Mar 2 13:03:25 prd-ubuntu20-04-docker-2c-8g-2869 passwd[680]: password for 'ubuntu' changed by 'root' Mar 2 13:03:25 prd-ubuntu20-04-docker-2c-8g-2869 sshd[759]: Server listening on 0.0.0.0 port 22. Mar 2 13:03:25 prd-ubuntu20-04-docker-2c-8g-2869 sshd[759]: Server listening on :: port 22. Mar 2 13:03:25 prd-ubuntu20-04-docker-2c-8g-2869 systemd-logind[727]: New seat seat0. Mar 2 13:03:25 prd-ubuntu20-04-docker-2c-8g-2869 systemd-logind[727]: Watching system buttons on /dev/input/event0 (Power Button) Mar 2 13:03:25 prd-ubuntu20-04-docker-2c-8g-2869 systemd-logind[727]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Mar 2 13:03:29 prd-ubuntu20-04-docker-2c-8g-2869 sshd[921]: error: kex_exchange_identification: Connection closed by remote host Mar 2 13:03:32 prd-ubuntu20-04-docker-2c-8g-2869 sshd[928]: Invalid user jenkins from 10.30.120.5 port 51408 Mar 2 13:03:32 prd-ubuntu20-04-docker-2c-8g-2869 sshd[928]: Received disconnect from 10.30.120.5 port 51408:11: Closed due to user request. [preauth] Mar 2 13:03:32 prd-ubuntu20-04-docker-2c-8g-2869 sshd[928]: Disconnected from invalid user jenkins 10.30.120.5 port 51408 [preauth] Mar 2 13:03:34 prd-ubuntu20-04-docker-2c-8g-2869 sshd[930]: Invalid user jenkins from 10.30.120.5 port 51410 Mar 2 13:03:35 prd-ubuntu20-04-docker-2c-8g-2869 sshd[930]: Received disconnect from 10.30.120.5 port 51410:11: Closed due to user request. [preauth] Mar 2 13:03:35 prd-ubuntu20-04-docker-2c-8g-2869 sshd[930]: Disconnected from invalid user jenkins 10.30.120.5 port 51410 [preauth] Mar 2 13:03:37 prd-ubuntu20-04-docker-2c-8g-2869 sshd[932]: Invalid user jenkins from 10.30.120.5 port 51412 Mar 2 13:03:37 prd-ubuntu20-04-docker-2c-8g-2869 sshd[932]: Received disconnect from 10.30.120.5 port 51412:11: Closed due to user request. [preauth] Mar 2 13:03:37 prd-ubuntu20-04-docker-2c-8g-2869 sshd[932]: Disconnected from invalid user jenkins 10.30.120.5 port 51412 [preauth] Mar 2 13:03:39 prd-ubuntu20-04-docker-2c-8g-2869 sshd[934]: Invalid user jenkins from 10.30.120.5 port 51414 Mar 2 13:03:39 prd-ubuntu20-04-docker-2c-8g-2869 sshd[934]: Received disconnect from 10.30.120.5 port 51414:11: Closed due to user request. [preauth] Mar 2 13:03:39 prd-ubuntu20-04-docker-2c-8g-2869 sshd[934]: Disconnected from invalid user jenkins 10.30.120.5 port 51414 [preauth] Mar 2 13:03:41 prd-ubuntu20-04-docker-2c-8g-2869 sshd[936]: Invalid user jenkins from 10.30.120.5 port 51416 Mar 2 13:03:41 prd-ubuntu20-04-docker-2c-8g-2869 sshd[936]: Received disconnect from 10.30.120.5 port 51416:11: Closed due to user request. [preauth] Mar 2 13:03:41 prd-ubuntu20-04-docker-2c-8g-2869 sshd[936]: Disconnected from invalid user jenkins 10.30.120.5 port 51416 [preauth] Mar 2 13:03:43 prd-ubuntu20-04-docker-2c-8g-2869 sshd[1082]: Invalid user jenkins from 10.30.120.5 port 51420 Mar 2 13:03:44 prd-ubuntu20-04-docker-2c-8g-2869 sshd[1082]: Received disconnect from 10.30.120.5 port 51420:11: Closed due to user request. [preauth] Mar 2 13:03:44 prd-ubuntu20-04-docker-2c-8g-2869 sshd[1082]: Disconnected from invalid