Nov 11 11:34:13 prd-ubuntu2004-docker-4c-4g-6519 passwd[712]: password for 'ubuntu' changed by 'root' Nov 11 11:34:13 prd-ubuntu2004-docker-4c-4g-6519 sshd[785]: Server listening on 0.0.0.0 port 22. Nov 11 11:34:13 prd-ubuntu2004-docker-4c-4g-6519 sshd[785]: Server listening on :: port 22. Nov 11 11:34:13 prd-ubuntu2004-docker-4c-4g-6519 systemd-logind[767]: New seat seat0. Nov 11 11:34:13 prd-ubuntu2004-docker-4c-4g-6519 systemd-logind[767]: Watching system buttons on /dev/input/event0 (Power Button) Nov 11 11:34:13 prd-ubuntu2004-docker-4c-4g-6519 systemd-logind[767]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Nov 11 11:34:14 prd-ubuntu2004-docker-4c-4g-6519 sshd[822]: error: kex_exchange_identification: Connection closed by remote host Nov 11 11:34:20 prd-ubuntu2004-docker-4c-4g-6519 sshd[2925]: Invalid user jenkins from 10.30.168.15 port 50862 Nov 11 11:34:20 prd-ubuntu2004-docker-4c-4g-6519 sshd[2925]: Received disconnect from 10.30.168.15 port 50862:11: Closed due to user request. [preauth] Nov 11 11:34:20 prd-ubuntu2004-docker-4c-4g-6519 sshd[2925]: Disconnected from invalid user jenkins 10.30.168.15 port 50862 [preauth] Nov 11 11:34:23 prd-ubuntu2004-docker-4c-4g-6519 sshd[4060]: Invalid user jenkins from 10.30.168.15 port 50878 Nov 11 11:34:23 prd-ubuntu2004-docker-4c-4g-6519 sshd[4060]: Received disconnect from 10.30.168.15 port 50878:11: Closed due to user request. [preauth] Nov 11 11:34:23 prd-ubuntu2004-docker-4c-4g-6519 sshd[4060]: Disconnected from invalid user jenkins 10.30.168.15 port 50878 [preauth] Nov 11 11:34:26 prd-ubuntu2004-docker-4c-4g-6519 sshd[4886]: Invalid user jenkins from 10.30.168.15 port 50892 Nov 11 11:34:26 prd-ubuntu2004-docker-4c-4g-6519 sshd[4886]: Received disconnect from 10.30.168.15 port 50892:11: Closed due to user request. [preauth] Nov 11 11:34:26 prd-ubuntu2004-docker-4c-4g-6519 sshd[4886]: Disconnected from invalid user jenkins 10.30.168.15 port 50892 [preauth] Nov 11 11:34:30 prd-ubuntu2004-docker-4c-4g-6519 sshd[5916]: Invalid user jenkins from 10.30.168.15 port 50910 Nov 11 11:34:30 prd-ubuntu2004-docker-4c-4g-6519 sshd[5916]: Received disconnect from 10.30.168.15 port 50910:11: Closed due to user request. [preauth] Nov 11 11:34:30 prd-ubuntu2004-docker-4c-4g-6519 sshd[5916]: Disconnected from invalid user jenkins 10.30.168.15 port 50910 [preauth] Nov 11 11:34:32 prd-ubuntu2004-docker-4c-4g-6519 sshd[7031]: Invalid user jenkins from 10.30.168.15 port 50916 Nov 11 11:34:33 prd-ubuntu2004-docker-4c-4g-6519 sshd[7031]: Received disconnect from 10.30.168.15 port 50916:11: Closed due to user request. [preauth] Nov 11 11:34:33 prd-ubuntu2004-docker-4c-4g-6519 sshd[7031]: Disconnected from invalid user jenkins 10.30.168.15 port 50916 [preauth] Nov 11 11:34:35 prd-ubuntu2004-docker-4c-4g-6519 sshd[8071]: Invalid user jenkins from 10.30.168.15 port 50924 Nov 11 11:34:35 prd-ubuntu2004-docker-4c-4g-6519 sshd[8071]: Received disconnect from 10.30.168.15 port 50924:11: Closed due to user request. [preauth] Nov 11 11:34:35 prd-ubuntu2004-docker-4c-4g-6519 