Support load-balanced runner groups for multitenant compute isolation (#814)

* Initial stab at the protocol

* initial protocol sketch for node pool manager

* Added http header frame as a message

* Force the use of WithAgent variants when creating a server

* adds grpc models for node pool manager plus go deps

* Naming things is really hard

* Merge (and optionally purge) details received by the NPM

* WIP: starting to add the runner-side functionality of the new data plane

* WIP: Basic startup of grpc server for pure runner. Needs proper certs.

* Go fmt

* Initial agent for LB nodes.

* Agent implementation for LB nodes.

* Pass keys and certs to LB node agent.

* Remove accidentally left reference to env var.

* Add env variables for certificate files

* stub out the capacity and group membership server channels

* implement server-side runner manager service

* removes unused variable

* fixes build error

* splits up GetCall and GetLBGroupId

* Change LB node agent to use TLS connection.

* Encode call model as JSON to send to runner node.

* Use hybrid client in LB node agent.

This should provide access to get app and route information for the call
from an API node.

* More error handling on the pure runner side

* Tentative fix for GetCall problem: set deadlines correctly when reserving slot

* Connect loop for LB agent to runner nodes.

* Extract runner connection function in LB agent.

* drops committed capacity counts

* Bugfix - end state tracker only in submit

* Do logs properly

* adds first pass of tracking capacity metrics in agent

* maked memory capacity metric uint64

* maked memory capacity metric uint64

* removes use of old capacity field

* adds remove capacity call

* merges overwritten reconnect logic

* First pass of a NPM

Provide a service that talks to a (simulated) CP.

- Receive incoming capacity assertions from LBs for LBGs
- expire LB requests after a short period
- ask the CP to add runners to a LBG
- note runner set changes and readvertise
- scale down by marking runners as "draining"
- shut off draining runners after some cool-down period

* add capacity update on schedule

* Send periodic capcacity metrics

Sending capcacity metrics to node pool manager

* splits grpc and api interfaces for capacity manager

* failure to advertise capacity shouldn't panic

* Add some instructions for starting DP/CP parts.

* Create the poolmanager server with TLS

* Use logrus

* Get npm compiling with cert fixups.

* Fix: pure runner should not start async processing

* brings runner, nulb and npm together

* Add field to acknowledgment to record slot allocation latency; fix a bug too

* iterating on pool manager locking issue

* raises timeout of placement retry loop

* Fix up NPM

Improve logging

Ensure that channels etc. are actually initialised in the structure
creation!

* Update the docs - runners GRPC port is 9120

* Bugfix: return runner pool accurately.

* Double locking

* Note purges as LBs stop talking to us

* Get the purging of old LBs working.

* Tweak: on restart, load runner set before making scaling decisions.

* more agent synchronization improvements

* Deal with teh CP pulling out active hosts from under us.

* lock at lbgroup level

* Send request and receive response from runner.

* Add capacity check right before slot reservation

* Pass the full Call into the receive loop.

* Wait for the data from the runner before finishing

* force runner list refresh every time

* Don't init db and mq for pure runners

* adds shutdown of npm

* fixes broken log line

* Extract an interface for the Predictor used by the NPM

* purge drained connections from npm

* Refactor of the LB agent into the agent package

* removes capacitytest wip

* Fix undefined err issue

* updating README for poolmanager set up

* ues retrying dial for lb to npm connections

* Rename lb_calls to lb_agent now that all functionality is there

* Use the right deadline and errors in LBAgent

* Make stream error flag per-call rather than global otherwise the whole runner is damaged by one call dropping

* abstracting gRPCNodePool

* Make stream error flag per-call rather than global otherwise the whole runner is damaged by one call dropping

* Add some init checks for LB and pure runner nodes

* adding some useful debug

* Fix default db and mq for lb node

* removes unreachable code, fixes typo

* Use datastore as logstore in API nodes.

This fixes a bug caused by trying to insert logs into a nil logstore. It
was nil because it wasn't being set for API nodes.