user jenkins 10.30.120.5 port 51420 [preauth] Mar 2 13:03:46 prd-ubuntu20-04-docker-2c-8g-2869 sshd[1258]: Invalid user jenkins from 10.30.120.5 port 51424 Mar 2 13:03:46 prd-ubuntu20-04-docker-2c-8g-2869 sshd[1258]: Received disconnect from 10.30.120.5 port 51424:11: Closed due to user request. [preauth] Mar 2 13:03:46 prd-ubuntu20-04-docker-2c-8g-2869 sshd[1258]: Disconnected from invalid user jenkins 10.30.120.5 port 51424 [preauth] Mar 2 13:03:48 prd-ubuntu20-04-docker-2c-8g-2869 sshd[1262]: Invalid user jenkins from 10.30.120.5 port 51428 Mar 2 13:03:48 prd-ubuntu20-04-docker-2c-8g-2869 sshd[1262]: Received disconnect from 10.30.120.5 port 51428:11: Closed due to user request. [preauth] Mar 2 13:03:48 prd-ubuntu20-04-docker-2c-8g-2869 sshd[1262]: Disconnected from invalid user jenkins 10.30.120.5 port 51428 [preauth] Mar 2 13:03:50 prd-ubuntu20-04-docker-2c-8g-2869 useradd[1283]: new group: name=jenkins, GID=1001 Mar 2 13:03:50 prd-ubuntu20-04-docker-2c-8g-2869 useradd[1283]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash, from=none Mar 2 13:03:50 prd-ubuntu20-04-docker-2c-8g-2869 usermod[1294]: add 'jenkins' to group 'docker' Mar 2 13:03:50 prd-ubuntu20-04-docker-2c-8g-2869 usermod[1294]: add 'jenkins' to shadow group 'docker' Mar 2 13:03:50 prd-ubuntu20-04-docker-2c-8g-2869 sshd[1289]: Received disconnect from 10.30.120.5 port 51430:11: Closed due to user request. [preauth] Mar 2 13:03:50 prd-ubuntu20-04-docker-2c-8g-2869 sshd[1289]: Disconnected from authenticating user jenkins 10.30.120.5 port 51430 [preauth] Mar 2 13:03:52 prd-ubuntu20-04-docker-2c-8g-2869 sshd[1348]: Accepted publickey for jenkins from 10.30.120.5 port 51434 ssh2: RSA SHA256:aPmPdMw/h9M56P/o8xjsZcdBWoRKGeie6FPOwnlsRmU Mar 2 13:03:52 prd-ubuntu20-04-docker-2c-8g-2869 sshd[1348]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Mar 2 13:03:52 prd-ubuntu20-04-docker-2c-8g-2869 systemd-logind[727]: New session 1 of user jenkins. Mar 2 13:03:52 prd-ubuntu20-04-docker-2c-8g-2869 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Mar 2 13:04:02 prd-ubuntu20-04-docker-2c-8g-2869 CRON[1861]: pam_unix(cron:session): session opened for user root by (uid=0) Mar 2 13:04:02 prd-ubuntu20-04-docker-2c-8g-2869 CRON[1861]: pam_unix(cron:session): session closed for user root Mar 2 13:05:01 prd-ubuntu20-04-docker-2c-8g-2869 CRON[2291]: pam_unix(cron:session): session opened for user root by (uid=0) Mar 2 13:05:01 prd-ubuntu20-04-docker-2c-8g-2869 CRON[2291]: pam_unix(cron:session): session closed for user root Mar 2 13:06:01 prd-ubuntu20-04-docker-2c-8g-2869 CRON[3138]: pam_unix(cron:session): session opened for user root by (uid=0) Mar 2 13:06:01 prd-ubuntu20-04-docker-2c-8g-2869 CRON[3138]: pam_unix(cron:session): session closed for user root Mar 2 13:06:03 prd-ubuntu20-04-docker-2c-8g-2869 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/ci-management-openstack-cron ; USER=root ; COMMAND=/usr/bin/cp /var/log/auth.log /tmp Mar 2 13:06:03 prd-ubuntu20-04-docker-2c-8g-2869 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)