All checks were successful
Build and publish policy-nexus image / build-and-push (push) Successful in 1m10s
Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a058f3-8ba0-7692-a042-9a870fc3d663
219 lines
20 KiB
HTML
219 lines
20 KiB
HTML
<!doctype html>
|
|
<html lang="en"><meta charset="utf-8">
|
|
<meta name="policy-source-revision" content="9781102e2971d762ae42fdd5085a6647afd1cd66">
|
|
<meta name="policy-source-digest" content="e92a43649bb6e14e53ec62ecc819405bf3a44bda9557487f7177402f107bbd13">
|
|
<title>Recursive Multi-Tenant Identity and Authorization Architecture</title>
|
|
<style>
|
|
:root{
|
|
--paper:#EDEEF0; --surface:#F6F7F8; --surface-2:#E4E6E9;
|
|
--ink:#171D24; --ink-2:#4A5561; --ink-3:#737E8A;
|
|
--rule:#D3D7DC; --rule-strong:#B6BCC3;
|
|
--brass:#8A6A2E; --brass-soft:#EFE5CD; --brass-line:#C9AE74;
|
|
--clay:#8A3A2C; --clay-soft:#F2DFDA;
|
|
--l0:#DCE0E2; --l1:#B9C4C7; --l2:#8CA1A6; --l3:#567D84; --l4:#23555E;
|
|
--chip-fg:#F6F7F8;
|
|
--font-display:ui-sans-serif,system-ui,-apple-system,"Segoe UI",Roboto,"Helvetica Neue",sans-serif;
|
|
--font-body:"Iowan Old Style","Palatino Linotype",Palatino,Georgia,serif;
|
|
--font-mono:ui-monospace,"SF Mono","Cascadia Code",Menlo,Consolas,monospace;
|
|
--measure:66ch;
|
|
}
|
|
@media (prefers-color-scheme:dark){
|
|
:root:not([data-theme="light"]){
|
|
--paper:#12161A; --surface:#191E24; --surface-2:#222831;
|
|
--ink:#E6E9EC; --ink-2:#A3ADB7; --ink-3:#78838E;
|
|
--rule:#2A3138; --rule-strong:#3B444D;
|
|
--brass:#C9A45C; --brass-soft:#33290F; --brass-line:#6B5426;
|
|
--clay:#D08A76; --clay-soft:#3A211B;
|
|
--l0:#262C32; --l1:#35424A; --l2:#4A626B; --l3:#6A939D; --l4:#97C4CD;
|
|
--chip-fg:#12161A;
|
|
}
|
|
}
|
|
:root[data-theme="dark"]{
|
|
--paper:#12161A; --surface:#191E24; --surface-2:#222831;
|
|
--ink:#E6E9EC; --ink-2:#A3ADB7; --ink-3:#78838E;
|
|
--rule:#2A3138; --rule-strong:#3B444D;
|
|
--brass:#C9A45C; --brass-soft:#33290F; --brass-line:#6B5426;
|
|
--clay:#D08A76; --clay-soft:#3A211B;
|
|
--l0:#262C32; --l1:#35424A; --l2:#4A626B; --l3:#6A939D; --l4:#97C4CD;
|
|
--chip-fg:#12161A;
|
|
}
|
|
|
|
*{box-sizing:border-box}
|
|
body{
|
|
margin:0; background:var(--paper); color:var(--ink);
|
|
font-family:var(--font-body); font-size:17px; line-height:1.62;
|
|
-webkit-font-smoothing:antialiased;
|
|
}
|
|
.wrap{max-width:1180px;margin:0 auto;padding:0 24px 96px}
|
|
.layout{display:grid;grid-template-columns:180px minmax(0,1fr);gap:56px;align-items:start}
|
|
@media (max-width:960px){.layout{grid-template-columns:1fr;gap:0}.rail{display:none}}
|
|
|
|
/* ---------- rail ---------- */
|
|
.rail{position:sticky;top:28px;padding-top:8px;font-family:var(--font-display);font-size:12px;line-height:1.5}
|
|
.rail ol{list-style:none;margin:0;padding:0;display:flex;flex-direction:column;gap:7px}
|
|
.rail a{color:var(--ink-3);text-decoration:none;display:flex;gap:9px}
|
|
.rail a:hover,.rail a:focus-visible{color:var(--brass)}
|
|
.rail .n{font-family:var(--font-mono);font-size:10px;color:var(--rule-strong);min-width:16px;padding-top:1px}
|
|
.rail .grp{margin-top:14px;font-size:9.5px;letter-spacing:.14em;text-transform:uppercase;color:var(--rule-strong)}
|
|
|
|
/* ---------- header ---------- */
|
|
header{padding:64px 0 40px;border-bottom:2px solid var(--ink);margin-bottom:44px}
|
|
.eyebrow{font-family:var(--font-mono);font-size:11.5px;letter-spacing:.13em;text-transform:uppercase;color:var(--ink-3);display:flex;flex-wrap:wrap;gap:14px;margin-bottom:22px}
|
|
.eyebrow .stat{color:var(--clay)}
|
|