* creates placement abstraction and moves capacity APIs to NodePool

* removed TODO, added logging

* Dial reconnections for LB <-> runners

LB grpc connections to runners are established using a backoff stategy
in event of reconnections, this allows to let the LB up even in case one
of the runners go away and reconnect to it as soon as it is back.

* Add a status call to the Runner protocol

Stub at the moment. To be used for things like draindown, health checks.

* Remove comment.

* makes assign/release capacity lockless

* Fix hanging issue in lb agent when connections drop

* Add the CH hash from fnlb

Select this with FN_PLACER=ch when launching the LB.

* small improvement for locking on reloadLBGmembership

* Stabilise the list of Runenrs returned by NodePool

The NodePoolManager makes some attempt to keep the list of runner nodes advertised as
stable as possible. Let's preserve this effort in the client side. The main point of this
is to attempt to keep the same runner at the same inxed in the []Runner returned by
NodePool.Runners(lbgid); the ch algorithm likes it when this is the case.

* Factor out a generator function for the Runners so that mocks can be injected

* temporarily allow lbgroup to be specified in HTTP header, while we sort out changes to the model

* fixes bug with nil runners

* Initial work for mocking things in tests

* fix for anonymouse go routine error

* fixing lb_test to compile

* Refactor: internal objects for gRPCNodePool are now injectable, with defaults for the real world case

* Make GRPC port configurable, fix weird handling of web port too

* unit test reload Members

* check on runner creation failure

* adding nullRunner in case of failure during runner creation

* Refactored capacity advertisements/aggregations. Made grpc advertisement post asynchronous and non-blocking.

* make capacityEntry private

* Change the runner gRPC bind address.

This uses the existing `whoAmI` function, so that the gRPC server works
when the runner is running on a different host.

* Add support for multiple fixed runners to pool mgr

* Added harness for dataplane system tests, minor refactors

* Add Dockerfiles for components, along with docs.

* Doc fix: second runner needs a different name.

* Let us have three runners in system tests, why not

* The first system test running a function in API/LB/PureRunner mode

* Add unit test for Advertiser logic

* Fix issue with Pure Runner not sending the last data frame

* use config in models.Call as a temporary mechanism to override lb group ID

* make gofmt happy

* Updates documentation for how to configure lb groups for an app/route

* small refactor unit test

* Factor NodePool into its own package

* Lots of fixes to Pure Runner - concurrency woes with errors and cancellations

* New dataplane with static runnerpool (#813)

Added static node pool as default implementation

* moved nullRunner to grpc package

* remove duplication in README

* fix go vet issues

* Fix server initialisation in api tests

* Tiny logging changes in pool manager.

Using `WithError` instead of `Errorf` when appropriate.

* Change some log levels in the pure runner

* fixing readme

* moves multitenant compute documentation

* adds introduction to multitenant readme

* Proper triggering of system tests in makefile

* Fix insructions about starting up the components

* Change db file for system tests to avoid contention in parallel tests

* fixes revisions from merge

* Fix merge issue with handling of reserved slot

* renaming nulb to lb in the doc and images folder

* better TryExec sleep logic clean shutdown

In this change we implement a better way to deal with the sleep inside
the for loop during the attempt for placing a call.
Plus we added a clean way to shutdown the connections with external
component when we shut down the server.

* System_test mysql port

set mysql port for system test to a different value to the one set for
the api tests to avoid conflicts as they can run in parallel.

* change the container name for system-test

* removes flaky test TestRouteRunnerExecution pending resolution by issue #796

* amend remove_containers to remove new added containers

* Rework capacity reservation logic at a higher level for now

* LB agent implements Submit rather than delegating.

