yaml b/helm/manifestservice/Chart.yaml index 839aa16bc..ede1c8f11 100644 --- a/helm/manifestservice/Chart.yaml +++ b/helm/manifestservice/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.44 +version: 0.1.45 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/manifestservice/README.md b/helm/manifestservice/README.md index 7cbc9a1c0..ead44689e 100644 --- a/helm/manifestservice/README.md +++ b/helm/manifestservice/README.md @@ -1,6 +1,6 @@ # manifestservice -![Version: 0.1.44](https://img.shields.io/badge/Version-0.1.44-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.45](https://img.shields.io/badge/Version-0.1.45-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for Kubernetes @@ -83,6 +83,7 @@ A Helm chart for Kubernetes | secrets | map | `{"awsAccessKeyId":null,"awsSecretAccessKey":null}` | Secret information for External Secrets. | | secrets.awsAccessKeyId | str | `nil` | AWS access key ID. Overrides global key. | | secrets.awsSecretAccessKey | str | `nil` | AWS secret access key ID. Overrides global key. | +| securityContext | map | `{}` | Security context for the containers in the pod | | selectorLabels | map | `nil` | Will completely override the selectorLabels defined in the common chart's _label_setup.tpl | | service | map | `{"port":80,"targetPort":80,"type":"ClusterIP"}` | Kubernetes service information. | | service.port | int | `80` | The port number that the service exposes. | diff --git a/helm/manifestservice/templates/deployment.yaml b/helm/manifestservice/templates/deployment.yaml index 75df25d76..6fd27f563 100644 --- a/helm/manifestservice/templates/deployment.yaml +++ b/helm/manifestservice/templates/deployment.yaml @@ -52,6 +52,8 @@ spec: - name: manifestservice image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}" imagePullPolicy: {{ .Values.image.pullPolicy }} + securityContext: + {{- toYaml .Values.securityContext | nindent 12 }} env: {{- toYaml .Values.env | nindent 12 }} {{- if and .Values.manifestserviceG3auto.awsaccesskey .Values.manifestserviceG3auto.awssecretkey }} diff --git a/helm/manifestservice/values.yaml b/helm/manifestservice/values.yaml index 5d0e22a70..5375e29ee 100644 --- a/helm/manifestservice/values.yaml +++ b/helm/manifestservice/values.yaml @@ -103,6 +103,16 @@ image: # -- (string) Overrides the image tag whose default is the chart appVersion. tag: "" +# -- (map) Security context for the containers in the pod +securityContext: + {} + # capabilities: + # drop: + # - ALL + # readOnlyRootFilesystem: true + # runAsNonRoot: true + # runAsUser: 1000 + # -- (map) Kubernetes service information. service: # -- (string) Type of service. Valid values are "ClusterIP", "NodePort", "LoadBalancer", "ExternalName". diff --git a/helm/metadata/Chart.yaml b/helm/metadata/Chart.yaml index b9e069cdc..4a34ab9d4 100644 --- a/helm/metadata/Chart.yaml +++ b/helm/metadata/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.46 +version: 0.1.47 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/metadata/README.md b/helm/metadata/README.md index 11abf0322..f06dd7567 100644 --- a/helm/metadata/README.md +++ b/helm/metadata/README.md @@ -1,6 +1,6 @@ # metadata -![Version: 0.1.46](https://img.shields.io/badge/Version-0.1.46-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.47](https://img.shields.io/badge/Version-0.1.47-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Metadata Service @@ -117,6 +117,7 @@ A Helm chart for gen3 Metadata Service | secrets | map | `{"awsAccessKeyId":null,"awsSecretAccessKey":null}` | Secret information to access the db restore job S3 bucket. | | secrets.awsAccessKeyId | str | `nil` | AWS access key ID. Overrides global key. | | secrets.awsSecretAccessKey | str | `nil` | AWS secret access key ID. Overrides global key. | +| securityContext | map | `{}` | Security context for the containers in the pod | | selectorLabels | map | `nil` | Will completely override the selectorLabels defined in the common chart's _label_setup.tpl | | service | map | `{"port":[{"name":"http","port":80,"protocol":"TCP","targetPort":80}],"targetPort":80,"type":"ClusterIP"}` | Kubernetes service information. | | service.port | int | `[{"name":"http","port":80,"protocol":"TCP","targetPort":80}]` | The port number that the service exposes. | diff --git a/helm/metadata/templates/deployment.yaml b/helm/metadata/templates/deployment.yaml index 3968899c8..94eb88809 100644 --- a/helm/metadata/templates/deployment.yaml +++ b/helm/metadata/templates/deployment.yaml @@ -56,6 +56,8 @@ spec: optional: true containers: - name: {{ .Chart.Name }} + securityContext: + {{- toYaml .Values.securityContext | nindent 12 }} image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}" env: - name: GEN3_DEBUG @@ -127,6 +129,8 @@ spec: {{- end }} initContainers: - name: {{ .Values.initContainerName }} + securityContext: + {{- toYaml .Values.securityContext | nindent 12 }} image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}" imagePullPolicy: {{ .Values.image.pullPolicy }} {{- with .Values.initVolumeMounts }} diff --git a/helm/metadata/values.yaml b/helm/metadata/values.yaml index 9a7159d9a..1f13b5382 100644 --- a/helm/metadata/values.yaml +++ b/helm/metadata/values.yaml @@ -329,6 +329,16 @@ serviceAnnotations: prefix: /index/ service: http://metadata-service:80 +# -- (map) Security context for the containers in the pod +securityContext: + {} + # capabilities: + # drop: + # - ALL + # readOnlyRootFilesystem: true + # runAsNonRoot: true + # runAsUser: 1000 + # -- (map) Kubernetes service information. service: # -- (string) Type of service. Valid values are "ClusterIP", "NodePort", "LoadBalancer", "ExternalName". diff --git a/helm/sheepdog/Chart.yaml b/helm/sheepdog/Chart.yaml index 71a922a2f..947523fcb 100644 --- a/helm/sheepdog/Chart.yaml +++ b/helm/sheepdog/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.45 +version: 0.1.46 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/sheepdog/README.md b/helm/sheepdog/README.md index d0d2ee5c0..8566e7fd1 100644 --- a/helm/sheepdog/README.md +++ b/helm/sheepdog/README.md @@ -1,6 +1,6 @@ # sheepdog -![Version: 0.1.45](https://img.shields.io/badge/Version-0.1.45-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.46](https://img.shields.io/badge/Version-0.1.46-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Sheepdog Service diff --git a/helm/sheepdog/templates/deployment.yaml b/helm/sheepdog/templates/deployment.yaml index 111be725e..e7ed92b63 100644 --- a/helm/sheepdog/templates/deployment.yaml +++ b/helm/sheepdog/templates/deployment.yaml @@ -62,6 +62,8 @@ spec: name: config-helper initContainers: - name: sheepdog-init + securityContext: + {{- toYaml .Values.securityContext | nindent 12 }} image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}" imagePullPolicy: {{ .Values.image.pullPolicy }} env: @@ -121,6 +123,8 @@ spec: fi containers: - name: sheepdog + securityContext: + {{- toYaml .Values.securityContext | nindent 12 }} image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}" imagePullPolicy: {{ .Values.image.pullPolicy }} ports: diff --git a/helm/wts/Chart.yaml b/helm/wts/Chart.yaml index 91349b28f..d1f7554d6 100644 --- a/helm/wts/Chart.yaml +++ b/helm/wts/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.42 +version: 0.1.43 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/wts/README.md b/helm/wts/README.md index 1818784e8..4c52af331 100644 --- a/helm/wts/README.md +++ b/helm/wts/README.md @@ -1,6 +1,6 @@ # wts -![Version: 0.1.42](https://img.shields.io/badge/Version-0.1.42-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.43](https://img.shields.io/badge/Version-0.1.43-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 workspace token service diff --git a/helm/wts/templates/deployment.yaml b/helm/wts/templates/deployment.yaml index 5a4503aa3..6c32c51b9 100644 --- a/helm/wts/templates/deployment.yaml +++ b/helm/wts/templates/deployment.yaml @@ -73,6 +73,8 @@ spec: serviceAccountName: workspace-token-service containers: - name: {{ .Chart.Name }} + securityContext: + {{- toYaml .Values.securityContext | nindent 12 }} image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}" imagePullPolicy: {{ .Values.image.pullPolicy }} volumeMounts: @@ -147,6 +149,8 @@ spec: {{- toYaml .Values.resources | nindent 12 }} initContainers: - name: wts-db-migrate + securityContext: + {{- toYaml .Values.securityContext | nindent 10 }} image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}" imagePullPolicy: {{ .Values.image.pullPolicy }} volumeMounts: From b74d49edac5a64846639502dae112c802d95b2e8 Mon Sep 17 00:00:00 2001 From: Sai Shanmukha Date: Thu, 23 Jul 2026 15:03:24 -0500 Subject: [PATCH 154/196] Bump gen3 chart version --- helm/gen3/Chart.yaml | 2 +- helm/gen3/README.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index 7abab663c..97341dc80 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -213,7 +213,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.70 +version: 0.3.71 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index 011c5ce13..f5785f26f 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,6 +1,6 @@ # gen3 -![Version: 0.3.70](https://img.shields.io/badge/Version-0.3.70-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.3.71](https://img.shields.io/badge/Version-0.3.71-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons From 4f0cabb1ae633ca7d14655d731ebcd14d5df66f4 Mon Sep 17 00:00:00 2001 From: Sai Shanmukha Date: Thu, 23 Jul 2026 15:43:46 -0500 Subject: [PATCH 155/196] gen3 version bump --- helm/gen3/Chart.yaml | 2 +- helm/gen3/README.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index f67b22ec8..40ea75d94 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -213,7 +213,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.71 +version: 0.3.72 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index 2cdce8c9a..7c8a4119f 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,6 +1,6 @@ # gen3 -![Version: 0.3.71](https://img.shields.io/badge/Version-0.3.71-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.3.72](https://img.shields.io/badge/Version-0.3.72-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons From 6a6fba8b1591a2440f4fa34255742ca5fddf1e57 Mon Sep 17 00:00:00 2001 From: Ajo Augustine Date: Thu, 23 Jul 2026 16:32:49 -0500 Subject: [PATCH 156/196] bump charts --- helm/cohort-middleware/README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/helm/cohort-middleware/README.md b/helm/cohort-middleware/README.md index 4e7c9abd1..1080eb990 100644 --- a/helm/cohort-middleware/README.md +++ b/helm/cohort-middleware/README.md @@ -114,3 +114,4 @@ A Helm chart for gen3 cohort-middleware | tolerations | list | `[]` | | | volumeMounts | list | `[]` | | | volumes | string | `nil` | | + From aa7c3e3de21a1bc6a332f74a1cff9b03a45db285 Mon Sep 17 00:00:00 2001 From: Ajo Augustine Date: Thu, 23 Jul 2026 16:34:33 -0500 Subject: [PATCH 157/196] bump charts --- helm/cohort-middleware/templates/deployment.yaml | 1 + 1 file changed, 1 insertion(+) diff --git a/helm/cohort-middleware/templates/deployment.yaml b/helm/cohort-middleware/templates/deployment.yaml index 1ec4451c3..511f4f8a7 100644 --- a/helm/cohort-middleware/templates/deployment.yaml +++ b/helm/cohort-middleware/templates/deployment.yaml @@ -85,3 +85,4 @@ spec: tolerations: {{- toYaml . | nindent 8 }} {{- end }} + From 29eb51fb6c3919b6b3e6efecbb37615e0d7323a9 Mon Sep 17 00:00:00 2001 From: Ajo Augustine Date: Thu, 23 Jul 2026 17:04:07 -0500 Subject: [PATCH 158/196] bump charts --- helm/cohort-middleware/README.md | 1 - helm/gen3/Chart.yaml | 2 +- helm/gen3/README.md | 2 +- 3 files changed, 2 insertions(+), 3 deletions(-) diff --git a/helm/cohort-middleware/README.md b/helm/cohort-middleware/README.md index 1080eb990..4e7c9abd1 100644 --- a/helm/cohort-middleware/README.md +++ b/helm/cohort-middleware/README.md @@ -114,4 +114,3 @@ A Helm chart for gen3 cohort-middleware | tolerations | list | `[]` | | | volumeMounts | list | `[]` | | | volumes | string | `nil` | | - diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index 987aad1d6..adbb3d5ee 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -213,7 +213,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.72 +version: 0.3.73 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index 6fa9db5bb..f756ccf03 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,6 +1,6 @@ # gen3 -![Version: 0.3.72](https://img.shields.io/badge/Version-0.3.72-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.3.73](https://img.shields.io/badge/Version-0.3.73-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons From 0223982a95cb279df82268aad436296cb2b3912f Mon Sep 17 00:00:00 2001 From: Sai Shanmukha Date: Thu, 23 Jul 2026 18:55:00 -0500 Subject: [PATCH 159/196] move `storage` to `Kubernetes.Storage` and remove unused fields + Update worker-pv with right mountOptions --- helm/funnel/README.md | 8 +------ helm/funnel/files/worker-pv.yaml | 36 +++++++++++++++++++------------- helm/funnel/values.yaml | 14 ++++--------- 3 files changed, 26 insertions(+), 32 deletions(-) diff --git a/helm/funnel/README.md b/helm/funnel/README.md index bf9088ee9..51d662f0c 100644 --- a/helm/funnel/README.md +++ b/helm/funnel/README.md @@ -74,6 +74,7 @@ A Helm chart for Kubernetes | Kubernetes.Resources.Limits.DiskGb | string | `"4096Mi"` | | | Kubernetes.Resources.Limits.RamGb | string | `"4096Mi"` | | | Kubernetes.ServiceAccount | string | `""` | | +| Kubernetes.Storage.type | string | `"mountpoint_s3"` | | | Kubernetes.Timeout.duration | string | `"300s"` | | | Kubernetes.Tolerations | list | `[]` | | | Kubernetes.Worker.Annotations."karpenter.sh/do-not-disrupt" | string | `"true"` | | @@ -216,13 +217,6 @@ A Helm chart for Kubernetes | service.httpPort | int | `8000` | | | service.rpcPort | int | `9090` | | | service.type | string | `"ClusterIP"` | | -| storage.accessMode | string | `"ReadWriteMany"` | | -| storage.className | string | `"s3-csi-sc"` | | -| storage.createStorageClass | bool | `true` | | -| storage.driver | string | `"aws-s3"` | | -| storage.provisioner | string | `"s3.csi.aws.com"` | | -| storage.size | string | `"10Mi"` | | -| storage.type | string | `"mountpoint_s3"` | | | stsRegion | string | `"us-east-1"` | | | volumeMounts[0].mountPath | string | `"/etc/config/funnel-server.yaml"` | | | volumeMounts[0].name | string | `"funnel-patched-config-volume"` | | diff --git a/helm/funnel/files/worker-pv.yaml b/helm/funnel/files/worker-pv.yaml index 2241c3f17..d118617bf 100644 --- a/helm/funnel/files/worker-pv.yaml +++ b/helm/funnel/files/worker-pv.yaml @@ -7,37 +7,41 @@ metadata: taskId: {{`{{.TaskId}}`}} namespace: {{`{{.Namespace}}`}} spec: - storageClassName: "" # Required for static provisioning - capacity: # Note: capacity is effectively elastic and only serves as a placeholder - storage: "10Mi" + storageClassName: "" # required for static provisioning accessModes: - ReadWriteMany persistentVolumeReclaimPolicy: Retain + capacity: # placeholder only — capacity is effectively elastic + storage: "10Mi" + mountOptions: - - tls - {{- if eq .Values.storage.type "mountpoint_s3" }} + {{- if eq .Values.Kubernetes.Storage.type "mountpoint_s3" }} - allow-delete - - allow-overwrite # allow overwriting existing files - - incremental-upload # allow appending to existing files - - allow-other # allow non-root users to access the mounted directory + - allow-overwrite # allow overwriting existing files + - incremental-upload # allow appending to existing files + - allow-other # allow non-root users to access the mount - region={{`{{.Region}}`}} - file-mode=0755 - prefix=funnel-temp-files/ - {{- end }} - {{- if eq .Values.storage.type "s3files" }} - - noresvport - {{- end }} {{`{{- if .KmsKeyID}}`}} - sse aws:kms - sse-kms-key-id={{`{{.KmsKeyID}}`}} {{`{{- end}}`}} + {{- end }} + + {{- if eq .Values.Kubernetes.Storage.type "s3files" }} + - tls + - noresvport + {{- end }} + {{- if .Values.endpoint_url }} - endpoint-url={{ .Values.endpoint_url }} + - force-path-style # avoids DNS resolution issue, see: # https://github.com/awslabs/mountpoint-s3/blob/v1.22.2/doc/TROUBLESHOOTING.md#invalid-hostname-for-dns-resolution - - force-path-style {{- end }} + csi: - {{- if eq .Values.storage.type "mountpoint_s3" }} + {{- if eq .Values.Kubernetes.Storage.type "mountpoint_s3" }} driver: s3.csi.aws.com volumeHandle: s3-csi-{{`{{.TaskId}}`}} volumeAttributes: @@ -47,12 +51,14 @@ spec: stsRegion: {{ .Values.stsRegion }} {{- end }} {{- end }} - {{- if eq .Values.storage.type "s3files" }} + + {{- if eq .Values.Kubernetes.Storage.type "s3files" }} driver: efs.csi.aws.com volumeHandle: s3files:{{`{{.S3FilesystemId}}`}} volumeAttributes: encryptInTransit: "true" {{- end }} + claimRef: namespace: {{`{{.Namespace}}`}} name: funnel-worker-pvc-{{`{{.TaskId}}`}} \ No newline at end of file diff --git a/helm/funnel/values.yaml b/helm/funnel/values.yaml index 2ca35dc59..dec8d5420 100644 --- a/helm/funnel/values.yaml +++ b/helm/funnel/values.yaml @@ -253,16 +253,6 @@ service: httpPort: 8000 rpcPort: 9090 -# Funnel Worker + Executor storage (S3 bucket) -storage: - # type: either "mountpoint_s3" or "s3files" - type: mountpoint_s3 - driver: aws-s3 - size: 10Mi - accessMode: ReadWriteMany - className: s3-csi-sc - provisioner: s3.csi.aws.com - createStorageClass: true # Funnel default settings configured for Gen3-managed PostgreSQL. # @@ -432,6 +422,10 @@ Kubernetes: RamGb: 4096Mi DiskGb: 4096Mi + # Funnel Worker + Executor storage (S3 bucket) + Storage: + # type: either "mountpoint_s3" or "s3files" + type: mountpoint_s3 # cleanup configures an optional CronJob that runs `funnel kubernetes cleanup` # to delete orphaned Funnel-managed Kubernetes resources. It is intentionally # turned off by default; set cleanup.enabled=true to enable it. From c17a15ddf37040729a787f4c88ceb57d4f5b79c2 Mon Sep 17 00:00:00 2001 From: Sai Shanmukha Narumanchi Date: Fri, 24 Jul 2026 14:45:53 -0500 Subject: [PATCH 160/196] [COPY #635] integrate funnel helm chart (#637) --- .../workflows/integration_tests_on_kind.yaml | 1 + .pre-commit-config.yaml | 10 +- git-hook/funnel-chart-check.sh | 9 - helm/funnel/Chart.yaml | 12 +- helm/funnel/README.md | 240 ++++-- helm/funnel/charts/funnel-0.1.99-rc.36.tgz | Bin 146409 -> 0 bytes helm/funnel/files/executor-job.yaml | 146 ++++ helm/funnel/files/role.yaml | 39 + helm/funnel/files/rolebinding.yaml | 16 + helm/funnel/files/server-config.yaml | 201 +++++ helm/funnel/files/serviceaccount.yaml | 18 + helm/funnel/files/worker-configmap.yaml | 11 + helm/funnel/files/worker-job.yaml | 117 +++ helm/funnel/files/worker-pv.yaml | 44 + helm/funnel/files/worker-pvc.yaml | 17 + helm/funnel/templates/_helpers.tpl | 45 +- helm/funnel/templates/clusterrole.yaml | 65 ++ helm/funnel/templates/clusterrolebinding.yaml | 19 + helm/funnel/templates/cronjob.yaml | 45 + helm/funnel/templates/job-resources.yaml | 0 helm/funnel/templates/plugin-server.yaml | 66 ++ helm/funnel/templates/server-configmap.yaml | 15 + helm/funnel/templates/server-deployment.yaml | 96 +++ helm/funnel/templates/service.yaml | 18 + helm/funnel/templates/serviceaccount.yaml | 22 + .../templates/tests/test-connection.yaml | 15 + helm/funnel/templates/worker-configmap.yaml | 22 + helm/funnel/values.yaml | 798 ++++++++++++++---- helm/gen3/Chart.yaml | 4 +- helm/gen3/README.md | 4 +- 30 files changed, 1853 insertions(+), 262 deletions(-) delete mode 100755 git-hook/funnel-chart-check.sh delete mode 100644 helm/funnel/charts/funnel-0.1.99-rc.36.tgz create mode 100644 helm/funnel/files/executor-job.yaml create mode 100644 helm/funnel/files/role.yaml create mode 100644 helm/funnel/files/rolebinding.yaml create mode 100644 helm/funnel/files/server-config.yaml create mode 100644 helm/funnel/files/serviceaccount.yaml create mode 100644 helm/funnel/files/worker-configmap.yaml create mode 100644 helm/funnel/files/worker-job.yaml create mode 100644 helm/funnel/files/worker-pv.yaml create mode 100644 helm/funnel/files/worker-pvc.yaml create mode 100644 helm/funnel/templates/clusterrole.yaml create mode 100644 helm/funnel/templates/clusterrolebinding.yaml create mode 100644 helm/funnel/templates/cronjob.yaml create mode 100644 helm/funnel/templates/job-resources.yaml create mode 100644 helm/funnel/templates/plugin-server.yaml create mode 100644 helm/funnel/templates/server-configmap.yaml create mode 100644 helm/funnel/templates/server-deployment.yaml create mode 100644 helm/funnel/templates/service.yaml create mode 100644 helm/funnel/templates/serviceaccount.yaml create mode 100644 helm/funnel/templates/tests/test-connection.yaml create mode 100644 helm/funnel/templates/worker-configmap.yaml diff --git a/.github/workflows/integration_tests_on_kind.yaml b/.github/workflows/integration_tests_on_kind.yaml index 052c7c5a4..f81b9b03d 100644 --- a/.github/workflows/integration_tests_on_kind.yaml +++ b/.github/workflows/integration_tests_on_kind.yaml @@ -20,6 +20,7 @@ jobs: uses: uc-cdis/.github/.github/workflows/integration_tests.yaml@master with: EXTERNAL_TO_CTDS: "true" + HELM_BRANCH: ${{ github.event.pull_request.head.ref }} SERVICE_TO_TEST: gen3_workflow SETUP_SCRIPT_1: https://raw.githubusercontent.com/uc-cdis/gen3-workflow/refs/heads/master/.github/workflows/integration_tests_on_kind/ci_start_kind_cluster.sh SETUP_SCRIPT_2: https://raw.githubusercontent.com/uc-cdis/gen3-workflow/refs/heads/master/.github/workflows/integration_tests_on_kind/ci_override_config_and_start_minio.sh diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index b3defcaf2..9b3400a35 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -37,12 +37,4 @@ repos: entry: git-hook/helm-bump.sh language: script name: Helm Docs - require_serial: true - - - repo: local - hooks: - - id: funnel-chart-check - name: Funnel chart check - entry: git-hook/funnel-chart-check.sh - language: script - pass_filenames: false + require_serial: true \ No newline at end of file diff --git a/git-hook/funnel-chart-check.sh b/git-hook/funnel-chart-check.sh deleted file mode 100755 index 9f59fa783..000000000 --- a/git-hook/funnel-chart-check.sh +++ /dev/null @@ -1,9 +0,0 @@ -#!/bin/bash - -funnelVer=$(yq '.dependencies[] | select(.name == "funnel") .version' helm/funnel/Chart.yaml) -chartPath=helm/funnel/charts/funnel-$funnelVer.tgz -if [ ! -f "$chartPath" ]; then - echo "$chartPath does not exist. Please run 'cd helm/funnel && helm dependency update'. Existing files:" - ls helm/funnel/charts - exit 1 -fi diff --git a/helm/funnel/Chart.yaml b/helm/funnel/Chart.yaml index 030a4d7d1..e0077e047 100644 --- a/helm/funnel/Chart.yaml +++ b/helm/funnel/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.28 +version: 0.1.29 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -26,13 +26,3 @@ dependencies: - name: common version: 0.1.38 repository: file://../common - - name: funnel - # NOTE: - # When updating this version: - # 1) Run `helm dependency update` in this directory to generate a new .tgz file - # 2) Commit the updated .tgz file into gen3-helm in the same PR - # - # ArgoCD relies on this checked-in .tgz reference — if it's missing, - # Funnel will not be deployed as a dependency. - version: 0.1.99-rc.36 - repository: "https://calypr.github.io/helm-charts" diff --git a/helm/funnel/README.md b/helm/funnel/README.md index db1dc4e72..cd3df1527 100644 --- a/helm/funnel/README.md +++ b/helm/funnel/README.md @@ -1,6 +1,6 @@ # funnel -![Version: 0.1.28](https://img.shields.io/badge/Version-0.1.28-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.29](https://img.shields.io/badge/Version-0.1.29-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for Kubernetes @@ -9,74 +9,145 @@ A Helm chart for Kubernetes | Repository | Name | Version | |------------|------|---------| | file://../common | common | 0.1.38 | -| https://calypr.github.io/helm-charts | funnel | 0.1.99-rc.36 | ## Values | Key | Type | Default | Description | |-----|------|---------|-------------| +| AWSBatch.DisableReconciler | bool | `true` | | +| AWSBatch.JobDefinition | string | `"funnel-job-def"` | | +| AWSBatch.JobQueue | string | `"funnel-job-queue"` | | +| AWSBatch.Key | string | `""` | | +| AWSBatch.ReconcileRate | string | `"10s"` | | +| AWSBatch.Region | string | `""` | | +| AWSBatch.Secret | string | `""` | | +| AmazonS3.AWSConfig.Key | string | `""` | | +| AmazonS3.AWSConfig.MaxRetries | int | `10` | | +| AmazonS3.AWSConfig.Secret | string | `""` | | +| AmazonS3.Disabled | bool | `false` | | +| AmazonS3.SSE.CustomerKeyFile | string | `""` | | +| AmazonS3.SSE.KMSKey | string | `""` | | +| BoltDB | object | `{"Path":"./funnel-work-dir/funnel.db"}` | Local file database configuration. | +| Compute | string | `"kubernetes"` | | +| Database | string | `"postgres"` | | +| Datastore.CredentialsFile | string | `""` | | +| Datastore.Project | string | `""` | | +| Datastore.Timeout.duration | string | `"300s"` | | +| DynamoDB.AWSConfig.Key | string | `""` | | +| DynamoDB.AWSConfig.Region | string | `""` | | +| DynamoDB.AWSConfig.Secret | string | `""` | | +| DynamoDB.TableBasename | string | `"funnel"` | | +| Elastic.IndexPrefix | string | `"funnel"` | | +| Elastic.URL | string | `"http://localhost:9200"` | | +| EventWriters[0] | string | `"postgres"` | | +| EventWriters[1] | string | `"log"` | | +| FTPStorage.Disabled | bool | `false` | | +| FTPStorage.Password | string | `"anonymous"` | | +| FTPStorage.Timeout | string | `"10s"` | | +| FTPStorage.User | string | `"anonymous"` | | +| GoogleStorage.CredentialsFile | string | `""` | | +| GoogleStorage.Disabled | bool | `false` | | +| GridEngine.Template | string | `"#!bin/bash\n#$ -N {{.TaskId}}\n#$ -o {{.WorkDir}}/funnel-stdout\n#$ -e {{.WorkDir}}/funnel-stderr\n#$ -l nodes=1\n{{if ne .Cpus 0 -}}\n{{printf \"#$ -pe mpi %d\" .Cpus}}\n{{- end}}\n{{if ne .RamGb 0.0 -}}\n{{printf \"#$ -l h_vmem=%.0fG\" .RamGb}}\n{{- end}}\n{{if ne .DiskGb 0.0 -}}\n{{printf \"#$ -l h_fsize=%.0fG\" .DiskGb}}\n{{- end}}\n\n{{.Executable}} worker run --config {{.Config}} --taskID {{.TaskId}}\n"` | | +| GridEngine.TemplateFile | string | `""` | | +| HTCondor | object | `{"DisableReconciler":true,"ReconcileRate":"10s","Template":"universe = vanilla\ngetenv = True\nexecutable = {{.Executable}}\narguments = worker run --config {{.Config}} --task-id {{.TaskId}}\nlog = {{.WorkDir}}/condor-event-log\nerror = {{.WorkDir}}/funnel-stderr\noutput = {{.WorkDir}}/funnel-stdout\nshould_transfer_files = YES\nwhen_to_transfer_output = ON_EXIT_OR_EVICT\n{{if ne .Cpus 0 -}}\n{{printf \"request_cpus = %d\" .Cpus}}\n{{- end}}\n{{if ne .RamGb 0.0 -}}\n{{printf \"request_memory = %.0f GB\" .RamGb}}\n{{- end}}\n{{if ne .DiskGb 0.0 -}}\n{{printf \"request_disk = %.0f GB\" .DiskGb}}\n{{- end}}\n\nqueue\n","TemplateFile":""}` | HTCondor compute backend configuration. | +| HTTPStorage.Timeout | string | `"30s"` | | +| Kafka.Topic | string | `"funnel"` | | +| Kubernetes.DisableJobCleanup | bool | `false` | | +| Kubernetes.DisableReconciler | bool | `false` | | +| Kubernetes.Executor.Annotations."karpenter.sh/do-not-disrupt" | string | `"true"` | | +| Kubernetes.Executor.PriorityClassName | string | `""` | | +| Kubernetes.Executor.backoffLimit | int | `0` | | +| Kubernetes.Executor.completions | int | `1` | | +| Kubernetes.Executor.restartPolicy | string | `"Never"` | | +| Kubernetes.ExecutorTemplate | string | `""` | | +| Kubernetes.ForbiddenPathPrefixes | list | `[]` | Path prefixes that Funnel's Kubernetes backend must reject when creating worker pods. | +| Kubernetes.JobsNamespace | string | `""` | | +| Kubernetes.Namespace | string | `""` | | +| Kubernetes.NodeSelector | object | `{}` | | +| Kubernetes.PVCTemplate | string | `""` | | +| Kubernetes.PVTemplate | string | `""` | | +| Kubernetes.ReconcileRate | string | `"120s"` | | +| Kubernetes.Resources.Defaults.Cpus | string | `"1000m"` | | +| Kubernetes.Resources.Defaults.DiskGb | string | `"512Mi"` | | +| Kubernetes.Resources.Defaults.RamGb | string | `"512Mi"` | | +| Kubernetes.Resources.Limits.Cpus | string | `"8000m"` | | +| Kubernetes.Resources.Limits.DiskGb | string | `"4096Mi"` | | +| Kubernetes.Resources.Limits.RamGb | string | `"4096Mi"` | | +| Kubernetes.ServiceAccount | string | `""` | | +| Kubernetes.Timeout.duration | string | `"300s"` | | +| Kubernetes.Tolerations | list | `[]` | | +| Kubernetes.Worker.Annotations."karpenter.sh/do-not-disrupt" | string | `"true"` | | +| Kubernetes.Worker.PriorityClassName | string | `"system-cluster-critical"` | | +| Kubernetes.Worker.backoffLimit | int | `0` | | +| Kubernetes.Worker.completions | int | `1` | | +| Kubernetes.Worker.restartPolicy | string | `"Never"` | | +| Kubernetes.WorkerTemplate | string | `""` | | +| LocalStorage | object | `{"AllowedDirs":["./"]}` | Local file system storage configuration. | +| Logger.Formatter | string | `"json"` | | +| Logger.Level | string | `"debug"` | | +| Logger.OutputFile | string | `""` | | +| Logger.TextFormat.ForceColors | bool | `true` | | +| Logger.TextFormat.FullTimestamp | bool | `true` | | +| Logger.TextFormat.TimestampFormat | string | `"2006-01-02T15:04:05Z07:00"` | | +| Node.ID | string | `""` | | +| Node.Resources.Cpus | int | `0` | | +| Node.Resources.DiskGb | float | `0` | | +| Node.Resources.RamGb | float | `0` | | +| Node.Timeout.disabled | bool | `true` | | +| Node.UpdateRate | string | `"5s"` | | +| PBS.DisableReconciler | bool | `true` | | +| PBS.ReconcileRate | string | `"10s"` | | +| PBS.Template | string | `"#!bin/bash\n#PBS -N {{.TaskId}}\n#PBS -o {{.WorkDir}}/funnel-stdout\n#PBS -e {{.WorkDir}}/funnel-stderr\n{{if ne .Cpus 0 -}}\n{{printf \"#PBS -l nodes=1:ppn=%d\" .Cpus}}\n{{- end}}\n{{if ne .RamGb 0.0 -}}\n{{printf \"#PBS -l mem=%.0fgb\" .RamGb}}\n{{- end}}\n{{if ne .DiskGb 0.0 -}}\n{{printf \"#PBS -l file=%.0fgb\" .DiskGb}}\n{{- end}}\n\n{{.Executable}} worker run --config {{.Config}} --taskID {{.TaskId}}\n"` | | +| PBS.TemplateFile | string | `""` | | +| Plugins.Params.OidcClientId | string | `"FUNNEL_PLUGIN_OIDC_CLIENT_ID_PLACEHOLDER"` | | +| Plugins.Params.OidcClientSecret | string | `"FUNNEL_PLUGIN_OIDC_CLIENT_SECRET_PLACEHOLDER"` | | +| Plugins.Params.S3Url | string | `"FUNNEL_PLUGIN_S3URL_PLACEHOLDER"` | | +| Plugins.Path | string | `"plugin-binaries/auth-plugin"` | | +| Postgres.AdminPassword | string | `"example"` | | +| Postgres.AdminUser | string | `"postgres"` | | +| Postgres.Database | string | `"FUNNEL_POSTGRES_DATABASE_PLACEHOLDER"` | | +| Postgres.Host | string | `"FUNNEL_POSTGRES_HOST_PLACEHOLDER"` | | +| Postgres.Password | string | `"FUNNEL_POSTGRES_PASSWORD_PLACEHOLDER"` | | +| Postgres.Timeout.duration | string | `"300s"` | | +| Postgres.User | string | `"FUNNEL_POSTGRES_USER_PLACEHOLDER"` | | +| RPCClient.MaxRetries | int | `10` | | +| RPCClient.ServerAddress | string | `"localhost:9090"` | | +| RPCClient.Timeout.duration | string | `"60s"` | | +| Scheduler.NodeInitTimeout.duration | string | `"300s"` | | +| Scheduler.NodePingTimeout.duration | string | `"60s"` | | +| Scheduler.ScheduleChunk | int | `10` | | +| Scheduler.ScheduleRate | string | `"1s"` | | +| Server.DisableHTTPCache | bool | `true` | | +| Server.HTTPPort | string | `"8000"` | | +| Server.HostName | string | `"funnel"` | | +| Server.RPCPort | string | `"9090"` | | +| Slurm.DisableReconciler | bool | `true` | | +| Slurm.ReconcileRate | string | `"10s"` | | +| Slurm.Template | string | `"#!/bin/bash\n#SBATCH --job-name {{.TaskId}}\n#SBATCH --ntasks 1\n#SBATCH --error {{.WorkDir}}/funnel-stderr\n#SBATCH --output {{.WorkDir}}/funnel-stdout\n{{if ne .Cpus 0 -}}\n{{printf \"#SBATCH --cpus-per-task %d\" .Cpus}}\n{{- end}}\n{{if ne .RamGb 0.0 -}}\n{{printf \"#SBATCH --mem %.0fGB\" .RamGb}}\n{{- end}}\n{{if ne .DiskGb 0.0 -}}\n{{printf \"#SBATCH --tmp %.0fGB\" .DiskGb}}\n{{- end}}\n\n{{.Executable}} worker run --config {{.Config}} --taskID {{.TaskId}}\n"` | | +| Slurm.TemplateFile | string | `""` | | +| Swift.AuthURL | string | `""` | | +| Swift.ChunkSizeBytes | int | `500000000` | | +| Swift.Disabled | bool | `false` | | +| Swift.Password | string | `""` | | +| Swift.RegionName | string | `""` | | +| Swift.TenantID | string | `""` | | +| Swift.TenantName | string | `""` | | +| Swift.UserName | string | `""` | | +| Worker.LeaveWorkDir | bool | `true` | | +| Worker.LogTailSize | int | `10000` | | +| Worker.LogUpdateRate | string | `"5s"` | | +| Worker.MaxParallelTransfers | int | `10` | | +| Worker.PollingRate | string | `"5s"` | | +| Worker.WorkDir | string | `"./funnel-work-dir"` | | +| authenticationSource | string | `"pod"` | | +| cleanup.enabled | bool | `false` | | +| cleanup.schedule | string | `""` | | +| cleanup.scheduleOffsetMinutes | int | `0` | | | criticalService | string | `"false"` | Valid options are "true" or "false". If invalid option is set- the value will default to "false". | | externalSecrets | map | `{"createFunnelOidcClientSecret":true,"dbcreds":"","funnelOidcClient":null}` | External Secrets settings. | | externalSecrets.createFunnelOidcClientSecret | bool | `true` | Whether to create the Funnel OIDC client secret using the oidc job. | | externalSecrets.dbcreds | string | `""` | Name of the secret that will be created in secrets manager | | externalSecrets.funnelOidcClient | string | `nil` | Will override the name of the aws secrets manager secret. Default is "funnel-oidc-client". | -| funnel.Database | string | `"postgres"` | | -| funnel.EventWriters[0] | string | `"postgres"` | | -| funnel.EventWriters[1] | string | `"log"` | | -| funnel.Kubernetes.Executor.Annotations."karpenter.sh/do-not-disrupt" | string | `"true"` | | -| funnel.Kubernetes.Executor.backoffLimit | int | `0` | | -| funnel.Kubernetes.Executor.restartPolicy | string | `"Never"` | | -| funnel.Kubernetes.ReconcileRate | string | `"120s"` | | -| funnel.Kubernetes.Timeout.duration | string | `"300s"` | | -| funnel.Kubernetes.Worker.Annotations."karpenter.sh/do-not-disrupt" | string | `"true"` | | -| funnel.Kubernetes.Worker.PriorityClassName | string | `"system-cluster-critical"` | | -| funnel.Kubernetes.Worker.backoffLimit | int | `1` | | -| funnel.Kubernetes.Worker.restartPolicy | string | `"Never"` | | -| funnel.Logger.Level | string | `"info"` | | -| funnel.Plugins.Params.OidcClientId | string | `"FUNNEL_PLUGIN_OIDC_CLIENT_ID_PLACEHOLDER"` | | -| funnel.Plugins.Params.OidcClientSecret | string | `"FUNNEL_PLUGIN_OIDC_CLIENT_SECRET_PLACEHOLDER"` | | -| funnel.Plugins.Params.S3Url | string | `"FUNNEL_PLUGIN_S3URL_PLACEHOLDER"` | | -| funnel.Plugins.Path | string | `"plugin-binaries/auth-plugin"` | | -| funnel.Postgres.Database | string | `"FUNNEL_POSTGRES_DATABASE_PLACEHOLDER"` | | -| funnel.Postgres.Host | string | `"FUNNEL_POSTGRES_HOST_PLACEHOLDER"` | | -| funnel.Postgres.Password | string | `"FUNNEL_POSTGRES_PASSWORD_PLACEHOLDER"` | | -| funnel.Postgres.User | string | `"FUNNEL_POSTGRES_USER_PLACEHOLDER"` | | -| funnel.Worker.LeaveWorkDir | bool | `true` | | -| funnel.image | map | `{"initContainers":[{"command":["cp","/app/build/plugins/authorizer","/opt/funnel/plugin-binaries/auth-plugin"],"image":"quay.io/cdis/funnel-gen3-plugin","name":"plugin","pullPolicy":"Always","tag":"main-gen3","volumeMounts":[{"mountPath":"/opt/funnel/plugin-binaries","name":"plugin-volume"}]},{"args":["-c","# Create a funnel-patched.conf since /etc/config/funnel.conf is readonly\nCONFIG=/tmp/funnel-patched.conf\ncp /etc/config/funnel.conf $CONFIG\n\nnamespace=$(cat /var/run/secrets/kubernetes.io/serviceaccount/namespace)\nJOBS_NAMESPACE=workflow-pods-$namespace\nS3_URL=gen3-workflow-service.$namespace.svc.cluster.local\nDB_HOST=$DB_HOST:5432\n\n# `Kubernetes.JobsNamespace` has to be configured manually because of templating\n# limitations. This ensures it is configured to the value that is hardcoded elsewhere.\nconfigured=$(yq -r '.Kubernetes.JobsNamespace' \"$CONFIG\")\nif [[ \"$configured\" != \"$JOBS_NAMESPACE\" ]]; then\n echo \"ERROR: funnel.Kubernetes.JobsNamespace is set to '$configured' instead of '$JOBS_NAMESPACE'. Please fix the configuration\" >&2\n exit 1\nfi\n\necho \"======= Funnel configuration =======\"\necho \" Kubernetes.JobsNamespace : $JOBS_NAMESPACE\"\necho \" Plugins.Params.OidcClientId: $FUNNEL_OIDC_CLIENT_ID\"\necho \" Plugins.Params.S3Url : $S3_URL\"\necho \" Postgres.Host : $DB_HOST\"\necho \" Postgres.Database : $DB_DATABASE\"\necho \" Postgres.User : $DB_USER\"\necho \"====================================\"\n\n# Replace placeholders with actual values (in-place)\nsed -i \"s|FUNNEL_PLUGIN_OIDC_CLIENT_ID_PLACEHOLDER|${FUNNEL_OIDC_CLIENT_ID}|g\" $CONFIG\nsed -i \"s|FUNNEL_PLUGIN_OIDC_CLIENT_SECRET_PLACEHOLDER|${FUNNEL_OIDC_CLIENT_SECRET}|g\" $CONFIG\nsed -i \"s|FUNNEL_PLUGIN_S3URL_PLACEHOLDER|${S3_URL}|g\" $CONFIG\nsed -i \"s/FUNNEL_POSTGRES_HOST_PLACEHOLDER/${DB_HOST}/g\" $CONFIG\nsed -i \"s/FUNNEL_POSTGRES_DATABASE_PLACEHOLDER/${DB_DATABASE}/g\" $CONFIG\nsed -i \"s/FUNNEL_POSTGRES_USER_PLACEHOLDER/${DB_USER}/g\" $CONFIG\nsed -i \"s/FUNNEL_POSTGRES_PASSWORD_PLACEHOLDER/${DB_PASSWORD}/g\" $CONFIG\n"],"command":["/bin/bash"],"env":[{"name":"FUNNEL_OIDC_CLIENT_ID","valueFrom":{"secretKeyRef":{"key":"client_id","name":"funnel-oidc-client","optional":false}}},{"name":"FUNNEL_OIDC_CLIENT_SECRET","valueFrom":{"secretKeyRef":{"key":"client_secret","name":"funnel-oidc-client","optional":false}}},{"name":"DB_HOST","valueFrom":{"secretKeyRef":{"key":"host","name":"funnel-dbcreds","optional":false}}},{"name":"DB_USER","valueFrom":{"secretKeyRef":{"key":"username","name":"funnel-dbcreds","optional":false}}},{"name":"DB_PASSWORD","valueFrom":{"secretKeyRef":{"key":"password","name":"funnel-dbcreds","optional":false}}},{"name":"DB_DATABASE","valueFrom":{"secretKeyRef":{"key":"database","name":"funnel-dbcreds","optional":false}}}],"image":"quay.io/cdis/awshelper","name":"config-updater","tag":"master","volumeMounts":[{"mountPath":"/tmp","name":"funnel-patched-config-volume"},{"mountPath":"/etc/config/funnel.conf","name":"funnel-config-volume","subPath":"funnel-server.yaml"}]}],"pullPolicy":"Always","repository":"quay.io/ohsu-comp-bio/funnel"}` | Configuration for the Funnel container image. | -| funnel.image.initContainers | map | `[{"command":["cp","/app/build/plugins/authorizer","/opt/funnel/plugin-binaries/auth-plugin"],"image":"quay.io/cdis/funnel-gen3-plugin","name":"plugin","pullPolicy":"Always","tag":"main-gen3","volumeMounts":[{"mountPath":"/opt/funnel/plugin-binaries","name":"plugin-volume"}]},{"args":["-c","# Create a funnel-patched.conf since /etc/config/funnel.conf is readonly\nCONFIG=/tmp/funnel-patched.conf\ncp /etc/config/funnel.conf $CONFIG\n\nnamespace=$(cat /var/run/secrets/kubernetes.io/serviceaccount/namespace)\nJOBS_NAMESPACE=workflow-pods-$namespace\nS3_URL=gen3-workflow-service.$namespace.svc.cluster.local\nDB_HOST=$DB_HOST:5432\n\n# `Kubernetes.JobsNamespace` has to be configured manually because of templating\n# limitations. This ensures it is configured to the value that is hardcoded elsewhere.\nconfigured=$(yq -r '.Kubernetes.JobsNamespace' \"$CONFIG\")\nif [[ \"$configured\" != \"$JOBS_NAMESPACE\" ]]; then\n echo \"ERROR: funnel.Kubernetes.JobsNamespace is set to '$configured' instead of '$JOBS_NAMESPACE'. Please fix the configuration\" >&2\n exit 1\nfi\n\necho \"======= Funnel configuration =======\"\necho \" Kubernetes.JobsNamespace : $JOBS_NAMESPACE\"\necho \" Plugins.Params.OidcClientId: $FUNNEL_OIDC_CLIENT_ID\"\necho \" Plugins.Params.S3Url : $S3_URL\"\necho \" Postgres.Host : $DB_HOST\"\necho \" Postgres.Database : $DB_DATABASE\"\necho \" Postgres.User : $DB_USER\"\necho \"====================================\"\n\n# Replace placeholders with actual values (in-place)\nsed -i \"s|FUNNEL_PLUGIN_OIDC_CLIENT_ID_PLACEHOLDER|${FUNNEL_OIDC_CLIENT_ID}|g\" $CONFIG\nsed -i \"s|FUNNEL_PLUGIN_OIDC_CLIENT_SECRET_PLACEHOLDER|${FUNNEL_OIDC_CLIENT_SECRET}|g\" $CONFIG\nsed -i \"s|FUNNEL_PLUGIN_S3URL_PLACEHOLDER|${S3_URL}|g\" $CONFIG\nsed -i \"s/FUNNEL_POSTGRES_HOST_PLACEHOLDER/${DB_HOST}/g\" $CONFIG\nsed -i \"s/FUNNEL_POSTGRES_DATABASE_PLACEHOLDER/${DB_DATABASE}/g\" $CONFIG\nsed -i \"s/FUNNEL_POSTGRES_USER_PLACEHOLDER/${DB_USER}/g\" $CONFIG\nsed -i \"s/FUNNEL_POSTGRES_PASSWORD_PLACEHOLDER/${DB_PASSWORD}/g\" $CONFIG\n"],"command":["/bin/bash"],"env":[{"name":"FUNNEL_OIDC_CLIENT_ID","valueFrom":{"secretKeyRef":{"key":"client_id","name":"funnel-oidc-client","optional":false}}},{"name":"FUNNEL_OIDC_CLIENT_SECRET","valueFrom":{"secretKeyRef":{"key":"client_secret","name":"funnel-oidc-client","optional":false}}},{"name":"DB_HOST","valueFrom":{"secretKeyRef":{"key":"host","name":"funnel-dbcreds","optional":false}}},{"name":"DB_USER","valueFrom":{"secretKeyRef":{"key":"username","name":"funnel-dbcreds","optional":false}}},{"name":"DB_PASSWORD","valueFrom":{"secretKeyRef":{"key":"password","name":"funnel-dbcreds","optional":false}}},{"name":"DB_DATABASE","valueFrom":{"secretKeyRef":{"key":"database","name":"funnel-dbcreds","optional":false}}}],"image":"quay.io/cdis/awshelper","name":"config-updater","tag":"master","volumeMounts":[{"mountPath":"/tmp","name":"funnel-patched-config-volume"},{"mountPath":"/etc/config/funnel.conf","name":"funnel-config-volume","subPath":"funnel-server.yaml"}]}]` | Configuration for the Funnel init container. | -| funnel.image.initContainers[0].command | list | `["cp","/app/build/plugins/authorizer","/opt/funnel/plugin-binaries/auth-plugin"]` | Arguments to pass to the init container. | -| funnel.image.initContainers[0].image | string | `"quay.io/cdis/funnel-gen3-plugin"` | The Docker image repository for the Funnel init/plugin container. | -| funnel.image.initContainers[0].pullPolicy | string | `"Always"` | When to pull the image. This value should be "Always" to ensure the latest image is used. | -| funnel.image.initContainers[0].tag | string | `"main-gen3"` | The Docker image tag for the Funnel init/plugin container. | -| funnel.image.pullPolicy | string | `"Always"` | When to pull the image. This value should be "Always" to ensure the latest image is used. | -| funnel.image.repository | string | `"quay.io/ohsu-comp-bio/funnel"` | The Docker image repository for the Funnel service. | -| funnel.postgresql.enabled | bool | `false` | | -| funnel.resources.requests.ephemeral_storage | string | `"2Gi"` | | -| funnel.resources.requests.memory | string | `"2Gi"` | | -| funnel.volumeMounts[0].mountPath | string | `"/etc/config/funnel-server.yaml"` | | -| funnel.volumeMounts[0].name | string | `"funnel-patched-config-volume"` | | -| funnel.volumeMounts[0].subPath | string | `"funnel-patched.conf"` | | -| funnel.volumeMounts[1].mountPath | string | `"/etc/config/oidc"` | | -| funnel.volumeMounts[1].name | string | `"funnel-oidc-volume"` | | -| funnel.volumeMounts[1].readOnly | bool | `true` | | -| funnel.volumeMounts[2].mountPath | string | `"/etc/funnel/templates"` | | -| funnel.volumeMounts[2].name | string | `"worker-templates-volume"` | | -| funnel.volumeMounts[3].mountPath | string | `"/opt/funnel/plugin-binaries"` | | -| funnel.volumeMounts[3].name | string | `"plugin-volume"` | | -| funnel.volumes[0].configMap.name | string | `"funnel-server-config"` | | -| funnel.volumes[0].name | string | `"funnel-config-volume"` | | -| funnel.volumes[1].name | string | `"funnel-oidc-volume"` | | -| funnel.volumes[1].secret.items[0].key | string | `"client_id"` | | -| funnel.volumes[1].secret.items[0].path | string | `"client_id"` | | -| funnel.volumes[1].secret.items[1].key | string | `"client_secret"` | | -| funnel.volumes[1].secret.items[1].path | string | `"client_secret"` | | -| funnel.volumes[1].secret.secretName | string | `"funnel-oidc-client"` | | -| funnel.volumes[2].configMap.name | string | `"funnel-worker-templates"` | | -| funnel.volumes[2].name | string | `"worker-templates-volume"` | | -| funnel.volumes[3].emptyDir | object | `{}` | | -| funnel.volumes[3].name | string | `"plugin-volume"` | | -| funnel.volumes[4].emptyDir | object | `{}` | | -| funnel.volumes[4].name | string | `"funnel-patched-config-volume"` | | | global.aws.awsAccessKeyId | string | `nil` | Credentials for AWS stuff. | | global.aws.awsSecretAccessKey | string | `nil` | Credentials for AWS stuff. | | global.aws.enabled | bool | `false` | Set to true if deploying to AWS. Controls ingress annotations. | @@ -105,6 +176,15 @@ A Helm chart for Kubernetes | global.topologySpread.enabled | bool | `false` | Whether to enable topology spread constraints for all subcharts that support it. | | global.topologySpread.maxSkew | int | `1` | The maxSkew to use for topology spread constraints. Defaults to 1. | | global.topologySpread.topologyKey | string | `"topology.kubernetes.io/zone"` | The topology key to use for spreading. Defaults to "topology.kubernetes.io/zone". | +| image.initContainers | map | `[{"command":["cp","/app/build/plugins/authorizer","/opt/funnel/plugin-binaries/auth-plugin"],"image":"quay.io/cdis/funnel-gen3-plugin","name":"plugin","pullPolicy":"Always","tag":"main-gen3","volumeMounts":[{"mountPath":"/opt/funnel/plugin-binaries","name":"plugin-volume"}]},{"args":["-c","# Create a funnel-patched.conf since /etc/config/funnel.conf is readonly\nCONFIG=/tmp/funnel-patched.conf\ncp /etc/config/funnel.conf $CONFIG\n\nnamespace=$(cat /var/run/secrets/kubernetes.io/serviceaccount/namespace)\nJOBS_NAMESPACE=workflow-pods-$namespace\nS3_URL=gen3-workflow-service.$namespace.svc.cluster.local\nDB_HOST=$DB_HOST:5432\n\n# `Kubernetes.JobsNamespace` has to be configured manually because of templating\n# limitations. This ensures it is configured to the value that is hardcoded elsewhere.\nconfigured=$(yq -r '.Kubernetes.JobsNamespace' \"$CONFIG\")\nif [[ \"$configured\" != \"$JOBS_NAMESPACE\" ]]; then\n echo \"ERROR: funnel.Kubernetes.JobsNamespace is set to '$configured' instead of '$JOBS_NAMESPACE'. Please fix the configuration\" >&2\n exit 1\nfi\n\necho \"======= Funnel configuration =======\"\necho \" Kubernetes.JobsNamespace : $JOBS_NAMESPACE\"\necho \" Plugins.Params.OidcClientId: $FUNNEL_OIDC_CLIENT_ID\"\necho \" Plugins.Params.S3Url : $S3_URL\"\necho \" Postgres.Host : $DB_HOST\"\necho \" Postgres.Database : $DB_DATABASE\"\necho \" Postgres.User : $DB_USER\"\necho \"====================================\"\n\n# Replace placeholders with actual values (in-place)\nsed -i \"s|FUNNEL_PLUGIN_OIDC_CLIENT_ID_PLACEHOLDER|${FUNNEL_OIDC_CLIENT_ID}|g\" $CONFIG\nsed -i \"s|FUNNEL_PLUGIN_OIDC_CLIENT_SECRET_PLACEHOLDER|${FUNNEL_OIDC_CLIENT_SECRET}|g\" $CONFIG\nsed -i \"s|FUNNEL_PLUGIN_S3URL_PLACEHOLDER|${S3_URL}|g\" $CONFIG\nsed -i \"s/FUNNEL_POSTGRES_HOST_PLACEHOLDER/${DB_HOST}/g\" $CONFIG\nsed -i \"s/FUNNEL_POSTGRES_DATABASE_PLACEHOLDER/${DB_DATABASE}/g\" $CONFIG\nsed -i \"s/FUNNEL_POSTGRES_USER_PLACEHOLDER/${DB_USER}/g\" $CONFIG\nsed -i \"s/FUNNEL_POSTGRES_PASSWORD_PLACEHOLDER/${DB_PASSWORD}/g\" $CONFIG\n"],"command":["/bin/bash"],"env":[{"name":"FUNNEL_OIDC_CLIENT_ID","valueFrom":{"secretKeyRef":{"key":"client_id","name":"funnel-oidc-client","optional":false}}},{"name":"FUNNEL_OIDC_CLIENT_SECRET","valueFrom":{"secretKeyRef":{"key":"client_secret","name":"funnel-oidc-client","optional":false}}},{"name":"DB_HOST","valueFrom":{"secretKeyRef":{"key":"host","name":"funnel-dbcreds","optional":false}}},{"name":"DB_USER","valueFrom":{"secretKeyRef":{"key":"username","name":"funnel-dbcreds","optional":false}}},{"name":"DB_PASSWORD","valueFrom":{"secretKeyRef":{"key":"password","name":"funnel-dbcreds","optional":false}}},{"name":"DB_DATABASE","valueFrom":{"secretKeyRef":{"key":"database","name":"funnel-dbcreds","optional":false}}}],"image":"quay.io/cdis/awshelper","name":"config-updater","tag":"master","volumeMounts":[{"mountPath":"/tmp","name":"funnel-patched-config-volume"},{"mountPath":"/etc/config/funnel.conf","name":"funnel-config-volume","subPath":"funnel-server.yaml"}]}]` | Configuration for the Funnel init container. | +| image.initContainers[0].command | list | `["cp","/app/build/plugins/authorizer","/opt/funnel/plugin-binaries/auth-plugin"]` | Arguments to pass to the init container. | +| image.initContainers[0].image | string | `"quay.io/cdis/funnel-gen3-plugin"` | The Docker image repository for the Funnel init/plugin container. | +| image.initContainers[0].pullPolicy | string | `"Always"` | When to pull the image. This value should be "Always" to ensure the latest image is used. | +| image.initContainers[0].tag | string | `"main-gen3"` | The Docker image tag for the Funnel init/plugin container. | +| image.pullPolicy | string | `"Always"` | When to pull the image. This value should be "Always" to ensure the latest image is used. | +| image.repository | string | `"quay.io/ohsu-comp-bio/funnel"` | The Docker image repository for the Funnel service. | +| image.tag | string | `"develop-2026-07-09-19-49-55Z-97d1df55"` | | +| labels.app | string | `"funnel"` | | | metricsEnabled | bool | `false` | | | netPolicy | map | `{"egressApps":["gen3-workflow"],"ingressApps":["gen3-workflow"]}` | Configuration for network policies created by this chart. Only relevant if "global.netPolicy.enabled" is set to true | | netPolicy.egressApps | array | `["gen3-workflow"]` | List of apps that this app requires egress to | @@ -121,7 +201,49 @@ A Helm chart for Kubernetes | postgres.username | string | `nil` | Username for postgres. This is a service override, defaults to - | | postgresql | map | `{"primary":{"persistence":{"enabled":false}}}` | Postgresql subchart settings if deployed separately option is set to "true". Disable persistence by default so we can spin up and down ephemeral environments | | postgresql.primary.persistence.enabled | bool | `false` | Option to persist the dbs data. | +| rbac.create | bool | `true` | | | release | string | `"production"` | Valid options are "production" or "dev". If invalid option is set- the value will default to "dev". | +| replicaCount | int | `1` | | +| resources.limits.cpu | string | `"1000m"` | | +| resources.limits.ephemeral_storage | string | `"2Gi"` | | +| resources.limits.memory | string | `"2Gi"` | | +| resources.requests.cpu | string | `"100m"` | | +| resources.requests.ephemeral_storage | string | `"2Gi"` | | +| resources.requests.memory | string | `"2Gi"` | | | secrets | map | `{"awsAccessKeyId":null,"awsSecretAccessKey":null}` | Secret information for External Secrets. | | secrets.awsAccessKeyId | str | `nil` | AWS access key ID. Overrides global key. | | secrets.awsSecretAccessKey | str | `nil` | AWS secret access key ID. Overrides global key. | +| service.httpPort | int | `8000` | | +| service.rpcPort | int | `9090` | | +| service.type | string | `"ClusterIP"` | | +| storage.accessMode | string | `"ReadWriteMany"` | | +| storage.className | string | `"s3-csi-sc"` | | +| storage.createStorageClass | bool | `true` | | +| storage.driver | string | `"aws-s3"` | | +| storage.provisioner | string | `"s3.csi.aws.com"` | | +| storage.size | string | `"10Mi"` | | +| stsRegion | string | `"us-east-1"` | | +| volumeMounts[0].mountPath | string | `"/etc/config/funnel-server.yaml"` | | +| volumeMounts[0].name | string | `"funnel-patched-config-volume"` | | +| volumeMounts[0].subPath | string | `"funnel-patched.conf"` | | +| volumeMounts[1].mountPath | string | `"/etc/config/oidc"` | | +| volumeMounts[1].name | string | `"funnel-oidc-volume"` | | +| volumeMounts[1].readOnly | bool | `true` | | +| volumeMounts[2].mountPath | string | `"/etc/funnel/templates"` | | +| volumeMounts[2].name | string | `"worker-templates-volume"` | | +| volumeMounts[3].mountPath | string | `"/opt/funnel/plugin-binaries"` | | +| volumeMounts[3].name | string | `"plugin-volume"` | | +| volumes[0].configMap.name | string | `"funnel-server-config"` | | +| volumes[0].name | string | `"funnel-config-volume"` | | +| volumes[1].name | string | `"funnel-oidc-volume"` | | +| volumes[1].secret.items[0].key | string | `"client_id"` | | +| volumes[1].secret.items[0].path | string | `"client_id"` | | +| volumes[1].secret.items[1].key | string | `"client_secret"` | | +| volumes[1].secret.items[1].path | string | `"client_secret"` | | +| volumes[1].secret.secretName | string | `"funnel-oidc-client"` | | +| volumes[2].configMap.name | string | `"funnel-worker-templates"` | | +| volumes[2].name | string | `"worker-templates-volume"` | | +| volumes[3].emptyDir | object | `{}` | | +| volumes[3].name | string | `"plugin-volume"` | | +| volumes[4].emptyDir | object | `{}` | | +| volumes[4].name | string | `"funnel-patched-config-volume"` | | diff --git a/helm/funnel/charts/funnel-0.1.99-rc.36.tgz b/helm/funnel/charts/funnel-0.1.99-rc.36.tgz deleted file mode 100644 index 208c61aac8ff9fbd9d774739f52541ddced41551..0000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 146409 zcmV){Kz+X-iwG0|00000|0w_~VMtOiV@ORlOnEsqVl!4SWK%V1T2nbTPgYhoO;>Dc zVQyr3R8em|NM&qo0POwib{jd8AddHEJ_Saq*^+yd$%}3_=kJ-7C6!B6zGy|cYGnD9A*Y;(za}9`@i-xI2cZ#tD9y7j+*v|nHU{fG5`A76D{f7Nw+_e+ybiI77iW_WOLIDB&O7?1b&_VE7rkVO4K zzkj&5*X!ZIVE=GD#uIW7_v8Kj-jiN*FgQ5c9}Id=9`6k%J^Z*gIUFB#rX(dCOAQO1M5`Q1pI`XV-; z<1`+cpNfJg^L})3mUYKDP2#Spp^I}lW1RkONH%aRlZF%n7>sF(IVHM)q0f|9uq2<8 zmn=`E@T>M4A7~(#i_l!bUtl>KuBxunN${8?fEQ<(lPNme=#)%wo=Ef^q@WSu3&PRP zm6B0TvBYC6$fM3Sdc`CeqN^Ddhzf*J%F-ZHOjbyeN)#JV5OyRHlBUycOy&$_InS6N zBJ318${>=C_;phi87M*Q$2GTa;h}$x;p7)}g=rWiSL{s!*J|;XR zl8Dfv7adzjX!fTo)09V9K1BUqZw|laWDb+|pg(v?b<46DnG=qaw?Z-wEX!uNvXP$14a@EzIRQLJ}6?WEah3#L}4YT_lp6&v#Ka7Q1N5X-v{7P022r<1|;0YC?{& zjApy&+AW*TiLPwur?rzt7HR}<)THH>mL2gZY^8C!`*}UKi>~qH8h6fAg|JApG!_&c zsD2bXNT4d~bY8IOlyC*Pjnv;XouY&+)b@j7GR~*Fh^7;^iwNgT$wMzx<`5F05Y(k` z2|abGKpB>^5S>pDnP+mjt25QAQ2iiDssM$I3Fl!4q1U<0a`_!i$PjI9Swa-In`1dd zzX_Hi5JTR}4np5SvQ$f3z1EWP4ORriD`z8bNFana>8n%TlM zg=!E3lAzFc3ibp*y&ZBJou^Tf#{^CCBteqSiI8}niAEH8l3ZDc5)w_Fma-g*5M6$E zvbVSQM2Ti*Wrk3|Au+8|ht=L;(Cfot^6NUI zD}YzNpajJfgI6+C3?zPkb#(y(N}ie>2l$u5cSFV~#$q;Rn8$$c>gqyo4_j)#*lNOe zd2v!krwU$PoS1TIUoqvBNIn_0d~q&NF4R26PRt7d&G`f>S1bIQ zAdz$6wi#y`;mJ}-6Oz+NnmxyIV$BqhV&Z^hhlJA*MYB1J(P6J=IxMujbDlf`uxEE*@ANkT~~b<@>2o58_x%!yEy>DhU#e;ejJV?qwKIHAg&a1yI=#)%dJ zpZy(;z8*by=-950Go(f=O-Td|Q4E0Pu+p#epPFmMImcQDeb^Jal-g_N_&uHHbCl-u zG2yVT6?Z^#h9$yQu0=OANzj-eP9&#h-Ayn}a;}GP8!AI%B5w#u4VdcgBw;rK;S`bg z8B6srz(&O;6Lpf{68c!810;yrQS}VUGu3f@G^c4URgb;I?=Lk{CDPfQQbaQn=ZTt( zqF@NBzhA=UTiw#b&d8Rq4DAN7iP=kdo+9kyl!QBmVhdivX`?S(@i|VHpuLB&wx!kT zU@2+FaWc!(YiNf>lCX5Dir-)=T`%TYjFp5vCKJZhQ1NR$AyXDB$qvJee8pmNLDT7q z(Qd3o^^`#c`zYpew_26z$y#OSDU~gi?e)~$Qb0qyR?OaQYC1o4Qwisi&9Pd5NwP#v zb*gGPKZPyaqHt8qu<8twA{r-Jsi0a!)QIC0z|8F5Mbyk$G0P>2*-ffvY0yV=f>SlW zi8|W}lrpzuP|s%S1Vrb+t|Up82u~!@Q)@!GkTBx)MW#8KJp@CQ$Ixk-nsS?^79(P! zj@IZ#tvGk61UaW9%~PqHa7rdLRfFS>q982Hh^|L-5Hli(EeKa4sn8PDn9T5kGT5pw z{qrmE$%{9ls8WjxCs{6r2pB1_;NzDC#4hXr&otmAoQB66j1

vM#ho^=5U15NVR}YQ=F*9 zdcl%}rqiMcx9J>`#!4t=x$F|o^|fNcrjD7I{ixP$+xD2MTPzvs>F(e}s6(utV?s@T zlEi8%DOim)R&0}|(?l;oz*ejmVh`}-J(aLqykOJnD5)YZ@q0908X`g9fd27XVQ=GDIiI;#0{~b++4-lP6iz( zgIip?%FQO}uc;RVFNm8TMtcV*5jv+*Gcvc)Ml6kT&OuSiZqkI|SakCY{?$9)1?D(O zNOHw-DkkbAruV+!Zokg9Q|hX%I_@%#;QWWo0kHc$PUD1daraesv^HdDgd4S}jpD-T zjQ>{hz3=0Bh70HxnpfB9bxfe+oK*he*9~RV;w2prsod74b z-0}G55vWL+R?ST8 zOz3;R4K$6(dm_+|S_QjWGaz9mwqf<0xXeIvx0;In|ra zHhK-q3@32*&zKMtwhkY-S%`?Kh}4b;h8){y!r5H6H(gN9(m6?C5A_ZNPF>J33OL>C z>O3LPj44J3S{Qx4Ai_H*kl6H`5rBVuEZlvFRo@x$Gu9K&Pzgu-d6ob>-l1umQtlBF zOtTnudec%|%+hZqn&AaZYpr2Q)M*Ns%Un?cv=7lQf6>x{T}D)tmlZ4x5Si6hN>i(W z^mwn{B2)=DrPVJ-wypGIv17P-vZsiOsA-N?O3;SWVvKHPL~CBONM%nkO2$oN1gA1} zeo&_Yb-DtP#z{Lu?b$32*vH5sF7pG1DUHDuLG?)Sych<@S&U+AXfVeXj#Y*%e zu{unv^wWYxk_4!HQ~qUzrQ*GU9x6A zS2<6SIvxXO6%tEz?pD$QO$ZOs&oh$R%duT6$Q24OA`0R7`->AmS)6GlLlc_D_P`3K zd`^&%d33E-7Dj)~Nv?Ps)T^X6&KXxCUK*RDxe+9-Af_P|OXsl?0+*gn=hD&b6qeh_ zB`Wbxt=Cy0!Om)Gc=(Mu5xOE+|GLrN3a6?!>sHQ~AaGO6WwA~Qpi<3Bn9}-P&5S+O zu}vDHk1+l6lqyC~&{MR)DNPa#$x|Xpx65;O<YsEQ$X&rMr95V`NF=KfWzm-NBeGB(d=qdV-vk~MgcK%kf0>B}D{p#)6e?Px^ z`}*?j*-z&uR{;Lu1D&9hpimt$Q4a;Cbss)toThSuwv6`aZKMF6qJNIJG_V5<5J_YA z%bFUnPRIk>l5o5)Ui7E`iOO@8fN$ji>=eScs6=i`+uWr zfBT=tH0_SDnCYJv&qgSCRa=ufovm9#8jP%4lIz!oMwDo||7m}iW$Dv9SRfYdoXnr9 zDLftD!P2lu6~id7u38rr*10LGJS`1N=Q*eG8QjJWKX0tRX&mWqHW}w{HW+0Eb&C=aq4LXcUG6^!mVLsl;f^?|oWDY{a zod_odS~<@Ov|oQsg3{|5meCC9hcII^?aTKR_C$RA^9X6^+RdHCbEga3)n{jabz!HV zFM!)Iy?%?e`!~OC{l+z}+HLd$8|(Wd7=;L@p!%S4M&NP~Og+rV%<=CmEzB!lsl1)z z%U6$7lS_DpXv?fBwX$O}*|K&0H^mpftQtU3t^v5MuA|V>T3x5eNJJ-;#OOCR){I%3 zn=o?^1W+n3E;<72uS+W4LXqpMYDzy$?8 zAb6b9LTN5hczrF@oQXom^Tey;htmr3odlqu5&xv=mm?g zRxTm26q3xt4kV3=$06J3=NXkGp#p9v;Udd3`N*)G33M}~(adssDiBT*c0*!wVNC=~ zx?`PqO6@Df0EJye#rIcN7p6vMjVPHj?J%#ZkXD+To4p${hG!WVJwLm$#+G5nLp3a2 zv#PnNc)^Z%nU0@7Ov*OK7k|jA%^ISsL-B zHp|%=jm{qVhWn$@nX_%ng=BNW(FJD<8k5-J-bUPi^`dwxyz;@&f$;pr_GK5Y>}6Mp zLDQVZq^l`WgcNkxs(vI(5zgdXKNj>-Jsk<`ATLLEL(Cf`ZT|RjRFG0s|KrP%?QFQx zw9=b>Q)Qoy*vDa+?j|mj>^f7j?Ms?cX03xxNH*(iqvvYJp^=(p+SvTGZ2zdO&Ck*} zW7O<+I?2+ae|f`evghJQvb0v9+U~?#4^8v=Z`ZQqYrZ1tD)FN;x}g)<+%azi;hxxB z+_S^a<6O?b=Eo@PQk+T;S|^xcu;*bfe;Xb2dg$dd)$m!KUXSSS5<6BxH)CK}uIA!T_&T>&9+e`0kqt~8!t9!j^9!-nlkP;U*Bl^jidlVPyJt>0K z=?a3xZuJIWNV3%PVv;9d;twzP%5`cF2pxk$Kbi7v%7T)SkN;*{r@X|Ol?2+0bvmma ze}kztSRQ`(1blLaRoe~3y6)1C%s;!+Oz|)7y5g<-rv2x?b|*5jj}c47^jk!@#LmYW zwjqCI?{4_0{*U&^aKE4F1ZU6Ief9e4Y!u4(^6u(b=l^F=^Z&EoKiqrp|8XDR6?5;L z%0}fhB6^QYmb*$8RtwrH5Cc#c>cjSj4=B7O3BiJd#S#3|CzLTRg9+m|n8!#gqV9(e zh?*B_M)?~mo}y4~p->f3XQ!cgR!*WBLt8&lL8Y~5?GKK^Uf2u!L;aNSkM6sFgs-;# z-_A&q5iUZR-IXh#HS2%xU{Lk{chGzA|8+m#hY#I9ch25t_5rW|I2c@Ug`GclKYi+a z_z)QDRkwKc!VQW{5C%f+N)E1l!k@HcpdhX2fQJ@}K(NBLwz-=nQy3mIG_ zjn$tWAnrt8@?ckk7DWD<<3wKz;Vc8P!_Ln{;|6%CYEVrOXiOrU3xWijmu_&NvF169 zl6$~+hd%Yg8=4(!r~7K8U}-u9(dbdwIiDb|nVv=xY2QXd_nA(k#mO6V30NSkpNVT~ z+xoR&ined*#C4_3blqt{TJtyQ?nF2|-vH^ur<;#wL8I#gjij_KI66y-w(;}lOx9E_L4lB8mN-k9=m5oBk#?g^X4 zaXKaFn`^S%Mc?R)+u>8!aFvceeFEerx0$q6v(0Ji*9=j$SA)hT>*G(upcH~uLn)dH ziPNZf5zw|Ks+)wB6>;g-WJMeN`;%8~Y_1Fznv4F*Rew$o#W=ZRIq;fy}#EYHLc{j#<7 z7i&D=-{&c?E%*9PY!!(ai>p7o37h&!&fTF=gssSn5=`elfB?;RIR&_dVTXQ>e&|^x zMo27kle!>$?6+u2qz9f*;s3nBGMah6^{9CX+77|5uTnz4qE-p@eg;kT)-Kv2?%E8>W8RhUq7;3(9hlEK$TbCy@j#{NGf2y=LyBEu3YmnpY;NF6O$*SJNb{F!llk+;*du^PRcMR(q1$18WFC~J|L=L*{D=8g z?f+&Te6bj?X8-RG_6{ri|IuFmLH~O%-`CpzpXs@?nHXRuTDvqL^6_sZvbRdQva%&s zr+)8-+woaoV+ytc&h(Eu{@XtCoXM6<%Fs?q)&n&FxXeeo&ac$Mb(FdG8lJ31=8{Z6 z@m~|~K1--WZmU``ogTJ@`}}JB|2H-coP=;UC%|?0f9mft|37@V|GTHJHvZ;1+`Co( z;yTvd|MYv+``^RC!~TCi--i$W_OA~%S42o-qF0dt)VZkG?oZt@sC}C^(@7E`&7A6N zy7eY4&hHygii|`ihy~c3YvXdOFV!gK>Hy+9)L)AgIZI}P!E2=Yk`l5F&>>_AMcQnr z6fFaJfg!5p^mmKs7=Fz|6S<*^>7p%E27>Sh+>cmcj(3)1>jD08&x2@=b>TOwp>wQj zB>(d*b#Rt-jZYa38%APLfp;cBs{n2M5A@3xykixh-UuRd&NoBIr=SkFnb8C;6Uo1# zm?4o6lA*oBUhiMQv5za`S&QAer8ToL{jDkA34)-sCf#y0;^J3Wi+0wQ7u4G6?oFWp zWt>SCv1Ev@PA)pd94pNtiTRXBZ*sLZ_QZDHX3e#Ize#H?vf5-CqK^R(s#12Z$#Pe# z|8}3BUF}}Hx!OHFdvSJkrcL>DVFlGUVEtYAA7oD$Q&|I(HQ4R%_Dt3o1MWSOwYS?- z|Ffk`?!L+0SH(<0oMbbsG7n7V0aU1qj){c4Lz8z1HR`-6p3fok$YdS?R-GA>M3;PQ zG9Lp${mzFE4^sNy|5ua$8eQ3aSsm--|D&4y-{IlW;6eVok8j%rfAXE2n39t8#%}uDlJ&iMwOW=`>=Uy?g20tmeDfqm8M~0)Bep9)l zYk|j(UNv3&7<LBE{qPnRw>_s0wAekj-Cj__1;d3I+imOLGZz11 z2C!!RANKaD=l`SL(L?;dd-*=|bm!?4joFp6pD4}MEq#>RaK8HoDp0&u>^l-?PV^C_ z{!Ff)|C$w^{sUx9nUEYyGBu&xbhxWa?Y{d>aec-86f3UJ@%uNa^Nc=3edlJHq$20= zNHAGK5P^)v@T9N+x4z32=hXLP){S|AeUx)`-0Rts!8UrufGHYu)(v`|N}2#Bmc%+} zfiPB*lJGfAvA%F!dme7;^SUWl(f5bC4{vu$-gICeTQxR9o`;D7Pc$RZwaDk@xk$<6 zX$S1<&^MudHXJ^~g1{5At!4?wutyz8R^;=da<3-+(8Zrz&f2S?sDIY4n>}r;#dmiQ zc0R+|JuJuDEP$KhaB39Vl5I0A#X(llR$bz%lv4$4`K6qWVoQ~SztN{pL-j-ADf;wj zYn2j0ffeyP{Tk0Fub8~xM37WgDzv?0&iCcaTF}o@S2Pw;O;?2YhJ5AHq*|mkQPG9@ zRFrc-$7uPZ1$&EX)+ek| zx>Z7hmgjP5*%YBn?d&dPtEv96YC&BxcwM;+YPz_FS*)o3RulYfHCZ#bS~AbmTAFnP zR?ArZ5YGp%8OYdVKcJ@9mMkyr&c$7mdkY_Bd36mG!82DEHEv-mrIV7MhV_(a_|Krj z6l|iRQJ<>k-Au}?N?TRY+UqqIdU6Bm*stFS8(6dc`-8gu&;H=y{qMbetL;D6-8Ea&#CFB^O6A5{1H}~Gf-fLN zX_@XTc1=>_>gfIrJ^$#=ZLt3Q+8zA&|6cAN?W^&B39b~uXrc(K^<~?@TKVs&cK>sD z^kDyYFJB`Ax?phw*V$U@z$K_mo2@TlDGh4>E&DKi#@O|iwvux~W>vFiMZp{UXvyjG z#<^II*?XrEw02?ND$sAOX_qkt`*v-sef^(3J;4q0r%!;a(b4fAJ?{3at$!UQ;6Cj? z`h)(UX8&>cAphOV*J%G?mXh<=>w;bSZZC{+h_(j#Y|98U-CPy7Hje0g_)r)?By4Og zAPnMcVXpVWW1-0@j35S@&8)=`twFH{f%Tt%djvHX{I^HZaGbk666Xxy^NRZK2-`9I z(JSHqo1fwTq1svLG-aIJeI4ude+L!*KR7&mu>ZN24;=4G!c*|muV(Sn<+v8h5r)N~SuX%1#Cmu1)x2 z^iPjM^xB!rXp&GyI7(tG^ki)6Sp&M`s)TggIro zKZZ6Z`(y){-nk%`qpB&_Dfh1$P2C1A{yTxTYcnA9&!K)KQpR4AG!B zI1G9R!CnpbRxSCFs3xdkLmzFx4fsn$oN9;vwn6oll;Tb(>TK}1uogE5eMDo%6eaH@ z&&fOV5us9va)`8#NDWJ>q|bNNC})jjb;z@}VmfqLy`XNrSEd1`9LlEz-S3IU0@GR( z8o*2phBh!0e;{;WA661uhc4nnfCR59de`r*DzPC!*0sDhqTpk`4mlc~g_VE|Yq6^` zI*LLY=rfkc(`O-=iIzaZu6J4uV#>|$Fdi4BZJ7B|$>L=~0qCOsmmuw$D#HmS^MsYC z1a0&e1unE?(h9gt@tmDL+iVInK(C&N4Fy)u09W8jjsG(&h_N`Wt+}GiS%QV6QFxxl z>v`oCB$YpNDhU_A^!~DL)Jov}3b#H4U$jCjDr1=Y6apxt=g+=m zomiYP71w2qElUMNMSrf>X4dMNzJ@{X`IGiXJh{f<70YO}dRO%90cv35FZ`${^R6sXy7ep5=VIKh zB(#~`G!`jaa;%5H6|5gla{U;2p&B zQd6zC;Tp0OK>CW}mB6d(r-EUCp$$N~ ziW7RJyg;WP!Goy+|K%@Du=-l_mJG@i`W*ITir#`bnG&0`CR1PqV*=BJ738g3tbWkW z(2KKKJ2r(~ztD6_c=#PC*JSlD@ta_24fX|DkfaPp(+R7=y$0c9)vjs)ugH6;2~c!I zz|8fqsLy(hh^M|39~MEUcS z%G>lox%351r=L}|{R_g(Hg-%Mwt=7dxb%v=g;0^HQ#Yr7)dGJO_&gYx6b`8EMbJx&q?7i#p_tCTCtCR0h0Jm4L0hd|5%TFOp zKkEBwT8Xq$1L|On=4aKOv35Uj$f7J4K}I+*$uCouI-GMd2d&MQseuZ7a-Mnk?rB>n z5B#c)0fJ12CSvqzpmH$iV!67Y&=vT#x_J%O%&V)F7g4HL!`a~0n?S9{X5(zPL7BtT z3xXHK%;(nDT39x{!ZcC+=yN>3`wGZSL_-7p62HH|9484$u8f+sd9Sg@QSH2FBiu#P zR$YG<#c(cXB$dV{V+2BTRdk38@Fu4-zx4iM9kJBTiBYzB+3H;zc#Z`lHsjM;bgjF2 z|B$;5ZS_)aMd)b2Z`_WquRuG;DdFD4vG01s^;6ZxMN7_iJOtV!$@=oz@rhqE5Blqi z`JN2aZ|DDaZlbU*^JBy$H`lv6~0yN<^E$|+u!CRX~RM#-%wRL8_9Gf z)(~2`QEB%nwW^eT_BWFy3y8fi5>&BQ#qa9{8(3toG(u7|8Lj0aAXrFWNZC{vS?M6H9bFsiDfL`#kH|4Wt>fE`P#e<+^|O)k$h2S0_kL)$)!H=G~Vucpc}Tb6Wr?S z9OsfvNlG~Qa-DECHxb3{n@N-lRpBo)lFWmcMFK7QVShjL4B4kt&T^21x+&u~jK#lo z9eCG7sux{T?veK}#SC>!7NMAZr8fra-hUnL_bcx|`U?Ev{l`6gIJ-tTj?t7#6y-cY z3p&?N=GA}PbAl-gW3uSRNq5Tn;b1=;gb7Xa_W|bf!~IZV9!`JnNX$`ig1Wij+ME^z z?|+}5RYgcNW9Zw97*9g2ImazVi5+^>5_pw=r3~)n1P8&;i`K_y7BcRsSCcgNOH@_w#9& z7}|BZIp3@fFx5dw;_1-NWEXEL(l&z~gt8`Aw%h0e0MU6$C332nPQ_uhcHMD{I9J+j zyHAi-!f_^95pSV|sG4Wp07aSmbEN{YfZ9wS*y(8V4^oqiZ6AYqAWc zjEG=HxQQvPA7f}RZsBxrpDO4x$aLNs{6Jz_oE{=aPN!qv+NhQk?Evpj9XWu%i(>DBbjlBGY!a$2T}*DV7A;g;z(+eRA;VrS)vC6SOB_2Gh0i!AOv? zIB>q^x>yK0O;w@@z-+O*tu>?p21qscf+>+A5XP)24kQae@``3mkQ9o!E_>&7p6dA0 z^9$GV)JrW#*3of9zPTpLUGxo{R`C4hAiHQxEX>zUYZ(zi;u zBAFCj(>XMq24q3Od0f)#L8WCGo#TA>34%@oUrH`39=v@ zCn#3qz*#PkSc(WIi2!bmA`MHl$2rA2Gfo#YAya~g0@S95j2CVnAw46GFhjlu5(F8#XMQ#z-55o4q2!DVmWaL!88U zq`Qn$agEr-pp-K*kx+0>MJ`Ba_xF{~b&F$S&DG=@iKYA!#Ep7WtSY^wk7_x^{@xT? zrxFa=9WQDkgBu)k^49?8>PJKVidZ?V(^QS=Gnjg+-|?6xYJ-;yO)*W;oN-djFhBGT zND3D==gdvLa=#w}ue}1*Ki?&XWPu{-%>Fo0I{Paxy9-UpiIX^Xj zJwHG7ifcDnIE_8N@vg)}6lZ!P$Y@5A#E+U*4_Xu;7kay#8bn1xH9A&+oVDfFKmTyXJqit3sQ0MK(-J{e)8Xv^21|+AR%;BKf=<;Lsh8q0P6Q^NG@YJOZYQ=9eqze? z)OK*CFj&=2ZrRt*%CWS(plxPb_e0C*jb_W==eOE-1KkSyxBH_p+*5O~Clg@lonk{^ z;agtIs1!{JptRX8fIX)rKzEBDm>XYL#@Oc83pGW3s*(vAFo@q#pjv%nKU7-$mb0N#-yue$uy=m04YO92G?;~7auyr+6Ct}C%Gw+;R6PRmV)!OiSyPcJd)IE5TU^@3_P^1!GH8`-% z7EuGnMv3Z=R{4~^lK#*6dA-{@*4+OL`g>LX&wKj^5BER!^7;Bcup6^i93bU{*N@?_ z=5&CUENKr5WY+@3rBM4^S;JQs`vNuLn$&}vss`b=c8SuUi0be>QLJJc{Qw?HQ#=Jn zduo}_sSt2V4G_-gbI$TiC=m&Co?FIkyV>Z_FI&H{v4GSC;bTbAr+g(cO^HaWZu#Uvq;Z2jdHwRVNXGOtu_s;t)VmriFJU9h;Nt!M{SSjI9iW3hNt zC8SP+0=sR?+nU*o-L_CQL;XzHw6V42YM`w}ba*8R8Yg4g6b|h;1sj~seq-ZukoOJR z?wsHQar%a=c_e@~-TgnE_}#Cl(DpmU-eNbgO?uxI(q&-(`TX(dY-^8W0`1s7(VY+1 zzg*IEx&cw(Rj8E+I~D(E&i3$a^40c#-&y+|)v?b0>u6B5|2pXPAL75<%l8@k|1&*9 z?obRcbM7lj0wM?FPBH8Rs4>V^`8u;*(Y201wS+FoMA7F-Om`$FS-!ktsBX)4OY6U6 zHG6j)V9ovi{$8&t{~rvFdJpUWK0f2Mwxlbzo@~{ryKF*Jd%fPKW3E4Qht*SaF}J3? z=Zg-?SIlvm%a-5FL%CP$L(0?*gf@W%A)KCEB9dW!jt z-~(;%Si7iwz2=g(L{yRdQ~fHoO_6uD;)=I^C0$&?8jxC6`?YN|1uF+(+Zd#P$reIo z=WRpuvGd^rl39Xwc3LenJXa$2Ue|?pBC<8Y)uTtg!O^~>$638-imE;?*U{AA6LSSs z4Pmp|=qeNl)>^BBio_=JT05Z}F>kA-!i%5$nhO7y8&%Xz+_DoD*<{llwO#!Hbmy^vN^tT?6Nvq>;9_5?wwC81>w7RA9k8}oDZQF zbO6}uTSLu;+^e+Y8xcwt?ho~?Uj@?hj;JpJoeRb$yoG;8z2`YEhMLWLZWEhIw>Vfd z+^gh1ab59}t3`vL;z)4~imKa1)w9}#gT6pxSf( zRc?2)e=se8``*RYl+qr^^r@ii(QHMNH}HbyFnS)=HpbZKl}+`H%2Zg+PfMk>SIoF+ z#N4xsDtOIPB@{0F4%JI|K8eift8`eY$@CT1nUN>P*M;~BF!$y52C2OQ9y>w3qve&M zk#mfdg)3L_YXlW|4w0H*eSb*+UvkgXRHE#^$(FIspIS;d-%uLfb1cdeDX9Fah{?z^EQ5f8bO_tAT?IjeXAAfN+rq; zY1`Xd_jBtAZiWNLRqd449oOo0Z2j&w0~c<23+UD8%ie!C9He$Hxu6QhlWSZ^mhLd) zYj+^*h{-RGFBO$e9jN8JQ=RPr+S;l@K#Y^JvdxQqqUbI?u&tBhvTYsZ4X(VQ`EPMS z^<#e3m}v{k^mm-%b*;+Le>-`}W8@WfJr_TcrIiQmuliB3GBW1*?Wa%mhq(R(Fm4U( z#_zwwZAKVsfa+Mc=^dL&tyDMGXM_Gx*bV;CHz9ndEoDoiT;du<#;ca6inYBAh$qlID z5aT6t0(d_5`t-G`URw38etj9KeK%z&0*PB2vI~ScL1Ut-7kQQ?)Ot^nGlH(pM*3m% z6`qPayWIa=>jQYNsya*%sdy-OIg4%RbLfoY%U8hQ-dQ$#j^`@ln5Py;?U^sR7G)O@ zps@@vPu&Ze8WK|juulJ-wCj8QN(&w&2{b19@e!6Z!b!5!M&TqzG?ff22>-pa+54nF zdY(Ug&0mTCH{N7?c^&KQzxMa`tNj1y=)wQPy?o|DJQct;jRSh~l25T#m1=K#gno@V z*3Z+v(;lw0mZ{UYkGPApwYFl$QJ;A=qj@K4W6P*?lwHl3ZKb8^U|#FHAN>+YH@mpn z(OCcJvAK`0Y5m`=_m{Qn|ES+TtgQe2!`{Ke`oE9w%l*B4v3nOi>(+`;a9ytjK<(=r z#6HHQIYPc$XZmvXUUF=Tex{wvExaq-2K8+n)-(hQ1WX&at7(WD2u0hR)o2~$D%UXH z@U0#~GlsYEd(#kw(dk9M#On?Gu6U&R@ZqyPoisZl`7Ey|Wh&meAdv8 z%AO#;eCb%%5|BjR%kH)yGLSP8RC9s}<9a={4u8c@MbU;<2Nn}yO#fAXRiHwX=?@#v z(_>NGC{#{^)>)fD-DDbT*aYd4(OXJbvJ>u{Tm<>&e%*~l46V^Ca&Vy#OPBQbwH zhbA@e6#+6XG`y4`Dt6|Q_ly92^j4+uN!%22tihYTcU1DDkhL}R_I@GUaI}PZC~*|u zCBv$MCRjtIY@>sQRcPu#BT5)oxRz+Z>V??2O`FPrGCs3Kte9e9+>`X8D(D!KY z{6l!N$79!>ozA0SNj zc=*2l*QEb3X6AQR$2$KX2S*20{m=g4L;Qz(`5N`M7ZqNyR(+c-8rj(A-j=PuiL+;S z;l&{`M%!Cx8(rFK#|h)$;ebZSg%;A6jSJJ$u;uUw!VGnA6pg76zv3EI{v$fnSAipYBk9@rrWxiAH3 z8gV062YHq-9J{hO%LrVrBFUNyn_A_Ja91j2X}}qig@atCC(wpl60Gk`jSIg82D-qFEdfw(dDJ<=5YLN5fsV8nVL2oz362Uhj!DG>dKGdkh zUU!_Zad*)V2ZL~+PNLnb%hzw7y*L|v|N8aS`K#yQJl>}10w**MW=u%6IN*#Kry@|I zUXrW1WjmVjhy)pyvp~pYLh1^~NKj)029ddjs2p6YQ;0m@<1|i)0)Tj6&1+SI9!tsT zIG2T(qyr21=QVBPR2Fhd-QE~Zw$S)BKFj%u_154Vx=-`B6=g?N&Ecd8B}{ZIhipDu{lRR(tbg#S`W0ON!MA4p@9!T~?|%medq)rJ z|31FTN++p)o&!=VJR#6gi5f23A}q-iv{%+N-d+~ch@^suAv(@*G$X+v?3qRE)ito| z+9e%^y-*8=`bsJuqOC!1a2WLZ!Qk;#|H*JL81@gs{iDNP|0w7^9`<_Le{D>ZluOcx z7E9KuXy$Vx8I?m^S>X&qEsD@Y@dY8x{B7@K@YGZMn7p8bcVSyF2;YbA4Mig2G}9LL z=5@l(?LmDTDWh6x=irp(V`fo3g4Zs|tGc3SEbuP%RsfkM9EkpnqqAB`e z^!inh&})KX7Uk*?AVPGkZT3ivz+bg-c8${*&FFL%WQ0!`pW`%gF2>Jef)n70Fhh>ivkj-MP7LMBg+#z&YO?o9~B2ZS6P4fgjZ zM^E-59E}g+=<(qZp6pNJXdF!r560ueqk~>w>#k=^4OfH6Y zj)}h}=5O=3#vP8J_XLsU1ShwvCY7!l>tJt`62N{`GCS&l(of-wzKAGg`-Eo*evL z@fh=TM{$rH`;14ko3zAabdcM?V?lA5dtayQCIwEwNkVsFQGVv@Q@-`{KCJvyV~A~ClzhC%O%V+?<^^!DYSk^jpax_hF2-rM`1 zgML;2f3SD-@c!pszRK3xxUDt{^p%~qF36WR%-Uvo>y6TGk_{VVWpli1;TutD6bg4M zc;8m&{&E@lZsp@*!z$!rZ(FkRaIyWAPeCC_ajM`?%LX?Bns1!|~qa@!sCv0U5{fQE$9=Fn)3{*y}$blO7%%JU$#( z#k0Mjw-@yHt_FkQ-e9~hp&14>le0nB>=8m|AWI`Z%|wR zhkFnAKlk!&Z=?Sz2w1SA=Ls9*1Z9}xIgx~m&i1xVJY~@};o4la0&xNEW#GNHjj^`%8LdM&n*pQZ%N;_eRV%ex)%sE*3r$-TD2_Szpmmu=KTMs$uzmat{< zFcf&nE<{0&aEhoDB$=Qwv6CStsRaekL#S4*>UK?%68KBqJ=88>wztt)I1Tk*)jl2S zWKh>GZNVSOQfI%yV63^l-9hz|=$F4#?hZ|bH5wtk<1e2R*fh(F!=F70h3n6eq{(KqP? zyi^Dxq31lDmD%0YV`w6&a$kv#kO%c`rFWg(ZZJ)e1*!q7#j- z7VNL|8q@FOyg^rZJOo4a8{TuLgv3yAOi-SxUM66)r5GHJW6f8;^@@J0&a{ljg!>$~ zIIf{@VMYXSDNp#fNYI!>n5!D$1iMrMpmq`wQxT~Vw(rNyTtXSAbIg}0W3ehG@~ILI z)c{dpYsF}Wc^pJ6Hq>UE#59t?-mgwBP{w!>Ox@xsj0UiE8|SEh$TZcY5WY$C3LAu zO~O4<{9^{DrTJ!(4bhh5IZ<4xYd>qGSu7M3_l9)K%X1{h;ENDmM z<3OJQz^#sAiV;iI8s{W_6rwXFbb(?^$s(oAz^`$LK76VXm3}HCcw}e1gb4lS>q!t?~d`W&=tB7|MX_fkwpk+vKF|Uh*8ryG|fo8W*Zbf=)EN}3K=wwP5` z-Ljy>)8-N?V~5V?xt2c^wZMfq(IQn$;zu=XTIbb_(Bzo`y1`4U8N)aX!_b_i?NOSF zVgPoPuque$Z8%sJecM*CS52my4x8if$CA3P6M50 zmt*F=`#qn$V)B9$VV5h?FGfJ37M3W}$?A+yJ-eF2upPH~E~MgcbDZXY!x+5Sx#xt^ zaI=Q3ejKk_q8q1V;sut(&6KXjPr|9;?%C&@)U(pfIQt}Qlj@}h#zjtsr_Q8j!fc9$31sO>! z$s|wI(D=jSj(0wQl8yUJx%!_s7lZe}D!@BC_?dNcw}Zf{qcdR%%K zQrXpTE@x%IL#0&3jq=-)hBc#xF|=wEwcF{H*Oj?soZ_Ub5e8*M-I~~;x~onNXH0^- zhDyuaGcAk90uJG?W<<^}bQ7}7WHvPMGjC6~1(8y5KXoWpbp*gAaT*7yfyJ>)RbQ<7-bX!lI^iqH4#(TLyFQ|}es+TC% zDjLh17tlx#+EVxoK2@!Fm%@D?dnJyNPk5Q(rv@5)rYt7CQ@Sf#kgxDC}Egj{Wg zbvsJUZ-=;G?M+>XPR}kb&rXi7&Q6EGO{#6N45hudT2MHGR-mv%wxDorD5LONZ>Dfo zp3$-MI&UXh1ZnC;Kix3KE=b9|V5WRD{GuP+4MIvwqo8xE9iR3gAjd_OlKoA*Rlci}CdiDD1 zY>0kV?Wgivy#Tb*kSr+6J=t0d^>mstPU6sUJB3U{b)%?s!PSeAHH$@K zB5w#uL2unAB{U7&6Li4_Q$uxxkH0n{A{?lEe`F)PZa}Hj=OJ^_w>4^p z&C*qa2{@1A*m@N_IrizRwK2jcgv(~&811Mve7KKD3aaZz4aL>!Ef+&ZRz}xk*^B{9 z@>IQsV!&elE`%X{q%YT3d^2_&igAI@ zZud0(%7>TYo@L z+MRX=y04~g)Hx4bxV8&1A5%$qQy-eFf4BwcsR3V2Y5Lx1|EkTeDD%!!Dhn;8YcLR; zXH^|t8#1Tj+Yp_FZ$T*WbTdpFsREnpFiO9Ts`+{f!e-h$HQ`3|`D(*=kTVMvzY>+!V2?fhZ#pf=p8uYxq2~DTtDMvLb&;1 zqN=E0PE1s_3{jDzDTD=h;ufH@*|HuB-~^z31m0S|9kF?q!