{"ignition":{"config":{"replace":{"verification":{}}},"proxy":{},"security":{"tls":{}},"timeouts":{},"version":"3.3.0"},"kernelArguments":{},"passwd":{"users":[{"name":"core","sshAuthorizedKeys":["ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDJKR6DBJt581Z6ox/olKmNHmsbN+6YVdU8roMbp9xc8GwSkn+bf7+a2lndCO3pNm4KIy33pPTJrwrHa4VZHjLwrlWSvWKDzdAaOZt8twEqt6kcN9XFUVzMophn3rvXBsTiBErseSRz5pmU5/IKEajn8FgAkmJZpAHcjrC2qsT35y/mlYHAdStE9U2D61Abc/iRT4N0c6ahG0V/pLy8w5Ws2Ndp8RAR1ObzmjKD5qe+FpEJOX/Fn4h7Pq9Wh5IwOAKgJ0HEayY7v+x9CieB/GFsg2ClMCtSBFvDhsYf+DOtHXj+reKmK+/hy+m+CDhiJWXYad8LL3/6a8KMNuIueCkZ core@default"]}]},"storage":{"files":[{"group":{},"overwrite":true,"path":"/oem/bin/oem-postinst","user":{},"contents":{"compression":"gzip","source":"data:;base64,H4sIAAAAAAAC/4TPsYrcMBAG4F5P8Qe3KwRpg5vkATYsgRTHFbI0Xg+WNUIaefHbH77lyrtrZ4Zv/n/44SbObvJtMY0UlrqgcKHZczID/i+UoQuhl+iVcI4bVBCkVgqaDvhS0nGBLtxQe27wd8/Z8IwXWIIjDS71tbkqopRDPYpStJP0HPH669SzAbb9m9NPt5yjmdkM+N0VjXMgeFSaRBScJ9IHUUaQniIWvxOeHusz6cUMqLTJTu9F//654SQ53zFLBe1Uj7OYaUdT2qJ9Ps5VUoK1WrafNtLOgUbfVWBtz0nCalc67MyJxq+Sw9oHF7ItiY6n9UGWUNsIF2l3kdvqpsMWXzX5iZK7Xa//zFsAAAD//xWtcly8AQAA","verification":{}},"mode":493},{"group":{},"overwrite":true,"path":"/etc/flatcar/update.conf","user":{},"contents":{"source":"data:text/plain;charset=utf-8;base64,U0VSVkVSPWRpc2FibGVkCg==","verification":{}},"mode":420}],"filesystems":[{"device":"/dev/mapper/rootencrypted","format":"ext4","label":"ROOT"}],"luks":[{"clevis":{"custom":{}},"device":"/dev/disk/by-partlabel/ROOT","keyFile":{"verification":{}},"name":"rootencrypted","wipeVolume":true}]},"systemd":{"units":[{"contents":"[Unit]\nConditionFirstBoot=true\nOnFailure=emergency.target\nOnFailureJobMode=isolate\nAfter=first-boot-complete.target multi-user.target\n[Service]\nType=oneshot\nRemainAfterExit=yes\nExecStart=systemd-cryptenroll --tpm2-device=auto --unlock-key-file=/etc/luks/rootencrypted --tpm2-pcrs= /dev/disk/by-partlabel/ROOT\nExecStart=mv /etc/luks/rootencrypted /etc/luks/rootencrypted-bind\nExecStart=sleep 10\nExecStart=systemctl reboot\n[Install]\nWantedBy=multi-user.target\n","enabled":true,"name":"cryptenroll-helper-first.service"},{"contents":"[Unit]\nConditionFirstBoot=false\nConditionPathExists=/etc/luks/rootencrypted-bind\nOnFailure=emergency.target\nOnFailureJobMode=isolate\nBefore=update-engine.service\n[Service]\nType=oneshot\nRemainAfterExit=yes\nExecStart=systemd-cryptenroll --tpm2-device=auto --unlock-key-file=/etc/luks/rootencrypted-bind --tpm2-pcrs=4+7+8+9+11+12+13 --wipe-slot=tpm2 /dev/disk/by-partlabel/ROOT\nExecStart=mv /etc/luks/rootencrypted-bind /etc/luks/rootencrypted-bound\n[Install]\nWantedBy=multi-user.target\n","enabled":true,"name":"cryptenroll-helper-bind.service"},{"contents":"[Unit]\nDescription=QEMU metadata agent\nAfter=nss-lookup.target\nAfter=network-online.target\nWants=network-online.target\n\n[Service]\nType=oneshot\nEnvironment=OUTPUT=/run/metadata/flatcar\nExecStart=/usr/bin/mkdir --parent /run/metadata\nExecStart=/usr/bin/bash -c 'echo \"COREOS_CUSTOM_PRIVATE_IPV4=10.0.0.85\\nCOREOS_CUSTOM_PUBLIC_IPV4=10.0.0.85\\n\" \u003e ${OUTPUT}'\nExecStartPost=/usr/bin/ln -fs /run/metadata/flatcar /run/metadata/coreos\n","enabled":false,"name":"coreos-metadata.service"}]}}