Family infrastructure automation (DomainAdmin)
  • PowerShell 89.6%
  • Python 6.6%
  • Batchfile 2.6%
  • Go Template 0.5%
  • Shell 0.4%
  • Other 0.3%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
2026-08-04 18:09:22 +02:00
config Fix Forgejo Authelia OAuth authorization error. 2026-08-04 17:34:08 +02:00
scripts Document DomainAdmin Forgejo remote in README. 2026-08-04 18:00:07 +02:00
sites Fix Forgejo Authelia OAuth authorization error. 2026-08-04 17:34:08 +02:00
.gitignore Replace Authentik with Authelia as family IdP on auth.attiagani.fr. 2026-08-04 04:59:18 +02:00
Apply-OpenVpnTopologySubnet.cmd Add Immich SSO, remote CUDA ML on gpubuntu, and infra automation. 2026-08-03 16:02:58 +02:00
Backup-OpenVpnConfig.cmd Add Immich SSO, remote CUDA ML on gpubuntu, and infra automation. 2026-08-03 16:02:58 +02:00
Clear-AdHomeFolderAttributes.cmd Add Immich SSO, remote CUDA ML on gpubuntu, and infra automation. 2026-08-03 16:02:58 +02:00
Configure-GitAttiaganiProxy.cmd Install Forgejo on zero behind git.attiagani.fr. 2026-08-03 16:30:19 +02:00
Configure-ImmichExternalLibrary.cmd Add Immich SSO, remote CUDA ML on gpubuntu, and infra automation. 2026-08-03 16:02:58 +02:00
Configure-ImmichRemoteMl.cmd Add Immich SSO, remote CUDA ML on gpubuntu, and infra automation. 2026-08-03 16:02:58 +02:00
Connect-MardillyTunnel.cmd Add Immich SSO, remote CUDA ML on gpubuntu, and infra automation. 2026-08-03 16:02:58 +02:00
Connect-Proxmox.cmd Add Immich SSO, remote CUDA ML on gpubuntu, and infra automation. 2026-08-03 16:02:58 +02:00
Connect-SynologyDsm.cmd Add Immich SSO, remote CUDA ML on gpubuntu, and infra automation. 2026-08-03 16:02:58 +02:00
DESIGN.md Fix Forgejo Authelia OAuth authorization error. 2026-08-04 17:34:08 +02:00
Disable-AutheliaTwoFactor.cmd Disable Authelia 2FA and restore one_factor OIDC policy. 2026-08-04 14:51:38 +02:00
Enable-AutheliaTwoFactorMail.cmd Add Authelia 2FA with OVH SMTP notifier and TOTP enforcement. 2026-08-04 14:48:04 +02:00
Enable-Usb3GpoTest.cmd Add Immich SSO, remote CUDA ML on gpubuntu, and infra automation. 2026-08-03 16:02:58 +02:00
Fix-AuthAttiaganiCert.cmd Add Immich SSO, remote CUDA ML on gpubuntu, and infra automation. 2026-08-03 16:02:58 +02:00
Fix-ForgejoSso.cmd Fix Forgejo SSO user creation and account linking. 2026-08-03 18:26:34 +02:00
Get-SynologyInventory.cmd Add Immich SSO, remote CUDA ML on gpubuntu, and infra automation. 2026-08-03 16:02:58 +02:00
INFRASTRUCTURE.md Separate Immich upload data from external Photo library on zero. 2026-08-04 16:01:34 +02:00
Initialize-SynologyApiUser.cmd Add Immich SSO, remote CUDA ML on gpubuntu, and infra automation. 2026-08-03 16:02:58 +02:00
Install-AutheliaOnOne.cmd Replace Authentik with Authelia as family IdP on auth.attiagani.fr. 2026-08-04 04:59:18 +02:00
Install-AuthentikOnZero.cmd Add Immich SSO, remote CUDA ML on gpubuntu, and infra automation. 2026-08-03 16:02:58 +02:00
Install-Forgejo.cmd Install Forgejo on zero behind git.attiagani.fr. 2026-08-03 16:30:19 +02:00
Install-ForgejoOnZero.cmd Install Forgejo on zero behind git.attiagani.fr. 2026-08-03 16:30:19 +02:00
Install-ImmichMlOnGpubuntu.cmd Add Immich SSO, remote CUDA ML on gpubuntu, and infra automation. 2026-08-03 16:02:58 +02:00
Install-MardillyVpnSiteRouting.cmd Add Immich SSO, remote CUDA ML on gpubuntu, and infra automation. 2026-08-03 16:02:58 +02:00
INVENTORY-NAS.md Separate Immich upload data from external Photo library on zero. 2026-08-04 16:01:34 +02:00
Join-SynologyDomain.cmd Add Immich SSO, remote CUDA ML on gpubuntu, and infra automation. 2026-08-03 16:02:58 +02:00
Migrate-AuthentikToAuthelia.cmd Replace Authentik with Authelia as family IdP on auth.attiagani.fr. 2026-08-04 04:59:18 +02:00
Migrate-ImmichUploadLocation.cmd Separate Immich upload data from external Photo library on zero. 2026-08-04 16:01:34 +02:00
