Sep 29 16:14:46 prd-ubuntu20-04-docker-2c-8g-9755 passwd[650]: password for 'ubuntu' changed by 'root' Sep 29 16:14:46 prd-ubuntu20-04-docker-2c-8g-9755 sshd[735]: Server listening on 0.0.0.0 port 22. Sep 29 16:14:46 prd-ubuntu20-04-docker-2c-8g-9755 sshd[735]: Server listening on :: port 22. Sep 29 16:14:46 prd-ubuntu20-04-docker-2c-8g-9755 systemd-logind[686]: New seat seat0. Sep 29 16:14:46 prd-ubuntu20-04-docker-2c-8g-9755 systemd-logind[686]: Watching system buttons on /dev/input/event0 (Power Button) Sep 29 16:14:46 prd-ubuntu20-04-docker-2c-8g-9755 systemd-logind[686]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Sep 29 16:14:47 prd-ubuntu20-04-docker-2c-8g-9755 sshd[803]: error: kex_exchange_identification: Connection closed by remote host Sep 29 16:14:51 prd-ubuntu20-04-docker-2c-8g-9755 sshd[862]: Invalid user jenkins from 10.30.120.5 port 50724 Sep 29 16:14:51 prd-ubuntu20-04-docker-2c-8g-9755 sshd[862]: Received disconnect from 10.30.120.5 port 50724:11: Closed due to user request. [preauth] Sep 29 16:14:51 prd-ubuntu20-04-docker-2c-8g-9755 sshd[862]: Disconnected from invalid user jenkins 10.30.120.5 port 50724 [preauth] Sep 29 16:14:57 prd-ubuntu20-04-docker-2c-8g-9755 sshd[879]: Invalid user jenkins from 10.30.120.5 port 50728 Sep 29 16:14:57 prd-ubuntu20-04-docker-2c-8g-9755 sshd[879]: Received disconnect from 10.30.120.5 port 50728:11: Closed due to user request. [preauth] Sep 29 16:14:57 prd-ubuntu20-04-docker-2c-8g-9755 sshd[879]: Disconnected from invalid user jenkins 10.30.120.5 port 50728 [preauth] Sep 29 16:14:59 prd-ubuntu20-04-docker-2c-8g-9755 sshd[904]: Invalid user jenkins from 10.30.120.5 port 50736 Sep 29 16:14:59 prd-ubuntu20-04-docker-2c-8g-9755 sshd[904]: Received disconnect from 10.30.120.5 port 50736:11: Closed due to user request. [preauth] Sep 29 16:14:59 prd-ubuntu20-04-docker-2c-8g-9755 sshd[904]: Disconnected from invalid user jenkins 10.30.120.5 port 50736 [preauth] Sep 29 16:15:01 prd-ubuntu20-04-docker-2c-8g-9755 CRON[907]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 29 16:15:01 prd-ubuntu20-04-docker-2c-8g-9755 CRON[907]: pam_unix(cron:session): session closed for user root Sep 29 16:15:01 prd-ubuntu20-04-docker-2c-8g-9755 sshd[910]: Invalid user jenkins from 10.30.120.5 port 50740 Sep 29 16:15:01 prd-ubuntu20-04-docker-2c-8g-9755 sshd[910]: Received disconnect from 10.30.120.5 port 50740:11: Closed due to user request. [preauth] Sep 29 16:15:01 prd-ubuntu20-04-docker-2c-8g-9755 sshd[910]: Disconnected from invalid user jenkins 10.30.120.5 port 50740 [preauth] Sep 29 16:15:03 prd-ubuntu20-04-docker-2c-8g-9755 sshd[912]: Invalid user jenkins from 10.30.120.5 port 50752 Sep 29 16:15:03 prd-ubuntu20-04-docker-2c-8g-9755 sshd[912]: Received disconnect from 10.30.120.5 port 50752:11: Closed due to user request. [preauth] Sep 29 16:15:03 prd-ubuntu20-04-docker-2c-8g-9755 sshd[912]: Disconnected from invalid user jenkins 10.30.120.5 port 50752 [preauth] Sep 29 16:15:05 prd-ubuntu20-04-docker-2c-8g-9755 sshd[914]: Invalid