h1{font-family:var(--font-display);font-weight:800;letter-spacing:-.035em;line-height:.94;font-size:clamp(46px,9vw,92px);margin:0 0 6px;text-wrap:balance}
|
|
.sub{font-family:var(--font-display);font-weight:500;font-size:clamp(16px,2.4vw,21px);letter-spacing:-.01em;color:var(--ink-2);margin:0 0 30px;max-width:34ch;line-height:1.3}
|
|
.metagrid{display:grid;grid-template-columns:repeat(auto-fit,minmax(180px,1fr));gap:20px 28px;border-top:1px solid var(--rule);padding-top:20px}
|
|
.metagrid dt{font-family:var(--font-mono);font-size:10px;letter-spacing:.13em;text-transform:uppercase;color:var(--ink-3);margin-bottom:5px}
|
|
.metagrid dd{margin:0;font-family:var(--font-display);font-size:13.5px;line-height:1.45;color:var(--ink)}
|
|
|
|
/* ---------- typography ---------- */
|
|
section{margin-bottom:60px;scroll-margin-top:24px}
|
|
h2{font-family:var(--font-display);font-weight:750;letter-spacing:-.022em;font-size:clamp(24px,3.4vw,31px);line-height:1.12;margin:0 0 18px;text-wrap:balance;display:flex;gap:14px;align-items:baseline}
|
|
h2 .sn{font-family:var(--font-mono);font-size:12px;font-weight:400;color:var(--brass);letter-spacing:.06em;flex:none;padding-top:2px}
|
|
h3{font-family:var(--font-display);font-weight:700;font-size:16px;letter-spacing:-.008em;margin:34px 0 10px;color:var(--ink)}
|
|
p{margin:0 0 15px;max-width:var(--measure)}
|
|
ul,ol{max-width:var(--measure);margin:0 0 15px;padding-left:20px}
|
|
li{margin-bottom:7px}
|
|
strong{font-weight:600}
|
|
em{font-style:italic}
|
|
code{font-family:var(--font-mono);font-size:.855em;background:var(--surface-2);padding:1px 5px;border-radius:2px}
|
|
a{color:var(--brass)}
|
|
.lede{font-size:19px;line-height:1.55;color:var(--ink-2);max-width:60ch}
|
|
|
|
/* ---------- devices ---------- */
|
|
.callout{border-left:3px solid var(--brass);background:var(--brass-soft);padding:18px 22px;margin:0 0 24px;max-width:var(--measure)}
|
|
.callout p:last-child{margin-bottom:0}
|
|
.callout .lbl{font-family:var(--font-mono);font-size:10px;letter-spacing:.13em;text-transform:uppercase;color:var(--brass);display:block;margin-bottom:8px}
|
|
.rule-quote{border-top:2px solid var(--ink);border-bottom:2px solid var(--ink);padding:26px 0;margin:28px 0;max-width:var(--measure)}
|
|
.rule-quote p{font-family:var(--font-display);font-weight:600;font-size:19px;line-height:1.38;letter-spacing:-.014em;margin:0;text-wrap:balance}
|
|
.hard{border-left:3px solid var(--clay);background:var(--clay-soft);padding:18px 22px;margin:0 0 24px;max-width:var(--measure)}
|
|
.hard .lbl{font-family:var(--font-mono);font-size:10px;letter-spacing:.13em;text-transform:uppercase;color:var(--clay);display:block;margin-bottom:8px}
|
|
.hard p:last-child{margin-bottom:0}
|
|
.dec{font-family:var(--font-mono);font-size:10.5px;letter-spacing:.08em;color:var(--brass);text-transform:uppercase}
|
|
.vec{font-family:var(--font-mono);font-size:.9em;font-weight:600;background:var(--surface-2);padding:2px 7px;border-radius:2px;white-space:nowrap;letter-spacing:.04em}
|
|
|
|
/* ---------- tables ---------- */
|
|
.scroll{overflow-x:auto;margin:0 0 24px;-webkit-overflow-scrolling:touch}
|
|
table{border-collapse:collapse;width:100%;min-width:520px;font-family:var(--font-display);font-size:13.5px;line-height:1.45}
|
|
th{text-align:left;font-family:var(--font-mono);font-size:9.5px;letter-spacing:.13em;text-transform:uppercase;color:var(--ink-3);font-weight:400;padding:0 16px 8px 0;border-bottom:1px solid var(--rule-strong);vertical-align:bottom}
|
|
td{padding:11px 16px 11px 0;border-bottom:1px solid var(--rule);vertical-align:top;color:var(--ink-2)}