New-WindowsTestInstall.cmd Add Immich SSO, remote CUDA ML on gpubuntu, and infra automation. 2026-08-03 16:02:58 +02:00
Push-DomainAdminToForgejo.cmd Add Forgejo remote push helper and Cursor rule for git.attiagani.fr remotes. 2026-08-04 17:59:56 +02:00
README.md Add Forgejo remote push helper and Cursor rule for git.attiagani.fr remotes. 2026-08-04 17:59:56 +02:00
Reconnect-MardillyVpn.cmd Add Immich SSO, remote CUDA ML on gpubuntu, and infra automation. 2026-08-03 16:02:58 +02:00
Remove-DeprecatedWebSites.cmd Put HA and Bourgouin behind Authentik; harden Immich/Forgejo logins. 2026-08-03 18:14:03 +02:00
Remove-PhotoPrismOnZero.cmd Put HA and Bourgouin behind Authentik; harden Immich/Forgejo logins. 2026-08-03 18:14:03 +02:00
Repair-GpubuntuGpuForImmichMl.cmd Add Immich SSO, remote CUDA ML on gpubuntu, and infra automation. 2026-08-03 16:02:58 +02:00
Repair-HostBcd.cmd Add Immich SSO, remote CUDA ML on gpubuntu, and infra automation. 2026-08-03 16:02:58 +02:00
Repair-ImmichOAuthAccount.cmd Link Immich oauthId to Authelia opaque subject after IdP migration. 2026-08-04 14:14:27 +02:00
Repair-WtgBoot.cmd Add Immich SSO, remote CUDA ML on gpubuntu, and infra automation. 2026-08-03 16:02:58 +02:00
Reset-WindowsTestInstall.cmd Add Immich SSO, remote CUDA ML on gpubuntu, and infra automation. 2026-08-03 16:02:58 +02:00
Restart-AutheliaOnOne.cmd Allow client_secret_post for Immich on Authelia OIDC token endpoint. 2026-08-04 05:34:13 +02:00
Restart-PhotoPrismOnZero.cmd Restore PhotoPrism on zero and document vu.attiagani.fr runbook. 2026-08-02 22:50:36 +02:00
Set-AutheliaSmtpCredentials.cmd Add Authelia 2FA with OVH SMTP notifier and TOTP enforcement. 2026-08-04 14:48:04 +02:00
Set-MapHDriveGpo.cmd Add Immich SSO, remote CUDA ML on gpubuntu, and infra automation. 2026-08-03 16:02:58 +02:00
Set-MapPDriveGpo.cmd Add Immich SSO, remote CUDA ML on gpubuntu, and infra automation. 2026-08-03 16:02:58 +02:00
Set-OpenVPNServiceGpo.cmd Add Immich SSO, remote CUDA ML on gpubuntu, and infra automation. 2026-08-03 16:02:58 +02:00
Set-ParentalControlBrowsersGpo.cmd Add Immich SSO, remote CUDA ML on gpubuntu, and infra automation. 2026-08-03 16:02:58 +02:00
Setup-BourgouinFamilySso.cmd Put HA and Bourgouin behind Authentik; harden Immich/Forgejo logins. 2026-08-03 18:14:03 +02:00
Setup-ForgejoFamilySso.cmd Add Forgejo family SSO via Authentik OIDC. 2026-08-03 17:12:12 +02:00
Setup-HaFamilySso.cmd Put HA and Bourgouin behind Authentik; harden Immich/Forgejo logins. 2026-08-03 18:14:03 +02:00
Setup-ImmichFamilySso.cmd Add Immich SSO, remote CUDA ML on gpubuntu, and infra automation. 2026-08-03 16:02:58 +02:00
Setup-ImmichRemoteMl.cmd Add Immich SSO, remote CUDA ML on gpubuntu, and infra automation. 2026-08-03 16:02:58 +02:00
Setup-PhotoPrismFamilySso.cmd Add Immich SSO, remote CUDA ML on gpubuntu, and infra automation. 2026-08-03 16:02:58 +02:00
Test-AdMailForForgejo.cmd Add AD mail readiness check for Forgejo OAuth auto-registration. 2026-08-04 15:14:55 +02:00
Test-AutheliaSmtp.cmd Add Authelia 2FA with OVH SMTP notifier and TOTP enforcement. 2026-08-04 14:48:04 +02:00
Test-AutheliaTwoFactor.cmd Enable Authelia 2FA without requiring SMTP credentials. 2026-08-04 14:49:38 +02:00
Test-FamilySso.cmd Add Immich SSO, remote CUDA ML on gpubuntu, and infra automation. 2026-08-03 16:02:58 +02:00
Test-ForgejoSso.cmd Add Forgejo family SSO via Authentik OIDC. 2026-08-03 17:12:12 +02:00
Test-ImmichSso.cmd Add Immich SSO, remote CUDA ML on gpubuntu, and infra automation. 2026-08-03 16:02:58 +02:00
Test-ProxmoxLogin.cmd Add Immich SSO, remote CUDA ML on gpubuntu, and infra automation. 2026-08-03 16:02:58 +02:00
Unblock-ZeroAutoBlock.cmd Unblock zero DSM Auto Block and add a reusable reset script. 2026-08-03 16:27:51 +02:00

