May 7 19:03:43 prd-ubuntu20-04-docker-2c-8g-1068 passwd[673]: password for 'ubuntu' changed by 'root' May 7 19:03:43 prd-ubuntu20-04-docker-2c-8g-1068 sshd[754]: Server listening on 0.0.0.0 port 22. May 7 19:03:43 prd-ubuntu20-04-docker-2c-8g-1068 sshd[754]: Server listening on :: port 22. May 7 19:03:43 prd-ubuntu20-04-docker-2c-8g-1068 systemd-logind[713]: New seat seat0. May 7 19:03:43 prd-ubuntu20-04-docker-2c-8g-1068 systemd-logind[713]: Watching system buttons on /dev/input/event0 (Power Button) May 7 19:03:43 prd-ubuntu20-04-docker-2c-8g-1068 systemd-logind[713]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) May 7 19:03:46 prd-ubuntu20-04-docker-2c-8g-1068 sshd[907]: error: kex_exchange_identification: Connection closed by remote host May 7 19:03:51 prd-ubuntu20-04-docker-2c-8g-1068 sshd[914]: Invalid user jenkins from 10.30.120.5 port 46500 May 7 19:03:51 prd-ubuntu20-04-docker-2c-8g-1068 sshd[914]: Received disconnect from 10.30.120.5 port 46500:11: Closed due to user request. [preauth] May 7 19:03:51 prd-ubuntu20-04-docker-2c-8g-1068 sshd[914]: Disconnected from invalid user jenkins 10.30.120.5 port 46500 [preauth] May 7 19:03:53 prd-ubuntu20-04-docker-2c-8g-1068 sshd[917]: Invalid user jenkins from 10.30.120.5 port 46504 May 7 19:03:53 prd-ubuntu20-04-docker-2c-8g-1068 sshd[917]: Received disconnect from 10.30.120.5 port 46504:11: Closed due to user request. [preauth] May 7 19:03:53 prd-ubuntu20-04-docker-2c-8g-1068 sshd[917]: Disconnected from invalid user jenkins 10.30.120.5 port 46504 [preauth] May 7 19:03:55 prd-ubuntu20-04-docker-2c-8g-1068 sshd[919]: Invalid user jenkins from 10.30.120.5 port 46526 May 7 19:03:55 prd-ubuntu20-04-docker-2c-8g-1068 sshd[919]: Received disconnect from 10.30.120.5 port 46526:11: Closed due to user request. [preauth] May 7 19:03:55 prd-ubuntu20-04-docker-2c-8g-1068 sshd[919]: Disconnected from invalid user jenkins 10.30.120.5 port 46526 [preauth] May 7 19:03:57 prd-ubuntu20-04-docker-2c-8g-1068 sshd[921]: Invalid user jenkins from 10.30.120.5 port 46528 May 7 19:03:57 prd-ubuntu20-04-docker-2c-8g-1068 sshd[921]: Received disconnect from 10.30.120.5 port 46528:11: Closed due to user request. [preauth] May 7 19:03:57 prd-ubuntu20-04-docker-2c-8g-1068 sshd[921]: Disconnected from invalid user jenkins 10.30.120.5 port 46528 [preauth] May 7 19:03:59 prd-ubuntu20-04-docker-2c-8g-1068 sshd[923]: Invalid user jenkins from 10.30.120.5 port 46530 May 7 19:04:00 prd-ubuntu20-04-docker-2c-8g-1068 sshd[923]: Received disconnect from 10.30.120.5 port 46530:11: Closed due to user request. [preauth] May 7 19:04:00 prd-ubuntu20-04-docker-2c-8g-1068 sshd[923]: Disconnected from invalid user jenkins 10.30.120.5 port 46530 [preauth] May 7 19:04:01 prd-ubuntu20-04-docker-2c-8g-1068 CRON[925]: pam_unix(cron:session): session opened for user root by (uid=0) May 7 19:04:01 prd-ubuntu20-04-docker-2c-8g-1068 CRON[925]: pam_unix(cron:session): session closed for user root May 7 19:04:02 prd-ubuntu20-04-docker-2c-8g-1068 sshd[935]: Invalid user jenkins from 10.30.120.5 port 46532 