|
|
td:first-child{color:var(--ink);font-weight:600}
|
|
tbody tr:last-child td{border-bottom:none}
|
|
.lvl{font-family:var(--font-mono);font-weight:600;font-size:12px;letter-spacing:.04em;color:var(--ink)}
|
|
|
|
/* ---------- ladders ---------- */
|
|
.breakout{margin:34px 0 40px}
|
|
.bhead{display:flex;justify-content:space-between;align-items:baseline;gap:20px;border-bottom:1px solid var(--rule-strong);padding-bottom:9px;margin-bottom:22px;flex-wrap:wrap}
|
|
.bhead h3{margin:0;font-size:13px;letter-spacing:.1em;text-transform:uppercase;font-family:var(--font-mono);font-weight:400;color:var(--ink-3)}
|
|
.bhead .note{font-family:var(--font-display);font-size:12.5px;color:var(--ink-3)}
|
|
.ladders{display:grid;gap:26px}
|
|
.ladder{display:grid;grid-template-columns:126px minmax(0,1fr);gap:18px;align-items:start}
|
|
@media (max-width:700px){.ladder{grid-template-columns:1fr;gap:10px}}
|
|
.ladder .pname{font-family:var(--font-display);font-weight:700;font-size:14px;letter-spacing:-.01em;padding-top:2px}
|
|
.ladder .pname span{display:block;font-family:var(--font-mono);font-size:10px;font-weight:400;letter-spacing:.1em;text-transform:uppercase;color:var(--ink-3);margin-top:3px}
|
|
.rungs{display:grid;gap:3px;grid-template-columns:repeat(5,minmax(0,1fr))}
|
|
@media (max-width:700px){.rungs{grid-template-columns:repeat(2,minmax(0,1fr))}}
|
|
.rung{padding:9px 10px 11px;background:var(--surface);border-top:4px solid var(--l0);min-width:0}
|
|
.rung.r1{border-top-color:var(--l1)} .rung.r2{border-top-color:var(--l2)}
|
|
.rung.r3{border-top-color:var(--l3)} .rung.r4{border-top-color:var(--l4)}
|
|
.rung .code{font-family:var(--font-mono);font-size:11px;font-weight:600;letter-spacing:.06em;color:var(--ink);display:block;margin-bottom:4px}
|
|
.rung .txt{font-family:var(--font-display);font-size:11.5px;line-height:1.34;color:var(--ink-2);display:block}
|
|
.rung.na{opacity:.42}
|
|
|
|
/* ---------- matrix ---------- */
|
|
.matrix-shell{display:grid;grid-template-columns:auto minmax(0,1fr);gap:12px;align-items:stretch;margin-bottom:14px}
|
|
.ylab{writing-mode:vertical-rl;transform:rotate(180deg);font-family:var(--font-mono);font-size:9.5px;letter-spacing:.14em;text-transform:uppercase;color:var(--ink-3);text-align:center;padding-bottom:22px}
|
|
.mgrid{display:grid;grid-template-columns:34px repeat(5,minmax(0,1fr));gap:3px}
|
|
.mcell{background:var(--surface);min-height:60px;padding:6px;display:flex;flex-direction:column;justify-content:flex-end;gap:4px;min-width:0}
|
|
.mcell.tint1{background:color-mix(in srgb,var(--l1) 26%,var(--surface))}
|
|
.mcell.tint2{background:color-mix(in srgb,var(--l2) 26%,var(--surface))}
|
|
.mcell.tint3{background:color-mix(in srgb,var(--l3) 24%,var(--surface))}
|
|
.mcell.tint4{background:color-mix(in srgb,var(--l4) 22%,var(--surface))}
|
|
.mcell.void{background:repeating-linear-gradient(135deg,transparent,transparent 5px,var(--rule) 5px,var(--rule) 6px);opacity:.55}
|
|
.rlab,.clab{font-family:var(--font-mono);font-size:10px;font-weight:600;letter-spacing:.05em;color:var(--ink-3);display:flex;align-items:center;justify-content:center}
|
|
.rlab{min-height:60px}
|
|
.clab{padding-top:7px;min-height:22px}
|
|
.pin{font-family:var(--font-mono);font-size:9.5px;font-weight:600;letter-spacing:.02em;background:var(--ink);color:var(--paper);padding:2px 5px;border-radius:2px;line-height:1.3;display:block;overflow:hidden;text-overflow:ellipsis;white-space:nowrap}
|
|
.pin.ghost{background:transparent;color:var(--ink-2);border:1px dashed var(--rule-strong)}