{D0BTBGUxS+!2jG{+p_ z-d6RCUH9f@wYcat7ibB=3&YvqJ~v{ih}3CKzFzpEmG!)Sc zr;+|w@f)6l+LxpY%2^7pHT1TdP$?5)+ir;2MIw)8ih!3irK%U;)_2Kr6f<;#(^6Z! zV$ReCsGBe~fF`!hHcDu!U~v4KT99%^=BkF2L_`S8m%GpfoXpvR80`&DmT1f|bk9Vc z5x*@QPkbBJ=3v$9W0n0{dKI|6jn3ZVd6pCh z7~iobtVr;x+3)q{MUr)z*&jT9Nquf$3ZoC7D(DM@WltTquE7;A+c_v6a-2|@cxo#u zE?yxEVV$Q+Y~)>9-?ED!CGv*xYno2GIF1A3oFR}5I4+S9xPuabn#u5IU}}PU0gtMR zkw~HJsaT~#SCp0OA0jS#jnsW_>?wrRt(?9Zp_xmptGtXi z+pk4<8Qxks9fQ9Zs|I=s3X)PIT{DdK#54YbGUpeILo~XfGMa&#Hc0GR(H(MYH}kbS zrO#DuLv1vj>gwQ*GFu#ik&z?LyI65n3C8)`1>vX9+KE3c!`){y9Elm>U{2L36WxAW zG+GKt=I8~RIzx1=&c3tj1cOzPDWI|-Vbfqi_*lu5%OD{O;v0!-pcicVlLe{LtRYas zrpTc|RWxQ)MiyK9xV2)33&$EYL)7b3kvB~mfcOC~uzsMqdHoP9G!W`Mql%AoaRNT8 znntGWGA?4AbUkdrZ;qI*o+1?z>#fj~{=jmz_BU>Ufmg!7rnG{@N79INOS3RA0%CXD zz05S%YsPFn{7u(oIa0Bf4G}dqRKj1=;g>QeG$Gcm*xp237%N;Qzi9vc>X%kkZ*QaT z7qRjo;{+^^z*nElf2{zkBAR9)JcZ4572~7r|>)mOKga9 z>&xLILekWmXXvM=@!nmtF2Gi)V&xB zHEVz(3!f{PW*JEa+=uXql4x~KO61VD2OgrqQLlewlk$|l*9P<>2BC7-bgib>h8S<8 zTFx^Itv0$!_l#*8pJ&HO;^W;eNkwMDnJn)Ovm*`?3*n}C@@(@p?Jx0f5C!Iv;P^zz zempJL3hq#ZK-yp%#K}_SCjX_&F1lyJ_;saeD5LRrG$9x5BP!>a8_^L>QT^Q7a6nKoL$76DpLZS{E0JnR|CpVyuFYTWl-#-n2w(ciX>C zE%Vw5C5bj?s)_22-L>Xwv~}&LA7P`R6OPVB9fed;*3j_}s zC`%0v2h#5qFcFr~>`hh$*|Q+-U6NM(pV(la?wD9y71&4z&3FIh6|i1TXuGeswC7I8GCG9GIIQlL{Eyh+i)CMM6UK%mK4zn0((fRTgLl*AH&4G zdWlkAFYWXiCsT0avF{fkw}v0Br@q4do=hqEo_8a5N($`a604 z?CGF*C8P^95OkI7t6p3PW6xR=x~fl!{r6MH#T+W$dW}i(%u_AF_DWX1pu&~6Qw0U4 zs^juQt~;tWX?jd%w&D|rF#jr_kCiMssaBy)tG>485{MY0fp7bq#aNP&qe>CQA|a)zkWkafr@S zq%GNDGF$6`YC(T)>XMt7wmZGHIsqmO$B-mBOTdKPL)zWey%-4Hag=OiJHMuaqPg8| zgLqlxt>w|v98AA$y=3rm;|%~nI`>oTDP@k|k8(aGLo_(}=OXP*>YP*9oKCf_)|$-B z%2-?+@yuQQ1&jS-p}vrZjkm5}9l1+KXPpZJO4NBn{R5MKoYN$>JGQ4%w^waiyitO( zYC{7}L-d-%qfB+4U6$!Tp6It`aI;-|8l@V84Ft*nBy=m2PS87>`A*4tkZWaV?Wksm z-U&95`rX0|^Z4DZrcF~c&mvGN1U&6-gXRK$TWY`x9H)}H6w@>1)>gJ1m7hwwL67*D z{~@}i*6blt^nvWpVp5$0cTcSPZ;2|EP$8*w1zOM7jJ+~kP1M7p{^Id6H;w-y_ z$@1bS*Ua#}tUDdJ=CIH3jK2uxT%K9>f&VDuTJ@`>5}L{y(Ha2x5THld@J(TZT%^Ry zE(H2EGz0?b2%@5nuJ44PMq{Nd37wE=871U<#;yf=;s129LtQhZkJvi`9!p~5HMOEL z8j}g*L@`5c`~ner^9&9MrCO`AfbhAw4|&dUL@o%YEVhBAtMj4&MgWa8IP}3PMD=am zINhiV^ky~OYRK4v@C79|U1I>EZ9I%epsq&PH5+TA?+suC#o??`z$gOo-yLZl)~?(5 z+fI?S!1*Ox6n93lU?>8IX5RJVxW=9{78~DYpShsb>aZ0C87E|(xi#Go=)W`z%r!uB zbL<_#S8IedJTMgnP!Z5wrOT4taQOVzMNUUHaQ7y3e1+KQrMX-Q=f371%bNoJHX=>#rqrTgM+XN@`SuAE>Xyf$_6ASHtH#H@jnCE>3 z_@h5!*14i(+X$U@yBX;3aVzIxEB+!vKm5m=j%`(KjP(^uFB#Jh^xKeqE9&Fr7dCgP zjkPpQQP&(dNqua^#qf&xv&wpTqv^8Rc=_v@E`LSC<*#bC{56c0eT8ntT=@z#PqtT0 zVqK@@&51^AZgyyV@T27IY#qu@$xgY(HVYeNbD`=P5F5o`#eNw0WXU?YVw+sCOuiM~ z7Mo<(q6@~QGX!XDH(1}4*7SvT&sPM3D@=15#fF3~NJ@mzKDb)-`x`CPRVNoG`**h; zt%3IYRXUewYA%473a>6@wiYtl(o>S)r9C~I>ogRrL?leAnoyhJ%t~hweW3UZG}74! zKtXet{~3rTm?k+VS2Iq;j3qJpPA4GgQZ`2>aj?`Rl_A=>Nd z5ZwNeY@pK0odYHm2vr+8M2AXtsZcyb{nq)d&cXC=XM#I&8fSPpx4qcy=J=*q*Us`y z5p6KfH$}DKOy3mUhI74!u2W9gc(xzZCwsqXvLD=bu8$ISqg5+l+fXs2OLH zL~54H8E5%)X7wlf*kn*^?>14FS{ zMBVL}OlV3f$=+C-jK-Da=d~5N-KyFIt*kxYW=>lMz3{iQx`9zyPFgSDmP`~H#TxhIsG9F1Pi;w|p&Nyu;Ue$D}uPP^(tW?<0%%Z@qW)(cXq%HH~j^q3<2Sbo3OCqicaYGwfCV z?p0-=2GO?pmL1a;vUEsr3&?oGV}GC zagruv(Y<~wf)ZHZMO|1ki%Gh0GuT%7;`rIwi?^e*7iT9|uP=*PY!$mJyxl)FQ*O82 z$NdTrRlUvLs#5jp_~qH?;`rpOPEcbMg&Km>vuAIfHx#zs@*UG?Ff!HAa9*-Jm7>Yh zhPL-ij3Y#klP&y$8(egDN-7^~GV51g;c1ZXSkhd9n5R3r;9W8M|Fie*?QPr0!ua{y zp8_xAZmeBXzU0>9t#^-NyQxoo(PKI3>C^4wQX(vILy;^&I#Cni9vBGHc1 zwa)u)W0DvQ27|$1Fc&X{Tk1D><2{eUg)pYBmHV)gV42aQdOuHXq}78YY4r~SeyzWz zG&J8Y3}YW01}M!5^5AvuPemNKEo|3%xJdKJl}c{PhYf#BF97|q>LHZ)<37!&!VU-` zh{dzv#!}OnbQZSh@yu@ot|`4A?sXnS198YY4WeM4&p|}|Vz&~QPGFRIQ)qCJ#gdN- zE|M7rW!%+MK%;hBas|tLsYI3$sZ**FYe*?BkKok%xC~m}g66C7u{>>rmgZ@x`&hF= zBy_sd}xbxdqMTW!*E_k9^I%i5vYqm47e z3d0nA;J?Tg9ni}fJQiNIhUge4vFE?`LcEa`)iW>^QPa`4a8@)V_+Zbrp5Q)-4;Zn? zbJpPl(nw%oq6wdO8*O>g(c@v`(G^*h1oS;{7Ds};rNCN(0458A_aVJOtXG2C2`N`27wK<27b@i90FYRKnzu~-eRa7K&pz1T0ZV|kirjM7;ZgDArzG6lHcMc}6y2~(lPpU8LILW18aR3s8WBW2g?pM&QD1Ta9MahbUbK)^d8HPY zq<*nfaw3hn9t&0_;FZE}Vg~tJkTG?Pg{`z$534N)qEEX*t}8Q6>a-9{S)l@&64Irf z0B(@zTYy&Fj$}J95(Pnof;bX>;|DZ0iKY6W-4re@(|D7gst{JalGq1v3eq@_d^e59 z0dvQC$9&cgNc-a1G3hF`JtJ>2tSAk z8(`rWQL@-S+upVy&tM6D{Q-J@2oWlj%rs75ngvC^^BMa@Pw2}B&EG3)OLnyt7GJF| zC9kd_vhs*8j{&;_DMj7V;70v$yQU^0Q_m{qBxU?EOFCzW#VPX9S7T8uS}9n}cqA~T zsTX6#s-Tx=vCE5wF0}EH&j*oaSLX%xxcj*4L)+K9QDVS0(aEXk+sov{q|@`{oYK-*J5o0CAZHN(E(iJ)Kf zzm*d~KVz@8RM2F!RTb#iC#(Q9k{XU3jHbm*`$TYm`CKd5I01#V`qg8)D!wGpNMe5b#g7o167eh1V0qV z8kmA{8o!rPfH3)39F)Y(M#Zc*x|P6dRj8~K#d2snw~%bAwy-!=E-3`v=>3Ie>uG?f z?M|b(%MfWxHIy4!n*@HvJ%=OiwHqU7z4{mOz%op@u{YgBRiN)VHmFQjG9mzba-XAp)Z<3*#D}kP7{MPiADzmrH zqN{togDaG}OO#cvQN(aywu%F_3et`ex>Gy#WpVemZknCF2uH%H#?I9&&ch$nwPMn4_r{UBo(XV{+Y)-H*aRj}yL#TQTtv-lK^wSQb ztrlg6r&4uA=qJ+_qIJn5sw}_S9aA*~?&P#ue_mbf#43&6erjEs21_1a>khESBW&#< z);?6}Agja=4PlA`l)`AKBA6ZqFDxL6dO1QyQ&{qKF0zRJR!j$-4f5%4_F@r*H!>@;U4wE#qT_2obBy?# zn3!UBhl|@?m5GD>$ zLT}=LIV~{uK)mpo2WBvw10RMkgCI^=%44h-csC3dVE{Tf_8oyxg!2&>4))I1i$!yF zsA3qbU?V-aVS10~17HnBA&gI{UY;=-9JK{}CqMd!Xu({n9M>^5a-2<8#f^o8A|9F# z$O#7v9#I_p_!{I9!vJhxqA(Yl9+vT}qbLuu5PvrRCW#WCVOqud=w z^b1oFStrA)q%z$qPl?HH_>SB5@ZZ8uw)ldIVi#OM&;Kb6GI$Mrt<`M&g->m|X~%}#%Jd+P~JS;0u*-t4$@ zn0a*WNTphsc|nL&8?clQza`CuB6>jUn&IV9xDaMp8jSO-@Z}iAbI8(I$GH!8c-$=fpjo8!lJ^nSW++5={1s2kvzc!Yc;%3HgJ` z-77gU0g(OA6c?>ll8gRVwIIoUA*{oyJ6h z>rv2KQV2Zj%@_&K-l>TYibMzTwT7}K^#RfoAJ{_acz=UV3(fg93zZ-#4t zNH3efqc;fw0%Ccx)s6vk&FeZ3L-Ji#Or?nJx5bchbS+ie_!*TGr{&(Hcamo@k^d^m zFXQ(xqE|RH;D&7yrMaOW#t}P{Dbpsq5P}1mACRdgL|q5LHBIBd2^Sz8gddYxh#FK3}`)++k5<;sq$4V~SN9Z2~y@aPUErx*Sj~TzD@LH0yndf#I z!!Z6(m0gL{)SE$TVl7f2nW@}`D>9Q6hFn@a6>}ac<%7H=AnEm`+|1-TU+qA5VV1rT zVvYQL1Jkko#grY~#Dg$E+LI4nHkql9Xc0MaRw5X)3^~K1WB@zYmD1t7hJd6&Ar}lN zCafZJJKnm8R3t?KKLnW3@q}T)iU0AMvG#{JdMY1m+vUEcR(X>1RwU$S&$QA9>4TpJ7iY(3Z}trI3J~yNlEMiOD3KGG?(}ze@H)rRKiyOk)C3WE{X)EM zkjbZn7+L(oG`I;uIE6=O;)Qe@)NDioW1nt7#Sp|{zj)FNBsuTODMYSGAQyhh+J3xl0s>tOQO&5XmJ&#Bc6>)Sk~`lpPNbbS&`WGkRfYdNn*g)E`?WTFPE_ z5y#p0K?uGpKO3oAcWpVO#2?IAbpYL63>nU#K{9&eaUd{051RX^_n3C!}e3LIM@N~c%s7E#5Bo3mC6(D+4FQhn*NNv|>|I%R9?X2`#H{I(Y<5*Fg%%~T~ z@)W?s|E)Cq->PEwtq4~KebevVM4IhV;CB<~wpi~9_)@%geGi5ZZ!74AVczwfnj^cd z{oZACcRjN9fNm?oYEXBxE_lc<-{xuXwTQW8VcRs&mjsitxM9w_QVh2(g4-0o&Hn46 z84RiW1&!g}k>j^_m=}T;zg-)>-FfVGr;*z{bgU|B`yOMq?>=JN5dKh#)@~51EzwPl z({3H5-9e1@T}Ei%X?*q_M`zznY<86>s|&|ANXv3acC!v_QP@>oNRimeg=@k0rN}xd z0^1Z1ZHtEH!F6inbt&$;6m`8sALVFkjUuH|eB>jV1&H27#~*|ONA4Q0DLwcve^mC6Q=muIoFsVj-H6WL_;fm(Gb zV0maP{g4l7#am+ehUs639=XYkxp-N5#Es^+zz1&r+aCGv8}J!S@(j4X103L9?^4x~ zA%yXT3{&a^cAbYrcAO_L8qI?1j9rn>JOt2WLPY|%*cUo*XK@;M;g;w7u2dbtWpK7ihnCX)5l3qlqihfcWS=6pb_6f7 zZQxhHqwi?jW!%k&9bu1)58XSQJ<)Z%Y?nV*0r!68U=WCE~VDcx4@MivwNy#<4IN zeSUegM+G7;Q7^NRMijxNSZuKR_JTolw2A>7P%%e~T%^oBG0mfhGi@PUH<%>mnp7Yz z7<+xZ9GOOZ9j9~4B+{-*rEQ8X_$M1oa!Ni3?E0K)?>%D&1pf-?H11c#x^TgVTy-TYN?jH055|b8DAi18=4tBCQaN zP>=;TRHN#d(4p|GC|T~#i|Q_8;(bEz1@SuNQ>MCn)ZV7^{up36uV=eX!lEd@34RtQ zaTre*qa=l%e-K9~OT7ReiuCJZ@&S;)ASHWP&qKkHtCXDN*tm%FhL6y^HzDz@7+V=v z6teswj^872BL6A$6iMK#$uQ?$2DL4XdCTJAUo*0&SuQg3s{PqXPn28&@eMxO4VBt@ z9G}bLD?mPDRrdrrs-Rfem|okCvee7qbU}k~`Crte%YA_1oRwn2DlKV6=9-&IMvUV| z{PuW>>7UTJgb=1^OXA?IC$v8oQN(y|T%aP)WgQLgy@-i5>1}Z>4L~YCD=r%5-p5g% zPT?NdeesR_R4L)X->m^dzZJb|1W#iB)Qh|+xnp5Q%VA7Bu-QX?L0a}nq5wy;I1hb1 zC9JAo@CT$0mE#5Z57{}#c@X--xuM92%h~)oNKr;262z5f8M8fbp87C_{sr{>g>gJ+ zGJ}2|!t_k{eG+fLMojO&XI@lz5o1LqK#7-4X3{p+Fm}_Q2T_1B5}2yTY;u26S0Esz zl9sWxE{Y`fc>o5nG-hHE;+gVz7!8T4%lg74KDY+I@t41`lW{pp{Wla}XTM>Y@!QNx z{oh)y7B+$)n!3E`%$A2xFpY>pAH_c0dJ;sKH280hkLyLg>qS{0o=DTK4z`jkQ5IB@ zM(*HGM4!^A_W;I{n`(ThGsRsXjsLfV9e${xra6rA*(-lZr9GcN(=dos>tF(bnnkaa zWTpbg_i&-2NWG=;V^Yozi;qhDglVro75{z@7kj`_X9Vs-*ZYH1b#r8t>9;K~W_Pj% zq}dyecMV}ph%*|?_W%^{o$@0k84{lyi)JL|ontLx1@V57;H6F2aSo%lysc<v)o}-kgyMEjpIecG0hu9h2BUVdtIVpv!3460`UQrZ)ln zu*Ixk)X)`={|zS@+M*!0Bw2q_eM}-;CY}70%};fc?g~cC~oRm5e< z3Ys`N^Unau@*&yiutq7(051i&EMMSN&--$d6vBC;uto`8t16P_5msHz<6R^^<@ zt)z<)V;43ymhRgGBg=5*TdW3rRpnpOkeePIOdh6#iP(&Fw~|X@a^h5G53eQFxL}YP zfP!f#Nb(2tCEyiM|GXX~HX$;s%Jk=z?AmfYR~3f6u5G0r69zXhf(U^mjWPco;Vp{z z(~)(>Llhe>`>Oi^VOigLA~1JJuV#+om<w37C(D3EIfad3 z9km85xoeRg+V(cX%H7{)hq9l3cx=Equ2M=@M z2-J)#M}6A_K)bcm9)9iWX%Di&`e_fe;RKnIPJndlDE}VAY8Z4T202?ltc0e00mJ(2srKotOEtDcLck`99V_qpQDi(xk z0X^F`Yly^w>O|fm%YIm@_ExE{D@njAb*z1HSj0+Z84bHqOTN8O1X3AiZRc!{w0VCs zV69?OgZ4;bjxy4Uq-u|{NuC%GmT|D6iy2hJf>75}$uUlK-bN+chHQURo#j-xB`>r^ zoTn@fCi3P*Ff9v_lHO~thEgOD4OJ>W5V^;ttOT?>{6_7E9Kz%y4?cH2d(J7Sp>MmU zU}+snbmQqBmLeSo`qdFlAYSP=NIlI@<2=fcDR7HA?S%m%sbD0c-pCEDRyLieNOp>p z`!11}d?8Ur&W4twbPLVA6mIEX@gQ-@D#rZ?mEIcAWEpaxI>$d5mHILB0BRvG)UniC zl!vho4g-|tWF+8q?oX*trtUl4%z~Wek(};YwkZ4K;@Zd`+ngQ}f2<~f+G42>X$lS# zt~^PUESJS<6-F67frhQ~c@PamI*!vI3g-D7MEQIS)2#%i6BuRQl-yj&+AQ_FL)6hL zg~SNYU6+(v8!~vV6<82a+}XgX_puEsb8kW8Bz-6+7*SBs{N-wHzC=xtB6tH-7J?K) zmuD9D=1^>{mxbHCfE;PjkaB|xkB&xVGX(ZU6{j`Os>q?<-TfC-(lJm{Qi^o73t8yM zpU8Y6)u#tlm6e`60Y5;`53#}~NSMY6OtU}@`JJ)P%2i}^wE35+N4Az;8xv}#_1qVr z**|oQm0%-QAc#11XaPq>WuO8}b0Hu#+(@hN(=O(y5QUyg0VyF!b4b>;5aRZ<2@KP( zH3EsDuli+6)tnws5EAE!)-g!d;V>5|OB|AsG!HinNuYa2QAiB_y$2zQX%{g_@_ask zI3yXtc40{JK<+gZ$$;|RMj{zH{KA1qoSj?7AxWD~+fXFdW3x!4ntm+NNUV!hgOOP0 z4>1;r6R}As5?fw(ABn_}lI!DuGjcM(JSyuc_TmIZj0rDJP+uybC}>dJKolqlyT8U9 zmEls1W*tOJl{$WmmAa=`DMs&hp;8i;3d2CFh$dbz=1&yRR1i{gdzUxv|Hzmoi8AGo zrV@1?!hZx~h>^m&LNjpM+ z(I6*zQ!Ea5<=ybX#5r+fK!v% z`oi%|1{5E|oBp)nO~NSJG`eY~UelQ(oJueo1vpgz{?i9J>2jnp#%ZP-%sU8iQk0j6 z7vUuC6P5~aGPdq2zR3uDh43aLyp^Jxj1X52ZZbms&xvhP7R&<-Z4xqg$;c*i`_2NJ z%-~mvYcfMzEv(55bM>euGu%IOP}3-kKhW!1n$=vmj8AAi%Os66I3WcFXK9>IXKMTa z2IPw(Fxx{h>@m+>BTajB&XgN6TvGGD~ znfNJF+m6DgOrV#Ko-#pOC3wmNZ`If-6U;w*=oHsGmyDdMItwU%5mowI>)1AT4 z+M?Z6_>_Wp+vq7x|7e1D7co=}lp%ylkDFpHQFc9vX+Qr-F;sja+J{it4BLP9Fe=#v zvD+vr?_hnmNuU zD|yA%GZN*l5==vUR-^`Z4lj>*DenzZlZ-n+Vs)Q(73E>L38J{v9ji$#E(nSH%48PD zh{us|HBa;n)4p=)CqZmRcaNL^PKo#O@EsV?W6CM@6BTf!uXxOv3$WJuQyOIOJeo9M zJrw)_m6^SuR_z9JOUD-c0r$YSZ-NGcl7sc$9cWG&pe6{fV)gL7np{XE9t$$0xC)OV z@)h)fmu-S_q>LY2lW?g_-`HsEj53|FZomtkGNXJ0dgo(-D$2)xkP<(k1;6TMSZ6Wq z24t~7H;8}_ZCGHa(Y zN2d4Xut&r2O%3}00dK92s9o^ z#v~aCB9wVtzLdyII_n4HIf(-0MsRi}`ezm=!DPR9;9dtIykd}_kUy9(zfzT1g`V2w z+j8{8GHpcf!bdPOaWyDD(J?6AFdQsF;QZ7m#b}dlr6N4L6bH^5?E!~L8p|efPm$nS zZ}%Svt|9Q1#DQyA-%}X)Da_Jfg7gsZIeo0gfU}3X224e(Crli}6bqIa%n_O4G%E^X zn!>hU(_K>MLkxuiIbuM7WW-Pu|5-lnv$Eq@rlk7D>vA--Hzs4W?z!1#AR%$roDF4_usoa zFKI7QW1+G0vrzex$9^Q{Xqt|1ztGsKUrPreQ|II&y2?MVk(603*voiYWaqI&;EFpz zlhh;Ov{{<7s8#)wgizY~^a=FektooG8OrwJjXw?7lu%;6g^BQI}^ro66*r}CsWmU)bW0o-OfvR`So%^YA|1_yFd1BTL zmh`(eH}A^v+6;XK&ucTlm0YjQAXoOiHiP{#&euCeceNMoyhoo^dyke@i{{n!z?RF> zPS+Lyoq1hb;IHC#Z2`HO-?atk>W(ESt}$j#;uOYct2o!WaRO6Mv?IS(?YJ3~5$|xyYWJB%>UtKtVeOQrJkH)Na>(nIrH{ds-R|FQYc*5 z^Ls3Eug0EHGaki)W&^}6@VLokpy_r+0V*RyWuyAGDRELroMuQ$j|=*5n&y@!=1r22 zqzOaRPR0|1a&GCXrY`}?;1*!%pFX~juwZA9=Ewxm6e7H2R97$^aC4kk8mhO5rrbt$C?6W?FtBELPmbzF9Xd_wnQZsRA=f+FkJ znrtn_z1ns-^((Q%jYyLEfL>CjIYF9*7pN^t2J3j)ZB4_Z@MmJoVo0Bjg$Fwh68VAR z5_bFs*ALJnzJV!~G6lYhbzAGQg3&c(&3iCR%hVDVg~b-hoDSOV${GqO0Z%)j9LC^o zg2@a{-t%mac)Gj@KzdVim*Np)G)-fY=DMuTsm6SAiY^{)5vRpW&(s(~Vhy+=V^uCD zo;;zK0O>#$zm)-!21i1P0RDKBTro0|b3rqPVf+D1VjqHW7*F04R{?tc>5v{ADxfy$ z-66jkAE(~rJuDoO$){4zEP~}8_#v3in1lI=m%)g5=`b?Dk4d_R<;5Pm-nt6uCs*to zyElhk^kV+$-|=|gnJ@kwkDXia53t>TQ2@D)Nsc7x7LDyXGPx1Ffhox!nNV*t_NH`^ z!@tkxb1z*`^!eo*2$ca)<%EnHs{sG?`1{ZKUFT5*L#|seCzLHJT1am0x!3i^7epIAAeI8^XdBN-)#LNK{DB|1eIGsDxsx6-R5KYp6xDa9}<($!? z`~l4zEtOE9d-CljLp;xBCWNH{s|XMBYzCu@#d@m#1l2ej=tiD14NG|_VKR>65PAh{ z6&+?XR)^k2&Og!w7ILAKYt!X#Q(^Of%06NMLGX!0jduUx%(O- zj*5Z8*>4g9)IxNiKS7r_?83 z8yEl%;dqB>=bP%g#3Q^-czlarw4z~^%!3R8HaW&fqRyAHuUmRs2?_Q!(Cy>%=M3eAt_jA9s&tW=K(^*ONkws zn@?38*^*V3-B9)hZbrjD`2u8n)d*%k!o^ZF{Sht-2W|$A1Q2`8wuy&BRj1g<9UF0F zrNK#A(NM6)*Qh1o_9R(D_h-*e$IZ|~@sy4E;9>#26 z2hDYx6yozY29&{%*&v0Ure@L7qU|)Tq5}1*Dwd5d&6gBMrjj(3>&QT&hq4r;2-H?H zG?Wrdd?7{HMr~a|mWNm+-dd;sFl(bI_+vROqTJ00gKEiPC=7gk*QC!*13b(f(;M%j zLwvgp@7_iMmXXezpu0^`B5}>$XyjQM1wAbEnkJlEC44npo8Wo-MOped3NldS0jp$d z66_Oc>C@;vTqa_R!F3$^Ff}QQQd$ju)kqRQkiA_5TwVte@j5~oD*))!Od|LHZZLI~ zyRX4Rn8%$vNgcjhQ}VOfcwLiB+e@dsql!ca1aKcI*}{V%I5D;23ZCp;#RV^CdY~rY@U* z)n^>A-UFXO6huDO=bqy+^SIOwyCp%gRei3#VP)%ijz*FwZ@d8TBb?-T4<{sfpO4`r z3&9j-^b6N5?#A(KUqF&Rp-?p{QwQI83Ed3!`R zP4}S?IOXjTH^f^b*S%FiNoC|_yIs}rIi_D6!6@73$=HDVVQp=<56;JUkF$^nONu<1 zrk>9zPgFEUgcgDke|~a4IJ|m2I2oKB99>);53fFbA}(C(0oVbzxBJfeMh#iZvhVhm zJQvdO_SVIJ2lyXiF}gAMH;N;C(At0csgE)*%aO7N^n+-cLWF+V{-_#0HyS9o9^2O&69;_ZL1#|-Wd!^72g%(6l_#)kCNrR zN57Xot=x_5AD+cN9L8zp^zdfa+4kJ)sT;JHXR~4>zP(*@yZxhS_Xc{g6%BLiC9PvwDi2YpvEolH|`OqRg_QXnS!rN4J1^Fd88G4R2{X~ z8F!Svk(pz?jyd=ckjfa~Gw?pV2k!SzH=ly1pU4pxtg}sghfxaL-rhbfvk+fjM9GgL zI3czls^+r^+vFiDp5_!36455iG@5dr=21rrNVRpitY6nn=fHKdYysQ={{@MeX#eRM zyn*Rc;JPrn*>^0<-T2r6F3l@x#)G`#YuM!`Mq$aioWW?53|p1cs)4Gd5C%N4GMX_@ zNY|a=o!SxNc~gL$QUCQT2NH-JiXO`?(NVR&|VBsL}R z7a7D|*=cGP7&Avlin92rlws3RadUr6w6O%6-xvk7=r1QwSrHUjX9w zxAIL7XB<8zIGM$u-n8%)SZp?v*mrbeMv%cd`sJ^`_E7>S)Qtbj_OJbjt(DuS;4{cl z@D%^wzoMr-N8+&Hns1#*JF7NbVQT=KonId9f#W($8j#@wCLd(WT3^iAPhQ4j|B0oB z-qV4nf0`Nm@U(Vi+gFjabeCF3^3s1?KE?8>Hwu*7%EOT~#cyx6<)Q&K0gK4XuYo`-Bf!ksNJ>SQ3 z2FWw_$F0*Vp))+cxYQ6@6%~sFc0@%Z+u_`%f%XbzmMgLAjF!N4$ynCKU{=*u8)&Jm zc8>10iq3b61~dDi?OZ)oIDT|=@$UG*!1POD(-IYYBo&{3`b7RewODM>b9j}o1KT}t zdy8ck{STdbEL@zPa<<|OSqzo) z2^cSUHmtqo6KU2}*yKsx8Qi@VFB`k>OOM~@HOzs%*Wz0?^Hc|uhR(CmzP&i1$v*bB zwgf-4>7dBD&1^?;0;%zc9@3#t$Q(q#1LHLQfMD9M;s)J`?Sq%%$wB=z4#OatUV77F zB~m-rGA)(LI7>mObX8d%Y$*<51z1^VYt6av#tQ@A%OGvQyr~-cf7bc`Ud>>bz!def zBwW_VwA%mo`LkC$ySo4Ht5-XZ{=fI}`}Aq+uiz$_?~$O7>mY>WmVA!MGMT|W@YgNE zc3Xd4JNlS#cUn2+7Ga(K8vD*=d9d`uoNHlyB9X;`&y_@pOShA)zpe={ex4Z-kI)Fa#l7yhtU;7DyEX^b0x#?x#AF!X6IVNwBu znmUO~=LXAQ$8I?Bc?hfbz5d$qHDFhX6o^nZ=(Q?MEtaXJlSqjNj6B2EO0!~LsivEJ zAJLF@^ccZ!&Iy_{$s)VuWkt?>7**hBR%Besg3YYfnzmKazGMKRJ%>TBj~X=*YM&0H z=>><}PU)ZO0NgjTRteDiFCkS1-X12KVg2vMv(Ex=SLFf*rad=k4Q#u7UFw0Y_P|@fqRhy;TJ1LxMB{sYAv&jQi>zRGULIlWP7jc~F%9b+? zzs24eE96)ydI7pT85zT%L@;0Zg-cP7vz+>Vqv#1}l&0kQDy}$8%an zpVbki^(JWw%o@ogRpqQ5SR#Kb4-fxI?k7}fWnSrZE1*QBURyE^#FezH=}}7owM7=& zWKp|bGBOnI=?I^lC-Hnt&eHU>RiiUAi&DilO0n1eEZR2QIcu9$@0unvO2wAwR%?`{ z9OxwiSWFt_+V5j{yISTIJ?He8F-@HAf(kP#R)b*JOPn7s&Pd*ivbL>8BBq$ z^wFBoq|*WIvroO!)&fLRE61q-6Jrn`0#tR_Q-Pg{W1nHhjs2FUg?C<~xNaEFR~$C} ztXIzhyf26S!)XuJdU}zzDdGK5r2j%v3Tr7BnwAG`gXNmKj?=l9RqV@(gQ|?5?%GOF zvCI##xrKZ2A3saMYDBjRPqkDgpsbB;;;@GeoR@ea-+6$n?T9Fanw1XG0-XG}Rbp=#~&A+VFH z-Oi`6g{kp+1NCPKD{f0BVRY+^L+IeF?4fuK7=i{B60OW1JO_y;{CRc_%7~|4Qg>g1 z+xz1YZFX>K6d39^0y6(np2>zyltD@+WZcYUW9VLPV0!VylLb5Q=)HPty$DFuW2o8% z7---+loYMD5TPPpVd;#=Mrh)v{Q(YwLP+oKV9H#j*y99$lspY8oC!W)%n^qEMi zdMOCrvEc$dJs?10ry%v6S;pGY5Hu8dia^p84lczLQfZu|L>b0mFj=teMN1%)j=hO^ zgJH2Q_kaz+CXm|DtS}^u*z!5SN@@Y-Im+;ENz(3Ow0VL^0!u1psRL|EWOhlU*J^NS z&n(gxcz_U9DN5CN0#woXFo1avev8QP66z(C<^4aDsSxc$pW` z%9e76eV%BB)Dtn$XhY4=B){8tK7Rc8(dpGF1@$vU0@JlS5KLOloQg*jK`aElbg@>j zj;9pc!3~Asmf5Mxb#|KS8>RhK$ek~jIHgE&RnD7IlQxAXr>aQ1Qk8L~;7nz*Hno{5 z#6A<{W`qX@JcP7%4#;M~2e_$5 zq{b-_DD+q6hDg+k;!{!RJe={enHQB4DBweDV_vB^$cU|_bzW&1XjeIyzifJ9uzarJ zCV7q3ti}rOwxbqd=d&{FVAAP?r3rVb@G9}vJu)y~PVE@ibU0p~W6RJQaw~6mM||2| z=34p9FvOO;CdOLDWd%X*n7_y=xGEOochbXHB@9*P zCFO zt%jhS9JuT&U~SlhzjpSl?u43^s_`ghmQN=Uh}Ow#Arx0*v>CgRY{+En^Og)|Gru-r zt|m89Hr6ut+mx-$t=q5^gHXd+=6(cMSeP2A3fkq*F4hWD7|bz{x^HrIDf407PzP&a5JKEaY`sUeSYx*yz zw`T*v)3(%u_#b7c%G}!A+&GJGZGD5nc;bb#7-f6k_**20%s5&l7S%@Q?kS{?2oE+X4LpFY(4f7-RuN{U7r&WM$y`Z-R_hgj1a6aG$s% zr^2z0s-+RF>AH*q#^uSV&XuyxbMi7oHO`aD9w)2o6P(ru+s*F!eG>f=O9g zp%vVD*pL~UVJWVNc}$f_AvP;SbjAm-y6&tOj=6HNuJU+glF5xK{d(jN8@ljJyzbq1 zWD1Er4o?=Cve~L~yDU#?K|FD-hKbj()W~Nc`${ZUd{^Q&g>}{?&9t&(Mc0=)Zl&;R zee>iKtYgD6&>dC#JytKHa`3v(pLyg=gR*vRP(%%VH`Yqk-kG?N=Utu(K^l&w+h*-A zm;a|O{}V%LOE|Fg7v8*OCaCKCPun}spFdagKke?k+TDH3|8yTe#+LR~SaL6@Ed_Gtmy;z8p&v{k6e9n|0}Var)Y4g=c*pWQYDG$Lj88Lz63D`EAe z*XUjTn#zBk4#`C~leSwxjr`wzxwEaw|J`TLoV3zt;$o6cw zk3zpAp&zFeV%e5DP1GUwsx}E@2xenQD^jLWN9`!qbffHKPFw7bhKXf=paf3vG-Qhe z?iH>mYk(*8KOXLZvp9llfL2MNbLO(8nN1RxEhlEvD%C5{$y_Q_K-*( za0mRDrJlG;?`nrPK(8*nuMwEK!NzH&1etr;WJVX}DnjG|=on4+|HL0Jaq^?Ty8VCW z*-LHz-+r~a6UkDu(*&`1Z+*IOd&qq=$^@7rwoOk~?|BFxLI3ETXsPBD!A!vLju zf~Dl^+@Hd%;#Ao#aQ0Ed_|H04@}1JMAz>Dt2T|b_O4`d$jJu+_Srw6#mfpv=k*9U3 zJhOLdXlmZW$h1kDm2pwl?P)KIo&Iat)gFIMe@*v)lzADv&O-#V)_Oqo{{QUd&a+qL z^Z#T1|9knZa{jN|;ANh%?D8Y_$>?!+7ZeYd+21SAL}6)zU-~@!pp*~EyupX+84Mf^ zbd#$2xGUp@#a8iWHdV00`Ppi=!6f!iy~vxwIgB#uq+-^U%HLJ0WqIOz860J)m%%Cf zRDDLpLKgq*&CB_IwB}{#C&hh8=Vj>T`m=@DKi9{I%7+V%xyR2(gQAjODNh? z_*-O)&7?b-K|c>+dZu{5Dv!;UWu>8_h#3b~&Xv7aSr$`Cs@<<0hj)D)L_xNYn43Lm zY`v)7@;UtaSrv|MWmLqxV^*oek2RszHovI0kkRxw2F_#PhABiaBXFp=c7P-FZzqeB zIE<%@AK^msl`bCIhPSgVb1h-?Ea-X!63F`)MHKt6@eqjPe$5zUfOG&X=I_0XXT{g= zG3t~p8+}hdwT;lWotOZRm`+oCEI;jL2`T+FTt*GhpT#H}gn^oGS$fzF@^UZT;hx1I zO!du3de{x_axY!tPS@KgNulQ-#1YC;FNiW_B$iLQ8kY@&?narUL7WEJ;vn=8QuoNx zEAvst4xlLxX&z<492y|#Z;Tk&n>Qvx5m|6R39F~9#QVGQ0iEG^9+XpimZ1Sh*s4DB zGg{MGGqNU3=Rrg`{!Qvl;1H$(=`@byO#GFf8A;g?a0yK%^0lmM>)oiIcde#s&{sP` z*@7taPD}h!xHE89d^Zab3FJcJ6F`e{nJo@dJ+8hCmo>slvBAV3T9IN_%(hTcU-1t{ zH+#~b1;VF4Uk%R>ug(UiN2B53;7Iuh(7?R!(|Eq8y#Tac=>@zlzhUq28E8)&=?i0L z6&^pFk1nr>_ei%`up0At=hL7Y2ywSGkUphF!%p$p0I4AC2iL0T9DPiL0bSaQhT$A{ zO0i=RhzA2yLP1siRp26Gk#w?M2VeWbunJ3<*MT&*B!Yw|KCb{V4zkFb2V3PYF$gd6 z^#!B1*bb$)MG~ zY=c|9JMZk4kuEW*HWEMZrcsQtU~(G!(2O@{sFk)nts@50dOS1@1+Qk~Bv4S@zZ5dDq$U;9bX;~POgR* z$ESmfpNVQ~aTC;v(f9Ln@PVxg`e_k3pI+n73QgZ7|*>RvNETEM)v8E z6a*GqI$|Nzb!&iiGdO&Aba8n+I--Yy3Pw<9)$6Zs=nT}el2gJ`r$P1P4$m(xug>0{ zzCOCB9e+tDQL-#FrN`0P;PuJT)$#D%%X(?GfXD$(6iX$ki3mC#-n_JRsEd6$<3tT^ zI;)E$81=Nly`*uRy+tr>N(y6lJhMh~sYS#3e}oH*7n^WE3&jj?uo5`mURW2x|)a-ylH#Xp}{WeOi@A2*`!R zFxvCjhYA)Zx*4YMlgN=QH+Gy_vGsqK7lW(sPX=#B)|p;cCc-+KcC2i3)5LOTLi*t3 z_~`7i9(O|jZYQk8sEzD=6y3b@QeW=3A2AG`b8;sKrlS?RHZS(fp%Sj<-*iFt;RGLkPkzfC7yBxBZB0ef8ORb4b* z&X{V@bkrm;<^5Q%9%$o_{#047<0K<*8)h6uPzJ1^h)!mU}e zbiEp`cCDA(;>@BhZ&M(f3Zq#(Tk&J*l(90s2ex0lc%jd7x1z)mHRYOibJthG7YJPR`|LR`lPUfBGf8E*L-rdpjzrK9+nE&-&eoNeF#tBSmL@@AS0wX_&rXZ$oZ>aPlZGQO$tZz`@z-2EuWgLIZzjb_?&xB4e15jS{^|8#^uyJ~(dppw;D=v!ex>O3Rl5myOb&xF z>x4TcGdNeLga19h*mu@9rZBrgaPDQn;QKP!3(_3Kil3u$MllkV2q7#2u}3PF2IETJD$R5tvD0VMe~K$3?QeE z5;jYr6QENMWiTZe&B;F*BGQ{mT&{yP0Foe@y24-NYg@xhQ_#WZZGRp_2h@Fe<0&S@ zQ^KlsV=cu7)DW%ZN#FDR0B?g{coigQf1{^ACHf10{$Un`5KLhfCm8}xuovy2JqKKe z9yO)-v0%4}hahm)KjC+`4hSOkpx+}R9k`x`0r>8_@4)(}^Wo*-;?369<`%dGfB(B` zk}q0Tu*`(}>l^%^ zlva~O3W(YIEB}MO^D^)c_8?ARgizR@MAzWE?~cw-sO(SS@4u3NrSSKwqFNBx2RF~I zQusT?gr4E^0L`FJNC5UpgYpXj)$opX^b3Ow=$~T`1rs@bbRQfH_P!sSjHv(Qd$@Ru zyeaN6ilYmdVr%qzE0Jjru!aAFQLBiFmM!A4t<6FNG#`VE8(~u%2nK`nae5y6*8==kQsG z4$1f<;I9a>kVY8dbFdFYfiCj&c-Y^@-F#Bx;BNU#Ou(JpSN-k&c7KOFn@FHBY6lR!;1!@~aT$6HZ&iW?|_15V%#Fp;3q~ssC7@Qq`e|&Ppcb9$| z`B-;gIAEckA`iH6o&k9SBFPSRx1WDYCH#S?@d_qk0HbUR!Sn_zkKDY;0pexrM(_i0 zF@zGxaz_)C0vE49;A|c2za4Fz@1HKfc{=r?0MUcd*7@80l8uJe`;DWz!f(SRskXT*klySO+1H zFh}PI0uM=(42DOi^!0~XFqx5Rzq|l3ZZM9s8JI&-L=%&cweoVTd}dhp!TP$`XG)_i zamPPESx2JHeP!1|vpC6sivawXO~ZK1NA0H9;QwuC^YK{%_W59dK1<|c8{}*r`^03f zTke65h%Qa*1iVyXtT5>wAMQKbju9R`EjY4VcJQH!2WYt4&bqGOOWS8xAczU~|U)zyD{ z_DawHyS@AB)ua9YK7Q6iaEEo@>W#gRR|5ZWR|1`vczZ1Ew#=_i{u9RlHw;kwwD00q zBmcK|UcS)f|MSQCpZD{_Ya#WbDJnr~? zl>hJ}NeU3U-el6c3UH15fAwrzumAh(`D6W``}uvUs{hAUxvBggXNUpe2klF~;E5^q ztf9*nX}~TT58^z^?eh7!EvA!0hX`jkl( zAAVc`vJh4#OXiYbNpkWs#^iC^*|EUw5Ze)nYrep{lmTh^tr8&JMQ>FGS^&H-j3-_O zW!^fAeMoYGw54MuFgr~*;uLJGydZkZ!Ql8gJ;wjM(PipgUk4K@7jFyLMj+~ubw%z% z5MjMypj5HZ9=65W2(w!}solVcEq%3I{)Ckgs@}yE8YKBR4AAT>&Mu(mF9yD!LPW}j zWNB_Gz~62jFaUEFM^U!FB{V~NpOv%r9M{s#1)k5wD3TZ`4gYsFUds%>Wqi59vzhj+hX#upNF4S=UPyF$n`Ty*^d|vYZ zeD>^d|G$^tviCpiRU$k^b?w05Gc@rMZybcYnrj$L7X6|Ly9S~v#W3~{1C-_o7LTuU ze+sj1oC-kiQL9){tKeIXSuSIam4bZzE6ZP{AawR52CE{ zqMo-?Z-7n$l%2q6n$0kb5Jok=1-5%62A!KNm@bMc zQXAAV`nyI0`^b9q24eXOjMAyQZeNvGs%3K>u}?-_ZK_}GQJqadxXi9vb$$p-yXw+s z&xf$%+vrwl8R&wJ&3y_C`UzWBXI)vMlGs1>B5w-kFv<+&IJsU?{*1QgNfbf`u#1i) z_SF^IkpwB=u2xyQN|@Y_Kxvxnxs?lgnOX)LoxxHGs`CC+yS($}Bo7(N=Ua;Nv$Ew; zS3$7ezhpezf9)YS^s*Un%n=n%k1#2kdAl!OqI}+Na%-s26+>DKmP_S`C0Bt=P?s=N zN+J*QFr+zm?GnXeBAm>ipNB9#qtX2AW96~YPN}pjnKw(rVjIn1GQr}zBAavhLnWoN zc@(o4WrHyAkeu~bdf3TED|b>qwYF8P@7{{f2w9Jk6Uyq!0SDg@VZ|LlU?R8`Gk7I> ztO+$<`AA@g)pp}@VbF#tL^NSE+gcppIKau`Bo5>0;zziU5>6KntyKWFExJPEeOS=@4_utD_`^o-e0ulg45Bq@z*U5a?`-NgBkY1b^ru zq;7(xSH`1^y?sLr(mcw7IWz#!-xyCt*49l45c?xI$y4gnhiO`_4}sJV=-eu$m#n~w z`b*$5KXNslFB40`bRI;6(ch%r1P);ukUrzcm)WxFGZPsb!mZHFHGo(K9`H(mNVU1q zx)(#-CGn{&SL)#8geeM82BV2oroDyvuASwsA~h-i>Uc^gh3e6Ft7dD!S3CT5H7_z~ z?ifJfxk&*~d;$Pb+|5?NG9KjPQf(8V`x`7R78w0Rd~PnFIicBP^?E64T3Gt?(rKx# ziVG*&lh4ZE0LYNH8*X2Q`RPADvOF$V1rc-!75fo16F;jRCfd)PU8=eOe#^( zQ7&R?&@9dz<#8CJ>~Gg`9+6$)BW5Jvrfg>1i@Tc~iDX4U(FVxkQI-bL6l_$i zA7n+K*8>igsan11`dzcO6X1wmjQgjx9%DTs&2ebjZ%wJgaz{%QJ*)!L5#K`z04 zFZ28$)kRoQKF^>K8rN4VTa~3mB1cMO@6JNx>IJ(hwiOJv{YD~M)ovXyx-nBx&rGb5 zlkD>4!q|YwG#L8EdeQ71tFXu{-^Kk|6&@^oapzc|%*%2_>_i%L10n8~29229YUHgg z;|A(WxdBs|$*qHdq10qaUeV_~Ha+s;$4wSEE;A+9b(NZ9rRtOB;%J{fF~H?*w1l+% zW1~>9K3={cXKi6c9fVeLqmg>27U?Ke2&mKhP#4#SDh(xx*xKDe!!E$s{W}gK;A}eG zK&_a3U6hk-VG%i=n~;l)$kn!NvgcwTOYO31!&duhv$Ixr2iFz7M@%~`?#K0cN6mKE zN>tl#yY=9fKFaYmu8vY&<4yMRd)vZ_-bX(SE{+bbzCS)O_Pz(4Ej05|=x+tlb==QB zvJ}t?8#W^GQmdvR#Lm@JI_8QE!SI1-Tf3Vy;TIqmytaQ>cil-!=9X+s+8*9)J+@zR z%~qA!;AK6gnhW1IwWr#^R$En%@` zM5OER=J5OmrfJ|a1;w#;^~3Su;nCUE+4y~-ISAse|JH9*~oLmhrj!y>{KND86N*T$Ju-#wZ(23sbuW#rK(IfTFzNxn~ zh?@mdJ+vl-u+v{sCYiVL2wDPw>CYhNiiSV1>R6~U3_}%!R_VkCGB|v9ba8n+I--lY zf|nE$_t-4h_|ZNi6&2_j$v+YnGs#gF&)*`LB4eIR={;t1*AC;*%e*o1;j_aL-`HSj z`G2I|Yw3UVf0q}7tGA=03qmI=A1Onw;2ygPs*Ir+S3@ih2bY7_gHb(}1yPs6l=Fv| zXEU?Ts;ra^8|{0hSH++kj(Rv4jea`6I5dvhyu~15d;SqFEZdB|%nNNGbIG;`m@B#9S@E>0Q+9 zmrVqQ4X209po|P=9$oIXX>f9K{?pab>G1OB%Au==yC`;mvyeS}6;d}82&11zmq({p zC+Baj-W^@MJ|7)l8kds73TS~cI6sM}?_fHPQIJ{eaOLg}k4J;oCr47Z^#dhiB*QIE zst6Bq#L;Nm`~ME!4MqnS$3wezTi^TtdN&@m2sQ2g=#2J${`TT*aI#F-baMYU&araY zv|Fh#dF{;VHqD`ukB9GGEna(yPHz6b54|ZeqA;sDE!8>*Ia(Uk45w?{~0gvfZ2;G z38JYh4g+m3^OSkHfSw;%cp+8Zb;t}_r>k>=im90$x)_a-A5v{JUpGUHGB3^Y#J~^fO3Nn@!FNu}MVPpfOjN=P10Ykt|$k3Z{K||J9%4@0A_N#ECXFS4vj;bNB z&#W%Ft2@@3^vWO#GJiax--^nQ=GRu#$l7!9w+-;~uNx-iPpMG^;5=F(33jZH~L z%~-8rSkmFB1GdNpVy80xpaT0i$pnRYnmycTORmjmV*u+nH3qWg{%>~I90if8&%Q># zhGm=!J3AA%cb0E|w0S4Vue&;9`3|-(h!O+_nH;); zACoxEUW(j3A{V6T9QsSN_%7i)#_hr7V?6rf*|1t(#bMIf%{NIPQwxY)lX8!)|wWgkz zn)7UujN-|A!>qTR-=>qklpVI*xTCmh-2fi=aN>2ImP>$LDj^qDC=5ZLR@8P{z8#o+o0)s-hFmu1sQ8>}TB4n0y0igX?Z0)yv1Xs< zy%-c<`;Z>I(bZ~jCGNO~LAnP%RSwi{(r&RXG4W+%7X_`9jz% zC6rrW=m%=ne`%p9L#1EV-YQdg*4v4)aml!>4Wubr(zSXJdcmC6IS|D|^>Q7+LYsQZ z7>dRM(0!#DTbGT}n3q^eu518+M|MoioLX*Kxi^Z%e1*fKrXZ zn;lkZP<&EbXHYf@eBIRsD@vC?;EH~hLifw4Ssm59m$0Rbv&vqe@^sO2U+#E!1v&b) z{_5mEzf?sxlcfv5*U10f7q6b__1|B-daVC@FTZ-1JELG9QL|sISZDCQa)~b8p*(zv zE?Kw5B@;8!$_LvPg5NaoD$wodPF0^dbdT|=G3``z74mKC*pZMI0vzB`J^owSy` zLtJ+6SJ5t^A%OI0agNEnbPBVf;npxo<1C)U;U2g=;0es=VxMJM;#MpVy=!8C|n4>fg;c_ZK-TCjut8H!n-+8|Cxc}eF z&v5?JbpZW&!4emkB`m7KJdT1aPJ?LLpTsGQiHzJ53dB$WV%8&Svi;R-3>v120@0D; z@PPFJt2EZg;`x4n_be}53hzqMT-Q|#InDRQX&UE=*zH;{3$c3VVT+2n<|(m^jexGM zg8k5he-rtSTABKczZ&`f?D@`)D*tz0?d-mIl>hhf!z{U;pk#341tAvXU~eC6AUMB) z=|MbCyc7cGyPf{-3wK*S#j!;*@e*$wgtR~}R(_cL$A`Ke$=V}rFls-1IY~9mXiOC= zz^-p733<77vonU7C$ydCX8l}F7jxAp3TzwW6u75B2~_sLmdo!R$kvzE>X(j}MCn2_L9mLzd!0+FuGi|2zs8 z7jc|@AB2#m-75g6@b^4Op?{dh$$=!nxKc4VIawnWifMJiRS4Rs#G{q4OIk4jtq9ydzWu~m(yKBg5l6c+g)Em%U#|&DyhR{hC0`Y?NHm=R+5-%CF-Qf zw=haymQ^6%YZ!2Ad@a+qug+-Lps(fbYno7_J0`fBo0}$-DsFMuz~S%B+o=H;CI4k! zET926tsp47kyW2EVd2A%%YYQZ$8^Hv`_Gai@3ltgAoLI_50X4?Ja-m=rUAAEN1ZV* zh$db}Q+}(2+pW}1)#;iZStniwWx}7uJ|q`zjY(Ds#ZJDBI9-iD+BN1FIlLSI|N1iZ zuCIfMlp&}IP-AP=jI=DzAV>$}`u5b^cc zQz5PM7gRBCx(^6&Vh11&1nemtqJXS)s79$2EuuUO*DUVXiW@_XT4`Ud9e63U?CHUJ zEC3q)p26!pL@?7DB(d)n46o?IuIoP9S|0kZh5d(D)obkwTIc`ya!2?7e75~)|GA%E zap5;IQH%XQ@yB=K|A{w# z-T!lUcjs~czmMPY_dl2&%$_<1*9yf?C}GYFq6ypng-g$2fYLm{^7D1>Phs{II`#aC zw280C`=^96X3}{O6<%kgo%}>~EiryxMHJG)`}j8Uv@Voq5ppH6?i8lE4LKW_`)9{SxAFvvd!Vc?|;aGggJLVoJX3A1!@^#>y*F6zygTy_q%)U&aUYj6hfF> zWx*Wc&z|kMFG^pfFw4{Eim=cA&YF~_%JVS@*W=YNz<1w$2b}fE+%I5U$0^v@2*5tr z0e=Sp_->!$h5!89{toE%{to+pZl?G_f;D zW@6j6ZQHhO+nU(6pV&4gwrxCr-tYbDUps4UbXWDxUDX@iRo8Kyu-+%zNAtX1vQ~Ge z@717#QrX#6nt&6-10V2K2O*(5?eGTDbO^E~RoZ)_6Nh>rWw*Dq@o%K1L1TjgiaI2_uUT)u1`nC05)B3A z5eP4!5kCCKeD%BC#WOY6jA5L9r}N_Pb3i?kImF6NnjZbmqZ}lcN0vKb|vg13=qB*Tzy;--mAcJjBBUP7>VMlb=_R*p(iW3-0@=(hr1r8G~ay z!lH;`wdWq(Oh7(0{J|b-uwZ4QW4^r==t6t<>wA~%PY?uuQP(pwl7T5~3D8Ce+&9SR zFUpN9$K)0*Cx{ma|NBAT#?IOG_VscwO7VBNfx8@S$)~v=m#%WS(X{_0G)=0}8yjlh zN*O4FC3nu(aogWpnq~i&sH_|u<637)wP%sltiF|PU0p*-^IQ~-0Q*-DS4SH+J|3R# zr#)|nG1uO(+xg!jj?PPt5Cr1apT7t!JC9NOF$Bljx?S*E^l_a#djv2(l}_2WXWuWM zo+wP4(b{<3-zI8b;v{kt0KG~(y89~a^}gQFUr?@|JfxyO)v&ljd=}b~Yow)+h})n* zI|yTmfP7xS^{tkeOT@hEPYQa=4l6gUh8)&Y>+2j2zY$li-1UgK!;%HEPC1B(_+SPR zd+5yk}%1_6+6Kezo5*yU-%~k&F6&nQ z0oYwaXv7fwlE+N>{~+zfkEBafd&h(|Gs^bJ^Y7smdQ0L#)2TsB$a#nmVSZzai_fe4 z@sn!y*j7pxu8(BMbs8d-JVpBma~f=E{1M4I75Y$-!k@?hnv-;bZvwA`7671h*vD!E zITcxOP)n6_l1V-}A38;gxe7k1CK3T>$?J~+CDVtX*fTaWghe4FOur*oMGH7*E3L@i zpeX4Av5Qp8-w{|;D1MP+$d8s|q;njKn`unbhY(ZJ#b~6+VCu$*3eVWfn&Y03@82rM z&h4|lEihuNhcxE~Q)1Lt!+l46Vjm3WJPK}gh z1Y$(777ki~w_sg!ksFA53#eK}}#;msB~%+a)uH0|Y#FI=&0M@4(bJygRVIfb}vTPWHdp zuH5yX`p9&)KlZOQiCv3z*Ph<4D2$}%ldXOfGJ+Q~uq=y=@h&t3QD29Wb%GJ)fMHG9 zgLUZm>L4@T@j=V-n*odx|17{Qn}9=X(gLAK;Nu|Z4m(Xo*Zj})Y2!j|HS4gcNc2Eo zgV_EAoP-W3e?2EV)iPWod`4sN?O}Dt!z|trk5gop7m&sNbs7CCFq^$B@WKkRD=?tT zA}dvtsN3jshI&nRdulTWCAi{$9szzrc{}BW-h+4}-NWZ{f9_{}G(?Q-$So}tFr((o zcPrK749o-0ifeX#JxGDN8#(r*=30q!ApmCZWhE4<9S0y+f2(L;BiEV5`|sB zeQwY8p7svzHXo;kmd2*+43%F@3KmaSMz-JHX<7}W1P)7j-kw&s(ZaU)_pt3OIAjbb3`Fr8bfDF7oI(D;tH-CJ8vU+=uvg_#qmL$1V zyi;3d5@keK0!-8MQHR_7#q@qv=xyEhY+Hbkdx~A@P9}8*a}zf-H1#8?og+@~`H2^! zPaKKsRuC1SXX*vO5cu3K3mnEk^V4TK=4aSJa1z8IMK&>mlCbCJ5zgmE8Mh+{QZW^& zEF~cxIRb^A*$MB1^DjcC?I`DfFy@DkNrSYd09GIP6+v=?P9V)aYzVdz_pkMdq zGfk=}Sv>=oe&&43c0Cg>9C-?fi9&K=U;Z zI+?mMJ5=bvm#bvBf3UdNfxf;HHp%=Lqj4zir7U%S*z4N zF2Q>yK+=IHU@Bi~(qPHSx7h!1gHrF!_+ryE^tH?=JGr*zqm83eMc8Pu7J3n?c!V10 z`K+q_3ER_)7(70vc;P+$^}-{6)0g2Hsdk?nH<(-AF;L~6F`fa1*^W{CM{+O3TX+O* zGTwcEcoBtRwKaUqpnHKrwVpTihBkT?TY$j97F&Avkb15H9nrT4u7Xg5r{A z6zktWG|qd9koz2V4A~CkXj~ca3X6o1c*0n_Ai2}rjX8HUWD)lP?oZ9FpdSdE9>#`R z%YB%D!|K`PXg6I4<0|=I>YD=~cn1tvSe_+ewb`*)`0HU1+^Hc{)6Yl`)m86)E3xXV zMHwvIt?kU75tm;-KgTgc>6hjv$EhFD`Tq16%(uJ{I8i>UtsKd{L8DjaiEl8FobZ4% z{IPgkb$~k+G3slO?lk6s zb{1YOKiAwc0xm88wN~XVPH=l&qB~UCIDR%=Tvnf9s*e5rhsNLcFCv#5)<>lXNaERF zn&?YqOVg>^<$Oo2W?qKT7|??Ea=J~wS!#$>s~VM+ns@?BYES6sjWuTxlTC5BO{2oo zEU6ZwCsoKPM>Hz`*Caka!gB0uI#TkYT$RANnH6mK&LAW8X8@@GchE6NPz0=nlM3nc zG1w?d^mKib63SY(txk&~^U0c%AMLZT#;+d^`+_U7 zZ8jm37q`=#mJ#Me%N8<>nHiy)cPcQ##4fOM&wdq^E#SK)k08&MSzwM|c#*=~J~wWB zZ^cEMtCEi*Rx233cSc5(?>3XQ&{f+16%&Yl3imM>K|r&At?YhFI9qG;&tVZc99_j19PtAR!uj4(5{q8*XCnlFY^Q z;4!(&NdEYts+KIqt-^d0q_O z<{zw_#NY<_yV}gPt5m;w zI@B%87-7`~$y95c*H;VlcqUQP^ra>+&I)Yg4*^{TL9;$hP4cW=;i|>IjO>CdM#09CEI@g>{PperrXD3q)`L>!(#$6837Aw^vWnf4lG#ZR{fpC)uCV{0f zx|x`@us!_g4dKTnMhm(i&H*+c#Q|D|wurqsHVNhW26N6=4AUd0Q?-yCa#`3#C zZ65<=p}`5Gpidsm!IU^js*HT_P{+TVq>mzY)~;Xgkme=^Pu%QS*+7SXqsx(W`X}^w z!*5lup)bPe+aWr$D_yMeFcX-@#* z7rJ(TSd}i<*JO}@j+fNDoYmHmjinKd>IXM68qL2Cr4D6tSyKFrxj&(vm6q=pu~;-= zK+nAnD21?deRcX%yX20Ncd*6d9one`d^>pPV*ZY{|6(9&+@D9x_Q_}O5ZFJXJ7eSc z(2UXI)?3=8_ipGDEuU}(;*4)%JAvH7PD;IGcUs2P@v6v^u&{uof+x|^y zJa7tA&0oeyNfjCPR--p_zc?AF)j zr>0WrRi@z45`&vnCi!b1goJg=v-q?bM5b;dxmcRtUV~T_hkqIyr8EKN~!Dyt}R+*-}mWY!zW(k!p|Ksg72JaMuA$cXLqr$>t5M+oLZ$=MQICCN#VqV`eX+mifN;Ati+iz@U(xYMQg35g5S=wA`_;L z?>KPZtXA8kedvj9z%Bu8;_fU$SlUpo|HsN=K@#tDXR8PE_x8_bV-1jrgXTaN6?-WL zT|8NLa8%NwYF0C;GR@_5N(F#PxRjA4)+$!qoH;|}oE}U&RsNKp7NTQ$luNHy+))~4 zYprYz?N&|>;Ny_&`IcN7t^vaIyZt+#C(m_i1-uWMh&fvh2V*-oOU!qi5#L-U+q|pO zM_c1GidF>l<#p!M?ejj14YTxktDPMqVK=oc!S!F$vheu*l{k^%iNW=lE%ue}_uYf` zS($ilSeo;-{RjbYCTb`8`xa4sNxvzM`&8&~qz^SRl9Lgxnq_%rO%@z7Hjg$}qjlKT zu6&n`08erNcaSvLZty$gIpb4MK{Th{HRjvgaQ?P2d#iT7J~r{PJ}-;TsM-)w<1i_e zAlDT&OxSK({<1`&63n3!Kz^S`B|{!1paWCRWE|$Fb@4XrJM*X{;QV{Z<0IXkR5~R0 z!K~?qey@XjyUTRwJ0<^LzDU01l0w-p%k50mmS1~i2`YyUii1MgW{Npe=X399KjKi6 zXpg_Uxhb@B}4t9sv~w_O)|Mx}vhQbb7$ItB^?e(qH&2HLGx93XlA7^W#4Q@{!{1olj!O!u~V8f$1dX-MD&Xd1gUEFLPHl)h4 ztE$z>MKCiL@7f4sXFUhB`x3nxZvb0KP8nS0Q zV_HX%Q`@XJ7O*82S(}>X&K5;RYO&p+$E@SZBsT{ip!XQU46W_7oSokG$J5o@$I<56 z#8L?hs_9UaRdP;u)xNFV;QLY>L$>^V!1BwJLbq2ytQ@ONotM4a6CuDLVi81*SdgyA zmZKPiUZ$A613Mx<#83ixrRLvhu!K9GZtjON(SoK?cPP6S(}#(6X&UBnt!>t>&F`rJ z*x(3IPPwb?-pSYgj*7P#OE&pewc1YRMHkckQnl&Y;&vgCIQ0}*%i;Zp3eFXxoVOJU z{)0VmDI>b|M^!`AgkMF;Dyl+d>)Hs#_fiQ}Bh_uyJyxLiB+|nbWyw z!1di`L;Oo+r;sJx)E3u!3XzcQ`x%J*H0fsgxjY=4=BZ^gY-4>zVFwQ2Io5yyilsmN z5@bV9u4TXWfns8n!)ug{(OXYcl2zhIqLnr? z6s}nfZj-fFUg7(!X;5P)b?USb8S10)q&%T`^|yO=F!t=O0rZ8Cu|r6sH5_^?CFdcK zg^?A~Rk=klFj2L|BN-gnb_d4dKBa!h$%$Q?tOqH|8Q*AB(`|yoEVWCjfFOkc7jW;k z5oJHdj8JK06DxgHXgHR+%egK$ORSHs)UixEHG%6z=OE>2bhEj9-J-gGu5B+hI-%(u zR$oJD$gHgnsk(1|0+q&w*ktL;fcgPH3GoxZ&SoHP z-rT+Xuf0oq{A$dQ5S_r247Do{-no+qWyE~2gFbdhuMv%rJ6b{QB))U=2lK^{p!{V& z`8ZN>p3{ZCbgHJf@y+E?g}+DWCWfpDcUMt^y(0skP*7K3@!p*(a>-Z4UGm!ydEN&M zGwcn=g3V>~`}P}5=iH3rJBm?`V+WybfaYOS9By+>)->08L2O6O490X@Tz;eLQ+J}J z)wuc_s^Otd`gn@^mugkk*&b|y(S^opYDY)Q3I-`~zpQq%+fVi$@Uz)PCXQzE<7sKN zCRZ)fiBA5_>(E?%lw6Xc_Nx@A|yLB-YRu#*Z3?q`%Sk59Xr z+Lkc?(hq*NYb4Ll6Fz~EYBde2Nv|1uS9spV#G{p5x_V^IHBdfoucLj6P{U@H9>eA} z+4SpBEa5}kaJNWRIQj)7ZBgC3i*{;S-&~(*LzCzI_FsmfrYReVE^5vic@`37J(JS3 zQO99nKQGg0_VK3FqS!UvPQiGUgU&_;v}hWp6%|~-Os!9MZgIMscg|Z57tCg|T=_TE zV&QDR7XW7qZWgT?*PG=1uF`HsUK)dAiC<&+n?s`U4Cy$e}UIGo!5WyQ|^FxJU&kkQeOZY?`W&gRu%pUm&?6+K~!$g2=sXb6F>1 zZg}o7%z#6=jZRjdb>J#XguB2#kY>oLp=!SC$@(I74j1xk=(HPXc=CxZPt>46(1FAuNxCRK~|gHSOO9nF_}$jK@q? z5kaxEKI}&vTss?T?U>qBE4tvVC)3)cDz9vGyr69KOLe;ZO+!Bpu~)O>esj-q69u}-_W6hE5uQooGS`q~;Y~v*8ib8YS2kKr zAB?}EuW^IsEakN?%%gsChybcFKQTUTAKwR&uZ`i-3mC>=qLlnP>TqTf5)2idwQxJ} z3uJBHUFJb_xUB}^hWUt=NOHrvQfquE8yU=Av?yxy_JR^PPR1)`k?Msd52#|oFMJcB z{Z<&mSAdap6dyi&+Li+iGN_Q#bjnDt`8XSxoXpd|B}He+g(RvMz7?Y zL=D*2kVC&%Pr1J?h*N3UD~X3ABK6wOPj?85F{4*xfDz1B!6MMMdV>oOP&+{V7G?#D zi$?o8;I*6CXXlcQBBF`Kef(TsScQQj>igL#Qj$d^_{Qj_#Utob7yF;zjML5bBdX&U zq65mVaYF;vto;{(&-15&1kmZ_$oWo4-b6?qk42GW zE(E1z$^W?P41X{=wU%uBqPKUo+4;@{FuI(5y&*6kOcpn^s8|F;`Jt49?kc0Zk6!vP z!GQ5$u?M`{&2|;Df7H@X`T~{}0Qo+yqQ3mN2x@m@jBi`lQAD#gp>I3sN9s~`Xr;;; zXk_LhkJzM6-i#p1(QIF9FeN{5UrlOXR54qP?r`kDQ`AQr+zn9|-ZPH`QsJs%zjBq= z?@z8@$=eXwoP_brG?oO%_Pme&94&!{{xY68ztB=!X)P_+69nCcS|nMVhte$f^Udk^ zo1Tl+#ZakKz*yLV&Mk;e>3PGZxo}_muv##sWz0?f8~s~vZ-67VP{{y?O7q{;EZ;G^ z5b{a3zZcg2=n`ECf7-j!h=P7?J03zyO~&6j!F-yG(FhrO?=K!n(d_VC5M^5Oi~S47 zE}<}zLJzgmvutPv|F38y-pz!*y@3W2u z5IBIy=bZp-xqX$tPPlBU?}c&N&^S2LNYog{+6t3X@RTHX8uw>8{e2(Fmw1tu1*hf6 zd-RmN78;xrRjN&nz!Xj~ooqs^sWL>eu)OUQLqx6KtAZ}wyL3UJ z`}#g7O~I7WoPfKJ#guUiO3(f_kpLAcUT4Cw_?hKW7CG8bnCI>p)%r^To5xG~DZ8l_ zcHjLc@e@uZejaSmDlA>EZSGeiXQWs0o+Y?4)nQ1Ctt+oL`wPZDr2gLQ0(g05l<{96 zJv{VNg*7Qroy|B>D5ANw`D{TE;l)acEZSVN9nh%|NL1PaKb+^I|LsGII4ZdH)~Lti zaH|fu=r--ujxus{MHtP#Zp;4Qc1)lbEHnfuy3xW3{9Z)yX9s}{GkE0jYX>+mf;M_g z+T#!@1mPGp8{c7cuFt<}UYuoqbewr$H+ovCCI=K(Usq3UyTofAA<$-8jvwS{o2-im z-}R-DkY0Pt$UH=yt)6`r(jrdhyMvnJ7>(@@elewqY`(ZtV!#Qhs7AN`v)io0ke+@# zw}nbNA(kz@S@MR8MR@*KTlKVx1wTAznz59ex{mQGu1W1lfT$o6b!p%juM>&28iOP$ zC(*G3U!0_tHcGj4S--wfc__fjSEB-0>u4=rlAP$tpw2gYD=>QNa*>`EYNaQkjR1|) ztTgP-Y96W;VEK_8QKV1ki`5h15EgwW@=(51R@GZdO}B%RM)|BWP=)rhT<*J@UU2kt z2tPsbtk?!Yy!@OLlpayyjfrl9p0L<2(*gIOSe}PRD|T|z*6n9%C6pBXEXwxf{QDdd zS;DF}I_ZVGf%#+e8=Rg^N^J#Xk&Q9^oMcn>QiVx2Hg|QQAdVY1wG68cnwrd8WPuSQ^EE4oxFFT`Odl6%Qg5$cRl)dIDv+Ol@tN=lB>2lm_?1g2g z`98AwwoV$MDA*B-|1O9gdOV*OD*LMnhA16ML%ZV7=PhElgEcBQDBIMw#b7cv!!#C_ z?aNKAA(Q4}edLxdKL`x+m;Z$_&EKU%-p`L0(M%|Z%qKM}=f5$}sqtrgu$1Wm+@B6f z9K8M>J@fT7%O^%Ty}y(Hqew+>LVdX|P&+UTNd|B7Oi$~7Vkb!2rP(Q{w(}6p zm|md8Eo5v$6W-ceh|VT1B{u zRj-s7Kgp{HLf-?gp)t)$&Hc)-U3`+{1!?IX$%IB(>ZV3 zn--q{tU9UAudP>m)K=p5P($7Qp$Q`gDJH+AY80aC6QP%Kwhl}dHc@cqxl(6dm9<5{ zEc}PiSoK4bUgqzqQ!cF7DlE?azCH&6FYH-jWSb}bY;1|Sv)DHWrqYNTf@|WElM}BjuLhHO%i8DDiw;jlfjLg$XncCyNa#DqccFrsu+9h&w*7u-G-)i1#GHRm;I`KR8!NN3eyU90V7?s z;Va&NV%dMGFEr{tx2nLci8>)@{Th}nT>IQ2>ns_uVBf5V0fB4d9~f=OKmgM%hvcS1 z+4DG5S4lSYUSW~N`5n|d`eD=SrKeV(rJs-NJ%@wH|6pJGZ|qx_SzQ~)GDSZ|ua!L< zub363=G)-3`$EO~m@$PKD$?n$4%Lho!*q7#7=Nb)SX2WN3{iAhN|*mt?NXkmuMV9ohq2LlxY>NHVMrK)S(NHn~PCRv*yW39`wFlY`%K#)*M z-(mG2f5WOdejW-|Mz2`WP|D$UGt*s7hYgW|k}7cc?erm${SXo_9e$?IQoe(Cohy5o zDtu%EY3zhH%gb7i5D5NRYvq3Le5C1`acVv~DM~cWx<0Roq)+Wh&v{P)^nJMs+ckHmpcb z+O78yL4J?doSa(p2l7%Fa^Son-F4#C+)5T^>*DTMP`C1yn18I>>!rrm%kA^+VzV-- z^8V{_?9{{J*AT;}k*Mim(fNNUucCur4q$9|rDAcfz8qmhPw&}oJK}=p}osS zz50D6O|5t(oeYcl7#8XYg$HQ}K~~NjQZPm3CGj6VYqK8Z?mxRP9gbr|qO_MG7m`MEOlO8431RFSwH!0l z9c{~AseO&Y+B@21C}b7GnSYKWC%3!$B@Dko?uGe0VbsTY%7mE^e0w{ZlxTi;{DXJvD+)IQSvdW;7>=u^@_7>n z?WqhS)*KyPbK2?g`KC(EbM39klz?2Y55`WmwAO{+E$47kHEJkTHN&aK>@<`zae|~b zMRk4l@pQD;^!Gkw7^XrPxpK`tfNL`BR4I4PakODpqI!**EG@0p&&SQz#phj%=JW|U zJs#nNdh%G`stnvs9@zSI`MT6OvBKBw<>Y&R=K|b&Y8@`-$4t&&BgyCzSc{jRj#u`~g~n!VjsQ%!$3q2TWDdGvaAprgIb zr`Ish7?pLuu(84h=-6v8n3&O7nF!^(yfB2KT0;F|>+w-uhn>BJ zar!B#=9Klv!}x1+Q&yEWWu>CPlzX z?fhz#Yj?`3aM7gRBtY+HzNHgK@-&?Y7~C^WPem3)3G2P)kDpfT|6!k#*JuUOlvd2WGOm(zRUrn8Z3qf?D!Ikl-g&S46xPenSGJHhZ_VeTEZA|iouODpukF%1% zD_LFW8@#D?E~hFIi?4;zr#eq{y{EKx?nriX!Uk2C<|to(hXRPE2FsAE`fkXrQ@ymp zIX{k@M`gu!x82)0VDg<>rO-exm1l`D_uY(+xxTQY%NnF7Jo-w0Sp;SRgOFWP&2?T& z^wUgUzg-VI5w8TEEa{)m1Yb=T|4-e-25)JX18`jmK*0^4x6>uf!uq9^hgKZP;3eCz zsKsZZF-y<1%xMr;m3T~f8lKk=by6@DI*QGmyB09jDLPj0zX4PJx%E?P2+3aR7*(hW z5iD(0gO#egK(i^72PC_G?mkPe>UJmW_LP{1Az@112ZU}piD7xDj!onUBW6P#tdYH1 z4Onda;WDb^gv~2(oF~IS8qNl2CgF;+9Io`FQUH*zmqPH4*Br-O1GkexMtogG5rO|; zPW1M`&w;z^xg(juoVAf(w{$c0QrsiUSWUJcYY*FRG);5M9{=H-sg3{PoHV8X;hZL; z-<-3d@qanzhx0e*q&571an72C|8mX~+W+O8JVyWJoR6{p7tT3Pt4dXSJRmP1<`67e z$HRBg)t$m!R~)=+UwT7{e~)S4h3|AaCZ1~BI+uQ5-=v?sLd|y=*SFhf7IuhiBk&iy zWWt)Ty@IRZRy$=-6iBEc*LSL7%Ze=D+_OBz6})vsVtewcsdc29bvejqWe-mSH`w3s z0B<(3BUC(w?u~%^@$)ceAh&i8e^0}eTJ;G&w-eUXTork%x-x2_L6l(f(Ztm8FE1ar zwK))hCNr}Z!{IwgB$M@B11kD_y#87pUzwg1X8gH=k)fP4pN1Es*6Z!UV}X+PM*=gQ zc)%P(g`H0Er2&t9KJ>=iY4oSQ0-@BK-ng-lu86zJ%FaL6SOxMZ>1BHJ8f+nMINazi z&Ln9uQ?l}PtShAa) zDh~rt=R=N`QFBHS7styFpv-;`t6}&b8beDDpWy*A>C)4`Veidp*~dD zjAayOAct5}Rds%}@!Q+cxgq4MyObcU4(d!h#xgOOHN-&>7ZmeP*2HEmcmTjU>_ zf>mt!>=%ABl%zk=Q3QwE%^IV8uB*=Q&RN~iY0AlJ2BN?)8XfTvU8{Wn^cSm-&xHOKYPI~mBE@WOXF``nY%y0{TRB-o>& z^4Dd&M9^6k_V(ges$|&#hNx+?vfjiPpH-i>;<^S(r4=PedV%|L;R5)l6;_}N;jOuVyscfLL&@r%)AQw+{21xhn*K+rI zV=(o>cNm>JVG`i_!|lzHy49Qde9o3n&-onNQv32N%ecZI3awpHaDx5xXfd+)*RX3d ztgGxkhY5LS+tr1NWb}hwL-&WA8KAhoMnpC4U>-W@2*gNCK}l=%Z5n1m#inpoIQ){5 z`__d>u+TAQvbgfh-^oLnV?WBs55cu^OR+x}&Pi`nh)sLkan|PR%v;~anh{$6W>LZy zeZ&|7o6*lpgpl|jRZfz!7LoTqa+FcrpVqAgevUCr5ErGe*CAE`r1Kq3fQ5(3A%|Rf420K zh^}qub%OgHTThro(>=QQtgvS1MF}>}{xdn)wz$SHqrJbHWm8F{+<(mz^e6SDR z37}3(@bl)Z<=iEB{sM6DaddKCPZg-Xm2CpI@qC^?Zpxaz8Nlx8H*!ds0e+NkT;44d zReICEz_NS25@2V3u${O98yfFZzHFaOo_Dnti+x1vVAODxVope{msoyo=GPD7^xQ*msvWj7F;r3&;|t<_Fk*U z9Os07uql0Kp?~2Bu>dkzv<&j^eFl^WCjC$l5AlO=#!k@Pj}(1juN^gBSV5^Y(*t}l zXnup9hz8_PhVWZx5;Pb?gNB`#H8h1mDY1KG0*=0RqgVAGCGlYC;cKTAYYH+C{ybT0 z+{go5LF%6N(0LV;yzc3HbIQ}4Vz@-1dyskLA=t(RUen}#>_kl6x}IEIdOnc0bl>?+ zreK;xsEGWF{9F*wiA);`S8Q_RhUHL z3ATbvEL&+OZ-fSp%JdShu7hpi%YE@kq8d<2veQ~T2!@asVg!k&%A1gf|1n3J;{zlEsT&%WGsE)L6f1o!*IaE2ZA-g0XKG8~!| zCGVX4@5aDb3e)hb3ugfVI`%WX&lSHbXA|)4$J{4`SG^UxgS(?=>0}EIq3a9|%!z$S z0_f~$CUFf`Ojt{nN<+{S1C%^hS6hi5#+O#dT*ybq+OZVE>;tY-h&xL*_ObZ%gV?09`d3yb1Vi)rE^xgiXoC27)raVIWm1E>TeHD zJ<9z+-isFbu%1q=XT?J;p+rBd9LUbcZWlv4IW$11>XA_Zp&%imM#%9#91S5ZrNlsw zek4uX%q*rD0AxnwxyFr=La&PI^MvhN&)=S8wF1AfGT_;z0Xg>W5>L?`d~A)fzz z8aBXwNBGyqo>U?TgxJC!JX0rwyNa;rQw^2+aljOTW4&vjx*B_X-U+`ws({SO#g4ul zL#;R54IcoEFTzdD$n4^R8!Z3I!4JO=J5d)ZyM)FUKR{mDeUEn?$M@onrC0`IVYz$!}f4bI7_S8HN8hmwbV{6r& z6k~Vx^uXHc+)T%@ePs33TOvXNYaATMGC&`T>A8$Vj(dWRao&lTJ|TPdq>!+#O{F$d z$72h==?eKbA_fz-zxghkvz~)hoQSoU0YfDUuZ5DHkJYz|(kf1%{39;dPVrUS09Nj~ zfqgY4F&gPkj6P+>CAzGIJwF_>0Uwc-)F78gz9LOn<#Cqe?^5=1KwmZ`u;uaubDSDk~A@r4O5FR{H zeG&pM9koMxO55CzH4{}vE^Wewp^NdFb#zwsS@SiydB;ed;d+@_vq#N<)7K#v${j6G z+cD0K1gD{B59P3WXYcD)DRP`|$-KPIjzeSap&2fijU&a(=UScVA>J>k$j|loq^a!s ziK!@&*ySkCV@ay>R#K@8BT{z3} zPhD=SUdu7FNCQP)&Wlq$1nNa1?t$b^3detBRA;qsKxsj8`b%eW34~V9A3b+8H~)ms zQWSS=-^xNr% z|HuJi(2A7EpRh<6n7GG8irV2YFDV!=fb(B;I*e$C`FW?DmZ=e+2GtoXqX4yvMyh$V ziQ0-Stu!jC6rX55;LLK#qV?mdLVMjRwcn>zcA*Cnu>_Ftd8qm|Q2@Yw*w}P4A8bmMs{Eeiq&2aP4FlV_eElU!LKb?>BHp zthKbQfy{U&i|s3taEWP$N@+GQK9|SH@a(xz^EE2=ld$)02_-}pwh6GurMWTo^UmB0 zclo50QDJh7s=FnF!4Y2TNC63Lp~rEh*E2_&jm+hqD6HK|w38|PU6%Y={ zY!Subpre^1mJ>x51BLM#6BE9$Oe@lv_{LU zCN;!jylK_0Tqbk(XzK4N^?|?47LuH2QRGN&`PIkA*!$&^*4Ub+{(vduRjcf#0IHyb*nQ33i@Ux}I;8pT(DKB(IfnaPnV4 z9M;8BlIh^sy|!g?o(kd7Q^VgZi=W6|{N%_rIPG5wfOdXZeEDDZz;j11N~|Gu%{AhL ziuU=cR}*pBOziSn%9s;9kj3x0M0h8k9NmzW%d;X_$)VoJ}1dj5m4D4hl9`9LGi zYk|RWX!5=F&N!D4y|8+$S!nw$c9UFqqs%*1I-W-Y)|t)63&hVe7H%m5IObasSNCJZ zjI+x8p1R=y0`WAxz3*@&?nT9ZQP=+#k@D`lth`OEbbuHFJb4m?HSLX3B#8cas;m(q z`h*CtO8N8c=DW34C4oyOsN&eu;6=h_{(Og zXDL0eUCYu}bUMC4Dg#&~M$PUbXp?XPEJGwdCFt7X_wAHDKXh(AA1O`k=1FJ1H5N^NlJLf^}d^h0ZG2QE0j3XR4XVV?lvYye%pu=9xH_s%6MXjuaJ_q@=F)n#5k`P zDBY5#bVA(XveE@oj27}HDvRvnL6?SXOz`qO%)`ehlzbu4@?!7#K{{oNRb~b?{R^zb z+{bRwL!^RpEU2;5!BE2f*+u_5btw(|iG@#PfPv0}bNZh?%e?cWTu>85{sr-{?WbkW z3cMAuE-1f-5!}u>U$a-WylMMikxMlN6&!0lw?h(|!Z3tIRtrCsk}wk|`Qj%IucaUB zoC%yw&hsqR@8g^RTj9I9sPp$@UPwV8XyaV6leoqc{~9KkE=+t;)%p5SscIqmu5>Vx zhIZk_Me%*#ir9LF%3~pthFw72|F4tOcCXd8lyorU>pkGRbvyWANJomwJ%sIf6KIRYa!%QeK z2-H-m-WJY0?jf~Kib}d%6y6kz{tmCHF}Wikgc81O%KBcGn28UQ0!C&99(3b9oFK1Q zt8(Bf50SVI`3H7f`9$bUkOw&w4%H~Og_7Mc&t9EgG|cWH!pEkKDQgTB(5U}F8(EO? z+@*G2rEX+f(Zo`@6)G;*c?LxZnop^8h{&=WHx_pz_Op7`OBA0LWiVE+{XRg>HbBnw zZ6%XAEBMIJA;Uz&@e1*(HH(l16*=X#ZG3=uA`CVeT?$W?02 z9anrq`}xES`E6|YF8>4RO|5?|A0lULsQpo zu@bcMl)L$RUb9QGgp=gH$d-&ZQ0;yV$wX9~^{0#^PIYDW_Xlesar(RJVgZ_Q(G1(z zya6e}auegUBfO=_OjuiV2O7OS7ZfM1B+DS7x-5 zEU4sGP1^v7?{$-^D$_l34?%WKm4$vE?LzudYljq#u|7jZl7K)%vsK>Z%15I7i+Ax) zlafN?4_e{88R#7btP_GCAW>F&a=bBl(4+2v5q9hKN!u=% zflZkJ-$lMP_gCBcKF$?;$ZIN;{5y~+X-FH;r;x$2y>6#;>GoS#Q}T;qtb{-2xV^Nu zFe6kHcJlf-?k2Cl92Y>s_FY2!$=9vQbo#TxDp%z4;uX0imhb54_FZx?y}jQlU0p9d zcJcH&ut&G#kr~DX55gKmY!vK_+;z?cM#@e~u>REm0dY+z~#N%4KMm)s^CIJG4snTH?A<_%N|hc32;S5H?cZ!I1@atrJh4 zbtvlGq#X9Ie5+&w6p8ML$M2SQL=m3flwcZ-IepbU+rMrNel=G%L~q$?5Ar7O6{VQP>LXPfbqkGzFyI~=hu zma!u+A=*;5uJIsMN}+$q<-q&p{bmevjGMOsQjvfTqI#RUW$f)f@=zK*xqza3i`T|J zp^-5eC;gb-%2EThRX8wE2-4*&AXbGUFX^jg-g~a^+Xy8KUdwfmvUl@X+24vk30|9@X|1tHBVU{#av}oJLw5Dy_wr$(CZQJf?+vc=wPusS2_WPZCpL_pB z)vk)j%FL>r5xHW;E%ELTOL{QkD;K6TpaTo>Zm5&~LHQe=#as`*!q*_wX!?tG*WT4I zGd5XOm0wd8WiU}V>%_;dNn87NzoYbRWq{UE7!6x*qM6uZvM;x$LYKb*AgtfgU91w{|L^3cM5@29W#@NpMHA|zs3+ zPQkr+12&uRUt&xj_tT_R+3pJMcl37(%56J5i@+C4Vm-Ry1kNfDKd`p@vKruDpKZ`L znEM`ig`1XPrzu0Ftw-W-s0QzC@Wg&#!6yj5m9gnFqT6N|+r6Kb*&gw~J>FOSL$dp?ooaX= zLc-Rm``q4!%Yr=LGXGD$51%G{9!vhESNFPmgorbIv5&Z*cD8_~{qLp$otuL8e9U32 zX6L}?g+1_P#ORNlpV~ln)Alq_?eHdh>9R9_?e4PF=QLa$BE5M>ndczu`*|`26Z~}j z5usYhZW6-hUkW4M+K^C(9IyePaA<4KNU+wQuAu?e*9q8rI$??WF&Bl;CtXW*r3Hxw4Z1%eptcs$92 z`UX&NR!cV{R&SAVad)~{j1=9p>^GcpKRl-yUyxv)%}!@(Msq32g9qPg z>t&{T;W9>YmuV6HgMnG?W{F_cPlFM<7CS0dIkMtgtgx^Bl{!k{`zV(AWOtOu#3&Op zOn$$5C8c4hm!!cX$_N8iA<;aX{;>IPQ`O;VAW`PKEVg8AU0)Q zIzj71@cV`?PYe_~7Gl}EPWn{a@`{AWySr0QqTf&y zsSJ93RSSC}^dLnfz=VMKf#lrGWX-5|B4|b3jV;kkt0dd(p&Ogev12P=Ej=~MCYuJa zD1enmlpzYaMA}woGoMarff5|&oSktORUpw!kRFDS<+a7!&pe-SJ7Jz2w9p#043 zozd)|=E(RC11RbDp+?MxnpvuQhYYJv=EczP`E$isf3wb8lo~E-jf^Z0-miMY{(ojR zs|L9hMXa}0s|&etbr)$QF{alpq*^$&Zuu{{GlJIB%hwORi>Vg2?Hj(^?w#0LxawWA zA9Cu#RR>lto;zn!&1^bXd^g;>kt<Mcw+Sd5_P; z8V1tPxUBfzs*y67)9ioWRCQR(##6>@@78%s6O>1UcqXw zp(j&9Ed1Ho?OEw2%E&JOhD|S+!4IIa!)VGn4uH6}ljdHNFeB%=>vqJD)xru&OC!L*8+(hW$Mv zPr$3>(Z1j2l#k^51u;g9aBGw;xcRw9q;>)^aJmY|{K$n>ICBF!`nl`R%9)(~;7n{9 z9nT;fZ*Y5(U;nURJT0GmtiRASe>y0L-}b6-wEBq$$Yfr+N%`xK4tzPBS`i@!yGtg- z`OX(_;80*o1uLuX+A|&Qx&-yjhJU=S=6a|lswj7KED3uE`7(UwSf$i7hsSDk%pZiB zY9)|C4ofY@EH)HD^4XahNy|DUIkbL9cP{H?wo;R^^Xl57x>Y2!lAVmVm~)AoGXZDd zgL9+~Kc*2D?%dkby>Kx%sF}L72k(+}`HACe?4?}us(6Z=9+{m^UiL$7hm1WvLCMUY z`Vst@f@)nkc{y$|)S)6=o%VU05N=3lT+^dK>jBbaW0Z{k0*OH?S%X}J8=$9z3)~e6 zFYv5vL{>*h?QALgOS5bn5SoLL<(n$Gjn}9m-2g$M*Oq-_2HW`kjYM5F-4ux8l zwu~fu6y9#3vzCin6g)VGanHF#H=PNE7~LEues_e!jk2&fQAa?J?}BWMm7Hior2_i) zVtl$PTAd$P-5)d~2&x1NJJK`^^}+S$8xSFgkf-2xZ}O$qL6IApoxRVWbXF=6;ThC5 zf5jWM2%0&A8sP$Up9xj|VitJ2!NGb7Pd7Ry zsz%w#G^fZqjw=inrfevBfJXVDAjdKZaz=y?qZHmm9kGn=uG?82Pl9p~YT*#hA+%VW zF0{p`m}W&)1%GA@R9?C>d(yrWz>NnFRvW` zf`b>^iP$?7gt&O=;OYFH@}TI7c>JO|3xFlCBkCP*73b9PJveN!iPK#n|G^xH7d?M= zzd2RAG27nzY>ToQp+bT`2Z(}3MC<1j4y5~W>D4uCYPNKX%Qt=y_)*1&J-x_WxHemQ zQTPk1x$>-uYI$?EK(*v#?tzcMv^&`*;%(We$D?u+>1t)-Ynz6l<>k)IH(j`=dDt6( zSUtSsQ=ztvtzhnp7ULpK$sNL6c-QVzqJ_;MN~EcSET~>XP|z>7h+UE@(JJd-yx5xQ z;TmCNQkJNVTuNnT%J=$bV1dZ7ze#klBdzy^^9!}Ye zm$-atDk=6aMH0lw=hQ+nei~Xq)Kcn!5OFLhillV0S;Al%BLtx>Cv4|0Ftzcp?fO3} zQ~q{2GHwD*=#6>ov6dFc&asxxl(RT)OFXdz!oF#OVPvp%u)D-_qQ%=+f~LL#%yhcr zM^xEKsC6z-zAaWCgjLVTaCQ>E4@~Z(Ei4U)WhGs}Q8@&2GC%&<^1*C9($H6+1I3m7 za~*kf{Z$Aj$_^zKEodooW)W578PoW_#`xT1s|S6F^47>48u<%KBEl1LV$n9nl5gW5d6$V9OYq znY37oWHI~;X$@g9Y~SSiC;pX-V<|*rGU#$$33B$Ik6i%6p4L*x7E=LwhU+xET%RCi zUCG^ybZlTGxH1U$MiZ}sqRaQ^w*-J&&t|azf}ke#ZBXd&mxOZ}^h|+LuLb2WDrH0M zizUaO*NkU)=?<~t;f#f}0X8X$hQyet2W5 zSIZ^_-Q%+C`hH8HEJGrdOvd6R|DugDOF!ZHmH~;3R-B2Hy}vo31t!|?I#k)@aI*@a zb0|ux73e+#67bGIHH2;zKTf*&@Q2y^XZp)}5L)P#xwW%_OHU#nP($vjHEhcV-R~OM z67dL#@o5557%oHmPOWNhwtJ!{V6W3uQ1Hd@T9Tf?mHMEm>+Fl4EzJixPz8zHqJ8HLXF2Y|D3K#jh9eyp=oHAo+$~g{*#byP?q9CBgU!wnI_-)P9LIzGv)8^g?yzesF2y>CKz^XIH$9wsj4+btUw4c<4s_M0WCg zbZm!OMXuckxQn)pp4xpL^BKWvTuKbe-eX7j`B{s&t*-sdL!XchEW=zK!$ zO5~jP+4{v#dl%=qH+0GSvg^ff@?f+64^8p5@lMmrW@zVBhF84r&9*(Nb?}lo;S=7+ zcFzveLT3-Xttg$W;NX{&T7&TXUuX&Nsizxd*%yky#}T7wIXYFrtfqz50tmt@oaEDv zY_){*vcuM}W@t+D!ZOcE*Q{*{rYkQScUUdOn(6`x>pAI)c5_)ZRP^FXy=((v8}DNL z1@ugH8`3B>y)qQzZUwwh01gnJkxdT^Ji2w6V{%@#Z^g~xKw(xqNNviWEde| zg_aO!1Os|f)U7v|d4`#@<;jN=o-7jezs_meU#$q(BxrFiVacdhC}+zBx_e-=$IJ;+ z=E5ns#S}P&Ap?;L-`b_-f6Ig9#(91bh7ia(1qW#1BtXp2C;WZsL%Yt#qjLq{p$}Fe zHOd`;((EmKlDN<#xyQ_O2xFOaar)LCT+H{XKZZ z1br&#;HBQ2OVNKdYgL5s*f2M3yS?~#Tx6mg^o!QT*`GGd)j1D?HL>~;2Ku1~P_M+( z;I+aE-L(Ke%+Bs%8&i;)WR9E|$W=NIOAv4ivy1aF%vwenpp=rCKKzzW#%P%2CX61= zWMS>y=6|}qi4(%X-W)s>+pfovL%cGZ9|HAoM-Ih67khrJqb`7i2>oa<53n3BT13~;n4$>j)pUCN$wy1}q4A*XYEAhE;nC*5 z-}^`{LczQ`PLE}vjg7zQ49h`z^t#L0_db+degC`2kFsz(2UccH1JdhnyMp}?u9@i) zT^%O>d77@Vz#2TwlyGT?R`o^f+XPGgY2Y>!-4f12Hgw`!5RbV|Is38jVz&@TkHvqY z{36dvARg;~7t}xt;2!J#$=2Q;HM5$P8>6;iK7oB~b}X!YXww9~U@8agv2$^jLaqKa z0ik1$W~IN4&2QzNAhNELj2|aDgIz8?g9%)&yUo$b880tqdAa%tc2+0Mgx}KN5|}cybYZ zl*4i3KW-ln%@Eyyj#Q7go5}sxCAx|ix{-*zzLEj%`FeWHc5{N-TnpOc>*AdK@&-%? zI_I_Ihib6=@A%7q2}Tp5W#_jBYn!J&!7h_Qt@sr?yc(c`=_QK%^y-x19}yM+N8%I` zsJ~Asi?cVo`xJK9F%Mb)6K@hkzHBNQYR!o@Z;4^{2?Mu9IyuPiBy zeRKnMzyz>cn9dbZ9BzJwR9q7be@Si1*_Za0p83-Rk1z9d_FnB3~DWr2nl+)M22*y`&~sj2WRx^Hooe5L?> z#c$W#x)hwJ`)?)SI!QC^Z!-K~onE%P$do-X=81r}_i0P``VIMh>!eH_98nLxD%^{I zJCI|4jrI^kYCoBC06nX-nP?W-pvPI_XL`CixzhXlT%Od?Pgc)oRiiEsuWxz2cHHj< z`$C=s+OPlO$Eo7lz6`2Zp#!+`Zs}J_5mywD$w$FC8uH#9rYVJ?DWi0!#s}w}Y~zR=*DP`wEgWd*GJbpx$^FI|=T+?!+`d zoO0ROeW0o|uAluCo+A8#{=4fl;jKrBPV~Cd0`&!f9SgvK@)i$X#~S)A0EXFHn!cqL z$EVa4Fg7{0g0#QO>yRdIEoz$o;!{`E^CvTCY-he3AEDGGK@@}e2k z3bo8k!ZuOIDwn6#Ense)`uZydJ%TLgtY<;7D^k^qp?;u|!CxIgzA79^V0B`m(SY-C z1LqOv=hqN)R5=xa>V-wiBm)3XaP8wde7i6eM}t>`quhZE>{+?tjHMqOJw`lx;49OAQe}#AB1sJNj&G799=#}`HZgy{vf??@_BBe1 zumq8$ikHEL$|Y7lGAh9Xhz(sSoHqA6wbM)3B}5q+MbJn(kXT0r>^eFj0!15!qyYk* z&~2FYc!(~q%gqZY7)JitnjhVd`@rjAe;OG@F4WZhlC|@I-%2$tQ0wL#zT_4Vd;anA zI%LqOR6ur8uhDyklbU&Yon&8g_Dc^F8kPVClcBU!>x2%Q4J|F2srf|yN2jF1jG;9? ze-DV7|37Ha+Vm-DF6=kk;n!wEQQNpEQgxNw88hihYz*|k9JV1oe`&KfI;!6{?$avm z@JFpCr8h& z4mcaO<5N4Lp@S%YMMWdNe$uACbydLb%aQy8Xgh%0%c1^l5q<+}JHcAS!;mL$BxMIg zM+xAe@AKD_wgCeg!9z8aZy;?4Mn?tWsS@EokoFIzQXrW1hwvLh+lkph5xKof_!F`9 z&~3Mf$iY4QmDpw+en51X%6acjel1Bm2+*c{A!2kq|4`ZvN`SdTMZ#}bLp#`u%?0jq zsAX~RS7xwI#%8&ZMwO)xcAN1ULwKqbgu^J3jKnGO%zT(h$GJ9`V4RY(lx&lf0W|Vt zot{52{;)l>7igvltJ*twy)J4%j3rPN$H}c0F7|Zp6!Qq)G*_3o(7AEgTwBgwV0?SEx@utX#_l zY#O2hsLgpdR(0QjJiBqF(6FInBB3F_Z(<}#z9B=!lm4~kNR=*68h&&0|*@!VL`MV z849k(Nq0t4h{@5e*YGu)A6+%q{qDu^FLB8flz&1?!^<<#{t1OZnpx4C6;j~E+YH6P ztdc2Tl5B!B{zC>Kb&Nn2uXp$+6xRD8_>Wd%!NhuD8+eDbJ5$DWYBlj0ELDbJ^)_?` zQt}K2>6jgEoe%x$vPMoSZW0)ucq9cN;q|TA5VO%P=&jS`wV(wfZH2M+@z^6SN z>?;Fyii+-fmlk=!yB1aqIFw;gWgT|uL=e|=`=J4EZu~zdH=saG<2oWlreJWT6nSTZ zhI63&NivI#eND`maAG8dBx2lVoDAA7%p|t!-|peTNnZn;+0RTuYb{Klo`kgZ&A4;D z6a}`~dH|^BxBXiU-C$qKq!7H3ifTxm=9fQt zNMMRWR5+9HtOZPRBn#u=J|Z5paghD}wK!Ik!e54%Grod{`IHAAUT?GnnzG>Qs^J%P zv{|p+6`O3Wn(SCA%619AW<)^vkF4g}SsX3R`{q)wuh2U!fY|cLIj6AJ2Fjpyw&9Ms zQfk8?&Uj@QI$$1-JfjgV%I0@WLIwyAL`S%#z4-}=S&oKYz$_*IaZsf3}&+Y~U zMZ}uRrlP!wnYbxjfFYId=S&X`@caox43uHml+0rauB28`PGk0E6~Ypw@0Cs6CI#I!EbM5N+`8m6j+vV%yuuP2Yq> zlSknhA8jfkX?^^rr=q=>SHJE=XEsGXr#;X2%!{tWX9oK!SQWWw}LNUA>jE=Y^qN|yYj8;oKVE&et` z)FBBlNkki+_h!jrE*5pt^T)4;1d*VUt$4+yG6xyu=GJ`x;b%tF+%{*qoD_o?5rm_R zxQ%#n15gjdItCSo5M)Tg`Q;%hrV;qLq%6eWk{^nx!86#oEw9 zW@4QLfT{(KW2~Ug@j9D~Lfx!kTbta+M1k$ zN1PZqV(m$VBgQ1g>_lmz0EOO;`;3$>t9j08DvW#F0So>9agN{=Q)fmsFH}4Y*<=60 z+R|3)imPA7e)VN(!;)y|Z}pXD;{a^)5qd|djNKl!$<=8dqG55ZjgcY%8-K*s2W{px zdU2puZRCf{RM;>i8s@qXrETA7q~b*gKV7oCXnw zPeRlhKQ}jqG54mf-`s6W9s!zUkD_1y-Bv@DsL-F%mDwaX06lXex6nq>{knm2^W1_0 z35T%>(-Ki@yp9nW`NaWNoZ(2g23@KX4bgJ743gUZf?39&qUi;Msx1Q!tYjOqK9ccX zOwpbeAgmj0nSdV(UnK6RCb-nl7OH7d ziGpVsZ^C8mZBd0z$g^N61|5dtPGigz=Sc<%QE~8iPJRs0lSGN#S`p5mKVFI!?avk~ z5jdJLi8_`!M-)B|HbtTF`Z}lUkHRtRJKm9(8V=nQu3eRrm0SA@94i_}i1Z2!_h`!s z87qAz31^1#5^cX5_`26vN{eitzo&!u`iV7H-^2+@y@GdCN^&C_Ced@ieX)C#Aho4M ze$z1|+UVy`r@{nER=hOSLJb?VVm;2}AYI?j2pI+YYoO)gU$H~jn z@%wy*PN7|aBfj0Ye+(>A$Lvj$gGe(>tlHw`@N)WX`bzZY^K$FIL}vY5om|ABb&8fg z1D<%}esN&ZKQ@FztG)z{`i}o-*m!biL%W*;b>w;**Zmoh+tR<-Fe1SInKDivmGK#= zQL$Q^LUHQqs2ouvDARL0y&Y=~#Pr<1^!;o}5U0jZ(rsM?;ya?Kj)w{}wGp0%KCiTo zYaILSB{{!O^|(#Fu7OQ1w=OX`5OyZ&;e=hEOzU1+4x8w%K0Zq#H&Kec zn(Ui;etGy(NYDYpQyyL1+-Jy{mPyh*Aq;y`2k4;6lfBVJvYLdGbt=W5R^aYA@zCS59H5NgRr5 zkPQH#2CR%a(%k7wzB$>S8Dr`5~&~^BwX7glOkfUF1_2c5SHVK{rz>JYrJ! zeY;Ns^*vpCFI%+c=6=o(oMV_LLbe9@3QWjyXKPN1Si)e@D6dRvV_BA(yTjLWm>QZw z)a20Kj+-eS;0r8BM2Qwhd5I7sOK#J&sk5t+rOr;mDblJW5x|vnVip~BmIKd)!VsE^ zA0PR|yL(FUbvW8VN$8*X`2Hdb`=1wEcRb>W~E8ag8hsS33HEtEi0l07B zYHUs04Xk}t#Mn%dDLn^gXOu=5fGd}u^Dub}!p%NZ>!P5yahmym| zQGYA#k*v%y2FN+`@#5zr&@IW_-8u~fREgHL_pl;F(fQnjYWVA$77zf*`_S^L33Y_` zB_rsfU4oi~~clR1r^51lRP6CcB_ALTy z_YwCNtFF!mGQVjmSG7?oQFBldfqzMK*(9PcjNB+Tt1rqvQSw$(n;JAV8TVcT53G>J zu1u?nzX?!E5v9Zo0S979%z^G;8c|;doBPOd+AM%RX@cxrI8p zI;?SXoqzcfgk9IaY#H9%1ov#m8C`v1PonWtWb`ad!qECkX@>2_Sm%|%$u3}HSbLfGZ03}iTxUE1VC+qj48uvcLDXw>fjsi9rvf*x$acZ z8RVTxcMLy8oia^QP}k6FKKxhy$-tW+RAIYR`dg-y(j~66Cm5os0KzAy+Tm~>F}O(a z4aVP$NrmN*dWqq_3?w!%3vjdTbF{QGi{4-aTz|&XA`vf_Rk@a;YK3Sm>Tza%xjQH-LZEJ2Lz(l!>12V zn}3u&cT7o!iRq@Ji*A;5Z>jaf;8h&+9{W>0rW;a_MrseI{ALb|a4nlE7&D!LoueAV zPFBLS%io)*e=e!|@3~saj^2G4g59AM&VWEe{{qYG^)%eTsCJgZVmvqBzo}A6YX6Wb=%->Za|V z#lg2}XhFd#9xT!CBN$s_DSmInRXTtN}E zJryw&@gHw-Xv>ts$O3fS*^Q7*7JTwQ3O`HR?(hXq7~N^k@wU{^mBKVO)3?sBtbZrZ zVJ@RQet($dj^e4La4q?XI%vBlUIgzE+&MlC+f==GaGxCPSPx$vGa(HN6Dzlzq&$e8 zrtkcrhxUEvq9>l-c+lKO>|aCEi>dD9i$b5Ey;9XA695L42Mu= zHsJKcO~CMRJ(KrR(oeUOo3qbOYKMHPRycOhK#xJ5MZoAXq^4=Wpf|PBTyd~> zIH7Ta&0^6b38i-Scd14dS7E%IQ6BQ|DC`9%=MtC?=$TR-#}q#{(*$DZ=;>C>fEWTc z6fKPOQi-Egs^fT`1qF8taVCshD(Z-;EzGC_!^v*YwBN2=j8pMds+xp?1?|2jH5h&p zM(`lQE(Q@^3n_&XFWqS_tW$8M3})TA;;;uiX4&w+aZ)`%L0;aiYZ1vf4!O`sI)@ja zU1y+CYAl|7M_U>#>g;@d5^(Oo5sWU#N2E5Kr84>wz?sS3kUn+mnvceBEZo~2ODdFc zI-{W(>XzhgKVNrGm+yLJrP!5%2C*8@wtYF-40f5r;nReUFk9RWs9LfPEbxTs3>eND z6v9ao?um)g=Ii=kkIQF z89PzAJ~!for)p~q%9qwF80i|e`RQ*H^+rzltrZ6pcQETjG%BBr9!Adp8<ESsT5(3E0@7B&a+orTN@t) zns1t%S0c?{Z+dxzczOD`9^Jm5S-F!~o!FQ+8Jd#?8xX92x3ulkvPvb;bC_GDD&4{lRFfClU;@tBL(Lspv4*XKTslYCt#`Ms-|}y{2U$ljXZFWCAN}as#K+;BwS+d+~?zI9yO zyw7qO`rQp8;TEJ%bem<)4yR-l+aSDQq)ZA9k+Cq)$q}EhC|x$w=ay3tf|k643z;=5 zs5$j9n+mz@Yz3_p2KH-%*30e@cEu8h32#TQg*blAWbZw0$nQ&@WYG{LSgqZuv~l5O zB~cJsjxu9ubK_yp8gp3OcyyNG21WtE@8?d?3)YZA4=h&mRdLm&8)}}u;O$4O4@^Sm zn_Jfs!$O%T-0asD{x)`g@73>?#6LB24csjaBHu5Nv(ooJnm_BwpZ+nkBM?*(-Ldc_ z#J4uM*SE#)9>qdb!(nuingSf;|1gez!u1zL?786RHvO}H;_p0vdS6I83!4ZvLWUreXm07vf@lU( z;O5hN5b?Qi6|0@)8a=66qm0VJY<`q25h2~PXFgscMg&<9q0glt?rCcSg^~1uPK#<1 zAh6E$l0`9G`+UDTqdT1{&WdQ;4LU!j2Rzk3Km6U=+7e&(gdyuaf3_DPUP);qsGvpE zib;5a6!Ks_rI}*M$&)iOM@R3`l7|=8NT?Gz2sVxx1~nOY)3iluXsuz#SvBG2KVHWA z$Y3A$f=w6aG$lg#Y{BFS)1KtzLjH8p}I(T<@X2zZjo9`O!&tybR z?g2bRE6*6z#6Yrdk+F!Mu!C=io$}M~?bc-MUho8woOT7$zG@KF6^8;UFZMY;W9aBL zlRHq&z(=(bAD~Nffuof}*Geg$#4n^TL%D~}T1n@Lc7-nbHa6rnu$tB0uQq*$Lcc22O~ZK}9W9>yJF}y6t}u1pj}`Wp z-d4@Vr=hN&=Bf-A_Z+7ha-G6)$XpwEK=nlC3&&=f^#$w{8f#je{5VtDBU7rC(QTL? zaX+=@A21Ha%n~i_fUGP2;DPJ!rlK!%|C{me2a0^|HUDa`Mz!{KF6hcs4TO`3Ckb4% zV`&~-oM|JJ2IRQk$jUyJgY~d%DfiVz1k2SsTD-T2wmkl0)*skWb_Ks0X*X1;FDwg} zw^c|bWHghMa*!u&r64E5Q_7q<5^<*op~pYnjLGVvo}E2r#vGZt2+s(!NjXT%KjH)X zxNqOL8n=~aA-`LJp*msDC&;|ngOSH?3oepcYHd7~z16jbNxDqWTFyPVsVcb4sZlPf zycelvPgmmfU=*?CKQHP8X?4iYf>MV28Wp9B&KBawwTTO>TZvQYI{EGoXNqVkO;jyp ziwBy-&8c!od}>0RK>lhePSoCI6f5ceV2UgVLR>)=ORpk{)AMmv7Ja9J52RQrirkR% zAq=Xqf4+FL>yXN=5{2fMKd)J@zOh4wzlomGnxmVzThQBI_iax?oUEsmP*q(@k=RuB z@+slv;kS?)B!p4V-F#Pvqh>XINflRBbnsQ;=H!-VgrzkPLNB9lB-i&Lpp=>z1%0WL z8o6#gCEj@tY|zX&fOX6u9Ag~-$4P7?RW5?n6(nBQNXZ#rw5V$cc5I>4pdGX1J=(by zj-l+QQ7t99S{^+Q4jh5gQdx3=<&Afvd1l4(`rp|5od5-K?6rcR=&Yvn4lmTL4qb#> z;F+^9fj@up_R$|;|HEwodiWFPo$}&X5y6{jKqqgz>HD)Mj6ryCczGe>1427-)vEd) z4DAUiW(QTE8d!3(GdQ-q7r^HuK#a1>NsiJe2TS(uD_czc7*ECx{63o3SLT#hKJ~2I zE^QkFIyOO+4C-R4#@6?6l%Afz0k)s9M+8z-^yLsn%(i}LA!f{#J*xWW?kJr$)he}a z;qP)L;xE(An>IVYYj6Lbm*;f;AAS7qucL58eV6$(VZ2Aki8WD(f&TL)p?=_J%l+1P zTj~$y|7P}tP5|}m_m^qM&(8MldV#^umhZ~X`S|w-X1?3AKGH+_V#+kRGNor!B!a0& z4^J|S``D?8D-sag8$>7&4zlLVjmx$J523K9g?BJ9b`X;T4fg5F{H^Gj2_^kds(C6s zc3cD^!E_`}cXHVrU{&llB7+_6*B9M+Pe<@@gqCC2X)INQR5?}zSm{i!o}h#UhyQh` z2MGfWHiSlJ)pV8m#Y|%=b7_~kI2MIWnQXAhyNkg!(D97J?oK4g2Aeutu!en~pasKI zZ2f*pnraFCuwax~dMBd4l^Qey> zPg0di=j2CJa|_-#J8vA%6W(z@ynk#*nU0D_u2DVQE_ZdIQWNe&lxk)G#u?1T(=(MH z=kMzBpYdj&i{+o^kKnJO@3t4TpAU|F^hf^5bE4$r@)S(QBS+bI$djM&!3Wvh8Jo2i)=6ueY*c<(^}YTe~uu0=;v$1kS3 z0w&Q0w6u-FWjnD2tk|RT-M{0vL)##m&-qrPkVlgQgcdn12Ra?e^j20&UX&U;qRyP9 zgt!%vHeu14o${N;}e0}9WD)SdYfYKfl(n>FN-7o5N->bAKv~jti6~XG`&#HEU zLHf8xIKd@ZT;eqCWRzTql4Xxj6`RGorMk_jWg|F3afs=&$|&I^yxHQ3)x#}{R$Ycn zWS)0_Q&_D0ud07vF7<70)n+%@mR1L+mI!Ij4x@oQg2_fR4<4hUyBW&^WsBwAvD3EP zg6xqX9~|>MQJ2MjR2{I?D6M*#7AJ`dg~ZLLT@l*^u7}-GB$;aTFIi%0%}YWN*i;0B z2amkJ=10&r%FvcyLJ6&}c1nOIr<;vzX!g_}>HghDf2A>ZdQ!939)>CE;|8sfUh0~u zAgrNj3xihTdKgQRz~VC*)lC-1cw_r|q#S!LW17b6;m)5k`C6MeT|AlRue$z8(VvyV z=_mc@GoS6HTK{=@$-npKnJ`EHxw+}LOGTEDqcVYr94>-~;K?GVik0wtX*eSAb8s_q zir6Uqxu>f2kZCbGtm!-z*8IDy{UqJPZETs=r`#9ye8xP9Z9BjcW`X~R*p5b?)@BZi zE}~CUZLrz0m!_}V<&I*`7bKo=>=IoOf|Z$&RPiB!G}G#=U+K*@Z0!qGQ`V-~uAyTOL=PXgextRG zF^D0}Ls;p9M2$99sC8p#60I%qgph== z1gsLtbQRl^VMYGi^+>@@+Lk~Cc-GI7`xIKqGJs`9$71uX%W=rz`BU?*#|}ZG<=-xT z&@h!t;ias4m&@K-wlcF>tC`v05+y>5`jNq9RtvS|YT9sx@ ztLh%%)6)c=5-A4d82P`;YT`&|c6yxUmO&_IgoR_hM;=N6?Zn!n^JxT&s^ph}3hM}* z1eOOArfnAa5K~fVurtrMdk{yiNXa#1^wSIohk=ySA`Lm!Mn_T1F0YfEmZ8z1*pi&Ovbn&a=m} zCZo|bCLKeu@Kyn%I8u#YbbOVaMAlMb4qpf{8uZZzv3Fs8*oUX|Mq#x|TGuTDCFkto z97r~>>Dg=aTr6k)Z|4#M*jXb&Ir#9pZog*3i+UmVCT`+R3*kPZ?-t$pcTIGseV6+U z8e0g?>>rCjzwCpExQew55@?r|n@ zt!Nc-a`Yma^&zArYtP)|#xH#Ms3wN7NuP>1NP(<~U^(m0aS21 zQ?@OWo4;Al6-u?g;Z3C~to4?{&A_p-y$1cW-7TQl4!S)P`#4v&P8XhrmT@#0rqE^6AFy{HI!$DTUu z!1K&XoKHSYWLM&C;iV5Q)vZ}fm+M-~V=d%>x4x`Y3n^S{$BRs$!b zVZ=0cVQnKsh`3+zLm2qA7^;RQ#WkVqy`>JI5)%0wS1335Y#UQ(zxb1HfmRp-v1%cs zoHyQXpOmP=30C=rC1rr3%1Jf``ctH%1(S1xv%DC&KaEtvfv`S>Bo~x87|HVpZ;U+9 z0DE3W85pr8v%NNr(S)3A?o2CivJwr$TE>945CIy5WmLvlYUrm}qGH>86*((D;nqvT zhwE7a^c085?kUV4tD1%530dDMt0X!mEPQSAYl<5wIyk4_3_x#Qfu^8MZX80bq0tP! zI(*{3@t3LAQ(oCUxhjj3-6A+|KsAqgx4I~k#~qQOt7A-~HI$QGaM$7?iv~M;+{Nkl z_&S4G3dZW5kCc^nAqgpT8#mO|`{~pn>zr;+VLOMU(>`=yro4J>;>w}pi52np?h7>P zl8mNJG?2C<5=pL+s-c`))EAjm9ClG!#t-6|eM=V7$0xEr8IMVRQ0(_+40xi@i|eN9ChLnl_dRd?H$ zLO`>SR85#os@z-HdfkpUcmL|5;H2a^{On zByZE$?w0J9mof~*5ta_~j2e{I_GDJ0+U_;J#p5SdBxu)(TVKuTl+YMfGULoXGOdoSWq3>9xb$d3ZPZ30s%><|5s^eG z7JOy<_Ta)tObI_{fMYwITBn5unZ+h+GI&J{Hpbe*lR|Y?V{>oD*(o9^;hF3Q;v;GVUNI)bm@)!Ec%)nyK7jQpM3Lr`k5O z*lEheWYztpYUf84*r~+UY$0XfXSx@(J5>YaWA6c1-TN$4`1I&|R^~RT*mSLj4q=8b zayS3(FY#t2#LXc(NGJ1|z-H5~zKLd(a}|!I#HjBQ{&BP(%hC%;#H`k~YV@6Ld$o~- zs#SJMM&Cj;m!?%pLzP|F5h*tgxvE28Zq;@kqa-Cal+Ag0SAy;BEpH<;WXWYR9+Wyxl-dHDag%oE%j=P{00ZXPLb`x(UM+V?J_dx`Iqi5T{{zvy@yy< zS8iIWF{|y(lVJb!J}b)qJQ>akE5H)@-+$i!s(An7VDS7&{y)ZNCHWtRBsC`r^1#L% z&uAuTa-^76(~1Rkl>{={F~eunoGVciS!#g?N-(8k#?0W|HkZm z{)K1Jc6IGfDD%>a^IskWtU3OxzuPaxe?8s*`Z%8z=D$qlL1TGe3WU;U3{AvdTkm|8 zO{ZQ0Nd8ggsR_x{yl>ue>!kPUDb(@w!v}#SK^6gVv{Arv+iwiTEo`PO!>mfmqPEe-QZN7s7rq{EW>b?4rGBSauoH* z%od)p3oaj;0w~M41aH76GKnY{D7g3nR|E+4S9RE`0Vf29n3HcyRpFq)D<%^xwqdUs zwb1hXfpsOekUXpK(RPJ?3_tT@i&`i(u3A~X5`$S?t(|fNmyTTHS+4P(lD}4(VkN-2 zfl2g6oorhp=yzS)Vzsdr)}QS4=vVRLi^9pGDW*o#v{Z88v*36YXS9io!b!;uB{DFF z#2HPMb)1dS=3n`yGASY&BYl1U7tM#U1uN;6Hm~N$xEx}=cu{8&bquFBV*GM<1X%?j zq6RanG|+1rT8n9`(z|=8cwi zHR;f&p@=?xKFViB{r?uHF^wmyZ2^|rfBPl-?^nA|`v0SRR?z={l4FnXh|M!~;aAF{ z2;wyHq)F{JY@^Cw;z`5x59f?!P2#;0nr$=1afr5zWumJC54y;@!eLuwT`u0n@Q3vK z_?E^Y>U!xfzl4AL;txK>yZg_FU73*ir-Sp;lhf~p=sfQ|3Q0zSjD%=Q=-}2>5g$Gb z#S>BH!-wr1q;!nf+PQcwsgf~8^6e$r3}D2D`#>42jlF|=3R~H(_9(52PVr4}O5TzV zo5eh@%ThsBA05eU-ca_pc8zRHTx-)=2!E^C!sHMX$WmaX15dg8wgM!}79fP9H=Lwr zDH+put-xH9g)b`=AZhPl+iy7E4CVf7g*IImR!}QgDiwz>im`u?fw~w)3TLd_`lTX> zOiJrU3zocidC^+6iU)M5yS47m70laRhFEU+D!;4tWzG*^mdgOhagvnoOVw~I+@)>* z<4X7Ah72t8cQm3nU06Xv(xwerS?FY%X&W0$3o*Zq!fokP(V2r9#MMU-8%xo4ENXs^ zqQx;qxBncboLj{>TW#Pjcp@}`Yz=5#1FvRo-j&tHUQ4&?L2o}88cvH*ux*3&BceOj zKzql?C?sD^SVxtK`@VG7Zq0JMSE9MS6le{?=n5(=_$NR6>`p8h^WrS48cz4klgs7P z=RW(t8BQqMC?65LbrhkHIu5I`zp$}V8XoC1CXf-r)G-%rxK@Q|^MKRM>B4>HnY|*dGO=pvt=TXq=I;t4o2%KM<*4T9FBwr=N>+`S{ruya;qGJq zk%jMT{~7e3mGXb@_xHYfvj05B=T7z?G4My<{8vgQ|Gj=Akm9OO#|UKiw%!sX(Y~iG z$ZqO^3_@k{u4WKY_19t$a$(gNgqqDbE{Ga4&QhaNp;PrnrBBTubc8cJ!n{~NRF5Ca zpmafWU`N@MB;PHCbTH4R$2qT9a13A6n4#eDaXp)@VlT0=Sh5#=0PB~uLD(pKl4da_ z>iz@FVzPog$?nstfwSBg2g#e|a-3u>OmewcT4sz>C0j7PEbnoW zc_yv=8ZB@Nktf?*TV-Q?wl`3|Mr+wNw!r%?HUS0p^R~UIPOLEQceTCMK)J8&O@aNy zZEvkDG<6#ELt1Foyw9oa!!k3CHKFccrg>14Xw#PD^BtP|+eP(|J-l7?W1D6k<#QkV zAEbV55eT}>|7(A*=>PR>|Es6?&qw*($^N&v_}^cy-|**T68`vRKj`FxdVWC*4`k*m z5_2^pAJkrpiO+^~M~^QDnLGP?*-)Omy`H?i$~%0R(fN2+_*g`8KPxj$F68vWUgW_uH%k%phPAJ<(!_ptvYjAxUSEH?rz@&6h;FWG|Ef)tiIzGWW9yS#3RxVW^tGD_Msu5cf<2Qvs>c zL}YfCro6rVS`Jl6d;OH>hK?m|SbL=g@1p9~Dh(^XyV!h0Yf8CTC1vZk`Q_sE``U`R zv8EI=Wh`9tilUG;kSlSaJ&O70xpst#CW_tOx~JvJ9;{E>e5H*YC6#c+A*fL+AJ7=G-t9r_9zBTk$cw%)2cpX*2OO_aFm?q|%!mHk@&& z^3HB8xx2`#+}nP}>{8pOB`j0J5=mj2+x*Z}?&H{x?_vKmk8 z{ipjMALrA#ivjptjQqod|4OF%WNg2HPQBR|Uf<8+D_eLNV{eI=?aZ>WT04tut;3xI zb@r}TFc{zy_@W1@3_SylWSS*I&6KdQH3XF|hF7icSYeuF!Z3jOF- zIZu0$$hLR?NHyJ&0jI9R^n zTpb7v-jev&39x#G#oBlSj1 z_P#Zx!6Ks;&IjCMtxXH5U-s*VS=O<~teNzOQxaTra|#3W2K)iyCf5|@QlHZTT+T_f zrE~`L&lhO$Y`gVHRH_~K;QvZ^ma)rTd9+Y>m#?iAbgpf=7ItfNFVTRy2lS3>M-kg* z^@EPmjp%#hl){8GhaU}%=7B~)l zu?x#tBOiV1nI>R~5}(Gtrj7pZPf0YRlbEICPHimF|NHy9#ruEzd;5D&`u}5mHqaT) zgrwqvx8)#!M8D&YeouSwuYNF{^u#~Kb z^gbi2M4S14etdBB>e!!!cWh%x{MUXd|M%dl{r=PZf0WM#`i5pPo>4s;UeZx2w3b7` z0-eqQ`uTej&D_WT-kN4v!iT+{SQ&gi?S(Ahy^JL^;Jru|eXE#gLzLMD`}ZVe^F)Xg z$yg|26B?iq$!>`dI0_M2&+l|LHqhnE|2{hJbgr(hgl63dNkZa~!~rErdlzf#P{D(B zUYSydXyCu|-)XNK#%adV#Sm%4RU@iRKVY+-`YsxS76TS@7Lks?ADNaHXr2f~)f5B7 za6*674c`np*E9}?NNnNhGUJ`0>B#ua-e@q+u~c@#-!NI25gwPp*c8=>y^ zB#IdNiKS84l}K!Cpp!UDSvZGth)xHjwA4hBl--YaA>xhjZ5isEAMM46KBShn5o*^Dg$qd7r4RkWY6LQX2 zmNP+0CX{FCLX20oNXQUz*avkG3JDKV3Y(!JI%2^!oVm#2)-I0 zc$P$Dh(f64Q`YHN485eOb5jziC*ceBvLP$R@5K`uzw2}|JXr=-!pZQ&1~c#n&;5ZH zk`cwRH|Trm^Sw?dnMctXi)gSES0MIyfv^OBW-6M)C(uzg529PV;G1IqV(<_&+XNeR zwz(sZk%Zzdil2;6S$38ZPU37+;v)~>d5#cHQ@rRPL^C4I0?nA}U2U{LTq7MzAc89m z`l=nYm51J7ZYCh#_B)-BjOG@(NAirWL>k!_I1iy?v|w{|%jQvtB6>~48%_u!@3Isl z8jo2zlRB0ZvD_Xcd3q;!`yfU%<{6FyqJWLau(M&<(&o4gM~1rmvLWbSGx{6I8h&Jt zL}vrZt}Bd`AlpD^LX7f^!~w}?mO7bTN+*4sDa#A}QN!|WA_zKmIy_@3o{+-`bH0o> zznd~HEg(698Tye$^BF-G5)cANJLqJrd9UkrcaYu8DaihASIOLva)BpD;X)8JkkVSL zA~c>j7{$WavOLD|Qn*Yu1s2zTpgqr0WK<2wNb)1_BBI(i^a&v6?kJ zd+a#&L;-m zy;Y8vh?AI8*j>V0gk&_fia=w872-RHvl&4doe?eo+~OD}JiyE2GSghwP&D-=$W_EqH&zE1FO zb7GXrd^Fy_M<&ui+h6}cqvy{^9GDo&4<9;Cr^6)5d+htZvip(vW@w^`wT6CnaB=a| z>+>V?0!d@vw<((qt%pbv8a%+p?wba3>CurrR+igRT7v43zv5wm+vGJ_G`4tcnTp#s zr~;sJPs0x%fPS3~`y2ttT9{GpMBwj4h4kFqEQ689f&dAwy(x&| zC_+N}MYDxEgaONSVW3`gyE_G1zUX#=<2MUMTbjm;4Sb;|`da~_U@osW`FG5$BkvNH zX2=5b;)^Y@FATB>D(fRO59C~e17d=Eb6!9mL%(ts3-n%e-@}DSzQu(fx_dA`RU&rW_-H_Rc zq-e0WgLeD7{T;c5zS-4QVRVZ*f-Q*H9*t>C`ILnD7Jovs>3jqR7s0&B5VOHEoXxq% z#$Glho-(j*@1Sf-Ihx^LS*k5NVyh=z{Db5V;w<0awte*T_ar6F zrbBHq6g+?vsygL?Sl@^d=3#kW-6<|t?J=e00DIPl%%o>tZIl{sz&s@)T zIZ>$LB*9%L%G97VXIYjMOQLbgW(bR}NnT_z(QA^n^{JV&1Mv7%Y#HLs42^~8!tnx8 z&gX=;Z&K>$Y91*@E1tWh;4dPSz#2hNl%s`p6Cg*>D}yl8B<^PdjEuF?IjIJ zEH;#fELlkR{QnAAviNVYjP2=J)9I*kA)3dbaxOnea4;nr!Vc1LK)Ze)ZHWS1^{Tu5 z-yOj=GrRx}6oMCqA7(ar7mx&Ie!yl)MCI;TuNn%3-}#pUz(yH{$u6+e%bY5OaMtMn zHHN+3?d`3P0Y#sslU^i?@ZQUl!{gJ7V{g~*|FhG16Gw#ee4QLEquG(+l+aTXb;xFZ9F7>Cp}%R9f@i38~2i zf^-I}y5G4V#A#exxuiXo1}MVuWR52UP1p@dV>rkr>5Ou@OyW4~M07?oB@9d5@js(O z+$q0qJUQu>PDi&bWD|}NOGu13n~QC?v}StJTLoMc^`*J!I%c<`86i_r5>c#d zgJOjTvm=c&GD&H+@X^8H$&sh!dA5USmb=G{SxV?6M%QG)chIkl#(YO$PsuIcL0L*C z6Ow``Qeov{*AS3UY&!hTlnE+UY@77)i<+}pN=R>pX>4BPv$#V8K@$zcUbHdiB;!4v z;o#bt_;fb0etJ;A+uiNI+ueKSC-J0nO%~u+Du&u>D*w^(3@tkzlJBg{7adO@)OG~g zVwEGQ#W;E?MrfW!EhwODWELuNhyi3%ZKm69reO|5th83v53$;Ia({z?|95||_n9pl zwesIGMBcZJM)^PZYH#oPeo_8Ed&>X(IG>FT^go=)_|@-Zdd4L8f!NqUXRt@v5&A6A z?%I?~%cRh(QW{E4EU&hsEUiN4ve$+k6o5y}Je4}8RFB>4nVpS|j{GfTzrYUQ>cm=b zw0^D~CltcUpF%nV=(PoEcMx)F3=vp6tHIhQ_AX@Osi6#SV0II`N`2}tVGZ8tVb z9ssH@VlkU7G%`OBWz|2G{unvBc1`s2zpF5|k1;j27xpu;c$E%hxA?YhsBjJ{$db=~ zdG1nb)RKKN`-A#z0_DvYt&W>4Z(W4L8I9r84Q*-0;pnOo(A9Q31oTx}@)T8`1_pDU zv6*ZrV<<=o&PcgQUA1jfNo^lnHkho~H=~Y}`(|D>G^fk7ZLV-erH`cx=bw7o0(a$_ zR*;gA#2LjAFJt0DzS{QNA!N=0xeu&k9dH@!)Uov%kZfq}O1maY*R?5$(N!xVUJ136 z%OmvFIxKkU(fV6x>?3ryBKz8d_qw{xwRPTH4>By|lRPtLw(8&wAuWomM@hMqp3v4K z7X|A@-p~95y~x&9afw3RyJ||AB25F$NqR#A;=_K(&dqEMm@0$75^IlGU1cNDI^}fWW zD?l;}G^kouH-HW=!QloSgrV}i5iRMX7TF@C&rw@W=#*7)h~9rF!92)qE&$lF!L)^L zfzVCJYXDG4@g!zEqk(k)(=nVG&d7Kkagqrrc`5Bqm?P=FGnsX2;BN_Zla!5!+7yh4 z_G=7{tC>3eHU$*3g(NomsPWU2{-6yAX<&!yZ^m-w70BfK`l`;W<`fVqDLlj@LXxIN zaXR7XK>Ty3=0tVf7LCU=rrE-kM)nd`Cz$lno>f+EdU8>OQZmkMCe!&yTi60N>!lUu zjb4T)yl3$!K=jR)r_`3&V3n&FU-ODe`dz77h9~9n;^7vZ&E}arr^geSelaD2IATW` zZkHg1bV7Jm2Bw~?(YeJ7#HV<7|M?JO-}imB#nn4p8Fnlwzk?_^^X^pacQZUGVUT+} zm$4A*=khc7wNSDPOa4hskI@$t#SdOSSeTlEnv?mVxe;V z(6zp$5#i_+o5z`B5C!`OB)S0CMuNjU;0ecw#5Xi$@k~0Ur&P=uYq4>lTWXm`!oH%~ zBDV8<>q@5mj95&r5KA4IcLgRHyZjL4#YI#0J&RiFl}-g48?Kb{0v#~DBbjmU^M2BF3 z5;AZC%dS|-a4ZnT`esWr{|*IHT~%#QD!e0LkD|gHdg(mQ=!|%B+`L;H`O|C`ZG89U z(7X88>EZY1uTNjUx$q8Ozj}3YX=Yk+2!^Q3#$zF3tI07${aOMlk4NzxB%S)+Ug4wDRAP>=O@z#3g*Z`HLe%4?VH-*5UE$x1GwV``li}s)G z?aCceNV6Qdjg58e8L$9KW82&TkNk*DzGplGh3h4opdg|`bWGJVURB|c#j!MbN#m!g z6S0X$!9y#}Eums*kJtnxRu!xx%7c1vY@YE|045Wlp6G~xzapIDiIC*-3t$nE8xp}5dWuuaff#hw3L?FvF;Vv$ zT)AYOFARJvzQ?BMXSC7B81y!c$RRvi418bc-7*R z+`{W}gY(=S+5A;bR_(J;q;oDFN@N@&lBO(`E#zcTkgTrh0}aq0OUsNR2&j?;<2Y1M z{(qwA(ec^&@!`Sc@sTV(Pa|}q1hZHLZlvW0qw!oUR3;)os4SbR2Hn(ab+K_y(i@VZ zlQV?FPDfs&6c?R1{zy{Q+ zF-vE9`W&4?_!N!HU7C+wpz5xMRbdthFE)=yrz_H4R0?B<{3WvqiZB z_~f>hYhTuzBWJ8lo7iiz+&1a-$*BT|iU_ zNm2s&jQ+p>_x~x8E{n{~8?}_P%AgBkEXx_wnO-hmULX<&=^|16=!km5s&hpt+l=cybX{Rqgaeq=hGL&E{6UJ0adeslg(PFVV*j-F#Xhvo%UBJ5i&BDZY%L6;uD;o7ZL|b69f;1-4LXBv?g-{zWzAc+U zSG|zj^!RiJbNTA|vsYJ5M+~w_Pldr6I`>p0-?PE{SK}|lLNe5MT zD{dYa^(=_R7wmE)^9+dvMR%%b>yeZ$xfzts4D!Y}{hhp|dbbbuzFg8^$Oxn;sdOgM zYBo#8ayO_p)$l?TRmvC?K!Mmkb0g;sNjA9}a0%Hs6f1%ll!j>V9W{I7{HdH)LJSu5 z)sB)dc~5O=dYsG8EXCt74UGP}+%ZD{!t;!MrxTGQ{Y@+^Y=(8vGAGg4<8%^}P~u3^ zjE=>slOMY}fa+RHAXfGQMED_1rb1Ndq+gatxs>snTs8*fkgQ7LfN+#zb#oAw11Pr& zoB0uNxtR)%5eV5mDcIO?g*6hQ{B6s16(!0rOEzWQ^tUu3pduXRbzpZJTPL)3!CFW^ zkVPf1YqF>WXqB&pd3cb6Jg7&}U6-t>3yYAYq5z-vE-qfG0pn=2fQVKishmy83}Kso zE10SN?mw4H){JCR7IM96nI7l8sqSzZncj*odYr+w>U92`+%RQEdP#Zil9U4|J1bgL zIZNpbr;CDrP$HkYGhIFOOGjerMSkSAMJD>;4w_*O&My(cq4?|jz7e1**h&_yY|Ifr zRfvOMpj%32)1dLMGFKVqR`S%OM8yce)KY$(T#5~4%&ho@aQz`hLn9_W1OT=5)2V5&23pd36YmzgaL ztIQT0wkCtW@A`x1U;BN(-`jnLX5qdOpB3oTkXTDdS$c+(O7Ur!L7Ka&2BA#u)7O{B zLv&Timde^*KhULP!Qx?`LAar7891uB40NoXF6{)`lC}>SD+O}~(&0)y&?&lI!C&{W z_eK%B^|TS$%a}JJp3rVdD3dI}36ckDrYF`=@Rd=Rc{w0~V@|dTVl3r~W2e^LxkIOXb0RJeH&%8hElnV;)W?kTt}p6!Lj7tV{PGjYgE6uUUQXF$ESHXx)?B&z#qL%ud=MuGC5VtG(7T_4&vh*6^h{coI z&cSK+5<*u|pb))N+kIGcHB%NQiSZp18`XCtn5%4Nm7Hxn5n4=LZL+Ot*LL}9*KXN6 zOiS84A)bl@+2lq~%?~6-B)`>lWL}8HQCdAz2#ExpvnH%*C`cLSx{Pz43kDRq2Pu@A z(#aIz8%!gW2SUOA7n@7au}Ya^yl^Y@AL9h8@>(flf=mu1^UO(3mbzLMhT4g#a=}#O zFxz@-Ppq1%r!ClO9cse*>d;eN1KilQ`u)977cZv-!I#`ALAva!HkH-VX`>BrIIy|| z9!ysU4q?v#ug2txkktt@JFK>wl)V(oTd=r_QG)T5i)WQ%jg0jPfpscWmY9XgB4C+; z>{cufZMi4=_Vw$ISu6By5hI*-EgdYcU5qQQ>d4`%vcq7$Qds+2(@W7iUbMiKyHr5t z@Kr0i*7-21=j+3##^{poBxK-`iKVlYa%FPWMYiVBk3{C$gHwN{^2nHj?P5Gq-LQae z*3cllZ{3>I+jLX809G+|i8MslkS$kBH&H}yNK822K`Fr@6<<|88=PkILL6RN?dm{VGVbbtTe5BiUTman`gBu z_xP6%Qmpub|X3_!6Jyr_l#ZhD&t>C0Kle6o-LDty?jK*EG3Y} zb}Y863io`iw;RiGs%T9oT+nBWQm2K3`Ifq@6>uD|Su%&nTb0G3SF<#z*S>5AcDd%E zYP=PR>ehA*Uw6t^4hNT0(@_#?FNC!=6eROPE8(w???4$Cm__IplZ9cDr(#U z8@J_P#{9dK%@ZX5JvlODPM8&sTC7&5J}78H^7aR2x2UG#$0MI9zl4an*l0!0TCnLn zK9IrA@Q+1RQ^h)2u7puXVFTKxaRIL>R3n65F7FF4X;UW*n5Kqo^i^xc z>`ALNSxlr<*X~&6?15AuSq;??R;A=EADJ8aZAL>CGBKs)utCnonLJLK;xxQ!Cs*@1 z9ZX3$hr}l2MxI^vFyv@}xg4{Q^fqXmkraMwd^{Y79*#3=p4en^`d{xbBM6$&mejJ_ z`V*3@M2I2Wq)@AMidKp&^bq|J|CSII4-44VoD7yr`q?5ORij+hBe+a*jl*mX7Uk7G zwFjCNXkU{>E!H5z!1>X{X0$?Cw|*>h0mFB=La^(O8`&iu{v9sxa*pt?D>ExLbV4P2 zYVJpVyBu_-CHbrRqDCTjOYo5F%Aovc*Y21e!n*Sf%_X{fO{)`nOaW}XUABc z8cQa&^6ai%7j~Kj;f^|Gt{clzCJH#mq1h%3hgp(Uo!aF}0KOm*2{M+VQ^N#}>;1|U zwKljQPdGFvh-ym|jYci58H-Gm?WOho5e8pq=@|@kj)Xzp!mE~LGnTN3O%@kPN^p3{ zVxFY}rs#=$gXAk@zY{%!)z9<-aajsWzk>yv=g01N#^Q;#YcsduFhyF(L8TU z51}DP42QfY=qmp4be}wllh}o6%zGQipX=i)zGAtib+ZtY?Ji;*kV0oa$5DKqv915f+hk8j;_LEu(4K4vPFzS_z zU8=}{DE$WDYFx1+3qz{z)VZ-MwlVnGp<2b3n|)Sf$-AJ}h*=?g%xb9?9Zo|MfFDp8 z+O4VQcE(t>Q*CY+eJf<2lc`ZRQE~zjtA|SYn8(+^DGMb3wB8q9omp8gWkSxpfJv&Y z9Z^kl;*Hx5m|E>zB||jW-Fs%_nnt{ictW>1%n4K=p?JGG{Zy7qjl;$Ua$6};F=U=` zu`Q8sH0O&EdzU}YeRnoPwz-2gP2J6Z>oyAwHgfVA3ojB9)N`^fuo~N{T8$?kIvIP} zTfI|AwO+yYDqlOuWh?FXg@UO>aACuyQt+IdErHrLg}mz@ZY6^+rOVNdzCuHm7j}UY zYr;5joq&TWV_YSuACc^qkQn`Auix+Yy}jM9o`3bvC8!HcxRmV2G+WShHLUh~{t6SW zde++zG={xRku(OUD)Q9sKXs1+J!t3x!jw?{0QMXzDa@4M5N@5+I97Sbo2o;oXd`L8 zT8h$&Mov}D31%pn0-M?sEA%%w!f^oIe#vl%M(Q^@Ig^Q_bH;}hWG}5cS0>Cr-3D&I zbgRO3oS>CPaF_CWSww?|2p>;(!6uB`)fQtx-bs*`GNM>z#MWmrGF(obu%4VryHI+g zMUC!S3*{P)^*t-iR<2}29y3oP;`R-aKLf5R&96kslPGyKu{&Sc7bCV-V3G@felBnL zK9C7}h|1K4QzAXo^`>8sKjjWz=;rQ48ngchA~p{_<@KI=W15m%97Vm2l<+L2LFOqi zVwWenq6z3#%$|)6RM%TG)jc%m`||(&-tMzH9&_r-m2wHUiN#F_@MBmW3&LFcgSV3c zIkXl{a{|}N8k^OH{OuaCtff%Z+kudh5kXxc@w!50b`OCEPtMHTIvHCJ;p#L_f;q&i zs3~N;6Y_f(QW-z1&yQd`&BFBxj2oI}a~ydz;b1;dF9ajKqr?gJDA31|@GWU7os-3c zF>165Ow8~6b!(Wgt13X2a;4WK%Hh~6)B!@ zSF{LuQ|xA?C-~WqhYp{YPNJ8ztK(iHOlOs0m}fs8Dr1d1pR9TfYlq#|Ol8sOWN=v3v{{)_rUlY`J~Alt`AE)1mYS=(74{jE zO`(iwpeolSjZsK$>{t=$cO+1!Bx4$raL2h+P#UiOVL$q(RY%?C(Dk}i)w~vpu^!ZZonB5mx|!BV>Lau@Np_Kt z_di|is7$q~7_c1DcRw8Oh}Y=9(CdW67a0z&-TSM`_b@ISI=L#pVj+0v>4C0aZE z-EKggi@eN_M=HQN&J{}uqt9K;0Zg9S%@&o#i#Y|;QZ5h4AY*yml~rbKQwJ+Kr$H;q zgTh|XaFPtsY$0?(cO`RlU4tokrTHoG3T;lzpN|%Jl?v=9GTykj~ovtSPRus%Oh1J8Q98S9oU& zv}yu89n>B(%F}816A1OpN%*-3dpeZ8bHryAJ=!+2uE5WRChiga*#PxkA)pO#?;Qu) z0Q*lL3|i1B?i>-i8b?1=U}#e#_lXW|f_uLZ(I&|Ej}vWz{^t)Cb$Wlth|$&f`XK^G z>l?Ux^k_ZI`-G6zL%nYtX+7jWeK4u3Lq2{)X+`^w9adU_!sEr37L;>Ym}J%V7PfV^9l5g0%*swuAkV zqEQ{>YC=-;iS+3QrIz}$p2*ZHYP5|_Eur)=0#w}1!c{XkryJqwu5Qc1Tnh@+Q=n@_plgX` z+C;nFld$)UcXd#18T9%vtZ?VB*FqPbVqfnb`|7G1cM5=QRt=Yiz`6$7&o&O$<;hip zVO<^Wvk8ZFI=v(&Ht%A)sMsdhwV|=qjr^H|W6M4)4;CR?VVYbiMz#*swFSyLv#4#T ztSf)+6E9oY{C`BmtV6^5hRs%!@zW2SEwlH1qGua-TDNgYAf+t*(AGiaBXF?PZ73D2=pHtX1kPKo?>m+6l+_@cdG{6Hp+&^ zklRWOp5kurA9ve^u%B!2t)<7^BmCAi)3l1g%^SXd6mEU<4-|@9+u$c3k6VlRCmfVp zkMl~Axdo1Uip_nz*xcF?eB1!tdPZ7%lx}^G*BPo?+sggob?fQ$X9(J@?cLfUca`6g z+Gbc5Tv6&E47HzBA_@qFWMiWf+jZPnT<2ABN!2b_29`F&6g|G{;LV88s`)awQh>{{ zXe&v<{zT^5{?!ON#xueb9OTE3KeN%VB*^}aUa^>FEEQa1N}0h^9O{cjiJRj}y^2D_ zv)GS@B+m4WyE$T;IY7S!j^Jh4fL#I+2zSQo%-{uQl)fG&)qJg&e!*B#qNFt!0F5D< z8Jr!XOR1tYG3*vBI<$ptS1~%~Ni6gaj?U*1u`XAKhw!YZL%PFam(*9<%EjSz94)?0 z*{sO0ss>8uk#drs;p>Kc-=GP|C4`FlR)X4c%N>xHWX}eiE+O8C%HJH~J*$3N0Ug;*zd*OJea@ zNaDpIi(|PJ;+O1LomXh-MvB5MB(d0Euz5CNV5pD>8{z?{A(7!a@|a);k#_+}c9V*4qqhQ|3k=O}s-(A~BNBtBiSDVi>dU^W*-SZ#S%v~OOK=8q84}~b zR#_26=T4GSrj~exErDfbR{TYZ>{UGFEV7njtc*Fk=?121W~t>2Rb(e;$E?f*XC$3b zFkSQFw)v#sn32C8ir3OIW7Qv`!zqp@l6}}Mq=Sh=G=V@nWz$S@JB6&j#kZw-GhsB& z#IKB@%{}GA>|J_ER#U zJWCe^N~`i-Vhs&cK)OOp=n3N#49e}{>ng2U$nc~!Xi;{H&SvursGs2phttlK1Z*~g z1X$ax8V%`$@T_&as<=A!yTuE{r+9b&`4D5@_kDC05zL7Y8iH@B#pOHl5I@_I%7Kpm z1~?g>v_dv9Zdk1m7FCoyY~6%R8O2v?gUd?BPyl{VN`H`SHbfx{u1V@srk-o|7$SY_ zq5gV&N+Nmkk>SY@4F+CFMij^1VBn?CWO@QQ7RFeeSUzee<5QM_1Ac5yXeykfaEvgd zJ7eSA&rS8-Xl0rjvpLV;><7nlfFeBtLd^`0v8vTsXme<;=#O&NOHz7+A>>_BvZq@( z&i($R=9A;^EE2QDxvKgDS;zvX*tLV(RgLFafdd{hj=#*HrC|Q${Am!jact3m>E8-X z=sGI~(_8j7yQ$5ZaBq3e2pZLt-Nt$y0UP(2MIlLr(h{;5PWqO|RZFO17=@xEK#fSm zZY!wM7FI2J?-1neuBz=Ky{)+JzN@3W&ZZPmAKh(1W`N-8h+;_edJI41({1TmGW8Ia5>Yi8$2_%Rr-J;MIO5sX59QyAdECErDCL|^)h|jq>+!RYUi=}bGAJ3x*3Oi9RCIe|9P@sS} zL|QKJ6Vv$%I(AHuM+zzJA-txQAfK#PqEHJ6qD{4>l5!*PK;C6(AVI#{zJFsoi+raa0 z4i4o;N`NxaxOpPdRPUnH@`w`(+k&DSyJj*euq|UQX!v6pK(=LZNJe^2j{0J zr{4|B?_jYZNlF5(3R$jbHv@lnfWWc_3h+F}H<(6hzXY%M&1*5(2~Wyn?TGMK>ip6c z;?@aV-pS&jC?rxs*g9SW556?Zmz9Psmxfl@XgOKq4cub|w`rGE1ZehFEkRaptX!aC zi_{9*%6lod9knGYdN@7OR>{T1+90*+dfo1*3{~#}Ooozm?|ihwmuIo1+WqwX!N7NR zK)bt7JD|te0TmcRE}>cq9f7Nt9et#hSXI1YPh@2azfIYk@R&qq?BD9K-w+_qTDE6=?X$6VFJCfDD*=N0b1zb0tRmf z9Ufd9qo2M%J{1rGoZ*N~{3+%J+FLOaG$IqSWvcIty<>1}VY{vy+n%wl8Dqw_ZQHhO zXU2ABY}>YN+v%Net=e_gIdyi`?*H9Yqq_SYqps_I?k8{Rr}(t==RKJlr}gq{{fBg= zJz7i6b9WO_MvG!2rD7nUch6VmM5?iNGkQH0z=6FfJRx+5yYwtn*oDeN+iGY`O7VVUA}x!}9)JPXyV;>bXYQ3H1jhlT**MXPf99Y`ScWa%*nP zyFuD@bL-B}gMW1`Cgy?hvsodZ81VV~5P9B;S-&8*Ch7gr`NX5FoU*C)c@BDAgvKEnY9}HXUuOyZuu_jg}2%>x^><0ZJIT z%&FCoklUj;HHT!+0)?7?&m+YA>YC+PrP#LH}@9d^`W5v_}HKRx&_{PLSh;BA@< zAJ$PXiq0B{4+qCBK3y*Rt&7KNjq97<&NI;B_L=~{T-p~_!ke_+Ziv$_r;Qb$?}yT+ z6}%oJ(GTw1TcM(+nqZ%o=;xH(>!itUlwF^PRW*<=N~%l9xb*(*trb4YpJLpz5n1h< z=5Ke-3#s)MY1{k*#Z)Lz9a_Ewl{PBvu60S-e7CpLo1mY`|0X}LNug`+{8po!chQKp zBB}*Gc02Fw%k1@zfw7k%y!%lshoeIe3sVxKPn(q2;!#eS>K*p%G0%cym!dLAkE~Uj z%elb;CbHnIsgf$np&axDMBH&@<8cVJNfbr{ZdpVB;E+Hds?3r6w0dM#qH?|pxB{*( z{}LswNOdRag(9<;IvGuWL%pjYg#%5^agd~kr1n1puvCb_*1^737^DtRyy0w$&mI-7 z+-$qTEAH|8gKR=6QKa##l^@?c_hj&2$K|(sK};l?;XShAkqw`>sv={ovivHhV}F#3 zqo+#|d||J$tdL>HgHD-aC_){nz4(9WWF{{qxK4>5-9>oB3+(}Q2JfY69!nF~IT6oP z!$DC*ud~#7TUt~RnoPsT&PIF(GXKnrQ6-l4roo}864a_gEc+J+-|0?s;VTJW#t^fe zPcf3(a2ob`i|$JoPs^0?!LnCysFAF7YoRDrublVX)BjrIjz^J)A&xwVS2jcT=(Xh( zZ@$Tl#B9>0ahCP5|488_Li*^_NNBhhrdBkMM~cC~XxTVj8g^Tm(+;awPYN6UGvL5U z?)IyEN~c*V%QWR>H5Jlez*9AutV~4TO{PT=gi?q;)#*(qgR>Y)HWBLH%ZUSP_x+fd zPHj^j1GJnNAS?55f7cc=Nb?~9t8D&j`Iyc^T;wL=sR%0s`F_-?Sp%`RQ0w6rE4| zmOmx@jU{m6LA1YZ!6Fvg+D%sIRJ2_k5`@9QkEda+^4Cg2n*95O=&Qi1R1@dHSyrfv zVcjKW8U=&sA%T+BUNZ<0$Z>BERXCfEzOL3g;6KSvET|XlX@rWF!DEschT!+Yp+xRK z-h#7ETE=?@QMs|hJEi7{eh$OxsFNL0_j}zwKcdH3(qacT(XAfGtIAmsEf$0V4{`aH z`SOOSPn-O|zWh9mFP%GL0AbLMtvYpl2<8t3W%SCyF?b1qE=0wQIUup;kHmJHb56)J z)g6DUogOi%IxzxX4tzOW5qBnJ&kJ)RAgFe4B9YNBL>&ds@#Av5%W^Kp+$sBZtoFKe zPTopT)zYB#%3B6Gg0EjQ2kF9^`C}APa@(fBZF^>`fRu*UX`9E7ukQ!5nO(b{9fnW5 z$DZ|#kN%50iB>$}+Rra3bELz?%78_K08zHk$-;GcT!PgnuV zPA-N=ih}3OrLcn}(kv=CynY^=Fqf=ceTZ4o-7S23!24pKC4D{`Z0!%(ak)ya8C490 zydH0<1{gz?$4xII*$8d6%Mo;(hiL=@aH01ULJ?4uy7Zw5cdBq(V$?|(UdYRzOw~QB zr_TPg}}N;2kD;>Ga;|zb_sU+qb}>zY4p^U9S{3+0v=O4re1RR*0yIeb0EuL2hd;Rq$q?ei z!DSKP8r3_)R@bs$QzuFHLoB-)p5|Ux=;!4=A+x`KcqQjz zsHLlsrdF=NAZMNA%(#{AVDO_gS1AwPk^}LBAqa$vA!O3e0t^NS{8+B)^_yfX)b|Fz z-j*rkZX_ol53=I;4`RR6D$!LHhuPLevMqbhZrqIT6~D(}fh*A06j8$Rf}A~s2lmCs z&1%Z>F7nRdeOJKQry||#3^Slxcjm59-v6R5rZ_h^;fcH1R;-jqw`H22wSL%YW|iwO zYl9bM>i2Pbw7H*oFoUwhT-?{WM7&9EFa5h8O@-x(o~`kM->lv6dv=ilow(dP5##jCpl*D3&gLS?^Yd zuc;t7)M!6v%ySSW7l|-s^nYB37%c4`OumQRG|O+B7+snx;wXq;A?jH!SNKh7^2c!j z>6t&b#YXzxpx&;=;`H#MHQ?eWdV<~h+_TkX)-jWN>Gz*b?`>2rme_&Bi)dbU8eX>n zo|aL&l3=>#&0;egpV!$w=r4sy4GhG&sXQl{1N$;VC*8fG2SCHizpd&G@q$zD=bB!X zd3IM*Dc?)6_gC3tS`k;*&i%0Ad)etMX$Bl(B50dPeW+RPa}K~4J&?CQDSsdu*+xX2 zDc3eJz6yW7d>OSe9dgj;yjRw6Ls?Uy@neN(0IjC7t7B^Yj-Q-NYS1Lp3zTmRlu*5^ zW#@j9QmyBpKz&j$2oEDrT<=Kt#L>B1JrB@bBRML`#&D>4lVrXVhI`#M4~B3ry?xz4 z;(*YO0fX=QGN@i44=T&3+Yw(=UO9qJfhzC#(0g75=wfdre`b6TXA60lV|BMH~)?C>B*Uf2WOIXbbfGzU) zbA`gRJ_Y2li)HGULOdDEwiyE4E}B>R-n_ns)LAmd1X0_kO4GbJ+}%W)sBR$Ied2Y| z7_zQpS)OQ|oePW4Xe?hQdJGi{Mf2YmhXuS=seV>3>Juf68a|W$m&Cv0C-IcXifaCV z1gdSCd8JWBDF|%pB@_#_UYeq6#pgY4^y)zOtu^fmDpSXXvN5rH+G9EJ)~(4S{7Fe= zSSI_u?3VokTbDHrK1^9=*PXq~3Vtk8H8;Uebke(0s^)t>llXj%Lxn-EWq^;<6?VMNnpBetQ}!} zkK|=F=`)Ib+vk9;8{_%=msACZ6Y5-(@4~7F&XMUPv$^c?SPaq%RzxqLpimvp-J&Dt zEQnd0IIO6n)pEF?Hv~>b9qL!c2=&6Jog*Knbfk)p@)n8!(Z)+NL)h3|HpHjIUs9k8 zMoFM$eLp|7BU5e+^D&5)0T{sc<#4jxnCxb(0Gsm;g1Zb_Dq1cVJXQ=dMb`JQaBrl- zK1s60ps@qSXj|!=Bf${s12D29S{seC!|p_%jPzL04WWq9C`KNI$h;s$gq)(C+-z2K zrCi~Wr&S3j2A3X3rci<96H2#MSS*w;H~BRwzwGiBR~o<5OX$Q_*k@~7)98s+`5)+U z6(>0Au*CT)tjV2GgGy5e0ZJTCEX5-E;QIqlN!SDVQ0OnOpZ!+ZH2St_%BO6E97%RFYfgn5CPPYnEe3HBxBhMn%*%O~+pxD<@J74PS6~CGW zx)N}z4yLBU!}|C0i$7P1u+QbQjgXPzCe@Ps0e>Wod=BlIl+VzFP_gh1aDvmrdtdO2 zlsjoBf6iCA<4P3~hM2tkX^^&ruzqiXw%jTCL#>l!im5Z85UER8><=tK$QUPqFlNoN z3e(WV`WI80zb0TbD+dzNFTU5D;4-G}E;n-)Q6sdOZt^ZWm zy0GD!&~a2wZ+j&F!>H&=^oX3vm#dFpJpQ{)gL51kAQY&wBS2IbsUdNk%M_6m+S$YT zm+8u+iZofVq>q@#!2)M-P65M(ZG{w;OsleP)Kh+Xq>u?LL<$*5&p#L0J_3*eXB;U+ zdOtX15vxtMT080#LS;`VlIp%xqBa&VZ(o|uRkO{Yn$#bMeA?mRWkPT%SJxwl8KU{4q#oS0N!9I;r&>O>cPZeNF4+xKtPZdp8CTjNc5o~uJ7@O zv|9JJ1C@@Lgk1rOFN!DFY&8IGu77vG8oeiqfCkH)dmO0#s>TxKo_&|2rfghjlIl#w zFZ7SuRE|knPUq~9B5%sSLyoMGryz9JiR`8ePd!H zgiF=QZV`ymE*@mV@W=6ivBxF1Rq(IVYxU0;5_d4!LH-?Zo>|bZwYhAKXC-;bmSp_$ zPaST)?s6~K&F|NPRVZx@%E(;PK)&x&uwvrhclDia4p8p`2f)uF&$ra@Wo0~y=;?(~ z>IZAyEMc$A%ovGlek6atCPa)veOerH^Lh?(N%djvq28rlweH=b(bCXxNS05k--(B* zdxoYwVP@OnK+gyK>7g!;e4n9A0K6m#3`G$D56yqTy>^UQO0$SR*rMm(5z#WOz{(pc zBh<#1?wbH7j3h;e#lllfAN!6s=(EmatsLe=>Oi?$<~{$#Xn>rfpazn<6KzFoQ7KV7 z21k0E8@IyN>K(>P*EfhMANFbSz}n7$WN>~+891X2L*Owin%>?sh?!#{r8WuwcjRI~ zl`$wuOvyXKKBB8Xme+6Vw8-4d+8bx`i9cFh*5|G5cwp$bU&Y!5@S|)ji6^YynZFY; zhs{s+cg+{$kA5|Gcd_?W*7z~|l}9#!