Sep 2 03:03:26 prd-ubuntu20-04-docker-2c-8g-8124 passwd[648]: password for 'ubuntu' changed by 'root' Sep 2 03:03:26 prd-ubuntu20-04-docker-2c-8g-8124 sshd[735]: Server listening on 0.0.0.0 port 22. Sep 2 03:03:26 prd-ubuntu20-04-docker-2c-8g-8124 sshd[735]: Server listening on :: port 22. Sep 2 03:03:26 prd-ubuntu20-04-docker-2c-8g-8124 systemd-logind[684]: New seat seat0. Sep 2 03:03:26 prd-ubuntu20-04-docker-2c-8g-8124 systemd-logind[684]: Watching system buttons on /dev/input/event0 (Power Button) Sep 2 03:03:26 prd-ubuntu20-04-docker-2c-8g-8124 systemd-logind[684]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Sep 2 03:03:26 prd-ubuntu20-04-docker-2c-8g-8124 sshd[802]: error: kex_exchange_identification: Connection closed by remote host Sep 2 03:03:32 prd-ubuntu20-04-docker-2c-8g-8124 sshd[855]: Invalid user jenkins from 10.30.120.5 port 45336 Sep 2 03:03:32 prd-ubuntu20-04-docker-2c-8g-8124 sshd[855]: Received disconnect from 10.30.120.5 port 45336:11: Closed due to user request. [preauth] Sep 2 03:03:32 prd-ubuntu20-04-docker-2c-8g-8124 sshd[855]: Disconnected from invalid user jenkins 10.30.120.5 port 45336 [preauth] Sep 2 03:03:34 prd-ubuntu20-04-docker-2c-8g-8124 sshd[877]: Invalid user jenkins from 10.30.120.5 port 45338 Sep 2 03:03:34 prd-ubuntu20-04-docker-2c-8g-8124 sshd[877]: Received disconnect from 10.30.120.5 port 45338:11: Closed due to user request. [preauth] Sep 2 03:03:34 prd-ubuntu20-04-docker-2c-8g-8124 sshd[877]: Disconnected from invalid user jenkins 10.30.120.5 port 45338 [preauth] Sep 2 03:03:36 prd-ubuntu20-04-docker-2c-8g-8124 sshd[886]: Invalid user jenkins from 10.30.120.5 port 45340 Sep 2 03:03:36 prd-ubuntu20-04-docker-2c-8g-8124 sshd[886]: Received disconnect from 10.30.120.5 port 45340:11: Closed due to user request. [preauth] Sep 2 03:03:36 prd-ubuntu20-04-docker-2c-8g-8124 sshd[886]: Disconnected from invalid user jenkins 10.30.120.5 port 45340 [preauth] Sep 2 03:03:39 prd-ubuntu20-04-docker-2c-8g-8124 sshd[889]: Invalid user jenkins from 10.30.120.5 port 45342 Sep 2 03:03:39 prd-ubuntu20-04-docker-2c-8g-8124 sshd[889]: Received disconnect from 10.30.120.5 port 45342:11: Closed due to user request. [preauth] Sep 2 03:03:39 prd-ubuntu20-04-docker-2c-8g-8124 sshd[889]: Disconnected from invalid user jenkins 10.30.120.5 port 45342 [preauth] Sep 2 03:03:41 prd-ubuntu20-04-docker-2c-8g-8124 sshd[891]: Invalid user jenkins from 10.30.120.5 port 45344 Sep 2 03:03:41 prd-ubuntu20-04-docker-2c-8g-8124 sshd[891]: Received disconnect from 10.30.120.5 port 45344:11: Closed due to user request. [preauth] Sep 2 03:03:41 prd-ubuntu20-04-docker-2c-8g-8124 sshd[891]: Disconnected from invalid user jenkins 10.30.120.5 port 45344 [preauth] Sep 2 03:03:43 prd-ubuntu20-04-docker-2c-8g-8124 sshd[893]: Invalid user jenkins from 10.30.120.5 port 45348 Sep 2 03:03:43 prd-ubuntu20-04-docker-2c-8g-8124 sshd[893]: Received disconnect from 10.30.120.5 port 45348:11: Closed due to user request. [preauth] Sep 2 03:03:43 prd-ubuntu20-04-docker-2c-8g-8124 sshd[893]: Disconnected from invalid user jenkins 10.30.120.5 port 45348 [preauth] Sep 2 03:03:46 prd-ubuntu20-04-docker-2c-8g-8124 sshd[1163]: Invalid user jenkins from 10.30.120.5 port 45350 Sep 2 03:03:46 prd-ubuntu20-04-docker-2c-8g-8124 sshd[1163]: Received disconnect from 10.30.120.5 port 45350:11: Closed due to user request. [preauth] Sep 2 03:03:46 prd-ubuntu20-04-docker-2c-8g-8124 sshd[1163]: Disconnected from invalid user jenkins 10.30.120.5 port 45350 [preauth] Sep 2 03:03:48 prd-ubuntu20-04-docker-2c-8g-8124 sshd[1209]: Invalid user jenkins from 10.30.120.5 port 45352 Sep 2 03:03:48 prd-ubuntu20-04-docker-2c-8g-8124 sshd[1209]: Received disconnect from 10.30.120.5 port 45352:11: Closed due to user request. [preauth] Sep 2 03:03:48 prd-ubuntu20-04-docker-2c-8g-8124 sshd[1209]: Disconnected from invalid user jenkins 10.30.120.5 port 45352 [preauth] Sep 2 03:03:50 prd-ubuntu20-04-docker-2c-8g-8124 useradd[1232]: new group: name=jenkins, GID=1001 Sep 2 03:03:50 prd-ubuntu20-04-docker-2c-8g-8124 useradd[1232]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash, from=none Sep 2 03:03:50 prd-ubuntu20-04-docker-2c-8g-8124 usermod[1244]: add 'jenkins' to group 'docker' Sep 2 03:03:50 prd-ubuntu20-04-docker-2c-8g-8124 usermod[1244]: add 'jenkins' to shadow group 'docker' Sep 2 03:03:50 prd-ubuntu20-04-docker-2c-8g-8124 sshd[1234]: Received disconnect from 10.30.120.5 port 45354:11: Closed due to user request. [preauth] Sep 2 03:03:50 prd-ubuntu20-04-docker-2c-8g-8124 sshd[1234]: Disconnected from authenticating user jenkins 10.30.120.5 port 45354 [preauth] Sep 2 03:03:52 prd-ubuntu20-04-docker-2c-8g-8124 sshd[1279]: Accepted publickey for jenkins from 10.30.120.5 port 45356 ssh2: RSA SHA256:aPmPdMw/h9M56P/o8xjsZcdBWoRKGeie6FPOwnlsRmU Sep 2 03:03:52 prd-ubuntu20-04-docker-2c-8g-8124 sshd[1279]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Sep 2 03:03:52 prd-ubuntu20-04-docker-2c-8g-8124 systemd-logind[684]: New session 1 of user jenkins. Sep 2 03:03:52 prd-ubuntu20-04-docker-2c-8g-8124 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Sep 2 03:04:02 prd-ubuntu20-04-docker-2c-8g-8124 CRON[1668]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 2 03:04:02 prd-ubuntu20-04-docker-2c-8g-8124 CRON[1668]: pam_unix(cron:session): session closed for user root Sep 2 03:05:01 prd-ubuntu20-04-docker-2c-8g-8124 CRON[2206]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 2 03:05:01 prd-ubuntu20-04-docker-2c-8g-8124 CRON[2206]: pam_unix(cron:session): session closed for user root Sep 2 03:06:01 prd-ubuntu20-04-docker-2c-8g-8124 CRON[2945]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 2 03:06:01 prd-ubuntu20-04-docker-2c-8g-8124 CRON[2945]: pam_unix(cron:session): session closed for user root Sep 2 03:06:14 prd-ubuntu20-04-docker-2c-8g-8124 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/ci-management-openstack-cron ; USER=root ; COMMAND=/usr/bin/cp /var/log/auth.log /tmp Sep 2 03:06:14 prd-ubuntu20-04-docker-2c-8g-8124 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)