|
|
.mnote{display:flex;gap:22px;flex-wrap:wrap;font-family:var(--font-display);font-size:12px;color:var(--ink-3);padding-top:6px}
|
|
.mnote .k{display:flex;align-items:center;gap:7px}
|
|
.sw{width:13px;height:13px;flex:none;background:var(--ink)}
|
|
.sw.g{background:transparent;border:1px dashed var(--rule-strong)}
|
|
.sw.v{background:repeating-linear-gradient(135deg,transparent,transparent 4px,var(--rule) 4px,var(--rule) 5px);border:1px solid var(--rule)}
|
|
@media (max-width:640px){
|
|
.mgrid{grid-template-columns:28px repeat(5,minmax(0,1fr))}
|
|
.mcell{min-height:52px;padding:4px}
|
|
.pin{font-size:8px;padding:1px 3px}
|
|
.rlab{min-height:52px}
|
|
}
|
|
|
|
/* ---------- methodology ---------- */
|
|
.verbs{display:grid;grid-template-columns:repeat(auto-fit,minmax(210px,1fr));gap:2px;background:var(--rule);border:1px solid var(--rule)}
|
|
.verb{background:var(--surface);padding:18px 18px 20px}
|
|
.verb h4{font-family:var(--font-display);font-weight:750;font-size:15px;margin:0 0 7px;letter-spacing:-.01em}
|
|
.verb p{font-family:var(--font-display);font-size:12.5px;line-height:1.46;color:var(--ink-2);margin:0;max-width:none}
|
|
.verb .step{font-family:var(--font-mono);font-size:9.5px;letter-spacing:.13em;color:var(--brass);display:block;margin-bottom:9px}
|
|
|
|
/* ---------- questions ---------- */
|
|
.qs{display:flex;flex-direction:column;gap:0;border-top:1px solid var(--rule-strong)}
|
|
.q{display:grid;grid-template-columns:34px minmax(0,1fr) 170px;gap:18px;padding:16px 0;border-bottom:1px solid var(--rule);align-items:start}
|
|
@media (max-width:760px){.q{grid-template-columns:28px minmax(0,1fr);gap:12px}.q .owner{grid-column:2}}
|
|
.q .qn{font-family:var(--font-mono);font-size:11px;color:var(--brass);padding-top:3px}
|
|
.q .qt{font-family:var(--font-display);font-size:14px;line-height:1.48;color:var(--ink-2)}
|
|
.q .qt b{color:var(--ink);font-weight:700;display:block;margin-bottom:2px;font-size:14.5px}
|
|
.owner{font-family:var(--font-mono);font-size:10px;letter-spacing:.05em;color:var(--ink-3);padding-top:4px}
|
|
.owner .tag{display:inline-block;border:1px solid var(--rule-strong);padding:2px 7px;border-radius:2px}
|
|
.owner .tag.need{border-color:var(--clay);color:var(--clay)}
|
|
|
|
/* ---------- misc ---------- */
|
|
.numbers{font-family:var(--font-mono);font-size:12.5px;line-height:1.85;background:var(--surface);border-left:3px solid var(--l3);padding:16px 20px;margin:0 0 22px;overflow-x:auto;max-width:var(--measure)}
|
|
.numbers .v{color:var(--ink);font-weight:600}
|
|
.numbers .k{color:var(--ink-3)}
|
|
pre{font-family:var(--font-mono);font-size:12.5px;line-height:1.68;background:var(--surface);border-left:3px solid var(--rule-strong);padding:16px 20px;overflow-x:auto;margin:0 0 22px;max-width:var(--measure);color:var(--ink-2)}
|
|
.alt{border-bottom:1px solid var(--rule);padding:14px 0;max-width:var(--measure)}
|
|
.alt:last-of-type{border-bottom:none}
|
|
.alt b{font-family:var(--font-display);font-size:14px;display:block;margin-bottom:3px}
|
|
.alt p{font-size:14.5px;margin:0;color:var(--ink-2)}
|
|
.alt .verdict{font-family:var(--font-mono);font-size:10px;letter-spacing:.1em;text-transform:uppercase;color:var(--clay)}
|
|
footer{border-top:2px solid var(--ink);margin-top:20px;padding-top:22px;font-family:var(--font-mono);font-size:11px;letter-spacing:.06em;color:var(--ink-3);display:flex;justify-content:space-between;gap:20px;flex-wrap:wrap}
|
|
.tm td,.tm th{text-align:center}
|
|
.tm td:first-child,.tm th:first-child{text-align:left}
|
|