$kK;8<;sUQC=^YQ?X|A z93RDhxgfT>rjzTt)q-eW-Z;Mx@f1|HVP?C)*?IW8l;FN0dj8yB&Dhfhq8c`S8qRoq zXc_M~j^1y2KtlxyLMu70&`%>4QM7M$=k|pQU)5+cR^>g*D$Q{m+@XnvNq4_G$73HRvD?et^Kuku+ zxp6{-OClC{L$3ZeSM}L6JfO-(-&S3IgkK#!CE|Z?{Qi_Cdhko0VYOL%=iNkQTWy8z zcE=p?vILG%=g1nPJ_WL)n!SHJ$927m@g?&t{!e!ou5P-968SG#T#DU=S^leZ|@ZtlY*icaOalDSESY5qh}!y6Bb{VH#+Jz4A_ya#RxxTlDCZ8DN~* zPm(t7p3YuMS6Y%5E^=jS?8M9t2xM!tKyiZ2hZ)B9Kw-o<)brxm;$1m83KuRi&x7g( zrK|;T?-==VzTGYqCOiJsA|b%6nU89e*wu;rY@2QdwKh)&@=D1@^^`H_;ym8n~ctZ@XuTYw2oIO3izjq#-!FWKRj$tM4j>A18-?VN` zYLKWzmSc1|hoqALaky~0EOZDrePx$ooSC7Q1JC6A;Cp7IE@bJz%joUylX_&>-f5zJ=2i&5U-R&qiXt` zJdY;}o)Y9)lOKcmRHs0fm6SUi$P2WsDRmv&D1W9jljk%4WyGqd#0oRkZ0w`aYiDsy z4!asR&J(n*O|Onw__x+A>cm0D*2Lp=9Oyf-{brh6=#UOBTB`9@e3R^3b&n*?Jcpj+ zWQONB%Foy{lx)-q@+FrQdSJX9IWDs_XcDd03g4#GE!WLDx&Q+;&ro;&B!2V-CVzfM zAR~12PowjmM{{XWhC%9=(rLgq2rj-4GY1wf90DvtS!!lG|8n+Jr{nQI_9X8uHjYf5 zC5ncLwZ{FUr_MWEK0*S83WM03_j0G}bb?lz=ky?r83Jzp%0K~6kH+tNT$IlG(U`hX zHH0>J1do`!D0o_?NuP@>F^tgbNQvY8Wv4NE#!CGp1KtT-UNHymMDm)sYughG=w1 zX(1a{hK5)Ci1}cxkp$=({JP=FDgpk}W@)d?cYL5N@E{n&_3-VOQl{=lUX_C5f?i-b z+e<%pT0bG(PZOR^IT+NnDob|ud9L@ZohJ`Bmd1ox5ndsLvL_a~cI#`09ILg(hd)y# zD|HJVIz4_Geh+3R_SG|`WdU!Pvlku#-9+6`v;X-J#~=Z3N4Xjke0d^ z6Nfplu{|<^Nv(Nq$DkMJ*Ie zp9{nBJB(SZ9AV5(-{jf`@!}iGTSjnh>bdp3YCYZcn~$7hc=d z7i5}u!zxnKCOa}NL)9vbOU{4sThUebo`NB-pq7b+oRsp(V{{cKL;L5;xt1xGL9;br zA4&(<;6l(zTe(TH97gXD-tR1$o(q4enq_n0{hDF{j(|ND(@e=jwY;mHV^ zRsFbpG#qoi@FW@6nG5Th0LqRILwMDtg9Icobi`kD_1G2T+*K~6kn%x+#!S76f^oZ?X@ln0^hwbj<@k+XY?^=TVqqeAX$ zRiZLcdv0FGMd#NUATm!Y^RBf4UcGpU)A)X7eY~qnj43u@WFL@9s=cOxO8Je+HS+0C zZ~yTqbnR<0XYaFIZeGGZ_%r#zVwR6h+=NhK`R^5{1n%P@0rE~!3e-bLay?Z-Sh(Yl z0LN#kvr|K_{s61cok^%2u}H8vlfz5(Z6hXgOT2oG| z+!Ixwz71!|X4d1sO1r}1>6RClEAUe-Ox9YGf@{@p%>s?mBjq3PK5Bmh5()8YkL;C(svca%JyK`MSXJdLq zYjhKQb1)Y81=hvoIY9(Z?X3PBo_eM$z7wV>TY)^9Gr%z9i ze;n3QbdP&YzU_h5%0r4~CUE)<=E={SUhoTAB)76gkW}352||7n(e1nNR1QI^7Y%rC zxbFZ%)R}!1SX5I&r6%&K>E6RM9!tZ@L!Br?k{a$e)--a` z@cKN`QlPeu;4VblAdNBM#=}m$_0oBCIVS*dhoFlg3t+e7$KlNbXi=!pWetH>{Iom@ zR46c6l!Ay%RLDhI-Bm|FM^(Pzi8;O9S9O8y7%u#g2j~bbA`kIxR}WcIVwe& zPV<@mR&7K)UU6RbnD>5mp6A7q)cd-SKC%2x)$a zbN98{TO%H{b=~C<5y^DT@WWDssXt4E$_?GPIWximAosS+9nZ8X2C>!6HbFiYBSPg4 zn2RT5V=tcX3s1>Uh3(WVTM1m|pQB1At$S^BpVDBpINZ%CMA%vDGeTF-){#$Na1gzZisGo&T3bX?b>xLUG1|sG(JpFv-Y>0 z&COQMoq)q;&p$h$_v(=(W1qMnBFI>fODSkI3MbX(6`^2a`yj*7U~HL77qQtbdcK$! z$6+qO3f}wc97>LQ>8}hVllh($1M!dbjA%f<@4zy2#CRHs6qjwqD`c(6hF&K;v^-f@ z@n{WcSaNYMvsu!&r8u40*n~Dld`35@OzN1+vGgY_kbSGc^@b;WTraq}tX&MLYuIgC}v(2P$11fTQR#hBqX-QTg*Z5fP>bG|m3!k{L;i z0?gnr-)N2B6#bZQR@nNJDX;Gq*idef=NscvvC*4)gTpKWPB*abQBIw98oNu>TR~7PixQ{&SI;V*#0f@EboWYh~&KwPac<_F*1_c z!NiC*4YY^lxoi(;-adZyJ;e$Emk!z?NYiL?oI!RrY1m4kc;~f8{tnlFAL8 z)SV4G>}cCHy`-8zUVdFRtJ>Qcldx$Omu?lp8*D8;(^+pgA_d7@Yk#bawNEupXDnrZ zzImh!(Uz^!hJ$ ztc1z7u02C17&thxFzX>+!^e|68lF^l%qCQE?K{oFd3c)j%qxF zM8fZKc)2>(Fnzd3O}bD*c&x1mn!K2!u^Q23y@zbn!gdmulFHy=N*-EoGgwaoWZ#tY zbd{R%vbwdyA)L~%fWU(>a%8hWbEb@Df@};GCuQ&7o>IFufoN{)C^o-t8-iey5VS6? zt8!;zOPNoc>hC-G%J=#TXd$io6TGyh=JT4Zct6{$Ygd~rT57*-N`6vX~9WV5=6yuIbx9z-OuEOLrrIWSWp*? z(U?DI$C)R-%dy#Z>XO!$UGtRMhI&Y|BS>84(Sp*O(2n6Z6_q+FGO)QOBgycrd zByHbEU^6Uw0w}~9`}GaRZS1pA9Tx#3hs{=E+MkngI+~5B`QATmI5=_9@YBPERZM2p zg@f+$-6>_NzgU_5re%~%>hK>#kZrG7P7abD(@iTW`Xr6#)R>oGktZovQXr9@V8`AM zbXy5aCA{=cjgX3#Tz+}Suq5$9&8$psN2ryv)enzTxhmtg*aJqvgP`YXkP(pmvvU9F zBTgm2Dl*4QKZpH?D?hCkU0J>eG<4~ow|I)F%YdJJ&AL6Pw)3v$8v5nZ!}L5SD7_xl z=|?(&)Xt>#brVj0)%5W~uYRL36VTULGA8Uq#b8S92O>g3l7pDy=4>dQqC9@m9=@@~5SdV4$xBjTi2>vu-Mv$nvhb7S(md{LC-BeKelN3dj_^l>pQ0T?S)NfjmgMl zK=gc~-vVMmq6SOiM_IUVbrrFyU8IITtr0)N+d4phD&{t_-$T$xVowb5PJbGJe>xL; z-B^$rDAS(#_jq;uP`PG3^ zT}#E~vt2Q>R^O`l1DQMje;_kh@DF4b1^VBRIcBZrp9$=;md?uCGF$hR>A%ms+J|{g zn{}-(tJ^8|9e*E8p38-y`Xl@EkfJ}cTp(LXxU3k)OSn-Lpr)Bc%OH--R<;xtINaO& zmMePMmtvq@&Kw_B$`QDYNKHT`S3J|+01E~ha`wP}R-i*W_6rFf*7!N|3OgLXGQ928 z00TSa&&^<=QYAIhiSr@(k=851GW~Uiqkb#?K$$^kJB0EkD6SpLccrX%MVmzY#)s;nea* z1QB%YAb27@Iduw*f6-@%K4d&?E;uE@mE0{I9v?iN9rjGyji{}#x1{CLcXM~Kfv5ox z27Ehn|4sAhWNqhUEg`DWwP1xd#_LAc%fVcaB<)Sr;&-C~P)B#65i0fPM-lY=4F)kr z&F&Vm@0-zo8KgwRM5c9!??gKK-ke1&Zd7W8Z^$J@KB;myWgd@zVl7n@M<#j$?-1jlpf-F~V-5)Z&`jxTBXOr%KSZlfd(zpSv^EORP${TSSPWyJ$BxcGC zD`0lNlU7LZuZF&cSH@OM4HMIhed%M+)_z0A;q8nVQlN7 zP^hl>HT;WDHF$l)wInyfRPtoG~C5>s;VO=4ar}X z@QpPu!Ch1PYH}ANpBmS7!Fj`TgXu}P4fA3j38pX&miGJP?K$$cjuqY5>h2kX5 zjw;45yZbWXuF&0`9o=?3ENm#MRO>eiHbQ#xjtLiNH*;{8ldcHsHKn`I!*uN|{jGe^q>SW6?<{5^4R{z~7ck=N5_|X6`;w&V}*xSLLIV-)X7R#Hf z8iLw^rzmZqNP|Di*?E$spXh1perh#Kqo5le>ej->{P=f)(ao{Uxz78%)h zQvaTh(qiU$Hfpk=9rj95I&d+E*fNlb!(21ZKrHf!;0OB))`cK6I>a5Db(It)@n&Y) zj{4P#3>_I!o*3_GDZO6jJt9LtI zc8niKmn}T)Nf>2T_=8n&5I9T>J0$3TxdY25laPft(i+dcKRRv1;g5zI?4XWXhIxqCcK*?n+5AWbcyU&9+{5e<~#0(IqeZX_kY;~ zn_}uMN~^7v1q8cWl&`4QW+yKvSBH1M8hV^rX)b=qTL>qC%@bo=qnvM!PiIHhfxhNo z)iYlncn#mjjk#OXRftGr<5_0V2k=(IPs(yo6K7vnPY)+A2Uia-2d=+xd^zj3Fe3w_ zW|*rz{K@^Cmi4F0G0y1@{fnOA7alR8o5w53KE!42?-e zjB_y8-DhXcE-h1Nt}dsJj7RACJkjsIS28Ohvqk)Cq?6F^nsNep?U=DRVN6p~f8P<- zhFvBO87QL{P$7gczz^c3qjcxTe|AN!jFY(T0+sYz+`4GvBxa6F?RDO>%GgKjWn}4uMvg8fjwwR3xRE+pZe`To)`Rz{!_xijMW)92#Vk~ z&OX!vk*^*g&<#=P?XBlA29)giDYhWr)`3#v9jD6bvVbEu4D6ZL0~98<1BUs|hqVJxpZ=rK4AD26X_0cP5(Z zS%Bb-vv@gIYUsxqP?CDT>PxsbH@>p`Tv4yPduUe5K|TRgTj`Jz>-X}MEhSvjG-~qt zNC|d!FwvWZ3{TRrxb2np`U1$@QH}=634VyrVS_z7(q)71pU94$P+cO#a)}20;1&iK zgsa}=#%c)N8ZyOw$dNt@mL^7%)!eiK_)K{f-6)KGaJ9S&FIvgZzpuHjm5ZZRY5^Kn zfF{qa4EOV97ThH)T=rKewH#Ho?iMZx+Gu%Lu$*s!$BT~V^)<^uye!FoNRxi)g51M% z!3K>-s27%Deu@Z_>oVC9u|D4soIX!4kl*~*^QNeP1 zy6Udn=smB!HFyPN|4WWfqrY#XR!R3edosE+ytNAMSK;%wp7R3rtlK0!sxIPADBdM- zu~PTcn6mQuYp&3H*CNpIPc>UU>j7t0iE-f_*mu22$3HyGn#SF}0IHb+$l~yL2lH$93rqDIqF`i8}C8=za>Qa$p4TKc3S_D5Pw0b|4Tv) zzFXMtY6oQQRi z$Vna{?nq|sX<^mudXjN-HSJ)lRPnzmxC2?!e8ASYr%jClH@T?C2xYjsEpH&x5Du}C zFrJJOSepIY^(0v)D{Jo#=WEyC9U0p7@j$%tmSN$lQkq|Iysa5shE83Qsg-BGsSn* z;twtMGBk4rdb7ktVRaJj2mYYcRpXIOnuQj50@BsJ)9Gz4^;+C7e+Fi-B(3<0>$=7+ zY<-5y&rX;}A|Z+~XP+_?mCc+;YLYL%Ndv@gHA<=n+oaE z3&O(`CQtTWk*O*;AZJ|RGjN9}CReC0&WfDnDhuD2=ONt{D*p``+S0m+*6%X-2EC44 zeUrgvu%xXE$Fwdz65*&8`*HDf^>CUmq}!fGJ60QSLdgiDw$?e5b@eNAtE*-Z{ySQD zT*P_Wp&BM@GU+@DI-jnmvu&i?3vRyhF_wD#H25(Ke@q`B zM@R{KDHxBKhuZL9bx0&Wx6Aa#In!H73ic)w`ZKKBr}ClGPj7$(cU?#Y<1>har(d62 zqR9vGJDod2Nf5y?CrM+uz4wTVMQ3xnTnIhn&0B7uplDT8vu3dgaz1Jl}qOtUUPPhmQtNm~S;et-1%z1laD+F6q5k{sT>2FVU>K#`)x@Sewj$@xN%1={X=)X^;{>y+|TpJ{*p?bWHeIbeQKR)L>xY)O{iTn3} zrr45r)XC3tS&h96}4-!BJW<3GyeGC--d|%gBa~E$tDTaOkhBij$B1p>krAonF z6(ad!Btk?=xH@;t#V0bon|USZ{ivQ_>>U8srO$E20l<$F;-b?QkBwJqi zLg;$7zt*?Elzpv4D+Wur`>KHL==04SJ!Gy0tAYQydM`QK)rOq|&FD2bpQ-MDdxUJ3 zYlthCR_}0A%zhzw&brC3ZZw$NOK1<)U`x2t`;v$7KH3U$WEzM){ApW_YZmd%{j2Sr zaZosxFK>NHB~w%fzpdrOt>9x+$+6K~!pOEYi9qzpn`!x1ap_)@UuB%-6 z9*~FFj1EnAX>DCe=Ctj~+Z~W)7W>nc!+lp`m2A}Mn*h=!+K9Mc&^X%QRzKW#o4|*19pL`-V{R}cVKKkc5$FxM z28ii#0i^;7nrpB- z<3sb!VT#V?w*xOuaeWTCeu7uo&#NQR@ z1R@W?`I;5I9&xSskWT_RYG+)Ox2h26vgL2Ux6K>?aC>@H`Pmbr=xs&4;)zw$)cA=L z^O>Y=<3+^FH-1#vCr(rSEpf^JQx0YaF+ZR+=Y!g7Fc=OcpHzB=;~4k(S$N*>j((-v zpReBs@EPPyy5&U*E#lqZ>39P8zD#`-e4kwH?a=^sMCX2e-oujxm$?EWjF9rGYFX31(|n8)P(oE1 z_-L`zkBMj8N4mlC=K8gv+Vv~ufC!6|KDcL8FE3G_eMvC@9p|+F*o0jk^kKz`Z!Qy^ z<^xfKxS1aro&?dw55Udkt=0&@#q)K#{f{wdtOXc9_P)qUeavvINK7rwIp6-Xc%ve` zzog}xIWuOjxPnP)1#U?84d(07XF`-fL+kXtbPJL9dT6L7k+C;G@87S}K)`)D;i3c- z4efuL>7pRiuQl<}{hSONg)KubdSP}uJ?{X!V&yJC;`&Y|DF(S2o!8j#_k6(as}`f! zw|N=cId?7Owy%5cvJ@6-jm=QIaHTx{_S%}yXZ4;aT|mON8-+1+9m6@fH^&Q6IX-v7 zCsL1coQhkT2;~)i>&UHOi-23_J1fkeOMauYS=0=N@sC?Z6Mc3CS#O?KoFl-9)_2Tv zGAI3vmapY=y)4&h0hriOXLDFprmR$LhH4d0-j&y+DIeKs{LqF~;0dpz7^Sf!D}fhG z!0pxWOW~R{iQ(HagfWap+WNnq*!*KM=(PK6DI($kv4xWq1YC}~mB%y$T&Q-h|CVTn zY05<)a+RS~|7;UwBo@Drs~c7HOor(&Vc!@?@iPo}j?~^{M*YHWcG9-}y1Ct#0M^B5 z?rIz%v4&4+CnKzPvu=q%*uPAK&B(N*-70ccgibu|w881FF$H2ul7-#etb~{SOz1MLhcvH_$it@f~pN8h`MjT`}qYwT*u|qD9EY zcsL?KP(0VWYeo)V_JJ6tG^lUML1>$J-Z~x+@XY)Ci*> z@zkegu^nHNs8__q{8h>}C;ZMTaTKqDIL0TE$N4=GD38&RVvKZ4Ff&~EiFnYEbQ#8Y zANGhUQa2)i<#CGT?K0(u_g+~uxDn-aDc1A1M@(QhpX~nEBQJGmVC%Vv@ZU1}K7^yF z_r)}ih%Y1i^o+Z-+ZLnSy|0g!8#kbI1&?9ZMV-Xus|+M^CXs4Np$TK^902ee1p~$j z;0naUJMOl6%QE`>0dTbuG*Ivb*!}8I1Kd<6@A&QftcBb?`kfaZ@aq}rCws9$mWyE) z5Zkx%;rChBFi?3FeMkkbgu~4ztM-$_@^lYPfYnC|M@63$$7XW;iL&a`srB(GAAk%Kj%@HJ&s9T@&@y zCf-xezKT5SM1D~4>-i!lk@`OJewQG08ie_IG+dd8~moysul zovbuK5dw%vOEPC0=n2r}3z8EiJ5?KnHL)nI*%XcRt7&V`8hDAgspkK~{`i-!(b9&B z;TapY)L9y*D#v!6Q*~_651>bpHY5>i0Y;iyKssoBg*IZK4a;oW!hBysH5E+PN$!AM zNp6LT(J#dzW*DThPg+3+mHZm{Dw!l% zH&FbFiFw1cri)-Y3BHK?PAb(yh7qwK$-a8%sfAMs2VOe?{nxLb*VKQ+NG9>m}Pf0wn915*j zu0Nnn6_Ip+QpVboavFvEEI8dJ(t$%Fc|+V{D(`{8 z(<~^IW|`Ex`+;_PBazG02` z@bpaq2d*QIG@Ga2#ir8Dx$&f0ro1-x-|`m$I;>|UI&yl~Dst-io;#+-nGVr-8c^QP zG=dv&RWNdf;v=>^`$lU)Kbv8Un4UF3!N`rsdS8x(hB`JK4U$9%^Z&&vxr1u20|GIIy0Ask{uPM zGB-87n~}uS#Ywbf6GRp!8T%(a2Jy%SwW`t9FUAb4=9c`Yh9!M7tNA!|SNFf;&SzQF zZuS=OO>T~mPJavAUC3F)Y}pzrc!Hi5+K*X)hZZRwd+K=T6KwZ)gZzGq6qAflqwIe+1VF|Pv(RQBeoS2 z=%oMqw29MzEiZjTCowo#9f1@2`RhV1LOb-DlQd6t*p~*iS^xuxFGI%97-JBml_*k2 z$n3V`aNOL)QzNdAy+IhkC4`ZtN2cXMjbwElW(&qWp0u&x($hrosV3}SR^4VOPZcl> z{c^6-i;8*O#NV4jGcm;yIO(N?(EJog@)}7cr}gXND8U89UnTfcrB2oK&KB5=wv9=( zjFp~?8?${1C|SA$RU1)ppLyM-$+e`2|7zI8la~r2KpnTFM;dqK0jNe+6@A1I(kBbC zA9ZG(N^yhj;2C}=|Mm##$Dfen&0BPmAC>m`9TzK~_!g?xEmoP)u9yJ%GurX8DAxq} z4r}lJIJK*9&&UDx#Sf40H{;et!{mRFbdAxKG~GJ3ZJyY+ZQEyJOgPCT6Wg|pi8*m{ zV%wRCZ5uc5cmM2FYjt(^kLs?fT@SW8|Ec-K@3O$@GnlfXw8>$w`Gk;#zQzIYz`%|F z@W*RkP?0%Wp}*>cES{Z+ANV`|e}Wek{c@73F9mRX!>_$SKmXz3)`(KCZrhwjB0ZQD z35vr9E4&v99PS5va5UAkX(6c8aCKf8M<^BNpM&@V#`mK)U_xi&p@6wD%UFT&Kyd4x zUa~Dy%O0CYXJ0hXkjwBTG!Sv;0LA}a2Hx8AA|Z+r033_!V!!Cz5rKaYyYzd@Rp&Cs z5)-re=L-Tq^?S<;JA#olO_jc9 z{N3T&TsXr~yo-_7mL1tAM*%>BU=;ZL~{59hZ_XNKsMrrCq(v_a=^ z0cP$j{XzwS*CLX8X9>)VXJVosX) z$P@9?ZcYYdUv>->yeeabj#$020;9V9tw5<8FK%qP(OTfgFCE*m2~$aV_~c4(qV`Pl zM!dfaQ#zjLFTE8i)0#aYlf8gA$Y{G5wl?B^&KWt;&kf$x+dhN9y&#N{A7tG@5ZA0? zg3yTJ>t)xcwZ3obxT73jL$vRRr}oRS2ug>E&( z`0$&s&9gQ9&SrUxSetF?n#t<;*q50qWI3@XxA!F(kUi>{9U=(Mn=D}ckq}xr8P?bFv{qksE~8kj4e7h&Z?m;FUNt0{mOC6m|Ma(b>+X2b2HG zXza0~PM{}oy}UCHbkj+o9R14t`Mgqw^b*U8xt|H|6dD^uo8ke!gTQraMVkX{$Qg6M zH={Wcj68%w9}4ojGJ>e-hUF2-4!m9*^$YYBar6#Xs-h>95=PXacs=!J?)|`eebtb~ z6%eqB2#ij+n?;lN-rVuX&*rM9m5o`zfCp^$(O~_dtU*WKF0UY#{_uya$gFbL^aDS- z^+6gOpu`n4r6p3egZMr8QQEg9xwr2iEg0v0@Jra&D~2{b#GK9@2Z#R_ZD8BwnU3zEDDV07LwhJMY!x!Yo`=HK#Qz%OrL+|xi+=mrHR~AIG^CT16}McL zw7xz1pUUMYZ^oPV51*U!v<~{Bh|6j1tToxH41Ljf+dO~2FQ_7(sr&q$*?ul)ZazT7 zYYSbGT#9rfpu0mSpeQ^bYw{ndpCE!|f^niS2l$ledy6ovOZ|IPVW(5fPwC~Hy#yC+3qwq)zuH4Njn z5JWPmi9L9Rby7HPSE{%YOXCY0#1Ea@4ItFgKcUxE0Os;qV=HS~F#! zP;4(6IvBPX^9G~JD#VA z;+Yt2V)25Y}7NGPI@ zUzSw!11W=2Xq<{`w36wG-s3`e#W+ov$KbWr<<;E9>wSJzwo$8U*zqUA9i~NEyzbMd zLdp?y&;18X;`=_GD_^hhWpZGUQ2o*MTA6a7AAqnHUCb(-hSR~Xz{>_8lKA)0-hNaP zQ+$i|(F*W}B(WSza1_+I8BI}T^}gck^RYR!m*1)-Jm2g*|dkcXb5rtN$rU?0{ zvi{zpa#;Md4+6(wBbbrwM;3|CT`Iz_;^y!PVHTp#DXL=E^kA<@lh0J9V4+2gn7;Rj zf=E6OFs9TLX0GJPe`J1M1pR6%bPTR!^?@W|eNo&5!`XQz3ej|v$A?cq42i#+cF*V9cht({Vc>@NiY`D{TC+XN3Y{r! zl^C7{GH&_=p?4MOm#(ls1^Hn=pqL{4i43={NY%aj3F2?|rytF-fPjaGhj>hv=mrMd zdFNrk{%_JUe#imP@awA?(L${suai_=4>n}tsGc+u;y&fdPySg5lhhlcN>=powORlAV z5u$X1-x&>NpT`2OiNAAra2duR(rivnH^IrHlhaerhff)cz)t~Q0-`Iw7{5g2e{XeC zW(|Lms?nam*c>SEPEnliIio4q~0+5tUz<4*z%KGw$?^_ygqA=Y4pfwV2s4il(jkq598Y6wsU&_M4+ z>$gAfMmFcrXiK^v+b*Dk$kOUi1hj0jxwUm#8wcVmRqPCiI1C;V*jApvCzbzxtRl?K zq@3)%=8+HvWQuObKzJXOat>FC2-|BPh-rA)r$d=d6eL5yz)+>(9_?2GaRN=>=8qT< z$Vvu4tUfeZ2{DGODx6y7R%B>uy~~f^$ZGeDG5?@G5%c8CI7WqEkM;nNu2)62nG*3+ zzWELrFKIkHi4qmX2TqUN!bFm91fcf=3QZ%Qj^Pa{ma+!dd8p7nrdfJr(3hkNvT|}{ z(94^5Cd%pKwxHzBDQG6rG)MwkN&JU%WM&+Vdii7W>HtoNcb7Y=BJB1~69|`#R&1qZ zyeM^@dQ@j_yHP9cf`J{zmng}zI>4_Q;iBm8Sl279R7%^b;j^qr+pZZ2GER@}OPn5a_>vA#VCYqcn7t4j*ybI(?tp-&X&UwKrWb z0%`Q_kuJRMk`#RU7g@rdm?`tz-zBk3gM5YY3f(b)ccVyv6wF+fqIIm@&vM6~@~-N5 zj*eGNM>>*qT?_?&aoRg2e_t9^xz0Ag44*gXyC0b29lPAqAtG1uiC;pVN<8)#H{o6e z%{uzJ>0VyqS3R<%H(AfV?g;9pW3@;C7t9p*IH+TPcrceS3GMDghz-6Tc%X0Hjxu&3 z)$pxo&2V_y(7G_5i%ulEXGVR~>b&|5+#z?*xitO0*SCLo5R0fj+Un7Ef{Csl;n)ur z>fP_j5FbxH^AZ!V;ML8rfT|E4GS*ydy3Qe%bf+0C8zOB<*%)G;(-zU}Kod;qQl_ng zL)&5usaN^jZe1|?{InrwoqVVZ-Hsn=P=H3M3zw8_H+O2(xj}Ek=P?U;M^TWlgFEil z&S_88c7S~-J<5_*mQ`>%^z0mRt5apCuxS!3n;Bre-uC>CipeRDuquE}K&9pIhYUY| zRzz`IW~1V%@d*t2tnUmwa)nRB+}AfzGu*>J>a7clAVJ~21|zeT5JicIK6+ZNJ%<;N zQ36oo)PTXylp>L;0{wlPDjFZ} z%C^`iH!j7vZA-l|tMRqZclN1xSv=JLax%HN0mvHU5Iogqr(Zpv`s6upBXQRYrCJL8 zVV8RnoL{rnp^j;L)Xz+nanj+QD%){rVMm&>!#d1NF>^w3zjncABR6K{P1AFg7>MIU zFMh_inab1igz^Zxgt>%;^}$tQyL$}_d%rsWC1shwu)D)o=p|*mreR}YUL@)MjHKhw zyfyoZI*f(_6SM$vnzYAeMep4S{u724=vdsFCNI@V+P&cypx&KY@dZx7Q%n;^;W;6< z;yXf_@3kTqUePecZC%*A%dPNAVm*f_sp)3eDjZR!LydqMQ`#BT}Ds<^=$RxW2Vj9+NJyW$udsEeIusj6WXN`b{}BblRn$O zqOH7Ma~4+r6=AnBbg|DDNE zT;SIZHt5zw1KU5$P3<$TJL7HNSblu>&>;a4=MAjOGJHSQ9s)pFx9T~260orwEnW6t zXf*!i$hvPKNC))t41QDYZvUO1D!Dbp27h$|j?>_QH8O%F{*jtL`iF=uT|v-<6--FJ zVR$~f8!G1~Gm<7m#%QpD9_N-=wu)J#&m(tTKp9;00?-VBNOrc@-J)d&PW$1c{@VPd zF;(U~hy1zRAY<~mysIW!pG0f4=}zqrdzNe7FC+YB!OU2F)lM7g@hhQ+c;(7xIA+OE z`9%#i-qnepkk_Hgl4n_iDtq~;@t^(@J5goHsH_8hk+=Hh^)p#?YeT>FznSW4h`3q>>yy+I# zo}*TKLobKloMgP2z2vkGn2;bGOWs~x!|``MW4jK6C8aGn#$o0BLT_|KoNO%KtocSu zg-0(58-<Pxui^)v0&b`p?pvR6BT*C z^XydJUZ{Alea+R7l;o+}p-Jvu0SGbS$Cp?>G^$@;GknI!Q+LJ5vuzK7=WCq+Ke$ME?VF1zZf6ei#CS5~w4)>!Hl1 z;SC<@wc4EPH*gn{nvPMf2VbN@qC)(SNz=SGIg;~;vt@73x;Rm?O#gp?73|yqUc0+W z+NE*x^NV`qAcyp=TDpr;pb*Sz zSU|5WDP5_Fe%_n*QU{_0(~A0@EHgr}*M|jHxJdU|xD4~PVYMOEeOh^h*cdYEgi1G3 zGe8C{hv@y$t(m}5-+SR=a8-g+I3Soz(z$^Poua^A9-#k$nX{u}Y_9|J`u%(?+fbgN zM^Ixx+EkK+tG2}1rj8x-H4oA~TX!?h5ezK^W{U49r>sy{nFVvaVwCT zcFI9UqPK_^oaxC`s9x25YS?<8JSrYAx5e$g}@vr~tL@8!{4L+xy z*~9b12DXl6gFm^;F!>Ff+w?VOF!_|Cb)2X#Y(N!QXEDqQw%Gm)mUDyE2sXTkaW%(c zh|0TRx~ZG;p0~vjkPdQlnTWFjThu&T7(^a_d@^uuxhaME>Q>L#4FwneTD5a5Qlw6b zN@jo``57{Gt=Z@G7RHUp>?E_gG#113h$m9*>BvqSfJb)f9fW-xR|NR&CK06`5*| zO_=WXGGfbe4XurqKPWw%T(uJ|_k{n_DOa$Bns_KH)eBfXar(vyX<~aFphq{1;(XNm zz6#pZe*La*;o2!tNhTS;n!Jp1nj_!GqC*!uzB+~0u9tRvjd6j_@I)`=mR4fFWT){I z(*lMEGtS+X3yFe)chH6>A zy%g;16O+$*EFs~^7d(i|Y33rE2nF;OMn|MYSvW}Ud#=f9c95Xoqq`k1dy5f6h15h& zAfk;jEIfB<{;?LfJ)nBgUML3OoIEL#UI^wyeA-Q2O96GYyq|Ay36$VZ20ls&|B zhtUSOep0J5C%>bMZY)f?7q8?2iIMb&mi&aG(e)pI51vRY316>*E`ml0X_9W{E#@>v zQj0Hphw}0y3r;{KgXADmhbawqqho2&h3#_LM<3ZdM_bvqA{FVWFLWswDNEmm^@W;} zZEf0DRC1b;X4Z5Hf0PKgN$PFu=hX+Y{;SVeh&SPZ7e4B%?a}NJ}hn(H(h>taW zOTxgAuA73oSc#)RwZbi#1@D!YuHhMCTfbVh-AT@Ice8D4}(C_A1dBgAcPU_FUV!VcA8)6wQ}*YtO(~3^l9!?5DF~nbbOD9^hnAqUrTW6qYNsL{(pvK?-2ikcOh?{A_0zbC_YYrz_MAsvHBuz zDhe9~+MDmtRDvkWw@q=x9|*iZPyyDN z(?=QVc7}B01=?fZBuAr1y)_WiAAi-~I_{tLI#H2W5_yNd5=!l{J$E6%=C#ts_4-!_ z0)G=CqjZ`%lY=>~(P3zx=7Y9LuyZP7c*B*LNytjbYtPW?m>itrF=>q{|BpJ2TV&VA$6vF@0eO`uTwc^At`m3vK0q`7PL{ggbF)`#pk&+p% z_=XsMD8Rw*n^X$nKKx*1-YTG{MJOmn_yorg2{a%@jW9`ZQ?e){$c$(iqA)X)7fZ}) zHX_*85Eju-*ec-fh(rOn@9Hc~B-kDJ9Ug*@u!v0~4;bUx>PD=Fb}}Gp#p9G0WBa#@zbH%Ih_nXQOE@_Kb%WTW{Q~QqQMT=!y|+%7glYmI$FRXJ zjDdWV%@}#bV8HlRDN$bi8B;#9Y_&lzNZdHm*~yI|)t%EU-VC-l<*E9SUGAz;bmktd zWEA5^1^pMUm(o2gKbW!Y$Jtlp`K;?O#0X%4_LASM*9;?0~R|j-@5oiA5Be?A!eZeIi!g$2BCdKZvOz zhU|`p@plIBaVg~0veyYh;d*t20J(?&yFfZsogz#kM)MeZ;wL@alVIU%U;f}gwo&V# z9_Zjw=Q*A>K7wsg^pf-^iJae|n*jsMow3q6Tu7V zihX~#fug>#tD@%U+{Rp|96FP8^6&G!32Y6iY#uP9HDY)^q<|rYFdEuU+u#bkm?pP8 z8uL(9A;LZQ(fi3>46C-ht^dO202}wUWIe`Zw%#24U>&KkXwxE^Ca$06C(6u0rOpeG zamvjgX@T(-bdw+|2c`B|AU{iuau(%c$&n(-Dq*i+J7Wwa@@+a{FTM;ldZ%Vc}#m~Hl$$+K{AizZS)p76cmIg@d@OADI}%$ zLsr5^EQ`#W#LNFh+Ouj(uUpj1>`@JmkC5La23hW*9W%N}OA8YB*t6O((xZ9mZFBq= z**O1;0so7$|BK{Y2;$##oVmFBTF%;*6i{l^LPnw@>;8)fjsI&m|F7MeAW>XdPMC$> z{M&>-1KrcCfM+7Sv+jw|Qqou#4TXb(g%KkRKLHmfmeSA455&gD8QwY3OGF@PZ0Q!; z=TmGEjxq_~8bC(;5bj1;R&;yYg-l@tb-DsYabQaPBfKeQr5@h7k{u|6l8{E!QiPI# zi`h|>Kj7O2E_jCK39csS63&UTpWtxp0CiipJmg538}^-m5gGY`XCRGefs&=rjd1l_ z%qR~z(6gbIc%!J!il6!GRoJ^lrzO@wvK|4#?Zc(`6fuQ9d$KmW*TQF$^Dz>>SZJ$G zGjU__q@I`grOqNZrJqVNA9W@PLm&}^aC_djVf}DT8L(N3hI%|QWI@s;1W0vW$#zsI z;B@m+EOdjO;TgJ~0NKb8dOe^zjR+gy7wd*YU`{C>DYWc0dM$QSyvQvp`w_gUnU3~L zl0XJw6m3PiDt=6sTq}Gb3~`pSp~9d1;mqTeO@b3a&J`&n^rB%MfhciZM;o2&41Lw` zF8)BZHe@7JJlri%%5`o{mMEb{d%&f!XU~*EU(y&TiOxj9!d4ZIlaPjIAQ>fl3Pw35 z*Asw7Imz>?5Y1jFwMP|7P+^pihT%BSL_rKieC*xN`SqPhlhljtNd=RRGLY&Ik&T91 z7pch-@FI0?i2|f0jrBP(C@EN&01@~J56*H32BnQ#c;{%IHXykPhMPW$2sGnY8=@$6AXe#Sso=yTs|Kye6a!q=O!-Hio(M@ysvB4SlzBD906 z;*7jFMOcI7=9Mdo2Q=Y{teSLsgk~goPu7&z?B8jhaU@>b=+}TUH ztnNk~ZTKj}e+2IviOMVZ0&M3FzM*|Ei~ml=U^+OrBG-dJ{~KvWb7Kl88-BRr8012Q zZ$M^O=;RrFY^?)~w)q_f1V~R|iKMDPltC%(k|4SHKlk8d1Tus;q+KAl>*`^Khy=1Z zA17_oRSOL+n&7TJMc~z{iE^j@cKNIOdO#JoLLDX4@Ec37$2sdvZ^P9D9>1yH!LG-O zA%4;RFY|-F8OG9POHNglz!yHc3W5CS`~G`#PWZ;O+n@b{c+x z!_`uXFyxB@gWTfLW3l`)il;}Wk`v5x5<);Z5jni@nkYGZ#{gXnRxzs!8-LxoNe#-S zufpHk#T(*ZC-?2TDv_d|gE+KMyIkfYhh+S}XPR0f1!48r7^IS9&J;NRQ!ChS1 z>#eF=ft(WfLYXaIX6aGxAX7-)N=<^{0r(j9Sn;SAf$ex}1({(m1KAG-{!1SS8=|lu zB6Hu z_it!6;rIGTkV*9{ZQ!Td8Y1M=q8H-p>ZP=!*^-*3zvGg!>{Jp|`C1)8p*p4-gh{0H z^{O^iY+gS8L&6I$XDS%xXMr+^$8cO>YkdzFV)Zr+#xrE78a14{(GmRv^(asGXlvZ~ z#1}e|1XOMoE;?TnNxj8z62C&8S`GbcEf4!?P1Y|4)C2h7B0sBPxZ3?_&+^G~6QIA= zwD?;gUE#a546}*$Ol;3H9ZN?k&h!-e^U}0q^@k$ch8>7U(i3)lvSQxr0lEGk$erUj zy+L&$&@uc7r6o&b7;Df7vRi44DCJhua`HI*o^wl(JHo}5SLLuxlwhV?$%_c{a8(l} z2_}1(nl3is)*kNTq0td2WH1>z?|-`j=&jfi%!1fVy@S#%%%1s$uj5R z$}YS0CP8kgQHmt|?;#|KEn9?Ax#tHhHVUuO3058W4vKvCC%rt8g6ost=1m_Q)R)U2 z(jCleZSraB<#dYzdt$P=VnDUZ8vivFxs-ZUrm*p~Y;9EkWVmG?KPMlpv0EiRkT;Ql z{(bVlz4Ew2xONq(+cy3gmDlim&<}DHc;&v3MR<}!NJC0MHk|=`^Zv<&dA`6f(h=Rh zIgA#MT8=!99N$b)w{nJ7^;9ajBl+9QYtgGW2oE z;YCA$?}InW2B8sGyxT6;(-#b6){ge85yH&>07zsnQzpV?3C=DL{?(J3r;;l_+ znkz9{(8bM~_k|FCz(*h*n+|>YA>|7mA25x0#yH0}rCt|)EOXILVsH*h0~=`Q(jKPM zXqST;P{wAGlttM*AA+nDdOB#Oi`3ChERqz2Nw}UKVBnXJgh~-?P~hfr0lAfYhrxVe z`cuQFAIVPrKo{iu+~%8vUqgQmLQU|8dcEB-derw#0R00rB0;DCBJ!Q^e}+@bL2AG> z!92C34njQL9G+re#MK)l31O_{QLasSRtP

8@0hDrg#iGjOr9ge){iI1v=#*@d zmVEbW!;u2-yD+R~Mz-t$^G(wD<3F5~-41=Vy#ETF%suspxRphuM;hhdCM&xn4tCzY z;GCP26C5|lTWAkmkTP?k8Efpe62!u7gcw6Uf4j58-M?=73iqLpF-QK#xISt1CrJK zR5|qXbM^J{qSe7%4J)tbna+uJx@E6?)ppd~l5_pl18Y^TX=mj{PQLSSr41)j(t{F+ zi3BEpF(91x&WuF@W%3@c-{A8ny_twBLZ(2KRudaRi*=7)@=y)!4cF`b#J^PVRi;BYGQ^#)k}>Ziq0LjmLL{)vgic7Bvfz3igaN(O(YFY zpp)*ge076=xC2L!NTM4-0Y{I6n$17Qg^>UPMXt(qT5>wIXyz;~mKlU5&$r5zImGYf zLB~h+^!6@u^T_1%f3WQ%!+65D8LjDmaZ2!J%tebUBYRcMfYbwy;P|X8de4hw99gHW zxqa{8a!$7D(Fpn#BaHSIirs+tVe4 zrN{KxmipM@YYQ^qh%Hi|;TmFeGeu{3{l5jWke5Yy*^vL04xIyYp*I?zIl&$$kq2Bu ziZuRb!6{G=j94Mnde6DU4I19Pe1E=^zW144+ z*IaC@$2BQJbq=$Q=AeM`8cs4{o()y7q9;3)Mux>a?Ej=W1eI#1NwKPPX5VIueC`~z z!Fp2ztI_YPmuDTbHsY$uR#rsAQUvL3HyGTGoZ9Q_12!_FS&o)9+%&HXm}r>H>cf#{ zSbywS82Rblkq}aPy(!0d2^mo+O?N{w_X339G~@qd@5$Jnz#&Q zpO(VfCMR6?Jlu@ABMoss`|<>={!FF96KqywnrOX3bK)H~8|#tjAi8~<1K^0ah>~D; zVh|hb1KSnBsc4*H5^h)`Q@w(g7{XB6i=-Jp_XD0`Ns?{uFIuIa|7}XCU~i=-;%K8! zBzz!b#h_VgQL@|-%wRi7YI+zw>{L6 z@&V7fLc&JVjM8QKqpEdHcb_o~ocb=2IwaFUf=<^2A*)^--C!_atqyTF^*q#w^tWl| za?^ty9wMP<@vapHnkrU#CF7Q2EyTTA1{5T5aiE@)>9ne<302V$GCmglQ&A!k*?i^XeRYFOL|=5n9SvkN)U=-OntIMgiu{z~;~a#qE3A zJXo1CCSdmU8`@4@xavAJ z(gN_ET!>D$=@K&23dON?xeifU#%M~!S_>GU`ku~HApH>Zr8DCEh<2EdipY4!i0F~= z5d-o5j$mdgw0#$Y9gkOX2byQ(Ie+K29Au%s*K`)e4xME95oYn_wxGRMJsB=14aTJC zY^-NndpAjFdZXF&uel9aa`rvclye~e>|u}kREQsuv~H)DV6qYA%E)V;g> zLoGCWKvXnq=Q7jRv>8|^GQJ|U_joO&1Rw0NA`@l-y%lxx!(%XSq^jrwI^)M8s^B1A z{GHIg`1f^zJ$+dJ>)w-vey5_Dzg{9>3~SHNo)hdKbqJ9ZR`l_O7IS_4q-ZAs9jDo( zildCnu3QWQuiyWy)J#$$fg3OS$iE*5DjRTcxY8TpM_c~s+ZNThuLu;43ng{VND1oy z?zW#BZLIs&WLA=xBWPrZT=McS%S2-@aH7wp74ALF(l)Yik>ImgIP%@LN-2Dv%#(#dK^ULw{W|@x zi;1cYhytP-qrkRaG+l(MjIgA1>mFF-pR_3piBI+6q{PYT?}nF#mt=;|8;yY2iM&Qc z+Z_qZ9!LbFhGg28iRC}SRaa;+f7#dv+)xBbSv)1*+JjPhyR+h3@vVFXmPGuWlN+ve z!7bj)TgI3GX7b}*#k!3B9ZQ1AUg741n%Ay3Fc+o9jw+m1?wUw;13GbEmva0~y#p_BS(|xPVEe`e6lYP|0Ou z#N>#>>qb1>heuo7B6U~$}R-|>Hl&%%? z;x+$xl$ZtF$L`7FPXm8vs*e}l!`)`tIwd=x9!^UsYOZT=@gL5t)}QvFF8{WuVo|85U9t_#GT1Uh_1_G zNoaV2b(-Vi6mZE8^Q(I?5kcV`MHbsEl7a8Y8GLz(M@1WPRe7h(+rj9d-7UdnOOX=L z;h-7h%x06Wa~(IOqgaS;k8&6UA_fQ%`%y>4pU9X7kVuZF{WB`G?+WHZ5{1A2rab-6 zB1?#8d`SVIyF-pc&|=P8wpo)nX?#i*KpoeFEX+_U(dSdjgl%(&11*ShT-V2c?as6AP4ZASr;Eff5KQz;y(xy6B(x0|+;drz6T! zeFw?CH#2rjO=i{A-xX$3iKy>r|ESfdT!3&@PB2-yT1C{WzblFn&!Wg_4YP9=;$veL zb?9(V^vO}$$h~k^hWP#HgzFk?0oc>pu$2y#$j~i8(U#Tl>ol^`-?t59lrgEo9J={L z42B#Tz|!>nlEyxv0VuQ42tkUf1hp3k#s1>Zz6&*1Y-Bp*TF8J`Wygf+ONXw!Ce6$L zRQ>#QqNm)O%YukpbF;0B|;AW==g4zQIMaiw~I26o{^+wof<7!CM)$I zqeY)kxI~4E3^$p+IN{KojCIJi4BcmUY>)gTez!26YFbrXDtAY(!nRTT09x{RaOAHh z33i1My;qkIkIWHU>(DrZIQzn1lQTWt)cilwpk0J6ZMb4yrnJZ%rXga5`t-+Gzx15J z^Z>Q$fYhJ9OXDNCq`G+oWGemP3!zA{(Hp}{z1HiY$<>->+3?N(ps0(5vNMl6-9oGS z9h~~$`F(x79{NY4<{x{qyLnfc{e(ZKUY)(2yj~9OM_n%$XDf>u4>!9+c%QeMo*yPb zNhnK2Rm1o}u2hXK z$XWvPTy?r!ES;=lh#bCrhlRE;i)F@ZY>F#}%q49diFihN5|&5VmYO7MT_=L#uuh5W z0DOG43I;Vbfu7PnS4Ln&3Q9rKV z_!D(HjYSdLc<^5OZy)LsT&S)oId}d7$_m!%^oU>e$nr_*Yj7dqprI2)jWh8=i)Xae|%16cQ0x3_;7Li#tVo)z!4Pp)Ah#WyBR%Y*UN%sGYYAAdr0# zXoRIw%2?ss9G2}R!*4k%5m46_V_R%_>a;`J$zXX(+PO~uG5YjXnZi$I#mN2#kl0-3 zHJ4tl?qVV+tSX+1EW2P%VCSfAxET(XZ5)`WpyoOS5}$Ei8rPfC2sHNVe^~0*o9oXg z7J9X0KnR2cKSU}~*A$9v;fqhcqB+HATg%(N>TCK_?e}bC4GxtU*{+th7OuzcsDSUx ze_kiP)ESdSQCwpuqp)af`qzJ2z9VS%+VsOEb){nztyweIF^!a6j*t|8d2`X)mQ;vK z)6v~38#_`=8Bb#Y7wWdWkJpU~s?00rw4SVwZ#VL`WF;Ia^oKCkR$g3oVf04dTJoat zY->Jz#_ns0MZf|-`0L^?dAFs^pDKA1Hn1#r3c?4x0c=L|wbkrL5Sbip^f`wi&S>d} z{hi61nSMO}7C!SC*IE)RHj35mY14|flyhM?YL1+<@X{nn^1 zL@MD9W`ysyoroSq#7z|l!3P?x_qAZ=R)UaX5_TM#d4=oAep@nvlNty*d^zQonc=QAT0 zSY?U3f1u;pWB03rqqE`Vp6mi1SQ;AG+NoIM?80T5qpSPMLm4ZXT9cf@Bywp1mWVS6PMM=84Nre73mmcAo^j%I6}xMVBNxHr)ay{&Wv;F;B`HlYdsuo5hJk;+-_|48l zameRB?wyXg(RXzQZ5UUoCdVsKCZTmKNM;tz1S*b#Z!$>clV?S=2Z-|Pa`qONBHU%l zm!=+xA`|WJ@;>jY(9_=}&zLgT_beX$wUd4u^z1y7qB!VNzq;GI^^=#)f6wlZqwg<0 zQNvMtjih8)-{gj(rypk3q`o6LDaYXbiDUMF%s#w0{N98qgp$aPJ}JyE%5oh4O?bYr zRoG4w0u~UrIGj-Tpw3-d-}nLLQMglYOAQ)B%Fv_Vz zFFzwuL=p5YCf`bifL1kn-$ZLUR!O@>x_s*xqX@x`YyJ;BM`@;kVIyOaB+zdqAba1O zw8V=fX#B+9?|Va+-_jl9=%*0u@5NVLz$bF9aP{>kXzTbw=(8uv>Ko)D@AeSPoKA+% z;Nw-f-_ze<)Ly+nmnk3x6kG`5kzW*Ira>6LEC!CfJ=BNecuv#oUapTf+jQdT<^{0u z(^z(Bo7=jZk>URzT~qzp)%7pu_1+J6+Qjdkv_OIXAM9)GT);y2r~U6443!aKuZ7P$ zI@OXuObD9wp@Yd}7x&*b;KZf6;ajymXp=ilvTz7o|0Gj&fm&peS+oW9k_CrN=!Hi* zU2U{JY>AACm~gP)5%X1FUxSZ8I4^f}tYG(NY)UdZT`GAHv=6=BV0g119D6(@TEY*C z<8HweyDP=UUdW$hoH?0u=U0?Z>$*FPM z8AJs$EVl@IgC5%*tati=3Nq`_|10gPy5i`XHNoB8o!}0^gS)%CGq_7|2pZhoVPGI3 zxCIS5xH|-QcjoY}?)m^^IeL(~MIyF5Bw)A4zy8VWWK_UBtROL1q`tOZYAgiLHc` z_+{K5%U_$#wtCRqT@iMgF2wXIQ5IjRkSBC+#sY-7o~SKnx$>Lop-M;vkP zrmB%7roP2!%N}t6UYfMUK;DqgsaRpUm}+jRZo6Y0d%}v!xYl&GhV@hf^~IJdDvtl{JR58EV+F!BlIO@vmLChwt!K>(?=jLP)@ zL7(NJe|jpAqTiU+%HEBlKu)l+E5)LMK7&+psN>jX6j8J>*hQG7-u;0cL6Z84a?K%w zX&s|9E;z*UtG=Gs*2Jsm^9eidQ<>Vg#g>uI3ywx_A5Ec(#jKL*TA+APG+;B6eojLO z+aXw6lZfwGO`7EFiGmChUb|U5XT-tLaIZyuv?1`h^?ltNp={;!vXq)rD^=eiHxST& zA%>io4izdff`Yx$suhdzS^dH(1Ba)C7S4y_V8030vf%*ZZ$&z$^bKtPxdVAI0GX?c z_EqhQLq+YeFx>9)$A(I4ND_N26(gfBux#Dv2WcQ+G?BE|SDMHD_|b7kBW@GA`Wipe z#*Q-dQ%f6`=nsdwy6=lNUKl-&;um$6i&XsdM)wt8`Yl~|_@Xe4;v6uNu@Aq{$Zwh2 z@rQQh3AKvHn~Hp)DxLXt^004|h0N;`6#nl$DtD@2b9`q+8vv=z6`ekUQQ#eStTsmT z2wWj~G@^4dsVBb5&{l4Ej2TxeKWa!s+?}b*cWSk`QPeh6>pW(s*PQOZN{cWQ4SOm z?wFAZXOuelwN|I)Pw8fvBy#hs*T>5Y8#oMCl{}Ir1szzpxR%cqkIg|Y(Kwl znwL+HW)(K^%yBvNcsQCrcN{{Ds~{g4e#bYv;+jVR?;w+u+BOkaSgZZZvi_OF%M&|p zDgg#eAx{b;Y~b9Gdql&}mTvAvDLl6AW%;}zH+_{T1IXN?)W(>XM3ol-8*Kn(60`@Mv{0_9JP+cDd74J6e(Q zJLL@>y+Fh)m$gzVQRbT1tDPCgAD1O#ec_d3CX-|rQT^nk-XrMslVqxg7skqx1QQR% zme#K6+NUnQDb;@>tudt2a7$n5-#(Bx<+G?W1f=wvRo&QY0&m*H84abZSYSk$_wTL$ z7T6WuC7tVFdy?3&xjW6;`=I|R4FAM74FYm|2g-Kxy+F3Ez^PsPPZwQ~&3s|zVF>uu zg&IfVa=Wkv5GJL1HBp0J~)!ANf*t zs$iH_RXZree+lRdvSWWN>#Ig5=N-5j#M_tmgOb!_vc>v(i8di~N}rfa;(gn0`p4c< zaBW)_?#D_Tq724Ez!9P`7THHgykei5!QanPugsQ;YwsVcq(nY-CXsT(Pln!!Cp)dO z>YqP!z$|%!^I=5_vy;MIl?Z|uozB${Sn?)Toc`?y!86r<6!$qY%8#EIT<+lhRr@#W z@`A|}#%e$qTXW`#D`)22(_Z506jRtR-j8QYM)@a3Ny{2a2VvvR10F@)&jc!j7er&m z9QfbO41cA#7x!GJtW-;6n0}of93$DEnXYp98gn<5+v8-YlYoP_x~SYVq|?tgo)J7bbcg?&B#bCwF>Z*`lwpV; zUSlMUdt98UH4K?cc++ia64Y!TU{n@9>xpCp&|oJ#q$AS5%aKL(BX$+r$GQ`n7Gdp4 z`2V~F>`>_y#yBg5*Brp!Z3VXd%Rshy8;t*rI??Br(NHa!=PaYja9n&rsE7ovQSQpd zY$b5y@{L{g9M;GTauc6TBwZQETM5jvl7~)lNk&CdO0}sGOeOvUO9+e;h(2d`$w^ek zl(1Bqq8j!*{F>87+ppECNbk_w=f?@Ew~_9IX%aYuJM}JxPj`TC^5c`CEHKk zTTmme4b^H%XV0xM`laaA6=o+z57eH}iZuCt!15?I?j0C81REU0~EsYWSUztHB3^8BfFuk`ijeJXVsifJw zf3Wj9oD4U6yQ41(p2hmDOgimZ)IcsL)=r7?TEtd!aDJV<#*SG^J>f2ZM6bHm(+kCG z-y4-qYf;Q^hu3Mg&N6GYqoCkG&tj@cV~8!5G&0lSr8%V?h@Xwyrk-uRIDUZ-`%S7m zc9;J&&UJ|34+M25EjVv)xEI+nVTNLw0xlJ{sa^Ty*Fwj5RF0rDyNZfQ;c35#qs~Cb z<;9Niq4hPly~b$;sHbO4LP%*<2$t>CwVAKLjO^w(yL(LCJMAvx=WxqFr!!2)+Muh+62h2CPWrAxNI&Q@VN<78|aeh^iwOeAqaF&xb;r2~}? zq_YTp6a{=o1L(Kn_U6B+t7)B z#F(~~1pI&w<^<)C(=m?JD3zf|c)k92ae=kkn*R1YMG>`7H>4PB<+#fA3 ze}i?zAiyt&Y+i`1Tdyt+FJ<2#H&+|r*_WH14qu%%$gW?i-1uK99cb#@+TX^3b*uHO zK2j&16?TEQtCuKX#(Cgo&gD15Jr=>+?bqsBvSl47gnZUTx@&9-{!??XpMsaSYk^0G zM{N1?>Us<(6(bIl@27pBd2;;0@+7lIM()z+MtXkR`&&mi$;-nD+xlRBTjD$DlxgGr z#?2apnH|a=U2Z^mY@K{}mf$w;&g{U}y>c%5apM!G?ec|FEA5QaQAb%FRmPQ-fYx%! ziR6#qp)TC0PGm(I`^!gg4Dvyn9&<^=KuUb97RyA%E3r=u6Zh?8C~d%zjR0)ZdY993 znDS47!cKgnYPwiG=J^AvrTavP-)>?@eeOmQ%BJNR=mC^^fsUTP({oz0BS~8S$HlpO z^8_75z*g(rluYvJ(^)MQ`&4i74Oo=W2Rq#b>th}oY$NY#R7Wb4;AI_A$zXT z9uCYbKl<{$il)})_4D5aPe2$6VoWnO*%52>NP?efaX3|wOtFEfr1g}^=XJ5*W>&P&%dDB5|EAUjP;({`Dc6Kpu>WR`=Lsp&!hu3rFuWL_i+zbb5mVO z%N{Y;P7d193n<1C?o=w~v_l6>oBXz1!(%3Hau_o6Tm2%FCJLKgJH2gMC>n{_Mp>CW z5m5Z6r0;?ReP%mk%eEZ#(ZuIj!Gi(yaF&6GmNP2Os>V7eA;0k$ZW>Dipr2C=S&O@$ zJBN{fpehKGuo5o^L<)B)r?lXfneG_`}KPT4zY4 zlkQ0;M1&C4o8+O#r@N~KvN71$_l7aKgtCmysp@&mJv}0YTDP>5W4k3>Uzy$5QnB)O z)}=>_lcGYyIXx#(87r_BEjaN`d1rv1n``jyrXS#U#+P;*)#!jmTwH-tqC}PZ4v|C1S|6}H$Voj#O{x; z#Jqcg{DUDM3lrWWBo3qPewG*9(mm$UqOf<9WwQGj^%$D}XNIKq^&Q=I9=+B4iRznd zFO`uj2iqc4McA@J*V39S_k+DBqgh!Tycu6wg)ZvaW(}$o1R(wVBZ){8>0+Co>XF$v zKy8W2S*z>_^-XfyY8M~M1X@zyz_0J8s z8@VmZ!jtQfx5vFlQ|9OQ+RZ8mj(caLPz%)!Gdbrzcow?LFvDj&O$1x zf07o+W(^Tc^l)lra1%juU+5%vwOLhHn)n`J5_p(h6T~eZ<>7I+%n@fO9~~MVIV_jY z?l10t+PuFTQmk&8_hM&kEwtA_%A5ll-;V>76AB`-Jd>rF>?bET&#o_Xg<~XJO|5Yb zSvJy&^L5})y1m_(&av_4njdLEe*o>xf*k*{(;Dg1`SemKVzFb!oH+nlRagT%z%4^# z>&~Ily7a08^nX3`dk`+Rv0s9Jpr3*dj#NY-iyN~p7rT)4kw%Tz9u}&#_0O{e_oVgB zxLhtY0HmYvnvXhW+dn~J96OJjVDr~z?;9dJAG>x}@}n}`uYTK!4tBU9zXdww2vQ_l zL55~MfnE0mxS#Cq?o8>EO)@^Q=s{EqMXL{j{X4l^Cn4?(lf19NoMrqn-zr?XkhhKM z0P6v?r4BK2ylP#dgx?^~UUrXP{Td-1;i+nGFToNx%Rt9vpWC9Ee|hnU2ef`BRd~U~ zs&X1-JR}t2d}=q(g9z9JNu5(hMGTlBrhh$kF_!dA4?9Qs3`@Rkfx4T2_%9;e^}9p& zGCfSI?{_WquRUyNL04xt1f*wZiDBy2y1P{xtPc`N9>z{xNu8I9KU@jO;Ebn|OzgtO zKeq_{!0~Z1tM6hJOQ?y|w3HE}33R~Rc*)s!2cNE+?X2a=e-EcP{%FbEhkuRAXr$i1 zVht2>20iEAxEs-26aNO=TLW`UbnLYktA4i+Uk$ka$)m%E1l{@2A06K$HGTYy{kH&1`JBs3?$?AmsFZY78(NT)_99J6t+y#OoG#@SU#d z(IIs9q}2y&@D;q3wYuPm;n34Y5SjuE4L5gco!kp;-7-41)>*;x5343G)JB`wud>Dm z1`coQfp<-{U5=p6@gqoI)x&G*BC1|NFi+ZN5o3|TRWeyTd!ED5?hSl|q73xs;R)df zMdt!l0q_Rv^$8ra`1x$^y+@-3PD@5CqwVp`zhw^FHaZ^eKCW)x{58z_G!bs_IF>QY zXN{7n(^n0rQ}^4p55h8^#AfJ7Mf6UMD7J4UCB`y84wo(6u2Dxv!aDqeMyud5jT6-| z=$?rR;F|GOP!^E{QbhiO!-cs}IxLa6&iXP2w~>(hiI=<32aL9HpdX ziR6xZxl`6`BGztGR*y&aYG3)zZH%+`9nsQ|L<6&gmR8uItXWm$C+5{TM8OK;OPk?K8M_!!b3UC-uUpHQD>!~BbfULw6VtUjk;BEXCB!E{ zR%Y@+;mbn{G_&{@{ob<3*B#wLvF~smCZ^VaS^YQn;Qsyhw&M4{@)86TFzkYm_0{F- zqhM9=DJwuGnhbDSa&4KnSX6hJ12oN1DzDG3MNO>2*K-(b#t|0*W`g)3FW^{mrrYk zUK5C;BaA2?tWik*sL!mjG z@EB_;dattAu(USr;?)t%Zv?Pzzlmnb?|S1JPM95>&7bA=IUoZ9NcgpEyh=^WsDVDh z`M}Z9r8)YjF)4EHpX_gcui;p$C%#yi+D+u!TOA+K~YxvlxugwT7~qy{FH zb0;T2mTcu|2LZOo`E0}VCmZ!}*WgZbLGBUc-DD8}rxyt6071lp+$kWt&IKn`5E(KZ z>#x%kDHWi4YoE^;C@)FYrTJvvO-u=%j6i%INM(|XEzpH{cm6^`=0w84@|Irz0Fu^? z46LViT9LECnb_QBDjtu5#R~BQd9K_pGV6|H%b@HH!BfU^y=i+@`-??IjOlt}y`o)o z7!;-Hop-OF3Ms;AW-+TBh`K-P=k}i6fn4BCu;4=OF7j^E}I8vf~Zd*|B*A)F=_ zY!|ZhymT_i zOjy)qo!v77@GnG*?e$3<-8lgg>LTdegxB=$bWFFl(*%I=*QeAiAN9f?0>h&ADI+Pq zE>z%hn?EEPC&kO{He~=SQwXPlghdXf&-GVaGY46or%}|roBK}spLk(eR@P0qw**!T zmZb%6d@iOPhZ?3m2-zloQ+`byv#jxOtF5xu4h;zLr$5nD6ty0RaTB5!x~&zg%W%_I0AJf8Wd_`WO(ad z)E&F-lfHZ3|8(eg6!m?GYNZ}Dx-zNpUyAUhgVr7S=%{i`FvM{ zp!nlZr&U(}mO$KBB*23J;gfz_8_&TM>-D1E1||`ZvulNkSJ5WFY<($mC7=^dWd{Yg zXi2B-_P|`Rvv5`WqvPqjN%AajQ06{glg+n-hYZugy{6-4Q_eQeMEg%8o=H+BhWnx- zgtN^_7I4yVR{o=cgu^ zGoBZ)kiBtA$FivN-?i1SnRKVF=5Bk?ng77d!iIt2S%t~?E>b$|^-orqB;C#p4JwB9 zMNNmZDv_@*vdzSis)VUz#W1Z8jJ3BbGl}V*jsRR0C=<0{x5u!jJE7Brch?oZK7XKT z1X_naNK|p%2jw+v-9}TAMud0Jk_|d8M3GW=|`MIBzw$@?5g}Db7YoliSU6Fq=Sk&;0OK5Aw!mn1HP!Il` z&U2@I$RQVCe<2tuoZ)0MA)_nw9dG|FXMX{t<7}7EF!60WN~bU%^lOMoVx83h-`TBA zJIXcHYyUzH$Woi=@5skkeb>=9o?&sXD*&W>M6sDWNC9x~_dq%`bDZrU*{rT_;kLH4quQpBzryT#B|>H{bu!>SyGF`Qz*If$hoHMzJpF-wk>&2_JnQo zRGUljU?uc;)0s$P&LCuC#lz*SnrWq>d(wO{j{h{B-;ovW!bK z(KT%osWgs%KeqAkQ%u~AGHoV1XrDwo6JsH1BzcCQdXrzAeN4;ns^@27K37I#@1-_x zPd+U;Pzxz@nU;vxva0}$8MDnP>VH07ic!V%{<_>~+0Txg=-R8t92gV)CtA6O9H%Ti zob&MWAH4O9lGNnS0ZEqQJDi(mkdjiR)Vq|;*$~|uz+4d_GS7F>smq(x*pskg>n@L^ z9k`?x_!-|+Mz2Lg$&fw}vs+Fw+uRERqh#G4)-&up19Y_g8LFbL0~qGjbKX?ZU7ha! zte79du^NZ!MQ3PWRl-e|N$GFg&G7xS_Y}0uWee5TGQ!I2R6EIp(6{KyTCWL#tx=BBd3&g8VS&g}=jSNe3`WYo#AE?%tQ|}jk26T2uBp?^4^2w*=y1w!s)cGl ziZ|iL+*ueV`+EKi<5Xh{x*mLx84|ZxjC+?ymUD{D2KO}=$T{@ituha>J>-~v4Be(! zA)b7%N3jJ(!HEFsLj4H9(shiJw6LbQqAE9OVR#xkNwNgOgtD(J|0Wh+5AH)8|HR+qxp? z1j|2)PkEdPBa120m!jb5Q}9WNymWB`Rf2>gI0RoE)ea9C+NGRL=YCju?v0%xO0A-cny`|(Xeq4xH` z?nq*`h^YIx=XGd=ZaeI?%;a25a=(&MyPT`XE-0m*NT;3ktI##H!mPUEt1WMlt>A%i z%c}tup>(6obTPzF66LJaz%kXuX;4TnYc&oQ`JOC#0y2wfc!P%m8ynpoq-infpWoL z=}MrHM)dhqY`^31Dy7iDLi_9}%B0daixc;LK4AG^@KTN$ZI{!mxRASxm%kUsq_r(w zJmBER4VzKLF8_9Mm25p!UD8(l^(~n$LQ)1)a8zFDf8i34R*O~HHQ!he;`n6BaP4yv0PW3cm_m7C}U;0sMx@9w-UV+8?|Qz`6DEowepY& z)@-);U#F4BUl~w3{6Mso8hTaU-p*MTs1uA=FV_2pI;>+^uGz|sL)iZ`2{N#GbOT)}{d~!`kxn>KbS}TC2)sr{PRPyx0SZfTr6dW*! zr&?yJUK`|pIQ6D|?-Nf2iErZaj3tj#Gthnq!mJ0|IEe|`DxsltkJ@&L)kqW5_tRX( zMU~c&LdU~besBbjY(k=6M1pRf|2;AKySZOKTT#5_;`xj0f7n|hiint7$NDrun=90d z**aba=024}0l;T27LVuFgY?u;L_#WAY>nv|CAqu`j(fns4D4VYEo~}pCG>~t7VE2w zT*;4$e-Y!St0*aobVPd*C``2fa4qaP={~D)=EpXLyan}c*D8(Z1=dt^4`m-0qKO+Q zU}mh(WP(@I4W<>{bx<{_>ElN>BFbjTPrF2zq{O9yOGyJ&Q%x@%Bs6C{ZY)M~v#}Nl zcQzf<l5A@?6dKyrDJ~ z#ncD~#;^p(8eL&4Yk#)3Brc^&){U?lZjj3#G?Wr=_!$Z|c|UoQ$IL4%oV?^g!%kry z{1V5=xg!--X|?$q;dHEQW6w-w0XpOJi$6X0kuk{i}tsRK0#| zqYG@~xu2;rgOs_DMl|_yYZ8p)rQ7`;M`RE`->9{ya^rqz>mx{J1omMAN#W9^V8t=2 z-+g6hvFtF>-k+4GX3?TOf0F%FXE$wgR-n%?EgZ2ek=5r?(c_yLdDv$);a zR@qU{Xa?IQa^vpMBRn{Q#8{X=VW$}mp^o7N2@~vO=(Iz=X{qfgbcPrQOCi8dWup^f55TLYGl@aR0O(+qWAk^aozR6mA_jwg8V>OAth-d#WeRpnQPJ@ zspohU^D-04y9r9K3Txk$DA13?H8Hri_q&rRJDWYEc^?FZ;^zlQgyDf5+vg8}4Egi% zpmBIg;{bJeX!-}JmD2qzl=>Tu3qfJLLSRgep6qKm$j5{(T}6#YgIKRkM9oZ`Y=;!X zzWrZ{gFefmf#sMO0O)oV*72laAdB$s^q0JVX0UsL&)0+k^dViMqT9Em4)S)oclurZ zkoBcJR(9nEAm}a&XM&+{FqySe=FY6)iJgB^_s9M@-*qU@x~I`x>wM(^;JPDxz;b~5 z%dDfMfq5Ap#CgH|NB=y?OD!{U)^Qtu8y8!Vi%CQLID`$QaJH$7~c=vimO0U4ehv%D|a1Mm9O>*RS>s|EpyMLmEbI> zk(jMx8x~7}}_@RBQE`Tk_`&}|NN6pLFJHqOQcy*;L(fE6Sl_1Y;~FUZqn+)OjL z;__$Sn^~VEg}|R25`%G(0TP1<2di?JVH@Pj4m|+puSDRiHFttfcj*aXsfbOeli!D8#CIh4Ps{rwW)ZhdeQ63N{Zdx!BWLDFvBir4Y)!P2jb z#MRm}{Ry5M0ltTNnWE2yqhUO;cOSw-T1Bv71=JhV-+cwS7L?f}VXh|3k-5G(TV97% zTYn-7QVIcizb5+@ppKpOpx`zKe!I_KRJJX2P7E||9pmn%BK_v7XK+>-XEnKx9g3cm zesI<=w_qRJ%gJ|e%UiG5^Os7I`sTywTK+?{f_sr>(J|WhtwcNvYBds#x^Hgrd;gp= zQaxNkT&q==PzGdrhn2;H7*RVly>Mvt`wbk_1-dV7$u%aVC@S<2n;Hv!sL~gZL3nKt z3ULRe)>r*P%7P>@WNIr$UEZYQTPSUyEjl?Cn2Y`{Hq^`g{u&oa5UeC1Si&hit zCeqw^GGBk5(ev<2lBF?Y@Ru11N(W9^7|SI#hP=PwiiGas;+Gk{3sBQx12tT&)YcwI zwOrV5T_~{uE(z3tjlQ27gbJ(4vK#YpNZD>p<+w2O^rOH{>!R2KF*M>D*os5IrZg2d zHnv@d>>EFLvLvlc9E?S2qD8TN0|IN75~MS)Vj>@uQ{;(Q5i1i5ln5`#A={Hf~Jl4A1 zy9`YAKOI$#DiHFM1R{PBqX()9lX@nQZ4dZWK7&dzA`wp9G5^f*f!VxR51CX^+(h)< zH%56@4qlu5`gx!59E_PoZ-~awh(>j*OzR#Wf#RD2mro^?-{zl+k!m=DooheOf5%&; zR-U)CA>K#$gdIEm{ac70&bjI)KJ-unLHhGYRWHFu#*8mp;2R>`@lN@O+niJWEuI{> zX{BT)omxi>S}8sZ8~+;gmiHxxUjid&4=V)!c+zm{;5>sP@k?^v$0#6(MOGPtlQ*u0 zDkO{jDz-SrRYqUeuSV)Op?X)O_lo z-2s%Hxa0~IQ=T0CLeK%sJ)?MRcdS&Y%GQ0UC#5mT<}fAP%QMo@LFD1fQf6^refE4q zWR)`QU|3kZT?*3UO8jdTB$`!dJ8N8cuz#?8$23q|NgJ!l5_r?;Qpi6W_2;+7N2m!5 zZmPG;5uTlZh5%d7dvn`%`q>wqPsoB}n(Na!R&DHh4u+|%cW@{=qGY4Oye$HE#mV&2 ztvnYcT)oPC1m1rHR$dPJq!AeVfGcc8B;_lcMi5LKoid~u%B)qFid;aYR{WQzQp#*4 z+h%tobwMyi9?)3Ro+ip6IN9@O)1kL&+=9%ZVitjO^1p?J->LzuS2MSu^S-v_KNuhT z6LJey&d+rnPlOZnv*uCyO;Q; zPWxaq0?6bA=pOFk%;(K$_qhKclT_3PVmh_UodNfWQ;@1PpzT;DlFdtDB^}&)eLEPeS9bEX_vNmXUOqFs;MN^Va@J6=LY^V zXrB>=@Z5cZmD7b2AKDh_Z+e@d*9JO(*>NX#;>pAH+rEIO>)O09+se&xj6yv_I8-oCq2)lh0r)QUnWVmG(ItQhT4it+2V`VI(DVr*=yX+XXa=3 z2S2cG&nC{tcsQFkfLr+;8eUqMN|U8C*Q%zPD-es{$KW0&;vWmc3;mKsh?<7VVs{s! zWgH1HY!7oQi6oo?(b^|uOlpct9@P<1g(4j(eN5lvEPPKd4R|%32&0X>Ys2Qy{6@|R zQP|LdUFnHqZ(8z~3DlC_S-UC4;iR2f{-vX<$^h{s0{fbJ3w8(GB#|7d+FUVjJmU-& z4m&Ynx%x{b;fSnseDui1Xu+5Men5V=0w&Vn51INb;eDwjCDFM{LfN0#l;Z*gaER*i zo*@%YNh^V-N2o|Bo)skGPFi6u?DlPr%JO%jnz*n?MEK2?-r-bWul%~8%KP=+&K_6JVwr9SBT>0JK)PE{s2aU9U)nW*Z)Vd}{t; z3H-rx0xi*BkFmK=Z793vQRGZXv4j?pr&W!-oYp3moGn@2M~ABSN$0c5-O!qp?oCCO zKYdkMrc}Lj635$?H|E4xu$g+IHXuko7@?Q7Yo|B~F%F>89qm{`@_~zT6Oc7ots><7{ zXKVEKKvhG6#*_td*5w38iQuZ04PABaFK3gk6Hh*JbGOdp0@F8 zoDNP6;r0Y{z<&`OANLR0iQ+XXHKb`#H|nCkzfA5&7)0yxC&FG7(y`2LdhN8gzn6aQ{w{e{jbcJz04Yt4Q)yv8+q z4p`}Zu>cBVb5u(NrT>hWuP~Bo>b2isI(lN3A=4X<0m*-9qZg)QZWBnKHYYf3j_R5r zbyz!oEW0Bl@Sr3>dND$12_R_1d2bvfQ$GSx13vT zreb&}sjO@A6IfeI>bdtU4YFw6AokL=9Bp`}FsoQrjsk8U#!^&vA!zBRi^Pkh+cbSeMVjU7}EbsnXI1=h*8 zT)9Vxh(9i@h^N!rKdTA8U}_Yqr9;WvFk0_l}qff3C+7s4(ebIRY52f5V}FKt2C_@R)N}}<TC2NLWETs4vZmJ4>vSy%+o%Ejp zq-o}!<}1tT!w*Uq)Eu+WCS_GESDym~ISCqeHYb4*T_&wH6LdSfyPJ z;Mf6lykh!@T*KwNJX|H!=H6C%5RIh+M@nPDoE9@M|F#o|=^8AB6PBO>SeW4ZUAgYk z7>%8PyW6*ndPIvh=2LC$*%*tOADd;BrMWMW)9wqEwB85I=b+Yl$S_}?|K6CL^A|hb z9d|{wyM5uc_=vak5B|*-h`PUAnGDN$dCriJSe-*q;%CHQuh$92k3RL8+*AQ{l=MW=iyK@t_KfJ}qMk@InwC?HVr)JEDcNEV&kea*SuendTA@=c76?1O`&gNT(T{4%A&8 z!uprM`FG?>KY3&r!9#H5I6O9)QWV(#B2=rVNIrO5%5qJIT}_@SoVo&l^~ftlL)(>Cy3tTBg2~8~M!4$Wm{YP1X)Ei`+*ti*f js4>7o_4ZOG`!M&2 + exit 1 + fi + + echo "======= Funnel configuration =======" + echo " Kubernetes.JobsNamespace : $JOBS_NAMESPACE" + echo " Plugins.Params.OidcClientId: $FUNNEL_OIDC_CLIENT_ID" + echo " Plugins.Params.S3Url : $S3_URL" + echo " Postgres.Host : $DB_HOST" + echo " Postgres.Database : $DB_DATABASE" + echo " Postgres.User : $DB_USER" + echo "====================================" + + # Replace placeholders with actual values (in-place) + sed -i "s|FUNNEL_PLUGIN_OIDC_CLIENT_ID_PLACEHOLDER|${FUNNEL_OIDC_CLIENT_ID}|g" $CONFIG + sed -i "s|FUNNEL_PLUGIN_OIDC_CLIENT_SECRET_PLACEHOLDER|${FUNNEL_OIDC_CLIENT_SECRET}|g" $CONFIG + sed -i "s|FUNNEL_PLUGIN_S3URL_PLACEHOLDER|${S3_URL}|g" $CONFIG + sed -i "s/FUNNEL_POSTGRES_HOST_PLACEHOLDER/${DB_HOST}/g" $CONFIG + sed -i "s/FUNNEL_POSTGRES_DATABASE_PLACEHOLDER/${DB_DATABASE}/g" $CONFIG + sed -i "s/FUNNEL_POSTGRES_USER_PLACEHOLDER/${DB_USER}/g" $CONFIG + sed -i "s/FUNNEL_POSTGRES_PASSWORD_PLACEHOLDER/${DB_PASSWORD}/g" $CONFIG + -funnel: - # -- (map) Configuration for the Funnel container image. - image: - # -- (string) The Docker image repository for the Funnel service. - repository: quay.io/ohsu-comp-bio/funnel - # -- (string) When to pull the image. This value should be "Always" to ensure the latest image is used. - pullPolicy: Always - - # -- (map) Configuration for the Funnel init container. - initContainers: - - name: plugin - # -- (string) The Docker image repository for the Funnel init/plugin container. - image: quay.io/cdis/funnel-gen3-plugin - # -- (string) The Docker image tag for the Funnel init/plugin container. - tag: main-gen3 - # -- (string) When to pull the image. This value should be "Always" to ensure the latest image is used. - pullPolicy: Always - # -- (list) Arguments to pass to the init container. - command: - - cp - - /app/build/plugins/authorizer - - /opt/funnel/plugin-binaries/auth-plugin - volumeMounts: - - name: plugin-volume - mountPath: /opt/funnel/plugin-binaries - - name: config-updater - image: quay.io/cdis/awshelper - tag: master - env: - - name: FUNNEL_OIDC_CLIENT_ID - valueFrom: - secretKeyRef: - name: funnel-oidc-client - key: client_id - optional: false - - name: FUNNEL_OIDC_CLIENT_SECRET - valueFrom: - secretKeyRef: - name: funnel-oidc-client - key: client_secret - optional: false - - name: DB_HOST - valueFrom: - secretKeyRef: - name: funnel-dbcreds - key: host - optional: false - - name: DB_USER - valueFrom: - secretKeyRef: - name: funnel-dbcreds - key: username - optional: false - - name: DB_PASSWORD - valueFrom: - secretKeyRef: - name: funnel-dbcreds - key: password - optional: false - - name: DB_DATABASE - valueFrom: - secretKeyRef: - name: funnel-dbcreds - key: database - optional: false - volumeMounts: - - name: funnel-patched-config-volume - mountPath: /tmp - - name: funnel-config-volume - mountPath: /etc/config/funnel.conf - subPath: funnel-server.yaml - command: ["/bin/bash"] - args: - - "-c" - - | - # Create a funnel-patched.conf since /etc/config/funnel.conf is readonly - CONFIG=/tmp/funnel-patched.conf - cp /etc/config/funnel.conf $CONFIG - - namespace=$(cat /var/run/secrets/kubernetes.io/serviceaccount/namespace) - JOBS_NAMESPACE=workflow-pods-$namespace - S3_URL=gen3-workflow-service.$namespace.svc.cluster.local - DB_HOST=$DB_HOST:5432 - - # `Kubernetes.JobsNamespace` has to be configured manually because of templating - # limitations. This ensures it is configured to the value that is hardcoded elsewhere. - configured=$(yq -r '.Kubernetes.JobsNamespace' "$CONFIG") - if [[ "$configured" != "$JOBS_NAMESPACE" ]]; then - echo "ERROR: funnel.Kubernetes.JobsNamespace is set to '$configured' instead of '$JOBS_NAMESPACE'. Please fix the configuration" >&2 - exit 1 - fi - - echo "======= Funnel configuration =======" - echo " Kubernetes.JobsNamespace : $JOBS_NAMESPACE" - echo " Plugins.Params.OidcClientId: $FUNNEL_OIDC_CLIENT_ID" - echo " Plugins.Params.S3Url : $S3_URL" - echo " Postgres.Host : $DB_HOST" - echo " Postgres.Database : $DB_DATABASE" - echo " Postgres.User : $DB_USER" - echo "====================================" - - # Replace placeholders with actual values (in-place) - sed -i "s|FUNNEL_PLUGIN_OIDC_CLIENT_ID_PLACEHOLDER|${FUNNEL_OIDC_CLIENT_ID}|g" $CONFIG - sed -i "s|FUNNEL_PLUGIN_OIDC_CLIENT_SECRET_PLACEHOLDER|${FUNNEL_OIDC_CLIENT_SECRET}|g" $CONFIG - sed -i "s|FUNNEL_PLUGIN_S3URL_PLACEHOLDER|${S3_URL}|g" $CONFIG - sed -i "s/FUNNEL_POSTGRES_HOST_PLACEHOLDER/${DB_HOST}/g" $CONFIG - sed -i "s/FUNNEL_POSTGRES_DATABASE_PLACEHOLDER/${DB_DATABASE}/g" $CONFIG - sed -i "s/FUNNEL_POSTGRES_USER_PLACEHOLDER/${DB_USER}/g" $CONFIG - sed -i "s/FUNNEL_POSTGRES_PASSWORD_PLACEHOLDER/${DB_PASSWORD}/g" $CONFIG - - volumes: +labels: + app: funnel + +rbac: + create: true + +# AWS STS Source + Region for S3 CSI Driver +authenticationSource: pod +stsRegion: us-east-1 + +# Kubernetes Service Settings +service: + type: ClusterIP + httpPort: 8000 + rpcPort: 9090 + +# Funnel Worker + Executor storage (S3 bucket) +storage: + driver: aws-s3 + size: 10Mi + accessMode: ReadWriteMany + className: s3-csi-sc + provisioner: s3.csi.aws.com + createStorageClass: true + +# Funnel default settings configured for Gen3-managed PostgreSQL. +# +# These are passed into `files/server-config.yaml` and made available to the deployment via `server-configmap.yaml` +# +# - Ref: https://github.com/ohsu-comp-bio/funnel/blob/master/config/default-config.yaml + +# The name of the active compute backend +# Available backends: local, htcondor, slurm, pbs, gridengine, manual, aws-batch, kubernetes +Compute: kubernetes + + +# Overrides the default volumes configured in the server deployment. +# If custom volumes are specified, they will fully replace the default values. +volumes: - name: funnel-config-volume configMap: name: funnel-server-config @@ -260,63 +298,485 @@ funnel: - name: funnel-patched-config-volume emptyDir: {} # Shared volume for config data - volumeMounts: - - name: funnel-patched-config-volume - mountPath: /etc/config/funnel-server.yaml - subPath: funnel-patched.conf +# Overrides the default volumesMounts configured in the server deployment. +# If custom volumesMounts are specified, they will fully replace the default values. +volumeMounts: + - name: funnel-patched-config-volume + mountPath: /etc/config/funnel-server.yaml + subPath: funnel-patched.conf - - name: "funnel-oidc-volume" - readOnly: true - mountPath: "/etc/config/oidc" + - name: "funnel-oidc-volume" + readOnly: true + mountPath: "/etc/config/oidc" - - name: worker-templates-volume - mountPath: /etc/funnel/templates + - name: worker-templates-volume + mountPath: /etc/funnel/templates - - name: plugin-volume - mountPath: /opt/funnel/plugin-binaries + - name: plugin-volume + mountPath: /opt/funnel/plugin-binaries - resources: - requests: - memory: "2Gi" - ephemeral_storage: "2Gi" +# Resource Requests/Limits for worker jobs and server pods. +resources: + requests: + cpu: 100m + memory: "2Gi" + ephemeral_storage: "2Gi" + limits: + cpu: 1000m + memory: "2Gi" + ephemeral_storage: "2Gi" + +# The name of the active server database backend +# Available backends: boltdb, badger, datastore, dynamodb, elastic, mongodb, postgres +Database: postgres +# The name of the active event writer backend(s). +# Available backends: log, boltdb, badger, datastore, dynamodb, elastic, mongodb, postgres, kafka +EventWriters: + - postgres + - log +Postgres: + Host: FUNNEL_POSTGRES_HOST_PLACEHOLDER + Database: FUNNEL_POSTGRES_DATABASE_PLACEHOLDER + User: FUNNEL_POSTGRES_USER_PLACEHOLDER + Password: FUNNEL_POSTGRES_PASSWORD_PLACEHOLDER + AdminUser: postgres + AdminPassword: example + Timeout: + duration: 300s +Logger: + # Logging levels: debug, info, error + Level: debug + # Write logs to this path. If empty, logs are written to stderr. + OutputFile: "" + # Log format: json or text + Formatter: json + # Text format settings + TextFormat: + # Try to force colors/rich format in text output + ForceColors: true + # Include full timestamps in text output + FullTimestamp: true + # Format for timestamps. RFC3339 is default. + TimestampFormat: "2006-01-02T15:04:05Z07:00" +Plugins: + Path: plugin-binaries/auth-plugin + Params: + OidcClientId: FUNNEL_PLUGIN_OIDC_CLIENT_ID_PLACEHOLDER + OidcClientSecret: FUNNEL_PLUGIN_OIDC_CLIENT_SECRET_PLACEHOLDER + S3Url: FUNNEL_PLUGIN_S3URL_PLACEHOLDER + +# Kubernetes describes the configuration for the Kubernetes compute backend. +Kubernetes: + # Timeout for task creation (worker pod creation). On timeout, tasks fail with SYSTEM_ERROR + Timeout: + duration: 300s + ReconcileRate: 120s + Executor: + PriorityClassName: "" + restartPolicy: Never + # Setting backoffLimit to 0 means no retries. + backoffLimit: 0 + Annotations: + karpenter.sh/do-not-disrupt: "true" + # Setting completions to 1 means the job completes after one successful execution. + completions: 1 - Database: postgres - EventWriters: - - postgres - - log - postgresql: # default bitnami postgres pod - enabled: false - Postgres: - Host: FUNNEL_POSTGRES_HOST_PLACEHOLDER - Database: FUNNEL_POSTGRES_DATABASE_PLACEHOLDER - User: FUNNEL_POSTGRES_USER_PLACEHOLDER - Password: FUNNEL_POSTGRES_PASSWORD_PLACEHOLDER - Logger: - Level: info - Plugins: - Path: plugin-binaries/auth-plugin - Params: - OidcClientId: FUNNEL_PLUGIN_OIDC_CLIENT_ID_PLACEHOLDER - OidcClientSecret: FUNNEL_PLUGIN_OIDC_CLIENT_SECRET_PLACEHOLDER - S3Url: FUNNEL_PLUGIN_S3URL_PLACEHOLDER Worker: - # This lets mount-s3 pods unmount and Complete. https://ctds-planx.atlassian.net/browse/MIDRC-1214 - LeaveWorkDir: true - Kubernetes: - # Timeout for task creation (worker pod creation). On timeout, tasks fail with SYSTEM_ERROR - Timeout: - duration: 300s - ReconcileRate: 120s - Executor: - restartPolicy: Never - backoffLimit: 0 - Annotations: - karpenter.sh/do-not-disrupt: "true" - Worker: - restartPolicy: Never - backoffLimit: 1 - Annotations: - karpenter.sh/do-not-disrupt: "true" - # When a new node is ready, worker pods may start before system-level pods do. This ensures - # worker pods are not preempted by new system-level pods on that node. - PriorityClassName: "system-cluster-critical" + + restartPolicy: Never + backoffLimit: 0 + completions: 1 + Annotations: + karpenter.sh/do-not-disrupt: "true" + # When a new node is ready, worker pods may start before system-level pods do. This ensures + # worker pods are not preempted by new system-level pods on that node. + PriorityClassName: "system-cluster-critical" + + # Turn off task state reconciler. When enabled, Funnel communicates with Kubernetes + # to find tasks that are stuck in a queued state or errored and + # updates the task state accordingly. + DisableReconciler: false + DisableJobCleanup: false + # -- Path prefixes that Funnel's Kubernetes backend must reject when creating worker pods. + ForbiddenPathPrefixes: [] + # ReconcileRate is how often the compute backend compares states in Funnel's backend + # to those reported by the backend + # Kubernetes Namespace to spawn jobs within + Namespace: "" + # Kubernetes Namespace to spawn jobs within + JobsNamespace: "" + # Kubernetes ServiceAccount to use for the job + ServiceAccount: "" + + # Master batch job template. See: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.17/#job-v1-batch + WorkerTemplate: "" + # NodeSelector (scheduling) + NodeSelector: {} + # Tolerations (scheduling) + Tolerations: [] + + # Job template used for executing the tasks. + ExecutorTemplate: "" + PVTemplate: "" + PVCTemplate: "" + + Resources: + Defaults: + Cpus: 1000m + RamGb: 512Mi + DiskGb: 512Mi + Limits: + Cpus: 8000m + RamGb: 4096Mi + DiskGb: 4096Mi + +# cleanup configures an optional CronJob that runs `funnel kubernetes cleanup` +# to delete orphaned Funnel-managed Kubernetes resources. It is intentionally +# turned off by default; set cleanup.enabled=true to enable it. +cleanup: + enabled: false + # Leave empty to derive the schedule from Kubernetes.ReconcileRate. Set a + # standard 5-field cron expression to override, e.g. "*/15 * * * *". + schedule: "" + # Offset the start minute so cleanup jobs in different namespaces do not all + # fire at the same instant. Must be 0-59. + scheduleOffsetMinutes: 0 + +# ------------------------------------------------------------------------------- +# Storage +# ------------------------------------------------------------------------------- + +# If possible, credentials will be automatically discovered +# from the environment. + +# -- Local file system storage configuration. +LocalStorage: + # Whitelist of local directory paths which Funnel is allowed to access. + AllowedDirs: + - ./ + +# HTTPStorage is used to download public files on the web via a GET request. +HTTPStorage: + # Timeout for http(s) GET requests. + Timeout: 30s + +AmazonS3: + Disabled: false + # The maximum number of times that a request will be retried for failures. + AWSConfig: + MaxRetries: 10 + # AWS Access key ID + Key: "" + # AWS Secret Access Key + Secret: "" + # Server Side Encryption (SSE) settings + SSE: + # Customer Provided Key + # ref: https://docs.aws.amazon.com/AmazonS3/latest/userguide/ServerSideEncryptionCustomerKeys.html + CustomerKeyFile: "" + # KMS Key + # ref: https://docs.aws.amazon.com/AmazonS3/latest/userguide/UsingKMSEncryption.html + KMSKey: "" + +# Configure storage backends for S3 providers such as Minio and/or Ceph +# GenericS3: +# - Disabled: true +# Endpoint: "" +# Key: "" +# Secret: "" +# KmsKeyID: "" + +GoogleStorage: + Disabled: false + # Path to account credentials file. + # Optional. If possible, credentials will be automatically discovered + # from the environment. + CredentialsFile: "" +# Available backends: local, htcondor, slurm, pbs, gridengine, manual, aws-batch, kubernetes/Kube +Swift: + Disabled: false + UserName: "" + Password: "" + AuthURL: "" + TenantName: "" + TenantID: "" + RegionName: "" + # 500 MB + ChunkSizeBytes: 500000000 + +FTPStorage: + Disabled: false + Timeout: 10s + User: "anonymous" + Password: "anonymous" + +Server: + # Hostname of the Funnel server. + HostName: funnel + + # Port used for HTTP communication and the web dashboard. + HTTPPort: "8000" + + # Port used for RPC communication. + RPCPort: "9090" + + # Require basic authentication for the server APIs using a password. + # If used, make sure to properly restrict access to the config file + # (e.g. chmod 600 funnel.config.yml) + # BasicAuth: + # - User: user1 + # Password: abc123 + # - User: user2 + # Password: foobar + + # Include a "Cache-Control: no-store" HTTP header in Get/List responses + # to prevent caching by intermediary services. + DisableHTTPCache: true + +RPCClient: + # RPC server address + ServerAddress: localhost:9090 + + # Credentials for Basic authentication for the server APIs using a password. + # If used, make sure to properly restrict access to the config file + # (e.g. chmod 600 funnel.config.yml) + # User: funnel + # Password: abc123 + + # connection timeout. + Timeout: + duration: 60s + + # The maximum number of times that a request will be retried for failures. + # Time between retries follows an exponential backoff starting at 5 seconds + # up to 1 minute + MaxRetries: 10 + +# The scheduler is used for the Manual compute backend. +Scheduler: + # How often to run a scheduler iteration. + ScheduleRate: 1s + # How many tasks to schedule in one iteration. + ScheduleChunk: 10 + # How long to wait between updates before marking a node dead. + NodePingTimeout: + duration: 60s + # How long to wait for a node to start, before marking the node dead. + NodeInitTimeout: + duration: 300s + +Node: + # If empty, a node ID will be automatically generated. + ID: "" + + # If the node has been idle for longer than the timeout, it will shut down. + # -1 means there is no timeout. 0 means timeout immediately after the first task. + Timeout: + disabled: true + + # A Node will automatically try to detect what resources are available to it. + # Defining Resources in the Node configuration overrides this behavior. + Resources: + # CPUs available. + Cpus: 0 + + # RAM available, in GB. + RamGb: 0.0 + + # Disk space available, in GB. + DiskGb: 0.0 + + # For low-level tuning. + # How often to sync with the Funnel server. + UpdateRate: 5s + +Worker: + # Files created during processing will be written in this directory. + WorkDir: ./funnel-work-dir + + # For low-level tuning. + # How often to poll for cancel signals + PollingRate: 5s + + # For low-level tuning. + # How often to send stdout/err task log updates to the Funnel server. + # Setting this to 0 will result in these fields being updated a single time + # after the executor exits. + LogUpdateRate: 5s + + # Max bytes to store for stdout/err in the task log (10 KB) + LogTailSize: 10000 + + # Normally the worker deletes its working directory after executing. + # This option disables that behavior. + # This lets mount-s3 pods unmount and Complete. https://ctds-planx.atlassian.net/browse/MIDRC-1214 + LeaveWorkDir: true + + # Limit the number of concurrent downloads/uploads + MaxParallelTransfers: 10 + +# ------------------------------------------------------------------------------- +# Databases and/or Event Writers/Handlers +# ------------------------------------------------------------------------------- + +# -- Local file database configuration. +BoltDB: + # Path to the database file + Path: ./funnel-work-dir/funnel.db + +DynamoDB: + # Basename to use for dynamodb tables + TableBasename: funnel + AWSConfig: + # AWS region + Region: "" + # AWS Access key ID + Key: "" + # AWS Secret Access Key + Secret: "" + +Elastic: + # Prefix to use for indexes (task, events, nodes) + IndexPrefix: funnel + # URL of the elasticsearch server. + URL: http://localhost:9200 + +# Google Cloud Datastore task database. +Datastore: + Project: "" + # Path to account credentials file. + # Optional. If possible, credentials will be automatically discovered + # from the environment. + CredentialsFile: "" + + Timeout: + duration: 300s + +Kafka: + Topic: funnel + +# ------------------------------------------------------------------------------- +# Compute Backends +# ------------------------------------------------------------------------------- + +# -- HTCondor compute backend configuration. +HTCondor: + # Turn off task state reconciler. When enabled, Funnel communicates with the HPC + # scheduler to find tasks that are stuck in a queued state or errored and + # updates the task state accordingly. + DisableReconciler: true + # ReconcileRate is how often the compute backend compares states in Funnel's backend + # to those reported by the backend + ReconcileRate: 10s + TemplateFile: "" + Template: | + universe = vanilla + getenv = True + executable = {{.Executable}} + arguments = worker run --config {{.Config}} --task-id {{.TaskId}} + log = {{.WorkDir}}/condor-event-log + error = {{.WorkDir}}/funnel-stderr + output = {{.WorkDir}}/funnel-stdout + should_transfer_files = YES + when_to_transfer_output = ON_EXIT_OR_EVICT + {{if ne .Cpus 0 -}} + {{printf "request_cpus = %d" .Cpus}} + {{- end}} + {{if ne .RamGb 0.0 -}} + {{printf "request_memory = %.0f GB" .RamGb}} + {{- end}} + {{if ne .DiskGb 0.0 -}} + {{printf "request_disk = %.0f GB" .DiskGb}} + {{- end}} + + queue + +PBS: + # Turn off task state reconciler. When enabled, Funnel communicates with the HPC + # scheduler to find tasks that are stuck in a queued state or errored and + # updates the task state accordingly. + DisableReconciler: true + # ReconcileRate is how often the compute backend compares states in Funnel's backend + # to those reported by the backend + ReconcileRate: 10s + TemplateFile: "" + Template: | + #!bin/bash + #PBS -N {{.TaskId}} + #PBS -o {{.WorkDir}}/funnel-stdout + #PBS -e {{.WorkDir}}/funnel-stderr + {{if ne .Cpus 0 -}} + {{printf "#PBS -l nodes=1:ppn=%d" .Cpus}} + {{- end}} + {{if ne .RamGb 0.0 -}} + {{printf "#PBS -l mem=%.0fgb" .RamGb}} + {{- end}} + {{if ne .DiskGb 0.0 -}} + {{printf "#PBS -l file=%.0fgb" .DiskGb}} + {{- end}} + + {{.Executable}} worker run --config {{.Config}} --taskID {{.TaskId}} + +GridEngine: + TemplateFile: "" + Template: | + #!bin/bash + #$ -N {{.TaskId}} + #$ -o {{.WorkDir}}/funnel-stdout + #$ -e {{.WorkDir}}/funnel-stderr + #$ -l nodes=1 + {{if ne .Cpus 0 -}} + {{printf "#$ -pe mpi %d" .Cpus}} + {{- end}} + {{if ne .RamGb 0.0 -}} + {{printf "#$ -l h_vmem=%.0fG" .RamGb}} + {{- end}} + {{if ne .DiskGb 0.0 -}} + {{printf "#$ -l h_fsize=%.0fG" .DiskGb}} + {{- end}} + + {{.Executable}} worker run --config {{.Config}} --taskID {{.TaskId}} + +Slurm: + # Turn off task state reconciler. When enabled, Funnel communicates with the HPC + # scheduler to find tasks that are stuck in a queued state or errored and + # updates the task state accordingly. + DisableReconciler: true + # ReconcileRate is how often the compute backend compares states in Funnel's backend + # to those reported by the backend + ReconcileRate: 10s + TemplateFile: "" + Template: | + #!/bin/bash + #SBATCH --job-name {{.TaskId}} + #SBATCH --ntasks 1 + #SBATCH --error {{.WorkDir}}/funnel-stderr + #SBATCH --output {{.WorkDir}}/funnel-stdout + {{if ne .Cpus 0 -}} + {{printf "#SBATCH --cpus-per-task %d" .Cpus}} + {{- end}} + {{if ne .RamGb 0.0 -}} + {{printf "#SBATCH --mem %.0fGB" .RamGb}} + {{- end}} + {{if ne .DiskGb 0.0 -}} + {{printf "#SBATCH --tmp %.0fGB" .DiskGb}} + {{- end}} + + {{.Executable}} worker run --config {{.Config}} --taskID {{.TaskId}} + +# AWSBatch describes the configuration for the AWS Batch compute backend. +AWSBatch: + # Turn off task state reconciler. When enabled, Funnel communicates with AWS Batch + # to find tasks that never started and updates task state accordingly. + DisableReconciler: true + # ReconcileRate is how often the compute backend compares states in Funnel's backend + # to those reported by AWS Batch + ReconcileRate: 10s + # JobDefinition can be either a name or the Amazon Resource Name (ARN). + JobDefinition: "funnel-job-def" + # JobQueue can be either a name or the Amazon Resource Name (ARN). + JobQueue: "funnel-job-queue" + # AWS region of the specified job queue and to create the job definition in + Region: "" + Key: "" + Secret: "" diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index adbb3d5ee..b955189d5 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -72,7 +72,7 @@ dependencies: repository: "file://../fence" condition: fence.enabled - name: funnel - version: 0.1.28 + version: 0.1.29 repository: "file://../funnel" condition: gen3-workflow.enabled - name: gen3-user-data-library @@ -213,7 +213,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.73 +version: 0.3.74 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index f756ccf03..8a113551b 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,6 +1,6 @@ # gen3 -![Version: 0.3.73](https://img.shields.io/badge/Version-0.3.73-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.3.74](https://img.shields.io/badge/Version-0.3.74-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons @@ -36,7 +36,7 @@ Helm chart to deploy Gen3 Data Commons | file://../etl | etl | 0.1.24 | | file://../fence | fence | 0.1.81 | | file://../frontend-framework | frontend-framework | 0.1.31 | -| file://../funnel | funnel | 0.1.28 | +| file://../funnel | funnel | 0.1.29 | | file://../gen3-analysis | gen3-analysis | 0.1.14 | | file://../gen3-network-policies | gen3-network-policies | 0.1.4 | | file://../gen3-user-data-library | gen3-user-data-library | 0.1.17 | From 4a623a490021b762966c139517a6d7194c9ad3eb Mon Sep 17 00:00:00 2001 From: Edward Malinowski Date: Tue, 28 Jul 2026 11:16:12 -0500 Subject: [PATCH 161/196] Added fix to postgres values in gen3 chart --- helm/gen3/Chart.yaml | 2 +- helm/gen3/README.md | 6 +++--- helm/gen3/values.yaml | 3 +-- helm/revproxy/Chart.yaml | 2 +- helm/revproxy/README.md | 2 +- 5 files changed, 7 insertions(+), 8 deletions(-) diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index e60685570..1ec5e265b 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -116,7 +116,7 @@ dependencies: repository: "file://../requestor" condition: requestor.enabled - name: revproxy - version: 0.1.67 + version: 0.1.68 repository: "file://../revproxy" condition: revproxy.enabled - name: sheepdog diff --git a/helm/gen3/README.md b/helm/gen3/README.md index 18b35fe45..5282155f3 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,6 +1,6 @@ # gen3 -![Version: 0.3.75](https://img.shields.io/badge/Version-0.3.74-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.3.75](https://img.shields.io/badge/Version-0.3.75-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons @@ -55,7 +55,7 @@ Helm chart to deploy Gen3 Data Commons | file://../peregrine | peregrine | 0.1.44 | | file://../portal | portal | 0.1.62 | | file://../requestor | requestor | 0.1.37 | -| file://../revproxy | revproxy | 0.1.67 | +| file://../revproxy | revproxy | 0.1.68 | | file://../sheepdog | sheepdog | 0.1.46 | | file://../sower | sower | 0.1.48 | | file://../ssjdispatcher | ssjdispatcher | 0.1.49 | @@ -257,7 +257,7 @@ Helm chart to deploy Gen3 Data Commons | peregrine.enabled | bool | `true` | Whether to deploy the peregrine subchart. | | pidgin.enabled | bool | `false` | Whether to deploy the pidgin subchart. | | portal.enabled | bool | `true` | Whether to deploy the portal subchart. | -| postgresql | map | `{"global":{"imageRegistry":"quay.io"},"image":{"repository":"cdis/docker-bitnami-pgvector","tag":16},"primary":{"persistence":{"enabled":false}}}` | To configure postgresql subchart Disable persistence by default so we can spin up and down ephemeral environments | +| postgresql | map | `{"image":{"registry":"quay.io","repository":"cdis/docker-bitnami-pgvector","tag":16},"primary":{"persistence":{"enabled":false}}}` | To configure postgresql subchart Disable persistence by default so we can spin up and down ephemeral environments | | postgresql.primary.persistence.enabled | bool | `false` | Option to persist the dbs data. | | requestor.enabled | bool | `false` | Whether to deploy the requestor subchart. | | revproxy.enabled | bool | `true` | Whether to deploy the revproxy subchart. | diff --git a/helm/gen3/values.yaml b/helm/gen3/values.yaml index 71f2b7e08..170534293 100644 --- a/helm/gen3/values.yaml +++ b/helm/gen3/values.yaml @@ -423,9 +423,8 @@ access-backend: # -- (map) To configure postgresql subchart # Disable persistence by default so we can spin up and down ephemeral environments postgresql: - global: - imageRegistry: "quay.io" image: + registry: quay.io repository: "cdis/docker-bitnami-pgvector" tag: 16 primary: diff --git a/helm/revproxy/Chart.yaml b/helm/revproxy/Chart.yaml index f4a76178d..fba5a5cbc 100644 --- a/helm/revproxy/Chart.yaml +++ b/helm/revproxy/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.67 +version: 0.1.68 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/revproxy/README.md b/helm/revproxy/README.md index cd9c0fff6..9f57b5af1 100644 --- a/helm/revproxy/README.md +++ b/helm/revproxy/README.md @@ -1,6 +1,6 @@ # revproxy -![Version: 0.1.67](https://img.shields.io/badge/Version-0.1.67-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.68](https://img.shields.io/badge/Version-0.1.68-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 revproxy From 229492c67ad71a65291ff8fe31698fced8e34b69 Mon Sep 17 00:00:00 2001 From: Sai Shanmukha Date: Thu, 30 Jul 2026 14:23:14 -0500 Subject: [PATCH 162/196] Add eksSG to gen3-workflow helm chart --- helm/gen3-workflow/Chart.yaml | 2 +- helm/gen3-workflow/README.md | 3 ++- helm/gen3-workflow/templates/secrets.yaml | 1 + helm/gen3-workflow/values.yaml | 2 ++ helm/gen3/Chart.yaml | 4 ++-- helm/gen3/README.md | 4 ++-- 6 files changed, 10 insertions(+), 6 deletions(-) diff --git a/helm/gen3-workflow/Chart.yaml b/helm/gen3-workflow/Chart.yaml index 96e7423f7..0731dd2e1 100644 --- a/helm/gen3-workflow/Chart.yaml +++ b/helm/gen3-workflow/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.25 +version: 0.1.26 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3-workflow/README.md b/helm/gen3-workflow/README.md index ad9643300..8dc331073 100644 --- a/helm/gen3-workflow/README.md +++ b/helm/gen3-workflow/README.md @@ -1,6 +1,6 @@ # gen3-workflow -![Version: 0.1.25](https://img.shields.io/badge/Version-0.1.25-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.26](https://img.shields.io/badge/Version-0.1.26-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for Kubernetes @@ -42,6 +42,7 @@ A Helm chart for Kubernetes | fullnameOverride | string | `""` | Override the full name of the chart, which is used as the name of resources created by the chart | | gen3WorkflowConfig.arboristUrl | string | `""` | Custom Arborist URL. Ignored if already set via environment variable. | | gen3WorkflowConfig.debug | bool | `false` | Enables debug mode for the application. | +| gen3WorkflowConfig.eksSecurityGroupNames | list | `[]` | Names of the EKS security groups that Karpenter attaches to an EKS worker node in the cluster (needed for S3Files) | | gen3WorkflowConfig.enableOptimizedNodeScheduling | bool | `true` | When enabled, jobs are configured to run on specific nodes through Kubernetes NodeSelector and Tolerations. Disable this if using a cluster that does not support nodepools. | | gen3WorkflowConfig.enablePrometheusMetrics | bool | `false` | Enables Prometheus metrics for the workflow service. | | gen3WorkflowConfig.enableS3Files | bool | `false` | Set it to true to create S3Files resources (default - false) | diff --git a/helm/gen3-workflow/templates/secrets.yaml b/helm/gen3-workflow/templates/secrets.yaml index 41aeb2433..8ae04b72f 100644 --- a/helm/gen3-workflow/templates/secrets.yaml +++ b/helm/gen3-workflow/templates/secrets.yaml @@ -54,4 +54,5 @@ stringData: EKS_CLUSTER_NAME: {{ .Values.global.clusterName }} EKS_CLUSTER_REGION: {{ .Values.global.aws.region }} {{- end }} + EKS_SECURITY_GROUP_NAMES: {{ .Values.gen3WorkflowConfig.eksSecurityGroupNames | toJson }} {{- end }} diff --git a/helm/gen3-workflow/values.yaml b/helm/gen3-workflow/values.yaml index a7c7676d5..86e078b3f 100644 --- a/helm/gen3-workflow/values.yaml +++ b/helm/gen3-workflow/values.yaml @@ -316,6 +316,8 @@ gen3WorkflowConfig: kmsEncryptionEnabled: true # -- (bool) Set it to true to create S3Files resources (default - false) enableS3Files: false + # -- (list) Names of the EKS security groups that Karpenter attaches to an EKS worker node in the cluster (needed for S3Files) + eksSecurityGroupNames: [] # -- (string) TES server URL to which workflow tasks are forwarded. tesServerUrl: http://funnel:8000 # -- (list) Whitelist of container image patterns allowed for workflow tasks. diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index 1ec5e265b..7f162b8e5 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -80,7 +80,7 @@ dependencies: repository: "file://../gen3-user-data-library" condition: gen3-user-data-library.enabled - name: gen3-workflow - version: 0.1.25 + version: 0.1.26 repository: "file://../gen3-workflow" condition: gen3-workflow.enabled - name: guppy @@ -213,7 +213,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.75 +version: 0.3.76 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index 5282155f3..c4619c901 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,6 +1,6 @@ # gen3 -![Version: 0.3.75](https://img.shields.io/badge/Version-0.3.75-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.3.76](https://img.shields.io/badge/Version-0.3.76-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons @@ -40,7 +40,7 @@ Helm chart to deploy Gen3 Data Commons | file://../gen3-analysis | gen3-analysis | 0.1.14 | | file://../gen3-network-policies | gen3-network-policies | 0.1.4 | | file://../gen3-user-data-library | gen3-user-data-library | 0.1.17 | -| file://../gen3-workflow | gen3-workflow | 0.1.25 | +| file://../gen3-workflow | gen3-workflow | 0.1.26 | | file://../guppy | guppy | 0.1.40 | | file://../hatchery | hatchery | 0.1.72 | | file://../indexd | indexd | 0.1.49 | From 766377cab85a264858cd03faad268f90df74448c Mon Sep 17 00:00:00 2001 From: Pauline Ribeyre <4224001+paulineribeyre@users.noreply.github.com> Date: Thu, 30 Jul 2026 17:12:49 -0500 Subject: [PATCH 163/196] gen3-workflow s3:ListMultipartUploads + _IMAGE_PULL_POLICY tag (#661) --- helm/funnel/Chart.yaml | 2 +- helm/funnel/README.md | 2 +- helm/funnel/files/executor-job.yaml | 2 +- helm/gen3-workflow/Chart.yaml | 2 +- helm/gen3-workflow/README.md | 2 +- helm/gen3-workflow/templates/crossplane.yaml | 5 +++-- helm/gen3/Chart.yaml | 6 +++--- helm/gen3/README.md | 6 +++--- 8 files changed, 14 insertions(+), 13 deletions(-) diff --git a/helm/funnel/Chart.yaml b/helm/funnel/Chart.yaml index e0077e047..8edfd6062 100644 --- a/helm/funnel/Chart.yaml +++ b/helm/funnel/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.29 +version: 0.1.30 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/funnel/README.md b/helm/funnel/README.md index cd3df1527..889a99cc5 100644 --- a/helm/funnel/README.md +++ b/helm/funnel/README.md @@ -1,6 +1,6 @@ # funnel -![Version: 0.1.29](https://img.shields.io/badge/Version-0.1.29-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.30](https://img.shields.io/badge/Version-0.1.30-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for Kubernetes diff --git a/helm/funnel/files/executor-job.yaml b/helm/funnel/files/executor-job.yaml index 8bd6a3da5..250a2fad8 100644 --- a/helm/funnel/files/executor-job.yaml +++ b/helm/funnel/files/executor-job.yaml @@ -79,7 +79,7 @@ spec: containers: - name: funnel-executor-{{`{{.TaskId}}`}} image: {{`{{.Image}}`}} - imagePullPolicy: Always + imagePullPolicy: {{`{{if .ImagePullPolicy}}{{.ImagePullPolicy}}{{else}}Always{{end}}`}} securityContext: # Block the ability to gain more privileges allowPrivilegeEscalation: false diff --git a/helm/gen3-workflow/Chart.yaml b/helm/gen3-workflow/Chart.yaml index 96e7423f7..0731dd2e1 100644 --- a/helm/gen3-workflow/Chart.yaml +++ b/helm/gen3-workflow/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.25 +version: 0.1.26 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3-workflow/README.md b/helm/gen3-workflow/README.md index ad9643300..9b8d58584 100644 --- a/helm/gen3-workflow/README.md +++ b/helm/gen3-workflow/README.md @@ -1,6 +1,6 @@ # gen3-workflow -![Version: 0.1.25](https://img.shields.io/badge/Version-0.1.25-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.26](https://img.shields.io/badge/Version-0.1.26-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for Kubernetes diff --git a/helm/gen3-workflow/templates/crossplane.yaml b/helm/gen3-workflow/templates/crossplane.yaml index a99dff0ca..fed9d5a86 100644 --- a/helm/gen3-workflow/templates/crossplane.yaml +++ b/helm/gen3-workflow/templates/crossplane.yaml @@ -60,6 +60,7 @@ spec: "s3:GetObject", "s3:PutObject", "s3:DeleteObject", + "s3:ListBucketMultipartUploads", "s3:AbortMultipartUpload", "s3:DeleteBucketPolicy", "s3:GetEncryptionConfiguration", @@ -69,7 +70,7 @@ spec: "s3:PutLifecycleConfiguration", "s3:GetBucketVersioning", "s3:PutBucketVersioning", - "s3:"DeleteObjectVersion", + "s3:DeleteObjectVersion", "s3:GetBucketNotification", "s3:PutBucketNotification" ], @@ -194,4 +195,4 @@ spec: roleName: "{{ .Values.global.environment }}-{{ .Release.Namespace }}-{{ include "gen3workflow.serviceAccountName" . }}" policyArnRef: name: "{{ .Values.global.environment }}-{{ .Release.Namespace }}-gen3-workflow-policy" -{{- end }} \ No newline at end of file +{{- end }} diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index 1ec5e265b..013936b10 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -72,7 +72,7 @@ dependencies: repository: "file://../fence" condition: fence.enabled - name: funnel - version: 0.1.29 + version: 0.1.30 repository: "file://../funnel" condition: gen3-workflow.enabled - name: gen3-user-data-library @@ -80,7 +80,7 @@ dependencies: repository: "file://../gen3-user-data-library" condition: gen3-user-data-library.enabled - name: gen3-workflow - version: 0.1.25 + version: 0.1.26 repository: "file://../gen3-workflow" condition: gen3-workflow.enabled - name: guppy @@ -213,7 +213,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.75 +version: 0.3.76 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index 5282155f3..4baab365a 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,6 +1,6 @@ # gen3 -![Version: 0.3.75](https://img.shields.io/badge/Version-0.3.75-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.3.76](https://img.shields.io/badge/Version-0.3.76-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons @@ -36,11 +36,11 @@ Helm chart to deploy Gen3 Data Commons | file://../etl | etl | 0.1.24 | | file://../fence | fence | 0.1.81 | | file://../frontend-framework | frontend-framework | 0.1.31 | -| file://../funnel | funnel | 0.1.29 | +| file://../funnel | funnel | 0.1.30 | | file://../gen3-analysis | gen3-analysis | 0.1.14 | | file://../gen3-network-policies | gen3-network-policies | 0.1.4 | | file://../gen3-user-data-library | gen3-user-data-library | 0.1.17 | -| file://../gen3-workflow | gen3-workflow | 0.1.25 | +| file://../gen3-workflow | gen3-workflow | 0.1.26 | | file://../guppy | guppy | 0.1.40 | | file://../hatchery | hatchery | 0.1.72 | | file://../indexd | indexd | 0.1.49 | From 2ad1417d0b0e5322d037f599cb126c34fac34906 Mon Sep 17 00:00:00 2001 From: Sai Shanmukha Date: Thu, 30 Jul 2026 21:53:10 -0500 Subject: [PATCH 164/196] Version bump gen3-workflow --- helm/gen3-workflow/Chart.yaml | 2 +- helm/gen3-workflow/README.md | 2 +- helm/gen3/Chart.yaml | 4 ++-- helm/gen3/README.md | 4 ++-- 4 files changed, 6 insertions(+), 6 deletions(-) diff --git a/helm/gen3-workflow/Chart.yaml b/helm/gen3-workflow/Chart.yaml index 0731dd2e1..bb47357b6 100644 --- a/helm/gen3-workflow/Chart.yaml +++ b/helm/gen3-workflow/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.26 +version: 0.1.27 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3-workflow/README.md b/helm/gen3-workflow/README.md index 8dc331073..78afda907 100644 --- a/helm/gen3-workflow/README.md +++ b/helm/gen3-workflow/README.md @@ -1,6 +1,6 @@ # gen3-workflow -![Version: 0.1.26](https://img.shields.io/badge/Version-0.1.26-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.27](https://img.shields.io/badge/Version-0.1.27-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for Kubernetes diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index 013936b10..030fc05d3 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -80,7 +80,7 @@ dependencies: repository: "file://../gen3-user-data-library" condition: gen3-user-data-library.enabled - name: gen3-workflow - version: 0.1.26 + version: 0.1.27 repository: "file://../gen3-workflow" condition: gen3-workflow.enabled - name: guppy @@ -213,7 +213,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.76 +version: 0.3.77 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index 4baab365a..107cbb7c8 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,6 +1,6 @@ # gen3 -![Version: 0.3.76](https://img.shields.io/badge/Version-0.3.76-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.3.77](https://img.shields.io/badge/Version-0.3.77-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons @@ -40,7 +40,7 @@ Helm chart to deploy Gen3 Data Commons | file://../gen3-analysis | gen3-analysis | 0.1.14 | | file://../gen3-network-policies | gen3-network-policies | 0.1.4 | | file://../gen3-user-data-library | gen3-user-data-library | 0.1.17 | -| file://../gen3-workflow | gen3-workflow | 0.1.26 | +| file://../gen3-workflow | gen3-workflow | 0.1.27 | | file://../guppy | guppy | 0.1.40 | | file://../hatchery | hatchery | 0.1.72 | | file://../indexd | indexd | 0.1.49 | From 8da5d4f2b7170170b9795be16077cc533c214277 Mon Sep 17 00:00:00 2001 From: Pauline Ribeyre <4224001+paulineribeyre@users.noreply.github.com> Date: Fri, 31 Jul 2026 13:56:42 -0500 Subject: [PATCH 165/196] Add s3:ListBucketVersions to crossplane.yaml --- helm/gen3-workflow/Chart.yaml | 2 +- helm/gen3-workflow/README.md | 2 +- helm/gen3-workflow/templates/crossplane.yaml | 1 + helm/gen3/Chart.yaml | 2 +- helm/gen3/README.md | 2 +- 5 files changed, 5 insertions(+), 4 deletions(-) diff --git a/helm/gen3-workflow/Chart.yaml b/helm/gen3-workflow/Chart.yaml index bb47357b6..7be836540 100644 --- a/helm/gen3-workflow/Chart.yaml +++ b/helm/gen3-workflow/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.27 +version: 0.1.28 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3-workflow/README.md b/helm/gen3-workflow/README.md index 78afda907..98a46d989 100644 --- a/helm/gen3-workflow/README.md +++ b/helm/gen3-workflow/README.md @@ -1,6 +1,6 @@ # gen3-workflow -![Version: 0.1.27](https://img.shields.io/badge/Version-0.1.27-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.28](https://img.shields.io/badge/Version-0.1.28-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for Kubernetes diff --git a/helm/gen3-workflow/templates/crossplane.yaml b/helm/gen3-workflow/templates/crossplane.yaml index fed9d5a86..d34aadb10 100644 --- a/helm/gen3-workflow/templates/crossplane.yaml +++ b/helm/gen3-workflow/templates/crossplane.yaml @@ -70,6 +70,7 @@ spec: "s3:PutLifecycleConfiguration", "s3:GetBucketVersioning", "s3:PutBucketVersioning", + "s3:ListBucketVersions", "s3:DeleteObjectVersion", "s3:GetBucketNotification", "s3:PutBucketNotification" diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index d90e7f099..3e84ce2fe 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -80,7 +80,7 @@ dependencies: repository: "file://../gen3-user-data-library" condition: gen3-user-data-library.enabled - name: gen3-workflow - version: 0.1.27 + version: 0.1.28 repository: "file://../gen3-workflow" condition: gen3-workflow.enabled - name: guppy diff --git a/helm/gen3/README.md b/helm/gen3/README.md index 765fdad96..8ddcdf156 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -40,7 +40,7 @@ Helm chart to deploy Gen3 Data Commons | file://../gen3-analysis | gen3-analysis | 0.1.14 | | file://../gen3-network-policies | gen3-network-policies | 0.1.4 | | file://../gen3-user-data-library | gen3-user-data-library | 0.1.17 | -| file://../gen3-workflow | gen3-workflow | 0.1.27 | +| file://../gen3-workflow | gen3-workflow | 0.1.28 | | file://../guppy | guppy | 0.1.40 | | file://../hatchery | hatchery | 0.1.72 | | file://../indexd | indexd | 0.1.49 | From 1e7730732ac8500516a8b33388e7755d3ca4e798 Mon Sep 17 00:00:00 2001 From: Edward Malinowski Date: Fri, 31 Jul 2026 16:41:39 -0500 Subject: [PATCH 166/196] Update efs-csi-driver.yaml --- helm/cluster-level-resources/templates/efs-csi-driver.yaml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/helm/cluster-level-resources/templates/efs-csi-driver.yaml b/helm/cluster-level-resources/templates/efs-csi-driver.yaml index fe5b330f9..3f3db2fc1 100644 --- a/helm/cluster-level-resources/templates/efs-csi-driver.yaml +++ b/helm/cluster-level-resources/templates/efs-csi-driver.yaml @@ -27,11 +27,11 @@ spec: controller: serviceAccount: annotations: - eks.amazonaws.com/role-arn: arn:aws:iam::{{ .Values.accountNumber }}:role/gen3_service/{{ .Values.eksClusterName | default .Values.cluster }}--kube-system--efs-csi-controller + eks.amazonaws.com/role-arn: arn:aws:iam::{{ .Values.accountNumber }}:role/{{ .Values.eksClusterName | default .Values.cluster }}--kube-system--efs-csi-controller node: serviceAccount: annotations: - eks.amazonaws.com/role-arn: arn:aws:iam::{{ .Values.accountNumber }}:role/gen3_service/{{ .Values.eksClusterName | default .Values.cluster }}--kube-system--efs-csi-node + eks.amazonaws.com/role-arn: arn:aws:iam::{{ .Values.accountNumber }}:role/{{ .Values.eksClusterName | default .Values.cluster }}--kube-system--efs-csi-node {{- end }} destination: server: "https://kubernetes.default.svc" From 3a12e75da1a5bf0d39b61b664c7d9f216f6303e2 Mon Sep 17 00:00:00 2001 From: Justin Barnowski Date: Tue, 4 Aug 2026 12:57:40 -0500 Subject: [PATCH 167/196] feat(config): let configuration get passed through for cert-manager --- helm/cluster-level-resources/Chart.yaml | 2 +- helm/cluster-level-resources/README.md | 2 +- helm/cluster-level-resources/templates/certmanager.yaml | 3 +++ 3 files changed, 5 insertions(+), 2 deletions(-) diff --git a/helm/cluster-level-resources/Chart.yaml b/helm/cluster-level-resources/Chart.yaml index 938343293..c2790ed48 100644 --- a/helm/cluster-level-resources/Chart.yaml +++ b/helm/cluster-level-resources/Chart.yaml @@ -4,6 +4,6 @@ description: An app-of-apps Helm chart that allows for flexible deployment of re type: application -version: 0.6.45 +version: 0.6.46 appVersion: "1.17.0" diff --git a/helm/cluster-level-resources/README.md b/helm/cluster-level-resources/README.md index 42d8af39a..65b732728 100644 --- a/helm/cluster-level-resources/README.md +++ b/helm/cluster-level-resources/README.md @@ -1,6 +1,6 @@ # cluster-level-resources -![Version: 0.6.45](https://img.shields.io/badge/Version-0.6.45-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.17.0](https://img.shields.io/badge/AppVersion-1.17.0-informational?style=flat-square) +![Version: 0.6.46](https://img.shields.io/badge/Version-0.6.46-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.17.0](https://img.shields.io/badge/AppVersion-1.17.0-informational?style=flat-square) An app-of-apps Helm chart that allows for flexible deployment of resources that support Gen3 diff --git a/helm/cluster-level-resources/templates/certmanager.yaml b/helm/cluster-level-resources/templates/certmanager.yaml index 81ebca55d..4998680a1 100644 --- a/helm/cluster-level-resources/templates/certmanager.yaml +++ b/helm/cluster-level-resources/templates/certmanager.yaml @@ -15,6 +15,9 @@ spec: values: | crds: enabled: true + {{- if (index .Values "cert-manager" "configuration" "enabled") }} + {{- nindent 10 (toYaml .Values.cert-manager.configuration") }} + {{- end }} destination: server: "https://kubernetes.default.svc" namespace: cert-manager From 9ed3c1d17ad84e5e60aa7cb916038116d89b29fd Mon Sep 17 00:00:00 2001 From: Justin Barnowski Date: Tue, 4 Aug 2026 13:11:51 -0500 Subject: [PATCH 168/196] fix(syntax): nindent at the end --- helm/cluster-level-resources/templates/certmanager.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/helm/cluster-level-resources/templates/certmanager.yaml b/helm/cluster-level-resources/templates/certmanager.yaml index 4998680a1..785892602 100644 --- a/helm/cluster-level-resources/templates/certmanager.yaml +++ b/helm/cluster-level-resources/templates/certmanager.yaml @@ -16,7 +16,7 @@ spec: crds: enabled: true {{- if (index .Values "cert-manager" "configuration" "enabled") }} - {{- nindent 10 (toYaml .Values.cert-manager.configuration") }} + {{ toYaml (index .Values "cert-manager" "configuration") | nindent 10 }} {{- end }} destination: server: "https://kubernetes.default.svc" From 1e4cc55d1b5f4e1b9c2a3af85297da03f36ccffb Mon Sep 17 00:00:00 2001 From: Edward Malinowski Date: Tue, 4 Aug 2026 16:27:12 -0500 Subject: [PATCH 169/196] Update efs-csi-driver.yaml --- helm/cluster-level-resources/templates/efs-csi-driver.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/helm/cluster-level-resources/templates/efs-csi-driver.yaml b/helm/cluster-level-resources/templates/efs-csi-driver.yaml index 3f3db2fc1..d7b1142e9 100644 --- a/helm/cluster-level-resources/templates/efs-csi-driver.yaml +++ b/helm/cluster-level-resources/templates/efs-csi-driver.yaml @@ -21,7 +21,7 @@ spec: {{- else }} values: | image: - tag: v3.2.0 + tag: v3.3.0 useFIPS: true controller: From 8dd4efa88441f85e90dbb5443e1a8e4b87d3163c Mon Sep 17 00:00:00 2001 From: mark xiao Date: Tue, 4 Aug 2026 16:59:34 -0500 Subject: [PATCH 170/196] update --- helm/common/Chart.yaml | 4 ---- helm/common/README.md | 4 ---- helm/fence/Chart.yaml | 4 ---- helm/fence/README.md | 4 ---- helm/gen3/Chart.yaml | 16 --------------- helm/gen3/README.md | 44 +--------------------------------------- helm/revproxy/Chart.yaml | 4 ---- helm/revproxy/README.md | 4 ---- 8 files changed, 1 insertion(+), 83 deletions(-) diff --git a/helm/common/Chart.yaml b/helm/common/Chart.yaml index 330cbcf9a..3dfd2f1cc 100644 --- a/helm/common/Chart.yaml +++ b/helm/common/Chart.yaml @@ -15,11 +15,7 @@ type: library # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -<<<<<<< HEAD -version: 0.1.36 -======= version: 0.1.38 ->>>>>>> origin/master # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/common/README.md b/helm/common/README.md index 283ed240b..b48fb0ddf 100644 --- a/helm/common/README.md +++ b/helm/common/README.md @@ -1,10 +1,6 @@ # common -<<<<<<< HEAD -![Version: 0.1.36](https://img.shields.io/badge/Version-0.1.36-informational?style=flat-square) ![Type: library](https://img.shields.io/badge/Type-library-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) -======= ![Version: 0.1.38](https://img.shields.io/badge/Version-0.1.38-informational?style=flat-square) ![Type: library](https://img.shields.io/badge/Type-library-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) ->>>>>>> origin/master A Helm chart for provisioning databases in gen3 diff --git a/helm/fence/Chart.yaml b/helm/fence/Chart.yaml index d88d9d7a8..29e19a6af 100644 --- a/helm/fence/Chart.yaml +++ b/helm/fence/Chart.yaml @@ -15,11 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -<<<<<<< HEAD -version: 0.1.78 -======= version: 0.1.81 ->>>>>>> origin/master # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/fence/README.md b/helm/fence/README.md index 2976650c9..6251a0962 100644 --- a/helm/fence/README.md +++ b/helm/fence/README.md @@ -1,10 +1,6 @@ # fence -<<<<<<< HEAD -![Version: 0.1.78](https://img.shields.io/badge/Version-0.1.78-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) -======= ![Version: 0.1.81](https://img.shields.io/badge/Version-0.1.81-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) ->>>>>>> origin/master A Helm chart for gen3 Fence diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index 52f2d0af5..924ebef4d 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -41,11 +41,7 @@ dependencies: repository: "file://../cohort-middleware" condition: cohort-middleware.enabled - name: common -<<<<<<< HEAD - version: 0.1.36 -======= version: 0.1.38 ->>>>>>> origin/master repository: file://../common - name: dashboard version: 0.1.23 @@ -72,11 +68,7 @@ dependencies: repository: "file://../frontend-framework" condition: frontend-framework.enabled - name: fence -<<<<<<< HEAD - version: 0.1.78 -======= version: 0.1.81 ->>>>>>> origin/master repository: "file://../fence" condition: fence.enabled - name: funnel @@ -128,11 +120,7 @@ dependencies: repository: "file://../requestor" condition: requestor.enabled - name: revproxy -<<<<<<< HEAD - version: 0.1.59 -======= version: 0.1.68 ->>>>>>> origin/master repository: "file://../revproxy" condition: revproxy.enabled - name: sheepdog @@ -229,11 +217,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -<<<<<<< HEAD -version: 0.3.48 -======= version: 0.3.78 ->>>>>>> origin/master # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index a5a709d2a..e0775b965 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,10 +1,6 @@ # gen3 -<<<<<<< HEAD -![Version: 0.3.48](https://img.shields.io/badge/Version-0.3.48-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) -======= ![Version: 0.3.78](https://img.shields.io/badge/Version-0.3.78-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) ->>>>>>> origin/master Helm chart to deploy Gen3 Data Commons @@ -22,29 +18,6 @@ Helm chart to deploy Gen3 Data Commons | Repository | Name | Version | |------------|------|---------| -<<<<<<< HEAD -| file://../access-backend | access-backend | 0.1.19 | -| file://../ambassador | ambassador | 0.1.36 | -| file://../arborist | arborist | 0.1.33 | -| file://../argo-wrapper | argo-wrapper | 0.1.28 | -| file://../audit | audit | 0.1.41 | -| file://../aws-es-proxy | aws-es-proxy | 0.1.40 | -| file://../aws-sigv4-proxy | aws-sigv4-proxy | 0.1.1 | -| file://../cedar | cedar | 0.1.25 | -| file://../cohort-middleware | cohort-middleware | 0.1.21 | -| file://../common | common | 0.1.36 | -| file://../dashboard | dashboard | 0.1.19 | -| file://../data-upload-cron | data-upload-cron | 0.1.5 | -| file://../datareplicate | datareplicate | 0.1.19 | -| file://../dicom-server | dicom-server | 0.1.29 | -| file://../embedding-management-service | embedding-management-service | 0.1.6 | -| file://../etl | etl | 0.1.23 | -| file://../fence | fence | 0.1.78 | -| file://../frontend-framework | frontend-framework | 0.1.28 | -| file://../funnel | funnel | 0.1.24 | -| file://../gen3-analysis | gen3-analysis | 0.1.11 | -| file://../gen3-embeddings | gen3-embeddings | 0.1.0 | -======= | file://../access-backend | access-backend | 0.1.22 | | file://../ambassador | ambassador | 0.1.39 | | file://../arborist | arborist | 0.1.36 | @@ -65,7 +38,7 @@ Helm chart to deploy Gen3 Data Commons | file://../frontend-framework | frontend-framework | 0.1.31 | | file://../funnel | funnel | 0.1.31 | | file://../gen3-analysis | gen3-analysis | 0.1.14 | ->>>>>>> origin/master +| file://../gen3-embeddings | gen3-embeddings | 0.1.0 | | file://../gen3-network-policies | gen3-network-policies | 0.1.4 | | file://../gen3-user-data-library | gen3-user-data-library | 0.1.17 | | file://../gen3-workflow | gen3-workflow | 0.1.28 | @@ -76,20 +49,6 @@ Helm chart to deploy Gen3 Data Commons | file://../manifestservice | manifestservice | 0.1.45 | | file://../metadata | metadata | 0.1.47 | | file://../neuvector | neuvector | 0.1.2 | -<<<<<<< HEAD -| file://../ohdsi-atlas | ohdsi-atlas | 0.1.1 | -| file://../ohdsi-webapi | ohdsi-webapi | 0.1.4 | -| file://../ohif-viewer | ohif-viewer | 0.1.12 | -| file://../orthanc | orthanc | 0.1.13 | -| file://../peregrine | peregrine | 0.1.41 | -| file://../portal | portal | 0.1.57 | -| file://../requestor | requestor | 0.1.33 | -| file://../revproxy | revproxy | 0.1.59 | -| file://../sheepdog | sheepdog | 0.1.41 | -| file://../sower | sower | 0.1.45 | -| file://../ssjdispatcher | ssjdispatcher | 0.1.45 | -| file://../wts | wts | 0.1.39 | -======= | file://../ohdsi-atlas | ohdsi-atlas | 0.1.2 | | file://../ohdsi-webapi | ohdsi-webapi | 0.1.7 | | file://../ohif-viewer | ohif-viewer | 0.1.16 | @@ -105,7 +64,6 @@ Helm chart to deploy Gen3 Data Commons | file://../workspace-proxy | workspace-proxy | 0.1.3 | | file://../wts | wts | 0.1.43 | | file://../zendesk-wrapper | zendesk-wrapper | 0.1.1 | ->>>>>>> origin/master | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | | https://helm.elastic.co | elasticsearch | 7.10.2 | diff --git a/helm/revproxy/Chart.yaml b/helm/revproxy/Chart.yaml index c7c7daa42..fba5a5cbc 100644 --- a/helm/revproxy/Chart.yaml +++ b/helm/revproxy/Chart.yaml @@ -15,11 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -<<<<<<< HEAD -version: 0.1.59 -======= version: 0.1.68 ->>>>>>> origin/master # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/revproxy/README.md b/helm/revproxy/README.md index c346070fa..9f57b5af1 100644 --- a/helm/revproxy/README.md +++ b/helm/revproxy/README.md @@ -1,10 +1,6 @@ # revproxy -<<<<<<< HEAD -![Version: 0.1.59](https://img.shields.io/badge/Version-0.1.59-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) -======= ![Version: 0.1.68](https://img.shields.io/badge/Version-0.1.68-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) ->>>>>>> origin/master A Helm chart for gen3 revproxy From b59f470607e6303a478f2235575819164a742821 Mon Sep 17 00:00:00 2001 From: Edward Malinowski Date: Wed, 5 Aug 2026 08:56:38 -0500 Subject: [PATCH 171/196] Bumped chart version --- helm/cluster-level-resources/Chart.yaml | 2 +- helm/cluster-level-resources/README.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/helm/cluster-level-resources/Chart.yaml b/helm/cluster-level-resources/Chart.yaml index c2790ed48..ebf157a7c 100644 --- a/helm/cluster-level-resources/Chart.yaml +++ b/helm/cluster-level-resources/Chart.yaml @@ -4,6 +4,6 @@ description: An app-of-apps Helm chart that allows for flexible deployment of re type: application -version: 0.6.46 +version: 0.6.47 appVersion: "1.17.0" diff --git a/helm/cluster-level-resources/README.md b/helm/cluster-level-resources/README.md index 81bf3e670..fce4a0cc3 100644 --- a/helm/cluster-level-resources/README.md +++ b/helm/cluster-level-resources/README.md @@ -1,6 +1,6 @@ # cluster-level-resources -![Version: 0.6.46](https://img.shields.io/badge/Version-0.6.46-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.17.0](https://img.shields.io/badge/AppVersion-1.17.0-informational?style=flat-square) +![Version: 0.6.47](https://img.shields.io/badge/Version-0.6.47-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.17.0](https://img.shields.io/badge/AppVersion-1.17.0-informational?style=flat-square) An app-of-apps Helm chart that allows for flexible deployment of resources that support Gen3 From b1589eb3d34ca689935586ee1dbe9434ed475e69 Mon Sep 17 00:00:00 2001 From: mark xiao Date: Wed, 5 Aug 2026 09:28:41 -0500 Subject: [PATCH 172/196] update --- helm/gen3-embeddings/Chart.yaml | 2 +- helm/gen3-embeddings/README.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/helm/gen3-embeddings/Chart.yaml b/helm/gen3-embeddings/Chart.yaml index 0f565b1d5..ea96b9bd3 100644 --- a/helm/gen3-embeddings/Chart.yaml +++ b/helm/gen3-embeddings/Chart.yaml @@ -24,7 +24,7 @@ version: 0.1.0 appVersion: "main" dependencies: - name: common - version: 0.1.35 + version: 0.1.38 repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/gen3-embeddings/README.md b/helm/gen3-embeddings/README.md index 60911de7a..5e46b37f1 100644 --- a/helm/gen3-embeddings/README.md +++ b/helm/gen3-embeddings/README.md @@ -8,7 +8,7 @@ A Helm chart for Kubernetes | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.35 | +| file://../common | common | 0.1.38 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | ## Values From e3ec67a8511e6cf9cf90041f84550f501b1414ec Mon Sep 17 00:00:00 2001 From: mark xiao Date: Wed, 5 Aug 2026 10:10:49 -0500 Subject: [PATCH 173/196] version bump --- helm/access-backend/Chart.yaml | 2 +- helm/access-backend/README.md | 2 +- helm/ambassador/Chart.yaml | 2 +- helm/ambassador/README.md | 2 +- helm/arborist/Chart.yaml | 2 +- helm/arborist/README.md | 2 +- helm/argo-wrapper/Chart.yaml | 2 +- helm/argo-wrapper/README.md | 2 +- helm/audit/Chart.yaml | 2 +- helm/audit/README.md | 2 +- helm/aws-es-proxy/Chart.yaml | 2 +- helm/aws-es-proxy/README.md | 2 +- helm/aws-sigv4-proxy/Chart.yaml | 2 +- helm/aws-sigv4-proxy/README.md | 2 +- helm/cedar/Chart.yaml | 2 +- helm/cedar/README.md | 2 +- helm/cohort-middleware/Chart.yaml | 2 +- helm/cohort-middleware/README.md | 2 +- helm/common/Chart.yaml | 2 +- helm/common/README.md | 2 +- helm/common/templates/_db_setup_job.tpl | 1 + helm/dashboard/Chart.yaml | 2 +- helm/dashboard/README.md | 2 +- helm/data-upload-cron/Chart.yaml | 2 +- helm/data-upload-cron/README.md | 2 +- helm/datareplicate/Chart.yaml | 2 +- helm/datareplicate/README.md | 2 +- helm/dicom-server/Chart.yaml | 2 +- helm/dicom-server/README.md | 2 +- helm/embedding-management-service/Chart.yaml | 2 +- helm/embedding-management-service/README.md | 2 +- helm/fence/Chart.yaml | 4 ++-- helm/fence/README.md | 4 ++-- helm/frontend-framework/Chart.yaml | 2 +- helm/frontend-framework/README.md | 2 +- helm/funnel/Chart.yaml | 2 +- helm/funnel/README.md | 2 +- helm/gen3-analysis/Chart.yaml | 2 +- helm/gen3-analysis/README.md | 2 +- helm/gen3-embeddings/Chart.yaml | 4 ++-- helm/gen3-embeddings/README.md | 4 ++-- helm/gen3-user-data-library/Chart.yaml | 2 +- helm/gen3-user-data-library/README.md | 2 +- helm/gen3-workflow/Chart.yaml | 2 +- helm/gen3-workflow/README.md | 2 +- helm/gen3/Chart.yaml | 10 +++++----- helm/gen3/README.md | 10 +++++----- helm/guppy/Chart.yaml | 2 +- helm/guppy/README.md | 2 +- helm/hatchery/Chart.yaml | 2 +- helm/hatchery/README.md | 2 +- helm/indexd/Chart.yaml | 2 +- helm/indexd/README.md | 2 +- helm/jeg/Chart.yaml | 2 +- helm/jeg/README.md | 2 +- helm/manifestservice/Chart.yaml | 2 +- helm/manifestservice/README.md | 2 +- helm/metadata/Chart.yaml | 2 +- helm/metadata/README.md | 2 +- helm/ohdsi-webapi/Chart.yaml | 2 +- helm/ohdsi-webapi/README.md | 2 +- helm/ohif-viewer/Chart.yaml | 2 +- helm/ohif-viewer/README.md | 2 +- helm/orthanc/Chart.yaml | 2 +- helm/orthanc/README.md | 2 +- helm/peregrine/Chart.yaml | 2 +- helm/peregrine/README.md | 2 +- helm/portal/Chart.yaml | 2 +- helm/portal/README.md | 2 +- helm/requestor/Chart.yaml | 2 +- helm/requestor/README.md | 2 +- helm/revproxy/Chart.yaml | 4 ++-- helm/revproxy/README.md | 4 ++-- helm/sheepdog/Chart.yaml | 2 +- helm/sheepdog/README.md | 2 +- helm/sower/Chart.yaml | 2 +- helm/sower/README.md | 2 +- helm/ssjdispatcher/Chart.yaml | 2 +- helm/ssjdispatcher/README.md | 2 +- helm/vectis-overlays/Chart.yaml | 2 +- helm/vectis-overlays/README.md | 2 +- helm/workspace-proxy/Chart.yaml | 2 +- helm/workspace-proxy/README.md | 2 +- helm/wts/Chart.yaml | 2 +- helm/wts/README.md | 2 +- helm/zendesk-wrapper/Chart.yaml | 2 +- helm/zendesk-wrapper/README.md | 2 +- 87 files changed, 101 insertions(+), 100 deletions(-) diff --git a/helm/access-backend/Chart.yaml b/helm/access-backend/Chart.yaml index ed6b5ee8d..802c585aa 100644 --- a/helm/access-backend/Chart.yaml +++ b/helm/access-backend/Chart.yaml @@ -25,5 +25,5 @@ appVersion: "1.6.1" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common diff --git a/helm/access-backend/README.md b/helm/access-backend/README.md index 803ef603e..35614f267 100644 --- a/helm/access-backend/README.md +++ b/helm/access-backend/README.md @@ -8,7 +8,7 @@ A Helm chart for Kubernetes | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | ## Values diff --git a/helm/ambassador/Chart.yaml b/helm/ambassador/Chart.yaml index f00cf59ae..8934b3f4e 100644 --- a/helm/ambassador/Chart.yaml +++ b/helm/ambassador/Chart.yaml @@ -25,5 +25,5 @@ appVersion: "1.4.2" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common diff --git a/helm/ambassador/README.md b/helm/ambassador/README.md index 370aa3b2e..8531c9bae 100644 --- a/helm/ambassador/README.md +++ b/helm/ambassador/README.md @@ -8,7 +8,7 @@ A Helm chart for deploying ambassador for gen3 | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | ## Values diff --git a/helm/arborist/Chart.yaml b/helm/arborist/Chart.yaml index c7e2935d8..8f8de4334 100644 --- a/helm/arborist/Chart.yaml +++ b/helm/arborist/Chart.yaml @@ -25,7 +25,7 @@ appVersion: "master" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/arborist/README.md b/helm/arborist/README.md index 889dfb6fe..c00e9ab8b 100644 --- a/helm/arborist/README.md +++ b/helm/arborist/README.md @@ -8,7 +8,7 @@ A Helm chart for gen3 arborist | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | ## Values diff --git a/helm/argo-wrapper/Chart.yaml b/helm/argo-wrapper/Chart.yaml index f92e708d4..b4ed620f0 100644 --- a/helm/argo-wrapper/Chart.yaml +++ b/helm/argo-wrapper/Chart.yaml @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common diff --git a/helm/argo-wrapper/README.md b/helm/argo-wrapper/README.md index 82d62a70b..cb3369c44 100644 --- a/helm/argo-wrapper/README.md +++ b/helm/argo-wrapper/README.md @@ -8,7 +8,7 @@ A Helm chart for gen3 Argo Wrapper Service | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | ## Values diff --git a/helm/audit/Chart.yaml b/helm/audit/Chart.yaml index 7630c13f1..d494a6e63 100644 --- a/helm/audit/Chart.yaml +++ b/helm/audit/Chart.yaml @@ -24,7 +24,7 @@ appVersion: "master" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/audit/README.md b/helm/audit/README.md index d0fc1786f..94ec78b3d 100644 --- a/helm/audit/README.md +++ b/helm/audit/README.md @@ -8,7 +8,7 @@ A Helm chart for Kubernetes | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | ## Values diff --git a/helm/aws-es-proxy/Chart.yaml b/helm/aws-es-proxy/Chart.yaml index 09bc48ac0..043a5d158 100644 --- a/helm/aws-es-proxy/Chart.yaml +++ b/helm/aws-es-proxy/Chart.yaml @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common diff --git a/helm/aws-es-proxy/README.md b/helm/aws-es-proxy/README.md index eb7f1c4b6..a64b5bdd4 100644 --- a/helm/aws-es-proxy/README.md +++ b/helm/aws-es-proxy/README.md @@ -8,7 +8,7 @@ A Helm chart for AWS ES Proxy Service for gen3 | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | ## Values diff --git a/helm/aws-sigv4-proxy/Chart.yaml b/helm/aws-sigv4-proxy/Chart.yaml index 6b2fb249f..36c06571b 100644 --- a/helm/aws-sigv4-proxy/Chart.yaml +++ b/helm/aws-sigv4-proxy/Chart.yaml @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common diff --git a/helm/aws-sigv4-proxy/README.md b/helm/aws-sigv4-proxy/README.md index cc7b9213d..fb0797bf0 100644 --- a/helm/aws-sigv4-proxy/README.md +++ b/helm/aws-sigv4-proxy/README.md @@ -8,7 +8,7 @@ A Helm chart for AWS ES Proxy Service for gen3 | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | ## Values diff --git a/helm/cedar/Chart.yaml b/helm/cedar/Chart.yaml index e6ef00600..72d5dc48b 100644 --- a/helm/cedar/Chart.yaml +++ b/helm/cedar/Chart.yaml @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common diff --git a/helm/cedar/README.md b/helm/cedar/README.md index e16124399..2b31cbbb6 100644 --- a/helm/cedar/README.md +++ b/helm/cedar/README.md @@ -8,7 +8,7 @@ A Helm chart for gen3 cedar wrapper | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | ## Values diff --git a/helm/cohort-middleware/Chart.yaml b/helm/cohort-middleware/Chart.yaml index 250941f1c..47be6b27e 100644 --- a/helm/cohort-middleware/Chart.yaml +++ b/helm/cohort-middleware/Chart.yaml @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common diff --git a/helm/cohort-middleware/README.md b/helm/cohort-middleware/README.md index 4e7c9abd1..3863f42f6 100644 --- a/helm/cohort-middleware/README.md +++ b/helm/cohort-middleware/README.md @@ -8,7 +8,7 @@ A Helm chart for gen3 cohort-middleware | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | ## Values diff --git a/helm/common/Chart.yaml b/helm/common/Chart.yaml index 3dfd2f1cc..7b5af7e44 100644 --- a/helm/common/Chart.yaml +++ b/helm/common/Chart.yaml @@ -15,7 +15,7 @@ type: library # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.38 +version: 0.1.39 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/common/README.md b/helm/common/README.md index b48fb0ddf..67cfc57dc 100644 --- a/helm/common/README.md +++ b/helm/common/README.md @@ -1,6 +1,6 @@ # common -![Version: 0.1.38](https://img.shields.io/badge/Version-0.1.38-informational?style=flat-square) ![Type: library](https://img.shields.io/badge/Type-library-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.39](https://img.shields.io/badge/Version-0.1.39-informational?style=flat-square) ![Type: library](https://img.shields.io/badge/Type-library-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for provisioning databases in gen3 diff --git a/helm/common/templates/_db_setup_job.tpl b/helm/common/templates/_db_setup_job.tpl index 00f4143fd..395721688 100644 --- a/helm/common/templates/_db_setup_job.tpl +++ b/helm/common/templates/_db_setup_job.tpl @@ -164,6 +164,7 @@ spec: psql -c "GRANT ALL PRIVILEGES ON DATABASE \"$SERVICE_PGDB\" TO \"$SERVICE_PGUSER\";" psql -d $SERVICE_PGDB -c "ALTER SCHEMA public OWNER TO \"$SERVICE_PGUSER\";" psql -d $SERVICE_PGDB -c "GRANT ALL ON SCHEMA public TO \"$SERVICE_PGUSER\";" + psql -d $SERVICE_PGDB -c "GRANT ALL ON ALL TABLES IN SCHEMA public TO \"$SERVICE_PGUSER\";" psql -d $SERVICE_PGDB -c "ALTER DEFAULT PRIVILEGES IN SCHEMA public GRANT ALL ON TABLES TO \"$SERVICE_PGUSER\";" psql -d $SERVICE_PGDB -c "ALTER ROLE \"$SERVICE_PGUSER\" WITH LOGIN;" diff --git a/helm/dashboard/Chart.yaml b/helm/dashboard/Chart.yaml index 3273f5320..5488da63c 100644 --- a/helm/dashboard/Chart.yaml +++ b/helm/dashboard/Chart.yaml @@ -25,5 +25,5 @@ appVersion: "1.16.0" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common diff --git a/helm/dashboard/README.md b/helm/dashboard/README.md index d6019d2e0..8c9a4d388 100644 --- a/helm/dashboard/README.md +++ b/helm/dashboard/README.md @@ -8,7 +8,7 @@ A Helm chart for Kubernetes | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | ## Values diff --git a/helm/data-upload-cron/Chart.yaml b/helm/data-upload-cron/Chart.yaml index 34423931b..280b9f8d2 100644 --- a/helm/data-upload-cron/Chart.yaml +++ b/helm/data-upload-cron/Chart.yaml @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common diff --git a/helm/data-upload-cron/README.md b/helm/data-upload-cron/README.md index 45a39bc5d..49b32ab76 100644 --- a/helm/data-upload-cron/README.md +++ b/helm/data-upload-cron/README.md @@ -8,7 +8,7 @@ A Helm chart for the data upload cronjob | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | ## Values diff --git a/helm/datareplicate/Chart.yaml b/helm/datareplicate/Chart.yaml index 93c1d56eb..f784d42cf 100644 --- a/helm/datareplicate/Chart.yaml +++ b/helm/datareplicate/Chart.yaml @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common diff --git a/helm/datareplicate/README.md b/helm/datareplicate/README.md index a97ce6eb8..17175cd77 100644 --- a/helm/datareplicate/README.md +++ b/helm/datareplicate/README.md @@ -8,7 +8,7 @@ A Helm chart for gen3 datareplicate | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | ## Values diff --git a/helm/dicom-server/Chart.yaml b/helm/dicom-server/Chart.yaml index 148be68e9..32d680baa 100644 --- a/helm/dicom-server/Chart.yaml +++ b/helm/dicom-server/Chart.yaml @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common diff --git a/helm/dicom-server/README.md b/helm/dicom-server/README.md index 97b8ea659..1e1319bf9 100644 --- a/helm/dicom-server/README.md +++ b/helm/dicom-server/README.md @@ -8,7 +8,7 @@ A Helm chart for gen3 Dicom Server | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | ## Values diff --git a/helm/embedding-management-service/Chart.yaml b/helm/embedding-management-service/Chart.yaml index 6e17d0aa5..88f0a598f 100644 --- a/helm/embedding-management-service/Chart.yaml +++ b/helm/embedding-management-service/Chart.yaml @@ -25,5 +25,5 @@ appVersion: "1.16.0" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common diff --git a/helm/embedding-management-service/README.md b/helm/embedding-management-service/README.md index f23c3c412..d6fd5d32c 100644 --- a/helm/embedding-management-service/README.md +++ b/helm/embedding-management-service/README.md @@ -8,7 +8,7 @@ A Helm chart for Kubernetes | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | ## Values diff --git a/helm/fence/Chart.yaml b/helm/fence/Chart.yaml index 29e19a6af..bb8147209 100644 --- a/helm/fence/Chart.yaml +++ b/helm/fence/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.81 +version: 0.1.82 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -24,7 +24,7 @@ appVersion: "master" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/fence/README.md b/helm/fence/README.md index 6251a0962..5f51dd27f 100644 --- a/helm/fence/README.md +++ b/helm/fence/README.md @@ -1,6 +1,6 @@ # fence -![Version: 0.1.81](https://img.shields.io/badge/Version-0.1.81-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.82](https://img.shields.io/badge/Version-0.1.82-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Fence @@ -8,7 +8,7 @@ A Helm chart for gen3 Fence | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | ## Values diff --git a/helm/frontend-framework/Chart.yaml b/helm/frontend-framework/Chart.yaml index cb6c0f6eb..cea0118d1 100644 --- a/helm/frontend-framework/Chart.yaml +++ b/helm/frontend-framework/Chart.yaml @@ -25,5 +25,5 @@ appVersion: "develop" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common diff --git a/helm/frontend-framework/README.md b/helm/frontend-framework/README.md index eaaef8f41..2088256cb 100644 --- a/helm/frontend-framework/README.md +++ b/helm/frontend-framework/README.md @@ -8,7 +8,7 @@ A Helm chart for the gen3 frontend framework | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | ## Values diff --git a/helm/funnel/Chart.yaml b/helm/funnel/Chart.yaml index 1e80bd0fd..c31c6876f 100644 --- a/helm/funnel/Chart.yaml +++ b/helm/funnel/Chart.yaml @@ -24,5 +24,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common diff --git a/helm/funnel/README.md b/helm/funnel/README.md index bafc18a0b..8da1c8de6 100644 --- a/helm/funnel/README.md +++ b/helm/funnel/README.md @@ -8,7 +8,7 @@ A Helm chart for Kubernetes | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | ## Values diff --git a/helm/gen3-analysis/Chart.yaml b/helm/gen3-analysis/Chart.yaml index f4f850ca6..810c76d99 100644 --- a/helm/gen3-analysis/Chart.yaml +++ b/helm/gen3-analysis/Chart.yaml @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common diff --git a/helm/gen3-analysis/README.md b/helm/gen3-analysis/README.md index 2c3fdbf11..502577801 100644 --- a/helm/gen3-analysis/README.md +++ b/helm/gen3-analysis/README.md @@ -8,7 +8,7 @@ A Helm chart for gen3 gen3-analysis Service | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | ## Values diff --git a/helm/gen3-embeddings/Chart.yaml b/helm/gen3-embeddings/Chart.yaml index ea96b9bd3..f53f66110 100644 --- a/helm/gen3-embeddings/Chart.yaml +++ b/helm/gen3-embeddings/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.0 +version: 0.1.1 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -24,7 +24,7 @@ version: 0.1.0 appVersion: "main" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/gen3-embeddings/README.md b/helm/gen3-embeddings/README.md index 5e46b37f1..87b96b6cb 100644 --- a/helm/gen3-embeddings/README.md +++ b/helm/gen3-embeddings/README.md @@ -1,6 +1,6 @@ # gen3-embeddings -![Version: 0.1.0](https://img.shields.io/badge/Version-0.1.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: main](https://img.shields.io/badge/AppVersion-main-informational?style=flat-square) +![Version: 0.1.1](https://img.shields.io/badge/Version-0.1.1-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: main](https://img.shields.io/badge/AppVersion-main-informational?style=flat-square) A Helm chart for Kubernetes @@ -8,7 +8,7 @@ A Helm chart for Kubernetes | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | ## Values diff --git a/helm/gen3-user-data-library/Chart.yaml b/helm/gen3-user-data-library/Chart.yaml index 7694a491c..6c27417da 100644 --- a/helm/gen3-user-data-library/Chart.yaml +++ b/helm/gen3-user-data-library/Chart.yaml @@ -24,7 +24,7 @@ version: 0.1.17 appVersion: "main" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/gen3-user-data-library/README.md b/helm/gen3-user-data-library/README.md index 31820a4b8..60c8cea86 100644 --- a/helm/gen3-user-data-library/README.md +++ b/helm/gen3-user-data-library/README.md @@ -8,7 +8,7 @@ A Helm chart for Kubernetes | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | ## Values diff --git a/helm/gen3-workflow/Chart.yaml b/helm/gen3-workflow/Chart.yaml index 7be836540..1b40af09e 100644 --- a/helm/gen3-workflow/Chart.yaml +++ b/helm/gen3-workflow/Chart.yaml @@ -24,5 +24,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common diff --git a/helm/gen3-workflow/README.md b/helm/gen3-workflow/README.md index 98a46d989..6f79ccad9 100644 --- a/helm/gen3-workflow/README.md +++ b/helm/gen3-workflow/README.md @@ -8,7 +8,7 @@ A Helm chart for Kubernetes | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | ## Values diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index 924ebef4d..f42e6c4d8 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -41,7 +41,7 @@ dependencies: repository: "file://../cohort-middleware" condition: cohort-middleware.enabled - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common - name: dashboard version: 0.1.23 @@ -68,7 +68,7 @@ dependencies: repository: "file://../frontend-framework" condition: frontend-framework.enabled - name: fence - version: 0.1.81 + version: 0.1.82 repository: "file://../fence" condition: fence.enabled - name: funnel @@ -76,7 +76,7 @@ dependencies: repository: "file://../funnel" condition: gen3-workflow.enabled - name: gen3-embeddings - version: 0.1.0 + version: 0.1.1 repository: "file://../gen3-embeddings" condition: gen3-embeddings.enabled - name: gen3-user-data-library @@ -120,7 +120,7 @@ dependencies: repository: "file://../requestor" condition: requestor.enabled - name: revproxy - version: 0.1.68 + version: 0.1.69 repository: "file://../revproxy" condition: revproxy.enabled - name: sheepdog @@ -217,7 +217,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.78 +version: 0.3.79 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index e0775b965..4c3d4ff2d 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,6 +1,6 @@ # gen3 -![Version: 0.3.78](https://img.shields.io/badge/Version-0.3.78-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.3.79](https://img.shields.io/badge/Version-0.3.79-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons @@ -27,18 +27,18 @@ Helm chart to deploy Gen3 Data Commons | file://../aws-sigv4-proxy | aws-sigv4-proxy | 0.1.4 | | file://../cedar | cedar | 0.1.28 | | file://../cohort-middleware | cohort-middleware | 0.1.25 | -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | | file://../dashboard | dashboard | 0.1.23 | | file://../data-upload-cron | data-upload-cron | 0.1.8 | | file://../datareplicate | datareplicate | 0.1.23 | | file://../dicom-server | dicom-server | 0.1.33 | | file://../embedding-management-service | embedding-management-service | 0.1.10 | | file://../etl | etl | 0.1.24 | -| file://../fence | fence | 0.1.81 | +| file://../fence | fence | 0.1.82 | | file://../frontend-framework | frontend-framework | 0.1.31 | | file://../funnel | funnel | 0.1.31 | | file://../gen3-analysis | gen3-analysis | 0.1.14 | -| file://../gen3-embeddings | gen3-embeddings | 0.1.0 | +| file://../gen3-embeddings | gen3-embeddings | 0.1.1 | | file://../gen3-network-policies | gen3-network-policies | 0.1.4 | | file://../gen3-user-data-library | gen3-user-data-library | 0.1.17 | | file://../gen3-workflow | gen3-workflow | 0.1.28 | @@ -56,7 +56,7 @@ Helm chart to deploy Gen3 Data Commons | file://../peregrine | peregrine | 0.1.44 | | file://../portal | portal | 0.1.62 | | file://../requestor | requestor | 0.1.37 | -| file://../revproxy | revproxy | 0.1.68 | +| file://../revproxy | revproxy | 0.1.69 | | file://../sheepdog | sheepdog | 0.1.46 | | file://../sower | sower | 0.1.48 | | file://../ssjdispatcher | ssjdispatcher | 0.1.49 | diff --git a/helm/guppy/Chart.yaml b/helm/guppy/Chart.yaml index 0efebdf1c..322ae90b1 100644 --- a/helm/guppy/Chart.yaml +++ b/helm/guppy/Chart.yaml @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common diff --git a/helm/guppy/README.md b/helm/guppy/README.md index 33ebe174c..bdaf3c64b 100644 --- a/helm/guppy/README.md +++ b/helm/guppy/README.md @@ -8,7 +8,7 @@ A Helm chart for gen3 Guppy Service | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | ## Values diff --git a/helm/hatchery/Chart.yaml b/helm/hatchery/Chart.yaml index bb43e5f59..c7e7fdaaa 100644 --- a/helm/hatchery/Chart.yaml +++ b/helm/hatchery/Chart.yaml @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common diff --git a/helm/hatchery/README.md b/helm/hatchery/README.md index 467281767..ed6a98539 100644 --- a/helm/hatchery/README.md +++ b/helm/hatchery/README.md @@ -8,7 +8,7 @@ A Helm chart for gen3 Hatchery | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | ## Values diff --git a/helm/indexd/Chart.yaml b/helm/indexd/Chart.yaml index a4cc5a487..cab96517b 100644 --- a/helm/indexd/Chart.yaml +++ b/helm/indexd/Chart.yaml @@ -25,7 +25,7 @@ appVersion: "master" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/indexd/README.md b/helm/indexd/README.md index 4525e81a5..41696a827 100644 --- a/helm/indexd/README.md +++ b/helm/indexd/README.md @@ -8,7 +8,7 @@ A Helm chart for gen3 indexd | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | ## Values diff --git a/helm/jeg/Chart.yaml b/helm/jeg/Chart.yaml index 1a6c63308..dba67434c 100644 --- a/helm/jeg/Chart.yaml +++ b/helm/jeg/Chart.yaml @@ -10,5 +10,5 @@ appVersion: "3.2.3" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common diff --git a/helm/jeg/README.md b/helm/jeg/README.md index 3491f1b29..8559690ba 100644 --- a/helm/jeg/README.md +++ b/helm/jeg/README.md @@ -8,7 +8,7 @@ Jupyter Enterprise Gateway for gen3 vectis workspaces. Launches ephemeral kernel | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | ## Values diff --git a/helm/manifestservice/Chart.yaml b/helm/manifestservice/Chart.yaml index ede1c8f11..4008c3678 100644 --- a/helm/manifestservice/Chart.yaml +++ b/helm/manifestservice/Chart.yaml @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common diff --git a/helm/manifestservice/README.md b/helm/manifestservice/README.md index ead44689e..f44f75150 100644 --- a/helm/manifestservice/README.md +++ b/helm/manifestservice/README.md @@ -8,7 +8,7 @@ A Helm chart for Kubernetes | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | ## Values diff --git a/helm/metadata/Chart.yaml b/helm/metadata/Chart.yaml index 4a34ab9d4..19a2b96ae 100644 --- a/helm/metadata/Chart.yaml +++ b/helm/metadata/Chart.yaml @@ -25,7 +25,7 @@ appVersion: "master" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/metadata/README.md b/helm/metadata/README.md index f06dd7567..d1de6fff5 100644 --- a/helm/metadata/README.md +++ b/helm/metadata/README.md @@ -8,7 +8,7 @@ A Helm chart for gen3 Metadata Service | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | | https://helm.elastic.co | elasticsearch | 7.17.1 | diff --git a/helm/ohdsi-webapi/Chart.yaml b/helm/ohdsi-webapi/Chart.yaml index afa082a61..9dfe27b1d 100644 --- a/helm/ohdsi-webapi/Chart.yaml +++ b/helm/ohdsi-webapi/Chart.yaml @@ -25,7 +25,7 @@ appVersion: "2.15.0" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/ohdsi-webapi/README.md b/helm/ohdsi-webapi/README.md index fbaddc8ba..312ceda7b 100644 --- a/helm/ohdsi-webapi/README.md +++ b/helm/ohdsi-webapi/README.md @@ -8,7 +8,7 @@ A Helm chart for OHDSI WebAPI | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | ## Values diff --git a/helm/ohif-viewer/Chart.yaml b/helm/ohif-viewer/Chart.yaml index a89d13a7e..4f61bea1a 100644 --- a/helm/ohif-viewer/Chart.yaml +++ b/helm/ohif-viewer/Chart.yaml @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common diff --git a/helm/ohif-viewer/README.md b/helm/ohif-viewer/README.md index 7a396b6d7..f6939b383 100644 --- a/helm/ohif-viewer/README.md +++ b/helm/ohif-viewer/README.md @@ -8,7 +8,7 @@ A Helm chart for gen3 Ohif Viewer | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | ## Values diff --git a/helm/orthanc/Chart.yaml b/helm/orthanc/Chart.yaml index d93626c27..2acb46f50 100644 --- a/helm/orthanc/Chart.yaml +++ b/helm/orthanc/Chart.yaml @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common diff --git a/helm/orthanc/README.md b/helm/orthanc/README.md index fd3bda1cc..2d633ef97 100644 --- a/helm/orthanc/README.md +++ b/helm/orthanc/README.md @@ -8,7 +8,7 @@ A Helm chart for gen3 Dicom Server | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | ## Values diff --git a/helm/peregrine/Chart.yaml b/helm/peregrine/Chart.yaml index 2cede462c..2edc618c2 100644 --- a/helm/peregrine/Chart.yaml +++ b/helm/peregrine/Chart.yaml @@ -25,7 +25,7 @@ appVersion: "master" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/peregrine/README.md b/helm/peregrine/README.md index 74a8d38e0..beee8c40a 100644 --- a/helm/peregrine/README.md +++ b/helm/peregrine/README.md @@ -8,7 +8,7 @@ A Helm chart for gen3 Peregrine service | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | ## Values diff --git a/helm/portal/Chart.yaml b/helm/portal/Chart.yaml index 138282dc4..c6d2b8510 100644 --- a/helm/portal/Chart.yaml +++ b/helm/portal/Chart.yaml @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common diff --git a/helm/portal/README.md b/helm/portal/README.md index cc9de621d..9ae365a99 100644 --- a/helm/portal/README.md +++ b/helm/portal/README.md @@ -8,7 +8,7 @@ A Helm chart for gen3 data-portal | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | ## Values diff --git a/helm/requestor/Chart.yaml b/helm/requestor/Chart.yaml index 6d6090a1d..97cb7801f 100644 --- a/helm/requestor/Chart.yaml +++ b/helm/requestor/Chart.yaml @@ -25,7 +25,7 @@ appVersion: "master" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/requestor/README.md b/helm/requestor/README.md index 5a7be8f8b..53c21963f 100644 --- a/helm/requestor/README.md +++ b/helm/requestor/README.md @@ -8,7 +8,7 @@ A Helm chart for gen3 Requestor Service | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | ## Values diff --git a/helm/revproxy/Chart.yaml b/helm/revproxy/Chart.yaml index fba5a5cbc..421b1467c 100644 --- a/helm/revproxy/Chart.yaml +++ b/helm/revproxy/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.68 +version: 0.1.69 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common diff --git a/helm/revproxy/README.md b/helm/revproxy/README.md index 9f57b5af1..4496ebc16 100644 --- a/helm/revproxy/README.md +++ b/helm/revproxy/README.md @@ -1,6 +1,6 @@ # revproxy -![Version: 0.1.68](https://img.shields.io/badge/Version-0.1.68-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.69](https://img.shields.io/badge/Version-0.1.69-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 revproxy @@ -8,7 +8,7 @@ A Helm chart for gen3 revproxy | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | ## Values diff --git a/helm/sheepdog/Chart.yaml b/helm/sheepdog/Chart.yaml index 947523fcb..e19549d2a 100644 --- a/helm/sheepdog/Chart.yaml +++ b/helm/sheepdog/Chart.yaml @@ -25,7 +25,7 @@ appVersion: "master" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/sheepdog/README.md b/helm/sheepdog/README.md index 8566e7fd1..52495a83a 100644 --- a/helm/sheepdog/README.md +++ b/helm/sheepdog/README.md @@ -8,7 +8,7 @@ A Helm chart for gen3 Sheepdog Service | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | ## Values diff --git a/helm/sower/Chart.yaml b/helm/sower/Chart.yaml index 77a508b11..7987b2ae0 100644 --- a/helm/sower/Chart.yaml +++ b/helm/sower/Chart.yaml @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common diff --git a/helm/sower/README.md b/helm/sower/README.md index 2d63351ee..650ce9ed4 100644 --- a/helm/sower/README.md +++ b/helm/sower/README.md @@ -8,7 +8,7 @@ A Helm chart for gen3 sower | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | ## Values diff --git a/helm/ssjdispatcher/Chart.yaml b/helm/ssjdispatcher/Chart.yaml index 42e293b7a..276483315 100644 --- a/helm/ssjdispatcher/Chart.yaml +++ b/helm/ssjdispatcher/Chart.yaml @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common diff --git a/helm/ssjdispatcher/README.md b/helm/ssjdispatcher/README.md index fa2ba9cbd..415f1c209 100644 --- a/helm/ssjdispatcher/README.md +++ b/helm/ssjdispatcher/README.md @@ -8,7 +8,7 @@ A Helm chart for gen3 ssjdispatcher | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | ## Values diff --git a/helm/vectis-overlays/Chart.yaml b/helm/vectis-overlays/Chart.yaml index f54394788..2b764f03b 100644 --- a/helm/vectis-overlays/Chart.yaml +++ b/helm/vectis-overlays/Chart.yaml @@ -7,5 +7,5 @@ appVersion: "1.0" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common diff --git a/helm/vectis-overlays/README.md b/helm/vectis-overlays/README.md index 7cd448d11..1fd02e3b2 100644 --- a/helm/vectis-overlays/README.md +++ b/helm/vectis-overlays/README.md @@ -8,7 +8,7 @@ Vectis overlay API services (guppy-compat, siem, search-auth-proxy) | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | ## Values diff --git a/helm/workspace-proxy/Chart.yaml b/helm/workspace-proxy/Chart.yaml index b3ba0e68a..94e3cbf20 100644 --- a/helm/workspace-proxy/Chart.yaml +++ b/helm/workspace-proxy/Chart.yaml @@ -10,5 +10,5 @@ appVersion: "1.0" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common diff --git a/helm/workspace-proxy/README.md b/helm/workspace-proxy/README.md index c78d16322..0862edcc2 100644 --- a/helm/workspace-proxy/README.md +++ b/helm/workspace-proxy/README.md @@ -8,7 +8,7 @@ Per-user workspace HTTP/WebSocket router for gen3 vectis. Replaces Emissary/Amba | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | ## Values diff --git a/helm/wts/Chart.yaml b/helm/wts/Chart.yaml index d1f7554d6..c4e55d392 100644 --- a/helm/wts/Chart.yaml +++ b/helm/wts/Chart.yaml @@ -25,7 +25,7 @@ appVersion: "master" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/wts/README.md b/helm/wts/README.md index 4c52af331..56e0c1a08 100644 --- a/helm/wts/README.md +++ b/helm/wts/README.md @@ -8,7 +8,7 @@ A Helm chart for gen3 workspace token service | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | ## Values diff --git a/helm/zendesk-wrapper/Chart.yaml b/helm/zendesk-wrapper/Chart.yaml index 6f6983ff8..4fb376b05 100644 --- a/helm/zendesk-wrapper/Chart.yaml +++ b/helm/zendesk-wrapper/Chart.yaml @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.38 + version: 0.1.39 repository: file://../common diff --git a/helm/zendesk-wrapper/README.md b/helm/zendesk-wrapper/README.md index 441c13509..24657633d 100644 --- a/helm/zendesk-wrapper/README.md +++ b/helm/zendesk-wrapper/README.md @@ -8,7 +8,7 @@ A Helm chart for gen3 Zendesk Wrapper Service | Repository | Name | Version | |------------|------|---------| -| file://../common | common | 0.1.38 | +| file://../common | common | 0.1.39 | ## Values From cf02da52cbcda9b29a1c34aeb07575e5a61422cb Mon Sep 17 00:00:00 2001 From: mark xiao Date: Wed, 5 Aug 2026 14:02:12 -0500 Subject: [PATCH 174/196] bump more versions --- helm/access-backend/Chart.yaml | 2 +- helm/access-backend/README.md | 2 +- helm/ambassador/Chart.yaml | 2 +- helm/ambassador/README.md | 2 +- helm/arborist/Chart.yaml | 2 +- helm/arborist/README.md | 2 +- helm/argo-wrapper/Chart.yaml | 2 +- helm/argo-wrapper/README.md | 2 +- helm/audit/Chart.yaml | 2 +- helm/audit/README.md | 2 +- helm/aws-es-proxy/Chart.yaml | 2 +- helm/aws-es-proxy/README.md | 2 +- helm/aws-sigv4-proxy/Chart.yaml | 2 +- helm/aws-sigv4-proxy/README.md | 2 +- helm/cedar/Chart.yaml | 2 +- helm/cedar/README.md | 2 +- helm/cohort-middleware/Chart.yaml | 2 +- helm/cohort-middleware/README.md | 2 +- helm/dashboard/Chart.yaml | 2 +- helm/dashboard/README.md | 2 +- helm/data-upload-cron/Chart.yaml | 2 +- helm/data-upload-cron/README.md | 2 +- helm/datareplicate/Chart.yaml | 2 +- helm/datareplicate/README.md | 2 +- helm/dicom-server/Chart.yaml | 2 +- helm/dicom-server/README.md | 2 +- helm/embedding-management-service/Chart.yaml | 2 +- helm/embedding-management-service/README.md | 2 +- helm/frontend-framework/Chart.yaml | 2 +- helm/frontend-framework/README.md | 2 +- helm/funnel/Chart.yaml | 2 +- helm/funnel/README.md | 2 +- helm/gen3-analysis/Chart.yaml | 2 +- helm/gen3-analysis/README.md | 2 +- helm/gen3-user-data-library/Chart.yaml | 2 +- helm/gen3-user-data-library/README.md | 2 +- helm/gen3-workflow/Chart.yaml | 2 +- helm/gen3-workflow/README.md | 2 +- helm/gen3/Chart.yaml | 76 ++++++++++---------- helm/gen3/README.md | 76 ++++++++++---------- helm/guppy/Chart.yaml | 2 +- helm/guppy/README.md | 2 +- helm/hatchery/Chart.yaml | 2 +- helm/hatchery/README.md | 2 +- helm/indexd/Chart.yaml | 2 +- helm/indexd/README.md | 2 +- helm/jeg/Chart.yaml | 2 +- helm/jeg/README.md | 2 +- helm/manifestservice/Chart.yaml | 2 +- helm/manifestservice/README.md | 2 +- helm/metadata/Chart.yaml | 2 +- helm/metadata/README.md | 2 +- helm/ohdsi-webapi/Chart.yaml | 2 +- helm/ohdsi-webapi/README.md | 2 +- helm/ohif-viewer/Chart.yaml | 2 +- helm/ohif-viewer/README.md | 2 +- helm/orthanc/Chart.yaml | 2 +- helm/orthanc/README.md | 2 +- helm/peregrine/Chart.yaml | 2 +- helm/peregrine/README.md | 2 +- helm/portal/Chart.yaml | 2 +- helm/portal/README.md | 2 +- helm/requestor/Chart.yaml | 2 +- helm/requestor/README.md | 2 +- helm/sheepdog/Chart.yaml | 2 +- helm/sheepdog/README.md | 2 +- helm/sower/Chart.yaml | 2 +- helm/sower/README.md | 2 +- helm/ssjdispatcher/Chart.yaml | 2 +- helm/ssjdispatcher/README.md | 2 +- helm/vectis-overlays/Chart.yaml | 2 +- helm/vectis-overlays/README.md | 2 +- helm/workspace-proxy/Chart.yaml | 2 +- helm/workspace-proxy/README.md | 2 +- helm/wts/Chart.yaml | 2 +- helm/wts/README.md | 2 +- helm/zendesk-wrapper/Chart.yaml | 2 +- helm/zendesk-wrapper/README.md | 2 +- 78 files changed, 152 insertions(+), 152 deletions(-) diff --git a/helm/access-backend/Chart.yaml b/helm/access-backend/Chart.yaml index 802c585aa..94243d7b6 100644 --- a/helm/access-backend/Chart.yaml +++ b/helm/access-backend/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.22 +version: 0.1.23 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/access-backend/README.md b/helm/access-backend/README.md index 35614f267..e6fdd6cf5 100644 --- a/helm/access-backend/README.md +++ b/helm/access-backend/README.md @@ -1,6 +1,6 @@ # access-backend -![Version: 0.1.22](https://img.shields.io/badge/Version-0.1.22-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.6.1](https://img.shields.io/badge/AppVersion-1.6.1-informational?style=flat-square) +![Version: 0.1.23](https://img.shields.io/badge/Version-0.1.23-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.6.1](https://img.shields.io/badge/AppVersion-1.6.1-informational?style=flat-square) A Helm chart for Kubernetes diff --git a/helm/ambassador/Chart.yaml b/helm/ambassador/Chart.yaml index 8934b3f4e..d80843d6d 100644 --- a/helm/ambassador/Chart.yaml +++ b/helm/ambassador/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.39 +version: 0.1.40 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/ambassador/README.md b/helm/ambassador/README.md index 8531c9bae..2ec108d86 100644 --- a/helm/ambassador/README.md +++ b/helm/ambassador/README.md @@ -1,6 +1,6 @@ # ambassador -![Version: 0.1.39](https://img.shields.io/badge/Version-0.1.39-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.4.2](https://img.shields.io/badge/AppVersion-1.4.2-informational?style=flat-square) +![Version: 0.1.40](https://img.shields.io/badge/Version-0.1.40-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.4.2](https://img.shields.io/badge/AppVersion-1.4.2-informational?style=flat-square) A Helm chart for deploying ambassador for gen3 diff --git a/helm/arborist/Chart.yaml b/helm/arborist/Chart.yaml index 8f8de4334..03f6d5e8a 100644 --- a/helm/arborist/Chart.yaml +++ b/helm/arborist/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.36 +version: 0.1.37 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/arborist/README.md b/helm/arborist/README.md index c00e9ab8b..08111cbb9 100644 --- a/helm/arborist/README.md +++ b/helm/arborist/README.md @@ -1,6 +1,6 @@ # arborist -![Version: 0.1.36](https://img.shields.io/badge/Version-0.1.36-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.37](https://img.shields.io/badge/Version-0.1.37-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 arborist diff --git a/helm/argo-wrapper/Chart.yaml b/helm/argo-wrapper/Chart.yaml index b4ed620f0..1bb1fdb6c 100644 --- a/helm/argo-wrapper/Chart.yaml +++ b/helm/argo-wrapper/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.33 +version: 0.1.34 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/argo-wrapper/README.md b/helm/argo-wrapper/README.md index cb3369c44..aa172afca 100644 --- a/helm/argo-wrapper/README.md +++ b/helm/argo-wrapper/README.md @@ -1,6 +1,6 @@ # argo-wrapper -![Version: 0.1.33](https://img.shields.io/badge/Version-0.1.33-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.34](https://img.shields.io/badge/Version-0.1.34-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Argo Wrapper Service diff --git a/helm/audit/Chart.yaml b/helm/audit/Chart.yaml index d494a6e63..ae67e9a73 100644 --- a/helm/audit/Chart.yaml +++ b/helm/audit/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.46 +version: 0.1.47 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/audit/README.md b/helm/audit/README.md index 94ec78b3d..815530451 100644 --- a/helm/audit/README.md +++ b/helm/audit/README.md @@ -1,6 +1,6 @@ # audit -![Version: 0.1.46](https://img.shields.io/badge/Version-0.1.46-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.47](https://img.shields.io/badge/Version-0.1.47-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for Kubernetes diff --git a/helm/aws-es-proxy/Chart.yaml b/helm/aws-es-proxy/Chart.yaml index 043a5d158..1aaa10486 100644 --- a/helm/aws-es-proxy/Chart.yaml +++ b/helm/aws-es-proxy/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.44 +version: 0.1.45 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/aws-es-proxy/README.md b/helm/aws-es-proxy/README.md index a64b5bdd4..b274d8406 100644 --- a/helm/aws-es-proxy/README.md +++ b/helm/aws-es-proxy/README.md @@ -1,6 +1,6 @@ # aws-es-proxy -![Version: 0.1.44](https://img.shields.io/badge/Version-0.1.44-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.45](https://img.shields.io/badge/Version-0.1.45-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for AWS ES Proxy Service for gen3 diff --git a/helm/aws-sigv4-proxy/Chart.yaml b/helm/aws-sigv4-proxy/Chart.yaml index 36c06571b..6e706d725 100644 --- a/helm/aws-sigv4-proxy/Chart.yaml +++ b/helm/aws-sigv4-proxy/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.4 +version: 0.1.5 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/aws-sigv4-proxy/README.md b/helm/aws-sigv4-proxy/README.md index fb0797bf0..b988c88d1 100644 --- a/helm/aws-sigv4-proxy/README.md +++ b/helm/aws-sigv4-proxy/README.md @@ -1,6 +1,6 @@ # aws-sigv4-proxy -![Version: 0.1.4](https://img.shields.io/badge/Version-0.1.4-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.5](https://img.shields.io/badge/Version-0.1.5-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for AWS ES Proxy Service for gen3 diff --git a/helm/cedar/Chart.yaml b/helm/cedar/Chart.yaml index 72d5dc48b..d2af513f9 100644 --- a/helm/cedar/Chart.yaml +++ b/helm/cedar/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.28 +version: 0.1.29 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/cedar/README.md b/helm/cedar/README.md index 2b31cbbb6..ab2d69305 100644 --- a/helm/cedar/README.md +++ b/helm/cedar/README.md @@ -1,6 +1,6 @@ # cedar -![Version: 0.1.28](https://img.shields.io/badge/Version-0.1.28-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.29](https://img.shields.io/badge/Version-0.1.29-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 cedar wrapper diff --git a/helm/cohort-middleware/Chart.yaml b/helm/cohort-middleware/Chart.yaml index 47be6b27e..854d85d80 100644 --- a/helm/cohort-middleware/Chart.yaml +++ b/helm/cohort-middleware/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.25 +version: 0.1.26 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/cohort-middleware/README.md b/helm/cohort-middleware/README.md index 3863f42f6..269f3534f 100644 --- a/helm/cohort-middleware/README.md +++ b/helm/cohort-middleware/README.md @@ -1,6 +1,6 @@ # cohort-middleware -![Version: 0.1.25](https://img.shields.io/badge/Version-0.1.25-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.26](https://img.shields.io/badge/Version-0.1.26-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 cohort-middleware diff --git a/helm/dashboard/Chart.yaml b/helm/dashboard/Chart.yaml index 5488da63c..75b3bc1ce 100644 --- a/helm/dashboard/Chart.yaml +++ b/helm/dashboard/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.23 +version: 0.1.24 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/dashboard/README.md b/helm/dashboard/README.md index 8c9a4d388..a5cfe1df1 100644 --- a/helm/dashboard/README.md +++ b/helm/dashboard/README.md @@ -1,6 +1,6 @@ # dashboard -![Version: 0.1.23](https://img.shields.io/badge/Version-0.1.23-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.16.0](https://img.shields.io/badge/AppVersion-1.16.0-informational?style=flat-square) +![Version: 0.1.24](https://img.shields.io/badge/Version-0.1.24-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.16.0](https://img.shields.io/badge/AppVersion-1.16.0-informational?style=flat-square) A Helm chart for Kubernetes diff --git a/helm/data-upload-cron/Chart.yaml b/helm/data-upload-cron/Chart.yaml index 280b9f8d2..565513700 100644 --- a/helm/data-upload-cron/Chart.yaml +++ b/helm/data-upload-cron/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.8 +version: 0.1.9 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/data-upload-cron/README.md b/helm/data-upload-cron/README.md index 49b32ab76..7485b2024 100644 --- a/helm/data-upload-cron/README.md +++ b/helm/data-upload-cron/README.md @@ -1,6 +1,6 @@ # data-upload-cron -![Version: 0.1.8](https://img.shields.io/badge/Version-0.1.8-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.9](https://img.shields.io/badge/Version-0.1.9-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for the data upload cronjob diff --git a/helm/datareplicate/Chart.yaml b/helm/datareplicate/Chart.yaml index f784d42cf..bd0cf7651 100644 --- a/helm/datareplicate/Chart.yaml +++ b/helm/datareplicate/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.23 +version: 0.1.24 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/datareplicate/README.md b/helm/datareplicate/README.md index 17175cd77..d89f11c1a 100644 --- a/helm/datareplicate/README.md +++ b/helm/datareplicate/README.md @@ -1,6 +1,6 @@ # datareplicate -![Version: 0.1.23](https://img.shields.io/badge/Version-0.1.23-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.24](https://img.shields.io/badge/Version-0.1.24-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 datareplicate diff --git a/helm/dicom-server/Chart.yaml b/helm/dicom-server/Chart.yaml index 32d680baa..f59d194aa 100644 --- a/helm/dicom-server/Chart.yaml +++ b/helm/dicom-server/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.33 +version: 0.1.34 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/dicom-server/README.md b/helm/dicom-server/README.md index 1e1319bf9..c14448414 100644 --- a/helm/dicom-server/README.md +++ b/helm/dicom-server/README.md @@ -1,6 +1,6 @@ # dicom-server -![Version: 0.1.33](https://img.shields.io/badge/Version-0.1.33-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.34](https://img.shields.io/badge/Version-0.1.34-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Dicom Server diff --git a/helm/embedding-management-service/Chart.yaml b/helm/embedding-management-service/Chart.yaml index 88f0a598f..0af67496c 100644 --- a/helm/embedding-management-service/Chart.yaml +++ b/helm/embedding-management-service/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.10 +version: 0.1.11 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/embedding-management-service/README.md b/helm/embedding-management-service/README.md index d6fd5d32c..3bad167e5 100644 --- a/helm/embedding-management-service/README.md +++ b/helm/embedding-management-service/README.md @@ -1,6 +1,6 @@ # embedding-management-service -![Version: 0.1.10](https://img.shields.io/badge/Version-0.1.10-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.16.0](https://img.shields.io/badge/AppVersion-1.16.0-informational?style=flat-square) +![Version: 0.1.11](https://img.shields.io/badge/Version-0.1.11-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.16.0](https://img.shields.io/badge/AppVersion-1.16.0-informational?style=flat-square) A Helm chart for Kubernetes diff --git a/helm/frontend-framework/Chart.yaml b/helm/frontend-framework/Chart.yaml index cea0118d1..c435a52b6 100644 --- a/helm/frontend-framework/Chart.yaml +++ b/helm/frontend-framework/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.31 +version: 0.1.32 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/frontend-framework/README.md b/helm/frontend-framework/README.md index 2088256cb..c22bde71e 100644 --- a/helm/frontend-framework/README.md +++ b/helm/frontend-framework/README.md @@ -1,6 +1,6 @@ # frontend-framework -![Version: 0.1.31](https://img.shields.io/badge/Version-0.1.31-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: develop](https://img.shields.io/badge/AppVersion-develop-informational?style=flat-square) +![Version: 0.1.32](https://img.shields.io/badge/Version-0.1.32-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: develop](https://img.shields.io/badge/AppVersion-develop-informational?style=flat-square) A Helm chart for the gen3 frontend framework diff --git a/helm/funnel/Chart.yaml b/helm/funnel/Chart.yaml index c31c6876f..3483bcbe8 100644 --- a/helm/funnel/Chart.yaml +++ b/helm/funnel/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.31 +version: 0.1.32 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/funnel/README.md b/helm/funnel/README.md index 8da1c8de6..aeb5be980 100644 --- a/helm/funnel/README.md +++ b/helm/funnel/README.md @@ -1,6 +1,6 @@ # funnel -![Version: 0.1.31](https://img.shields.io/badge/Version-0.1.31-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.32](https://img.shields.io/badge/Version-0.1.32-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for Kubernetes diff --git a/helm/gen3-analysis/Chart.yaml b/helm/gen3-analysis/Chart.yaml index 810c76d99..93f461dc9 100644 --- a/helm/gen3-analysis/Chart.yaml +++ b/helm/gen3-analysis/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.14 +version: 0.1.15 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3-analysis/README.md b/helm/gen3-analysis/README.md index 502577801..4754d7f60 100644 --- a/helm/gen3-analysis/README.md +++ b/helm/gen3-analysis/README.md @@ -1,6 +1,6 @@ # gen3-analysis -![Version: 0.1.14](https://img.shields.io/badge/Version-0.1.14-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.15](https://img.shields.io/badge/Version-0.1.15-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 gen3-analysis Service diff --git a/helm/gen3-user-data-library/Chart.yaml b/helm/gen3-user-data-library/Chart.yaml index 6c27417da..c1d2c1fbe 100644 --- a/helm/gen3-user-data-library/Chart.yaml +++ b/helm/gen3-user-data-library/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.17 +version: 0.1.18 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3-user-data-library/README.md b/helm/gen3-user-data-library/README.md index 60c8cea86..809e4753f 100644 --- a/helm/gen3-user-data-library/README.md +++ b/helm/gen3-user-data-library/README.md @@ -1,6 +1,6 @@ # gen3-user-data-library -![Version: 0.1.17](https://img.shields.io/badge/Version-0.1.17-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: main](https://img.shields.io/badge/AppVersion-main-informational?style=flat-square) +![Version: 0.1.18](https://img.shields.io/badge/Version-0.1.18-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: main](https://img.shields.io/badge/AppVersion-main-informational?style=flat-square) A Helm chart for Kubernetes diff --git a/helm/gen3-workflow/Chart.yaml b/helm/gen3-workflow/Chart.yaml index 1b40af09e..42a98103b 100644 --- a/helm/gen3-workflow/Chart.yaml +++ b/helm/gen3-workflow/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.28 +version: 0.1.29 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3-workflow/README.md b/helm/gen3-workflow/README.md index 6f79ccad9..7c9ceaed7 100644 --- a/helm/gen3-workflow/README.md +++ b/helm/gen3-workflow/README.md @@ -1,6 +1,6 @@ # gen3-workflow -![Version: 0.1.28](https://img.shields.io/badge/Version-0.1.28-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.29](https://img.shields.io/badge/Version-0.1.29-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for Kubernetes diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index f42e6c4d8..7d985f0f7 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -5,58 +5,58 @@ description: Helm chart to deploy Gen3 Data Commons # Dependencies dependencies: - name: access-backend - version: 0.1.22 + version: 0.1.23 repository: "file://../access-backend" condition: access-backend.enabled - name: ambassador - version: 0.1.39 + version: 0.1.40 repository: "file://../ambassador" condition: ambassador.enabled - name: arborist - version: 0.1.36 + version: 0.1.37 repository: "file://../arborist" condition: arborist.enabled - name: argo-wrapper - version: 0.1.33 + version: 0.1.34 repository: "file://../argo-wrapper" condition: argo-wrapper.enabled - name: audit - version: 0.1.46 + version: 0.1.47 repository: "file://../audit" condition: audit.enabled - name: aws-es-proxy - version: 0.1.44 + version: 0.1.45 repository: "file://../aws-es-proxy" condition: aws-es-proxy.enabled - name: aws-sigv4-proxy - version: 0.1.4 + version: 0.1.5 repository: "file://../aws-sigv4-proxy" condition: aws-sigv4-proxy.enabled - name: cedar - version: 0.1.28 + version: 0.1.29 repository: "file://../cedar" condition: cedar.enabled - name: cohort-middleware - version: 0.1.25 + version: 0.1.26 repository: "file://../cohort-middleware" condition: cohort-middleware.enabled - name: common version: 0.1.39 repository: file://../common - name: dashboard - version: 0.1.23 + version: 0.1.24 repository: file://../dashboard condition: dashboard.enabled - name: datareplicate - version: 0.1.23 + version: 0.1.24 repository: "file://../datareplicate" condition: datareplicate.enabled - name: data-upload-cron - version: 0.1.8 + version: 0.1.9 repository: "file://../data-upload-cron" condition: data-upload-cron.enabled - name: embedding-management-service - version: 0.1.10 + version: 0.1.11 repository: file://../embedding-management-service condition: embedding-management-service.enabled - name: etl @@ -64,7 +64,7 @@ dependencies: repository: file://../etl condition: etl.enabled - name: frontend-framework - version: 0.1.31 + version: 0.1.32 repository: "file://../frontend-framework" condition: frontend-framework.enabled - name: fence @@ -72,7 +72,7 @@ dependencies: repository: "file://../fence" condition: fence.enabled - name: funnel - version: 0.1.31 + version: 0.1.32 repository: "file://../funnel" condition: gen3-workflow.enabled - name: gen3-embeddings @@ -80,43 +80,43 @@ dependencies: repository: "file://../gen3-embeddings" condition: gen3-embeddings.enabled - name: gen3-user-data-library - version: 0.1.17 + version: 0.1.18 repository: "file://../gen3-user-data-library" condition: gen3-user-data-library.enabled - name: gen3-workflow - version: 0.1.28 + version: 0.1.29 repository: "file://../gen3-workflow" condition: gen3-workflow.enabled - name: guppy - version: 0.1.40 + version: 0.1.41 repository: "file://../guppy" condition: guppy.enabled - name: hatchery - version: 0.1.72 + version: 0.1.73 repository: "file://../hatchery" condition: hatchery.enabled - name: indexd - version: 0.1.49 + version: 0.1.50 repository: "file://../indexd" condition: indexd.enabled - name: manifestservice - version: 0.1.45 + version: 0.1.46 repository: "file://../manifestservice" condition: manifestservice.enabled - name: metadata - version: 0.1.47 + version: 0.1.48 repository: "file://../metadata" condition: metadata.enabled - name: peregrine - version: 0.1.44 + version: 0.1.45 repository: "file://../peregrine" condition: peregrine.enabled - name: portal - version: 0.1.62 + version: 0.1.63 repository: "file://../portal" condition: portal.enabled - name: requestor - version: 0.1.37 + version: 0.1.38 repository: "file://../requestor" condition: requestor.enabled - name: revproxy @@ -124,23 +124,23 @@ dependencies: repository: "file://../revproxy" condition: revproxy.enabled - name: sheepdog - version: 0.1.46 + version: 0.1.47 repository: "file://../sheepdog" condition: sheepdog.enabled - name: ssjdispatcher - version: 0.1.49 + version: 0.1.50 repository: "file://../ssjdispatcher" condition: ssjdispatcher.enabled - name: sower - version: 0.1.48 + version: 0.1.49 condition: sower.enabled repository: "file://../sower" - name: wts - version: 0.1.43 + version: 0.1.44 repository: "file://../wts" condition: wts.enabled - name: zendesk-wrapper - version: 0.1.1 + version: 0.1.2 repository: "file://../zendesk-wrapper" condition: zendesk-wrapper.enabled - name: gen3-network-policies @@ -148,19 +148,19 @@ dependencies: repository: "file://../gen3-network-policies" condition: global.netPolicy.enabled - name: dicom-server - version: 0.1.33 + version: 0.1.34 repository: file://../dicom-server condition: dicom-server.enabled - name: ohif-viewer - version: 0.1.16 + version: 0.1.17 repository: file://../ohif-viewer condition: ohif-viewer.enabled - name: orthanc - version: 0.1.17 + version: 0.1.18 repository: file://../orthanc condition: orthanc.enabled - name: gen3-analysis - version: 0.1.14 + version: 0.1.15 repository: file://../gen3-analysis condition: gen3-analysis.enabled - name: ohdsi-atlas @@ -168,7 +168,7 @@ dependencies: repository: file://../ohdsi-atlas condition: ohdsi-atlas.enabled - name: ohdsi-webapi - version: 0.1.7 + version: 0.1.8 repository: file://../ohdsi-webapi condition: ohdsi-webapi.enabled @@ -191,15 +191,15 @@ dependencies: repository: "file://../neuvector" condition: neuvector.enabled - name: jeg - version: 0.1.3 + version: 0.1.4 repository: "file://../jeg" condition: jeg.enabled - name: workspace-proxy - version: 0.1.3 + version: 0.1.4 repository: "file://../workspace-proxy" condition: workspace-proxy.enabled - name: vectis-overlays - version: 0.1.3 + version: 0.1.4 repository: "file://../vectis-overlays" condition: vectis-overlays.enabled diff --git a/helm/gen3/README.md b/helm/gen3/README.md index 4c3d4ff2d..6d7b018a3 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -18,52 +18,52 @@ Helm chart to deploy Gen3 Data Commons | Repository | Name | Version | |------------|------|---------| -| file://../access-backend | access-backend | 0.1.22 | -| file://../ambassador | ambassador | 0.1.39 | -| file://../arborist | arborist | 0.1.36 | -| file://../argo-wrapper | argo-wrapper | 0.1.33 | -| file://../audit | audit | 0.1.46 | -| file://../aws-es-proxy | aws-es-proxy | 0.1.44 | -| file://../aws-sigv4-proxy | aws-sigv4-proxy | 0.1.4 | -| file://../cedar | cedar | 0.1.28 | -| file://../cohort-middleware | cohort-middleware | 0.1.25 | +| file://../access-backend | access-backend | 0.1.23 | +| file://../ambassador | ambassador | 0.1.40 | +| file://../arborist | arborist | 0.1.37 | +| file://../argo-wrapper | argo-wrapper | 0.1.34 | +| file://../audit | audit | 0.1.47 | +| file://../aws-es-proxy | aws-es-proxy | 0.1.45 | +| file://../aws-sigv4-proxy | aws-sigv4-proxy | 0.1.5 | +| file://../cedar | cedar | 0.1.29 | +| file://../cohort-middleware | cohort-middleware | 0.1.26 | | file://../common | common | 0.1.39 | -| file://../dashboard | dashboard | 0.1.23 | -| file://../data-upload-cron | data-upload-cron | 0.1.8 | -| file://../datareplicate | datareplicate | 0.1.23 | -| file://../dicom-server | dicom-server | 0.1.33 | -| file://../embedding-management-service | embedding-management-service | 0.1.10 | +| file://../dashboard | dashboard | 0.1.24 | +| file://../data-upload-cron | data-upload-cron | 0.1.9 | +| file://../datareplicate | datareplicate | 0.1.24 | +| file://../dicom-server | dicom-server | 0.1.34 | +| file://../embedding-management-service | embedding-management-service | 0.1.11 | | file://../etl | etl | 0.1.24 | | file://../fence | fence | 0.1.82 | -| file://../frontend-framework | frontend-framework | 0.1.31 | -| file://../funnel | funnel | 0.1.31 | -| file://../gen3-analysis | gen3-analysis | 0.1.14 | +| file://../frontend-framework | frontend-framework | 0.1.32 | +| file://../funnel | funnel | 0.1.32 | +| file://../gen3-analysis | gen3-analysis | 0.1.15 | | file://../gen3-embeddings | gen3-embeddings | 0.1.1 | | file://../gen3-network-policies | gen3-network-policies | 0.1.4 | -| file://../gen3-user-data-library | gen3-user-data-library | 0.1.17 | -| file://../gen3-workflow | gen3-workflow | 0.1.28 | -| file://../guppy | guppy | 0.1.40 | -| file://../hatchery | hatchery | 0.1.72 | -| file://../indexd | indexd | 0.1.49 | -| file://../jeg | jeg | 0.1.3 | -| file://../manifestservice | manifestservice | 0.1.45 | -| file://../metadata | metadata | 0.1.47 | +| file://../gen3-user-data-library | gen3-user-data-library | 0.1.18 | +| file://../gen3-workflow | gen3-workflow | 0.1.29 | +| file://../guppy | guppy | 0.1.41 | +| file://../hatchery | hatchery | 0.1.73 | +| file://../indexd | indexd | 0.1.50 | +| file://../jeg | jeg | 0.1.4 | +| file://../manifestservice | manifestservice | 0.1.46 | +| file://../metadata | metadata | 0.1.48 | | file://../neuvector | neuvector | 0.1.2 | | file://../ohdsi-atlas | ohdsi-atlas | 0.1.2 | -| file://../ohdsi-webapi | ohdsi-webapi | 0.1.7 | -| file://../ohif-viewer | ohif-viewer | 0.1.16 | -| file://../orthanc | orthanc | 0.1.17 | -| file://../peregrine | peregrine | 0.1.44 | -| file://../portal | portal | 0.1.62 | -| file://../requestor | requestor | 0.1.37 | +| file://../ohdsi-webapi | ohdsi-webapi | 0.1.8 | +| file://../ohif-viewer | ohif-viewer | 0.1.17 | +| file://../orthanc | orthanc | 0.1.18 | +| file://../peregrine | peregrine | 0.1.45 | +| file://../portal | portal | 0.1.63 | +| file://../requestor | requestor | 0.1.38 | | file://../revproxy | revproxy | 0.1.69 | -| file://../sheepdog | sheepdog | 0.1.46 | -| file://../sower | sower | 0.1.48 | -| file://../ssjdispatcher | ssjdispatcher | 0.1.49 | -| file://../vectis-overlays | vectis-overlays | 0.1.3 | -| file://../workspace-proxy | workspace-proxy | 0.1.3 | -| file://../wts | wts | 0.1.43 | -| file://../zendesk-wrapper | zendesk-wrapper | 0.1.1 | +| file://../sheepdog | sheepdog | 0.1.47 | +| file://../sower | sower | 0.1.49 | +| file://../ssjdispatcher | ssjdispatcher | 0.1.50 | +| file://../vectis-overlays | vectis-overlays | 0.1.4 | +| file://../workspace-proxy | workspace-proxy | 0.1.4 | +| file://../wts | wts | 0.1.44 | +| file://../zendesk-wrapper | zendesk-wrapper | 0.1.2 | | https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | | https://helm.elastic.co | elasticsearch | 7.10.2 | diff --git a/helm/guppy/Chart.yaml b/helm/guppy/Chart.yaml index 322ae90b1..9d427002c 100644 --- a/helm/guppy/Chart.yaml +++ b/helm/guppy/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.40 +version: 0.1.41 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/guppy/README.md b/helm/guppy/README.md index bdaf3c64b..a96095f53 100644 --- a/helm/guppy/README.md +++ b/helm/guppy/README.md @@ -1,6 +1,6 @@ # guppy -![Version: 0.1.40](https://img.shields.io/badge/Version-0.1.40-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.41](https://img.shields.io/badge/Version-0.1.41-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Guppy Service diff --git a/helm/hatchery/Chart.yaml b/helm/hatchery/Chart.yaml index c7e7fdaaa..690ba9e9c 100644 --- a/helm/hatchery/Chart.yaml +++ b/helm/hatchery/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.72 +version: 0.1.73 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/hatchery/README.md b/helm/hatchery/README.md index ed6a98539..8af45ae9c 100644 --- a/helm/hatchery/README.md +++ b/helm/hatchery/README.md @@ -1,6 +1,6 @@ # hatchery -![Version: 0.1.72](https://img.shields.io/badge/Version-0.1.72-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.73](https://img.shields.io/badge/Version-0.1.73-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Hatchery diff --git a/helm/indexd/Chart.yaml b/helm/indexd/Chart.yaml index cab96517b..4f7b7f6e6 100644 --- a/helm/indexd/Chart.yaml +++ b/helm/indexd/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.49 +version: 0.1.50 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/indexd/README.md b/helm/indexd/README.md index 41696a827..6c0376a83 100644 --- a/helm/indexd/README.md +++ b/helm/indexd/README.md @@ -1,6 +1,6 @@ # indexd -![Version: 0.1.49](https://img.shields.io/badge/Version-0.1.49-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.50](https://img.shields.io/badge/Version-0.1.50-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 indexd diff --git a/helm/jeg/Chart.yaml b/helm/jeg/Chart.yaml index dba67434c..a0adcbcda 100644 --- a/helm/jeg/Chart.yaml +++ b/helm/jeg/Chart.yaml @@ -5,7 +5,7 @@ description: > Launches ephemeral kernel pods in the workspace namespace on behalf of user Jupyter sessions proxied through workspace-proxy. type: application -version: 0.1.3 +version: 0.1.4 appVersion: "3.2.3" dependencies: diff --git a/helm/jeg/README.md b/helm/jeg/README.md index 8559690ba..4dc2bf0a0 100644 --- a/helm/jeg/README.md +++ b/helm/jeg/README.md @@ -1,6 +1,6 @@ # jeg -![Version: 0.1.3](https://img.shields.io/badge/Version-0.1.3-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 3.2.3](https://img.shields.io/badge/AppVersion-3.2.3-informational?style=flat-square) +![Version: 0.1.4](https://img.shields.io/badge/Version-0.1.4-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 3.2.3](https://img.shields.io/badge/AppVersion-3.2.3-informational?style=flat-square) Jupyter Enterprise Gateway for gen3 vectis workspaces. Launches ephemeral kernel pods in the workspace namespace on behalf of user Jupyter sessions proxied through workspace-proxy. diff --git a/helm/manifestservice/Chart.yaml b/helm/manifestservice/Chart.yaml index 4008c3678..2e216b0a2 100644 --- a/helm/manifestservice/Chart.yaml +++ b/helm/manifestservice/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.45 +version: 0.1.46 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/manifestservice/README.md b/helm/manifestservice/README.md index f44f75150..1f0ad3145 100644 --- a/helm/manifestservice/README.md +++ b/helm/manifestservice/README.md @@ -1,6 +1,6 @@ # manifestservice -![Version: 0.1.45](https://img.shields.io/badge/Version-0.1.45-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.46](https://img.shields.io/badge/Version-0.1.46-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for Kubernetes diff --git a/helm/metadata/Chart.yaml b/helm/metadata/Chart.yaml index 19a2b96ae..76a0c935a 100644 --- a/helm/metadata/Chart.yaml +++ b/helm/metadata/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.47 +version: 0.1.48 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/metadata/README.md b/helm/metadata/README.md index d1de6fff5..3b08de802 100644 --- a/helm/metadata/README.md +++ b/helm/metadata/README.md @@ -1,6 +1,6 @@ # metadata -![Version: 0.1.47](https://img.shields.io/badge/Version-0.1.47-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.48](https://img.shields.io/badge/Version-0.1.48-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Metadata Service diff --git a/helm/ohdsi-webapi/Chart.yaml b/helm/ohdsi-webapi/Chart.yaml index 9dfe27b1d..e35c756ce 100644 --- a/helm/ohdsi-webapi/Chart.yaml +++ b/helm/ohdsi-webapi/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.7 +version: 0.1.8 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/ohdsi-webapi/README.md b/helm/ohdsi-webapi/README.md index 312ceda7b..da539b51d 100644 --- a/helm/ohdsi-webapi/README.md +++ b/helm/ohdsi-webapi/README.md @@ -1,6 +1,6 @@ # ohdsi-webapi -![Version: 0.1.7](https://img.shields.io/badge/Version-0.1.7-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 2.15.0](https://img.shields.io/badge/AppVersion-2.15.0-informational?style=flat-square) +![Version: 0.1.8](https://img.shields.io/badge/Version-0.1.8-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 2.15.0](https://img.shields.io/badge/AppVersion-2.15.0-informational?style=flat-square) A Helm chart for OHDSI WebAPI diff --git a/helm/ohif-viewer/Chart.yaml b/helm/ohif-viewer/Chart.yaml index 4f61bea1a..e7c13832d 100644 --- a/helm/ohif-viewer/Chart.yaml +++ b/helm/ohif-viewer/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.16 +version: 0.1.17 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/ohif-viewer/README.md b/helm/ohif-viewer/README.md index f6939b383..fa11af110 100644 --- a/helm/ohif-viewer/README.md +++ b/helm/ohif-viewer/README.md @@ -1,6 +1,6 @@ # ohif-viewer -![Version: 0.1.16](https://img.shields.io/badge/Version-0.1.16-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.17](https://img.shields.io/badge/Version-0.1.17-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Ohif Viewer diff --git a/helm/orthanc/Chart.yaml b/helm/orthanc/Chart.yaml index 2acb46f50..c0a7d929d 100644 --- a/helm/orthanc/Chart.yaml +++ b/helm/orthanc/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.17 +version: 0.1.18 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/orthanc/README.md b/helm/orthanc/README.md index 2d633ef97..fbfa9260c 100644 --- a/helm/orthanc/README.md +++ b/helm/orthanc/README.md @@ -1,6 +1,6 @@ # orthanc -![Version: 0.1.17](https://img.shields.io/badge/Version-0.1.17-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.18](https://img.shields.io/badge/Version-0.1.18-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Dicom Server diff --git a/helm/peregrine/Chart.yaml b/helm/peregrine/Chart.yaml index 2edc618c2..dbde621f1 100644 --- a/helm/peregrine/Chart.yaml +++ b/helm/peregrine/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.44 +version: 0.1.45 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/peregrine/README.md b/helm/peregrine/README.md index beee8c40a..cacba1fbc 100644 --- a/helm/peregrine/README.md +++ b/helm/peregrine/README.md @@ -1,6 +1,6 @@ # peregrine -![Version: 0.1.44](https://img.shields.io/badge/Version-0.1.44-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.45](https://img.shields.io/badge/Version-0.1.45-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Peregrine service diff --git a/helm/portal/Chart.yaml b/helm/portal/Chart.yaml index c6d2b8510..ef0b3d4d4 100644 --- a/helm/portal/Chart.yaml +++ b/helm/portal/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.62 +version: 0.1.63 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/portal/README.md b/helm/portal/README.md index 9ae365a99..6730e0b0f 100644 --- a/helm/portal/README.md +++ b/helm/portal/README.md @@ -1,6 +1,6 @@ # portal -![Version: 0.1.62](https://img.shields.io/badge/Version-0.1.62-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.63](https://img.shields.io/badge/Version-0.1.63-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 data-portal diff --git a/helm/requestor/Chart.yaml b/helm/requestor/Chart.yaml index 97cb7801f..895c266c8 100644 --- a/helm/requestor/Chart.yaml +++ b/helm/requestor/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.37 +version: 0.1.38 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/requestor/README.md b/helm/requestor/README.md index 53c21963f..5b10ab36d 100644 --- a/helm/requestor/README.md +++ b/helm/requestor/README.md @@ -1,6 +1,6 @@ # requestor -![Version: 0.1.37](https://img.shields.io/badge/Version-0.1.37-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.38](https://img.shields.io/badge/Version-0.1.38-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Requestor Service diff --git a/helm/sheepdog/Chart.yaml b/helm/sheepdog/Chart.yaml index e19549d2a..1105790be 100644 --- a/helm/sheepdog/Chart.yaml +++ b/helm/sheepdog/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.46 +version: 0.1.47 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/sheepdog/README.md b/helm/sheepdog/README.md index 52495a83a..e50831dd9 100644 --- a/helm/sheepdog/README.md +++ b/helm/sheepdog/README.md @@ -1,6 +1,6 @@ # sheepdog -![Version: 0.1.46](https://img.shields.io/badge/Version-0.1.46-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.47](https://img.shields.io/badge/Version-0.1.47-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Sheepdog Service diff --git a/helm/sower/Chart.yaml b/helm/sower/Chart.yaml index 7987b2ae0..c16e77628 100644 --- a/helm/sower/Chart.yaml +++ b/helm/sower/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.48 +version: 0.1.49 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/sower/README.md b/helm/sower/README.md index 650ce9ed4..9760561d8 100644 --- a/helm/sower/README.md +++ b/helm/sower/README.md @@ -1,6 +1,6 @@ # sower -![Version: 0.1.48](https://img.shields.io/badge/Version-0.1.48-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.49](https://img.shields.io/badge/Version-0.1.49-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 sower diff --git a/helm/ssjdispatcher/Chart.yaml b/helm/ssjdispatcher/Chart.yaml index 276483315..d67c80e57 100644 --- a/helm/ssjdispatcher/Chart.yaml +++ b/helm/ssjdispatcher/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.49 +version: 0.1.50 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/ssjdispatcher/README.md b/helm/ssjdispatcher/README.md index 415f1c209..d7d99592d 100644 --- a/helm/ssjdispatcher/README.md +++ b/helm/ssjdispatcher/README.md @@ -1,6 +1,6 @@ # ssjdispatcher -![Version: 0.1.49](https://img.shields.io/badge/Version-0.1.49-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.50](https://img.shields.io/badge/Version-0.1.50-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 ssjdispatcher diff --git a/helm/vectis-overlays/Chart.yaml b/helm/vectis-overlays/Chart.yaml index 2b764f03b..a38a8981f 100644 --- a/helm/vectis-overlays/Chart.yaml +++ b/helm/vectis-overlays/Chart.yaml @@ -2,7 +2,7 @@ apiVersion: v2 name: vectis-overlays description: Vectis overlay API services (guppy-compat, siem, search-auth-proxy) type: application -version: 0.1.3 +version: 0.1.4 appVersion: "1.0" dependencies: diff --git a/helm/vectis-overlays/README.md b/helm/vectis-overlays/README.md index 1fd02e3b2..9908953ed 100644 --- a/helm/vectis-overlays/README.md +++ b/helm/vectis-overlays/README.md @@ -1,6 +1,6 @@ # vectis-overlays -![Version: 0.1.3](https://img.shields.io/badge/Version-0.1.3-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.0](https://img.shields.io/badge/AppVersion-1.0-informational?style=flat-square) +![Version: 0.1.4](https://img.shields.io/badge/Version-0.1.4-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.0](https://img.shields.io/badge/AppVersion-1.0-informational?style=flat-square) Vectis overlay API services (guppy-compat, siem, search-auth-proxy) diff --git a/helm/workspace-proxy/Chart.yaml b/helm/workspace-proxy/Chart.yaml index 94e3cbf20..1f5d6a1da 100644 --- a/helm/workspace-proxy/Chart.yaml +++ b/helm/workspace-proxy/Chart.yaml @@ -5,7 +5,7 @@ description: > Replaces Emissary/Ambassador. Reads Service annotations written by Hatchery to resolve each user's workspace upstream, then proxies traffic from revproxy. type: application -version: 0.1.3 +version: 0.1.4 appVersion: "1.0" dependencies: diff --git a/helm/workspace-proxy/README.md b/helm/workspace-proxy/README.md index 0862edcc2..1b523d216 100644 --- a/helm/workspace-proxy/README.md +++ b/helm/workspace-proxy/README.md @@ -1,6 +1,6 @@ # workspace-proxy -![Version: 0.1.3](https://img.shields.io/badge/Version-0.1.3-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.0](https://img.shields.io/badge/AppVersion-1.0-informational?style=flat-square) +![Version: 0.1.4](https://img.shields.io/badge/Version-0.1.4-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.0](https://img.shields.io/badge/AppVersion-1.0-informational?style=flat-square) Per-user workspace HTTP/WebSocket router for gen3 vectis. Replaces Emissary/Ambassador. Reads Service annotations written by Hatchery to resolve each user's workspace upstream, then proxies traffic from revproxy. diff --git a/helm/wts/Chart.yaml b/helm/wts/Chart.yaml index c4e55d392..9710da208 100644 --- a/helm/wts/Chart.yaml +++ b/helm/wts/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.43 +version: 0.1.44 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/wts/README.md b/helm/wts/README.md index 56e0c1a08..fb8e80646 100644 --- a/helm/wts/README.md +++ b/helm/wts/README.md @@ -1,6 +1,6 @@ # wts -![Version: 0.1.43](https://img.shields.io/badge/Version-0.1.43-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.44](https://img.shields.io/badge/Version-0.1.44-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 workspace token service diff --git a/helm/zendesk-wrapper/Chart.yaml b/helm/zendesk-wrapper/Chart.yaml index 4fb376b05..2d1484d8e 100644 --- a/helm/zendesk-wrapper/Chart.yaml +++ b/helm/zendesk-wrapper/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.1 +version: 0.1.2 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/zendesk-wrapper/README.md b/helm/zendesk-wrapper/README.md index 24657633d..a8b592c59 100644 --- a/helm/zendesk-wrapper/README.md +++ b/helm/zendesk-wrapper/README.md @@ -1,6 +1,6 @@ # zendesk-wrapper -![Version: 0.1.1](https://img.shields.io/badge/Version-0.1.1-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.2](https://img.shields.io/badge/Version-0.1.2-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Zendesk Wrapper Service From 3730409ce0e00125460ba7d6a0988fc5813c8672 Mon Sep 17 00:00:00 2001 From: mark xiao Date: Fri, 7 Aug 2026 12:30:08 -0500 Subject: [PATCH 175/196] update --- helm/gen3-embeddings/values.yaml | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/helm/gen3-embeddings/values.yaml b/helm/gen3-embeddings/values.yaml index 62fc4a1ca..6a8d4fea4 100644 --- a/helm/gen3-embeddings/values.yaml +++ b/helm/gen3-embeddings/values.yaml @@ -136,7 +136,7 @@ readinessProbe: port: http # Additional volumeMounts on the output Deployment definition. -volumeMounts: +volumeMounts: - mountPath: /services/gen3_embeddings/.env name: gen3-embeddings-g3auto-volume readOnly: true @@ -204,4 +204,3 @@ secrets: # -- (str) AWS secret access key ID. Overrides global key. awsSecretAccessKey: gunicornWorkers: 1 - From cd66e7ba3097eaedd72a2b4746aa2a9d4df5962a Mon Sep 17 00:00:00 2001 From: Jawad Date: Tue, 9 Jun 2026 14:25:07 -0500 Subject: [PATCH 176/196] Add conditional rewritePath support in revproxy configuration --- helm/gen3/Chart.yaml | 4 ++-- helm/gen3/README.md | 4 ++-- helm/revproxy/Chart.yaml | 2 +- helm/revproxy/README.md | 2 +- helm/revproxy/templates/configMaps.yaml | 4 ++++ helm/revproxy/values.yaml | 1 + 6 files changed, 11 insertions(+), 6 deletions(-) diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index 7d985f0f7..06bda3737 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -120,7 +120,7 @@ dependencies: repository: "file://../requestor" condition: requestor.enabled - name: revproxy - version: 0.1.69 + version: 0.1.70 repository: "file://../revproxy" condition: revproxy.enabled - name: sheepdog @@ -217,7 +217,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.79 +version: 0.3.80 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index 6d7b018a3..7ad7bb83e 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,6 +1,6 @@ # gen3 -![Version: 0.3.79](https://img.shields.io/badge/Version-0.3.79-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.3.80](https://img.shields.io/badge/Version-0.3.80-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons @@ -56,7 +56,7 @@ Helm chart to deploy Gen3 Data Commons | file://../peregrine | peregrine | 0.1.45 | | file://../portal | portal | 0.1.63 | | file://../requestor | requestor | 0.1.38 | -| file://../revproxy | revproxy | 0.1.69 | +| file://../revproxy | revproxy | 0.1.70 | | file://../sheepdog | sheepdog | 0.1.47 | | file://../sower | sower | 0.1.49 | | file://../ssjdispatcher | ssjdispatcher | 0.1.50 | diff --git a/helm/revproxy/Chart.yaml b/helm/revproxy/Chart.yaml index 421b1467c..d49fe0ede 100644 --- a/helm/revproxy/Chart.yaml +++ b/helm/revproxy/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.69 +version: 0.1.70 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/revproxy/README.md b/helm/revproxy/README.md index 4496ebc16..3b2b6ba8a 100644 --- a/helm/revproxy/README.md +++ b/helm/revproxy/README.md @@ -1,6 +1,6 @@ # revproxy -![Version: 0.1.69](https://img.shields.io/badge/Version-0.1.69-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.70](https://img.shields.io/badge/Version-0.1.70-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 revproxy diff --git a/helm/revproxy/templates/configMaps.yaml b/helm/revproxy/templates/configMaps.yaml index 3fcecd8cb..b09666eb0 100644 --- a/helm/revproxy/templates/configMaps.yaml +++ b/helm/revproxy/templates/configMaps.yaml @@ -51,7 +51,11 @@ data: {{- if .customNginxConfigs }} {{ "\n " }}{{- .customNginxConfigs | trim | replace "\n" "\n " }} {{- end }} + + {{- if ne .rewritePath false }} rewrite ^{{ .path }}/(.*) /$1 break; + {{- end }} + proxy_pass $upstream; proxy_redirect http://$host/ https://$host{{ .path }}/; } diff --git a/helm/revproxy/values.yaml b/helm/revproxy/values.yaml index b490970c2..4a3e1b3c9 100644 --- a/helm/revproxy/values.yaml +++ b/helm/revproxy/values.yaml @@ -270,6 +270,7 @@ extraServices: # authzPolicy: "protein-paint" # authzService: "protein-paint" # csrfCheck: true +# rewritePath: true # customNginxConfigs: | # proxy_buffering off; # proxy_cache off; From 10217109737ca81f0bbd9f71d4c1af1391abd370 Mon Sep 17 00:00:00 2001 From: Ajo Augustine Date: Mon, 10 Aug 2026 12:56:15 -0500 Subject: [PATCH 177/196] include db bootstrap, pushsecret --- helm/gen3-embeddings/Chart.yaml | 2 +- helm/gen3-embeddings/README.md | 2 +- helm/gen3-embeddings/templates/db-init.yaml | 8 +++++++- helm/gen3/Chart.yaml | 4 ++-- helm/gen3/README.md | 4 ++-- 5 files changed, 13 insertions(+), 7 deletions(-) diff --git a/helm/gen3-embeddings/Chart.yaml b/helm/gen3-embeddings/Chart.yaml index f53f66110..4fc045a86 100644 --- a/helm/gen3-embeddings/Chart.yaml +++ b/helm/gen3-embeddings/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.1 +version: 0.1.2 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3-embeddings/README.md b/helm/gen3-embeddings/README.md index 87b96b6cb..d93b0656b 100644 --- a/helm/gen3-embeddings/README.md +++ b/helm/gen3-embeddings/README.md @@ -1,6 +1,6 @@ # gen3-embeddings -![Version: 0.1.1](https://img.shields.io/badge/Version-0.1.1-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: main](https://img.shields.io/badge/AppVersion-main-informational?style=flat-square) +![Version: 0.1.2](https://img.shields.io/badge/Version-0.1.2-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: main](https://img.shields.io/badge/AppVersion-main-informational?style=flat-square) A Helm chart for Kubernetes diff --git a/helm/gen3-embeddings/templates/db-init.yaml b/helm/gen3-embeddings/templates/db-init.yaml index 0393aa732..95297b084 100644 --- a/helm/gen3-embeddings/templates/db-init.yaml +++ b/helm/gen3-embeddings/templates/db-init.yaml @@ -6,4 +6,10 @@ {{ include "common.s3_pg_restore" . }} {{- else }} {{ include "common.db_setup_job" . }} -{{- end -}} \ No newline at end of file +{{- end -}} +{{- if and $.Values.global.externalSecrets.deploy (or $.Values.global.externalSecrets.pushSecret .Values.externalSecrets.pushSecret) }} +--- +{{ include "common.db-push-secret" . }} +--- +{{ include "common.secret.db.bootstrap" . }} +{{- end }} diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index 06bda3737..d55932059 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -76,7 +76,7 @@ dependencies: repository: "file://../funnel" condition: gen3-workflow.enabled - name: gen3-embeddings - version: 0.1.1 + version: 0.1.2 repository: "file://../gen3-embeddings" condition: gen3-embeddings.enabled - name: gen3-user-data-library @@ -217,7 +217,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.80 +version: 0.3.81 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index 7ad7bb83e..be1c4f9bd 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,6 +1,6 @@ # gen3 -![Version: 0.3.80](https://img.shields.io/badge/Version-0.3.80-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.3.81](https://img.shields.io/badge/Version-0.3.81-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons @@ -38,7 +38,7 @@ Helm chart to deploy Gen3 Data Commons | file://../frontend-framework | frontend-framework | 0.1.32 | | file://../funnel | funnel | 0.1.32 | | file://../gen3-analysis | gen3-analysis | 0.1.15 | -| file://../gen3-embeddings | gen3-embeddings | 0.1.1 | +| file://../gen3-embeddings | gen3-embeddings | 0.1.2 | | file://../gen3-network-policies | gen3-network-policies | 0.1.4 | | file://../gen3-user-data-library | gen3-user-data-library | 0.1.18 | | file://../gen3-workflow | gen3-workflow | 0.1.29 | From 1c8bf69244eac14ede28b55b3a350af9080d6f31 Mon Sep 17 00:00:00 2001 From: Pauline Ribeyre <4224001+paulineribeyre@users.noreply.github.com> Date: Tue, 11 Aug 2026 11:23:24 -0500 Subject: [PATCH 178/196] Fix funnel 'replicas' to use configured value (#674) --- helm/funnel/Chart.yaml | 2 +- helm/funnel/README.md | 2 +- helm/funnel/templates/server-deployment.yaml | 2 +- helm/funnel/values.yaml | 1 - helm/gen3/Chart.yaml | 4 ++-- helm/gen3/README.md | 4 ++-- 6 files changed, 7 insertions(+), 8 deletions(-) diff --git a/helm/funnel/Chart.yaml b/helm/funnel/Chart.yaml index 3483bcbe8..71b7b2a58 100644 --- a/helm/funnel/Chart.yaml +++ b/helm/funnel/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.32 +version: 0.1.33 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/funnel/README.md b/helm/funnel/README.md index aeb5be980..91eba3362 100644 --- a/helm/funnel/README.md +++ b/helm/funnel/README.md @@ -1,6 +1,6 @@ # funnel -![Version: 0.1.32](https://img.shields.io/badge/Version-0.1.32-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.33](https://img.shields.io/badge/Version-0.1.33-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for Kubernetes diff --git a/helm/funnel/templates/server-deployment.yaml b/helm/funnel/templates/server-deployment.yaml index 0186403f5..04e656b25 100644 --- a/helm/funnel/templates/server-deployment.yaml +++ b/helm/funnel/templates/server-deployment.yaml @@ -6,7 +6,7 @@ metadata: labels: {{- include "funnel.labels" . | nindent 4 }} spec: - replicas: 1 + replicas: {{ .Values.replicaCount }} strategy: type: RollingUpdate rollingUpdate: diff --git a/helm/funnel/values.yaml b/helm/funnel/values.yaml index dec8d5420..e49125757 100644 --- a/helm/funnel/values.yaml +++ b/helm/funnel/values.yaml @@ -133,7 +133,6 @@ image: # -- (string) When to pull the image. This value should be "Always" to ensure the latest image is used. pullPolicy: Always - # -- (map) Configuration for the Funnel init container. initContainers: - name: plugin diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index 06bda3737..d24042d92 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -72,7 +72,7 @@ dependencies: repository: "file://../fence" condition: fence.enabled - name: funnel - version: 0.1.32 + version: 0.1.33 repository: "file://../funnel" condition: gen3-workflow.enabled - name: gen3-embeddings @@ -217,7 +217,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.80 +version: 0.3.81 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index 7ad7bb83e..4a24f9776 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,6 +1,6 @@ # gen3 -![Version: 0.3.80](https://img.shields.io/badge/Version-0.3.80-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.3.81](https://img.shields.io/badge/Version-0.3.81-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons @@ -36,7 +36,7 @@ Helm chart to deploy Gen3 Data Commons | file://../etl | etl | 0.1.24 | | file://../fence | fence | 0.1.82 | | file://../frontend-framework | frontend-framework | 0.1.32 | -| file://../funnel | funnel | 0.1.32 | +| file://../funnel | funnel | 0.1.33 | | file://../gen3-analysis | gen3-analysis | 0.1.15 | | file://../gen3-embeddings | gen3-embeddings | 0.1.1 | | file://../gen3-network-policies | gen3-network-policies | 0.1.4 | From a338503535185e0e7e3d112d34c20e267d5e036e Mon Sep 17 00:00:00 2001 From: Kyle Burton Date: Mon, 10 Aug 2026 10:07:37 -0500 Subject: [PATCH 179/196] fix(BDC-1250): Adds default preferred_type for DRS 1.5 Adds configuration to indexd trustedIssuers to support changing the order of the supportedTypes returned by the DRS Authorization endpoints. Updates revproxy to forward bulk DRS object access requests to fence instead of indexd. --- helm/gen3/Chart.yaml | 4 ++-- helm/gen3/README.md | 4 ++-- helm/indexd/Chart.yaml | 2 +- helm/indexd/README.md | 5 +++-- helm/indexd/indexd-settings/local_settings.py | 5 +++++ helm/indexd/templates/deployment.yaml | 2 ++ helm/indexd/values.yaml | 3 +++ helm/revproxy/Chart.yaml | 2 +- helm/revproxy/README.md | 2 +- .../gen3.nginx.conf/fence-service-ga4gh.conf | 14 ++++++++++++++ 10 files changed, 34 insertions(+), 9 deletions(-) diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index d24042d92..045a11e77 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -96,7 +96,7 @@ dependencies: repository: "file://../hatchery" condition: hatchery.enabled - name: indexd - version: 0.1.50 + version: 0.1.51 repository: "file://../indexd" condition: indexd.enabled - name: manifestservice @@ -120,7 +120,7 @@ dependencies: repository: "file://../requestor" condition: requestor.enabled - name: revproxy - version: 0.1.70 + version: 0.1.71 repository: "file://../revproxy" condition: revproxy.enabled - name: sheepdog diff --git a/helm/gen3/README.md b/helm/gen3/README.md index 4a24f9776..c93d2c374 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -44,7 +44,7 @@ Helm chart to deploy Gen3 Data Commons | file://../gen3-workflow | gen3-workflow | 0.1.29 | | file://../guppy | guppy | 0.1.41 | | file://../hatchery | hatchery | 0.1.73 | -| file://../indexd | indexd | 0.1.50 | +| file://../indexd | indexd | 0.1.51 | | file://../jeg | jeg | 0.1.4 | | file://../manifestservice | manifestservice | 0.1.46 | | file://../metadata | metadata | 0.1.48 | @@ -56,7 +56,7 @@ Helm chart to deploy Gen3 Data Commons | file://../peregrine | peregrine | 0.1.45 | | file://../portal | portal | 0.1.63 | | file://../requestor | requestor | 0.1.38 | -| file://../revproxy | revproxy | 0.1.70 | +| file://../revproxy | revproxy | 0.1.71 | | file://../sheepdog | sheepdog | 0.1.47 | | file://../sower | sower | 0.1.49 | | file://../ssjdispatcher | ssjdispatcher | 0.1.50 | diff --git a/helm/indexd/Chart.yaml b/helm/indexd/Chart.yaml index 4f7b7f6e6..e860d6de1 100644 --- a/helm/indexd/Chart.yaml +++ b/helm/indexd/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.50 +version: 0.1.51 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/indexd/README.md b/helm/indexd/README.md index 6c0376a83..ea44f6cef 100644 --- a/helm/indexd/README.md +++ b/helm/indexd/README.md @@ -1,6 +1,6 @@ # indexd -![Version: 0.1.50](https://img.shields.io/badge/Version-0.1.50-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.51](https://img.shields.io/badge/Version-0.1.51-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 indexd @@ -114,9 +114,10 @@ A Helm chart for gen3 indexd | serviceAccount.create | bool | `false` | Specifies whether a service account should be created. | | serviceAccount.name | string | `""` | The name of the service account | | tolerations | list | `[]` | Tolerations for the pods | -| trustedIssuers | map | `{"defaultBearerIssuer":"","defaultPassportIssuer":""}` | Maps an arborist resource to the issuers for passports and bearer tokens. | +| trustedIssuers | map | `{"defaultBearerIssuer":"","defaultPassportIssuer":"","defaultPreferredType":"BearerAuth"}` | Maps an arborist resource to the issuers for passports and bearer tokens. | | trustedIssuers.defaultBearerIssuer | string | `""` | The default issuer for bearer tokens to be used if a given auth resource isn't provided. Defaults to the fence token issuer | | trustedIssuers.defaultPassportIssuer | string | `""` | The default issuer for passports to be used if a given auth resource isn't provided. | +| trustedIssuers.defaultPreferredType | string | `"BearerAuth"` | The default preferred supported_type. This will ensure indexd return this supported_type before the other. | | useSingleTable | string | `"False"` | | | uwsgi | map | `{"listen":1024}` | Values for overriding uwsgi settings | | volumeMounts | list | `[{"mountPath":"/etc/uwsgi/uwsgi.ini","name":"uwsgi-config","subPath":"uwsgi.ini"},{"mountPath":"/var/www/indexd/local_settings.py","name":"config-volume","readOnly":true,"subPath":"local_settings.py"},{"mountPath":"/indexd/deployment/wsgi/gunicorn.conf.py","name":"gunicorn-conf","readOnly":true,"subPath":"gunicorn.conf.py"}]` | Volumes to mount to the container. | diff --git a/helm/indexd/indexd-settings/local_settings.py b/helm/indexd/indexd-settings/local_settings.py index b87b72414..766684fca 100644 --- a/helm/indexd/indexd-settings/local_settings.py +++ b/helm/indexd/indexd-settings/local_settings.py @@ -106,4 +106,9 @@ if default_passport_issuer: CONFIG["DEFAULT_PASSPORT_ISSUER"] = default_passport_issuer +default_preferred_type = environ.get("DEFAULT_PREFERRED_TYPE", None) + +if default_preferred_type: + CONFIG["DEFAULT_PREFERRED_TYPE"] = default_preferred_type + settings = {"config": CONFIG, "auth": AUTH} diff --git a/helm/indexd/templates/deployment.yaml b/helm/indexd/templates/deployment.yaml index a9dcfb0c8..ab999c487 100644 --- a/helm/indexd/templates/deployment.yaml +++ b/helm/indexd/templates/deployment.yaml @@ -94,6 +94,8 @@ spec: value: {{ default (printf "https://%s/user" .Values.global.hostname) .Values.trustedIssuers.defaultBearerIssuer | quote }} - name: DEFAULT_PASSPORT_ISSUER value: {{ .Values.trustedIssuers.defaultPassportIssuer | quote }} + - name: DEFAULT_PREFERRED_TYPE + value: {{ .Values.trustedIssuers.defaultPreferredType | quote }} - name: CLOUD_PROVIDER_MAP value: {{ .Values.cloudProviderMap | toJson | quote }} {{- toYaml .Values.env | nindent 12 }} diff --git a/helm/indexd/values.yaml b/helm/indexd/values.yaml index b916f2417..f5ce02485 100644 --- a/helm/indexd/values.yaml +++ b/helm/indexd/values.yaml @@ -297,12 +297,15 @@ cloudProviderMap: # -- (map) Maps an arborist resource to the issuers for passports and bearer tokens. trustedIssuers: + # -- (string) The default preferred supported_type. This will ensure indexd return this supported_type before the other. + defaultPreferredType: "BearerAuth" # -- (string) The default issuer for bearer tokens to be used if a given auth resource isn't provided. Defaults to the fence token issuer defaultBearerIssuer: "" # -- (string) The default issuer for passports to be used if a given auth resource isn't provided. defaultPassportIssuer: "" # Example: # "/programs/parent": + # preferred_type: "PassportAuth" # passport_auth_issuers: # - "https://stsstg.nih.gov" # bearer_auth_issuers: diff --git a/helm/revproxy/Chart.yaml b/helm/revproxy/Chart.yaml index d49fe0ede..d2ce7a4f6 100644 --- a/helm/revproxy/Chart.yaml +++ b/helm/revproxy/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.70 +version: 0.1.71 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/revproxy/README.md b/helm/revproxy/README.md index 3b2b6ba8a..3f227bff6 100644 --- a/helm/revproxy/README.md +++ b/helm/revproxy/README.md @@ -1,6 +1,6 @@ # revproxy -![Version: 0.1.70](https://img.shields.io/badge/Version-0.1.70-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.1.71](https://img.shields.io/badge/Version-0.1.71-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 revproxy diff --git a/helm/revproxy/gen3.nginx.conf/fence-service-ga4gh.conf b/helm/revproxy/gen3.nginx.conf/fence-service-ga4gh.conf index af8c1d3d6..401c03b8b 100644 --- a/helm/revproxy/gen3.nginx.conf/fence-service-ga4gh.conf +++ b/helm/revproxy/gen3.nginx.conf/fence-service-ga4gh.conf @@ -11,3 +11,17 @@ location ~ \/ga4gh\/drs\/v1\/objects\/(.*)\/access { proxy_connect_timeout 400; proxy_pass $upstream; } + +location ~ \/ga4gh\/drs\/v1\/objects\/access { + if ($csrf_check !~ ^ok-\S.+$) { + return 403 "failed csrf check"; + } + + set $proxy_service "presigned-url-fence"; + set $upstream http://presigned-url-fence-service$des_domain; + rewrite ^/user/(.*) /$1 break; + proxy_read_timeout 400; + proxy_send_timeout 400; + proxy_connect_timeout 400; + proxy_pass $upstream; +} From fbbd6200cbcda19a42ad8f485a5b62dfb548a95a Mon Sep 17 00:00:00 2001 From: Kyle Burton Date: Tue, 11 Aug 2026 13:14:28 -0500 Subject: [PATCH 180/196] Bumping Gen3 version --- helm/gen3/Chart.yaml | 2 +- helm/gen3/README.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index 045a11e77..32cd8bb67 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -217,7 +217,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.81 +version: 0.3.82 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index c93d2c374..c1e7e2a1b 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,6 +1,6 @@ # gen3 -![Version: 0.3.81](https://img.shields.io/badge/Version-0.3.81-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Version: 0.3.82](https://img.shields.io/badge/Version-0.3.82-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons From dbf7279896e60fd694d3a231c6f48b3565fefff6 Mon Sep 17 00:00:00 2001 From: Jawad Date: Mon, 10 Aug 2026 11:25:32 -0500 Subject: [PATCH 181/196] feat(ci): derive chart versions from git tags Adds .github/scripts/release.py, which works out chart versions at release time instead of reading them from Chart.yaml. Three subcommands: plan which charts a merge should publish, and at what version stamp write those versions into the working tree (never committed) publish package, upload releases, then merge the repo index `plan` is side-effect free so PR CI can preview a merge using the same code path the release job runs. The publish set is the charts a merge touched plus everything that depends on them, resolved through the file:// dependency graph. Previously a change to `common` bumped only itself and its ~42 dependents shipped unpublished. Two things the old bash hook got wrong are handled explicitly: - Tag lookup sorts semantically. `git tag -l 'fence-*' | sort | tail -1` returns fence-0.1.9, not fence-0.1.82. - Tag names are matched anchored and in full, so gen3-workflow-0.1.29 is not read as a `gen3` tag. A `gen3-*` glob matches 7 different charts. Also drops the pre-commit bump hook and git-hook/helm-bump.sh, which have nothing left to do. Besides being obsolete, the script diffed against the local `master` rather than origin/master, so a stale local branch produced wrong bumps. helm-docs now renders from a shared .helm-docs/README.md.gotmpl that omits the version badge and the dependency version column, since both would show the frozen placeholder on every chart. The READMEs link to the releases page instead. --- .github/scripts/release.py | 508 ++++++++++++++++++++++++++++++++++++ .helm-docs/README.md.gotmpl | 33 +++ .pre-commit-config.yaml | 13 +- git-hook/helm-bump.sh | 116 -------- 4 files changed, 544 insertions(+), 126 deletions(-) create mode 100755 .github/scripts/release.py create mode 100644 .helm-docs/README.md.gotmpl delete mode 100755 git-hook/helm-bump.sh diff --git a/.github/scripts/release.py b/.github/scripts/release.py new file mode 100755 index 000000000..6f966ec48 --- /dev/null +++ b/.github/scripts/release.py @@ -0,0 +1,508 @@ +#!/usr/bin/env python3 +"""Compute, stamp and publish Helm chart versions. + +Chart versions are frozen at a placeholder (0.0.0) in git. The real version is +derived from the existing ``-X.Y.Z`` git tags at release time and stamped +into a throwaway working tree just before packaging, so nothing is hardcoded in +the repo and nothing has to be bumped in a PR. + +Subcommands: + + plan --base SHA --head SHA compute the publish set; no side effects + stamp --plan plan.json rewrite Chart.yaml versions in the worktree + publish --plan plan.json package charts and upload releases + index + +``plan`` is pure so that PR CI can run the exact same code path as the release +job to preview what a merge would publish. +""" + +from __future__ import annotations + +import argparse +import json +import os +import re +import shutil +import subprocess +import sys +from collections import defaultdict, deque +from pathlib import Path + +import yaml + +HELM_DIR = Path("helm") +PLACEHOLDER = "0.0.0" +BASE_VERSION = "0.1.0" +FILE_PREFIX = "file://" + +# Anchored on exactly three numeric components so that the chart name is +# captured in full. Keying on the full name is what keeps `gen3-workflow-0.1.29` +# from being read as a `gen3` tag -- a `gen3-*` glob matches 7 different charts. +TAG_RE = re.compile(r"^(?P.+)-(?P\d+\.\d+\.\d+)$") + + +# -------------------------------------------------------------------------- +# git helpers +# -------------------------------------------------------------------------- + + +def git(*args: str, check: bool = True) -> str: + proc = subprocess.run( + ["git", *args], capture_output=True, text=True, check=False + ) + if check and proc.returncode != 0: + raise SystemExit(f"git {' '.join(args)} failed: {proc.stderr.strip()}") + return proc.stdout.strip() + + +def rev_exists(rev: str) -> bool: + return ( + subprocess.run( + ["git", "cat-file", "-e", f"{rev}^{{commit}}"], + capture_output=True, + ).returncode + == 0 + ) + + +def is_ancestor(a: str, b: str) -> bool: + return ( + subprocess.run( + ["git", "merge-base", "--is-ancestor", a, b], capture_output=True + ).returncode + == 0 + ) + + +def resolve_base(before: str | None, head: str) -> str | None: + """Pick the ref to diff against for a push event. + + Returns None when no trustworthy base exists. Callers must treat that as a + hard error rather than silently falling back to "publish everything" -- an + accidental ~50-chart release burst is far worse than a skipped run, and a + skipped run self-heals on the next merge. + """ + if not before or set(before) == {"0"}: + return None # branch creation / initial push + if not rev_exists(before): + return None # garbage collected after a force-push + if not is_ancestor(before, head): + # Force-push: `before..head` would silently under-report. + merge_base = git("merge-base", before, head, check=False) + if merge_base: + return merge_base + parent = git("rev-parse", f"{head}^1", check=False) + return parent or None + return before + + +def changed_paths(base: str, head: str) -> list[str]: + out = git("diff", "--name-only", f"{base}..{head}") + return [line for line in out.splitlines() if line.strip()] + + +# -------------------------------------------------------------------------- +# chart discovery and dependency graph +# -------------------------------------------------------------------------- + + +def load_charts() -> dict[str, dict]: + """Map chart *name* -> {dir, meta}. + + Keyed on the declared ``name:``, never the directory: helm/observability + declares ``name: lgtma-chart`` and owns the ``lgtma-chart-*`` tag line. + """ + charts: dict[str, dict] = {} + for chart_yaml in sorted(HELM_DIR.glob("*/Chart.yaml")): + meta = yaml.safe_load(chart_yaml.read_text()) or {} + name = meta.get("name") + if not name: + raise SystemExit(f"{chart_yaml} has no name:") + if name in charts: + # Turns a silent clobber (two charts publishing under one name, + # last writer wins) into a loud failure. + raise SystemExit( + f"duplicate chart name {name!r}: " + f"{charts[name]['dir']} and {chart_yaml.parent}" + ) + charts[name] = {"dir": chart_yaml.parent, "meta": meta} + return charts + + +def local_dep_target(dep: dict, chart_dir: Path, charts: dict[str, dict]) -> str | None: + """Resolve a file:// dependency to a chart name, by path. + + The path is authoritative; the dep's own ``name:`` field is only checked for + consistency. + """ + repo = str(dep.get("repository") or "") + if not repo.startswith(FILE_PREFIX): + return None + target_dir = (chart_dir / repo[len(FILE_PREFIX) :]).resolve() + for name, chart in charts.items(): + if chart["dir"].resolve() == target_dir: + declared = dep.get("name") + if declared and declared != name: + raise SystemExit( + f"{chart_dir}/Chart.yaml declares dependency name " + f"{declared!r} but {repo} resolves to chart {name!r}" + ) + return name + raise SystemExit(f"{chart_dir}/Chart.yaml: {repo} does not resolve to a chart") + + +def reverse_deps(charts: dict[str, dict]) -> dict[str, set[str]]: + """dep name -> set of charts that depend on it (file:// edges only).""" + rdeps: dict[str, set[str]] = defaultdict(set) + for name, chart in charts.items(): + for dep in chart["meta"].get("dependencies") or []: + target = local_dep_target(dep, chart["dir"], charts) + if target: + rdeps[target].add(name) + return rdeps + + +def transitive_closure(seeds: set[str], rdeps: dict[str, set[str]]) -> set[str]: + seen = set(seeds) + queue = deque(seeds) + while queue: + for parent in rdeps.get(queue.popleft(), ()): + if parent not in seen: + seen.add(parent) + queue.append(parent) + return seen + + +def charts_from_paths(paths: list[str], charts: dict[str, dict]) -> set[str]: + """Map changed file paths to chart names via their helm/

/ component.""" + by_dir = {chart["dir"].name: name for name, chart in charts.items()} + touched: set[str] = set() + for path in paths: + parts = Path(path).parts + if len(parts) < 3 or parts[0] != HELM_DIR.name: + continue + # helm//charts/** is vendored build output, not a source change. + if len(parts) > 2 and parts[2] == "charts": + continue + name = by_dir.get(parts[1]) + if name: + touched.add(name) + return touched + + +# -------------------------------------------------------------------------- +# version derivation +# -------------------------------------------------------------------------- + + +def version_key(version: str) -> tuple[int, ...]: + return tuple(int(part) for part in version.split(".")) + + +def tags_by_chart() -> dict[str, list[str]]: + index: dict[str, list[str]] = defaultdict(list) + for tag in git("tag", "--list").splitlines(): + match = TAG_RE.match(tag.strip()) + if match: + index[match.group("name")].append(match.group("version")) + return index + + +def release_exists(tag: str) -> bool: + if not os.environ.get("GITHUB_TOKEN") and not os.environ.get("CR_TOKEN"): + return False + return ( + subprocess.run( + ["gh", "release", "view", tag], capture_output=True + ).returncode + == 0 + ) + + +def next_version(name: str, index: dict[str, list[str]], check_releases: bool = False) -> str: + versions = index.get(name) + if not versions: + return BASE_VERSION + # Semantic, not lexical: sorted() would pick fence-0.1.9 over fence-0.1.82. + highest = max(versions, key=version_key) + major, minor, patch = version_key(highest) + candidate = f"{major}.{minor}.{patch + 1}" + if check_releases: + # A prior run may have created the release but died before tagging. + while release_exists(f"{name}-{candidate}"): + patch += 1 + candidate = f"{major}.{minor}.{patch + 1}" + if candidate == PLACEHOLDER: + raise SystemExit(f"refusing to publish placeholder version for {name}") + return candidate + + +# -------------------------------------------------------------------------- +# stamping +# -------------------------------------------------------------------------- + + +def stamp_version(chart_yaml: Path, version: str) -> None: + """Rewrite the top-level version: line, preserving everything else. + + Dependency versions are indented, so anchoring at column 0 is unambiguous. + A line-oriented edit keeps the explanatory comment blocks intact. + """ + text = chart_yaml.read_text() + new_text, count = re.subn( + r"^version:.*$", f"version: {version}", text, count=1, flags=re.M + ) + if count != 1: + raise SystemExit(f"{chart_yaml}: expected exactly one top-level version:") + chart_yaml.write_text(new_text) + + +def stamp_dependencies(chart_yaml: Path, versions: dict[str, str], charts: dict[str, dict]) -> None: + """Point each file:// dependency at the version we are about to publish. + + Not required for resolution -- Chart.lock and the vendored subchart copies + already carry concrete versions -- but `helm show chart` is what consumers + read, and "*" tells them nothing. + """ + meta = yaml.safe_load(chart_yaml.read_text()) or {} + deps = meta.get("dependencies") or [] + if not deps: + return + chart_dir = chart_yaml.parent + lines = chart_yaml.read_text().splitlines(keepends=True) + + # Walk the dependency list textually so comments and key order survive. + current: str | None = None + for i, line in enumerate(lines): + name_match = re.match(r"^\s*-\s+name:\s*(\S+)", line) + if name_match: + current = name_match.group(1) + continue + version_match = re.match(r"^(\s+version:\s*)(\S+)(.*)$", line) + if version_match and current: + dep = next((d for d in deps if d.get("name") == current), None) + if dep is None: + continue + target = local_dep_target(dep, chart_dir, charts) + if target and target in versions: + lines[i] = f"{version_match.group(1)}{versions[target]}\n" + current = None + chart_yaml.write_text("".join(lines)) + + +# -------------------------------------------------------------------------- +# subcommands +# -------------------------------------------------------------------------- + + +def build_plan(base: str | None, head: str, all_charts: bool) -> dict: + charts = load_charts() + rdeps = reverse_deps(charts) + + if all_charts: + selected = set(charts) + directly = selected + else: + if base is None: + raise SystemExit( + "could not determine a trustworthy base commit (initial push, " + "force-push, or gc'd ref). Re-run via workflow_dispatch with an " + "explicit --base, or pass --all deliberately." + ) + directly = charts_from_paths(changed_paths(base, head), charts) + selected = transitive_closure(directly, rdeps) + + index = tags_by_chart() + entries = [] + for name in sorted(selected): + entries.append( + { + "name": name, + "dir": str(charts[name]["dir"]), + "version": next_version(name, index), + "previous": max(index.get(name, ["-"]), key=lambda v: version_key(v)) + if index.get(name) + else None, + "direct": name in directly, + } + ) + return {"base": base, "head": head, "charts": entries} + + +def cmd_plan(args: argparse.Namespace) -> int: + base = args.base + if base is None and not args.all: + base = resolve_base(os.environ.get("GITHUB_EVENT_BEFORE"), args.head) + plan = build_plan(base, args.head, args.all) + + if args.markdown: + entries = plan["charts"] + if not entries: + print("## Chart releases\n\nNo charts would be published by this change.") + return 0 + cascaded = sum(1 for e in entries if not e["direct"]) + print(f"## Chart releases ({len(entries)} charts)\n") + if cascaded: + print( + f"{len(entries) - cascaded} directly changed, " + f"{cascaded} cascaded via dependencies.\n" + ) + print("| Chart | Current | Would publish | Reason |") + print("| --- | --- | --- | --- |") + for e in entries: + reason = "changed" if e["direct"] else "depends on a changed chart" + print(f"| {e['name']} | {e['previous'] or '-'} | {e['version']} | {reason} |") + else: + print(json.dumps(plan, indent=2)) + + if args.output: + Path(args.output).write_text(json.dumps(plan, indent=2)) + return 0 + + +def cmd_stamp(args: argparse.Namespace) -> int: + plan = json.loads(Path(args.plan).read_text()) + charts = load_charts() + versions = {e["name"]: e["version"] for e in plan["charts"]} + + for entry in plan["charts"]: + stamp_version(Path(entry["dir"]) / "Chart.yaml", entry["version"]) + # Second pass: every chart being published points its local deps at the + # versions we just assigned. + for entry in plan["charts"]: + stamp_dependencies(Path(entry["dir"]) / "Chart.yaml", versions, charts) + + for entry in plan["charts"]: + print(f"stamped {entry['name']} -> {entry['version']}") + return 0 + + +def count_index_versions( + pages_branch: str, index_path: str, fetch: bool = False +) -> int | None: + """Total chart versions listed in the published index.yaml. + + Used to assert the index never shrinks: it carries ~1700 versions, and + replacing rather than merging it would break every consumer pinned to an + older release. Returns None if the index can't be read, so a missing branch + doesn't fail the run on its own. + """ + if fetch: + subprocess.run( + ["git", "fetch", "origin", pages_branch], capture_output=True + ) + for ref in (f"origin/{pages_branch}", pages_branch): + raw = git("show", f"{ref}:{index_path}", check=False) + if raw: + entries = (yaml.safe_load(raw) or {}).get("entries") or {} + return sum(len(v or []) for v in entries.values()) + return None + + +def clean_vendored(chart_dir: Path) -> None: + """Remove build artifacts so each package is resolved from a clean slate. + + Both the chart's own charts/ dir and any nested ones left by a sibling's + earlier `dependency update`. Chart.lock goes too, since a stale lock makes + `dependency build` resolve the wrong versions. + """ + for path in [chart_dir / "charts", *chart_dir.glob("charts/*/charts")]: + if path.is_dir(): + shutil.rmtree(path) + lock = chart_dir / "Chart.lock" + if lock.exists(): + lock.unlink() + + +def cmd_publish(args: argparse.Namespace) -> int: + plan = json.loads(Path(args.plan).read_text()) + packages = Path(args.packages) + packages.mkdir(parents=True, exist_ok=True) + + for entry in plan["charts"]: + chart_dir = Path(entry["dir"]) + # Resolve dependencies immediately before packaging this chart, and + # clean first. Leftover charts/ dirs from a previous chart's resolution + # get vendored a second level deep (e.g. gen3/charts/fence/charts/common), + # and the nested copy shadows the parent's global values at render time. + clean_vendored(chart_dir) + # Always `update`: despite the !helm/funnel/charts gitignore exception, + # no helm/*/charts/* files are actually tracked, so there are no + # committed tarballs to preserve and the lock file may be stale. + subprocess.run(["helm", "dependency", "update", str(chart_dir)], check=True) + subprocess.run( + ["helm", "package", str(chart_dir), "-d", str(packages)], check=True + ) + # Don't leave this chart's vendored deps behind for the next one. + clean_vendored(chart_dir) + print(f"packaged {entry['name']}-{entry['version']}") + + if args.package_only: + return 0 + + owner, repo = args.repo.split("/", 1) + subprocess.run( + [ + "cr", "upload", + "-o", owner, + "-r", repo, + "--package-path", str(packages), + "--skip-existing", + "--make-release-latest=false", + ], + check=True, + ) + before = count_index_versions(args.pages_branch, args.index_path) + subprocess.run( + [ + "cr", "index", + "-o", owner, + "-r", repo, + "--package-path", str(packages), + "--index-path", args.index_path, + "--pages-branch", args.pages_branch, + "--push", + ], + check=True, + ) + after = count_index_versions(args.pages_branch, args.index_path, fetch=True) + if before is not None and after is not None and after < before: + raise SystemExit( + f"index shrank {before} -> {after} versions; the published repo has " + "lost entries and consumers pinning old versions will break" + ) + print(f"index versions: {before} -> {after}") + return 0 + + +def main() -> int: + parser = argparse.ArgumentParser(description=__doc__) + sub = parser.add_subparsers(dest="command", required=True) + + p = sub.add_parser("plan", help="compute the publish set (no side effects)") + p.add_argument("--base") + p.add_argument("--head", default="HEAD") + p.add_argument("--all", action="store_true", help="select every chart") + p.add_argument("--markdown", action="store_true") + p.add_argument("--output") + p.set_defaults(func=cmd_plan) + + s = sub.add_parser("stamp", help="write real versions into the working tree") + s.add_argument("--plan", required=True) + s.set_defaults(func=cmd_stamp) + + u = sub.add_parser("publish", help="package and upload") + u.add_argument("--plan", required=True) + u.add_argument("--repo", default="uc-cdis/gen3-helm") + u.add_argument("--packages", default=".cr-release-packages") + u.add_argument("--index-path", default="index.yaml") + u.add_argument("--pages-branch", default="gh-pages") + u.add_argument("--package-only", action="store_true") + u.set_defaults(func=cmd_publish) + + args = parser.parse_args() + return args.func(args) + + +if __name__ == "__main__": + sys.exit(main()) diff --git a/.helm-docs/README.md.gotmpl b/.helm-docs/README.md.gotmpl new file mode 100644 index 000000000..5028432b2 --- /dev/null +++ b/.helm-docs/README.md.gotmpl @@ -0,0 +1,33 @@ +{{ template "chart.header" . }} + +{{/* + Chart versions are frozen at a placeholder in git and derived from git tags + when the chart is published, so the version badge and the dependency version + column would only ever show "0.0.0" and "*". They are omitted here rather + than rendered misleadingly -- see the releases page for published versions. +*/}} +![Type: {{ .Type }}](https://img.shields.io/badge/Type-{{ .Type }}-informational?style=flat-square) {{ if .AppVersion }}![AppVersion: {{ .AppVersion }}](https://img.shields.io/badge/AppVersion-{{ .AppVersion | replace "-" "--" }}-informational?style=flat-square){{ end }} + +{{ template "chart.description" . }} + +{{ template "chart.homepageLine" . }} + +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + +{{ template "chart.maintainersSection" . }} + +{{ template "chart.sourcesSection" . }} + +{{ if .Dependencies }} +## Requirements + +| Repository | Name | +|------------|------| +{{- range .Dependencies }} +| {{ .Repository }} | {{ .Name }} | +{{- end }} +{{ end }} + +{{ template "chart.valuesSection" . }} diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index 9b3400a35..ad0267df8 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -28,13 +28,6 @@ repos: args: - "--chart-search-root=helm" - "--skip-version-footer" - - - repo: local - hooks: - - id: helm-chart-bump - args: [] - description: Updates the .Chart.yaml with updates version if there are changes since master branch. This is to ensure we bump our charts for updates. - entry: git-hook/helm-bump.sh - language: script - name: Helm Docs - require_serial: true \ No newline at end of file + # Shared template: omits the version badge and dependency version + # column, which are frozen placeholders in git rather than real values. + - "--template-files=/helm-docs/.helm-docs/README.md.gotmpl" \ No newline at end of file diff --git a/git-hook/helm-bump.sh b/git-hook/helm-bump.sh deleted file mode 100755 index 54180601a..000000000 --- a/git-hook/helm-bump.sh +++ /dev/null @@ -1,116 +0,0 @@ -#!