May 7 19:04:02 prd-ubuntu20-04-docker-2c-8g-1068 sshd[935]: Received disconnect from 10.30.120.5 port 46532:11: Closed due to user request. [preauth] May 7 19:04:02 prd-ubuntu20-04-docker-2c-8g-1068 sshd[935]: Disconnected from invalid user jenkins 10.30.120.5 port 46532 [preauth] May 7 19:04:05 prd-ubuntu20-04-docker-2c-8g-1068 sshd[1122]: Invalid user jenkins from 10.30.120.5 port 46536 May 7 19:04:05 prd-ubuntu20-04-docker-2c-8g-1068 sshd[1122]: Received disconnect from 10.30.120.5 port 46536:11: Closed due to user request. [preauth] May 7 19:04:05 prd-ubuntu20-04-docker-2c-8g-1068 sshd[1122]: Disconnected from invalid user jenkins 10.30.120.5 port 46536 [preauth] May 7 19:04:07 prd-ubuntu20-04-docker-2c-8g-1068 sshd[1161]: Invalid user jenkins from 10.30.120.5 port 46538 May 7 19:04:07 prd-ubuntu20-04-docker-2c-8g-1068 sshd[1161]: Received disconnect from 10.30.120.5 port 46538:11: Closed due to user request. [preauth] May 7 19:04:07 prd-ubuntu20-04-docker-2c-8g-1068 sshd[1161]: Disconnected from invalid user jenkins 10.30.120.5 port 46538 [preauth] May 7 19:04:09 prd-ubuntu20-04-docker-2c-8g-1068 useradd[1193]: new group: name=jenkins, GID=1001 May 7 19:04:09 prd-ubuntu20-04-docker-2c-8g-1068 useradd[1193]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash, from=none May 7 19:04:09 prd-ubuntu20-04-docker-2c-8g-1068 usermod[1203]: add 'jenkins' to group 'docker' May 7 19:04:09 prd-ubuntu20-04-docker-2c-8g-1068 usermod[1203]: add 'jenkins' to shadow group 'docker' May 7 19:04:09 prd-ubuntu20-04-docker-2c-8g-1068 sshd[1204]: Received disconnect from 10.30.120.5 port 46540:11: Closed due to user request. [preauth] May 7 19:04:09 prd-ubuntu20-04-docker-2c-8g-1068 sshd[1204]: Disconnected from authenticating user jenkins 10.30.120.5 port 46540 [preauth] May 7 19:04:11 prd-ubuntu20-04-docker-2c-8g-1068 sshd[1242]: Accepted publickey for jenkins from 10.30.120.5 port 46542 ssh2: RSA SHA256:aPmPdMw/h9M56P/o8xjsZcdBWoRKGeie6FPOwnlsRmU May 7 19:04:11 prd-ubuntu20-04-docker-2c-8g-1068 sshd[1242]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) May 7 19:04:11 prd-ubuntu20-04-docker-2c-8g-1068 systemd-logind[713]: New session 2 of user jenkins. May 7 19:04:11 prd-ubuntu20-04-docker-2c-8g-1068 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) May 7 19:05:02 prd-ubuntu20-04-docker-2c-8g-1068 CRON[2034]: pam_unix(cron:session): session opened for user root by (uid=0) May 7 19:05:02 prd-ubuntu20-04-docker-2c-8g-1068 CRON[2034]: pam_unix(cron:session): session closed for user root May 7 19:06:01 prd-ubuntu20-04-docker-2c-8g-1068 CRON[2694]: pam_unix(cron:session): session opened for user root by (uid=0) May 7 19:06:01 prd-ubuntu20-04-docker-2c-8g-1068 CRON[2694]: pam_unix(cron:session): session closed for user root May 7 19:06:51 prd-ubuntu20-04-docker-2c-8g-1068 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/ci-management-openstack-cron ; USER=root ; COMMAND=/usr/bin/cp /var/log/auth.log /tmp May 7 19:06:51 prd-ubuntu20-04-docker-2c-8g-1068 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)