.yes{color:var(--l4);font-weight:700}
|
|
.no{color:var(--clay);font-weight:700}
|
|
.kind{font-family:var(--font-mono);font-size:9px;letter-spacing:.09em;text-transform:uppercase;padding:2px 6px;border-radius:2px;white-space:nowrap;border:1px solid var(--rule-strong);color:var(--ink-3)}
|
|
.kind.adv{border-color:var(--clay);color:var(--clay)}
|
|
.routes{display:grid;grid-template-columns:repeat(auto-fit,minmax(240px,1fr));gap:2px;background:var(--rule);border:1px solid var(--rule);margin:0 0 22px}
|
|
.route{background:var(--surface);padding:16px 18px}
|
|
.route h4{font-family:var(--font-display);font-weight:750;font-size:14px;margin:0 0 6px}
|
|
.route p{font-family:var(--font-display);font-size:12.5px;line-height:1.45;color:var(--ink-2);margin:0;max-width:none}
|
|
.route .tag{font-family:var(--font-mono);font-size:9px;letter-spacing:.1em;text-transform:uppercase;color:var(--brass);display:block;margin-bottom:8px}
|
|
a:focus-visible,.rail a:focus-visible{outline:2px solid var(--brass);outline-offset:3px}
|
|
@media (prefers-reduced-motion:reduce){*{animation:none!important;transition:none!important}}
|
|
|
|
</style>
|
|
<div class="wrap"><header><div class="eyebrow"><span>NK-ADR-0006</span> <span class="stat">accepted · 1</span> <span>net-kingdom</span> <span>reviewed 2026-08-22</span><span>generated from canonical source — do not edit</span></div><h1>Recursive Multi-Tenant Identity and Authorization Architecture</h1><p class="sub">Source: <code>net-kingdom · docs/adr/ADR-0006-recursive-multi-tenant-identity-authorization.md · 9781102e2971d762ae42fdd5085a6647afd1cd66</code></p><p class="sub">Review due: 2027-02-22</p></header><div class="layout"><nav class="rail" aria-label="Sections"><ol><li><a href="#context"><span class="n">·</span>Context</a></li><li><a href="#decision"><span class="n">·</span>Decision</a></li><li><a href="#consequences"><span class="n">·</span>Consequences</a></li><li><a href="#alternatives-considered"><span class="n">·</span>Alternatives Considered</a></li><li><a href="#follow-up"><span class="n">·</span>Follow-Up</a></li></ol></nav><main><p><strong>Status:</strong> Accepted <strong>Date:</strong> 2026-05-17 <strong>Deciders:</strong> Bernd Worsch</p>
|
|
<section id="context"><h2>Context</h2>
|
|
<p>The Coulomb platform is being built from the same repositories and services that will later support other use cases. This creates a recursive architecture problem: Coulomb needs to use the shared identity, security, policy, and deployment capabilities, while those capabilities are themselves part of the infrastructure being built.</p>
|
|
<p>If this recursion is left implicit, the first internal use case can drift into being treated as the platform root of trust. That would make future multi-tenant use harder, blur operational authority, and make secure bootstrap/recovery decisions harder to reason about.</p>
|
|
<p>NetKingdom already owns identity and security architecture concerns. key-cape provides a lightweight IAM implementation of the NetKingdom IAM Profile. Keycloak remains the expanded production IAM option. privacyIDEA is relevant for MFA/token lifecycle. flex-auth is emerging as the canonical authorization control plane and practical reference implementation of CARING authorization semantics. Topaz is the most likely first delegated authorization runtime behind flex-auth.</p>
|
|
</section>
|
|
<section id="decision"><h2>Decision</h2>
|
|
<p>We will document and implement the platform security architecture as a recursive multi-tenant architecture with three explicit planes:</p>