/bin/bash - -function bump_semver() { - # Get the current version - version=$1 - - # Split the version into its components - IFS='.' read -r -a version_components <<< "$version" - - # Increment the patch version - version_components[2]=$((version_components[2] + 1)) - - # Reassemble the version string - new_version="${version_components[0]}.${version_components[1]}.${version_components[2]}" - - # Print the new version - echo $new_version -} - -# Array to track which charts were updated -declare -a updated_charts=() - -diff=$(git diff --name-only master helm/* | awk -F '/' '{print $2}' | sort -u) - -for i in $diff; do - # Skip processing the gen3 umbrella chart in the first loop - if [[ "$i" == "gen3" ]]; then - continue - fi - - if git show master:helm/$i/Chart.yaml > /dev/null 2>&1; then - current_version=$(grep -E '^version:' helm/$i/Chart.yaml | awk '{print $2}') - master_version=$(git show master:helm/$i/Chart.yaml | grep -E '^version:' | awk '{print $2}') - if [[ "${current_version}" == "${master_version}" ]]; then - new_version=$(bump_semver $current_version) - echo "Bumping chart version in $i to $new_version" - # Creating a backup file so sed command works on both linux and mac - sed -i.bak "s#^version:.*#version: ${new_version/v/}#g" "helm/$i/Chart.yaml" && rm "helm/$i/Chart.yaml.bak" - - # Track this chart as updated - updated_charts+=("$i") - else - echo "Chart $i already has version bumped from $master_version to $current_version" - # Still track it as updated since it has changes - updated_charts+=("$i") - fi - else - echo "No Chart.yaml for $i in master branch. Maybe it's a new chart?" - # Track new charts too - updated_charts+=("$i") - fi -done - -# Now handle the gen3 umbrella chart -umbrella_chart_path="helm/gen3/Chart.yaml" -umbrella_needs_update=false - -# Check if gen3 umbrella chart itself was modified -if echo "$diff" | grep -q "^gen3$"; then - umbrella_needs_update=true -fi - -# Check if umbrella chart version needs bumping -if git show master:$umbrella_chart_path > /dev/null 2>&1; then - current_umbrella_version=$(grep -E '^version:' $umbrella_chart_path | awk '{print $2}') - master_umbrella_version=$(git show master:$umbrella_chart_path | grep -E '^version:' | awk '{print $2}') - - # Update dependency versions for changed charts - for chart in "${updated_charts[@]}"; do - # Get the new version of the dependency chart - if [[ -f "helm/$chart/Chart.yaml" ]]; then - new_dep_version=$(grep -E '^version:' helm/$chart/Chart.yaml | awk '{print $2}') - - # Update the dependency version in umbrella chart - # Look for the dependency entry and update its version - if grep -q "name: $chart" $umbrella_chart_path; then - echo "Updating $chart dependency version to $new_dep_version in umbrella chart" - # Use awk to update the version line that comes after the matching name - awk -v chart="$chart" -v new_version="$new_dep_version" ' - /^ - name: / { in_dep = ($3 == chart) } - /^ version: / && in_dep { - print " version: " new_version - in_dep = 0 - next - } - { print } - ' $umbrella_chart_path > ${umbrella_chart_path}.tmp && mv ${umbrella_chart_path}.tmp $umbrella_chart_path - - umbrella_needs_update=true - fi - fi - done - - # Bump umbrella chart version if needed - if [[ "$umbrella_needs_update" == "true" ]]; then - if [[ "${current_umbrella_version}" == "${master_umbrella_version}" ]]; then - new_umbrella_version=$(bump_semver $current_umbrella_version) - echo "Bumping gen3 umbrella chart version to $new_umbrella_version" - sed -i.bak "s#^version:.*#version: ${new_umbrella_version/v/}#g" "$umbrella_chart_path" && rm "${umbrella_chart_path}.bak" - else - echo "Gen3 umbrella chart version already bumped from $master_umbrella_version to $current_umbrella_version" - fi - fi -else - echo "No umbrella Chart.yaml found in master branch" -fi - -# Handle common chart special case -if printf '%s\n' "${updated_charts[@]}" | grep -q "^common$"; then - echo "Common chart was updated - this affects all charts that depend on it" - # You might want to add logic here to bump versions of charts that depend on common - # For now, just print a warning - echo "WARNING: Common chart updated. Consider if other chart versions need manual bumping." -fi - -echo "Charts updated: ${updated_charts[*]}" \ No newline at end of file From d5b24e0ee35e4a3a40c22732818b74596ba691f6 Mon Sep 17 00:00:00 2001 From: Jawad Date: Mon, 10 Aug 2026 11:28:31 -0500 Subject: [PATCH 182/196] feat: freeze chart versions in git, resolve them at release time Every Chart.yaml is pinned at the placeholder `version: 0.0.0`, and every dependency between charts in this repo becomes `version: "*"`. Real versions are derived from the existing -X.Y.Z git tags when a chart is published and stamped into the CI working tree only. Why: keeping a hand-maintained version in Chart.yaml, duplicated again in the gen3 umbrella's dependency block, meant every PR carried a version bump. Those bumps conflicted between concurrent PRs and went stale while a PR sat open, and the whole thing was enforced by a pre-commit hook that got it wrong often enough to matter. What changes for contributors: nothing to bump. The "Lint and Test Charts" job summary shows what a merge would publish, including charts pulled in by the dependency cascade. Release workflow now runs plan -> stamp -> publish via the cr CLI rather than chart-releaser-action. The action publishes any chart whose version has no release, which with frozen versions would have published -0.0.0 for all 51 charts on the first run and permanently polluted the index. It also now adds the elastic, grafana and calypr repos -- only bitnami was added before, so `helm dep up` on metadata, alloy, faro-collector and observability was relying on those repos already being present. ct.yaml turns off check-version-increment, which would otherwise fail every PR. Fixes the list-changed quoting bug (`echo "changed=true >> $GITHUB_OUTPUT"` wrote a literal string to stdout and never set the output). Verified locally against helm v3.10.0 (the version CI pins), on all 51 charts: - `helm dependency update` succeeds for all 50 non-library charts with wildcard file:// deps; a 0.0.0 placeholder resolves but a 0.0.0-dev one does not, since Helm's semver matcher excludes prereleases from "*" - packaged artifacts carry concrete versions in Chart.lock and in every vendored subchart; no placeholder reaches a published chart - gen3-0.3.80.tgz renders standalone (146 resources, unchanged) - unpacking the new gen3 package and diffing it against one built from master shows no differences outside Chart.yaml/Chart.lock - rendered output matches master except chart/version labels; the remaining diffs are randomly generated secrets that also differ between two renders of the same artifact - `ct lint --all` passes The .secrets.baseline change is line-number churn from the shorter READMEs; the same five tracked secrets are present before and after. --- .github/ct.yaml | 4 +- .github/scripts/release.py | 45 ++++++-- .github/workflows/lint_test.yaml | 12 ++- .github/workflows/release.yaml | 84 +++++++++++++-- .gitignore | 4 + .pre-commit-config.yaml | 5 +- .secrets.baseline | 6 +- CONTRIBUTING.md | 51 ++++++--- helm/access-backend/Chart.yaml | 4 +- helm/access-backend/README.md | 12 ++- helm/alloy/Chart.yaml | 2 +- helm/alloy/README.md | 12 ++- helm/ambassador/Chart.yaml | 4 +- helm/ambassador/README.md | 12 ++- helm/arborist/Chart.yaml | 4 +- helm/arborist/README.md | 14 ++- helm/argo-wrapper/Chart.yaml | 4 +- helm/argo-wrapper/README.md | 12 ++- helm/audit/Chart.yaml | 4 +- helm/audit/README.md | 14 ++- helm/aws-es-proxy/Chart.yaml | 4 +- helm/aws-es-proxy/README.md | 12 ++- helm/aws-sigv4-proxy/Chart.yaml | 4 +- helm/aws-sigv4-proxy/README.md | 12 ++- helm/cedar/Chart.yaml | 4 +- helm/cedar/README.md | 12 ++- helm/cluster-level-resources/Chart.yaml | 2 +- helm/cluster-level-resources/README.md | 6 +- helm/cohort-middleware/Chart.yaml | 4 +- helm/cohort-middleware/README.md | 12 ++- helm/common/Chart.yaml | 2 +- helm/common/README.md | 6 +- helm/dashboard/Chart.yaml | 4 +- helm/dashboard/README.md | 12 ++- helm/data-upload-cron/Chart.yaml | 4 +- helm/data-upload-cron/README.md | 12 ++- helm/datareplicate/Chart.yaml | 4 +- helm/datareplicate/README.md | 12 ++- helm/dicom-server/Chart.yaml | 4 +- helm/dicom-server/README.md | 12 ++- helm/embedding-management-service/Chart.yaml | 4 +- helm/embedding-management-service/README.md | 12 ++- helm/etl/Chart.yaml | 2 +- helm/etl/README.md | 6 +- helm/faro-collector/Chart.yaml | 6 +- helm/faro-collector/README.md | 16 +-- helm/fence/Chart.yaml | 4 +- helm/fence/README.md | 14 ++- helm/frontend-framework/Chart.yaml | 4 +- helm/frontend-framework/README.md | 12 ++- helm/funnel/Chart.yaml | 4 +- helm/funnel/README.md | 12 ++- helm/gen3-analysis/Chart.yaml | 4 +- helm/gen3-analysis/README.md | 12 ++- helm/gen3-embeddings/Chart.yaml | 4 +- helm/gen3-embeddings/README.md | 14 ++- helm/gen3-network-policies/Chart.yaml | 2 +- helm/gen3-network-policies/README.md | 6 +- helm/gen3-user-data-library/Chart.yaml | 4 +- helm/gen3-user-data-library/README.md | 14 ++- helm/gen3-workflow/Chart.yaml | 4 +- helm/gen3-workflow/README.md | 12 ++- helm/gen3/Chart.yaml | 94 ++++++++-------- helm/gen3/README.md | 106 ++++++++++--------- helm/guppy/Chart.yaml | 4 +- helm/guppy/README.md | 12 ++- helm/hatchery/Chart.yaml | 4 +- helm/hatchery/README.md | 12 ++- helm/indexd/Chart.yaml | 4 +- helm/indexd/README.md | 14 ++- helm/jeg/Chart.yaml | 4 +- helm/jeg/README.md | 12 ++- helm/manifestservice/Chart.yaml | 4 +- helm/manifestservice/README.md | 12 ++- helm/metadata/Chart.yaml | 4 +- helm/metadata/README.md | 16 +-- helm/neuvector/Chart.yaml | 2 +- helm/neuvector/README.md | 6 +- helm/observability/Chart.yaml | 2 +- helm/observability/README.md | 12 ++- helm/ohdsi-atlas/Chart.yaml | 2 +- helm/ohdsi-atlas/README.md | 6 +- helm/ohdsi-webapi/Chart.yaml | 4 +- helm/ohdsi-webapi/README.md | 14 ++- helm/ohif-viewer/Chart.yaml | 4 +- helm/ohif-viewer/README.md | 12 ++- helm/orthanc/Chart.yaml | 4 +- helm/orthanc/README.md | 12 ++- helm/peregrine/Chart.yaml | 4 +- helm/peregrine/README.md | 14 ++- helm/portal/Chart.yaml | 4 +- helm/portal/README.md | 12 ++- helm/requestor/Chart.yaml | 4 +- helm/requestor/README.md | 14 ++- helm/revproxy/Chart.yaml | 4 +- helm/revproxy/README.md | 12 ++- helm/sheepdog/Chart.yaml | 4 +- helm/sheepdog/README.md | 14 ++- helm/sower/Chart.yaml | 4 +- helm/sower/README.md | 12 ++- helm/ssjdispatcher/Chart.yaml | 4 +- helm/ssjdispatcher/README.md | 12 ++- helm/vectis-overlays/Chart.yaml | 4 +- helm/vectis-overlays/README.md | 12 ++- helm/workspace-proxy/Chart.yaml | 4 +- helm/workspace-proxy/README.md | 12 ++- helm/wts/Chart.yaml | 4 +- helm/wts/README.md | 14 ++- helm/zendesk-wrapper/Chart.yaml | 4 +- helm/zendesk-wrapper/README.md | 12 ++- 110 files changed, 767 insertions(+), 424 deletions(-) diff --git a/.github/ct.yaml b/.github/ct.yaml index 17d1fff20..4ee912ee4 100644 --- a/.github/ct.yaml +++ b/.github/ct.yaml @@ -8,7 +8,9 @@ chart-repos: - grafana=https://grafana.github.io/helm-charts - calypr=https://calypr.github.io/helm-charts helm-extra-args: --timeout 600s -check-version-increment: true +# Chart versions are frozen at a placeholder in git and derived from tags at +# release time, so there is no per-PR bump to enforce. +check-version-increment: false debug: false validate-maintainers: false helm-dependency-extra-args: "--skip-refresh" diff --git a/.github/scripts/release.py b/.github/scripts/release.py index 6f966ec48..58a675ea8 100755 --- a/.github/scripts/release.py +++ b/.github/scripts/release.py @@ -209,8 +209,16 @@ def tags_by_chart() -> dict[str, list[str]]: def release_exists(tag: str) -> bool: + """Whether a GitHub release already exists for this tag. + + Only an extra guard against re-using a version after a partially failed + run; the tag list is the primary source. Treats an unavailable gh CLI or + missing token as "no release" rather than failing the run. + """ if not os.environ.get("GITHUB_TOKEN") and not os.environ.get("CR_TOKEN"): return False + if shutil.which("gh") is None: + return False return ( subprocess.run( ["gh", "release", "view", tag], capture_output=True @@ -326,7 +334,25 @@ def build_plan(base: str | None, head: str, all_charts: bool) -> dict: "direct": name in directly, } ) - return {"base": base, "head": head, "charts": entries} + + # Charts that are not being released but get vendored into one that is. + # They still need a real version stamped in: an umbrella packaged with + # unstamped subcharts ships them at the 0.0.0 placeholder, and its own + # dependency block keeps the "*" constraint. Their current version is the + # newest existing tag -- they have not changed, so nothing is incremented. + vendored = [] + for name in sorted(set(charts) - selected): + versions = index.get(name) + vendored.append( + { + "name": name, + "dir": str(charts[name]["dir"]), + "version": max(versions, key=version_key) + if versions + else BASE_VERSION, + } + ) + return {"base": base, "head": head, "charts": entries, "vendored": vendored} def cmd_plan(args: argparse.Namespace) -> int: @@ -363,17 +389,22 @@ def cmd_plan(args: argparse.Namespace) -> int: def cmd_stamp(args: argparse.Namespace) -> int: plan = json.loads(Path(args.plan).read_text()) charts = load_charts() - versions = {e["name"]: e["version"] for e in plan["charts"]} + # Stamp released and merely-vendored charts alike. A released umbrella + # vendors its whole dependency tree, so any subchart left at the + # placeholder would ship inside it as 0.0.0. + everything = plan["charts"] + plan.get("vendored", []) + versions = {e["name"]: e["version"] for e in everything} - for entry in plan["charts"]: + for entry in everything: stamp_version(Path(entry["dir"]) / "Chart.yaml", entry["version"]) - # Second pass: every chart being published points its local deps at the - # versions we just assigned. - for entry in plan["charts"]: + # Second pass, once every version is known: rewrite the "*" constraints so + # the published Chart.yaml records concrete versions. + for entry in everything: stamp_dependencies(Path(entry["dir"]) / "Chart.yaml", versions, charts) for entry in plan["charts"]: - print(f"stamped {entry['name']} -> {entry['version']}") + print(f"stamped {entry['name']} -> {entry['version']} (releasing)") + print(f"stamped {len(plan.get('vendored', []))} more charts at their current version") return 0 diff --git a/.github/workflows/lint_test.yaml b/.github/workflows/lint_test.yaml index b89d8c7ca..3df233a81 100644 --- a/.github/workflows/lint_test.yaml +++ b/.github/workflows/lint_test.yaml @@ -29,9 +29,19 @@ jobs: run: | changed=$(ct list-changed --config .github/ct.yaml) if [[ -n "$changed" ]]; then - echo "changed=true >> $GITHUB_OUTPUT" + echo "changed=true" >> "$GITHUB_OUTPUT" fi + # Chart versions are frozen in git, so show what merging this PR would + # actually publish -- including charts pulled in by the dependency + # cascade (a change to common fans out to everything that depends on it). + - name: Preview chart releases + run: | + python3 .github/scripts/release.py plan \ + --base "${{ github.event.pull_request.base.sha }}" \ + --head "${{ github.event.pull_request.head.sha }}" \ + --markdown >> "$GITHUB_STEP_SUMMARY" + - name: Run chart-testing (lint) run: ct lint --config .github/ct.yaml diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index f4391ce5e..29da233ed 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -4,6 +4,23 @@ on: push: branches: - master + workflow_dispatch: + inputs: + base: + description: "Commit to diff against (recovery for a missed or force-pushed run)" + required: false + type: string + all: + description: "Release every chart, ignoring the diff" + required: false + type: boolean + default: false + +# Never run two releases at once: they would race on gh-pages, and cancelling +# mid-run can leave GitHub Releases that the index never learns about. +concurrency: + group: release-charts + cancel-in-progress: false jobs: release: @@ -12,7 +29,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout - uses: actions/checkout@v3 + uses: actions/checkout@v4 with: fetch-depth: 0 @@ -20,19 +37,70 @@ jobs: run: | git config user.name "$GITHUB_ACTOR" git config user.email "$GITHUB_ACTOR@users.noreply.github.com" - + - name: Install Helm uses: azure/setup-helm@v3 with: version: v3.10.0 - + - name: Add helm repositories run: | helm repo add bitnami https://charts.bitnami.com/bitnami + helm repo add elastic https://helm.elastic.co + helm repo add grafana https://grafana.github.io/helm-charts + helm repo add calypr https://calypr.github.io/helm-charts + helm repo update - - name: Run chart-releaser - uses: helm/chart-releaser-action@v1.4.1 - with: - charts_dir: helm + - name: Install chart-releaser + run: | + CR_VERSION=1.6.1 + curl -sSLo cr.tar.gz \ + "https://github.com/helm/chart-releaser/releases/download/v${CR_VERSION}/chart-releaser_${CR_VERSION}_linux_amd64.tar.gz" + tar -xzf cr.tar.gz cr + sudo mv cr /usr/local/bin/cr + rm cr.tar.gz + cr version + + # Versions live in git tags, not in Chart.yaml. Work out which charts this + # push touched (plus everything that depends on them) and what version + # each should be published at. + - name: Compute release plan env: - CR_TOKEN: "${{ secrets.GITHUB_TOKEN }}" + GITHUB_EVENT_BEFORE: ${{ github.event.before }} + run: | + python3 .github/scripts/release.py plan \ + --head "${{ github.sha }}" \ + ${{ inputs.base && format('--base {0}', inputs.base) || '' }} \ + ${{ inputs.all && '--all' || '' }} \ + --output plan.json + python3 .github/scripts/release.py plan \ + --head "${{ github.sha }}" \ + ${{ inputs.base && format('--base {0}', inputs.base) || '' }} \ + ${{ inputs.all && '--all' || '' }} \ + --markdown >> "$GITHUB_STEP_SUMMARY" + + - name: Check whether anything needs releasing + id: check + run: | + count=$(jq '.charts | length' plan.json) + echo "count=$count" >> "$GITHUB_OUTPUT" + echo "Charts to release: $count" + + # Stamp the computed versions into the working tree. This is never + # committed -- Chart.yaml stays at the placeholder in git. + - name: Stamp versions + if: steps.check.outputs.count != '0' + run: python3 .github/scripts/release.py stamp --plan plan.json + + # Releases first, index last: a release with no index entry is invisible + # but harmless and self-heals, whereas an index entry with no release is a + # broken download link. + - name: Package and publish + if: steps.check.outputs.count != '0' + env: + CR_TOKEN: ${{ secrets.GITHUB_TOKEN }} + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + run: | + python3 .github/scripts/release.py publish \ + --plan plan.json \ + --repo "${{ github.repository }}" diff --git a/.gitignore b/.gitignore index 9c4dbf3ce..12c0efce0 100644 --- a/.gitignore +++ b/.gitignore @@ -10,3 +10,7 @@ _sample-*/ !helm/funnel/charts helm/funnel/charts/common* *copy.yaml + +# Python bytecode +__pycache__/ +*.pyc diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index ad0267df8..b3a251200 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -30,4 +30,7 @@ repos: - "--skip-version-footer" # Shared template: omits the version badge and dependency version # column, which are frozen placeholders in git rather than real values. - - "--template-files=/helm-docs/.helm-docs/README.md.gotmpl" \ No newline at end of file + # Absolute path: pre-commit's docker_image language mounts the repo at + # /src, and helm-docs only resolves this flag as an absolute path or + # relative to each chart dir. + - "--template-files=/src/.helm-docs/README.md.gotmpl" \ No newline at end of file diff --git a/.secrets.baseline b/.secrets.baseline index 72eea1827..077d8ef79 100644 --- a/.secrets.baseline +++ b/.secrets.baseline @@ -137,14 +137,14 @@ "filename": "helm/portal/README.md", "hashed_secret": "eb9739c6625f06b4ab73035223366dda6262ae77", "is_verified": false, - "line_number": 37 + "line_number": 41 }, { "type": "Base64 High Entropy String", "filename": "helm/portal/README.md", "hashed_secret": "08eeb737b239bdb7362a875b90e22c10b8826b20", "is_verified": false, - "line_number": 42 + "line_number": 46 } ], "helm/portal/values.yaml": [ @@ -173,5 +173,5 @@ } ] }, - "generated_at": "2026-06-04T14:01:16Z" + "generated_at": "2026-08-10T16:27:55Z" } diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index c81ac0d39..09de74214 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -58,29 +58,50 @@ Each chart has its own README.md that is automatically built with [helm-docs](ht ## Helm chart release strategy -It is important to understand that when a branch is merged into the main branch, a GitHub action will generate a new helm chart release if the helm chart version in the chart.yaml file has been incremented. Consider the following example where a change to the Helm chart has been made and the contributor wants a new version to be released: - -The original Chart.yaml file: +**You do not need to bump any chart versions.** Every `Chart.yaml` in this repo +is frozen at the placeholder `version: 0.0.0`, and dependencies between charts +in this repo are declared as `version: "*"`: ```yaml apiVersion: v2 - name: Sheepdog + name: sheepdog description: A Helm chart for Kubernetes type: application - version: 0.1.0 + version: 0.0.0 # placeholder -- never edit this + dependencies: + - name: common + version: "*" # resolved locally, stamped at release time + repository: file://../common ``` -If a modification to the Helm chart is made (an update to the values.yaml file for instance) the version in Chart.yaml is incremented to `0.2.0`: +The real version is worked out when the chart is published. On a merge to +`master`, the release workflow: - ```yaml - apiVersion: v2 - name: Sheepdog - description: A Helm chart for Kubernetes - type: application - version: 0.2.0 # version updates to 0.2.0 - ``` +1. Diffs the merge to find which charts changed. +2. Adds every chart that depends on a changed chart -- so a change to `common` + republishes everything that uses it, and any subchart change republishes the + `gen3` umbrella. +3. Looks up the highest existing `-X.Y.Z` git tag for each of those + charts and increments the patch number. +4. Stamps those versions into `Chart.yaml` (in the CI working tree only -- this + is never committed), packages, and publishes. + +So if `sheepdog-0.1.47` is the latest tag and you change something under +`helm/sheepdog/`, merging produces `sheepdog-0.1.48` plus a new `gen3` release. +Nothing in the repo records that number. + +To see exactly what your PR would publish, check the **job summary** on the +"Lint and Test Charts" run -- it lists every chart that would be released, the +version it would get, and whether it was pulled in directly or by the +dependency cascade. + +Two consequences worth knowing: -Once the associated branch is merged into the main branch, the GitHub action packages and publishes an artifact, making it available for consumption. The release name is based off the 'name' field and the 'version' field in the Chart.yaml file. Given the example above, GitHub action will produce a release called `sheepdog-0.2.0`. +- A one-line change to `helm/common/` republishes ~43 charts. That is + intentional -- previously those dependents were silently left unpublished. +- Chart READMEs no longer show a version badge, since the in-repo version is + always the placeholder. Published versions are listed at + and on the [releases page](https://github.com/uc-cdis/gen3-helm/releases). ## Branch Naming Conventions @@ -114,7 +135,7 @@ Before submitting a PR for review, try to make sure you’ve accomplished these The PR: - contains a brief description of what it changes and/or adds - passes status checks -- If there are changes to the charts, it bumps the chart versions +- If there are changes to the charts, the release preview in the job summary looks right (chart versions are derived at release time -- do not bump them by hand) To merge the PR: diff --git a/helm/access-backend/Chart.yaml b/helm/access-backend/Chart.yaml index 94243d7b6..76a3ef811 100644 --- a/helm/access-backend/Chart.yaml +++ b/helm/access-backend/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.23 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "1.6.1" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common diff --git a/helm/access-backend/README.md b/helm/access-backend/README.md index e6fdd6cf5..c3c24ba50 100644 --- a/helm/access-backend/README.md +++ b/helm/access-backend/README.md @@ -1,14 +1,18 @@ # access-backend -![Version: 0.1.23](https://img.shields.io/badge/Version-0.1.23-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.6.1](https://img.shields.io/badge/AppVersion-1.6.1-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.6.1](https://img.shields.io/badge/AppVersion-1.6.1-informational?style=flat-square) A Helm chart for Kubernetes +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | +| Repository | Name | +|------------|------| +| file://../common | common | ## Values diff --git a/helm/alloy/Chart.yaml b/helm/alloy/Chart.yaml index ac429f844..8377ec932 100644 --- a/helm/alloy/Chart.yaml +++ b/helm/alloy/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.2 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/alloy/README.md b/helm/alloy/README.md index 97a37142a..8caf56baf 100644 --- a/helm/alloy/README.md +++ b/helm/alloy/README.md @@ -1,14 +1,18 @@ # alloy -![Version: 0.1.2](https://img.shields.io/badge/Version-0.1.2-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for deploying Grafana Alloy +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| https://grafana.github.io/helm-charts | alloy | 0.9.1 | +| Repository | Name | +|------------|------| +| https://grafana.github.io/helm-charts | alloy | ## Values diff --git a/helm/ambassador/Chart.yaml b/helm/ambassador/Chart.yaml index d80843d6d..4de067b5c 100644 --- a/helm/ambassador/Chart.yaml +++ b/helm/ambassador/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.40 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "1.4.2" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common diff --git a/helm/ambassador/README.md b/helm/ambassador/README.md index 2ec108d86..312614f7e 100644 --- a/helm/ambassador/README.md +++ b/helm/ambassador/README.md @@ -1,14 +1,18 @@ # ambassador -![Version: 0.1.40](https://img.shields.io/badge/Version-0.1.40-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.4.2](https://img.shields.io/badge/AppVersion-1.4.2-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.4.2](https://img.shields.io/badge/AppVersion-1.4.2-informational?style=flat-square) A Helm chart for deploying ambassador for gen3 +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | +| Repository | Name | +|------------|------| +| file://../common | common | ## Values diff --git a/helm/arborist/Chart.yaml b/helm/arborist/Chart.yaml index 03f6d5e8a..56793bfdc 100644 --- a/helm/arborist/Chart.yaml +++ b/helm/arborist/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.37 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,7 +25,7 @@ appVersion: "master" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/arborist/README.md b/helm/arborist/README.md index 08111cbb9..cc91a6821 100644 --- a/helm/arborist/README.md +++ b/helm/arborist/README.md @@ -1,15 +1,19 @@ # arborist -![Version: 0.1.37](https://img.shields.io/badge/Version-0.1.37-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 arborist +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | -| https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | +| Repository | Name | +|------------|------| +| file://../common | common | +| https://charts.bitnami.com/bitnami | postgresql | ## Values diff --git a/helm/argo-wrapper/Chart.yaml b/helm/argo-wrapper/Chart.yaml index 1bb1fdb6c..35b567a7c 100644 --- a/helm/argo-wrapper/Chart.yaml +++ b/helm/argo-wrapper/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.34 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common diff --git a/helm/argo-wrapper/README.md b/helm/argo-wrapper/README.md index aa172afca..4a238d390 100644 --- a/helm/argo-wrapper/README.md +++ b/helm/argo-wrapper/README.md @@ -1,14 +1,18 @@ # argo-wrapper -![Version: 0.1.34](https://img.shields.io/badge/Version-0.1.34-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Argo Wrapper Service +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | +| Repository | Name | +|------------|------| +| file://../common | common | ## Values diff --git a/helm/audit/Chart.yaml b/helm/audit/Chart.yaml index ae67e9a73..d51cd32d4 100644 --- a/helm/audit/Chart.yaml +++ b/helm/audit/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.47 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -24,7 +24,7 @@ appVersion: "master" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/audit/README.md b/helm/audit/README.md index 815530451..c38aff7a9 100644 --- a/helm/audit/README.md +++ b/helm/audit/README.md @@ -1,15 +1,19 @@ # audit -![Version: 0.1.47](https://img.shields.io/badge/Version-0.1.47-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for Kubernetes +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | -| https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | +| Repository | Name | +|------------|------| +| file://../common | common | +| https://charts.bitnami.com/bitnami | postgresql | ## Values diff --git a/helm/aws-es-proxy/Chart.yaml b/helm/aws-es-proxy/Chart.yaml index 1aaa10486..cdae086cd 100644 --- a/helm/aws-es-proxy/Chart.yaml +++ b/helm/aws-es-proxy/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.45 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common diff --git a/helm/aws-es-proxy/README.md b/helm/aws-es-proxy/README.md index b274d8406..61c80bc2d 100644 --- a/helm/aws-es-proxy/README.md +++ b/helm/aws-es-proxy/README.md @@ -1,14 +1,18 @@ # aws-es-proxy -![Version: 0.1.45](https://img.shields.io/badge/Version-0.1.45-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for AWS ES Proxy Service for gen3 +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | +| Repository | Name | +|------------|------| +| file://../common | common | ## Values diff --git a/helm/aws-sigv4-proxy/Chart.yaml b/helm/aws-sigv4-proxy/Chart.yaml index 6e706d725..a7115ec8a 100644 --- a/helm/aws-sigv4-proxy/Chart.yaml +++ b/helm/aws-sigv4-proxy/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.5 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common diff --git a/helm/aws-sigv4-proxy/README.md b/helm/aws-sigv4-proxy/README.md index b988c88d1..c4422188f 100644 --- a/helm/aws-sigv4-proxy/README.md +++ b/helm/aws-sigv4-proxy/README.md @@ -1,14 +1,18 @@ # aws-sigv4-proxy -![Version: 0.1.5](https://img.shields.io/badge/Version-0.1.5-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for AWS ES Proxy Service for gen3 +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | +| Repository | Name | +|------------|------| +| file://../common | common | ## Values diff --git a/helm/cedar/Chart.yaml b/helm/cedar/Chart.yaml index d2af513f9..5088eeb9c 100644 --- a/helm/cedar/Chart.yaml +++ b/helm/cedar/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.29 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common diff --git a/helm/cedar/README.md b/helm/cedar/README.md index ab2d69305..4f20d69f6 100644 --- a/helm/cedar/README.md +++ b/helm/cedar/README.md @@ -1,14 +1,18 @@ # cedar -![Version: 0.1.29](https://img.shields.io/badge/Version-0.1.29-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 cedar wrapper +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | +| Repository | Name | +|------------|------| +| file://../common | common | ## Values diff --git a/helm/cluster-level-resources/Chart.yaml b/helm/cluster-level-resources/Chart.yaml index ebf157a7c..e8ed0007d 100644 --- a/helm/cluster-level-resources/Chart.yaml +++ b/helm/cluster-level-resources/Chart.yaml @@ -4,6 +4,6 @@ description: An app-of-apps Helm chart that allows for flexible deployment of re type: application -version: 0.6.47 +version: 0.0.0 appVersion: "1.17.0" diff --git a/helm/cluster-level-resources/README.md b/helm/cluster-level-resources/README.md index fce4a0cc3..5414c228e 100644 --- a/helm/cluster-level-resources/README.md +++ b/helm/cluster-level-resources/README.md @@ -1,9 +1,13 @@ # cluster-level-resources -![Version: 0.6.47](https://img.shields.io/badge/Version-0.6.47-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.17.0](https://img.shields.io/badge/AppVersion-1.17.0-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.17.0](https://img.shields.io/badge/AppVersion-1.17.0-informational?style=flat-square) An app-of-apps Helm chart that allows for flexible deployment of resources that support Gen3 +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Values | Key | Type | Default | Description | diff --git a/helm/cohort-middleware/Chart.yaml b/helm/cohort-middleware/Chart.yaml index 854d85d80..29ae1ac88 100644 --- a/helm/cohort-middleware/Chart.yaml +++ b/helm/cohort-middleware/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.26 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common diff --git a/helm/cohort-middleware/README.md b/helm/cohort-middleware/README.md index 269f3534f..3abb23738 100644 --- a/helm/cohort-middleware/README.md +++ b/helm/cohort-middleware/README.md @@ -1,14 +1,18 @@ # cohort-middleware -![Version: 0.1.26](https://img.shields.io/badge/Version-0.1.26-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 cohort-middleware +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | +| Repository | Name | +|------------|------| +| file://../common | common | ## Values diff --git a/helm/common/Chart.yaml b/helm/common/Chart.yaml index 7b5af7e44..f3f2d8e86 100644 --- a/helm/common/Chart.yaml +++ b/helm/common/Chart.yaml @@ -15,7 +15,7 @@ type: library # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.39 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/common/README.md b/helm/common/README.md index 67cfc57dc..1e9ad2ca1 100644 --- a/helm/common/README.md +++ b/helm/common/README.md @@ -1,9 +1,13 @@ # common -![Version: 0.1.39](https://img.shields.io/badge/Version-0.1.39-informational?style=flat-square) ![Type: library](https://img.shields.io/badge/Type-library-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Type: library](https://img.shields.io/badge/Type-library-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for provisioning databases in gen3 +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Values | Key | Type | Default | Description | diff --git a/helm/dashboard/Chart.yaml b/helm/dashboard/Chart.yaml index 75b3bc1ce..f3027a8b3 100644 --- a/helm/dashboard/Chart.yaml +++ b/helm/dashboard/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.24 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "1.16.0" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common diff --git a/helm/dashboard/README.md b/helm/dashboard/README.md index a5cfe1df1..dcdf09cf2 100644 --- a/helm/dashboard/README.md +++ b/helm/dashboard/README.md @@ -1,14 +1,18 @@ # dashboard -![Version: 0.1.24](https://img.shields.io/badge/Version-0.1.24-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.16.0](https://img.shields.io/badge/AppVersion-1.16.0-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.16.0](https://img.shields.io/badge/AppVersion-1.16.0-informational?style=flat-square) A Helm chart for Kubernetes +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | +| Repository | Name | +|------------|------| +| file://../common | common | ## Values diff --git a/helm/data-upload-cron/Chart.yaml b/helm/data-upload-cron/Chart.yaml index 565513700..9e63c612e 100644 --- a/helm/data-upload-cron/Chart.yaml +++ b/helm/data-upload-cron/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.9 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common diff --git a/helm/data-upload-cron/README.md b/helm/data-upload-cron/README.md index 7485b2024..9901fc07a 100644 --- a/helm/data-upload-cron/README.md +++ b/helm/data-upload-cron/README.md @@ -1,14 +1,18 @@ # data-upload-cron -![Version: 0.1.9](https://img.shields.io/badge/Version-0.1.9-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for the data upload cronjob +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | +| Repository | Name | +|------------|------| +| file://../common | common | ## Values diff --git a/helm/datareplicate/Chart.yaml b/helm/datareplicate/Chart.yaml index bd0cf7651..93aea2dee 100644 --- a/helm/datareplicate/Chart.yaml +++ b/helm/datareplicate/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.24 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common diff --git a/helm/datareplicate/README.md b/helm/datareplicate/README.md index d89f11c1a..d933a45b5 100644 --- a/helm/datareplicate/README.md +++ b/helm/datareplicate/README.md @@ -1,14 +1,18 @@ # datareplicate -![Version: 0.1.24](https://img.shields.io/badge/Version-0.1.24-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 datareplicate +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | +| Repository | Name | +|------------|------| +| file://../common | common | ## Values diff --git a/helm/dicom-server/Chart.yaml b/helm/dicom-server/Chart.yaml index f59d194aa..5b6d415c1 100644 --- a/helm/dicom-server/Chart.yaml +++ b/helm/dicom-server/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.34 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common diff --git a/helm/dicom-server/README.md b/helm/dicom-server/README.md index c14448414..c29c9c16e 100644 --- a/helm/dicom-server/README.md +++ b/helm/dicom-server/README.md @@ -1,14 +1,18 @@ # dicom-server -![Version: 0.1.34](https://img.shields.io/badge/Version-0.1.34-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Dicom Server +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | +| Repository | Name | +|------------|------| +| file://../common | common | ## Values diff --git a/helm/embedding-management-service/Chart.yaml b/helm/embedding-management-service/Chart.yaml index 0af67496c..4fbc8e68b 100644 --- a/helm/embedding-management-service/Chart.yaml +++ b/helm/embedding-management-service/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.11 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "1.16.0" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common diff --git a/helm/embedding-management-service/README.md b/helm/embedding-management-service/README.md index 3bad167e5..ca4542204 100644 --- a/helm/embedding-management-service/README.md +++ b/helm/embedding-management-service/README.md @@ -1,14 +1,18 @@ # embedding-management-service -![Version: 0.1.11](https://img.shields.io/badge/Version-0.1.11-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.16.0](https://img.shields.io/badge/AppVersion-1.16.0-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.16.0](https://img.shields.io/badge/AppVersion-1.16.0-informational?style=flat-square) A Helm chart for Kubernetes +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | +| Repository | Name | +|------------|------| +| file://../common | common | ## Values diff --git a/helm/etl/Chart.yaml b/helm/etl/Chart.yaml index 6785caabc..c32a33b0f 100644 --- a/helm/etl/Chart.yaml +++ b/helm/etl/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.24 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/etl/README.md b/helm/etl/README.md index 6fd84ce6e..e431de400 100644 --- a/helm/etl/README.md +++ b/helm/etl/README.md @@ -1,9 +1,13 @@ # etl -![Version: 0.1.24](https://img.shields.io/badge/Version-0.1.24-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 etl +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Values | Key | Type | Default | Description | diff --git a/helm/faro-collector/Chart.yaml b/helm/faro-collector/Chart.yaml index ac429f844..65344a84a 100644 --- a/helm/faro-collector/Chart.yaml +++ b/helm/faro-collector/Chart.yaml @@ -1,6 +1,6 @@ apiVersion: v2 -name: alloy -description: A Helm chart for deploying Grafana Alloy +name: faro-collector +description: A Helm chart for deploying Grafana Alloy as a Faro collector # A chart can be either an 'application' or a 'library' chart. # @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.2 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/faro-collector/README.md b/helm/faro-collector/README.md index fd1f86dbd..a8a35c59c 100644 --- a/helm/faro-collector/README.md +++ b/helm/faro-collector/README.md @@ -1,14 +1,18 @@ -# alloy +# faro-collector -![Version: 0.1.2](https://img.shields.io/badge/Version-0.1.2-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) -A Helm chart for deploying Grafana Alloy +A Helm chart for deploying Grafana Alloy as a Faro collector + +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| https://grafana.github.io/helm-charts | alloy | 0.9.1 | +| Repository | Name | +|------------|------| +| https://grafana.github.io/helm-charts | alloy | ## Values diff --git a/helm/fence/Chart.yaml b/helm/fence/Chart.yaml index bb8147209..bf13dd279 100644 --- a/helm/fence/Chart.yaml +++ b/helm/fence/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.82 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -24,7 +24,7 @@ appVersion: "master" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/fence/README.md b/helm/fence/README.md index 5f51dd27f..833fc0603 100644 --- a/helm/fence/README.md +++ b/helm/fence/README.md @@ -1,15 +1,19 @@ # fence -![Version: 0.1.82](https://img.shields.io/badge/Version-0.1.82-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Fence +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | -| https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | +| Repository | Name | +|------------|------| +| file://../common | common | +| https://charts.bitnami.com/bitnami | postgresql | ## Values diff --git a/helm/frontend-framework/Chart.yaml b/helm/frontend-framework/Chart.yaml index c435a52b6..15029725d 100644 --- a/helm/frontend-framework/Chart.yaml +++ b/helm/frontend-framework/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.32 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "develop" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common diff --git a/helm/frontend-framework/README.md b/helm/frontend-framework/README.md index c22bde71e..c2c5d86b2 100644 --- a/helm/frontend-framework/README.md +++ b/helm/frontend-framework/README.md @@ -1,14 +1,18 @@ # frontend-framework -![Version: 0.1.32](https://img.shields.io/badge/Version-0.1.32-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: develop](https://img.shields.io/badge/AppVersion-develop-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: develop](https://img.shields.io/badge/AppVersion-develop-informational?style=flat-square) A Helm chart for the gen3 frontend framework +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | +| Repository | Name | +|------------|------| +| file://../common | common | ## Values diff --git a/helm/funnel/Chart.yaml b/helm/funnel/Chart.yaml index 71b7b2a58..c8657cc4b 100644 --- a/helm/funnel/Chart.yaml +++ b/helm/funnel/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.33 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -24,5 +24,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common diff --git a/helm/funnel/README.md b/helm/funnel/README.md index 91eba3362..8b25fa75c 100644 --- a/helm/funnel/README.md +++ b/helm/funnel/README.md @@ -1,14 +1,18 @@ # funnel -![Version: 0.1.33](https://img.shields.io/badge/Version-0.1.33-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for Kubernetes +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | +| Repository | Name | +|------------|------| +| file://../common | common | ## Values diff --git a/helm/gen3-analysis/Chart.yaml b/helm/gen3-analysis/Chart.yaml index 93f461dc9..100028e76 100644 --- a/helm/gen3-analysis/Chart.yaml +++ b/helm/gen3-analysis/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.15 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common diff --git a/helm/gen3-analysis/README.md b/helm/gen3-analysis/README.md index 4754d7f60..c3da7063a 100644 --- a/helm/gen3-analysis/README.md +++ b/helm/gen3-analysis/README.md @@ -1,14 +1,18 @@ # gen3-analysis -![Version: 0.1.15](https://img.shields.io/badge/Version-0.1.15-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 gen3-analysis Service +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | +| Repository | Name | +|------------|------| +| file://../common | common | ## Values diff --git a/helm/gen3-embeddings/Chart.yaml b/helm/gen3-embeddings/Chart.yaml index 4fc045a86..6c0d56329 100644 --- a/helm/gen3-embeddings/Chart.yaml +++ b/helm/gen3-embeddings/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.2 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -24,7 +24,7 @@ version: 0.1.2 appVersion: "main" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/gen3-embeddings/README.md b/helm/gen3-embeddings/README.md index d93b0656b..408e6e90d 100644 --- a/helm/gen3-embeddings/README.md +++ b/helm/gen3-embeddings/README.md @@ -1,15 +1,19 @@ # gen3-embeddings -![Version: 0.1.2](https://img.shields.io/badge/Version-0.1.2-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: main](https://img.shields.io/badge/AppVersion-main-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: main](https://img.shields.io/badge/AppVersion-main-informational?style=flat-square) A Helm chart for Kubernetes +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | -| https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | +| Repository | Name | +|------------|------| +| file://../common | common | +| https://charts.bitnami.com/bitnami | postgresql | ## Values diff --git a/helm/gen3-network-policies/Chart.yaml b/helm/gen3-network-policies/Chart.yaml index f998a269b..e822ba394 100644 --- a/helm/gen3-network-policies/Chart.yaml +++ b/helm/gen3-network-policies/Chart.yaml @@ -4,6 +4,6 @@ description: A Helm chart that holds network policies needed to run Gen3 type: application -version: 0.1.4 +version: 0.0.0 appVersion: "0.1.2" diff --git a/helm/gen3-network-policies/README.md b/helm/gen3-network-policies/README.md index 22498af89..a1cc65439 100644 --- a/helm/gen3-network-policies/README.md +++ b/helm/gen3-network-policies/README.md @@ -1,9 +1,13 @@ # gen3-network-policies -![Version: 0.1.4](https://img.shields.io/badge/Version-0.1.4-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 0.1.2](https://img.shields.io/badge/AppVersion-0.1.2-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 0.1.2](https://img.shields.io/badge/AppVersion-0.1.2-informational?style=flat-square) A Helm chart that holds network policies needed to run Gen3 +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Values | Key | Type | Default | Description | diff --git a/helm/gen3-user-data-library/Chart.yaml b/helm/gen3-user-data-library/Chart.yaml index c1d2c1fbe..6a8765a3d 100644 --- a/helm/gen3-user-data-library/Chart.yaml +++ b/helm/gen3-user-data-library/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.18 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -24,7 +24,7 @@ version: 0.1.18 appVersion: "main" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/gen3-user-data-library/README.md b/helm/gen3-user-data-library/README.md index 809e4753f..77cce4b7f 100644 --- a/helm/gen3-user-data-library/README.md +++ b/helm/gen3-user-data-library/README.md @@ -1,15 +1,19 @@ # gen3-user-data-library -![Version: 0.1.18](https://img.shields.io/badge/Version-0.1.18-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: main](https://img.shields.io/badge/AppVersion-main-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: main](https://img.shields.io/badge/AppVersion-main-informational?style=flat-square) A Helm chart for Kubernetes +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | -| https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | +| Repository | Name | +|------------|------| +| file://../common | common | +| https://charts.bitnami.com/bitnami | postgresql | ## Values diff --git a/helm/gen3-workflow/Chart.yaml b/helm/gen3-workflow/Chart.yaml index 42a98103b..e9dc652ee 100644 --- a/helm/gen3-workflow/Chart.yaml +++ b/helm/gen3-workflow/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.29 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -24,5 +24,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common diff --git a/helm/gen3-workflow/README.md b/helm/gen3-workflow/README.md index 7c9ceaed7..3f03f8c0e 100644 --- a/helm/gen3-workflow/README.md +++ b/helm/gen3-workflow/README.md @@ -1,14 +1,18 @@ # gen3-workflow -![Version: 0.1.29](https://img.shields.io/badge/Version-0.1.29-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for Kubernetes +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | +| Repository | Name | +|------------|------| +| file://../common | common | ## Values diff --git a/helm/gen3/Chart.yaml b/helm/gen3/Chart.yaml index 68e866190..08c4b2da1 100644 --- a/helm/gen3/Chart.yaml +++ b/helm/gen3/Chart.yaml @@ -5,170 +5,170 @@ description: Helm chart to deploy Gen3 Data Commons # Dependencies dependencies: - name: access-backend - version: 0.1.23 + version: "*" repository: "file://../access-backend" condition: access-backend.enabled - name: ambassador - version: 0.1.40 + version: "*" repository: "file://../ambassador" condition: ambassador.enabled - name: arborist - version: 0.1.37 + version: "*" repository: "file://../arborist" condition: arborist.enabled - name: argo-wrapper - version: 0.1.34 + version: "*" repository: "file://../argo-wrapper" condition: argo-wrapper.enabled - name: audit - version: 0.1.47 + version: "*" repository: "file://../audit" condition: audit.enabled - name: aws-es-proxy - version: 0.1.45 + version: "*" repository: "file://../aws-es-proxy" condition: aws-es-proxy.enabled - name: aws-sigv4-proxy - version: 0.1.5 + version: "*" repository: "file://../aws-sigv4-proxy" condition: aws-sigv4-proxy.enabled - name: cedar - version: 0.1.29 + version: "*" repository: "file://../cedar" condition: cedar.enabled - name: cohort-middleware - version: 0.1.26 + version: "*" repository: "file://../cohort-middleware" condition: cohort-middleware.enabled - name: common - version: 0.1.39 + version: "*" repository: file://../common - name: dashboard - version: 0.1.24 + version: "*" repository: file://../dashboard condition: dashboard.enabled - name: datareplicate - version: 0.1.24 + version: "*" repository: "file://../datareplicate" condition: datareplicate.enabled - name: data-upload-cron - version: 0.1.9 + version: "*" repository: "file://../data-upload-cron" condition: data-upload-cron.enabled - name: embedding-management-service - version: 0.1.11 + version: "*" repository: file://../embedding-management-service condition: embedding-management-service.enabled - name: etl - version: 0.1.24 + version: "*" repository: file://../etl condition: etl.enabled - name: frontend-framework - version: 0.1.32 + version: "*" repository: "file://../frontend-framework" condition: frontend-framework.enabled - name: fence - version: 0.1.82 + version: "*" repository: "file://../fence" condition: fence.enabled - name: funnel - version: 0.1.33 + version: "*" repository: "file://../funnel" condition: gen3-workflow.enabled - name: gen3-embeddings - version: 0.1.2 + version: "*" repository: "file://../gen3-embeddings" condition: gen3-embeddings.enabled - name: gen3-user-data-library - version: 0.1.18 + version: "*" repository: "file://../gen3-user-data-library" condition: gen3-user-data-library.enabled - name: gen3-workflow - version: 0.1.29 + version: "*" repository: "file://../gen3-workflow" condition: gen3-workflow.enabled - name: guppy - version: 0.1.41 + version: "*" repository: "file://../guppy" condition: guppy.enabled - name: hatchery - version: 0.1.73 + version: "*" repository: "file://../hatchery" condition: hatchery.enabled - name: indexd - version: 0.1.51 + version: "*" repository: "file://../indexd" condition: indexd.enabled - name: manifestservice - version: 0.1.46 + version: "*" repository: "file://../manifestservice" condition: manifestservice.enabled - name: metadata - version: 0.1.48 + version: "*" repository: "file://../metadata" condition: metadata.enabled - name: peregrine - version: 0.1.45 + version: "*" repository: "file://../peregrine" condition: peregrine.enabled - name: portal - version: 0.1.63 + version: "*" repository: "file://../portal" condition: portal.enabled - name: requestor - version: 0.1.38 + version: "*" repository: "file://../requestor" condition: requestor.enabled - name: revproxy - version: 0.1.71 + version: "*" repository: "file://../revproxy" condition: revproxy.enabled - name: sheepdog - version: 0.1.47 + version: "*" repository: "file://../sheepdog" condition: sheepdog.enabled - name: ssjdispatcher - version: 0.1.50 + version: "*" repository: "file://../ssjdispatcher" condition: ssjdispatcher.enabled - name: sower - version: 0.1.49 + version: "*" condition: sower.enabled repository: "file://../sower" - name: wts - version: 0.1.44 + version: "*" repository: "file://../wts" condition: wts.enabled - name: zendesk-wrapper - version: 0.1.2 + version: "*" repository: "file://../zendesk-wrapper" condition: zendesk-wrapper.enabled - name: gen3-network-policies - version: 0.1.4 + version: "*" repository: "file://../gen3-network-policies" condition: global.netPolicy.enabled - name: dicom-server - version: 0.1.34 + version: "*" repository: file://../dicom-server condition: dicom-server.enabled - name: ohif-viewer - version: 0.1.17 + version: "*" repository: file://../ohif-viewer condition: ohif-viewer.enabled - name: orthanc - version: 0.1.18 + version: "*" repository: file://../orthanc condition: orthanc.enabled - name: gen3-analysis - version: 0.1.15 + version: "*" repository: file://../gen3-analysis condition: gen3-analysis.enabled - name: ohdsi-atlas - version: 0.1.2 + version: "*" repository: file://../ohdsi-atlas condition: ohdsi-atlas.enabled - name: ohdsi-webapi - version: 0.1.8 + version: "*" repository: file://../ohdsi-webapi condition: ohdsi-webapi.enabled @@ -187,19 +187,19 @@ dependencies: # Reference: https://github.com/neuvector/neuvector-helm # For more information, please use the Gen3 community Slack. - name: neuvector - version: "0.1.2" + version: "*" repository: "file://../neuvector" condition: neuvector.enabled - name: jeg - version: 0.1.4 + version: "*" repository: "file://../jeg" condition: jeg.enabled - name: workspace-proxy - version: 0.1.4 + version: "*" repository: "file://../workspace-proxy" condition: workspace-proxy.enabled - name: vectis-overlays - version: 0.1.4 + version: "*" repository: "file://../vectis-overlays" condition: vectis-overlays.enabled @@ -217,7 +217,7 @@ type: application # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.3.83 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/gen3/README.md b/helm/gen3/README.md index af9983b34..2c3fca053 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -1,9 +1,13 @@ # gen3 -![Version: 0.3.83](https://img.shields.io/badge/Version-0.3.83-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) Helm chart to deploy Gen3 Data Commons +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Maintainers | Name | Email | Url | @@ -16,56 +20,56 @@ Helm chart to deploy Gen3 Data Commons ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../access-backend | access-backend | 0.1.23 | -| file://../ambassador | ambassador | 0.1.40 | -| file://../arborist | arborist | 0.1.37 | -| file://../argo-wrapper | argo-wrapper | 0.1.34 | -| file://../audit | audit | 0.1.47 | -| file://../aws-es-proxy | aws-es-proxy | 0.1.45 | -| file://../aws-sigv4-proxy | aws-sigv4-proxy | 0.1.5 | -| file://../cedar | cedar | 0.1.29 | -| file://../cohort-middleware | cohort-middleware | 0.1.26 | -| file://../common | common | 0.1.39 | -| file://../dashboard | dashboard | 0.1.24 | -| file://../data-upload-cron | data-upload-cron | 0.1.9 | -| file://../datareplicate | datareplicate | 0.1.24 | -| file://../dicom-server | dicom-server | 0.1.34 | -| file://../embedding-management-service | embedding-management-service | 0.1.11 | -| file://../etl | etl | 0.1.24 | -| file://../fence | fence | 0.1.82 | -| file://../frontend-framework | frontend-framework | 0.1.32 | -| file://../funnel | funnel | 0.1.33 | -| file://../gen3-analysis | gen3-analysis | 0.1.15 | -| file://../gen3-embeddings | gen3-embeddings | 0.1.2 | -| file://../gen3-network-policies | gen3-network-policies | 0.1.4 | -| file://../gen3-user-data-library | gen3-user-data-library | 0.1.18 | -| file://../gen3-workflow | gen3-workflow | 0.1.29 | -| file://../guppy | guppy | 0.1.41 | -| file://../hatchery | hatchery | 0.1.73 | -| file://../indexd | indexd | 0.1.51 | -| file://../jeg | jeg | 0.1.4 | -| file://../manifestservice | manifestservice | 0.1.46 | -| file://../metadata | metadata | 0.1.48 | -| file://../neuvector | neuvector | 0.1.2 | -| file://../ohdsi-atlas | ohdsi-atlas | 0.1.2 | -| file://../ohdsi-webapi | ohdsi-webapi | 0.1.8 | -| file://../ohif-viewer | ohif-viewer | 0.1.17 | -| file://../orthanc | orthanc | 0.1.18 | -| file://../peregrine | peregrine | 0.1.45 | -| file://../portal | portal | 0.1.63 | -| file://../requestor | requestor | 0.1.38 | -| file://../revproxy | revproxy | 0.1.71 | -| file://../sheepdog | sheepdog | 0.1.47 | -| file://../sower | sower | 0.1.49 | -| file://../ssjdispatcher | ssjdispatcher | 0.1.50 | -| file://../vectis-overlays | vectis-overlays | 0.1.4 | -| file://../workspace-proxy | workspace-proxy | 0.1.4 | -| file://../wts | wts | 0.1.44 | -| file://../zendesk-wrapper | zendesk-wrapper | 0.1.2 | -| https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | -| https://helm.elastic.co | elasticsearch | 7.10.2 | +| Repository | Name | +|------------|------| +| file://../access-backend | access-backend | +| file://../ambassador | ambassador | +| file://../arborist | arborist | +| file://../argo-wrapper | argo-wrapper | +| file://../audit | audit | +| file://../aws-es-proxy | aws-es-proxy | +| file://../aws-sigv4-proxy | aws-sigv4-proxy | +| file://../cedar | cedar | +| file://../cohort-middleware | cohort-middleware | +| file://../common | common | +| file://../dashboard | dashboard | +| file://../data-upload-cron | data-upload-cron | +| file://../datareplicate | datareplicate | +| file://../dicom-server | dicom-server | +| file://../embedding-management-service | embedding-management-service | +| file://../etl | etl | +| file://../fence | fence | +| file://../frontend-framework | frontend-framework | +| file://../funnel | funnel | +| file://../gen3-analysis | gen3-analysis | +| file://../gen3-embeddings | gen3-embeddings | +| file://../gen3-network-policies | gen3-network-policies | +| file://../gen3-user-data-library | gen3-user-data-library | +| file://../gen3-workflow | gen3-workflow | +| file://../guppy | guppy | +| file://../hatchery | hatchery | +| file://../indexd | indexd | +| file://../jeg | jeg | +| file://../manifestservice | manifestservice | +| file://../metadata | metadata | +| file://../neuvector | neuvector | +| file://../ohdsi-atlas | ohdsi-atlas | +| file://../ohdsi-webapi | ohdsi-webapi | +| file://../ohif-viewer | ohif-viewer | +| file://../orthanc | orthanc | +| file://../peregrine | peregrine | +| file://../portal | portal | +| file://../requestor | requestor | +| file://../revproxy | revproxy | +| file://../sheepdog | sheepdog | +| file://../sower | sower | +| file://../ssjdispatcher | ssjdispatcher | +| file://../vectis-overlays | vectis-overlays | +| file://../workspace-proxy | workspace-proxy | +| file://../wts | wts | +| file://../zendesk-wrapper | zendesk-wrapper | +| https://charts.bitnami.com/bitnami | postgresql | +| https://helm.elastic.co | elasticsearch | ## Values diff --git a/helm/guppy/Chart.yaml b/helm/guppy/Chart.yaml index 9d427002c..347eb6841 100644 --- a/helm/guppy/Chart.yaml +++ b/helm/guppy/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.41 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common diff --git a/helm/guppy/README.md b/helm/guppy/README.md index a96095f53..36a12c8af 100644 --- a/helm/guppy/README.md +++ b/helm/guppy/README.md @@ -1,14 +1,18 @@ # guppy -![Version: 0.1.41](https://img.shields.io/badge/Version-0.1.41-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Guppy Service +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | +| Repository | Name | +|------------|------| +| file://../common | common | ## Values diff --git a/helm/hatchery/Chart.yaml b/helm/hatchery/Chart.yaml index 690ba9e9c..a4344400b 100644 --- a/helm/hatchery/Chart.yaml +++ b/helm/hatchery/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.73 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common diff --git a/helm/hatchery/README.md b/helm/hatchery/README.md index 8af45ae9c..e83cb74c5 100644 --- a/helm/hatchery/README.md +++ b/helm/hatchery/README.md @@ -1,14 +1,18 @@ # hatchery -![Version: 0.1.73](https://img.shields.io/badge/Version-0.1.73-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Hatchery +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | +| Repository | Name | +|------------|------| +| file://../common | common | ## Values diff --git a/helm/indexd/Chart.yaml b/helm/indexd/Chart.yaml index e860d6de1..4de36fdf7 100644 --- a/helm/indexd/Chart.yaml +++ b/helm/indexd/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.51 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,7 +25,7 @@ appVersion: "master" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/indexd/README.md b/helm/indexd/README.md index ea44f6cef..1ab7ac1c0 100644 --- a/helm/indexd/README.md +++ b/helm/indexd/README.md @@ -1,15 +1,19 @@ # indexd -![Version: 0.1.51](https://img.shields.io/badge/Version-0.1.51-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 indexd +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | -| https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | +| Repository | Name | +|------------|------| +| file://../common | common | +| https://charts.bitnami.com/bitnami | postgresql | ## Values diff --git a/helm/jeg/Chart.yaml b/helm/jeg/Chart.yaml index a0adcbcda..cfb94ab22 100644 --- a/helm/jeg/Chart.yaml +++ b/helm/jeg/Chart.yaml @@ -5,10 +5,10 @@ description: > Launches ephemeral kernel pods in the workspace namespace on behalf of user Jupyter sessions proxied through workspace-proxy. type: application -version: 0.1.4 +version: 0.0.0 appVersion: "3.2.3" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common diff --git a/helm/jeg/README.md b/helm/jeg/README.md index 4dc2bf0a0..05b95f0b1 100644 --- a/helm/jeg/README.md +++ b/helm/jeg/README.md @@ -1,14 +1,18 @@ # jeg -![Version: 0.1.4](https://img.shields.io/badge/Version-0.1.4-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 3.2.3](https://img.shields.io/badge/AppVersion-3.2.3-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 3.2.3](https://img.shields.io/badge/AppVersion-3.2.3-informational?style=flat-square) Jupyter Enterprise Gateway for gen3 vectis workspaces. Launches ephemeral kernel pods in the workspace namespace on behalf of user Jupyter sessions proxied through workspace-proxy. +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | +| Repository | Name | +|------------|------| +| file://../common | common | ## Values diff --git a/helm/manifestservice/Chart.yaml b/helm/manifestservice/Chart.yaml index 2e216b0a2..8e4ea6a0e 100644 --- a/helm/manifestservice/Chart.yaml +++ b/helm/manifestservice/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.46 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common diff --git a/helm/manifestservice/README.md b/helm/manifestservice/README.md index 1f0ad3145..93cd2a86b 100644 --- a/helm/manifestservice/README.md +++ b/helm/manifestservice/README.md @@ -1,14 +1,18 @@ # manifestservice -![Version: 0.1.46](https://img.shields.io/badge/Version-0.1.46-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for Kubernetes +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | +| Repository | Name | +|------------|------| +| file://../common | common | ## Values diff --git a/helm/metadata/Chart.yaml b/helm/metadata/Chart.yaml index 76a0c935a..76710fee8 100644 --- a/helm/metadata/Chart.yaml +++ b/helm/metadata/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.48 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,7 +25,7 @@ appVersion: "master" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/metadata/README.md b/helm/metadata/README.md index 3b08de802..2e2337929 100644 --- a/helm/metadata/README.md +++ b/helm/metadata/README.md @@ -1,16 +1,20 @@ # metadata -![Version: 0.1.48](https://img.shields.io/badge/Version-0.1.48-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Metadata Service +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | -| https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | -| https://helm.elastic.co | elasticsearch | 7.17.1 | +| Repository | Name | +|------------|------| +| file://../common | common | +| https://charts.bitnami.com/bitnami | postgresql | +| https://helm.elastic.co | elasticsearch | ## Values diff --git a/helm/neuvector/Chart.yaml b/helm/neuvector/Chart.yaml index 845c17972..66d966074 100644 --- a/helm/neuvector/Chart.yaml +++ b/helm/neuvector/Chart.yaml @@ -19,7 +19,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.2 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/neuvector/README.md b/helm/neuvector/README.md index 928cd747d..4de9b4582 100644 --- a/helm/neuvector/README.md +++ b/helm/neuvector/README.md @@ -1,9 +1,13 @@ # neuvector -![Version: 