Jun 2 11:50:21 prd-ubuntu20-04-docker-2c-8g-12228 passwd[682]: password for 'ubuntu' changed by 'root' Jun 2 11:50:21 prd-ubuntu20-04-docker-2c-8g-12228 sshd[763]: Server listening on 0.0.0.0 port 22. Jun 2 11:50:21 prd-ubuntu20-04-docker-2c-8g-12228 sshd[763]: Server listening on :: port 22. Jun 2 11:50:21 prd-ubuntu20-04-docker-2c-8g-12228 systemd-logind[718]: New seat seat0. Jun 2 11:50:21 prd-ubuntu20-04-docker-2c-8g-12228 systemd-logind[718]: Watching system buttons on /dev/input/event0 (Power Button) Jun 2 11:50:21 prd-ubuntu20-04-docker-2c-8g-12228 systemd-logind[718]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Jun 2 11:50:26 prd-ubuntu20-04-docker-2c-8g-12228 sshd[935]: error: kex_exchange_identification: Connection closed by remote host Jun 2 11:50:31 prd-ubuntu20-04-docker-2c-8g-12228 sshd[936]: Invalid user jenkins from 10.30.120.5 port 59202 Jun 2 11:50:31 prd-ubuntu20-04-docker-2c-8g-12228 sshd[936]: Received disconnect from 10.30.120.5 port 59202:11: Closed due to user request. [preauth] Jun 2 11:50:31 prd-ubuntu20-04-docker-2c-8g-12228 sshd[936]: Disconnected from invalid user jenkins 10.30.120.5 port 59202 [preauth] Jun 2 11:50:33 prd-ubuntu20-04-docker-2c-8g-12228 sshd[940]: Invalid user jenkins from 10.30.120.5 port 59204 Jun 2 11:50:33 prd-ubuntu20-04-docker-2c-8g-12228 sshd[940]: Received disconnect from 10.30.120.5 port 59204:11: Closed due to user request. [preauth] Jun 2 11:50:33 prd-ubuntu20-04-docker-2c-8g-12228 sshd[940]: Disconnected from invalid user jenkins 10.30.120.5 port 59204 [preauth] Jun 2 11:50:35 prd-ubuntu20-04-docker-2c-8g-12228 sshd[942]: Invalid user jenkins from 10.30.120.5 port 59206 Jun 2 11:50:35 prd-ubuntu20-04-docker-2c-8g-12228 sshd[942]: Received disconnect from 10.30.120.5 port 59206:11: Closed due to user request. [preauth] Jun 2 11:50:35 prd-ubuntu20-04-docker-2c-8g-12228 sshd[942]: Disconnected from invalid user jenkins 10.30.120.5 port 59206 [preauth] Jun 2 11:50:38 prd-ubuntu20-04-docker-2c-8g-12228 sshd[944]: Invalid user jenkins from 10.30.120.5 port 59208 Jun 2 11:50:38 prd-ubuntu20-04-docker-2c-8g-12228 sshd[944]: Received disconnect from 10.30.120.5 port 59208:11: Closed due to user request. [preauth] Jun 2 11:50:38 prd-ubuntu20-04-docker-2c-8g-12228 sshd[944]: Disconnected from invalid user jenkins 10.30.120.5 port 59208 [preauth] Jun 2 11:50:41 prd-ubuntu20-04-docker-2c-8g-12228 sshd[1229]: Invalid user jenkins from 10.30.120.5 port 59210 Jun 2 11:50:42 prd-ubuntu20-04-docker-2c-8g-12228 sshd[1229]: Received disconnect from 10.30.120.5 port 59210:11: Closed due to user request. [preauth] Jun 2 11:50:42 prd-ubuntu20-04-docker-2c-8g-12228 sshd[1229]: Disconnected from invalid user jenkins 10.30.120.5 port 59210 [preauth] Jun 2 11:50:44 prd-ubuntu20-04-docker-2c-8g-12228 sshd[1267]: Invalid user jenkins from 10.30.120.5 port 59214 Jun 2 11:50:44 prd-ubuntu20-04-docker-2c-8g-12228 sshd[1267]: Received disconnect from 10.30.120.5 port 59214:11: Closed due to user request. [preauth] Jun 2 11:50:44 prd-ubuntu20-04-docker-2c-8g-12228 