<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[samperrin.com]]></title><description><![CDATA[Sam Perrin's technical blog.]]></description><link>https://samperrin.com</link><generator>GatsbyJS</generator><lastBuildDate>Wed, 17 Jan 2024 20:40:47 GMT</lastBuildDate><item><title><![CDATA[Why Simplification could bring Business Value]]></title><description><![CDATA[This post explores why a simplification in licensing and a bundling of products could help bring more opportunities to show improved business value.]]></description><link>https://samperrin.com/posts/why-simplification-can-bring-business-value</link><guid isPermaLink="false">https://samperrin.com/posts/why-simplification-can-bring-business-value</guid><category><![CDATA[vmware]]></category><category><![CDATA[broadcom]]></category><pubDate>Wed, 17 Jan 2024 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Broadcom announced a &lt;a href=&quot;https://news.vmware.com/company/vmware-by-broadcom-business-transformation&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;simplification in their licensing model&lt;/a&gt; on December 11, since that time there has been mixed feelings within the industry, particularly around the shift to subscription and possible cost increases. This post aims to demonstrate some of the potential business value that can come from access to more products in the VMware Cloud Foundation offering. &lt;/p&gt;&lt;p&gt;The &lt;strong&gt;VMware Cloud Foundation&lt;/strong&gt; (VCF) offering includes the following products; &lt;/p&gt;&lt;ul&gt;&lt;li&gt;SDDC Manager&lt;/li&gt;&lt;li&gt;vSphere Enterprise Plus&lt;ul&gt;&lt;li&gt;vCenter Standard&lt;/li&gt;&lt;li&gt;vSphere with Tanzu&lt;/li&gt;&lt;li&gt;ESXi&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;vSAN Enterprise (&lt;em&gt;1TiB/Core&lt;/em&gt;)&lt;/li&gt;&lt;li&gt;NSX Enterprise Plus (&lt;em&gt;NSX Networking only&lt;/em&gt;)&lt;/li&gt;&lt;li&gt;HCX Enterprise&lt;/li&gt;&lt;li&gt;Aria Suite Enterprise&lt;ul&gt;&lt;li&gt;Aria Suite Lifecycle (previously vRealize Suite Lifecycle Manager)&lt;/li&gt;&lt;li&gt;Aria Automation (previously vRealize Automation)&lt;/li&gt;&lt;li&gt;Aria Operations (previously vRealize Operations)&lt;/li&gt;&lt;li&gt;Aria Operations for Logs (previously vRealize Log Insight)&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Aria Operations for Network (previously vRealize Network Insight)&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;It also provides access to a several add-ons that can be purchased separately, such as; &lt;/p&gt;&lt;ul&gt;&lt;li&gt;VMware Cloud Disaster Recovery (VCDR)&lt;/li&gt;&lt;li&gt;VMware Load Balancer (NSX Advanced Load Balancer)&lt;/li&gt;&lt;li&gt;Tanzu Mission Control (TMC)&lt;/li&gt;&lt;li&gt;Tanzu Application Platform (TAP)&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;An excellent resource is &lt;a href=&quot;https://twitter.com/lamw&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;William’s&lt;/a&gt; blog post that provides more information on the offerings and lists all of the add-ons: &lt;a href=&quot;https://williamlam.com/2024/01/whats-in-the-new-vmware-vsphere-foundation-vvf-and-vmware-cloud-foundation-vcf-offers.html&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;What’s in the new VMware vSphere Foundation (VVF) and VMware Cloud Foundation (VCF) offers?&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;This post will not go into detail about each product or why they might be licensed the way they are, instead it will attempt to identify opportunities that these products could bring to the business. &lt;/p&gt;&lt;p&gt;&lt;em&gt;Value&lt;/em&gt; is relative to the company, typically stakeholders, whether that is IT or other business functions, will decide what is of value and this usually aligns with the priorities of the business. For the sake of this post we will generalise and work on the basis that… &lt;strong&gt;Value is something that brings a positive change to the business, either through efficiency, cost saving or risk reduction&lt;/strong&gt;. &lt;/p&gt;&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Product&lt;/th&gt;&lt;th&gt;Efficiency&lt;/th&gt;&lt;th&gt;Cost Saving&lt;/th&gt;&lt;th&gt;Risk Reduction&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;SDDC Manager&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Automates deployment, configuration, upgrading, and patching of the VCF stack (vCenter, ESXi, NSX), simplifying operations and reducing manual labour.&lt;/td&gt;&lt;td&gt;Reduces the need for manual deployments and configurations that require lengthy designing and planning.&lt;/td&gt;&lt;td&gt;Reduces the operational risk of workloads breaking during upgrades and patches. Security risk is reduced due to the ability to quickly patch an environment.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;vSphere Enterprise Plus&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Enhances operational efficiency and transforms existing infrastructure. Maximises infrastructure capacity utilisation and improves workload performance.&lt;/td&gt;&lt;td&gt;Achieves better price performance using the latest technology on industry-standard servers.&lt;/td&gt;&lt;td&gt;Decreases downtime and improves reliability with predictive analytics and built-in high availability capabilities.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;vSAN Enterprise&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Simplifies storage management and scales elastically in per-server increments.&lt;/td&gt;&lt;td&gt;Reduces storage cost and complexity, and achieves better price performance using the latest storage technology on industry-standard servers.&lt;/td&gt;&lt;td&gt;Ensures data protection and availability.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;NSX Enterprise Plus&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Automates network management, saving time and effort.&lt;/td&gt;&lt;td&gt;Reduces network provisioning time and improves operational efficiency through automation, allowing businesses can roll out new services faster.&lt;/td&gt;&lt;td&gt;Provides consistent management of networking and security policies, independent of physical network topology, reducing the risk of outages and strengthens network infrastructure security.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;HCX Enterprise&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Supports non-vSphere workload migration into vSphere, allowing businesses to migrate large quantities of virtual workloads from different environments, providing flexibility and reducing the time and effort required for migration.&lt;/td&gt;&lt;td&gt;Multiple appliances bundled as one service, with automated functions, eliminates the need for different tools, reducing TCO.&lt;/td&gt;&lt;td&gt;Minimizes risk by providing a mobility platform across environments by abstracting the underlying infrastructure, reducing the risk of migration failures, data loss and downtime, which help ensure the continuity of operations.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Aria Suite Lifecycle&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Accelerates deployment and upgrades of the Aria Suite products.&lt;/td&gt;&lt;td&gt;Reduces ongoing management and operational costs.&lt;/td&gt;&lt;td&gt;Enforces alignment with VMware recommended reference architectures and validated designs, reducing the risk of non-compliance.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Aria Automation&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Removes the requirement for manual tasks with advanced workflows and infrastructure as code.&lt;/td&gt;&lt;td&gt;Reduces the total cost of ownership by freeing up IT budget and resources that can be reallocated elsewhere.&lt;/td&gt;&lt;td&gt;Establishes consistent policies across multi-cloud environments, reduces human error through automated infrastructure deployment.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Aria Operations&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Provides continuous performance and capacity optimisation, with intelligent remediation.&lt;/td&gt;&lt;td&gt;Reduces operating expenses and increases operational efficiency by reducing troubleshooting times and improving resolution time.&lt;/td&gt;&lt;td&gt;Reduces risk and enforces regulatory standards with integrated compliance. Can help identify under utilised and at risk infrastructure components.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Aria Operations for Logs&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Extensible across physical, virtual, and cloud environments, enabling administrators to have a single location to collect, store, and analyse logs at scale.&lt;/td&gt;&lt;td&gt;Reduces operating expenses and increases operational efficiency by reducing troubleshooting times and improving resolution time.&lt;/td&gt;&lt;td&gt;Provides visibility into security-related events, mitigating costs from unplanned downtime, by using predictive analytics, machine learning, and root cause analysis tools.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Aria Operations for Network&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Provides network visibility and analytics to accelerate application discovery and optimise network performance.&lt;/td&gt;&lt;td&gt;Reduces time spent monitoring the network, leading to cost savings.&lt;/td&gt;&lt;td&gt;Minimises the risk during application migration through discovery and identifies missing firewall policies.&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p&gt;This is a slightly different post to my usual, but hopefully with all of the recent changes within the VMware by Broadcom landscape, this provides some insight into where the VMware Cloud Foundation offering can benefit the business. &lt;/p&gt;&lt;h1 id=&quot;resources&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#resources&quot; aria-label=&quot;resources permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Resources&lt;/h1&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;https://kb.vmware.com/s/article/95927&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;Counting Cores for vSphere Foundation and VMware Cloud Foundation and TiBs for vSAN Add-on (95927)&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://news.vmware.com/company/vmware-by-broadcom-business-transformation&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;VMware by Broadcom Dramatically Simplifies Offer Lineup and Licensing Model&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://williamlam.com/2024/01/whats-in-the-new-vmware-vsphere-foundation-vvf-and-vmware-cloud-foundation-vcf-offers.html#more-184473&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;What’s in the new VMware vSphere Foundation (VVF) and VMware Cloud Foundation (VCF) offers?&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</content:encoded><tags>vmware,broadcom</tags><featuredImage>https://samperrin.com/static/2b525ae2a40d3a405bc07cf4a57ef59d/hero.jpg</featuredImage></item><item><title><![CDATA[On-demand Networking with Aria Automation and NSX]]></title><description><![CDATA[Aria Automation provides the capability to deploy on-demand network objects when combined with NSX-T, this blog post runs through the on-demand networking options available. I am not heading to VMware Explore this year but I thought I would have a browse through the sessions to build out an agenda as if I was there!]]></description><link>https://samperrin.com/posts/ondemand-networking-with-aria-automation-and-nsx/</link><guid isPermaLink="false">https://samperrin.com/posts/ondemand-networking-with-aria-automation-and-nsx/</guid><category><![CDATA[vmware]]></category><category><![CDATA[aria]]></category><category><![CDATA[automation]]></category><pubDate>Wed, 20 Dec 2023 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;In Aria Automation you can create Network Profiles, these are the networks and network settings for deployments, one of those settings is for &lt;strong&gt;Isolation Policy&lt;/strong&gt;, which has the options; &lt;code class=&quot;language-text&quot;&gt;None&lt;/code&gt;, &lt;code class=&quot;language-text&quot;&gt;On-demand Network&lt;/code&gt; and &lt;code class=&quot;language-text&quot;&gt;On-demand Security Group&lt;/code&gt;. In this post we will have a high-level look at what both of the on-demand options really mean and what is required to get them working with Aria Automation. &lt;/p&gt;&lt;h2 id=&quot;on-demand-network&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#on-demand-network&quot; aria-label=&quot;on demand network permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;On-demand Network&lt;/h2&gt;&lt;p&gt;With this policy a network is created for each deployment using the settings specified within the Network Policies tab and all virtual machines within the deployment are attached to this network/segment.&lt;/p&gt;&lt;h3 id=&quot;network-profile-requirements-summary&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#network-profile-requirements-summary&quot; aria-label=&quot;network profile requirements summary permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Network Profile Requirements Summary&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;NSX Cloud Account within Aria Automation. &lt;/li&gt;&lt;li&gt;Transport Zone configured within NSX.&lt;/li&gt;&lt;li&gt;An “External Network”, think of it as routable, available within NSX and Aria Automation, this is used to create an outbound SNAT rule from the on-demand networks. &lt;/li&gt;&lt;li&gt;The “External Network” needs to be configured within Aria Automation with Domain, CIDR, DNS and IP Range. &lt;/li&gt;&lt;li&gt;A Tier-0 router configured within NSX, this is used for outbound access for the on-demand networks. &lt;/li&gt;&lt;li&gt;An Edge Cluster configured within NSX, this is used for outbound access for the on-demand networks. &lt;/li&gt;&lt;li&gt;An IPAM configuration using either Aria Automation Internal IPAM or External IPAM, this is used to allocate the subnets to the on-demand networks. &lt;/li&gt;&lt;li&gt;A Cloud Template that has a NSX network resource using the networkType of &lt;code class=&quot;language-text&quot;&gt;outbound&lt;/code&gt;, &lt;code class=&quot;language-text&quot;&gt;private&lt;/code&gt;, or &lt;code class=&quot;language-text&quot;&gt;routed&lt;/code&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;When a deployment associates itself with a Network Profile that is set to create an on-demand network, the following objects are created within NSX, which differ depending on the networkType. &lt;/p&gt;&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Object/Resource&lt;/th&gt;&lt;th&gt;&lt;code class=&quot;language-text&quot;&gt;outbound&lt;/code&gt;&lt;/th&gt;&lt;th&gt;&lt;code class=&quot;language-text&quot;&gt;private&lt;/code&gt;&lt;/th&gt;&lt;th&gt;&lt;code class=&quot;language-text&quot;&gt;routed&lt;/code&gt;&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;Tier-1 Gateway&lt;/td&gt;&lt;td&gt;✓&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;✓&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Network Segment&lt;/td&gt;&lt;td&gt;✓&lt;/td&gt;&lt;td&gt;✓&lt;/td&gt;&lt;td&gt;✓&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;NAT Rule (SNAT)&lt;/td&gt;&lt;td&gt;✓&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;DHCP Server*&lt;/td&gt;&lt;td&gt;✓&lt;/td&gt;&lt;td&gt;✓&lt;/td&gt;&lt;td&gt;✓&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;ul&gt;&lt;li&gt;The created Tier-1 Gateway is attached to the Tier-0 Gateway and Edge Cluster specified in the Network Profile. &lt;/li&gt;&lt;li&gt;The created Segment is attached to the Transport Zone specified in the Network Profile and a subnet is allocated from the IPAM section within the Network Profile. The gateway address is set to first address in the allocated subnet. &lt;/li&gt;&lt;li&gt;If required, an SNAT rule is attached to the created Tier-1. This is configured so that the “Source” is the IP range allocated to the segment and the “Translated IP” comes from the External Network specified within the Network Profile and its pre-configured IP Range. &lt;/li&gt;&lt;li&gt;Virtual Machines within the Deployment are attached to the created Segment (if linked in the Cloud Template)&lt;/li&gt;&lt;li&gt;&lt;em&gt;If the Network Profile &amp;gt; Network Policies &amp;gt; IP Address Management &amp;gt; IP Range Assignment is set to use &lt;/em&gt;DHCP&lt;em&gt; or &lt;/em&gt;Static and DHCP&lt;em&gt; then an NSX hosted DHCP Server is created. The size of this range depends on the option, for &lt;/em&gt;DHCP&lt;em&gt; it is for ALL IP’s in the network, for &lt;/em&gt;Static and DHCP* it is half of the network. &lt;/li&gt;&lt;/ul&gt;&lt;h2 id=&quot;on-demand-security-group&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#on-demand-security-group&quot; aria-label=&quot;on demand security group permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;On-demand Security Group&lt;/h2&gt;&lt;p&gt;With this policy a security group is created for each deployment and all of the virtual machines within the deployment are members of this security group. &lt;/p&gt;&lt;h3 id=&quot;network-profile-requirements-summary-1&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#network-profile-requirements-summary-1&quot; aria-label=&quot;network profile requirements summary 1 permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Network Profile Requirements Summary&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;NSX Cloud Account within Aria Automation. &lt;/li&gt;&lt;li&gt;Existing networks configured to attach VMs to.&lt;/li&gt;&lt;li&gt;If you are going to use static IP assignment within the Cloud Template then the networks need to be configured within Aria Automation with Domain, CIDR, DNS and IP Range.&lt;/li&gt;&lt;li&gt;A Cloud Template that has a NSX network resource using the networkType of &lt;code class=&quot;language-text&quot;&gt;outbound&lt;/code&gt; or &lt;code class=&quot;language-text&quot;&gt;private&lt;/code&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;When a deployment associates itself with a Network Profile that is set to create an on-demand security group, the following DFW rules are created within NSX. The security group is usually named &lt;em&gt;isolation-securitygroup-GUID&lt;/em&gt;. The VMs are added to the security group based on their allocated IP address (the IP’s are security group members).&lt;/p&gt;&lt;h4 id=&quot;network-type-outbound&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#network-type-outbound&quot; aria-label=&quot;network type outbound permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Network Type: Outbound&lt;/h4&gt;&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Rule Name&lt;/th&gt;&lt;th&gt;Sources&lt;/th&gt;&lt;th&gt;Destinations&lt;/th&gt;&lt;th&gt;Services&lt;/th&gt;&lt;th&gt;Applied To&lt;/th&gt;&lt;th&gt;Action&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;inbound-deny-all&lt;/td&gt;&lt;td&gt;Any&lt;/td&gt;&lt;td&gt;isolation-securitygroup&lt;/td&gt;&lt;td&gt;Any&lt;/td&gt;&lt;td&gt;isolation-securitygroup&lt;/td&gt;&lt;td&gt;Reject&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;outbound-allow-all&lt;/td&gt;&lt;td&gt;isolation-securitygroup&lt;/td&gt;&lt;td&gt;Any&lt;/td&gt;&lt;td&gt;Any&lt;/td&gt;&lt;td&gt;isolation-securitygroup&lt;/td&gt;&lt;td&gt;Allow&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;allow-intra-traffic&lt;/td&gt;&lt;td&gt;isolation-securitygroup&lt;/td&gt;&lt;td&gt;isolation-securitygroup&lt;/td&gt;&lt;td&gt;Any&lt;/td&gt;&lt;td&gt;isolation-securitygroup&lt;/td&gt;&lt;td&gt;Allow&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;h4 id=&quot;network-type-private&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#network-type-private&quot; aria-label=&quot;network type private permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Network Type: Private&lt;/h4&gt;&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Rule Name&lt;/th&gt;&lt;th&gt;Sources&lt;/th&gt;&lt;th&gt;Destinations&lt;/th&gt;&lt;th&gt;Services&lt;/th&gt;&lt;th&gt;Applied To&lt;/th&gt;&lt;th&gt;Action&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;inbound-deny-all&lt;/td&gt;&lt;td&gt;Any&lt;/td&gt;&lt;td&gt;isolation-securitygroup&lt;/td&gt;&lt;td&gt;Any&lt;/td&gt;&lt;td&gt;isolation-securitygroup&lt;/td&gt;&lt;td&gt;Reject&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;allow-intra-traffic&lt;/td&gt;&lt;td&gt;isolation-securitygroup&lt;/td&gt;&lt;td&gt;isolation-securitygroup&lt;/td&gt;&lt;td&gt;Any&lt;/td&gt;&lt;td&gt;isolation-securitygroup&lt;/td&gt;&lt;td&gt;Allow&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;outbound-allow-all&lt;/td&gt;&lt;td&gt;isolation-securitygroup&lt;/td&gt;&lt;td&gt;Any&lt;/td&gt;&lt;td&gt;Any&lt;/td&gt;&lt;td&gt;isolation-securitygroup&lt;/td&gt;&lt;td&gt;Reject&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p&gt;&lt;strong&gt;Tip&lt;/strong&gt;: Tag your resources in Aria Automation to easily identify objects created by AA - for example add a tag with key: ManagedBy and value: AriaAutomation to Network and Virtual Machine resources to enable the quick search and filtering of these tags in vSphere and NSX - be aware that the DHCP Server in NSX is not tagged!&lt;/p&gt;&lt;p&gt;Hopefully this has been helpful in understanding what is created within NSX when using Aria Automation’s on-demand isolation options. &lt;/p&gt;&lt;h1 id=&quot;resources&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#resources&quot; aria-label=&quot;resources permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Resources&lt;/h1&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;https://docs.vmware.com/en/VMware-Aria-Automation/SaaS/Using-Automation-Assembler/GUID-01E442EE-4004-4ED1-AA32-9CF73F24CB09.html&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;Learn more about network profiles in VMware Aria Automation&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</content:encoded><tags>vmware,aria,automation</tags><featuredImage>https://samperrin.com/static/abb78af02a17814c03097659061de8d2/hero.jpg</featuredImage></item><item><title><![CDATA[VMware Explore 2023 Session Agenda]]></title><description><![CDATA[I am not heading to VMware Explore this year but I thought I would have a browse through the sessions to build out an agenda as if I was there!]]></description><link>https://samperrin.com/posts/vmware-explore-2023-session-agenda/</link><guid isPermaLink="false">https://samperrin.com/posts/vmware-explore-2023-session-agenda/</guid><category><![CDATA[vmware]]></category><pubDate>Thu, 19 Oct 2023 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;I am not heading to VMware Explore this year but I thought I would spend a bit of time going through the Content Catalog. I have built out a rough agenda based on the products I am interested in, you can find that agenda below (&lt;em&gt;I have not put much effort into avoiding duplicate time slots&lt;/em&gt;).  &lt;/p&gt;&lt;h1 id=&quot;honorary-mentions&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#honorary-mentions&quot; aria-label=&quot;honorary mentions permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Honorary Mentions&lt;/h1&gt;&lt;p&gt;There are a couple of sessions from &lt;strong&gt;Xtravirt&lt;/strong&gt;, these are;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Mastering Cross-Cloud Integration: Insights &amp;amp; Best Practices from Xtravirt [&lt;a href=&quot;https://event.vmware.com/flow/vmware/explore2023bcn/content/page/catalog?search=CEIB1454BCN&amp;amp;tab.contentcatalogtabs=1627421929827001vRXW&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;CEIB1454BCN&lt;/a&gt;]&lt;/strong&gt;&lt;br/&gt;
&lt;a href=&quot;https://event.vmware.com/flow/vmware/explore2023bcn/content/page/speakers?search=%22Steve%20Wood%22#:~:text=Steve%20Wood&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;Steve Wood&lt;/a&gt;, Head of Managed Services&lt;br/&gt;
&lt;em&gt;Wednesday, Nov 8 2:00 PM - 2:45 PM CET&lt;/em&gt;&lt;br/&gt;
Explore real-world challenges solved by VMware Cross-Cloud Services through tangible use-cases and experiences, underlined by Xtravirt’s expertise. Dive into how a strategic partnership with a Cross-Cloud Managed Services Provider navigates complexities, ensures interoperability, and maintains compliance across varied cloud environments, enhancing efficiency and security in your cloud ecosystem, whilst optimising for scale.&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Customer Panel: Cloud-Smart Insights from the Public Sector [&lt;a href=&quot;https://event.vmware.com/flow/vmware/explore2023bcn/content/page/catalog?search=CEIB1800BCN&amp;amp;tab.contentcatalogtabs=1627421929827001vRXW&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;CEIB1800BCN&lt;/a&gt;]&lt;/strong&gt;&lt;br/&gt;
&lt;a href=&quot;https://event.vmware.com/flow/vmware/explore2023bcn/content/page/speakers?search=%22Robin%20Gardner%22#:~:text=Robin%252Gardner&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;Robin Gardner&lt;/a&gt;, Director of Strategic Services&lt;br/&gt;
&lt;em&gt;Tuesday, Nov 7 2:15 PM - 3:00 PM CET&lt;/em&gt;&lt;br/&gt;
As IT accelerates in this era of AI, Cross Cloud Services and Big Data, join Xtravirt and a panel of Higher Education and Government IT leaders for an open and honest discussion on how Public Sector organisations are evolving to embrace these new opportunities. Challenged by skills shortages, financial constraints, ransomware and the ever present burden of technical debt, the panel will share their experiences of navigating their own pathway to cloud smart. From universities to local government, how are establishments achieving the game-changing benefits new technologies offer?&lt;br/&gt;&lt;/p&gt;&lt;h1 id=&quot;selected-sessions&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#selected-sessions&quot; aria-label=&quot;selected sessions permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Selected Sessions&lt;/h1&gt;&lt;p&gt;These are the sessions that have piqued my interest across the 4 days of VMware Explore Barcelona. &lt;/p&gt;&lt;h2 id=&quot;monday-6th-nov&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#monday-6th-nov&quot; aria-label=&quot;monday 6th nov permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Monday 6th Nov&lt;/h2&gt;&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Session&lt;/th&gt;&lt;th&gt;Session ID&lt;/th&gt;&lt;th&gt;Time (CET)&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;Deliver Cloud-Native and Traditional IT Resources on VMware Cloud&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://event.vmware.com/flow/vmware/explore2023bcn/content/page/catalog?search=MAPT1605BCN&amp;amp;tab.contentcatalogtabs=1627421929827001vRXW&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;MAPT1605BCN&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;em&gt;11:00 AM - 12:30 PM&lt;/em&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Blueprint to Brilliance: Navigating the Marvels of VMware Cloud Foundation&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://event.vmware.com/flow/vmware/explore2023bcn/content/page/catalog?search=CXS2060BCN&amp;amp;tab.contentcatalogtabs=1627421929827001vRXW&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;CXS2060BCN&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;em&gt;1:00 PM - 1:45 PM&lt;/em&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;VMware Edge Compute Stack Reference Architecture Deep Dive&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://event.vmware.com/flow/vmware/explore2023bcn/content/page/catalog?search=CEIT1999BCN&amp;amp;tab.contentcatalogtabs=1627421929827001vRXW&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;CEIT1999BCN&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;em&gt;1:00 PM - 2:30 PM&lt;/em&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Livefire: Reveal Cluster Class Model for ClusterAPI Topologies Explore TAP&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://event.vmware.com/flow/vmware/explore2023bcn/content/page/catalog?search=PART2247BCN&amp;amp;tab.contentcatalogtabs=1627421929827001vRXW&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;PART2247BCN&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;em&gt;1:00 PM - 5:00 PM&lt;/em&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Join the Revolution to Shape the Future of the Multi-Cloud Platform&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://event.vmware.com/flow/vmware/explore2023bcn/content/page/catalog?search=DWS2147BCN&amp;amp;tab.contentcatalogtabs=1627421929827001vRXW&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;DWS2147BCN&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;em&gt;2:30 PM - 3:30 PM&lt;/em&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Platform Engineering Done Right: Providing a Developer Platform with VMware Tanzu&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://event.vmware.com/flow/vmware/explore2023bcn/content/page/catalog?search=MAPT1606BCN&amp;amp;tab.contentcatalogtabs=1627421929827001vRXW&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;MAPT1606BCN&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;em&gt;3:00 PM - 4:30 PM&lt;/em&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;How to Migrate Apps Live to Any Cloud&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://event.vmware.com/flow/vmware/explore2023bcn/content/page/catalog?search=VMTN2196BCN&amp;amp;tab.contentcatalogtabs=1627421929827001vRXW&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;VMTN2196BCN&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;em&gt;4:00 PM - 4:15 PM&lt;/em&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;A Road to Modern Apps with VMware Tanzu&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://event.vmware.com/flow/vmware/explore2023bcn/content/page/catalog?search=CODE1986BCN&amp;amp;tab.contentcatalogtabs=1627421929827001vRXW&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;CODE1986BCN&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;em&gt;4:00 PM - 4:20 PM&lt;/em&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;h2 id=&quot;tuesday-7th-nov&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#tuesday-7th-nov&quot; aria-label=&quot;tuesday 7th nov permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Tuesday 7th Nov&lt;/h2&gt;&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Session&lt;/th&gt;&lt;th&gt;Session ID&lt;/th&gt;&lt;th&gt;Time (CET)&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;Network Observability for Private and Public Cloud with VMware Aria Operations for Networks&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://event.vmware.com/flow/vmware/explore2023bcn/content/page/catalog?search=MAPB2297BCN&amp;amp;tab.contentcatalogtabs=1627421929827001vRXW&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;MAPB2297BCN&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;em&gt;10:30 AM - 11:15 AM&lt;/em&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Protecting VMware Workloads Running in Azure, AWS or Google Cloud with Veeam&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://event.vmware.com/flow/vmware/explore2023bcn/content/page/catalog?search=CEIB1649BCN&amp;amp;tab.contentcatalogtabs=1627421929827001vRXW&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;CEIB1649BCN&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;em&gt;10:30 AM - 11:15 AM&lt;/em&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Extending the Capabilities of VMware Aria Automation&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://event.vmware.com/flow/vmware/explore2023bcn/content/page/catalog?search=CXS1887BCN&amp;amp;tab.contentcatalogtabs=1627421929827001vRXW&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;CXS1887BCN&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;em&gt;11:30 AM - 12:15 PM&lt;/em&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Unleash the Power of Cloud Native – Insights from a Leading Cloud Provider&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://event.vmware.com/flow/vmware/explore2023bcn/content/page/catalog?search=MAPB1236BCN&amp;amp;tab.contentcatalogtabs=1627421929827001vRXW&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;MAPB1236BCN&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;em&gt;1:00 PM - 1:45 PM&lt;/em&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Apps and Infra Management with the New VMware Tanzu Integrated Solution Powered by Tanzu Hub&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://event.vmware.com/flow/vmware/explore2023bcn/content/page/catalog?search=MAPB2300BCN&amp;amp;tab.contentcatalogtabs=1627421929827001vRXW&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;MAPB2300BCN&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;em&gt;2:15 PM - 3:00 PM&lt;/em&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Developing for VMware Aria Automation at Enterprise Scale&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://event.vmware.com/flow/vmware/explore2023bcn/content/page/catalog?search=CEIB1235BCN&amp;amp;tab.contentcatalogtabs=1627421929827001vRXW&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;CEIB1235BCN&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;em&gt;2:15 PM - 3:00 PM&lt;/em&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;What’s New with VMware Cloud Foundation and Operational Best Practices?&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://event.vmware.com/flow/vmware/explore2023bcn/content/page/catalog?search=CEIB1446BCN&amp;amp;tab.contentcatalogtabs=1627421929827001vRXW&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;CEIB1446BCN&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;em&gt;2:15 PM - 3:00 PM&lt;/em&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;h2 id=&quot;wednesday-8th-nov&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#wednesday-8th-nov&quot; aria-label=&quot;wednesday 8th nov permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Wednesday 8th Nov&lt;/h2&gt;&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Session&lt;/th&gt;&lt;th&gt;Session ID&lt;/th&gt;&lt;th&gt;Time (CET)&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;Transforming the Retail Experience with VMware Edge Compute Stack&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://event.vmware.com/flow/vmware/explore2023bcn/content/page/catalog?search=CEIB2001BCN&amp;amp;tab.contentcatalogtabs=1627421929827001vRXW&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;CEIB2001BCN&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;em&gt;9:00 AM - 9:45 AM&lt;/em&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Automate Kubernetes Platform Ops with VMware Tanzu for Kubernetes Operations&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://event.vmware.com/flow/vmware/explore2023bcn/content/page/catalog?search=MAPB1392BCN&amp;amp;tab.contentcatalogtabs=1627421929827001vRXW&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;MAPB1392BCN&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;em&gt;11:30 AM - 12:15 PM&lt;/em&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Mastering VCF: Orange France Streamlines Cloud Without VMware Expertise&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://event.vmware.com/flow/vmware/explore2023bcn/content/page/catalog?search=CEIB2131BCN&amp;amp;tab.contentcatalogtabs=1627421929827001vRXW&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;CEIB2131BCN&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;em&gt;11:30 AM - 12:15 PM&lt;/em&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Optimizing Distributed Cloud Architectures – Powered by Platform Equinix.&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://event.vmware.com/flow/vmware/explore2023bcn/content/page/catalog?search=CEI2472BCNS&amp;amp;tab.contentcatalogtabs=1627421929827001vRXW&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;CEI2472BCNS&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;em&gt;12:45 PM - 1:15 PM&lt;/em&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;AI Without GPUs: Run AI/ML Workloads on Intel AMX CPUs with vSphere 8 and Tanzu&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://event.vmware.com/flow/vmware/explore2023bcn/content/page/catalog?search=MAPB2367BCN&amp;amp;tab.contentcatalogtabs=1627421929827001vRXW&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;MAPB2367BCN&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;em&gt;12:45 PM - 1:30 PM&lt;/em&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Automating with VMware Aria Automation Orchestrator&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://event.vmware.com/flow/vmware/explore2023bcn/content/page/catalog?search=CXS1888BCN&amp;amp;tab.contentcatalogtabs=1627421929827001vRXW&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;CXS1888BCN&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;em&gt;1:00 PM - 1:45 PM&lt;/em&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Mastering Cross-Cloud Integration: Insights &amp;amp; Best Practices from Xtravirt&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://event.vmware.com/flow/vmware/explore2023bcn/content/page/catalog?search=CEIB1454BCN&amp;amp;tab.contentcatalogtabs=1627421929827001vRXW&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;CEIB1454BCN&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;em&gt;2:00 PM - 2:45 PM&lt;/em&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Achieve AI/ML-Based Insights with Full-Stack Contextual Observability&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://event.vmware.com/flow/vmware/explore2023bcn/content/page/catalog?search=MAPB1747BCN&amp;amp;tab.contentcatalogtabs=1627421929827001vRXW&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;MAPB1747BCN&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;em&gt;2:00 PM - 2:45 PM&lt;/em&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Success Story – Accelerate DC Exit by Using Google Cloud VMware Engine&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://event.vmware.com/flow/vmware/explore2023bcn/content/page/catalog?search=MAPB1604BCN&amp;amp;tab.contentcatalogtabs=1627421929827001vRXW&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;MAPB1604BCN&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;em&gt;3:15 PM - 4:00 PM&lt;/em&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Resilient IT Architecture in a Multi-Cloud World&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://event.vmware.com/flow/vmware/explore2023bcn/content/page/catalog?search=VMTN2345BCN&amp;amp;tab.contentcatalogtabs=1627421929827001vRXW&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;VMTN2345BCN&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;em&gt;4:00 PM - 4:25 PM&lt;/em&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Need to Migrate Thousands of Workloads? No Problem.&lt;/td&gt;&lt;td&gt;[&lt;a href=&quot;https://event.vmware.com/flow/vmware/explore2023bcn/content/page/catalog?search=CXS1373BCN&amp;amp;tab.contentcatalogtabs=1627421929827001vRXW&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;XS1373BCN&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;em&gt;4:00 PM - 4:45 PM&lt;/em&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;h2 id=&quot;thursday-9th-nov&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#thursday-9th-nov&quot; aria-label=&quot;thursday 9th nov permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Thursday 9th Nov&lt;/h2&gt;&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Session&lt;/th&gt;&lt;th&gt;Session ID&lt;/th&gt;&lt;th&gt;Time (CET)&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;How to Migrate 25K Workloads to VMware Cloud Foundation with Security Posture&lt;/td&gt;&lt;td&gt;&lt;a href=&quot;https://event.vmware.com/flow/vmware/explore2023bcn/content/page/catalog?search=CSXB1301BCN&amp;amp;tab.contentcatalogtabs=1627421929827001vRXW&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;CSXB1301BCN&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;em&gt;11:15 AM - 12:00 PM&lt;/em&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;h1 id=&quot;products&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#products&quot; aria-label=&quot;products permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Products&lt;/h1&gt;&lt;p&gt;The products I am interested in which I used to filter the Content Catalog by, I dont have a session for every product. &lt;/p&gt;&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Tanzu / Cloud Native / Modern Apps&lt;/th&gt;&lt;th&gt;VMware Aria Suite&lt;/th&gt;&lt;th&gt;Everything Else&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;VMware Tanzu&lt;/td&gt;&lt;td&gt;VMware Aria Automation&lt;/td&gt;&lt;td&gt;Azure VMware Solution&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;VMware Tanzu Application Platform&lt;/td&gt;&lt;td&gt;VMware Aria Automation Assembler&lt;/td&gt;&lt;td&gt;VMware Cloud Director&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;VMware Tanzu CloudHealth&lt;/td&gt;&lt;td&gt;VMware Aria Automation Config&lt;/td&gt;&lt;td&gt;VMware Cloud Foundation&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;VMware Tanzu Hub&lt;/td&gt;&lt;td&gt;VMware Aria Automation Orchestrator&lt;/td&gt;&lt;td&gt;VMware Cloud Foundation with Tanzu&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;VMware Tanzu Mission Control&lt;/td&gt;&lt;td&gt;VMware Aria Operations for Networks&lt;/td&gt;&lt;td&gt;VMware Cloud on Equinix Metal&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Cluster API&lt;/td&gt;&lt;td&gt;VMware Aria Universal Suite&lt;/td&gt;&lt;td&gt;VMware Edge&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Project Harbor&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;VMware Edge Compute Stack&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Project Antrea&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;VMware NSX Advanced Load Balancer&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;VMware Application Catalog&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;VMware Validated Design&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;h1 id=&quot;resources&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#resources&quot; aria-label=&quot;resources permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Resources&lt;/h1&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;https://event.vmware.com/flow/vmware/explore2023bcn/content/page/catalog&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;Content Catalog - VMware Explore 2023 Barcelona&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</content:encoded><tags>vmware</tags><featuredImage>https://samperrin.com/static/6003ba9369062bf706f9e55e5f5b0259/hero.png</featuredImage></item><item><title><![CDATA[Aria Automation Startup Troubleshooting]]></title><description><![CDATA[Recently I experienced some issues bringing up an older version or vRealize/Aria Automation, this post looks at the steps to bring the appliance back online.]]></description><link>https://samperrin.com/posts/aria-automation-startup-troubleshooting/</link><guid isPermaLink="false">https://samperrin.com/posts/aria-automation-startup-troubleshooting/</guid><category><![CDATA[vmware]]></category><category><![CDATA[aria]]></category><category><![CDATA[aria-automation]]></category><category><![CDATA[aria-hub]]></category><category><![CDATA[vrealize]]></category><pubDate>Thu, 20 Jul 2023 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;I recently had to bring up an old lab environment that was using an older version of vRA (8.8), but at appliance boot the Kubernetes API-Server containers continuously rebooted and I got an error with kubectl. This post covers some of the troubleshooting steps taken and how it was resolved, ultimately it was caused by an expired certificate. &lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:831px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:69.31407942238268%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAOCAYAAAAvxDzwAAAACXBIWXMAAA7DAAAOwwHHb6hkAAACCUlEQVQ4y22T67KcIBCEdRXkKngHXXWT93/HTs2469lU8oNScWi+aZri97biSAlOKUTf4nWeaNsWRVFAKYVpGiEbiVoIPB4PGGsxzjO0sahqgRA7Hkob/i7SumJJGVobOO+RckYIkQXruoaxhoe1FlJKCCnhvIMxGmVZoGka/q+15jXFtm1Y0sLFNLmkhGmeuDDEgHEc4b1navovhEAbApxzTExdEAhtyIJ5zVi3lReHGLE9nxjGgemUVogxspCUAlVVsaB/C5RlyRtbdxGz4H7s2PedBb1vMU4T03B7ooZv/VX4HtSyb9tbkAlZ0Fw1aVuRt5UX0o9hGPhJYh8aWvgteHloLkKlWPz28Nw2zMMAJSWkqJmOBi34+PotWNFBGcN20DxtqrRmUq45+h45RkRjEJ1Dzgmxi2hDy6TWWfaJD0RKXkxEJMj+WXO/k8fFuT+R5xk1+SEbLMty41P++r7n3WnuEyOypVEN13wS0DTyIpw5JjMXUCv03g8Di1Ex0RIR+UbCFHDrvjzkHH55eBw7jvNA13Xo+h7n68W5vOJgMY4DtDEQ79iQr5QI2uCTw+tA3zlMObEAhZN2IWHnPLdHAiT61ykLccfk/4TnidevF7dGIU4p85NImCYElI/HLUhzPzel/Pem0FWjFuqqQiUq6KBhtLkI6+p9Z38IaZ4sIKHv2BAp1fwB9is51QwbYpIAAAAASUVORK5CYII=&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;kube-apiserver container existing and disappearing due to startup issues&quot; title=&quot;kube-apiserver container existing and disappearing due to startup issues&quot; src=&quot;/static/d9a6676cef21580fc46dff03eb37a19d/1aa23/Screenshot_2023-07-21_113816.png&quot; srcSet=&quot;/static/d9a6676cef21580fc46dff03eb37a19d/1aa23/Screenshot_2023-07-21_113816.png 831w&quot; sizes=&quot;(max-width: 831px) 100vw, 831px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;kube-apiserver container existing and disappearing due to startup issues&lt;/figcaption&gt;
  &lt;/figure&gt; &lt;/p&gt;&lt;p&gt;I checked the service status for both kubelet and docker, both were active and running. Next I checked kubelet with journalctl - &lt;code class=&quot;language-text&quot;&gt;journalctl -u kubelet -r&lt;/code&gt;, the &lt;code class=&quot;language-text&quot;&gt;-r&lt;/code&gt; flag shows us the newest messages first. &lt;/p&gt;&lt;p&gt;There was a lot of repetitive logs stating the DNS name of our node was not found, but in amongst the noise there was also TLS and certificate related messages, include the path to the pem file that it was trying to use. &lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1123px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:36.15316117542298%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAHCAYAAAAIy204AAAACXBIWXMAAA7DAAAOwwHHb6hkAAABA0lEQVQoz42RyXLEIAxEvdt4YROLjeP8/1/2lERmbknl0AVoeWqgMccOshbBE1JKCCEgxgjnHOZ5xjRNGMcR4zTKeRgGNE3zu7quw6Z3nF8nyveNnDO01ljXVWB93wuE6/4EveWsQ8wJlAjGm4+Ltm0F1vVdXf8LVErJ9YgCGG6txbZt4pBzy7LUVS0SY71jalVYRTXOZhptDAyDXJX3DK/v6T3BOY8QIrQ2oEAg8pKXemthnZUeMbJvaOQTUkJMESlnXNeF+y54ngc5n0j5xHUVeCJcpUiu3EVquS+ftSflJHBxaH+uym54Og9hhxw3hh14HMfxybG4lp/KeS/DeL/vO16ct6Ag3B8gUAAAAABJRU5ErkJggg==&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Kubelet service status with node not found logs&quot; title=&quot;Kubelet service status with node not found logs&quot; src=&quot;/static/a62811ac8c12b29aae4454c13a51e94c/323a1/Screenshot_2023-07-21_114351.png&quot; srcSet=&quot;/static/a62811ac8c12b29aae4454c13a51e94c/323a1/Screenshot_2023-07-21_114351.png 1123w&quot; sizes=&quot;(max-width: 1123px) 100vw, 1123px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Kubelet service status with node not found logs&lt;/figcaption&gt;
  &lt;/figure&gt; &lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1591px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:14.330609679446887%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAADCAYAAACTWi8uAAAACXBIWXMAAA7DAAAOwwHHb6hkAAAAi0lEQVQI1x2PQQ7EMAgDWym9bE+AIaFp//9Mr+CAFJl4bA4DqKqMcM41CYBmNda6u9MdzCcJB0WVqkK4871vbhFaeWdwjMGjFmUuWGYyIgh4g9WMPmdre++GlFb/6/3dP74iRAQzF69r8OiGpp2wcnWLathGUe6COrgqbEbDal/hnyk36rJFwHieJ/+8YknMjyhf0AAAAABJRU5ErkJggg==&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Kubelet service status with TLS/certificate errors in the logs&quot; title=&quot;Kubelet service status with TLS/certificate errors in the logs&quot; src=&quot;/static/492da97d22846a823b679d67338888d5/7cfc5/Screenshot_2023-07-21_115903.png&quot; srcSet=&quot;/static/492da97d22846a823b679d67338888d5/7cfc5/Screenshot_2023-07-21_115903.png 1591w&quot; sizes=&quot;(max-width: 1591px) 100vw, 1591px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Kubelet service status with TLS/certificate errors in the logs&lt;/figcaption&gt;
  &lt;/figure&gt; &lt;/p&gt;&lt;p&gt;I then used an OpenSSL command to check the validity of the certificate: &lt;code class=&quot;language-text&quot;&gt;sudo openssl x509 -in /var/lib/kubelet/pki/kubelet-server-current.pem -text -noout  | grep -A 2 Validity&lt;/code&gt; - this showed us that the certificate had expired. &lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1022px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:6.066536203522505%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAABCAYAAADeko4lAAAACXBIWXMAAA7DAAAOwwHHb6hkAAAAOklEQVQI1z2IMQ6AQAzDGGjTiiYL4v9PDbobbrBs+Xru8Av4o6yhJXlIc3nG3e2qOgawycxNRJxe/wdudRYSsyqEEgAAAABJRU5ErkJggg==&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;openssl command to show the certificate validity&quot; title=&quot;openssl command to show the certificate validity&quot; src=&quot;/static/104ad4fd11bed1f0298659f1f2f6bcd8/e5fd4/Screenshot_2023-07-21_120045.png&quot; srcSet=&quot;/static/104ad4fd11bed1f0298659f1f2f6bcd8/e5fd4/Screenshot_2023-07-21_120045.png 1022w&quot; sizes=&quot;(max-width: 1022px) 100vw, 1022px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;openssl command to show the certificate validity&lt;/figcaption&gt;
  &lt;/figure&gt; &lt;/p&gt;&lt;p&gt;After some digging I came across the following VMware KB article, although the symptoms were not the same it did mention that the certificate had expired after a year, which did match what I was seeing - &lt;a href=&quot;https://kb.vmware.com/s/article/82378&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://kb.vmware.com/s/article/82378&lt;/a&gt;&lt;/p&gt;&lt;p&gt;I am using a single vRA Appliance, so I followed the relevant steps within the KB, however I had some issues, which is the purpose of this post, the adjustments I made are below, along with the exact commands I ran…&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Take a snapshot of the vRA VM.&lt;/li&gt;&lt;li&gt;Locate an etcd backup at &lt;code class=&quot;language-text&quot;&gt;/data/etcd-backup/&lt;/code&gt; and copy the selected backup to &lt;code class=&quot;language-text&quot;&gt;/root&lt;/code&gt;.&lt;ul&gt;&lt;li&gt;I ran &lt;code class=&quot;language-text&quot;&gt;ls -lh /data/etcd-backup/&lt;/code&gt; - this showed me the available backups in date order (oldest to newest). I picked the most recent backup (not the .part file).&lt;/li&gt;&lt;li&gt;I copied this to root with &lt;code class=&quot;language-text&quot;&gt;cp /data/etcd-backup/backup-1679068501.db /root&lt;/code&gt;.&lt;/li&gt;&lt;li&gt;I checked the backup was in root with &lt;code class=&quot;language-text&quot;&gt;ls /root&lt;/code&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Reset Kubernetes by running &lt;code class=&quot;language-text&quot;&gt;vracli cluster leave&lt;/code&gt;.&lt;ul&gt;&lt;li&gt;This takes a little while to run.&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Restore the etcd backup in &lt;code class=&quot;language-text&quot;&gt;/root&lt;/code&gt; by using the &lt;code class=&quot;language-text&quot;&gt;/opt/scripts/recover_etcd.sh&lt;/code&gt; command. Example: &lt;code class=&quot;language-text&quot;&gt;/opt/scripts/recover_etcd.sh --confirm /root/backup-123456789.db&lt;/code&gt;.&lt;ul&gt;&lt;li&gt;I ran &lt;code class=&quot;language-text&quot;&gt;/opt/scripts/recover_etcd.sh --confirm /root/backup-1679068501.db&lt;/code&gt; - the same as the example from VMware, updated with my backup file name. &lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Extract VA config from etcd with: &lt;code class=&quot;language-text&quot;&gt;kubectl get vaconfig -o yaml --export &amp;gt; /root/vaconfig.yaml&lt;/code&gt;.&lt;ul&gt;&lt;li&gt;This is the first step where I had issues, initially I had the error &lt;strong&gt;Error: unknown flag: - -export&lt;/strong&gt;, so I removed the flag from the command.&lt;/li&gt;&lt;li&gt;I then got the same error I started with &lt;strong&gt;The connection to the server vra-k8s.local:6443 was refused - did you specify the right host or port?&lt;/strong&gt;.&lt;/li&gt;&lt;li&gt;I ran through the same initial troubleshooting steps, I checked docker (all good) and kubelet (not started).&lt;/li&gt;&lt;li&gt;I started the kubelet service with &lt;code class=&quot;language-text&quot;&gt;systemctl start kubelet&lt;/code&gt; and kept an eye on the status to ensure it stayed running.&lt;/li&gt;&lt;li&gt;I check with &lt;code class=&quot;language-text&quot;&gt;docker ps&lt;/code&gt; and could see the kube-apiserver container was running so then ran the &lt;code class=&quot;language-text&quot;&gt;kubectl get vaconfig -o yaml &amp;gt; /root/vaconfig.yaml&lt;/code&gt; command - this time it was successful.&lt;/li&gt;&lt;li&gt;I validated that the /root/vaconfig.yaml file had contents with &lt;code class=&quot;language-text&quot;&gt;cat /root/vaconfig.yaml&lt;/code&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Reset Kubernetes once again using: &lt;code class=&quot;language-text&quot;&gt;vracli cluster leave&lt;/code&gt;.&lt;ul&gt;&lt;li&gt;Again this takes a little while to run.&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Run to Install the VA config: &lt;code class=&quot;language-text&quot;&gt;kubectl apply -f /root/vaconfig.yaml --force&lt;/code&gt;.&lt;ul&gt;&lt;li&gt;The server seemed to be running after the previous leave step, but check its status at this point and wait for the kube-apiserver container to exist and be running.&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Run &lt;code class=&quot;language-text&quot;&gt;vracli license&lt;/code&gt; to confirm that VA config is installed properly.&lt;/li&gt;&lt;li&gt;Run: &lt;code class=&quot;language-text&quot;&gt;/opt/scripts/deploy.sh&lt;/code&gt;.&lt;ul&gt;&lt;li&gt;This takes a while time to run, but you should see that prelude has been successfully deployed.&lt;/li&gt;&lt;li&gt;I had issues accessing the vRA UI, so I rebooted and it resolved itself.&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h1 id=&quot;resources&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#resources&quot; aria-label=&quot;resources permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Resources&lt;/h1&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;https://kb.vmware.com/s/article/82378&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://kb.vmware.com/s/article/82378&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</content:encoded><tags>vmware,aria,aria-automation,aria-hub,vrealize</tags><featuredImage>https://samperrin.com/static/f4e85ba1bf88dfe0b1d1a36feb9103a4/hero.jpg</featuredImage></item><item><title><![CDATA[Monitor Cloud Extensibility Proxy embeded Aria Automation Orchestrator (vRealize Orchestrator) with Aria Operations Cloud (vRealize Operations Cloud)]]></title><description><![CDATA[This blog post covers the process of creating an OAuth App within VMware Cloud Services for Cloud Extensibility Proxies that will allow you to monitor vRO (Aria Automation Orchestrator) via Aria Operations Cloud]]></description><link>https://samperrin.com/posts/monitoring-cloud-extensibility-proxy-orchestrator-with-aria-operations-cloud/</link><guid isPermaLink="false">https://samperrin.com/posts/monitoring-cloud-extensibility-proxy-orchestrator-with-aria-operations-cloud/</guid><category><![CDATA[vmware]]></category><category><![CDATA[vrealize]]></category><category><![CDATA[vro]]></category><category><![CDATA[aria]]></category><category><![CDATA[aria-automation]]></category><category><![CDATA[aria-operations]]></category><pubDate>Tue, 03 Jan 2023 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Aria Operations Cloud (vRealize Operations Cloud) includes a management/integration pack for monitoring Aria Automation Orchestrator (vRealize Orchestrator), however when vRO is deployed within a Cloud Extensibility Proxy appliance the authentication process is to redirect the user to VMware Cloud Services where they sign in with their user ID and are then redirected to the vRO dashboard. If you use these same credentials for the vRO appliance when trying to connect via Aria Operations you will fail validation for the integration. &lt;/p&gt;&lt;p&gt;The way to monitor vRO with Aria Operations Cloud is to create an OAuth App within VMware Cloud Services and give it the appropriate Service Role to connect to the vRealize Orchestrator instance embedded in the CEXP. &lt;/p&gt;&lt;p&gt;In this post we will run through the short process of creating and entitling the OAuth App, setting up the vROps integration into CEXP based vRO and also adding additional workflows for monitoring. &lt;/p&gt;&lt;h1 id=&quot;create-oauth-app&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#create-oauth-app&quot; aria-label=&quot;create oauth app permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Create OAuth App&lt;/h1&gt;&lt;p&gt;To create an OAuth App we need to use the VMware Cloud Services console and you must have access to the Organization section.&lt;/p&gt;&lt;ol&gt;&lt;li&gt;Go to &lt;a href=&quot;https://console.cloud.vmware.com/&quot; target=&quot;_blank&quot;&gt;VMware Cloud Services&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;Go to &lt;b&gt;Organization&lt;/b&gt; &amp;gt; &lt;b&gt;OAuth Apps&lt;/b&gt;&lt;/li&gt;&lt;li&gt;Press &lt;b&gt;CREATE APP&lt;/b&gt;&lt;/li&gt;&lt;li&gt;Select &lt;b&gt;Server to server app&lt;/b&gt; and press &lt;b&gt;CONTINUE&lt;/b&gt;&lt;/li&gt;&lt;li&gt;Provide the following information&lt;ol&gt;&lt;li&gt;App Name (e.g appliance name)&lt;/li&gt;&lt;li&gt;App Description (e.g. Cloud Extensibility Proxy vROps)&lt;/li&gt;&lt;li&gt;Access Token TTL (default value of 30 minutes is OK)&lt;/li&gt;&lt;/ol&gt;&lt;/li&gt;&lt;li&gt;Select Service Roles: &amp;#x27;Cloud Assembly Administrator&amp;#x27;&lt;/li&gt;&lt;li&gt;Click &lt;b&gt;CREATE&lt;/b&gt;&lt;/li&gt;&lt;li&gt;Take note of both the &lt;b&gt;App ID&lt;/b&gt; and &lt;b&gt;App Secret&lt;/b&gt; values&lt;/li&gt;&lt;li&gt;Press &lt;b&gt;CONTINUE&lt;/b&gt;&lt;/li&gt;&lt;li&gt;If prompted to Add to this organization, review the message and press Add&lt;/li&gt;&lt;/ol&gt;&lt;h1 id=&quot;validate-oauth-app&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#validate-oauth-app&quot; aria-label=&quot;validate oauth app permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Validate OAuth App&lt;/h1&gt;&lt;p&gt;This is an optional step, but it is to ensure our OAuth App is correctly registered against our VMware Cloud Services Organization. &lt;/p&gt;&lt;ol&gt;&lt;li&gt;Go to &lt;a href=&quot;https://console.cloud.vmware.com/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;VMware Cloud Services&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;Go to &lt;b&gt;Identity &amp;amp; Access Management&lt;/b&gt; &amp;gt; &lt;b&gt;OAuth Apps&lt;/b&gt;.&lt;/li&gt;&lt;li&gt;Confirm the OAuth App you created in the &lt;a href=&quot;#create-oauth-app&quot;&gt;Create OAuth App&lt;/a&gt; step is listed with the correct Organization Roles and Service Roles&lt;/li&gt;&lt;/ol&gt;&lt;h1 id=&quot;add-vro-integration-in-aria-operations-cloud&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#add-vro-integration-in-aria-operations-cloud&quot; aria-label=&quot;add vro integration in aria operations cloud permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Add vRO Integration in Aria Operations Cloud&lt;/h1&gt;&lt;p&gt;In this step we will be added the vRealize Orchestrator endpoint and we will be using our OAuth App ID and token for authentication. &lt;/p&gt;&lt;ol&gt;&lt;li&gt;Open Aria Operations Cloud (vRealize Operations Cloud)&lt;/li&gt;&lt;li&gt;Navigate to &lt;b&gt;Data Sources&lt;/b&gt; &amp;gt; &lt;b&gt;Integrations&lt;/b&gt;&lt;/li&gt;&lt;li&gt;Press &lt;b&gt;Add Account&lt;/b&gt; and select vRealize Orchestrator Adapter&lt;/li&gt;&lt;li&gt;Provide the correct inputs, for the &lt;b&gt;vRealize Orchestrator Host&lt;/b&gt; input use the appliance FQDN&lt;/li&gt;&lt;li&gt;For Credential press the &lt;b&gt;+&lt;/b&gt; to Add New&lt;ol&gt;&lt;li&gt;Credential Kind = CSP OAuth App Credential&lt;/li&gt;&lt;li&gt;Credential name = A friendly identifier, e.g. CEXP/vRO CSP OAuth Credentials&lt;/li&gt;&lt;li&gt;Client Id = App ID value recorded from earlier&lt;/li&gt;&lt;li&gt;Client Secret = App Secrete value recorded from earlier&lt;/li&gt;&lt;li&gt;Press &lt;b&gt;OK&lt;/b&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/li&gt;&lt;li&gt;Select the appropriate collector or collector group&lt;/li&gt;&lt;li&gt;Press &lt;b&gt;VALIDATE CONNECTION&lt;/b&gt;&lt;/li&gt;&lt;li&gt;Press &lt;b&gt;SAVE&lt;/b&gt;&lt;/li&gt;&lt;/ol&gt;&lt;h1 id=&quot;verify-collection-status&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#verify-collection-status&quot; aria-label=&quot;verify collection status permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Verify Collection Status&lt;/h1&gt;&lt;p&gt;This step is to ensure our newly added integration is collecting data.&lt;/p&gt;&lt;ol&gt;&lt;li&gt;Login to Aria Operations Cloud (vRealize Operations Cloud)&lt;/li&gt;&lt;li&gt;Navivate to &lt;strong&gt;Environment&lt;/strong&gt; &amp;gt; &lt;strong&gt;Inventory&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;Expand &lt;strong&gt;Adapter Instances&lt;/strong&gt; and select &lt;strong&gt;vRealize Orchestrator Adapter Instance&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;On the &lt;strong&gt;Objects&lt;/strong&gt; tab you should see your vRealize Orchestrator instance&lt;/li&gt;&lt;li&gt;Under the Collection State column ensure State = Collecting&lt;/li&gt;&lt;li&gt;Under the Collection Status column ensure Status = Data recieving &lt;/li&gt;&lt;/ol&gt;&lt;h1 id=&quot;add-workflow-packages&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#add-workflow-packages&quot; aria-label=&quot;add workflow packages permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Add Workflow Packages&lt;/h1&gt;&lt;p&gt;By default the vRealize Orchestrator management pack only monitors workflows and items stored in the packages &lt;strong&gt;com.vmware.library.vcenter&lt;/strong&gt; (vCenter Workflows) and &lt;strong&gt;com.vmware.vrops.oob_content&lt;/strong&gt; (Default Management Pack for vRealize Orchestrator workflows). If you have additional workflows that need to be monitored they will need to be compiled into a package and added into Aria Operations. &lt;/p&gt;&lt;h3 id=&quot;create-vro-package&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#create-vro-package&quot; aria-label=&quot;create vro package permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Create vRO Package&lt;/h3&gt;&lt;ol&gt;&lt;li&gt;Login to the vRealize Orchestrator Client.&lt;/li&gt;&lt;li&gt;Navigate to &lt;strong&gt;Assets&lt;/strong&gt; &amp;gt; &lt;strong&gt;Packages&lt;/strong&gt;.&lt;/li&gt;&lt;li&gt;Click &lt;strong&gt;New Package&lt;/strong&gt;.&lt;/li&gt;&lt;li&gt;On the General tab, enter a name and description for the package.&lt;/li&gt;&lt;li&gt;On the Content tab, click &lt;strong&gt;ADD&lt;/strong&gt;.&lt;/li&gt;&lt;li&gt;Select the objects that you want to add to the package and click &lt;strong&gt;ADD&lt;/strong&gt;.&lt;/li&gt;&lt;li&gt;To finish creating the package, click &lt;strong&gt;CREATE&lt;/strong&gt;.&lt;/li&gt;&lt;/ol&gt;&lt;h3 id=&quot;add-vro-package-to-aria-operations&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#add-vro-package-to-aria-operations&quot; aria-label=&quot;add vro package to aria operations permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Add vRO Package to Aria Operations&lt;/h3&gt;&lt;ol&gt;&lt;li&gt;Login to Aria Operations Cloud (vRealize Operations Cloud)&lt;/li&gt;&lt;li&gt;Navivate to &lt;strong&gt;Environment&lt;/strong&gt; &amp;gt; &lt;strong&gt;Inventory&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;Expand &lt;strong&gt;Adapter Instances&lt;/strong&gt; and select &lt;strong&gt;vRealize Orchestrator Adapter Instance&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;Select to highlight the target vRealize Orchestrator adapter instance.&lt;/li&gt;&lt;li&gt;Select the cog icon (actions) in the right pane and select &lt;strong&gt;Configure Package Discovery&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;Double click the entry in the Configure Package Discovery dialog box and add your package name to a new line. &lt;/li&gt;&lt;li&gt;Click &lt;strong&gt;BEGIN ACTION&lt;/strong&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:542px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:101.8450184501845%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAUCAYAAACNiR0NAAAACXBIWXMAAA7DAAAOwwHHb6hkAAACLElEQVQ4y62UW47TMBSGuxNe2AULYGFI7IAHtoBA8M6wBIRgpEp0OrSZprk38d1xnORHdpKZptBquBzp0zmN5d8+/u0uGDmgqQWU0lBKQeshT/X0e8p1XcNaO8MYAxfr9RoLXe1hqgCECZTlAVVVgXOOsixRFIXP7puHED92Gk7UxWazwUJKhaaxqLX2q9fGoGk7dJ2jHelmuW3nTILb7RYLt2KW54jjBHGSIElTVEzCLSSk8vkXlEOPKHAuUJtm2CGhFLt9hCiOEY2ijiiKcbcLfb2PYoT7PdI085MpYyCEeBjjUK4702C9vsXCDSZJivJw8GfmSJMEjNLhCOrBGFf77MwpCsgsg85zGCl9u10P3DhTnGCaFyCMgXKOitL72rVDKfVGSCl95kJ4GGNou25wpe997V12E1ieQxcFRJ5DZJmHxTEUIej7HufCjQ3jJ4LR6gbJconw+hrRcokqCMB2O9Aw9KLHk3+HiwdBxqAIRScELOewQp7dySVmgo1t8a/R9f3UMgMZrb+/W/oPGOdwqQaXhRCQtYHQNaQ2fwVXGk3bT09P4n+Ff3qT4GMO/hzdeB9ngo+J/ghnwkR7Kjitcn4H43075lzL7k/T235B0GHbDrqxHmNbJEwhKAV2lUBwYCiUxWZzJHjuiU2fhbEIiUTMlBd7/voTnr784Hny4h2evbrC5+X3ueClp+V2xXQDXjcQtcXVKsbbrwHef7vDmy8bfFxnWN3+wE8PawmaM0R6egAAAABJRU5ErkJggg==&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Configure Package Discovery dialog box&quot; title=&quot;Configure Package Discovery dialog box&quot; src=&quot;/static/7c666be7bf71eb624d5b51a7624c8c95/47f85/Screenshot_20230103_130417.png&quot; srcSet=&quot;/static/7c666be7bf71eb624d5b51a7624c8c95/47f85/Screenshot_20230103_130417.png 542w&quot; sizes=&quot;(max-width: 542px) 100vw, 542px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Configure Package Discovery dialog box&lt;/figcaption&gt;
  &lt;/figure&gt; &lt;/p&gt;&lt;h2 id=&quot;references&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#references&quot; aria-label=&quot;references permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;References&lt;/h2&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;https://docs.vmware.com/en/VMware-vRealize-Operations-Management-Pack-for-vRealize-Orchestrator/3.2/vrealize-orchestrator/GUID-8642D39F-58E9-4294-952F-BF9D1267DA8E.html&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;Create an OAuth App for vRealize Orchestrator Management Pack&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://docs.vmware.com/en/VMware-vRealize-Operations-Management-Pack-for-vRealize-Orchestrator/3.2/vrealize-orchestrator/GUID-CE89A064-09D8-4412-9903-9604A09BD0EF.html&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;Configure the Management Pack for vRealize Orchestrator&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://docs.vmware.com/en/vRealize-Orchestrator/8.10/com.vmware.vrealize.orchestrator-using-client-guide.doc/GUID-CCCC435B-C083-4E2E-B553-7D1DAF517488.html&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;Create a Package in the vRealize Orchestrator Client&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://docs.vmware.com/en/VMware-vRealize-Operations-Management-Pack-for-vRealize-Orchestrator/3.2/vrealize-orchestrator/GUID-21153DAB-C7EA-4F13-A9C0-12AB60581AAF.html&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;Package Discovery&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</content:encoded><tags>vmware,vrealize,vro,aria,aria-automation,aria-operations</tags><featuredImage>https://samperrin.com/static/a0511c8075ba8349a213f67f0f3e2347/hero_5.jpg</featuredImage></item><item><title><![CDATA[Exploring Aria Hub Search and GraphQL]]></title><description><![CDATA[In this post, we will learn how to search within Aria Hub and query our inventory using GraphQL and Altair. We will cover search examples and the use of operators, comparison functions, and property names and values. We will also discuss using Aria Graph and Altair for advanced GraphQL queries.]]></description><link>https://samperrin.com/posts/exploring-aria-hub-search-and-graphql/</link><guid isPermaLink="false">https://samperrin.com/posts/exploring-aria-hub-search-and-graphql/</guid><category><![CDATA[vmware]]></category><category><![CDATA[aria]]></category><category><![CDATA[aria-automation]]></category><category><![CDATA[aria-hub]]></category><pubDate>Wed, 28 Dec 2022 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;In this post, we will learn how to search within Aria Hub and query our inventory using GraphQL and Altair. We will cover search examples and the use of operators, comparison functions and property names and values. We will also discuss using Aria Graph and Altair for advanced GraphQL queries. &lt;/p&gt;&lt;h1 id=&quot;aria-hub-search&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#aria-hub-search&quot; aria-label=&quot;aria hub search permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Aria Hub Search&lt;/h1&gt;&lt;p&gt;As we briefly covered in the previous post &lt;a href=&quot;/posts/getting-started-with-aria-hub-free-tier/&quot;&gt;Getting started with Aria Hub Free Tier&lt;/a&gt; we can search for objects using any of the objects data/properties - such as &lt;code class=&quot;language-text&quot;&gt;IP address&lt;/code&gt;, &lt;code class=&quot;language-text&quot;&gt;name&lt;/code&gt;, &lt;code class=&quot;language-text&quot;&gt;ID&lt;/code&gt;. Here we will cover some of our options for querying data within the UI. &lt;/p&gt;&lt;h2 id=&quot;search-examples&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#search-examples&quot; aria-label=&quot;search examples permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Search Examples&lt;/h2&gt;&lt;p&gt;These queries can be used within the Aria Hub UI. &lt;/p&gt;&lt;ul&gt;&lt;li&gt;Find all EC2 Instances: &lt;code class=&quot;language-text&quot;&gt;entityType = AWS.EC2.Instance&lt;/code&gt;.&lt;/li&gt;&lt;li&gt;Find all EC2 Network ACL’s: &lt;code class=&quot;language-text&quot;&gt;entityType = AWS.EC2.NetworkAcl&lt;/code&gt;.&lt;/li&gt;&lt;li&gt;Find all EC2 Instances and EC2 Network ACL’s: &lt;code class=&quot;language-text&quot;&gt;entityType = AWS.EC2.NetworkAcl OR entityType = AWS.EC2.Instance&lt;/code&gt;. We use &lt;code class=&quot;language-text&quot;&gt;OR&lt;/code&gt; because if we use &lt;code class=&quot;language-text&quot;&gt;AND&lt;/code&gt; the object would need to be both entityTypes &lt;code class=&quot;language-text&quot;&gt;AWS.EC2.NetworkAcl&lt;/code&gt; and &lt;code class=&quot;language-text&quot;&gt;AWS.EC2.Instance&lt;/code&gt; at the same time, which it cant be.&lt;/li&gt;&lt;li&gt;Find everything within a particular AWS region: &lt;code class=&quot;language-text&quot;&gt;region = us-east-1&lt;/code&gt;.&lt;/li&gt;&lt;li&gt;Find the EC2 Network ACL’s in either of the two specified regions and provide a count of how many per region: &lt;code class=&quot;language-text&quot;&gt;AWS.EC2.NetworkAcl HAS (region = us-east-2 OR region = us-east-1) count(region)&lt;/code&gt;.&lt;/li&gt;&lt;li&gt;Find EC2 Instances launched before a specific data (e.g. 31st December 2022): &lt;code class=&quot;language-text&quot;&gt;AWS.EC2.Instance HAS LaunchTime &amp;lt; 2022-12-31&lt;/code&gt;.&lt;/li&gt;&lt;li&gt;Find EC2 Instances launched within the last 7 days: &lt;code class=&quot;language-text&quot;&gt;AWS.EC2.Instance HAS LaunchTime &amp;gt; daysAgo(7)&lt;/code&gt;.&lt;/li&gt;&lt;li&gt;Use wildcards, such as a PrivateIpAddress in the 172.31.82.x network: &lt;code class=&quot;language-text&quot;&gt;AWS.EC2.Instance HAS PrivateIpAddress = 172.31.82.*&lt;/code&gt;.&lt;/li&gt;&lt;li&gt;Find EC2 Instances that do not have InstanceType t2.large: &lt;code class=&quot;language-text&quot;&gt;AWS.EC2.Instance HAS InstanceType != t2.large&lt;/code&gt;. Can also be represented as: &lt;code class=&quot;language-text&quot;&gt;AWS.EC2.Instance HAS NOT InstanceType = t2.large&lt;/code&gt;.&lt;/li&gt;&lt;li&gt;Find EC2 Instances with PrivateIpAddress and PublicIpAddress properties: &lt;code class=&quot;language-text&quot;&gt;AWS.EC2.Instance HAS pn(PrivateIpAddress) AND propertyName(PublicIpAddress)&lt;/code&gt;. Properties &lt;code class=&quot;language-text&quot;&gt;pn&lt;/code&gt; can be used interchangably with &lt;code class=&quot;language-text&quot;&gt;propertyName&lt;/code&gt;, the same for &lt;code class=&quot;language-text&quot;&gt;pv&lt;/code&gt; and &lt;code class=&quot;language-text&quot;&gt;propertyValue&lt;/code&gt;. &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1241px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:98.14665592264302%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAUCAYAAACNiR0NAAAACXBIWXMAAA7DAAAOwwHHb6hkAAACi0lEQVQ4y41U2XKiQBTlN8agiEGEZodeQFEWJ8aMlTympub//+NM9UUtl1jJw6lu7uWevsvpNvzVFo7cwEpLzPIlnnmNcSRgZyX8qoWnGliJJNtPYHiqxZyvEax3iJo9rFjBDDnGIcckEoTx8dv8BpNYwrBiiWmiME1L2GmFSSgw8rMr/PJSgt4/3fjIxnLyL1QPY+Sn54BzEMsJp70VSeiDL2230HZdnfGl8/iDLnOWVWBVj6Dq8ZwtyXaZ2W2WxiMyakOihgxjRdB7bbMTdSTK76oxbg1EFuupSgoYhwJBcUDIPzAOhv5q3zRWVzGn1bjtgxkUw3BYCifpEPAPeOINTLyCiQOctIPJUthJhXFQ3PX8jtAiqUiwZAnVfaLqPxEUO2TFGgHfI5DvYFlDmrOoim8IdblaUyNWYPnyD2/7v0iyGjF/gZdvwMQ7ptEKI5bBTsqfZKgJC1hRjUi+IuYVwnyDhO+QSIVYtTCDklpz2ceHhFrYWnN+WiNSb4jUgUoNi1dE8gWR2sEvDrASdb4EjwmPRj2UcZjDjtcIxQcNwxN7KtdJtzT5WVrhid1L50vZnCZtBpwOYcUfzLgmKMhmp+XVhB/K5ko+LKemayFP4qENWtzaZt7I5SrD0fH+Xl328z6lTHSvNIasHj8SRDjNKpIJnRIUeApO64DRsbenHp99tM/v4gy27OGqFo5oMBdruGIDR6zpjZwVKyz4hh7gZ76Cqxq4Qj/CS7hK2zaYSx1XU+yM1zBc0cJbbrGQPfxKrx3Bo+/f8FUHr+rhypZW/Yq7ssFCdZjLDRZVB0/18MstHNXAmBNhT44h0xau/ll0w0G6ArHGQjVweI1F1WOuWtjF6gI1QWf4HwfRXmfGPZ/yAAAAAElFTkSuQmCC&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Inventory search within a specific region&quot; title=&quot;Inventory search within a specific region&quot; src=&quot;/static/7d9a248b3006f3b37ca5b07e592260aa/bcd18/Screenshot_20221223_162606.png&quot; srcSet=&quot;/static/7d9a248b3006f3b37ca5b07e592260aa/bcd18/Screenshot_20221223_162606.png 1241w&quot; sizes=&quot;(max-width: 1241px) 100vw, 1241px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Inventory search within a specific region&lt;/figcaption&gt;
  &lt;/figure&gt; &lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1243px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:98.47144006436042%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAUCAYAAACNiR0NAAAACXBIWXMAAA7DAAAOwwHHb6hkAAACEElEQVQ4y6VU7XKiQBDkLe5UFEHD9zcsoKCguYunSeX936avZjCp1cAlqfvRNcvMbFdv77CKVXVYix0WYYFlXMFIt5j7ObRIwK062OUe3qaDS6haOFXb57YHmKKB6ueMOccMil11MIs93OY3wu7CpFScBwLLqIQWlRzfoEk5LSy4j+HnLEqhJBX1eMPqFoHA1Em+hZmbYmLHsMojFFrIeGuQQTmuD9TkHj3eQhkrytESO9jFHk7ZYu5lTP5Wn0p9lFfuN8uRNq+SLUzRYp03MMUeq7TGws8xtu+GUF5rgeDNZLiRbLBOd9ATmgD6rrEMi0FSZVRZWvfH4eNl8MULFn7x7qVxp/SfhEa8YSW96hhmekJQPsIX5FlPol7tGCWcub3BMyJMtteGGFqwgZNf4IozfPEMPWowcSLupT7VGzlyn0ihureEZvoLnniGk59hZU+wsz/9jTox9Lj6cEGDCldJzRtWUYugeIUrLkxK0S9e8RAfemtI4VcupfcwxzKoYUQ72NkJXvECN7/AiPfQw+ZzD+VIvqz5lhP8sAImJUJS/NMOMbGjD/M4SCivqZlIF0HBxFb6BNXrX5ZV2vCcfnkOZaV0fPJKv0YacprT+/53wrGf/VZ1wubzxUknGQK/NtPrKzP4NH3yfQ/loWj5H1WD/oFUA/FfUKLdCcnhjKDuEHcn+M0j3PoIrz5y/C7+AsKkWGsrX3X+AAAAAElFTkSuQmCC&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Multiple entityType search&quot; title=&quot;Multiple entityType search&quot; src=&quot;/static/0b0ec4cb9065036dc9cf3d2fb7bcab50/2c0f3/Screenshot_20221223_162401.png&quot; srcSet=&quot;/static/0b0ec4cb9065036dc9cf3d2fb7bcab50/2c0f3/Screenshot_20221223_162401.png 1243w&quot; sizes=&quot;(max-width: 1243px) 100vw, 1243px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Multiple entityType search&lt;/figcaption&gt;
  &lt;/figure&gt; &lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1559px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:17.63951250801796%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAECAYAAACOXx+WAAAACXBIWXMAAA7DAAAOwwHHb6hkAAAAnUlEQVQY043NWw6CMBCF4S4ECoipgNJSWnrhIia6Afe/mGNaDTE8GB++zEzyJ0MK6XBUEwrpkbYabFhQ+xsqu6KyVzCz4PQR9tqtsU1ajbQd3rhB0kiwxxOkGu9gZkVyVlHGDXJhkXMT929F56L0ord+0/SgwoOUw4Ksc6DcgAobZ/hI94RFqWbk0sc7C+0eNyB5P+Kg578UKph+Ni+CkHsPrD3B3gAAAABJRU5ErkJggg==&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Search across multiple regions based on the entityType, displayed as a count per region&quot; title=&quot;Search across multiple regions based on the entityType, displayed as a count per region&quot; src=&quot;/static/d4a34455c450ddcff7c143a3591321d9/4509c/Screenshot_20221223_163114.png&quot; srcSet=&quot;/static/d4a34455c450ddcff7c143a3591321d9/4509c/Screenshot_20221223_163114.png 1559w&quot; sizes=&quot;(max-width: 1559px) 100vw, 1559px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Search across multiple regions based on the entityType, displayed as a count per region&lt;/figcaption&gt;
  &lt;/figure&gt; &lt;/p&gt;&lt;h2 id=&quot;operators-comparison-operators-and-functions&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#operators-comparison-operators-and-functions&quot; aria-label=&quot;operators comparison operators and functions permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Operators, Comparison Operators and Functions&lt;/h2&gt;&lt;h4 id=&quot;operators&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#operators&quot; aria-label=&quot;operators permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Operators&lt;/h4&gt;&lt;p&gt;These Operators are &lt;strong&gt;case-insentive&lt;/strong&gt;. &lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;HAS&lt;/code&gt; - Apply one or more conditions to a resource type.&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;AND&lt;/code&gt; - Group conditions when all of them must be satisfied.&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;OR&lt;/code&gt; - Group conditions when at least one of them must be satisfied.&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;NOT&lt;/code&gt; - Reverse a condition.&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;()&lt;/code&gt; - Specify the order in which conditions are evaluated.&lt;/li&gt;&lt;/ul&gt;&lt;h4 id=&quot;functions&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#functions&quot; aria-label=&quot;functions permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Functions&lt;/h4&gt;&lt;ul&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;hoursAgo(x)&lt;/code&gt; - The time &lt;em&gt;x&lt;/em&gt; hours earlier than now.&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;daysAgo(x)&lt;/code&gt; - The time &lt;em&gt;x&lt;/em&gt; days earlier than now.&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;monthsAgo(x)&lt;/code&gt; - The time &lt;em&gt;x&lt;/em&gt; months earlier than now.&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;yearsAgo(x)&lt;/code&gt; - The time &lt;em&gt;x&lt;/em&gt; years earlier than now.&lt;/li&gt;&lt;/ul&gt;&lt;h4 id=&quot;comparison-operators&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#comparison-operators&quot; aria-label=&quot;comparison operators permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Comparison Operators&lt;/h4&gt;&lt;ul&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;=&lt;/code&gt; - Equal to.&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;!=&lt;/code&gt; - Not equal to.&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;&amp;lt;=&lt;/code&gt; - Less than or equal to.&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;=&amp;gt;&lt;/code&gt; - Equal to or more than.&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;&amp;lt;&lt;/code&gt; - Less than.&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;&amp;gt;&lt;/code&gt; - More than.&lt;/li&gt;&lt;/ul&gt;&lt;h2 id=&quot;identifying-object-properties&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#identifying-object-properties&quot; aria-label=&quot;identifying object properties permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Identifying Object Properties&lt;/h2&gt;&lt;p&gt;In the above queries we use various property names, we can find these names by browsing to an object of the type we are interested in, such as an &lt;strong&gt;AWS.EC2.Instance&lt;/strong&gt;. Once selected we can expand the Properties pane, the left side of the table is the PropertyName (pn) and the right side of the table is the PropertyValue (pv). &lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:487px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:173.51129363449692%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAjCAYAAACU9ioYAAAACXBIWXMAAA7DAAAOwwHHb6hkAAAEDElEQVRIx51WWXPiZhDkRyRVu7Yxh8EgoQPd9w2yBbZZr5PUVlKp2qNqn5P//9CpGUkYMJBNHqYEttTqnumej8614sBI7+GUj/DKJ2hxibEZ42pm/q/qdGUbEyvGzC9wa8W40QOua9nGtez8eCkOupKNTleycCkauDVD+MsHmOk9uqKOK9H4z3UtWeh0ZyYmfgm9fEG0+QNW9SuEeMU1jeoSotfPx6uCEK8xdgt0CFm5/4TF579RfvkL8vpPaJsv0DafYTx/5dI/0PXbmfoK65fvkBYfa8kDLcDISjAL7iCFd5CjCmq6xsiMMbZTTN0MfS3AUA/PVIQbPawBSXZPdjCxU0yshKd8ayXck55sYzj3tlO8PNPDnuI0gJKN/tzDzCswdXIITop2WH3VhUPDyir0VYdB62feFt27BSR0YjV1MkzsmiX9r6fYEN0MclBg5mas5hCofckOIH3xIHoFZv6CQQUnYy+SZMnPoUYLiE6KC0Fn5rt1hKGFGy2A5C0hujkD01svRINN7pUbhNUzkvULwuoDXGpBvkK8+sitoJfsARKTrmQ21/p72/yhFiDf/Iby5XeUz5+QPLxwCIaaj5ER4kbzj0sezH2IbgHBzSC4OSaNvB5HysK7yRzvBf28ZOWgh2QbHoydYmzF/MbB3OPrqcmeHAo9KPCEUx5MO6CxGb1hsgtyEpB6RQAkl4GMCO+nGm8Rd/nIvToEfQO4L9llueQ/qkGTjp7qQg2XGKjuSVMfBaSpETvJX2K6m5S5CyU4DdhG8g3gQKUe5hw9skN7Y19xoITF3sO7dZIhSaSEkOxdQLINJYUY0mcq8mm/sdM+Q+dgyl4Bwcs5HeS3C9rcMxN6WtUJKZ8QVRs+e/y7Jww178CHDjrXkr0dCpmZGFJNGj8SWzlYQAkXzJLz3bCkdF3NrOMMydhTSoid8nBIPnmRJq7Fd3wa1pE818MDyQRAoLQXiSHFjVgJdoKfx8oPTJkky86rD5vIkeQ29PR3yS8wteNtrg/9tw/Y9JAZ+guW3FrnslnrSriElVW8G99NNB7YLtgB4KsPqW9TO2Nj8z4U9PoIWDxADpcw0grO8hF2sWbwf+0hAzYLgrJM6SFANSp5MGMj4PvILicl70av3jAF70UekJ0ygJGvEVXPfPrV+9A8Lfkwy6KX85VXmZUwIBn8p5F8coWdkZxudyIvWbNesjQgWvuHU367bY5KXtSSG3MPNB9msYZXPvJLyZsXzVHQHgl70dtLivN6npB0YkQMZb+Onp7cwcjuMY9LqHEJM1uxR9tW7AH2FLfJcYxbO2H5vFVUFzMvh+imDCpwWxK+0g8A+m15QnIAOaQ330NNKr6OjbpvJNkuHhCtnjHSfZZNrNoTcHfV/QMUOUQzD3PRQAAAAABJRU5ErkJggg==&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Object Properties&quot; title=&quot;Object Properties&quot; src=&quot;/static/8501fac0a386e686e0e2152eb1dfefe3/6a170/Screenshot_20221223_171005.png&quot; srcSet=&quot;/static/8501fac0a386e686e0e2152eb1dfefe3/6a170/Screenshot_20221223_171005.png 487w&quot; sizes=&quot;(max-width: 487px) 100vw, 487px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Object Properties&lt;/figcaption&gt;
  &lt;/figure&gt; &lt;/p&gt;&lt;h1 id=&quot;altair&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#altair&quot; aria-label=&quot;altair permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Altair&lt;/h1&gt;&lt;blockquote&gt;&lt;p&gt;VMware Aria Graph provides built-in access to an open-source client for developing and testing your GraphQL queries and includes features like collections and pre- and post-scripts.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;We have explored how to query data directly within the UI, but a key point to &lt;strong&gt;VMware Aria Hub&lt;/strong&gt; is that it is powered by &lt;strong&gt;VMware Aria Graph&lt;/strong&gt;. Aria Graph has been developed with an API-first approach, for us to start consuming these API’s, and specifically the data behind them, we need to use GraphQL. &lt;/p&gt;&lt;p&gt;There are a couple of browser based methods for this, the &lt;a href=&quot;https://api.mgmt.cloud.vmware.com/aria/graphql&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;GraphiQL&lt;/a&gt; UI or with Altair, which is ”&lt;strong&gt;…a feature-rich GraphQL Client IDE for all platforms&lt;/strong&gt;”. It is very similar to the GraphiQL UI but gives us a few more features. &lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1654px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:53.14389359129383%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAALCAYAAAB/Ca1DAAAACXBIWXMAAA7DAAAOwwHHb6hkAAAA7klEQVQoz5WT226EMAxE+f9/hcSOyRWY1aRyt6paxEYa8QA+zNjOsq4rQgiQGJFSgqrCzLDv+1TOGSKCECJEFFHkT/HdFiIWFpRSUGtF731qjIHzPKd4CFZNKLUhl3qrRUlXQTKdbo7jmCLUwV/O0yzYc7nVomrYxFALHTb00XBd13TmT7ZAngIZdYzjO24f79j/AW8j72azf66ffWT0j4HsD5tulmahi4Nylx8BWdhae0fufQ6CIJ8yh6XJngH5MR0wnq/K76HQqXEnnwDpiL1zkDtzdzz8mdlD4LZt4G3hbWA/6dhviC89E6SHwBcn9VhtwidNswAAAABJRU5ErkJggg==&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;GraphiQL UI&quot; title=&quot;GraphiQL UI&quot; src=&quot;/static/571a8338485125815225ab5943e8bdd7/c371b/Screenshot_20221223_180932.png&quot; srcSet=&quot;/static/571a8338485125815225ab5943e8bdd7/c371b/Screenshot_20221223_180932.png 1654w&quot; sizes=&quot;(max-width: 1654px) 100vw, 1654px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;GraphiQL UI&lt;/figcaption&gt;
  &lt;/figure&gt; &lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1654px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:53.50665054413544%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAALCAYAAAB/Ca1DAAAACXBIWXMAAA7DAAAOwwHHb6hkAAABhUlEQVQoz31T2Y7TQBD0L8Emtucez+FjcpBkya4W/gDx/6+Fuu04CYt4KHW3ZJXqGFfdUJDLEaHfw8UJPhWeNoxPMN3jPqw7f9tNKJczPn5fUUkX4NKAkHcIucD4jFZ1aKRHoxZIDxt6aJ8hbYSLI++t7viWJiGUHq+/9qi0SzBdhvEJQntsW41aWLzUCl+3Ei+1xJeNwOF0XZX7ODEpKb1BuwFC9qiUTVA6gIl9gjIBjXRohGXiG/nh/DYTLqSOSZ/h04RKdwnT+wE2ZCgTUcs70bY1jE2j7wrj+CnfR1TSRYi8Q2sitsJgIzSE7piErJJtmsebQlZXuETKvcs7uHRXXSkbUbd3VWR3nnTPCsny69tPuDDBDxPG8xH9dMJQThj3F34ZKyFlZ5dSaFqf59slVtoqz2ov1x9zVolALfdrIevzIctqKUOawIUou0wT0Eq3KrwRzll9LmTNUD82y3ZnAlJFeLL8j2b/RpXHPWJfmJTsaxfnSdlSrgvh7tv39S/5H/4ADH2C0XU/7HgAAAAASUVORK5CYII=&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Altair UI&quot; title=&quot;Altair UI&quot; src=&quot;/static/535bfc2d1fec8e70849dec45f66ab62b/c371b/Screenshot_20221223_181627.png&quot; srcSet=&quot;/static/535bfc2d1fec8e70849dec45f66ab62b/c371b/Screenshot_20221223_181627.png 1654w&quot; sizes=&quot;(max-width: 1654px) 100vw, 1654px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Altair UI&lt;/figcaption&gt;
  &lt;/figure&gt; &lt;/p&gt;&lt;p&gt;You can access Altair either through &lt;strong&gt;Aria Hub&lt;/strong&gt; &amp;gt; &lt;strong&gt;Developer Resources&lt;/strong&gt; &amp;gt; &lt;strong&gt;Altair GraphQL Client&lt;/strong&gt; or directly using the following link: &lt;a href=&quot;https://api.mgmt.cloud.vmware.com/aria/altair/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://api.mgmt.cloud.vmware.com/aria/altair/&lt;/a&gt;.&lt;/p&gt;&lt;h2 id=&quot;csp-token&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#csp-token&quot; aria-label=&quot;csp token permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;CSP Token&lt;/h2&gt;&lt;p&gt;Before we can use Altair we need to generate a CSP Token, you can do this by going to the &lt;a href=&quot;https://console.cloud.vmware.com/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;Cloud Services Portal&lt;/a&gt; &amp;gt; &lt;strong&gt;Select the dropdown by your username (top right)&lt;/strong&gt; &amp;gt; &lt;strong&gt;My Account&lt;/strong&gt; &amp;gt; &lt;strong&gt;API Tokens&lt;/strong&gt;.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Press GENERATE TOKEN&lt;/li&gt;&lt;li&gt;Provide a Token Name&lt;/li&gt;&lt;li&gt;Select a Token TTL &lt;/li&gt;&lt;li&gt;Select Service Role &amp;gt; VMware Aria Hub&lt;/li&gt;&lt;li&gt;Press GENERATE and take note of the CSP token value - we will need this token for Altair&lt;/li&gt;&lt;/ul&gt;&lt;h2 id=&quot;altair-setup&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#altair-setup&quot; aria-label=&quot;altair setup permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Altair Setup&lt;/h2&gt;&lt;p&gt;Once generated, head back to &lt;a href=&quot;https://api.mgmt.cloud.vmware.com/aria/altair/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;Altair&lt;/a&gt;. For us to be able to query data we need to &lt;em&gt;authorize&lt;/em&gt; our requests, we can use the mutation that is provided by default to help generate a Bearer token. &lt;/p&gt;&lt;p&gt;At the bottom of your Altair window press the &lt;strong&gt;VARIABLES&lt;/strong&gt; button and construct the input like below and then press &lt;strong&gt;(Run mutation)&lt;/strong&gt;. Take note of the returned Bearer token. &lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;json&quot;&gt;&lt;pre class=&quot;language-json&quot;&gt;&lt;code class=&quot;language-json&quot;&gt;&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
  &lt;span class=&quot;token property&quot;&gt;&amp;quot;CSP_USER_TOKEN&amp;quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;c-l7aUhW7OWzJaOAaq2Ho8MYEXAMPLECSPTOKENBrJF3i9M_3N6R_JFHglYX&amp;quot;&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Once you have the Bearer token, within Altair select the &lt;strong&gt;Set Headers&lt;/strong&gt; menu on the left (&lt;em&gt;yellow box in the image below&lt;/em&gt;). For the Header key enter &lt;code class=&quot;language-text&quot;&gt;authorization&lt;/code&gt; and for the Header value enter the Bearer token, including the &lt;strong&gt;Bearer&lt;/strong&gt; word. Press Save. &lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1657px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:53.34942667471334%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAALCAYAAAB/Ca1DAAAACXBIWXMAAA7EAAAOxAGVKw4bAAABlklEQVQoz5XSy27UMBSA4bwSnZkkTmI7vseTSedCC62KBAsWbHj/5Y8c1BZUBsTik+8+Prar+RxJh4WQZ2yY8CljwoQ0+YWyGTkmlEkoW8Ze69pNaJvZX048fr+nWk49ebEsx7ia9hYfJTYMuDCgjEJIjY4TvYkI6daNhjHSDGZtd9Iz5sj520wlZEDqQK88TW+4qSXbVrHrOrZC0KsWLXd8+Xrh7mHBhwnrM9ZNGJtWY1EykJGq146mRNGeUXuUtEihMI1kbCS6lvSbjqfzPXPa836feDB+9WjDK/dTZUbH50vmYDxeWkwrUULRFu1A00o27cDpwxPS7RlMubPrql5aDtpjekvTDtTtQN8b6npgsxHc7DrebQV3Hz8xurw+gnL5qiqPkXmMmFZhhMKWdIXEdArbKVyrqIVmms/ossj+44ST8pzykUOcufWJY0jchsRSSp+YbVojy5dvkt/4tb/qyr2ZtBrN9BtjpnXy84Ln+t9UnfJov/9j5P9mM9VgHL1NdDrSKUcJ8JZbP3JJ+xplEzokfgCVqodfcqNpoQAAAABJRU5ErkJggg==&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Altair IDE Setup&quot; title=&quot;Altair IDE Setup&quot; src=&quot;/static/50b5247d7a0c812f43a4f8cf5cecb278/a22e6/Screenshot_20221223_182324.png&quot; srcSet=&quot;/static/50b5247d7a0c812f43a4f8cf5cecb278/a22e6/Screenshot_20221223_182324.png 1657w&quot; sizes=&quot;(max-width: 1657px) 100vw, 1657px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Altair IDE Setup&lt;/figcaption&gt;
  &lt;/figure&gt; &lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:516px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:61.82170542635659%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAMCAYAAABiDJ37AAAACXBIWXMAAA7EAAAOxAGVKw4bAAABu0lEQVQoz32S626cMBCFeaE2We6YNZibwcFcNrslqnKRqv5qpDxM3qx9olONd012oyQ/PhiG4cx4Dg4vK/z8fY/l1x2m/QE3+hZ62mOYDxh3P6D0DNXPJjfdLghiDjdg8MJ0ZeMn2OYV4lTACeIMWS6R8hqZkMgKibxskZcSomrBRQ0uGpMrqg5+tF0F6W5jEqXYocu1G5vEtWeJ3/Avn+1UbpBeTGlxQsYRpvwiSVN8BDU3ccwRJhkCIuYm54XHGkfoAuPDgGFcMO/vzK6o6FyYhGifejqYGtrltFvMng/LPZTeIWL5UdB2pYSFBM8hcbrTO5rMQvu38Xpk2h3jpelStz2abkCrRnT9DNkNkGpAezMZpymuW41GjaaurBUq2Zs6amZMsW5tCD8xXYq6M4Wi6lA2Ck2n0ZBQ28NPK2ySAm4iVpfdkMGLThNawXNTTAOfrR9QoyNUZznV+imurphh4zE45FTExEqY5J+6/B4vSMGKDOqpRvdYYdvkcBJeQk4acu7R7jR4Id+O8gV0xO/fEnRPJV7//cHr32fMLw0cPzq5xzJEaW6c++ynfQ8dMRYc6rGGemjAKo7/seKcqrtY42cAAAAASUVORK5CYII=&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Altair IDE Headers&quot; title=&quot;Altair IDE Headers&quot; src=&quot;/static/22c00c74887a8e593f8c9e221fed0cec/fbb32/Screenshot_20221223_183116.png&quot; srcSet=&quot;/static/22c00c74887a8e593f8c9e221fed0cec/fbb32/Screenshot_20221223_183116.png 516w&quot; sizes=&quot;(max-width: 516px) 100vw, 516px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Altair IDE Headers&lt;/figcaption&gt;
  &lt;/figure&gt; &lt;/p&gt;&lt;p&gt;Now Altair is ready for us to start making some queries. Clear out the existing code in the Query panel or open a new tab by pressing &lt;strong&gt;+ Add new&lt;/strong&gt; at the top (&lt;em&gt;make sure you set the header again&lt;/em&gt;).&lt;/p&gt;&lt;h2 id=&quot;graphql-queries&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#graphql-queries&quot; aria-label=&quot;graphql queries permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;GraphQL Queries&lt;/h2&gt;&lt;p&gt;Using Altair we can start to query our data that exists in Aria Hub. Lets repeat some of the searches that we did within the UI. &lt;/p&gt;&lt;h3 id=&quot;return-all-aws-ec2-instances&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#return-all-aws-ec2-instances&quot; aria-label=&quot;return all aws ec2 instances permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Return all AWS EC2 Instances&lt;/h3&gt;&lt;p&gt;This query returns all entities that match &lt;code class=&quot;language-text&quot;&gt;entityType: &amp;quot;AWS.EC2.Instance&amp;quot;&lt;/code&gt;. For each of the returned entities we want the values for fields &lt;code class=&quot;language-text&quot;&gt;entityName&lt;/code&gt; and &lt;code class=&quot;language-text&quot;&gt;entityType&lt;/code&gt;.&lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1602px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:19.600499375780274%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAECAYAAACOXx+WAAAACXBIWXMAAA7EAAAOxAGVKw4bAAAAs0lEQVQY012PWY6DMBBEuVJYTGwDNniJe4gyiiLN/W/yRiyKonyUqn/6VVWVXis6ZZreorWlv1pqZWk6Q6MsdWfo9MD69ySUX6alMC6y+6HzDoLPQtVePRcTd2CrDn0D235gcDcmeeHzgxALSxL8BgmFOQouHAGVMm5/+tQG26EnsDeOOf0wxjvz7cFdClKEkISYCykf8K1ttaXXZ5tGna2+Gio94eP6njnOwvgxeTzdBeEf3wyKBei7vG4AAAAASUVORK5CYII=&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Return all AWS EC2 Instances&quot; title=&quot;Return all AWS EC2 Instances&quot; src=&quot;/static/1bccf5b5079bcbd2bf1b6808aaf0dfff/b5600/Screenshot_20221223_185004.png&quot; srcSet=&quot;/static/1bccf5b5079bcbd2bf1b6808aaf0dfff/b5600/Screenshot_20221223_185004.png 1602w&quot; sizes=&quot;(max-width: 1602px) 100vw, 1602px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Return all AWS EC2 Instances&lt;/figcaption&gt;
  &lt;/figure&gt;&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;graphql&quot;&gt;&lt;pre class=&quot;language-graphql&quot;&gt;&lt;code class=&quot;language-graphql&quot;&gt;&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
  &lt;span class=&quot;token object&quot;&gt;entityQuery&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
    &lt;span class=&quot;token property-query&quot;&gt;queryEntities&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token attr-name&quot;&gt;entityType&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;AWS.EC2.Instance&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
      &lt;span class=&quot;token object&quot;&gt;entities&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
        &lt;span class=&quot;token property&quot;&gt;entityName&lt;/span&gt;
        &lt;span class=&quot;token property&quot;&gt;entityId&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
    &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
  &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h3 id=&quot;return-aws-ec2-instances-and-all-of-their-properties&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#return-aws-ec2-instances-and-all-of-their-properties&quot; aria-label=&quot;return aws ec2 instances and all of their properties permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Return AWS EC2 Instances and all of their properties.&lt;/h3&gt;&lt;p&gt;Similar to the above example, but this time we want to see all property names and values for each entity. &lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1559px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:45.22129570237331%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAJCAYAAAAywQxIAAAACXBIWXMAAA7EAAAOxAGVKw4bAAABD0lEQVQoz5WR7Y6DIBBFfaNNa6soFqyMwIiuG7Pv/yp3A1bb7lfSHzcwITk5d8hadlDTgFxcUFQSopI4iwZ5IfccTjW64GHnBdoEaOOhOk7R5jmZqFu8VRb5hXAqK5RC4lRKHM91SgTGs24MVP8OxZ9oKaAjjyvxDez3ZFJ1OAqNXKgbRO6gLXFudI/WMC5ugR1mfASPgRlkGb1lOOdhekZWK8IhAnbIZvV4fwDSBMcjAvsE886jo9UyVS5qfTf6ZvarIU2wfsQcVuAG2qo/A/9IfJeaElDRiN6vhmm+AeNH/TT8B9j1YTWhKQHHCKRHwxeB6uqSUWNCqhwN9ZMhvwbcKpthgXEjrN12eK8bgV8JdzZ4jxf+gwAAAABJRU5ErkJggg==&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Return AWS EC2 Instances and all of their properties&quot; title=&quot;Return AWS EC2 Instances and all of their properties&quot; src=&quot;/static/c285466e76e686c22518f626eaca43c5/4509c/Screenshot_20221228_093400.png&quot; srcSet=&quot;/static/c285466e76e686c22518f626eaca43c5/4509c/Screenshot_20221228_093400.png 1559w&quot; sizes=&quot;(max-width: 1559px) 100vw, 1559px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Return AWS EC2 Instances and all of their properties&lt;/figcaption&gt;
  &lt;/figure&gt;&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;graphql&quot;&gt;&lt;pre class=&quot;language-graphql&quot;&gt;&lt;code class=&quot;language-graphql&quot;&gt;&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
  &lt;span class=&quot;token object&quot;&gt;entityQuery&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
    &lt;span class=&quot;token property-query&quot;&gt;queryEntities&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token attr-name&quot;&gt;entityType&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;AWS.EC2.Instance&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
      &lt;span class=&quot;token object&quot;&gt;entities&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
        &lt;span class=&quot;token property&quot;&gt;entityName&lt;/span&gt;
        &lt;span class=&quot;token property&quot;&gt;entityId&lt;/span&gt;
        &lt;span class=&quot;token object&quot;&gt;properties&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
          &lt;span class=&quot;token property&quot;&gt;name&lt;/span&gt;
          &lt;span class=&quot;token property&quot;&gt;value&lt;/span&gt;
        &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
    &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
  &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h3 id=&quot;return-aws-ec2-instances-and-only-some-properties&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#return-aws-ec2-instances-and-only-some-properties&quot; aria-label=&quot;return aws ec2 instances and only some properties permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Return AWS EC2 Instances and only some properties.&lt;/h3&gt;&lt;p&gt;In this search we only want the name and value for specific properties from each entity. In this instance &lt;code class=&quot;language-text&quot;&gt;PrivateDnsName&lt;/code&gt;, &lt;code class=&quot;language-text&quot;&gt;PrivateIpAddress&lt;/code&gt; and &lt;code class=&quot;language-text&quot;&gt;StateName&lt;/code&gt;.&lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1612px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:38.0272952853598%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAICAYAAAD5nd/tAAAACXBIWXMAAA7DAAAOwwHHb6hkAAABFElEQVQoz42SyW7EIBBE/UeJdwNeMGDceJlRopGi/P+HVMTiaC5R5lBq+sDrKprMfh0o2h5VK9B0ItSi9uIoG4H3gmFaDc7vB6Q+MCrCqF2ok/ZymFSss3XI3toF1bigYRycC3RMoG6jPNCDWy4x6BOje2Ay+y9oVBE8KIfBD1KErGASpZjRdByMRSBLqtseecXA+hnSOAzrJ/T2gdtGODcHY70I1hIW68KQLK8FypoHJ5fy69yIBFSQ2mEwBzTdcN8pwEJMQ0kJeL3VX3oGjmaHpjM4tKuDXijFjtFj5H+ARcXQ+cjB4Q5DJxxR6KW+FpOW86rDQS6Ylz1s97p4uYpbjv3LwD4A45eZFKXL0VkAPw36ASAkFFrFILELAAAAAElFTkSuQmCC&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Return AWS EC2 Instances and only some properties&quot; title=&quot;Return AWS EC2 Instances and only some properties&quot; src=&quot;/static/9efa07ba7a6e3f98597742af8aa3c4b5/f0f3e/Screenshot_20221228_093816.png&quot; srcSet=&quot;/static/9efa07ba7a6e3f98597742af8aa3c4b5/f0f3e/Screenshot_20221228_093816.png 1612w&quot; sizes=&quot;(max-width: 1612px) 100vw, 1612px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Return AWS EC2 Instances and only some properties&lt;/figcaption&gt;
  &lt;/figure&gt;&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;graphql&quot;&gt;&lt;pre class=&quot;language-graphql&quot;&gt;&lt;code class=&quot;language-graphql&quot;&gt;&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
  &lt;span class=&quot;token object&quot;&gt;entityQuery&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
    &lt;span class=&quot;token property-query&quot;&gt;queryEntities&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token attr-name&quot;&gt;entityType&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;AWS.EC2.Instance&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
      &lt;span class=&quot;token object&quot;&gt;entities&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
        &lt;span class=&quot;token property&quot;&gt;entityName&lt;/span&gt;
        &lt;span class=&quot;token property&quot;&gt;entityId&lt;/span&gt;
        &lt;span class=&quot;token property-query&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token attr-name&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;PrivateDnsName&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;PrivateIpAddress&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;StateName&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
          &lt;span class=&quot;token property&quot;&gt;name&lt;/span&gt;
          &lt;span class=&quot;token property&quot;&gt;value&lt;/span&gt;
        &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
    &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
  &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&quot;introducing-variables&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#introducing-variables&quot; aria-label=&quot;introducing variables permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Introducing Variables&lt;/h2&gt;&lt;p&gt;The previous examples were static queries, if we want to change what data gets returned we have to manually update the GraphQL query. To make it more dynamic we can start to use variables.  &lt;/p&gt;&lt;p&gt;In the below query we take in four variables&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;entityId&lt;/code&gt; - the ID of the object we want to look at. &lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;statKey&lt;/code&gt; the metric(s) we want values for&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;startTime&lt;/code&gt; - from what point we want to see the metrics&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;intervalMins&lt;/code&gt; - the interval of the timestamps for the metrics.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;We can utilise the Altair variables window to input our values. The key of the variables payload must match the variable name in the GraphQL query, for example key &lt;code class=&quot;language-text&quot;&gt;entityId&lt;/code&gt; matches variable &lt;code class=&quot;language-text&quot;&gt;$entityId&lt;/code&gt;. &lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:2034px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:35.693215339233035%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAHCAYAAAAIy204AAAACXBIWXMAAA7DAAAOwwHHb6hkAAAA+klEQVQoz33Q23KDIBRA0fxRk3hFBYGIgsY4bf7/W3ZH0phLp33YwxOLw9m1IaDGESENZa3JSkkuVKyoWo5ZTS4k3flCOywoG97ytKeANAPDtLDLhWZfaopKkYkmnqmoKSrNMati6yPKeKT/ovcTU/B0LtA5T9eHDezDwq6UlmOpSApJklckef3SDVS0J49yM36+4vx5m+zeA2xMvPQO/QLtCp4Z5iudnzfw+csRTIuGj6Rkn1axw0/37x5SEfep3YR6Av6csB8XjHVYY2i1pVYWqSyisZRrtaFp3Q18w57RDVx3Ml8+Cd7TDyPWBU4uoLvwMsEDCf9O+A2NNvS5904gjwAAAABJRU5ErkJggg==&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Return specific AWS EC2 Instance with metrics/stats&quot; title=&quot;Return specific AWS EC2 Instance with metrics/stats&quot; src=&quot;/static/a118466e6f63d1a0020f0f673d83cee7/39b47/Screenshot_20221228_104305.png&quot; srcSet=&quot;/static/a118466e6f63d1a0020f0f673d83cee7/39b47/Screenshot_20221228_104305.png 2034w&quot; sizes=&quot;(max-width: 2034px) 100vw, 2034px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Return specific AWS EC2 Instance with metrics/stats&lt;/figcaption&gt;
  &lt;/figure&gt;&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;graphql&quot;&gt;&lt;pre class=&quot;language-graphql&quot;&gt;&lt;code class=&quot;language-graphql&quot;&gt;&lt;span class=&quot;token keyword&quot;&gt;query&lt;/span&gt; &lt;span class=&quot;token definition-query function&quot;&gt;awsStats&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token variable&quot;&gt;$entityId&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token class-name&quot;&gt;EntityId&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;!&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token variable&quot;&gt;$statKey&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token scalar&quot;&gt;String&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;!&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token variable&quot;&gt;$startTime&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token class-name&quot;&gt;DateTime&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token variable&quot;&gt;$intervalMins&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token scalar&quot;&gt;Int&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
  &lt;span class=&quot;token object&quot;&gt;entityQuery&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
    &lt;span class=&quot;token property-query&quot;&gt;queryEntities&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token attr-name&quot;&gt;entityId&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token variable&quot;&gt;$entityId&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
      &lt;span class=&quot;token object&quot;&gt;entities&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
        &lt;span class=&quot;token property&quot;&gt;entityName&lt;/span&gt;
        &lt;span class=&quot;token property&quot;&gt;entityId&lt;/span&gt;
        &lt;span class=&quot;token property-query&quot;&gt;stats&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;
          &lt;span class=&quot;token attr-name&quot;&gt;input&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;&lt;span class=&quot;token attr-name&quot;&gt;keys&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token variable&quot;&gt;$statKey&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token attr-name&quot;&gt;startTime&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token variable&quot;&gt;$startTime&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token attr-name&quot;&gt;intervalMins&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token variable&quot;&gt;$intervalMins&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
        &lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
          &lt;span class=&quot;token property&quot;&gt;key&lt;/span&gt;
          &lt;span class=&quot;token property&quot;&gt;values&lt;/span&gt;
          &lt;span class=&quot;token property&quot;&gt;timestampsMillis&lt;/span&gt;
        &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
    &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
  &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;json&quot;&gt;&lt;pre class=&quot;language-json&quot;&gt;&lt;code class=&quot;language-json&quot;&gt;&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
  &lt;span class=&quot;token property&quot;&gt;&amp;quot;entityId&amp;quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;AWS.EC2.628637233703.us-east-1.Instance.i-069ecb9cb0e422211&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
  &lt;span class=&quot;token property&quot;&gt;&amp;quot;statKey&amp;quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;CPUUtilization&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;NetworkIn&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
  &lt;span class=&quot;token property&quot;&gt;&amp;quot;startTime&amp;quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;2022-12-27T09:49:30.629Z&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
  &lt;span class=&quot;token property&quot;&gt;&amp;quot;intervalMins&amp;quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;30&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&quot;introducing-fragments&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#introducing-fragments&quot; aria-label=&quot;introducing fragments permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Introducing Fragments&lt;/h2&gt;&lt;p&gt;From the &lt;a href=&quot;https://graphql.org/learn/queries/#fragments&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;GraphQL docs&lt;/a&gt;, the core capability of Fragments is as follows…&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;Fragments let you construct sets of fields, and then include them in queries where you need to.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;The query below, which is for a single AWS EC2 Instance, returns the following information&lt;/p&gt;&lt;ul&gt;&lt;li&gt;The name, type and ID or our queried entity.&lt;/li&gt;&lt;li&gt;The tags for our queried entity.&lt;/li&gt;&lt;li&gt;Relationships to children entities (&lt;code class=&quot;language-text&quot;&gt;entitiesIn&lt;/code&gt;), including their properties and their own children.&lt;/li&gt;&lt;li&gt;Relationships to parent entities (&lt;code class=&quot;language-text&quot;&gt;entitiesOut&lt;/code&gt;), including their properties&lt;/li&gt;&lt;li&gt;Stats keys of our queried entity. &lt;/li&gt;&lt;li&gt;Costing information of our queried entity. &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;If we look at the query below we are asking for the same information multiple times, for example on the queried entity we want &lt;code class=&quot;language-text&quot;&gt;entityId&lt;/code&gt;, &lt;code class=&quot;language-text&quot;&gt;entityType&lt;/code&gt;, &lt;code class=&quot;language-text&quot;&gt;entityName&lt;/code&gt; and &lt;code class=&quot;language-text&quot;&gt;properties&lt;/code&gt;, we then ask for the same with the parent and child entities that are connected. By using fragments we can reduce some of this repetition and utilise reuable information. &lt;/p&gt;&lt;div class=&quot;gatsby-highlight has-highlighted-lines&quot; data-language=&quot;graphql&quot;&gt;&lt;pre class=&quot;language-graphql&quot;&gt;&lt;code class=&quot;language-graphql&quot;&gt;&lt;span class=&quot;token keyword&quot;&gt;query&lt;/span&gt; &lt;span class=&quot;token definition-query function&quot;&gt;entityDetails&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token variable&quot;&gt;$entityId&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token class-name&quot;&gt;EntityId&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;!&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
  &lt;span class=&quot;token object&quot;&gt;entityQuery&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
    &lt;span class=&quot;token property-query&quot;&gt;queryEntities&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token attr-name&quot;&gt;entityId&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token variable&quot;&gt;$entityId&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
      &lt;span class=&quot;token object&quot;&gt;entities&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;        &lt;span class=&quot;token property&quot;&gt;entityId&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;        &lt;span class=&quot;token property&quot;&gt;entityType&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;        &lt;span class=&quot;token property&quot;&gt;entityName&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;        &lt;span class=&quot;token object&quot;&gt;properties&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;          &lt;span class=&quot;token property&quot;&gt;name&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;          &lt;span class=&quot;token property&quot;&gt;value&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;        &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;/span&gt;        &lt;span class=&quot;token object&quot;&gt;tags&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
          &lt;span class=&quot;token property&quot;&gt;key&lt;/span&gt;
          &lt;span class=&quot;token property&quot;&gt;value&lt;/span&gt;
        &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
        &lt;span class=&quot;token attr-name&quot;&gt;entitiesIn&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token property-query&quot;&gt;entitiesIn&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token attr-name&quot;&gt;first&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;500&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token attr-name&quot;&gt;traversalScope&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token constant&quot;&gt;SAME_PARTITION&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
          &lt;span class=&quot;token property&quot;&gt;count&lt;/span&gt;
          &lt;span class=&quot;token property&quot;&gt;totalCount&lt;/span&gt;
          &lt;span class=&quot;token object&quot;&gt;entities&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;            &lt;span class=&quot;token property&quot;&gt;entityId&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;            &lt;span class=&quot;token property&quot;&gt;entityType&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;            &lt;span class=&quot;token property&quot;&gt;entityName&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;            &lt;span class=&quot;token object&quot;&gt;properties&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;              &lt;span class=&quot;token property&quot;&gt;name&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;              &lt;span class=&quot;token property&quot;&gt;value&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;            &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;/span&gt;            &lt;span class=&quot;token property&quot;&gt;service&lt;/span&gt;
            &lt;span class=&quot;token attr-name&quot;&gt;entitiesIn&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token property-query&quot;&gt;entitiesIn&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token attr-name&quot;&gt;first&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;500&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token attr-name&quot;&gt;traversalScope&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token constant&quot;&gt;SAME_PARTITION&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
              &lt;span class=&quot;token property&quot;&gt;count&lt;/span&gt;
              &lt;span class=&quot;token property&quot;&gt;totalCount&lt;/span&gt;
              &lt;span class=&quot;token object&quot;&gt;entities&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
                &lt;span class=&quot;token property&quot;&gt;entityId&lt;/span&gt;
                &lt;span class=&quot;token property&quot;&gt;entityType&lt;/span&gt;
                &lt;span class=&quot;token property&quot;&gt;entityName&lt;/span&gt;
                &lt;span class=&quot;token property&quot;&gt;provider&lt;/span&gt;
              &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
            &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
        &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
        &lt;span class=&quot;token attr-name&quot;&gt;entitiesOut&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token property-query&quot;&gt;entitiesOut&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token attr-name&quot;&gt;first&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;500&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token attr-name&quot;&gt;traversalScope&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token constant&quot;&gt;ANY_PARTITION&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
          &lt;span class=&quot;token property&quot;&gt;count&lt;/span&gt;
          &lt;span class=&quot;token object&quot;&gt;entities&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;            &lt;span class=&quot;token property&quot;&gt;entityId&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;            &lt;span class=&quot;token property&quot;&gt;entityType&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;            &lt;span class=&quot;token property&quot;&gt;entityName&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;            &lt;span class=&quot;token object&quot;&gt;properties&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;              &lt;span class=&quot;token property&quot;&gt;name&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;              &lt;span class=&quot;token property&quot;&gt;value&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;            &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;/span&gt;            &lt;span class=&quot;token property&quot;&gt;service&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
        &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
        &lt;span class=&quot;token property&quot;&gt;service&lt;/span&gt;
        &lt;span class=&quot;token property-query&quot;&gt;stats&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token attr-name&quot;&gt;input&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;&lt;span class=&quot;token attr-name&quot;&gt;namespace&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;AWS&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
          &lt;span class=&quot;token property&quot;&gt;key&lt;/span&gt;
        &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
        &lt;span class=&quot;token object&quot;&gt;costing&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
          &lt;span class=&quot;token object&quot;&gt;listPrices&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
            &lt;span class=&quot;token property&quot;&gt;publicPrice&lt;/span&gt;
            &lt;span class=&quot;token property&quot;&gt;displayName&lt;/span&gt;
            &lt;span class=&quot;token property&quot;&gt;description&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
        &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
    &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
  &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;To construct a Fragment we need to know the schema type, we can find that out in two ways - through the &lt;a href=&quot;https://api.mgmt.cloud.vmware.com/aria/docs/entity.doc.html&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;Aria GraphQL docs&lt;/a&gt; or by adding the &lt;code class=&quot;language-text&quot;&gt;__typename&lt;/code&gt; field to our queries. &lt;/p&gt;&lt;p&gt;By using the &lt;code class=&quot;language-text&quot;&gt;__typeName&lt;/code&gt; method we have identified two schema types that we want to construct our Fragments on: &lt;strong&gt;Entity&lt;/strong&gt; and &lt;strong&gt;EntityConnection&lt;/strong&gt;. &lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1649px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:27.410551849605824%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAFCAYAAABFA8wzAAAACXBIWXMAAA7EAAAOxAGVKw4bAAAA8klEQVQY012PSW7DMBAE/aBcZIvaKFPcRJOiLW9JkP9/pAJJgZHk0Oi5dKFmdxxP2MeMiRbtLVVvKIRkX0mKn+zrHnu+oKcng88oG1E2rT24tGa5Q76ya6XmTVh65ZhNS3IVwQqiESQj8EowDoI5DqScUfHJGCLWxxdo6aM5ccp3dlI59vWRcshYf+ESMpNLzCHxCInJJpJNzHEmh8XyAx/P+DGiVrvfwNsGLETHoVFbtwrRm1dKqWmUJ9+/mK6fmOkdnZ5MKWLHtL7+B9gPjqLVHKSjrDuqRlI2HXXT0TYdRdlyqCTab6PFSrkJ4ze7/8BvX1ywn7H7J9gAAAAASUVORK5CYII=&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;__typeName field information &quot; title=&quot;__typeName field information &quot; src=&quot;/static/528b988b5fd762c4f911f4b8600e020a/e315f/Screenshot_20221228_130314.png&quot; srcSet=&quot;/static/528b988b5fd762c4f911f4b8600e020a/e315f/Screenshot_20221228_130314.png 1649w&quot; sizes=&quot;(max-width: 1649px) 100vw, 1649px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;__typeName field information &lt;/figcaption&gt;
  &lt;/figure&gt;&lt;/p&gt;&lt;p&gt;A fragment consists of two things, its name and the schema type we are fragmenting on - &lt;code class=&quot;language-text&quot;&gt;fragment &amp;lt;fragmentName&amp;gt; on &amp;lt;type&amp;gt;&lt;/code&gt;. By using them we can reduce the overall length of our query. We can use a Fragment by referencing its name &lt;code class=&quot;language-text&quot;&gt;...&amp;lt;fragmentName&amp;gt;&lt;/code&gt;, as seen in the highlighted code below. &lt;/p&gt;&lt;div class=&quot;gatsby-highlight has-highlighted-lines&quot; data-language=&quot;graphql&quot;&gt;&lt;pre class=&quot;language-graphql&quot;&gt;&lt;code class=&quot;language-graphql&quot;&gt;&lt;span class=&quot;token keyword&quot;&gt;query&lt;/span&gt; &lt;span class=&quot;token definition-query function&quot;&gt;entityDetails&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token variable&quot;&gt;$entityId&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token class-name&quot;&gt;EntityId&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;!&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
  &lt;span class=&quot;token object&quot;&gt;entityQuery&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
    &lt;span class=&quot;token property-query&quot;&gt;queryEntities&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token attr-name&quot;&gt;entityId&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token variable&quot;&gt;$entityId&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
      &lt;span class=&quot;token object&quot;&gt;entities&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;        &lt;span class=&quot;token operator&quot;&gt;...&lt;/span&gt;&lt;span class=&quot;token fragment function&quot;&gt;entity&lt;/span&gt;&lt;/span&gt;        &lt;span class=&quot;token object&quot;&gt;tags&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
          &lt;span class=&quot;token property&quot;&gt;key&lt;/span&gt;
          &lt;span class=&quot;token property&quot;&gt;value&lt;/span&gt;
        &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
        &lt;span class=&quot;token attr-name&quot;&gt;entitiesIn&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token property-query&quot;&gt;entitiesIn&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token attr-name&quot;&gt;first&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;500&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token attr-name&quot;&gt;traversalScope&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token constant&quot;&gt;SAME_PARTITION&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;          &lt;span class=&quot;token operator&quot;&gt;...&lt;/span&gt;&lt;span class=&quot;token fragment function&quot;&gt;connection&lt;/span&gt;&lt;/span&gt;          &lt;span class=&quot;token object&quot;&gt;entities&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;            &lt;span class=&quot;token operator&quot;&gt;...&lt;/span&gt;&lt;span class=&quot;token fragment function&quot;&gt;entity&lt;/span&gt;&lt;/span&gt;            &lt;span class=&quot;token attr-name&quot;&gt;entitiesIn&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token property-query&quot;&gt;entitiesIn&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token attr-name&quot;&gt;first&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;500&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token attr-name&quot;&gt;traversalScope&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token constant&quot;&gt;SAME_PARTITION&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;              &lt;span class=&quot;token operator&quot;&gt;...&lt;/span&gt;&lt;span class=&quot;token fragment function&quot;&gt;connection&lt;/span&gt;&lt;/span&gt;              &lt;span class=&quot;token object&quot;&gt;entities&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;                &lt;span class=&quot;token operator&quot;&gt;...&lt;/span&gt;&lt;span class=&quot;token fragment function&quot;&gt;childrenChildrenEntity&lt;/span&gt;&lt;/span&gt;              &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
            &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
        &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
        &lt;span class=&quot;token attr-name&quot;&gt;entitiesOut&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token property-query&quot;&gt;entitiesOut&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token attr-name&quot;&gt;first&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;500&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token attr-name&quot;&gt;traversalScope&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token constant&quot;&gt;ANY_PARTITION&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;          &lt;span class=&quot;token operator&quot;&gt;...&lt;/span&gt;&lt;span class=&quot;token fragment function&quot;&gt;connection&lt;/span&gt;&lt;/span&gt;          &lt;span class=&quot;token object&quot;&gt;entities&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;            &lt;span class=&quot;token operator&quot;&gt;...&lt;/span&gt;&lt;span class=&quot;token fragment function&quot;&gt;entity&lt;/span&gt;&lt;/span&gt;          &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
        &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
        &lt;span class=&quot;token property-query&quot;&gt;stats&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token attr-name&quot;&gt;input&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;&lt;span class=&quot;token attr-name&quot;&gt;namespace&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;AWS&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
          &lt;span class=&quot;token property&quot;&gt;key&lt;/span&gt;
        &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
        &lt;span class=&quot;token object&quot;&gt;costing&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
          &lt;span class=&quot;token object&quot;&gt;listPrices&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
            &lt;span class=&quot;token property&quot;&gt;publicPrice&lt;/span&gt;
            &lt;span class=&quot;token property&quot;&gt;displayName&lt;/span&gt;
            &lt;span class=&quot;token property&quot;&gt;description&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
        &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
    &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
  &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;

