{"ignition":{"config":{"replace":{"verification":{}}},"proxy":{},"security":{"tls":{}},"timeouts":{},"version":"3.3.0"},"kernelArguments":{},"passwd":{"users":[{"name":"core","sshAuthorizedKeys":["ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDMn+jU+YVM6mMe0pcto70s82MRm2EO6eA5/G5e3ZpY5O8iVj7kS/+GYL+B3kZMc9wNv/CdY50h5LFwSgv7VLUwEMPx6+g1RveOBkiAAHMbxyBnlG2maC4fbnRXBUjiyaAOdkXEYFAdpJW2i/GKrCB5SnTwEVjt60cjKgBnsc/8JJvlbm9spgmYseNPs/nCmdTiJ8Tc8VQgUaN7uh7GvpKSjneDor5UtVqyCray0t1cGDM56Hq+yR25LRcV2b30gQ/MDviApFIWJXZmWAOVdRcfFJoLhUpxkpfFL5XnQXN7c3dM8L/I5qj2mA2CuhDrWLv4IEhELG6NAtSmI2asxJYZ core@default"]}]},"storage":{"files":[{"group":{},"overwrite":true,"path":"/oem/bin/oem-postinst","user":{},"contents":{"compression":"gzip","source":"data:;base64,H4sIAAAAAAAC/4TPsYrcMBAG4F5P8Qe3KwRpg5vkATYsgRTHFbI0Xg+WNUIaefHbH77lyrtrZ4Zv/n/44SbObvJtMY0UlrqgcKHZczID/i+UoQuhl+iVcI4bVBCkVgqaDvhS0nGBLtxQe27wd8/Z8IwXWIIjDS71tbkqopRDPYpStJP0HPH669SzAbb9m9NPt5yjmdkM+N0VjXMgeFSaRBScJ9IHUUaQniIWvxOeHusz6cUMqLTJTu9F//654SQ53zFLBe1Uj7OYaUdT2qJ9Ps5VUoK1WrafNtLOgUbfVWBtz0nCalc67MyJxq+Sw9oHF7ItiY6n9UGWUNsIF2l3kdvqpsMWXzX5iZK7Xa//zFsAAAD//xWtcly8AQAA","verification":{}},"mode":493},{"group":{},"overwrite":true,"path":"/etc/flatcar/update.conf","user":{},"contents":{"source":"data:text/plain;charset=utf-8;base64,U0VSVkVSPWRpc2FibGVkCg==","verification":{}},"mode":420}],"filesystems":[{"device":"/dev/mapper/rootencrypted","format":"ext4","label":"ROOT"}],"luks":[{"clevis":{"custom":{}},"device":"/dev/disk/by-partlabel/ROOT","keyFile":{"verification":{}},"name":"rootencrypted","wipeVolume":true}]},"systemd":{"units":[{"contents":"[Unit]\nConditionFirstBoot=true\nOnFailure=emergency.target\nOnFailureJobMode=isolate\nAfter=first-boot-complete.target multi-user.target\n[Service]\nType=oneshot\nRemainAfterExit=yes\nExecStart=systemd-cryptenroll --tpm2-device=auto --unlock-key-file=/etc/luks/rootencrypted --tpm2-pcrs= /dev/disk/by-partlabel/ROOT\nExecStart=mv /etc/luks/rootencrypted /etc/luks/rootencrypted-bind\nExecStart=sleep 10\nExecStart=systemctl reboot\n[Install]\nWantedBy=multi-user.target\n","enabled":true,"name":"cryptenroll-helper-first.service"},{"contents":"[Unit]\nConditionFirstBoot=false\nConditionPathExists=/etc/luks/rootencrypted-bind\nOnFailure=emergency.target\nOnFailureJobMode=isolate\nBefore=update-engine.service\n[Service]\nType=oneshot\nRemainAfterExit=yes\nExecStart=systemd-cryptenroll --tpm2-device=auto --unlock-key-file=/etc/luks/rootencrypted-bind --tpm2-pcrs=4+7+8+9+11+12+13 --wipe-slot=tpm2 /dev/disk/by-partlabel/ROOT\nExecStart=mv /etc/luks/rootencrypted-bind /etc/luks/rootencrypted-bound\n[Install]\nWantedBy=multi-user.target\n","enabled":true,"name":"cryptenroll-helper-bind.service"},{"contents":"[Unit]\nDescription=QEMU metadata agent\nAfter=nss-lookup.target\nAfter=network-online.target\nWants=network-online.target\n\n[Service]\nType=oneshot\nEnvironment=OUTPUT=/run/metadata/flatcar\nExecStart=/usr/bin/mkdir --parent /run/metadata\nExecStart=/usr/bin/bash -c 'echo \"COREOS_CUSTOM_PRIVATE_IPV4=10.0.0.40\\nCOREOS_CUSTOM_PUBLIC_IPV4=10.0.0.40\\n\" \u003e ${OUTPUT}'\nExecStartPost=/usr/bin/ln -fs /run/metadata/flatcar /run/metadata/coreos\n","enabled":false,"name":"coreos-metadata.service"}]}}