* Fix go vet linting errors

* Changed a couple of error levels

* Fix formatting

* removes commmented out test

* adds snappy to vendor directory

* updates Gopkg and vendor directories, removing snappy and addhing siphash

* wait for db containers to come up before starting the tests

* make system tests start API node on 8085 to avoid port conflict with api_tests

* avoid port conflicts with api_test.sh which are run in parallel

* fixes postgres port conflict and issue with removal of old containers

* Remove spurious println
This commit is contained in:
Gerardo Viedma
2018-03-08 22:45:19 +00:00
committed by Tolga Ceylan
parent d5da6fd8c5
commit 8af57da7b2
510 changed files with 263280 additions and 92 deletions

View File

@@ -72,7 +72,7 @@ func getServerWithCancel() (*server.Server, context.CancelFunc) {
dbURL = fmt.Sprintf("sqlite3://%s", tmpDb)
}
s = server.New(ctx, server.WithDBURL(dbURL), server.WithMQURL(mqURL))
s = server.New(ctx, server.WithDBURL(dbURL), server.WithMQURL(mqURL), server.WithFullAgent())
go s.Start(ctx)
started := false
@@ -81,7 +81,6 @@ func getServerWithCancel() (*server.Server, context.CancelFunc) {
panic("Failed to start server.")
}
})
log.Println("apiURL:", apiURL)
_, err := http.Get(apiURL + "/version")
for err != nil {
_, err = http.Get(apiURL + "/version")
@@ -146,7 +145,6 @@ func SetupDefaultSuite() *SuiteSetup {
} else {
_, ok := http.Get(fmt.Sprintf("http://%s/version", Host()))
if ok != nil {
log.Println("Making functions server")
_, cancel := getServerWithCancel()
ss.Cancel = cancel
}

View File

@@ -0,0 +1,52 @@
package tests
import (
"bytes"
//"fmt"
"net/url"
//"os"
"path"
"strings"
"testing"
apiutils "github.com/fnproject/fn/test/fn-api-tests"
)
func LB() (string, error) {
lbURL := "http://127.0.0.1:8081"
u, err := url.Parse(lbURL)
if err != nil {
return "", err
}
return u.Host, nil
}
func TestCanExecuteFunction(t *testing.T) {
s := apiutils.SetupDefaultSuite()
apiutils.CreateApp(t, s.Context, s.Client, s.AppName, map[string]string{})
apiutils.CreateRoute(t, s.Context, s.Client, s.AppName, s.RoutePath, s.Image, "sync",
s.Format, s.Timeout, s.IdleTimeout, s.RouteConfig, s.RouteHeaders)
lb, err := LB()
if err != nil {
t.Fatalf("Got unexpected error: %v", err)
}
u := url.URL{
Scheme: "http",
Host: lb,
}
u.Path = path.Join(u.Path, "r", s.AppName, s.RoutePath)
content := &bytes.Buffer{}
output := &bytes.Buffer{}
_, err = apiutils.CallFN(u.String(), content, output, "POST", []string{})
if err != nil {
t.Errorf("Got unexpected error: %v", err)
}
expectedOutput := "Hello World!\n"
if !strings.Contains(expectedOutput, output.String()) {
t.Errorf("Assertion error.\n\tExpected: %v\n\tActual: %v", expectedOutput, output.String())
}
apiutils.DeleteApp(t, s.Context, s.Client, s.AppName)
}