&lt;span class=&quot;token keyword&quot;&gt;fragment&lt;/span&gt; &lt;span class=&quot;token fragment function&quot;&gt;entity&lt;/span&gt; &lt;span class=&quot;token keyword&quot;&gt;on&lt;/span&gt; &lt;span class=&quot;token class-name&quot;&gt;Entity&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
  &lt;span class=&quot;token property&quot;&gt;__typename&lt;/span&gt;
  &lt;span class=&quot;token property&quot;&gt;entityId&lt;/span&gt;
  &lt;span class=&quot;token property&quot;&gt;entityName&lt;/span&gt;
  &lt;span class=&quot;token property&quot;&gt;entityType&lt;/span&gt;
  &lt;span class=&quot;token property&quot;&gt;service&lt;/span&gt;
  &lt;span class=&quot;token object&quot;&gt;properties&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
    &lt;span class=&quot;token property&quot;&gt;name&lt;/span&gt; 
    &lt;span class=&quot;token property&quot;&gt;value&lt;/span&gt;
  &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;

&lt;span class=&quot;token keyword&quot;&gt;fragment&lt;/span&gt; &lt;span class=&quot;token fragment function&quot;&gt;childrenChildrenEntity&lt;/span&gt; &lt;span class=&quot;token keyword&quot;&gt;on&lt;/span&gt; &lt;span class=&quot;token class-name&quot;&gt;Entity&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
  &lt;span class=&quot;token property&quot;&gt;entityId&lt;/span&gt;
  &lt;span class=&quot;token property&quot;&gt;entityName&lt;/span&gt;
  &lt;span class=&quot;token property&quot;&gt;entityType&lt;/span&gt;
  &lt;span class=&quot;token property&quot;&gt;provider&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;

&lt;span class=&quot;token keyword&quot;&gt;fragment&lt;/span&gt; &lt;span class=&quot;token fragment function&quot;&gt;connection&lt;/span&gt; &lt;span class=&quot;token keyword&quot;&gt;on&lt;/span&gt; &lt;span class=&quot;token class-name&quot;&gt;EntityConnection&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
  &lt;span class=&quot;token property&quot;&gt;__typename&lt;/span&gt;
  &lt;span class=&quot;token property&quot;&gt;count&lt;/span&gt;
  &lt;span class=&quot;token property&quot;&gt;totalCount&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&quot;using-our-data&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#using-our-data&quot; aria-label=&quot;using our data permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Using our Data&lt;/h2&gt;&lt;p&gt;One example of returned data is the stats object. Depending on what you ask for this is typically returned as values and timestamps. They are returned as seperate keys, like the example below, however they are ordered the same - e.g. the top value relates to the top timestamp. &lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;json&quot;&gt;&lt;pre class=&quot;language-json&quot;&gt;&lt;code class=&quot;language-json&quot;&gt;&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
  &lt;span class=&quot;token property&quot;&gt;&amp;quot;key&amp;quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;CPUUtilization&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
  &lt;span class=&quot;token property&quot;&gt;&amp;quot;values&amp;quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;
    &lt;span class=&quot;token string&quot;&gt;&amp;quot;0.1832291531770028&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
    &lt;span class=&quot;token string&quot;&gt;&amp;quot;0.18350209991521224&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
    &lt;span class=&quot;token string&quot;&gt;&amp;quot;0.18358360369332824&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
    &lt;span class=&quot;token string&quot;&gt;&amp;quot;0.18885047821375775&amp;quot;&lt;/span&gt;
  &lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
  &lt;span class=&quot;token property&quot;&gt;&amp;quot;timestampsMillis&amp;quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;
    &lt;span class=&quot;token number&quot;&gt;1672226340000&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
    &lt;span class=&quot;token number&quot;&gt;1672224540000&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
    &lt;span class=&quot;token number&quot;&gt;1672222740000&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
    &lt;span class=&quot;token number&quot;&gt;1672220940000&lt;/span&gt;
  &lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;With the metrics results we can take them and use an external tool, such as Excel to build out charts similar to the one within Aria Hub. &lt;/p&gt;&lt;table&gt;&lt;tr&gt;&lt;td&gt;&lt;b&gt;Aria Hub&lt;/b&gt;&lt;/td&gt;&lt;td&gt;&lt;b&gt;Excel&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style=&quot;width:50%&quot;&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:734px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:58.58310626702997%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAMCAYAAABiDJ37AAAACXBIWXMAAA7DAAAOwwHHb6hkAAACT0lEQVQoz3VSS2sTURjNf2ipqWCTeeWdNJN5ZTLPPE2jgVRaK5Qi6KYrwUBdVF0ouFQrilbBrVKKIKnVhdSfU0gTDUapBKtH7p0kWqGLM9+De78595zPx4g5MJkTIOrjPJDWMTOrIZDOgskYJ97xsZIBRjbBjKLsRdrXXai1eTiNJZQWllG+uAKlUkdA1MHSs/9AMmjPRxJOsSCoNm2QfARecxDKuojmCkhaZaScs4ibJYRIX3PHkVdt8IoNbjSQDiKs/gMZSphOJxVMREVMRERMxSVMJWRMxjI0J/FMOgtBdcBKJnyc/JcdffbwB0SPsF1GwC2jeeceWh/3sLWz6+Hde2zvfsCrty209j6hcWUVpxMKeMWCj3yiuksLljyT0FdtcJKJeOkcuPkFvNx+gyP8wvd+n+LH4SF+Dgb42vsC4Deu3b6LUzGJyuMj7MKag6DkORckLoo6AimVMmTrDTx5vYXe0QC9Thfd9gEO9vfxudNBt93Gt34fqzfWMcknPYaCYiGSdamGvFFApHIe4VKNIlG/gNjyChavr+Hm00007z/ErecvsLHTQvPBBtYePcb6s03kL1+FUJyDYBS9J4c0m4rPZV0ITgWCW4HglBEiuVXCjO7AL+UomHwF8cVL8KezmJYN+DM6mFwekXwVnOZ4Lo+MIC5xZDCpJQO8bNEeiYJij8FljOP18Ax1mR2tjWJSUWNmCVHDQzo/h4RVoXmM9oqYdatIuVWaj86RO2Kh5pkyXpMh0yAxZgiBLqzp1ZLXoxKp9rGzRH8iG1nsP0mxthiozbGiAAAAAElFTkSuQmCC&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Metrics in Aria Hub chart&quot; title=&quot;Metrics in Aria Hub chart&quot; src=&quot;/static/667812b2ad0ec3db1e45fa0953c2defa/e42f2/Screenshot_20221228_103523.png&quot; srcSet=&quot;/static/667812b2ad0ec3db1e45fa0953c2defa/e42f2/Screenshot_20221228_103523.png 734w&quot; sizes=&quot;(max-width: 734px) 100vw, 734px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Metrics in Aria Hub chart&lt;/figcaption&gt;
  &lt;/figure&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style=&quot;width:50%&quot;&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:637px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:54.94505494505494%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAALCAYAAAB/Ca1DAAAACXBIWXMAAA7DAAAOwwHHb6hkAAABIUlEQVQoz4WT646FIAyEff933GT94R0VRQGvs5keNehJVpIv1FKHKWi0rivItm039n3HPM/QWqOua/R9/1UTQo1lWRAx8N5fIiHMTdMk6xR/rj9rL0Hn3MMdF1cs6wbg/tKby5vDE4qkykKbSeI3oS9BOgztc/xmI0a3SPxfqye3M6Tg53I2gS3/JAbGzp/2j7wgZ/XikAfP9irtoQ6q1t+ftUfROJnL1qJsrMxFY1Fri2me5eJE0Fp7tBpyjp09S2TtiDiOkSQJyqKAqirUSkEphYLPSiGiVbbMi+EudHvig5i7W+fQNA26roMxRuh7I98oNWhMHLKIu2ZZhjRNrzmEOdbkeX7LMzcMw3UxEVXbtpU/gpzxM0e48RO6PcUo+AcoJ1j6aXfnpwAAAABJRU5ErkJggg==&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Metrics in Excel chart&quot; title=&quot;Metrics in Excel chart&quot; src=&quot;/static/46dcefc0f4ec3406e810e4ddd7bb2f5d/90cda/Screenshot_20221228_103844.png&quot; srcSet=&quot;/static/46dcefc0f4ec3406e810e4ddd7bb2f5d/90cda/Screenshot_20221228_103844.png 637w&quot; sizes=&quot;(max-width: 637px) 100vw, 637px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Metrics in Excel chart&lt;/figcaption&gt;
  &lt;/figure&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;/tr&gt;&lt;/table&gt;&lt;h2 id=&quot;exploring-queries-with-web-browser-developer-tools&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#exploring-queries-with-web-browser-developer-tools&quot; aria-label=&quot;exploring queries with web browser developer tools permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Exploring Queries with Web Browser Developer Tools&lt;/h2&gt;&lt;p&gt;Developer Tools within your web browser are a great way to find the queries being used to generate the graphics within the UI. Once you have Developer Tools open you need to find the relevant GraphQL query, in my case it was the one with &lt;code class=&quot;language-text&quot;&gt;operationName: &amp;quot;entityDetails&amp;quot;&lt;/code&gt;.&lt;/p&gt;&lt;p&gt;This particular query shows the relationships as well as all of the information for the selected entity. With the query selected in Developer Tools, right click on the query field and press Copy Value for get the GraphQL query data. Do the same for the Variables entry. &lt;/p&gt;&lt;p&gt;The outputs from both of these can be used in Altair or other tools. &lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:3440px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:37.52%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAICAYAAAD5nd/tAAAACXBIWXMAAA7EAAAOxAGVKw4bAAABUklEQVQoz22R646bMBBGeYwmEHwhgG0MxlxCiNJt3/+lTmW2yqbV/jiyPZbPaD5nhYskzm1PbgI/av8tuZuQ8YEPkRgn5nlmntJ+/GQcmWIkE8NGOdwoupnCL+Td/CLVzm5CxZ3m9otyfHB/PFmXjW7aMcOC72f6fqLtJyoXyU5t4Gzjt5xsJDcjsl9RqbFf+f38SWc7ZGVQV4NUDcu6sz0+KFVDdjbjMc67KLeR0kaUjci0ugndLVy7hRAiuqoRQiNlRSkU1nm8HxBSfwnTeJd+pd8+CMsTmc6pUco33fv14KLqQyTV9YU4xPrYH8KLX1DhThV39Hg/MtNxRw4bhZuPhpck8yulbo7HZZL8j9BfGZ7M+A+p0SuCv8KiW7BuoHceaxy2tZg3Ui0Tww0xbohwQ4Q7Inz++jspitzNqHFn8AFbXenqFqOvNAcVTVVjasMfYfXr9bgxW4cAAAAASUVORK5CYII=&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Web Browser Developer Tools to find GraphQL queries&quot; title=&quot;Web Browser Developer Tools to find GraphQL queries&quot; src=&quot;/static/25ac91b5c44abb95df910b89e7a87fbf/b70ed/Screenshot_20221228_110809_2.png&quot; srcSet=&quot;/static/25ac91b5c44abb95df910b89e7a87fbf/6482f/Screenshot_20221228_110809_2.png 2500w,/static/25ac91b5c44abb95df910b89e7a87fbf/b70ed/Screenshot_20221228_110809_2.png 3440w&quot; sizes=&quot;(max-width: 3440px) 100vw, 3440px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Web Browser Developer Tools to find GraphQL queries&lt;/figcaption&gt;
  &lt;/figure&gt;&lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:2115px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:48.08510638297873%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAKCAYAAAC0VX7mAAAACXBIWXMAAA7DAAAOwwHHb6hkAAABYElEQVQoz3WS3XKDIBCFfaK2agwRQUEUAX/SpL3oRWf6/k9xOoDmt704s8sM+7Fnl+T4c0StOlCukO0r5Kuygob4lpeo2x7n7y8IPYO3Bry1qFuD+hINGhXz5GWvkBF2gWzawOmuBG86aPsOpk/ozAxrDFRvoXqDrrcXmI9JTiVywlGQCkVZgZRVyK8dHtBIDTudwNQE42aM1kB2FkLFeAfMqEKA7ilyUmF3Y3sD+kI3n8HVCKlnMGnA5NVugK0xSUmD9CCQFyVyQrEjFAWhSFfrrxmBUAPG5QOsdRDuE7MzmJ0NdoNtHTv1M014O4A3LXgjwWqJRsRIKokDkyBUgEuN3ixhIa09YQowA6Gi7UZtS7FIROfiPFZtub/wKF8g9BSB2j5t24OT2zn8Jw/zD0fgAmdd6NCft+4uHcaDedLt34rAWOCXMjmHYXgGhi3/Ze3e5gNwWDC6cX30/o4H/gJJr2CjsEeb/AAAAABJRU5ErkJggg==&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Altair query with Developer Tools information&quot; title=&quot;Altair query with Developer Tools information&quot; src=&quot;/static/09ac711b2079792c29f6dc8c741de7c2/17cef/Screenshot_20221228_161011.png&quot; srcSet=&quot;/static/09ac711b2079792c29f6dc8c741de7c2/17cef/Screenshot_20221228_161011.png 2115w&quot; sizes=&quot;(max-width: 2115px) 100vw, 2115px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Altair query with Developer Tools information&lt;/figcaption&gt;
  &lt;/figure&gt;&lt;/p&gt;&lt;h3 id=&quot;rest-api&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#rest-api&quot; aria-label=&quot;rest api permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;REST API&lt;/h3&gt;&lt;p&gt;When it comes to real world use it is unlikely you will spend all of your time within Altair, so lets explore how we can use a tool such as Postman to get the same information back via REST API. &lt;/p&gt;&lt;p&gt;First we need to setup Postman&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Set the Authorization header to Bearer Token and paste in our token value. &lt;/li&gt;&lt;li&gt;Setup the payload Body&lt;/li&gt;&lt;li&gt;Use Postman Pre-request scripts to convert our raw GraphQL query to a JSON string &lt;/li&gt;&lt;li&gt;Request Method: &lt;strong&gt;POST&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;API Endpoint: &lt;a href=&quot;https://api.mgmt.cloud.vmware.com/aria/graphql&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://api.mgmt.cloud.vmware.com/aria/graphql&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1314px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:18.72146118721461%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAECAYAAACOXx+WAAAACXBIWXMAAA7DAAAOwwHHb6hkAAAAo0lEQVQY03XN3QnDMAwE4KzRp9iWf6QklgmJt+gIHaTjdNMrdklKCn34kEDHadCcUfcd27Z1tVYUVaSUwMxd2/9iQaIR5v7E7fHCUGaBcAQLI6SIGCPmZUbidJYR0ZUnhBDgvf+KApIVQ0gClhlFC6Zp6sFjHuG2i8ipPbmUtYwnkDMYZFkROMNa2wXvQc5hHEcYY/pshaoKzYpSPo/b7Zd1Dm/kzXUcXhmsiQAAAABJRU5ErkJggg==&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Set Authorization to Bearer Token&quot; title=&quot;Set Authorization to Bearer Token&quot; src=&quot;/static/b7f34759ab503b1eb1d0603ceb3be023/b49e7/Screenshot_20221228_121345.png&quot; srcSet=&quot;/static/b7f34759ab503b1eb1d0603ceb3be023/b49e7/Screenshot_20221228_121345.png 1314w&quot; sizes=&quot;(max-width: 1314px) 100vw, 1314px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Set Authorization to Bearer Token&lt;/figcaption&gt;
  &lt;/figure&gt;
&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1285px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:14.396887159533076%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAADCAYAAACTWi8uAAAACXBIWXMAAA7DAAAOwwHHb6hkAAAAYElEQVQI15WOSQqAMBAE85RktizGQCSg4P/f1UJAr+qhqEtTtMuto60rqgmSCogIRGE6hPAbV8eBbT8xloheEmpUFBNkEzARvPefmUFLGZrKDBTT+TIKQ5lhws/wjTt4AR/sVK3PwPpmAAAAAElFTkSuQmCC&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Set Payload Body&quot; title=&quot;Set Payload Body&quot; src=&quot;/static/7cd76fe78a24bb8203fd86fae4731847/49304/Screenshot_20221228_135706.png&quot; srcSet=&quot;/static/7cd76fe78a24bb8203fd86fae4731847/49304/Screenshot_20221228_135706.png 1285w&quot; sizes=&quot;(max-width: 1285px) 100vw, 1285px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Set Payload Body&lt;/figcaption&gt;
  &lt;/figure&gt;
&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1261px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:58.84218873909596%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAMCAYAAABiDJ37AAAACXBIWXMAAA7DAAAOwwHHb6hkAAAA3UlEQVQoz6WSW07DMBBFvRLsmfE8LGgJ5SEk2P+2LoqjoLQJpYGPK0uWdXTPeJK54fNjwGkImAkiBO6CuBJTRikEonUSs2A4Kp4G67DxspTya4i27ghJpPZmr89Tw1tgS8Ccb2CtFcyMl5OjLXXjurZ27bIGqo5AwsN97RHZns1WfgBqh+RcdunOgMszuSvcGLVOofHxfxq2Znh/a30us+7lwPfAU4RheLSufJfXKruBZorjYdSefrjK+dLeCl4AK1owhKkrMxXknHv2tD1r6B5Qs77YZA5tDRH+p4ZfRk5PrZoNZtsAAAAASUVORK5CYII=&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Set Pre-Request Script&quot; title=&quot;Set Pre-Request Script&quot; src=&quot;/static/315105b530be41a4232913ce566dbd63/05ccf/Screenshot_20221228_135646.png&quot; srcSet=&quot;/static/315105b530be41a4232913ce566dbd63/05ccf/Screenshot_20221228_135646.png 1261w&quot; sizes=&quot;(max-width: 1261px) 100vw, 1261px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Set Pre-Request Script&lt;/figcaption&gt;
  &lt;/figure&gt;
&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1277px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:73.21848081440876%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAPCAYAAADkmO9VAAAACXBIWXMAAA7DAAAOwwHHb6hkAAABJUlEQVQ4y6WSa3KDMAyEOUnBlvyQzCMlyfT+J9uOjdMhk0Kd6Y9vQGNYr1bqmBkuKryOsMag73sMwwBjzCFn5521FsQMvVyRPu9wUX5+OmJ//iJIRNsH/QdkWZGWtdTZrbX1WaFanzp8CGanZuih6xemy4qrBtxGQXQMz1TI747oXJB5J2gMwjhDxwnqXXG4b7VvaXkvWPIkArkAx3TYXrPDLOCjIKa5tKeenwT+mv6vDjM+KlLwmKIH1YtaxKogv7TsJWGMAVIH4si2Cz6mbOqa5AvYh9LyftFb6ZxzZbG5EkQLWTA43oZEBNtIJyKIO3I9r3cs6w2aEkKICLGd4rDkR1t+2eVWE0zdzXcoQ9kCz8FvmT0zvEWnGpFSgIqHiC/P//ANiv6mT1WExA4AAAAASUVORK5CYII=&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Returned Data&quot; title=&quot;Returned Data&quot; src=&quot;/static/7bd0430961e64894ff3b5b10a85486b6/18380/Screenshot_20221228_143004.png&quot; srcSet=&quot;/static/7bd0430961e64894ff3b5b10a85486b6/18380/Screenshot_20221228_143004.png 1277w&quot; sizes=&quot;(max-width: 1277px) 100vw, 1277px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Returned Data&lt;/figcaption&gt;
  &lt;/figure&gt;&lt;/p&gt;&lt;h1 id=&quot;closing&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#closing&quot; aria-label=&quot;closing permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Closing&lt;/h1&gt;&lt;p&gt;This brings us to the end of this post, its been a long one. The Aria Hub Free Tier is limited to two Cloud Accounts, Azure and AWS. With the paid for version you can integrate additional clouds and data sources, such as Aria Automation and Aria Operations - with data from these sources your queries will become a lot more powerful. &lt;/p&gt;&lt;h1 id=&quot;resources&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#resources&quot; aria-label=&quot;resources permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Resources&lt;/h1&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;https://api.mgmt.cloud.vmware.com/aria/docs/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;Graphql schema documentation&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://graphql.org/learn/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;Introduction to GraphQL&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://docs.vmware.com/en/VMware-Aria-Hub/SaaS/Using-and-Managing-VMware-Aria-Hub/GUID-35EC1BE2-78E8-4BE3-92B9-98D08A37D75B.html&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;VMware Aria Graph search query construction in VMware Aria Hub&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://blogs.vmware.com/management/2022/08/project-ensemble-preview-api-first-approach.html&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;VMware Aria Graph: API First Approach&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</content:encoded><tags>vmware,aria,aria-automation,aria-hub</tags><featuredImage>https://samperrin.com/static/535bfc2d1fec8e70849dec45f66ab62b/hero.png</featuredImage></item><item><title><![CDATA[Getting started with Aria Hub Free Tier]]></title><description><![CDATA[A short article covering the setup of a new account with Aria Hub Free Tier and basics of exploring our discovered Inventory]]></description><link>https://samperrin.com/posts/getting-started-with-aria-hub-free-tier/</link><guid isPermaLink="false">https://samperrin.com/posts/getting-started-with-aria-hub-free-tier/</guid><category><![CDATA[vmware]]></category><category><![CDATA[aria]]></category><category><![CDATA[aria-automation]]></category><category><![CDATA[aria-hub]]></category><pubDate>Thu, 22 Dec 2022 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;The free tier of VMware Aria Hub was accounced VMware Explore back in November and I recently got access. This blog post covers the three  steps required to get an AWS account connected and explores how we can start to query the inventory data. &lt;/p&gt;&lt;p&gt;The free tier allows you to connect up to two public cloud accounts from either Azure or AWS and there is no reliance on other VMware products or services, so this allows you to sign-up and experience how &lt;code class=&quot;language-text&quot;&gt;VMware Aria Hub powered by VMware Aria Graph&lt;/code&gt; can simplify the complexity of multi-cloud management. &lt;/p&gt;&lt;h1 id=&quot;data-source-setup&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#data-source-setup&quot; aria-label=&quot;data source setup permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Data Source Setup&lt;/h1&gt;&lt;p&gt;The very first step before we onboard our account is to access the service. Login to &lt;a href=&quot;https://console.cloud.vmware.com/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://console.cloud.vmware.com&lt;/a&gt; and launch the VMware Aria Hub service. &lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1363px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:46.07483492296405%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAJCAYAAAAywQxIAAAACXBIWXMAAA7DAAAOwwHHb6hkAAAA8UlEQVQoz41S227FMAjL///opHa9JIFAkk6eoE1XTWfTeXAvJoANCdu2Yp4nMBf03lFrRWvtLTAzMhFKKVBVR5iWFR/TJ4jID4iIF30HVsDOi+hPwXXfMS8LpBTvaiqHUq16Jw/eIHpy7XIzePsOWcVlm8LRxS31ji1F5JQRY7rV9NawEyOmBMoZOeeTv4oG+/EgkQdjjD4TC9pcRfVh8UwUKUhXzpjfcBGKKhIX6C9bPnRRSK04juOB7k2oyJ0zYm45MSPlUz4x31sec/wLrb3mgz34sXazUFvzjv9doVpf88ECrNWX8PWwdibV+/0uvgGuJr6Fx33woQAAAABJRU5ErkJggg==&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;VMware Cloud Services Portal - My Services&quot; title=&quot;VMware Cloud Services Portal - My Services&quot; src=&quot;/static/74de6fa68a611ce4e4d414d59035ac03/8093a/Screenshot_20221221_141000.png&quot; srcSet=&quot;/static/74de6fa68a611ce4e4d414d59035ac03/8093a/Screenshot_20221221_141000.png 1363w&quot; sizes=&quot;(max-width: 1363px) 100vw, 1363px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;VMware Cloud Services Portal - My Services&lt;/figcaption&gt;
  &lt;/figure&gt; &lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1827px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:59.660645867542414%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAMCAYAAABiDJ37AAAACXBIWXMAAA7EAAAOxAGVKw4bAAAC40lEQVQozx2Ry24bZQBG//E19tie+/0+vs3YsSvXjkNInMSNKKSiSVoR2kpQKQ0gRCVEhbqAFUKCNTvY8QA85EHu4lt8myMdHZGVE9y8RI9yVDdCdUJ0L6JrhzTtlF4ypu2mtDSHVlenacaoXkIeBLiWj2p4TIYpQZoi6y7CLHPkUYnspXSdkK7h0bMD9odD6sURr/7+j+tv3yLMnKbfR9cUPu3bfBKaHJoaT6YJf/x4Rc8JEbKO8EYF2WyGHfXxRjP8vMSOhyRRRnmw4eD2nuPXdxiXzylevuCwTHnsdvl52eXNwuXd8yNmp1tErU1V9xBWkGL5CV3DQXUCFCfCzgtkN8cJMvbXxyyOzzBHU1wn5iO7w+9bg3+/yPjhSMWYfYxQA4RURTQ6CM1LUGwf1faRNYs9xUA2PdpWTFOLOFuv2Sz32SymfH864M+TFv98d84vFyPkVgdh5FTrbYRUR4gKwvASvHSInw0x/ISe5dEzXeo9izibMB8kWKbOi7nMb+cyv756xLu7G3o9A9HQqVQaH2BSpYnUNhFWVhD1C6JB+QG801btgJrmEqdjtgOXN8s23yy6TEOT+y8veXRxgqRFVHs+oqEgVdtItQ6SEiOswS5EgRP3MYMU3Y1Q7ADNjHm57/F+3eHtsoOnqCzGJT99dc3500uqaoho6og9A1FpIqp7SLu/i+JnY5wwQ93p7mZHXM8z/rqQuZ928BWbzEt4slqxnkzY3N7iPb5BqAlSrUvD9BCijiSbCD0t8BanuA82OMUS3w/pZyl3hxpXuYytBAirTy2a0fDGtPSYdjBk/vk12uwM0TCoxhOqeoBQY4Q5WROdXRGfXREdbBmGDmXqsE1VblIV1U2R8jm1xWeIyZbKcIWdzCn3l6yePkMUG3qzLaJtITU1RNtO2FNMDN1k5JuMI5fM9xjpLQwvpB4XNNIp4XSJcniNOLxBHixJV6eMHz6g/+w12dfvacy2DB+e8D8E9U9mmI7joQAAAABJRU5ErkJggg==&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;VMware Aria Hub Welcome screen&quot; title=&quot;VMware Aria Hub Welcome screen&quot; src=&quot;/static/1ea899fc49bf0384b28710c217401c71/6320d/Screenshot_20221221_141025.png&quot; srcSet=&quot;/static/1ea899fc49bf0384b28710c217401c71/6320d/Screenshot_20221221_141025.png 1827w&quot; sizes=&quot;(max-width: 1827px) 100vw, 1827px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;VMware Aria Hub Welcome screen&lt;/figcaption&gt;
  &lt;/figure&gt; &lt;/p&gt;&lt;p&gt;Select your data source, in this post we will be using AWS. &lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:875px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:58.51428571428572%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAMCAYAAABiDJ37AAAACXBIWXMAAA7DAAAOwwHHb6hkAAABTklEQVQoz52T207DMAyG+xAMCdiWtivrDtrWc9o0KVoZY0wCJK54Al6Fx/5R3HbswKFw8cmOrf61Y8dweYFhIuEminBCgd4sOmQeVxzH92AexxlzYCT3z4jXT4jJPmKc38IMc9hRDitsj8NvcG6PYNiRhB1khBkIMD8lezkXZNtiRRIdawjD9Dmu+Bpdvoblc3Q9gVnK8f42gRNy9H1BFdBH31Snc3ak0LFcGE6iMCq2cIst7FD/ScErSry+SExlCd3BT2IngnSoW2ZeCtPPYAU5LhaSrBlkv97fiSDzM8KsYSSaVrGWd7gTpKG0oKmm8Y9zdlwLTtUdRqKEmy1pZbSv7ViUn34Tr88TjVxhLLS/otwgKaopL5YPmMoqeDrNL4axn9f+QctD3bLCIFZU8l8WeUck4agNrtWmWuz+PEFvVj2t/r9IwHSVoaSn9wHNHHVwilz1vQAAAABJRU5ErkJggg==&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Create Data Source popup window&quot; title=&quot;Create Data Source popup window&quot; src=&quot;/static/3731d22768716a71d1d102ba099fe871/8b7fc/Screenshot_20221221_141052.png&quot; srcSet=&quot;/static/3731d22768716a71d1d102ba099fe871/8b7fc/Screenshot_20221221_141052.png 875w&quot; sizes=&quot;(max-width: 875px) 100vw, 875px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Create Data Source popup window&lt;/figcaption&gt;
  &lt;/figure&gt; &lt;/p&gt;&lt;p&gt;Provide a name and the AWS Account ID that you are connecting to.&lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1718px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:44.528521536670546%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAJCAYAAAAywQxIAAAACXBIWXMAAA7EAAAOxAGVKw4bAAABEUlEQVQoz6XR2W6CUBSF4fMerQNUkUHBHjjKqIBtIiBiL9r3f5O/KTY2bdJU04sve0rWzRb7psApTsjdETc/MAl3aEGOroqbacEWMcs7gvoNuX9lvjvhlB12cbxRi112mNsDwk8l3dGhbRe0B4eqsqgqk7q2ek1t03z2P33tbZrKYL72EHac45fPLLcldpyyzEu8TY4VJVhRihnGmOtfhPG3u+5HiAe1YRqWjGTCaBkxmCtGXsjAXTH0wvP+8QoyYSxjxESlGKusHzQZMXaDvupBih4kaH6C1t/+4MfnQKNomT29oPUBKdP1x4eziz7wWjJBaEGGEZXoMmawUGfu6mJ4IzFcKAw/YaYy7m3J3T+9A0+oHw6ZwJSrAAAAAElFTkSuQmCC&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Add AWS Data Source - Account Information step&quot; title=&quot;Add AWS Data Source - Account Information step&quot; src=&quot;/static/27e9edf648c7fb54856c66280865908e/954d4/Screenshot_20221221_141611.png&quot; srcSet=&quot;/static/27e9edf648c7fb54856c66280865908e/954d4/Screenshot_20221221_141611.png 1718w&quot; sizes=&quot;(max-width: 1718px) 100vw, 1718px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Add AWS Data Source - Account Information step&lt;/figcaption&gt;
  &lt;/figure&gt; &lt;/p&gt;&lt;p&gt;Step 2 includes some steps to configure an IAM Role that will allow VMware Aria Hub to connect to our AWS account. &lt;/p&gt;&lt;p&gt;If you click the &lt;code class=&quot;language-text&quot;&gt;CREATE AWS IAM ROLE FOR VMWARE ARIA&lt;/code&gt; button it will open in a new window and auto populate the Account ID and External ID. The Account ID that is provided in this step is an external account.  &lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1720px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:44.53488372093023%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAJCAYAAAAywQxIAAAACXBIWXMAAA7DAAAOwwHHb6hkAAABF0lEQVQoz53P3W6CQBCGYW7DpsYfhEVUEARBfhbQikhjD+r9X8vbLCQeGLVND55kM9/O7I72sXfRNxJ7myGClKHtMRAOA+E+4DzRZ2+Wi2bIM359xauvzJIGMztjZu2dviae6LK8xUwbtEXR4tffOIcvRNYgcuXcsRSptN25zx7I+h4zrdH0MGdZNCzkiXleM08PWLsKEZcYW4keZMzCnGmQMlrHjLwX1jGaEZUEzRVnf8EuWuz8hHpkskkZ+0pyo2qvqDvabCtZyVP3IzMqMeMSVZsGWee+4ZnbQGNbIHYVIz9BDyXL/NgNNeMKld0GbZK/DbSSivB4ITx+siob9Kj8dbWXK0+8HXZcskgqxm7E+zJkuPq/HzOsHMIAzmU5AAAAAElFTkSuQmCC&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Add AWS Data Source - Connect Account step&quot; title=&quot;Add AWS Data Source - Connect Account step&quot; src=&quot;/static/52b3ef1c0f51a7a49a7b9f996224a82a/92aea/Screenshot_20221221_141635.png&quot; srcSet=&quot;/static/52b3ef1c0f51a7a49a7b9f996224a82a/92aea/Screenshot_20221221_141635.png 1720w&quot; sizes=&quot;(max-width: 1720px) 100vw, 1720px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Add AWS Data Source - Connect Account step&lt;/figcaption&gt;
  &lt;/figure&gt; &lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:977px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:103.58239508700102%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAVCAYAAABG1c6oAAAACXBIWXMAAA7DAAAOwwHHb6hkAAACYUlEQVQ4y51V23KbMBDlx/vSz+g/dKZ/0E4f+9pM2yR2bGxDgjESQlcQ+HR2bbDjXMYTzRwkFu3R7llJJMYYNFrDWoux7fmxx36/5/7wup8wHG036wY//+7Yo+si+r5HIoQAoVaK+6qq0HqH87Y/EoxtGAYmse0AaeM0h+yJlAK7soQQEm0IMC7gJrOY5TVmmcBdJpAJB5pXbkteNMbIkKJCoyT7SinZlmRZxlGppkHwHsa3+HGr8DuV+LeRuFlJzJ4sHh9zlGWJhuaFwM6bzYaJlFJsZ0KtNRrdQDeaPxCM0VAN2Q1siNAu4rJdyjDaOOW6ppBryJpWq1HudqiqHYSoELuO9Yqx4wjOizMVaRgYTHi5yjD0kKRn28JYC8qAiJzznCo5UjVHDP3wPMLL1ajRVrLOwzrHYyLV3B/HR5Bu9H0kf0F4rg2lmucZ1us1i59tMlAB8zzHarU62LLTd6o+ZZBcijoStm3AcrnE4mGBxWKB5TLF/GGJNE2xSlOsV2smIzv1tJD3/qWGU4QxHojSlLdVVQmUokGtNJyzrC+dLmNPY9L9TULSpJbV4eS0LS9A+9Q5N8E7C28NnDWwRr9M+bmGAf7pD3xxC7+dwRd3cMU9XHHHY1/cwxQLmG0KX85hxeP7hH3seJKpclj5hKAKeLXlPtT0voWUClIZBGc54jdTHuFDi0Zb+NBNt9A5zm+n0Sd55fy8erSmq+wMp11xmvtmhJfRXovkI05XEX6kndxOyiavFeNaEAH9DkIEfATaHkho447/k/EKugZ9P8D4iF9zhU9f5/j8bY4v3zP8B8CqYvtljBqrAAAAAElFTkSuQmCC&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;AWS IAM Role creation&quot; title=&quot;AWS IAM Role creation&quot; src=&quot;/static/faa5c0882f48ffc382cfd0293ea332b5/8cd91/Screenshot_20221221_141731.png&quot; srcSet=&quot;/static/faa5c0882f48ffc382cfd0293ea332b5/8cd91/Screenshot_20221221_141731.png 977w&quot; sizes=&quot;(max-width: 977px) 100vw, 977px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;AWS IAM Role creation&lt;/figcaption&gt;
  &lt;/figure&gt; &lt;/p&gt;&lt;p&gt;We need to specifically attach the SecurityAudit policy to our new role. &lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:987px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:34.04255319148936%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAHCAYAAAAIy204AAAACXBIWXMAAA7DAAAOwwHHb6hkAAABB0lEQVQoz5WPSW7DMAxFff8T9RpFF20cpBk8T4o8W5KlV1hGW2RTpAQeRFIk/mfQti1936OUZgvnHM/EPud4eS25ViOwsq4rQdM0CCGoqoq6bthqrbX/tNb+ibMWOWpmZXDOepFAiIZWSoZhYBxHzzRNKKX+5XgT2IwEp88rWV5ijPENbQyrtd7h1vtmE3hEo7RmXhamafZXSikJ3k8Rx3NEHN3Is5SyLOha+UPftci7IE1i0iTZSRM/H8f7Xng4cAwPNE1NEKU5YfjB2+HCJamI85pbWnHLHonyeieriYuG8BwRnmOfJ4Xwr2h7AjkquqGn6Az3cWVQjv4Junn9rRdLt1gW4/gCEh8auDAvtOIAAAAASUVORK5CYII=&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;AWS IAM Role creation - attach policies screen&quot; title=&quot;AWS IAM Role creation - attach policies screen&quot; src=&quot;/static/2360313ac4d0fa2abc5793777eb15483/b2a21/Screenshot_20221221_141752.png&quot; srcSet=&quot;/static/2360313ac4d0fa2abc5793777eb15483/b2a21/Screenshot_20221221_141752.png 987w&quot; sizes=&quot;(max-width: 987px) 100vw, 987px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;AWS IAM Role creation - attach policies screen&lt;/figcaption&gt;
  &lt;/figure&gt; &lt;/p&gt;&lt;p&gt;No tags are required, but add them if your organisation uses them. &lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:981px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:29.76554536187564%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAGCAYAAADDl76dAAAACXBIWXMAAA7DAAAOwwHHb6hkAAAAw0lEQVQY04VQ0YrEIAz0/3/pPuPel7702q2lGpWqpTrHBMrCLr0LDBNjHCcxKSWEEEBurQHo6P1/ME7tb3g8E76+rb41zjls2wayiOA+boR7R64nXDo0N3R3iW7OwXuPFCMu5+I9JEQ4Sci5oJSCnLOi1qp81IJ2HjqhWZYF1lrFlU/TD4ZhwDiOWNcVVsEpvH74Dk42z7P2GjpjQjcxRmXWKE5WlyIIIsqXwHvOXp4NR2CBYvu+f26Ou9IN/rHd/rr9Bddr0MR3FOeeAAAAAElFTkSuQmCC&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;AWS IAM Role creation - add tags screen&quot; title=&quot;AWS IAM Role creation - add tags screen&quot; src=&quot;/static/ec220db213915aafd00ab8450c58f516/fea73/Screenshot_20221221_141807.png&quot; srcSet=&quot;/static/ec220db213915aafd00ab8450c58f516/fea73/Screenshot_20221221_141807.png 981w&quot; sizes=&quot;(max-width: 981px) 100vw, 981px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;AWS IAM Role creation - add tags screen&lt;/figcaption&gt;
  &lt;/figure&gt; &lt;/p&gt;&lt;p&gt;Provide a name for your new role, I have used &lt;code class=&quot;language-text&quot;&gt;VMwareAriaHub&lt;/code&gt;. Make not of this role name as you will need it in a later step. &lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:965px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:55.95854922279793%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAALCAYAAAB/Ca1DAAAACXBIWXMAAA7DAAAOwwHHb6hkAAABFElEQVQoz4VSWW7FIAzk/kfpSXqSfkTZALMvU9l5eUponmppwBgz2APKGANGCAH/We/9jXNdSkFl1Iqv7x+oeZ6xLAtijEJ6BcfOOB+8EjJaazcAHSrnjPQ6dBJM04Rt27Guq/jW2qOSWt84q7x3AKgxyBd475FSEim01kLIPhHJHs8p5T8yMNQY4EqN1jIz6bX9saonCdSYcK82IZeCUqpUzqQiUUqCkZClUNeb2DiRyCKmDHJBfGsNnHOyx1oyKePp5dUYKCVjWVaYbUKkBbuNMOTl9qdvNK4fWy61IXuNFneE3JFKe9Rs7O5WIRu/IP/Jfd9AzsP5AEd0wDm0C8knU5zI34Ccw5nHcz+Gl/+5zZHwF8h4Yd4i5QObAAAAAElFTkSuQmCC&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;AWS IAM Role creation - review screen&quot; title=&quot;AWS IAM Role creation - review screen&quot; src=&quot;/static/40c93aaa82d70559214152f3a32964cd/e7a62/Screenshot_20221221_141923.png&quot; srcSet=&quot;/static/40c93aaa82d70559214152f3a32964cd/e7a62/Screenshot_20221221_141923.png 965w&quot; sizes=&quot;(max-width: 965px) 100vw, 965px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;AWS IAM Role creation - review screen&lt;/figcaption&gt;
  &lt;/figure&gt; &lt;/p&gt;&lt;p&gt;Once the role has been created, select it and make note of the &lt;code class=&quot;language-text&quot;&gt;ARN&lt;/code&gt;. &lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1489px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:59.63734049697784%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAMCAYAAABiDJ37AAAACXBIWXMAAA7EAAAOxAGVKw4bAAABaUlEQVQoz5VTWa6CQBCc+9/AQ2j00z+v4IceABeYGZBVYFisl2ocQ3hL8jqpAL1U13QPynU96sahrht0XQfa6/X6N5xzaFsHVVUVoihCkiRwM8LfbEk091OQEOZ5Lo5xHD+JfB+GQWL3+11QFMW3BnVdwxiD6/UKay0UpfrjksQbyeg7Ho/Y7XbYbrc4n88SO51O2O/3OBwOWK1WWK/X2Gw2kqucazF07kPiVfZ9L92Xx+f38/nE4/FAmqaSMzdFMldlmJTWoopomkk1ixmbN1vafFSqbVsYa2UpeVHKYqiOBBOmWdLnm5VlKQo5f682jmOQS1GV1loGa9/ETOAylqDfFzN3/oy0lhxZitYhLpcASZohz7JPoS++3W5ytVjMuXmweRAECMNQ4lSsOKvo7YgiDWNjOZIHk3hd2N1/L8E4IfeQhL6DMVoUsdgnzcF5LcGREX55isOmfB6PzulqjD/+XtzmX+CWvwDSCZxPUMgXMwAAAABJRU5ErkJggg==&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;AWS IAM Role summary screen&quot; title=&quot;AWS IAM Role summary screen&quot; src=&quot;/static/0e44007e26cda22b1a50be717d27eece/bf9c5/Screenshot_20221221_141956.png&quot; srcSet=&quot;/static/0e44007e26cda22b1a50be717d27eece/bf9c5/Screenshot_20221221_141956.png 1489w&quot; sizes=&quot;(max-width: 1489px) 100vw, 1489px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;AWS IAM Role summary screen&lt;/figcaption&gt;
  &lt;/figure&gt; &lt;/p&gt;&lt;p&gt;Paste the &lt;code class=&quot;language-text&quot;&gt;ARN&lt;/code&gt; value into the IAM Role ARN field in the Aria Hub portal. The External ID value should match the one you used when creating the IAM Role. &lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1720px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:44.70930232558139%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAJCAYAAAAywQxIAAAACXBIWXMAAA7EAAAOxAGVKw4bAAABGElEQVQoz53Q6U7CQBSG4V6GJpK2tKULQvdCd2Rpi5jg9l/v/yZe00JQVJD448nJzDnzTWaEajFG8XOsKEMPUnqWy9VgxLU+/gcbQcsrnOVTR4krtKRGS5td/a7dP2HQ1rhCGJYb/OYVZ/WIUdzvbTpmeeyz/5sNetYgKEHGsKgZ5hVmtsJMFxjxHfp0hhYVtH01zOn7KaIzQXSmZ0wQ1KjEq58ZzR8wijVGtkKNCuQgQ/ZTJC/ZS7v1Oe2coIYF9myNkcwx4jlmskD2ku5GyYt/HDjlS2COPikR7QgtzHFmDZIdIo1DZHf6Z9DBITCrMbfvmNs39OoFJSrpt3/W2j/7Ym2g5CYY6RIrrxDdhJvb4EjvQrvZkA+AbxxkaZJU4gAAAABJRU5ErkJggg==&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Add AWS Data Source - Connect Account step with ARN&quot; title=&quot;Add AWS Data Source - Connect Account step with ARN&quot; src=&quot;/static/4470b97a4baab1acd7de1ce871bc1152/92aea/Screenshot_20221221_142031.png&quot; srcSet=&quot;/static/4470b97a4baab1acd7de1ce871bc1152/92aea/Screenshot_20221221_142031.png 1720w&quot; sizes=&quot;(max-width: 1720px) 100vw, 1720px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Add AWS Data Source - Connect Account step with ARN&lt;/figcaption&gt;
  &lt;/figure&gt; &lt;/p&gt;&lt;p&gt;This is the final step for onboarding our account and it is asking us for a couple of things&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Enable CloudTrail in AWS for event monitoring purposes (we wont cover this step, but find CloudTrail and follow the steps to enable). &lt;/li&gt;&lt;li&gt;Run a script to configure an Event Stream stack that utilises CloudFormation. &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1719px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:49.1564863292612%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAKCAYAAAC0VX7mAAAACXBIWXMAAA7EAAAOxAGVKw4bAAABdUlEQVQoz6XM3XKaQByGce6hnanGOoER1CoYWVgFXL6MqaJU0H5dQhs7yf2fPZ0Sk3bamRykB7953v8erBanPpbMGQcpAxnTtX06I/FiWld4DGcJlq9oD6f/9Vln5KFNbmr87Ve84gv29eHlVgdGeYVmBisGase7pESXK7re8slbkf9l+SzdT9FmmeTzJ8HxKKjrK+pq0nS/n1CWY8rSbux2Y4qNRbExz33cJpuNxa7oMY1ctHGkiG5yglWGzGOmaYyzmOOEPpNQ4oTyXB878LAD8cQJPJzQazoJBZY/R+tmNRcf72nXJ9qHH1wc75q29t9pVbf/aFcnWtWp6Zvqltflt8ar/YmOKtF684xhtsVKdwzyD+iewpApo7xkkBT0481vyZ9dN9tSa0z1HlOtMWSCZoZL+tE1llT0ZwnGdE5PhM02pTqLsX6ZxQ+3fyZV897zFhhuiCEiNCsrMZMtl1dzLt0IXSzQRYTuhg995J6JZ7ghPwFQMUTQCjDLCgAAAABJRU5ErkJggg==&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Add AWS Data Source - Account Onboarding&quot; title=&quot;Add AWS Data Source - Account Onboarding&quot; src=&quot;/static/2a889a3af1bcb3456ea8b6f2109ef7be/11e42/Screenshot_20221221_142046.png&quot; srcSet=&quot;/static/2a889a3af1bcb3456ea8b6f2109ef7be/11e42/Screenshot_20221221_142046.png 1719w&quot; sizes=&quot;(max-width: 1719px) 100vw, 1719px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Add AWS Data Source - Account Onboarding&lt;/figcaption&gt;
  &lt;/figure&gt; &lt;/p&gt;&lt;p&gt;Press the link &lt;code class=&quot;language-text&quot;&gt;Connect Event Stream&lt;/code&gt; to download the .sh script. I then uploaded this to AWS CloudShell. From CloudShell I ran the command specifed: &lt;code class=&quot;language-text&quot;&gt;bash cloud_account_onboarding.sh &amp;lt;ACCOUNT_ID&amp;gt;,&amp;lt;AWS_IAM_ROLE_NAME&amp;gt;&lt;/code&gt;&lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1364px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:67.08211143695014%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAANCAYAAACpUE5eAAAACXBIWXMAAA7EAAAOxAGVKw4bAAABuElEQVQ4y4WTS5PaMBCEzY0TnODKcVObDQvmsTYF5lFhiddvS5Zk1ub//4tOzSQmoULMYUoq2fO5p1u2lFL4/KwgdIow8ZHECdI0xWG/x2KxwHa7xWrlYrlc/lP0/O+az+ewtNbIsgy+7yMKQ7iui9lsBsdxeL9arbBer7mBzmm9B6U9A40xoMplijD6QBCEOBwOOB6PvL69LTEYDOB5Hp9R4+vrBNPp9G6xwrq+INcx/PAdl+oCKQtUVQWyY7/fwbIsxHEMow1cx8FkMoFt23fLUsUvDzMVMbA6V8jzHOdzCSkldrstOp0OA+mcmkjJf4GksKpqZCq+AZZlCSEEPG+DbrfLHpPXziOFDKzrq0KjDISUkFKwKgpiPB5fA6G1VSH5RB42CgkoiwJFIRHHCezpn5cb49vG/g2sb4CNwiiKMLNtVkVjPoJdR25S/hEcOUmtNIqiYA+/vbxgNBrh9H7CZr1phd2EkusEJwaWKMsztFIM//L0hF6vh9KUHExbINdr04x8+vjOEGqmD9FKwH6/D0N/VJry39AeSqFYoTApj0zjam0gRM7X5OvzM4bDIUQuEAbBQ+BP1r7FWSvUMTgAAAAASUVORK5CYII=&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;cloud_account_onboarding script output&quot; title=&quot;cloud_account_onboarding script output&quot; src=&quot;/static/4410b4c4ae39471fa077b56c5ad5c4f8/46d5f/Screenshot_20221222_150126.png&quot; srcSet=&quot;/static/4410b4c4ae39471fa077b56c5ad5c4f8/46d5f/Screenshot_20221222_150126.png 1364w&quot; sizes=&quot;(max-width: 1364px) 100vw, 1364px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;cloud_account_onboarding script output&lt;/figcaption&gt;
  &lt;/figure&gt; &lt;/p&gt;&lt;p&gt;Within AWS we can see under CloudFormation the creation of a new Stack. &lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1531px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:16.394513389941213%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAADCAYAAACTWi8uAAAACXBIWXMAAA7DAAAOwwHHb6hkAAAAfElEQVQI112NSQ5DIQxDuf9ZWxLIAISFK0L7F11Yji3lubwqoXKDu8PHSI2vn278sl8XUagazP2RmoG5oYugiAiIOAF7b0QE5pyIvTOf28YEi0F6z6fTrYirtVJnRFRRzip3RVO/sLXwbgoSh8+FHGROP7BKhN7/oBHP7wdH6+h9/aUw1wAAAABJRU5ErkJggg==&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;cloudcoreo-events CloudFormation Stack - CREATE_IN_PROGRESS&quot; title=&quot;cloudcoreo-events CloudFormation Stack - CREATE_IN_PROGRESS&quot; src=&quot;/static/55aea0f6a5eee49495baa3457e5e5cf8/14af7/Screenshot_20221221_145924.png&quot; srcSet=&quot;/static/55aea0f6a5eee49495baa3457e5e5cf8/14af7/Screenshot_20221221_145924.png 1531w&quot; sizes=&quot;(max-width: 1531px) 100vw, 1531px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;cloudcoreo-events CloudFormation Stack - CREATE_IN_PROGRESS&lt;/figcaption&gt;
  &lt;/figure&gt; &lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1523px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:14.182534471437952%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAADCAYAAACTWi8uAAAACXBIWXMAAA7DAAAOwwHHb6hkAAAAeklEQVQI102Pyw5EIQhD/f9/HUW04GPRG5lxchdNaVJOIGlrHHNyjBGar/lmuNOOzHj6drM7YUbAmHNhVWX65EIz596ba61YOpC1dwCBzgpnbY0iQgDRu5o/DzjAJA3U/oWMOVi0UFqhuQW8iFBV2YG44ED/X710wMcficnou9m3NA8AAAAASUVORK5CYII=&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;cloudcoreo-events CloudFormation Stack - CREATE_COMPLETE&quot; title=&quot;cloudcoreo-events CloudFormation Stack - CREATE_COMPLETE&quot; src=&quot;/static/003ae242ab4440f9950e5cbc15600a51/15058/Screenshot_20221221_150420.png&quot; srcSet=&quot;/static/003ae242ab4440f9950e5cbc15600a51/15058/Screenshot_20221221_150420.png 1523w&quot; sizes=&quot;(max-width: 1523px) 100vw, 1523px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;cloudcoreo-events CloudFormation Stack - CREATE_COMPLETE&lt;/figcaption&gt;
  &lt;/figure&gt; &lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1193px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:58.25649622799665%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAMCAYAAABiDJ37AAAACXBIWXMAAA7DAAAOwwHHb6hkAAABjUlEQVQoz32Ti27DIAxF+/8fuqaPJLwM2ATuZLNs3VQNyYLi+PjauJfH44l1XUE5o/eOdhw4/rH2d2/N4jS+1oqLXqhzjIH/logghIiUCCHqnuB9MJDeO+ctwSWXYh9XZhS/okSHXCqYGYkIzIKs2ZkNpEGqSO08H1+/VdRlWW5Yt80CKNN38Gn8spuJmIBX06SaTKu9+BCgVkqxi2mC9hpgQRMo/HP+vhOB8x6iwE3V1Wog7cdtdfCpgKqWWkCUzSdf/pgiRFQpm097qaUr2HoYY5p0EfQ+cN3JrEizD0IIllBXbQUbPeHyBj7Y7s7H1N166L3HvjsLUqCLhD0SCgv6ccA5Zyp0Fcm4xwUrPQyurBP0AwzBgKZwDKwkeJLAlalwdw4xRgNmA17xTHcD4h1Qa9cHmSNw4L5c8bgtGH3Opiqf/o7WG4iTKdXzW4VngM3WGPjYE24+o7Y5W6VUU6+rdUHiiCxkwLc9VJi+5vzHdHx4bTyDeL6s+rUK7S83RqoJmQnS5NdQzwoHPgFqZ6olWjbxAQAAAABJRU5ErkJggg==&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;cloudcoreo-events CloudFormation Stack - Resources&quot; title=&quot;cloudcoreo-events CloudFormation Stack - Resources&quot; src=&quot;/static/85c2bcd6690f8918206bb71dc116a0b3/d054a/Screenshot_20221221_150513.png&quot; srcSet=&quot;/static/85c2bcd6690f8918206bb71dc116a0b3/d054a/Screenshot_20221221_150513.png 1193w&quot; sizes=&quot;(max-width: 1193px) 100vw, 1193px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;cloudcoreo-events CloudFormation Stack - Resources&lt;/figcaption&gt;
  &lt;/figure&gt; &lt;/p&gt;&lt;h1 id=&quot;explore-the-inventory&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#explore-the-inventory&quot; aria-label=&quot;explore the inventory permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Explore the inventory&lt;/h1&gt;&lt;p&gt;Now we have our data source connected we will start to see objects appear in our inventory. Aria Hub will start to pull in all types of inventory objects, including items that “out-of-the-box” from AWS themselevs, such as the IAM root user, EC2 network ACL’s etc. The objects are coming in from all AWS Regions. &lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1812px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:38.52097130242825%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAICAYAAAD5nd/tAAAACXBIWXMAAA7EAAAOxAGVKw4bAAABA0lEQVQoz4WR0U6DMBiFeQU1yyKwUopKKmMILQO6zkgxXhi9ML7/sxxDhzjBzYsv/XOac9Lz16F8gyW9w4UXjlye4Ne9f5gXwS0W5AZXHsUyjOGwysBPt3B5DppKrNIS/lrOSSRIukWQVRNdwBvoZ4d3HyC5RmleYcwneNMhlBqh2M1gUlv+urMUCg5JBK7jDEnTont+A29a0EKBibkxKvdnArX1Oe59Yeu6vEC+e0dctaBCTYz630Cr94HeELhaS1T1C3htTlY6V3cW2C/4SXdIlAE92te4N6kRlY9g5d7Ox7oNlUPlMTARYEIhzBuQTWV/k0wIsh/9+6QPNaL+AcXB+wWxJfL4a6FQbQAAAABJRU5ErkJggg==&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Aria Hub Inventory&quot; title=&quot;Aria Hub Inventory&quot; src=&quot;/static/d2dc7c303ed523fc998d16f02a18aba0/5c1e2/Screenshot_20221221_151614.png&quot; srcSet=&quot;/static/d2dc7c303ed523fc998d16f02a18aba0/5c1e2/Screenshot_20221221_151614.png 1812w&quot; sizes=&quot;(max-width: 1812px) 100vw, 1812px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Aria Hub Inventory&lt;/figcaption&gt;
  &lt;/figure&gt; &lt;/p&gt;&lt;p&gt;I have a single EC2 instance deployed, with the Name &lt;code class=&quot;language-text&quot;&gt;aria-demo&lt;/code&gt; and Instance ID &lt;code class=&quot;language-text&quot;&gt;i-069ecb9cb0e422211&lt;/code&gt;&lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1586px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:12.925598991172762%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAADCAYAAACTWi8uAAAACXBIWXMAAA7EAAAOxAGVKw4bAAAArElEQVQI11XNO26FMBSEYfa/BkSRimwkTfaQGwmuibENBj+OD1L0RyJpUnzFjDSabj8SZ86knBER9Lq4/qjqPyllpDVKrWz7Ti2FJEq1H7T3kfT2Qje7jclHUhFijMTjuMe1Vprq74kqrTVE2t2XUqhVsNbivcP5gNsO5Pqm8yHwmAzLGrDO8jk9MMsX8/xkdQ67rjjvMcvC0xhCCJxnuvMwDLe+73kdR2Lc+QG/fOB/khgiqwAAAABJRU5ErkJggg==&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;AWS EC2 Instances&quot; title=&quot;AWS EC2 Instances&quot; src=&quot;/static/52f2d096bd790583d7778a7ca5d59120/867ee/Screenshot_20221221_161823.png&quot; srcSet=&quot;/static/52f2d096bd790583d7778a7ca5d59120/867ee/Screenshot_20221221_161823.png 1586w&quot; sizes=&quot;(max-width: 1586px) 100vw, 1586px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;AWS EC2 Instances&lt;/figcaption&gt;
  &lt;/figure&gt; &lt;/p&gt;&lt;p&gt;We can search for our instance in a couple of way, we can provide a generic search &lt;code class=&quot;language-text&quot;&gt;entityType = AWS.EC2.Instance&lt;/code&gt; and this will return all EC2 instances across all regions, or we can be specific and search using our Instance ID - or any of the properties attached to our EC2 instance, such as the Private IP Address. &lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:2163px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:53.72168284789643%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAALCAYAAAB/Ca1DAAAACXBIWXMAAA7DAAAOwwHHb6hkAAABmUlEQVQoz42S227TQBRF8wmABKW5OnZ9j++3sRPboXkqiA/oEx/BC6oEVERcWoT45IXGaWoa0ZaHrdGM9qzZ55wZmGKNkTcooUAJC8y8Qc9WTLzscfkZIydCa17jvjnHrk4ZKEGBGi+ZLFKGdszQjjqNnPhBTb0cLVlh5i1qKBhZIS90n4G8fGyFN5AetAc/JCUQ6GnNPCx5acW8PX/H4LEk90mG0OIKxS+YuCnPNI/P33/ugP8q8W7ye4BJjVufoYsNQ7/iYnt1F7gvRZrHboJdtLeXD3s7tENmfoElTnGqDUdWzMWXHz1wb556GVpUsqhekW/OcETb7eXQDh+fLjL0pMbKG46MgA+XX3dAmWYelJzES4y0xsyWnMQVU69AjUrMrMZM665n0if9MrWctJG13fnTucunb9f9UGQCaRw5CeP9mZvelji+efjvpBKopw2OWPNc97m8+tWXfGxF//VVeu0Smvm66/UTxWZ7/ZuBkbcoUYWWVmhx2X1yNVl1qxKVzCLRrYeahYJZIDCyBi2qUKOK9x+3/AHFXVIpYWLGPAAAAABJRU5ErkJggg==&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Aria Hub Explore - Searching by entityType&quot; title=&quot;Aria Hub Explore - Searching by entityType&quot; src=&quot;/static/42b631a2cc64c4dd78d08db6b108c09a/75318/Screenshot_20221222_172158.png&quot; srcSet=&quot;/static/42b631a2cc64c4dd78d08db6b108c09a/75318/Screenshot_20221222_172158.png 2163w&quot; sizes=&quot;(max-width: 2163px) 100vw, 2163px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Aria Hub Explore - Searching by entityType&lt;/figcaption&gt;
  &lt;/figure&gt; &lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:2165px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:53.48729792147806%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAALCAYAAAB/Ca1DAAAACXBIWXMAAA7DAAAOwwHHb6hkAAABiUlEQVQoz42Sy26bQBiFeYRGqqo0sQ02xkDABoYBhouhkTdNu+6i6jN0UWWR3pRUkauqT/1VjOXacSqni6O5iP+bo3MwXHXJLO+wYsU4UXhFhxkVDOfZkxotcgaBwF5eEbx9j1+tMMxFwVjUDELJmZ9onV+IJ9UD7bTRBuxYce7FPJ9cYPSAl178ALQP3u7/JSsqmKYN47jk1BO8efcB45iLY257E7aoGEeKYSA5mYR8/vFzA9QvHrjrBwaB/Ov+EN7fT0RD0F7hqBVn85Lr2/UecG9oEKQ4skZevmYqKn1+HEXMaFHgqRVBteLUT7n+fr8D9kM6E1HjZg2ubPR+JhvcbMk0KbEipb/bgodhhpMu8fKWF86CT1/vdkDdXCh1HltHW/XnYa9QPsh3NM+ZyRZb1JyMA27u1nulHLZ4pOEdMMORLX7xSjv8cv/rcYb/o83jMaMww807/KLjmeXzbf0bw8lbrKTCTitsUTIRtW6vX62kxEyUXg9lxgozUsyybvP7xCUfb275AyI3UJ+2q0lLAAAAAElFTkSuQmCC&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Aria Hub Explore - Searching by Instance ID&quot; title=&quot;Aria Hub Explore - Searching by Instance ID&quot; src=&quot;/static/76b961d5bb6fcb3d0bc55978f2d03334/a0cba/Screenshot_20221222_172225.png&quot; srcSet=&quot;/static/76b961d5bb6fcb3d0bc55978f2d03334/a0cba/Screenshot_20221222_172225.png 2165w&quot; sizes=&quot;(max-width: 2165px) 100vw, 2165px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Aria Hub Explore - Searching by Instance ID&lt;/figcaption&gt;
  &lt;/figure&gt; &lt;/p&gt;&lt;p&gt;The previous two screenshots show the same result in our case, but the next two start to show how powerful Aria Hub is. &lt;/p&gt;&lt;p&gt;When we search by the Private IP Address, Aria Hub finds two items that match the criteria, the &lt;code class=&quot;language-text&quot;&gt;AWS.EC2.Instance&lt;/code&gt; and also the &lt;code class=&quot;language-text&quot;&gt;AWS.EC2.NetworkInterface&lt;/code&gt;. Previously the NetworkInterface was shown as a connected object, when our Search Results only returned the Instance, but now we have two search results and we have the ability to expand each of their related objects.&lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:2165px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:53.62586605080831%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAALCAYAAAB/Ca1DAAAACXBIWXMAAA7EAAAOxAGVKw4bAAABjElEQVQoz4WS3U7jMBCF8wgIJBbahKYxSeukTfyTH9cNaUWv2L3lBu1TrLTiAoGgCJYV4p0PsqHQilRcHI0dT745nrEzUHNEZQOfKfSZApEa7iiHNy6+V1qgG3OQ5ieSXxeg+hSOn1UIxBTeKEeHcqtuLL6VNy5BZI1B2SBgCi7l2OtTOAZwOGQW5MYSR+PyA7oqsE3GTJifoM8mOKACZ+e/4axXNUnm2v2s+iiyzaE5J0LbXDfJsUvGuH74/wZcd+QlEqGcIipq9NLyC3S1t0BZI2nOEKoFOqnG5d2/T2AnfofG3PYznS4Qydr+2AbsUIajtMJQnSLWCxwMJS5vHzYdrtZuInAsJhsO26I3KhDKEwzLBj+iDH+vl1+Bm71UOKSstYcmxwwwKhoQMcVukODq/mlzKOvJ5tp+prYOZgUM8wa0mmM/zHDz+LzWwxaZZ9T2vWsjs8BBOQetZtjxY9w+vcCJyhl8rkFyDSIm9pEHorbR5xP0uHqPn7J7ptDLFKJiBsI1Aq7x52qJV+PtUI0WI1Z6AAAAAElFTkSuQmCC&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Aria Hub Explore - Searching by PrivateIpAddress (EC2 Instance)&quot; title=&quot;Aria Hub Explore - Searching by PrivateIpAddress (EC2 Instance)&quot; src=&quot;/static/7831542c926318917dc812c588b98921/a0cba/Screenshot_20221222_172327.png&quot; srcSet=&quot;/static/7831542c926318917dc812c588b98921/a0cba/Screenshot_20221222_172327.png 2165w&quot; sizes=&quot;(max-width: 2165px) 100vw, 2165px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Aria Hub Explore - Searching by PrivateIpAddress (EC2 Instance)&lt;/figcaption&gt;
  &lt;/figure&gt; &lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:2165px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:53.5796766743649%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAALCAYAAAB/Ca1DAAAACXBIWXMAAA7EAAAOxAGVKw4bAAABa0lEQVQoz4WSaW6DMBCFuUYChDXsm1lsA4EQVKlqe4Le/yCvshPShCTtj6dhrJnPnnkofnuCR48wCw6LcDhVBy2poafN/8ootIjAGT8Rf30j7mYoRs5glT30pMY2JNhGJdS4giriH9qlDZxygE8neFWPbZDDTBooArIJCglbipd8kRqRu3yRmXO49QiraKGlFHbOoaxvXgqXFxsZhZW30OLq4VKHdDAzJs+1pIGdszNwKRRRgJL2hIBOcEgrZWb8ObAaEA0fcOgJLpvhNcdHoGhM+ISsf4Nb9vIF2qpGxqCAkXH4bIbPJpikg0u6X+BtwyYksAmHmTPYRQ/1GTAk0hi/OSLtZnj1AVa2Gvl2HLtoJfDq/JNd71Iqx7RJJ3foXE0JbwplFGYwOORwaX4BTBroSQMtrqXuTFlL7G0x4pXUqJJAIfFtiP9wT0dYpIddHWALE0gLg3AYxVkiX8u4RD2lEiYm2NcDyvEdP+IPSY3i1utrAAAAAElFTkSuQmCC&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Aria Hub Explore - Searching by PrivateIpAddress (Network Interface)&quot; title=&quot;Aria Hub Explore - Searching by PrivateIpAddress (Network Interface)&quot; src=&quot;/static/c71600e4f23a9b02efa9c9f574458424/a0cba/Screenshot_20221222_172340.png&quot; srcSet=&quot;/static/c71600e4f23a9b02efa9c9f574458424/a0cba/Screenshot_20221222_172340.png 2165w&quot; sizes=&quot;(max-width: 2165px) 100vw, 2165px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Aria Hub Explore - Searching by PrivateIpAddress (Network Interface)&lt;/figcaption&gt;
  &lt;/figure&gt; &lt;/p&gt;&lt;p&gt;That is it for this post, we have configured our AWS Data Source and started to explore our Inventory. In our next post &lt;a href=&quot;/posts/exploring-aria-hub-search-and-graphql/&quot;&gt;Exploring Aria Hub Search and GraphQL&lt;/a&gt; we will continue the Inventory exploration and look at the &lt;code class=&quot;language-text&quot;&gt;Altair&lt;/code&gt; portal. &lt;/p&gt;&lt;h2 id=&quot;additional&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#additional&quot; aria-label=&quot;additional permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Additional&lt;/h2&gt;&lt;p&gt;After adding my data source I noticed a warning against the Data Source: &lt;code class=&quot;language-text&quot;&gt;Event stream is not connected, please configure event monitoring&lt;/code&gt;. This is not expected behaviour and I have raised this with VMware who are investigating. At present it does not seem to be impacting my discovered Inventory. &lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1829px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:32.91416074357572%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAHCAYAAAAIy204AAAACXBIWXMAAA7EAAAOxAGVKw4bAAABB0lEQVQoz3XQ7W6CMBQGYO5hbk6NUCwdYOZavgq0rKiQ7P6v6F1aInHofjwhhxxezjke+yrgxyesfIqVH92hi3f0wcue4jWIsA5jrAnDW8DgMXmGtUszbP/I8Z7c1cccu3/Y3lufFzU9aNGBiBb+SYIIiYA3ILzCMEp81L1DCw2f1whsH68nwtbNJGtBMgWPlhq07HAoO4SFds+JhjBX0MqAVt8gvATNFVI9ItEDEjUgbq+IpHHst5ZHbHKuntCI1ejC7d9ZbU9jQESDMGvdEFFl5gHmwDBXc7H0aX4QtxcXmKqLm3CTCmyOGfZcPgzhAoPbPRbsXZjsnSnw7Nal0uBQTSs+2+wXgFfUSpuo1jAAAAAASUVORK5CYII=&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Data Source Event stream warning&quot; title=&quot;Data Source Event stream warning&quot; src=&quot;/static/53cd9d71eb33da6517c4353cd2f0464c/a4646/Screenshot_20221221_150432.png&quot; srcSet=&quot;/static/53cd9d71eb33da6517c4353cd2f0464c/a4646/Screenshot_20221221_150432.png 1829w&quot; sizes=&quot;(max-width: 1829px) 100vw, 1829px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Data Source Event stream warning&lt;/figcaption&gt;
  &lt;/figure&gt; &lt;/p&gt;&lt;p&gt;&lt;em&gt;UPDATE&lt;/em&gt;: (23rd December 2022)&lt;/p&gt;&lt;p&gt;It turns out this is because Secure State was not enabled within my &lt;em&gt;Organization&lt;/em&gt;, after claiming the invite in the Aria Hub Free Tier welcome email for Secure State (which I initially missed!) and after deleting and onboarding the data source again, I am pleased to say the connection is much happier.&lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1876px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:20.52238805970149%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAECAYAAACOXx+WAAAACXBIWXMAAA7EAAAOxAGVKw4bAAAAo0lEQVQY02VPWw6DIBD0IKYo0meMFgQFxEeN/ej9DzQNaNNWPzaZnZmd3Y1OegCrWqTCgpQNUq4RFxp502B8Ohz1hIudQIUBERap925r5RNhEVHlkEkHKt0iysWUqQ5n8wDhJhgPhQK564CTn4C/nhtEgVjFz0aPqexQji+wug/9tZ0R3zhoZcHqYef/BnITNm/Lv+Ev9Jf6gbyfwVS3C9kGvgGysHzGmVQlcgAAAABJRU5ErkJggg==&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Data Source OK&quot; title=&quot;Data Source OK&quot; src=&quot;/static/a875f0c8a25bbda96a6a22933504c71a/bd320/Screenshot_20221223_174051.png&quot; srcSet=&quot;/static/a875f0c8a25bbda96a6a22933504c71a/bd320/Screenshot_20221223_174051.png 1876w&quot; sizes=&quot;(max-width: 1876px) 100vw, 1876px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Data Source OK&lt;/figcaption&gt;
  &lt;/figure&gt; &lt;/p&gt;</content:encoded><tags>vmware,aria,aria-automation,aria-hub</tags><featuredImage>https://samperrin.com/static/9b6d9fcd9b11bbe2dab5a5160bf0ec5f/hero.png</featuredImage></item><item><title><![CDATA[vRA/AA - Windows Cloudbase-init - Function Update]]></title><description><![CDATA[An updated example of Cloudbase-init that uses multi-part user data to run cloud-config and PowerShell code that uses functions for some deployment guarantees]]></description><link>https://samperrin.com/posts/vra-aa-windows-cloudbase-init-function-update/</link><guid isPermaLink="false">https://samperrin.com/posts/vra-aa-windows-cloudbase-init-function-update/</guid><category><![CDATA[vmware]]></category><category><![CDATA[aria]]></category><category><![CDATA[aria-automation]]></category><pubDate>Thu, 15 Dec 2022 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Back in August I created the following post that showed an example Cloudbase-init multi-part user data script for use within an Aria Automation Template (vRealize Cloud Template) - &lt;a href=&quot;/posts/vra-windows-cloudbase-init-multi-part-user-data-example/&quot;&gt;vRA - Windows Cloudbase-init - Multi-part User Data Example&lt;/a&gt;&lt;/p&gt;&lt;p&gt;This post is a follow-on from that which expands on the Cloudbase-init code by utilising PowerShell functions. Cloudbase-init itself provides no guarantees that things will run, this can cause issues if you are relying on it to provide the intial customisation of virtual machines, so by using function we can provide some sort of control around when the next stages of the Cloudbase-init code are run - for example, we can wait for the network to be up before we attempt a domain join. &lt;/p&gt;&lt;p&gt;I will not be going into any detail around the Aria Automation Templates or the compute resources, instead we will focus just on the Cloudbase-init code. Refer back to the first post if you want to see the rest of the Template code.  &lt;/p&gt;&lt;h2 id=&quot;establish-the-multi-part-user-data&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#establish-the-multi-part-user-data&quot; aria-label=&quot;establish the multi part user data permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Establish the multi-part user data&lt;/h2&gt;&lt;p&gt;You can find the full Cloudbase-init code at the bottom, but first we will break down what each main part is doing. &lt;/p&gt;&lt;p&gt;This is the start of our multi-part code. First we set our boundary &lt;code class=&quot;language-text&quot;&gt;==NewPart==&lt;/code&gt;. When this appears we start a new “part” (section). Section 1 is using &lt;a href=&quot;https://cloudbase-init.readthedocs.io/en/latest/userdata.html#cloud-config&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;cloud-config&lt;/a&gt; and we set the hostname using the &lt;a href=&quot;https://cloudbase-init.readthedocs.io/en/latest/userdata.html?highlight=set_hostname#cloud-config&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;set_hostname&lt;/a&gt; Cloudbase-init plugin. Section 2 uses &lt;a href=&quot;https://cloudbase-init.readthedocs.io/en/latest/userdata.html#powershell&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;powershell&lt;/a&gt;, from this point down our code is run in PowerShell, we specifically use &lt;a href=&quot;https://cloudbase-init.readthedocs.io/en/latest/userdata.html?highlight=ps1_sysnative#powershell&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;#ps1_sysnative&lt;/a&gt;. &lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;yaml&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-yaml line-numbers&quot;&gt;&lt;code class=&quot;language-yaml&quot;&gt;  &lt;span class=&quot;token key atrule&quot;&gt;Content-Type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; multipart/mixed; boundary=&amp;quot;==NewPart==&amp;quot;
  &lt;span class=&quot;token key atrule&quot;&gt;MIME-Version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;1.0&lt;/span&gt;

  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;==NewPart==
  &lt;span class=&quot;token key atrule&quot;&gt;Content-Type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; text/cloud&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;config; charset=&amp;quot;us&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;ascii&amp;quot;
  &lt;span class=&quot;token key atrule&quot;&gt;MIME-Version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;1.0&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;Content-Transfer-Encoding&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 7bit
  &lt;span class=&quot;token key atrule&quot;&gt;Content-Disposition&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; attachment; filename=&amp;quot;cloud&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;config&amp;quot;

  &lt;span class=&quot;token key atrule&quot;&gt;set_hostname&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; $&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;self.resourceName&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;

  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;==NewPart==
  &lt;span class=&quot;token key atrule&quot;&gt;Content-Type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; text/x&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;shellscript; charset=&amp;quot;us&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;ascii&amp;quot;
  &lt;span class=&quot;token key atrule&quot;&gt;MIME-Version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;1.0&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;Content-Transfer-Encoding&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 7bit
  &lt;span class=&quot;token key atrule&quot;&gt;Content-Disposition&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; attachment; filename=&amp;quot;INIT.ps1&amp;quot;

  &lt;span class=&quot;token comment&quot;&gt;#ps1_sysnative&lt;/span&gt;&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&quot;the-functions&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#the-functions&quot; aria-label=&quot;the functions permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;The Functions&lt;/h2&gt;&lt;p&gt;Next up is a logging function. Cloudbase-init itself creates a log output but it is easy to miss what is actually happening. This function is used throughout the Cloudbase-init code to write to a seperate log file. We have used this function quite heavily throughout our Cloudbase-init code, even within other functions, it will look similar to this: &lt;code class=&quot;language-text&quot;&gt;CustomLog(&amp;quot;Create Local User - Started&amp;quot;)&lt;/code&gt;. &lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;powershell&quot;&gt;&lt;pre class=&quot;language-powershell&quot;&gt;&lt;code class=&quot;language-powershell&quot;&gt;&lt;span class=&quot;token keyword&quot;&gt;function&lt;/span&gt; CustomLog &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token variable&quot;&gt;$LogMessage&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
  &lt;span class=&quot;token variable&quot;&gt;$LogFilePath&lt;/span&gt; = &lt;span class=&quot;token string&quot;&gt;&amp;quot;C:\Program Files\Cloudbase Solutions\Cloudbase-Init\log\CustomLog.txt&amp;quot;&lt;/span&gt;
  &lt;span class=&quot;token function&quot;&gt;Write-Output&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&lt;span class=&quot;token function&quot;&gt;$&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;Get-Date&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;/span&gt;.ToString(&amp;#x27;T&amp;#x27;)) &lt;span class=&quot;token variable&quot;&gt;$LogMessage&lt;/span&gt;&amp;quot;&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;Out-File&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;FilePath &lt;span class=&quot;token variable&quot;&gt;$LogFilePath&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Append
&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;We establish our first of the “check” type functions. In this one we take in a property from a Property Group which is the FQDN of our Domain Server.  &lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;powershell&quot;&gt;&lt;pre class=&quot;language-powershell&quot;&gt;&lt;code class=&quot;language-powershell&quot;&gt;&lt;span class=&quot;token keyword&quot;&gt;function&lt;/span&gt; DomainDnsTest &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
  &lt;span class=&quot;token variable&quot;&gt;$DomainDnsTestResult&lt;/span&gt; = &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;Test-NetConnection&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;ComputerName &lt;span class=&quot;token string&quot;&gt;&amp;quot;${propgroup.defaultServerValues.windowsDomainServer}&amp;quot;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Port 389&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;TcpTestSucceeded
  &lt;span class=&quot;token keyword&quot;&gt;return&lt;/span&gt; &lt;span class=&quot;token variable&quot;&gt;$DomainDnsTestResult&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This function check a property within Windows to see if it has domain joined. &lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;powershell&quot;&gt;&lt;pre class=&quot;language-powershell&quot;&gt;&lt;code class=&quot;language-powershell&quot;&gt;&lt;span class=&quot;token keyword&quot;&gt;function&lt;/span&gt; DomainJoinStatus &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
  &lt;span class=&quot;token variable&quot;&gt;$DomainJoinStatusResult&lt;/span&gt; = &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;Get-WmiObject&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token keyword&quot;&gt;Class&lt;/span&gt; Win32_ComputerSystem&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;PartOfDomain
  &lt;span class=&quot;token keyword&quot;&gt;return&lt;/span&gt; &lt;span class=&quot;token variable&quot;&gt;$DomainJoinStatusResult&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This function waits for the network interface status to return as “Up”. This status alone is not enough to know if a network is &lt;em&gt;ready&lt;/em&gt;, hence why we create a DNS check too. &lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;powershell&quot;&gt;&lt;pre class=&quot;language-powershell&quot;&gt;&lt;code class=&quot;language-powershell&quot;&gt;&lt;span class=&quot;token keyword&quot;&gt;function&lt;/span&gt; WaitForNetwork &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
  CustomLog&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;-- Starting WaitForNetwork. Starting status &lt;span class=&quot;token function&quot;&gt;$&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;Get-NetAdapter&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Name Ethernet0&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;/span&gt;.Status)&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;
  &lt;span class=&quot;token keyword&quot;&gt;While&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;Get-NetAdapter&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Name Ethernet0&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;Status &lt;span class=&quot;token operator&quot;&gt;-ne&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;Up&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
    CustomLog&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;-- Waiting for network Ethernet0 to be up. Current status &lt;span class=&quot;token function&quot;&gt;$&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;Get-NetAdapter&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Name Ethernet0&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;/span&gt;.Status)&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;
    &lt;span class=&quot;token function&quot;&gt;Start-Sleep&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Seconds 2
  &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
  CustomLog&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;-- Ending WaitForNetwork. Ending status &lt;span class=&quot;token function&quot;&gt;$&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;Get-NetAdapter&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Name Ethernet0&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;/span&gt;.Status)&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This function utilises another nested function and waits for DNS to be ready. &lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;powershell&quot;&gt;&lt;pre class=&quot;language-powershell&quot;&gt;&lt;code class=&quot;language-powershell&quot;&gt;&lt;span class=&quot;token keyword&quot;&gt;function&lt;/span&gt; WaitForDns &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
  CustomLog&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;-- Starting WaitForDns. Starting status &lt;span class=&quot;token function&quot;&gt;$&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;DomainDnsTest&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;/span&gt;&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;
  &lt;span class=&quot;token keyword&quot;&gt;While&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;DomainDnsTest&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-ne&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;True&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
    CustomLog&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;-- Waiting for DNS to succeed. Current status &lt;span class=&quot;token function&quot;&gt;$&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;DomainDnsTest&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;/span&gt;&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;
    &lt;span class=&quot;token function&quot;&gt;Start-Sleep&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Seconds 2
  &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
  CustomLog&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;-- Ending WaitForDns. Ending status &lt;span class=&quot;token function&quot;&gt;$&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;DomainDnsTest&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;/span&gt;&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This functions code has some values replaced by the users Input or from Property Group values. It attempts to domain join the server. We use the &lt;code class=&quot;language-text&quot;&gt;Add-Computer&lt;/code&gt; cmdlet because the computer object already exists within Active Directory because Aria Automation has created it via its native integration. &lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;powershell&quot;&gt;&lt;pre class=&quot;language-powershell&quot;&gt;&lt;code class=&quot;language-powershell&quot;&gt;&lt;span class=&quot;token keyword&quot;&gt;function&lt;/span&gt; JoinDomain &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
  CustomLog&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;-- Starting JoinDomain&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;
  WaitForNetwork
  WaitForDns
  &lt;span class=&quot;token variable&quot;&gt;$DomainJoinCreds&lt;/span&gt; = &lt;span class=&quot;token function&quot;&gt;New-Object&lt;/span&gt; System&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;Management&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;Automation&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;PSCredential &lt;span class=&quot;token string&quot;&gt;&amp;quot;${propgroup.defaultServerValues.windowsDomainJoinUsername}@${propgroup.defaultServerValues.windowsDomain}&amp;quot;&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;ConvertTo-SecureString&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;String &lt;span class=&quot;token string&quot;&gt;&amp;quot;${input.domainPassword}&amp;quot;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;AsPlainText &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Force&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;
  &lt;span class=&quot;token function&quot;&gt;Add-Computer&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;DomainName &lt;span class=&quot;token string&quot;&gt;&amp;quot;${propgroup.defaultServerValues.windowsDomain}&amp;quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Credential &lt;span class=&quot;token variable&quot;&gt;$DomainJoinCreds&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Server &lt;span class=&quot;token string&quot;&gt;&amp;quot;${propgroup.defaultServerValues.windowsDomainServer}&amp;quot;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Restart:&lt;span class=&quot;token boolean&quot;&gt;$false&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Force
  CustomLog&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;-- Ending JoinDomain&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Our final function, we use one of our earlier created functions (&lt;code class=&quot;language-text&quot;&gt;DomainJoinStatus&lt;/code&gt;) and we wait for that property to return true. &lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;powershell&quot;&gt;&lt;pre class=&quot;language-powershell&quot;&gt;&lt;code class=&quot;language-powershell&quot;&gt;&lt;span class=&quot;token keyword&quot;&gt;function&lt;/span&gt; WaitForDomainJoin &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
  CustomLog&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;-- Starting WaitForDomainJoin. Starting status &lt;span class=&quot;token function&quot;&gt;$&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;DomainJoinStatus&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;/span&gt;&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;
  &lt;span class=&quot;token keyword&quot;&gt;While&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;DomainJoinStatus&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-ne&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;True&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
    CustomLog&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;---- Waiting for Domain to be True. Current status &lt;span class=&quot;token function&quot;&gt;$&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;DomainJoinStatus&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;/span&gt;&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;
    CustomLog&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;---- Starting Sleep&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;
    &lt;span class=&quot;token function&quot;&gt;Start-Sleep&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Seconds 10
    CustomLog&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;---- Ending Sleep&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;
    JoinDomain
  &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
  CustomLog&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;-- Ending WaitForDomainJoin. Ending status &lt;span class=&quot;token function&quot;&gt;$&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;DomainJoinStatus&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;/span&gt;&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&quot;the-remaining-parts&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#the-remaining-parts&quot; aria-label=&quot;the remaining parts permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;The Remaining Parts&lt;/h2&gt;&lt;p&gt;I have added comments inline with the rest of the code and each major section. &lt;/p&gt;&lt;div class=&quot;gatsby-highlight has-highlighted-lines&quot; data-language=&quot;powershell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-powershell line-numbers&quot;&gt;&lt;code class=&quot;language-powershell&quot;&gt;&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;&lt;span class=&quot;token comment&quot;&gt;## We create a local user and add the user to the Administrators group.&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;&lt;span class=&quot;token comment&quot;&gt;## Only the CustomLog function is used here.&lt;/span&gt;&lt;/span&gt;CustomLog&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;Create Local User - Started&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;
&lt;span class=&quot;token variable&quot;&gt;$localUserPassword&lt;/span&gt; = &lt;span class=&quot;token function&quot;&gt;ConvertTo-SecureString&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;${input.serverPassword}&amp;quot;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;AsPlainText &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Force
&lt;span class=&quot;token function&quot;&gt;New-LocalUser&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Name &lt;span class=&quot;token string&quot;&gt;&amp;quot;${input.serverUser}&amp;quot;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Password &lt;span class=&quot;token variable&quot;&gt;$localUserPassword&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;Add-LocalGroupMember&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;Group&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;Administrators&amp;quot;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Member &lt;span class=&quot;token string&quot;&gt;&amp;quot;${input.serverUser}&amp;quot;&lt;/span&gt;
CustomLog&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;Create Local User - Finished&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;

&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;&lt;span class=&quot;token comment&quot;&gt;## We set some Windows Firewall settings.&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;&lt;span class=&quot;token comment&quot;&gt;## Only the CustomLog function is used here.&lt;/span&gt;&lt;/span&gt;CustomLog&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;Set Local Firewall - Started&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;Set-NetFirewallRule&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;DisplayName &lt;span class=&quot;token string&quot;&gt;&amp;quot;File and Printer Sharing (Echo Request - ICMPv4-In)&amp;quot;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;enabled True
&lt;span class=&quot;token function&quot;&gt;Enable-NetFirewallRule&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;DisplayGroup &lt;span class=&quot;token string&quot;&gt;&amp;quot;Remote Desktop&amp;quot;&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;Set-ItemProperty&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Path &lt;span class=&quot;token string&quot;&gt;&amp;#x27;HKLM:\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters&amp;#x27;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Name &lt;span class=&quot;token string&quot;&gt;&amp;#x27;NV Domain&amp;#x27;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Value &lt;span class=&quot;token string&quot;&gt;&amp;quot;${propgroup.defaultServerValues.fqdnDomain}&amp;quot;&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;Set-ItemProperty&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Path &lt;span class=&quot;token string&quot;&gt;&amp;#x27;HKLM:\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters&amp;#x27;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Name SyncDomainWithMembership &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Value &lt;span class=&quot;token string&quot;&gt;&amp;quot;0&amp;quot;&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;Set-ItemProperty&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Path &lt;span class=&quot;token string&quot;&gt;&amp;#x27;HKLM:\System\CurrentControlSet\Control\Terminal Server&amp;#x27;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;name &lt;span class=&quot;token string&quot;&gt;&amp;quot;fDenyTSConnections&amp;quot;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;value 0
CustomLog&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;Set Local Firewall - Finished&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;

&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;&lt;span class=&quot;token comment&quot;&gt;## We format any additional disk drives that were added as part of the VM deployment request.&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;&lt;span class=&quot;token comment&quot;&gt;## Only the CustomLog function is used here.&lt;/span&gt;&lt;/span&gt;CustomLog&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;Initialise Disk - Started&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;Get-Disk&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;Where-Object&lt;/span&gt; PartitionStyle &lt;span class=&quot;token operator&quot;&gt;-Eq&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;RAW&amp;quot;&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;Initialize-Disk&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;PassThru &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;New-Partition&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;AssignDriveLetter &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;UseMaximumSize &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;Format-Volume&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;NewFileSystemLabel &lt;span class=&quot;token string&quot;&gt;&amp;quot;DATA&amp;quot;&lt;/span&gt;
CustomLog&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;Initialise Disk - Finished&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;

&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;&lt;span class=&quot;token comment&quot;&gt;## We configure some DNS settings. Only the CustomLog function is used here.&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;&lt;span class=&quot;token comment&quot;&gt;## Only the CustomLog function is used here.&lt;/span&gt;&lt;/span&gt;CustomLog&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;Set DNS Settings - Started&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;Get-NetAdapter&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;Set-DnsClient&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;RegisterThisConnectionsAddress &lt;span class=&quot;token boolean&quot;&gt;$False&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;Get-NetAdapter&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;Set-DnsClient&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;UseSuffixWhenRegistering &lt;span class=&quot;token boolean&quot;&gt;$False&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;Get-NetAdapter&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;Set-DnsClient&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;ConnectionSpecificSuffix $&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;propgroup&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;defaultServerValues&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;fqdnDomain&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;Set-DnsClientGlobalSetting&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;SuffixSearchList @&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;domain.com&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;sub.domain.com&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;
CustomLog&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;Set DNS Settings - Finished&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;

&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;&lt;span class=&quot;token comment&quot;&gt;## We set the IP address, this uses the vRA IPAM and is injected at deployment time. &lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;&lt;span class=&quot;token comment&quot;&gt;## Along with the CustomLog function we also use WaitForNetwork and WaitForDns.&lt;/span&gt;&lt;/span&gt;CustomLog&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;Set IP Settings - Started&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;
&lt;span class=&quot;token variable&quot;&gt;$adapter&lt;/span&gt; = &lt;span class=&quot;token function&quot;&gt;Get-NetAdapter&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; ? &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; &lt;span class=&quot;token variable&quot;&gt;$_&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;Name &lt;span class=&quot;token operator&quot;&gt;-eq&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;Ethernet0&amp;quot;&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
&lt;span class=&quot;token variable&quot;&gt;$adapter&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;Remove-NetIpAddress&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Confirm:&lt;span class=&quot;token boolean&quot;&gt;$false&lt;/span&gt;
&lt;span class=&quot;token variable&quot;&gt;$adapter&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;Remove-NetRoute&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Confirm:&lt;span class=&quot;token boolean&quot;&gt;$false&lt;/span&gt;
&lt;span class=&quot;token variable&quot;&gt;$adapter&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;New-NetIpAddress&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;IPAddress $&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;self&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;networks&lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;0&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;address&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;PrefixLength $&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;resource&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;Network&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;prefixLength&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;DefaultGateway $&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;resource&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;Network&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;gateway&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
&lt;span class=&quot;token variable&quot;&gt;$adapter&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;Set-DnsClientServerAddress&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;ServerAddresses&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;${join(resource.Network.dns,&amp;#x27;&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;#x27;)}&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;
&lt;span class=&quot;token variable&quot;&gt;$adapter&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;Disable-NetAdapterBinding&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;ComponentID ms_tcpip6
WaitForNetwork
WaitForDns
&lt;span class=&quot;token function&quot;&gt;Set-NetConnectionProfile&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;InterfaceAlias Ethernet0 &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;NetworkCategory &lt;span class=&quot;token string&quot;&gt;&amp;quot;Private&amp;quot;&lt;/span&gt;
CustomLog&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;Set IP Settings - Finished&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;

&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;&lt;span class=&quot;token comment&quot;&gt;## At this point both Network and DNS should be ready so we attempt to domain join. &lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;&lt;span class=&quot;token comment&quot;&gt;## We use the WaitForDomainJoin and CustomLog functions.&lt;/span&gt;&lt;/span&gt;CustomLog&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;Domain Join - Started&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;
WaitForDomainJoin
CustomLog&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;Domain Join - Finished&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;

&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;&lt;span class=&quot;token comment&quot;&gt;## We tidy up some of the log files. &lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;&lt;span class=&quot;token comment&quot;&gt;## Only the CustomLog function is used here.&lt;/span&gt;&lt;/span&gt;CustomLog&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;Tidying Logs - Started&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;Get-Content&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;C:\Program Files\Cloudbase Solutions\Cloudbase-Init\log\cloudbase-init.log&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-replace&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;${input.domainPassword}&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;lt;DOMAIN-JOIN-PASSWORD&amp;gt;&amp;quot;&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;Set-Content&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;C:\Program Files\Cloudbase Solutions\Cloudbase-Init\log\cloudbase-init.log&amp;quot;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Verbose
&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;Get-Content&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;C:\Program Files\Cloudbase Solutions\Cloudbase-Init\log\cloudbase-init.log&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-replace&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;${input.serverPassword}&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;lt;LOCAL-USER-PASSWORD&amp;gt;&amp;quot;&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;Set-Content&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;C:\Program Files\Cloudbase Solutions\Cloudbase-Init\log\cloudbase-init.log&amp;quot;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Verbose
CustomLog&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;Tidying Logs - Finished&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;

&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;&lt;span class=&quot;token comment&quot;&gt;## We eject the CD drive that was attached automatically by vRA. &lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;&lt;span class=&quot;token comment&quot;&gt;## Only the CustomLog function is used here.&lt;/span&gt;&lt;/span&gt;CustomLog&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;Ejecting CD Drives - Started&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;
&lt;span class=&quot;token variable&quot;&gt;$drives&lt;/span&gt; = &lt;span class=&quot;token function&quot;&gt;Get-WmiObject&lt;/span&gt; Win32_Volume &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token keyword&quot;&gt;Filter&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;DriveType=5&amp;quot;&lt;/span&gt;
&lt;span class=&quot;token variable&quot;&gt;$drives&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;ForEach-Object&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;New-Object&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;ComObject Shell&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;Application&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;Namespace&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;17&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;ParseName&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token variable&quot;&gt;$_&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;Name&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;InvokeVerb&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;Eject&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;ErrorAction SilentlyContinue
CustomLog&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;Ejecting CD Drives - Finished&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;

&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;&lt;span class=&quot;token comment&quot;&gt;## We reboot the server. &lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;&lt;span class=&quot;token comment&quot;&gt;## Only the CustomLog function is used here.&lt;/span&gt;&lt;/span&gt;CustomLog&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;Preparing to Reboot - Started&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;
shutdown &lt;span class=&quot;token operator&quot;&gt;/&lt;/span&gt;r &lt;span class=&quot;token operator&quot;&gt;/&lt;/span&gt;t 10
CustomLog&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;Preparing to Reboot - Finished&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&quot;cloud-config-in-full&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#cloud-config-in-full&quot; aria-label=&quot;cloud config in full permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Cloud-config in full&lt;/h2&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;yaml&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-yaml line-numbers&quot;&gt;&lt;code class=&quot;language-yaml&quot;&gt;&lt;span class=&quot;token key atrule&quot;&gt;cloudConfig&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt;&lt;span class=&quot;token scalar string&quot;&gt;
  Content-Type: multipart/mixed; boundary=&amp;quot;==NewPart==&amp;quot;
  MIME-Version: 1.0&lt;/span&gt;

  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;==NewPart==
  &lt;span class=&quot;token key atrule&quot;&gt;Content-Type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; text/cloud&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;config; charset=&amp;quot;us&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;ascii&amp;quot;
  &lt;span class=&quot;token key atrule&quot;&gt;MIME-Version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;1.0&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;Content-Transfer-Encoding&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 7bit
  &lt;span class=&quot;token key atrule&quot;&gt;Content-Disposition&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; attachment; filename=&amp;quot;cloud&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;config&amp;quot;

  &lt;span class=&quot;token key atrule&quot;&gt;set_hostname&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; $&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;self.resourceName&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;

  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;==NewPart==
  &lt;span class=&quot;token key atrule&quot;&gt;Content-Type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; text/x&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;shellscript; charset=&amp;quot;us&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;ascii&amp;quot;
  &lt;span class=&quot;token key atrule&quot;&gt;MIME-Version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;1.0&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;Content-Transfer-Encoding&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 7bit
  &lt;span class=&quot;token key atrule&quot;&gt;Content-Disposition&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; attachment; filename=&amp;quot;INIT.ps1&amp;quot;

  &lt;span class=&quot;token comment&quot;&gt;#ps1_sysnative&lt;/span&gt;

  function CustomLog ($LogMessage) &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
    $LogFilePath = &amp;quot;C&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;\Program Files\Cloudbase Solutions\Cloudbase&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Init\log\CustomLog.txt&amp;quot;
    Write&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Output &amp;quot;$((Get&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Date).ToString(&amp;#x27;T&amp;#x27;)) $LogMessage&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; Out&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;File &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;FilePath $LogFilePath &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Append
  &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;

  function DomainDnsTest &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
    $DomainDnsTestResult = (Test&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;NetConnection &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;ComputerName &amp;quot;$&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;propgroup.defaultServerValues.windowsDomainServerDc3&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Port 389).TcpTestSucceeded
    return $DomainDnsTestResult
  &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;

  function DomainJoinStatus &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
    $DomainJoinStatusResult = (Get&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;WmiObject &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Class Win32_ComputerSystem).PartOfDomain
    return $DomainJoinStatusResult
  &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;

  function WaitForNetwork &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
    CustomLog(&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; Starting WaitForNetwork. Starting status $((Get&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;NetAdapter &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Name Ethernet0).Status)&amp;quot;)
    While ((Get&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;NetAdapter &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Name Ethernet0).Status &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;ne &amp;quot;Up&amp;quot;) &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
      CustomLog(&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; Waiting for network Ethernet0 to be up. Current status $((Get&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;NetAdapter &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Name Ethernet0).Status)&amp;quot;)
      Start&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Sleep &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Seconds 2
    &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
    CustomLog(&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; Ending WaitForNetwork. Ending status $((Get&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;NetAdapter &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Name Ethernet0).Status)&amp;quot;)
  &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;

  function WaitForDns &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
    CustomLog(&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; Starting WaitForDns. Starting status $(DomainDnsTest)&amp;quot;)
    While ((DomainDnsTest) &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;ne &amp;quot;True&amp;quot;) &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
      CustomLog(&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; Waiting for DNS to succeed. Current status $(DomainDnsTest)&amp;quot;)
      Start&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Sleep &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Seconds 2
    &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
    CustomLog(&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; Ending WaitForDns. Ending status $(DomainDnsTest)&amp;quot;)
  &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;

  function JoinDomain &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
    CustomLog(&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; Starting JoinDomain&amp;quot;)
    WaitForNetwork
    WaitForDns
    $DomainJoinCreds = New&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Object System.Management.Automation.PSCredential &amp;quot;$&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;propgroup.defaultServerValues.windowsDomainJoinUsername&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;@$&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;propgroup.defaultServerValues.windowsDomain&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;(ConvertTo&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;SecureString &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;String &amp;quot;$&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;input.domainPassword&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;AsPlainText &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Force)
    Add&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Computer &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;DomainName &amp;quot;$&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;propgroup.defaultServerValues.windowsDomain&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Credential $DomainJoinCreds &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Server &amp;quot;$&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;propgroup.defaultServerValues.windowsDomainServerDc3&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Restart&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;$false &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Force
    CustomLog(&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; Ending JoinDomain&amp;quot;)
  &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;

  function WaitForDomainJoin &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
    CustomLog(&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; Starting WaitForDomainJoin. Starting status $(DomainJoinStatus)&amp;quot;)
    While ((DomainJoinStatus) &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;ne &amp;quot;True&amp;quot;) &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
      CustomLog(&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; Waiting for Domain to be True. Current status $(DomainJoinStatus)&amp;quot;)
      CustomLog(&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; Starting Sleep&amp;quot;)
      Start&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Sleep &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Seconds 10
      CustomLog(&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; Ending Sleep&amp;quot;)
      JoinDomain
    &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
    CustomLog(&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; Ending WaitForDomainJoin. Ending status $(DomainJoinStatus)&amp;quot;)
  &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;

  CustomLog(&amp;quot;Create Local User &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; Started&amp;quot;)
  $localUserPassword = ConvertTo&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;SecureString &amp;quot;$&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;input.serverPassword&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;AsPlainText &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Force
  New&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;LocalUser &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Name &amp;quot;$&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;input.serverUser&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Password $localUserPassword
  Add&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;LocalGroupMember &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Group &amp;quot;Administrators&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Member &amp;quot;$&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;input.serverUser&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&amp;quot;
  CustomLog(&amp;quot;Create Local User &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; Finished&amp;quot;)

  CustomLog(&amp;quot;Set Local Firewall &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; Started&amp;quot;)
  Set&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;NetFirewallRule &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;DisplayName &amp;quot;File and Printer Sharing (Echo Request &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; ICMPv4&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;In)&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;enabled True
  Enable&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;NetFirewallRule &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;DisplayGroup &amp;quot;Remote Desktop&amp;quot;
  Set&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;ItemProperty &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Path &amp;#x27;HKLM&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters&amp;#x27; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Name &amp;#x27;NV Domain&amp;#x27; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Value &amp;quot;$&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;propgroup.defaultServerValues.fqdnDomain&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&amp;quot;
  Set&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;ItemProperty &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Path &amp;#x27;HKLM&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters&amp;#x27; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Name SyncDomainWithMembership &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Value &amp;quot;0&amp;quot;
  Set&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;ItemProperty &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Path &amp;#x27;HKLM&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;\System\CurrentControlSet\Control\Terminal Server&amp;#x27; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;name &amp;quot;fDenyTSConnections&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;value 0
  CustomLog(&amp;quot;Set Local Firewall &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; Finished&amp;quot;)

  CustomLog(&amp;quot;Initialise Disk &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; Started&amp;quot;)
  Get&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Disk &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; Where&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Object PartitionStyle &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Eq &amp;quot;RAW&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; Initialize&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Disk &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;PassThru &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; New&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Partition &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;AssignDriveLetter &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;UseMaximumSize &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; Format&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Volume &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;NewFileSystemLabel &amp;quot;DATA&amp;quot;
  CustomLog(&amp;quot;Initialise Disk &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; Finished&amp;quot;)

  CustomLog(&amp;quot;Set DNS Settings &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; Started&amp;quot;)
  Get&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;NetAdapter &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; Set&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;DnsClient &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;RegisterThisConnectionsAddress $False
  Get&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;NetAdapter &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; Set&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;DnsClient &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;UseSuffixWhenRegistering $False
  Get&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;NetAdapter &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; Set&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;DnsClient &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;ConnectionSpecificSuffix $&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;propgroup.defaultServerValues.fqdnDomain&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
  Set&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;DnsClientGlobalSetting &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;SuffixSearchList @(&amp;quot;domain.com&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &amp;quot;sub.domain.com&amp;quot;)
  CustomLog(&amp;quot;Set DNS Settings &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; Finished&amp;quot;)

  CustomLog(&amp;quot;Set IP Settings &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; Started&amp;quot;)
  $adapter = Get&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;NetAdapter &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;?&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; $_.Name &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;eq &amp;quot;Ethernet0&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
  $adapter &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; Remove&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;NetIpAddress &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Confirm&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;$false
  $adapter &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; Remove&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;NetRoute &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Confirm&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;$false
  $adapter &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; New&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;NetIpAddress &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;IPAddress $&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;self.networks&lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;0&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;.address&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;PrefixLength $&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;resource.Network.prefixLength&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;DefaultGateway $&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;resource.Network.gateway&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
  $adapter &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; Set&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;DnsClientServerAddress &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;ServerAddresses(&amp;quot;$&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;join(resource.Network.dns&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;&amp;#x27;&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &amp;quot;&amp;#x27;)&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&amp;quot;)
  $adapter &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; Disable&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;NetAdapterBinding &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;ComponentID ms_tcpip6
  WaitForNetwork
  WaitForDns
  Set&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;NetConnectionProfile &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;InterfaceAlias Ethernet0 &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;NetworkCategory &amp;quot;Private&amp;quot;
  CustomLog(&amp;quot;Set IP Settings &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; Finished&amp;quot;)

  CustomLog(&amp;quot;Domain Join &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; Started&amp;quot;)
  WaitForDomainJoin
  CustomLog(&amp;quot;Domain Join &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; Finished&amp;quot;)

  CustomLog(&amp;quot;Tidying Logs &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; Started&amp;quot;)
  (Get&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Content &amp;quot;C&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;\Program Files\Cloudbase Solutions\Cloudbase&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Init\log\cloudbase&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;init.log&amp;quot;) &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;replace &amp;quot;$&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;input.domainPassword&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;&amp;quot;&amp;lt;DOMAIN&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;JOIN&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;PASSWORD&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; Set&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Content &amp;quot;C&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;\Program Files\Cloudbase Solutions\Cloudbase&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Init\log\cloudbase&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;init.log&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Verbose
  (Get&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Content &amp;quot;C&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;\Program Files\Cloudbase Solutions\Cloudbase&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Init\log\cloudbase&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;init.log&amp;quot;) &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;replace &amp;quot;$&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;input.serverPassword&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;&amp;quot;&amp;lt;LOCAL&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;USER&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;PASSWORD&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; Set&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Content &amp;quot;C&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;\Program Files\Cloudbase Solutions\Cloudbase&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Init\log\cloudbase&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;init.log&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Verbose
  CustomLog(&amp;quot;Tidying Logs &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; Finished&amp;quot;)

  CustomLog(&amp;quot;Ejecting CD Drives &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; Started&amp;quot;)
  $drives = Get&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;WmiObject Win32_Volume &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Filter &amp;quot;DriveType=5&amp;quot;
  $drives &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; ForEach&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Object &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; (New&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Object &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;ComObject Shell.Application).Namespace(17).ParseName($_.Name).InvokeVerb(&amp;quot;Eject&amp;quot;) &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;ErrorAction SilentlyContinue
  CustomLog(&amp;quot;Ejecting CD Drives &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; Finished&amp;quot;)

  CustomLog(&amp;quot;Preparing to Reboot &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; Started&amp;quot;)
  shutdown /r /t 10
  CustomLog(&amp;quot;Preparing to Reboot &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; Finished&amp;quot;)
&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;</content:encoded><tags>vmware,aria,aria-automation</tags><featuredImage>https://samperrin.com/static/60191658b420a104c0cae4e60b79ea86/hero_8.jpg</featuredImage></item><item><title><![CDATA[VMware Cloud Foundation - PowerShell Reporting Module]]></title><description><![CDATA[A short post to highlight the PowerShell module for running reports on your VMware Cloud Foundation environment]]></description><link>https://samperrin.com/posts/vmware-cloud-foundation-powershell-reporting-module/</link><guid isPermaLink="false">https://samperrin.com/posts/vmware-cloud-foundation-powershell-reporting-module/</guid><category><![CDATA[vmware]]></category><pubDate>Mon, 05 Dec 2022 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Day to day I am involved in architecting, designing, building, managing or fixing VMware Cloud Foundation environments. Given the potential size of these environments its easy to spend hours gathering information on them, so I was pleased when I was introduced to the &lt;code class=&quot;language-text&quot;&gt;VMware.CloudFoundation.Reporting&lt;/code&gt; module.&lt;/p&gt;&lt;p&gt;This is a short post highlighting this tool - the steps needed to get it installed and some information on the reports it provides. &lt;/p&gt;&lt;h2 id=&quot;available-reports&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#available-reports&quot; aria-label=&quot;available reports permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Available Reports&lt;/h2&gt;&lt;p&gt;This module provides the following VMware Cloud Foundation reports:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;Alert Report&lt;/code&gt;: Collects system alerts that are currently active across the VMware Cloud Foundation components.&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;Configuration Report&lt;/code&gt;: Collects information about the configuration settings in a VMware Cloud Foundation instance.&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;Health Report&lt;/code&gt;: he report contains detailed information about the health of the VMware Cloud Foundation system and its components by combining the SoS Utility health checks with additional health checks that were not previously available in earlier VMware Cloud Foundation releases.&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;Overview Report&lt;/code&gt;: Contains high-level information about the VMware Cloud Foundation system, can be used to provide a quick system overview.&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;Password Policy Report&lt;/code&gt;: Collects information about the password policy settings across VMware Cloud Foundation components.&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;Upgrade Pre-check Report&lt;/code&gt;: Initiates an upgrade precheck of a workload domain using the REST API and presents the results in an HTML report. &lt;/li&gt;&lt;/ul&gt;&lt;h2 id=&quot;installing-the-module&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#installing-the-module&quot; aria-label=&quot;installing the module permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Installing the Module&lt;/h2&gt;&lt;p&gt;There are a few pre-requisite/supporting modules required for the VCF reporting module, you can install them all using the below:&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;powershell&quot;&gt;&lt;pre class=&quot;language-powershell&quot;&gt;&lt;code class=&quot;language-powershell&quot;&gt;&lt;span class=&quot;token function&quot;&gt;Set-PSRepository&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Name PSGallery &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;InstallationPolicy Trusted
&lt;span class=&quot;token function&quot;&gt;Install-Module&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Name VMware&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;PowerCLI &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;MinimumVersion 12&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;4&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;1
&lt;span class=&quot;token function&quot;&gt;Install-Module&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Name VMware&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;vSphere&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;SsoAdmin &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;MinimumVersion 1&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;3&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;7
&lt;span class=&quot;token function&quot;&gt;Install-Module&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Name PowerVCF &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;MinimumVersion 2&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;2&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;0
&lt;span class=&quot;token function&quot;&gt;Install-Module&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Name PowerValidatedSolutions &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;MinimumVersion 1&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;7&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;0
&lt;span class=&quot;token function&quot;&gt;Install-Module&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Name VMware&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;CloudFoundation&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;Reporting&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Validate the reporting module has been installed by running&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;powershell&quot;&gt;&lt;pre class=&quot;language-powershell&quot;&gt;&lt;code class=&quot;language-powershell&quot;&gt;&lt;span class=&quot;token function&quot;&gt;Get-Command&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Module VMware&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;CloudFoundation&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;Reporting&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&quot;generate-reports&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#generate-reports&quot; aria-label=&quot;generate reports permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Generate Reports&lt;/h2&gt;&lt;p&gt;Replace the variable values with ones that suit your environment, &lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;powershell&quot;&gt;&lt;pre class=&quot;language-powershell&quot;&gt;&lt;code class=&quot;language-powershell&quot;&gt;&lt;span class=&quot;token variable&quot;&gt;$sddcManagerFqdn&lt;/span&gt; = &lt;span class=&quot;token string&quot;&gt;&amp;quot;sddc-manager.domain.com&amp;quot;&lt;/span&gt;
&lt;span class=&quot;token variable&quot;&gt;$sddcManagerUser&lt;/span&gt; = &lt;span class=&quot;token string&quot;&gt;&amp;quot;admin@local&amp;quot;&lt;/span&gt;
&lt;span class=&quot;token variable&quot;&gt;$sddcManagerPass&lt;/span&gt; = &lt;span class=&quot;token string&quot;&gt;&amp;quot;VMw@re1!VMw@re1!&amp;quot;&lt;/span&gt; 
&lt;span class=&quot;token variable&quot;&gt;$sddcManagerRootPass&lt;/span&gt; = &lt;span class=&quot;token string&quot;&gt;&amp;quot;VMw@re1!&amp;quot;&lt;/span&gt;

&lt;span class=&quot;token variable&quot;&gt;$reportPath&lt;/span&gt; = &lt;span class=&quot;token string&quot;&gt;&amp;quot;C:\VCF&amp;quot;&lt;/span&gt;

&lt;span class=&quot;token variable&quot;&gt;$mgmtWorkloadDomain&lt;/span&gt; = &lt;span class=&quot;token string&quot;&gt;&amp;quot;lon-m01&amp;quot;&lt;/span&gt;
&lt;span class=&quot;token variable&quot;&gt;$viWorkloadDomain&lt;/span&gt; = &lt;span class=&quot;token string&quot;&gt;&amp;quot;lon-w01&amp;quot;&lt;/span&gt;

&lt;span class=&quot;token comment&quot;&gt;#Overview report&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;Invoke-VcfOverviewReport&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;sddcManagerFqdn &lt;span class=&quot;token variable&quot;&gt;$sddcManagerFqdn&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;sddcManagerUser &lt;span class=&quot;token variable&quot;&gt;$sddcManagerUser&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;sddcManagerPass &lt;span class=&quot;token variable&quot;&gt;$sddcManagerPass&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;reportPath &lt;span class=&quot;token variable&quot;&gt;$reportPath&lt;/span&gt;

&lt;span class=&quot;token comment&quot;&gt;#Health report&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;Invoke-VcfHealthReport&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;sddcManagerFqdn &lt;span class=&quot;token variable&quot;&gt;$sddcManagerFqdn&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;sddcManagerUser &lt;span class=&quot;token variable&quot;&gt;$sddcManagerUser&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;sddcManagerPass &lt;span class=&quot;token variable&quot;&gt;$sddcManagerPass&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;sddcManagerRootPass &lt;span class=&quot;token variable&quot;&gt;$sddcManagerRootPass&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;reportPath &lt;span class=&quot;token variable&quot;&gt;$reportPath&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;allDomains

&lt;span class=&quot;token comment&quot;&gt;#Alert report&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;Invoke-VcfAlertReport&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;sddcManagerFqdn &lt;span class=&quot;token variable&quot;&gt;$sddcManagerFqdn&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;sddcManagerUser &lt;span class=&quot;token variable&quot;&gt;$sddcManagerUser&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;sddcManagerPass &lt;span class=&quot;token variable&quot;&gt;$sddcManagerPass&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;reportPath &lt;span class=&quot;token variable&quot;&gt;$reportPath&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;allDomains

&lt;span class=&quot;token comment&quot;&gt;#Password Policy report&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;Invoke-VcfPasswordPolicy&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;sddcManagerFqdn &lt;span class=&quot;token variable&quot;&gt;$sddcManagerFqdn&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;sddcManagerUser &lt;span class=&quot;token variable&quot;&gt;$sddcManagerUser&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;sddcManagerPass &lt;span class=&quot;token variable&quot;&gt;$sddcManagerPass&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;reportPath &lt;span class=&quot;token variable&quot;&gt;$reportPath&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;allDomains