DomainAdmin

PowerShell tooling and design documentation for dom.attiagani.fr Active Directory and Group Policy.

Document Scope
INFRASTRUCTURE.md Whole infrastructure — Crozatier & Countryside sites, WAN, DNS, VPN, Proxmox/Ollama, backup
DESIGN.md AD/GPO design — users, groups, policies, effective policy by persona; §16 public exposure & SSO posture
INVENTORY-NAS.md Live NAS audit tables (regenerate with Get-SynologyInventory.cmd; Docker §10 from config/inventory-docker-zero.md)

Parental Control — Edge / Chrome (no PAC)

GPO Parental Control applies to ATTIAGANI\Enfants (Emilie, Roxane). Web filtering no longer uses the ChildrenProxy PAC; Edge and Chrome are managed directly.

Setting Value
GPO name Parental Control
GPO ID ff1fdaef-ea49-4bf4-96ee-6e9290799eff
Edge Family Safety enabled, SafeSearch strict, Qwant Junior, incognito off
Chrome SafeSearch forced, Qwant Junior, incognito off; force sign-in
Firefox Disabled
Sign-in Emilie → emilie@attiagani.fr, Roxane → roxane@attiagani.fr (Edge + Chrome)
Set-ParentalControlBrowsersGpo.cmd

One-time (Family Safety cloud): add each child at family.microsoft.com with emilie@attiagani.fr / roxane@attiagani.fr, sign them into Edge with that account, enable web/search filters. GPO restricts browser sign-in to those addresses; Family Safety category blocking is Edge + Microsoft account only.

Quick re-apply account rules only: Set-ParentalControlBrowsersGpo.cmd -AccountsOnly

OpenVPN Service Setup (laptops)

GPO OpenVPN Service Setup runs at boot on domain computers (script skips desktops). It installs OpenVPN, creates/resets COMPUTERNAME_VPN, and deploys VPNConfig.ovpn from \\one\Public\_Admin\.

Setting Value
GPO name OpenVPN Service Setup
GPO ID ad626f78-5bcc-41c2-b3c9-e67a65b5b116
Task OpenVPNServiceSetup (SYSTEM, at startup)
Canonical script scripts/Setup-OpenVPN-Service.ps1
Set-OpenVPNServiceGpo.cmd

On a laptop: gpupdate /force /target:computer, reboot, then check C:\ProgramData\Attiagani\Logs\Setup-OpenVPN-Service.log.