user jenkins from 10.30.120.5 port 50754 Sep 29 16:15:05 prd-ubuntu20-04-docker-2c-8g-9755 sshd[914]: Received disconnect from 10.30.120.5 port 50754:11: Closed due to user request. [preauth] Sep 29 16:15:05 prd-ubuntu20-04-docker-2c-8g-9755 sshd[914]: Disconnected from invalid user jenkins 10.30.120.5 port 50754 [preauth] Sep 29 16:15:08 prd-ubuntu20-04-docker-2c-8g-9755 sshd[1197]: Invalid user jenkins from 10.30.120.5 port 50756 Sep 29 16:15:08 prd-ubuntu20-04-docker-2c-8g-9755 sshd[1197]: Received disconnect from 10.30.120.5 port 50756:11: Closed due to user request. [preauth] Sep 29 16:15:08 prd-ubuntu20-04-docker-2c-8g-9755 sshd[1197]: Disconnected from invalid user jenkins 10.30.120.5 port 50756 [preauth] Sep 29 16:15:10 prd-ubuntu20-04-docker-2c-8g-9755 sshd[1229]: Invalid user jenkins from 10.30.120.5 port 50760 Sep 29 16:15:12 prd-ubuntu20-04-docker-2c-8g-9755 sshd[1229]: Received disconnect from 10.30.120.5 port 50760:11: Closed due to user request. [preauth] Sep 29 16:15:12 prd-ubuntu20-04-docker-2c-8g-9755 sshd[1229]: Disconnected from invalid user jenkins 10.30.120.5 port 50760 [preauth] Sep 29 16:15:13 prd-ubuntu20-04-docker-2c-8g-9755 useradd[1252]: new group: name=jenkins, GID=1001 Sep 29 16:15:13 prd-ubuntu20-04-docker-2c-8g-9755 useradd[1252]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash, from=none Sep 29 16:15:13 prd-ubuntu20-04-docker-2c-8g-9755 usermod[1262]: add 'jenkins' to group 'docker' Sep 29 16:15:13 prd-ubuntu20-04-docker-2c-8g-9755 usermod[1262]: add 'jenkins' to shadow group 'docker' Sep 29 16:15:14 prd-ubuntu20-04-docker-2c-8g-9755 sshd[1275]: Accepted publickey for jenkins from 10.30.120.5 port 50762 ssh2: RSA SHA256:aPmPdMw/h9M56P/o8xjsZcdBWoRKGeie6FPOwnlsRmU Sep 29 16:15:14 prd-ubuntu20-04-docker-2c-8g-9755 sshd[1275]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Sep 29 16:15:14 prd-ubuntu20-04-docker-2c-8g-9755 systemd-logind[686]: New session 2 of user jenkins. Sep 29 16:15:14 prd-ubuntu20-04-docker-2c-8g-9755 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Sep 29 16:16:01 prd-ubuntu20-04-docker-2c-8g-9755 CRON[2055]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 29 16:16:01 prd-ubuntu20-04-docker-2c-8g-9755 CRON[2055]: pam_unix(cron:session): session closed for user root Sep 29 16:17:01 prd-ubuntu20-04-docker-2c-8g-9755 CRON[2528]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 29 16:17:01 prd-ubuntu20-04-docker-2c-8g-9755 CRON[2529]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 29 16:17:01 prd-ubuntu20-04-docker-2c-8g-9755 CRON[2529]: pam_unix(cron:session): session closed for user root Sep 29 16:17:01 prd-ubuntu20-04-docker-2c-8g-9755 CRON[2528]: pam_unix(cron:session): session closed for user root Sep 29 16:17:40 prd-ubuntu20-04-docker-2c-8g-9755 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/ci-management-openstack-cron ; USER=root ; COMMAND=/usr/bin/cp /var/log/auth.log /tmp Sep 29 16:17:40 prd-ubuntu20-04-docker-2c-8g-9755 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)