0.1.2](https://img.shields.io/badge/Version-0.1.2-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.16.0](https://img.shields.io/badge/AppVersion-1.16.0-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.16.0](https://img.shields.io/badge/AppVersion-1.16.0-informational?style=flat-square) NeuVector Kubernetes Security Policy templates to protect Gen3 +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Values | Key | Type | Default | Description | diff --git a/helm/observability/Chart.yaml b/helm/observability/Chart.yaml index 0d0317ef0..fca128e29 100644 --- a/helm/observability/Chart.yaml +++ b/helm/observability/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.3 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/observability/README.md b/helm/observability/README.md index 72b9951d2..7ada6ba59 100644 --- a/helm/observability/README.md +++ b/helm/observability/README.md @@ -1,14 +1,18 @@ # lgtma-chart -![Version: 0.1.3](https://img.shields.io/badge/Version-0.1.3-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.0.0](https://img.shields.io/badge/AppVersion-1.0.0-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.0.0](https://img.shields.io/badge/AppVersion-1.0.0-informational?style=flat-square) A Helm chart for deploying the LGTM stack with additional resources +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| https://grafana.github.io/helm-charts | lgtm(lgtm-distributed) | 2.1.0 | +| Repository | Name | +|------------|------| +| https://grafana.github.io/helm-charts | lgtm-distributed | ## Values diff --git a/helm/ohdsi-atlas/Chart.yaml b/helm/ohdsi-atlas/Chart.yaml index 94f3694a0..83a01321a 100644 --- a/helm/ohdsi-atlas/Chart.yaml +++ b/helm/ohdsi-atlas/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.2 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to diff --git a/helm/ohdsi-atlas/README.md b/helm/ohdsi-atlas/README.md index f74fbf621..1558a2f4c 100644 --- a/helm/ohdsi-atlas/README.md +++ b/helm/ohdsi-atlas/README.md @@ -1,9 +1,13 @@ # ohdsi-atlas -![Version: 0.1.2](https://img.shields.io/badge/Version-0.1.2-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 2.15.0](https://img.shields.io/badge/AppVersion-2.15.0-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 2.15.0](https://img.shields.io/badge/AppVersion-2.15.0-informational?style=flat-square) A Helm chart for OHDSI Atlas +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Values | Key | Type | Default | Description | diff --git a/helm/ohdsi-webapi/Chart.yaml b/helm/ohdsi-webapi/Chart.yaml index e35c756ce..bff9fa4d3 100644 --- a/helm/ohdsi-webapi/Chart.yaml +++ b/helm/ohdsi-webapi/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.8 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,7 +25,7 @@ appVersion: "2.15.0" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/ohdsi-webapi/README.md b/helm/ohdsi-webapi/README.md index da539b51d..313b46fd9 100644 --- a/helm/ohdsi-webapi/README.md +++ b/helm/ohdsi-webapi/README.md @@ -1,15 +1,19 @@ # ohdsi-webapi -![Version: 0.1.8](https://img.shields.io/badge/Version-0.1.8-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 2.15.0](https://img.shields.io/badge/AppVersion-2.15.0-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 2.15.0](https://img.shields.io/badge/AppVersion-2.15.0-informational?style=flat-square) A Helm chart for OHDSI WebAPI +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | -| https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | +| Repository | Name | +|------------|------| +| file://../common | common | +| https://charts.bitnami.com/bitnami | postgresql | ## Values diff --git a/helm/ohif-viewer/Chart.yaml b/helm/ohif-viewer/Chart.yaml index e7c13832d..a578cab27 100644 --- a/helm/ohif-viewer/Chart.yaml +++ b/helm/ohif-viewer/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.17 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common diff --git a/helm/ohif-viewer/README.md b/helm/ohif-viewer/README.md index fa11af110..622b950db 100644 --- a/helm/ohif-viewer/README.md +++ b/helm/ohif-viewer/README.md @@ -1,14 +1,18 @@ # ohif-viewer -![Version: 0.1.17](https://img.shields.io/badge/Version-0.1.17-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Ohif Viewer +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | +| Repository | Name | +|------------|------| +| file://../common | common | ## Values diff --git a/helm/orthanc/Chart.yaml b/helm/orthanc/Chart.yaml index c0a7d929d..b554e001e 100644 --- a/helm/orthanc/Chart.yaml +++ b/helm/orthanc/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.18 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common diff --git a/helm/orthanc/README.md b/helm/orthanc/README.md index fbfa9260c..02b70fb1b 100644 --- a/helm/orthanc/README.md +++ b/helm/orthanc/README.md @@ -1,14 +1,18 @@ # orthanc -![Version: 0.1.18](https://img.shields.io/badge/Version-0.1.18-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Dicom Server +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | +| Repository | Name | +|------------|------| +| file://../common | common | ## Values diff --git a/helm/peregrine/Chart.yaml b/helm/peregrine/Chart.yaml index dbde621f1..25dd1f366 100644 --- a/helm/peregrine/Chart.yaml +++ b/helm/peregrine/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.45 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,7 +25,7 @@ appVersion: "master" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/peregrine/README.md b/helm/peregrine/README.md index cacba1fbc..98962e9f9 100644 --- a/helm/peregrine/README.md +++ b/helm/peregrine/README.md @@ -1,15 +1,19 @@ # peregrine -![Version: 0.1.45](https://img.shields.io/badge/Version-0.1.45-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Peregrine service +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | -| https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | +| Repository | Name | +|------------|------| +| file://../common | common | +| https://charts.bitnami.com/bitnami | postgresql | ## Values diff --git a/helm/portal/Chart.yaml b/helm/portal/Chart.yaml index ef0b3d4d4..f333e6a67 100644 --- a/helm/portal/Chart.yaml +++ b/helm/portal/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.63 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common diff --git a/helm/portal/README.md b/helm/portal/README.md index 6730e0b0f..888e67d92 100644 --- a/helm/portal/README.md +++ b/helm/portal/README.md @@ -1,14 +1,18 @@ # portal -![Version: 0.1.63](https://img.shields.io/badge/Version-0.1.63-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 data-portal +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | +| Repository | Name | +|------------|------| +| file://../common | common | ## Values diff --git a/helm/requestor/Chart.yaml b/helm/requestor/Chart.yaml index 895c266c8..d933b6102 100644 --- a/helm/requestor/Chart.yaml +++ b/helm/requestor/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.38 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,7 +25,7 @@ appVersion: "master" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/requestor/README.md b/helm/requestor/README.md index 5b10ab36d..a8806504e 100644 --- a/helm/requestor/README.md +++ b/helm/requestor/README.md @@ -1,15 +1,19 @@ # requestor -![Version: 0.1.38](https://img.shields.io/badge/Version-0.1.38-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Requestor Service +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | -| https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | +| Repository | Name | +|------------|------| +| file://../common | common | +| https://charts.bitnami.com/bitnami | postgresql | ## Values diff --git a/helm/revproxy/Chart.yaml b/helm/revproxy/Chart.yaml index d2ce7a4f6..04ec47faf 100644 --- a/helm/revproxy/Chart.yaml +++ b/helm/revproxy/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.71 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common diff --git a/helm/revproxy/README.md b/helm/revproxy/README.md index 3f227bff6..4fd02f186 100644 --- a/helm/revproxy/README.md +++ b/helm/revproxy/README.md @@ -1,14 +1,18 @@ # revproxy -![Version: 0.1.71](https://img.shields.io/badge/Version-0.1.71-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 revproxy +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | +| Repository | Name | +|------------|------| +| file://../common | common | ## Values diff --git a/helm/sheepdog/Chart.yaml b/helm/sheepdog/Chart.yaml index 1105790be..97e23b8f3 100644 --- a/helm/sheepdog/Chart.yaml +++ b/helm/sheepdog/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.47 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,7 +25,7 @@ appVersion: "master" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/sheepdog/README.md b/helm/sheepdog/README.md index e50831dd9..d8970578c 100644 --- a/helm/sheepdog/README.md +++ b/helm/sheepdog/README.md @@ -1,15 +1,19 @@ # sheepdog -![Version: 0.1.47](https://img.shields.io/badge/Version-0.1.47-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Sheepdog Service +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | -| https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | +| Repository | Name | +|------------|------| +| file://../common | common | +| https://charts.bitnami.com/bitnami | postgresql | ## Values diff --git a/helm/sower/Chart.yaml b/helm/sower/Chart.yaml index c16e77628..3b053c336 100644 --- a/helm/sower/Chart.yaml +++ b/helm/sower/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.49 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common diff --git a/helm/sower/README.md b/helm/sower/README.md index 9760561d8..def59a16b 100644 --- a/helm/sower/README.md +++ b/helm/sower/README.md @@ -1,14 +1,18 @@ # sower -![Version: 0.1.49](https://img.shields.io/badge/Version-0.1.49-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 sower +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | +| Repository | Name | +|------------|------| +| file://../common | common | ## Values diff --git a/helm/ssjdispatcher/Chart.yaml b/helm/ssjdispatcher/Chart.yaml index d67c80e57..c6e19ffb1 100644 --- a/helm/ssjdispatcher/Chart.yaml +++ b/helm/ssjdispatcher/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.50 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common diff --git a/helm/ssjdispatcher/README.md b/helm/ssjdispatcher/README.md index d7d99592d..58adcbe1f 100644 --- a/helm/ssjdispatcher/README.md +++ b/helm/ssjdispatcher/README.md @@ -1,14 +1,18 @@ # ssjdispatcher -![Version: 0.1.50](https://img.shields.io/badge/Version-0.1.50-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 ssjdispatcher +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | +| Repository | Name | +|------------|------| +| file://../common | common | ## Values diff --git a/helm/vectis-overlays/Chart.yaml b/helm/vectis-overlays/Chart.yaml index a38a8981f..49c90b686 100644 --- a/helm/vectis-overlays/Chart.yaml +++ b/helm/vectis-overlays/Chart.yaml @@ -2,10 +2,10 @@ apiVersion: v2 name: vectis-overlays description: Vectis overlay API services (guppy-compat, siem, search-auth-proxy) type: application -version: 0.1.4 +version: 0.0.0 appVersion: "1.0" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common diff --git a/helm/vectis-overlays/README.md b/helm/vectis-overlays/README.md index 9908953ed..129d96d4e 100644 --- a/helm/vectis-overlays/README.md +++ b/helm/vectis-overlays/README.md @@ -1,14 +1,18 @@ # vectis-overlays -![Version: 0.1.4](https://img.shields.io/badge/Version-0.1.4-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.0](https://img.shields.io/badge/AppVersion-1.0-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.0](https://img.shields.io/badge/AppVersion-1.0-informational?style=flat-square) Vectis overlay API services (guppy-compat, siem, search-auth-proxy) +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | +| Repository | Name | +|------------|------| +| file://../common | common | ## Values diff --git a/helm/workspace-proxy/Chart.yaml b/helm/workspace-proxy/Chart.yaml index 1f5d6a1da..23c0d1f53 100644 --- a/helm/workspace-proxy/Chart.yaml +++ b/helm/workspace-proxy/Chart.yaml @@ -5,10 +5,10 @@ description: > Replaces Emissary/Ambassador. Reads Service annotations written by Hatchery to resolve each user's workspace upstream, then proxies traffic from revproxy. type: application -version: 0.1.4 +version: 0.0.0 appVersion: "1.0" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common diff --git a/helm/workspace-proxy/README.md b/helm/workspace-proxy/README.md index 1b523d216..a712cca15 100644 --- a/helm/workspace-proxy/README.md +++ b/helm/workspace-proxy/README.md @@ -1,14 +1,18 @@ # workspace-proxy -![Version: 0.1.4](https://img.shields.io/badge/Version-0.1.4-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.0](https://img.shields.io/badge/AppVersion-1.0-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 1.0](https://img.shields.io/badge/AppVersion-1.0-informational?style=flat-square) Per-user workspace HTTP/WebSocket router for gen3 vectis. Replaces Emissary/Ambassador. Reads Service annotations written by Hatchery to resolve each user's workspace upstream, then proxies traffic from revproxy. +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | +| Repository | Name | +|------------|------| +| file://../common | common | ## Values diff --git a/helm/wts/Chart.yaml b/helm/wts/Chart.yaml index 9710da208..b4a2a0ade 100644 --- a/helm/wts/Chart.yaml +++ b/helm/wts/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.44 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,7 +25,7 @@ appVersion: "master" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common - name: postgresql version: 11.9.13 diff --git a/helm/wts/README.md b/helm/wts/README.md index fb8e80646..ea69e4c59 100644 --- a/helm/wts/README.md +++ b/helm/wts/README.md @@ -1,15 +1,19 @@ # wts -![Version: 0.1.44](https://img.shields.io/badge/Version-0.1.44-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 workspace token service +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | -| https://charts.bitnami.com/bitnami | postgresql | 11.9.13 | +| Repository | Name | +|------------|------| +| file://../common | common | +| https://charts.bitnami.com/bitnami | postgresql | ## Values diff --git a/helm/zendesk-wrapper/Chart.yaml b/helm/zendesk-wrapper/Chart.yaml index 2d1484d8e..9696ec2a6 100644 --- a/helm/zendesk-wrapper/Chart.yaml +++ b/helm/zendesk-wrapper/Chart.yaml @@ -15,7 +15,7 @@ type: application # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.2 +version: 0.0.0 # This is the version number of the application being deployed. This version number should be # incremented each time you make changes to the application. Versions are not expected to @@ -25,5 +25,5 @@ appVersion: "master" dependencies: - name: common - version: 0.1.39 + version: "*" repository: file://../common diff --git a/helm/zendesk-wrapper/README.md b/helm/zendesk-wrapper/README.md index a8b592c59..bd6ca7d74 100644 --- a/helm/zendesk-wrapper/README.md +++ b/helm/zendesk-wrapper/README.md @@ -1,14 +1,18 @@ # zendesk-wrapper -![Version: 0.1.2](https://img.shields.io/badge/Version-0.1.2-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) +![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: master](https://img.shields.io/badge/AppVersion-master-informational?style=flat-square) A Helm chart for gen3 Zendesk Wrapper Service +Published versions of this chart are listed in the +[Helm repository](https://helm.gen3.org) (`helm search repo gen3`) and on the +[releases page](https://github.com/uc-cdis/gen3-helm/releases). + ## Requirements -| Repository | Name | Version | -|------------|------|---------| -| file://../common | common | 0.1.39 | +| Repository | Name | +|------------|------| +| file://../common | common | ## Values From 28acd1ebeb180cae2dcaf334771b3141e18f6d66 Mon Sep 17 00:00:00 2001 From: Ajo Augustine Date: Thu, 13 Aug 2026 14:51:38 -0500 Subject: [PATCH 183/196] Update gen3-user-data-library include db bootstrap, pushsecret --- helm/gen3-user-data-library/templates/db-init.yaml | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/helm/gen3-user-data-library/templates/db-init.yaml b/helm/gen3-user-data-library/templates/db-init.yaml index 0393aa732..95297b084 100644 --- a/helm/gen3-user-data-library/templates/db-init.yaml +++ b/helm/gen3-user-data-library/templates/db-init.yaml @@ -6,4 +6,10 @@ {{ include "common.s3_pg_restore" . }} {{- else }} {{ include "common.db_setup_job" . }} -{{- end -}} \ No newline at end of file +{{- end -}} +{{- if and $.Values.global.externalSecrets.deploy (or $.Values.global.externalSecrets.pushSecret .Values.externalSecrets.pushSecret) }} +--- +{{ include "common.db-push-secret" . }} +--- +{{ include "common.secret.db.bootstrap" . }} +{{- end }} From 07ff1bfb41e42022c9679c9db3466248e98a3a8d Mon Sep 17 00:00:00 2001 From: Edward Malinowski Date: Tue, 18 Aug 2026 10:59:15 -0500 Subject: [PATCH 184/196] Added some minor fixes to our charts --- helm/gen3/README.md | 4 ++-- helm/gen3/values.yaml | 2 +- helm/portal/templates/deployment-cached.yaml | 3 ++- 3 files changed, 5 insertions(+), 4 deletions(-) diff --git a/helm/gen3/README.md b/helm/gen3/README.md index 2c3fca053..62073e924 100644 --- a/helm/gen3/README.md +++ b/helm/gen3/README.md @@ -165,8 +165,8 @@ Published versions of this chart are listed in the | global.dictionaryUrl | string | `"https://s3.amazonaws.com/dictionary-artifacts/datadictionary/develop/schema.json"` | URL of the data dictionary. | | global.dispatcherJobNum | int | `"10"` | Number of dispatcher jobs. | | global.environment | string | `"default"` | Environment name. This should be the same as vpcname if you're doing an AWS deployment. Currently this is being used to share ALB's if you have multiple namespaces in same cluster. | -| global.externalSecrets | map | `{"apiVersion":"external-secrets.io/v1beta1","clusterSecretStoreRef":"","createLocalK8sSecret":false,"createSlackWebhookSecret":false,"deploy":false,"slackWebhookSecretName":""}` | External Secrets settings. | -| global.externalSecrets.apiVersion | string | `"external-secrets.io/v1beta1"` | API version to use for External Secrets resources. Defaults to v1beta1 when unset. | +| global.externalSecrets | map | `{"apiVersion":"external-secrets.io/v1","clusterSecretStoreRef":"","createLocalK8sSecret":false,"createSlackWebhookSecret":false,"deploy":false,"slackWebhookSecretName":""}` | External Secrets settings. | +| global.externalSecrets.apiVersion | string | `"external-secrets.io/v1"` | API version to use for External Secrets resources. Defaults to v1beta1 when unset. | | global.externalSecrets.createLocalK8sSecret | bool | `false` | Will create the databases and store the creds in Kubernetes Secrets even if externalSecrets is deployed. Useful if you want to use ExternalSecrets for other secrets besides db secrets. | | global.externalSecrets.createSlackWebhookSecret | bool | `false` | Will create a Kubernetes Secret for the slack webhook. | | global.externalSecrets.deploy | bool | `false` | Will use ExternalSecret resources to pull secrets from Secrets Manager instead of creating them locally. Be cautious as this will override secrets you have deployed. | diff --git a/helm/gen3/values.yaml b/helm/gen3/values.yaml index e815dfb30..f76c1e5d2 100644 --- a/helm/gen3/values.yaml +++ b/helm/gen3/values.yaml @@ -130,7 +130,7 @@ global: # -- (map) External Secrets settings. externalSecrets: # -- (string) API version to use for External Secrets resources. Defaults to v1beta1 when unset. - apiVersion: "external-secrets.io/v1beta1" + apiVersion: "external-secrets.io/v1" # -- (bool) Will use ExternalSecret resources to pull secrets from Secrets Manager instead of creating them locally. Be cautious as this will override secrets you have deployed. deploy: false # -- (bool) Will create the databases and store the creds in Kubernetes Secrets even if externalSecrets is deployed. Useful if you want to use ExternalSecrets for other secrets besides db secrets. diff --git a/helm/portal/templates/deployment-cached.yaml b/helm/portal/templates/deployment-cached.yaml index 2a3beaa94..489128297 100644 --- a/helm/portal/templates/deployment-cached.yaml +++ b/helm/portal/templates/deployment-cached.yaml @@ -411,7 +411,8 @@ spec: resources: {{- toYaml .Values.resources | nindent 12 }} ports: - - containerPort: 80 + - containerPort: {{ .Values.service.targetPort }} + name: http - containerPort: 443 env: - name: HOSTNAME From 25283ac6e614d32c7f143caeec339e1a10849f14 Mon Sep 17 00:00:00 2001 From: Edward Malinowski Date: Tue, 18 Aug 2026 15:07:56 -0500 Subject: [PATCH 185/196] Updated portal builder job to ensure CSS is setup correctly --- helm/portal/templates/secret.yaml | 71 +++++++++++++++++++++++++++++++ 1 file changed, 71 insertions(+) diff --git a/helm/portal/templates/secret.yaml b/helm/portal/templates/secret.yaml index 81e98d4f7..04c96de10 100644 --- a/helm/portal/templates/secret.yaml +++ b/helm/portal/templates/secret.yaml @@ -480,9 +480,80 @@ stringData: sed -n '1,20p' "/data-portal/data/config/${APP}.json" || true fi + echo "[INFO] Preparing cached-build theme assets" + + mkdir -p /data-portal/src/css + mkdir -p /data-portal/public/src/css + + CUSTOM_CSS="/data-portal/custom/css/${APP}.css" + THEME_CSS="/data-portal/src/css/themeoverrides.css" + PUBLIC_THEME_CSS="/data-portal/public/src/css/themeoverrides.css" + + if [ -f "${CUSTOM_CSS}" ]; then + echo "[INFO] Found custom CSS: ${CUSTOM_CSS}" + + cp -f "${CUSTOM_CSS}" "${THEME_CSS}" + cp -f "${CUSTOM_CSS}" "${PUBLIC_THEME_CSS}" + + echo "[INFO] Created:" + ls -l "${THEME_CSS}" "${PUBLIC_THEME_CSS}" + else + echo "[WARN] Custom CSS not found at ${CUSTOM_CSS}" + echo "[INFO] Creating empty theme override" + + printf '/* generated file - no custom theme configured */\n' \ + > "${THEME_CSS}" + + printf '/* generated file - no custom theme configured */\n' \ + > "${PUBLIC_THEME_CSS}" + fi + + echo "[INFO] Starting webpack build to ${WEBPACK_OUTDIR}" + # Run the webpack build bash runWebpack.sh + + echo "[INFO] Staging runtime static assets" + + mkdir -p "${WEBPACK_OUTDIR}/src/css" + + # themeoverrides.css is created/modified outside webpack output, + # so explicitly copy it into the cached artifact. + if [ -f "/data-portal/src/css/themeoverrides.css" ]; then + cp -f \ + "/data-portal/src/css/themeoverrides.css" \ + "${WEBPACK_OUTDIR}/src/css/themeoverrides.css" + else + echo "[WARN] /data-portal/src/css/themeoverrides.css does not exist" + fi + + # graphiql.css and any other directly-served src/css assets + if [ -d "/data-portal/src/css" ]; then + cp -a /data-portal/src/css/. "${WEBPACK_OUTDIR}/src/css/" + fi + + # Static node_modules CSS/LESS referenced directly by index.html + if [ -d "/data-portal/node_modules/@gen3/ui-component/dist/css" ]; then + mkdir -p "${WEBPACK_OUTDIR}/node_modules/@gen3/ui-component/dist/css" + cp -a \ + /data-portal/node_modules/@gen3/ui-component/dist/css/. \ + "${WEBPACK_OUTDIR}/node_modules/@gen3/ui-component/dist/css/" + fi + + echo "[INFO] Verifying cached runtime assets" + + for required in \ + "${WEBPACK_OUTDIR}/index.html" \ + "${WEBPACK_OUTDIR}/src/css/themeoverrides.css" \ + "${WEBPACK_OUTDIR}/src/css/graphiql.css" + do + if [ ! -f "$required" ]; then + echo "[ERROR] Required cached artifact missing: $required" + exit 1 + fi + done + # Stage assets that nginx will serve directly echo "[INFO] Staging extra assets into ${WEBPACK_OUTDIR}" mkdir -p "${WEBPACK_OUTDIR}/src" From a370c81773c4219b43f69743b34626f287f0a083 Mon Sep 17 00:00:00 2001 From: avantol Date: Wed, 19 Aug 2026 13:46:59 -0500 Subject: [PATCH 186/196] feat(gen3_embeddings): updates to use uvicorn, local observability, JSON logs, tracing --- .../scripts/regenerate_local_alloy_values.py | 193 ++++++++ docs/kubernetes-in-docker.md | 6 +- docs/local-observability.md | 141 ++++++ examples/local_alloy_values.yaml | 457 ++++++++++++++++++ examples/local_lgtm.yaml | 91 ++++ helm/alloy/SETUP.md | 2 + helm/gen3-embeddings/README.md | 9 +- .../gen3-embeddings/templates/deployment.yaml | 20 +- helm/gen3-embeddings/templates/secrets.yaml | 1 - helm/gen3-embeddings/templates/service.yaml | 2 +- helm/gen3-embeddings/values.yaml | 36 +- 11 files changed, 935 insertions(+), 23 deletions(-) create mode 100644 .github/scripts/regenerate_local_alloy_values.py create mode 100644 docs/local-observability.md create mode 100644 examples/local_alloy_values.yaml create mode 100644 examples/local_lgtm.yaml diff --git a/.github/scripts/regenerate_local_alloy_values.py b/.github/scripts/regenerate_local_alloy_values.py new file mode 100644 index 000000000..54e4ebb80 --- /dev/null +++ b/.github/scripts/regenerate_local_alloy_values.py @@ -0,0 +1,193 @@ +#!/usr/bin/env python3 +""" +Regenerate examples/local_alloy_values.yaml from the Alloy chart's own configuration. + +``helm/alloy/values.yaml`` carries Alloy's whole configuration in a single YAML string, +``alloy.alloyConfigmapData``. Helm can only replace such a value wholesale, never merge into it, +so the local-development overlay has to contain a full copy. This script produces that copy so +it stays byte-identical to the chart apart from a fixed set of substitutions: the three write +endpoints, which in the chart point at Mimir, Loki and Tempo hostnames that do not exist on a +laptop, and the two external labels, which the chart writes as Go template syntax that +``templates/alloy-config.yaml`` never renders. + +Run it after any change to the chart's configuration: + + python3 .github/scripts/regenerate_local_alloy_values.py + +It exits non-zero, changing nothing, if the chart no longer contains a line it expects to +rewrite. That means the chart moved and the substitutions below need revisiting - it is the +signal that the overlay would otherwise have drifted silently. +""" + +from __future__ import annotations + +import sys +from pathlib import Path + +REPO_ROOT = Path(__file__).resolve().parents[2] +CHART_VALUES = REPO_ROOT / "helm" / "alloy" / "values.yaml" +OVERLAY = REPO_ROOT / "examples" / "local_alloy_values.yaml" + +# Applied in order to the copied configuration, each exactly once. +SUBSTITUTIONS = [ + ( + ' endpoint = "http://monitoring-tempo-distributor.monitoring:4317"\n', + ' endpoint = "lgtm.monitoring:4317"\n', + ), + ( + # X-Scope-OrgID is Mimir's tenant header; the local Prometheus has no notion of tenants. + ' url = "https://mimir.example.com/api/v1/push"\n' + "\n" + " headers = {\n" + ' "X-Scope-OrgID" = "anonymous",\n' + " }\n" + "\n", + ' url = "http://lgtm.monitoring:9090/api/v1/write"\n', + ), + ( + ' url = "https://loki.example.com/loki/api/v1/push"\n', + ' url = "http://lgtm.monitoring:3100/loki/api/v1/push"\n', + ), + ( + ' loki.source.kubernetes "pods" {\n' + " targets = discovery.relabel.all_pods.output\n" + " forward_to = [loki.write.endpoint.receiver]\n" + " }\n", + ' loki.source.kubernetes "pods" {\n' + " targets = discovery.relabel.all_pods.output\n" + " forward_to = [loki.process.pod_logs.receiver]\n" + " }\n" + "\n" + " // Gen3 services log JSON carrying the OpenTelemetry trace_id. Promoting it to\n" + " // structured metadata is what lets Grafana's trace-to-logs query filter on\n" + ' // `| trace_id = "..."` with no parser stage, which is how the Tempo datasource in\n' + " // the local LGTM image is provisioned. It deliberately does not become a stream\n" + " // label: a per-request value there would multiply Loki's stream cardinality.\n" + " //\n" + " // Lines that are not JSON, such as etcd and kube-proxy output, extract nothing and\n" + " // pass through unchanged.\n" + ' loki.process "pod_logs" {\n' + " forward_to = [loki.write.endpoint.receiver]\n" + "\n" + " stage.json {\n" + ' expressions = { trace_id = "trace_id", span_id = "span_id", otel_service = "service" }\n' + " }\n" + "\n" + " stage.structured_metadata {\n" + ' values = { trace_id = "", span_id = "" }\n' + " }\n" + "\n" + " // Each line reports the service.name its span was recorded under. Using that as\n" + " // the stream label is what keeps logs joinable to traces: Grafana builds its\n" + " // trace-to-logs query from service.name, while Loki would otherwise derive\n" + " // service_name from the pod's `app` label. Those two spellings differ whenever a\n" + " // service names itself with underscores, and the join then silently finds nothing.\n" + " //\n" + " // Lines logged outside a span extract nothing here and keep Loki's derived value.\n" + " stage.labels {\n" + ' values = { service_name = "otel_service" }\n' + " }\n" + " }\n", + ), + # Once per write endpoint, hence the repeated pairs. + (' cluster = "{{ .Values.cluster }}",\n', ' cluster = "local-kind",\n'), + (' project = "{{ .Values.project }}",\n', ' project = "local",\n'), + (' cluster = "{{ .Values.cluster }}",\n', ' cluster = "local-kind",\n'), + (' project = "{{ .Values.project }}",\n', ' project = "local",\n'), +] + +HEADER = """\ +# GENERATED by .github/scripts/regenerate_local_alloy_values.py - re-run that script rather than +# editing alloyConfigmapData below by hand. +# +# Grafana Alloy sized for a kind cluster, writing to the single-pod LGTM stack described in +# docs/local-observability.md. Install with: +# +# helm dependency update helm/alloy +# helm upgrade --install alloy ./helm/alloy -n monitoring -f examples/local_alloy_values.yaml +# +# The release must be named `alloy` in namespace `monitoring`: that is the collector address +# Gen3 service images have baked in as OTEL_EXPORTER_OTLP_ENDPOINT. +alloy: + controller: + type: deployment + replicas: 1 + # helm/alloy/values.yaml pins Alloy to topology.kubernetes.io/zone=us-east-1a. A kind node + # carries no zone label, so without this the pod never leaves Pending. It has to be null + # rather than {}: Helm merges an empty map, which leaves the chart's affinity in place, and + # only an explicit null deletes the key. + affinity: null + + alloy: + stabilityLevel: "public-preview" + uiPathPrefix: /alloy + # Lists replace rather than merge, so the OTLP ports have to be restated here. + extraPorts: + - name: "otel-grpc" + port: 4317 + targetPort: 4317 + protocol: "TCP" + - name: "otel-http" + port: 4318 + targetPort: 4318 + protocol: "TCP" + # A single replica has nobody to gossip with, and the peer lookups are noise in the logs. + clustering: + enabled: false + # The parent chart renders the alloy-gen3 ConfigMap; letting the subchart render one too + # would collide on the name. + configMap: + create: false + name: alloy-gen3 + key: config + resources: + requests: + cpu: 100m + memory: 256Mi + + # Copied from helm/alloy/values.yaml, changing only the three write endpoints and the two + # external labels. + # + # The labels are written out literally on purpose. templates/alloy-config.yaml renders this + # with toYaml rather than tpl, so any {{ }} left in here reaches the ConfigMap unrendered. + alloyConfigmapData: | +""" + +CONFIG_KEY = " alloyConfigmapData: |" + + +def main() -> int: + """ + Write the overlay from the current chart configuration. + + Returns: + int: 0 on success, 1 if the chart no longer matches what the substitutions expect. + """ + lines = CHART_VALUES.read_text().splitlines(keepends=True) + + try: + start = next(i for i, line in enumerate(lines) if line.startswith(CONFIG_KEY)) + except StopIteration: + print(f"{CHART_VALUES} has no '{CONFIG_KEY.strip()}' key", file=sys.stderr) + return 1 + + # alloyConfigmapData is the last key in the file, so the config block runs to the end. + config = "".join(lines[start + 1 :]).rstrip("\n") + "\n" + + for needle, replacement in SUBSTITUTIONS: + if needle not in config: + print(f"chart configuration no longer contains:\n{needle}", file=sys.stderr) + return 1 + config = config.replace(needle, replacement, 1) + + if "{{" in config: + print("template syntax left in the copied configuration", file=sys.stderr) + return 1 + + OVERLAY.write_text(HEADER + config) + print(f"wrote {OVERLAY} ({len(config.splitlines())} configuration lines)") + return 0 + + +if __name__ == "__main__": + sys.exit(main()) diff --git a/docs/kubernetes-in-docker.md b/docs/kubernetes-in-docker.md index 91707a20c..914cb3023 100644 --- a/docs/kubernetes-in-docker.md +++ b/docs/kubernetes-in-docker.md @@ -112,4 +112,8 @@ portal: ```bash helm repo add gen3 http://helm.gen3.org helm upgrade --install gen3 gen3/gen3 -f ./values.yaml -``` \ No newline at end of file +``` + +# Optional: metrics and traces + +To see the metrics and traces your services emit, see [local-observability.md](local-observability.md). \ No newline at end of file diff --git a/docs/local-observability.md b/docs/local-observability.md new file mode 100644 index 000000000..82dc4c9ef --- /dev/null +++ b/docs/local-observability.md @@ -0,0 +1,141 @@ +# Local observability on kind + +## Overview + +Gen3 services emit two kinds of telemetry: Prometheus metrics scraped from a `/metrics` +endpoint, and OpenTelemetry traces pushed over OTLP. In a deployed cluster both flow through +[Grafana Alloy](../helm/alloy/SETUP.md), which forwards metrics to Mimir, logs to Loki, and +traces to Tempo. + +This guide stands the same Alloy pipeline up on a kind cluster, backed by a single-pod LGTM +stack instead of the [observability](../helm/observability/SETUP.md) chart. You get Grafana, +Prometheus, Tempo, and Loki in one container, and Alloy configured exactly as it is in a real +cluster apart from the three addresses it writes to. + +Use this when you are developing a service and want to see its own metrics and traces. Do not +use it as a model for a deployed cluster: + +- one replica of everything, no high availability +- `emptyDir` storage, so all data is lost when the pod restarts +- no ingress, no TLS, no authentication beyond Grafana's default `admin` / `admin` + +The `observability` chart is the deployed-cluster answer. It is sized for EKS - five Mimir +ingesters, S3 storage, ALB ingresses - and will not fit comfortably on a laptop. + +## Prerequisites + +A running kind cluster. See [kubernetes-in-docker.md](kubernetes-in-docker.md). + +# Step 1. Deploy the LGTM backend + +[examples/local_lgtm.yaml](../examples/local_lgtm.yaml) is adapted from the manifest published +by [grafana/docker-otel-lgtm](https://github.com/grafana/docker-otel-lgtm), with one change: the +Loki port is exposed, so Alloy has somewhere to send logs. The image already starts Prometheus +with `--web.enable-remote-write-receiver`, which is what Alloy needs in order to deliver +metrics, so nothing has to be passed to enable it. + +```bash +kubectl apply -f examples/local_lgtm.yaml + +kubectl wait --namespace monitoring \ + --for=condition=ready pod \ + --selector=app=lgtm \ + --timeout=180s +``` + +Grafana comes with Prometheus, Tempo, and Loki datasources already provisioned, so there is +nothing to wire up by hand. + +# Step 2. Deploy Alloy + +[examples/local_alloy_values.yaml](../examples/local_alloy_values.yaml) is the stock Alloy +configuration with its three write endpoints pointed at the pod from step 1. It also clears the +`us-east-1a` node affinity the chart applies by default, which no kind node satisfies. + +```bash +helm dependency update helm/alloy +helm upgrade --install alloy ./helm/alloy -n monitoring -f examples/local_alloy_values.yaml +``` + +The release has to be named `alloy` and live in `monitoring`. Gen3 service images ship with +`OTEL_EXPORTER_OTLP_ENDPOINT=http://alloy.monitoring:4318` baked in, and that address is +`.`. + +Confirm Alloy came up clean: + +```bash +kubectl -n monitoring logs deploy/alloy | grep -i error +``` + +Scrape jobs for `kube-state-metrics`, `node-exporter`, and the kubelet are part of the shipped +configuration and find nothing on kind. They sit idle rather than failing. + +# Step 3. Point a service at it + +**Metrics need nothing.** Every Gen3 chart stamps `prometheus.io/scrape: "true"` and +`prometheus.io/path: /metrics` onto its pods, controlled by `global.metricsEnabled` (default +`true`). Alloy discovers pods by those annotations and scrapes `:/metrics`. +The only requirement is that your service actually serves `/metrics`. + +**Traces need three values**, and only if you want to override what the image already does. For +`gen3-embeddings`: + +```yaml +gen3-embeddings: + otel: + enabled: true + endpoint: "http://alloy.monitoring:4318" + protocol: "http/protobuf" +``` + +`endpoint` and `protocol` have to change together: Alloy listens for `http/protobuf` on 4318 and +for `grpc` on 4317, and a mismatched pair fails when the first span is exported rather than at +startup. + +Services deployed in another namespace reach Alloy fine - `alloy.monitoring` resolves from +anywhere in the cluster. + +# Step 4. Look at the data + +```bash +kubectl port-forward -n monitoring svc/lgtm 3000:3000 # Grafana, admin / admin +kubectl port-forward -n monitoring svc/alloy 12345:12345 # Alloy UI, at /alloy +``` + +In Grafana, Explore against the Prometheus datasource for metrics and the Tempo datasource for +traces. Traces are searchable by `service.name`. + +Every sample Alloy forwards carries `cluster="local-kind"` and `project="local"`, set as +external labels in the values file. If a metric has those labels it came through this pipeline. + +## When a metric does not show up + +Work backwards along the path. + +1. **Is the endpoint serving?** `kubectl exec deploy/ -- curl -sf localhost:/metrics`. + An empty 200 is a real failure mode for Python services using `prometheus_client` in + multiprocess mode: the client picks its storage backend when it is first imported, so + `PROMETHEUS_MULTIPROC_DIR` has to be set in the environment before then, not at runtime. +1. **Did Alloy find the pod?** The Alloy UI lists the targets for `prometheus.scrape "metrics"`. + A missing pod means the annotations are absent; a target in state DOWN means Alloy reached + the pod and the endpoint failed. +1. **Did the sample land?** Query Prometheus directly through the port-forward at + `http://localhost:9090`, which rules out a Grafana datasource problem. + +For traces, check the Alloy logs for OTLP export failures, then confirm the service is exporting +at all - some Gen3 services log the collector address they were configured with at startup. + +## Keeping the values file current + +`examples/local_alloy_values.yaml` contains a copy of `alloyConfigmapData` from +[helm/alloy/values.yaml](../helm/alloy/values.yaml). Helm treats that setting as one string, so +it can only be replaced wholesale, never merged into. Regenerate the copy rather than editing +it, after any change to the chart's configuration: + +```bash +python3 .github/scripts/regenerate_local_alloy_values.py +``` + +The script exits non-zero and writes nothing if the chart no longer contains a line it expects +to rewrite, which means the substitutions need revisiting. Running it in CI and checking for a +dirty tree would catch the overlay drifting from the chart. \ No newline at end of file diff --git a/examples/local_alloy_values.yaml b/examples/local_alloy_values.yaml new file mode 100644 index 000000000..ce0e469ec --- /dev/null +++ b/examples/local_alloy_values.yaml @@ -0,0 +1,457 @@ +# GENERATED by .github/scripts/regenerate_local_alloy_values.py - re-run that script rather than +# editing alloyConfigmapData below by hand. +# +# Grafana Alloy sized for a kind cluster, writing to the single-pod LGTM stack described in +# docs/local-observability.md. Install with: +# +# helm dependency update helm/alloy +# helm upgrade --install alloy ./helm/alloy -n monitoring -f examples/local_alloy_values.yaml +# +# The release must be named `alloy` in namespace `monitoring`: that is the collector address +# Gen3 service images have baked in as OTEL_EXPORTER_OTLP_ENDPOINT. +alloy: + controller: + type: deployment + replicas: 1 + # helm/alloy/values.yaml pins Alloy to topology.kubernetes.io/zone=us-east-1a. A kind node + # carries no zone label, so without this the pod never leaves Pending. It has to be null + # rather than {}: Helm merges an empty map, which leaves the chart's affinity in place, and + # only an explicit null deletes the key. + affinity: null + + alloy: + stabilityLevel: "public-preview" + uiPathPrefix: /alloy + # Lists replace rather than merge, so the OTLP ports have to be restated here. + extraPorts: + - name: "otel-grpc" + port: 4317 + targetPort: 4317 + protocol: "TCP" + - name: "otel-http" + port: 4318 + targetPort: 4318 + protocol: "TCP" + # A single replica has nobody to gossip with, and the peer lookups are noise in the logs. + clustering: + enabled: false + # The parent chart renders the alloy-gen3 ConfigMap; letting the subchart render one too + # would collide on the name. + configMap: + create: false + name: alloy-gen3 + key: config + resources: + requests: + cpu: 100m + memory: 256Mi + + # Copied from helm/alloy/values.yaml, changing only the three write endpoints and the two + # external labels. + # + # The labels are written out literally on purpose. templates/alloy-config.yaml renders this + # with toYaml rather than tpl, so any {{ }} left in here reaches the ConfigMap unrendered. + alloyConfigmapData: | + logging { + level = "info" + format = "json" + write_to = [loki.write.endpoint.receiver] + } + + /////////////////////// OTLP START /////////////////////// + + otelcol.receiver.otlp "default" { + grpc {} + http {} + + output { + metrics = [otelcol.processor.batch.default.input] + traces = [otelcol.processor.batch.default.input] + } + } + + otelcol.processor.batch "default" { + output { + metrics = [otelcol.exporter.prometheus.default.input] + traces = [otelcol.exporter.otlp.tempo.input] + } + } + + otelcol.exporter.prometheus "default" { + forward_to = [prometheus.remote_write.default.receiver] + } + + otelcol.exporter.otlp "tempo" { + client { + endpoint = "lgtm.monitoring:4317" + // Configure TLS settings for communicating with the endpoint. + tls { + // The connection is insecure. + insecure = true + // Do not verify TLS certificates when connecting. + insecure_skip_verify = true + } + } + } + + + /////////////////////// OTLP END /////////////////////// + + // discover all pods, to be used later in this config + discovery.kubernetes "pods" { + role = "pod" + } + + // discover all services, to be used later in this config + discovery.kubernetes "services" { + role = "service" + } + + // discover all nodes, to be used later in this config + discovery.kubernetes "nodes" { + role = "node" + } + + // Generic scrape of any pod with Annotation "prometheus.io/scrape: true" + discovery.relabel "annotation_autodiscovery_pods" { + targets = discovery.kubernetes.pods.targets + rule { + source_labels = ["__meta_kubernetes_pod_annotation_prometheus_io_scrape"] + regex = "true" + action = "keep" + } + rule { + source_labels = ["__meta_kubernetes_pod_annotation_prometheus_io_job"] + action = "replace" + target_label = "job" + } + rule { + source_labels = ["__meta_kubernetes_pod_annotation_prometheus_io_instance"] + action = "replace" + target_label = "instance" + } + rule { + source_labels = ["__meta_kubernetes_pod_annotation_prometheus_io_path"] + action = "replace" + target_label = "__metrics_path__" + } + + // Choose the pod port + // The discovery generates a target for each declared container port of the pod. + // If the metricsPortName annotation has value, keep only the target where the port name matches the one of the annotation. + rule { + source_labels = ["__meta_kubernetes_pod_container_port_name"] + target_label = "__tmp_port" + } + rule { + source_labels = ["__meta_kubernetes_pod_annotation_prometheus_io_portName"] + regex = "(.+)" + target_label = "__tmp_port" + } + rule { + source_labels = ["__meta_kubernetes_pod_container_port_name"] + action = "keepequal" + target_label = "__tmp_port" + } + + // If the metrics port number annotation has a value, override the target address to use it, regardless whether it is + // one of the declared ports on that Pod. + rule { + source_labels = ["__meta_kubernetes_pod_annotation_prometheus_io_port", "__meta_kubernetes_pod_ip"] + regex = "(\\d+);(([A-Fa-f0-9]{1,4}::?){1,7}[A-Fa-f0-9]{1,4})" + replacement = "[$2]:$1" // IPv6 + target_label = "__address__" + } + rule { + source_labels = ["__meta_kubernetes_pod_annotation_prometheus_io_port", "__meta_kubernetes_pod_ip"] + regex = "(\\d+);((([0-9]+?)(\\.|$)){4})" // IPv4, takes priority over IPv6 when both exists + replacement = "$2:$1" + target_label = "__address__" + } + + rule { + source_labels = ["__meta_kubernetes_pod_annotation_prometheus_io_scheme"] + action = "replace" + target_label = "__scheme__" + } + + + // add labels + rule { + source_labels = ["__meta_kubernetes_pod_name"] + target_label = "pod" + } + rule { + source_labels = ["__meta_kubernetes_pod_container_name"] + target_label = "container" + } + rule { + source_labels = ["__meta_kubernetes_pod_controller_name"] + target_label = "controller" + } + + rule { + source_labels = ["__meta_kubernetes_namespace"] + target_label = "namespace" + } + + + rule { + source_labels = ["__meta_kubernetes_pod_label_app"] + target_label = "app" + } + + // map all labels + rule { + action = "labelmap" + regex = "__meta_kubernetes_pod_label_(.+)" + } + } + + // Generic scrape of any service with + // Annotation Autodiscovery + discovery.relabel "annotation_autodiscovery_services" { + targets = discovery.kubernetes.services.targets + rule { + source_labels = ["__meta_kubernetes_service_annotation_prometheus_io_scrape"] + regex = "true" + action = "keep" + } + rule { + source_labels = ["__meta_kubernetes_service_annotation_prometheus_io_job"] + action = "replace" + target_label = "job" + } + rule { + source_labels = ["__meta_kubernetes_service_annotation_prometheus_io_instance"] + action = "replace" + target_label = "instance" + } + rule { + source_labels = ["__meta_kubernetes_service_annotation_prometheus_io_path"] + action = "replace" + target_label = "__metrics_path__" + } + + // Choose the service port + rule { + source_labels = ["__meta_kubernetes_service_port_name"] + target_label = "__tmp_port" + } + rule { + source_labels = ["__meta_kubernetes_service_annotation_prometheus_io_portName"] + regex = "(.+)" + target_label = "__tmp_port" + } + rule { + source_labels = ["__meta_kubernetes_service_port_name"] + action = "keepequal" + target_label = "__tmp_port" + } + + rule { + source_labels = ["__meta_kubernetes_service_port_number"] + target_label = "__tmp_port" + } + rule { + source_labels = ["__meta_kubernetes_service_annotation_prometheus_io_port"] + regex = "(.+)" + target_label = "__tmp_port" + } + rule { + source_labels = ["__meta_kubernetes_service_port_number"] + action = "keepequal" + target_label = "__tmp_port" + } + + rule { + source_labels = ["__meta_kubernetes_service_annotation_prometheus_io_scheme"] + action = "replace" + target_label = "__scheme__" + } + } + + prometheus.scrape "metrics" { + job_name = "integrations/autodiscovery_metrics" + targets = concat(discovery.relabel.annotation_autodiscovery_pods.output, discovery.relabel.annotation_autodiscovery_services.output) + honor_labels = true + clustering { + enabled = true + } + forward_to = [prometheus.relabel.metrics_service.receiver] + } + + + // Node Exporter + // TODO: replace with https://grafana.com/docs/alloy/latest/reference/components/prometheus.exporter.unix/ + discovery.relabel "node_exporter" { + targets = discovery.kubernetes.pods.targets + rule { + source_labels = ["__meta_kubernetes_pod_label_app_kubernetes_io_instance"] + regex = "monitoring-extras" + action = "keep" + } + rule { + source_labels = ["__meta_kubernetes_pod_label_app_kubernetes_io_name"] + regex = "node-exporter" + action = "keep" + } + rule { + source_labels = ["__meta_kubernetes_pod_node_name"] + action = "replace" + target_label = "instance" + } + } + + prometheus.scrape "node_exporter" { + job_name = "integrations/node_exporter" + targets = discovery.relabel.node_exporter.output + scrape_interval = "60s" + clustering { + enabled = true + } + forward_to = [prometheus.relabel.node_exporter.receiver] + } + + prometheus.relabel "node_exporter" { + rule { + source_labels = ["__name__"] + regex = "up|node_cpu.*|node_network.*|node_exporter_build_info|node_filesystem.*|node_memory.*|process_cpu_seconds_total|process_resident_memory_bytes" + action = "keep" + } + forward_to = [prometheus.relabel.metrics_service.receiver] + } + + // Logs from all pods + discovery.relabel "all_pods" { + targets = discovery.kubernetes.pods.targets + rule { + source_labels = ["__meta_kubernetes_namespace"] + target_label = "namespace" + } + rule { + source_labels = ["__meta_kubernetes_pod_name"] + target_label = "pod" + } + rule { + source_labels = ["__meta_kubernetes_pod_container_name"] + target_label = "container" + } + rule { + source_labels = ["__meta_kubernetes_pod_controller_name"] + target_label = "controller" + } + + rule { + source_labels = ["__meta_kubernetes_pod_label_app"] + target_label = "app" + } + + // map all labels + rule { + action = "labelmap" + regex = "__meta_kubernetes_pod_label_(.+)" + } + + } + + loki.source.kubernetes "pods" { + targets = discovery.relabel.all_pods.output + forward_to = [loki.write.endpoint.receiver] + } + + // kube-state-metrics + discovery.relabel "relabel_kube_state_metrics" { + targets = discovery.kubernetes.services.targets + rule { + source_labels = ["__meta_kubernetes_namespace"] + regex = "monitoring" + action = "keep" + } + rule { + source_labels = ["__meta_kubernetes_service_name"] + regex = "monitoring-extras-kube-state-metrics" + action = "keep" + } + } + + prometheus.scrape "kube_state_metrics" { + targets = discovery.relabel.relabel_kube_state_metrics.output + job_name = "kube-state-metrics" + metrics_path = "/metrics" + forward_to = [prometheus.remote_write.default.receiver] + } + + // Kubelet + discovery.relabel "kubelet" { + targets = discovery.kubernetes.nodes.targets + rule { + target_label = "__address__" + replacement = "kubernetes.default.svc.cluster.local:443" + } + rule { + source_labels = ["__meta_kubernetes_node_name"] + regex = "(.+)" + replacement = "/api/v1/nodes/${1}/proxy/metrics" + target_label = "__metrics_path__" + } + } + + prometheus.scrape "kubelet" { + job_name = "integrations/kubernetes/kubelet" + targets = discovery.relabel.kubelet.output + scheme = "https" + scrape_interval = "60s" + bearer_token_file = "/var/run/secrets/kubernetes.io/serviceaccount/token" + tls_config { + insecure_skip_verify = true + } + clustering { + enabled = true + } + forward_to = [prometheus.relabel.kubelet.receiver] + } + + prometheus.relabel "kubelet" { + rule { + source_labels = ["__name__"] + regex = "up|container_cpu_usage_seconds_total|kubelet_certificate_manager_client_expiration_renew_errors|kubelet_certificate_manager_client_ttl_seconds|kubelet_certificate_manager_server_ttl_seconds|kubelet_cgroup_manager_duration_seconds_bucket|kubelet_cgroup_manager_duration_seconds_count|kubelet_node_config_error|kubelet_node_name|kubelet_pleg_relist_duration_seconds_bucket|kubelet_pleg_relist_duration_seconds_count|kubelet_pleg_relist_interval_seconds_bucket|kubelet_pod_start_duration_seconds_bucket|kubelet_pod_start_duration_seconds_count|kubelet_pod_worker_duration_seconds_bucket|kubelet_pod_worker_duration_seconds_count|kubelet_running_container_count|kubelet_running_containers|kubelet_running_pod_count|kubelet_running_pods|kubelet_runtime_operations_errors_total|kubelet_runtime_operations_total|kubelet_server_expiration_renew_errors|kubelet_volume_stats_available_bytes|kubelet_volume_stats_capacity_bytes|kubelet_volume_stats_inodes|kubelet_volume_stats_inodes_used|kubernetes_build_info|namespace_workload_pod|rest_client_requests_total|storage_operation_duration_seconds_count|storage_operation_errors_total|volume_manager_total_volumes" + action = "keep" + } + forward_to = [prometheus.relabel.metrics_service.receiver] + } + + // Cluster Events + loki.source.kubernetes_events "cluster_events" { + job_name = "integrations/kubernetes/eventhandler" + log_format = "logfmt" + forward_to = [loki.write.endpoint.receiver] + } + + prometheus.relabel "metrics_service" { + forward_to = [prometheus.remote_write.default.receiver] + } + + + // Write Endpoints + // prometheus write endpoint + prometheus.remote_write "default" { + external_labels = { + cluster = "local-kind", + project = "local", + } + endpoint { + url = "http://lgtm.monitoring:9090/api/v1/write" + } + } + + // loki write endpoint + loki.write "endpoint" { + external_labels = { + cluster = "local-kind", + project = "local", + } + endpoint { + url = "http://lgtm.monitoring:3100/loki/api/v1/push" + } + } diff --git a/examples/local_lgtm.yaml b/examples/local_lgtm.yaml new file mode 100644 index 000000000..98d35b254 --- /dev/null +++ b/examples/local_lgtm.yaml @@ -0,0 +1,91 @@ +# A single-pod Grafana + Prometheus + Tempo + Loki stack for local development, backing the +# Alloy install described in docs/local-observability.md. Apply with: +# +# kubectl apply -f examples/local_lgtm.yaml +# +# Adapted from the manifest published by grafana/docker-otel-lgtm, with one change: the Loki +# port is exposed, so Alloy has somewhere to send logs. +# +# For local development only. One replica, emptyDir storage so everything is lost on restart, +# no ingress, no TLS, and Grafana's default admin/admin. The observability chart is the answer +# for a deployed cluster. +--- +apiVersion: v1 +kind: Namespace +metadata: + name: monitoring +--- +apiVersion: apps/v1 +kind: Deployment +metadata: + name: lgtm + namespace: monitoring +spec: + replicas: 1 + selector: + matchLabels: + app: lgtm + template: + metadata: + labels: + app: lgtm + spec: + containers: + - name: lgtm + image: grafana/otel-lgtm:0.30.2 + # Do not add PROMETHEUS_EXTRA_ARGS=--web.enable-remote-write-receiver. The image's + # run-prometheus.sh already passes that flag, and appending a second copy stops + # Prometheus from starting at all, which shows up only as the pod never going Ready. + env: + # Gen3 pods carry enough labels that Alloy's labelmap of them exceeds Loki's + # default of 15 per stream, and every log push is then rejected with a 400. + # Old entries are accepted too, because the pod tailers start from the beginning + # of each pod's log rather than from now. + - name: LOKI_EXTRA_ARGS + value: "-validation.max-label-names-per-series=32 -validation.reject-old-samples=false" + ports: + - { name: grafana, containerPort: 3000 } + - { name: loki, containerPort: 3100 } + - { name: tempo, containerPort: 3200 } + - { name: otel-grpc, containerPort: 4317 } + - { name: otel-http, containerPort: 4318 } + - { name: prometheus, containerPort: 9090 } + readinessProbe: + exec: + command: ["cat", "/tmp/ready"] + initialDelaySeconds: 10 + periodSeconds: 5 + resources: + requests: + cpu: 200m + memory: 1Gi + volumeMounts: + - { name: tempo-data, mountPath: /data/tempo } + - { name: grafana-data, mountPath: /data/grafana } + - { name: loki-data, mountPath: /data/loki } + - { name: loki-storage, mountPath: /loki } + - { name: p8s-storage, mountPath: /data/prometheus } + - { name: pyroscope-storage, mountPath: /data/pyroscope } + volumes: + - { name: tempo-data, emptyDir: {} } + - { name: grafana-data, emptyDir: {} } + - { name: loki-data, emptyDir: {} } + - { name: loki-storage, emptyDir: {} } + - { name: p8s-storage, emptyDir: {} } + - { name: pyroscope-storage, emptyDir: {} } +--- +apiVersion: v1 +kind: Service +metadata: + name: lgtm + namespace: monitoring +spec: + selector: + app: lgtm + ports: + - { name: grafana, port: 3000, targetPort: 3000 } + - { name: loki, port: 3100, targetPort: 3100 } + - { name: tempo, port: 3200, targetPort: 3200 } + - { name: otel-grpc, port: 4317, targetPort: 4317 } + - { name: otel-http, port: 4318, targetPort: 4318 } + - { name: prometheus, port: 9090, targetPort: 9090 } diff --git a/helm/alloy/SETUP.md b/helm/alloy/SETUP.md index 6a0b28f23..b2f43ee67 100644 --- a/helm/alloy/SETUP.md +++ b/helm/alloy/SETUP.md @@ -8,6 +8,8 @@ In this deployment, the Alloy ConfigMap plays a crucial role in configuring whic Before deploying Alloy, it is important to first deploy the "observability" Helm chart, as it provides the necessary components and configuration for Alloy to function properly. Please refer to the [SETUP.md](https://github.com/uc-cdis/gen3-helm/blob/master/helm/observability/SETUP.md) observability chart documentation for instructions on how to set it up before proceeding with the Alloy deployment. +For a kind cluster, follow [docs/local-observability.md](../../docs/local-observability.md) instead. The observability chart is sized for EKS and does not deploy Tempo, so traces have nowhere to go. + ## Configuring Alloy ### Helm Chart Configuration diff --git a/helm/gen3-embeddings/README.md b/helm/gen3-embeddings/README.md index 408e6e90d..428b170d1 100644 --- a/helm/gen3-embeddings/README.md +++ b/helm/gen3-embeddings/README.md @@ -25,7 +25,7 @@ Published versions of this chart are listed in the | commonLabels | map | `nil` | Will completely override the commonLabels defined in the common chart's _label_setup.tpl | | criticalService | string | `"false"` | Valid options are "true" or "false". If invalid option is set- the value will default to "false". | | debug | bool | `false` | | -| env | list | `[{"name":"GEN3_DEBUG","value":"false"},{"name":"ARBORIST_URL","valueFrom":{"configMapKeyRef":{"key":"arborist_url","name":"manifest-global","optional":true}}},{"name":"PGPOOL_MIN_SIZE","value":"1"},{"name":"PGPOOL_MAX_SIZE","value":"5"},{"name":"GUNICORN_WORKERS","value":"2"}]` | Environment variables to pass to the container | +| env | list | `[{"name":"GEN3_DEBUG","value":"false"},{"name":"ARBORIST_URL","valueFrom":{"configMapKeyRef":{"key":"arborist_url","name":"manifest-global","optional":true}}},{"name":"PGPOOL_MIN_SIZE","value":"1"},{"name":"PGPOOL_MAX_SIZE","value":"5"}]` | Environment variables to pass to the container | | externalSecrets | map | `{"createK8sGen3EmbeddingsSecret":false,"dbcreds":null,"gen3EmbeddingsG3auto":null,"pushSecret":false}` | External Secrets settings. | | externalSecrets.createK8sGen3EmbeddingsSecret | string | `false` | Will create the Helm "gen3Embeddings-g3auto" secret even if Secrets Manager is enabled. This is helpful if you are wanting to use External Secrets for some, but not all secrets. | | externalSecrets.dbcreds | string | `nil` | Will override the name of the aws secrets manager secret. Default is "Values.global.environment-.Chart.Name-creds" | @@ -58,7 +58,6 @@ Published versions of this chart are listed in the | global.topologySpread.enabled | bool | `false` | Whether to enable topology spread constraints for all subcharts that support it. | | global.topologySpread.maxSkew | int | `1` | The maxSkew to use for topology spread constraints. Defaults to 1. | | global.topologySpread.topologyKey | string | `"topology.kubernetes.io/zone"` | The topology key to use for spreading. Defaults to "topology.kubernetes.io/zone". | -| gunicornWorkers | int | `1` | | | image.pullPolicy | string | `"Always"` | | | image.repository | string | `"quay.io/cdis/gen3_embeddings"` | | | image.tag | string | `"main"` | | @@ -73,6 +72,10 @@ Published versions of this chart are listed in the | livenessProbe.httpGet.port | string | `"http"` | | | metricsEnabled | bool | `nil` | Whether Metrics are enabled. | | nameOverride | string | `""` | | +| otel | map | `{"enabled":null,"endpoint":"","protocol":""}` | OpenTelemetry tracing. Every field is optional: leave one empty to keep the default baked into the image. Alloy accepts OTLP on both 4318 (http/protobuf) and 4317 (grpc), so `endpoint` and `protocol` have to be changed together. | +| otel.enabled | bool | `nil` | Whether the service exports traces. Unset keeps the image default (enabled). | +| otel.endpoint | string | `""` | Base URL of the OTLP collector, e.g. "http://alloy.monitoring:4318". | +| otel.protocol | string | `""` | OTLP protocol, either "http/protobuf" or "grpc". | | partOf | string | `"Embeddings"` | Label to help organize pods and their use. Any value is valid, but use "_" or "-" to divide words. | | postgres | map | `{"database":null,"dbCreate":null,"dbRestore":false,"host":null,"password":null,"port":"5432","separate":false,"username":null}` | Postgres database configuration. If db does not exist in postgres cluster and dbCreate is set ot true then these databases will be created for you | | postgres.database | string | `nil` | Database name for postgres. This is a service override, defaults to - | @@ -88,7 +91,7 @@ Published versions of this chart are listed in the | readinessProbe.httpGet.port | string | `"http"` | | | release | string | `"production"` | Valid options are "production" or "dev". If invalid option is set- the value will default to "dev". | | replicaCount | int | `1` | | -| resources | object | `{}` | | +| resources | map | `{"limits":{"cpu":"1","memory":"1Gi"},"requests":{"cpu":"100m","memory":"256Mi"}}` | Compute resources. Sized for the single Uvicorn process the image runs; add replicas rather than raising these to serve more concurrent traffic. The same values apply to the migration initContainer. | | secrets | map | `{"awsAccessKeyId":null,"awsSecretAccessKey":null}` | Secret information to access the db restore job S3 bucket. | | secrets.awsAccessKeyId | str | `nil` | AWS access key ID. Overrides global key. | | secrets.awsSecretAccessKey | str | `nil` | AWS secret access key ID. Overrides global key. | diff --git a/helm/gen3-embeddings/templates/deployment.yaml b/helm/gen3-embeddings/templates/deployment.yaml index aaaa229bf..0fefa6868 100644 --- a/helm/gen3-embeddings/templates/deployment.yaml +++ b/helm/gen3-embeddings/templates/deployment.yaml @@ -91,6 +91,20 @@ spec: optional: false - name: CONFIG_PATH value: /services/gen3_embeddings/.env + {{- /* Only emit OTel vars that are explicitly set, so an unset value falls + through to the default baked into the image rather than being blanked. */}} + {{- if kindIs "bool" .Values.otel.enabled }} + - name: ENABLE_OPENTELEMETRY_TRACES + value: {{ .Values.otel.enabled | quote }} + {{- end }} + {{- with .Values.otel.endpoint }} + - name: OTEL_EXPORTER_OTLP_ENDPOINT + value: {{ . | quote }} + {{- end }} + {{- with .Values.otel.protocol }} + - name: OTEL_EXPORTER_OTLP_PROTOCOL + value: {{ . | quote }} + {{- end }} {{- if eq .Values.global.dev false }} - name: FENCE_URL value: https://{{ .Values.global.hostname }}/user @@ -106,19 +120,19 @@ spec: optional: false imagePullPolicy: {{ .Values.image.pullPolicy }} ports: - - containerPort: 4142 + - containerPort: 8000 name: http livenessProbe: httpGet: path: /_status - port: 4142 + port: 8000 initialDelaySeconds: 30 periodSeconds: 60 timeoutSeconds: 30 readinessProbe: httpGet: path: /_status - port: 4142 + port: 8000 {{- with .Values.volumeMounts }} volumeMounts: {{- toYaml . | nindent 10 }} diff --git a/helm/gen3-embeddings/templates/secrets.yaml b/helm/gen3-embeddings/templates/secrets.yaml index 1c2245ae5..e48c7f447 100644 --- a/helm/gen3-embeddings/templates/secrets.yaml +++ b/helm/gen3-embeddings/templates/secrets.yaml @@ -10,7 +10,6 @@ stringData: DEBUG={{ .Values.debug}} DB_HOST={{ .Values.postgres.host }} DB_USER={{ .Values.postgres.username }} - GUNICORN_WORKERS={{ .Values.gunicornWorkers}} DB_PASSWORD={{ include "gen3-embeddings.postgres.password" . }} DB_DATABASE={{ .Values.postgres.dbname }} ADMIN_LOGINS={{ $randomPass }} diff --git a/helm/gen3-embeddings/templates/service.yaml b/helm/gen3-embeddings/templates/service.yaml index 9d470fd62..baf8b74b6 100644 --- a/helm/gen3-embeddings/templates/service.yaml +++ b/helm/gen3-embeddings/templates/service.yaml @@ -8,7 +8,7 @@ spec: type: {{ .Values.service.type }} ports: - port: {{ .Values.service.port }} - targetPort: 4142 + targetPort: 8000 protocol: TCP name: http selector: diff --git a/helm/gen3-embeddings/values.yaml b/helm/gen3-embeddings/values.yaml index 6a8d4fea4..3354e52b4 100644 --- a/helm/gen3-embeddings/values.yaml +++ b/helm/gen3-embeddings/values.yaml @@ -98,17 +98,28 @@ ingress: # hosts: # - chart-example.local -resources: {} - # We usually recommend not to specify default resources and to leave this as a conscious - # choice for the user. This also increases chances charts run on environments with little - # resources, such as Minikube. If you do want to specify resources, uncomment the following - # lines, adjust them as necessary, and remove the curly braces after 'resources:'. - # limits: - # cpu: 100m - # memory: 128Mi - # requests: - # cpu: 100m - # memory: 128Mi +# -- (map) Compute resources. Sized for the single Uvicorn process the image runs; add +# replicas rather than raising these to serve more concurrent traffic. The same values apply +# to the migration initContainer. +resources: + requests: + cpu: 100m + memory: 256Mi + limits: + cpu: "1" + memory: 1Gi + +# -- (map) OpenTelemetry tracing. Every field is optional: leave one empty to keep the +# default baked into the image. Alloy accepts OTLP on both 4318 (http/protobuf) and 4317 (grpc), +# so `endpoint` and `protocol` have to be changed together. +otel: + # -- (bool) Whether the service exports traces. Unset keeps the image default (enabled). + enabled: + # -- (string) Base URL of the OTLP collector, e.g. "http://alloy.monitoring:4318". + endpoint: "" + # -- (string) OTLP protocol, either "http/protobuf" or "grpc". + protocol: "" + # -- (list) Environment variables to pass to the container env: - name: GEN3_DEBUG @@ -123,8 +134,6 @@ env: value: "1" - name: PGPOOL_MAX_SIZE value: "5" - - name: GUNICORN_WORKERS - value: "2" # This is to setup the liveness and readiness probes more information can be found here: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/ livenessProbe: httpGet: @@ -203,4 +212,3 @@ secrets: awsAccessKeyId: # -- (str) AWS secret access key ID. Overrides global key. awsSecretAccessKey: -gunicornWorkers: 1 From ef765b254debe1b961e54bec350cf5e11bd85633 Mon Sep 17 00:00:00 2001 From: avantol Date: Wed, 19 Aug 2026 15:46:43 -0500 Subject: [PATCH 187/196] fix(observabilitiy): fix trace matching to logs --- .../scripts/regenerate_local_alloy_values.py | 17 +++++-- docs/local-observability.md | 45 +++++++++++++++++-- examples/local_alloy_values.yaml | 37 ++++++++++++++- 3 files changed, 89 insertions(+), 10 deletions(-) diff --git a/.github/scripts/regenerate_local_alloy_values.py b/.github/scripts/regenerate_local_alloy_values.py index 54e4ebb80..f2037e02d 100644 --- a/.github/scripts/regenerate_local_alloy_values.py +++ b/.github/scripts/regenerate_local_alloy_values.py @@ -7,8 +7,15 @@ so the local-development overlay has to contain a full copy. This script produces that copy so it stays byte-identical to the chart apart from a fixed set of substitutions: the three write endpoints, which in the chart point at Mimir, Loki and Tempo hostnames that do not exist on a -laptop, and the two external labels, which the chart writes as Go template syntax that -``templates/alloy-config.yaml`` never renders. +laptop; the two external labels, which the chart writes as Go template syntax that +``templates/alloy-config.yaml`` never renders; and a ``loki.process`` stage inserted after the pod +log source. + +That last one is not an address rewrite but an added behaviour, and it is the only place it +exists. It promotes ``trace_id`` to Loki structured metadata and relabels ``service_name`` from the +log line, which is what makes Grafana's trace-to-logs query resolve. The chart has no equivalent, +so moving the stage into ``helm/alloy/values.yaml`` is what would extend correlation to deployed +clusters, and this substitution would then be dropped. Run it after any change to the chart's configuration: @@ -145,8 +152,10 @@ cpu: 100m memory: 256Mi - # Copied from helm/alloy/values.yaml, changing only the three write endpoints and the two - # external labels. + # Copied from helm/alloy/values.yaml, changing the three write endpoints and the two external + # labels, and inserting the loki.process stage that follows the pod log source. That stage is + # local-only: the chart has no equivalent, so trace-to-logs correlation works here and not in a + # cluster deployed from helm/alloy. # # The labels are written out literally on purpose. templates/alloy-config.yaml renders this # with toYaml rather than tpl, so any {{ }} left in here reaches the ConfigMap unrendered. diff --git a/docs/local-observability.md b/docs/local-observability.md index 82dc4c9ef..c339d598f 100644 --- a/docs/local-observability.md +++ b/docs/local-observability.md @@ -9,8 +9,15 @@ traces to Tempo. This guide stands the same Alloy pipeline up on a kind cluster, backed by a single-pod LGTM stack instead of the [observability](../helm/observability/SETUP.md) chart. You get Grafana, -Prometheus, Tempo, and Loki in one container, and Alloy configured exactly as it is in a real -cluster apart from the three addresses it writes to. +Prometheus, Tempo, and Loki in one container, and Alloy configured as it is in a real cluster +apart from the three addresses it writes to and one added log-processing stage. + +That stage is the one deliberate behavioural difference, and it matters when comparing against a +deployed cluster: the overlay promotes each log line's `trace_id` to Loki structured metadata and +takes `service_name` from the line itself, which is what makes Grafana's trace-to-logs link +resolve. `helm/alloy/values.yaml` carries no such stage, so a deployed cluster using that chart +correlates traces to logs only once the change described in +[otel-logs-and-traces.md](otel-logs-and-traces.md) lands there. Use this when you are developing a service and want to see its own metrics and traces. Do not use it as a model for a deployed cluster: @@ -102,12 +109,42 @@ kubectl port-forward -n monitoring svc/lgtm 3000:3000 # Grafana, admin / adm kubectl port-forward -n monitoring svc/alloy 12345:12345 # Alloy UI, at /alloy ``` -In Grafana, Explore against the Prometheus datasource for metrics and the Tempo datasource for -traces. Traces are searchable by `service.name`. +In Grafana, Explore against the Prometheus datasource for metrics, the Tempo datasource for +traces, and the Loki datasource for logs. Traces are searchable by `service.name`; logs are +selected by `service_name`, for example `{service_name="gen3_embeddings"}`. + +To jump from a trace to its logs, open a span in Tempo and follow its logs link. The Tempo +datasource in the LGTM image builds that query as `{service_name="..."