Sep 2 15:03:25 prd-ubuntu20-04-docker-2c-8g-8167 passwd[652]: password for 'ubuntu' changed by 'root' Sep 2 15:03:25 prd-ubuntu20-04-docker-2c-8g-8167 sshd[748]: Server listening on 0.0.0.0 port 22. Sep 2 15:03:25 prd-ubuntu20-04-docker-2c-8g-8167 sshd[748]: Server listening on :: port 22. Sep 2 15:03:25 prd-ubuntu20-04-docker-2c-8g-8167 sshd[787]: error: kex_exchange_identification: Connection closed by remote host Sep 2 15:03:25 prd-ubuntu20-04-docker-2c-8g-8167 systemd-logind[694]: New seat seat0. Sep 2 15:03:25 prd-ubuntu20-04-docker-2c-8g-8167 systemd-logind[694]: Watching system buttons on /dev/input/event0 (Power Button) Sep 2 15:03:25 prd-ubuntu20-04-docker-2c-8g-8167 systemd-logind[694]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Sep 2 15:03:31 prd-ubuntu20-04-docker-2c-8g-8167 sshd[891]: Invalid user jenkins from 10.30.120.5 port 38052 Sep 2 15:03:32 prd-ubuntu20-04-docker-2c-8g-8167 sshd[891]: Received disconnect from 10.30.120.5 port 38052:11: Closed due to user request. [preauth] Sep 2 15:03:32 prd-ubuntu20-04-docker-2c-8g-8167 sshd[891]: Disconnected from invalid user jenkins 10.30.120.5 port 38052 [preauth] Sep 2 15:03:34 prd-ubuntu20-04-docker-2c-8g-8167 sshd[894]: Invalid user jenkins from 10.30.120.5 port 38060 Sep 2 15:03:34 prd-ubuntu20-04-docker-2c-8g-8167 sshd[894]: Received disconnect from 10.30.120.5 port 38060:11: Closed due to user request. [preauth] Sep 2 15:03:34 prd-ubuntu20-04-docker-2c-8g-8167 sshd[894]: Disconnected from invalid user jenkins 10.30.120.5 port 38060 [preauth] Sep 2 15:03:36 prd-ubuntu20-04-docker-2c-8g-8167 sshd[896]: Invalid user jenkins from 10.30.120.5 port 38064 Sep 2 15:03:36 prd-ubuntu20-04-docker-2c-8g-8167 sshd[896]: Received disconnect from 10.30.120.5 port 38064:11: Closed due to user request. [preauth] Sep 2 15:03:36 prd-ubuntu20-04-docker-2c-8g-8167 sshd[896]: Disconnected from invalid user jenkins 10.30.120.5 port 38064 [preauth] Sep 2 15:03:38 prd-ubuntu20-04-docker-2c-8g-8167 sshd[898]: Invalid user jenkins from 10.30.120.5 port 38066 Sep 2 15:03:38 prd-ubuntu20-04-docker-2c-8g-8167 sshd[898]: Received disconnect from 10.30.120.5 port 38066:11: Closed due to user request. [preauth] Sep 2 15:03:38 prd-ubuntu20-04-docker-2c-8g-8167 sshd[898]: Disconnected from invalid user jenkins 10.30.120.5 port 38066 [preauth] Sep 2 15:03:40 prd-ubuntu20-04-docker-2c-8g-8167 sshd[900]: Invalid user jenkins from 10.30.120.5 port 38068 Sep 2 15:03:40 prd-ubuntu20-04-docker-2c-8g-8167 sshd[900]: Received disconnect from 10.30.120.5 port 38068:11: Closed due to user request. [preauth] Sep 2 15:03:40 prd-ubuntu20-04-docker-2c-8g-8167 sshd[900]: Disconnected from invalid user jenkins 10.30.120.5 port 38068 [preauth] Sep 2 15:03:42 prd-ubuntu20-04-docker-2c-8g-8167 sshd[902]: Invalid user jenkins from 10.30.120.5 port 38070 Sep 2 15:03:42 prd-ubuntu20-04-docker-2c-8g-8167 sshd[902]: Received disconnect from 10.30.120.5 port 38070:11: Closed due to user request. [preauth] Sep 2 15:03:42 prd-ubuntu20-04-docker-2c-8g-8167 sshd[902]: Disconnected from invalid user jenkins 10.30.120.5 port 38070 [preauth] Sep 2 15:03:44 prd-ubuntu20-04-docker-2c-8g-8167 sshd[1169]: Invalid user jenkins from 10.30.120.5 port 38072 Sep 2 15:03:44 prd-ubuntu20-04-docker-2c-8g-8167 sshd[1169]: Received disconnect from 10.30.120.5 port 38072:11: Closed due to user request. [preauth] Sep 2 15:03:44 prd-ubuntu20-04-docker-2c-8g-8167 sshd[1169]: Disconnected from invalid user jenkins 10.30.120.5 port 38072 [preauth] Sep 2 15:03:46 prd-ubuntu20-04-docker-2c-8g-8167 sshd[1215]: Invalid user jenkins from 10.30.120.5 port 38074 Sep 2 15:03:46 prd-ubuntu20-04-docker-2c-8g-8167 sshd[1215]: Received disconnect from 10.30.120.5 port 38074:11: Closed due to user request. [preauth] Sep 2 15:03:46 prd-ubuntu20-04-docker-2c-8g-8167 sshd[1215]: Disconnected from invalid user jenkins 10.30.120.5 port 38074 [preauth] Sep 2 15:03:49 prd-ubuntu20-04-docker-2c-8g-8167 useradd[1240]: new group: name=jenkins, GID=1001 Sep 2 15:03:49 prd-ubuntu20-04-docker-2c-8g-8167 useradd[1240]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash, from=none Sep 2 15:03:49 prd-ubuntu20-04-docker-2c-8g-8167 usermod[1252]: add 'jenkins' to group 'docker' Sep 2 15:03:49 prd-ubuntu20-04-docker-2c-8g-8167 usermod[1252]: add 'jenkins' to shadow group 'docker' Sep 2 15:03:49 prd-ubuntu20-04-docker-2c-8g-8167 sshd[1242]: Received disconnect from 10.30.120.5 port 38076:11: Closed due to user request. [preauth] Sep 2 15:03:49 prd-ubuntu20-04-docker-2c-8g-8167 sshd[1242]: Disconnected from authenticating user jenkins 10.30.120.5 port 38076 [preauth] Sep 2 15:03:51 prd-ubuntu20-04-docker-2c-8g-8167 sshd[1287]: Accepted publickey for jenkins from 10.30.120.5 port 38080 ssh2: RSA SHA256:aPmPdMw/h9M56P/o8xjsZcdBWoRKGeie6FPOwnlsRmU Sep 2 15:03:51 prd-ubuntu20-04-docker-2c-8g-8167 sshd[1287]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Sep 2 15:03:51 prd-ubuntu20-04-docker-2c-8g-8167 systemd-logind[694]: New session 1 of user jenkins. Sep 2 15:03:51 prd-ubuntu20-04-docker-2c-8g-8167 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Sep 2 15:04:01 prd-ubuntu20-04-docker-2c-8g-8167 CRON[1788]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 2 15:04:01 prd-ubuntu20-04-docker-2c-8g-8167 CRON[1788]: pam_unix(cron:session): session closed for user root Sep 2 15:05:01 prd-ubuntu20-04-docker-2c-8g-8167 CRON[2224]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 2 15:05:01 prd-ubuntu20-04-docker-2c-8g-8167 CRON[2224]: pam_unix(cron:session): session closed for user root Sep 2 15:06:01 prd-ubuntu20-04-docker-2c-8g-8167 CRON[3090]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 2 15:06:01 prd-ubuntu20-04-docker-2c-8g-8167 CRON[3090]: pam_unix(cron:session): session closed for user root Sep 2 15:06:10 prd-ubuntu20-04-docker-2c-8g-8167 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/ci-management-openstack-cron ; USER=root ; COMMAND=/usr/bin/cp /var/log/auth.log /tmp Sep 2 15:06:10 prd-ubuntu20-04-docker-2c-8g-8167 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)