Nov 11 13:04:21 prd-ubuntu2004-docker-4c-4g-6555 passwd[713]: password for 'ubuntu' changed by 'root' Nov 11 13:04:21 prd-ubuntu2004-docker-4c-4g-6555 sshd[807]: Server listening on 0.0.0.0 port 22. Nov 11 13:04:21 prd-ubuntu2004-docker-4c-4g-6555 sshd[807]: Server listening on :: port 22. Nov 11 13:04:21 prd-ubuntu2004-docker-4c-4g-6555 systemd-logind[762]: New seat seat0. Nov 11 13:04:21 prd-ubuntu2004-docker-4c-4g-6555 systemd-logind[762]: Watching system buttons on /dev/input/event0 (Power Button) Nov 11 13:04:21 prd-ubuntu2004-docker-4c-4g-6555 systemd-logind[762]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Nov 11 13:04:23 prd-ubuntu2004-docker-4c-4g-6555 sshd[1294]: error: kex_exchange_identification: Connection closed by remote host Nov 11 13:04:30 prd-ubuntu2004-docker-4c-4g-6555 sshd[3625]: Invalid user jenkins from 10.30.168.15 port 49282 Nov 11 13:04:30 prd-ubuntu2004-docker-4c-4g-6555 sshd[3625]: Received disconnect from 10.30.168.15 port 49282:11: Closed due to user request. [preauth] Nov 11 13:04:30 prd-ubuntu2004-docker-4c-4g-6555 sshd[3625]: Disconnected from invalid user jenkins 10.30.168.15 port 49282 [preauth] Nov 11 13:04:33 prd-ubuntu2004-docker-4c-4g-6555 sshd[4521]: Invalid user jenkins from 10.30.168.15 port 49296 Nov 11 13:04:33 prd-ubuntu2004-docker-4c-4g-6555 sshd[4521]: Received disconnect from 10.30.168.15 port 49296:11: Closed due to user request. [preauth] Nov 11 13:04:33 prd-ubuntu2004-docker-4c-4g-6555 sshd[4521]: Disconnected from invalid user jenkins 10.30.168.15 port 49296 [preauth] Nov 11 13:04:36 prd-ubuntu2004-docker-4c-4g-6555 sshd[5484]: Invalid user jenkins from 10.30.168.15 port 49302 Nov 11 13:04:36 prd-ubuntu2004-docker-4c-4g-6555 sshd[5484]: Received disconnect from 10.30.168.15 port 49302:11: Closed due to user request. [preauth] Nov 11 13:04:36 prd-ubuntu2004-docker-4c-4g-6555 sshd[5484]: Disconnected from invalid user jenkins 10.30.168.15 port 49302 [preauth] Nov 11 13:04:38 prd-ubuntu2004-docker-4c-4g-6555 sshd[6457]: Invalid user jenkins from 10.30.168.15 port 49320 Nov 11 13:04:38 prd-ubuntu2004-docker-4c-4g-6555 sshd[6457]: Received disconnect from 10.30.168.15 port 49320:11: Closed due to user request. [preauth] Nov 11 13:04:38 prd-ubuntu2004-docker-4c-4g-6555 sshd[6457]: Disconnected from invalid user jenkins 10.30.168.15 port 49320 [preauth] Nov 11 13:04:41 prd-ubuntu2004-docker-4c-4g-6555 sshd[7706]: Invalid user jenkins from 10.30.168.15 port 49326 Nov 11 13:04:41 prd-ubuntu2004-docker-4c-4g-6555 sshd[7706]: Received disconnect from 10.30.168.15 port 49326:11: Closed due to user request. [preauth] Nov 11 13:04:41 prd-ubuntu2004-docker-4c-4g-6555 sshd[7706]: Disconnected from invalid user jenkins 10.30.168.15 port 49326 [preauth] Nov 11 13:04:44 prd-ubuntu2004-docker-4c-4g-6555 sshd[8888]: Invalid user jenkins from 10.30.168.15 port 49330 Nov 11 13:04:44 prd-ubuntu2004-docker-4c-4g-6555 sshd[8888]: Received disconnect from 10.30.168.15 port 49330:11: Closed due to user request. [preauth] Nov 11 13:04:44 prd-ubuntu2004-docker-4c-4g-6555 