&lt;span class=&quot;token comment&quot;&gt;#Configuration report&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;Invoke-VcfConfigReport&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;sddcManagerFqdn &lt;span class=&quot;token variable&quot;&gt;$sddcManagerFqdn&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;sddcManagerUser &lt;span class=&quot;token variable&quot;&gt;$sddcManagerUser&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;sddcManagerPass &lt;span class=&quot;token variable&quot;&gt;$sddcManagerPass&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;reportPath &lt;span class=&quot;token variable&quot;&gt;$reportPath&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;allDomains

&lt;span class=&quot;token comment&quot;&gt;#Upgrade pre-check report&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;Invoke-VcfUpgradePrecheck&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;sddcManagerFqdn &lt;span class=&quot;token variable&quot;&gt;$sddcManagerFqdn&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;sddcManagerUser &lt;span class=&quot;token variable&quot;&gt;$sddcManagerUser&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;sddcManagerPass &lt;span class=&quot;token variable&quot;&gt;$sddcManagerPass&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;reportPath &lt;span class=&quot;token variable&quot;&gt;$reportPath&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;workloadDomain &lt;span class=&quot;token variable&quot;&gt;$mgmtWorkloadDomain&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;Invoke-VcfUpgradePrecheck&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;sddcManagerFqdn &lt;span class=&quot;token variable&quot;&gt;$sddcManagerFqdn&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;sddcManagerUser &lt;span class=&quot;token variable&quot;&gt;$sddcManagerUser&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;sddcManagerPass &lt;span class=&quot;token variable&quot;&gt;$sddcManagerPass&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;reportPath &lt;span class=&quot;token variable&quot;&gt;$reportPath&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;workloadDomain &lt;span class=&quot;token variable&quot;&gt;$viWorkloadDomain&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&quot;bonus&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#bonus&quot; aria-label=&quot;bonus permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Bonus&lt;/h2&gt;&lt;p&gt;The reports can also be generated in dark mode using the &lt;code class=&quot;language-text&quot;&gt;-darkMode&lt;/code&gt; flag when running the Invoke Report cmdlets&lt;/p&gt;&lt;p&gt;You can &lt;code class=&quot;language-text&quot;&gt;Get-Help&lt;/code&gt; for the available cmdlets: &lt;code class=&quot;language-text&quot;&gt;Get-Help -Name Invoke-VcfConfigReport&lt;/code&gt;&lt;/p&gt;&lt;h2 id=&quot;preview&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#preview&quot; aria-label=&quot;preview permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Preview&lt;/h2&gt;&lt;p&gt;&lt;img src=&quot;/697873edc604ab6db0e7ab45a057c48b/VcfOverviewReport.png&quot; alt=&quot;VCF Overview Report&quot;/&gt; &lt;/p&gt;&lt;p&gt;&lt;img src=&quot;/d68832b8513373c12e680d98372f8523/VcfOverviewReportDark.png&quot; alt=&quot;VCF Overview Report (Dark Mode)&quot;/&gt; &lt;/p&gt;&lt;h2 id=&quot;references&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#references&quot; aria-label=&quot;references permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;References&lt;/h2&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;https://www.powershellgallery.com/packages/VMware.CloudFoundation.Reporting&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://www.powershellgallery.com/packages/VMware.CloudFoundation.Reporting&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</content:encoded><tags>vmware</tags><featuredImage>https://samperrin.com/static/2501455c64a887a24ab3eab5e8852efd/hero_7.jpg</featuredImage></item><item><title><![CDATA[vRA - Windows Cloudbase-init - Multi-part User Data Example]]></title><description><![CDATA[An example of Cloudbase-init that uses multi-part user data to run cloud-config and PowerShell code]]></description><link>https://samperrin.com/posts/vra-windows-cloudbase-init-multi-part-user-data-example/</link><guid isPermaLink="false">https://samperrin.com/posts/vra-windows-cloudbase-init-multi-part-user-data-example/</guid><category><![CDATA[automation]]></category><category><![CDATA[vmware]]></category><category><![CDATA[vra]]></category><category><![CDATA[vrealize]]></category><pubDate>Wed, 17 Aug 2022 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;The following blog post runs through a vRA Cloud Template that deploys a Windows server using Cloudbase-init Multi-part user data, including cloud-config and PowerShell code to configure various things.&lt;/p&gt;&lt;p&gt;This post is broken into 4 main sections…&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Cloud Template Inputs.&lt;/li&gt;&lt;li&gt;Cloud Template Resources.&lt;/li&gt;&lt;li&gt;Cloud-config for the Cloud.Machine resource.&lt;/li&gt;&lt;li&gt;A breakdown of the Cloud-config components.&lt;/li&gt;&lt;/ul&gt;&lt;h2 id=&quot;cloud-template-inputs&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#cloud-template-inputs&quot; aria-label=&quot;cloud template inputs permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Cloud Template Inputs&lt;/h2&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;yaml&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-yaml line-numbers&quot;&gt;&lt;code class=&quot;language-yaml&quot;&gt;&lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Windows
&lt;span class=&quot;token key atrule&quot;&gt;version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 0.0.66
&lt;span class=&quot;token key atrule&quot;&gt;formatVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;1&lt;/span&gt;
&lt;span class=&quot;token key atrule&quot;&gt;inputs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;image&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
    &lt;span class=&quot;token key atrule&quot;&gt;default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; windows&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;server&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;2019&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;standard
    &lt;span class=&quot;token key atrule&quot;&gt;title&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Operating System and Version
    &lt;span class=&quot;token key atrule&quot;&gt;oneOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;title&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Windows Server 2019 Standard
        &lt;span class=&quot;token key atrule&quot;&gt;const&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; windows&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;server&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;2019&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;standard
  &lt;span class=&quot;token key atrule&quot;&gt;flavor&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
    &lt;span class=&quot;token key atrule&quot;&gt;title&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Server Size
    &lt;span class=&quot;token key atrule&quot;&gt;oneOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;title&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Standard Small (2CPU&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; 8GB RAM)
        &lt;span class=&quot;token key atrule&quot;&gt;const&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; s1.small
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;title&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Standard Medium (2CPU&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; 16GB RAM)
        &lt;span class=&quot;token key atrule&quot;&gt;const&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; s1.medium
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;title&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Standard Large (4CPU&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; 16GB RAM)
        &lt;span class=&quot;token key atrule&quot;&gt;const&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; s1.large
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;title&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Standard Extra&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Large (4CPU&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; 32GB RAM)
        &lt;span class=&quot;token key atrule&quot;&gt;const&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; s1.xlarge
  &lt;span class=&quot;token key atrule&quot;&gt;serverUser&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
  &lt;span class=&quot;token key atrule&quot;&gt;serverPassword&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
    &lt;span class=&quot;token key atrule&quot;&gt;encrypted&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;title&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Server Password
  &lt;span class=&quot;token key atrule&quot;&gt;serverCount&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
    &lt;span class=&quot;token key atrule&quot;&gt;maximum&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;5&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;minimum&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;1&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;1&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;title&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Number of Servers
  &lt;span class=&quot;token key atrule&quot;&gt;dataDisk1Size&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
    &lt;span class=&quot;token key atrule&quot;&gt;title&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Data Disk Size
    &lt;span class=&quot;token key atrule&quot;&gt;minimum&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;0&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;maximum&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;1000&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;0&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;domainPassword&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
    &lt;span class=&quot;token key atrule&quot;&gt;readOnly&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;false&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;encrypted&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&quot;cloud-template-resources&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#cloud-template-resources&quot; aria-label=&quot;cloud template resources permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Cloud Template Resources&lt;/h2&gt;&lt;p&gt;We have configured 3x resources on our Cloud Template, 1x Cloud.Volume (labelled &lt;code class=&quot;language-text&quot;&gt;DataDisk&lt;/code&gt;), 1x Cloud.Network (labelled &lt;code class=&quot;language-text&quot;&gt;Network&lt;/code&gt;) and 1x Cloud.Machine (labelled &lt;code class=&quot;language-text&quot;&gt;Server&lt;/code&gt;). &lt;/p&gt;&lt;p&gt;There are some specific properties worth calling out…&lt;/p&gt;&lt;ol&gt;&lt;li&gt;On the &lt;code class=&quot;language-text&quot;&gt;Server&lt;/code&gt; resource &lt;code class=&quot;language-text&quot;&gt;customizeGuestOs: false&lt;/code&gt; - this stops vRA customising the VM, this would usually configure the VM Name and IP by creating a temporary customisation spec at deployment time. &lt;/li&gt;&lt;li&gt;On the &lt;code class=&quot;language-text&quot;&gt;Server&lt;/code&gt; resource &lt;code class=&quot;language-text&quot;&gt;assignment: static&lt;/code&gt; - this pulls an IP from vRA’s IPAM. &lt;/li&gt;&lt;/ol&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;yaml&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-yaml line-numbers&quot;&gt;&lt;code class=&quot;language-yaml&quot;&gt;&lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;DataDisk&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Cloud.Volume
    &lt;span class=&quot;token key atrule&quot;&gt;allocatePerInstance&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;capacityGb&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; $&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;input.dataDisk1Size&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;count&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${input.dataDisk1Size == 0 ? 0 : input.serverCount}&amp;#x27;&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;Network&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Cloud.Network
    &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;networkType&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; outbound
      &lt;span class=&quot;token key atrule&quot;&gt;constraints&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;tag&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; network.isolated&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;Server&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Cloud.Machine
    &lt;span class=&quot;token key atrule&quot;&gt;allocatePerInstance&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;customizeGuestOs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;false&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;image&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; $&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;input.image&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;flavor&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; $&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;input.flavor&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;count&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; $&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;input.serverCount&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;attachedDisks&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; $&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;map_to_object(slice(resource.DataDisk&lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;*&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;.id&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; count.index&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; count.index + 1)&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &amp;quot;source&amp;quot;)&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;constraints&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;tag&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; cloud.zone.region&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;dc3
      &lt;span class=&quot;token key atrule&quot;&gt;networks&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;network&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; $&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;resource.Network.id&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;assignment&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; static
      &lt;span class=&quot;token key atrule&quot;&gt;cloudConfig&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token comment&quot;&gt;#see below section&lt;/span&gt;&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:501px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:68.8622754491018%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAOCAYAAAAvxDzwAAAACXBIWXMAAA7DAAAOwwHHb6hkAAABVklEQVQ4y5VT2Y6DMAzk/z9x+7S7qlTR5r5JwqxsQkX3pdTSiBCb8TFmWtcV70AWYoLUGlKbAf2ENhYpZ46d3pOtKMsCpQ2MtXA+wDoHHwJCjPAhQmgD6zzHTmeqo+zX6xXzPMM7B6M1WmvsowhhLCcle0+4rliWyi0TMUEbgxDi9p4yYkob+ZmW9ypLKdyWCwFCqu3sA5z33D5VeJqw1gbjPIx1TDTfHywGvRPkmOFpwqVWfF0u+P35hpCS29+t0wy1Rc75kxkumO93VjmXAqU1YkwoZUHKBdb7Z/ypCgmdWm+NYYzhimqtnKz1/jnhUaA8lni3o58Je+9cQd/PAxz07wPey5TYfyTDTkibvm18GNufEHm3MivLLbXGoHaJyPvX+yMmqRTE4wGlNIQQT7UoKalHd0ophhzP2+32cs8+KWGtpQoD/4+kHikWx+YTyHec1Rn7A3b5SgBn1jvVAAAAAElFTkSuQmCC&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;vRA Cloud Template&quot; title=&quot;vRA Cloud Template&quot; src=&quot;/static/836c4bc9d10a8e5ee9c933798aedddbd/56272/cloud-template.png&quot; srcSet=&quot;/static/836c4bc9d10a8e5ee9c933798aedddbd/56272/cloud-template.png 501w&quot; sizes=&quot;(max-width: 501px) 100vw, 501px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;vRA Cloud Template&lt;/figcaption&gt;
  &lt;/figure&gt; &lt;/p&gt;&lt;h2 id=&quot;cloudbase-init-cloud-config&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#cloudbase-init-cloud-config&quot; aria-label=&quot;cloudbase init cloud config permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Cloudbase-Init (Cloud Config)&lt;/h2&gt;&lt;p&gt;This cloudConfig utilises the multi-part user data (&lt;a href=&quot;https://cloudbase-init.readthedocs.io/en/latest/userdata.html#multi-part-content&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;Multi-part content&lt;/a&gt;), this allows us to run a variety of content types, including cloud-config and PowerShell scripts. &lt;/p&gt;&lt;p&gt;The example below uses a combination of Inputs and Property Groups to get its data. The cloudConfig does the following:&lt;/p&gt;&lt;ol&gt;&lt;li&gt;Sets virtual machine hostname using cloud-config.&lt;/li&gt;&lt;li&gt;Creates a local user based on two inputs, one for the username, one for the password and then adds that user to the Administrators group.&lt;/li&gt;&lt;li&gt;Enables the “Remote Desktop” and “ICMPv4-In” firewall rules.&lt;/li&gt;&lt;li&gt;Sets some Registry Key values.&lt;/li&gt;&lt;li&gt;Formats the additional disk that was added in the Cloud Template.&lt;/li&gt;&lt;li&gt;Configures various network adapter settings, including the IP and DNS.&lt;/li&gt;&lt;li&gt;Sleeps between setting the network and Domain Join. &lt;/li&gt;&lt;li&gt;Joins the server to the Domain. &lt;/li&gt;&lt;li&gt;Removes any reference to entered passwords from the Cloudbase-init log files. &lt;/li&gt;&lt;li&gt;Ejects any CD-ROMs. &lt;/li&gt;&lt;li&gt;Reboots the server. &lt;/li&gt;&lt;/ol&gt;&lt;p&gt;The virtual machine template is running Windows Server 2019, it has Cloudbase-init installed with the Cloudbase-init service set to &lt;strong&gt;“Automatic (Delayed)”&lt;/strong&gt;. The Sysprep options were also unchecked on the Cloudbase-init installer. Refer to &lt;a href=&quot;https://twitter.com/mpoore&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;Michael Poore’s&lt;/a&gt; blog post on this -  &lt;a href=&quot;https://blog.v12n.io/installing-cloudbase-init-on-windows-for-vra-customisation/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;Installing Cloudbase-Init on Windows for vRA Customisation&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;Below is the Cloud-config in full, we break down each section at the bottom. &lt;/p&gt;&lt;h2 id=&quot;cloud-config-in-full&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#cloud-config-in-full&quot; aria-label=&quot;cloud config in full permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Cloud-config in full&lt;/h2&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;yaml&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-yaml line-numbers&quot;&gt;&lt;code class=&quot;language-yaml&quot;&gt;&lt;span class=&quot;token key atrule&quot;&gt;cloudConfig&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt;
&lt;span class=&quot;token key atrule&quot;&gt;Content-Type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; multipart/mixed; boundary=&amp;quot;==NewPart==&amp;quot;
&lt;span class=&quot;token key atrule&quot;&gt;MIME-Version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;1.0&lt;/span&gt;

&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;==NewPart==
&lt;span class=&quot;token key atrule&quot;&gt;Content-Type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; text/cloud&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;config; charset=&amp;quot;us&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;ascii&amp;quot;
&lt;span class=&quot;token key atrule&quot;&gt;MIME-Version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;1.0&lt;/span&gt;
&lt;span class=&quot;token key atrule&quot;&gt;Content-Transfer-Encoding&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 7bit
&lt;span class=&quot;token key atrule&quot;&gt;Content-Disposition&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; attachment; filename=&amp;quot;cloud&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;config&amp;quot;

&lt;span class=&quot;token key atrule&quot;&gt;set_hostname&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; $&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;self.resourceName&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;

&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;==NewPart==
&lt;span class=&quot;token key atrule&quot;&gt;Content-Type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; text/x&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;shellscript; charset=&amp;quot;us&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;ascii&amp;quot;
&lt;span class=&quot;token key atrule&quot;&gt;MIME-Version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;1.0&lt;/span&gt;
&lt;span class=&quot;token key atrule&quot;&gt;Content-Transfer-Encoding&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 7bit
&lt;span class=&quot;token key atrule&quot;&gt;Content-Disposition&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; attachment; filename=&amp;quot;INIT.ps1&amp;quot;

&lt;span class=&quot;token comment&quot;&gt;#ps1_sysnative&lt;/span&gt;

$localUserPassword = ConvertTo&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;SecureString $&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;input.serverPassword&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;AsPlainText &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Force
New&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;LocalUser &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Name &amp;quot;$&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;input.serverUser&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Password $localUserPassword
Add&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;LocalGroupMember &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Group &amp;quot;Administrators&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Member &amp;quot;$&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;input.serverUser&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&amp;quot;

Set&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;NetFirewallRule &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;DisplayName &amp;quot;File and Printer Sharing (Echo Request &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; ICMPv4&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;In)&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;enabled True
Enable&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;NetFirewallRule &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;DisplayGroup &amp;quot;Remote Desktop&amp;quot;

Set&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;ItemProperty &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Path &amp;#x27;HKLM&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters&amp;#x27; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Name &amp;#x27;NV Domain&amp;#x27; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Value &amp;quot;$&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;propgroup.defaultServerValues.fqdnDomain&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&amp;quot;
Set&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;ItemProperty &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Path &amp;#x27;HKLM&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters&amp;#x27; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Name SyncDomainWithMembership &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Value &amp;quot;0&amp;quot;
Set&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;ItemProperty &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Path &amp;#x27;HKLM&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;\System\CurrentControlSet\Control\Terminal Server&amp;#x27; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;name &amp;quot;fDenyTSConnections&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;value 0

Get&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Disk &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; Where&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Object PartitionStyle &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Eq &amp;quot;RAW&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; Initialize&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Disk &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;PassThru &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; New&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Partition &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;AssignDriveLetter &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;UseMaximumSize &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; Format&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Volume &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;NewFileSystemLabel &amp;quot;DATA&amp;quot;

Get&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;NetAdapter &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; Set&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;DnsClient &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;RegisterThisConnectionsAddress $False
Get&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;NetAdapter &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; Set&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;DnsClient &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;UseSuffixWhenRegistering $False
Get&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;NetAdapter &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; Set&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;DnsClient &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;ConnectionSpecificSuffix $&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;propgroup.defaultServerValues.fqdnDomain&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
Set&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;DnsClientGlobalSetting &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;SuffixSearchList @(&amp;quot;domain.com&amp;quot;)

$adapter = Get&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;NetAdapter &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;?&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; $_.Name &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;eq &amp;quot;Ethernet0&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
$adapter &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; Remove&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;NetIpAddress &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Confirm&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;$false
$adapter &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; Remove&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;NetRoute &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Confirm&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;$false
$adapter &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; New&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;NetIpAddress &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;IPAddress $&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;self.networks&lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;0&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;.address&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;PrefixLength $&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;resource.Network.prefixLength&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;DefaultGateway $&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;resource.Network.gateway&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
$adapter &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; Set&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;DnsClientServerAddress &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;ServerAddresses(&amp;quot;$&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;join(resource.Network.dns&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;&amp;#x27;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &amp;#x27;)&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&amp;quot;)
$adapter &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; Disable&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;NetAdapterBinding &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;ComponentID ms_tcpip6

Start&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Sleep &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Seconds 10

$domainJoinCreds = New&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Object System.Management.Automation.PSCredential &amp;quot;$&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;propgroup.defaultServerValues.windowsDomainJoinUsername&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;@$&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;propgroup.defaultServerValues.windowsDomain&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;(ConvertTo&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;SecureString &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;String &amp;quot;$&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;input.domainPassword&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;AsPlainText &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Force)
Add&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Computer &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;DomainName &amp;quot;$&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;propgroup.defaultServerValues.windowsDomain&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Credential $domainJoinCreds &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Server &amp;quot;$&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;propgroup.defaultServerValues.windowsDomainServerDc3&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Restart&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;$false &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Force

(Get&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Content &amp;quot;C&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;\Program Files\Cloudbase Solutions\Cloudbase&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Init\log\cloudbase&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;init.log&amp;quot;) &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;replace &amp;quot;$&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;input.domainPassword&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;&amp;quot;&amp;lt;DOMAIN&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;JOIN&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;PASSWORD&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; Set&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Content &amp;quot;C&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;\Program Files\Cloudbase Solutions\Cloudbase&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Init\log\cloudbase&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;init.log&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Verbose
(Get&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Content &amp;quot;C&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;\Program Files\Cloudbase Solutions\Cloudbase&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Init\log\cloudbase&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;init.log&amp;quot;) &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;replace &amp;quot;$&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;input.serverPassword&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;&amp;quot;&amp;lt;LOCAL&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;USER&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;PASSWORD&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; Set&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Content &amp;quot;C&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;\Program Files\Cloudbase Solutions\Cloudbase&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Init\log\cloudbase&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;init.log&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Verbose

$drives = Get&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;WmiObject Win32_Volume &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Filter &amp;quot;DriveType=5&amp;quot;
$drives &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; ForEach&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Object &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; (New&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Object &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;ComObject Shell.Application).Namespace(17).ParseName($_.Name).InvokeVerb(&amp;quot;Eject&amp;quot;) &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;ErrorAction SilentlyContinue

shutdown /r /t 10&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&quot;identify-multi-part-boundary&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#identify-multi-part-boundary&quot; aria-label=&quot;identify multi part boundary permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Identify Multi-part boundary&lt;/h2&gt;&lt;p&gt;We establish our multi-part boundary, which tells cloudConfig where a new type starts. Our boundary parameter is &lt;code class=&quot;language-text&quot;&gt;==NewPart==&lt;/code&gt;. &lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;yaml&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-yaml line-numbers&quot;&gt;&lt;code class=&quot;language-yaml&quot;&gt;&lt;span class=&quot;token key atrule&quot;&gt;cloudConfig&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt;
&lt;span class=&quot;token key atrule&quot;&gt;Content-Type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; multipart/mixed; boundary=&amp;quot;==NewPart==&amp;quot;
&lt;span class=&quot;token key atrule&quot;&gt;MIME-Version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;1.0&lt;/span&gt;&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&quot;cloud-config-section&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#cloud-config-section&quot; aria-label=&quot;cloud config section permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Cloud-config Section&lt;/h2&gt;&lt;p&gt;Our new section requires the use of our boundary parameter, this boundary also requires a prefix of &lt;code class=&quot;language-text&quot;&gt;--&lt;/code&gt;. In this section we set the virtual machine hostname using a reference the the resource itself - in otherwords, whatever the VM is called (based on Custom Names in vRA) we push it into the cloud-config section. This seems to automatically reboot the VM after the hostname is set.&lt;/p&gt;&lt;p&gt;In this section we specify the filename as &lt;em&gt;cloud-config&lt;/em&gt; - &lt;code class=&quot;language-text&quot;&gt;Content-Disposition: attachment; filename=&amp;quot;cloud-config&amp;quot;&lt;/code&gt;. We can any cloud-config related commands in here. Refer to the Cloudbase-init docs for information - &lt;a href=&quot;https://cloudbase-init.readthedocs.io/en/latest/userdata.html#cloud-config&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;#cloud-config&lt;/a&gt;.&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;yaml&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-yaml line-numbers&quot;&gt;&lt;code class=&quot;language-yaml&quot;&gt;&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;==NewPart==
&lt;span class=&quot;token key atrule&quot;&gt;Content-Type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; text/cloud&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;config; charset=&amp;quot;us&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;ascii&amp;quot;
&lt;span class=&quot;token key atrule&quot;&gt;MIME-Version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;1.0&lt;/span&gt;
&lt;span class=&quot;token key atrule&quot;&gt;Content-Transfer-Encoding&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 7bit
&lt;span class=&quot;token key atrule&quot;&gt;Content-Disposition&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; attachment; filename=&amp;quot;cloud&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;config&amp;quot;

&lt;span class=&quot;token key atrule&quot;&gt;set_hostname&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; $&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;self.resourceName&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&quot;start-of-the-powershell-section&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#start-of-the-powershell-section&quot; aria-label=&quot;start of the powershell section permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Start of the PowerShell Section&lt;/h2&gt;&lt;p&gt;This section is the start of our PowerShell code, again we use our boundary and its double-dash prefix &lt;code class=&quot;language-text&quot;&gt;--==NewPart==&lt;/code&gt;. Again we set a filename but this time with the file extension &lt;em&gt;.ps1&lt;/em&gt; - &lt;code class=&quot;language-text&quot;&gt;Content-Disposition: attachment; filename=&amp;quot;INIT.ps1&amp;quot;&lt;/code&gt;. The addition of &lt;code class=&quot;language-text&quot;&gt;#ps1_sysnative&lt;/code&gt; tells cloudConfig what executable to use. Refer to the Cloudbase-init docs for information - &lt;a href=&quot;https://cloudbase-init.readthedocs.io/en/latest/userdata.html#powershell&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;#powershell&lt;/a&gt;.&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;yaml&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-yaml line-numbers&quot;&gt;&lt;code class=&quot;language-yaml&quot;&gt;&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;==NewPart==
&lt;span class=&quot;token key atrule&quot;&gt;Content-Type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; text/x&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;shellscript; charset=&amp;quot;us&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;ascii&amp;quot;
&lt;span class=&quot;token key atrule&quot;&gt;MIME-Version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;1.0&lt;/span&gt;
&lt;span class=&quot;token key atrule&quot;&gt;Content-Transfer-Encoding&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 7bit
&lt;span class=&quot;token key atrule&quot;&gt;Content-Disposition&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; attachment; filename=&amp;quot;INIT.ps1&amp;quot;

&lt;span class=&quot;token comment&quot;&gt;#ps1_sysnative&lt;/span&gt;&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&quot;local-user-creation&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#local-user-creation&quot; aria-label=&quot;local user creation permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Local User Creation&lt;/h2&gt;&lt;p&gt;We utilise the Inputs for serverPassword and serverUser to add and configure our local user. &lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;powershell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-powershell line-numbers&quot;&gt;&lt;code class=&quot;language-powershell&quot;&gt;&lt;span class=&quot;token variable&quot;&gt;$localUserPassword&lt;/span&gt; = &lt;span class=&quot;token function&quot;&gt;ConvertTo-SecureString&lt;/span&gt; $&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;input&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;serverPassword&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;AsPlainText &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Force
&lt;span class=&quot;token function&quot;&gt;New-LocalUser&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Name &lt;span class=&quot;token string&quot;&gt;&amp;quot;${input.serverUser}&amp;quot;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Password &lt;span class=&quot;token variable&quot;&gt;$localUserPassword&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;Add-LocalGroupMember&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;Group&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;Administrators&amp;quot;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Member &lt;span class=&quot;token string&quot;&gt;&amp;quot;${input.serverUser}&amp;quot;&lt;/span&gt;&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&quot;set-firewall-rules&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#set-firewall-rules&quot; aria-label=&quot;set firewall rules permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Set Firewall Rules&lt;/h2&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;powershell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-powershell line-numbers&quot;&gt;&lt;code class=&quot;language-powershell&quot;&gt;&lt;span class=&quot;token function&quot;&gt;Set-NetFirewallRule&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;DisplayName &lt;span class=&quot;token string&quot;&gt;&amp;quot;File and Printer Sharing (Echo Request - ICMPv4-In)&amp;quot;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;enabled True
&lt;span class=&quot;token function&quot;&gt;Enable-NetFirewallRule&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;DisplayGroup &lt;span class=&quot;token string&quot;&gt;&amp;quot;Remote Desktop&amp;quot;&lt;/span&gt;&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&quot;set-registry-values&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#set-registry-values&quot; aria-label=&quot;set registry values permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Set Registry Values&lt;/h2&gt;&lt;p&gt;We utilise values from a Property Group called &lt;code class=&quot;language-text&quot;&gt;defaultServerValues&lt;/code&gt; and specifically the value of property &lt;code class=&quot;language-text&quot;&gt;fqdnDomain&lt;/code&gt;. An example value could be &lt;code class=&quot;language-text&quot;&gt;domain.com&lt;/code&gt;.&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;powershell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-powershell line-numbers&quot;&gt;&lt;code class=&quot;language-powershell&quot;&gt;&lt;span class=&quot;token function&quot;&gt;Set-ItemProperty&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Path &lt;span class=&quot;token string&quot;&gt;&amp;#x27;HKLM:\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters&amp;#x27;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Name &lt;span class=&quot;token string&quot;&gt;&amp;#x27;NV Domain&amp;#x27;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Value &lt;span class=&quot;token string&quot;&gt;&amp;quot;${propgroup.defaultServerValues.fqdnDomain}&amp;quot;&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;Set-ItemProperty&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Path &lt;span class=&quot;token string&quot;&gt;&amp;#x27;HKLM:\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters&amp;#x27;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Name SyncDomainWithMembership &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Value &lt;span class=&quot;token string&quot;&gt;&amp;quot;0&amp;quot;&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;Set-ItemProperty&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Path &lt;span class=&quot;token string&quot;&gt;&amp;#x27;HKLM:\System\CurrentControlSet\Control\Terminal Server&amp;#x27;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;name &lt;span class=&quot;token string&quot;&gt;&amp;quot;fDenyTSConnections&amp;quot;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;value 0&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&quot;format-additional-disk&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#format-additional-disk&quot; aria-label=&quot;format additional disk permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Format Additional Disk&lt;/h2&gt;&lt;p&gt;This code looks for all disks that have a matching partition style and then initialises them before applying a driver letter and label. We only add a single disk in this Cloud Template, hence a single label - if you add more than one disk you will need to adapt the code to suit. &lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;powershell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-powershell line-numbers&quot;&gt;&lt;code class=&quot;language-powershell&quot;&gt;&lt;span class=&quot;token function&quot;&gt;Get-Disk&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;Where-Object&lt;/span&gt; PartitionStyle &lt;span class=&quot;token operator&quot;&gt;-Eq&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;RAW&amp;quot;&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;Initialize-Disk&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;PassThru &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;New-Partition&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;AssignDriveLetter &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;UseMaximumSize &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;Format-Volume&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;NewFileSystemLabel &lt;span class=&quot;token string&quot;&gt;&amp;quot;DATA&amp;quot;&lt;/span&gt;&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&quot;configure-network-dns-client-settings&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#configure-network-dns-client-settings&quot; aria-label=&quot;configure network dns client settings permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Configure Network DNS Client Settings&lt;/h2&gt;&lt;p&gt;Again we utilise values from a Property Group called &lt;code class=&quot;language-text&quot;&gt;defaultServerValues&lt;/code&gt; and specifically the value of property &lt;code class=&quot;language-text&quot;&gt;fqdnDomain&lt;/code&gt;. An example value could be &lt;code class=&quot;language-text&quot;&gt;domain.com&lt;/code&gt;.&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;powershell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-powershell line-numbers&quot;&gt;&lt;code class=&quot;language-powershell&quot;&gt;&lt;span class=&quot;token function&quot;&gt;Get-NetAdapter&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;Set-DnsClient&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;RegisterThisConnectionsAddress &lt;span class=&quot;token boolean&quot;&gt;$False&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;Get-NetAdapter&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;Set-DnsClient&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;UseSuffixWhenRegistering &lt;span class=&quot;token boolean&quot;&gt;$False&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;Get-NetAdapter&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;Set-DnsClient&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;ConnectionSpecificSuffix $&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;propgroup&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;defaultServerValues&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;fqdnDomain&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;Set-DnsClientGlobalSetting&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;SuffixSearchList @&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;domain.com&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&quot;configure-network-dns-client-settings-1&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#configure-network-dns-client-settings-1&quot; aria-label=&quot;configure network dns client settings 1 permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Configure Network DNS Client Settings&lt;/h2&gt;&lt;p&gt;Our virtual machine template includes a single network adapter with the label Ethernet0, we first identify this network adapter object and we then configure the required values, including IP and DNS. &lt;/p&gt;&lt;p&gt;Within this Cloud Template we have configure the Machine resource to have &lt;code class=&quot;language-text&quot;&gt;assignment: static&lt;/code&gt; for it’s networking, so we are allocating an IP address from vRA’s IPAM. &lt;/p&gt;&lt;p&gt;On line 4 below we retrieve the IP address assigned to the virtual machine - &lt;code class=&quot;language-text&quot;&gt;${self.networks[0].address}&lt;/code&gt;. For prefix and default gateway values we reference the attached Network resource - &lt;code class=&quot;language-text&quot;&gt;${resource.Network.prefixLength}&lt;/code&gt; and &lt;code class=&quot;language-text&quot;&gt;${resource.Network.gateway}&lt;/code&gt;. &lt;/p&gt;&lt;p&gt;Finally for line 5 we pull out the attached Networks DNS servers &lt;code class=&quot;language-text&quot;&gt;${join(resource.Network.dns,&amp;#x27;, &amp;#x27;)}&lt;/code&gt;. In this particular variable we also utilise one of vRA’s supported expression syntaxes &lt;code class=&quot;language-text&quot;&gt;join&lt;/code&gt;. &lt;a href=&quot;https://docs.vmware.com/en/vRealize-Automation/services/Using-and-Managing-Cloud-Assembly/GUID-12F0BC64-6391-4E5F-AA48-C5959024F3EB.html&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;Cloud Assembly expression syntax&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:548px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:123.54014598540147%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAZCAIAAAC+dZmEAAAACXBIWXMAAA7DAAAOwwHHb6hkAAACA0lEQVQ4y41UCY4bIRDk/+9MFO96uOkDusHRwNo7PuJNCY1GDaUuigITQ/zz+5e19uN0+jx/hhAv/w3Taq3MY3RV7b2PMXrvMqGqP5BjjIB0LNVaU0oxRSL6gcxMAABl/1zG2Ml7qRARIsnb5gYAQgg5pxjjIjcskCIglgLvle+ynXPbtnnvb7Kd93FKDz6klI6EMb+ZJbMYQsy5LKtuCxZW8VD/NgW4Vu0GAVLKx7nltqqKSHuCiHjnfAbWvu/ZeweIq+PlchGRtDsQEfBbxhV9rilVoIlhopwzE+tst8g555QzAK7+z6japQ9TStmsPZ/Pp9PJOTe3xNbazW6AoL2L6vNY52IQ0AfPXL/3PMaetb5n7pnW9iAqNiFRw8w551rbg2Fyjeg7MkCxEx+fH+uolyu3o3qp/CqbKKUEALebUFv1wYcQYore+1xKfQKLNu0mpWytTSndwoCEbiKmZO22Z/4evWtEhqrmYWKM0UQeKv2AMcaerqnREFEpBREBgJnXORMRMa/BtT6MvdhEejc5Z2tdCN45m3Ne0e1voSLhpexpWLtbeo/eOxGLTNnHS7P+m8jUO+Vx1WeITLfHi84iAlAQEEo5Ju94n6EpNv0XeQcS1fqajE2pqVnbOE635fZuOLWbefdPAotW6cZ7764P0NcEcQwTMaSc1y/OC//whv0FeCC7VbxuUHMAAAAASUVORK5CYII=&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;vRA Network Settings&quot; title=&quot;vRA Network Settings&quot; src=&quot;/static/75691bf1f2b2dfcb36207ad50de9de89/9079b/network-settings.png&quot; srcSet=&quot;/static/75691bf1f2b2dfcb36207ad50de9de89/9079b/network-settings.png 548w&quot; sizes=&quot;(max-width: 548px) 100vw, 548px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;vRA Network Settings&lt;/figcaption&gt;
  &lt;/figure&gt; &lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;powershell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-powershell line-numbers&quot;&gt;&lt;code class=&quot;language-powershell&quot;&gt;&lt;span class=&quot;token variable&quot;&gt;$adapter&lt;/span&gt; = &lt;span class=&quot;token function&quot;&gt;Get-NetAdapter&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; ? &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; &lt;span class=&quot;token variable&quot;&gt;$_&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;Name &lt;span class=&quot;token operator&quot;&gt;-eq&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;Ethernet0&amp;quot;&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
&lt;span class=&quot;token variable&quot;&gt;$adapter&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;Remove-NetIpAddress&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Confirm:&lt;span class=&quot;token boolean&quot;&gt;$false&lt;/span&gt;
&lt;span class=&quot;token variable&quot;&gt;$adapter&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;Remove-NetRoute&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Confirm:&lt;span class=&quot;token boolean&quot;&gt;$false&lt;/span&gt;
&lt;span class=&quot;token variable&quot;&gt;$adapter&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;New-NetIpAddress&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;IPAddress $&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;self&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;networks&lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;0&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;address&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;PrefixLength $&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;resource&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;Network&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;prefixLength&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;DefaultGateway $&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;resource&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;Network&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;gateway&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
&lt;span class=&quot;token variable&quot;&gt;$adapter&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;Set-DnsClientServerAddress&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;ServerAddresses&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;${join(resource.Network.dns,&amp;#x27;, &amp;#x27;)}&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;
&lt;span class=&quot;token variable&quot;&gt;$adapter&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;Disable-NetAdapterBinding&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;ComponentID ms_tcpip6&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&quot;sleep&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#sleep&quot; aria-label=&quot;sleep permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Sleep&lt;/h2&gt;&lt;p&gt;There is a slight delay between configuring the network and it being available, you could probably change this to a loop that better monitors the network status but during testing we found good success at the 10 second mark. &lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;powershell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-powershell line-numbers&quot;&gt;&lt;code class=&quot;language-powershell&quot;&gt;&lt;span class=&quot;token function&quot;&gt;Start-Sleep&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Seconds 10&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&quot;join-active-directory-domain&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#join-active-directory-domain&quot; aria-label=&quot;join active directory domain permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Join Active Directory Domain&lt;/h2&gt;&lt;p&gt;Within vRA we have configured Active Directory integration and we have made it available to all of the Projects that require it. This creates the Computer Object in our specified OU, which leaves us to only do the domain joining from within the deployed guest OS. &lt;/p&gt;&lt;p&gt;We utilise more Property Group values in this code as well as an additional Input for the &lt;code class=&quot;language-text&quot;&gt;domainPassword&lt;/code&gt;, our specific approach for this Input was to provide a Default Value for it on the Custom Form and set the &lt;strong&gt;Visibility&lt;/strong&gt; to &lt;strong&gt;No&lt;/strong&gt;, this way the user does not see it. The reason for this approach is because Secrets cannot be shared across the Organization, they are Project specific, which would have caused us to have multiple copies of this specific value (1x per Project). &lt;/p&gt;&lt;p&gt;In the first line we create a PowerShell Credentials object by using two Property Group values &lt;code class=&quot;language-text&quot;&gt;${propgroup.defaultServerValues.windowsDomainJoinUsername}&lt;/code&gt; and &lt;code class=&quot;language-text&quot;&gt;${propgroup.defaultServerValues.windowsDomain}&lt;/code&gt;, in combination with the &lt;code class=&quot;language-text&quot;&gt;@&lt;/code&gt; symbol we construct a UPN that will be used for the domain join, such as &lt;code class=&quot;language-text&quot;&gt;user@example.com&lt;/code&gt;, the second part of the Credentials object is the &lt;code class=&quot;language-text&quot;&gt;domainPassword&lt;/code&gt; value. &lt;/p&gt;&lt;p&gt;This Credentials object is then used on the second line along with some additional Property Group values, &lt;code class=&quot;language-text&quot;&gt;${propgroup.defaultServerValues.windowsDomain}&lt;/code&gt;, for example &lt;code class=&quot;language-text&quot;&gt;ad.domain.com&lt;/code&gt; and &lt;code class=&quot;language-text&quot;&gt;${propgroup.defaultServerValues.windowsDomainServerDc3}&lt;/code&gt; which is a specific server that we want to talk to, such as &lt;code class=&quot;language-text&quot;&gt;server1.ad.domain.com&lt;/code&gt; - this input is not required normally, but due to some network constraints we need to speak to a specific server. &lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;powershell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-powershell line-numbers&quot;&gt;&lt;code class=&quot;language-powershell&quot;&gt;&lt;span class=&quot;token variable&quot;&gt;$domainJoinCreds&lt;/span&gt; = &lt;span class=&quot;token function&quot;&gt;New-Object&lt;/span&gt; System&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;Management&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;Automation&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;PSCredential &lt;span class=&quot;token string&quot;&gt;&amp;quot;${propgroup.defaultServerValues.windowsDomainJoinUsername}@${propgroup.defaultServerValues.windowsDomain}&amp;quot;&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;ConvertTo-SecureString&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;String &lt;span class=&quot;token string&quot;&gt;&amp;quot;${input.domainPassword}&amp;quot;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;AsPlainText &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Force&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;Add-Computer&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;DomainName &lt;span class=&quot;token string&quot;&gt;&amp;quot;${propgroup.defaultServerValues.windowsDomain}&amp;quot;&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Credential &lt;span class=&quot;token variable&quot;&gt;$domainJoinCreds&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Server &lt;span class=&quot;token string&quot;&gt;&amp;quot;${propgroup.defaultServerValues.windowsDomainServerDc3}&amp;quot;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Restart:&lt;span class=&quot;token boolean&quot;&gt;$false&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Force&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&quot;clean-the-cloudbase-init-log-files&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#clean-the-cloudbase-init-log-files&quot; aria-label=&quot;clean the cloudbase init log files permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Clean the Cloudbase-init Log Files&lt;/h2&gt;&lt;p&gt;Due to the configured logging level of Cloudbase-init we can see the inputted passwords in clear text. We run the below PowerShell code to look for the Input values for &lt;code class=&quot;language-text&quot;&gt;domainPassword&lt;/code&gt; and &lt;code class=&quot;language-text&quot;&gt;serverPassword&lt;/code&gt; and replace them with some placeholder values - &lt;code class=&quot;language-text&quot;&gt;&amp;lt;DOMAIN-JOIN-PASSWORD&amp;gt;&lt;/code&gt; and &lt;code class=&quot;language-text&quot;&gt;&amp;lt;LOCAL-USER-PASSWORD&amp;gt;&lt;/code&gt;. An alternative would be to change the Cloudbase-init logging level. &lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;powershell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-powershell line-numbers&quot;&gt;&lt;code class=&quot;language-powershell&quot;&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;Get-Content&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;C:\Program Files\Cloudbase Solutions\Cloudbase-Init\log\cloudbase-init.log&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-replace&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;${input.domainPassword}&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;lt;DOMAIN-JOIN-PASSWORD&amp;gt;&amp;quot;&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;Set-Content&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;C:\Program Files\Cloudbase Solutions\Cloudbase-Init\log\cloudbase-init.log&amp;quot;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Verbose
&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;Get-Content&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;C:\Program Files\Cloudbase Solutions\Cloudbase-Init\log\cloudbase-init.log&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-replace&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;${input.serverPassword}&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;lt;LOCAL-USER-PASSWORD&amp;gt;&amp;quot;&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;Set-Content&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;C:\Program Files\Cloudbase Solutions\Cloudbase-Init\log\cloudbase-init.log&amp;quot;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;Verbose&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&quot;eject-cd-rom&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#eject-cd-rom&quot; aria-label=&quot;eject cd rom permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Eject CD-ROM&lt;/h2&gt;&lt;p&gt;We remove the Cloud-config attached CD-ROM, im not sure if this is absolutely necessary but during testing we observed CD’s still being connected to the deployed VM. &lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;powershell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-powershell line-numbers&quot;&gt;&lt;code class=&quot;language-powershell&quot;&gt;&lt;span class=&quot;token variable&quot;&gt;$drives&lt;/span&gt; = &lt;span class=&quot;token function&quot;&gt;Get-WmiObject&lt;/span&gt; Win32_Volume &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token keyword&quot;&gt;Filter&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;DriveType=5&amp;quot;&lt;/span&gt;
&lt;span class=&quot;token variable&quot;&gt;$drives&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;ForEach-Object&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;New-Object&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;ComObject Shell&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;Application&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;Namespace&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;17&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;ParseName&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token variable&quot;&gt;$_&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;Name&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;InvokeVerb&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;Eject&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;-&lt;/span&gt;ErrorAction SilentlyContinue&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&quot;shutdown-vm&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#shutdown-vm&quot; aria-label=&quot;shutdown vm permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Shutdown VM&lt;/h2&gt;&lt;p&gt;Finally, we reboot the VM, this is so the VM recognise it is domain joined.&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;powershell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-powershell line-numbers&quot;&gt;&lt;code class=&quot;language-powershell&quot;&gt;shutdown &lt;span class=&quot;token operator&quot;&gt;/&lt;/span&gt;r &lt;span class=&quot;token operator&quot;&gt;/&lt;/span&gt;t 10&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;</content:encoded><tags>automation,vmware,vra,vrealize</tags><featuredImage>https://samperrin.com/static/a213f55596b00d3cfd56cf3887d8a808/hero_4.jpg</featuredImage></item><item><title><![CDATA[Tanzu Community Edition - Azure Cluster]]></title><description><![CDATA[This post runs through the deployment of Tanzu Community Edition onto Azure - we will look at creating a Management Cluster, a Workload Cluster and the deployment of a demo application.]]></description><link>https://samperrin.com/posts/tanzu-community-edition-azure-cluster/</link><guid isPermaLink="false">https://samperrin.com/posts/tanzu-community-edition-azure-cluster/</guid><category><![CDATA[development]]></category><category><![CDATA[kubernetes]]></category><pubDate>Thu, 10 Feb 2022 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;This post runs through the deployment of Tanzu Community Edition onto Azure - we will look at creating a Management Cluster, a Workload Cluster and the deployment of a demo application. &lt;/p&gt;&lt;h2 id=&quot;prepare-bootstrap-devicevm&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#prepare-bootstrap-devicevm&quot; aria-label=&quot;prepare bootstrap devicevm permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Prepare Bootstrap Device/VM&lt;/h2&gt;&lt;p&gt;Install the TCE Tanzu CLI - &lt;a href=&quot;https://tanzucommunityedition.io/docs/latest/cli-installation/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://tanzucommunityedition.io/docs/latest/cli-installation/&lt;/a&gt; \
You will need both &lt;code class=&quot;language-text&quot;&gt;kubectl&lt;/code&gt; and &lt;code class=&quot;language-text&quot;&gt;docker&lt;/code&gt; installed.&lt;/p&gt;&lt;p&gt;If you are using Windows and hit the x509 certificate error, follow the steps here to resolve: &lt;a href=&quot;https://tanzucommunityedition.io/docs/latest/faq-cluster-bootstrapping/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://tanzucommunityedition.io/docs/latest/faq-cluster-bootstrapping/&lt;/a&gt;  &lt;/p&gt;&lt;p&gt;When the CLI is installed;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;tanzu management-cluster create --ui&lt;/code&gt; to open up the browser based installer on the bootstrap device. &lt;/li&gt;&lt;li&gt;Alternatively, use the following command to access the UI from another device &lt;code class=&quot;language-text&quot;&gt;tanzu management-cluster create --ui --bind &amp;lt;BOOTSTRAP_DEVICE_IP&amp;gt;:&amp;lt;PORT&amp;gt; --browser none&lt;/code&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1618px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:56.674907292954266%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAALCAYAAAB/Ca1DAAAACXBIWXMAAA7DAAAOwwHHb6hkAAAB1klEQVQoz4WR2ZKTUBCGeYnRgrAEAgESIMDhsK8mlsaq6KipctSrubH0Zqb0wgewfO/fouNgnHK5+A7dTZ+/lyMU+yOyp0ckj18i2V0SnOx/cXnKP6M5XqO7+gDhoeVD9jmMvIPsJZA9Bi3K4aQtlqzEMqlgsQo2b2CnDeykgZu1UDwGyY0wW43EEO0NHphrCKLLYBUvYB5uEV1/Q3Z4DdXjcPIBFu9gpT1M1sBkNUxWEVZSk7+IK2hBSqhBCnnNIFw4IV59/Y7h3RcY7XMYUQE9zKkjK6mgxyWkVUzdjIhONNnkuxEu7JM9cyMI4yE5ASTbh7j0ITohVdPCHE6zh84qqJsMSpBikdQI+h5W2lBsZMFKNH0Lg5XknwRXMe1htjrtZR4VsIsB6+EAu9zCSGrqdFkM8PsOdtHDYDXmcQm3fIRhO9B3LH5P8DSa4nNKDq4+wayfQPU5dT1nNfy3NzCKHdSAE0bWY/3+M4xsoJwzwWgSHF9djwo43TMYvIUS8KmgvMkxWzPa190dZYz91BDGgwTdX4JaWMBKW+j5DmbW08jTwzjhb49yPyZIfxhZG5fNW2zefMSy22Me5tP//yEoXkLdSW44cTeOlm0h++kUO8/5Gz8AK2hWaxWh8toAAAAASUVORK5CYII=&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Tanzu Community Edition Installer UI&quot; title=&quot;Tanzu Community Edition Installer UI&quot; src=&quot;/static/83f2e989ad378127d243d026857f808c/f4146/installer-ui.png&quot; srcSet=&quot;/static/83f2e989ad378127d243d026857f808c/f4146/installer-ui.png 1618w&quot; sizes=&quot;(max-width: 1618px) 100vw, 1618px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Tanzu Community Edition Installer UI&lt;/figcaption&gt;
  &lt;/figure&gt;&lt;/p&gt;&lt;h2 id=&quot;prepare-azure-environment&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#prepare-azure-environment&quot; aria-label=&quot;prepare azure environment permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Prepare Azure Environment&lt;/h2&gt;&lt;p&gt;Follow the steps here to prepare for an Azure installation: &lt;a href=&quot;https://tanzucommunityedition.io/docs/latest/azure-mgmt/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://tanzucommunityedition.io/docs/latest/azure-mgmt/&lt;/a&gt; &lt;/p&gt;&lt;p&gt;To quickly summarise what you will need to complete:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Get Tenant ID&lt;/li&gt;&lt;li&gt;Create App Registration &lt;/li&gt;&lt;li&gt;Get Application ID (Client ID)&lt;/li&gt;&lt;li&gt;Get Subscription ID&lt;/li&gt;&lt;li&gt;Configure Access control &lt;/li&gt;&lt;li&gt;Configure Client secret&lt;/li&gt;&lt;li&gt;Accept base image license&lt;/li&gt;&lt;li&gt;Configure SSH keys&lt;/li&gt;&lt;/ul&gt;&lt;h2 id=&quot;deploy-tce-cluster&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#deploy-tce-cluster&quot; aria-label=&quot;deploy tce cluster permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Deploy TCE Cluster&lt;/h2&gt;&lt;p&gt;From the UI select the Azure deploy button, populate the &lt;code class=&quot;language-text&quot;&gt;Tenant ID&lt;/code&gt;, &lt;code class=&quot;language-text&quot;&gt;Client ID&lt;/code&gt;, &lt;code class=&quot;language-text&quot;&gt;Client Secret&lt;/code&gt; and &lt;code class=&quot;language-text&quot;&gt;Subscription ID&lt;/code&gt; fields and press Connect. \
Select the appropriate Region for your deployment, in my case it is UK South. \
Enter your public SSH key. &lt;/p&gt;&lt;p&gt;As this is my first TCE deployment I will be creating a new Resource Group - I have named it &lt;code class=&quot;language-text&quot;&gt;TCE&lt;/code&gt;&lt;/p&gt;&lt;p&gt;&lt;img src=&quot;/d1a41e54c9728567a1fad4b224efd38b/azure-vnet-settings.png&quot; alt=&quot;Azure VNET Settings&quot;/&gt;&lt;/p&gt;&lt;p&gt;To save some costs on this initial installation we will deploy a Development cluster. \
Select an appropriate Instance Type from the dropdown list - you can use a service such as &lt;a href=&quot;https://azureprice.net&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://azureprice.net&lt;/a&gt; to find the out the cheapest option - for me it looks like &lt;code class=&quot;language-text&quot;&gt;Standard_F2s_v2&lt;/code&gt; is the cheapest choice, giving me 2 vCPU and 4Gb memory, if I pay slightly more I can bump up to a &lt;code class=&quot;language-text&quot;&gt;Standard_D2s_v3&lt;/code&gt; to give me 2 vCPU and 8Gb memory.
Once all the fields are populated we will have our &lt;code class=&quot;language-text&quot;&gt;dev plan&lt;/code&gt;. &lt;/p&gt;&lt;ul&gt;&lt;li&gt;We do not need to provide any additional Metadata. &lt;/li&gt;&lt;li&gt;We can accept the default settings for the Antrea CNI.&lt;/li&gt;&lt;li&gt;We will leave Identity Management off for now.&lt;/li&gt;&lt;li&gt;Select an appropriate OS image, for this I have gone with Ubuntu 20.04.&lt;/li&gt;&lt;li&gt;We will skip the Tanzu Mission Control (TMC) registration. &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Review and validate the configuration settings. &lt;/p&gt;&lt;p&gt;In the &lt;strong&gt;CLI Command Equivalent&lt;/strong&gt; box you will see where the temporary YAML file is stored. Take note of the directory for this file, we can use it as a template for our Workload Cluster, it will look something like this: &lt;code class=&quot;language-text&quot;&gt;/home/tanzu/.config/tanzu/tkg/clusterconfigs/37elw85tmr.yaml&lt;/code&gt; &lt;/p&gt;&lt;p&gt;Press &lt;strong&gt;Deploy Management Cluster&lt;/strong&gt; and follow along the installation &lt;/p&gt;&lt;h2 id=&quot;follow-the-installation&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#follow-the-installation&quot; aria-label=&quot;follow the installation permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Follow the Installation&lt;/h2&gt;&lt;p&gt;The TCE deployment will run through multiple stages, you can monitor progress through the logs but you can also see whats happening via &lt;code class=&quot;language-text&quot;&gt;kubectl&lt;/code&gt; and the Azure portal. &lt;/p&gt;&lt;p&gt;&lt;strong&gt;Setup bootstrap cluster&lt;/strong&gt; &lt;/p&gt;&lt;ul&gt;&lt;li&gt;After the image has been pulled you will see a container running within Docker, this is the bootstrap image which will do all the necessary things to then create a cluster within Azure. &lt;/li&gt;&lt;li&gt;When the Azure based management cluster is running, the bootstrap cluster will hand over to it. &lt;/li&gt;&lt;li&gt;Within the logs you will see reference to a kubeconfig file. &lt;code class=&quot;language-text&quot;&gt;Bootstrapper created. Kubeconfig: /home/tanzu/.kube-tkg/tmp/config_Jpd1gEfK&lt;/code&gt; - you can use this to run &lt;code class=&quot;language-text&quot;&gt;kubectl&lt;/code&gt; commands on the bootstrap cluster to see what is happening: &lt;code class=&quot;language-text&quot;&gt;kubectl get pod -A --kubeconfig /home/tanzu/.kube-tkg/tmp/config_Jpd1gEfK&lt;/code&gt; &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Install providers on bootstrap cluster&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;This stage will bring up additional pods and deployments that are required for the provisioning of clusters into Azure.  &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Create management cluster&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;At this point activity will start within Azure, head to &lt;a href=&quot;https://portal.azure.com&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://portal.azure.com&lt;/a&gt; and monitor the items that get created, such as a resource group, network, load balancers, security groups and VMs.&lt;/li&gt;&lt;li&gt;Within the logs you will see reference to another kubeconfig &lt;code class=&quot;language-text&quot;&gt;Saving management cluster kubeconfig into /home/tanzu/.kube/config&lt;/code&gt;. &lt;/li&gt;&lt;li&gt;You can set your context to the new management cluster to monitor progress &lt;/li&gt;&lt;/ul&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;kubectl config get-contexts
CURRENT   NAME                                  CLUSTER          AUTHINFO               NAMESPACE
          tce-azure-mgmt-admin@tce-azure-mgmt   tce-azure-mgmt   tce-azure-mgmt-admin
          tce-mgmt-admin@tce-mgmt               tce-mgmt         tce-mgmt-admin
*         tce-wl01-admin@tce-wl01               tce-wl01         tce-wl01-admin
kubectl config use-context tce-azure-mgmt-admin@tce-azure-mgmt&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;strong&gt;Install providers on management cluster&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;This stage will bring up additional pods and deployments that are required for the management of clusters into Azure.  &lt;/li&gt;&lt;/ul&gt;&lt;h2 id=&quot;deploy-workload-cluster&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#deploy-workload-cluster&quot; aria-label=&quot;deploy workload cluster permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Deploy Workload Cluster&lt;/h2&gt;&lt;p&gt;We can use the yaml file that was created by the UI for our Management Cluster to create our Workload Cluster. &lt;/p&gt;&lt;ul&gt;&lt;li&gt;Copy the yaml used for the management cluster: &lt;code class=&quot;language-text&quot;&gt;cp /home/tanzu/.config/tanzu/tkg/clusterconfigs/37elw85tmr.yaml /home/tanzu/.config/tanzu/tkg/clusterconfigs/azure-wl01.yaml&lt;/code&gt;&lt;/li&gt;&lt;li&gt;Edit the yaml and tidy up to reduce any unnecessary info (see example below): &lt;code class=&quot;language-text&quot;&gt;vi /home/tanzu/.config/tanzu/tkg/clusterconfigs/azure-wl01.yaml&lt;/code&gt;&lt;/li&gt;&lt;li&gt;Deploy the cluster: &lt;code class=&quot;language-text&quot;&gt;tanzu cluster create tce-azure-wl01 --file /home/tanzu/.config/tanzu/tkg/clusterconfigs/azure-wl01.yaml -v 6&lt;/code&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;As we have not specified the names of VNET’s or SUBNETS’s, you will notice that they inherit the clusters name, such as &lt;code class=&quot;language-text&quot;&gt;tce-azure-wl01-vnet&lt;/code&gt; and &lt;code class=&quot;language-text&quot;&gt;tce-azure-wl01-node-subnet&lt;/code&gt;, other resources inherit this naming convention too. \
As we did specify the resource group (&lt;code class=&quot;language-text&quot;&gt;TCE&lt;/code&gt;), all the resources will be created inside this.&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;yaml&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-yaml line-numbers&quot;&gt;&lt;code class=&quot;language-yaml&quot;&gt;&lt;span class=&quot;token key atrule&quot;&gt;CLUSTER_PLAN&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; dev
&lt;span class=&quot;token key atrule&quot;&gt;NAMESPACE&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; default
&lt;span class=&quot;token key atrule&quot;&gt;CNI&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; antrea

&lt;span class=&quot;token key atrule&quot;&gt;AZURE_CONTROL_PLANE_MACHINE_TYPE&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Standard_D2s_v3
&lt;span class=&quot;token key atrule&quot;&gt;AZURE_NODE_MACHINE_TYPE&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Standard_D2s_v3
&lt;span class=&quot;token key atrule&quot;&gt;AZURE_TENANT_ID&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;lt;TENANT_ID&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;
&lt;span class=&quot;token key atrule&quot;&gt;AZURE_SUBSCRIPTION_ID&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;lt;SUBSCRIPTION_ID&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;
&lt;span class=&quot;token key atrule&quot;&gt;AZURE_CLIENT_ID&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;lt;CLIENT_ID&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;
&lt;span class=&quot;token key atrule&quot;&gt;AZURE_CLIENT_SECRET&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;lt;CLIENT_SECRET&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;
&lt;span class=&quot;token key atrule&quot;&gt;AZURE_LOCATION&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; uksouth
&lt;span class=&quot;token key atrule&quot;&gt;AZURE_SSH_PUBLIC_KEY_B64&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;lt;SSH_KEY&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt; 
&lt;span class=&quot;token key atrule&quot;&gt;AZURE_RESOURCE_GROUP&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; TCE

&lt;span class=&quot;token key atrule&quot;&gt;CLUSTER_CIDR&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 100.96.0.0/11
&lt;span class=&quot;token key atrule&quot;&gt;SERVICE_CIDR&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 100.64.0.0/13
&lt;span class=&quot;token key atrule&quot;&gt;ENABLE_MHC&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;true&amp;quot;&lt;/span&gt;
&lt;span class=&quot;token key atrule&quot;&gt;OS_ARCH&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; amd64
&lt;span class=&quot;token key atrule&quot;&gt;OS_NAME&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ubuntu
&lt;span class=&quot;token key atrule&quot;&gt;OS_VERSION&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;20.04&amp;quot;&lt;/span&gt;&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Change to the context of your new workload cluster once it has been created: &lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;tanzu cluster kubeconfig get tce-azure-wl01 --admin
kubectl config use-context tce-azure-wl01-admin@tce-azure-wl01&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&quot;deploy-example-application&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#deploy-example-application&quot; aria-label=&quot;deploy example application permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Deploy Example Application&lt;/h2&gt;&lt;p&gt;For this we will use the ACME fitness demo application - &lt;a href=&quot;https://github.com/vmwarecloudadvocacy/acme_fitness_demo/tree/master/kubernetes-manifests&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://github.com/vmwarecloudadvocacy/acme_fitness_demo/tree/master/kubernetes-manifests&lt;/a&gt;&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;&lt;span class=&quot;token comment&quot;&gt;## Clone Repo&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;mkdir&lt;/span&gt; /home/tanzu/demo-apps
&lt;span class=&quot;token builtin class-name&quot;&gt;cd&lt;/span&gt; /home/tanzu/demo-apps
&lt;span class=&quot;token function&quot;&gt;git&lt;/span&gt; clone https://github.com/vmwarecloudadvocacy/acme_fitness_demo.git
&lt;span class=&quot;token builtin class-name&quot;&gt;cd&lt;/span&gt; acme_fitness_demo/kubernetes-manifests

&lt;span class=&quot;token comment&quot;&gt;## Set ENV &lt;/span&gt;
&lt;span class=&quot;token assign-left variable&quot;&gt;APP_PASSWORD&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;DemoApp123&lt;span class=&quot;token operator&quot;&gt;!&lt;/span&gt;
&lt;span class=&quot;token assign-left variable&quot;&gt;APP_NAMESPACE&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;acme-demo

&lt;span class=&quot;token comment&quot;&gt;## Deploy App&lt;/span&gt;
kubectl create ns &lt;span class=&quot;token variable&quot;&gt;${APP_NAMESPACE}&lt;/span&gt;
kubectl create secret generic cart-redis-pass --from-literal&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;password&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token variable&quot;&gt;${APP_PASSWORD}&lt;/span&gt; -n &lt;span class=&quot;token variable&quot;&gt;${APP_NAMESPACE}&lt;/span&gt; 
kubectl apply -f cart-redis-total.yaml -n &lt;span class=&quot;token variable&quot;&gt;${APP_NAMESPACE}&lt;/span&gt; 
kubectl apply -f cart-total.yaml -n &lt;span class=&quot;token variable&quot;&gt;${APP_NAMESPACE}&lt;/span&gt; 
kubectl create secret generic catalog-mongo-pass --from-literal&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;password&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token variable&quot;&gt;${APP_PASSWORD}&lt;/span&gt; -n &lt;span class=&quot;token variable&quot;&gt;${APP_NAMESPACE}&lt;/span&gt; 
kubectl create -f catalog-db-initdb-configmap.yaml -n &lt;span class=&quot;token variable&quot;&gt;${APP_NAMESPACE}&lt;/span&gt; 
kubectl apply -f catalog-db-total.yaml -n &lt;span class=&quot;token variable&quot;&gt;${APP_NAMESPACE}&lt;/span&gt; 
kubectl apply -f catalog-total.yaml -n &lt;span class=&quot;token variable&quot;&gt;${APP_NAMESPACE}&lt;/span&gt; 
kubectl apply -f payment-total.yaml -n &lt;span class=&quot;token variable&quot;&gt;${APP_NAMESPACE}&lt;/span&gt; 
kubectl create secret generic order-postgres-pass --from-literal&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;password&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token variable&quot;&gt;${APP_PASSWORD}&lt;/span&gt; -n &lt;span class=&quot;token variable&quot;&gt;${APP_NAMESPACE}&lt;/span&gt; 
kubectl apply -f order-db-total.yaml -n &lt;span class=&quot;token variable&quot;&gt;${APP_NAMESPACE}&lt;/span&gt; 
kubectl apply -f order-total.yaml -n &lt;span class=&quot;token variable&quot;&gt;${APP_NAMESPACE}&lt;/span&gt; 
kubectl create secret generic users-mongo-pass --from-literal&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;password&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token variable&quot;&gt;${APP_PASSWORD}&lt;/span&gt; -n &lt;span class=&quot;token variable&quot;&gt;${APP_NAMESPACE}&lt;/span&gt; 
kubectl create secret generic users-redis-pass --from-literal&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;password&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token variable&quot;&gt;${APP_PASSWORD}&lt;/span&gt; -n &lt;span class=&quot;token variable&quot;&gt;${APP_NAMESPACE}&lt;/span&gt; 
kubectl create -f users-db-initdb-configmap.yaml -n &lt;span class=&quot;token variable&quot;&gt;${APP_NAMESPACE}&lt;/span&gt; 
kubectl apply -f users-db-total.yaml -n &lt;span class=&quot;token variable&quot;&gt;${APP_NAMESPACE}&lt;/span&gt; 
kubectl apply -f users-redis-total.yaml -n &lt;span class=&quot;token variable&quot;&gt;${APP_NAMESPACE}&lt;/span&gt; 
kubectl apply -f users-total.yaml -n &lt;span class=&quot;token variable&quot;&gt;${APP_NAMESPACE}&lt;/span&gt; 
kubectl apply -f frontend-total.yaml -n &lt;span class=&quot;token variable&quot;&gt;${APP_NAMESPACE}&lt;/span&gt; 
kubectl apply -f point-of-sales-total.yaml -n &lt;span class=&quot;token variable&quot;&gt;${APP_NAMESPACE}&lt;/span&gt; 

&lt;span class=&quot;token comment&quot;&gt;## Monitor App&lt;/span&gt;
kubectl get pods -n &lt;span class=&quot;token variable&quot;&gt;${APP_NAMESPACE}&lt;/span&gt; 
kubectl get &lt;span class=&quot;token function&quot;&gt;service&lt;/span&gt; frontend -n &lt;span class=&quot;token variable&quot;&gt;${APP_NAMESPACE}&lt;/span&gt; &lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Using the external IP listed against the service you should be able to browse to the website: &lt;code class=&quot;language-text&quot;&gt;http://&amp;lt;external-service-IP&amp;gt;&lt;/code&gt;&lt;/p&gt;&lt;h2 id=&quot;octant&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#octant&quot; aria-label=&quot;octant permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Octant&lt;/h2&gt;&lt;p&gt;Lets use Octant to view the cluster
&lt;a href=&quot;https://github.com/vmware-tanzu/octant/releases&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://github.com/vmware-tanzu/octant/releases&lt;/a&gt;&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;&lt;span class=&quot;token builtin class-name&quot;&gt;cd&lt;/span&gt; /tmp
&lt;span class=&quot;token function&quot;&gt;wget&lt;/span&gt; https://github.com/vmware-tanzu/octant/releases/download/v0.25.0/octant_0.25.0_Linux-64bit.tar.gz
&lt;span class=&quot;token function&quot;&gt;tar&lt;/span&gt; -xzvf /tmp/octant_0.25.0_Linux-64bit.tar.gz
&lt;span class=&quot;token function&quot;&gt;mv&lt;/span&gt; /tmp/octant_0.25.0_Linux-64bit /usr/bin/octant&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;I am starting octant with the following command so I can access the UI from another device, the value for the &lt;code class=&quot;language-text&quot;&gt;OCTANT_ACCEPTED_HOSTS&lt;/code&gt; variable is the IP of the octant host. \
&lt;code class=&quot;language-text&quot;&gt;OCTANT_ACCEPTED_HOSTS=$(/sbin/ip -o -4 addr list eth0 | awk &amp;#x27;{print $4}&amp;#x27; | cut -d/ -f1) KUBECONFIG=/home/tanzu/.kube/config OCTANT_LISTENER_ADDR=0.0.0.0:8900 OCTANT_DISABLE_OPEN_BROWSER=true octant&lt;/code&gt;&lt;/p&gt;&lt;p&gt;&lt;img src=&quot;/4116f8a711fbe9a592101a9a3753dfe1/octact-app-overview.png&quot; alt=&quot;Octant Application overview screen&quot;/&gt;&lt;/p&gt;&lt;p&gt;&lt;img src=&quot;/a5312f36846cebbc8807a2c803eaa3e3/octact-frontend-overview.png&quot; alt=&quot;Octant Frontend overview screen&quot;/&gt;&lt;/p&gt;&lt;p&gt;&lt;img src=&quot;/ed25df5cf4f1d50bc846cb5bbed1b45e/octact-frontend-service.png&quot; alt=&quot;Octant Frontend service screen&quot;/&gt;&lt;/p&gt;&lt;h2 id=&quot;tidy-up&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#tidy-up&quot; aria-label=&quot;tidy up permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Tidy Up&lt;/h2&gt;&lt;h3 id=&quot;delete-workload-cluster&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#delete-workload-cluster&quot; aria-label=&quot;delete workload cluster permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Delete workload cluster&lt;/h3&gt;&lt;p&gt;Get the current Tanzu clusters and identify the name of the cluster to delete.&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;tanzu cluster list
NAME            NAMESPACE  STATUS   CONTROLPLANE  WORKERS  KUBERNETES        ROLES   PLAN
tce-azure-wl01  default    running  &lt;span class=&quot;token number&quot;&gt;1&lt;/span&gt;/1           &lt;span class=&quot;token number&quot;&gt;1&lt;/span&gt;/1      v1.21.2+vmware.1  &lt;span class=&quot;token operator&quot;&gt;&amp;lt;&lt;/span&gt;none&lt;span class=&quot;token operator&quot;&gt;&amp;gt;&lt;/span&gt;  dev&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Start the cluster deletion. It will take a few minutes to clean up in Azure. Within the Azure portal you will start to see resources be deleted.&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;tanzu cluster delete tce-azure-wl01
Deleting workload cluster &lt;span class=&quot;token string&quot;&gt;&amp;#x27;tce-azure-wl01&amp;#x27;&lt;/span&gt;&lt;span class=&quot;token builtin class-name&quot;&gt;.&lt;/span&gt; Are you sure? &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;y/N&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;: y
Workload cluster &lt;span class=&quot;token string&quot;&gt;&amp;#x27;tce-azure-wl01&amp;#x27;&lt;/span&gt; is being deleted&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Monitor the deletion of the cluster, you can use both &lt;code class=&quot;language-text&quot;&gt;kubectl&lt;/code&gt; and &lt;code class=&quot;language-text&quot;&gt;tanzu&lt;/code&gt; commands. &lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;kubectl get cluster
NAME             PHASE
tce-azure-wl01   Deleting

tanzu cluster list
NAME            NAMESPACE  STATUS    CONTROLPLANE  WORKERS  KUBERNETES        ROLES   PLAN
tce-azure-wl01  default    deleting  &lt;span class=&quot;token number&quot;&gt;1&lt;/span&gt;/1                    v1.21.2+vmware.1  &lt;span class=&quot;token operator&quot;&gt;&amp;lt;&lt;/span&gt;none&lt;span class=&quot;token operator&quot;&gt;&amp;gt;&lt;/span&gt;  dev&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;After the deletion has completed, the two commands will return no results.&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;kubectl get cluster
No resources found &lt;span class=&quot;token keyword&quot;&gt;in&lt;/span&gt; default namespace.

tanzu cluster list
NAME  NAMESPACE  STATUS  CONTROLPLANE  WORKERS  KUBERNETES  ROLES  PLAN&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;You might need to delete the workload clusters context from your config file: &lt;code class=&quot;language-text&quot;&gt;kubectl config delete-context tce-azure-wl01-admin@tce-azure-wl01&lt;/code&gt;&lt;/p&gt;&lt;h3 id=&quot;delete-management-cluster&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#delete-management-cluster&quot; aria-label=&quot;delete management cluster permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Delete management cluster&lt;/h3&gt;&lt;p&gt;When the process to delete a management cluster is started a temporary &lt;code class=&quot;language-text&quot;&gt;kind&lt;/code&gt; cluster is stood up to manage the deletion. The &lt;code class=&quot;language-text&quot;&gt;kind&lt;/code&gt; cluster is then deleted after completion. &lt;/p&gt;&lt;p&gt;Retrieve the name of the management cluster.&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;tanzu management-cluster get
NAME            NAMESPACE   STATUS   CONTROLPLANE  WORKERS  KUBERNETES        ROLES
tce-azure-mgmt  tkg-system  running  &lt;span class=&quot;token number&quot;&gt;1&lt;/span&gt;/1           &lt;span class=&quot;token number&quot;&gt;1&lt;/span&gt;/1      v1.21.2+vmware.1  management&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Start the deletion of the management cluster. &lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;tanzu management-cluster delete tce-azure-mgmt
Deleting management cluster &lt;span class=&quot;token string&quot;&gt;&amp;#x27;tce-azure-mgmt&amp;#x27;&lt;/span&gt;&lt;span class=&quot;token builtin class-name&quot;&gt;.&lt;/span&gt; Are you sure? &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;y/N&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;: y&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;You can monitor the status of the temporary &lt;code class=&quot;language-text&quot;&gt;kind&lt;/code&gt; cluster through the use of docker and the temporary kubeconfig that is created. &lt;/p&gt;&lt;p&gt;Temporary kubeconfig files are stored in &lt;code class=&quot;language-text&quot;&gt;~/.kube-tkg/tmp&lt;/code&gt;&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;&lt;span class=&quot;token function&quot;&gt;docker&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;ps&lt;/span&gt; -a
CONTAINER ID   IMAGE                                                         COMMAND                  CREATED         STATUS         PORTS                       NAMES
e52dac6edc9b   projects.registry.vmware.com/tkg/kind/node:v1.21.2_vmware.1   &lt;span class=&quot;token string&quot;&gt;&amp;quot;/usr/local/bin/entr…&amp;quot;&lt;/span&gt;   &lt;span class=&quot;token number&quot;&gt;3&lt;/span&gt; minutes ago   Up &lt;span class=&quot;token number&quot;&gt;2&lt;/span&gt; minutes   &lt;span class=&quot;token number&quot;&gt;127.0&lt;/span&gt;.0.1:37555-&lt;span class=&quot;token operator&quot;&gt;&amp;gt;&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;6443&lt;/span&gt;/tcp   tkg-kind-c82jls8gcv0cn7u54j30-control-plane

kubectl get cluster -A --kubeconfig /home/tanzu/.kube-tkg/tmp/config_jIv63FND
NAMESPACE    NAME             PHASE
tkg-system   tce-azure-mgmt   Deleting&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Log output from deleting management cluster &lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;tanzu management-cluster delete tce-azure-mgmt
Deleting management cluster &lt;span class=&quot;token string&quot;&gt;&amp;#x27;tce-azure-mgmt&amp;#x27;&lt;/span&gt;&lt;span class=&quot;token builtin class-name&quot;&gt;.&lt;/span&gt; Are you sure? &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;y/N&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;: y
Verifying management cluster&lt;span class=&quot;token punctuation&quot;&gt;..&lt;/span&gt;.
Setting up cleanup cluster&lt;span class=&quot;token punctuation&quot;&gt;..&lt;/span&gt;.
Installing providers to cleanup cluster&lt;span class=&quot;token punctuation&quot;&gt;..&lt;/span&gt;.
Fetching providers
Installing cert-manager &lt;span class=&quot;token assign-left variable&quot;&gt;Version&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;v1.1.0&amp;quot;&lt;/span&gt;
Waiting &lt;span class=&quot;token keyword&quot;&gt;for&lt;/span&gt; cert-manager to be available&lt;span class=&quot;token punctuation&quot;&gt;..&lt;/span&gt;.
Installing &lt;span class=&quot;token assign-left variable&quot;&gt;Provider&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;cluster-api&amp;quot;&lt;/span&gt; &lt;span class=&quot;token assign-left variable&quot;&gt;Version&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;v0.3.23&amp;quot;&lt;/span&gt; &lt;span class=&quot;token assign-left variable&quot;&gt;TargetNamespace&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;capi-system&amp;quot;&lt;/span&gt;
Installing &lt;span class=&quot;token assign-left variable&quot;&gt;Provider&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;bootstrap-kubeadm&amp;quot;&lt;/span&gt; &lt;span class=&quot;token assign-left variable&quot;&gt;Version&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;v0.3.23&amp;quot;&lt;/span&gt; &lt;span class=&quot;token assign-left variable&quot;&gt;TargetNamespace&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;capi-kubeadm-bootstrap-system&amp;quot;&lt;/span&gt;
Installing &lt;span class=&quot;token assign-left variable&quot;&gt;Provider&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;control-plane-kubeadm&amp;quot;&lt;/span&gt; &lt;span class=&quot;token assign-left variable&quot;&gt;Version&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;v0.3.23&amp;quot;&lt;/span&gt; &lt;span class=&quot;token assign-left variable&quot;&gt;TargetNamespace&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;capi-kubeadm-control-plane-system&amp;quot;&lt;/span&gt;
Installing &lt;span class=&quot;token assign-left variable&quot;&gt;Provider&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;infrastructure-azure&amp;quot;&lt;/span&gt; &lt;span class=&quot;token assign-left variable&quot;&gt;Version&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;v0.4.15&amp;quot;&lt;/span&gt; &lt;span class=&quot;token assign-left variable&quot;&gt;TargetNamespace&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;capz-system&amp;quot;&lt;/span&gt;
Moving Cluster API objects from management cluster to cleanup cluster&lt;span class=&quot;token punctuation&quot;&gt;..&lt;/span&gt;.
Performing move&lt;span class=&quot;token punctuation&quot;&gt;..&lt;/span&gt;.
Discovering Cluster API objects
Moving Cluster API objects &lt;span class=&quot;token assign-left variable&quot;&gt;Clusters&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;1&lt;/span&gt;
Creating objects &lt;span class=&quot;token keyword&quot;&gt;in&lt;/span&gt; the target cluster
Deleting objects from the &lt;span class=&quot;token builtin class-name&quot;&gt;source&lt;/span&gt; cluster
Waiting &lt;span class=&quot;token keyword&quot;&gt;for&lt;/span&gt; the Cluster API objects to get ready after move&lt;span class=&quot;token punctuation&quot;&gt;..&lt;/span&gt;.
Deleting management cluster&lt;span class=&quot;token punctuation&quot;&gt;..&lt;/span&gt;.
Management cluster &lt;span class=&quot;token string&quot;&gt;&amp;#x27;tce-azure-mgmt&amp;#x27;&lt;/span&gt; deleted.
Deleting the management cluster context from the kubeconfig &lt;span class=&quot;token function&quot;&gt;file&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;/home/tanzu/.kube/config&amp;#x27;&lt;/span&gt;
warning: this removed your active context, use &lt;span class=&quot;token string&quot;&gt;&amp;quot;kubectl config use-context&amp;quot;&lt;/span&gt; to &lt;span class=&quot;token keyword&quot;&gt;select&lt;/span&gt; a different one

Management cluster deleted&lt;span class=&quot;token operator&quot;&gt;!&lt;/span&gt;&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Your Azure portal should now be empty of any resources from this deployment. &lt;/p&gt;</content:encoded><tags>development,kubernetes</tags><featuredImage>https://samperrin.com/static/1c89d7bd9ce795ec0476812eb75210cc/hero_2.jpg</featuredImage></item><item><title><![CDATA[Tanzu Community Edition - Tips and Concepts]]></title><description><![CDATA[Tanzu Community Edition is a full-featured, easy to manage Kubernetes platform, this post covers some tips and concepts for TCE.]]></description><link>https://samperrin.com/posts/tanzu-community-edition-tips-and-concepts/</link><guid isPermaLink="false">https://samperrin.com/posts/tanzu-community-edition-tips-and-concepts/</guid><category><![CDATA[kubernetes]]></category><category><![CDATA[development]]></category><category><![CDATA[vmware]]></category><pubDate>Wed, 02 Feb 2022 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;VMware Tanzu Community Edition is a full-featured, easy to manage Kubernetes platform that is a freely available, community supported, open source distribution of VMware Tanzu. &lt;/p&gt;&lt;p&gt;The project enables the creation of application platforms through the use of Cluster API to provide declarative deployment and management of Kubernetes clusters. &lt;/p&gt;&lt;p&gt;This post covers a few tips and concepts for using and building with Tanzu Community Edition. &lt;/p&gt;&lt;h2 id=&quot;1-cluster-types&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#1-cluster-types&quot; aria-label=&quot;1 cluster types permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;1. Cluster Types&lt;/h2&gt;&lt;p&gt;There are three primary types of clusters:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Management Clusters&lt;/strong&gt;, a “permanent” cluster that is your interface for deploying managed Workload Clusters, use to perform lifecycle operations on managed clusters&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Workload Clusters&lt;/strong&gt;, a managed cluster, deployed via the Management Cluster, used to run workloads for services/apps, there can be multiple Workload Clusters under a single Management Cluster&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Standalone Clusters&lt;/strong&gt;, deployed via a temporary Management Cluster that is automatically deleted after provisioning, reduces overall system requirements and a “faster time to cluster”.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Read more: &lt;a href=&quot;https://tanzucommunityedition.io/docs/latest/architecture/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://tanzucommunityedition.io/docs/latest/architecture/&lt;/a&gt; &lt;/p&gt;&lt;h2 id=&quot;2-management-cluster-creation&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#2-management-cluster-creation&quot; aria-label=&quot;2 management cluster creation permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;2. Management Cluster Creation&lt;/h2&gt;&lt;p&gt;There are two ways to deploy a Management Cluster:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Through the Tanzu Community Edition UI, which you can start by running: &lt;code class=&quot;language-text&quot;&gt;tanzu management-cluster create --ui&lt;/code&gt;&lt;/li&gt;&lt;li&gt;Directly through the Tanzu CLU, by running; &lt;code class=&quot;language-text&quot;&gt;tanzu management-cluster create --file FILE_PATH&lt;/code&gt;&lt;/li&gt;&lt;li&gt;Add the verbosity flags to get more output; &lt;code class=&quot;language-text&quot;&gt;-v&lt;/code&gt; / &lt;code class=&quot;language-text&quot;&gt;--verbose&lt;/code&gt;&lt;/li&gt;&lt;li&gt;You can create clusters in specific namespaces to keep them organised &lt;/li&gt;&lt;/ul&gt;&lt;h2 id=&quot;3-delete-management-clusters&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#3-delete-management-clusters&quot; aria-label=&quot;3 delete management clusters permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;3. Delete Management Clusters&lt;/h2&gt;&lt;p&gt;To delete a Management Cluster:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;If it’s still up and accessible: &lt;code class=&quot;language-text&quot;&gt;tanzu management-cluster delete MGMT_CLUSTER_NAME&lt;/code&gt;&lt;/li&gt;&lt;li&gt;If it’s stuck and won’t delete, try adding the &lt;code class=&quot;language-text&quot;&gt;–force&lt;/code&gt; flag &lt;/li&gt;&lt;li&gt;If it’s been manually deleted or inaccessible: &lt;code class=&quot;language-text&quot;&gt;tanzu config server delete MGMT_CLUSTER_NAME&lt;/code&gt;&lt;/li&gt;&lt;li&gt;Add the &lt;code class=&quot;language-text&quot;&gt;--yes&lt;/code&gt; flag to avoid confirmation prompts &lt;/li&gt;&lt;/ul&gt;&lt;h2 id=&quot;4-delete-workload-clusters&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#4-delete-workload-clusters&quot; aria-label=&quot;4 delete workload clusters permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;4. Delete Workload Clusters&lt;/h2&gt;&lt;p&gt;To delete Workload Clusters:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Delete them all; &lt;code class=&quot;language-text&quot;&gt;tanzu cluster delete&lt;/code&gt;&lt;/li&gt;&lt;li&gt;Delete a specific cluster: &lt;code class=&quot;language-text&quot;&gt;tanzu cluster delete WORKLOAD_CLUSTER_NAME&lt;/code&gt;&lt;/li&gt;&lt;li&gt;Add the &lt;code class=&quot;language-text&quot;&gt;--yes&lt;/code&gt; flag to avoid confirmation prompts &lt;/li&gt;&lt;/ul&gt;&lt;h2 id=&quot;5-clusters-on-vsphere&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#5-clusters-on-vsphere&quot; aria-label=&quot;5 clusters on vsphere permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;5. Clusters on vSphere&lt;/h2&gt;&lt;p&gt;If you are about to deploy your TCE clusters on vSphere, there are a few things to check:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;The target network for the Nodes (Management and Workload) has DHCP enabled&lt;/li&gt;&lt;li&gt;A set of static IP addresses in the same subnet as DHCP but not in the DHCP range – the static IP’s are used by Kube-Vip for the API server endpoint&lt;/li&gt;&lt;li&gt;All Nodes can reach vCenter (FQDN/IP) or port 443&lt;/li&gt;&lt;li&gt;Traffic is allowed between the bootstrap machine and all Nodes on port 6433&lt;/li&gt;&lt;li&gt;Add DHCP reservations for deployed Nodes after they have been created&lt;/li&gt;&lt;/ul&gt;&lt;h2 id=&quot;6-tanzu-packages&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#6-tanzu-packages&quot; aria-label=&quot;6 tanzu packages permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;6. Tanzu Packages&lt;/h2&gt;&lt;p&gt;Use &lt;code class=&quot;language-text&quot;&gt;tanzu package&lt;/code&gt; to discover, configure and manage bundled software, known as packages, within clusters. Packages utilise a Package Repository that is installed into a cluster, this then allows the packages for installation. Some example packages include:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;cert-manager &lt;a href=&quot;https://cert-manager.io/docs/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://cert-manager.io/docs/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Velero &lt;a href=&quot;https://twitter.com/projectvelero&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://twitter.com/projectvelero&lt;/a&gt; &lt;/li&gt;&lt;li&gt;Harbor &lt;a href=&quot;https://twitter.com/project_harbor&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://twitter.com/project_harbor&lt;/a&gt; &lt;/li&gt;&lt;li&gt;Contour &lt;a href=&quot;https://twitter.com/projectcontour&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://twitter.com/projectcontour&lt;/a&gt; &lt;/li&gt;&lt;li&gt;ExternalDNS &lt;a href=&quot;https://github.com/kubernetes-sigs/external-dns&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://github.com/kubernetes-sigs/external-dns&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Read more: &lt;a href=&quot;https://tanzucommunityedition.io/docs/latest/package-management/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://tanzucommunityedition.io/docs/latest/package-management/&lt;/a&gt; &lt;/p&gt;&lt;h2 id=&quot;7-scale-clusters&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#7-scale-clusters&quot; aria-label=&quot;7 scale clusters permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;7. Scale Clusters&lt;/h2&gt;&lt;p&gt;Management and Workload Clusters can both be scaled through the Tanzu CLI, with flags for scaling control plan and worker machine counts. &lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;tanzu cluster scale WORKLOAD_CLUSTER_NAME --controlplane-machine-count 5 --worker-machine-count 10 --namespace NAMESPACE&lt;/code&gt;&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;tanzu cluster scale MGMT_CLUSTER_NAME --controlplane-machine-count 5 --worker-machine-count 10 --namespace NAMESPACE&lt;/code&gt;&lt;/li&gt;&lt;li&gt;Clusters can be vertically scaled by modifying &lt;code class=&quot;language-text&quot;&gt;MachineTemplates&lt;/code&gt;: &lt;a href=&quot;https://cluster-api.sigs.k8s.io/tasks/updating-machine-templates.html&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://cluster-api.sigs.k8s.io/tasks/updating-machine-templates.html&lt;/a&gt; &lt;/li&gt;&lt;/ul&gt;&lt;h2 id=&quot;8-cluster-api&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#8-cluster-api&quot; aria-label=&quot;8 cluster api permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;8. Cluster API&lt;/h2&gt;&lt;p&gt;Tanzu Community Edition uses Cluster API for the lifecycle management of Kubernetes clusters. A few definitions to be aware of:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Machine&lt;/strong&gt;, an infrastructure component, such as a VM, hosting a Kubernetes Node.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;MachineDeployment&lt;/strong&gt;, behaves similarly to a Kubernetes Deployment, provides declarative updates to Machines and MachineSets.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;MachineSet&lt;/strong&gt;, like Kubernetes ReplicaSets, these form part of a MachineDeployment and ensure a stable set of Machines are running and in desired state.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;MachineHealthCheck&lt;/strong&gt;, monitors the status of Nodes, if deemed unhealthy, and if part of a MachineSet, the unhealthy Machine is deleted and a new one is created to replace it&lt;/li&gt;&lt;/ul&gt;&lt;h2 id=&quot;9-cluster-bootstrapping-on-windows&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#9-cluster-bootstrapping-on-windows&quot; aria-label=&quot;9 cluster bootstrapping on windows permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;9. Cluster Bootstrapping on Windows&lt;/h2&gt;&lt;p&gt;When deploying a Management Cluster on Windows you might get an x509 certificate error: &lt;code class=&quot;language-text&quot;&gt;x509: certificate signed by unknown authority&lt;/code&gt;. \
You can work around this by updating the Tanzu config file found at &lt;code class=&quot;language-text&quot;&gt;%USERPROFILE%.config\tanzu\tkg\config.yaml&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Read more: &lt;a href=&quot;https://tanzucommunityedition.io/docs/latest/faq-cluster-bootstrapping/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://tanzucommunityedition.io/docs/latest/faq-cluster-bootstrapping/&lt;/a&gt;&lt;/p&gt;</content:encoded><tags>kubernetes,development,vmware</tags><featuredImage>https://samperrin.com/static/4baf0f5e471c12bb261184c9deab22c3/hero_1.jpg</featuredImage></item><item><title><![CDATA[Tanzu and vRealize - VMworld 2021]]></title><description><![CDATA[VMworld 2021 provided lots of annoucements and updates across the vRealize and Tanzu portfolios]]></description><link>https://samperrin.com/posts/tanzu-and-vrealize-vmworld-2021/</link><guid isPermaLink="false">https://samperrin.com/posts/tanzu-and-vrealize-vmworld-2021/</guid><category><![CDATA[vmware]]></category><pubDate>Wed, 13 Oct 2021 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;VMworld 2021 has been and gone, it was delivered as a virtual event again with the hope and aim that next years events will be in person - in both Barcelona and San Francisco, this year had a heavy focus around multi-cloud and how these clouds can provide advantages into application development and delivery. &lt;/p&gt;&lt;p&gt;With Multi-Cloud becoming a more viable concept, it raises plenty of new challenges around control, adoption and operability. VMware have captured what they believe are the core elements to a successful cloud transformation, they have labelled this the &lt;code class=&quot;language-text&quot;&gt;VMware Cloud Operating Model&lt;/code&gt;. This operating model was a key focus area for VMworld and the majority of other announcements feed directly into this. &lt;/p&gt;&lt;p&gt;&lt;img src=&quot;/628ca7367a466c00335988800a172f48/1.png&quot; alt=&quot;VMware Cloud Operating Model diagram&quot;/&gt;&lt;/p&gt;&lt;p&gt;Below I have summarised the announcements across the vRealize Suite and Tanzu Portfolios.&lt;/p&gt;&lt;h2 id=&quot;vrealize-suite&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#vrealize-suite&quot; aria-label=&quot;vrealize suite permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;vRealize Suite&lt;/h2&gt;&lt;p&gt;With a continued focus on Multi-Cloud and Cloud Management, it is no surprise that the vRealize Suite has seen multiple enhancements and releases. &lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;Project Ensemble&lt;/code&gt;: A tech preview was announced for Project Ensemble, that brings single UI with persona and app-centric views for a unified experience across all vRealize Cloud Management services.&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;vRealize Cloud Universal&lt;/code&gt;: Combine SaaS and on-premises capabilities for automation, operations, log analytics, and network visibility with vRealize Cloud Universal. You get the flexibility to deploy as SaaS or on-premises and the freedom to move between the two as needed.&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;vRealize Suite Lifecycle Manager 8.6&lt;/code&gt;: Topology view of vRealize product deployments, notification enhancements, and additional capability for managing vRealize products, such as snapshot management and cloud proxy deployment.&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;vRealize Automation Cloud and 8.6&lt;/code&gt;: New multi-cloud capabilities, particularly focused around Azure. New integration support for VMware Cloud Director environments and improvements to its VMware vSphere with Tanzu integration.&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;vRealize Operations Cloud and 8.6&lt;/code&gt;: Improved integration between vROPs and vRA and also public clouds, such as AWS, Azure and GCP. New management packs and bi-directional integration with CloudHealth&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;vRealize True Visibility Suite 2.0&lt;/code&gt;: Storage and Compute management packs now included with every licensed level of vROPs&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;vRealize AI Cloud&lt;/code&gt;: New beta features to support vRA Cloud and improved network optimisation within vRNI. The product also saw added capability around Smart Initial Sizing and Placement, adding KPI based statistics that better align to business value. &lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;vRealize Log Insight Cloud and 8.6&lt;/code&gt;: Continued improvements around the logging capability for both cloud and on-premises products. Enhanced regional availability and AI powered root cause analysis for vRLI Cloud. &lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;vRealize Cloud Universal Standard Add-on for Horizon (MP4H)&lt;/code&gt;: A new monitoring add-on for all VMware Horizon customers that adds capabilities and enhancements into vROPs.&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;vRealize Network Insight Cloud and 6.4&lt;/code&gt;: New locations for vRNI Cloud, including Frankfurt and Central Canada. Added capabilities and integrations for NSX Federation, VMware Cloud and ServiceNow. &lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;CloudHealth&lt;/code&gt;: Introduction of line items, allowing better visibility and control for chargeback and showback across multi-cloud environments.&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;CloudHealth Secure State&lt;/code&gt;: Two new capabilities focused on the security and risk visibility across cloud infrastructure; Kubernetes Security Posture Management (KSPM) and Explore - a powerful search feature for multi-cloud deployments, allowing the effective management &lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;VMware Skyline&lt;/code&gt;: Skyline Advisor Pro is a new offering for Production, Premier, vRealize Cloud Universal, and Success 360 Customers that promises to provide faster, smarter and simpler insights into issues, remediation suggestions and findings across its managed environments. &lt;/li&gt;&lt;/ul&gt;&lt;h2 id=&quot;tanzu&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#tanzu&quot; aria-label=&quot;tanzu permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Tanzu&lt;/h2&gt;&lt;ul&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;Tanzu Community Edition&lt;/code&gt;: A full featured and easy to manage Kubernetes platform based on the existing Tanzu Kubernetes Grid offering. TCE provides an opinionated approach to deploying Kubernetes clusters utilising Cluster API. &lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;Tanzu Application Platform/Service&lt;/code&gt;: Continued improvements to the modular and application-aware platform for developers - some improvements include better developer tooling, such as IDE plugins and extensions, supply chain choreography based on the Cartographer open source project, and security enhancements. &lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;Tanzu Mission Control&lt;/code&gt;: A new Starter Plan - a free tier to Tanzu Mission Control - allowing access to the multi-cloud management plane, for better visibility and control into Kubernetes clusters. TMC also has added capability around the lifecycle of Tanzu Kubernetes Grid clusters deployed into Azure. TMC Essentials will be included in VMware Cloud with Tanzu Services.&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;VMware Cloud with Tanzu Services&lt;/code&gt;: A portfolio of managed Kubernetes services built on top of VMware Cloud.&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;VMware Tanzu Kubernetes Grid GPU Support&lt;/code&gt;: VMware have announced GPU support with vSphere with Tanzu (TKGS) and also with Tanzu Kubernetes Grid (TKG) on AWS and Azure, helping organisations avoid AI silos for developers. &lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;Tanzu Observability&lt;/code&gt;: AI/ML capabilities to aide in root cause analysis (Automated Probable Root Cause), enhanced Prometheus Query Language support, improved alerting processes and integrations into vROPs Cloud.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Sources&lt;/strong&gt; \
&lt;a href=&quot;https://blogs.vmware.com/management/2021/10/whats-new-in-cloud-management-at-vmworld-2021.html&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://blogs.vmware.com/management/2021/10/whats-new-in-cloud-management-at-vmworld-2021.html&lt;/a&gt; \
&lt;a href=&quot;https://blogs.vmware.com/management/2021/10/introducing-vmware-cloud-director-support-in-vrealize-automation.html&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://blogs.vmware.com/management/2021/10/introducing-vmware-cloud-director-support-in-vrealize-automation.html&lt;/a&gt; \
&lt;a href=&quot;https://tanzu.vmware.com/content/blog/vmware-tanzu-community-edition-kubernetes-cloud-native-ecosystem&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://tanzu.vmware.com/content/blog/vmware-tanzu-community-edition-kubernetes-cloud-native-ecosystem&lt;/a&gt; \
&lt;a href=&quot;https://tanzu.vmware.com/content/blog/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://tanzu.vmware.com/content/blog/&lt;/a&gt; &lt;/p&gt;</content:encoded><tags>vmware</tags><featuredImage>https://samperrin.com/static/f4e85ba1bf88dfe0b1d1a36feb9103a4/hero_6.jpg</featuredImage></item><item><title><![CDATA[Custom Naming in vRA8]]></title><description><![CDATA[vRealize Automation 8 provides various levels and methods of applying custom naming to deployed virtual machine resources. This article explores these options.]]></description><link>https://samperrin.com/posts/custom-naming-in-vra8/</link><guid isPermaLink="false">https://samperrin.com/posts/custom-naming-in-vra8/</guid><category><![CDATA[automation]]></category><category><![CDATA[development]]></category><category><![CDATA[vra]]></category><category><![CDATA[vmware]]></category><pubDate>Wed, 14 Jul 2021 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;VMware vRealize Automation 8 provides several methods for applying custom naming to deployed virtual machines. This article will explore a few of these. &lt;/p&gt;&lt;p&gt;The testing/development within this article was based on vRA 8.2. VMware are providing frequent updates to the vRA product and some areas may be different if you are using an older/newer version.&lt;/p&gt;&lt;p&gt;&lt;em&gt;We will only be focusing on the naming of the virtual machine object, not the hostname/FQDN within the VM OS.&lt;/em&gt;&lt;/p&gt;&lt;p&gt;The blog covers the following methods:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;No Custom Naming / Out-of-the-Box Default&lt;/li&gt;&lt;li&gt;Name Property&lt;/li&gt;&lt;li&gt;Project Custom Naming Template&lt;/li&gt;&lt;li&gt;ABX Action&lt;/li&gt;&lt;li&gt;vRO Workflow&lt;/li&gt;&lt;/ul&gt;&lt;h2 id=&quot;no-custom-naming--out-of-the-box-default&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#no-custom-naming--out-of-the-box-default&quot; aria-label=&quot;no custom naming  out of the box default permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;No Custom Naming / Out-of-the-Box Default&lt;/h2&gt;&lt;p&gt;If you do not apply any of the methods below, vRA automatically names the deployed virtual machine based on the following: &lt;/p&gt;&lt;ul&gt;&lt;li&gt;Resource name (e.g. &lt;code class=&quot;language-text&quot;&gt;SERVER&lt;/code&gt; or &lt;code class=&quot;language-text&quot;&gt;Cloud_Machine_1&lt;/code&gt;) &lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;mcm###&lt;/code&gt; (provided by vRA)&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;############&lt;/code&gt; (provided by vRA)&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;In this instance our Cloud Template looks like this…&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;yaml&quot;&gt;&lt;pre class=&quot;language-yaml&quot;&gt;&lt;code class=&quot;language-yaml&quot;&gt;&lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Custom Naming Test
&lt;span class=&quot;token key atrule&quot;&gt;formatVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;1&lt;/span&gt;
&lt;span class=&quot;token key atrule&quot;&gt;inputs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
&lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;SERVER&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token comment&quot;&gt;# This is the resource name used, by default it will be something like Cloud_Machine_#&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Cloud.Machine
    &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;image&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;TF-CentOS7&amp;#x27;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;flavor&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;B&amp;#x27;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Final result for our VM name: &lt;code class=&quot;language-text&quot;&gt;SERVER-mcm809-174067533632&lt;/code&gt;&lt;/p&gt;&lt;h2 id=&quot;name-property&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#name-property&quot; aria-label=&quot;name property permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Name Property&lt;/h2&gt;&lt;p&gt;Extending slightly on the method above, we could pass in a custom value to the &lt;code class=&quot;language-text&quot;&gt;name&lt;/code&gt; property under our Compute resource. I am using static values in the example Cloud Template, but this could be more dynamic through the use of Inputs.  &lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;yaml&quot;&gt;&lt;pre class=&quot;language-yaml&quot;&gt;&lt;code class=&quot;language-yaml&quot;&gt;&lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Custom Naming Test
&lt;span class=&quot;token key atrule&quot;&gt;formatVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;1&lt;/span&gt;
&lt;span class=&quot;token key atrule&quot;&gt;inputs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
&lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;SERVER&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Cloud.Machine
    &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;myservername&amp;#x27;&lt;/span&gt; &lt;span class=&quot;token comment&quot;&gt;# This overwrites the resource name above&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;image&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;TF-CentOS7&amp;#x27;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;flavor&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;B&amp;#x27;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Final result for our VM name: &lt;code class=&quot;language-text&quot;&gt;myservername-mcm812-174067802073&lt;/code&gt;&lt;/p&gt;&lt;h2 id=&quot;project-custom-naming-template&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#project-custom-naming-template&quot; aria-label=&quot;project custom naming template permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Project Custom Naming Template&lt;/h2&gt;&lt;p&gt;A Project Custom Naming template can be applied to each Project within vRA. This naming template is then applied to machines, networks, security groups and disks provisioned under the Project. &lt;/p&gt;&lt;p&gt;The Custom Naming template used for this example looks like this: &lt;code class=&quot;language-text&quot;&gt;${resource.serviceTier}-${resource.environment}-${resource.role}${####}${resource.datacentreLetter}&lt;/code&gt;&lt;/p&gt;&lt;p&gt;&lt;img src=&quot;/22f320cbc2935bdd7d98841c73da175f/2.png&quot; alt=&quot;Project Custom Naming template&quot;/&gt;&lt;/p&gt;&lt;p&gt;To make this Cloud Template work, we need to provide values for the properties &lt;code class=&quot;language-text&quot;&gt;role&lt;/code&gt;, &lt;code class=&quot;language-text&quot;&gt;serviceTier&lt;/code&gt;, &lt;code class=&quot;language-text&quot;&gt;environment&lt;/code&gt; and &lt;code class=&quot;language-text&quot;&gt;datacentreLetter&lt;/code&gt;. In the Cloud Template example below, under the machine resource we have the properties section, this is where we put our required values. Again, these could be driven by Inputs.&lt;/p&gt;&lt;p&gt;The &lt;code class=&quot;language-text&quot;&gt;####&lt;/code&gt; value within the custom naming template is replaced at deployment time by numbers, this is managed by vRA. This is not required but helps to ensure resource names are unique if you don’t have any other method of checking for uniqueness (suggestions for this in the vRO section below)&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;yaml&quot;&gt;&lt;pre class=&quot;language-yaml&quot;&gt;&lt;code class=&quot;language-yaml&quot;&gt;&lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Custom Naming Test
&lt;span class=&quot;token key atrule&quot;&gt;formatVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;1&lt;/span&gt;
&lt;span class=&quot;token key atrule&quot;&gt;inputs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
&lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;SERVER&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Cloud.Machine
    &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;role&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;web&amp;#x27;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;serviceTier&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;silver&amp;#x27;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;environment&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;dev&amp;#x27;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;datacentreLetter&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;s&amp;#x27;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;image&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;TF-CentOS7&amp;#x27;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;flavor&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;B&amp;#x27;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Final result for our VM name: &lt;code class=&quot;language-text&quot;&gt;silver-dev-web0277s&lt;/code&gt; &lt;em&gt;(serviceTier-environment-role####datacentreLetter)&lt;/em&gt;&lt;/p&gt;&lt;p&gt;In addition to using Properties from the Cloud Template you can utilise the Custom Properties section within the Project. These can then be referenced with &lt;code class=&quot;language-text&quot;&gt;${resource.propertyName}&lt;/code&gt; in the Custom Naming template.&lt;/p&gt;&lt;p&gt;&lt;img src=&quot;/45a9fcbbef22805b606584373c313fe9/5.png&quot; alt=&quot;Project custom properties&quot;/&gt;&lt;/p&gt;&lt;h2 id=&quot;abx-action&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#abx-action&quot; aria-label=&quot;abx action permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;ABX Action&lt;/h2&gt;&lt;p&gt;vRA provides an ABX template that can be used for renaming a resource, by default this expects a property called &lt;code class=&quot;language-text&quot;&gt;newName&lt;/code&gt;. We will modify the action slightly to use the properties in our existing Cloud Template. &lt;/p&gt;&lt;p&gt;As the properties we added are “custom properties” we will need to pull them from the &lt;code class=&quot;language-text&quot;&gt;customProperties&lt;/code&gt; object as part of the inputs. &lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;javascript&quot;&gt;&lt;pre class=&quot;language-javascript&quot;&gt;&lt;code class=&quot;language-javascript&quot;&gt;exports&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;token function-variable function&quot;&gt;handler&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;token keyword&quot;&gt;function&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;handler&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token parameter&quot;&gt;context&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; inputs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;

    &lt;span class=&quot;token comment&quot;&gt;//Get original resource name&lt;/span&gt;
    &lt;span class=&quot;token keyword&quot;&gt;let&lt;/span&gt; oldName &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; inputs&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;resourceNames&lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;0&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
    &lt;span class=&quot;token comment&quot;&gt;//Get random number &lt;/span&gt;
    &lt;span class=&quot;token keyword&quot;&gt;let&lt;/span&gt; number &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; Math&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;floor&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;1000&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;+&lt;/span&gt; Math&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;random&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;*&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;9000&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
    &lt;span class=&quot;token comment&quot;&gt;//Retrieve required properties&lt;/span&gt;
    &lt;span class=&quot;token keyword&quot;&gt;let&lt;/span&gt; customProps &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; inputs&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;customProperties&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
    &lt;span class=&quot;token keyword&quot;&gt;let&lt;/span&gt; role &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; customProps&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;role&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
    &lt;span class=&quot;token keyword&quot;&gt;let&lt;/span&gt; serviceTier &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; customProps&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;serviceTier&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
    &lt;span class=&quot;token keyword&quot;&gt;let&lt;/span&gt; environment &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; customProps&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;environment&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
    &lt;span class=&quot;token keyword&quot;&gt;let&lt;/span&gt; datacentreLetter &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; customProps&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;datacentreLetter&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;

    &lt;span class=&quot;token comment&quot;&gt;//Construct new name&lt;/span&gt;
    &lt;span class=&quot;token keyword&quot;&gt;let&lt;/span&gt; newName &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; serviceTier &lt;span class=&quot;token operator&quot;&gt;+&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;-&amp;quot;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;+&lt;/span&gt; environment &lt;span class=&quot;token operator&quot;&gt;+&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;-&amp;quot;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;+&lt;/span&gt; role &lt;span class=&quot;token operator&quot;&gt;+&lt;/span&gt; number &lt;span class=&quot;token operator&quot;&gt;+&lt;/span&gt; datacentreLetter&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;

    &lt;span class=&quot;token comment&quot;&gt;//Return new name as &amp;quot;outputs&amp;quot;&lt;/span&gt;
    &lt;span class=&quot;token keyword&quot;&gt;let&lt;/span&gt; outputs &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
    outputs&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;resourceNames &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; inputs&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;resourceNames&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
    outputs&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;resourceNames&lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;0&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; newName&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
    console&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;log&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;Setting machine name from &amp;#x27;&amp;quot;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;+&lt;/span&gt; oldName &lt;span class=&quot;token operator&quot;&gt;+&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;#x27; to &amp;#x27;&amp;quot;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;+&lt;/span&gt; newName &lt;span class=&quot;token operator&quot;&gt;+&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;#x27;&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
    &lt;span class=&quot;token keyword&quot;&gt;return&lt;/span&gt; outputs&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Once the action has been created we will add a Subscription and subscribe to the &lt;code class=&quot;language-text&quot;&gt;Compute allocation&lt;/code&gt; event. &lt;/p&gt;&lt;p&gt;&lt;img src=&quot;/21238ae61455ff5884ced476d4d1dcef/6.png&quot; alt=&quot;ABX subscription for custom naming&quot;/&gt;&lt;/p&gt;&lt;p&gt;Final result for our VM name: &lt;code class=&quot;language-text&quot;&gt;silver-prod-web6769s&lt;/code&gt; &lt;em&gt;(serviceTier-environment-role####datacentreLetter)&lt;/em&gt;&lt;/p&gt;&lt;h2 id=&quot;vro-workflow&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#vro-workflow&quot; aria-label=&quot;vro workflow permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;vRO Workflow&lt;/h2&gt;&lt;p&gt;An alternative to the ABX action is to utilise vRealize Orchestrator. We can use almost the same code within our workflow to generate our name, with a few changes. &lt;/p&gt;&lt;p&gt;I won’t go in to detail on how to use vRO here, but there are some additional reference at the bottom of this post that provide a similar outcome but go into much more detail on how to construct the vRO Workflow.&lt;/p&gt;&lt;p&gt;Our workflow needs 1x Input &lt;code class=&quot;language-text&quot;&gt;inputProperties&lt;/code&gt; and 1x Output &lt;code class=&quot;language-text&quot;&gt;resourceNames&lt;/code&gt;. The input will be passed to vRO by vRA, and the output then returned to vRA. &lt;/p&gt;&lt;p&gt;&lt;img src=&quot;/d92f64e4ef360f19d88f31417466b891/7.png&quot; alt=&quot;vRO Inputs/Outputs&quot;/&gt;&lt;/p&gt;&lt;p&gt;For now our Workflow only needs one item, a Scriptable task that we will label &lt;code class=&quot;language-text&quot;&gt;Get Properties and Prepare Name&lt;/code&gt;. &lt;/p&gt;&lt;p&gt;The script will need the same inputs and outputs as our main workflow. &lt;/p&gt;&lt;p&gt;&lt;img src=&quot;/75faf27bfb610e6fe6a343a6667f0239/8.png&quot; alt=&quot;vRO Script Item Inputs/Outputs&quot;/&gt;&lt;/p&gt;&lt;p&gt;The code for our script item will be:&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;javascript&quot;&gt;&lt;pre class=&quot;language-javascript&quot;&gt;&lt;code class=&quot;language-javascript&quot;&gt;&lt;span class=&quot;token comment&quot;&gt;//Get original resource name&lt;/span&gt;
&lt;span class=&quot;token keyword&quot;&gt;var&lt;/span&gt; oldName &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; inputProperties&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;resourceNames&lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;0&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
&lt;span class=&quot;token comment&quot;&gt;//Get random number &lt;/span&gt;
&lt;span class=&quot;token keyword&quot;&gt;var&lt;/span&gt; number &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; Math&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;floor&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;1000&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;+&lt;/span&gt; Math&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;random&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;*&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;9000&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
&lt;span class=&quot;token comment&quot;&gt;//Retrieve required properties&lt;/span&gt;
&lt;span class=&quot;token keyword&quot;&gt;var&lt;/span&gt; customProps &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; inputs&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;customProperties&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
&lt;span class=&quot;token keyword&quot;&gt;var&lt;/span&gt; role &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; customProps&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;role&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
&lt;span class=&quot;token keyword&quot;&gt;var&lt;/span&gt; serviceTier &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; customProps&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;serviceTier&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
&lt;span class=&quot;token keyword&quot;&gt;var&lt;/span&gt; environment &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; customProps&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;environment&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
&lt;span class=&quot;token keyword&quot;&gt;var&lt;/span&gt; datacentreLetter &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; customProps&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;datacentreLetter&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;

&lt;span class=&quot;token comment&quot;&gt;//Construct new name&lt;/span&gt;
&lt;span class=&quot;token keyword&quot;&gt;var&lt;/span&gt; newName &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; serviceTier &lt;span class=&quot;token operator&quot;&gt;+&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;-&amp;quot;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;+&lt;/span&gt; environment &lt;span class=&quot;token operator&quot;&gt;+&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;-&amp;quot;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;+&lt;/span&gt; role &lt;span class=&quot;token operator&quot;&gt;+&lt;/span&gt; number &lt;span class=&quot;token operator&quot;&gt;+&lt;/span&gt; datacentreLetter&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;

