{"ignition":{"config":{"replace":{"verification":{}}},"proxy":{},"security":{"tls":{}},"timeouts":{},"version":"3.3.0"},"kernelArguments":{},"passwd":{"users":[{"name":"core","sshAuthorizedKeys":["ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDfR3tKnee5T29LnRSShAH8jndIQXtzHgv5706dMGci9th2KTFF3I5H+rL/xuKUlRNHl4Dp7Bh7ZHomF5yIouYrJpIo+rbse9ehpjmT5x019xK0gxWSUx2t24ex2qPD6dlXBaMVL1QuIhYNMBqXbqT+rJPCIhrJboN/4y1GiyUPqY0kr5nGYgN/84mHWzgCDkq+l4ndCjQ1iHIzhPLZfQRCJt2XGaUZ6QaGIYLTETMCMTYn4hlgOXnKg//QMM4WLpAgMW5H/RqP8kXr1PjaDB3o2Qu28e5zcft6bigzrB65pP26vIkkj5Z+aZB7XrhgQCN8JS1frSz2Tb83z8LCoDb3 core@default"]}]},"storage":{"files":[{"group":{},"overwrite":true,"path":"/oem/bin/oem-postinst","user":{},"contents":{"compression":"gzip","source":"data:;base64,H4sIAAAAAAAC/4TPsYrcMBAG4F5P8Qe3KwRpg5vkATYsgRTHFbI0Xg+WNUIaefHbH77lyrtrZ4Zv/n/44SbObvJtMY0UlrqgcKHZczID/i+UoQuhl+iVcI4bVBCkVgqaDvhS0nGBLtxQe27wd8/Z8IwXWIIjDS71tbkqopRDPYpStJP0HPH669SzAbb9m9NPt5yjmdkM+N0VjXMgeFSaRBScJ9IHUUaQniIWvxOeHusz6cUMqLTJTu9F//654SQ53zFLBe1Uj7OYaUdT2qJ9Ps5VUoK1WrafNtLOgUbfVWBtz0nCalc67MyJxq+Sw9oHF7ItiY6n9UGWUNsIF2l3kdvqpsMWXzX5iZK7Xa//zFsAAAD//xWtcly8AQAA","verification":{}},"mode":493},{"group":{},"overwrite":true,"path":"/etc/flatcar/update.conf","user":{},"contents":{"source":"data:text/plain;charset=utf-8;base64,U0VSVkVSPWRpc2FibGVkCg==","verification":{}},"mode":420}],"filesystems":[{"device":"/dev/mapper/rootencrypted","format":"ext4","label":"ROOT"}],"luks":[{"clevis":{"custom":{}},"device":"/dev/disk/by-partlabel/ROOT","keyFile":{"verification":{}},"name":"rootencrypted","wipeVolume":true}]},"systemd":{"units":[{"contents":"[Unit]\nConditionFirstBoot=true\nOnFailure=emergency.target\nOnFailureJobMode=isolate\nAfter=first-boot-complete.target multi-user.target\n[Service]\nType=oneshot\nRemainAfterExit=yes\nExecStart=systemd-cryptenroll --tpm2-device=auto --unlock-key-file=/etc/luks/rootencrypted --tpm2-pcrs= /dev/disk/by-partlabel/ROOT\nExecStart=mv /etc/luks/rootencrypted /etc/luks/rootencrypted-bind\nExecStart=sleep 10\nExecStart=systemctl reboot\n[Install]\nWantedBy=multi-user.target\n","enabled":true,"name":"cryptenroll-helper-first.service"},{"contents":"[Unit]\nConditionFirstBoot=false\nConditionPathExists=/etc/luks/rootencrypted-bind\nOnFailure=emergency.target\nOnFailureJobMode=isolate\nBefore=update-engine.service\n[Service]\nType=oneshot\nRemainAfterExit=yes\nExecStart=systemd-cryptenroll --tpm2-device=auto --unlock-key-file=/etc/luks/rootencrypted-bind --tpm2-pcrs=4+7+8+9+11+12+13 --wipe-slot=tpm2 /dev/disk/by-partlabel/ROOT\nExecStart=mv /etc/luks/rootencrypted-bind /etc/luks/rootencrypted-bound\n[Install]\nWantedBy=multi-user.target\n","enabled":true,"name":"cryptenroll-helper-bind.service"},{"contents":"[Unit]\nDescription=QEMU metadata agent\nAfter=nss-lookup.target\nAfter=network-online.target\nWants=network-online.target\n\n[Service]\nType=oneshot\nEnvironment=OUTPUT=/run/metadata/flatcar\nExecStart=/usr/bin/mkdir --parent /run/metadata\nExecStart=/usr/bin/bash -c 'echo \"COREOS_CUSTOM_PRIVATE_IPV4=10.0.0.104\\nCOREOS_CUSTOM_PUBLIC_IPV4=10.0.0.104\\n\" \u003e ${OUTPUT}'\nExecStartPost=/usr/bin/ln -fs /run/metadata/flatcar /run/metadata/coreos\n","enabled":false,"name":"coreos-metadata.service"}]}}