|
|
<ul><li><strong>Bootstrap plane</strong> - establishes the first trusted runtime and recovery authority before normal platform services exist.</li><li><strong>Platform control plane</strong> - operates shared identity, MFA, secrets, authorization, policy, audit, and explanation services.</li><li><strong>Tenant plane</strong> - runs Coulomb and future workloads under scoped tenant authority.</li></ul>
|
|
<p>Coulomb will be treated as the first internal/reference tenant, not as the platform root of trust.</p>
|
|
<p>NetKingdom will own the canonical security architecture and standards. Railiance will own deployment layering and orchestration boundaries. flex-auth will own the canonical authorization interface and CARING-based policy/decision model. Topaz will be the first delegated PDP runtime, with other authorization engines treated as adapters where useful.</p>
|
|
</section>
|
|
<section id="consequences"><h2>Consequences</h2>
|
|
<ul><li>Architecture documentation must separate platform-root authority from tenant administration, even for Coulomb.</li><li>Workplans for identity, authorization, and bootstrapping must include explicit tenant and control-plane boundaries.</li><li>Bootstrap design must include trust-state transitions and recovery procedures rather than assuming the final IAM service already exists.</li><li>flex-auth should model tenants, platform resources, CARING descriptors, decision envelopes, and runtime adapters in a provider-neutral way.</li><li>key-cape and Keycloak should be treated as implementations of the IAM Profile, not as the canonical source of resource authorization semantics.</li><li>A future orchestration repo may be useful, but only to coordinate safe sequencing across Railiance and NetKingdom capabilities. It must not bypass Railiance stack ownership.</li></ul>
|
|
</section>
|
|
<section id="alternatives-considered"><h2>Alternatives Considered</h2>
|
|
<h3>Treat Coulomb As The Platform Root</h3>
|
|
<p>This is simpler during early development but creates long-term coupling between one internal use case and the shared platform. It makes later multi-tenant operation and secure bootstrap harder.</p>
|
|
<h3>Put All Security Semantics Into Keycloak</h3>
|
|
<p>Keycloak is useful for expanded IAM and can provide authorization features, but making it the canonical model would make lightweight mode and future authorization backends harder to support. The preferred model keeps identity provider concerns separate from canonical authorization semantics.</p>
|
|
<h3>Create An Orchestration Repo Immediately</h3>
|
|
<p>A dedicated orchestration repo may become appropriate. Creating it before we define trust states and repo boundaries would risk encoding accidental sequence logic too early. The immediate step is to document the state machine and update workplans.</p>
|
|
</section>
|
|
<section id="follow-up"><h2>Follow-Up</h2>
|
|
<ul><li>Refine bootstrapping around explicit trust-state transitions.</li><li>Add tenant/control-plane language to flex-auth authorization workplans.</li><li>Define the first production Topaz integration boundary for flex-auth.</li><li>Decide when key-cape is sufficient and when Keycloak expanded mode is required.</li><li>Decide what, if anything, should live in a future orchestration repo.</li></ul>
|
|
</section><footer><span>NK-ADR-0006 · 1 · accepted</span><span>net-kingdom · docs/adr/ADR-0006-recursive-multi-tenant-identity-authorization.md · 9781102e2971d762ae42fdd5085a6647afd1cd66</span></footer></main></div></div></html>
|