&lt;span class=&quot;token comment&quot;&gt;//Return new name as &amp;quot;resourceNames&amp;quot;&lt;/span&gt;
resourceNames &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
resourceNames&lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;0&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; newName&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
System&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;log&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;Setting machine name from &amp;#x27;&amp;quot;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;+&lt;/span&gt; oldName &lt;span class=&quot;token operator&quot;&gt;+&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;#x27; to &amp;#x27;&amp;quot;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;+&lt;/span&gt; newName &lt;span class=&quot;token operator&quot;&gt;+&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;#x27;&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Once the workflow is ready, we just need to update the Subscription that we created earlier and swap out the ABX action for the vRO workflow. &lt;/p&gt;&lt;p&gt;&lt;img src=&quot;/5c7e403bbcff1022da86bcd85ed20dbd/9.png&quot; alt=&quot;vRO subscription for custom naming&quot;/&gt;&lt;/p&gt;&lt;p&gt;Request your deployment and observe vRO for a Workflow run. &lt;/p&gt;&lt;p&gt;Final result for our VM name: &lt;code class=&quot;language-text&quot;&gt;silver-prod-web6477s&lt;/code&gt; &lt;em&gt;(serviceTier-environment-role####datacentreLetter)&lt;/em&gt;&lt;/p&gt;&lt;h2 id=&quot;extending-the-custom-naming&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#extending-the-custom-naming&quot; aria-label=&quot;extending the custom naming permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Extending the Custom Naming&lt;/h2&gt;&lt;p&gt;With the base of our Custom Naming in place, we need to think about duplicate detection and how we handle conflicting names. &lt;/p&gt;&lt;p&gt;One way we could do this is with vRO, we can add additional integrations and endpoints that connect with PowerShell Hosts, Active Directory, ITSM/CMDB systems, and most other things with vRO Plugins or REST API’s. &lt;/p&gt;&lt;p&gt;From here we could use these additional systems to confirm that the name we have generated is unique, for example;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Active Directory to ensure no other computer objects exist with the same name&lt;/li&gt;&lt;li&gt;PowerShell Hosts to connect to DNS servers to ensure there are no existing DNS entries for our new name&lt;/li&gt;&lt;li&gt;CMDB tools to check our name is unique across all other systems, and to also register our new name so we don’t generate it again in the future &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Custom Naming is a key aspect of automated deployments, but be mindful that this will rely on other systems to be successful. &lt;/p&gt;&lt;h2 id=&quot;additional-reading&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#additional-reading&quot; aria-label=&quot;additional reading permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Additional Reading&lt;/h2&gt;&lt;p&gt;&lt;a href=&quot;https://www.stevenbright.com/2020/02/custom-hostname-generation-in-vrealize-automation-8&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://www.stevenbright.com/2020/02/custom-hostname-generation-in-vrealize-automation-8&lt;/a&gt; \
&lt;a href=&quot;https://blog.v12n.io/custom-naming-in-vrealize-automation-8x-2&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://blog.v12n.io/custom-naming-in-vrealize-automation-8x-2&lt;/a&gt; \
&lt;a href=&quot;https://virtuallypotato.com/vra8-custom-provisioning-part-two&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://virtuallypotato.com/vra8-custom-provisioning-part-two&lt;/a&gt;&lt;/p&gt;</content:encoded><tags>automation,development,vra,vmware</tags><featuredImage>https://samperrin.com/static/f4e85ba1bf88dfe0b1d1a36feb9103a4/hero_6.jpg</featuredImage></item><item><title><![CDATA[Azure AKS - Failed to provision volume with StorageClass "default"]]></title><description><![CDATA[When deploying concourse to Azure AKS I encountered an error relating to PersistentVolumes]]></description><link>https://samperrin.com/posts/azure-aks-failed-to-provision-volume-with-storageclass-default/</link><guid isPermaLink="false">https://samperrin.com/posts/azure-aks-failed-to-provision-volume-with-storageclass-default/</guid><category><![CDATA[kubernetes]]></category><category><![CDATA[development]]></category><pubDate>Mon, 07 Dec 2020 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;I wanted to deploy Concourse CI in to my Azure AKS cluster, which I hadn’t touched for a while, and encountered the error &lt;code class=&quot;language-text&quot;&gt;Failed to provision volume with StorageClass &amp;quot;default&amp;quot;&lt;/code&gt;. &lt;/p&gt;&lt;p&gt;This post will cover my troubleshooting steps and ultimately the resolution - which was to update/rotate my Azure AKS credentials. &lt;/p&gt;&lt;p&gt;I followed the HELM install steps from Concourse CI &lt;a href=&quot;https://github.com/concourse/concourse-chart&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://github.com/concourse/concourse-chart&lt;/a&gt;.&lt;/p&gt;&lt;h2 id=&quot;troubleshooting-steps&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#troubleshooting-steps&quot; aria-label=&quot;troubleshooting steps permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Troubleshooting Steps&lt;/h2&gt;&lt;p&gt;To start I checked the status of the Pods deployed, they all showed Pending: &lt;code class=&quot;language-text&quot;&gt;kubectl get pods&lt;/code&gt;.&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;text&quot;&gt;&lt;pre class=&quot;language-text&quot;&gt;&lt;code class=&quot;language-text&quot;&gt;NAMESPACE     NAME                                         READY   STATUS    RESTARTS   AGE
default       concourse-ci-postgresql-0                    0/1     Pending   0          5m11s
default       concourse-ci-web-d6bc9f97d-pr5zd             0/1     Running   1          5m11s
default       concourse-ci-worker-0                        0/1     Pending   0          5m11s
default       concourse-ci-worker-1                        0/1     Pending   0          5m11s&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;I investigated the logs from pod &lt;em&gt;concourse-ci-web-d6bc9f97d-pr5zd&lt;/em&gt;: &lt;code class=&quot;language-text&quot;&gt;kubectl logs concourse-ci-web-d6bc9f97d-pr5zd&lt;/code&gt;.&lt;/p&gt;&lt;p&gt;These showed an error trying to reach the database. &lt;code class=&quot;language-text&quot;&gt;&amp;quot;error&amp;quot;:&amp;quot;dial tcp: lookup concourse-ci-postgresql on 10.0.0.10:53: no such host&amp;quot;&lt;/code&gt;&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;text&quot;&gt;&lt;pre class=&quot;language-text&quot;&gt;&lt;code class=&quot;language-text&quot;&gt;{&amp;quot;timestamp&amp;quot;:&amp;quot;2020-12-07T10:57:08.526432188Z&amp;quot;,&amp;quot;level&amp;quot;:&amp;quot;info&amp;quot;,&amp;quot;source&amp;quot;:&amp;quot;atc&amp;quot;,&amp;quot;message&amp;quot;:&amp;quot;atc.cmd.start&amp;quot;,&amp;quot;data&amp;quot;:{&amp;quot;session&amp;quot;:&amp;quot;1&amp;quot;}}
{&amp;quot;timestamp&amp;quot;:&amp;quot;2020-12-07T10:57:08.561956604Z&amp;quot;,&amp;quot;level&amp;quot;:&amp;quot;error&amp;quot;,&amp;quot;source&amp;quot;:&amp;quot;atc&amp;quot;,&amp;quot;message&amp;quot;:&amp;quot;atc.db.failed-to-open-db-retrying&amp;quot;,&amp;quot;data&amp;quot;:{&amp;quot;error&amp;quot;:&amp;quot;dial tcp: lookup concourse-ci-postgresql on 10.0.0.10:53: no such host&amp;quot;,&amp;quot;session&amp;quot;:&amp;quot;3&amp;quot;}}
{&amp;quot;timestamp&amp;quot;:&amp;quot;2020-12-07T10:57:13.671634392Z&amp;quot;,&amp;quot;level&amp;quot;:&amp;quot;error&amp;quot;,&amp;quot;source&amp;quot;:&amp;quot;atc&amp;quot;,&amp;quot;message&amp;quot;:&amp;quot;atc.db.failed-to-open-db-retrying&amp;quot;,&amp;quot;data&amp;quot;:{&amp;quot;error&amp;quot;:&amp;quot;dial tcp: lookup concourse-ci-postgresql on 10.0.0.10:53: no such host&amp;quot;,&amp;quot;session&amp;quot;:&amp;quot;3&amp;quot;}}
{&amp;quot;timestamp&amp;quot;:&amp;quot;2020-12-07T10:57:18.707090349Z&amp;quot;,&amp;quot;level&amp;quot;:&amp;quot;error&amp;quot;,&amp;quot;source&amp;quot;:&amp;quot;atc&amp;quot;,&amp;quot;message&amp;quot;:&amp;quot;atc.db.failed-to-open-db-retrying&amp;quot;,&amp;quot;data&amp;quot;:{&amp;quot;error&amp;quot;:&amp;quot;dial tcp: lookup concourse-ci-postgresql on 10.0.0.10:53: no such host&amp;quot;,&amp;quot;session&amp;quot;:&amp;quot;3&amp;quot;}}&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Due to the database connection error above, I looked in to the &lt;em&gt;concourse-ci-postgresql-0&lt;/em&gt; pod. I did a &lt;code class=&quot;language-text&quot;&gt;describe&lt;/code&gt; this time to see what Events were being produced: &lt;code class=&quot;language-text&quot;&gt;kubectl describe pod concourse-ci-postgresql-0&lt;/code&gt;. &lt;/p&gt;&lt;p&gt;The top event shows us that it is having issues with scheduling and binding to PersistentVolumeClaims: &lt;code class=&quot;language-text&quot;&gt;Warning  FailedScheduling  11m   default-scheduler  running &amp;quot;VolumeBinding&amp;quot; filter plugin for pod &amp;quot;concourse-ci-postgresql-0&amp;quot;: pod has unbound immediate PersistentVolumeClaims&lt;/code&gt;.&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;text&quot;&gt;&lt;pre class=&quot;language-text&quot;&gt;&lt;code class=&quot;language-text&quot;&gt;Name:           concourse-ci-postgresql-0
Namespace:      default
Priority:       0
Node:           &amp;lt;none&amp;gt;
Labels:         app.kubernetes.io/instance=concourse-ci
                app.kubernetes.io/managed-by=Helm
                app.kubernetes.io/name=postgresql
                controller-revision-hash=concourse-ci-postgresql-5c7bfbd7bb
                helm.sh/chart=postgresql-9.2.0
                role=master
                statefulset.kubernetes.io/pod-name=concourse-ci-postgresql-0
Annotations:    &amp;lt;none&amp;gt;
Status:         Pending
IP:
IPs:            &amp;lt;none&amp;gt;
Controlled By:  StatefulSet/concourse-ci-postgresql
Containers:
  concourse-ci-postgresql:
    Image:      docker.io/bitnami/postgresql:11.8.0-debian-10-r76
    Port:       5432/TCP
    Host Port:  0/TCP
    Requests:
      cpu:      250m
      memory:   256Mi
    Liveness:   exec [/bin/sh -c exec pg_isready -U &amp;quot;concourse&amp;quot; -d &amp;quot;dbname=concourse&amp;quot; -h 127.0.0.1 -p 5432] delay=30s timeout=5s period=10s #success=1 #failure=6
    Readiness:  exec [/bin/sh -c -e exec pg_isready -U &amp;quot;concourse&amp;quot; -d &amp;quot;dbname=concourse&amp;quot; -h 127.0.0.1 -p 5432
[ -f /opt/bitnami/postgresql/tmp/.initialized ] || [ -f /bitnami/postgresql/.initialized ]
] delay=5s timeout=5s period=10s #success=1 #failure=6
    Environment:
      BITNAMI_DEBUG:           false
      POSTGRESQL_PORT_NUMBER:  5432
      POSTGRESQL_VOLUME_DIR:   /bitnami/postgresql
      PGDATA:                  /bitnami/postgresql/data
      POSTGRES_USER:           concourse
      POSTGRES_PASSWORD:       &amp;lt;set to the key &amp;#x27;postgresql-password&amp;#x27; in secret &amp;#x27;concourse-ci-postgresql&amp;#x27;&amp;gt;  Optional: false
      POSTGRESQL_ENABLE_LDAP:  no
      POSTGRESQL_ENABLE_TLS:   no
    Mounts:
      /bitnami/postgresql from data (rw)
      /var/run/secrets/kubernetes.io/serviceaccount from default-token-zpr9z (ro)
  Type           Status
  PodScheduled   False
Volumes:
  data:
    Type:       PersistentVolumeClaim (a reference to a PersistentVolumeClaim in the same namespace)
    ClaimName:  data-concourse-ci-postgresql-0
    ReadOnly:   false
  dshm:
    Type:       EmptyDir (a temporary directory that shares a pod&amp;#x27;s lifetime)
    Medium:     Memory
    SizeLimit:  1Gi
  default-token-zpr9z:
    Type:        Secret (a volume populated by a Secret)
    SecretName:  default-token-zpr9z
    Optional:    false
QoS Class:       Burstable
Node-Selectors:  &amp;lt;none&amp;gt;
Tolerations:     node.kubernetes.io/not-ready:NoExecute op=Exists for 300s
                 node.kubernetes.io/unreachable:NoExecute op=Exists for 300s
Events:
  Type     Reason            Age   From               Message
  ----     ------            ----  ----               -------
  Warning  FailedScheduling  11m   default-scheduler  running &amp;quot;VolumeBinding&amp;quot; filter plugin for pod &amp;quot;concourse-ci-postgresql-0&amp;quot;: pod has unbound immediate PersistentVolumeClaims
  Warning  FailedScheduling  11m   default-scheduler  running &amp;quot;VolumeBinding&amp;quot; filter plugin for pod &amp;quot;concourse-ci-postgresql-0&amp;quot;: pod has unbound immediate PersistentVolumeClaims&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Next step was to have a look at the PersistentVolumeClaims: &lt;code class=&quot;language-text&quot;&gt;kubectl get pvc&lt;/code&gt;.&lt;/p&gt;&lt;p&gt;Again, like the pods, these were all Pending. &lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;text&quot;&gt;&lt;pre class=&quot;language-text&quot;&gt;&lt;code class=&quot;language-text&quot;&gt;NAME                                       STATUS    VOLUME   CAPACITY   ACCESS MODES   STORAGECLASS   AGE
concourse-work-dir-concourse-ci-worker-0   Pending                                      default        14m
concourse-work-dir-concourse-ci-worker-1   Pending                                      default        14m
data-concourse-ci-postgresql-0             Pending                                      default        14m&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;I investigated one of the PVC’s: &lt;code class=&quot;language-text&quot;&gt;kubectl describe pvc concourse-work-dir-concourse-ci-worker-0&lt;/code&gt;. &lt;/p&gt;&lt;p&gt;Within the messages we can see quite clearly what the problem is: &lt;code class=&quot;language-text&quot;&gt;Failed to provision volume with StorageClass &amp;quot;default&amp;quot;: Retriable: false, RetryAfter: 0s, HTTPStatusCode: 401, RawError: Retriable: false, RetryAfter: 0s, HTTPStatusCode: 401, RawError: azure.BearerAuthorizer#WithAuthorization: Failed to refresh the Token for request to http://localhost:7788/subscriptions/8af15f99-1234-43e2-8876-55bd7e6a727b/resourceGroups/mc_development_uksouth/providers/Microsoft.Compute/disks/kubernetes-dynamic-pvc-f52878cf-5fb4-4de5-82f0-e9b284b29a9d?api-version=2019-07-01&lt;/code&gt;&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;text&quot;&gt;&lt;pre class=&quot;language-text&quot;&gt;&lt;code class=&quot;language-text&quot;&gt;Name:          concourse-work-dir-concourse-ci-worker-0
Namespace:     default
StorageClass:  default
Status:        Pending
Volume:
Labels:        app=concourse-ci-worker
               release=concourse-ci
Annotations:   volume.beta.kubernetes.io/storage-provisioner: kubernetes.io/azure-disk
Finalizers:    [kubernetes.io/pvc-protection]
Capacity:
Access Modes:
VolumeMode:    Filesystem
Mounted By:    concourse-ci-worker-0
Events:
  Type     Reason              Age                  From                         Message
  ----     ------              ----                 ----                         -------
  Warning  ProvisioningFailed  15m                  persistentvolume-controller  Failed to provision volume with StorageClass &amp;quot;default&amp;quot;: Retriable: false, RetryAfter: 0s, HTTPStatusCode: 401, RawError: Retriable: false, RetryAfter: 0s, HTTPStatusCode: 401, RawError: azure.BearerAuthorizer#WithAuthorization: Failed to refresh the Token for request to http://localhost:7788/subscriptions/8af15f99-1234-43e2-8876-55bd7e6a727b/resourceGroups/mc_development_uksouth/providers/Microsoft.Compute/disks/kubernetes-dynamic-pvc-f52878cf-5fb4-4de5-82f0-e9b284b29a9d?api-version=2019-07-01: StatusCode=401 -- Original Error: adal: Refresh request failed. Status Code = &amp;#x27;401&amp;#x27;. Response body: {&amp;quot;error&amp;quot;:&amp;quot;invalid_client&amp;quot;,&amp;quot;error_description&amp;quot;:&amp;quot;AADSTS7000222: The provided client secret keys are expired. Visit the Azure Portal to create new keys for your app, or consider using certificate credentials for added security: https://docs.microsoft.com/azure/active-directory/develop/active-directory-certificate-credentials\r\nTrace ID: 8f13a52c-9f01-4012-9da2-4127e054cf00\r\nCorrelation ID: 054bec33-1b44-456f-b91b-4cb8bc4967e1\r\nTimestamp: 2020-12-07 10:55:24Z&amp;quot;,&amp;quot;error_codes&amp;quot;:[7000222],&amp;quot;timestamp&amp;quot;:&amp;quot;2020-12-07 10:55:24Z&amp;quot;,&amp;quot;trace_id&amp;quot;:&amp;quot;8f13a52c-9f01-4012-9da2-4127e054cf00&amp;quot;,&amp;quot;correlation_id&amp;quot;:&amp;quot;054bec33-1b44-456f-b91b-4cb8bc4967e1&amp;quot;,&amp;quot;error_uri&amp;quot;:&amp;quot;https://login.microsoftonline.com/error?code=7000222&amp;quot;}&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Next step was to resolve the storage provisioning issues. Using information from the error above, and some Googling, I came across the following GitHub issue which showed the same error we were recieving &lt;a href=&quot;https://github.com/Azure/AKS/issues/222&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://github.com/Azure/AKS/issues/222&lt;/a&gt;. &lt;/p&gt;&lt;p&gt;This GitHub issue included a comment to the following Microsoft documentation page for updating credentials. &lt;a href=&quot;https://docs.microsoft.com/en-us/azure/aks/update-credentials&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://docs.microsoft.com/en-us/azure/aks/update-credentials&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;After completing the steps provided, I checked the same PVC as earlier to check on its status: &lt;code class=&quot;language-text&quot;&gt;kubectl describe pvc concourse-work-dir-concourse-ci-worker-0&lt;/code&gt;. We can now see that the volume has been provisioned: &lt;code class=&quot;language-text&quot;&gt;Successfully provisioned volume pvc-f52878cf-5fb4-4de5-82f0-e9b284b29a9d using kubernetes.io/azure-disk&lt;/code&gt;&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;text&quot;&gt;&lt;pre class=&quot;language-text&quot;&gt;&lt;code class=&quot;language-text&quot;&gt;Name:          concourse-work-dir-concourse-ci-worker-0
Namespace:     default
StorageClass:  default
Status:        Bound
Volume:        pvc-f52878cf-5fb4-4de5-82f0-e9b284b29a9d
Labels:        app=concourse-ci-worker
               release=concourse-ci
Annotations:   pv.kubernetes.io/bind-completed: yes
               pv.kubernetes.io/bound-by-controller: yes
               volume.beta.kubernetes.io/storage-provisioner: kubernetes.io/azure-disk
Finalizers:    [kubernetes.io/pvc-protection]
Capacity:      20Gi
Access Modes:  RWO
VolumeMode:    Filesystem
Mounted By:    concourse-ci-worker-0
Events:
  Type     Reason                 Age                   From                         Message
  ----     ------                 ----                  ----                         -------
  Normal   ProvisioningSucceeded  66s                   persistentvolume-controller  Successfully provisioned volume pvc-f52878cf-5fb4-4de5-82f0-e9b284b29a9d using kubernetes.io/azure-disk&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Checking the status of the pods again, we can see they are now Running/Creating: &lt;code class=&quot;language-text&quot;&gt;kubectl get pod&lt;/code&gt;.&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;text&quot;&gt;&lt;pre class=&quot;language-text&quot;&gt;&lt;code class=&quot;language-text&quot;&gt;NAME                               READY   STATUS              RESTARTS   AGE
concourse-ci-postgresql-0          0/1     ContainerCreating   0          46m
concourse-ci-web-d6bc9f97d-pr5zd   0/1     Running             14         46m
concourse-ci-worker-0              1/1     Running             0          46m
concourse-ci-worker-1              0/1     Pending             0          46m&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&quot;references&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#references&quot; aria-label=&quot;references permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;References&lt;/h2&gt;&lt;p&gt;&lt;a href=&quot;https://github.com/Azure/AKS/issues/222&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://github.com/Azure/AKS/issues/222&lt;/a&gt; \
&lt;a href=&quot;https://docs.microsoft.com/en-us/azure/aks/update-credentials&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://docs.microsoft.com/en-us/azure/aks/update-credentials&lt;/a&gt;&lt;/p&gt;</content:encoded><tags>kubernetes,development</tags><featuredImage>https://samperrin.com/static/a0511c8075ba8349a213f67f0f3e2347/hero_5.jpg</featuredImage></item><item><title><![CDATA[Triggering vRO Workflow with SRM Recovery Plan]]></title><description><![CDATA[VMware Site Recovery Manager allows you to trigger Custom Scripts as part of a Recovery Plan, this post explores triggering a vRO Workflow with an SRM Recovery Plan]]></description><link>https://samperrin.com/posts/triggering-vro-workflow-with-srm-recovery-plan/</link><guid isPermaLink="false">https://samperrin.com/posts/triggering-vro-workflow-with-srm-recovery-plan/</guid><category><![CDATA[automation]]></category><category><![CDATA[vro]]></category><category><![CDATA[vrealize]]></category><category><![CDATA[vra]]></category><pubDate>Tue, 01 Dec 2020 00:00:00 GMT</pubDate><content:encoded>&lt;h2 id=&quot;introduction&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#introduction&quot; aria-label=&quot;introduction permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Introduction&lt;/h2&gt;&lt;p&gt;VMware Site Recovery Manager (SRM) provides you with the ability to create Custom Recovery Steps as part of a Recovery Plan. &lt;/p&gt;&lt;p&gt;There are two types of Custom Recovery Step, &lt;strong&gt;Command&lt;/strong&gt; and &lt;strong&gt;Message Prompt&lt;/strong&gt;. Each of these can be run as “top-level” steps in the recovery plan or on a “per-vm” basis during &lt;em&gt;pre-&lt;/em&gt; and &lt;em&gt;post-&lt;/em&gt; power on phases. &lt;/p&gt;&lt;p&gt;This post will explore triggering a vRO Workflow as a “top-level” step in a Recovery Plan, to summarise the steps we will go through: &lt;/p&gt;&lt;ul&gt;&lt;li&gt;Create vRO workflow.&lt;/li&gt;&lt;li&gt;Create shell script on SRM Appliance.&lt;/li&gt;&lt;li&gt;Create Recovery Plan with Custom Step.&lt;/li&gt;&lt;li&gt;Run a Recovery test.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;If you are following this step for step, you will need:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Working deployment of SRM and the ability to create Recovery Plans.&lt;/li&gt;&lt;li&gt;Access to the SRM appliances to create local scripts.&lt;/li&gt;&lt;li&gt;Working deployment of vRO and access to create workflows.&lt;/li&gt;&lt;li&gt;An account with permissions to execute workflows.&lt;/li&gt;&lt;/ul&gt;&lt;h2 id=&quot;create-vro-workflow&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#create-vro-workflow&quot; aria-label=&quot;create vro workflow permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Create vRO Workflow&lt;/h2&gt;&lt;p&gt;Create a new workflow with 3 inputs, all of type &lt;code class=&quot;language-text&quot;&gt;string&lt;/code&gt;:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;recoveryPlanName&lt;/code&gt;&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;recoveryPlanMode&lt;/code&gt;&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;recoveryVmwareVcHost&lt;/code&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Map these inputs to a Scripting object that has the following contents.&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;javascript&quot;&gt;&lt;pre class=&quot;language-javascript&quot;&gt;&lt;code class=&quot;language-javascript&quot;&gt;System&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;debug&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;Recovery Plan Name: &amp;quot;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;+&lt;/span&gt; recoveryPlanName&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
System&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;debug&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;Recovery Plan Mode: &amp;quot;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;+&lt;/span&gt; recoveryPlanMode&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
System&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;debug&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;Recovery Plan VC: &amp;quot;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;+&lt;/span&gt; recoveryVmwareVcHost&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Once the workflow has been created, take note of the workflow ID. If you are using the Java Client you will find this in the ID field on the “General” tab of the workflow. If you are using the HTML5 client you will find it in the URL bar when in edit mode. &lt;/p&gt;&lt;p&gt;You can also download the Workflow and import it: &lt;a href=&quot;/332f7f39562ba59f0137d5c8f933e29a/SRM-Recovery-Plan-Details.zip&quot;&gt;SRM Recovery Plan Details.zip&lt;/a&gt;&lt;/p&gt;&lt;h2 id=&quot;environment-variables&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#environment-variables&quot; aria-label=&quot;environment variables permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Environment Variables&lt;/h2&gt;&lt;p&gt;Site Recovery Manager sets the following environment variables for the duration of the command step. Тhe environment variables do not exist in Site Recovery Manager Server or the guest OS of the recovered VM when the command is completed. We will utilise these environment variables within our shell script, and you might have noticed they provide the values that our workflow is looking for as inputs. &lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;VMware_RecoveryName&lt;/code&gt;: Name of the recovery plan that is running.&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;VMware_RecoveryMode&lt;/code&gt;	Recovery mode.&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;VMware_VC_Host&lt;/code&gt; Host name of the vCenter Server at the recovery site.&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;VMware_VC_Port&lt;/code&gt; Network port used to contact vCenter Server.&lt;/li&gt;&lt;/ul&gt;&lt;h2 id=&quot;create-shell-script&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#create-shell-script&quot; aria-label=&quot;create shell script permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Create Shell Script&lt;/h2&gt;&lt;p&gt;This script will trigger the vRO workflow we have just created. It will need to be stored on the SRM server. We are using the Appliance version of SRM, if you are using the Windows version you will need to modify the commands used and save it as &lt;code class=&quot;language-text&quot;&gt;.bat&lt;/code&gt; instead of .&lt;code class=&quot;language-text&quot;&gt;sh&lt;/code&gt;.&lt;/p&gt;&lt;p&gt;Connect to the SRM Appliance via SSH and login as user &lt;code class=&quot;language-text&quot;&gt;admin&lt;/code&gt;.&lt;/p&gt;&lt;p&gt;When the recovery plan is run, this script will be triggered by the Command Custom Step, and it is run on the recovery site appliance as user &lt;code class=&quot;language-text&quot;&gt;srm&lt;/code&gt;. I would suggest adding this script to both the protected site and recovery site Appliances - this will allow you to execute the script in either direction. This script executes a function that makes a POST request to the vRO server with a payload that maps to our Workflow inputs.&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre class=&quot;language-shell&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;&lt;span class=&quot;token comment&quot;&gt;#Create the script file&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;vi&lt;/span&gt; /home/admin/trigger-vro-workflow.sh&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Add the following contents. You will need to modify the values for the variables on the highlighted lines. (&lt;code class=&quot;language-text&quot;&gt;VRO_SERVER&lt;/code&gt;, &lt;code class=&quot;language-text&quot;&gt;VRO_WORKFLOW_ID&lt;/code&gt;, &lt;code class=&quot;language-text&quot;&gt;VRO_USERNAME&lt;/code&gt;, &lt;code class=&quot;language-text&quot;&gt;VRO_PASSWORD&lt;/code&gt;).&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre class=&quot;language-shell&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;&lt;span class=&quot;token shebang important&quot;&gt;#!/bin/bash&lt;/span&gt;

&lt;span class=&quot;token comment&quot;&gt;#FQDN or IP of the vRO server.&lt;/span&gt;
&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;&lt;span class=&quot;token assign-left variable&quot;&gt;VRO_SERVER&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;vroserver01.domain.com&amp;quot;&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;token comment&quot;&gt;#Workflow ID to execute.&lt;/span&gt;
&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;&lt;span class=&quot;token assign-left variable&quot;&gt;VRO_WORKFLOW_ID&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;67748eec-e51c-8dd9-ac57-a7ca789a706c&amp;quot;&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;token comment&quot;&gt;#Username and Password with the required credentials to execute the specified workflow.&lt;/span&gt;
&lt;span class=&quot;token comment&quot;&gt;#Recommendation is to create a service account for just this purpose, with reduced permissions to workflows.&lt;/span&gt;
&lt;span class=&quot;token comment&quot;&gt;#Or modify the script to retirieve the credentials from something like Hashicorp Vault&lt;/span&gt;
&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;&lt;span class=&quot;token assign-left variable&quot;&gt;VRO_USERNAME&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;administrator@vsphere.local&amp;quot;&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;gatsby-highlight-code-line&quot;&gt;&lt;span class=&quot;token assign-left variable&quot;&gt;VRO_PASSWORD&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;password1!&amp;quot;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;token comment&quot;&gt;#Autogenerated&lt;/span&gt;
&lt;span class=&quot;token assign-left variable&quot;&gt;DATE&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token variable&quot;&gt;&lt;span class=&quot;token variable&quot;&gt;$(&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;date&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;+%Y-%m-%d_%H-%M-%S&amp;quot;&lt;/span&gt;&lt;span class=&quot;token variable&quot;&gt;)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;token assign-left variable&quot;&gt;VRO_URL&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;https://&lt;span class=&quot;token variable&quot;&gt;$VRO_SERVER&lt;/span&gt;/vco/api/workflows/&lt;span class=&quot;token variable&quot;&gt;$VRO_WORKFLOW_ID&lt;/span&gt;/executions

&lt;span class=&quot;token function-name function&quot;&gt;vro_function&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
  &lt;span class=&quot;token builtin class-name&quot;&gt;echo&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&lt;span class=&quot;token variable&quot;&gt;$DATE&lt;/span&gt;: Recovery Plan &lt;span class=&quot;token variable&quot;&gt;$VMware_RecoveryName&lt;/span&gt; ran in &lt;span class=&quot;token variable&quot;&gt;$VMware_RecoveryMode&lt;/span&gt; mode&amp;quot;&lt;/span&gt;
  &lt;span class=&quot;token builtin class-name&quot;&gt;echo&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;vRO REST Call: &lt;span class=&quot;token variable&quot;&gt;$VRO_URL&lt;/span&gt;&amp;quot;&lt;/span&gt;

  &lt;span class=&quot;token function&quot;&gt;curl&lt;/span&gt; -k &lt;span class=&quot;token variable&quot;&gt;$VRO_URL&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;\&lt;/span&gt;
    -H &lt;span class=&quot;token string&quot;&gt;&amp;quot;Accept: application/json&amp;quot;&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;\&lt;/span&gt;
    -H &lt;span class=&quot;token string&quot;&gt;&amp;quot;Content-Type:application/json&amp;quot;&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;\&lt;/span&gt;
    --user &lt;span class=&quot;token variable&quot;&gt;$VRO_USERNAME&lt;/span&gt;&lt;span class=&quot;token builtin class-name&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token variable&quot;&gt;$VRO_PASSWORD&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;\&lt;/span&gt;
    -d &lt;span class=&quot;token string&quot;&gt;&amp;quot;&lt;span class=&quot;token variable&quot;&gt;&lt;span class=&quot;token variable&quot;&gt;$(&lt;/span&gt;
      &lt;span class=&quot;token function&quot;&gt;cat&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;&amp;lt;&amp;lt;&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;EOF
    {
      &amp;quot;parameters&amp;quot;: [
        {
          &amp;quot;value&amp;quot;: {
            &amp;quot;string&amp;quot;: {
              &amp;quot;value&amp;quot;: &amp;quot;&lt;span class=&quot;token variable&quot;&gt;$VMware_RecoveryName&lt;/span&gt;&amp;quot;
            }
          },
          &amp;quot;type&amp;quot;: &amp;quot;string&amp;quot;,
          &amp;quot;name&amp;quot;: &amp;quot;recoveryPlanName&amp;quot;,
          &amp;quot;scope&amp;quot;: &amp;quot;local&amp;quot;
        },
        {
          &amp;quot;value&amp;quot;: {
            &amp;quot;string&amp;quot;: {
              &amp;quot;value&amp;quot;: &amp;quot;&lt;span class=&quot;token variable&quot;&gt;$VMware_RecoveryMode&lt;/span&gt;&amp;quot;
            }
          },
          &amp;quot;type&amp;quot;: &amp;quot;string&amp;quot;,
          &amp;quot;name&amp;quot;: &amp;quot;recoveryPlanMode&amp;quot;,
          &amp;quot;scope&amp;quot;: &amp;quot;local&amp;quot;
        },
        {
          &amp;quot;value&amp;quot;: {
            &amp;quot;string&amp;quot;: {
              &amp;quot;value&amp;quot;: &amp;quot;&lt;span class=&quot;token variable&quot;&gt;$VMware_VC_Host&lt;/span&gt;&amp;quot;
            }
          },
          &amp;quot;type&amp;quot;: &amp;quot;string&amp;quot;,
          &amp;quot;name&amp;quot;: &amp;quot;recoveryVmwareVcHost&amp;quot;,
          &amp;quot;scope&amp;quot;: &amp;quot;local&amp;quot;
        }
      ]
    }
EOF&lt;/span&gt;
    &lt;span class=&quot;token variable&quot;&gt;)&lt;/span&gt;&lt;/span&gt;&amp;quot;&lt;/span&gt;
&lt;span class=&quot;token builtin class-name&quot;&gt;echo&lt;/span&gt;  &lt;span class=&quot;token comment&quot;&gt;#add new line in log file&lt;/span&gt;
&lt;span class=&quot;token builtin class-name&quot;&gt;echo&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;------------------&amp;quot;&lt;/span&gt;

&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;&amp;gt;&amp;gt;&lt;/span&gt; /tmp/SRM-VRO-Output.log &lt;span class=&quot;token operator&quot;&gt;&lt;span class=&quot;token file-descriptor important&quot;&gt;2&lt;/span&gt;&amp;gt;&lt;/span&gt;&lt;span class=&quot;token file-descriptor important&quot;&gt;&amp;amp;1&lt;/span&gt;
vro_function

&lt;span class=&quot;token builtin class-name&quot;&gt;exit&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;0&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;When the script is triggered through the Custom step, it is run as user &lt;code class=&quot;language-text&quot;&gt;srm&lt;/code&gt;. To support this, we need to change the permissions on our script. &lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre class=&quot;language-shell&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;&lt;span class=&quot;token comment&quot;&gt;#Change the scripts access permissions, to allow the user &amp;quot;srm&amp;quot; to execute it&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;chmod&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;755&lt;/span&gt; /home/admin/trigger-vro-workflow.sh&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&quot;createmodify-srm-recovery-plan&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#createmodify-srm-recovery-plan&quot; aria-label=&quot;createmodify srm recovery plan permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Create/Modify SRM Recovery Plan&lt;/h2&gt;&lt;p&gt;Create or Modify an SRM Recovery Plan, on the Recovery Steps tab, right click on &lt;strong&gt;Power on priority 1 VMs&lt;/strong&gt; and select “Add Step Before”.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Type&lt;/strong&gt;: Command on SRM Server&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Name&lt;/strong&gt;: vRO Workflow&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Content&lt;/strong&gt;: &lt;code class=&quot;language-text&quot;&gt;/bin/sh -c /home/admin/trigger-vro-workflow.sh&lt;/code&gt; &lt;/li&gt;&lt;li&gt;&lt;strong&gt;Timeout&lt;/strong&gt;: 5 minutes &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Execute a TEST of the Recovery Plan, you should hopefully see a success against the vRO Workflow step. &lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:403px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:83.6228287841191%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAARCAYAAADdRIy+AAAACXBIWXMAAA7DAAAOwwHHb6hkAAAB7ElEQVQ4y5VU0Y7TMBDs//8Q3A/whODpJCQ4xFU91CZO4l3biWOnGbQbu7Qcp0KkkbauPTu7O/ZunmfknG+QUkKMEfLf/2I3TRPaplE0TYPT6QQiekUqsey9ByU0XY/9zyOMMUrYdR2YWSHkgmmKSnoPO8lOzuPbSwPvPZhIMfSDEvV9rwmWZcH5fL4LJUx5wf5EcMxKQMRwzmEYLJzblA7DlsCShdWY0bYNnPdYgWvChJwj2pdPqlA2kiUlVEjZWv5WuuyRdS5rznms63pLuOQJw/EjQgiqROB4OyQKraWNoCivv2W/9+FPwgjLHl8PPULwsNaqEjlszDYcshZd32ssg5P+5rygfq96yD7g6WgQtOR6mMqErSYRiJXuDyUleGIcHr+U/mxW8Vc95GKdlPNNeX8nzBkLM+y7B22+9E97xVuvZECaiPlyiy4ot0ziaqvdnDLWOSA9f8A4jqpElKknmcpgvPZK2tOZTsuX/nbGXG6VkIl6JYxhgP3+oCR1KDpN+h2L8nGaLurUv1fx1VAyHLUw+/fFElZVSQ9JB8NqXiGMcf6HHkqmOeH5x6F4zpYynZJxVWutKrlLmNKMMSZ8fjoWEtLh1HstHhQDi33ExPIJ6VtQY7Mf8bg3N6+LxNV/dV0S1qfsrdfmF4GPI1MLAhcgAAAAAElFTkSuQmCC&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;SRM Recovery Plan insert step context menu&quot; title=&quot;SRM Recovery Plan insert step context menu&quot; src=&quot;/static/c1ce89dafc83ac9717d2d63f9de07e7c/6945a/2.png&quot; srcSet=&quot;/static/c1ce89dafc83ac9717d2d63f9de07e7c/6945a/2.png 403w&quot; sizes=&quot;(max-width: 403px) 100vw, 403px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;SRM Recovery Plan insert step context menu&lt;/figcaption&gt;
  &lt;/figure&gt;&lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1157px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:49.351771823681936%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAKCAYAAAC0VX7mAAAACXBIWXMAAA7DAAAOwwHHb6hkAAAA2ElEQVQoz52RSQrDMAxFff9Vr9Fr9AQ9QhdusgmZB8tDfvkGh7g0nQQPgZC+JqW1hr5r0JdlmVEUBaqqQtu2aJrmLcyp6xrKGAPvPZxzCCFAnIcPIcbIr6amacoCzSzo+wGMs5m1NiIiG2y0rutL1DAM2SRWBH3XRTEWJ5+EmctNDgXneY4Jybi6GINlWSIUJKmAdiQWBdk9Je39P3Yo+M0kr+Az1TiO2Q3TjdLxeQLySWz7Mu+zn5Bie54Lni3EyVZUo6DoTL7yu8KjqYwLWKzH+VridLnhAQ/DEkMGZ8YjAAAAAElFTkSuQmCC&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Custom recovery step options and settings modal&quot; title=&quot;Custom recovery step options and settings modal&quot; src=&quot;/static/c438601ebcb64b0d99342769a5fa4457/03e15/3.png&quot; srcSet=&quot;/static/c438601ebcb64b0d99342769a5fa4457/03e15/3.png 1157w&quot; sizes=&quot;(max-width: 1157px) 100vw, 1157px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Custom recovery step options and settings modal&lt;/figcaption&gt;
  &lt;/figure&gt;&lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:400px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:86.75%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAARCAIAAABSJhvpAAAACXBIWXMAAA7DAAAOwwHHb6hkAAACH0lEQVQ4y3WTW4sTQRCF8/cFH/QXCL4IIviga1xdQRDUSeLGgKsuCl42M9lMMl1dVd3VPZeelp6sbGA330P1MFBzTs2pHhmioiiKPF8V+fJiKSJ17b33qQ4P3iX2zmtGbVP/KcplWRlCAA0KlAJE3Gw2zBxjDCH0oU+1T7XbY9S1rUKzrrQ1jIhMzGwogcxmUHMi4r2zA7uv7BiF0AHb9aYSaxHRmgQRibX8H2Kyw0utdbff3HSx4XMqF0xuu90qBZTEWVWKiAAABxcKQKNWSjlf7/yHEJLtsizX5boWQdCWDWOaXowhRENkEFGjiOv3NK+Uu64t2OVofQyVWKxr9DWIUNOACHpvug6ZnXP9DUat2OXb9/m7jzJfqGwCkwlMZjSdwWRWZVM+nfffzqOvY4y3NMdl/unOvWx80iwWMJmpLMPZqZ7OIJtWH7JqPqdHj9sfP/sYb7OtVH73/u8HD/H1m/LZkRofV+Pj7dFYvXy1ef6iOj6xT552xepAc4z+65mZn0rTEIAzllMm6YdZZjvsSX+b5yGqEMPmnP9+1iygFDNrrQEg5ZOiUuEwKWeznmKRWd8xk3Pe2LQpYq0Z9qQ/zKjt4vbyrFx9MdYDJOWUq9ZEZIzVWocbo143931Qlb5clc45RE3Mw2ISIooIErZtGw/NHPvwa8PfL7ZejFJgjB22UhtzZSEeZlR7XwKtK+1EiHm4FbvrYNikwx3mH0W3xlJZQCnpAAAAAElFTkSuQmCC&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;SRM Recovery Plan steps after custom step has been added&quot; title=&quot;SRM Recovery Plan steps after custom step has been added&quot; src=&quot;/static/5e11622cbdc00c1eec6d03524d1deff6/d9f49/4.png&quot; srcSet=&quot;/static/5e11622cbdc00c1eec6d03524d1deff6/d9f49/4.png 400w&quot; sizes=&quot;(max-width: 400px) 100vw, 400px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;SRM Recovery Plan steps after custom step has been added&lt;/figcaption&gt;
  &lt;/figure&gt;&lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:632px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:55.69620253164557%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAALCAYAAAB/Ca1DAAAACXBIWXMAAA7DAAAOwwHHb6hkAAABTUlEQVQoz41S2U7EMAzs//8bjzyABEiwQkVsE8e5j3ZQvNvSLlqJSqM0sTMexzMwM6ZpEjjnkXNGSgkxxrvocSINTST5+9hAhnEazyCtQJrAxoCuibXWuyg5Y5oUjDGH8yGmhG81wbKV4Iqu3DknMIaQSwGwYF5mLMuC0jLYGon3/YohRQc6v8IYhlZKiLrCDq21rP2sK57nGa01WWuryCWjlir7FYN1Hl9nDWt5IxCYS/X+Lmv19VL/TzVCk4K1FvMuNhjn8XwaEbwTok68tt3VLMBBwUoYS/gl3CsMbPH++AQfvLTWCXsSs0Wt7aBsT1hbQUpxe4qNsHmL/PYIvg5gG8ZN5b+k2L4DYfQKND6A2Yk6lglfJt7uki3INcE6RgjhpuXgMY4fouzWNt1Xe0vs0eaGUopM+WAbGxJePpV4jchcQf8ydx9aa8ezH8sFWDP29rc1AAAAAElFTkSuQmCC&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;SRM Recovery Plan test with successful mark against the custom step&quot; title=&quot;SRM Recovery Plan test with successful mark against the custom step&quot; src=&quot;/static/b66243824e41f06528ddac5a57a93eb2/afa26/5.png&quot; srcSet=&quot;/static/b66243824e41f06528ddac5a57a93eb2/afa26/5.png 632w&quot; sizes=&quot;(max-width: 632px) 100vw, 632px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;SRM Recovery Plan test with successful mark against the custom step&lt;/figcaption&gt;
  &lt;/figure&gt;&lt;/p&gt;&lt;h2 id=&quot;check-appliance-log-files-and-vro-workflow-log&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#check-appliance-log-files-and-vro-workflow-log&quot; aria-label=&quot;check appliance log files and vro workflow log permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Check Appliance Log Files and vRO Workflow Log&lt;/h2&gt;&lt;p&gt;Check the Workflow within vRO, you should see a new run. Check the logs to see details from our recovery plan. \
You should see an output similar to the below. &lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;text&quot;&gt;&lt;pre class=&quot;language-text&quot;&gt;&lt;code class=&quot;language-text&quot;&gt;[2020-12-02 12:15:29.139] [D] Recovery Plan Name: recovery-plan-01
[2020-12-02 12:15:29.143] [D] Recovery Plan Mode: test
[2020-12-02 12:15:29.153] [D] Recovery Plan VC: drvcenter.domain.com&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;In the script we created earlier, we output all of the logs from our function to a file &lt;code class=&quot;language-text&quot;&gt;/tmp/SRM-VRO-Output.log&lt;/code&gt;.
This will show details of the API request, and some additional logs. &lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;text&quot;&gt;&lt;pre class=&quot;language-text&quot;&gt;&lt;code class=&quot;language-text&quot;&gt;2020-12-02_12-22-24: Recovery Plan recovery-plan-01 ran in test mode
vRO REST Call: https://vroserver01.domain.com/vco/api/workflows/67748eec-e51c-8dd9-ac57-a7ca789a706c/executions
  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current
                                 Dload  Upload   Total   Spent    Left  Speed
100  1360    0   627  100   733   8360   9773 --:--:-- --:--:-- --:--:-- 18133
{&amp;quot;id&amp;quot;:&amp;quot;2a7edc1a-78b3-4710-b25d-593d1ffe1b29&amp;quot;,&amp;quot;state&amp;quot;:&amp;quot;running&amp;quot;,&amp;quot;start-date&amp;quot;:&amp;quot;2020-12-02T12:23:55Z&amp;quot;,&amp;quot;started-by&amp;quot;:&amp;quot;administrator@vsphere.local&amp;quot;,&amp;quot;name&amp;quot;:&amp;quot;SRM Recovery Plan Details&amp;quot;,&amp;quot;current-item-for-display&amp;quot;:&amp;quot;__item-undefined__&amp;quot;,&amp;quot;input-parameters&amp;quot;:[{&amp;quot;value&amp;quot;:{&amp;quot;string&amp;quot;:{&amp;quot;value&amp;quot;:&amp;quot;recovery-plan-01&amp;quot;}},&amp;quot;type&amp;quot;:&amp;quot;string&amp;quot;,&amp;quot;name&amp;quot;:&amp;quot;recoveryPlanName&amp;quot;,&amp;quot;scope&amp;quot;:&amp;quot;local&amp;quot;},{&amp;quot;value&amp;quot;:{&amp;quot;string&amp;quot;:{&amp;quot;value&amp;quot;:&amp;quot;test&amp;quot;}},&amp;quot;type&amp;quot;:&amp;quot;string&amp;quot;,&amp;quot;name&amp;quot;:&amp;quot;recoveryPlanMode&amp;quot;,&amp;quot;scope&amp;quot;:&amp;quot;local&amp;quot;},{&amp;quot;value&amp;quot;:{&amp;quot;string&amp;quot;:{&amp;quot;value&amp;quot;:&amp;quot;drvcenter.domain.com&amp;quot;}},&amp;quot;type&amp;quot;:&amp;quot;string&amp;quot;,&amp;quot;name&amp;quot;:&amp;quot;recoveryVmwareVcHost&amp;quot;,&amp;quot;scope&amp;quot;:&amp;quot;local&amp;quot;}],&amp;quot;output-parameters&amp;quot;:[],&amp;quot;workflow-attributes&amp;quot;:[]}
------------------&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&quot;closing&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#closing&quot; aria-label=&quot;closing permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Closing&lt;/h2&gt;&lt;p&gt;The script and workflow within this post are very simple use cases. In a real world scenario you could modify the vRO Workflow to retrieve additional details about the Recovery Plan - as we have been provided with the Recovery Plan name - for instance, we could retrieve a list of all Virtual Machines protected by the plan and tag them on the recovery site with some data. &lt;/p&gt;&lt;p&gt;The script can also be used on a per-vm basis, this allows much more fine grained controls and it also provides us access to additional environment variables.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;VMware_VM_Uuid&lt;/code&gt;: UUID used by vCenter Server to uniquely identify this virtual machine.&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;VMware_VM_Name&lt;/code&gt;: Name of this virtual machine, as set at the protected site.&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;VMware_VM_Ref&lt;/code&gt;: Managed object ID of the virtual machine.&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;VMware_VM_GuestName&lt;/code&gt;: Name of the guest OS as defined by the VIM API.&lt;/li&gt;&lt;/ul&gt;&lt;h2 id=&quot;additional-resources&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#additional-resources&quot; aria-label=&quot;additional resources permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Additional Resources&lt;/h2&gt;&lt;p&gt;&lt;a href=&quot;https://docs.vmware.com/en/Site-Recovery-Manager/8.2/srm-admin-8-2.pdf&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;SRM Administration Guide PDF (docs.vmware.com)&lt;/a&gt; \
&lt;a href=&quot;https://docs.vmware.com/en/Site-Recovery-Manager/8.2/com.vmware.srm.admin.doc/GUID-75F89A6E-87F1-45D5-B2F1-15DE991F7A7F.html&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;SRM Creating Custom Recovery Steps (docs.vmware.com)&lt;/a&gt; \
&lt;a href=&quot;https://kskilling.com/2019/03/31/adding-srm-protection-to-vms-via-vra-part-1/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;Adding SRM Protection to VMs via vRA (kskilling.com)&lt;/a&gt;&lt;/p&gt;</content:encoded><tags>automation,vro,vrealize,vra</tags><featuredImage>https://samperrin.com/static/a0511c8075ba8349a213f67f0f3e2347/hero_5.jpg</featuredImage></item><item><title><![CDATA[How to use the vCenter Managed Object Browser]]></title><description><![CDATA[The vCenter Managed Object Browser is invaluable when trying to explore vSphere objects. This blog covers how it can be utilised with tools like vRO and PowerCLI]]></description><link>https://samperrin.com/posts/how-to-use-the-vcenter-managed-object-browser/</link><guid isPermaLink="false">https://samperrin.com/posts/how-to-use-the-vcenter-managed-object-browser/</guid><category><![CDATA[automation]]></category><category><![CDATA[vmware]]></category><category><![CDATA[vro]]></category><category><![CDATA[vrealize]]></category><pubDate>Mon, 16 Nov 2020 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;The Managed Object Browser or MOB is a tool that is bundled with vCenter and ESXi, and it can be used to visually explore the structure of various vSphere related objects, such as Virtual Machines, Datastores and Clusters. This becomes invaluable when developing automation or reporting on infrastructure. &lt;/p&gt;&lt;p&gt;Each object within the MOB contains an array of data, from common information such as the objects name, configured CPU &amp;amp; Memory or its overall status, to less explored data such hardware device keys, VMX file paths and snapshot tree structure. &lt;/p&gt;&lt;p&gt;Not only can the MOB be used to explore this information, but it can also be used to invoke various methods against the various objects. For example, when viewing a Virtual Machine object you can invoke &lt;code class=&quot;language-text&quot;&gt;ShutdownGuest&lt;/code&gt; and &lt;code class=&quot;language-text&quot;&gt;CreateSnapshot&lt;/code&gt; tasks. &lt;/p&gt;&lt;h3 id=&quot;mob-key-components&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#mob-key-components&quot; aria-label=&quot;mob key components permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;MOB Key Components&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Property Path&lt;/strong&gt;: Used to identify where you are within an object. The path can be “walked” to reach specific information.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Properties/Attributes&lt;/strong&gt;: The information on part of the path, referencing this property with something like PowerCLI or vRO will return the value of the property, for example &lt;code class=&quot;language-text&quot;&gt;vm.name&lt;/code&gt; would return the &lt;code class=&quot;language-text&quot;&gt;name&lt;/code&gt; of the virtual machine object you are working with. &lt;/li&gt;&lt;li&gt;&lt;strong&gt;Property Types&lt;/strong&gt;: The property type shows what form the data is, such as &lt;code class=&quot;language-text&quot;&gt;string&lt;/code&gt;, &lt;code class=&quot;language-text&quot;&gt;number&lt;/code&gt;, or another &lt;code class=&quot;language-text&quot;&gt;object&lt;/code&gt;. When the value of a property is another object, the path can continue to be walked.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Parent Object Managed ID&lt;/strong&gt;: This is often known as the moRef value, it is a unique ID generated by vCenter for a given object. This will be shown at the top of the page for the object you are in. &lt;/li&gt;&lt;li&gt;&lt;strong&gt;Browser Address Bar&lt;/strong&gt;: The address bar gives you a direct link to wherever you are in the MOB, &lt;code class=&quot;language-text&quot;&gt;https://&amp;lt;vcenter-server-IP-or-FQDN&amp;gt;/mob/?moid=vm-725&amp;amp;doPath=guest&lt;/code&gt; - including the moRef of the vCenter object (e.g. &lt;code class=&quot;language-text&quot;&gt;vm-725&lt;/code&gt;)&lt;/li&gt;&lt;/ul&gt;&lt;h3 id=&quot;mob-guided-tour&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#mob-guided-tour&quot; aria-label=&quot;mob guided tour permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;MOB Guided Tour&lt;/h3&gt;&lt;p&gt;To connect to your vCenter MOB, navigate to &lt;em&gt;&lt;code class=&quot;language-text&quot;&gt;https://&amp;lt;vcenter-server-IP-or-FQDN&amp;gt;/mob&lt;/code&gt;&lt;/em&gt; and login with valid credentials.&lt;/p&gt;&lt;p&gt;At the top of your page you should see a table, the first column is the property/attribute name, followed by its type, and then the value. This structure will be used throughout the MOB. &lt;/p&gt;&lt;ol&gt;&lt;li&gt;&lt;strong&gt;Click on the link for &lt;code class=&quot;language-text&quot;&gt;content&lt;/code&gt;.&lt;/strong&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1857px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:23.317178244480345%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAFCAIAAADKYVtkAAAACXBIWXMAAA7DAAAOwwHHb6hkAAAAcUlEQVQY05XC2w6CMAwA0P7/n1nMyKLt9ghuFDtDCfES8QFM/ACVkwOdWpPPTepFrS+jqI3X5+O13ufl++k2g6t9tau8PxAHDpFDJI7E4WcOEVJO7ZGkPYlIKfr5JwVERFfj3hETbwQ2WO70MkzLutkb3wkOWmbJ4esAAAAASUVORK5CYII=&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;The top level location within the MOB, which provides links to vSphere content&quot; title=&quot;The top level location within the MOB, which provides links to vSphere content&quot; src=&quot;/static/3953a420508e932b60f2eee02b0a35a6/530b1/1.png&quot; srcSet=&quot;/static/3953a420508e932b60f2eee02b0a35a6/530b1/1.png 1857w&quot; sizes=&quot;(max-width: 1857px) 100vw, 1857px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;The top level location within the MOB, which provides links to vSphere content&lt;/figcaption&gt;
  &lt;/figure&gt;&lt;/p&gt;&lt;p&gt;This second page shows us various Service Managers that vCenter provides, such as &lt;code class=&quot;language-text&quot;&gt;FileManager&lt;/code&gt; and &lt;code class=&quot;language-text&quot;&gt;OvfManager&lt;/code&gt;, these provide various actions and functions, but for now we are only interested in consuming existing information. &lt;/p&gt;&lt;ol start=&quot;2&quot;&gt;&lt;li&gt;&lt;strong&gt;Click on the link against the property &lt;code class=&quot;language-text&quot;&gt;rootFolder&lt;/code&gt;, the value should be &lt;code class=&quot;language-text&quot;&gt;group-d1 (Datacenters)&lt;/code&gt;&lt;/strong&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1840px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:56.30434782608695%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAALCAIAAADwazoUAAAACXBIWXMAAA7DAAAOwwHHb6hkAAABHklEQVQoz4WQW26DMBQF2f/SWvWRBkoaNTbX9r2YAIljwC8eqrqBMJrfo5FO9v5xeHl9O3wdPw/HvCiPRZnnZXk6F9+nJ+bF6ef8mw3WSimMMdem4ZxXFWeMU91M47jjNGaTcwAQQtBac86FFBKJQZ3SvG3b+pTMGIOI4zhqraWUiIikFTXDMC3LMj8lG4ZBgLDW1nV9uVwqqAAU6S7GuOyRWWuJyDvfdZ2UioiQtMTGOb9fnqYJALzz7bVljAFUFSgGFEJc13WnHGIgIuf8wxgAQFQKa6zblNK8R+acU0o55/q+Z4xLIYRArNsY0/Ps/zjGqLX2zltrhRBSKfplOi/jw67btjOeUzIPE2MMIXRdd7/f+tt9GN26rLtv/wF39m2qyTqX3QAAAABJRU5ErkJggg==&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Service contents and access to the rootFolder (Datacenters)&quot; title=&quot;Service contents and access to the rootFolder (Datacenters)&quot; src=&quot;/static/d50a28b00ad9856082ffe9561fd83e8d/ec056/2.png&quot; srcSet=&quot;/static/d50a28b00ad9856082ffe9561fd83e8d/ec056/2.png 1840w&quot; sizes=&quot;(max-width: 1840px) 100vw, 1840px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Service contents and access to the rootFolder (Datacenters)&lt;/figcaption&gt;
  &lt;/figure&gt;&lt;/p&gt;&lt;p&gt;At the top of this next page you will see a &lt;code class=&quot;language-text&quot;&gt;childEntity&lt;/code&gt; property, you should see some familiar values here - your Datacenters, their names will be shown within brackets ( ). &lt;/p&gt;&lt;ol start=&quot;3&quot;&gt;&lt;li&gt;&lt;strong&gt;Click on one of your &lt;code class=&quot;language-text&quot;&gt;Datacenters&lt;/code&gt;.&lt;/strong&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1836px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:47.167755991285404%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAJCAIAAAC9o5sfAAAACXBIWXMAAA7DAAAOwwHHb6hkAAAA4ElEQVQoz43P3W6DMAwF4Lz/w62MqWg1aC1lEELTgJPgAvlhUntdZZ/OpS0fs284V+cGqvrn0tatuHLJ5dSnwm+jGBT7zLI8zwHgeCy+Dtnp43AqCihLACjfA4C6vrBlWbTWzrmZaBRC/7a7c/s/xBjZ+BRCUErd5B0taTMba4loS2Hbtnnv4xNqC9W1bvqOC0RMX9ZGI2KMcV3XaUKih3vyKc45hhqllIjYdR3nnIhC8K/9dG1jjJ1n7z096K7GlksxKKUma0yMMbznvWevibjvIQZj56YV/aCkVNaY5M9/Ke4BeDmVJmQAAAAASUVORK5CYII=&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Top level Datacenter object&quot; title=&quot;Top level Datacenter object&quot; src=&quot;/static/9dff406401e4703e6008654981e2c2d0/78496/3.png&quot; srcSet=&quot;/static/9dff406401e4703e6008654981e2c2d0/78496/3.png 1836w&quot; sizes=&quot;(max-width: 1836px) 100vw, 1836px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Top level Datacenter object&lt;/figcaption&gt;
  &lt;/figure&gt;&lt;/p&gt;&lt;p&gt;Within the Datacenter object screen you will see a lot of familiar information, this is the real start of what you would see within vCenter. On this page you will see links to your Datastores and Networks. At the bottom you will also see &lt;code class=&quot;language-text&quot;&gt;vmFolder&lt;/code&gt;. &lt;/p&gt;&lt;p&gt;You might have noticed that Datastores start with &lt;code class=&quot;language-text&quot;&gt;datastore-&lt;/code&gt; and Networks start with &lt;code class=&quot;language-text&quot;&gt;network-&lt;/code&gt;. As you browse the MOB you will see that various vSphere related objects have a naming prefix to them. (&lt;code class=&quot;language-text&quot;&gt;vm-&lt;/code&gt; for VMs, &lt;code class=&quot;language-text&quot;&gt;host-&lt;/code&gt; for Hosts etc). &lt;/p&gt;&lt;ol start=&quot;4&quot;&gt;&lt;li&gt;&lt;strong&gt;Click the link next to &lt;code class=&quot;language-text&quot;&gt;vmFolder&lt;/code&gt;.&lt;/strong&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1835px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:54.11444141689373%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAALCAIAAADwazoUAAAACXBIWXMAAA7DAAAOwwHHb6hkAAABBklEQVQoz42RzZKCMBCE8/6P5p5Uflx3CxGFIcQEYmYCSQC30POiX3XVXKa7ZqpZlldF1fxkRV7AFcS55EKZuw2a/LqUtmyz+dpud3GS7qMoSQ5peojjJIrjde2j6Pt4ZAAgpbRE+ekkbtI57713n8GstYiIBpVSdSN5I4jo8XjM03uYMabv+2HoiehS1qf8Im6tMTgMwxLxP4vZez9N03NvKkFk5+p85QAcEdfN8zyztm27riOibpn6lRVCGMN7mHOOkBCRCMuKV1Br3Y3jOH34MxEZY6SSvLlJqRCN9378AKa1Xs7VGgC0wf7ZlXM+BP/+7KfzvpjrWvxmGjjanpDcq/FV/gDsJ3RiFZ3wEAAAAABJRU5ErkJggg==&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Top level VM folder object&quot; title=&quot;Top level VM folder object&quot; src=&quot;/static/e3b54edc965eb3860709597abffa78b7/2e51b/4.png&quot; srcSet=&quot;/static/e3b54edc965eb3860709597abffa78b7/2e51b/4.png 1835w&quot; sizes=&quot;(max-width: 1835px) 100vw, 1835px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Top level VM folder object&lt;/figcaption&gt;
  &lt;/figure&gt;&lt;/p&gt;&lt;p&gt;Inside the top level VM folder, which has the name &lt;code class=&quot;language-text&quot;&gt;vm&lt;/code&gt; (find the &lt;code class=&quot;language-text&quot;&gt;name&lt;/code&gt; property), you will find all child folders as well as any virtual machines that have not been organised in to a folder. This is the root, or top level, &lt;strong&gt;vm&lt;/strong&gt; folder - some applications such as &lt;code class=&quot;language-text&quot;&gt;govc&lt;/code&gt; rely on this when providing the path to an object, for example if you wanted to move a vm in to a folder: &lt;code class=&quot;language-text&quot;&gt;govc object.mv /dc1/vm/vm-foo-* /dc1/vm/folder-foo&lt;/code&gt;.  &lt;/p&gt;&lt;ol start=&quot;5&quot;&gt;&lt;li&gt;&lt;strong&gt;Find a virtual machine and click its link, if your VMs are organised into folders select one of those to find a VM object (remember to look for an object that starts &lt;code class=&quot;language-text&quot;&gt;vm-&lt;/code&gt;).&lt;/strong&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1836px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:47.875816993464056%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAKCAIAAAA7N+mxAAAACXBIWXMAAA7DAAAOwwHHb6hkAAAA30lEQVQoz5XOy07DMBCFYb//qwFSaS5kAQVywXbijJ06ievM2EaiQmLVlE//ZjSbw1qhPhrx2cpWDC1XxnqHad12Wnyc7IU9PD4ds+KYF4fnY/VSlWWVF+VuWV68vp1YP/TTZNSoeNc1h0zWzbKuzt2TY/FHSgmRmubLaH09d8UYmZ1nouC9t9ba+RwCXR+0BxEZaJ1SstYKKWUPcoARjDGGiMJNRMSI6Hc2vte87nrZA4xAIcSbQghsBEBE773W2jn3d9UuBgDLsiiluBBnay/e490YjKPfNmMM5wL/6Rvwtz1RN1LV1wAAAABJRU5ErkJggg==&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;VM folder object with child entities, such as folders and ungrouped virtual machines&quot; title=&quot;VM folder object with child entities, such as folders and ungrouped virtual machines&quot; src=&quot;/static/d99ad291307cf21364cfb2c4d840a4a7/78496/5.png&quot; srcSet=&quot;/static/d99ad291307cf21364cfb2c4d840a4a7/78496/5.png 1836w&quot; sizes=&quot;(max-width: 1836px) 100vw, 1836px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;VM folder object with child entities, such as folders and ungrouped virtual machines&lt;/figcaption&gt;
  &lt;/figure&gt;&lt;/p&gt;&lt;p&gt;Take some time to look through this object, take note of the values against the &lt;code class=&quot;language-text&quot;&gt;datastore&lt;/code&gt; and &lt;code class=&quot;language-text&quot;&gt;network&lt;/code&gt; properties. Now compare these to what you see within the vCenter UI, they should match. &lt;/p&gt;&lt;ol start=&quot;6&quot;&gt;&lt;li&gt;&lt;strong&gt;Next, click the link next to the &lt;code class=&quot;language-text&quot;&gt;guest&lt;/code&gt; property.&lt;/strong&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1833px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:56.082924168030544%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAALCAIAAADwazoUAAAACXBIWXMAAA7DAAAOwwHHb6hkAAABB0lEQVQoz43R246CMBAGYN7/8VxwDa4KIoVSegB6moGWjZjs3Ypf5qZN/k5mmnzn159bdb7cL7dHUTXlg5Y1pXyk/fCmWjZQJpOvwyHLsuvmdDql6THNjmmant/K87woigQBhmFc19V7T2nbUmasA/DrnhhjIqVkjOGMk57quhZCWmudcwCAexLYhBC2I9RNl1+qB2GUdoi40/n1xt9V3/PyXvW9sNaFEOL/QgjJPM+IGDYxRqlU07Ra67jnGeacCyGMMeM4dazrymr2GGKc9zxn1lorpZZlUVISUrekNea5METcDxtrlJLee8Y6QghjvXXOe/9R52mauBAAwDl/fZUHXJblk/Av7/V1Y26nHosAAAAASUVORK5CYII=&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Virtual Machine object page with link to guest page highlighted&quot; title=&quot;Virtual Machine object page with link to guest page highlighted&quot; src=&quot;/static/ab822ec8ac2de935fe1e6729b74942b1/f533c/6.png&quot; srcSet=&quot;/static/ab822ec8ac2de935fe1e6729b74942b1/f533c/6.png 1833w&quot; sizes=&quot;(max-width: 1833px) 100vw, 1833px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Virtual Machine object page with link to guest page highlighted&lt;/figcaption&gt;
  &lt;/figure&gt;&lt;/p&gt;&lt;p&gt;We are now looking at the &lt;code class=&quot;language-text&quot;&gt;guest&lt;/code&gt; information for our Virtual Machine. Take a look at the &lt;code class=&quot;language-text&quot;&gt;guestState&lt;/code&gt; and &lt;code class=&quot;language-text&quot;&gt;hostname&lt;/code&gt; properties. Once again, these should match what you see within vCenter - is the VM powered on or off? What is the hostname shown on the summary tab? &lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1854px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:40.183387270765905%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAICAIAAAB2/0i6AAAACXBIWXMAAA7DAAAOwwHHb6hkAAAAp0lEQVQY042OQQ6DIBBFuf/V3IFVmsZ0ZQPKwGCEBhkmTXuB8vK2P/+JWS83vejH87X5cLz9kQFTj2ZHodQ4DINSo9Z3KZWUaprmLudZMHNKKYRQSvEAGJG7EddVjTHOudYaIjpraym1D5FSstaGEJj5PM9dqoKxtlav6/845xwjIn5rrbXgXGOmPgQRxR9EBAAOIOfcm01ExhjvfaUaj7iu67Ztnc8fbEzHALY9cvYAAAAASUVORK5CYII=&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Virtual Machine guest information&quot; title=&quot;Virtual Machine guest information&quot; src=&quot;/static/8e11ed7c011cbf621f7837775a2510bc/b7708/7.png&quot; srcSet=&quot;/static/8e11ed7c011cbf621f7837775a2510bc/b7708/7.png 1854w&quot; sizes=&quot;(max-width: 1854px) 100vw, 1854px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Virtual Machine guest information&lt;/figcaption&gt;
  &lt;/figure&gt;&lt;/p&gt;&lt;ol start=&quot;7&quot;&gt;&lt;li&gt;&lt;strong&gt;Go back a page to the top level of the virtual machine object you selected, scroll down and select &lt;code class=&quot;language-text&quot;&gt;summary&lt;/code&gt;&lt;/strong&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1840px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:50.05434782608695%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAKCAIAAAA7N+mxAAAACXBIWXMAAA7DAAAOwwHHb6hkAAAA30lEQVQoz43QTXOEIAwGYP7/L+xML+u4y/IRAQUMJKAd7aWXuj7XJPMmESklHwIzp5ystRactpMPc0qZiNolwcyt8Xba911p+PoeRmmU0kS0/2/btmP4b5P3fhgG51xrbbvUexdEVEohImbuvcclhjBXqr/la8I7DwCllGVZpJTvt650XNE+YWaBiPM8996C90orpU2MCRH5BpFznqaJiADscxztsUU9v3gjOcYIAIirMUZKaWFaYmKmW8mICADrisaYx/CQ4wvz2m44hlOKIYTee63VWuueL84rn7WPyT+jzUXarlEeTwAAAABJRU5ErkJggg==&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Virtual Machine object page with link to summmary page highlighted&quot; title=&quot;Virtual Machine object page with link to summmary page highlighted&quot; src=&quot;/static/60fc2327df205b01510caeeac77942d6/ec056/8.png&quot; srcSet=&quot;/static/60fc2327df205b01510caeeac77942d6/ec056/8.png 1840w&quot; sizes=&quot;(max-width: 1840px) 100vw, 1840px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Virtual Machine object page with link to summmary page highlighted&lt;/figcaption&gt;
  &lt;/figure&gt;&lt;/p&gt;&lt;p&gt;Take note of the &lt;code class=&quot;language-text&quot;&gt;Property Path&lt;/code&gt; at the top of the page, this currently shows &lt;code class=&quot;language-text&quot;&gt;summary&lt;/code&gt;.&lt;/p&gt;&lt;ol start=&quot;8&quot;&gt;&lt;li&gt;&lt;strong&gt;Press the &lt;code class=&quot;language-text&quot;&gt;config&lt;/code&gt; link&lt;/strong&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1852px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:19.27645788336933%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAECAIAAAABPYjBAAAACXBIWXMAAA7DAAAOwwHHb6hkAAAAY0lEQVQI143CWwqAIBAAQO9/sYrKgrIHfghlaAW10Ypu/nQFh2HtrPJBqcVs5w1Ij/sSn9fL6qbNKl5z3hel6HohhsTjODFEhPuSUppVe+8pWQiBAYC1VuvV7AeiizF+aYjoB7zH3UE1fTolAAAAAElFTkSuQmCC&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Virtual Machine summary page with link to config page highlighted&quot; title=&quot;Virtual Machine summary page with link to config page highlighted&quot; src=&quot;/static/dea92dabfe1c7c64e83fe62d68afc5c4/b0464/9.png&quot; srcSet=&quot;/static/dea92dabfe1c7c64e83fe62d68afc5c4/b0464/9.png 1852w&quot; sizes=&quot;(max-width: 1852px) 100vw, 1852px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Virtual Machine summary page with link to config page highlighted&lt;/figcaption&gt;
  &lt;/figure&gt;&lt;/p&gt;&lt;p&gt;Check the &lt;code class=&quot;language-text&quot;&gt;Property Path&lt;/code&gt; again, you should now see that we are in &lt;code class=&quot;language-text&quot;&gt;summary.config&lt;/code&gt;. The path shows us where we are within an object, so at the moment we are within &lt;code class=&quot;language-text&quot;&gt;vm.summary.confg&lt;/code&gt;.&lt;/p&gt;&lt;p&gt;Take a look at some of the properties listed here, such as the &lt;code class=&quot;language-text&quot;&gt;guestFullName&lt;/code&gt;, check it against vCenter. The full path to this property would be &lt;code class=&quot;language-text&quot;&gt;vm.summary.config.guestFullName&lt;/code&gt;&lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1852px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:36.285097192224626%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAHCAIAAACHqfpvAAAACXBIWXMAAA7DAAAOwwHHb6hkAAAAl0lEQVQY05XNYQrCMAwF4N7/Ph5B/ClOiE63pXPgIGsJa2HpuooydwDrxyP/3osqzrA/wu5wKkqssMNH3z0pJ7rr1a0sLwBVXV8B7gC6blBrzKO898wcYxzalhED8+udSxHRYIyIENEkqxBCzKOcc8ycUnLjGGNM/1DWWrN+noy1y7KklLabVRaZvPfzPBtrxi8R2SZ++gBAl4yFlwwT0wAAAABJRU5ErkJggg==&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Virtual Machine summary.config page with highlighted properties &amp;quot;guestFullName&amp;quot; and &amp;quot;guestId&amp;quot;&quot; title=&quot;Virtual Machine summary.config page with highlighted properties &amp;quot;guestFullName&amp;quot; and &amp;quot;guestId&amp;quot;&quot; src=&quot;/static/2dbdab0746e4f6f86318322b577616b5/b0464/10.png&quot; srcSet=&quot;/static/2dbdab0746e4f6f86318322b577616b5/b0464/10.png 1852w&quot; sizes=&quot;(max-width: 1852px) 100vw, 1852px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Virtual Machine summary.config page with highlighted properties &amp;quot;guestFullName&amp;quot; and &amp;quot;guestId&amp;quot;&lt;/figcaption&gt;
  &lt;/figure&gt;&lt;/p&gt;&lt;h3 id=&quot;example-with-powercli&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#example-with-powercli&quot; aria-label=&quot;example with powercli permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Example with PowerCLI&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Install PowerCLI: &lt;code class=&quot;language-text&quot;&gt;Install-Module -Name VMware.PowerCLI&lt;/code&gt;.&lt;/li&gt;&lt;li&gt;Connect to vCenter: &lt;code class=&quot;language-text&quot;&gt;Connect-VIServer -Server &amp;quot;vcenter.domain.com&amp;quot; -User &amp;quot;username&amp;quot; -Password &amp;quot;password&amp;quot;&lt;/code&gt;.&lt;/li&gt;&lt;li&gt;Get the VM object we looked at earlier in the MOB: &lt;code class=&quot;language-text&quot;&gt;$vm = Get-VM -Name &amp;quot;vm-name&amp;quot;&lt;/code&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;To access the data we would normally see on an object within the MOB, via PowerCLI, we need to use the &lt;code class=&quot;language-text&quot;&gt;ExtensionData&lt;/code&gt; property.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Output all ExtensionData, cross reference what you see as an output with what you see in the MOB: &lt;code class=&quot;language-text&quot;&gt;$vm.extensiondata&lt;/code&gt;.&lt;/li&gt;&lt;li&gt;Get the hostName of our VM object (step 6 above): &lt;code class=&quot;language-text&quot;&gt;$vm.extensiondata.guest.hostname&lt;/code&gt;.&lt;/li&gt;&lt;li&gt;Get the guestFullName of our VM object (step 8 above): &lt;code class=&quot;language-text&quot;&gt;$vm.extensiondata.summary.config.guestFullName&lt;/code&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Ignoring the ExtensionData property, we can see in the two simple examples above that the path we have gone down to get our data through PowerCLI matches the same path we went down to get the data from MOB.&lt;/p&gt;&lt;h3 id=&quot;example-with-vro&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#example-with-vro&quot; aria-label=&quot;example with vro permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Example with vRO&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;Create a new workflow, name it &lt;em&gt;VM Details&lt;/em&gt;.&lt;/li&gt;&lt;li&gt;Create a new Input call &lt;code class=&quot;language-text&quot;&gt;vm&lt;/code&gt; with the type &lt;code class=&quot;language-text&quot;&gt;VC:VirtualMachine&lt;/code&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:330px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:47.878787878787875%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAKCAIAAAA7N+mxAAAACXBIWXMAAA7DAAAOwwHHb6hkAAABfElEQVQoz52MW2/aQBSE9///hKqq+tRGitSL8lLlQmtMiIMMIUnVgL03gw3xeneN1xivseOtEEqKWuWln+ZhzpnRAIwJRBgijDEJwyiKFpTOPB8iTNA+ggghvPc+RDsDd32EMRiPx9YPy7a6YRghD04nvkzTgXN9cXruXDlBEPS6tt3tuu4Q+vDStvv9fues871jYYSBEIIxFsdxlmV1XTdNXZbl/sNYIoRInhFCcM7/nFwAY0zbtua/AGEY0WBO6ZzQWSLTl63DxfYVgExXXKYsfmTxMpOy0rrabpVSRVE0lda6Kja6fgWg9FbqJyWClJNyMMqXc6kWrjv0ITYCxo/JhTVpmqfWmH8FUs4pwZLzPFO5lOuVXGdSiiSaB6lIynVeqGyTq02uijz7S+Dy3jvp3fZ+kjFNbggbEXZD+QjH35z7M3c68JdXk/DaWzjTaIh36aHA57vwyGtPZu0Xal70CbcfH6oPv/Rbd/VmIN/f5u9G6thvvgbmsPYbmOEgODPwuKgAAAAASUVORK5CYII=&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Workflow Inputs tab, showing vm as an input of type VC:VirtualMachne&quot; title=&quot;Workflow Inputs tab, showing vm as an input of type VC:VirtualMachne&quot; src=&quot;/static/12b5a16e6e31fc41aa55e933125c5e61/748ba/13.png&quot; srcSet=&quot;/static/12b5a16e6e31fc41aa55e933125c5e61/748ba/13.png 330w&quot; sizes=&quot;(max-width: 330px) 100vw, 330px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Workflow Inputs tab, showing vm as an input of type VC:VirtualMachne&lt;/figcaption&gt;
  &lt;/figure&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Drag a Scripting object on to the canvas, between the Start and End, rename it if necessary.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:402px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:28.35820895522388%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAGCAYAAADDl76dAAAACXBIWXMAAA7DAAAOwwHHb6hkAAABAklEQVQY03WRz0rDQBDG9zF8IV/Dow/gUfHgC4jvoCAFI4IXPXjyqKIgVIpNNdRDezC0hGw0uzM/ySZpE6F72Pnzzcx+862hc1QVtLbB/4+hDcYGHExeWu6+7pnl8xpAO0Xw8KJMPnUVN0i4pzriprgi93Y11Fwnt+w/H3KZXIS63DpsIWSZxzll70g5jyQ0WCsUhbBYOlwJB9kuWx+GKD0LuFOHGaYjTt6OGS5eQ9KLIKphWPXiIPI8PklgJVLnSudD7SA9ZSfZZlLEIRYVTE8H1tpZWzKOU5Jpxmy+5D3+5ufX9Vbua1hvYSo21eTuh7R6eL9m1rJrMW36vPpgWw3/AALDy1nb9VllAAAAAElFTkSuQmCC&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Workflow canvas with scripting object between Start and End items&quot; title=&quot;Workflow canvas with scripting object between Start and End items&quot; src=&quot;/static/de6feebb8789651af0d6a88321175134/752e8/14.png&quot; srcSet=&quot;/static/de6feebb8789651af0d6a88321175134/752e8/14.png 402w&quot; sizes=&quot;(max-width: 402px) 100vw, 402px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Workflow canvas with scripting object between Start and End items&lt;/figcaption&gt;
  &lt;/figure&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Map the Input to the scripting object&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:480px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:23.541666666666664%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAFCAYAAABFA8wzAAAACXBIWXMAAA7DAAAOwwHHb6hkAAAA5klEQVQY012Q62qEMBCFff+nU/BPdE3b3UhuStV4iUY9ZYaFlgY+kjlzCDMnM8agVS2stbDWwWiDuqphjYV3Hh/yk+vXS6HzHSpRQ2uDGCO2GPn+SxbCgmVZsG0b1nVlhmHgOm4RIcyYpglhCqyNw4B5nnFdF67zxPmPzPlvKKXYTCYS6T6O45eUWEvvHnlomn3f+Z0SkXAcCVnTPCBEha/nE13XwXsP5xyEECjLEkVRIM9zKNWi73vuk09KiUZKGGuhtebISM8A4L5vhtd4M44jm+gDypnWpkM98tLkFFUIgaGoSP8BUUZ91fjBgIcAAAAASUVORK5CYII=&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Scripting object In tab showing an input mapping to the workflow Input &amp;quot;vm&amp;quot;&quot; title=&quot;Scripting object In tab showing an input mapping to the workflow Input &amp;quot;vm&amp;quot;&quot; src=&quot;/static/05c845ce92c27a2329015919d0627de4/9aebd/15.png&quot; srcSet=&quot;/static/05c845ce92c27a2329015919d0627de4/9aebd/15.png 480w&quot; sizes=&quot;(max-width: 480px) 100vw, 480px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Scripting object In tab showing an input mapping to the workflow Input &amp;quot;vm&amp;quot;&lt;/figcaption&gt;
  &lt;/figure&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Update the code within the scripting object&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:689px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:16.110304789550074%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAADCAYAAACTWi8uAAAACXBIWXMAAA7DAAAOwwHHb6hkAAAAvElEQVQI123Fy0rDQABA0fz/d4gLu1IEW3AhGKU0VFCwYNPS9EFm2nk0MwlqOjNeETcuvHC42Xy5QR0UQgjqWrA/KLxvkUKitcbaI65xfKVEjIGUIin+I0VCOJFN3gSVkDTG4HxL3/eEU08MgZ9821E8PTMrF9SVZlluKas1s/mCcrVGaotUBqEMTfdOdjUuGOT3DB9euLwrOB8+cnaTc3E74Xr8yiifstkJjGtx7gN77NCNx/rf/9V9Br4B0GPeWICJ7JAAAAAASUVORK5CYII=&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Scripting object script&amp;quot;&quot; title=&quot;Scripting object script&amp;quot;&quot; src=&quot;/static/b54820813efa1e192aaa602d3ce17f61/a585f/16.png&quot; srcSet=&quot;/static/b54820813efa1e192aaa602d3ce17f61/a585f/16.png 689w&quot; sizes=&quot;(max-width: 689px) 100vw, 689px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Scripting object script&amp;quot;&lt;/figcaption&gt;
  &lt;/figure&gt;&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;javascript&quot;&gt;&lt;pre class=&quot;language-javascript&quot;&gt;&lt;code class=&quot;language-javascript&quot;&gt;System&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;log&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;vm&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;guest&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;hostName&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
System&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;log&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;vm&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;summary&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;config&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;guestFullName&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;Run the workflow, the output should show the same information as vCenter&lt;/li&gt;&lt;/ul&gt;</content:encoded><tags>automation,vmware,vro,vrealize</tags><featuredImage>https://samperrin.com/static/a0511c8075ba8349a213f67f0f3e2347/hero_5.jpg</featuredImage></item><item><title><![CDATA[VMware Automation/Orchestration Resources]]></title><description><![CDATA[A collection of development/automation resources that relate to VMware Automation/Orchestration]]></description><link>https://samperrin.com/posts/vmware-automation-orchestration-resources/</link><guid isPermaLink="false">https://samperrin.com/posts/vmware-automation-orchestration-resources/</guid><category><![CDATA[automation]]></category><category><![CDATA[development]]></category><category><![CDATA[vmware]]></category><category><![CDATA[vro]]></category><category><![CDATA[vra]]></category><category><![CDATA[vrealize]]></category><pubDate>Fri, 30 Oct 2020 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;A short collection of blogs, people and other resources that I have found helpful for VMware Automation/Orchestration related work. &lt;/p&gt;&lt;p&gt;If you feel something should be added to this list, please let me know! &lt;a href=&quot;https://twitter.com/sam_perrin&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;@sam_perrin&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;VMware API References/Resources&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;https://developer.vmware.com/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;Developer Documentation&lt;/a&gt; - Contains lots of additional links. &lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://developer.vmware.com/powercli&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;PowerCLI Reference&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://code.vmware.com/home&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;VMware {code}&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://blogs.vmware.com/code/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;VMware {code} Blog&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://code.vmware.com/apis/366/vsphere-automation&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;vSphere Automation API (6.7)&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://developer.vmware.com/docs/vsphere-automation/latest/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;vSphere Automation API (7.0)&lt;/a&gt;&lt;/li&gt;&lt;li&gt;vCenter MOB (Managed Object Browser) - web based app available to vCenter that allows you to examine objects that exist on the server, populated with runtime information and can help reveal the underlying structures of the object model.&lt;ul&gt;&lt;li&gt;To access the MOB&lt;/li&gt;&lt;li&gt;In a Web browser, navigate to the FQDN or IP address of your vCenter Server and add &lt;code class=&quot;language-text&quot;&gt;/mob&lt;/code&gt; to the end:  &lt;code class=&quot;language-text&quot;&gt;https://vcenter-fqdn-ip/mob&lt;/code&gt;&lt;/li&gt;&lt;li&gt;Enter the user account and password for the system when prompted.&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://vdc-repo.vmware.com/vmwb-repository/dcr-public/f1c3b41b-ead5-4d47-aca4-33298d5a4fcf/778a00f3-a9b6-42f4-8f22-7216733f5f03/doc/PG_Appx_Using_MOB.20.2.html&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;Using the MOB to Explore the Object Model &lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;vRealize Automation (vRA) / vRealize Orchestrator (vRO)&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;https://code.vmware.com/apis/894&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;vRA8 - Resource Type Scheme&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://docs.vmware.com/en/vRealize-Automation/8.2/Using-and-Managing-Cloud-Assembly/GUID-12F0BC64-6391-4E5F-AA48-C5959024F3EB.html&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;vRA8 - Cloud template expression syntax in vRealize Automation Cloud Assembly &lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://docs.vmware.com/en/vRealize-Automation/8.2/Using-and-Managing-Cloud-Assembly/GUID-74B39C1C-A1C5-451B-B936-8EC607E3C6A8.html&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;vRA8 - How to use expressions to make vRealize Automation Cloud Assembly blueprint code more versatile &lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://docs.vmware.com/en/vRealize-Automation/8.2/Using-and-Managing-Cloud-Assembly/GUID-6BA1DA96-5C20-44BF-9C81-F8132B9B4872.html&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;vRA8 - How user input can customize a cloud template in vRealize Automation &lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://docs.vmware.com/en/vRealize-Automation/8.2/Using-and-Managing-CodeStream/GUID-5094086E-AF44-456D-AB35-6853FB780F42.html&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;vRA8 - What variables and expressions can I use when binding pipeline tasks in vRealize Automation Code Stream&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://docs.vmware.com/en/vRealize-Automation/7.6/vrealize-automation-76-custom-properties.pdf&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;vRA7 - Custom Properties Reference&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://docs.vmware.com/en/vRealize-Automation/7.6/vrealize-automation-76-extensibility.pdf&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;vRA7 - Life Cycle Extensibility
&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://i1.wp.com/vbounty.com/wp-content/uploads/2018/10/vRA-States-Events.drawIo_v1.1.png&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;vRA7 - vRealize Automation EBS Lifecycle States &amp;amp; Events
&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://blogs.vmware.com/management/technical&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;VMware Cloud Management Blog&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.vroapi.com/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;vroapi.com&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;People (most links to Twitter where possible)&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;https://twitter.com/virtualhobbit&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;Mark Brookfield
&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://twitter.com/GaryFlynnAU&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;Gary Flynn&lt;/a&gt; &lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://twitter.com/skillk01&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;Katherine Skilling&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://twitter.com/PaulDavey_79&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;Paul Davey&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://twitter.com/thecloudxpert&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;Christopher Lewis
&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://twitter.com/knotacoder&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;Dana Gertsch&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://twitter.com/Virtual_Simon&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;Simon Conyard&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://twitter.com/sammcgeown&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;Sam McGeown&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://twitter.com/mpoore&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;Michael Poore&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.simplygeek.co.uk/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;Gavin Stephens&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</content:encoded><tags>automation,development,vmware,vro,vra,vrealize</tags><featuredImage>https://samperrin.com/static/a0511c8075ba8349a213f67f0f3e2347/hero_5.jpg</featuredImage></item><item><title><![CDATA[vRA8 Code Stream - Lightweight Cluster API Container]]></title><description><![CDATA[Build a lightweight container that includes Cluster API and various other tools. Can be utilised by vRA8 Code Stream]]></description><link>https://samperrin.com/posts/vra8-code-stream-lightweight-cluster-api-container/</link><guid isPermaLink="false">https://samperrin.com/posts/vra8-code-stream-lightweight-cluster-api-container/</guid><category><![CDATA[automation]]></category><category><![CDATA[development]]></category><category><![CDATA[vrealize]]></category><category><![CDATA[vra]]></category><category><![CDATA[vmware]]></category><pubDate>Mon, 26 Oct 2020 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;The below code can be used to create a Dockerfile that will create a container with the following toolset;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;curl&lt;/code&gt;&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;ovftool&lt;/code&gt;&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;govc&lt;/code&gt;&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;kubectl&lt;/code&gt;&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;clusterctl&lt;/code&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;This container can then be utilised by vRA8 Code Stream when using Docker endpoints. &lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://docs.vmware.com/en/vRealize-Automation/8.1/Using-and-Managing-CodeStream/GUID-04481662-27C6-4F53-8EA0-D7B2C3DC04C1.html&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://docs.vmware.com/en/vRealize-Automation/8.1/Using-and-Managing-CodeStream/GUID-04481662-27C6-4F53-8EA0-D7B2C3DC04C1.html&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Dockerfile&lt;/strong&gt;&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;dockerfile&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-dockerfile line-numbers&quot;&gt;&lt;code class=&quot;language-dockerfile&quot;&gt;&lt;span class=&quot;token instruction&quot;&gt;&lt;span class=&quot;token keyword&quot;&gt;FROM&lt;/span&gt; alpine:3.12&lt;/span&gt;

&lt;span class=&quot;token instruction&quot;&gt;&lt;span class=&quot;token keyword&quot;&gt;ARG&lt;/span&gt; GOVC_VERSION=0.22.1&lt;/span&gt;
&lt;span class=&quot;token instruction&quot;&gt;&lt;span class=&quot;token keyword&quot;&gt;ARG&lt;/span&gt; OVFTOOL_FILENAME=VMware-ovftool-4.4.0-16360108-lin.x86_64.bundle&lt;/span&gt;

&lt;span class=&quot;token comment&quot;&gt;# Install additional tools&lt;/span&gt;
&lt;span class=&quot;token instruction&quot;&gt;&lt;span class=&quot;token keyword&quot;&gt;RUN&lt;/span&gt; apk add --no-cache curl ca-certificates bash jq python3 &amp;amp;&amp;amp; &lt;span class=&quot;token operator&quot;&gt;\&lt;/span&gt;
    apk add --no-cache --virtual .build-apps wget unzip git coreutils libgcc&lt;/span&gt;

&lt;span class=&quot;token instruction&quot;&gt;&lt;span class=&quot;token keyword&quot;&gt;RUN&lt;/span&gt; wget -q -O /etc/apk/keys/sgerrand.rsa.pub https://alpine-pkgs.sgerrand.com/sgerrand.rsa.pub &amp;amp;&amp;amp; &lt;span class=&quot;token operator&quot;&gt;\&lt;/span&gt;
    wget https://github.com/sgerrand/alpine-pkg-glibc/releases/download/2.32-r0/glibc-2.32-r0.apk &amp;amp;&amp;amp; &lt;span class=&quot;token operator&quot;&gt;\&lt;/span&gt;
    wget https://github.com/sgerrand/alpine-pkg-glibc/releases/download/2.32-r0/glibc-bin-2.32-r0.apk &amp;amp;&amp;amp; &lt;span class=&quot;token operator&quot;&gt;\&lt;/span&gt;
    wget https://github.com/sgerrand/alpine-pkg-glibc/releases/download/2.32-r0/glibc-i18n-2.32-r0.apk&lt;/span&gt;
&lt;span class=&quot;token instruction&quot;&gt;&lt;span class=&quot;token keyword&quot;&gt;RUN&lt;/span&gt; apk add glibc-2.32-r0.apk glibc-bin-2.32-r0.apk glibc-i18n-2.32-r0.apk &amp;amp;&amp;amp; &lt;span class=&quot;token operator&quot;&gt;\&lt;/span&gt;
    /usr/glibc-compat/bin/localedef -i en_GB -f UTF-8 en_GB.UTF-8 &amp;amp;&amp;amp; &lt;span class=&quot;token operator&quot;&gt;\&lt;/span&gt;
    rm -f glibc-2.32-r0.apk glibc-bin-2.32-r0.apk glibc-i18n-2.32-r0.apk&lt;/span&gt;

&lt;span class=&quot;token comment&quot;&gt;# Install ovftool&lt;/span&gt;
&lt;span class=&quot;token instruction&quot;&gt;&lt;span class=&quot;token keyword&quot;&gt;RUN&lt;/span&gt; wget --quiet https://raw.githubusercontent.com/sam-perrin/codestream-cluster-api/master/files/&lt;span class=&quot;token variable&quot;&gt;$OVFTOOL_FILENAME&lt;/span&gt; &amp;amp;&amp;amp; &lt;span class=&quot;token operator&quot;&gt;\&lt;/span&gt;
    chmod +x /&lt;span class=&quot;token variable&quot;&gt;$OVFTOOL_FILENAME&lt;/span&gt; &amp;amp;&amp;amp; &lt;span class=&quot;token operator&quot;&gt;\&lt;/span&gt;
    /bin/sh /&lt;span class=&quot;token variable&quot;&gt;$OVFTOOL_FILENAME&lt;/span&gt; --console --eulas-agreed --required &amp;amp;&amp;amp; &lt;span class=&quot;token operator&quot;&gt;\&lt;/span&gt;
    rm -f /&lt;span class=&quot;token variable&quot;&gt;$OVFTOOL_FILENAME&lt;/span&gt;&lt;/span&gt;

&lt;span class=&quot;token comment&quot;&gt;#Download and Extract GOVC&lt;/span&gt;
&lt;span class=&quot;token instruction&quot;&gt;&lt;span class=&quot;token keyword&quot;&gt;RUN&lt;/span&gt; wget --quiet https://github.com/vmware/govmomi/releases/download/v&lt;span class=&quot;token variable&quot;&gt;$GOVC_VERSION&lt;/span&gt;/govc_linux_amd64.gz &amp;amp;&amp;amp; &lt;span class=&quot;token operator&quot;&gt;\&lt;/span&gt;
    gunzip -fq govc_linux_amd64.gz &amp;amp;&amp;amp; &lt;span class=&quot;token operator&quot;&gt;\&lt;/span&gt;
    mv govc_linux_amd64 govc &amp;amp;&amp;amp; &lt;span class=&quot;token operator&quot;&gt;\&lt;/span&gt;
    chown root govc &amp;amp;&amp;amp; &lt;span class=&quot;token operator&quot;&gt;\&lt;/span&gt;
    chmod ug+r+x govc &amp;amp;&amp;amp; &lt;span class=&quot;token operator&quot;&gt;\&lt;/span&gt;
    mv govc /usr/local/bin/.&lt;/span&gt;

&lt;span class=&quot;token comment&quot;&gt;# Install kubectl&lt;/span&gt;
&lt;span class=&quot;token instruction&quot;&gt;&lt;span class=&quot;token keyword&quot;&gt;RUN&lt;/span&gt; curl -LO &lt;span class=&quot;token string&quot;&gt;&amp;quot;https://storage.googleapis.com/kubernetes-release/release/$(curl -s https://storage.googleapis.com/kubernetes-release/release/stable.txt)/bin/linux/amd64/kubectl&amp;quot;&lt;/span&gt; &amp;amp;&amp;amp; &lt;span class=&quot;token operator&quot;&gt;\&lt;/span&gt;
    mv kubectl /usr/bin/kubectl &amp;amp;&amp;amp; &lt;span class=&quot;token operator&quot;&gt;\&lt;/span&gt;
    chmod +x /usr/bin/kubectl&lt;/span&gt;

&lt;span class=&quot;token comment&quot;&gt;# Install clusterctl&lt;/span&gt;
&lt;span class=&quot;token instruction&quot;&gt;&lt;span class=&quot;token keyword&quot;&gt;RUN&lt;/span&gt; curl -L https://github.com/kubernetes-sigs/cluster-api/releases/download/v0.3.8/clusterctl-linux-amd64 -o clusterctl &amp;amp;&amp;amp; &lt;span class=&quot;token operator&quot;&gt;\&lt;/span&gt;
    mv clusterctl /usr/bin/clusterctl &amp;amp;&amp;amp; &lt;span class=&quot;token operator&quot;&gt;\&lt;/span&gt;
    chmod +x /usr/bin/clusterctl&lt;/span&gt;

&lt;span class=&quot;token instruction&quot;&gt;&lt;span class=&quot;token keyword&quot;&gt;RUN&lt;/span&gt; apk del .build-apps&lt;/span&gt;&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;</content:encoded><tags>automation,development,vrealize,vra,vmware</tags><featuredImage>https://samperrin.com/static/a0511c8075ba8349a213f67f0f3e2347/hero_5.jpg</featuredImage></item><item><title><![CDATA[Cluster API vSphere - Using ClusterResourceSet to install Calico CNI]]></title><description><![CDATA[Utilise the Cluster API ClusterResourceSet resource type to install the Calico CNI on cluster deployment]]></description><link>https://samperrin.com/posts/cluster-api-vsphere-using-clusterresourceset-to-install-calico-cni/</link><guid isPermaLink="false">https://samperrin.com/posts/cluster-api-vsphere-using-clusterresourceset-to-install-calico-cni/</guid><category><![CDATA[kubernetes]]></category><category><![CDATA[development]]></category><category><![CDATA[vmware]]></category><pubDate>Wed, 23 Sep 2020 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;This post covers the steps required to get Cluster API vSphere (CAPV) to install the Calico CNI when a new cluster is deployed. This post assumes you are using haproxy with CAPV.&lt;/p&gt;&lt;p&gt;We will be utilising the &lt;code class=&quot;language-text&quot;&gt;ClusterResourceSet&lt;/code&gt; resource type, which was introduced in Cluster API 0.3.7 - in theory these steps can be followed regardless of the cloud provided you are using with Cluster API. &lt;/p&gt;&lt;p&gt;Even though the &lt;code class=&quot;language-text&quot;&gt;ClusterResourceSet&lt;/code&gt; was introduced in 0.3.7, I had issues getting it to correctly create the resource, so in the end I upgraded to 0.3.9. This might have been due to CAPV not knowing what the new resource type was until a later version of the provider. &lt;/p&gt;&lt;p&gt;&lt;code class=&quot;language-text&quot;&gt;ClusterResourceSet&lt;/code&gt; is an experimental feature. Follow the officially documented steps to enable. &lt;a href=&quot;https://cluster-api.sigs.k8s.io/tasks/experimental-features/experimental-features.html#enabling-experimental-features-on-existing-management-clusters&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://cluster-api.sigs.k8s.io/tasks/experimental-features/experimental-features.html#enabling-experimental-features-on-existing-management-clusters&lt;/a&gt;&lt;/p&gt;&lt;p&gt;In this post we use &lt;code class=&quot;language-text&quot;&gt;$HOME&lt;/code&gt; instead of &lt;code class=&quot;language-text&quot;&gt;~&lt;/code&gt; for consistency, &lt;code class=&quot;language-text&quot;&gt;--kubeconfig&lt;/code&gt; can sometimes be fussy when using &lt;code class=&quot;language-text&quot;&gt;~&lt;/code&gt;.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;If you haven’t yet setup clusterctl or if you do not have a working management control plane, follow this first: &lt;a href=&quot;Cluster-API-Setup-Steps--vSphere-&quot;&gt;Cluster API Setup Steps (vSphere)&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;The versions used within this post:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;clusterctl: 0.3.9&lt;/li&gt;&lt;li&gt;Cluster API: 0.3.9&lt;/li&gt;&lt;li&gt;Kubernetes: 1.18.2&lt;/li&gt;&lt;li&gt;kubectl: 1.18.2&lt;/li&gt;&lt;li&gt;capv provider: 0.7.1&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Upgrade Cluster API&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Install the latest binary of &lt;code class=&quot;language-text&quot;&gt;clusterctl&lt;/code&gt; with curl. Follow the steps below, or check the official documentation for additional info. &lt;a href=&quot;https://cluster-api.sigs.k8s.io/user/quick-start.html&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://cluster-api.sigs.k8s.io/user/quick-start.html&lt;/a&gt;&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;&lt;span class=&quot;token function&quot;&gt;curl&lt;/span&gt; -L https://github.com/kubernetes-sigs/cluster-api/releases/download/v0.3.9/clusterctl-linux-amd64 -o clusterctl
&lt;span class=&quot;token function&quot;&gt;chmod&lt;/span&gt; +x ./clusterctl
&lt;span class=&quot;token function&quot;&gt;sudo&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;mv&lt;/span&gt; ./clusterctl /usr/local/bin/clusterctl
clusterctl version
&lt;span class=&quot;token comment&quot;&gt;#sudo clusterctl version&lt;/span&gt;&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;strong&gt;Upgrade Cluster API components&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Official documentation: &lt;a href=&quot;https://cluster-api.sigs.k8s.io/clusterctl/commands/upgrade.html&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://cluster-api.sigs.k8s.io/clusterctl/commands/upgrade.html&lt;/a&gt;&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;clusterctl upgrade plan
&lt;span class=&quot;token comment&quot;&gt;#Run the upgrade with the command shown in response to the upgrade plan&lt;/span&gt;
clusterctl upgrade apply --management-group capi-system/cluster-api  --contract v1alpha3&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;strong&gt;Prepare Calico CNI ConfigMap and Custom Cluster Template file&lt;/strong&gt; &lt;/p&gt;&lt;p&gt;Here we will download the Calico manifest and default cluster template file. We will then create a ConfigMap from the Calico manifest.&lt;/p&gt;&lt;p&gt;This section assumes your &lt;code class=&quot;language-text&quot;&gt;KUBECONFIG&lt;/code&gt; is set to your management control plane. If not, use &lt;code class=&quot;language-text&quot;&gt;--kubeconfig&lt;/code&gt; to specify your management control plane kubeconfig file. Check this for reference: &lt;a href=&quot;Cluster-API-Setup-Steps--vSphere-&quot;&gt;Cluster API Setup Steps (vSphere)&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Download the &lt;code class=&quot;language-text&quot;&gt;cluster-template-haproxy.yaml&lt;/code&gt; from the Cluster API vSphere (CAPV) releases page. &lt;a href=&quot;https://github.com/kubernetes-sigs/cluster-api-provider-vsphere/releases/tag/v0.7.1&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://github.com/kubernetes-sigs/cluster-api-provider-vsphere/releases/tag/v0.7.1&lt;/a&gt;&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;&lt;span class=&quot;token function&quot;&gt;curl&lt;/span&gt; -L https://github.com/kubernetes-sigs/cluster-api-provider-vsphere/releases/download/v0.7.1/cluster-template-haproxy.yaml -o &lt;span class=&quot;token string&quot;&gt;&amp;quot;&lt;span class=&quot;token environment constant&quot;&gt;$HOME&lt;/span&gt;/custom-cluster-template-haproxy.yaml&amp;quot;&lt;/span&gt;&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Download the Calico manifest file&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;&lt;span class=&quot;token function&quot;&gt;curl&lt;/span&gt; -L https://docs.projectcalico.org/manifests/calico.yaml -o &lt;span class=&quot;token string&quot;&gt;&amp;quot;&lt;span class=&quot;token environment constant&quot;&gt;$HOME&lt;/span&gt;/calico-manifest.yaml&amp;quot;&lt;/span&gt;&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Create ConfigMap yaml from manifest file, it will be named &lt;code class=&quot;language-text&quot;&gt;calico-cni&lt;/code&gt;&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;kubectl create configmap calico-cni --from-file&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;&lt;span class=&quot;token environment constant&quot;&gt;$HOME&lt;/span&gt;/calico-manifest.yaml&amp;quot;&lt;/span&gt; -o yaml --dry-run&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;client &lt;span class=&quot;token operator&quot;&gt;&amp;gt;&lt;/span&gt; &lt;span class=&quot;token environment constant&quot;&gt;$HOME&lt;/span&gt;/calico-configmap.yaml&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;em&gt;The contents of the &lt;code class=&quot;language-text&quot;&gt;calico-configmap.yaml&lt;/code&gt; is large, I have provided a full copy of my &lt;code class=&quot;language-text&quot;&gt;custom-cluster-template-haproxy.yaml&lt;/code&gt; file at the bottom of this post.&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Update &lt;code class=&quot;language-text&quot;&gt;custom-cluster-template-haproxy.yaml&lt;/code&gt; and generate cluster resources&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Here we will add the contents of the &lt;code class=&quot;language-text&quot;&gt;calico-configmap.yaml&lt;/code&gt; to our custom cluster template file and add the ClusterResourceSet, which then references the new ConfigMap.&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;&lt;span class=&quot;token builtin class-name&quot;&gt;echo&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;---&amp;quot;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;&amp;gt;&amp;gt;&lt;/span&gt; &lt;span class=&quot;token environment constant&quot;&gt;$HOME&lt;/span&gt;/custom-cluster-template-haproxy.yaml
&lt;span class=&quot;token function&quot;&gt;cat&lt;/span&gt; &lt;span class=&quot;token environment constant&quot;&gt;$HOME&lt;/span&gt;/calico-configmap.yaml &lt;span class=&quot;token operator&quot;&gt;&amp;gt;&amp;gt;&lt;/span&gt; &lt;span class=&quot;token environment constant&quot;&gt;$HOME&lt;/span&gt;/custom-cluster-template-haproxy.yaml
&lt;span class=&quot;token function&quot;&gt;cat&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;&amp;gt;&amp;gt;&lt;/span&gt; &lt;span class=&quot;token environment constant&quot;&gt;$HOME&lt;/span&gt;/custom-cluster-template-haproxy.yaml &lt;span class=&quot;token operator&quot;&gt;&amp;lt;&amp;lt;&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;#x27;EOL&amp;#x27;
---
apiVersion: addons.cluster.x-k8s.io/v1alpha3
kind: ClusterResourceSet
metadata:
  name: ${ CLUSTER_NAME }-crs-0
  namespace: &amp;#x27;${ NAMESPACE }&amp;#x27;
spec:
  clusterSelector:
    matchLabels:
      cluster.x-k8s.io/cluster-name: &amp;#x27;${ CLUSTER_NAME }&amp;#x27;
  resources:
  - kind: ConfigMap
    name: calico-cni
EOL&lt;/span&gt;&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Using this new cluster template file we will now generate our cluster resources using &lt;code class=&quot;language-text&quot;&gt;clusterctl&lt;/code&gt;, we then deploy these resources using &lt;code class=&quot;language-text&quot;&gt;kubectl&lt;/code&gt;.
Replace &lt;code class=&quot;language-text&quot;&gt;WORKLOAD_CLUSTER_NAME&lt;/code&gt; value with the name of your new workload cluster.&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;&lt;span class=&quot;token builtin class-name&quot;&gt;export&lt;/span&gt; &lt;span class=&quot;token assign-left variable&quot;&gt;WORKLOAD_CLUSTER_NAME&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;cluster01&amp;quot;&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;mkdir&lt;/span&gt; -p &lt;span class=&quot;token environment constant&quot;&gt;$HOME&lt;/span&gt;/&lt;span class=&quot;token variable&quot;&gt;$WORKLOAD_CLUSTER_NAME&lt;/span&gt;
clusterctl config cluster &lt;span class=&quot;token variable&quot;&gt;$WORKLOAD_CLUSTER_NAME&lt;/span&gt; --kubernetes-version v1.18.2 --control-plane-machine-count &lt;span class=&quot;token number&quot;&gt;1&lt;/span&gt; --worker-machine-count &lt;span class=&quot;token number&quot;&gt;3&lt;/span&gt; --from &lt;span class=&quot;token environment constant&quot;&gt;$HOME&lt;/span&gt;/custom-cluster-template-haproxy.yaml &lt;span class=&quot;token operator&quot;&gt;&amp;gt;&lt;/span&gt; &lt;span class=&quot;token environment constant&quot;&gt;$HOME&lt;/span&gt;/&lt;span class=&quot;token variable&quot;&gt;$WORKLOAD_CLUSTER_NAME&lt;/span&gt;/cluster.yaml

&lt;span class=&quot;token comment&quot;&gt;# with kubeconfig specified&lt;/span&gt;
&lt;span class=&quot;token comment&quot;&gt;# clusterctl config cluster $WORKLOAD_CLUSTER_NAME --kubernetes-version v1.18.2 --control-plane-machine-count 1 --worker-machine-count 3 --from $HOME/custom-cluster-template-haproxy.yaml --kubeconfig=local-control-plane/kubeconfig &amp;gt; $HOME/$WORKLOAD_CLUSTER_NAME/cluster.yaml&lt;/span&gt;&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Review the cluster config file &lt;code class=&quot;language-text&quot;&gt;$HOME/$WORKLOAD_CLUSTER_NAME/cluster.yaml&lt;/code&gt; and make any required changes. Some suggestions to review are CPU, Memory, Storage and Pods CIDR range.&lt;/p&gt;&lt;p&gt;You can use &lt;code class=&quot;language-text&quot;&gt;sed&lt;/code&gt; to do a find and replace within the file, the below examples are for changing the Storage and Memory on all virtual machines as part of this deployment and the Pods CIDR.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Pod CIDR from &lt;code class=&quot;language-text&quot;&gt;192.168.0.0/16&lt;/code&gt; to &lt;code class=&quot;language-text&quot;&gt;192.168.200.0/24&lt;/code&gt;&lt;/li&gt;&lt;li&gt;Memory from &lt;code class=&quot;language-text&quot;&gt;8192&lt;/code&gt; to &lt;code class=&quot;language-text&quot;&gt;4096&lt;/code&gt;&lt;/li&gt;&lt;li&gt;Storage from &lt;code class=&quot;language-text&quot;&gt;25&lt;/code&gt; to &lt;code class=&quot;language-text&quot;&gt;20&lt;/code&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;&lt;span class=&quot;token function&quot;&gt;sed&lt;/span&gt; -i &lt;span class=&quot;token string&quot;&gt;&amp;quot;s/192.168.0.0\/16/192.168.200.0\/24/g&amp;quot;&lt;/span&gt; &lt;span class=&quot;token environment constant&quot;&gt;$HOME&lt;/span&gt;/&lt;span class=&quot;token variable&quot;&gt;$WORKLOAD_CLUSTER_NAME&lt;/span&gt;/cluster.yaml
&lt;span class=&quot;token function&quot;&gt;sed&lt;/span&gt; -i &lt;span class=&quot;token string&quot;&gt;&amp;quot;s/memoryMiB: 8192/memoryMiB: 4096/g&amp;quot;&lt;/span&gt; &lt;span class=&quot;token environment constant&quot;&gt;$HOME&lt;/span&gt;/&lt;span class=&quot;token variable&quot;&gt;$WORKLOAD_CLUSTER_NAME&lt;/span&gt;/cluster.yaml
&lt;span class=&quot;token function&quot;&gt;sed&lt;/span&gt; -i &lt;span class=&quot;token string&quot;&gt;&amp;quot;s/diskGiB: 25/diskGiB: 20/g&amp;quot;&lt;/span&gt; &lt;span class=&quot;token environment constant&quot;&gt;$HOME&lt;/span&gt;/&lt;span class=&quot;token variable&quot;&gt;$WORKLOAD_CLUSTER_NAME&lt;/span&gt;/cluster.yaml&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Deploy the cluster components. Monitor the deployment of virtual machines within vSphere.&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;kubectl apply -f &lt;span class=&quot;token environment constant&quot;&gt;$HOME&lt;/span&gt;/&lt;span class=&quot;token variable&quot;&gt;$WORKLOAD_CLUSTER_NAME&lt;/span&gt;/cluster.yaml&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Use &lt;code class=&quot;language-text&quot;&gt;kubectl&lt;/code&gt; to see the progress of your new cluster. As the CNI is now being deployed on cluster provision we should see it change to Ready.&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;kubectl get cluster --all-namespaces
kubectl get kubeadmcontrolplane --all-namespaces&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Retrieve the &lt;code class=&quot;language-text&quot;&gt;kubeconfig&lt;/code&gt; file for the workload cluster, and then check the node status as well as the existence of calico pods. &lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;kubectl get secret &lt;span class=&quot;token variable&quot;&gt;$WORKLOAD_CLUSTER_NAME&lt;/span&gt;-kubeconfig -o&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;jsonpath&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;#x27;{.data.value}&amp;#x27;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; base64 -d &lt;span class=&quot;token operator&quot;&gt;&lt;span class=&quot;token file-descriptor important&quot;&gt;2&lt;/span&gt;&amp;gt;&lt;/span&gt;/dev/null &lt;span class=&quot;token operator&quot;&gt;||&lt;/span&gt; base64 -D&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;&amp;gt;&lt;/span&gt; &lt;span class=&quot;token environment constant&quot;&gt;$HOME&lt;/span&gt;/&lt;span class=&quot;token variable&quot;&gt;$WORKLOAD_CLUSTER_NAME&lt;/span&gt;/kubeconfig
kubectl get &lt;span class=&quot;token function&quot;&gt;node&lt;/span&gt; -o wide --kubeconfig&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;&lt;span class=&quot;token environment constant&quot;&gt;$HOME&lt;/span&gt;/&lt;span class=&quot;token variable&quot;&gt;$WORKLOAD_CLUSTER_NAME&lt;/span&gt;/kubeconfig&amp;quot;&lt;/span&gt;
kubectl get pod -A -o wide --kubeconfig&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;&lt;span class=&quot;token environment constant&quot;&gt;$HOME&lt;/span&gt;/&lt;span class=&quot;token variable&quot;&gt;$WORKLOAD_CLUSTER_NAME&lt;/span&gt;/kubeconfig&amp;quot;&lt;/span&gt;&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;If all is well, we should see all nodes Ready and several pods running with names starting with &lt;code class=&quot;language-text&quot;&gt;calico-&lt;/code&gt;.&lt;/p&gt;&lt;p&gt;This completes the steps required to get calico deployed at cluster provisioning. ClusterResourceSet could be use to deploy a multitude of other resources at provisioning time, such as CSI’s. &lt;/p&gt;&lt;p&gt;&lt;strong&gt;Complete Custom Cluster Template Example&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;This can be used to generate your cluster resource files. &lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;yaml&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-yaml line-numbers&quot;&gt;&lt;code class=&quot;language-yaml&quot;&gt;&lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
&lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; cluster.x&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;k8s.io/v1alpha3
&lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Cluster
&lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;labels&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;cluster.x-k8s.io/cluster-name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ CLUSTER_NAME }&amp;#x27;&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ CLUSTER_NAME }&amp;#x27;&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;namespace&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ NAMESPACE }&amp;#x27;&lt;/span&gt;
&lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;clusterNetwork&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;pods&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;cidrBlocks&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; 192.168.0.0/16
  &lt;span class=&quot;token key atrule&quot;&gt;controlPlaneRef&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; controlplane.cluster.x&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;k8s.io/v1alpha3
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; KubeadmControlPlane
    &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ CLUSTER_NAME }&amp;#x27;&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;infrastructureRef&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; infrastructure.cluster.x&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;k8s.io/v1alpha3
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; VSphereCluster
    &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ CLUSTER_NAME }&amp;#x27;&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
&lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; infrastructure.cluster.x&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;k8s.io/v1alpha3
&lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; HAProxyLoadBalancer
&lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;labels&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;cluster.x-k8s.io/cluster-name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ CLUSTER_NAME }&amp;#x27;&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ CLUSTER_NAME }&amp;#x27;&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;namespace&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ NAMESPACE }&amp;#x27;&lt;/span&gt;
&lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;user&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;authorizedKeys&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ VSPHERE_SSH_AUTHORIZED_KEY }&amp;#x27;&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; capv
  &lt;span class=&quot;token key atrule&quot;&gt;virtualMachineConfiguration&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;cloneMode&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; linkedClone
    &lt;span class=&quot;token key atrule&quot;&gt;datacenter&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ VSPHERE_DATACENTER }&amp;#x27;&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;datastore&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ VSPHERE_DATASTORE }&amp;#x27;&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;diskGiB&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;25&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;folder&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ VSPHERE_FOLDER }&amp;#x27;&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;memoryMiB&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;8192&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;network&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;devices&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;dhcp4&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;networkName&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ VSPHERE_NETWORK }&amp;#x27;&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;numCPUs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;2&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;resourcePool&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ VSPHERE_RESOURCE_POOL }&amp;#x27;&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;server&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ VSPHERE_SERVER }&amp;#x27;&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;template&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ VSPHERE_HAPROXY_TEMPLATE }&amp;#x27;&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
&lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; infrastructure.cluster.x&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;k8s.io/v1alpha3
&lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; VSphereCluster
&lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ CLUSTER_NAME }&amp;#x27;&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;namespace&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ NAMESPACE }&amp;#x27;&lt;/span&gt;
&lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;cloudProviderConfiguration&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;global&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;insecure&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;secretName&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; cloud&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;provider&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;vsphere&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;credentials
      &lt;span class=&quot;token key atrule&quot;&gt;secretNamespace&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;system
    &lt;span class=&quot;token key atrule&quot;&gt;network&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ VSPHERE_NETWORK }&amp;#x27;&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;providerConfig&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;cloud&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;controllerImage&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; gcr.io/cloud&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;provider&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;vsphere/cpi/release/manager&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;v1.2.0
      &lt;span class=&quot;token key atrule&quot;&gt;storage&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;attacherImage&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; quay.io/k8scsi/csi&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;attacher&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;v2.0.0
        &lt;span class=&quot;token key atrule&quot;&gt;controllerImage&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; gcr.io/cloud&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;provider&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;vsphere/csi/release/driver&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;v2.0.0
        &lt;span class=&quot;token key atrule&quot;&gt;livenessProbeImage&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; quay.io/k8scsi/livenessprobe&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;v1.1.0
        &lt;span class=&quot;token key atrule&quot;&gt;metadataSyncerImage&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; gcr.io/cloud&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;provider&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;vsphere/csi/release/syncer&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;v2.0.0
        &lt;span class=&quot;token key atrule&quot;&gt;nodeDriverImage&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; gcr.io/cloud&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;provider&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;vsphere/csi/release/driver&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;v2.0.0
        &lt;span class=&quot;token key atrule&quot;&gt;provisionerImage&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; quay.io/k8scsi/csi&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;provisioner&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;v1.4.0
        &lt;span class=&quot;token key atrule&quot;&gt;registrarImage&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; quay.io/k8scsi/csi&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;node&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;driver&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;registrar&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;v1.2.0
    &lt;span class=&quot;token key atrule&quot;&gt;virtualCenter&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      $&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; VSPHERE_SERVER &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;datacenters&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ VSPHERE_DATACENTER }&amp;#x27;&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;workspace&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;datacenter&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ VSPHERE_DATACENTER }&amp;#x27;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;datastore&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ VSPHERE_DATASTORE }&amp;#x27;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;folder&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ VSPHERE_FOLDER }&amp;#x27;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;resourcePool&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ VSPHERE_RESOURCE_POOL }&amp;#x27;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;server&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ VSPHERE_SERVER }&amp;#x27;&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;loadBalancerRef&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; infrastructure.cluster.x&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;k8s.io/v1alpha3
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; HAProxyLoadBalancer
    &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ CLUSTER_NAME }&amp;#x27;&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;server&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ VSPHERE_SERVER }&amp;#x27;&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
&lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; infrastructure.cluster.x&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;k8s.io/v1alpha3
&lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; VSphereMachineTemplate
&lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ CLUSTER_NAME }&amp;#x27;&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;namespace&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ NAMESPACE }&amp;#x27;&lt;/span&gt;
&lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;template&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;cloneMode&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; linkedClone
      &lt;span class=&quot;token key atrule&quot;&gt;datacenter&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ VSPHERE_DATACENTER }&amp;#x27;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;datastore&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ VSPHERE_DATASTORE }&amp;#x27;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;diskGiB&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;25&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;folder&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ VSPHERE_FOLDER }&amp;#x27;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;memoryMiB&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;8192&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;network&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;devices&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;dhcp4&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;networkName&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ VSPHERE_NETWORK }&amp;#x27;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;numCPUs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;2&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;resourcePool&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ VSPHERE_RESOURCE_POOL }&amp;#x27;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;server&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ VSPHERE_SERVER }&amp;#x27;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;template&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ VSPHERE_TEMPLATE }&amp;#x27;&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
&lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; controlplane.cluster.x&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;k8s.io/v1alpha3
&lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; KubeadmControlPlane
&lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ CLUSTER_NAME }&amp;#x27;&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;namespace&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ NAMESPACE }&amp;#x27;&lt;/span&gt;
&lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;infrastructureTemplate&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; infrastructure.cluster.x&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;k8s.io/v1alpha3
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; VSphereMachineTemplate
    &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ CLUSTER_NAME }&amp;#x27;&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;kubeadmConfigSpec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;clusterConfiguration&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;apiServer&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;extraArgs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;cloud-provider&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; external
      &lt;span class=&quot;token key atrule&quot;&gt;controllerManager&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;extraArgs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;cloud-provider&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; external
    &lt;span class=&quot;token key atrule&quot;&gt;initConfiguration&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;nodeRegistration&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;criSocket&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /var/run/containerd/containerd.sock
        &lt;span class=&quot;token key atrule&quot;&gt;kubeletExtraArgs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;cloud-provider&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; external
        &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;{{ ds.meta_data.hostname }}&amp;#x27;&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;joinConfiguration&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;nodeRegistration&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;criSocket&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /var/run/containerd/containerd.sock
        &lt;span class=&quot;token key atrule&quot;&gt;kubeletExtraArgs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;cloud-provider&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; external
        &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;{{ ds.meta_data.hostname }}&amp;#x27;&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;preKubeadmCommands&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; hostname &amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; ds.meta_data.hostname &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&amp;quot;
    &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; echo &amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;1         ipv6&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;localhost ipv6&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;loopback&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;/etc/hosts
    &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; echo &amp;quot;127.0.0.1   localhost&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;/etc/hosts
    &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; echo &amp;quot;127.0.0.1   &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; ds.meta_data.hostname &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;/etc/hosts
    &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; echo &amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; ds.meta_data.hostname &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;/etc/hostname
    &lt;span class=&quot;token key atrule&quot;&gt;useExperimentalRetryJoin&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;users&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; capv
      &lt;span class=&quot;token key atrule&quot;&gt;sshAuthorizedKeys&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ VSPHERE_SSH_AUTHORIZED_KEY }&amp;#x27;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;sudo&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ALL=(ALL) NOPASSWD&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;ALL
  &lt;span class=&quot;token key atrule&quot;&gt;replicas&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; $&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; CONTROL_PLANE_MACHINE_COUNT &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ KUBERNETES_VERSION }&amp;#x27;&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
&lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; bootstrap.cluster.x&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;k8s.io/v1alpha3
&lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; KubeadmConfigTemplate
&lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ CLUSTER_NAME }-md-0&amp;#x27;&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;namespace&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ NAMESPACE }&amp;#x27;&lt;/span&gt;
&lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;template&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;joinConfiguration&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;nodeRegistration&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;criSocket&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /var/run/containerd/containerd.sock
          &lt;span class=&quot;token key atrule&quot;&gt;kubeletExtraArgs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token key atrule&quot;&gt;cloud-provider&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; external
          &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;{{ ds.meta_data.hostname }}&amp;#x27;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;preKubeadmCommands&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; hostname &amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; ds.meta_data.hostname &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&amp;quot;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; echo &amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;1         ipv6&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;localhost ipv6&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;loopback&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;/etc/hosts
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; echo &amp;quot;127.0.0.1   localhost&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;/etc/hosts
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; echo &amp;quot;127.0.0.1   &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; ds.meta_data.hostname &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;/etc/hosts
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; echo &amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; ds.meta_data.hostname &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;/etc/hostname
      &lt;span class=&quot;token key atrule&quot;&gt;users&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; capv
        &lt;span class=&quot;token key atrule&quot;&gt;sshAuthorizedKeys&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ VSPHERE_SSH_AUTHORIZED_KEY }&amp;#x27;&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;sudo&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ALL=(ALL) NOPASSWD&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;ALL
&lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
&lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; cluster.x&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;k8s.io/v1alpha3
&lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; MachineDeployment
&lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;labels&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;cluster.x-k8s.io/cluster-name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ CLUSTER_NAME }&amp;#x27;&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ CLUSTER_NAME }-md-0&amp;#x27;&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;namespace&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ NAMESPACE }&amp;#x27;&lt;/span&gt;
&lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;clusterName&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ CLUSTER_NAME }&amp;#x27;&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;replicas&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; $&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; WORKER_MACHINE_COUNT &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;matchLabels&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;template&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;labels&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;cluster.x-k8s.io/cluster-name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ CLUSTER_NAME }&amp;#x27;&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;bootstrap&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;configRef&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; bootstrap.cluster.x&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;k8s.io/v1alpha3
          &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; KubeadmConfigTemplate
          &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ CLUSTER_NAME }-md-0&amp;#x27;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;clusterName&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ CLUSTER_NAME }&amp;#x27;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;infrastructureRef&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; infrastructure.cluster.x&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;k8s.io/v1alpha3
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; VSphereMachineTemplate
        &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ CLUSTER_NAME }&amp;#x27;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ KUBERNETES_VERSION }&amp;#x27;&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
&lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; v1
&lt;span class=&quot;token key atrule&quot;&gt;data&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;calico-manifest.yaml&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt;+
    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token comment&quot;&gt;# Source: calico/templates/calico-config.yaml&lt;/span&gt;
    &lt;span class=&quot;token comment&quot;&gt;# This ConfigMap is used to configure a self-hosted Calico installation.&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ConfigMap
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; v1
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;config
      &lt;span class=&quot;token key atrule&quot;&gt;namespace&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;system
    &lt;span class=&quot;token key atrule&quot;&gt;data&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token comment&quot;&gt;# Typha is disabled.&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;typha_service_name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;none&amp;quot;&lt;/span&gt;
      &lt;span class=&quot;token comment&quot;&gt;# Configure the backend to use.&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;calico_backend&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;bird&amp;quot;&lt;/span&gt;
      &lt;span class=&quot;token comment&quot;&gt;# Configure the MTU to use for workload interfaces and tunnels.&lt;/span&gt;
      &lt;span class=&quot;token comment&quot;&gt;# - If Wireguard is enabled, set to your network MTU - 60&lt;/span&gt;
      &lt;span class=&quot;token comment&quot;&gt;# - Otherwise, if VXLAN or BPF mode is enabled, set to your network MTU - 50&lt;/span&gt;
      &lt;span class=&quot;token comment&quot;&gt;# - Otherwise, if IPIP is enabled, set to your network MTU - 20&lt;/span&gt;
      &lt;span class=&quot;token comment&quot;&gt;# - Otherwise, if not using any encapsulation, set to your network MTU.&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;veth_mtu&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;1440&amp;quot;&lt;/span&gt;