OpenVPN config backup

Server + client profile backed up under config/openvpn/ (see config/openvpn/README.md).

Backup-OpenVpnConfig.cmd
Apply-OpenVpnTopologySubnet.cmd

Map H Drive GPO

GPO Map H Drive - Home maps H: to each user's home folder on \\one for all domain users at logon.

Setting Value
GPO name Map H Drive - Home
GPO ID 310ebecf-c283-4fe4-ae75-9f7fd03bc685
Link dom.attiagani.fr (domain root)
Security filter Authenticated Users
Preference User → Drive Maps → Update, Reconnect enabled
UNC path \\one\%LogonUser% (Mineur → \\one\Manu)
Label Home
Set-MapHDriveGpo.cmd

Clear legacy AD home attributes

Profile-tab homeDrive / homeDirectory on user objects duplicated the H: GPO and caused unreliable second connect attempts on Windows 11. Clear them once GPP is in place:

Clear-AdHomeFolderAttributes.cmd

Dry run: Clear-AdHomeFolderAttributes.cmd -WhatIf

Affected users (when last audited): Manu, Léa, Emilie, Roxane, Mineur.

Map P Drive GPO

GPO Map P Drive - Manu maps P: to \\one\Manu\Projects for ATTIAGANI\Manu at every logon (and on gpupdate /target:user).

Setting Value
GPO name Map P Drive - Manu
GPO ID 5f8022ac-06b2-46ae-b6b1-29445683177e
Link dom.attiagani.fr (domain root)
Security filter ATTIAGANI\Manu only (Authenticated Users: Read)
Preference User → Drive Maps → Update, Reconnect enabled
UNC path \\one\Manu\Projects
Label Projects

Deploy or update

From a domain-joined machine with GPO edit rights:

Set-MapPDriveGpo.cmd

Or directly:

.\scripts\Set-MapPDriveGpo.ps1

Verify on a client

gpupdate /force /target:user
net use H:
net use P:

In gpresult.html, look under Drive Maps — the winning GPO should be Map P Drive - Manu with location \\one\Manu\Projects.

Requirements

  • Domain: dom.attiagani.fr
  • DC: one.dom.attiagani.fr
  • RSAT GroupPolicy module
  • Write access to SYSVOL and GPO objects in AD

Synology DSM (secure API login)

DSM has no API keys for core automation — use a dedicated local user (no 2FA) and store credentials outside git:

Copy-Item .secrets\synology.credential.ps1.example .secrets\synology.credential.ps1
# edit .secrets\synology.credential.ps1 — gitignored

Account domainadmin-api is provisioned on DSM one (2026-06-28), is a member of the administrators group (full Synology administration), and is the only DSM account used by this project for one. Password lives in .secrets\synology.credential.ps1 only.

Other hosts (zero, mardilly): use .secrets\synology-<host>.credential.ps1 (see .secrets\synology-zero.credential.ps1.example, .secrets\synology-mardilly.credential.ps1.example).

Proxmox (triple7): .secrets\proxmox.credential.ps1 (see .secrets\proxmox.credential.ps1.example). Verify: Test-ProxmoxLogin.cmd. Design: DESIGN.md §12.

. .\scripts\Connect-SynologyDsm.ps1
$session = Connect-SynologyDsm
Invoke-SynologyApi -Session $session -Api 'SYNO.Core.System' -Method info -Version 3

Or set SYNOLOGY_ACCOUNT / SYNOLOGY_PASSWORD in the environment. Automation design, SSH, and multi-host credentials: DESIGN.md §11.

. .\scripts\Connect-SynologyDsm.ps1
Get-SynologySshTarget -Profile one
Get-SynologySshTarget -Profile zero
Get-SynologySshTarget -Profile mardilly
Connect-MardillyTunnel.cmd
Test-SynologyDsmLogin -Profile mardilly

Infrastructure & NAS inventory

Document Content
INFRASTRUCTURE.md Sites, WAN, DNS, VPN, Proxmox/Ollama (gpubuntu), backup topology, operational runbooks
INVENTORY-NAS.md Live audit tables from one
Get-SynologyInventory.cmd
Get-NasBackupStatus.cmd
Reconnect-MardillyVpn.cmd
Install-MardillyVpnSiteRouting.cmd
Restart-PhotoPrismOnZero.cmd
Unblock-ZeroAutoBlock.cmd
Test-ProxmoxLogin.cmd
Join-SynologyDomain.cmd -Profile zero -DomainUser Admin -DomainPassword "..."

