Jan 22 05:04:36 prd-ubuntu20-04-docker-2c-8g-947 passwd[679]: password for 'ubuntu' changed by 'root' Jan 22 05:04:36 prd-ubuntu20-04-docker-2c-8g-947 systemd-logind[724]: New seat seat0. Jan 22 05:04:36 prd-ubuntu20-04-docker-2c-8g-947 systemd-logind[724]: Watching system buttons on /dev/input/event0 (Power Button) Jan 22 05:04:36 prd-ubuntu20-04-docker-2c-8g-947 systemd-logind[724]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Jan 22 05:04:36 prd-ubuntu20-04-docker-2c-8g-947 sshd[780]: Server listening on 0.0.0.0 port 22. Jan 22 05:04:36 prd-ubuntu20-04-docker-2c-8g-947 sshd[780]: Server listening on :: port 22. Jan 22 05:04:38 prd-ubuntu20-04-docker-2c-8g-947 sshd[924]: error: kex_exchange_identification: Connection closed by remote host Jan 22 05:04:43 prd-ubuntu20-04-docker-2c-8g-947 sshd[933]: Invalid user jenkins from 10.30.120.5 port 35158 Jan 22 05:04:43 prd-ubuntu20-04-docker-2c-8g-947 sshd[933]: Received disconnect from 10.30.120.5 port 35158:11: Closed due to user request. [preauth] Jan 22 05:04:43 prd-ubuntu20-04-docker-2c-8g-947 sshd[933]: Disconnected from invalid user jenkins 10.30.120.5 port 35158 [preauth] Jan 22 05:04:45 prd-ubuntu20-04-docker-2c-8g-947 sshd[935]: Invalid user jenkins from 10.30.120.5 port 35160 Jan 22 05:04:45 prd-ubuntu20-04-docker-2c-8g-947 sshd[935]: Received disconnect from 10.30.120.5 port 35160:11: Closed due to user request. [preauth] Jan 22 05:04:45 prd-ubuntu20-04-docker-2c-8g-947 sshd[935]: Disconnected from invalid user jenkins 10.30.120.5 port 35160 [preauth] Jan 22 05:04:47 prd-ubuntu20-04-docker-2c-8g-947 sshd[937]: Invalid user jenkins from 10.30.120.5 port 35162 Jan 22 05:04:47 prd-ubuntu20-04-docker-2c-8g-947 sshd[937]: Received disconnect from 10.30.120.5 port 35162:11: Closed due to user request. [preauth] Jan 22 05:04:47 prd-ubuntu20-04-docker-2c-8g-947 sshd[937]: Disconnected from invalid user jenkins 10.30.120.5 port 35162 [preauth] Jan 22 05:04:49 prd-ubuntu20-04-docker-2c-8g-947 sshd[939]: Invalid user jenkins from 10.30.120.5 port 35164 Jan 22 05:04:49 prd-ubuntu20-04-docker-2c-8g-947 sshd[939]: Received disconnect from 10.30.120.5 port 35164:11: Closed due to user request. [preauth] Jan 22 05:04:49 prd-ubuntu20-04-docker-2c-8g-947 sshd[939]: Disconnected from invalid user jenkins 10.30.120.5 port 35164 [preauth] Jan 22 05:04:51 prd-ubuntu20-04-docker-2c-8g-947 sshd[941]: Invalid user jenkins from 10.30.120.5 port 35166 Jan 22 05:04:51 prd-ubuntu20-04-docker-2c-8g-947 sshd[941]: Received disconnect from 10.30.120.5 port 35166:11: Closed due to user request. [preauth] Jan 22 05:04:51 prd-ubuntu20-04-docker-2c-8g-947 sshd[941]: Disconnected from invalid user jenkins 10.30.120.5 port 35166 [preauth] Jan 22 05:04:53 prd-ubuntu20-04-docker-2c-8g-947 sshd[957]: Invalid user jenkins from 10.30.120.5 port 35168 Jan 22 05:04:53 prd-ubuntu20-04-docker-2c-8g-947 sshd[957]: Received disconnect from 10.30.120.5 port 35168:11: Closed due to user request. [preauth] Jan 22 05:04:53 prd-ubuntu20-04-docker-2c-8g-947 sshd[957]: Disconnected from invalid user jenkins 10.30.120.5 port 35168 [preauth] Jan 22 05:04:56 prd-ubuntu20-04-docker-2c-8g-947 sshd[1260]: Invalid user jenkins from 10.30.120.5 port 35170 Jan 22 05:04:56 prd-ubuntu20-04-docker-2c-8g-947 sshd[1260]: Received disconnect from 10.30.120.5 port 35170:11: Closed due to user request. [preauth] Jan 22 05:04:56 prd-ubuntu20-04-docker-2c-8g-947 sshd[1260]: Disconnected from invalid user jenkins 10.30.120.5 port 35170 [preauth] Jan 22 05:04:58 prd-ubuntu20-04-docker-2c-8g-947 sshd[1268]: Invalid user jenkins from 10.30.120.5 port 35174 Jan 22 05:04:58 prd-ubuntu20-04-docker-2c-8g-947 sshd[1268]: Received disconnect from 10.30.120.5 port 35174:11: Closed due to user request. [preauth] Jan 22 05:04:58 prd-ubuntu20-04-docker-2c-8g-947 sshd[1268]: Disconnected from invalid user jenkins 10.30.120.5 port 35174 [preauth] Jan 22 05:05:00 prd-ubuntu20-04-docker-2c-8g-947 useradd[1289]: new group: name=jenkins, GID=1001 Jan 22 05:05:00 prd-ubuntu20-04-docker-2c-8g-947 useradd[1289]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash, from=none Jan 22 05:05:00 prd-ubuntu20-04-docker-2c-8g-947 usermod[1299]: add 'jenkins' to group 'docker' Jan 22 05:05:00 prd-ubuntu20-04-docker-2c-8g-947 usermod[1299]: add 'jenkins' to shadow group 'docker' Jan 22 05:05:00 prd-ubuntu20-04-docker-2c-8g-947 sshd[1300]: Received disconnect from 10.30.120.5 port 35176:11: Closed due to user request. [preauth] Jan 22 05:05:00 prd-ubuntu20-04-docker-2c-8g-947 sshd[1300]: Disconnected from authenticating user jenkins 10.30.120.5 port 35176 [preauth] Jan 22 05:05:02 prd-ubuntu20-04-docker-2c-8g-947 CRON[1354]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 22 05:05:02 prd-ubuntu20-04-docker-2c-8g-947 CRON[1354]: pam_unix(cron:session): session closed for user root Jan 22 05:05:03 prd-ubuntu20-04-docker-2c-8g-947 sshd[1357]: Accepted publickey for jenkins from 10.30.120.5 port 35184 ssh2: RSA SHA256:aPmPdMw/h9M56P/o8xjsZcdBWoRKGeie6FPOwnlsRmU Jan 22 05:05:03 prd-ubuntu20-04-docker-2c-8g-947 sshd[1357]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Jan 22 05:05:03 prd-ubuntu20-04-docker-2c-8g-947 systemd-logind[724]: New session 2 of user jenkins. Jan 22 05:05:03 prd-ubuntu20-04-docker-2c-8g-947 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Jan 22 05:06:01 prd-ubuntu20-04-docker-2c-8g-947 CRON[2120]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 22 05:06:01 prd-ubuntu20-04-docker-2c-8g-947 CRON[2120]: pam_unix(cron:session): session closed for user root Jan 22 05:07:01 prd-ubuntu20-04-docker-2c-8g-947 CRON[2806]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 22 05:07:01 prd-ubuntu20-04-docker-2c-8g-947 CRON[2806]: pam_unix(cron:session): session closed for user root Jan 22 05:07:22 prd-ubuntu20-04-docker-2c-8g-947 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/ci-management-openstack-cron ; USER=root ; COMMAND=/usr/bin/cp /var/log/auth.log /tmp Jan 22 05:07:22 prd-ubuntu20-04-docker-2c-8g-947 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)