      &lt;span class=&quot;token comment&quot;&gt;# The CNI network configuration to install on each node. The special&lt;/span&gt;
      &lt;span class=&quot;token comment&quot;&gt;# values in this config will be automatically populated.&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;cni_network_config&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;
        &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;name&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;k8s-pod-network&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;cniVersion&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;0.3.1&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;plugins&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;
            &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;type&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;calico&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;log_level&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;info&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;log_file_path&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;/var/log/calico/cni/cni.log&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;datastore_type&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;kubernetes&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;nodename&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;__KUBERNETES_NODE_NAME__&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;mtu&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; __CNI_MTU__&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;ipam&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;type&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;calico-ipam&amp;quot;&lt;/span&gt;
              &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;policy&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;type&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;k8s&amp;quot;&lt;/span&gt;
              &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;kubernetes&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;kubeconfig&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;__KUBECONFIG_FILEPATH__&amp;quot;&lt;/span&gt;
              &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
            &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
            &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;type&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;portmap&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;snat&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;capabilities&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;portMappings&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
            &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
            &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;type&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;bandwidth&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;capabilities&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;bandwidth&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
            &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token comment&quot;&gt;# Source: calico/templates/kdd-crds.yaml&lt;/span&gt;


    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; apiextensions.k8s.io/v1
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CustomResourceDefinition
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;annotations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;controller-gen.kubebuilder.io/version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; (devel)
      &lt;span class=&quot;token key atrule&quot;&gt;creationTimestamp&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token null important&quot;&gt;null&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; bgpconfigurations.crd.projectcalico.org
    &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;group&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; crd.projectcalico.org
      &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; BGPConfiguration
        &lt;span class=&quot;token key atrule&quot;&gt;listKind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; BGPConfigurationList
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; bgpconfigurations
        &lt;span class=&quot;token key atrule&quot;&gt;singular&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; bgpconfiguration
      &lt;span class=&quot;token key atrule&quot;&gt;scope&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Cluster
      &lt;span class=&quot;token key atrule&quot;&gt;versions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; v1
        &lt;span class=&quot;token key atrule&quot;&gt;schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;openAPIV3Schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; BGPConfiguration contains the configuration for any BGP routing.
            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;APIVersion defines the versioned schema of this representation
                  of an object. Servers should convert recognized schemas to the latest
                  internal value&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;and may reject unrecognized values. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#resources&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Kind is a string value representing the REST resource this
                  object represents. Servers may infer this from the endpoint the client
                  &lt;span class=&quot;token key atrule&quot;&gt;submits requests to. Cannot be updated. In CamelCase. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#types-kinds&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
              &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; BGPConfigurationSpec contains the values of the BGP configuration.
                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;asNumber&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;ASNumber is the default AS number used by a node. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token number&quot;&gt;64512&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;format&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; int32
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                  &lt;span class=&quot;token key atrule&quot;&gt;communities&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Communities is a list of BGP community values and their
                      arbitrary names for tagging routes.
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Community contains standard or large community value
                        and its name.
                      &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Name given to community value.
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                        &lt;span class=&quot;token key atrule&quot;&gt;value&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Value must be of format `aa&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;nn` or `aa&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;nn&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;mm`.
                            For standard community use `aa&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;nn` format&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; where `aa` and
                            `nn` are 16 bit number. For large community use `aa&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;nn&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;mm`
                            format&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; where `aa`&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; `nn` and `mm` are 32 bit number. Where&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                            `aa` is an AS Number&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; `nn` and `mm` are per&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;AS identifier.
                          &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^(\d+)&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;(\d+)$&lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt;^(\d+)&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;(\d+)&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;(\d+)$
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                  &lt;span class=&quot;token key atrule&quot;&gt;listenPort&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ListenPort is the port where BGP protocol should listen.
                      Defaults to 179
                    &lt;span class=&quot;token key atrule&quot;&gt;maximum&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;65535&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;minimum&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;1&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                  &lt;span class=&quot;token key atrule&quot;&gt;logSeverityScreen&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;LogSeverityScreen is the log severity above which logs
                      are sent to the stdout. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; INFO&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;nodeToNodeMeshEnabled&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;NodeToNodeMeshEnabled sets whether full node to node
                      BGP mesh is enabled. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;prefixAdvertisements&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; PrefixAdvertisements contains per&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;prefix advertisement
                      configuration.
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; PrefixAdvertisement configures advertisement properties
                        for the specified CIDR.
                      &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;cidr&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CIDR for which properties should be advertised.
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                        &lt;span class=&quot;token key atrule&quot;&gt;communities&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Communities can be list of either community names
                            already defined in `Specs.Communities` or community value
                            of format `aa&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;nn` or `aa&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;nn&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;mm`. For standard community use
                            `aa&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;nn` format&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; where `aa` and `nn` are 16 bit number. For
                            large community use `aa&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;nn&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;mm` format&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; where `aa`&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; `nn` and
                            `mm` are 32 bit number. Where&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;`aa` is an AS Number&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; `nn` and
                            `mm` are per&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;AS identifier.
                          &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                  &lt;span class=&quot;token key atrule&quot;&gt;serviceClusterIPs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ServiceClusterIPs are the CIDR blocks from which service
                      cluster IPs are allocated. If specified&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; Calico will advertise these
                      blocks&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; as well as any cluster IPs within them.
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ServiceClusterIPBlock represents a single allowed ClusterIP
                        CIDR block.
                      &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;cidr&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                  &lt;span class=&quot;token key atrule&quot;&gt;serviceExternalIPs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ServiceExternalIPs are the CIDR blocks for Kubernetes
                      Service External IPs. Kubernetes Service ExternalIPs will only be
                      advertised if they are within one of these blocks.
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ServiceExternalIPBlock represents a single allowed
                        External IP CIDR block.
                      &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;cidr&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
        &lt;span class=&quot;token key atrule&quot;&gt;served&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;storage&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;status&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;acceptedNames&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;conditions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;storedVersions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; apiextensions.k8s.io/v1
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CustomResourceDefinition
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;annotations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;controller-gen.kubebuilder.io/version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; (devel)
      &lt;span class=&quot;token key atrule&quot;&gt;creationTimestamp&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token null important&quot;&gt;null&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; bgppeers.crd.projectcalico.org
    &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;group&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; crd.projectcalico.org
      &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; BGPPeer
        &lt;span class=&quot;token key atrule&quot;&gt;listKind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; BGPPeerList
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; bgppeers
        &lt;span class=&quot;token key atrule&quot;&gt;singular&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; bgppeer
      &lt;span class=&quot;token key atrule&quot;&gt;scope&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Cluster
      &lt;span class=&quot;token key atrule&quot;&gt;versions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; v1
        &lt;span class=&quot;token key atrule&quot;&gt;schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;openAPIV3Schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;APIVersion defines the versioned schema of this representation
                  of an object. Servers should convert recognized schemas to the latest
                  internal value&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;and may reject unrecognized values. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#resources&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Kind is a string value representing the REST resource this
                  object represents. Servers may infer this from the endpoint the client
                  &lt;span class=&quot;token key atrule&quot;&gt;submits requests to. Cannot be updated. In CamelCase. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#types-kinds&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
              &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; BGPPeerSpec contains the specification for a BGPPeer resource.
                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;asNumber&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; The AS Number of the peer.
                    &lt;span class=&quot;token key atrule&quot;&gt;format&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; int32
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                  &lt;span class=&quot;token key atrule&quot;&gt;keepOriginalNextHop&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Option to keep the original nexthop field when routes
                      are sent to a BGP Peer. Setting &amp;quot;true&amp;quot; configures the selected BGP
                      Peers node to use the &amp;quot;next hop keep;&amp;quot; instead of &amp;quot;next hop self;&amp;quot;(default)
                      in the specific branch of the Node on &amp;quot;bird.cfg&amp;quot;.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;node&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; The node name identifying the Calico node instance that
                      is peering with this peer. If this is not set&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; this represents a
                      global peer&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; i.e. a peer that peers with every node in the deployment.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;nodeSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Selector for the nodes that should have this peering.  When
                      this is set&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the Node field must be empty.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;peerIP&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; The IP address of the peer followed by an optional port
                      number to peer with. If port number is given&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; format should be `&lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&amp;lt;IPv6&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;port`
                      or `&amp;lt;IPv4&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&amp;lt;port&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;` for IPv4. If optional port number is not set&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      and this peer IP and ASNumber belongs to a calico/node with ListenPort
                      set in BGPConfiguration&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; then we use that port to peer.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;peerSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Selector for the remote nodes to peer with.  When this
                      is set&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the PeerIP and ASNumber fields must be empty.  For each
                      peering between the local node and selected remote nodes&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; we configure
                      an IPv4 peering if both ends have NodeBGPSpec.IPv4Address specified&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      and an IPv6 peering if both ends have NodeBGPSpec.IPv6Address specified.  The
                      remote AS number comes from the remote node’s NodeBGPSpec.ASNumber&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      or the global default if that is not set.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                &lt;span class=&quot;token key atrule&quot;&gt;required&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; asNumber
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; peerIP
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
        &lt;span class=&quot;token key atrule&quot;&gt;served&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;storage&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;status&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;acceptedNames&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;conditions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;storedVersions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; apiextensions.k8s.io/v1
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CustomResourceDefinition
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;annotations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;controller-gen.kubebuilder.io/version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; (devel)
      &lt;span class=&quot;token key atrule&quot;&gt;creationTimestamp&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token null important&quot;&gt;null&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; blockaffinities.crd.projectcalico.org
    &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;group&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; crd.projectcalico.org
      &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; BlockAffinity
        &lt;span class=&quot;token key atrule&quot;&gt;listKind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; BlockAffinityList
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; blockaffinities
        &lt;span class=&quot;token key atrule&quot;&gt;singular&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; blockaffinity
      &lt;span class=&quot;token key atrule&quot;&gt;scope&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Cluster
      &lt;span class=&quot;token key atrule&quot;&gt;versions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; v1
        &lt;span class=&quot;token key atrule&quot;&gt;schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;openAPIV3Schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;APIVersion defines the versioned schema of this representation
                  of an object. Servers should convert recognized schemas to the latest
                  internal value&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;and may reject unrecognized values. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#resources&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Kind is a string value representing the REST resource this
                  object represents. Servers may infer this from the endpoint the client
                  &lt;span class=&quot;token key atrule&quot;&gt;submits requests to. Cannot be updated. In CamelCase. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#types-kinds&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
              &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; BlockAffinitySpec contains the specification for a BlockAffinity
                  resource.
                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;cidr&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;deleted&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Deleted indicates that this block affinity is being deleted.
                      This field is a string for compatibility with older releases that
                      mistakenly treat this field as a string.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;node&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;state&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                &lt;span class=&quot;token key atrule&quot;&gt;required&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; cidr
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; deleted
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; node
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; state
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
        &lt;span class=&quot;token key atrule&quot;&gt;served&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;storage&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;status&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;acceptedNames&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;conditions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;storedVersions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; apiextensions.k8s.io/v1
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CustomResourceDefinition
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;annotations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;controller-gen.kubebuilder.io/version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; (devel)
      &lt;span class=&quot;token key atrule&quot;&gt;creationTimestamp&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token null important&quot;&gt;null&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; clusterinformations.crd.projectcalico.org
    &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;group&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; crd.projectcalico.org
      &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ClusterInformation
        &lt;span class=&quot;token key atrule&quot;&gt;listKind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ClusterInformationList
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; clusterinformations
        &lt;span class=&quot;token key atrule&quot;&gt;singular&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; clusterinformation
      &lt;span class=&quot;token key atrule&quot;&gt;scope&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Cluster
      &lt;span class=&quot;token key atrule&quot;&gt;versions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; v1
        &lt;span class=&quot;token key atrule&quot;&gt;schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;openAPIV3Schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ClusterInformation contains the cluster specific information.
            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;APIVersion defines the versioned schema of this representation
                  of an object. Servers should convert recognized schemas to the latest
                  internal value&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;and may reject unrecognized values. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#resources&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Kind is a string value representing the REST resource this
                  object represents. Servers may infer this from the endpoint the client
                  &lt;span class=&quot;token key atrule&quot;&gt;submits requests to. Cannot be updated. In CamelCase. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#types-kinds&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
              &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ClusterInformationSpec contains the values of describing
                  the cluster.
                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;calicoVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CalicoVersion is the version of Calico that the cluster
                      is running
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;clusterGUID&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ClusterGUID is the GUID of the cluster
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;clusterType&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ClusterType describes the type of the cluster
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;datastoreReady&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; DatastoreReady is used during significant datastore migrations
                      to signal to components such as Felix that it should wait before
                      accessing the datastore.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;variant&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Variant declares which variant of Calico should be active.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
        &lt;span class=&quot;token key atrule&quot;&gt;served&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;storage&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;status&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;acceptedNames&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;conditions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;storedVersions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; apiextensions.k8s.io/v1
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CustomResourceDefinition
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;annotations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;controller-gen.kubebuilder.io/version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; (devel)
      &lt;span class=&quot;token key atrule&quot;&gt;creationTimestamp&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token null important&quot;&gt;null&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; felixconfigurations.crd.projectcalico.org
    &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;group&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; crd.projectcalico.org
      &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; FelixConfiguration
        &lt;span class=&quot;token key atrule&quot;&gt;listKind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; FelixConfigurationList
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; felixconfigurations
        &lt;span class=&quot;token key atrule&quot;&gt;singular&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; felixconfiguration
      &lt;span class=&quot;token key atrule&quot;&gt;scope&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Cluster
      &lt;span class=&quot;token key atrule&quot;&gt;versions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; v1
        &lt;span class=&quot;token key atrule&quot;&gt;schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;openAPIV3Schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Felix Configuration contains the configuration for Felix.
            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;APIVersion defines the versioned schema of this representation
                  of an object. Servers should convert recognized schemas to the latest
                  internal value&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;and may reject unrecognized values. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#resources&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Kind is a string value representing the REST resource this
                  object represents. Servers may infer this from the endpoint the client
                  &lt;span class=&quot;token key atrule&quot;&gt;submits requests to. Cannot be updated. In CamelCase. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#types-kinds&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
              &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; FelixConfigurationSpec contains the values of the Felix configuration.
                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;allowIPIPPacketsFromWorkloads&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;AllowIPIPPacketsFromWorkloads controls whether Felix
                      will add a rule to drop IPIP encapsulated traffic from workloads
                      &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;false&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;allowVXLANPacketsFromWorkloads&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;AllowVXLANPacketsFromWorkloads controls whether Felix
                      will add a rule to drop VXLAN encapsulated traffic from workloads
                      &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;false&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;awsSrcDstCheck&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Set source&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;destination&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;check on AWS EC2 instances. Accepted
                      value must be one of &amp;quot;DoNothing&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &amp;quot;Enabled&amp;quot; or &amp;quot;Disabled&amp;quot;. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      DoNothing&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;enum&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; DoNothing
                    &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; Enable
                    &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; Disable
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;bpfConnectTimeLoadBalancingEnabled&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;BPFConnectTimeLoadBalancingEnabled when in BPF mode&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      controls whether Felix installs the connection&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;time load balancer.  The
                      connect&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;time load balancer is required for the host to be able to
                      reach Kubernetes services and it improves the performance of pod&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;to&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;service
                      connections.  The only reason to disable it is for debugging purposes.  &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;bpfDataIfacePattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;BPFDataIfacePattern is a regular expression that controls
                      which interfaces Felix should attach BPF programs to in order to
                      catch traffic to/from the network.  This needs to match the interfaces
                      that Calico workload traffic flows over as well as any interfaces
                      that handle incoming traffic to nodeports and services from outside
                      the cluster.  It should not match the workload interfaces (usually
                      named cali&lt;span class=&quot;token punctuation&quot;&gt;...&lt;/span&gt;). &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^(en.&lt;span class=&quot;token important&quot;&gt;*|eth.*|tunl0$)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;bpfDisableUnprivileged&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;BPFDisableUnprivileged&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if enabled&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; Felix sets the kernel.unprivileged_bpf_disabled
                      sysctl to disable unprivileged use of BPF.  This ensures that unprivileged
                      users cannot access Calico&amp;#x27;&amp;#x27;s BPF maps and cannot insert their own
                      BPF programs to interfere with Calico&amp;#x27;&amp;#x27;s. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;bpfEnabled&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;BPFEnabled&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if enabled Felix will use the BPF dataplane.
                      &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;false&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;bpfExternalServiceMode&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;BPFExternalServiceMode in BPF mode&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; controls how connections
                      from outside the cluster to services (node ports and cluster IPs)
                      are forwarded to remote workloads.  If set to &amp;quot;Tunnel&amp;quot; then both
                      request and response traffic is tunneled to the remote node.  If
                      set to &amp;quot;DSR&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the request traffic is tunneled but the response traffic
                      is sent directly from the remote node.  In &amp;quot;DSR&amp;quot; mode&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the remote
                      node appears to use the IP of the ingress node; this requires a
                      permissive L2 network.  &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Tunnel&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;bpfKubeProxyEndpointSlicesEnabled&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; BPFKubeProxyEndpointSlicesEnabled in BPF mode&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; controls
                      whether Felix&amp;#x27;s embedded kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;proxy accepts EndpointSlices or not.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;bpfKubeProxyIptablesCleanupEnabled&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;BPFKubeProxyIptablesCleanupEnabled&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if enabled in BPF
                      mode&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; Felix will proactively clean up the upstream Kubernetes kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;proxy&amp;#x27;&amp;#x27;s
                      iptables chains.  Should only be enabled if kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;proxy is not running.  &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;bpfKubeProxyMinSyncPeriod&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;BPFKubeProxyMinSyncPeriod&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; in BPF mode&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; controls the
                      minimum time between updates to the dataplane for Felix&amp;#x27;&amp;#x27;s embedded
                      kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;proxy.  Lower values give reduced set&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;up latency.  Higher values
                      reduce Felix CPU usage by batching up more work.  &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 1s&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;bpfLogLevel&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;BPFLogLevel controls the log level of the BPF programs
                      when in BPF dataplane mode.  One of &amp;quot;Off&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;Info&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; or &amp;quot;Debug&amp;quot;.  The
                      logs are emitted to the BPF trace pipe&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; accessible with the command
                      `tc exec bpf debug`. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Off&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;.&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;chainInsertMode&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;ChainInsertMode controls whether Felix hooks the kernel’s
                      top&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;level iptables chains by inserting a rule at the top of the
                      chain or by appending a rule at the bottom. insert is the safe default
                      since it prevents Calico’s rules from being bypassed. If you switch
                      to append mode&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; be sure that the other rules in the chains signal
                      acceptance by falling through to the Calico rules&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; otherwise the
                      Calico policy will be bypassed. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; insert&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;dataplaneDriver&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;debugDisableLogDropping&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;debugMemoryProfilePath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;debugSimulateCalcGraphHangAfter&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;debugSimulateDataplaneHangAfter&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;defaultEndpointToHostAction&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;DefaultEndpointToHostAction controls what happens to
                      traffic that goes from a workload endpoint to the host itself (after
                      the traffic hits the endpoint egress policy). By default Calico
                      blocks traffic from workload endpoints to the host itself with an
                      iptables “DROP” action. If you want to allow some or all traffic
                      from endpoint to host&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; set this parameter to RETURN or ACCEPT. Use
                      RETURN if you have your own rules in the iptables “INPUT” chain;
                      Calico will insert its rules at the top of that chain&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; then “RETURN”
                      packets to the “INPUT” chain once it has completed processing workload
                      endpoint egress policy. Use ACCEPT to unconditionally accept packets
                      from workloads after processing workload endpoint egress policy.
                      &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Drop&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;deviceRouteProtocol&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; This defines the route protocol added to programmed device
                      routes&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; by default this will be RTPROT_BOOT when left blank.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                  &lt;span class=&quot;token key atrule&quot;&gt;deviceRouteSourceAddress&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; This is the source address to use on programmed device
                      routes. By default the source address is left blank&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; leaving the
                      kernel to choose the source address used.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;disableConntrackInvalidCheck&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;endpointReportingDelay&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;endpointReportingEnabled&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;externalNodesList&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ExternalNodesCIDRList is a list of CIDR&amp;#x27;s of external&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;non&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;nodes
                      which may source tunnel traffic and have the tunneled traffic be
                      accepted at calico nodes.
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                  &lt;span class=&quot;token key atrule&quot;&gt;failsafeInboundHostPorts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;FailsafeInboundHostPorts is a comma&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;delimited list of
                      UDP/TCP ports that Felix will allow incoming traffic to host endpoints
                      on irrespective of the security policy. This is useful to avoid
                      accidentally cutting off a host with incorrect configuration. Each
                      port should be specified as tcp&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&amp;lt;port&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;number&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt; or udp&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&amp;lt;port&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;number&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;.
                      For back&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;compatibility&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if the protocol is not specified&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; it defaults
                      to “tcp”. To disable all inbound host ports&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; use the value none.
                      The default value allows ssh access and DHCP. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; tcp&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;22&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      udp&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;68&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; tcp&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;179&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; tcp&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;2379&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; tcp&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;2380&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; tcp&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;6443&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; tcp&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;6666&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; tcp&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;6667&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ProtoPort is combination of protocol and port&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; both
                        must be specified.
                      &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;port&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                        &lt;span class=&quot;token key atrule&quot;&gt;protocol&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                      &lt;span class=&quot;token key atrule&quot;&gt;required&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; port
                      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; protocol
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                  &lt;span class=&quot;token key atrule&quot;&gt;failsafeOutboundHostPorts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;FailsafeOutboundHostPorts is a comma&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;delimited list
                      of UDP/TCP ports that Felix will allow outgoing traffic from host
                      endpoints to irrespective of the security policy. This is useful
                      to avoid accidentally cutting off a host with incorrect configuration.
                      Each port should be specified as tcp&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&amp;lt;port&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;number&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt; or udp&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&amp;lt;port&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;number&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;.
                      For back&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;compatibility&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if the protocol is not specified&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; it defaults
                      to “tcp”. To disable all outbound host ports&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; use the value none.
                      The default value opens etcd’s standard ports to ensure that Felix
                      does not get cut off from etcd as well as allowing DHCP and DNS.
                      &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; tcp&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;179&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; tcp&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;2379&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; tcp&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;2380&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; tcp&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;6443&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; tcp&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;6666&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; tcp&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;6667&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      udp&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;53&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; udp&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;67&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ProtoPort is combination of protocol and port&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; both
                        must be specified.
                      &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;port&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                        &lt;span class=&quot;token key atrule&quot;&gt;protocol&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                      &lt;span class=&quot;token key atrule&quot;&gt;required&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; port
                      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; protocol
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                  &lt;span class=&quot;token key atrule&quot;&gt;featureDetectOverride&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; FeatureDetectOverride is used to override the feature
                      detection. Values are specified in a comma separated list with no
                      spaces&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; example; &amp;quot;SNATFullyRandom=true&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;MASQFullyRandom=false&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;RestoreSupportsLock=&amp;quot;.
                      &amp;quot;true&amp;quot; or &amp;quot;false&amp;quot; will force the feature&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; empty or omitted values
                      are auto&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;detected.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;genericXDPEnabled&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;GenericXDPEnabled enables Generic XDP so network cards
                      that don&amp;#x27;&amp;#x27;t support XDP offload or driver modes can use XDP. This
                      is not recommended since it doesn&amp;#x27;&amp;#x27;t provide better performance
                      than iptables. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;false&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;healthEnabled&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;healthHost&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;healthPort&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                  &lt;span class=&quot;token key atrule&quot;&gt;interfaceExclude&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;InterfaceExclude is a comma&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;separated list of interfaces
                      that Felix should exclude when monitoring for host endpoints. The
                      default value ensures that Felix ignores Kubernetes&amp;#x27;&amp;#x27; IPVS dummy
                      interface&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; which is used internally by kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;proxy. If you want to
                      exclude multiple interface names using a single value&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the list
                      supports regular expressions. For regular expressions you must wrap
                      the value with &amp;#x27;&amp;#x27;/&amp;#x27;&amp;#x27;. For example having values &amp;#x27;&amp;#x27;/^kube/&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;veth1&amp;#x27;&amp;#x27;
                      will exclude all interfaces that begin with &amp;#x27;&amp;#x27;kube&amp;#x27;&amp;#x27; and also the
                      interface &amp;#x27;&amp;#x27;veth1&amp;#x27;&amp;#x27;. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;ipvs0&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;interfacePrefix&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;InterfacePrefix is the interface name prefix that identifies
                      workload endpoints and so distinguishes them from host endpoint
                      &lt;span class=&quot;token key atrule&quot;&gt;interfaces. Note&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; in environments other than bare metal&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the orchestrators
                      configure this appropriately. For example our Kubernetes and Docker
                      integrations set the ‘cali’ value&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; and our OpenStack integration
                      sets the ‘tap’ value. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; cali&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;interfaceRefreshInterval&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; InterfaceRefreshInterval is the period at which Felix
                      rescans local interfaces to verify their state. The rescan can be
                      disabled by setting the interval to 0.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;ipipEnabled&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;ipipMTU&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;IPIPMTU is the MTU to set on the tunnel device. See
                      Configuring MTU &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;1440&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                  &lt;span class=&quot;token key atrule&quot;&gt;ipsetsRefreshInterval&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;IpsetsRefreshInterval is the period at which Felix re&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;checks
                      all iptables state to ensure that no other process has accidentally
                      broken Calico’s rules. Set to 0 to disable iptables refresh. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      90s&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;iptablesBackend&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; IptablesBackend specifies which backend of iptables will
                      be used. The default is legacy.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;iptablesFilterAllowAction&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;iptablesLockFilePath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;IptablesLockFilePath is the location of the iptables
                      lock file. You may need to change this if the lock file is not in
                      its standard location (for example if you have mapped it into Felix’s
                      container at a different path). &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /run/xtables.lock&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;iptablesLockProbeInterval&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;IptablesLockProbeInterval is the time that Felix will
                      wait between attempts to acquire the iptables lock if it is not
                      available. Lower values make Felix more responsive when the lock
                      is contended&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; but use more CPU. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 50ms&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;iptablesLockTimeout&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;IptablesLockTimeout is the time that Felix will wait
                      for the iptables lock&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; or 0&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; to disable. To use this feature&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; Felix
                      must share the iptables lock file with all other processes that
                      also take the lock. When running Felix inside a container&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; this
                      requires the /run directory of the host to be mounted into the calico/node
                      or calico/felix container. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 0s disabled&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;iptablesMangleAllowAction&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;iptablesMarkMask&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;IptablesMarkMask is the mask that Felix selects its
                      IPTables Mark bits from. Should be a 32 bit hexadecimal number with
                      at least 8 bits set&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; none of which clash with any other mark bits
                      in use on the system. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;0xff000000&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;format&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; int32
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                  &lt;span class=&quot;token key atrule&quot;&gt;iptablesNATOutgoingInterfaceFilter&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;iptablesPostWriteCheckInterval&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;IptablesPostWriteCheckInterval is the period after Felix
                      has done a write to the dataplane that it schedules an extra read
                      back in order to check the write was not clobbered by another process.
                      This should only occur if another application on the system doesn’t
                      respect the iptables lock. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 1s&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;iptablesRefreshInterval&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;IptablesRefreshInterval is the period at which Felix
                      re&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;checks the IP sets in the dataplane to ensure that no other process
                      has accidentally broken Calico’s rules. Set to 0 to disable IP sets
                      &lt;span class=&quot;token key atrule&quot;&gt;refresh. Note&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; the default for this value is lower than the other
                      refresh intervals as a workaround for a Linux kernel bug that was
                      fixed in kernel version 4.11. If you are using v4.11 or greater
                      you may want to set this to&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; a higher value to reduce Felix CPU
                      usage. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 10s&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;ipv6Support&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;kubeNodePortRanges&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;KubeNodePortRanges holds list of port ranges used for
                      service node ports. Only used if felix detects kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;proxy running
                      in ipvs mode. Felix uses these ranges to separate host and workload
                      traffic. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 30000&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;32767&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;.&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                      &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                      &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                  &lt;span class=&quot;token key atrule&quot;&gt;logFilePath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;LogFilePath is the full path to the Felix log. Set to
                      none to disable file logging. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /var/log/calico/felix.log&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;logPrefix&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;LogPrefix is the log prefix that Felix uses when rendering
                      LOG rules. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;packet&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;logSeverityFile&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;LogSeverityFile is the log severity above which logs
                      are sent to the log file. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Info&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;logSeverityScreen&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;LogSeverityScreen is the log severity above which logs
                      are sent to the stdout. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Info&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;logSeveritySys&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;LogSeveritySys is the log severity above which logs
                      are sent to the syslog. Set to None for no logging to syslog. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      Info&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;maxIpsetSize&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                  &lt;span class=&quot;token key atrule&quot;&gt;metadataAddr&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;MetadataAddr is the IP address or domain name of the
                      server that can answer VM queries for cloud&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;init metadata. In OpenStack&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      this corresponds to the machine running nova&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;api (or in Ubuntu&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      nova&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;metadata). A value of none (case insensitive) means that
                      Felix should not set up any NAT rule for the metadata path. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      127.0.0.1&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;metadataPort&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;MetadataPort is the port of the metadata server. This&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      combined with global.MetadataAddr (if not ‘None’)&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; is used to set
                      up a NAT rule&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; from 169.254.169.254&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;80 to MetadataAddr&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;MetadataPort.
                      In most cases this should not need to be changed &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;8775&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;.&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                  &lt;span class=&quot;token key atrule&quot;&gt;natOutgoingAddress&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NATOutgoingAddress specifies an address to use when performing
                      source NAT for traffic in a natOutgoing pool that is leaving the
                      network. By default the address used is an address on the interface
                      the traffic is leaving on (ie it uses the iptables MASQUERADE target)
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;natPortRange&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                    &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NATPortRange specifies the range of ports that is used
                      for port mapping when doing outgoing NAT. When unset the default
                      behavior of the network stack is used.
                    &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                    &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;netlinkTimeout&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;openstackRegion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;OpenstackRegion is the name of the region that a particular
                      Felix belongs to. In a multi&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;region Calico/OpenStack deployment&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      this must be configured somehow for each Felix (here in the datamodel&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      or in felix.cfg or the environment on each compute node)&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; and must
                      match the &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;calico&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt; openstack_region value configured in neutron.conf
                      on each node. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Empty&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;policySyncPathPrefix&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;PolicySyncPathPrefix is used to by Felix to communicate
                      policy changes to external services&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; like Application layer policy.
                      &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Empty&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;prometheusGoMetricsEnabled&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;PrometheusGoMetricsEnabled disables Go runtime metrics
                      collection&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; which the Prometheus client does by default&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; when set
                      to false. This reduces the number of metrics reported&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; reducing
                      Prometheus load. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;prometheusMetricsEnabled&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;PrometheusMetricsEnabled enables the Prometheus metrics
                      server in Felix if set to true. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;false&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;prometheusMetricsHost&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;PrometheusMetricsHost is the host that the Prometheus
                      metrics server should bind to. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; empty&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;prometheusMetricsPort&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;PrometheusMetricsPort is the TCP port that the Prometheus
                      metrics server should bind to. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;9091&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                  &lt;span class=&quot;token key atrule&quot;&gt;prometheusProcessMetricsEnabled&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;PrometheusProcessMetricsEnabled disables process metrics
                      collection&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; which the Prometheus client does by default&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; when set
                      to false. This reduces the number of metrics reported&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; reducing
                      Prometheus load. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;removeExternalRoutes&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Whether or not to remove device routes that have not
                      been programmed by Felix. Disabling this will allow external applications
                      to also add device routes. This is enabled by default which means
                      we will remove externally added routes.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;reportingInterval&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;ReportingInterval is the interval at which Felix reports
                      its status into the datastore or 0 to disable. Must be non&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;zero
                      in OpenStack deployments. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 30s&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;reportingTTL&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;ReportingTTL is the time&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;to&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;live setting for process&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;wide
                      status reports. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 90s&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;routeRefreshInterval&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;RouterefreshInterval is the period at which Felix re&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;checks
                      the routes in the dataplane to ensure that no other process has
                      accidentally broken Calico’s rules. Set to 0 to disable route refresh.
                      &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 90s&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;routeSource&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;RouteSource configures where Felix gets its routing
                      &lt;span class=&quot;token key atrule&quot;&gt;information. - WorkloadIPs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; use workload endpoints to construct
                      &lt;span class=&quot;token key atrule&quot;&gt;routes. - CalicoIPAM&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; the default &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; use IPAM data to construct routes.&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;routeTableRange&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Calico programs additional Linux route tables for various
                      purposes.  RouteTableRange specifies the indices of the route tables
                      that Calico should use.
                    &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;max&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                      &lt;span class=&quot;token key atrule&quot;&gt;min&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                    &lt;span class=&quot;token key atrule&quot;&gt;required&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; max
                    &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; min
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                  &lt;span class=&quot;token key atrule&quot;&gt;sidecarAccelerationEnabled&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;SidecarAccelerationEnabled enables experimental sidecar
                      acceleration &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;false&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;usageReportingEnabled&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;UsageReportingEnabled reports anonymous Calico version
                      number and cluster size to projectcalico.org. Logs warnings returned
                      by the usage server. For example&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if a significant security vulnerability
                      has been discovered in the version of Calico being used. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;usageReportingInitialDelay&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;UsageReportingInitialDelay controls the minimum delay
                      before Felix makes a report. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 300s&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;usageReportingInterval&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;UsageReportingInterval controls the interval at which
                      Felix makes reports. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 86400s&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;useInternalDataplaneDriver&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;vxlanEnabled&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;vxlanMTU&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;VXLANMTU is the MTU to set on the tunnel device. See
                      Configuring MTU &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;1440&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                  &lt;span class=&quot;token key atrule&quot;&gt;vxlanPort&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                  &lt;span class=&quot;token key atrule&quot;&gt;vxlanVNI&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                  &lt;span class=&quot;token key atrule&quot;&gt;wireguardEnabled&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;WireguardEnabled controls whether Wireguard is enabled.
                      &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;false&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;wireguardInterfaceName&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;WireguardInterfaceName specifies the name to use for
                      the Wireguard interface. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; wg.calico&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;wireguardListeningPort&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;WireguardListeningPort controls the listening port used
                      by Wireguard. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;51820&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                  &lt;span class=&quot;token key atrule&quot;&gt;wireguardMTU&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;WireguardMTU controls the MTU on the Wireguard interface.
                      See Configuring MTU &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;1420&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                  &lt;span class=&quot;token key atrule&quot;&gt;wireguardRoutingRulePriority&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;WireguardRoutingRulePriority controls the priority value
                      to use for the Wireguard routing rule. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;99&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                  &lt;span class=&quot;token key atrule&quot;&gt;xdpEnabled&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;XDPEnabled enables XDP acceleration for suitable untracked
                      incoming deny rules. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;xdpRefreshInterval&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;XDPRefreshInterval is the period at which Felix re&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;checks
                      all XDP state to ensure that no other process has accidentally broken
                      Calico&amp;#x27;&amp;#x27;s BPF maps or attached programs. Set to 0 to disable XDP
                      refresh. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 90s&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
        &lt;span class=&quot;token key atrule&quot;&gt;served&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;storage&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;status&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;acceptedNames&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;conditions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;storedVersions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; apiextensions.k8s.io/v1
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CustomResourceDefinition
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;annotations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;controller-gen.kubebuilder.io/version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; (devel)
      &lt;span class=&quot;token key atrule&quot;&gt;creationTimestamp&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token null important&quot;&gt;null&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; globalnetworkpolicies.crd.projectcalico.org
    &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;group&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; crd.projectcalico.org
      &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; GlobalNetworkPolicy
        &lt;span class=&quot;token key atrule&quot;&gt;listKind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; GlobalNetworkPolicyList
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; globalnetworkpolicies
        &lt;span class=&quot;token key atrule&quot;&gt;singular&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; globalnetworkpolicy
      &lt;span class=&quot;token key atrule&quot;&gt;scope&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Cluster
      &lt;span class=&quot;token key atrule&quot;&gt;versions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; v1
        &lt;span class=&quot;token key atrule&quot;&gt;schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;openAPIV3Schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;APIVersion defines the versioned schema of this representation
                  of an object. Servers should convert recognized schemas to the latest
                  internal value&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;and may reject unrecognized values. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#resources&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Kind is a string value representing the REST resource this
                  object represents. Servers may infer this from the endpoint the client
                  &lt;span class=&quot;token key atrule&quot;&gt;submits requests to. Cannot be updated. In CamelCase. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#types-kinds&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
              &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;applyOnForward&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ApplyOnForward indicates to apply the rules in this policy
                      on forward traffic.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;doNotTrack&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; DoNotTrack indicates whether packets matched by the rules
                      in this policy should go through the data plane&amp;#x27;s connection tracking&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      such as Linux conntrack.  If True&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the rules in this policy are
                      applied before any data plane connection tracking&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; and packets allowed
                      by this policy are marked as not to be tracked.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;egress&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; The ordered set of egress rules.  Each rule contains
                      a set of packet match criteria and a corresponding action to apply.
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;A Rule encapsulates a set of match criteria and an
                        action.  Both selector&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;based security Policy and security Profiles
                        reference rules &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; separated out as a list of rules for both ingress
                        and egress packet matching. \n Each positive match criteria has
                        a negated version&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; prefixed with ”Not”. All the match criteria
                        within a rule must be satisfied for a packet to match. A single
                        rule can contain the positive and negative version of a match
                        and both must be satisfied for the rule to match.&amp;quot;
                      &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;action&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                        &lt;span class=&quot;token key atrule&quot;&gt;destination&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Destination contains the match criteria that apply
                            to destination entity.
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;namespaceSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;NamespaceSelector is an optional field that
                                contains a selector expression. Only traffic that originates
                                from (or terminates at) endpoints within the selected
                                namespaces will be matched. When both NamespaceSelector
                                and Selector are defined on the same rule&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; then only workload
                                endpoints that are matched by both selectors will be selected
                                by the rule. \n For NetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; an empty NamespaceSelector
                                implies that the Selector is limited to selecting only
                                workload endpoints in the same namespace as the NetworkPolicy.
                                \n For NetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; `global()` NamespaceSelector implies
                                that the Selector is limited to selecting only GlobalNetworkSet
                                or HostEndpoint. \n For GlobalNetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; an empty
                                NamespaceSelector implies the Selector applies to workload
                                endpoints across all namespaces.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;nets&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Nets is an optional field that restricts the
                                rule to only apply to traffic that originates from (or
                                terminates at) IP addresses in any of the given subnets.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notNets&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotNets is the negated version of the Nets
                                field.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notPorts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotPorts is the negated version of the Ports
                                field. Since only some protocols have ports&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if any ports
                                are specified it requires the Protocol match in the Rule
                                to be set to &amp;quot;TCP&amp;quot; or &amp;quot;UDP&amp;quot;.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                                &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotSelector is the negated version of the Selector
                                field.  See Selector field for subtleties with negated
                                selectors.
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;ports&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Ports is an optional field that restricts
                                the rule to only apply to traffic that has a source (destination)
                                port that matches one of these ranges/values. This value
                                is a list of integers or strings that represent ranges
                                of ports. \n Since only some protocols have ports&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if
                                any ports are specified it requires the Protocol match
                                in the Rule to be set to \&amp;quot;TCP\&amp;quot; or \&amp;quot;UDP\&amp;quot;.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                                &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Selector is an optional field that contains
                                a selector expression (see Policy for sample syntax).
                                \ Only traffic that originates from (terminates at) endpoints
                                &lt;span class=&quot;token key atrule&quot;&gt;matching the selector will be matched. \n Note that&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; in
                                addition to the negated version of the Selector (see NotSelector
                                below)&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the selector expression syntax itself supports
                                negation.  The two types of negation are subtly different.
                                One negates the set of matched endpoints&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the other negates
                                &lt;span class=&quot;token key atrule&quot;&gt;the whole match&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; \n \tSelector = \&amp;quot;&lt;span class=&quot;token tag&quot;&gt;!has(my_label)&lt;/span&gt;\&amp;quot; matches
                                packets that are from other Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled \tendpoints
                                that do not have the label “my_label”. \n \tNotSelector
                                = \&amp;quot;has(my_label)\&amp;quot; matches packets that are not from
                                Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled \tendpoints that do have the label “my_label”.
                                \n The effect is that the latter will accept packets from
                                non&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Calico sources whereas the former is limited to packets
                                from Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled endpoints.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;serviceAccounts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ServiceAccounts is an optional field that restricts
                                the rule to only apply to traffic that originates from
                                (or terminates at) a pod running as a matching service
                                account.
                              &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Names is an optional field that restricts
                                    the rule to only apply to traffic that originates
                                    from (or terminates at) a pod running as a service
                                    account whose name is in the list.
                                  &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                  &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                                &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Selector is an optional field that restricts
                                    the rule to only apply to traffic that originates
                                    from (or terminates at) a pod running as a service
                                    account that matches the given label selector. If
                                    both Names and Selector are specified then they are
                                    AND&amp;#x27;ed.
                                  &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;http&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; HTTP contains match criteria that apply to HTTP
                            requests.
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;methods&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Methods is an optional field that restricts
                                the rule to apply only to HTTP requests that use one of
                                the listed HTTP Methods (e.g. GET&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; PUT&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; etc.) Multiple
                                methods are OR&amp;#x27;d together.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;paths&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Paths is an optional field that restricts
                                the rule to apply to HTTP requests that use one of the
                                listed HTTP Paths. Multiple paths are OR&amp;#x27;&amp;#x27;d together.
                                &lt;span class=&quot;token key atrule&quot;&gt;e.g&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;exact&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;/foo - prefix&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;/bar NOTE&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Each entry may
                                ONLY specify either a `exact` or a `prefix` match. The
                                validator will check for it.&amp;#x27;
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;HTTPPath specifies an HTTP path to match.
                                  &lt;span class=&quot;token key atrule&quot;&gt;It may be either of the form&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;exact&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;&amp;lt;path&amp;gt;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; which matches
                                  &lt;span class=&quot;token key atrule&quot;&gt;the path exactly or prefix&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;&amp;lt;path-prefix&amp;gt;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; which matches
                                  the path prefix&amp;#x27;
                                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;exact&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                  &lt;span class=&quot;token key atrule&quot;&gt;prefix&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;icmp&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ICMP is an optional field that restricts the rule
                            to apply to a specific type and code of ICMP traffic.  This
                            should only be specified if the Protocol field is set to &amp;quot;ICMP&amp;quot;
                            or &amp;quot;ICMPv6&amp;quot;.
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;code&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Match on a specific ICMP code.  If specified&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                                the Type value must also be specified. This is a technical
                                limitation imposed by the kernel’s iptables firewall&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                                which Calico uses to enforce the rule.
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Match on a specific ICMP type.  For example
                                a value of 8 refers to ICMP Echo Request (i.e. pings).
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;ipVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; IPVersion is an optional field that restricts the
                            rule to only match a specific IP version.
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                        &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Metadata contains additional information for this
                            rule
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;annotations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;additionalProperties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Annotations is a set of key value pairs that
                                give extra information about the rule
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;notICMP&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotICMP is the negated version of the ICMP field.
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;code&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Match on a specific ICMP code.  If specified&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                                the Type value must also be specified. This is a technical
                                limitation imposed by the kernel’s iptables firewall&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                                which Calico uses to enforce the rule.
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Match on a specific ICMP type.  For example
                                a value of 8 refers to ICMP Echo Request (i.e. pings).
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;notProtocol&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotProtocol is the negated version of the Protocol
                            field.
                          &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                          &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;protocol&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Protocol is an optional field that restricts the
                            rule to only apply to traffic of a specific IP protocol. Required
                            if any of the EntityRules contain Ports (because ports only
                            apply to certain protocols). \n Must be one of these string
                            &lt;span class=&quot;token key atrule&quot;&gt;values&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; \&amp;quot;TCP\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;UDP\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;ICMP\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;ICMPv6\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;SCTP\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                            \&amp;quot;UDPLite\&amp;quot; or an integer in the range 1&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;255.&amp;quot;
                          &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                          &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;source&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Source contains the match criteria that apply to
                            source entity.
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;namespaceSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;NamespaceSelector is an optional field that
                                contains a selector expression. Only traffic that originates
                                from (or terminates at) endpoints within the selected
                                namespaces will be matched. When both NamespaceSelector
                                and Selector are defined on the same rule&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; then only workload
                                endpoints that are matched by both selectors will be selected
                                by the rule. \n For NetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; an empty NamespaceSelector
                                implies that the Selector is limited to selecting only
                                workload endpoints in the same namespace as the NetworkPolicy.
                                \n For NetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; `global()` NamespaceSelector implies
                                that the Selector is limited to selecting only GlobalNetworkSet
                                or HostEndpoint. \n For GlobalNetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; an empty
                                NamespaceSelector implies the Selector applies to workload
                                endpoints across all namespaces.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;nets&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Nets is an optional field that restricts the
                                rule to only apply to traffic that originates from (or
                                terminates at) IP addresses in any of the given subnets.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notNets&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotNets is the negated version of the Nets
                                field.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notPorts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotPorts is the negated version of the Ports
                                field. Since only some protocols have ports&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if any ports
                                are specified it requires the Protocol match in the Rule
                                to be set to &amp;quot;TCP&amp;quot; or &amp;quot;UDP&amp;quot;.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                                &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotSelector is the negated version of the Selector
                                field.  See Selector field for subtleties with negated
                                selectors.
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;ports&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Ports is an optional field that restricts
                                the rule to only apply to traffic that has a source (destination)
                                port that matches one of these ranges/values. This value
                                is a list of integers or strings that represent ranges
                                of ports. \n Since only some protocols have ports&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if
                                any ports are specified it requires the Protocol match
                                in the Rule to be set to \&amp;quot;TCP\&amp;quot; or \&amp;quot;UDP\&amp;quot;.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                                &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Selector is an optional field that contains
                                a selector expression (see Policy for sample syntax).
                                \ Only traffic that originates from (terminates at) endpoints
                                &lt;span class=&quot;token key atrule&quot;&gt;matching the selector will be matched. \n Note that&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; in
                                addition to the negated version of the Selector (see NotSelector
                                below)&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the selector expression syntax itself supports
                                negation.  The two types of negation are subtly different.
                                One negates the set of matched endpoints&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the other negates
                                &lt;span class=&quot;token key atrule&quot;&gt;the whole match&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; \n \tSelector = \&amp;quot;&lt;span class=&quot;token tag&quot;&gt;!has(my_label)&lt;/span&gt;\&amp;quot; matches
                                packets that are from other Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled \tendpoints
                                that do not have the label “my_label”. \n \tNotSelector
                                = \&amp;quot;has(my_label)\&amp;quot; matches packets that are not from
                                Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled \tendpoints that do have the label “my_label”.
                                \n The effect is that the latter will accept packets from
                                non&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Calico sources whereas the former is limited to packets
                                from Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled endpoints.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;serviceAccounts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ServiceAccounts is an optional field that restricts
                                the rule to only apply to traffic that originates from
                                (or terminates at) a pod running as a matching service
                                account.
                              &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Names is an optional field that restricts
                                    the rule to only apply to traffic that originates
                                    from (or terminates at) a pod running as a service
                                    account whose name is in the list.
                                  &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                  &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                                &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Selector is an optional field that restricts
                                    the rule to only apply to traffic that originates
                                    from (or terminates at) a pod running as a service
                                    account that matches the given label selector. If
                                    both Names and Selector are specified then they are
                                    AND&amp;#x27;ed.
                                  &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                      &lt;span class=&quot;token key atrule&quot;&gt;required&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; action
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                  &lt;span class=&quot;token key atrule&quot;&gt;ingress&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; The ordered set of ingress rules.  Each rule contains
                      a set of packet match criteria and a corresponding action to apply.
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;A Rule encapsulates a set of match criteria and an
                        action.  Both selector&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;based security Policy and security Profiles
                        reference rules &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; separated out as a list of rules for both ingress
                        and egress packet matching. \n Each positive match criteria has
                        a negated version&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; prefixed with ”Not”. All the match criteria
                        within a rule must be satisfied for a packet to match. A single
                        rule can contain the positive and negative version of a match
                        and both must be satisfied for the rule to match.&amp;quot;
                      &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;action&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                        &lt;span class=&quot;token key atrule&quot;&gt;destination&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Destination contains the match criteria that apply
                            to destination entity.
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;namespaceSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;NamespaceSelector is an optional field that
                                contains a selector expression. Only traffic that originates
                                from (or terminates at) endpoints within the selected
                                namespaces will be matched. When both NamespaceSelector
                                and Selector are defined on the same rule&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; then only workload
                                endpoints that are matched by both selectors will be selected
                                by the rule. \n For NetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; an empty NamespaceSelector
                                implies that the Selector is limited to selecting only
                                workload endpoints in the same namespace as the NetworkPolicy.
                                \n For NetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; `global()` NamespaceSelector implies
                                that the Selector is limited to selecting only GlobalNetworkSet
                                or HostEndpoint. \n For GlobalNetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; an empty
                                NamespaceSelector implies the Selector applies to workload
                                endpoints across all namespaces.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;nets&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Nets is an optional field that restricts the
                                rule to only apply to traffic that originates from (or
                                terminates at) IP addresses in any of the given subnets.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notNets&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotNets is the negated version of the Nets
                                field.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notPorts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotPorts is the negated version of the Ports
                                field. Since only some protocols have ports&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if any ports
                                are specified it requires the Protocol match in the Rule
                                to be set to &amp;quot;TCP&amp;quot; or &amp;quot;UDP&amp;quot;.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                                &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotSelector is the negated version of the Selector
                                field.  See Selector field for subtleties with negated
                                selectors.
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;ports&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Ports is an optional field that restricts
                                the rule to only apply to traffic that has a source (destination)
                                port that matches one of these ranges/values. This value
                                is a list of integers or strings that represent ranges
                                of ports. \n Since only some protocols have ports&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if
                                any ports are specified it requires the Protocol match
                                in the Rule to be set to \&amp;quot;TCP\&amp;quot; or \&amp;quot;UDP\&amp;quot;.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                                &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Selector is an optional field that contains
                                a selector expression (see Policy for sample syntax).
                                \ Only traffic that originates from (terminates at) endpoints
                                &lt;span class=&quot;token key atrule&quot;&gt;matching the selector will be matched. \n Note that&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; in
                                addition to the negated version of the Selector (see NotSelector
                                below)&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the selector expression syntax itself supports
                                negation.  The two types of negation are subtly different.
                                One negates the set of matched endpoints&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the other negates
                                &lt;span class=&quot;token key atrule&quot;&gt;the whole match&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; \n \tSelector = \&amp;quot;&lt;span class=&quot;token tag&quot;&gt;!has(my_label)&lt;/span&gt;\&amp;quot; matches
                                packets that are from other Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled \tendpoints
                                that do not have the label “my_label”. \n \tNotSelector
                                = \&amp;quot;has(my_label)\&amp;quot; matches packets that are not from
                                Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled \tendpoints that do have the label “my_label”.
                                \n The effect is that the latter will accept packets from
                                non&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Calico sources whereas the former is limited to packets
                                from Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled endpoints.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;serviceAccounts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ServiceAccounts is an optional field that restricts
                                the rule to only apply to traffic that originates from
                                (or terminates at) a pod running as a matching service
                                account.
                              &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Names is an optional field that restricts
                                    the rule to only apply to traffic that originates
                                    from (or terminates at) a pod running as a service
                                    account whose name is in the list.
                                  &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                  &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                                &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Selector is an optional field that restricts
                                    the rule to only apply to traffic that originates
                                    from (or terminates at) a pod running as a service
                                    account that matches the given label selector. If
                                    both Names and Selector are specified then they are
                                    AND&amp;#x27;ed.
                                  &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;http&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; HTTP contains match criteria that apply to HTTP
                            requests.
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;methods&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Methods is an optional field that restricts
                                the rule to apply only to HTTP requests that use one of
                                the listed HTTP Methods (e.g. GET&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; PUT&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; etc.) Multiple
                                methods are OR&amp;#x27;d together.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;paths&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Paths is an optional field that restricts
                                the rule to apply to HTTP requests that use one of the
                                listed HTTP Paths. Multiple paths are OR&amp;#x27;&amp;#x27;d together.
                                &lt;span class=&quot;token key atrule&quot;&gt;e.g&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;exact&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;/foo - prefix&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;/bar NOTE&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Each entry may
                                ONLY specify either a `exact` or a `prefix` match. The
                                validator will check for it.&amp;#x27;
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;HTTPPath specifies an HTTP path to match.
                                  &lt;span class=&quot;token key atrule&quot;&gt;It may be either of the form&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;exact&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;&amp;lt;path&amp;gt;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; which matches
                                  &lt;span class=&quot;token key atrule&quot;&gt;the path exactly or prefix&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;&amp;lt;path-prefix&amp;gt;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; which matches
                                  the path prefix&amp;#x27;
                                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;exact&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                  &lt;span class=&quot;token key atrule&quot;&gt;prefix&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;icmp&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ICMP is an optional field that restricts the rule
                            to apply to a specific type and code of ICMP traffic.  This
                            should only be specified if the Protocol field is set to &amp;quot;ICMP&amp;quot;
                            or &amp;quot;ICMPv6&amp;quot;.
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;code&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Match on a specific ICMP code.  If specified&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                                the Type value must also be specified. This is a technical
                                limitation imposed by the kernel’s iptables firewall&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                                which Calico uses to enforce the rule.
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Match on a specific ICMP type.  For example
                                a value of 8 refers to ICMP Echo Request (i.e. pings).
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;ipVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; IPVersion is an optional field that restricts the
                            rule to only match a specific IP version.
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                        &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Metadata contains additional information for this
                            rule
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;annotations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;additionalProperties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Annotations is a set of key value pairs that
                                give extra information about the rule
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;notICMP&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotICMP is the negated version of the ICMP field.
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;code&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Match on a specific ICMP code.  If specified&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                                the Type value must also be specified. This is a technical
                                limitation imposed by the kernel’s iptables firewall&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                                which Calico uses to enforce the rule.
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Match on a specific ICMP type.  For example
                                a value of 8 refers to ICMP Echo Request (i.e. pings).
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;notProtocol&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotProtocol is the negated version of the Protocol
                            field.
                          &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                          &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;protocol&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Protocol is an optional field that restricts the
                            rule to only apply to traffic of a specific IP protocol. Required
                            if any of the EntityRules contain Ports (because ports only
                            apply to certain protocols). \n Must be one of these string
                            &lt;span class=&quot;token key atrule&quot;&gt;values&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; \&amp;quot;TCP\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;UDP\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;ICMP\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;ICMPv6\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;SCTP\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                            \&amp;quot;UDPLite\&amp;quot; or an integer in the range 1&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;255.&amp;quot;
                          &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                          &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;source&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Source contains the match criteria that apply to
                            source entity.
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;namespaceSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;NamespaceSelector is an optional field that
                                contains a selector expression. Only traffic that originates
                                from (or terminates at) endpoints within the selected
                                namespaces will be matched. When both NamespaceSelector
                                and Selector are defined on the same rule&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; then only workload
                                endpoints that are matched by both selectors will be selected
                                by the rule. \n For NetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; an empty NamespaceSelector
                                implies that the Selector is limited to selecting only
                                workload endpoints in the same namespace as the NetworkPolicy.
                                \n For NetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; `global()` NamespaceSelector implies
                                that the Selector is limited to selecting only GlobalNetworkSet
                                or HostEndpoint. \n For GlobalNetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; an empty
                                NamespaceSelector implies the Selector applies to workload
                                endpoints across all namespaces.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;nets&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Nets is an optional field that restricts the
                                rule to only apply to traffic that originates from (or
                                terminates at) IP addresses in any of the given subnets.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notNets&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotNets is the negated version of the Nets
                                field.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notPorts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotPorts is the negated version of the Ports
                                field. Since only some protocols have ports&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if any ports
                                are specified it requires the Protocol match in the Rule
                                to be set to &amp;quot;TCP&amp;quot; or &amp;quot;UDP&amp;quot;.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                                &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotSelector is the negated version of the Selector
                                field.  See Selector field for subtleties with negated
                                selectors.
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;ports&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Ports is an optional field that restricts
                                the rule to only apply to traffic that has a source (destination)
                                port that matches one of these ranges/values. This value
                                is a list of integers or strings that represent ranges
                                of ports. \n Since only some protocols have ports&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if
                                any ports are specified it requires the Protocol match
                                in the Rule to be set to \&amp;quot;TCP\&amp;quot; or \&amp;quot;UDP\&amp;quot;.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                                &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Selector is an optional field that contains
                                a selector expression (see Policy for sample syntax).
                                \ Only traffic that originates from (terminates at) endpoints
                                &lt;span class=&quot;token key atrule&quot;&gt;matching the selector will be matched. \n Note that&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; in
                                addition to the negated version of the Selector (see NotSelector
                                below)&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the selector expression syntax itself supports
                                negation.  The two types of negation are subtly different.
                                One negates the set of matched endpoints&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the other negates
                                &lt;span class=&quot;token key atrule&quot;&gt;the whole match&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; \n \tSelector = \&amp;quot;&lt;span class=&quot;token tag&quot;&gt;!has(my_label)&lt;/span&gt;\&amp;quot; matches
                                packets that are from other Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled \tendpoints
                                that do not have the label “my_label”. \n \tNotSelector
                                = \&amp;quot;has(my_label)\&amp;quot; matches packets that are not from
                                Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled \tendpoints that do have the label “my_label”.
                                \n The effect is that the latter will accept packets from
                                non&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Calico sources whereas the former is limited to packets
                                from Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled endpoints.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;serviceAccounts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ServiceAccounts is an optional field that restricts
                                the rule to only apply to traffic that originates from
                                (or terminates at) a pod running as a matching service
                                account.
                              &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Names is an optional field that restricts
                                    the rule to only apply to traffic that originates
                                    from (or terminates at) a pod running as a service
                                    account whose name is in the list.
                                  &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                  &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                                &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Selector is an optional field that restricts
                                    the rule to only apply to traffic that originates
                                    from (or terminates at) a pod running as a service
                                    account that matches the given label selector. If
                                    both Names and Selector are specified then they are
                                    AND&amp;#x27;ed.
                                  &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                      &lt;span class=&quot;token key atrule&quot;&gt;required&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; action
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                  &lt;span class=&quot;token key atrule&quot;&gt;namespaceSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NamespaceSelector is an optional field for an expression
                      used to select a pod based on namespaces.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;order&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Order is an optional field that specifies the order in
                      which the policy is applied. Policies with higher &amp;quot;order&amp;quot; are applied
                      after those with lower order.  If the order is omitted&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; it may be
                      considered to be &amp;quot;infinite&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; i.e. the policy will be applied last.  Policies
                      with identical order will be applied in alphanumerical order based
                      on the Policy &amp;quot;Name&amp;quot;.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; number
                  &lt;span class=&quot;token key atrule&quot;&gt;preDNAT&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; PreDNAT indicates to apply the rules in this policy before
                      any DNAT.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;The selector is an expression used to pick pick out
                      the endpoints that the policy should be applied to. \n Selector
                      &lt;span class=&quot;token key atrule&quot;&gt;expressions follow this syntax&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; \n \tlabel == \&amp;quot;string_literal\&amp;quot;
                      \ &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;  comparison&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; e.g. my_label == \&amp;quot;foo bar\&amp;quot; \tlabel &lt;span class=&quot;token tag&quot;&gt;!=&lt;/span&gt; \&amp;quot;string_literal\&amp;quot;
                      \  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;  not equal; also matches if label is not present \tlabel in
                      &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; \&amp;quot;a\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;b\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;c\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;...&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;  true if the value of label X is
                      one of \&amp;quot;a\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;b\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;c\&amp;quot; \tlabel not in &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; \&amp;quot;a\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;b\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;c\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      &lt;span class=&quot;token punctuation&quot;&gt;...&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;  true if the value of label X is not one of \&amp;quot;a\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;b\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      \&amp;quot;c\&amp;quot; \thas(label_name)  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt; True if that label is present \t&lt;span class=&quot;token tag&quot;&gt;!&lt;/span&gt; expr
                      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt; negation of expr \texpr &lt;span class=&quot;token important&quot;&gt;&amp;amp;&amp;amp;&lt;/span&gt; expr  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt; Short&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;circuit and \texpr
                      &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; expr  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt; Short&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;circuit or \t( expr ) &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt; parens for grouping \tall()
                      or the empty selector &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt; matches all endpoints. \n Label names are
                      allowed to contain alphanumerics&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; _ and /. String literals are
                      more permissive but they do not support escape characters. \n Examples
                      &lt;span class=&quot;token key atrule&quot;&gt;(with made-up labels)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; \n \ttype == \&amp;quot;webserver\&amp;quot; &lt;span class=&quot;token important&quot;&gt;&amp;amp;&amp;amp;&lt;/span&gt; deployment
                      == \&amp;quot;prod\&amp;quot; \ttype in &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;\&amp;quot;frontend\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;backend\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt; \tdeployment &lt;span class=&quot;token tag&quot;&gt;!=&lt;/span&gt;
                      \&amp;quot;dev\&amp;quot; \t&lt;span class=&quot;token tag&quot;&gt;!&lt;/span&gt; has(label_name)&amp;quot;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;serviceAccountSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ServiceAccountSelector is an optional field for an expression
                      used to select a pod based on service accounts.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;types&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Types indicates whether this policy applies to ingress&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      or to egress&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; or to both.  When not explicitly specified (and so
                      the value on creation is empty or nil)&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; Calico defaults Types according
                      to what Ingress and Egress rules are present in the policy.  The
                      &lt;span class=&quot;token key atrule&quot;&gt;default is&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; \n &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt; PolicyTypeIngress &lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if there are no Egress rules
                      (including the case where there are   also no Ingress rules) \n
                      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt; PolicyTypeEgress &lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if there are Egress rules but no Ingress
                      rules \n &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt; PolicyTypeIngress&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; PolicyTypeEgress &lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if there are
                      both Ingress and Egress rules. \n When the policy is read back again&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      Types will always be one of these values&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; never empty or nil.&amp;quot;
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; PolicyType enumerates the possible values of the PolicySpec
                        Types field.
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
        &lt;span class=&quot;token key atrule&quot;&gt;served&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;storage&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;status&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;acceptedNames&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;conditions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;storedVersions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; apiextensions.k8s.io/v1
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CustomResourceDefinition
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;annotations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;controller-gen.kubebuilder.io/version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; (devel)
      &lt;span class=&quot;token key atrule&quot;&gt;creationTimestamp&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token null important&quot;&gt;null&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; globalnetworksets.crd.projectcalico.org
    &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;group&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; crd.projectcalico.org
      &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; GlobalNetworkSet
        &lt;span class=&quot;token key atrule&quot;&gt;listKind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; GlobalNetworkSetList
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; globalnetworksets
        &lt;span class=&quot;token key atrule&quot;&gt;singular&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; globalnetworkset
      &lt;span class=&quot;token key atrule&quot;&gt;scope&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Cluster
      &lt;span class=&quot;token key atrule&quot;&gt;versions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; v1
        &lt;span class=&quot;token key atrule&quot;&gt;schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;openAPIV3Schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; GlobalNetworkSet contains a set of arbitrary IP sub&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;networks/CIDRs
              that share labels to allow rules to refer to them via selectors.  The labels
              of GlobalNetworkSet are not namespaced.
            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;APIVersion defines the versioned schema of this representation
                  of an object. Servers should convert recognized schemas to the latest
                  internal value&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;and may reject unrecognized values. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#resources&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Kind is a string value representing the REST resource this
                  object represents. Servers may infer this from the endpoint the client
                  &lt;span class=&quot;token key atrule&quot;&gt;submits requests to. Cannot be updated. In CamelCase. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#types-kinds&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
              &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; GlobalNetworkSetSpec contains the specification for a NetworkSet
                  resource.
                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;nets&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; The list of IP networks that belong to this set.
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
        &lt;span class=&quot;token key atrule&quot;&gt;served&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;storage&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;status&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;acceptedNames&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;conditions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;storedVersions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; apiextensions.k8s.io/v1
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CustomResourceDefinition
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;annotations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;controller-gen.kubebuilder.io/version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; (devel)
      &lt;span class=&quot;token key atrule&quot;&gt;creationTimestamp&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token null important&quot;&gt;null&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; hostendpoints.crd.projectcalico.org
    &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;group&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; crd.projectcalico.org
      &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; HostEndpoint
        &lt;span class=&quot;token key atrule&quot;&gt;listKind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; HostEndpointList
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; hostendpoints
        &lt;span class=&quot;token key atrule&quot;&gt;singular&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; hostendpoint
      &lt;span class=&quot;token key atrule&quot;&gt;scope&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Cluster
      &lt;span class=&quot;token key atrule&quot;&gt;versions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; v1
        &lt;span class=&quot;token key atrule&quot;&gt;schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;openAPIV3Schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;APIVersion defines the versioned schema of this representation
                  of an object. Servers should convert recognized schemas to the latest
                  internal value&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;and may reject unrecognized values. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#resources&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Kind is a string value representing the REST resource this
                  object represents. Servers may infer this from the endpoint the client
                  &lt;span class=&quot;token key atrule&quot;&gt;submits requests to. Cannot be updated. In CamelCase. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#types-kinds&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
              &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; HostEndpointSpec contains the specification for a HostEndpoint
                  resource.
                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;expectedIPs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;The expected IP addresses (IPv4 and IPv6) of the endpoint.
                      If \&amp;quot;InterfaceName\&amp;quot; is not present&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; Calico will look for an interface
                      &lt;span class=&quot;token key atrule&quot;&gt;matching any of the IPs in the list and apply policy to that. Note&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      \tWhen using the selector match criteria in an ingress or egress
                      security Policy \tor Profile&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; Calico converts the selector into
                      a set of IP addresses. For host \tendpoints&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the ExpectedIPs field
                      is used for that purpose. (If only the interface \tname is specified&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      Calico does not learn the IPs of the interface for use in match
                      \tcriteria.)&amp;quot;
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                  &lt;span class=&quot;token key atrule&quot;&gt;interfaceName&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Either \&amp;quot;&lt;span class=&quot;token important&quot;&gt;*\&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; or the name of a specific Linux interface
                      to apply policy to; or empty.  \&amp;quot;&lt;span class=&quot;token important&quot;&gt;*\&amp;quot;&lt;/span&gt; indicates that this HostEndpoint
                      governs all traffic to&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; from or through the default network namespace
                      of the host named by the \&amp;quot;Node\&amp;quot; field; entering and leaving that
                      namespace via any interface&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; including those from/to non&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;host&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;networked
                      local workloads. \n If InterfaceName is not \&amp;quot;&lt;span class=&quot;token important&quot;&gt;*\&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; this HostEndpoint
                      only governs traffic that enters or leaves the host through the
                      specific interface named by InterfaceName&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; or &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; when InterfaceName
                      is empty &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; through the specific interface that has one of the IPs
                      in ExpectedIPs. Therefore&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; when InterfaceName is empty&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; at least
                      one expected IP must be specified.  Only external interfaces (such
                      as “eth0”) are supported here; it isn&amp;#x27;t possible for a HostEndpoint
                      to protect traffic through a specific local workload interface.
                      &lt;span class=&quot;token key atrule&quot;&gt;\n Note&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Only some kinds of policy are implemented for \&amp;quot;&lt;span class=&quot;token important&quot;&gt;*\&amp;quot;&lt;/span&gt; HostEndpoints;
                      initially just pre&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;DNAT policy.  Please check Calico documentation
                      for the latest position.&amp;quot;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;node&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; The node name identifying the Calico node instance.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;ports&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Ports contains the endpoint&amp;#x27;s named ports&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; which may
                      be referenced in security policy rules.
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                        &lt;span class=&quot;token key atrule&quot;&gt;port&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                        &lt;span class=&quot;token key atrule&quot;&gt;protocol&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                          &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                          &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;required&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; name
                      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; port
                      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; protocol
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                  &lt;span class=&quot;token key atrule&quot;&gt;profiles&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; A list of identifiers of security Profile objects that
                      apply to this endpoint. Each profile is applied in the order that
                      they appear in this list.  Profile rules are applied after the selector&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;based
                      security policy.
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
        &lt;span class=&quot;token key atrule&quot;&gt;served&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;storage&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;status&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;acceptedNames&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;conditions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;storedVersions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; apiextensions.k8s.io/v1
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CustomResourceDefinition
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;annotations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;controller-gen.kubebuilder.io/version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; (devel)
      &lt;span class=&quot;token key atrule&quot;&gt;creationTimestamp&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token null important&quot;&gt;null&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ipamblocks.crd.projectcalico.org
    &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;group&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; crd.projectcalico.org
      &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; IPAMBlock
        &lt;span class=&quot;token key atrule&quot;&gt;listKind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; IPAMBlockList
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ipamblocks
        &lt;span class=&quot;token key atrule&quot;&gt;singular&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ipamblock
      &lt;span class=&quot;token key atrule&quot;&gt;scope&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Cluster
      &lt;span class=&quot;token key atrule&quot;&gt;versions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; v1
        &lt;span class=&quot;token key atrule&quot;&gt;schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;openAPIV3Schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;APIVersion defines the versioned schema of this representation
                  of an object. Servers should convert recognized schemas to the latest
                  internal value&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;and may reject unrecognized values. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#resources&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Kind is a string value representing the REST resource this
                  object represents. Servers may infer this from the endpoint the client
                  &lt;span class=&quot;token key atrule&quot;&gt;submits requests to. Cannot be updated. In CamelCase. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#types-kinds&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
              &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; IPAMBlockSpec contains the specification for an IPAMBlock
                  resource.
                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;affinity&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;allocations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                      &lt;span class=&quot;token comment&quot;&gt;# TODO: This nullable is manually added in. We should update controller-gen&lt;/span&gt;
                      &lt;span class=&quot;token comment&quot;&gt;# to handle []*int properly itself.&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;nullable&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                  &lt;span class=&quot;token key atrule&quot;&gt;attributes&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;handle_id&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                        &lt;span class=&quot;token key atrule&quot;&gt;secondary&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;additionalProperties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                  &lt;span class=&quot;token key atrule&quot;&gt;cidr&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;deleted&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;strictAffinity&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;unallocated&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                &lt;span class=&quot;token key atrule&quot;&gt;required&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; allocations
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; attributes
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; cidr
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; deleted
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; strictAffinity
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; unallocated
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
        &lt;span class=&quot;token key atrule&quot;&gt;served&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;storage&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;status&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;acceptedNames&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;conditions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;storedVersions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; apiextensions.k8s.io/v1
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CustomResourceDefinition
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;annotations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;controller-gen.kubebuilder.io/version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; (devel)
      &lt;span class=&quot;token key atrule&quot;&gt;creationTimestamp&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token null important&quot;&gt;null&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ipamconfigs.crd.projectcalico.org
    &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;group&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; crd.projectcalico.org
      &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; IPAMConfig
        &lt;span class=&quot;token key atrule&quot;&gt;listKind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; IPAMConfigList
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ipamconfigs
        &lt;span class=&quot;token key atrule&quot;&gt;singular&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ipamconfig
      &lt;span class=&quot;token key atrule&quot;&gt;scope&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Cluster
      &lt;span class=&quot;token key atrule&quot;&gt;versions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; v1
        &lt;span class=&quot;token key atrule&quot;&gt;schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;openAPIV3Schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;APIVersion defines the versioned schema of this representation
                  of an object. Servers should convert recognized schemas to the latest
                  internal value&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;and may reject unrecognized values. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#resources&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Kind is a string value representing the REST resource this
                  object represents. Servers may infer this from the endpoint the client
                  &lt;span class=&quot;token key atrule&quot;&gt;submits requests to. Cannot be updated. In CamelCase. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#types-kinds&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
              &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; IPAMConfigSpec contains the specification for an IPAMConfig
                  resource.
                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;autoAllocateBlocks&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;strictAffinity&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                &lt;span class=&quot;token key atrule&quot;&gt;required&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; autoAllocateBlocks
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; strictAffinity
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
        &lt;span class=&quot;token key atrule&quot;&gt;served&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;storage&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;status&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;acceptedNames&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;conditions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;storedVersions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; apiextensions.k8s.io/v1
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CustomResourceDefinition
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;annotations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;controller-gen.kubebuilder.io/version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; (devel)
      &lt;span class=&quot;token key atrule&quot;&gt;creationTimestamp&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token null important&quot;&gt;null&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ipamhandles.crd.projectcalico.org
    &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;group&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; crd.projectcalico.org
      &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; IPAMHandle
        &lt;span class=&quot;token key atrule&quot;&gt;listKind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; IPAMHandleList
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ipamhandles
        &lt;span class=&quot;token key atrule&quot;&gt;singular&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ipamhandle
      &lt;span class=&quot;token key atrule&quot;&gt;scope&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Cluster
      &lt;span class=&quot;token key atrule&quot;&gt;versions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; v1
        &lt;span class=&quot;token key atrule&quot;&gt;schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;openAPIV3Schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;APIVersion defines the versioned schema of this representation
                  of an object. Servers should convert recognized schemas to the latest
                  internal value&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;and may reject unrecognized values. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#resources&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Kind is a string value representing the REST resource this
                  object represents. Servers may infer this from the endpoint the client
                  &lt;span class=&quot;token key atrule&quot;&gt;submits requests to. Cannot be updated. In CamelCase. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#types-kinds&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
              &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; IPAMHandleSpec contains the specification for an IPAMHandle
                  resource.
                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;block&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;additionalProperties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                  &lt;span class=&quot;token key atrule&quot;&gt;handleID&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                &lt;span class=&quot;token key atrule&quot;&gt;required&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; block
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; handleID
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
        &lt;span class=&quot;token key atrule&quot;&gt;served&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;storage&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;status&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;acceptedNames&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;conditions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;storedVersions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; apiextensions.k8s.io/v1
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CustomResourceDefinition
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;annotations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;controller-gen.kubebuilder.io/version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; (devel)
      &lt;span class=&quot;token key atrule&quot;&gt;creationTimestamp&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token null important&quot;&gt;null&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ippools.crd.projectcalico.org
    &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;group&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; crd.projectcalico.org
      &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; IPPool
        &lt;span class=&quot;token key atrule&quot;&gt;listKind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; IPPoolList
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ippools
        &lt;span class=&quot;token key atrule&quot;&gt;singular&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ippool
      &lt;span class=&quot;token key atrule&quot;&gt;scope&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Cluster
      &lt;span class=&quot;token key atrule&quot;&gt;versions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; v1
        &lt;span class=&quot;token key atrule&quot;&gt;schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;openAPIV3Schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;APIVersion defines the versioned schema of this representation
                  of an object. Servers should convert recognized schemas to the latest
                  internal value&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;and may reject unrecognized values. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#resources&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Kind is a string value representing the REST resource this
                  object represents. Servers may infer this from the endpoint the client
                  &lt;span class=&quot;token key atrule&quot;&gt;submits requests to. Cannot be updated. In CamelCase. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#types-kinds&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
              &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; IPPoolSpec contains the specification for an IPPool resource.
                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;blockSize&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; The block size to use for IP address assignments from
                      this pool. Defaults to 26 for IPv4 and 112 for IPv6.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                  &lt;span class=&quot;token key atrule&quot;&gt;cidr&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; The pool CIDR.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;disabled&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; When disabled is true&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; Calico IPAM will not assign addresses
                      from this pool.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;ipip&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Deprecated&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; this field is only used for APIv1 backwards
                      compatibility. Setting this field is not allowed&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; this field is
                      for internal use only.&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;enabled&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; When enabled is true&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; ipip tunneling will be used
                          to deliver packets to destinations within this pool.
                        &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                      &lt;span class=&quot;token key atrule&quot;&gt;mode&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; The IPIP mode.  This can be one of &amp;quot;always&amp;quot; or &amp;quot;cross&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;subnet&amp;quot;.  A
                          mode of &amp;quot;always&amp;quot; will also use IPIP tunneling for routing to
                          destination IP addresses within this pool.  A mode of &amp;quot;cross&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;subnet&amp;quot;
                          will only use IPIP tunneling when the destination node is on
                          a different subnet to the originating node.  The default value
                          (if not specified) is &amp;quot;always&amp;quot;.
                        &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                  &lt;span class=&quot;token key atrule&quot;&gt;ipipMode&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Contains configuration for IPIP tunneling for this pool.
                      If not specified&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; then this is defaulted to &amp;quot;Never&amp;quot; (i.e. IPIP tunneling
                      is disabled).
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;nat-outgoing&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Deprecated&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; this field is only used for APIv1 backwards
                      compatibility. Setting this field is not allowed&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; this field is
                      for internal use only.&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;natOutgoing&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; When nat&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;outgoing is true&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; packets sent from Calico networked
                      containers in this pool to destinations outside of this pool will
                      be masqueraded.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;nodeSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Allows IPPool to allocate for a specific node by label
                      selector.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;vxlanMode&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Contains configuration for VXLAN tunneling for this pool.
                      If not specified&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; then this is defaulted to &amp;quot;Never&amp;quot; (i.e. VXLAN
                      tunneling is disabled).
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                &lt;span class=&quot;token key atrule&quot;&gt;required&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; cidr
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
        &lt;span class=&quot;token key atrule&quot;&gt;served&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;storage&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;status&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;acceptedNames&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;conditions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;storedVersions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; apiextensions.k8s.io/v1
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CustomResourceDefinition
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;annotations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;controller-gen.kubebuilder.io/version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; (devel)
      &lt;span class=&quot;token key atrule&quot;&gt;creationTimestamp&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token null important&quot;&gt;null&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; kubecontrollersconfigurations.crd.projectcalico.org
    &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;group&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; crd.projectcalico.org
      &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; KubeControllersConfiguration
        &lt;span class=&quot;token key atrule&quot;&gt;listKind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; KubeControllersConfigurationList
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; kubecontrollersconfigurations
        &lt;span class=&quot;token key atrule&quot;&gt;singular&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; kubecontrollersconfiguration
      &lt;span class=&quot;token key atrule&quot;&gt;scope&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Cluster
      &lt;span class=&quot;token key atrule&quot;&gt;versions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; v1
        &lt;span class=&quot;token key atrule&quot;&gt;schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;openAPIV3Schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;APIVersion defines the versioned schema of this representation
                  of an object. Servers should convert recognized schemas to the latest
                  internal value&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;and may reject unrecognized values. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#resources&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Kind is a string value representing the REST resource this
                  object represents. Servers may infer this from the endpoint the client
                  &lt;span class=&quot;token key atrule&quot;&gt;submits requests to. Cannot be updated. In CamelCase. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#types-kinds&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
              &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; KubeControllersConfigurationSpec contains the values of the
                  Kubernetes controllers configuration.
                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;controllers&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Controllers enables and configures individual Kubernetes
                      controllers
                    &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;namespace&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Namespace enables and configures the namespace controller.
                          Enabled by default&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; set to nil to disable.
                        &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;reconcilerPeriod&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;ReconcilerPeriod is the period to perform reconciliation
                              with the Calico datastore. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 5m&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                        &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                      &lt;span class=&quot;token key atrule&quot;&gt;node&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Node enables and configures the node controller.
                          Enabled by default&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; set to nil to disable.
                        &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;hostEndpoint&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; HostEndpoint controls syncing nodes to host endpoints.
                              Disabled by default&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; set to nil to disable.
                            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;autoCreate&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;AutoCreate enables automatic creation of
                                  host endpoints for every node. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Disabled&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                          &lt;span class=&quot;token key atrule&quot;&gt;reconcilerPeriod&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;ReconcilerPeriod is the period to perform reconciliation
                              with the Calico datastore. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 5m&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                          &lt;span class=&quot;token key atrule&quot;&gt;syncLabels&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;SyncLabels controls whether to copy Kubernetes
                              node labels to Calico nodes. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Enabled&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                        &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                      &lt;span class=&quot;token key atrule&quot;&gt;policy&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Policy enables and configures the policy controller.
                          Enabled by default&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; set to nil to disable.
                        &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;reconcilerPeriod&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;ReconcilerPeriod is the period to perform reconciliation
                              with the Calico datastore. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 5m&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                        &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                      &lt;span class=&quot;token key atrule&quot;&gt;serviceAccount&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ServiceAccount enables and configures the service
                          account controller. Enabled by default&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; set to nil to disable.
                        &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;reconcilerPeriod&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;ReconcilerPeriod is the period to perform reconciliation
                              with the Calico datastore. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 5m&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                        &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                      &lt;span class=&quot;token key atrule&quot;&gt;workloadEndpoint&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; WorkloadEndpoint enables and configures the workload
                          endpoint controller. Enabled by default&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; set to nil to disable.
                        &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;reconcilerPeriod&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;ReconcilerPeriod is the period to perform reconciliation
                              with the Calico datastore. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 5m&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                        &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                  &lt;span class=&quot;token key atrule&quot;&gt;etcdV3CompactionPeriod&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;EtcdV3CompactionPeriod is the period between etcdv3
                      compaction requests. Set to 0 to disable. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 10m&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;healthChecks&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;HealthChecks enables or disables support for health
                      checks &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Enabled&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;logSeverityScreen&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;LogSeverityScreen is the log severity above which logs
                      are sent to the stdout. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Info&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                &lt;span class=&quot;token key atrule&quot;&gt;required&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; controllers
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
              &lt;span class=&quot;token key atrule&quot;&gt;status&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; KubeControllersConfigurationStatus represents the status
                  of the configuration. It&amp;#x27;s useful for admins to be able to see the actual
                  config that was applied&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; which can be modified by environment variables
                  on the kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controllers process.
                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;environmentVars&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;additionalProperties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; EnvironmentVars contains the environment variables on
                      the kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controllers that influenced the RunningConfig.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                  &lt;span class=&quot;token key atrule&quot;&gt;runningConfig&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; RunningConfig contains the effective config that is running
                      in the kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controllers pod&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; after merging the API resource with
                      any environment variables.
                    &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;controllers&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Controllers enables and configures individual Kubernetes
                          controllers
                        &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;namespace&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Namespace enables and configures the namespace
                              controller. Enabled by default&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; set to nil to disable.
                            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;reconcilerPeriod&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;ReconcilerPeriod is the period to perform
                                  reconciliation with the Calico datastore. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  5m&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                          &lt;span class=&quot;token key atrule&quot;&gt;node&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Node enables and configures the node controller.
                              Enabled by default&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; set to nil to disable.
                            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;hostEndpoint&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; HostEndpoint controls syncing nodes to host
                                  endpoints. Disabled by default&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; set to nil to disable.
                                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;autoCreate&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;AutoCreate enables automatic creation
                                      of host endpoints for every node. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Disabled&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                              &lt;span class=&quot;token key atrule&quot;&gt;reconcilerPeriod&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;ReconcilerPeriod is the period to perform
                                  reconciliation with the Calico datastore. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  5m&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;syncLabels&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;SyncLabels controls whether to copy Kubernetes
                                  node labels to Calico nodes. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Enabled&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                          &lt;span class=&quot;token key atrule&quot;&gt;policy&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Policy enables and configures the policy controller.
                              Enabled by default&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; set to nil to disable.
                            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;reconcilerPeriod&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;ReconcilerPeriod is the period to perform
                                  reconciliation with the Calico datastore. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  5m&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                          &lt;span class=&quot;token key atrule&quot;&gt;serviceAccount&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ServiceAccount enables and configures the service
                              account controller. Enabled by default&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; set to nil to disable.
                            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;reconcilerPeriod&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;ReconcilerPeriod is the period to perform
                                  reconciliation with the Calico datastore. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  5m&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                          &lt;span class=&quot;token key atrule&quot;&gt;workloadEndpoint&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; WorkloadEndpoint enables and configures the workload
                              endpoint controller. Enabled by default&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; set to nil to disable.
                            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;reconcilerPeriod&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;ReconcilerPeriod is the period to perform
                                  reconciliation with the Calico datastore. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  5m&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                      &lt;span class=&quot;token key atrule&quot;&gt;etcdV3CompactionPeriod&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;EtcdV3CompactionPeriod is the period between etcdv3
                          compaction requests. Set to 0 to disable. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 10m&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                        &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                      &lt;span class=&quot;token key atrule&quot;&gt;healthChecks&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;HealthChecks enables or disables support for health
                          checks &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Enabled&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                        &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                      &lt;span class=&quot;token key atrule&quot;&gt;logSeverityScreen&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;LogSeverityScreen is the log severity above which
                          logs are sent to the stdout. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Info&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                        &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                    &lt;span class=&quot;token key atrule&quot;&gt;required&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; controllers
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
        &lt;span class=&quot;token key atrule&quot;&gt;served&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;storage&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;status&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;acceptedNames&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;conditions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;storedVersions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; apiextensions.k8s.io/v1
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CustomResourceDefinition
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;annotations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;controller-gen.kubebuilder.io/version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; (devel)
      &lt;span class=&quot;token key atrule&quot;&gt;creationTimestamp&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token null important&quot;&gt;null&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; networkpolicies.crd.projectcalico.org
    &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;group&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; crd.projectcalico.org
      &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NetworkPolicy
        &lt;span class=&quot;token key atrule&quot;&gt;listKind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NetworkPolicyList
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; networkpolicies
        &lt;span class=&quot;token key atrule&quot;&gt;singular&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; networkpolicy
      &lt;span class=&quot;token key atrule&quot;&gt;scope&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Namespaced
      &lt;span class=&quot;token key atrule&quot;&gt;versions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; v1
        &lt;span class=&quot;token key atrule&quot;&gt;schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;openAPIV3Schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;APIVersion defines the versioned schema of this representation
                  of an object. Servers should convert recognized schemas to the latest
                  internal value&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;and may reject unrecognized values. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#resources&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Kind is a string value representing the REST resource this
                  object represents. Servers may infer this from the endpoint the client
                  &lt;span class=&quot;token key atrule&quot;&gt;submits requests to. Cannot be updated. In CamelCase. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#types-kinds&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
              &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;egress&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; The ordered set of egress rules.  Each rule contains
                      a set of packet match criteria and a corresponding action to apply.
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;A Rule encapsulates a set of match criteria and an
                        action.  Both selector&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;based security Policy and security Profiles
                        reference rules &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; separated out as a list of rules for both ingress
                        and egress packet matching. \n Each positive match criteria has
                        a negated version&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; prefixed with ”Not”. All the match criteria
                        within a rule must be satisfied for a packet to match. A single
                        rule can contain the positive and negative version of a match
                        and both must be satisfied for the rule to match.&amp;quot;
                      &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;action&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                        &lt;span class=&quot;token key atrule&quot;&gt;destination&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Destination contains the match criteria that apply
                            to destination entity.
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;namespaceSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;NamespaceSelector is an optional field that
                                contains a selector expression. Only traffic that originates
                                from (or terminates at) endpoints within the selected
                                namespaces will be matched. When both NamespaceSelector
                                and Selector are defined on the same rule&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; then only workload
                                endpoints that are matched by both selectors will be selected
                                by the rule. \n For NetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; an empty NamespaceSelector
                                implies that the Selector is limited to selecting only
                                workload endpoints in the same namespace as the NetworkPolicy.
                                \n For NetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; `global()` NamespaceSelector implies
                                that the Selector is limited to selecting only GlobalNetworkSet
                                or HostEndpoint. \n For GlobalNetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; an empty
                                NamespaceSelector implies the Selector applies to workload
                                endpoints across all namespaces.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;nets&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Nets is an optional field that restricts the
                                rule to only apply to traffic that originates from (or
                                terminates at) IP addresses in any of the given subnets.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notNets&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotNets is the negated version of the Nets
                                field.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notPorts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotPorts is the negated version of the Ports
                                field. Since only some protocols have ports&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if any ports
                                are specified it requires the Protocol match in the Rule
                                to be set to &amp;quot;TCP&amp;quot; or &amp;quot;UDP&amp;quot;.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                                &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotSelector is the negated version of the Selector
                                field.  See Selector field for subtleties with negated
                                selectors.
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;ports&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Ports is an optional field that restricts
                                the rule to only apply to traffic that has a source (destination)
                                port that matches one of these ranges/values. This value
                                is a list of integers or strings that represent ranges
                                of ports. \n Since only some protocols have ports&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if
                                any ports are specified it requires the Protocol match
                                in the Rule to be set to \&amp;quot;TCP\&amp;quot; or \&amp;quot;UDP\&amp;quot;.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                                &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Selector is an optional field that contains
                                a selector expression (see Policy for sample syntax).
                                \ Only traffic that originates from (terminates at) endpoints
                                &lt;span class=&quot;token key atrule&quot;&gt;matching the selector will be matched. \n Note that&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; in
                                addition to the negated version of the Selector (see NotSelector
                                below)&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the selector expression syntax itself supports
                                negation.  The two types of negation are subtly different.
                                One negates the set of matched endpoints&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the other negates
                                &lt;span class=&quot;token key atrule&quot;&gt;the whole match&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; \n \tSelector = \&amp;quot;&lt;span class=&quot;token tag&quot;&gt;!has(my_label)&lt;/span&gt;\&amp;quot; matches
                                packets that are from other Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled \tendpoints
                                that do not have the label “my_label”. \n \tNotSelector
                                = \&amp;quot;has(my_label)\&amp;quot; matches packets that are not from
                                Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled \tendpoints that do have the label “my_label”.
                                \n The effect is that the latter will accept packets from
                                non&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Calico sources whereas the former is limited to packets
                                from Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled endpoints.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;serviceAccounts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ServiceAccounts is an optional field that restricts
                                the rule to only apply to traffic that originates from
                                (or terminates at) a pod running as a matching service
                                account.
                              &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Names is an optional field that restricts
                                    the rule to only apply to traffic that originates
                                    from (or terminates at) a pod running as a service
                                    account whose name is in the list.
                                  &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                  &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                                &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Selector is an optional field that restricts
                                    the rule to only apply to traffic that originates
                                    from (or terminates at) a pod running as a service
                                    account that matches the given label selector. If
                                    both Names and Selector are specified then they are
                                    AND&amp;#x27;ed.
                                  &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;http&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; HTTP contains match criteria that apply to HTTP
                            requests.
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;methods&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Methods is an optional field that restricts
                                the rule to apply only to HTTP requests that use one of
                                the listed HTTP Methods (e.g. GET&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; PUT&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; etc.) Multiple
                                methods are OR&amp;#x27;d together.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;paths&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Paths is an optional field that restricts
                                the rule to apply to HTTP requests that use one of the
                                listed HTTP Paths. Multiple paths are OR&amp;#x27;&amp;#x27;d together.
                                &lt;span class=&quot;token key atrule&quot;&gt;e.g&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;exact&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;/foo - prefix&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;/bar NOTE&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Each entry may
                                ONLY specify either a `exact` or a `prefix` match. The
                                validator will check for it.&amp;#x27;
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;HTTPPath specifies an HTTP path to match.
                                  &lt;span class=&quot;token key atrule&quot;&gt;It may be either of the form&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;exact&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;&amp;lt;path&amp;gt;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; which matches
                                  &lt;span class=&quot;token key atrule&quot;&gt;the path exactly or prefix&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;&amp;lt;path-prefix&amp;gt;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; which matches
                                  the path prefix&amp;#x27;
                                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;exact&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                  &lt;span class=&quot;token key atrule&quot;&gt;prefix&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;icmp&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ICMP is an optional field that restricts the rule
                            to apply to a specific type and code of ICMP traffic.  This
                            should only be specified if the Protocol field is set to &amp;quot;ICMP&amp;quot;
                            or &amp;quot;ICMPv6&amp;quot;.
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;code&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Match on a specific ICMP code.  If specified&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                                the Type value must also be specified. This is a technical
                                limitation imposed by the kernel’s iptables firewall&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                                which Calico uses to enforce the rule.
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Match on a specific ICMP type.  For example
                                a value of 8 refers to ICMP Echo Request (i.e. pings).
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;ipVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; IPVersion is an optional field that restricts the
                            rule to only match a specific IP version.
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                        &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Metadata contains additional information for this
                            rule
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;annotations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;additionalProperties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Annotations is a set of key value pairs that
                                give extra information about the rule
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;notICMP&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotICMP is the negated version of the ICMP field.
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;code&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Match on a specific ICMP code.  If specified&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                                the Type value must also be specified. This is a technical
                                limitation imposed by the kernel’s iptables firewall&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                                which Calico uses to enforce the rule.
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Match on a specific ICMP type.  For example
                                a value of 8 refers to ICMP Echo Request (i.e. pings).
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;notProtocol&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotProtocol is the negated version of the Protocol
                            field.
                          &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                          &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;protocol&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Protocol is an optional field that restricts the
                            rule to only apply to traffic of a specific IP protocol. Required
                            if any of the EntityRules contain Ports (because ports only
                            apply to certain protocols). \n Must be one of these string
                            &lt;span class=&quot;token key atrule&quot;&gt;values&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; \&amp;quot;TCP\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;UDP\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;ICMP\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;ICMPv6\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;SCTP\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                            \&amp;quot;UDPLite\&amp;quot; or an integer in the range 1&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;255.&amp;quot;
                          &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                          &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;source&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Source contains the match criteria that apply to
                            source entity.
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;namespaceSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;NamespaceSelector is an optional field that
                                contains a selector expression. Only traffic that originates
                                from (or terminates at) endpoints within the selected
                                namespaces will be matched. When both NamespaceSelector
                                and Selector are defined on the same rule&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; then only workload
                                endpoints that are matched by both selectors will be selected
                                by the rule. \n For NetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; an empty NamespaceSelector
                                implies that the Selector is limited to selecting only
                                workload endpoints in the same namespace as the NetworkPolicy.
                                \n For NetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; `global()` NamespaceSelector implies
                                that the Selector is limited to selecting only GlobalNetworkSet
                                or HostEndpoint. \n For GlobalNetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; an empty
                                NamespaceSelector implies the Selector applies to workload
                                endpoints across all namespaces.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;nets&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Nets is an optional field that restricts the
                                rule to only apply to traffic that originates from (or
                                terminates at) IP addresses in any of the given subnets.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notNets&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotNets is the negated version of the Nets
                                field.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notPorts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotPorts is the negated version of the Ports
                                field. Since only some protocols have ports&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if any ports
                                are specified it requires the Protocol match in the Rule
                                to be set to &amp;quot;TCP&amp;quot; or &amp;quot;UDP&amp;quot;.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                                &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotSelector is the negated version of the Selector
                                field.  See Selector field for subtleties with negated
                                selectors.
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;ports&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Ports is an optional field that restricts
                                the rule to only apply to traffic that has a source (destination)
                                port that matches one of these ranges/values. This value
                                is a list of integers or strings that represent ranges
                                of ports. \n Since only some protocols have ports&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if
                                any ports are specified it requires the Protocol match
                                in the Rule to be set to \&amp;quot;TCP\&amp;quot; or \&amp;quot;UDP\&amp;quot;.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                                &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Selector is an optional field that contains
                                a selector expression (see Policy for sample syntax).
                                \ Only traffic that originates from (terminates at) endpoints
                                &lt;span class=&quot;token key atrule&quot;&gt;matching the selector will be matched. \n Note that&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; in
                                addition to the negated version of the Selector (see NotSelector
                                below)&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the selector expression syntax itself supports
                                negation.  The two types of negation are subtly different.
                                One negates the set of matched endpoints&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the other negates
                                &lt;span class=&quot;token key atrule&quot;&gt;the whole match&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; \n \tSelector = \&amp;quot;&lt;span class=&quot;token tag&quot;&gt;!has(my_label)&lt;/span&gt;\&amp;quot; matches
                                packets that are from other Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled \tendpoints
                                that do not have the label “my_label”. \n \tNotSelector
                                = \&amp;quot;has(my_label)\&amp;quot; matches packets that are not from
                                Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled \tendpoints that do have the label “my_label”.
                                \n The effect is that the latter will accept packets from
                                non&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Calico sources whereas the former is limited to packets
                                from Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled endpoints.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;serviceAccounts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ServiceAccounts is an optional field that restricts
                                the rule to only apply to traffic that originates from
                                (or terminates at) a pod running as a matching service
                                account.
                              &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Names is an optional field that restricts
                                    the rule to only apply to traffic that originates
                                    from (or terminates at) a pod running as a service
                                    account whose name is in the list.
                                  &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                  &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                                &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Selector is an optional field that restricts
                                    the rule to only apply to traffic that originates
                                    from (or terminates at) a pod running as a service
                                    account that matches the given label selector. If
                                    both Names and Selector are specified then they are
                                    AND&amp;#x27;ed.
                                  &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                      &lt;span class=&quot;token key atrule&quot;&gt;required&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; action
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                  &lt;span class=&quot;token key atrule&quot;&gt;ingress&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; The ordered set of ingress rules.  Each rule contains
                      a set of packet match criteria and a corresponding action to apply.
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;A Rule encapsulates a set of match criteria and an
                        action.  Both selector&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;based security Policy and security Profiles
                        reference rules &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; separated out as a list of rules for both ingress
                        and egress packet matching. \n Each positive match criteria has
                        a negated version&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; prefixed with ”Not”. All the match criteria
                        within a rule must be satisfied for a packet to match. A single
                        rule can contain the positive and negative version of a match
                        and both must be satisfied for the rule to match.&amp;quot;
                      &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;action&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                        &lt;span class=&quot;token key atrule&quot;&gt;destination&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Destination contains the match criteria that apply
                            to destination entity.
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;namespaceSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;NamespaceSelector is an optional field that
                                contains a selector expression. Only traffic that originates
                                from (or terminates at) endpoints within the selected
                                namespaces will be matched. When both NamespaceSelector
                                and Selector are defined on the same rule&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; then only workload
                                endpoints that are matched by both selectors will be selected
                                by the rule. \n For NetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; an empty NamespaceSelector
                                implies that the Selector is limited to selecting only
                                workload endpoints in the same namespace as the NetworkPolicy.
                                \n For NetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; `global()` NamespaceSelector implies
                                that the Selector is limited to selecting only GlobalNetworkSet
                                or HostEndpoint. \n For GlobalNetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; an empty
                                NamespaceSelector implies the Selector applies to workload
                                endpoints across all namespaces.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;nets&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Nets is an optional field that restricts the
                                rule to only apply to traffic that originates from (or
                                terminates at) IP addresses in any of the given subnets.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notNets&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotNets is the negated version of the Nets
                                field.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notPorts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotPorts is the negated version of the Ports
                                field. Since only some protocols have ports&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if any ports
                                are specified it requires the Protocol match in the Rule
                                to be set to &amp;quot;TCP&amp;quot; or &amp;quot;UDP&amp;quot;.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                                &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotSelector is the negated version of the Selector
                                field.  See Selector field for subtleties with negated
                                selectors.
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;ports&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Ports is an optional field that restricts
                                the rule to only apply to traffic that has a source (destination)
                                port that matches one of these ranges/values. This value
                                is a list of integers or strings that represent ranges
                                of ports. \n Since only some protocols have ports&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if
                                any ports are specified it requires the Protocol match
                                in the Rule to be set to \&amp;quot;TCP\&amp;quot; or \&amp;quot;UDP\&amp;quot;.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                                &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Selector is an optional field that contains
                                a selector expression (see Policy for sample syntax).
                                \ Only traffic that originates from (terminates at) endpoints
                                &lt;span class=&quot;token key atrule&quot;&gt;matching the selector will be matched. \n Note that&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; in
                                addition to the negated version of the Selector (see NotSelector
                                below)&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the selector expression syntax itself supports
                                negation.  The two types of negation are subtly different.
                                One negates the set of matched endpoints&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the other negates
                                &lt;span class=&quot;token key atrule&quot;&gt;the whole match&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; \n \tSelector = \&amp;quot;&lt;span class=&quot;token tag&quot;&gt;!has(my_label)&lt;/span&gt;\&amp;quot; matches
                                packets that are from other Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled \tendpoints
                                that do not have the label “my_label”. \n \tNotSelector
                                = \&amp;quot;has(my_label)\&amp;quot; matches packets that are not from
                                Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled \tendpoints that do have the label “my_label”.
                                \n The effect is that the latter will accept packets from
                                non&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Calico sources whereas the former is limited to packets
                                from Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled endpoints.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;serviceAccounts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ServiceAccounts is an optional field that restricts
                                the rule to only apply to traffic that originates from
                                (or terminates at) a pod running as a matching service
                                account.
                              &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Names is an optional field that restricts
                                    the rule to only apply to traffic that originates
                                    from (or terminates at) a pod running as a service
                                    account whose name is in the list.
                                  &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                  &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                                &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Selector is an optional field that restricts
                                    the rule to only apply to traffic that originates
                                    from (or terminates at) a pod running as a service
                                    account that matches the given label selector. If
                                    both Names and Selector are specified then they are
                                    AND&amp;#x27;ed.
                                  &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;http&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; HTTP contains match criteria that apply to HTTP
                            requests.
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;methods&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Methods is an optional field that restricts
                                the rule to apply only to HTTP requests that use one of
                                the listed HTTP Methods (e.g. GET&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; PUT&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; etc.) Multiple
                                methods are OR&amp;#x27;d together.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;paths&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Paths is an optional field that restricts
                                the rule to apply to HTTP requests that use one of the
                                listed HTTP Paths. Multiple paths are OR&amp;#x27;&amp;#x27;d together.
                                &lt;span class=&quot;token key atrule&quot;&gt;e.g&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;exact&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;/foo - prefix&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;/bar NOTE&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Each entry may
                                ONLY specify either a `exact` or a `prefix` match. The
                                validator will check for it.&amp;#x27;
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;HTTPPath specifies an HTTP path to match.
                                  &lt;span class=&quot;token key atrule&quot;&gt;It may be either of the form&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;exact&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;&amp;lt;path&amp;gt;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; which matches
                                  &lt;span class=&quot;token key atrule&quot;&gt;the path exactly or prefix&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;&amp;lt;path-prefix&amp;gt;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; which matches
                                  the path prefix&amp;#x27;
                                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;exact&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                  &lt;span class=&quot;token key atrule&quot;&gt;prefix&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;icmp&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ICMP is an optional field that restricts the rule
                            to apply to a specific type and code of ICMP traffic.  This
                            should only be specified if the Protocol field is set to &amp;quot;ICMP&amp;quot;
                            or &amp;quot;ICMPv6&amp;quot;.
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;code&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Match on a specific ICMP code.  If specified&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                                the Type value must also be specified. This is a technical
                                limitation imposed by the kernel’s iptables firewall&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                                which Calico uses to enforce the rule.
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Match on a specific ICMP type.  For example
                                a value of 8 refers to ICMP Echo Request (i.e. pings).
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;ipVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; IPVersion is an optional field that restricts the
                            rule to only match a specific IP version.
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                        &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Metadata contains additional information for this
                            rule
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;annotations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;additionalProperties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Annotations is a set of key value pairs that
                                give extra information about the rule
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;notICMP&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotICMP is the negated version of the ICMP field.
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;code&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Match on a specific ICMP code.  If specified&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                                the Type value must also be specified. This is a technical
                                limitation imposed by the kernel’s iptables firewall&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                                which Calico uses to enforce the rule.
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Match on a specific ICMP type.  For example
                                a value of 8 refers to ICMP Echo Request (i.e. pings).
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;notProtocol&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotProtocol is the negated version of the Protocol
                            field.
                          &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                          &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;protocol&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Protocol is an optional field that restricts the
                            rule to only apply to traffic of a specific IP protocol. Required
                            if any of the EntityRules contain Ports (because ports only
                            apply to certain protocols). \n Must be one of these string
                            &lt;span class=&quot;token key atrule&quot;&gt;values&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; \&amp;quot;TCP\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;UDP\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;ICMP\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;ICMPv6\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;SCTP\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                            \&amp;quot;UDPLite\&amp;quot; or an integer in the range 1&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;255.&amp;quot;
                          &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                          &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;source&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Source contains the match criteria that apply to
                            source entity.
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;namespaceSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;NamespaceSelector is an optional field that
                                contains a selector expression. Only traffic that originates
                                from (or terminates at) endpoints within the selected
                                namespaces will be matched. When both NamespaceSelector
                                and Selector are defined on the same rule&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; then only workload
                                endpoints that are matched by both selectors will be selected
                                by the rule. \n For NetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; an empty NamespaceSelector
                                implies that the Selector is limited to selecting only
                                workload endpoints in the same namespace as the NetworkPolicy.
                                \n For NetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; `global()` NamespaceSelector implies
                                that the Selector is limited to selecting only GlobalNetworkSet
                                or HostEndpoint. \n For GlobalNetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; an empty
                                NamespaceSelector implies the Selector applies to workload
                                endpoints across all namespaces.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;nets&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Nets is an optional field that restricts the
                                rule to only apply to traffic that originates from (or
                                terminates at) IP addresses in any of the given subnets.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notNets&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotNets is the negated version of the Nets
                                field.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notPorts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotPorts is the negated version of the Ports
                                field. Since only some protocols have ports&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if any ports
                                are specified it requires the Protocol match in the Rule
                                to be set to &amp;quot;TCP&amp;quot; or &amp;quot;UDP&amp;quot;.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                                &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotSelector is the negated version of the Selector
                                field.  See Selector field for subtleties with negated
                                selectors.
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;ports&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Ports is an optional field that restricts
                                the rule to only apply to traffic that has a source (destination)
                                port that matches one of these ranges/values. This value
                                is a list of integers or strings that represent ranges
                                of ports. \n Since only some protocols have ports&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if
                                any ports are specified it requires the Protocol match
                                in the Rule to be set to \&amp;quot;TCP\&amp;quot; or \&amp;quot;UDP\&amp;quot;.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                                &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Selector is an optional field that contains
                                a selector expression (see Policy for sample syntax).
                                \ Only traffic that originates from (terminates at) endpoints
                                &lt;span class=&quot;token key atrule&quot;&gt;matching the selector will be matched. \n Note that&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; in
                                addition to the negated version of the Selector (see NotSelector
                                below)&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the selector expression syntax itself supports
                                negation.  The two types of negation are subtly different.
                                One negates the set of matched endpoints&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the other negates
                                &lt;span class=&quot;token key atrule&quot;&gt;the whole match&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; \n \tSelector = \&amp;quot;&lt;span class=&quot;token tag&quot;&gt;!has(my_label)&lt;/span&gt;\&amp;quot; matches
                                packets that are from other Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled \tendpoints
                                that do not have the label “my_label”. \n \tNotSelector
                                = \&amp;quot;has(my_label)\&amp;quot; matches packets that are not from
                                Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled \tendpoints that do have the label “my_label”.
                                \n The effect is that the latter will accept packets from
                                non&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Calico sources whereas the former is limited to packets
                                from Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled endpoints.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;serviceAccounts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ServiceAccounts is an optional field that restricts
                                the rule to only apply to traffic that originates from
                                (or terminates at) a pod running as a matching service
                                account.
                              &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Names is an optional field that restricts
                                    the rule to only apply to traffic that originates
                                    from (or terminates at) a pod running as a service
                                    account whose name is in the list.
                                  &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                  &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                                &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Selector is an optional field that restricts
                                    the rule to only apply to traffic that originates
                                    from (or terminates at) a pod running as a service
                                    account that matches the given label selector. If
                                    both Names and Selector are specified then they are
                                    AND&amp;#x27;ed.
                                  &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                      &lt;span class=&quot;token key atrule&quot;&gt;required&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; action
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                  &lt;span class=&quot;token key atrule&quot;&gt;order&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Order is an optional field that specifies the order in
                      which the policy is applied. Policies with higher &amp;quot;order&amp;quot; are applied
                      after those with lower order.  If the order is omitted&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; it may be
                      considered to be &amp;quot;infinite&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; i.e. the policy will be applied last.  Policies
                      with identical order will be applied in alphanumerical order based
                      on the Policy &amp;quot;Name&amp;quot;.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; number
                  &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;The selector is an expression used to pick pick out
                      the endpoints that the policy should be applied to. \n Selector
                      &lt;span class=&quot;token key atrule&quot;&gt;expressions follow this syntax&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; \n \tlabel == \&amp;quot;string_literal\&amp;quot;
                      \ &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;  comparison&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; e.g. my_label == \&amp;quot;foo bar\&amp;quot; \tlabel &lt;span class=&quot;token tag&quot;&gt;!=&lt;/span&gt; \&amp;quot;string_literal\&amp;quot;
                      \  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;  not equal; also matches if label is not present \tlabel in
                      &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; \&amp;quot;a\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;b\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;c\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;...&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;  true if the value of label X is
                      one of \&amp;quot;a\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;b\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;c\&amp;quot; \tlabel not in &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; \&amp;quot;a\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;b\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;c\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      &lt;span class=&quot;token punctuation&quot;&gt;...&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;  true if the value of label X is not one of \&amp;quot;a\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;b\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      \&amp;quot;c\&amp;quot; \thas(label_name)  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt; True if that label is present \t&lt;span class=&quot;token tag&quot;&gt;!&lt;/span&gt; expr
                      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt; negation of expr \texpr &lt;span class=&quot;token important&quot;&gt;&amp;amp;&amp;amp;&lt;/span&gt; expr  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt; Short&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;circuit and \texpr
                      &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; expr  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt; Short&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;circuit or \t( expr ) &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt; parens for grouping \tall()
                      or the empty selector &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt; matches all endpoints. \n Label names are
                      allowed to contain alphanumerics&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; _ and /. String literals are
                      more permissive but they do not support escape characters. \n Examples
                      &lt;span class=&quot;token key atrule&quot;&gt;(with made-up labels)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; \n \ttype == \&amp;quot;webserver\&amp;quot; &lt;span class=&quot;token important&quot;&gt;&amp;amp;&amp;amp;&lt;/span&gt; deployment
                      == \&amp;quot;prod\&amp;quot; \ttype in &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;\&amp;quot;frontend\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;backend\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt; \tdeployment &lt;span class=&quot;token tag&quot;&gt;!=&lt;/span&gt;
                      \&amp;quot;dev\&amp;quot; \t&lt;span class=&quot;token tag&quot;&gt;!&lt;/span&gt; has(label_name)&amp;quot;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;serviceAccountSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ServiceAccountSelector is an optional field for an expression
                      used to select a pod based on service accounts.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;types&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Types indicates whether this policy applies to ingress&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      or to egress&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; or to both.  When not explicitly specified (and so
                      the value on creation is empty or nil)&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; Calico defaults Types according
                      to what Ingress and Egress are present in the policy.  The default
                      &lt;span class=&quot;token key atrule&quot;&gt;is&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; \n &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt; PolicyTypeIngress &lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if there are no Egress rules (including
                      the case where there are   also no Ingress rules) \n &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt; PolicyTypeEgress
                      &lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if there are Egress rules but no Ingress rules \n &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt; PolicyTypeIngress&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      PolicyTypeEgress &lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if there are both Ingress and Egress rules.
                      \n When the policy is read back again&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; Types will always be one
                      of these values&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; never empty or nil.&amp;quot;
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; PolicyType enumerates the possible values of the PolicySpec
                        Types field.
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
        &lt;span class=&quot;token key atrule&quot;&gt;served&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;storage&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;status&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;acceptedNames&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;conditions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;storedVersions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; apiextensions.k8s.io/v1
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CustomResourceDefinition
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;annotations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;controller-gen.kubebuilder.io/version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; (devel)
      &lt;span class=&quot;token key atrule&quot;&gt;creationTimestamp&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token null important&quot;&gt;null&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; networksets.crd.projectcalico.org
    &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;group&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; crd.projectcalico.org
      &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NetworkSet
        &lt;span class=&quot;token key atrule&quot;&gt;listKind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NetworkSetList
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; networksets
        &lt;span class=&quot;token key atrule&quot;&gt;singular&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; networkset
      &lt;span class=&quot;token key atrule&quot;&gt;scope&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Namespaced
      &lt;span class=&quot;token key atrule&quot;&gt;versions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; v1
        &lt;span class=&quot;token key atrule&quot;&gt;schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;openAPIV3Schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NetworkSet is the Namespaced&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;equivalent of the GlobalNetworkSet.
            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;APIVersion defines the versioned schema of this representation
                  of an object. Servers should convert recognized schemas to the latest
                  internal value&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;and may reject unrecognized values. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#resources&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Kind is a string value representing the REST resource this
                  object represents. Servers may infer this from the endpoint the client
                  &lt;span class=&quot;token key atrule&quot;&gt;submits requests to. Cannot be updated. In CamelCase. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#types-kinds&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
              &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NetworkSetSpec contains the specification for a NetworkSet
                  resource.
                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;nets&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; The list of IP networks that belong to this set.
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
        &lt;span class=&quot;token key atrule&quot;&gt;served&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;storage&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;status&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;acceptedNames&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;conditions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;storedVersions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token comment&quot;&gt;# Source: calico/templates/calico-kube-controllers-rbac.yaml&lt;/span&gt;