sshd[8071]: Disconnected from invalid user jenkins 10.30.168.15 port 50924 [preauth] Nov 11 11:34:38 prd-ubuntu2004-docker-4c-4g-6519 sshd[8988]: Invalid user jenkins from 10.30.168.15 port 50940 Nov 11 11:34:38 prd-ubuntu2004-docker-4c-4g-6519 sshd[8988]: Received disconnect from 10.30.168.15 port 50940:11: Closed due to user request. [preauth] Nov 11 11:34:38 prd-ubuntu2004-docker-4c-4g-6519 sshd[8988]: Disconnected from invalid user jenkins 10.30.168.15 port 50940 [preauth] Nov 11 11:34:41 prd-ubuntu2004-docker-4c-4g-6519 sshd[9638]: Invalid user jenkins from 10.30.168.15 port 50950 Nov 11 11:34:41 prd-ubuntu2004-docker-4c-4g-6519 sshd[9638]: Received disconnect from 10.30.168.15 port 50950:11: Closed due to user request. [preauth] Nov 11 11:34:41 prd-ubuntu2004-docker-4c-4g-6519 sshd[9638]: Disconnected from invalid user jenkins 10.30.168.15 port 50950 [preauth] Nov 11 11:34:43 prd-ubuntu2004-docker-4c-4g-6519 useradd[10067]: new group: name=jenkins, GID=1001 Nov 11 11:34:43 prd-ubuntu2004-docker-4c-4g-6519 useradd[10067]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash, from=none Nov 11 11:34:44 prd-ubuntu2004-docker-4c-4g-6519 usermod[10191]: add 'jenkins' to group 'docker' Nov 11 11:34:44 prd-ubuntu2004-docker-4c-4g-6519 usermod[10191]: add 'jenkins' to shadow group 'docker' Nov 11 11:34:45 prd-ubuntu2004-docker-4c-4g-6519 sshd[10393]: Accepted publickey for jenkins from 10.30.168.15 port 50976 ssh2: RSA SHA256:BBsm4mRgG5V0fGum4Y1Rmy/vs16stdRVhwvexlLUhUs Nov 11 11:34:45 prd-ubuntu2004-docker-4c-4g-6519 sshd[10393]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Nov 11 11:34:45 prd-ubuntu2004-docker-4c-4g-6519 systemd-logind[767]: New session 1 of user jenkins. Nov 11 11:34:45 prd-ubuntu2004-docker-4c-4g-6519 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Nov 11 11:35:01 prd-ubuntu2004-docker-4c-4g-6519 CRON[15601]: pam_unix(cron:session): session opened for user root by (uid=0) Nov 11 11:35:01 prd-ubuntu2004-docker-4c-4g-6519 CRON[15601]: pam_unix(cron:session): session closed for user root Nov 11 11:36:01 prd-ubuntu2004-docker-4c-4g-6519 CRON[28541]: pam_unix(cron:session): session opened for user root by (uid=0) Nov 11 11:36:01 prd-ubuntu2004-docker-4c-4g-6519 CRON[28541]: pam_unix(cron:session): session closed for user root Nov 11 11:37:01 prd-ubuntu2004-docker-4c-4g-6519 CRON[28987]: pam_unix(cron:session): session opened for user root by (uid=0) Nov 11 11:37:01 prd-ubuntu2004-docker-4c-4g-6519 CRON[28987]: pam_unix(cron:session): session closed for user root Nov 11 11:38:01 prd-ubuntu2004-docker-4c-4g-6519 CRON[28998]: pam_unix(cron:session): session opened for user root by (uid=0) Nov 11 11:38:01 prd-ubuntu2004-docker-4c-4g-6519 CRON[28998]: pam_unix(cron:session): session closed for user root Nov 11 11:38:27 prd-ubuntu2004-docker-4c-4g-6519 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/docs-rtd-verify-calcium ; USER=root ; COMMAND=/usr/bin/cp /var/log/auth.log /tmp Nov 11 11:38:27 prd-ubuntu2004-docker-4c-4g-6519 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)