View File

@@ -0,0 +1,251 @@
package tests
import (
"bytes"
"context"
"fmt"
"github.com/fnproject/fn/api/agent"
"github.com/fnproject/fn/api/agent/hybrid"
agent_grpc "github.com/fnproject/fn/api/agent/nodepool/grpc"
"github.com/fnproject/fn/api/server"
"github.com/sirupsen/logrus"
"net"
"net/http"
"os"
"strconv"
"strings"
"testing"
"time"
)
type SystemTestNodePool struct {
runners []agent.Runner
}
func NewSystemTestNodePool() (agent.NodePool, error) {
myAddr := whoAmI()
runners := []string{
fmt.Sprintf("%s:9190", myAddr),
fmt.Sprintf("%s:9191", myAddr),
fmt.Sprintf("%s:9192", myAddr),
}
return agent_grpc.DefaultStaticNodePool(runners), nil
}
func SetUpSystem() error {
ctx := context.Background()
api, err := SetUpAPINode(ctx)
if err != nil {
return err
}
logrus.Info("Created API node")
lb, err := SetUpLBNode(ctx)
if err != nil {
return err
}
logrus.Info("Created LB node")
pr0, err := SetUpPureRunnerNode(ctx, 0)
if err != nil {
return err
}
pr1, err := SetUpPureRunnerNode(ctx, 1)
if err != nil {
return err
}
pr2, err := SetUpPureRunnerNode(ctx, 2)
if err != nil {
return err
}
logrus.Info("Created Pure Runner nodes")
go func() { api.Start(ctx) }()
logrus.Info("Started API node")
go func() { lb.Start(ctx) }()
logrus.Info("Started LB node")
go func() { pr0.Start(ctx) }()
go func() { pr1.Start(ctx) }()
go func() { pr2.Start(ctx) }()
logrus.Info("Started Pure Runner nodes")
// Wait for init - not great
time.Sleep(5 * time.Second)
return nil
}
func CleanUpSystem() error {
_, err := http.Get("http://127.0.0.1:8081/shutdown")
if err != nil {
return err
}
_, err = http.Get("http://127.0.0.1:8082/shutdown")
if err != nil {
return err
}
_, err = http.Get("http://127.0.0.1:8083/shutdown")
if err != nil {
return err
}
_, err = http.Get("http://127.0.0.1:8084/shutdown")
if err != nil {
return err
}
_, err = http.Get("http://127.0.0.1:8085/shutdown")
if err != nil {
return err
}
// Wait for shutdown - not great
time.Sleep(5 * time.Second)
return nil
}
func SetUpAPINode(ctx context.Context) (*server.Server, error) {
curDir := pwd()
var defaultDB, defaultMQ string
defaultDB = fmt.Sprintf("sqlite3://%s/data/fn.db", curDir)
defaultMQ = fmt.Sprintf("bolt://%s/data/fn.mq", curDir)
nodeType := server.ServerTypeAPI
opts := make([]server.ServerOption, 0)
opts = append(opts, server.WithWebPort(8085))
opts = append(opts, server.WithType(nodeType))
opts = append(opts, server.WithLogLevel(server.DefaultLogLevel))
opts = append(opts, server.WithLogDest(server.DefaultLogDest, "API"))
opts = append(opts, server.WithDBURL(getEnv(server.EnvDBURL, defaultDB)))
opts = append(opts, server.WithMQURL(getEnv(server.EnvMQURL, defaultMQ)))
opts = append(opts, server.WithLogURL(""))
opts = append(opts, server.WithLogstoreFromDatastore())
opts = append(opts, server.EnableShutdownEndpoint(ctx, func() {})) // TODO: do it properly
return server.New(ctx, opts...), nil
}
func SetUpLBNode(ctx context.Context) (*server.Server, error) {
nodeType := server.ServerTypeLB
opts := make([]server.ServerOption, 0)
opts = append(opts, server.WithWebPort(8081))
opts = append(opts, server.WithType(nodeType))
opts = append(opts, server.WithLogLevel(server.DefaultLogLevel))
opts = append(opts, server.WithLogDest(server.DefaultLogDest, "LB"))