    &lt;span class=&quot;token comment&quot;&gt;# Include a clusterrole for the kube-controllers component,&lt;/span&gt;
    &lt;span class=&quot;token comment&quot;&gt;# and bind it to the calico-kube-controllers serviceaccount.&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ClusterRole
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; rbac.authorization.k8s.io/v1
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controllers
    &lt;span class=&quot;token key atrule&quot;&gt;rules&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token comment&quot;&gt;# Nodes are watched to monitor for deletions.&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; nodes
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; watch
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; list
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; get
      &lt;span class=&quot;token comment&quot;&gt;# Pods are queried to check for existence.&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; pods
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; get
      &lt;span class=&quot;token comment&quot;&gt;# IPAM resources are manipulated when nodes are deleted.&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;crd.projectcalico.org&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; ippools
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; list
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;crd.projectcalico.org&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; blockaffinities
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; ipamblocks
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; ipamhandles
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; get
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; list
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; create
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; update
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; delete
      &lt;span class=&quot;token comment&quot;&gt;# kube-controllers manages hostendpoints.&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;crd.projectcalico.org&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; hostendpoints
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; get
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; list
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; create
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; update
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; delete
      &lt;span class=&quot;token comment&quot;&gt;# Needs access to update clusterinformations.&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;crd.projectcalico.org&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; clusterinformations
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; get
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; create
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; update
      &lt;span class=&quot;token comment&quot;&gt;# KubeControllersConfiguration is where it gets its config&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;crd.projectcalico.org&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; kubecontrollersconfigurations
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token comment&quot;&gt;# read its own config&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; get
          &lt;span class=&quot;token comment&quot;&gt;# create a default if none exists&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; create
          &lt;span class=&quot;token comment&quot;&gt;# update status&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; update
          &lt;span class=&quot;token comment&quot;&gt;# watch for changes&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; watch
    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ClusterRoleBinding
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; rbac.authorization.k8s.io/v1
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controllers
    &lt;span class=&quot;token key atrule&quot;&gt;roleRef&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;apiGroup&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; rbac.authorization.k8s.io
      &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ClusterRole
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controllers
    &lt;span class=&quot;token key atrule&quot;&gt;subjects&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ServiceAccount
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controllers
      &lt;span class=&quot;token key atrule&quot;&gt;namespace&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;system
    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token comment&quot;&gt;# Source: calico/templates/calico-node-rbac.yaml&lt;/span&gt;
    &lt;span class=&quot;token comment&quot;&gt;# Include a clusterrole for the calico-node DaemonSet,&lt;/span&gt;
    &lt;span class=&quot;token comment&quot;&gt;# and bind it to the calico-node serviceaccount.&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ClusterRole
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; rbac.authorization.k8s.io/v1
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;node
    &lt;span class=&quot;token key atrule&quot;&gt;rules&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token comment&quot;&gt;# The CNI plugin needs to get pods, nodes, and namespaces.&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; pods
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; nodes
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; namespaces
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; get
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; endpoints
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; services
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token comment&quot;&gt;# Used to discover service IPs for advertisement.&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; watch
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; list
          &lt;span class=&quot;token comment&quot;&gt;# Used to discover Typhas.&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; get
      &lt;span class=&quot;token comment&quot;&gt;# Pod CIDR auto-detection on kubeadm needs access to config maps.&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; configmaps
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; get
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; nodes/status
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token comment&quot;&gt;# Needed for clearing NodeNetworkUnavailable flag.&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; patch
          &lt;span class=&quot;token comment&quot;&gt;# Calico stores some configuration information in node annotations.&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; update
      &lt;span class=&quot;token comment&quot;&gt;# Watch for changes to Kubernetes NetworkPolicies.&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;networking.k8s.io&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; networkpolicies
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; watch
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; list
      &lt;span class=&quot;token comment&quot;&gt;# Used by Calico for policy information.&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; pods
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; namespaces
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; serviceaccounts
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; list
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; watch
      &lt;span class=&quot;token comment&quot;&gt;# The CNI plugin patches pods/status.&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; pods/status
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; patch
      &lt;span class=&quot;token comment&quot;&gt;# Calico monitors various CRDs for config.&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;crd.projectcalico.org&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; globalfelixconfigs
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; felixconfigurations
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; bgppeers
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; globalbgpconfigs
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; bgpconfigurations
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; ippools
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; ipamblocks
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; globalnetworkpolicies
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; globalnetworksets
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; networkpolicies
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; networksets
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; clusterinformations
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; hostendpoints
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; blockaffinities
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; get
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; list
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; watch
      &lt;span class=&quot;token comment&quot;&gt;# Calico must create and update some CRDs on startup.&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;crd.projectcalico.org&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; ippools
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; felixconfigurations
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; clusterinformations
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; create
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; update
      &lt;span class=&quot;token comment&quot;&gt;# Calico stores some configuration information on the node.&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; nodes
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; get
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; list
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; watch
      &lt;span class=&quot;token comment&quot;&gt;# These permissions are only required for upgrade from v2.6, and can&lt;/span&gt;
      &lt;span class=&quot;token comment&quot;&gt;# be removed after upgrade or on fresh installations.&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;crd.projectcalico.org&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; bgpconfigurations
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; bgppeers
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; create
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; update
      &lt;span class=&quot;token comment&quot;&gt;# These permissions are required for Calico CNI to perform IPAM allocations.&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;crd.projectcalico.org&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; blockaffinities
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; ipamblocks
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; ipamhandles
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; get
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; list
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; create
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; update
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; delete
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;crd.projectcalico.org&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; ipamconfigs
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; get
      &lt;span class=&quot;token comment&quot;&gt;# Block affinities must also be watchable by confd for route aggregation.&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;crd.projectcalico.org&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; blockaffinities
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; watch
      &lt;span class=&quot;token comment&quot;&gt;# The Calico IPAM migration needs to get daemonsets. These permissions can be&lt;/span&gt;
      &lt;span class=&quot;token comment&quot;&gt;# removed if not upgrading from an installation using host-local IPAM.&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;apps&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; daemonsets
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; get

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; rbac.authorization.k8s.io/v1
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ClusterRoleBinding
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;node
    &lt;span class=&quot;token key atrule&quot;&gt;roleRef&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;apiGroup&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; rbac.authorization.k8s.io
      &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ClusterRole
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;node
    &lt;span class=&quot;token key atrule&quot;&gt;subjects&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ServiceAccount
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;node
      &lt;span class=&quot;token key atrule&quot;&gt;namespace&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;system

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token comment&quot;&gt;# Source: calico/templates/calico-node.yaml&lt;/span&gt;
    &lt;span class=&quot;token comment&quot;&gt;# This manifest installs the calico-node container, as well&lt;/span&gt;
    &lt;span class=&quot;token comment&quot;&gt;# as the CNI plugins and network config on&lt;/span&gt;
    &lt;span class=&quot;token comment&quot;&gt;# each master and worker node in a Kubernetes cluster.&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; DaemonSet
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; apps/v1
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;node
      &lt;span class=&quot;token key atrule&quot;&gt;namespace&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;system
      &lt;span class=&quot;token key atrule&quot;&gt;labels&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;k8s-app&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;node
    &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;matchLabels&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;k8s-app&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;node
      &lt;span class=&quot;token key atrule&quot;&gt;updateStrategy&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; RollingUpdate
        &lt;span class=&quot;token key atrule&quot;&gt;rollingUpdate&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;maxUnavailable&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;1&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;template&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;labels&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token key atrule&quot;&gt;k8s-app&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;node
        &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;nodeSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token key atrule&quot;&gt;kubernetes.io/os&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; linux
          &lt;span class=&quot;token key atrule&quot;&gt;hostNetwork&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;tolerations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token comment&quot;&gt;# Make sure calico-node gets scheduled on all nodes.&lt;/span&gt;
            &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;effect&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NoSchedule
              &lt;span class=&quot;token key atrule&quot;&gt;operator&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Exists
            &lt;span class=&quot;token comment&quot;&gt;# Mark the pod as a critical add-on for rescheduling.&lt;/span&gt;
            &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;key&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CriticalAddonsOnly
              &lt;span class=&quot;token key atrule&quot;&gt;operator&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Exists
            &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;effect&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NoExecute
              &lt;span class=&quot;token key atrule&quot;&gt;operator&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Exists
          &lt;span class=&quot;token key atrule&quot;&gt;serviceAccountName&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;node
          &lt;span class=&quot;token comment&quot;&gt;# Minimize downtime during a rolling upgrade or deletion; tell Kubernetes to do a &amp;quot;force&lt;/span&gt;
          &lt;span class=&quot;token comment&quot;&gt;# deletion&amp;quot;: https://kubernetes.io/docs/concepts/workloads/pods/pod/#termination-of-pods.&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;terminationGracePeriodSeconds&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;0&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;priorityClassName&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; system&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;node&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;critical
          &lt;span class=&quot;token key atrule&quot;&gt;initContainers&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token comment&quot;&gt;# This container performs upgrade from host-local IPAM to calico-ipam.&lt;/span&gt;
            &lt;span class=&quot;token comment&quot;&gt;# It can be deleted if this is a fresh installation, or if you have already&lt;/span&gt;
            &lt;span class=&quot;token comment&quot;&gt;# upgraded to use calico-ipam.&lt;/span&gt;
            &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; upgrade&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;ipam
              &lt;span class=&quot;token key atrule&quot;&gt;image&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico/cni&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;v3.16.1
              &lt;span class=&quot;token key atrule&quot;&gt;command&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;/opt/cni/bin/calico-ipam&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;-upgrade&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;envFrom&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
              &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;configMapRef&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token comment&quot;&gt;# Allow KUBERNETES_SERVICE_HOST and KUBERNETES_SERVICE_PORT to be overridden for eBPF mode.&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; kubernetes&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;services&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;endpoint
                  &lt;span class=&quot;token key atrule&quot;&gt;optional&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;env&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; KUBERNETES_NODE_NAME
                  &lt;span class=&quot;token key atrule&quot;&gt;valueFrom&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;fieldRef&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;fieldPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; spec.nodeName
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CALICO_NETWORKING_BACKEND
                  &lt;span class=&quot;token key atrule&quot;&gt;valueFrom&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;configMapKeyRef&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;config
                      &lt;span class=&quot;token key atrule&quot;&gt;key&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico_backend
              &lt;span class=&quot;token key atrule&quot;&gt;volumeMounts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;mountPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /var/lib/cni/networks
                  &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; host&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;local&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;net&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;dir
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;mountPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /host/opt/cni/bin
                  &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; cni&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;bin&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;dir
              &lt;span class=&quot;token key atrule&quot;&gt;securityContext&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;privileged&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
            &lt;span class=&quot;token comment&quot;&gt;# This container installs the CNI binaries&lt;/span&gt;
            &lt;span class=&quot;token comment&quot;&gt;# and CNI network config file on each node.&lt;/span&gt;
            &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; install&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;cni
              &lt;span class=&quot;token key atrule&quot;&gt;image&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico/cni&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;v3.16.1
              &lt;span class=&quot;token key atrule&quot;&gt;command&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;/opt/cni/bin/install&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;envFrom&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
              &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;configMapRef&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token comment&quot;&gt;# Allow KUBERNETES_SERVICE_HOST and KUBERNETES_SERVICE_PORT to be overridden for eBPF mode.&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; kubernetes&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;services&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;endpoint
                  &lt;span class=&quot;token key atrule&quot;&gt;optional&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;env&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token comment&quot;&gt;# Name of the CNI config file to create.&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CNI_CONF_NAME
                  &lt;span class=&quot;token key atrule&quot;&gt;value&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;10-calico.conflist&amp;quot;&lt;/span&gt;
                &lt;span class=&quot;token comment&quot;&gt;# The CNI network config to install on each node.&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CNI_NETWORK_CONFIG
                  &lt;span class=&quot;token key atrule&quot;&gt;valueFrom&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;configMapKeyRef&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;config
                      &lt;span class=&quot;token key atrule&quot;&gt;key&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; cni_network_config
                &lt;span class=&quot;token comment&quot;&gt;# Set the hostname based on the k8s node name.&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; KUBERNETES_NODE_NAME
                  &lt;span class=&quot;token key atrule&quot;&gt;valueFrom&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;fieldRef&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;fieldPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; spec.nodeName
                &lt;span class=&quot;token comment&quot;&gt;# CNI MTU Config variable&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CNI_MTU
                  &lt;span class=&quot;token key atrule&quot;&gt;valueFrom&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;configMapKeyRef&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;config
                      &lt;span class=&quot;token key atrule&quot;&gt;key&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; veth_mtu
                &lt;span class=&quot;token comment&quot;&gt;# Prevents the container from sleeping forever.&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; SLEEP
                  &lt;span class=&quot;token key atrule&quot;&gt;value&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;false&amp;quot;&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;volumeMounts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;mountPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /host/opt/cni/bin
                  &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; cni&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;bin&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;dir
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;mountPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /host/etc/cni/net.d
                  &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; cni&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;net&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;dir
              &lt;span class=&quot;token key atrule&quot;&gt;securityContext&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;privileged&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
            &lt;span class=&quot;token comment&quot;&gt;# Adds a Flex Volume Driver that creates a per-pod Unix Domain Socket to allow Dikastes&lt;/span&gt;
            &lt;span class=&quot;token comment&quot;&gt;# to communicate with Felix over the Policy Sync API.&lt;/span&gt;
            &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; flexvol&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;driver
              &lt;span class=&quot;token key atrule&quot;&gt;image&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico/pod2daemon&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;flexvol&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;v3.16.1
              &lt;span class=&quot;token key atrule&quot;&gt;volumeMounts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
              &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; flexvol&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;driver&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;host
                &lt;span class=&quot;token key atrule&quot;&gt;mountPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /host/driver
              &lt;span class=&quot;token key atrule&quot;&gt;securityContext&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;privileged&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;containers&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token comment&quot;&gt;# Runs calico-node container on each Kubernetes node. This&lt;/span&gt;
            &lt;span class=&quot;token comment&quot;&gt;# container programs network policy and routes on each&lt;/span&gt;
            &lt;span class=&quot;token comment&quot;&gt;# host.&lt;/span&gt;
            &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;node
              &lt;span class=&quot;token key atrule&quot;&gt;image&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico/node&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;v3.16.1
              &lt;span class=&quot;token key atrule&quot;&gt;envFrom&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
              &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;configMapRef&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token comment&quot;&gt;# Allow KUBERNETES_SERVICE_HOST and KUBERNETES_SERVICE_PORT to be overridden for eBPF mode.&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; kubernetes&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;services&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;endpoint
                  &lt;span class=&quot;token key atrule&quot;&gt;optional&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;env&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token comment&quot;&gt;# Use Kubernetes API as the backing datastore.&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; DATASTORE_TYPE
                  &lt;span class=&quot;token key atrule&quot;&gt;value&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;kubernetes&amp;quot;&lt;/span&gt;
                &lt;span class=&quot;token comment&quot;&gt;# Wait for the datastore.&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; WAIT_FOR_DATASTORE
                  &lt;span class=&quot;token key atrule&quot;&gt;value&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;true&amp;quot;&lt;/span&gt;
                &lt;span class=&quot;token comment&quot;&gt;# Set based on the k8s node name.&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NODENAME
                  &lt;span class=&quot;token key atrule&quot;&gt;valueFrom&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;fieldRef&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;fieldPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; spec.nodeName
                &lt;span class=&quot;token comment&quot;&gt;# Choose the backend to use.&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CALICO_NETWORKING_BACKEND
                  &lt;span class=&quot;token key atrule&quot;&gt;valueFrom&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;configMapKeyRef&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;config
                      &lt;span class=&quot;token key atrule&quot;&gt;key&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico_backend
                &lt;span class=&quot;token comment&quot;&gt;# Cluster type to identify the deployment type&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CLUSTER_TYPE
                  &lt;span class=&quot;token key atrule&quot;&gt;value&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;k8s,bgp&amp;quot;&lt;/span&gt;
                &lt;span class=&quot;token comment&quot;&gt;# Auto-detect the BGP IP address.&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; IP
                  &lt;span class=&quot;token key atrule&quot;&gt;value&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;autodetect&amp;quot;&lt;/span&gt;
                &lt;span class=&quot;token comment&quot;&gt;# Enable IPIP&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CALICO_IPV4POOL_IPIP
                  &lt;span class=&quot;token key atrule&quot;&gt;value&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;Always&amp;quot;&lt;/span&gt;
                &lt;span class=&quot;token comment&quot;&gt;# Enable or Disable VXLAN on the default IP pool.&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CALICO_IPV4POOL_VXLAN
                  &lt;span class=&quot;token key atrule&quot;&gt;value&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;Never&amp;quot;&lt;/span&gt;
                &lt;span class=&quot;token comment&quot;&gt;# Set MTU for tunnel device used if ipip is enabled&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; FELIX_IPINIPMTU
                  &lt;span class=&quot;token key atrule&quot;&gt;valueFrom&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;configMapKeyRef&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;config
                      &lt;span class=&quot;token key atrule&quot;&gt;key&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; veth_mtu
                &lt;span class=&quot;token comment&quot;&gt;# Set MTU for the VXLAN tunnel device.&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; FELIX_VXLANMTU
                  &lt;span class=&quot;token key atrule&quot;&gt;valueFrom&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;configMapKeyRef&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;config
                      &lt;span class=&quot;token key atrule&quot;&gt;key&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; veth_mtu
                &lt;span class=&quot;token comment&quot;&gt;# Set MTU for the Wireguard tunnel device.&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; FELIX_WIREGUARDMTU
                  &lt;span class=&quot;token key atrule&quot;&gt;valueFrom&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;configMapKeyRef&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;config
                      &lt;span class=&quot;token key atrule&quot;&gt;key&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; veth_mtu
                &lt;span class=&quot;token comment&quot;&gt;# The default IPv4 pool to create on startup if none exists. Pod IPs will be&lt;/span&gt;
                &lt;span class=&quot;token comment&quot;&gt;# chosen from this range. Changing this value after installation will have&lt;/span&gt;
                &lt;span class=&quot;token comment&quot;&gt;# no effect. This should fall within `--cluster-cidr`.&lt;/span&gt;
                &lt;span class=&quot;token comment&quot;&gt;# - name: CALICO_IPV4POOL_CIDR&lt;/span&gt;
                &lt;span class=&quot;token comment&quot;&gt;#   value: &amp;quot;192.168.0.0/16&amp;quot;&lt;/span&gt;
                &lt;span class=&quot;token comment&quot;&gt;# Disable file logging so `kubectl logs` works.&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CALICO_DISABLE_FILE_LOGGING
                  &lt;span class=&quot;token key atrule&quot;&gt;value&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;true&amp;quot;&lt;/span&gt;
                &lt;span class=&quot;token comment&quot;&gt;# Set Felix endpoint to host default action to ACCEPT.&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; FELIX_DEFAULTENDPOINTTOHOSTACTION
                  &lt;span class=&quot;token key atrule&quot;&gt;value&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;ACCEPT&amp;quot;&lt;/span&gt;
                &lt;span class=&quot;token comment&quot;&gt;# Disable IPv6 on Kubernetes.&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; FELIX_IPV6SUPPORT
                  &lt;span class=&quot;token key atrule&quot;&gt;value&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;false&amp;quot;&lt;/span&gt;
                &lt;span class=&quot;token comment&quot;&gt;# Set Felix logging to &amp;quot;info&amp;quot;&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; FELIX_LOGSEVERITYSCREEN
                  &lt;span class=&quot;token key atrule&quot;&gt;value&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;info&amp;quot;&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; FELIX_HEALTHENABLED
                  &lt;span class=&quot;token key atrule&quot;&gt;value&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;true&amp;quot;&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;securityContext&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;privileged&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;requests&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;cpu&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 250m
              &lt;span class=&quot;token key atrule&quot;&gt;livenessProbe&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;exec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;command&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; /bin/calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;node
                  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;felix&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;live
                  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;bird&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;live
                &lt;span class=&quot;token key atrule&quot;&gt;periodSeconds&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;10&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;initialDelaySeconds&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;10&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;failureThreshold&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;6&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;readinessProbe&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;exec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;command&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; /bin/calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;node
                  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;felix&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;ready
                  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;bird&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;ready
                &lt;span class=&quot;token key atrule&quot;&gt;periodSeconds&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;10&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;volumeMounts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;mountPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /lib/modules
                  &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; lib&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;modules
                  &lt;span class=&quot;token key atrule&quot;&gt;readOnly&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;mountPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /run/xtables.lock
                  &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; xtables&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;lock
                  &lt;span class=&quot;token key atrule&quot;&gt;readOnly&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;false&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;mountPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /var/run/calico
                  &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; var&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;run&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;calico
                  &lt;span class=&quot;token key atrule&quot;&gt;readOnly&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;false&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;mountPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /var/lib/calico
                  &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; var&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;lib&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;calico
                  &lt;span class=&quot;token key atrule&quot;&gt;readOnly&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;false&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; policysync
                  &lt;span class=&quot;token key atrule&quot;&gt;mountPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /var/run/nodeagent
                &lt;span class=&quot;token comment&quot;&gt;# For eBPF mode, we need to be able to mount the BPF filesystem at /sys/fs/bpf so we mount in the&lt;/span&gt;
                &lt;span class=&quot;token comment&quot;&gt;# parent directory.&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; sysfs
                  &lt;span class=&quot;token key atrule&quot;&gt;mountPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /sys/fs/
                  &lt;span class=&quot;token comment&quot;&gt;# Bidirectional means that, if we mount the BPF filesystem at /sys/fs/bpf it will propagate to the host.&lt;/span&gt;
                  &lt;span class=&quot;token comment&quot;&gt;# If the host is known to mount that filesystem already then Bidirectional can be omitted.&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;mountPropagation&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Bidirectional
          &lt;span class=&quot;token key atrule&quot;&gt;volumes&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token comment&quot;&gt;# Used by calico-node.&lt;/span&gt;
            &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; lib&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;modules
              &lt;span class=&quot;token key atrule&quot;&gt;hostPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;path&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /lib/modules
            &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; var&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;run&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;calico
              &lt;span class=&quot;token key atrule&quot;&gt;hostPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;path&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /var/run/calico
            &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; var&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;lib&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;calico
              &lt;span class=&quot;token key atrule&quot;&gt;hostPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;path&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /var/lib/calico
            &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; xtables&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;lock
              &lt;span class=&quot;token key atrule&quot;&gt;hostPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;path&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /run/xtables.lock
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; FileOrCreate
            &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; sysfs
              &lt;span class=&quot;token key atrule&quot;&gt;hostPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;path&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /sys/fs/
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; DirectoryOrCreate
            &lt;span class=&quot;token comment&quot;&gt;# Used to install CNI.&lt;/span&gt;
            &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; cni&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;bin&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;dir
              &lt;span class=&quot;token key atrule&quot;&gt;hostPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;path&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /opt/cni/bin
            &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; cni&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;net&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;dir
              &lt;span class=&quot;token key atrule&quot;&gt;hostPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;path&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /etc/cni/net.d
            &lt;span class=&quot;token comment&quot;&gt;# Mount in the directory for host-local IPAM allocations. This is&lt;/span&gt;
            &lt;span class=&quot;token comment&quot;&gt;# used when upgrading from host-local to calico-ipam, and can be removed&lt;/span&gt;
            &lt;span class=&quot;token comment&quot;&gt;# if not using the upgrade-ipam init container.&lt;/span&gt;
            &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; host&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;local&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;net&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;dir
              &lt;span class=&quot;token key atrule&quot;&gt;hostPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;path&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /var/lib/cni/networks
            &lt;span class=&quot;token comment&quot;&gt;# Used to create per-pod Unix Domain Sockets&lt;/span&gt;
            &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; policysync
              &lt;span class=&quot;token key atrule&quot;&gt;hostPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; DirectoryOrCreate
                &lt;span class=&quot;token key atrule&quot;&gt;path&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /var/run/nodeagent
            &lt;span class=&quot;token comment&quot;&gt;# Used to install Flex Volume Driver&lt;/span&gt;
            &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; flexvol&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;driver&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;host
              &lt;span class=&quot;token key atrule&quot;&gt;hostPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; DirectoryOrCreate
                &lt;span class=&quot;token key atrule&quot;&gt;path&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /usr/libexec/kubernetes/kubelet&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;plugins/volume/exec/nodeagent~uds
    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;

    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; v1
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ServiceAccount
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;node
      &lt;span class=&quot;token key atrule&quot;&gt;namespace&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;system

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token comment&quot;&gt;# Source: calico/templates/calico-kube-controllers.yaml&lt;/span&gt;
    &lt;span class=&quot;token comment&quot;&gt;# See https://github.com/projectcalico/kube-controllers&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; apps/v1
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Deployment
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controllers
      &lt;span class=&quot;token key atrule&quot;&gt;namespace&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;system
      &lt;span class=&quot;token key atrule&quot;&gt;labels&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;k8s-app&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controllers
    &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token comment&quot;&gt;# The controllers can only have a single active instance.&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;replicas&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;1&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;matchLabels&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;k8s-app&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controllers
      &lt;span class=&quot;token key atrule&quot;&gt;strategy&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Recreate
      &lt;span class=&quot;token key atrule&quot;&gt;template&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controllers
          &lt;span class=&quot;token key atrule&quot;&gt;namespace&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;system
          &lt;span class=&quot;token key atrule&quot;&gt;labels&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token key atrule&quot;&gt;k8s-app&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controllers
        &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;nodeSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token key atrule&quot;&gt;kubernetes.io/os&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; linux
          &lt;span class=&quot;token key atrule&quot;&gt;tolerations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token comment&quot;&gt;# Mark the pod as a critical add-on for rescheduling.&lt;/span&gt;
            &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;key&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CriticalAddonsOnly
              &lt;span class=&quot;token key atrule&quot;&gt;operator&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Exists
            &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;key&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; node&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;role.kubernetes.io/master
              &lt;span class=&quot;token key atrule&quot;&gt;effect&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NoSchedule
          &lt;span class=&quot;token key atrule&quot;&gt;serviceAccountName&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controllers
          &lt;span class=&quot;token key atrule&quot;&gt;priorityClassName&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; system&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;cluster&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;critical
          &lt;span class=&quot;token key atrule&quot;&gt;containers&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controllers
              &lt;span class=&quot;token key atrule&quot;&gt;image&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico/kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controllers&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;v3.16.1
              &lt;span class=&quot;token key atrule&quot;&gt;env&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token comment&quot;&gt;# Choose which controllers to run.&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ENABLED_CONTROLLERS
                  &lt;span class=&quot;token key atrule&quot;&gt;value&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; node
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; DATASTORE_TYPE
                  &lt;span class=&quot;token key atrule&quot;&gt;value&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; kubernetes
              &lt;span class=&quot;token key atrule&quot;&gt;readinessProbe&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;exec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;command&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; /usr/bin/check&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;status
                  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;r

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;

    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; v1
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ServiceAccount
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controllers
      &lt;span class=&quot;token key atrule&quot;&gt;namespace&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;system

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token comment&quot;&gt;# Source: calico/templates/calico-etcd-secrets.yaml&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token comment&quot;&gt;# Source: calico/templates/calico-typha.yaml&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token comment&quot;&gt;# Source: calico/templates/configure-canal.yaml&lt;/span&gt;


&lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ConfigMap
&lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;creationTimestamp&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token null important&quot;&gt;null&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;cni
&lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; v1
&lt;span class=&quot;token key atrule&quot;&gt;data&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;calico-manifest.yaml&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt;+
    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token comment&quot;&gt;# Source: calico/templates/calico-config.yaml&lt;/span&gt;
    &lt;span class=&quot;token comment&quot;&gt;# This ConfigMap is used to configure a self-hosted Calico installation.&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ConfigMap
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; v1
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;config
      &lt;span class=&quot;token key atrule&quot;&gt;namespace&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;system
    &lt;span class=&quot;token key atrule&quot;&gt;data&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token comment&quot;&gt;# Typha is disabled.&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;typha_service_name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;none&amp;quot;&lt;/span&gt;
      &lt;span class=&quot;token comment&quot;&gt;# Configure the backend to use.&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;calico_backend&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;bird&amp;quot;&lt;/span&gt;
      &lt;span class=&quot;token comment&quot;&gt;# Configure the MTU to use for workload interfaces and tunnels.&lt;/span&gt;
      &lt;span class=&quot;token comment&quot;&gt;# - If Wireguard is enabled, set to your network MTU - 60&lt;/span&gt;
      &lt;span class=&quot;token comment&quot;&gt;# - Otherwise, if VXLAN or BPF mode is enabled, set to your network MTU - 50&lt;/span&gt;
      &lt;span class=&quot;token comment&quot;&gt;# - Otherwise, if IPIP is enabled, set to your network MTU - 20&lt;/span&gt;
      &lt;span class=&quot;token comment&quot;&gt;# - Otherwise, if not using any encapsulation, set to your network MTU.&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;veth_mtu&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;1440&amp;quot;&lt;/span&gt;

      &lt;span class=&quot;token comment&quot;&gt;# The CNI network configuration to install on each node. The special&lt;/span&gt;
      &lt;span class=&quot;token comment&quot;&gt;# values in this config will be automatically populated.&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;cni_network_config&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;
        &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;name&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;k8s-pod-network&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;cniVersion&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;0.3.1&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;plugins&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;
            &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;type&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;calico&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;log_level&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;info&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;log_file_path&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;/var/log/calico/cni/cni.log&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;datastore_type&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;kubernetes&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;nodename&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;__KUBERNETES_NODE_NAME__&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;mtu&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; __CNI_MTU__&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;ipam&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;type&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;calico-ipam&amp;quot;&lt;/span&gt;
              &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;policy&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;type&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;k8s&amp;quot;&lt;/span&gt;
              &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;kubernetes&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;kubeconfig&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;__KUBECONFIG_FILEPATH__&amp;quot;&lt;/span&gt;
              &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
            &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
            &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;type&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;portmap&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;snat&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;capabilities&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;portMappings&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
            &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
            &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;type&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;bandwidth&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;capabilities&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;&amp;quot;bandwidth&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
            &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token comment&quot;&gt;# Source: calico/templates/kdd-crds.yaml&lt;/span&gt;


    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; apiextensions.k8s.io/v1
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CustomResourceDefinition
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;annotations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;controller-gen.kubebuilder.io/version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; (devel)
      &lt;span class=&quot;token key atrule&quot;&gt;creationTimestamp&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token null important&quot;&gt;null&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; bgpconfigurations.crd.projectcalico.org
    &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;group&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; crd.projectcalico.org
      &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; BGPConfiguration
        &lt;span class=&quot;token key atrule&quot;&gt;listKind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; BGPConfigurationList
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; bgpconfigurations
        &lt;span class=&quot;token key atrule&quot;&gt;singular&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; bgpconfiguration
      &lt;span class=&quot;token key atrule&quot;&gt;scope&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Cluster
      &lt;span class=&quot;token key atrule&quot;&gt;versions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; v1
        &lt;span class=&quot;token key atrule&quot;&gt;schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;openAPIV3Schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; BGPConfiguration contains the configuration for any BGP routing.
            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;APIVersion defines the versioned schema of this representation
                  of an object. Servers should convert recognized schemas to the latest
                  internal value&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;and may reject unrecognized values. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#resources&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Kind is a string value representing the REST resource this
                  object represents. Servers may infer this from the endpoint the client
                  &lt;span class=&quot;token key atrule&quot;&gt;submits requests to. Cannot be updated. In CamelCase. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#types-kinds&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
              &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; BGPConfigurationSpec contains the values of the BGP configuration.
                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;asNumber&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;ASNumber is the default AS number used by a node. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token number&quot;&gt;64512&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;format&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; int32
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                  &lt;span class=&quot;token key atrule&quot;&gt;communities&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Communities is a list of BGP community values and their
                      arbitrary names for tagging routes.
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Community contains standard or large community value
                        and its name.
                      &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Name given to community value.
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                        &lt;span class=&quot;token key atrule&quot;&gt;value&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Value must be of format `aa&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;nn` or `aa&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;nn&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;mm`.
                            For standard community use `aa&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;nn` format&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; where `aa` and
                            `nn` are 16 bit number. For large community use `aa&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;nn&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;mm`
                            format&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; where `aa`&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; `nn` and `mm` are 32 bit number. Where&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                            `aa` is an AS Number&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; `nn` and `mm` are per&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;AS identifier.
                          &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^(\d+)&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;(\d+)$&lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt;^(\d+)&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;(\d+)&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;(\d+)$
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                  &lt;span class=&quot;token key atrule&quot;&gt;listenPort&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ListenPort is the port where BGP protocol should listen.
                      Defaults to 179
                    &lt;span class=&quot;token key atrule&quot;&gt;maximum&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;65535&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;minimum&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;1&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                  &lt;span class=&quot;token key atrule&quot;&gt;logSeverityScreen&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;LogSeverityScreen is the log severity above which logs
                      are sent to the stdout. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; INFO&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;nodeToNodeMeshEnabled&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;NodeToNodeMeshEnabled sets whether full node to node
                      BGP mesh is enabled. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;prefixAdvertisements&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; PrefixAdvertisements contains per&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;prefix advertisement
                      configuration.
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; PrefixAdvertisement configures advertisement properties
                        for the specified CIDR.
                      &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;cidr&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CIDR for which properties should be advertised.
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                        &lt;span class=&quot;token key atrule&quot;&gt;communities&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Communities can be list of either community names
                            already defined in `Specs.Communities` or community value
                            of format `aa&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;nn` or `aa&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;nn&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;mm`. For standard community use
                            `aa&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;nn` format&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; where `aa` and `nn` are 16 bit number. For
                            large community use `aa&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;nn&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;mm` format&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; where `aa`&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; `nn` and
                            `mm` are 32 bit number. Where&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;`aa` is an AS Number&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; `nn` and
                            `mm` are per&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;AS identifier.
                          &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                  &lt;span class=&quot;token key atrule&quot;&gt;serviceClusterIPs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ServiceClusterIPs are the CIDR blocks from which service
                      cluster IPs are allocated. If specified&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; Calico will advertise these
                      blocks&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; as well as any cluster IPs within them.
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ServiceClusterIPBlock represents a single allowed ClusterIP
                        CIDR block.
                      &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;cidr&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                  &lt;span class=&quot;token key atrule&quot;&gt;serviceExternalIPs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ServiceExternalIPs are the CIDR blocks for Kubernetes
                      Service External IPs. Kubernetes Service ExternalIPs will only be
                      advertised if they are within one of these blocks.
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ServiceExternalIPBlock represents a single allowed
                        External IP CIDR block.
                      &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;cidr&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
        &lt;span class=&quot;token key atrule&quot;&gt;served&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;storage&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;status&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;acceptedNames&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;conditions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;storedVersions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; apiextensions.k8s.io/v1
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CustomResourceDefinition
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;annotations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;controller-gen.kubebuilder.io/version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; (devel)
      &lt;span class=&quot;token key atrule&quot;&gt;creationTimestamp&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token null important&quot;&gt;null&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; bgppeers.crd.projectcalico.org
    &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;group&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; crd.projectcalico.org
      &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; BGPPeer
        &lt;span class=&quot;token key atrule&quot;&gt;listKind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; BGPPeerList
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; bgppeers
        &lt;span class=&quot;token key atrule&quot;&gt;singular&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; bgppeer
      &lt;span class=&quot;token key atrule&quot;&gt;scope&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Cluster
      &lt;span class=&quot;token key atrule&quot;&gt;versions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; v1
        &lt;span class=&quot;token key atrule&quot;&gt;schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;openAPIV3Schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;APIVersion defines the versioned schema of this representation
                  of an object. Servers should convert recognized schemas to the latest
                  internal value&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;and may reject unrecognized values. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#resources&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Kind is a string value representing the REST resource this
                  object represents. Servers may infer this from the endpoint the client
                  &lt;span class=&quot;token key atrule&quot;&gt;submits requests to. Cannot be updated. In CamelCase. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#types-kinds&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
              &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; BGPPeerSpec contains the specification for a BGPPeer resource.
                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;asNumber&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; The AS Number of the peer.
                    &lt;span class=&quot;token key atrule&quot;&gt;format&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; int32
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                  &lt;span class=&quot;token key atrule&quot;&gt;keepOriginalNextHop&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Option to keep the original nexthop field when routes
                      are sent to a BGP Peer. Setting &amp;quot;true&amp;quot; configures the selected BGP
                      Peers node to use the &amp;quot;next hop keep;&amp;quot; instead of &amp;quot;next hop self;&amp;quot;(default)
                      in the specific branch of the Node on &amp;quot;bird.cfg&amp;quot;.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;node&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; The node name identifying the Calico node instance that
                      is peering with this peer. If this is not set&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; this represents a
                      global peer&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; i.e. a peer that peers with every node in the deployment.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;nodeSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Selector for the nodes that should have this peering.  When
                      this is set&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the Node field must be empty.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;peerIP&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; The IP address of the peer followed by an optional port
                      number to peer with. If port number is given&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; format should be `&lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&amp;lt;IPv6&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;port`
                      or `&amp;lt;IPv4&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&amp;lt;port&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;` for IPv4. If optional port number is not set&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      and this peer IP and ASNumber belongs to a calico/node with ListenPort
                      set in BGPConfiguration&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; then we use that port to peer.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;peerSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Selector for the remote nodes to peer with.  When this
                      is set&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the PeerIP and ASNumber fields must be empty.  For each
                      peering between the local node and selected remote nodes&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; we configure
                      an IPv4 peering if both ends have NodeBGPSpec.IPv4Address specified&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      and an IPv6 peering if both ends have NodeBGPSpec.IPv6Address specified.  The
                      remote AS number comes from the remote node’s NodeBGPSpec.ASNumber&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      or the global default if that is not set.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                &lt;span class=&quot;token key atrule&quot;&gt;required&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; asNumber
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; peerIP
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
        &lt;span class=&quot;token key atrule&quot;&gt;served&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;storage&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;status&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;acceptedNames&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;conditions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;storedVersions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; apiextensions.k8s.io/v1
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CustomResourceDefinition
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;annotations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;controller-gen.kubebuilder.io/version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; (devel)
      &lt;span class=&quot;token key atrule&quot;&gt;creationTimestamp&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token null important&quot;&gt;null&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; blockaffinities.crd.projectcalico.org
    &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;group&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; crd.projectcalico.org
      &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; BlockAffinity
        &lt;span class=&quot;token key atrule&quot;&gt;listKind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; BlockAffinityList
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; blockaffinities
        &lt;span class=&quot;token key atrule&quot;&gt;singular&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; blockaffinity
      &lt;span class=&quot;token key atrule&quot;&gt;scope&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Cluster
      &lt;span class=&quot;token key atrule&quot;&gt;versions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; v1
        &lt;span class=&quot;token key atrule&quot;&gt;schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;openAPIV3Schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;APIVersion defines the versioned schema of this representation
                  of an object. Servers should convert recognized schemas to the latest
                  internal value&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;and may reject unrecognized values. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#resources&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Kind is a string value representing the REST resource this
                  object represents. Servers may infer this from the endpoint the client
                  &lt;span class=&quot;token key atrule&quot;&gt;submits requests to. Cannot be updated. In CamelCase. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#types-kinds&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
              &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; BlockAffinitySpec contains the specification for a BlockAffinity
                  resource.
                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;cidr&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;deleted&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Deleted indicates that this block affinity is being deleted.
                      This field is a string for compatibility with older releases that
                      mistakenly treat this field as a string.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;node&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;state&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                &lt;span class=&quot;token key atrule&quot;&gt;required&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; cidr
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; deleted
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; node
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; state
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
        &lt;span class=&quot;token key atrule&quot;&gt;served&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;storage&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;status&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;acceptedNames&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;conditions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;storedVersions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; apiextensions.k8s.io/v1
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CustomResourceDefinition
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;annotations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;controller-gen.kubebuilder.io/version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; (devel)
      &lt;span class=&quot;token key atrule&quot;&gt;creationTimestamp&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token null important&quot;&gt;null&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; clusterinformations.crd.projectcalico.org
    &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;group&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; crd.projectcalico.org
      &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ClusterInformation
        &lt;span class=&quot;token key atrule&quot;&gt;listKind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ClusterInformationList
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; clusterinformations
        &lt;span class=&quot;token key atrule&quot;&gt;singular&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; clusterinformation
      &lt;span class=&quot;token key atrule&quot;&gt;scope&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Cluster
      &lt;span class=&quot;token key atrule&quot;&gt;versions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; v1
        &lt;span class=&quot;token key atrule&quot;&gt;schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;openAPIV3Schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ClusterInformation contains the cluster specific information.
            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;APIVersion defines the versioned schema of this representation
                  of an object. Servers should convert recognized schemas to the latest
                  internal value&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;and may reject unrecognized values. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#resources&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Kind is a string value representing the REST resource this
                  object represents. Servers may infer this from the endpoint the client
                  &lt;span class=&quot;token key atrule&quot;&gt;submits requests to. Cannot be updated. In CamelCase. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#types-kinds&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
              &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ClusterInformationSpec contains the values of describing
                  the cluster.
                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;calicoVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CalicoVersion is the version of Calico that the cluster
                      is running
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;clusterGUID&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ClusterGUID is the GUID of the cluster
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;clusterType&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ClusterType describes the type of the cluster
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;datastoreReady&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; DatastoreReady is used during significant datastore migrations
                      to signal to components such as Felix that it should wait before
                      accessing the datastore.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;variant&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Variant declares which variant of Calico should be active.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
        &lt;span class=&quot;token key atrule&quot;&gt;served&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;storage&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;status&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;acceptedNames&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;conditions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;storedVersions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; apiextensions.k8s.io/v1
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CustomResourceDefinition
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;annotations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;controller-gen.kubebuilder.io/version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; (devel)
      &lt;span class=&quot;token key atrule&quot;&gt;creationTimestamp&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token null important&quot;&gt;null&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; felixconfigurations.crd.projectcalico.org
    &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;group&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; crd.projectcalico.org
      &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; FelixConfiguration
        &lt;span class=&quot;token key atrule&quot;&gt;listKind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; FelixConfigurationList
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; felixconfigurations
        &lt;span class=&quot;token key atrule&quot;&gt;singular&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; felixconfiguration
      &lt;span class=&quot;token key atrule&quot;&gt;scope&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Cluster
      &lt;span class=&quot;token key atrule&quot;&gt;versions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; v1
        &lt;span class=&quot;token key atrule&quot;&gt;schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;openAPIV3Schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Felix Configuration contains the configuration for Felix.
            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;APIVersion defines the versioned schema of this representation
                  of an object. Servers should convert recognized schemas to the latest
                  internal value&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;and may reject unrecognized values. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#resources&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Kind is a string value representing the REST resource this
                  object represents. Servers may infer this from the endpoint the client
                  &lt;span class=&quot;token key atrule&quot;&gt;submits requests to. Cannot be updated. In CamelCase. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#types-kinds&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
              &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; FelixConfigurationSpec contains the values of the Felix configuration.
                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;allowIPIPPacketsFromWorkloads&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;AllowIPIPPacketsFromWorkloads controls whether Felix
                      will add a rule to drop IPIP encapsulated traffic from workloads
                      &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;false&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;allowVXLANPacketsFromWorkloads&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;AllowVXLANPacketsFromWorkloads controls whether Felix
                      will add a rule to drop VXLAN encapsulated traffic from workloads
                      &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;false&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;awsSrcDstCheck&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Set source&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;destination&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;check on AWS EC2 instances. Accepted
                      value must be one of &amp;quot;DoNothing&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &amp;quot;Enabled&amp;quot; or &amp;quot;Disabled&amp;quot;. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      DoNothing&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;enum&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; DoNothing
                    &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; Enable
                    &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; Disable
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;bpfConnectTimeLoadBalancingEnabled&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;BPFConnectTimeLoadBalancingEnabled when in BPF mode&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      controls whether Felix installs the connection&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;time load balancer.  The
                      connect&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;time load balancer is required for the host to be able to
                      reach Kubernetes services and it improves the performance of pod&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;to&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;service
                      connections.  The only reason to disable it is for debugging purposes.  &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;bpfDataIfacePattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;BPFDataIfacePattern is a regular expression that controls
                      which interfaces Felix should attach BPF programs to in order to
                      catch traffic to/from the network.  This needs to match the interfaces
                      that Calico workload traffic flows over as well as any interfaces
                      that handle incoming traffic to nodeports and services from outside
                      the cluster.  It should not match the workload interfaces (usually
                      named cali&lt;span class=&quot;token punctuation&quot;&gt;...&lt;/span&gt;). &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^(en.&lt;span class=&quot;token important&quot;&gt;*|eth.*|tunl0$)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;bpfDisableUnprivileged&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;BPFDisableUnprivileged&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if enabled&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; Felix sets the kernel.unprivileged_bpf_disabled
                      sysctl to disable unprivileged use of BPF.  This ensures that unprivileged
                      users cannot access Calico&amp;#x27;&amp;#x27;s BPF maps and cannot insert their own
                      BPF programs to interfere with Calico&amp;#x27;&amp;#x27;s. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;bpfEnabled&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;BPFEnabled&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if enabled Felix will use the BPF dataplane.
                      &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;false&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;bpfExternalServiceMode&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;BPFExternalServiceMode in BPF mode&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; controls how connections
                      from outside the cluster to services (node ports and cluster IPs)
                      are forwarded to remote workloads.  If set to &amp;quot;Tunnel&amp;quot; then both
                      request and response traffic is tunneled to the remote node.  If
                      set to &amp;quot;DSR&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the request traffic is tunneled but the response traffic
                      is sent directly from the remote node.  In &amp;quot;DSR&amp;quot; mode&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the remote
                      node appears to use the IP of the ingress node; this requires a
                      permissive L2 network.  &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Tunnel&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;bpfKubeProxyEndpointSlicesEnabled&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; BPFKubeProxyEndpointSlicesEnabled in BPF mode&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; controls
                      whether Felix&amp;#x27;s embedded kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;proxy accepts EndpointSlices or not.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;bpfKubeProxyIptablesCleanupEnabled&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;BPFKubeProxyIptablesCleanupEnabled&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if enabled in BPF
                      mode&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; Felix will proactively clean up the upstream Kubernetes kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;proxy&amp;#x27;&amp;#x27;s
                      iptables chains.  Should only be enabled if kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;proxy is not running.  &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;bpfKubeProxyMinSyncPeriod&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;BPFKubeProxyMinSyncPeriod&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; in BPF mode&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; controls the
                      minimum time between updates to the dataplane for Felix&amp;#x27;&amp;#x27;s embedded
                      kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;proxy.  Lower values give reduced set&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;up latency.  Higher values
                      reduce Felix CPU usage by batching up more work.  &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 1s&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;bpfLogLevel&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;BPFLogLevel controls the log level of the BPF programs
                      when in BPF dataplane mode.  One of &amp;quot;Off&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;Info&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; or &amp;quot;Debug&amp;quot;.  The
                      logs are emitted to the BPF trace pipe&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; accessible with the command
                      `tc exec bpf debug`. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Off&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;.&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;chainInsertMode&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;ChainInsertMode controls whether Felix hooks the kernel’s
                      top&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;level iptables chains by inserting a rule at the top of the
                      chain or by appending a rule at the bottom. insert is the safe default
                      since it prevents Calico’s rules from being bypassed. If you switch
                      to append mode&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; be sure that the other rules in the chains signal
                      acceptance by falling through to the Calico rules&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; otherwise the
                      Calico policy will be bypassed. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; insert&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;dataplaneDriver&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;debugDisableLogDropping&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;debugMemoryProfilePath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;debugSimulateCalcGraphHangAfter&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;debugSimulateDataplaneHangAfter&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;defaultEndpointToHostAction&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;DefaultEndpointToHostAction controls what happens to
                      traffic that goes from a workload endpoint to the host itself (after
                      the traffic hits the endpoint egress policy). By default Calico
                      blocks traffic from workload endpoints to the host itself with an
                      iptables “DROP” action. If you want to allow some or all traffic
                      from endpoint to host&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; set this parameter to RETURN or ACCEPT. Use
                      RETURN if you have your own rules in the iptables “INPUT” chain;
                      Calico will insert its rules at the top of that chain&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; then “RETURN”
                      packets to the “INPUT” chain once it has completed processing workload
                      endpoint egress policy. Use ACCEPT to unconditionally accept packets
                      from workloads after processing workload endpoint egress policy.
                      &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Drop&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;deviceRouteProtocol&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; This defines the route protocol added to programmed device
                      routes&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; by default this will be RTPROT_BOOT when left blank.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                  &lt;span class=&quot;token key atrule&quot;&gt;deviceRouteSourceAddress&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; This is the source address to use on programmed device
                      routes. By default the source address is left blank&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; leaving the
                      kernel to choose the source address used.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;disableConntrackInvalidCheck&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;endpointReportingDelay&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;endpointReportingEnabled&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;externalNodesList&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ExternalNodesCIDRList is a list of CIDR&amp;#x27;s of external&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;non&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;nodes
                      which may source tunnel traffic and have the tunneled traffic be
                      accepted at calico nodes.
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                  &lt;span class=&quot;token key atrule&quot;&gt;failsafeInboundHostPorts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;FailsafeInboundHostPorts is a comma&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;delimited list of
                      UDP/TCP ports that Felix will allow incoming traffic to host endpoints
                      on irrespective of the security policy. This is useful to avoid
                      accidentally cutting off a host with incorrect configuration. Each
                      port should be specified as tcp&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&amp;lt;port&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;number&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt; or udp&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&amp;lt;port&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;number&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;.
                      For back&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;compatibility&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if the protocol is not specified&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; it defaults
                      to “tcp”. To disable all inbound host ports&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; use the value none.
                      The default value allows ssh access and DHCP. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; tcp&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;22&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      udp&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;68&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; tcp&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;179&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; tcp&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;2379&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; tcp&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;2380&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; tcp&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;6443&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; tcp&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;6666&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; tcp&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;6667&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ProtoPort is combination of protocol and port&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; both
                        must be specified.
                      &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;port&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                        &lt;span class=&quot;token key atrule&quot;&gt;protocol&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                      &lt;span class=&quot;token key atrule&quot;&gt;required&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; port
                      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; protocol
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                  &lt;span class=&quot;token key atrule&quot;&gt;failsafeOutboundHostPorts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;FailsafeOutboundHostPorts is a comma&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;delimited list
                      of UDP/TCP ports that Felix will allow outgoing traffic from host
                      endpoints to irrespective of the security policy. This is useful
                      to avoid accidentally cutting off a host with incorrect configuration.
                      Each port should be specified as tcp&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&amp;lt;port&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;number&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt; or udp&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&amp;lt;port&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;number&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;.
                      For back&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;compatibility&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if the protocol is not specified&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; it defaults
                      to “tcp”. To disable all outbound host ports&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; use the value none.
                      The default value opens etcd’s standard ports to ensure that Felix
                      does not get cut off from etcd as well as allowing DHCP and DNS.
                      &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; tcp&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;179&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; tcp&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;2379&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; tcp&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;2380&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; tcp&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;6443&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; tcp&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;6666&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; tcp&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;6667&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      udp&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;53&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; udp&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;67&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ProtoPort is combination of protocol and port&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; both
                        must be specified.
                      &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;port&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                        &lt;span class=&quot;token key atrule&quot;&gt;protocol&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                      &lt;span class=&quot;token key atrule&quot;&gt;required&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; port
                      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; protocol
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                  &lt;span class=&quot;token key atrule&quot;&gt;featureDetectOverride&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; FeatureDetectOverride is used to override the feature
                      detection. Values are specified in a comma separated list with no
                      spaces&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; example; &amp;quot;SNATFullyRandom=true&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;MASQFullyRandom=false&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;RestoreSupportsLock=&amp;quot;.
                      &amp;quot;true&amp;quot; or &amp;quot;false&amp;quot; will force the feature&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; empty or omitted values
                      are auto&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;detected.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;genericXDPEnabled&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;GenericXDPEnabled enables Generic XDP so network cards
                      that don&amp;#x27;&amp;#x27;t support XDP offload or driver modes can use XDP. This
                      is not recommended since it doesn&amp;#x27;&amp;#x27;t provide better performance
                      than iptables. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;false&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;healthEnabled&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;healthHost&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;healthPort&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                  &lt;span class=&quot;token key atrule&quot;&gt;interfaceExclude&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;InterfaceExclude is a comma&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;separated list of interfaces
                      that Felix should exclude when monitoring for host endpoints. The
                      default value ensures that Felix ignores Kubernetes&amp;#x27;&amp;#x27; IPVS dummy
                      interface&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; which is used internally by kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;proxy. If you want to
                      exclude multiple interface names using a single value&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the list
                      supports regular expressions. For regular expressions you must wrap
                      the value with &amp;#x27;&amp;#x27;/&amp;#x27;&amp;#x27;. For example having values &amp;#x27;&amp;#x27;/^kube/&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;veth1&amp;#x27;&amp;#x27;
                      will exclude all interfaces that begin with &amp;#x27;&amp;#x27;kube&amp;#x27;&amp;#x27; and also the
                      interface &amp;#x27;&amp;#x27;veth1&amp;#x27;&amp;#x27;. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;ipvs0&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;interfacePrefix&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;InterfacePrefix is the interface name prefix that identifies
                      workload endpoints and so distinguishes them from host endpoint
                      &lt;span class=&quot;token key atrule&quot;&gt;interfaces. Note&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; in environments other than bare metal&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the orchestrators
                      configure this appropriately. For example our Kubernetes and Docker
                      integrations set the ‘cali’ value&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; and our OpenStack integration
                      sets the ‘tap’ value. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; cali&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;interfaceRefreshInterval&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; InterfaceRefreshInterval is the period at which Felix
                      rescans local interfaces to verify their state. The rescan can be
                      disabled by setting the interval to 0.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;ipipEnabled&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;ipipMTU&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;IPIPMTU is the MTU to set on the tunnel device. See
                      Configuring MTU &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;1440&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                  &lt;span class=&quot;token key atrule&quot;&gt;ipsetsRefreshInterval&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;IpsetsRefreshInterval is the period at which Felix re&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;checks
                      all iptables state to ensure that no other process has accidentally
                      broken Calico’s rules. Set to 0 to disable iptables refresh. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      90s&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;iptablesBackend&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; IptablesBackend specifies which backend of iptables will
                      be used. The default is legacy.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;iptablesFilterAllowAction&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;iptablesLockFilePath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;IptablesLockFilePath is the location of the iptables
                      lock file. You may need to change this if the lock file is not in
                      its standard location (for example if you have mapped it into Felix’s
                      container at a different path). &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /run/xtables.lock&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;iptablesLockProbeInterval&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;IptablesLockProbeInterval is the time that Felix will
                      wait between attempts to acquire the iptables lock if it is not
                      available. Lower values make Felix more responsive when the lock
                      is contended&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; but use more CPU. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 50ms&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;iptablesLockTimeout&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;IptablesLockTimeout is the time that Felix will wait
                      for the iptables lock&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; or 0&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; to disable. To use this feature&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; Felix
                      must share the iptables lock file with all other processes that
                      also take the lock. When running Felix inside a container&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; this
                      requires the /run directory of the host to be mounted into the calico/node
                      or calico/felix container. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 0s disabled&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;iptablesMangleAllowAction&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;iptablesMarkMask&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;IptablesMarkMask is the mask that Felix selects its
                      IPTables Mark bits from. Should be a 32 bit hexadecimal number with
                      at least 8 bits set&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; none of which clash with any other mark bits
                      in use on the system. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;0xff000000&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;format&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; int32
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                  &lt;span class=&quot;token key atrule&quot;&gt;iptablesNATOutgoingInterfaceFilter&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;iptablesPostWriteCheckInterval&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;IptablesPostWriteCheckInterval is the period after Felix
                      has done a write to the dataplane that it schedules an extra read
                      back in order to check the write was not clobbered by another process.
                      This should only occur if another application on the system doesn’t
                      respect the iptables lock. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 1s&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;iptablesRefreshInterval&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;IptablesRefreshInterval is the period at which Felix
                      re&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;checks the IP sets in the dataplane to ensure that no other process
                      has accidentally broken Calico’s rules. Set to 0 to disable IP sets
                      &lt;span class=&quot;token key atrule&quot;&gt;refresh. Note&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; the default for this value is lower than the other
                      refresh intervals as a workaround for a Linux kernel bug that was
                      fixed in kernel version 4.11. If you are using v4.11 or greater
                      you may want to set this to&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; a higher value to reduce Felix CPU
                      usage. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 10s&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;ipv6Support&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;kubeNodePortRanges&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;KubeNodePortRanges holds list of port ranges used for
                      service node ports. Only used if felix detects kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;proxy running
                      in ipvs mode. Felix uses these ranges to separate host and workload
                      traffic. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 30000&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;32767&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;.&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                      &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                      &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                  &lt;span class=&quot;token key atrule&quot;&gt;logFilePath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;LogFilePath is the full path to the Felix log. Set to
                      none to disable file logging. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /var/log/calico/felix.log&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;logPrefix&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;LogPrefix is the log prefix that Felix uses when rendering
                      LOG rules. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;packet&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;logSeverityFile&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;LogSeverityFile is the log severity above which logs
                      are sent to the log file. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Info&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;logSeverityScreen&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;LogSeverityScreen is the log severity above which logs
                      are sent to the stdout. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Info&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;logSeveritySys&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;LogSeveritySys is the log severity above which logs
                      are sent to the syslog. Set to None for no logging to syslog. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      Info&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;maxIpsetSize&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                  &lt;span class=&quot;token key atrule&quot;&gt;metadataAddr&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;MetadataAddr is the IP address or domain name of the
                      server that can answer VM queries for cloud&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;init metadata. In OpenStack&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      this corresponds to the machine running nova&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;api (or in Ubuntu&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      nova&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;metadata). A value of none (case insensitive) means that
                      Felix should not set up any NAT rule for the metadata path. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      127.0.0.1&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;metadataPort&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;MetadataPort is the port of the metadata server. This&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      combined with global.MetadataAddr (if not ‘None’)&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; is used to set
                      up a NAT rule&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; from 169.254.169.254&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;80 to MetadataAddr&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;MetadataPort.
                      In most cases this should not need to be changed &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;8775&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;.&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                  &lt;span class=&quot;token key atrule&quot;&gt;natOutgoingAddress&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NATOutgoingAddress specifies an address to use when performing
                      source NAT for traffic in a natOutgoing pool that is leaving the
                      network. By default the address used is an address on the interface
                      the traffic is leaving on (ie it uses the iptables MASQUERADE target)
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;natPortRange&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                    &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NATPortRange specifies the range of ports that is used
                      for port mapping when doing outgoing NAT. When unset the default
                      behavior of the network stack is used.
                    &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                    &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;netlinkTimeout&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;openstackRegion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;OpenstackRegion is the name of the region that a particular
                      Felix belongs to. In a multi&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;region Calico/OpenStack deployment&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      this must be configured somehow for each Felix (here in the datamodel&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      or in felix.cfg or the environment on each compute node)&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; and must
                      match the &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;calico&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt; openstack_region value configured in neutron.conf
                      on each node. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Empty&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;policySyncPathPrefix&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;PolicySyncPathPrefix is used to by Felix to communicate
                      policy changes to external services&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; like Application layer policy.
                      &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Empty&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;prometheusGoMetricsEnabled&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;PrometheusGoMetricsEnabled disables Go runtime metrics
                      collection&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; which the Prometheus client does by default&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; when set
                      to false. This reduces the number of metrics reported&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; reducing
                      Prometheus load. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;prometheusMetricsEnabled&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;PrometheusMetricsEnabled enables the Prometheus metrics
                      server in Felix if set to true. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;false&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;prometheusMetricsHost&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;PrometheusMetricsHost is the host that the Prometheus
                      metrics server should bind to. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; empty&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;prometheusMetricsPort&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;PrometheusMetricsPort is the TCP port that the Prometheus
                      metrics server should bind to. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;9091&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                  &lt;span class=&quot;token key atrule&quot;&gt;prometheusProcessMetricsEnabled&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;PrometheusProcessMetricsEnabled disables process metrics
                      collection&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; which the Prometheus client does by default&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; when set
                      to false. This reduces the number of metrics reported&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; reducing
                      Prometheus load. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;removeExternalRoutes&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Whether or not to remove device routes that have not
                      been programmed by Felix. Disabling this will allow external applications
                      to also add device routes. This is enabled by default which means
                      we will remove externally added routes.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;reportingInterval&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;ReportingInterval is the interval at which Felix reports
                      its status into the datastore or 0 to disable. Must be non&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;zero
                      in OpenStack deployments. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 30s&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;reportingTTL&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;ReportingTTL is the time&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;to&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;live setting for process&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;wide
                      status reports. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 90s&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;routeRefreshInterval&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;RouterefreshInterval is the period at which Felix re&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;checks
                      the routes in the dataplane to ensure that no other process has
                      accidentally broken Calico’s rules. Set to 0 to disable route refresh.
                      &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 90s&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;routeSource&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;RouteSource configures where Felix gets its routing
                      &lt;span class=&quot;token key atrule&quot;&gt;information. - WorkloadIPs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; use workload endpoints to construct
                      &lt;span class=&quot;token key atrule&quot;&gt;routes. - CalicoIPAM&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; the default &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; use IPAM data to construct routes.&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;routeTableRange&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Calico programs additional Linux route tables for various
                      purposes.  RouteTableRange specifies the indices of the route tables
                      that Calico should use.
                    &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;max&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                      &lt;span class=&quot;token key atrule&quot;&gt;min&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                    &lt;span class=&quot;token key atrule&quot;&gt;required&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; max
                    &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; min
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                  &lt;span class=&quot;token key atrule&quot;&gt;sidecarAccelerationEnabled&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;SidecarAccelerationEnabled enables experimental sidecar
                      acceleration &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;false&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;usageReportingEnabled&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;UsageReportingEnabled reports anonymous Calico version
                      number and cluster size to projectcalico.org. Logs warnings returned
                      by the usage server. For example&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if a significant security vulnerability
                      has been discovered in the version of Calico being used. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;usageReportingInitialDelay&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;UsageReportingInitialDelay controls the minimum delay
                      before Felix makes a report. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 300s&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;usageReportingInterval&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;UsageReportingInterval controls the interval at which
                      Felix makes reports. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 86400s&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;useInternalDataplaneDriver&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;vxlanEnabled&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;vxlanMTU&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;VXLANMTU is the MTU to set on the tunnel device. See
                      Configuring MTU &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;1440&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                  &lt;span class=&quot;token key atrule&quot;&gt;vxlanPort&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                  &lt;span class=&quot;token key atrule&quot;&gt;vxlanVNI&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                  &lt;span class=&quot;token key atrule&quot;&gt;wireguardEnabled&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;WireguardEnabled controls whether Wireguard is enabled.
                      &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;false&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;wireguardInterfaceName&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;WireguardInterfaceName specifies the name to use for
                      the Wireguard interface. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; wg.calico&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;wireguardListeningPort&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;WireguardListeningPort controls the listening port used
                      by Wireguard. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;51820&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                  &lt;span class=&quot;token key atrule&quot;&gt;wireguardMTU&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;WireguardMTU controls the MTU on the Wireguard interface.
                      See Configuring MTU &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;1420&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                  &lt;span class=&quot;token key atrule&quot;&gt;wireguardRoutingRulePriority&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;WireguardRoutingRulePriority controls the priority value
                      to use for the Wireguard routing rule. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;99&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                  &lt;span class=&quot;token key atrule&quot;&gt;xdpEnabled&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;XDPEnabled enables XDP acceleration for suitable untracked
                      incoming deny rules. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;xdpRefreshInterval&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;XDPRefreshInterval is the period at which Felix re&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;checks
                      all XDP state to ensure that no other process has accidentally broken
                      Calico&amp;#x27;&amp;#x27;s BPF maps or attached programs. Set to 0 to disable XDP
                      refresh. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 90s&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
        &lt;span class=&quot;token key atrule&quot;&gt;served&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;storage&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;status&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;acceptedNames&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;conditions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;storedVersions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; apiextensions.k8s.io/v1
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CustomResourceDefinition
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;annotations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;controller-gen.kubebuilder.io/version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; (devel)
      &lt;span class=&quot;token key atrule&quot;&gt;creationTimestamp&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token null important&quot;&gt;null&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; globalnetworkpolicies.crd.projectcalico.org
    &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;group&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; crd.projectcalico.org
      &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; GlobalNetworkPolicy
        &lt;span class=&quot;token key atrule&quot;&gt;listKind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; GlobalNetworkPolicyList
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; globalnetworkpolicies
        &lt;span class=&quot;token key atrule&quot;&gt;singular&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; globalnetworkpolicy
      &lt;span class=&quot;token key atrule&quot;&gt;scope&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Cluster
      &lt;span class=&quot;token key atrule&quot;&gt;versions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; v1
        &lt;span class=&quot;token key atrule&quot;&gt;schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;openAPIV3Schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;APIVersion defines the versioned schema of this representation
                  of an object. Servers should convert recognized schemas to the latest
                  internal value&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;and may reject unrecognized values. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#resources&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Kind is a string value representing the REST resource this
                  object represents. Servers may infer this from the endpoint the client
                  &lt;span class=&quot;token key atrule&quot;&gt;submits requests to. Cannot be updated. In CamelCase. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#types-kinds&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
              &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;applyOnForward&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ApplyOnForward indicates to apply the rules in this policy
                      on forward traffic.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;doNotTrack&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; DoNotTrack indicates whether packets matched by the rules
                      in this policy should go through the data plane&amp;#x27;s connection tracking&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      such as Linux conntrack.  If True&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the rules in this policy are
                      applied before any data plane connection tracking&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; and packets allowed
                      by this policy are marked as not to be tracked.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;egress&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; The ordered set of egress rules.  Each rule contains
                      a set of packet match criteria and a corresponding action to apply.
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;A Rule encapsulates a set of match criteria and an
                        action.  Both selector&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;based security Policy and security Profiles
                        reference rules &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; separated out as a list of rules for both ingress
                        and egress packet matching. \n Each positive match criteria has
                        a negated version&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; prefixed with ”Not”. All the match criteria
                        within a rule must be satisfied for a packet to match. A single
                        rule can contain the positive and negative version of a match
                        and both must be satisfied for the rule to match.&amp;quot;
                      &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;action&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                        &lt;span class=&quot;token key atrule&quot;&gt;destination&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Destination contains the match criteria that apply
                            to destination entity.
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;namespaceSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;NamespaceSelector is an optional field that
                                contains a selector expression. Only traffic that originates
                                from (or terminates at) endpoints within the selected
                                namespaces will be matched. When both NamespaceSelector
                                and Selector are defined on the same rule&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; then only workload
                                endpoints that are matched by both selectors will be selected
                                by the rule. \n For NetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; an empty NamespaceSelector
                                implies that the Selector is limited to selecting only
                                workload endpoints in the same namespace as the NetworkPolicy.
                                \n For NetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; `global()` NamespaceSelector implies
                                that the Selector is limited to selecting only GlobalNetworkSet
                                or HostEndpoint. \n For GlobalNetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; an empty
                                NamespaceSelector implies the Selector applies to workload
                                endpoints across all namespaces.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;nets&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Nets is an optional field that restricts the
                                rule to only apply to traffic that originates from (or
                                terminates at) IP addresses in any of the given subnets.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notNets&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotNets is the negated version of the Nets
                                field.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notPorts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotPorts is the negated version of the Ports
                                field. Since only some protocols have ports&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if any ports
                                are specified it requires the Protocol match in the Rule
                                to be set to &amp;quot;TCP&amp;quot; or &amp;quot;UDP&amp;quot;.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                                &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotSelector is the negated version of the Selector
                                field.  See Selector field for subtleties with negated
                                selectors.
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;ports&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Ports is an optional field that restricts
                                the rule to only apply to traffic that has a source (destination)
                                port that matches one of these ranges/values. This value
                                is a list of integers or strings that represent ranges
                                of ports. \n Since only some protocols have ports&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if
                                any ports are specified it requires the Protocol match
                                in the Rule to be set to \&amp;quot;TCP\&amp;quot; or \&amp;quot;UDP\&amp;quot;.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                                &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Selector is an optional field that contains
                                a selector expression (see Policy for sample syntax).
                                \ Only traffic that originates from (terminates at) endpoints
                                &lt;span class=&quot;token key atrule&quot;&gt;matching the selector will be matched. \n Note that&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; in
                                addition to the negated version of the Selector (see NotSelector
                                below)&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the selector expression syntax itself supports
                                negation.  The two types of negation are subtly different.
                                One negates the set of matched endpoints&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the other negates
                                &lt;span class=&quot;token key atrule&quot;&gt;the whole match&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; \n \tSelector = \&amp;quot;&lt;span class=&quot;token tag&quot;&gt;!has(my_label)&lt;/span&gt;\&amp;quot; matches
                                packets that are from other Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled \tendpoints
                                that do not have the label “my_label”. \n \tNotSelector
                                = \&amp;quot;has(my_label)\&amp;quot; matches packets that are not from
                                Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled \tendpoints that do have the label “my_label”.
                                \n The effect is that the latter will accept packets from
                                non&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Calico sources whereas the former is limited to packets
                                from Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled endpoints.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;serviceAccounts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ServiceAccounts is an optional field that restricts
                                the rule to only apply to traffic that originates from
                                (or terminates at) a pod running as a matching service
                                account.
                              &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Names is an optional field that restricts
                                    the rule to only apply to traffic that originates
                                    from (or terminates at) a pod running as a service
                                    account whose name is in the list.
                                  &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                  &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                                &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Selector is an optional field that restricts
                                    the rule to only apply to traffic that originates
                                    from (or terminates at) a pod running as a service
                                    account that matches the given label selector. If
                                    both Names and Selector are specified then they are
                                    AND&amp;#x27;ed.
                                  &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;http&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; HTTP contains match criteria that apply to HTTP
                            requests.
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;methods&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Methods is an optional field that restricts
                                the rule to apply only to HTTP requests that use one of
                                the listed HTTP Methods (e.g. GET&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; PUT&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; etc.) Multiple
                                methods are OR&amp;#x27;d together.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;paths&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Paths is an optional field that restricts
                                the rule to apply to HTTP requests that use one of the
                                listed HTTP Paths. Multiple paths are OR&amp;#x27;&amp;#x27;d together.
                                &lt;span class=&quot;token key atrule&quot;&gt;e.g&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;exact&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;/foo - prefix&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;/bar NOTE&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Each entry may
                                ONLY specify either a `exact` or a `prefix` match. The
                                validator will check for it.&amp;#x27;
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;HTTPPath specifies an HTTP path to match.
                                  &lt;span class=&quot;token key atrule&quot;&gt;It may be either of the form&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;exact&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;&amp;lt;path&amp;gt;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; which matches
                                  &lt;span class=&quot;token key atrule&quot;&gt;the path exactly or prefix&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;&amp;lt;path-prefix&amp;gt;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; which matches
                                  the path prefix&amp;#x27;
                                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;exact&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                  &lt;span class=&quot;token key atrule&quot;&gt;prefix&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;icmp&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ICMP is an optional field that restricts the rule
                            to apply to a specific type and code of ICMP traffic.  This
                            should only be specified if the Protocol field is set to &amp;quot;ICMP&amp;quot;
                            or &amp;quot;ICMPv6&amp;quot;.
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;code&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Match on a specific ICMP code.  If specified&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                                the Type value must also be specified. This is a technical
                                limitation imposed by the kernel’s iptables firewall&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                                which Calico uses to enforce the rule.
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Match on a specific ICMP type.  For example
                                a value of 8 refers to ICMP Echo Request (i.e. pings).
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;ipVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; IPVersion is an optional field that restricts the
                            rule to only match a specific IP version.
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                        &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Metadata contains additional information for this
                            rule
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;annotations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;additionalProperties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Annotations is a set of key value pairs that
                                give extra information about the rule
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;notICMP&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotICMP is the negated version of the ICMP field.
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;code&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Match on a specific ICMP code.  If specified&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                                the Type value must also be specified. This is a technical
                                limitation imposed by the kernel’s iptables firewall&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                                which Calico uses to enforce the rule.
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Match on a specific ICMP type.  For example
                                a value of 8 refers to ICMP Echo Request (i.e. pings).
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;notProtocol&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotProtocol is the negated version of the Protocol
                            field.
                          &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                          &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;protocol&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Protocol is an optional field that restricts the
                            rule to only apply to traffic of a specific IP protocol. Required
                            if any of the EntityRules contain Ports (because ports only
                            apply to certain protocols). \n Must be one of these string
                            &lt;span class=&quot;token key atrule&quot;&gt;values&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; \&amp;quot;TCP\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;UDP\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;ICMP\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;ICMPv6\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;SCTP\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                            \&amp;quot;UDPLite\&amp;quot; or an integer in the range 1&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;255.&amp;quot;
                          &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                          &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;source&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Source contains the match criteria that apply to
                            source entity.
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;namespaceSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;NamespaceSelector is an optional field that
                                contains a selector expression. Only traffic that originates
                                from (or terminates at) endpoints within the selected
                                namespaces will be matched. When both NamespaceSelector
                                and Selector are defined on the same rule&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; then only workload
                                endpoints that are matched by both selectors will be selected
                                by the rule. \n For NetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; an empty NamespaceSelector
                                implies that the Selector is limited to selecting only
                                workload endpoints in the same namespace as the NetworkPolicy.
                                \n For NetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; `global()` NamespaceSelector implies
                                that the Selector is limited to selecting only GlobalNetworkSet
                                or HostEndpoint. \n For GlobalNetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; an empty
                                NamespaceSelector implies the Selector applies to workload
                                endpoints across all namespaces.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;nets&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Nets is an optional field that restricts the
                                rule to only apply to traffic that originates from (or
                                terminates at) IP addresses in any of the given subnets.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notNets&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotNets is the negated version of the Nets
                                field.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notPorts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotPorts is the negated version of the Ports
                                field. Since only some protocols have ports&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if any ports
                                are specified it requires the Protocol match in the Rule
                                to be set to &amp;quot;TCP&amp;quot; or &amp;quot;UDP&amp;quot;.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                                &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotSelector is the negated version of the Selector
                                field.  See Selector field for subtleties with negated
                                selectors.
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;ports&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Ports is an optional field that restricts
                                the rule to only apply to traffic that has a source (destination)
                                port that matches one of these ranges/values. This value
                                is a list of integers or strings that represent ranges
                                of ports. \n Since only some protocols have ports&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if
                                any ports are specified it requires the Protocol match
                                in the Rule to be set to \&amp;quot;TCP\&amp;quot; or \&amp;quot;UDP\&amp;quot;.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                                &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Selector is an optional field that contains
                                a selector expression (see Policy for sample syntax).
                                \ Only traffic that originates from (terminates at) endpoints
                                &lt;span class=&quot;token key atrule&quot;&gt;matching the selector will be matched. \n Note that&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; in
                                addition to the negated version of the Selector (see NotSelector
                                below)&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the selector expression syntax itself supports
                                negation.  The two types of negation are subtly different.
                                One negates the set of matched endpoints&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the other negates
                                &lt;span class=&quot;token key atrule&quot;&gt;the whole match&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; \n \tSelector = \&amp;quot;&lt;span class=&quot;token tag&quot;&gt;!has(my_label)&lt;/span&gt;\&amp;quot; matches
                                packets that are from other Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled \tendpoints
                                that do not have the label “my_label”. \n \tNotSelector
                                = \&amp;quot;has(my_label)\&amp;quot; matches packets that are not from
                                Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled \tendpoints that do have the label “my_label”.
                                \n The effect is that the latter will accept packets from
                                non&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Calico sources whereas the former is limited to packets
                                from Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled endpoints.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;serviceAccounts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ServiceAccounts is an optional field that restricts
                                the rule to only apply to traffic that originates from
                                (or terminates at) a pod running as a matching service
                                account.
                              &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Names is an optional field that restricts
                                    the rule to only apply to traffic that originates
                                    from (or terminates at) a pod running as a service
                                    account whose name is in the list.
                                  &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                  &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                                &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Selector is an optional field that restricts
                                    the rule to only apply to traffic that originates
                                    from (or terminates at) a pod running as a service
                                    account that matches the given label selector. If
                                    both Names and Selector are specified then they are
                                    AND&amp;#x27;ed.
                                  &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                      &lt;span class=&quot;token key atrule&quot;&gt;required&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; action
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                  &lt;span class=&quot;token key atrule&quot;&gt;ingress&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; The ordered set of ingress rules.  Each rule contains
                      a set of packet match criteria and a corresponding action to apply.
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;A Rule encapsulates a set of match criteria and an
                        action.  Both selector&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;based security Policy and security Profiles
                        reference rules &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; separated out as a list of rules for both ingress
                        and egress packet matching. \n Each positive match criteria has
                        a negated version&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; prefixed with ”Not”. All the match criteria
                        within a rule must be satisfied for a packet to match. A single
                        rule can contain the positive and negative version of a match
                        and both must be satisfied for the rule to match.&amp;quot;
                      &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;action&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                        &lt;span class=&quot;token key atrule&quot;&gt;destination&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Destination contains the match criteria that apply
                            to destination entity.
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;namespaceSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;NamespaceSelector is an optional field that
                                contains a selector expression. Only traffic that originates
                                from (or terminates at) endpoints within the selected
                                namespaces will be matched. When both NamespaceSelector
                                and Selector are defined on the same rule&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; then only workload
                                endpoints that are matched by both selectors will be selected
                                by the rule. \n For NetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; an empty NamespaceSelector
                                implies that the Selector is limited to selecting only
                                workload endpoints in the same namespace as the NetworkPolicy.
                                \n For NetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; `global()` NamespaceSelector implies
                                that the Selector is limited to selecting only GlobalNetworkSet
                                or HostEndpoint. \n For GlobalNetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; an empty
                                NamespaceSelector implies the Selector applies to workload
                                endpoints across all namespaces.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;nets&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Nets is an optional field that restricts the
                                rule to only apply to traffic that originates from (or
                                terminates at) IP addresses in any of the given subnets.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notNets&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotNets is the negated version of the Nets
                                field.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notPorts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotPorts is the negated version of the Ports
                                field. Since only some protocols have ports&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if any ports
                                are specified it requires the Protocol match in the Rule
                                to be set to &amp;quot;TCP&amp;quot; or &amp;quot;UDP&amp;quot;.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                                &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotSelector is the negated version of the Selector
                                field.  See Selector field for subtleties with negated
                                selectors.
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;ports&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Ports is an optional field that restricts
                                the rule to only apply to traffic that has a source (destination)
                                port that matches one of these ranges/values. This value
                                is a list of integers or strings that represent ranges
                                of ports. \n Since only some protocols have ports&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if
                                any ports are specified it requires the Protocol match
                                in the Rule to be set to \&amp;quot;TCP\&amp;quot; or \&amp;quot;UDP\&amp;quot;.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                                &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Selector is an optional field that contains
                                a selector expression (see Policy for sample syntax).
                                \ Only traffic that originates from (terminates at) endpoints
                                &lt;span class=&quot;token key atrule&quot;&gt;matching the selector will be matched. \n Note that&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; in
                                addition to the negated version of the Selector (see NotSelector
                                below)&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the selector expression syntax itself supports
                                negation.  The two types of negation are subtly different.
                                One negates the set of matched endpoints&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the other negates
                                &lt;span class=&quot;token key atrule&quot;&gt;the whole match&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; \n \tSelector = \&amp;quot;&lt;span class=&quot;token tag&quot;&gt;!has(my_label)&lt;/span&gt;\&amp;quot; matches
                                packets that are from other Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled \tendpoints
                                that do not have the label “my_label”. \n \tNotSelector
                                = \&amp;quot;has(my_label)\&amp;quot; matches packets that are not from
                                Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled \tendpoints that do have the label “my_label”.
                                \n The effect is that the latter will accept packets from
                                non&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Calico sources whereas the former is limited to packets
                                from Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled endpoints.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;serviceAccounts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ServiceAccounts is an optional field that restricts
                                the rule to only apply to traffic that originates from
                                (or terminates at) a pod running as a matching service
                                account.
                              &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Names is an optional field that restricts
                                    the rule to only apply to traffic that originates
                                    from (or terminates at) a pod running as a service
                                    account whose name is in the list.
                                  &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                  &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                                &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Selector is an optional field that restricts
                                    the rule to only apply to traffic that originates
                                    from (or terminates at) a pod running as a service
                                    account that matches the given label selector. If
                                    both Names and Selector are specified then they are
                                    AND&amp;#x27;ed.
                                  &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;http&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; HTTP contains match criteria that apply to HTTP
                            requests.
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;methods&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Methods is an optional field that restricts
                                the rule to apply only to HTTP requests that use one of
                                the listed HTTP Methods (e.g. GET&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; PUT&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; etc.) Multiple
                                methods are OR&amp;#x27;d together.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;paths&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Paths is an optional field that restricts
                                the rule to apply to HTTP requests that use one of the
                                listed HTTP Paths. Multiple paths are OR&amp;#x27;&amp;#x27;d together.
                                &lt;span class=&quot;token key atrule&quot;&gt;e.g&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;exact&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;/foo - prefix&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;/bar NOTE&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Each entry may
                                ONLY specify either a `exact` or a `prefix` match. The
                                validator will check for it.&amp;#x27;
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;HTTPPath specifies an HTTP path to match.
                                  &lt;span class=&quot;token key atrule&quot;&gt;It may be either of the form&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;exact&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;&amp;lt;path&amp;gt;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; which matches
                                  &lt;span class=&quot;token key atrule&quot;&gt;the path exactly or prefix&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;&amp;lt;path-prefix&amp;gt;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; which matches
                                  the path prefix&amp;#x27;
                                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;exact&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                  &lt;span class=&quot;token key atrule&quot;&gt;prefix&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;icmp&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ICMP is an optional field that restricts the rule
                            to apply to a specific type and code of ICMP traffic.  This
                            should only be specified if the Protocol field is set to &amp;quot;ICMP&amp;quot;
                            or &amp;quot;ICMPv6&amp;quot;.
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;code&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Match on a specific ICMP code.  If specified&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                                the Type value must also be specified. This is a technical
                                limitation imposed by the kernel’s iptables firewall&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                                which Calico uses to enforce the rule.
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Match on a specific ICMP type.  For example
                                a value of 8 refers to ICMP Echo Request (i.e. pings).
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;ipVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; IPVersion is an optional field that restricts the
                            rule to only match a specific IP version.
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                        &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Metadata contains additional information for this
                            rule
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;annotations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;additionalProperties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Annotations is a set of key value pairs that
                                give extra information about the rule
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;notICMP&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotICMP is the negated version of the ICMP field.
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;code&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Match on a specific ICMP code.  If specified&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                                the Type value must also be specified. This is a technical
                                limitation imposed by the kernel’s iptables firewall&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                                which Calico uses to enforce the rule.
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Match on a specific ICMP type.  For example
                                a value of 8 refers to ICMP Echo Request (i.e. pings).
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;notProtocol&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotProtocol is the negated version of the Protocol
                            field.
                          &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                          &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;protocol&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Protocol is an optional field that restricts the
                            rule to only apply to traffic of a specific IP protocol. Required
                            if any of the EntityRules contain Ports (because ports only
                            apply to certain protocols). \n Must be one of these string
                            &lt;span class=&quot;token key atrule&quot;&gt;values&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; \&amp;quot;TCP\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;UDP\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;ICMP\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;ICMPv6\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;SCTP\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                            \&amp;quot;UDPLite\&amp;quot; or an integer in the range 1&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;255.&amp;quot;
                          &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                          &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;source&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Source contains the match criteria that apply to
                            source entity.
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;namespaceSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;NamespaceSelector is an optional field that
                                contains a selector expression. Only traffic that originates
                                from (or terminates at) endpoints within the selected
                                namespaces will be matched. When both NamespaceSelector
                                and Selector are defined on the same rule&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; then only workload
                                endpoints that are matched by both selectors will be selected
                                by the rule. \n For NetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; an empty NamespaceSelector
                                implies that the Selector is limited to selecting only
                                workload endpoints in the same namespace as the NetworkPolicy.
                                \n For NetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; `global()` NamespaceSelector implies
                                that the Selector is limited to selecting only GlobalNetworkSet
                                or HostEndpoint. \n For GlobalNetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; an empty
                                NamespaceSelector implies the Selector applies to workload
                                endpoints across all namespaces.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;nets&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Nets is an optional field that restricts the
                                rule to only apply to traffic that originates from (or
                                terminates at) IP addresses in any of the given subnets.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notNets&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotNets is the negated version of the Nets
                                field.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notPorts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotPorts is the negated version of the Ports
                                field. Since only some protocols have ports&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if any ports
                                are specified it requires the Protocol match in the Rule
                                to be set to &amp;quot;TCP&amp;quot; or &amp;quot;UDP&amp;quot;.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                                &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotSelector is the negated version of the Selector
                                field.  See Selector field for subtleties with negated
                                selectors.
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;ports&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Ports is an optional field that restricts
                                the rule to only apply to traffic that has a source (destination)
                                port that matches one of these ranges/values. This value
                                is a list of integers or strings that represent ranges
                                of ports. \n Since only some protocols have ports&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if
                                any ports are specified it requires the Protocol match
                                in the Rule to be set to \&amp;quot;TCP\&amp;quot; or \&amp;quot;UDP\&amp;quot;.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                                &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Selector is an optional field that contains
                                a selector expression (see Policy for sample syntax).
                                \ Only traffic that originates from (terminates at) endpoints
                                &lt;span class=&quot;token key atrule&quot;&gt;matching the selector will be matched. \n Note that&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; in
                                addition to the negated version of the Selector (see NotSelector
                                below)&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the selector expression syntax itself supports
                                negation.  The two types of negation are subtly different.
                                One negates the set of matched endpoints&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the other negates
                                &lt;span class=&quot;token key atrule&quot;&gt;the whole match&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; \n \tSelector = \&amp;quot;&lt;span class=&quot;token tag&quot;&gt;!has(my_label)&lt;/span&gt;\&amp;quot; matches
                                packets that are from other Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled \tendpoints
                                that do not have the label “my_label”. \n \tNotSelector
                                = \&amp;quot;has(my_label)\&amp;quot; matches packets that are not from
                                Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled \tendpoints that do have the label “my_label”.
                                \n The effect is that the latter will accept packets from
                                non&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Calico sources whereas the former is limited to packets
                                from Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled endpoints.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;serviceAccounts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ServiceAccounts is an optional field that restricts
                                the rule to only apply to traffic that originates from
                                (or terminates at) a pod running as a matching service
                                account.
                              &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Names is an optional field that restricts
                                    the rule to only apply to traffic that originates
                                    from (or terminates at) a pod running as a service
                                    account whose name is in the list.
                                  &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                  &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                                &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Selector is an optional field that restricts
                                    the rule to only apply to traffic that originates
                                    from (or terminates at) a pod running as a service
                                    account that matches the given label selector. If
                                    both Names and Selector are specified then they are
                                    AND&amp;#x27;ed.
                                  &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                      &lt;span class=&quot;token key atrule&quot;&gt;required&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; action
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                  &lt;span class=&quot;token key atrule&quot;&gt;namespaceSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NamespaceSelector is an optional field for an expression
                      used to select a pod based on namespaces.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;order&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Order is an optional field that specifies the order in
                      which the policy is applied. Policies with higher &amp;quot;order&amp;quot; are applied
                      after those with lower order.  If the order is omitted&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; it may be
                      considered to be &amp;quot;infinite&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; i.e. the policy will be applied last.  Policies
                      with identical order will be applied in alphanumerical order based
                      on the Policy &amp;quot;Name&amp;quot;.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; number
                  &lt;span class=&quot;token key atrule&quot;&gt;preDNAT&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; PreDNAT indicates to apply the rules in this policy before
                      any DNAT.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;The selector is an expression used to pick pick out
                      the endpoints that the policy should be applied to. \n Selector
                      &lt;span class=&quot;token key atrule&quot;&gt;expressions follow this syntax&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; \n \tlabel == \&amp;quot;string_literal\&amp;quot;
                      \ &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;  comparison&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; e.g. my_label == \&amp;quot;foo bar\&amp;quot; \tlabel &lt;span class=&quot;token tag&quot;&gt;!=&lt;/span&gt; \&amp;quot;string_literal\&amp;quot;
                      \  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;  not equal; also matches if label is not present \tlabel in
                      &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; \&amp;quot;a\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;b\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;c\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;...&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;  true if the value of label X is
                      one of \&amp;quot;a\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;b\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;c\&amp;quot; \tlabel not in &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; \&amp;quot;a\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;b\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;c\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      &lt;span class=&quot;token punctuation&quot;&gt;...&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;  true if the value of label X is not one of \&amp;quot;a\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;b\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      \&amp;quot;c\&amp;quot; \thas(label_name)  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt; True if that label is present \t&lt;span class=&quot;token tag&quot;&gt;!&lt;/span&gt; expr
                      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt; negation of expr \texpr &lt;span class=&quot;token important&quot;&gt;&amp;amp;&amp;amp;&lt;/span&gt; expr  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt; Short&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;circuit and \texpr
                      &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; expr  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt; Short&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;circuit or \t( expr ) &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt; parens for grouping \tall()
                      or the empty selector &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt; matches all endpoints. \n Label names are
                      allowed to contain alphanumerics&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; _ and /. String literals are
                      more permissive but they do not support escape characters. \n Examples
                      &lt;span class=&quot;token key atrule&quot;&gt;(with made-up labels)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; \n \ttype == \&amp;quot;webserver\&amp;quot; &lt;span class=&quot;token important&quot;&gt;&amp;amp;&amp;amp;&lt;/span&gt; deployment
                      == \&amp;quot;prod\&amp;quot; \ttype in &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;\&amp;quot;frontend\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;backend\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt; \tdeployment &lt;span class=&quot;token tag&quot;&gt;!=&lt;/span&gt;
                      \&amp;quot;dev\&amp;quot; \t&lt;span class=&quot;token tag&quot;&gt;!&lt;/span&gt; has(label_name)&amp;quot;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;serviceAccountSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ServiceAccountSelector is an optional field for an expression
                      used to select a pod based on service accounts.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;types&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Types indicates whether this policy applies to ingress&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      or to egress&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; or to both.  When not explicitly specified (and so
                      the value on creation is empty or nil)&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; Calico defaults Types according
                      to what Ingress and Egress rules are present in the policy.  The
                      &lt;span class=&quot;token key atrule&quot;&gt;default is&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; \n &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt; PolicyTypeIngress &lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if there are no Egress rules
                      (including the case where there are   also no Ingress rules) \n
                      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt; PolicyTypeEgress &lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if there are Egress rules but no Ingress
                      rules \n &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt; PolicyTypeIngress&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; PolicyTypeEgress &lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if there are
                      both Ingress and Egress rules. \n When the policy is read back again&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      Types will always be one of these values&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; never empty or nil.&amp;quot;
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; PolicyType enumerates the possible values of the PolicySpec
                        Types field.
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
        &lt;span class=&quot;token key atrule&quot;&gt;served&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;storage&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;status&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;acceptedNames&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;conditions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;storedVersions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; apiextensions.k8s.io/v1
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CustomResourceDefinition
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;annotations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;controller-gen.kubebuilder.io/version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; (devel)
      &lt;span class=&quot;token key atrule&quot;&gt;creationTimestamp&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token null important&quot;&gt;null&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; globalnetworksets.crd.projectcalico.org
    &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;group&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; crd.projectcalico.org
      &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; GlobalNetworkSet
        &lt;span class=&quot;token key atrule&quot;&gt;listKind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; GlobalNetworkSetList
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; globalnetworksets
        &lt;span class=&quot;token key atrule&quot;&gt;singular&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; globalnetworkset
      &lt;span class=&quot;token key atrule&quot;&gt;scope&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Cluster
      &lt;span class=&quot;token key atrule&quot;&gt;versions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; v1
        &lt;span class=&quot;token key atrule&quot;&gt;schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;openAPIV3Schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; GlobalNetworkSet contains a set of arbitrary IP sub&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;networks/CIDRs
              that share labels to allow rules to refer to them via selectors.  The labels
              of GlobalNetworkSet are not namespaced.
            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;APIVersion defines the versioned schema of this representation
                  of an object. Servers should convert recognized schemas to the latest
                  internal value&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;and may reject unrecognized values. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#resources&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Kind is a string value representing the REST resource this
                  object represents. Servers may infer this from the endpoint the client
                  &lt;span class=&quot;token key atrule&quot;&gt;submits requests to. Cannot be updated. In CamelCase. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#types-kinds&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
              &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; GlobalNetworkSetSpec contains the specification for a NetworkSet
                  resource.
                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;nets&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; The list of IP networks that belong to this set.
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
        &lt;span class=&quot;token key atrule&quot;&gt;served&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;storage&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;status&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;acceptedNames&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;conditions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;storedVersions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; apiextensions.k8s.io/v1
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CustomResourceDefinition
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;annotations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;controller-gen.kubebuilder.io/version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; (devel)
      &lt;span class=&quot;token key atrule&quot;&gt;creationTimestamp&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token null important&quot;&gt;null&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; hostendpoints.crd.projectcalico.org
    &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;group&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; crd.projectcalico.org
      &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; HostEndpoint
        &lt;span class=&quot;token key atrule&quot;&gt;listKind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; HostEndpointList
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; hostendpoints
        &lt;span class=&quot;token key atrule&quot;&gt;singular&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; hostendpoint
      &lt;span class=&quot;token key atrule&quot;&gt;scope&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Cluster
      &lt;span class=&quot;token key atrule&quot;&gt;versions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; v1
        &lt;span class=&quot;token key atrule&quot;&gt;schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;openAPIV3Schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;APIVersion defines the versioned schema of this representation
                  of an object. Servers should convert recognized schemas to the latest
                  internal value&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;and may reject unrecognized values. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#resources&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Kind is a string value representing the REST resource this
                  object represents. Servers may infer this from the endpoint the client
                  &lt;span class=&quot;token key atrule&quot;&gt;submits requests to. Cannot be updated. In CamelCase. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#types-kinds&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
              &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; HostEndpointSpec contains the specification for a HostEndpoint
                  resource.
                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;expectedIPs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;The expected IP addresses (IPv4 and IPv6) of the endpoint.
                      If \&amp;quot;InterfaceName\&amp;quot; is not present&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; Calico will look for an interface
                      &lt;span class=&quot;token key atrule&quot;&gt;matching any of the IPs in the list and apply policy to that. Note&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      \tWhen using the selector match criteria in an ingress or egress
                      security Policy \tor Profile&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; Calico converts the selector into
                      a set of IP addresses. For host \tendpoints&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the ExpectedIPs field
                      is used for that purpose. (If only the interface \tname is specified&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      Calico does not learn the IPs of the interface for use in match
                      \tcriteria.)&amp;quot;
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                  &lt;span class=&quot;token key atrule&quot;&gt;interfaceName&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Either \&amp;quot;&lt;span class=&quot;token important&quot;&gt;*\&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; or the name of a specific Linux interface
                      to apply policy to; or empty.  \&amp;quot;&lt;span class=&quot;token important&quot;&gt;*\&amp;quot;&lt;/span&gt; indicates that this HostEndpoint
                      governs all traffic to&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; from or through the default network namespace
                      of the host named by the \&amp;quot;Node\&amp;quot; field; entering and leaving that
                      namespace via any interface&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; including those from/to non&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;host&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;networked
                      local workloads. \n If InterfaceName is not \&amp;quot;&lt;span class=&quot;token important&quot;&gt;*\&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; this HostEndpoint
                      only governs traffic that enters or leaves the host through the
                      specific interface named by InterfaceName&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; or &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; when InterfaceName
                      is empty &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; through the specific interface that has one of the IPs
                      in ExpectedIPs. Therefore&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; when InterfaceName is empty&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; at least
                      one expected IP must be specified.  Only external interfaces (such
                      as “eth0”) are supported here; it isn&amp;#x27;t possible for a HostEndpoint
                      to protect traffic through a specific local workload interface.
                      &lt;span class=&quot;token key atrule&quot;&gt;\n Note&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Only some kinds of policy are implemented for \&amp;quot;&lt;span class=&quot;token important&quot;&gt;*\&amp;quot;&lt;/span&gt; HostEndpoints;
                      initially just pre&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;DNAT policy.  Please check Calico documentation
                      for the latest position.&amp;quot;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;node&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; The node name identifying the Calico node instance.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;ports&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Ports contains the endpoint&amp;#x27;s named ports&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; which may
                      be referenced in security policy rules.
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                        &lt;span class=&quot;token key atrule&quot;&gt;port&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                        &lt;span class=&quot;token key atrule&quot;&gt;protocol&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                          &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                          &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;required&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; name
                      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; port
                      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; protocol
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                  &lt;span class=&quot;token key atrule&quot;&gt;profiles&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; A list of identifiers of security Profile objects that
                      apply to this endpoint. Each profile is applied in the order that
                      they appear in this list.  Profile rules are applied after the selector&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;based
                      security policy.
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
        &lt;span class=&quot;token key atrule&quot;&gt;served&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;storage&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;status&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;acceptedNames&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;conditions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;storedVersions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; apiextensions.k8s.io/v1
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CustomResourceDefinition
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;annotations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;controller-gen.kubebuilder.io/version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; (devel)
      &lt;span class=&quot;token key atrule&quot;&gt;creationTimestamp&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token null important&quot;&gt;null&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ipamblocks.crd.projectcalico.org
    &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;group&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; crd.projectcalico.org
      &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; IPAMBlock
        &lt;span class=&quot;token key atrule&quot;&gt;listKind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; IPAMBlockList
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ipamblocks
        &lt;span class=&quot;token key atrule&quot;&gt;singular&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ipamblock
      &lt;span class=&quot;token key atrule&quot;&gt;scope&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Cluster
      &lt;span class=&quot;token key atrule&quot;&gt;versions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; v1
        &lt;span class=&quot;token key atrule&quot;&gt;schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;openAPIV3Schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;APIVersion defines the versioned schema of this representation
                  of an object. Servers should convert recognized schemas to the latest
                  internal value&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;and may reject unrecognized values. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#resources&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Kind is a string value representing the REST resource this
                  object represents. Servers may infer this from the endpoint the client
                  &lt;span class=&quot;token key atrule&quot;&gt;submits requests to. Cannot be updated. In CamelCase. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#types-kinds&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
              &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; IPAMBlockSpec contains the specification for an IPAMBlock
                  resource.
                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;affinity&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;allocations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                      &lt;span class=&quot;token comment&quot;&gt;# TODO: This nullable is manually added in. We should update controller-gen&lt;/span&gt;
                      &lt;span class=&quot;token comment&quot;&gt;# to handle []*int properly itself.&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;nullable&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                  &lt;span class=&quot;token key atrule&quot;&gt;attributes&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;handle_id&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                        &lt;span class=&quot;token key atrule&quot;&gt;secondary&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;additionalProperties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                  &lt;span class=&quot;token key atrule&quot;&gt;cidr&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;deleted&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;strictAffinity&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;unallocated&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                &lt;span class=&quot;token key atrule&quot;&gt;required&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; allocations
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; attributes
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; cidr
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; deleted
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; strictAffinity
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; unallocated
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
        &lt;span class=&quot;token key atrule&quot;&gt;served&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;storage&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;status&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;acceptedNames&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;conditions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;storedVersions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; apiextensions.k8s.io/v1
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CustomResourceDefinition
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;annotations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;controller-gen.kubebuilder.io/version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; (devel)
      &lt;span class=&quot;token key atrule&quot;&gt;creationTimestamp&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token null important&quot;&gt;null&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ipamconfigs.crd.projectcalico.org
    &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;group&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; crd.projectcalico.org
      &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; IPAMConfig
        &lt;span class=&quot;token key atrule&quot;&gt;listKind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; IPAMConfigList
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ipamconfigs
        &lt;span class=&quot;token key atrule&quot;&gt;singular&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ipamconfig
      &lt;span class=&quot;token key atrule&quot;&gt;scope&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Cluster
      &lt;span class=&quot;token key atrule&quot;&gt;versions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; v1
        &lt;span class=&quot;token key atrule&quot;&gt;schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;openAPIV3Schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;APIVersion defines the versioned schema of this representation
                  of an object. Servers should convert recognized schemas to the latest
                  internal value&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;and may reject unrecognized values. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#resources&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Kind is a string value representing the REST resource this
                  object represents. Servers may infer this from the endpoint the client
                  &lt;span class=&quot;token key atrule&quot;&gt;submits requests to. Cannot be updated. In CamelCase. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#types-kinds&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
              &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; IPAMConfigSpec contains the specification for an IPAMConfig
                  resource.
                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;autoAllocateBlocks&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;strictAffinity&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                &lt;span class=&quot;token key atrule&quot;&gt;required&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; autoAllocateBlocks
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; strictAffinity
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
        &lt;span class=&quot;token key atrule&quot;&gt;served&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;storage&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;status&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;acceptedNames&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;conditions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;storedVersions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; apiextensions.k8s.io/v1
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CustomResourceDefinition
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;annotations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;controller-gen.kubebuilder.io/version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; (devel)
      &lt;span class=&quot;token key atrule&quot;&gt;creationTimestamp&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token null important&quot;&gt;null&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ipamhandles.crd.projectcalico.org
    &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;group&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; crd.projectcalico.org
      &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; IPAMHandle
        &lt;span class=&quot;token key atrule&quot;&gt;listKind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; IPAMHandleList
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ipamhandles
        &lt;span class=&quot;token key atrule&quot;&gt;singular&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ipamhandle
      &lt;span class=&quot;token key atrule&quot;&gt;scope&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Cluster
      &lt;span class=&quot;token key atrule&quot;&gt;versions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; v1
        &lt;span class=&quot;token key atrule&quot;&gt;schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;openAPIV3Schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;APIVersion defines the versioned schema of this representation
                  of an object. Servers should convert recognized schemas to the latest
                  internal value&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;and may reject unrecognized values. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#resources&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Kind is a string value representing the REST resource this
                  object represents. Servers may infer this from the endpoint the client
                  &lt;span class=&quot;token key atrule&quot;&gt;submits requests to. Cannot be updated. In CamelCase. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#types-kinds&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
              &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; IPAMHandleSpec contains the specification for an IPAMHandle
                  resource.
                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;block&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;additionalProperties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                  &lt;span class=&quot;token key atrule&quot;&gt;handleID&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                &lt;span class=&quot;token key atrule&quot;&gt;required&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; block
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; handleID
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
        &lt;span class=&quot;token key atrule&quot;&gt;served&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;storage&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;status&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;acceptedNames&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;conditions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;storedVersions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; apiextensions.k8s.io/v1
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CustomResourceDefinition
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;annotations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;controller-gen.kubebuilder.io/version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; (devel)
      &lt;span class=&quot;token key atrule&quot;&gt;creationTimestamp&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token null important&quot;&gt;null&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ippools.crd.projectcalico.org
    &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;group&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; crd.projectcalico.org
      &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; IPPool
        &lt;span class=&quot;token key atrule&quot;&gt;listKind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; IPPoolList
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ippools
        &lt;span class=&quot;token key atrule&quot;&gt;singular&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ippool
      &lt;span class=&quot;token key atrule&quot;&gt;scope&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Cluster
      &lt;span class=&quot;token key atrule&quot;&gt;versions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; v1
        &lt;span class=&quot;token key atrule&quot;&gt;schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;openAPIV3Schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;APIVersion defines the versioned schema of this representation
                  of an object. Servers should convert recognized schemas to the latest
                  internal value&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;and may reject unrecognized values. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#resources&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Kind is a string value representing the REST resource this
                  object represents. Servers may infer this from the endpoint the client
                  &lt;span class=&quot;token key atrule&quot;&gt;submits requests to. Cannot be updated. In CamelCase. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#types-kinds&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
              &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; IPPoolSpec contains the specification for an IPPool resource.
                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;blockSize&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; The block size to use for IP address assignments from
                      this pool. Defaults to 26 for IPv4 and 112 for IPv6.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                  &lt;span class=&quot;token key atrule&quot;&gt;cidr&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; The pool CIDR.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;disabled&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; When disabled is true&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; Calico IPAM will not assign addresses
                      from this pool.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;ipip&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Deprecated&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; this field is only used for APIv1 backwards
                      compatibility. Setting this field is not allowed&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; this field is
                      for internal use only.&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;enabled&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; When enabled is true&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; ipip tunneling will be used
                          to deliver packets to destinations within this pool.
                        &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                      &lt;span class=&quot;token key atrule&quot;&gt;mode&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; The IPIP mode.  This can be one of &amp;quot;always&amp;quot; or &amp;quot;cross&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;subnet&amp;quot;.  A
                          mode of &amp;quot;always&amp;quot; will also use IPIP tunneling for routing to
                          destination IP addresses within this pool.  A mode of &amp;quot;cross&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;subnet&amp;quot;
                          will only use IPIP tunneling when the destination node is on
                          a different subnet to the originating node.  The default value
                          (if not specified) is &amp;quot;always&amp;quot;.
                        &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                  &lt;span class=&quot;token key atrule&quot;&gt;ipipMode&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Contains configuration for IPIP tunneling for this pool.
                      If not specified&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; then this is defaulted to &amp;quot;Never&amp;quot; (i.e. IPIP tunneling
                      is disabled).
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;nat-outgoing&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Deprecated&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; this field is only used for APIv1 backwards
                      compatibility. Setting this field is not allowed&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; this field is
                      for internal use only.&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;natOutgoing&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; When nat&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;outgoing is true&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; packets sent from Calico networked
                      containers in this pool to destinations outside of this pool will
                      be masqueraded.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; boolean
                  &lt;span class=&quot;token key atrule&quot;&gt;nodeSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Allows IPPool to allocate for a specific node by label
                      selector.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;vxlanMode&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Contains configuration for VXLAN tunneling for this pool.
                      If not specified&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; then this is defaulted to &amp;quot;Never&amp;quot; (i.e. VXLAN
                      tunneling is disabled).
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                &lt;span class=&quot;token key atrule&quot;&gt;required&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; cidr
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
        &lt;span class=&quot;token key atrule&quot;&gt;served&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;storage&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;status&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;acceptedNames&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;conditions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;storedVersions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; apiextensions.k8s.io/v1
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CustomResourceDefinition
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;annotations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;controller-gen.kubebuilder.io/version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; (devel)
      &lt;span class=&quot;token key atrule&quot;&gt;creationTimestamp&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token null important&quot;&gt;null&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; kubecontrollersconfigurations.crd.projectcalico.org
    &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;group&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; crd.projectcalico.org
      &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; KubeControllersConfiguration
        &lt;span class=&quot;token key atrule&quot;&gt;listKind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; KubeControllersConfigurationList
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; kubecontrollersconfigurations
        &lt;span class=&quot;token key atrule&quot;&gt;singular&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; kubecontrollersconfiguration
      &lt;span class=&quot;token key atrule&quot;&gt;scope&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Cluster
      &lt;span class=&quot;token key atrule&quot;&gt;versions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; v1
        &lt;span class=&quot;token key atrule&quot;&gt;schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;openAPIV3Schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;APIVersion defines the versioned schema of this representation
                  of an object. Servers should convert recognized schemas to the latest
                  internal value&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;and may reject unrecognized values. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#resources&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Kind is a string value representing the REST resource this
                  object represents. Servers may infer this from the endpoint the client
                  &lt;span class=&quot;token key atrule&quot;&gt;submits requests to. Cannot be updated. In CamelCase. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#types-kinds&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
              &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; KubeControllersConfigurationSpec contains the values of the
                  Kubernetes controllers configuration.
                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;controllers&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Controllers enables and configures individual Kubernetes
                      controllers
                    &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;namespace&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Namespace enables and configures the namespace controller.
                          Enabled by default&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; set to nil to disable.
                        &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;reconcilerPeriod&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;ReconcilerPeriod is the period to perform reconciliation
                              with the Calico datastore. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 5m&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                        &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                      &lt;span class=&quot;token key atrule&quot;&gt;node&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Node enables and configures the node controller.
                          Enabled by default&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; set to nil to disable.
                        &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;hostEndpoint&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; HostEndpoint controls syncing nodes to host endpoints.
                              Disabled by default&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; set to nil to disable.
                            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;autoCreate&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;AutoCreate enables automatic creation of
                                  host endpoints for every node. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Disabled&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                          &lt;span class=&quot;token key atrule&quot;&gt;reconcilerPeriod&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;ReconcilerPeriod is the period to perform reconciliation
                              with the Calico datastore. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 5m&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                          &lt;span class=&quot;token key atrule&quot;&gt;syncLabels&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;SyncLabels controls whether to copy Kubernetes
                              node labels to Calico nodes. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Enabled&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                        &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                      &lt;span class=&quot;token key atrule&quot;&gt;policy&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Policy enables and configures the policy controller.
                          Enabled by default&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; set to nil to disable.
                        &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;reconcilerPeriod&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;ReconcilerPeriod is the period to perform reconciliation
                              with the Calico datastore. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 5m&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                        &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                      &lt;span class=&quot;token key atrule&quot;&gt;serviceAccount&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ServiceAccount enables and configures the service
                          account controller. Enabled by default&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; set to nil to disable.
                        &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;reconcilerPeriod&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;ReconcilerPeriod is the period to perform reconciliation
                              with the Calico datastore. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 5m&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                        &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                      &lt;span class=&quot;token key atrule&quot;&gt;workloadEndpoint&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; WorkloadEndpoint enables and configures the workload
                          endpoint controller. Enabled by default&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; set to nil to disable.
                        &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;reconcilerPeriod&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;ReconcilerPeriod is the period to perform reconciliation
                              with the Calico datastore. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 5m&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                        &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                  &lt;span class=&quot;token key atrule&quot;&gt;etcdV3CompactionPeriod&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;EtcdV3CompactionPeriod is the period between etcdv3
                      compaction requests. Set to 0 to disable. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 10m&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;healthChecks&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;HealthChecks enables or disables support for health
                      checks &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Enabled&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;logSeverityScreen&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;LogSeverityScreen is the log severity above which logs
                      are sent to the stdout. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Info&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                &lt;span class=&quot;token key atrule&quot;&gt;required&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; controllers
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
              &lt;span class=&quot;token key atrule&quot;&gt;status&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; KubeControllersConfigurationStatus represents the status
                  of the configuration. It&amp;#x27;s useful for admins to be able to see the actual
                  config that was applied&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; which can be modified by environment variables
                  on the kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controllers process.
                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;environmentVars&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;additionalProperties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; EnvironmentVars contains the environment variables on
                      the kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controllers that influenced the RunningConfig.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                  &lt;span class=&quot;token key atrule&quot;&gt;runningConfig&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; RunningConfig contains the effective config that is running
                      in the kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controllers pod&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; after merging the API resource with
                      any environment variables.
                    &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;controllers&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Controllers enables and configures individual Kubernetes
                          controllers
                        &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;namespace&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Namespace enables and configures the namespace
                              controller. Enabled by default&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; set to nil to disable.
                            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;reconcilerPeriod&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;ReconcilerPeriod is the period to perform
                                  reconciliation with the Calico datastore. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  5m&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                          &lt;span class=&quot;token key atrule&quot;&gt;node&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Node enables and configures the node controller.
                              Enabled by default&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; set to nil to disable.
                            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;hostEndpoint&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; HostEndpoint controls syncing nodes to host
                                  endpoints. Disabled by default&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; set to nil to disable.
                                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;autoCreate&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;AutoCreate enables automatic creation
                                      of host endpoints for every node. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Disabled&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                              &lt;span class=&quot;token key atrule&quot;&gt;reconcilerPeriod&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;ReconcilerPeriod is the period to perform
                                  reconciliation with the Calico datastore. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  5m&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;syncLabels&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;SyncLabels controls whether to copy Kubernetes
                                  node labels to Calico nodes. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Enabled&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                          &lt;span class=&quot;token key atrule&quot;&gt;policy&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Policy enables and configures the policy controller.
                              Enabled by default&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; set to nil to disable.
                            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;reconcilerPeriod&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;ReconcilerPeriod is the period to perform
                                  reconciliation with the Calico datastore. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  5m&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                          &lt;span class=&quot;token key atrule&quot;&gt;serviceAccount&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ServiceAccount enables and configures the service
                              account controller. Enabled by default&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; set to nil to disable.
                            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;reconcilerPeriod&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;ReconcilerPeriod is the period to perform
                                  reconciliation with the Calico datastore. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  5m&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                          &lt;span class=&quot;token key atrule&quot;&gt;workloadEndpoint&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; WorkloadEndpoint enables and configures the workload
                              endpoint controller. Enabled by default&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; set to nil to disable.
                            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;reconcilerPeriod&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;ReconcilerPeriod is the period to perform
                                  reconciliation with the Calico datastore. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  5m&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                      &lt;span class=&quot;token key atrule&quot;&gt;etcdV3CompactionPeriod&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;EtcdV3CompactionPeriod is the period between etcdv3
                          compaction requests. Set to 0 to disable. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 10m&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                        &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                      &lt;span class=&quot;token key atrule&quot;&gt;healthChecks&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;HealthChecks enables or disables support for health
                          checks &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Enabled&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                        &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                      &lt;span class=&quot;token key atrule&quot;&gt;logSeverityScreen&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;LogSeverityScreen is the log severity above which
                          logs are sent to the stdout. &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token key atrule&quot;&gt;Default&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Info&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&amp;#x27;
                        &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                    &lt;span class=&quot;token key atrule&quot;&gt;required&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; controllers
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
        &lt;span class=&quot;token key atrule&quot;&gt;served&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;storage&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;status&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;acceptedNames&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;conditions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;storedVersions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; apiextensions.k8s.io/v1
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CustomResourceDefinition
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;annotations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;controller-gen.kubebuilder.io/version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; (devel)
      &lt;span class=&quot;token key atrule&quot;&gt;creationTimestamp&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token null important&quot;&gt;null&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; networkpolicies.crd.projectcalico.org
    &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;group&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; crd.projectcalico.org
      &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NetworkPolicy
        &lt;span class=&quot;token key atrule&quot;&gt;listKind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NetworkPolicyList
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; networkpolicies
        &lt;span class=&quot;token key atrule&quot;&gt;singular&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; networkpolicy
      &lt;span class=&quot;token key atrule&quot;&gt;scope&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Namespaced
      &lt;span class=&quot;token key atrule&quot;&gt;versions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; v1
        &lt;span class=&quot;token key atrule&quot;&gt;schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;openAPIV3Schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;APIVersion defines the versioned schema of this representation
                  of an object. Servers should convert recognized schemas to the latest
                  internal value&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;and may reject unrecognized values. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#resources&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Kind is a string value representing the REST resource this
                  object represents. Servers may infer this from the endpoint the client
                  &lt;span class=&quot;token key atrule&quot;&gt;submits requests to. Cannot be updated. In CamelCase. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#types-kinds&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
              &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;egress&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; The ordered set of egress rules.  Each rule contains
                      a set of packet match criteria and a corresponding action to apply.
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;A Rule encapsulates a set of match criteria and an
                        action.  Both selector&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;based security Policy and security Profiles
                        reference rules &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; separated out as a list of rules for both ingress
                        and egress packet matching. \n Each positive match criteria has
                        a negated version&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; prefixed with ”Not”. All the match criteria
                        within a rule must be satisfied for a packet to match. A single
                        rule can contain the positive and negative version of a match
                        and both must be satisfied for the rule to match.&amp;quot;
                      &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;action&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                        &lt;span class=&quot;token key atrule&quot;&gt;destination&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Destination contains the match criteria that apply
                            to destination entity.
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;namespaceSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;NamespaceSelector is an optional field that
                                contains a selector expression. Only traffic that originates
                                from (or terminates at) endpoints within the selected
                                namespaces will be matched. When both NamespaceSelector
                                and Selector are defined on the same rule&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; then only workload
                                endpoints that are matched by both selectors will be selected
                                by the rule. \n For NetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; an empty NamespaceSelector
                                implies that the Selector is limited to selecting only
                                workload endpoints in the same namespace as the NetworkPolicy.
                                \n For NetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; `global()` NamespaceSelector implies
                                that the Selector is limited to selecting only GlobalNetworkSet
                                or HostEndpoint. \n For GlobalNetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; an empty
                                NamespaceSelector implies the Selector applies to workload
                                endpoints across all namespaces.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;nets&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Nets is an optional field that restricts the
                                rule to only apply to traffic that originates from (or
                                terminates at) IP addresses in any of the given subnets.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notNets&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotNets is the negated version of the Nets
                                field.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notPorts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotPorts is the negated version of the Ports
                                field. Since only some protocols have ports&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if any ports
                                are specified it requires the Protocol match in the Rule
                                to be set to &amp;quot;TCP&amp;quot; or &amp;quot;UDP&amp;quot;.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                                &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotSelector is the negated version of the Selector
                                field.  See Selector field for subtleties with negated
                                selectors.
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;ports&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Ports is an optional field that restricts
                                the rule to only apply to traffic that has a source (destination)
                                port that matches one of these ranges/values. This value
                                is a list of integers or strings that represent ranges
                                of ports. \n Since only some protocols have ports&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if
                                any ports are specified it requires the Protocol match
                                in the Rule to be set to \&amp;quot;TCP\&amp;quot; or \&amp;quot;UDP\&amp;quot;.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                                &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Selector is an optional field that contains
                                a selector expression (see Policy for sample syntax).
                                \ Only traffic that originates from (terminates at) endpoints
                                &lt;span class=&quot;token key atrule&quot;&gt;matching the selector will be matched. \n Note that&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; in
                                addition to the negated version of the Selector (see NotSelector
                                below)&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the selector expression syntax itself supports
                                negation.  The two types of negation are subtly different.
                                One negates the set of matched endpoints&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the other negates
                                &lt;span class=&quot;token key atrule&quot;&gt;the whole match&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; \n \tSelector = \&amp;quot;&lt;span class=&quot;token tag&quot;&gt;!has(my_label)&lt;/span&gt;\&amp;quot; matches
                                packets that are from other Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled \tendpoints
                                that do not have the label “my_label”. \n \tNotSelector
                                = \&amp;quot;has(my_label)\&amp;quot; matches packets that are not from
                                Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled \tendpoints that do have the label “my_label”.
                                \n The effect is that the latter will accept packets from
                                non&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Calico sources whereas the former is limited to packets
                                from Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled endpoints.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;serviceAccounts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ServiceAccounts is an optional field that restricts
                                the rule to only apply to traffic that originates from
                                (or terminates at) a pod running as a matching service
                                account.
                              &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Names is an optional field that restricts
                                    the rule to only apply to traffic that originates
                                    from (or terminates at) a pod running as a service
                                    account whose name is in the list.
                                  &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                  &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                                &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Selector is an optional field that restricts
                                    the rule to only apply to traffic that originates
                                    from (or terminates at) a pod running as a service
                                    account that matches the given label selector. If
                                    both Names and Selector are specified then they are
                                    AND&amp;#x27;ed.
                                  &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;http&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; HTTP contains match criteria that apply to HTTP
                            requests.
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;methods&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Methods is an optional field that restricts
                                the rule to apply only to HTTP requests that use one of
                                the listed HTTP Methods (e.g. GET&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; PUT&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; etc.) Multiple
                                methods are OR&amp;#x27;d together.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;paths&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Paths is an optional field that restricts
                                the rule to apply to HTTP requests that use one of the
                                listed HTTP Paths. Multiple paths are OR&amp;#x27;&amp;#x27;d together.
                                &lt;span class=&quot;token key atrule&quot;&gt;e.g&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;exact&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;/foo - prefix&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;/bar NOTE&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Each entry may
                                ONLY specify either a `exact` or a `prefix` match. The
                                validator will check for it.&amp;#x27;
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;HTTPPath specifies an HTTP path to match.
                                  &lt;span class=&quot;token key atrule&quot;&gt;It may be either of the form&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;exact&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;&amp;lt;path&amp;gt;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; which matches
                                  &lt;span class=&quot;token key atrule&quot;&gt;the path exactly or prefix&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;&amp;lt;path-prefix&amp;gt;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; which matches
                                  the path prefix&amp;#x27;
                                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;exact&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                  &lt;span class=&quot;token key atrule&quot;&gt;prefix&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;icmp&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ICMP is an optional field that restricts the rule
                            to apply to a specific type and code of ICMP traffic.  This
                            should only be specified if the Protocol field is set to &amp;quot;ICMP&amp;quot;
                            or &amp;quot;ICMPv6&amp;quot;.
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;code&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Match on a specific ICMP code.  If specified&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                                the Type value must also be specified. This is a technical
                                limitation imposed by the kernel’s iptables firewall&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                                which Calico uses to enforce the rule.
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Match on a specific ICMP type.  For example
                                a value of 8 refers to ICMP Echo Request (i.e. pings).
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;ipVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; IPVersion is an optional field that restricts the
                            rule to only match a specific IP version.
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                        &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Metadata contains additional information for this
                            rule
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;annotations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;additionalProperties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Annotations is a set of key value pairs that
                                give extra information about the rule
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;notICMP&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotICMP is the negated version of the ICMP field.
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;code&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Match on a specific ICMP code.  If specified&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                                the Type value must also be specified. This is a technical
                                limitation imposed by the kernel’s iptables firewall&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                                which Calico uses to enforce the rule.
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Match on a specific ICMP type.  For example
                                a value of 8 refers to ICMP Echo Request (i.e. pings).
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;notProtocol&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotProtocol is the negated version of the Protocol
                            field.
                          &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                          &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;protocol&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Protocol is an optional field that restricts the
                            rule to only apply to traffic of a specific IP protocol. Required
                            if any of the EntityRules contain Ports (because ports only
                            apply to certain protocols). \n Must be one of these string
                            &lt;span class=&quot;token key atrule&quot;&gt;values&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; \&amp;quot;TCP\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;UDP\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;ICMP\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;ICMPv6\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;SCTP\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                            \&amp;quot;UDPLite\&amp;quot; or an integer in the range 1&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;255.&amp;quot;
                          &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                          &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;source&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Source contains the match criteria that apply to
                            source entity.
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;namespaceSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;NamespaceSelector is an optional field that
                                contains a selector expression. Only traffic that originates
                                from (or terminates at) endpoints within the selected
                                namespaces will be matched. When both NamespaceSelector
                                and Selector are defined on the same rule&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; then only workload
                                endpoints that are matched by both selectors will be selected
                                by the rule. \n For NetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; an empty NamespaceSelector
                                implies that the Selector is limited to selecting only
                                workload endpoints in the same namespace as the NetworkPolicy.
                                \n For NetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; `global()` NamespaceSelector implies
                                that the Selector is limited to selecting only GlobalNetworkSet
                                or HostEndpoint. \n For GlobalNetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; an empty
                                NamespaceSelector implies the Selector applies to workload
                                endpoints across all namespaces.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;nets&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Nets is an optional field that restricts the
                                rule to only apply to traffic that originates from (or
                                terminates at) IP addresses in any of the given subnets.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notNets&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotNets is the negated version of the Nets
                                field.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notPorts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotPorts is the negated version of the Ports
                                field. Since only some protocols have ports&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if any ports
                                are specified it requires the Protocol match in the Rule
                                to be set to &amp;quot;TCP&amp;quot; or &amp;quot;UDP&amp;quot;.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                                &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotSelector is the negated version of the Selector
                                field.  See Selector field for subtleties with negated
                                selectors.
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;ports&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Ports is an optional field that restricts
                                the rule to only apply to traffic that has a source (destination)
                                port that matches one of these ranges/values. This value
                                is a list of integers or strings that represent ranges
                                of ports. \n Since only some protocols have ports&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if
                                any ports are specified it requires the Protocol match
                                in the Rule to be set to \&amp;quot;TCP\&amp;quot; or \&amp;quot;UDP\&amp;quot;.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                                &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Selector is an optional field that contains
                                a selector expression (see Policy for sample syntax).
                                \ Only traffic that originates from (terminates at) endpoints
                                &lt;span class=&quot;token key atrule&quot;&gt;matching the selector will be matched. \n Note that&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; in
                                addition to the negated version of the Selector (see NotSelector
                                below)&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the selector expression syntax itself supports
                                negation.  The two types of negation are subtly different.
                                One negates the set of matched endpoints&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the other negates
                                &lt;span class=&quot;token key atrule&quot;&gt;the whole match&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; \n \tSelector = \&amp;quot;&lt;span class=&quot;token tag&quot;&gt;!has(my_label)&lt;/span&gt;\&amp;quot; matches
                                packets that are from other Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled \tendpoints
                                that do not have the label “my_label”. \n \tNotSelector
                                = \&amp;quot;has(my_label)\&amp;quot; matches packets that are not from
                                Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled \tendpoints that do have the label “my_label”.
                                \n The effect is that the latter will accept packets from
                                non&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Calico sources whereas the former is limited to packets
                                from Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled endpoints.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;serviceAccounts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ServiceAccounts is an optional field that restricts
                                the rule to only apply to traffic that originates from
                                (or terminates at) a pod running as a matching service
                                account.
                              &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Names is an optional field that restricts
                                    the rule to only apply to traffic that originates
                                    from (or terminates at) a pod running as a service
                                    account whose name is in the list.
                                  &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                  &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                                &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Selector is an optional field that restricts
                                    the rule to only apply to traffic that originates
                                    from (or terminates at) a pod running as a service
                                    account that matches the given label selector. If
                                    both Names and Selector are specified then they are
                                    AND&amp;#x27;ed.
                                  &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                      &lt;span class=&quot;token key atrule&quot;&gt;required&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; action
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                  &lt;span class=&quot;token key atrule&quot;&gt;ingress&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; The ordered set of ingress rules.  Each rule contains
                      a set of packet match criteria and a corresponding action to apply.
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;A Rule encapsulates a set of match criteria and an
                        action.  Both selector&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;based security Policy and security Profiles
                        reference rules &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; separated out as a list of rules for both ingress
                        and egress packet matching. \n Each positive match criteria has
                        a negated version&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; prefixed with ”Not”. All the match criteria
                        within a rule must be satisfied for a packet to match. A single
                        rule can contain the positive and negative version of a match
                        and both must be satisfied for the rule to match.&amp;quot;
                      &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;action&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                        &lt;span class=&quot;token key atrule&quot;&gt;destination&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Destination contains the match criteria that apply
                            to destination entity.
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;namespaceSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;NamespaceSelector is an optional field that
                                contains a selector expression. Only traffic that originates
                                from (or terminates at) endpoints within the selected
                                namespaces will be matched. When both NamespaceSelector
                                and Selector are defined on the same rule&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; then only workload
                                endpoints that are matched by both selectors will be selected
                                by the rule. \n For NetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; an empty NamespaceSelector
                                implies that the Selector is limited to selecting only
                                workload endpoints in the same namespace as the NetworkPolicy.
                                \n For NetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; `global()` NamespaceSelector implies
                                that the Selector is limited to selecting only GlobalNetworkSet
                                or HostEndpoint. \n For GlobalNetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; an empty
                                NamespaceSelector implies the Selector applies to workload
                                endpoints across all namespaces.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;nets&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Nets is an optional field that restricts the
                                rule to only apply to traffic that originates from (or
                                terminates at) IP addresses in any of the given subnets.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notNets&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotNets is the negated version of the Nets
                                field.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notPorts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotPorts is the negated version of the Ports
                                field. Since only some protocols have ports&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if any ports
                                are specified it requires the Protocol match in the Rule
                                to be set to &amp;quot;TCP&amp;quot; or &amp;quot;UDP&amp;quot;.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                                &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotSelector is the negated version of the Selector
                                field.  See Selector field for subtleties with negated
                                selectors.
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;ports&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Ports is an optional field that restricts
                                the rule to only apply to traffic that has a source (destination)
                                port that matches one of these ranges/values. This value
                                is a list of integers or strings that represent ranges
                                of ports. \n Since only some protocols have ports&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if
                                any ports are specified it requires the Protocol match
                                in the Rule to be set to \&amp;quot;TCP\&amp;quot; or \&amp;quot;UDP\&amp;quot;.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                                &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Selector is an optional field that contains
                                a selector expression (see Policy for sample syntax).
                                \ Only traffic that originates from (terminates at) endpoints
                                &lt;span class=&quot;token key atrule&quot;&gt;matching the selector will be matched. \n Note that&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; in
                                addition to the negated version of the Selector (see NotSelector
                                below)&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the selector expression syntax itself supports
                                negation.  The two types of negation are subtly different.
                                One negates the set of matched endpoints&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the other negates
                                &lt;span class=&quot;token key atrule&quot;&gt;the whole match&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; \n \tSelector = \&amp;quot;&lt;span class=&quot;token tag&quot;&gt;!has(my_label)&lt;/span&gt;\&amp;quot; matches
                                packets that are from other Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled \tendpoints
                                that do not have the label “my_label”. \n \tNotSelector
                                = \&amp;quot;has(my_label)\&amp;quot; matches packets that are not from
                                Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled \tendpoints that do have the label “my_label”.
                                \n The effect is that the latter will accept packets from
                                non&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Calico sources whereas the former is limited to packets
                                from Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled endpoints.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;serviceAccounts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ServiceAccounts is an optional field that restricts
                                the rule to only apply to traffic that originates from
                                (or terminates at) a pod running as a matching service
                                account.
                              &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Names is an optional field that restricts
                                    the rule to only apply to traffic that originates
                                    from (or terminates at) a pod running as a service
                                    account whose name is in the list.
                                  &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                  &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                                &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Selector is an optional field that restricts
                                    the rule to only apply to traffic that originates
                                    from (or terminates at) a pod running as a service
                                    account that matches the given label selector. If
                                    both Names and Selector are specified then they are
                                    AND&amp;#x27;ed.
                                  &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;http&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; HTTP contains match criteria that apply to HTTP
                            requests.
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;methods&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Methods is an optional field that restricts
                                the rule to apply only to HTTP requests that use one of
                                the listed HTTP Methods (e.g. GET&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; PUT&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; etc.) Multiple
                                methods are OR&amp;#x27;d together.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;paths&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Paths is an optional field that restricts
                                the rule to apply to HTTP requests that use one of the
                                listed HTTP Paths. Multiple paths are OR&amp;#x27;&amp;#x27;d together.
                                &lt;span class=&quot;token key atrule&quot;&gt;e.g&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;exact&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;/foo - prefix&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;/bar NOTE&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Each entry may
                                ONLY specify either a `exact` or a `prefix` match. The
                                validator will check for it.&amp;#x27;
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;HTTPPath specifies an HTTP path to match.
                                  &lt;span class=&quot;token key atrule&quot;&gt;It may be either of the form&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;exact&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;&amp;lt;path&amp;gt;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; which matches
                                  &lt;span class=&quot;token key atrule&quot;&gt;the path exactly or prefix&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;&amp;lt;path-prefix&amp;gt;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; which matches
                                  the path prefix&amp;#x27;
                                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;exact&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                  &lt;span class=&quot;token key atrule&quot;&gt;prefix&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;icmp&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ICMP is an optional field that restricts the rule
                            to apply to a specific type and code of ICMP traffic.  This
                            should only be specified if the Protocol field is set to &amp;quot;ICMP&amp;quot;
                            or &amp;quot;ICMPv6&amp;quot;.
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;code&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Match on a specific ICMP code.  If specified&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                                the Type value must also be specified. This is a technical
                                limitation imposed by the kernel’s iptables firewall&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                                which Calico uses to enforce the rule.
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Match on a specific ICMP type.  For example
                                a value of 8 refers to ICMP Echo Request (i.e. pings).
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;ipVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; IPVersion is an optional field that restricts the
                            rule to only match a specific IP version.
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                        &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Metadata contains additional information for this
                            rule
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;annotations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;additionalProperties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Annotations is a set of key value pairs that
                                give extra information about the rule
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;notICMP&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotICMP is the negated version of the ICMP field.
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;code&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Match on a specific ICMP code.  If specified&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                                the Type value must also be specified. This is a technical
                                limitation imposed by the kernel’s iptables firewall&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                                which Calico uses to enforce the rule.
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Match on a specific ICMP type.  For example
                                a value of 8 refers to ICMP Echo Request (i.e. pings).
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                        &lt;span class=&quot;token key atrule&quot;&gt;notProtocol&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotProtocol is the negated version of the Protocol
                            field.
                          &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                          &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;protocol&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Protocol is an optional field that restricts the
                            rule to only apply to traffic of a specific IP protocol. Required
                            if any of the EntityRules contain Ports (because ports only
                            apply to certain protocols). \n Must be one of these string
                            &lt;span class=&quot;token key atrule&quot;&gt;values&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; \&amp;quot;TCP\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;UDP\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;ICMP\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;ICMPv6\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;SCTP\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                            \&amp;quot;UDPLite\&amp;quot; or an integer in the range 1&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;255.&amp;quot;
                          &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                          &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                        &lt;span class=&quot;token key atrule&quot;&gt;source&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                          &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Source contains the match criteria that apply to
                            source entity.
                          &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                            &lt;span class=&quot;token key atrule&quot;&gt;namespaceSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;NamespaceSelector is an optional field that
                                contains a selector expression. Only traffic that originates
                                from (or terminates at) endpoints within the selected
                                namespaces will be matched. When both NamespaceSelector
                                and Selector are defined on the same rule&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; then only workload
                                endpoints that are matched by both selectors will be selected
                                by the rule. \n For NetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; an empty NamespaceSelector
                                implies that the Selector is limited to selecting only
                                workload endpoints in the same namespace as the NetworkPolicy.
                                \n For NetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; `global()` NamespaceSelector implies
                                that the Selector is limited to selecting only GlobalNetworkSet
                                or HostEndpoint. \n For GlobalNetworkPolicy&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; an empty
                                NamespaceSelector implies the Selector applies to workload
                                endpoints across all namespaces.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;nets&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Nets is an optional field that restricts the
                                rule to only apply to traffic that originates from (or
                                terminates at) IP addresses in any of the given subnets.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notNets&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotNets is the negated version of the Nets
                                field.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notPorts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotPorts is the negated version of the Ports
                                field. Since only some protocols have ports&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if any ports
                                are specified it requires the Protocol match in the Rule
                                to be set to &amp;quot;TCP&amp;quot; or &amp;quot;UDP&amp;quot;.
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                                &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;notSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NotSelector is the negated version of the Selector
                                field.  See Selector field for subtleties with negated
                                selectors.
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;ports&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Ports is an optional field that restricts
                                the rule to only apply to traffic that has a source (destination)
                                port that matches one of these ranges/values. This value
                                is a list of integers or strings that represent ranges
                                of ports. \n Since only some protocols have ports&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if
                                any ports are specified it requires the Protocol match
                                in the Rule to be set to \&amp;quot;TCP\&amp;quot; or \&amp;quot;UDP\&amp;quot;.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;anyOf&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; integer
                                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                &lt;span class=&quot;token key atrule&quot;&gt;pattern&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ^.*
                                &lt;span class=&quot;token key atrule&quot;&gt;x-kubernetes-int-or-string&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                            &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Selector is an optional field that contains
                                a selector expression (see Policy for sample syntax).
                                \ Only traffic that originates from (terminates at) endpoints
                                &lt;span class=&quot;token key atrule&quot;&gt;matching the selector will be matched. \n Note that&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; in
                                addition to the negated version of the Selector (see NotSelector
                                below)&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the selector expression syntax itself supports
                                negation.  The two types of negation are subtly different.
                                One negates the set of matched endpoints&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; the other negates
                                &lt;span class=&quot;token key atrule&quot;&gt;the whole match&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; \n \tSelector = \&amp;quot;&lt;span class=&quot;token tag&quot;&gt;!has(my_label)&lt;/span&gt;\&amp;quot; matches
                                packets that are from other Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled \tendpoints
                                that do not have the label “my_label”. \n \tNotSelector
                                = \&amp;quot;has(my_label)\&amp;quot; matches packets that are not from
                                Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled \tendpoints that do have the label “my_label”.
                                \n The effect is that the latter will accept packets from
                                non&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;Calico sources whereas the former is limited to packets
                                from Calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controlled endpoints.&amp;quot;
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                            &lt;span class=&quot;token key atrule&quot;&gt;serviceAccounts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                              &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ServiceAccounts is an optional field that restricts
                                the rule to only apply to traffic that originates from
                                (or terminates at) a pod running as a matching service
                                account.
                              &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Names is an optional field that restricts
                                    the rule to only apply to traffic that originates
                                    from (or terminates at) a pod running as a service
                                    account whose name is in the list.
                                  &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                                  &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                                &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                                  &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Selector is an optional field that restricts
                                    the rule to only apply to traffic that originates
                                    from (or terminates at) a pod running as a service
                                    account that matches the given label selector. If
                                    both Names and Selector are specified then they are
                                    AND&amp;#x27;ed.
                                  &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                              &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                          &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                      &lt;span class=&quot;token key atrule&quot;&gt;required&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; action
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                  &lt;span class=&quot;token key atrule&quot;&gt;order&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Order is an optional field that specifies the order in
                      which the policy is applied. Policies with higher &amp;quot;order&amp;quot; are applied
                      after those with lower order.  If the order is omitted&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; it may be
                      considered to be &amp;quot;infinite&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; i.e. the policy will be applied last.  Policies
                      with identical order will be applied in alphanumerical order based
                      on the Policy &amp;quot;Name&amp;quot;.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; number
                  &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;The selector is an expression used to pick pick out
                      the endpoints that the policy should be applied to. \n Selector
                      &lt;span class=&quot;token key atrule&quot;&gt;expressions follow this syntax&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; \n \tlabel == \&amp;quot;string_literal\&amp;quot;
                      \ &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;  comparison&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; e.g. my_label == \&amp;quot;foo bar\&amp;quot; \tlabel &lt;span class=&quot;token tag&quot;&gt;!=&lt;/span&gt; \&amp;quot;string_literal\&amp;quot;
                      \  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;  not equal; also matches if label is not present \tlabel in
                      &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; \&amp;quot;a\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;b\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;c\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;...&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;  true if the value of label X is
                      one of \&amp;quot;a\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;b\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;c\&amp;quot; \tlabel not in &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; \&amp;quot;a\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;b\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;c\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      &lt;span class=&quot;token punctuation&quot;&gt;...&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;  true if the value of label X is not one of \&amp;quot;a\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;b\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      \&amp;quot;c\&amp;quot; \thas(label_name)  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt; True if that label is present \t&lt;span class=&quot;token tag&quot;&gt;!&lt;/span&gt; expr
                      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt; negation of expr \texpr &lt;span class=&quot;token important&quot;&gt;&amp;amp;&amp;amp;&lt;/span&gt; expr  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt; Short&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;circuit and \texpr
                      &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt; expr  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt; Short&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;circuit or \t( expr ) &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt; parens for grouping \tall()
                      or the empty selector &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt; matches all endpoints. \n Label names are
                      allowed to contain alphanumerics&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; _ and /. String literals are
                      more permissive but they do not support escape characters. \n Examples
                      &lt;span class=&quot;token key atrule&quot;&gt;(with made-up labels)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; \n \ttype == \&amp;quot;webserver\&amp;quot; &lt;span class=&quot;token important&quot;&gt;&amp;amp;&amp;amp;&lt;/span&gt; deployment
                      == \&amp;quot;prod\&amp;quot; \ttype in &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;\&amp;quot;frontend\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; \&amp;quot;backend\&amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt; \tdeployment &lt;span class=&quot;token tag&quot;&gt;!=&lt;/span&gt;
                      \&amp;quot;dev\&amp;quot; \t&lt;span class=&quot;token tag&quot;&gt;!&lt;/span&gt; has(label_name)&amp;quot;
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;serviceAccountSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ServiceAccountSelector is an optional field for an expression
                      used to select a pod based on service accounts.
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                  &lt;span class=&quot;token key atrule&quot;&gt;types&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;quot;Types indicates whether this policy applies to ingress&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      or to egress&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; or to both.  When not explicitly specified (and so
                      the value on creation is empty or nil)&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; Calico defaults Types according
                      to what Ingress and Egress are present in the policy.  The default
                      &lt;span class=&quot;token key atrule&quot;&gt;is&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; \n &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt; PolicyTypeIngress &lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if there are no Egress rules (including
                      the case where there are   also no Ingress rules) \n &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt; PolicyTypeEgress
                      &lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if there are Egress rules but no Ingress rules \n &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt; PolicyTypeIngress&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;
                      PolicyTypeEgress &lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; if there are both Ingress and Egress rules.
                      \n When the policy is read back again&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; Types will always be one
                      of these values&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; never empty or nil.&amp;quot;
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; PolicyType enumerates the possible values of the PolicySpec
                        Types field.
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
        &lt;span class=&quot;token key atrule&quot;&gt;served&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;storage&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;status&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;acceptedNames&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;conditions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;storedVersions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; apiextensions.k8s.io/v1
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CustomResourceDefinition
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;annotations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;controller-gen.kubebuilder.io/version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; (devel)
      &lt;span class=&quot;token key atrule&quot;&gt;creationTimestamp&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token null important&quot;&gt;null&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; networksets.crd.projectcalico.org
    &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;group&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; crd.projectcalico.org
      &lt;span class=&quot;token key atrule&quot;&gt;names&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NetworkSet
        &lt;span class=&quot;token key atrule&quot;&gt;listKind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NetworkSetList
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; networksets
        &lt;span class=&quot;token key atrule&quot;&gt;singular&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; networkset
      &lt;span class=&quot;token key atrule&quot;&gt;scope&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Namespaced
      &lt;span class=&quot;token key atrule&quot;&gt;versions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; v1
        &lt;span class=&quot;token key atrule&quot;&gt;schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;openAPIV3Schema&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NetworkSet is the Namespaced&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;equivalent of the GlobalNetworkSet.
            &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;APIVersion defines the versioned schema of this representation
                  of an object. Servers should convert recognized schemas to the latest
                  internal value&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;and may reject unrecognized values. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#resources&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &amp;#x27;Kind is a string value representing the REST resource this
                  object represents. Servers may infer this from the endpoint the client
                  &lt;span class=&quot;token key atrule&quot;&gt;submits requests to. Cannot be updated. In CamelCase. More info&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; https&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;//git.k8s.io/community/contributors/devel/sig&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;architecture/api&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;conventions.md&lt;span class=&quot;token comment&quot;&gt;#types-kinds&amp;#x27;&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
              &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
              &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NetworkSetSpec contains the specification for a NetworkSet
                  resource.
                &lt;span class=&quot;token key atrule&quot;&gt;properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;nets&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;description&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; The list of IP networks that belong to this set.
                    &lt;span class=&quot;token key atrule&quot;&gt;items&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; string
                    &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; array
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
            &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; object
        &lt;span class=&quot;token key atrule&quot;&gt;served&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;storage&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;status&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;acceptedNames&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;plural&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;conditions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;storedVersions&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token comment&quot;&gt;# Source: calico/templates/calico-kube-controllers-rbac.yaml&lt;/span&gt;