sshd[1267]: Disconnected from invalid user jenkins 10.30.120.5 port 59214 [preauth] Jun 2 11:50:44 prd-ubuntu20-04-docker-2c-8g-12228 useradd[1274]: new group: name=jenkins, GID=1001 Jun 2 11:50:44 prd-ubuntu20-04-docker-2c-8g-12228 useradd[1274]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash, from=none Jun 2 11:50:44 prd-ubuntu20-04-docker-2c-8g-12228 usermod[1284]: add 'jenkins' to group 'docker' Jun 2 11:50:44 prd-ubuntu20-04-docker-2c-8g-12228 usermod[1284]: add 'jenkins' to shadow group 'docker' Jun 2 11:50:46 prd-ubuntu20-04-docker-2c-8g-12228 sshd[1319]: Accepted publickey for jenkins from 10.30.120.5 port 59218 ssh2: RSA SHA256:aPmPdMw/h9M56P/o8xjsZcdBWoRKGeie6FPOwnlsRmU Jun 2 11:50:46 prd-ubuntu20-04-docker-2c-8g-12228 sshd[1319]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Jun 2 11:50:46 prd-ubuntu20-04-docker-2c-8g-12228 systemd-logind[718]: New session 1 of user jenkins. Jun 2 11:50:46 prd-ubuntu20-04-docker-2c-8g-12228 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Jun 2 11:51:02 prd-ubuntu20-04-docker-2c-8g-12228 CRON[1892]: pam_unix(cron:session): session opened for user root by (uid=0) Jun 2 11:51:02 prd-ubuntu20-04-docker-2c-8g-12228 CRON[1892]: pam_unix(cron:session): session closed for user root Jun 2 11:52:01 prd-ubuntu20-04-docker-2c-8g-12228 CRON[2120]: pam_unix(cron:session): session opened for user root by (uid=0) Jun 2 11:52:01 prd-ubuntu20-04-docker-2c-8g-12228 CRON[2120]: pam_unix(cron:session): session closed for user root Jun 2 11:53:02 prd-ubuntu20-04-docker-2c-8g-12228 CRON[2124]: pam_unix(cron:session): session opened for user root by (uid=0) Jun 2 11:53:02 prd-ubuntu20-04-docker-2c-8g-12228 CRON[2124]: pam_unix(cron:session): session closed for user root Jun 2 11:54:01 prd-ubuntu20-04-docker-2c-8g-12228 CRON[2128]: pam_unix(cron:session): session opened for user root by (uid=0) Jun 2 11:54:01 prd-ubuntu20-04-docker-2c-8g-12228 CRON[2128]: pam_unix(cron:session): session closed for user root Jun 2 11:55:01 prd-ubuntu20-04-docker-2c-8g-12228 CRON[2132]: pam_unix(cron:session): session opened for user root by (uid=0) Jun 2 11:55:01 prd-ubuntu20-04-docker-2c-8g-12228 CRON[2132]: pam_unix(cron:session): session closed for user root Jun 2 11:56:01 prd-ubuntu20-04-docker-2c-8g-12228 CRON[2634]: pam_unix(cron:session): session opened for user root by (uid=0) Jun 2 11:56:01 prd-ubuntu20-04-docker-2c-8g-12228 CRON[2634]: pam_unix(cron:session): session closed for user root Jun 2 11:57:01 prd-ubuntu20-04-docker-2c-8g-12228 CRON[3061]: pam_unix(cron:session): session opened for user root by (uid=0) Jun 2 11:57:01 prd-ubuntu20-04-docker-2c-8g-12228 CRON[3061]: pam_unix(cron:session): session closed for user root Jun 2 11:57:22 prd-ubuntu20-04-docker-2c-8g-12228 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/ci-management-packer-merge-ubuntu-24.04-arm64-local-docker ; USER=root ; COMMAND=/usr/bin/cp /var/log/auth.log /tmp Jun 2 11:57:22 prd-ubuntu20-04-docker-2c-8g-12228 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)