} | trace_id = "..."`, a +label filter with no parser stage, which resolves only because the Alloy overlay stores +`trace_id` as structured metadata. Every sample Alloy forwards carries `cluster="local-kind"` and `project="local"`, set as external labels in the values file. If a metric has those labels it came through this pipeline. +## When a log line or trace link does not show up + +Alloy tails every pod's containers by default, so absent logs are usually a write or a label +problem rather than a collection one. Work forwards along the path. + +1. **Is Alloy tailing the pod?** `kubectl -n monitoring logs deploy/alloy -c alloy | grep "opened log stream"` + names each container it reads. `tailer stopped; will retry` against a pod that is still + starting is normal and clears on its own. +1. **Is Loki accepting the writes?** `kubectl -n monitoring logs deploy/alloy -c alloy | grep "error sending batch"`. + A 500 reading `at least 1 live replicas required, could only find 0` means Loki's single + ingester missed its heartbeat, which on a laptop is resource pressure rather than + misconfiguration. Alloy retries, so short stalls only leave gaps in log history. +1. **Did the line land?** `{service_name=""}` in Explore. If the stream exists under a + different `service_name` than you expect, the line had no `service` field and Loki fell back to + deriving the label from the pod's `app` label. +1. **Is `trace_id` queryable?** `{service_name=""} | trace_id != ""` must return lines with + no `| json` stage. If it only works with `| json`, `stage.structured_metadata` is not taking + effect and the trace-to-logs link will stay empty. +1. **Does the span agree?** Compare `service.name` on a span in Tempo against `service_name` on + the log stream. They have to be spelled identically, underscores included. + +Lines logged outside a span carry `"trace_id": null`, which is expected for startup and for the +OTLP exporter's own HTTP calls. Only lines emitted while a span is active can correlate. + ## When a metric does not show up Work backwards along the path. diff --git a/examples/local_alloy_values.yaml b/examples/local_alloy_values.yaml index ce0e469ec..767a0c3f8 100644 --- a/examples/local_alloy_values.yaml +++ b/examples/local_alloy_values.yaml @@ -46,8 +46,10 @@ alloy: cpu: 100m memory: 256Mi - # Copied from helm/alloy/values.yaml, changing only the three write endpoints and the two - # external labels. + # Copied from helm/alloy/values.yaml, changing the three write endpoints and the two external + # labels, and inserting the loki.process stage that follows the pod log source. That stage is + # local-only: the chart has no equivalent, so trace-to-logs correlation works here and not in a + # cluster deployed from helm/alloy. # # The labels are written out literally on purpose. templates/alloy-config.yaml renders this # with toYaml rather than tpl, so any {{ }} left in here reaches the ConfigMap unrendered. @@ -357,7 +359,38 @@ alloy: loki.source.kubernetes "pods" { targets = discovery.relabel.all_pods.output + forward_to = [loki.process.pod_logs.receiver] + } + + // Gen3 services log JSON carrying the OpenTelemetry trace_id. Promoting it to + // structured metadata is what lets Grafana's trace-to-logs query filter on + // `| trace_id = "..."` with no parser stage, which is how the Tempo datasource in + // the local LGTM image is provisioned. It deliberately does not become a stream + // label: a per-request value there would multiply Loki's stream cardinality. + // + // Lines that are not JSON, such as etcd and kube-proxy output, extract nothing and + // pass through unchanged. + loki.process "pod_logs" { forward_to = [loki.write.endpoint.receiver] + + stage.json { + expressions = { trace_id = "trace_id", span_id = "span_id", otel_service = "service" } + } + + stage.structured_metadata { + values = { trace_id = "", span_id = "" } + } + + // Each line reports the service.name its span was recorded under. Using that as + // the stream label is what keeps logs joinable to traces: Grafana builds its + // trace-to-logs query from service.name, while Loki would otherwise derive + // service_name from the pod's `app` label. Those two spellings differ whenever a + // service names itself with underscores, and the join then silently finds nothing. + // + // Lines logged outside a span extract nothing here and keep Loki's derived value. + stage.labels { + values = { service_name = "otel_service" } + } } // kube-state-metrics From 327013a4c9743c4186cac187cf78b0b9457e7239 Mon Sep 17 00:00:00 2001 From: avantol Date: Thu, 20 Aug 2026 09:29:44 -0500 Subject: [PATCH 188/196] chore(docs): docs about observability --- docs/otel-logs-and-traces.md | 314 +++++++++++++++++++++++++++++++++++ 1 file changed, 314 insertions(+) create mode 100644 docs/otel-logs-and-traces.md diff --git a/docs/otel-logs-and-traces.md b/docs/otel-logs-and-traces.md new file mode 100644 index 000000000..1328771f8 --- /dev/null +++ b/docs/otel-logs-and-traces.md @@ -0,0 +1,314 @@ +# Structured logs and tracing in a deployed cluster + +> **Working notes** This is one reading of what the platform would need in order to +> support JSON logging and tracing for Gen3 services in general. This file is meant to be deleted once the work is scoped. + +## What the services emit + +The Gen3 AI services (`gen3-embeddings` and its siblings) v1.0.0 will emit logs in JSON, tracing info with Open Telemetry, and metrics with prometheus. Metrics need no +chart work from what I can tell. + +`gen3logging`'s JSON formatter writes one object per line: + +```json +{ + "timestamp": "2026-08-17T17:43:05.149Z", + "logger": "gen3_embeddings", + "level": "INFO", + "message": "...", + "trace_id": "4bf92f3577b34da6a3ce929d0e0e4736", + "span_id": "00f067aa0ba902b7", + "service": "gen3_embeddings" +} +``` + +* Traces go to Alloy over OTLP on port 4318 (`http/protobuf`). +* `trace_id` and `span_id` come from `opentelemetry-instrumentation-logging`(python library), which puts them on + every log record. They are `null` for anything logged outside a request span, such as startup or + the OTLP exporter's own HTTP calls. Only lines emitted while a span is active can correlate. +* `service` is the OpenTelemetry `service.name`, and it is **underscored** (`gen3_embeddings`), + matching the Python package. Kubernetes labels for the same service appear **hyphenated** + (`gen3-embeddings`). + - I opted to keep the service name aligned to the Python package and repo in the traces +* `GEN3_JSON_LOGS=false` switches to existing text formatter that appends `[trace_id=... span_id=...]` as + a suffix if we need to. But everything below assumes JSON. + +For the laptop equivalent, see [local-observability.md](local-observability.md). + +## What production seemingly runs today + +Alloy reaches clusters by two different paths, but they are not equivalent: + +| Path | Config lives in | Traces go to | +| ----------------------- | ------------------------------------------ | --------------------------------------------------------------------- | +| ArgoCD (the one in use) | `helm/cluster-level-resources/values.yaml` | `https://tempo.planx-pla.net:443`, external and CTDS-managed | +| The `helm/alloy` chart | `helm/alloy/values.yaml` | `monitoring-tempo-distributor.monitoring:4317`, which nothing creates | + +Logs and metrics in both cases go to the Loki and Mimir deployed by `helm/observability` (the +`lgtm-distributed` chart, with `lgtm.tempo.enabled: false`). + +Everything below refers to the ArgoCD path unless it says otherwise. + +# Getting correlation working + +These three sections are ordered by dependency. Nothing in the second is observable until the +first is done, and the third has no effect without the second. + +## 1. Loki has to accept the streams + +**Symptom:** no logs in Loki for a service, and `final error sending batch ... status 400` in +Alloy's own logs, reading `has N label names; limit 15`. + +`helm/observability/values.yaml` sets `loki.structuredConfig.limits_config` with +`max_query_series`, `max_streams_per_user`, and `max_entries_limit_per_query`, but not +`max_label_names_per_series`, which therefore sits at Loki's default of **15**. + +A Gen3 pod stream carries about fifteen. `discovery.relabel "all_pods"` in +`cluster-level-resources/values.yaml` sets five labels, `labelmap`s every pod label on top, then +drops nine high-cardinality ones; `loki.write` adds `cluster` and `project`, and +`loki.source.kubernetes` adds `instance` and `job`. What pushes it over is the network-policy +labels Gen3 charts attach: `netnolimit`, `public`, `userhelper`, and for some services +`authprovider`, `internet`, `linklocal`, `netvpc`. `fence` is the clearest case. + +Two fixes, not exclusive: + +```yaml +# helm/observability/values.yaml, under lgtm.loki.structuredConfig.limits_config +limits_config: + max_label_names_per_series: 32 +``` + +or extend the existing `labeldrop` regex in `cluster-level-resources/values.yaml` to drop the +network-policy labels, which are probably not useful for querying logs: + +``` +regex = "pod_template_hash|...|netnolimit|public|userhelper|authprovider|internet|linklocal|netvpc" +``` + +Raising the limit is the smaller change and keeps the labels available. Dropping them is better +hygiene, since each one multiplies Loki's stream count. Prefer dropping, and raise the limit as +well so that a chart adding one more label does not silently start dropping logs again. + +**Verify:** `kubectl -n monitoring logs deploy/alloy | grep "status 400"` is quiet, and +`{service_name="gen3_embeddings"}` in Explore returns lines. + +## 2. `trace_id` and `service_name` have to be queryable + +`cluster-level-resources/values.yaml` wires pod logs straight through: + +```alloy +loki.source.kubernetes "pods" { + targets = discovery.relabel.all_pods.output + forward_to = [loki.write.endpoint.receiver] +} +``` + +Two problems follow from that. + +`trace_id` is only text inside the log message, so a LogQL label filter cannot see it and a query +built from a trace id matches nothing. + +The service name also disagrees with itself. Grafana builds its trace-to-logs stream selector from +the span's `service.name`, while Loki derives `service_name` from the pod's `app` label when the +label is absent. A span says `service.name = gen3_embeddings` and its logs land on a stream +labelled `service_name = gen3-embeddings`, so the join finds nothing. Underscore against hyphen. + +Insert a processing stage between the source and the write: + +```alloy +loki.source.kubernetes "pods" { + targets = discovery.relabel.all_pods.output + forward_to = [loki.process.pod_logs.receiver] +} + +loki.process "pod_logs" { + forward_to = [loki.write.endpoint.receiver] + + stage.json { + expressions = { trace_id = "trace_id", span_id = "span_id", otel_service = "service" } + } + + stage.structured_metadata { + values = { trace_id = "", span_id = "" } + } + + stage.labels { + values = { service_name = "otel_service" } + } +} +``` + +`trace_id` becomes **structured metadata**, not a stream label. That distinction is the point: +structured metadata is filterable with `| trace_id = "..."` and no parser stage, while a +per-request value used as a stream label would multiply Loki's stream cardinality without bound. + +`stage.labels` takes `service_name` from the line's own `service` field, so the label matches the +span by construction. Lines logged outside a span have no `service` value and keep Loki's derived +label, which is why both spellings appear in a healthy cluster. + +Requires Loki on `tsdb` with schema `v13` or later. `helm/observability/values.yaml` already +configures `store: tsdb` with `schema: v13`. + +Lines that are not JSON, such as etcd, kube-proxy, and nginx, extract nothing and pass through +unchanged. + +This stage currently ships in one place only: the kind overlay, where +`.github/scripts/regenerate_local_alloy_values.py` inserts it while generating +`examples/local_alloy_values.yaml`. Neither `cluster-level-resources/values.yaml` nor +`helm/alloy/values.yaml` contains it, so correlation is a local-development capability until this +lands in one of them. Anything verified against a kind cluster is exercising the overlay rather +than the configuration a cluster runs. + +**Verify:** `{service_name="gen3_embeddings"} | trace_id != ""` returns lines **with no `| json` +stage**. That absence is the proof the value is structured metadata rather than text. If the +stream exists but the filter returns nothing, `stage.json` is not matching, so check that +`GEN3_JSON_LOGS` is not false. Then compare `service.name` on a span in Tempo against +`service_name` on the log stream; they have to be spelled identically. + +## 3. Grafana has to be wired for it + +`helm/observability/values.yaml` does not override `grafana.datasources`, so the +`lgtm-distributed` defaults apply. Those give the Tempo datasource a `tracesToLogsV2` block with +nothing but `datasourceUid: loki` in it. + +Without a `customQuery`, trace-to-logs does a plain stream lookup over a time window rather than +filtering to the request, so "Logs for this span" returns everything the service logged around +that moment. And the Loki datasource has no `derivedFields`, so there is no link in the other +direction, from a log line to its trace. Both need stating explicitly: + +```yaml +lgtm: + grafana: + datasources: + datasources.yaml: + apiVersion: 1 + datasources: + - name: Tempo + uid: tempo + type: tempo + url: http://{{ .Release.Name }}-tempo-query-frontend:3200 + jsonData: + tracesToLogsV2: + customQuery: true + datasourceUid: loki + query: '{$${__tags}} | trace_id = "$${__trace.traceId}"' + tags: + - key: service.name + value: service_name + - name: Loki + uid: loki + type: loki + url: http://{{ .Release.Name }}-loki-gateway + jsonData: + derivedFields: + - name: trace_id + matcherType: label + matcherRegex: trace_id + url: "$${__value.raw}" + datasourceUid: tempo +``` + +Overriding `datasources.yaml` replaces the whole list, so the Mimir datasource has to be restated +alongside these. The `$$` escaping is required because these strings pass through Helm templating. + +`matcherType: label` is what makes the derived field read structured metadata rather than +re-parsing the line, which is why section 2 has to land first. + +While editing datasources, `exemplarTraceIdDestinations` on the Mimir datasource is worth adding. +It turns latency panels into click-throughs to a trace, but only once Mimir is started with +exemplar storage enabled, which is a separate change. + +**Verify:** open a span in Tempo and use its logs link. It should return only that request's +lines, not everything in the window. + +# Separate decisions + +## There is no Tempo in the observability chart + +`helm/observability/values.yaml:12` sets `lgtm.tempo.enabled: false`, and the `helm/alloy` chart +points at a `monitoring-tempo-distributor` that nothing creates. Clusters using the ArgoCD path +send traces to the external `tempo.planx-pla.net` instead, so tracing works there and only there. + +Enabling Tempo needs three values, not one: + +```yaml +lgtm: + tempo: + enabled: true + traces: + otlp: + grpc: + enabled: true # tempo-distributed defaults this to false + storage: + trace: + backend: s3 # `local` cannot work: ingesters and queriers share no filesystem + s3: {} # bucket, region, and an IRSA policy alongside Mimir's and Loki's +``` + +The `traces.otlp.grpc.enabled` default is the one that catches people: enabling Tempo alone leaves +port 4317 closed, and Alloy's exporter fails with nothing obviously wrong in the chart. + +Whether a cluster should run its own Tempo at all, given the central one, is a decision rather +than a defect. + +## Alert rules assume a different log shape + +`helm/observability/values.yaml` provisions Grafana alert rules that parse logs. Two filter on a +JSON field the new format does not emit: + +```logql +sum by (cluster) (count_over_time({cluster=~".+"} | json | http_status_code="500" [1h])) > 0 +sum(count_over_time({cluster=~".+"} | json | http_status_code="431" [5m])) >= 2 +``` + +The Gen3 AI services emit `timestamp`, `logger`, `level`, `message`, `trace_id`, `span_id`, and +`service`. There is no `http_status_code`, so these alerts will never fire for them. They were +written against another service's log shape. + +Either have the services add an `http_status_code` field when logging a response, or narrow the +alerts to the services that do emit it. Adding the field is the smaller change and makes the alert +mean what it says. + +> Do we need/use this rule? Should I change the Gen3 AI services to include `http_status_code` when it's available? The problem is that we'd have to ensure a log at the end of every request when the status code is locked in. + +# Seemingly we have defects in the `helm/alloy` chart + +Not required for the ArgoCD path, but it should probably not stay broken. Grouped by what each one costs. + +**Prevents startup.** + +- The template opens a block scalar with `config: |` and then runs the value through `toYaml`, + which emits a second block scalar inside the first. A literal `|` becomes the first line of the + ConfigMap and Alloy fails with `missing second | in ||`. + `cluster-level-resources/templates/alloy-configmap.yaml:8` avoids this by not opening a scalar + and letting `toYaml` produce it: + `config: {{ tpl (index .Values "alloy-configmap-data") . | toYaml | indent 2}}`. +- `values.yaml:12` pins the pod to `topology.kubernetes.io/zone=us-east-1a`, so it stays `Pending` + anywhere else. Clearing this from a values file needs `affinity: null`; `affinity: {}` merges an + empty map and changes nothing. + +**Degrades the data.** + +- The config is never passed through `tpl`, so `cluster` and `project` reach the ConfigMap as the + literal strings `{{ .Values.cluster }}` and `{{ .Values.project }}`, and every metric and log + stream Alloy forwards carries those as external labels. Dropping `toYaml` alone does not fix + this; only `tpl` evaluates the template. Note that `tpl` evaluates the whole config, so any + future stage using Go-style braces, `stage.template` being the common one, would break. +- No `labeldrop`, unlike the ArgoCD config, which makes the label limit in section 1 worse. + +**Blocks correlation.** + +- No `loki.process` stage, so section 2 does not apply and pod logs reach Loki with `trace_id` as + message text only. + +**Collides with another chart.** + +- `helm/faro-collector/templates/alloy-config.yaml` uses the same construction and also renders a + ConfigMap named `alloy-gen3`, so the two charts overwrite each other in one namespace. + +# What needs no work + +Metrics. `common.grafanaAnnotations` already puts `prometheus.io/scrape` and `prometheus.io/path` +on every Gen3 pod, `global.metricsEnabled` defaults to true, and Alloy's +`annotation_autodiscovery_pods` relabel already resolves those to `podIP:/metrics`. +A service only has to serve the endpoint. \ No newline at end of file From cb724c77813bfb81087ee029f09a5c15021a56e8 Mon Sep 17 00:00:00 2001 From: Piotr Senkow Date: Thu, 20 Aug 2026 14:48:21 -0500 Subject: [PATCH 189/196] Fix invalid JSON in gen3-workflow crossplane policy document --- helm/gen3-workflow/templates/crossplane.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/helm/gen3-workflow/templates/crossplane.yaml b/helm/gen3-workflow/templates/crossplane.yaml index d34aadb10..98cc916b6 100644 --- a/helm/gen3-workflow/templates/crossplane.yaml +++ b/helm/gen3-workflow/templates/crossplane.yaml @@ -181,7 +181,7 @@ spec: "events:ListTargetsByRule" ], "Resource": "arn:aws:events:*:{{ .Values.global.crossplane.accountId }}:rule/*" - }, + } ] } --- From 381ce1d406e0e8d07e4eff0f1f8b0fcc6a4f7da5 Mon Sep 17 00:00:00 2001 From: Mingfei Shao <2475897+mfshao@users.noreply.github.com> Date: Thu, 20 Aug 2026 22:07:10 -0500 Subject: [PATCH 190/196] add GEN3_ZENDESK_BRAND_ID to zendesk wrapper --- helm/zendesk-wrapper/values.yaml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/helm/zendesk-wrapper/values.yaml b/helm/zendesk-wrapper/values.yaml index e62e178b9..96b77440a 100644 --- a/helm/zendesk-wrapper/values.yaml +++ b/helm/zendesk-wrapper/values.yaml @@ -82,6 +82,9 @@ env: # -- (string) Zendesk instance URL (e.g., https://gen3support.zendesk.com) - name: GEN3_ZENDESK_URL value: "" + # -- (string) Zendesk brand ID (e.g., 123456, can be found in Zendesk admin panel) + - name: GEN3_ZENDESK_BRAND_ID + value: "" # -- (map) Secret environment variables (referenced from Kubernetes secrets) externalSecrets: From 367ebf63dc4db02d738e59c8b3fb08c025ccf0a0 Mon Sep 17 00:00:00 2001 From: Ajo Augustine Date: Fri, 21 Aug 2026 11:35:34 -0500 Subject: [PATCH 191/196] Update Chart.yaml --- helm/cluster-level-resources/Chart.yaml | 3 --- 1 file changed, 3 deletions(-) diff --git a/helm/cluster-level-resources/Chart.yaml b/helm/cluster-level-resources/Chart.yaml index a7f0656b2..e8ed0007d 100644 --- a/helm/cluster-level-resources/Chart.yaml +++ b/helm/cluster-level-resources/Chart.yaml @@ -4,9 +4,6 @@ description: An app-of-apps Helm chart that allows for flexible deployment of re type: application - - version: 0.0.0 - appVersion: "1.17.0" From 4c7bf778bfd70875b610dbcdb387ba997f0a7c2b Mon Sep 17 00:00:00 2001 From: Sai Shanmukha Date: Fri, 21 Aug 2026 11:40:38 -0500 Subject: [PATCH 192/196] Pick external secret version from values.yaml --- helm/funnel/templates/external-secret.yaml | 2 +- helm/gen3-workflow/templates/external-secret.yaml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/helm/funnel/templates/external-secret.yaml b/helm/funnel/templates/external-secret.yaml index 4cede2583..b705d168d 100644 --- a/helm/funnel/templates/external-secret.yaml +++ b/helm/funnel/templates/external-secret.yaml @@ -1,5 +1,5 @@ {{ if .Values.global.externalSecrets.deploy }} -apiVersion: external-secrets.io/v1beta1 +apiVersion: {{ include "common.externalSecrets.apiVersion" . }} kind: ExternalSecret metadata: name: funnel-oidc-client diff --git a/helm/gen3-workflow/templates/external-secret.yaml b/helm/gen3-workflow/templates/external-secret.yaml index 9c36e5f09..bbdefab82 100644 --- a/helm/gen3-workflow/templates/external-secret.yaml +++ b/helm/gen3-workflow/templates/external-secret.yaml @@ -1,6 +1,6 @@ {{ if .Values.global.externalSecrets.deploy }} {{- if not .Values.externalSecrets.createK8sGen3WorkflowSecret}} -apiVersion: external-secrets.io/v1beta1 +apiVersion: {{ include "common.externalSecrets.apiVersion" . }} kind: ExternalSecret metadata: name: gen3workflow-g3auto From f01cf026b425bf22c81aed8a4240ada2fcd9da62 Mon Sep 17 00:00:00 2001 From: avantol Date: Tue, 25 Aug 2026 18:54:03 -0500 Subject: [PATCH 193/196] feat(observability): pyroscope --- docs/local-observability.md | 33 ++++++++++++++++++----- examples/local_lgtm.yaml | 2 ++ helm/alloy/templates/alloy-config.yaml | 2 +- helm/gen3-workflow/README.md | 2 +- helm/gen3-workflow/templates/secrets.yaml | 7 ++++- helm/gen3-workflow/values.yaml | 10 +++++-- 6 files changed, 44 insertions(+), 12 deletions(-) diff --git a/docs/local-observability.md b/docs/local-observability.md index c339d598f..cac097421 100644 --- a/docs/local-observability.md +++ b/docs/local-observability.md @@ -9,7 +9,8 @@ traces to Tempo. This guide stands the same Alloy pipeline up on a kind cluster, backed by a single-pod LGTM stack instead of the [observability](../helm/observability/SETUP.md) chart. You get Grafana, -Prometheus, Tempo, and Loki in one container, and Alloy configured as it is in a real cluster +Prometheus, Tempo, Loki, and Pyroscope in one container, and Alloy configured as it is in a real +cluster apart from the three addresses it writes to and one added log-processing stage. That stage is the one deliberate behavioural difference, and it matters when comparing against a @@ -36,8 +37,11 @@ A running kind cluster. See [kubernetes-in-docker.md](kubernetes-in-docker.md). # Step 1. Deploy the LGTM backend [examples/local_lgtm.yaml](../examples/local_lgtm.yaml) is adapted from the manifest published -by [grafana/docker-otel-lgtm](https://github.com/grafana/docker-otel-lgtm), with one change: the -Loki port is exposed, so Alloy has somewhere to send logs. The image already starts Prometheus +by [grafana/docker-otel-lgtm](https://github.com/grafana/docker-otel-lgtm), with two changes: the +Loki port is exposed, so Alloy has somewhere to send logs, and the Pyroscope port is exposed, so +services can push profiles. Both listen inside the image already; only the Service was missing +them, and a Service without the port silently drops the traffic rather than refusing it. The +image already starts Prometheus with `--web.enable-remote-write-receiver`, which is what Alloy needs in order to deliver metrics, so nothing has to be passed to enable it. @@ -50,8 +54,8 @@ kubectl wait --namespace monitoring \ --timeout=180s ``` -Grafana comes with Prometheus, Tempo, and Loki datasources already provisioned, so there is -nothing to wire up by hand. +Grafana comes with Prometheus, Tempo, Loki, and Pyroscope datasources already provisioned, so +there is nothing to wire up by hand. # Step 2. Deploy Alloy @@ -99,8 +103,22 @@ gen3-embeddings: for `grpc` on 4317, and a mismatched pair fails when the first span is exported rather than at startup. +**Profiles need one address.** A service that ships a Pyroscope SDK pushes to +`PYROSCOPE_SERVER_ADDRESS`, which here is: + +``` +PYROSCOPE_SERVER_ADDRESS=http://lgtm.monitoring:4040 +``` + +CPU and memory are enabled separately. `cdispyutils.observability.configure_profiling` reads +`PROFILE_CPU` (default true) and `PROFILE_MEMORY` (default **false**), so a service pushes CPU +profiles and no memory series until `PROFILE_MEMORY` is set. Both are read from the process +environment rather than from a service's config file, so they belong in the chart's `env` list +next to the other container variables, not in the config block that carries +`PYROSCOPE_SERVER_ADDRESS`. + Services deployed in another namespace reach Alloy fine - `alloy.monitoring` resolves from -anywhere in the cluster. +anywhere in the cluster, as does `lgtm.monitoring`. # Step 4. Look at the data @@ -109,7 +127,8 @@ kubectl port-forward -n monitoring svc/lgtm 3000:3000 # Grafana, admin / adm kubectl port-forward -n monitoring svc/alloy 12345:12345 # Alloy UI, at /alloy ``` -In Grafana, Explore against the Prometheus datasource for metrics, the Tempo datasource for +In Grafana, Explore against the Prometheus datasource for metrics, the Pyroscope datasource for +profiles, the Tempo datasource for traces, and the Loki datasource for logs. Traces are searchable by `service.name`; logs are selected by `service_name`, for example `{service_name="gen3_embeddings"}`. diff --git a/examples/local_lgtm.yaml b/examples/local_lgtm.yaml index 98d35b254..c1a6d800b 100644 --- a/examples/local_lgtm.yaml +++ b/examples/local_lgtm.yaml @@ -50,6 +50,7 @@ spec: - { name: otel-grpc, containerPort: 4317 } - { name: otel-http, containerPort: 4318 } - { name: prometheus, containerPort: 9090 } + - { name: pyroscope, containerPort: 4040 } readinessProbe: exec: command: ["cat", "/tmp/ready"] @@ -89,3 +90,4 @@ spec: - { name: otel-grpc, port: 4317, targetPort: 4317 } - { name: otel-http, port: 4318, targetPort: 4318 } - { name: prometheus, port: 9090, targetPort: 9090 } + - { name: pyroscope, port: 4040, targetPort: 4040 } diff --git a/helm/alloy/templates/alloy-config.yaml b/helm/alloy/templates/alloy-config.yaml index 0bf028758..c49e453c4 100644 --- a/helm/alloy/templates/alloy-config.yaml +++ b/helm/alloy/templates/alloy-config.yaml @@ -5,5 +5,5 @@ metadata: data: config: | {{- with .Values.alloy.alloyConfigmapData }} - {{- toYaml . | nindent 4 }} + {{- . | nindent 4 }} {{ end }} \ No newline at end of file diff --git a/helm/gen3-workflow/README.md b/helm/gen3-workflow/README.md index 3f03f8c0e..0045a2f7c 100644 --- a/helm/gen3-workflow/README.md +++ b/helm/gen3-workflow/README.md @@ -18,6 +18,7 @@ Published versions of this chart are listed in the | Key | Type | Default | Description | |-----|------|---------|-------------| +| GEN3_WORKFLOW_CONFIG | map | `{}` | Passed straight through to the service's own configuration file, so any setting gen3-workflow supports can be set here using its real ALL_UPPER name, without the chart needing a matching key. Rendered after the `gen3WorkflowConfig` values below, so setting a key that the chart already templates does override it, but leaves both lines in the rendered config file. See https://github.com/uc-cdis/gen3-workflow/blob/master/gen3workflow/config-default.yaml | | affinity | map | `{"nodeAffinity":{"preferredDuringSchedulingIgnoredDuringExecution":[{"preference":{"matchExpressions":[{"key":"karpenter.sh/capacity-type","operator":"In","values":["spot"]}]},"weight":100},{"preference":{"matchExpressions":[{"key":"eks.amazonaws.com/capacityType","operator":"In","values":["SPOT"]}]},"weight":99}]},"podAntiAffinity":{"preferredDuringSchedulingIgnoredDuringExecution":[{"podAffinityTerm":{"labelSelector":{"matchExpressions":[{"key":"app","operator":"In","values":["gen3-workflow"]}]},"topologyKey":"kubernetes.io/hostname"},"weight":25}]}}` | Affinity to use for the deployment. | | affinity.nodeAffinity.preferredDuringSchedulingIgnoredDuringExecution | map | `[{"preference":{"matchExpressions":[{"key":"karpenter.sh/capacity-type","operator":"In","values":["spot"]}]},"weight":100},{"preference":{"matchExpressions":[{"key":"eks.amazonaws.com/capacityType","operator":"In","values":["SPOT"]}]},"weight":99}]` | Option for scheduling to be required or preferred. | | affinity.nodeAffinity.preferredDuringSchedulingIgnoredDuringExecution[0] | int | `{"preference":{"matchExpressions":[{"key":"karpenter.sh/capacity-type","operator":"In","values":["spot"]}]},"weight":100}` | Weight value for preferred scheduling. | @@ -54,7 +55,6 @@ Published versions of this chart are listed in the | gen3WorkflowConfig.httpxDebug | bool | `false` | Enables verbose logging specifically for httpx requests. | | gen3WorkflowConfig.kmsEncryptionEnabled | bool | `true` | Enables KMS encryption for S3 uploads. | | gen3WorkflowConfig.mockAuth | bool | `false` | Enables mock authentication, bypassing Arborist. Use only for development. | -| gen3WorkflowConfig.nWorkers | int | `2` | Number of gunicorn workers | | gen3WorkflowConfig.prometheusMultiprocDir | string | `"/var/tmp/prometheus_metrics"` | Filesystem directory used for Prometheus multi-process metrics collection. | | gen3WorkflowConfig.proxyPrefix | string | `"/workflows"` | For deployments that run the app behind a proxy. The value should start with a slash. | | gen3WorkflowConfig.s3AccessKeyId | string | `""` | AWS Access Key ID used to make S3 requests on behalf of users. Leave empty to use credentials from an existing STS session. | diff --git a/helm/gen3-workflow/templates/secrets.yaml b/helm/gen3-workflow/templates/secrets.yaml index 8ae04b72f..59f667230 100644 --- a/helm/gen3-workflow/templates/secrets.yaml +++ b/helm/gen3-workflow/templates/secrets.yaml @@ -14,7 +14,6 @@ stringData: HOSTNAME: {{ default .Values.global.hostname .Values.gen3WorkflowConfig.hostname }} APP_DEBUG: {{ .Values.gen3WorkflowConfig.debug }} HTTPX_DEBUG: {{ .Values.gen3WorkflowConfig.httpxDebug }} - N_WORKERS: {{ .Values.gen3WorkflowConfig.nWorkers }} PROXY_PREFIX: {{ .Values.gen3WorkflowConfig.proxyPrefix }} ARBORIST_URL: {{ .Values.gen3WorkflowConfig.arboristUrl }} MOCK_AUTH: {{ .Values.gen3WorkflowConfig.mockAuth }} @@ -55,4 +54,10 @@ stringData: EKS_CLUSTER_REGION: {{ .Values.global.aws.region }} {{- end }} EKS_SECURITY_GROUP_NAMES: {{ .Values.gen3WorkflowConfig.eksSecurityGroupNames | toJson }} + + # Any setting the service supports, under its real ALL_UPPER name. Rendered last, so a key + # repeated from above overrides it (at the cost of appearing twice in this file). + {{- with .Values.GEN3_WORKFLOW_CONFIG }} + {{- toYaml . | nindent 6 }} + {{- end }} {{- end }} diff --git a/helm/gen3-workflow/values.yaml b/helm/gen3-workflow/values.yaml index 86e078b3f..9fcf7e97c 100644 --- a/helm/gen3-workflow/values.yaml +++ b/helm/gen3-workflow/values.yaml @@ -285,6 +285,14 @@ extraLabels: # for network policy netnolimit: "yes" +# -- (map) Passed straight through to the service's own configuration file, so any setting +# gen3-workflow supports can be set here using its real ALL_UPPER name, without the chart +# needing a matching key. Rendered after the `gen3WorkflowConfig` values below, so setting a key +# that the chart already templates does override it, but leaves both lines in the rendered +# config file. +# See https://github.com/uc-cdis/gen3-workflow/blob/master/gen3workflow/config-default.yaml +GEN3_WORKFLOW_CONFIG: {} + gen3WorkflowConfig: # -- (string) Override hostname where the workflow service runs. If empty, gen3-workflow falls back to values.global.hostname hostname: "" @@ -292,8 +300,6 @@ gen3WorkflowConfig: debug: false # -- (bool) Enables verbose logging specifically for httpx requests. httpxDebug: false - # -- (int) Number of gunicorn workers - nWorkers: 2 # -- (string) For deployments that run the app behind a proxy. The value should start with a slash. proxyPrefix: /workflows # -- (string) Custom Arborist URL. Ignored if already set via environment variable. From 88df4e25df80056e49700574d31323464403b660 Mon Sep 17 00:00:00 2001 From: avantol Date: Wed, 26 Aug 2026 10:50:08 -0500 Subject: [PATCH 194/196] chore(breaking): revert breaking service changes, isolate this to only observability updates and non-breaking changes --- helm/gen3-embeddings/README.md | 9 ++--- .../gen3-embeddings/templates/deployment.yaml | 20 ++--------- helm/gen3-embeddings/templates/secrets.yaml | 1 + helm/gen3-embeddings/templates/service.yaml | 2 +- helm/gen3-embeddings/values.yaml | 36 ++++++++----------- helm/gen3-workflow/README.md | 1 + helm/gen3-workflow/templates/secrets.yaml | 3 +- helm/gen3-workflow/values.yaml | 2 ++ helm/zendesk-wrapper/README.md | 3 +- 9 files changed, 29 insertions(+), 48 deletions(-) diff --git a/helm/gen3-embeddings/README.md b/helm/gen3-embeddings/README.md index 428b170d1..408e6e90d 100644 --- a/helm/gen3-embeddings/README.md +++ b/helm/gen3-embeddings/README.md @@ -25,7 +25,7 @@ Published versions of this chart are listed in the | commonLabels | map | `nil` | Will completely override the commonLabels defined in the common chart's _label_setup.tpl | | criticalService | string | `"false"` | Valid options are "true" or "false". If invalid option is set- the value will default to "false". | | debug | bool | `false` | | -| env | list | `[{"name":"GEN3_DEBUG","value":"false"},{"name":"ARBORIST_URL","valueFrom":{"configMapKeyRef":{"key":"arborist_url","name":"manifest-global","optional":true}}},{"name":"PGPOOL_MIN_SIZE","value":"1"},{"name":"PGPOOL_MAX_SIZE","value":"5"}]` | Environment variables to pass to the container | +| env | list | `[{"name":"GEN3_DEBUG","value":"false"},{"name":"ARBORIST_URL","valueFrom":{"configMapKeyRef":{"key":"arborist_url","name":"manifest-global","optional":true}}},{"name":"PGPOOL_MIN_SIZE","value":"1"},{"name":"PGPOOL_MAX_SIZE","value":"5"},{"name":"GUNICORN_WORKERS","value":"2"}]` | Environment variables to pass to the container | | externalSecrets | map | `{"createK8sGen3EmbeddingsSecret":false,"dbcreds":null,"gen3EmbeddingsG3auto":null,"pushSecret":false}` | External Secrets settings. | | externalSecrets.createK8sGen3EmbeddingsSecret | string | `false` | Will create the Helm "gen3Embeddings-g3auto" secret even if Secrets Manager is enabled. This is helpful if you are wanting to use External Secrets for some, but not all secrets. | | externalSecrets.dbcreds | string | `nil` | Will override the name of the aws secrets manager secret. Default is "Values.global.environment-.Chart.Name-creds" | @@ -58,6 +58,7 @@ Published versions of this chart are listed in the | global.topologySpread.enabled | bool | `false` | Whether to enable topology spread constraints for all subcharts that support it. | | global.topologySpread.maxSkew | int | `1` | The maxSkew to use for topology spread constraints. Defaults to 1. | | global.topologySpread.topologyKey | string | `"topology.kubernetes.io/zone"` | The topology key to use for spreading. Defaults to "topology.kubernetes.io/zone". | +| gunicornWorkers | int | `1` | | | image.pullPolicy | string | `"Always"` | | | image.repository | string | `"quay.io/cdis/gen3_embeddings"` | | | image.tag | string | `"main"` | | @@ -72,10 +73,6 @@ Published versions of this chart are listed in the | livenessProbe.httpGet.port | string | `"http"` | | | metricsEnabled | bool | `nil` | Whether Metrics are enabled. | | nameOverride | string | `""` | | -| otel | map | `{"enabled":null,"endpoint":"","protocol":""}` | OpenTelemetry tracing. Every field is optional: leave one empty to keep the default baked into the image. Alloy accepts OTLP on both 4318 (http/protobuf) and 4317 (grpc), so `endpoint` and `protocol` have to be changed together. | -| otel.enabled | bool | `nil` | Whether the service exports traces. Unset keeps the image default (enabled). | -| otel.endpoint | string | `""` | Base URL of the OTLP collector, e.g. "http://alloy.monitoring:4318". | -| otel.protocol | string | `""` | OTLP protocol, either "http/protobuf" or "grpc". | | partOf | string | `"Embeddings"` | Label to help organize pods and their use. Any value is valid, but use "_" or "-" to divide words. | | postgres | map | `{"database":null,"dbCreate":null,"dbRestore":false,"host":null,"password":null,"port":"5432","separate":false,"username":null}` | Postgres database configuration. If db does not exist in postgres cluster and dbCreate is set ot true then these databases will be created for you | | postgres.database | string | `nil` | Database name for postgres. This is a service override, defaults to - | @@ -91,7 +88,7 @@ Published versions of this chart are listed in the | readinessProbe.httpGet.port | string | `"http"` | | | release | string | `"production"` | Valid options are "production" or "dev". If invalid option is set- the value will default to "dev". | | replicaCount | int | `1` | | -| resources | map | `{"limits":{"cpu":"1","memory":"1Gi"},"requests":{"cpu":"100m","memory":"256Mi"}}` | Compute resources. Sized for the single Uvicorn process the image runs; add replicas rather than raising these to serve more concurrent traffic. The same values apply to the migration initContainer. | +| resources | object | `{}` | | | secrets | map | `{"awsAccessKeyId":null,"awsSecretAccessKey":null}` | Secret information to access the db restore job S3 bucket. | | secrets.awsAccessKeyId | str | `nil` | AWS access key ID. Overrides global key. | | secrets.awsSecretAccessKey | str | `nil` | AWS secret access key ID. Overrides global key. | diff --git a/helm/gen3-embeddings/templates/deployment.yaml b/helm/gen3-embeddings/templates/deployment.yaml index 0fefa6868..aaaa229bf 100644 --- a/helm/gen3-embeddings/templates/deployment.yaml +++ b/helm/gen3-embeddings/templates/deployment.yaml @@ -91,20 +91,6 @@ spec: optional: false - name: CONFIG_PATH value: /services/gen3_embeddings/.env - {{- /* Only emit OTel vars that are explicitly set, so an unset value falls - through to the default baked into the image rather than being blanked. */}} - {{- if kindIs "bool" .Values.otel.enabled }} - - name: ENABLE_OPENTELEMETRY_TRACES - value: {{ .Values.otel.enabled | quote }} - {{- end }} - {{- with .Values.otel.endpoint }} - - name: OTEL_EXPORTER_OTLP_ENDPOINT - value: {{ . | quote }} - {{- end }} - {{- with .Values.otel.protocol }} - - name: OTEL_EXPORTER_OTLP_PROTOCOL - value: {{ . | quote }} - {{- end }} {{- if eq .Values.global.dev false }} - name: FENCE_URL value: https://{{ .Values.global.hostname }}/user @@ -120,19 +106,19 @@ spec: optional: false imagePullPolicy: {{ .Values.image.pullPolicy }} ports: - - containerPort: 8000 + - containerPort: 4142 name: http livenessProbe: httpGet: path: /_status - port: 8000 + port: 4142 initialDelaySeconds: 30 periodSeconds: 60 timeoutSeconds: 30 readinessProbe: httpGet: path: /_status - port: 8000 + port: 4142 {{- with .Values.volumeMounts }} volumeMounts: {{- toYaml . | nindent 10 }} diff --git a/helm/gen3-embeddings/templates/secrets.yaml b/helm/gen3-embeddings/templates/secrets.yaml index e48c7f447..1c2245ae5 100644 --- a/helm/gen3-embeddings/templates/secrets.yaml +++ b/helm/gen3-embeddings/templates/secrets.yaml @@ -10,6 +10,7 @@ stringData: DEBUG={{ .Values.debug}} DB_HOST={{ .Values.postgres.host }} DB_USER={{ .Values.postgres.username }} + GUNICORN_WORKERS={{ .Values.gunicornWorkers}} DB_PASSWORD={{ include "gen3-embeddings.postgres.password" . }} DB_DATABASE={{ .Values.postgres.dbname }} ADMIN_LOGINS={{ $randomPass }} diff --git a/helm/gen3-embeddings/templates/service.yaml b/helm/gen3-embeddings/templates/service.yaml index baf8b74b6..9d470fd62 100644 --- a/helm/gen3-embeddings/templates/service.yaml +++ b/helm/gen3-embeddings/templates/service.yaml @@ -8,7 +8,7 @@ spec: type: {{ .Values.service.type }} ports: - port: {{ .Values.service.port }} - targetPort: 8000 + targetPort: 4142 protocol: TCP name: http selector: diff --git a/helm/gen3-embeddings/values.yaml b/helm/gen3-embeddings/values.yaml index 3354e52b4..6a8d4fea4 100644 --- a/helm/gen3-embeddings/values.yaml +++ b/helm/gen3-embeddings/values.yaml @@ -98,28 +98,17 @@ ingress: # hosts: # - chart-example.local -# -- (map) Compute resources. Sized for the single Uvicorn process the image runs; add -# replicas rather than raising these to serve more concurrent traffic. The same values apply -# to the migration initContainer. -resources: - requests: - cpu: 100m - memory: 256Mi - limits: - cpu: "1" - memory: 1Gi - -# -- (map) OpenTelemetry tracing. Every field is optional: leave one empty to keep the -# default baked into the image. Alloy accepts OTLP on both 4318 (http/protobuf) and 4317 (grpc), -# so `endpoint` and `protocol` have to be changed together. -otel: - # -- (bool) Whether the service exports traces. Unset keeps the image default (enabled). - enabled: - # -- (string) Base URL of the OTLP collector, e.g. "http://alloy.monitoring:4318". - endpoint: "" - # -- (string) OTLP protocol, either "http/protobuf" or "grpc". - protocol: "" - +resources: {} + # We usually recommend not to specify default resources and to leave this as a conscious + # choice for the user. This also increases chances charts run on environments with little + # resources, such as Minikube. If you do want to specify resources, uncomment the following + # lines, adjust them as necessary, and remove the curly braces after 'resources:'. + # limits: + # cpu: 100m + # memory: 128Mi + # requests: + # cpu: 100m + # memory: 128Mi # -- (list) Environment variables to pass to the container env: - name: GEN3_DEBUG @@ -134,6 +123,8 @@ env: value: "1" - name: PGPOOL_MAX_SIZE value: "5" + - name: GUNICORN_WORKERS + value: "2" # This is to setup the liveness and readiness probes more information can be found here: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/ livenessProbe: httpGet: @@ -212,3 +203,4 @@ secrets: awsAccessKeyId: # -- (str) AWS secret access key ID. Overrides global key. awsSecretAccessKey: +gunicornWorkers: 1 diff --git a/helm/gen3-workflow/README.md b/helm/gen3-workflow/README.md index 0045a2f7c..fff704990 100644 --- a/helm/gen3-workflow/README.md +++ b/helm/gen3-workflow/README.md @@ -55,6 +55,7 @@ Published versions of this chart are listed in the | gen3WorkflowConfig.httpxDebug | bool | `false` | Enables verbose logging specifically for httpx requests. | | gen3WorkflowConfig.kmsEncryptionEnabled | bool | `true` | Enables KMS encryption for S3 uploads. | | gen3WorkflowConfig.mockAuth | bool | `false` | Enables mock authentication, bypassing Arborist. Use only for development. | +| gen3WorkflowConfig.nWorkers | int | `2` | Number of gunicorn workers | | gen3WorkflowConfig.prometheusMultiprocDir | string | `"/var/tmp/prometheus_metrics"` | Filesystem directory used for Prometheus multi-process metrics collection. | | gen3WorkflowConfig.proxyPrefix | string | `"/workflows"` | For deployments that run the app behind a proxy. The value should start with a slash. | | gen3WorkflowConfig.s3AccessKeyId | string | `""` | AWS Access Key ID used to make S3 requests on behalf of users. Leave empty to use credentials from an existing STS session. | diff --git a/helm/gen3-workflow/templates/secrets.yaml b/helm/gen3-workflow/templates/secrets.yaml index 59f667230..faea3c62c 100644 --- a/helm/gen3-workflow/templates/secrets.yaml +++ b/helm/gen3-workflow/templates/secrets.yaml @@ -14,6 +14,7 @@ stringData: HOSTNAME: {{ default .Values.global.hostname .Values.gen3WorkflowConfig.hostname }} APP_DEBUG: {{ .Values.gen3WorkflowConfig.debug }} HTTPX_DEBUG: {{ .Values.gen3WorkflowConfig.httpxDebug }} + N_WORKERS: {{ .Values.gen3WorkflowConfig.nWorkers }} PROXY_PREFIX: {{ .Values.gen3WorkflowConfig.proxyPrefix }} ARBORIST_URL: {{ .Values.gen3WorkflowConfig.arboristUrl }} MOCK_AUTH: {{ .Values.gen3WorkflowConfig.mockAuth }} @@ -54,10 +55,10 @@ stringData: EKS_CLUSTER_REGION: {{ .Values.global.aws.region }} {{- end }} EKS_SECURITY_GROUP_NAMES: {{ .Values.gen3WorkflowConfig.eksSecurityGroupNames | toJson }} + {{- with .Values.GEN3_WORKFLOW_CONFIG }} # Any setting the service supports, under its real ALL_UPPER name. Rendered last, so a key # repeated from above overrides it (at the cost of appearing twice in this file). - {{- with .Values.GEN3_WORKFLOW_CONFIG }} {{- toYaml . | nindent 6 }} {{- end }} {{- end }} diff --git a/helm/gen3-workflow/values.yaml b/helm/gen3-workflow/values.yaml index 9fcf7e97c..04f4e74f8 100644 --- a/helm/gen3-workflow/values.yaml +++ b/helm/gen3-workflow/values.yaml @@ -300,6 +300,8 @@ gen3WorkflowConfig: debug: false # -- (bool) Enables verbose logging specifically for httpx requests. httpxDebug: false + # -- (int) Number of gunicorn workers + nWorkers: 2 # -- (string) For deployments that run the app behind a proxy. The value should start with a slash. proxyPrefix: /workflows # -- (string) Custom Arborist URL. Ignored if already set via environment variable. diff --git a/helm/zendesk-wrapper/README.md b/helm/zendesk-wrapper/README.md index bd6ca7d74..fc2e7f9b9 100644 --- a/helm/zendesk-wrapper/README.md +++ b/helm/zendesk-wrapper/README.md @@ -26,8 +26,9 @@ Published versions of this chart are listed in the | autoscaling | object | `{}` | | | commonLabels | string | `nil` | | | criticalService | string | `"false"` | | -| env | map | `[{"name":"GEN3_ZENDESK_URL","value":""}]` | Environment variables for the Zendesk wrapper service | +| env | map | `[{"name":"GEN3_ZENDESK_URL","value":""},{"name":"GEN3_ZENDESK_BRAND_ID","value":""}]` | Environment variables for the Zendesk wrapper service | | env[0] | string | `{"name":"GEN3_ZENDESK_URL","value":""}` | Zendesk instance URL (e.g., https://gen3support.zendesk.com) | +| env[1] | string | `{"name":"GEN3_ZENDESK_BRAND_ID","value":""}` | Zendesk brand ID (e.g., 123456, can be found in Zendesk admin panel) | | externalSecrets | map | `{"name":"zendesk-wrapper-secret"}` | Secret environment variables (referenced from Kubernetes secrets) | | externalSecrets.name | string | `"zendesk-wrapper-secret"` | Name of the Kubernetes secret containing the Zendesk API token | | global.autoscaling.averageCPUValue | string | `"500m"` | | From 8f0bcc5c79b88cd2390d47be25876ef84fe3ea8a Mon Sep 17 00:00:00 2001 From: avantol Date: Wed, 26 Aug 2026 12:04:00 -0500 Subject: [PATCH 195/196] chore(docs): docs updates for pyroscope --- docs/kubernetes-in-docker.md | 4 ++-- docs/local-observability.md | 35 ++++++++++++++++++--------------- docs/otel-logs-and-traces.md | 38 +++++++++++++++++++++++++++++++++--- examples/local_lgtm.yaml | 8 +++++--- helm/alloy/SETUP.md | 2 ++ helm/observability/SETUP.md | 7 ++++++- 6 files changed, 69 insertions(+), 25 deletions(-) diff --git a/docs/kubernetes-in-docker.md b/docs/kubernetes-in-docker.md index 914cb3023..8d6f35d6c 100644 --- a/docs/kubernetes-in-docker.md +++ b/docs/kubernetes-in-docker.md @@ -114,6 +114,6 @@ helm repo add gen3 http://helm.gen3.org helm upgrade --install gen3 gen3/gen3 -f ./values.yaml ``` -# Optional: metrics and traces +# Optional: metrics, traces, and profiles -To see the metrics and traces your services emit, see [local-observability.md](local-observability.md). \ No newline at end of file +To see the metrics, traces, logs, and profiles your services emit, see [local-observability.md](local-observability.md). \ No newline at end of file diff --git a/docs/local-observability.md b/docs/local-observability.md index cac097421..979a38513 100644 --- a/docs/local-observability.md +++ b/docs/local-observability.md @@ -2,16 +2,17 @@ ## Overview -Gen3 services emit two kinds of telemetry: Prometheus metrics scraped from a `/metrics` -endpoint, and OpenTelemetry traces pushed over OTLP. In a deployed cluster both flow through -[Grafana Alloy](../helm/alloy/SETUP.md), which forwards metrics to Mimir, logs to Loki, and -traces to Tempo. +Gen3 services emit four kinds of telemetry: Prometheus metrics scraped from a `/metrics` +endpoint, logs written to stdout, OpenTelemetry traces pushed over OTLP, and continuous profiles +pushed to Pyroscope. In a deployed cluster the first three flow through +[Grafana Alloy](../helm/alloy/SETUP.md), which forwards metrics to Mimir, logs to Loki, and traces +to Tempo. Profiles take no such detour - the SDK inside each service pushes them straight to +Pyroscope, so nothing in Alloy's configuration is involved in carrying them. This guide stands the same Alloy pipeline up on a kind cluster, backed by a single-pod LGTM stack instead of the [observability](../helm/observability/SETUP.md) chart. You get Grafana, Prometheus, Tempo, Loki, and Pyroscope in one container, and Alloy configured as it is in a real -cluster -apart from the three addresses it writes to and one added log-processing stage. +cluster apart from the three addresses it writes to and one added log-processing stage. That stage is the one deliberate behavioural difference, and it matters when comparing against a deployed cluster: the overlay promotes each log line's `trace_id` to Loki structured metadata and @@ -20,15 +21,17 @@ resolve. `helm/alloy/values.yaml` carries no such stage, so a deployed cluster u correlates traces to logs only once the change described in [otel-logs-and-traces.md](otel-logs-and-traces.md) lands there. -Use this when you are developing a service and want to see its own metrics and traces. Do not -use it as a model for a deployed cluster: +Use this when you are developing a service and want to see its own metrics, traces, logs, and +profiles. Do not use it as a model for a deployed cluster: - one replica of everything, no high availability - `emptyDir` storage, so all data is lost when the pod restarts - no ingress, no TLS, no authentication beyond Grafana's default `admin` / `admin` The `observability` chart is the deployed-cluster answer. It is sized for EKS - five Mimir -ingesters, S3 storage, ALB ingresses - and will not fit comfortably on a laptop. +ingesters, S3 storage, ALB ingresses - and will not fit comfortably on a laptop. It also deploys +neither Tempo nor Pyroscope, so a deployed cluster gets traces and profiles only from backends +outside that chart; see [otel-logs-and-traces.md](otel-logs-and-traces.md). ## Prerequisites @@ -41,9 +44,8 @@ by [grafana/docker-otel-lgtm](https://github.com/grafana/docker-otel-lgtm), with Loki port is exposed, so Alloy has somewhere to send logs, and the Pyroscope port is exposed, so services can push profiles. Both listen inside the image already; only the Service was missing them, and a Service without the port silently drops the traffic rather than refusing it. The -image already starts Prometheus -with `--web.enable-remote-write-receiver`, which is what Alloy needs in order to deliver -metrics, so nothing has to be passed to enable it. +image already starts Prometheus with `--web.enable-remote-write-receiver`, which is what Alloy +needs in order to deliver metrics, so nothing has to be passed to enable it. ```bash kubectl apply -f examples/local_lgtm.yaml @@ -127,10 +129,11 @@ kubectl port-forward -n monitoring svc/lgtm 3000:3000 # Grafana, admin / adm kubectl port-forward -n monitoring svc/alloy 12345:12345 # Alloy UI, at /alloy ``` -In Grafana, Explore against the Prometheus datasource for metrics, the Pyroscope datasource for -profiles, the Tempo datasource for -traces, and the Loki datasource for logs. Traces are searchable by `service.name`; logs are -selected by `service_name`, for example `{service_name="gen3_embeddings"}`. +In Grafana, Explore against the Prometheus datasource for metrics, the Tempo datasource for +traces, the Loki datasource for logs, and the Pyroscope datasource for profiles. Traces are +searchable by `service.name`; logs are selected by `service_name`, for example +`{service_name="gen3_embeddings"}`. Profiles are selected by the application name the SDK +registers, which the service sets rather than the chart. To jump from a trace to its logs, open a span in Tempo and follow its logs link. The Tempo datasource in the LGTM image builds that query as `{service_name="..."} | trace_id = "..."`, a diff --git a/docs/otel-logs-and-traces.md b/docs/otel-logs-and-traces.md index 1328771f8..eac53ef6a 100644 --- a/docs/otel-logs-and-traces.md +++ b/docs/otel-logs-and-traces.md @@ -3,10 +3,11 @@ > **Working notes** This is one reading of what the platform would need in order to > support JSON logging and tracing for Gen3 services in general. This file is meant to be deleted once the work is scoped. -## What the services emit +## What the services (will eventually) emit -The Gen3 AI services (`gen3-embeddings` and its siblings) v1.0.0 will emit logs in JSON, tracing info with Open Telemetry, and metrics with prometheus. Metrics need no -chart work from what I can tell. +The Gen3 AI services (`gen3-embeddings` and its siblings) v1.0.0 will emit logs in JSON, tracing info with Open Telemetry, metrics with prometheus, and continuous profiles with Pyroscope. Metrics need no +chart work from what I can tell, and profiles need only an address plus a backend to put at the +other end of it. `gen3logging`'s JSON formatter writes one object per line: @@ -23,6 +24,11 @@ chart work from what I can tell. ``` * Traces go to Alloy over OTLP on port 4318 (`http/protobuf`). +* Profiles go to Pyroscope on port 4040, pushed by the SDK in the service rather than collected by + Alloy. The service reads `PYROSCOPE_SERVER_ADDRESS` for the destination, and `PROFILE_CPU` + (default true) and `PROFILE_MEMORY` (default false) for what to push. All three are process + environment variables, so in a chart they belong in the container `env` rather than in a config + file. * `trace_id` and `span_id` come from `opentelemetry-instrumentation-logging`(python library), which puts them on every log record. They are `null` for anything logged outside a request span, such as startup or the OTLP exporter's own HTTP calls. Only lines emitted while a span is active can correlate. @@ -251,6 +257,32 @@ port 4317 closed, and Alloy's exporter fails with nothing obviously wrong in the Whether a cluster should run its own Tempo at all, given the central one, is a decision rather than a defect. +## There is no Pyroscope in the observability chart either + +The same gap as Tempo, one step further along. `lgtm-distributed` has no Pyroscope subchart at +all: its dependencies are Grafana, `loki-distributed`, `mimir-distributed`, `tempo-distributed`, +and OnCall. Nor is there a CTDS-managed Pyroscope playing the role `tempo.planx-pla.net` plays for +traces. No chart in this repo sets `PYROSCOPE_SERVER_ADDRESS`, so no deployed service pushes +profiles today. + +Local Grafana showing a Pyroscope datasource is not evidence against this. That comes from the +`grafana/otel-lgtm` container in [local-observability.md](local-observability.md), which bundles +Pyroscope and provisions the datasource itself. The two stacks share the letters and nothing +else: the kind overlay runs one process with everything in it, `helm/observability` runs the +distributed charts, and only the first has a profiling backend. + +Supporting profiles in a cluster is a separate release rather than a values change: + +- the [`pyroscope`](https://github.com/grafana/pyroscope/tree/main/operations/pyroscope/helm/pyroscope) + chart from `grafana/helm-charts`, whose distributed mode needs S3 and so an IRSA policy + alongside Mimir's and Loki's +- a Pyroscope datasource in Grafana, which section 3 has to restate anyway once + `datasources.yaml` is overridden +- `PYROSCOPE_SERVER_ADDRESS` on each service that should profile, and `PROFILE_MEMORY` where heap + profiles are wanted + +Nothing in Alloy changes for any of it, which is the one simplifying difference from traces. + ## Alert rules assume a different log shape `helm/observability/values.yaml` provisions Grafana alert rules that parse logs. Two filter on a diff --git a/examples/local_lgtm.yaml b/examples/local_lgtm.yaml index c1a6d800b..a8df42ec6 100644 --- a/examples/local_lgtm.yaml +++ b/examples/local_lgtm.yaml @@ -1,10 +1,12 @@ -# A single-pod Grafana + Prometheus + Tempo + Loki stack for local development, backing the +# A single-pod Grafana + Prometheus + Tempo + Loki + Pyroscope stack for local development, backing the # Alloy install described in docs/local-observability.md. Apply with: # # kubectl apply -f examples/local_lgtm.yaml # -# Adapted from the manifest published by grafana/docker-otel-lgtm, with one change: the Loki -# port is exposed, so Alloy has somewhere to send logs. +# Adapted from the manifest published by grafana/docker-otel-lgtm, with two changes: the Loki +# port is exposed, so Alloy has somewhere to send logs, and the Pyroscope port is exposed, so +# services can push profiles. Both already listen inside the image; a Service that omits the port +# drops the traffic rather than refusing it. # # For local development only. One replica, emptyDir storage so everything is lost on restart, # no ingress, no TLS, and Grafana's default admin/admin. The observability chart is the answer diff --git a/helm/alloy/SETUP.md b/helm/alloy/SETUP.md index b2f43ee67..0fb74cc4e 100644 --- a/helm/alloy/SETUP.md +++ b/helm/alloy/SETUP.md @@ -10,6 +10,8 @@ Before deploying Alloy, it is important to first deploy the "observability" Helm For a kind cluster, follow [docs/local-observability.md](../../docs/local-observability.md) instead. The observability chart is sized for EKS and does not deploy Tempo, so traces have nowhere to go. +Profiles are the one kind of telemetry Alloy does not carry. A service that ships a Pyroscope SDK pushes to the address in its own `PYROSCOPE_SERVER_ADDRESS`, so supporting profiling needs a Pyroscope for that address to point at and no change to `alloyConfigmapData`. + ## Configuring Alloy ### Helm Chart Configuration diff --git a/helm/observability/SETUP.md b/helm/observability/SETUP.md index d9c849778..6c9c942bc 100644 --- a/helm/observability/SETUP.md +++ b/helm/observability/SETUP.md @@ -2,7 +2,7 @@ ## Overview -The Observability Helm chart provides an all-in-one solution for deploying Mimir, Loki, and Grafana to your Kubernetes cluster, enabling a complete observability stack for metrics, logs, and visualization. +The Observability Helm chart provides an all-in-one solution for deploying Mimir, Loki, and Grafana to your Kubernetes cluster, enabling a complete observability stack for metrics, logs, and visualization. Traces and profiles are supported by the wider Gen3 observability setup, but their backends live outside this chart: Tempo is disabled here (`lgtm.tempo.enabled: false`), and Pyroscope is not part of the underlying `lgtm-distributed` chart at all. ### Grafana: A leading open-source platform for data visualization and monitoring. Grafana allows you to create rich, interactive dashboards from a variety of data sources, making it easy to analyze metrics and logs from your systems. @@ -15,6 +15,11 @@ Grafana Loki is a log aggregation system designed to efficiently collect, store, By deploying this Helm chart, you'll set up these three components together, allowing you to monitor your systems and applications comprehensively with metrics from Mimir, logs from Loki, and dashboards and alerts in Grafana. +### Pyroscope: +Grafana Pyroscope stores continuous profiling data - the CPU and memory profiles pushed by services that ship a Pyroscope SDK - and Grafana renders them as flame graphs next to the metrics from Mimir and the logs from Loki. + +***Note: Pyroscope is not a component of the `lgtm-distributed` chart and is therefore not deployed by this chart. Services push profiles directly to the Pyroscope ingest endpoint they are given in `PYROSCOPE_SERVER_ADDRESS`, rather than through Alloy, so a cluster that wants profiles needs its own Pyroscope release ([`grafana/pyroscope`](https://github.com/grafana/pyroscope/tree/main/operations/pyroscope/helm/pyroscope)) or an external one, plus a Pyroscope datasource in Grafana. For local development, [docs/local-observability.md](../../docs/local-observability.md) runs one inside the single-pod LGTM image. + ### Alloy: Grafana Alloy is a powerful observability tool that collects and ships logs and metrics from your services to Grafana Loki and Mimir for storage and analysis. From 6e57838ae29dbac91abbce094a74339f2f0c2c8f Mon Sep 17 00:00:00 2001 From: avantol Date: Wed, 26 Aug 2026 12:12:49 -0500 Subject: [PATCH 196/196] chore(docs): update local --- docs/local-observability.md | 26 +++++++++++++------------- 1 file changed, 13 insertions(+), 13 deletions(-) diff --git a/docs/local-observability.md b/docs/local-observability.md index 979a38513..74774b93d 100644 --- a/docs/local-observability.md +++ b/docs/local-observability.md @@ -77,11 +77,14 @@ The release has to be named `alloy` and live in `monitoring`. Gen3 service image Confirm Alloy came up clean: ```bash -kubectl -n monitoring logs deploy/alloy | grep -i error +kubectl -n monitoring logs deploy/alloy | grep '"level":"error"' ``` -Scrape jobs for `kube-state-metrics`, `node-exporter`, and the kubelet are part of the shipped -configuration and find nothing on kind. They sit idle rather than failing. +Expect `"level":"warn"` lines reading `tailer stopped; will retry` for any container that has not +started yet. `loki.source.kubernetes` gets a target per declared container as soon as the pod object +exists, so it retries on a backoff until the container runs. A pod stuck in +`Init:CreateContainerConfigError` or `ImagePullBackOff` produces these indefinitely without +affecting collection from healthy pods. # Step 3. Point a service at it @@ -105,19 +108,14 @@ gen3-embeddings: for `grpc` on 4317, and a mismatched pair fails when the first span is exported rather than at startup. -**Profiles need one address.** A service that ships a Pyroscope SDK pushes to -`PYROSCOPE_SERVER_ADDRESS`, which here is: +**Profiles need one address.** A service that ships a Pyroscope SDK likely pushes to +`PYROSCOPE_SERVER_ADDRESS`, which is something like: ``` PYROSCOPE_SERVER_ADDRESS=http://lgtm.monitoring:4040 ``` -CPU and memory are enabled separately. `cdispyutils.observability.configure_profiling` reads -`PROFILE_CPU` (default true) and `PROFILE_MEMORY` (default **false**), so a service pushes CPU -profiles and no memory series until `PROFILE_MEMORY` is set. Both are read from the process -environment rather than from a service's config file, so they belong in the chart's `env` list -next to the other container variables, not in the config block that carries -`PYROSCOPE_SERVER_ADDRESS`. +> NOTE: Check the individual service config for how to enable and configure observability. We are trying to consolidate Python observability into one of our Python packages that we import and use in the services, but there may be some differences across services. Services deployed in another namespace reach Alloy fine - `alloy.monitoring` resolves from anywhere in the cluster, as does `lgtm.monitoring`. @@ -149,8 +147,10 @@ Alloy tails every pod's containers by default, so absent logs are usually a writ problem rather than a collection one. Work forwards along the path. 1. **Is Alloy tailing the pod?** `kubectl -n monitoring logs deploy/alloy -c alloy | grep "opened log stream"` - names each container it reads. `tailer stopped; will retry` against a pod that is still - starting is normal and clears on its own. + names each container it reads. `tailer stopped; will retry` is normal against a container that + is not running, and clears once it starts. Against a pod wedged in `ImagePullBackOff` or + `Init:CreateContainerConfigError` it repeats on a backoff for as long as the pod exists - that is + a broken pod, not a broken collector. 1. **Is Loki accepting the writes?** `kubectl -n monitoring logs deploy/alloy -c alloy | grep "error sending batch"`. A 500 reading `at least 1 live replicas required, could only find 0` means Loki's single ingester missed its heartbeat, which on a laptop is resource pressure rather than