    &lt;span class=&quot;token comment&quot;&gt;# Include a clusterrole for the kube-controllers component,&lt;/span&gt;
    &lt;span class=&quot;token comment&quot;&gt;# and bind it to the calico-kube-controllers serviceaccount.&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ClusterRole
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; rbac.authorization.k8s.io/v1
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controllers
    &lt;span class=&quot;token key atrule&quot;&gt;rules&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token comment&quot;&gt;# Nodes are watched to monitor for deletions.&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; nodes
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; watch
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; list
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; get
      &lt;span class=&quot;token comment&quot;&gt;# Pods are queried to check for existence.&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; pods
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; get
      &lt;span class=&quot;token comment&quot;&gt;# IPAM resources are manipulated when nodes are deleted.&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;crd.projectcalico.org&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; ippools
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; list
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;crd.projectcalico.org&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; blockaffinities
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; ipamblocks
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; ipamhandles
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; get
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; list
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; create
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; update
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; delete
      &lt;span class=&quot;token comment&quot;&gt;# kube-controllers manages hostendpoints.&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;crd.projectcalico.org&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; hostendpoints
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; get
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; list
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; create
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; update
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; delete
      &lt;span class=&quot;token comment&quot;&gt;# Needs access to update clusterinformations.&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;crd.projectcalico.org&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; clusterinformations
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; get
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; create
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; update
      &lt;span class=&quot;token comment&quot;&gt;# KubeControllersConfiguration is where it gets its config&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;crd.projectcalico.org&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; kubecontrollersconfigurations
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token comment&quot;&gt;# read its own config&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; get
          &lt;span class=&quot;token comment&quot;&gt;# create a default if none exists&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; create
          &lt;span class=&quot;token comment&quot;&gt;# update status&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; update
          &lt;span class=&quot;token comment&quot;&gt;# watch for changes&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; watch
    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ClusterRoleBinding
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; rbac.authorization.k8s.io/v1
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controllers
    &lt;span class=&quot;token key atrule&quot;&gt;roleRef&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;apiGroup&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; rbac.authorization.k8s.io
      &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ClusterRole
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controllers
    &lt;span class=&quot;token key atrule&quot;&gt;subjects&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ServiceAccount
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controllers
      &lt;span class=&quot;token key atrule&quot;&gt;namespace&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;system
    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token comment&quot;&gt;# Source: calico/templates/calico-node-rbac.yaml&lt;/span&gt;
    &lt;span class=&quot;token comment&quot;&gt;# Include a clusterrole for the calico-node DaemonSet,&lt;/span&gt;
    &lt;span class=&quot;token comment&quot;&gt;# and bind it to the calico-node serviceaccount.&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ClusterRole
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; rbac.authorization.k8s.io/v1
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;node
    &lt;span class=&quot;token key atrule&quot;&gt;rules&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token comment&quot;&gt;# The CNI plugin needs to get pods, nodes, and namespaces.&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; pods
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; nodes
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; namespaces
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; get
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; endpoints
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; services
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token comment&quot;&gt;# Used to discover service IPs for advertisement.&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; watch
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; list
          &lt;span class=&quot;token comment&quot;&gt;# Used to discover Typhas.&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; get
      &lt;span class=&quot;token comment&quot;&gt;# Pod CIDR auto-detection on kubeadm needs access to config maps.&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; configmaps
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; get
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; nodes/status
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token comment&quot;&gt;# Needed for clearing NodeNetworkUnavailable flag.&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; patch
          &lt;span class=&quot;token comment&quot;&gt;# Calico stores some configuration information in node annotations.&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; update
      &lt;span class=&quot;token comment&quot;&gt;# Watch for changes to Kubernetes NetworkPolicies.&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;networking.k8s.io&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; networkpolicies
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; watch
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; list
      &lt;span class=&quot;token comment&quot;&gt;# Used by Calico for policy information.&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; pods
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; namespaces
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; serviceaccounts
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; list
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; watch
      &lt;span class=&quot;token comment&quot;&gt;# The CNI plugin patches pods/status.&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; pods/status
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; patch
      &lt;span class=&quot;token comment&quot;&gt;# Calico monitors various CRDs for config.&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;crd.projectcalico.org&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; globalfelixconfigs
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; felixconfigurations
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; bgppeers
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; globalbgpconfigs
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; bgpconfigurations
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; ippools
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; ipamblocks
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; globalnetworkpolicies
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; globalnetworksets
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; networkpolicies
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; networksets
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; clusterinformations
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; hostendpoints
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; blockaffinities
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; get
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; list
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; watch
      &lt;span class=&quot;token comment&quot;&gt;# Calico must create and update some CRDs on startup.&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;crd.projectcalico.org&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; ippools
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; felixconfigurations
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; clusterinformations
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; create
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; update
      &lt;span class=&quot;token comment&quot;&gt;# Calico stores some configuration information on the node.&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; nodes
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; get
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; list
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; watch
      &lt;span class=&quot;token comment&quot;&gt;# These permissions are only required for upgrade from v2.6, and can&lt;/span&gt;
      &lt;span class=&quot;token comment&quot;&gt;# be removed after upgrade or on fresh installations.&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;crd.projectcalico.org&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; bgpconfigurations
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; bgppeers
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; create
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; update
      &lt;span class=&quot;token comment&quot;&gt;# These permissions are required for Calico CNI to perform IPAM allocations.&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;crd.projectcalico.org&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; blockaffinities
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; ipamblocks
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; ipamhandles
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; get
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; list
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; create
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; update
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; delete
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;crd.projectcalico.org&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; ipamconfigs
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; get
      &lt;span class=&quot;token comment&quot;&gt;# Block affinities must also be watchable by confd for route aggregation.&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;crd.projectcalico.org&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; blockaffinities
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; watch
      &lt;span class=&quot;token comment&quot;&gt;# The Calico IPAM migration needs to get daemonsets. These permissions can be&lt;/span&gt;
      &lt;span class=&quot;token comment&quot;&gt;# removed if not upgrading from an installation using host-local IPAM.&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;apiGroups&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;apps&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; daemonsets
        &lt;span class=&quot;token key atrule&quot;&gt;verbs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; get

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; rbac.authorization.k8s.io/v1
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ClusterRoleBinding
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;node
    &lt;span class=&quot;token key atrule&quot;&gt;roleRef&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;apiGroup&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; rbac.authorization.k8s.io
      &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ClusterRole
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;node
    &lt;span class=&quot;token key atrule&quot;&gt;subjects&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ServiceAccount
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;node
      &lt;span class=&quot;token key atrule&quot;&gt;namespace&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;system

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token comment&quot;&gt;# Source: calico/templates/calico-node.yaml&lt;/span&gt;
    &lt;span class=&quot;token comment&quot;&gt;# This manifest installs the calico-node container, as well&lt;/span&gt;
    &lt;span class=&quot;token comment&quot;&gt;# as the CNI plugins and network config on&lt;/span&gt;
    &lt;span class=&quot;token comment&quot;&gt;# each master and worker node in a Kubernetes cluster.&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; DaemonSet
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; apps/v1
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;node
      &lt;span class=&quot;token key atrule&quot;&gt;namespace&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;system
      &lt;span class=&quot;token key atrule&quot;&gt;labels&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;k8s-app&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;node
    &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;matchLabels&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;k8s-app&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;node
      &lt;span class=&quot;token key atrule&quot;&gt;updateStrategy&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; RollingUpdate
        &lt;span class=&quot;token key atrule&quot;&gt;rollingUpdate&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;maxUnavailable&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;1&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;template&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;labels&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token key atrule&quot;&gt;k8s-app&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;node
        &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;nodeSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token key atrule&quot;&gt;kubernetes.io/os&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; linux
          &lt;span class=&quot;token key atrule&quot;&gt;hostNetwork&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;tolerations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token comment&quot;&gt;# Make sure calico-node gets scheduled on all nodes.&lt;/span&gt;
            &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;effect&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NoSchedule
              &lt;span class=&quot;token key atrule&quot;&gt;operator&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Exists
            &lt;span class=&quot;token comment&quot;&gt;# Mark the pod as a critical add-on for rescheduling.&lt;/span&gt;
            &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;key&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CriticalAddonsOnly
              &lt;span class=&quot;token key atrule&quot;&gt;operator&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Exists
            &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;effect&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NoExecute
              &lt;span class=&quot;token key atrule&quot;&gt;operator&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Exists
          &lt;span class=&quot;token key atrule&quot;&gt;serviceAccountName&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;node
          &lt;span class=&quot;token comment&quot;&gt;# Minimize downtime during a rolling upgrade or deletion; tell Kubernetes to do a &amp;quot;force&lt;/span&gt;
          &lt;span class=&quot;token comment&quot;&gt;# deletion&amp;quot;: https://kubernetes.io/docs/concepts/workloads/pods/pod/#termination-of-pods.&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;terminationGracePeriodSeconds&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;0&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;priorityClassName&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; system&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;node&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;critical
          &lt;span class=&quot;token key atrule&quot;&gt;initContainers&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token comment&quot;&gt;# This container performs upgrade from host-local IPAM to calico-ipam.&lt;/span&gt;
            &lt;span class=&quot;token comment&quot;&gt;# It can be deleted if this is a fresh installation, or if you have already&lt;/span&gt;
            &lt;span class=&quot;token comment&quot;&gt;# upgraded to use calico-ipam.&lt;/span&gt;
            &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; upgrade&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;ipam
              &lt;span class=&quot;token key atrule&quot;&gt;image&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico/cni&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;v3.16.1
              &lt;span class=&quot;token key atrule&quot;&gt;command&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;/opt/cni/bin/calico-ipam&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;-upgrade&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;envFrom&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
              &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;configMapRef&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token comment&quot;&gt;# Allow KUBERNETES_SERVICE_HOST and KUBERNETES_SERVICE_PORT to be overridden for eBPF mode.&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; kubernetes&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;services&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;endpoint
                  &lt;span class=&quot;token key atrule&quot;&gt;optional&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;env&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; KUBERNETES_NODE_NAME
                  &lt;span class=&quot;token key atrule&quot;&gt;valueFrom&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;fieldRef&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;fieldPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; spec.nodeName
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CALICO_NETWORKING_BACKEND
                  &lt;span class=&quot;token key atrule&quot;&gt;valueFrom&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;configMapKeyRef&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;config
                      &lt;span class=&quot;token key atrule&quot;&gt;key&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico_backend
              &lt;span class=&quot;token key atrule&quot;&gt;volumeMounts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;mountPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /var/lib/cni/networks
                  &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; host&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;local&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;net&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;dir
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;mountPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /host/opt/cni/bin
                  &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; cni&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;bin&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;dir
              &lt;span class=&quot;token key atrule&quot;&gt;securityContext&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;privileged&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
            &lt;span class=&quot;token comment&quot;&gt;# This container installs the CNI binaries&lt;/span&gt;
            &lt;span class=&quot;token comment&quot;&gt;# and CNI network config file on each node.&lt;/span&gt;
            &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; install&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;cni
              &lt;span class=&quot;token key atrule&quot;&gt;image&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico/cni&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;v3.16.1
              &lt;span class=&quot;token key atrule&quot;&gt;command&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;/opt/cni/bin/install&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;envFrom&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
              &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;configMapRef&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token comment&quot;&gt;# Allow KUBERNETES_SERVICE_HOST and KUBERNETES_SERVICE_PORT to be overridden for eBPF mode.&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; kubernetes&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;services&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;endpoint
                  &lt;span class=&quot;token key atrule&quot;&gt;optional&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;env&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token comment&quot;&gt;# Name of the CNI config file to create.&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CNI_CONF_NAME
                  &lt;span class=&quot;token key atrule&quot;&gt;value&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;10-calico.conflist&amp;quot;&lt;/span&gt;
                &lt;span class=&quot;token comment&quot;&gt;# The CNI network config to install on each node.&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CNI_NETWORK_CONFIG
                  &lt;span class=&quot;token key atrule&quot;&gt;valueFrom&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;configMapKeyRef&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;config
                      &lt;span class=&quot;token key atrule&quot;&gt;key&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; cni_network_config
                &lt;span class=&quot;token comment&quot;&gt;# Set the hostname based on the k8s node name.&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; KUBERNETES_NODE_NAME
                  &lt;span class=&quot;token key atrule&quot;&gt;valueFrom&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;fieldRef&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;fieldPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; spec.nodeName
                &lt;span class=&quot;token comment&quot;&gt;# CNI MTU Config variable&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CNI_MTU
                  &lt;span class=&quot;token key atrule&quot;&gt;valueFrom&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;configMapKeyRef&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;config
                      &lt;span class=&quot;token key atrule&quot;&gt;key&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; veth_mtu
                &lt;span class=&quot;token comment&quot;&gt;# Prevents the container from sleeping forever.&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; SLEEP
                  &lt;span class=&quot;token key atrule&quot;&gt;value&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;false&amp;quot;&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;volumeMounts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;mountPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /host/opt/cni/bin
                  &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; cni&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;bin&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;dir
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;mountPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /host/etc/cni/net.d
                  &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; cni&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;net&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;dir
              &lt;span class=&quot;token key atrule&quot;&gt;securityContext&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;privileged&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
            &lt;span class=&quot;token comment&quot;&gt;# Adds a Flex Volume Driver that creates a per-pod Unix Domain Socket to allow Dikastes&lt;/span&gt;
            &lt;span class=&quot;token comment&quot;&gt;# to communicate with Felix over the Policy Sync API.&lt;/span&gt;
            &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; flexvol&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;driver
              &lt;span class=&quot;token key atrule&quot;&gt;image&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico/pod2daemon&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;flexvol&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;v3.16.1
              &lt;span class=&quot;token key atrule&quot;&gt;volumeMounts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
              &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; flexvol&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;driver&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;host
                &lt;span class=&quot;token key atrule&quot;&gt;mountPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /host/driver
              &lt;span class=&quot;token key atrule&quot;&gt;securityContext&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;privileged&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;containers&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token comment&quot;&gt;# Runs calico-node container on each Kubernetes node. This&lt;/span&gt;
            &lt;span class=&quot;token comment&quot;&gt;# container programs network policy and routes on each&lt;/span&gt;
            &lt;span class=&quot;token comment&quot;&gt;# host.&lt;/span&gt;
            &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;node
              &lt;span class=&quot;token key atrule&quot;&gt;image&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico/node&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;v3.16.1
              &lt;span class=&quot;token key atrule&quot;&gt;envFrom&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
              &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;configMapRef&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token comment&quot;&gt;# Allow KUBERNETES_SERVICE_HOST and KUBERNETES_SERVICE_PORT to be overridden for eBPF mode.&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; kubernetes&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;services&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;endpoint
                  &lt;span class=&quot;token key atrule&quot;&gt;optional&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;env&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token comment&quot;&gt;# Use Kubernetes API as the backing datastore.&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; DATASTORE_TYPE
                  &lt;span class=&quot;token key atrule&quot;&gt;value&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;kubernetes&amp;quot;&lt;/span&gt;
                &lt;span class=&quot;token comment&quot;&gt;# Wait for the datastore.&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; WAIT_FOR_DATASTORE
                  &lt;span class=&quot;token key atrule&quot;&gt;value&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;true&amp;quot;&lt;/span&gt;
                &lt;span class=&quot;token comment&quot;&gt;# Set based on the k8s node name.&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NODENAME
                  &lt;span class=&quot;token key atrule&quot;&gt;valueFrom&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;fieldRef&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;fieldPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; spec.nodeName
                &lt;span class=&quot;token comment&quot;&gt;# Choose the backend to use.&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CALICO_NETWORKING_BACKEND
                  &lt;span class=&quot;token key atrule&quot;&gt;valueFrom&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;configMapKeyRef&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;config
                      &lt;span class=&quot;token key atrule&quot;&gt;key&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico_backend
                &lt;span class=&quot;token comment&quot;&gt;# Cluster type to identify the deployment type&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CLUSTER_TYPE
                  &lt;span class=&quot;token key atrule&quot;&gt;value&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;k8s,bgp&amp;quot;&lt;/span&gt;
                &lt;span class=&quot;token comment&quot;&gt;# Auto-detect the BGP IP address.&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; IP
                  &lt;span class=&quot;token key atrule&quot;&gt;value&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;autodetect&amp;quot;&lt;/span&gt;
                &lt;span class=&quot;token comment&quot;&gt;# Enable IPIP&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CALICO_IPV4POOL_IPIP
                  &lt;span class=&quot;token key atrule&quot;&gt;value&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;Always&amp;quot;&lt;/span&gt;
                &lt;span class=&quot;token comment&quot;&gt;# Enable or Disable VXLAN on the default IP pool.&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CALICO_IPV4POOL_VXLAN
                  &lt;span class=&quot;token key atrule&quot;&gt;value&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;Never&amp;quot;&lt;/span&gt;
                &lt;span class=&quot;token comment&quot;&gt;# Set MTU for tunnel device used if ipip is enabled&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; FELIX_IPINIPMTU
                  &lt;span class=&quot;token key atrule&quot;&gt;valueFrom&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;configMapKeyRef&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;config
                      &lt;span class=&quot;token key atrule&quot;&gt;key&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; veth_mtu
                &lt;span class=&quot;token comment&quot;&gt;# Set MTU for the VXLAN tunnel device.&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; FELIX_VXLANMTU
                  &lt;span class=&quot;token key atrule&quot;&gt;valueFrom&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;configMapKeyRef&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;config
                      &lt;span class=&quot;token key atrule&quot;&gt;key&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; veth_mtu
                &lt;span class=&quot;token comment&quot;&gt;# Set MTU for the Wireguard tunnel device.&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; FELIX_WIREGUARDMTU
                  &lt;span class=&quot;token key atrule&quot;&gt;valueFrom&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                    &lt;span class=&quot;token key atrule&quot;&gt;configMapKeyRef&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;config
                      &lt;span class=&quot;token key atrule&quot;&gt;key&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; veth_mtu
                &lt;span class=&quot;token comment&quot;&gt;# The default IPv4 pool to create on startup if none exists. Pod IPs will be&lt;/span&gt;
                &lt;span class=&quot;token comment&quot;&gt;# chosen from this range. Changing this value after installation will have&lt;/span&gt;
                &lt;span class=&quot;token comment&quot;&gt;# no effect. This should fall within `--cluster-cidr`.&lt;/span&gt;
                &lt;span class=&quot;token comment&quot;&gt;# - name: CALICO_IPV4POOL_CIDR&lt;/span&gt;
                &lt;span class=&quot;token comment&quot;&gt;#   value: &amp;quot;192.168.0.0/16&amp;quot;&lt;/span&gt;
                &lt;span class=&quot;token comment&quot;&gt;# Disable file logging so `kubectl logs` works.&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CALICO_DISABLE_FILE_LOGGING
                  &lt;span class=&quot;token key atrule&quot;&gt;value&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;true&amp;quot;&lt;/span&gt;
                &lt;span class=&quot;token comment&quot;&gt;# Set Felix endpoint to host default action to ACCEPT.&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; FELIX_DEFAULTENDPOINTTOHOSTACTION
                  &lt;span class=&quot;token key atrule&quot;&gt;value&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;ACCEPT&amp;quot;&lt;/span&gt;
                &lt;span class=&quot;token comment&quot;&gt;# Disable IPv6 on Kubernetes.&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; FELIX_IPV6SUPPORT
                  &lt;span class=&quot;token key atrule&quot;&gt;value&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;false&amp;quot;&lt;/span&gt;
                &lt;span class=&quot;token comment&quot;&gt;# Set Felix logging to &amp;quot;info&amp;quot;&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; FELIX_LOGSEVERITYSCREEN
                  &lt;span class=&quot;token key atrule&quot;&gt;value&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;info&amp;quot;&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; FELIX_HEALTHENABLED
                  &lt;span class=&quot;token key atrule&quot;&gt;value&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;true&amp;quot;&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;securityContext&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;privileged&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;requests&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;cpu&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; 250m
              &lt;span class=&quot;token key atrule&quot;&gt;livenessProbe&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;exec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;command&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; /bin/calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;node
                  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;felix&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;live
                  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;bird&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;live
                &lt;span class=&quot;token key atrule&quot;&gt;periodSeconds&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;10&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;initialDelaySeconds&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;10&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;failureThreshold&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;6&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;readinessProbe&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;exec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;command&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; /bin/calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;node
                  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;felix&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;ready
                  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;bird&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;ready
                &lt;span class=&quot;token key atrule&quot;&gt;periodSeconds&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;10&lt;/span&gt;
              &lt;span class=&quot;token key atrule&quot;&gt;volumeMounts&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;mountPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /lib/modules
                  &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; lib&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;modules
                  &lt;span class=&quot;token key atrule&quot;&gt;readOnly&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;mountPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /run/xtables.lock
                  &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; xtables&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;lock
                  &lt;span class=&quot;token key atrule&quot;&gt;readOnly&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;false&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;mountPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /var/run/calico
                  &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; var&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;run&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;calico
                  &lt;span class=&quot;token key atrule&quot;&gt;readOnly&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;false&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;mountPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /var/lib/calico
                  &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; var&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;lib&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;calico
                  &lt;span class=&quot;token key atrule&quot;&gt;readOnly&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;false&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; policysync
                  &lt;span class=&quot;token key atrule&quot;&gt;mountPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /var/run/nodeagent
                &lt;span class=&quot;token comment&quot;&gt;# For eBPF mode, we need to be able to mount the BPF filesystem at /sys/fs/bpf so we mount in the&lt;/span&gt;
                &lt;span class=&quot;token comment&quot;&gt;# parent directory.&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; sysfs
                  &lt;span class=&quot;token key atrule&quot;&gt;mountPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /sys/fs/
                  &lt;span class=&quot;token comment&quot;&gt;# Bidirectional means that, if we mount the BPF filesystem at /sys/fs/bpf it will propagate to the host.&lt;/span&gt;
                  &lt;span class=&quot;token comment&quot;&gt;# If the host is known to mount that filesystem already then Bidirectional can be omitted.&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;mountPropagation&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Bidirectional
          &lt;span class=&quot;token key atrule&quot;&gt;volumes&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token comment&quot;&gt;# Used by calico-node.&lt;/span&gt;
            &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; lib&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;modules
              &lt;span class=&quot;token key atrule&quot;&gt;hostPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;path&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /lib/modules
            &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; var&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;run&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;calico
              &lt;span class=&quot;token key atrule&quot;&gt;hostPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;path&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /var/run/calico
            &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; var&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;lib&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;calico
              &lt;span class=&quot;token key atrule&quot;&gt;hostPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;path&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /var/lib/calico
            &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; xtables&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;lock
              &lt;span class=&quot;token key atrule&quot;&gt;hostPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;path&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /run/xtables.lock
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; FileOrCreate
            &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; sysfs
              &lt;span class=&quot;token key atrule&quot;&gt;hostPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;path&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /sys/fs/
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; DirectoryOrCreate
            &lt;span class=&quot;token comment&quot;&gt;# Used to install CNI.&lt;/span&gt;
            &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; cni&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;bin&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;dir
              &lt;span class=&quot;token key atrule&quot;&gt;hostPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;path&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /opt/cni/bin
            &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; cni&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;net&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;dir
              &lt;span class=&quot;token key atrule&quot;&gt;hostPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;path&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /etc/cni/net.d
            &lt;span class=&quot;token comment&quot;&gt;# Mount in the directory for host-local IPAM allocations. This is&lt;/span&gt;
            &lt;span class=&quot;token comment&quot;&gt;# used when upgrading from host-local to calico-ipam, and can be removed&lt;/span&gt;
            &lt;span class=&quot;token comment&quot;&gt;# if not using the upgrade-ipam init container.&lt;/span&gt;
            &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; host&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;local&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;net&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;dir
              &lt;span class=&quot;token key atrule&quot;&gt;hostPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;path&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /var/lib/cni/networks
            &lt;span class=&quot;token comment&quot;&gt;# Used to create per-pod Unix Domain Sockets&lt;/span&gt;
            &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; policysync
              &lt;span class=&quot;token key atrule&quot;&gt;hostPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; DirectoryOrCreate
                &lt;span class=&quot;token key atrule&quot;&gt;path&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /var/run/nodeagent
            &lt;span class=&quot;token comment&quot;&gt;# Used to install Flex Volume Driver&lt;/span&gt;
            &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; flexvol&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;driver&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;host
              &lt;span class=&quot;token key atrule&quot;&gt;hostPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; DirectoryOrCreate
                &lt;span class=&quot;token key atrule&quot;&gt;path&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /usr/libexec/kubernetes/kubelet&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;plugins/volume/exec/nodeagent~uds
    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;

    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; v1
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ServiceAccount
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;node
      &lt;span class=&quot;token key atrule&quot;&gt;namespace&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;system

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token comment&quot;&gt;# Source: calico/templates/calico-kube-controllers.yaml&lt;/span&gt;
    &lt;span class=&quot;token comment&quot;&gt;# See https://github.com/projectcalico/kube-controllers&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; apps/v1
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Deployment
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controllers
      &lt;span class=&quot;token key atrule&quot;&gt;namespace&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;system
      &lt;span class=&quot;token key atrule&quot;&gt;labels&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;k8s-app&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controllers
    &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token comment&quot;&gt;# The controllers can only have a single active instance.&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;replicas&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;1&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;matchLabels&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;k8s-app&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controllers
      &lt;span class=&quot;token key atrule&quot;&gt;strategy&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;type&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Recreate
      &lt;span class=&quot;token key atrule&quot;&gt;template&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controllers
          &lt;span class=&quot;token key atrule&quot;&gt;namespace&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;system
          &lt;span class=&quot;token key atrule&quot;&gt;labels&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token key atrule&quot;&gt;k8s-app&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controllers
        &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;nodeSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token key atrule&quot;&gt;kubernetes.io/os&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; linux
          &lt;span class=&quot;token key atrule&quot;&gt;tolerations&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token comment&quot;&gt;# Mark the pod as a critical add-on for rescheduling.&lt;/span&gt;
            &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;key&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; CriticalAddonsOnly
              &lt;span class=&quot;token key atrule&quot;&gt;operator&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Exists
            &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;key&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; node&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;role.kubernetes.io/master
              &lt;span class=&quot;token key atrule&quot;&gt;effect&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; NoSchedule
          &lt;span class=&quot;token key atrule&quot;&gt;serviceAccountName&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controllers
          &lt;span class=&quot;token key atrule&quot;&gt;priorityClassName&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; system&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;cluster&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;critical
          &lt;span class=&quot;token key atrule&quot;&gt;containers&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
            &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controllers
              &lt;span class=&quot;token key atrule&quot;&gt;image&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico/kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controllers&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;v3.16.1
              &lt;span class=&quot;token key atrule&quot;&gt;env&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token comment&quot;&gt;# Choose which controllers to run.&lt;/span&gt;
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ENABLED_CONTROLLERS
                  &lt;span class=&quot;token key atrule&quot;&gt;value&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; node
                &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; DATASTORE_TYPE
                  &lt;span class=&quot;token key atrule&quot;&gt;value&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; kubernetes
              &lt;span class=&quot;token key atrule&quot;&gt;readinessProbe&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                &lt;span class=&quot;token key atrule&quot;&gt;exec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token key atrule&quot;&gt;command&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
                  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; /usr/bin/check&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;status
                  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;r

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;

    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; v1
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ServiceAccount
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;controllers
      &lt;span class=&quot;token key atrule&quot;&gt;namespace&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; kube&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;system

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token comment&quot;&gt;# Source: calico/templates/calico-etcd-secrets.yaml&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token comment&quot;&gt;# Source: calico/templates/calico-typha.yaml&lt;/span&gt;

    &lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
    &lt;span class=&quot;token comment&quot;&gt;# Source: calico/templates/configure-canal.yaml&lt;/span&gt;


&lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ConfigMap
&lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;creationTimestamp&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token null important&quot;&gt;null&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;cni
&lt;span class=&quot;token punctuation&quot;&gt;---&lt;/span&gt;
&lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; addons.cluster.x&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;k8s.io/v1alpha3
&lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ClusterResourceSet
&lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; $&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; CLUSTER_NAME &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;crs&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;0&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;namespace&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ NAMESPACE }&amp;#x27;&lt;/span&gt;
&lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;clusterSelector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;matchLabels&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;cluster.x-k8s.io/cluster-name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;${ CLUSTER_NAME }&amp;#x27;&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;resources&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
  &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ConfigMap
    &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; calico&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;cni&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;</content:encoded><tags>kubernetes,development,vmware</tags><featuredImage>https://samperrin.com/static/a0511c8075ba8349a213f67f0f3e2347/hero_5.jpg</featuredImage></item><item><title><![CDATA[Cluster API - Using a Private Container Registry]]></title><description><![CDATA[Quick steps on getting a Private Container Registry working with Cluster API Provider vSphere (CAPV) images]]></description><link>https://samperrin.com/posts/cluster-api-using-a-private-container-registry/</link><guid isPermaLink="false">https://samperrin.com/posts/cluster-api-using-a-private-container-registry/</guid><category><![CDATA[kubernetes]]></category><category><![CDATA[development]]></category><category><![CDATA[vmware]]></category><pubDate>Mon, 17 Aug 2020 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;The pre-configured Cluster API Provider vSphere (CAPV) images use &lt;code class=&quot;language-text&quot;&gt;containerd&lt;/code&gt; as their Container Runtime, and to get this to pull images from a non-secure, or self-signed certificate container registry you need to make a few changes to the &lt;code class=&quot;language-text&quot;&gt;/etc/containerd/config.toml&lt;/code&gt; file.&lt;/p&gt;&lt;p&gt;These are the steps I followed to get a private &lt;a href=&quot;https://goharbor.io/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;Harbor&lt;/a&gt; repository working over https with a self-signed certificate, that my Kubernetes clusters did not trust. &lt;/p&gt;&lt;p&gt;If you have already deployed your workload cluster that needs to use this Private Registry, the easiest way to get this working is to manually adjust the file on each of the Kubernetes nodes, and restart the relevant service. &lt;/p&gt;&lt;p&gt;&lt;strong&gt;Existing Workload Cluster&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;SSH (default username is &lt;code class=&quot;language-text&quot;&gt;capv&lt;/code&gt; if created with CAPV) to each node in the workload cluster, and run the following (&lt;strong&gt;this will replace any existing content of the file&lt;/strong&gt;).&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;&lt;span class=&quot;token function&quot;&gt;sudo&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;su&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;cat&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;&amp;gt;&lt;/span&gt; /etc/containerd/config.toml &lt;span class=&quot;token operator&quot;&gt;&amp;lt;&amp;lt;&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;EOF
version = 2
[plugins]
  [plugins.&amp;quot;io.containerd.grpc.v1.cri&amp;quot;]
    sandbox_image = &amp;quot;k8s.gcr.io/pause:3.2&amp;quot;
    [plugins.&amp;quot;io.containerd.grpc.v1.cri&amp;quot;.registry.mirrors]
      [plugins.&amp;quot;io.containerd.grpc.v1.cri&amp;quot;.registry.mirrors.&amp;quot;REGISTRY-FQDN&amp;quot;]
        endpoint = [&amp;quot;https://REGISTRY-FQDN&amp;quot;]
    [plugins.&amp;quot;io.containerd.grpc.v1.cri&amp;quot;.registry.configs]
      [plugins.&amp;quot;io.containerd.grpc.v1.cri&amp;quot;.registry.configs.&amp;quot;REGISTRY-FQDN&amp;quot;.tls]
        insecure_skip_verify = true
EOF&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;sudo&lt;/span&gt; systemctl restart containerd
&lt;span class=&quot;token function&quot;&gt;sudo&lt;/span&gt; systemctl status containerd &lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;A nicer way is to add the configuration above in to your &lt;code class=&quot;language-text&quot;&gt;cluster.yaml&lt;/code&gt; and have it populate the &lt;code class=&quot;language-text&quot;&gt;/etc/containerd/config.toml&lt;/code&gt; file whenever you create another cluster with CAPV.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;New Workload Cluster&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Update your &lt;code class=&quot;language-text&quot;&gt;cluster.yaml&lt;/code&gt; to include a &lt;code class=&quot;language-text&quot;&gt;files:&lt;/code&gt; section for the &lt;code class=&quot;language-text&quot;&gt;KubeadmConfigTemplate&lt;/code&gt; and &lt;code class=&quot;language-text&quot;&gt;KubeadmControlPlane&lt;/code&gt; resource types. The &lt;code class=&quot;language-text&quot;&gt;files:&lt;/code&gt; section needs to be added in the below locations: &lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;KubeadmConfigTemplate&lt;/code&gt; (worker nodes): Add &lt;code class=&quot;language-text&quot;&gt;files:&lt;/code&gt; section to &lt;code class=&quot;language-text&quot;&gt;spec.template.spec&lt;/code&gt;&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;KubeadmControlPlane&lt;/code&gt; (control plane nodes): Add &lt;code class=&quot;language-text&quot;&gt;files:&lt;/code&gt; section to &lt;code class=&quot;language-text&quot;&gt;spec.kubeadmConfigSpec&lt;/code&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Replace &lt;code class=&quot;language-text&quot;&gt;REGISTRY-FQDN&lt;/code&gt; with the FQDN or IP address of your registry. Ensure that your endpoint has the correct protocol (http or https).&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;yaml&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-yaml line-numbers&quot;&gt;&lt;code class=&quot;language-yaml&quot;&gt;&lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; controlplane.cluster.x&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;k8s.io/v1alpha3
&lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; KubeadmControlPlane
&lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; cluster01
  &lt;span class=&quot;token key atrule&quot;&gt;namespace&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; default
&lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;kubeadmConfigSpec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;files&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;path&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /etc/containerd/config.toml
        &lt;span class=&quot;token key atrule&quot;&gt;content&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt;&lt;span class=&quot;token scalar string&quot;&gt;
          version = 2
          [plugins]
            [plugins.&amp;quot;io.containerd.grpc.v1.cri&amp;quot;]
              sandbox_image = &amp;quot;k8s.gcr.io/pause:3.2&amp;quot;
              [plugins.&amp;quot;io.containerd.grpc.v1.cri&amp;quot;.registry.mirrors]
                [plugins.&amp;quot;io.containerd.grpc.v1.cri&amp;quot;.registry.mirrors.&amp;quot;REGISTRY-FQDN&amp;quot;]
                  endpoint = [&amp;quot;https://REGISTRY-FQDN&amp;quot;]
              [plugins.&amp;quot;io.containerd.grpc.v1.cri&amp;quot;.registry.configs]
                [plugins.&amp;quot;io.containerd.grpc.v1.cri&amp;quot;.registry.configs.&amp;quot;REGISTRY-FQDN&amp;quot;.tls]
                  insecure_skip_verify = true&lt;/span&gt;&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;yaml&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-yaml line-numbers&quot;&gt;&lt;code class=&quot;language-yaml&quot;&gt;&lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; bootstrap.cluster.x&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;k8s.io/v1alpha3
&lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; KubeadmConfigTemplate
&lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; cluster01&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;md&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;0&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;namespace&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; default
&lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;template&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;files&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;path&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /etc/containerd/config.toml
          &lt;span class=&quot;token key atrule&quot;&gt;content&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt;&lt;span class=&quot;token scalar string&quot;&gt;
            version = 2
            [plugins]
              [plugins.&amp;quot;io.containerd.grpc.v1.cri&amp;quot;]
                sandbox_image = &amp;quot;k8s.gcr.io/pause:3.2&amp;quot;
                [plugins.&amp;quot;io.containerd.grpc.v1.cri&amp;quot;.registry.mirrors]
                  [plugins.&amp;quot;io.containerd.grpc.v1.cri&amp;quot;.registry.mirrors.&amp;quot;REGISTRY-FQDN&amp;quot;]
                    endpoint = [&amp;quot;https://REGISTRY-FQDN&amp;quot;]
                [plugins.&amp;quot;io.containerd.grpc.v1.cri&amp;quot;.registry.configs]
                  [plugins.&amp;quot;io.containerd.grpc.v1.cri&amp;quot;.registry.configs.&amp;quot;REGISTRY-FQDN&amp;quot;.tls]
                    insecure_skip_verify = true&lt;/span&gt;&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Deploy the new cluster from your Cluster API management cluster: &lt;code class=&quot;language-text&quot;&gt;kubectl apply -f cluster.yaml&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Once the cluster is up, you can validate that the file has the correct content by SSH’ing in to each of your clusters nodes and running:&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;&lt;span class=&quot;token function&quot;&gt;sudo&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;cat&lt;/span&gt; /etc/containerd/config.toml&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;strong&gt;Create Kubernetes Secret&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Within your new workload cluster, you can now &lt;code class=&quot;language-text&quot;&gt;docker login REGISTRY-FQDN&lt;/code&gt;, and utilise the stored credentials to create a Kubernetes Secret that can be used within deployments to pull from your private registry. &lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;&lt;span class=&quot;token comment&quot;&gt;#Retrieve new workload cluster kubeconfig&lt;/span&gt;
&lt;span class=&quot;token builtin class-name&quot;&gt;export&lt;/span&gt; &lt;span class=&quot;token assign-left variable&quot;&gt;WORKLOAD_CLUSTER_NAME&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;lt;CLUSTER-NAME&amp;gt;&amp;quot;&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;mkdir&lt;/span&gt; -p &lt;span class=&quot;token environment constant&quot;&gt;$HOME&lt;/span&gt;/&lt;span class=&quot;token variable&quot;&gt;$WORKLOAD_CLUSTER_NAME&lt;/span&gt;
kubectl get secret &lt;span class=&quot;token variable&quot;&gt;$WORKLOAD_CLUSTER_NAME&lt;/span&gt;-kubeconfig -o&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;jsonpath&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;#x27;{.data.value}&amp;#x27;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; base64 -d &lt;span class=&quot;token operator&quot;&gt;&lt;span class=&quot;token file-descriptor important&quot;&gt;2&lt;/span&gt;&amp;gt;&lt;/span&gt;/dev/null &lt;span class=&quot;token operator&quot;&gt;||&lt;/span&gt; base64 -D&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;&amp;gt;&lt;/span&gt; &lt;span class=&quot;token environment constant&quot;&gt;$HOME&lt;/span&gt;/&lt;span class=&quot;token variable&quot;&gt;$WORKLOAD_CLUSTER_NAME&lt;/span&gt;/kubeconfig
&lt;span class=&quot;token comment&quot;&gt;#Enter a valid username/password for the registry&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;docker&lt;/span&gt; login REGISTRY-FQDN
&lt;span class=&quot;token comment&quot;&gt;#Afer successful login, create a kubernetes secret based on the docker config file&lt;/span&gt;
kubectl create secret generic regcred --from-file&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;.dockerconfigjson&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token environment constant&quot;&gt;$HOME&lt;/span&gt;/.docker/config.json --type&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;kubernetes.io/dockerconfigjson --kubeconfig&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token environment constant&quot;&gt;$HOME&lt;/span&gt;/&lt;span class=&quot;token variable&quot;&gt;$WORKLOAD_CLUSTER_NAME&lt;/span&gt;/kubeconfig&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;strong&gt;Deploying from the Private Repo/Registry&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Create a deployment using the created secret. This step assumes you have a container image available to pull from your Privary Registry.&lt;/p&gt;&lt;p&gt;The image path could look something like this &lt;code class=&quot;language-text&quot;&gt;harbor01.domain.com/myrepo/my-node-app:latest&lt;/code&gt;.&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;yaml&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-yaml line-numbers&quot;&gt;&lt;code class=&quot;language-yaml&quot;&gt;&lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; apps/v1
&lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; Deployment
&lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;labels&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;app&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; node&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;app
  &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; node&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;app
&lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;replicas&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;1&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;selector&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;matchLabels&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;app&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; node&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;app
  &lt;span class=&quot;token key atrule&quot;&gt;template&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;labels&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;app&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; node&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;app
    &lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;containers&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;image&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; REGISTRY&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;FQDN/REPO/CONTAINER&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;TAG
        &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; node&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;app
      &lt;span class=&quot;token key atrule&quot;&gt;imagePullSecrets&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; regcred&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Validate your app has been deployed&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;kubectl get deployment node-app --kubeconfig&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token environment constant&quot;&gt;$HOME&lt;/span&gt;/&lt;span class=&quot;token variable&quot;&gt;$WORKLOAD_CLUSTER_NAME&lt;/span&gt;/kubeconfig
kubectl get pods -l &lt;span class=&quot;token assign-left variable&quot;&gt;app&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;node-app --kubeconfig&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token environment constant&quot;&gt;$HOME&lt;/span&gt;/&lt;span class=&quot;token variable&quot;&gt;$WORKLOAD_CLUSTER_NAME&lt;/span&gt;/kubeconfig&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;strong&gt;Snippet from &lt;code class=&quot;language-text&quot;&gt;cluster.yaml&lt;/code&gt; including &lt;code class=&quot;language-text&quot;&gt;files:&lt;/code&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;This is a snippet from the full &lt;code class=&quot;language-text&quot;&gt;cluster.yaml&lt;/code&gt; that Cluster API generates, but it shows a document that includes &lt;code class=&quot;language-text&quot;&gt;files:&lt;/code&gt;.&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;yaml&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-yaml line-numbers&quot;&gt;&lt;code class=&quot;language-yaml&quot;&gt;&lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; controlplane.cluster.x&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;k8s.io/v1alpha3
&lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; KubeadmControlPlane
&lt;span class=&quot;token key atrule&quot;&gt;metadata&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; wlc01
  &lt;span class=&quot;token key atrule&quot;&gt;namespace&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; default
&lt;span class=&quot;token key atrule&quot;&gt;spec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;infrastructureTemplate&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;apiVersion&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; infrastructure.cluster.x&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;k8s.io/v1alpha3
    &lt;span class=&quot;token key atrule&quot;&gt;kind&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; VSphereMachineTemplate
    &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; wlc01
  &lt;span class=&quot;token key atrule&quot;&gt;kubeadmConfigSpec&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;clusterConfiguration&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;apiServer&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;extraArgs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;cloud-provider&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; external
      &lt;span class=&quot;token key atrule&quot;&gt;controllerManager&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;extraArgs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;cloud-provider&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; external
    &lt;span class=&quot;token key atrule&quot;&gt;initConfiguration&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;nodeRegistration&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;criSocket&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /var/run/containerd/containerd.sock
        &lt;span class=&quot;token key atrule&quot;&gt;kubeletExtraArgs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;cloud-provider&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; external
        &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;{{ ds.meta_data.hostname }}&amp;#x27;&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;joinConfiguration&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token key atrule&quot;&gt;nodeRegistration&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
        &lt;span class=&quot;token key atrule&quot;&gt;criSocket&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /var/run/containerd/containerd.sock
        &lt;span class=&quot;token key atrule&quot;&gt;kubeletExtraArgs&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
          &lt;span class=&quot;token key atrule&quot;&gt;cloud-provider&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; external
        &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;{{ ds.meta_data.hostname }}&amp;#x27;&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;preKubeadmCommands&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; hostname &amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; ds.meta_data.hostname &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&amp;quot;
    &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; echo &amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;1         ipv6&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;localhost ipv6&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;loopback&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;/etc/hosts
    &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; echo &amp;quot;127.0.0.1   localhost&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;/etc/hosts
    &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; echo &amp;quot;127.0.0.1   &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; ds.meta_data.hostname &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;/etc/hosts
    &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; echo &amp;quot;&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; ds.meta_data.hostname &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&amp;quot; &lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;/etc/hostname
    &lt;span class=&quot;token key atrule&quot;&gt;files&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;path&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; /etc/containerd/config.toml
        &lt;span class=&quot;token key atrule&quot;&gt;content&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;|&lt;/span&gt;&lt;span class=&quot;token scalar string&quot;&gt;
          version = 2
          [plugins]
            [plugins.&amp;quot;io.containerd.grpc.v1.cri&amp;quot;]
              sandbox_image = &amp;quot;k8s.gcr.io/pause:3.2&amp;quot;
              [plugins.&amp;quot;io.containerd.grpc.v1.cri&amp;quot;.registry.mirrors]
                [plugins.&amp;quot;io.containerd.grpc.v1.cri&amp;quot;.registry.mirrors.&amp;quot;REGISTRY-FQDN&amp;quot;]
                  endpoint = [&amp;quot;https://REGISTRY-FQDN&amp;quot;]
              [plugins.&amp;quot;io.containerd.grpc.v1.cri&amp;quot;.registry.configs]
                [plugins.&amp;quot;io.containerd.grpc.v1.cri&amp;quot;.registry.configs.&amp;quot;REGISTRY-FQDN&amp;quot;.tls]
                  insecure_skip_verify = true&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;useExperimentalRetryJoin&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token boolean important&quot;&gt;true&lt;/span&gt;
    &lt;span class=&quot;token key atrule&quot;&gt;users&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
    &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;token key atrule&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; capv
      &lt;span class=&quot;token key atrule&quot;&gt;sshAuthorizedKeys&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;
      &lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt; ssh&lt;span class=&quot;token punctuation&quot;&gt;-&lt;/span&gt;rsa OMITTED
      &lt;span class=&quot;token key atrule&quot;&gt;sudo&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; ALL=(ALL) NOPASSWD&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt;ALL
  &lt;span class=&quot;token key atrule&quot;&gt;replicas&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;token number&quot;&gt;1&lt;/span&gt;
  &lt;span class=&quot;token key atrule&quot;&gt;version&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;:&lt;/span&gt; v1.18.2&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;strong&gt;Other Articles in this Series&lt;/strong&gt;\
&lt;a href=&quot;Cluster-API-Setup-Steps--vSphere-&quot;&gt;Cluster API Setup Steps (vSphere)&lt;/a&gt;\
&lt;a href=&quot;Cluster-API-Workload-Cluster--vSphere-&quot;&gt;Cluster API Workload Cluster (vSphere)&lt;/a&gt;&lt;/p&gt;</content:encoded><tags>kubernetes,development,vmware</tags><featuredImage>https://samperrin.com/static/a0511c8075ba8349a213f67f0f3e2347/hero_5.jpg</featuredImage></item><item><title><![CDATA[Deploying your first App into a Workload Cluster]]></title><description><![CDATA[Deploy your first App in to the workload cluster that was deployed with Cluster API]]></description><link>https://samperrin.com/posts/deploying-your-first-App-into-a-Workload-Cluster-workload-cluster-vsphere/</link><guid isPermaLink="false">https://samperrin.com/posts/deploying-your-first-App-into-a-Workload-Cluster-workload-cluster-vsphere/</guid><category><![CDATA[development]]></category><category><![CDATA[kubernetes]]></category><category><![CDATA[vmware]]></category><pubDate>Tue, 11 Aug 2020 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;strong&gt;Prerequisites&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Access to a working Workload Cluster (see &lt;a href=&quot;Cluster-API-Workload-Cluster--vSphere-&quot;&gt;Cluster API Workload Cluster (vSphere)&lt;/a&gt;) via &lt;code class=&quot;language-text&quot;&gt;kubectl&lt;/code&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Set your &lt;code class=&quot;language-text&quot;&gt;kubeconfig&lt;/code&gt; so you can access the workload cluster. &lt;/p&gt;&lt;p&gt;If you followed the steps in the linked article above, you should hopefully have the environment variable &lt;code class=&quot;language-text&quot;&gt;$WORKLOAD_CLUSTER_NAME&lt;/code&gt; already set, and its &lt;code class=&quot;language-text&quot;&gt;kubeconfig&lt;/code&gt; file is located in &lt;code class=&quot;language-text&quot;&gt;$HOME/$WORKLOAD_CLUSTER_NAME/kubeconfig&lt;/code&gt;. &lt;/p&gt;&lt;p&gt;This step assumes you followed &lt;a href=&quot;Cluster-API-Workload-Cluster--vSphere-&quot;&gt;Cluster API Workload Cluster (vSphere)&lt;/a&gt;.&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;&lt;span class=&quot;token comment&quot;&gt;#Replace the value to match the name of your workload cluster&lt;/span&gt;
&lt;span class=&quot;token builtin class-name&quot;&gt;export&lt;/span&gt; &lt;span class=&quot;token assign-left variable&quot;&gt;WORKLOAD_CLUSTER_NAME&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;wlc01&amp;quot;&lt;/span&gt;
&lt;span class=&quot;token builtin class-name&quot;&gt;export&lt;/span&gt; &lt;span class=&quot;token assign-left variable&quot;&gt;KUBECONFIG&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;&lt;span class=&quot;token environment constant&quot;&gt;$HOME&lt;/span&gt;/&lt;span class=&quot;token variable&quot;&gt;$WORKLOAD_CLUSTER_NAME&lt;/span&gt;/kubeconfig&amp;quot;&lt;/span&gt;&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Create a development namespace&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;kubectl create namespace development&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Create a simple deployment. The below will create a YAML file in the &lt;code class=&quot;language-text&quot;&gt;$HOME/Development&lt;/code&gt; directory. &lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;&lt;span class=&quot;token function&quot;&gt;mkdir&lt;/span&gt; -p &lt;span class=&quot;token environment constant&quot;&gt;$HOME&lt;/span&gt;/Development
&lt;span class=&quot;token function&quot;&gt;tee&lt;/span&gt; &lt;span class=&quot;token environment constant&quot;&gt;$HOME&lt;/span&gt;/Development/my-nginx-deployment.yaml &lt;span class=&quot;token operator&quot;&gt;&amp;gt;&lt;/span&gt;/dev/null &lt;span class=&quot;token operator&quot;&gt;&amp;lt;&amp;lt;&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;EOF
apiVersion: apps/v1
kind: Deployment
metadata:
  name: my-nginx-deployment
  labels:
    app: nginx
spec:
  replicas: 3
  selector:
    matchLabels:
      app: nginx 
  template:
    metadata:
      labels:
        app: nginx
    spec:
      containers:
      - name: nginx
        image: nginx:1.14.2
        ports:
        - containerPort: 80
EOF&lt;/span&gt;&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Apply the Deployment, this will deploy &lt;code class=&quot;language-text&quot;&gt;nginx&lt;/code&gt; with the deployment name &lt;code class=&quot;language-text&quot;&gt;my-nginx-deployment&lt;/code&gt;.&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;kubectl apply -f &lt;span class=&quot;token string&quot;&gt;&amp;quot;&lt;span class=&quot;token environment constant&quot;&gt;$HOME&lt;/span&gt;/Development/my-nginx-deployment.yaml&amp;quot;&lt;/span&gt; --namespace development&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Check to see if our Deployment has been created. You should hopefully see all Pods &lt;code class=&quot;language-text&quot;&gt;READY&lt;/code&gt; and &lt;code class=&quot;language-text&quot;&gt;Running&lt;/code&gt;&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;kubectl get deployment -n development
kubectl get pod -n development&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Alternative imperative commands to create the same deployment, with a slightly different name.&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;kubectl create deployment my-nginx-deployment2 --image&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;nginx:1.14.2 --namespace&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;development
kubectl &lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;strong&gt;Previous Article in this Series&lt;/strong&gt;: &lt;a href=&quot;Cluster-API-Setup-Steps--vSphere-&quot;&gt;Cluster API Setup Steps (vSphere)&lt;/a&gt;&lt;/p&gt;</content:encoded><tags>development,kubernetes,vmware</tags><featuredImage>https://samperrin.com/static/a0511c8075ba8349a213f67f0f3e2347/hero_5.jpg</featuredImage></item><item><title><![CDATA[Cluster API Workload Cluster (vSphere)]]></title><description><![CDATA[Deploy your first workload cluster with Cluster API]]></description><link>https://samperrin.com/posts/clusterapi-workload-cluster-vsphere/</link><guid isPermaLink="false">https://samperrin.com/posts/clusterapi-workload-cluster-vsphere/</guid><category><![CDATA[development]]></category><category><![CDATA[kubernetes]]></category><category><![CDATA[vmware]]></category><pubDate>Mon, 10 Aug 2020 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;strong&gt;Prerequisites&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;PhotonOS Kubernetes template within vSphere&lt;/li&gt;&lt;li&gt;HAProxy template within vSphere&lt;/li&gt;&lt;li&gt;Working Management Cluster (follow these steps &lt;a href=&quot;Cluster-API-Setup-Steps--vSphere-&quot;&gt;Cluster API Setup Steps (vSphere)&lt;/a&gt;)&lt;/li&gt;&lt;li&gt;Access to the Management Cluster with &lt;code class=&quot;language-text&quot;&gt;kubectl&lt;/code&gt; &lt;/li&gt;&lt;li&gt;Access to a machine with &lt;code class=&quot;language-text&quot;&gt;clusterctl&lt;/code&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Create clusterctl.yaml to store configuration values. Replace the values where required. Take particular note of values between &amp;lt; and &amp;gt;.&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;&lt;span class=&quot;token function&quot;&gt;mkdir&lt;/span&gt; -p &lt;span class=&quot;token environment constant&quot;&gt;$HOME&lt;/span&gt;/.cluster-api
&lt;span class=&quot;token function&quot;&gt;tee&lt;/span&gt; &lt;span class=&quot;token environment constant&quot;&gt;$HOME&lt;/span&gt;/.cluster-api/clusterctl.yaml &lt;span class=&quot;token operator&quot;&gt;&amp;gt;&lt;/span&gt;/dev/null &lt;span class=&quot;token operator&quot;&gt;&amp;lt;&amp;lt;&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;EOF
## -- Controller settings -- ##
VSPHERE_USERNAME: &amp;quot;administrator@vsphere.local&amp;quot;            # The username used to access the remote vSphere endpoint
VSPHERE_PASSWORD: &amp;quot;vmware1&amp;quot;                                # The password used to access the remote vSphere endpoint

## -- Required workload cluster default settings -- ##
VSPHERE_SERVER: &amp;quot;vcenter1.domain.com&amp;quot;                                 # The vCenter server IP or FQDN
VSPHERE_DATACENTER: &amp;quot;Datacenter&amp;quot;                                      # The vSphere datacenter to deploy the management cluster on
VSPHERE_DATASTORE: &amp;quot;Datastore&amp;quot;                                        # The vSphere datastore to deploy the management cluster on
VSPHERE_NETWORK: &amp;quot;VM Network&amp;quot;                                         # The VM network to deploy the management cluster on
VSPHERE_RESOURCE_POOL: &amp;quot;&amp;lt;ClusterName&amp;gt;/Resources/&amp;lt;ResourcePoolName&amp;gt;&amp;quot;   # The vSphere resource pool for your VMs
VSPHERE_FOLDER: &amp;quot;vm/&amp;lt;FolderName&amp;gt;/&amp;lt;ChildFolderName&amp;gt;&amp;quot;                   # The VM folder for your VMs. Set to &amp;quot;&amp;quot; to use the root vSphere folder
VSPHERE_TEMPLATE: &amp;quot;photon-3-kube-v1.18.2&amp;quot;                             # The VM template to use for your management cluster.
VSPHERE_HAPROXY_TEMPLATE: &amp;quot;capv-haproxy-v0.6.4&amp;quot;                       # The VM template to use for the HAProxy load balancer
VSPHERE_SSH_AUTHORIZED_KEY: &amp;quot;&amp;lt;ssh key&amp;gt;&amp;quot;                               # The public ssh authorized key on all machines in this cluster. Set to &amp;quot;&amp;quot; if you don&amp;#x27;t want to enable SSH, or are using another solution.
EOF&lt;/span&gt;&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Change the value of &lt;code class=&quot;language-text&quot;&gt;WORKLOAD_CLUSTER_NAME&lt;/code&gt; to be the name of your new workload cluster.&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;&lt;span class=&quot;token builtin class-name&quot;&gt;export&lt;/span&gt; &lt;span class=&quot;token assign-left variable&quot;&gt;WORKLOAD_CLUSTER_NAME&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;wlc01&amp;quot;&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;mkdir&lt;/span&gt; -p &lt;span class=&quot;token environment constant&quot;&gt;$HOME&lt;/span&gt;/&lt;span class=&quot;token variable&quot;&gt;$WORKLOAD_CLUSTER_NAME&lt;/span&gt;
clusterctl config cluster &lt;span class=&quot;token variable&quot;&gt;$WORKLOAD_CLUSTER_NAME&lt;/span&gt; --infrastructure vsphere --kubernetes-version v1.18.2 --control-plane-machine-count &lt;span class=&quot;token number&quot;&gt;1&lt;/span&gt; --worker-machine-count &lt;span class=&quot;token number&quot;&gt;3&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;&amp;gt;&lt;/span&gt; &lt;span class=&quot;token environment constant&quot;&gt;$HOME&lt;/span&gt;/&lt;span class=&quot;token variable&quot;&gt;$WORKLOAD_CLUSTER_NAME&lt;/span&gt;/cluster.yaml&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Review the cluster config file and make any required changes. Some suggestions to review are CPU, Memory, Storage and Pods CIDR range.&lt;/p&gt;&lt;p&gt;You can use &lt;code class=&quot;language-text&quot;&gt;sed&lt;/code&gt; to do a find and replace within the file, the below examples are for changing the Storage and Memory on all virtual machines as part of this deployment and the Pods CIDR.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Pod CIDR from &lt;code class=&quot;language-text&quot;&gt;192.168.0.0/16&lt;/code&gt; to &lt;code class=&quot;language-text&quot;&gt;192.168.200.0/24&lt;/code&gt;&lt;/li&gt;&lt;li&gt;Memory from &lt;code class=&quot;language-text&quot;&gt;8192&lt;/code&gt; to &lt;code class=&quot;language-text&quot;&gt;4096&lt;/code&gt;&lt;/li&gt;&lt;li&gt;Storage from &lt;code class=&quot;language-text&quot;&gt;25&lt;/code&gt; to &lt;code class=&quot;language-text&quot;&gt;20&lt;/code&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;&lt;span class=&quot;token function&quot;&gt;sed&lt;/span&gt; -i &lt;span class=&quot;token string&quot;&gt;&amp;quot;s/192.168.0.0\/16/192.168.200.0\/24/g&amp;quot;&lt;/span&gt; &lt;span class=&quot;token environment constant&quot;&gt;$HOME&lt;/span&gt;/&lt;span class=&quot;token variable&quot;&gt;$WORKLOAD_CLUSTER_NAME&lt;/span&gt;/cluster.yaml
&lt;span class=&quot;token function&quot;&gt;sed&lt;/span&gt; -i &lt;span class=&quot;token string&quot;&gt;&amp;quot;s/memoryMiB: 8192/memoryMiB: 4096/g&amp;quot;&lt;/span&gt; &lt;span class=&quot;token environment constant&quot;&gt;$HOME&lt;/span&gt;/&lt;span class=&quot;token variable&quot;&gt;$WORKLOAD_CLUSTER_NAME&lt;/span&gt;/cluster.yaml
&lt;span class=&quot;token function&quot;&gt;sed&lt;/span&gt; -i &lt;span class=&quot;token string&quot;&gt;&amp;quot;s/diskGiB: 25/diskGiB: 20/g&amp;quot;&lt;/span&gt; &lt;span class=&quot;token environment constant&quot;&gt;$HOME&lt;/span&gt;/&lt;span class=&quot;token variable&quot;&gt;$WORKLOAD_CLUSTER_NAME&lt;/span&gt;/cluster.yaml&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Deploy the cluster components. Monitor the deployment of virtual machines within vSphere.&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;kubectl apply -f &lt;span class=&quot;token environment constant&quot;&gt;$HOME&lt;/span&gt;/&lt;span class=&quot;token variable&quot;&gt;$WORKLOAD_CLUSTER_NAME&lt;/span&gt;/cluster.yaml&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Use &lt;code class=&quot;language-text&quot;&gt;kubectl&lt;/code&gt; to see cluster progress. The control planes won’t be Ready until we install a CNI in a later step.&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;kubectl get cluster --all-namespaces
kubectl get kubeadmcontrolplane --all-namespaces&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Retrieve the kubeconfig file for the workload cluster, and set it as KUBECONFIG environment variable.&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;kubectl get secret &lt;span class=&quot;token variable&quot;&gt;$WORKLOAD_CLUSTER_NAME&lt;/span&gt;-kubeconfig -o&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;jsonpath&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;#x27;{.data.value}&amp;#x27;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; base64 -d &lt;span class=&quot;token operator&quot;&gt;&lt;span class=&quot;token file-descriptor important&quot;&gt;2&lt;/span&gt;&amp;gt;&lt;/span&gt;/dev/null &lt;span class=&quot;token operator&quot;&gt;||&lt;/span&gt; base64 -D&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;&amp;gt;&lt;/span&gt; &lt;span class=&quot;token environment constant&quot;&gt;$HOME&lt;/span&gt;/&lt;span class=&quot;token variable&quot;&gt;$WORKLOAD_CLUSTER_NAME&lt;/span&gt;/kubeconfig
&lt;span class=&quot;token builtin class-name&quot;&gt;export&lt;/span&gt; &lt;span class=&quot;token assign-left variable&quot;&gt;KUBECONFIG&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;&lt;span class=&quot;token environment constant&quot;&gt;$HOME&lt;/span&gt;/&lt;span class=&quot;token variable&quot;&gt;$WORKLOAD_CLUSTER_NAME&lt;/span&gt;/kubeconfig&amp;quot;&lt;/span&gt;&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Deploy Calico CNI to &lt;code class=&quot;language-text&quot;&gt;$WORKLOAD_CLUSTER_NAME&lt;/code&gt;. (or any other CNI)&lt;/p&gt;&lt;p&gt;Because we have set KUBECONFIG in the above step our kubectl commands will run against the local-control-plane cluster. If you want to be certain, add &lt;code class=&quot;language-text&quot;&gt;--kubeconfig=&amp;quot;$HOME/$WORKLOAD_CLUSTER_NAME/kubeconfig&amp;quot;&lt;/code&gt; to the commands. &lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;kubectl apply -f https://docs.projectcalico.org/manifests/calico.yaml
&lt;span class=&quot;token comment&quot;&gt;#Example with kubeconfig specified&lt;/span&gt;
&lt;span class=&quot;token comment&quot;&gt;#kubectl apply -f https://docs.projectcalico.org/manifests/calico.yaml --kubeconfig=&amp;quot;$HOME/$WORKLOAD_CLUSTER_NAME/kubeconfig&amp;quot;&lt;/span&gt;&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Reset your KUBECONFIG back to the management cluster&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;text&quot;&gt;&lt;pre class=&quot;language-text&quot;&gt;&lt;code class=&quot;language-text&quot;&gt;unset KUBECONFIG
export KUBECONFIG=$HOME/local-control-plane/kubeconfig&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;You will now be able to continue performing cluster management operations. Some examples below.&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;&lt;span class=&quot;token comment&quot;&gt;#Retrieve related vSphere VMs&lt;/span&gt;
kubectl get vspheremachine
&lt;span class=&quot;token comment&quot;&gt;#Retrieve related machines&lt;/span&gt;
kubectl get machine
&lt;span class=&quot;token comment&quot;&gt;#Retrieve additional machine details&lt;/span&gt;
kubectl describe machine &lt;span class=&quot;token operator&quot;&gt;&amp;lt;&lt;/span&gt;machine-name&lt;span class=&quot;token operator&quot;&gt;&amp;gt;&lt;/span&gt;
&lt;span class=&quot;token comment&quot;&gt;#Retrieve additional cluster information&lt;/span&gt;
kubectl describe cluster local-control-plane
&lt;span class=&quot;token comment&quot;&gt;#Get machinedeployment (replicaset equivalent for machines)&lt;/span&gt;
kubectl get machinedeployment
&lt;span class=&quot;token comment&quot;&gt;#Scale worker nodes machinedeployment&lt;/span&gt;
kubectl scale machinedeployment &lt;span class=&quot;token variable&quot;&gt;$WORKLOAD_CLUSTER_NAME&lt;/span&gt;-md-0 --replicas&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;4&lt;/span&gt;
&lt;span class=&quot;token comment&quot;&gt;#Get various machine resources at once&lt;/span&gt;
kubectl get cluster,machine,machinesets,machinedeployment,vspheremachine
&lt;span class=&quot;token comment&quot;&gt;#Get most/all Cluster API resources&lt;/span&gt;
kubectl get clusters,machinedeployments,machinehealthchecks,machines,machinesets,providers,kubeadmcontrolplanes,machinepools,haproxyloadbalancers,vsphereclusters,vspheremachines,vspheremachinetemplates,vspherevms&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The next article will cover deploying an application to your new workload cluster. &lt;/p&gt;&lt;p&gt;&lt;strong&gt;Previous Article in this Series&lt;/strong&gt;: &lt;a href=&quot;Cluster-API-Setup-Steps--vSphere-&quot;&gt;Cluster API Setup Steps (vSphere)&lt;/a&gt;&lt;/p&gt;</content:encoded><tags>development,kubernetes,vmware</tags><featuredImage>https://samperrin.com/static/a0511c8075ba8349a213f67f0f3e2347/hero_5.jpg</featuredImage></item><item><title><![CDATA[Cluster API Setup Steps (vSphere)]]></title><description><![CDATA[Steps to get a cluster-api management cluster up and running]]></description><link>https://samperrin.com/posts/clusterapi-setup-steps-vsphere/</link><guid isPermaLink="false">https://samperrin.com/posts/clusterapi-setup-steps-vsphere/</guid><category><![CDATA[development]]></category><category><![CDATA[kubernetes]]></category><category><![CDATA[vmware]]></category><pubDate>Sun, 02 Aug 2020 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Download the PhotonOS Kubernetes and HAProxy images from here &lt;a href=&quot;http://storage.googleapis.com/capv-images&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;http://storage.googleapis.com/capv-images&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;HAProxy&lt;/strong&gt; version used in the steps below: &lt;a href=&quot;http://storage.googleapis.com/capv-images/extra/haproxy/release/v0.6.4/capv-haproxy-v0.6.4.ova&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;http://storage.googleapis.com/capv-images/extra/haproxy/release/v0.6.4/capv-haproxy-v0.6.4.ova&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;PhotonOS Kubernetes&lt;/strong&gt; version used in the steps below: &lt;a href=&quot;http://storage.googleapis.com/capv-images/release/v1.18.2/photon-3-kube-v1.18.2.ova&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;http://storage.googleapis.com/capv-images/release/v1.18.2/photon-3-kube-v1.18.2.ova&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Deploy both OVA files in to vSphere, take a snapshot of them, and then covert to templates.&lt;/p&gt;&lt;p&gt;&lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:242px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:41.735537190082646%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAICAYAAAD5nd/tAAAACXBIWXMAAA7DAAAOwwHHb6hkAAABGklEQVQoz32R227CMAyGef/n281udmC0aU52zi0d5Z/qIjYQw5JlKXE+fXZ25zPwPc/gXKAowjHDWQdmkqq1QcoZy7LgvDYD1/ooduvV8TghlIqDi+Cc4bSBGhSU2tJ5uj54BtuAl4bldMI4TQINuSLFhJwTiBm1Fuz3n4gxbr0X2/u8Ac7zLMBPTdAUUFKEMQaD1gLy3knPs1hZu0djcGl4Uw6t1c2wVDAxvPcCZg5IKcFaA08k56v1jeFfbRcLXr+0fMyh79FqhTUWXdeDyAugtoYQAqKsJv+OfK8shrniY/CIgRFDEMuSs4weA4F9ABGhjSOsHWCdwzRN/wNtLHh572CG4bpHJr/t0hn0nYLWGrkUBHYCHC/AH87ca7HnuWY/AAAAAElFTkSuQmCC&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;templates&quot; title=&quot;templates&quot; src=&quot;/static/854e2ea588f09e1ae24749541ef37d90/9ccb4/templates.png&quot; srcSet=&quot;/static/854e2ea588f09e1ae24749541ef37d90/9ccb4/templates.png 242w&quot; sizes=&quot;(max-width: 242px) 100vw, 242px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;&lt;/p&gt;&lt;p&gt;Create a new CentOS or Ubuntu VM to act as a temporary bootstrap server - steps below will be focused on CentOS. Alternatively, install the components below on your current device.&lt;/p&gt;&lt;p&gt;This machine will be used in later stages of your cluster lifecycle management, due to the presence of &lt;code class=&quot;language-text&quot;&gt;clusterctl&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Install Docker&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;&lt;span class=&quot;token function&quot;&gt;curl&lt;/span&gt; -fsSL https://get.docker.com -o get-docker.sh
&lt;span class=&quot;token function&quot;&gt;sudo&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;sh&lt;/span&gt; get-docker.sh
&lt;span class=&quot;token assign-left variable&quot;&gt;MAINUSER&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token variable&quot;&gt;&lt;span class=&quot;token variable&quot;&gt;$(&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;logname&lt;/span&gt;&lt;span class=&quot;token variable&quot;&gt;)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;sudo&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;usermod&lt;/span&gt; -aG &lt;span class=&quot;token function&quot;&gt;docker&lt;/span&gt; &lt;span class=&quot;token variable&quot;&gt;$MAINUSER&lt;/span&gt;&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Install KIND&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;&lt;span class=&quot;token assign-left variable&quot;&gt;KINDVERSION&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token variable&quot;&gt;&lt;span class=&quot;token variable&quot;&gt;$(&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;curl&lt;/span&gt; -s https://github.com/kubernetes-sigs/kind/releases/latest/download &lt;span class=&quot;token operator&quot;&gt;&lt;span class=&quot;token file-descriptor important&quot;&gt;2&lt;/span&gt;&amp;gt;&lt;/span&gt;&lt;span class=&quot;token file-descriptor important&quot;&gt;&amp;amp;1&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;grep&lt;/span&gt; -Po &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;0&lt;/span&gt;-9&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;+&lt;span class=&quot;token punctuation&quot;&gt;\&lt;/span&gt;.&lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;0&lt;/span&gt;-9&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;+&lt;span class=&quot;token punctuation&quot;&gt;\&lt;/span&gt;.&lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;0&lt;/span&gt;-9&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;+&lt;span class=&quot;token variable&quot;&gt;)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;curl&lt;/span&gt; -L &lt;span class=&quot;token string&quot;&gt;&amp;quot;https://github.com/kubernetes-sigs/kind/releases/download/v&lt;span class=&quot;token variable&quot;&gt;$KINDVERSION&lt;/span&gt;/kind-&lt;span class=&quot;token variable&quot;&gt;&lt;span class=&quot;token variable&quot;&gt;$(&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;uname&lt;/span&gt; -s &lt;span class=&quot;token operator&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;tr&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;[:upper:]&amp;#x27;&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;[:lower:]&amp;#x27;&lt;/span&gt;&lt;span class=&quot;token variable&quot;&gt;)&lt;/span&gt;&lt;/span&gt;-&lt;span class=&quot;token variable&quot;&gt;&lt;span class=&quot;token variable&quot;&gt;$(&lt;/span&gt;dpkg --print-architecture&lt;span class=&quot;token variable&quot;&gt;)&lt;/span&gt;&lt;/span&gt;&amp;quot;&lt;/span&gt; -o /usr/local/bin/kind
&lt;span class=&quot;token function&quot;&gt;chmod&lt;/span&gt; +x /usr/local/bin/kind&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Install kubectl &lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;&lt;span class=&quot;token function&quot;&gt;curl&lt;/span&gt; -LO &lt;span class=&quot;token string&quot;&gt;&amp;quot;https://storage.googleapis.com/kubernetes-release/release/&lt;span class=&quot;token variable&quot;&gt;&lt;span class=&quot;token variable&quot;&gt;$(&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;curl&lt;/span&gt; -s https://storage.googleapis.com/kubernetes-release/release/stable.txt&lt;span class=&quot;token variable&quot;&gt;)&lt;/span&gt;&lt;/span&gt;/bin/linux/amd64/kubectl&amp;quot;&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;chmod&lt;/span&gt; +x ./kubectl
&lt;span class=&quot;token function&quot;&gt;sudo&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;mv&lt;/span&gt; ./kubectl /usr/local/bin/kubectl&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Install clusterctl&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;&lt;span class=&quot;token assign-left variable&quot;&gt;CLUSTERCTLVERSION&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token variable&quot;&gt;&lt;span class=&quot;token variable&quot;&gt;$(&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;curl&lt;/span&gt; -s https://github.com/kubernetes-sigs/cluster-api/releases/latest/download &lt;span class=&quot;token operator&quot;&gt;&lt;span class=&quot;token file-descriptor important&quot;&gt;2&lt;/span&gt;&amp;gt;&lt;/span&gt;&lt;span class=&quot;token file-descriptor important&quot;&gt;&amp;amp;1&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;grep&lt;/span&gt; -Po &lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;0&lt;/span&gt;-9&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;+&lt;span class=&quot;token punctuation&quot;&gt;\&lt;/span&gt;.&lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;0&lt;/span&gt;-9&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;+&lt;span class=&quot;token punctuation&quot;&gt;\&lt;/span&gt;.&lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;0&lt;/span&gt;-9&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;+&lt;span class=&quot;token variable&quot;&gt;)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;curl&lt;/span&gt; -L &lt;span class=&quot;token string&quot;&gt;&amp;quot;https://github.com/kubernetes-sigs/cluster-api/releases/download/v&lt;span class=&quot;token variable&quot;&gt;$CLUSTERCTLVERSION&lt;/span&gt;/clusterctl-&lt;span class=&quot;token variable&quot;&gt;&lt;span class=&quot;token variable&quot;&gt;$(&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;uname&lt;/span&gt; -s &lt;span class=&quot;token operator&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;tr&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;[:upper:]&amp;#x27;&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;#x27;[:lower:]&amp;#x27;&lt;/span&gt;&lt;span class=&quot;token variable&quot;&gt;)&lt;/span&gt;&lt;/span&gt;-&lt;span class=&quot;token variable&quot;&gt;&lt;span class=&quot;token variable&quot;&gt;$(&lt;/span&gt;dpkg --print-architecture&lt;span class=&quot;token variable&quot;&gt;)&lt;/span&gt;&lt;/span&gt;&amp;quot;&lt;/span&gt; -o /usr/local/bin/clusterctl
&lt;span class=&quot;token function&quot;&gt;chmod&lt;/span&gt; +x /usr/local/bin/clusterctl&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Create KIND cluster&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;kind create cluster&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Create clusterctl.yaml to store configuration values. Replace the values where required. Take particular note of values between &amp;lt; and &amp;gt;.&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;&lt;span class=&quot;token function&quot;&gt;mkdir&lt;/span&gt; -p ~/.cluster-api
&lt;span class=&quot;token function&quot;&gt;tee&lt;/span&gt; ~/.cluster-api/clusterctl.yaml &lt;span class=&quot;token operator&quot;&gt;&amp;gt;&lt;/span&gt;/dev/null &lt;span class=&quot;token operator&quot;&gt;&amp;lt;&amp;lt;&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;EOF
## -- Controller settings -- ##
VSPHERE_USERNAME: &amp;quot;administrator@vsphere.local&amp;quot;            # The username used to access the remote vSphere endpoint
VSPHERE_PASSWORD: &amp;quot;vmware1&amp;quot;                                # The password used to access the remote vSphere endpoint

## -- Required workload cluster default settings -- ##
VSPHERE_SERVER: &amp;quot;vcenter1.domain.com&amp;quot;                                 # The vCenter server IP or FQDN
VSPHERE_DATACENTER: &amp;quot;Datacenter&amp;quot;                                      # The vSphere datacenter to deploy the management cluster on
VSPHERE_DATASTORE: &amp;quot;Datastore&amp;quot;                                        # The vSphere datastore to deploy the management cluster on
VSPHERE_NETWORK: &amp;quot;VM Network&amp;quot;                                         # The VM network to deploy the management cluster on
VSPHERE_RESOURCE_POOL: &amp;quot;&amp;lt;ClusterName&amp;gt;/Resources/&amp;lt;ResourcePoolName&amp;gt;&amp;quot;   # The vSphere resource pool for your VMs
VSPHERE_FOLDER: &amp;quot;vm/&amp;lt;FolderName&amp;gt;/&amp;lt;ChildFolderName&amp;gt;&amp;quot;                   # The VM folder for your VMs. Set to &amp;quot;&amp;quot; to use the root vSphere folder
VSPHERE_TEMPLATE: &amp;quot;photon-3-kube-v1.18.2&amp;quot;                             # The VM template to use for your management cluster.
VSPHERE_HAPROXY_TEMPLATE: &amp;quot;capv-haproxy-v0.6.4&amp;quot;                       # The VM template to use for the HAProxy load balancer
VSPHERE_SSH_AUTHORIZED_KEY: &amp;quot;&amp;lt;ssh key&amp;gt;&amp;quot;                               # The public ssh authorized key on all machines in this cluster. Set to &amp;quot;&amp;quot; if you don&amp;#x27;t want to enable SSH, or are using another solution.
EOF&lt;/span&gt;&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Initialise and Create the Bootstrap Management Cluster. Change the number of control-plane and worker nodes, kubernetes version etc as appropriate.&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;clusterctl init --infrastructure vsphere
&lt;span class=&quot;token comment&quot;&gt;# if this fails use clusterctl init --infrastructure=vsphere:v0.6.6&lt;/span&gt;
&lt;span class=&quot;token function&quot;&gt;mkdir&lt;/span&gt; -p ~/local-control-plane
clusterctl config cluster local-control-plane --infrastructure vsphere --kubernetes-version v1.18.2 --control-plane-machine-count &lt;span class=&quot;token number&quot;&gt;1&lt;/span&gt; --worker-machine-count &lt;span class=&quot;token number&quot;&gt;1&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;&amp;gt;&lt;/span&gt; ~/local-control-plane/cluster.yaml&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Review the cluster config file and make any required changes. Some suggestions to review are CPU, Memory, Storage and Pods CIDR range.&lt;/p&gt;&lt;p&gt;You can use &lt;code class=&quot;language-text&quot;&gt;sed&lt;/code&gt; to do a find and replace within the file, the below examples are for changing the Storage and Memory on all virtual machines as part of this deployment and the Pods CIDR.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Pod CIDR from &lt;code class=&quot;language-text&quot;&gt;192.168.0.0/16&lt;/code&gt; to &lt;code class=&quot;language-text&quot;&gt;192.168.100.0/24&lt;/code&gt;&lt;/li&gt;&lt;li&gt;Memory from &lt;code class=&quot;language-text&quot;&gt;8192&lt;/code&gt; to &lt;code class=&quot;language-text&quot;&gt;4096&lt;/code&gt;&lt;/li&gt;&lt;li&gt;Storage from &lt;code class=&quot;language-text&quot;&gt;25&lt;/code&gt; to &lt;code class=&quot;language-text&quot;&gt;20&lt;/code&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;&lt;span class=&quot;token function&quot;&gt;sed&lt;/span&gt; -i &lt;span class=&quot;token string&quot;&gt;&amp;quot;s/192.168.0.0\/16/192.168.100.0\/24/g&amp;quot;&lt;/span&gt; ~/local-control-plane/cluster.yaml
&lt;span class=&quot;token function&quot;&gt;sed&lt;/span&gt; -i &lt;span class=&quot;token string&quot;&gt;&amp;quot;s/memoryMiB: 8192/memoryMiB: 4096/g&amp;quot;&lt;/span&gt; ~/local-control-plane/cluster.yaml
&lt;span class=&quot;token function&quot;&gt;sed&lt;/span&gt; -i &lt;span class=&quot;token string&quot;&gt;&amp;quot;s/diskGiB: 25/diskGiB: 20/g&amp;quot;&lt;/span&gt; ~/local-control-plane/cluster.yaml&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Deploy the cluster components. Monitor the deployment of virtual machines within vSphere.&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;kubectl apply -f ~/local-control-plane/cluster.yaml&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Use &lt;code class=&quot;language-text&quot;&gt;kubectl&lt;/code&gt; to see cluster progress. The control planes won’t be Ready until we install a CNI in a later step.&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;kubectl get cluster --all-namespaces
kubectl get kubeadmcontrolplane --all-namespaces&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Retrieve the kubeconfig file for the local-control-plane cluster, and set it as KUBECONFIG environment variable.&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;kubectl get secret local-control-plane-kubeconfig -o&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;jsonpath&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;#x27;{.data.value}&amp;#x27;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;|&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; base64 -d &lt;span class=&quot;token operator&quot;&gt;&lt;span class=&quot;token file-descriptor important&quot;&gt;2&lt;/span&gt;&amp;gt;&lt;/span&gt;/dev/null &lt;span class=&quot;token operator&quot;&gt;||&lt;/span&gt; base64 -D&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;&amp;gt;&lt;/span&gt; ~/local-control-plane/kubeconfig
&lt;span class=&quot;token builtin class-name&quot;&gt;export&lt;/span&gt; &lt;span class=&quot;token assign-left variable&quot;&gt;KUBECONFIG&lt;/span&gt;&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;&lt;span class=&quot;token environment constant&quot;&gt;$HOME&lt;/span&gt;/local-control-plane/kubeconfig&amp;quot;&lt;/span&gt;&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Deploy Calico CNI to local-control-plane.&lt;/p&gt;&lt;p&gt;Because we have set KUBECONFIG in the above step our kubectl commands will run against the local-control-plane cluster. If you want to be certain, add &lt;code class=&quot;language-text&quot;&gt;--kubeconfig=&amp;quot;$HOME/local-control-plane/kubeconfig&amp;quot;&lt;/code&gt; to the commands. &lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;kubectl apply -f https://docs.projectcalico.org/manifests/calico.yaml
&lt;span class=&quot;token comment&quot;&gt;#Example with kubeconfig specified&lt;/span&gt;
&lt;span class=&quot;token comment&quot;&gt;#kubectl apply -f https://docs.projectcalico.org/manifests/calico.yaml --kubeconfig=&amp;quot;$HOME/local-control-plane/kubeconfig&amp;quot;&lt;/span&gt;&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Now we will initialise the local-control-plane cluster as our cluster-api management cluster.&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;clusterctl init --infrastructure vsphere&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Revert back to the kubeconfig for the bootstrap cluster, migrate management components from it to the local-control-plane cluster, and finally delete.&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;&lt;span class=&quot;token builtin class-name&quot;&gt;unset&lt;/span&gt; KUBECONFIG
clusterctl move --to-kubeconfig&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;&lt;span class=&quot;token environment constant&quot;&gt;$HOME&lt;/span&gt;/local-control-plane/kubeconfig&amp;quot;&lt;/span&gt;
kind delete cluster --name bootstrap&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Set the local-control-plane kubeconfig as our default &lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;&lt;span class=&quot;token function&quot;&gt;cp&lt;/span&gt; ~/local-control-plane/kubeconfig ~/.kube/config&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;You will now be able to perform cluster management operations. Some examples below.&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;shell&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-shell line-numbers&quot;&gt;&lt;code class=&quot;language-shell&quot;&gt;&lt;span class=&quot;token comment&quot;&gt;#Retrieve related vSphere VMs&lt;/span&gt;
kubectl get vspheremachine
&lt;span class=&quot;token comment&quot;&gt;#Retrieve related machines&lt;/span&gt;
kubectl get machine
&lt;span class=&quot;token comment&quot;&gt;#Retrieve additional machine details&lt;/span&gt;
kubectl describe machine &lt;span class=&quot;token operator&quot;&gt;&amp;lt;&lt;/span&gt;machine-name&lt;span class=&quot;token operator&quot;&gt;&amp;gt;&lt;/span&gt;
&lt;span class=&quot;token comment&quot;&gt;#Retrieve additional cluster information&lt;/span&gt;
kubectl describe cluster local-control-plane
&lt;span class=&quot;token comment&quot;&gt;#Get machinedeployment (replicaset equivalent for machines)&lt;/span&gt;
kubectl get machinedeployment
&lt;span class=&quot;token comment&quot;&gt;#Scale worker nodes machinedeployment&lt;/span&gt;
kubectl scale machinedeployment local-control-plane-md-0 --replicas&lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;3&lt;/span&gt;
&lt;span class=&quot;token comment&quot;&gt;#Get various machine resources at once&lt;/span&gt;
kubectl get cluster,machine,machinesets,machinedeployment,vspheremachine
&lt;span class=&quot;token comment&quot;&gt;#Get most/all Cluster API resources&lt;/span&gt;
kubectl get clusters,machinedeployments,machinehealthchecks,machines,machinesets,providers,kubeadmcontrolplanes,machinepools,haproxyloadbalancers,vsphereclusters,vspheremachines,vspheremachinetemplates,vspherevms&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The next article will cover deploying a workload cluster that can be consumed by your development teams. &lt;/p&gt;&lt;p&gt;&lt;strong&gt;Next Article in this Series&lt;/strong&gt;: &lt;a href=&quot;Cluster-API-Workload-Cluster--vSphere-&quot;&gt;Cluster API Workload Cluster (vSphere)&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Reference&lt;/strong&gt;: &lt;a href=&quot;https://cluster-api.sigs.k8s.io/introduction.html&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;The Cluster API project&lt;/a&gt;&lt;/p&gt;</content:encoded><tags>development,kubernetes,vmware</tags><featuredImage>https://samperrin.com/static/a0511c8075ba8349a213f67f0f3e2347/hero_5.jpg</featuredImage></item><item><title><![CDATA[vRO Email Templates with Dynamic Data]]></title><description><![CDATA[Email templates with variable placeholders, that allow easy replacement with Dynamic data]]></description><link>https://samperrin.com/posts/vro-email-templates-with-dynamic-data/</link><guid isPermaLink="false">https://samperrin.com/posts/vro-email-templates-with-dynamic-data/</guid><category><![CDATA[automation]]></category><category><![CDATA[development]]></category><category><![CDATA[vmware]]></category><category><![CDATA[vra]]></category><category><![CDATA[vro]]></category><pubDate>Wed, 03 Jun 2020 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;There are quite often occasions when you need to utilise vRO for sending out your email, there are a couple of ways of doing this, such as creating the HTML yourself with JavaScript code - or you can utilise Resources within vRO and store a HTML file.&lt;/p&gt;&lt;p&gt;This is the method we are going to walk through today. We are obtaining information from two places, the &lt;code class=&quot;language-text&quot;&gt;VC:VirtualMachine&lt;/code&gt; object, and also from its related &lt;code class=&quot;language-text&quot;&gt;vCAC:VirtualMachine&lt;/code&gt; - as the VMs in question have been deployed from vRA. &lt;/p&gt;&lt;p&gt;For the sake of this article, we are only retrieving simple information, but you can get it from anywhere - a payload directly from a vRA EBS event, an external system, etc - the method for replacing data remains the same. &lt;/p&gt;&lt;h1 id=&quot;create-the-html-template&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#create-the-html-template&quot; aria-label=&quot;create the html template permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Create the HTML template&lt;/h1&gt;&lt;p&gt;This is going to be a relatively simple HTML template, in this scenario we need to email a user with specific information from their VM. &lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;html&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-html line-numbers&quot;&gt;&lt;code class=&quot;language-html&quot;&gt;&lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;lt;&lt;/span&gt;html&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;lt;&lt;/span&gt;body&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;
  &lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;lt;&lt;/span&gt;p&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;================&lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;lt;/&lt;/span&gt;p&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;
  &lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;lt;&lt;/span&gt;p&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;Please find your VM details below;&lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;lt;/&lt;/span&gt;p&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;
 
  &lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;lt;&lt;/span&gt;ul&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;
    &lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;lt;&lt;/span&gt;li&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;VM Name = {{vmName}}&lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;lt;/&lt;/span&gt;li&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;
    &lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;lt;&lt;/span&gt;li&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;Expiry Date = {{expiryDate}}&lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;lt;/&lt;/span&gt;li&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;
    &lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;lt;&lt;/span&gt;li&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;IP Address = {{ipAddress}}&lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;lt;/&lt;/span&gt;li&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;
    &lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;lt;&lt;/span&gt;li&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;Memory = {{memory}}&lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;lt;/&lt;/span&gt;li&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;
    &lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;lt;&lt;/span&gt;li&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;CPU = {{cpu}}&lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;lt;/&lt;/span&gt;li&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;
    &lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;lt;&lt;/span&gt;li&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;Guest OS = {{guestOs}}&lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;lt;/&lt;/span&gt;li&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;
  &lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;lt;/&lt;/span&gt;ul&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;

  &lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;lt;&lt;/span&gt;p&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;================&lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;lt;/&lt;/span&gt;p&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;lt;/&lt;/span&gt;body&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;

&lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token tag&quot;&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;lt;/&lt;/span&gt;html&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Once your template has been created, save it as &lt;code class=&quot;language-text&quot;&gt;VM-Details.html&lt;/code&gt; upload it to the Resources section within vRO, under a folder called &lt;code class=&quot;language-text&quot;&gt;Email-Templates&lt;/code&gt;.&lt;/p&gt;&lt;p&gt;&lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:274px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:67.15328467153286%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAANCAIAAAAmMtkJAAAACXBIWXMAAA7DAAAOwwHHb6hkAAACDUlEQVQoz42Qz24SURTG78KlvIR9ARfdISbqI5i48Q1cGWP9xzBMCI0aNZpoilYsYKyNQgppS4ltpBS1NDWGKkxLZVpmgJl7gTJ3GJlSOsNcw5+Nqdr+8uWeuznf+c4B67lCplh3J/dWcyib4yYTbEngxXpzvagq8q5Qhp++stu8iL/7qgkGVWoZTlz5UahWEEIIpHN8XlKCbLvW1GXl10ZJ3m+12qapdAghJla1tcyOqu0bwpqWjWEsx1Kb3mimVkWSBMG3PCR4I/3Bf+PWHdpBMTRFUZSLYdwuxul0UnY746QdFHWbomnXqCRJXUvT0HuAdGGX8Mng3Sunh4fP2s50sXWLdfC1DV6r9cL5czzPE0I6nW4qQgjgIDYM0kDZlhBFEIkS1LS9rj05GpCHinGg14rp6maY47ZZli2VoWma7Xb74BCm+Ycn4KBCCGnVt3RpESsNSSxLEOm6QY4z+acoE0JWE5G3z656X/kCAb8g8Kra7B3GPKpZUgjpXLx0GZywWE5ahoZOYYz7nX06/9YgdomNZxYeLC/FVz5/qUARiSV+h1Mbyv/nA/dUwu6dc7wMPgpMvY+z99/E3IGoc3zaPhYcDcw/fBd3TERp3/xfNBEFlH9xxBO+NhZxvf4YSm49CS09Di2/mE15ZlNPp5P3Jheue8IjzyOHdXN8BkBZ62Xrb3msI/cXwXL9N2IQf6ZvYNPOAAAAAElFTkSuQmCC&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;vro resources&quot; title=&quot;vro resources&quot; src=&quot;/static/c58f3c37c85a40187f2f902e8c9c51a1/64b85/vro-resources.png&quot; srcSet=&quot;/static/c58f3c37c85a40187f2f902e8c9c51a1/64b85/vro-resources.png 274w&quot; sizes=&quot;(max-width: 274px) 100vw, 274px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;&lt;/p&gt;&lt;h1 id=&quot;create-the-workflow&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#create-the-workflow&quot; aria-label=&quot;create the workflow permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Create the Workflow&lt;/h1&gt;&lt;p&gt;Next, create your workflow - you will need two items in it. A script element, which we will add the below code in to, and we will make use of the &lt;code class=&quot;language-text&quot;&gt;Send notification&lt;/code&gt; workflow, which is found out of the box, under Library &amp;gt; Mail. &lt;/p&gt;&lt;p&gt;&lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:518px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:25.28957528957529%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAFCAIAAADKYVtkAAAACXBIWXMAAA7DAAAOwwHHb6hkAAAAsklEQVQY06WP0QqCUBBE/en+I+grfO+liCD7g7IgoiDELEkj762bt92ZUCPouX3anRnYMwH/mIDk9DhfliuSAEhW1uXlrTnbRFVjdnhtCyWpbSBN0ziOAQReXv31YJKNqHw48Z55cUuyC8nnE1IjuUpvfB9uPEl7VxFGURSGoYg0n403TlxHAuB0NtnJGFt3Sl48Fvtql1Qq2inOOWvtB7slxLcJQBGofnZoY6l2nX46vwGdlyBUJrG7XgAAAABJRU5ErkJggg==&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;vro workflow&quot; title=&quot;vro workflow&quot; src=&quot;/static/aaed03cceaa65f874fbcd9dc199f914e/2f227/vro-workflow.png&quot; srcSet=&quot;/static/aaed03cceaa65f874fbcd9dc199f914e/2f227/vro-workflow.png 518w&quot; sizes=&quot;(max-width: 518px) 100vw, 518px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;&lt;/p&gt;&lt;p&gt;Create one input in to the script element, name &lt;code class=&quot;language-text&quot;&gt;vm&lt;/code&gt; of type &lt;code class=&quot;language-text&quot;&gt;VC:VirtualMachine&lt;/code&gt; and one output called &lt;code class=&quot;language-text&quot;&gt;emailContent&lt;/code&gt; of type &lt;code class=&quot;language-text&quot;&gt;string&lt;/code&gt;. Copy in the below code. &lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;javascript&quot;&gt;&lt;pre style=&quot;counter-reset:linenumber 0&quot; class=&quot;language-javascript line-numbers&quot;&gt;&lt;code class=&quot;language-javascript&quot;&gt;&lt;span class=&quot;token comment&quot;&gt;/*
  - Input: vm [VC:VirtualMachine]
  - Output: emailContent [string]
*/&lt;/span&gt;

&lt;span class=&quot;token keyword&quot;&gt;var&lt;/span&gt; vmName &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; vm&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;name&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
&lt;span class=&quot;token keyword&quot;&gt;var&lt;/span&gt; ipAddress &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; vm&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;ipAddress&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
&lt;span class=&quot;token keyword&quot;&gt;var&lt;/span&gt; memory &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; vm&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;memory&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
&lt;span class=&quot;token keyword&quot;&gt;var&lt;/span&gt; cpu &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; vm&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;cpu&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
&lt;span class=&quot;token keyword&quot;&gt;var&lt;/span&gt; guestOs &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; vm&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;guestOS&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;

&lt;span class=&quot;token keyword&quot;&gt;var&lt;/span&gt; vcacVm &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; Server&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;findAllForType&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;vCAC:VirtualMachine&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;ExternalReferenceId eq &amp;#x27;&amp;quot;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;+&lt;/span&gt; vm&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;id &lt;span class=&quot;token operator&quot;&gt;+&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;&amp;#x27;&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;token number&quot;&gt;0&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;]&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
&lt;span class=&quot;token keyword&quot;&gt;var&lt;/span&gt; expiryDate &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; vcacVm&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;expires&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
&lt;span class=&quot;token keyword&quot;&gt;if&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;expiryDate&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
	expiryDate &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; expiryDate&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;toDate&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;

