Nov 11 13:17:11 prd-ubuntu2004-docker-4c-4g-6563 passwd[711]: password for 'ubuntu' changed by 'root' Nov 11 13:17:11 prd-ubuntu2004-docker-4c-4g-6563 systemd-logind[760]: New seat seat0. Nov 11 13:17:11 prd-ubuntu2004-docker-4c-4g-6563 systemd-logind[760]: Watching system buttons on /dev/input/event0 (Power Button) Nov 11 13:17:11 prd-ubuntu2004-docker-4c-4g-6563 systemd-logind[760]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Nov 11 13:17:11 prd-ubuntu2004-docker-4c-4g-6563 sshd[799]: Server listening on 0.0.0.0 port 22. Nov 11 13:17:11 prd-ubuntu2004-docker-4c-4g-6563 sshd[799]: Server listening on :: port 22. Nov 11 13:17:14 prd-ubuntu2004-docker-4c-4g-6563 sshd[1964]: error: kex_exchange_identification: Connection closed by remote host Nov 11 13:17:19 prd-ubuntu2004-docker-4c-4g-6563 sshd[3494]: Invalid user jenkins from 10.30.168.15 port 43146 Nov 11 13:17:19 prd-ubuntu2004-docker-4c-4g-6563 sshd[3494]: Received disconnect from 10.30.168.15 port 43146:11: Closed due to user request. [preauth] Nov 11 13:17:19 prd-ubuntu2004-docker-4c-4g-6563 sshd[3494]: Disconnected from invalid user jenkins 10.30.168.15 port 43146 [preauth] Nov 11 13:17:22 prd-ubuntu2004-docker-4c-4g-6563 sshd[4405]: Invalid user jenkins from 10.30.168.15 port 43162 Nov 11 13:17:22 prd-ubuntu2004-docker-4c-4g-6563 sshd[4405]: Received disconnect from 10.30.168.15 port 43162:11: Closed due to user request. [preauth] Nov 11 13:17:22 prd-ubuntu2004-docker-4c-4g-6563 sshd[4405]: Disconnected from invalid user jenkins 10.30.168.15 port 43162 [preauth] Nov 11 13:17:25 prd-ubuntu2004-docker-4c-4g-6563 sshd[5339]: Invalid user jenkins from 10.30.168.15 port 43168 Nov 11 13:17:25 prd-ubuntu2004-docker-4c-4g-6563 sshd[5339]: Received disconnect from 10.30.168.15 port 43168:11: Closed due to user request. [preauth] Nov 11 13:17:25 prd-ubuntu2004-docker-4c-4g-6563 sshd[5339]: Disconnected from invalid user jenkins 10.30.168.15 port 43168 [preauth] Nov 11 13:17:28 prd-ubuntu2004-docker-4c-4g-6563 sshd[6281]: Invalid user jenkins from 10.30.168.15 port 43182 Nov 11 13:17:28 prd-ubuntu2004-docker-4c-4g-6563 sshd[6281]: Received disconnect from 10.30.168.15 port 43182:11: Closed due to user request. [preauth] Nov 11 13:17:28 prd-ubuntu2004-docker-4c-4g-6563 sshd[6281]: Disconnected from invalid user jenkins 10.30.168.15 port 43182 [preauth] Nov 11 13:17:31 prd-ubuntu2004-docker-4c-4g-6563 sshd[7454]: Invalid user jenkins from 10.30.168.15 port 43186 Nov 11 13:17:31 prd-ubuntu2004-docker-4c-4g-6563 sshd[7454]: Received disconnect from 10.30.168.15 port 43186:11: Closed due to user request. [preauth] Nov 11 13:17:31 prd-ubuntu2004-docker-4c-4g-6563 sshd[7454]: Disconnected from invalid user jenkins 10.30.168.15 port 43186 [preauth] Nov 11 13:17:34 prd-ubuntu2004-docker-4c-4g-6563 sshd[8352]: Invalid user jenkins from 10.30.168.15 port 43188 Nov 11 13:17:34 prd-ubuntu2004-docker-4c-4g-6563 sshd[8352]: Received disconnect from 10.30.168.15 port 43188:11: Closed due to user request. [preauth] Nov 11 13:17:34 prd-ubuntu2004-docker-4c-4g-6563 