Immich (vu.attiagani.fr)

Galerie photo sur zero (Docker Immich v3, port 2283, données Immich /volume2/Immich, librairie externe /volume2/Photo). Ingress public : one reverse proxy → https://vu.attiagani.fr/.

SSO famille (AD) : Authelia sur one (https://auth.attiagani.fr/) + OIDC Immich. Connexion avec identifiant AD (Manu, Admin, etc.) et mot de passe domaine.

Composant Hôte URL
Immich zero https://vu.attiagani.fr/
Immich ML (CUDA) gpubuntu http://192.168.6.129:3003 (GPU 1)
Authelia (LDAP AD + OIDC) one https://auth.attiagani.fr/
Setup-ImmichFamilySso.cmd       REM déploiement complet (Immich + Authelia + proxy)
Repair-GpubuntuGpuForImmichMl.cmd  REM GPU stack + Immich ML CUDA (GPU 1)
Setup-ImmichRemoteMl.ps1        REM ML distant sur gpubuntu + config zero (Ollama intact)
Install-ImmichMlOnGpubuntu.cmd  REM ML seul sur gpubuntu
Configure-ImmichRemoteMl.cmd    REM pointer zero vers ML distant
Configure-ImmichExternalLibrary.cmd  REM librairie externe /volume2/Photo + scan
Migrate-ImmichUploadLocation.cmd     REM données Immich -> /volume2/Immich (hors Photo)
Test-ImmichSso.cmd              REM vérifie chaque étape (exit 1 si échec)
Repair-ImmichOAuthAccount.cmd   REM lie oauthId Immich au sub Authelia (migration Authentik)
Fix-AuthAttiaganiCert.cmd       REM corrige cert LE auth.attiagani.fr (retire cert AD)
Restart-PhotoPrismOnZero.cmd    REM rollback PhotoPrism (containers conservés)

PhotoPrism containers removed (2026-08-03) — Remove-PhotoPrismOnZero.cmd. Détails : INVENTORY-NAS.md §10, DESIGN.md §16.

DSM media indexing (one, zero, mardilly)

Pas de miniatures DSM sur les NAS photo — galerie famille via Immich sur zero. Arrête et masque les daemons synoindex / thumbd (persiste au reboot).

Hôte Partage Chemin Photo
one Photo /volume1/Photo
zero Photo /volume2/Photo
mardilly AttiaGani /volume1/AttiaGani/Photo
Stop-OneMediaIndexing.cmd
Stop-ZeroMediaIndexing.cmd
Stop-MardillyMediaIndexing.cmd
Remove-ZeroMardillyPhotoEadir.cmd   REM supprime les @eaDir DSM restants
Start-OneMediaIndexing.cmd   REM redémarre l'indexation DSM sur one uniquement

Forgejo (git.attiagani.fr)

Forgejo Git sur zero (Docker Forgejo 16, port 3000, SQLite). Ingress : one reverse proxy → https://git.attiagani.fr/. Clone HTTPS (SSH embarqué désactivé — bind bloqué par Docker Synology).

SSO famille (AD) : Authelia + OIDC Forgejo. Connexion avec identifiant AD (Manu, Admin, etc.) — mot de passe local désactivé sur l'UI web. Nouveaux comptes AD : création automatique au 1er login OAuth (OPENID_CONNECT_SCOPES = openid profile email dans app.ini — obligatoire pour Forgejo). Changement de compte : logout Forgejo coupe aussi la session Authelia (footer custom), puis reconnexion OAuth normale.

