May 16 16:03:22 prd-ubuntu20-04-docker-2c-8g-9494 passwd[681]: password for 'ubuntu' changed by 'root' May 16 16:03:22 prd-ubuntu20-04-docker-2c-8g-9494 sshd[756]: Server listening on 0.0.0.0 port 22. May 16 16:03:22 prd-ubuntu20-04-docker-2c-8g-9494 sshd[756]: Server listening on :: port 22. May 16 16:03:22 prd-ubuntu20-04-docker-2c-8g-9494 systemd-logind[718]: New seat seat0. May 16 16:03:22 prd-ubuntu20-04-docker-2c-8g-9494 systemd-logind[718]: Watching system buttons on /dev/input/event0 (Power Button) May 16 16:03:22 prd-ubuntu20-04-docker-2c-8g-9494 systemd-logind[718]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) May 16 16:03:25 prd-ubuntu20-04-docker-2c-8g-9494 sshd[920]: error: kex_exchange_identification: Connection closed by remote host May 16 16:03:31 prd-ubuntu20-04-docker-2c-8g-9494 sshd[930]: Invalid user jenkins from 10.30.120.5 port 42702 May 16 16:03:32 prd-ubuntu20-04-docker-2c-8g-9494 sshd[930]: Received disconnect from 10.30.120.5 port 42702:11: Closed due to user request. [preauth] May 16 16:03:32 prd-ubuntu20-04-docker-2c-8g-9494 sshd[930]: Disconnected from invalid user jenkins 10.30.120.5 port 42702 [preauth] May 16 16:03:34 prd-ubuntu20-04-docker-2c-8g-9494 sshd[932]: Invalid user jenkins from 10.30.120.5 port 42704 May 16 16:03:34 prd-ubuntu20-04-docker-2c-8g-9494 sshd[932]: Received disconnect from 10.30.120.5 port 42704:11: Closed due to user request. [preauth] May 16 16:03:34 prd-ubuntu20-04-docker-2c-8g-9494 sshd[932]: Disconnected from invalid user jenkins 10.30.120.5 port 42704 [preauth] May 16 16:03:36 prd-ubuntu20-04-docker-2c-8g-9494 sshd[934]: Invalid user jenkins from 10.30.120.5 port 42706 May 16 16:03:36 prd-ubuntu20-04-docker-2c-8g-9494 sshd[934]: Received disconnect from 10.30.120.5 port 42706:11: Closed due to user request. [preauth] May 16 16:03:36 prd-ubuntu20-04-docker-2c-8g-9494 sshd[934]: Disconnected from invalid user jenkins 10.30.120.5 port 42706 [preauth] May 16 16:03:38 prd-ubuntu20-04-docker-2c-8g-9494 sshd[936]: Invalid user jenkins from 10.30.120.5 port 42708 May 16 16:03:38 prd-ubuntu20-04-docker-2c-8g-9494 sshd[936]: Received disconnect from 10.30.120.5 port 42708:11: Closed due to user request. [preauth] May 16 16:03:38 prd-ubuntu20-04-docker-2c-8g-9494 sshd[936]: Disconnected from invalid user jenkins 10.30.120.5 port 42708 [preauth] May 16 16:03:41 prd-ubuntu20-04-docker-2c-8g-9494 sshd[1212]: Invalid user jenkins from 10.30.120.5 port 42714 May 16 16:03:41 prd-ubuntu20-04-docker-2c-8g-9494 sshd[1212]: Received disconnect from 10.30.120.5 port 42714:11: Closed due to user request. [preauth] May 16 16:03:41 prd-ubuntu20-04-docker-2c-8g-9494 sshd[1212]: Disconnected from invalid user jenkins 10.30.120.5 port 42714 [preauth] May 16 16:03:45 prd-ubuntu20-04-docker-2c-8g-9494 sshd[1259]: Invalid user jenkins from 10.30.120.5 port 42716 May 16 16:03:45 prd-ubuntu20-04-docker-2c-8g-9494 sshd[1259]: Received disconnect from 10.30.120.5 port 42716:11: Closed due to user request. [preauth] May 16 16:03:45 prd-ubuntu20-04-docker-2c-8g-9494 sshd[1259]: Disconnected from invalid user jenkins 10.30.120.5 port 42716 [preauth] May 16 16:03:47 prd-ubuntu20-04-docker-2c-8g-9494 sshd[1263]: Invalid user jenkins from 10.30.120.5 port 42718 May 16 16:03:48 prd-ubuntu20-04-docker-2c-8g-9494 sshd[1263]: Received disconnect from 10.30.120.5 port 42718:11: Closed due to user request. [preauth] May 16 16:03:48 prd-ubuntu20-04-docker-2c-8g-9494 sshd[1263]: Disconnected from invalid user jenkins 10.30.120.5 port 42718 [preauth] May 16 16:03:50 prd-ubuntu20-04-docker-2c-8g-9494 sshd[1282]: Invalid user jenkins from 10.30.120.5 port 42720 May 16 16:03:50 prd-ubuntu20-04-docker-2c-8g-9494 sshd[1282]: Received disconnect from 10.30.120.5 port 42720:11: Closed due to user request. [preauth] May 16 16:03:50 prd-ubuntu20-04-docker-2c-8g-9494 sshd[1282]: Disconnected from invalid user jenkins 10.30.120.5 port 42720 [preauth] May 16 16:03:51 prd-ubuntu20-04-docker-2c-8g-9494 useradd[1289]: new group: name=jenkins, GID=1001 May 16 16:03:51 prd-ubuntu20-04-docker-2c-8g-9494 useradd[1289]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash, from=none May 16 16:03:51 prd-ubuntu20-04-docker-2c-8g-9494 usermod[1299]: add 'jenkins' to group 'docker' May 16 16:03:51 prd-ubuntu20-04-docker-2c-8g-9494 usermod[1299]: add 'jenkins' to shadow group 'docker' May 16 16:03:52 prd-ubuntu20-04-docker-2c-8g-9494 sshd[1334]: Accepted publickey for jenkins from 10.30.120.5 port 42722 ssh2: RSA SHA256:aPmPdMw/h9M56P/o8xjsZcdBWoRKGeie6FPOwnlsRmU May 16 16:03:52 prd-ubuntu20-04-docker-2c-8g-9494 sshd[1334]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) May 16 16:03:52 prd-ubuntu20-04-docker-2c-8g-9494 systemd-logind[718]: New session 1 of user jenkins. May 16 16:03:52 prd-ubuntu20-04-docker-2c-8g-9494 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) May 16 16:04:02 prd-ubuntu20-04-docker-2c-8g-9494 CRON[1549]: pam_unix(cron:session): session opened for user root by (uid=0) May 16 16:04:02 prd-ubuntu20-04-docker-2c-8g-9494 CRON[1549]: pam_unix(cron:session): session closed for user root May 16 16:05:01 prd-ubuntu20-04-docker-2c-8g-9494 CRON[2115]: pam_unix(cron:session): session opened for user root by (uid=0) May 16 16:05:01 prd-ubuntu20-04-docker-2c-8g-9494 CRON[2115]: pam_unix(cron:session): session closed for user root May 16 16:06:01 prd-ubuntu20-04-docker-2c-8g-9494 CRON[2589]: pam_unix(cron:session): session opened for user root by (uid=0) May 16 16:06:01 prd-ubuntu20-04-docker-2c-8g-9494 CRON[2589]: pam_unix(cron:session): session closed for user root May 16 16:07:01 prd-ubuntu20-04-docker-2c-8g-9494 CRON[2844]: pam_unix(cron:session): session opened for user root by (uid=0) May 16 16:07:01 prd-ubuntu20-04-docker-2c-8g-9494 CRON[2844]: pam_unix(cron:session): session closed for user root May 16 16:07:21 prd-ubuntu20-04-docker-2c-8g-9494 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/ci-management-openstack-cron ; USER=root ; COMMAND=/usr/bin/cp /var/log/auth.log /tmp May 16 16:07:21 prd-ubuntu20-04-docker-2c-8g-9494 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)