sshd[8888]: Disconnected from invalid user jenkins 10.30.168.15 port 49330 [preauth] Nov 11 13:04:47 prd-ubuntu2004-docker-4c-4g-6555 sshd[9632]: Invalid user jenkins from 10.30.168.15 port 49338 Nov 11 13:04:47 prd-ubuntu2004-docker-4c-4g-6555 sshd[9632]: Received disconnect from 10.30.168.15 port 49338:11: Closed due to user request. [preauth] Nov 11 13:04:47 prd-ubuntu2004-docker-4c-4g-6555 sshd[9632]: Disconnected from invalid user jenkins 10.30.168.15 port 49338 [preauth] Nov 11 13:04:49 prd-ubuntu2004-docker-4c-4g-6555 sshd[10116]: Invalid user jenkins from 10.30.168.15 port 49340 Nov 11 13:04:49 prd-ubuntu2004-docker-4c-4g-6555 sshd[10116]: Received disconnect from 10.30.168.15 port 49340:11: Closed due to user request. [preauth] Nov 11 13:04:49 prd-ubuntu2004-docker-4c-4g-6555 sshd[10116]: Disconnected from invalid user jenkins 10.30.168.15 port 49340 [preauth] Nov 11 13:04:50 prd-ubuntu2004-docker-4c-4g-6555 useradd[10511]: new group: name=jenkins, GID=1001 Nov 11 13:04:50 prd-ubuntu2004-docker-4c-4g-6555 useradd[10511]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash, from=none Nov 11 13:04:50 prd-ubuntu2004-docker-4c-4g-6555 usermod[10547]: add 'jenkins' to group 'docker' Nov 11 13:04:50 prd-ubuntu2004-docker-4c-4g-6555 usermod[10547]: add 'jenkins' to shadow group 'docker' Nov 11 13:04:52 prd-ubuntu2004-docker-4c-4g-6555 sshd[11118]: Accepted publickey for jenkins from 10.30.168.15 port 49348 ssh2: RSA SHA256:BBsm4mRgG5V0fGum4Y1Rmy/vs16stdRVhwvexlLUhUs Nov 11 13:04:52 prd-ubuntu2004-docker-4c-4g-6555 sshd[11118]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Nov 11 13:04:52 prd-ubuntu2004-docker-4c-4g-6555 systemd-logind[762]: New session 1 of user jenkins. Nov 11 13:04:52 prd-ubuntu2004-docker-4c-4g-6555 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Nov 11 13:05:01 prd-ubuntu2004-docker-4c-4g-6555 CRON[14141]: pam_unix(cron:session): session opened for user root by (uid=0) Nov 11 13:05:01 prd-ubuntu2004-docker-4c-4g-6555 CRON[14141]: pam_unix(cron:session): session closed for user root Nov 11 13:06:01 prd-ubuntu2004-docker-4c-4g-6555 CRON[28557]: pam_unix(cron:session): session opened for user root by (uid=0) Nov 11 13:06:01 prd-ubuntu2004-docker-4c-4g-6555 CRON[28557]: pam_unix(cron:session): session closed for user root Nov 11 13:07:01 prd-ubuntu2004-docker-4c-4g-6555 CRON[29003]: pam_unix(cron:session): session opened for user root by (uid=0) Nov 11 13:07:01 prd-ubuntu2004-docker-4c-4g-6555 CRON[29003]: pam_unix(cron:session): session closed for user root Nov 11 13:08:01 prd-ubuntu2004-docker-4c-4g-6555 CRON[29006]: pam_unix(cron:session): session opened for user root by (uid=0) Nov 11 13:08:01 prd-ubuntu2004-docker-4c-4g-6555 CRON[29006]: pam_unix(cron:session): session closed for user root Nov 11 13:08:44 prd-ubuntu2004-docker-4c-4g-6555 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/docs-rtd-verify-calcium ; USER=root ; COMMAND=/usr/bin/cp /var/log/auth.log /tmp Nov 11 13:08:44 prd-ubuntu2004-docker-4c-4g-6555 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)