opts = append(opts, server.WithDBURL(""))
opts = append(opts, server.WithMQURL(""))
opts = append(opts, server.WithLogURL(""))
opts = append(opts, server.EnableShutdownEndpoint(ctx, func() {})) // TODO: do it properly
apiURL := "http://127.0.0.1:8085"
cl, err := hybrid.NewClient(apiURL)
if err != nil {
return nil, err
}
delegatedAgent := agent.New(agent.NewCachedDataAccess(cl))
nodePool, err := NewSystemTestNodePool()
if err != nil {
return nil, err
}
placer := agent.NewNaivePlacer()
agent, err := agent.NewLBAgent(delegatedAgent, nodePool, placer)
if err != nil {
return nil, err
}
opts = append(opts, server.WithAgent(agent))
return server.New(ctx, opts...), nil
}
func SetUpPureRunnerNode(ctx context.Context, nodeNum int) (*server.Server, error) {
nodeType := server.ServerTypePureRunner
opts := make([]server.ServerOption, 0)
opts = append(opts, server.WithWebPort(8082+nodeNum))
opts = append(opts, server.WithGRPCPort(9190+nodeNum))
opts = append(opts, server.WithType(nodeType))
opts = append(opts, server.WithLogLevel(server.DefaultLogLevel))
opts = append(opts, server.WithLogDest(server.DefaultLogDest, "PURE-RUNNER"))
opts = append(opts, server.WithDBURL(""))
opts = append(opts, server.WithMQURL(""))
opts = append(opts, server.WithLogURL(""))
opts = append(opts, server.EnableShutdownEndpoint(ctx, func() {})) // TODO: do it properly
ds, err := hybrid.NewNopDataStore()
if err != nil {
return nil, err
}
opts = append(opts, server.WithAgent(agent.NewSyncOnly(agent.NewCachedDataAccess(ds))))
return server.New(ctx, opts...), nil
}
func pwd() string {
cwd, err := os.Getwd()
if err != nil {
logrus.WithError(err).Fatalln("couldn't get working directory, possibly unsupported platform?")
}
// Replace forward slashes in case this is windows, URL parser errors
return strings.Replace(cwd, "\\", "/", -1)
}
func getEnv(key, fallback string) string {
if value, ok := os.LookupEnv(key); ok {
return value
}
return fallback
}
func getEnvInt(key string, fallback int) int {
if value, ok := os.LookupEnv(key); ok {
// linter liked this better than if/else
var err error
var i int
if i, err = strconv.Atoi(value); err != nil {
panic(err) // not sure how to handle this
}
return i
}
return fallback
}
// whoAmI searches for a non-local address on any network interface, returning
// the first one it finds. it could be expanded to search eth0 or en0 only but
// to date this has been unnecessary.
func whoAmI() net.IP {
ints, _ := net.Interfaces()
for _, i := range ints {
if i.Name == "docker0" || i.Name == "lo" {
// not perfect
continue
}
addrs, _ := i.Addrs()
for _, a := range addrs {
ip, _, err := net.ParseCIDR(a.String())
if a.Network() == "ip+net" && err == nil && ip.To4() != nil {
if !bytes.Equal(ip, net.ParseIP("127.0.0.1")) {
return ip
}
}
}
}
return nil
}
func TestCanInstantiateSystem(t *testing.T) {
}
func TestMain(m *testing.M) {
err := SetUpSystem()
if err != nil {
logrus.WithError(err).Fatal("Could not initialize system")
os.Exit(1)
}
// call flag.Parse() here if TestMain uses flags
result := m.Run()
err = CleanUpSystem()
if err != nil {
logrus.WithError(err).Warn("Could not clean up system")
}
if result == 0 {
fmt.Fprintln(os.Stdout, "😀 👍 🎗")
}
os.Exit(result)
}