sshd[8352]: Disconnected from invalid user jenkins 10.30.168.15 port 43188 [preauth] Nov 11 13:17:37 prd-ubuntu2004-docker-4c-4g-6563 sshd[9202]: Invalid user jenkins from 10.30.168.15 port 43198 Nov 11 13:17:37 prd-ubuntu2004-docker-4c-4g-6563 sshd[9202]: Received disconnect from 10.30.168.15 port 43198:11: Closed due to user request. [preauth] Nov 11 13:17:37 prd-ubuntu2004-docker-4c-4g-6563 sshd[9202]: Disconnected from invalid user jenkins 10.30.168.15 port 43198 [preauth] Nov 11 13:17:40 prd-ubuntu2004-docker-4c-4g-6563 sshd[9829]: Invalid user jenkins from 10.30.168.15 port 43206 Nov 11 13:17:40 prd-ubuntu2004-docker-4c-4g-6563 sshd[9829]: Received disconnect from 10.30.168.15 port 43206:11: Closed due to user request. [preauth] Nov 11 13:17:40 prd-ubuntu2004-docker-4c-4g-6563 sshd[9829]: Disconnected from invalid user jenkins 10.30.168.15 port 43206 [preauth] Nov 11 13:17:40 prd-ubuntu2004-docker-4c-4g-6563 useradd[10097]: new group: name=jenkins, GID=1001 Nov 11 13:17:40 prd-ubuntu2004-docker-4c-4g-6563 useradd[10097]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash, from=none Nov 11 13:17:41 prd-ubuntu2004-docker-4c-4g-6563 usermod[10164]: add 'jenkins' to group 'docker' Nov 11 13:17:41 prd-ubuntu2004-docker-4c-4g-6563 usermod[10164]: add 'jenkins' to shadow group 'docker' Nov 11 13:17:43 prd-ubuntu2004-docker-4c-4g-6563 sshd[10631]: Accepted publickey for jenkins from 10.30.168.15 port 43214 ssh2: RSA SHA256:BBsm4mRgG5V0fGum4Y1Rmy/vs16stdRVhwvexlLUhUs Nov 11 13:17:43 prd-ubuntu2004-docker-4c-4g-6563 sshd[10631]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Nov 11 13:17:43 prd-ubuntu2004-docker-4c-4g-6563 systemd-logind[760]: New session 1 of user jenkins. Nov 11 13:17:43 prd-ubuntu2004-docker-4c-4g-6563 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Nov 11 13:18:02 prd-ubuntu2004-docker-4c-4g-6563 CRON[16893]: pam_unix(cron:session): session opened for user root by (uid=0) Nov 11 13:18:02 prd-ubuntu2004-docker-4c-4g-6563 CRON[16893]: pam_unix(cron:session): session closed for user root Nov 11 13:19:01 prd-ubuntu2004-docker-4c-4g-6563 CRON[28562]: pam_unix(cron:session): session opened for user root by (uid=0) Nov 11 13:19:01 prd-ubuntu2004-docker-4c-4g-6563 CRON[28562]: pam_unix(cron:session): session closed for user root Nov 11 13:20:01 prd-ubuntu2004-docker-4c-4g-6563 CRON[29008]: pam_unix(cron:session): session opened for user root by (uid=0) Nov 11 13:20:01 prd-ubuntu2004-docker-4c-4g-6563 CRON[29008]: pam_unix(cron:session): session closed for user root Nov 11 13:21:01 prd-ubuntu2004-docker-4c-4g-6563 CRON[29014]: pam_unix(cron:session): session opened for user root by (uid=0) Nov 11 13:21:01 prd-ubuntu2004-docker-4c-4g-6563 CRON[29014]: pam_unix(cron:session): session closed for user root Nov 11 13:21:38 prd-ubuntu2004-docker-4c-4g-6563 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/docs-rtd-verify-calcium ; USER=root ; COMMAND=/usr/bin/cp /var/log/auth.log /tmp Nov 11 13:21:38 prd-ubuntu2004-docker-4c-4g-6563 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)