Composant Hôte URL / chemin
Forgejo zero https://git.attiagani.fr/
Ce dépôt Forgejo https://git.attiagani.fr/Manu/DomainAdmin.git
Authelia (OIDC) one https://auth.attiagani.fr/
Stack zero /volume2/docker/forgejo
Secrets local .secrets/forgejo.credential.ps1
Install-Forgejo.cmd                 REM stack + proxy + Let's Encrypt
Setup-ForgejoFamilySso.cmd          REM Authelia OIDC + Forgejo OAuth
Test-ForgejoSso.cmd                 REM vérifie la chaîne SSO (exit 1 si échec)
Repair-ForgejoOAuthAccount.cmd      REM lie compte bootstrap (ex. Manu) au SSO Authelia
Fix-ForgejoSso.cmd                  REM scopes OIDC email/profile (auto-register)
Push-DomainAdminToForgejo.cmd       REM push ce dépôt vers Forgejo (remote origin)
Install-AutheliaOnOne.cmd           REM IdP Authelia sur one (port 9000)
Migrate-AuthentikToAuthelia.cmd    REM migration complète Authentik → Authelia
Install-ForgejoOnZero.cmd           REM conteneur seul
Configure-GitAttiaganiProxy.cmd     REM reverse proxy + cert

Site doc : sites/git.attiagani.fr.md.

Home Assistant (ha.attiagani.fr)

Reverse proxy onezero:8123 + hass-oidc-auth (Authelia). Kiosk Surface : trusted_networks LAN. Secours : ?skip_oidc_redirect=true.

Setup-HaFamilySso.cmd

Site : sites/ha.attiagani.fr.md.

Bourgouin (bourgouin.attiagani.fr)

Planning Flask derrière Authelia OIDC (/login → IdP). Fallback mot de passe : ?local=1.

Setup-BourgouinFamilySso.cmd

Authelia (auth.attiagani.fr)

IdP familial sur one (Docker Authelia 4.38 + Redis, port 9000 → nginx auth.attiagani.fr). Authentification LDAP contre Samba AD ; OIDC pour Immich, Forgejo, Home Assistant et Bourgouin.

2FA : désactivée par défaut (one_factor). Optionnel : Enable-AutheliaTwoFactorMail.cmd / Disable-AutheliaTwoFactor.cmd.

Composant Hôte Chemin
Stack one /volume1/docker/authelia
Config one configuration.yml (généré)
Secrets local .secrets/authelia.credential.ps1
Install-AutheliaOnOne.cmd           REM déploie Authelia + génère configuration.yml
Set-AutheliaSmtpCredentials.cmd     REM optionnel : alertes mail OVH
Enable-AutheliaTwoFactorMail.cmd    REM active TOTP + two_factor OIDC
Disable-AutheliaTwoFactor.cmd       REM repasse en one_factor
Test-AutheliaTwoFactor.cmd          REM vérifie config 2FA
Migrate-AuthentikToAuthelia.cmd    REM arrête Authentik, installe Authelia, reconfigure apps
Finish-AutheliaMigration.ps1       REM Forgejo + HA + Bourgouin (sans Immich)
Test-ImmichSso.cmd                 REM vérifie Immich + Authelia
Test-ForgejoSso.cmd                REM vérifie Forgejo + Authelia

Migration (2026-08-04) : Authentik remplacé par Authelia. Issuer OIDC : https://auth.attiagani.fr (plus de slug /application/o/.../). Scripts Authentik conservés pour référence (Install-AuthentikOnOne.cmd, Stop-AuthentikOnOne.ps1).

Cleanup

Remove-DeprecatedWebSites.cmd   REM adm.attiagani.fr + paste.attiagani.fr
Remove-PhotoPrismOnZero.cmd     REM containers PhotoPrism + MariaDB

Windows To Go (GPO test disk for other machines)

Portable Windows 11 Pro on the USB disk (D:). Built from this laptop; booted on other PCs via firmware USB boot.

This laptop's BCD is never modified by install/reset scripts.

Item Location
WTG disk D: (USB, label Win11-WTG)
Staged image C:\ProgramData\Attiagani\WimStage\install.wim
Tools on WTG D:\Attiagani\
New-WindowsTestInstall.cmd      REM first build (~1 h)
Reset-WindowsTestInstall.cmd    REM refresh WTG image
Repair-WtgBoot.cmd              REM fix WTG boot on D: only
Enable-Usb3GpoTest.cmd          REM USB 3.0 (from build machine, disk as D:)
Repair-HostBcd.cmd              REM emergency: fix THIS laptop only (if BCD was damaged)

On a test machine: plug USB disk → firmware boot from USB → join dom.attiagani.fr → run D:\Attiagani\Test-GpoPolicy.ps1.

Test checklist: French keyboard GPO, H: map, role GPOs (Parental Control / P: drive), Windows Hello.