View File

@@ -0,0 +1,19 @@
-----BEGIN CERTIFICATE-----
MIIDEjCCAfqgAwIBAgIQcAcGZqoPa3ZuUah4WH354jANBgkqhkiG9w0BAQsFADAS
MRAwDgYDVQQKEwdBY21lIENvMB4XDTE4MDIyNjEzNDEzMVoXDTE5MDIyNjEzNDEz
MVowEjEQMA4GA1UEChMHQWNtZSBDbzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCC
AQoCggEBAObG9pc0wuEwMTa0mG0UxHhQVseTdOGhvK8hcZ+CzHsYw//GxHnPoCS1
7gKl+tBmGVAqJKtgx0WsvFIo5AHxgngnsX4iwngkrPAKh8T7dTxHj1mVKV0SizQX
6mjNN/vw5/SUVnQ5oKMyo1Lz9jpIj8UYcvhY0Hpozv/Hf5nKR9cjvI3z4UvuGVIZ
6KnX7AuBebupp/CrcfHHXMQnLMCbNjTWTICO4/YJGd2dPkEtXs7vmR9DL4KcrLLy
WTnXzmWCTLtlZ2uoeqNWZUzi3X8n1uatkNAVII6uYuBEVZX9gu8cSMnJX38CQyJm
PIeEOY4ydckuX9ttrEcDK2X4XXQYWTkCAwEAAaNkMGIwDgYDVR0PAQH/BAQDAgWg
MB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAMBgNVHRMBAf8EAjAAMCMG
A1UdEQQcMBqCCWxvY2FsaG9zdIEHYUBhLmNvbYcEfwAAATANBgkqhkiG9w0BAQsF
AAOCAQEAuBP9rnWrgSI8m6tGQ2S2NmMplO0LDx19rTF6tNOwBixEQZP9AwEBiefP
u9HTEDqaZARQq0WAmWien80n2ISRdyYSoSZEYf2Eec8YY1epJj6QgmOn+yeFB5Ua
hgEPNge1oiny1p/9F1P2rxsnYbVcHGO7lbaQQKQq2pWvMg5ypSrDdDLY5/1UiwyF
7BWfASEt+rGcOYmw6VTEur4nUOFIepMybPEpWnhst/lFkE2D79t3Lk6DTDvOizuP
m5k2G/pMw9xClPnta+fwp66Dz++v+vYlJzC8kL4DUNnsy+NPSnYYj36QIqiMXbus
K3F6ZSaerZvCD+VYq0Bnj6AG5/rG+w==
-----END CERTIFICATE-----

View File

@@ -0,0 +1,19 @@
-----BEGIN CERTIFICATE-----
MIIDEjCCAfqgAwIBAgIQcAcGZqoPa3ZuUah4WH354jANBgkqhkiG9w0BAQsFADAS
MRAwDgYDVQQKEwdBY21lIENvMB4XDTE4MDIyNjEzNDEzMVoXDTE5MDIyNjEzNDEz
MVowEjEQMA4GA1UEChMHQWNtZSBDbzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCC
AQoCggEBAObG9pc0wuEwMTa0mG0UxHhQVseTdOGhvK8hcZ+CzHsYw//GxHnPoCS1
7gKl+tBmGVAqJKtgx0WsvFIo5AHxgngnsX4iwngkrPAKh8T7dTxHj1mVKV0SizQX
6mjNN/vw5/SUVnQ5oKMyo1Lz9jpIj8UYcvhY0Hpozv/Hf5nKR9cjvI3z4UvuGVIZ
6KnX7AuBebupp/CrcfHHXMQnLMCbNjTWTICO4/YJGd2dPkEtXs7vmR9DL4KcrLLy
WTnXzmWCTLtlZ2uoeqNWZUzi3X8n1uatkNAVII6uYuBEVZX9gu8cSMnJX38CQyJm
PIeEOY4ydckuX9ttrEcDK2X4XXQYWTkCAwEAAaNkMGIwDgYDVR0PAQH/BAQDAgWg
MB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAMBgNVHRMBAf8EAjAAMCMG
A1UdEQQcMBqCCWxvY2FsaG9zdIEHYUBhLmNvbYcEfwAAATANBgkqhkiG9w0BAQsF
AAOCAQEAuBP9rnWrgSI8m6tGQ2S2NmMplO0LDx19rTF6tNOwBixEQZP9AwEBiefP
u9HTEDqaZARQq0WAmWien80n2ISRdyYSoSZEYf2Eec8YY1epJj6QgmOn+yeFB5Ua
hgEPNge1oiny1p/9F1P2rxsnYbVcHGO7lbaQQKQq2pWvMg5ypSrDdDLY5/1UiwyF
7BWfASEt+rGcOYmw6VTEur4nUOFIepMybPEpWnhst/lFkE2D79t3Lk6DTDvOizuP
m5k2G/pMw9xClPnta+fwp66Dz++v+vYlJzC8kL4DUNnsy+NPSnYYj36QIqiMXbus
K3F6ZSaerZvCD+VYq0Bnj6AG5/rG+w==
-----END CERTIFICATE-----