&lt;span class=&quot;token keyword&quot;&gt;var&lt;/span&gt; htmlTemplate &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;fetchEmailTemplate&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;VM-Details.html&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
		
&lt;span class=&quot;token keyword&quot;&gt;var&lt;/span&gt; fieldKeyValues &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;token keyword&quot;&gt;new&lt;/span&gt; &lt;span class=&quot;token class-name&quot;&gt;Properties&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
fieldKeyValues&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;put&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;{{vmName}}&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;vmName&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
fieldKeyValues&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;put&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;{{ipAddress}}&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;ipAddress&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
fieldKeyValues&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;put&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;{{guestOs}}&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;guestOs&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
fieldKeyValues&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;put&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;{{cpu}}&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;cpu&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
fieldKeyValues&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;put&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;{{memory}}&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;memory&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
fieldKeyValues&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;put&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;{{expiryDate}}&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;expiryDate&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;

&lt;span class=&quot;token keyword&quot;&gt;for&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;each&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token parameter&quot;&gt;field &lt;span class=&quot;token keyword&quot;&gt;in&lt;/span&gt; fieldKeyValues&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;keys&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
	htmlTemplate &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;updateContent&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;field&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;fieldKeyValues&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;get&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;field&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;htmlTemplate&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;

System&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;debug&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token string&quot;&gt;&amp;quot;==== Email Content ==== \n&amp;quot;&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;+&lt;/span&gt; htmlTemplate&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
emailContent &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; htmlTemplate&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;

&lt;span class=&quot;token keyword&quot;&gt;function&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;fetchEmailTemplate&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token parameter&quot;&gt;elementName&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt; 
	&lt;span class=&quot;token keyword&quot;&gt;var&lt;/span&gt; categoryPath &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;token string&quot;&gt;&amp;quot;Email-Templates&amp;quot;&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
	&lt;span class=&quot;token keyword&quot;&gt;var&lt;/span&gt; category &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; Server&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;getResourceElementCategoryWithPath&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;categoryPath&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
	&lt;span class=&quot;token keyword&quot;&gt;for&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;each&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token parameter&quot;&gt;&lt;span class=&quot;token keyword&quot;&gt;var&lt;/span&gt; resourceElement &lt;span class=&quot;token keyword&quot;&gt;in&lt;/span&gt; category&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;resourceElements&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
		&lt;span class=&quot;token keyword&quot;&gt;if&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;resourceElement&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;name&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;toLowerCase&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token operator&quot;&gt;===&lt;/span&gt; elementName&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;toLowerCase&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
			&lt;span class=&quot;token keyword&quot;&gt;var&lt;/span&gt; mime &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; resourceElement&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;getContentAsMimeAttachment&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;
			&lt;span class=&quot;token keyword&quot;&gt;return&lt;/span&gt; mime&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;content&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
		&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
	&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;

&lt;span class=&quot;token keyword&quot;&gt;function&lt;/span&gt; &lt;span class=&quot;token function&quot;&gt;updateContent&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;token parameter&quot;&gt;key&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;value&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;content&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;token punctuation&quot;&gt;{&lt;/span&gt;
	content &lt;span class=&quot;token operator&quot;&gt;=&lt;/span&gt; content&lt;span class=&quot;token punctuation&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;token function&quot;&gt;replace&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;(&lt;/span&gt;key&lt;span class=&quot;token punctuation&quot;&gt;,&lt;/span&gt;value&lt;span class=&quot;token punctuation&quot;&gt;)&lt;/span&gt;&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
	&lt;span class=&quot;token keyword&quot;&gt;return&lt;/span&gt; content&lt;span class=&quot;token punctuation&quot;&gt;;&lt;/span&gt;
&lt;span class=&quot;token punctuation&quot;&gt;}&lt;/span&gt;&lt;/code&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;line-numbers-rows&quot; style=&quot;white-space:normal;width:auto;left:0&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h1 id=&quot;what-does-the-code-do&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#what-does-the-code-do&quot; aria-label=&quot;what does the code do permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;What does the code do?&lt;/h1&gt;&lt;p&gt;In lines 6 to 16 we are retrieving all of the data we need for the email. &lt;/p&gt;&lt;p&gt;Line 18 we retrieve our email template from our resource element, this uses a function within the script (lines 35 to 44). &lt;/p&gt;&lt;p&gt;In lines 20 to 26 we are putting these bits of information in to a Properties object, for the key we are specifying the variable that needs to be replaced within the HTML - for example &lt;code class=&quot;language-text&quot;&gt;{{cpu}}&lt;/code&gt; is the key name, which relates to line 11 in the HTML template. &lt;/p&gt;&lt;p&gt;Finally in lines 28 to 30, we iterate over each key within the Properties element, find a match within the HTML content and replace it with the relevant value (this uses the function found on lines 46 to 49).&lt;/p&gt;&lt;p&gt;Your email should look something like the below&lt;/p&gt;&lt;p&gt;&lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:401px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:58.104738154613464%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAMCAYAAABiDJ37AAAACXBIWXMAAA7DAAAOwwHHb6hkAAABJElEQVQoz5VT14rEMAz0/39fEtJ7fwgE0puOESh4w97enmGQo8jSaCyruq6pbVtqmoZtVVU0DANhXdf1AvF9Wmrfd9q2jWAF53neAXqCv5JxQsuyKIoi8n2f8jynJEnI8zxyHIdc12WEYUjHcbxl/YQCG2x0dk98w0yKKeg1zzOzACtY6CgsYfEfwWAp0CUSH7c8jiMfsG2b20aCsiwpTVOK45glgB/f2ANZlrEUkAqSwYdYdMMMp2niRIZhcCBuOwgCDu77niuDwVMG4Om7E5qmyUlQHRatowgm4D/rRcOiKPimoV3XdazPsiy0ritDxgs+AOdkxO5bFg1FHww4NBSW8GEPHcFe9JL/0oFMgtJvCtVgvx2TdwOv9KcHfHp6v0Fn+AMEMZymrcWrDAAAAABJRU5ErkJggg==&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;email outcome&quot; title=&quot;email outcome&quot; src=&quot;/static/a9521c208e38da9a9161601d5c12a3c6/25946/email-outcome.png&quot; srcSet=&quot;/static/a9521c208e38da9a9161601d5c12a3c6/25946/email-outcome.png 401w&quot; sizes=&quot;(max-width: 401px) 100vw, 401px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;&lt;/p&gt;&lt;h1 id=&quot;how-can-i-utilise-this&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#how-can-i-utilise-this&quot; aria-label=&quot;how can i utilise this permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;How can I utilise this?&lt;/h1&gt;&lt;p&gt;Once you have all of the data you need, modify the HTML template to have variables that you need to replace. &lt;/p&gt;&lt;p&gt;Add matching variables in to your Properties object, so a matching key with the correct value/data, and that is it! &lt;/p&gt;&lt;p&gt;Dont forget to map the required inputs and outputs in to the &lt;code class=&quot;language-text&quot;&gt;Send notification&lt;/code&gt; workflow! &lt;/p&gt;&lt;p&gt;&lt;strong&gt;A little side note, if you are using the same variable multiple times within the HTML template, you might need to change the method for replacing the content - you should be able to use a Regex with the /g flag&lt;/strong&gt;&lt;/p&gt;</content:encoded><tags>automation,development,vmware,vra,vro</tags><featuredImage>https://samperrin.com/static/a0511c8075ba8349a213f67f0f3e2347/hero_5.jpg</featuredImage></item><item><title><![CDATA[vRA 8.1 Code Stream - Add GitHub Endpoint]]></title><description><![CDATA[A quick tidbit on adding a GitHub endpoint in to vRA 8.1 Code Stream]]></description><link>https://samperrin.com/posts/vra-8-1-code-stream-add-github-endpoint/</link><guid isPermaLink="false">https://samperrin.com/posts/vra-8-1-code-stream-add-github-endpoint/</guid><category><![CDATA[automation]]></category><category><![CDATA[vmware]]></category><category><![CDATA[vra]]></category><category><![CDATA[vrealize]]></category><pubDate>Tue, 02 Jun 2020 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;When adding a GitHub endpoint, I came across a part where the Guided Setup suggested using &lt;code class=&quot;language-text&quot;&gt;https://github.com/&amp;lt;name&amp;gt;/&amp;lt;repo-name&amp;gt;&lt;/code&gt; but instead you need to use the API endpoint &lt;code class=&quot;language-text&quot;&gt;https://api.github.com/&amp;lt;name&amp;gt;/&amp;lt;repo-name&amp;gt;&lt;/code&gt;&lt;/p&gt;&lt;p&gt;To access your repo you should also create a personal access token, instead of using your password for the GitHub API: &lt;a href=&quot;https://github.com/settings/tokens&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://github.com/settings/tokens&lt;/a&gt;&lt;/p&gt;&lt;p&gt;This screenshot is from the Guided Setup, showing the suggested repo URL format.&lt;/p&gt;&lt;p&gt;&lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:297px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:51.515151515151516%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAKCAYAAAC0VX7mAAAACXBIWXMAAA7DAAAOwwHHb6hkAAABxUlEQVQoz1VS7XaiMBD1TXZ7dv2ocrbqogFtEUISRVAIUEURPe3u9v3f4O5JLFR/zJm5Q5KZe7mtR4uhR3z0bQ5V34bq90id/TvcndJrJr4+O7A4DMLQGrkR5qsUP00P7qZAdHgHTY6wox3C4h00PiDcVRDZGav8giCv4CUlNuVf8KREkJ/x6yVAnzAYFkfLmC8xdAK0JxR+ckRWfSAp/oHLo+4/OQFGbojRIsTQWevecBFiymKNf3sRBjOBvsVgEI5WTa8z9eHHBySHP5DFB6LXC3qE3tG/laOmWsvVUK61GdgcP8YLfHt6xvfRCx7GjtapM/F06Fpj2vTbpvf5nX5tOPY2ICxG26Rwwh3C/RlutIcfl6DbPagsIdIS8yCHty0gslKf42mF9e4NLKvAZQFDbak2VBqN3RDdqQ/CEzjRKywhYS8zzFYSRNVCas3UYCISTPwt7GWqB8+CHBaPYczE9cHGFhYDEZm+vNjs4WUnPK8ztE1XD6st0tSf9Dump3sNZSWoii5hsNd7bQOen7HMLuBS0T7AT0pQeQKTRzCV0xNoXELIs6auGD7WtlEva1Pb16z/mFrfFg2+DW2RO8xvjM3xH1KDXGbSgOLRAAAAAElFTkSuQmCC&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;guidesetupsteps&quot; title=&quot;guidesetupsteps&quot; src=&quot;/static/39590d97d1fcc069dceb9ead9a690801/4c69f/guidesetupsteps.png&quot; srcSet=&quot;/static/39590d97d1fcc069dceb9ead9a690801/4c69f/guidesetupsteps.png 297w&quot; sizes=&quot;(max-width: 297px) 100vw, 297px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;&lt;/p&gt;&lt;p&gt;The other issue I had with the setup was the variable reference, for some reason when creating one through the Endpoint page it didn’t auto-populate the field - you can manually reference it by using the following format &lt;code class=&quot;language-text&quot;&gt;${var.&amp;lt;varName&amp;gt;}&lt;/code&gt; - where &lt;code class=&quot;language-text&quot;&gt;&amp;lt;varName&amp;gt;&lt;/code&gt; is the name of your variable (without the &lt;code class=&quot;language-text&quot;&gt;&amp;lt; &amp;gt;&lt;/code&gt;)&lt;/p&gt;&lt;p&gt;&lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:596px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:8.389261744966444%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAACCAYAAABYBvyLAAAACXBIWXMAAA7DAAAOwwHHb6hkAAAAdUlEQVQI1zXMOw6DMBREUfa/vxRRilBhgxGO38fEprgRllJMNVdnSimhIlzXRWttrPdOPU9EBDNDVSml4O7j6/1uv4Qyc2glZCOJE7MxiSq11hH+wRu/oRgD27YSYySEhX3fR+te8Wq8jwdLNl7rhzkJz5D5AcEYmR/0XRgSAAAAAElFTkSuQmCC&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;variable reference&quot; title=&quot;variable reference&quot; src=&quot;/static/2d8173aa107718a627ef314335002a74/fe133/variable-reference.png&quot; srcSet=&quot;/static/2d8173aa107718a627ef314335002a74/fe133/variable-reference.png 596w&quot; sizes=&quot;(max-width: 596px) 100vw, 596px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;&lt;/p&gt;&lt;p&gt;Once you have changed the above, you should be able to validate your endpoint successfully. &lt;/p&gt;&lt;p&gt;All of this can be found in the official vRA 8.1 documentation, just be mindful of the info in the Guided Setup&lt;/p&gt;&lt;p&gt;Variable creation and referencing: &lt;a href=&quot;https://docs.vmware.com/en/vRealize-Automation/8.1/Using-and-Managing-CodeStream/GUID-CF0E3CB7-BD6A-45F5-BA08-82F8C2E0373B.html&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://docs.vmware.com/en/vRealize-Automation/8.1/Using-and-Managing-CodeStream/GUID-CF0E3CB7-BD6A-45F5-BA08-82F8C2E0373B.html&lt;/a&gt;&lt;/p&gt;&lt;p&gt;GitHub Endpoint URL: &lt;a href=&quot;https://docs.vmware.com/en/vRealize-Automation/8.1/Using-and-Managing-CodeStream/GUID-06E10810-CFF1-486C-B773-13A48A92D914.html&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://docs.vmware.com/en/vRealize-Automation/8.1/Using-and-Managing-CodeStream/GUID-06E10810-CFF1-486C-B773-13A48A92D914.html&lt;/a&gt;&lt;/p&gt;</content:encoded><tags>automation,vmware,vra,vrealize</tags><featuredImage>https://samperrin.com/static/a0511c8075ba8349a213f67f0f3e2347/hero_5.jpg</featuredImage></item><item><title><![CDATA[The Importance Of Standards]]></title><description><![CDATA[In this article we will take a look at a process that hasn’t been standardised, and then compare it to the same process with some standards applied.]]></description><link>https://samperrin.com/posts/the-importance-of-standards/</link><guid isPermaLink="false">https://samperrin.com/posts/the-importance-of-standards/</guid><category><![CDATA[automation]]></category><category><![CDATA[development]]></category><pubDate>Mon, 10 Feb 2020 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Recently I have been working with a financial industry customer who is all in on Automation, however it became apparent quite early on that they haven’t standardised their processes. Now, in day to day running’s and operations of a business – particularly IT – this might not be a problem, but when you want to start automating, a lack of standards begins to complicate things. In the below article we will take a look at a process that hasn’t been standardised, and then compare it to the same process with some standards applied. We will then go on to discuss how much simpler it is to automate a standardised process.&lt;/p&gt;&lt;h3 id=&quot;non-standardised-process-1--creating-a-new-user&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#non-standardised-process-1--creating-a-new-user&quot; aria-label=&quot;non standardised process 1  creating a new user permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Non-standardised Process 1 – Creating a new user&lt;/h3&gt;&lt;p&gt;This process creates a new user, currently there are three ways someone can request a new account, and as we can see the information can arrive staggered, each of the yellow block. This results in multiple edits and updates before the account is ready for handover.&lt;/p&gt;&lt;p&gt;This staggered process also introduces the risk of error, for example, the request received via the phone might result in the incorrect spelling of a surname which then requires more edits to the user account.&lt;/p&gt;&lt;p&gt;&lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1355px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:18.228782287822877%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAECAYAAACOXx+WAAAACXBIWXMAAA7DAAAOwwHHb6hkAAABHklEQVQY0zXMz0rCAADA4T1djxAd6tAp8FCXoKAhHbqUBEHQSSIYgURRGaGiBoKblg7DnIrOP2mzprNAcbqJ+wVB3wN8wjjaxBkWsBUR51vHzviZGTJUg1A84LIF/jeYf+Yhs0Ojp7KbOaFhtiFYZqEN+OctPIRxpIXTe2KS3MAdVnCT69CJElafiWll9EaeFyVEpR7mKiVimEWyCR9GRyYUlqg030DtM69Zf6kwTrwzM7NMFRF7WKedPmLSLyHVJkjaALt6gV0I8PqlcaocY3bTjOQ9LKvKmRog/5Gid53DVDQ8d4EwutWZdmPMIstYPyZL8TmPBpD1QU4kWLpjM3WIo99DfI1yV2Ylsk2pk4bYKl7jgS1ln3Ndwr2p8QsOvRB/5LpTQAAAAABJRU5ErkJggg==&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;importance of standards pic1&quot; title=&quot;importance of standards pic1&quot; src=&quot;/static/fc17a8606ed6a2f045e97910ca5b6858/89e0a/importance_of_standards_pic1.png&quot; srcSet=&quot;/static/fc17a8606ed6a2f045e97910ca5b6858/89e0a/importance_of_standards_pic1.png 1355w&quot; sizes=&quot;(max-width: 1355px) 100vw, 1355px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;&lt;/p&gt;&lt;p&gt;On top of the different ways the process can be run, we also have no naming standards within this process, for example;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;A new user request comes in with the first name and last name details of Joe Bloggs&lt;/li&gt;&lt;li&gt;Service Desk Staff 1 generates the username of: jbloggs (first name initial and full last name)&lt;/li&gt;&lt;li&gt;Service Desk Staff 2 generates the username of: bloggj (first five characters from last name and first name initial)&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1033px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:39.49661181026138%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAICAYAAAD5nd/tAAAACXBIWXMAAA7DAAAOwwHHb6hkAAABWUlEQVQoz3WSzS8DURTF54+w9UfY+1j4trATTfhfbOxYSQitRERsEI02aaKEhb0EIRE7/aKUqelM38yd934yQ6NVTnKSl5N77s0791rGGNoZoVsziIR4vuAowVWCpwSju+utSDSh/uF3QQutV9Qkka8ym68ylq2wem3Hehh2+i1+o72ZFkyoCAMX1w8Zz1YYzVTo2yuydPkWjzO/7Fbj+J7SzDbFmW1qy+ex6Hs2ztEUzuEw9a1e3LsdfKAZCK5oXDE0lcRa/eyBUmKH0twubysXWE7mlsJUisJkiupCjhCwrzaxkz04+/04B4Moz0YJiNY4gcYTg+8LTeAle0dhZJ3H8SSviyd/fDmCekd7L+hmDSMuOs4wIJF/ZiJbYShdZi3O0HRZv5bSTtOZi/nOtaGE+dMq07knBtJlNm7altLy6WjL/56N7tCis6m5AeUPn7LjU/eCP8/sE8zfU7zViw2UAAAAAElFTkSuQmCC&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;importance of standards pic2&quot; title=&quot;importance of standards pic2&quot; src=&quot;/static/1b1cb1d2757d658577ef71eb1c6f6288/8144d/importance_of_standards_pic2.png&quot; srcSet=&quot;/static/1b1cb1d2757d658577ef71eb1c6f6288/8144d/importance_of_standards_pic2.png 1033w&quot; sizes=&quot;(max-width: 1033px) 100vw, 1033px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;&lt;/p&gt;&lt;h1 id=&quot;what-is-a-standard&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#what-is-a-standard&quot; aria-label=&quot;what is a standard permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;What is a Standard&lt;/h1&gt;&lt;p&gt;Standardisation is a set of rules and agreements that all users or consumers must adhere to, so that all processes are equal and meet set guidelines. This ensures that the end product has consistent quality and that any conclusions made are comparable with all other equivalent items in the same process. Standardisation is achieved by setting generally accepted guidelines with regard to how a product or service is created or supported, as well as to how a business is operated or how certain required processes are governed. The goal of standardisation is to enforce a level of consistency or uniformity to certain practices or operations within the selected environment.&lt;/p&gt;&lt;p&gt;(Reference: &lt;a href=&quot;https://www.investopedia.com/terms/s/standardization.asp&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://www.investopedia.com/terms/s/standardization.asp&lt;/a&gt;)\
(Reference: &lt;a href=&quot;http://www.qualityindustries.com/news-and-events/2015/06/30/five-benefits-of-standardized-work.1652673&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;http://www.qualityindustries.com/news-and-events/2015/06/30/five-benefits-of-standardized-work.1652673&lt;/a&gt;)&lt;/p&gt;&lt;h1 id=&quot;standardised-process-1--creating-a-new-user&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#standardised-process-1--creating-a-new-user&quot; aria-label=&quot;standardised process 1  creating a new user permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Standardised Process 1 – Creating a new user&lt;/h1&gt;&lt;p&gt;This is the same process as we saw earlier, but we have now applied standards. All requests for a new user must come in through a form, and this form has data fields that the requester must complete before submitting.&lt;/p&gt;&lt;p&gt;This now ensures that all data required for a user account arrives at once, and because it is via a typed form, we avoid the issues of misinterpretation that we had earlier with the first &amp;amp; last name spelling.&lt;/p&gt;&lt;p&gt;The new process reduces the number of edits and ultimately results in the requester getting their end product – the user account – much sooner.&lt;/p&gt;&lt;p&gt;&lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1194px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:16.499162479061976%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAADCAYAAACTWi8uAAAACXBIWXMAAA7DAAAOwwHHb6hkAAAA2UlEQVQI1x2MPUvDQABAb3fu6qijdHLyDzg4Ovlr/ACHQnXo0kHsoiBdpCCEOoibHWodStuQogGHipF8Xblc7nJPmgdvezwB4EqLsxWwEcrQQ43OKT46FJNr1NspetbDAn6smfwWBElJ5VzdO2Prxwbxd/VKsH3G134b9ZmyVivizhZxW5D2dki6DaILgR63WBnYuw9p3IQc9L/JgNhbsNy9rM0HU4ReRkhvzvrFxxnQwQPZXZP88RDpnSAHR8inY7AKVUF3mtJ6T7idZRjARhL57COHPuYn5x+oDMzWNqJ7ywAAAABJRU5ErkJggg==&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;importance of standards pic3&quot; title=&quot;importance of standards pic3&quot; src=&quot;/static/f82c63c1d4bbf49cc1a99e8426aa5e48/69dce/importance_of_standards_pic3.png&quot; srcSet=&quot;/static/f82c63c1d4bbf49cc1a99e8426aa5e48/69dce/importance_of_standards_pic3.png 1194w&quot; sizes=&quot;(max-width: 1194px) 100vw, 1194px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;&lt;/p&gt;&lt;p&gt;In the previous non-standardised process, we also had the differences in naming standards, these have now changed and all users created are in the format of: first initial and full last name.&lt;/p&gt;&lt;p&gt;&lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:1018px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:12.475442043222005%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAACCAYAAABYBvyLAAAACXBIWXMAAA7DAAAOwwHHb6hkAAAAo0lEQVQI1x2MTQvBAABA/R43JzKufsCuSiQHfoGT3yAfJ1eFISkSiUhxIko5OFjY2KK1zVepJ3vHV++57sUZaryGEq1gT/d8gedxjt0KYXdFDEkA68DWgPDgQnKiI/Yu7G4f/uilBWqsipqQeIz3uLR0BzmQ5+DNYrY3ztDoJzDLbqy6gDVKOeFKe+FrnokMNTy1E8vr2/FKpo/szyEHC5iNNT8/M4FreScMmAAAAABJRU5ErkJggg==&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;importance of standards pic4&quot; title=&quot;importance of standards pic4&quot; src=&quot;/static/f8dedd14f29b6cce04ae2bcfe9440338/f759a/importance_of_standards_pic4.png&quot; srcSet=&quot;/static/f8dedd14f29b6cce04ae2bcfe9440338/f759a/importance_of_standards_pic4.png 1018w&quot; sizes=&quot;(max-width: 1018px) 100vw, 1018px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;&lt;/p&gt;&lt;h1 id=&quot;automating-process&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#automating-process&quot; aria-label=&quot;automating process permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Automating Process&lt;/h1&gt;&lt;p&gt;When automating a process, we can see how standards simplify the task. Without standards we would need to account for every scenario that the request could follow, allow for breaks in the process, enable human interaction, and provide error correction. With standards we can allow automation to generate the username, validate the inputs and hand over the item to the requester.&lt;/p&gt;&lt;p&gt;When we have standards, estimating the time required for automation also becomes simpler, we have a clearly defined process with a set of inputs (the user details) and an expected outcome (the user account).&lt;/p&gt;&lt;p&gt;Once the process is standardised, and automated, changes to this process become more controlled – we can introduce and enforce a review process which means any changes to the process are agreed within the team and released in an agreed manner.&lt;/p&gt;&lt;h1 id=&quot;how-can-you-standardise&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#how-can-you-standardise&quot; aria-label=&quot;how can you standardise permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;How Can You Standardise?&lt;/h1&gt;&lt;p&gt;This is a very simplified approach, but it’s a great start for introducing standards.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Identify the core processes owners&lt;ul&gt;&lt;li&gt;These are the people that run it day-to-day (e.g. service desk staff)&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Hold a process review workshop with the process owners&lt;ul&gt;&lt;li&gt;Include someone who can moderate the meeting and create agreement between the team&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Whiteboard the process, get each owner to do it to highlight any differences&lt;ul&gt;&lt;li&gt;Like the non-standardised flow diagrams above, this will show differences amongst the team&lt;/li&gt;&lt;li&gt;Remember that because process owners might have their own view on a process, they aren’t wrong&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Identify the following information for the process&lt;ul&gt;&lt;li&gt;Process Inputs (what information is needed for the process to run, this can be from both users and other systems)&lt;/li&gt;&lt;li&gt;Process Outputs (what is the end product of the process, what does the requester get at the end)&lt;/li&gt;&lt;li&gt;Error handling (what happens in an error occurs at each of the steps)&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;For any process inputs, try to identify standards within those&lt;ul&gt;&lt;li&gt;Naming standards, for example, username generation&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;As an outcome, you should have one documented process that has been agreed by all process owners, this is your new standard&lt;/li&gt;&lt;li&gt;Try to identify how this will be rolled out to the business and enforced – this is important, otherwise your standard will collapse again!&lt;/li&gt;&lt;/ul&gt;</content:encoded><tags>automation,development</tags><featuredImage>https://samperrin.com/static/a0511c8075ba8349a213f67f0f3e2347/hero_5.jpg</featuredImage></item><item><title><![CDATA[Kubernetes - CKA Study Resources]]></title><description><![CDATA[A list of resources I have used in preperation for the CKA exam]]></description><link>https://samperrin.com/posts/kubernetes-cka-study-resources/</link><guid isPermaLink="false">https://samperrin.com/posts/kubernetes-cka-study-resources/</guid><category><![CDATA[kubernetes]]></category><category><![CDATA[development]]></category><pubDate>Thu, 23 Jan 2020 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;I am currently preparing for the CKA exam, here are the resources I have found so far…&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Detailed study guide: &lt;a href=&quot;https://github.com/burkeazbill/cka-studyguide&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://github.com/burkeazbill/cka-studyguide&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Knowledge dump with terminal tips: &lt;a href=&quot;https://gist.github.com/benc-uk/09cd8e8db23ff3f0e901bc04e0417ea4&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://gist.github.com/benc-uk/09cd8e8db23ff3f0e901bc04e0417ea4&lt;/a&gt;&lt;/li&gt;&lt;li&gt;CKA Study guide: &lt;a href=&quot;https://github.com/David-VTUK/CKA-StudyGuide&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://github.com/David-VTUK/CKA-StudyGuide&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Kubernetes Certified Administrator online resources: &lt;a href=&quot;https://github.com/walidshaari/Kubernetes-Certified-Administrator&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://github.com/walidshaari/Kubernetes-Certified-Administrator&lt;/a&gt;&lt;/li&gt;&lt;li&gt;List of tools and resources used, as well as pointers on aliases: &lt;a href=&quot;https://www.contino.io/insights/the-ultimate-guide-to-passing-the-cka-exam&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://www.contino.io/insights/the-ultimate-guide-to-passing-the-cka-exam&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Long list of CKA resources: &lt;a href=&quot;https://gist.github.com/strongjz/4c9ad30a12ab715ae94cf72d0e7bbc30&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://gist.github.com/strongjz/4c9ad30a12ab715ae94cf72d0e7bbc30&lt;/a&gt;&lt;/li&gt;&lt;li&gt;@kubernetesio Concepts: &lt;a href=&quot;https://kubernetes.io/docs/concepts/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://kubernetes.io/docs/concepts/&lt;/a&gt; &lt;/li&gt;&lt;li&gt;@kubernetesio kubeclt cheat sheet: &lt;a href=&quot;https://kubernetes.io/docs/reference/kubectl/cheatsheet/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://kubernetes.io/docs/reference/kubectl/cheatsheet/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Kubernetes the hard way: &lt;a href=&quot;https://github.com/kelseyhightower/kubernetes-the-hard-way&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://github.com/kelseyhightower/kubernetes-the-hard-way&lt;/a&gt;&lt;/li&gt;&lt;li&gt;@linuxacademyCOM kubectl cheat sheet: &lt;a href=&quot;https://linuxacademy.com/site-content/uploads/2019/04/Kubernetes-Cheat-Sheet_07182019.pdf&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://linuxacademy.com/site-content/uploads/2019/04/Kubernetes-Cheat-Sheet_07182019.pdf&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Exam preperation pointers: &lt;a href=&quot;https://medium.com/faun/preparation-and-resources-for-cka-exam-ca868fc678c9&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://medium.com/faun/preparation-and-resources-for-cka-exam-ca868fc678c9&lt;/a&gt;&lt;/li&gt;&lt;li&gt;CKA Ultimate guide: &lt;a href=&quot;https://medium.com/faun/certified-kubernetes-administrator-cka-ultimate-guide-238710f9ba73&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://medium.com/faun/certified-kubernetes-administrator-cka-ultimate-guide-238710f9ba73&lt;/a&gt;&lt;/li&gt;&lt;li&gt;@linuxfoundation Intro to Kubernetes: &lt;a href=&quot;https://training.linuxfoundation.org/training/introduction-to-kubernetes/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://training.linuxfoundation.org/training/introduction-to-kubernetes/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;KubeAcademy: &lt;a href=&quot;https://kube.academy/courses&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://kube.academy/courses&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Kubernet.io Study guide: &lt;a href=&quot;http://www.kubernet.io/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;http://www.kubernet.io/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;@teamKatacoda Kubernetes: &lt;a href=&quot;https://www.katacoda.com/courses/kubernetes&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://www.katacoda.com/courses/kubernetes&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</content:encoded><tags>kubernetes,development</tags><featuredImage>https://samperrin.com/static/a0511c8075ba8349a213f67f0f3e2347/hero_5.jpg</featuredImage></item><item><title><![CDATA[vRealize Orchestrator - Datastore Browser File Query File Types]]></title><description><![CDATA[vRO instance types of various Datastore File objects. Can be used when performing Datastore Browser File Queries]]></description><link>https://samperrin.com/posts/vrealize-orchestrator-datastore-browser-file-query-file-types/</link><guid isPermaLink="false">https://samperrin.com/posts/vrealize-orchestrator-datastore-browser-file-query-file-types/</guid><category><![CDATA[automation]]></category><category><![CDATA[development]]></category><category><![CDATA[vrealize]]></category><category><![CDATA[vro]]></category><category><![CDATA[vmware]]></category><category><![CDATA[til]]></category><pubDate>Thu, 12 Dec 2019 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;When performing a Datastore File browser search, the results can contain the following instance types, which files will be categorised under. &lt;/p&gt;&lt;p&gt;The instance types can be used when performing IF statements etc. E.g.
&lt;code class=&quot;language-text&quot;&gt;if (file instanceof VcVmDiskFileInfo)&lt;/code&gt;&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;text&quot;&gt;&lt;pre class=&quot;language-text&quot;&gt;&lt;code class=&quot;language-text&quot;&gt;VcFolderFileInfo
VcFloppyImageFileInfo
VcIsoImageFileInfo
VcTemplateConfigFileInfo
VcVmNvramFileInfo
VcVmDiskFileInfo
VcFileInfo
VcVmConfigFileInfo
VcVmLogFileInfo
VcVmSnapshotFileInfo&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;</content:encoded><tags>automation,development,vrealize,vro,vmware,til</tags><featuredImage>https://samperrin.com/static/a213f55596b00d3cfd56cf3887d8a808/hero_4.jpg</featuredImage></item><item><title><![CDATA[VMware vRealize Automation 8 Podcast]]></title><description><![CDATA[Cloud Insiders vRA8 Podcast]]></description><link>https://samperrin.com/posts/vmware-vrealize-automation-8-podcast/</link><guid isPermaLink="false">https://samperrin.com/posts/vmware-vrealize-automation-8-podcast/</guid><category><![CDATA[automation]]></category><category><![CDATA[vra]]></category><category><![CDATA[vmware]]></category><pubDate>Wed, 27 Nov 2019 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;“Automation has come a long way from the days of pen and paper, flowcharts, code and scripts, and now with the release of VMware vRealize Automation (vRA) 8 it’s moved to another level. Easy to deploy, streamlined, user friendly and faster – in this podcast, &lt;a href=&quot;https://www.xtravirt.com/automation&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;Xtravirt Cloud Automation&lt;/a&gt; consultant &lt;a href=&quot;https://twitter.com/sam_perrin&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;Sam Perrin&lt;/a&gt; discusses what vRA 8 is all about and why it’s re-ignited his excitement and passion for automation.”&lt;/p&gt;&lt;iframe src=&quot;https://player.acast.com/cloud-insiders/episodes/tech-focus-vmware-vrealize-automation-8&quot; frameBorder=&quot;0&quot; width=&quot;100%&quot; height=&quot;110px&quot; allow=&quot;autoplay&quot;&gt;&lt;/iframe&gt;</content:encoded><tags>automation,vra,vmware</tags><featuredImage>https://samperrin.com/static/a213f55596b00d3cfd56cf3887d8a808/hero_4.jpg</featuredImage></item><item><title><![CDATA[vRealize Automation 7 - Install vRA Agents on CentOS virtual machine]]></title><description><![CDATA[Steps required to install the vRA 7.x Agent on a CentOS Virtual Machine.]]></description><link>https://samperrin.com/posts/vrealize-automation-7-install-vra-agents-on-centos-virtual-machine/</link><guid isPermaLink="false">https://samperrin.com/posts/vrealize-automation-7-install-vra-agents-on-centos-virtual-machine/</guid><category><![CDATA[automation]]></category><category><![CDATA[development]]></category><category><![CDATA[vrealize]]></category><category><![CDATA[vra]]></category><category><![CDATA[vmware]]></category><category><![CDATA[vrealize]]></category><pubDate>Tue, 01 Oct 2019 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Ensure &lt;code class=&quot;language-text&quot;&gt;curl&lt;/code&gt; is install and change to the &lt;code class=&quot;language-text&quot;&gt;tmp&lt;/code&gt; directory for when we download the agent installer &lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;text&quot;&gt;&lt;pre class=&quot;language-text&quot;&gt;&lt;code class=&quot;language-text&quot;&gt;yum install curl -y
cd /tmp&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Download and extract the installer and make the script executable. Add the &lt;code class=&quot;language-text&quot;&gt;--insecure&lt;/code&gt; flag to the curl command if your vRA is behind a self-signed certificate. &lt;/p&gt;&lt;p&gt;Update the value of &lt;code class=&quot;language-text&quot;&gt;$VRA_FQDN&lt;/code&gt; to be your vRA instance (without the &lt;code class=&quot;language-text&quot;&gt;https://&lt;/code&gt;)&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;text&quot;&gt;&lt;pre class=&quot;language-text&quot;&gt;&lt;code class=&quot;language-text&quot;&gt;export $VRA_FQDN=vra01.domain.com
curl --insecure -LO https://$VRA_FQDN/software/download/prepare_vra_template_linux.tar.gz
tar -xvf prepare_vra_template_linux.tar.gz
cd prepare_vra_template_linux
chmod +x prepare_vra_template.sh&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Execute the script and follow the prompts.
You will need to know the FQDN for the vRA and IaaS boxes.&lt;/p&gt;&lt;p&gt;&lt;code class=&quot;language-text&quot;&gt;./prepare_vra_template.sh&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Remove udev persistence rules.&lt;/p&gt;&lt;p&gt;&lt;code class=&quot;language-text&quot;&gt;/bin/rm -f /etc/udev/rules.d/70*&lt;/code&gt;  &lt;/p&gt;&lt;p&gt;Enable machines cloned from this template to have their own unique identifiers&lt;/p&gt;&lt;p&gt;&lt;code class=&quot;language-text&quot;&gt;/bin/sed -i &amp;#x27;/^\(HWADDR\|UUID\)=/d&amp;#x27; /etc/sysconfig/network-scripts/ifcfg-eth0&lt;/code&gt; &lt;/p&gt;&lt;p&gt;If you rebooted or reconfigured the reference machine after installing the software bootstrap agent, reset the agent and follow the steps. &lt;/p&gt;&lt;p&gt;&lt;code class=&quot;language-text&quot;&gt;/opt/vmware-appdirector/agent-bootstrap/agent_reset.sh&lt;/code&gt; &lt;/p&gt;&lt;p&gt;Power down the VM&lt;/p&gt;&lt;p&gt;&lt;code class=&quot;language-text&quot;&gt;shutdown -h now&lt;/code&gt;&lt;/p&gt;</content:encoded><tags>automation,development,vrealize,vra,vmware,vrealize</tags><featuredImage>https://samperrin.com/static/a213f55596b00d3cfd56cf3887d8a808/hero_4.jpg</featuredImage></item><item><title><![CDATA[Small, Medium or Large: There Is No One Size Fits All]]></title><description><![CDATA[Working out the effort required for an automation project can be challenging. The primary advantage to t-shirt sizes is the speed and ease of getting started and they can be a great way of getting used to relative estimating]]></description><link>https://samperrin.com/posts/small-medium-or-large-there-is-no-one-size-fits-all/</link><guid isPermaLink="false">https://samperrin.com/posts/small-medium-or-large-there-is-no-one-size-fits-all/</guid><category><![CDATA[automation]]></category><category><![CDATA[development]]></category><pubDate>Tue, 18 Dec 2018 00:00:00 GMT</pubDate><content:encoded>&lt;h2 id=&quot;why-a-t-shirt--do-i-look-good-in-this&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#why-a-t-shirt--do-i-look-good-in-this&quot; aria-label=&quot;why a t shirt  do i look good in this permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Why A T-Shirt &amp;amp; Do I Look Good In This?&lt;/h2&gt;&lt;p&gt;Working out the effort required for an automation project can be challenging. Teams may have different abilities and skill-sets causing individuals effort estimations for tasks to differ. The primary advantage to t-shirt sizes is the speed and ease of getting started and they can be a great way of getting used to relative estimating\
By expelling the focus on a numerical score, the development team has the ability and freedom to think more dynamically and abstractly about the effort associated with a request. By limiting the number of t-shirt sizes, you allow for faster estimates and less deliberation around placement. You can use t-shirts without a numerical value associated with them, but with the values you can better identify the differences in size between the t-shirts and use those same values for pricing and velocity calculations.&lt;/p&gt;&lt;h2 id=&quot;whats-in-a-t-shirt&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#whats-in-a-t-shirt&quot; aria-label=&quot;whats in a t shirt permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;What’s In A T-Shirt&lt;/h2&gt;&lt;p&gt;A t-shirt is a defined amount of effort, measured in days, hours, points, or anything else you feel appropriate. These types of estimates become more efficient and effective when you have lots of ‘things’ to estimate at the same time, rather than just a single ‘thing.’ Behind a t-shirt size you often have a numerical value associated to it, this can be Fibonacci numbers or hours and days. So for example, if you believe the new requirement will suit a medium t-shirt size, you now have an idea of the effort that will be required. The table below shows an example of days of effort per t-shirt size.&lt;/p&gt;&lt;h2 id=&quot;t-shirt-sizing-table&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#t-shirt-sizing-table&quot; aria-label=&quot;t shirt sizing table permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;T-Shirt Sizing Table&lt;/h2&gt;&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Size&lt;/th&gt;&lt;th&gt;Effort (days)&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;Small&lt;/td&gt;&lt;td&gt;1&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Medium&lt;/td&gt;&lt;td&gt;2-3&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Large&lt;/td&gt;&lt;td&gt;4.5&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;X-Large&lt;/td&gt;&lt;td&gt;Estimated Per Requirement!&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;h2 id=&quot;so-how-do-we-get-started&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#so-how-do-we-get-started&quot; aria-label=&quot;so how do we get started permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;So How Do We Get Started?&lt;/h2&gt;&lt;ul&gt;&lt;li&gt;We create a relative estimation. We do this by comparing the new requirement to a previous requirement&lt;/li&gt;&lt;li&gt;The old and new requirements are evaluated (at a high level) and a decision is made as to if they are equivalent in effort or not&lt;/li&gt;&lt;li&gt;If the old requirement had previously been gauged a ‘medium t-shirt’ and the requirement doesn’t fit this size.. well, you pick the right size t-shirt to fit the body!&lt;/li&gt;&lt;/ul&gt;&lt;h2 id=&quot;does-it-fit-right&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#does-it-fit-right&quot; aria-label=&quot;does it fit right permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Does It Fit Right&lt;/h2&gt;&lt;p&gt;During the development process you will get an idea if the estimate was accurate or not. If it’s way off adjust it accordingly. Just keep in mind that it’s also beneficial to keep with the initial estimate so that it can be reviewed afterwards. When you do, it allows you to ask questions such as&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Why was the initial estimate for the request an S,M,L,XL?&lt;/li&gt;&lt;li&gt;When the work was finished, was the request more like a S,M,L,XL?&lt;/li&gt;&lt;li&gt;Why was the request larger than expected?&lt;/li&gt;&lt;li&gt;What made this request an S,M,L,XL instead of a S,M,L,XL? Was there just more work? Was this type of work new?&lt;/li&gt;&lt;li&gt;How can we avoid underestimating this type of request in the future &lt;em&gt;(&lt;strong&gt;hint:&lt;/strong&gt; adopting a working Agile methodology, working in sprints and having planning and review sessions will greatly help with this. A blog post for another time maybe?)&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Once you have reviewed your estimates against the reality (post delivery) you can build out or adjust your baseline for each size. New requests from this point will use this baseline. If a request is too big to fit a t-shirt you have two options&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Break it down into smaller requirements that do fit within your sizes&lt;/li&gt;&lt;li&gt;As a last resort, place it into a X-Large or XX-Large t-shirt size where you don’t have an estimation of effort &lt;em&gt;(&lt;strong&gt;warning:&lt;/strong&gt; This is a really bad idea and completely devalues all your other sizing efforts. You don’t know how long it will take, amount of resource required, cost.. so what do I do? you ask. See the previous point)&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h2 id=&quot;how-does-xtravirt-use-t-shirt-sizes&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#how-does-xtravirt-use-t-shirt-sizes&quot; aria-label=&quot;how does xtravirt use t shirt sizes permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;How Does Xtravirt Use T-Shirt Sizes?&lt;/h2&gt;&lt;p&gt;&lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:300px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:27.666666666666668%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAGCAYAAADDl76dAAAACXBIWXMAAAsTAAALEwEAmpwYAAABtElEQVQY0y1PTUhUYRQ9jzEmCJlQIXAhKlgUgdAmcMpJSCkXbRSmVFJ7OpE/oxaEmAhRoiNoWOnM1HS+N81CJRdCSGDiJrAIRBwjwoX4rr7GwIVLF8HIN87ics7l3HvuPQDlNCgAdwxQvKCMg7YLSlyguE80OZXFnCzqqgXFzHCV6VtAeazJPChBUKKgjIGSBiUGShIUBcogKH9AiYAyA0oBKAOgvAPlc3ZOa19A+Q+DdqM2MT7sXDFoV4HyyaB9E5TvBu3beuFM9Lf+dA6UTVASoMyCdhsoKVBWYGXSDIHyCrBSw1DOIeL7JmaOimD9XYWVGoDlvMfXtBvKWUP8nx/K2YKV6oZyDhDfv4+PB1VQe0dQziTUrk6qD/xAwdRarHxs4ZYnnIz6+0eKz739OegJJ+fypte70yVwF01+u5sb+bXoCScXyyaWKwvfrHZee5m4cH58qcYT2UycDW8E8qfX4Ypt6xQhjLbVe589elAz0XqnvCcYrA6ZdV42XC8dbvdf7urtu/Ei0FBh3fNeet1ce7W/o/3i84dNlU+6OnxPOwO+kFlXMWrWl8UafcBSGuAujgFzgd6zEYXtmQAAAABJRU5ErkJggg==&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;xtravirt blue sl 3x 300x83&quot; title=&quot;xtravirt blue sl 3x 300x83&quot; src=&quot;/static/e3c16d35c3fc39036e99d25aee687789/a8a0d/xtravirt_blue_sl-3x-300x83.png&quot; srcSet=&quot;/static/e3c16d35c3fc39036e99d25aee687789/a8a0d/xtravirt_blue_sl-3x-300x83.png 300w&quot; sizes=&quot;(max-width: 300px) 100vw, 300px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;&lt;/p&gt;&lt;p&gt;Often the information received during an automation project kickoff, is the name and a brief description of the Service Request (the thing that needs to be automated). The real detail is missing at this stage. Having a small amount of information makes detailed planning difficult, you have questions that need to be answered, you don’t know the risks, full requirements or the even the success criteria; yet you still need to provide two estimates to the customer – a cost estimate and an effort estimate. This is where t-shirt sizes help us. &lt;/p&gt;&lt;p&gt;We work with four sizes; small, medium, large and extra-large. Together as a team we go through the list of Service Requests, discuss what we believe may be required and provide our estimates. These estimates are based on previous experience and so afford us an educated idea on what size to allocate (relative estimation). When the team are agreed on the size of the Service Request we move on to the next until we have an estimate for all the required work. Once all the estimations are completed, we can provide an idea on the total effort, which then leads to an informed cost quote for the customer!&lt;/p&gt;&lt;p&gt;Due to our experiences, we have been able to analyse our decisions, see where we have over or under estimated effort and identify why that happened. This allows us to ensure the original t-shirt still fits. If it doesn’t, we can change it for future estimates. Using this data, we can build out a baseline number of days associated to each t-shirt size.&lt;/p&gt;&lt;h2 id=&quot;the-takeaway&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#the-takeaway&quot; aria-label=&quot;the takeaway permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;The Takeaway&lt;/h2&gt;&lt;ul&gt;&lt;li&gt;Create effort estimations before commencing any work&lt;/li&gt;&lt;li&gt;Record actual effort&lt;/li&gt;&lt;li&gt;Review actual vs estimated effort to better educate yourself for ‘next time’&lt;/li&gt;&lt;li&gt;Using terminology such as ‘t-shirt’ sizes help abstract away from hours, minutes, days of effort which is often hard to quantify&lt;/li&gt;&lt;li&gt;Continual refinement and education means better estimation of effort and delivery cost as opposed to continually working with ‘Guesstimates’&lt;/li&gt;&lt;/ul&gt;</content:encoded><tags>automation,development</tags><featuredImage>https://samperrin.com/static/2b659793bd268bdef6cc3b954b4db8de/hero_3.jpg</featuredImage></item><item><title><![CDATA[Behind Automation]]></title><description><![CDATA[Cloud Insiders "Behind Automation" Podcast]]></description><link>https://samperrin.com/posts/behind-automation/</link><guid isPermaLink="false">https://samperrin.com/posts/behind-automation/</guid><category><![CDATA[automation]]></category><pubDate>Fri, 14 Sep 2018 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;I was lucky enough to partake in a podcast recently with colleagues Paul Davey and Stuart Robinson of &lt;a href=&quot;http://xtravirt.com/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;Xtravirt&lt;/a&gt;. If you want to learn more about automation then please check it out!&lt;/p&gt;&lt;p&gt;This episode outlines:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;What is automation?&lt;/li&gt;&lt;li&gt;The common reasons businesses are automating business processes.&lt;/li&gt;&lt;li&gt;Some of tools being used in automation – from Puppet and Chef for configuration management to HashiCorp’s options for provisioning, security and the running of applications.&lt;/li&gt;&lt;li&gt;The need for businesses to take a business logic first approach to automation projects.&lt;/li&gt;&lt;li&gt;Some common mistakes to avoid.&lt;/li&gt;&lt;li&gt;How Xtravirt have designed workshops and best practice methodologies to ensure automation projects stay on track and deliver the business outcomes they were intended to.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;You can listen to the podcast by clicking &lt;a href=&quot;https://shows.pippa.io/cloud-insiders/behind-automation&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;here&lt;/a&gt;.&lt;/p&gt;</content:encoded><tags>automation</tags><featuredImage>https://samperrin.com/static/2b659793bd268bdef6cc3b954b4db8de/hero_3.jpg</featuredImage></item><item><title><![CDATA[Install VestaCP on Google Cloud in 5 steps]]></title><description><![CDATA[5 quick steps to get up and running with VestaCP and finish with adding your first domain to the portal.]]></description><link>https://samperrin.com/posts/install-vestacp-on-google-cloud-in-5-steps/</link><guid isPermaLink="false">https://samperrin.com/posts/install-vestacp-on-google-cloud-in-5-steps/</guid><category><![CDATA[development]]></category><pubDate>Mon, 29 Aug 2016 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;This article will provide you with 5 quick steps to get up and running with VestaCP and finish with adding your first domain to the portal.&lt;/p&gt;&lt;p&gt;VestaCP is an Open Source control panel that helps you manage your web server and simplifies a lot of things! &lt;a href=&quot;https://vestacp.com/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;https://vestacp.com/&lt;/a&gt;&lt;/p&gt;&lt;ol&gt;&lt;li&gt;&lt;p&gt;Within the Google Cloud Console, navigate to &lt;a href=&quot;https://console.cloud.google.com/networking/firewalls/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;Networking &amp;gt; Firewall Rules&lt;/a&gt;.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Add a new firewall rule for VestaCP&lt;/li&gt;&lt;li&gt;Name = &lt;code class=&quot;language-text&quot;&gt;vestacp-panel&lt;/code&gt;&lt;/li&gt;&lt;li&gt;Source Filter = &lt;code class=&quot;language-text&quot;&gt;allow from any source (0.0.0.0/0)&lt;/code&gt;&lt;/li&gt;&lt;li&gt;Allowed protocols and ports= &lt;code class=&quot;language-text&quot;&gt;8083/tcp&lt;/code&gt;&lt;/li&gt;&lt;li&gt;Target Tags = &lt;code class=&quot;language-text&quot;&gt;vestacp-panel&lt;/code&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Deploy a new &lt;a href=&quot;https://console.cloud.google.com/compute/instances&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;Compute Engine VM Instance&lt;/a&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Define Name and Zone based on your preference&lt;/li&gt;&lt;li&gt;Choose Machine Type (I have used “micro”)&lt;/li&gt;&lt;li&gt;Boot Disk = 10gb and CentOS 7&lt;/li&gt;&lt;li&gt;Firewall = allow HTTP and HTTPS (so your websites can get through when setup)&lt;/li&gt;&lt;li&gt;Expand “Management, disk, networking, SSH keys”&lt;ul&gt;&lt;li&gt;Under Management, in the Tags section, add “vestacp-panel”&lt;/li&gt;&lt;li&gt;Under Networking, assign a New Static External IP (or re-use an old one if you have any) – take note of the External IP assigned, you’ll need this later.&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Create the instance&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Wait for the new VM to finish deploying, connect to it via SSH and install VestaCP&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;cd /tmp/&lt;/code&gt;&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;curl -O http://vestacp.com/pub/vst-install.sh&lt;/code&gt;&lt;/li&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;sudo bash vst-install.sh&lt;/code&gt;&lt;/li&gt;&lt;li&gt;Follow the on screen steps&lt;/li&gt;&lt;li&gt;When it asks for an FQDN, provide the full URL that you will use to access the portal (e.g. panel.example.com) – you will also need to add this as an A record for your domain.&lt;/li&gt;&lt;li&gt;Take note of password presented to you at the end of the install&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Login to your new VestaCP Control Panel&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;code class=&quot;language-text&quot;&gt;https://&amp;lt;your_server_ip&amp;gt;:8083&lt;/code&gt; or &lt;code class=&quot;language-text&quot;&gt;https://&amp;lt;your_server_URL&amp;gt;:8083&lt;/code&gt;&lt;/li&gt;&lt;li&gt;Username = &lt;code class=&quot;language-text&quot;&gt;admin&lt;/code&gt;&lt;/li&gt;&lt;li&gt;Password = provided at the end of Step 3&lt;/li&gt;&lt;li&gt;If you can’t reach the portal, check your Firewall Rules from Step 1 and ensure your VM has the correct tags, as per Step 2&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Configure your VestaCP server&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Edit the Admin user and change the password to something secure&lt;/li&gt;&lt;li&gt;Edit the VestaCP firewall and modify any existing rules to drop traffic you don’t want/need (POP3, DB, PING etc)&lt;/li&gt;&lt;li&gt;Add your domain&lt;ul&gt;&lt;li&gt;After this you’ll need to point your website to your new VestaCP web server&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;There are plenty more things to set up within VestaCP, such as setting Private Nameservers, creating Packages etc but the above will get you up and running.&lt;/p&gt;</content:encoded><tags>development</tags><featuredImage>https://samperrin.com/static/1c89d7bd9ce795ec0476812eb75210cc/hero_2.jpg</featuredImage></item><item><title><![CDATA[Elasticsearch Cluster Install on CentOS 7]]></title><description><![CDATA[Setup a simple 3 not Elasticsearch cluster]]></description><link>https://samperrin.com/posts/elasticsearch-cluster-install-on-centos-7/</link><guid isPermaLink="false">https://samperrin.com/posts/elasticsearch-cluster-install-on-centos-7/</guid><category><![CDATA[development]]></category><pubDate>Fri, 24 Jun 2016 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;This post wont go in to any detail around setting up CentOS itself, but it will cover getting a simple 3 node Elasticsearch cluster up and running, with a couple of helpful plugins.&lt;/p&gt;&lt;p&gt;Install Java and check the install&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;text&quot;&gt;&lt;pre class=&quot;language-text&quot;&gt;&lt;code class=&quot;language-text&quot;&gt;yum install java-1.8.0-openjdk.x86_64 -y
java -version&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Download Elasticsearch (check the site &lt;a href=&quot;https://www.elastic.co/downloads/elasticsearch&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;here&lt;/a&gt; for the latest versions)&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;text&quot;&gt;&lt;pre class=&quot;language-text&quot;&gt;&lt;code class=&quot;language-text&quot;&gt;cd /tmp
wget https://download.elasticsearch.org/elasticsearch/release/org/elasticsearch/distribution/rpm/elasticsearch/2.2.1/elasticsearch-2.2.1.rpm&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Install Elasticsearch&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;text&quot;&gt;&lt;pre class=&quot;language-text&quot;&gt;&lt;code class=&quot;language-text&quot;&gt;cd /tmp
sudo rpm -ivh elasticsearch-2.2.1.rpm&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This results in Elasticsearch being installed in &lt;code class=&quot;language-text&quot;&gt;/usr/share/elasticsearch/&lt;/code&gt; with its configuration files placed in &lt;code class=&quot;language-text&quot;&gt;/etc/elasticsearch&lt;/code&gt; and its init script added in &lt;code class=&quot;language-text&quot;&gt;/etc/init.d/elasticsearch&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Enable Elasticsearch on Boot&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;text&quot;&gt;&lt;pre class=&quot;language-text&quot;&gt;&lt;code class=&quot;language-text&quot;&gt;sudo systemctl enable elasticsearch.service&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Configure Elasticsearch&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;text&quot;&gt;&lt;pre class=&quot;language-text&quot;&gt;&lt;code class=&quot;language-text&quot;&gt;vi /etc/elasticsearch/elasticsearch.yml&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Add near the top, and replace anything in &amp;lt; &amp;gt; with your details&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;text&quot;&gt;&lt;pre class=&quot;language-text&quot;&gt;&lt;code class=&quot;language-text&quot;&gt;cluster.name: &amp;lt;name of the cluster&amp;gt;
#below line dynamically sets the node name based on the server hostname
node.name: ${HOSTNAME}
#below binds elasticsearch to the local (127.0.0.1) and site ip address (e.g. 192.168.1.1)
network.host: [_site_, _local_]
http.port: 9200
bootstrap.mlockall: true
#below sets the nodes the cluster should find
discovery.zen.ping.unicast.hosts: [&amp;quot;&amp;lt;node1_ip_or_fqdn&amp;gt;&amp;quot;, &amp;quot;&amp;lt;node2_ip_or_fqdn&amp;gt;&amp;quot;, &amp;quot;&amp;lt;node3_ip_or_fqdn&amp;gt;&amp;quot;]&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Restart and Verify Elasticsearch status&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;text&quot;&gt;&lt;pre class=&quot;language-text&quot;&gt;&lt;code class=&quot;language-text&quot;&gt;sudo systemctl restart elasticsearch.service
sudo systemctl status elasticsearch.service&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;You should be able to access the node now, on: &lt;code class=&quot;language-text&quot;&gt;http://&amp;lt;node-ip&amp;gt;:9200&lt;/code&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Optional:&lt;/strong&gt; Install Elastic-HQ and Head Plugins&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;text&quot;&gt;&lt;pre class=&quot;language-text&quot;&gt;&lt;code class=&quot;language-text&quot;&gt;cd /usr/share/elasticsearch/
bin/plugin install mobz/elasticsearch-head
sudo bin/plugin install royrusso/elasticsearch-HQ
sudo systemctl restart elasticsearch.service
sudo systemctl status elasticsearch.service&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Once installed, you can access these plugins via:\
Head = &lt;code class=&quot;language-text&quot;&gt;http://&amp;lt;node-ip&amp;gt;:9200/_plugin/head&lt;/code&gt;
HQ = &lt;code class=&quot;language-text&quot;&gt;http://&amp;lt;node-ip&amp;gt;:9200/_plugin/hq&lt;/code&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Additional Nodes:&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Repeat the same process on your other servers, you can add more than 3 nodes to the cluster, but if you do make sure you update &lt;code class=&quot;language-text&quot;&gt;discovery.zen.ping.unicast.hosts&lt;/code&gt; in your Elasticsearch config to include those additional nodes.&lt;/p&gt;</content:encoded><tags>development</tags><featuredImage>https://samperrin.com/static/1c89d7bd9ce795ec0476812eb75210cc/hero_2.jpg</featuredImage></item><item><title><![CDATA[CentOS 7 – Installing pymssql with pip, libgnutls.so.26 error]]></title><description><![CDATA[When trying to install pymssql with pip you may get a requirements error for libgnutls.so.26]]></description><link>https://samperrin.com/posts/centos-7-–-installing-pymssql-with-pip-libgnutls-so-26-error/</link><guid isPermaLink="false">https://samperrin.com/posts/centos-7-–-installing-pymssql-with-pip-libgnutls-so-26-error/</guid><category><![CDATA[development]]></category><category><![CDATA[linux]]></category><pubDate>Tue, 09 Feb 2016 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;When trying to install pymssql with pip you may get a requirements error for libgnutls.so.26&lt;/p&gt;&lt;p&gt;To fix this error I took the following steps:&lt;/p&gt;&lt;p&gt;For the below you may need the EPEL repo, install this with the below command&lt;/p&gt;&lt;p&gt;&lt;code class=&quot;language-text&quot;&gt;yum install epel-release&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Install gcc&lt;/p&gt;&lt;p&gt;&lt;code class=&quot;language-text&quot;&gt;yum install gcc&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Install python-devel&lt;/p&gt;&lt;p&gt;&lt;code class=&quot;language-text&quot;&gt;yum install python-devel&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Download &lt;code class=&quot;language-text&quot;&gt;freetds-devel&lt;/code&gt; and &lt;code class=&quot;language-text&quot;&gt;freetds&lt;/code&gt; for CentOS 7 and store in &lt;code class=&quot;language-text&quot;&gt;/tmp/&lt;/code&gt; (or somewhere else, but remember where you stored it for later)&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;http://rpm.pbone.net/index.php3/stat/4/idpl/31220521/dir/redhat_el_7/com/freetds-devel-0.95.19-1.el7.x86_64.rpm.html&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;http://rpm.pbone.net/index.php3/stat/4/idpl/31220521/dir/redhat_el_7/com/freetds-devel-0.95.19-1.el7.x86_64.rpm.html&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;http://rpm.pbone.net/index.php3/stat/4/idpl/31220520/dir/redhat_el_7/com/freetds-0.95.19-1.el7.x86_64.rpm.html&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;http://rpm.pbone.net/index.php3/stat/4/idpl/31220520/dir/redhat_el_7/com/freetds-0.95.19-1.el7.x86_64.rpm.html&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Install both of them&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;text&quot;&gt;&lt;pre class=&quot;language-text&quot;&gt;&lt;code class=&quot;language-text&quot;&gt;yum install /tmp/freetds-0.95.19-1.el7.x86_64.rpm
yum install /tmp/freetds-devel-0.95.19-1.el7.x86_64.rpm&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Run &lt;code class=&quot;language-text&quot;&gt;pip install pymssql&lt;/code&gt; again, it should hopefully succeed this time.&lt;/p&gt;</content:encoded><tags>development,linux</tags><featuredImage>https://samperrin.com/static/1c89d7bd9ce795ec0476812eb75210cc/hero_2.jpg</featuredImage></item><item><title><![CDATA[FortiGate as Slave DNS with Windows DNS Master]]></title><description><![CDATA[Setup your FortiGate device so that requests towards specific domains are forwarded to a Windows DNS server.]]></description><link>https://samperrin.com/posts/fortigate-as-slave-dns-with-windows-dns-master/</link><guid isPermaLink="false">https://samperrin.com/posts/fortigate-as-slave-dns-with-windows-dns-master/</guid><category><![CDATA[other]]></category><pubDate>Sat, 24 Oct 2015 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;It is possible to setup your FortiGate device so that requests towards specific domains are forwarded to a Windows DNS server. Below are the steps needed to get this working.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;On the Windows Master DNS Server&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Open DNS Manager and open the zone needed&lt;/li&gt;&lt;li&gt;Find the Start of Authority (SOA) record&lt;/li&gt;&lt;li&gt;Properties &amp;gt; Zone Transfers&lt;/li&gt;&lt;li&gt;Allow Zone Transfers &amp;gt; To Any Server (you can also specify the server)&lt;/li&gt;&lt;li&gt;Open ‘Notify’ and add in the Slave DNS IP address (the IP your FortiGate will be seen as to the Master DNS)&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;On the FortiGate Slave&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Enable the DNS Database feature (System &amp;gt; Config &amp;gt; Features)&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Go to System &amp;gt; Network &amp;gt; DNS Servers and Create a new DNS Database.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Type: Slave&lt;/li&gt;&lt;li&gt;View: Shadow&lt;/li&gt;&lt;li&gt;DNS Zone:&lt;em&gt;&amp;lt;dns_zone&amp;gt;&lt;/em&gt;&lt;/li&gt;&lt;li&gt;Domain Name:&lt;em&gt;&amp;lt;dns_zone.local&amp;gt;&lt;/em&gt;&lt;/li&gt;&lt;li&gt;IP of Master:&lt;/li&gt;&lt;li&gt;Authoritative: Enable/Disable&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;You will then to add an SRV record, as well as identify the source IP address if your Master DNS is over VPN;&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Connect to FortiGate CLI&lt;/li&gt;&lt;li&gt;Add SRV record&lt;/li&gt;&lt;/ul&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;text&quot;&gt;&lt;pre class=&quot;language-text&quot;&gt;&lt;code class=&quot;language-text&quot;&gt;config system dns-database
edit &amp;quot;&amp;lt;dns_zone&amp;gt;&amp;quot;
set forwarder &amp;quot;&amp;lt;IP of Master DNS&amp;gt;&amp;quot;
next
end&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;Specify source IP&lt;/li&gt;&lt;/ul&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;text&quot;&gt;&lt;pre class=&quot;language-text&quot;&gt;&lt;code class=&quot;language-text&quot;&gt;config system dns-database
edit &amp;quot;&amp;lt;dns_zone&amp;gt;&amp;quot;
set source-ip &amp;quot;&amp;lt;IP of FortiGate&amp;gt;&amp;quot;
next
end&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;strong&gt;Add the DNS service to the Interface&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Go to System &amp;gt; Network &amp;gt; DNS Servers and Create a new DNS Service.&lt;/li&gt;&lt;li&gt;Interface:&lt;em&gt;&lt;code class=&quot;language-text&quot;&gt;&amp;lt;Interface users will connect to&amp;gt;&lt;/code&gt;&lt;/em&gt;&lt;/li&gt;&lt;li&gt;Mode: Recursive&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Testing&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;You can test the new DNS service works by running a ping through your FortiGate CLI&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;text&quot;&gt;&lt;pre class=&quot;language-text&quot;&gt;&lt;code class=&quot;language-text&quot;&gt;execute ping-options source &amp;lt;interface IP address&amp;gt;
execute ping &amp;lt;FQDN of a server in the new DNS zone&amp;gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;strong&gt;Potential Issues&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;The interface your users connect to may be set to use the “Same as System DNS”. If you use external DNS servers this means your users will not benefit from the changes we have just made.&lt;/p&gt;&lt;p&gt;To fix this change the interface settings to be “Same as Interface IP”, this now means users will get the Interface IP as their DNS server, and will benefit from all DNS Database changes we make on the FortiGate&lt;/p&gt;</content:encoded><tags>other</tags><featuredImage>https://samperrin.com/static/4baf0f5e471c12bb261184c9deab22c3/hero_1.jpg</featuredImage></item><item><title><![CDATA[FortiGate – Change Switch Mode]]></title><description><![CDATA[Change FortiGate device switch mode]]></description><link>https://samperrin.com/posts/fortigate-–-change-switch-mode/</link><guid isPermaLink="false">https://samperrin.com/posts/fortigate-–-change-switch-mode/</guid><category><![CDATA[other]]></category><pubDate>Tue, 13 Oct 2015 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Out of the box, your FortiGate device will most likely be in Switch mode, this groups the internal interfaces in to a single switch. To change to Interface mode, follow the below steps.&lt;/p&gt;&lt;p&gt;Interface mode allows you to control all of the interfaces separately. To change modes make sure none of the interfaces (lan/internal) are referenced&lt;/p&gt;&lt;p&gt;Enter Interface Mode&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;text&quot;&gt;&lt;pre class=&quot;language-text&quot;&gt;&lt;code class=&quot;language-text&quot;&gt;config system global
set internal-switch-mode interface
end&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Enter Switch Mode:&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;text&quot;&gt;&lt;pre class=&quot;language-text&quot;&gt;&lt;code class=&quot;language-text&quot;&gt;config system global
set internal-switch-mode switch
end&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;</content:encoded><tags>other</tags><featuredImage>https://samperrin.com/static/4baf0f5e471c12bb261184c9deab22c3/hero_1.jpg</featuredImage></item><item><title><![CDATA[FortiGate Reports Menu Missing]]></title><description><![CDATA[Resolve issue with Reports menu missing from Fortigate]]></description><link>https://samperrin.com/posts/fortigate-reports-menu-missing/</link><guid isPermaLink="false">https://samperrin.com/posts/fortigate-reports-menu-missing/</guid><category><![CDATA[other]]></category><pubDate>Thu, 03 Sep 2015 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;You might come across an instance where your Reports menu is missing from within the FortiGate GUI. I noticed this today when I went to disable local report emails and wasn’t able to!&lt;/p&gt;&lt;p&gt;We use FortiAnalyzer for our reports, so when transferring to this we disabled Local Disk logging, this in turn removed the reports menu.&lt;/p&gt;&lt;p&gt;It is a quick fix to get the menu back;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Connect to your FortiGate GUI&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Log &amp;amp; Report &amp;gt; Log Config &amp;gt; Log Settings&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Enable Disk logging&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Enable Local Reports&lt;/p&gt;&lt;ul&gt;&lt;li&gt;If you are using FortiAnalyzer you may get an error message about Fortinet recommendations, you can ignore this for the moment&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Log out and then Log back in, you will now see the menu&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Log &amp;amp; Report &amp;gt; Log Config &amp;gt; Report&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;In my case we disabled “Email Generated Reports” and then disabled Local Reports and Disk logging. By disabling Local Reports you clear the FortiAnalyzer message you might have come across earlier.&lt;/p&gt;</content:encoded><tags>other</tags><featuredImage>https://samperrin.com/static/4baf0f5e471c12bb261184c9deab22c3/hero_1.jpg</featuredImage></item><item><title><![CDATA[FortiManager Disable SSLv3]]></title><description><![CDATA[FortiManager Disable SSLv3]]></description><link>https://samperrin.com/posts/fortimanager-disable-sslv3/</link><guid isPermaLink="false">https://samperrin.com/posts/fortimanager-disable-sslv3/</guid><category><![CDATA[other]]></category><pubDate>Fri, 07 Aug 2015 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;This is documented in the latest release notes, but to quickly disable SSLv3 on your FortiManager device, run the following;&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;text&quot;&gt;&lt;pre class=&quot;language-text&quot;&gt;&lt;code class=&quot;language-text&quot;&gt;config system global
set ssl-protocol tlsv1
end&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;</content:encoded><tags>other</tags><featuredImage>https://samperrin.com/static/4baf0f5e471c12bb261184c9deab22c3/hero_1.jpg</featuredImage></item><item><title><![CDATA[IPsec VPN with Public IP Subnet’s on a FortiGate]]></title><description><![CDATA[IPsec VPN with Public IP Subnet’s on a FortiGate]]></description><link>https://samperrin.com/posts/ipsec-vpn-with-public-ip-subnet’s-on-a-fortigate/</link><guid isPermaLink="false">https://samperrin.com/posts/ipsec-vpn-with-public-ip-subnet’s-on-a-fortigate/</guid><category><![CDATA[development]]></category><pubDate>Tue, 23 Jun 2015 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;I recently came across a requirement where I had to create a site-to-site IPsec VPN, this is usually not an issue, set your Phase 1 and Phase 2 settings, apply your policies and you are good to go, but the difference this time was those local and remote subnets were Public IP addresses.\
The Public IP address our side was also being used as a VIP&lt;/p&gt;&lt;p&gt;Below I will document the steps in getting this working – the issue I had was where I put my policies, and not enabling NAT on the outgoing policy!&lt;/p&gt;&lt;h3 id=&quot;create-your-ipsec-tunnel&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#create-your-ipsec-tunnel&quot; aria-label=&quot;create your ipsec tunnel permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Create your IPsec tunnel;&lt;/h3&gt;&lt;p&gt;&lt;em&gt;FortiGate GUI &amp;gt; VPN &amp;gt; IPsec &amp;gt; Tunnels &amp;gt; Create New&lt;/em&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Set your name and chose your template. I used “Custom VPN Tunnel (No Template)”&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Fill in your Phase1 settings&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Fill in your Phase2 settings;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Local Subnet – this will be your Public IP/Range&lt;/li&gt;&lt;li&gt;Remote Subnet – this will be their Public IP/Range&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Press OK to create the tunnel&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 id=&quot;add-in-your-new-route&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#add-in-your-new-route&quot; aria-label=&quot;add in your new route permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Add in your new route;&lt;/h3&gt;&lt;p&gt;&lt;em&gt;FortiGate GUI &amp;gt; Router &amp;gt; Static Routes &amp;gt; Create New&lt;/em&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Destination IP/Mask – this will be the Remote Subnet you entered for your Phase2&lt;/li&gt;&lt;li&gt;Device – this will be the tunnel you have just created&lt;/li&gt;&lt;li&gt;Change any of the other settings if you need to&lt;/li&gt;&lt;li&gt;OK to add the new route&lt;/li&gt;&lt;/ul&gt;&lt;h3 id=&quot;create-an-ip-pool&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#create-an-ip-pool&quot; aria-label=&quot;create an ip pool permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Create an IP Pool;&lt;/h3&gt;&lt;p&gt;&lt;em&gt;FortiGate GUI &amp;gt; Policy &amp;amp; Objects &amp;gt; Objects &amp;gt; IP Pools &amp;gt; Create New&lt;/em&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Add a name and comments if required, and set the type (I am using Overload)&lt;/li&gt;&lt;li&gt;External IP Range = the range you set for Local Subnet&lt;/li&gt;&lt;li&gt;Ok to create the IP Pool&lt;/li&gt;&lt;/ul&gt;&lt;h3 id=&quot;create-your-policies&quot; style=&quot;position:relative&quot;&gt;&lt;a href=&quot;#create-your-policies&quot; aria-label=&quot;create your policies permalink&quot; class=&quot;heading-anchor before&quot;&gt;&lt;span&gt;#&lt;/span&gt;&lt;/a&gt;Create your policies;&lt;/h3&gt;&lt;p&gt;&lt;em&gt;FortiGate GUI &amp;gt; Policy &amp;amp; Objects &amp;gt; Policy &amp;gt; IPv4 &amp;gt; Create New&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;em&gt;Outgoing&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Incoming Interface = The internal interface where your server exists&lt;/li&gt;&lt;li&gt;Source Address = An object with the internal IP address of your server&lt;/li&gt;&lt;li&gt;Outgoing Interface = The tunnel you just made&lt;/li&gt;&lt;li&gt;Destination Address = An object with the remote Public IP range&lt;/li&gt;&lt;li&gt;Apply any Schedules and Service restrictions and Action = Accept&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;You now need to enable NAT, this is the bit I missed at first;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;NAT = On&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;Use Dynamic IP Pool = Select the pool you made in the previous step&lt;/li&gt;&lt;li&gt;Add any other settings and then OK to create your first policy&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;&lt;em&gt;Incoming&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Create the second policy for Tunnel to Internal&lt;/li&gt;&lt;li&gt;Incoming Interface = The tunnel you just made&lt;/li&gt;&lt;li&gt;Source Address = An object with the remote Public IP range&lt;/li&gt;&lt;li&gt;Outgoing Interface = The internal interface where your server exists&lt;/li&gt;&lt;li&gt;Destination Address = The VIP that belongs to the internal server (same as the IP Pool address)&lt;/li&gt;&lt;li&gt;Apply any Schedules and Service restrictions and Action = Accept&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;On this policy you &lt;strong&gt;do not need&lt;/strong&gt; NAT&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;NAT = Off&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;Add any other settings and then OK to create your first policy&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Check to see if your Tunnel is Up and try sending some traffic down it\
&lt;em&gt;FortiGate GUI &amp;gt; VPN &amp;gt; Monitor &amp;gt; IPsec Monitor&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:650px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:67.6923076923077%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAOCAIAAACgpqunAAAACXBIWXMAAA7DAAAOwwHHb6hkAAABt0lEQVQoz5WRS27bMBRFufV2AwW6gXYFGbizoA1QoEGBIJMM3B+aWnIokRIl0yJF8vEfyIJdOe6kZ0AQIC553iWipCYVpjUJIeYFWo3FhhV/9qz1AH5J8HE/EmU71HcdJURpnc+RQ/fpI7+6MquV63sXgrPWzXgX+EiV2yHWtg2lrG0BYBk2SnJG+cBydt67JfZwTc4ZVfiJ1nX1hM0xnNK0Pv6Gb+tBG2nAO3em7ZyXeufCiGhNOsaahjrvl2HW8vfvzM/vg1ZiMl087F3sBRbQILwtrXPpwFF52ljTkmqr1JCSPU170garUw5ISpnOq5pvkX3x5XNxfc2rCkKwAPYEGLsbqPEC5Qvm8MjLt2+6V6/j3Z3L2QEcq/beGKMPv4PGvcg5hxnvY4jz0GBFWdaE7MEG718UNrlP4a+/Hh63RV1VtK63Zck5vxS5ZD5Bq+7hB9mAMgBgtNJKSSljTCn5lFQIau7vn6BsQ89YXeEa4wpjIQYpx5zTZgMfVvLmZr9eh5xjCPEvIWkrXFCoYS1jLWuZEGIp1TTp9jbd36eyjC/DMYFTLmhUlkXTUEIIwRXf8fw/PANmmiQVz4KC7gAAAABJRU5ErkJggg==&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;outgoing&quot; title=&quot;outgoing&quot; src=&quot;/static/6254c54d3d74f1fd1bb175f63ba13c84/663f3/outgoing.png&quot; srcSet=&quot;/static/6254c54d3d74f1fd1bb175f63ba13c84/663f3/outgoing.png 650w&quot; sizes=&quot;(max-width: 650px) 100vw, 650px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:643px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:60.186625194401245%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAMCAIAAADtbgqsAAAACXBIWXMAAA7DAAAOwwHHb6hkAAABdElEQVQoz42QS24VMRBFe5dZBGwhW8gsg6wggl3ACCEmCJg9yENxf/zr9rO7y64qf1DyRNIIkHIGNTu6dW9ntZbTOPb9bOf2SK0PN+dyewt9j0SASDuQOft1mbefnT85LeXY98TcfvOo08cP8v07551C5D05lw28j6rDlIxWRuvZWkR88ktpzhqtBx9Cycy8DycAqLV2xuhB9KMQSqpcynN4rVrqQUxuCdtG3mNKeIaIw+pOceqMVuMwGKOtsW1PZacOdz/kzQ1dXfH1NS0L5UyIxJzD5hwMnVHKGNP+ohQO7liKjgDWsnP0NBsTbxASr11KiYjOf+5+bq3Fr5++vH4V3r4Jre07P6y9OBui6XLOe20n47fPx4sLvrxkACR67oyI67qWUjqtVPCemCNAghgjnGertQKGNcycqZRa/oSZH9aW0/T9cDge7+Qk5Tj1QqSE7WV0McZ7cT/P82lxmXP7V4H/ygAghNBaT8Mohwm2rb2YX5mBsMg1LEJqAAAAAElFTkSuQmCC&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;incoming&quot; title=&quot;incoming&quot; src=&quot;/static/ca1749554e8e2711dd57bae2ca05e3ac/45cbc/incoming.png&quot; srcSet=&quot;/static/ca1749554e8e2711dd57bae2ca05e3ac/45cbc/incoming.png 643w&quot; sizes=&quot;(max-width: 643px) 100vw, 643px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;&lt;/p&gt;</content:encoded><tags>development</tags><featuredImage>https://samperrin.com/static/4baf0f5e471c12bb261184c9deab22c3/hero_1.jpg</featuredImage></item><item><title><![CDATA[Disable SSLv3 on FortiGate GUI and SSL VPN]]></title><description><![CDATA[Disable SSLv3 on FortiGate GUI and SSL VPN]]></description><link>https://samperrin.com/posts/disable-sslv3-on-fortigate-gui-and-ssl-vpn/</link><guid isPermaLink="false">https://samperrin.com/posts/disable-sslv3-on-fortigate-gui-and-ssl-vpn/</guid><category><![CDATA[development]]></category><pubDate>Tue, 09 Jun 2015 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;To disable SSLv3 on both the FortiGate GUI and SSL VPN you need to run the below commands via CLI. According to the &lt;a href=&quot;http://www.fortiguard.com/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;FortiGuard&lt;/a&gt; website, the only reported compatibility issue that may follow with running the below is with IE6&lt;/p&gt;&lt;p&gt;For the HTTPS GUI:&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;text&quot;&gt;&lt;pre class=&quot;language-text&quot;&gt;&lt;code class=&quot;language-text&quot;&gt;config system global
set strong-crypto enable
end&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;For SSL VPN:&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;text&quot;&gt;&lt;pre class=&quot;language-text&quot;&gt;&lt;code class=&quot;language-text&quot;&gt;config vpn ssl settings
set sslv3 disable
end&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;</content:encoded><tags>development</tags><featuredImage>https://samperrin.com/static/4baf0f5e471c12bb261184c9deab22c3/hero_1.jpg</featuredImage></item><item><title><![CDATA[Set Port Speed for a FortiGate Virtual Switch Interface]]></title><description><![CDATA[FortiGate set a specific port within switch to a different speed]]></description><link>https://samperrin.com/posts/set-port-speed-for-a-fortigate-virtual-switch-interface/</link><guid isPermaLink="false">https://samperrin.com/posts/set-port-speed-for-a-fortigate-virtual-switch-interface/</guid><category><![CDATA[other]]></category><pubDate>Tue, 31 Mar 2015 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;You might come across a scenario where you have created a Virtual Switch/Hardware Switch on your FortiGate and you need to set a specific port within that switch to a different speed&lt;/p&gt;&lt;p&gt;In our case we had a 4 port switch, 1 of those ports connected to another appliance, the other device was set as 100mb Full – by default all of the ports on the FortiGate virtual-switch were set to auto, so this 1 port ultimately fell down to 100mb Half&lt;/p&gt;&lt;p&gt;Below are the steps to set a port to the correct speed within a FortiGate switch&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;text&quot;&gt;&lt;pre class=&quot;language-text&quot;&gt;&lt;code class=&quot;language-text&quot;&gt;config system virtual-switch
edit &amp;lt;switch name&amp;gt;
config port
edit &amp;lt;port&amp;gt;
set speed &amp;lt;speed&amp;gt;
end
end&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;strong&gt;Speed options:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;auto&lt;/li&gt;&lt;li&gt;10full&lt;/li&gt;&lt;li&gt;10half&lt;/li&gt;&lt;li&gt;100full&lt;/li&gt;&lt;li&gt;100half&lt;/li&gt;&lt;li&gt;1000full&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;The steps needed to set an interface speed for a port that is&lt;strong&gt;not&lt;/strong&gt;in a virtual-switch are slightly different, for that you use:&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;text&quot;&gt;&lt;pre class=&quot;language-text&quot;&gt;&lt;code class=&quot;language-text&quot;&gt;config system interface
edit &amp;lt;port&amp;gt;
set speed &amp;lt;speed&amp;gt;
end
end&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;You can use the&lt;em&gt;show&lt;/em&gt;command to show available ports/switches that you can edit&lt;/p&gt;&lt;p&gt;Within the FortiGate web console under Network &amp;gt; Interfaces, if you hover over the Interface image you can see the speed of a port&lt;/p&gt;&lt;p&gt;&lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:443px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:22.347629796839726%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAECAIAAAABPYjBAAAACXBIWXMAAA7CAAAOwgEVKEqAAAAA2UlEQVQI1yXC207CMBgA4L2wL+MD8A4aoxfcEEzAbGX9W3eQSg8wlnZdD+gMXi01kS9fhgCOGOfb7Wq9VsfT9fo7xe8YotNWSSWkvD1wwYXYM3bu+2EcB2t7Y7IPxlx/FoJzIX+mafzyz+R105aL/LEgZVs3lFJCAAAYYwVC3vsQwmCMv1wyoVRKaZ7nlJL3HhH8hFZFDXcv9w+bJd0BQmj3j3NeVZW1NsbonXMhZA1jo3Naa2PMqevatsGo5PtPXNHynVBalYCBAAZcN81bnh84l0pJpTqt/wCU3c2/BzBJggAAAABJRU5ErkJggg==&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;2015 03 31 14 46 50 fortigate cc dc01 fgt200d 01&quot; title=&quot;2015 03 31 14 46 50 fortigate cc dc01 fgt200d 01&quot; src=&quot;/static/eed5cc48e2c765cac9ca4328a3aa5155/4d697/2015-03-31-14_46_50-fortigate-cc-dc01-fgt200d-01.png&quot; srcSet=&quot;/static/eed5cc48e2c765cac9ca4328a3aa5155/4d697/2015-03-31-14_46_50-fortigate-cc-dc01-fgt200d-01.png 443w&quot; sizes=&quot;(max-width: 443px) 100vw, 443px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:441px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:22.22222222222222%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAECAIAAAABPYjBAAAACXBIWXMAAA7CAAAOwgEVKEqAAAAA5UlEQVQI1xXN206DMAAA0P3/p/hgUCHLFqMGwlYuBgFFAQdjo5dBse0QEoFRsw84OYtdnqdgYwGw3QLaNJfp0p3bvvsrMj/b3TOmC2FyYTBuTJM7ju44AsZS2gh2FouKUooxRBBj0v/2Mc5V7/nBN1Tntojv9oXGfl6a5klwve/MYbCldGj9AcvTFfO2lVLO8yylhGVpupb+Zj96lmLfULQk1TrPFHjUTnBZk9UwWlLanMd1xZjgi5IQiK4vRGh/OERRFHj+d5qHIQhCNU7WwbvqeIofap9fK4Q3bf9aHMMkyQit/wFfHtDR8XGR5gAAAABJRU5ErkJggg==&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;2015 03 31 14 48 38 fortigate cc dc01 fgt200d 01&quot; title=&quot;2015 03 31 14 48 38 fortigate cc dc01 fgt200d 01&quot; src=&quot;/static/9f15dcc3d034aed2da26471dc5a5e17d/7cad8/2015-03-31-14_48_38-fortigate-cc-dc01-fgt200d-01.png&quot; srcSet=&quot;/static/9f15dcc3d034aed2da26471dc5a5e17d/7cad8/2015-03-31-14_48_38-fortigate-cc-dc01-fgt200d-01.png 441w&quot; sizes=&quot;(max-width: 441px) 100vw, 441px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;&lt;/p&gt;</content:encoded><tags>other</tags><featuredImage>https://samperrin.com/static/4baf0f5e471c12bb261184c9deab22c3/hero_1.jpg</featuredImage></item><item><title><![CDATA[Upgrading Dell PowerEdge R710 BIOS]]></title><description><![CDATA[A quick How-To on upgrading the Dell PowerEdge R710 BIOS using a USB drive]]></description><link>https://samperrin.com/posts/upgrading-dell-poweredge-r710-bios/</link><guid isPermaLink="false">https://samperrin.com/posts/upgrading-dell-poweredge-r710-bios/</guid><category><![CDATA[vmware]]></category><pubDate>Mon, 23 Feb 2015 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;You will need to download the required BIOS from the Dell website, in ‘Non-Packaged’ File Format. I also used Rufus to create a bootable USB drive&lt;/p&gt;&lt;p&gt;&lt;em&gt;R710 BIOS 6.4.0 – R710-060400C.exe&lt;/em&gt;\
&lt;a href=&quot;https://www.dell.com/support/home/us/en/19/Drivers/DriversDetails?driverid=4HKX2&quot; title=&quot;Dell Server BIOS R710 Version 6.4.0&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;http://www.dell.com/support/home/us/en/19/Drivers/DriversDetails?driverid=4HKX2&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;Rufus 1.4.12&lt;/em&gt;\
&lt;a href=&quot;https://rufus.akeo.ie/downloads/rufus-1.4.12.exe&quot; title=&quot;Rufus 1.4.12&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;http://rufus.akeo.ie/downloads/rufus-1.4.12.exe&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Once you have got the above we can begin to create our Bootable USB&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Plug in your USB drive and open Rufus.exe&lt;/li&gt;&lt;li&gt;From the Device drop down select your USB drive&lt;/li&gt;&lt;li&gt;Leave the other large drop downs as default&lt;/li&gt;&lt;li&gt;Label the USB drive if required&lt;/li&gt;&lt;li&gt;Check the 2nd, 3rd and 4th check boxes&lt;/li&gt;&lt;li&gt;Ensure FreeDOS is selected from the smaller drop down&lt;/li&gt;&lt;li&gt;Press Start&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:326px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:151.53374233128832%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAeCAIAAACjcKk8AAAACXBIWXMAAA7DAAAOwwHHb6hkAAAEkUlEQVQ4y31VW28cNRjNb0RCiFataJB445kfwFMlIKJCfWgTkBAIRB+oCoVCgRayyXZ3LrueGc99PPcZz9X2zuwmbZMGeWcTVYj06Njy2Dr6rvZs+Y8/mN1/vx29Rw62vV+vze694/x8FT26pt2/Yj64qv74bvXPDXKw3exvx4+vl6Mb6Psr8vZbwvW3rZsfbsX7HxXz2wx+QdRbWN4Jxp8m089yaScVdnJxJxV3GuVWq55Tu9XMP0//+iT87WYj3N6qtK+irIXQLiq6Oj7pV89XRy+75XPWHS16TrpYXZCw5fLoVNfkB6Nny1rfKpRd5EfjwwMwn1umiTwXaqrnOmWBMc4LnBcFZ8mJywJXZRGFAbQ9lopc7AeJJMmiIM5mMw3C8XisaXpRFFmW5Xl+Madpmq2RZ2mcYJpJW6W6FyWlDjXLdpDn6bqBUOB5LgDAth0IoWmapmEkaX58fLxcLheLBaOkWz7fiC0nHO2PJFGcTKYKANPJVBQlTkEURQkAIAiCoqiqqiiKmiQpxrkfZhuxhxJJkviRolimoakahNAyLU2Dum6Ypgl1DgDmAIA4jvMsjQa3K+1LP8hsi3sXRvHx8XHf98tlz+fN2GC5xmLBGKP96sXasrJre5EoCuODg4ODQw3qGOPsEuRD8tIE+QkXF8puGGOoQwi5dwj5vEQYF5cD4zzJqk3McZLL0sxzHM9Dq9Wq7/uu69ibQLvli41lhKJn4/HheCxL4lQQR/v7k6mQcgf/H1maeBduRzG2THOdUV1VVV03giDAb3Q7w82Q7T3bi8Fcmc1mc6DO5JkfRKvV0dq9xSVkrDvm4nx+p26Z67qu41LGzs7Ozl69enV6enKOl//hy5PT05Pl0QlJ1r2dF61hGI7rWrat64YbxhEuKeFoCWnallLKGGtJ27Zt3TR1XTWkX8cM7pY1s0xTAYqmQTADpuO6QZjzm5ANkQd+4HneusZ50zSMEsKWXIzB3bpdBL4vSZICeAtDTYNQn8ky71kNBkEoTKaj/ZFtO57nVVXFGN2IS2UvzStJEABQDNNUFC0Io6HaQ3dSQrqu6/ueUkIpj4aPQbyOudFUdT4HsjzXdV2WJEGUJVHWVA0AxfPQ5Nnk6ZOnUDc8z0XIl2WQ4YblMhdnuAbzma7rEOqO46iKur6AqmHwi2XbtiiICPlVVRVFUZZlGAZ1220slxXxkY8QchwHIWRZNi+c47guQsgPw9DzPIyLi57tuwV/0oaEEdoT0lJKGKNDVYZ5/UUJj5TyIp2jqsqNZQzu4qKJ4yh5DfEaSXLOOE6TJE2HwzSOowzX55bZcm156AsObpnSmrCasIYuhkXbbg4JaVs6ZBvsFhWZPBs/efK3ZVlFUUBNm05FSoidMdWOfvp9X0epk5IoxZ5r//H4T9t2cNHy9sTgDmV905RNU7dt3ZKmLPm1IW2NqzorqhSXeVHhqqnKsirw8IZXNaGpsIXBnh+WHgoQil0/CcKMdUes4z8K1q0Wr3HYHPZZf0qz+VY4+tia/gAPvzbG38Dxt9bkO2z9chlz82FuPuQL61Fl3PsXUGYcrpYhX2sAAAAASUVORK5CYII=&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;Rufus Settings&quot; title=&quot;Rufus Settings&quot; src=&quot;/static/4c2f61b1677d2b377ee989eadfe414bd/15a61/rufus-settings.png&quot; srcSet=&quot;/static/4c2f61b1677d2b377ee989eadfe414bd/15a61/rufus-settings.png 326w&quot; sizes=&quot;(max-width: 326px) 100vw, 326px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;Rufus Settings&lt;/figcaption&gt;
  &lt;/figure&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Running the Update&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Your new bootable drive will show within Windows Explorer, open it and copy your BIOS .exe download to the root of the drive.\
Rename the .exe to something simpler, such as R710.exe (this will help later).&lt;/p&gt;&lt;p&gt;Insert the USB in to the server and boot, when prompted press&lt;strong&gt;F11&lt;/strong&gt;to Enter Boot Menu.\
Use the arrow keys to highlight ‘Hard Drive C:’, on the sub-menu select your USB device and press enter.&lt;/p&gt;&lt;p&gt;When at the command prompt type in&lt;strong&gt;R710.exe&lt;/strong&gt;(if you did not rename the file in the earlier steps you will need to use the original name at this point). You will be entered in to the BIOS updater screen. Follow the steps until completion&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Forcing a BIOS Update&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;If you wish to re-flash your BIOS with the same version as already installed, or if you need to replace an OEM BIOS you might need to use&lt;strong&gt;&lt;em&gt;/forcetype&lt;/em&gt;&lt;/strong&gt;in order to force a BIOS update.&lt;/p&gt;&lt;p&gt;E.g. – `R710.exe /forcetype`&lt;/p&gt;</content:encoded><tags>vmware</tags><featuredImage>https://samperrin.com/static/4baf0f5e471c12bb261184c9deab22c3/hero_1.jpg</featuredImage></item><item><title><![CDATA[EqualLogic PS4100 and ESXi 5.5 VMkernel Setup]]></title><description><![CDATA[iSCSI VMkernel setup for EqualLogic MEM on ESXi 5.5 U2]]></description><link>https://samperrin.com/posts/equallogic-ps4100-and-esxi-5-5-vmkernel-setup/</link><guid isPermaLink="false">https://samperrin.com/posts/equallogic-ps4100-and-esxi-5-5-vmkernel-setup/</guid><category><![CDATA[vmware]]></category><pubDate>Wed, 12 Nov 2014 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Read the first blog post &lt;a href=&quot;/posts/dell-mem-v1-2-and-esxi-5-5-u2/&quot; title=&quot;Dell MEM v1.2 and ESXi 5.5 U2&quot;&gt;here&lt;/a&gt; about Dell MEM and ESXi 5.5&lt;/p&gt;&lt;p&gt;As part of the EqualLogic MEM setup.pl script it creates a new vSwitch and also its iSCSI VMkernel’s, but due to that script not currently being compatible with ESXi 5.5 U2 we had to manually create the connections. Below is the setup we have used and a few differences compared to the Dell EqualLogic best practice document.&lt;/p&gt;&lt;p&gt;In the document it states that the heartbeat connection is no longer required for ESXi servers of version 5.1 or above. I had issues with this and found that if a switch that one of the adapters connected to failed, the pings would stop to the storage device and ESXi would report that all paths were down for the EqualLogic array, and therefore lose access to the datastore. I added a heartbeat connection in and was able to keep a path active when an adapter failed. Below will cover the settings I have in place and the tests I did to determine successful failover in various scenarios&lt;/p&gt;&lt;p&gt;&lt;code class=&quot;language-text&quot;&gt;The Storage Heartbeat VMkernel port is no longer required for ESX servers running version 5.1 and greater&lt;/code&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;vSwitch Setup&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Create a new Standard VMkernel vSwitch on your host and assign two or more network adapters to it (these are obviously the adapters that connect to your storage network where the EqualLogic sits)&lt;/li&gt;&lt;li&gt;Name the adapter “EQL Heartbeat”&lt;/li&gt;&lt;li&gt;Assign an IP to the EQL Heartbeat VMkernel port&lt;/li&gt;&lt;li&gt;Finish the setup screen&lt;/li&gt;&lt;li&gt;Find the vSwitch in the Networking window and select Properties&lt;/li&gt;&lt;li&gt;Add a new VMkernel port to the vSwitch; press Add, select VMkernel, label it EQL_1&lt;/li&gt;&lt;li&gt;Assign an IP address (same subnet as your heartbeat port), finish the setup&lt;/li&gt;&lt;li&gt;Repeat the process again and label the new VMkernel EQL_2, again this needs to be in the same subnet as the other two VMkernel ports&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Once you have done that you should have something that looks similar to this;&lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:356px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:38.48314606741573%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAICAIAAAB2/0i6AAAACXBIWXMAABYlAAAWJQFJUiTwAAABMklEQVQY03WP2U7DMBBF8//fAm/8AV0gDQ1V7DpN7LZem6V0ARJQ4wWSEgpCnJcZaXR053oQQCHk7HGWJAuEYt+fQAAZ5689L/9wPB69GMVRBMIwnE5DAEAURQCAOI7RHEEIEUL4D2lHnufecHQ7GA6CSTAe32FMsixTSkkp/Xt/PBpNgoAxppQSP6AdZVl6QRRlRZFt1HrNTk3jnLPWOue2ZcmFzPJCa22Mce58sa6nqirv5kGQzU4yut8fjLHfcp7lGBPOBGMcp3i1ou27mFR1fZGv/AWUSlG6fdo12lhrejnDeCmF5EKkSUopb9viZV2/XeRrfzGXiq8pZZxgQgip6nfnXFkWhKykaNumScoY74JXv+T980Fb3Raz3dD6nGyM0V8YY6xu9Klp2q2v/Sl/AJ6ltN+2nDU4AAAAAElFTkSuQmCC&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;vSwitch Layout&quot; title=&quot;vSwitch Layout&quot; src=&quot;/static/51c0156d41a8bf1ce33599b80853ff38/323b2/vswitch1.png&quot; srcSet=&quot;/static/51c0156d41a8bf1ce33599b80853ff38/323b2/vswitch1.png 356w&quot; sizes=&quot;(max-width: 356px) 100vw, 356px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;vSwitch Layout&lt;/figcaption&gt;
  &lt;/figure&gt;&lt;/p&gt;&lt;p&gt;We need to make a few more changes to this vSwitch;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Edit each of the items in the screen shot to have an MTU of 9000 (your switch must also support this!)&lt;/li&gt;&lt;li&gt;Edit vSwitch &amp;gt; NIC teaming tab, all adapters should be active&lt;/li&gt;&lt;li&gt;Edit EQL Heartbeat &amp;gt; NIC teaming tab, all adapters should be active (will most likely be grayed out as inherits settings from vSwitch)&lt;/li&gt;&lt;li&gt;Edit EQL_1 &amp;gt; NIC teaming tab, under Failover Order tick Override switch failover adapter, keep one in Active and move the other to unused&lt;/li&gt;&lt;li&gt;Edit EQL_2 &amp;gt; NIC teaming tab, under Failover Order tick Override switch failover adapter, keep one in Active and move the other to unused – this needs to be different to the one used in EQL_1&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:536px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:124.25373134328359%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAZCAIAAAC+dZmEAAAACXBIWXMAABYlAAAWJQFJUiTwAAADaUlEQVQ4y42UW2/jRBSA8ysRy7ZP/AqE+CEIXnnZXSou6m4DhW5L01vcJK1jO7E9npsdz4ztGY/tkEJuyHZZtXRZ+HQ0Gtn6dMbH50zn0x+/2j344Xn34Hn3ze7PB010dw72n+29/OT7vY+/ffFs7+VO9/XOT2/a2O2+/ujo8Iuvv/zm8886L8zBOQDHwD8B/rHvHnvese+deO6vjv12Onnr2Ee2dex5PQjPEGqjh1Af4++scaePMAsgAQBOptjzY4xjTBgh2AcxpSljM0zS2eyPqlzO539W82atNovFKKSdS4xnhIxt27admPGyKvM8V0pJpeI4DqOaMIwwxghjQgjGGFMaR9GpO63lCKLRze3YHOPmdZIkWus0TQEATgNo8DwfQugDEECIQdBr5RAh25nYtg0hopQmSZrneZZlCMEgAAih2WwmGjjnQgjGGIGwkQmmQTC2LM6FlLIoiubUKssyAAClVAgRx/Gsod1EsxkGoJYvMEriGBPKGNNaF3/TJpdSKqXyx0ilMs57rlvLgeteXw+MvuE4znQydacupWFTNpmlmZIqTdPsHpmmiVSqVOrMcztXlASua1wPTHM8HIyGg6HRN4y+MRwMLctCCEVRBFuCACHk+76UqszzOvMlxp7tXF0ZbWEH14PRaOQ4jmma/b7h2HYQvHMDznmSJozzhLFzz+tcYDyxb4c3A8uyaRhmWZam2XK5vLu7E0Ioqe4eoLWOoohQyqLo3Pc6l5hMJ0PTGXiez4UoiqIsqk1DVc3X6/X2AVVVNV0TJXHcynhimWeXvd5Z78owiqJcN2w2m/XmEdvtdj6f18XXupDyrK42wgjZLKWlrlbrdVVVUqrNdrvZrPNcr1arh5nv5TzXUtbVPgX+77pYLlftVy0Wi3ZdNLvFA1arVVVVj+RzhHgUOpOJ4zie78N/R4i6Bev//06+QEgKjjGGEMZx3PaWfh/1qD2VU8YIDYui0FrnH+SJjDEPw+HohnPxX+57ZCSiyAegHYMP0Db3P+V5k1H+P9pL5l7uAZByHjWz+hTGmEgSkSS8uQm4EPUjzlPOf5tOOwbBq7Is83yu9dPIOCdBgEHAwjCJYxaGhZQJY4qxIYKdV441DOklwVdPok/JiTvdN4x9wzgcm4em2R2NTn3vl/H4yDRfmbd/Aem0L9TmEHnKAAAAAElFTkSuQmCC&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;EQL_1 Properties&quot; title=&quot;EQL_1 Properties&quot; src=&quot;/static/b51c2ec6cb795885ae82b70f077fb2ff/e52bb/eql_1.png&quot; srcSet=&quot;/static/b51c2ec6cb795885ae82b70f077fb2ff/e52bb/eql_1.png 536w&quot; sizes=&quot;(max-width: 536px) 100vw, 536px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;EQL_1 Properties&lt;/figcaption&gt;
  &lt;/figure&gt;&lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:537px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:123.83612662942272%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAZCAIAAAC+dZmEAAAACXBIWXMAABYlAAAWJQFJUiTwAAADhklEQVQ4y5WU6W7bRhCA9ZBNAOsB+gAF2qfpj6Io0DZ1kQaoLxmpA9uxZUuUqIM6yL3JXXJ5Li/JsSSrIFUHrtPzw2AxIPjtLGaHbHz+69fN4zfN1nGzddQ8PW6eHjVbR3vHBy9//vHl6/0XP/3wYv/V3tHBXuto7+Rw7+SweXzw2dvWF99+891XXzb2R/0+ITcY32J0g1AbwjqB1+a8Day2aV7NZm0ANcZ6tr0LzbYHjvMbBI1LYAmECIBgNkcWYAgJ27YJwRbgjPmuaxPqOnyRZcuiWOb5Mi8WeX5fFJYQjQuEpGPrg9FoNBZC5EWplEpUEieJ67qO4wghHM4psymljDFahydED4DGBYKCMn0wNIwJxhgjLKWfpmkYhhij6XQ6nc0AAAghYNUrhJgQRkglX2LkMjadzieTKWNMCBEEgVIqiiJCCEKIUMI592uklL7vu55nU9qvZcwJ0YcjKWUUx1maJjVRFCGEGGNSStd1xRO4EI+VEYqlR5ntum6apnlFlmVZmqZxHCdJopRKH9nlu711CCuZWFan0+1pvfF4bBiT2XRGCI3jOIyiIAziKK6PHFSEofT9OI6LLKvkK4IZBLedzmAw6Ot6t9vtdrTObUfTesPhiBDCeXWVhFCEMaEUIRSEUZnnf1TGpqVpPdM0Lcvq6/3hcGia5mQy0TRtbBgQQlKBEUJVX8KwWoOgatgFhNZsrOndiWFATJIkCYLg/v7+w91dEPhJou6ekOc559xxHN/zesBqXEAErZE+6UIAmW1nVcOKzWaz3W7Lslyv19snlGXJOedChL5fHbuqPDXOr86v3l9et9uxUpuah4eH9Wq9S3Zst9vFYpHUF1CkqY5g4xxAblsy4R/uVru9lUo3m+rVLMtWq9XTysvlcifnaVpVPpvPSpXer9bL5XJR8zF5xmq1KsvyT/I5BIHgk+nUMCamaVJKyd/g1zdcfzaP8gWEKgwYs+vBdndj9JfsZva5HEsfU/pxAP+BT2QEQ9fVen1Pyv8tn0MQui6AKAyj+N94KvdhNWFgkWWJUvF/I0mqn0yu1ACjxpk5j33fEcL1vE/Dk9IPAj8IpO97smL3PPT9HoSNawQ3RVEotUjTZ7HMsjQMKYAMIs+2Y89zmZ1FcSRlyIXFeeP70bBjs/cEX1HyLK4ZfWeZr29ufrm9PRzorfHooN8/M+enhnEyGLwxxr8Du/Ewo7IyGhkAAAAASUVORK5CYII=&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;EQL_2 Properties&quot; title=&quot;EQL_2 Properties&quot; src=&quot;/static/37ce090fd37a26025b16943df9b87d01/673a2/eql_2.png&quot; srcSet=&quot;/static/37ce090fd37a26025b16943df9b87d01/673a2/eql_2.png 537w&quot; sizes=&quot;(max-width: 537px) 100vw, 537px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;EQL_2 Properties&lt;/figcaption&gt;
  &lt;/figure&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;iSCSI Software Adapter&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;If you don’t yet have an iSCSI software adapter now is the time to add one in, once you have done that select it and press Properties. Under Network Configuration and press Add, select the two adapters you just configured (EQL_1 and EQL_2).&lt;/p&gt;&lt;p&gt;While you are here also add in your EqualLogic’s group IP address in to the Dynamic Discovery tab&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Setup VMware Round Robin&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;The next steps I have documented in the post &lt;a href=&quot;/posts/dell-mem-v1-2-and-esxi-5-5-u2/&quot; title=&quot;Dell MEM v1.2 and ESXi 5.5 U2&quot;&gt;Dell MEM v1.2 and ESXi 5.5 U2&lt;/a&gt;, so I wont cover them again here. These steps setup cover the remaining recommendations from Dell.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Testing Failover&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;To confirm the above settings I did the followings tests to confirm failover – during these tests you should not have all paths down.\
These tests make the assumption that you have at least two switches, two network adapters and two controllers in your EqualLogic, and that you return to default before running the next test.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Remove a network cable from the host (which connects to the storage network)&lt;/li&gt;&lt;li&gt;Remove the other network cable&lt;/li&gt;&lt;li&gt;Power off 1 switch&lt;/li&gt;&lt;li&gt;Power off other switch&lt;/li&gt;&lt;li&gt;Disconnect controller&lt;/li&gt;&lt;li&gt;Disconnect other controller&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;If you do encounter an APD scenario double-check your cabling, as per this diagram from Dell, a long with the heartbeat adapter the cabling also caused a problem. This was resolved with the help of this diagram.&lt;/p&gt;&lt;p&gt;&lt;figure class=&quot;gatsby-resp-image-figure&quot;&gt;
    &lt;span class=&quot;gatsby-resp-image-wrapper&quot; style=&quot;position:relative;display:block;margin-left:auto;margin-right:auto;max-width:767px&quot;&gt;
      &lt;span class=&quot;gatsby-resp-image-background-image&quot; style=&quot;padding-bottom:102.34680573663624%;position:relative;bottom:0;left:0;background-image:url(&amp;#x27;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAUCAIAAAAC64paAAAACXBIWXMAABYlAAAWJQFJUiTwAAAEUklEQVQ4y3WSeVMaBxjG98vlE7RfoNPGeCu3IbEmIoc2wSON0TThDERIgF2WFRYRBITdBZHlWAJegNE4BbxYYOXa7djMtNM/+szvr3feZ56Z93mBs7NzMpNLJMkkmSLJdCZLHR6d7KeyWSqXSWdJMl04ODw8PIJdmyAIgaDT4/E6QMgBQskkCdRqtSget9lBBHHDMOJxe2LxBIygIAhBTthmd2z7d/KFg7k5hWRKurzyamX5lUgkmV/4LZHYByrVqnpxeVYml8nkcoVq4eWKav7F+ARvdIL/8JdHAz8P8PlCIhiY5Y0PjE5q196on4h/eji4tLRSLBaBq6trFEVRjxvc2bbvRNxhygGhsM0K+nYxb8hrdeUSib0kaTSaNBqdRqO1Wj9pdQaNRlcslgCO465a3ejXeqh0c0/xOly+xc8am/nal+wJhWe4Tvuu272sXVYq1Vrt8uLi4uvXs6Pj49vb+r2Zuqh7C9Xzm+ZJrVG8bBRrdLHWKNfoE+roTzLbpek+x/X6/V6vx7IswzB0o0HTdLfbvTcXqs3EOc1xXJ/l/hXb56rV9sFRv8Vw/yOg32ZCuVNLKJMgiCgWw/AYhhMYHsOjxD7qS0KuWDhCJJJEKheMkb5AKBqJ4HgMw7Crq2ug8u18Qftp5PkCXzDBk4h4YsGkkM8TCcZ5EyqReFkkFo0NC5/JJ2Vq3ox8dHZpTCB5NDgy80xWLp8CnX4vjcc9q+tBnSGo1Qc19wQ0+sAf7+MbVtIB7u2GfbGUNxLfw6PhfcruJ4wGUzKVbrUY4I5lK7F4QW8inEjc4YyDzpgDTjmRtBNJb6JpdPuYyhFkPp7Klwr5VLYQTOa3ff4slWu1WsBZpWJVLynHRkfFQoFYNCEWyEXCN1LpvFCgFosXpyQv+ZOLzxRzUzPq8TGlZHp4Wjk8NDanUJVKZYC5u6MyGb/fHwqFw6GQP7wLmmwO0G1yeT86PWan5yPsNnqCSAjDtry70KZth9je8u4nU81mC/jv8VmG4xLJ4/o1fctx9X/4XmGzeXlUOm327/f+ngAsy3Is2//+A71evdPPkwWuwbSvqHrefFOw3x7a6weW5kW0V6cr+cPjmzuu1213uizbB9qdDt1otNtthmF6nTbDcV/SBe6Oa55++IY+KHt//Lb9w4XnAU3JuCZTLZyUG93vySzLAmckth/ZsUMug8FotVh2iYxN59rReuyvN/3LK44X6+Cqxbm2jJoR3BXIhwMmdBcGQb3BmMlkgZDPKxEJlcoFvkD09OlTm91nXrVaRJr3AxufhOYP4xuGKevb6TnNjG7r3ed3CrlAsfSr9MnQ8GgwGAIQNyqWPFYoVJOTfLFUihgd8NzaB5XRPGuwPF/XT6+ZlQaL6ne72gy/Nstli0LlyvRj6eDQCIp6ATKZcoCQy4VotXqDyRRBg34o6DDj9jcRxByDdQSkx5y2gNu6B8PYZ9QPuTwbGxtr628zGeovRx2DdAdLmzcAAAAASUVORK5CYII=&amp;#x27;);background-size:cover;display:block&quot;&gt;&lt;/span&gt;
  &lt;img class=&quot;gatsby-resp-image-image&quot; alt=&quot;PS4100 Cabling&quot; title=&quot;PS4100 Cabling&quot; src=&quot;/static/13d418a768d4d03de2b58c8a277c1f1a/dff2b/ps4100-cabling.png&quot; srcSet=&quot;/static/13d418a768d4d03de2b58c8a277c1f1a/dff2b/ps4100-cabling.png 767w&quot; sizes=&quot;(max-width: 767px) 100vw, 767px&quot; style=&quot;width:100%;height:100%;margin:0;vertical-align:middle;position:absolute;top:0;left:0&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot;/&gt;
    &lt;/span&gt;
    &lt;figcaption class=&quot;gatsby-resp-image-figcaption&quot;&gt;PS4100 Cabling&lt;/figcaption&gt;
  &lt;/figure&gt;&lt;/p&gt;</content:encoded><tags>vmware</tags><featuredImage>https://samperrin.com/static/4baf0f5e471c12bb261184c9deab22c3/hero_1.jpg</featuredImage></item><item><title><![CDATA[Dell MEM v1.2 and ESXi 5.5 U2]]></title><description><![CDATA[Install Dell MEM v1.2 on ESXi 5.5 U2 using esxcli]]></description><link>https://samperrin.com/posts/dell-mem-v1-2-and-esxi-5-5-u2/</link><guid isPermaLink="false">https://samperrin.com/posts/dell-mem-v1-2-and-esxi-5-5-u2/</guid><category><![CDATA[vmware]]></category><pubDate>Tue, 04 Nov 2014 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;It would seem that the Dell MEM v1.2 will not install on ESXi 5.5 U2 using esxcli. It can apparently be deployed using vMA or VUM but as these aren’t used we had to look for an alternative.&lt;/p&gt;&lt;p&gt;The issue was with Dell who pointed us towards the following best practice document;\
&lt;a href=&quot;http://en.community.dell.com/cfs-file/__key/telligent-evolution-components-attachments/13-4491-00-00-20-43-46-01/TR1091-Best-Practices-with-EqualLogic-and-VMware-1.1.pdf?forcedownload=true&quot; title=&quot;TR1091-Best-Practices-with-EqualLogic-and-VMware-1.1.pdf&quot; target=&quot;_blank&quot; rel=&quot;noreferrer&quot;&gt;http://en.community.dell.com/cfs-file/__key/telligent-evolution-components-attachments/13-4491-00-00-20-43-46-01/TR1091-Best-Practices-with-EqualLogic-and-VMware-1.1.pdf?forcedownload=true&lt;/a&gt;&lt;/p&gt;&lt;p&gt;In summary they recommend the following.\
– Use Round Robin\
– Change from 1000 IO’s per path to 3 IO’s per path\
– Change iSCSI Timeout values from default to 60 seconds\
– Disable Delayed ACK&lt;/p&gt;&lt;p&gt;Dell have provided some handy scripts to get you started, here they are for ESXi 5.x (they can all be found in the PDF attached earlier in the post so please refer to this for full details);&lt;/p&gt;&lt;p&gt;Set all EqualLogic volumes to Round Robin and set IOPS value to 3 – this must be run on all hosts;&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;text&quot;&gt;&lt;pre class=&quot;language-text&quot;&gt;&lt;code class=&quot;language-text&quot;&gt;esxcli storage nmp satp set --default-psp=VMW_PSP_RR --satp=VMW_SATP_EQL ; for i in `esxcli storage nmp device list | grep EQLOGIC|awk &amp;#x27;{print $7}&amp;#x27;|sed &amp;#x27;s/(//g&amp;#x27;|sed &amp;#x27;s/)//g&amp;#x27;` ; do esxcli storage nmp device set -d $i --psp=VMW_PSP_RR ; esxcli storage nmp psp roundrobin deviceconfig set -d $i -I 3 -t iops ; done&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Set a default so that new EQL volumes will inherit the correct settings;&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;text&quot;&gt;&lt;pre class=&quot;language-text&quot;&gt;&lt;code class=&quot;language-text&quot;&gt;esxcli storage nmp satp rule add -s &amp;quot;VMW_SATP_EQL&amp;quot; -V &amp;quot;EQLOGIC&amp;quot; -M &amp;quot;100E-00&amp;quot; -P &amp;quot;VMW_PSP_RR&amp;quot; -O &amp;quot;iops=3&amp;quot;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The above command will require a restart of the host before it becomes effective, once you have restarted you can verify the correct settings using the below;&lt;/p&gt;&lt;p&gt;&lt;code class=&quot;language-text&quot;&gt;esxcli storage nmp device list&lt;/code&gt;&lt;/p&gt;&lt;p&gt;The output will be similar to what is shown below, the parts in bold are what you are looking for;&lt;/p&gt;&lt;div class=&quot;gatsby-highlight&quot; data-language=&quot;text&quot;&gt;&lt;pre class=&quot;language-text&quot;&gt;&lt;code class=&quot;language-text&quot;&gt;naa.6090a098703e5059e3e2e483c401f002
Device Display Name: EQLOGIC iSCSI Disk
(naa.6090a098703e5059e3e2e483c401f002) 
Storage Array Type: VMW_SATP_EQL
Storage Array Type Device Config: SATP VMW_SATP_EQL does not support device configuration. 
Path Selection Policy: VMW_PSP_RR
Path Selection Policy Device Config: {policy=iops,iops=3,bytes=10485760,useANO=0;lastPathIndex=3: NumIOsPending=0,numBytesPending=0}&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;strong&gt;VMW_SATP_EQL&lt;/strong&gt; (indicates its an EqualLogic)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;VMW_PSP_RR&lt;/strong&gt; (path selection is set to Round Robin)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;policy=iops,iops=3&lt;/strong&gt; (shows IOPS have been set to 3)&lt;/p&gt;&lt;p&gt;Next up is to change the default iSCSI timeout values. “By default, the MEM configuration script will make an attempt to set each of these timeout values to 60 seconds which is the recommendation.”, so we will copy that with the below;&lt;/p&gt;&lt;p&gt;&lt;code class=&quot;language-text&quot;&gt;esxcli iscsi adapter param set --adapter=vmhba## --key=LoginTimeout --value=60&lt;/code&gt;&lt;/p&gt;&lt;p&gt;Replace ## with that of your iSCSI software adapter, for example vmhba33.&lt;/p&gt;&lt;p&gt;After you have done the above you will need to disable Delayed ACK, Dell don’t provide a command line for disabling this, so it needs to be done through the vCentre GUI – please refer to Page 10 in the PDF for steps on how to do this.&lt;/p&gt;&lt;p&gt;Dell do list a few other recommendations, around such things as LRO and SIOC but I have not applied these so I wont go in to detail on what they mention.&lt;/p&gt;&lt;p&gt;Hopefully this post will come in handy for a few people, as I know it held us back a bit!&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Please check the commands before you apply them and also work with your vendor if you are unsure of the implications of changes some of the settings listed above will have towards other storage arrays, etc. 🙂&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;I will soon be posting about the VMkernel/NIC setup for this, as we have had some issues relating to that too – events such as APD! I will update this post with a link to that once it is ready&lt;/p&gt;&lt;p&gt;UPDATE: Post relating to iSCSI setup is here! (to be updated)&lt;/p&gt;</content:encoded><tags>vmware</tags><featuredImage>https://samperrin.com/static/4baf0f5e471c12bb261184c9deab22c3/hero_1.jpg</featuredImage></item></channel></rss>