View File

@@ -0,0 +1,27 @@
-----BEGIN RSA PRIVATE KEY-----
MIIEpQIBAAKCAQEA5sb2lzTC4TAxNrSYbRTEeFBWx5N04aG8ryFxn4LMexjD/8bE
ec+gJLXuAqX60GYZUCokq2DHRay8UijkAfGCeCexfiLCeCSs8AqHxPt1PEePWZUp
XRKLNBfqaM03+/Dn9JRWdDmgozKjUvP2OkiPxRhy+FjQemjO/8d/mcpH1yO8jfPh
S+4ZUhnoqdfsC4F5u6mn8Ktx8cdcxCcswJs2NNZMgI7j9gkZ3Z0+QS1ezu+ZH0Mv
gpyssvJZOdfOZYJMu2Vna6h6o1ZlTOLdfyfW5q2Q0BUgjq5i4ERVlf2C7xxIyclf
fwJDImY8h4Q5jjJ1yS5f222sRwMrZfhddBhZOQIDAQABAoIBAAUoo3CD3GteQWtg
pBukIDQ0T4xMjotQq0Aa9khDi0ChMBhyoAe9DW5kprpmbXHlJmG1X3Z5RlsXXmpT
wa0NcgYvlPcl3cUDxN3kzl4n5NoBG4I8JF2RQY1bj4DiPYMjQnwkKL6WXzHmuuHq
1DE/V/9m6YMFsTtbRm1PT1nnvK1hcz7xMKlCxNrep4pow+dV/RZd4MijMtYQA7pJ
SPGjG1b3xMLYtjbBMxPJXrH9RKRkf2nEnF61f5UgS08G1qHRectzPa/00qmMMFaO
WEVYaE0+2dxUCdaVgAInyHA1PHSP5dGXzFE8xSP/9+TVdRosYs0LS2lJe06r8Y/y
bc3qhAECgYEA5s532Iy84Lmpq0OAD8oBII3hmJCO5tLlTkQm7LB+biYaSFBOYrQ7
vsTiWhbU8E69Fr68dlTsAtrUFXFpjkZkA1vRbVTRqN9NcT0Uzije1BxX4SFIWa/Q
5gnbebmliOC4+s2kAZnhJTlnVypBSVw/nMJT0yYFvbiGHnJ8WJXm74ECgYEA//et
CCTRcO0Zq3o158VzsVzLLd2Urz88nFbvFcnbQaqWUarW8u8TdSLJfE3/5pv1CIi2
lEBpJGfHhAhcfHfekpqioaJe1j6Oek9K234CIGH8X55kQDV6p1xMy8ktv2Chcmuz
GZBc/Ox4tgsSBWdVweKqPZ9oLXAKBzQkKo1nxbkCgYEA5Mnduucng4wHSCGNHBmd
rGt4KQeC4ARGEaM1AoKhkQZsHyqbyPPoFV6NEch4JA2pGpbPsmzT1rCccvUNMV9N
XJbzrnDZs5BG7+0gZovU9mVyJ1Qap+zEIoO675q7IEfClbqqzHuA1qlkat8UAGhV
Fkr7VN7n6fyz1hKeeCF/3gECgYEAi9ToB9zlNcWxEkZPEHCDhU7mCAZWZW4sVFQB
hGujhboFKFQl3MzSWllIrMmHlJl6QNE+vLp7NdIj4nMW40AwrPIhCh/Do1LFTvfm
MwYhb0NYNXw31APjH26C3YjnnvbQ+8ruKnb89YbRYtGlZKJQ7PxAeC2PIdNlBw5q
+3wIRrECgYEAxlBmbox01qxkrSIO0Y5EsCwyL6lufqr28wlHOEO5WN8Z/d7K0RxZ
Q4uWXuZKUUGg/Zn+T6NreTVIsWyKwW/PPTFUjQFFp6de1067alifKBqVLljsL1Du
eiIgQRqwnj+1M4AKN8PRNEaAvDP4pNCuJEfnSNISN+HlmDLIJ0fIkwA=
-----END RSA PRIVATE KEY-----